Repository navigation
Ferrum Foundry v0.4.0
Ferrum Foundry v0.4.0
Foundry v0.4.0 pairs with the published Ferrum Edge v0.9.10 release. It
adds an MCP tool catalog and per-tool policy editing, adopts the Ferrum
Contracts catalog, and supports allow_path_parameters on HTTP proxies. It
also includes security fixes for starter identity probes and the container's
PCRE2 runtime library. Changes since
v0.3.0:
git log v0.3.0..v0.4.0.
Supported pairing
| Foundry | v0.4.0 — ferrumedge/ferrum-foundry:v0.4.0, linux/amd64 and linux/arm64. Deploy it by the multi-architecture digest this release's run publishes |
| Ferrum Edge | Ferrum Edge v0.9.10 — ferrumedge/ferrum-edge@sha256:430d6a7d41361de5ad12562786481f97f1e97fef72a0b5f1a0699eced7cdd4cc, commit ee040d5e3281fde424aa65f5b18004852c5b53b0; linux/amd64 sha256:18a8a962ad13bacb2505a122330bb25ce921b21a2f3cb5362a6ea93f11fe44d5, linux/arm64 sha256:c35253bed87153afa6e193074f9b644eb3feeedb35459d1c15de5a23a78e4891 |
| Tested gateway | database mode on SQLite, writable and with FERRUM_ADMIN_READ_ONLY=true; admin JWT with audience and namespace-claim enforcement |
| Tested access | trusted-proxy authentication through the starter's identity proxy; viewer, operator, and admin |
| Tested browser | Chromium (the build bundled with Playwright 1.63.0) |
| CI evidence | #524, which qualified v0.9.10, and this release's Pre-publication Gates, which rerun every gate against the same image before anything is published |
Best-effort: PostgreSQL/MySQL database mode, cp mode, other browsers,
Kubernetes, and static-token authentication (development only). Not qualified:
file/dp/mesh/node_agent modes (so the mesh, waypoint, trust, and
chargeback pages), any other Edge release, and any other Edge image, including
the 0.9.10-ebpf and 0.9.10-ebpf-tools variants. The full envelope, including
tested scale, is in
docs/compatibility.md.
Ferrum Edge v0.9.10 includes ferrum-edge#5954: mcp_gateway and
ai_prompt_shield reject non-UTF-8 charset inputs and fail closed on
uninspectable or over-nested JSON-RPC batches (GHSA-4f9m-cfqg-fhx9,
GHSA-f2jp-59r9-fp64). These changes do not alter the admin API or the plugin
sensitivity rules Foundry uses. It also retains ferrum-edge#5661 conditional
writes and ferrum-edge#5726's proxy-scoped plugin configuration filter.
Highlights since v0.3.0
MCP tools
- Proxy pages show the node-local cached tool catalog for
mcp_gateway, its
source, annotations, configured and effective policy, grants, refresh state,
and errors. The tab explains when a control plane does not serve the catalog. - Edit one tool's allow, deny, discovery visibility, and group grants inline
through guarded writes. An AI governance summary shows whether tool-related
protections and rate limits cover MCP calls.
Contracts and proxy routing
- Adopt the shared Ferrum Contracts plugin catalog and
provisioned-by
vocabulary, with integrity checks for the vendored contracts. - HTTP proxies can opt into RFC 3986 semicolon path parameters with
allow_path_parameters.
Security and reliability
- Starter probes restrict delivery of the trusted-proxy proof to HTTPS or exact
localhostand verified IPv4/IPv6 loopback literals. - Runtime images pin
libpcre2-8-0to10.46-1~deb13u3for CVE-2026-103111. - Production
brace-expansionandfast-uridependencies are updated for
reported denial-of-service and URI parsing vulnerabilities. - Editors now handle masked secret placeholders according to Edge v0.9.9's
write refusal; failed reads across TLS surfaces are shown as unavailable,
not as empty stores.
The complete list is in
CHANGELOG.md.
Known limitations
- One qualified gateway configuration. Modes other than
database, and
Edge releases other than v0.9.10, have not been run in CI. - Scale. Real-gateway testing covers tens of resources per namespace.
Request budgets are measured at 50,000 records against a synthetic gateway;
browser latency is not measured. - One browser. Only Chromium runs in the release gate.
Install
Run the pairing above, both by digest.
docker pull ferrumedge/ferrum-edge@sha256:430d6a7d41361de5ad12562786481f97f1e97fef72a0b5f1a0699eced7cdd4cc
docker pull ferrumedge/ferrum-foundry:v0.4.0 # then pin the digest it resolves to- New deployment: follow Getting started
with the starter, then Deployment
for the production checklist. SetFOUNDRY_IMAGEto the Foundry digest; the
starter's default (:main) is the development channel. FERRUM_JWT_SECRETmust equal the gateway'sFERRUM_ADMIN_JWT_SECRET, and
FERRUM_JWT_AUDIENCEitsFERRUM_ADMIN_JWT_AUDIENCE.
Security
- GHSA-gg76-x87w-mj4v affected v0.2.0 through v0.3.0. Starter probes could
send the trusted-proxy proof secret over plain HTTP to a127.*-prefixed
host that was not actually loopback. Fixed in #507: probes now use HTTPS or
HTTP only for exactlocalhostand verified IPv4/IPv6 loopback literals. - CVE-2026-103111 is an out-of-bounds write in PCRE2. Fixed in #513 by
pinning the runtimelibpcre2-8-0package to Debian's
10.46-1~deb13u3security update.
Upgrading from v0.3.0
Foundry keeps no persistent state of its own, so an upgrade replaces the
Foundry image. This release pairs with Ferrum Edge v0.9.10; follow Edge's own
upgrade guide
when moving from an earlier Edge release. Then deploy the Foundry image by its
release digest and confirm GET /api/health/ready reports version 0.4.0 and
a reachable gateway. Reload open browser tabs to use the new SPA bundle.
No Foundry environment-variable change is required for this upgrade. If you
use the deployment starter, update it with this release so its identity probes
include the GHSA-gg76-x87w-mj4v fix.
Rolling back
- Foundry: redeploy the previous immutable tag or digest. Foundry writes
configuration to Ferrum Edge, so a rollback does not undo configuration
changes made through the newer UI. v0.3.0 is paired with Edge v0.9.8, not
v0.9.10. - Ferrum Edge: follow Ferrum Edge's rollback guidance and take a backup per
namespace before either upgrade.
Docker
docker pull ferrumedge/ferrum-foundry:v0.4.0
docker pull ghcr.io/ferrum-edge/ferrum-foundry:v0.4.0Production quick start
Run Foundry only behind an identity-aware reverse proxy that removes
client-supplied identity headers and injects the trusted proxy proof:
export FERRUM_JWT_SECRET=$(openssl rand -hex 32)
export FERRUM_TRUSTED_PROXY_SECRET=$(openssl rand -hex 32)
docker run \
-e FERRUM_ADMIN_URL=https://your-gateway:9443 \
-e FERRUM_JWT_SECRET \
-e FERRUM_AUTH_MODE=trusted-proxy \
-e FERRUM_TRUSTED_PROXY_SECRET \
-p 127.0.0.1:8080:8080 \
ferrumedge/ferrum-foundry:v0.4.0Configure the proxy to send X-Ferrum-Auth-Secret,
X-Forwarded-User, X-Ferrum-Role, and exact
X-Ferrum-Namespaces grants. See
Production authentication.