Install this version

curl -fsSL https://raw.githubusercontent.com/BlkLeg/CircuitBreaker/main/install.sh | sudo bash -s -- --version 0.4.3

Or pick any method on the download page. The installer verifies every download against the release's checksums.

Downloads

x86_64 (amd64)

PackageForSizeSHA-256Signature
.debDebian, Ubuntu128 MB3b540e00babd….asc
.rpmFedora, RHEL, openSUSE128 MB47fd6eea7b05….asc
.apkAlpine129 MB5cf251aa726d….asc
AppImageAny distribution126 MB92cf7bf5d255….asc
.tar.gzManual install127 MB2e50d871c194….asc

ARM64 (aarch64)

PackageForSizeSHA-256Signature
.debDebian, Ubuntu127 MB767b879fde7f….asc
.rpmFedora, RHEL, openSUSE127 MBaacb6a9e1cdf….asc
.apkAlpine128 MBc1808be9d08a….asc
.tar.gzManual install127 MB713618a103a4….asc
Checksums, signing key, SBOMs and other files

Checksums

Release signing key

Software bills of materials

Build manifests

Install scripts

Bundled dependency packages

Changes

Fixes the defect that made 0.4.2 unusable, and closes the gap in the release pipeline that let it ship.

v0.4.2’s native binary did not contain the application. PyInstaller builds from a static import graph, and app.main was reached only through the string "app.main:app" handed to uvicorn.run, so it was silently dropped. Every release gate was green, because the only thing any of them executed was --version — which start.py resolves from an embedded file and returns on before the application is ever imported. The artifact was signed, attested, SBOM’d, scanned and version-parity-checked, and empty.

Fixed

  • The native binary contains the application again. Verified by archive inspection: 3,630 modules with app.main present, against 3,261 without it in the published 0.4.2.
  • PostgreSQL now starts on Arch. pacman’s postgresql package never creates /run/postgresql, unlike apt’s postgresql-common and the PGDG dnf packages, so the server died immediately on its socket lock file. The directory is now this project’s responsibility on every distro.
  • nginx configuration is applied on Arch. Arch’s nginx package ships neither conf.d/ nor an include for it, so the installer’s config was written to a directory that did not exist — and where the include was missing it would have been silently ignored rather than failing loudly.
  • The installer’s progress display no longer erases real output. The upgrade path’s success banner, including the URL block, was being truncated.
  • The remaining time estimate no longer reports “taking longer than expected” around three seconds into every run.
  • The pre-flight phase is written to the install log. It previously reached no file at all, so a failure there named a log that did not exist.
  • cb info and cb doctor tell a missing install identity apart from one they are not permitted to read, naming the path and suggesting sudo; the JSON output carries the unreadable path.
  • A Docker socket proxy timeout at startup is a warning, no longer fatal: the proxy only feeds opt-in container telemetry.
  • Worker services are granted the ambient capabilities they exec into, and a worker exiting no longer deletes the backend’s runtime directory.
  • The security scan distinguishes a scanner that failed from one that found something, rather than reporting an engine crash as findings.

Added

  • circuit-breaker --selftest resolves the ASGI target the way uvicorn does and imports every worker module and the migration entrypoint. It needs no database, broker or network. The build refuses to stage a binary that fails it, the release gate runs it on the installed artifact, and cb doctor exposes it to operators.
  • A redesigned install experience: seven phase headlines with durations, a themed progress bar, and elapsed and remaining time. --verbose restores the previous per-step output, and non-interactive installs get plain timestamped lines. Every detail line still reaches the install log in all three modes, and a failed install now prints a phase ledger and replays the log tail before its diagnostics.
  • cb diag bundle collects the install log, doctor output, self-test result, unit states, journal and redacted configuration into one file for reporting problems. It fails closed rather than emitting anything unredacted.
  • Release verification: the tarball is smoked, the installed package is booted and probed at /readyz, the published release is re-downloaded and verified from its own URLs, and a release-readiness checklist blocks publication.
  • The installer is now executed end to end in CI, across Ubuntu, Debian, Fedora, Arch and Rocky.
  • Non-interactive uninstall options (--purge, --keep-data, --help), covering both native and packaged installs.
  • A release dry run that exercises packaging, install, startup, authentication, upgrade and cleanup without publishing anything.

Security

  • cb diag bundle and cb doctor no longer emit credentials. Four shapes this codebase actually writes were escaping redaction: empty-userinfo URLs (redis://:password@…), driver-qualified schemes (postgresql+asyncpg://…), http(s)://user:password@…, and key names such as CB_REDIS_PASSWORD. Doctor evidence was also stored unredacted on its success path.

From the GitHub release

What’s Changed

Full Changelog: v0.4.2…v0.4.3