Files
2026-09-22 19:23:17 +02:00

42 KiB

Changelog

2.1.0rc9 - Core 3.3.0rc8 release reconciliation

Compatibility: separately deployed Core 3.3.0rc8; public service/wire/event 1.0; WebGUI HTTP v2; SQLite schema 5 unchanged.

  • Repackage the rc8-compatible WebGUI line as rc9 after reconciling current-release metadata, operator guidance and verification evidence with the supplied Core 3.3.0rc8 archive.
  • Preserve the rc8 public contract and live capability gates, including ansible.windows >=3.8.0,<4.0.0, play_task_host_v1, inventory_hierarchy_v1, target_outcome_summary_v1, native_defaults_preflight_v2 and structured operation results.
  • Remove stale current-candidate rc4/rc5 labels from active documentation while retaining historical release notes and historical Core reviews as provenance.
  • Refresh release verification against the supplied rc8 source tree; no Core files, database schema, service API, permission model, credential model or execution semantics are changed by this repackaging.
  • Correct a stale legacy rollback comment (rc18-only) to describe the actual pre-2.x adapter boundary; runtime behavior is unchanged.

2.1.0rc5 - Core 3.3.0rc8 compatibility

Compatibility: separately deployed Core 3.3.0rc8; public service/wire/event 1.0; WebGUI HTTP v2; SQLite schema 5 unchanged.

  • Requalify the exact adapter/executor/deployment gates for Core 3.3.0rc8 while retaining live capability negotiation.
  • Require Core's advertised ansible.windows >=3.8.0,<4.0.0 collection baseline. WebGUI does not install or upgrade collections.
  • Accept and render the additive patch_summary_v1.reboot_reasons_before native reboot-source observations without changing job verdicts or triggering follow-up work.
  • Update Windows filesystem-report wording to attached local storage volumes; mapped/network drives are intentionally excluded by Core rc8.
  • Preserve patch continuation, remaining-update knowledge, HRESULT presentation, report/journal retention, credentials, mobile UX, database schema 5 and the existing permission/systemd model.
  • Treat Core rc8 Checkmk script relocation/ACL hardening as Core-owned runbook behavior; do not reconstruct paths/ACLs or add private APIs.
  • Update fresh-install, deployment, controller-pilot and agent guidance for the new native collection floor and Core rc8 acceptance boundary.

Preserved previous release notes

2.1.0rc4 - Core 3.3.0rc3 patch-wave support

Compatibility: separately deployed Core3.3.0rc3; public service/wire/event1.0; WebGUI HTTPv2; SQLite5 unchanged from rc3.

  • Update exact adapter/executor/CLI/deployment compatibility checks while retaining live capability negotiation. Core remains unchanged.
  • Expose reboot message/delay and Windows-only post-reboot continuation through existing public catalog forms, showing platform applicability and catalog hints. Blank still omits overrides. Review distinguishes explicit reboot/continuation/delay from inherited inventory/role policy.
  • Present continuation_required independently from successful/failed Core and job status. No automatic follow-up jobs, reboot enablement or continuation override.
  • Render reboot before/after/deferred state, observed AIM reboot, reviewed delay, cycles, stop reasons and per-update unsigned/hex HRESULT, fixed reason and safe message. No raw fatal-text/event-log parsing.
  • Treat remaining_updates_known=false as unknown rather than an authoritative empty/old queue. True labels a final read-only, dated discovery, not an expanded install queue or current compliance. Original validated JSON stays available.
  • Preserve old patch reports using their recorded contracts, including the older closed patch_summary_v1 shape; do not invent absent fields or validate old history against the new catalog.
  • Keep modal/mobile/graph/history, retained journal/report policy, target outcomes, execution review, credential boundaries and the generated permission/unit contract unchanged.
  • Include the requested ADDON-INSTALLATION.md in the release and update deployment/patch acceptance/agent guidance. No new database migration, dependencies, services or write exceptions.
  • Add public-Core rc3, historical-report, patch-state, escaped-output and review regression coverage. Actual results and environment limitations are in docs/VERIFICATION.md.

Preserved previous release notes

2.1.0rc3 - Core3.3 reports and retained execution evidence

  • Target independently managed Core3.3.0rc1 with existing service/wire/event1.0; WebHTTPv2, additive SQLite schema5.
  • Preserve negotiated result contracts in review; validate final operation reports and new result_validation/error families while keeping native outcome and report availability separate.
  • Separate large public-result framing from unchanged inbound credential/request limits; reject malformed, torn or oversized payloads without replay.
  • Retain structured worker-side progress with bounded batched writes, tail/checkpoints, durable cursor replay and explicit coverage gaps. No raw output or browser-dependent collection.
  • Retain eight ordinary report types by default and only metadata for parsed Checkmk config unless opted in. All9 schema-keyed summaries and generic supported JSON views; lazy per-slot payload reads, dated Host Activity links.
  • Cascade report/journal deletion with jobs, preserving only compact audit metadata. Historical jobs are not backfilled and stale pre-upgrade work is stopped by migration.
  • Preserve modal, mobile header, hierarchy/history, normal executor identity and all narrow staging/IPC permissions. Add restored-adapter Core compatibility check before service restarts on rollback.
  • Qualification evidence is recorded in docs/VERIFICATION.md; no new live-host certification is implied.

