# AIM WebGUI 2.1.0rc9 Independent add-on for **AIM Core 3.3.0rc8**, service/wire/event API **1.0**. WebGUI HTTP API **v2**; SQLite **schema 5**. This remains a release candidate, not a native Windows Update/controller acceptance certificate. ## This update Core 3.3.0rc8 keeps service/wire/event API 1.0 and the nine structured report contracts, while tightening the native Windows baseline and several runbook internals. WebGUI now qualifies exactly against rc8 and requires the live capability metadata to advertise `ansible.windows >=3.8.0,<4.0.0`. Collection installation remains Core/operator owned; the add-on does not upgrade it. The patch report accepts rc8's additive `reboot_reasons_before` facts from native `ansible.windows.win_reboot_info`, renders them as dated observations, and keeps them separate from the existing reboot-required/blocked/continuation semantics. The overall patch policy remains unchanged: no automatic retry, no automatic follow-up job, and no silent post-reboot continuation. Windows filesystem reporting is relabeled to match rc8: it represents attached local storage volumes. Mapped/network drives are intentionally outside that host-capacity report. Existing retained reports continue to render against their recorded contracts. Core also relocates several AIM-managed Checkmk scripts and hardens their Windows ACLs. Those are Core/runbook changes, not WebGUI API changes; WebGUI continues to display the validated structured reports rather than reconstructing filesystem paths or ACL state. ## Preserved functionality The credential modal, grouped passphrase controls, compact mobile hamburger/theme header, inventory map, Host Activity, Playbook Insights, one-run review, optional collision-safe plan names and per-target/partial-success views remain. The worker-side structured journal survives page reloads and other-device viewing: tail of20,000 events or8MiB by default. Final reports for nine schemas are retained separately with a16MiB per-job budget; full parsed Checkmk configuration stays opt-in. No raw output archive, credential cache, terminal-history collector, inventory/Vault manager or alternative execution engine is added. Job deletion removes linked evidence. ## Install or upgrade Fresh installations: follow [ADDON-INSTALLATION.md](ADDON-INSTALLATION.md) after Core's separate `scripts/docs/INSTALLATION.md`. Upgrades: read [Deployment](docs/DEPLOYMENT.md). Quiesce work, independently deploy Core3.3.0rc8 with its own preview/apply procedure, then install from a fresh add-on extraction. The old add-on's exact Core gate must not be bypassed. ```bash cd /var/tmp sha256sum -c AIM-WebGUI-2.1.0rc9.zip.sha256 unzip AIM-WebGUI-2.1.0rc9.zip cd aim-web-2.1.0rc9 sudo python3 deploy/deploy.py update ``` No --migrate-core flag is needed from2.x. From2.1.0rc3, no database schema change is needed. Accounts/plans/jobs/journals/reports/audit are retained. The approved full webgui.toml is still release-managed and overwritten. Existing unit/permission/staging contracts, dependency pins and browser pins are unchanged. No new ports or services. Unknown local unit overrides still require operator review. ```bash aim-web --version aim-web config-check sudo systemctl status aim-web-executor.service aim-web.service aim-web-worker.service --no-pager sudo -u aim-web aim-web core-check ``` ## Guides - [Patch-wave inputs, reports and semantic boundaries](docs/PATCH-WAVES.md) - [Reviewed Core rc8 delta](docs/CORE-3.3.0RC8-REVIEW.md) - [Operation reports](docs/REPORTS.md) and [retained progress](docs/JOURNAL.md) - [Credential modal](docs/RUN-COMFORT.md) and [read-only history](docs/READ-ONLY-EXPERIENCE.md) - [Controller acceptance](docs/CONTROLLER-PILOT.md) - [Current verification and limits](docs/VERIFICATION.md) - [Public API](docs/API.md), [security](docs/SECURITY.md), [agent standards](AGENTS.md) The release is not a complete offline dependency bundle. Bootstrap5.3.8 / HTMX2.0.10 remain locally served and integrity-checked by the installer. Tests are separate from managed production environments; fixture browser assets and native-command simulators are never release acceptance of actual target updates or the production service sandbox.