SecondBox v0.18.0
SecondBox v0.18.0
Deployment boundary
This release keeps Runner protocol generation 5, the public API v1, and the v0.15.0 database migration baseline.
It adds no migration, changes no standard Profile revision, and ships the signed secondbox-0.17.0 Firecracker bundle unchanged.
A v0.17.0 Firecracker deployment can update in place with the guided updater; no reinstall is necessary.
Stop active Sandboxes and take a coordinated database and Runner-storage backup before the update.
Update the control plane, every Runner, and the image fetchers to the same release.
Deployments older than v0.17.0 must first cross the boundaries in the v0.17.0 notes and the earlier release notes.
Breaking for gVisor operators. Every gVisor Runner now requires a running image fetcher, a reflink-capable execution image cache, per-Tenant registry configuration, and the execution image publisher key. A gVisor Runner started without them, or whose cache filesystem cannot reflink, refuses to start. Deploy the fetcher and configuration beside each gVisor Runner before updating it. There is no fixed-assets-only gVisor mode.
Firecracker bundle and trust anchor
This release ships the retained signed secondbox-0.17.0 Firecracker bundle, component identities, and RSA trust anchor without change.
The runtime and toolchain component-manifest digests that Profiles pin are the same as in v0.17.0 and are recorded in the v0.17.0 notes.
Client-selected execution images on gVisor
gVisor Runners now launch client-selected execution images.
An application that selects a signed image on every create and start, such as an agent platform, runs on Linux hosts and Kubernetes nodes without KVM.
The gVisor Runner consumes the same signed OCI artifact the Firecracker Runner boots, so an application publishes one image for both backends.
- Retrieval, the registry allowlist, per-Tenant registry authorization, and the publisher signature and fingerprint checks are the implementation Firecracker already uses.
- Only the image's signed
rootfs.ext4is used. The Runner reflinks it into an unnamed per-Instance clone and mounts it as the sandbox root. The Runner's pinnedrunscand guest agent launch the Sandbox; the image's kernel,shared.img, and embedded agent are ignored. The materialization's agent must speak the image's guest protocol generation and every mandatory guest feature the image signs. - As under Firecracker, guests may write anywhere in that root. The writes stay in
runsc's in-memory overlay, count against the Instance memory limit, and vanish when the Instance stops. The cached image is never modified. The fixed flat root remains read-only to the guest. - gVisor Runners report
client-selected-imagereadiness, so they receiveimages:preparetargets and selected-image placement. The runner protocol and control plane are unchanged.
See client-selected execution images and gVisor runtime.
Required gVisor Runner settings
Every gVisor Runner states these values explicitly; they have no defaults:
| Setting | Value |
|---|---|
SECONDBOX_RUNNER_EXECUTION_IMAGE_CACHE_ROOT |
Absolute cache directory shared with the fetcher, on a Btrfs or XFS filesystem with reflink support, disjoint from SECONDBOX_GVISOR_RUNTIME_DIR. |
SECONDBOX_RUNNER_IMAGE_FETCHER_SOCKET |
The fetcher's private Unix socket, in a directory shared only with the Runner. |
SECONDBOX_RUNNER_EXECUTION_IMAGE_PUBLIC_KEY |
The execution image publisher's PEM public key. |
SECONDBOX_RUNNER_EXECUTION_IMAGE_PUBLIC_KEY_SHA256 |
The SHA-256 of that key's DER encoding, pinned independently. |
Run secondbox-image-fetcher from the same runner-gvisor release image as a separate unprivileged process (UID 10002 in the reference pod), without Workspace mounts, host devices, or privileges. Configure its SECONDBOX_IMAGE_FETCHER_* inputs as for Firecracker: the socket, the cache root, the per-Tenant registry configuration (tenants.json, token or Docker login files, and optional certificates/<registry-host>/ca.crt), the registry allowlist, the publisher key and fingerprint, and the download, expanded, and cache byte limits. The fetcher refuses world-readable registry credentials. A cold retrieval reserves twice the download limit plus the expanded limit on the cache filesystem.
The reference pod runner/deploy/gvisor-runner-pod.yaml now runs an unprivileged image-fetcher container beside the runner, with a node-local cache hostPath, a pod-local socket emptyDir, the registry configuration as a Secret, the publisher key as a ConfigMap, and fsGroup: 10002.
Distribution
The runner-gvisor image now includes secondbox-image-fetcher and Skopeo.
The default release tier qualifies Firecracker, local gVisor, and the Btrfs-image installer guest and publishes Linux amd64 container images. This release's default tier carries no pod evidence. Before merge, the nightly tier qualified the gVisor host and the reference pod on a no-KVM K3s node, including a selected image, at #173 commit 7fbc893, whose tree is identical to the released merge. CLI and deployment binaries ship for Linux and macOS on amd64 and arm64. The public API remains v1; the Runner protocol window is [5,5].
Install the TypeScript SDK with npm install @secondstack-ai/secondbox@0.18.0.
The Go module is github.com/SecondStack-AI/SecondBox@v0.18.0.
Install
Guided Linux amd64 install:
curl -fsSL https://github.com/SecondStack-AI/SecondBox/releases/download/v0.18.0/install.sh | shSDKs: npm install @secondstack-ai/secondbox@0.18.0 and go get github.com/SecondStack-AI/SecondBox@v0.18.0