Web Console provides the browser interface for compatible environments, hosts, stacks, services, containers, catalogs, storage, networking, access control, and administration.
PastureStack is an independent community effort to preserve, audit, and modernize the Rancher 1.6 ecosystem. It is not affiliated with or endorsed by Rancher Labs or SUSE.
Upstream: rancher/ui, preserved from its 1.6-dev line. This GitHub fork retains upstream history, authorship, dates, tags, licenses, and dependency notices. PastureStack maintenance is consolidated into one commit after the preserved upstream boundary.
Published 1.6.178 repairs viewing and editing an inactive environment by skipping
only the network and policy-manager reads that the API correctly denies for that state.
Global project/member capabilities and other authorization errors are unchanged;
the form explains network unavailability in all thirteen packaged locales.
Formal CI passed 848/848 tests, and both reproducible archives match the immutable
public download; Server v1.6.516 packages this exact component.
Server publication, artifact readback and separate isolated QA deployment passed;
first start/restart each reached HTTP 200/pong after ten bounded probe attempts,
with runtime settings and five core-table counts unchanged. Docker health is null,
not healthy; no company-site deployment is claimed. In one inactive environment,
native detail/reload, write-free edit/remove cancellation and native deletion/list
absence were observed, but the parent cleanup timeout remains HOLD. A separate
read-only database observation confirmed the environment and four networks were
purged, with no remaining members or dependent resources. Fresh API and complete
foreign-data preservation verification remain incomplete. This is not full native
lifecycle PASS; the full matrix is INCOMPLETE and earlier HOLDs remain.
See the release note.
Published 1.6.177 prevents ended log and terminal workspace entries from
reconnecting after remount/reload or from late access-ticket, broker, socket
and timer callbacks. Both components share one lifecycle boundary; asynchronous
work remains bound to its original entry. Explicitly opening a new entry and
reconnecting a live entry remain supported. Seventeen targeted real-component
tests passed within formal exact-source
CI 37255121243:
841 tests passed with zero failures/todo, and both production archives are byte-identical.
Numeric lightweight tag 1.6.177
binds signed source commit b9b841e65afe1d89a5b03ac767e9168bccd3c3ea; it is not a signed tag.
Normal PR #175 squash merge 5d150806be20226657e5caa8a0150d068006c772 has the same reviewed tree
109a60fc005d9dc18e38864089dd0055980485c3 and a verified signature.
Anonymous public archive readback matched SHA256
4e34eb2b3165f078134cddcf1721239b3da7baf11dd683991b2d6aa5bae944e0 (2,982,494 bytes).
Published Server 515
packages this exact component: source f0267ff3a347ea526088db1749b1d3c8dfd9bd37, manifest
sha256:fcc79f616927040ef2b3a5c58662fa948823220dbc57ffe275dee2ad88764d47.
Its official publisher and independent artifact/runtime/security readback passed.
Separate isolated Server 515 / Web 177 deployment and independent readback passed:
initial-start and restart polling reached HTTP 200/pong after 10 and 11 attempts,
respectively. Runtime configuration, environment overrides, three named volumes
and five core-table counts were preserved,
with docker-default, unless-stopped, database backup and 514 rollback retained.
There is no Docker Healthcheck; running/pong is not Docker healthy.
Isolated native browser lifecycle acceptance remains pending; the full matrix remains
INCOMPLETE. A separate fresh Project v2 native run remains HOLD after a successful
deactivate response and a UI wait timeout; native removal and database cleanup
are incomplete. Historical HOLDs are unchanged, and this is not production
acceptance. See the
release note.
Published 1.6.176 repairs native select bindings that passed a mut reference
directly to the classic compatibility action helper. The helper receives the
current value instead of a setter; wrap mut in native fn to retain the setter
while preserving the existing event value mapping. This covers the same 21
select bindings in 11 templates, including project roles, schema fields,
balancer rules, settings and machine-driver fields. Project member capabilities,
identities, metadata/network write boundaries, save finalizers and authentication
remain unchanged. Exact-source
CI37175725533
passed 824/824 tests with zero failures, skips or todo, including 32 targeted
cases (29 retained and three new native-mut regressions). The signed immutable
numeric release
pins source a1bbf172aad8443bfbb1859760d62669d6705189 and tree
dfa280c29e241bb815eff852e8a188c101e338eb. Both reproducible CI archives and
anonymous public downloads match SHA256
071ce0b7091b323e0d84fe91269684f59fcf2e29000bd8ff94428e8dd03ece52
(2,982,158 bytes). Thirteen packaged locales and the source gates passed;
affected build-package modules are absent from the static artifact inventory,
not a runtime not-affected or zero-CVE claim. The build audit remains 7 High /
3 Moderate, with the existing reviewed GHSA-vfj7-8cjw-p6xm vendor-pending
boundary through 2026-10-10. The published
Server v1.6.514
includes this component and Catalog Service 0.20.12; its official packaging,
startup and restart checks passed. Isolated deployed UI checks also passed for
the Traditional Chinese and English container/VM forms and INIT layout. These
form checks do not establish VM boot, GPU runtime or every locale. Separate
isolated tests verified network service editing and cleanup, and completion
and cleanup of an existing catalog upgrade. Readonly and target-environment
no-access container denials were verified separately. Owner start/restart,
logs, terminal and deletion returned their expected native responses in separate
runs; logs and terminal had actual WebSocket output and normal termination, and
the delete confirmation closed normally. Independent read-only queries found
the container and its six associated records terminal (removed or purged).
This cleanup observation is not full historical data-protection or lifecycle PASS.
Environment deactivate/reactivate/remove
screens were observed in separate stages and test-data cleanup was independently
confirmed; this is not complete historical data-protection acceptance.
Earlier incomplete results are not promoted. The full matrix remains
INCOMPLETE. See the
release note.
Published 1.6.175 keeps the container/VM form's image validation message in
sync when the operator corrects the image or changes the locale. Only the
form's own validation aggregate is refreshed: model/command errors and later
backend save errors remain intact. The shared save lifecycle, lock ownership,
payloads, permissions and authentication are unchanged. Exact-source
CI37163340764
passed 821/821 tests, including four new real-component regressions, with zero
failures, skips or todo. The signed immutable numeric
release
pins source bb905d092700c262497b88f5773e7714fc1f4be4. Both reproducible
builds and anonymous public downloads match archive SHA256
9833467b2be47d4fa01f09954fcd35beb292c59d382d5c1aecd76d17c6a387a2
(2,982,158 bytes). Server packaging and deployed UI acceptance remain pending;
the full matrix remains INCOMPLETE. See the
release note.
