Skip to content

Burrow v0.1.2

Choose a tag to compare

@github-actions github-actions released this 09 Oct 16:40
bc6b77e

Burrow v0.1.2

This release makes the global MFA policy configurable, simplifies login/logout
presentation and improves password validation feedback. Linux amd64 and arm64
containers and standalone binaries remain supported.

Changes

  • security.mfa_enabled in YAML and BURROW_MFA_ENABLED in the environment
    enable or disable TOTP for every account, including Administrator. Both
    defaults are false; manually enable MFA when it is required.
  • Disabling MFA preserves existing encrypted bindings. Temporary passwords
    still require a change. Re-enabling MFA rejects password-only sessions and
    requires login with authenticator setup or verification. OIDC amr reports
    the authentication actually completed.
  • The login brand no longer ends with a slash. The signed-in logout button
    revokes the Burrow session immediately and returns to login. Application-initiated
    OIDC logout retains its confirmation and redirect checks.
  • User creation explains password-policy failures and validates the backend's
    12–256 UTF-8 byte limit before submission. Password reset and change use the
    same validation, with English and Simplified Chinese messages.
  • Updated product screenshots from the maintainer's local browser acceptance,
    plus Grafana and Nightingale application icon examples.
  • GHCR and Docker Hub publish unified multi-platform tags from tested images
    by digest, without architecture-suffixed tags.

Install

Docker selects the appropriate Linux architecture from either image:

ghcr.io/arkgravity/burrow:v0.1.2
docker.io/logic3579/burrow:v0.1.2

The six attachments are:

  • burrow_v0.1.2_linux_amd64.tar.gz
  • burrow_v0.1.2_linux_arm64.tar.gz
  • burrow_v0.1.2_deploy.tar.gz
  • INSTALL.md
  • IMAGES.txt
  • SHA256SUMS

Both binaries embed the frontend and require glibc 2.36 or newer, such as
Debian 12. Containers are the recommended deployment method. Follow the attached
installation guide and verify the attachment checksums.

Upgrade and MFA policy

Back up the database, original master key and configuration before upgrading.
Select the v0.1.2 image or binary, run migration and seed, then start the server.
There is no new database migration; schema v5, identities, passwords, grants,
applications and signing keys are preserved.

v0.1.0 and v0.1.1 required MFA. v0.1.2 defaults to disabling it. To preserve
mandatory MFA when upgrading, set BURROW_MFA_ENABLED=true in your Compose
.env or exported service environment before starting the new version.
For native commands, you can instead set the selected YAML configuration:

security:
  mfa_enabled: true

Native commands do not load .env. Environment values override YAML. Restart
the service or recreate the Compose application container after changing this
setting. Existing bindings are retained whichever policy you select.

Verification scope

The release workflow requires successful full CI for the exact main commit.
Both native release jobs must pass the packaged-binary SQLite/MFA/OIDC browser
suite and production PostgreSQL container startup checks before a draft is
published. See Actions for the results of this version.

The maintainer reported successful local browser acceptance of administrator
application, role, group and user creation, followed by new-user login and the
application portal. That checkpoint is separate from automated CI, downstream
SSO login, production validation and OpenID Foundation certification.

中文说明

v0.1.2 新增全局 MFA 开关,security.mfa_enabled 和 BURROW_MFA_ENABLED
默认均为 false,需要 TOTP 时必须手动开启,开启后作用于所有账户(含管理员)。
关闭时保留已有绑定,临时密码仍需修改;重新开启后,密码登录产生的会话需重新登录
并完成绑定或验证。OIDC amr 按实际完成的认证返回。

登录页品牌后的斜杠已移除,站内退出改为单击立即注销;应用发起的 OIDC 退出仍保留
确认及重定向校验。创建用户、重置密码和改密表单统一校验 12–256 UTF-8 字节长度,
密码策略失败时给出明确的中英文提示。README 更新本地人工验收截图,SSO 示例补充
Grafana 和 Nightingale 的图标 URL。

继续提供 Linux amd64/arm64 二进制和统一双架构镜像标签,不发布架构后缀标签。
附件包含两个二进制包、共享部署包、安装指南、镜像摘要和校验文件。

从强制 MFA 的 v0.1.0/v0.1.1 升级时,若要继续要求 MFA,务必在启动新版前
显式设置 BURROW_MFA_ENABLED=true,或在所选 YAML 中设置 security.mfa_enabled: true。

升级前备份数据库、原主密钥和配置,依次执行迁移、seed、启动;schema v5 保持不变。
用户报告的本地管理功能及新用户登录/门户验收,与自动化检查、下游应用 SSO、
生产部署和官方 OIDC 认证分别记录。