<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Spinifex changelog</title><description>A monthly summary of what shipped in Spinifex, the AWS-compatible cloud you run on your own hardware.</description><link>https://mulgadc.com/</link><language>en-au</language><atom:link href="https://mulgadc.com/changelog/rss.xml" rel="self" type="application/rss+xml"/><item><title>September 2026: Self-healing clusters and Terraform plans that stay quiet</title><link>https://mulgadc.com/changelog#2026-09</link><guid isPermaLink="true">https://mulgadc.com/changelog#2026-09</guid><description>A cluster now survives losing a node, with its state replicated everywhere and instances relaunching on their own. Instances take up to eight GPUs, object storage got a sturdier shard layout, and Terraform plans and IAM responses came into line with AWS.</description><pubDate>Mon, 28 Sep 2026 14:00:00 GMT</pubDate><content:encoded>&lt;p&gt;A cluster now survives losing a node, with its state replicated everywhere and instances relaunching on their own. Instances take up to eight GPUs, object storage got a sturdier shard layout, and Terraform plans and IAM responses came into line with AWS.&lt;/p&gt;&lt;h3&gt;Terraform and OpenTofu: applies that succeed&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;The &lt;code&gt;terraform-aws-modules/eks&lt;/code&gt; module applies clean and re-plans with no changes.&lt;/li&gt;&lt;li&gt;&lt;code&gt;ebs_block_device&lt;/code&gt; and the &lt;code&gt;aws_vpc&lt;/code&gt; data source work, and parallel applies no longer lose load balancer targets or tags.&lt;/li&gt;&lt;li&gt;Load balancer attributes are accepted in full, and a retried apply no longer duplicates the resource.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Terraform and OpenTofu: plans that report no changes&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;A no-op plan no longer destroys and recreates a working instance.&lt;/li&gt;&lt;li&gt;Permanent diffs are cleared on &lt;code&gt;user_data&lt;/code&gt;, &lt;code&gt;enclave_options&lt;/code&gt;, security group rule tags and ECS &lt;code&gt;availability_zone_rebalancing&lt;/code&gt;.&lt;/li&gt;&lt;li&gt;ECR and ECS return the fields you set at create time, and &lt;code&gt;most_recent&lt;/code&gt; picks the newest AMI.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Identity (IAM and STS): AWS conformance&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Requests and responses are tested against AWS&apos;s published API models for ten services.&lt;/li&gt;&lt;li&gt;IAM responses carry the fields AWS returns for each action, with policy documents URL-encoded as AWS does.&lt;/li&gt;&lt;li&gt;Managed policy versions, capped at five as in AWS, so editing an &lt;code&gt;aws_iam_policy&lt;/code&gt; updates it in place.&lt;/li&gt;&lt;li&gt;Trust policies evaluate conditions, and STS rejects session policies and tags instead of ignoring them.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Reliability&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Instances on a failed node relaunch on a surviving one automatically.&lt;/li&gt;&lt;li&gt;Cluster state is replicated to every node, so losing one no longer takes the cluster down.&lt;/li&gt;&lt;li&gt;Spinifex deploys on Oracle Cloud Infrastructure (OCI), in beta.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;GPU compute&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Up to eight GPUs per instance, with &lt;code&gt;g5.48xlarge&lt;/code&gt; and &lt;code&gt;p4d.24xlarge&lt;/code&gt; matching AWS&apos;s GPU counts.&lt;/li&gt;&lt;li&gt;A new &lt;code&gt;gpu.&amp;lt;count&amp;gt;x&amp;lt;vcpu&amp;gt;c&lt;/code&gt; family for smaller edge hosts, such as &lt;code&gt;gpu.8x4c&lt;/code&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Storage (S3)&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Bucket versioning, user metadata, &lt;code&gt;CopyObject&lt;/code&gt;, &lt;code&gt;UploadPartCopy&lt;/code&gt; and batch &lt;code&gt;DeleteObjects&lt;/code&gt; are available.&lt;/li&gt;&lt;li&gt;Keys with special characters are listed by their decoded name, and ETags are derived from content.