Levelrail v0.2.0-beta.15
NOTE
This is a pre-release on the beta channel. Pin this exact version for anything you care about staying still.
Highlights
- log controls, brand logos, status page, disk and cert guards (#663) by @thegdsks
- log level tags, level filter chips, expandable rows and jump to first error (#669) by @thegdsks
- brand logos for frameworks, integrations and backup targets (#671) by @thegdsks
What's changed
Features
- log controls, brand logos, status page, disk and cert guards (#663) by @thegdsks
- log level tags, level filter chips, expandable rows and jump to first error (#669) by @thegdsks
- brand logos for frameworks, integrations and backup targets (#671) by @thegdsks
- report certificate renewal state (ok or stalled) in API, CLI and dashboard (#670) by @thegdsks
- server-side audit log search and failed-only filter (#674) by @thegdsks
- control plane self-backup and offline restore (snapshots, scheduler, pre-migration copy, downgrade guard, CLI, docs) (#678) by @thegdsks
- control plane backups card on general settings (#675) by @thegdsks
- app quick actions menu, redeploy button, empty-state CTAs (#672) by @thegdsks
- failed deploys and disk pressure in attention (#673) by @thegdsks
- cli build detect/branches and restore history lists (backups, pitr, app-volume-backups) (#684) by @thegdsks
- add 12 service templates (catalog tranche 5) (#683) by @thegdsks
- doctor check for stale control plane backups, verified pre-upgrade snapshot and downgrade guard live (#685) by @thegdsks
- MCP tools for attention, node status history, audit search and control plane backups (#682) by @thegdsks
- command palette actions, per-app quick actions, recent items and keyboard hints (#693) by @thegdsks
- app health timeline on the overview page (deploys, restarts, error windows) (#694) by @thegdsks
- dashboard setup checklist, deploy failure summary and keyboard shortcuts help (#699) by @thegdsks
- env editor .env import preview, pending diff, secret-safe export, and apps env import/export CLI (#690) by @thegdsks
- readyz endpoint, CLI parity tranche 2, MCP backup verify and failed deploys tools, e2e cleanup (#700) by @thegdsks
- node_offline alert kind (API, CLI, dashboard, docs) (#691) by @thegdsks
- connection-lost banner with backoff reconnect and 12 new service templates (#696) by @thegdsks
- security follow-ups, control plane backup stale alert and verify, generated API reference (#697) by @thegdsks
- AI model deploys on GPU nodes, load balancer, S3/R2 log archive, pipelines, catalogue (#701) by @thegdsks
- GPU-aware scheduling, S3 build cache, pipeline graph and repo sync, fork PR guard, gateway fix (#702) by @thegdsks
- agent certificate renewal, agent-generated keys, re-enrollment and agent version reporting (#710) by @thegdsks
- request metrics, deploy safety, model keys, app management, import, preflight and migration runner fix (#711) by @thegdsks
- encrypted off-box control plane backups, platform as code, alert silences and a public status page (#712) by @thegdsks
- dashboard redesign with a UI kit, overview v2, mission control home, visual apps list and grouped navigation (#715) by @thegdsks
- load balancer check history, check now and per-upstream admin state (#719) by @thegdsks
- load balancer page redesign with live topology, suggestions, health history and export (#721) by @thegdsks
- app timeline, pending changes, secret declaration on set, domains CLI and previous-release hold cap (#718) by @thegdsks
- cross-app deployments API with summary, stream, CLI and MCP tools (#725) by @thegdsks
- cross-app deployments page with live feed, filters, drawer and shortcuts (#728) by @thegdsks
- deploy preview screenshots (opt-in thumbnails per deploy) (#727) by @thegdsks
- tiered deploy previews with a free metadata default (#736) by @thegdsks
- real preview thumbnails on the deployments page and cross-app API (#737) by @thegdsks
- per-key daily token budget, created_by, revoke MCP tool and reworked model keys panel (#740) by @thegdsks
