Repository navigation
v0.15.0 - Getting Lean
A maintenance release: everything brought up to date, the CLI tightened, and the stack made to rebuild itself from what's on disk. If a cluster is deleted and recreated, obol stack up now restores your models, RPCs, pricing, branding, agents and offers from your config directory.
Warning
This software is early alpha, you could lose what you put in. Please use caution when it comes to non-testnet assets. Back up before upgrading: obol stack export --file backup.tar.gz.
Install / Upgrade
# Fresh install
curl -fsSL https://stack.obol.org/v0.15.0 | bash
obol stack init && obol stack up
# Upgrade an existing stack (installs pinned tools, updates CRDs, then charts)
curl -fsSL https://stack.obol.org/v0.15.0 | bash
obol upgradeRelease Highlights
The stack rebuilds itself from your config
obol stack up, obol stack import and obol sell resume now share one ordered replay of recorded state: models, local networks, RPC upstreams, the eRPC overlay, x402 pricing, ERC-8004 identity, agent instances, Agent resources, storefront branding, apps, then sell offers. Each step is best-effort and the run ends with a summary. x402 pricing and ERC-8004 identity are now recorded, so they also survive a cluster recreation. Model API keys taken from your environment are recorded as env: references instead of plaintext. obol stack import now does the whole restore in one command, and obol stack purge offers an export first.
obol <tool> behaves like the tool
obol kubectl|helm|helmfile|k9s run the real binary directly: same flags, stdin, TTY, exit codes, signals and tab completion. They always target the stack (pass --kubeconfig to target something else), and commands that don't need a cluster, such as helm template or kubectl version --client, now work before obol stack up. Prefer plain kubectl? eval "$(obol env)" prints the exports; nothing is written to your ~/.kube/config.
obol manages its own toolchain
kubectl, helm, k3d, helmfile, k9s and helm-diff are pinned with per-platform checksums and installed automatically on stack init and stack up. obol update shows their status, and obol upgrade --tools-only updates them. This is groundwork for package-manager installs; Homebrew comes next.
Helm 4
obol now installs and drives Helm 4.3.0. Every release is synced with server-side apply, so the Kubernetes API server tracks who owns each field and obol's own writes no longer fight Helm's. Existing Helm 3 releases switch over on their next sync, with no action needed. A repeat obol stack up on an unchanged stack now restarts nothing, and the v0.14 → v0.15 upgrade path has been tested end to end.
Up to date
Go 1.27, k3s v1.35.9, Traefik 39, kube-prometheus-stack 91, eRPC 0.3.0, Hermes v2026.9.24, cloudflared 2026.10.0, refreshed Ethereum clients and Go modules. obol upgrade now applies chart CRDs server-side before syncing, since Helm never upgrades CRDs by itself.
Smaller wins
- Grouped
obol --help- generated from the command tree, with "did you mean" for typos and shell completion (obol completion bash|zsh|fish). - Dashboard links - commands that create something print a link to it in the dashboard. The browser opens only on the first
stack upand the first offer, never over SSH, in CI or in JSON mode, or with--no-open. obol agent new <name>- pins the cluster's top-ranked model when--modelis omitted.- Safer secrets - the Hermes dashboard password and the dashboard's auth secrets are now read from Kubernetes Secrets instead of appearing in Deployment specs.
- eRPC overlays - replacing or resetting an overlay no longer leaves the old upstreams live.
- Paid agent conversations - the verified payer wallet is injected into the agent's message.
- k3s backend -
stack downcleans up properly, andpurgeno longer removes a system-wide k3s it doesn't own. - Wallet-safe
agent delete- deleting an agent that holds a wallet now refuses until you pass--delete-wallet, and points you at the backup command first. - Paid streaming - a fix in the seller gateway stops long streamed agent responses from being cut off mid-stream (
unexpected EOF). - Dead tunnel tokens - if Cloudflare rejects the tunnel's connector token (tunnel deleted or token rotated in the dashboard),
stack upandtunnel statusnow say so and print theobol tunnel setupcommand to fix it, andtunnel statusexplains an HTTP 525.tunnel setup --hostnamenow moves the storefront page to the new hostname straight away. - Safe without a terminal - in scripts and CI, destructive commands (
app,sell,agentandtunnel delete) now fail and ask for--forceinstead of silently skipping or proceeding, and nothing waits on a prompt nobody can answer. - Upgrading from v0.14 keeps your
obol sell pricingsettings. - Security patches - updated storefront dependencies (next, postcss, sharp) and Go modules.
- Dashboard - front-end v0.1.29-rc0: renders before wallet code loads, has 404 and error pages, and includes accessibility and mobile fixes.
Breaking changes / Migration notes
- Flag renames:
obol stack export,obol agent wallet backupandobol openclaw wallet backuptake--file <path>(was--output, which is now only the global human/json switch).obol domain searchtakes the query as a positional argument.app list -vandsell info -vare replaced by the global--verbose.
