Skip to content

Levelrail v0.2.0-beta.15 ​

Released as a pre-release. View on GitHub. All releases.

NOTE

This is a pre-release on the beta channel. Pin this exact version for anything you care about staying still.

Highlights ​

  • log controls, brand logos, status page, disk and cert guards (#663) by @thegdsks
  • log level tags, level filter chips, expandable rows and jump to first error (#669) by @thegdsks
  • brand logos for frameworks, integrations and backup targets (#671) by @thegdsks

What's changed ​

Features ​

  • log controls, brand logos, status page, disk and cert guards (#663) by @thegdsks
  • log level tags, level filter chips, expandable rows and jump to first error (#669) by @thegdsks
  • brand logos for frameworks, integrations and backup targets (#671) by @thegdsks
  • report certificate renewal state (ok or stalled) in API, CLI and dashboard (#670) by @thegdsks
  • server-side audit log search and failed-only filter (#674) by @thegdsks
  • control plane self-backup and offline restore (snapshots, scheduler, pre-migration copy, downgrade guard, CLI, docs) (#678) by @thegdsks
  • control plane backups card on general settings (#675) by @thegdsks
  • app quick actions menu, redeploy button, empty-state CTAs (#672) by @thegdsks
  • failed deploys and disk pressure in attention (#673) by @thegdsks
  • cli build detect/branches and restore history lists (backups, pitr, app-volume-backups) (#684) by @thegdsks
  • add 12 service templates (catalog tranche 5) (#683) by @thegdsks
  • doctor check for stale control plane backups, verified pre-upgrade snapshot and downgrade guard live (#685) by @thegdsks
  • MCP tools for attention, node status history, audit search and control plane backups (#682) by @thegdsks
  • command palette actions, per-app quick actions, recent items and keyboard hints (#693) by @thegdsks
  • app health timeline on the overview page (deploys, restarts, error windows) (#694) by @thegdsks
  • dashboard setup checklist, deploy failure summary and keyboard shortcuts help (#699) by @thegdsks
  • env editor .env import preview, pending diff, secret-safe export, and apps env import/export CLI (#690) by @thegdsks
  • readyz endpoint, CLI parity tranche 2, MCP backup verify and failed deploys tools, e2e cleanup (#700) by @thegdsks
  • node_offline alert kind (API, CLI, dashboard, docs) (#691) by @thegdsks
  • connection-lost banner with backoff reconnect and 12 new service templates (#696) by @thegdsks
  • security follow-ups, control plane backup stale alert and verify, generated API reference (#697) by @thegdsks
  • AI model deploys on GPU nodes, load balancer, S3/R2 log archive, pipelines, catalogue (#701) by @thegdsks
  • GPU-aware scheduling, S3 build cache, pipeline graph and repo sync, fork PR guard, gateway fix (#702) by @thegdsks
  • agent certificate renewal, agent-generated keys, re-enrollment and agent version reporting (#710) by @thegdsks
  • request metrics, deploy safety, model keys, app management, import, preflight and migration runner fix (#711) by @thegdsks
  • encrypted off-box control plane backups, platform as code, alert silences and a public status page (#712) by @thegdsks
  • dashboard redesign with a UI kit, overview v2, mission control home, visual apps list and grouped navigation (#715) by @thegdsks
  • load balancer check history, check now and per-upstream admin state (#719) by @thegdsks
  • load balancer page redesign with live topology, suggestions, health history and export (#721) by @thegdsks
  • app timeline, pending changes, secret declaration on set, domains CLI and previous-release hold cap (#718) by @thegdsks
  • cross-app deployments API with summary, stream, CLI and MCP tools (#725) by @thegdsks
