Skip to content

Releases: hrishikeshdkakkad/fluidbox

v0.8.0

Choose a tag to compare

@github-actions github-actions released this 15 Aug 05:24
5f0d03e

0.8.0 (2026-08-15)

Added

  • web: six-section IA — real activity/resources routes, derived breadcrumbs, focus (0e940cd)
  • web: the delight pass — activity workbench, warm kernel, real tables (4b1a452)
  • web: the delight pass — activity workbench, warm kernel, real tables (f5f5060)
  • web: the public/private boundary — one product, chrome that knows you (8fb8329)

Fixed

  • web,login: confirm destructive revokes, give the sign-in refusal a way back (e37bbf2)
  • web: gate the design scales and fix four user-visible defects (f4dfd1d)
  • web: gate the design scales, fix four user-visible defects, and close three high-severity findings (bbf27d2)
  • web: restore the run primary and stop the email overlapping the toggle (3206890)

Changed

  • web: fold the 47 duplicate selectors, ratchet the CSS gate 59 -> 10 (ffec520)
  • web: retire 239 of the 298 gated CSS warnings, ratchet 298 -> 59 (54452bd)

v0.7.0

Choose a tag to compare

@github-actions github-actions released this 13 Aug 02:17
938b4c8

0.7.0 (2026-08-13)

Added

  • db: backfill the default policy into every tenant (0030) (f00fb91)
  • db: backfill tiered policies into existing tenants (0029) (f8efc38)
  • policy: add open, standard, and governed seed policy tiers (d3d6ab1)
  • policy: rename the open tier to unrestricted (0031) (0246036)
  • policy: tiered seed policies — unrestricted / standard / governed (7b4b088)
  • web: make an agent's declared egress visible, and declarable at creation (44bc3f7)
  • web: make an agent's declared egress visible, and declarable at creation (e417112)

Fixed

  • cloud,web: cold-start enforcement deadline + collapse the grant card on Overview (1d6373e)
  • cloud,web: cold-start enforcement deadline + E2E scenario matrix evidence (2f25b2f)
  • doctor: repair the RLS check, which could never pass (0fc1383)
  • doctor: repair the RLS check, which could never pass (ab98009)
  • orgs: seed default and tiered policies when an org is created (0315de9)
  • policy: close the governed shell hole and three review findings (509a42c)
  • web: close the network-grant UI review findings (78adc96)
  • web: close the network-grant UI review findings (10a7166)

Documentation

  • cloud: cold-start regression test confirms the netpol deadline fix (9218025)
  • cloud: live acceptance — a granted run reaches the internet (9fb474e)
  • cloud: network-grant UI live acceptance evidence (94bcc6d)

v0.6.0

Choose a tag to compare

@github-actions github-actions released this 05 Aug 00:11
0b3b32a

0.6.0 (2026-08-05)

Added

  • api: report the resolved network enforcer so the dashboard cannot offer what it cannot enforce (82d880d)
  • cloud: turn on governed network access — chart 0.5.1 + the Cilium enforcer (e94729a)
  • network-grant dashboard UI — govern sandbox egress from the dashboard (5f6287e)
  • web: authorize a parked network grant from the timeline (ca0b2da)
  • web: declare an agent's network needs on a revision (13ee4a6)
  • web: edit the sandbox egress ceiling in Governance (e0c9957)
  • web: narrow a single run to offline from the composer (b0d0ff0)
  • web: shared target editor for network grant rules (c39895f)
  • web: type mirrors and presentation helpers for network grants (4b6fa7d)

Fixed

  • web,api: review fixes — preserve the allow catalog across ceiling switches, never fabricate a declaration, persist and reset the run narrowing choice, pin enforcer delegation (21108b4)

Documentation

  • cloud: record the Cilium cutover, its two upstream bugs, and the last mile (33b0524)
  • plan: implementation plan for the network-grant dashboard UI (8dffed5)
  • spec: governed sandbox egress, selectable in the dashboard (395bdab)

v0.5.1

Choose a tag to compare

@github-actions github-actions released this 04 Aug 15:29
9ea787f

0.5.1 (2026-08-04)

