Wise Global Solutions Support Downloads
Download now

Iron & Alloy 26.10.0 CTP Preview · Steel 26.10 · Available now

Your infrastructure.
Forged for
what comes next.

Turn the hardware you own into dependable private infrastructure. Wise Foundry brings compute, containers and fleet management together in secure, ready-to-run appliances that stay consistent and recover automatically.

Iron 26.10.0 CTP
Build
20261001T072646Z
Base
Alpine 3.24.2 · kernel 6.18.54-0-lts
Root hash
8cef887b0e5f3229…90

iron-26.10.0.iso · .raw · .ironupd

Steel 26.10.0 Release
Build
20261001T073020Z
Runs
Docker · Compose · API on :8443
Root hash
a179f5b770da8da0…08

steel-26.10.0.ova · .iso · .steelupd

Alloy 26.10.0 CTP
Build
20261001T073137Z
Runs on
Steel 26.10.0 · PostgreSQL 17
Manages
Iron hosts, their workloads and updates

alloy-installer-26.10.0.iso · .alloyupd

The Wise Foundry family

One foundation. Three products.

Start with what you need today and add more without changing foundations. Iron runs your servers, Steel gives automated containers a focused home, and Alloy brings the whole estate together.

CTP Preview

Turn every server into a secure home for virtual machines, system containers and Docker.

Install Iron like a hypervisor. Use the browser for everyday work and the on-machine console when you need direct access.

Version
26.10.0
Workloads
KVM virtual machines, LXC system containers, Docker and Compose stacks
Ships as
UEFI installer ISO, 16 GiB raw disk image, .ironupd update bundle
Manage
Foundry Console at https://<host>/ · Iron Console on the machine’s display or BMC, or a serial port when you turn one on · recovery console on :9443 before the agent starts
What Iron does →

26.10 · Available now

A purpose-built container appliance that turns infrastructure-as-code into running services.

Deploy Steel on Iron or any UEFI virtual machine. The API keeps deployments repeatable, while the web and VM consoles cover operations, backups and troubleshooting.

Version
26.10.0
Workloads
Docker containers and Compose stacks, with images, volumes and networks, created through the API only
Ships as
OVA in Iron's format (q35, UEFI, 2 vCPU, 2 GiB, qcow2 disk), installer ISO, .steelupd bundle
Manage
REST API and web console on :8443 · Steel Console on the VM console or serial port
Operate
Encrypted backups, support bundles, metrics, audit log, remote syslog
License
Apache License 2.0
What Steel does →

CTP Preview

Manage every Iron host, workload, network and update from one place.

The guided installer deploys Alloy in your Foundry environment. Enroll each host with a one-time code, then manage the estate from one place while each host remains in control.

Version
26.10.0
Manages
Enrolled Iron hosts in clusters: VMs, LXC and Docker containers, datastores, port groups and virtual routers
Ships as
Installer ISO with a Linux and a Windows wizard that deploys Alloy onto a Steel appliance on an Iron host, .alloyupd image pack
Manage
Web console and REST API on https://<alloy>/ · every call to a host signed and certificate-pinned
What Alloy does →

Security by design

Trust built into every boot

Security starts before the operating system. Each stage verifies the next and every core component is signed, so an unauthorized change stops the boot before it can take control.

  1. UEFI Secure BootFirmware checks the boot loader against the Foundry db key.
  2. systemd-bootSigned boot loader, built with Iron’s own changes, with boot counting and an A/B fallback.
  3. Signed UKIKernel, initramfs and Iron’s own parameters signed together as one file, carrying the update key.
  4. Signed image manifestThe boot loader’s stub verifies the slot’s Ed25519-signed manifest before the kernel starts, and the initramfs verifies it again.
  5. dm-verity rootA read-only EROFS root, every block checked against the hash the manifest names. No package manager in the base image.
  6. Health checkThe agent and its services must come up healthy before the boot is marked good.

Kernel boot options are yours to change, but the essentials that guard this chain can’t be overridden. Updates follow the same process: each signed bundle is verified before anything is written.

