Skip to content
 
 

Latest commit

 

History

3,065 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

PastureStack Web Console

Web Console provides the browser interface for compatible environments, hosts, stacks, services, containers, catalogs, storage, networking, access control, and administration.

PastureStack is an independent community effort to preserve, audit, and modernize the Rancher 1.6 ecosystem. It is not affiliated with or endorsed by Rancher Labs or SUSE.

Upstream: rancher/ui, preserved from its 1.6-dev line. This GitHub fork retains upstream history, authorship, dates, tags, licenses, and dependency notices. PastureStack maintenance is consolidated into one commit after the preserved upstream boundary.

Project status

Published 1.6.178 repairs viewing and editing an inactive environment by skipping only the network and policy-manager reads that the API correctly denies for that state. Global project/member capabilities and other authorization errors are unchanged; the form explains network unavailability in all thirteen packaged locales. Formal CI passed 848/848 tests, and both reproducible archives match the immutable public download; Server v1.6.516 packages this exact component. Server publication, artifact readback and separate isolated QA deployment passed; first start/restart each reached HTTP 200/pong after ten bounded probe attempts, with runtime settings and five core-table counts unchanged. Docker health is null, not healthy; no company-site deployment is claimed. In one inactive environment, native detail/reload, write-free edit/remove cancellation and native deletion/list absence were observed, but the parent cleanup timeout remains HOLD. A separate read-only database observation confirmed the environment and four networks were purged, with no remaining members or dependent resources. Fresh API and complete foreign-data preservation verification remain incomplete. This is not full native lifecycle PASS; the full matrix is INCOMPLETE and earlier HOLDs remain. See the release note.

Published 1.6.177 prevents ended log and terminal workspace entries from reconnecting after remount/reload or from late access-ticket, broker, socket and timer callbacks. Both components share one lifecycle boundary; asynchronous work remains bound to its original entry. Explicitly opening a new entry and reconnecting a live entry remain supported. Seventeen targeted real-component tests passed within formal exact-source CI 37255121243: 841 tests passed with zero failures/todo, and both production archives are byte-identical. Numeric lightweight tag 1.6.177 binds signed source commit b9b841e65afe1d89a5b03ac767e9168bccd3c3ea; it is not a signed tag. Normal PR #175 squash merge 5d150806be20226657e5caa8a0150d068006c772 has the same reviewed tree 109a60fc005d9dc18e38864089dd0055980485c3 and a verified signature. Anonymous public archive readback matched SHA256 4e34eb2b3165f078134cddcf1721239b3da7baf11dd683991b2d6aa5bae944e0 (2,982,494 bytes). Published Server 515 packages this exact component: source f0267ff3a347ea526088db1749b1d3c8dfd9bd37, manifest sha256:fcc79f616927040ef2b3a5c58662fa948823220dbc57ffe275dee2ad88764d47. Its official publisher and independent artifact/runtime/security readback passed. Separate isolated Server 515 / Web 177 deployment and independent readback passed: initial-start and restart polling reached HTTP 200/pong after 10 and 11 attempts, respectively. Runtime configuration, environment overrides, three named volumes and five core-table counts were preserved, with docker-default, unless-stopped, database backup and 514 rollback retained. There is no Docker Healthcheck; running/pong is not Docker healthy. Isolated native browser lifecycle acceptance remains pending; the full matrix remains INCOMPLETE. A separate fresh Project v2 native run remains HOLD after a successful deactivate response and a UI wait timeout; native removal and database cleanup are incomplete. Historical HOLDs are unchanged, and this is not production acceptance. See the release note.

Published 1.6.176 repairs native select bindings that passed a mut reference directly to the classic compatibility action helper. The helper receives the current value instead of a setter; wrap mut in native fn to retain the setter while preserving the existing event value mapping. This covers the same 21 select bindings in 11 templates, including project roles, schema fields, balancer rules, settings and machine-driver fields. Project member capabilities, identities, metadata/network write boundaries, save finalizers and authentication remain unchanged. Exact-source CI37175725533 passed 824/824 tests with zero failures, skips or todo, including 32 targeted cases (29 retained and three new native-mut regressions). The signed immutable numeric release pins source a1bbf172aad8443bfbb1859760d62669d6705189 and tree dfa280c29e241bb815eff852e8a188c101e338eb. Both reproducible CI archives and anonymous public downloads match SHA256 071ce0b7091b323e0d84fe91269684f59fcf2e29000bd8ff94428e8dd03ece52 (2,982,158 bytes). Thirteen packaged locales and the source gates passed; affected build-package modules are absent from the static artifact inventory, not a runtime not-affected or zero-CVE claim. The build audit remains 7 High / 3 Moderate, with the existing reviewed GHSA-vfj7-8cjw-p6xm vendor-pending boundary through 2026-10-10. The published Server v1.6.514 includes this component and Catalog Service 0.20.12; its official packaging, startup and restart checks passed. Isolated deployed UI checks also passed for the Traditional Chinese and English container/VM forms and INIT layout. These form checks do not establish VM boot, GPU runtime or every locale. Separate isolated tests verified network service editing and cleanup, and completion and cleanup of an existing catalog upgrade. Readonly and target-environment no-access container denials were verified separately. Owner start/restart, logs, terminal and deletion returned their expected native responses in separate runs; logs and terminal had actual WebSocket output and normal termination, and the delete confirmation closed normally. Independent read-only queries found the container and its six associated records terminal (removed or purged). This cleanup observation is not full historical data-protection or lifecycle PASS. Environment deactivate/reactivate/remove screens were observed in separate stages and test-data cleanup was independently confirmed; this is not complete historical data-protection acceptance. Earlier incomplete results are not promoted. The full matrix remains INCOMPLETE. See the release note.

Published 1.6.175 keeps the container/VM form's image validation message in sync when the operator corrects the image or changes the locale. Only the form's own validation aggregate is refreshed: model/command errors and later backend save errors remain intact. The shared save lifecycle, lock ownership, payloads, permissions and authentication are unchanged. Exact-source CI37163340764 passed 821/821 tests, including four new real-component regressions, with zero failures, skips or todo. The signed immutable numeric release pins source bb905d092700c262497b88f5773e7714fc1f4be4. Both reproducible builds and anonymous public downloads match archive SHA256 9833467b2be47d4fa01f09954fcd35beb292c59d382d5c1aecd76d17c6a387a2 (2,982,158 bytes). Server packaging and deployed UI acceptance remain pending; the full matrix remains INCOMPLETE. See the release note.