Historical releases

Changelog

2.1.0rc2 - one-run credential dialog and attention

Compatibility: AIM Core 3.2.1rc2; service/event API 1.0; WebGUI HTTP v2; SQLite schema 4. No Core, deployment, permission or dependency-pin change.

  • Replace default navigation to password entry with an owner-initiated native modal; retain full-page/no-JavaScript fallback. The modal is outside polled job fragments.
  • Show reviewed job context, server-synchronized reservation countdown, required fields, Show/Hide and Caps Lock feedback. Short/mobile viewports scroll within the dialog.
  • Add Bootstrap 5 segmented radio choices for customer-Vault versus separate SSH key passphrase only when Core permits both. Explicitly required key passphrases stay required. No Custom authentication override.
  • Clear revealed/masked inputs on dismissal, submit, invalidation and navigation. Treat lost acknowledgement as uncertain; reconcile with read-only status rather than automatically resending credentials.
  • Add Needs your attention to Overview/Jobs with owner credential actions and existing independent-administrator review links. Do not change approval or execution policy.
  • Add canonical /api/v2/runs/{id}/credentials POST alias, retaining /api/v2/jobs/{id}/credentials; add owner-only credential-status and guarded HTML fragment GETs. Both POST routes share existing throttling and worker handoff.
  • Preserve literal secrets, CSRF/origin/session/grant checks, bounded bodies and existing one-run deadlines. Improve ambiguous-handoff wording; enforce an explicitly required SSH key passphrase.
  • Add synthetic endpoint and real local worker-socket tests plus mobile/desktop credential-dialog browser fixtures. See VERIFICATION.md for measured results and limitations.

2.1.0rc1 - read-only experience candidate

Compatibility: independently managed AIM Core3.2.1rc2; service/wire/event1.0; WebGUI HTTPv2; SQLite4. Based on WebGUI2.0.0rc8. No new Core requirement, database migration, runtime permission or execution-policy change.

  • Replace the mobile swipe rail with a compact AIM-home / sun-moon / right-aligned hamburger row and native keyboard-operable dropdown; desktop sidebar retained.
  • Add current Core Inventory Explorer with linked SVG group/host map, branch focus, distinct counts, search and equivalent mobile outline. Graph nodes navigate, never execute.
  • Add Host Activity from retained WebGUI final per-target results with mode/time/playbook/outcome filters, paginated timeline, counter details and own saved-plan references.
  • Add Playbook Insights with explicit metric denominators, outcome distribution, paged host-by-playbook matrix and mobile cards. Never scrape terminal/core-wide history or infer live health.
  • Scope aggregation to underlying job authorization before reading records; cover more than100 jobs, legacy/unknown data and deletion without a shadow archive.
  • Connect existing host lists, job target summaries, Jobs and Saved Plans previews to activity pages. Keep partial host/parent outcomes distinct and current inventory outages visible.
  • Preserve one-run review/idempotency, optional collision-safe names, credentials, retry/deletion controls, bounded live output and existing managed permission model.
  • Reconcile current agent/read-only/mobile documentation and add unit, real-Core read, browser-fixture and synthetic large-history coverage. Actual qualification is recorded in docs/VERIFICATION.md, not inferred from older RC counts.

Preserved historical record

The following is the changelog as supplied in2.0.0rc8, including its duplicated historical headings. It is retained as provenance; it is not new2.1 behavior or new verification.

Changelog

2.0.0rc8

  • Require and integrate AIM Core 3.2.1rc2 / service API 1.0 while preserving the independent Core/WebGUI release boundary.
  • Consume target_outcome_summary_v1 and retain Core's authoritative overall failed status while presenting mixed requested-target outcomes as Partially succeeded in WebGUI.
  • Show Core-provided per-target outcome and task counters on Job detail; Jobs overview shows successful/requested and failed/unreachable/not-started/indeterminate counts. No task-event reconstruction is used for final host state.
  • Consume read-only inventory_hierarchy_v1 for nested parent/subgroup selection and inventory display. Parent scopes include Core-declared descendant hosts; execution still submits explicit reviewed hostnames.
  • Require native_defaults_preflight_v2; keep rc6 release-managed split-home staging and executor sandbox unchanged.
  • Remove the special persistent orange outline around Jobs and Saved plans; active/hover navigation styling remains consistent with the rest of the menu.
  • Preserve one-run jobs, optional collision-safe plan names, detailed safe live output, running-job deletion protection, API v2, SQLite schema 4, and the rc6 managed permission model.

