Wave 0 — DECISIONS (the gap assessments name the options)
#208: pick the retrieval channel (setup-time paste is the lazy correct default)
+ the default-flip migration story (don't brick existing fleets on upgrade)
#261: pick terminator (xmrig-proxy native TLS — verify upstream) + port model
(replace :3333 vs parallel TLS port for mixed-fleet migration) + trust model
(self-signed + fingerprint pinning recommended)
│
▼
#208 auto-fetch stratum password → default-on auth [mostly rigforge#113]
└─► #261 stratum-over-TLS [lockstep with rigforge#115]
▼
SHIP 1.9
All milestone issues closed or punted-with-comment. Closing this tracker with the milestone.
Warm-up — before the stratum work
Upgrade hygiene (from the 2026-07-18 prod
v1.7.0 → v1.8.1one-click — all observed live):current->+ dir name on the old version, destroying the previous bundle. The heavyweight of the wave: needs the extract-to-fresh-dir design (mind theDASHBOARD_DATA_DIR-inside-version-dir mount caveat, Standardize the deploy-box layout: upgrade maintains a symlink; dashboard data joins the shared data root #455). Prod's rollback is currently degraded to v1.6.2 and every one-click compounds it — do this first.make testomits the frontend node suite — addtest-frontendto the chain so local == CI.Efficiency:
Docs:
The stratum work
"auto"default question); the implementation is rigforge#113. Interacts with v1.4'spithead rotate-secrets: regenerate the stack's internal credentials in one command #378 (rotate-secretsbecomes fleet-practical once rigs can re-fetch).pools[].tls+ fingerprint pinning) lands in lockstep.Rolled in during the cycle (2026-07-18)
Operator-filed during the cut window; reviewed + merged, rides v1.9.0.
Operator-filed during the cut window; retroactive tracking issue Dashboard: surface XvB raffle wins (chart markers, wins list, log) #644 carries the design
record. Verifier PASS; security pass found one MEDIUM (unbounded storage of rows mirrored
from the untrusted winners file) — fixed pre-merge with parse/table/read bounds. Rides
v1.9.0.
cut window; completes One-click upgrade leaves current-> symlink and dir name on the old version, destroying the previous bundle #629's rollback story (in-place path snapshots config/.env fail-closed,
symlink-safe, pruned to three pairs; both paths name the restore point in the result + modal).
Reviewed line-by-line in-session; rides v1.9.0.
fills a gap in shipped Confirm payouts on-chain with a view-only wallet (monero-wallet-rpc against the local node) #381/Confirm Tari payouts on-chain with a view-only minotari wallet (sibling of #381) #462; no tracking issue needed. Rides v1.9.0.
feed, per its own note) ride the next release.
ESM — the first v1.9.0 cut stopped at the stage-2 test gate the moment make test omits the frontend node suite — local run diverges from CI #632 wired the frontend
suite into
make test(working exactly as intended: that skew was previously invisible).Box upgraded to node 20 LTS via nodesource; recorded in gouda's
~/README.md.Release status — ✅ SHIPPED (v1.9.0 published 2026-07-19T01:14Z)
v1.9.0=7649402; images digest-pinned; main merged (release: v1.9.0 — stratum link security #649) + back-merged(release: back-merge main into develop after v1.9.0 #650), invariant verified. Release notes = CHANGELOG [1.9.0].
restored (
current -> pithead-v1.9.0,pithead-v1.8.0rollback). NOTE: that upgrade ran underthe v1.8.1 runner — the LAST in-place one; the One-click upgrade leaves current-> symlink and dir name on the old version, destroying the previous bundle #629 fresh-dir path goes live-proven on the next
one-click (same as-designed lag as One-click upgrade shows "Upgrade did not complete — HTTP 502" on a successful upgrade #622's poller fix).
pin refused ("Failed to verify server certificate fingerprint"); cleartext rig coexists.
Fingerprint
cb1c0159…c34c8de3, cert under the shared data root. miner-1 restored to baseline.90/hr, HSDir fails 971→235/hr, tor CPU 32-44%→14-21%(early windows; caveats on the issue). Lever 3 deliberately dropped.
final observation). docs: refresh screenshots and images to current dashboard/branding #479 punted to v1.10 (logo gate cleared; needs an operator capture
session).
v1.9.0 is prod's last in-place extraction, everything after keeps versioned dirs + rollback.
All milestone issues closed or punted-with-comment. Closing this tracker with the milestone.