[{"data":1,"prerenderedAt":1423},["ShallowReactive",2],{"navigation_docs":3,"-changelog":144,"-changelog-surround":1418},[4,35,84,109,124,134,139],{"title":5,"path":6,"stem":7,"children":8,"page":34},"Get Started","\u002Fget-started","1.get-started",[9,14,19,24,29],{"title":10,"path":11,"stem":12,"icon":13},"Introduction","\u002Fget-started\u002Fintroduction","1.get-started\u002F1.introduction","i-lucide-house",{"title":15,"path":16,"stem":17,"icon":18},"Installation","\u002Fget-started\u002Finstallation","1.get-started\u002F2.installation","i-lucide-download",{"title":20,"path":21,"stem":22,"icon":23},"Quick start","\u002Fget-started\u002Fquickstart","1.get-started\u002F3.quickstart","i-lucide-rocket",{"title":25,"path":26,"stem":27,"icon":28},"Project structure","\u002Fget-started\u002Fproject-structure","1.get-started\u002F4.project-structure","i-lucide-folder-tree",{"title":30,"path":31,"stem":32,"icon":33},"Dashboard","\u002Fget-started\u002Fdashboard","1.get-started\u002F5.dashboard","i-lucide-layout-dashboard",false,{"title":36,"path":37,"stem":38,"children":39,"page":34},"Concepts","\u002Fconcepts","2.concepts",[40,45,50,55,60,65,69,74,79],{"title":41,"path":42,"stem":43,"icon":44},"Architecture","\u002Fconcepts\u002Farchitecture","2.concepts\u002F1.architecture","i-lucide-layers",{"title":46,"path":47,"stem":48,"icon":49},"Machines","\u002Fconcepts\u002Fmachines","2.concepts\u002F2.machines","i-lucide-server",{"title":51,"path":52,"stem":53,"icon":54},"Colony & users","\u002Fconcepts\u002Fcolony","2.concepts\u002F3.colony","i-lucide-users",{"title":56,"path":57,"stem":58,"icon":59},"Transport","\u002Fconcepts\u002Ftransport","2.concepts\u002F4.transport","i-lucide-network",{"title":61,"path":62,"stem":63,"icon":64},"Configuration","\u002Fconcepts\u002Fconfiguration","2.concepts\u002F5.configuration","i-lucide-settings",{"title":66,"path":67,"stem":68,"icon":23},"Deploy","\u002Fconcepts\u002Fdeploy","2.concepts\u002F6.deploy",{"title":70,"path":71,"stem":72,"icon":73},"Groups","\u002Fconcepts\u002Fgroups","2.concepts\u002F7.groups","i-lucide-boxes",{"title":75,"path":76,"stem":77,"icon":78},"Templates","\u002Fconcepts\u002Ftemplates","2.concepts\u002F8.templates","i-lucide-package-plus",{"title":80,"path":81,"stem":82,"icon":83},"Existing projects","\u002Fconcepts\u002Fexisting-projects","2.concepts\u002F9.existing-projects","i-lucide-folder-open",{"title":85,"path":86,"stem":87,"children":88,"page":34},"Remote","\u002Fremote","3.remote",[89,94,99,104],{"title":90,"path":91,"stem":92,"icon":93},"Remote machines","\u002Fremote\u002Foverview","3.remote\u002F1.overview","i-lucide-cloud",{"title":95,"path":96,"stem":97,"icon":98},"Remote deploy","\u002Fremote\u002Fdeploy","3.remote\u002F2.deploy","i-lucide-send",{"title":100,"path":101,"stem":102,"icon":103},"CI","\u002Fremote\u002Fci","3.remote\u002F3.ci","i-lucide-workflow",{"title":105,"path":106,"stem":107,"icon":108},"Tunnels","\u002Fremote\u002Ftunnel","3.remote\u002F4.tunnel","i-lucide-cable",{"title":110,"path":111,"stem":112,"children":113,"page":34},"Security","\u002Fsecurity","4.security",[114,119],{"title":115,"path":116,"stem":117,"icon":118},"Security model","\u002Fsecurity\u002Fmodel","4.security\u002F1.model","i-lucide-shield",{"title":120,"path":121,"stem":122,"icon":123},"Known issues","\u002Fsecurity\u002Fknown-issues","4.security\u002F2.known-issues","i-lucide-triangle-alert",{"title":125,"path":126,"stem":127,"children":128,"page":34},"Reference","\u002Freference","5.reference",[129],{"title":130,"path":131,"stem":132,"icon":133},"CLI reference","\u002Freference\u002Fcli","5.reference\u002F1.cli","i-lucide-terminal",{"title":135,"path":136,"stem":137,"icon":138},"Changelog","\u002Fchangelog","changelog","i-lucide-history",{"title":140,"path":141,"stem":142,"icon":143},"Communities","\u002Fcommunities","communities","i-lucide-heart-handshake",{"id":145,"title":135,"body":146,"description":1410,"extension":1411,"links":1412,"meta":1413,"navigation":1414,"path":136,"seo":1415,"stem":137,"__hash__":1417},"docs\u002Fchangelog.md",{"type":147,"value":148,"toc":1395},"minimark",[149,162,168,173,178,458,462,507,511,570,574,1040,1043,1282,1285,1360,1364,1379,1383],[150,151,152,153,157,158,161],"p",{},"Ant