Releases: PastureStack/server
Release list
PastureStack Server v1.6.492
Server v1.6.492 candidate
This candidate prepares to package Web Console 1.6.158 on the unchanged
Server v1.6.460 runtime base and Orchestration Engine v0.183.326.
The Web Console source is merged main commit
4c99e4803d594a6bc7c340aefc686d34e4ea0f87 from
Web Console PR #133.
Web Console main validation run 36634695941 passed. The official
web-console-1.6.158.tar.gz archive SHA-256 is
286833d3313c5bc04469a8fafd41bab7de1c4b60527f91aae9eef8a4016b17f6. The published release asset and its
checksum sidecar were read back with that same SHA-256.
The downloaded archive checksum and VERSION.txt=1.6.158 were verified.
The prior v1.6.491 image packages Web Console 1.6.157. API acceptance
observed inaccessible Secret IDs returning HTTP 403, readonly Secret PUT and
DELETE without schema methods returning HTTP 405, and scoped Service direct-ID
denials. Web Console 1.6.158 maps Service direct-ID and Secrets collection
load failures through the existing resource-safe error handling: HTTP 403 and
404 share an unavailable message, and HTTP 5xx receives a server-failure
message. HTTP 405 save and action failures use existing localized unavailable
messages. New load copy is supplied in English, Traditional Chinese, and
Japanese, with English fallback for other locales. Authorization and request
payload contracts are unchanged.
Focused Web Console source tests passed 7/7 Chrome QUnit cases for the route
failures, HTTP 405 responses, and three-language copy. These tests and this
Server source preparation do not establish a v1.6.492 image or packaged
browser acceptance. After the official archive is published and pinned, the
Server release gate must verify its checksum and compiled UI, merged-rootfs
security scan, and first-boot/restart health. Packaged browser QA must verify
the Service direct-ID and Secrets load messages, HTTP 405 action feedback,
and the prior role and locale boundaries.
The Server OpenVEX identity and vendor-pending register advance to this
candidate. Existing Ubuntu findings remain subject to the exact-set image
scan and review. Retain the previously deployed immutable image digest with
the same volumes and runtime settings for isolated rollback. Formal
stack.ascdc.tw deployment is outside this candidate preparation.
PastureStack Server v1.6.491
Server v1.6.491
This release packages Web Console 1.6.157 on the unchanged
Server v1.6.460 runtime base and Orchestration Engine v0.183.326.
The Web Console source is merged main commit
3f2760da44d25fcc277a627e843fb0c088972ec6 from
Web Console PR #131.
The Web Console main CI web-console-1.6.157.tar.gz artifact SHA-256 is
ba1724c8a2e3d204c6f1527c7880cd361f3e307863133a1d1ba45120fce53a3f.
Web Console main validation run 36622118528 passed. The archive checksum
and VERSION.txt=1.6.157 were verified before this Server source preparation.
The published Web Console release asset was read back with the same SHA-256.
The prior v1.6.490 image packages Web Console 1.6.156. In isolated 8080
browser QA, a readonly user's fresh direct visit to /apps/stacks/add showed
the permission denial but left the notice fixed under BODY, overlapping
right-side header actions at 1440px. An in-app route transition moved the
notice into the page flow. Web Console 1.6.157 renders a growl-mount
component in the authenticated template and moves the existing jGrowl
container when the component enters the DOM. On teardown it returns the
container to BODY only while the component owns it. Login and MFA notices
therefore retain their existing body host. Permission checks, API
authorization, notice copy, and request payloads are unchanged.
The Web Console focused source tests passed 7/7 Chrome QUnit cases for notice
placement, component insertion and teardown, delete notices, and layout.
The official Server release assets
include published.txt, image-inspect.txt,
candidate-smoke.txt, the merged-rootfs security-summary.txt, and the image
SBOM server.cdx.json and OpenVEX server.openvex.json. published.txt and
image-inspect.txt identify the published
image as
ghcr.io/pasturestack/server:v1.6.491@sha256:c484d298e5bde93b51b44acd476a725bbaa471959d1079d19331c01bc55f8705.
The candidate smoke reports first-boot and restart health; the security
summary reports SERVER_SECURITY_GATE_OK with eight vendor-pending findings.
Post-release isolated 8080 QA identified that image and Web Console 1.6.157.
