Skip to content

Releases: juan52878911/kindling

v0.17.0

Choose a tag to compare

@github-actions github-actions released this 29 Sep 19:40
4d2b0ea

Added

  • kling db: disposable Postgres databases, one per microVM or git branch (#51)
  • kling db clone, diff, ask, rehearse, tenant-check, class and report (#51, #99, #105, #109)
  • MySQL, MariaDB, Redis and SQLite in kling db (#105, #109)
  • kling graph: several microVMs with link, depends, share and credential edges (#51, #100, #109)
  • Copy-on-write disk store: run -from no longer copies the whole golden disk (#51)
  • Credential proxy for HTTP APIs and Postgres: keys never enter the guest (#47, #48, #49, #50)
  • Per-session isolation for MCP services: one microVM per session (#52)
  • Per-operation authorization on the daemon socket (#105)
  • Android phones on kindling: K1 kernel, image-defined readiness, optional virtio-gpu (#101, #102, #103, #104, #106)
  • Volume snapshots and rollback with kling volume snapshot (#49)

Changed

  • The daemon and kling-vz must be upgraded together (#100)
  • The credential audit log moves out of the VMM's reach (#109)
  • macOS: CPU cap uses short SIGSTOP pauses instead of pausing the VM (#108)
  • Internal: CI triage example tweaks, e2e sections for kling db and graphs (#46, #100)

Fixed

  • The MCP gateway has a per-service replica cap (#48)
  • kling run -from inherits the template's egress (#48)
  • Two daemons on one host no longer wipe each other's network or subnet (#109)

Security

  • IPv6 is closed in every egress mode (#48)
  • Per-credential method and path rules with -allow-request (#48)
  • Per-session MMDS secrets removed; the session id was not a secret (#48)
  • kling image put on Linux no longer writes outside the image (#105)
  • Copy-on-write store: each jail sees only its own instance directory (#51)

Install or upgrade: curl -fsSL https://raw.githubusercontent.com/juan52878911/kindling/main/scripts/install.sh | KLING_VERSION=v0.17.0 sh

v0.16.0

Choose a tag to compare

@github-actions github-actions released this 27 Sep 21:39
a5f0351

Added

  • macOS: -cpu-pct now applies with the vz backend (#45)

Security

  • A guest can no longer reach host services through the host's public IP (#45)
  • kling save and fork refuse machines with injected secrets (#45)
  • macOS: only your user reaches a sandbox's agent (#45)
  • macOS: kling-vz runs inside a sandbox profile (#45)

Install or upgrade: curl -fsSL https://raw.githubusercontent.com/juan52878911/kindling/main/scripts/install.sh | KLING_VERSION=v0.16.0 sh

v0.15.0

Choose a tag to compare

@github-actions github-actions released this 27 Sep 21:04
9f61cc2

Added

  • kling sandbox fork: branch a running sandbox into N copies (#42)
  • Minimal custom kernel and faster boot (#42)
  • LICENSE (Apache-2.0) and docs/benchmarks.md (#42)

Changed

  • Jailer is mandatory by default on Linux (#42)
  • kling logs returns at most 4 MiB (#42)
  • rm/stop/freeze wait for a machine that is still starting (#42)

Fixed

  • Machine lifecycle, kling save locking and Firecracker dump/restore timeouts (#42)
  • Bounded serial console, allowlist DNS resolver and shared-folder descriptors (#42)

Security

  • Path traversal through escaped URL names (#42)
  • Frozen machines' memory is no longer world-readable (#42)
  • A compromised VMM can no longer rewrite kernels, images or goldens (#42)

Install or upgrade: curl -fsSL https://raw.githubusercontent.com/juan52878911/kindling/main/scripts/install.sh | KLING_VERSION=v0.15.0 sh

v0.14.0

Choose a tag to compare

@github-actions github-actions released this 27 Sep 00:49
c06624c

Added

  • kling with no arguments shows where to start; one help system for every command (#41)
  • Size and duration units: -mem 512M, -ttl 10m (#41)
  • -q on every ls; next: hints after creating something (#41)
  • Generic intent tasks in the AI gateway (#41)