is pre-alpha. Every push to ",[154,155,156],"code",{},"main"," is tagged ",[154,159,160],{},"vX.Y.Z"," (a patch bump from\nthe previous release) and published to the download host.",[150,163,164],{},[165,166,167],"em",{},"No tagged releases yet.",[169,170,172],"h2",{"id":171},"unreleased","Unreleased",[174,175,177],"h3",{"id":176},"added","Added",[179,180,181,205,215,224,237,254,262,279,288,301,311,320,329,343,353,363,379,391,403,409,445],"ul",{},[182,183,184,188,189,192,193,196,197,200,201,204],"li",{},[185,186,187],"strong",{},"Rollback",": ",[154,190,191],{},"ant trail rollback [deployment] [--to RELEASE] [--steps N]","\nredeploys a previously released image without rebuilding, with optional\n",[154,194,195],{},"rollback.pre_hook"," \u002F ",[154,198,199],{},"rollback.post_hook","; ",[154,202,203],{},"rollback.keep_releases"," is the\nfallback for image retention.",[182,206,207,210,211,214],{},[185,208,209],{},"Audit log",": a tamper-evident, hash-chained log of privileged RPCs on each\nmachine, read with ",[154,212,213],{},"ant nest audit"," (rotates at 8 MiB; admin-only).",[182,216,217,188,220,223],{},[185,218,219],{},"State backup\u002Frestore",[154,221,222],{},"ant nest state export | import"," (owner-only)\nbacks up and restores a machine's roster and invites.",[182,225,226,188,229,232,233,236],{},[185,227,228],{},"Cleanup",[154,230,231],{},"ant nest doctor --cleanup"," removes client leftovers (pre-v2\nconfig backup, world-readable deploy logs, empty ",[154,234,235],{},"~\u002F.ant\u002Flocal"," trees) and,\non a machine, stored projects whose workload is gone.",[182,238,239,188,242,245,246,249,250,253],{},[185,240,241],{},"Machine decommission",[154,243,244],{},"ant nest machines decommission NAME --host … --yes","\nreverses provisioning over SSH (",[154,247,248],{},"--purge",", ",[154,251,252],{},"--keep-record",").",[182,255,256,188,258,261],{},[185,257,105],{},[154,259,260],{},"ant nest tunnel --container NAME --port P"," forwards a local\nport to a container port on a machine over iroh; the dashboard's remote\nmachine page has the same action on a running container's row (the listener\nstays on the dashboard's host).",[182,263,264,267,268,249,271,274,275,278],{},[185,265,266],{},"Secret providers",": a secret may name ",[154,269,270],{},"from: op:\u002F\u002F…",[154,272,273],{},"cmd:…",", or ",[154,276,277],{},"env:…",",\nresolved at deploy time so the value is never stored.",[182,280,281,188,284,287],{},[185,282,283],{},"Dashboard password",[154,285,286],{},"ant ui passwd"," sets the password required for a\nnon-loopback bind; a successful login issues a signed session cookie.",[182,289,290,188,293,296,297,300],{},[185,291,292],{},"Project templates",[154,294,295],{},"ant nest templates list | search | show | add | sync","\nand ",[154,298,299],{},"ant nest new",", backed by the Dokploy blueprint catalog (bundled snapshot\nplus live fetch).",[182,302,303,306,307,310],{},[185,304,305],{},"Image signing",": opt-in cosign verification via ",[154,308,309],{},"deploy.image_signing",";\nthe worker verifies on the machine before pulling and running, not just the\nlocal CLI.",[182,312,313,188,316,319],{},[185,314,315],{},"Branch-optional naming",[154,317,318],{},"naming.branch: false"," keeps one set of resources\nper project+env across branches.",[182,321,322,188,325,328],{},[185,323,324],{},"Dashboard service",[154,326,327],{},"ant ui install | status | start | stop | restart | recreate | logs | passwd | run | uninstall"," runs the console as a background\nservice (a systemd user unit on Linux, a launchd agent on macOS).",[182,330,331,334,335,338,339,342],{},[185,332,333],{},"Domains are opt-in",": ant never adds a hostname. Each\n",[154,336,337],{},"deployments.