Prepare v6.4.0-rc.1 release

This commit is contained in:
rcourtman 2026-08-25 09:51:51 +01:00
parent 67a9f33273
commit 831e55f011
14 changed files with 231 additions and 31 deletions

View file

@ -1 +1 @@
6.3.1
6.4.0-rc.1

View file

@ -2,9 +2,9 @@ apiVersion: v2
name: pulse
description: Helm chart for deploying the Pulse hub and optional Docker, Kubernetes, or OpenShift monitoring agent.
type: application
version: 6.3.1
appVersion: "6.3.1"
icon: https://raw.githubusercontent.com/rcourtman/Pulse/v6.3.1/docs/images/pulse-logo.svg
version: 6.4.0-rc.1
appVersion: "6.4.0-rc.1"
icon: https://raw.githubusercontent.com/rcourtman/Pulse/v6.4.0-rc.1/docs/images/pulse-logo.svg
keywords:
- monitoring
- proxmox
@ -32,7 +32,7 @@ annotations:
description: Smoke tests with kind cluster deployment
artifacthub.io/links: |
- name: Documentation
url: https://github.com/rcourtman/Pulse/blob/v6.3.1/docs/KUBERNETES.md
url: https://github.com/rcourtman/Pulse/blob/v6.4.0-rc.1/docs/KUBERNETES.md
- name: Support
url: https://github.com/rcourtman/Pulse/discussions
artifacthub.io/maintainers: |

View file

@ -1,6 +1,6 @@
# pulse
![Version: 6.3.1](https://img.shields.io/badge/Version-6.3.1-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 6.3.1](https://img.shields.io/badge/AppVersion-6.3.1-informational?style=flat-square)
![Version: 6.4.0-rc.1](https://img.shields.io/badge/Version-6.4.0--rc.1-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 6.4.0-rc.1](https://img.shields.io/badge/AppVersion-6.4.0--rc.1-informational?style=flat-square)
Helm chart for deploying the Pulse hub and optional Docker, Kubernetes, or OpenShift monitoring agent.

View file

@ -2,7 +2,7 @@ version: '3.8'
services:
pulse:
image: ${PULSE_IMAGE:-rcourtman/pulse:6.3.1}
image: ${PULSE_IMAGE:-rcourtman/pulse:6.4.0-rc.1}
container_name: pulse
restart: unless-stopped
logging:

View file

@ -6,6 +6,10 @@ Pulse release notes live on GitHub:
For historical v4 notes that previously lived in this repo, see:
`docs/releases/RELEASE_NOTES_v4.md`
For the current v6 release candidate packet (the current v6 support release candidate packet), see:
- `docs/releases/RELEASE_NOTES_v6.4.0-rc.1.md`
- `docs/releases/V6_CHANGELOG_v6.4.0-rc.1.md`
For the current stable v6 packet, see:
- `docs/releases/RELEASE_NOTES_v6.3.1.md`
- `docs/releases/V6_CHANGELOG_v6.3.1.md`

View file

@ -2,6 +2,11 @@
This guide covers practical upgrade steps for existing Pulse installs moving to v6.
For the current v6 release candidate packet (the current v6 support release candidate packet), see:
- `docs/releases/RELEASE_NOTES_v6.4.0-rc.1.md`
- `docs/releases/V6_CHANGELOG_v6.4.0-rc.1.md`
For the current stable v6 packet, see:
- `docs/releases/RELEASE_NOTES_v6.3.1.md`

View file

@ -9761,7 +9761,21 @@
}
],
"candidate_lanes": [],
"work_claims": [],
"work_claims": [
{
"id": "root-lane-l1",
"agent_id": "root",
"summary": "Prepare and publish the next governed Pulse release candidate from current main.",
"target_id": "v6-product-lane-expansion",
"claimed_at": "2026-08-25T08:42:33Z",
"heartbeat_at": "2026-08-25T08:42:33Z",
"expires_at": "2026-08-25T10:42:33Z",
"work_item": {
"kind": "lane",
"id": "L1"
}
}
],
"open_decisions": [],
"source_of_truth_file": "docs/release-control/v6/internal/SOURCE_OF_TRUTH.md",
"resolved_decisions": [

