Clearplane 1.0.0-alpha1

· Prerelease

Highlights

The first Clearplane alpha brings reverse proxying, automatic certificates, Docker discovery, and a browser management interface together on a single Linux Docker host. This is a private evaluation release for alpha participants.

Changes

  • Configure proxy routes and upstream clusters through the UI or Docker labels, with reusable policies for access control, rate limiting, bans, headers, caching, and compression.
  • Issue and renew certificates through Let's Encrypt using HTTP-01 or DNS-01, or import an existing certificate.
  • Review service status, request logs, background jobs, and traffic analytics from the management interface.
  • Run Edge, Core, the UI, and ContainerProxy as separate containers. Internal services authenticate each other with mutual TLS; ContainerProxy owns access to the Docker socket.
  • Install and operate the deployment with the self-contained clearplane host CLI. Release downloads include Linux x64 and arm64 launchers plus compose.yaml.

Upgrade instructions

Alpha1 is the initial packaged release. Its installation layout uses a clearplane binary beside a docker/ directory containing compose.yaml. Use the launcher for host checks, initial installation, and routine operations.

Follow the alpha1 installation instructions and alpha1 operating guide. Configure trusted HTTPS or a secured local connection before submitting administrator credentials.

The deployment flow changes in alpha2. Read its migration notes before upgrading an alpha1 installation.

Known issues

  • Alpha downloads and container images require an authorized GitHub account.
  • The supported target is one Linux Docker host on x64 or arm64. High availability, multiple hosts, and rolling upgrades are outside this release's scope.
  • A supported backup and restore workflow covering all databases, keys, and certificates is not available. Changing image versions does not provide database rollback.
  • Native WAF inspection and Basic/JWT authentication for proxied applications are outside the supported alpha evaluation scope. Forward authentication and client-certificate authentication for customer routes are not implemented in this release.
  • Host firewall, DNS, Docker socket permissions, and SELinux policy remain the operator's responsibility.

Release downloads