\u003Cenv>.domains"," entry names its routing target (a compose\nservice\u002Fport, a path, or a bare port) and is added with ",[154,340,341],{},"ant nest edit domain add"," or the dashboard's Domains tab.",[182,344,345,348,349,352],{},[185,346,347],{},"Group base domains",": a group carries a list of base domains; a deployment\nadds a subdomain or path, uses one as-is, or pins one with ",[154,350,351],{},"group_domain",".",[182,354,355,358,359,362],{},[185,356,357],{},"Machine-wide network",": opt in per project with\n",[154,360,361],{},"deploy.use_machine_network","; the machine's worker ensures and attaches it.",[182,364,365,188,368,371,372,296,375,378],{},[185,366,367],{},"Docker volume management",[154,369,370],{},"ant nest volume list | rm",", a ",[154,373,374],{},"GET \u002Fapi\u002Fvolumes",[154,376,377],{},"DELETE \u002Fapi\u002Fvolumes\u002F{name}"," endpoint, and a Volumes section on a machine's\ndashboard page. Volumes report whether a container mounts them.",[182,380,381,384,385,249,388,253],{},[185,382,383],{},"Colony profiles",": edit a member's name, email, or linked unix account\n(",[154,386,387],{},"ant colony users update",[154,389,390],{},"ant colony profile",[182,392,393,188,395,398,399,402],{},[185,394,90],{},[154,396,397],{},"ant-worker"," (from ",[154,400,401],{},"cmd\u002Fagent",") with per-RPC\nauthorization, signed single-use (and revocable) invites, and remote deploy\nover the iroh transport.",[182,404,405,408],{},[185,406,407],{},"Web dashboard parity",": the roster backend is shared between the CLI and the\ndashboard, so users, roles, and deploys agree in both.",[182,410,411,414,415,418,419,249,422,425,426,200,429,432,433,436,437,440,441,444],{},[185,412,413],{},"Deploy-time registry credentials",": with ",[154,416,417],{},"ANT_REGISTRY_PASSWORD"," set, the\npull credential travels with the deploy (",[154,420,421],{},"deploy.run",[154,423,424],{},"compose.apply",",\n",[154,427,428],{},"stack.apply",[154,430,431],{},"ANT_REGISTRY_USERNAME"," covers a registry-qualified ",[154,434,435],{},"--image",")\nas a short-lived worker-side ",[154,438,439],{},"DOCKER_CONFIG",", so private images need no\nstored ",[154,442,443],{},"docker login"," on the machine.",[182,446,447,188,450,453,454,457],{},[185,448,449],{},"Handover Caddyfile",[154,451,452],{},"decommission --handover"," exports\n",[154,455,456],{},"caddy\u002FCaddyfile.ant-handover"," with the routes ant programmed, so domains\nkeep resolving after the takeover.",[174,459,461],{"id":460},"changed","Changed",[179,463,464,489,495,501],{},[182,465,466,472,473,476,477,480,481,484,485,488],{},[185,467,468,471],{},[154,469,470],{},"~\u002F.ant"," layout",": a worker's state moved under ",[154,474,475],{},"~\u002F.ant\u002Fworker\u002F","\n(identity, state, audit log, remote-compose) and the managed local Caddy's\nPID under ",[154,478,479],{},"~\u002F.ant\u002Fcaddy\u002F","; a default-path worker adopts pre-existing files\non first run, and explicit ",[154,482,483],{},"--identity","\u002F",[154,486,487],{},"--state"," flags are untouched.",[182,490,491,494],{},[185,492,493],{},"Dashboard look",": the console wears the ant palette (warm paper in light,\nwarm charcoal in dark, the logo's wood amber as the single interactive\naccent); the home stat cards became one status strip, and the theme control\nfollows the applied theme, system included.",[182,496,497,500],{},[185,498,499],{},"Project page and settings",": the project header groups its actions by\nintent (environment, Build → Deploy, a joined Restart|Stop, quiet Terminal\nand settings icons, and a menu for rollback\u002Fdestroy); page tabs are one\nunderlined rail on the project, group, machine, and settings pages; and\nsettings\u002Fdetail cards share one titled section pattern.",[182,502,503,506],{},[185,504,505],{},"Machine and project details",": remote machines can be renamed from the\nmachine page; the project overview lists what each compose service runs (or\nthat it builds on deploy); volume rows use Key\u002FValue plus the container path;\nand editing an environment shows the compose file it uses, overridden or\ninherited.",[174,508,510],{"id":509},"changed-breaking","Changed (breaking)",[179,512,513,554,564],{},[182,514,515,518,519,522,523,249,526,529,530,533,534,537,538,541,542,545,546,549,550,553],{},[185,516,517],{},"CLI surface cleanup."," Machine resources moved to ",[154,520,521],{},"nest"," (",[154,524,525],{},"ant nest containers",[154,527,528],{},"ant nest volume",") and ",[154,531,532],{},"ant trail ps"," was removed; ",[154,535,536],{},"colony users promote"," became ",[154,539,540],{},"colony users update --role","; the hidden ",[154,543,544],{},"ant forage"," alias\nwas retired. Config-target flags use ",[154,547,548],{},"--target-machine"," now, so ",[154,551,552],{},"--machine","\nis routing-only and local-only commands fail fast on a remote.",[182,555,556,559,560,563],{},[185,557,558],{},"Wire shape: deploy payloads."," Deploy-path payloads are shared types on both\nsides, and ",[154,561,562],{},"route.apply"," carries a route spec (service + port) the worker\nresolves. The pre-release protocol version stays v1; upgrade the CLI and every\nworker together, since mixed versions fail closed.",[182,565,566,569],{},[185,567,568],{},"Wire shape: compose profiles."," Compose profiles and external-network\nsemantics ride on the deploy payloads.",[174,571,573],{"id":572},"fixed","Fixed",[179,575,576,582,592,602,612,624,630,654,662,668,674,680,695,708,730,744,758,764,778,787,796,806,812,832,845,851,868,877,890,922,936,951,974,980,989,995,1008,1014,1020,1030],{},[182,577,578,581],{},[185,579,580],{},"Project page environment scoping",": the environment picker scopes the\nheader status, badges, image, and Monitoring (containers, logs, disk usage on\nthat environment's machine) to the selected deployment; a remote\nenvironment reads its containers from its own machine instead of showing the\nlocal deployment's running state.",[182,583,584,587,588,591],{},[185,585,586],{},"Local container secrets."," The default local ",[154,589,590],{},"run: container"," path dropped\nprovider-resolved secrets entirely; it now passes them like the other paths.",[182,593,594,597,598,601],{},[185,595,596],{},"Cancelled deploys."," A cancelled running probe no longer leaves the app\nstopped; ",[154,599,600],{},"ContainerRunning"," errors abort the swap.",[182,603,604,607,608,611],{},[185,605,606],{},"Branch naming"," works when the project lives in a subdirectory and the\ndefault relative ",[154,609,610],{},"--config ant.yaml"," is used.",[182,613,614,522,617,484,620,623],{},[185,615,616],{},"Swap leftovers",[154,618,619],{},"-staging",[154,621,622],{},"-previous",") are removed only when their app\nlabel matches, so a colliding resource name from another app is not deleted.",[182,625,626,629],{},[185,627,628],{},"Zero-downtime ports"," preserve an explicit host IP (including loopback).",[182,631,632,188,636,249,639,642,643,646,647,649,650,653],{},[185,633,634],{},[154,635,552],{},[154,637,638],{},"trail logs",[154,640,641],{},"trail rollback",", and ",[154,644,645],{},"haul"," honor\n",[154,648,552],{},", and an explicit ",[154,651,652],{},"--machine local"," fails fast when the config\ntargets another machine.",[182,655,656,661],{},[185,657,658],{},[154,659,660],{},"nest edit"," computes env\u002Fsecret\u002Fvolume\u002Fnetwork list mutations under the\nconfig lock and stores an absolute project root for groups.",[182,663,664,667],{},[185,665,666],{},"Health checks"," with an invalid path return an error instead of panicking.",[182,669,670,673],{},[185,671,672],{},"Archive extraction"," caps the entry count.",[182,675,676,679],{},[185,677,678],{},"Provisioning"," keeps a corrupt machine identity instead of regenerating it,\nand removes the upload directory on every path.",[182,681,682,188,685,688,689,642,692,694],{},[185,683,684],{},"History and logs",[154,686,687],{},"history --clear --machine"," keeps other machines'\nentries, remote logs resolve the deployment's ",[154,690,691],{},"run:",[154,693,645],{}," records the\nmachine it built on.",[182,696,697,700,701,704,705,707],{},[185,698,699],{},"Managed Caddy"," uses the configured ",[154,702,703],{},"caddy.admin_listen",", keeps its config\nin ",[154,706,470],{},", stops a live managed process before starting another, and removes\na PID file only when it names the exiting process.",[182,709,710,713,714,717,718,721,722,725,726,729],{},[185,711,712],{},"Remote compose deploys."," ",[154,715,716],{},"deploy.files"," layers are all resolved (previously\nonly the first was shipped), ",[154,719,720],{},"deploy.profiles"," activate the same services\nremotely as locally, ",[154,723,724],{},"deploy.build_services: false"," no longer rebuilds anyway,\nand runtime secrets are no longer interpolated to empty (or baked) on the\nclient before the worker's ",[154,727,728],{},"secrets.env"," applies.",[182,731,732,735,736,739,740,743],{},[185,733,734],{},"Release