Exclusive Access · Invitation Only
Pre-release · rc

Version 1.0.0-rc.81

A pre-release build. It installs only on a node with a pre-release licence.

Metadata

version1.0.0-rc.81
published2026-10-04
channelrc
platformlinux/amd64 arm64

Release notes

Stratum v1.0.0-rc.81

Release candidate. It continues the Stratum 1.0 preview and is recommended for evaluation and staging. Hold production rollouts for the stable v1.0.0 release.

This release brings clusters: several servers managed as one, from any of them. It also fixes how licences renew, makes installed plugins survive a restart, and makes saving keys and plugin changes fail safely.

Clusters

  • Form a cluster from the web console (Datacenter › Cluster) or with cenvero-str-ctl cluster create, then add servers with single-use join codes. A cluster holds up to 32 servers.
  • One view of everything. From any server's console you see every server and every machine, network, volume, tenant, task and audit record on all of them. Each server shows whether it is online, out of date or unreachable.
  • Act anywhere. Start, stop, restart or resize a machine on any server from any other, and open its display or serial console.
  • Shared tenants. A tenant change made on any server reaches every server within seconds. Suspending a tenant stops its machines wherever they run.
  • When a server stops, the others mark it within seconds, refuse requests to it with a plain answer, and keep working. When it returns, it catches up by itself.
  • Security.
- Servers prove who they are to each other with keys recorded for each server. - A removed server is cut off at once, including its open connections. - Customer keys and the tenant portal stay on their own server until a later release.
  • Before you join, see what happens. The join wizard names the cluster and lists the tenants that will be shared, or any conflicts.
  • Plans. Clustering is part of every Suite plan, Suite Lab included.

Clusters: reliability and security

  • Coming back. A server that restarts catches up with its cluster by itself, even when servers joined, or the leader changed, while it was away.
  • Leaving. A server can leave from either side, and leaving, removing a server and revoking a join code always work, whatever the licence says. A server whose plan no longer includes clustering can still read its status and list its join codes.
  • Allowed addresses. Each server applies its own allowed addresses to you, even when you reach it through another server of the cluster, consoles included.
  • Blocks. Automatic blocks shared across a cluster (intrusion detection and connection limits) end at the same time on every server and never apply to a cluster member's address, so forged traffic cannot cut the servers of a cluster off from each other. A manual block of a member's address is refused with an explanation.
  • Joins. Joining a busy server works, and clusters set up by hand keep working when a server joins.

Data protection

  • Local files. The server's local database and data folder can no longer be read or listed by other local accounts or by plugins. Existing servers are corrected at their next start.

Licences

  • Renewals take effect at once. A renewed or upgraded licence now takes effect immediately, with no restart. Servers whose changes were frozen after a renewal recover when they upgrade.
  • Licence commands apply immediately. cenvero-str-ctl license activate, renew and load now load the new licence into the running service at once.
  • Hardware binding. A licence must be bound to this machine's hardware identity.
  • No downgrades. Downgrades within a product are refused for the 2026 plans too.

Plugins

  • Plugins survive a restart. Installed plugins now come back after the service restarts.
- Before one starts, it is checked again: its signature, its certificate's scope, revocation, and the supported version range. - It runs with only the capabilities it was granted.
  • Sandboxed plugins start on Linux, inside their sandbox.
  • Plugins installed by an earlier version are listed as disabled after the upgrade. Enable each one to start it.
  • Each plugin runs alone. Every plugin now runs under its own account, sees only its own processes and runs with no system privileges, so plugins can no longer read one another's files or reach one another's processes. Plugins also no longer see the server's own configuration and data folders. Plugins installed earlier move to their own account the next time they start.
  • No plugin runs unisolated. If the server cannot give a plugin its own account and its own view of the system, the plugin is not started and says why, instead of running with less separation than intended.
  • Revocations keep working. Revocations of plugin developer keys reach servers again after the plugin signing key is renewed.
  • No false success. Disabling, enabling, installing or removing a plugin reports an error when the change could not be saved.

Keys and tenants

  • No false success. Revoking or creating an API key, or deleting a tenant, now reports an error when the server cannot save the change.
  • Revocation is immediate. A revoked key stops working at once, and repeating the call saves the revocation.
  • Deleted tenants stay deleted. A deleted tenant's keys never work again, including on a server that restarts in a cluster.

Fixes

  • Machine crashes. A machine that crashes just after it starts is now restarted, not shown as running.
  • Block lists. Intrusion-detection blocks are shared with the cluster in the background and never slow the server down.

New in the API and command line

  • cenvero-str-ctl cluster create | join-code create | join | remove | leave and related commands.
  • /api/v1/nodes/{node}/… acts on another server of the cluster.
  • /api/v1/cluster/resources, /cluster/tasks, /cluster/audit and /cluster/events give cluster-wide views.
  • POST /api/v1/cluster/join-preview previews a join without using the code.

Upgrade notes

  • Plugins: plugins installed before this version are listed as disabled after the upgrade; enable each one to start it again.
  • Plugin authors: a plugin no longer sees the server's configuration or data folders, and runs under its own account. A plugin that read those folders needs to use the plugin interface instead.
  • If you restrict the agent's service: plugins need a few privileges from it to be isolated. If those are withheld, plugins now refuse to start rather than run with less separation. The installed service file says which, in a comment.
  • Reading the server's files yourself: the data folder and the server's database are now private to the service account. A script of your own that read them directly needs to run as that account, or use the API or the command line.
  • Mixed versions: servers must run this version to join a cluster. A server on an older version is shown as needing an update.

Feedback on this release candidate is welcome. Report issues through your account before the stable v1.0.0 cut.

Install

This is a pre-release (rc) build. It runs only on a node with a pre-release licence — the installer reads the channel from your licence, so a node on this key only ever pulls beta/rc updates, and a stable licence cannot install it. Run it once your pre-release licence is active:

printf 'X-License-Key: %s\n' "$KEY" \ | curl -sSL -H @- https://www.stratum.cenvero.com/install?channel=rc | sudo bash

// Set KEY to your licence key first. Passed this way, the key stays out of the server's process list.

// the ?channel=rc pin keeps this node on the rc channel for every later self-update — it never crosses beta↔rc.

Files

agent

Architecture File Size
amd64 cenvero-stratum sha256 b4d5ee97e659d27261c5c33baf1f604251d9e3a4f6e453d4fb28f8ca24e03811 91.96 MB
arm64 cenvero-stratum sha256 3bf2a3eeda69d354fefa3198889598e491e25510781dc16aa56714cdcfdeab56 81.69 MB

ctl

Architecture File Size
amd64 cenvero-stratum sha256 2f007c17dd29338a79a42375a95d06cd679b52065190560b0381df8837a9c129 24.86 MB
arm64 cenvero-stratum sha256 ada99471b9294fe6704b9fd2648e1a525697e30990e99c39b3288e8fa015fc8c 21.5 MB

plugin-packer

Architecture File Size
amd64 cenvero-stratum sha256 5c646ebf14559bf5bf021f64a18c721a65973401da0783bc7b0c94c375d4a899 10.45 MB
arm64 cenvero-stratum sha256 dcb6ca316644ee9a335567f1280173564a3afaf7099f627ed12207094cfbcea8 9.56 MB
darwin-amd64 cenvero-stratum sha256 70e4419b00fd9de41bb02ee9a857a9d7939e1c9e369778d16d28fc48807844cc 10.34 MB
darwin-arm64 cenvero-stratum sha256 a70ca764a2a43cf6104ce407584c0cd97e1865345e4fa5c608c21ecc2b6f3c60 9.45 MB
← All releases