Skip to content
NebulaCtrldocs

Changelog

Every NebulaCtrl release, newest first, with what was added, changed and fixed and what to read before you upgrade.

Every release of NebulaCtrl, newest first. NebulaCtrl is in beta: upgrades migrate your data in place and can be rolled back, and the HTTP API and nebula.toml may still change before 1.0. Each change is listed here in the release that ships it. Read the BREAKING CHANGES entries before you upgrade.

To upgrade, see Upgrade the control plane.

0.39.2 (2026-10-02)

Fixed

  • api: the OpenAPI document declares its security schemes and describes every tag
  • console: the approval dead-end message names the real self-approval switch

Documentation

  • generated API reference, CLI reference and changelog
  • rewrite the documentation site, checked against the code, in the console's look

0.39.1 (2026-10-02)

Fixed

  • agent: no service-account token in workload and release-command pods, so file mounts under /run/secrets work
  • cli: nebula config validate no longer reads a repository nebula.toml as its own configuration
  • console: new project prefers the repository's nebula.toml and lets you choose what to create
  • services planned from a project nebula.toml show on the canvas without a reload

0.39.0 (2026-10-02)

Added

  • deploys wait for what they depend on

0.38.3 (2026-10-02)

Fixed

  • agents bring their CRDs, refused releases are shown, Deploy deploys

0.38.2 (2026-10-01)

Fixed

  • console: keep Update agent busy until the agent update finishes

0.38.1 (2026-10-01)

Fixed

  • console: no reveal button for an empty secret in the compose import
  • console: tell a tab left open across a control-plane update to reload

0.38.0 (2026-10-01)

Added

  • update the control plane from the console

0.37.0 (2026-10-01)

Added

  • console: compose import walks you through services, secrets, wiring and staging
  • declare a project's services, databases and their wiring in a root nebula.toml
  • mount a service's variables as read-only files, and set a release command in the console

Fixed

  • agent: wait for a first deploy's volume to be provisioned instead of failing at once
  • compose import asks for values only you can supply instead of generating them
  • compose import mounts compose secrets as files, shares a secret across services, and keeps one-shot migrations as a release command

Documentation

  • project config guide and reference, compose import steps

0.36.0 (2026-10-01)

Added

  • compose import as a one-time migration at project start
  • web: confirm an activity export with its event count

0.35.0 (2026-10-01)

Added

  • compose import, ask-to-generate secrets, newer deployment supersedes the one in flight
  • console: expand the staged bar to show what is staged
  • console: right-click menu on the Projects page
  • console: search repositories by the new project's name
  • delete an environment with everything it owns
  • let a service skip production approval
  • web: label the import table's columns
  • web: replace existing variables from an import, after a confirmation

Fixed

  • agent empty namespace set watches forbidden types; netguard refuses reserved IPv6
  • console: keep an approval open after deciding it
  • console: stay signed in after deleting or leaving an organization
  • web: link a tailnet domain to its reported ts.net address

Documentation

  • explain variables and ${{ }} references, and say so in the console

0.34.1 (2026-09-30)

Fixed

  • live namespace changes for the agent, bounded backup uploads, API-token git connections

0.34.0 (2026-09-30)

BREAKING CHANGES

  • staged changes, env templates, structured logging everywhere, Go modernization

Added

  • staged changes, env templates, structured logging everywhere, Go modernization

0.33.0 (2026-09-29)

BREAKING CHANGES

  • CloudNativePG-only Postgres, self-healing delivery, Claude Design v3 console

Added

  • CloudNativePG-only Postgres, self-healing delivery, Claude Design v3 console

0.32.0 (2026-09-29)

Added

  • CloudNativePG databases, zero-config builds, canvas metrics; move to nebulactrl

0.31.0 (2026-09-28)

Added

  • configure a service from its repository with nebula.toml

Fixed

  • upgrade: drop links into the private repository from the public changelog

0.30.0 (2026-09-28)

Added

  • installable, shareable templates

0.29.0 (2026-09-27)

Added

  • a cron helper everywhere a schedule is entered

0.28.2 (2026-09-27)

Fixed

  • web: show a toast's whole title and description

0.28.1 (2026-09-27)

Fixed

  • agent: broker re-contends after losing its lease; node Tailscale route requires the CRD field

0.28.0 (2026-09-27)