- Hugging Face preflight and model cache manager (#741) by @thegdsks
- change correlation on alerts and SLO burn-rate rules (#742) by @thegdsks
- path filters, merge queue trigger, and forge status reporting for pipelines and deploys (#744) by @thegdsks
- supply chain visibility per deploy (SBOM, optional scan gate) (#743) by @thegdsks
- cancel, queue and digest-pinned rollback for deploys (#731) by @thegdsks
- wire queue, cancel and digest rollback into the deployments page (#750) by @thegdsks
- harden PR preview environments (caps, fork approval, single comment) (#745) by @thegdsks
- audit MCP tool surface and add a token budget test (#758) by @thegdsks
- machine-readable CLI errors and a --json coverage test (#762) by @thegdsks
- structured deploy failure object across API, CLI and MCP (#761) by @thegdsks
- compact log query for agents (MCP query_logs, CLI logs query) (#763) by @thegdsks
- agent identity on API tokens and audit entries (#765) by @thegdsks
- wait_for_deploy and plan_change for the agent layer (#766) by @thegdsks
- platform ops load (apps metrics batch, promote/clone plans, safe upgrade, move plan, honest comparison) (#768) by @thegdsks
- agent onboarding (init, agent identity UI, log levels, agents settings page) (#769) by @thegdsks
- AI serving load (model page, engine metrics, VRAM fit, on-demand residency, CDI attach) (#770) by @thegdsks
- wave 3 agent surface (experimental gate, failure classes, failure view, agent loop e2e, launch docs) (#772) by @thegdsks
- local dogfood run, experimental gate cleanup, security alert verdicts (#773) by @thegdsks
- build node routing preference and node onboarding clarity (#775) by @thegdsks
- cloud node provisioning (Hetzner, DigitalOcean) (#776) by @thegdsks
- add Azure and GCP cloud node provisioning (#782) by @thegdsks
- Docker Compose depends_on start ordering, unsupported key validation, apps validate (#784) by @thegdsks
- overnight batch (cloud node provisioning, real 2-node verification, scheduled deploys, agent/MCP tooling, templates, and more) (#792) by @thegdsks
- rootless Docker/Podman detection + pipeline OIDC federation (#785) by @thegdsks
- overnight batch 2 (compose replicas, scheduled-deploy verification, pipeline OIDC, Redis preview isolation, node doctor checks) (#801) by @thegdsks
- add thesvg logo mappings for 4 catalog templates (#805) by @thegdsks
- add 16 new self-hosted service templates to catalog (#807) by @thegdsks
- SLO burn-rate auto-rollback with auto, dry-run, and pause-for-human modes (#810) by @thegdsks
- web: add brand logos for 5 of the selfhosted4 templates (#812) by @thegdsks
- one-click deploy for templates with no required config (#811) by @thegdsks
- add standalone template detail and catalog routes (#814) by @thegdsks
- search public Docker Hub from the docker-image deploy picker (#815) by @thegdsks
- connect apps to managed databases via API, CLI, and UI (#818) by @thegdsks
- add whole-mesh network topology view (#819) by @thegdsks
- redesign setup wizard server check into a compact summary (#821) by @thegdsks
- adopt an existing machine as a node over SSH (#822) by @thegdsks
- wire up support@levelrail.com and support@glincker.com contacts (#827) by @thegdsks
- docs: add amber WebGL ambient field to homepage hero (#832) by @thegdsks
- docs: scope hero WebGL field to hero, add scroll parallax and footer stars (#834) by @thegdsks
- dashboard consistency pass (settings nav, search, headers, InfoTip docs links) (#838) by @thegdsks
- add dashboard toggle for HSTS (#840) by @thegdsks
- surface IAM/registry in top nav, real skeletons on detail pages (#842) by @thegdsks
- dashboard waves 1-2, domains attention and backup relocation (#844) by @thegdsks
- show WAF, redirect, and maintenance status on the Domains page (#843) by @thegdsks
- skeleton-first loading states across remaining detail and settings routes (#847) by @thegdsks
- unify wizard step chrome across setup and node wizards (#849) by @thegdsks
