Files
Ansible/scripts/addons/webgui/docs/CORE-3.3.0RC8-REVIEW.md
T
2026-09-22 19:23:17 +02:00

51 lines
2.4 KiB
Markdown

# Core 3.3.0rc8 integration review
This is a source/package compatibility review of the user-supplied AIM Core 3.3.0rc8
archive against AIM WebGUI 2.1.0rc9. Core remains separately deployed and unmodified.
## Public contract
Core remains service/wire/event API 1.0 with the existing detail-progress,
inventory-hierarchy, target-outcome and `aim_operation_result_v1` contracts. The nine
shipped report schemas remain catalog-driven. WebGUI therefore does not add a private
adapter or parse playbook output.
The release changes the required native Windows collection baseline. Live Core
capabilities now advertise:
```text
ansible.windows >=3.8.0,<4.0.0
```
WebGUI 2.1.0rc9 requires that capability declaration. The actual collection remains
Core/operator managed and must be visible to the execution identity in the canonical
Ansible collection path. Core readiness remains authoritative for the installed runtime.
## Report deltas
`patch_summary_v1` is additive: rc8 adds optional `reboot_reasons_before`, a bounded
array of `{source, description}` observations from `ansible.windows.win_reboot_info`.
Existing required fields and the established patch continuation/reboot semantics remain.
Historical reports continue to validate against their recorded result contracts.
`filesystem_usage_v1` remains schema-compatible, but Windows semantics now describe
attached local storage volumes through `community.windows.win_disk_facts`; mapped/network
drives are intentionally excluded. WebGUI updates its explanatory note accordingly.
Core's Checkmk script placement and Windows ACL hardening are runbook behavior, not a new
add-on API. WebGUI does not reconstruct those paths, permissions or deployment rules from
private source; it renders final structured reports supplied by Core.
## Patch behavior retained
The rc4 patch-wave model remains: one native `win_updates` wave per selected categories,
AIM-owned reviewed reboot message/delay, explicit opt-in for post-reboot continuation,
no automatic replay, and `remaining_updates_known` governing whether a final pending list
is authoritative. `install_not_allowed` alone is not treated as proof of a reboot need.
## Qualification boundary
This review does not certify native Windows Update, Checkmk ACL changes, collection
installation, WinRM/SSH, or the production systemd sandbox. Controller acceptance must
use Core rc8's current SANITY/VALIDATION guidance under the actual executor identity.