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Object storage engine (Predastore)&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Shards spread evenly across nodes, so losing one no longer degrades the whole keyspace.&lt;/li&gt;&lt;li&gt;Streaming shard reads and writes with hedged repair, and ranged &lt;code&gt;GET&lt;/code&gt;s read only the stripes they touch.&lt;/li&gt;&lt;li&gt;Predastore runs standalone with systemd integration.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Networking and security&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Policy evaluation fails closed, and &lt;code&gt;sts:AssumeRole&lt;/code&gt; is gated on the caller&apos;s identity policy.&lt;/li&gt;&lt;li&gt;Auto-assigned public IPs are released on stop and reassigned on start, as in AWS.&lt;/li&gt;&lt;li&gt;Outbound SMTP to public destinations is blocked by default, matching AWS.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Releases: &lt;a href=&quot;https://github.com/mulgadc/spinifex/releases/tag/v1.21.0&quot;&gt;v1.21.0&lt;/a&gt;, &lt;a href=&quot;https://github.com/mulgadc/spinifex/releases/tag/v1.20.0&quot;&gt;v1.20.0&lt;/a&gt;, &lt;a href=&quot;https://github.com/mulgadc/spinifex/releases/tag/v1.19.0&quot;&gt;v1.19.0&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://mulgadc.com/changelog#2026-09&quot;&gt;Read this month on mulgadc.com&lt;/a&gt;&lt;/p&gt;</content:encoded><category>v1.21.0</category><category>v1.20.0</category><category>v1.19.0</category></item><item><title>August 2026: RDS arrives, and the firewall comes on by default</title><link>https://mulgadc.com/changelog#2026-08</link><guid isPermaLink="true">https://mulgadc.com/changelog#2026-08</guid><description>The largest month of the year. Managed relational databases went from nothing to two engines, TLS-by-default and drift-free Terraform in three weeks. Underneath it, the install path grew separate WAN, LAN and VPC interfaces and started arming an nftables host firewall, so the cluster&apos;s own ports stopped being reachable from anything that could route to a node.</description><pubDate>Tue, 25 Aug 2026 14:00:00 GMT</pubDate><content:encoded>&lt;p&gt;The largest month of the year. Managed relational databases went from nothing to two engines, TLS-by-default and drift-free Terraform in three weeks. Underneath it, the install path grew separate WAN, LAN and VPC interfaces and started arming an nftables host firewall, so the cluster&apos;s own ports stopped being reachable from anything that could route to a node.&lt;/p&gt;&lt;h3&gt;Databases (RDS)&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Amazon RDS is available: managed PostgreSQL and MariaDB, driven from the AWS CLI, the SDKs, or Terraform&apos;s &lt;code&gt;aws_db_instance&lt;/code&gt;, across the &lt;code&gt;db.t3&lt;/code&gt;, &lt;code&gt;db.m5&lt;/code&gt; and &lt;code&gt;db.r5&lt;/code&gt; families.&lt;/li&gt;&lt;li&gt;Every database gets a private endpoint inside your VPC, locked down by security group and never publicly addressable. Connections require TLS by default on both engines.&lt;/li&gt;&lt;li&gt;Manual snapshots, automated backups in your window, and restore-to-new-instance, with a new RDS console covering instances, subnet groups, parameter groups and snapshots.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Installation and deployment&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;WAN, LAN and VPC each get their own network interface, so public traffic, internal cluster traffic and VPC overlay traffic no longer share one NIC. A plane left without a NIC folds onto the one above it, so one-, two- and three-NIC servers install from the same model.&lt;/li&gt;&lt;li&gt;ext4 joins ZFS as a supported install layout, and the installer assigns whole drives by role so spinifex and predastore each get dedicated disks.&lt;/li&gt;&lt;li&gt;&lt;code&gt;scripts/install-node.sh&lt;/code&gt; forms a multi-node cluster over SSH in one command, and ISO-installed servers convert into a cluster rather than being reinstalled.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Security&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;A new nftables host firewall restricts cluster ports to known peers, armed by default on ISO installs and opt-in via &lt;code&gt;--firewall=on&lt;/code&gt; for package installs, so it never cuts off services already running.