Releases
Published versions, compatibility requirements, and upgrade notes for the Ferrum family. Verified October 2, 2026.
Ferrum Edge v0.9.10
Published October 1, 2026. This is the latest published versioned release as checked on October 2. Edge remains pre-1.0. Use one explicit version for binaries, checksums, charts and images.
GitHub's /releases/latest excludes prereleases. The historical release and container tag
literally named latest are development artifacts and are not refreshed by versioned releases.
- v0.9.10 tightens MCP charset and JSON-RPC inspection in
mcp_gateway,ai_prompt_shieldandai_transcript_audit. - v0.9.9 introduced the node-local MCP tool catalog, OpenAPI-to-MCP tooling, opt-in diagnostic references and explicit HTTP path-parameter admission.
- Linux and macOS x86_64/ARM64 gateway binaries, Windows x86_64, Linux CNI binaries, adjacent
.sha256files, and versioned container images are published.
Upgrade to the Current Release
Plan the rollout before replacing binaries
- Review all intervening releases in the tagged upgrade guide and changelog, then validate configuration with the new binary before cutover.
- Edge's SQL baseline changed in v0.9.9. PostgreSQL, MySQL and SQLite databases created by earlier releases need a fresh database and namespace-complete logical export/re-import. Keep the old database intact for rollback; restarting an old binary on a new baseline is unsupported. MongoDB is unaffected by that SQL baseline change.
- HTTP routes refuse semicolon path parameters unless
allow_path_parametersis enabled, and refuse empty path segments. Review affected clients and stricter plugin settings. - Upgrade companion tools using their own qualified pair below. The newest gateway is not automatically a tested pair for every tool.
Follow the release-tagged upgrade guide; automatic startup migrations do not replace its rebuild and rollback procedure.
Companion Tools
| Tool | Published release / source status | Compatibility |
|---|---|---|
| Ferrum Foundry | v0.4.0 (October 1, 2026) | Qualified with Edge v0.9.10: SQLite database mode, trusted-proxy authentication and Chromium. Other modes, Edge releases and eBPF images are not qualified. Linux AMD64/ARM64 images are published. |
| Ferrum Nexus | v0.3.0 (October 1, 2026) | Paired with Edge v0.9.9; other releases, including v0.9.10, are unverified. Tagged source build, no prebuilt Nexus image. Nexus forward migrations and the Edge SQL export/re-import are separate upgrade steps. |
| GitForgeOps | Source version 0.1.0; no GitHub release | Proposed baseline uses Edge v0.9.10, but the release record is still pending. Older validator checksum allowlist entries do not establish support. File/mesh output needs an external fleet delivery system. |
| Ferrum Alloy | Pre-release source; not on crates.io | The audited source record lists Edge v0.9.10 and v0.9.9 in file mode. Works standalone; this is source compatibility, not an Alloy release. |
| Ferrum Anvil | v0.1.1 unsigned preview (October 1, 2026); verify downloads with SHA256SUMS. GitHub marks this non-prerelease, while the release notes explicitly label the artifacts a preview | Desktop API client and CLI; no Edge gateway required. Catalogs cover Edge 0.9.8 (default), 0.9.7 and 0.9.5, not the latest Edge. macOS/Windows installers lack platform code signing; in-app updater signatures are verified. Preview downloads. |
| Ferrum Contracts | contracts-edge-0.9.9-r2 (October 1, 2026) | Shared schemas and vocabularies, not a gateway binary. Edge-owned contracts describe v0.9.9 and also cover v0.9.10; the revision adds Alloy's optional agents manifest schema. Consumer pins still differ. |
Published records were checked directly on GitHub, excluding drafts and prereleases. Source version numbers and merged release-preparation changes do not prove an artifact is published.
Capabilities and Build Options
Edge has eight operating modes and 82 built-in registrations: the 80 configurable plugins in the catalog, the internal mesh BPF metrics plugin,
and the config-only transaction_log_schema. See features and the plugin catalog.
- Published standard binaries and images include
cloud-secrets. Default source builds need that feature or provider-specific features for Vault/AWS/GCP/Azure backends. - The standard image has mock eBPF capture. Real Linux capture needs
-ebpf; shell/iptables fallback and the Ambient UDP lifecycle need-ebpf-tools. - The three Edge container families are signed at immutable digests and carry SBOM/provenance attestations. Raw binaries have SHA-256 checksums; a checksum is not a platform code signature.
- ACME requires an
acmebuild. FIPS requires a separate--no-default-features --features fipsbuild and documented deployment controls. - Node waypoint remains experimental. Mesh and standards support have explicit maturity and topology limits in the supported matrix.
Historical Release: v0.9.5
Published September 14, 2026. This introduced resource labels on proxies, consumers, upstreams and plugin configurations,
with X-Ferrum-Provisioned-By attribution on creates. v0.9.4 and earlier reject non-empty labels;
upgrade data planes before a control plane starts distributing them.