Skip to content

v0.9.7

Choose a tag to compare

@github-actions github-actions released this 25 Sep 09:57
· 346 commits to main since this release
8fed134

Release v0.9.7

Binaries

Pre-built binaries for all supported platforms:

Platform Binary
Linux x86_64 ferrum-edge-linux-x86_64
Linux x86_64 CNI plugin ferrum-cni-linux-x86_64
Linux ARM64 ferrum-edge-linux-aarch64
Linux ARM64 CNI plugin ferrum-cni-linux-aarch64
macOS x86_64 ferrum-edge-macos-x86_64
macOS ARM64 (Apple Silicon) ferrum-edge-macos-aarch64
Windows x86_64 ferrum-edge-windows-x86_64.exe

Docker

docker pull ferrumedge/ferrum-edge:v0.9.7
docker pull ghcr.io/ferrum-edge/ferrum-edge:v0.9.7

The default image ships the no-op mock eBPF capture backend. For
real ambient / node-waypoint eBPF capture, pull the Linux-only
-ebpf variant (built with --features ebpf; requires kernel
≥ 5.7 with cgroup v2 + bpffs). Capabilities depend on the kernel: on
≥ 5.8 use CAP_BPF/CAP_PERFMON/CAP_NET_ADMIN; on the
5.7.x window use CAP_SYS_ADMIN + CAP_NET_ADMIN instead,
because CAP_BPF/CAP_PERFMON were only split out of
CAP_SYS_ADMIN in 5.8 — see
docs/node_agent_security.md.
On a node whose kernel/cgroup/bpffs probe fails, the -ebpf pod
exits (default FERRUM_NODE_AGENT_FALLBACK_MODE=fail) rather than
degrading. The published -ebpf image is distroless — it has no
/bin/sh and no iptables — and stays that way on purpose:

docker pull ferrumedge/ferrum-edge:v0.9.7-ebpf
docker pull ghcr.io/ferrum-edge/ferrum-edge:v0.9.7-ebpf

The host iptables fallback and the Ambient host-network UDP capture
lifecycle run generated sh -c iptables/ip6tables/ip
commands, which the distroless -ebpf image cannot execute, so
FERRUM_NODE_AGENT_FALLBACK_MODE=iptables crash-loops there. Use the
-ebpf-tools variant instead: the same Linux-only eBPF build on a
Debian slim base carrying /bin/sh, iptables, ip6tables, and
ip (see docs/node_agent.md).
The mesh Helm chart auto-selects it for the Ambient UDP lifecycle:

docker pull ferrumedge/ferrum-edge:v0.9.7-ebpf-tools
docker pull ghcr.io/ferrum-edge/ferrum-edge:v0.9.7-ebpf-tools

All three image families — default, -ebpf, and -ebpf-tools — are
Cosign-signed on their immutable multi-arch digests in both registries
and carry SLSA provenance plus per-platform SPDX SBOM attestations; see
docs/ci_cd.md
for the verification commands.

Checksums

Verify the integrity of downloaded binaries:

96e92431cd212103d7d0b1bbbabaea0b7e4fd712706f780fc7ab672b04a07f81  ferrum-cni-linux-aarch64
c70eb58b8b1a758f1f2651ad714d949c56d96a6b12dc52cc2fddccd292517e61  ferrum-cni-linux-x86_64
600d9a754df33e60c178ad0a1b21610ee21c824d808e678000b684552c4492b6  ferrum-edge-linux-aarch64
c26ba4c059be2d78f4044a3768ebfed5be4e7eb5640620fa93ea9199776b0902  ferrum-edge-linux-x86_64
f3bd0027512768488db036ac3c83a21cba0c9fa53538700041ca8337eac0dd03  ferrum-edge-macos-aarch64
8742b1362c3306eeea8a52a75a9911eb0bbd76cb40e424f879d16509d8c65f6d  ferrum-edge-macos-x86_64
a8f0d4f482085efd252d0edb682f4baae525e2435999701c3624075f988bbb77 *ferrum-edge-windows-x86_64.exe

Usage

Download the binary for your platform and make it executable:

chmod +x ferrum-edge-linux-x86_64
FERRUM_MODE=file FERRUM_FILE_CONFIG_PATH=config.yaml ./ferrum-edge-linux-x86_64 run

See README.md for configuration and usage instructions.