&lt;/li&gt;&lt;li&gt;IAM policies are evaluated against the actual resource ARNs a request names across every service, so a policy scoped to one resource no longer authorises all of them.&lt;/li&gt;&lt;li&gt;&lt;code&gt;Condition&lt;/code&gt; blocks on identity policies are enforced instead of being silently discarded.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Storage and quotas&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Erasure-coded reads are served from parity, so one node down no longer makes objects unreadable, and reads are hedged across shards so a single stalled node does not set the latency of every read.&lt;/li&gt;&lt;li&gt;Per-account service quotas cap every metered resource, with an admin surface for per-account overrides.&lt;/li&gt;&lt;li&gt;Each storage node can own its data directory, keeping a disk failure to one shard.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Kubernetes and certificates&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;HA control planes spread across distinct Availability Zones first, so a cluster survives losing an AZ.&lt;/li&gt;&lt;li&gt;Certificates issue and auto-renew from a tenant Private CA, and re-importing material re-renders every load balancer referencing that ARN.&lt;/li&gt;&lt;li&gt;Rebuilt &lt;code&gt;eks-node&lt;/code&gt; and &lt;code&gt;ecs-node&lt;/code&gt; images, including GPU variants with open-kernel NVIDIA drivers for Blackwell cards.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Releases: &lt;a href=&quot;https://github.com/mulgadc/spinifex/releases/tag/v1.18.0&quot;&gt;v1.18.0&lt;/a&gt;, &lt;a href=&quot;https://github.com/mulgadc/spinifex/releases/tag/v1.17.0&quot;&gt;v1.17.0&lt;/a&gt;, &lt;a href=&quot;https://github.com/mulgadc/spinifex/releases/tag/v1.16.0&quot;&gt;v1.16.0&lt;/a&gt;, &lt;a href=&quot;https://github.com/mulgadc/spinifex/releases/tag/v1.15.0&quot;&gt;v1.15.0&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://mulgadc.com/changelog#2026-08&quot;&gt;Read this month on mulgadc.com&lt;/a&gt;&lt;/p&gt;</content:encoded><category>v1.18.0</category><category>v1.17.0</category><category>v1.16.0</category><category>v1.15.0</category></item><item><title>July 2026: Multinode goes real: OVN clustering and HA EKS</title><link>https://mulgadc.com/changelog#2026-07</link><guid isPermaLink="true">https://mulgadc.com/changelog#2026-07</guid><description>July was when a Spinifex cluster stopped being several machines and started being one. Software-defined networking moved onto clustered OVSDB RAFT, the EKS control plane spread across hosts and learned to self-heal, and block storage began reclaiming space instead of growing forever.</description><pubDate>Mon, 27 Jul 2026 14:00:00 GMT</pubDate><content:encoded>&lt;p&gt;July was when a Spinifex cluster stopped being several machines and started being one. Software-defined networking moved onto clustered OVSDB RAFT, the EKS control plane spread across hosts and learned to self-heal, and block storage began reclaiming space instead of growing forever.&lt;/p&gt;&lt;h3&gt;Networking&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Multinode software-defined networking via OVN with clustered OVSDB RAFT, plus routed-NAT external mode with two-tier ingress for cleaner north-south traffic.&lt;/li&gt;&lt;li&gt;ALB and NLB endpoints resolve by DNS name, and EKS in-cluster DNS resolves from the VPC.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Kubernetes (EKS)&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Multinode EKS control plane: run the control plane across several hosts, with automatic recovery and continuous reconciliation after node loss.&lt;/li&gt;&lt;li&gt;Control-plane disaster recovery — snapshot etcd and restore an entire cluster from a snapshot.&lt;/li&gt;&lt;li&gt;Run GPU workloads on EKS, with NVIDIA GPUs exposed to pods through the device plugin, and NVIDIA Blackwell passthrough stable in the EKS and ECS GPU images.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Compute (EC2)&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;EC2 Launch Templates: capture reusable launch configuration and launch straight from a template, in both the API and the console.