- Plane with OIDC users, projects and VDCs with per-VDC roles, SSH key vault, Cloudflare exposure, TLS certificates, and a gateway that forwards allowlisted calls to core with the VDC as tenant_id.
- Also added docker compose for setups
A packaged worker binary and node docker-compose for hardware we don't own, authenticated only with its host secret.
Added build scripts for the binary and NSController image, uninstaller.
- Give each NIC its own guest PCI slot; a shared 0x05 default made libvirt reject VMs with more than one network
- VM reconcile no longer treats a domain as orphaned when its assigned host row is the same physical machine
- Pin a workload to one host, which a community lease needs
- A VM's networks, volumes, ports, metadata and GPUs are created once and reused on every retry.
Workloads, Network, Volume, Pod, Server group usees tenant_id for isolation with region_id for placement.
DNS zones and worker DNS paths are tenant-scoped and rooted at BASE_DOMAIN.
Universes, projects, VDCs, region access, permissions, SSH keys, Cloudflare and TLS certificates are product concerns and moves to the cloud/community plane.
Core keeps only infrastructure.
- Move app/, worker/, websocket_server/, migrations/, tests and the services to core/, which becomes a self-contained root
- .gitmodules path for the novnc submodule rewritten by git mv.
- Initial Step to split into core and cloud/community
The management panel for cloud (backend/hyperscale/community) will be handled seperatly via React/Typescript frontend (Secured and More convinient).
Cleaning the repo!
- User can now add zerotier id during vm creation which will add the node to zerotier via cloud-config
- VM creation supports population of user-data cloud-config
Move Libvirt VM creation entirely into the worker thread instead of instantiating it on the main thread, preventing ping-pong responses to/from the master from being blocked.
Previously ns controller pod injected by XCF_DEFAULT_OVS_BRIDGE making it ovs-bridge and not attaching docker bridge.
Added DNS (Essential for cloudflared side container)
Flasgger uses find('---') substring search to detect YAML in docstrings.
Numpy-style section underlines (-------, -----------, etc.) inside route
handler docstrings were triggering YAML parsing on plain English text,
crashing the spec view with a TypeError on every request to /apispec.json.
Added watchdog for celery in dev mode to apply changes
Fix Overwritten of worker settings. Priority keys over .env overwrites
Chore: Script fixes of master,worker