Published 1.6.174 removes the ordinary-container default and quick picks from
the VM image field. Custom images, existing image values and the last-used VM
image remain supported; ordinary container defaults are unchanged. A blank
image still blocks the existing save lifecycle. VM boot-image guidance and
required errors for both VM and container images use reviewed English and
Traditional Chinese copy with the existing English fallback.
Dependency versions and the dependency graph are unchanged. Exact-source
CI37152802665
passed 817/817 tests with zero failures, skips or todo. The signed numeric
release
pins source d24b7f4e164f058e3ef9057347caa2080e2b5407; both reproducible CI
archives and anonymous public readback match SHA256
6408775898f412e4b27092eeddd9cdc2028ad7b27835f489139c2d0cf62c6776
(2,982,022 bytes). Server v1.6.512 packages this exact component. QA125/8080
fresh VM/container image forms passed eight scoped English/Traditional Chinese
cases with zero resource writes. This is not a successful VM boot or full
permission/resource/locale acceptance; the discovered stale parent image error
is addressed by the published 1.6.175 component above, not yet deployed. Historical releases
and HOLDs are unchanged; the full matrix remains INCOMPLETE. See the
published release note.
Published 1.6.173 repairs empty environment-template choice labels. These
choices are native ProjectTemplate resources, not Catalog templates: their
authoritative label is name, and selection remains bound to the template ID.
Four focused regressions cover the actual model, rendered choices, renaming and
selection. Exact-source official validation
37115288389
passed 812/812 tests with zero failures, skips or todo and two byte-identical
production archives. The signed immutable numeric
release
pins source c8b8bb2659fdad3539cf6a72866c94a77ec516b6; anonymous public archive
and checksum downloads match SHA256
a566684e6e0831630a15cb7212989c0e9fe707ed07965156c2b664b9cdb5ba27
(2,982,104 bytes). Publication reused the formal CI artifact without rebuilding.
Server v1.6.511
officially packages Engine333 and this exact component; its isolated artifact
and public readback gates passed. QA125/8080 upgrade and independent read-only
checks passed with first-start11/restart10 HTTP200/pong and unchanged runtime/DB
counts; this image has no Healthcheck, so Docker healthy is not claimed.
The version-bound native read-only proof for existing Template117 passed with
3 Full17/14 guards, zero resource writes and source-bound same-ID empty
stacks/services verification; it is not a native-create finalizer.
Process native list/link/detail and same-ID direct GET passed for one current ID:
two API roots × six roles, 12/12 cells and zero resource writes. Other IDs and
write methods remain untested.
Fresh Project key 1c6998 is independently verified as
DERIVED_SCOPED_KEY511_VERIFIED_NOT_ORIGINAL_PASS: the same actual child run has
4 native writes, 13 guards, 6 cookie-free issued Basic GETs before deactivate/delete,
4 barriers and 18 first-delivery checks. Its original parent QA-receipt identity-schema HOLD is retained;
the read-only derived check did not rewrite receipts or replay writes. See the
release note for evidence and limits.
Native Project/Host acceptance remains independently pending; publication or
this key scoped result does not promote historical HOLDs or establish those outcomes.
The complete permission/resource/locale matrix remains INCOMPLETE. See the
release note.
Published 1.6.172 preserves API-key create-only first delivery when a redacted
subscribe model arrives before POST/201. Only the API-key editor opts into a
request-private, Schema-bound delivery to its detached clone; newer canonical
state and nested resources remain intact, and the canonical Store does not need
to retain the secret. Compatibility revision 6 replaces revision 5 without
changing dependency versions or the graph. Exact-source official validation
37109872791
passed 808/808 tests with zero failures, skips or todo, including fourteen
installed-Store ordering cases and two save-owner cases. Personal and project
stores each exercise 100 deterministic barriers. Two production builds are
byte-identical. The signed immutable numeric
release
pins source daab6e8ed5206562feb60e6549a3b9e72b4c8381; archive SHA-256 is
9a21c5e6ff9fbb274dbc7c45ec1ccffdbff33a945544b64d5976b14ee9752bfa
(2,981,642 bytes). Anonymous public archive and checksum downloads match the
same formal CI artifact; publication did not rebuild it.
Server v1.6.510
officially packages Engine333 and this exact component. Separate QA deployment
and fresh-key native first-delivery acceptance remain pending. Historical HOLDs
remain HOLD; the complete permission/resource/locale matrix is INCOMPLETE. See the
release note.
Published 1.6.171 repairs a shared Store ordering defect: a delayed initial
create response could overwrite a newer subscribe model and leave a successfully
created local Volume stuck in its initial state. Only ID-less create POST/201
uses an existing exact-ID, concrete-type canonical model in the same Store,
generation and API base. Ordinary reads, updates, actions and backend permissions
keep their existing contracts. API-store compatibility revision 5 replaces
revision 4 without changing the dependency graph; earlier archives are retained.
Focused Chrome validation passed 36/36 tests, including ten new regressions and
100 deterministic subscribe-before-201 barrier iterations, with no failures,
skips or todo. Exact-source official validation
37094728912
passed 802/802 tests with zero failures, skips or todo, including the ten new
create-order cases; all 22 audit-gate selftests passed. Two production archives
are byte-identical. The signed immutable numeric
release
pins source fc37f5af9320e492bec7e7244cd62144908b720e; archive SHA-256 is
49fac41ca93eb628d0877104f9512ef382ffd9dbc89e04c940196b3a9c57798b
(2,981,230 bytes). Anonymous public downloads match the formal artifact.
Server508 packaging and native fresh-volume create/cancel/refresh/denial/removal
acceptance remain separate pending gates. Historical HOLDs are not promoted;
the complete permission / resource / locale matrix remains INCOMPLETE. See the
release note.
The first exact-source official run stopped before tests on newly reviewed
GHSA-vfj7-8cjw-p6xm in build-only [email protected]; upstream has no patched
release. It remains a High vendor-pending finding, not a zero-vulnerability
claim. The live audit preserves the High threshold and rejects unexpected
advisories, dependency drift, non-development exposure and expired reviews.
Only the exact reviewed advisory's dependency closure may remain pending until
2026-10-10. No third-party runtime patch or toolchain downgrade is applied.
See the bounded risk record.
Published 1.6.170 corrects an optional mounts: null projection being
mistaken for a real allocation in the shared local-volume list. It preserves
the complete advertised pool relationship, full scoped mount cache, exact-volume
binding checks and backend permissions. Raw IDs and malformed values do not
become empty evidence. Exact-source official validation
37082272427
passed 792/792 tests with zero failures, skips or todo and two byte-identical
production archives. The signed immutable numeric
release
pins source 09df1480c5f4b58c6a9a9060ff94d980792f7015; archive SHA-256 is
900974b07bb20ba5b2e7c1dede7012a53c6e2c96cd094c67cb7019434c4f27c9
(2,981,065 bytes). Anonymous public downloads match the formal artifact.