Published 1.6.174 removes the ordinary-container default and quick picks from the VM image field. Custom images, existing image values and the last-used VM image remain supported; ordinary container defaults are unchanged. A blank image still blocks the existing save lifecycle. VM boot-image guidance and required errors for both VM and container images use reviewed English and Traditional Chinese copy with the existing English fallback. Dependency versions and the dependency graph are unchanged. Exact-source CI37152802665 passed 817/817 tests with zero failures, skips or todo. The signed numeric release pins source d24b7f4e164f058e3ef9057347caa2080e2b5407; both reproducible CI archives and anonymous public readback match SHA256 6408775898f412e4b27092eeddd9cdc2028ad7b27835f489139c2d0cf62c6776 (2,982,022 bytes). Server v1.6.512 packages this exact component. QA125/8080 fresh VM/container image forms passed eight scoped English/Traditional Chinese cases with zero resource writes. This is not a successful VM boot or full permission/resource/locale acceptance; the discovered stale parent image error is addressed by the published 1.6.175 component above, not yet deployed. Historical releases and HOLDs are unchanged; the full matrix remains INCOMPLETE. See the published release note.

Published 1.6.173 repairs empty environment-template choice labels. These choices are native ProjectTemplate resources, not Catalog templates: their authoritative label is name, and selection remains bound to the template ID. Four focused regressions cover the actual model, rendered choices, renaming and selection. Exact-source official validation 37115288389 passed 812/812 tests with zero failures, skips or todo and two byte-identical production archives. The signed immutable numeric release pins source c8b8bb2659fdad3539cf6a72866c94a77ec516b6; anonymous public archive and checksum downloads match SHA256 a566684e6e0831630a15cb7212989c0e9fe707ed07965156c2b664b9cdb5ba27 (2,982,104 bytes). Publication reused the formal CI artifact without rebuilding. Server v1.6.511 officially packages Engine333 and this exact component; its isolated artifact and public readback gates passed. QA125/8080 upgrade and independent read-only checks passed with first-start11/restart10 HTTP200/pong and unchanged runtime/DB counts; this image has no Healthcheck, so Docker healthy is not claimed. The version-bound native read-only proof for existing Template117 passed with 3 Full17/14 guards, zero resource writes and source-bound same-ID empty stacks/services verification; it is not a native-create finalizer. Process native list/link/detail and same-ID direct GET passed for one current ID: two API roots × six roles, 12/12 cells and zero resource writes. Other IDs and write methods remain untested. Fresh Project key 1c6998 is independently verified as DERIVED_SCOPED_KEY511_VERIFIED_NOT_ORIGINAL_PASS: the same actual child run has 4 native writes, 13 guards, 6 cookie-free issued Basic GETs before deactivate/delete, 4 barriers and 18 first-delivery checks. Its original parent QA-receipt identity-schema HOLD is retained; the read-only derived check did not rewrite receipts or replay writes. See the release note for evidence and limits. Native Project/Host acceptance remains independently pending; publication or this key scoped result does not promote historical HOLDs or establish those outcomes. The complete permission/resource/locale matrix remains INCOMPLETE. See the release note.

Published 1.6.172 preserves API-key create-only first delivery when a redacted subscribe model arrives before POST/201. Only the API-key editor opts into a request-private, Schema-bound delivery to its detached clone; newer canonical state and nested resources remain intact, and the canonical Store does not need to retain the secret. Compatibility revision 6 replaces revision 5 without changing dependency versions or the graph. Exact-source official validation 37109872791 passed 808/808 tests with zero failures, skips or todo, including fourteen installed-Store ordering cases and two save-owner cases. Personal and project stores each exercise 100 deterministic barriers. Two production builds are byte-identical. The signed immutable numeric release pins source daab6e8ed5206562feb60e6549a3b9e72b4c8381; archive SHA-256 is 9a21c5e6ff9fbb274dbc7c45ec1ccffdbff33a945544b64d5976b14ee9752bfa (2,981,642 bytes). Anonymous public archive and checksum downloads match the same formal CI artifact; publication did not rebuild it. Server v1.6.510 officially packages Engine333 and this exact component. Separate QA deployment and fresh-key native first-delivery acceptance remain pending. Historical HOLDs remain HOLD; the complete permission/resource/locale matrix is INCOMPLETE. See the release note.

Published 1.6.171 repairs a shared Store ordering defect: a delayed initial create response could overwrite a newer subscribe model and leave a successfully created local Volume stuck in its initial state. Only ID-less create POST/201 uses an existing exact-ID, concrete-type canonical model in the same Store, generation and API base. Ordinary reads, updates, actions and backend permissions keep their existing contracts. API-store compatibility revision 5 replaces revision 4 without changing the dependency graph; earlier archives are retained. Focused Chrome validation passed 36/36 tests, including ten new regressions and 100 deterministic subscribe-before-201 barrier iterations, with no failures, skips or todo. Exact-source official validation 37094728912 passed 802/802 tests with zero failures, skips or todo, including the ten new create-order cases; all 22 audit-gate selftests passed. Two production archives are byte-identical. The signed immutable numeric release pins source fc37f5af9320e492bec7e7244cd62144908b720e; archive SHA-256 is 49fac41ca93eb628d0877104f9512ef382ffd9dbc89e04c940196b3a9c57798b (2,981,230 bytes). Anonymous public downloads match the formal artifact. Server508 packaging and native fresh-volume create/cancel/refresh/denial/removal acceptance remain separate pending gates. Historical HOLDs are not promoted; the complete permission / resource / locale matrix remains INCOMPLETE. See the release note.

The first exact-source official run stopped before tests on newly reviewed GHSA-vfj7-8cjw-p6xm in build-only [email protected]; upstream has no patched release. It remains a High vendor-pending finding, not a zero-vulnerability claim. The live audit preserves the High threshold and rejects unexpected advisories, dependency drift, non-development exposure and expired reviews. Only the exact reviewed advisory's dependency closure may remain pending until 2026-10-10. No third-party runtime patch or toolchain downgrade is applied. See the bounded risk record.

