Repository navigation
v0.9.7
Release v0.9.7
Binaries
Pre-built binaries for all supported platforms:
| Platform | Binary |
|---|---|
| Linux x86_64 | ferrum-edge-linux-x86_64 |
| Linux x86_64 CNI plugin | ferrum-cni-linux-x86_64 |
| Linux ARM64 | ferrum-edge-linux-aarch64 |
| Linux ARM64 CNI plugin | ferrum-cni-linux-aarch64 |
| macOS x86_64 | ferrum-edge-macos-x86_64 |
| macOS ARM64 (Apple Silicon) | ferrum-edge-macos-aarch64 |
| Windows x86_64 | ferrum-edge-windows-x86_64.exe |
Docker
docker pull ferrumedge/ferrum-edge:v0.9.7
docker pull ghcr.io/ferrum-edge/ferrum-edge:v0.9.7The default image ships the no-op mock eBPF capture backend. For
real ambient / node-waypoint eBPF capture, pull the Linux-only
-ebpf variant (built with --features ebpf; requires kernel
≥ 5.7 with cgroup v2 + bpffs). Capabilities depend on the kernel: on
≥ 5.8 use CAP_BPF/CAP_PERFMON/CAP_NET_ADMIN; on the
5.7.x window use CAP_SYS_ADMIN + CAP_NET_ADMIN instead,
because CAP_BPF/CAP_PERFMON were only split out of
CAP_SYS_ADMIN in 5.8 — see
docs/node_agent_security.md.
On a node whose kernel/cgroup/bpffs probe fails, the -ebpf pod
exits (default FERRUM_NODE_AGENT_FALLBACK_MODE=fail) rather than
degrading. The published -ebpf image is distroless — it has no
/bin/sh and no iptables — and stays that way on purpose:
docker pull ferrumedge/ferrum-edge:v0.9.7-ebpf
docker pull ghcr.io/ferrum-edge/ferrum-edge:v0.9.7-ebpfThe host iptables fallback and the Ambient host-network UDP capture
lifecycle run generated sh -c iptables/ip6tables/ip
commands, which the distroless -ebpf image cannot execute, so
FERRUM_NODE_AGENT_FALLBACK_MODE=iptables crash-loops there. Use the
-ebpf-tools variant instead: the same Linux-only eBPF build on a
Debian slim base carrying /bin/sh, iptables, ip6tables, and
ip (see docs/node_agent.md).
The mesh Helm chart auto-selects it for the Ambient UDP lifecycle:
docker pull ferrumedge/ferrum-edge:v0.9.7-ebpf-tools
docker pull ghcr.io/ferrum-edge/ferrum-edge:v0.9.7-ebpf-toolsAll three image families — default, -ebpf, and -ebpf-tools — are
Cosign-signed on their immutable multi-arch digests in both registries
and carry SLSA provenance plus per-platform SPDX SBOM attestations; see
docs/ci_cd.md
for the verification commands.
Checksums
Verify the integrity of downloaded binaries:
96e92431cd212103d7d0b1bbbabaea0b7e4fd712706f780fc7ab672b04a07f81 ferrum-cni-linux-aarch64
c70eb58b8b1a758f1f2651ad714d949c56d96a6b12dc52cc2fddccd292517e61 ferrum-cni-linux-x86_64
600d9a754df33e60c178ad0a1b21610ee21c824d808e678000b684552c4492b6 ferrum-edge-linux-aarch64
c26ba4c059be2d78f4044a3768ebfed5be4e7eb5640620fa93ea9199776b0902 ferrum-edge-linux-x86_64
f3bd0027512768488db036ac3c83a21cba0c9fa53538700041ca8337eac0dd03 ferrum-edge-macos-aarch64
8742b1362c3306eeea8a52a75a9911eb0bbd76cb40e424f879d16509d8c65f6d ferrum-edge-macos-x86_64
a8f0d4f482085efd252d0edb682f4baae525e2435999701c3624075f988bbb77 *ferrum-edge-windows-x86_64.exe
Usage
Download the binary for your platform and make it executable:
chmod +x ferrum-edge-linux-x86_64
FERRUM_MODE=file FERRUM_FILE_CONFIG_PATH=config.yaml ./ferrum-edge-linux-x86_64 runSee README.md for configuration and usage instructions.