ids."," A remote source build without ",[154,737,738],{},"--release"," records the minted\nimage tag, so history and ",[154,741,742],{},"rollback --to"," can address the deploy.",[182,745,746,751,752,755,756,352],{},[185,747,748],{},[154,749,750],{},"trail destroy"," no longer reports success when the container removal\nfails, and a non-path-safe ",[154,753,754],{},"app:"," value is refused instead of deleting a\ndirectory outside ",[154,757,235],{},[182,759,760,763],{},[185,761,762],{},"Caddy routes."," Local deploys validate route paths (no wildcards), path\nroutes are ordered before a host-only route, and conflict checks cover every\nhost in a match set.",[182,765,766,769,770,773,774,777],{},[185,767,768],{},"Config."," Legacy group ",[154,771,772],{},"machine:"," values are normalized during migration,\nmachine identity paths normalize their id, concurrent ",[154,775,776],{},"EditFile"," writes are\nserialized, deployment keys that normalize to the same name are rejected, a\nnewer schema version is refused instead of silently downgraded, and config\nwrites follow a symlinked config to its target.",[182,779,780,783,784,352],{},[185,781,782],{},"Machine ops."," A failed container-existence probe aborts a deploy instead of\ndeleting the live app, the stop\u002Fpark step survives a cancelled RPC, the reaper\nrestores a parked container when the canonical one exists but is not running,\nand a bad network name no longer leaks a secret env file in ",[154,785,786],{},"\u002Ftmp",[182,788,789,791,792,795],{},[185,790,187],{}," no longer fails on an unavailable build-secret provider, compose\nconfig writes restore the previous file when the secrets file cannot be\nwritten, and ",[154,793,794],{},"nest init"," quotes generated YAML values.",[182,797,798,801,802,805],{},[185,799,800],{},"Remote compose domains."," A remote compose deploy now programs its domains\nafter ",[154,803,804],{},"up"," instead of dropping them silently; a routing failure fails the\ndeploy with the stack left running.",[182,807,808,811],{},[185,809,810],{},"First-deploy health gate"," probes a first-time container (previously only\nstaged replacements were gated), and a failed first deploy removes the\nhalf-created container.",[182,813,814,817,818,484,821,824,825,484,828,831],{},[185,815,816],{},"Teardown clears routes"," on ",[154,819,820],{},"compose.down",[154,822,823],{},"containers.remove"," and local\n",[154,826,827],{},"trail down",[154,829,830],{},"destroy",", so a domain does not keep pointing at a removed app.",[182,833,834,188,837,840,841,844],{},[185,835,836],{},"Buildpacks and railpack builds work",[154,838,839],{},"pack"," no longer gets an unsupported\n",[154,842,843],{},"--label",", and provisioning starts BuildKit when railpack is installed.",[182,846,847,850],{},[185,848,849],{},"Provisioning installs the Docker Compose and buildx plugins"," when the\ndistro ships them separately; a missing plugin now fails with a clear\nmessage.",[182,852,853,856,857,484,860,863,864,867],{},[185,854,855],{},"Local Caddy listener changes",": changing ",[154,858,859],{},"caddy.http_listen",[154,861,862],{},"https_listen","\nnow reaches a running managed Caddy: the next local deploy restarts it, and\n",[154,865,866],{},"ant nest tools caddy restart"," applies it on demand. The old behavior silently\nkept the previous listeners.",[182,869,870,188,873,876],{},[185,871,872],{},"Local Caddy without a PID file",[154,874,875],{},"ant nest tools caddy stop|restart"," now\nfalls back to Caddy's admin API, so it works on a proxy started by an earlier\nant invocation (or one whose PID file was cleaned).",[182,878,879,188,882,885,886,889],{},[185,880,881],{},"Tool status",[154,883,884],{},"ant nest tools \u003Ctool> status [--json]"," reports any tool\n(installed, version, path, install hint; Docker also reports daemon\nreachability, so a down daemon is not shown as \"not installed\"). Only the one\ntool ant runs as a service, caddy, additionally gets\n",[154,887,888],{},"ant nest tools caddy restart|stop","; the builders are one-shot CLIs and the\nDocker daemon is host-managed, so they have no lifecycle verbs.",[182,891,892,188,895,249,898,901,902,905,906,909,910,913,914,917,918,921],{},[185,893,894],{},"Per-deployment