Exclusive Access · Invitation Only
Pre-release · rc

Version 1.0.0-rc.77

A pre-release build. It installs only on a node with a pre-release licence.

Metadata

version1.0.0-rc.77
published2026-09-28
channelrc
platformlinux/amd64 arm64

Release notes

Stratum v1.0.0-rc.77

Release candidate. Continues the Stratum 1.0 preview. It is recommended for evaluation and staging. Hold production rollouts for the stable v1.0.0 release.

This is the largest update of the 1.0 preview. Stratum is growing into a platform. Alongside Fabric networking, this build carries early-access previews of Stratum Compute (virtual machines) and Stratum Storage (volumes and backups). The previews are active only on nodes whose licence includes them. Apart from the improvements below, a Fabric node behaves as before.

Highlights

  • Stronger isolation between tenants on the same node. Traffic between two tenants' workloads is now blocked at every workload port, including traffic that never leaves the node's own switch. A tenant's workloads still reach each other, the node and the internet.
  • Public addresses for workloads. Register the extra IPv4 addresses your provider routes to the server, then give single addresses to workloads. Anti-spoofing, tenant isolation and bandwidth plans apply to them. An address that no workload holds is answered by the node itself, instead of bouncing back to your provider.
  • Internet access for a network with one flag. network create --host-gateway places the network's gateway on the node, with optional outbound NAT (--snat) and DHCP (--dhcp). The same option can be switched on for an existing network.
  • Safer defaults.
- A workload may send only from its own addresses. - Private addresses that no NAT rule covers no longer leave the uplink untranslated. An operator setting keeps the previous behaviour, for providers who route private ranges.
  • Suspension holds for tenants of any size. Suspending a tenant now covers every address it uses, however many there are.
  • Runs alongside Docker on the same server.
  • New installer profiles. fabric (the default), compute and suite. Compute is set up only when the licence includes it, and the installer never changes virtualization settings that another management panel on the same server relies on.

Early access: Stratum Compute

Requires a licence that includes Compute.
  • Virtual machines from cloud images. Images are checksum-verified before use. Each machine is set up on first boot (hostname, SSH keys, static addressing) and connected to Fabric networking before it starts.
  • Consoles. The display and serial consoles of a machine are available through the API and from the command line.
  • Machine settings. Change a machine's size, choose UEFI, Secure Boot and TPM, and add or remove network cards on a running machine.
  • Operations. Password reset through the guest agent, per-machine metrics and a machine-down alert.
  • Suspension. Suspending a tenant stops its machines. Resuming starts again the ones that were running.
  • Restarts. Machines keep running while Stratum itself restarts or updates.

Early access: Stratum Storage

Requires a licence that includes Storage.
  • Volumes. Data volumes can be attached to running machines and grown while attached.
  • Snapshots. Machines keep running while a snapshot is taken.
  • Backups. Full and incremental backups, verified before they are listed as complete.
  • Restore. Restore to a new volume, or in place.

Security

  • Tenant keys. Tenant-scoped API keys can no longer change their own quotas, billing state or tenant record. A tenant key reads its own tenant, quota and billing state, and manages its own tenant's keys only.
  • Consoles and imports. Console sessions and local image imports are hardened against misuse by other local users.

Improvements

  • Reliability fixes. Tenant isolation, address handling, handing a public address over from one tenant to another, and suspension.
  • The installer.
- It waits for another package manager to finish instead of failing. - It explains a refusal clearly even when it is piped into a shell. - Its package steps can no longer hang.
  • The website and customer area have been redesigned.

Documentation

  • New sections: virtual machines (early access), public addresses, the network host gateway, and what a tenant key can and cannot do.

Feedback on this release candidate is welcome. Report issues through your account before the stable v1.0.0 cut.

Install

This is a pre-release (rc) build. It runs only on a node with a pre-release licence — the installer reads the channel from your licence, so a node on this key only ever pulls beta/rc updates, and a stable licence cannot install it. Run it once your pre-release licence is active:

printf 'X-License-Key: %s\n' "$KEY" \ | curl -sSL -H @- https://www.stratum.cenvero.com/install?channel=rc | sudo bash

// Set KEY to your licence key first. Passed this way, the key stays out of the server's process list.

// the ?channel=rc pin keeps this node on the rc channel for every later self-update — it never crosses beta↔rc.

Files

agent

Architecture File Size
amd64 cenvero-stratum sha256 592a22da031fedac955248ae857b652e74fa2766124c21ff1a90c4e471408e4b 80.25 MB
arm64 cenvero-stratum sha256 6e4da8f973a7bae821e401bc1b09c1730cb5e780ec64b0b6f136e0f31e754de9 70.44 MB

ctl

Architecture File Size
amd64 cenvero-stratum sha256 5b611570fa4cb37a7023f564852d00095fb87638c386aa52ebdc3eb5e6003b7d 23.74 MB
arm64 cenvero-stratum sha256 0cb7032db273377b06af5f805fa8c53b022642469c85bbecee9cbdcd1f1bd786 20.63 MB

plugin-packer

Architecture File Size
amd64 cenvero-stratum sha256 f73a7fee96cd9762d9b1b12cc28cc1ee31644a2b428719e1a32ce50863094b47 10.82 MB
arm64 cenvero-stratum sha256 7fb7bd770a7aadde0b41c3a948f67b896877933286e79cac59527512939984fc 9.38 MB
darwin-amd64 cenvero-stratum sha256 fd4367a6f5fde647f11a91823ae9211d83c2029e71d73ba62cd6b375e191823a 10.14 MB
darwin-arm64 cenvero-stratum sha256 3bc8fb4904a317ac8c1d9ccf3e345e6bfee193050422fb54ddc36768595adb76 9.24 MB
← All releases