  • cross-app deployments page with live feed, filters, drawer and shortcuts (#728) by @thegdsks
  • deploy preview screenshots (opt-in thumbnails per deploy) (#727) by @thegdsks
  • tiered deploy previews with a free metadata default (#736) by @thegdsks
  • real preview thumbnails on the deployments page and cross-app API (#737) by @thegdsks
  • per-key daily token budget, created_by, revoke MCP tool and reworked model keys panel (#740) by @thegdsks
  • Hugging Face preflight and model cache manager (#741) by @thegdsks
  • change correlation on alerts and SLO burn-rate rules (#742) by @thegdsks
  • path filters, merge queue trigger, and forge status reporting for pipelines and deploys (#744) by @thegdsks
  • supply chain visibility per deploy (SBOM, optional scan gate) (#743) by @thegdsks
  • cancel, queue and digest-pinned rollback for deploys (#731) by @thegdsks
  • wire queue, cancel and digest rollback into the deployments page (#750) by @thegdsks
  • harden PR preview environments (caps, fork approval, single comment) (#745) by @thegdsks
  • audit MCP tool surface and add a token budget test (#758) by @thegdsks
  • machine-readable CLI errors and a --json coverage test (#762) by @thegdsks
  • structured deploy failure object across API, CLI and MCP (#761) by @thegdsks
  • compact log query for agents (MCP query_logs, CLI logs query) (#763) by @thegdsks
  • agent identity on API tokens and audit entries (#765) by @thegdsks
  • wait_for_deploy and plan_change for the agent layer (#766) by @thegdsks
  • platform ops load (apps metrics batch, promote/clone plans, safe upgrade, move plan, honest comparison) (#768) by @thegdsks
  • agent onboarding (init, agent identity UI, log levels, agents settings page) (#769) by @thegdsks
  • AI serving load (model page, engine metrics, VRAM fit, on-demand residency, CDI attach) (#770) by @thegdsks
  • wave 3 agent surface (experimental gate, failure classes, failure view, agent loop e2e, launch docs) (#772) by @thegdsks
  • local dogfood run, experimental gate cleanup, security alert verdicts (#773) by @thegdsks
  • build node routing preference and node onboarding clarity (#775) by @thegdsks
  • cloud node provisioning (Hetzner, DigitalOcean) (#776) by @thegdsks
  • add Azure and GCP cloud node provisioning (#782) by @thegdsks
  • Docker Compose depends_on start ordering, unsupported key validation, apps validate (#784) by @thegdsks
  • overnight batch (cloud node provisioning, real 2-node verification, scheduled deploys, agent/MCP tooling, templates, and more) (#792) by @thegdsks
  • rootless Docker/Podman detection + pipeline OIDC federation (#785) by @thegdsks
  • overnight batch 2 (compose replicas, scheduled-deploy verification, pipeline OIDC, Redis preview isolation, node doctor checks) (#801) by @thegdsks
  • add thesvg logo mappings for 4 catalog templates (#805) by @thegdsks
  • add 16 new self-hosted service templates to catalog (#807) by @thegdsks
  • SLO burn-rate auto-rollback with auto, dry-run, and pause-for-human modes (#810) by @thegdsks
  • web: add brand logos for 5 of the selfhosted4 templates (#812) by @thegdsks
  • one-click deploy for templates with no required config (#811) by @thegdsks
  • add standalone template detail and catalog routes (#814) by @thegdsks
  • search public Docker Hub from the docker-image deploy picker (#815) by @thegdsks
  • connect apps to managed databases via API, CLI, and UI (#818) by @thegdsks
  • add whole-mesh network topology view (#819) by @thegdsks
  • redesign setup wizard server check into a compact summary (#821) by @thegdsks
  • adopt an existing machine as a node over SSH (#822) by @thegdsks
