Skip to content

LLMKube

v0.8.2 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai apple-silicon autoscaling edge-computing gguf gpu
+12 more
self-hosted inference kubernetes llama-cpp llm local-llm metal mlx multi-gpu nvidia tgi vllm

Affected surfaces

deps

ReleasePort's take

Moderate signal
editorial:auto 1mo

Upgrade the Go toolchain to version 1.26.4 to patch standard‑library CVEs affecting the runtime dependency.

Why it matters: Patching the Go toolchain to 1.26.4 resolves critical standard‑library vulnerabilities that impact all applications using this runtime; failure to upgrade leaves a known exploitable flaw.

Summary

AI summary

Updates Bug Fixes, 0.8.2, and 2026-06-10 across a mixed release.

Changes in this release

Security Critical

Patch standard‑library CVEs by bumping Go toolchain to 1.26.4

Patch standard‑library CVEs by bumping Go toolchain to 1.26.4

Source: llm_adapter@2026-06-10

Confidence: high

Feature Medium

Add Model refreshPolicy and upstream drift detection to controller

Add Model refreshPolicy and upstream drift detection to controller

Source: llm_adapter@2026-06-10

Confidence: high

Feature Medium

Implement real accelerator availability check for Model status in controller

Implement real accelerator availability check for Model status in controller

Source: llm_adapter@2026-06-10

Confidence: high

Feature Medium

Introduce opt‑in NetworkPolicy to Foreman Helm chart

Introduce opt‑in NetworkPolicy to Foreman Helm chart

Source: llm_adapter@2026-06-10

Confidence: high

Feature Medium

Add escalation‑only reviewer emission on base NO‑GO in Foreman

Add escalation‑only reviewer emission on base NO‑GO in Foreman

Source: llm_adapter@2026-06-10

Confidence: high

Feature Medium

Implement Job execution strategy for remote‑model coder/reviewer Agents in Foreman

Implement Job execution strategy for remote‑model coder/reviewer Agents in Foreman

Source: llm_adapter@2026-06-10

Confidence: high

Feature Medium

Stabilize host‑side client proxy on a fixed port in metal‑agent

Stabilize host‑side client proxy on a fixed port in metal‑agent

Source: llm_adapter@2026-06-10

Confidence: high

Bugfix Medium

Recreate InferenceService Deployment when selector becomes immutable

Recreate InferenceService Deployment when selector becomes immutable

Source: llm_adapter@2026-06-10

Confidence: high

Bugfix Medium

Revalidate http/https model sources in controller init container

Revalidate http/https model sources in controller init container

Source: llm_adapter@2026-06-10

Confidence: high

Bugfix Medium

Detect stale FleetNodes via heartbeat window in Foreman

Detect stale FleetNodes via heartbeat window in Foreman

Source: llm_adapter@2026-06-10

Confidence: high

Bugfix Low

Harden the agent loop against false‑negative INCOMPLETE terminations in Foreman

Harden the agent loop against false‑negative INCOMPLETE terminations in Foreman

Source: granite4.1:30b@2026-06-10-audit

Confidence: low

Bugfix Low

Propagate Job-mode branch and commit SHA to AgenticTask status in Foreman

Propagate Job-mode branch and commit SHA to AgenticTask status in Foreman

Source: granite4.1:30b@2026-06-10-audit

Confidence: low

Bugfix Low

Fail closed when memory admission check cannot complete in metal‑agent

Fail closed when memory admission check cannot complete in metal‑agent

Source: granite4.1:30b@2026-06-10-audit

Confidence: low

Full changelog

0.8.2 (2026-06-10)

Features

  • controller: add Model refreshPolicy + upstream drift detection (#635) (7dc5b14)
  • controller: real accelerator availability check for Model status (#230) (#610) (f8652fd)
  • foreman: add opt-in NetworkPolicy to the Foreman Helm chart (#625) (8872b4d)
  • foreman: escalation-only reviewer emission on base NO-GO (#639) (d596ce3)
  • foreman: Job execution strategy for remote-model coder/reviewer Agents (#620) (#621) (2317ac0)
  • metal-agent: stable host-side client proxy on a fixed port (#406) (#608) (5b4ea34)

Bug Fixes

  • bump Go toolchain to 1.26.4 to patch standard-library CVEs (#626) (6d8fbb7)
  • controller: recreate InferenceService Deployment on immutable selector change (#606) (#607) (faf9151)
  • controller: revalidate http/https model sources in init container (#636) (64812e5)
  • foreman: detect stale FleetNodes via heartbeat window (#633) (515bdfe)
  • foreman: harden the agent loop against false-negative INCOMPLETE terminations (#623) (edc93e4)
  • foreman: propagate Job-mode branch + commit SHA to AgenticTask status (#634) (3586a14)
  • metal-agent: fail closed when memory admission check cannot complete (#641) (cfe53aa)

Documentation

  • roadmap: rewrite around the heterogeneous sovereign fleet thesis + milestones (#632) (d98b257)

Security Fixes

  • bump Go toolchain to 1.26.4 — patches standard‑library CVEs

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track LLMKube

Get notified when new releases ship.

Sign up free

About LLMKube

Kubernetes operator for llama.cpp-native LLM inference with GPU scheduling, Apple Silicon Metal support, and OpenAI-compatible API.

All releases →

Related context

Earlier breaking changes

  • v0.8.1 foreman: requestTimeoutSeconds now sets loop-wide budget, default changes from 600 to 3600.

Beta — feedback welcome: [email protected]