Skip to content

Latest commit

 

History

History
1006 lines (947 loc) · 73.1 KB

File metadata and controls

1006 lines (947 loc) · 73.1 KB

Compatibility Contract

Server v1.6.516 published

Package published Web Console 1.6.178, signed source 60a494e943150ecd300d1aa653ee397f590b575b, archive SHA256 7d4476f3ae1ecd455d0de25008b62327d8c2fa02fafe2b5252ce79fb3309d981. Formal CI 37273270200 passed 848 tests; two archives and anonymous immutable download agree. Only exactly inactive environments skip scoped network/policy reads; global project/member reads and capabilities remain authoritative. Other states, authorization errors, generation/mutex, OIDC and MFA are unchanged. The new status hint exists in all 13 packaged locales. The numeric lightweight tag binds the signed Web source commit; it is not a signed tag.

Server source is e024e054be7371c60d719d0590ca3f5b86bdb6ee; its immutable image is ghcr.io/pasturestack/server:v1.6.516@sha256:3741b7d87273387f36b49e44d407c240658db0ab7fc7fb8d518ae08f55ac733c. Publisher 37275775509 and independent public artifact readback passed. Tag and immutable manifest bytes, config/version/revision identity, checksummed release assets and SBOM identity agree. Publication and isolated QA acceptance are separate evidence. The actual isolated 516 deployment separately passed: first start and restart each reached HTTP 200/pong after ten bounded probe attempts. Runtime settings and five core-table counts have zero differences; the existing AppArmor, three named volumes and unless-stopped policy remain. Docker health is null, not healthy; no company-site deployment is claimed.

Image catalog defaults pin normally merged commit 7670ffd81d5f0b5570197fb03c7e55b46da45bf3 (IPsec Overlay 12 / v0.14.38). Explicit user catalog settings, existing template revisions and backend/plugin ownership are preserved. Template visibility is not managed upgrade acceptance. Engine 333, Catalog Service 0.20.12, four build stages and one final runtime layer remain unchanged. VEX/vendor-pending changes only their release identity; review deadline and findings are not reset. In one inactive environment, native detail/reload, edit/remove cancellation, DELETE 200 and absence from the list after reload were observed. The parent cleanup timeout remains HOLD. A separate read-only database observation confirmed the environment and four networks were purged, with no remaining members or dependent resources. Fresh API and complete foreign-data preservation verification remain incomplete; this is not full native lifecycle PASS. The full matrix is INCOMPLETE and historical HOLDs remain. See the release note for exact artifact identities.

Server v1.6.515 published

Package published Web Console 1.6.177 from signed source b9b841e65afe1d89a5b03ac767e9168bccd3c3ea, archive SHA256 4e34eb2b3165f078134cddcf1721239b3da7baf11dd683991b2d6aa5bae944e0. Its numeric lightweight tag binds this signed source commit; the tag itself is not signed. Normal PR #175 merge 5d150806be20226657e5caa8a0150d068006c772 has the same reviewed tree and a verified signature. Formal CI 37255121243 passed 841 tests, including 17 new regressions; anonymous archive readback matched both CI builds. Ended logs/terminal entries cannot reconnect or accept late responses and old callbacks; explicit new entries and live reconnects remain supported. Permission checks, API contracts, workspace persistence, generation/mutex and MFA are unchanged. Engine 333, Catalog Service 0.20.12, all other components/plugins, the pinned 460 base, four build stages and final single-runtime-layer publication flow are unchanged. Server 515 source is f0267ff3a347ea526088db1749b1d3c8dfd9bd37; its immutable image is ghcr.io/pasturestack/server:v1.6.515@sha256:fcc79f616927040ef2b3a5c58662fa948823220dbc57ffe275dee2ad88764d47. Publisher 37256753740 and independent public artifact/runtime/security readback passed. Separate isolated QA 515 / Web 177 deployment and readback passed: initial-start and restart polling reached HTTP 200/pong after 10 and 11 attempts, respectively. Runtime configuration, environment overrides, three named persistent volumes and five core-table counts were preserved, with docker-default, unless-stopped, database backup and 514 rollback retained. There is no Docker Healthcheck: running/pong is not Docker healthy. Native lifecycle acceptance remains pending; deployment readback is not native UI or full-matrix PASS. A separate fresh Project v2 native run remains HOLD after a successful deactivate response and a UI wait timeout. Native removal and database cleanup are incomplete. Quick Start follows published 515; retain 514, configuration, named volumes and rollback backups. The complete matrix remains INCOMPLETE; historical HOLDs and 514 evidence are unchanged.

Server v1.6.514 published

Package Catalog Service 0.20.12 from verified main CI 37177694304, source d708579092eae0fd03b2750ac594ff0396cf563b; 39 integration cases passed twice and archives are reproducible. Official publication run 37178033799 succeeded; anonymous public readback verified two asset bytes, both binaries, source LICENSE and immutable coordinates. Publication receipt SHA256 is 552ba8ab75e5379e462a44b03dc94d21b32e75476bd768db3d11cfee25d666de. Exact component hashes are recorded in the release notes. Skip root .git metadata, reject invalid revision folders before allocating a template, and rebuild an empty/unnamed cached index within the existing catalog transaction. The cache check is scoped by catalog name and environment; another catalog cannot satisfy it. Startup refresh can rebuild an affected catalog without a source commit change. Database and API template IDs may remap; catalog origin, template keys, versions, content and labels must be preserved and checked independently of those IDs. Back up persistent data before upgrade and keep the old image and backup for rollback. No SQL repair, live binary override, role change, authentication change or firewall change. Web Console 1.6.176 repairs 21 native-select mut bindings through the existing invokable function contract, including project member-role edits. Permission checks, identity metadata and Web175 image-error handling remain unchanged. Component and native DOM/model/save verification are required; hiding the timeout alone is not acceptance. Engine333, four build stages, the final one-layer image and all unrelated pins remain. Server514 source is 076aa43c6b978dfe65cd0fb3a05efc97ec5d02dd; its immutable image is ghcr.io/pasturestack/server:v1.6.514@sha256:45712644bc11325df927d10bdbab47421168cc3c512eb5f2a51d85020671a71f. Publisher37179046649 and independent public artifact/runtime/security readback are recorded in the release notes, with receipt SHA256 59340dd9c4b365df3e08633d71be66b56640e7d9cc673a79670c78c7739b2d70. Quick Start follows this exact published514 identity. QA125/8080 now runs514/Web176; first-start11/restart9 probes returned HTTP200/pong, runtime settings, volumes and five core-table counts were preserved, with512 retained for rollback. Two real read-only catalog migration captures agreed:12 blank Git stubs and2 README-only entries were removed while valid origin/template/version/content/label semantics were preserved. Native UI and the full resource/role/locale/layout matrix remain INCOMPLETE, not PASS. The image has no Docker Healthcheck; running/pong must not be reported as Docker healthy. Traditional Chinese/English native VM/container forms passed eight cases and two INIT toggle/restore checks without creating resources or starting a VM; other locales, GPU hardware and VM runtime remain unverified. Historical513/512 publication and rollback records are unchanged; no zero-CVE claim is made.

