Harbor Desk v0.5.2
Pre-releaseHarbor Desk v0.5.2 preview
This preview contains the client-first desktop app with its automatic loopback policy gateway, plus the optional server-side Docker gateway installer.
Changes
Added
- The server-side
npx harbor-desk install-serverflow now supports a remote
Docker Engine over HTTPS mTLS with--engine-endpoint, CA, client
certificate, and client private key file options. - Remote Engine credentials stay on the server host and are mounted read-only
into the gateway container without mounting a Docker socket. The interactive
setup and-AIcontext describe both Engine transport choices.
Security
- Remote Engine mode requires HTTPS and all three mTLS files, validates them
before writing the install target, and rejects mixing remote mTLS with the
privileged local Docker socket mount.
Downloads
- Windows: x64 NSIS installer and blockmap
- Linux: x86_64 AppImage and Debian package
- macOS: x64 and arm64 DMG/ZIP packages and blockmaps
- Server: attached GitHub release tarball
harbor-desk-0.5.2.tgz - Integrity:
SHA256SUMScontains SHA-256 checksums for every distributable asset
npm distribution
The npm registry provides v0.5.2 under the preview dist-tag (the default latest dist-tag is unchanged). To run that exact version instead of following the latest dist-tag:
npx --yes harbor-desk@0.5.2 --versionPreview and security boundaries
This remains a prerelease. Desktop binaries are currently unsigned; verify SHA256SUMS before installation and use a source build where signed artifacts are required.
The desktop starts its bundled gateway automatically on 127.0.0.1 and does not require a local Docker Engine. Docker access remains behind the gateway; the renderer never receives a Docker socket or direct Engine connection. The optional server installer supports controlled Linux, Windows, and macOS Docker hosts, but requires explicit --allow-local-engine-socket acknowledgement before mounting a host's Docker Engine socket.
See SECURITY.md for the current security and dependency-advisory boundary.