Skip to content

Server compatibility

The client and server are versioned independently. A client release "targets" a server release when its pinned OpenAPI contract comes from that server tag and the complete Docker-backed library and consumer integration suites pass against an immutable image for the same release.

Dedicated typed helpers do not necessarily exist for every server operation. Authenticated relative routes remain available through raw() while typed coverage evolves.

Compatibility history

Client version Server target Tested server image Evidence
0.13.0 0.0.17 ghcr.io/hubuum/hubuum-server@sha256:cc0518167816bfddb38853b8b7217c4a347511318d51e1abca93ca418f31b302 Declared target; 227-operation contract and 87 wire-model mappings. Canonical run passed with approval enforcement: 93 library tests, 33 consumer tests including both notification modes, and all four full restore/recovery variants (2026-10-05).
0.12.0 0.0.16 ghcr.io/hubuum/hubuum-server@sha256:37b3299edd845a0c2aa7772d7d68565233ac8c1802bc44be3fb4bbc6dfa8778e Declared target; 220-operation contract and 79 wire-model mappings. Complete canonical run passed with approval enforcement required: 93 library tests, all downstream suites with typed discovery and retained details for all six task kinds, real cursor pagination, and four full restore/recovery variants (2026-09-22).
0.11.2 0.0.16 ghcr.io/hubuum/hubuum-server@sha256:37b3299edd845a0c2aa7772d7d68565233ac8c1802bc44be3fb4bbc6dfa8778e Declared target; 220-operation contract and 73 wire-model mappings. Complete canonical run passed with approval enforcement required: 93 library tests, all downstream suites including async/blocking task discovery, and four full restore/recovery variants (2026-09-22).
0.11.1 0.0.15 ghcr.io/hubuum/hubuum-server@sha256:36af667dbc9e221a40448496d4a87e168c999d0834df4b69177345ff3d36e821 Declared target; unchanged 218-operation contract, optional credential approvals, and refreshed Rust 1.88-compatible dependencies. Complete canonical run passed: 93 library integration tests, all downstream consumer suites, and four async/blocking full restore/recovery variants (2026-09-22).
0.11.0 0.0.15 ghcr.io/hubuum/hubuum-server@sha256:36af667dbc9e221a40448496d4a87e168c999d0834df4b69177345ff3d36e821 Declared target; 218-operation pinned contract, 67 wire-model mappings, schema evolution, cancellation, format 6 backups, and refreshed Rust 1.88-compatible dependencies. 91 library and 26 consumer integration tests, plus four async/blocking full restores with and without history and schema-evidence-preserving recovery (2026-09-16).
0.10.1 0.0.14 ghcr.io/hubuum/hubuum-server@sha256:6c1c8d7316a1f60a02e4505611a44e21030ba678b5b451f5b293a12f2bd87594 Declared target; unchanged 204-operation OpenAPI contract, refreshed Rust 1.88-compatible dependencies, 89 library and 24 consumer integration tests, plus four async/blocking full restores with and without history and revision-preserving recovery with subsequent backup validation (2026-09-10)
0.10.0 0.0.13 ghcr.io/hubuum/hubuum-server@sha256:512562e789d6430875c5075faf832a9669a4f266f7fe9fbf8c1524b49a6476c5 Declared target; pinned OpenAPI, refreshed Rust 1.88-compatible dependencies, 89 library and 24 consumer integration tests, plus blocking and async full restore completion, token invalidation, and recovery after each restore (2026-09-09)
0.9.1 0.0.9 ghcr.io/hubuum/hubuum-server@sha256:1f12baf882b6d3df5b4b2dbdf26aad0793274e57f86a2c186b8e1e68632db5db Declared target; JSON-path validation, advertised pagination limits, atomic export downloads, property-level OpenAPI model reconciliation, dependency and release-workflow security updates, with pinned Docker-backed library plus downstream-consumer integration coverage