It passed 14 scoped cases: 12 readonly Stack and Service direct-create denials
across Traditional Chinese, English, and Japanese at 1440x900 and 375x812,
and two owner checks that the create forms open at 1440x900. Two additional
fresh direct-URL checks for readonly
passed at 1440x900. The record reports zero resource writes, so the owner
checks do not establish successful creation. Packaged behavior at 280px, both
themes and directions, login/MFA notice behavior, and the broader six-role
resource matrix remain outside this QA result.
The Server OpenVEX identity and vendor-pending register advance to this
release. Retain the previously deployed immutable image digest with the same
volumes and runtime settings for isolated rollback. This release and isolated
QA do not establish deployment to the formal stack.ascdc.tw site.
PastureStack Server v1.6.490
Server v1.6.490
Server v1.6.490 packages Web Console 1.6.156 on the unchanged Server
v1.6.460 runtime base and Orchestration Engine v0.183.326. The Web Console
source is main commit 29cda4fd9239e159ff46769cf7db4318c6406d0f
from Web Console PR #129.
The official web-console-1.6.156.tar.gz release asset's
SHA-256 is 8ddb875fe374c8893bbdde4ee595d3cc9502e24dc30832b866404c12fc2cacd2.
Web Console main validation run 36614540232 passed. The numeric release tag,
archive identity, and VERSION.txt=1.6.156 were verified before this Server
image build.
The prior v1.6.489 isolated browser run found that a fixed permission notice
still covered a page title at 375px and right-side sort controls at 1440px.
Web Console 1.6.156 moves the existing jGrowl container into an in-flow
mount between the navigation and <main> on authenticated pages. It returns
the same container to the body when leaving that route, preserving login and
MFA notices. The package and image checks require the growl-mount browser
asset marker and static-position CSS in all four theme assets. This is a
layout change; API, Engine, authorization, and request payload contracts are
unchanged.
Web Console source tests and local compiled-CSS checks do not establish a
v1.6.490 image or packaged browser acceptance. The image requires the
merged-rootfs security gates and first-boot/restart health checks. Packaged
browser checks must verify that permission notices clear the navbar, page
title, and header actions at 280px, 375px, and 1440px in both theme and text
directions, and that login/MFA notices remain visible. The prior six-role
matrix remains separate and must not be claimed complete from these layout
checks.
The Server OpenVEX identity and vendor-pending register advance with this
release. Existing Ubuntu findings remain subject to exact-set image scan and
review; this patch does not claim they are fixed. Retain the previously
deployed immutable image digest with the same volumes and runtime settings
for isolated rollback. Formal stack.ascdc.tw deployment is outside this
release rollout.
PastureStack Server v1.6.489
Server v1.6.489
Server v1.6.489 packages Web Console 1.6.155 on the unchanged Server
v1.6.460 runtime base and Orchestration Engine v0.183.326. The Web Console
source is main/tag commit 20ed369c6f9600fc063b6ff8f3587de70ae838ff.
The official web-console-1.6.155.tar.gz release asset has SHA-256
fb4591618bfd782dc05932b401296c40d91785a2c7eb20218d29086850500d8f.
The Server build verifies that archive and VERSION.txt=1.6.155, then checks
all four theme CSS assets after extraction and in the assembled image. Web
Console main validation run 36605681674 passed 713 Chrome tests and produced
two byte-identical release candidates; the published tag and archive match
this source commit and digest.
The Web Console notification is offset below the 45px navbar, and its close
control is bounded to calc(100vw - 20px) so it stays usable on narrow
viewports. The preceding Stack and Service route permission notices from
v1.6.488 remain in place. This package changes no API, Engine, or request
payload contract.
Web Console PR #128 CI passed. That source and asset evidence is not proof of
a v1.6.489 image, packaged browser acceptance, or complete six-role QA.
The image acceptance criteria are merged-rootfs security gates,
first-boot/restart health, and packaged browser checks for notification
placement and narrow viewport behavior. The previous isolated role matrix
need not be rerun for this CSS change unless those checks reveal a permission
regression. The Server release record carries the resulting image identity
and acceptance evidence.