Updates without the anxiety

Move forward with a way back

Each host keeps the working release while the new one starts in a separate system slot. If its health checks fail, the host returns to the last working version and tells you what happened. A change to the kernel boot options is tried the same way, with the image’s defaults to fall back to.

Updates and rollbacks replace the system, not your configuration, application data or datastores.

Upgrade from installer media, the console, the API, a URL or the command line. Any earlier Iron or Steel release can move directly to the latest version.

Alloy handles updates across a fleet. It synchronizes trusted depots, checks hosts against your baseline and updates them one at a time. It also coordinates updates for Alloy and its Steel appliance.

IRON_ESP / loader / entriesDuring an upgrade
iron-26.10.0-b+2-1.conf On trial New version in slot B, its UKI and signed manifest beside it. Two boot tries left, waiting for iron-health.
iron-26.09.0-a.conf Good Previous version in slot A, still installed. systemd-boot falls back here automatically.
/persist  ·  /var Untouched Host configuration and workload data stay exactly as they were.

Release channels & support

Choose your release path

Use the rolling channel for the latest Wise Foundry features and community support, or choose an LTS build with additional testing and paid professional support.

Rolling releases

Get new features, improvements and fixes as they become available. Rolling builds include community support.

LTS builds

LTS builds receive additional testing and are available to professional-support customers who need a more predictable release cycle.

Professional support

Paid support includes LTS builds and direct help from Wise Global Solutions. The rolling channel remains available for community-supported deployments.

Wise Foundry Iron 26.10.0 · CTP Preview

Iron turns servers into infrastructure

Run virtual machines, system containers and Docker on one familiar platform. Iron keeps every host on a trusted release as your environment grows.

Manage each host in one place

Every Iron host includes a web console, so your team can manage it without deploying another server.

  • See health, performance, logs, events and audit history
  • Track long-running operations in Recent tasks
  • noVNC and serial consoles for VMs in the browser; shells for containers
  • Datastore browser with uploads, downloads, moves and folders
  • kSwitches, oSwitches, port groups and virtual routers, with automatic revert for management changes
  • Manage virtual machines, system containers and Docker in the same interface
  • Administrator, Operator and Read-only roles, plus custom roles scoped to guests, tags, datastores or port groups
  • A firewall tab on every VM and system container, and AppArmor profiles and denials under Manage
https://iron01.wisegs.local/vms/app01/summary
Foundry Console showing a Debian virtual machine's summary, with its power and move actions, the Summary, Hardware, Cloud-Init, Options, Firewall, Snapshots, Console, Monitor and Log tabs, its live console, resources and guest details, and the Navigator's list of virtual machines
A virtual machine's page, from the console's automated screenshot run against its mock API.

One screen from power-on to shutdown

Iron starts like the hypervisors your team already knows. The boot loader shows what it is about to load and counts down, with ENTER to boot and SHIFT+O to edit the boot options; any other key opens the boot menu, with the other slot and a rescue entry.

  • Every check is on the screen as it happens: the image manifest and its key, the root image, each plugin and who signed it, then each service as it starts
  • Warnings, such as text the firmware added to the command line, show in red and are reported in the host’s health
  • Restarting and shutting down use the same screen, naming each service as it stops and the workloads as they shut down
  • The display is the console by default. A serial console is a boot option, as a mirror or as the primary console
Iron's boot screen on a Wise Foundry Iron 26.10.0 host: the release and build, an HP ProLiant DL380 Gen9 with two Xeon processors and 756 GiB of memory on dark grey, and "libvirtd started successfully." on orange above a full-width bar of blocks that fills as the host starts
The boot screen, rendered at 80×25 from the Iron Console’s own screen code with a test host’s details, as its screen tests draw it. On the machine it fills the display.

Direct access at the machine

When the host is up, the Iron Console takes over where the boot screen was, in the same layout. From the physical screen, BMC or serial port, you can see the host’s hardware, health, services, storage and management addresses.

