hostit changelog
The recent releases of hostit, newest first. Dates are the release date. Anything that changes a config default or on-disk state is called an Upgrade note.
v0.48.1 – 2026-09-28
A quieter node while someone is watching, and two small fixes.
- Even quieter while someone is watching. With the dashboard or an app page open, the node answers from its cache when the data is under 15 seconds old, so a watched node measures about every 15 seconds instead of every 5. The UI refreshes every 15 to 20 seconds, so nothing looks different.
- Clearer pool refusal. Creating an app that does not fit its owner’s memory or disk pool now says what a new app needs and how much is free.
- Fix: “Notifications failing” was listed twice in the Alerts type filter.
v0.48.0 – 2026-09-28
Alert destinations for everyone, and a much quieter node.
- Alert destinations for everyone. With
alerts.defaults: [slack, email]incontrol.yml, every active person gets a Slack direct message (the account the bot finds by their email) and an email to their own address, so their app alerts reach them without setup. They show a “Default” chip and are theirs to change or remove; a removed one is not added again, and nobody gets a duplicate of one they already made. Upgrade note: migration 64; nothing changes unlessalerts.defaultsis set. - A quieter node. Control asked every node for a fresh measurement of its apps every 2 seconds, which kept a 1-vCPU host at a load of about 3 around the clock. It now polls every 5 seconds while someone is looking at the dashboard or an app page, and every 30 seconds otherwise, answered from the node’s cache. Start and stop still show within seconds.
v0.47.0 – 2026-09-28
Alerting, password sign-in, a Settings page, and apps that can call each other through a proxy on a private network.
- Alerting. hostit watches its own health and tells the admins (a member that stopped reporting, a full disk, failing snapshots, a failing notification destination), and watches each owner’s apps and tells them (down, near its disk or memory limit, pinned at its CPU cap, a connection that needs reconnecting). Alerts live on a new Alerts page with an inbox and a 90-day history; each notification links straight to its alert, which shows the timeline and who was told. Notifications go to an ntfy topic, Slack (the instance’s bot: a channel for system alerts, a direct message for your own) or email, and a table of alert types by destination picks which kinds go where. Conditions must hold before they alert and clear before they resolve, so nothing flaps; dismissing is shared, pausing is per type. Upgrade note: new optional
smtp:andalerts:blocks incontrol.yml; Slack and email are offered only when configured. Migrations 59 to 61 and 63 add the alert tables. - Password sign-in. With
password-login: true, the sign-in page offers an email and password beside Google (or instead of it). Admins set passwords; people change theirs under Settings. Attempts are throttled per account, per address and instance-wide, and a password change signs the person out everywhere else. - Settings replaces Profile. Appearance (theme, default tabs), assistant preferences, password, notifications, SSH keys and tokens in one page; the account menu is regrouped with icons.
- Apps can reach other apps through the proxy on a private network. Proxies report their addresses and nodes allow app traffic to ports 80 and 443 there, and nowhere else in private space. Upgrade note: migration 62; an older proxy reports no addresses until upgraded.
- Fixes. App CPU figures are current, not lifetime averages; a cut-off bulk upload no longer half-overwrites a file, and an oversized one says so; uploads are limited by the app’s disk budget only; errors no longer say “invalid request” twice; a failed credential-key rotation can no longer leave secrets unreadable.
v0.46.0 – 2026-09-23
Cluster members must be approved before they get in, a revoked node stops serving, and an assistant chat can no longer wedge itself on an oversized tool result.
- Cluster members are approved, not auto-trusted. A node or proxy that dials in from another machine now lands as pending and gets no privileges until an operator approves it, in Admin -> Cluster or with
hostit-control node approve <name>. Revoking a member drops its session and is sticky: a removed machine cannot re-admit itself by reconnecting. The colocated node and proxy on the control host approve automatically, so a single-box install is unchanged. Upgrade note: every member that exists at upgrade time is approved; only members added afterwards need approval. - A revoked node stops serving its apps, over HTTP and SSH. Its routes and its SSH relay entries are withdrawn within a second, so visitors get “nothing deployed here” and the relay no longer offers a shell into its apps. Nothing on the machine is stopped or deleted, and approving the node again restores both. The Admin dialog spells this out before you confirm.
- Fix: an assistant chat could get permanently stuck with
prompt is too long. One oversized tool result (a large log tail, or a big response from a connected MCP server) could exceed the model’s context window, and because the same history was re-sent every turn, the chat then failed forever. Requests are now bounded by size: a single tool result is cut at 128 KiB and the conversation is trimmed to fit. A chat already in this state recovers on its next message. - The assistant’s hourly budget is now 180 turns per user (was 60). The cap covers both your own chats and the calls your apps make on your behalf, so an app that asks the assistant on a schedule no longer collides with you.
- Sandbox hardening. The Claude Max sandbox now aborts a turn before running anything if the runtime advertises any tool outside hostit’s own MCP tools, so a built-in tool that slips past the blocklist after a version bump cannot reach the operator’s subscription token.
