Skip to content
v0.8.4stable

v0.8.2 changes and upgrade boundaries

Administrators can create reusable HTTP or HTTPS CONNECT proxies, store Basic Auth credentials encrypted in the Vault, test connectivity, and bind a proxy to a Provider. A Provider with a proxy never silently falls back to a direct connection.

Private, loopback, or clear-text authenticated endpoints require an explicit risk acknowledgement. A container’s 127.0.0.1 is the container itself, not the host; use a reviewed host gateway or network service instead.

The Admin Console resource lists now keep their essential identity and status visible at narrow widths while moving secondary evidence into expandable detail. This is a presentation change, not a change to authorization or resource state.

For Bedrock Mantle, Region is part of the credential-bound endpoint. Existing records are migrated during upgrade. After rollout, verify every Bedrock Credential, Provider, and Deployment before restoring traffic; do not create duplicate Regions on downstream objects.

  • Provider proxy lifecycle and connection testing are available in Admin.
  • The current model enumeration and capability-evidence boundaries remain separate: discovery says which targets exist, not what they can do.
  • Package channels have independent verification and may lag GitHub Release.
  • Existing single-writer, backup, Master Key, and rollback requirements remain.
  1. Read the changelog and back up the complete data set plus the separate Master Key or recovery material.
  2. Stop the writer. Never let two versions use the same data directory.
  3. Pin the new binary or image digest and start exactly one instance.
  4. Run health, Provider, Deployment, Route, pricing, and negative-policy checks.
  5. If acceptance fails, stop the new writer before restoring the matching backup, key material, configuration, and previous image.

See Install and deploy and Backup and restore for the complete operator procedure.

Current distribution channels
ChannelStatusVersion boundary
GitHub ReleaseAvailablev0.8.2; checksum, Sigstore, SBOM, and attestation verification required
GHCRAvailablev0.8.2 for linux/amd64 and linux/arm64; pin a digest in production
HomebrewAvailableMay lag GitHub Release; check the installation page before upgrading
APTIn progressDo not advertise or install until the signed snapshot and clean-host acceptance are complete