Server v1.6.513 published

Server v1.6.513 packages 正式 Web Console 1.6.175: 映像補正/語系切換同步表單自有 required 錯誤,保留非映像錯誤及後續 backend save 錯誤。 正式 source bb905d092700c262497b88f5773e7714fc1f4be4、 tree b2b38347e5fa24bd945706fd2aaab0136ea4ef45、 CI37163340764 821/821、fail/skip/todo 0;兩 production archive 一致,簽章數字 tag 及匿名讀回已核對。 公開 archive 2982158 bytes,SHA256 9833467b2be47d4fa01f09954fcd35beb292c59d382d5c1aecd76d17c6a387a2。 Publication receipt SHA256 為 a177e4d2a20bff51b18c8f233e87672a3f343ff5a1df12edcc57771ae41ba125。 Server513 source 為 eefc84d670188f8d81978d6ce600d1c0400fe720,正式不可變映像為 ghcr.io/pasturestack/server:v1.6.513@sha256:d6df82fe1ec29d720af47fe62ec83dcf0f96ce1b0dcfc00059363f8621dc61ab。 Publisher37164995463 與獨立公開讀回通過:23 assets/22 SHA-256、SBOM來源/digest/版本及單runtime layer, 隔離首次啟動13次/重啟7次後HTTP200/pong、34 MFA/API、TLS1.2/1.3、 不信任TLS憑證拒絕與private API no-store。這些是正式成品驗證,不是QA部署/UI PASS。 Engine333、460 base、四 build stages/單 runtime layer、其他 component/package pins、 原生 save/payload/角色/OIDC-MFA、ENV/volumes/AppArmor 契約不變。 VEX51 exact-set 與 vendor-pending severity/available-fix/untracked/secret 門檻不放寬, 513 actual scan raw52/VEX51,vendor pending為8 Medium package findings/4 CVEs; untracked/Critical/High/available-fix/secret均0,2026-10-20 review deadline保留,不宣稱零CVE。 No migration or runtime patch is required. Quick Start指向已發布513 exact digest;QA目前仍512,513尚未部署, 舊512/511發行、rollback與 scoped/HOLD 證據不升格,full matrix INCOMPLETE。 原生UI/角色/語系/版面及VM開機仍待本版實機驗收。 詳見已發布發行說明。

Server v1.6.512 published

Server v1.6.512 packages Web Console 1.6.174 的VM映像表單防呆與缺映像訊息。 只移除全新VM的一般容器預填/quick picks,保留自訂/initialValue/last-used、 一般容器預設及原生required/willSave語意;不改Engine、schema、角色或VM runtime。 Web174正式signed source為 d24b7f4e164f058e3ef9057347caa2080e2b5407、 tree為 c408e8b018d99db2ca228203880f4e72663ab1b7。 正式CI37152802665 通過817/817,fail/skip/todo為0; 數字tag 1.6.174 已簽章發布,匿名公開archive原bytes與CI一致,2982022 bytes, archive SHA256為 6408775898f412e4b27092eeddd9cdc2028ad7b27835f489139c2d0cf62c6776。 獨立publication receipt SHA256為 aa79ea915bb8d6de4542b1095c35e39479af4d6c24e7b7d9cd2e28ffbf08f603; 此為Web component讀回,不代表完整功能矩陣 PASS。 Server512 source 為 c533ac7753d222abb515848effc27d007bd700b6,不可變映像為 ghcr.io/pasturestack/server:v1.6.512@sha256:805078de83c0320c751dff90304bd841b8e64bec720079198258d22fa41d0145。 正式 publisher37153784888 及獨立公開讀回通過:23 assets/22 SHA-256、單 runtime layer、 隔離首次啟動12次/重啟8次後 HTTP200/pong、34 MFA/API、TLS1.2/1.3、 private no-store 與不受信任 TLS 憑證拒絕均核對。這些不代表全部實機操作或權限已驗收。 實際 merged-rootfs scan 為 raw52/VEX51、8 Medium package findings/4 vendor-pending CVE; Critical/High、available-fix、untracked 與 secrets 為0,不宣稱零 CVE。 Engine333、460 digest-pinned base、四build stages/最終單runtime layer、其他component pins、 runtime ENV/volumes/AppArmor、VEX51 exact-set、vendor-pending門檻與2026-10-20期限不變。 No migration or runtime patch is required. Quick Start 對齊512已核實公開digest,511仍為歷史rollback參考; 歷史HOLD及full matrix INCOMPLETE不升格。 詳見已發布發行說明。

Server v1.6.511 published

Server v1.6.511 packages Web Console 1.6.173 的原生Project Template卡片名稱修正:使用模型既有 name,不依賴未實作的 localizedName。 Web正式source為 c8b8bb2659fdad3539cf6a72866c94a77ec516b6, tree為 f590310e157edea79de81fcf333e8b39dbc5677e。 CI 37115288389 通過812/812,fail/skip/todo為0,兩次production成品一致; CI archive SHA256為 a566684e6e0831630a15cb7212989c0e9fe707ed07965156c2b664b9cdb5ba27。 Web數字tag 1.6.173 已簽章發布,匿名公開byte讀回與CI SHA256一致; Server source為 e995f8f35bc6335effaceb6c973f7915c68df2ab,不可變映像為 ghcr.io/pasturestack/server:v1.6.511@sha256:bce474ce4403398044a7c24aafe6c8314bac38b44731540c5ffaa2dfc40699cd。 正式publisher37116124788與公開讀回通過:23 assets/22 SHA-256、單runtime layer, 隔離首次啟動13次/重啟9次後HTTP200/pong、34 MFA/API、TLS1.2/1.3、 private no-store與不受信任TLS憑證拒絕均核對。 Engine維持正式 v0.183.333,460 digest-pinned base、單runtime layer驗證、 角色/schema/登入/production環境/持久volumes契約與安全門檻保留。 No migration or runtime patch is required. Server511實際scan保留raw52 findings、VEX51 statements、8 Medium package findings/ 4 vendor-pending CVE,review 2026-10-20;Critical/High、available-fix、 untracked與secrets均為0,不宣稱零CVE。Quick start採本版已核實公開digest。 QA125/8080升級與獨立只讀核對通過:首次啟動11次/重啟10次探測後HTTP200/pong, 既有binds、environment、unless-stopped、docker-default與五項DB計數不變。 映像未定義Healthcheck,不宣稱Docker healthy。 當版既有Template117原生只讀proof已通過:3 Full17/14 guards、0資源寫入, source-bound proof核對同一ID及空stacks/services;這不是native create finalizer。 當版Process原生list/link/detail及同一ID direct GET只讀驗收通過:兩API roots×六角色 共12/12格、0資源寫入;僅涵蓋一個實際ID,不代表所有ID或write操作。 當版全新Project key 1c6998 已獨立核對為 DERIVED_SCOPED_KEY511_VERIFIED_NOT_ORIGINAL_PASS:同一次實機child有4筆原生寫入、 13 guards、6筆停用/刪除前cookie-free issued Basic GET、4 barriers及18項首次交付判斷。 原parent的QA receipt identity schema失配HOLD不重寫,只讀derived核對沒有重跑寫入; 詳見發行說明的證據與範圍。 Project與Host原生流程仍獨立pending,完整矩陣 INCOMPLETE;不以key scoped結果升格。 既有版本的scoped PASS與歷史HOLD不重寫或升格,公司站不部署。

Server v1.6.510 published

Server v1.6.510 packages Web Console 1.6.172 的 create-only first delivery,Engine保留正式 v0.183.333。canonical store 只保存正常資源身分; 首次201限定欄位由 request-local delivery 交給本次非 canonical modal clone。 Web172正式 source/archive 已固定並匿名讀回,808/808測試通過。 Server正式 source為 1a323f5f690ed89a4f03e7ead1ad2e51ddeb4fdf,映像為 ghcr.io/pasturestack/server:v1.6.510@sha256:82e4ee7fa51dae3fb6b1f339ee794d17b593f6feae2fd313ef5354ccaaf2d89f。 正式 publisher37110936143與公開讀回通過:23 assets/22 SHA-256、單 runtime layer、34 MFA/API、首次啟動/重啟、TLS、SBOM與成品scan均核對。 QA部署及新key create/edit/deactivate/delete尚待原生驗收,不宣稱生命周期PASS。 No migration or runtime patch is required. 460 digest-pinned base、單 runtime layer、role/schema、登入、production環境變數與 volumes不變。510成品scan保留raw52、VEX51與8 Medium/4CVE vendor-pending exact-set(review 2026-10-20);不宣稱零CVE。 509正式digest、6974/6977 scoped closures、6982 HOLD與active保留資源不重寫或升格; 公司站不部署,完整矩陣仍 INCOMPLETE。

Server v1.6.509 published

Server v1.6.509 已正式發布,封裝 Web Console 1.6.171 與 Engine v0.183.333。create-only 欄位僅限真正的 POST create response, 不包含 POST action;既有首次 API Key 金鑰交付、角色授權、所有 frozen schema、登入、防火牆與持久資料契約保持不變。

