aim-web2.1.0rc9
This commit is contained in:
@@ -0,0 +1,556 @@
|
||||
# Changelog
|
||||
|
||||
## 2.1.0rc9 - Core 3.3.0rc8 release reconciliation
|
||||
|
||||
Compatibility: separately deployed Core 3.3.0rc8; public service/wire/event 1.0; WebGUI HTTP v2; SQLite schema 5 unchanged.
|
||||
|
||||
- Repackage the rc8-compatible WebGUI line as rc9 after reconciling current-release metadata, operator guidance and verification evidence with the supplied Core 3.3.0rc8 archive.
|
||||
- Preserve the rc8 public contract and live capability gates, including `ansible.windows >=3.8.0,<4.0.0`, `play_task_host_v1`, `inventory_hierarchy_v1`, `target_outcome_summary_v1`, `native_defaults_preflight_v2` and structured operation results.
|
||||
- Remove stale current-candidate rc4/rc5 labels from active documentation while retaining historical release notes and historical Core reviews as provenance.
|
||||
- Refresh release verification against the supplied rc8 source tree; no Core files, database schema, service API, permission model, credential model or execution semantics are changed by this repackaging.
|
||||
- Correct a stale legacy rollback comment (`rc18-only`) to describe the actual pre-2.x adapter boundary; runtime behavior is unchanged.
|
||||
|
||||
## 2.1.0rc5 - Core 3.3.0rc8 compatibility
|
||||
|
||||
Compatibility: separately deployed Core 3.3.0rc8; public service/wire/event 1.0; WebGUI HTTP v2; SQLite schema 5 unchanged.
|
||||
|
||||
- Requalify the exact adapter/executor/deployment gates for Core 3.3.0rc8 while retaining live capability negotiation.
|
||||
- Require Core's advertised `ansible.windows >=3.8.0,<4.0.0` collection baseline. WebGUI does not install or upgrade collections.
|
||||
- Accept and render the additive `patch_summary_v1.reboot_reasons_before` native reboot-source observations without changing job verdicts or triggering follow-up work.
|
||||
- Update Windows filesystem-report wording to attached local storage volumes; mapped/network drives are intentionally excluded by Core rc8.
|
||||
- Preserve patch continuation, remaining-update knowledge, HRESULT presentation, report/journal retention, credentials, mobile UX, database schema 5 and the existing permission/systemd model.
|
||||
- Treat Core rc8 Checkmk script relocation/ACL hardening as Core-owned runbook behavior; do not reconstruct paths/ACLs or add private APIs.
|
||||
- Update fresh-install, deployment, controller-pilot and agent guidance for the new native collection floor and Core rc8 acceptance boundary.
|
||||
|
||||
## Preserved previous release notes
|
||||
|
||||
## 2.1.0rc4 - Core 3.3.0rc3 patch-wave support
|
||||
|
||||
Compatibility: separately deployed Core3.3.0rc3; public service/wire/event1.0; WebGUI HTTPv2; SQLite5 unchanged from rc3.
|
||||
|
||||
- Update exact adapter/executor/CLI/deployment compatibility checks while retaining live capability negotiation. Core remains unchanged.
|
||||
- Expose reboot message/delay and Windows-only post-reboot continuation through existing public catalog forms, showing platform applicability and catalog hints. Blank still omits overrides. Review distinguishes explicit reboot/continuation/delay from inherited inventory/role policy.
|
||||
- Present continuation_required independently from successful/failed Core and job status. No automatic follow-up jobs, reboot enablement or continuation override.
|
||||
- Render reboot before/after/deferred state, observed AIM reboot, reviewed delay, cycles, stop reasons and per-update unsigned/hex HRESULT, fixed reason and safe message. No raw fatal-text/event-log parsing.
|
||||
- Treat remaining_updates_known=false as unknown rather than an authoritative empty/old queue. True labels a final read-only, dated discovery, not an expanded install queue or current compliance. Original validated JSON stays available.
|
||||
- Preserve old patch reports using their recorded contracts, including the older closed patch_summary_v1 shape; do not invent absent fields or validate old history against the new catalog.
|
||||
- Keep modal/mobile/graph/history, retained journal/report policy, target outcomes, execution review, credential boundaries and the generated permission/unit contract unchanged.
|
||||
- Include the requested ADDON-INSTALLATION.md in the release and update deployment/patch acceptance/agent guidance. No new database migration, dependencies, services or write exceptions.
|
||||
- Add public-Core rc3, historical-report, patch-state, escaped-output and review regression coverage. Actual results and environment limitations are in docs/VERIFICATION.md.
|
||||
|
||||
## Preserved previous release notes
|
||||
|
||||
|
||||
## 2.1.0rc3 - Core3.3 reports and retained execution evidence
|
||||
|
||||
- Target independently managed Core3.3.0rc1 with existing service/wire/event1.0; WebHTTPv2, additive SQLite schema5.
|
||||
- Preserve negotiated result contracts in review; validate final operation reports and new result_validation/error families while keeping native outcome and report availability separate.
|
||||
- Separate large public-result framing from unchanged inbound credential/request limits; reject malformed, torn or oversized payloads without replay.
|
||||
- Retain structured worker-side progress with bounded batched writes, tail/checkpoints, durable cursor replay and explicit coverage gaps. No raw output or browser-dependent collection.
|
||||
- Retain eight ordinary report types by default and only metadata for parsed Checkmk config unless opted in. All9 schema-keyed summaries and generic supported JSON views; lazy per-slot payload reads, dated Host Activity links.
|
||||
- Cascade report/journal deletion with jobs, preserving only compact audit metadata. Historical jobs are not backfilled and stale pre-upgrade work is stopped by migration.
|
||||
- Preserve modal, mobile header, hierarchy/history, normal executor identity and all narrow staging/IPC permissions. Add restored-adapter Core compatibility check before service restarts on rollback.
