Download Latest Version 0.4.0 source code.zip (1.9 MB) Google Add to Preferred Sources
Home / 0.3.0
Name Modified Size InfoDownloads / Week
Parent folder
docker-compose-0.3.0.yml 2026-08-05 13.1 kB
sinas-0.3.0.tgz 2026-08-05 9.8 kB
0.3.0 source code.tar.gz 2026-08-05 1.3 MB
0.3.0 source code.zip 2026-08-05 1.6 MB
README.md 2026-08-05 8.1 kB
Totals: 5 Items   3.0 MB 0

Sinas 0.3.0

Connectors get OAuth 2.0, users get external identities and custom fields, and Sinas can now be deployed on Kubernetes with no Docker socket. Plus LLM cost visibility and a batch of correctness fixes.

Highlights

  • Connector OAuth 2.0 — client-credentials and per-user authorization-code grants, so connectors can call APIs that require OAuth.
  • User identities & custom fields — link external identities, exchange tokens with external auth systems, and expose per-user context to agents, functions, and queries.
  • Kubernetes deployment — a Helm chart plus a k8s_pod executor that runs untrusted code in ephemeral, hardened Pods. No Docker socket, no privileged DinD.
  • LLM cost visibility — every LLM call's token usage is recorded and surfaced on the dashboard, and Anthropic prompt caching is enabled with cache-token accounting.

Features

Connectors / OAuth (#66)

  • OAuth 2.0 client-credentials auth, with in-process token caching
  • OAuth 2.0 authorization-code (per-user) grant with PKCE
  • API-key auth in the query string (not just headers)
  • Auth auto-derived from an OpenAPI spec's securitySchemes on import
  • Console UI for OAuth setup and query-string API keys

Identity & auth (#89)

  • User identities, custom fields, and identity management APIs
  • Token-exchange endpoint for integrating external auth systems
  • Per-user context (custom fields) exposed to agents, functions, and queries
  • custom_fields returned from /auth/me
  • Console UI for custom fields and external identities

Kubernetes / deployment (#69)

  • Helm chart (charts/sinas) for a full single-namespace deployment
  • k8s_pod sandbox executor — one hardened, single-use Pod per untrusted execution (RBAC-scoped, network-isolated, no ServiceAccount token)
  • inprocess trusted executor and docker_ephemeral sandbox — enable socket-free / single-container deployments
  • Configurable sandbox Pod scheduling (nodeSelector / tolerations / affinity) and per-release worker concurrency
  • Compact deployment profile: clickhouse.enabled: false runs without ClickHouse (logging cleanly disabled), and leaner resource defaults + a documented density preset fit ~3 small instances on a 4GB node
  • CI builds multi-arch images (amd64 + arm64) for every version, release candidate, and dev, plus on-demand feature-branch builds; each release ships a version-pinned docker-compose.yml. Chart changes are lint/template-checked in CI for both profiles

LLM

  • Per-call LLM token-usage tracking, with a token-usage tile on the home dashboard (#94)
  • Anthropic prompt caching + cache-token tracking (#98)

Fixes

  • Oversized tool results are now truncated structure-aware (whole JSON elements + a machine-readable {"_truncated": true, "returned": X, "total": Y} marker) instead of a mid-JSON byte-slice that sent agents into retry loops; the context cap is configurable via TOOL_RESULT_CONTEXT_MAX_SIZE (default 100KB, was a hardcoded 10KB) (#104)
  • Agent delegation failures now report the real error instead of masking it behind a NameError (#104)
  • Eliminated delegation-slot starvation on the agent queue (#90)
  • CDC polling no longer crashes on non-text poll columns (bigint, timestamptz, uuid) — the text bookmark is now bound as text before casting to the column type (#80, thanks @aliiqbal208)
  • Connector OAuth security & correctness review: browser-session binding to prevent account-linking, token-cache isolation, robust token-expiry/refresh handling, fail-closed auth
  • Connectors no longer send a request body on GET/HEAD (some gateways rejected it)
  • Console no longer crashes rendering raw API validation errors (React [#31])

⚠️ Behavior changes — read before upgrading

From the auth hardening (#102):

  • Deleting a user now takes effect immediately. The delete used to persist nothing; it now deactivates the account, revokes all of that user's API keys and refresh tokens, and blocks every auth path. Re-creating the same email reactivates the account.
  • Login no longer reveals whether an email exists (anti-enumeration). Unknown or inactive emails get a decoy session in OTP mode (200 + a throwaway session_id) and a generic 401 in password modes. The old 403 "User not found" is gone from the login path — any client keying on that response must update.
  • Accounts with no password set now get the generic 401 instead of a "no password" hint.
  • Non-admins can now update/delete their own agents (a UUID-vs-str comparison bug previously blocked them).

Database: this release adds users.is_active (and identity/custom-field tables). Apply migrations with a standard alembic upgrade head — the backend does this automatically on start.

Upgrading

Docker images (multi-arch, amd64 + arm64): ghcr.io/sinas-platform/sinas/{backend,console,builder,executor}:0.3.0

docker-compose: download the pinned docker-compose-0.3.0.yml attached below, or from a checkout: IMAGE_TAG=0.3.0 docker compose up -d.

Kubernetes: helm upgrade --install sinas charts/sinas ... — see RELEASING.md and the Kubernetes deployment guide in the docs.

Existing docker-compose deployments are unaffected by the executor work — the defaults remain SANDBOX_EXECUTOR=docker_pool and TRUSTED_EXECUTOR=docker_shared. The k8s_pod / inprocess / docker_ephemeral executors are opt-in.


What's Changed

New Contributors

Full Changelog: https://github.com/sinas-platform/sinas/compare/0.2.0...0.3.0

Source: README.md, updated 2026-08-05