Releases: hrishikeshdkakkad/fluidbox
Release list
v0.8.0
0.8.0 (2026-08-15)
Added
- web: six-section IA — real activity/resources routes, derived breadcrumbs, focus (0e940cd)
- web: the delight pass — activity workbench, warm kernel, real tables (4b1a452)
- web: the delight pass — activity workbench, warm kernel, real tables (f5f5060)
- web: the public/private boundary — one product, chrome that knows you (8fb8329)
Fixed
- web,login: confirm destructive revokes, give the sign-in refusal a way back (e37bbf2)
- web: gate the design scales and fix four user-visible defects (f4dfd1d)
- web: gate the design scales, fix four user-visible defects, and close three high-severity findings (bbf27d2)
- web: restore the run primary and stop the email overlapping the toggle (3206890)
Changed
v0.7.0
0.7.0 (2026-08-13)
Added
- db: backfill the default policy into every tenant (0030) (f00fb91)
- db: backfill tiered policies into existing tenants (0029) (f8efc38)
- policy: add open, standard, and governed seed policy tiers (d3d6ab1)
- policy: rename the open tier to unrestricted (0031) (0246036)
- policy: tiered seed policies — unrestricted / standard / governed (7b4b088)
- web: make an agent's declared egress visible, and declarable at creation (44bc3f7)
- web: make an agent's declared egress visible, and declarable at creation (e417112)
Fixed
- cloud,web: cold-start enforcement deadline + collapse the grant card on Overview (1d6373e)
- cloud,web: cold-start enforcement deadline + E2E scenario matrix evidence (2f25b2f)
- doctor: repair the RLS check, which could never pass (0fc1383)
- doctor: repair the RLS check, which could never pass (ab98009)
- orgs: seed default and tiered policies when an org is created (0315de9)
- policy: close the governed shell hole and three review findings (509a42c)
- web: close the network-grant UI review findings (78adc96)
- web: close the network-grant UI review findings (10a7166)
Documentation
v0.6.0
0.6.0 (2026-08-05)
Added
- api: report the resolved network enforcer so the dashboard cannot offer what it cannot enforce (82d880d)
- cloud: turn on governed network access — chart 0.5.1 + the Cilium enforcer (e94729a)
- network-grant dashboard UI — govern sandbox egress from the dashboard (5f6287e)
- web: authorize a parked network grant from the timeline (ca0b2da)
- web: declare an agent's network needs on a revision (13ee4a6)
- web: edit the sandbox egress ceiling in Governance (e0c9957)
- web: narrow a single run to offline from the composer (b0d0ff0)
- web: shared target editor for network grant rules (c39895f)
- web: type mirrors and presentation helpers for network grants (4b6fa7d)
Fixed
- web,api: review fixes — preserve the allow catalog across ceiling switches, never fabricate a declaration, persist and reset the run narrowing choice, pin enforcer delegation (21108b4)
Documentation
v0.5.1
0.5.1 (2026-08-04)
Fixed
- chart: the controlled resolver could not exec — grant it NET_BIND_SERVICE (d5ccd59)
- chart: the controlled resolver could not exec — grant it NET_BIND_SERVICE (dd1382d)
- network: a CAS answers "did I win", never "is there work left" (75d7e61)
- network: a CAS loser must distinguish "someone else won" from "resolved away" (256a723)
- network: a DNS deny Cilium cannot express, plus the third review's blockers (786b86d)
- network: close the review's blocking findings (991deb5)
- network: close the second review's blockers, including a race my own fix added (494ac12)
- network: disambiguate legacy deny snapshots, and reconcile live grants (343b60b)
- network: fail closed at the renderer, and align adoption with ownership (8c226ef)
- network: reconcile from the datapath, and bound the schema in both directions (ea3fec9)
- network: scope DNS lookups to the grant, align the deny wall, correct the order (a8ae238)
- network: ten security fixes for governed network access (nine review rounds) (4ee659d)
v0.5.0
0.5.0 (2026-08-04)
Added
- core: bounded denied-flow observation + EKS acceptance runbook (b0ddb5d)
- core: network grant domain, authorization pause, Cilium spike findings (1145e6e)
- Enterprise Recipes — versioned templates that stamp governed automations (dcacd9b)
- governed sandbox network access (d006881)
- k8s: actually program the per-run network policy at provision (29fa915)
- k8s: Cilium enforcer + verify() at provision (d491bc1)
