Self-healing clusters and Terraform plans that stay quiet
A cluster now survives losing a node, with its state replicated everywhere and instances relaunching on their own. Instances take up to eight GPUs, object storage got a sturdier shard layout, and Terraform plans and IAM responses came into line with AWS.
Terraform and OpenTofu: applies that succeed
-
The
terraform-aws-modules/eksmodule applies clean and re-plans with no changes. -
ebs_block_deviceand theaws_vpcdata source work, and parallel applies no longer lose load balancer targets or tags. - Load balancer attributes are accepted in full, and a retried apply no longer duplicates the resource.
Terraform and OpenTofu: plans that report no changes
- A no-op plan no longer destroys and recreates a working instance.
-
Permanent diffs are cleared on
user_data,enclave_options, security group rule tags and ECSavailability_zone_rebalancing. -
ECR and ECS return the fields you set at create time, and
most_recentpicks the newest AMI.
Identity (IAM and STS): AWS conformance
- Requests and responses are tested against AWS's published API models for ten services.
- IAM responses carry the fields AWS returns for each action, with policy documents URL-encoded as AWS does.
-
Managed policy versions, capped at five as in AWS, so editing an
aws_iam_policyupdates it in place. - Trust policies evaluate conditions, and STS rejects session policies and tags instead of ignoring them.
Reliability
- Instances on a failed node relaunch on a surviving one automatically.
- Cluster state is replicated to every node, so losing one no longer takes the cluster down.
- Spinifex deploys on Oracle Cloud Infrastructure (OCI), in beta.
GPU compute
-
Up to eight GPUs per instance, with
g5.48xlargeandp4d.24xlargematching AWS's GPU counts. -
A new
gpu.<count>x<vcpu>cfamily for smaller edge hosts, such asgpu.8x4c.
Storage (S3)
-
Bucket versioning, user metadata,
CopyObject,UploadPartCopyand batchDeleteObjectsare available. - Keys with special characters are listed by their decoded name, and ETags are derived from content.
Object storage engine (Predastore)
- Shards spread evenly across nodes, so losing one no longer degrades the whole keyspace.
-
Streaming shard reads and writes with hedged repair, and ranged
GETs read only the stripes they touch. - Predastore runs standalone with systemd integration.
Networking and security
-
Policy evaluation fails closed, and
sts:AssumeRoleis gated on the caller's identity policy. - Auto-assigned public IPs are released on stop and reassigned on start, as in AWS.
- Outbound SMTP to public destinations is blocked by default, matching AWS.