- Container IPv6 is gated on the host actually having public IPv6. A v4-only host no longer gives its containers a dead v6 stack.
v0.45.0 – 2026-09-19
IPv6 support, MCP connection tools, and an assistant that keeps working when a model’s limit is reached.
- IPv6. Apps are now reachable over IPv6 and can make outbound IPv6 connections. The per-app firewall applies the same egress isolation to v6 (blocking metadata and private space) as it does to v4. Upgrade note: IPv6 is opt-in at the infrastructure level – give the host a public IPv6 address, open 443/80 for v6, and add
AAAADNS (a wildcard and/or per custom domain). With none of that in place, nothing changes. - MCP server: manage an app’s connections. The MCP server gained
connection_list,app_connection_list,app_connection_grantandapp_connection_revoke, so an assistant can see which of your connections an app may use and change them without leaving the chat;app_getnow reports an app’s granted connections inline. - The assistant falls through to the next model on a usage limit. When an app asks the model without naming one and the default model’s allowance is exhausted, hostit retries the next model in the catalog instead of failing. Naming a model explicitly still returns that model’s limit as-is.
- Fix: token-authenticated requests to a private app hung ~30s, then returned a 404. On a single-box install the per-app firewall did not admit the control plane’s own dial to the app, so bearer-authenticated requests (webhooks, scripts, the CLI) to a private app timed out. Fixed.
- Fix: a snapshot rollback could leave the app powered off if the underlying storage swap failed; it now brings the app back up on the failure path.
v0.44.0 – 2026-09-18
hostit as an MCP server: create and manage your apps from an assistant on your own machine.
- hostit is now an MCP server. Point an MCP client on your machine (Claude Code, Claude Desktop, any MCP client) at
POST /api/mcpand it gets typedapp_...tools to manage your apps end to end – create, inspect, deploy, rename, fork, start/stop, archive and delete; read and write files; run a command in the container; take, restore and delete snapshots; and set visibility, the description and custom domains. Every call runs as your account, with the same ownership and limits the dashboard enforces. Add it withclaude mcp add --transport http hostit https://<host>/api/mcp: log in once in the browser (nothing to paste, since hostit is its own OAuth authorization server and reuses your existing login), or pass an account token as a header. The token appears as “Claude (MCP)” in your Profile and is revocable there. - Delegated MCP tool lists follow the service. A delegated server’s tool list now refreshes on “Refresh now” and on the periodic sweep, so a connector or role the service adds later shows up without re-adding anything.
- Empty-page and Connections polish. The empty Apps, Chats and Explore pages share one centered look with a single call to action and no longer flash a loading state when you switch to them; in a connection’s Manage dialog the MCP tool list is bounded and scrolls, with a toggle between a detailed list and compact name chips.
v0.43.0 – 2026-09-17
Delegated connections, and a redesigned Connections page.
- Delegated connections. A new connection kind for a service that already trusts this instance to say who its users are: hostit mints each user’s token itself by RFC 8693 token exchange, as a client the service’s operator registered, with no consent screen and nothing stored. Configure it under
connections:(a token handed to apps) ormcp-servers:(a server hostit calls tools on) withauth: delegated, aclient-id/client-secret, asubject-token-type, andclient-auth(client_secret_jwtby default).auto-connect: trueprovisions it for every approved user;auto-grant: truealso grants it to their apps and chats and marks it included by default there, shown as a checked, locked toggle. The user sees “provided by your administrator”, the scopes the service granted, and a “Refresh now” button; they cannot rename or remove it. - Connections page redesign. The page is a gallery of logo tiles you click to manage. One Manage dialog now holds everything for a connection – rename, permissions (as toggles), the credential, granted scopes, MCP tools, and “Include by default in all apps and chats” – folding in the old separate edit and health-check dialogs. A card’s status dot goes amber when a service is reachable but has nothing granted or has gone unreachable, and red when it needs a reconnect or an admin. The list loads instantly even when a configured service is slow or unreachable: endpoint discovery runs in the background.
- ntfy connection: topic required, token optional. An ntfy connection asks for its topic and treats the access token as optional, since a public topic needs none.
- Welcome tour blends a custom page. A
welcome-urlpage is framed with the member’s theme, background and accent passed through, drawn flat with no border. - Chat and assistant polish. Shorter auto-generated chat titles, the composer refocuses when a turn finishes, and a calmer working-word animation.
- Upgrade note: additive schema migration (a
managedcolumn); no behaviour change for the existing connection kinds.
v0.42.0 – 2026-09-16
Node-to-node app moves for admins, capacity-aware placement, and a security fix for chat-to-app conversion.
