. Useful overrides include:
```bash
PORT=8080 RESOLUTION=1600x900 make up
+PLATFORM=linux/arm64 make build
DOCKER=podman make up
```
+The Makefile selects `linux/amd64` or `linux/arm64` from the host by default.
+
`make stop` removes the node container but preserves its named volumes.
## Pinned components
@@ -308,9 +312,12 @@ DOCKER=podman make up
| Codex ACP adapter | `1.1.7` |
| Claude ACP adapter | `0.62.0` |
-The Buzz `.deb` and Goose archive are SHA-256 verified during the image build.
-Only the required headless Buzz binaries are extracted from the `.deb`; the
-package and its desktop application are not installed.
+On AMD64, the Buzz `.deb` and Goose archive are SHA-256 verified during the
+image build. Only the required headless Buzz binaries are extracted from the
+`.deb`; the package and its desktop application are not installed. Upstream
+does not publish a Linux ARM64 package, so ARM64 builds compile only those
+headless tools from the pinned tag after verifying its exact Git commit. The
+ARM64 Goose archive is independently SHA-256 verified.
## Persistence
@@ -329,8 +336,13 @@ Buzznode is a trusted, single-user workstation:
- the saved agent private key can act as that agent;
- KasmVNC browser authentication and TLS are disabled;
- the `agent` user has passwordless sudo;
-- coding agents can operate on `/workspace`; and
-- browser sessions and agent credentials persist in volumes.
+- coding agents can operate on `/workspace`;
+- browser sessions and agent credentials persist in volumes; and
+- Codex runs with `sandbox_mode = "danger-full-access"`, because its bubblewrap
+ sandbox cannot create a user namespace inside a container, so no sandbox mode
+ is enforceable here whatever is configured. The setting states what is true
+ rather than implying a boundary that does not exist; the boundary is the
+ container. Override with `BUZZNODE_CODEX_SANDBOX_MODE`.
The provided Makefile binds the desktop to `127.0.0.1`. Keep that default, or
put Buzznode behind authentication, TLS, and suitable network controls. Never
diff --git a/RELEASES.md b/RELEASES.md
index 0b4af53..809f668 100644
--- a/RELEASES.md
+++ b/RELEASES.md
@@ -22,8 +22,12 @@ Existing tags and releases are never replaced.
Stable releases publish `vX.Y.Z`, `X.Y.Z`, `X.Y`, and `latest`. Prereleases
publish versioned tags without moving `latest`.
-The image is OCI-compatible and currently targets `linux/amd64`, because the
-upstream Buzz desktop package is only available for that architecture.
+Each tag is a multi-architecture image supporting `linux/amd64` and
+`linux/arm64`. Docker selects the matching image automatically. CI builds and
+smoke-tests each architecture on a native GitHub-hosted runner before the
+release workflow combines their digests into one manifest. Upstream publishes
+its Linux package only for AMD64, so the ARM64 image builds the same pinned
+headless Buzz tools from the exact tagged source commit.
After the first publication, make the GHCR package public in GitHub package
settings if anonymous pulls should be allowed.
diff --git a/VERSION b/VERSION
index 6e8bf73..0ea3a94 100644
--- a/VERSION
+++ b/VERSION
@@ -1 +1 @@
-0.1.0
+0.2.0
diff --git a/browser/index.html b/browser/index.html
index 33d8e5f..1f02467 100644
--- a/browser/index.html
+++ b/browser/index.html
@@ -3,13 +3,12 @@
- Buzznode
+ Buzznode Browser
-
- Buzznode
-
- This is a persistent desktop for one agent connected to an existing Buzz
- workspace.
-
-
- Open a terminal and run buzznode setup to connect it, or
- buzznode status to inspect it.
-
-
+
+██████╗ ██╗ ██╗███████╗███████╗███╗ ██╗ ██████╗ ██████╗ ███████╗
+██╔══██╗██║ ██║╚══███╔╝╚══███╔╝████╗ ██║██╔═══██╗██╔══██╗██╔════╝
+██████╔╝██║ ██║ ███╔╝ ███╔╝ ██╔██╗ ██║██║ ██║██║ ██║█████╗
+██╔══██╗██║ ██║ ███╔╝ ███╔╝ ██║╚██╗██║██║ ██║██║ ██║██╔══╝
+██████╔╝╚██████╔╝███████╗███████╗██║ ╚████║╚██████╔╝██████╔╝███████╗
+╚═════╝ ╚═════╝ ╚══════╝╚══════╝╚═╝ ╚═══╝ ╚═════╝ ╚═════╝ ╚══════╝