- k8s: Cilium provider seam, per-run policy lowering, chart-static wall (9d9c2ac)
- k8s: implement the Cilium enforcer and invoke verify() at provision (7df0baf)
- server: resolve, park, and revoke sandbox network grants (96def7a)
Documentation
- network-grant runbook, design doc, threat-model residuals, claim fixes (d317ade)
v0.4.0
0.4.0 (2026-07-31)
� BREAKING CHANGES
- policies: fold managed overrides into head rules in the engine
Added
- audience-scoped sandbox credentials � llm/tool/control/workspace split (#33) (fa87936)
- bring your own MCP server, intuitively + authoritative harness/model (#24) (ac7653f)
- broker,db: tear down upstream MCP sessions from any replica (#34) (7007ac5)
- capabilities: design-doc Phase 5 � capability & MCP catalog (c31f3e0)
- catalog: connector-catalog bulk import � MCP Registry (primary) + open-connector (supplement) (#25) (6ee603e)
- catalog: decorate entries with live connection/bundle state; connected cards get Disconnect/Reconnect (b1da355)
- chart: archive object store and replica declaration (#34) (95ad63d)
- ci,dx: non-vacuous CI, supply-chain gate, GHCR distribution, user guides, policy proptests (#22) (7aabf3b)
- ci: prove the permission gate with no model spend, and gate it on every PR (0e49849)
- ci: secrets acceptance matrix � KMS, invariant 20, virtual keys, RLS (#32,#75) (3bb321d)
- codex: codex-runner image + app-server supervisor; facade strips server tools (Phase 6 step 6) (b13a8ab)
- connectors: Phase 5.5 � connector catalog & OAuth credential custody (81e1887)
- core,server: frozen-schema argument enforcement at the gate (#33) (708cecc)
- core: connection requirements + run-binding fields on RunSpec (#31) (d72aedc)
- core: event invocation context + github result destinations + TrustTier::as_str (a6ed044)
- core: read-only trust tier classifier (fork events review, never write) (b9af0a8)
- db,server,chart: remove the ceilings that made 300 concurrent runs impossible (#34) (e7ecb3d)
- db: 0013 appendix � legacy brokered bundles to connection requirements, subscriptions repointed (#31) (4de4e9c)
- db: atomic subscription+schedule update with stale guard (042655c)
- db: event delivery/dispatch/external-result tables + trust-tier & dispatch binding (migration 0005) (0891d45)
- db: identity layer � migration 0012, TenantScope, identity repositories (#30) (86395a8)
- db: migration 0013 � connection ownership, tool snapshots, run resource bindings (#31) (b632736)
- db: RLS policies + tenant GUC plumbing, wave A (#32,#75) (9f27a47)
- db: RLS wave B � identity + audited system_worker bypass (#32,#75) (cd5f00d)
- demo: fixture repo + demo compose (3c1f5c9)
- demo: just demo � five-minute no-key first-run + validation drills (007da29)
- dev: local Postgres container replaces Neon for local development (21c5b03)
- docs,web: public /docs platform � relocated engine, search, new guides (f3b4454)
- docs,web: repo docs tree + in-app /developer docs engine (7865c42)
- durable automation API contract, PATCH /v1/triggers/{id}, self-explanatory template box (db19dba)
- dx: one-command bootstrap (just setup) + environment preflight (just doctor) (d4bb3b9)
- dx: one-command bootstrap (just setup) + environment preflight (just doctor) (3ae195c)
- e2e: codex phase 10 (protocol replay + no-model probes + live tier) + deploy wiring (Phase 6 step 8) (95abec5)
- facade+gate: second dialect enforcement boundary, OpenAI metering, intent-based tool budget, approval digest binding (Phase 6 step 4) (955bc57)
- github: expose updated_at/pushed_at in the repo picker projection (c3c12f1)
- github: Phase 5.6 � seamless GitHub connect via App manifest + install dances (c56638f)
- governance: the Governance page � per-tool permissions matrix + managed overrides (#36) (e7a253f)
- governor,db: cross-replica egress governance � durable rate windows + breaker (#34) (023c151)
- harness: server-side harness registry; per-harness API defaults; orchestrator env seam (Phase 6 steps 1-3) (fd2b266)
- k8s: Phase 0 � provider seam + collection hardening (Docker-only) (#49) (7930e96)
- k8s: Phase 1 � KubernetesProvider + workspaced collector + dual listener (#50) (223e5e8)
- k8s: Phase 2 � Helm chart + verified network hardening + per-cloud presets (#51) (336bc92)
- k8s: Phase 3 � CI + provider conformance (#52) (8c54b7b)
- phase-f: Codex review gate fixes + operational metrics (#34) ([54df7e0](https://github.com/hrishikeshdkakkad/fluidbox...