No migration or runtime patch is required. Engine CI273 suites/1164 tests、隔離啟動與正式元件六檔讀回已通過。 Server source 為 261bb23c980f5f896375923233e36f6554b99751,不可變映像為 ghcr.io/pasturestack/server:v1.6.509@sha256:d934c9d7bc7387626fedca5d403210fac70b7b4e35e334dcdb439f79f555ab87。 正式 publisher 37105881483 與公開成品讀回通過:23 assets/22 SHA-256、 public tag/digest/config、單 runtime layer、34 MFA/API、首次啟動/重啟與TLS均核對。 成品 raw52 findings/VEX51 statements、8 Medium package findings/4 CVE exact-set 保留; Critical/High 為0,安全門檻不放寬,不宣稱零CVE。 QA8080 的509部署與唯讀驗收通過:首次啟動13次、重啟9次重試後均為200 pong; 環境變數、執行設定與五表筆數不變,508回復容器與資料庫備份保留。 owner2513 的 Account6974 續接scoped PASS:本次PUT200/deactivate202/DELETE200, 3筆原生寫入/9個full16及14API守門,cleanup=true;508 POST201與HOLD保留。 Project6977 續接移除scoped PASS:本次僅DELETE200/4個守門,cleanup=true; 508已知POST201/PUT200/deactivate202不能拼成509新4writes或整案PASS。 全新Project key第二次僅POST201建立1c6982,3個守門與Store barrier通過, Web171首次交付timeout而HOLD;未執行issued Basic讀取/edit/deactivate/delete, active資源保留、不自動重試或清理,第一次0資源寫入HOLD不升格。 Web172修正尚未包含在509不可變成品,不宣稱原生首次交付已修復。 Host原生註冊/healthy/停用/移除仍pending;空template首次0writes/0guards HOLD, guest或fixture不能建立Host PASS。上述結果不代表Docker healthy、公司站部署 或完整權限/語系/版面矩陣通過。 508 scoped PASS 與歷史 HOLD 保持原版本及原狀態,不升格為509證據。

Server v1.6.508 published

Server v1.6.508 已正式發布,封裝 Web Console 1.6.171。 Server source為 69744f3ef0c00c14147fb83480306e07ccb667d9,不可變映像為 ghcr.io/pasturestack/server:v1.6.508@sha256:e24f9993593bb609a7a0e26dc12fbbb21ab402b73c60af28955b988b83b6ac04。 正式publisher 37095694250 與公開讀回通過:23 assets/22 SHA-256、 public tag/digest/config、單runtime layer、34 MFA/API、首次啟動/重啟與TLS均核對。 正式成品讀回不代表QA部署、Docker healthy或native Volume驗收。 Web signed source 固定為 fc37f5af9320e492bec7e7244cd62144908b720e;1.6.171 已正式發布。 公開 archive SHA256 為 49fac41ca93eb628d0877104f9512ef382ffd9dbc89e04c940196b3a9c57798b, CI 37094728912 通過802/802,含10項新回歸、100次barrier與22項audit self-tests;CodeQL通過。 API-store compatibility revision 5 的 canonical adoption 僅限新建 POST201、 精確 type/server-generated ID、同 Store/generation/base URL;action 清除 createIdentity。 無相符 cache、GET/PUT/action/非201/204/errors 維持原語意,沒有狀態/時間排序 heuristic。 Engine保持 v0.183.332,WAR SHA256為 31090699e214f8e357f7fe413ce307e722b9b53177003e5de0bbbca1bc7bc3f5; API/Auth/CRUD、pool/mount證明與部署/回復參數不變。 8個 MEDIUM package findings/4 CVE、51個 VEX statements 與安全 exact-set 不放寬。 Web建置audit仍為7 High/3 Moderate/0 Critical,精確上游待補風險複核至2026-10-10; 這不是零CVE或runtime整體不受影響的宣告。 QA8080已部署508,首次10次/重啟9次HTTP200/pong;runtime、environment及 五表counts差異0。三named volumes、AppArmor、restart policy與507回復點保留; health=null,不宣稱healthy。Registry member生命周期分項通過(5次原生寫入及 2次API憑證收尾),英文憑證必填驗證/取消零寫入通過。原生Volume同ID生命週期 已可追溯續接通過:POST201/DELETE200、readonly兩版DELETE405、no-access兩版 GET/DELETE403,繁中/英文可讀拒絕與取消、刪除、刷新終態皆核對。 16個生命週期守門區分12個既有證據與4個本次守門;no-access API既有4請求/9守門 與本次零API請求/5畫面及終態守門分開,不重送已完成請求,不追認歷史HOLD。 完整矩陣INCOMPLETE。 508發布時的Quick start曾對齊其完整不可變映像;507歷史來源、HOLD與scoped PASS不拼成新版本整體PASS。

Server v1.6.507 已正式發布,封裝 Web Console 1.6.170(source 09df1480c5f4b58c6a9a9060ff94d980792f7015)。 範圍僅 nullable Volume 關聯欄位的前端分類相容性;Engine v0.183.332/ 原 WAR、API/Auth、角色授權、pool/mount 證明、部署參數與安全門檻保留。 正式 CI archive SHA-256 為 900974b07bb20ba5b2e7c1dede7012a53c6e2c96cd094c67cb7019434c4f27c9; Web170 與 Server507 已正式公開;Server source 為 34287791861643ba93edd9923fa11dd504172f60,不可變映像為 ghcr.io/pasturestack/server:v1.6.507@sha256:c0ee312207e38f4e31b8503521c0e43cbf178110e91fac61c23056026603c91e。 publisher37083174895及23 assets/22 SHA-256、單runtime layer、34 MFA/API、TLS、 SBOM與安全門檻均讀回;QA/原生驗收另行記錄,不借用506證據。 完整矩陣仍 INCOMPLETE,506 已發布/部署實績及歷史 HOLD 保留。 QA507首次9次/restart8次HTTP200/pong,runtime/環境參數/五表counts差異0, 原named volumes、AppArmor、restart policy與506回復點保留;health=null。 首輪QA根分割區滿的HOLD不追認,新部署通過3GiB空間及本機精確image守門。 本版兩筆既有隔離Volume已通過原生Store/列表/刷新、取消零寫入、 唯讀兩根DELETE405、owner原生DELETE200及終態消失;新建仍在追查。 主機新增入口三低權限角色的繁中、英文拒絕分項通過,無資源或註冊Token寫入。 這些不是全矩陣、主機註冊或完整多語系版面PASS。精確清除10個停止的舊Server 容器後,保留507與最近506回滾點,主機UI重新登入/刷新無舊重複項目;VM與資料卷未刪除。

Server v1.6.506 已正式封裝 Web Console 1.6.169,將本機 Volume 的 externalId 視為識別碼而非配置綁定。完整 pool/mount 關聯、主機/image/ instance null binding、環境 schema 與 API 授權保護均不變。Engine 保持 v0.183.332,不涉及資料遷移、認證或防火牆變更。正式 source 為 3cfb920a428fc2af6af6a07a832d6882663f544d,不可變映像為 ghcr.io/pasturestack/server:v1.6.506@sha256:f6860a1d0e96587b05afbf72d52c063921ff8473a976552c6d0a01d223a7a188。 publisher37079727511已通過;Web169正式CI791/791。QA8080部署完成,首次11次/ restart9次HTTP200/pong,runtime/environment/五表counts差異0,505回復點保留; health=null,不稱healthy。原生生命週期及完整角色矩陣另案驗收,不以正式成品或來源測試代替。

The packaging migration preserves established database schemas, API paths and fields, event names, environment-variable aliases, service names used by stored data, container labels, filesystem upgrade paths, and bootstrap contracts.