Published 1.6.170 corrects an optional mounts: null projection being mistaken for a real allocation in the shared local-volume list. It preserves the complete advertised pool relationship, full scoped mount cache, exact-volume binding checks and backend permissions. Raw IDs and malformed values do not become empty evidence. Exact-source official validation 37082272427 passed 792/792 tests with zero failures, skips or todo and two byte-identical production archives. The signed immutable numeric release pins source 09df1480c5f4b58c6a9a9060ff94d980792f7015; archive SHA-256 is 900974b07bb20ba5b2e7c1dede7012a53c6e2c96cd094c67cb7019434c4f27c9 (2,981,065 bytes). Anonymous public downloads match the formal artifact. Packaged Server507 acceptance passed the existing-volume Store/list/refresh, write-free delete cancellation, exact-ID readonly denial through both API roots, and native owner removal for two isolated volumes. Restricted, readonly and no-access Host Add entry denials passed separately in Traditional Chinese and English. Fresh volume creation remains under investigation; historical HOLDs and the complete matrix are not promoted. See the release note.

Published 1.6.169 corrects the shared unallocated-local-volume classifier. The engine may generate externalId from a volume's name; that identifier does not allocate the volume to a host, workload or storage pool. Classification still requires explicit local/non-native fields, no host/image/instance binding, the complete advertised storage-pool relationship and the full scoped mount cache. Identifier changes invalidate stale relationship proof. No API permission, authentication or lifecycle request is changed. Exact-source official validation 37078265265 passed 791/791 tests with zero failures, skips or todo, including three identifier/allocation-proof regressions, and produced two byte-identical production archives. The signed immutable numeric release pins source 5962f57fccb4062a65b5921646c06b4663713b9b; archive SHA-256 is e2bcb97b0da810f2ff216f9738739235e3c6f29ef46f1d99b623cf9c9f7258e2 (2,981,057 bytes). Anonymous public downloads match the formal artifact. Server v1.6.506 is now published and deployed on the QA 8080 host, with initial and restart HTTP 200 checks and preserved configuration/volumes. The packaged native existing-volume terminal found the null-projection defect above; fresh create/cancel/refresh/readonly-denial/remove acceptance remain pending. Historical HOLDs are not promoted; the complete permission/resource/locale matrix remains INCOMPLETE. See the release note.

Published 1.6.168 makes the Volume Add control and direct create route use the current environment's actual schema capability. The shared create/upgrade route guard rejects missing or stale environment schemas; upgrades still require PUT rather than POST. Existing localized permission notices and backend authorization remain unchanged. Nine directly affected Chrome regression tests passed with no failures or skips. The release also adds an independent local Volume entry and an unallocated local-volume list. Classification requires the actual complete storage-pool relationship and full environment-scoped mount cache, including inactive workloads; missing data does not mean unused. The native advertised deactivate action is offered only for a proven unallocated volume in the current environment, before the existing remove workflow. Relation failures retain the original route/growl error instead of silently inventing an empty result. Exact-source official validation 37061716638 passed 788/788 tests, with zero failures, skips or todo, including sixteen new scoped Volume cases, and produced two byte-identical production archives. The signed immutable numeric release pins source 2120e0416fd4a0efb5d351f9da4ec632ac8eacdc; archive SHA-256 is fdd1d33d47b032eef8b5b6d5dbb1401110daf860d84a6c17003577463d3d2cb5 (2,981,125 bytes). Anonymous downloads match the formal artifact. Server v1.6.504 packages this component and passed QA first start/restart with unchanged runtime settings and database counts. Native Volume lifecycle acceptance remains pending: the first run stopped before resource writes on a v1/v2 schema assumption in the acceptance tool. That HOLD is preserved. Publication and deployment are not complete permission-matrix PASS. See the release note.

Published 1.6.167 fixes mixed-case schema-ID lookup in the shared API store. Schema keys use the same normalization as the existing cache producer; ordinary resource IDs remain case-sensitive. Inherited resource getters and capability checks read the actual project store's schema, without fallback permissions or changes to API names, authorization or lifecycle requests. Compatibility archive revision 4 replaces revision 3; earlier archives remain unchanged. Four new actual Store/schema regression cases and the local Chrome 4-test/43-assertion run passed. Exact-source official validation 37012345421 passed 772/772 tests, zero failures, skips or todo, and produced two byte-identical production archives. The signed immutable numeric release pins source dff35fc4bce340e21cac7204146a7bcb20a7b60b; archive SHA-256 is e8e714fc06282de75a3570aac1d4d4d04a3c9478d982d0d5aaeae14efa8ebbaf (2,976,297 bytes). Anonymous public downloads match the formal artifact. The artifact is separately packaged and QA-deployed in Server503. Its first start and one restart returned HTTP 200/pong after nine attempts each, with unchanged runtime settings and five-table count baselines. Docker health is null, not a healthy result. Packaged QA confirmed the actual GET-only registry/credential models for the readonly role and readable permission errors for readonly/no-access roles; their 24 normal-CSRF v1/v2-beta write denials passed. This exact-fixture coverage is not all API authorization or full native lifecycle/locale acceptance. The complete permission/resource/locale matrix remains INCOMPLETE. See the release note.

Published 1.6.166 completes the shared state-badge display translation for Inactive. The thirteen supported language files gain that display label; icons, colors, API states and health/connection overrides are unchanged. Eight focused Chrome rendering tests passed all 34 assertions, including switching the actual thirteen language catalogs and retaining unknown-state and override behavior. Exact-source official validation 36998466706 passed 768/768 tests, zero failures, skips or todo, and produced two byte-identical archives. The signed immutable numeric release pins source b63fa15f6726cb78659ae43258dfc802b30d6d04; archive SHA-256 is 9205fbaec6e80f31846212f0949c3eac0fae083f80c6c46a3122d64c4d9da6c6. Anonymous public downloads match the reviewed artifact's hash and size; publication reused it without rebuilding. This component publication does not establish Server packaging/deployment, packaged native-browser or complete permission/resource/locale-matrix acceptance. See the release note.

Published 1.6.165 fixes ambiguous container names on Host cards. Long names now wrap within the existing card instead of hiding distinguishing rollback suffixes. IP addresses and action triggers retain their own space. The change is scoped to the shared container/VM subpod; global clipped labels, Host titles, names, IDs, API requests and authorization remain unchanged. Compiled-CSS regressions passed four Chrome cases and 744 assertions across light/dark, LTR/RTL and desktop/narrow viewports. Exact-source validation 36979009940 passed 767/767 tests, zero failures or skips, and produced two byte-identical production archives. The signed immutable numeric release pins source 00bcd9fdc92afead708dffb4a2b3b01f4ebaeaa0; archive SHA-256 is 5baaa4879fe5548cc8b66cd1c7a2005edf586d4b5f12b6dbb3796b6692e41959. Anonymous public downloads match the reviewed artifact's hash and size; publication did not rebuild it. Packaged Server501 native initial/reload matched six exact Docker IDs and complete names, including all five readable rollback suffixes. Root reviewed both actual screenshots; IP/action separation and native menu open/close passed, with zero resource writes or page/console/loading errors. WebSocket connected and a real server message was observed. These scoped checks do not promote earlier receipts or the complete permission/resource/locale matrix to PASS; that matrix remains INCOMPLETE. See the release note.

