Skip to content

Now 100% more functional

Pre-release
Pre-release

Choose a tag to compare

@dasmatus dasmatus released this 06 Oct 09:56
· 317 commits to main since this release

What's Changed

  • Fix Nix proxy publishing failure on empty references by @dasmatus with @Copilot in #37
  • fix(security): close the claim-window, loopback, mesh-pod and edge DoS holes by @dasmatus in #38
  • fix(boot): let the installed system find its disk inside a VM by @dasmatus in #44
  • fix: the six code findings from the critical review (wizard claim, admin key, pins, gc, TPM default, change) by @dasmatus in #45
  • ci: simplify devenv update to use nixpkgs devenv by @dasmatus in #46
  • feat(install): seal the disk key to the TPM2 by default; --no-tpm opts out; fix the NUL-stripped keyfile by @dasmatus in #48
  • fix(installer): write a keyfile that survives disko's shell substitution by @dasmatus in #47
  • fix(upgrade): read the box's install-target.nix and overrides.nix under --impure so a remote upgrade keeps them by @dasmatus in #49
  • deps(cargo)(deps): bump the cargo-major group across 2 directories with 2 updates by @dependabot[bot] in #43
  • deps(github-actions)(deps): bump the githubactions-major group across 1 directory with 3 updates by @dependabot[bot] in #41
  • deps(npm)(deps): bump the npm-major group across 2 directories with 5 updates by @dependabot[bot] in #40
  • feat(edge): run the registrar as a Vercel Function for the demo (edge-vercel/) by @dasmatus in #50
  • fix(wizard, install): wait for Nextcloud before the first password; stop the chown errors in nixos-install by @dasmatus in #51
  • Fix the Nextcloud pod crash loop (/run/nextcloud) and surface a dying pod's last log line in the wizard by @dasmatus in #55
  • Survive a claim reply lost in transit: replay the admin key to the same password, retry in the wizard, 10-minute API timeout by @dasmatus in #56
  • deps(cargo): bump the cargo-minor-patch group across 2 directories with 4 updates by @dependabot[bot] in #54
  • deps(npm): bump the npm-minor-patch group across 2 directories with 8 updates by @dependabot[bot] in #53
  • deps(github-actions): bump actions/checkout from 4 to 7 in the githubactions-major group across 1 directory by @dependabot[bot] in #52
  • Build every Rust binary with mold, ccache and sccache by @dasmatus in #59
  • feat(cache): the appliance and installer pull from losos-proxy.dasmat.us by default by @dasmatus in #57
  • deps(npm): bump source-map-js from 1.2.1 to 1.2.2 in /admin-ui/app in the npm-security group across 1 directory by @dependabot[bot] in #58

Full Changelog: v0.1.5...v0.1.6

Installer ISO

losos-installer-v0.1.6.iso — 1.43 GiB

sha256  83a624f70cb842bc445866b394793eb38b5321ac9b095cd341d34a53e3a1da15

Verify it with:

curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.6/losos-installer-v0.1.6.iso.sha256
curl -fsSLO https://github.com/dasmatus/losos/releases/download/v0.1.6/losos-installer-v0.1.6.iso
sha256sum -c losos-installer-v0.1.6.iso.sha256

Write it to a USB stick and boot the target machine; the installer
partitions, encrypts and installs unattended. It needs a network
connection, because it clones the flake at run time.

Built from f2993c3 by this workflow run.

Demo QCOW2

losos-demo-v0.1.6.qcow2 — 5.56 GiB, too large for a GitHub release asset,
so it lives on GHCR: package page.

sha256  c9acace51b5a0420b6ad552818aa9491a367abec495264c047736e85f4aa1d74

Download the layer directly with curl (the token is anonymous):

token=$(curl -fsS "https://ghcr.io/token?scope=repository:dasmatus/losos-demo-qcow2:pull" | jq -r .token)
curl -fL -H "Authorization: Bearer $token" -o losos-demo-v0.1.6.qcow2 \
  https://ghcr.io/v2/dasmatus/losos-demo-qcow2/blobs/sha256:c9acace51b5a0420b6ad552818aa9491a367abec495264c047736e85f4aa1d74
echo "c9acace51b5a0420b6ad552818aa9491a367abec495264c047736e85f4aa1d74  losos-demo-v0.1.6.qcow2" | sha256sum -c

Or pull it with oras, which fetches the
.sha256 beside it:

oras pull ghcr.io/dasmatus/losos-demo-qcow2:v0.1.6
sha256sum -c losos-demo-v0.1.6.qcow2.sha256

This image is for demos and development only. It does not carry the
appliance's TPM-sealed encrypted disk layout, so anyone who can read
the file can read its data.

The installer ISO is on GHCR too (package page):
oras pull ghcr.io/dasmatus/losos-installer-iso:v0.1.6


Build the installer ISO from this tag instead:

nix build .#nixosConfigurations.iso.config.system.build.isoImage

Build the demo QCOW2 instead:

nix build .#losos-disk-qcow2