已發布的 Server v1.6.505 封裝 Engine v0.183.332 與既有 Web Console 1.6.168。 Server source 為 400f7dc8d533a5f13a555398c595b9ae42e0c454,不可變映像為 ghcr.io/pasturestack/server:v1.6.505@sha256:b3dd402cfd773b4d37ecf06f716187833e56cc6f211b7ab920dccf8dcb7366c5。 正式 publisher 37072151759 及23個 assets/22項 SHA-256、公開 image/component identity 讀回通過。隔離映像首次啟動/一次重啟均 HTTP 200/pong,分別在第10/6次 探測取得;34項 MFA/API、TLS、單 runtime layer 與成品 SBOM/安全門檻通過。 這些是正式成品證據,不是 QA8080 部署、Docker healthy 或原生 Volume PASS。 本次 API/schema 有窄幅相容性補齊:v1 與 v2-beta Volume 恢復 server-owned 唯讀 isNative。客戶端不能寫入該欄位;其他欄位、methods、完整 actions、 角色限制及環境隔離不變,無資料庫 migration。8080 的實際 504 schema 讀回 證明兩個 API 根都缺漏分類,補充更正先前只歸因於 v1 驗收工具的診斷; 原始零資源寫入 HOLD 不改成 PASS。Engine 正式 source 為 7a625eee58fb2bdba83d2f008bdf7dd3c0ae4295,WAR SHA-256 為 31090699e214f8e357f7fe413ce307e722b9b53177003e5de0bbbca1bc7bc3f5; 正式 CI 通過270 suites/1,150 tests,failure/error/skip皆為0,含6個新增回歸。 QA8080 已部署本版並完成一次重啟;HTTP 200/pong、runtime/環境參數與 五項資料筆數保存,504 回復點保留。Docker health 為 null,不稱為 healthy。 原生建立/列表/取消/刷新/刪除仍在驗收,完整資源/角色矩陣尚未完成。 未配置 local Volume 的 inactive 是合法狀態,原生清單不要求 active; 移除須核對當次 action 與空關聯,不要求額外 activate/deactivate。 部署環境、掛載、restart、AppArmor、HTTPS origin、OIDC/MFA 與 firewall 契約保持。 Vendor-pending 8個 Medium package findings/4個 CVE、2026-10-20複核期限、 VEX 51 statements 與安全門檻不放寬;正式發行不代表零 CVE或完整矩陣 PASS。

已發布的 Server v1.6.504 固定封裝 Web Console 1.6.168;Web tested source/ archive、SSH-signed numeric tag 與 Server 正式成品均已讀回。Server source 為 e33ef8565ebe40dd188170baa46da8092fc131b9,不可變映像為 ghcr.io/pasturestack/server:v1.6.504@sha256:11393d4a5189601464d2a2e1ffc823160bedd6bda6c1fbae12457337f7cb9e2f。 正式 publisher 37063207602 與 23 個公開 assets/22 項 SHA-256 驗證通過。 測試環境首次啟動/重啟均 HTTP 200/pong,runtime、環境參數、既有掛載及五表 counts 無差異;503 回復容器與資料庫備份保留,health=null,不稱 healthy。 安裝指引已對齊本版;正式公司站未部署或修改。

Volume 的新增 CTA、直接新增路由及既有 update 路由都要求目前 project 與 schemaProjectId 相符;建立仍須實際 schema 的 POST 能力,update 原有 PUT 判斷保留。獨立未配置 local 區段及原生 Add 不依賴任何 pool 存在;列表以 實際 GET storagePools 完整 collection 與包含 inactive mounts 的完整 scoped mount cache 判斷,避免將停止工作負載仍持有的 Volume 當成未使用。 原始403、network/sync error 保留並交既有 route/growl 診斷,不轉成空關聯。 只有目前 project/schema 相符且當次資源 advertised deactivate 才原生停用, active→detached 後沿用既有 advertised remove/原生刪除,不另造清理 API。

API/schema、後端授權、資料/state 語意、Engine v0.183.331/exact WAR、 session ownership、OIDC/MFA、部署參數、相依套件、安全門檻及多階段/單 runtime layer 契約不變;無需 migration 或 runtime patch。Web168正式CI 37061716638 通過788/788個 QUnit案例、fail/skip/todo皆為0,包含16個 scoped Volume案例; 兩次production archive一致。上述 component 與成品/部署證據不代替原生 建立/列表/清理或完整矩陣 PASS。首次原生驗收在任何資源寫入前,因工具 誤要求 v1 schema 的 isNative 欄位中止;原 HOLD 保留,原生驗收仍待完成。Vendor-pending 8 個 Medium package findings/4 個 CVE、reviewAfter、VEX statements 與 policy 保留;正式504僅同步必要的 release-coordinate metadata,不放寬任何門檻。 詳見發行說明。

Published Server v1.6.503 packages immutable Web Console 1.6.167 for schema-only ID lookup normalization. It does not change API schemas, server authorization, ordinary resource IDs, project-store isolation, Engine v0.183.331, authentication/session ownership, MFA or runtime/firewall settings. Missing schemas do not grant capabilities. No migration or runtime patch is required. Web source dff35fc4bce340e21cac7204146a7bcb20a7b60b and archive SHA-256 e8e714fc06282de75a3570aac1d4d4d04a3c9478d982d0d5aaeae14efa8ebbaf match the immutable component publication. Its validation passed 772/772 tests with zero failures, skips or todo, including four actual Store/schema cases, and produced byte-identical production archives. Official publisher 37015013747 passed isolated startup/restart, 34 MFA/API checks, TLS, exact-rootfs single-layer comparison and final-image SBOM/security gates. Anonymous registry and all 23 release assets match Server source df061d5c93d0e4fdbc0e06664493ac5328a6f596; the public image is ghcr.io/pasturestack/server:v1.6.503@sha256:4a8997768c5c16a9aefdc682f906aab34417e204d622d03116e62b2fcfe0af79. Eight Medium package findings covering four CVEs remain vendor-pending until review on 2026-10-20; publication is not a zero-vulnerability result. QA deployment passed first start and one restart with HTTP 200/pong after nine attempts each. Runtime settings, environment overrides, named mounts and five-table count baselines were preserved; the prior immutable Server502 rollback and database backup were retained. Docker health is null, not healthy. Packaged exact-fixture QA confirmed GET-only registry/credential models for the readonly role and denied all 24 normal-CSRF v1/v2-beta writes for readonly/no-access roles, with the existing readable permission errors. That bounded result does not establish all API authorization, thirteen-locale or lifecycle acceptance. Existing 502 HOLD results are not promoted and the complete matrix remains INCOMPLETE. See the release notes.

Published Server v1.6.502 packages Web Console 1.6.166 for the shared inactive-state display label in thirteen supported catalogs. Only display translations and component/release pins change; Engine v0.183.331, its exact WAR, API/schema, authorization, session ownership, OIDC/MFA, icon/color and state semantics, deployment overrides and firewall contracts are unchanged. No migration or runtime patch is required. Official publisher 37003831065 passed startup/restart, 34 MFA/API checks, TLS, exact-rootfs single-layer and final-image SBOM/security checks. Anonymous registry and 23 release assets were verified against the immutable publication. The public image is ghcr.io/pasturestack/server:v1.6.502@sha256:ee6d0141574280473cb27a638814ae924b3d5bfe344f1ee0e1741aae0f3efddb. Eight Medium package findings covering four CVEs remain vendor-pending. Component validation passed 768/768 tests, including eight state/date rendering cases; it does not establish all packaged UI, resource/role or layout cases. The QA upgrade and one restart returned HTTP 200/pong with unchanged runtime configuration, named mounts and account/credential/setting/membership/host counts; the prior immutable 501 container and database backup were retained. This is deployment preservation evidence, not native-browser or role-matrix acceptance. The full permission/resource/locale matrix remains INCOMPLETE. See the release notes.

Published Server v1.6.501 packages Web Console 1.6.165 to keep complete container names readable on Host cards without shrinking IP/action areas. The shared subpod layout alone changes; real names/IDs, API permissions, authentication/session ownership, Engine v0.183.331/exact WAR, database schema, Compose overrides, named volumes, AppArmor, restart and nftables contracts remain unchanged. No migration or runtime patch is required. Web source/archive are pinned in the build and verified by actual 767/767 CI cases with identical production archives. Publisher 36980705366 passed, including single-layer comparison, startup/restart, 34 MFA/API cases, TLS and exact final-image SBOM/security checks. Public digest is ghcr.io/pasturestack/server:v1.6.501@sha256:0a671e2695eecc74d79ef666267a40e81172205f0f8b1d0b12a7dbbed446becd. Native QA initial/reload accepted six exact Docker IDs and complete names, including distinguishing rollback suffixes. Actual menu open/close, separate IP/action areas and both screenshots passed scoped review, with zero resource writes or page/console/loading errors. One restart preserved runtime settings and database counts. The historical 500 visual HOLD remains unchanged and the full permission/resource/locale matrix remains INCOMPLETE. See the release notes.

