Release notes
2609.0.0-preview.7 — 2026-09-16
CloudGrange now runs on Kubernetes and is deployed by Helm. This is the first release whose downloadable artifact deploys the Kubernetes stack rather than Docker Compose.
Added
- Helm chart published to an OCI registry —
oci://ghcr.io/cloudgrange/charts/cloudgrange. Install onto any Kubernetes cluster you already run; see Helm install. This is a fifth installation path alongside Appliance, Online, Bundled and Native Linux. - K3s/Helm install bundle —
Install-CloudGrange-K3s-Bundled.zip, containing the umbrella chart (api, portal, relay, postgres, keycloak, observability) plus vendored cert-manager, CloudNativePG, MetalLB and Velero charts. global.ingress.className/global.ingress.annotationsvalues so the chart installs on any ingress controller — Traefik, ingress-nginx, microk8spublic, Azure Application Gateway, AWS ALB.
Changed
- The default engine is now K3s for both
Install-CloudGrange-Linux.shandInstall-CloudGrange.ps1. Docker Compose remains available via--engine compose/-Engine Composefor one release cycle and is still the only engine supporting fully offline Bundled mode. - Install documentation rewritten for the Kubernetes/Helm architecture across every path, including the relay and agent guides.
Fixed
- Portal could not start on Kubernetes. The image declared a non-numeric
USER nginx, which Kubernetes cannot verify againstrunAsNonRoot: true, producingCreateContainerConfigErrorand stallinghelm install. The image now declaresUSER 101and the chart pinsrunAsUser/fsGroup. - Portal crash-looped under Docker Compose with
chown("/var/cache/nginx/client_temp") failed (Operation not permitted)— the base image retained auserdirective requiringCAP_CHOWN, which the hardened Compose stack drops. - The installer reported success over a broken install. The readiness gate excluded the portal pod from its not-Ready check and tolerated a failed
helm --wait, so a dead container still producedinstall complete. Both allowances removed; any pod that is not Ready now fails the install. - The Ingress hardcoded
ingressClassName: traefik, so on any non-K3s cluster no controller claimed it and the product was unreachable with no error.
Known limitations
- The K3s bundle does not yet ship offline container images; it needs internet access at install time. Use the Appliance for a fully offline Kubernetes deployment.
- Images publish only a
latesttag, so ahelm upgradethat does not change the tag will not roll pods. Force a refresh withkubectl rollout restartafter pulling.
Downloads
- Install-CloudGrange-K3s-Bundled.zip
- Chart:
helm install cloudgrange oci://ghcr.io/cloudgrange/charts/cloudgrange --version 2609.0.0-preview.7
2609.0.0-preview.4 — 2026-09-15
CloudGrange 2609.0.0-preview.4 is the first publicly downloadable on-premises preview. It is not Generally Available or certified for production.
Included
- A single-node Docker Compose control plane with the CloudGrange API, portal, and relay; PostgreSQL 17; Keycloak; nginx; OpenTelemetry Collector; Prometheus; Loki; and Grafana.
- Published first-party images at
ghcr.io/cloudgrange/cloudgrange-api:latest,ghcr.io/cloudgrange/cloudgrange-portal:latest, andghcr.io/cloudgrange/cloudgrange-relay:latest. These are private packages; registry-backed installs require authorized access. - Four on-premises installation modes:
- Online: Windows/Hyper-V creates an Ubuntu VM and downloads dependencies.
- Bundled: Windows/Hyper-V creates an Ubuntu VM from the offline release bundle.
- Appliance: imports the separately hosted
0.1.0-lab.1VHDX. - Native Linux: installs directly on an existing Ubuntu/Debian server with Docker Engine and Compose already present.
- Public installer source and release at CloudGrange/cloudgrange-deployment-installer.
- The preview update channel points at the
2609.0.0-preview.4bundle. This release corrects the preview.3 portal startup failure and makes the Updates page check and display the real channel result.
Download
- Windows Online/Bundled release package
- Windows package SHA-256
- Native Linux installer
- Native Linux SHA-256
- Appliance VHDX archive
Known preview limitations
- Artifacts are unsigned. Published SHA-256 values check integrity, not publisher authenticity.
- Online and Native Linux pull private GHCR packages and require entitlement. Bundled and Appliance carry their images.
- Native Linux is online-only in this preview and does not install Docker.
- The relay's internal agent listener is HTTP; nginx exposes it over TLS on port 8443. Per-agent mTLS is planned.
- Azure-hosted PaaS is coming soon and is not part of this release.
- Module signing and the full general-purpose encrypted secrets backend are not complete.