September releases: DNS checks and renewal fixes
September’s releases cover local file permissions, container distribution and certificate workflow failures. The app changes below are September 24 merges to main; they are listed separately from tagged releases and do not establish production deployment status.
CLI v0.4.0
Released September 4, with these changes documented in the v0.4.0 changelog:
- Config permissions: Permissions broader than
0600now cause a configuration error and refusal to proceed, replacing the previous warning; this check is not enforced on Windows. For the default config location, usechmod 600 ~/.config/krakenkey/config.yaml; ifXDG_CONFIG_HOMEis set, apply the change to the config file under that directory. - Container images: Images now come from
ghcr.io/krakenkey/cli, and the Docker Hub image is no longer updated. A single OCI index coversamd64andarm64; separate per-architecture tags are no longer published.
Probe v0.3.0
- State-file permissions: The September 4 release changes the state file’s creation mode from
0644to0600, as recorded in the changelog. Existing state files retain their current permissions; the new creation mode applies when a file is first written.
cert-action v1.2.0
- Renewal errors: The September 4 release now surfaces CLI error output when renewal fails. These changes merged on August 31 and appear in the v1.2.0 changelog.
- Download sequencing: With waiting enabled, a successful renewal wait now triggers certificate downloads, even when the initial response still reports
renewing; a failed wait stops the action. Without waiting, downloads require anissuedstatus (implementation).
App: merged September 24
The app has no tagged releases; these entries describe merged changes.
- Delegation preflight: PR #108 checks
_acme-challengeCNAME delegation before creating an ACME account or order. It strips wildcard prefixes, deduplicates domains and follows CNAME chains up to five hops. - Incorrect delegation: Missing or wrong targets produce a permanent failure with the exact corrective record in the error message, avoiding repeated validation for known incorrect delegation. Resolver errors such as timeouts or SERVFAIL warn and continue normal validation, so preflight does not replace CA validation or change the one-time delegation model.
- Dissolution retries: PR #107 handles an owner’s existing personal subscription and removes a failed queue job with the same ID before re-queueing, allowing the retry to execute. Conflicting live subscriptions still require manual resolution.