|
||||
- Qualification evidence is recorded in docs/VERIFICATION.md; no new live-host certification is implied.
|
||||
|
||||
## Historical releases
|
||||
|
||||
# Changelog
|
||||
|
||||
## 2.1.0rc2 - one-run credential dialog and attention
|
||||
|
||||
Compatibility: AIM Core 3.2.1rc2; service/event API 1.0; WebGUI HTTP v2; SQLite schema 4. No Core, deployment, permission or dependency-pin change.
|
||||
|
||||
- Replace default navigation to password entry with an owner-initiated native modal; retain full-page/no-JavaScript fallback. The modal is outside polled job fragments.
|
||||
- Show reviewed job context, server-synchronized reservation countdown, required fields, Show/Hide and Caps Lock feedback. Short/mobile viewports scroll within the dialog.
|
||||
- Add Bootstrap 5 segmented radio choices for customer-Vault versus separate SSH key passphrase only when Core permits both. Explicitly required key passphrases stay required. No Custom authentication override.
|
||||
- Clear revealed/masked inputs on dismissal, submit, invalidation and navigation. Treat lost acknowledgement as uncertain; reconcile with read-only status rather than automatically resending credentials.
|
||||
- Add Needs your attention to Overview/Jobs with owner credential actions and existing independent-administrator review links. Do not change approval or execution policy.
|
||||
- Add canonical /api/v2/runs/{id}/credentials POST alias, retaining /api/v2/jobs/{id}/credentials; add owner-only credential-status and guarded HTML fragment GETs. Both POST routes share existing throttling and worker handoff.
|
||||
- Preserve literal secrets, CSRF/origin/session/grant checks, bounded bodies and existing one-run deadlines. Improve ambiguous-handoff wording; enforce an explicitly required SSH key passphrase.
|
||||
- Add synthetic endpoint and real local worker-socket tests plus mobile/desktop credential-dialog browser fixtures. See VERIFICATION.md for measured results and limitations.
|
||||
|
||||
|
||||
## 2.1.0rc1 - read-only experience candidate
|
||||
|
||||
Compatibility: independently managed AIM Core3.2.1rc2; service/wire/event1.0; WebGUI HTTPv2; SQLite4. Based on WebGUI2.0.0rc8. No new Core requirement, database migration, runtime permission or execution-policy change.
|
||||
|
||||
- Replace the mobile swipe rail with a compact AIM-home / sun-moon / right-aligned hamburger row and native keyboard-operable dropdown; desktop sidebar retained.
|
||||
- Add current Core Inventory Explorer with linked SVG group/host map, branch focus, distinct counts, search and equivalent mobile outline. Graph nodes navigate, never execute.
|
||||
- Add Host Activity from retained WebGUI final per-target results with mode/time/playbook/outcome filters, paginated timeline, counter details and own saved-plan references.
|
||||
- Add Playbook Insights with explicit metric denominators, outcome distribution, paged host-by-playbook matrix and mobile cards. Never scrape terminal/core-wide history or infer live health.
|
||||
- Scope aggregation to underlying job authorization before reading records; cover more than100 jobs, legacy/unknown data and deletion without a shadow archive.
|
||||
- Connect existing host lists, job target summaries, Jobs and Saved Plans previews to activity pages. Keep partial host/parent outcomes distinct and current inventory outages visible.
|
||||
- Preserve one-run review/idempotency, optional collision-safe names, credentials, retry/deletion controls, bounded live output and existing managed permission model.
|
||||
- Reconcile current agent/read-only/mobile documentation and add unit, real-Core read, browser-fixture and synthetic large-history coverage. Actual qualification is recorded in docs/VERIFICATION.md, not inferred from older RC counts.
|
||||
|
||||
## Preserved historical record
|
||||
|
||||
The following is the changelog as supplied in2.0.0rc8, including its duplicated historical headings. It is retained as provenance; it is not new2.1 behavior or new verification.
|
||||
|
||||
# Changelog
|
||||
|
||||
## 2.0.0rc8
|
||||
|
||||
- Require and integrate AIM Core 3.2.1rc2 / service API 1.0 while preserving the independent Core/WebGUI release boundary.
|
||||
- Consume `target_outcome_summary_v1` and retain Core's authoritative overall `failed` status while presenting mixed requested-target outcomes as `Partially succeeded` in WebGUI.
|
||||
- Show Core-provided per-target outcome and task counters on Job detail; Jobs overview shows successful/requested and failed/unreachable/not-started/indeterminate counts. No task-event reconstruction is used for final host state.
|
||||
- Consume read-only `inventory_hierarchy_v1` for nested parent/subgroup selection and inventory display. Parent scopes include Core-declared descendant hosts; execution still submits explicit reviewed hostnames.
|
||||
- Require `native_defaults_preflight_v2`; keep rc6 release-managed split-home staging and executor sandbox unchanged.
|
||||
- Remove the special persistent orange outline around Jobs and Saved plans; active/hover navigation styling remains consistent with the rest of the menu.
|
||||
- Preserve one-run jobs, optional collision-safe plan names, detailed safe live output, running-job deletion protection, API v2, SQLite schema 4, and the rc6 managed permission model.
|
||||
|
||||
## 2.0.0rc6
|
||||
|
||||
- Fix delegated `localhost` execution under the hardened executor sandbox. Ansible 2.19 local connections expand `~svc_bf-ansible/.ansible/tmp` from the passwd database even when the executor service sets `HOME=/var/lib/aim-web-executor`.
|
||||
- Release-manage `/home/<executor>/.ansible` and `/home/<executor>/.ansible/tmp` as executor-owned `0700`, and grant `ReadWritePaths` only to that exact local staging path while keeping `ProtectHome=read-only`.
|
||||
- Extend `core-staging-check` so startup validates both Core controller-local staging and Ansible delegated-local staging inside the actual systemd sandbox.
