Versions¶
Generated from CHANGELOG.md by scripts/gen_versions.py; do not edit by hand. Semver, 0.x is pre-stable; each release is tagged v<version> and GitHub Actions attaches downloadable zips.
| Version | Date | Theme | Links |
|---|---|---|---|
0.4.0 (current) |
— | console polish, docs, and proof | release |
0.3.2 |
2026-09-28 | verified on GKE | release |
0.3.1 |
2026-09-28 | gRPC transport | release · architecture |
0.3.0 |
2026-09-28 | AWS, auth & policy, docs | release · architecture |
0.2.0 |
2026-09-28 | GCP | release · architecture |
0.1.0 |
2026-09-27 | local core | release · architecture |
0.4.0 — console polish, docs, and proof¶
- (in progress) Console: naming and sentence case, sidebar identity, per-zone action sections, two-pane logs, per-zone package toggles, 12-character password and key policy, enforced API key client types (agent vs devops), colour-free health wording, session revocation. Docs: dark-only site, aligned badges, real architecture diagram, transport and security write-up, repository topics. Verification: multi-zone and autoscaling on kind then GKE, per-zone tool isolation, independent LLM clients, a role and group security matrix, and an independent review of the claims.
0.3.2 — verified on GKE¶
- gRPC header routing verified on a live GKE Gateway over cleartext HTTP/2 (h2c); no TLS fallback needed. Live harness: 126 passed, 0 failed.
- Fixes from the live run: zone identity (GSA + Workload Identity + baseline grants) is ensured when a zone is attached, not only by an explicit service-account call; IAM bindings on new service accounts wait for propagation; all worker services (Mcp, Health, reflection) are routed through the Gateway; the node retries its initial load instead of waiting for an admin reload; the bridge pins the server certificate in insecure-TLS mode.
- API:
GET /api/v1/zones/{zone}andGET /api/v1/groups/{group}/environments/{env}.make envwarns when.envis older than the example. Terraform lock files are committed.
0.3.1 — gRPC transport¶
- Breaking for HTTP MCP clients (D19, contract §11): the worker's HTTP surface (
POST /mcp,/healthz,/readyz,/metrics,/admin/reload,RAMEN_MCP_PATH_PREFIX) is removed. Workers speak JSON-RPC 2.0 over gRPC:ramen.v1.Mcp/Callcarries one JSON-RPC message asbytes body,ramen.v1.Admin/{Reload,Metrics}replace the admin routes,grpc.health.v1.HealthreportsSERVINGonce code is loaded; one h2c portRAMEN_NODE_PORT(8080), optional node TLS viaRAMEN_TLS_CERT/RAMEN_TLS_KEY. Standard MCP clients (Claude Desktop, Cursor, the mcp SDK) connect throughramen-mcp-bridge(stdio;ramen-runtime[grpc]console script, also in the worker image):--target <host:port> --key <rmk_> --group <g> --zone <z> [--tls|--insecure] [--ca <pem>]. Migration: docs Migrate 0.3.0 → 0.3.1. - Security parity on gRPC: metadata
authorization: Bearer <rmk_key>with constant-time compare (UNAUTHENTICATED; empty key set = deny all),RAMEN_ALLOWED_CIDRS/x-forwarded-forwithRAMEN_TRUST_PROXY=1(PERMISSION_DENIED),x-ramen-admin-key+RAMEN_ADMIN_CIDRSonAdmin/*, blocked names hidden from*/listand answered-32601, 4 MiB message limit,RAMEN_MAX_INFLIGHT→RESOURCE_EXHAUSTED, unauthenticated health, access log gainsgrpc_code. - Edge routing by metadata: clients and the bridge send
ramen-group/ramen-zone; GKE Gateway HTTPRoutes match on those headers (worker ServiceappProtocol: kubernetes.io/h2c,HealthCheckPolicytypeGRPC, no path rewrite); AWS ALB target groupsbackend-protocol-version: GRPCwith header listener rules and gRPC health code 0; Cloud Armor / WAF unchanged. - Console:
ramen_console.grpcclient(grpcio) replaces every HTTP call to workers (Admin/Reload+tools/listsmoke,Admin/Metricsfor load,Health/Checkfor readiness);RAMEN_GCP_POD_PROXY/RAMEN_AWS_POD_PROXYremoved. Local stack,make demo,mcp_call.pyandmcp-client-config.example.jsonuse gRPC / the bridge; harnessramen_tests.mcp_clientspeaks gRPC and covers the bridge end to end through the mcp stdio client;scripts/cloud_smoke.shusesgrpcurl. - Protos:
proto/ramen/v1/{mcp,admin}.protoare the single source; Rust via tonic-build, Python stubs (ramen_proto) vendored in console, runtime-py and tests, regenerated withmake proto. - Carried security mediums fixed: GCP console GSA drops
resourcemanager.projectIamAdminforiam.serviceAccountAdmin+ a custom role limited tosetIamPolicyonramen-*service accounts, with bucket-/secret-level bindings; AWS console role narrowswafv2:*to theramenweb ACL / IP sets andiam:PutRolePolicyto/ramen/roles; console ClusterRole loses cluster-widesecrets/serviceaccountsin favour of a namespaced Role + RoleBinding per attached zone;sync_repopasses the GitHub token viahttp.extraheader/GIT_ASKPASSand strips credentials from.git/config; OIDC uses PKCE (S256) +nonce; node key compares are constant-time. - Logo v2 (same coral/off-white palette) in the console, docs site (
docs/img/logo.png,logo-mark.png,favicon.png), README and launch drafts. Docs: architecture v0.3.1, transport sections in how-it-works / protos / concepts, bridge + grpcurl quickstart, GCP/AWS header routing and gRPC health, security parity table, migration note;mkdocs.ymlversion_current: 0.3.1.