Published Server v1.6.500 packages Engine v0.183.331 to accept only the two stable imported-container lifecycle pairs, running/active and stopped/inactive, in both selection and the name-only full-row CAS. All existing ownership, full Docker ID, active Host/Agent, unique mapping, managed/service exclusions, role/schema denials and deployment/authentication contracts remain unchanged. No migration or runtime patch is required. Engine source is 515a5d37a1194f827bc3ffde34db729905ecb2b1, with exact WAR SHA-256 0c8310d9e9a872589972658d2fd8cb88f59f473ab8072a4746df5b0f4ef9e70e. The immutable image is ghcr.io/pasturestack/server:v1.6.500@sha256:7ffd67a7f82da0d374d7846b97b5a2fb71647ad01a159120418544591899f5f5, from source abdee460eb67c8cd02a2db8e9a55b15f58020d83 and successful publication run 36973764295. Exact public asset/image/component readback matched. The unchanged merged-rootfs gate retains 52 raw findings and eight Medium vendor-pending package findings (four unique CVEs), with zero untracked, Critical/High, fixed-available or secret findings; this is not a zero-CVE claim. QA500 first start/restart returned HTTP 200 / pong (nine and 10 attempts). Runtime-contract and tracked five-table count differences are zero; original environment overrides, three named volumes, docker-default AppArmor and unless-stopped restart policy were preserved. Docker health is null, not Docker healthy; count equality is not a whole-database comparison. The previous Server499 rollback is retained and stopped. Native Host1 initial/reload checks matched five unique full Docker IDs, names and links, excluded removed mappings, and observed a forwarded WebSocket server message without resource writes or browser/console errors. Screenshot review still found indistinguishable truncated rollback names, so visual acceptance remains HOLD pending a scoped Web Console layout correction; the full resource/role matrix remains INCOMPLETE. No company-site, all-page or all-locale acceptance is claimed. See the release notes. Historical 499 name failure and browser HOLD below remain unchanged and are not promoted to 500.

Published Server v1.6.499 packages Engine v0.183.330 from source 3f7320a8063a5471618be5b8be6a168f49559847, with exact CI WAR SHA-256 c01cbbfd63625fc09f39c5494775919aad6db22c92050b217b28b940b57e1de3. Only eligible standalone imported-container names are synchronized to fresh full-ID Docker names; managed-service logical names remain unchanged. No database-schema or stored-data-format migration is introduced. Web Console 1.6.164, Engine329 role/schema protections, Compose, mounts, OIDC/MFA/session ownership, runtime base and security thresholds remain unchanged. Engine330's signed release, exact CI assets and isolated H2 startup passed. The immutable Server image is ghcr.io/pasturestack/server:v1.6.499@sha256:8552137dd4e40bf20dee5524cabf09540ed7431328e584ca1e488065e6fec394, from source 0a656e617c51059b92fb37a9b0571f142e8463aa and successful publication run 36969193015. Exact build/flatten and isolated first start/restart HTTP 200 / pong (12 and eight attempts), 34 MFA policy/API checks and TLS 1.2/1.3 checks passed; untrusted certificates were rejected. Public assets/image/SBOM readback matched. The unchanged merged-rootfs gate reports 52 raw findings and eight exact Medium vendor-pending package findings (four unique CVEs), with zero untracked, Critical/High, fixed-available or secret findings; this is not a zero-CVE claim. QA499 first start/restart returned HTTP 200 / pong (nine attempts each), with original environment overrides, mounts, AppArmor and restart policy preserved; runtime-contract and tracked five-table count differences are zero. Docker health is null, not Docker healthy. Targeted name acceptance remains failed: Engine330 rejects normal stopped/inactive instance/mapping pairs. Retained rollback containers were not deleted or manually renamed. The browser HOLD and this product defect remain recorded pending a new immutable correction; these results are not full-matrix or company-site acceptance. See the release notes. The published 498 evidence below is historical to that release and is not promoted to 499 proof.

Published Server v1.6.498 packages Engine v0.183.329 and Web Console 1.6.164. Readonly/restricted GenericObject key/resourceData visibility changes in both API versions; privileged roles retain those fields. Use typed plugin APIs for safe low-role configuration reads. No stored-data migration, authentication, session, Compose/AppArmor/nftables or Web Console version change is introduced. The immutable image is ghcr.io/pasturestack/server:v1.6.498@sha256:bd8671e99fbf3661f91d6667f6cb04b16ade89a8d463ae872ffd84ce1e65a6e7, from source ea58d92167eef31b76c7616f41df4d515530c359 and successful publication run 36954622994. Exact build/flatten, isolated first start/restart HTTP 200 / pong (10 and six attempts), 34 MFA policy/API checks and TLS 1.2/1.3 checks passed; public assets/image/SBOM readback matched. The final one-layer merged-rootfs scan has 52 raw findings and eight exact Medium vendor-pending package findings (four unique CVEs), with zero untracked, Critical/High, fixed-available or secret findings. This is not a zero-CVE claim. The exact Engine329 WAR's normal CI executed 266 suites / 1,123 tests with zero failures, errors or skips. The recorded QA498 8080 upgrade ran the immutable 498 image / Web Console 1.6.164. First start/restart returned HTTP 200 / pong (11 and 10 attempts); runtime contract and tracked five-table DB-count differences were zero. The original three named volumes, environment overrides, docker-default AppArmor and unless-stopped restart policy were preserved. Docker health is null, not Docker healthy; counts do not establish whole-database equality. The previous v1.6.497 rollback container is retained and stopped. Limited Receiver role/API/header/message gates passed in scoped QA. Member retains privileged reads; restricted/readonly typed reads retain safe configuration without URLs, and GenericObject exact/list reads omit key/resourceData in both API versions. No-access exact API requests return 403. Member Add is visible; restricted/readonly Add is hidden, with Traditional Chinese direct-create denial and no-access unavailable messages verified. Normal owner fixture creation/deletion and cleanup were verified. Secret and other 498 resources, all-resource, full-page and all-locale acceptance are not established. Publication smoke and QA startup alone do not establish backend-write authorization or company-site acceptance. Historical HOLDs remain HOLD and the matrix remains INCOMPLETE. Preserve original volumes/settings for rollback; rolling back to 497 restores the low-role capability exposure. See the release notes for exact component pins.

The first 498 publisher run failed the fixed-available OpenSSL gate and remains failed evidence. This release selects official Ubuntu 3.5.5-1ubuntu3.7 via the signed HTTPS 20261002T000000Z snapshot; security thresholds and the four remaining unfixed CVEs / eight Medium package findings are retained.

Published Server v1.6.497 packages officially published Web Console 1.6.164. It includes the shared state/date display-locale fixes and Receiver validation-label fixes without changing API authorization, driver actions, clone behavior, schemas or stored data. Engine v0.183.328, embedded Cache 5.7.5, base Server v1.6.460, Compose, AppArmor and nftables contracts remain unchanged. The immutable image is ghcr.io/pasturestack/server:v1.6.497@sha256:1a1f05415e50d2ea337140d89063c6d7ae993140befa5aa79c5c83922990021d, from source 80d97523052aa86ec761ade8ec487c382a8d5e1d and successful publication run 36836319609. All 56 source gates, exact build/flatten, isolated first start/restart and 34 MFA policy/API checks passed; public assets/image/SBOM readback matched. The final one-layer merged-rootfs scan has 58 raw findings and 14 exact vendor-pending package findings (eight Medium and six Low, six unique CVEs), with zero untracked, Critical/High, fixed-available or secret findings. This is not a zero-CVE claim. The recorded QA497 8080 deployment ran v1.6.497 / Web Console 1.6.164; first start/restart returned HTTP 200 / pong (10 and nine attempts), with zero runtime-contract and tracked five-table DB-count differences. The original three named data volumes, environment overrides, AppArmor and restart policy were preserved. This is count preservation, not a whole-database row comparison; Docker health is null, and no Docker healthy result is claimed. That deployment did not establish packaged native Receiver browser acceptance. Publication smoke and QA startup do not establish full-language/layout, backend-write authorization or company-site acceptance. Historical HOLDs remain HOLD and the matrix remains INCOMPLETE. Preserve the nearest v1.6.496 QA rollback with its original volumes/settings. The v1.6.495 image and backups remain retained; its obsolete stopped container was removed. See the release notes.

