Elestio Release Notes
18 release notes curated from 83 sources by the Releasebot Team. Last updated: Jul 20, 2026
- Jul 19, 2026
- Date parsed from source:Jul 19, 2026
- First seen by Releasebot:Jul 20, 2026
Elestio Catalog Updates: 26 New Releases This Week (July 12-18, 2026)
Elestio ships a busy weekly catalog update with 26 stable releases across identity, databases, AI, dev tools, and apps, led by Gitea security hardening, NocoDB Calendar Sync, and Chatwoot help center upgrades.
Another busy week across the Elestio catalog. Twenty-six stable releases landed between July 12 and 18, with a heavy run of identity and database updates, a fresh Ghost, and a major Paperless-ngx beta on the horizon. Here's everything worth updating for, grouped by category.
Security note
Gitea 1.27.0 ships several security hardening fixes this week, including stricter public-only token scopes, hardened access checks, and proof-of-possession requirements for cross-repo objects. If you self-host Gitea, treat this as a priority update rather than a routine one.
Databases
- InfluxDB v3.10.3 (July 15): Point release for the 3.x time-series engine with bug fixes and stability improvements.
- Milvus 2.6.20 (July 15): Maintenance release for the vector database, with fixes across the query and index paths.
- Weaviate v1.38.5 (July 16): LSM store performance improvements, a fix for potential deadlocks in batch vectorization, and a leaner reference cacher. Backports also landed for the 1.37 and 1.36 lines.
- TimescaleDB 2.28.3 (July 16): Patch release for the Postgres time-series extension.
AI/GPU
- Ollama v0.32.1 (July 16): Follows the 0.32.0 feature release with fixes for model loading and runtime stability.
- Dify v1.16.0 (July 17): New minor release for the LLM app platform, continuing work on workflows and the plugin ecosystem.
- Langflow v1.11.0 (July 17): Feature release for the visual agent builder, arriving alongside a 1.10.3 security fix that isolates serve request logs.
Development
- Gitea 1.27.0 (July 13): Owner-level and global scoped Actions workflows, the security hardening noted above, plus token introspection and an OpenAPI 3.0 spec.
- n8n 2.31.3 (July 17): The automation platform kept up its rapid cadence, shipping patches across both the 2.x and 1.x lines through the week.
- Strapi v5.50.2 (July 15): Patch release for the headless CMS with bug fixes and dependency updates.
- NocoDB 2026.07.0 (July 14): Calendar Sync pulls Google, Outlook, or CalDAV events into a read-only table, plus image annotations and a new comment-based workflow trigger.
- Directus v12.1.1 (July 13): The 12.1 line brings fixes and refinements on top of the 12.0 major, landing several point releases in a single day.
- Authentik 2026.5.5 (July 15): Maintenance releases across the 2026.5 and 2026.2 lines for the identity provider.
- PocketBase v0.39.7 (July 16): Patch release for the single-binary backend, with a matching 0.22 backport.
- Zitadel v4.16.1 (July 17): Fixes for the cloud-native identity platform across the 4.x and 3.x lines.
- Qdrant v1.18.3 (July 17): Patch release for the vector search engine.
- Budibase 3.39.31 (July 15): Two point releases for the low-code app builder with bug fixes.
Hosting & Infrastructure
- Portainer 2.39.5 LTS (July 13): LTS maintenance release for the container management UI.
- VictoriaMetrics v1.147.0 (July 16): New minor for the time-series database and monitoring stack, following 1.146.0 earlier in the week.
- SigNoz v0.133.0 (July 15): Fresh release for the OpenTelemetry-native observability platform.
Applications
- Ghost v6.53.0 (July 17): Latest weekly release for the publishing platform (yes, this blog runs on it).
- Immich v3.0.3 (July 15): Point release settling the big 3.0 line, which brought Workflows, HLS transcoding, a rebuilt mobile editor, and integrity reports.
- Mattermost v11.9.0 (July 16): Feature release for the team messaging platform, alongside security-focused patch releases across older supported lines.
- Metabase v0.63.1.2 (July 17): Patch releases across the 0.63, 0.62, and 0.61 lines for the BI tool.
- Chatwoot v4.16.0 (July 18): Help Center staged edits and reordering, report drilldowns, and an Intercom import workflow. Note the video-call integration moved from Dyte to Cloudflare RealtimeKit, so existing setups need reconfiguring.
- ERPNext v16.28.0 (July 15): Feature and fix releases across the 16.x and 15.x lines of the ERP suite.
What stood out this week
NocoDB's Calendar Sync is the most genuinely new feature of the week. Pulling Google, Outlook, or CalDAV events into a live read-only table turns NocoDB into a place where scheduling data and your own records finally sit side by side, without a brittle Zapier chain in between.
Gitea 1.27.0 matters for two reasons: the security hardening is not optional given the rough month self-hosted Git has had, and owner-level scoped Actions workflows are a real quality-of-life win for anyone running CI on their own instance.
Chatwoot 4.16.0 is worth a careful read before you upgrade. The Help Center improvements are great, but the video-call backend swapping from Dyte to Cloudflare RealtimeKit means you'll need to reconfigure calls, so don't run this one blind on a Friday.
And keep an eye on the horizon: Paperless-ngx tagged a 3.0.0 beta on July 18. It's not production-ready yet, but a major version of one of the most-loved document management tools is worth watching over the coming weeks.
Every service above is available as a fully managed, one-click deployment on Elestio, with backups, SSL, and updates handled for you. Browse the full catalog at elest.io/fully-managed-services.
Thanks for reading ❤️ See you next Sunday 👋
Original source - Jul 12, 2026
- Date parsed from source:Jul 12, 2026
- First seen by Releasebot:Jul 13, 2026
Elestio Catalog Updates: 12 New Releases This Week (July 5-11, 2026)
Elestio ships a busy week of catalog updates with stronger security, better observability, and faster search. Highlights include Keycloak’s SCIM preview, SigNoz’s dashboard overhaul, Meilisearch’s synonym performance boost, and fresh releases for Immich, n8n, Langflow, and VictoriaMetrics.
Another busy week across the catalog. Twelve services in the Elestio catalog shipped new versions between July 5 and July 11, and this batch leans heavily toward security hardening and observability. Keycloak added a preview SCIM API, SigNoz pushed a big dashboard overhaul, and Immich kept its rapid v3 cadence going. Here is everything worth knowing, grouped by category.
Databases
ClickHouse v25.8.28.1-lts (July 5): A new long-term-support build in the 25.8 line, published across 52 distribution assets covering AMD64 and ARM64 as archives, RPM, and DEB packages. If you run ClickHouse in production, the LTS track is the one to pin to for predictable maintenance.
AI / GPU
Langflow v1.10.2 (July 7): This one is security-forward. It adds global variable model overrides so you can swap models across flows in one place, and it hardens the code-execution path by blocking public builds of code-execution agents and restricting MCP stdio access. Python 3.14 compatibility landed too.
Development
Keycloak 26.7.0 (July 9): The headline is a preview SCIM API for automated user provisioning and deprovisioning with standard tooling. It also ships a simplified multi-cluster HA setup that drops the external cache requirement (preview), step-up authentication for SAML clients, and cleaner reverse-proxy blueprints for HAProxy and Traefik.
n8n 2.29.10 (July 10): Capping a steady week of releases (2.29.7 through 2.29.10), this stream focused on reliability: AI Agent and Code node fixes when workflows contain AI tools, safer expression handling, and Postgres-only connection recovery. Boring in the best way.
Meilisearch v1.49.0 (July 6): Reworked synonym storage with lazy loading delivers up to a 13x performance gain depending on how many synonyms you run. If your search config leans on large synonym lists, this is a free speedup.
PocketBase v0.39.6 (July 8): Adds Cc and Bcc recipients to the dev sendmail command, hardens the Microsoft OAuth2 provider with safer email extraction, and bumps the minimum Go version to 1.26.5 along with a WeakMap regression fix.
Hosting & Infrastructure
SigNoz v0.132.2 (July 8-10): A three-release sprint (v0.132.0 to v0.132.2) that overhauls dashboards. You get v2 Perses-spec public dashboards, dashboard variables with dynamic panel substitution, a new Kubernetes container monitoring API, and reworked trace details with a width-driven layout and shared metadata. The observability crowd should upgrade.
VictoriaMetrics v1.147.0 (July 6): Security and efficiency in one release. vmauth now adds a 2-3 second delay on failed auth attempts per OWASP guidance to blunt brute-force attacks, vmagent cuts CPU usage by roughly 10% for remote-storage sharding, and stream aggregation handling for out-of-order samples improved.
Applications
Immich v3.0.2 (July 9): The photo-management juggernaut keeps moving. This patch adds HLS variant configuration for more flexible video streaming, a date-based filter for the Workflows automation system, and 24-plus bug fixes covering mobile video playback, OAuth account linking, and search visibility.
Mattermost v11.9.0 (July 8): A fresh stable minor release following three release candidates, arriving right after the v11.8.3 bug-fix patch on July 6. If you self-host team chat, this is the current stable to target.
Metabase 61.7 (July 9): A stable maintenance release on the 61 line, shipped alongside a 60.12 patch for older deployments and a 63.0-beta for anyone who likes living on the edge (not in production, please).
Ghost v6.52.1 (July 10): The v6.52 line adds tax ID collection to Stripe checkout when automatic tax is enabled, retires the outdated Tenor GIF provider, and fixes mobile display plus color-accessibility issues. The v6.52.1 patch cleaned up link selection in the automations email editor.
What stood out this week
A few releases are worth more than a line:
- Keycloak's SCIM preview is the big one for anyone managing identity at scale. Automated provisioning and deprovisioning through a standard API is the feature enterprises keep asking for, and the simplified HA path is a nice bonus for multi-region setups.
- SigNoz's dashboard overhaul signals it is serious about being a real Grafana-adjacent observability platform, not just a tracing tool. Public v2 dashboards and Kubernetes container monitoring close real gaps.
- Meilisearch's 13x synonym speedup is the kind of quiet performance win you get for free just by upgrading. No config changes, just faster search.
- Langflow and VictoriaMetrics both shipped security hardening this week (agent code-execution restrictions and OWASP brute-force delays, respectively). A good reminder that "upgrade regularly" is itself a security practice.
