| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| Caddyfile | 2026-09-30 | 830 Bytes | |
| docker-compose-0.4.0.yml | 2026-09-30 | 14.4 kB | |
| docker-compose-lite-0.4.0.yml | 2026-09-30 | 4.5 kB | |
| docker-compose.lite.exec.yml | 2026-09-30 | 709 Bytes | |
| sinas-0.4.0.tgz | 2026-09-30 | 17.4 kB | |
| 0.4.0 source code.tar.gz | 2026-09-30 | 1.5 MB | |
| 0.4.0 source code.zip | 2026-09-30 | 1.9 MB | |
| README.md | 2026-09-30 | 16.1 kB | |
| Totals: 8 Items | 3.4 MB | 0 | |
Sinas 0.4.0 adds pipelines, a single-container deployment profile, role-scoped API keys and OIDC-compatible tokens, and brings the Anthropic integration up to date with the current Claude models. It also closes two permission gaps in API keys, so read the upgrade notes before upgrading from 0.3.
Documentation: docs.sinas.co
Highlights
- Pipelines. Unified triggers and linear, typed steps, with a steps editor in the console. Agents can call pipelines as tools.
- All-in-one lite profile. API, workers, scheduler, change data capture and the console in one container, idling at about 256 MiB including Postgres and Redis.
- Role-scoped API keys. Keys can be linked to roles, and a key's permissions are always capped by what its owner holds right now.
- Current Claude models. Per-agent effort control, native structured outputs, and fixes for parallel tool calls.
- Console at
/ui. The console now lives under/ui, so the ingress routes by path with no allowlist to maintain.
New
Pipelines and automation
- Pipelines with unified triggers and linear typed steps, schedulable, with persisted run output.
- A pipeline steps editor in the console, and pipeline tools on agents.
- Webhooks can target agents natively, with an optional raw response mode.
- Runtime discovery endpoints
GET /pipelinesandGET /queries, completing the discovery surface.
Authentication and access
- OIDC-compatible tokens. Optional RS256 signing, a
/.well-known/jwks.jsonendpoint and/userinfo, so other services can verify Sinas tokens with standard JWT libraries. - API keys linked to roles. A key can carry zero or more roles. Its effective permissions are its own grants plus its roles' permissions, capped by the owner's live permissions.
PATCH /api-keys/{id}changes a key's scope in place, and roles can be created with their permissions inline.- Packages can ship roles. They define roles but never assign them.
- Superadmin setup link. An install with no superadmin password and no SMTP no longer fails to install. On boot, the backend logs a one-time setup link for the superadmin.
Models and providers
- Per-agent effort for Anthropic models. Current Claude models think by default, and effort is the only control over how much. Set it per agent in the console or with
providerOverrides.effort. - Native structured outputs for Anthropic. Output-schema agents now use Claude's native structured outputs, which work on every current Claude model.
- Per-agent provider overrides, starting with prompt caching.
- A Gemini provider type with batch support.
- Provider-native batching for tool-less agent batches, at batch pricing.
- Cached-token reporting for OpenAI-compatible providers.
- Configurable OAuth token-response paths for connectors whose providers deviate from the standard, such as Slack.
Deployment
- The all-in-one lite profile, with a
values-lite.yamlpreset anddocker-compose.lite.yml. - External PostgreSQL, for managed databases such as Cloud SQL.
nodeSelector,tolerationsandaffinityfor every workload. Global defaults deliberately never reach the stateful datastores.- Toggles to disable code execution and the built-in database.
- Image tags now default to the chart's version, so a versioned install pulls matching images.
Console
- Light mode, with a theme toggle.
- The new Sinas logo and favicon.
Fixes
- Parallel tool calls on OpenAI, Azure and Gemini collapsed onto one id when streaming. The chat then failed on that turn and on every turn after it.
- Authentication under load. Every request wrote the same API key row and the same user row, so a single shared service key serialised all traffic. Usage timestamps are now written at most once a minute.