target and secrets",[154,896,897],{},"trail deploy",[154,899,900],{},"trail status",", and\nthe rollback history honor a deployment's ",[154,903,904],{},"server:"," override (and ",[154,907,908],{},"trail status --machine M"," targets ",[154,911,912],{},"M","); ",[154,915,916],{},"deploy.publish"," merges per deployment; and\nediting secrets keeps each ",[154,919,920],{},"from:"," provider reference.",[182,923,924,927,928,931,932,935],{},[185,925,926],{},"Local compose secrets"," are no longer written into a ",[154,929,930],{},".ant-\u003Capp>.yml"," file\nin the project directory; the patch uses ",[154,933,934],{},"${KEY}"," placeholders and the values\npass through the compose process environment.",[182,937,938,941,942,945,946,484,948,950],{},[185,939,940],{},"Interrupted-deploy reaper"," no longer mistakes a compose service whose\n",[154,943,944],{},"container_name"," ends in ",[154,947,619],{},[154,949,622],{}," for a leftover swap container.",[182,952,953,959,960,963,964,425,967,274,970,973],{},[185,954,955,958],{},[154,956,957],{},"ant.yaml"," typos"," are refused instead of silently ignored: unknown keys\nand a newer ",[154,961,962],{},"version:"," fail the load, so a misspelled ",[154,965,966],{},"zero_downtime",[154,968,969],{},"health_check",[154,971,972],{},"image_signing"," cannot disable the feature it names.",[182,975,976,979],{},[185,977,978],{},"Zero-downtime cleanup"," runs on a detached context and reports failures as\ndeploy warnings, so a cancelled RPC cannot leave the old container holding\nthe canonical name unnoticed.",[182,981,982,985,986,988],{},[185,983,984],{},"Deploy probes"," report a failed ",[154,987,600],{}," as a probe error, abort\ncancellation promptly, and remove a container whose first-deploy health gate\nfailed.",[182,990,991,994],{},[185,992,993],{},"Docker reads"," on the worker keep a per-call timeout, so an unresponsive\ndaemon cannot pin a container, image, or volume listing RPC.",[182,996,997,1000,1001,1004,1005,1007],{},[185,998,999],{},"Service units"," escape a literal ",[154,1002,1003],{},"%"," for systemd and write units\u002Fplists\natomically; a corrupt deploy history is backed up instead of overwritten;\nmalformed legacy config values (including group entries) are reported instead\nof dropped; and unknown secret providers no longer echo the full ",[154,1006,920],{},"\nreference.",[182,1009,1010,1013],{},[185,1011,1012],{},"Remote nests in the dashboard"," no longer fail with \"Remote worker: context\ndeadline exceeded\": the dashboard shares one iroh endpoint per process\ninstead of dialing per request, remote probes get individual slices of a\nbounded page budget, and page polls never start a new request before the\nprevious one settles.",[182,1015,1016,1019],{},[185,1017,1018],{},"Last owner",": the machine's sole owner can no longer be demoted or removed\n(dashboard and daemon), and the settings page lists group scan roots next to\nthe machine's own so group-registered projects are visible.",[182,1021,1022,1025,1026,1029],{},[185,1023,1024],{},"Compose volume edits"," keep mount modes beyond ",[154,1027,1028],{},"ro"," and preserve tmpfs \u002F\noption-carrying long-syntax mounts verbatim; a volume row's Key and Value are\nmutually exclusive instead of silently dropping one.",[182,1031,1032,1035,1036,1039],{},[185,1033,1034],{},"Stack routing"," warns when a routed service publishes in ",[154,1037,1038],{},"mode: host"," on a\nmulti-node swarm, where a manager-local Caddy cannot reach the task.",[174,1041,110],{"id":1042},"security",[179,1044,1045,1055,1065,1077,1083,1089,1095,1101,1107,1113,1119,1138,1148,1161,1169,1175,1184,1209,1214,1224,1230,1246,1252,1258,1264,1270,1276],{},[182,1046,1047,1050,1051,1054],{},[185,1048,1049],{},"Dashboard CSRF over GET."," Cross-site requests to the dashboard's API are\nrejected for every method, GET included: a malicious page could otherwise\ntrigger ",[154,1052,1053],{},"GET \u002Fapi\u002Fprojects\u002F{name}\u002Fexec"," (which runs a command in a container).