Skip to content

Ferrum Foundry v0.4.0

Choose a tag to compare

@github-actions github-actions released this 01 Oct 14:18
· 32 commits to main since this release
cb6dbe5

Ferrum Foundry v0.4.0

Foundry v0.4.0 pairs with the published Ferrum Edge v0.9.10 release. It
adds an MCP tool catalog and per-tool policy editing, adopts the Ferrum
Contracts catalog, and supports allow_path_parameters on HTTP proxies. It
also includes security fixes for starter identity probes and the container's
PCRE2 runtime library. Changes since
v0.3.0:
git log v0.3.0..v0.4.0.

Supported pairing

Foundry v0.4.0 — ferrumedge/ferrum-foundry:v0.4.0, linux/amd64 and linux/arm64. Deploy it by the multi-architecture digest this release's run publishes
Ferrum Edge Ferrum Edge v0.9.10 — ferrumedge/ferrum-edge@sha256:430d6a7d41361de5ad12562786481f97f1e97fef72a0b5f1a0699eced7cdd4cc, commit ee040d5e3281fde424aa65f5b18004852c5b53b0; linux/amd64 sha256:18a8a962ad13bacb2505a122330bb25ce921b21a2f3cb5362a6ea93f11fe44d5, linux/arm64 sha256:c35253bed87153afa6e193074f9b644eb3feeedb35459d1c15de5a23a78e4891
Tested gateway database mode on SQLite, writable and with FERRUM_ADMIN_READ_ONLY=true; admin JWT with audience and namespace-claim enforcement
Tested access trusted-proxy authentication through the starter's identity proxy; viewer, operator, and admin
Tested browser Chromium (the build bundled with Playwright 1.63.0)
CI evidence #524, which qualified v0.9.10, and this release's Pre-publication Gates, which rerun every gate against the same image before anything is published

Best-effort: PostgreSQL/MySQL database mode, cp mode, other browsers,
Kubernetes, and static-token authentication (development only). Not qualified:
file/dp/mesh/node_agent modes (so the mesh, waypoint, trust, and
chargeback pages), any other Edge release, and any other Edge image, including
the 0.9.10-ebpf and 0.9.10-ebpf-tools variants. The full envelope, including
tested scale, is in
docs/compatibility.md.

Ferrum Edge v0.9.10 includes ferrum-edge#5954: mcp_gateway and
ai_prompt_shield reject non-UTF-8 charset inputs and fail closed on
uninspectable or over-nested JSON-RPC batches (GHSA-4f9m-cfqg-fhx9,
GHSA-f2jp-59r9-fp64). These changes do not alter the admin API or the plugin
sensitivity rules Foundry uses. It also retains ferrum-edge#5661 conditional
writes and ferrum-edge#5726's proxy-scoped plugin configuration filter.

Highlights since v0.3.0

MCP tools

  • Proxy pages show the node-local cached tool catalog for mcp_gateway, its
    source, annotations, configured and effective policy, grants, refresh state,
    and errors. The tab explains when a control plane does not serve the catalog.
  • Edit one tool's allow, deny, discovery visibility, and group grants inline
    through guarded writes. An AI governance summary shows whether tool-related
    protections and rate limits cover MCP calls.

Contracts and proxy routing

  • Adopt the shared Ferrum Contracts plugin catalog and provisioned-by
    vocabulary, with integrity checks for the vendored contracts.
  • HTTP proxies can opt into RFC 3986 semicolon path parameters with
    allow_path_parameters.

Security and reliability

  • Starter probes restrict delivery of the trusted-proxy proof to HTTPS or exact
    localhost and verified IPv4/IPv6 loopback literals.
  • Runtime images pin libpcre2-8-0 to 10.46-1~deb13u3 for CVE-2026-103111.
  • Production brace-expansion and fast-uri dependencies are updated for
    reported denial-of-service and URI parsing vulnerabilities.
  • Editors now handle masked secret placeholders according to Edge v0.9.9's
    write refusal; failed reads across TLS surfaces are shown as unavailable,
    not as empty stores.