Every one of these runs on Elestio as a fully managed, one-click deployment with automated backups and updates. Browse the full Elestio catalog to spin one up, or if you already run these, your managed instances will pick up the new versions on the standard update cycle.
Thanks for reading ❤️ See you next week 👋
Original source All of your release notes in one feed
Join Releasebot and get updates from Elestio and hundreds of other software products.
- Jul 5, 2026
- Date parsed from source:Jul 5, 2026
- First seen by Releasebot:Jul 6, 2026
Elestio Catalog Updates: 9 New Releases This Week (June 29 - July 5, 2026)
Elestio highlights a busy weekly release roundup with Immich v3, Ollama speed boosts for Gemma 4 on Apple Silicon, and notable security and feature updates across Directus, Open WebUI, Appwrite, Grafana, n8n, ClickHouse, and Rocket.Chat.
A quieter week than the last, but a meaningful one. Immich shipped its long-awaited v3, Ollama made Gemma 4 dramatically faster on Apple Silicon, and a handful of developer platforms landed security hardening worth applying. Here's everything that shipped across the Elestio catalog from June 29 to July 5, 2026.
Security Notes
No headline CVE numbers this week, but three releases carry security fixes you shouldn't sit on:
- Directus 12.1.1 hardened its GraphQL layer (single-use sensitive mutations), removed the hash utility endpoints, and moved to distroless Docker images.
- Open WebUI 0.10.2 ships access-control and security improvements; prioritize this one on production instances.
- Rocket.Chat 8.6.0 bundles security, authentication, and data-protection changes.
If you run any of these, upgrade sooner rather than later.
Databases
ClickHouse 26.5.5.8-stable and 25.8.25.37-lts (June 30 to July 1) - Two branch releases this week: a fresh stable in the 26.5 line and a long-term-support build in the 25.8 line for teams that stay on LTS. Both ship the usual signed packages across amd64 and arm64. If you value stability over new features, the LTS bump is the one to track.
AI / GPU
Ollama 0.31.1 (June 30) - The headline is speed: Gemma 4 now runs nearly 90% faster on Apple Silicon thanks to multi-token prediction and a new small-batch matmul kernel in the MLX engine. The bundled llama.cpp engine was also bumped. If you self-host Gemma 4 on Mac hardware, this is a free performance win.
Open WebUI 0.10.2 (July 1) - Reasoning models now stream their thinking content live and render it correctly in the chat overview and exported conversations. Dragging a folder into a knowledge base finally preserves the subfolder structure instead of flattening everything. Plus the security fixes noted above.
Development
n8n 2.28.6 (July 3) - A stability-focused week for n8n. This build fixes duplicate zod instances that were breaking npm installs, cleans up parameter input alignment in the editor, and stops duplicate AI Gateway notices from appearing. Several pre-release 2.29.x builds are also in flight if you like living on the edge.
Directus 12.1.1 (July 1) - Beyond the security hardening, this release adds a PROJECT_OWNER_ENABLED option, updates Vite to 8.1.2 across app and API, and ships distroless Docker image variants. A small but sensible maintenance release for a fast-moving headless CMS.
Appwrite 1.9.5 (July 1) - A big one for the backend-as-a-service crowd. Public APIs now cover project variables, keys, SMTP, auth methods, platforms, and OAuth2 providers. The database layer gains BigInt support and JSON import/export for DocumentsDB and VectorsDB, and auth picks up disposable-email blocking, password policies, and impersonation support.
Hosting & Infrastructure
Grafana 13.1.0 (July 1) - Annotations clustering reached general availability, so busy dashboards stop drowning in overlapping markers. Alerting gained Rules API v2 support in the panel alert rule drawer, and JWT auth now accepts inline public keys. A solid feature release on the heels of last week's security patch.
Applications
Immich 3.0.0 and 3.0.1 (July 2) - The big one. Immich v3.0.0 landed with non-destructive mobile editing, a workflows preview, and improved background backup. The same-day v3.0.1 patch quickly fixed a bug where albums weren't showing up in the mobile app and added a recently-added link to the web sidebar. If you self-host your photos, this is the most significant update in months, though as always, wait for your backup to complete before jumping on a brand-new major.
Rocket.Chat 8.6.0 (July 3) - A security-and-compliance release with authentication changes and data-protection improvements, supported through January 2027. Worth planning an upgrade for any team running Rocket.Chat in a regulated environment.
What Stood Out This Week
Immich v3 is the obvious standout. Non-destructive mobile editing and workflows push it further into "genuinely better than the SaaS it replaces" territory, and the fact that v3.0.1 followed v3.0.0 within hours shows a team that watches its release channel closely.
Ollama's Gemma 4 speedup is quietly huge for anyone running local models on Mac hardware. A ~90% throughput jump from an engine-level optimization, with zero changes to your setup, is exactly the kind of free win self-hosters love.
Appwrite 1.9.5 meaningfully expands what you can automate through its public APIs, which matters if you're building agents or infrastructure-as-code around it. Combined with Grafana 13.1.0's annotations clustering going GA, it was a good week for developer-facing polish.
Deploy Any of These on Elestio
Every service above is available as a fully-managed, one-click deployment on Elestio, with automated backups, SSL, and updates handled for you. Browse the full catalog of 400+ open-source services at elest.io and have the latest version running in minutes.
Thanks for reading ❤️ See you next week 👋
Original source - Jul 3, 2026
- Date parsed from source:Jul 3, 2026
- First seen by Releasebot:Jul 4, 2026
Self-Hosted Weekly: Week 27, 2026. TrueNAS 26, Grafana RCE, Gemma 4
Elestio rounds up a week of self-hosted and AI infrastructure updates, from TrueNAS 26’s container and GPU support to critical Grafana and PostgreSQL fixes, plus Gemma 4, Docker Desktop model tooling, and Immich release candidates.
Another week, another reminder that "self-hosted" and "AI agents" are quietly becoming the same conversation. This week gave us a homelab NAS that keeps eating Proxmox's lunch, two security patches you should apply before the weekend, a fresh batch of open models you can actually run yourself, and an acquisition that says a lot about where infrastructure is heading. Let's get into it.
1. TrueNAS 26 keeps closing the gap on Proxmox
TrueNAS 26 is no longer just a storage box. LXC containers, experimental for a while, are now fully supported, and you can pass NVIDIA (and other) GPUs straight into a container from the config screen. Add the shift to an annual release cadence with plain version numbers instead of fish-themed code names, and it's starting to look like a serious homelab hypervisor.
Hot take: It still isn't Proxmox, and the VM tooling has some catching up to do. But for anyone who wants storage, containers, and a couple of VMs on one box without running two platforms, the "just use TrueNAS" argument gets stronger every release. The GPU-into-LXC bit is the sleeper feature: that's local AI inference on your NAS.
2. Grafana patches a critical RCE. Patch now.
Grafana shipped a critical fix for CVE-2026-27876, a 9.1 CVSS remote code execution in SQL expressions. If the sqlExpressions feature toggle is on, an attacker who can run data source queries can overwrite a driver or write a data source config file and get full RCE. A second flaw, CVE-2026-27880 (7.5), lets an unauthenticated attacker crash the server through unbounded requests to the OpenFeature endpoints.
Hot take: "Monitoring dashboard" and "remote code execution" are two phrases you never want in the same sentence, because Grafana usually sits deep inside your network with credentials to everything. Update to the patched releases today. If you run managed Grafana on Elestio, the update path is one click.
3. PostgreSQL closes eleven security holes
The coordinated PostgreSQL update (18.4, 17.10, 16.14, 15.18, 14.23) fixes eleven vulnerabilities, several rated CVSS 8.8: an integer underflow leading to memory corruption, a symlink-following bug in pg_basebackup and pg_rewind, a stack buffer overflow allowing arbitrary code execution, and a SQL injection path.
Hot take: Postgres is the database half the self-hosted world runs on, so this one is quietly the biggest patch of the week. The scary part isn't the RCE, it's the pg_basebackup symlink bug, because that's your backup tooling. Schedule the minor-version bump. Postgres point releases are boringly reliable, which is exactly why people put off applying them.
4. Google's Gemma 4 lands under Apache 2.0
Google DeepMind released Gemma 4, a family of open models (from small on-device sizes up to a 31B dense and a 26B mixture-of-experts) built for reasoning and agentic workflows, all under the permissive Apache 2.0 license. Permissive means commercial use, derivatives, and redistribution are explicitly fine.
Hot take: The interesting story isn't the benchmark chart, it's the license. Apache 2.0 on a capable model means you can pull it into Ollama, run it on your own VM, and build a product on top without a lawyer in the room. That's the whole pitch for self-hosted AI: your model, your hardware, your rules, no per-token meter running.
5. OpenAI absorbs Ona, the startup formerly known as Gitpod
OpenAI is acquiring Ona, the German company that used to be Gitpod, the open-source cloud development environment more than 750,000 developers once used. Ona had already pivoted from browser IDEs to secure, long-running cloud environments for AI agents, and that infrastructure is what Codex is buying: somewhere for an agent to run uninterrupted for hours inside enterprise cloud.
Hot take: This is the clearest signal yet that "sandbox where an agent can safely run for a long time" is the infrastructure everyone actually wants. It's also a small eulogy for the open-source CDE dream. The lesson for self-hosters isn't to mourn, it's to notice what's valuable: an isolated, persistent place to run untrusted agent code. You can build that yourself, and you probably should.
6. Docker Desktop leans hard into MCP and local models
The latest Docker Desktop updates add MCP profile template cards and an onboarding tour, let you filter logs by Compose stack, and extend Model Runner with support for Qwen3.5. Docker is clearly positioning itself as the place where you wire local models and MCP servers into your dev loop.
Hot take: Two years ago Docker was fighting to stay relevant. Now it's shipping first-class MCP and local-model tooling faster than most AI-native startups. If you've been running models in a random Python venv, the Compose-plus-Model-Runner path is worth a look, because reproducible AI environments are the thing everyone forgets they need until a teammate can't reproduce a result.
7. Immich v3 moves into release candidates
Immich, the self-hosted Google Photos alternative, is closing in on its v3 release, now in release-candidate territory. The headline features: non-destructive mobile editing, workflows, and the ability to use Immich as a full gallery app on Android.
