Skip to content

Levelrail v0.2.0-beta.17 ​

Released as a pre-release. View on GitHub. All releases.

NOTE

This is a pre-release on the beta channel. Pin this exact version for anything you care about staying still.

What's changed ​

Features ​

  • one-command npm bootstrap and opt-in hands-off releases (#995) by @thegdsks
  • route ingress to apps on remote nodes over the WireGuard mesh (#996) by @thegdsks

Security ​

  • security review hardening (CSRF, cert purge churn, placeholder escape, git SSRF, hardening default) (#997) by @thegdsks

Bug fixes ​

  • make node enrolment and mesh work out of the box on the agent image (#983) by @thegdsks
  • Homebrew formula exec bit, npm trusted publishing, split publish jobs (#992) by @thegdsks
  • auth: token ownership, OAuth state binding with PKCE, atomic device redeem (#981) by @thegdsks
  • balance multi-replica apps by default and route the local node's replicas (#994) by @thegdsks
  • app delete tears containers down and retries until gone (#991) by @thegdsks

Install ​

Fresh install on a Linux host, pinned to this release:

sh
curl -fsSL https://raw.githubusercontent.com/glincker/levelrail/main/install.sh | sudo env LEVELRAIL_VERSION=v0.2.0-beta.17 sh

Upgrade an existing install in place (keeps the unit file and data):

sh
curl -fsSL https://raw.githubusercontent.com/glincker/levelrail/main/install.sh | sudo env LEVELRAIL_VERSION=v0.2.0-beta.17 sh -s upgrade

Docker Compose: pin the image tag in docker-compose.yml:

yaml
services:
  levelrail:
    image: ghcr.io/glincker/levelrail:v0.2.0-beta.17

Container images ​

Multi-arch (linux/amd64, linux/arm64), signed with cosign, SBOM and provenance attached. Also tagged beta at release time (moving tags).

ImageTagDigest
ghcr.io/glincker/levelrailv0.2.0-beta.17sha256:9bd3e65906f7b1a56ced3237d545a2e5bd0b459499807c58bfcae60affc96fe0
ghcr.io/glincker/levelrail-agentv0.2.0-beta.17sha256:a4e2872db24c8b27a21a3b78003bbf3fbd5c919ebd07b50583592058bf4fb8ae

Verify ​

Binaries: check downloads against checksums.txt:

sh
gh release download v0.2.0-beta.17 --repo glincker/levelrail --pattern 'levelrail-linux-amd64' --pattern checksums.txt
sha256sum --ignore-missing -c checksums.txt

Images: verify the keyless signature was made by this repository's release workflow:

sh
cosign verify ghcr.io/glincker/levelrail@sha256:9bd3e65906f7b1a56ced3237d545a2e5bd0b459499807c58bfcae60affc96fe0 \
  --certificate-identity-regexp '^https://github\.com/glincker/levelrail/\.github/workflows/release\.yml@refs/(heads/main|tags/v.+)$' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

Contributors ​

Thanks to @thegdsks.

Full changelog: v0.2.0-beta.16...v0.2.0-beta.17 | Release page | Installing | Upgrading | Verifying signatures

Released under the Apache 2.0 License.