Repository navigation
docs: track 0.18.1 — every page says what 0.18.1 does, with release notes and an upgrade guide for 0.15.1–0.18.1 - #141
Merged
Merged
Conversation
…es you The quickstart now scaffolds fluidVersion 0.7.5, so the pin that guards it moves with it. Content for 0.15.1 through 0.18.1 follows in this branch.
…de guide from 0.15.x to 0.18.1
…egion pin and guard, Lake Formation column grants and bucket policy, KMS and lifecycle, masking at landing, verify on Glue/Athena
…al sandbox and path rules; Snowflake governance as it ships in 0.18.1
…oped DAGs, Command Center publish, and corrected ship, retention and secrets behaviour
…8.1, and what nothing enforces
validate: --probe is accepted and ignored, --report applies to bundles only, the workspace form runs the schema check only; adds --env overlay behaviour, governance binding checks, bundle validation and schema versions. rollback: snapshots exist only on the native apply path, restore per provider, the latest-snapshot ordering issue. runs, stats, status, describe, docs, version, doctor, auth: real output and flags.
…-build DAGs, sql and dbt engine output, ci options and Jenkins defaults, GCP grants, per-provider state key, known --provider limits
… remote state keys, Command Center run reporting, live and state drift in diff
… anchor stays put
…ags, contract digest, working contract-tests baseline, init paths and fluidVersion table, import --server-url, ai test
… and product types match 0.18.1 Rewrite consumes[] with the productId/exposeId shape and how a DuckDB build resolves it (workspace, FLUID_UPSTREAM_CONTRACTS, --env, lineage-only, explicit inputs), with real output and failures. Fix invalid examples (s3 path, execution trigger, Python build), the binding enums, the cloud-switch claim (overlays), the required-field count, the version list (0.7.6 preview) and the spec link. Say what validate, plan, apply and diff actually do with composition rules and versions.
… against 0.18.1, with runnable examples and real output
…limit refusals, show where accessPolicy lives, fix the build-destination wording
…w and network pages from 0.18.1 Environment variables are regrouped from the 0.18.1 read sites, with the variables that earlier versions listed but nothing reads named as such. The CI page follows the bundle chain the generated Jenkinsfile runs and documents the generate ci options, the dry-run default and the advisory federation check. The error pages now cover the codes added in 0.16 to 0.18 (state, overlay, publish, masking, sandbox) with real output, correct exit codes and the real render shape. Airflow leads with fluid generate schedule; credential-resolver, network-safety and capability-warnings are corrected against the code.
…does, drop drift rule claim
…y --format json output
…m-scaffold command, CLI-linked pages contract, honest demo caveats
…licy checks and audit writes
…ten two unchecked claims
… pip install form, GCP bucket permissions
…debar duplicate and scoping of the upgrade notes
…nt cases and Data Catalog wording
… the contract pages
…ts and the Forge GPT pack re-verified on CLI 0.18.1
… MCP and source-aligned walkthroughs on 0.18.1 and fix what drifted
…port walkthroughs on CLI 0.18.1 The local walkthrough now runs a two-product journey that lands real files, and states what the local engine does and refuses (sandbox, first-expose writes, masking, placeholder output). The 11-stage page follows the bundle chain the generated Jenkinsfile runs, with the live and state drift gate, the stage 6 sovereignty check, Command Center apply reporting, env-scoped DAG layout and the first-build parameter caveat. The Airflow and export pages show real generated output, and the export contracts validate.
…laims, clearer MCP fragment note
…tention warning on apply, drop a non-reproducible sql_chars value
…-run behaviour, complete the GCP DAG output
…ugh, advanced and SDK passes
… runs The companion package's entry point is named generate-custom-scaffold, but the subcommand it registers is custom-scaffold, and only that name runs. The SDK pages now use it, so the allowlist entry follows.
…e, playground AWS path, anchor fix
…witch clouds below it
….18.1 pass Link the provider pages to the verify, apply, governance and acquisition references, say that the local reader depends on the apply mode, explain the missing-pattern validation error, replace the 0.18 quality-rule description, add the FAQ symptoms, mark the 0.15.0 federation gate as superseded and complete the data-model flag list.