Published release 1.6.164 reuses visible Receiver form labels for shared required-field and numeric validation errors. The three supported driver configurations retain their own label scopes; model-specific translations still take precedence and unknown fields keep their existing fallback. The scale models' existing minimum-greater-than-maximum checks use the existing localized numeric error. No validation rule, API, schema, permission or driver behavior is changed. Focused Chrome 153 source validation passed 12/12 tests with 61/61 assertions (eight new Receiver cases and four adjacent existing cases). Official validation 36831735186 passed 763/763 actual tests, including those cases and the twelve retained Web163 locale cases, with two byte-identical production archives. The signed immutable numeric release pins source c3c0779d930d4d0367ec0517166ca21f6b3dc6d4; its archive SHA-256 is 734898ac6ed2fe8774e5bb947988da9720a3a65aa0bb7ec09a89420adc0acc20. Anonymous public downloads match the reviewed candidate's hash and size; the existing candidate was published without rebuilding. This does not establish Server packaging, QA or production deployment, native packaged-browser, complete-language or complete-matrix acceptance. The initial fixture failure, published 1.6.163 and historical HOLDs remain unchanged. See the release note.

Published release 1.6.163 contains two shared display-locale fixes. Relative dates recompute when the selected language changes and use a Moment instance locale, without changing the global locale during formatting. State badges translate seven known display labels through existing translations; unknown labels and model health/connection overrides such as Disconnected remain unchanged. Icons, colors, model state and API behavior are preserved. Focused native Chrome 153 source validation passed 12/12 tests: seven rendering checks, three relative-date/helper checks and two existing user-language checks. Official validation 36827428183 passed 755/755 tests, including those 12 locale cases, and produced two byte-identical production archives. The immutable numeric release pins source 5db737a5e04c4cc15672f97296d5bf521ab9a8da. Its archive SHA-256 is 54ef4e0726c6564abfb0b16727e991ef8a2258d9655cd1e603f43d6a557f8d27; public downloads match the reviewed candidate's hash and size. Component publication does not declare Server packaging, deployment or packaged browser acceptance. This is not full-language or resource/role matrix acceptance; earlier HOLD evidence remains HOLD. See the release note.

Published release 1.6.162 contains two narrow desktop fixes. The Secrets table headers use the existing generic translations while retaining their sorting, search and QA mapping fields. Host details show Add Container only when the current environment's loaded container schema permits creation; schema reloads and environment changes cannot reuse stale create access. Container-list and Host-card capability checks and the direct Add route remain unchanged. The permission gate uses schema capabilities, not role-name checks. Focused source validation passed Secrets 2/2 and Host 8/8 tests (four new Host cases plus four adjacent existing cases), plus two desktop rendering checks. Official CI passed 746/746 tests and produced two byte-identical archives. At component publication, Server packaging remained v1.6.495 / Web Console 1.6.161; packaged browser acceptance of 1.6.162 was still pending. Responsive/mobile Secrets labels and all-language layout acceptance are not claimed. Earlier HOLD evidence remains HOLD and the broader resource/role matrix remains INCOMPLETE. See the release note.

The numeric release 1.6.162 pins source 46501e31071b3d74595aea91908876eec32b7fd6. Its archive SHA-256 is 9c5b34d2cdf7ad354e1dab199795b12e5de119e47dc342547d5cdc84c7911581. See official run 36810596087. Component publication does not establish packaged browser or backend-write acceptance.

Published release 1.6.161 fixes existing Certificate metadata edits blocked by the masked private key. Name/description-only edits omit certificate material from the PUT body; new certificates and material replacements keep full validation. The editor explains this distinction in all supported locales. Focused real-model and rendered three-language UI tests passed 25/25; the full official CI passed 738/738. Packaged owner/member Certificate browser checks passed on isolated Server v1.6.495: Cancel, metadata Save, refresh and the in-use delete explanation. Earlier HOLD receipts remain HOLD, and the broader resource/role matrix remains INCOMPLETE. See the release note.

The numeric release 1.6.161 pins source 2ad068d62b5afd3cd213cde8addc5ebbef738130. Its archive SHA-256 is fa3ec0bf5173fa75a53dd621b87e1f587b20d9ecc6e5cb42a703ac4f5f7e97e7. Official run 36738408143 produced two byte-identical archives. Component publication is not completion of the broader resource/role matrix.

The console retains the existing Node 24, Ember, Sass, dependency, browser-smoke, terminal, console, and test-harness modernization. It adds a provider-neutral OpenID Connect administration and sign-in flow with PKCE S256, staged configuration validation, a real test login before activation, and local-authentication recovery. Product-owned names, logos, icons, package metadata, and visible text use PastureStack branding. API models and protocol fields remain compatible.

Release 1.6.160 adds a clear, localized explanation when the API rejects deleting a certificate still referenced by a load balancer. It tells the user to remove those references first, without exposing service names. Denied or missing resources and unrelated action failures retain neutral messages; authorization, delete behavior, session and MFA contracts do not change. See the release note.

The official numeric release 1.6.160 is published from source commit 63964fa3a6da5cbd452cdc1061c1e18340055362. The web-console-1.6.160.tar.gz archive has SHA-256 705946b96e693c55a8ab5de3bc96b14020a52a050bf3992c302b9fb3c1408a51. Official validation run 36702030007 passed 725/725 tests and produced two byte-identical archives. The published asset's hash was independently read back and matched. Server artifact and isolated browser acceptance remain pending; this component publication does not complete the resource/role matrix.

Release 1.6.159 preserves an existing Registry credential's password when the editor changes only its username or leaves the password input blank. The editor submits a password only when a new nonempty value is entered, preserving its literal whitespace. It retains the exact-resource, parent-registry, project and current update-capability checks. This is a browser payload fix; Server authorization and Registry credential creation are unchanged. See the release note.