Added

  • route tailnet reverse proxies through the node's Tailscale; clean up on project deletion

0.27.5 (2026-09-27)

Fixed

  • mesh: make edge-fronted domains reachable and certifiable
  • reverse proxies survive a slow Tailscale operator, type switches and edits

0.27.4 (2026-09-27)

Fixed

  • domain: request an http-01 certificate only once DNS points

Documentation

  • adr: record the mesh's measured residual risks

0.27.3 (2026-09-27)

Fixed

  • agent: detect edge fronting from the Domain CRD's upstreams field

Documentation

  • api-guide: document the mesh, gateways, mesh grants and edge fronting

0.27.2 (2026-09-27)

Fixed

  • agent: admit Tailscale ingress proxies to tailnet-only domains
  • restart nebula0 on address changes; admit the broker's registry claim

0.27.1 (2026-09-27)

Fixed

  • install: keep the mesh working under Ubuntu's WireGuard AppArmor profiles

0.27.0 (2026-09-27)

Added

  • mesh: self-managed WireGuard mesh, public gateways, edge fronting and cross-cluster grants

0.26.1 (2026-09-26)

Fixed

  • agent: make Stop work on clusters installed before the stopped flag existed

0.26.0 (2026-09-26)

Added

  • run control-plane background work on River

0.25.0 (2026-09-26)

Added

  • stop and start a service by scaling its live release to zero and back

Fixed

  • build: report the pushed digest again so git builds deploy

0.24.2 (2026-09-26)

Fixed

  • agent: bring the previous release back for good when a downtime deploy is cancelled
  • agentlink: record release stages from real clusters again

0.24.1 (2026-09-26)

Fixed

  • agent: fail a traffic switch that never completes instead of retrying forever
  • web: fill hold-to-confirm buttons while they are held
  • web: keep the project canvas sharp after zooming
  • web: show which release keeps serving after a failed deploy, and show proxies as routing

0.24.0 (2026-09-26)

Added

  • install: install NebulaCtrl with curl -fsSL https://get.nebulactrl.dev | sh
  • release: print the release feed with nebula changelog and link to the public changelog
  • web: chart service metrics in real units against their limits
  • web: open deployments in a card with their pipeline, logs and details

Fixed

  • agent: clone git sources into a build workspace owned by another user
  • web: slide the service panel in without bouncing past its edge

Changed

  • web: drop the project list view

0.23.2 (2026-09-26)

Fixed

  • web: keep Projects on screen until the card has grown over it

0.23.1 (2026-09-26)

Fixed

  • changeset: setting a value back to its default leaves nothing to approve

0.23.0 (2026-09-26)

Added

  • release: approving a deploy settles older requests still waiting

0.22.0 (2026-09-26)

Added

  • docs: publish the public documentation site

Fixed

  • agent: retry the stream Hello until the control plane receives it

0.21.3 (2026-09-26)

Fixed

  • agent: unblock the broker cutover on real clusters

0.21.2 (2026-09-26)

Fixed

  • web: frame the canvas before the open-project morph reveals it

0.21.1 (2026-09-26)

Fixed

  • security: harden tenancy, agent RBAC, credentials and join flows
  • web: align console with v3 design and clear state on sign-out

0.21.0 (2026-09-25)

Added

  • web: filter activity by the days picked in the deploy calendar
  • web: read any point on a metric chart and see its configured limit
  • web: the animated NebulaCtrl mark

Fixed

  • agent: connect the database console to its database, not localhost
  • web: morph out of the project canvas to every page
  • web: show a service's in-flight progress once, as text

0.20.1 (2026-09-25)

Fixed

  • web: match Console v3's panel, menu and back motion

0.20.0 (2026-09-25)

Added

  • web: the brand assets and the Console v4 sign-in, onboarding and panel

0.19.0 (2026-09-25)

Added

  • release: count deployments per day for a year-long activity calendar
  • web: the Console v3 design

0.18.1 (2026-09-25)

Fixed

  • agent: start a volume-mounting release only after the previous release's pods have exited
  • web: stack the source dialog's cards when the field is narrow

0.18.0 (2026-09-25)

Added

  • upgrade: show newer releases and K3s upgrades from public release feeds
  • web: the Console v2 design

Fixed

  • release: name only the resources a surge is actually short of
  • upgrade: classify the update routes for token scope and name a non-feed answer

