Skip to content

Harbor Desk v0.5.2

Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 28 Aug 15:12
· 65 commits to main since this release

Harbor Desk v0.5.2 preview

This preview contains the client-first desktop app with its automatic loopback policy gateway, plus the optional server-side Docker gateway installer.

Changes

Added

  • The server-side npx harbor-desk install-server flow now supports a remote
    Docker Engine over HTTPS mTLS with --engine-endpoint, CA, client
    certificate, and client private key file options.
  • Remote Engine credentials stay on the server host and are mounted read-only
    into the gateway container without mounting a Docker socket. The interactive
    setup and -AI context describe both Engine transport choices.

Security

  • Remote Engine mode requires HTTPS and all three mTLS files, validates them
    before writing the install target, and rejects mixing remote mTLS with the
    privileged local Docker socket mount.

Downloads

  • Windows: x64 NSIS installer and blockmap
  • Linux: x86_64 AppImage and Debian package
  • macOS: x64 and arm64 DMG/ZIP packages and blockmaps
  • Server: attached GitHub release tarball harbor-desk-0.5.2.tgz
  • Integrity: SHA256SUMS contains SHA-256 checksums for every distributable asset

npm distribution

The npm registry provides v0.5.2 under the preview dist-tag (the default latest dist-tag is unchanged). To run that exact version instead of following the latest dist-tag:

npx --yes harbor-desk@0.5.2 --version

Preview and security boundaries

This remains a prerelease. Desktop binaries are currently unsigned; verify SHA256SUMS before installation and use a source build where signed artifacts are required.

The desktop starts its bundled gateway automatically on 127.0.0.1 and does not require a local Docker Engine. Docker access remains behind the gateway; the renderer never receives a Docker socket or direct Engine connection. The optional server installer supports controlled Linux, Windows, and macOS Docker hosts, but requires explicit --allow-local-engine-socket acknowledgement before mounting a host's Docker Engine socket.

See SECURITY.md for the current security and dependency-advisory boundary.