Releases: juan52878911/kindling
Release list
v0.17.0
Added
kling db: disposable Postgres databases, one per microVM or git branch (#51)kling db clone,diff,ask,rehearse,tenant-check,classandreport(#51, #99, #105, #109)- MySQL, MariaDB, Redis and SQLite in
kling db(#105, #109) kling graph: several microVMs withlink,depends,shareandcredentialedges (#51, #100, #109)- Copy-on-write disk store:
run -fromno longer copies the whole golden disk (#51) - Credential proxy for HTTP APIs and Postgres: keys never enter the guest (#47, #48, #49, #50)
- Per-session isolation for MCP services: one microVM per session (#52)
- Per-operation authorization on the daemon socket (#105)
- Android phones on kindling: K1 kernel, image-defined readiness, optional virtio-gpu (#101, #102, #103, #104, #106)
- Volume snapshots and rollback with
kling volume snapshot(#49)
Changed
- The daemon and
kling-vzmust be upgraded together (#100) - The credential audit log moves out of the VMM's reach (#109)
- macOS: CPU cap uses short SIGSTOP pauses instead of pausing the VM (#108)
- Internal: CI triage example tweaks, e2e sections for
kling dband graphs (#46, #100)
Fixed
- The MCP gateway has a per-service replica cap (#48)
kling run -frominherits the template's egress (#48)- Two daemons on one host no longer wipe each other's network or subnet (#109)
Security
- IPv6 is closed in every egress mode (#48)
- Per-credential method and path rules with
-allow-request(#48) - Per-session MMDS secrets removed; the session id was not a secret (#48)
kling image puton Linux no longer writes outside the image (#105)- Copy-on-write store: each jail sees only its own instance directory (#51)
Install or upgrade: curl -fsSL https://raw.githubusercontent.com/juan52878911/kindling/main/scripts/install.sh | KLING_VERSION=v0.17.0 sh
v0.16.0
Added
- macOS:
-cpu-pctnow applies with thevzbackend (#45)
Security
- A guest can no longer reach host services through the host's public IP (#45)
kling saveandforkrefuse machines with injected secrets (#45)- macOS: only your user reaches a sandbox's agent (#45)
- macOS:
kling-vzruns inside a sandbox profile (#45)
Install or upgrade: curl -fsSL https://raw.githubusercontent.com/juan52878911/kindling/main/scripts/install.sh | KLING_VERSION=v0.16.0 sh
v0.15.0
Added
kling sandbox fork: branch a running sandbox into N copies (#42)- Minimal custom kernel and faster boot (#42)
LICENSE(Apache-2.0) anddocs/benchmarks.md(#42)
Changed
- Jailer is mandatory by default on Linux (#42)
kling logsreturns at most 4 MiB (#42)rm/stop/freezewait for a machine that is still starting (#42)
Fixed
- Machine lifecycle,
kling savelocking and Firecracker dump/restore timeouts (#42) - Bounded serial console, allowlist DNS resolver and shared-folder descriptors (#42)
Security
- Path traversal through escaped URL names (#42)
- Frozen machines' memory is no longer world-readable (#42)
- A compromised VMM can no longer rewrite kernels, images or goldens (#42)
Install or upgrade: curl -fsSL https://raw.githubusercontent.com/juan52878911/kindling/main/scripts/install.sh | KLING_VERSION=v0.15.0 sh
v0.14.0
Added
klingwith no arguments shows where to start; one help system for every command (#41)- Size and duration units:
-mem 512M,-ttl 10m(#41) -qon everyls;next:hints after creating something (#41)- Generic intent tasks in the AI gateway (#41)
Changed
- New names:
save(wascommit),template ls|inspect|rm; old names stay as aliases (#41) - Extensions get a namespace (manifest v2); MCP commands live under
kling mcp(#41) frozenstate shown inps,inspect,topand the API (#41)- The home automation demo is a separate program,
kindling-domotica(#41)
Install or upgrade: curl -fsSL https://raw.githubusercontent.com/juan52878911/kindling/main/scripts/install.sh | KLING_VERSION=v0.14.0 sh
v0.13.0
Added
kling plugins install|ls|rm|enable|disable(#40)-jsononsandbox ls,context ls,config showandversion(#40)- Errors suggest the next step when it is known (#40)
scripts/install.sh --with mcp,sandboxinstalls extensions (#40)
Changed
- One repo: kling-mcp and kling-sandbox move to
ext/and ship in the same release (#40) ai,chispaandmodelsbecome built-in extensions (#40)
Install or upgrade: curl -fsSL https://raw.githubusercontent.com/juan52878911/kindling/main/scripts/install.sh | KLING_VERSION=v0.13.0 sh
v0.12.0
Added
kling ai serve: AI gateway with Chispa and small LLMs, scaling to zero (#26)- Chispa: tiny linear classifier, same bits on amd64 and arm64 (#22)
kling models: small on-demand LLMs in microVMs (#25)- Serverless Chispa: one task per frozen microVM (#31)
kling ai retrain: Chispa learns from what slower layers resolved (#34)kling pause: paused level wakes in about 2 ms (#35)- CI failure triage example (
examples/ci-triage) (#36) - Home automation demo (
examples/domotica) (#27, #29, #33)
Changed
- Waking a frozen machine drops from 152 to 27 ms (#35)
Fixed
- The daemon no longer freezes a gateway instance mid-request (#23, #24)
max_replicasis a hard limit; shrinking a layer no longer corrupts it (#37)
Install or upgrade: curl -fsSL https://raw.githubusercontent.com/juan52878911/kindling/main/scripts/install.sh | KLING_VERSION=v0.12.0 sh
v0.10.0
v0.9.1
Fixed
- Guests resync clock and entropy after every restore (#20)
- Jailed machines are re-adopted after a daemon restart (#20)
- Scheduler
Bindno longer overwrites a session pinned elsewhere (#20)
Install or upgrade: curl -fsSL https://raw.githubusercontent.com/juan52878911/kindling/main/scripts/install.sh | KLING_VERSION=v0.9.1 sh
v0.9.0
v0.8.0
Added
- Elastic memory with
kling run -mem-max(#16) - Admission by real memory pressure and load-based scaling (#16)
Fixed
- Half-written freeze dumps and interrupted commits are detected and cleaned (#16)
Security
- Snapshots are signed with a host key (#16)
- The guest proxy only reaches the agent port and declared ports (#16)
- Jailer is used by default when installed (#16)
Install or upgrade: curl -fsSL https://raw.githubusercontent.com/juan52878911/kindling/main/scripts/install.sh | KLING_VERSION=v0.8.0 sh