0.17.1 (2026-09-24)

Fixed

  • deploy: end the image check with an if, not a trailing && list

0.17.0 (2026-09-24)

Added

  • deploy: the release pipeline deploys the production control plane

0.16.1 (2026-09-24)

Fixed

  • domain: say when only a placeholder certificate is served, and issue Cloudflare domains over DNS by default

0.16.0 (2026-09-24)

Added

  • build: check a build before it starts and explain why one failed in plain words
  • release: say before a deploy what will happen, and stop build-started deploys waiting for approval
  • web: show deploy checks before you click, build state in the header, and approve in place

Fixed

  • web: show why a build or proxy deploy was refused in the deploy dialog

Build

  • publish the app images before nebula-postgres, so a Postgres rebuild never delays a release

0.15.1 (2026-09-24)

Fixed

  • agent: push builds to the in-cluster registry through its Service

Build

  • build images only for releases, nebula-postgres only when it changed, and use the runner's own caches
  • fail the image plan when nebula-postgres/majors lists no major

0.15.0 (2026-09-24)

Added

  • registry: tell a named image user from a numeric one
  • run a new environment on the best connected cluster instead of none
  • web: centre the selected service in the canvas the sheet leaves visible

Fixed

  • db: drop cluster_allocation_sample's foreign key, which deadlocked chunk creation
  • domain: say what to do when a domain's environment has no cluster, and sync DNS once it gets one

Documentation

  • research: the share incident and what can shorten a single-instance deploy gap

0.14.1 (2026-09-24)

Fixed

  • agent: bring the previous release back when a downtime-accepted deploy fails

Build

  • run the envtest suite and bound the runner's caches on the production node

0.14.0 (2026-09-24)

Added

  • database: connect services to databases, pin newest engine majors, replace Redis with Valkey
  • observe: keep telemetry in TimescaleDB hypertables and report real pod and traffic metrics
  • read a process's start command from its image, override only when custom
  • web: live deploy progress, a stacked deployment card and labelled connection edges

Fixed

  • agent: release objects are garbage-collected, so namespaces never strand (EXP-28)

Build

  • use the dex a persistent runner host already serves on :5556

0.13.0 (2026-09-23)

Added

  • web: widen the detail sheet so more fits beside the canvas

Fixed

  • auth: hand the provider logout URL back instead of redirecting a fetch
  • web: keep the project toolbar usable in list view and give the list a panel

0.12.0 (2026-09-23)

