Releases: irixsoft/ferrum
Release list
v0.1.2
Run a command in an app from its page, update Ferrum from the Updates card, and Redis instances start.
What's New
- A Run tab on every app that has a process. Type a command and it runs in the app's current release, as the app's user, with the app's environment and toolchain, under the build memory limit and the migration time limit. The output streams live and the last 20 runs stay on the tab with their result.
- Update now on the Updates card in Settings, next to Check now.
- After an update, the tab reloads by itself once the new build answers.
- Redis is set up with
vm.overcommit_memory = 1, as Redis recommends, when it is installed and when Ferrum starts.
Bug Fixes
- A Redis instance requested for an app never started: its configuration named the append-only directory with the wrong directive, and Redis refused the file. Instances made before this release are corrected and started when Ferrum starts.
- Requesting Redis reported success even when Redis exited right after starting. The request now fails with the last lines of the instance's log and leaves nothing behind.
- The update banner could sit above the visible page. It now stays inside the page frame on desktop and inside the header on phones.
Update
From the panel: Settings → Updates → Update now, or ferrum update on the server. A fresh install:
curl -fsSL https://raw.githubusercontent.com/irixsoft/ferrum/main/install.sh | sudo shVerify
Every release ships ferrum-x86_64-unknown-linux-musl, ferrum-aarch64-unknown-linux-musl, SHA256SUMS, SHA256SUMS.sig and ferrum-pub.pem. The installer and the updater check them; by hand:
openssl pkeyutl -verify -pubin -inkey ferrum-pub.pem -rawin -in SHA256SUMS -sigfile SHA256SUMS.sig
sha256sum -c SHA256SUMS --ignore-missingFerrum 0.1.1
System packages follow an app's Aptfile and can be uninstalled with it, unknown names on port 443 are refused, and dumps made with pg_dump --clean load.
What's New
- A deploy reads the tag's
Aptfileand installs what is new in it. The deploy log names what was added and what the file no longer lists. A deploy never uninstalls. - Deleting an app shows which of its packages would be uninstalled, which stay because another app lists them, and which were on the server before Ferrum. You choose.
- Removing a package on the Configuration tab uninstalls it on Save, under the same rule.
- Packages installed before this release are treated as pre-existing and are never removed.
- A default server on port 443 refuses the TLS handshake for any name that has no site.
bunxis available in every Bun toolchain, including ones installed earlier.
Bug Fixes
- A dump made with
pg_dump --cleanfailed to load with "must be owner of extension". ItsDROP EXTENSIONline is now skipped like the other extension lines. - A site could be left without HTTPS when provisioning ran while a build was deleting cache files. Provisioning now touches only its own directories, and the certificate sweep rewrites any site that does not match the certificates on disk.
- A start command that begins with
bunin a Node app, or the reverse, failed at run time although the same tool worked at build time. The unit now gets that toolchain on its PATH.
Update
From the panel: Settings → Updates, or ferrum update on the server. A fresh install:
curl -fsSL https://raw.githubusercontent.com/irixsoft/ferrum/main/install.sh | sudo shVerify
Every release ships ferrum-x86_64-unknown-linux-musl, ferrum-aarch64-unknown-linux-musl, SHA256SUMS, SHA256SUMS.sig and ferrum-pub.pem. The installer and the updater check them; by hand:
openssl pkeyutl -verify -pubin -inkey ferrum-pub.pem -rawin -in SHA256SUMS -sigfile SHA256SUMS.sig
sha256sum -c SHA256SUMS --ignore-missingFerrum 0.1.0
Ferrum deploys your applications to a server you own, from one binary: GitHub in, nginx and a certificate out, PostgreSQL and Redis when an app asks, a panel to run it all. This is the first stable release.
Install
On a fresh Ubuntu 22.04 or 24.04 server, x86_64 or arm64:
curl -fsSL https://raw.githubusercontent.com/irixsoft/ferrum/main/install.sh | sudo shSetup asks for the panel's hostname and an email address, installs nginx, requests the certificate, and prints a single-use link for your first passkey.
Highlights
- Apps from GitHub tags. A private GitHub App per account or organisation, read-only. Pick a repository and a tag; Ferrum inspects the code and prefills the runtime, the commands, the migration script and the environment keys. Every tag you push deploys, with a health check before it counts as live, and one-click rollback that can bring the database snapshot with it.
- Node, Bun, .NET and static sites. Toolchains installed per version and shared. A Bun app builds and runs on Bun alone.
- Environment variables with a
.envimport that never leaves the browser until you click Save. - PostgreSQL installed on first use, one role and password per database, injected as
DATABASE_URL. Create a database blank, or from apg_dumpin custom or plain SQL format taken on any PostgreSQL host: the extensions it needs are turned on for you, and every table ends up owned by the app's role. - Extensions: anything the server offers, searchable, pgvector included.
- Redis per app, password protected, persistent.
- Host hardening in one click each: ufw, fail2ban, unattended security updates, SSH key-only login.
- Signed self-updates. A daily check, a banner, one click. Every release is verified against the Ed25519 key built into the binary before it replaces the running one.
- Your agent. Ferrum is an MCP server; a token, read-only if you like, lets an agent deploy, read logs and manage databases.
Requirements
Ubuntu 22.04 or 24.04, root on a machine that is yours, an A record for the panel's hostname, ports 22, 80 and 443.
Verify
Five assets ship with every release: ferrum-x86_64-unknown-linux-musl, ferrum-aarch64-unknown-linux-musl, SHA256SUMS, SHA256SUMS.sig and ferrum-pub.pem. The installer checks them for you; to do it by hand:
openssl pkeyutl -verify -pubin -inkey ferrum-pub.pem -rawin -in SHA256SUMS -sigfile SHA256SUMS.sig
sha256sum -c SHA256SUMS --ignore-missing