- sidebar visual redesign with a real expandable Projects tree (#857) by @thegdsks
- passkey login, Microsoft OAuth, Resend email, and a redesigned login screen (#855) by @thegdsks
- redesign docs site with custom nav/sidebar and AI-readiness (#860) by @thegdsks
- local checks post PR signal, flag new comment bloat pre-commit (#862) by @thegdsks
- support MariaDB in the slow query log viewer (#858) by @thegdsks
- weekly GHCR cleanup for orphaned untagged image versions (#864) by @thegdsks
- lock Levelrail visual identity and wire it in (#867) by @thegdsks
- enlarge Levelrail mark, fix header's placeholder logo (#868) by @thegdsks
- docs: redesign footer with scroll-reveal and glass pill accents (#871) by @thegdsks
- add platform capabilities panel to empty dashboard (#870) by @thegdsks
- roll the real mark out to every remaining fallback spot (#873) by @thegdsks
- manage orphaned containers, not just view them (#859) by @thegdsks
- update channel settings, scheduled check, and version-skew notice (#866) by @thegdsks
- rebuild homepage sections to drop templated card-grid feel (#872) by @thegdsks
- docs: give each landing feature card real proof, not a generic icon (#878) by @thegdsks
- browsable template marketplace with category filters and search (#882) by @thegdsks
- beta feature push (domains/DNS, SSL certs, volumes, NAS, VPN mesh, firewall, signatures) (#884) by @thegdsks
- mark one-click template deploys as trials, add a stop-and-delete banner (#886) by @thegdsks
- clean no-root install path for levelrail-cli, like aws/gh (#889) by @thegdsks
- import 36 Coolify-compatible catalog templates (devtools, productivity, automation) (#896) by @thegdsks
- wave 3 (changelog, API explorer, cost estimator, templates, push, env diff, topology, forecast, chat approvals) (#890) by @thegdsks
- add opt-in per-app deploy status badge (#898) by @thegdsks
- harden and polish the in-app AI assistant chat (#899) by @thegdsks
- replace keyboard shortcuts dialog with a stage-overlay nav surface (#908) by @thegdsks
- bring glinui tokens into the control-plane dashboard (#907) by @thegdsks
- unify brand to petrol-blue, redesign docs homepage, bring glinui tokens to web (#909) by @thegdsks
- add react-i18next foundation, migrate 3 deploy settings cards (#905) by @thegdsks
- integrations: add free self-hosted catalog entries (#914) by @thegdsks
- label certificate events in the audit log (#919) by @thegdsks
- log API request latency with slow/critical bands (#924) by @thegdsks
- auto-pick a free dashboard port, make ingress ports overridable (#926) by @thegdsks
- forward raw TCP streams through the embedded ingress (#921) by @thegdsks
- surface cross-node ingress unreachability instead of failing silently (#933) by @thegdsks
Security
- security and correctness findings from review of #711 (#713) by @thegdsks
- security hardening (log redaction, login timing, CSP) (#885) by @thegdsks
Bug fixes
- accessibility pass on status, log viewer and node events, plus component tests (#681) by @thegdsks
- pin the e2e PITR minio image and skip when the registry is unavailable (#698) by @thegdsks
- reject a second concurrent manual build of the same app, add deploy pipeline failure-mode tests (#692) by @thegdsks
- [HIGH] ssrf in http log drains (#688)
- IAM scoping for app routes, review findings, load balancers and pipelines overview pages, salvaged Jules tests (#708) by @thegdsks
- pipeline script injection, IAM and stream re-auth gaps, secret binding, gateway limits, MCP safety, container hardening, signed releases (#709) by @thegdsks
- read host memory on macOS and report unsupported platforms cleanly instead of a raw /proc error (#714) by @thegdsks
- renumber the deploy approval options migration to 0144, it collided with the status page migration at 0142 (#716) by @thegdsks
- reject noncanonical upstream ids and clear admin state when a load balancer is removed (#720) by @thegdsks
- IaC env placeholders require an explicit allowlist and triage of open CodeQL alerts (#717) by @thegdsks
