Repository navigation
Vectory 0.2.1 is a self-hosted control plane for Vector.
Install
Use the guided quickstart. Download vectory-0.2.1-server-linux-amd64.tar.gz, extract it, and run ./start.sh on a Linux x86-64 Docker host. The kit verifies release signatures, pulls immutable images from GHCR, and guides first administrator setup. No source compilation is needed.
The native Linux x86-64 server kit is vectory-0.2.1-server-native-linux-amd64.tar.gz. It installs the same prebuilt server, dashboard and agents with an isolated systemd validator, without Docker or a compiler. Use the native installation guide for the supported host requirements and signature-verifying one-command installer. vectory-0.2.1-native-runtime-source.tar.gz separately retains the exact corresponding Debian runtime sources; ordinary installation does not need that optional source archive. The public native installer and exact runtime/source provenance are included as signed release assets.
The local evaluation kit is separate. Managed devices need an existing supported Vector installation; Add device provides the platform download and setup command.
Verify
SHA256SUMS.sigstore.json authenticates SHA256SUMS using GitHub OIDC and Sigstore. IMAGE-DIGESTS.env contains the immutable server and validator references. Both images carry Cosign signatures. Verify the certificate identity https://github.com/416rehman/Vectory/.github/workflows/release.yml@refs/tags/v0.2.1 and issuer https://token.actions.githubusercontent.com. The starter does this through a pinned Cosign container, with no host Cosign installation.
Built-in agent-update catalog signatures use a separate operator key and are not enabled by this release signature. Windows Authenticode and Apple Developer ID/notarization are not present; operating systems may show trust prompts even though the download has a verified Sigstore signature.
Validation and operational limits
Publication requires all application, native service, package, isolated validator, starter TLS/bootstrap/restart, provenance and signature gates on this tag. File download or writing configuration is not verified device activation.
Container scans reject every critical record and every high record with an available fix. Unfixed findings remain disclosed in the three *-image-vulnerabilities.json files and summarized in RELEASE.json. Counts are package records, not proof of exploitability or safety. Use least privilege, backups, restricted dashboard access and your deployment review process.
This release supports a Linux x86-64 Docker Compose manager, Linux amd64/arm64 agents, macOS Intel/Apple Silicon agent downloads and Windows amd64 agents. Consult the tested compatibility matrix before production rollout. Native tests cannot cover every OS or workload.
Source: ca41ed8e38b2def9ab53d1a99e48388eaaece327. CI receipt. Vectory is independent of Datadog and the Vector project.