  • Use F2 to configure networking safely, run tests and enter maintenance mode
  • Roll back and reach logs or support information directly from the keyboard
  • Emergency shell and SSH are off by default and show a warning while enabled
  • Guided installer with install and upgrade modes, plus unattended answer files
Iron Console main screen of a Wise Foundry Iron 26.10.0 host in the boot screen's layout: its release, hardware, health, running services and mounted datastores on dark grey, and the addresses to manage it at, IPv4 and IPv6, on orange, with F2 and F12 in the footer
The Iron Console’s main screen, rendered from its own screen code with a test host’s details. F2 customizes the host, F12 shuts it down or restarts it.

Tune the kernel, keep the essentials

Kernel boot options are free-form text, edited in the Foundry Console under Manage › Advanced, in the Iron Console, from the command line or once at the boot menu. Presets fill in common settings, and every word is checked as you type.

  • Only the options that protect the boot are refused: Iron’s own parameters, what runs first, module signature enforcement and kernel lockdown
  • A change is tried like an update: after three failed boots the host falls back to the image’s defaults
  • Your options carry over to every update
  • The root’s trust no longer rides on the command line: it comes from the signed image manifest
Iron Console System Customization: an orange menu with Configure Management Network selected in a dark grey bar, then Restart, Test and Restore for the management network, Maintenance Mode, Rollback, Kernel Boot Options, Wise Foundry Alloy, Plugins, Troubleshooting Options, System Logs and Support Information, beside the management network's host name, address and VLAN on grey
System Customization, rendered from the Iron Console’s screen code with a test host’s details.

Virtual machines

libvirt QEMU/KVM with SeaBIOS or OVMF, TPM 2.0, q35, VirtIO, PCI and USB passthrough, cloud-init, virtiofs, snapshots and clones. Disk locks keep two hosts from ever running the same disk.

LXC containers

System containers from the linuxcontainers.org catalog, unprivileged by default, with qcow2 root disks on datastores, snapshots and clones. Debian, Ubuntu and other systemd distributions run their sandboxed services and service credentials under the container’s own AppArmor profile.

Docker & Compose

Create, edit, log, shell and monitor containers, or deploy Compose stacks with validation, pull progress and automatic rollback. Containers get their own addresses on port groups.

kSwitches & oSwitches

Kernel bridges with NIC teaming and LACP carry the krn management and storage adapters, over IPv4 and IPv6, or IPv6 alone for management. Open vSwitch oSwitches carry the VLAN port groups that VMs, LXC and Docker attach to.

Isolation by default

Every VM and system container gets its own stateful firewall and anti-spoofing, and runs under its own AppArmor profile; Docker containers are filtered and confined the same way. Your own AppArmor rules sit in custom files beside Iron's, so every fix Iron ships still arrives. Imported disk images are read by an unprivileged helper.

Virtual routers

Connect port groups with DHCP, DNS, source NAT, port forwards, floating addresses and static routes, each in its own network namespace.

Import & export

Import VMware, VirtualBox and standard OVF 1.x appliances from a datastore or URL, or a Proxmox vzdump backup of a VM or container, and export to OVA with VMDK or qcow2 disks. Iron-to-Iron moves keep every setting.

Datastores

Local directories, ext4 or xfs disks, and NFS shares (v3 to 4.2) for a shared ISO library, VM disks and container data.

Plugins

Signed, dm-verity protected layers that bring their own API endpoints and console pages, so a host carries no code for a feature it doesn’t have. A bad plugin set falls back to the last one that booted. The plugin SDK builds and signs your own.

Storage plugins

ZFS pools and datasets, NFS exports, iSCSI in both directions, with sessions bound to the adapters you choose and multipath across them, and a shared OCFS2 volume several hosts can mount at once — each installed only where it’s wanted.

Recovery & support

A recovery console on 9443 answers before the agent: pull a support bundle, read the logs, restart a service, disable a plugin or roll back on a host that hasn’t finished booting. Support bundles never include passwords, private keys, enrollment codes or container environments.

Hardware transcoding

Pick a render node from a list that names the card behind it, read from the PCI database on the host. Share one GPU across several containers or system containers.

Secure Boot

Images carry Foundry's Secure Boot keys, and each slot's signed image manifest is checked by the boot loader and again by the initramfs before the root opens. Put the firmware in setup mode and enroll the keys from the boot menu. Online updates signed with another key set are refused; move a host to another key set by upgrading from the ISO.

