Skip to content

SecondBox v0.16.0

Choose a tag to compare

@DmitriyAlergant DmitriyAlergant released this 22 Sep 22:23
· 12 commits to main since this release
6a605c6

SecondBox v0.16.0

Deployment boundary

This release keeps Runner protocol generation 5, the public API v1, and the v0.15.0 database schema.
It adds no migration, and it does not change a standard Profile revision.
A v0.15.0 deployment can update in place with the guided updater, and no reinstall is necessary.
Stop active Sandboxes and take a coordinated database and Runner-storage backup before the update.
Update the control plane, every Runner, and the image fetchers to the same release.
Deployments older than v0.15.0 must first cross the boundaries in the v0.15.0 notes and the earlier release notes.

Firecracker bundle and trust anchor

This release ships the retained signed secondbox-0.12.0 Firecracker bundle, 6.12.94 kernel, component identities, and RSA trust anchor without change.
The bundle was not rebuilt, so the runtime and toolchain component-manifest digests that Profiles pin are the same as in v0.15.0.
Their identities are recorded in the v0.12.0 notes.

The microVM image pipeline no longer runs the rootfs secret scan, and a newly built bundle no longer records secretScanPolicySha256 in its rootfs contract.
The golden rootfs is built only from Docker layers and never receives per-Sandbox runtime secrets.
The installer continues to accept secretScanPolicySha256 in bundles signed before this change, including the shipped secondbox-0.12.0 bundle, and ignores its value.

Runner gateway endpoints for guest executions

Firecracker and gVisor Runners now publish the logical gateway endpoints that the Sandbox's pinned egress context resolves.
Every ordinary guest execution receives the reserved SECONDBOX_RUNNER_GATEWAYS environment variable.
Its value is a space-separated list of logicalName=address:port entries, sorted by logical name and then port.
An IPv6 address appears in brackets.
The variable is absent when the Profile resolves no logical gateway.

The entries are routing information only; they contain no credentials.
An application wrapper selects the entry it needs and sets its own proxy variables, so the application host no longer configures a Runner-host address.
Exec requests that supply SECONDBOX_RUNNER_GATEWAYS themselves are rejected before dispatch, as SECONDBOX_EXECUTION_GATEWAY already is.
Attributed generations resolve no logical gateway and continue to receive only SECONDBOX_EXECUTION_GATEWAY.
The experimental Microsandbox backend does not use the Runner guest protocol, so it neither publishes nor reserves the name.
See SDK, CLI, and Flue integration.

Distribution

The default release tier qualifies Firecracker, local gVisor, and the Btrfs-image installer guest and publishes Linux amd64 container images.
CLI and deployment binaries ship for Linux and macOS on amd64 and arm64.
The public API remains v1; the Runner protocol window is [5,5].

Install the TypeScript SDK with npm install @secondstack-ai/secondbox@0.16.0.
The Go module is github.com/SecondStack-AI/SecondBox@v0.16.0.

Install

Guided Linux amd64 install:

curl -fsSL https://github.com/SecondStack-AI/SecondBox/releases/download/v0.16.0/install.sh | sh

SDKs: npm install @secondstack-ai/secondbox@0.16.0 and go get github.com/SecondStack-AI/SecondBox@v0.16.0