0.9.0 0.0.9 ghcr.io/hubuum/hubuum-server@sha256:1f12baf882b6d3df5b4b2dbdf26aad0793274e57f86a2c186b8e1e68632db5db Declared target; revision and ETag concurrency, import v2, settings JSON Patch, revision-owned permission and membership responses, computed-field points, token lifecycle state and renewal, with pinned Docker-backed library plus downstream-consumer integration coverage
0.8.0 0.0.8 ghcr.io/hubuum/hubuum-server@sha256:850bfd95a2802485f93c1700fbff5a33465cbc7855cbc94962982c1074fd96f6 Declared target; property-complete v0.0.8 cardinality, core-import timestamp, and export-timing models with pinned Docker-backed library plus downstream-consumer integration coverage
0.7.3 0.0.8 ghcr.io/hubuum/hubuum-server@sha256:850bfd95a2802485f93c1700fbff5a33465cbc7855cbc94962982c1074fd96f6 Declared target; pinned OpenAPI and complete Docker-backed library plus downstream-consumer integration suites
0.7.2 0.0.5 ghcr.io/hubuum/hubuum-server@sha256:6f3e0f0debd418acd5cbc2b1399db9859a85ca1fa397525a5ef0e2f493a77c9b Declared target; pinned OpenAPI and full integration suites, including public default-token-lifetime discovery, authoritative login and token-mint expiry metadata, token retention configuration, scoped/unscoped token lifecycles, expiry enforcement, revocation, imports, exports, and downstream-consumer coverage
0.7.1 0.0.4 ghcr.io/hubuum/hubuum-server@sha256:60142d605f423b1dc58d9dfe709164b0d5ec93befd2d702f9bdca7ee0654a583 Declared target; pinned OpenAPI and full integration suites, including sensitive secret-header metadata plus blocking user and async service-account scoped/unscoped token lifecycles, expiry enforcement, revocation, and post-revocation rejection
0.7.0 0.0.4 ghcr.io/hubuum/hubuum-server@sha256:60142d605f423b1dc58d9dfe709164b0d5ec93befd2d702f9bdca7ee0654a583 Declared target; pinned OpenAPI and full integration suites, including blocking user and async service-account scoped/unscoped token lifecycles, expiry enforcement, revocation, and post-revocation rejection
0.6.1 0.0.3 ghcr.io/hubuum/hubuum-server@sha256:f1f57a991f69005ee81f24e77533e61f75b5586949d98cccf1c40fc4329eb186 Declared target; pinned OpenAPI and full integration suites, including async and blocking diagnostic redaction, custom-transport isolation, and redirect-confinement regressions
0.6.0 0.0.3 ghcr.io/hubuum/hubuum-server@sha256:f1f57a991f69005ee81f24e77533e61f75b5586949d98cccf1c40fc4329eb186 Declared target; pinned OpenAPI and full integration suites, including exact-name routing, aggregates, object-data patching, and public pagination configuration
0.5.1 0.0.2 ghcr.io/hubuum/hubuum-server@sha256:8f543383b422124546c8d337fd557e1b182b1b6c7078d7870d3c5cd4f955ef1f Declared target; pinned OpenAPI and full integration suites, including the runtime-configurable metrics route
0.5.0 0.0.2 ghcr.io/hubuum/hubuum-server@sha256:8f543383b422124546c8d337fd557e1b182b1b6c7078d7870d3c5cd4f955ef1f Declared target; pinned OpenAPI and full integration suites
0.4.0 main@eed194f2339ce221ef251a14062e2a37850186b1 ghcr.io/hubuum/hubuum-server@sha256:9eb7d2eb83220ac6e38d9964df2e6f4268152a072b0cece3e81a63b52d7b8e19 Reproducible pre-release snapshot, not a stable server release
0.3.0 main@eed194f2339ce221ef251a14062e2a37850186b1 ghcr.io/hubuum/hubuum-server@sha256:9eb7d2eb83220ac6e38d9964df2e6f4268152a072b0cece3e81a63b52d7b8e19 Reproducible pre-release snapshot, not a stable server release
0.2.0 main (floating) Not recorded No stable server target was declared
0.1.0 Not recorded Not recorded No stable server target was declared
0.0.3 main (floating) Not recorded No stable server target was declared
0.0.2 no-tls-main (floating) Not recorded No stable server target was declared
0.0.1 Not recorded Not recorded No stable server target was declared

The client version 0.0.2 row predates and is unrelated to the independently versioned Hubuum server v0.0.2 release.

