Levelrail v0.2.0-beta.17
NOTE
This is a pre-release on the beta channel. Pin this exact version for anything you care about staying still.
What's changed
Features
- one-command npm bootstrap and opt-in hands-off releases (#995) by @thegdsks
- route ingress to apps on remote nodes over the WireGuard mesh (#996) by @thegdsks
Security
- security review hardening (CSRF, cert purge churn, placeholder escape, git SSRF, hardening default) (#997) by @thegdsks
Bug fixes
- make node enrolment and mesh work out of the box on the agent image (#983) by @thegdsks
- Homebrew formula exec bit, npm trusted publishing, split publish jobs (#992) by @thegdsks
- auth: token ownership, OAuth state binding with PKCE, atomic device redeem (#981) by @thegdsks
- balance multi-replica apps by default and route the local node's replicas (#994) by @thegdsks
- app delete tears containers down and retries until gone (#991) by @thegdsks
Install
Fresh install on a Linux host, pinned to this release:
sh
curl -fsSL https://raw.githubusercontent.com/glincker/levelrail/main/install.sh | sudo env LEVELRAIL_VERSION=v0.2.0-beta.17 shUpgrade an existing install in place (keeps the unit file and data):
sh
curl -fsSL https://raw.githubusercontent.com/glincker/levelrail/main/install.sh | sudo env LEVELRAIL_VERSION=v0.2.0-beta.17 sh -s upgradeDocker Compose: pin the image tag in docker-compose.yml:
yaml
services:
levelrail:
image: ghcr.io/glincker/levelrail:v0.2.0-beta.17Container images
Multi-arch (linux/amd64, linux/arm64), signed with cosign, SBOM and provenance attached. Also tagged beta at release time (moving tags).
| Image | Tag | Digest |
|---|---|---|
ghcr.io/glincker/levelrail | v0.2.0-beta.17 | sha256:9bd3e65906f7b1a56ced3237d545a2e5bd0b459499807c58bfcae60affc96fe0 |
ghcr.io/glincker/levelrail-agent | v0.2.0-beta.17 | sha256:a4e2872db24c8b27a21a3b78003bbf3fbd5c919ebd07b50583592058bf4fb8ae |
Verify
Binaries: check downloads against checksums.txt:
sh
gh release download v0.2.0-beta.17 --repo glincker/levelrail --pattern 'levelrail-linux-amd64' --pattern checksums.txt
sha256sum --ignore-missing -c checksums.txtImages: verify the keyless signature was made by this repository's release workflow:
sh
cosign verify ghcr.io/glincker/levelrail@sha256:9bd3e65906f7b1a56ced3237d545a2e5bd0b459499807c58bfcae60affc96fe0 \
--certificate-identity-regexp '^https://github\.com/glincker/levelrail/\.github/workflows/release\.yml@refs/(heads/main|tags/v.+)$' \
--certificate-oidc-issuer https://token.actions.githubusercontent.comContributors
Thanks to @thegdsks.
Full changelog: v0.2.0-beta.16...v0.2.0-beta.17 | Release page | Installing | Upgrading | Verifying signatures