Skip to content

WolfStack v25.25.0

Choose a tag to compare

@github-actions github-actions released this 07 Sep 07:28
· 30 commits to master since this release

v25.25.0: WolfHA protects Proxmox-managed containers on ZFS with zfs send

A Proxmox container whose volumes live on a ZFS pool storage can now be
protected: one atomic snapshot of every volume per round, streamed to
each standby as an incremental from the newest shared base, received
straight into zfs receive. Same VMID, same identity, onboot off on the
standby; promotion and failback work as for native containers. Both ends
must be Proxmox hosts running WolfStack with the same pool layout.

Co-Authored-By: CodeWolf paul@wolf.uk.com
Co-Authored-By: IntelligentWolf Ltd paul@wolf.uk.com
Claude-Session: https://claude.ai/code/session_01F6WgFfZnkidT9DuzaYFxeK


Verifying this release

Each binary is signed via cosign keyless OIDC (no key distribution — signing identity is the GitHub Actions workflow itself, anchored to the Sigstore Fulcio CA and the Rekor transparency log) and ships with a SLSA build provenance attestation.

Verify the cosign signature:

cosign verify-blob \
  --bundle wolfstack-x86_64.cosign.bundle \
  --certificate-identity-regexp 'https://github.com/intelligentwolf/WolfStack/\.github/workflows/release\.yml@.*' \
  --certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \
  wolfstack-x86_64

Verify the build provenance:

gh attestation verify wolfstack-x86_64 --repo intelligentwolf/WolfStack

Verify the SHA-256 checksum:

sha256sum -c SHA256SUMS

Artifacts

  • wolfstack-x86_64 / wolfstack-aarch64 / wolfstack-armv7 — static musl binaries (Linux x86_64, ARM64 / Raspberry Pi 4+, and 32-bit ARM).
  • wolfstack-<arch>.cosign.bundle — cosign signature bundle (cert + signature + Rekor entry).
  • SHA256SUMS — checksums for both binaries.

For per-version history see CHANGELOG.md.