NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #1872 by repository stars
Last release 9 days ago
29 Sep 2026
Ships on a steady schedule
a new release about every 9 days
Some releases are documented
notes for 32 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
1 years old
156 releases · first in 2025
One column per month.
0536e66 : Pin SDK modules to v0.20.0 for release ( @akclace )
Nothing published for this version
Nothing published for this version
ec61e1d : Add job plugin apis ( @akclace )
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
6095063 : Add app config doc ( @akclace )
https.acme_ca_url sets the CA's ACME directory URL (enables certmagic even without service_email, for private CAs like step-ca), https.acme_ca_cert points to a root CA PEM to trust for the CA endpoint, and https.acme_eab_key_id/https.acme_eab_mac_key configure External Account Binding for CAs that require it (e.g. ZeroSSL).https.enable_http_challenge: answers ACME HTTP-01 challenges on the HTTP port (before the HTTPS redirect and auth), in addition to the always-on TLS-ALPN challenge. Works with Let's Encrypt and custom ACME CAs; the HTTP listener must be reachable by the CA, on port 80 for public CAs.Nothing published for this version
3a60269 : Fix lint failures and update reverse proxy since proxy.Director is deprecated ( @akclace )
localhost), on docker/podman peer containers on a per app network.app delete now removes the app's runtime assets: its containers and sidecars, generated images, named volumes and per app network on docker/podman, and its workloads, service and volume claims on Kubernetes. Foreign sidecar images and remote registry images are not removed.--prune to sync schedule: each sync run deletes the apps and bindings the sync itself created that are no longer present in the apply file. Resources created imperatively and later adopted by the sync are never pruned. Pruning runs in the same transaction as the apply, so a blocked delete fails and rolls back the run.openrun delete <filePath> [<appPathGlob>] command, the counterpart of apply for removal: the apps and bindings declared in the file that match the glob are deleted (declared resources that do not exist are skipped and reported). All deletes run in one transaction; a blocked delete rolls the whole command back.provider:read and provider:manage checks to the RBAC permission catalog. provider:manage now implies provider:read, and the built-in operator/monitor roles include the corresponding provider permission.067d999 : Pin SDK modules to v0.19.1 for release ( @akclace )
9606f9d : Add health check api for service bindings ( @akclace )
static_root_cache_control app config property: sets the Cache-Control header value for files served from an app's static_root directory (favicons and other stable-named root files). Default is empty, no header. The built-in list_apps app sets public, max-age=3600.Nothing published for this version
2b47842 : Add usage checks for service and binding deletes ( @akclace )
db49bd8 : Added export and diff apis ( @akclace )
e76ce1c : Add support for setting app config in app definition ( @akclace )
openrun_admin.secret_reveal: returns the clear text value of a secret reference (typically an app param holding {{secret_from ...}}), so an HTML app can pass an API key into a served page explicitly while the value lives only in the secret store, never in the app source or git history.static_from_disk app config property instead of being hardcoded to the static_disk spec name.ace.app settings dict now supports an app_config section which sets app config properties from app.star, e.g. settings={"app_config": {"fs": {"retain_versions": 3}}}.redis/valkey service binding is now compiled into the server as a built-in binding type; it no longer needs openrun provider install redis. Each base binding gets a dedicated ACL user restricted to a unique key prefix (and matching pub/sub channel prefix); derived bindings share the base prefix with grant-controlled patterns. Requires Redis 7+ or Valkey, standalone mode.openrun server stop --wait: waits for the server process to fully exit instead of returning as soon as shutdown starts (the final litestream sync runs as the process exits, so scripts that move or restore data directories after a stop need this). Over the unix domain socket the server's pid (now returned by the stop API) is polled; over http(s) the listener port is polled as a best effort signal. Also added openrun server status (prints ok when the server connection works) and openrun server version (reports the server's build version and commit).openrun CLI now discovers a machine scoped Windows service install: when OPENRUN_HOME is not set and no config is found relative to the executable (a winget binary is a links shim, so executable-relative discovery finds nothing), it checks %ProgramData%\openrun\openrun.toml and connects to the server's unix domain socket under that home, like /var/lib/openrun on Linux. Previously the CLI fell back to $HOME\openrun and failed to find the service's socket unless OPENRUN_HOME was set machine-wide.Nothing published for this version
Release v0.18.17 Compare # Choose a tag to compare
Release v0.18.17
Compare
Nothing published for this version
Nothing published for this version
Added the sqlite service binding type: an app bound to a sqlite service gets a persistent volume (Docker/Podman named volume or Kubernetes PVC, ReadWr