|
||||
- Do not set global `ANSIBLE_REMOTE_TMP`; doing so would also alter POSIX temp paths on managed Linux hosts.
|
||||
- Preserve Core 3.2.1rc1 detailed progress, managed socket/runtime permissions, API v2, SQLite schema 4, and existing credential boundaries.
|
||||
|
||||
## 2.0.0rc5
|
||||
|
||||
- Fix the rc4 executor-start race: deployment now waits for the `Type=simple` executor to bind and permission `/run/aim-web-executor/core.sock` before validating runtime ownership/mode. A temporarily missing socket is treated as startup-in-progress rather than immediate migration failure.
|
||||
- Fail deterministically if the executor service exits before binding, or if the managed socket does not become ready within the bounded startup window.
|
||||
- Preserve the rc4 release-managed identity model: `svc_bf-ansible` primary user/group, unit-scoped `aim-web` supplementary group, executor-owned `0711` runtime directory, and `executor:aim-web 0660` socket.
|
||||
- No Core, database schema, API, credential, inventory, Vault, key-ownership, or global SSH-trust changes.
|
||||
|
||||
|
||||
## 2.0.0rc5
|
||||
|
||||
- Fix the rc3 runtime-directory ownership transition: systemd now owns `/run/aim-web-executor` as the executor identity with mode `0711`; authorization remains on `core.sock` as `executor:aim-web 0660`. This removes runtime `chgrp` and allows upgrades from rc2 without manual `/run` repair.
|
||||
- Preserve the release-managed executor primary group plus unit-scoped `aim-web` supplementary group, staging checks, config/state ownership, and detailed Core 3.2.1rc1 progress rendering.
|
||||
|
||||
|
||||
## 2.0.0rc5 — Core 3.2 detailed progress, operational UI, and managed permissions
|
||||
|
||||
Compatibility: AIM 3.2.1rc1; public core service/wire/event 1.0; detail schema `play_task_host_v1`; WebGUI HTTP v2; SQLite 4.
|
||||
|
||||
- Negotiate `progress_mode=detail` and render safety-filtered play/task/host progress in the live job console while keeping raw module stdout/stderr unavailable.
|
||||
- Adopt Core 3.2.1rc1 controller staging preflight requirements in the executor unit: private `.ansible/tmp`, scoped `ReadWritePaths`, and startup staging check.
|
||||
- Add semantic job state chips, richer Jobs and Saved plans scope previews, stronger navigation emphasis, aligned Audit filters, and viewport-bounded internal console scrolling.
|
||||
- Preserve running-job deletion protection, one-run execution, optional collision-safe plan names, API v2, schema 4, and separate non-root core executor architecture.
|
||||
- Preserve the executor account's normal primary group and grant `aim-web` only as a unit-scoped supplementary group; no `/etc/group` mutation is performed.
|
||||
- Release-manage and verify WebGUI config/state, executor HOME/staging, systemd unit ownership, runtime directory group, and core socket mode/ownership during deployment.
|
||||
- Keep Core-owned inventory/Vault/private-key permissions and global SSH trust outside WebGUI's ownership boundary.
|
||||
|
||||
## 2.0.0rc1 — independent core API migration
|
||||
|
||||
Compatibility: AIM3.1.0; public core service/wire/event1.0; WebGUI HTTPv2; SQLite4.
|
||||
Release candidate: no live-controller execution qualification is implied.
|
||||
|
||||
- Replace private rc18 imports/command hooks/Ansible strategies and sudo key export
|
||||
with the documented aimctl protocol. Pre-started non-root add-on executor under
|
||||
the existing authorized key-owning account; no automatic core/user/permission edits.
|
||||
- New run -> review -> one-run submission, without a saved plan. Mode/key handling
|
||||
included in immutable review. Saving is secondary and optional.
|
||||
- Generated unique titles for blank names, transactional casefold/NFKC duplicate
|
||||
rejection for explicit account-local titles. Never overwrite by title.
|
||||
- Preserve authentication, grants, history, audit, bulk deletion, explicit retry,
|
||||
existing orange light/dark/mobile shell and browser-local timestamp lifecycle.
|
||||
- Schema4 retains records; old pending/queued jobs blocked, running interrupted.
|
||||
Old plans require fresh core review. Historical duplicate titles retained.
|
||||
- Retire unsupported Custom/raw-console features rather than misrepresent native
|
||||
inventory defaults or bypass the new API. Platform groups remain selectable;
|
||||
core1.0 lacks subgroup paths. Structured final core result/counters are shown.
|
||||
- Major migration requires --migrate-core; stages public core checks as executor,
|
||||
backs up/removes known legacy helpers/drop-in, uses no privileged capabilities.
|
||||
Rollback to legacy adapter remains stopped with incompatible core.
|
||||
- Verify the release manifest before deployment; use a separate executor HOME for
|
||||
native caches and independently verified host trust. Alternative direct-HTTP
|
||||
browsing profile keeps execution/credentials disabled.
|
||||
- New API/migration/security/contract-review/agent guidance and regression coverage.
|
||||
|
||||
## Historical WebGUI1.x entries (superseded architecture)
|
||||
|
||||
# Changelog
|
||||
|
||||
## 2.0.0rc5
|
||||
|
||||
- Fix the rc3 runtime-directory ownership transition: systemd now owns `/run/aim-web-executor` as the executor identity with mode `0711`; authorization remains on `core.sock` as `executor:aim-web 0660`. This removes runtime `chgrp` and allows upgrades from rc2 without manual `/run` repair.
|
||||
- Preserve the release-managed executor primary group plus unit-scoped `aim-web` supplementary group, staging checks, config/state ownership, and detailed Core 3.2.1rc1 progress rendering.
