Dagster 1.13.24 - gRPC SSL and Kubernetes Pipes


Dagster published 1.13.24 on 21 September 2026. Library packages in the same release are 0.29.24. The operator facing fix is --use-ssl: it was ignored on a gRPC code server reached through --grpc-port or --grpc-socket, so the channel stayed insecure.

The full release notes and downloads are on the GitHub release page.

Connecting with --grpc-port or --grpc-socket used to swallow --use-ssl. The client opened an insecure channel and did not say the flag was dropped. 1.13.24 honors it. A code server that terminates TLS now gets a TLS client. A plaintext listener will refuse a handshake that used to succeed. Check the listener before you roll hosts that pass --use-ssl by default.

dagster dev --use-legacy-code-server-behavior discarded --package-name and --autoload-defs-module-name when it started the webserver and the daemon. Those arguments now reach the child processes. A workspace that loaded without the package you named will load that package after the upgrade.

A project whose root module is not importable now raises an error that says the project package is likely not installed. The old failure was a bare ModuleNotFoundError, which reads like a missing import inside user code.

dagster-k8s changes Dagster Pipes when a run pod init container has already failed. The client waited until the wait timed out. The default is a day. The run now fails with the init container error.

A failing init no longer holds a worker slot for that full timeout. Pods that never reach a terminal state still wait. The notes do not rename the timeout. They only change the failed init path.

Alerts keyed on a run left in started for hours will see fewer hangs and more explicit failures. A board that counted day long Pipes timeouts should expect that series to drop on 1.13.24.

fetch_column_metadata() in dagster-dbt now emits column lineage for dbt snapshots on dbt 1.12 and later. On earlier dbt the same call no longer logs a warning and a traceback for snapshots. A snapshot on an older dbt stays without that lineage, and it stays quiet. Call fetch_column_metadata() on dbt 1.12 or later when snapshot column lineage is the point.

A DbtProject whose project_dir was a string rather than a Path raised AttributeError after the project was round tripped through Dagster metadata. String paths work now. build_schedule_from_dbt_selection already accepted tag values that are not strings at runtime, matching define_asset_job. The annotation failed type checking. It matches the runtime now, and it does not alter a launched run.

dagster-airflow stops writing every Airflow task log line twice into the compute logs on Airflow 2.9 and later. Each line is stored once. Versions before 2.9 are outside the fix.

A job with a @multi_asset set to can_subset=True failed to resolve when specs used different partition definitions and one unselected dependency had been turned into an external asset. The error was DagsterInvalidDefinitionError at definition load, so the subsetted job could not launch. @Terroface reported it. 1.13.24 resolves that graph.

A callable with a custom __signature__ had type hints read from __call__ instead. Resource parameters were treated as asset inputs, or dropped from the required resources on a sensor. The reader uses the custom signature now. Recheck a callable asset whose resource parameters showed up as inputs, or a sensor that dropped required resources.

dagster-cloud adds cross account service discovery on the ECS agent. When the Cloud Map namespace is in a different AWS account from the agent, the agent registers code server tasks in Cloud Map and reconciles them on service_discovery_reconcile_interval. The default is 300 seconds. Same account deployments are unchanged. Expect a reconcile lag of that interval. The notes do not list the IAM calls in the other account.

Docs added with the tag cover code backed and UI managed alert policies in Dagster+, owner scoped RBAC, and asset groups including nested groups. The asset selection syntax page now says wildcard matching is not limited to the key filter. That is a doc correction. Read old selections again. Asset health and other live data no longer stay stale after a failed refresh until a full page reload.

The notes do not remove a public method. Three behavior changes still move running systems.

--use-ssl with --grpc-port or --grpc-socket now opens a TLS channel. Confirm the code server presents a certificate. A client pointed at a plaintext port will fail the handshake. A client pointed at a TLS port was on an insecure channel before this tag.

Kubernetes Pipes runs with a failed init container fail the run instead of waiting out the default day. Paging that used the hang, or a timeout after a day, as the signal needs a look.

dagster dev --use-legacy-code-server-behavior forwards --package-name and --autoload-defs-module-name. A dev loop that only worked because those flags were dropped will load the package you named.