Documentation

Last updated: 2026-09-11

Everlock 0.9.0

The 0.9.0 release makes Everlock a git host: repositories are served over HTTP, browsed in a web UI, and built by CI runs that a push starts. It also replaces the two embedded AI models with one that can read the text in a photograph. Binaries are on the download page — one per platform now, with no model to choose — and the container image is published as cr.everlock.sh/everlock:0.9.

Highlights

  • Git over HTTP, with a web UI. Repositories clone, fetch and push over HTTPS alongside the existing SSH transport, on one vhost. The browser surface lists repositories, browses trees and blobs with syntax highlighting, walks history, shows a commit's diff, and opens a pull request by pushing a refs/pull/<slug>/<target> ref — a pull request is a ref, so nothing else has to store one. Anonymous access is a grant like any other.

  • CI runs on a push. A commit carrying .forgejo/workflows/ starts a run. Everlock speaks the runner protocol itself, so a stock forgejo-runner registers against it and takes work. strategy.matrix expands to one task per combination, concurrency: groups serialize, and a workflow declaring on: workflow_dispatch can be started from the Workflows tab. Repositories carry their own secrets and variables, and a secret's value is replaced with *** in job logs.

  • One embedded model instead of two. Every build now carries MiniCPM-V 4.6. SmolVLM and the Qwen3.5 pair are gone, and so is the choice between them.

    The reason is text in images. A vision model normally resizes an image to one fixed square and looks at it once, which throws away the text in a screenshot before the model ever sees it. MiniCPM-V slices instead: an overview plus a grid taken from the image's aspect ratio, ten views rather than one, so small text is never scaled past legibility. On a German screenshot the previous default returned "3 · "; this one returns the page, line for line. It is also faster on a large photo — about 19 seconds against 34 — because its language half is 752M parameters and the decoder dominates that work.

    We wrote up the measurements in One model instead of two.

  • The photo backend speaks Immich 3.1. It reports version 3.1.0, answers in the 3.x entity shapes, and sync resumes where a client left off instead of restarting. The map, the folder view and the user list are served from data the gallery already holds, so the app's map draws the library. A live photo no longer appears twice.

  • Sites publish on a schedule and page themselves. A page dated in the future stays out of listings, search, feeds and sitemaps until the moment arrives — no push, no restart. List templates take over paging with {% set p = paginate(by=50) %}.

Behavior changes

Downloads lose their model segment. With one embedded model there is one binary per platform, so the path no longer names a model:

https://everlock.sh/dl/latest/everlock-linux-amd64v3

Installs from 0.8.0 and earlier ask for /dl/latest/<variant>/everlock-<platform>. Both of those now resolve to the same binary, so an existing install updates itself one more time on its own and follows the new path afterwards. Nothing to do by hand.

Container images drop the variant suffix: cr.everlock.sh/everlock:0.9, and :latest is that image.

Building from source takes no feature flags. The qwen3 Cargo feature is gone, and with it the only feature the workspace defined. cargo build --release produces the one build there is.

Security

An SSH key authenticates only the account it is registered to. Public-key auth resolved a presented key against every user in the registry and accepted it for whichever login the client asked for, then ran the session as the key's owner. Anyone holding a registered key could therefore connect under any username, and the log recorded the name requested rather than the one authenticated. The session's access was always the key owner's, so no grant was crossed — but the account named in the connection, and in the audit trail, was not the one acting. A key is now accepted only under a name its owner answers to: their primary_name, or the login of one of their password credentials. A mismatch is rejected, logged with the owner the key belongs to, and falls through to password auth.

Fixes

  • A live photo no longer appears twice in the Immich app. The motion half of a pair is stored as the still's companion rather than as a second timeline asset.
  • Code blocks on a site take the styling the site asked for, instead of the default theme.
  • Generated tags are written in the configured language.
  • A failed enhancement now fails its job rather than reporting success.

Upgrading

Auto-update handles it. Everlock compares the digest of the binary it is running against the one the server advertises, so the version number is not part of the decision — the update lands on the next daily tick.

The full list is in the changelog.

updates release git workflows ai models immich