- Move an app to another node.
hostit control app move --to <node> <name>(orPOST /api/apps/{name}/relocate) relocates an app with its files, snapshots, unix identity, keys and limits over the cluster link, no SSH; its name, URL and port do not change. The move runs in the background and the CLI follows it. A moved app lands as a copy-on-write clone of the shared base image (the base ships once per node and is retained), so a move costs the app’s own delta, not a rootfs copy. - Crash-safe moves, from an untrusted stream. A move is a durable record: control resumes it after a restart, an app mid-move is protected on both nodes from the orphan sweep, a stalled transfer is aborted, and a target without the RAM or disk headroom is refused with the numbers. The receiving node treats the stream as hostile (chrooted
btrfs receive, validated base ids, device nodes refused, byte caps), so a compromised node cannot write on another through a move. - Capacity-aware placement. A new app goes to the node that fits its limits and is least loaded across RAM, disk and CPU; creation is refused (503) when every node is out of RAM or disk instead of overcommitting one.
- Security: converting a chat to an app enforces the app limits. Converting bypassed the per-user app count and pool check and could mint standing apps past a user’s limit.
- Connections: include by default, icons, and a welcome nudge. Tick “Include by default” on a connection and every chat and app you create gets it as it is made; every provider has an icon (custom ones name one from the shipped library or drop an image next to
control.yml), drawn on chips, menus and rows;suggested: trueon a provider or MCP server offers it on the new member’s welcome tour, to connect with one click (the consent opens in a popup);welcome-urladds your own page as the tour’s last step. The Connections page is now a gallery of logo tiles with one Add connection menu. - Admin cluster view by machine, chat snapshots pruned again by retention, and assistant layout polish.
- Upgrade note: two automatic schema additions (
app.base_uuid,app_move); each node stamps its local base images once at first start (nothing to do by hand); a node keeps ~860 MB per foreign base image it holds moved-in apps for; the defaultchat-expirydropped from 30 to 14 days.
v0.41.0 – 2026-09-14
Conversations: standalone chats with the built-in assistant, separate from apps, plus an always-on app gallery and sharper admin and CLI tooling.
- A new “Chats” page. A conversation is a chat with the assistant that is not a hosted app: no port, no public URL, no SSH, no deploy. It costs almost nothing when idle (its container is built on the first turn and released between turns), and it converts into a real app in place when it outgrows a chat.
- Separate limits.
chat-limit(default 20) caps conversations per user;chat-expiry(default 30 days) auto-deletes an idle one unless it’s pinned. - Owner-only preview and file export. A chat can build pages under
public/that only its owner can see, and its files can be downloaded as an archive. - The public app gallery is always on. The “Explore” gallery (public apps whose owners chose to list them, visible only to signed-in members) no longer has an on/off switch.
- Admin and CLI. The admin “All apps” table is click-to-sort with an active/deleted/all filter;
hostit control app listandhostit node statusgained RAM, disk and kind columns,--sortand--deleted. - Snapshots take less room by default (every 6 hours, keep the last 10), and a chat’s deleted remains are reaped after a shorter grace.
- Upgrade note: two schema migrations run at first start (one recreates the app table to allow port-less chats); the app soft-delete grace dropped from 7 days to 3; the removed
app-listingsetting can be deleted fromcontrol.yml.
v0.40.0 – 2026-09-08
A security fix for app egress that had never actually worked, plus GitHub, Stripe and GitHub App connections. Upgrading is strongly recommended for any instance running untrusted apps, and required on a cloud host with a metadata service.
- App containers could reach the cloud metadata endpoint and every other app on the box; now they can’t. Per-app nftables egress rules block private space (including 169.254.169.254) by default, whitelistable narrowly.
- GitHub connections ask for only the access they need, plus a
github-appprovider for per-repository access and a Stripe provider (a pasted restricted key).
v0.39.1 – 2026-09-04
Security fixes from a review of the whole codebase. Recommended for any instance where people share or hand over apps.
- A transferred app no longer carries its previous owner’s credentials.
- Credentials are redacted before the assistant streams them.
- The screenshot sandbox no longer shares uid space with apps.
- An app can no longer exceed its memory cap through swap, and front doors no longer forward a client’s forwarding headers.
v0.39.0 – 2026-09-04
A public app gallery, a Google Drive connection, an instance default for the assistant’s model, and a substantially more reliable app preview.
- Explore gallery (opt-in per instance), Google Drive (read-only) alongside Calendar, a
default-assistant-modelsetting, and much less blank/half-rendered previews. - Upgrade note: a schema migration adds the app-listing column; the gallery stays off until an admin turns it on.
v0.38.0 – 2026-09-03
Deferred app deletion (a delete you can take back), plus assistant reliability and SSH-relay improvements.
- Soft delete: deleting an app shelves it for a grace period before it is really gone.
- Assistant turns no longer cut off at five minutes; the SSH relay can hide the node’s host so
ssh <app>@apps.example.comreaches any app on any node; Go builds work in low-memory containers.
v0.37.0 – 2026-09-02
Connections gain permission checkboxes, editable and genuinely narrowable permissions, token revocation, and richer provider configuration.
- Scope checkboxes in the add dialog; edit and narrow a connection’s permissions after the fact; removing or re-scoping a connection revokes the old token; providers can forbid a second connection on the same account.