0.3.0 — AWS, auth & policy, docs¶
- AWS path (untested on a real account, D18): Terraform
deploy/terraform/aws(EKS, DynamoDB, S3, ECR, IRSA roles, AWS Load Balancer Controller + Fluent Bit via Helm, self-signed cert in ACM), CloudFormationdeploy/cloudformation/ramen.yaml, Helmprovider: aws(ALB IngressGroup, weighted stable/canary target groups, IRSA), consoleawscloud adapter (S3 repo sync, CloudWatch Logs Insights, ALB weights, WAFv2 IP rules, IAM role per group+zone,apply_sa_permissions) andawssecrets backend (Secrets Managerramen/<group>/<env|all>/<zone|all>/<NAME>); runtime syncss3://buckets; nodeRAMEN_MCP_PATH_PREFIXserves/mcp/<group>/<zone>behind an ALB. - Auth: OAuth/OIDC providers (
RAMEN_OAUTH_<NAME>_*, role mapping by claim), email via SMTP or thefile://dev backend (invite on user create, password reset, magic-link login), super-admin togglesGET|PUT /api/v1/config/authwith break-glassRAMEN_ADMIN_FORCE_PASSWORD, CSRF double-submit token for cookie sessions (API keys exempt). - SA policy engine: permission catalogue
GET /api/v1/policy/permissions, group-admin requestsPOST /api/v1/requests, super-admin approval →Cloud.apply_sa_permissions(gcp IAM roles with prefix conditions, aws inline policy, local recorded); denied-by-rule → 409, audited. - Tool blocking per environment:
PUT …/environments/{env}/blocked→RAMEN_BLOCKEDon deploy; the node hides blocked names from*/listand answers-32601; block/unblock toggle on the group page. - Docs: MkDocs Material site on GitHub Pages (architecture per version, how-tos for local/GCP/AWS/security/secrets/DevOps API, wiki, generated version tracker,
llms.txt+ JSON-LD), README with screenshots and a 5-command quickstart,skills/cloud-ops agent skills, launch drafts. - Tooling:
rufflint/format config shared viaruff.toml,make lint, CI lint job; Dockerfiles pinuvand carry OCI labels. - Hardening after the security audit: no constant signing secret, security headers, failure-only login rate limit, token redaction in logs, same-origin login redirect, strict names in log queries, OIDC email verification, CSV formula escaping, worker NetworkPolicy + container securityContext, pinned CI actions. Standards pass: ruff across the repo,
make lint, CI lint job.
0.2.0 — GCP¶
- Console GCP adapter: zone = namespace, canary deploy flow, workers/metrics, Cloud Logging, rebalance via backend capacity, Cloud Armor IP rules, per-group+zone service accounts with Workload Identity, refresh, group destruction.
- Secrets backend
store|gcp(Secret Manager). Runtime syncs the group bucket from GCS on load. - Deploy: Terraform (GKE Autopilot, Firestore, Artifact Registry, static IP, groups bucket, console GSA), Helm
ramen(console, GKE Gateway, RBAC, backend policy) andramen-worker(zone namespace, canary, HTTPRoute/mcp/<group>/<zone>),make push, GCP how-to. - Node: separate
RAMEN_ADMIN_CIDRS; console: IPv6 CIDRs, zone validation on rebalance, drain-aware deploys, thread-safe Google API transport. - Tests: cloud suites (canary, rebalance, IP rules, logs, service accounts, secrets), cloud smoke and cost-check scripts, manual
cloud-e2eworkflow. Verified on a throwaway GKE project: 89 passed, 0 failed.
0.1.0 — local core¶
- Python runtime sidecar (
ramen_runtime): loads group repos, validates protos, executes tools/resources/prompts, resolves{{$group.VAR}}secrets. - Rust MCP node (
ramen-node): JSON-RPC 2.0 over MCP Streamable HTTP, bearer auth, CIDR allowlist, metrics, admin reload, sidecar supervisor. - FastAPI console: auth, RBAC (super admin / group admin / viewer), groups, environments, zones, secrets (names only), deploy jobs, rebalance, logs, audit, API keys, backups, config; Firestore, DynamoDB and memory stores with Fernet encryption.
- Local stack: docker-compose (Firestore emulator + console + worker),
make demo; Helm chart; GCP Terraform skeleton (Phase 2). - Test harness: conformance (node, sidecar, console API), e2e demo flow, coverage report, version check, CI with e2e job, tag-driven releases.