Releases: metio/stageset-controller
Release list
2026.7.30171933
2026.7.30171933
Dependencies
Fixed
- update module github.com/modelcontextprotocol/go-sdk to v1.7.0 (#184)
Usage
Pull the container from ghcr.io/metio/stageset-controller:2026.7.30171933.
See Upgrading — https://stageset.projects.metio.wtf/reference/upgrading/ — for any required actions on your part.
Prebuilt binaries are attached below for both the controller
(stageset-controller_*) and the stagesetctl CLI (stagesetctl_*):
linux:amd64,arm(v7),arm64,ppc64le,riscv64,s390xwindows:amd64,arm64(.zip)darwin(macOS):amd64,arm64
The CLI doubles as a kubectl plugin: rename it to kubectl-stageset
on your PATH and run kubectl stageset ….
Verify
All release artifacts are signed with cosign keyless. See Verifying releases — https://stageset.projects.metio.wtf/reference/verifying-releases/ — for the verification commands.
2026.7.29075427
2026.7.29075427
Dependencies
Fixed
- update module github.com/fluxcd/pkg/auth to v0.56.0 (#180)
Usage
Pull the container from ghcr.io/metio/stageset-controller:2026.7.29075427.
See Upgrading — https://stageset.projects.metio.wtf/reference/upgrading/ — for any required actions on your part.
Prebuilt binaries are attached below for both the controller
(stageset-controller_*) and the stagesetctl CLI (stagesetctl_*):
linux:amd64,arm(v7),arm64,ppc64le,riscv64,s390xwindows:amd64,arm64(.zip)darwin(macOS):amd64,arm64
The CLI doubles as a kubectl plugin: rename it to kubectl-stageset
on your PATH and run kubectl stageset ….
Verify
All release artifacts are signed with cosign keyless. See Verifying releases — https://stageset.projects.metio.wtf/reference/verifying-releases/ — for the verification commands.
2026.7.28032129
2026.7.28032129
Fixed
- update module github.com/google/cel-go to v0.30.0 (#177)
Usage
Pull the container from ghcr.io/metio/stageset-controller:2026.7.28032129.
See Upgrading — https://stageset.projects.metio.wtf/reference/upgrading/ — for any required actions on your part.
Prebuilt binaries are attached below for both the controller
(stageset-controller_*) and the stagesetctl CLI (stagesetctl_*):
linux:amd64,arm(v7),arm64,ppc64le,riscv64,s390xwindows:amd64,arm64(.zip)darwin(macOS):amd64,arm64
The CLI doubles as a kubectl plugin: rename it to kubectl-stageset
on your PATH and run kubectl stageset ….
Verify
All release artifacts are signed with cosign keyless. See Verifying releases — https://stageset.projects.metio.wtf/reference/verifying-releases/ — for the verification commands.
2026.7.27155724
2026.7.27155724
Dependencies
- update docker.io/library/golang:1.26.5 docker digest to 3aff665 (#176)
- update docker/login-action digest to abd2ef4 (#174)
- update metio ci (#175)
Usage
Pull the container from ghcr.io/metio/stageset-controller:2026.7.27155724.
See Upgrading — https://stageset.projects.metio.wtf/reference/upgrading/ — for any required actions on your part.
Prebuilt binaries are attached below for both the controller
(stageset-controller_*) and the stagesetctl CLI (stagesetctl_*):
linux:amd64,arm(v7),arm64,ppc64le,riscv64,s390xwindows:amd64,arm64(.zip)darwin(macOS):amd64,arm64
The CLI doubles as a kubectl plugin: rename it to kubectl-stageset
on your PATH and run kubectl stageset ….
Verify
All release artifacts are signed with cosign keyless. See Verifying releases — https://stageset.projects.metio.wtf/reference/verifying-releases/ — for the verification commands.
2026.7.27090051
2026.7.27090051
Dependencies
Fixed
- update go modules (#173)
Usage
Pull the container from ghcr.io/metio/stageset-controller:2026.7.27090051.
See Upgrading — https://stageset.projects.metio.wtf/reference/upgrading/ — for any required actions on your part.
Prebuilt binaries are attached below for both the controller
(stageset-controller_*) and the stagesetctl CLI (stagesetctl_*):
linux:amd64,arm(v7),arm64,ppc64le,riscv64,s390xwindows:amd64,arm64(.zip)darwin(macOS):amd64,arm64
The CLI doubles as a kubectl plugin: rename it to kubectl-stageset
on your PATH and run kubectl stageset ….
Verify
All release artifacts are signed with cosign keyless. See Verifying releases — https://stageset.projects.metio.wtf/reference/verifying-releases/ — for the verification commands.
2026.7.20124852
2026.7.20124852
Added
- engage producer watches on CRD install via a CRDWatcher
Usage
Pull the container from ghcr.io/metio/stageset-controller:2026.7.20124852.