Hot take: Immich is the poster child for self-hosted software that's genuinely better than the SaaS it replaces, and v3 pushes it further onto your phone, which is where the "just use Google Photos" temptation actually lives. If it can be your default gallery app, Google Photos stops being a habit. Wait for the stable tag before you point your only copy of the family photos at it, though. Release candidates are called candidates for a reason.
8. UN Open Source Week put digital sovereignty on the main stage
UN Open Source Week wrapped at UN headquarters with keynotes from Yann LeCun and Linus Torvalds and sessions on financing open source, AI governance, and digital sovereignty. When the UN is running a track on how countries stay in control of their own software, the sovereignty conversation has officially left the homelab.
Hot take: "Digital sovereignty" sounds abstract until you realize it's the same instinct that makes an individual self-host their email: don't hand the keys to someone who can change the locks. For teams that need to keep data in a specific jurisdiction, running open-source software on European infrastructure is the practical version of that idea, no UN panel required.
What We're Watching Next Week
Kubernetes 1.37 hits its feature freeze on July 10, heading toward a late-August release. Worth tracking if you run clusters, because this is the point where the shape of the next version locks in.
Claude Sonnet 5 is being pitched as the most agentic model yet, able to drive browsers and terminals on its own. The question for self-hosters: do the open agent stacks like OpenClaw and Hermes keep pace, or does the frontier pull further ahead of what you can run yourself?
Bottom Line
Three threads ran through the week. Consolidation: the agent-sandbox layer is so valuable that OpenAI bought a company to get it. Capability: Gemma 4 under Apache 2.0 means the models you can self-host keep getting better and freer. And maintenance: Grafana and PostgreSQL both shipped fixes you should apply now, not next sprint. The tools keep getting more powerful, but the boring habit of patching is still what keeps your stack yours.
Thanks for reading ❤️ See you next week 👋
Original source - Jul 2, 2026
- Date parsed from source:Jul 2, 2026
- First seen by Releasebot:Jul 3, 2026
Elestio AI DevOps Now Runs in Your Browser (and Costs Less)
Elestio ships a big AI DevOps update with a browser-based service page UI, faster diagnostics, and a major price drop for live server interventions from 10 credits to 2, while keeping backup-first, secure, transparent fixes in one hour sessions.
What AI DevOps does
It's late, your site is throwing a 502, and you're staring at a terminal you'd rather not be staring at. You know the fix is probably five commands away. You also know that one wrong command at this hour is how a small outage becomes a long night. That gap, between "I can see the problem" and "I trust myself to fix it right now," is exactly what Elestio's AI DevOps was built to close.
We just shipped a big update to it, and I want to walk you through what changed and how you'd actually use it.
AI DevOps is an agent that connects directly to one of your Elestio services, reads the problem you describe in plain language, and fixes it while you watch every step. You don't SSH in. You don't paste commands from a forum thread. You open your service page, tell it what's wrong ("website returns 502 after the last deploy"), and it takes it from there.
Under the hood it opens a short-lived, secure session on that specific server, snapshots a backup first, diagnoses the issue, and applies the fix. You see the whole thing happen in a live view, and you can stop it at any moment.
The point isn't to replace you. It's to handle the mechanical parts (find the failing container, check the logs, restart the right service, renew the cert) so a routine incident doesn't cost you an hour and a spike in blood pressure.
What actually changed in this update
Three things, and they all matter.
It runs in your browser now. The old version dropped you into a terminal-style view. The new one is a proper web UI on the service page. You type what's wrong, you watch the agent work in a clean interface, and you approve or stop it without living in a console. Same transparency, far less intimidating for anyone who isn't a full-time sysadmin.
It got a lot cheaper. A full server intervention used to cost 10 credits. It now costs 2. That's a 5x drop for the exact same work. Documentation-based answers (where the agent just explains something from the Elestio docs) still cost 1 credit.
It's faster and smarter. The model behind it is quicker to reach a diagnosis and better at the messy, real-world cases, the ones where the error message and the actual root cause aren't the same thing.
Put those together and the math changes. The Level 1 support plan includes 60 credits per month per service. At 2 credits per intervention, that's around 30 real fixes a month before you even think about the next tier. For most services, that's plenty.
ACTION CREDIT COST NOTES Documentation answer 1 credit Explains a topic from the Elestio docs, no server access Full server intervention 2 credits (was 10) Live session, backup, diagnosis, and fix Monthly included credits 60 / 120 / 300 By support tier; resets on the 1stHow a session actually goes
Here's the flow, start to finish:
- You open the affected service in the Elestio dashboard and start an AI DevOps session.
- You describe the problem in plain English. No log paths, no jargon required.
- The agent opens a time-boxed secure session on that server (capped at one hour) and takes an automatic backup before touching anything.
- It investigates: reads logs, checks container health, inspects config, whatever the problem calls for.
- It applies the fix and shows you exactly what it ran, live.
- You confirm it's resolved, or you hit stop and take over.
The kinds of things it handles well are the everyday incidents: a 502 after a bad deploy, an SSL certificate that didn't auto-renew, a service that won't come back up after an update, a database that's refusing connections. These are the tickets that eat an afternoon precisely because they're fiddly, not because they're hard.
The part people worry about
"An AI with root on my server" is a fair thing to be nervous about, so it's worth being clear about the guardrails.
Every session is scoped to a single service. The agent can't wander across your infrastructure. Every session is time-boxed to a maximum of one hour, then it's gone. A backup is taken automatically before any change, so there's always a rollback point. And you get full command transparency: nothing happens off-screen, and you can kill the session mid-run if you don't like where it's going.
That's the trade the design makes. You get automation on the boring, error-prone work, but with a backup net, a hard time limit, a narrow blast radius, and a stop button in your hand.
Where it fits (and where it doesn't)
Be honest with yourself about the job. AI DevOps is excellent at bounded, well-understood incidents on a running service. It is not a replacement for architecture decisions, capacity planning, or a proper post-mortem after a serious outage. Think of it as the on-call engineer who clears the routine tickets fast, so your actual attention goes to the problems that need a human.
If your service is already down hard and data integrity is on the line, the automatic backup-first step is your friend, but you should still be watching the live session, not walking away from it.
Try it on your next 502
If you're already running something on Elestio, this is now sitting on your service page waiting for the next time something breaks. New UI, 2 credits a fix, 60 included every month on Level 1. The next time you catch yourself dreading a terminal at midnight, describe the problem instead and watch it get handled.
You can see the full breakdown and screenshots on the AI DevOps page, and it works with any service you're already running on Elestio.
Thanks for reading ❤️ See you in the next one 👋
Original source Similar to Elestio with recent updates:
- Smokeball release notes136 release notes · Latest Jul 16, 2026
- Cosmolex release notes20 release notes · Latest Jul 30, 2025
- PracticePanther release notes35 release notes · Latest Jul 7, 2026
- Salesforce release notes57 release notes · Latest Jul 1, 2026
- Microsoft release notes737 release notes · Latest Jul 21, 2026
- Zoom release notes179 release notes · Latest Jul 22, 2026
- Jun 28, 2026
- Date parsed from source:Jun 28, 2026
- First seen by Releasebot:Jun 28, 2026
Elestio Catalog Updates: 9 New Releases This Week (June 22-28, 2026)
Elestio highlights a patch-heavy week across its catalog, led by Grafana, Meilisearch, Mastodon, and Weaviate security fixes, plus updates for n8n, ClickHouse, Ollama, Rocket.Chat, and Immich. The week blends urgent vulnerability patches with a few fresh feature upgrades.
If last week was quiet, this one made up for it. Nine services in the Elestio catalog shipped releases between June 22 and 28, and the dominant theme was security: Grafana cleared a stack of CVEs, Meilisearch and Mastodon both pushed urgent patches, and Weaviate closed an SSRF hole. If you run any of these, this is a patch-first week. Here is everything worth knowing.
Security alerts
Several releases this week exist primarily to fix vulnerabilities. Treat these as priority upgrades:
- Grafana 13.0.3 and its backports (12.4.5, 12.3.8, 12.2.10, 11.6.16) patch a batch of seven CVEs, including CVE-2026-9029 and CVE-2026-33382. If your Grafana is exposed, update now.
- Meilisearch 1.48.2 (and the 1.47.1 backport) fix CVE-2026-57824, a privilege escalation affecting index-scoped API keys, and CVE-2026-57823, an information disclosure affecting tenant tokens. The maintainers report no evidence of exploitation in the wild.
- Mastodon 4.6.2, plus 4.5.13 and 4.4.20, ship a fix for CVE-2026-8461 in FFmpeg and are flagged as critical if you run the Docker images. A separate 4.5.12 release also hardened LDAP TLS verification.
- Weaviate 1.38.2 validates module base-URL request headers to close an SSRF vector.
- n8n 1.123.60 rolled up fixes for a pile of dependency CVEs across tmp, protobufjs, ws, and axios.
Databases
- Weaviate v1.38.2 (June 25). Beyond the SSRF fix above, this one improves HFresh vector index handling, adds parallel pre-fill for the uncompressed vector cache, and ships a new generative-deepseek module. Backports landed in 1.37.10 and 1.36.19.
- ClickHouse v26.6.1 (June 25). A fresh stable release for the analytics database, alongside an LTS bump to 26.3.15.4 (June 23) for teams that stay on long-term support. Full binaries for amd64 and arm64 as always.
AI and GPU
- Ollama v0.30.11 (June 25). Adds thinking-capability detection for OpenCode and auto-installation of Claude Code, fixes GPU classification on Windows hybrid-graphics machines, and unifies speculative decoding in the MLX runner. Memory efficiency also improved through smarter multimodal projector offloading.
Development
- n8n 2.27.4 (June 24). The stable line picked up a Google Ads node API upgrade (v20 to v21) and fixes for Python relative imports and chained node building. The 1.123.60 maintenance release on June 22 carried the dependency security fixes noted above.
- Meilisearch v1.48.2 (June 24). The security patch is the headline, but 1.48.0 earlier in the week also introduced experimental template rendering and refined filter support for the search engine.
Hosting and infrastructure
- Grafana 13.0.3 (June 23). The security fixes dominate, but the release also bumps the Docker Alpine base image to 3.23.4 and improves provisioning so a _folder.json is written when you create dashboards in new folders. The point releases across older branches add a datasource UID validation fix.
Applications
- Mastodon 4.6.2 (June 25). Security-driven, but the 4.6.1 release the day before added avatar and header description fields to the API and fixed emoji database loading.