Access control

Local users, LDAP directories and OpenID Connect single sign-on, with TOTP second factors. Built-in and custom roles, each scoped to guests, tags, datastores or port groups. SSH and the emergency shell are off by default; SSH accepts only root with keys added in the console.

Backup & restore

Back up the host's configuration and sealed secrets with a passphrase, and restore it onto a fresh install or a different machine. Guests are exported or backed up incrementally through the API, by Alloy or your own scheduler.

Monitoring & alarms

Live and historical host metrics, hardware sensors, alarms with e-mail and webhook notifications, remote syslog and SNMP, plus an audit log of every change.

Maintenance & autostart

Put a host in maintenance mode before you work on it, and start again what it shut down when you leave. Guests start and stop in the order you set, with delays, when the host boots or shuts down, and every restart and power-off takes one path that finishes even when a serial port holds the console.

Ready for Alloy

Enroll a host with an Alloy code. The host pins Alloy's certificate and checks every signed call against Alloy's Ed25519 key. Alloy then shows the host with these very pages, and uses its API to move guests between hosts and back them up.

Wise Foundry Steel 26.10 · Available now

Steel makes automation operational

Steel gives automated container workloads a focused place to run, with the consistency and automatic recovery of the Foundry foundation.

From code to running containers

Every service is defined through the API, so each deployment is captured in code. Supply the OVA properties and the appliance starts ready for automation.

  • One consistent /api/v1 for containers, images, volumes and networks
  • Compose stacks as YAML at /api/v1/stacks, validated against the same safety rules
  • Bearer tokens stored as SHA-256 digests; browser sessions with CSRF protection
  • Upload, verify, apply and roll back signed .steelupd bundles over the API
  • The web console gives operators safe start-and-stop control without changing the declared configuration
  • The data disk grows at boot when you add space to it
alloy@ops — bashsteel01:8443
# Create a service container on a Steel appliance
$ curl -k -H "Authorization: Bearer $TOKEN" \
    -H 'Content-Type: application/json' \
    -X POST https://steel01:8443/api/v1/containers \
    -d '{"name":"dns",
         "image":"coredns/coredns:1.12.1",
         "network":"host",
         "restart_policy":"unless-stopped",
         "volumes":[{"type":"data","path":"/dns",
                     "destination":"/etc/coredns"}]}'

# Roll out a new Steel release, then reboot into it
$ curl -k -H "$H" -d '{"path":".../steel-26.11.0.steelupd"}' \
    https://steel01:8443/api/v1/updates/apply
$ curl -k -H "$H" -d '{"action":"reboot"}' \
    https://steel01:8443/api/v1/host/power
Examples adapted from the Steel README. A failed update reports rolled_back instead.

Appliance status at a glance

The VM console and serial port show Steel's version, virtual hardware, Docker health, services and management address. Alerts highlight anything that needs attention.

  • F2 sets the administrator password on first start, then opens System Customization
  • Configure Management Network: DHCP or static IPv4, DNS and host name, validated before anything changes
  • Configure Time: time zone and NTP servers
  • Troubleshooting Options: emergency shell, SSH and a management agent restart
Steel Console main screen of a freshly deployed Wise Foundry Steel 26.10.0 appliance: its build, virtual hardware, deployment slot, Docker running and services on grey, and the address to manage it at on blue, with F2 and F12 in the footer
The Steel Console of a freshly deployed 26.10.0 appliance, captured from its own display in QEMU and cropped to its text. It refreshes every 5 seconds.

Access for people and automation

Administrators use the web and VM consoles, additional accounts are managed through the API, and automation uses dedicated API tokens.

RoleCan
AdministratorEverything: containers, tokens, updates, power, host name, network, time, services, SSH, emergency and service shells
OperatorView, start and stop, create and remove containers
Read-onlyView the appliance and its containers

Container API

Create and recreate containers as tracked jobs, with the previous container restored if a recreate fails. Pull images, and manage data volumes and bridge networks; live logs, stats and specs. Script it from PowerShell with the WiseFoundry module.

Compose stacks

Deploy Compose projects as YAML with environment values. Create, update with rollback, start, stop, pull, down and delete, with per-service logs. Published images only.

