open-compute 0.1.5
0.1.5 completes the first self-hosted AI Search path: operators can index whole documents from uploads or R2 buckets, extract text from common document and image formats, run bounded OCR or vision-language processing when configured, and query the resulting immutable indexes through the existing Cloudflare-compatible control plane.
This release is intended for single-machine operators who need local, restart-safe document retrieval without adding a hosted indexing service or a second metadata authority.
What's new
- AI Search can create durable R2-backed sources with explicit bucket, prefix, include/exclude glob, object-size, object-count, and total-byte limits. Source credentials remain referenced through encrypted provider profiles rather than copied into source records.
- R2 indexing uses SigV4 pagination, bounded downloads, conditional object identity checks, deterministic filtering, and immutable source snapshots. Restart reconciliation resumes from persisted authority and rejects source drift instead of silently repairing it.
- Whole-document ingestion accepts supported text, PDF, Office, HTML, Markdown, and image inputs. Extraction is bounded by input, output, page, pixel, concurrency, CPU, and timeout policies.
- Optional OCR and vision-language extraction support local or configured AI providers while preserving fail-closed secret handling and stable sanitized errors.
- The Cloudflare-compatible AI Search API, dashboard, and Wrangler extension now expose upload and R2 source lifecycles, indexing progress, source summaries, and deletion behavior from one current Day1 model.
Fixed
- Wrangler version drift is now reported as a non-blocking diagnostic where the supported API contract remains unchanged, while exact runtime and extension pins continue to be enforced at their authority boundaries.
- AI provider profiles now use one explicit provider model with validated capabilities, encrypted credentials, bounded requests, and consistent dashboard and API behavior.
- Document extraction and indexing reject unsupported formats, oversized inputs, corrupt parser output, changed R2 objects, and incomplete source configuration with stable errors rather than partial index admission.
Before you upgrade
- Upgrading from 0.1.4 does not require a configuration rewrite or manual database action. Startup transactionally applies the new platform migrations for AI provider profiles, document extraction, AI Search sources, and their restart-safe indexing state.
- Existing Workers, resources, Artifacts repositories, snapshots, configuration, secrets, and object authority remain in place. New AI Search content consumes the configured data directory and object-store capacity.
- R2 source creation requires an existing R2 bucket and an authorized provider profile or the platform-owned local object authority, depending on the selected source. Review prefix and byte limits before indexing a large bucket.
- OCR and vision-language extraction are optional. Without a configured eligible provider, ordinary supported text extraction remains available and inputs requiring the missing capability fail closed.
- open-compute remains pre-1.0 and keeps one current Day1 schema and API model; obsolete development databases, provider-profile shapes, and experimental source formats are not supported.
After replacement, verify the installation with:
ocd --version
ocd config check
ocd doctor
ocd target listInstall or upgrade
An existing receipt-managed installation can upgrade directly:
ocd upgrade 0.1.5For a new system-wide installation, download and review the installer before elevating it:
curl -fsSL -o install.sh https://raw.githubusercontent.com/elliothux/open-compute/v0.1.5/scripts/install.sh
less install.sh
sudo env OPEN_COMPUTE_RELEASE_TAG=v0.1.5 sh install.sh
sudo /usr/local/bin/ocd setup --yesFor a user-owned project installation without a system service, use OPEN_COMPUTE_INSTALL_PREFIX="$HOME/.local" sh install.sh instead. The binary and receipt remain under that one prefix.
Downloads
| Host | Asset |
|---|---|
| macOS on Apple silicon | ocd-v0.1.5-darwin-arm64 |
| Linux on ARM64 | ocd-v0.1.5-linux-arm64 |
| Linux on x86-64 | ocd-v0.1.5-linux-x64 |
The release also contains release.json and SHA256SUMS. Every executable embeds the formally pinned v1.20260905.0-open-compute-p1.b3e1a278 runtime (workerd 2026-09-05) and the Pyodide 314.0.6_2026-08-17_2 bundle selected by compatibility date 2026-09-08. Production startup remains offline. Windows and Intel macOS do not have qualified binaries.
Security
There are no published security advisories specific to 0.1.5. R2 credentials remain encrypted references, source snapshots persist only bounded object metadata and content identities, downloads use authenticated SigV4 requests, and indexing rejects redirects, identity drift, over-limit responses, and malformed extraction output. Tenant-visible responses and logs do not expose credentials, signed requests, document contents, parser paths, or internal topology.
Known limitations
- AI Search is designed for one self-hosted machine. It does not claim Cloudflare's managed multi-region placement, billing, fleet coordination, or global indexing throughput.
- R2 source refresh is an explicit indexing operation rather than a bucket event subscription. Objects outside the configured prefix or filters are not indexed, and objects that change during a run cause that run to fail closed.
- OCR and vision-language quality, latency, and supported languages depend on the configured provider and model. The platform enforces bounds but does not normalize model-specific semantic differences.
- Code signing and macOS notarization are not included. Windows and Intel macOS remain source-build-only targets outside formal release qualification.
Verification
The frozen 0.1.5 candidate is qualified with the repository build, formatting and static checks, Rust 1.98 checks, dependency-boundary checks, Cloudflare compatibility review, at least 90% Rust line coverage, and one complete workspace Gate. Product coverage includes authenticated R2 listing and download, filtering and limits, object drift rejection, extraction success and failure paths, restart reconciliation, encrypted provider profiles, immutable source snapshots, and upload/R2 API lifecycles. The tag-triggered release workflow independently runs macOS and Linux qualification, packages all three targets, verifies checksums and isolated offline startup, and publishes only after every required job succeeds.