Published Server v1.6.496 pins Web Console 1.6.162, Orchestration Engine v0.183.328 and the WAR's distributed-cache runtime 5.7.5. Jackson core/databind metadata is 2.22.3 / 3.2.3; numeric Hazelcast cluster runtime remains 5.7.3. The Host Add Container entry follows the loaded exact-project Container POST schema; the Secret desktop headings use existing translation keys. Neither a schema GET nor a hidden UI entry establishes API write authorization. Established schemas, stored-data formats and API permissions are unchanged. The immutable image is ghcr.io/pasturestack/server:v1.6.496@sha256:6c85435b3de8771e5adff0b247274e0f1b9fe9d66c8b91e07d55a444e5589678, from source d8e0e898b08aae45e040eb085936d11de14027fb and successful publication run 36821096323. Public assets/image readback, official candidate first start/restart and 34 MFA policy/API checks passed. The one-layer merged-rootfs scan retains 58 raw findings and 14 exact vendor-pending package findings (eight Medium and six Low) after VEX, with zero untracked, Critical/High, fixed-available or secret findings; it is not a zero-CVE claim. Isolated QA496 deployment passed first start/restart HTTP 200 / pong (10 attempts each), with zero runtime-contract and tracked five-table DB-count differences; Docker health is null, not healthy. Two zero-resource-write 1440 x 1000 desktop cases passed: readonly Host Add Container absence/Edit unavailability and the member Secret table's four Traditional Chinese headings. Host statistics remained connecting and its right-side table was not fully reviewed; the Secret body was masked. No full-layout, backend-write authorization or lifecycle acceptance is inferred. Mobile and all-language acceptance remain pending. Historical HOLDs and the first failed publication remain unchanged; the broader resource/role matrix remains INCOMPLETE. No company-site deployment is claimed. Retain v1.6.495 with its original volumes/settings for rollback; see the release notes for component source/hash identities and the publication/QA boundary.

Published Server v1.6.495 changes the Web Console Certificate editor and installs Ubuntu's official libdbi-perl 1.647-1ubuntu0.26.04.3 security fix. An existing matching certificate with a masked key and unchanged certificate and chain may submit only name/description. New or replacement material keeps full validation. No global write-only exemption, API permission change or stored-data migration is introduced. The immutable image is ghcr.io/pasturestack/server:v1.6.495@sha256:ffd4d1c2a208b0bce3f9f961500ddebfdf7024bbddcf2d1e156cdbe76d30ba56, from signed source 512d4b2377e34ce04a33266af19b62ed45949eda and successful publication run 36744673716. It pins Web Console 1.6.161 and the unchanged Engine v0.183.327. Independent assets/image readback and isolated first start/restart passed; runtime settings and database-count baselines were preserved. The one-layer runtime scan retains 52 raw findings and eight exact Medium vendor-pending package findings after VEX, not a zero-CVE claim. Browser and broader resource/role acceptance remain separate; see the release notes.

Published Server v1.6.494 pins Orchestration Engine v0.183.327 and Web Console 1.6.160; both component releases are published and hash-verified. The official image is ghcr.io/pasturestack/server:v1.6.494@sha256:9d1ddbe6f0c3fa11fefc141e14f419163c7bd14609163373d898ab0a857d790c, from source c3b50ad6891ebbde4612e89dd5a1114bc731431c and successful publication run 36704785404. Its single-layer image and 22 checksummed assets were independently read back. The security gate retains 52 raw findings and eight exact Medium vendor-pending package findings after VEX, with zero untracked, Critical/High, fixed-available or secret findings; it does not assert zero CVEs. Isolated 8080 deployment start/restart passed with unchanged runtime and database-count baselines. Certificate API/browser acceptance and the broader resource/role matrix remain pending. Retain the immutable v1.6.493 image and original volumes/settings for rollback; that image retains the Certificate defects.

Certificate name-only and description-only updates omit cert without replacing stored certificate or private-key data. Explicit null cert values are rejected by the existing non-nullable API schema with 422 / NotNullable; empty and malformed non-null values receive 422 / InvalidFormat. Create validation is unchanged. Certificate DELETE and remove actions reject alternate and default references from non-removed load balancer services in the certificate's account with the existing 405 / InvalidAction response. The console explains only the known certificate-in-use response in English, Traditional Chinese and Japanese; public action names remain case-sensitive: undeclared ReMoVe receives 422 / InvalidAction during schema validation, not the reference guard's 405. 403 and 404 remain neutral, without service names or IDs. API shapes, authorization, key masking, database formats and authentication/session behavior are preserved. No database migration is required. All other packaging coordinates and runtime security gates are retained from v1.6.493.

Preferred product-facing coordinates use PastureStack/*, ghcr.io/pasturestack/*, PLATFORM_*, and PASTURESTACK_*. Historical identifiers remain only where existing databases, agents, clients, templates, or upgrade tooling consume them. They must not be mechanically removed.

The catalog helper is packaged and installed as catalog-service and catalog-service-sqlite. The historical executable path remains only as a compatibility wrapper because the preserved service supervisor and persisted settings still invoke it. Release assets must use the PastureStack filename catalog-service-<version>.tar.xz; compatibility aliases must never leak back into the public asset name.

The authentication helper follows the same boundary: the GitHub Release asset and actual executable use authentication-service, while the preserved supervisor-facing executable name exists only as a compatibility wrapper.

PastureStack keeps the platform account as the authorization principal and treats local credentials and external identities as explicit login links. Provider changes therefore preserve the account identifier, direct project memberships, and administrator role. OpenID Connect links use exact issuer and subject values; username and email are never compatibility matching keys. Explicit reassignment may copy direct memberships and administrator status, but never copies passwords, API keys, sessions, MFA factors, recovery codes, or audit history.

Machine management uses the neutral machine-driver-bundle asset, and vSphere operations use the neutral vsphere-cli-bundle asset. The externally defined executable names inside those archives are compatibility interfaces, not PastureStack branding. Artifact, license, and command-surface checks must pass before assembly; real provider and authenticated vSphere lifecycles still require isolated integration tests.

Server v1.6.483 packages Web Console 1.6.149. Secret Edit follows the effective Secret schema: name and stored value remain immutable, while only description is submitted on save, including an explicit empty string when the user clears it. The Server API, authorization, Engine, and stored resource formats are unchanged from v1.6.482. New Registry, RegistryCredential, Certificate, and Secret action links are refreshed by ID after creation; ambiguous RegistryCredential writes are not repeated. Browser write acceptance remains an independent isolated 8080 check.

Secret payload operations use the neutral secret-delivery-api asset. The preserved engine still invokes the historical secrets-api executable and /v1-secrets routes, so Server supplies that filename only as an internal symlink while keeping the public artifact, primary executable, source repository, and license destination under the PastureStack name. Existing database key names and encrypted payload formats remain compatibility data and must survive upgrade and rollback testing.

The established telemetry.opt, service.package.telemetry.url, and /v1-telemetry identifiers remain internal compatibility data. Server installs usage-telemetry-agent, retains /usr/bin/telemetry only as an internal symlink, and packages the agent privacy notice beside its license and source record. A legacy target variable never enables publishing.

The webhook.service.*, service.package.webhook.service.url, /v1-webhooks, and four established driver identifiers also remain internal compatibility data. Server installs the neutral webhook-automation-service executable and retains /usr/bin/webhook-service only as an internal rollback link. The public asset and license destination use the neutral name, and the child process receives only the RSA public verification key.

The published v1.6.482 release changes only Web Console packaging to 1.6.147. Service Edit sends just name, description, and scale instead of the cloned launch configuration or upgrade strategy; the separate quick scale action sends only scale. The Server API and stored-resource contracts are unchanged. Its verified release identity is Server source 3d909952d31e8577793acb7e402e10b883e1c8a6 and immutable image ghcr.io/pasturestack/server@sha256:e3ac65290f17981201a6cf2857e0f6def3eb79974746bc7110357fd87869a609. Isolated 8080 deployment and restart are healthy with Web Console 1.6.147; a bounded owner-browser run passed Service Edit Cancel, Save, and injected 503 retry, plus Container and Service Remove Cancel/Confirm. The six-role permission matrix remains a separate validation scope.