Added

  • agent: dump and point-in-time restore volume jobs
  • agent: prune orphaned namespaces, expand volume claims, report node labels and volume usage
  • agent: read-only database console over correlated agent commands
  • audit: filter activity and its export by kind server-side
  • audit: show a project-restricted token only its own projects' activity
  • auth: GET /api/v1/installation reports version, address and identity provider
  • auth: record two-factor evidence from amr and let an organization require it
  • auth: refuse project-restricted tokens every organization-wide resource
  • auth: refuse project-restricted tokens organization-wide actions; hold services to their project
  • auth: rename developer to deployer; API tokens carry a role and optional project scope
  • auth: report the running version in the public auth config
  • backup: dump backups, signed downloads and point-in-time restores
  • backup: hold backups, restores and schedules to the token's projects
  • build: hold builds and their log streams to the token's projects
  • cluster: join token labels, lifetime, list and revoke; ssh install
  • cluster: node labels, expandable storage classes, volume usage, degraded status
  • database: database services, read-only console and Postgres PITR
  • db: gitlab connections, installation permissions and preview environments schema
  • db: join token labels and revocation, ssh installs, volume usage
  • db: migration 0047 for database services and point-in-time recovery
  • delivery: per-environment settings, change sets and delivery policy
  • domain: hold domains and certificate renewal to the token's projects
  • feed: organization live change stream with bounded per-subscriber buffers
  • feed: relay only a restricted token's own projects' changes on the event stream
  • gitsource: gitlab connections, pull request webhooks, commit compare and canvas deep links
  • images: nebula-postgres, Postgres 16 with WAL-G
  • notification: member inbox, Slack and PagerDuty channels, and a retrying outbox
  • observe: bucketed service metrics summary with usage as a share of limits
  • observe: hold logs, metrics, runtime and traffic to the token's projects
  • observe: parse log levels at ingest and filter logs by minimum level
  • preview: hold a project's preview settings to the token's projects
  • preview: pull request preview environments
  • project: clone environments and publish on environment delete
  • publish live-feed changes and notifications from release, build, backup, cluster and domains
  • release: hold releases, deployments and approvals to the token's projects
  • scim: provision people and groups from the identity provider
  • team: teams own projects; members list their teams
  • variable: hold variables, external resources and dependencies to the token's projects
  • web: activity grouped by day with the deploys chart in the header
  • web: add a database from a template on the canvas
  • web: add a server with labels, by script or over SSH
  • web: change-set hook, canvas graph derivation and promotion diff
  • web: clusters page with the floating cluster sheet
  • web: connect GitLab in place during onboarding
  • web: console primitives and status vocabulary
  • web: console revamp design tokens
  • web: create a project with its environments, team and a Postgres start
  • web: dump backups, downloads and point-in-time recovery
  • web: glass sign-in and auth screens over the nebula shader
  • web: inbox popover and shared console links
  • web: open services in the canvas sheet; old service pages become a redirect
  • web: org live feed invalidates queries from the event stream
  • web: parse and check node labels the way the control plane does
  • web: phrase database and backup-download events in Activity
  • web: project canvas workspace replaces the project, environment and services pages
  • web: projects card grid and the new project dialog
  • web: props-driven project canvas kit
  • web: restyle ui primitives to the console design
  • web: review dialog and the workspace's floating panels
  • web: service sheet helpers and a change-set hook
  • web: service sheet with deployments, variables, logs, metrics, instances, data, backups and settings
  • web: settings API tokens with project scoping and a reveal step
  • web: settings General section with workspace identity and danger zone
  • web: settings Integrations section and the sub-nav; retire the old settings pages
  • web: settings Members section with teams, two-factor state and role legend
  • web: settings Security & policy section
  • web: show each machine's join-time labels in cluster settings
  • web: show the owning team on project cards
  • web: the database Data tab with connection card and read-only console
  • web: three-step onboarding at /$org/welcome
  • web: top bar and tab nav shell with the console command palette
  • web: two-pane approvals with checks, commits, diff and blast radius
  • web: typed confirm dialog with a useConfirm hook
  • web: WebGL nebula shader for sign-in and the canvas

Fixed

  • agent: count console results by their encoded size
  • cluster: let an SSH install reach machines on the operator's own network
  • database: refuse a project-restricted token before revealing a service is a database
  • gitsource: refuse a project-restricted token the GitHub App manifest leg
  • images: build WAL-G against grpc 1.83.2
  • release: answer 404, not a scope refusal, for another organization's service
  • web: accept the downtime a database's volume deploy needs
  • web: approval checks show a duration only when it is not already in the detail
  • web: canvas polish from a browser pass
  • web: floating sheets open below the console bars
  • web: hold the shell's org-scoped reads until an organization is active
  • web: keep the cluster sheet open while the add-server dialog is used
  • web: phone layout of the canvas header, top bar and backup list
  • web: polish from a browser pass over the new screens
  • web: polish from a browser pass over the service sheet
  • web: punctuate server errors and quote schema-qualified tables
  • web: read Cloudflare's 409 as not connected, widen backup actions
  • web: role gate speaks deployer and knows the team, policy and channel actions

Changed

  • preview: name the settings wire body and enumerate connection kinds
  • web: let the org live feed replace polling it supersedes
  • web: open an approval from the Deployments tab with a typed search
  • web: restyle the deployment page and org error screens, delete orphans

Documentation

  • adr: decisions for the console revamp
  • api-guide: change sets, per-environment settings, references and delivery policy
  • api-guide: spell out what a project-restricted token reaches
  • database services, the console, dumps and point-in-time recovery
  • runbook: never pin the agent image; apply CRD-only changes from the tag
  • web: say why the rollout log has no per-replica lines

Build

  • build nebula-postgres's WAL-G and gosu from source; allowlist a test fixture
  • ignore a pseudo-version false positive in the nebula-postgres scan

0.11.0 (2026-09-23)