The official numeric release 1.6.159 is published from source commit aab95cf41ebc45e4c51513d9589602ab990399c9. The web-console-1.6.159.tar.gz archive has SHA-256 f014083480e10430701e3a08588cf617242188938d9f935fbaac42a3b5feeb90. Official validation run 36686121660 passed all 723 tests (723/723) and verified deterministic packaging. The earlier 7/7 result covered only the focused Registry editor tests. Published Server v1.6.493 packages this archive at immutable image digest sha256:61067362a2d91b791c7e80cb2ec4a5a907bc03884774d2019dccf1bf0e29788f.

Scoped Registry acceptance on isolated QA 8080 passed 24 GET checks across six roles and both API roots, eight no-access PUT/DELETE denials with HTTP 403, two API password replacements, and one owner browser username-only save that omitted secretValue. Eight readonly write cases returned HTTP 405 because the schema omits those methods; they remain N/A, not authorization passes. Cancel, refresh, credential and parent Registry identity preservation passed. The password hint and controls fit in English, Traditional Chinese and Japanese at 1440px and 390px. Both disposable fixture resources reached their terminal cleanup states. Other workflows and the broader role/resource matrix still require acceptance.

The same release also pins official compatible High-severity security fixes for the build and test graph: brace-expansion 1.1.21 / 2.1.7 / 5.0.12 on their existing major lines, and engine.io 6.6.10. The reviewed lock baseline and dependency gates cover these pins; the live npm audit --audit-level=high gate remains unchanged. This does not claim that remaining Moderate advisories are fixed.

Release 1.6.158 gives Service direct-ID and Secrets-list load failures the same localized, resource-safe handling already used for Stack loads. It also gives HTTP 405 save and action failures the existing translated unavailable messages. Focused source tests cover English, Traditional Chinese, and Japanese. The official archive is published with SHA-256 286833d3313c5bc04469a8fafd41bab7de1c4b60527f91aae9eef8a4016b17f6; Server packaging and live browser acceptance remain separate. See the release note.

Release 1.6.157 mounts authenticated-page notices when their component enters the DOM. This covers the fresh direct-URL denial missed by 1.6.156's route render callback while keeping login/MFA notices on the body. The focused source tests pass, and the official archive is packaged in Server v1.6.491. Isolated 8080 QA on that image passed 14 scoped Stack and Service direct-create notice cases with zero resource writes. This does not establish the broader role and resource matrix or a formal company-site deployment. See the release note.

Release 1.6.156 introduced the in-flow authenticated notice layout, but Server v1.6.490 QA found that a fresh readonly direct create URL still left the notice fixed on the body and overlapping header actions. An in-app transition did mount it correctly. See the 1.6.156 release note.

Release 1.6.155 moved global notices below the navigation bar and bounded their width. QA 8080 browser acceptance subsequently found that the fixed notice still covered the mobile page title and desktop header actions. It is not the accepted layout; see the 1.6.155 release note.

Release 1.6.154 shows a localized, persistent permission error when a direct Stack or Service creation URL is denied, then returns to the Stacks list. Service upgrade URLs continue to use update permission and receive an update error only when that permission is absent. The shared message covers all resource types using the route guard. See the release note for source test evidence. It was packaged in Server v1.6.488; its 8080 browser acceptance identified the notification/navbar overlap addressed by 1.6.155.

Release 1.6.153 makes Stack, Service, and Container write controls check their current project/resource capability when the user acts; delayed project upgrades and service scaling cannot carry a click into a different selected project. It improves Registry edit recovery, localized errors and Japanese form labels, and shows an unavailable state when host/container monitoring cannot connect instead of leaving a spinner. These are browser-console changes, not a substitute for Server-side per-resource authorization. See the release note for test evidence and the remaining 8080 acceptance boundary.

Release 1.6.152 uses each Stack, Service, and Container form's visible, translated name label in its required-field error. This closes the Chinese/Japanese Stack mismatch observed on isolated Server v1.6.485 QA; it does not change request payloads, server authorization, or other fields. See the release note. Source tests alone do not establish acceptance of a packaged Server image.

Release 1.6.151 restores Secret Edit when the current resource schema allows PUT and the active Secret has a self link. Secret Remove still follows the API's explicit remove action. This matches the API's existing Secret write contract without granting Edit to read-only users or changing Secret payloads. See the release note. Source tests and the earlier API-only QA do not by themselves establish browser acceptance of a newly packaged Server image.

Release 1.6.150 limits Certificate Edit and existing RegistryCredential Edit to the fields shown in their forms. Their PUT requests no longer resubmit cloned server-owned IDs, state, timestamps, or unrelated model metadata. RegistryCredential creation after a missing credential retains its existing readback and uncertain-write safeguards. See the release note; source tests do not by themselves establish browser or API acceptance.

The 1.6.149 source change makes Registry creation recoverable when its separate credential request fails: it never automatically deletes a registry or blindly repeats an uncertain credential write. New Registry, Certificate, and Secret records are refreshed by ID so their action links are available after creation; Certificate Edit also rejects encrypted private keys. See the source release note. Browser acceptance and publication are separate steps.

Release 1.6.148 makes Secret Edit follow the current Secret schema: the name is shown read-only with an explanation, and Save sends only the editable description. A successful Save updates the listed Secret; a rejected Save leaves the form open. Secret Add continues to accept a name and value. This builds on the 1.6.147 Service Edit fix without changing the Server API. See the release note.

Release 1.6.147 limits Service Edit to the editable name, description, and scale fields so saving does not resubmit cloned launch configuration or upgrade strategy. The scale form preserves an initial value of zero and applies quick scale selections during editing; quick scale writes submit only the scale field. See the release note for the change scope and validation boundary.

Release 1.6.146 makes required-field errors use the visible translated form labels for Secret, Certificate, Registry, and RegistryCredential instead of schema-derived English names. It retains model-specific translations and the existing fallback for fields without a form label. The encrypted-key error on Certificate submission is localized as well. See the release note. Browser acceptance is tracked separately from the unit test.

Release 1.6.145 normalizes resource type names before checking the cached project schema. It restores Registry Add for authorized users while retaining the Registry plus RegistryCredential POST requirement and direct-route denial for unauthorized users. See the release note.

Release 1.6.144 introduced schema-gated Secret, Certificate, and Registry Add controls and localized 403 errors on denied direct Add URLs. Secret Edit also began following its update action link. Isolated 8080 acceptance found that Registry Add was incorrectly hidden even for authorized users because the cached schema ID was lowercase. See the release note. That regression is addressed by 1.6.145; its browser acceptance must be recorded separately.