Forward compatibility

Client 0.11.1 introduced the fresh credential approval API for servers incorporating PR 423. That release kept its declared v0.0.15 target, pinned image, and OpenAPI snapshot. Existing calls do not require the approval endpoints. On an enforcing server, credential mutations return reauthentication_required until the caller uses the explicit approval workflow.

Focused live verification on 2026-09-19 used the PR's merged source revision 3a1c44c938cc9d06d665229612c0fb1b4f3c98c8 and immutable Linux amd64 image ghcr.io/hubuum/hubuum-server@sha256:62438f2473ee15f9699ccc904e79c4c20c27e06a1219986c04493d269127f3e0. With HUBUUM_INTEGRATION_EXPECT_CREDENTIAL_APPROVALS=1, async and blocking token creation/renewal preserved approved expirations, and downstream user/password and credential-import dry runs passed. Blocking and async full restore confirmation and recovery passed with and without history. These focused checks supplement the required complete pinned-server run; they do not declare compatibility with all other changes on server main.

The canonical complete pinned-server command also passed on 2026-09-19 against the v0.0.15 image declared in Cargo.toml, including library and downstream consumer tests and all four restore/recovery scenarios. The new credential scenarios passed through the original APIs without requiring approval support.

After the fixture repairs in client PR 95, the complete library and downstream consumer integration suite passed on 2026-09-22 against immutable server candidate 61f1bfd3455af26254e1dc73e697a80b0536813a, image ghcr.io/hubuum/hubuum-server@sha256:8944a31e47ff97eb14bf5072772149c06d87714a316db54aa4e010195c5811a0. Approval enforcement was required, and all four full restore/recovery variants passed. This extends the earlier focused evidence to the complete suite. This evidence preceded publication of v0.0.16. Client 0.11.2 targets the released artifact and reviewed contract as described below.

Required CI is deterministic and stays pinned to the declared target. Scheduled jobs separately compare the contract and run the integration suites against the server's main branch. Those scheduled checks are early-warning signals; they do not change a published client's declared target.

v0.0.17 target

Client 0.13.0 targets server v0.0.17. The reviewed contract grows from 220 to 227 operations and from 330 to 336 schemas. Most other snapshot changes reorder nullable schema alternatives after the server's Utoipa update; they do not alter wire behavior. Rust 1.88 and the client feature sets are unchanged.

Event sink CRUD and import models preserve delivery policy, subscription filters include task kinds, and delivery responses preserve purpose and deferral details. Delivery health accepts an absent or null collection ID for system subscriptions. The seven new system-subscription CRUD and notification preview/test operations use the existing authenticated raw() extension point. Their routes and limitations are recorded in known gaps.

This is a breaking Rust release: handle None in EventSubscriptionDeliveryHealth.collection_id, add delivery_policy: None to exhaustive sink request/import literals and task_kinds: None to exhaustive subscription filter literals. Default-based construction remains available for sink requests and filters; use .. in exhaustive destructuring patterns.

The server emits backup format 7 and still accepts format 6 with legacy notification defaults. The client recognizes both formats and rejects older or unknown formats through has_supported_version(). Existing format-6 schema sections and format-7 notification data remain intact in the generic backup section maps. See the backup guide.

Upgrading from v0.0.16 requires a maintenance window. Stop all writers, including API, worker, and restore-executor processes; take a PostgreSQL snapshot; then apply the webhook-notification migration and deploy matching v0.0.17 binaries. Binary-only rollback is unsupported. Recovery requires that snapshot with the matching v0.0.16 binaries and loses writes made after the snapshot. Older servers cannot restore format 7. Optional Treetop backends also require protocol 0.1 and updated policy bundles. See the server release notes.