Fixed

  • chart: the controlled resolver could not exec — grant it NET_BIND_SERVICE (d5ccd59)
  • chart: the controlled resolver could not exec — grant it NET_BIND_SERVICE (dd1382d)
  • network: a CAS answers "did I win", never "is there work left" (75d7e61)
  • network: a CAS loser must distinguish "someone else won" from "resolved away" (256a723)
  • network: a DNS deny Cilium cannot express, plus the third review's blockers (786b86d)
  • network: close the review's blocking findings (991deb5)
  • network: close the second review's blockers, including a race my own fix added (494ac12)
  • network: disambiguate legacy deny snapshots, and reconcile live grants (343b60b)
  • network: fail closed at the renderer, and align adoption with ownership (8c226ef)
  • network: reconcile from the datapath, and bound the schema in both directions (ea3fec9)
  • network: scope DNS lookups to the grant, align the deny wall, correct the order (a8ae238)
  • network: ten security fixes for governed network access (nine review rounds) (4ee659d)

v0.5.0

Choose a tag to compare

@github-actions github-actions released this 04 Aug 04:48
de74508

0.5.0 (2026-08-04)

Added

  • core: bounded denied-flow observation + EKS acceptance runbook (b0ddb5d)
  • core: network grant domain, authorization pause, Cilium spike findings (1145e6e)
  • Enterprise Recipes — versioned templates that stamp governed automations (dcacd9b)
  • governed sandbox network access (d006881)
  • k8s: actually program the per-run network policy at provision (29fa915)
  • k8s: Cilium enforcer + verify() at provision (d491bc1)
  • k8s: Cilium provider seam, per-run policy lowering, chart-static wall (9d9c2ac)
  • k8s: implement the Cilium enforcer and invoke verify() at provision (7df0baf)
  • server: resolve, park, and revoke sandbox network grants (96def7a)

Documentation

  • network-grant runbook, design doc, threat-model residuals, claim fixes (d317ade)

v0.4.0

Choose a tag to compare

@github-actions github-actions released this 31 Jul 23:30
2101df1

0.4.0 (2026-07-31)

� BREAKING CHANGES

  • policies: fold managed overrides into head rules in the engine

Added

  • audience-scoped sandbox credentials � llm/tool/control/workspace split (#33) (fa87936)
  • bring your own MCP server, intuitively + authoritative harness/model (#24) (ac7653f)
  • broker,db: tear down upstream MCP sessions from any replica (#34) (7007ac5)
  • capabilities: design-doc Phase 5 � capability & MCP catalog (c31f3e0)
  • catalog: connector-catalog bulk import � MCP Registry (primary) + open-connector (supplement) (#25) (6ee603e)
  • catalog: decorate entries with live connection/bundle state; connected cards get Disconnect/Reconnect (b1da355)
  • chart: archive object store and replica declaration (#34) (95ad63d)
  • ci,dx: non-vacuous CI, supply-chain gate, GHCR distribution, user guides, policy proptests (#22) (7aabf3b)
  • ci: prove the permission gate with no model spend, and gate it on every PR (0e49849)
  • ci: secrets acceptance matrix � KMS, invariant 20, virtual keys, RLS (#32,#75) (3bb321d)
  • codex: codex-runner image + app-server supervisor; facade strips server tools (Phase 6 step 6) (b13a8ab)
  • connectors: Phase 5.5 � connector catalog & OAuth credential custody (81e1887)
  • core,server: frozen-schema argument enforcement at the gate (#33) (708cecc)
  • core: connection requirements + run-binding fields on RunSpec (#31) (d72aedc)
  • core: event invocation context + github result destinations + TrustTier::as_str (a6ed044)
  • core: read-only trust tier classifier (fork events review, never write) (b9af0a8)
  • db,server,chart: remove the ceilings that made 300 concurrent runs impossible (#34) (e7ecb3d)
  • db: 0013 appendix � legacy brokered bundles to connection requirements, subscriptions repointed (#31) (4de4e9c)
  • db: atomic subscription+schedule update with stale guard (042655c)
  • db: event delivery/dispatch/external-result tables + trust-tier & dispatch binding (migration 0005) (0891d45)
  • db: identity layer � migration 0012, TenantScope, identity repositories (#30) (86395a8)
  • db: migration 0013 � connection ownership, tool snapshots, run resource bindings (#31) (b632736)
  • db: RLS policies + tenant GUC plumbing, wave A (#32,#75) (9f27a47)
  • db: RLS wave B � identity + audited system_worker bypass (#32,#75) (cd5f00d)
  • demo: fixture repo + demo compose (3c1f5c9)
  • demo: just demo � five-minute no-key first-run + validation drills (007da29)
  • dev: local Postgres container replaces Neon for local development (21c5b03)
  • docs,web: public /docs platform � relocated engine, search, new guides (f3b4454)
  • docs,web: repo docs tree + in-app /developer docs engine (7865c42)
  • durable automation API contract, PATCH /v1/triggers/{id}, self-explanatory template box (db19dba)
  • dx: one-command bootstrap (just setup) + environment preflight (just doctor) (d4bb3b9)
  • dx: one-command bootstrap (just setup) + environment preflight (just doctor) (3ae195c)
  • e2e: codex phase 10 (protocol replay + no-model probes + live tier) + deploy wiring (Phase 6 step 8) (95abec5)
  • facade+gate: second dialect enforcement boundary, OpenAI metering, intent-based tool budget, approval digest binding (Phase 6 step 4) (955bc57)
  • github: expose updated_at/pushed_at in the repo picker projection (c3c12f1)
  • github: Phase 5.6 � seamless GitHub connect via App manifest + install dances (c56638f)
  • governance: the Governance page � per-tool permissions matrix + managed overrides (#36) (e7a253f)
  • governor,db: cross-replica egress governance � durable rate windows + breaker (#34) (023c151)
  • harness: server-side harness registry; per-harness API defaults; orchestrator env seam (Phase 6 steps 1-3) (fd2b266)
  • k8s: Phase 0 � provider seam + collection hardening (Docker-only) (#49) (7930e96)
  • k8s: Phase 1 � KubernetesProvider + workspaced collector + dual listener (#50) (223e5e8)
  • k8s: Phase 2 � Helm chart + verified network hardening + per-cloud presets (#51) (336bc92)
  • k8s: Phase 3 � CI + provider conformance (#52) (8c54b7b)
  • phase-f: Codex review gate fixes + operational metrics (#34) ([54df7e0](https://github.com/hrishikeshdkakkad/fluidbox...
Read more

