Skip to content

Releases: FrontAnalyticsInc/steward

Steward v0.1.3

Choose a tag to compare

@altonalexander altonalexander released this 19 Aug 00:38

macOS/arm64 support hardened with real-hardware fixes on top of the v0.1.2 base:

  • Docker Desktop Rosetta-failure guidance for Apple Silicon
  • Fixed installs hanging on tailscale
  • Fixed compose project naming
  • Fixed .env heredoc backtick escaping
  • Renderer runs as the uid that owns its profile directory
  • First-run setup page instead of an empty console
  • Customization surface for local agents (agents_local)
  • Removed the browser-linkedin service

install.sh and hermes-update.sh now default to this version.

Steward v0.1.2

Choose a tag to compare

@altonalexander altonalexander released this 18 Aug 05:32

v0.1.0 and v0.1.1 cannot be installed. Use this one.

curl -fsSL https://raw.githubusercontent.com/FrontAnalyticsInc/steward/main/install.sh | bash

Upstream rewrote the file this project patches, and the superseded image stopped being served — so the base the patch was derived from is no longer pullable at all. The gateway patch is re-derived onto the current upstream by three-way merge, and the base image is pinned to a digest that exists.

Also: the installer publishes the console to your tailnet itself and prints the URL, so the last step is opening https://<your-node>.ts.net/ — no port, real HTTPS certificate.

The console still has no authentication of its own. On a tailnet, tailnet membership is the whole of its access control — restrict your ACLs and never enable Funnel on this node.

Steward v0.1.1

Choose a tag to compare

@altonalexander altonalexander released this 18 Aug 05:06

Fixes an install that could not complete. v0.1.0 is not installable — it builds the gateway from a floating upstream tag that has since moved, and the Dockerfile's checksum guard correctly stops the build.

curl -fsSL https://raw.githubusercontent.com/FrontAnalyticsInc/steward/main/install.sh | bash

Not sudo bash. Ubuntu 22.04/24.04 x86_64, 8 GB RAM, 40 GB free where Docker writes. Budget 20–40 minutes for the build.

Everything here came from installing v0.1.0 on a clean box:

  • Upstream gateway image pinned by digest. :latest moved and broke every fresh install; a machine with the layer cached kept building green, which is how it got past CI.
  • The stack file is rendered interpolated, so compose can read it back. Un-interpolated, every bind mount rendered as an undeclared named volume and the whole project was rejected at up.
  • Compose v2 is installed, not just required.
  • The docker group no longer ends the install — it re-enters with the group applied.
  • The sudo password is read from the terminal, not from the script the pipe is feeding it.
  • RAM is reported without losing a gigabyte to truncation. An 8 GB box said 7 and was warned; a 6 GB box said 5 and was refused.
  • No Anthropic key no longer stops the install. It builds and starts so the console is reachable, then says plainly that nothing can call a model until you add one.
  • The install ends by telling you how to open the console, including Tailscale setup for this machine and the one you browse from.

The console on :9120 still has no authentication. Leave DASHBOARD_BIND at 127.0.0.1 and reach it over a tailnet or an SSH tunnel.

Steward v0.1.0

Choose a tag to compare

@altonalexander altonalexander released this 18 Aug 03:59

First release that installs.

curl -fsSL https://raw.githubusercontent.com/FrontAnalyticsInc/steward/main/install.sh | bash

Not sudo bash — the installer refuses to run as root.

Steward builds its images on your machine from this tag's source. Nothing is pulled from a private registry and no access token is needed. Budget 20–40 minutes, almost all of it the build; the browser image carries Playwright and Chromium.

Needs Ubuntu 22.04 or 24.04 on x86_64, 8 GB RAM (it refuses below 6), and 40 GB free where Docker writes. Not a laptop — Steward runs on a schedule and a sleeping machine misses it.

You will be asked for an Anthropic API key. It never leaves the box: it is written mode 0600 and read from there.

The console on :9120 has no authentication. The only thing protecting it is the loopback bind. Leave DASHBOARD_BIND at 127.0.0.1 and reach it over an SSH tunnel or a restricted tailnet — see the README.

Two workflows ship: summarize_note and intentional_failure_demo. They exist to be read and to give the smoke test something to run. Gmail, Calendar and Attio need Google Workspace domain-wide delegation from an admin in your own domain and are not part of a bare install.

Run the five-step smoke test in the README after installing.