The published v1.6.481 release consumes Orchestration Engine v0.183.326, Web Console package 1.6.146, Webhook Automation Service v0.10.3, Authentication Service v0.4.42, API Explorer v1.1.18, Compose Executor v0.14.36, Node Agent v0.13.27, Load Balancer Service v0.9.27, Catalog Service v0.20.11, WebSocket Proxy v0.23.14, vSphere CLI Bundle v0.55.2, distributed cache runtime v5.7.4, and Catalog Templates at commit e082033ba3c12b5f5cfcae93ff1d6f50d5440d07 (Catalog Templates v0.3.12). A Catalog upgrade changes pinned_commit first and leaves the last indexed commit untouched until Catalog Service has rebuilt the template index; pre-advancing both values can preserve a stale nonempty index. Operational container references must use numeric semantic version tags. The verified release identity is signed Server source 9c6914cda01a48dda4fb38f62d1a3f0c4db10be8 and immutable image ghcr.io/pasturestack/server@sha256:013eb045ed669344a67b8ac85d2ce56193abb74f34628281dec503dced8ab415. Web Console 1.6.146 localizes required-field and encrypted-key feedback; the isolated 8080 browser and six-role write matrix remains pending. The published v1.6.480 identity and its pending Registry Add QA are retained in its release notes. Web Console packaging must retain its fingerprinted /assets/ui*.js entry, and API Explorer must retain /api-ui/ui.min.js and /api-ui/ui.min.css.

The frozen /v1 authorization snapshots expose runtime, shmSize, and typed deviceRequests on both direct containers and service launchConfig payloads, matching /v2-beta. Role-specific create and update permissions remain authoritative; neither API version bypasses the shared service create and upgrade validation or Docker conversion path.

OIDC configuration retains a strict source-versus-policy boundary. An already enabled provider can change only its site access policy without repeating discovery or local-recovery initialization. The same comparison is applied to the platform-setting reload event emitted after the save, so the event cannot reinitialize an unchanged live provider. Startup, a first enablement, provider switch, or identity-source change still requires fresh local recovery. Broadening access requires the existing one-use MFA confirmation bound to the operator, oidcAccessPolicyUpdate purpose, and canonical request digest. unrestricted is represented with an empty allowlist in both the API and database. Its setting update carries an explicit value: "" field; generated client omission rules cannot turn the clear into a no-op. Restricted allowlists contain only deduplicated oidc_user and oidc_group principals, while stable error codes preserve the client contract. The same two identity types are present in the default external-identity list and generated project-member schema. Engine v0.183.310 makes schema creation wait for completed configuration startup, loads the reviewed list from the packaged runtime defaults, then merges base and configured options in stable deduplicated order. Engine v0.183.311 also unions the reviewed OIDC types with an older database override and exposes the same types from its frozen /v1 schema, so an upgraded installation cannot reject a valid OIDC project member merely because its persisted list predates OIDC. Unknown types remain rejected, and the configured-provider state is restored from persisted settings after restart. For an external token exchange that Authentication Service has already validated, Engine v0.183.311 treats that successful exchange as the provider boundary and validates every returned identity against the reviewed external type allowlist. It does not re-read the asynchronously propagated provider flag for those same identities. Unknown and missing types remain rejected; generic identity and project-member operations still require current provider state. Engine v0.183.312 validates Authentication Service identities before access policy evaluation, account lookup, or persistent mutation. The Engine-owned stable rancher_id added after account resolution is handled on a separate internal path and is accepted only when it resolves to the account authenticated by that token. A provider-supplied or mismatched platform identity cannot select another account. This completes the boundary that v0.183.311 began without broadening the external or project-member type contracts. Engine v0.183.313 preserves that boundary and makes fresh external-account activation synchronous. The complete account.create lifecycle now reaches active before the token path enters MFA, while MFA continues to reject every non-active account. Existing accounts, identity validation, session ownership, and access-policy behavior are unchanged. Engine v0.183.314 closes the remaining frozen-v1 schema boundary. When the historical /v1 projectMember.externalIdType options are loaded, only that field is enriched from the reviewed current core schema. Historical provider values remain in stable order, oidc_user and oidc_group become available to v1 environment and membership creation, and unrelated schemas or enum fields are not widened. Runtime validation of unknown external identity types remains fail-closed. Engine v0.183.315 restores identity ownership across repeated OIDC logins on upgraded installations. Authentication credentials are persisted for the explicitly verified user or administrator, and internal service accounts are not accepted by login-identity lookup. A historical link owned by the built-in token account is repaired only when the provider, external identity type, external ID, derived link digest, and target account identity all match. Links owned by another real account remain fail-closed and require the explicit reassignment workflow. Engine v0.183.316 keeps the existing local administrator recovery path usable when the external provider is configured with required site access. The exception is limited to a server-encrypted local-auth payload whose stable principal is revalidated as an active administrator while platform security and local recovery are enabled. Ordinary OIDC sessions continue through the unchanged user or group allow-list. Engine v0.183.317 makes shared-project provisioning explicit and role-preserving. In the default shared mode, each successful login reconciles the stable internal account identity into the single adminProject Default environment only when no direct or group membership already exists. Existing owner, member, restricted, readonly, and noaccess decisions are never replaced; existing personal environments remain intact. The optional personal and none modes preserve compatible deployments without changing authorization semantics. Engine v0.183.318 resolves an existing external identity link before applying restricted-site admission. Restricted mode can therefore honor that account's existing project membership, including the shared Default membership, without weakening required mode: required mode continues to admit only the configured OIDC user or group allow-list (plus the separately guarded local recovery administrator). Inactive or unresolved accounts still fail closed. Engine v0.183.319 makes shared-Default reconciliation atomic. It checks all active direct, group, and stable-identity memberships and creates a baseline member only while holding the same project lock used by administrator member updates. Existing owner, member, restricted, readonly, and noaccess decisions remain authoritative under concurrent login and policy changes. Engine v0.183.320 checks project-member collection requests against the requested project before loading members. A token authorized for project A cannot use that project's X-API-Project-Id header to list project B's members through ?projectId=B on either /v1/projectMembers or /v2-beta/projectMembers; unauthorized and malformed project IDs return 404. Authorized collections and direct member-ID access retain their established project checks. Engine v0.183.321 excludes inactive or removed project-member rows from direct ID reads, matching active membership collections. Active direct reads still require the caller to have access to the row's project, and an ID from another project remains unavailable. This applies equally to /v1 and /v2-beta; a removed row is not exposed merely because its database ID still exists. Web Console 1.6.132 uses the effective per-project schema for workload create and upgrade controls as well as direct routes. A missing POST or PUT method therefore cannot be bypassed by typing the route, and a project switch forces capability re-evaluation. Account administration reads exact per-account authIdentityLink records for local and OpenID Connect identity display. The environment editor separately follows project update, project setmembers, and network update action links; a direct ?editing=true URL does not grant a missing action. These UI guards supplement, and do not replace, server-side token and project authorization. The environment editor's network-policy lookup also supplies its project ID in X-Api-Project-Id; an unscoped read of a project-only network is not treated as evidence that the selected project has no network policy. The environment detail page offers an Edit entry for network-only capability after its network model loads, without inferring permissions from a role name. Direct /env/:project_id navigation and refresh select that permitted project from the router's public RouteInfo before the tab or user Default fallback. Missing, inactive, and inaccessible IDs retain the existing authorized fallback; valid URL environments are not replaced by a saved preference. Each readable account still receives an exact authIdentityLink lookup. HTTP 404 for an inactive historical account is isolated to that row and uses the embedded identity fallback; 401, 403, 5xx, transport, and unexpected failures continue to reject the route. Environment view and edit use the project projectMembers link, so member reads follow the same project authorization boundary. A 403 or 404 during the project or member load is shown as a localized access or not-found message. Server failures during environment load show a localized retry message instead of the raw response. Save failures identify whether the project, members, or network policy failed; the form warns that an earlier save step may already have completed. Identity search distinguishes a zero-result lookup from 401, 403, and server failure. An authenticated account with no active environment is a valid empty state. The console clears stale project scope, skips project-scoped collections until an authorized environment exists, and does not loop on an obsolete direct URL. Account names prefer authoritative identity links in the order name, login, then external ID; a missing link falls back to the embedded identity. Descriptions remain account data, and display-only identity links are never serialized in an account update. Web Console 1.6.133 applies the active project's effective host POST schema to host creation and cloning. A direct Add Host URL without that permission shows a 403 before registration data loads; responses from an earlier project selection cannot restore stale permissions. Project details wait for the selected project before reading its network and policy. Host access errors use localized text across all 13 console locales and remain readable in narrow and right-to-left layouts. This release changes no backend API or authentication contract. Web Console 1.6.135 requests the full active environment collection for a site administrator's switcher, including environments where that account is not a direct member. Other signed-in users still request their authorized collection; the Server remains the authority for all=true and direct IDs. The affected switcher labels use reviewed French and Russian translations. Web Console 1.6.136 bounds the environment-switcher menu in left-to-right and right-to-left views and corrects the Persian /fail page direction. It revalidates a stored environment selection with a fresh direct GET. A 403 or 404 falls back to an available environment; 401 and 5xx errors remain visible to the caller. Environment management consumes a fresh collection, so stale cached records cannot keep a revoked environment in the list. This refresh preserves the active environment and its loaded schema on return navigation; a permitted direct URL still works when its environment is absent from the collection. An already open view can retain its former selection until reinitialization or an explicit switch; Server authorization still checks membership on each request. Web Console 1.6.137 lets empty pod-list messages wrap within narrow viewports, including the Russian no-hosts message that overflowed by 6 pixels at 320 pixels. Pod-column layout, translations, host API, and authorization behavior are unchanged. Web Console 1.6.138 waits for each confirmed deletion, prevents duplicate submits, and keeps failed items available for retry. Authenticated routes wait for language initialization; denied and missing resource pages translate in the active locale without changing API authorization. Webhook Automation Service v0.10.2 requires the trusted project header to match a receiver management request and confines receiver lookup, deletion, name checks, and key or signed-JWT execution to webhookReceiver objects. The internal /usr/bin/webhook-service compatibility link is preserved. Web Console 1.6.139 reads project schema methods before showing Container, project API-key, or Receiver Hook write controls. Its Container edit modal waits for primary, port, and link saves; a failed port or link update restores that field and leaves the modal open, while successful peer updates are not retried. These separate API writes are not atomic. Webhook Automation Service v0.10.3 returns role-specific Receiver schema methods for both schema endpoints and marks those responses private and non-cacheable; stored receivers and existing routes are unchanged. Orchestration Engine v0.183.325 exposes projectTemplate.isPublic read-only in its core schema, but its frozen /v1 non-admin user schema omits the field. It omits remove actions for public or non-owned templates and keeps direct non-admin mutations owner-scoped. Web Console 1.6.140 shows ProjectTemplate edit/remove only for administrators or an exact, non-empty template owner account ID match; direct edit routes check ownership again. Its sortable-table controls reflow at narrow widths, and closing an API-key modal before delayed focus runs no longer targets a destroyed input. Role labels alone do not establish Container write capabilities: use each account's effective project schema methods when validating the controls and API writes. Orchestration Engine v0.183.325 packages FreeMarker 2.3.35 exactly once. Server v1.6.475 retains the signed Ubuntu 26.04 curl security revision 8.18.0-1ubuntu2.7 without replacing the preserved runtime base. Orchestration Engine v0.183.326 restores the read-only projectTemplate.isPublic field in the frozen /v1 non-admin user schema, matching /v2-beta; the administrator's create/update schema and stored data are unchanged. Web Console 1.6.141 gives the same localized denial on ProjectTemplate direct-edit routes for 403, 404, and owner mismatch while retaining 401 session recovery. Failed API-key saves display the existing API error inside the modal without rendering key values. Web Console 1.6.142 keeps server-issued Receiver URLs and lifecycle state out of cloned create requests, clears inherited catalog identity on new private ProjectTemplates, and reports inaccessible direct environment routes without revealing whether an ID exists. Container table actions remain within their visible scroll host while data columns keep their own width in LTR, RTL, narrow panels, and desktop-to-mobile resize transitions. Web Console 1.6.143 constructs a new private ProjectTemplate from editable fields and deep-copies its initial stacks. The create request omits Default's server-owned creation time, lifecycle state, ID, UUID, and catalog identity. Shared new-resource clones for Host, Service, Container, and VM likewise omit server-owned identity and lifecycle fields; edit and upgrade copies retain their existing behavior. Receiver clones omit inactive driver configurations, and unsupported drivers cannot submit the create form. Web Console 1.6.144 introduced create-capability checks for Secret, Certificate, and Registry Add controls and direct Add routes; Registry creation requires both registry and registryCredential POST. Follow-up isolated QA found that Registry Add was falsely denied for superadministrator, owner, member, and restricted roles when schema IDs had different casing, despite both POST capabilities. Readonly and no-access roles passed their denial checks; Secret and Certificate checks passed in English and Traditional Chinese. The false denial caused no resource writes. Web Console 1.6.145 resolves create capabilities across the mixed-case schema IDs. Denied direct routes retain localized 403 feedback, and Secret Edit follows its update action link. These are browser controls and feedback, not changes to Server authorization or API contracts. Legacy provider settings are imported only while the encrypted auth.config object does not exist. After that one-time migration boundary, the common access-mode and allowlist settings are authoritative; service and Server container restarts cannot replay absent legacy OIDC keys over a saved restricted or unrestricted policy. The /v1-auth proxy preserves the caller's PastureStack authorization for an exact POST /v1-auth/config, so the actor-bound policy confirmation reaches the Authentication Service. Provider-backed reads continue to receive the external identity-provider token; unrelated proxy routes are unchanged. New browser tokens keep the create-only clientSessionId field through the dynamic authorization overlay and the frozen base, superadmin, and token v1 schemas. Explicit logout normalizes a cookie's bare key and a standard Authorization: Bearer value to the same database key; mismatched generations and unsupported authorization schemes cannot revoke the token. Cookie and session-generation reads, login commit, and explicit logout share one origin-level mutex. A tab captures its generation when starting requests, timers, and subscriptions; stale passive failures stop their own work and adopt the newer committed session without clearing shared state. Storage and sanitized BroadcastChannel events carry no token material and converge through one serialized reconciliation path. An explicit logout is the only browser path allowed to revoke the bound token. The current-token collection is authenticated only when its first entry has a non-empty accountId, user, or userIdentity; an HTTP 200 provider login-options object with no identity is an unauthenticated response. The console normalizes it to its local 401 contract, clears only an unchanged Cookie and generation under the authentication mutex, and routes to login without a passive DELETE or reload loop. Promise/callback interoperability uses one RSVP-based adapter for PromiseToCb, authenticated-route lookup, and settings loading. Task factories start in a deferred RSVP turn, so synchronous throws, thenables, plain values, and Promises share one settlement contract; callback exceptions cannot enter a second error callback. The 27 NewOrEdit consumers share one awaitable, owner-bound save lifecycle covering validation, persistence, success hooks, error hooks, completion callbacks, and cleanup. A pre-existing saving=true lock is never claimed or cleared by a duplicate submission. Environment member loading uses the supported followLink('projectMembers') store boundary.