- Rocket.Chat 8.6.0-rc.2 (June 26). The 8.6 release candidate firmed up this week with a federation message-syncing fix and a two-factor authentication fix for personal access tokens. Worth tracking ahead of the stable cut.
- Immich v3.0.0-rc.3 (June 26). The photo platform's v3 inches closer, adding a webhook workflow action, keyboard seeking in the new video player, and a batch of detail-panel and external-library fixes.
What stood out this week
A few releases are worth more than a line:
- Grafana's CVE sweep. Seven CVEs in one coordinated release is a lot, and Grafana sits at the center of most self-hosted monitoring stacks. This is the upgrade to do first.
- Meilisearch's API-key privilege escalation. If you hand out scoped or tenant-token keys, this is exactly the kind of bug that turns a limited key into more than you intended. Patch to 1.48.2.
- Mastodon's FFmpeg fix. Media-processing CVEs are easy to underestimate until someone uploads a malicious file. The fix spans three release branches, so there is no excuse to stay behind.
- Immich v3 nearing the finish line. Webhook actions plus the workflow engine mean Immich is quietly becoming automatable, not just a photo viewer. The stable v3 looks close.
Run any of these on Elestio
Every service above is available as a fully managed, one-click deployment on Elestio, with automated updates, backups, and monitoring so the patch-now weeks are less of a scramble. Browse the full catalog of 400+ open-source apps at elest.io/fully-managed-services.
That is the week. Heavier on security than features, which is a good reminder that running your own software means owning the upgrade cadence. Patch the exposed ones today. Thanks for reading ❤️ See you next Sunday 👋
Original source - Jun 24, 2026
- Date parsed from source:Jun 24, 2026
- First seen by Releasebot:Jun 25, 2026
T Cloud Public on Elestio: Sovereign, GDPR-Compliant Hosting
Elestio adds support for T Cloud Public as a Bring Your Own Cloud provider, bringing managed open-source deployments, backups, monitoring, updates, and scaling to German sovereign cloud infrastructure for teams that need stronger data residency and compliance control.
What we shipped
For a lot of European companies, the cloud question stopped being "which region is cheapest" a while ago. It is now "whose laws actually apply to my data?" If you are in a regulated industry, the public sector, or you simply do not want your customer records sitting under a foreign jurisdiction, that question matters more than a few cents per gigabyte. So we are happy to share something that answers it directly: you can now run your Elestio services on T Cloud Public.
T Cloud Public, formerly Open Telekom Cloud, is the sovereign public cloud operated by T-Systems, a Deutsche Telekom company. Elestio now supports it as a Bring Your Own Cloud provider. In plain terms: you keep your own T Cloud Public account, you point Elestio at it, and we handle the rest. Provisioning, scaling, backups, monitoring, updates, and the full lifecycle of 400+ open-source applications, all running on infrastructure you own, in data centers that never leave Germany.
You get the Elestio experience you already know, one-click open-source deployments without the operational grind, on a cloud built specifically for European data sovereignty.
Why enterprises care about this
The appeal here is not marketing. T Cloud Public is built around a simple promise: your data stays in German data centers, governed exclusively by German and EU law, independent of non-European access. That comes with a stack of certifications that procurement and compliance teams actually ask for:
AREA WHAT T CLOUD PUBLIC OFFERS Data residency Stored and processed in German data centers (eu-de, eu-nl regions) Jurisdiction Subject to German and EU law, GDPR-compliant Security certifications BSI C5:2020, ISO 27001 / 27018 / 27701, SOC 1/2/3, TISAX Operator T-Systems, a Deutsche Telekom companyFor a bank, a hospital, a public agency, or any company with data-residency clauses in its contracts, that combination is the difference between "we can use this" and "legal said no." Pairing it with open-source software you control end to end, instead of a closed SaaS, closes the sovereignty loop completely.
How Bring Your Own Cloud works
The model is straightforward. Your T Cloud Public account stays yours, and you give Elestio scoped programmatic access to automate on top of it. You need three things:
CREDENTIAL WHERE IT COMES FROM Access Key (AK) A dedicated IAM user Secret Key (SK) Generated with the access key Domain Name Your account identifier (e.g. OTC00000000001)The setup is quick:
- In the T Cloud Public console, create a dedicated IAM user configured for programmatic access, and save the Access Key and Secret Key.
- Assign the IAM policies Elestio needs to provision and manage infrastructure (compute, block storage, networking, encryption-key read access, and DNS), scoped to all existing and future projects.
- Make sure at least one region project is enabled, for example eu-de or eu-nl.
- Grab your Domain Name from the account info page.
- In the Elestio dashboard, choose BYO-TCloud as your provider, enter the AK, SK, and Domain Name, and click Verify Config for automatic validation.
That is it. From there you deploy and manage services exactly as you would on any other Elestio provider. The full step-by-step, including the exact IAM policies, is in our T Cloud Public (BYO-TCloud) documentation.
A note on cost
Bring Your Own Cloud means you pay T Cloud Public directly for the underlying infrastructure, and Elestio for the managed automation layer on top. There is no markup hidden in your compute bill, and you keep full visibility and ownership of the account. For teams that have already committed to T Cloud Public, or have to for compliance reasons, this turns Elestio into the easy button for running open-source software there.
Troubleshooting the connection
- "No projects found" usually means no region project is enabled yet. Enable eu-de or eu-nl in the T Cloud Public console and retry.
- Volumes fail to create? Confirm the evs/default encryption key exists and the IAM user has read access to KMS.
- Managing existing services? The IAM user needs multi-region access, not just a single project.
Who should try it
If data sovereignty is a hard requirement rather than a nice-to-have, this is for you. Regulated industries, European public sector, and any enterprise that wants a reliable German operator behind its infrastructure can now get managed open-source on T Cloud Public without building the automation themselves.
You can connect your account today from the Elestio dashboard. If you want to see the full catalog first, browse the 400+ managed open-source services you can run on it.
Thanks for reading ❤️ See you in the next one 👋
Original source - Jun 24, 2026
- Date parsed from source:Jun 24, 2026
- First seen by Releasebot:Jun 24, 2026
Less Dashboard, More Agent: Day-2 Ops with the Elestio MCP
Elestio ships the MCP connector, bringing conversational control to its dashboard workflows. It maps 68 tools to the Elestio API for deploying services, managing backups, logs, billing, and more, with OAuth 2.1 and PKCE for safer access.
I have a confession: I used to keep the Elestio dashboard pinned in a browser tab all day. Deploy something here, resize a database there, hunt through logs when a service started throwing 502s. It works. It is also a lot of clicking for things I could describe in one sentence. So when we shipped the Elestio MCP connector, I did what any reasonable person would do and tried to stop opening the dashboard entirely. Here is what that actually looks like, and where I still keep my hands on the wheel.
We already wrote the setup walkthrough, so I am not going to re-explain connecting it. Thirty-second version: add https://mcp.elest.io as a custom connector in Claude, ChatGPT, Cursor, or Claude Code, authorize once through your browser, and you are in. This piece is about the part that comes after, the day-2 stuff.
What the connector actually exposes
The Elestio MCP maps 68 tools straight onto the Elestio API. That is the whole platform, not a toy subset: deploy and manage services across 400+ templates, handle volumes, firewall rules, SSL certificates, and SSH keys, run backups, snapshots, CI/CD pipelines, and system updates, pull container logs, and read billing and audit data. Anything you can do by clicking, an agent can do by asking.
The reason I trust it near production is the auth model. It uses OAuth 2.1 with PKCE: you authorize once in the browser, and the AI client gets short-lived tokens instead of a permanent API key sitting in a config file. Your credentials never leave the Elestio domain. That detail is the difference between "fun demo" and "thing I will actually point at a live service."
The workflows that replaced my dashboard
Once it is connected, the value is not "deploy WordPress by chatting." It is the boring operational work that normally costs you a context switch. A few I lean on:
WHAT I TYPE WHAT THE AGENT DOES "Why is my Ghost service throwing 502s?" Pulls recent container logs, reads the stack trace, points at the cause "Resize the Postgres node to 8 GB before tonight's launch" Resizes the service and confirms the new spec "Snapshot this service before I change the env vars" Triggers a backup, then makes the change "Restart the worker and lock it so nobody touches it" Restarts, then locks the service against changes "What did I spend across all services this month?" Reads billing data and totals it upThe debugging one is the keeper. Instead of opening the dashboard, finding the service, opening the log view, and scrolling, I ask a question and get an answer with the relevant lines already quoted. The agent has the logs and the context, so it can reason about the error instead of just showing it to me.
The other quietly useful one is the "snapshot before I do something dumb" pattern. I am far more willing to experiment on a live service when taking a backup is a clause in a sentence rather than a five-click detour I will skip when I am in a hurry.
Where I still keep my hands on the wheel
This is the part the breathless agent demos skip. Letting a model operate real infrastructure is great until it confidently does the wrong thing at scale. So a few rules I follow:
- Destructive verbs get confirmation. Delete, move, and resize all change or risk data. I want the agent to tell me what it is about to do and wait, not surprise me. Treat anything irreversible as a human checkpoint.
- The audit trail is your friend. Every action the agent takes through the MCP shows up in your Elestio audit log, the same as any other API call. After an agent-driven session, I skim it. It is also how you answer "wait, what changed?" three days later.
- Scope the session to the task. Short-lived tokens already limit the blast radius, but it helps to keep an agent session focused on one job rather than handing it the keys and walking away.
None of this is exotic. It is the same discipline you would want before giving a new teammate production access. The MCP just makes the access conversational, so the guardrails have to be conversational too.
Troubleshooting
- Connector shows red or won't authorize. Re-run the browser authorization; the token may have expired. Confirm the URL is exactly https://mcp.elest.io with no trailing path.
- The agent can't see a service. Make sure you authorized with the account that owns it. The MCP only exposes what your Elestio account can see.
- It hesitates on a destructive action. That is the design, not a bug. Confirm explicitly, or do that specific step in the dashboard if you would rather click it yourself.
So, is the dashboard dead?
Not quite, and I would be lying if I said I never open it. But the balance has flipped. Routine ops, debugging, scaling, backups, cost checks, now start as a sentence, and I reach for the dashboard mostly when I want to see something visually. That is the shift the whole industry is feeling right now: less clicking, more describing.