|
||||
|
||||
|
||||
## 1.1.0rc10 - 2026-09-19 (ephemeral live job console and execution diagnostics)
|
||||
|
||||
- Adds an authenticated same-origin Server-Sent Events job console backed by an owner-only local Unix socket. Playbook output is bounded in memory, sanitized before leaving the worker child, cleared on navigation, and never stored in SQLite, audit history, or regular files.
|
||||
- Keeps the console outside the HTMX-polled status fragment so polling cannot erase the stream. SSE responses disable proxy buffering and use keepalives for reverse-proxy compatibility without WebSockets.
|
||||
- Classifies non-zero Ansible runs into remote connection/authentication, playbook task, controller/playbook-loading, or generic execution failures using sanitized output only.
|
||||
- Retains rc9 credential/runtime fixes and AIM 3.0.0rc18 compatibility; no AIM or database-schema changes.
|
||||
|
||||
## 1.1.0rc9 - 2026-09-19 (Ansible 2.19 runtime qualification fixes)
|
||||
|
||||
- Treat resolved Vault/connection secret values as literal data. Standard AIM exact variable references are dereferenced once; the resulting password/passphrase is never recursively templated, so Jinja-looking password text remains unchanged.
|
||||
- Remove the empty `ANSIBLE_CALLBACKS_ENABLED` environment override. Ansible Core 2.19.11 interprets an empty callback name as an invalid plugin and aborts before playbook execution.
|
||||
- Correct the synthetic SSH-key runtime test to use owner-only `0600`, matching the secure canonical-key policy.
|
||||
- Correct `credential-check` acceptance-test guidance for a disposable test environment and `AIM_TEST_ANSIBLE_PYTHON`.
|
||||
- No AIM 3.0.0rc18, SQLite schema, permission model, HTTP API version, or credential lifetime change.
|
||||
|
||||
## 1.1.0rc8 - 2026-09-19 (secure key handoff + history QOL)
|
||||
|
||||
- Fix the rc7 secure-key preflight: the resolver no longer opens canonical service-owned `0600` SSH private keys as `aim-web`. It validates path/type/mode metadata only; the restricted export helper running as AIM `service_user` is the sole reader of canonical key bytes.
|
||||
- Add bulk deletion to the Jobs overview for terminal jobs and to the Saved Plans overview for the requesting account's own plans. Individual deletion and append-only deletion audit records remain.
|
||||
- Add **Retry as new job** for failed jobs. Retry is requester-only, manual, creates a new job ID, revalidates current grants/source revisions/execution policy, preserves reviewed non-secret parameters and credential mode, and requires fresh one-run credentials.
|
||||
- Preserve the secure permission model: inventory/Vault sharing through `aim-runtime`; canonical private keys owned by AIM `service_user` at `0600`; one-job WebGUI key copies only.
|
||||
- No AIM 3.0.0rc18 or SQLite schema change. HTTP API v1 gains the additive manual retry endpoint.
|
||||
|
||||
## 1.1.0rc7 - 2026-09-19 (rc6 deployment packaging fix)
|
||||
|
||||
- Fix deployment of the restricted SSH key-export helper after the staged source directory is atomically activated. rc6 moved the staging directory before reading `key_export.py`, then attempted to read the obsolete staging path and rolled back. rc7 reads the helper from the activated managed source tree.
|
||||
- No AIM 3.0.0rc18, SQLite schema, execution policy, credential protocol, or WebGUI API changes.
|
||||
- Retains the rc6 secure permission model, terminal-job deletion, saved-plan deletion, and browser-local timestamp behavior.
|
||||
|
||||
|
||||
## 1.1.0rc6 - 2026-09-18 (Ansible 2.19 Vault/runtime qualification fixes)
|
||||
|
||||
- Use Ansible Core 2.19.11's runtime `VaultSecret` API with UTF-8 bytes for one-run Vault passwords; remove the unavailable `TextVaultSecret` test-helper import exposed by controller qualification.
|
||||
- Keep `/usr/bin` as the shipped Ansible binary directory for this controller profile and resolve `/usr/bin/python3` from the actual `ansible-playbook` runtime rather than assuming a venv.
|
||||
- Distinguish missing, unreadable and empty SSH private keys using sanitized fixed messages. Permission failures now point to the shared `aim-runtime` read/traverse policy rather than collapsing into a generic Vault/reference error.
|
||||
- Preserve the rc4 fixes for literal special characters, explicit Vault-decrypt preflight, browser-local timestamp rendering, grant de-duplication and one-run credential lifetime.
|
||||
- Document the qualified filesystem model: AIM/WebGUI runtime identities need read/traverse access to encrypted Vault and configured customer private keys; AIM source remains externally managed and unchanged.
|
||||
- No AIM, HTTP API or SQLite schema change.
|
||||
|
||||
## 1.1.0rc3 - 2026-09-18 (grant picker de-duplication)
|
||||
|
||||
- Scoped execution grant forms now refresh the playbook choices for the selected account/customer and omit exact grants the account already has.
|
||||
- If every catalog playbook is already granted for that scope, the form shows a disabled explanatory option instead of offering a duplicate grant.
|
||||
- Duplicate grant submissions are rejected server-side with a conflict response rather than silently succeeding.
|
||||
- Existing grants remain visible below the form for review and revocation.
|
||||
- No schema, credential, execution, API version, AIM compatibility, or deployment-policy changes.
|
||||
|
||||
## 1.1.0rc2 - 2026-09-18 (administration layout fix)
|
||||
|
||||
- Removed the duplicate **Scoped execution grants** panel from the User administration page subtitle area.
|
||||
- Kept a single grant-management panel below Local accounts / Add account so account administration reads top-to-bottom without repeated controls.
|
||||
- No schema, credential, execution, API, AIM compatibility, or deployment-policy changes.
|
||||
|
||||
## 1.1.0rc2 - 2026-09-18 (credential feature candidate)
|
||||
|
||||
**Compatibility:** AIM **3.0.0rc18 only, unchanged**; HTTP API v1 with additive
|
||||
credential routes; SQLite schema **3** (additive from 2); Python >=3.11.