2.0.0rc6

  • Fix delegated localhost execution under the hardened executor sandbox. Ansible 2.19 local connections expand ~svc_bf-ansible/.ansible/tmp from the passwd database even when the executor service sets HOME=/var/lib/aim-web-executor.
  • Release-manage /home/<executor>/.ansible and /home/<executor>/.ansible/tmp as executor-owned 0700, and grant ReadWritePaths only to that exact local staging path while keeping ProtectHome=read-only.
  • Extend core-staging-check so startup validates both Core controller-local staging and Ansible delegated-local staging inside the actual systemd sandbox.
  • Do not set global ANSIBLE_REMOTE_TMP; doing so would also alter POSIX temp paths on managed Linux hosts.
  • Preserve Core 3.2.1rc1 detailed progress, managed socket/runtime permissions, API v2, SQLite schema 4, and existing credential boundaries.

2.0.0rc5

  • Fix the rc4 executor-start race: deployment now waits for the Type=simple executor to bind and permission /run/aim-web-executor/core.sock before validating runtime ownership/mode. A temporarily missing socket is treated as startup-in-progress rather than immediate migration failure.
  • Fail deterministically if the executor service exits before binding, or if the managed socket does not become ready within the bounded startup window.
  • Preserve the rc4 release-managed identity model: svc_bf-ansible primary user/group, unit-scoped aim-web supplementary group, executor-owned 0711 runtime directory, and executor:aim-web 0660 socket.
  • No Core, database schema, API, credential, inventory, Vault, key-ownership, or global SSH-trust changes.

2.0.0rc5

  • Fix the rc3 runtime-directory ownership transition: systemd now owns /run/aim-web-executor as the executor identity with mode 0711; authorization remains on core.sock as executor:aim-web 0660. This removes runtime chgrp and allows upgrades from rc2 without manual /run repair.
  • Preserve the release-managed executor primary group plus unit-scoped aim-web supplementary group, staging checks, config/state ownership, and detailed Core 3.2.1rc1 progress rendering.

2.0.0rc5 — Core 3.2 detailed progress, operational UI, and managed permissions

Compatibility: AIM 3.2.1rc1; public core service/wire/event 1.0; detail schema play_task_host_v1; WebGUI HTTP v2; SQLite 4.

  • Negotiate progress_mode=detail and render safety-filtered play/task/host progress in the live job console while keeping raw module stdout/stderr unavailable.
  • Adopt Core 3.2.1rc1 controller staging preflight requirements in the executor unit: private .ansible/tmp, scoped ReadWritePaths, and startup staging check.
  • Add semantic job state chips, richer Jobs and Saved plans scope previews, stronger navigation emphasis, aligned Audit filters, and viewport-bounded internal console scrolling.
  • Preserve running-job deletion protection, one-run execution, optional collision-safe plan names, API v2, schema 4, and separate non-root core executor architecture.
  • Preserve the executor account's normal primary group and grant aim-web only as a unit-scoped supplementary group; no /etc/group mutation is performed.
  • Release-manage and verify WebGUI config/state, executor HOME/staging, systemd unit ownership, runtime directory group, and core socket mode/ownership during deployment.
  • Keep Core-owned inventory/Vault/private-key permissions and global SSH trust outside WebGUI's ownership boundary.

2.0.0rc1 — independent core API migration

Compatibility: AIM3.1.0; public core service/wire/event1.0; WebGUI HTTPv2; SQLite4. Release candidate: no live-controller execution qualification is implied.

  • Replace private rc18 imports/command hooks/Ansible strategies and sudo key export with the documented aimctl protocol. Pre-started non-root add-on executor under the existing authorized key-owning account; no automatic core/user/permission edits.
  • New run -> review -> one-run submission, without a saved plan. Mode/key handling included in immutable review. Saving is secondary and optional.
  • Generated unique titles for blank names, transactional casefold/NFKC duplicate rejection for explicit account-local titles. Never overwrite by title.
  • Preserve authentication, grants, history, audit, bulk deletion, explicit retry, existing orange light/dark/mobile shell and browser-local timestamp lifecycle.
  • Schema4 retains records; old pending/queued jobs blocked, running interrupted. Old plans require fresh core review. Historical duplicate titles retained.
  • Retire unsupported Custom/raw-console features rather than misrepresent native inventory defaults or bypass the new API. Platform groups remain selectable; core1.0 lacks subgroup paths. Structured final core result/counters are shown.
  • Major migration requires --migrate-core; stages public core checks as executor, backs up/removes known legacy helpers/drop-in, uses no privileged capabilities. Rollback to legacy adapter remains stopped with incompatible core.
  • Verify the release manifest before deployment; use a separate executor HOME for native caches and independently verified host trust. Alternative direct-HTTP browsing profile keeps execution/credentials disabled.
  • New API/migration/security/contract-review/agent guidance and regression coverage.

