Ferrum 0.1.0
Ferrum deploys your applications to a server you own, from one binary: GitHub in, nginx and a certificate out, PostgreSQL and Redis when an app asks, a panel to run it all. This is the first stable release.
Install
On a fresh Ubuntu 22.04 or 24.04 server, x86_64 or arm64:
curl -fsSL https://raw.githubusercontent.com/irixsoft/ferrum/main/install.sh | sudo shSetup asks for the panel's hostname and an email address, installs nginx, requests the certificate, and prints a single-use link for your first passkey.
Highlights
- Apps from GitHub tags. A private GitHub App per account or organisation, read-only. Pick a repository and a tag; Ferrum inspects the code and prefills the runtime, the commands, the migration script and the environment keys. Every tag you push deploys, with a health check before it counts as live, and one-click rollback that can bring the database snapshot with it.
- Node, Bun, .NET and static sites. Toolchains installed per version and shared. A Bun app builds and runs on Bun alone.
- Environment variables with a
.envimport that never leaves the browser until you click Save. - PostgreSQL installed on first use, one role and password per database, injected as
DATABASE_URL. Create a database blank, or from apg_dumpin custom or plain SQL format taken on any PostgreSQL host: the extensions it needs are turned on for you, and every table ends up owned by the app's role. - Extensions: anything the server offers, searchable, pgvector included.
- Redis per app, password protected, persistent.
- Host hardening in one click each: ufw, fail2ban, unattended security updates, SSH key-only login.
- Signed self-updates. A daily check, a banner, one click. Every release is verified against the Ed25519 key built into the binary before it replaces the running one.
- Your agent. Ferrum is an MCP server; a token, read-only if you like, lets an agent deploy, read logs and manage databases.
Requirements
Ubuntu 22.04 or 24.04, root on a machine that is yours, an A record for the panel's hostname, ports 22, 80 and 443.
Verify
Five assets ship with every release: ferrum-x86_64-unknown-linux-musl, ferrum-aarch64-unknown-linux-musl, SHA256SUMS, SHA256SUMS.sig and ferrum-pub.pem. The installer checks them for you; to do it by hand:
openssl pkeyutl -verify -pubin -inkey ferrum-pub.pem -rawin -in SHA256SUMS -sigfile SHA256SUMS.sig
sha256sum -c SHA256SUMS --ignore-missing