&lt;/li&gt;&lt;li&gt;EC2 Spot Instances are available, and AMIs can be created from volume snapshots and booted directly.&lt;/li&gt;&lt;li&gt;Ubuntu NVIDIA GPU node images with automatic GPU-aware AMI selection, and GPU passthrough and MIG partition state visible across the EC2, EKS and ECS console.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Resource tagging&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Full EC2 tagging — &lt;code&gt;create-tags&lt;/code&gt;, &lt;code&gt;delete-tags&lt;/code&gt; and &lt;code&gt;describe-tags&lt;/code&gt; across instances, volumes, snapshots, AMIs, key pairs, VPCs, gateways, route tables, EIPs and placement groups.&lt;/li&gt;&lt;li&gt;Tag at creation with &lt;code&gt;--tag-specifications&lt;/code&gt;, and filter &lt;code&gt;describe&lt;/code&gt; calls by &lt;code&gt;tag:&amp;lt;key&amp;gt;&lt;/code&gt;.&lt;/li&gt;&lt;li&gt;IAM tagging for users, roles, policies, instance profiles and OIDC providers, plus tag reads on load balancers, target groups and listeners.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Identity and storage&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;IAM Groups with managed and inline policies, member inheritance, and inline policies on IAM users, editable from the console.&lt;/li&gt;&lt;li&gt;Presigned S3 URLs — time-limited GET and PUT links authenticated via SigV4 query-string auth.&lt;/li&gt;&lt;li&gt;Block storage reclaims space: unreferenced chunks are garbage-collected and overlapping writes coalesced, so volume growth stays bounded. Enabled by default from v1.14.0.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Observability&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Full-stack telemetry across the platform: distributed tracing, metrics and structured logs, with per-VM guest metrics.&lt;/li&gt;&lt;li&gt;Control-plane, S3 and block-storage logs stream to Elasticsearch via an OTLP bridge.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Releases: &lt;a href=&quot;https://github.com/mulgadc/spinifex/releases/tag/v1.14.0&quot;&gt;v1.14.0&lt;/a&gt;, &lt;a href=&quot;https://github.com/mulgadc/spinifex/releases/tag/v1.13.0&quot;&gt;v1.13.0&lt;/a&gt;, &lt;a href=&quot;https://github.com/mulgadc/spinifex/releases/tag/v1.12.1&quot;&gt;v1.12.1&lt;/a&gt;, &lt;a href=&quot;https://github.com/mulgadc/spinifex/releases/tag/v1.12.0&quot;&gt;v1.12.0&lt;/a&gt;, &lt;a href=&quot;https://github.com/mulgadc/spinifex/releases/tag/v1.11.0&quot;&gt;v1.11.0&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://mulgadc.com/changelog#2026-07&quot;&gt;Read this month on mulgadc.com&lt;/a&gt;&lt;/p&gt;</content:encoded><category>v1.14.0</category><category>v1.13.0</category><category>v1.12.1</category><category>v1.12.0</category><category>v1.11.0</category></item><item><title>June 2026: Kubernetes, containers, and a registry to feed them</title><link>https://mulgadc.com/changelog#2026-06</link><guid isPermaLink="true">https://mulgadc.com/changelog#2026-06</guid><description>Managed Kubernetes landed on a K3s control plane with IAM-authenticated kubectl and IRSA, ECS followed with task definitions and services on EC2 capacity, and ECR closed the loop so workers could pull images without external DNS. Encryption at rest became the default for new installs.</description><pubDate>Mon, 29 Jun 2026 14:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Managed Kubernetes landed on a K3s control plane with IAM-authenticated kubectl and IRSA, ECS followed with task definitions and services on EC2 capacity, and ECR closed the loop so workers could pull images without external DNS. Encryption at rest became the default for new installs.&lt;/p&gt;&lt;h3&gt;Kubernetes (EKS)&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;A new AWS-compatible managed Kubernetes service on a K3s control plane: full cluster lifecycle, managed node groups whose workers auto-join on boot, and managed add-ons.&lt;/li&gt;&lt;li&gt;IAM-authenticated &lt;code&gt;kubectl&lt;/code&gt; — &lt;code&gt;aws eks get-token&lt;/code&gt; resolves to AccessEntries and access policies, with no &lt;code&gt;aws-auth&lt;/code&gt; ConfigMap. IRSA ships with a per-cluster OIDC provider and JWKS discovery.