Web console

Iron's layout with Recent tasks: host summary, host name, network and time, services, updates, and Start and Stop for containers and stacks. HTTPS on :8443.

Deployment

An OVA in Iron's format with deployment properties for host name, network, admin password and API token, or the UEFI installer ISO with unattended answer files. The data disk grows at boot.

Signed updates

A/B slots and Ed25519-signed .steelupd bundles. A new version is kept only once the agent and Docker are healthy; otherwise Steel rolls back on its own.

Backup & restore

Configuration and stack backups with optional AES-256 encryption and container data. Restores are staged and applied at the next boot, optionally keeping the network settings.

Monitoring & support

An hour of host metrics, logs, audit events and remote syslog. Support bundles leave out passwords, tokens, private keys and container environment values.

Secure by default

SSH and the emergency shell are off by default. Logins are rate-limited, host-network containers need an Administrator, and /persist is mounted noexec.

Alloy appliance

Alloy's stack runs as Compose services on a Steel appliance, and Alloy keeps that appliance up to date itself: from its Update Management, or from its installer when it upgrades Alloy.

Wise Foundry Alloy 26.10.0 · CTP Preview

Alloy makes many hosts feel like one

Alloy manages every Iron host in one place without taking control away from the host. Each action is authenticated, permissions are enforced, and every host remains independently manageable. Alloy is a CTP Preview and a proof of concept: ready to evaluate with Iron, not yet to run your estate.

One view of every workload

Alloy brings every host and workload into one inventory. Open a workload to use the same Foundry Console pages you see on its host.

  • Explore the same inventory by folder, host or workload type
  • The host's own tabs and toolbar, plugins' additions included
  • Migrate, move, organize and create templates from the same toolbar
  • An Alloy tab with the folder, identity, tags and desired state Alloy keeps
  • Every call signed by Alloy and checked against your own role before it reaches the host
https://alloy.wisegs.local/vms/hosts/iron01/vms/app01/summary
Wise Foundry Alloy showing its Virtual Machines inventory, folders of workloads from several Iron hosts, beside a virtual machine's page that is the Foundry Console's own, with Alloy's Migrate, Move to host, Move to folder and Create template actions and an Alloy tab added
A virtual machine in Alloy, from Alloy's automated screenshot run against a mocked API.

The whole fleet, down to each host

Open any host to see its own navigation and pages within the wider context of sites and clusters.

  • Sites, clusters and hosts in one tree, with counts
  • Each host's own summary, settings, monitoring, storage and networking
  • Enrollment, heartbeats, maintenance and evacuation on the host's Alloy page
  • One console for the estate, while each host remains independently manageable
https://alloy.wisegs.local/hosts/iron01/host
Wise Foundry Alloy's Navigator listing sites, clusters and hosts, with an Iron host's own Navigator tree opened under it, beside that host's summary page with its version, health, hardware, configuration and workloads
An Iron host in Alloy, from the same screenshot run.

Enrollment

Enroll a host with a single-use code from its own console. The host pins Alloy's certificate and verifies every call against Alloy's Ed25519 key; Alloy pins the host's in return, and key rotation and certificate re-issue need no re-enrollment.

One inventory

Every host's VMs, LXC and Docker containers in one tree, by host, by kind or in folders that span hosts, with tags, sites and search. Create, start, snapshot, clone, edit and delete them from the same pages.

Moves & maintenance

Live-migrate machines and move containers between hosts in a cluster, with CPU and shared-storage checks first. Put a host in maintenance, or evacuate everything on it to the rest of its cluster.

Consoles

Graphical and serial consoles for VMs, Console, TTY and Shell for LXC, and exec for Docker, through Alloy's own session. Alloy signs the upgrade and passes the frames through untouched.

Storage & networking

Datastores and the datastore browser for every host, and a new NFS datastore on the hosts you choose. Port groups, oSwitches and virtual routers across a cluster, with the hosts where a name is missing or disagrees.

Policy & guardrails

Resource pools and quotas, cluster admission, affinity rules and approval policies, checked before any host is asked. Admission is checked under a lock, so two requests can’t both take a host’s last room. Batch moves and evacuations wait for an approver, and a new workload joins its affinity rules as it’s created.