Added

  • agent: install control-plane certificates as TLS Secrets
  • domain: Cloudflare connection, DNS-01 certificates from the control plane, proxy-aware checks
  • domain: manage a domain's DNS in Cloudflare and choose DNS-01 certificates
  • web: a cluster that never connected opens on how to connect it
  • web: configure services in human units
  • web: creating a service deploys it
  • web: domain DNS mode, certificate method and managed DNS status
  • web: guide a new organization from its first cluster to a live URL
  • web: make projects and environments readable at a glance and on a phone
  • web: one clear next step for domains, and truthful logs and builds
  • web: open a service where it runs, and lead with what went wrong
  • web: readable activity and approvals, settings in setup order
  • web: search everything with Ctrl+K, and lead navigation with what you deploy
  • web: shared foundations for a calmer, more legible console

Fixed

  • agent: ship logs, metrics and traffic for namespaces the agent did not create
  • agent: stop reporting the desired state resent after every reconnect
  • dev: seed a realistic organization against the current API
  • domain: attribute background DNS and certificate events to their organization; clearer managed-DNS copy
  • report what a service is serving, apart from what waits or failed on top
  • sim: report each simulated pod's process

Changed

  • web: finish the move to human-unit formatters; fit tables and alerts on phones

Documentation

  • research: single-instance processes, Kubernetes feature review, Cloudflare-managed DNS

0.10.3 (2026-09-22)

Build

  • gate the image scan on CRITICAL and HIGH, as documented

0.10.2 (2026-09-22)

Added

  • backup: wire volume backup/restore into the running control plane
  • web: object storage settings and per-volume backup/restore UI
  • implement agent-side volume backup and restore

Fixed

  • install: stop Traefik cutting off uploads after 60 seconds
  • observe: accept build.step in cluster_event's kind check

Build

  • keep the integration job's Postgres data on tmpfs

0.10.1 (2026-09-22)

Fixed

  • agent: activate a worker that exposes no port
  • agent: give a tailnet domain's Ingress a dot-free name
  • domain: route a proxy service's domain to its upstream port
  • install: let Traefik route domains to ExternalName services

0.10.0 (2026-09-22)

BREAKING CHANGES

  • agent: existing release-scoped claims are not adopted; data in them must be copied into the new vol-<slug>-<name> claim before the next deploy.

Added

  • agent: configure Traefik ACME HTTP-01 TLS and detect its resolvers
  • let a worker process expose an in-cluster TCP port

Fixed

  • agent: keep a volume's claim across releases instead of recreating it empty
  • agent: name a tailnet domain's device after the hostname it asks for
  • deploy: pass NEBULA_AGENT_IMAGE into the control plane container

Changed

  • keep readiness and port validation within the complexity budget

Documentation

  • backfill the changelog through v0.9.3

Build

  • let the lint job run beside a local golangci-lint on the shared runner host
  • run every workflow on the self-hosted homelab-1 runner

0.9.3 (2026-09-22)

Fixed

  • agent: derive a namespace's pod security level from its workloads
  • agent: ship observed events from every replica, not only the leader
  • release: publish an auto-approved deploy to its cluster

0.9.0 (2026-09-22)

Added

  • service: reverse-proxy services and tailnet-only exposure

0.8.1 (2026-09-22)

Added

  • release: let a process declare the UID it runs as

Fixed

  • cluster: refresh the agent's reported facts on every hello

0.7.0 (2026-09-22)

Added

  • release: approve a production deploy automatically for someone who can decide

0.6.0 (2026-09-22)

Added

  • service: build from a public repository with no connected account

0.5.2 (2026-09-22)

Fixed

  • agent: ship the Build CRD so a fresh cluster can connect

0.5.1 (2026-09-22)

Fixed

  • install: accept newer Ubuntu and Debian, and make a re-run converge

0.5.0 (2026-09-22)

BREAKING CHANGES

  • cluster.profile is dropped from the schema and the API. createCluster and updateCluster no longer accept it, ClusterBody no longer returns it, and createClusterJoinCommand no longer takes a role.

