Skip to content

Ferrum 0.1.1

Choose a tag to compare

@github-actions github-actions released this 07 Sep 06:08
· 53 commits to main since this release

System packages follow an app's Aptfile and can be uninstalled with it, unknown names on port 443 are refused, and dumps made with pg_dump --clean load.

What's New

  • A deploy reads the tag's Aptfile and installs what is new in it. The deploy log names what was added and what the file no longer lists. A deploy never uninstalls.
  • Deleting an app shows which of its packages would be uninstalled, which stay because another app lists them, and which were on the server before Ferrum. You choose.
  • Removing a package on the Configuration tab uninstalls it on Save, under the same rule.
  • Packages installed before this release are treated as pre-existing and are never removed.
  • A default server on port 443 refuses the TLS handshake for any name that has no site.
  • bunx is available in every Bun toolchain, including ones installed earlier.

Bug Fixes

  • A dump made with pg_dump --clean failed to load with "must be owner of extension". Its DROP EXTENSION line is now skipped like the other extension lines.
  • A site could be left without HTTPS when provisioning ran while a build was deleting cache files. Provisioning now touches only its own directories, and the certificate sweep rewrites any site that does not match the certificates on disk.
  • A start command that begins with bun in a Node app, or the reverse, failed at run time although the same tool worked at build time. The unit now gets that toolchain on its PATH.

Update

From the panel: Settings → Updates, or ferrum update on the server. A fresh install:

curl -fsSL https://raw.githubusercontent.com/irixsoft/ferrum/main/install.sh | sudo sh

Verify

Every release ships ferrum-x86_64-unknown-linux-musl, ferrum-aarch64-unknown-linux-musl, SHA256SUMS, SHA256SUMS.sig and ferrum-pub.pem. The installer and the updater check them; by hand:

openssl pkeyutl -verify -pubin -inkey ferrum-pub.pem -rawin -in SHA256SUMS -sigfile SHA256SUMS.sig
sha256sum -c SHA256SUMS --ignore-missing