Release notes

2609.0.0-preview.7 — 2026-09-16

CloudGrange now runs on Kubernetes and is deployed by Helm. This is the first release whose downloadable artifact deploys the Kubernetes stack rather than Docker Compose.

Added

  • Helm chart published to an OCI registry — oci://ghcr.io/cloudgrange/charts/cloudgrange. Install onto any Kubernetes cluster you already run; see Helm install. This is a fifth installation path alongside Appliance, Online, Bundled and Native Linux.
  • K3s/Helm install bundle — Install-CloudGrange-K3s-Bundled.zip, containing the umbrella chart (api, portal, relay, postgres, keycloak, observability) plus vendored cert-manager, CloudNativePG, MetalLB and Velero charts.
  • global.ingress.className / global.ingress.annotations values so the chart installs on any ingress controller — Traefik, ingress-nginx, microk8s public, Azure Application Gateway, AWS ALB.

Changed

  • The default engine is now K3s for both Install-CloudGrange-Linux.sh and Install-CloudGrange.ps1. Docker Compose remains available via --engine compose / -Engine Compose for one release cycle and is still the only engine supporting fully offline Bundled mode.
  • Install documentation rewritten for the Kubernetes/Helm architecture across every path, including the relay and agent guides.

Fixed

  • Portal could not start on Kubernetes. The image declared a non-numeric USER nginx, which Kubernetes cannot verify against runAsNonRoot: true, producing CreateContainerConfigError and stalling helm install. The image now declares USER 101 and the chart pins runAsUser/fsGroup.
  • Portal crash-looped under Docker Compose with chown("/var/cache/nginx/client_temp") failed (Operation not permitted) — the base image retained a user directive requiring CAP_CHOWN, which the hardened Compose stack drops.
  • The installer reported success over a broken install. The readiness gate excluded the portal pod from its not-Ready check and tolerated a failed helm --wait, so a dead container still produced install complete. Both allowances removed; any pod that is not Ready now fails the install.
  • The Ingress hardcoded ingressClassName: traefik, so on any non-K3s cluster no controller claimed it and the product was unreachable with no error.

Known limitations

  • The K3s bundle does not yet ship offline container images; it needs internet access at install time. Use the Appliance for a fully offline Kubernetes deployment.
  • Images publish only a latest tag, so a helm upgrade that does not change the tag will not roll pods. Force a refresh with kubectl rollout restart after pulling.

Downloads

2609.0.0-preview.4 — 2026-09-15

CloudGrange 2609.0.0-preview.4 is the first publicly downloadable on-premises preview. It is not Generally Available or certified for production.

Included

  • A single-node Docker Compose control plane with the CloudGrange API, portal, and relay; PostgreSQL 17; Keycloak; nginx; OpenTelemetry Collector; Prometheus; Loki; and Grafana.
  • Published first-party images at ghcr.io/cloudgrange/cloudgrange-api:latest, ghcr.io/cloudgrange/cloudgrange-portal:latest, and ghcr.io/cloudgrange/cloudgrange-relay:latest. These are private packages; registry-backed installs require authorized access.
  • Four on-premises installation modes:
    • Online: Windows/Hyper-V creates an Ubuntu VM and downloads dependencies.
    • Bundled: Windows/Hyper-V creates an Ubuntu VM from the offline release bundle.
    • Appliance: imports the separately hosted 0.1.0-lab.1 VHDX.
    • Native Linux: installs directly on an existing Ubuntu/Debian server with Docker Engine and Compose already present.
  • Public installer source and release at CloudGrange/cloudgrange-deployment-installer.
  • The preview update channel points at the 2609.0.0-preview.4 bundle. This release corrects the preview.3 portal startup failure and makes the Updates page check and display the real channel result.

Download

Known preview limitations

  • Artifacts are unsigned. Published SHA-256 values check integrity, not publisher authenticity.
  • Online and Native Linux pull private GHCR packages and require entitlement. Bundled and Appliance carry their images.
  • Native Linux is online-only in this preview and does not install Docker.
  • The relay's internal agent listener is HTTP; nginx exposes it over TLS on port 8443. Per-agent mTLS is planned.
  • Azure-hosted PaaS is coming soon and is not part of this release.
  • Module signing and the full general-purpose encrypted secrets backend are not complete.

See current product and release status.