  • wire up support@levelrail.com and support@glincker.com contacts (#827) by @thegdsks
  • docs: add amber WebGL ambient field to homepage hero (#832) by @thegdsks
  • docs: scope hero WebGL field to hero, add scroll parallax and footer stars (#834) by @thegdsks
  • dashboard consistency pass (settings nav, search, headers, InfoTip docs links) (#838) by @thegdsks
  • add dashboard toggle for HSTS (#840) by @thegdsks
  • surface IAM/registry in top nav, real skeletons on detail pages (#842) by @thegdsks
  • dashboard waves 1-2, domains attention and backup relocation (#844) by @thegdsks
  • show WAF, redirect, and maintenance status on the Domains page (#843) by @thegdsks
  • skeleton-first loading states across remaining detail and settings routes (#847) by @thegdsks
  • unify wizard step chrome across setup and node wizards (#849) by @thegdsks
  • sidebar visual redesign with a real expandable Projects tree (#857) by @thegdsks
  • passkey login, Microsoft OAuth, Resend email, and a redesigned login screen (#855) by @thegdsks
  • redesign docs site with custom nav/sidebar and AI-readiness (#860) by @thegdsks
  • local checks post PR signal, flag new comment bloat pre-commit (#862) by @thegdsks
  • support MariaDB in the slow query log viewer (#858) by @thegdsks
  • weekly GHCR cleanup for orphaned untagged image versions (#864) by @thegdsks
  • lock Levelrail visual identity and wire it in (#867) by @thegdsks
  • enlarge Levelrail mark, fix header's placeholder logo (#868) by @thegdsks
  • docs: redesign footer with scroll-reveal and glass pill accents (#871) by @thegdsks
  • add platform capabilities panel to empty dashboard (#870) by @thegdsks
  • roll the real mark out to every remaining fallback spot (#873) by @thegdsks
  • manage orphaned containers, not just view them (#859) by @thegdsks
  • update channel settings, scheduled check, and version-skew notice (#866) by @thegdsks
  • rebuild homepage sections to drop templated card-grid feel (#872) by @thegdsks
  • docs: give each landing feature card real proof, not a generic icon (#878) by @thegdsks
  • browsable template marketplace with category filters and search (#882) by @thegdsks
  • beta feature push (domains/DNS, SSL certs, volumes, NAS, VPN mesh, firewall, signatures) (#884) by @thegdsks
  • mark one-click template deploys as trials, add a stop-and-delete banner (#886) by @thegdsks
  • clean no-root install path for levelrail-cli, like aws/gh (#889) by @thegdsks
  • import 36 Coolify-compatible catalog templates (devtools, productivity, automation) (#896) by @thegdsks
  • wave 3 (changelog, API explorer, cost estimator, templates, push, env diff, topology, forecast, chat approvals) (#890) by @thegdsks
  • add opt-in per-app deploy status badge (#898) by @thegdsks
  • harden and polish the in-app AI assistant chat (#899) by @thegdsks
  • replace keyboard shortcuts dialog with a stage-overlay nav surface (#908) by @thegdsks
  • bring glinui tokens into the control-plane dashboard (#907) by @thegdsks
  • unify brand to petrol-blue, redesign docs homepage, bring glinui tokens to web (#909) by @thegdsks
  • add react-i18next foundation, migrate 3 deploy settings cards (#905) by @thegdsks
  • integrations: add free self-hosted catalog entries (#914) by @thegdsks
  • label certificate events in the audit log (#919) by @thegdsks
  • log API request latency with slow/critical bands (#924) by @thegdsks
  • auto-pick a free dashboard port, make ingress ports overridable (#926) by @thegdsks
  • forward raw TCP streams through the embedded ingress (#921) by @thegdsks
  • surface cross-node ingress unreachability instead of failing silently (#933) by @thegdsks