v0.3.0 — multi-user MCP control plane

Choose a tag to compare

@hrishikeshdkakkad hrishikeshdkakkad released this 24 Jul 18:56
1b87a89

Multi-user MCP control plane. Six phases (A–F) and migrations 00110025 turn fluidbox from a single-admin control plane into one that can host many organizations, many users, and many separately-owned credentials without ever letting a model pick an identity.

Every hosted capability is opt-in behind a flag, and the default single-admin Docker deployment is the same product it was in v0.2.0 — with FLUIDBOX_REQUIRE_SSO unset, nothing below is active.

The organizing idea: connector definition ≠ credential-bearing connection ≠ agent connection requirement ≠ per-run resource binding. An agent declares what it requires, never whose credential satisfies it. Run creation resolves each requirement to an explicit, frozen authority source before any model spend. The model picks tools; it can never pick an identity.

Highlights

  • Per-organization, IdP-agnostic identityFLUIDBOX_REQUIRE_SSO=1 confines the admin token to /v1/admin/* as break-glass and introduces three principals: Operator (admin token), User (__Host-fbx_web session cookie), and Pat (fbx_pat_ bearer). Any conformant OIDC issuer is configured per org. No IdP configured ⇒ single-admin mode, unchanged.
  • Tenant isolation with a database floor — every tenant-owned repository method takes a TenantScope, making isolation a signature requirement rather than a remember-to-filter convention. Migration 0018 adds row-level security underneath: 37 tables ENABLE+FORCE RLS keyed on a transaction-local GUC, with FLUIDBOX_RUNTIME_ROLE splitting the pool onto a non-owner role.
  • Connection ownership and per-run resource bindings — brokered MCP tools moved onto four objects, resolved to a tagged authority (connection | subscription_secret | none) across typed slots before provisioning. A personal-connection approval is decidable only by its owner-who-invoked — no role, admin, or operator override.
  • Versioned envelope sealing with a real key-retirement path — per-tenant DEKs wrapped by a KEK (FLUIDBOX_KMS_MODE=off|static|aws), AAD-bound so a sealed blob is untransplantable across tenants or columns. A resumable, CAS-guarded POST /v1/admin/reseal migrates legacy rows; two boot gates fail closed in both directions.
  • One hardened egress boundary — a pure admit_url pre-flight blocks private/loopback/link-local/metadata address classes at every dial site (reqwest dials an IP literal without consulting a resolver, so the pre-flight is what actually stops 169.254.169.254). Broker, delivery callbacks, and both connector-OAuth token legs refuse redirects outright — a 307/308 replays the request body, which would forward an authorization code plus PKCE verifier to the redirect target.
  • MCP 2025-11-25 conformance — per-run upstream sessions; a negotiated version that drifts from the frozen surface denies the call.
  • Frozen tool schemas enforced server-side — arguments validated against the schema photographed at freeze time, dialect chosen by the snapshot's protocol version. Exactly one new stage in the permission gate; nothing else moved.
  • At-most-once brokered dispatch — a durable four-state execution claim per call. Decision idempotency and execution idempotency are now distinct properties.
  • Audience-scoped sandbox credentials — the sandbox's single bearer splits into four tokens (llm | tool | control | workspace).
  • Replica coordination + durable budget admission — approval emission rides the deciding CAS, orchestrator leases with epoch fencing, per-row delivery claims, and request-keyed LLM reservations.
  • Operations — bounded-cardinality metrics at GET /v1/admin/metrics, durable cross-replica egress governance, S3-compatible archives, and a guarded load harness.