&lt;/li&gt;&lt;li&gt;Highly available control plane: three servers across distinct hosts, each cluster in its own managed VPC with private subnets and a NAT gateway for image pulls.&lt;/li&gt;&lt;li&gt;Works with stock &lt;code&gt;terraform-aws-eks&lt;/code&gt; and &lt;code&gt;eksctl&lt;/code&gt; out of the box. Persistent volumes arrive via the &lt;code&gt;aws-ebs-csi-driver&lt;/code&gt; addon, and L7 ALB Ingress via &lt;code&gt;aws-load-balancer-controller&lt;/code&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Containers (ECS)&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Amazon ECS arrives: register task definitions, run tasks, and run long-lived services on EC2 capacity.&lt;/li&gt;&lt;li&gt;Pick &lt;code&gt;awsvpc&lt;/code&gt;, &lt;code&gt;bridge&lt;/code&gt; or &lt;code&gt;host&lt;/code&gt; networking per task — &lt;code&gt;awsvpc&lt;/code&gt; gives each task its own ENI and VPC IP.&lt;/li&gt;&lt;li&gt;Services register with ELBv2 target groups, tasks assume IAM roles through the task credential endpoint, and capacity providers provision EC2 instances on demand.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Container Registry (ECR)&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;A new Elastic Container Registry: create repositories, then push and pull OCI images with &lt;code&gt;docker&lt;/code&gt;, &lt;code&gt;crane&lt;/code&gt; and &lt;code&gt;skopeo&lt;/code&gt;.&lt;/li&gt;&lt;li&gt;EKS workers pull from the internal registry without external DNS, for air-gapped clusters.&lt;/li&gt;&lt;li&gt;Lifecycle policies expire old images on a background sweep, and immutable tags stop a pushed tag being overwritten onto a different image.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Security&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;At-rest volume encryption works end-to-end and is on by default for new installs, covering encrypted boot volumes, attach and detach, &lt;code&gt;ModifyVolume&lt;/code&gt; and snapshots. CMMC Level 1 compliant.&lt;/li&gt;&lt;li&gt;Intra-AZ traffic is encrypted by default over IPsec.&lt;/li&gt;&lt;li&gt;The web console signs in with short-lived STS session credentials instead of static long-lived keys.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Compute and instance metadata&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Instances self-configure at boot from instance metadata using cloud-init&apos;s standard &lt;code&gt;Ec2&lt;/code&gt; datasource, so stock cloud images boot unmodified and one AMI serves every instance.&lt;/li&gt;&lt;li&gt;Each instance gets its own metadata endpoint at 169.254.169.254, serving identity, network and per-MAC interface metadata, with IMDSv2 reported faithfully.&lt;/li&gt;&lt;li&gt;NVIDIA MIG GPU slicing, selectable per instance via &lt;code&gt;mig.&amp;lt;profile&amp;gt;&lt;/code&gt; types, with GPU inventory in the admin UI.&lt;/li&gt;&lt;li&gt;Capacity Reservations: reserve capacity and launch instances directly into a reservation.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Load balancing&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Network Load Balancers with an L4 data plane on nginx and active per-target health checks, HTTPS listeners with TLS termination, and listener rules routing on host, path, header, method, source IP and query.&lt;/li&gt;&lt;li&gt;A new ACM-compatible service for BYO certificates, powering HTTPS listeners.&lt;/li&gt;&lt;li&gt;Hosts track real available memory and stop accepting VMs they cannot fit, ending overcommit-driven OOMs.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Releases: &lt;a href=&quot;https://github.com/mulgadc/spinifex/releases/tag/v1.10.0&quot;&gt;v1.10.0&lt;/a&gt;, &lt;a href=&quot;https://github.com/mulgadc/spinifex/releases/tag/v1.9.0&quot;&gt;v1.9.0&lt;/a&gt;, &lt;a href=&quot;https://github.com/mulgadc/spinifex/releases/tag/v1.8.0&quot;&gt;v1.8.0&lt;/a&gt;, &lt;a href=&quot;https://github.com/mulgadc/spinifex/releases/tag/v1.7.0&quot;&gt;v1.7.0&lt;/a&gt;, &lt;a href=&quot;https://github.com/mulgadc/spinifex/releases/tag/v1.6.1&quot;&gt;v1.6.1&lt;/a&gt;, &lt;a href=&quot;https://github.com/mulgadc/spinifex/releases/tag/v1.6.0&quot;&gt;v1.6.0&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://mulgadc.com/changelog#2026-06&quot;&gt;Read this month on