The pinned multi-platform index is sha256:cc0518167816bfddb38853b8b7217c4a347511318d51e1abca93ca418f31b302. Its Linux amd64 manifest is sha256:a7082cb13a94d2c0f8934ade79f2117e39b66c1725b4ee9696e49c2895bcb672. The image's version and source labels identify v0.0.17 and tag commit 4a03d56b27f35af62175a80d09d36d0d41c4a663.

The canonical combined command passed on 2026-10-05 against that Linux amd64 image with HUBUUM_INTEGRATION_EXPECT_CREDENTIAL_APPROVALS=1: all 93 library integration tests, 33 ordinary consumer tests, and all four async/blocking restore/recovery variants with history included and omitted. The consumer tests covered all seven new notification routes in both modes, nullable system health, delivery-policy round trips and clearing, task-kind filter serialization, rendered previews, and real test-delivery decoding. Format-7 backups staged and restored successfully; recovery retained resource and schema revisions and validated subsequent backups.

All workspace tests, feature combinations, Rust 1.88, lint, documentation, generator, pinned contract, and dependency audit/policy checks passed. Dependency resolution is current under Rust 1.88 and upstream constraints; crypto-common 0.1.7 still pins generic-array to 0.14.7. The normal public API check accepts the 0.13.0 version; a stricter comparison confirms the documented added-field breaks requiring this pre-1.0 major bump. All GitHub Action pins and the PostgreSQL 18 fixture digest were verified current.

v0.0.16 target

Clients 0.11.2 and 0.12.0 target server v0.0.16. The pinned contract grows from 218 to 220 operations and from 315 to 330 schemas. Both added approval routes already have typed async and blocking APIs. Client 0.12.0 reconciles 79 wire-model mappings, including retained task details. Feature availability, Rust 1.88, and backup format 6 are unchanged.

Credential mutations require fresh, operation-bound password approval. Before upgrading the running server, update applications to use the approval workflow. Existing mutation methods retain their original behavior and return reauthentication_required when the server enforces approvals; they do not prompt or automatically retry.

Client 0.12.0 exposes every task-discovery filter and retained detail projection through the async and blocking typed APIs, including cursor pagination and local query validation. Client 0.11.2 required raw() for those additions. The new optional fields break exhaustive Rust struct literals and destructuring; see the task discovery migration guide.

Keep a verified v0.0.15 backup, quiesce protected mutations, drain workers, and apply 2026-09-18-000001_task_discovery and 2026-09-19-000001_credential_approvals with hubuum-admin --migrate. Deploy matching API, worker, administrator, and separately supervised restore-executor binaries before resuming operations. Older format-6 backups without discovery metadata remain accepted. See the server release notes.

The immutable multi-platform release image is ghcr.io/hubuum/hubuum-server@sha256:37b3299edd845a0c2aa7772d7d68565233ac8c1802bc44be3fb4bbc6dfa8778e. Its Linux amd64 manifest is sha256:2f1e59519c3e5fb0a849ee6db8f3f3981b76145cac2f9ffb6f463a8927d4f7d2, and its source label matches the v0.0.16 tag commit 8f4194ffe25d172d579b676f109efbdc71d9aab7.

The canonical combined command passed on 2026-09-22 with HUBUUM_INTEGRATION_EXPECT_CREDENTIAL_APPROVALS=1: all 93 library integration tests, every downstream consumer suite, and all four async/blocking full restore/recovery variants. The downstream discovery scenarios verified resource and output filters, comma-separated statuses, retained export metadata, and decoding of newer responses through the unchanged typed task models.

v0.0.13 target

The 0.10.0 release targets server v0.0.13, which fixes the restore drain-state race and JSON-null insertion failure found during v0.0.12 verification. Its 204-operation OpenAPI contract is unchanged from v0.0.12 apart from the server version. Backup format 5 is unchanged.

Install matching server, administrator, and template-worker binaries, including any separately deployed hubuum-admin --restore-executor. See the server release notes and the backup and restore guide for migration and recovery steps.