The complete list is in
CHANGELOG.md.

Known limitations

  • One qualified gateway configuration. Modes other than database, and
    Edge releases other than v0.9.10, have not been run in CI.
  • Scale. Real-gateway testing covers tens of resources per namespace.
    Request budgets are measured at 50,000 records against a synthetic gateway;
    browser latency is not measured.
  • One browser. Only Chromium runs in the release gate.

Install

Run the pairing above, both by digest.

docker pull ferrumedge/ferrum-edge@sha256:430d6a7d41361de5ad12562786481f97f1e97fef72a0b5f1a0699eced7cdd4cc
docker pull ferrumedge/ferrum-foundry:v0.4.0   # then pin the digest it resolves to
  • New deployment: follow Getting started
    with the starter, then Deployment
    for the production checklist. Set FOUNDRY_IMAGE to the Foundry digest; the
    starter's default (:main) is the development channel.
  • FERRUM_JWT_SECRET must equal the gateway's FERRUM_ADMIN_JWT_SECRET, and
    FERRUM_JWT_AUDIENCE its FERRUM_ADMIN_JWT_AUDIENCE.

Security

  • GHSA-gg76-x87w-mj4v affected v0.2.0 through v0.3.0. Starter probes could
    send the trusted-proxy proof secret over plain HTTP to a 127.*-prefixed
    host that was not actually loopback. Fixed in #507: probes now use HTTPS or
    HTTP only for exact localhost and verified IPv4/IPv6 loopback literals.
  • CVE-2026-103111 is an out-of-bounds write in PCRE2. Fixed in #513 by
    pinning the runtime libpcre2-8-0 package to Debian's
    10.46-1~deb13u3 security update.

Upgrading from v0.3.0

Foundry keeps no persistent state of its own, so an upgrade replaces the
Foundry image. This release pairs with Ferrum Edge v0.9.10; follow Edge's own
upgrade guide
when moving from an earlier Edge release. Then deploy the Foundry image by its
release digest and confirm GET /api/health/ready reports version 0.4.0 and
a reachable gateway. Reload open browser tabs to use the new SPA bundle.

No Foundry environment-variable change is required for this upgrade. If you
use the deployment starter, update it with this release so its identity probes
include the GHSA-gg76-x87w-mj4v fix.

Rolling back

  • Foundry: redeploy the previous immutable tag or digest. Foundry writes
    configuration to Ferrum Edge, so a rollback does not undo configuration
    changes made through the newer UI. v0.3.0 is paired with Edge v0.9.8, not
    v0.9.10.
  • Ferrum Edge: follow Ferrum Edge's rollback guidance and take a backup per
    namespace before either upgrade.

Docker

docker pull ferrumedge/ferrum-foundry:v0.4.0
docker pull ghcr.io/ferrum-edge/ferrum-foundry:v0.4.0

Production quick start

Run Foundry only behind an identity-aware reverse proxy that removes
client-supplied identity headers and injects the trusted proxy proof:

export FERRUM_JWT_SECRET=$(openssl rand -hex 32)
export FERRUM_TRUSTED_PROXY_SECRET=$(openssl rand -hex 32)

docker run \
  -e FERRUM_ADMIN_URL=https://your-gateway:9443 \
  -e FERRUM_JWT_SECRET \
  -e FERRUM_AUTH_MODE=trusted-proxy \
  -e FERRUM_TRUSTED_PROXY_SECRET \
  -p 127.0.0.1:8080:8080 \
  ferrumedge/ferrum-foundry:v0.4.0

Configure the proxy to send X-Ferrum-Auth-Secret,
X-Forwarded-User, X-Ferrum-Role, and exact
X-Ferrum-Namespaces grants. See
Production authentication.