Packaged Server507 acceptance passed the existing-volume Store/list/refresh,
write-free delete cancellation, exact-ID readonly denial through both API roots,
and native owner removal for two isolated volumes. Restricted, readonly and
no-access Host Add entry denials passed separately in Traditional Chinese and
English. Fresh volume creation remains under investigation; historical HOLDs
and the complete matrix are not promoted. See the
release note.
Published 1.6.169 corrects the shared unallocated-local-volume classifier.
The engine may generate externalId from a volume's name; that identifier does
not allocate the volume to a host, workload or storage pool. Classification
still requires explicit local/non-native fields, no host/image/instance binding,
the complete advertised storage-pool relationship and the full scoped mount
cache. Identifier changes invalidate stale relationship proof. No API permission,
authentication or lifecycle request is changed. Exact-source official validation
37078265265
passed 791/791 tests with zero failures, skips or todo, including three
identifier/allocation-proof regressions, and produced two byte-identical
production archives. The signed immutable numeric
release
pins source 5962f57fccb4062a65b5921646c06b4663713b9b; archive SHA-256 is
e2bcb97b0da810f2ff216f9738739235e3c6f29ef46f1d99b623cf9c9f7258e2
(2,981,057 bytes). Anonymous public downloads match the formal artifact.
Server v1.6.506 is now published and deployed on the QA 8080 host, with initial
and restart HTTP 200 checks and preserved configuration/volumes. The packaged
native existing-volume terminal found the null-projection defect above; fresh
create/cancel/refresh/readonly-denial/remove acceptance remain pending.
Historical HOLDs are not promoted; the complete permission/resource/locale
matrix remains INCOMPLETE. See the
release note.
Published 1.6.168 makes the Volume Add control and direct create route
use the current environment's actual schema capability. The shared create/upgrade
route guard rejects missing or stale environment schemas; upgrades still require
PUT rather than POST. Existing localized permission notices and backend
authorization remain unchanged. Nine directly affected Chrome regression tests
passed with no failures or skips. The release also adds an independent local
Volume entry and an unallocated local-volume list. Classification requires the
actual complete storage-pool relationship and full environment-scoped mount
cache, including inactive workloads; missing data does not mean unused. The
native advertised deactivate action is offered only for a proven unallocated
volume in the current environment, before the existing remove workflow.
Relation failures retain the original route/growl error instead of silently
inventing an empty result. Exact-source official validation
37061716638
passed 788/788 tests, with zero failures, skips or todo, including sixteen new
scoped Volume cases, and produced two byte-identical production archives.
The signed immutable numeric release
pins source 2120e0416fd4a0efb5d351f9da4ec632ac8eacdc; archive SHA-256 is
fdd1d33d47b032eef8b5b6d5dbb1401110daf860d84a6c17003577463d3d2cb5
(2,981,125 bytes). Anonymous downloads match the formal artifact.
Server v1.6.504 packages this component and passed QA first start/restart
with unchanged runtime settings and database counts. Native Volume lifecycle
acceptance remains pending: the first run stopped before resource writes on a
v1/v2 schema assumption in the acceptance tool. That HOLD is preserved.
Publication and deployment are not complete permission-matrix PASS. See the
release note.
Published 1.6.167 fixes mixed-case schema-ID lookup in the shared API store.
Schema keys use the same normalization as the existing cache producer; ordinary
resource IDs remain case-sensitive. Inherited resource getters and capability
checks read the actual project store's schema, without fallback permissions or
changes to API names, authorization or lifecycle requests. Compatibility archive
revision 4 replaces revision 3; earlier archives remain unchanged. Four new
actual Store/schema regression cases and the local Chrome 4-test/43-assertion
run passed. Exact-source official validation
37012345421
passed 772/772 tests, zero failures, skips or todo, and produced two
byte-identical production archives. The signed immutable numeric
release
pins source dff35fc4bce340e21cac7204146a7bcb20a7b60b; archive SHA-256 is
e8e714fc06282de75a3570aac1d4d4d04a3c9478d982d0d5aaeae14efa8ebbaf
(2,976,297 bytes). Anonymous public downloads match the formal artifact.
The artifact is separately packaged and QA-deployed in Server503. Its first
start and one restart returned HTTP 200/pong after nine attempts each, with
unchanged runtime settings and five-table count baselines. Docker health is
null, not a healthy result. Packaged QA confirmed the actual GET-only
registry/credential models for the readonly role and readable permission errors
for readonly/no-access roles; their 24 normal-CSRF v1/v2-beta write denials passed. This exact-fixture
coverage is not all API authorization or full native lifecycle/locale acceptance.
The complete permission/resource/locale matrix remains INCOMPLETE. See the
release note.
Published 1.6.166 completes the shared state-badge display translation for
Inactive. The thirteen supported language files gain that display label;
icons, colors, API states and health/connection overrides are unchanged.
Eight focused Chrome rendering tests passed all 34 assertions, including
switching the actual thirteen language catalogs and retaining unknown-state
and override behavior. Exact-source official validation
36998466706
passed 768/768 tests, zero failures, skips or todo, and produced two
byte-identical archives. The signed immutable numeric
release
pins source b63fa15f6726cb78659ae43258dfc802b30d6d04; archive SHA-256 is
9205fbaec6e80f31846212f0949c3eac0fae083f80c6c46a3122d64c4d9da6c6.
Anonymous public downloads match the reviewed artifact's hash and size;
publication reused it without rebuilding. This component publication does
not establish Server packaging/deployment, packaged native-browser or
complete permission/resource/locale-matrix acceptance. See the
release note.
Published 1.6.165 fixes ambiguous container names on Host cards. Long names
now wrap within the existing card instead of hiding distinguishing rollback
suffixes. IP addresses and action triggers retain their own space. The change
is scoped to the shared container/VM subpod; global clipped labels, Host titles,
names, IDs, API requests and authorization remain unchanged. Compiled-CSS
regressions passed four Chrome cases and 744 assertions across light/dark,
LTR/RTL and desktop/narrow viewports. Exact-source validation
36979009940
passed 767/767 tests, zero failures or skips, and produced two byte-identical
production archives. The signed immutable numeric
release
pins source 00bcd9fdc92afead708dffb4a2b3b01f4ebaeaa0; archive SHA-256 is
5baaa4879fe5548cc8b66cd1c7a2005edf586d4b5f12b6dbb3796b6692e41959.
