Files
2026-09-22 19:23:17 +02:00

2.4 KiB

Core 3.3.0rc8 integration review

This is a source/package compatibility review of the user-supplied AIM Core 3.3.0rc8 archive against AIM WebGUI 2.1.0rc9. Core remains separately deployed and unmodified.

Public contract

Core remains service/wire/event API 1.0 with the existing detail-progress, inventory-hierarchy, target-outcome and aim_operation_result_v1 contracts. The nine shipped report schemas remain catalog-driven. WebGUI therefore does not add a private adapter or parse playbook output.

The release changes the required native Windows collection baseline. Live Core capabilities now advertise:

ansible.windows >=3.8.0,<4.0.0

WebGUI 2.1.0rc9 requires that capability declaration. The actual collection remains Core/operator managed and must be visible to the execution identity in the canonical Ansible collection path. Core readiness remains authoritative for the installed runtime.

Report deltas

patch_summary_v1 is additive: rc8 adds optional reboot_reasons_before, a bounded array of {source, description} observations from ansible.windows.win_reboot_info. Existing required fields and the established patch continuation/reboot semantics remain. Historical reports continue to validate against their recorded result contracts.

filesystem_usage_v1 remains schema-compatible, but Windows semantics now describe attached local storage volumes through community.windows.win_disk_facts; mapped/network drives are intentionally excluded. WebGUI updates its explanatory note accordingly.

Core's Checkmk script placement and Windows ACL hardening are runbook behavior, not a new add-on API. WebGUI does not reconstruct those paths, permissions or deployment rules from private source; it renders final structured reports supplied by Core.

Patch behavior retained

The rc4 patch-wave model remains: one native win_updates wave per selected categories, AIM-owned reviewed reboot message/delay, explicit opt-in for post-reboot continuation, no automatic replay, and remaining_updates_known governing whether a final pending list is authoritative. install_not_allowed alone is not treated as proof of a reboot need.

Qualification boundary

This review does not certify native Windows Update, Checkmk ACL changes, collection installation, WinRM/SSH, or the production systemd sandbox. Controller acceptance must use Core rc8's current SANITY/VALIDATION guidance under the actual executor identity.