Signed-binary trust you manage in the node, and safer scripts
v0.2.1
•Platform
Features
Trusted keys: an Owner adds a signing key under Security, Trusted Keys. The key is shared with every node of the cluster and is included in configuration backups, replacing key files kept on each node. Removing a key stops binaries it signed at their next start.
Signed binaries: the service that starts extension services now refuses any binary that is unsigned or whose signature no trusted key verifies. The extension installer and the service starter accept the same keys.
Tools: the command-line tools are published as separate images on Docker Hub, one per tool, and are no longer part of the node image.
Bug Fixes
Permissions: scripts and rule chains can no longer create or edit permissions, roles, API keys or user role assignments, and can no longer change entity schemas. They can still read them.
Performance
Image size: the command-line tools and the VPN binary no longer ship in the node image. The VPN extension installs its binary on every node.