Releases: FrontAnalyticsInc/steward
Release list
Steward v0.1.3
macOS/arm64 support hardened with real-hardware fixes on top of the v0.1.2 base:
- Docker Desktop Rosetta-failure guidance for Apple Silicon
- Fixed installs hanging on tailscale
- Fixed compose project naming
- Fixed .env heredoc backtick escaping
- Renderer runs as the uid that owns its profile directory
- First-run setup page instead of an empty console
- Customization surface for local agents (agents_local)
- Removed the browser-linkedin service
install.sh and hermes-update.sh now default to this version.
Steward v0.1.2
v0.1.0 and v0.1.1 cannot be installed. Use this one.
curl -fsSL https://raw.githubusercontent.com/FrontAnalyticsInc/steward/main/install.sh | bashUpstream rewrote the file this project patches, and the superseded image stopped being served — so the base the patch was derived from is no longer pullable at all. The gateway patch is re-derived onto the current upstream by three-way merge, and the base image is pinned to a digest that exists.
Also: the installer publishes the console to your tailnet itself and prints the URL, so the last step is opening https://<your-node>.ts.net/ — no port, real HTTPS certificate.
The console still has no authentication of its own. On a tailnet, tailnet membership is the whole of its access control — restrict your ACLs and never enable Funnel on this node.
Steward v0.1.1
Fixes an install that could not complete. v0.1.0 is not installable — it builds the gateway from a floating upstream tag that has since moved, and the Dockerfile's checksum guard correctly stops the build.
curl -fsSL https://raw.githubusercontent.com/FrontAnalyticsInc/steward/main/install.sh | bashNot sudo bash. Ubuntu 22.04/24.04 x86_64, 8 GB RAM, 40 GB free where Docker writes. Budget 20–40 minutes for the build.
Everything here came from installing v0.1.0 on a clean box:
- Upstream gateway image pinned by digest.
:latestmoved and broke every fresh install; a machine with the layer cached kept building green, which is how it got past CI. - The stack file is rendered interpolated, so compose can read it back. Un-interpolated, every bind mount rendered as an undeclared named volume and the whole project was rejected at
up. - Compose v2 is installed, not just required.
- The docker group no longer ends the install — it re-enters with the group applied.
- The sudo password is read from the terminal, not from the script the pipe is feeding it.
- RAM is reported without losing a gigabyte to truncation. An 8 GB box said 7 and was warned; a 6 GB box said 5 and was refused.
- No Anthropic key no longer stops the install. It builds and starts so the console is reachable, then says plainly that nothing can call a model until you add one.
- The install ends by telling you how to open the console, including Tailscale setup for this machine and the one you browse from.
The console on :9120 still has no authentication. Leave DASHBOARD_BIND at 127.0.0.1 and reach it over a tailnet or an SSH tunnel.
Steward v0.1.0
First release that installs.
curl -fsSL https://raw.githubusercontent.com/FrontAnalyticsInc/steward/main/install.sh | bashNot sudo bash — the installer refuses to run as root.
Steward builds its images on your machine from this tag's source. Nothing is pulled from a private registry and no access token is needed. Budget 20–40 minutes, almost all of it the build; the browser image carries Playwright and Chromium.
Needs Ubuntu 22.04 or 24.04 on x86_64, 8 GB RAM (it refuses below 6), and 40 GB free where Docker writes. Not a laptop — Steward runs on a schedule and a sleeping machine misses it.
You will be asked for an Anthropic API key. It never leaves the box: it is written mode 0600 and read from there.
The console on :9120 has no authentication. The only thing protecting it is the loopback bind. Leave DASHBOARD_BIND at 127.0.0.1 and reach it over an SSH tunnel or a restricted tailnet — see the README.
Two workflows ship: summarize_note and intentional_failure_demo. They exist to be read and to give the smoke test something to run. Gmail, Calendar and Attio need Google Workspace domain-wide delegation from an admin in your own domain and are not part of a bare install.
Run the five-step smoke test in the README after installing.