Release 1.6.143 creates a private ProjectTemplate from editable fields only. It deep-copies the Default template's stacks without sending the Default's creation time, lifecycle state, or identity in the new resource request. See the release note. New-resource clones also omit server-owned lifecycle fields across Host, Service, Container, and VM forms. Receiver clones exclude inactive driver settings; unsupported Receiver drivers cannot be submitted from the form.

Release 1.6.142 stops a cloned Receiver from reusing its source's issued webhook URL or lifecycle state; the server issues the new URL. It also keeps the container table's actions visible during horizontal scrolling without changing data-column widths, clears catalog identity when creating a private ProjectTemplate, and shows localized denial for direct create routes and an inaccessible environment. See the release note.

Release 1.6.141 gives denied or missing ProjectTemplate edit URLs the same localized message in English and Traditional Chinese. Failed API-key saves now show the existing API error in the modal; a failed creation does not display key values. See the release note.

Version 1.6.140 shows ProjectTemplate edit and remove controls only to administrators or the template's account owner, including when the Server omits isPublic from non-administrator responses. Direct edit URLs repeat the ownership check before loading the editor. Closing an API-key modal before its delayed focus runs no longer attempts to focus a removed input; cancellation remains write-free.

Release 1.6.139 derives Container, project API-key, and Receiver Hook write controls from the current project's API schema. Direct routes repeat capability checks instead of relying on hidden buttons. Receiver role-aware controls require Webhook Automation Service v0.10.3 or newer; the Server remains responsible for authorization. Container editing now waits for its dependent saves and keeps the form open on a failed update. See the release note for the precise behavior and retry boundary.

Release 1.6.138 keeps delete confirmation open while requests run, prevents duplicate submissions, and allows retry after a failed deletion. Denied and missing resource pages keep their shared 404 presentation when the language finishes loading; the authenticated route waits for that language setup.

Release 1.6.137 lets empty pod-list messages wrap within narrow screens. This fixes a Russian no-hosts message that caused 6px of horizontal overflow at 320px. Pod columns keep their existing layout, and the environment switcher and error-page behavior from 1.6.136 are unchanged.

Release 1.6.136 keeps the environment switcher inside the viewport in left-to-right and right-to-left layouts, including narrow screens and long environment names. It also preserves right-to-left text direction on the shared error page. A stored environment selection is rechecked with the API; when the authenticated console loads after access is revoked, it selects an accessible fallback. The environment management list uses a fresh collection without resetting the active environment's schema. Authentication and server failures still surface as errors. Server authorization is unchanged.

Release 1.6.135 keeps the administrator environment switcher behavior from 1.6.134 and corrects the switcher list labels in French and Russian. The French labels no longer mix English words into French; the Russian labels identify all environments and your environments using the same term as the switcher. No API or permission behavior changes in this release.

Release 1.6.134 includes every active environment in the switcher for an authenticated site administrator, including environments where that account is not a direct member. Other signed-in users continue to see their member environments. The Server still authorizes the all=true collection request.

Release 1.6.133 uses the active environment's API schema to show host creation and cloning only to users who can create hosts. A direct add-host URL now returns a translated access error before loading registration data when creation is forbidden. Project schema loads are generation-checked so a late response cannot restore an earlier environment's controls. Environment detail waits for its project lookup before reading related resources. Error layout is usable on narrow screens and in right-to-left locales. Server authorization is unchanged.

Release 1.6.132 loads an environment's network policy under that project's API context, just as the policy-manager lookup and network save already do. Without the project header, a project member's network list was empty even though the same token could read and update the network in its project. The form still follows the returned update capability: readonly members cannot edit policy. No Server authorization rule is relaxed.

Release 1.6.131 limits account identity-link lookups to the user and admin rows that the account page actually displays. The account API also returns project accounts, whose identity-link lookup correctly returns 404; that 404 previously blocked the whole page. The list still surfaces authorization and backend errors for visible accounts instead of hiding them.

Release 1.6.130 makes direct stack, account-list, and account-security load failures show translated, actionable messages. A denied identity-link lookup no longer appears as an empty identity; only a confirmed missing link on an inactive account is treated as historical data. Account and environment-member validation errors now use the selected language. These are display and error-handling changes; API authorization remains enforced by the Server.

Release 1.6.129 adds an Edit link to the environment detail header when the network policy is editable but project metadata and members are not. The link opens the existing edit form for that environment; it does not change API permissions or duplicate the Edit action for project and member editors.

Release 1.6.128 makes the environment edit page follow API capabilities even when opened directly with ?editing=true. Existing members stay visible, but adding, changing roles, and removing members require the project's setmembers action link. Project metadata and network policy controls follow their own update links. A fully read-only edit page keeps an exit action without offering a save button. Focused browser-template and component tests cover the separate capabilities and new-environment creation flow.

Release 1.6.127 makes environment permission failures understandable in the existing page and form error surfaces. An inaccessible or missing environment or member list no longer exposes raw API details; a failed member or network policy update explains that earlier steps may already have saved. Identity search distinguishes no matching identity, insufficient permission, expired session, and temporary service failure. Route-level HTTP 401 retains the existing session recovery path. Pair this release with Engine 0.183.320 and Server v1.6.464 for the tested project-member authorization boundary.

Release 1.6.126 treats an authenticated account with no active environment as a valid empty state. It clears stale tab and store scope, skips every project-scoped request, and avoids a permanent loading error. Account rows use the authoritative login identity fallback order name, login, then externalId only when the account name is empty. Descriptions continue to show only the real account.description; identity names and e-mail addresses are never substituted. Pair this release with Engine 0.183.319 and Server v1.6.462.

Release 1.6.125 keeps account administration available when the account inventory contains an inactive historical row. The page still loads fresh, account-scoped authentication identities for every readable account, but an expected AccountNotFound from the identity-link endpoint is isolated to that single row and falls back to its embedded identity fields. Authorization, authentication, and server failures other than HTTP 404 still reject the route and remain diagnosable. Pair this release with Engine 0.183.318 and Server v1.6.461.

Release 1.6.124 restores direct navigation and refreshes for every /env/:project_id page after the Ember 7 transition upgrade. The authenticated parent route now reads the requested environment from the public RouteInfo tree, rather than the removed legacy transition parameter bag, before it considers a tab or user default. A permitted non-default environment therefore remains selected across direct links and reloads, while inaccessible IDs still fall through the existing server-authorized selection path. Pair this release with Engine 0.183.317 and Server v1.6.459.