- Package uninstall failed once a package had been used, because of function versions and chats that still referenced it. Chats are now kept, and only their link to the removed agent is cleared.
- Keys created in the console could not execute namespaced resources such as functions. The editor now grants the path-form permission as well.
- Resumed turns that failed after tool approval or delegation now leave an error in the chat, instead of stopping silently.
- Admin password reset returned a 500 on every install that had never issued one.
- The built-in database connection can no longer be renamed or re-pointed into a broken state.
- Queue saturation is handled with bounded deferral and retry, and crash-safe slot claims in the shared worker pool.
- Numerous chart fixes, including
helm upgrade --reuse-valuesfrom older releases and datastore resource requests. - The chart now passes the configured domain to the backend. OAuth connector callbacks and public file links previously pointed at
localhoston chart deployments.
Upgrading from 0.3
| Change | What to do |
|---|---|
The console moved to /ui |
Update bookmarks and links to https://<your-domain>/ui/. Old console paths redirect. |
| API keys are capped by their owner's live permissions | A key keeps only the permissions its owner currently holds. Keys whose grants exceed their owner's roles lose the excess on upgrade. Review service keys before upgrading. |
| Creating a role no longer adds the creator as a member | Assign members explicitly. A non-admin who creates a role cannot see it unless they are added to it. |
| Output schemas on Anthropic agents | Schemas are now enforced natively. An object that allows arbitrary extra keys, such as a free-form map, is rejected with the path named. Give it explicit properties, or model it as an array of key and value objects. |
temperature has no effect on Anthropic models |
The current Anthropic SDK no longer accepts sampling parameters. Use effort to trade depth for cost instead. |
| Superadmin password | If SUPERADMIN_PASSWORD is set, it is applied on every restart, and changes made in the console are reverted. Leave it unset to manage the password in Sinas. |
Helm --reuse-values |
Prefer -f values.yaml. --reuse-values does not pick up new chart defaults. |
extraEnv workarounds |
Remove any AUTH_MODE or SUPERADMIN_PASSWORD entries you added to extraEnv before upgrading. The chart now sets these itself, and duplicate keys are rejected. |
Objects patched by hand with kubectl |
Helm will report field-manager conflicts on upgrade. Delete the patched object and let Helm recreate it. |
Known limitations
- Effort is rejected by Claude Haiku 4.5 and Sonnet 4.5. Leave it unset for agents on those models.
- Streaming chat does not yet enforce output schemas on Anthropic models, and relies on the instruction in the prompt.
What's Changed
- feat(webhooks): native agent targets and raw response mode by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/111
- feat(deploy): toggles to disable code execution and the built-in database by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/112
- fix(config): Phase-0 defects — unsafe secret matching, boot crash, lost notifications by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/113
- Pipelines: unified triggers + linear typed steps by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/114
- Console: ergonomic pipeline steps editor (Studio-reusable) by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/115
- fix(console): keep pipeline step rows inside their card by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/116
- feat(auth): OIDC-compatible token verification — RS256, JWKS, userinfo by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/117
- feat(ops): operations metering — counted ops, durable snapshots, cumulative push by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/118
- feat(connectors): configurable OAuth token-response paths (#109) by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/120
- feat(console): light mode — palette-layer theming with a UI toggle by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/122
- Remove dead get_current_user_optional dependency by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/119
- feat(batch): provider-native batch mode for tool-less agent batches by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/123
- feat(providers): cached-token reporting for OpenAI-compat + fix mid-turn system prompt loss by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/121
- fix(helm): fail fast when required secrets are empty by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/124
- fix(config): Phase-0 leftovers — component compilation, version churn, ${ENV_VAR} docs by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/125
- feat(agents): per-agent provider overrides — prompt_caching first by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/126
- fix(providers): round-trip Gemini 3 thought_signature on tool calls by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/127
- feat(providers): Gemini provider type with working batch support by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/128
- fix(providers): parse Gemini camelCase batch usage by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/129
- fix(console): connector list showed 'No Auth' for OAuth connectors by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/130
- Console: enable pipeline tools on agents by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/133
- fix(queue): defer-and-retry function jobs when the shared pool is saturated by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/134
- fix(queue): time-based saturation window (6h default, 0 = forever) by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/136