Validation

Five hermetic acceptance suites green against CI-identical throwaway databases — identity 87/0, bindings 104/0, secrets 128/0, hardening 274/0, scale 18/0 = 611/0 — plus live Docker-provider tiers and a second live EKS acceptance on arm64/Graviton with the runtime-role RLS split active and an AWS-audited zero-orphan teardown.

Known limitations

The gated 60/150/300-seat load campaign and the final two rollout gates remain open on #34. This release does not claim a proven 300-run production ceiling. The hosted OAuth Connect flow also carries one documented residual: a deliberately-shared start URL can still route a victim's grant into the initiating connection (docs/hosted/threat-model.md).

Upgrading

Migration 0018 is stop the old binary, migrate, then deploy — not a rolling upgrade. A pre-0018 binary sets no tenant GUC and would see zero rows, and it holds transactions across outbound HTTP that would block the migration's ACCESS EXCLUSIVE locks.

Do not drop FLUIDBOX_CREDENTIAL_KEY when enabling FLUIDBOX_KMS_MODE: run POST /v1/admin/reseal and let boot prove zero remaining v1 rows first. From the moment any v2 row exists, the KEK is the root of custody and losing it is unrecoverable — back it up before enabling.


Full changelog: CHANGELOG.md · Hosted deployment: rollout gates and KMS/RLS runbook

helm install fluidbox oci://ghcr.io/hrishikeshdkakkad/charts/fluidbox --version 0.3.0

v0.2.0 — Kubernetes-native execution provider

Choose a tag to compare

@hrishikeshdkakkad hrishikeshdkakkad released this 17 Jul 03:18
0ad2e8b

What's Changed

  • feat(dx): one-command bootstrap (just setup) + environment preflight (just doctor) by @hrishikeshdkakkad in #21
  • feat(ci,dx): non-vacuous CI, supply-chain gate, GHCR distribution, user guides, policy proptests by @hrishikeshdkakkad in #22
  • fix(e2e): make no-live mode zero-spend and deterministic (closes the CI flake class) by @hrishikeshdkakkad in #23
  • feat: bring your own MCP server, intuitively + authoritative harness/model by @hrishikeshdkakkad in #24
  • feat(catalog): connector-catalog bulk import — MCP Registry (primary) + open-connector (supplement) by @hrishikeshdkakkad in #25
  • feat(web): unify dashboard and run workflows by @hrishikeshdkakkad in #26
  • feat(governance): the Governance page — per-tool permissions matrix + managed overrides by @hrishikeshdkakkad in #36
  • docs(web): run-composer pickers — unleak connections, one card vocabulary, working + new by @hrishikeshdkakkad in #42
  • feat(scripts): db-clean-tests — a scalpel for test residue, not a reset by @hrishikeshdkakkad in #46
  • docs(handovers): commit 2026-07-13 + 2026-07-14 session briefs by @hrishikeshdkakkad in #53
  • K8s Phase 0 — provider seam + collection hardening (Docker-only) (#49) by @hrishikeshdkakkad in #54
  • K8s Phase 1 — KubernetesProvider + workspaced collector + dual listener (#50) by @hrishikeshdkakkad in #55
  • K8s Phase 2 — Helm chart + verified network hardening + per-cloud presets (#51) by @hrishikeshdkakkad in #56
  • K8s Phase 3 — CI + provider conformance (#52) by @hrishikeshdkakkad in #57
  • fix(k8s): install ring CryptoProvider so the Kubernetes provider boots by @hrishikeshdkakkad in #58
  • fix(k8s): numeric runAsUser for bundled LiteLLM by @hrishikeshdkakkad in #59
  • fix(k8s): make the kind-calico CI tier a real check (H1) by @hrishikeshdkakkad in #60
  • fix(k8s): extract in-tree symlinks in the workspace archive (H4, L4-pack) by @hrishikeshdkakkad in #61
  • fix(k8s): helm↔provider wiring — sandbox values reach the provider, digests render, probe gate parity (M3, M9, M10, L12) by @hrishikeshdkakkad in #66
  • fix(k8s): reconcile — periodic adopt-or-terminate sweep, graded config errors, node-loss visibility, Docker-parity pre-launch diffs (M5, M6, M7, L9) by @hrishikeshdkakkad in #68
  • fix(k8s): cleanups — fail-closed gate resolution, UID-guarded deletes, quiesce replay (L2, L10, L11) by @hrishikeshdkakkad in #65
  • fix(k8s): finalizer durability — the persisted intent is the single source of truth (H2,H3,H5,M1,L6,L7) by @hrishikeshdkakkad in #63
  • fix(k8s): listener hardening — no /internal on the public plane under K8s (M8, L1, L5, L8) by @hrishikeshdkakkad in #64
  • Kubernetes-native execution provider + Helm deployability (release branch) by @hrishikeshdkakkad in #47

