Skip to content

Releases: Strazahq/straza

Release list

v1.1.0

Choose a tag to compare

@github-actions github-actions released this 08 Oct 04:20
v1.1.0
e9d6bfa

Straza 1.1.0 is the first public release of Straza, open source runtime governance for AI
agents. Straza is the control plane between your identity manager and your agents. Your identity
manager says who people and AI agents are and which roles they hold. Straza turns those roles
into a decision at every action an agent takes, and it records every decision.

What it does

  • Each shell command, file write, network fetch and MCP tool call that reaches a Straza hook, the
    MCP gateway or straza exec is decided against signed policy before it runs. It is allowed,
    denied with a reason the model can read, or held for a person.
  • A held call goes to the Straza approver app on iOS and Android, the console, Slack or
    strazactl. The app signs each decision with a key kept in the phone's secure hardware, and
    strazad verifies every signature.
  • The MCP gateway fronts your MCP servers as one /mcp endpoint that denies by default. An agent
    sees only the tools its roles have access to, and upstream credentials stay at the gateway.
  • Every decision joins a SHA-256 hash chain that strazactl audit verify recomputes, and sinks
    stream the records to your SIEM.
  • People, AI agents and roles come from your identity manager over SCIM 2.0. Deactivating a user
    revokes every session of that user.
  • When Straza cannot decide, it denies. No AI runs inside it, and it never proxies model traffic.

What ships

  • strazad, the server, is one static binary. On one machine it runs on its embedded SQLite
    database and event broker, and on Kubernetes it runs on Postgres and NATS.
  • straza runs beside the agent. It hooks into Claude Code, Codex CLI and Gemini CLI, and it
    governs a process with no hooks through straza exec. The Python agent kit calls it for every
    decision.
  • strazactl and the web console administer the server.
  • Each archive holds all three binaries, strazad, strazactl and straza. The archives cover Linux, macOS and Windows on amd64 and arm64, each with an SBOM. The container
    image ghcr.io/strazahq/straza is built for linux/amd64 and linux/arm64 and signed by digest.
    The Helm chart is in the repository under deploy/helm/straza.

Get started

Verify your download first, with the recipe in
Download a release and verify it.

Know the limits

A hook installed in user mode on an open machine is advisory, because an agent that can run
anything can skip it. The MCP gateway holds at a boundary, because the decision, the catalog and
the credential all live on the server. The trust model
says what each lane is worth, and Known limits
lists what this release does not protect.

Straza sends no usage data. The Helm chart and the compose template turn on the hosted push relay
for phone approvals, and
Ports and network
lists every connection strazad makes and how to turn the relay off.

What comes next

Microsoft Teams, a Cursor adapter and passkeys for the built-in sign-in come next, and the
roadmap says what follows.

The core is AGPL-3.0-only, and the specifications, the agent kits and the mobile approver app are
Apache-2.0, as the license page spells out. Report a
vulnerability through GitHub private vulnerability reporting or to security@straza.ai, never in a
public issue.

Verify this release

Static binaries for linux/windows/darwin (amd64/arm64). Verify with:

cosign verify-blob --signature checksums.txt.sig --certificate checksums.txt.pem \
  --certificate-identity-regexp '^https://github\.com/Strazahq/straza/\.github/workflows/release\.yml@refs/tags/v[0-9]+\.[0-9]+\.[0-9]+$' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com checksums.txt
sha256sum -c checksums.txt --ignore-missing

Container image: ghcr.io/strazahq/straza:1.1.0 (cosign-signed).