- feat(workers): configurable shared-worker memory limit by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/137
- fix(queue): crash-safe shared-pool slot claims + auto-scaling reserve by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/138
- fix(providers): Anthropic structured outputs + long-request stream fallback by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/139
- fix(pipelines): persist run output, honest run ids, schedulable pipelines by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/148
- fix(packages): secret-type variables 500 on preview/install by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/149
- fix(webhooks): partial template renders append payload instead of replacing the message by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/151
- fix(chart): compute requests for postgres/redis/pgbouncer (Autopilot cost + QoS) by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/152
- fix(chart): SMTP-less install login path + cross-namespace egress allowlist by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/153
- fix(chart): survive helm upgrade --reuse-values from pre-rc.5 values by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/154
- feat(chart): external PostgreSQL support (Cloud SQL et al.) by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/155
- feat(auth): API keys scoped by roles + live permission intersection; packages ship roles by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/156
- feat(auth): PATCH api-keys, inline role permissions, chat-without-read advisory, Retry-After by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/157
- fix(providers): migrate to anthropic SDK 1.0.0 and bound the dependency by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/158
- fix(auth): password_reset_tokens.created_at missing DB default (admin reset 500s) by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/159
- feat(chart): nodeSelector/tolerations/affinity, with StatefulSets held back from global defaults by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/160
- fix(batch): provider batches must reject agents carrying pipeline tools by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/164
- fix(chart): route /info to the backend so the console learns the auth mode by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/165
- feat(api): runtime GET /pipelines — complete the discovery surface by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/168
- feat(console): serve the console under /ui; ingress routes by namespace, not allowlist by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/169
- fix(ci): attach Caddyfile to release assets by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/170
- feat(metering): sinas.metering/v2 — Platform-issued periods via POST-only handshake (SIN-640) by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/171
- chore: drop fixtures README — contract decisions live in Jira, not the test tree by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/172
- ci: backend test suite + console build on every PR by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/173
- feat(api): runtime GET /queries — same discovery gap as pipelines by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/176
- feat(deploy): all-in-one lite profile — one sinas container instead of five by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/175
- feat(lite): cap embedded worker concurrency — enforce the per-client burst envelope by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/177
- feat(console): new Sinas logo, both themes; un-pin branding from immutable cache by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/181
- feat(console): orange logo mark with mount fade; new favicon by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/182
- feat(console): logo mark color-bounce on mount by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/183
- fix(chart): image tags default to the chart's appVersion by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/184
- fix(console): lite consoles on localhost talked to the wrong backend by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/185
- fix(console): stale-tab and silent-failure fixes around store states by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/186
- fix(console): logo bounce uses two colors only — white and brand orange by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/187
- fix(console): static orange logo, legible favicon, smaller lockup by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/188
- fix(metering): report zero immediately after rollover; diagnosable 409 rejections by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/189
- feat(auth): one-time setup link for a password-less superadmin by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/194
- fix(llm): parallel tool calls collapsed onto one id on OpenAI-style streaming by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/197
- fix: pre-GA issue sweep (#63, [#71], [#76], [#77], [#132], [#167]) by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/198
- fix(auth): stop every authenticated request contending for the same two rows by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/199
- fix(deps): pin sqlalchemy[asyncio] to the 2.0 line — 2.1 dropped greenlet by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/201
- feat(agents): per-agent effort override for Anthropic models by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/200
- feat(anthropic): native structured outputs replace forced tool use by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/203
- Release 0.4.0 by @kjeldoostra in https://github.com/sinas-platform/sinas/pull/204
Full Changelog: https://github.com/sinas-platform/sinas/compare/0.3.0...0.4.0