|
||||
Credential execution targets **Ansible Core 2.19.11 exactly**, in the existing
|
||||
external Ansible environment. No Ansible/AIM package is installed or updated.
|
||||
|
||||
**Candidate, not production-qualified:** the build environment could not obtain
|
||||
Ansible 2.19.11 or OpenSSH client tools. Local protocol/route/policy tests and
|
||||
fake-worker regression tests pass; real Ansible/SSH/WinRM qualification remains
|
||||
required. Read docs/VERIFICATION.md, not a test count as a certification.
|
||||
|
||||
### Added
|
||||
- Separate disabled-by-default [credentials] enabled switch, plus existing
|
||||
execution allowlist, HTTPS transport attestation and approval requirements.
|
||||
- Accessible Vault/Custom mode control at job review. The custom username and
|
||||
mode become immutable reviewed metadata. Passwords are collected only after
|
||||
approval and the single worker reserves the job; they are not plan fields.
|
||||
- Five-minute empty worker reservation and 60-second single-run hand-off/start
|
||||
deadline. No secrets are held for approval or scheduled-job delays. A retry or
|
||||
check-to-apply is a new credential submission. No automatic replay on restart.
|
||||
- Private Unix socket hand-off, requester/session/job checks, anonymous child
|
||||
pipe and job-private password-source helpers. Add-on code never persists
|
||||
infrastructure passwords to SQLite, helper text, argv or environment values.
|
||||
- Resolver in the existing Ansible Python: standard customer Vault, effective
|
||||
host/group connection references, per-host Windows NTLM credentials, existing
|
||||
customer SSH keys and separate Vault key passphrase. Unused legacy SSH
|
||||
password references do not block key authentication.
|
||||
- Custom mode overrides connection identity/password for every selected host;
|
||||
disables prior SSH control sockets and key/agent fallback. SSH uses an add-on
|
||||
ASKPASS helper, avoiding the native 2.19 named password shared-memory helper.
|
||||
- Dedicated linear strategy adapter and final launch authorization. Endpoint
|
||||
changes, unsupported auth transports and selected source patterns fail closed.
|
||||
- aim-web credential-check for non-secret exact-runtime/import/tool checks;
|
||||
six opt-in synthetic actual-Ansible tests and an execution acceptance guide.
|
||||
- Mobile/desktop credential page and no-echo error handling. Existing appearance,
|
||||
account policy, selection semantics and network/TLS profile remain unchanged.
|
||||
|
||||
### Deliberate restrictions
|
||||
- Standard SSH and WinRM/NTLM only; no network/API plugins, become-password
|
||||
collection, private-key uploads, saved passwords, raw output streaming or SSO.
|
||||
- Credential jobs reject delegation, asynchronous tasks, explicit strategies,
|
||||
dynamic task imports/inventory changes, external roles and SSH argument escape
|
||||
hatches. Some rc18 catalog plays (notably delegated Checkmk work) remain terminal
|
||||
only. An allowlist entry is not a guarantee that a play is eligible.
|
||||
- Custom credentials may still require Vault unlock for unrelated play variables.
|
||||
- Passwords use small HTTPS POST bodies. Proxy/body buffering and trusted playbook
|
||||
behavior remain deployment responsibilities; process separation/shared UID is
|
||||
not a privilege sandbox, and Python does not promise physical memory erasure.
|
||||
|
||||
### Upgrade and rollback
|
||||
- Whole-release replacement and overwritten TOML continue. Credentials and
|
||||
execution are both disabled in shipped defaults; the backend TLS setup is not
|
||||
touched. Existing accounts, sessions, plans and jobs survive forward migration.
|
||||
- Schema 3 adds only credential phase/deadline metadata, not a credential store.
|
||||
- Rollback to 1.0.0/schema2 requires explicit historical database restoration,
|
||||
losing post-checkpoint changes and potentially restoring old passwords. Make
|
||||
a current protected backup first. Do not manually repoint the active venv.
|
||||
- Global AGENTS.md and security/API/deployment/execution docs updated together.
|
||||
|
||||
|
||||
## 1.0.0 - 2026-09-18
|
||||
|
||||
**Compatibility:** AIM 3.0.0rc18 only (unchanged); HTTP API v1; SQLite schema **2**;
|
||||
Python >=3.11. Independently versioned add-on, not an AIM release.
|
||||
|
||||
### Added
|
||||
- Named-administrator setup and bootstrap retirement, with forced first-password
|
||||
change and last-admin/session protections retained.
|
||||
- Status/config-check/doctor CLI and administrator System diagnostics.
|
||||
- Inventory search, group filters, sorting and 100-row browse pagination;
|
||||
private selection restoration, clear/visible select-all controls.
|
||||
- Typed catalog forms and private non-secret saved plans/preset reuse, using
|
||||
existing rc18 input parsing and target validation.
|
||||
- Searchable/paginated administrative audit history and lifecycle events.
|
||||
- Optional disabled-by-default worker using rc18's existing PlaybookManager.run
|
||||
and its external_presentation hook; no monkey patches or duplicated AIM CLI.
|
||||
- Exact customer/playbook execution grants; catalog allowlist; independent
|
||||
administrator approval; one active job; host/timeout/start-window policies;
|
||||
idempotent submission; one-shot UTC schedules; cancellation and crash recovery.
|
||||
- API v1 plan, selection, diagnostics, audit and job routes. Existing preflight
|
||||
remains validation-only. POST /api/v1/runs returns 501 while execution is off.
|
||||
- Source-revision checks at submission and dispatch; interrupted jobs are never
|
||||
automatically replayed. Potentially sensitive raw command output is discarded.
|
||||
|
||||
### Fixed
|
||||
- Mobile group count badges have their own constrained grid slot instead of
|
||||
overflowing two-column group cards. Long labels wrap without moving counts out.