\nOpening the UI itself from another site (a top-level navigation) still works.",[182,1056,1057,1060,1061,1064],{},[185,1058,1059],{},"Container env passthrough."," Runtime secrets (including multi-line values)\ntravel only in the docker process environment on both local and remote\ncontainer deploys; the temporary ",[154,1062,1063],{},"--env-file"," is gone.",[182,1066,1067,1073,1074,1076],{},[185,1068,1069,1070,352],{},"Compose ",[154,1071,1072],{},"~"," The mount\u002Fread guards refuse a leading ",[154,1075,1072],{},", which compose\nexpands to the user's home directory.",[182,1078,1079,1082],{},[185,1080,1081],{},"Transport lifetimes."," Per-connection idle deadlines, tunnel first-stream\ndeadlines, and oldest-connection eviction bound connection-slot exhaustion; a\nsplit read\u002Fhandler budget stops empty streams from blocking RPC processing.",[182,1084,1085,1088],{},[185,1086,1087],{},"Caddy routes"," are serialized in-process.",[182,1090,1091,1094],{},[185,1092,1093],{},"Denial audit"," has a global per-interval cap; invite redemptions and failed\ntunnel authorizations are recorded.",[182,1096,1097,1100],{},[185,1098,1099],{},"System accounts"," derive from 12 NodeID characters; duplicate links are\nrefused.",[182,1102,1103,1106],{},[185,1104,1105],{},"Resource-name collisions"," are refused instead of replacing another app's\ncontainer.",[182,1108,1109,1112],{},[185,1110,1111],{},"Cloud-init"," escapes values for the single-quoted systemd unit.",[182,1114,1115,1118],{},[185,1116,1117],{},"Build-context extraction."," A symlink whose target traverses an earlier\nsymlink is refused, and the remote Dockerfile write removes an existing\nsymlink first, closing an arbitrary-file-write path.",[182,1120,1121,713,1124,249,1127,1130,1131,642,1134,1137],{},[185,1122,1123],{},"Compose guard.",[154,1125,1126],{},"env_file",[154,1128,1129],{},"build"," context, ",[154,1132,1133],{},"extends",[154,1135,1136],{},"include"," paths\nare checked on the worker (client-side parent-relative paths stay allowed); a\nremote apply refuses build services outright.",[182,1139,1140,1143,1144,1147],{},[185,1141,1142],{},"Local container secrets"," are passed through the docker process environment\ninstead of ",[154,1145,1146],{},"docker run -e KEY=VALUE",", so they no longer appear in argv.",[182,1149,1150,1153,1154,1157,1158,1160],{},[185,1151,1152],{},"Worker bootstrap"," uploads into a private ",[154,1155,1156],{},"mktemp -d"," directory instead of\npredictable ",[154,1159,786],{}," names a local user could pre-create.",[182,1162,1163,1168],{},[185,1164,1165],{},[154,1166,1167],{},"trail prune --volumes"," removes only the project's unused volumes, scoped\nby its compose label, and refuses to run without a project; previously it\nremoved every unused volume on the host.",[182,1170,1171,1174],{},[185,1172,1173],{},"Transport hardening."," Per-peer connection caps and a first-stream watchdog\nbound connection-slot exhaustion; the endpoint no longer hangs forever waiting\nfor a relay; an oversize error reply is truncated rather than dropped.",[182,1176,1177,1180,1181,1183],{},[185,1178,1179],{},"Managed Caddy PID file"," moved out of world-writable ",[154,1182,786],{},", and a PID file\nwith no recorded binary is never signalled.",[182,1185,1186,522,1191,249,1194,249,1197,425,1199,249,1202,1205,1206,1208],{},[185,1187,1188,1190],{},[154,1189,552],{}," on local-only trail commands",[154,1192,1193],{},"down",[154,1195,1196],{},"restart",[154,1198,830],{},[154,1200,1201],{},"env",[154,1203,1204],{},"exec",") now fails fast, and ",[154,1207,897],{}," honors it as a routing\noverride.",[182,1210,1211,1213],{},[185,1212,1093],{}," entries are rate-limited per peer+method, so an\nunauthenticated caller cannot force log rotation.",[182,1215,1216,1219,1220,1223],{},[185,1217,1218],{},"App names"," are validated at config load, and unknown ",[154,1221,1222],{},"users.remove"," ops are\nrejected instead of deleting the roster row without a plan.",[182,1225,1226,1229],{},[185,1227,1228],{},"Build-context extraction"," can no longer be redirected outside the\nextraction root by a chained symlink.",[182,1231,1232,1235,1236,1239,1240,1242,1243,1245],{},[185,1233,1234],{},"Container-deploy mounts"," refuse relative sources (they resolved against\nthe worker's working directory), ancestors of the docker socket, and compose\n",[154,1237,1238],{},"volumes_from","; the identity directory and ",[154,1241,470],{}," are