Security ​

  • security and correctness findings from review of #711 (#713) by @thegdsks
  • security hardening (log redaction, login timing, CSP) (#885) by @thegdsks

Bug fixes ​

  • accessibility pass on status, log viewer and node events, plus component tests (#681) by @thegdsks
  • pin the e2e PITR minio image and skip when the registry is unavailable (#698) by @thegdsks
  • reject a second concurrent manual build of the same app, add deploy pipeline failure-mode tests (#692) by @thegdsks
  • [HIGH] ssrf in http log drains (#688)
  • IAM scoping for app routes, review findings, load balancers and pipelines overview pages, salvaged Jules tests (#708) by @thegdsks
  • pipeline script injection, IAM and stream re-auth gaps, secret binding, gateway limits, MCP safety, container hardening, signed releases (#709) by @thegdsks
  • read host memory on macOS and report unsupported platforms cleanly instead of a raw /proc error (#714) by @thegdsks
  • renumber the deploy approval options migration to 0144, it collided with the status page migration at 0142 (#716) by @thegdsks
  • reject noncanonical upstream ids and clear admin state when a load balancer is removed (#720) by @thegdsks
  • IaC env placeholders require an explicit allowlist and triage of open CodeQL alerts (#717) by @thegdsks
  • dashboard review follow-ups (health link, fallback url, unhealthy diagnosis, cleanup card, read on open, lazy row metrics, stop polling on 404/501) (#722) by @thegdsks
  • load balancer page review followups (safe export commands, no default probe, retry 0, serialized saves, estimated shares) (#723) by @thegdsks
  • deployments review follow-ups (per-event visibility, old held in needs_attention, rollback and live precision) (#726) by @thegdsks
  • scope failed deploys and deploy approvals lists to readable apps (#729) by @thegdsks
  • deployments page review followups (pinned redeploy, confirm copy, deep link, retry loop) (#730) by @thegdsks
  • judge deleted-app approvals by IAM instead of hiding them (#732) by @thegdsks
  • deploy preview review follow-ups (opt-out, deletion, labeling races) (#733) by @thegdsks
  • scope cross-app list endpoints to apps the caller can read (#734) by @thegdsks
  • unbounded scoped backup paging and case-insensitive cert domain ownership (#735) by @thegdsks
  • preview tiers review follow-ups (card kept on failure, public-domain Host, bounded thumbs) (#738) by @thegdsks
  • change correlation and SLO burn review follow-ups (#746) by @thegdsks
  • hugging face preflight review follow-ups (docker disk, per-GPU fit, gated ollama, file lookup, cache key, UI) (#747) by @thegdsks
  • supply chain gate review follow-ups (#749) by @thegdsks
  • review follow-ups for path filters and forge status reporting (#748) by @thegdsks
  • deployments preview follow-ups (#739) by @thegdsks
  • launch wave 1 (nightly, CodeQL, agent-core MCP profile, env tools, VPS smoke) (#759) by @thegdsks
  • preview hardening and agent-core profile follow-ups (#771) by @thegdsks
  • static-site CLI gaps, framework detection, webhook URL, git import (F-017/F-018/F-020/F-021/F-022/F-023) (#778) by @thegdsks
  • node provisioning follow-up fixes from post-merge review (#779) by @thegdsks
  • gate ingress routing and deploy-attempt status on real readiness (F-002) (#774) by @thegdsks
  • resolve migration 0135 number collision (#787) by @thegdsks
  • remove duplicate backup_history index migration (#788) by @thegdsks
  • cap API token abilities to the caller's own, add route guard test (#689) by @thegdsks
  • silence shellcheck SC2016 false positive in install.sh test (#789) by @thegdsks
  • remove duplicate backup_history migration and quote colons in docs frontmatter (#790) by @thegdsks
  • scope lint cache per worktree, harden AI-attribution check (#793) by @thegdsks
  • reuse existing badge variant, add inferable name defaults (#797) by @thegdsks
  • replace window.confirm with the standard delete-confirm dialog (#800) by @thegdsks
  • address SonarCloud gate findings on overnight2 (#804) by @thegdsks
  • resolve database env vars to mesh DNS names, not container names (#816) by @thegdsks
  • detect actually-open dialogs, not closed-but-mounted ones (#820) by @thegdsks
  • force vite to apply CJS interop to mermaid's fastdom dep (#831) by @thegdsks
  • paint the hero WebGL field's first frame unconditionally (#833) by @thegdsks
  • stop squeezing the template catalog into a narrow fullscreen column (#845) by @thegdsks
  • dashboard visual polish across metric tiles, node providers, and domains (#856) by @thegdsks
  • close a status race in SSH node provisioning (#863) by @thegdsks
  • recover two commits orphaned by an earlier merge-queue timing race (#865) by @thegdsks
  • docs: footer giant mark position, mobile overflow, and scroll reveal (#875) by @thegdsks
  • docs: keep hero stars twinkling instead of fading to black, pause offscreen (#874) by @thegdsks
  • stop forcing the favicon mark to look small (#876) by @thegdsks
  • cache-bust the favicon so a redeploy actually shows the new one (#877) by @thegdsks
  • mesh placement bug, safe SQLite volume backups, settings sidebar (#880) by @thegdsks
  • accessibility and baseline-ui pass on the beta feature wave (#887) by @thegdsks
  • confirm dialog for deploy cancel, aria-hidden on status header icon (#895) by @thegdsks
  • remove unresolved merge markers from main's api-reference.md (#900) by @thegdsks
  • collapse long always-visible prose into on-demand InfoTip (#903) by @thegdsks
  • [HIGH] ssrf in http log drain sinks (#894)
  • drop --delete-branch from dependabot auto-merge, incompatible with the merge queue (#906) by @thegdsks
  • CPU percent always reads near zero on some Docker installs (#904) by @thegdsks
  • extend pre-commit comment-density check to web/*.ts and *.tsx (#910) by @thegdsks
  • Docker web-build symlinks, stop forcing full CI on every main push (#911) by @thegdsks
  • point MinIO template at its still-public registry path (#913) by @thegdsks
  • stop showing add-tag control on every app tab (#920) by @thegdsks
  • stop showing a dead container's logs as live in blue-green overlaps (#923) by @thegdsks
  • reuse stored git-source token, merge ingress settings on set (#928) by @thegdsks
  • resolve non-default branch refs in manual build triggers (#930) by @thegdsks
  • sort beta releases by publish time, not list order (#931) by @thegdsks
  • GitHub App manifest redirect blocked by its own CSP (#929) by @thegdsks