Anonymous public downloads match the reviewed artifact's hash and size;
publication did not rebuild it. Packaged Server501 native initial/reload
matched six exact Docker IDs and complete names, including all five readable
rollback suffixes. Root reviewed both actual screenshots; IP/action separation
and native menu open/close passed, with zero resource writes or
page/console/loading errors. WebSocket connected and a real server message was
observed. These scoped checks do not promote earlier receipts or the complete
permission/resource/locale matrix to PASS; that matrix remains INCOMPLETE.
See the release note.
Published release 1.6.164 reuses visible Receiver form labels for shared
required-field and numeric validation errors. The three supported driver
configurations retain their own label scopes; model-specific translations still
take precedence and unknown fields keep their existing fallback. The scale
models' existing minimum-greater-than-maximum checks use the existing localized
numeric error. No validation rule, API, schema, permission or driver behavior is
changed. Focused Chrome 153 source validation passed 12/12 tests with 61/61
assertions (eight new Receiver cases and four adjacent existing cases).
Official validation 36831735186
passed 763/763 actual tests, including those cases and the twelve retained
Web163 locale cases, with two byte-identical production archives. The signed
immutable numeric release
pins source c3c0779d930d4d0367ec0517166ca21f6b3dc6d4; its archive SHA-256 is
734898ac6ed2fe8774e5bb947988da9720a3a65aa0bb7ec09a89420adc0acc20.
Anonymous public downloads match the reviewed candidate's hash and size; the
existing candidate was published without rebuilding. This does not establish
Server packaging, QA or production deployment, native packaged-browser,
complete-language or complete-matrix acceptance. The initial fixture failure,
published 1.6.163 and historical HOLDs remain unchanged. See the
release note.
Published release 1.6.163 contains two shared display-locale fixes.
Relative dates recompute when the selected language changes and use a Moment
instance locale, without changing the global locale during formatting. State
badges translate seven known display labels through existing translations;
unknown labels and model health/connection overrides such as Disconnected
remain unchanged. Icons, colors, model state and API behavior are preserved.
Focused native Chrome 153 source validation passed 12/12 tests: seven rendering
checks, three relative-date/helper checks and two existing user-language checks.
Official validation 36827428183
passed 755/755 tests, including those 12 locale cases, and produced two
byte-identical production archives. The immutable numeric
release
pins source 5db737a5e04c4cc15672f97296d5bf521ab9a8da. Its archive SHA-256 is
54ef4e0726c6564abfb0b16727e991ef8a2258d9655cd1e603f43d6a557f8d27;
public downloads match the reviewed candidate's hash and size. Component
publication does not declare Server packaging, deployment or packaged browser
acceptance. This is not full-language or resource/role matrix acceptance;
earlier HOLD evidence remains HOLD. See the
release note.
Published release 1.6.162 contains two narrow desktop fixes. The Secrets
table headers use the existing generic translations while retaining their
sorting, search and QA mapping fields. Host details show Add Container only
when the current environment's loaded container schema permits creation;
schema reloads and environment changes cannot reuse stale create access.
Container-list and Host-card capability checks and the direct Add route remain
unchanged. The permission gate uses schema capabilities, not role-name checks.
Focused source validation passed Secrets 2/2 and Host 8/8 tests (four new Host
cases plus four adjacent existing cases), plus two desktop rendering checks.
Official CI passed 746/746 tests and produced two byte-identical archives.
At component publication, Server packaging remained v1.6.495 / Web Console
1.6.161; packaged browser acceptance of 1.6.162 was still pending. Responsive/mobile Secrets
labels and all-language layout acceptance are not claimed. Earlier HOLD evidence remains
HOLD and the broader resource/role matrix remains INCOMPLETE. See the
release note.
The numeric release 1.6.162
pins source 46501e31071b3d74595aea91908876eec32b7fd6. Its archive SHA-256 is
9c5b34d2cdf7ad354e1dab199795b12e5de119e47dc342547d5cdc84c7911581.
See official run 36810596087.
Component publication does not establish packaged browser or backend-write
acceptance.
Published release 1.6.161 fixes existing Certificate metadata edits
blocked by the masked private key. Name/description-only edits omit certificate
material from the PUT body; new certificates and material replacements keep
full validation. The editor explains this distinction in all supported locales.
Focused real-model and rendered three-language UI tests passed 25/25; the full
official CI passed 738/738. Packaged owner/member Certificate browser checks
passed on isolated Server v1.6.495: Cancel, metadata Save, refresh and the
in-use delete explanation. Earlier HOLD receipts remain HOLD, and the broader
resource/role matrix remains INCOMPLETE.
See the release note.
The numeric release 1.6.161
pins source 2ad068d62b5afd3cd213cde8addc5ebbef738130. Its archive SHA-256 is
fa3ec0bf5173fa75a53dd621b87e1f587b20d9ecc6e5cb42a703ac4f5f7e97e7.
Official run 36738408143
produced two byte-identical archives. Component publication is not completion
of the broader resource/role matrix.
The console retains the existing Node 24, Ember, Sass, dependency, browser-smoke, terminal, console, and test-harness modernization. It adds a provider-neutral OpenID Connect administration and sign-in flow with PKCE S256, staged configuration validation, a real test login before activation, and local-authentication recovery. Product-owned names, logos, icons, package metadata, and visible text use PastureStack branding. API models and protocol fields remain compatible.
Release 1.6.160 adds a clear, localized explanation when the API rejects
deleting a certificate still referenced by a load balancer. It tells the user
to remove those references first, without exposing service names. Denied or
missing resources and unrelated action failures retain neutral messages;
authorization, delete behavior, session and MFA contracts do not change. See
the release note.
The official numeric release 1.6.160
is published from source commit 63964fa3a6da5cbd452cdc1061c1e18340055362.
The web-console-1.6.160.tar.gz archive has SHA-256
705946b96e693c55a8ab5de3bc96b14020a52a050bf3992c302b9fb3c1408a51.
Official validation run 36702030007
passed 725/725 tests and produced two byte-identical archives. The published
asset's hash was independently read back and matched. Server artifact and
isolated browser acceptance remain pending; this component publication does
not complete the resource/role matrix.
Release 1.6.159 preserves an existing Registry credential's password when
the editor changes only its username or leaves the password input blank. The
editor submits a password only when a new nonempty value is entered, preserving
its literal whitespace. It retains the exact-resource, parent-registry,
project and current update-capability checks. This is a browser payload fix;
Server authorization and Registry credential creation are unchanged. See the
release note.
The official numeric release 1.6.159
is published from source commit aab95cf41ebc45e4c51513d9589602ab990399c9.
