Documents, AI, operations and SvelteKit 3
The first tagged release, and the first one to upgrade from. Start with Breaking in CHANGELOG.md.
- Upgrades follow release tags.
UPGRADING.mdstarts you on the newest release and renames each one on akit-renamedbranch beforemainmerges it, so a renamed fork conflicts only where you and the release changed the same lines. This release carries four migrations. Three need steps before you deploy (see Breaking), andbun run db:migrateapplies whichever your database lacks. - Licence 1.1.
LICENSE.mdnames the two licences sold, Solo (one Invited Account) and Team (up to five, plus a 45-minute onboarding call). Purchases from 8 October 2026 get an Update Period of 12 months from the purchase; earlier ones keep the update terms they were sold with. - SvelteKit 3. The web app runs on SvelteKit 3.0.1 and Svelte 5.57.2.
$libis now#lib, environment variables are declared inapps/web/src/env.ts, and an installed Node.js must be 22.17 or newer.UPGRADING.mdlists the changes your own code needs. - Documents, jobs and AI. Presigned uploads to local disk or S3/R2/MinIO, a Postgres job queue that runs inline or as a separate worker, an AI-credit ledger, and Documents and Jobs pages. The FastAPI service extracts text (with OCR), summarizes and embeds, locally or through any OpenAI-compatible endpoint. Workspaces get pgvector search and storage quotas.
- A home page.
/appshows a getting-started checklist that hides once every step is done: verify the address and add a passkey or two-factor authentication. It also shows the organization’s member and AI-credit counters and its workspaces, and the checklist asks for a first workspace and an invited teammate too. - Setup.
bun run setupwrites every local.env,bun run doctorchecks prerequisites and configuration,bun run verifyruns lint, typecheck and test in CI’s order, andbun run renamerenames the kit to your product.QUICKSTART.mdis the one setup guide;AGENTS.mdgives coding agents the layout, the commands and the rules the code relies on.bun run seedloads demo data: an organization, a team, workspaces, documents and jobs. - Operations. A provisioning script for a fresh VPS, GHCR images, SOPS-encrypted secrets,
nightly backups with an off-box copy and a restore drill, and a runbook. Deploys are opt-in
(set
DEPLOY_ENABLEDtotrueif you already deploy from Actions), wait for CI to pass, keep no deploy key or token on the server, and can be recovered after an interrupted rollout. Requests get structured logs and OpenTelemetry traces. - Public demo mode.
PUBLIC_DEMO_MODEadds a demo banner and anoindextag, andinfra/demoruns a demo next to production on the same host. Uploads, search, starting or retrying jobs and billing actions are refused, and “Enter the demo” builds each visitor a private sample organization, so nothing one visitor does reaches the next. - Security. Forged requests are refused on
/rpcand/api/v1, the app’sscript-srchas no'unsafe-inline', request bodies are bounded at every layer, failed queries no longer log their parameters, and backups verify what they restore. An account can no longer get past plan limits by owning more organizations. - Billing. Entitlement ends three days past the period end, or after the dunning window once a payment is past due; a daily job reconciles subscriptions with Stripe; a downgrade below current usage is refused; webhook deliveries are deduplicated; the pricing page’s plan reaches checkout.