SecondBox v0.14.0
Deployment boundary
v0.14.0 requires a fresh database and a separate Runner storage root. The unlimited Snapshot retention fix changes the initial migration checksum, so existing installations, including v0.13.0, cannot upgrade in place. update --resume cannot repair the mismatch. Retain the previous deployment and its original state for rollback until its owners retire their Sandboxes.
The signed secondbox-0.12.0 Firecracker bundle and its trust anchor remain unchanged.
Changes
- Added optional
exclusiveBytesto Workspace storage observations, measuring extents unshared with templates, Snapshots, or other Workspaces. Bounded background probes preserve heartbeat responsiveness; unsupported, incomplete, unstable, or encoded extents report an unavailable exclusive measurement with a distinct reason. - Added Sandbox state and ID filters, intersecting with metadata and bound to pagination cursors, with Go and TypeScript options.
- Distinguished missing Workspace files (
file_not_found) from missing Sandboxes, unavailable compute, and generation fencing. - Added TypeScript Subject and ApplicationAuthority management helpers and tenant usage reads. Subject quota updates return an atomic
quotaObservation, preserved on idempotent replay. - Fixed unlimited Snapshot retention through persistence and reads/lists.
Full release notes and deployment guidance.
Qualification and distribution
Built and qualified from 1cda639f4641e041d9e1b688df10fdaf1a783e99. All ten local gates and GitHub CI passed. Firecracker and local gVisor scenarios passed; the disposable Btrfs-image installer passed 11 assertions, including reboot recovery and a real hello-world microVM. Qualification evidence is attached, including the existing scenario skips.
The default release tier ships Linux amd64 container images and Linux/macOS CLI and deployment binaries for amd64 and arm64. The full nightly/pod/arm64-image matrix was not run for this release.
TypeScript: npm install @secondstack-ai/secondbox@0.14.0
Go: go get github.com/SecondStack-AI/SecondBox@v0.14.0
For a fresh Linux amd64 deployment:
curl -fsSL https://github.com/SecondStack-AI/SecondBox/releases/download/v0.14.0/install.sh | sh