The web-console-1.6.159.tar.gz archive has SHA-256
f014083480e10430701e3a08588cf617242188938d9f935fbaac42a3b5feeb90.
Official validation run 36686121660
passed all 723 tests (723/723) and verified deterministic packaging. The earlier
7/7 result covered only the focused Registry editor tests. Published Server
v1.6.493
packages this archive at immutable image digest
sha256:61067362a2d91b791c7e80cb2ec4a5a907bc03884774d2019dccf1bf0e29788f.
Scoped Registry acceptance on isolated QA 8080 passed 24 GET checks across six
roles and both API roots, eight no-access PUT/DELETE denials with HTTP 403, two
API password replacements, and one owner browser username-only save that omitted
secretValue. Eight readonly write cases returned HTTP 405 because the schema
omits those methods; they remain N/A, not authorization passes. Cancel, refresh,
credential and parent Registry identity preservation passed. The password hint
and controls fit in English, Traditional Chinese and Japanese at 1440px and
390px. Both disposable fixture resources reached their terminal cleanup states.
Other workflows and the broader role/resource matrix still require acceptance.
The same release also pins official compatible High-severity security fixes for the build
and test graph: brace-expansion 1.1.21 / 2.1.7 / 5.0.12 on their existing
major lines, and engine.io 6.6.10. The reviewed lock baseline and dependency
gates cover these pins; the live npm audit --audit-level=high gate remains
unchanged. This does not claim that remaining Moderate advisories are fixed.
Release 1.6.158 gives Service direct-ID and Secrets-list load failures
the same localized, resource-safe handling already used for Stack loads. It
also gives HTTP 405 save and action failures the existing translated
unavailable messages. Focused source tests cover English, Traditional Chinese,
and Japanese. The official archive is published with SHA-256
286833d3313c5bc04469a8fafd41bab7de1c4b60527f91aae9eef8a4016b17f6;
Server packaging and live browser acceptance remain separate. See the
release note.
Release 1.6.157 mounts authenticated-page notices when their component enters
the DOM. This covers the fresh direct-URL denial missed by 1.6.156's route
render callback while keeping login/MFA notices on the body. The focused source
tests pass, and the official archive is packaged in Server v1.6.491. Isolated
8080 QA on that image passed 14 scoped Stack and Service direct-create notice
cases with zero resource writes. This does not establish the broader role and
resource matrix or a formal company-site deployment. See the
release note.
Release 1.6.156 introduced the in-flow authenticated notice layout, but
Server v1.6.490 QA found that a fresh readonly direct create URL still left
the notice fixed on the body and overlapping header actions. An in-app
transition did mount it correctly. See the
1.6.156 release note.
Release 1.6.155 moved global notices below the navigation bar and bounded
their width. QA 8080 browser acceptance subsequently found that the fixed
notice still covered the mobile page title and desktop header actions. It is
not the accepted layout; see the
1.6.155 release note.
Release 1.6.154 shows a localized, persistent permission error when a direct
Stack or Service creation URL is denied, then returns to the Stacks list.
Service upgrade URLs continue to use update permission and receive an update
error only when that permission is absent. The shared message covers all
resource types using the route guard. See the
release note for source test evidence.
It was packaged in Server v1.6.488; its 8080 browser acceptance identified
the notification/navbar overlap addressed by 1.6.155.
Release 1.6.153 makes Stack, Service, and Container write controls check
their current project/resource capability when the user acts; delayed project
upgrades and service scaling cannot carry a click into a different selected
project. It improves Registry edit recovery, localized errors and Japanese
form labels, and shows an unavailable state when host/container monitoring
cannot connect instead of leaving a spinner. These are browser-console
changes, not a substitute for Server-side per-resource authorization. See
the release note for test evidence
and the remaining 8080 acceptance boundary.
Release 1.6.152 uses each Stack, Service, and Container form's visible,
translated name label in its required-field error. This closes the
Chinese/Japanese Stack mismatch observed on isolated Server v1.6.485 QA;
it does not change request payloads, server authorization, or other fields.
See the release note. Source tests
alone do not establish acceptance of a packaged Server image.
Release 1.6.151 restores Secret Edit when the current resource schema
allows PUT and the active Secret has a self link. Secret Remove still follows
the API's explicit remove action. This matches the API's existing Secret
write contract without granting Edit to read-only users or changing Secret
payloads. See the release note.
Source tests and the earlier API-only QA do not by themselves establish
browser acceptance of a newly packaged Server image.
Release 1.6.150 limits Certificate Edit and existing RegistryCredential
Edit to the fields shown in their forms. Their PUT requests no longer resubmit
cloned server-owned IDs, state, timestamps, or unrelated model metadata.
RegistryCredential creation after a missing credential retains its existing
readback and uncertain-write safeguards. See the
release note; source tests do not by
themselves establish browser or API acceptance.
The 1.6.149 source change makes Registry creation recoverable when its
separate credential request fails: it never automatically deletes a registry
or blindly repeats an uncertain credential write. New Registry, Certificate,
and Secret records are refreshed by ID so their action links are available
after creation; Certificate Edit also rejects encrypted private keys. See the
source release note. Browser acceptance
and publication are separate steps.
Release 1.6.148 makes Secret Edit follow the current Secret schema: the name
is shown read-only with an explanation, and Save sends only the editable
description. A successful Save updates the listed Secret; a rejected Save
leaves the form open. Secret Add continues to accept a name and value. This
builds on the 1.6.147 Service Edit fix without changing the Server API.
See the release note.
Release 1.6.147 limits Service Edit to the editable name, description, and
scale fields so saving does not resubmit cloned launch configuration or upgrade
strategy. The scale form preserves an initial value of zero and applies quick
scale selections during editing; quick scale writes submit only the scale
field. See the release note for
the change scope and validation boundary.
Release 1.6.146 makes required-field errors use the visible translated form
labels for Secret, Certificate, Registry, and RegistryCredential instead of
schema-derived English names. It retains model-specific translations and the
existing fallback for fields without a form label. The encrypted-key error on
Certificate submission is localized as well. See the
release note. Browser acceptance is
tracked separately from the unit test.
Release 1.6.145 normalizes resource type names before checking the cached
project schema. It restores Registry Add for authorized users while retaining
the Registry plus RegistryCredential POST requirement and direct-route denial
for unauthorized users. See the release note.
Release 1.6.144 introduced schema-gated Secret, Certificate, and Registry
Add controls and localized 403 errors on denied direct Add URLs. Secret Edit
also began following its update action link. Isolated 8080 acceptance found
that Registry Add was incorrectly hidden even for authorized users because
the cached schema ID was lowercase. See the release note.
That regression is addressed by 1.6.145; its browser acceptance must be
recorded separately.
