Skip to content

ContextGate 0.6.0 — Named administrators and Apache-2.0

Choose a tag to compare

@SamuelSupe SamuelSupe released this 15 Sep 10:25
· 5 commits to main since this release

ContextGate is a Semantic Data Gateway for AI Agents: business concepts, verified native queries and controlled access to databases and HTTP APIs.

What's new in 0.6.0

  • Named administrator accounts with Super administrator and Administrator roles, temporary passwords and mandatory first-login password replacement.
  • One personal Configuration MCP identity per administrator, with owner-only token issuance/rotation and targeted cancellation when access is revoked.
  • Audit records identify the actual administrator, configuration identity and entry point, including Agent previews. Account security events are restricted to super administrators.
  • OTLP Logs over HTTP/protobuf and gRPC carry the new administrator fields. Two-administrator UI and Configuration MCP attribution is verified against a real Collector.
  • ContextGate is now open source under the Apache License 2.0. LICENSE, NOTICE and third-party notices are included with the source, images and distributions.
  • English and Simplified Chinese account management, personal-token settings, audit filters and help.

Upgrade notice

Back up the PostgreSQL metadata database and its matching master key, then stop the previous service before replacing it.

Sign in again with username admin and the existing administrator password. All old Configuration MCP tokens are revoked: each account owner must issue a new personal token in Settings → My configuration MCP and update their clients. Data sources, semantics, ontology versions, query Agent/OAuth grants, evaluations and audit history are preserved.

Do not run old and new server versions against the same metadata database. CLI password recovery now accepts --username; omission is allowed only with one administrator account.

Downloads

  • contextgate-0.6.0-linux-arm64.tar.gz
  • contextgate-0.6.0-linux-amd64.tar.gz
  • SHA256SUMS

Linux glibc 2.36+ and a PostgreSQL metadata database are required. Archives include the embedded UI, private C++ libraries, bilingual help, examples and licenses. No Node.js runtime is required. The mcpdbhub launcher alias and MCPDBHUB_* settings remain supported.

Validation

The attached records identify the exact release commit, passing native arm64/amd64 CI and independent checks of the downloaded archives. Package checks cover HTTP/stdio MCP, source/template/ontology persistence, HTTP API workflows, password recovery, credential revocation and real OTLP delivery. Local amd64 archive execution uses OrbStack emulation.

The administrator feature's 18-product / 20-version matrix passed 135 query/error cases and 104 denied operations; its original digest and test-stage boundaries are retained in administrators.json. Release packaging does not relabel that matrix as a new run. release-verification.json records final delivery evidence.

Help

Getting started · Installation · Administrator accounts and upgrade · Configuration MCP · Release notes · 中文说明