Release Notes
0.4.x
| Version | Date |
|---|---|
0.4.0 |
2026-10-03 |
0.4.0
Improvements
-
getStatusreportsinactiveReason(manual,auto-off,disabled,test-mode,launch-mode; absent while active) and the Dev UI status bar shows the reason next toInactive, so a silent dashboard is no longer a mystery. -
AssaultObservergainsonConfigChange(AssaultConfigChange): observers see every configuration change, once per published change (a wholeapplyConfigincluded), with the configuration before and after it as read-only snapshots, in dev and test mode — enough to record the exact attack an application went through and replay it after a fix (#71). The method has a default no-op, so existing observers are unaffected. -
The Chaos Dashboard and History pages show an animated goblin in their bottom-right corner while chaos is active, and hide it when chaos is off (a still image for reduced motion).
-
Saved scenarios: save the current assault configuration as a named scenario under
.goblin/scenarios/, then load or delete it from the new Scenarios section of the Dev UI, through JSON-RPC (listScenarios,saveScenario,loadScenario,deleteScenario) or Dev MCP, wherelistScenariosis enabled by default and the three others are opt-in (#49). -
Agent playbook and resilience inventory: two Dev MCP resources, enabled by default, for an AI agent driving Goblin (#72).
quarkus-goblin_agentPlaybookis the playbook shipped with the extension: safety rules, what each layer means for MicroProfile Fault Tolerance, how to observe an experiment including a circuit breaker’s state through theft_*metrics, the experiment loop and the report; the Agent playbook page includes the same text, with aRESILIENCE.mdtemplate for the application’s own promises.quarkus-goblin_resilienceInventorylists, indexed at build time, every application method guarded by@Timeout,@Retry,@CircuitBreaker,@Fallback,@Bulkheador@RateLimit, with the effective parameters and the Goblin layers that reach it inside Fault Tolerance. The post-assault assertions (#50) were dropped in favour of this: Goblin provides the signals, the agent or the human concludes.
Bug Fixes
-
Deactivating chaos from the Dev UI (master toggle,
Disable allkill switch,setActive(false)through JSON-RPC) is no longer undone by the next dev-mode live reload: a deactivation now survives the file save that follows it, and an explicit activation survives the next reload too. Like the auto-off, the decision belongs to the dev session and is kept in a JVM-wide system property, deliberately outside.goblin-state.json, so a new process still takes the active flag fromquarkus.goblin.enabled. A test application started by continuous testing keeps its own decision. -
The HTTP status and dependency degradation assaults no longer answer a plain-text body declared as
application/json: the abort now carries an explicit content type matching the resource contract —application/jsonwith a parseable{"message":"…","code":<status>}body on JSON resources (a JSON@Produces, or no@Producesand a POJO, collection or map return type),text/plainwith the raw message otherwise (#69). Clients switching on the 503 content type may observetext/plainwhere they previously (incorrectly) sawapplication/json.
0.3.x
| Version | Date |
|---|---|
0.3.1 |
2026-09-28 |
0.3.0 |
2026-09-25 |
0.3.1
Improvements
-
The auto-off is held by the engine instead of the browser: chaos switches itself off at the deadline even when the Dev UI is closed, and a pending auto-off survives a dev-mode live reload. The delay is bounded to 24 hours, and deactivating chaos (master toggle or kill switch) cancels it, while a configuration reset leaves it pending.
-
New JSON-RPC methods
startAutoOff(minutes)andcancelAutoOff();getStatusexposes the time left inautoOffRemainingMs. -
A profile other than
NONEalso turns the response body assault off and resets the messages of the assaults it enables (INTERMITTENTanswersInternal Server Error (Goblin chaos)). The client-side assaults and the armed layers stay untouched.
Bug Fixes
-
An application producing an anonymous, local or non-static inner class (for example a
MeterFilterreturned by a producer method) no longer fails to start: the SERVICE layer only weaves its binding onto classes that can be CDI beans, and never onto constructors. -
DATABASEexceptions no longer corrupt the Agroal pool: the fault now fires before a connection is checked out, instead of from the acquire interceptor, which left the connection enlisted in the transaction while back in the pool ("Closing connection in incorrect state CHECKED_IN", ever-growingagroal_active_count). -
A request whose entry point sits in an
exclude-packagespackage is no longer assaulted on theSERVICE,DATABASE,MESSAGINGorHTTP_OUTlayers: the layer used to be resolved before the targeting rules were checked. -
Once the auto-off has fired, chaos stays off across live reloads until it is switched on again, and clicking the master toggle just as the deadline elapses no longer switches chaos back on.
-
A test application started by continuous testing keeps its own auto-off instead of sharing the one of the dev-mode application.
-
The Dev UI dashboard survives transport errors and out-of-order status replies, and always reports an auto-disable.
0.3.0
New Features
-
Multi-layer chaos assaults with per-request layer resolution (
DATABASE→MESSAGING→SERVICE→HTTP_IN,HTTP_OUTrolled per outgoing call), one check-box per layer in the Dev UI, and service-layer assaults on business beans via a CDI interceptor that runs inside the Fault Tolerance machinery — so@Retry,@Fallback,@Timeoutand@CircuitBreakerare exercised for real. TheDATABASElayer fails or delays JDBC connection acquisition through an Agroal pool interceptor (JDBC, Hibernate ORM, Panache); theMESSAGINGlayer faults@Incomingconsumers outside Fault Tolerance, each consumed message resolving its own layer (#54). -
The
sourceof each recorded assault, already tagged in the metrics and traces since 0.2.1 (server,rest-client,webclient), gains theservice,databaseandmessagingvalues, and is now also exposed in the history, the counters and the Markdown report; the Dev UI status bar counts the assaults per source. -
The Markdown report describes the armed chaos layers and the client-side assaults.
Breaking changes
-
Chaos no longer activates in test mode by default: set
quarkus.goblin.test.enabled=trueto assault your@QuarkusTestsuite (or callAssaultEngine.setActive(true)from a test). Adding the extension therefore never slows down nor breaks an existing test suite. -
The
quarkus-goblin-metricsmodule now depends on the Micrometer API only (quarkus-micrometer): add the registry of your choice, e.g.quarkus-micrometer-registry-prometheus, to expose/q/metrics. -
Java API: the targeting rules moved from
GoblinConfig.TargetConfigtoGoblinTargetingConfig(the property names are unchanged), andAssaultEngine.setStaticConfigis removed.
Improvements
-
Every configuration key except the
quarkus.goblin.target.include-packages/exclude-packages/exclude-annotationstargeting rules is now read at runtime and can be overridden when the application starts. The targeting rules stay fixed at build time and are applied by a single implementation shared by every layer. -
No chaos wiring in production builds: the service and messaging interceptor bindings, the database hook and the Dev UI JSON-RPC are only registered in dev and test.
-
Configuration changes (profile switch, reset, import) are published atomically, and each assault hook reads one consistent snapshot per request. A Dev UI import is staged and applied at once: a rejected payload changes nothing, and values of the wrong type are converted or skipped with a warning.
-
The assault history records the latency actually endured, including a delay cut short by
@Timeout, on every layer. -
A blocking latency is never applied on a Vert.x event-loop thread (the WebClient latency uses a timer), and latency values are bounded to 0-300000 ms.
-
The Dev UI keeps its toggles and forms in sync with the server (changes made from another tab or a JSON-RPC client appear within 2 seconds) and validates response header names before saving.
-
The Dev UI state file is written as structured JSON; files written by earlier versions are still read.
-
Quarkus 3.38 and every later version are accepted by the build (including the ecosystem CI snapshot).
Bug Fixes
-
A decision left on a worker thread by a failed HTTP request no longer leaks into a later message consumer or scheduled job.
-
The Dev UI "client" counter counted nothing: assaults are now counted per source.
-
Saving response header rules with an invalid name no longer erases every rule.
-
A corrupted or legacy
.goblin-state.jsonno longer prevents the application from starting.
0.2.x
| Version | Date |
|---|---|
0.2.1 |
2026-09-24 |
0.2.0 |
2026-09-21 |
0.2.1
New Features
-
Assault metrics and latency histograms via Micrometer / Prometheus, in the optional
quarkus-goblin-metricsmodule (#51). -
Assault tracing via OpenTelemetry — one
goblin.assaultspan per assault withgoblin.assault.*attributes, linked to the parent request span, in the optionalquarkus-goblin-opentelemetrymodule (#47).
0.2.0
New Features
-
Predefined assault profiles (#35).
-
Turn the Assault History into a chaos testing console (#37).
-
Client-side assaults for outgoing REST Client calls (#38).
-
Client-side assaults for outgoing Vert.x WebClient calls via
GoblinWebClient.enable(…)(#31). -
Response body injection assault (#40).
-
Response header injection assault (#42).
Improvements
-
Chaos Dashboard overhaul with live controls and server-driven quick picks (#41).
Bug Fixes
-
The enabled flag now always comes from the property, never from persisted state (#39).
0.0.x
| Version | Date |
|---|---|
0.0.2 |
2026-09-01 |
0.0.1 |
2026-08-28 |
0.0.1
New Features
-
Server-side assaults: latency, exception, HTTP status and dependency degradation (#1).