aim-web2.1.0rc9
This commit is contained in:
@@ -0,0 +1,96 @@
|
||||
> Historical reference retained from the preceding release. Current deployment/contracts and evidence are in DEPLOYMENT.md, REPORTS.md, JOURNAL.md and VERIFICATION.md. Do not treat old limitations or tests as current qualification.
|
||||
|
||||
# AIM WebGUI 2.1.0rc2 compared with Jenkins, Semaphore UI and Foreman
|
||||
|
||||
## Basis and limits
|
||||
|
||||
This is a documentation-based capability and product-direction comparison, not a hands-on usability benchmark, security audit, licensing quotation or performance comparison. AIM statements refer to the inspected 2.1.0rc2 source and its test evidence. Other product statements refer to the official documentation listed below, consulted for this release. Features can depend on installed plugins, edition and configuration; Foreman examples use the published 3.18 host-management guide without claiming that version is the newest stable release. Recommendations below are design judgments, not measured rankings.
|
||||
|
||||
## The products solve different problems
|
||||
|
||||
**AIM Web** is a focused operator interface over a separately managed AIM Core. It discovers Core-owned customers, hosts, groups and catalog playbooks; prepares explicit reviewed runs; requests transient credentials only when the worker is ready; and shows Core-owned results. It does not own inventory/Vault editing, arbitrary automation code, server provisioning or a general plugin execution ecosystem. Its history covers retained WebGUI jobs only. [A1]
|
||||
|
||||
**Jenkins** is primarily a Pipeline/CI/CD automation platform. Pipeline models multistage work and supports extensible execution through steps and plugins. Its Ansible plugin accepts playbooks, inventories and credential IDs. Treating Jenkins as a direct equivalent of a host inventory system would obscure that pipeline-centric design. [J1, J2]
|
||||
|
||||
**Semaphore UI** is the closest operational comparator: projects combine repositories, inventories, reusable credentials, variables and task templates, with each execution recorded as a task. Its documented scope also includes tools other than Ansible. The user guide documents schedules and workflow-related capabilities, with some capabilities edition-dependent. [S1, S2]
|
||||
|
||||
**Foreman** is broader host lifecycle management, not merely a Puppet runner. It maintains host inventory/group settings and supports provisioning and infrastructure integrations. Its documented remote-execution and Ansible workflows can operate against selected hosts through Smart Proxies; Puppet is one part of that ecosystem. [F1, F2]
|
||||
|
||||
## Functional comparison
|
||||
|
||||
| Area | AIM Web 2.1.0rc2 | Established-product reference |
|
||||
|---|---|---|
|
||||
| Inventory | Current read-only Core hierarchy; linked SVG/outline explorer; customer-scoped host pages | Semaphore manages inventory resources used by templates. Foreman manages hosts, host groups and inherited settings. Jenkins' Ansible plugin consumes inventory files/inline inventory for pipeline execution. [S3, F1, J2] |
|
||||
| Starting work | One-run review without mandatory plan; optional collision-safe saved title; existing independent approval when enabled | Semaphore starts tasks from templates and exposes user prompts. Jenkins offers Pipeline parameters/input steps. Foreman provides host selection and job-template workflows. [S2, J3, F2] |
|
||||
| Credential experience | Owner-initiated modal, Core-required fields, one-run lifetime, no add-on reusable secret store | Jenkins supports stored credentials referenced by IDs. Semaphore has a Key Store for reusable credentials. Foreman job settings include authentication/password and key-passphrase inputs where applicable. These are different operating models, not a security ranking. [J4, S4, F2] |
|
||||
| Output | Core-filtered static play/task/host labels and hints, bounded ephemeral stream; authoritative final per-target outcomes retained with the job | Jenkins' Ansible plugin supports console output; Semaphore documents live/completed logs and a raw-log view. Broader log access is useful for diagnosis but creates a different retention/exposure decision. [J2, S5] |
|
||||
| History | Host Activity and Playbook Insights over authorized retained WebGUI jobs, separating Check/Apply and host/whole-job outcomes | Semaphore exposes task/template history; Foreman is natively host-oriented. Do not equate a job log with an authoritative machine-wide history or claim a feature is absent merely because its documentation was not inspected. [S2, S5, F1] |
|
||||
| Orchestration | Existing queue, bounded targets, optional independent review and one-off UTC scheduling; no workflow DAG or recurring scheduler | Jenkins supports pipeline composition. Semaphore documents cron schedules; its documentation identifies workflows as a Pro feature. Foreman offers remote-job controls through its host-management workflow. [J1, S6, S7, F2] |
|
||||
| Access | Local accounts, customer/playbook execution grants; owner-or-admin job/history access and owner-only plans; not hostile-tenant isolation | Semaphore has project teams and built-in roles, with Enterprise extended permissions. Jenkins credential use is scoped and depends on authorization/plugin configuration. Wider identity deployments need product-specific evaluation. [S8, J4] |