The connector itself is free with any Elestio account; you only pay for the services you actually deploy. If you have not wired it up yet, point your AI client at mcp.elest.io and start with something low-stakes like "list my services." You will probably keep going.
Thanks for reading ❤️ See you in the next one 👋
Original source - Jun 21, 2026
- Date parsed from source:Jun 21, 2026
- First seen by Releasebot:Jun 21, 2026
Elestio Catalog Updates: 9 New Releases This Week (June 15-21, 2026)
Elestio shares a quieter weekly release roundup with security hardening across Mattermost and Rocket.Chat, reliability fixes in n8n, new AI and search upgrades in Ollama, Weaviate, and Meilisearch, plus NocoDB Custom Sync and RabbitMQ management improvements.
After a busy run of major releases in early June, this week was quieter and more about hardening than headlines. Nine services in the Elestio catalog shipped updates between June 15 and 21, with a clear theme: security patches across team-chat tools, resilience fixes in automation, and steady progress on AI and vector search. Here is everything worth knowing.
Security alerts
No critical, internet-on-fire CVE landed this week, but two of the most widely self-hosted chat platforms shipped security releases you should not sit on:
- Mattermost 11.8.1 and the Extended Support releases 11.7.4 and 11.7.5 all carry medium-severity security fixes. If you run Mattermost in production, patch to your branch's latest point release.
- Rocket.Chat 8.5.1 ships security fixes including tightened permission checks on the fingerprint endpoint and corrected HTML escaping in exported data, with the same hotfixes backported across the 8.4.x, 8.3.x, 8.2.x, 8.1.x, and 7.x ESR branches.
- Weaviate also tightened its posture this week by disabling debug endpoints by default, which is worth knowing if any tooling depended on them.
The pattern is familiar: self-hosting means you own the patch cycle. Subscribe to your services' release feeds so these never catch you off guard.
Databases
- Weaviate v1.38.1 (June 18). The vector database had a busy mid-week, also shipping v1.37.9 (June 16) and v1.36.18 (June 17). Highlights across the three: a rate limiter for batch operations, async replication that auto-enables when your effective and actual replication factors line up, a fix for MCP hybrid search returning objects without properties, and the security hardening noted above.
AI and GPU
- Ollama v0.30.10 (June 17). Command A and the North family of models now run on Apple Silicon through the MLX engine, and the bundled llama.cpp moved to build 9672. The preceding v0.30.9 (June 15) added support for the Cohere2Moe architecture, fixed the LFM2 parser, and now returns a clear error when a single message exceeds the context window instead of failing silently.
Development
- n8n 2.26.8 (June 19). A steady stream of point releases this week (2.26.6 on June 17, 2.26.7 on June 18, 2.26.8 on June 19) focused on reliability: database connection recovery that suspends queries during reconnection to avoid race conditions, a Compression node fix so decompression targets the right archive members, and a Form Trigger fix that prevents crashes on older workflows missing an authentication default. The 1.123.x line also got a uuid library bump to 11.1.1 to clear advisory warnings.
- Meilisearch v1.47.0 (June 15). Search personalization now works with federated search requests, the new settings indexer reached feature-complete status for faster setting updates, and more Prometheus metrics are exposed for observability. Ranking-rule and searchCutoffMs edge-case bugs were squashed too.
- NocoDB 2026.06.1 (June 15). The no-code database introduced Custom Sync, which mirrors PostgreSQL or MySQL tables into NocoDB as read-only synced tables that stay current with their source, plus Microsoft SQL Server as an external data source. Real-time document collaboration with named cursors arrived, and large-form field switching went from roughly 550ms down to 40ms.
- Apache Superset Helm chart 0.16.2 (June 17). A Kubernetes deployment-tooling update for the popular BI platform. No change to the core app, but smoother for anyone running Superset on K8s.
Hosting and infrastructure
- RabbitMQ 4.3.2 (June 15). Alongside 4.2.8 the same day, the message broker fixed a feature-flag enabling edge case, corrected creation of password-less users over the HTTP API, and added a "Delayed" message-count column to the management UI. Both releases hardened the Management Plugin with improved CORS validation and response headers, and added encrypted-value support for more rabbitmq.conf keys.
Applications
- Mattermost 11.8.1 (June 15). Beyond the security fixes above, the 11.9.0 release candidate landed on June 18, previewing the next feature drop for the team-collaboration platform.
- Rocket.Chat 8.5.1 (June 15). The security patch headlines this one, but the 8.6.0 release candidate on June 20 is the one to watch: it adds LibreTranslate for fully self-hosted message translation, so no text leaves your server to get translated.
What stood out this week
A few releases are worth more than a one-line mention:
- n8n's reliability focus. Connection recovery that suspends queries during a reconnect is the kind of unglamorous fix that quietly saves your workflows during a database blip. For the second-most-searched tool in our catalog, that matters.
- Rocket.Chat's self-hosted translation. LibreTranslate integration means cross-language teams can translate messages without shipping a single word to a third-party API. That is sovereignty done right, even if it is still in RC.
- NocoDB Custom Sync. Mirroring live Postgres and MySQL tables into a no-code interface turns NocoDB into a friendly read layer over your existing databases, which is a genuinely useful pattern for ops dashboards.
- Ollama on Apple Silicon. Bringing more model families to the MLX engine keeps local inference fast on Macs, which is where a lot of developers prototype before deploying to a GPU VM.
Run any of these on Elestio
Every service above is available as a fully managed, one-click deployment on Elestio, with automated updates, backups, and monitoring so you spend your time using the tools rather than patching them. Browse the full catalog of 400+ open-source apps at elest.io/fully-managed-services.
That is the week. Quieter than the early-June rush, but the security fixes alone make it worth a maintenance window. Thanks for reading ❤️ See you next Sunday 👋
Original source - Jun 7, 2026
- Date parsed from source:Jun 7, 2026
- First seen by Releasebot:Jun 8, 2026
Elestio Catalog Updates: 34 Notable Releases This Week (June 1-7, 2026)
Elestio highlights a busy week of open-source releases, led by Valkey 9.1.0, Weaviate 1.38.0, NocoDB 2026.06.0, and coordinated Redis security patches, with steady updates across databases, AI tools, dev platforms, and apps.
Another busy week across the Elestio catalog: 34 notable stable releases landed between June 1 and June 7, including a new Valkey minor, a feature-packed Weaviate release, and coordinated Redis patches across three release lines. Here's everything worth knowing before your next update window.
Security Alerts
Redis: make sure you're past the May RCE fixes. This week's coordinated patches (8.6.4, 8.4.4, and 8.2.7, June 4) land on top of the recent security wave that fixed CVE-2026-23479 (authenticated RCE via use-after-free, CVSS 8.8) plus two related memory-safety CVEs. If any of your instances are still below 8.6.3 / 8.4.3 / 8.2.6, upgrading to this week's releases clears the backlog in one jump. Elestio-managed Redis instances are updated automatically.
Databases
- Valkey 9.1.0 (June 2): New minor release of the Linux Foundation Redis fork, shipped alongside 8.1.8 and 8.0.9 maintenance updates for the older lines.
- Redis 8.6.4 (June 4): Patch releases across the 8.6, 8.4, and 8.2 lines. See the security note above.
- Weaviate 1.38.0 (June 5): The feature release of the week, with namespaces, nested object filtering, the new HFresh index, and schema alteration with reindexing. Patch updates also landed for the 1.35-1.37 lines.
- Milvus 2.6.18 (June 5): Stability-focused patch for the vector database.
- TimescaleDB 2.27.2 (June 2): Bug-fix release for the Postgres time-series extension.
AI/GPU
- Ollama 0.30.6 (June 7): A rapid run of stable releases this week (0.30.3 through 0.30.6) with llama.cpp engine updates and Gemma fixes.
- Open WebUI 0.9.6 (June 2): Refinements and fixes for the self-hosted LLM front end.
- LibreChat 0.8.6 (June 1): Maintenance release for the multi-provider chat UI.
- Langflow 1.9.6 (June 2): Patch release. Reminder: if you're below 1.7.0 you're exposed to the actively exploited CORS flaw we covered in Friday's digest. Update.
- Gradio 6.17.0 (June 5): New minor with workflow canvas component updates, followed same-day by a 6.17.1 hotfix.
Development
- n8n 1.123.53 (June 5): Steady patch cadence on the 1.x LTS line, with parallel updates (2.25.5, 2.23.4) on the 2.x lines.
- Keycloak 26.6.3 (June 4): Patch release for the identity server.
- NocoDB 2026.06.0 (June 4): Introduces NocoDB Sync and document version history, the most feature-rich NocoDB release in months.
- Strapi 5.47.1 (June 3): Bug-fix patch for the headless CMS.
- Hasura 2.49.1 (June 4): Maintenance update for the v2 GraphQL engine line.
- Meilisearch 1.45.2 (June 2): Patch release for the search engine.
- PocketBase 0.39.1 (June 3): Fixes on the latest line, plus a 0.22.46 backport for legacy deployments.
- Qdrant 1.18.2 (June 4): Patch release for the vector search engine.
- Node-RED 4.1.11 (June 4): Maintenance release for the flow-based automation tool.
- Jenkins 2.567 (June 2): Weekly release train, business as usual.
Hosting & Infrastructure
- Grafana 13.0.2 (June 2): Patch for the new 13.0 line, followed June 4 by coordinated backports across 12.4, 12.3, 12.2, and 11.6 LTS.
- Vault 2.0.2 (June 5): Second patch release for the Vault 2.0 line.
- Portainer 2.39.3 LTS (June 4): LTS maintenance for the container management UI.
- SigNoz 0.127.0 (June 3): Regular feature release for the open-source observability stack.
Applications
- Nextcloud 33.0.5 (June 6): Maintenance for Hub 33, with 32.0.11 also out; meanwhile Nextcloud 34 is in late release-candidate stage (rc5).
- Ghost 6.44.0 (June 3): New minor for the publishing platform, with a 6.44.1 follow-up two days later.
- Jellyfin 10.11.11 (June 6): Patch release for the media server.
- Mastodon 4.5.11 (June 3): Same-day patches for 4.5 and 4.4, while the first 4.6.0 beta opens testing.
- Rocket.Chat 8.4.3 (June 2): Coordinated patches across the 8.2-8.4 lines.