Release 1.6.143 creates a private ProjectTemplate from editable fields only.
It deep-copies the Default template's stacks without sending the Default's
creation time, lifecycle state, or identity in the new resource request. See
the release note.
New-resource clones also omit server-owned lifecycle fields across Host,
Service, Container, and VM forms. Receiver clones exclude inactive driver
settings; unsupported Receiver drivers cannot be submitted from the form.
Release 1.6.142 stops a cloned Receiver from reusing its source's issued
webhook URL or lifecycle state; the server issues the new URL. It also keeps
the container table's actions visible during horizontal scrolling without
changing data-column widths, clears catalog identity when creating a private
ProjectTemplate, and shows localized denial for direct create routes and an
inaccessible environment. See the release note.
Release 1.6.141 gives denied or missing ProjectTemplate edit URLs the same
localized message in English and Traditional Chinese. Failed API-key saves now
show the existing API error in the modal; a failed creation does not display
key values. See the release note.
Version 1.6.140 shows ProjectTemplate edit and remove controls only to
administrators or the template's account owner, including when the Server
omits isPublic from non-administrator responses. Direct edit URLs repeat the
ownership check before loading the editor. Closing an API-key modal before its
delayed focus runs no longer attempts to focus a removed input; cancellation
remains write-free.
Release 1.6.139 derives Container, project API-key, and Receiver Hook write
controls from the current project's API schema. Direct routes repeat capability
checks instead of relying on hidden buttons. Receiver role-aware controls require
Webhook Automation Service v0.10.3 or newer; the Server remains responsible
for authorization. Container editing now waits for its dependent saves and keeps
the form open on a failed update. See the release note
for the precise behavior and retry boundary.
Release 1.6.138 keeps delete confirmation open while requests run, prevents
duplicate submissions, and allows retry after a failed deletion. Denied and
missing resource pages keep their shared 404 presentation when the language
finishes loading; the authenticated route waits for that language setup.
Release 1.6.137 lets empty pod-list messages wrap within narrow screens.
This fixes a Russian no-hosts message that caused 6px of horizontal overflow
at 320px. Pod columns keep their existing layout, and the environment switcher
and error-page behavior from 1.6.136 are unchanged.
Release 1.6.136 keeps the environment switcher inside the viewport in
left-to-right and right-to-left layouts, including narrow screens and long
environment names. It also preserves right-to-left text direction on the
shared error page. A stored environment selection is rechecked with the API;
when the authenticated console loads after access is revoked, it selects an
accessible fallback. The environment management list uses a fresh collection
without resetting the active environment's schema. Authentication and server
failures still surface as errors. Server authorization is unchanged.
Release 1.6.135 keeps the administrator environment switcher behavior from
1.6.134 and corrects the switcher list labels in French and Russian. The
French labels no longer mix English words into French; the Russian labels
identify all environments and your environments using the same term as the
switcher. No API or permission behavior changes in this release.
Release 1.6.134 includes every active environment in the switcher for an
authenticated site administrator, including environments where that account
is not a direct member. Other signed-in users continue to see their member
environments. The Server still authorizes the all=true collection request.
Release 1.6.133 uses the active environment's API schema to show host
creation and cloning only to users who can create hosts. A direct add-host URL
now returns a translated access error before loading registration data when
creation is forbidden. Project schema loads are generation-checked so a late
response cannot restore an earlier environment's controls. Environment detail
waits for its project lookup before reading related resources. Error layout is
usable on narrow screens and in right-to-left locales. Server authorization
is unchanged.
Release 1.6.132 loads an environment's network policy under that project's
API context, just as the policy-manager lookup and network save already do.
Without the project header, a project member's network list was empty even
though the same token could read and update the network in its project. The
form still follows the returned update capability: readonly members cannot
edit policy. No Server authorization rule is relaxed.
Release 1.6.131 limits account identity-link lookups to the user and admin
rows that the account page actually displays. The account API also returns
project accounts, whose identity-link lookup correctly returns 404; that 404
previously blocked the whole page. The list still surfaces authorization and
backend errors for visible accounts instead of hiding them.
Release 1.6.130 makes direct stack, account-list, and account-security load
failures show translated, actionable messages. A denied identity-link lookup
no longer appears as an empty identity; only a confirmed missing link on an
inactive account is treated as historical data. Account and environment-member
validation errors now use the selected language. These are display and
error-handling changes; API authorization remains enforced by the Server.
Release 1.6.129 adds an Edit link to the environment detail header when the
network policy is editable but project metadata and members are not. The link
opens the existing edit form for that environment; it does not change API
permissions or duplicate the Edit action for project and member editors.
Release 1.6.128 makes the environment edit page follow API capabilities even
when opened directly with ?editing=true. Existing members stay visible, but
adding, changing roles, and removing members require the project's setmembers
action link. Project metadata and network policy controls follow their own
update links. A fully read-only edit page keeps an exit action without offering
a save button. Focused browser-template and component tests cover the separate
capabilities and new-environment creation flow.
Release 1.6.127 makes environment permission failures understandable in the
existing page and form error surfaces. An inaccessible or missing environment
or member list no longer exposes raw API details; a failed member or network
policy update explains that earlier steps may already have saved. Identity
search distinguishes no matching identity, insufficient permission, expired
session, and temporary service failure. Route-level HTTP 401 retains the
existing session recovery path. Pair this release with Engine
0.183.320 and Server v1.6.464 for the tested project-member authorization
boundary.
Release 1.6.126 treats an authenticated account with no active environment
as a valid empty state. It clears stale tab and store scope, skips every
project-scoped request, and avoids a permanent loading error. Account rows use
the authoritative login identity fallback order name, login, then
externalId only when the account name is empty. Descriptions continue to
show only the real account.description; identity names and e-mail addresses
are never substituted. Pair this release with Engine 0.183.319 and Server
v1.6.462.
Release 1.6.125 keeps account administration available when the account
inventory contains an inactive historical row. The page still loads fresh,
account-scoped authentication identities for every readable account, but an
expected AccountNotFound from the identity-link endpoint is isolated to that
single row and falls back to its embedded identity fields. Authorization,
authentication, and server failures other than HTTP 404 still reject the route
and remain diagnosable. Pair this release with Engine 0.183.318 and Server
v1.6.461.
Release 1.6.124 restores direct navigation and refreshes for every
/env/:project_id page after the Ember 7 transition upgrade. The authenticated
parent route now reads the requested environment from the public RouteInfo
tree, rather than the removed legacy transition parameter bag, before it
considers a tab or user default. A permitted non-default environment therefore
remains selected across direct links and reloads, while inaccessible IDs still
fall through the existing server-authorized selection path. Pair this release
with Engine 0.183.317 and Server v1.6.459.
