Clearplane 1.0.0-alpha1
· Prerelease
Highlights
The first Clearplane alpha brings reverse proxying, automatic certificates, Docker discovery, and a browser management interface together on a single Linux Docker host. This is a private evaluation release for alpha participants.
Changes
- Configure proxy routes and upstream clusters through the UI or Docker labels, with reusable policies for access control, rate limiting, bans, headers, caching, and compression.
- Issue and renew certificates through Let's Encrypt using HTTP-01 or DNS-01, or import an existing certificate.
- Review service status, request logs, background jobs, and traffic analytics from the management interface.
- Run Edge, Core, the UI, and ContainerProxy as separate containers. Internal services authenticate each other with mutual TLS; ContainerProxy owns access to the Docker socket.
- Install and operate the deployment with the self-contained
clearplanehost CLI. Release downloads include Linux x64 and arm64 launchers pluscompose.yaml.
Upgrade instructions
Alpha1 is the initial packaged release. Its installation layout uses a clearplane binary beside a docker/ directory containing compose.yaml. Use the launcher for host checks, initial installation, and routine operations.
Follow the alpha1 installation instructions and alpha1 operating guide. Configure trusted HTTPS or a secured local connection before submitting administrator credentials.
The deployment flow changes in alpha2. Read its migration notes before upgrading an alpha1 installation.
Known issues
- Alpha downloads and container images require an authorized GitHub account.
- The supported target is one Linux Docker host on x64 or arm64. High availability, multiple hosts, and rolling upgrades are outside this release's scope.
- A supported backup and restore workflow covering all databases, keys, and certificates is not available. Changing image versions does not provide database rollback.
- Native WAF inspection and Basic/JWT authentication for proxied applications are outside the supported alpha evaluation scope. Forward authentication and client-certificate authentication for customer routes are not implemented in this release.
- Host firewall, DNS, Docker socket permissions, and SELinux policy remain the operator's responsibility.