Clavenar Lite status

Current release, proof commands, and deploy readiness.

The page operators check before pointing an agent at the single-binary OSS proxy. It separates the latest tagged release from what is already documented on main, then gives the install, verify, smoke, and rollout checks in one place.

Docs verified for site v1.250.5 Release facts checked  GitHub releases CHANGELOG.md
Latest tagged release

clavenar-lite v1.0.0

Released . This cut establishes the stable release baseline for the embedded policy and checksum-verified native installation surfaces.

Image
ghcr.io/clavenar/clavenar-lite:1.0.0
Binary
clavenar-lite-1.0.0-{x86_64,aarch64}-linux-musl.tar.gz
License
Apache-2.0
Smoke
HTTP + native lifecycle gates
1 · Release pulse

Install the exact protected tag.

Pinned deploys make evaluation handoffs reproducible. The protected publisher does not publish a mutable :latest tag.

Native service

clavenar-lite v1.0.0

The protected installer selects a static x86_64 or aarch64 binary, verifies its checksum, and installs a loopback-only hardened systemd service. Configuration and ledger state survive an in-place upgrade.

curl -fsSL https://github.com/clavenar/clavenar-lite/releases/download/v1.0.0/install.sh | sudo sh
curl http://127.0.0.1:8088/health

# Safe upgrade: rerun the installer; config and ledger remain
curl -fsSL https://github.com/clavenar/clavenar-lite/releases/download/v1.0.0/install.sh | sudo sh

Container

Pull or run the published multi-arch image.

# Pull the pinned release image
docker pull ghcr.io/clavenar/clavenar-lite:1.0.0

# Start in observe mode for first traffic
docker run --rm -p 8088:8088 \
  -e CLAVENAR_LITE_MODE=observe \
  -e CLAVENAR_LITE_UPSTREAM_URL=https://mcp.your-company.com/rpc \
  ghcr.io/clavenar/clavenar-lite:1.0.0

Static binary

Fetch the release asset when Docker is not available.

# Download and run the linux x86_64 musl asset
# Protected checksum: clavenar-lite-1.0.0-x86_64-linux-musl.tar.gz.sha256
# ARM64 checksum: clavenar-lite-1.0.0-aarch64-linux-musl.tar.gz.sha256
# Bootstrap checksums: install.sh.sha256 and uninstall.sh.sha256
VERSION=1.0.0
curl -fsSLO "https://github.com/clavenar/clavenar-lite/releases/download/v${VERSION}/clavenar-lite-${VERSION}-x86_64-linux-musl.tar.gz"
curl -fsSLO "https://github.com/clavenar/clavenar-lite/releases/download/v${VERSION}/clavenar-lite-${VERSION}-x86_64-linux-musl.tar.gz.sha256"
sha256sum -c "clavenar-lite-${VERSION}-x86_64-linux-musl.tar.gz.sha256"
tar xzf "clavenar-lite-${VERSION}-x86_64-linux-musl.tar.gz"
./clavenar-lite --help
2 · Verify this release

Check the binary, image, and day-1 surface before traffic.

These checks are deliberately copyable. They prove the asset checksum, the image manifest, the runtime version, and the operator smoke path.

Binary checksum

VERSION=1.0.0
curl -fsSLO "https://github.com/clavenar/clavenar-lite/releases/download/v${VERSION}/clavenar-lite-${VERSION}-x86_64-linux-musl.tar.gz"
curl -fsSLO "https://github.com/clavenar/clavenar-lite/releases/download/v${VERSION}/clavenar-lite-${VERSION}-x86_64-linux-musl.tar.gz.sha256"
sha256sum -c "clavenar-lite-${VERSION}-x86_64-linux-musl.tar.gz.sha256"
tar xzf "clavenar-lite-${VERSION}-x86_64-linux-musl.tar.gz"
./clavenar-lite --help

Image manifest

VERSION=1.0.0
docker buildx imagetools inspect ghcr.io/clavenar/clavenar-lite:${VERSION}
docker manifest inspect ghcr.io/clavenar/clavenar-lite:${VERSION}

Operator smoke

git clone https://github.com/clavenar/clavenar-lite.git
cd clavenar-lite
git checkout v1.0.0
scripts/smoke-e2e.sh
3 · v1.0.0 · what shipped

A stable self-sufficient native service without Docker.

The stable release baseline retains the embedded policy, checksum-verified static binaries, installation, upgrade, and data-preserving uninstall paths.