Release 1.6.123 makes environment and workload entry points follow the
effective API schema instead of assuming every signed-in account can create or
update resources. Stack, service, load-balancer, alias, external-service,
virtual-machine, and catalog launch routes reject direct navigation when the
current environment omits the required POST or PUT method; their matching
buttons are hidden from read-only and no-access roles. Catalog refresh and
environment-catalog management additionally require a project management
action. The account administration table now displays description and all
authoritative linked login identities for both local and OpenID Connect
accounts. Pair this release with Engine 0.183.317 and Server v1.6.458, which
place new and returning external users in the shared Default environment while
preserving explicit group or direct roles and existing environments.
Release 1.6.122 restores environment view and edit loading after the Ember 7
compatibility migration. Promise-to-callback adapters now distinguish source
Promise rejection from exceptions raised by downstream async completion, so
one operation can call its callback only once and the original error remains
diagnosable. The project route imports members through the supported
followLink contract before cloning the editable model; the removed
importLink helper can no longer leave the transition pending. Synchronous and
asynchronous failures from projects, members, networks, and policy managers now
reject the route and reach the normal error page instead of leaving the static
loading overlay in place. Focused tests cover resolved, rejected, downstream
callback, concurrent async.auto, every environment-loading dependency, and
the adjacent authenticated initialization path. The shared create/edit mixin
now returns one owned Promise across validation, persistence, dependent saves,
completion, error handling, and cleanup. Duplicate submissions cannot release
another request's saving lock, while synchronous hook, callback, and finalizer
exceptions remain diagnosable. Environment and load-balancer component tests
exercise the same lifecycle used by the browser. Pair this release with
Authentication Service v0.4.41 and Engine 0.183.309 or newer.
Release 1.6.121 closes the expired-session loading loop without changing the
server authentication contract. GET /token may return HTTP 200 with provider
login options when a Cookie is missing, invalid, or expired; the console now
requires an identity-bearing accountId, user, or userIdentity before it
adopts that response as an authenticated session. The unauthenticated object is
normalized to the existing local 401 path, where the origin-level mutex clears
only a still-matching Cookie and generation before routing to the login page.
Passive failures still issue no DELETE, and a delayed result cannot clear a
newer session. Deterministic tests cover simultaneous 401 recovery, single
invalidation, newer-generation protection, masked JWT responses, and the
existing TOTP, Passkey, callback, explicit-logout, and 403 boundaries. Pair this
release with Authentication Service v0.4.41 and Engine 0.183.309 or newer.
Release 1.6.120 completes the cross-tab session boundary under real browser
ordering. Shared cookie and generation reads now occur only after acquiring the
same origin-level mutex used by login commit, so a peer cannot cache a
half-written session. Storage events and BroadcastChannel feed one serialized
reconciliation path; a tab entering the login route also revalidates an already
committed cookie, covering refreshes and events missed during navigation.
Initial-transition 401 handling stays generation-aware, passive failures never
revoke a token, and explicit logout remains generation-bound and coalesced to a
single DELETE. Deterministic delayed-401 coverage runs TOTP and Passkey orderings
100 times, and the production browser smoke validates three-tab adoption,
refresh recovery, API access, WebSocket connectivity, and one explicit logout.
Pair this release with Authentication Service v0.4.39 and Engine 0.183.309
or newer.
Release 1.6.119 closes three persistence regressions found during the
1.6.442 integrated runtime review. External-service API hydration can now
replace the local healthy default, including with null, without assigning to
a getter-only computed property. OIDC site-access updates retain stable error
codes and bound MFA request digests when a rejection object is returned at the
top level. Load-balancer backend selection now follows an explicit child action
to the owning PortRule, so edit and upgrade PUT payloads retain the selected
serviceId. Browser tests cover the real model setter, the strict one-retry MFA
boundary, and the production DOM selector through the submitted API payload.
Pair this release with Authentication Service v0.4.38 and Engine 0.183.304
or newer.
Release 1.6.118 fixes OIDC site-access policy editing without weakening the
provider enablement boundary. Unrestricted mode clears stale authorized
identities before saving; restricted and required entries are normalized and
deduplicated by OIDC principal type and immutable external ID. Access expansion
opens the existing MFA security-confirmation dialog with a purpose and canonical
request digest supplied by the authentication service, retries exactly once,
and never retains the one-time ticket after completion or failure. Stable backend
codes are rendered as localized, actionable errors without exposing raw response
bodies. Pair this release with Authentication Service v0.4.37 and Engine
0.183.303 or newer.
Release 1.6.117 prevents an older same-origin browser tab from revoking or
clearing a session that a newer tab has just established. Explicit user logout
is now the only browser path that requests server-side token revocation. Passive
401, storage, WebSocket, timer, and route failures reconcile against a
non-sensitive session generation; ordinary 403 permission failures remain local
to the failed request. Login, cookie readback, generation commit, session
adoption, and explicit logout share one cross-tab mutex, with a tested
IndexedDB lease fallback when Web Locks is unavailable. OIDC transactions retain
the generation captured before leaving the origin, stale callbacks cannot
overwrite a newer login, and waiting tabs validate the shared cookie before
adopting it. JWTs remain cookie- and memory-only and are never persisted in Web
Storage. A precise 409 ClientSessionSuperseded response from the Engine is
treated as a stale completion rather than a failed active login, and request
options cannot override the provider, authorization value, or captured
generation. Pair this release with Engine 0.183.302 or newer for
session-bound, ordered, idempotent server logout protection.
Release 1.6.116 recognizes the MFA API's structured error code even when
the transport wraps it in a generic error. Sensitive settings updates open
the security-confirmation dialog and retry only after successful confirmation;
cancellation never resubmits the update. Unexpected API failures retain a
localized explanation with bounded HTTP status/code diagnostics, without
displaying raw response bodies. Use Engine 0.183.298 or newer for the
matching live v2-beta MFA settings and confirmation schema repair.
Release 1.6.115 closes the global resource-action menu before dispatching
the selected action. This prevents the row menu from remaining above account
edit and other modal forms, while preserving the selected resource and action
receiver. The same shared fix covers every resource table which uses this
menu; focused tests verify that the menu, trigger state, and anchor are closed
before the modal action executes.
Release 1.6.114 fixes the exact post-create exception captured during a real
ranchernode22 service creation. The live global service collection can contain
a transient empty slot while the API store merges a newly created resource; the
page-header observer now ignores only those unreadable entries before examining
application-service metadata. The same guard covers both observer and navigation
tree rebuild paths. Completion no longer performs the unrelated service reload
introduced by the two superseded diagnostic releases, while the saved payload,
route callback, hardware controls, and other page regions remain unchanged.