- dashboard review follow-ups (health link, fallback url, unhealthy diagnosis, cleanup card, read on open, lazy row metrics, stop polling on 404/501) (#722) by @thegdsks
- load balancer page review followups (safe export commands, no default probe, retry 0, serialized saves, estimated shares) (#723) by @thegdsks
- deployments review follow-ups (per-event visibility, old held in needs_attention, rollback and live precision) (#726) by @thegdsks
- scope failed deploys and deploy approvals lists to readable apps (#729) by @thegdsks
- deployments page review followups (pinned redeploy, confirm copy, deep link, retry loop) (#730) by @thegdsks
- judge deleted-app approvals by IAM instead of hiding them (#732) by @thegdsks
- deploy preview review follow-ups (opt-out, deletion, labeling races) (#733) by @thegdsks
- scope cross-app list endpoints to apps the caller can read (#734) by @thegdsks
- unbounded scoped backup paging and case-insensitive cert domain ownership (#735) by @thegdsks
- preview tiers review follow-ups (card kept on failure, public-domain Host, bounded thumbs) (#738) by @thegdsks
- change correlation and SLO burn review follow-ups (#746) by @thegdsks
- hugging face preflight review follow-ups (docker disk, per-GPU fit, gated ollama, file lookup, cache key, UI) (#747) by @thegdsks
- supply chain gate review follow-ups (#749) by @thegdsks
- review follow-ups for path filters and forge status reporting (#748) by @thegdsks
- deployments preview follow-ups (#739) by @thegdsks
- launch wave 1 (nightly, CodeQL, agent-core MCP profile, env tools, VPS smoke) (#759) by @thegdsks
- preview hardening and agent-core profile follow-ups (#771) by @thegdsks
- static-site CLI gaps, framework detection, webhook URL, git import (F-017/F-018/F-020/F-021/F-022/F-023) (#778) by @thegdsks
- node provisioning follow-up fixes from post-merge review (#779) by @thegdsks
- gate ingress routing and deploy-attempt status on real readiness (F-002) (#774) by @thegdsks
- resolve migration 0135 number collision (#787) by @thegdsks
- remove duplicate backup_history index migration (#788) by @thegdsks
- cap API token abilities to the caller's own, add route guard test (#689) by @thegdsks
- silence shellcheck SC2016 false positive in install.sh test (#789) by @thegdsks
- remove duplicate backup_history migration and quote colons in docs frontmatter (#790) by @thegdsks
- scope lint cache per worktree, harden AI-attribution check (#793) by @thegdsks
- reuse existing badge variant, add inferable name defaults (#797) by @thegdsks
- replace window.confirm with the standard delete-confirm dialog (#800) by @thegdsks
- address SonarCloud gate findings on overnight2 (#804) by @thegdsks
- resolve database env vars to mesh DNS names, not container names (#816) by @thegdsks
- detect actually-open dialogs, not closed-but-mounted ones (#820) by @thegdsks
- force vite to apply CJS interop to mermaid's fastdom dep (#831) by @thegdsks
- paint the hero WebGL field's first frame unconditionally (#833) by @thegdsks
- stop squeezing the template catalog into a narrow fullscreen column (#845) by @thegdsks
- dashboard visual polish across metric tiles, node providers, and domains (#856) by @thegdsks
- close a status race in SSH node provisioning (#863) by @thegdsks
- recover two commits orphaned by an earlier merge-queue timing race (#865) by @thegdsks
- docs: footer giant mark position, mobile overflow, and scroll reveal (#875) by @thegdsks
- docs: keep hero stars twinkling instead of fading to black, pause offscreen (#874) by @thegdsks
- stop forcing the favicon mark to look small (#876) by @thegdsks
- cache-bust the favicon so a redeploy actually shows the new one (#877) by @thegdsks
- mesh placement bug, safe SQLite volume backups, settings sidebar (#880) by @thegdsks
- accessibility and baseline-ui pass on the beta feature wave (#887) by @thegdsks
- confirm dialog for deploy cancel, aria-hidden on status header icon (#895) by @thegdsks