Resource balancing

Alloy measures each cluster member’s sustained load and recommends moves that even it out, each explained against capacity, affinity, maintenance and quotas. Apply them yourself, or let the policy apply them inside its windows, within its budgets and cooldowns. Containers move cold only when the policy opts in.

Templates & vApps

A content library of templates and OVAs, deployed onto the host you pick, and vApps that start and stop groups of guests in order with health checks.

Scheduled backup

Scheduled, incremental backups of VMs and LXC containers to backup storages, with pruning, verification and restores.

Update policy

Depots, baselines and compliance for Iron hosts, Alloy itself and the Steel appliance it runs on. Every bundle is verified against the Wise Global Solutions signature before a host applies it.

Access & audit

Users, roles scoped to hosts, folders and tags, API tokens, LDAP and single sign-on, with Alloy’s own TOTP second factor for directory and single sign-on accounts too, and an audit log of every action and host call. Manage the estate from PowerShell with the WiseFoundry module.

Health & alerts

Alloy watches its hosts and itself: heartbeats, host alarms and its own service checks raise alerts, with acknowledgement, silences, and e-mail or webhook delivery.

Guided installer

One ISO with a Linux and a Windows wizard installs Alloy onto a Steel appliance on an Iron host, restores it from a backup, or upgrades it, and updates the appliance under it too. Install, upgrade and restore are tested end to end on Steel appliances.

Recovery targets

Guests and the host jobs Alloy started keep running while it’s away. Documented targets: 5 minutes to bring the API back, 30 to restore on the same appliance, 2 hours onto a fresh one, and the backup interval, 24 hours by default, as the recovery point. Alloy itself has no high availability.

Offline updates

Import a release without the update share: choose the offline bundle in Update Management, pick the updates and plugins to take from it, and each is checked like any other upload.

Built on proven technology

Open components, carefully integrated

Wise Foundry combines proven open-source technology in a repeatable, rootless build. Versions are pinned, and the components remain open to inspection.

The technology behind Wise Foundry

  • Alpine Linux
    Alpine LinuxThe small, secure base under Iron and Steel.
  • KVM
    KVMThe Linux kernel hypervisor that runs Iron's virtual machines.
  • libvirt
    libvirtManages Iron's QEMU/KVM guests and LXC system containers.
  • Docker
    DockerRuns containers and Compose stacks on Iron, and every service on Steel.

Alpine Linux, KVM, libvirt and Docker are trademarks of their respective owners. Wise Foundry isn't affiliated with or endorsed by these projects.

System

  • Alpine Linux3.24.2 · musl
  • Linux LTS kernel6.18.54
  • systemd-boot + UKIsigned
  • EROFS + dm-veritysha256
  • OpenRC servicesinit.d
  • Ed25519 signaturesbundles · manifests
  • AppArmorguests · daemons

Workloads

  • QEMU / KVMlibvirt
  • libvirt LXCunprivileged
  • Docker Engine+ Compose
  • OVMF + swtpmUEFI · TPM 2.0
  • virtiofsd · NBD · qcow2storage
  • Open vSwitch · nftablesoSwitches
  • dnsmasqvirtual routers
  • NFSv3 – v4.2

Agents & consoles

  • Go agentsgo 1.26
  • go-libvirt · bboltstate
  • Bubble Tea TUIIron Console
  • React + TanStack Query19.3 · 5
  • xterm.js · noVNC6.0 · 1.7
  • Vite · Vitest · Playwrightbuild + test

Alloy

  • PostgreSQL17
  • Node.js + Fastify22
  • nginxTLS · CSP
  • Docker Composeon Steel
  • Electroninstaller wizards
  • Iron's consoleembedded

Find your fit

Choose the product that fits

The products share the same Foundry foundation. Use Iron on your servers, Steel for automated containers, and Alloy to manage multiple Iron hosts.