- Outline 1.8.0 (June 1): New minor for the team wiki, with a 1.8.1 fix released June 6.
- Metabase 0.61.3.6 (June 5): Patch for the stable BI line while 0.62 betas continue.
- Syncthing 2.1.1 (June 2): Maintenance release for the file synchronizer.
- Plausible 3.2.1 (June 1): Patch for the privacy-first analytics platform.
- ERPNext 16.21.0 (June 2): Feature minor with a 16.21.1 hotfix, plus 15.110.0 for the v15 LTS line.
What Stood Out This Week
Valkey 9.1.0 keeps up the post-fork momentum. Two years after the Redis license drama spawned it, Valkey is shipping minors at a pace that makes it a genuine first-choice key-value store rather than a protest fork.
Weaviate 1.38.0 is the most substantial upgrade of the batch. Namespaces and nested object filtering address two of the most common multi-tenant pain points, and arriving the same week ChromaDB took a CVSS 10.0, it's a good moment to evaluate where your vectors live.
NocoDB 2026.06.0 adds sync and document version history, pushing the Airtable alternative further into territory where teams previously needed paid SaaS.
Redis's triple patch is the housekeeping item: not glamorous, but with RCE-class CVEs in recent memory, version hygiene on your cache layer matters more than usual this month.
Keep Your Stack Current Without the Busywork
Every service above is available fully managed on Elestio, where updates like these are applied for you with automated backups before each one. Browse the full catalog of 400+ open-source services and let someone else watch the release feeds.
Thanks for reading ❤️ See you next Sunday 👋
Original source - May 31, 2026
- Date parsed from source:May 31, 2026
- First seen by Releasebot:May 31, 2026
Elestio Catalog Updates: 21 Notable Releases This Week (May 24-31, 2026)
Elestio highlights a busy week of self-hosted software updates, led by a critical Ghost CMS security patch, Directus 12 release candidate, fresh stable releases from Authentik, N8N and Mattermost, plus new updates for Prometheus, Uptime Kuma, Nextcloud and Mautic.
Quieter week than last one for splashy releases, but a critical Ghost CMS CVE means a lot of self-hosters need to drop everything and patch. We also got Prometheus 3.12, Uptime Kuma 2.4, a Directus 12 release candidate, fresh stable lines from Authentik, N8N, and Mattermost, and routine Nextcloud and Mautic point releases. Here's the rundown.
Security Alerts
Patch first, read second.
- Ghost CMS, CVE-2026-26980 (CVSS 9.4). Critical SQL injection in Ghost versions 3.24.0 through 6.19.0, actively exploited in the wild with 700+ confirmed compromises. If you are on any version 6.19.0 or older, upgrade to 6.19.1+ today. Anyone running this week's 6.43.1 line is already protected. (Hacker News advisory)
- Gitea, CVE-2026-27771. Last week's container-registry exposure still applies. Upgrade to 1.26.2 if you have not.
Databases
- Redis 8.8.0 (May 25). New stable on the 8.x line with continued vector set improvements and Redis Functions 2.0 hardening.
AI & GPU
- Langflow 1.9.5 (May 29). Follow-up patch to 1.9.4, smoothing recent flow editor performance issues and a handful of component-store fixes.
Development
- Authentik 2026.5.2 (May 28). Patch release across three supported lines (2026.5.2, 2026.2.4, 2025.12.6) addressing flow-engine edge cases and a stack-tracing fix in policy bindings.
- N8N 2.23.1 (May 28). Latest stable on the 2.x line, joining 2.22.5 LTS on the same day. Continued focus on credential-handling cleanup.
- Strapi v5.47.0 (May 28). Adds new admin panel improvements, content-type builder polish, and a fresh batch of bug fixes across the plugins SDK.
- Directus v12.0.0-rc.1 (May 29). First release candidate of Directus 12. Major version with schema migration improvements and updated permission model. Test in staging, not production.
- Hoppscotch 2026.5.0 (May 28). May feature release of the open-source API client. New collection-sharing improvements and continued WebSocket UI polish.
- Meilisearch v1.45.1 (May 28). Patch on top of v1.45.0 (May 26). Index-rebuild speedups and a couple of geo-search fixes.
Hosting & Infrastructure
- Prometheus v3.12.0 (May 28). Minor release on the 3.x line. Continued PromQL improvements, OTLP ingestion tuning, and TSDB compaction work.
- Uptime Kuma 2.4.0 (May 31). Sunday drop. Continues the 2.x rebuild with new monitor types, theme refinements, and notification integrations.
- Mailu 2024.06.52 (May 28). Maintenance release on the 2024.06 LTS line of the self-hosted email server suite.
Applications
- Nextcloud 33.0.4 + 32.0.10 (May 28). Maintenance patches on both supported lines, plus the 34.0.0rc3 candidate for early testers.
- Mattermost v11.7.2 (May 26). Latest stable, plus same-day patches to v11.6.4, v11.5.7, and the v10.11.19 ESR line.
- Jellyfin v10.11.10 (May 24). Maintenance patch on the 10.11 line. Playback and metadata fixes.
- Ghost v6.43.1 (May 29). Twice-weekly cadence continues with 6.41.1 (May 25), 6.42.0 (May 27), and 6.43.0/6.43.1 landing on May 29. Members and editor polish.
- BookStack v26.05 (May 28). Monthly release. New shelf and page features, improved API endpoints, and the usual translation refresh.
- Mautic 7.1.2 (May 28). Three-line drop: 7.1.2, 6.0.9, and 5.2.11. Stability and security fixes across all supported branches.
- Element Web v1.12.20 (May 27). Matrix client update with v1.12.19 on the same day. Sliding sync stabilization and call UI improvements.
- Wekan v9.32 (May 31). Follow-up to v9.31 (May 27). Board-search performance and CardKanban view fixes.
- Matomo 5.10.1 (May 29). Patch on the 5.10 line of the privacy-friendly analytics platform.
- Apache Airflow 3.2.2 (May 29). Patch on the 3.2 line. DAG processing and scheduler fixes.
What Stood Out This Week
- The Ghost CVE is the headline.
A CVSS 9.4 SQL injection sitting in Ghost for years, now actively exploited with 700+ confirmed compromises, is the kind of story that ends careers. If you self-host Ghost on a version older than 6.19.1, stop reading this and go upgrade. We are running 6.43.x on this blog and are protected.
- Directus 12.0.0-rc.1 is a big deal.
Major version jumps in headless CMS land are rare and usually break things. The RC is a chance to test schema migrations and permission changes before stable. Don't push to prod, but do spin up a staging instance and run your client schemas through it.
- Authentik's three-line patch shows the LTS model working.
Most projects let you stew on a vulnerable version when they release a new major. Authentik backported the same fix to 2026.5, 2026.2, and 2025.12 on the same day. That's how a serious identity provider should treat its installed base.
- Mattermost's four-version patch wave.
Same pattern: v11.7.2, v11.6.4, v11.5.7, and v10.11.19 all on the same day. If you delayed your last Mattermost upgrade, you have a clean path forward on whichever ESR line you're sitting on.
Deploy or Upgrade with One Click
Every service in this week's list is available as a one-click managed deployment on Elestio. Our infrastructure handles backups, SSL, and version updates so you can spend your weekend on things other than catching up on CVE patches.
Thanks for reading. See you next Sunday for the next round.
Original source - May 24, 2026
- Date parsed from source:May 24, 2026
- First seen by Releasebot:May 24, 2026
Elestio Catalog Updates: 23 Notable Releases This Week (May 17-24, 2026)
Elestio highlights a busy week of product releases across the catalog, led by Appsmith v2.0, ClickHouse stable and LTS updates, and Mastodon security backports. The roundup also covers new feature and patch releases for tools, databases, and apps.
Another busy week across the catalog. Mastodon shipped coordinated security backports across three major versions, Appsmith hit v2.0, and the database side stayed loud with ClickHouse pushing both stable and LTS updates. Here's the full rundown of what landed between May 17 and May 24, 2026.
Security Alerts
Mastodon 4.5.10 / 4.4.17 / 4.3.23 (May 20): Coordinated security release patching four advisories. Two SSRF-protection bypasses (GHSA-crr4-7rm4-8gpw, GHSA-xx55-4rrg-8xg6) and two Linked-Data Signature bypasses (GHSA-53m7-2wrh-q839, GHSA-chgx-jx3p-rf73). If you run a Mastodon instance, upgrade today. The release requires asset recompilation, so don't sleep-walk through the deploy.
Databases
- ClickHouse v26.5.1.882-stable (May 21): New stable cut with the Apache 2 pg_clickhouse Postgres extension officially shipped. The unified OLTP+OLAP story just got real.
- ClickHouse v26.3.12.3-lts (May 22): LTS patch with bug fixes for the long-term support line.
- QuestDB 9.4.0 (May 18): Time-series engine update with query-planner improvements and tighter Parquet integration for cold storage offload.
Development
- Appsmith v2.0 (May 21): Major version bump for the low-code internal-tool builder. Two years since 1.0, this one is the big rewrite of the workflow engine and the auth model.
- Authentik 2026.5.0 (May 22): Monthly cadence release. Flow editor improvements, new OAuth source providers, and group-claim handling fixes that several users requested.
- Keycloak 26.6.2 (May 19): Patch release on the 26.x line. Bug fixes across the admin console and OIDC client handling.
- n8n 2.21.7 stable (May 21): Stable channel update. Bug fixes for queue-mode worker handoff and the Microsoft Graph trigger node.
- Strapi v5.46.1 (May 20): Patch release on Strapi 5. Content-type schema fixes and admin UI polish.
- Gitea v1.26.2 (May 20): Patch on the 1.26 line. Fixes for the Actions runner reconnection logic that was biting self-hosters.
- ToolJet v3.20.164-lts (May 22): LTS patch with workspace permission fixes and new data-source connectors.
- PocketBase v0.38.2 (May 22): Latest on the 0.38 line with PocketBase JS SDK 0.30 compatibility fixes.
Hosting & Infrastructure
- Portainer 2.42.0 STS (May 20): Short-term-support cut. New Kubernetes RBAC enforcement modes and Docker Swarm rolling-restart improvements.
- RabbitMQ 4.3.1 (May 20): Patch on the 4.3 line. Stream consumer rebalancing fixes and federation plugin improvements.