Changed

  • New names: save (was commit), template ls|inspect|rm; old names stay as aliases (#41)
  • Extensions get a namespace (manifest v2); MCP commands live under kling mcp (#41)
  • frozen state shown in ps, inspect, top and the API (#41)
  • The home automation demo is a separate program, kindling-domotica (#41)

Install or upgrade: curl -fsSL https://raw.githubusercontent.com/juan52878911/kindling/main/scripts/install.sh | KLING_VERSION=v0.14.0 sh

v0.13.0

Choose a tag to compare

@github-actions github-actions released this 26 Sep 01:59
3e0f4ac

Added

  • kling plugins install|ls|rm|enable|disable (#40)
  • -json on sandbox ls, context ls, config show and version (#40)
  • Errors suggest the next step when it is known (#40)
  • scripts/install.sh --with mcp,sandbox installs extensions (#40)

Changed

  • One repo: kling-mcp and kling-sandbox move to ext/ and ship in the same release (#40)
  • ai, chispa and models become built-in extensions (#40)

Install or upgrade: curl -fsSL https://raw.githubusercontent.com/juan52878911/kindling/main/scripts/install.sh | KLING_VERSION=v0.13.0 sh

v0.12.0

Choose a tag to compare

@github-actions github-actions released this 25 Sep 07:55
618f5d0

Added

  • kling ai serve: AI gateway with Chispa and small LLMs, scaling to zero (#26)
  • Chispa: tiny linear classifier, same bits on amd64 and arm64 (#22)
  • kling models: small on-demand LLMs in microVMs (#25)
  • Serverless Chispa: one task per frozen microVM (#31)
  • kling ai retrain: Chispa learns from what slower layers resolved (#34)
  • kling pause: paused level wakes in about 2 ms (#35)
  • CI failure triage example (examples/ci-triage) (#36)
  • Home automation demo (examples/domotica) (#27, #29, #33)

Changed

  • Waking a frozen machine drops from 152 to 27 ms (#35)

Fixed

  • The daemon no longer freezes a gateway instance mid-request (#23, #24)
  • max_replicas is a hard limit; shrinking a layer no longer corrupts it (#37)

Install or upgrade: curl -fsSL https://raw.githubusercontent.com/juan52878911/kindling/main/scripts/install.sh | KLING_VERSION=v0.12.0 sh

v0.10.0

Choose a tag to compare

@github-actions github-actions released this 23 Sep 18:14
5ccd93d

Added

  • Shared folders: kling run -share with copy, read-only and live read-write modes (#21)

Fixed

  • The systemd daemon reads root's configuration (#21)

Install or upgrade: curl -fsSL https://raw.githubusercontent.com/juan52878911/kindling/main/scripts/install.sh | KLING_VERSION=v0.10.0 sh

v0.9.1

Choose a tag to compare

@github-actions github-actions released this 23 Sep 09:15
43ed42f

Fixed

  • Guests resync clock and entropy after every restore (#20)
  • Jailed machines are re-adopted after a daemon restart (#20)
  • Scheduler Bind no longer overwrites a session pinned elsewhere (#20)

Install or upgrade: curl -fsSL https://raw.githubusercontent.com/juan52878911/kindling/main/scripts/install.sh | KLING_VERSION=v0.9.1 sh

v0.9.0

Choose a tag to compare

@github-actions github-actions released this 23 Sep 08:09
6f357da

Added

  • Native macOS backend (kling-vz), selected with daemon.vmm vz, no root (#18)
  • kling images copy moves an image between daemons (#18)

Install or upgrade: curl -fsSL https://raw.githubusercontent.com/juan52878911/kindling/main/scripts/install.sh | KLING_VERSION=v0.9.0 sh

v0.8.0

Choose a tag to compare

@github-actions github-actions released this 23 Sep 05:29
10f3aba

Added

  • Elastic memory with kling run -mem-max (#16)
  • Admission by real memory pressure and load-based scaling (#16)

Fixed

  • Half-written freeze dumps and interrupted commits are detected and cleaned (#16)

Security

  • Snapshots are signed with a host key (#16)
  • The guest proxy only reaches the agent port and declared ports (#16)
  • Jailer is used by default when installed (#16)

Install or upgrade: curl -fsSL https://raw.githubusercontent.com/juan52878911/kindling/main/scripts/install.sh | KLING_VERSION=v0.8.0 sh