Feature Iron Steel Alloy
The product
What it isThe bare-metal host OSThe container applianceThe fleet manager
StatusCTP PreviewAvailable nowCTP Preview
Runs onA UEFI serverIron or any UEFI VMA Steel appliance on Iron
Ships asInstaller ISO, raw disk, .ironupdOVA, installer ISO, .steelupdInstaller ISO, .alloyupd
Workloads
KVM virtual machines✓–On its hosts
LXC system containers✓–On its hosts
Docker containers and Compose stacks✓✓On its hosts
Signed plugins (ZFS, iSCSI, NFS export and more)✓–From its depots
The appliance
Secure Boot and a dm-verity root✓✓On Steel
Signed A/B updates with automatic rollback✓✓With a backup before
Web console✓✓✓
Console on the machine's own screen✓✓Steel's
REST API with OpenAPI✓✓✓
Roles, API tokens, LDAP and single sign-on✓Roles and tokens✓
The fleet
Many hosts in one console––✓
Live migration and moves between hostsWith Alloy–✓
Scheduled, incremental guest backupWith Alloy–✓
Update baselines and compliance––✓
Quotas, affinity rules and approvalsQuotas per host–✓
Resource balancing recommendations––✓

Downloads

Get Wise Foundry and its tools

Iron and Alloy are available as CTP Previews, and Steel is ready for production. Each product supports trusted, in-place upgrades.

Iron 26.10.0

CTP Preview

Download the ISO

Iron brings virtual machines, LXC, Docker and Compose into one console, with flexible networking and storage, access controls, recovery tools and signed in-place upgrades. Install it on a spare server or nested VM and tell us what you think.

FileUse it to
iron-26.10.0.isoInstall from CD or USB on a UEFI server, or upgrade an existing host
iron-26.10.0.rawStart from a pre-installed 16 GiB disk with slot A ready
iron-26.10.0.ironupdUpgrade a running host from the console or iron-update apply
iron-26.10.0.txtCheck the build ID, root hash and SHA-256 checksums
iron-26.10.0.keys-summary.txtCompare the signing key fingerprints and Secure Boot db before you enroll

New in 26.10.0

  • A signed image manifest for each slot, verified by the boot loader before the kernel starts and again by the initramfs before the root opens
  • Free-form kernel boot options in Manage › Advanced and the Iron Console, with presets, protected essentials and a fallback to the defaults
  • New boot loader screen and menu, boot and shutdown screens, and the Iron Console in the same layout
  • The display is the default console; a serial console is a boot option
  • IPv6-only management, and iSCSI sessions bound to adapters with multipath across them
  • Restarts complete even when a serial port holds the console output

Before you install

  • Manage each host from its own Foundry Console, or enroll it with the Alloy preview to manage many together.
  • Enrolling only Iron's Secure Boot keys can stop Microsoft-signed option ROMs from loading. Make sure you can reset the firmware to setup mode, or install with Secure Boot off.
  • Online updates signed with another key set are refused. To move a host to another key set, upgrade from the ISO: the installer warns first, and Secure Boot then needs turning off or the new keys enrolled. Signed plugins need reinstalling.
  • Moving guests between hosts and scheduled backups are driven by Alloy. On its own, a host exports a guest when you ask it to.
  • There's no HA or replication, and guest Secure Boot hasn't been tested.
  • SSH and same-version build upgrades aren't covered by the automated test suites.
  • Almost every automated test runs on KVM guests under QEMU; Iron’s testing guide describes each suite and what it proves. Six physical servers have run Iron 26.09.0 as hosts, all Intel: an HP ProLiant DL380 Gen9, two Dell PowerEdge R720s, a Dell PowerEdge R250, an HP Z2 Mini G4 and an MSI Z490 board. AMD hosts are expected to work but haven’t been tested.
  • iSCSI binding and multipath have been tested over two virtual paths, not yet against a real SAN. The installer and the Iron Console still configure IPv4; switch to IPv6-only management from the Foundry Console or the API.

Steel 26.10.0

Release · Apache 2.0

Download the ISO Download the OVA

Steel runs automated container workloads through a focused container and Compose API. It also includes operator consoles, backup and recovery, monitoring, support tools and signed updates with automatic rollback.