|
||||
| Extensibility | Fixed public Core contract; add-on cannot import private Core managers or rewrite Ansible arguments | Jenkins has a broad Pipeline/plugin model; Foreman integrates host/provisioning components; Semaphore supports several automation applications. Flexibility also increases the scope an administrator must configure and govern. [J1, F1, S2] |
|
||||
|
||||
## What the new modal improves
|
||||
|
||||
The implemented path is now: open an existing reservation, recognize the reviewed customer/targets/mode, enter only the required credentials, submit once, then follow the job. Core-permitted key-passphrase choices use native radio buttons styled as a segmented control. Changing that presentation choice does not change reviewed scope, native inventory precedence or execution identity. [A2]
|
||||
|
||||
This intentionally avoids asking an operator to configure a reusable credential resource just to perform one reviewed run. It also preserves a cost: repetitive or unattended operations are less convenient when credentials must be resupplied. That tradeoff is part of the current requested product boundary, not evidence that all stored-credential products are unsafe. [A2, J4, S4]
|
||||
|
||||
Jenkins' input step demonstrates the value of making pending human input an explicit workflow state. Semaphore's template prompts demonstrate the value of exposing only the options a particular task needs. Our application of those lessons is the new Needs your attention section and Core-driven fields, not importing their wider parameter or credential models. [J3, S2]
|
||||
|
||||
## Where AIM Web is already well aligned with this controller
|
||||
|
||||
The strongest fit is the combination of explicit target review, customer-aware discovery, optional saved plans, per-target final results and linked host activity. Operators can inspect an inventory branch, open a host, find its last retained Checkmk result and return to the source run without moving inventory ownership out of AIM Core. The mobile header and native modal now make that narrower workflow easier to navigate. These are implemented behaviors, not evidence that our UI is universally faster or more accessible than the other products. [A1, A2]
|
||||
|
||||
The history design is unusually explicit about what it does not know: no terminal AIM runs, deleted-job reconstruction, current-health score, inferred installed version or invented success for legacy data. A partially successful parent job does not erase each target's own final outcome. Preserve that clarity as the UI grows. [A1]
|
||||
|
||||
## Where established platforms set a higher bar
|
||||
|
||||
**Operational breadth:** reusable template catalogs, external integration, distributed execution, scheduled orchestration and richer organization models are documented strengths across these platforms. AIM Web does not yet provide comparable breadth, and turning a UI preference into a rushed workflow engine would undo the modularity gained from Core. [J1, S1, S6, S7, F1]
|
||||
|
||||
**Investigative detail:** a retained full log can answer questions our ephemeral, filtered stream cannot. Semaphore explicitly exposes task logs after completion. AIM currently retains final facts, not a full transcript. A future Core-approved retention contract should be considered separately rather than quietly capturing raw stdout because it is convenient. [S5, A1]
|
||||
|
||||
**Release and deployment assurance:** our recent manifest, startup and permission failures remain evidence that packaging and controller acceptance need attention. A passing synthetic suite does not establish production-browser, systemd, SSH/WinRM, upgrade or security qualification. This report does not claim comparable maturity or measure other products' defect rates. [A3]
|
||||
|
||||
**Access administration:** project-scoped teams, federation and larger administrative structures deserve a deliberate design if the audience expands beyond the current controller. Semaphore documents built-in project roles and Enterprise extensions; those are not equivalent to our existing local execution grants. [S8, A1]
|
||||
|
||||
## Security is not a badge comparison
|
||||
|
||||
Jenkins documents encrypted stored credentials and ID-based use; its binding documentation also explains masking limitations and risks from processes sharing execution accounts. This is useful context, not a reason to claim that masking or a modal prevents all disclosure. [J4, J5]
|
||||
|
||||
AIM's transient credential path reduces intentional add-on secret retention, but authorized controller code and service accounts remain trusted. DOM clearing cannot prove physical memory erasure. Core owns execution semantics; an accepted credential handoff does not prove authentication. Foreman/Semaphore/Jenkins have different persistence, identity and deployment choices that require their own configured-environment review. [A2]
|
||||
|
||||
## Recommended direction after this RC
|
||||
|
||||
My recommendation is to borrow interaction patterns, not product scope.
