Charm Tech pulse 2026#20

In Charm Tech this pulse we’ve made a push on Quality of Life improvements across the various products we maintain. We’ve released updates to Hyrum, Pebble and Ops, with Ops requiring special attention due to a security fix. Please update to 3.8.3 or 3.9.0 to prevent leaking secrets into tracing span data.

Ops

  • Released 3.8.3, which is a security fix to stop Ops sending the content of Juju secrets in tracing span data. Please update as soon as possible.
  • Released 3.9.0 and 2.23.6, which are both collections of assorted bug fixes (3.9.0 includes the security fix from 3.8.3).
  • Enforced relation databag read permissions on all access paths (#2738), and made a relation that has gone away raise RelationNotFoundError rather than “permission denied” (#2748).
  • Kept sensitive data out of traces and hook command errors (#2782). Started work on avoiding exponential backtracking in the ops.testing storage name check (#2800).
  • Added an exception note when raising ModelError (#2786).
  • Let charms and libraries set on without a type: ignore (#2775).
  • In ops.testing: treated an _Abort(0) from the charm’s __init__ as success (#2780), and recorded trace data in every run with opentelemetry-sdk 1.45 (#2787).
  • Worked on making ops.hookcmds return all the data that the hook commands output (#2805).

Charming

  • Added a Workshop dev environment across Charm Tech repos: Hyrum (#136) and pytest-jubilant (#123) merged, with Ops (#2801), Charmlint (#434), Jubilant (#432) and charm-ubuntu (#125) in progress.
  • Added secrets handling to Charmcraft’s Kubernetes and machine init profiles (#2814).
  • Worked on adding Jubilant logging of how long wait took when it succeeds, fails, or times out (#419)
  • Worked on adding an ssh_key argument to Juju.ssh and Juju.scp for Juju 4.1 support (#430).
  • Drafted defaulting pytest-jubilant’s --juju-dump-logs to the log_file directory (#124).
  • Released Hyrum 1.0.0 (#169), including some additional improvements prior to that.
  • Finalised upgrading jhack scenario snapshot with bug, linting and formatting fixes (#252).
  • Worked on adding a GitHub configuration to the kubernetes and machine Charmcraft profiles (#2921).

Charmlibs

  • Worked on testing Charmlibs with Juju 4 (#707)
  • Added provider and requirer charms for interface library integration tests (#698).
  • Wrote OP093, which specifies how charm library testing packages can ship charm-shaped stand-ins for use with multiple-charm state-transition testing.

Pebble

  • Released Pebble v1.33.0 and v1.33.0-fips.
  • Fixed the setup of termios to pass input flags correctly (#1115).
  • Reject invalid metric types for Pebble’s prometheus scrape end point (#1118).
  • Fixed a panic in tlsstate (#1120).
  • Progress: Tracing self-telemetry for Pebble (#1103 #1114).
  • Progress: OP090 - Pebble TLS Trust Context spec accepted in principle.
  • Progress: OP092 - Pebble scheduled service start spec accepted in principle.
  • Drafting new specification OP095 - Pebble service starting check.

Documentation