|
||||
- The mobile navigation rail now shows scroll instructions and arrow controls.
|
||||
- Deployment journals before replacing TOML; checks installed candidate identity;
|
||||
manages the worker with rollback; tests schema compatibility before rollback.
|
||||
- Verified, unchanged installed browser assets can be reused without a download.
|
||||
|
||||
### Deployment changes requiring review
|
||||
- Release-managed TOML now uses loopback 127.0.0.1:8080 and trusts 127.0.0.1,
|
||||
matching NPM -> HTTPS controller:8443 -> local Nginx -> WebGUI. NPM/certificates
|
||||
are externally managed and are NOT modified by the add-on deployment.
|
||||
- Additive schema 1 -> 2 migration preserves accounts. Rollback to 0.1.x needs
|
||||
explicit --restore-auth-db and loses post-checkpoint data; read the guide.
|
||||
- Execution is off, has an empty allowlist, and has no TLS verification
|
||||
attestation by default. A release upgrade does not silently enable jobs.
|
||||
- Raw output streaming and interactive infrastructure credentials remain deferred.
|
||||
- See docs/VERIFICATION.md for actual test results and live-controller limits.
|
||||
|
||||
# AIM WebGUI changelog
|
||||
|
||||
WebGUI uses its own version sequence. An add-on release does not imply any AIM
|
||||
release, source edit or upgrade. Every entry must include supported AIM versions,
|
||||
auth schema compatibility, HTTP API compatibility and upgrade/rollback notes.
|
||||
|
||||
## 0.1.6 - 2026-09-17
|
||||
|
||||
### Compatibility
|
||||
|
||||
| Component | Contract |
|
||||
| --- | --- |
|
||||
| AIM base | **3.0.0rc18 only; unchanged and externally managed** |
|
||||
| Python | 3.11+ |
|
||||
| HTTP API | v1 unchanged |
|
||||
| Add-on database | Schema 1 unchanged |
|
||||
| WebGUI config | Release-managed; overwritten on install/update/rollback |
|
||||
|
||||
### Added / changed
|
||||
|
||||
- Made mobile/responsive behavior a global UI standard. At 760px and below the desktop sidebar becomes a compact sticky header with one non-wrapping, horizontally scrollable navigation rail, preventing staggered/wrapped top navigation.
|
||||
- Reworked the mobile account/display bar so theme controls and account actions remain level and usable, long usernames ellipsize, and the desktop layout remains unchanged.
|
||||
- Added narrow-screen rules for touch-friendly group controls, contained table scrolling, stacked forms/actions, responsive system facts, reduced card spacing, and device safe-area insets.
|
||||
- Expanded the repository-root `AGENTS.md` into the authoritative AI-agent/contributor standards document covering the immutable AIM boundary, release/state ownership, security invariants, design system, mobile requirements, selection semantics, authentication, testing, verification, and documentation upkeep.
|
||||
|
||||
### Upgrade / rollback
|
||||
|
||||
Whole-release replacement semantics are unchanged. The release-managed deployment profile remains the validated `https://aim.desq-gaming.de` / Nginx Proxy Manager configuration from 0.1.5. `/var/lib/aim/webgui` auth/runtime state remains preserved across normal updates. AIM rc18 is never modified.
|
||||
|
||||
## 0.1.5 - 2026-09-17
|
||||
|
||||
### Compatibility
|
||||
|
||||
| Component | Contract |
|
||||
| --- | --- |
|
||||
| AIM base | **3.0.0rc18 only; unchanged and externally managed** |
|
||||
| Python | 3.11+ |
|
||||
| HTTP API | v1 unchanged |
|
||||
| Add-on database | Schema 1 unchanged |
|
||||
| WebGUI config | Release-managed; overwritten on install/update/rollback |
|
||||
|
||||
### Added / changed
|
||||
|
||||
- Replaced the text Light/Dark selector with compact sun/moon theme controls while retaining explicit accessible labels and pressed-state semantics.
|
||||
- Tidied inventory-group bulk-selection controls and aligned the select-all header checkbox exactly with host-row selection checkboxes. Selection behavior and explicit-host-only preflight semantics are unchanged.
|
||||
- Managed deployment now creates `/usr/local/bin/aim-web` as a guarded symlink to `/opt/aim-web/current/bin/aim-web`. It follows update/rollback automatically and refuses to overwrite unrelated files or symlinks.
|
||||
|
||||
### Upgrade / rollback
|
||||
|
||||
Whole-release replacement semantics are unchanged. The release-managed config still uses `https://aim.desq-gaming.de`, backend listener `0.0.0.0:8080`, and trusted Nginx Proxy Manager `192.168.20.3`. `/var/lib/aim/webgui` auth/runtime state remains preserved across normal updates. AIM rc18 is never modified.
|
||||
|
||||
## 0.1.4 - 2026-09-17
|
||||
|
||||
### Compatibility
|
||||
|
||||
| Component | Contract |
|
||||
| --- | --- |
|
||||
| AIM base | **3.0.0rc18 only; unchanged and externally managed** |
|
||||
| Python | 3.11+ |
|
||||
| HTTP API | v1 unchanged |
|
||||
| Add-on database | Schema 1 unchanged |
|
||||
| WebGUI config | Release-managed; overwritten on install/update/rollback |
|
||||
|
||||
### Added / changed
|
||||
|
||||
- Added a global Light/Dark display selector in the WebGUI top bar. The preference is browser-local presentation state only; no authentication/session material is stored with it.
|
||||
- Added a dark palette built from charcoal/slate surfaces instead of pure black, while retaining the existing AIM orange accent and accessible focus/selection states.
|
||||
- Centralized additional surface, table, note, badge and control colors into theme tokens so pages switch consistently between light and dark modes.
|
||||
- Added a select-all checkbox to the explicit-host table header with checked/indeterminate synchronization.