|
||||
|
||||
1. **From Semaphore:** make supported playbook inputs feel like a small, well-labeled task form. Keep preflight and execution semantics in Core. Improve template/saved-plan discovery before adding arbitrary parameters.
|
||||
2. **From Foreman:** strengthen host-centric navigation and contextual actions. Add dated last-result overlays and comparisons of recorded runs, not invented live health or inventory mutation.
|
||||
3. **From Jenkins:** make stage transitions and pending human action unmistakable. Keep cancellation, acknowledgement uncertainty and dependency failures visible without turning every event into a wall of log text.
|
||||
|
||||
None of those follow-on features is claimed shipped in this RC. The immediate release contains the modal and attention surface; targeted retry preparation, history overlays, run comparisons, federation and workflow orchestration remain separate proposals. Reliability and installed-controller acceptance should remain the next gate.
|
||||
|
||||
## Official references and inspected AIM files
|
||||
|
||||
Sources are provided as exact locations so the comparison can be rechecked as products evolve.
|
||||
|
||||
- **A1** - This release: `AGENTS.md`, `docs/READ-ONLY-EXPERIENCE.md`, `docs/API.md`, `src/aim_webgui/activity.py`, `explorer.py`, `workflows.py` and `worker.py`.
|
||||
- **A2** - This release: `docs/RUN-COMFORT.md`, `docs/CREDENTIALS.md`, `credentials/presentation.py`, `credentials/service.py`, `routes/workflows.py`, credential templates and `static/js/credentials.js`.
|
||||
- **A3** - This release: `docs/VERIFICATION.md`, `docs/verification-results.json` and preserved `CHANGELOG.md` provenance.
|
||||
- **J1** - Jenkins Pipeline: `https://www.jenkins.io/doc/book/pipeline/`
|
||||
- **J2** - Official Jenkins Ansible plugin: `https://plugins.jenkins.io/ansible/`
|
||||
- **J3** - Jenkins Pipeline Input Step: `https://www.jenkins.io/doc/pipeline/steps/pipeline-input-step/`
|
||||
- **J4** - Jenkins Using credentials: `https://www.jenkins.io/doc/book/using/using-credentials/`
|
||||
- **J5** - Jenkins Credentials Binding: `https://www.jenkins.io/doc/pipeline/steps/credentials-binding/`
|
||||
- **S1** - Semaphore UI user guide: `https://semaphoreui.com/docs/user-guide`
|
||||
- **S2** - Semaphore task templates: `https://semaphoreui.com/docs/user-guide/task-templates/views` and `https://semaphoreui.com/docs/user-guide/task-templates`
|
||||
- **S3** - Semaphore inventory: `https://semaphoreui.com/docs/user-guide/inventory`
|
||||
- **S4** - Semaphore Key Store: `https://semaphoreui.com/docs/user-guide/key-store`
|
||||
- **S5** - Semaphore Tasks and log retention: `https://semaphoreui.com/docs/user-guide/tasks`
|
||||
- **S6** - Semaphore Schedules: `https://semaphoreui.com/docs/user-guide/schedules`
|
||||
- **S7** - Semaphore documentation index (Workflows Pro): `https://semaphoreui.com/docs`
|
||||
- **S8** - Semaphore Teams and Enterprise RBAC: `https://semaphoreui.com/docs/user-guide/team`
|
||||
- **F1** - Foreman introduction: `https://www.theforeman.org/introduction.html`
|
||||
- **F2** - Foreman 3.18 Managing hosts: `https://docs.theforeman.org/3.18/Managing_Hosts/index-foreman-el.html`
|
||||
- **U1** - User-provided Bootstrap4 button pattern: `https://getbootstrap.com/docs/4.0/components/buttons/#checkbox-and-radio-buttons`
|
||||
- **U2** - Bootstrap5 native check/radio toggle buttons used by this release: `https://getbootstrap.com/docs/5.3/forms/checks-radios/`
|
||||
- **U3** - WAI modal dialog interaction guidance: `https://www.w3.org/WAI/ARIA/apg/patterns/dialog-modal/`
|
||||
Reference in New Issue
Block a user