Skip to content

SecondBox v0.18.1

Choose a tag to compare

@melonamin melonamin released this 26 Sep 22:55
· 3 commits to main since this release
45bc523

SecondBox v0.18.1

Deployment boundary

This release keeps Runner protocol generation 5, public API v1, the v0.15.0 database migration baseline, standard Profile revisions, and the signed secondbox-0.17.0 Firecracker bundle and RSA trust anchor unchanged. It adds one optional Runner capability field within the existing protocol generation. Deployments already on v0.18.0 can update the control plane and Runners in place; no data migration or Sandbox recreation is required. Update the control plane and all Runners to the same release before enabling physical storage admission. Existing Runner configurations remain in logical mode unless the operator explicitly selects physical. Deployments older than v0.18.0 must first cross the boundaries in the earlier release notes.

Physical storage admission

Firecracker and gVisor Runners, including the reference Kubernetes pod, can opt into physical storage admission. In this mode, the control plane no longer rejects home placement or assignments because the sum of logical Workspace limits exceeds a Runner's advertised aggregate disk capacity. The Runner probes actual usage of its Workspace filesystem and denies new Workspaces and starts at its configured threshold; admission reopens only at the lower recovery threshold, and probe failure denies admission. Per-Sandbox Workspace size, CPU, memory, instance, operation, and Tenant/Subject Sandbox-count limits remain active.

For a manifest-managed Firecracker Runner, set storage_admission_mode = 'physical' in its [[runners]] block. For a gVisor host or pod Runner, set SECONDBOX_RUNNER_STORAGE_ADMISSION_MODE=physical and explicitly set SECONDBOX_RUNNER_STORAGE_PRESSURE_RECOVERY_PERCENT, ..._WARNING_PERCENT, and ..._ADMISSION_DENY_PERCENT such that 0 < recovery < warning < deny < 100. The reference gVisor pod manifest contains these fields for the operator to fill. With logical, gVisor retains its previous aggregate disk reservation behavior. See Firecracker operations and gVisor operations.

This mode permits logical overcommit. A full filesystem can interrupt guest writes or cause Kubernetes storage pressure or eviction before a Sandbox reaches its own Workspace limit. Monitor the underlying Workspace volume and retain enough headroom for the workload.

Qualification

The scenario image fetcher now requires SECONDBOX_SCENARIO_IMAGE_FETCHER_DNS, an explicit DNS server address reachable from its isolated Docker network. Set it in the qualification or release operator environment when running the selected-image scenario. This changes qualification setup only; deployed Runner DNS settings are unchanged.

Firecracker bundle and trust anchor

The release retains the signed secondbox-0.17.0 Firecracker bundle, component identities, and RSA trust anchor from v0.18.0. Existing pinned Profiles remain valid; no replacement bundle is required.

Distribution

The default lean release qualifies Firecracker and local gVisor and publishes Linux amd64 OCI images. CLI and deployment binaries ship for Linux and macOS on amd64 and arm64. The public API remains v1 and the Runner protocol window remains [5,5]. The default tier does not claim Kubernetes pod scenario evidence.

Install the TypeScript SDK with npm install @secondstack-ai/secondbox@0.18.1.
The Go module is github.com/SecondStack-AI/SecondBox@v0.18.1.

Install

Guided Linux amd64 install:

curl -fsSL https://github.com/SecondStack-AI/SecondBox/releases/download/v0.18.1/install.sh | sh

SDKs: npm install @secondstack-ai/secondbox@0.18.1 and go get github.com/SecondStack-AI/SecondBox@v0.18.1