Historical WebGUI1.x entries (superseded architecture)

Changelog

2.0.0rc5

  • Fix the rc3 runtime-directory ownership transition: systemd now owns /run/aim-web-executor as the executor identity with mode 0711; authorization remains on core.sock as executor:aim-web 0660. This removes runtime chgrp and allows upgrades from rc2 without manual /run repair.
  • Preserve the release-managed executor primary group plus unit-scoped aim-web supplementary group, staging checks, config/state ownership, and detailed Core 3.2.1rc1 progress rendering.

1.1.0rc10 - 2026-09-19 (ephemeral live job console and execution diagnostics)

  • Adds an authenticated same-origin Server-Sent Events job console backed by an owner-only local Unix socket. Playbook output is bounded in memory, sanitized before leaving the worker child, cleared on navigation, and never stored in SQLite, audit history, or regular files.
  • Keeps the console outside the HTMX-polled status fragment so polling cannot erase the stream. SSE responses disable proxy buffering and use keepalives for reverse-proxy compatibility without WebSockets.
  • Classifies non-zero Ansible runs into remote connection/authentication, playbook task, controller/playbook-loading, or generic execution failures using sanitized output only.
  • Retains rc9 credential/runtime fixes and AIM 3.0.0rc18 compatibility; no AIM or database-schema changes.

1.1.0rc9 - 2026-09-19 (Ansible 2.19 runtime qualification fixes)

  • Treat resolved Vault/connection secret values as literal data. Standard AIM exact variable references are dereferenced once; the resulting password/passphrase is never recursively templated, so Jinja-looking password text remains unchanged.
  • Remove the empty ANSIBLE_CALLBACKS_ENABLED environment override. Ansible Core 2.19.11 interprets an empty callback name as an invalid plugin and aborts before playbook execution.
  • Correct the synthetic SSH-key runtime test to use owner-only 0600, matching the secure canonical-key policy.
  • Correct credential-check acceptance-test guidance for a disposable test environment and AIM_TEST_ANSIBLE_PYTHON.
  • No AIM 3.0.0rc18, SQLite schema, permission model, HTTP API version, or credential lifetime change.

1.1.0rc8 - 2026-09-19 (secure key handoff + history QOL)

  • Fix the rc7 secure-key preflight: the resolver no longer opens canonical service-owned 0600 SSH private keys as aim-web. It validates path/type/mode metadata only; the restricted export helper running as AIM service_user is the sole reader of canonical key bytes.
  • Add bulk deletion to the Jobs overview for terminal jobs and to the Saved Plans overview for the requesting account's own plans. Individual deletion and append-only deletion audit records remain.
  • Add Retry as new job for failed jobs. Retry is requester-only, manual, creates a new job ID, revalidates current grants/source revisions/execution policy, preserves reviewed non-secret parameters and credential mode, and requires fresh one-run credentials.
  • Preserve the secure permission model: inventory/Vault sharing through aim-runtime; canonical private keys owned by AIM service_user at 0600; one-job WebGUI key copies only.
  • No AIM 3.0.0rc18 or SQLite schema change. HTTP API v1 gains the additive manual retry endpoint.

1.1.0rc7 - 2026-09-19 (rc6 deployment packaging fix)

  • Fix deployment of the restricted SSH key-export helper after the staged source directory is atomically activated. rc6 moved the staging directory before reading key_export.py, then attempted to read the obsolete staging path and rolled back. rc7 reads the helper from the activated managed source tree.
  • No AIM 3.0.0rc18, SQLite schema, execution policy, credential protocol, or WebGUI API changes.
  • Retains the rc6 secure permission model, terminal-job deletion, saved-plan deletion, and browser-local timestamp behavior.

1.1.0rc6 - 2026-09-18 (Ansible 2.19 Vault/runtime qualification fixes)

  • Use Ansible Core 2.19.11's runtime VaultSecret API with UTF-8 bytes for one-run Vault passwords; remove the unavailable TextVaultSecret test-helper import exposed by controller qualification.
  • Keep /usr/bin as the shipped Ansible binary directory for this controller profile and resolve /usr/bin/python3 from the actual ansible-playbook runtime rather than assuming a venv.
  • Distinguish missing, unreadable and empty SSH private keys using sanitized fixed messages. Permission failures now point to the shared aim-runtime read/traverse policy rather than collapsing into a generic Vault/reference error.
  • Preserve the rc4 fixes for literal special characters, explicit Vault-decrypt preflight, browser-local timestamp rendering, grant de-duplication and one-run credential lifetime.
  • Document the qualified filesystem model: AIM/WebGUI runtime identities need read/traverse access to encrypted Vault and configured customer private keys; AIM source remains externally managed and unchanged.
  • No AIM, HTTP API or SQLite schema change.