|
||||
- Added inventory-group bulk selection controls with host counts. Overlapping groups and manual host selections update group controls to checked/indeterminate states.
|
||||
- Group selection remains presentation-only: preflight continues to submit explicit inventory hostnames and never Ansible patterns or group expressions. The existing server-side explicit-target validation and 500-target limit are unchanged.
|
||||
|
||||
### Upgrade / rollback
|
||||
|
||||
Whole-release replacement semantics are unchanged. The release-managed config still uses `https://aim.desq-gaming.de`, backend listener `0.0.0.0:8080`, and trusted Nginx Proxy Manager `192.168.20.3`. `/var/lib/aim/webgui` auth/runtime state remains preserved across normal updates. AIM rc18 is never modified.
|
||||
|
||||
## 0.1.3 - 2026-09-17
|
||||
|
||||
### Compatibility
|
||||
|
||||
| Component | Contract |
|
||||
| --- | --- |
|
||||
| AIM base | **3.0.0rc18 only; unchanged and externally managed** |
|
||||
| Python | 3.11+ |
|
||||
| HTTP API | v1 unchanged |
|
||||
| Add-on database | Schema 1 unchanged; users/passwords/auth state preserved |
|
||||
| WebGUI config | Release-managed; overwritten on install/update/rollback |
|
||||
|
||||
### Fixed / changed
|
||||
|
||||
- Hardened browser CSRF-origin handling for reverse-proxy deployments. `Origin` remains authoritative when present and must match `public_url`; a same-origin `Referer` is accepted only when `Origin` is absent.
|
||||
- If both `Origin` and `Referer` are absent, unsafe browser requests are accepted only with `Sec-Fetch-Site: same-origin`, and the existing per-session CSRF token remains mandatory. `Origin: null`, cross-site Fetch Metadata, and mismatching Origin/Referer values remain rejected.
|
||||
- Changed the response `Referrer-Policy` from `no-referrer` to `same-origin` so browsers can provide the safe Referer fallback without leaking referrers cross-origin.
|
||||
- Improved origin-rejection messages to distinguish mismatched Origin, mismatched Referer, cross-site Fetch Metadata, and missing same-origin browser metadata.
|
||||
- Corrected the managed Nginx Proxy Manager trust address for the validated deployment profile to `192.168.20.3`; backend remains `192.168.20.46:8080` and public origin remains `https://aim.desq-gaming.de`.
|
||||
|
||||
### Upgrade / rollback
|
||||
|
||||
Whole-release replacement semantics from 0.1.2 are unchanged. The release-managed WebGUI configuration is overwritten with the 0.1.3 profile during update; `/var/lib/aim/webgui` authentication/runtime state is preserved. Rollback restores the prior release source/config while leaving the auth database intact unless explicitly requested. AIM rc18 is never modified.
|
||||
|
||||
## 0.1.2 - 2026-09-17
|
||||
|
||||
### Compatibility
|
||||
|
||||
| Component | Contract |
|
||||
| --- | --- |
|
||||
| AIM base | **3.0.0rc18 only; unchanged and externally managed** |
|
||||
| Python | 3.11+ |
|
||||
| HTTP API | v1 unchanged |
|
||||
| Add-on database | Schema 1 unchanged; users/passwords/auth state preserved |
|
||||
| WebGUI config | **Release-managed; overwritten on install/update/rollback** |
|
||||
|
||||
### Changed
|
||||
|
||||
- Managed deployments now treat `/etc/ansible/scripts/config/webgui.toml` as part of the versioned WebGUI release rather than operator state. Every install/update writes the release copy, and rollback restores the copy captured with the rolled-back release.
|
||||
- Update sequencing now snapshots and validates the active release before replacing configuration, then validates the candidate with the candidate runtime. An older WebGUI runtime is never asked to parse a newer configuration schema.
|
||||
- Authentication database checkpoints now use Python SQLite's native online backup API directly, so backup and update no longer depend on the previous WebGUI runtime or its ability to parse any configuration schema.
|
||||
- Private runtime state under `/var/lib/aim/webgui`, including the SQLite authentication database and consumed bootstrap state, remains preserved across normal updates.
|
||||
- The managed release profile binds `0.0.0.0:8080`, uses `https://aim.desq-gaming.de`, and trusts forwarded headers only from Nginx Proxy Manager at `192.168.10.11`.
|
||||
|
||||
### Upgrade semantics
|
||||
|
||||
`deploy/deploy.py update` performs whole-release replacement without Git. Source, venv, systemd unit and WebGUI configuration advance together. The SQLite authentication database is retained. On deployment failure, the previous source, venv, unit and configuration are restored automatically; AIM rc18 is never modified.
|
||||
|
||||
## 0.1.1 - 2026-09-17
|
||||
|
||||
### Compatibility
|
||||
|
||||
| Component | Contract in this release |
|
||||
| --- | --- |
|
||||
| AIM baseline | Original `AIM-Ansible-3.0.0rc18.zip` only; unchanged |
|
||||
| Upgrade from WebGUI | `0.1.0` supported by managed replacement update |
|
||||
| Add-on database | Schema 1 unchanged; users/passwords/sessions preserved |
|
||||
| HTTP interface | API v1 unchanged |
|
||||
| Reverse proxy | Explicit trusted forwarded-header support added |
|
||||
|
||||
### Fixed / changed
|
||||
|
||||
- Added explicit non-loopback listener support for reverse-proxy deployments. The safe default remains `127.0.0.1`.
|
||||
- Added `proxy_headers` and `forwarded_allow_ips`; Uvicorn now trusts forwarded headers only when configured.
|
||||
- Added sectioned TOML configuration while retaining full read compatibility with the 0.1.0 flat configuration.
|
||||
- Non-loopback listeners require an HTTPS `public_url`, proxy-header processing, and at least one explicitly trusted proxy address/network.
