Exclusive Access · Invitation Only
Pre-release · rc

Version 1.0.0-rc.79

A pre-release build. It installs only on a node with a pre-release licence.

Metadata

version1.0.0-rc.79
published2026-09-28
channelrc
platformlinux/amd64 arm64

Release notes

Stratum v1.0.0-rc.79

Release candidate. Continues the Stratum 1.0 preview. It is recommended for evaluation and staging. Hold production rollouts for the stable v1.0.0 release.

This release focuses on correctness and security. Every firewall setting is now either enforced exactly as written or refused. BGP works with standard routers and keeps its configuration across restarts. Alert webhooks are protected and signed.

Before you upgrade

  • Connections through address translation reset once. The first start after the upgrade resets the node's connection-tracking and address-translation state. Established connections through NAT may need to reconnect. Later restarts are unaffected.
  • Check your firewall rules after upgrading. Run cenvero-str-ctl firewall list. Any rule that uses a setting Stratum does not enforce is flagged, with the setting named (see Security).
  • Alert webhooks must point at a public address. Receivers on private or internal networks no longer get deliveries. Webhook actions created before this release keep delivering unsigned and are flagged; add them again to get a signing secret. See Security.

Security

  • Firewall rules are enforced exactly as written:
- Source ports: a rule's source port is now enforced. Before, an allow rule limited to a source port allowed every source port. - Unenforced settings are refused: a chain other than prerouting, a stateless rule, and reject. Existing rules that use them are flagged in firewall list. Allow rules that were never about arriving traffic are no longer applied, and a stored reject works as a drop. - Unreadable values: a rule with an unreadable address, hardware address or protocol is refused. Before, it could match all traffic. - Strict checks: the rules API now rejects fields it does not recognise. The command line refuses a rule whose action contradicts the command, such as firewall allow with a drop action. - Port ranges: a destination port range is now enforced as a whole range. Before, only its first port was.
  • Alert webhooks:
- Public addresses only: they are delivered only to public addresses, never follow redirects, and are signed. The X-Stratum-Signature header carries an HMAC of the body, using a secret shown once when you add the action. - No proxy: webhooks never go through a proxy set in the environment.

Improvements

  • BGP:
- Configuration survives restarts and updates: neighbours, announcements, prefix lists, route maps, policies, RPKI and EVPN settings. - Standard routers: sessions with standard BGP routers now establish (tested with BIRD 2). - Correct route attributes: announced routes carry the correct AS path, and eBGP peers no longer receive local preference.
  • Alerts:
- Duration: a condition's duration is honoured before an alert fires. - Resolution: alerts resolve when the condition clears, when their target stops reporting, or when the condition is removed. The resolution is announced to every action. - One alert per episode: an alert fires once for each episode, instead of again after every cooldown. - Bounded history: it keeps 30 days of alerts, at most 10,000. - Unsupported conditions: conditions that can never fire are refused. - Condition id: creating a condition through the API returns its id.
  • Firewall default: the new firewall default command and API set the firewall's default action.
  • Backups:
- Contents: configuration backups now contain the firewall rules and the default action. Before, they were always missing. - Restore: restoring a configuration backup is refused with a clear message, because it is an export for your records. Full backups restore as before. - Errors: a failed read now fails the backup, instead of being skipped silently.
  • Storage (early access):
- Snapshot delete: a snapshot delete is reported finished only once all its work is done. - Concurrent jobs: a rare case where two jobs on one volume could interfere is fixed.
  • Self-repair: a missing network bridge is re-created. The health report now shows each bridge separately.

Documentation

  • Firewall page: it says exactly what each rule setting does, and how to use a default-deny policy safely.
  • Monitoring page: it covers how alerts fire and resolve, and how to verify a webhook signature.
  • Clustering and high-availability pages: they now say plainly that these cannot be set up yet. They arrive with the multi-server release.

Feedback on this release candidate is welcome. Report issues through your account before the stable v1.0.0 cut.

Install

This is a pre-release (rc) build. It runs only on a node with a pre-release licence — the installer reads the channel from your licence, so a node on this key only ever pulls beta/rc updates, and a stable licence cannot install it. Run it once your pre-release licence is active:

printf 'X-License-Key: %s\n' "$KEY" \ | curl -sSL -H @- https://www.stratum.cenvero.com/install?channel=rc | sudo bash

// Set KEY to your licence key first. Passed this way, the key stays out of the server's process list.

// the ?channel=rc pin keeps this node on the rc channel for every later self-update — it never crosses beta↔rc.

Files

agent

Architecture File Size
amd64 cenvero-stratum sha256 f0c8c677190ce316d05d55fec5bbd8ea216aee42aef3a0eea81bdbb3c4b33a3a 82.78 MB
arm64 cenvero-stratum sha256 121c58e6ab3e9089567effed983189d6814895389deb36dc934ab53993262801 72.38 MB

ctl

Architecture File Size
amd64 cenvero-stratum sha256 e7afabe34e3590c0c0b5755cd23f02919406a2c2db2927e4f05b25e7ab4688a6 23.83 MB
arm64 cenvero-stratum sha256 b087378e3619722f115cf9c85db3e8a2485f090fcf8fd4d47cb3ead29dc573d6 20.5 MB

plugin-packer

Architecture File Size
amd64 cenvero-stratum sha256 ef1bfbb56108058092878b738f5d3bd346bc027c5ba8d1739eeadb6a338e59c4 10.6 MB
arm64 cenvero-stratum sha256 4f9c0dcb4a2c208dc08696b0b29ebb567dde996748c22fc7d140f34ddca5fac7 9.5 MB
darwin-amd64 cenvero-stratum sha256 e4b69763baed36d38d6da6526513bc987055650c4e54c6c94e39673fd6ca78c0 10.34 MB
darwin-arm64 cenvero-stratum sha256 ac745718a225c2c1e32ee34d66850872c602b06b40b7eeeb27e0ed983ac0a429 9.23 MB
← All releases