1.1.0rc3 - 2026-09-18 (grant picker de-duplication)

  • Scoped execution grant forms now refresh the playbook choices for the selected account/customer and omit exact grants the account already has.
  • If every catalog playbook is already granted for that scope, the form shows a disabled explanatory option instead of offering a duplicate grant.
  • Duplicate grant submissions are rejected server-side with a conflict response rather than silently succeeding.
  • Existing grants remain visible below the form for review and revocation.
  • No schema, credential, execution, API version, AIM compatibility, or deployment-policy changes.

1.1.0rc2 - 2026-09-18 (administration layout fix)

  • Removed the duplicate Scoped execution grants panel from the User administration page subtitle area.
  • Kept a single grant-management panel below Local accounts / Add account so account administration reads top-to-bottom without repeated controls.
  • No schema, credential, execution, API, AIM compatibility, or deployment-policy changes.

1.1.0rc2 - 2026-09-18 (credential feature candidate)

Compatibility: AIM 3.0.0rc18 only, unchanged; HTTP API v1 with additive credential routes; SQLite schema 3 (additive from 2); Python >=3.11. Credential execution targets Ansible Core 2.19.11 exactly, in the existing external Ansible environment. No Ansible/AIM package is installed or updated.

Candidate, not production-qualified: the build environment could not obtain Ansible 2.19.11 or OpenSSH client tools. Local protocol/route/policy tests and fake-worker regression tests pass; real Ansible/SSH/WinRM qualification remains required. Read docs/VERIFICATION.md, not a test count as a certification.

Added

  • Separate disabled-by-default [credentials] enabled switch, plus existing execution allowlist, HTTPS transport attestation and approval requirements.
  • Accessible Vault/Custom mode control at job review. The custom username and mode become immutable reviewed metadata. Passwords are collected only after approval and the single worker reserves the job; they are not plan fields.
  • Five-minute empty worker reservation and 60-second single-run hand-off/start deadline. No secrets are held for approval or scheduled-job delays. A retry or check-to-apply is a new credential submission. No automatic replay on restart.
  • Private Unix socket hand-off, requester/session/job checks, anonymous child pipe and job-private password-source helpers. Add-on code never persists infrastructure passwords to SQLite, helper text, argv or environment values.
  • Resolver in the existing Ansible Python: standard customer Vault, effective host/group connection references, per-host Windows NTLM credentials, existing customer SSH keys and separate Vault key passphrase. Unused legacy SSH password references do not block key authentication.
  • Custom mode overrides connection identity/password for every selected host; disables prior SSH control sockets and key/agent fallback. SSH uses an add-on ASKPASS helper, avoiding the native 2.19 named password shared-memory helper.
  • Dedicated linear strategy adapter and final launch authorization. Endpoint changes, unsupported auth transports and selected source patterns fail closed.
  • aim-web credential-check for non-secret exact-runtime/import/tool checks; six opt-in synthetic actual-Ansible tests and an execution acceptance guide.
  • Mobile/desktop credential page and no-echo error handling. Existing appearance, account policy, selection semantics and network/TLS profile remain unchanged.

Deliberate restrictions

  • Standard SSH and WinRM/NTLM only; no network/API plugins, become-password collection, private-key uploads, saved passwords, raw output streaming or SSO.
  • Credential jobs reject delegation, asynchronous tasks, explicit strategies, dynamic task imports/inventory changes, external roles and SSH argument escape hatches. Some rc18 catalog plays (notably delegated Checkmk work) remain terminal only. An allowlist entry is not a guarantee that a play is eligible.
  • Custom credentials may still require Vault unlock for unrelated play variables.
  • Passwords use small HTTPS POST bodies. Proxy/body buffering and trusted playbook behavior remain deployment responsibilities; process separation/shared UID is not a privilege sandbox, and Python does not promise physical memory erasure.

Upgrade and rollback

  • Whole-release replacement and overwritten TOML continue. Credentials and execution are both disabled in shipped defaults; the backend TLS setup is not touched. Existing accounts, sessions, plans and jobs survive forward migration.
  • Schema 3 adds only credential phase/deadline metadata, not a credential store.
  • Rollback to 1.0.0/schema2 requires explicit historical database restoration, losing post-checkpoint changes and potentially restoring old passwords. Make a current protected backup first. Do not manually repoint the active venv.
  • Global AGENTS.md and security/API/deployment/execution docs updated together.

1.0.0 - 2026-09-18

Compatibility: AIM 3.0.0rc18 only (unchanged); HTTP API v1; SQLite schema 2; Python >=3.11. Independently versioned add-on, not an AIM release.

