Skip to content

Harbor Desk v0.5.1

Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 28 Aug 14:38
· 65 commits to main since this release

Harbor Desk v0.5.1 preview

This preview contains the client-first desktop app with its automatic loopback policy gateway, plus the optional server-side Docker gateway installer.

Changes

Added

  • The server-side npx harbor-desk install-server flow now offers an
    interactive terminal setup for the destination, port, network binding,
    authentication mode, OIDC provider file, browser origins, and Docker socket
    acknowledgement.
  • -AI and --ai-context now provide stable machine-readable setup context for
    non-interactive agents without reading Docker, touching the filesystem, or
    exposing provider credentials.
  • The installer supports an explicit public preview binding with OIDC, HTTPS
    provider endpoint validation, narrow allowed origins, and protected generated
    environment settings while retaining loopback plus development authentication
    as the default.

Security

  • Public server preview setup rejects development authentication and requires
    OIDC configuration. TLS or reverse-proxy termination, firewall policy, and
    operational controls remain deployment responsibilities.

Downloads

  • Windows: x64 NSIS installer and blockmap
  • Linux: x86_64 AppImage and Debian package
  • macOS: x64 and arm64 DMG/ZIP packages and blockmaps
  • Server: attached GitHub release tarball harbor-desk-0.5.1.tgz
  • Integrity: SHA256SUMS contains SHA-256 checksums for every distributable asset

npm distribution

The npm registry provides v0.5.1 under the preview dist-tag (the default latest dist-tag is unchanged). To run that exact version instead of following the latest dist-tag:

npx --yes harbor-desk@0.5.1 --version

Preview and security boundaries

This remains a prerelease. Desktop binaries are currently unsigned; verify SHA256SUMS before installation and use a source build where signed artifacts are required.

The desktop starts its bundled gateway automatically on 127.0.0.1 and does not require a local Docker Engine. Docker access remains behind the gateway; the renderer never receives a Docker socket or direct Engine connection. The optional server installer supports controlled Linux, Windows, and macOS Docker hosts, but requires explicit --allow-local-engine-socket acknowledgement before mounting a host's Docker Engine socket.

See SECURITY.md for the current security and dependency-advisory boundary.