Releases
Release artifacts, digest pinning, versioning, deprecations, and known limitations for Orca AI Gateway.
Current release
0.4.3, published 2026-09-29, is the latest stable release and the version used by the installation guides. It updates provider pricing, preserves mid-conversation system messages, and publishes the Helm chart to an OCI registry.
Artifacts
Orca AI Gateway ships as a Docker image and an OCI Helm chart:
| Artifact | Detail |
|---|---|
| Container image | docker.io/streamnative/orca-ai-gateway:0.4.3, also published as ghcr.io/orca-ae/orca-ai-gateway:0.4.3. Multi-arch linux/amd64 and linux/arm64, based on debian:13-slim, runs as the non-root UID 65532. |
| Helm chart | oci://ghcr.io/orca-ae/charts/orca-ai-gateway, version 0.4.3 |
See Install for the commands.
Verifying artifacts
Pin the image by digest rather than tag where supply-chain integrity matters. The multi-platform
image digest, the same on Docker Hub and GHCR, is
sha256:739819bbc2f50ba3436609f02bec01f79c59fe8e5a8a09af185b987a9059dc1d. The OCI chart
digest is sha256:6f2e00d6db13cc47f8815cd38f4462b6db16f18607e8d0abff3f41f2567ebf1a.
The Docker Hub image is signed with cosign and carries SPDX SBOM and SLSA provenance attestations.
Versioning
Published releases are on the 0.x line. Pin the exact release tag or image digest when deploying.
Deprecations
These are deprecated. Move to the replacement:
| Deprecated | Replacement |
|---|---|
POST /mcp | POST /v1/mcp |
The legacy_mcp_gateway: config block | The modern configuration shape |
See Migrate for the rewrite.
Known limitations in the current release
Release 0.4.3 has these limitations:
- Agent-session endpoints return
501. - The WebAssembly plugin host is not started by the shipped binary, so plugin installation returns
503. - Native API-key proxying requires an explicit destination, route, and upstream path allowlist; model discovery still returns an empty list.
- File and Postgres config changes do not rebuild the running data plane; restart after a change.
- Live request paths do not emit signed tapes, even when a
signed_tapeexporter is configured. tape replayprints a recorded tape rather than re-issuing the call.- Only the plugin kinds listed in the configuration reference are supported.