Added

  • Named-administrator setup and bootstrap retirement, with forced first-password change and last-admin/session protections retained.
  • Status/config-check/doctor CLI and administrator System diagnostics.
  • Inventory search, group filters, sorting and 100-row browse pagination; private selection restoration, clear/visible select-all controls.
  • Typed catalog forms and private non-secret saved plans/preset reuse, using existing rc18 input parsing and target validation.
  • Searchable/paginated administrative audit history and lifecycle events.
  • Optional disabled-by-default worker using rc18's existing PlaybookManager.run and its external_presentation hook; no monkey patches or duplicated AIM CLI.
  • Exact customer/playbook execution grants; catalog allowlist; independent administrator approval; one active job; host/timeout/start-window policies; idempotent submission; one-shot UTC schedules; cancellation and crash recovery.
  • API v1 plan, selection, diagnostics, audit and job routes. Existing preflight remains validation-only. POST /api/v1/runs returns 501 while execution is off.
  • Source-revision checks at submission and dispatch; interrupted jobs are never automatically replayed. Potentially sensitive raw command output is discarded.

Fixed

  • Mobile group count badges have their own constrained grid slot instead of overflowing two-column group cards. Long labels wrap without moving counts out.
  • The mobile navigation rail now shows scroll instructions and arrow controls.
  • Deployment journals before replacing TOML; checks installed candidate identity; manages the worker with rollback; tests schema compatibility before rollback.
  • Verified, unchanged installed browser assets can be reused without a download.

Deployment changes requiring review

  • Release-managed TOML now uses loopback 127.0.0.1:8080 and trusts 127.0.0.1, matching NPM -> HTTPS controller:8443 -> local Nginx -> WebGUI. NPM/certificates are externally managed and are NOT modified by the add-on deployment.
  • Additive schema 1 -> 2 migration preserves accounts. Rollback to 0.1.x needs explicit --restore-auth-db and loses post-checkpoint data; read the guide.
  • Execution is off, has an empty allowlist, and has no TLS verification attestation by default. A release upgrade does not silently enable jobs.
  • Raw output streaming and interactive infrastructure credentials remain deferred.
  • See docs/VERIFICATION.md for actual test results and live-controller limits.

AIM WebGUI changelog

WebGUI uses its own version sequence. An add-on release does not imply any AIM release, source edit or upgrade. Every entry must include supported AIM versions, auth schema compatibility, HTTP API compatibility and upgrade/rollback notes.

0.1.6 - 2026-09-17

Compatibility

Component Contract
AIM base 3.0.0rc18 only; unchanged and externally managed
Python 3.11+
HTTP API v1 unchanged
Add-on database Schema 1 unchanged
WebGUI config Release-managed; overwritten on install/update/rollback

Added / changed

  • Made mobile/responsive behavior a global UI standard. At 760px and below the desktop sidebar becomes a compact sticky header with one non-wrapping, horizontally scrollable navigation rail, preventing staggered/wrapped top navigation.
  • Reworked the mobile account/display bar so theme controls and account actions remain level and usable, long usernames ellipsize, and the desktop layout remains unchanged.
  • Added narrow-screen rules for touch-friendly group controls, contained table scrolling, stacked forms/actions, responsive system facts, reduced card spacing, and device safe-area insets.
  • Expanded the repository-root AGENTS.md into the authoritative AI-agent/contributor standards document covering the immutable AIM boundary, release/state ownership, security invariants, design system, mobile requirements, selection semantics, authentication, testing, verification, and documentation upkeep.

Upgrade / rollback

Whole-release replacement semantics are unchanged. The release-managed deployment profile remains the validated https://aim.desq-gaming.de / Nginx Proxy Manager configuration from 0.1.5. /var/lib/aim/webgui auth/runtime state remains preserved across normal updates. AIM rc18 is never modified.

0.1.5 - 2026-09-17

Compatibility

Component Contract
AIM base 3.0.0rc18 only; unchanged and externally managed
Python 3.11+
HTTP API v1 unchanged
Add-on database Schema 1 unchanged
WebGUI config Release-managed; overwritten on install/update/rollback

Added / changed

  • Replaced the text Light/Dark selector with compact sun/moon theme controls while retaining explicit accessible labels and pressed-state semantics.
  • Tidied inventory-group bulk-selection controls and aligned the select-all header checkbox exactly with host-row selection checkboxes. Selection behavior and explicit-host-only preflight semantics are unchanged.
  • Managed deployment now creates /usr/local/bin/aim-web as a guarded symlink to /opt/aim-web/current/bin/aim-web. It follows update/rollback automatically and refuses to overwrite unrelated files or symlinks.

Upgrade / rollback

Whole-release replacement semantics are unchanged. The release-managed config still uses https://aim.desq-gaming.de, backend listener 0.0.0.0:8080, and trusted Nginx Proxy Manager 192.168.20.3. /var/lib/aim/webgui auth/runtime state remains preserved across normal updates. AIM rc18 is never modified.