v0.3.0 — multi-user MCP control plane
Multi-user MCP control plane. Six phases (A–F) and migrations 0011→0025 turn fluidbox from a single-admin control plane into one that can host many organizations, many users, and many separately-owned credentials without ever letting a model pick an identity.
Every hosted capability is opt-in behind a flag, and the default single-admin Docker deployment is the same product it was in v0.2.0 — with FLUIDBOX_REQUIRE_SSO unset, nothing below is active.
The organizing idea: connector definition ≠ credential-bearing connection ≠ agent connection requirement ≠ per-run resource binding. An agent declares what it requires, never whose credential satisfies it. Run creation resolves each requirement to an explicit, frozen authority source before any model spend. The model picks tools; it can never pick an identity.
Highlights
- Per-organization, IdP-agnostic identity —
FLUIDBOX_REQUIRE_SSO=1confines the admin token to/v1/admin/*as break-glass and introduces three principals: Operator (admin token), User (__Host-fbx_websession cookie), and Pat (fbx_pat_bearer). Any conformant OIDC issuer is configured per org. No IdP configured ⇒ single-admin mode, unchanged. - Tenant isolation with a database floor — every tenant-owned repository method takes a
TenantScope, making isolation a signature requirement rather than a remember-to-filter convention. Migration0018adds row-level security underneath: 37 tablesENABLE+FORCERLS keyed on a transaction-local GUC, withFLUIDBOX_RUNTIME_ROLEsplitting the pool onto a non-owner role. - Connection ownership and per-run resource bindings — brokered MCP tools moved onto four objects, resolved to a tagged authority (
connection|subscription_secret|none) across typed slots before provisioning. A personal-connection approval is decidable only by its owner-who-invoked — no role, admin, or operator override. - Versioned envelope sealing with a real key-retirement path — per-tenant DEKs wrapped by a KEK (
FLUIDBOX_KMS_MODE=off|static|aws), AAD-bound so a sealed blob is untransplantable across tenants or columns. A resumable, CAS-guardedPOST /v1/admin/resealmigrates legacy rows; two boot gates fail closed in both directions. - One hardened egress boundary — a pure
admit_urlpre-flight blocks private/loopback/link-local/metadata address classes at every dial site (reqwest dials an IP literal without consulting a resolver, so the pre-flight is what actually stops169.254.169.254). Broker, delivery callbacks, and both connector-OAuth token legs refuse redirects outright — a 307/308 replays the request body, which would forward an authorization code plus PKCE verifier to the redirect target. - MCP
2025-11-25conformance — per-run upstream sessions; a negotiated version that drifts from the frozen surface denies the call. - Frozen tool schemas enforced server-side — arguments validated against the schema photographed at freeze time, dialect chosen by the snapshot's protocol version. Exactly one new stage in the permission gate; nothing else moved.
- At-most-once brokered dispatch — a durable four-state execution claim per call. Decision idempotency and execution idempotency are now distinct properties.
- Audience-scoped sandbox credentials — the sandbox's single bearer splits into four tokens (
llm|tool|control|workspace). - Replica coordination + durable budget admission — approval emission rides the deciding CAS, orchestrator leases with epoch fencing, per-row delivery claims, and request-keyed LLM reservations.