mulgadc.com&lt;/a&gt;&lt;/p&gt;</content:encoded><category>v1.10.0</category><category>v1.9.0</category><category>v1.8.0</category><category>v1.7.0</category><category>v1.6.1</category><category>v1.6.0</category></item><item><title>May 2026: Security groups start filtering, and FIPS lands</title><link>https://mulgadc.com/changelog#2026-05</link><guid isPermaLink="true">https://mulgadc.com/changelog#2026-05</guid><description>Security group rules stopped being advisory. Ingress and egress reconcile into OVN ACLs with default-deny, which is the difference between a rule you can read back and a rule that drops a packet. FIPS 140-3 cryptography is enforced at startup across every binary, GPU passthrough gained AMD alongside NVIDIA, and a TUI installer replaced hand-assembly of a node.</description><pubDate>Mon, 25 May 2026 14:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Security group rules stopped being advisory. Ingress and egress reconcile into OVN ACLs with default-deny, which is the difference between a rule you can read back and a rule that drops a packet. FIPS 140-3 cryptography is enforced at startup across every binary, GPU passthrough gained AMD alongside NVIDIA, and a TUI installer replaced hand-assembly of a node.&lt;/p&gt;&lt;h3&gt;Security&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Security groups are enforced end-to-end: ingress and egress rules reconcile into OVN ACLs with default-deny, so they filter traffic rather than describing an intent.&lt;/li&gt;&lt;li&gt;FIPS 140-3 cryptography is enforced at startup across all binaries (Go Cryptographic Module v1.0.0, CMVP cert #5247).&lt;/li&gt;&lt;li&gt;TLS 1.3 minimum across the stack with hybrid post-quantum key exchange (X25519 + ML-KEM), and Raft cluster traffic TLS-wrapped.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Compute and GPU&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;NVIDIA VFIO GPU passthrough with auto-discovered &lt;code&gt;g5.*&lt;/code&gt; types and a driver-preinstalled Ubuntu GPU AMI, plus &lt;code&gt;spx admin gpu status|enable|disable&lt;/code&gt; with live config reload.&lt;/li&gt;&lt;li&gt;AMD support (MI350X) alongside NVIDIA, and multi-GPU instances with the new &lt;code&gt;g7e.12xlarge&lt;/code&gt;.&lt;/li&gt;&lt;li&gt;UEFI boot is supported and is the default for new instances. Rocky Linux, RHEL, Ubuntu 26.04 and Debian 13 images joined the catalog.&lt;/li&gt;&lt;li&gt;Load balancers launch via direct-boot QEMU microvm with no system AMI import — boot time dropped 12×, from 3.2 s to 264 ms.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Installation&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;A new TUI-based ISO installer with headless &lt;code&gt;autoinstall.toml&lt;/code&gt; mode, GRUB-driven disk selection, multi-NIC WAN/LAN bridge setup and a dedicated spinifex login user.&lt;/li&gt;&lt;li&gt;&lt;code&gt;spx admin init&lt;/code&gt;/&lt;code&gt;join&lt;/code&gt; splits listen from advertise addresses, provisions &lt;code&gt;br-mgmt&lt;/code&gt; over OVS, and supports formation join tokens.&lt;/li&gt;&lt;li&gt;Two-node distributed predastore mode using RS(1,1) mirroring, which previously required three nodes.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Networking and reliability&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;New tenant accounts auto-provision a default VPC and internet gateway, so &lt;code&gt;RunInstances&lt;/code&gt; works out of the box on a fresh tenant.&lt;/li&gt;&lt;li&gt;The daemon survives NATS outages, serving locally when the cluster control plane is unreachable, with local-first instance state and a read-only &lt;code&gt;/local/*&lt;/code&gt; API for operators.&lt;/li&gt;&lt;li&gt;&lt;code&gt;StartInstances&lt;/code&gt; routes back to the node that last ran the instance, where its volumes live, with automatic fallback on node-down or capacity exhaustion.