Cloud and BYOC for Orca Agent Engine are in Private Preview — request an invite
Docs

Releases

Release artifacts, digest pinning, versioning, deprecations, and known limitations for Orca AI Gateway.

Current release

0.4.3, published 2026-09-29, is the latest stable release and the version used by the installation guides. It updates provider pricing, preserves mid-conversation system messages, and publishes the Helm chart to an OCI registry.

Artifacts

Orca AI Gateway ships as a Docker image and an OCI Helm chart:

ArtifactDetail
Container imagedocker.io/streamnative/orca-ai-gateway:0.4.3, also published as ghcr.io/orca-ae/orca-ai-gateway:0.4.3. Multi-arch linux/amd64 and linux/arm64, based on debian:13-slim, runs as the non-root UID 65532.
Helm chartoci://ghcr.io/orca-ae/charts/orca-ai-gateway, version 0.4.3

See Install for the commands.

Verifying artifacts

Pin the image by digest rather than tag where supply-chain integrity matters. The multi-platform image digest, the same on Docker Hub and GHCR, is sha256:739819bbc2f50ba3436609f02bec01f79c59fe8e5a8a09af185b987a9059dc1d. The OCI chart digest is sha256:6f2e00d6db13cc47f8815cd38f4462b6db16f18607e8d0abff3f41f2567ebf1a.

The Docker Hub image is signed with cosign and carries SPDX SBOM and SLSA provenance attestations.

Versioning

Published releases are on the 0.x line. Pin the exact release tag or image digest when deploying.

Deprecations

These are deprecated. Move to the replacement:

DeprecatedReplacement
POST /mcpPOST /v1/mcp
The legacy_mcp_gateway: config blockThe modern configuration shape

See Migrate for the rewrite.

Known limitations in the current release

Release 0.4.3 has these limitations:

  • Agent-session endpoints return 501.
  • The WebAssembly plugin host is not started by the shipped binary, so plugin installation returns 503.
  • Native API-key proxying requires an explicit destination, route, and upstream path allowlist; model discovery still returns an empty list.
  • File and Postgres config changes do not rebuild the running data plane; restart after a change.
  • Live request paths do not emit signed tapes, even when a signed_tape exporter is configured.
  • tape replay prints a recorded tape rather than re-issuing the call.
  • Only the plugin kinds listed in the configuration reference are supported.

On this page