- RabbitMQ 4.2.7 (May 19): Maintenance release on the 4.2 line for teams not yet on 4.3.
- OpenTelemetry Collector v0.152.1 (May 19): Bi-weekly release. New processors and exporters, plus the usual upstream protobuf bumps.
- SigNoz v0.125.1 (May 20): Hot patch on top of 0.125.0. APM trace-sampling improvements and ClickHouse storage tuning.
Applications
- Ghost v6.41.0 (May 21): Twice-monthly cadence delivered. New newsletter analytics, member-stats dashboard polish, and editor performance improvements.
- Mattermost v11.6.3 (May 21): Bug-fix patch on the 11.6 ESR line. Channel-mention render fixes and integration framework patches.
- Mattermost v11.5.6 (May 21): Backport patch for teams still on 11.5 LTS.
- Jellyfin 10.11.9 (May 21): Stable patch. Subtitle handling fixes and transcoding improvements for newer hardware accelerators.
- Metabase 0.61.2 (May 19): Lead release on the 61.x line. Improved Mongo connector and dashboard load-time optimizations. Patch releases for 0.60.7, 0.59.12, and 0.58.15 also shipped for older lines.
- Chatwoot v4.14.0 (May 18): Feature release with WhatsApp Business API improvements and new automation triggers.
- BookStack v26.03.5 (May 21): Maintenance patch on the 26.03 line. Page revision UI fixes and OIDC provider improvements.
- Jitsi Meet 2.0.10978 (May 20): Stable channel cut. Mobile participant-list improvements and lobby-mode polish.
- Firefly III v6.6.3 (May 21): Personal finance manager. Currency-conversion fixes and budget-report performance improvements.
What stood out this week
A few releases worth your weekend attention:
Appsmith v2.0 is a real 2.0.
Two years of work landing in one cut, including the workflow-engine rewrite and a new auth model. If you've been on 1.x, read the migration guide before you click upgrade. There are breaking changes in the data-source config format.
ClickHouse + pg_clickhouse going Apache 2 matters more than the version bump.
The extension lets you run analytics queries against ClickHouse from inside Postgres. The "do we need a separate data warehouse?" conversation just got an easy answer for teams under 100 GB of analytical data.
Mastodon's coordinated backport is the kind of release ops teams love.
Patches landed simultaneously on 4.5, 4.4, and 4.3 with clear advisory IDs. No "you must upgrade two majors to get the fix" tax. More projects should ship this way.
Authentik's monthly cadence still produces.
Every monthly cut adds something concrete (group-claim handling this time). Steady release rhythm matters when the alternative (Keycloak) ships major versions on a 6-month schedule.
What we're watching next week
- Nextcloud Hub 34 is in RC. The stable cut should land in the next two weeks, bringing the new collaborative-Office mode and the unified search rewrite.
- Prometheus 3.12 RC is out. The histogram changes will affect anyone running long-term storage exporters.
- Percona Live (May 27-29) kicks off and usually triggers a wave of Postgres, MySQL, MariaDB, and Valkey announcements timed to the conference.
Browse the full catalog
Every service mentioned above runs on Elestio with managed updates, automated backups, TLS, and 24/7 monitoring out of the box.
Browse the full catalog: 400+ open-source services, one-click deployment.
Thanks for reading ❤️
See you next Sunday 👋
Original source - May 15, 2026
- Date parsed from source:May 15, 2026
- First seen by Releasebot:May 15, 2026
Self-Hosted GitLab + Elestio: Set Up CI/CD from Your Own Git
Elestio now supports self-hosted GitLab as a first-class CI/CD source, letting users connect private instances with a Personal Access Token and trigger auto-deploys on every push without mirror workarounds or custom runners.
If your code lives on a self-hosted GitLab instance, deploying it to a managed platform usually means writing your own pipeline scripts, juggling SSH keys, or running a custom runner somewhere. Plenty of you have told us you don't want to mirror private repos to GitHub or GitLab.com just to get auto-deploy on Elestio. As of today, that workaround is dead.
Elestio's CI/CD now supports self-hosted GitLab as a first-class Git source. Connect your private GitLab instance once with a Personal Access Token, and every push triggers a deploy on Elestio. Same flow you already get with GitHub or GitLab.com repos, just pointed at your own server.
Why this matters
If you run GitLab on your own infrastructure, you usually have a reason: compliance, data residency, network isolation, or simply the cost of a paid GitLab.com plan at scale. None of those reasons should force you off a managed deployment platform.
Until now, the workaround options were painful: mirror your private repos to a public Git host (defeating the point), or build your own deployment scripts on a self-managed runner. The new integration handles the boring parts for you: webhook setup, SSH key provisioning, repository scoping at the group or subgroup level, and branch tracking with auto-deploy triggers.
How it works
Elestio's CI/CD treats your self-hosted GitLab like any other Git provider. You give us two things:
- Your GitLab instance URL (e.g. https://gitlab.yourcompany.internal , no trailing slash)
- A Personal Access Token with the api scope
We use that PAT to list the repositories you have access to (respecting your GitLab permissions), register a webhook on each project you connect, and pull the latest code on each push. The PAT is encrypted at rest. Webhooks send a signed payload, and we verify the signature before kicking off a deploy.
The api scope is the only scope we need, and the only scope that works. Narrower scopes like read_api or read_repository cannot create webhooks or manage deploy keys, so connecting with them will fail. Requires GitLab 13.5 or newer (October 2020), which covers basically every active instance.
Step-by-step setup
Prerequisites
- A self-hosted GitLab instance reachable from Elestio
- A Personal Access Token from your GitLab account
- An Elestio service to deploy to, or a new one you're about to create
Step 1: Create the PAT on your GitLab instance
In your GitLab UI, go to your avatar menu (top right) → Preferences → Access Tokens → Add new token. Or jump straight to /-/profile/personal_access_tokens.
- Token name: elestio-cicd (or whatever you'll recognize later)
- Expiration: pick a date that fits your security policy
- Scopes: tick api , and only api
Hit "Create personal access token" and copy the value immediately. GitLab will not show it again. The token starts with glpat-.
Step 2: Pick GitLab in Elestio
When creating a new service, or editing an existing one's CI/CD source, pick GitLab as the Git provider. Then flip the Hosting Type toggle from Cloud to Self-Hosted.
Heads up: switching between Cloud and Self-Hosted resets any repositories and settings you'd already picked, so do this toggle first.
Step 3: Connect your instance
Click to add a new Git account. A modal appears asking for two fields:
- GitLab Instance URL: full URL with https:// and no trailing slash (e.g. https://gitlab.yourcompany.internal )
- Personal Access Token: paste the token you just generated
Hit Connect. On success you'll see Connected as [username] on [instance URL] , and the repository list loads below.
Step 4: Import the repo
Use the Git Scope dropdown to filter by group, subgroup, or user. Search for the repo you want to deploy. Click Import.
That's it. Elestio registers the webhook on your GitLab project, pulls the code, and starts the first deploy. From now on, every push to the tracked branch ships a new version to your service.
You can connect more than one self-hosted instance, by the way. Open the Git Account dropdown and pick "Add Git Account" to wire up another one with its own PAT.
For the full reference, see the Elestio docs on deploying a CI/CD pipeline via GitLab self-hosted.
Common gotchas
A few things that trip people up:
The GitLab instance must be reachable from Elestio. If your GitLab sits behind a firewall or VPN, you'll need to allow inbound HTTPS from Elestio's IP range.
Use a token from a service account, not your personal login. When the user who created the PAT leaves the company or rotates their token, every connected repo breaks. A service account avoids that whole class of problem.
The URL format is strict. Include the protocol, drop the trailing slash. https://gitlab.acme.com works; gitlab.acme.com/ or https://gitlab.acme.com/ does not.
If you use the "Clone Template" flow instead of "Import Git Repository," your GitLab admin needs to enable Admin Area → Settings → General → Import and export settings → Allow imports from external URLs. Without it, template-based project creation fails with 404 or insufficient_scope even when the token is fine.
Subgroups appear flat in the dropdown. GitLab nests groups infinitely, but the Elestio UI shows them as a flat list with the full path. If you have mycompany/backend/api , you'll see it as mycompany/backend/api in Git Scope, not nested.
Troubleshooting
ERROR | LIKELY CAUSE | FIX
AUTH_FAILED at connection | Invalid token, expired token, or wrong instance URL | Verify the URL responds to curl -I from a public host and includes https:// with no trailing slash. Regenerate the PAT if needed
INSUFFICIENT_SCOPES at connection | PAT missing the api scope | Edit the token (or create a new one) and tick api. Narrower scopes will not work
insufficient_scope during template import | External URL imports disabled at the instance level | Ask your GitLab admin to enable Allow imports from external URLs under Admin Area → Settings → General
Push doesn't trigger deploy | Webhook missing or signature mismatch | Re-import the repo, or check GitLab's webhook delivery logs under Project → Settings → Webhooks
Branch not found | Empty repo, or the tracked branch name does not exist | Push at least one commit on the branch you configured in the pipelineWhat's next
Self-hosted GitLab is the second self-hosted Git source we support, after a long stretch of GitHub-only and GitLab.com-only. Gitea, Forgejo, and Bitbucket self-hosted are on the roadmap. If one of those is blocking you, reply to this post and tell us which.
Until then: connect your GitLab instance on Elestio, push some code, and stop maintaining your own deployment glue.
Thanks for reading ❤️
See you in the next one 👋
Original source - May 15, 2026
- Date parsed from source:May 15, 2026
- First seen by Releasebot:May 15, 2026
We Shipped a New Elestio Dashboard, Here's What Changed
Elestio introduces a cleaner dashboard and a faster service creation flow, with a streamlined sidebar, consistent service tabs, inline credentials, live cost previews, and all-in-one Tools access for editing, terminal, SSH/SFTP, and password resets.
The Elestio dashboard you logged into this week looks different. Same platform underneath, but the path from "I need a Postgres cluster" to "here's a connection string" got shorter, and a few things we used to bury behind menus now sit on the page where you'd actually expect them.
Here's what changed and what to look for.
A Cleaner Sidebar (and Fewer Round Trips)
The left rail is now split into two groups: the things you build (Services, Clusters, CI/CD, Volumes, Load Balancer, Domains) and the things you manage (Members, Billing, Project Setting, Audit Trail, Account, Support Tickets, Monitoring, Documentation).