|
||||
- Managed readiness checks now work with wildcard listeners (`0.0.0.0` / `::`) by probing loopback while sending the configured public Host header.
|
||||
- Documented Nginx Proxy Manager deployment validated with `aim.desq-gaming.de`, backend `192.168.20.46:8080`; site-specific values are examples, not package defaults.
|
||||
- Clarified that the managed systemd unit supplies AIM rc18's required group as a supplementary process group; manual tests launched with `sudo -u` may not inherit that group.
|
||||
|
||||
### Upgrade / rollback
|
||||
|
||||
Use `deploy/deploy.py update` from a freshly unpacked 0.1.1 release. The active add-on source and isolated venv are replaced as a unit; operator configuration and `/var/lib/aim/webgui/webgui.sqlite3` are retained. 0.1.0 flat TOML remains valid after upgrade. Rollback to the managed 0.1.0 snapshot remains supported without restoring the auth database unless explicitly requested. AIM rc18 is never modified.
|
||||
|
||||
## 0.1.0 - 2026-09-17
|
||||
|
||||
### Compatibility
|
||||
|
||||
| Component | Contract in this release |
|
||||
| --- | --- |
|
||||
| AIM baseline | Original `AIM-Ansible-3.0.0rc18.zip` only |
|
||||
| AIM product version | `3.0.0rc18`, unchanged |
|
||||
| AIM rc19 / later | Not claimed; startup refuses unapproved versions |
|
||||
| Python | Requires 3.11+; executable tests run on CPython 3.13.5 |
|
||||
| Managed deployment | Linux with systemd; separate unprivileged service account |
|
||||
| Add-on database | Schema 1, SQLite rollback-journal mode |
|
||||
| HTTP interface | `/api/v1`, cookie authentication and CSRF for unsafe methods |
|
||||
| Frontend | Jinja2, HTMX 2.0.10, Bootstrap 5.3.8; no EJS/Node |
|
||||
| Core change requirement | None; no service/API facade added to AIM |
|
||||
|
||||
### Added
|
||||
|
||||
Independent `aim-webgui` Python distribution and `aim-web` executable. FastAPI /
|
||||
Uvicorn server, Jinja2 pages/partials, local static asset preparation and
|
||||
centralized orange theme with explicit Bootstrap component overrides.
|
||||
|
||||
Read-only rc18 adapter for Config, group membership, CustomerManager,
|
||||
InventoryDocument/InventoryEditor, catalog parsing, InputSpec.parse/validate
|
||||
and PlaybookManager.validate_overrides. Target/platform filtering mirrors the
|
||||
rc18 target screen without importing its terminal UI. Inputs inherit role
|
||||
defaults unless explicitly supplied; the existing cleanup-off safety default
|
||||
is retained. Customer path traversal and escaping symlinks are rejected.
|
||||
|
||||
SQLite bootstrap admin with random password written to private `.credentials`,
|
||||
mandatory first password change, Argon2id hashes, server-side hashed session IDs,
|
||||
CSRF/origin checks, idle/absolute expiry, request limits, login throttling,
|
||||
local account administration, last-admin protection and terminal recovery.
|
||||
|
||||
Add-on-only, non-git staged replacement deployment. It prepares dependencies
|
||||
before stopping WebGUI, stores SQLite backups using its backup API, retains
|
||||
operator config/auth state, replaces old source rather than merging, and
|
||||
switches between permanent isolated venv paths. Readiness failures attempt
|
||||
rollback; interrupted operations leave a root-owned recovery journal.
|
||||
Code-only rollback preserves accounts by default. Database restoration requires
|
||||
an explicit destructive flag, and session tokens are always revoked on rollback.
|
||||
|
||||
### Deliberately not included
|
||||
|
||||
Browser-triggered playbook execution, infrastructure writes, Vault/SSH/WinRM
|
||||
credential collection, job workers, customer-scoped roles, MFA, SSO, API bearer
|
||||
tokens, generic plugin discovery, or any change to the base AIM installation.
|
||||
The `POST /api/v1/runs` compatibility boundary explicitly returns 501 after
|
||||
normal authentication/CSRF checks. It never starts a job.
|
||||
|
||||
### Upgrade and rollback compatibility
|
||||
|
||||
This is the first independent Python add-on release. It is NOT an upgrade path
|
||||
for the historical Node/EJS rc19 WebGUI or its API daemon. Leave those separate
|
||||
artifacts unused when deploying against rc18.
|
||||
|
||||
Future updates must use a new add-on version and an explicitly recorded AIM
|
||||
compatibility contract. The installer refuses same-version replacement and
|
||||
downgrades through `update`. Use `rollback` for an installed prior snapshot.
|
||||
Migrations only advance schema versions; startup refuses a newer database.
|
||||
Do not restore an old database merely to roll back compatible code: that would
|
||||
also revert password, user and audit changes after the snapshot.
|
||||
|
||||
### Verification limits
|
||||
|
||||
See `docs/VERIFICATION.md` for actual results. No managed-host Ansible operations
|
||||
were run. Linux/systemd activation and an online dependency installation were
|
||||
not exercised against the operator's controller. The build container could not
|
||||
download browser assets or dependency wheels; deployment has a required pinned,
|
||||
integrity-checked online/offline preparation step. No claim of a penetration
|
||||
test or a current complete dependency vulnerability audit is made.
|
||||
|
||||
## 1.1.0rc7
|
||||
- Preserve canonical AIM SSH private keys as service-owned `0600`; WebGUI uses a restricted service-user export bridge and job-private `0600` copies only.
|
||||
- Add deletion of terminal job history while retaining append-only audit deletion records. Saved-plan deletion remains supported.
|
||||
- Re-run browser-local timestamp formatting after HTMX settle and browser page-cache restores.
|
||||
- Document the `aim-runtime` shared-read model: inventories/Vaults `root:aim-runtime`, private keys service-owned `0600`.
|
||||
Reference in New Issue
Block a user