Release 1.6.123 makes environment and workload entry points follow the effective API schema instead of assuming every signed-in account can create or update resources. Stack, service, load-balancer, alias, external-service, virtual-machine, and catalog launch routes reject direct navigation when the current environment omits the required POST or PUT method; their matching buttons are hidden from read-only and no-access roles. Catalog refresh and environment-catalog management additionally require a project management action. The account administration table now displays description and all authoritative linked login identities for both local and OpenID Connect accounts. Pair this release with Engine 0.183.317 and Server v1.6.458, which place new and returning external users in the shared Default environment while preserving explicit group or direct roles and existing environments.

Release 1.6.122 restores environment view and edit loading after the Ember 7 compatibility migration. Promise-to-callback adapters now distinguish source Promise rejection from exceptions raised by downstream async completion, so one operation can call its callback only once and the original error remains diagnosable. The project route imports members through the supported followLink contract before cloning the editable model; the removed importLink helper can no longer leave the transition pending. Synchronous and asynchronous failures from projects, members, networks, and policy managers now reject the route and reach the normal error page instead of leaving the static loading overlay in place. Focused tests cover resolved, rejected, downstream callback, concurrent async.auto, every environment-loading dependency, and the adjacent authenticated initialization path. The shared create/edit mixin now returns one owned Promise across validation, persistence, dependent saves, completion, error handling, and cleanup. Duplicate submissions cannot release another request's saving lock, while synchronous hook, callback, and finalizer exceptions remain diagnosable. Environment and load-balancer component tests exercise the same lifecycle used by the browser. Pair this release with Authentication Service v0.4.41 and Engine 0.183.309 or newer.

Release 1.6.121 closes the expired-session loading loop without changing the server authentication contract. GET /token may return HTTP 200 with provider login options when a Cookie is missing, invalid, or expired; the console now requires an identity-bearing accountId, user, or userIdentity before it adopts that response as an authenticated session. The unauthenticated object is normalized to the existing local 401 path, where the origin-level mutex clears only a still-matching Cookie and generation before routing to the login page. Passive failures still issue no DELETE, and a delayed result cannot clear a newer session. Deterministic tests cover simultaneous 401 recovery, single invalidation, newer-generation protection, masked JWT responses, and the existing TOTP, Passkey, callback, explicit-logout, and 403 boundaries. Pair this release with Authentication Service v0.4.41 and Engine 0.183.309 or newer.

Release 1.6.120 completes the cross-tab session boundary under real browser ordering. Shared cookie and generation reads now occur only after acquiring the same origin-level mutex used by login commit, so a peer cannot cache a half-written session. Storage events and BroadcastChannel feed one serialized reconciliation path; a tab entering the login route also revalidates an already committed cookie, covering refreshes and events missed during navigation. Initial-transition 401 handling stays generation-aware, passive failures never revoke a token, and explicit logout remains generation-bound and coalesced to a single DELETE. Deterministic delayed-401 coverage runs TOTP and Passkey orderings 100 times, and the production browser smoke validates three-tab adoption, refresh recovery, API access, WebSocket connectivity, and one explicit logout. Pair this release with Authentication Service v0.4.39 and Engine 0.183.309 or newer.

Release 1.6.119 closes three persistence regressions found during the 1.6.442 integrated runtime review. External-service API hydration can now replace the local healthy default, including with null, without assigning to a getter-only computed property. OIDC site-access updates retain stable error codes and bound MFA request digests when a rejection object is returned at the top level. Load-balancer backend selection now follows an explicit child action to the owning PortRule, so edit and upgrade PUT payloads retain the selected serviceId. Browser tests cover the real model setter, the strict one-retry MFA boundary, and the production DOM selector through the submitted API payload. Pair this release with Authentication Service v0.4.38 and Engine 0.183.304 or newer.

Release 1.6.118 fixes OIDC site-access policy editing without weakening the provider enablement boundary. Unrestricted mode clears stale authorized identities before saving; restricted and required entries are normalized and deduplicated by OIDC principal type and immutable external ID. Access expansion opens the existing MFA security-confirmation dialog with a purpose and canonical request digest supplied by the authentication service, retries exactly once, and never retains the one-time ticket after completion or failure. Stable backend codes are rendered as localized, actionable errors without exposing raw response bodies. Pair this release with Authentication Service v0.4.37 and Engine 0.183.303 or newer.

Release 1.6.117 prevents an older same-origin browser tab from revoking or clearing a session that a newer tab has just established. Explicit user logout is now the only browser path that requests server-side token revocation. Passive 401, storage, WebSocket, timer, and route failures reconcile against a non-sensitive session generation; ordinary 403 permission failures remain local to the failed request. Login, cookie readback, generation commit, session adoption, and explicit logout share one cross-tab mutex, with a tested IndexedDB lease fallback when Web Locks is unavailable. OIDC transactions retain the generation captured before leaving the origin, stale callbacks cannot overwrite a newer login, and waiting tabs validate the shared cookie before adopting it. JWTs remain cookie- and memory-only and are never persisted in Web Storage. A precise 409 ClientSessionSuperseded response from the Engine is treated as a stale completion rather than a failed active login, and request options cannot override the provider, authorization value, or captured generation. Pair this release with Engine 0.183.302 or newer for session-bound, ordered, idempotent server logout protection.

Release 1.6.116 recognizes the MFA API's structured error code even when the transport wraps it in a generic error. Sensitive settings updates open the security-confirmation dialog and retry only after successful confirmation; cancellation never resubmits the update. Unexpected API failures retain a localized explanation with bounded HTTP status/code diagnostics, without displaying raw response bodies. Use Engine 0.183.298 or newer for the matching live v2-beta MFA settings and confirmation schema repair.

Release 1.6.115 closes the global resource-action menu before dispatching the selected action. This prevents the row menu from remaining above account edit and other modal forms, while preserving the selected resource and action receiver. The same shared fix covers every resource table which uses this menu; focused tests verify that the menu, trigger state, and anchor are closed before the modal action executes.

Release 1.6.114 fixes the exact post-create exception captured during a real ranchernode22 service creation. The live global service collection can contain a transient empty slot while the API store merges a newly created resource; the page-header observer now ignores only those unreadable entries before examining application-service metadata. The same guard covers both observer and navigation tree rebuild paths. Completion no longer performs the unrelated service reload introduced by the two superseded diagnostic releases, while the saved payload, route callback, hardware controls, and other page regions remain unchanged.