The Server OpenVEX identity and vendor-pending register advance with this
release. Existing Ubuntu findings remain registered for exact-set image scan
and review; this patch does not claim they are fixed. Retain the previous
immutable v1.6.488 image digest with the same volumes and runtime settings
for isolated rollback. Formal stack.ascdc.tw deployment is outside this
release rollout.
PastureStack Server v1.6.488
Server v1.6.488
Server v1.6.488 packages Web Console 1.6.154 on the unchanged Server
v1.6.460 runtime base and Orchestration Engine v0.183.326. The Web Console
source is main commit f381a9fb29b54c1b7c18e453c001a93ff1d6a531.
The official web-console-1.6.154.tar.gz release asset has SHA-256
c36a8e2cb06f62439359c9b05ad7eb7d76405f54de7800db4c3fea7cde77440e.
The Server build verifies that archive and VERSION.txt=1.6.154. Web Console
main validation run 36598826825 passed and produced two bit-identical
release candidates; the published release tag and asset match this source
commit and digest.
When a read-only user opens a Stack or Service create route directly and the
effective schema does not allow creation, the page shows the existing growl
style with a localized permission notice before returning to Stacks. An
upgrade still checks update permission and uses a distinct update notice.
English, Traditional Chinese, and Japanese have their own messages; the
remaining locales use English fallback text. This package changes no API,
Engine, or request-payload contract.
The previous isolated v1.6.487 six-role API matrix recorded 136 passes and
20 read-only schema N/A cases. It did not cover every same-page submission or
direct resource-ID action. This source and Web Console asset are
not proof of a v1.6.488 image, browser acceptance, or complete six-role QA. A new image
still requires merged-rootfs security gates, first-boot/restart health, and
packaged browser checks for the permission notice and redirect.
The Server OpenVEX identity and vendor-pending register advance with this
release. Existing Ubuntu findings remain registered for exact-set image scan
and review; this patch does not claim they are fixed. Retain the previous
immutable v1.6.487 image digest with the same volumes and runtime settings
for isolated rollback. Formal stack.ascdc.tw deployment is outside this
release rollout.
PastureStack Server v1.6.487
Server v1.6.487
Server v1.6.487 packages Web Console 1.6.153 on the unchanged Server
v1.6.460 runtime base and Orchestration Engine v0.183.326. The Web
Console source is the signed main commit
2c1ac7b112cd82d4335d320880822b2a4a9b1ae8. Its immutable
web-console-1.6.153.tar.gz SHA-256 is pinned in the Server build; the build
verifies 21a4a3ddfe7e79cb3b7189d8ce8854271470a50193d6ab30a2124dd17f72c910
and VERSION.txt=1.6.153. Web Console main validation run 36532426851
passed all 712 tests and produced two identical release candidates. CodeQL
run 36532407773 passed on the same signed main commit.
This patch tightens Stack, Service, Container, Catalog, and adjacent UI write
controls against the currently selected project, effective API schema, and
resource action link. Queued project upgrades, delayed Service scale writes,
and Catalog save navigation remain bound to their originating project. A
denied or missing resource has localized, non-identifying feedback. Registry
edit recovery and Japanese wording were checked in their forms. Container and
Host charts stop loading when a stats link is absent; authorization and
not-found responses are not retried, while transient failures may retry with
a fresh socket. The Engine, API permission rules, stored payloads, and other
runtime components are unchanged.
The isolated Server v1.6.486 QA established six-role read-only page
discovery, selected cross-project ID denials, and bounded real Stack/Service/
Container writes and cancel/save/remove flows. It did not establish every
same-page submission or every direct resource-ID operation. A new Server
image must still pass first-boot/restart health, merged-rootfs security gates,
and packaged browser checks. Source checks and the Web Console asset are
not proof of a v1.6.487 image, browser acceptance, or six-role QA.
The Server OpenVEX identity and vendor-pending register advance with this
release. Ubuntu findings without an upstream fix remain registered for review
and subject to the exact-set image scan; this patch does not claim they are
fixed. Use previous image
ghcr.io/pasturestack/server:v1.6.486@sha256:fd33dba09cf3445ad3015ae8b0ecdb7302a97b45829d9c31ed222fbc19ba9ffb
as the isolated 8080 rollback with the same named volumes and runtime settings. The formal
stack.ascdc.tw deployment is outside this release rollout.