- remove unresolved merge markers from main's api-reference.md (#900) by @thegdsks
- collapse long always-visible prose into on-demand InfoTip (#903) by @thegdsks
- [HIGH] ssrf in http log drain sinks (#894)
- drop --delete-branch from dependabot auto-merge, incompatible with the merge queue (#906) by @thegdsks
- CPU percent always reads near zero on some Docker installs (#904) by @thegdsks
- extend pre-commit comment-density check to web/*.ts and *.tsx (#910) by @thegdsks
- Docker web-build symlinks, stop forcing full CI on every main push (#911) by @thegdsks
- point MinIO template at its still-public registry path (#913) by @thegdsks
- stop showing add-tag control on every app tab (#920) by @thegdsks
- stop showing a dead container's logs as live in blue-green overlaps (#923) by @thegdsks
- reuse stored git-source token, merge ingress settings on set (#928) by @thegdsks
- resolve non-default branch refs in manual build triggers (#930) by @thegdsks
- sort beta releases by publish time, not list order (#931) by @thegdsks
- GitHub App manifest redirect blocked by its own CSP (#929) by @thegdsks
Performance
- idle footprint benchmark, cached Docker disk usage, single container list per suspended reconcile (#695) by @thegdsks
- Skip weekend run (#724)
- index backup_history by started_at (#705)
- optimize get conditions for controllers query (#791)
- split internal/api test shard from 3 to 4 in fast CI lane (#795) by @thegdsks
- use json_each for SQLite IN clauses (#802)
- batch SQLite telemetry inserts using json_each (#881)
- optimize ListAppEvents and ListDeployFreezeWindows IN clauses (#893)
Documentation
- refresh roadmap, feature catalog, README status and CLI reference (#676) by @thegdsks
- add feature status page with per-area evidence and labels (#756) by @thegdsks
- note APP_AGENT_ADVERTISE_HOST requirement for real node enrollment (#780) by @thegdsks
- render mermaid diagrams, search body text, rewrite operator-facing content (#777) by @thegdsks
- explain mesh DNS resolution for cross-node database connections (#817) by @thegdsks
- fill network topology and connections gaps, tighten onboarding (#825) by @thegdsks
- redesign homepage with bento feature grid and real visual identity (#828) by @thegdsks
- add metallic headline gradient to homepage hero (#829) by @thegdsks
- serve install.sh from levelrail.com instead of raw GitHub URL (#830) by @thegdsks
- add credibility content to homepage (#835) by @thegdsks
- fix llms.txt domain, add sitemap lastmod/priority, per-page OG image (#837) by @thegdsks
- add a serif pull-quote accent card to the homepage (#836) by @thegdsks
- lead with user tasks instead of implementation details (#841) by @thegdsks
- polish homepage cohesion across tonight's content passes (#839) by @thegdsks
- remove GitHub star count from homepage trust strip (#846) by @thegdsks
- strip inline implementation names from resilience, DR, and backups pages (#851) by @thegdsks
- add real mermaid architecture diagrams to 16 pages (#852) by @thegdsks
- lead git-integrations, templates, feature-flags, and projects pages with user tasks (#853) by @thegdsks
- capture and embed load balancer, app overview, and network screenshots (#854) by @thegdsks
- record the docs site's amber accent as a deliberate second brand color (#879) by @thegdsks
- add a who-this-is-for page grounded in shipped features (#915) by @thegdsks
- apply the pending corrections from feature-status.md's audit (#917) by @thegdsks
- add full template catalog page (#916) by @thegdsks
- clarify the dashboard port isn't always 8080 (#927) by @thegdsks
Maintenance, CI, and dependency updates (33)
- add coverage for spec validation, compose parsing, audit retention, alerting migration and device auth (#662) by @thegdsks
- fast pre-push lane, smoke script that drives the real CLI, dev loop docs (#665) by @thegdsks
- auto-delete merged PR branches and sweep stale ones weekly (#666) by @thegdsks
- add gitleaks secret scanning (config, pre-commit hook, CI workflow) (#667) by @thegdsks