Added

  • derive cluster shape from attached machines instead of a profile

0.4.0 (2026-09-22)

Added

  • web: make the whole command block click-to-copy

Fixed

  • build: keep docs and release metadata out of the image contexts

0.3.2 (2026-09-22)

Fixed

  • build: make the dockerignore file the one BuildKit actually reads
  • web: let pages use the full width beside the nav

0.3.1 (2026-09-22)

Fixed

  • agent: harden the Traefik scrape and record server-token disclosure
  • registry: stop the reachability check from dialing internal addresses
  • release: refuse an agent event that would skip an approval

0.3.0 (2026-09-22)

Added

  • api: serve every fact the console could only mark "not reported"
  • web: redesign the console and wire it to the new API surface

Fixed

  • release: never ship a release that is awaiting approval
  • web: draw one focus ring around a field, not two
  • web: send the organization header on server-sent event streams

Documentation

  • write down where production runs and how a release gets there

0.2.2 (2026-09-21)

Fixed

  • ci: stamp the release version into the published images

0.2.1 (2026-09-21)

Fixed

  • ci: publish images for a release-please tag

Build

  • let a release run be retried by hand

0.2.0 (2026-09-21)

Added

  • cluster: one-command server install with hardening, live progress and node joins
  • cluster: update and roll back a cluster agent from the UI
  • deploy: production installer
  • git: GitHub App and Forgejo connections, in-cluster builds, push-to-deploy
  • tenancy: organizations in the URL, header-scoped API, isolation guards, project variables

Fixed

  • agent: ask for the agent tag that is actually published
  • build: cross-compile images natively and stamp the real target arch
  • web: keep dist/.gitkeep so the embed compiles on a clean checkout
  • web: wrap copy fields instead of truncating credentials

Changed

  • web: generate the API client and query options with hey-api

Build

  • allowlist the e2e master key and protocol token fixtures in the secret scan
  • cut releases with release-please
  • do not block image publishing on the Security-tab upload

Chores

  • release 0.2.0

[Unreleased]

[0.1.0] - 2026-09-20

First release. Pre-alpha: usable end to end, not yet usable in production.

Added

  • Control plane. A single Go binary serving the API, the embedded React interface and the link every cluster agent connects back to. Ninety-nine operations, all described by the OpenAPI document at /api/openapi.json, which the TypeScript client is generated from.
  • Authentication delegated entirely to one external OIDC provider per installation, with PKCE, no local passwords and no sign-up form. Identity is keyed by issuer|sub, never by email. The first person to sign in becomes the owner of a bootstrapped organization; everyone after needs an invitation.
  • Organizations with four roles, invitations, API tokens scoped read or write, and sealed registry credentials.
  • Clusters. One-command enrollment (kubectl apply -f <base-url>/agent/v1/install.yaml?token=…), node inventory, capacity, reported capabilities, and cordon, uncordon and drain as node commands.
  • Projects, environments, services, processes and volumes, with a namespace derived once at environment creation and never moved.
  • Variables sealed with envelope AES-256-GCM under one master key, merged external resource then environment then service, with a reveal that is recorded in the audit ledger by key and never by value.
  • Domains routed through Traefik, with a DNS check that says exactly which record to create.
  • Releases created from an OCI reference resolved once to an immutable digest, carrying a frozen configuration revision.
  • Deployments through a visible seven-stage state machine — pending, admitted, starting, qualifying, activating, draining, healthy — with a named blocker and a sentence a person can act on when one fails. Zero-downtime activation by patching one stable Service's selector; rollback is a second patch. Promotion carries a digest between environments; scaling is its own operation.
  • Approvals gating every change to a production environment, carrying the image diff, the replica diff, the variable keys that changed, and an impact summary with the capacity numbers behind it.
  • Logs and metrics in daily-partitioned Postgres with seven-day retention, full-text log search, and live tail over server-sent events.
  • An append-only audit ledger, enforced by a database trigger rather than by application code.
  • Cluster agent built on controller-runtime: outbound-only, leader-elected, persisting desired state as custom resources so it keeps reconciling while the control plane is unreachable.
  • A simulated cluster (--simulated-cluster) that walks releases through every stage with no Kubernetes at all, so the whole product can be driven on a laptop.
  • End-to-end suites against both the simulated cluster (make e2e-sim) and a real K3s cluster (make e2e-k3s), driving the published HTTP API only.

Known limitations

Each is tracked as an issue: building images from source, managed databases, volume backups and the Longhorn profile, mail, alerting, WAF and rate limiting, DNS automation, multiple OIDC issuers, group-claim role mapping, agent mTLS, pod autoscaling, cross-registry digest copy on promotion, and cluster upgrades.

A read-write-once volume still means accepted downtime on every release that touches it, and an image that runs as root cannot be deployed at all.

On this page