Area What changed Operator impact Upgrade risk
Native service Embedded baseline policy, checksum-verified native systemd lifecycle, loopback default, and static x86_64 plus aarch64 binaries. Use the protected installer for a Docker-free host deployment. Low. Upgrade preserves configuration and ledger state; default uninstall preserves both too.
Blocking work Regorus and SQLite operations run off the async executor behind bounded semaphores. Policy and ledger pressure queues instead of starving request scheduling. Low. Queue saturation is visible through dedicated metrics.
Notifications Webhook and Slack deliveries have bounded concurrency and request deadlines. Slow receivers cannot create unbounded background work. Low. Delivery remains advisory and failures remain observable.
Distribution Exact external-install commands bind the new source tag, archive, checksum, and image. Use only the versioned assets or protected image digest. Low. Mutable tags remain unavailable.
4 · Release lineage through v1.0.0

The cumulative public capability path.

The current tag includes the earlier operational slices and the hosted-profile boundary.

Changelog section Capability What to watch before upgrading
1.0.0 Stable release baseline for the existing protected Lite runtime and distribution surfaces. No wire migration from 0.13.0; update exact tags, assets, and release evidence together.
0.13.0 Embedded policy plus checksum-verified x86_64/aarch64 native service installation, upgrade, and uninstall. Keep the loopback bind unless an authenticated TLS boundary is placed in front.
0.12.2 Bounded Regorus/SQLite queues, queue-pressure metrics, and bounded notification delivery. Watch queue saturation and notification failure metrics under sustained traffic.
0.5.0 Multi-agent registry, online backup, atomic restore, async-HIL callback allowlist. Token uniqueness, DNS-validated and address-pinned callback target boundaries, backup destination overwrite behavior.
0.6.0 Outbound verdict webhook for SIEM, Datadog HTTP ingest, and generic webhook receivers. Receiver timeout behavior, event-name stability, and observability volume in observe mode.
0.12.1 Exact external-install documentation bound to an immutable source tag, static asset set, and multi-architecture image tag. Use the 0.12.1 archive, checksum, or image tag below; the runtime behavior is unchanged from 0.12.0.
0.12.0 Explicit fail-closed hosted profile, durable Fly volume, bounded per-agent rates and upstream I/O, and a compatible MCP JSON-RPC adapter. Hosted startup now refuses anonymous or overlapping auth, observe mode, ephemeral SQLite, scale-to-zero templates, placeholder/non-HTTPS upstreams, and the legacy raw-JSON adapter.
5 · Deployment readiness

The checklist before a Lite proxy fronts a real agent.

The automated smoke proves the HTTP surface. This checklist covers the operational choices that make the result repeatable after the first boot.

Pin the image or binary

Use exact 1.0.0 release assets or the protected image digest. Do not substitute a mutable tag.

Select the hosted profile

Set CLAVENAR_LITE_DEPLOYMENT_PROFILE=hosted. Keep enforce mode and the mcp-jsonrpc-v1 adapter selected.

Separate both auth planes

Configure distinct agent and operator credentials of at least 32 bytes. Anonymous access, ambiguous registries, and overlapping tokens are refused.

Bound traffic and upstream I/O

Set per-agent QPS and burst limits. The compatible adapter caps requests and responses at 1 MiB, enforces a 30-second maximum, matches JSON-RPC response IDs, and never retries effects.

Persist the ledger

Mount /data, use an absolute file-backed SQLite path beneath it, keep at least one machine running, and verify pending decisions and the hash chain after restart.

Archive release evidence

Save release notes, the checksum file, the image digest, and SBOM/license assets with the deployment evidence.

6 · Known operational notes

Small details that change how a rollout behaves.

These are not blockers, but they are the items that commonly explain day-1 surprises.

Topic Current behavior Operator action
Naming Current assets, binary, and image consistently use clavenar-lite. Use the exact v1.0.0 names and checksums shown above.
Docker vs binary The protected v1.0.0 image and static binary set both support x86_64 and aarch64. Use the native installer for a systemd host or the protected image for a container runtime.
Native uninstall The default uninstaller removes the service and executable but preserves configuration and ledger state. Use --purge only when configuration, ledger data, and the service account must also be deleted.
SQLite WAL File-backed ledgers permit concurrent audit reads; memory ledgers use memory-mode journaling. Persist the ledger path before real traffic and verify the chain after restart.
Decide endpoint Operator decisions are gated by CLAVENAR_LITE_DECIDE_TOKEN when configured. Keep the decide token distinct from the agent bearer token.
Hosted template The explicit hosted profile validates auth, enforce posture, bounded rates, durable storage, HTTPS upstream, adapter compatibility, and timeout before binding. Do not replace the checked-in Fly bounds with local developer defaults. A placeholder upstream intentionally prevents readiness until configured.
Slack webhook Park alerts are fire-and-forget; failures log warnings and never block the agent's 202. Monitor webhook delivery separately; the ledger remains the durable source of truth.