§01
Upgrade cliffs
Warning
§02
Release notes
The chapters of this book describe v0.6.0. This table records what each release since v0.4.0 changed, so the history is in one place. The "Upgrade" column repeats the transition rule from the callout above; a change marked behaviour altered what a running application observes and can bite on upgrade.
Tbl. 1
| Release | Date | Upgrade from previous | Notable changes |
|---|---|---|---|
| v0.4.0 | 2026·08·28 | Full stop from v0.3.0 | Workers KV, Queues, Workflows, and R2 arrive, graded Partial at the time. Every proxied cell call (fetch, RPC, WebSocket) moves onto one versioned plain-HTTP peer tunnel, and deployments adopt in place without a restart. The output gate applies one ordering rule across responses, outbound calls, Queue deliveries, and WebSocket sends. celld dev opens a local store, replacing the earlier "no local filesystem mode" guidance. Large KV values move under an epoch-qualified reference. Behaviour: the health path moves from /__celld/health to /.well-known/celld/health; update load balancers and readiness probes. Gaps at this release: wrapKey/unwrapKey, RSA signing, and HKDF/PBKDF2 derivation were unavailable; Workflow retention and manual deletion were unavailable; the store was allowed to ignore Range; a node whose ready gate expired reported healthy anyway; the docs said a queue consumer could not also export fetch(), and that create() with a terminal Workflow instance's ID replaced it. |
| v0.4.1 | 2026·09·05 | Rolling; never restart v0.4.0 once paging began | Durable Object facets, HTMLRewriter, TCP sockets, EventSource, MessageChannel, an always-miss Cache, and the missing Web Crypto pieces. Paged restore through a fault-in SQLite VFS, which makes exact ranged reads a correctness requirement. Ownership balancing replaces the earlier rule that a joining node took only unowned cells, with POST /rebalance/pause / /resume. The self-fence names its cause with three distinct events, and a failed lease renewal retries before the authority expires. Nodes that restart together recover acknowledged writes, with checkpoints and a heartbeat. The Queue producer path is rebuilt: shared transactions and durability rounds, time-ordered message IDs, 7,357 sends/s on one queue (up from a few hundred). celld diagnose shows each node's load sample. Outbound TCP makes egress control the fleet network's job. |
| v0.5.0 | 2026·09·15 | Full stop with a procedure (alarm wake format 2); no binary rollback | Containers and the Sandbox SDK (Experimental). Dynamic Workers, the renamed Worker Loader, leaves the experimental tier and is declared in wrangler.jsonc (worker_loaders) rather than CELLD_WORKER_LOADER. Exact ranged reads become the fourth documented store requirement, and the startup probe can no longer be disabled. The compatibility page is reframed to list only differences and to grade Yes / Partial / Experimental / No. Idle eviction becomes opt-in via CELLD_IDLE_EVICT_S. Deploy records SHA-256 module digests; no_bundle projects get Wrangler's **/*.wasm discovery; container images live under deploy/images/. celld dev gains --clean, --watch-ignore, and .dev.vars. A restarting node waits behind a peer already recovering its log. An AbortSignal passes through a same-node RPC call. Shutdown tunables collapse into CELLD_SHUTDOWN_TOTAL_MS; the CELLD_RELEASES default rises from 8 to 128; CELLD_ACTIVATIONS defaults to 8 per CPU. An expired ready gate keeps readiness closed. /state adds handed_off, rebalanced, rebalance_failed, remote_route_refreshes, and node_load. CELLD_OTEL picks the telemetry sink; OTEL_EXPORTER_OTLP_ENDPOINT is no longer read. Workflow retention becomes configurable and completed runs deletable; replay is no longer listed as a celld difference. D1 migration extensions become case-insensitive; KV prefix listings get faster; internal host functions stop being exposed to application code. Behaviour: the variables listed under Rejected at startup in the environment table stop a node that sets them. |
| v0.5.1 | 2026·09·19 | Rolling | WorkerCode.limits enforces cpuMs and subRequests, and WorkerCode.tails delivers Tail Worker reports (both rejected in v0.5.0). The celld r2 CLI (get, head, put, delete, list) replaces wrangler r2 object. The documentation splits into per-service pages. /state adds allocator, libc_malloc, and deployment.isolates; /evict/<cell> waits for the eviction and reports the true outcome instead of reporting success early. Wrangler define and rules are accepted. Workflow defaults are documented for the first time, along with the REST API / wrangler workflows exclusion. The facets page states the alarm, depth, and name-length limits. examples/queues exports both fetch and queue from one script. Behaviour: on Azure the R2 metadata name becomes celld_r2 (#209). |
| v0.6.0 | 2026·09·26 | Full stop under fleet durability (CLT2 log tail); rolling under bucket | First beta. Each facet gets its own SQLite file and replication stream, and a facet class can come from ctx.exports; facets written by v0.5.1 migrate on first open. Ed25519 (also NODE-ED25519) and X25519 in Web Crypto. ctx.exports holds default and each entrypoint. Headers accepts values above U+00FF and decodes response values as UTF-8. The WebSocket output gate holds each frame only for its own proof, and a close is wasClean: true whenever the peer sent a close frame. R2 keeps empty key segments and percent-encodes special characters. Behaviour: a facet write no longer commits atomically with a root transaction; a D1 TEXT value that is not valid UTF-8 decodes to U+FFFD instead of failing; WorkerCode requires compatibilityDate, a wasm module entry must be { wasm: bytes }, and a relative import in a module subdirectory resolves from the importing module's name; every export of the main module must be a handler object or a class; an R2 key v0.5.1 wrote as photos/ stays at photos. |
Sources
This chapter draws on: celld: documentation at v0.6.0 (9 entries) · celld: release notes (5 entries) · Cloudflare documentation (4 entries). The full entries are in the Bibliography.