Release 1.6.113 force-loaded the saved service by API ID while diagnosing the
post-create failure. Instrumented browser evidence later located the exception
in the page-header observer before completion navigation, so the extra request
is removed in 1.6.114; 1.6.113 remains a diagnostic boundary.
Release 1.6.112 introduced the first-create refresh boundary found by the
formal ranchernode22 acceptance test. The API could return a deliberately
sparse service while that same record was already visible to the destination
stack, causing its computed fields to render before the launch configuration
was hydrated. The shared create/upgrade form now refreshes the persisted
service before navigation and treats an optional refresh failure as
non-authoritative because the save itself has already succeeded. Focused tests
cover the intended refresh ordering, fallback behaviour, receiver binding, and
unchanged hardware payloads. Real-host acceptance later proved Resource reload
could not hydrate a response without a self link; 1.6.112 is retained as that
diagnostic boundary. The Traditional Chinese capability label now describes
mknod as creating a device node instead of presenting a misleading phonetic
transliteration.
Release 1.6.111 fixes the post-save callback receiver boundary found by creating a real
service on a managed host. The API and node correctly created the service, but
the legacy component action target could lose its controller receiver before
navigation. All four container and virtual-machine create routes now pass
receiver-bound completion and cancellation callbacks to the shared form. The
resource and hardware payload is unchanged. Real-host acceptance subsequently
found a separate sparse-response render race; 1.6.111 is retained as that
diagnostic boundary rather than the current compatibility target.
Release 1.6.110 restores the classic (action (mut ...)) contract used by
command and environment editors, and accepts the modern array-like browser
clipboard type list used by key/value inputs. This closes the two client-side
exceptions found while filling the complete hardware/runtime form on a real
host; it retains the INIT spacing and completion fixes from 1.6.109.
Release 1.6.109 corrects the create and upgrade completion contract exposed by
real-host acceptance testing. Top-level create routes now pass classic named
actions to the shared form so Ember dispatch preserves the controller receiver;
the compatibility layer also refuses to forward a component prototype callback
as an action name. This prevents a successfully persisted service from leaving
the form open with undefined.get or a template-action error. A regression test
exercises the controller transition, and the init-process control has additional
desktop separation from the adjacent process-limit input without changing its
payload binding.
Release 1.6.108 attempted to close the first-create completion failure with a
closure callback. Real-host acceptance testing subsequently showed that the
legacy action compatibility path could still misroute the callback after the
service was already persisted. It is retained as a superseded diagnostic step,
not as the current compatibility target.
Release 1.6.107 removed saved-response dereferences from route selection, but
real-host acceptance testing showed that the deprecated callback dispatch still
failed after persistence. It is retained only as a superseded diagnostic step,
not as the current compatibility target.
Release 1.6.106 fixes the real first-service creation completion path. An
empty service-link set no longer sends a redundant action after the service is
already persisted, and a non-empty link update preserves the stack route
identity even if the API returns a partial resource. The route also keeps its
original stack ID independently of the mutable service response. A successful
first click therefore leaves the form instead of showing an error that could
invite a duplicate service submission.
Release 1.6.105 fixes the post-save transition for a newly created service:
the persisted service now remains in the completion chain instead of being
discarded by the service-link action. Stack-scoped create routes also fall back
to their stable stack query parameter, and advanced key/value inputs render
localized placeholders. The create and upgrade resource payloads remain
unchanged.
Release 1.6.104 keeps the authenticated browser-session and OIDC corrections
from 1.6.103. It also keeps the init-process checkbox inside its own resource
grid column, with the launch-configuration binding unchanged, so the control no
longer touches the adjacent process-limit input on create or upgrade forms.
Release 1.6.103 keeps an authenticated browser session when a non-auth API
request fails during startup, displays the nested OIDC/API explanation instead
of an empty alert, and activates a newly verified provider in unrestricted mode
so every identity accepted by that provider can sign in. Administrators can
still narrow access afterward with the existing site-access controls.
The language picker includes English, German, Persian, Filipino, French, Hungarian, Japanese, Korean, Brazilian Portuguese, Russian, Ukrainian, Simplified Chinese, and Traditional Chinese for Taiwan. Every selectable locale must satisfy the complete message contract and regional formatting gates documented in Localization. New security-sensitive authentication text is maintained in English and Traditional Chinese first; other locales inherit the complete English text until a reviewed translation is available, rather than displaying missing translation keys.
The manually dispatched validation workflow tests and builds the exact selected commit on a GitHub-hosted runner and retains the reviewed candidate for 30 days. Release publication remains a separate reviewed step.
npm ci --ignore-scripts
npm run build -- --environment=production
npm test
package_version=$(node -p 'require("./package.json").version')
bash scripts/package-static-candidate \
"$package_version" dist "build/ui/${package_version}.tar.gz"The packaging command uses the current Git commit timestamp by default, or an
explicit SOURCE_DATE_EPOCH, and emits a deterministic tarball plus a portable
SHA-256 file. It creates a candidate only; publishing remains a separate,
reviewed release step. The archive root and VERSION.txt must equal the
numeric package version; a preserved compatibility version must not be
silently substituted into a new release artifact.
Catalog cards and launch pages read optional
io.pasturestack.catalog.name.<locale> and
io.pasturestack.catalog.description.<locale> labels. Unknown locales and
third-party catalogs fall back to their canonical metadata instead of showing
an empty string or an untranslated key.
Container terminals, container logs, and virtual machine consoles use the movable window system documented in Console workspace. Terminal and log sessions can be reopened after a tab refresh or browser restart, and active output is shared across signed-in tabs without persisting upstream access tokens.
Host storage pages provide checkbox selection, state filtering, search, pagination, and one operator-confirmed removal action. Selection rules, preview behavior, and the concurrency limit are documented in operator-selected storage removal.
Linux shared memory, runtimes, GPU/graphics devices and advanced container limits use the shared Resources and hardware form. The guide covers coordinated agent/API rollout and the distinction between device visibility and exclusive GPU allocation.
OpenID Connect configuration, stable account-to-identity assignment, safe provider switching, and local recovery are documented in OpenID Connect. TOTP, passkeys, recovery codes, email account recovery, and administrator controls are documented in Multi-factor authentication.
The repository includes explicit modernization gates because its historical frontend toolchain cannot be trusted without review. See COMPATIBILITY.md, SECURITY.md, and ORIGIN.md.
The inherited project remains licensed under Apache License 2.0, with additional attribution in COPYRIGHT_DETAILS.md. Bundled dependencies retain their own licenses and notices. PastureStack contributors claim authorship only for their own changes.