…ther; fix agent-policy fragment placement and three stale anchors
…ials corrected, CI stage and env-var coverage, snapshot and runs claims fixed
…chain and placeholders MCP output port: mTLS at a proxy authenticates the connection but binds no identity. FLUID_MCP_AUTH_MODE accepts shared-token, jwt and none; only a verified JWT supplies model, use_case, tenant_id and jurisdiction. The X-Client-CN and X-Client-Fingerprint headers are copied unverified into the caller attributes when an auth mode is enforced and reach no audit record. A shared token drops client-declared identity, so a model-gated contract denies every call as missing-model-identity. Credentials: Jenkins credentials binding is the recommended path; Global and Node Properties are warned against. Universal-pipeline Jenkinsfile gets a danger box listing its defects. The metadata-service opt-in is a per-call argument any MCP client can set. GitHub Actions template grants id-token: write per deploy job and pins the cloud trust to repository and environment. Supply chain: dependency-confusion warnings for FLUID_PIP_EXTRA_INDEX_URL, private plugin installs and FLUID_PLUGINS_ALLOWLIST, pin the Inspector and the scaffold-ci install. Placeholders: real third-party domains replaced with RFC 2606 names. GCP-bound examples use name.example.com because fluid validate refuses a .example principal on a GCP binding. Hash-suffixed IaC resource names recomputed for the new member. Also: init and secrets agree on secretRef for a database password; policy-apply is described as changing no permissions in 0.18.1; the GCP apply identity gets dataOwner and jobUser instead of bigquery.admin.
…on the first The gateway reads the caller's identity from each request's own context and never caches it on the shared session.
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this changes
The docs claimed to track CLI
0.15.3.pip install data-product-forgegives0.18.1. Content was last written for0.15.0:0.15.1–0.15.3only bumped version strings, and0.16.0–0.17.0had no docs pass at all. This PR brings every existing page up to what0.18.1does, and adds the release notes and upgrade guide that were missing.cli-version.jsonmoves to0.18.1.quickstartScaffoldVersionmoves to0.7.5, becausefluid init --quickstartnow emits it.0.7.5is stable and0.7.6is the preview.RELEASE_NOTES_0.16.0.mdcovers 0.15.1–0.16.2, andRELEASE_NOTES_0.17.0.mdcovers 0.16.3–0.17.0. Both use the 0.15.0 page's shape: headline, who should upgrade, checklist, per-area changes.upgrading.mdis a standing upgrade guide, with a per-version checklist from 0.15.x to 0.18.1 and how to check each step.RELEASE_NOTES_0.18.0.mdgains the 0.18.1 fix.docs/cli/**).--helpon 0.18.1. Missing flags and subcommands are added, for examplediff --state-backend/--workspace-dir/--no-state-drift,schedule-sync --delete-scope,generate ci's pipeline defaults andcontract digest. Wrong defaults, choices and outputs are corrected.opentofu_region_moved);bucketPolicy, andadminsbeing authoritative;lifecycle.expire;verifyon Glue/Athena.docs/governance-parity.md(#694). This covers dataset grants asiam_member, policy tags (with BigQuery's live refusal wording), CMEK, DAY-partition retention and sovereignty failing closed.consumes[]examples now validate.verifychecks.fluid policy-applychanges no permissions;validate --probeis accepted and ignored.fluid_build/_errors.py::_DOC_ROUTES), so those URLs are a contract.A second PR, "the story", follows once this merges. It adds the contract fragments concept page, environments, workspaces and state, one contract on two clouds, the generated contract field reference, and the reorganised navigation.
Tested
npm run docs:build: exit 0.node scripts/check-dist-links.mjs: clean, 115,736 absolute references across 227 built pages.scripts/check_cli_docs.pyagainst an installeddata-product-forge==0.18.1: every check OK, including the flag oracle over 1,226 documentedfluidinvocations and the version sweep.scripts/check_providers.py: OK./forge_docs/, as GitHub Pages serves it, and walked in a browser:advanced/typed-cli-errors.html#validation-schema,#capability-negotiation,#connectivity-secrets,#pipeline-operationsand#governance.Security review
FLUID_MCP_AUTH_MODE=jwtdoes.withCredentials, not agent-wide properties.allow_metadata_service.id-token: writeis granted on deploy jobs only.Prior art
Follow-ups (not in this PR)
examples/directory still usescompany.com/yourcompany.comin sample contracts.