sqlite service binding type: an app bound to a sqlite service gets a persistent volume (Docker/Podman named volume or Kubernetes PVC, ReadWriteOnce with single replica and Recreate strategy) holding its SQLite database files, surfaced through the SQLITE_URL/SQLITE_DB_PATH/SQLITE_DIR env variables. The mount directory defaults to /data and is configurable per binding with the path binding config key. An app can have one sqlite binding and a binding can be attached to one app (single-writer database); derived bindings and grants are not supported.[litestream.<name>] server config entries. metadata.litestream_config replicates the server's own metadata and audit databases (embedded Litestream, restore-on-startup rebuilds a lost node from the replica); a sqlite service's litestream_config config replicates its apps' databases via a per-app replication container (Docker/Podman) or restore init containers plus a native sidecar in the app pod (Kubernetes 1.29+). Every *.db file in the binding directory is replicated, missing databases are restored from the replica before the app starts, and prod/staged environments replicate to separate locations (a linked staging service can use its own litestream config).--bind source reference, e.g. --bind "sqlite;path=/mydata"; the comma separated params become the auto binding's config, for any service type. Slice CLI flag values are no longer split on commas (pass multiple values by repeating the flag).openrun server restart (or SIGHUP, or POST /_openrun/restart) re-execs the server binary and hands the HTTP/HTTPS/unix-socket listeners to the new process.Release v0.18.14 Compare # Choose a tag to compare
Release v0.18.14
Compare
Nothing published for this version
Release v0.18.12 Compare # Choose a tag to compare
Release v0.18.12
Compare
Release v0.18.11 Compare # Choose a tag to compare
Release v0.18.11
Compare
Nothing published for this version
Nothing published for this version
Nothing published for this version
Added out-of-process binding providers: new binding types (mongodb, redis/valkey, sqlserver, oracle) are built as standalone executables in the openru
openrun provider install/uninstall/list commands (/_openrun/provider APIs, gated by the new provider:read / provider:manage RBAC permissions); the install is recorded in the metadata database with pinned sha256 checksums, so it survives restarts and propagates to all server replicas — each replica materializes the verified binaries into the bindings.cache_dir local cache at startup, before serving traffic, making installs work on Kubernetes multi-replica deployments.FROM scratch image (ghcr.io/openrundev/openrun-binding-<name>), and the Helm chart's bindings.images values render one init container per provider which copies the binary (via the provider binary's new export subcommand) into a shared volume. The server registers pre-placed provider executables from the new bindings.preinstalled_dir config at startup, with no downloads and no database registration — integrity comes from the image digests, and the sha256 computed at discovery is verified on every provider launch. The new bindings.disable_install config (chart value bindings.disableInstall) rejects the imperative openrun provider install/uninstall API/CLI, for deployments where providers are managed only declaratively.builtin app auth type: username/password authentication (HTTP Basic) against [builtin_auth.<username>] config entries, each with a bcrypt password hash and a groups list used for RBAC group: matching (user id is builtin:<username> in grants). Users can be defined statically in openrun.toml or managed dynamically with the new openrun user add/update/delete/list commands (/_openrun/user APIs), which take effect immediately without a server restart and shadow static entries of the same name. Useful for small deployments and for testing RBAC policies with multiple users and groups without setting up OAuth/SAML.--as <provider>:<username> (e.g. openrun --as builtin:user1 app list): the management API call runs as the given user with RBAC enforcement (permission checks, list filtering, the owner rule, audit attribution) instead of as the trusted administrator. Supported over the unix domain socket only and requires RBAC to be enabled; for builtin: users the entry must exist and its groups feed group: grant matching, other provider ids (e.g. github:user) are taken literally with no groups so grants for SSO identities can be tested without creating them. Useful for testing RBAC policies from the CLI without going through an app.stop_server management API now enforces the server:stop RBAC permission (reachable only through --as; the trusted admin CLI is unaffected).targets accept service:<glob> entries matched against service ids (<type>/<name>, e.g. service:postgres/*) and binding:<glob> entries matched against binding paths (e.g. binding:/apps/team1/**); all matches every app, service and binding. New permissions: service:bind (provision binding accounts on a service, required to create base/auto bindings from it), binding:use (attach a binding to an app or derive a new binding from it), binding:reveal (read back binding account credentials with binding show-account; like secret:reveal it always needs an explicit grant — it is never implied by binding:manage and binding owners do not hold it by default, opt owners in via owner_permissions.binding), and the service:manage / binding:manage composites. Attaching