Performance ​

  • idle footprint benchmark, cached Docker disk usage, single container list per suspended reconcile (#695) by @thegdsks
  • Skip weekend run (#724)
  • index backup_history by started_at (#705)
  • optimize get conditions for controllers query (#791)
  • split internal/api test shard from 3 to 4 in fast CI lane (#795) by @thegdsks
  • use json_each for SQLite IN clauses (#802)
  • batch SQLite telemetry inserts using json_each (#881)
  • optimize ListAppEvents and ListDeployFreezeWindows IN clauses (#893)

Documentation ​

  • refresh roadmap, feature catalog, README status and CLI reference (#676) by @thegdsks
  • add feature status page with per-area evidence and labels (#756) by @thegdsks
  • note APP_AGENT_ADVERTISE_HOST requirement for real node enrollment (#780) by @thegdsks
  • render mermaid diagrams, search body text, rewrite operator-facing content (#777) by @thegdsks
  • explain mesh DNS resolution for cross-node database connections (#817) by @thegdsks
  • fill network topology and connections gaps, tighten onboarding (#825) by @thegdsks
  • redesign homepage with bento feature grid and real visual identity (#828) by @thegdsks
  • add metallic headline gradient to homepage hero (#829) by @thegdsks
  • serve install.sh from levelrail.com instead of raw GitHub URL (#830) by @thegdsks
  • add credibility content to homepage (#835) by @thegdsks
  • fix llms.txt domain, add sitemap lastmod/priority, per-page OG image (#837) by @thegdsks
  • add a serif pull-quote accent card to the homepage (#836) by @thegdsks
  • lead with user tasks instead of implementation details (#841) by @thegdsks
  • polish homepage cohesion across tonight's content passes (#839) by @thegdsks
  • remove GitHub star count from homepage trust strip (#846) by @thegdsks
  • strip inline implementation names from resilience, DR, and backups pages (#851) by @thegdsks
  • add real mermaid architecture diagrams to 16 pages (#852) by @thegdsks
  • lead git-integrations, templates, feature-flags, and projects pages with user tasks (#853) by @thegdsks
  • capture and embed load balancer, app overview, and network screenshots (#854) by @thegdsks
  • record the docs site's amber accent as a deliberate second brand color (#879) by @thegdsks
  • add a who-this-is-for page grounded in shipped features (#915) by @thegdsks
  • apply the pending corrections from feature-status.md's audit (#917) by @thegdsks
  • add full template catalog page (#916) by @thegdsks
  • clarify the dashboard port isn't always 8080 (#927) by @thegdsks
Maintenance, CI, and dependency updates (33)
  • add coverage for spec validation, compose parsing, audit retention, alerting migration and device auth (#662) by @thegdsks
  • fast pre-push lane, smoke script that drives the real CLI, dev loop docs (#665) by @thegdsks
  • auto-delete merged PR branches and sweep stale ones weekly (#666) by @thegdsks
  • add gitleaks secret scanning (config, pre-commit hook, CI workflow) (#667) by @thegdsks
  • half-success retry coverage for reconcilers (#677) by @thegdsks
  • real strict typecheck in pre-commit, free gitleaks binary instead of the licensed action (#679) by @thegdsks
  • group dependabot updates and hold cel-go until caddy supports 0.29 (#680) by @thegdsks
  • fold PR labels, size and anti-slop into one hygiene job, move flake report off PRs (#668) by @thegdsks
  • bump the actions group across 1 directory with 3 updates (#687)
  • bump the npm-deps group in /web with 3 updates (#703)
  • bump github.com/containerd/containerd/v2 from 2.3.5 to 2.3.6 (#707)
  • impact-based PR checks scoped to the affected packages and areas (#767) by @thegdsks
  • verify control plane death survival for workloads, ingress, and agents (#781) by @thegdsks
  • consolidate duplicated webhook header and pipeline status literals (#796) by @thegdsks
  • introduce reconcile.ConditionTypeReady constant (#798) by @thegdsks
  • align changelog config with actually-allowed commit types (#799) by @thegdsks
  • use EmptyState primitive for audit log, organizations, and projects (#803)
  • bump undici from 7.29.0 to 7.30.0 in /web (#806)
  • web: consolidate EmptyState onto one shared component (#808) by @thegdsks
  • bump ip-address from 10.5.0 to 10.7.2 in /web (#809)
  • web: consolidate ad-hoc error states onto Alert/EmptyState (#813) by @thegdsks
  • bump brace-expansion from 5.0.9 to 5.0.12 in /web (#823)
  • bump fast-uri from 3.1.7 to 3.1.8 in /web (#824)
  • migrate docs site to levelrail.com (#826) by @thegdsks
  • deduplicate handleListDomains's four status-flag fetches (#848) by @thegdsks
  • give control-plane backup/DR its own settings page, unify wizard back-buttons (#850) by @thegdsks
  • bump dompurify (#861)
  • deploy a diverse catalog template sample through the real reconciler (#888) by @thegdsks
  • close 3 more e2e gaps (supply chain, platform-as-code, load balancer) (#901) by @thegdsks
  • Unify brand to petrol-blue, redesign docs site, add glinui components (#902) by @thegdsks
  • bump the npm-deps group in /web with 10 updates (#891)
  • close 5 e2e gaps, add per-app health & readiness score (#897) by @thegdsks
  • bump the go-deps group across 1 directory with 12 updates (#892)