- Passthrough:
obol kubectl …now targets the stack even ifKUBECONFIGis exported in your shell. Global obol flags before a tool name (obol -o json kubectl …) are an error.obol hermesonly reads--agentas the first argument, or fromOBOL_AGENT. - Helm 4:
obol helm …runs Helm 4, which has some flag changes from Helm 3 (for example,helm listno longer takes-a). Runobol upgrade --tools-onlyif you installed tools before this release. obol agent delete: needs--delete-walletfor agents that hold a wallet.- No terminal, no prompt: without a TTY (or with
OBOL_NONINTERACTIVE=true),obol app|sell|agent|tunnel deleteneed--force. They used to exit 0 without deleting (or, fortunnel delete, delete without asking). - Exit codes: unknown commands exit 2 (was 3).
- Removed:
obol sell inference --vm,--tee,--model-hashand--enclave-tag, together with Secure Enclave and TEE attestation. Stored offers that used them are skipped on resume, with a hint to recreate them.- The autoresearch skills, which are moving to the Obol skills plugin.
- Deprecated (removed in v0.16): OpenClaw (
obol openclaw …,--runtime openclaw),obol domain, andobol tunnel login/tunnel setup --management local. Move an OpenClaw wallet to Hermes withobol agent wallet backup --runtime openclaw <id> --file w.json, thenobol agent wallet restore --runtime hermes --input w.json --force. Back up the Hermes wallet first. - Existing clusters: the local-path provisioner moved to v0.0.37.
stack upandobol upgraderecreate the oldlocal-pathStorageClass automatically; existing volumes are unaffected.
Known issues
- On macOS, a new Hermes agent may restart once or twice on first start (
attempt to write a readonly database) before running normally. Agent data lives on a Docker Desktop shared folder; a native-volume layout is being designed. - The Hermes dashboard sidecar logs
API server rejected invalid API keyfor/health/detailedevery few seconds. This is an upstream Hermes issue, and it's harmless.
What's Changed
What's Changed
- chore(deps): Go 1.27, module and infra bumps, fix Renovate coverage by @OisinKyne in #832
- fix(cli): generated grouped help, did-you-mean, flag clash fixes by @OisinKyne in #833
- feat(cli): manage kubectl/helm/k3d/helmfile ourselves so brew install… by @OisinKyne in #834
- Update devimage mgmt by @OisinKyne in #838
- fix(upgrade): apply chart CRDs before helmfile sync by @OisinKyne in #839
- ci(images): don't rebuild x402 images on release tags by @OisinKyne in #840
- fix(network): reconcile eRPC overlay replacements by @OisinKyne in #841
- Updates to tighten claude access by @OisinKyne in #842
- chore(deps): update dependency kubernetes-sigs/gateway-api to v1.6.3 by @github-actions[bot] in #830
- chore(deps): update dependency offchainlabs/prysm to v7.2.1 by @github-actions[bot] in #825
- ci(images): publish storefront per commit and gate releases on it by @OisinKyne in #843
- Backup restore by @OisinKyne in #844
- feat(cli): one base URL, safe browser opening, dashboard links by @OisinKyne in #846
- chore: remove unreachable code and CONTEXT.md by @OisinKyne in #847
- feat(cli): native passthrough exec, stack-pinned kubeconfig, obol env by @OisinKyne in #849
- Updating purge restoration and artifacts by @OisinKyne in #848
- Updating purge restoration and artifacts by @OisinKyne in #850
- chore: remove TEE/enclave/--vm, godog BDD and autoresearch skills by @OisinKyne in #852
- Chore/deprecate openclaw by @OisinKyne in #851
- fix: keep hermes dashboard password in Secret, migrate local-path SC by @OisinKyne in #853
- docs(claude): describe dev- image rebuilds and the bring-up recipe by @OisinKyne in #854
- fix(stack): rebuild dev images per commit; refresh installed Hermes o… by @OisinKyne in #855
- fix(agent): server-side apply for agent update and replay by @OisinKyne in #856
- fix(stack): print the ready banner after the state replay by @OisinKyne in #857
- fix(sell): re-resolve stack-owned images when replaying offers by @OisinKyne in #858
- fix(agent): pin a default model on create; clearer CLI hints by @OisinKyne in #859
- ci(release): serialise runs per tag by @OisinKyne in #860
- fix(agent): refuse to delete an agent that holds a wallet by @OisinKyne in #861
- feat(tools): move to Helm 4.3.0 with server-side apply by @OisinKyne in #867
- fix(deps): patch storefront next/postcss/sharp and edwards25519 by @OisinKyne in #868
- fix(x402): enable full duplex in HandleProxy; deflake watcher/SSE tests by @OisinKyne in #869
- security(frontend): move auth secrets from Deployment env to a Secret by @OisinKyne in #870
- fix: helm list without -a on Helm 4; ignore nested node_modules in im… by @OisinKyne in #871
- fix: exclude storefront node_modules after the web/ re-include by @OisinKyne in #873
- fix(test): isolate TestPaths from host PATH kubectl by @aly-obol in #872
- fix: stop stack up restarting LiteLLM and the verifier every run by @OisinKyne in #875
- fix(worker): validate installer release parameter by @aly-obol in #874
- docs: install with curl -fsSL https://stack.obol.org/ | bash by @OisinKyne in #876
- fix: v0.14 upgrade findings from the rc4 test by @OisinKyne in #877
- fix: no silent no-ops or hangs when there's no terminal by @OisinKyne in #878
- fix(tunnel): point at tunnel setup when Cloudflare rejects the token by @OisinKyne in #879
Full Changelog: v0.14.0...v0.15.0