See Upgrading — https://stageset.projects.metio.wtf/reference/upgrading/ — for any required actions on your part.
Prebuilt binaries are attached below for both the controller
(stageset-controller_*) and the stagesetctl CLI (stagesetctl_*):
linux:amd64,arm(v7),arm64,ppc64le,riscv64,s390xwindows:amd64,arm64(.zip)darwin(macOS):amd64,arm64
The CLI doubles as a kubectl plugin: rename it to kubectl-stageset
on your PATH and run kubectl stageset ….
Verify
All release artifacts are signed with cosign keyless. See Verifying releases — https://stageset.projects.metio.wtf/reference/verifying-releases/ — for the verification commands.
2026.7.19230104
2026.7.19230104
Dependencies
- update container base images (#169)
Usage
Pull the container from ghcr.io/metio/stageset-controller:2026.7.19230104.
See Upgrading — https://stageset.projects.metio.wtf/reference/upgrading/ — for any required actions on your part.
Prebuilt binaries are attached below for both the controller
(stageset-controller_*) and the stagesetctl CLI (stagesetctl_*):
linux:amd64,arm(v7),arm64,ppc64le,riscv64,s390xwindows:amd64,arm64(.zip)darwin(macOS):amd64,arm64
The CLI doubles as a kubectl plugin: rename it to kubectl-stageset
on your PATH and run kubectl stageset ….
Verify
All release artifacts are signed with cosign keyless. See Verifying releases — https://stageset.projects.metio.wtf/reference/verifying-releases/ — for the verification commands.
2026.7.19124103
2026.7.19124103
Fixed
- declare the events and pods permissions the controller uses (#168)
Usage
Pull the container from ghcr.io/metio/stageset-controller:2026.7.19124103.
See Upgrading — https://stageset.projects.metio.wtf/reference/upgrading/ — for any required actions on your part.
Prebuilt binaries are attached below for both the controller
(stageset-controller_*) and the stagesetctl CLI (stagesetctl_*):
linux:amd64,arm(v7),arm64,ppc64le,riscv64,s390xwindows:amd64,arm64(.zip)darwin(macOS):amd64,arm64
The CLI doubles as a kubectl plugin: rename it to kubectl-stageset
on your PATH and run kubectl stageset ….
Verify
All release artifacts are signed with cosign keyless. See Verifying releases — https://stageset.projects.metio.wtf/reference/verifying-releases/ — for the verification commands.
2026.7.19111454
2026.7.19111454
Fixed
- never crash-loop on a missing CRD or incomplete RBAC (#167)
Usage
Pull the container from ghcr.io/metio/stageset-controller:2026.7.19111454.
See Upgrading — https://stageset.projects.metio.wtf/reference/upgrading/ — for any required actions on your part.
Prebuilt binaries are attached below for both the controller
(stageset-controller_*) and the stagesetctl CLI (stagesetctl_*):
linux:amd64,arm(v7),arm64,ppc64le,riscv64,s390xwindows:amd64,arm64(.zip)darwin(macOS):amd64,arm64
The CLI doubles as a kubectl plugin: rename it to kubectl-stageset
on your PATH and run kubectl stageset ….
Verify
All release artifacts are signed with cosign keyless. See Verifying releases — https://stageset.projects.metio.wtf/reference/verifying-releases/ — for the verification commands.
2026.7.19095256
2026.7.19095256
Added
- --image-verification-insecure-registry for HTTP registries
- public-key cosign authorities
- gate stages on image verification before apply
- sigstore-go keyless image verifier
- PinImages rewrites verified images to digests (TOCTOU)
- ImageVerificationPolicy CRD + verification core (image-gate Phase 1a)
Changed
- get cosign from the flake devShell, not cosign-installer
- end-to-end image-verification kind scenario
- exclude go.mod from the typos scan
Documentation
- document the image-verification gate subsystem
- image verification page
Fixed
- correct cosign v3 signing in the image-verify scenario (#166)
Usage
Pull the container from ghcr.io/metio/stageset-controller:2026.7.19095256.
See Upgrading — https://stageset.projects.metio.wtf/reference/upgrading/ — for any required actions on your part.
Prebuilt binaries are attached below for both the controller
(stageset-controller_*) and the stagesetctl CLI (stagesetctl_*):
linux:amd64,arm(v7),arm64,ppc64le,riscv64,s390xwindows:amd64,arm64(.zip)darwin(macOS):amd64,arm64
The CLI doubles as a kubectl plugin: rename it to kubectl-stageset
on your PATH and run kubectl stageset ….
Verify
All release artifacts are signed with cosign keyless. See Verifying releases — https://stageset.projects.metio.wtf/reference/verifying-releases/ — for the verification commands.