Install ​

Fresh install on a Linux host, pinned to this release:

sh
curl -fsSL https://raw.githubusercontent.com/glincker/levelrail/main/install.sh | sudo env LEVELRAIL_VERSION=v0.2.0-beta.15 sh

Upgrade an existing install in place (keeps the unit file and data):

sh
curl -fsSL https://raw.githubusercontent.com/glincker/levelrail/main/install.sh | sudo env LEVELRAIL_VERSION=v0.2.0-beta.15 sh -s upgrade

Docker Compose: pin the image tag in docker-compose.yml:

yaml
services:
  levelrail:
    image: ghcr.io/glincker/levelrail:v0.2.0-beta.15

Container images ​

Multi-arch (linux/amd64, linux/arm64), signed with cosign, SBOM and provenance attached. Also tagged beta at release time (moving tags).

ImageTagDigest
ghcr.io/glincker/levelrailv0.2.0-beta.15sha256:202922c1616985e9676dd8322d34797d987d2715968ed726ed7ffb719cc75c47
ghcr.io/glincker/levelrail-agentv0.2.0-beta.15sha256:6fcd7fbb876f218abc0adec3cc1567afe24bdd28887b0532a3551de564d1dcd2

Verify ​

Binaries: check downloads against checksums.txt:

sh
gh release download v0.2.0-beta.15 --repo glincker/levelrail --pattern 'levelrail-linux-amd64' --pattern checksums.txt
sha256sum --ignore-missing -c checksums.txt

Images: verify the keyless signature was made by this repository's release workflow:

sh
cosign verify ghcr.io/glincker/levelrail@sha256:202922c1616985e9676dd8322d34797d987d2715968ed726ed7ffb719cc75c47 \
  --certificate-identity-regexp '^https://github\.com/glincker/levelrail/\.github/workflows/release\.yml@refs/(heads/main|tags/v.+)$' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

Contributors ​

  • google-labs-jules[bot] made their first contribution in #688

Thanks to @thegdsks.

Full changelog: v0.2.0-beta.14...v0.2.0-beta.15 | Release page | Installing | Upgrading | Verifying signatures

Released under the Apache 2.0 License.