Skip to content

v1.0.0

Latest

Choose a tag to compare

@github-actions github-actions released this 01 Oct 23:53
· 32 commits to main since this release
865532f

Plasmite 1.0.0

Plasmite 1.0 makes pools easier to share, explore, and use with your tools. It introduces a completely new secure sharing system built around invitations and saved connections, expands the MCP server and web interface, and redesigns the CLI for everyday use. It also brings downloadable Linux ARM SDKs and better Windows support.

Secure pool sharing, rebuilt

Sharing a pool now starts with an invitation. Create a named access key, give it to a recipient, and connect once. Plasmite saves the connection and verifies the server's identity before sending credentials on subsequent requests.

The new system brings setup and ongoing administration into a single set of commands:

  • Invite people or devices with individually named keys
  • Save connections to multiple servers and list them offline
  • Check a connection, revoke a key, or forget a saved destination
  • Approve browser access and manage browser trust separately

Remote connections use authenticated HTTPS; local administration stays on loopback. Access keys cover a served directory, including pools created there later.

The serving guide walks through setup, certificates, browser access, and Tailscale. For Tailscale users, it covers direct connections and optional raw TCP forwarding that preserves Plasmite's TLS identity.

More capable MCP connections

Compatible MCP clients can connect directly to a shared server over HTTPS, without a local Plasmite installation. Browser-based authorization lets you approve a client connection, and independently revocable grants let you withdraw it later.

For clients using a local stdio connection, the new plasmite mcp --remote SERVER_URL mode connects your installed Plasmite process to a shared server. It uses a saved connection, keeping the access key out of the MCP client's configuration.

Direct HTTPS connections require both the MCP client and its authorization browser to trust the server certificate. Revoking the underlying access key also invalidates its linked credentials. See the MCP connection guide for both setup paths.

A richer web interface

The web interface is now a much more useful place to work with pools:

  • Track live pools in the sortable Table, watch retained messages and new writes on the Map, and read messages in the Log
  • Filter loaded messages, load earlier history, and move around with the keyboard
  • Pin JSON fields as columns in the Log
  • Link to a specific message, inspect its contents, and copy its JSON
  • Append text or JSON directly from the browser
  • Inspect observed server requests and, where available, local processes with pool files open

Message links, history cursors, maps, and copied envelopes preserve exact 64-bit sequence numbers. History loading also reports retention gaps and connection failures instead of leaving you waiting without an explanation.

More platforms, better Windows support

Downloadable SDKs expand from three platforms to five. Alongside macOS on Intel and Apple Silicon and Linux x86_64, this release adds:

The new archives include the CLI/server, native libraries, and C headers, so you can use the SDK without installing a Rust toolchain. Both ARM targets are previews. Automated checks cover native behavior and cross-architecture pool compatibility; physical Raspberry Pi installation and reboot qualification are still ahead. We'd welcome community feedback on installation and real-world use. ARMv6 is unsupported.

Windows users get a better secure-sharing experience, too. Saved client access keys are encrypted with the current Windows account's DPAPI protection. Server state is protected by filesystem permissions, with checks for unsafe ownership, permissions, and linked paths. Guided Chrome and Edge certificate trust uses visible Windows approval, and removing trust targets the exact certificate.

A redesigned CLI, with more ways to read

The CLI has a consistent, task-oriented help layout, readable output by default, explicit JSON for scripts, and more useful recovery guidance. Global directory and color options work before or after commands.

Local and remote pools now share more of the same interface:

  • Fetch a message or inspect a pool using either a local name or a remote pool URL
  • List a remote server's pools using its saved connection
  • Read a finite slice of history with follow --tail N --no-follow
  • Read local or remote history since a timestamp or relative time using --since, including finite reads with --no-follow
  • Discover running servers, their directories, and their addresses with serve status

For example:

plasmite follow events --tail 100 --no-follow --json
plasmite pool list https://pools.example.net:9743
plasmite fetch https://pools.example.net:9743/events 42 --json

The remote examples require a saved connection. A finite history read has a fixed endpoint, so new messages cannot keep it running. --tail N selects the last N retained messages before applying filters.

Safer concurrent reads and faster writes

Retained message frames now own stable snapshots: later writes cannot change data a reader already holds. Go and Python synchronize native-handle operations and cleanup, and malformed retained frames return corruption errors instead of hanging.

Reader notifications now happen after committed writes release the writer lock, substantially reducing reader delays in the measured concurrent-write workloads.

Same-host, three-run comparisons with 0.8.0 measured 3–14% lower median time per append and 35–66% lower median time per message with multiple writers. Stable snapshots add copying and locking costs, so very small indexed reads are slower. The benchmark report includes the methodology, improvements, and regressions.

Other reliability improvements include exact 64-bit sequence handling in Node message envelopes, bounded tap output capture and child cleanup, a fix for recursive Python CLI fallback launches, and network deadlines for one-shot remote requests. Live streams retain their streaming limits; system DNS resolution is not interruptible, so the 30-second network deadline is not a hard wall-clock guarantee.

Upgrading to 1.0

This is a breaking CLI and Rust API release. Existing pool files and the C ABI remain compatible. Read the upgrade guide before updating scripts or shared servers.

  • Scripts must request JSON explicitly. Readable output is now the default even when piped. Add --json wherever you parse output; streaming --jsonl and --format jsonl remain supported
  • Set up remote access again. Old token configuration and insecure TLS options are removed, with no automatic conversion. Update servers and recipients together, then use access invite and access connect
  • Access keys grant full directory access. The old read-only mode has no replacement. Separate directories isolate groups of pools but do not provide read-only access
  • Node.js 24 or later is required
  • Linux x86_64 prebuilt CLI binaries require glibc 2.39 or later. For older systems, see the source-build requirements
  • Rust callers may need source changes. See the Rust migration steps

Secure native connections and certificate pinning are available in Rust and the CLI; other bindings retain their documented transport capabilities. Tailscale guidance has been checked against current documentation and local TLS/TCP-relay tests, but not a real two-device tailnet deployment. Never forward the unauthenticated local HTTP port; HTTPS-terminating proxies need explicit frontend-identity configuration.

Install or update · Full changes since 0.8.0