bindings at app create/update/apply time now enforces binding:use / service:bind for newly added bindings, sync background runs enforce them against the frozen creator snapshot, and service/binding list operations (including export) return only the entries the user can read. The creator of a service or binding holds the owner permissions on it (default service:manage / binding:manage, configurable via owner_permissions).service:* and binding:* permissions are no longer global. A grant that should confer them must include service:/binding: target entries (or use the all target); grants whose targets only name app paths no longer confer any service or binding permissions. Sync entries created before this change froze grants without typed targets — recreate RBAC-snapshotted syncs whose apply files manage bindings.--bind-perm flag, openrun app update bind-perm, the bind_perm apply file argument, the permissions.binding_source_perms server config and the runtime container-start source check are gone, and approval no longer covers binding sources. Binding access authority is now checked when the binding is attached (RBAC binding:use/service:bind); with RBAC disabled, management operations are admin-only as usual.app_versions row was attributed to admin regardless of the caller, so version listings misattributed changes made by RBAC/SSO/builtin users. Trusted CLI/UDS calls (no user identity) keep the admin attribution.regex: user patterns (in grant.users and group members) now must match the entire user ID instead of any substring. Patterns already anchored with ^...$ behave the same as before.Nothing published for this version
Added an embedded secrets store: the db secret provider encrypts values with AES-256-GCM and saves them in the metadata database. The master key is au
db secret provider encrypts values with AES-256-GCM and saves them in the metadata database. The master key is auto generated into $OPENRUN_HOME/config/secret.key or can be a {{secret_from ...}} reference resolved through another provider (for Kubernetes, mount it from a native Secret). Secrets are managed with the openrun secret create/list/show/delete/rekey commands, the /_openrun/secret management APIs and the openrun_admin plugin (create_secret, get_secret, list_secrets, delete_secret, rekey_secrets); create generates a unique name from a prefix and prints the {{secret_from "db" "<name>"}} reference to use. New secret:create, secret:read, secret:delete and secret:reveal RBAC permissions gate the APIs.{{secret ...}} reference.git_auth setting private_key for providing the SSH private key contents inline (supports {{secret ...}} references), as an alternative to key_file_path.container.separate_stage_prod_images for specs that need distinct staging and production container images.full template (and template names passed to ace.response) can now name a {{define}} block from the base templates instead of a template file, so fragment-only endpoints need no dedicated template file.static_disk app spec for serving static files directly from a local source directory without storing the static file contents in the metadata database.container:read permission covers listing containers, getting container details, logs and Kubernetes stats/status; new container:manage permission covers starting and stopping managed containers (and implies container:read). These operations previously had no RBAC check.audit:read RBAC permission, which grants read access to the audit log across all apps. It gates the list_audit_events and list_operations plugin APIs, which previously had no RBAC check.delete_apps plugin API now rejects an empty path glob instead of matching every app: a caller omitting the path argument could previously delete all apps (the HTTP route already validated this, plugin calls did not).security.headers_level app config defaults to 2, which adds X-Content-Type-Options: nosniff, X-Frame-Options: SAMEORIGIN and Referrer-Policy: strict-origin-when-cross-origin when the app did not set its own value. Apps embedded in cross-origin iframes need security.headers_level = 0 (settable per app with openrun app update conf) or an app-provided X-Frame-Options/CSP header, which takes precedence. Levels 5 and 10 opt into stricter sets (HSTS, CSP).stage_enable_write_access / preview_enable_write_access) now treats every method other than GET, HEAD and OPTIONS as a write, so PATCH and custom verbs fail closed; denied requests now return 403 instead of 500.stage.example.com:/app, instead of suffixing _cl_stage to the production path. Use system.stage_at, system.default_stage_domain, openrun app create --stage-at, or declarative stage_at to choose path-based staging or a specific staging domain for new apps.settings={"container": {"separate_stage_prod_images": True}}.container.deploy_health_attempts budget, and the best-effort EndpointSlice convergence check now skips immediately when the Kubernetes API or RBAC policy does not allow listing EndpointSlices.clc-app_prd_<id>-e96c79f753cfafff instead of a 143-character name. Containers running under the old names are stopped by the stale-container sweeper after upgrade and the app is recreated under the new name on its next request; images built under old tags are not reused.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Added the app internal /_openrun_app/verify_file/{file_name} API to verify that an app-relative source file exists and return its size.
