Tiyi v3.8.0

Tiyi v3.7.0 release notes

Released 2026-08-31. v3.7.0 is the adaptive-protection and trust-topology release.

Highlights

Required clean-state transition

v3.7.0 cannot open state created by v3.6.0 or earlier releases. This release does not provide an in-place database migration for the replaced site, rate-limit, trust, and observation contracts.

Before updating, stop writes and archive the complete installation: state directory, configuration, unit, binary, external KEK/license/certificates, and reviewed declarative source. Then use the documented uninstall --purge workflow, let the retained signed updater install v3.7.0, install a fresh service, recreate reviewed resources, and re-enroll every remote Agent. Do not import the old database, Agent identity, spool, or bundle cache into v3.7.0.

Follow Upgrade and migration for exact commands and the rollback boundary.

After installation

  1. Confirm tiyi --version reports v3.7.0, run tiyi system health, and verify the local node has an active bundle.
  2. Activate a Country database before enabling Country Access. Provider IP subscriptions start paused and empty; inspect and explicitly resume only the feeds you intend to trust or enforce.
  3. Leave WAF overload at Continue full inspection until an availability owner chooses reject or CRS-bypass behavior and verifies it in Logs → Enforcement.
  4. Enable bot protection only after the site is HTTPS-only. Test legitimate browsers, unsupported clients, health checks, and required login callbacks.
  5. Rebuild rate-limit rows and response profiles from reviewed intent; do not recreate legacy rows mechanically.

Downloads, SHA256SUMS, its Ed25519 signature, and the release manifest are on the GitHub release and the Gitee mirror.