Documentation

Last updated: 2026-09-30

Everlock 0.11.0

The 0.11.0 release puts a Windows binary on the download page, gives the built-in assistant a tool for every admin command, serves a page's Markdown source to clients that ask for it, and records when each credential was created and last used. Binaries are on the download page; the container image is published as cr.everlock.sh/everlock:0.11.

Highlights

  • Everlock runs on Windows. everlock-windows-amd64.exe joins the release row for row with the others: one static file, the same embedded model, no runtime to install. It is cross-built on the same Linux release runner as the rest — zig carries the MinGW toolchain — and its import table is checked before publish, so the only DLLs it asks for are Windows' own. The self-updater knows to fetch the .exe asset, so a Windows install updates itself like every other platform.

  • The assistant reaches every admin command. /ai had a hand-written tool table that had drifted to 53 of 127 commands; /server, /vault, /image, /calendar, /contacts, /files and /oauth were missing entirely. The table is now generated from the command registry itself, and each tool dispatches its own verb path with the model's JSON arguments — the same structured path MCP and the HTTP API already take. A drift test regenerates the table and compares, so a command added to the registry cannot go missing again. The argument examples the hand-written schemas carried are kept as a curated overlay, now covering 50 tools rather than 34.

  • The assistant's context window is the model's native 32 K. A tool schema for all 127 commands makes the fixed prefix about 13 K tokens; at the old 16 K window that left too little room for the conversation, which is the eviction that reads as the model forgetting mid-session. At 32 K roughly 19 K is left for the exchange. The prefix is prepaid by the build-time prefill cache, so its size costs KV-cache space rather than work on every turn.

  • A page can be fetched as Markdown. A Markdown-mode site answers a page URL with its Markdown source when the client asks for text/markdown — ordinary content negotiation, so browsers keep receiving HTML. The source is served with its front matter removed and its shortcodes expanded, and the front-matter title leads the body when the body has no heading of its own. Page responses carry Vary: Accept. See site routing.

  • Credentials carry their own history. Every password, SSH key and API key records when it was registered and when it last authenticated: /users list gains password set and last login, and /users ssh-keys list and /users apikey list gain created and last used. A use is noted in memory on the authentication path and written by the daily users.record-usage job, at shutdown, and before /users reload — one commit per flush, so a share link served all day costs a single commit and the column reads accurate to the day. A credential stored before the field existed is stamped the first time it is loaded. See the admin handbook.

Behavior changes

  • A repository's runs are read by its readers. /git workflow list and /git workflow log resolve the repository's own grant — reader reads a run and its log, because a build log quotes the code that produced it — and they sit beside /git secret and /git var above the system-admin gate. A listing without a repository spans every repository, so it shows only the ones the caller may read; naming one the caller cannot read is refused whether or not it exists. Previously both verbs required system administrator, so a repository's owner could see its runs in the web UI but not from the console. Registering a runner stays instance administration.

  • The MCP endpoint identifies itself as Everlock. The endpoint used to advertise the name and version of the MCP library it is built on. It now reports everlock, the running binary's version, a title, a description and the project URL, and its server instructions say how a verb path becomes a tool name and that authorization is per command. A test pins the identity.

  • The operator handbook describes the system rather than the CLI. It backs the AI system prompt, where actions go through typed tools, so its command samples duplicated the schemas in a shape the model does not use. It now carries the access-path model, what each namespace governs, and the behaviour no schema states; the anon scope it documented was stale and had missed git over HTTP entirely.

Fixes

  • Repository-scoped /git verbs answer once. /git secret set, /git var set|list|remove and /git repo set|unset check the repository's grant themselves and sit above the system-admin gate, but they were missing the explicit return every other arm of that match carries. After doing their work they fell through to the gate and appended "Access denied. System administrator privileges required." — an owner who was not also a system administrator got a correct answer followed by a refusal of it.

Upgrading

Self-updating servers pick 0.11.0 up on their daily check. For a manual upgrade, download the new binary (or pull the new image tag) and restart — stores, mail, and all versioned content carry over untouched. The full list of changes is in the changelog.

updates release windows ai admin git site