Skip to content

v0.2.0-beta.17

Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 05 Oct 05:11
c451d9b

Note

This is a pre-release on the beta channel. Pin this exact version for anything you care about staying still.

What's changed

Features

  • one-command npm bootstrap and opt-in hands-off releases (#995) by @thegdsks
  • route ingress to apps on remote nodes over the WireGuard mesh (#996) by @thegdsks

Security

  • security review hardening (CSRF, cert purge churn, placeholder escape, git SSRF, hardening default) (#997) by @thegdsks

Bug fixes

  • make node enrolment and mesh work out of the box on the agent image (#983) by @thegdsks
  • Homebrew formula exec bit, npm trusted publishing, split publish jobs (#992) by @thegdsks
  • auth: token ownership, OAuth state binding with PKCE, atomic device redeem (#981) by @thegdsks
  • balance multi-replica apps by default and route the local node's replicas (#994) by @thegdsks
  • app delete tears containers down and retries until gone (#991) by @thegdsks

Install

Fresh install on a Linux host, pinned to this release:

curl -fsSL https://raw.githubusercontent.com/glincker/levelrail/main/install.sh | sudo env LEVELRAIL_VERSION=v0.2.0-beta.17 sh

Upgrade an existing install in place (keeps the unit file and data):

curl -fsSL https://raw.githubusercontent.com/glincker/levelrail/main/install.sh | sudo env LEVELRAIL_VERSION=v0.2.0-beta.17 sh -s upgrade

Docker Compose: pin the image tag in docker-compose.yml:

services:
  levelrail:
    image: ghcr.io/glincker/levelrail:v0.2.0-beta.17

Container images

Multi-arch (linux/amd64, linux/arm64), signed with cosign, SBOM and provenance attached. Also tagged beta at release time (moving tags).

Image Tag Digest
ghcr.io/glincker/levelrail v0.2.0-beta.17 sha256:9bd3e65906f7b1a56ced3237d545a2e5bd0b459499807c58bfcae60affc96fe0
ghcr.io/glincker/levelrail-agent v0.2.0-beta.17 sha256:a4e2872db24c8b27a21a3b78003bbf3fbd5c919ebd07b50583592058bf4fb8ae

Verify

Binaries: check downloads against checksums.txt:

gh release download v0.2.0-beta.17 --repo glincker/levelrail --pattern 'levelrail-linux-amd64' --pattern checksums.txt
sha256sum --ignore-missing -c checksums.txt

Images: verify the keyless signature was made by this repository's release workflow:

cosign verify ghcr.io/glincker/levelrail@sha256:9bd3e65906f7b1a56ced3237d545a2e5bd0b459499807c58bfcae60affc96fe0 \
  --certificate-identity-regexp '^https://github\.com/glincker/levelrail/\.github/workflows/release\.yml@refs/(heads/main|tags/v.+)$' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

Contributors

Thanks to @thegdsks.

Full changelog: v0.2.0-beta.16...v0.2.0-beta.17 | Release page | Installing | Upgrading | Verifying signatures