Releases: HenkVanHoek/sovereign-stack
Releases · HenkVanHoek/sovereign-stack
v3.6.1 - The Sovereign Guard Release
Summary
This release marks the transition of the Sovereign Stack from a private laboratory project to a public, security-hardened blueprint. Optimized specifically for Raspberry Pi 5 with NVMe storage, this version introduces robust automation, integrity verification, and long-term maintenance utilities.
Key Features & Improvements
🛡️ Security & Resilience
- Sovereign Guards: Implemented
flockfile-locking andverify_env.shto prevent overlapping processes and ensure all secrets are present before execution. - JIT Dependency Management: Scripts now feature Just-In-Time installation for missing system tools like
wakeonlanandmsmtp. - Hardened Permissions: Automated
600permission enforcement for.envfiles and root-execution prevention. - Legal Compliance: Integrated GPLv3 license headers and documentation footers across the entire repository.
🚀 Hardware Optimization (M.2 NVMe)
- Re-engineered I/O operations to leverage the speed of M.2 SSDs on Raspberry Pi 5.
- Performance: Verified high-speed integrity checks on NVMe hardware with a successful 03:00/03:30 backup cycle.
🖥️ Windows & Remote Integration
- Enhanced
monitor_backup.shwith Windows-aware pathing andif existlogic for remote integrity checks. - Standardized remote transfer via secure
sftpwith automated Wake-on-LAN (WOL) support.
📚 Documentation & Maintenance
- Maintenance Guide: New
MAINTENANCE.mdincluding a 5-chapter guide on storage hygiene and update strategies. - Cleanup Utility: Introduced
clean_stack.shto automate Docker pruning and system update checks. - Interactive Wizard: Enhanced
INSTALL.shsetup wizard for automated environment configuration.
Technical Note
This release uses a 30-minute window between the backup pipeline (03:00) and the integrity monitor (03:30). In live tests on NVMe hardware, full backup and remote verification were completed in under 5 minutes.