Release 1.6.113 force-loaded the saved service by API ID while diagnosing the post-create failure. Instrumented browser evidence later located the exception in the page-header observer before completion navigation, so the extra request is removed in 1.6.114; 1.6.113 remains a diagnostic boundary.

Release 1.6.112 introduced the first-create refresh boundary found by the formal ranchernode22 acceptance test. The API could return a deliberately sparse service while that same record was already visible to the destination stack, causing its computed fields to render before the launch configuration was hydrated. The shared create/upgrade form now refreshes the persisted service before navigation and treats an optional refresh failure as non-authoritative because the save itself has already succeeded. Focused tests cover the intended refresh ordering, fallback behaviour, receiver binding, and unchanged hardware payloads. Real-host acceptance later proved Resource reload could not hydrate a response without a self link; 1.6.112 is retained as that diagnostic boundary. The Traditional Chinese capability label now describes mknod as creating a device node instead of presenting a misleading phonetic transliteration.

Release 1.6.111 fixes the post-save callback receiver boundary found by creating a real service on a managed host. The API and node correctly created the service, but the legacy component action target could lose its controller receiver before navigation. All four container and virtual-machine create routes now pass receiver-bound completion and cancellation callbacks to the shared form. The resource and hardware payload is unchanged. Real-host acceptance subsequently found a separate sparse-response render race; 1.6.111 is retained as that diagnostic boundary rather than the current compatibility target.

Release 1.6.110 restores the classic (action (mut ...)) contract used by command and environment editors, and accepts the modern array-like browser clipboard type list used by key/value inputs. This closes the two client-side exceptions found while filling the complete hardware/runtime form on a real host; it retains the INIT spacing and completion fixes from 1.6.109.

Release 1.6.109 corrects the create and upgrade completion contract exposed by real-host acceptance testing. Top-level create routes now pass classic named actions to the shared form so Ember dispatch preserves the controller receiver; the compatibility layer also refuses to forward a component prototype callback as an action name. This prevents a successfully persisted service from leaving the form open with undefined.get or a template-action error. A regression test exercises the controller transition, and the init-process control has additional desktop separation from the adjacent process-limit input without changing its payload binding.

Release 1.6.108 attempted to close the first-create completion failure with a closure callback. Real-host acceptance testing subsequently showed that the legacy action compatibility path could still misroute the callback after the service was already persisted. It is retained as a superseded diagnostic step, not as the current compatibility target.

Release 1.6.107 removed saved-response dereferences from route selection, but real-host acceptance testing showed that the deprecated callback dispatch still failed after persistence. It is retained only as a superseded diagnostic step, not as the current compatibility target.

Release 1.6.106 fixes the real first-service creation completion path. An empty service-link set no longer sends a redundant action after the service is already persisted, and a non-empty link update preserves the stack route identity even if the API returns a partial resource. The route also keeps its original stack ID independently of the mutable service response. A successful first click therefore leaves the form instead of showing an error that could invite a duplicate service submission.

Release 1.6.105 fixes the post-save transition for a newly created service: the persisted service now remains in the completion chain instead of being discarded by the service-link action. Stack-scoped create routes also fall back to their stable stack query parameter, and advanced key/value inputs render localized placeholders. The create and upgrade resource payloads remain unchanged.

Release 1.6.104 keeps the authenticated browser-session and OIDC corrections from 1.6.103. It also keeps the init-process checkbox inside its own resource grid column, with the launch-configuration binding unchanged, so the control no longer touches the adjacent process-limit input on create or upgrade forms.

Release 1.6.103 keeps an authenticated browser session when a non-auth API request fails during startup, displays the nested OIDC/API explanation instead of an empty alert, and activates a newly verified provider in unrestricted mode so every identity accepted by that provider can sign in. Administrators can still narrow access afterward with the existing site-access controls.

The language picker includes English, German, Persian, Filipino, French, Hungarian, Japanese, Korean, Brazilian Portuguese, Russian, Ukrainian, Simplified Chinese, and Traditional Chinese for Taiwan. Every selectable locale must satisfy the complete message contract and regional formatting gates documented in Localization. New security-sensitive authentication text is maintained in English and Traditional Chinese first; other locales inherit the complete English text until a reviewed translation is available, rather than displaying missing translation keys.

The manually dispatched validation workflow tests and builds the exact selected commit on a GitHub-hosted runner and retains the reviewed candidate for 30 days. Release publication remains a separate reviewed step.

Build and test

npm ci --ignore-scripts
npm run build -- --environment=production
npm test
package_version=$(node -p 'require("./package.json").version')
bash scripts/package-static-candidate \
  "$package_version" dist "build/ui/${package_version}.tar.gz"

The packaging command uses the current Git commit timestamp by default, or an explicit SOURCE_DATE_EPOCH, and emits a deterministic tarball plus a portable SHA-256 file. It creates a candidate only; publishing remains a separate, reviewed release step. The archive root and VERSION.txt must equal the numeric package version; a preserved compatibility version must not be silently substituted into a new release artifact.

Catalog cards and launch pages read optional io.pasturestack.catalog.name.<locale> and io.pasturestack.catalog.description.<locale> labels. Unknown locales and third-party catalogs fall back to their canonical metadata instead of showing an empty string or an untranslated key.

Container terminals, container logs, and virtual machine consoles use the movable window system documented in Console workspace. Terminal and log sessions can be reopened after a tab refresh or browser restart, and active output is shared across signed-in tabs without persisting upstream access tokens.

Host storage pages provide checkbox selection, state filtering, search, pagination, and one operator-confirmed removal action. Selection rules, preview behavior, and the concurrency limit are documented in operator-selected storage removal.

Linux shared memory, runtimes, GPU/graphics devices and advanced container limits use the shared Resources and hardware form. The guide covers coordinated agent/API rollout and the distinction between device visibility and exclusive GPU allocation.

OpenID Connect configuration, stable account-to-identity assignment, safe provider switching, and local recovery are documented in OpenID Connect. TOTP, passkeys, recovery codes, email account recovery, and administrator controls are documented in Multi-factor authentication.

The repository includes explicit modernization gates because its historical frontend toolchain cannot be trusted without review. See COMPATIBILITY.md, SECURITY.md, and ORIGIN.md.

License and attribution

The inherited project remains licensed under Apache License 2.0, with additional attribution in COPYRIGHT_DETAILS.md. Bundled dependencies retain their own licenses and notices. PastureStack contributors claim authorship only for their own changes.

About

Web management console for the PastureStack compatibility platform

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages