Release

Announcing Toise 0.16.0 — holding up at fleet scale

Released 2026-09-01 · written up 2026-09-30

0.16.0 is about keeping existing promises at a larger scale. A scale campaign on a 10,000-host estate, surveys of the tools consuming Toise, and a rolling-upgrade check each pointed at something to improve. None of it changes the contract: one additive object on the read tools, and no data migration.

The incident window, in milliseconds

"What changed in the last hour" is the question an incident starts with. On a 10,000-host estate most events in that hour are heartbeats, and the change reads were paying to classify each one before dropping it. Each time-index entry now carries a one-byte tag, so a reader that excludes heartbeats can skip them without touching the primary record.

Measured on the same 311,750-entity estate, over a window of 380,000 heartbeats:

recent_changes   7,612 ms  ->  21 ms
graph_diff       7,562 ms  ->  17 ms

A window full of real changes still takes as long as the answer is large. Cost now follows the answer rather than the noise. Older entries carry no tag and are read as before until retention ages them out.

A benchmark gate now runs on every pull request touching Go, so these fast paths stay fast. Its thresholds are deliberately generous, so it only fires on real regressions.

Every answer states its scope

Tools that weigh several sources against each other need each source to say how much it covers and how fresh it is. Every MCP read answer now carries a graph block: entity and relation counts, the newest event time in the tenant's log, the oldest instant still answerable, and the as_of when the answer reads the past. It matters most for an empty answer, which can now say how much it is able to speak for.

Operator annotations, shared and durable

Annotations are now keyed on the identity fingerprint, which every replica computes identically, instead of on a local id. Existing rows move on first touch, writing before deleting, so an interruption never loses a note.

When log shipping is enabled, annotations also travel through the shared object store, in both directions. Replicas never talk to each other; they meet at the store. A single-node deployment simply gains a backup of its annotations. Deletions are written as tombstones so they travel too.

Three limits become configuration

Malformed values are refused at boot rather than guessed at.

Upgrading

Additive: one graph object on the read tools. No data migration: annotation rows move on first touch, and untagged time-index entries age out with retention.


Get it

go install github.com/toise-dev/toise/cmd/toise-server@v0.16.0

Binaries for linux and darwin (amd64 / arm64) are on the release, each with a checksum, and the container image is on GHCR. See the 0.16.0 docs and the changelog.