
Arc 26.09.2 is a patch release focused on the parts of a database that matter after the launch-day benchmarks: predictable query latency, safe failover, honest failure signals, and storage behavior you can trust.
The headline result is an experimental file-level pruning path for high-frequency ingest. On a live workload flushing once per second, the same five-minute dashboard query fell from more than 340ms to 29ms as the current hour filled: 11.7x faster, while resident memory dropped from roughly 450MB to 90MB. This release also makes clustered deployments substantially safer, adds a write-specific readiness endpoint, closes several query and RBAC gaps, and replaces the Helm chart's bundled MinIO with SeaweedFS.
This is a patch release, but clustered Enterprise and bundled-object-store users have upgrade steps to read before deploying. Everyone running with the write-ahead log enabled should prioritize the update.
Live queries no longer slow down as the hour fills
Arc already prunes queries to the hour directories they can touch. High-frequency workloads exposed the next layer of the problem: the current, not-yet-compacted hour can accumulate thousands of small Parquet files, and a recent-window dashboard query still had to list and inspect every one.
26.09.2 introduces experimental file-level time pruning for the live hour. Arc uses the flush timestamp in each filename to discard files that cannot contain rows at or after the query's lower bound. On a 7,893-file live hour, the measured five-minute query improved from 340ms to 29ms; a 60-second window completed in 12ms. Avoiding those unnecessary footer reads also reduced memory use by about 80% on the same workload.
The feature is local-storage only and disabled by default while we continue its soak:
[query]
file_time_pruning = true
file_time_pruning_margin_seconds = 300The margin protects against writer clock skew. Backfilled data, unrecognized filenames, and compacted outputs stay in the scan, and Arc falls back to the unpruned path rather than risk a false empty result. We plan to make this stable and enabled by default in 27.01.1 if the soak and field feedback continue to hold.
A related fix restores partition pruning for DuckDB's native interval spelling. Queries using INTERVAL 300 SECOND previously scanned every partition, while INTERVAL '300 seconds' pruned correctly. Both forms now take the fast path.
Clusters get a safer operational baseline
This release contains a broad cluster reliability pass. The Helm chart now defaults to three writers, the minimum useful failover pool: one active writer and two candidates on local storage, or three ingest-capable writers on shared storage. Existing installs keep their configured count, and single-node deployments can still explicitly use one.
Load balancers also get a precise target with GET /ready/write. The existing /ready endpoint still answers whether a node is healthy and remains the right Kubernetes probe and query-pool check. /ready/write answers whether traffic should send writes to that node: every healthy writer in shared-storage mode, only the elected primary in local-storage mode, and never a reader or compactor. Writes sent elsewhere are still proxied, but the extra hop is now avoidable.
The underlying coordination work is just as important. 26.09.2 fixes cases where a reader or compactor could win Raft leadership, retention and continuous queries could run on every writer or on none of them, two nodes could compact the same data, WAL replication could attach to the wrong writer or wedge after a restart, and a restored node with an empty disk could fail to recover its own files. Cluster handshakes now authenticate every field, add replay protection, and return authenticated responses.
Because that handshake wire format changed, clustered Enterprise deployments require a coordinated restart: stop every node, upgrade all binaries, then restart the cluster. Do not use a rolling restart for this release.
SeaweedFS replaces bundled MinIO
MinIO retired its open-source container distribution, so Arc's bundled shared-storage tier now uses SeaweedFS. This affects the Enterprise Helm chart and the oss-s3 and enterprise-shared Compose stacks. Arc itself still speaks S3, and existing external MinIO deployments remain supported without changes.
For Helm users, this is a breaking values rename: minio: becomes seaweedfs:, the credential keys change, and the in-cluster service moves to <release>-seaweedfs:8333. The chart rejects stale minio.* values so an upgrade cannot silently deploy the wrong configuration.
Most importantly, data on an existing bundled-MinIO volume is not migrated automatically. SeaweedFS cannot read MinIO's on-disk layout. Sync the bucket to the new store before switching, or keep the existing MinIO deployment as an external S3-compatible backend. The same warning applies to Compose volumes when the data matters.