Full Changelog: v0.1.0...v0.2.0

v0.1.0 — the governed vertical slice

Choose a tag to compare

@hrishikeshdkakkad hrishikeshdkakkad released this 12 Jul 23:17

The first tagged release: the complete governed vertical slice, verified by a 10-phase live-inclusive acceptance suite (468 checks).

Highlights

  • Governed agent runs end to end — frozen RunSpecs, fresh sandboxes, live timelines, policy-gated tool calls with human approvals, and a diff + cost report per run.
  • Two harnesses behind one contract — Claude Agent SDK and Codex, with an in-server LLM facade that meters usage and keeps provider keys out of every sandbox.
  • Borrow the agent, on demand — API triggers, signed webhooks, cron schedules, and GitHub PR fan-out, all converging on one governed run path.

Added

  • Governed runs end to end — versioned agent definitions, immutable per-run RunSpec snapshots (model, prompts, policy, capability pins), fresh Docker sandboxes per run, live SSE event timelines with Last-Event-ID resume, and a final diff + cost report.
  • Policy engine & human approvals — YAML policies evaluated on every tool call (allow / deny / require-approval), idempotent restart-safe approvals with expiry, and an autonomous mode that rewrites approval verdicts to a policy fallback while recording both verdicts.
  • Append-only audit ledger — redaction enforced at the type level; prompts never reach the database, only digests, usage, cost, and decisions, with gapless per-session sequencing.
  • Two agent harnesses — Claude Agent SDK and Codex runner images behind one HTTP runner contract; the LLM facade speaks both the Anthropic Messages and OpenAI Responses dialects.
  • Credential inversion — the sandbox's ANTHROPIC_API_KEY is a session token; an in-server LLM facade validates it, enforces budget stops, meters streamed usage, and swaps in the real upstream credential held only by the LiteLLM gateway.
  • Git workspaces — credentialed fetch/copy happens control-plane-side before the agent starts; sandboxes only ever see a bind-mounted copy and stay egress-free.
  • Triggers — subscription-scoped API tokens, signed webhook ingress with two-level dedup that heals partial fan-outs, cron schedules with exactly-once firing and explicit missed-run/concurrency policies, and HMAC-signed result delivery with retry/backoff.
  • GitHub integration — seamless GitHub App connect (manifest + install flows), PR fan-out with one stable comment per PR and one check per head SHA, and fork PRs frozen to ReadOnly trust with no approval escape.
  • Capability catalog — append-only versioned MCP tool bundles pinned at run creation; sandbox tools run as contained stdio subprocesses while brokered tools execute on the control plane with sealed credentials the sandbox never sees.
  • Connector catalog + OAuth — catalog-driven connect flows with PKCE (S256), RFC 8707 resource indicators, DCR/CIMD client identity, sealed refresh tokens with atomic rotation, and fail-closed error states.
  • Dashboard — Next.js UI (Runs, Agents, Integrations, Automations, Settings); presentation-only, all logic in the Rust API.
  • CLIfluidbox run --repo … --task … to drive runs from the terminal.
  • Opsjust recipes for the full dev loop, an end-to-end acceptance suite (just e2e), Neon setup and DB-cleanup scripts, and CI (fmt, clippy -D warnings, tests, dashboard build).

Changed

  • Dependency refresh: sha2 0.11, hmac 0.13, chacha20poly1305 0.11, jsonwebtoken 10 (pinned to the pure-Rust rust_crypto provider), React 19.2.7, TypeScript 6, and current GitHub Actions. The sealed-credential wire format (nonce ‖ ciphertext) is unchanged — existing sealed credentials open fine.