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Releases: &lt;a href=&quot;https://github.com/mulgadc/spinifex/releases/tag/v1.5.0&quot;&gt;v1.5.0&lt;/a&gt;, &lt;a href=&quot;https://github.com/mulgadc/spinifex/releases/tag/v1.4.0&quot;&gt;v1.4.0&lt;/a&gt;, &lt;a href=&quot;https://github.com/mulgadc/spinifex/releases/tag/v1.3.0&quot;&gt;v1.3.0&lt;/a&gt;, &lt;a href=&quot;https://github.com/mulgadc/spinifex/releases/tag/v1.2.0&quot;&gt;v1.2.0&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://mulgadc.com/changelog#2026-05&quot;&gt;Read this month on mulgadc.com&lt;/a&gt;&lt;/p&gt;</content:encoded><category>v1.5.0</category><category>v1.4.0</category><category>v1.3.0</category><category>v1.2.0</category></item><item><title>April 2026: Hardening the perimeter after the 1.0 launch</title><link>https://mulgadc.com/changelog#2026-04</link><guid isPermaLink="true">https://mulgadc.com/changelog#2026-04</guid><description>NATS authentication became mandatory, `InsecureSkipVerify` was removed, services picked up systemd hardening directives and privilege separation, and the AWS gateway took shape as its own component. Load balancing made its first appearance.</description><pubDate>Mon, 13 Apr 2026 14:00:00 GMT</pubDate><content:encoded>&lt;p&gt;NATS authentication became mandatory, `InsecureSkipVerify` was removed, services picked up systemd hardening directives and privilege separation, and the AWS gateway took shape as its own component. Load balancing made its first appearance.&lt;/p&gt;&lt;h3&gt;Security&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;NATS authentication is enforced, &lt;code&gt;InsecureSkipVerify&lt;/code&gt; is removed, and TLS is enabled on the cluster manager API.&lt;/li&gt;&lt;li&gt;Privilege separation and systemd hardening directives across all service units.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Load balancing (ELBv2)&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;The initial ELBv2 implementation, with an attributes API, &lt;code&gt;DescribeTags&lt;/code&gt;, and a load balancer frontend.&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Platform&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;The AWS gateway (&lt;code&gt;awsgw&lt;/code&gt;) takes shape as its own component, alongside a webserver proxy and a migration framework.&lt;/li&gt;&lt;li&gt;A new nginx-ALB Terraform example with private-IP instances.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Releases: &lt;a href=&quot;https://github.com/mulgadc/spinifex/releases/tag/v1.1.0&quot;&gt;v1.1.0&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://mulgadc.com/changelog#2026-04&quot;&gt;Read this month on mulgadc.com&lt;/a&gt;&lt;/p&gt;</content:encoded><category>v1.1.0</category></item><item><title>March 2026: Spinifex 1.0 — cloud-native software, no cloud required</title><link>https://mulgadc.com/changelog#2026-03</link><guid isPermaLink="true">https://mulgadc.com/changelog#2026-03</guid><description>Spinifex 1.0 released on the 31st of March. The pitch has not changed since: replicate a hyperscale cloud environment on compute you own, so cloud-native applications and AI workloads run anywhere, independent of centralised infrastructure.</description><pubDate>Mon, 30 Mar 2026 14:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Spinifex 1.0 released on the 31st of March. The pitch has not changed since: replicate a hyperscale cloud environment on compute you own, so cloud-native applications and AI workloads run anywhere, independent of centralised infrastructure.&lt;/p&gt;&lt;h3&gt;The 1.0 release&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;The basics, working end to end: launch and terminate instances, create and attach volumes, take snapshots, put and get objects, and carve out a VPC to run it all in.&lt;/li&gt;&lt;li&gt;Install with a single command: &lt;code&gt;curl -fsSL https://install.mulgadc.com | bash&lt;/code&gt;, then &lt;code&gt;spx admin init&lt;/code&gt; and &lt;code&gt;systemctl start spinifex.target&lt;/code&gt;.&lt;/li&gt;&lt;li&gt;Point the AWS CLI at it with a profile and start making EC2 calls.&lt;/li&gt;&lt;li&gt;The first release we were happy to put a 1.0 on — enough of the surface was real that you could run something on it rather than evaluate it.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Releases: &lt;a href=&quot;https://github.com/mulgadc/spinifex/releases/tag/v1.0.0&quot;&gt;v1.0.0&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://mulgadc.com/changelog#2026-03&quot;&gt;Read this month on mulgadc.com&lt;/a&gt;&lt;/p&gt;</content:encoded><category>v1.0.0</category></item></channel></rss>