Query results and storage failures become harder to misread
Several fixes in 26.09.2 are about returning a clear failure instead of a plausible but incomplete success:
- JSON query responses now set
truncated: truewith a reason when streaming stops early. Truncated Arrow IPC streams now fail decoding instead of looking like complete results. - Enterprise query governance now covers every user-SQL endpoint, and capped responses identify that they may be incomplete.
- Every measurement now carries a zero-row schema anchor, so selecting a field absent from the queried time range returns
NULLinstead of a binder error. Dashboards no longer work or break depending on their zoom level. - A panic in any streaming response writer is contained to the request rather than taking down the server, and cleanup returns the DuckDB connection to the pool.
- Scheduled compaction can exclude selected databases, and
compaction.cycle_timeoutputs a deadline around both scheduled and manual cycles.
Two S3-prefix bugs are also fixed. Partition pruning had silently fallen back to full scans, and retention had reported successful runs while deleting nothing. Time-bounded queries should become faster immediately after upgrading. Retention requires more care: its first working cycle may delete the entire expired backlog accumulated since 26.03.2. Run each affected policy in dry-run mode and verify its window before upgrading.
WAL safety and security hardening
If wal.enabled = true, update. Arc's graceful shutdown sequence could purge the WAL before buffers were flushed, and buffer flush failures were logged without being returned. A routine Kubernetes drain during an object-store outage could therefore lose acknowledged data on a clean SIGTERM. The shutdown order is now correct, the WAL is purged only after every buffer flush succeeds, and an incomplete flush exits non-zero while retaining the WAL for replay.
The security work includes read-SQL validator hardening for quoted constructs, case-correct RBAC checks for table references, rejection of indirect PREPARE and EXECUTE statements, immediate enforcement of API-token expiry even on cache hits, authenticated cluster handshakes, and updated Apache Thrift and gRPC dependencies. RBAC-enabled multi-tenant deployments should prioritize this release. Thank you to @rexpository for the responsible reports behind several of these fixes.
Before you upgrade
- Clustered Enterprise: perform a coordinated restart, not a rolling one.
- Bundled MinIO: migrate the bucket or configure the existing deployment as external S3 before switching the chart or Compose stack to SeaweedFS.
- S3 with
storage.s3_prefix: dry-run retention policies first; the first corrected run can remove a large expired backlog. - WAL-enabled deployments: prioritize the update. If shutdown cannot flush cleanly, Arc now retains the WAL and exits with code 1 so the failure is visible and recoverable.
- Check
cluster.role,cluster.raft_bootstrap, edge-sync spoke IDs, andstorage.s3_prefixagainst the stricter validation described in the full notes.
Thank you to the Arc community
This release is better because people outside our team read the code, reproduced difficult failures, reported security issues responsibly, and sent fixes. Thank you to @Thundercloud12, @pujitha24, @efegokdemir, @xe-nvdk, @TayfurYldz, @alexeymoskalev-devops, @lecodev-26, @MrBeldum, @be-student, @atirna, @bferanmi806-sketch, @mah1104ahm, @copacabanaservice01, and @rexpository.
And thank you to everyone who opened an issue, tested a pre-release build, reviewed a pull request, or shared what Arc was doing in production. That feedback is what turns a long fix list into a safer database.
How to update
# Docker Hub
docker pull basekicklabs/arc:26.09.2
# or GitHub Container Registry
docker pull ghcr.io/basekick-labs/arc:26.09.2On macOS, run brew upgrade arc. For binary and package installations, download 26.09.2 from the GitHub releases page. For Kubernetes:
helm install arc https://github.com/basekick-labs/arc/releases/download/v26.09.2/arc-26.09.2.tgzThe full 26.09.2 release notes contain the complete fix list, configuration reference, and detailed upgrade guidance.
Get started:
Questions? Discord or GitHub Issues.