External-service healthState remains writable API data, including null. Load-balancer editing persists the chosen target through PortRule.serviceId; this changes no load-balancer runtime or API shape.

Deployments that terminate TLS before the Server container may set PROXY_PLATFORM_PUBLIC_ORIGIN to one exact public HTTP(S) origin. The proxy uses that origin only for requests whose Host matches the configured authority; unrelated hosts retain transport-derived forwarding values. Credentials, paths, queries, and fragments are rejected. Platform API responses are always rewritten to Cache-Control: private, no-store, while static assets preserve their existing cache policy.

Native MariaDB validation must override both CATTLE_DB_CATTLE_MYSQL_URL and CATTLE_DB_LIQUIBASE_MYSQL_URL; the application and migration pools are configured independently. The default compatibility path intentionally uses a MySQL JDBC scheme with the MariaDB driver compatibility options.

The embedded database explicitly sets innodb_snapshot_isolation=OFF. MariaDB 11.8 enables snapshot isolation by default, but the preserved control-platform transaction layer predates that behavior and already performs its own optimistic locking and retries. Leaving the new database default enabled can surface error 1020 during concurrent system-stack creation. External MariaDB deployments must apply the same compatibility setting before the Server starts.

Image defaults do not override rows already persisted in the setting and catalog tables. Existing installations must audit and migrate the narrow distribution-coordinate allowlist with scripts/migrate-approved-runtime-coordinates.sh against an isolated restore before cutover. The tool preserves compatibility setting names, creates an exact rollback bundle, and changes only approved GitHub, GHCR, CLI, Agent, load-balancer, and Catalog coordinates.

Before a future release, validate fresh install, preserved-database upgrade, both database modes, web console and API, CLI, node registration, authentication, subscriptions, catalog, networking, storage, backup/restore, rollback, artifact hashes, and non-root execution in isolated VMs.