PastureStack Server v1.6.486
Server v1.6.486
Server v1.6.486 packages released Web Console 1.6.152 on the unchanged
Server v1.6.460 runtime base and Orchestration Engine v0.183.326. The
Web Console tag resolves to merged commit
dae731085d00f209ad4ee9419acd21d0b6d64f2a; release asset
web-console-1.6.152.tar.gz has SHA-256
56c147e392d40395690e925e0d8590e44de90bd7d6aaa3e6076ca75f30341486.
The Server build verifies that asset and VERSION.txt=1.6.152. Web Console
main validation run 36446151881 passed its complete source gates and two
production builds on that commit.
The only product behavior change is the required-name error in Stack,
Service, and Container forms: it now uses the same visible translated label
as the input. Isolated Server v1.6.485 browser QA found four Chinese/Japanese
Stack mismatches. Earlier Service/Container browser cases exercised shared
memory errors but did not submit blank names; those cells remain untested.
There is no API, authorization, request-payload, or runtime component change.
Source and Web Console artifact checks are
not proof of a v1.6.486 image, browser acceptance, or six-role QA.
Publication requires an immutable Server
build with final merged-rootfs vulnerability/SBOM checks and first-boot/restart
health. Isolated 8080 browser QA must then verify zh-TW, en-US, and ja-JP
Stack/Service/Container blank-name errors at desktop and narrow widths, with
zero writes on invalid submission. Do not infer a complete all-resource ID
write-permission matrix from that localized check.
The OpenVEX statements are carried forward with a new document identity.
Official publish run 36448043632 stopped at the exact-set
merged-rootfs vulnerability gate before publishing an image: Trivy 0.74.0
reported two additional unresolved Medium occurrences of CVE-2026-86145
in Ubuntu 26.04 libpcre2-8-0 and libpcre2-posix3 at 10.46-1build1,
both with no FixedVersion. The vendor-pending register now records those
exact package/CVE pairs for review by 2026-10-20; the unfiltered scan and
exact-set gate remain required. Canonical marks the Ubuntu 26.04 pcre2
package vulnerable; the
register's needs-evaluation is this project's expiring review state, not
Canonical's package status. This does not claim the issue is fixed or absent.
Rollback uses the previous immutable Server v1.6.485 digest with the same
volumes, origin, restart policy, and AppArmor configuration. Production
stack.ascdc.tw is outside this isolated QA rollout.
PastureStack Server v1.6.485
Server v1.6.485
The Server v1.6.485 packaging uses the released Web Console 1.6.151 on the
existing Server v1.6.460 runtime base with Orchestration Engine
v0.183.326. The Web Console release tag 1.6.151 resolves to merged source
commit dfb9b6e799e6b88ae1bf4dd94e71ccc0a8e357ce. Its published archive
web-console-1.6.151.tar.gz has SHA-256
9cee713690d0f6064bd2490e8cd0a118a7dfb5589d588d50ebb5c443a0eff2b3;
the Server packaging gate requires VERSION.txt=1.6.151. GitHub main
validation run 36416310187 succeeded on that merged commit.
The Web Console source change exposes Secret Edit only when the Secret is
active, its current resource schema allows PUT, and it has a self link.
Secret Remove still requires its explicit action. The form payload, server
authorization, and Certificate and RegistryCredential action-link rules are
unchanged. The packaged Server image, browser/API write behavior, and full
role matrix require separate acceptance; the successful source run does not
establish those results.
Compared with Server v1.6.484, the source changes
the Web Console archive and Server version identity. The runtime base, other
component pins, and Engine remain unchanged. The reviewed OpenVEX and
vendor-pending finding sets are carried forward with new document identities;
this is not evidence of a new image scan. Publication still requires building
the exact source, scanning the final merged rootfs with pinned Trivy, and
matching unresolved findings against the vendor-pending tracker. New or
changed findings require review before publication.
Run bash -n on the changed scripts and
bash scripts/check-server-api-explorer-patch.sh (or the aggregate
bash scripts/check-server-source-gates.sh). Passing a source gate is
not proof of a v1.6.485 image, browser acceptance, or six-role QA. Retain
the workflow and QA evidence with the release record.
