Skip to content

Release v0.28.0 - #95

Merged
lchoquel merged 2 commits into
mainfrom
release/v0.28.0
Sep 25, 2026
Merged

lchoquel merged 2 commits into
mainfrom
release/v0.28.0

Conversation

@lchoquel

@lchoquel lchoquel commented Sep 25, 2026 •

Copy link
Copy Markdown
Member

Release v0.28.0

Bumps version from 0.27.5 to 0.28.0. Promotes dev → main.

Changelog

Highlights

The runner's logs are structured. Every line it writes to stderr is one JSON object with each value under a key of its own, the request id rides every record a request emits, the Pipelex runtime's included, and secrets are scrubbed before a line is written.

Changed

  • The server's logs are structured, one JSON object per line on stderr (Breaking): [runtime.log] sink = "json" replaces the Rich console renderer, console_log_target moves to stderr, and pretty_print_mode = "silent" stops an operator pipe drawing its "Output of pipe" panel on the thread serving a request. Every value an error line carries — route, status, error_type, error_domain, retryable, user_id / pipe_code / pipeline_run_id when the request bound them, and detail on the failures this API authors itself — is a key of its own now rather than part of a key=value run inside the message, and request_id rides the runtime's request-scoped log context, so it lands on every record emitted during a request, including the ones Pipelex emits from inside a run. The message is a short sentence built only from the status and the error type, so no caller-supplied string reaches it and the API's own escaping is gone: the sink is what serializes a value now. A log query matching event=api_error as text has to move to the event field. The new docs/logging.md documents the line and every field on it. Uvicorn's own banner and access log are unchanged and still plain text.
  • Pinned pipelex 0.66.0 (Breaking): up from ==0.65.0, exactly, the release that carries the structured-log seam the entry above rides on: named fields and the run-scoped log context, the json sink selected by [runtime.log] sink, the redaction of secrets before any sink sees a record, and Rich behind the cli extra, which this server's extras leave out. On this server's lines that means a credential echoed into detail reads [REDACTED], a control character in a field's value reads as its printable escape (\n where a caller sent a newline), and a line logged inside a traced run carries trace_id, span_id and trace_flags; docs/logging.md says so. The .pipelex/ config shipped here already sits at the schema that release migrates to, so no migration is required. One change reaches an operator beyond the logs: the S3 storage provider now signs links and reads and writes objects on the bucket's own regional host, <bucket>.s3.<region>.amazonaws.com, so a deployment whose egress rules allow S3 by hostname must allow *.s3.<region>.amazonaws.com. Nothing on the wire moves.
  • POST /v1/codegen stamps engine_version 0.66.0: the stamp is the pinned pipelex version, so a codegen.lock committed against 0.65.0 no longer matches until it is regenerated. POST /v1/build/runner carries the same stamp.

Fixed

  • A local image build no longer bakes the builder's own Pipelex overrides in: .pipelex/pipelex_override.toml and .pipelex/telemetry_override.toml are untracked per-developer files, so CI never had them, but make docker-build copied whatever the developer had into the image — their storage backend, their log level, their telemetry credentials. A locally built image then behaved differently from the published one, with nothing in the diff to say so. .dockerignore excludes them; an operator still supplies overrides to a container by mounting them at /root/.pipelex.

Closes L-260925-b2bafb

🤖 Generated with Claude Code

https://claude.ai/code/session_01TpAMq6PZNQfauyDvx3GR2H


Summary by cubic

Promotes dev → main for v0.28.0. The server's logs are now one JSON object per line on stderr instead of the Rich console renderer, and pipelex is pinned to 0.66.0, the release behind the structured-log seam. Error lines carry each value under its own key, secrets are redacted, and the request id rides every record a request emits, including ones Pipelex logs from inside a run.

Breaking

  • Tooling parsing the old log output must switch to the JSON line format; a custom pipelex.toml must keep sink = "json", console_log_target = "stderr", and pretty_print_mode = "silent".
  • POST /v1/codegen and POST /v1/build/runner stamp engine_version 0.66.0, so a codegen.lock against 0.65.0 must be regenerated.
  • The S3 storage provider signs links and reads/writes on <bucket>.s3.<region>.amazonaws.com; egress rules that allow S3 by hostname must allow *.s3.<region>.amazonaws.com.

Fixed

  • .dockerignore excludes the untracked .pipelex override files, so a local make docker-build no longer bakes a developer's storage backend, log level, or telemetry credentials into the image.

Written for commit 5e2f627. Summary will update on new commits.

Review in cubic

lchoquel and others added 2 commits September 25, 2026 18:51
…no rich (#81)

The runner now binds the runtime's log context per request and emits its
fields through the runtime's log calls, so its own request-id
contextvars and logfmt flattener are gone. It boots on the json sink
with the silent pretty-print mode and builds its image without the Rich
extra; it pins `pipelex` 0.66.0, the release that carries the log seam.

Closes L-260916-b7759f

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_019vmb35cM2bCxTwn49kCAXQ

<!-- This is an auto-generated description by cubic. -->
---
## Summary by cubic
Replaces the runner's request-id contextvars and logfmt flattener with
Pipelex's runtime log context and a JSON line sink on stderr. Error
lines now carry each value as its own JSON field, and `request_id` is
bound per request so every record the request emits — including ones
Pipelex emits from inside a run — carries it. Drops the `cli` extra, so
the Rich terminal renderer is never reached.

Closes L-260916-b7759f.

**Notes**
- Anything parsing the old console/logfmt output must switch to the JSON
line format.
- A custom `pipelex.toml` must keep `sink = "json"`, `console_log_target
= "stderr"`, and `pretty_print_mode = "silent"`.
- The sprint git-source pin for `pipelex` has collapsed onto the
released `0.66.0`; the runtime-contract guard and its test are deleted
with it.
- `pipelex` 0.66.0's redaction processor escapes control characters in
field values and redacts credentials echoed into `detail`; tests and
`docs/logging.md` cover both.
- Local Docker builds no longer bake untracked `.pipelex` override files
into the image.
- Deferred review findings are tracked in
`wip/structured-logs/review-deferrals.md`.

<sup>Written for commit ef292eb.
Summary will update on new commits.</sup>

<a
href="https://cubic.dev/pr/Pipelex/pipelex-api/pull/81?utm_source=github"
target="_blank" rel="noopener noreferrer"
data-no-image-dialog="true"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source
media="(prefers-color-scheme: light)"
srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img
alt="Review in cubic"
src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a>

<!-- End of auto-generated description by cubic. -->

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TpAMq6PZNQfauyDvx3GR2H
@lchoquel
lchoquel merged commit c61ff28 into main Sep 25, 2026
17 checks passed
@lchoquel
lchoquel deleted the release/v0.28.0 branch September 25, 2026 16:56
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 25, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant