Skip to content

SecondBox v0.18.0

Choose a tag to compare

@melonamin melonamin released this 26 Sep 03:00
· 5 commits to main since this release
c9da377

SecondBox v0.18.0

Deployment boundary

This release keeps Runner protocol generation 5, the public API v1, and the v0.15.0 database migration baseline.
It adds no migration, changes no standard Profile revision, and ships the signed secondbox-0.17.0 Firecracker bundle unchanged.
A v0.17.0 Firecracker deployment can update in place with the guided updater; no reinstall is necessary.
Stop active Sandboxes and take a coordinated database and Runner-storage backup before the update.
Update the control plane, every Runner, and the image fetchers to the same release.
Deployments older than v0.17.0 must first cross the boundaries in the v0.17.0 notes and the earlier release notes.

Breaking for gVisor operators. Every gVisor Runner now requires a running image fetcher, a reflink-capable execution image cache, per-Tenant registry configuration, and the execution image publisher key. A gVisor Runner started without them, or whose cache filesystem cannot reflink, refuses to start. Deploy the fetcher and configuration beside each gVisor Runner before updating it. There is no fixed-assets-only gVisor mode.

Firecracker bundle and trust anchor

This release ships the retained signed secondbox-0.17.0 Firecracker bundle, component identities, and RSA trust anchor without change.
The runtime and toolchain component-manifest digests that Profiles pin are the same as in v0.17.0 and are recorded in the v0.17.0 notes.

Client-selected execution images on gVisor

gVisor Runners now launch client-selected execution images.
An application that selects a signed image on every create and start, such as an agent platform, runs on Linux hosts and Kubernetes nodes without KVM.
The gVisor Runner consumes the same signed OCI artifact the Firecracker Runner boots, so an application publishes one image for both backends.

  • Retrieval, the registry allowlist, per-Tenant registry authorization, and the publisher signature and fingerprint checks are the implementation Firecracker already uses.
  • Only the image's signed rootfs.ext4 is used. The Runner reflinks it into an unnamed per-Instance clone and mounts it as the sandbox root. The Runner's pinned runsc and guest agent launch the Sandbox; the image's kernel, shared.img, and embedded agent are ignored. The materialization's agent must speak the image's guest protocol generation and every mandatory guest feature the image signs.
  • As under Firecracker, guests may write anywhere in that root. The writes stay in runsc's in-memory overlay, count against the Instance memory limit, and vanish when the Instance stops. The cached image is never modified. The fixed flat root remains read-only to the guest.
  • gVisor Runners report client-selected-image readiness, so they receive images:prepare targets and selected-image placement. The runner protocol and control plane are unchanged.

See client-selected execution images and gVisor runtime.

Required gVisor Runner settings

Every gVisor Runner states these values explicitly; they have no defaults:

Setting Value
SECONDBOX_RUNNER_EXECUTION_IMAGE_CACHE_ROOT Absolute cache directory shared with the fetcher, on a Btrfs or XFS filesystem with reflink support, disjoint from SECONDBOX_GVISOR_RUNTIME_DIR.
SECONDBOX_RUNNER_IMAGE_FETCHER_SOCKET The fetcher's private Unix socket, in a directory shared only with the Runner.
SECONDBOX_RUNNER_EXECUTION_IMAGE_PUBLIC_KEY The execution image publisher's PEM public key.
SECONDBOX_RUNNER_EXECUTION_IMAGE_PUBLIC_KEY_SHA256 The SHA-256 of that key's DER encoding, pinned independently.

Run secondbox-image-fetcher from the same runner-gvisor release image as a separate unprivileged process (UID 10002 in the reference pod), without Workspace mounts, host devices, or privileges. Configure its SECONDBOX_IMAGE_FETCHER_* inputs as for Firecracker: the socket, the cache root, the per-Tenant registry configuration (tenants.json, token or Docker login files, and optional certificates/<registry-host>/ca.crt), the registry allowlist, the publisher key and fingerprint, and the download, expanded, and cache byte limits. The fetcher refuses world-readable registry credentials. A cold retrieval reserves twice the download limit plus the expanded limit on the cache filesystem.

The reference pod runner/deploy/gvisor-runner-pod.yaml now runs an unprivileged image-fetcher container beside the runner, with a node-local cache hostPath, a pod-local socket emptyDir, the registry configuration as a Secret, the publisher key as a ConfigMap, and fsGroup: 10002.

Distribution

The runner-gvisor image now includes secondbox-image-fetcher and Skopeo.
The default release tier qualifies Firecracker, local gVisor, and the Btrfs-image installer guest and publishes Linux amd64 container images. This release's default tier carries no pod evidence. Before merge, the nightly tier qualified the gVisor host and the reference pod on a no-KVM K3s node, including a selected image, at #173 commit 7fbc893, whose tree is identical to the released merge. CLI and deployment binaries ship for Linux and macOS on amd64 and arm64. The public API remains v1; the Runner protocol window is [5,5].

Install the TypeScript SDK with npm install @secondstack-ai/secondbox@0.18.0.
The Go module is github.com/SecondStack-AI/SecondBox@v0.18.0.

Install

Guided Linux amd64 install:

curl -fsSL https://github.com/SecondStack-AI/SecondBox/releases/download/v0.18.0/install.sh | sh

SDKs: npm install @secondstack-ai/secondbox@0.18.0 and go get github.com/SecondStack-AI/SecondBox@v0.18.0