PastureStack Server v1.6.484
Server v1.6.484
This candidate packages Web Console 1.6.150 on the existing Server
v1.6.460 runtime base with Orchestration Engine v0.183.326. The Web Console
release tag 1.6.150 resolves to merged source commit
584a548dc30f8d59bcc3f1c9aba17e7b26eff4ef. Its published archive
web-console-1.6.150.tar.gz has SHA-256
9f9de0ab54ef9ad8b4bb1dd7f08e6d4c5c1aa1373e02f231fdad5e27916695b1
and contains VERSION.txt=1.6.150. Validation run 36392620778 passed source
tests and byte-identical production builds from the merged commit. The source
change limits Certificate and RegistryCredential edit requests to editable
fields; isolated browser/API write acceptance remains a separate gate.
Only the Web Console archive and Server identity change from v1.6.483; the
runtime base, package pins, and Engine remain unchanged. The prior reviewed
OpenVEX and vendor-pending finding sets are carried forward with a new document
identity, not treated as proof of a new scan. The release workflow must build
the exact candidate, flatten its final rootfs, scan it with pinned Trivy, and
prove the remaining findings equal the tracker. Any new or changed finding
blocks publication until reviewed; no severity threshold is relaxed.
Run bash -n on the changed scripts and
bash scripts/check-server-api-explorer-patch.sh (or the aggregate
bash scripts/check-server-source-gates.sh). The image build and merged-rootfs
security gate remain separate later validation steps; a source gate alone does
not prove their results.
This source note alone is not proof of image publication or isolated browser
acceptance; verify the immutable release tag, digest, and workflow evidence.
Preserve the current Compose environment,
volumes, restart policy, AppArmor configuration, HTTPS origin, OIDC settings,
and nftables architecture during later validation.
PastureStack Server v1.6.483
Server v1.6.483
This release packages Web Console 1.6.149 with unchanged Orchestration Engine
v0.183.326 and the other component coordinates from Server v1.6.482.
The Server API, database schema, authentication service, and host-agent
contracts do not change.
Secret Edit follows the effective Secret schema. Existing names are read-only;
the form explains why, retains Secret Add's name and value inputs, and submits
only description in an edit PUT. A cleared description is sent as an explicit
empty string rather than silently omitted. A rejected save leaves the entered
value and diagnostic error visible in the modal. The 13 shipped locales include
the read-only name explanation.
New Registry, Certificate, and Secret creates refresh their server action
links by exact ID before navigating away, so the first action menu reflects
the effective API permissions. Registry creation distinguishes the parent
Registry POST from the RegistryCredential POST: a credential failure cannot
repeat the parent creation, and an ambiguous credential response cannot be
blindly retried. An existing Registry with no credential can be edited to add
one after a fresh collection check. Certificate Edit also rejects encrypted
private keys, consistent with Certificate Add. The affected recovery guidance
is localized in Traditional Chinese, English, and Japanese.
The Web Console 1.6.149 source
is the merged commit b3139aced7227eab97d6034a4d97440d5823265b.
Its immutable web-console-1.6.149.tar.gz input has SHA-256
c8ff45db07d5db4599fbbaa6665f7bffe2977b09a907d493793f4becaa3c31d2
and declares VERSION.txt=1.6.149. The unchanged Engine input is commit
66160dfc1d9d134d1c9c85b4f2908c3f07f99365, with cattle.jar SHA-256
6427120ef0047deb0c436a5cd9167a9afb3a2fb3075123b50340ec1216a5fe81.
The Web Console merged-source validation passed in
run 36370870149.
The release source gate also checks all locale keys, component hashes, numeric
version identity, and the inherited Server runtime contracts. The source-gate
documentation markers now use stable release identity and contracts rather
than mutable candidate/publication wording, so post-publication README edits
do not invalidate the same source build.
The isolated 8080 Secret Edit browser write flow and six-role permission
matrix are separate acceptance gates. Until their evidence is attached below,
this source change does not claim browser acceptance or production readiness.
No production deployment is part of this release task.
Upgrading from v1.6.482 changes the Web Console package only. Preserve the
existing Compose environment variables, named volumes, restart policy,
AppArmor, HTTPS public origin, OIDC settings, and nftables architecture.
There is no database migration. If the isolated validation fails, stop the
new QA container and restart the retained v1.6.482 container with the same
volumes; do not restore or delete volumes merely to roll back the UI.