0.1.4 - 2026-09-17

Compatibility

Component Contract
AIM base 3.0.0rc18 only; unchanged and externally managed
Python 3.11+
HTTP API v1 unchanged
Add-on database Schema 1 unchanged
WebGUI config Release-managed; overwritten on install/update/rollback

Added / changed

  • Added a global Light/Dark display selector in the WebGUI top bar. The preference is browser-local presentation state only; no authentication/session material is stored with it.
  • Added a dark palette built from charcoal/slate surfaces instead of pure black, while retaining the existing AIM orange accent and accessible focus/selection states.
  • Centralized additional surface, table, note, badge and control colors into theme tokens so pages switch consistently between light and dark modes.
  • Added a select-all checkbox to the explicit-host table header with checked/indeterminate synchronization.
  • Added inventory-group bulk selection controls with host counts. Overlapping groups and manual host selections update group controls to checked/indeterminate states.
  • Group selection remains presentation-only: preflight continues to submit explicit inventory hostnames and never Ansible patterns or group expressions. The existing server-side explicit-target validation and 500-target limit are unchanged.

Upgrade / rollback

Whole-release replacement semantics are unchanged. The release-managed config still uses https://aim.desq-gaming.de, backend listener 0.0.0.0:8080, and trusted Nginx Proxy Manager 192.168.20.3. /var/lib/aim/webgui auth/runtime state remains preserved across normal updates. AIM rc18 is never modified.

0.1.3 - 2026-09-17

Compatibility

Component Contract
AIM base 3.0.0rc18 only; unchanged and externally managed
Python 3.11+
HTTP API v1 unchanged
Add-on database Schema 1 unchanged; users/passwords/auth state preserved
WebGUI config Release-managed; overwritten on install/update/rollback

Fixed / changed

  • Hardened browser CSRF-origin handling for reverse-proxy deployments. Origin remains authoritative when present and must match public_url; a same-origin Referer is accepted only when Origin is absent.
  • If both Origin and Referer are absent, unsafe browser requests are accepted only with Sec-Fetch-Site: same-origin, and the existing per-session CSRF token remains mandatory. Origin: null, cross-site Fetch Metadata, and mismatching Origin/Referer values remain rejected.
  • Changed the response Referrer-Policy from no-referrer to same-origin so browsers can provide the safe Referer fallback without leaking referrers cross-origin.
  • Improved origin-rejection messages to distinguish mismatched Origin, mismatched Referer, cross-site Fetch Metadata, and missing same-origin browser metadata.
  • Corrected the managed Nginx Proxy Manager trust address for the validated deployment profile to 192.168.20.3; backend remains 192.168.20.46:8080 and public origin remains https://aim.desq-gaming.de.

Upgrade / rollback

Whole-release replacement semantics from 0.1.2 are unchanged. The release-managed WebGUI configuration is overwritten with the 0.1.3 profile during update; /var/lib/aim/webgui authentication/runtime state is preserved. Rollback restores the prior release source/config while leaving the auth database intact unless explicitly requested. AIM rc18 is never modified.

0.1.2 - 2026-09-17

Compatibility

Component Contract
AIM base 3.0.0rc18 only; unchanged and externally managed
Python 3.11+
HTTP API v1 unchanged
Add-on database Schema 1 unchanged; users/passwords/auth state preserved
WebGUI config Release-managed; overwritten on install/update/rollback

Changed

  • Managed deployments now treat /etc/ansible/scripts/config/webgui.toml as part of the versioned WebGUI release rather than operator state. Every install/update writes the release copy, and rollback restores the copy captured with the rolled-back release.
  • Update sequencing now snapshots and validates the active release before replacing configuration, then validates the candidate with the candidate runtime. An older WebGUI runtime is never asked to parse a newer configuration schema.
  • Authentication database checkpoints now use Python SQLite's native online backup API directly, so backup and update no longer depend on the previous WebGUI runtime or its ability to parse any configuration schema.
  • Private runtime state under /var/lib/aim/webgui, including the SQLite authentication database and consumed bootstrap state, remains preserved across normal updates.
  • The managed release profile binds 0.0.0.0:8080, uses https://aim.desq-gaming.de, and trusts forwarded headers only from Nginx Proxy Manager at 192.168.10.11.

Upgrade semantics

deploy/deploy.py update performs whole-release replacement without Git. Source, venv, systemd unit and WebGUI configuration advance together. The SQLite authentication database is retained. On deployment failure, the previous source, venv, unit and configuration are restored automatically; AIM rc18 is never modified.