The canonical combined integration command passed on 2026-09-09 against the released immutable image above (Linux amd64). All 89 library and 24 ordinary consumer tests passed, followed by blocking and async full restore completion and recovery after each restore. Both modes reached Succeeded, rejected the pre-restore bearer token, and recovered the deleted object after administrator password reset and a fresh login.

The published image identifies source revision 8ecefbf3e3147714014221598d9873ba92e0fdce, matching the v0.0.13 release tag. The manifest pins the multi-platform image index; this live run verifies its Linux amd64 image.

v0.0.14 target

The 0.10.1 patch release targets server v0.0.14. Its 204-operation OpenAPI contract is unchanged from v0.0.13 apart from the server version. Public client APIs, features, the Rust 1.88 MSRV, and backup format 5 are unchanged.

The server fixes backup and restore consistency, including preserving revisions and establishing current temporal snapshots after history-free restores so later backups remain restorable. Install matching server, administrator, and template-worker binaries, including any separately deployed hubuum-admin --restore-executor. Existing history-free format 5 artifacts can be restored directly with the fixed executor. No database migration is added; the server's certified upgrade and application rollback path is v0.0.13 to v0.0.14. See the server release notes and the backup and restore guide.

The canonical combined integration command passed on 2026-09-10 against the released immutable image above (Linux amd64). All 89 library and 24 ordinary consumer tests passed, followed by all four combinations of blocking/async full restore and history included/omitted. Every restore reached Succeeded, rejected the pre-restore bearer token, and recovered the deleted object with its original revision after administrator password reset and a fresh login. Recovery also created and successfully staged default backups both before and after another mutation, covering the history-free restore fix.

The published image identifies source revision 0b0aa17f278496a32cc018cfcac56f34a408ccd6, matching the v0.0.14 release tag. The manifest pins the multi-platform image index; this live run verifies its Linux amd64 image.

v0.0.15 target

The 0.11.0 release targets server v0.0.15. The contract grows from 204 to 218 operations and from 280 to 315 schemas. All 14 new operations have typed async and blocking helpers, covering the class schema lifecycle, retained HTML repair reports, and task cancellation. Feature availability and Rust 1.88 remain unchanged.

ImportClassInput gains schema_activation; add schema_activation: None to existing struct literals or provide an explicit activation request. Changing schema policy on a nonempty class now requires staging, impact analysis, and activation instead of direct PATCH or legacy import overwrite. Imports must provide the exact staged policy. See the schema guide.

Backup format 6 replaces format 5, adding schema revisions, state, evidence, and history. Restore older artifacts using their matching older server before migrating and creating new format 6 backups; no artifact converter is provided. Drain old workers, apply the release's migrations, then deploy matching API, worker, administrator, and restore-executor binaries. Existing enforced objects start pending and need revalidation. See the backup guide and server release notes.

The server also tightens schema validation and resource budgets, changes string cursor ordering to byte ordering on locale-collated databases, and requires the CancelTask external authorization action. Restart in-progress string-sorted pagination, review stored schema admission, and deploy consistent schema, task, and backup limits across processes. Report assembly can return HTTP 413, and external-authorization traversal is bounded at 10,000 candidates.

All direct dependencies already use constraints that select the latest compatible releases. The lockfile refresh updates twelve packages, including Rustls 0.23.45 for RUSTSEC-2026-0285. generic-array remains at 0.14.7 because the current crypto-common 0.1.7 dependency requires that exact version.

The pinned multi-platform image identifies source revision 4bb889c66a5e2a1dfc86d1b6beac7495912fd02e, matching the annotated v0.0.15 tag.

The canonical combined integration command passed on 2026-09-16 against this image's Linux amd64 build. All 91 library and 26 ordinary consumer tests passed, including both modes of the schema lifecycle, diagnostic HTML, import activation, and task cancellation. All four combinations of blocking/async full restore and history included/omitted reached Succeeded and invalidated the old bearer token. Recovery after each restore preserved the object's resource revision, the active schema revision, and validation evidence. Subsequent backups before and after a mutation also passed restore staging validation.