Counts now appear inline as small badges next to the relevant items, so you can see at a glance that a project has 14 services, 35 CI/CD pipelines, or 1 volume without clicking through. Audit Trail and Monitoring used to live one level deeper. They're top-level now because that's where most teams open them in the first place.
A 4-Step Service Creation Flow
Spinning up a new service is now an explicit four-step wizard:
- Select service: the catalog grid, filterable by category (Databases, Applications, Development, Hosting & Infra, Full Stack, AI/GPU, CI/CD, Git).
- Select provider, region & service plan: pick your cloud (AWS, Hetzner, Netcup, Linode, DigitalOcean, Scaleway, Vultr, OVH, Lightsail) and VM size.
- Provide service name & cluster config: auto-generated names you can override, plus a clear toggle between Single Node and Primary/Replica.
- Select support & advanced settings: three support tiers (Basic / Pro / Business) priced by the hour, plus optional advanced config.
The progress bar at the top of every step tells you where you are. The right sidebar always shows the running summary: software, version, plan, provider, region, specs, IPv4, and an Estimated Monthly Cost that updates as you change selections. No more clicking "Create" only to find out it costs more than you thought.
A small but welcome detail: every config page has a Copy Terraform Config button next to the Create CTA, so the same setup you just clicked your way through can be checked into a repo as code.
Service Detail Page: Credentials Where You Expect Them
Open any running service and the Overview tab now leads with two things you actually need: Termination protection (a single toggle) and Connect to your service (your credentials, inline).
The credentials card shows HOST, PORT, USER, PASSWORD, and the ready-to-paste CLI command, each with its own copy button. There's a Hide credentials toggle for screen-sharing. The Admin software (pgAdmin, phpMyAdmin, the ClickHouse UI, whatever ships with your service) opens with one click below.
The right rail keeps the Quick Info card pinned: plan, provider, region, full specs, IPv4, service ID, project ID, who created it, and creation date. The fields that matter for support tickets are now copy-able directly from this card.
Your Existing Tools, Now in One Tab
VS Code, the File Explorer, the in-browser Terminal, SSH/SFTP details, and the Reset Password flow were already there. They were just scattered across different pages and modals depending on the service. The new Tools tab puts all five in the same place on every service:
- VS Code: browser-based editor running on your VM, one click.
- File Explorer: upload, download, navigate without dropping into a terminal.
- Terminal: direct console access in your browser.
- SSH/SFTP: connection details on demand, no key-hunting through your password manager.
- Reset Password: for SSH/SFTP, separated from the database credentials so you don't fat-finger the wrong reset.
Nothing new under the hood. What's new is that the layout is identical whether you're poking at a Postgres cluster, an n8n install, or a CI runner. Once you know where the Terminal lives, you know where it lives on every service in your fleet.
The Tabs Are Standard Across Every Service
Every service detail page now shares the same tab strip: Overview, Tools, Backups, Metrics, Monitoring, Logs, Audit, Security, Alerts. That consistency matters more than it sounds. If you're managing a fleet (one ClickHouse, two Postgres replicas, an n8n, a Mautic, a few CI runners), you don't have to relearn the layout for each one. Audit lives in the same place on every service. So does Alerts.
Live Cost Preview, Side by Side With the Config
Two visible changes here:
- The plan summary on the right side of the create flow now shows the hourly rate and the monthly estimate side by side. If you're sensitive to burst hourly billing (CI agents, ephemeral environments), the hourly number is what you want.
- Support tiers (Basic free, Pro at $0.0685/hour, Business at $0.2740/hour) are now their own selection step with clear inclusions. No buried checkbox.
This is the kind of thing that looks small in a screenshot but saves a support ticket a month from now.
What This Doesn't Change
The underlying platform is the same: same providers, same one-click catalog, same automated backups, same managed updates. The redesign is about reducing the number of clicks between intent and outcome, not changing what's underneath.
If you're already running services, log in and look around. The new sidebar grouping and the Tools tab are where most users will notice the difference first. If you're evaluating Elestio, the new create flow is the cleanest demo of what the platform does: pick a service from 400+, pick a region, get a running cluster with credentials, monitoring, backups, and a terminal in your browser.
Try it: elest.io. Feedback welcome.
Thanks for reading ❤️ See you in the next one 👋
Original source - May 11, 2026
- Date parsed from source:May 11, 2026
- First seen by Releasebot:May 11, 2026
How to Deploy Servers on Elestio with Claude (New MCP Connector)
Elestio launches MCP, letting users deploy and manage their Elestio account directly from Claude, ChatGPT, and any MCP-compatible AI agent. It streamlines self-hosted infrastructure by turning chat into action for deployments, backups, scaling, and credentials.
There's a moment when you're running self-hosted infrastructure where you realize you spend more time tabbing between the chat with your AI and the dashboard of your provider than actually building. You ask Claude how to set up WordPress in Frankfurt, it gives you a plan, you copy commands, you switch tabs, you fill forms, you wait. Multiply that by every project, every region, every redeploy.
We just shipped something that removes that loop entirely. Elestio MCP is now live at mcp.elest.io and lets you deploy and manage your entire Elestio account directly from Claude, ChatGPT, or any AI agent that speaks the Model Context Protocol. No more switching tabs. You describe what you want, the AI calls the API, the server boots.
This guide walks you through connecting it to Claude.ai in under two minutes and shipping your first deployment by simply asking for it.
What Elestio MCP actually unlocks
MCP (Model Context Protocol) is the open standard Anthropic released to let AI assistants talk to external services through structured tool calls. Once Claude is connected to Elestio MCP, it can do everything you would normally do in the Elestio dashboard, but through natural language.
Concretely, that means:
CAPABILITY | WHAT YOU CAN ASK
Deploy from the catalog | "Deploy a Postgres 16 cluster in Singapore on Hetzner"
Deploy your own code | "Deploy this GitHub repo with CI/CD on a 4-CPU node"
Manage existing services | "Trigger a backup, then resize my n8n instance"
Multi-region orchestration | "Spin up read replicas in 3 European regions"You get access to the full Elestio surface area: 9 cloud providers, 40 countries, 100 regions, the catalog of 400+ open-source applications, and your own frontend, backend, or agent code deployed via CI/CD. All from a chat window.
Step 1: Open the Connectors panel in Claude.ai
Inside Claude.ai, open Settings and pick the Connectors tab in the left sidebar. You'll already see a few built-in connectors (GitHub, Gmail, Google Calendar, Google Drive). We're going to add a custom one.
Scroll down and click Add custom connector.
Step 2: Add the Elestio MCP server
A small dialog appears. Fill it in like this:
- Name: elestio
- MCP server URL: https://mcp.elest.io
Leave the advanced settings alone. Click Add.
Claude will warn you that custom connectors come from third-party developers. That's correct, the connector is hosted by Elestio at the URL above, and you control which account it can touch.
Step 3: Authorize with your Elestio API token
Click Connect next to the new elestio entry. A browser tab opens on the Elestio authorization page asking for two things:
- Elestio email: the email you use on elest.io
- Elestio API token: copy it from your account security settings
Click Authorize. The page redirects back to Claude.ai and the connector now shows a green status. You can revoke access anytime from your account security settings.
That's the entire setup. Claude can now call Elestio.
Step 4: Deploy something by asking for it
Open a new conversation in Claude and type the kind of sentence you'd say to a colleague:
Can you deploy a WordPress on Elestio in Europe?
Claude reads your request, plans the work, and runs tool calls in parallel. In our test it did the following on its own:
- Loaded the WordPress template ID from the Elestio catalog
- Listed your existing projects to either reuse one or set up a new one
- Looked up European regions across the supported providers
- Picked a sensible VM size, confirmed the cost, and asked for go-ahead
Once you approve, the deployment fires and Claude streams progress back to you in plain English. A minute or two later, you have a running WordPress with HTTPS, automated backups, and a public URL. No dashboard tab opened.
Step 5: Pull credentials without leaving the chat
Once the service is up, the next thing you usually want is the URL, the admin login, and the password. Instead of opening the dashboard, ask Claude:
Can you give me my credentials please?
The connector pulls the secrets for the freshly deployed service and returns them inline: the public URL, the admin username, and the generated password. Click the URL, paste the credentials, you're in. The same prompt works for any service in the catalog, from databases to dashboards to internal tools.
This is the rhythm Elestio MCP unlocks. You don't break flow to look something up, you just keep talking.
Beyond WordPress: deploy your own code
The same flow works for code you wrote yourself. Point Claude at a GitHub repo and ask it to deploy with CI/CD. Elestio MCP wires up the build pipeline, sets the right environment variables, exposes the right ports, and gives you a redeploy hook on every push. Frontend, backend, AI agents: all the same flow.
It's not just Claude
Elestio MCP is provider-agnostic. The same https://mcp.elest.io endpoint works in:
- Claude.ai (Connectors, shown above)
- Claude Code and other Anthropic SDKs
- ChatGPT with custom MCP support
- Cursor, Continue, Zed, and any IDE that ships an MCP client
- Your own AI agent built on LangChain, LlamaIndex, or the official MCP SDKs
If your tool speaks MCP, it can drive Elestio.
Troubleshooting
"Authorize" loops back without connecting.
Your API token is wrong or revoked. Generate a fresh one in account security and retry.
Claude says it can't find a region.
Make sure the country you mentioned is one of the 40 supported. Try "Europe" or "Frankfurt" instead of a less common location.
Tool calls time out.
Long deployments (databases, big VMs) can take a couple of minutes. Claude will keep polling. If it gives up, ask it to "check the status of the latest deployment" and it will resume reporting.
You want to revoke access.
Visit your account security settings, find the Claude entry, click revoke. The connector in Claude will go red on the next call.
Try it
Spin it up in two minutes:
- Add https://mcp.elest.io as a custom connector in Claude.ai
- Authorize with your Elestio email and API token
- Ask Claude to deploy something
If you don't have an Elestio account yet, start a free trial. The MCP connector is included on every plan, no extra setup.
This is the version of self-hosted infrastructure we wanted to use ourselves: less clicking, more describing.
Thanks for reading ❤️
See you in the next one 👋
Original source
Curated by the Releasebot team
Releasebot is an aggregator of official release notes from hundreds of software vendors and thousands of sources.
Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.