SecondBox v0.15.0
SecondBox v0.15.0
Deployment boundary
This release upgrades the Runner protocol from generation 4 to generation 5.
Stop new application work, stop active Sandboxes, and take a coordinated database and Runner-storage backup before updating the control plane and every Runner together.
Generation 4 Runners cannot serve the generation 5 control plane.
Databases created by v0.14.0 can apply the forward migrations without recreating their resources or Workspaces.
The migration validator recognizes that release's exact retention-baseline checksum and preserves the recorded ledger.
Other checksum drift remains an error.
Rollback after migration uses the coordinated backup and its original software.
The signed secondbox-0.12.0 Firecracker bundle, 6.12.94 kernel, component identities, and RSA trust anchor remain unchanged.
Their identities are recorded in the v0.12.0 notes.
Existing fixed-Profile Sandboxes keep their assets when an application omits an image.
Application-selected execution images
Sandbox create and start accept an optional image.reference containing an OCI tag or digest.
The application builds and signs its userspace with the SecondBox image builder; the resulting bundle contains the guest agent and qualified kernel.
The Profile continues to control resources, placement, networking, and lifecycle policy.
An explicit tag resolves once per new Operation.
Starting with a changed digest boots the replacement image against the retained /workspace; a failed replacement does not overwrite the last successful image pin.
Omitting the image on start reuses the existing pin.
An explicit tag requires registry access even when its digest is cached.
POST /v1/images:prepare prepares the image on eligible Runners without starting compute and reports target and completion counts.
Firecracker on Linux amd64 supports selected images; Snapshot-resume Profiles, gVisor, and Microsandbox reject them.
Each Runner host needs an unprivileged image fetcher, independently provisioned publisher trust, and tenant-scoped registry configuration.
The fetcher has no Workspace mount, host devices, or Docker socket.
Registry credentials stay on the host and never enter lifecycle requests or guest files.
TLS verification is mandatory.
See client-selected execution images.
Lifecycle and image-cache corrections
- Warm starts reuse verified artifact identities instead of hashing the full bundle on every start.
- Cache reclamation protects the image being started and bounds resolution and lock metadata.
- Runner startup rejects a selected-image cache on a different filesystem from the reflink launch directory.
- Image preparation reports progress consistently and resolves on a compatible Runner.
- Lifecycle retries recover after terminal startup failure without unnecessary revision changes during unchanged waits.
Distribution
The default release tier qualifies Firecracker, local gVisor, and the Btrfs-image installer guest and publishes Linux amd64 container images.
CLI and deployment binaries ship for Linux and macOS on amd64 and arm64.
The public API remains v1; the Runner protocol window is [5,5].
Install the TypeScript SDK with npm install @secondstack-ai/secondbox@0.15.0.
The Go module is github.com/SecondStack-AI/SecondBox@v0.15.0.
Install
Guided Linux amd64 install:
curl -fsSL https://github.com/SecondStack-AI/SecondBox/releases/download/v0.15.0/install.sh | shSDKs: npm install @secondstack-ai/secondbox@0.15.0 and go get github.com/SecondStack-AI/SecondBox@v0.15.0