Release notes v0.0.1
This is the initial release of Sekoia Self-Hosted (MVP), introducing the core deployment and operational foundation for air-gapped and regulated environments. This article covers the feature scope, functional constraints, known issues, and support lifecycle for this version.
What's new
- Air-gap deployment support. You can deploy and operate the full platform in restricted or fully disconnected environments with no external connectivity.
- Self-Hosted Controller (SHC). A unified orchestration CLI to install, configure, diagnose, and manage the platform lifecycle.
- Built-in observability. Grafana, Prometheus, Loki, Alertmanager, and Promtail are deployed as part of every installation.
- Built-in diagnostics. On-demand health checks for cluster nodes, ArgoCD applications, databases, secrets, and resource allocation.
Technical foundation
| Attribute | Value |
|---|---|
| Kubernetes distribution | K3s |
| Certified node OS | Debian 11 (Bullseye) |
| GitOps engine | ArgoCD |
| Secret management | HashiCorp Vault |
| Relational database | PostgreSQL via CloudNativePG |
| Columnar storage | ClickHouse |
| Observability stack | Grafana, Prometheus, Loki, Alertmanager |
Functional scope
The functional scope aligns with the Defend Core subscription tier. Defend Core includes the core SIEM and detection capabilities: event ingestion, detection rule evaluation, case management, playbooks, threat hunting, dashboards, and user management.
| Feature | Available | Notes |
|---|---|---|
| Meta-playbooks | Yes | |
| OC Notifications | Yes | |
| Observable Tags Enrichment | No | Requires live CTI connectivity. Not available in air-gapped environments. |
| Cloud-to-Cloud Ingestion | No | Not supported in air-gapped deployments. |
| Encrypted ingestion (Syslog TLS, RELP TLS, HTTPS) | Yes | |
| Custom Intake Formats | Yes | |
| Sigma Correlation | Yes | |
| Playbooks | Yes | |
| Automatic Asset Discovery | Yes | |
| Retrohunt | Yes | |
| Anomaly Detection Engine | Yes | |
| Case Management | Yes | |
| Hot Storage | Yes | |
| Sekoia Endpoint Agent | Yes | |
| Contextualized Alerts | No | Requires live CTI. Not available in air-gapped environments. |
| SOL Query Builder | Yes | |
| Detection Rules | Yes | Full rules catalog embedded in the release. |
| Event Drop Detection | Yes | |
| Cases Custom Status | Yes | |
| Investigation Graph | Yes | |
| Notebooks | Yes | |
| Sigma Pattern Validation | Yes | |
| SOL Dataset | Yes | |
| Dashboard Filters | Yes | |
| Roy Assistant | No | AI assistant. Not compatible with air-gapped environments. Requires GPU and cloud connectivity. |
| Dashboards | Yes | |
| APIs | Yes | Full programmatic access. |
| Member Management | Yes | RBAC and user administration. |
| SSO / MFA | Yes | OpenID Connect compatible. |
| Usage Reporting | Yes | |
| Subscription Management | Yes | |
| Region Threat Telemetry | Yes |
Air-gapped environment constraints
Threat intelligence
The Threat Intelligence (CTI) research module is not available in air-gapped deployments because it requires live cloud connectivity for manual threat actor and observable exploration.
Detection capabilities remain fully operational. All Sekoia detection rules and integration connectors are embedded in every release.
Sekoia Forwarder
The Sekoia Forwarder supports disconnected deployments but is an optional add-on not included in the standard release. Its packaging, delivery, installation, and upgrade process are managed per customer. Contact Sekoia if your deployment requires a Forwarder.
Known issues and limitations
The following issues do not occur systematically. They are intermittent and may not affect every deployment.
| Issue | Impact | Workaround |
|---|---|---|
| No upgrade path documented | You cannot upgrade from v0.0.1 to a future version via the SHC. | An upgrade procedure will be provided in the next release notes. |
| No UI for platform administration | Infrastructure management is CLI-only. | Use the SHC CLI and config.yml for all administrative operations. |
| Automatic upgrade and rollback not available | Version updates are manual. | Follow the manual update procedure when a new release is published. |
| Content update UI not available | Detection rules and intake format updates require a new release. | Intelligence updates are delivered daily via the signed release mechanism. |
| Backup restore not yet documented | You cannot perform a tested restore from backup. | Contact Sekoia support for restore guidance specific to v0.0.1. |
| ArangoDB provisioning failure on first install | Platform installation fails intermittently at the ArangoDB step. |
Wait 1 hour for auto-recovery, then follow the ArangoDB troubleshooting procedure. |
| "Customer does not exist" error when creating an Entity | Creating a new Entity fails intermittently with a "Customer does not exist" error in the interface. | Navigate to Settings > General, edit the community description, and save. Wait a few minutes for the re-initialization to complete. See Common issues. |
Related links
- Technical requirements: Hardware and network prerequisites.
- Deploy the platform: Step-by-step installation instructions.