FileUse it to
steel-26.10.0.ovaDeploy on Iron with the deployment wizard, with deployment properties
steel-26.10.0.isoInstall on any UEFI VM or machine (at least 8 GiB), or upgrade a Steel disk
steel-26.10.0.steelupdUpgrade a running appliance over the API, in the web console or with steel-update apply
steel-26.10.0.txtCheck the build ID, root hash and SHA-256 checksums
steel-26.10.0.keys-summary.txtCompare the signing key fingerprints

Good to know

  • The OVA uses Iron's format with a qcow2 disk, so importers that don't understand the Foundry OVF extension refuse it. On other hypervisors, install from the ISO.
  • Containers and stacks are created through the API only. The web console starts and stops them but never changes them.
  • Bundles signed with another key set are refused. To move an appliance to another key set, upgrade from the ISO: the installer warns first, and Secure Boot then needs turning off or the new keys enrolled.
  • Steel doesn't check for updates on its own. You decide when to install a bundle.
  • The appliance Alloy runs on is updated by Alloy: from its Update Management, or by the Alloy installer when it upgrades Alloy.

Alloy 26.10.0

CTP Preview

Download the ISO

The Alloy preview puts hosts and workloads in one inventory, with migration, maintenance, resource balancing, cluster-wide storage and networking, policy, templates, backup and coordinated updates. It is a proof of concept: deploy it with the Iron preview, enroll a few hosts and tell us what you think.

FileUse it to
alloy-installer-26.10.0.isoInstall Alloy onto a Steel appliance on an Iron host, upgrade a running Alloy and the appliance under it, or restore one from a backup. The ISO carries the Linux and Windows wizards, the Steel OVA and update bundle, and Alloy's images
alloy-26.10.0.alloyupdUpgrade a running Alloy from its own Update Management
wisefoundry-26.10.0.off.zipImport this release’s Iron, Steel and Alloy updates and Iron plugins into Alloy without the update share

New in 26.10.0

  • Resource balancing: recommendations first, with windows, budgets and cooldowns, and cold moves of containers only when a policy opts in
  • Admission checked under a lock; approvals for batch moves and evacuations; affinity rules joined at create
  • Alloy’s own TOTP for directory and single sign-on accounts
  • Documented recovery targets (RTO and RPO), and restore from the console
  • Install, upgrade and restore tested end to end on Steel appliances, and more end-to-end steps against two Iron hosts

Before you install

  • Alloy needs an Iron 26.10.0 host to run on, and manages Iron hosts only. Steel appliances are updated from Alloy but not enrolled as hosts.
  • End-to-end tests run Alloy against two real Iron hosts in QEMU, with real directory, single sign-on and Prometheus servers beside it. vApps and moves of the host Alloy itself runs on haven't been run against real hosts yet, and nothing has run against a fleet of physical servers.
  • There's no high availability for Alloy itself, and none for guests. Back it up from its console or on a schedule; restore from the console, or with the installer onto a new appliance.
  • Hosts keep working without Alloy: each one still has its own Foundry Console, and leaving Alloy is a click on the host.

Developer tools

Preview

Download the plugin SDK Download the PowerShell module

The plugin SDK lets you write, sign and check Iron plugins, including their API endpoints and console pages, without Iron's source. The WiseFoundry PowerShell module manages Iron hosts, Steel appliances and Alloy from one shell, in the style of PowerCLI.

FileUse it to
iron-plugin-sdk-26.10.0.tar.zstBuild Iron 26.10.0 plugins in a container: podman load -i it, then iron-plugin-sdk new, build, keygen and inspect
WiseFoundry.0.1.0.nupkgInstall with Install-PSResource from a local repository, then Connect-FoundryServer to a host, an appliance or Alloy

Before you start

  • The SDK builds for one Iron release: build your plugin again with each release's kit. It needs podman or Docker.
  • To publish a signed plugin, request a vendor certificate from Wise Global Solutions with the file iron-plugin-sdk keygen writes. Unsigned plugins install only when a host is told to allow them.
  • The PowerShell module needs PowerShell 7.2 or later on Linux, macOS or Windows. Its tests check every call against the products' own APIs, but it hasn't yet been run against live hosts.

Questions about the Iron and Alloy previews or deploying Steel?

Contact Wise Global Solutions