protected even when\n",[154,1244,487],{}," points elsewhere.",[182,1247,1248,1251],{},[185,1249,1250],{},"Audit log flooding"," is bounded: details are capped, unauthenticated\nrequest bodies are not logged, oversized lines are skipped on read, and two\nrotated segments are kept.",[182,1253,1254,1257],{},[185,1255,1256],{},"Route upstreams"," are verified against the named container's published\nports, so a deploy cannot route the Caddy admin API or another local listener.",[182,1259,1260,1263],{},[185,1261,1262],{},"Role changes"," are re-checked against the state being mutated, closing the\nwindow where a demoted caller finished an in-flight privileged call.",[182,1265,1266,1269],{},[185,1267,1268],{},"Worker stream budgets"," stop a stalled or trickled request and bound every\ncall's duration, so a hung command cannot pin a handler slot.",[182,1271,1272,1275],{},[185,1273,1274],{},"Mount-path resolution"," fails closed: a bind source that cannot be resolved\n(an untraversable parent, a symlink loop) is refused, since the root-owned\ndocker daemon would follow it.",[182,1277,1278,1281],{},[185,1279,1280],{},"Invite revocation"," re-resolves the caller's role under the write lock, so\na demoted member cannot finish an in-flight revoke with its stale role.",[174,1283,461],{"id":1284},"changed-1",[179,1286,1287,1293,1312,1324,1348,1354],{},[182,1288,1289,1292],{},[185,1290,1291],{},"Caddy is required on a remote nest"," (optional locally); a worker with no\nreachable Caddy still starts (logging a warning) but refuses deploys until\nCaddy answers.",[182,1294,1295,188,1298,249,1301,642,1304,1307,1308,1311],{},[185,1296,1297],{},"Config schema v2",[154,1299,1300],{},"project_dirs",[154,1302,1303],{},"groups",[154,1305,1306],{},"caddy"," nest under\n",[154,1309,1310],{},"machines.\u003Cid>","; v1 configs migrate on load.",[182,1313,1314,1317,1318,1321,1322,253],{},[185,1315,1316],{},"Resource naming",": resources are named ",[154,1319,1320],{},"[\u003Cgroup>-]\u003Capp>-\u003Cenv>[-\u003Cbranch>]","\nfrom one rule (branch can be dropped with ",[154,1323,318],{},[182,1325,1326,188,1329,1332,1333,1336,1337,1340,1341,1344,1345,352],{},[185,1327,1328],{},"Machine resources moved",[154,1330,1331],{},"containers"," and ",[154,1334,1335],{},"volume"," live under ",[154,1338,1339],{},"ant nest",";\n",[154,1342,1343],{},"ant nest deploy"," is now ",[154,1346,1347],{},"ant trail deploy --image",[182,1349,1350,1353],{},[185,1351,1352],{},"Mount guard",": deploys that reach the worker's identity\u002Fstate (including its\nancestors), the docker socket, or the host root are refused.",[182,1355,1356,1359],{},[185,1357,1358],{},"Log color",": CLI and dashboard logs share one heuristic: errors red, warns\namber, success emerald, steps cyan, debug gray.",[174,1361,1363],{"id":1362},"removed","Removed",[179,1365,1366],{},[182,1367,1368,1374,1375,1378],{},[185,1369,1370,1371],{},"Project-wide ",[154,1372,1373],{},"expose",": routing lives per deployment under ",[154,1376,1377],{},"domains:",", so\neach hostname is paired with what it forwards to.",[169,1380,1382],{"id":1381},"pre-alpha","Pre-alpha",[150,1384,1385,1386,1390,1391,1394],{},"See the ",[1387,1388,1389],"a",{"href":16},"installation guide"," for release tarballs,\n",[154,1392,1393],{},"checksums.sha256",", and the rolling main build.",{"title":1396,"searchDepth":1397,"depth":1397,"links":1398},"",2,[1399,1409],{"id":171,"depth":1397,"text":172,"children":1400},[1401,1403,1404,1405,1406,1407,1408],{"id":176,"depth":1402,"text":177},3,{"id":460,"depth":1402,"text":461},{"id":509,"depth":1402,"text":510},{"id":572,"depth":1402,"text":573},{"id":1042,"depth":1402,"text":110},{"id":1284,"depth":1402,"text":461},{"id":1362,"depth":1402,"text":1363},{"id":1381,"depth":1397,"text":1382},"Notable changes to Ant.","md",null,{},{"icon":138},{"title":135,"description":1416},"Release notes for Ant.","jtzpdr55jL8gPfuDBAWd1wbxImCvdgCNLQ1JC1afSwE",[1419,1421],{"title":130,"path":131,"stem":132,"description":1420,"icon":133,"children":-1},"Every command group, global flag, and the common flows.",{"title":140,"path":141,"stem":142,"description":1422,"icon":143,"children":-1},"Where to find Ant, ask questions, and follow along.",1791494554236]