- Operations — bounded-cardinality metrics at
GET /v1/admin/metrics, durable cross-replica egress governance, S3-compatible archives, and a guarded load harness.
Validation
Five hermetic acceptance suites green against CI-identical throwaway databases — identity 87/0, bindings 104/0, secrets 128/0, hardening 274/0, scale 18/0 = 611/0 — plus live Docker-provider tiers and a second live EKS acceptance on arm64/Graviton with the runtime-role RLS split active and an AWS-audited zero-orphan teardown.
Known limitations
The gated 60/150/300-seat load campaign and the final two rollout gates remain open on #34. This release does not claim a proven 300-run production ceiling. The hosted OAuth Connect flow also carries one documented residual: a deliberately-shared start URL can still route a victim's grant into the initiating connection (docs/hosted/threat-model.md).
Upgrading
Migration 0018 is stop the old binary, migrate, then deploy — not a rolling upgrade. A pre-0018 binary sets no tenant GUC and would see zero rows, and it holds transactions across outbound HTTP that would block the migration's ACCESS EXCLUSIVE locks.
Do not drop FLUIDBOX_CREDENTIAL_KEY when enabling FLUIDBOX_KMS_MODE: run POST /v1/admin/reseal and let boot prove zero remaining v1 rows first. From the moment any v2 row exists, the KEK is the root of custody and losing it is unrecoverable — back it up before enabling.
Full changelog: CHANGELOG.md · Hosted deployment: rollout gates and KMS/RLS runbook
helm install fluidbox oci://ghcr.io/hrishikeshdkakkad/charts/fluidbox --version 0.3.0v0.2.0 — Kubernetes-native execution provider
What's Changed
- feat(dx): one-command bootstrap (just setup) + environment preflight (just doctor) by @hrishikeshdkakkad in #21
- feat(ci,dx): non-vacuous CI, supply-chain gate, GHCR distribution, user guides, policy proptests by @hrishikeshdkakkad in #22
- fix(e2e): make no-live mode zero-spend and deterministic (closes the CI flake class) by @hrishikeshdkakkad in #23
- feat: bring your own MCP server, intuitively + authoritative harness/model by @hrishikeshdkakkad in #24
- feat(catalog): connector-catalog bulk import — MCP Registry (primary) + open-connector (supplement) by @hrishikeshdkakkad in #25
- feat(web): unify dashboard and run workflows by @hrishikeshdkakkad in #26
- feat(governance): the Governance page — per-tool permissions matrix + managed overrides by @hrishikeshdkakkad in #36
- docs(web): run-composer pickers — unleak connections, one card vocabulary, working + new by @hrishikeshdkakkad in #42
- feat(scripts): db-clean-tests — a scalpel for test residue, not a reset by @hrishikeshdkakkad in #46
- docs(handovers): commit 2026-07-13 + 2026-07-14 session briefs by @hrishikeshdkakkad in #53
- K8s Phase 0 — provider seam + collection hardening (Docker-only) (#49) by @hrishikeshdkakkad in #54
- K8s Phase 1 — KubernetesProvider + workspaced collector + dual listener (#50) by @hrishikeshdkakkad in #55
- K8s Phase 2 — Helm chart + verified network hardening + per-cloud presets (#51) by @hrishikeshdkakkad in #56
- K8s Phase 3 — CI + provider conformance (#52) by @hrishikeshdkakkad in #57
- fix(k8s): install ring CryptoProvider so the Kubernetes provider boots by @hrishikeshdkakkad in #58
- fix(k8s): numeric runAsUser for bundled LiteLLM by @hrishikeshdkakkad in #59
- fix(k8s): make the kind-calico CI tier a real check (H1) by @hrishikeshdkakkad in #60
- fix(k8s): extract in-tree symlinks in the workspace archive (H4, L4-pack) by @hrishikeshdkakkad in #61
- fix(k8s): helm↔provider wiring — sandbox values reach the provider, digests render, probe gate parity (M3, M9, M10, L12) by @hrishikeshdkakkad in #66
- fix(k8s): reconcile — periodic adopt-or-terminate sweep, graded config errors, node-loss visibility, Docker-parity pre-launch diffs (M5, M6, M7, L9) by @hrishikeshdkakkad in #68
- fix(k8s): cleanups — fail-closed gate resolution, UID-guarded deletes, quiesce replay (L2, L10, L11) by @hrishikeshdkakkad in #65
- fix(k8s): finalizer durability — the persisted intent is the single source of truth (H2,H3,H5,M1,L6,L7) by @hrishikeshdkakkad in #63
- fix(k8s): listener hardening — no /internal on the public plane under K8s (M8, L1, L5, L8) by @hrishikeshdkakkad in #64
- Kubernetes-native execution provider + Helm deployability (release branch) by @hrishikeshdkakkad in #47
Full Changelog: v0.1.0...v0.2.0
v0.1.0 — the governed vertical slice
The first tagged release: the complete governed vertical slice, verified by a 10-phase live-inclusive acceptance suite (468 checks).
