Changelog

Bundles and checksums are on Download. Upgrade steps are in Upgrade and backup.

1.0.0

Released 2026-10-08. First production release for linux-amd64 and linux-arm64.

Release signing

  • Bundles are signed with the production release key, kid prod1. Its public key is compiled into every 1.0.0 binary. The development key dev1 is absent from release builds.
  • Key fingerprint, short form sha256:fc0ce1282a8d75e6:
sha256:fc0ce1282a8d75e6f868e8e1d3e88f514871b5ff454fe2d555e5f86352a562f3
  • install.sh prints the fingerprint during install. Compare it with the value above. Automated installs can pin it with --expect-fingerprint.
  • templassctl upgrade checks new bundles against the keys compiled into the installed controller and rejects a bundle that ships its own release-keys.json.

In this release

  • Flow detection from NetFlow, IPFIX and sFlow, IPv4 and IPv6.
  • BGP mitigation: RTBH with BLACKHOLE and NO_EXPORT, FlowSpec for IPv4 and IPv6. Tested against FRR, BIRD 2, OpenBGPD and Nokia SR Linux.
  • XDP scrub nodes, enrolled over mTLS on port 9412 with an internal CA, 90-day certificates, renewal and revocation.
  • Operator dashboard and customer panel.
  • Offline installer and templassctl: status, backup, restore, upgrade with automatic rollback, support bundle, uninstall. Optional daily backup timer.
  • Offline Ed25519 license keys. The updates date on the key gates upgrades.
  • Each bundle records its architecture. install.sh and templassctl upgrade refuse a bundle built for a different architecture than the host.

Known limits

  • arm64 builds are tested under QEMU emulation. Real arm64 hardware is untested.