/_openrun_app/verify_file/{file_name} API to verify that an app-relative source file exists and return its size.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fixed service stop error when running as windows service
Fixed an open redirect issue reported by @Fushuling https://github.com/openrundev/openrun/security/advisories/GHSA-h5g6-xmh4-hc37
Added Windows Service Control Manager support for openrun server start, allowing OpenRun to run as a native Windows service registered with sc.exe.
openrun server start, allowing OpenRun to run as a native Windows service registered with sc.exe.Nothing published for this version
Proxied responses now rewrite the Location header so upstream redirects don't leak the internal backend authority. Absolute Locations pointing at the
Location header so upstream redirects don't leak the internal backend authority. Absolute Locations pointing at the proxy target are converted to path-only URLs, and path-absolute Locations get any stripped prefix (strip_app / strip_path) restored so the client's next request lands on the same public route. Cross-host Locations (OAuth/SSO and similar) pass through unchanged.Nothing published for this version
Added forward auth support for apps using auth modifiers such as system+forward_policy, with named [forward. ] configs, trusted forwarded/OpenRun iden
system+forward_policy, with named [forward.<name>] configs, trusted forwarded/OpenRun identity headers and configurable copied response headers.Nothing published for this version
Fix #95: Pull image and update apps which use image spec when app reload is done.
Added background cleanup for stale Docker/Podman containers started by OpenRun. The cleanup stops running OpenRun-labeled containers that are no longer referenced by an active app, and its interval is configurable with system.stale_container_cleanup_interval_mins.
Fix #94: Added X-Openrun-User-Id and X-Openrun-User-Email headers for proxied apps, and exposed the same OIDC subject/email values on the Starlark request as UserSubject and UserEmail.
Nothing published for this version
Nothing published for this version
Action request bodies are now capped by default at 33554432 bytes. The limit can be configured globally with app_config.action.max_request_body_bytes
33554432 bytes. The limit can be configured globally with app_config.action.max_request_body_bytes or overridden per app with openrun app update conf --promote 'action.max_request_body_bytes=<bytes>' /myapp.http.in requests now inherit the current request context, support an optional timeout argument with a default of 300 seconds, and automatically close unread response bodies through deferred plugin cleanup when body() or json() are not called.openrun app create --cvol and openrun app update cvol now reject container volume values that start with --, making missing volume arguments fail clearly instead of consuming the next option as the volume name.Nothing published for this version
Added security.trusted_proxies server config to control which reverse proxies or load balancers are allowed to supply forwarded client IP headers.
security.trusted_proxies server config to control which reverse proxies or load balancers are allowed to supply forwarded client IP headers.system.fallback_unknown_domains server config to optionally preserve legacy routing of unknown hostnames to the default domain.system.builder_auth_token server config for delegated container builds, using a shared bearer token between the main OpenRun install and builder node(s).security.allowed_mounts server config to allow administrators to approve host directories that apps may use as container bind-mount sources.req.RemoteIP now ignores X-Forwarded-For and X-Real-IP unless the direct peer is listed in security.trusted_proxies.X-Forwarded-* / X-Real-IP set before sending the request upstream.Host values no longer route to the default domain unless system.fallback_unknown_domains is explicitly enabled./_openrun/delegate_build. Builder nodes should run with builder.mode = "delegate_server" and no longer require security.admin_over_tcp = true for delegated-build ingress. Existing delegated-build setups must set the same system.builder_auth_token value on the main install and every builder node before upgrading.app_config.cors.allow_origin is now empty and app_config.cors.allow_credentials is now "false". Apps that need browser cross-origin access must opt in with an app config override such as cors.allow_origin="https://frontend.example.com" or cors.allow_origin="origin".container.config(...) permission no longer allows access to all secrets. Containerized apps that pass secrets through params, build args or generated secret volumes now need an explicitly approved container.config permission with the required secrets=[...] allowlist, unless the server config is intentionally changed to allow those secrets globally.security.allowed_container_args. Built-in cpus and memory options continue to be parsed by OpenRun and do not require this raw flag allowlist.security.allowed_mounts. Relative bind sources must stay inside the app source tree.Added UserId, CustomPerms, and AppRBACEnabled to the request object available in Starlark handlers and HTML templates.
UserId, CustomPerms, and AppRBACEnabled to the request object available in Starlark handlers and HTML templates.Nothing published for this version
Added system.list_apps_title and system.show_hosted_with server config options to customize the built-in app listing page title and whether it shows t
Added system.list_apps_title and system.show_hosted_with server config options to customize the built-in app listing page title and whether it shows the Hosted with OpenRun text.
Add the security.auth_required server config option. When enabled, apps configured with auth="none" are denied at request time with 401 Authentication required, providing a server-wide guardrail against unauthenticated app access.
Your coding agent can read these notes before it upgrades. Set up the MCP server →