- half-success retry coverage for reconcilers (#677) by @thegdsks
- real strict typecheck in pre-commit, free gitleaks binary instead of the licensed action (#679) by @thegdsks
- group dependabot updates and hold cel-go until caddy supports 0.29 (#680) by @thegdsks
- fold PR labels, size and anti-slop into one hygiene job, move flake report off PRs (#668) by @thegdsks
- bump the actions group across 1 directory with 3 updates (#687)
- bump the npm-deps group in /web with 3 updates (#703)
- bump github.com/containerd/containerd/v2 from 2.3.5 to 2.3.6 (#707)
- impact-based PR checks scoped to the affected packages and areas (#767) by @thegdsks
- verify control plane death survival for workloads, ingress, and agents (#781) by @thegdsks
- consolidate duplicated webhook header and pipeline status literals (#796) by @thegdsks
- introduce reconcile.ConditionTypeReady constant (#798) by @thegdsks
- align changelog config with actually-allowed commit types (#799) by @thegdsks
- use EmptyState primitive for audit log, organizations, and projects (#803)
- bump undici from 7.29.0 to 7.30.0 in /web (#806)
- web: consolidate EmptyState onto one shared component (#808) by @thegdsks
- bump ip-address from 10.5.0 to 10.7.2 in /web (#809)
- web: consolidate ad-hoc error states onto Alert/EmptyState (#813) by @thegdsks
- bump brace-expansion from 5.0.9 to 5.0.12 in /web (#823)
- bump fast-uri from 3.1.7 to 3.1.8 in /web (#824)
- migrate docs site to levelrail.com (#826) by @thegdsks
- deduplicate handleListDomains's four status-flag fetches (#848) by @thegdsks
- give control-plane backup/DR its own settings page, unify wizard back-buttons (#850) by @thegdsks
- bump dompurify (#861)
- deploy a diverse catalog template sample through the real reconciler (#888) by @thegdsks
- close 3 more e2e gaps (supply chain, platform-as-code, load balancer) (#901) by @thegdsks
- Unify brand to petrol-blue, redesign docs site, add glinui components (#902) by @thegdsks
- bump the npm-deps group in /web with 10 updates (#891)
- close 5 e2e gaps, add per-app health & readiness score (#897) by @thegdsks
- bump the go-deps group across 1 directory with 12 updates (#892)
Install
Fresh install on a Linux host, pinned to this release:
sh
curl -fsSL https://raw.githubusercontent.com/glincker/levelrail/main/install.sh | sudo env LEVELRAIL_VERSION=v0.2.0-beta.15 shUpgrade an existing install in place (keeps the unit file and data):
sh
curl -fsSL https://raw.githubusercontent.com/glincker/levelrail/main/install.sh | sudo env LEVELRAIL_VERSION=v0.2.0-beta.15 sh -s upgradeDocker Compose: pin the image tag in docker-compose.yml:
yaml
services:
levelrail:
image: ghcr.io/glincker/levelrail:v0.2.0-beta.15Container images
Multi-arch (linux/amd64, linux/arm64), signed with cosign, SBOM and provenance attached. Also tagged beta at release time (moving tags).
| Image | Tag | Digest |
|---|---|---|
ghcr.io/glincker/levelrail | v0.2.0-beta.15 | sha256:202922c1616985e9676dd8322d34797d987d2715968ed726ed7ffb719cc75c47 |
ghcr.io/glincker/levelrail-agent | v0.2.0-beta.15 | sha256:6fcd7fbb876f218abc0adec3cc1567afe24bdd28887b0532a3551de564d1dcd2 |
Verify
Binaries: check downloads against checksums.txt:
sh
gh release download v0.2.0-beta.15 --repo glincker/levelrail --pattern 'levelrail-linux-amd64' --pattern checksums.txt
sha256sum --ignore-missing -c checksums.txtImages: verify the keyless signature was made by this repository's release workflow:
sh
cosign verify ghcr.io/glincker/levelrail@sha256:202922c1616985e9676dd8322d34797d987d2715968ed726ed7ffb719cc75c47 \
--certificate-identity-regexp '^https://github\.com/glincker/levelrail/\.github/workflows/release\.yml@refs/(heads/main|tags/v.+)$' \
--certificate-oidc-issuer https://token.actions.githubusercontent.comContributors
- google-labs-jules[bot] made their first contribution in #688
Thanks to @thegdsks.
Full changelog: v0.2.0-beta.14...v0.2.0-beta.15 | Release page | Installing | Upgrading | Verifying signatures