0.1.1 - 2026-09-17

Compatibility

Component Contract in this release
AIM baseline Original AIM-Ansible-3.0.0rc18.zip only; unchanged
Upgrade from WebGUI 0.1.0 supported by managed replacement update
Add-on database Schema 1 unchanged; users/passwords/sessions preserved
HTTP interface API v1 unchanged
Reverse proxy Explicit trusted forwarded-header support added

Fixed / changed

  • Added explicit non-loopback listener support for reverse-proxy deployments. The safe default remains 127.0.0.1.
  • Added proxy_headers and forwarded_allow_ips; Uvicorn now trusts forwarded headers only when configured.
  • Added sectioned TOML configuration while retaining full read compatibility with the 0.1.0 flat configuration.
  • Non-loopback listeners require an HTTPS public_url, proxy-header processing, and at least one explicitly trusted proxy address/network.
  • Managed readiness checks now work with wildcard listeners (0.0.0.0 / ::) by probing loopback while sending the configured public Host header.
  • Documented Nginx Proxy Manager deployment validated with aim.desq-gaming.de, backend 192.168.20.46:8080; site-specific values are examples, not package defaults.
  • Clarified that the managed systemd unit supplies AIM rc18's required group as a supplementary process group; manual tests launched with sudo -u may not inherit that group.

Upgrade / rollback

Use deploy/deploy.py update from a freshly unpacked 0.1.1 release. The active add-on source and isolated venv are replaced as a unit; operator configuration and /var/lib/aim/webgui/webgui.sqlite3 are retained. 0.1.0 flat TOML remains valid after upgrade. Rollback to the managed 0.1.0 snapshot remains supported without restoring the auth database unless explicitly requested. AIM rc18 is never modified.

0.1.0 - 2026-09-17

Compatibility

Component Contract in this release
AIM baseline Original AIM-Ansible-3.0.0rc18.zip only
AIM product version 3.0.0rc18, unchanged
AIM rc19 / later Not claimed; startup refuses unapproved versions
Python Requires 3.11+; executable tests run on CPython 3.13.5
Managed deployment Linux with systemd; separate unprivileged service account
Add-on database Schema 1, SQLite rollback-journal mode
HTTP interface /api/v1, cookie authentication and CSRF for unsafe methods
Frontend Jinja2, HTMX 2.0.10, Bootstrap 5.3.8; no EJS/Node
Core change requirement None; no service/API facade added to AIM

Added

Independent aim-webgui Python distribution and aim-web executable. FastAPI / Uvicorn server, Jinja2 pages/partials, local static asset preparation and centralized orange theme with explicit Bootstrap component overrides.

Read-only rc18 adapter for Config, group membership, CustomerManager, InventoryDocument/InventoryEditor, catalog parsing, InputSpec.parse/validate and PlaybookManager.validate_overrides. Target/platform filtering mirrors the rc18 target screen without importing its terminal UI. Inputs inherit role defaults unless explicitly supplied; the existing cleanup-off safety default is retained. Customer path traversal and escaping symlinks are rejected.

SQLite bootstrap admin with random password written to private .credentials, mandatory first password change, Argon2id hashes, server-side hashed session IDs, CSRF/origin checks, idle/absolute expiry, request limits, login throttling, local account administration, last-admin protection and terminal recovery.

Add-on-only, non-git staged replacement deployment. It prepares dependencies before stopping WebGUI, stores SQLite backups using its backup API, retains operator config/auth state, replaces old source rather than merging, and switches between permanent isolated venv paths. Readiness failures attempt rollback; interrupted operations leave a root-owned recovery journal. Code-only rollback preserves accounts by default. Database restoration requires an explicit destructive flag, and session tokens are always revoked on rollback.

Deliberately not included

Browser-triggered playbook execution, infrastructure writes, Vault/SSH/WinRM credential collection, job workers, customer-scoped roles, MFA, SSO, API bearer tokens, generic plugin discovery, or any change to the base AIM installation. The POST /api/v1/runs compatibility boundary explicitly returns 501 after normal authentication/CSRF checks. It never starts a job.

Upgrade and rollback compatibility

This is the first independent Python add-on release. It is NOT an upgrade path for the historical Node/EJS rc19 WebGUI or its API daemon. Leave those separate artifacts unused when deploying against rc18.

Future updates must use a new add-on version and an explicitly recorded AIM compatibility contract. The installer refuses same-version replacement and downgrades through update. Use rollback for an installed prior snapshot. Migrations only advance schema versions; startup refuses a newer database. Do not restore an old database merely to roll back compatible code: that would also revert password, user and audit changes after the snapshot.

Verification limits

See docs/VERIFICATION.md for actual results. No managed-host Ansible operations were run. Linux/systemd activation and an online dependency installation were not exercised against the operator's controller. The build container could not download browser assets or dependency wheels; deployment has a required pinned, integrity-checked online/offline preparation step. No claim of a penetration test or a current complete dependency vulnerability audit is made.

1.1.0rc7

  • Preserve canonical AIM SSH private keys as service-owned 0600; WebGUI uses a restricted service-user export bridge and job-private 0600 copies only.
  • Add deletion of terminal job history while retaining append-only audit deletion records. Saved-plan deletion remains supported.
  • Re-run browser-local timestamp formatting after HTMX settle and browser page-cache restores.
  • Document the aim-runtime shared-read model: inventories/Vaults root:aim-runtime, private keys service-owned 0600.