Highlights
- Governed agent runs end to end — frozen RunSpecs, fresh sandboxes, live timelines, policy-gated tool calls with human approvals, and a diff + cost report per run.
- Two harnesses behind one contract — Claude Agent SDK and Codex, with an in-server LLM facade that meters usage and keeps provider keys out of every sandbox.
- Borrow the agent, on demand — API triggers, signed webhooks, cron schedules, and GitHub PR fan-out, all converging on one governed run path.
Added
- Governed runs end to end — versioned agent definitions, immutable per-run
RunSpecsnapshots (model, prompts, policy, capability pins), fresh Docker sandboxes per run, live SSE event timelines withLast-Event-IDresume, and a final diff + cost report. - Policy engine & human approvals — YAML policies evaluated on every tool call (allow / deny / require-approval), idempotent restart-safe approvals with expiry, and an autonomous mode that rewrites approval verdicts to a policy fallback while recording both verdicts.
- Append-only audit ledger — redaction enforced at the type level; prompts never reach the database, only digests, usage, cost, and decisions, with gapless per-session sequencing.
- Two agent harnesses — Claude Agent SDK and Codex runner images behind one HTTP runner contract; the LLM facade speaks both the Anthropic Messages and OpenAI Responses dialects.
- Credential inversion — the sandbox's
ANTHROPIC_API_KEYis a session token; an in-server LLM facade validates it, enforces budget stops, meters streamed usage, and swaps in the real upstream credential held only by the LiteLLM gateway. - Git workspaces — credentialed fetch/copy happens control-plane-side before the agent starts; sandboxes only ever see a bind-mounted copy and stay egress-free.
- Triggers — subscription-scoped API tokens, signed webhook ingress with two-level dedup that heals partial fan-outs, cron schedules with exactly-once firing and explicit missed-run/concurrency policies, and HMAC-signed result delivery with retry/backoff.
- GitHub integration — seamless GitHub App connect (manifest + install flows), PR fan-out with one stable comment per PR and one check per head SHA, and fork PRs frozen to
ReadOnlytrust with no approval escape. - Capability catalog — append-only versioned MCP tool bundles pinned at run creation; sandbox tools run as contained stdio subprocesses while brokered tools execute on the control plane with sealed credentials the sandbox never sees.
- Connector catalog + OAuth — catalog-driven connect flows with PKCE (S256), RFC 8707 resource indicators, DCR/CIMD client identity, sealed refresh tokens with atomic rotation, and fail-closed error states.
- Dashboard — Next.js UI (Runs, Agents, Integrations, Automations, Settings); presentation-only, all logic in the Rust API.
- CLI —
fluidbox run --repo … --task …to drive runs from the terminal. - Ops —
justrecipes for the full dev loop, an end-to-end acceptance suite (just e2e), Neon setup and DB-cleanup scripts, and CI (fmt, clippy-D warnings, tests, dashboard build).
Changed
- Dependency refresh:
sha20.11,hmac0.13,chacha20poly13050.11,jsonwebtoken10 (pinned to the pure-Rustrust_cryptoprovider), React 19.2.7, TypeScript 6, and current GitHub Actions. The sealed-credential wire format (nonce ‖ ciphertext) is unchanged — existing sealed credentials open fine.