View file

@ -1721,7 +1721,27 @@ diagnostics. The same release workflow also executes the generated self-signed
and custom-CA Windows installer commands through Windows PowerShell 5.1 before
release assembly, so the first HTTPS fetch is release proof rather than a
string-shape assertion.
The active stable `v6.3.1` cut sets the repo-root `VERSION`, repo-root
The active prerelease `v6.4.0-rc.1` cut sets the repo-root `VERSION`, repo-root
`docker-compose.yml` image default, `scripts/install-docker.sh` fallback, and
Helm chart release metadata to the same `6.4.0-rc.1` release version. It follows
stable `v6.3.1` and opens the published `v6.4.0` candidate line. This prerelease
keeps `rollback_version=v6.3.1`, publishes a versioned public GitHub prerelease
plus versioned Docker and Helm artifacts, and does not move stable/latest
install pointers or stable semver aliases. The candidate makes large-estate
workload, infrastructure, storage, and platform rendering incremental;
canonicalizes table, drawer, touch, disclosure, sorting, and navigation
behavior; fixes fixed-interval scheduling, re-enrollment cleanup, offline-alert
policy, command-intent continuity, and forked-identity discovery lookup; and
moves release compilation behind an isolated immutable artifact handoff. The
changes since `v6.3.1` do not require a Pulse Mobile client change and preserve
the existing mobile, Relay, onboarding, and mobile-facing API contracts, so the
server cut is classified `no-mobile-impact`; no companion upload or public
mobile-store rollout is part of this candidate. The prerelease Windows path
retains exact-SHA, checksum, and detached-signature verification without
Authenticode; stable `v6.4.0` restores mandatory SignPath signing unless a new
version-bound decision is recorded.
The preceding stable `v6.3.1` cut set the repo-root `VERSION`, repo-root
`docker-compose.yml` image default, `scripts/install-docker.sh` fallback, and
Helm chart release metadata to the same `6.3.1` release version. This patch
release uses the stable hotfix path with `rollback_version=v6.3.0`,
@ -2130,13 +2150,14 @@ For the active stable `v6.1.2` cut, the repo-root compose default and
`scripts/install-docker.sh` fallback must both pin `6.1.2` whenever the
governed `VERSION` is that stable cut. The stable promotion guard remains in
force and rejects leftover `-rc.` defaults.
For the active stable `v6.3.1` cut, the repo-root compose default and
`scripts/install-docker.sh` fallback must both pin `6.3.1` until the next
governed release moves them forward. The stable promotion guard remains in
force and rejects leftover `-rc.` defaults. Each new release moves
For the active prerelease `v6.4.0-rc.1` cut, the repo-root compose default and
`scripts/install-docker.sh` fallback must both pin `6.4.0-rc.1` until the next
governed stable cut moves them forward. Each new release moves
these two pins together with the repo-root `VERSION` and the Helm chart metadata
in the same commit; a cut that leaves any of the four on a superseded value is a
release-packet blocker.
For the preceding stable `v6.3.1` cut, the repo-root compose default and
`scripts/install-docker.sh` fallback both pinned `6.3.1`.
For the preceding stable `v6.3.0` cut, the repo-root compose default and
`scripts/install-docker.sh` fallback both pinned `6.3.0`.
For the preceding stable `v6.2.1` cut, the repo-root compose default and

View file

@ -0,0 +1,94 @@
# Pulse v6.4.0-rc.1 Release Notes
`v6.4.0-rc.1` is a release candidate for the next Pulse v6 minor line. It
follows stable `v6.3.1` and is the first candidate on the `v6.4.0` line. It
focuses on responsive large-estate operation, consistent infrastructure
tables and detail drawers, monitoring correctness, and a more isolated release
build path.
## Highlights
- Large estates render, scroll, search, and update incrementally across workloads, infrastructure, storage, and platform pages.
- Infrastructure tables and drawers share consistent desktop, mobile, touch, sorting, density, and navigation behavior.
- Monitoring and agent re-enrollment fixes preserve configured polling, offline policy, command intent, and resource visibility.
## Added
- A weekly scheduled dependency-vulnerability scan now covers the Go, frontend,
integration, and GitHub Actions dependency surfaces.
- Shared windowed platform-list primitives extend bounded rendering to Docker,
Kubernetes, Proxmox, TrueNAS, VMware, standalone agent, availability, alert,
and storage views.
- Canonical object-drawer headers, attention sections, technical-detail
disclosures, sortable-table indicators, and touch-capability helpers provide
one reusable presentation contract across infrastructure surfaces.
## Improved
- Workload, Proxmox, infrastructure, and storage views use incremental
navigation, virtualized rows, stable scroll ownership, and adaptive preview
thresholds to keep 50-node estates responsive.
- Platform search and row visibility share the same predicates, including
Proxmox nodes and their visible guests. Navigation tabs remain stable across
WebSocket updates instead of remounting with live state.
- Route-level code splitting remains effective on cold start: the frontend no
longer modulepreloads every lazy route chunk, while integrity coverage stays
enforced for dynamically loaded assets.
- Proxmox backup views use canonical routes, compact healthy-state shields, and
recovery pagination derived from the normalized query limit.
- Mobile and touch layouts keep native page scrolling and gestures, avoid hover
tooltips, use consistent disclosure affordances, and retain reachable table
actions at narrow widths.
- Public and private release payloads compile once on isolated,
credential-free trusted workers, then cross an immutable artifact-identity
boundary before hosted signing, qualification, and publication.
## Fixed
- Fixed polling intervals are honored when adaptive scheduling is disabled.
- Re-enrollment clears host-removal blocks from every owning store so a valid
returning agent is not held in a partially removed state.
- Connection alerts can no longer bypass the configured offline-alert policy.
- Agent reinstall and hosted enrollment preserve command-policy intent instead
of silently dropping the command-execution posture.
- Discovery resolves known equivalent forked host identities when matching
resources, preventing an identity spelling difference from hiding current
discovery results.
- Large workload and platform tables no longer leave blank virtualized regions,
lose expanded-row scrolling, or move touch gestures away from the page.
- Notification configuration no longer returns the stored Apprise API key to
the browser after it has been saved.
## Release Qualification
- The v6 control plane reports all 44 readiness assertions and all 26 release
gates passed at the candidate cutoff.
- The single-build release workflow must pass its self-contained frontend,
backend, mobile-decision, immutable-candidate, container, Helm, installer,
public/private staging, and activation checks before publication.
- The release decision is `no-mobile-impact`: no Pulse Mobile API, Relay,
pairing, push, authentication, approval, or onboarding contract changed from
`v6.3.1`, and no companion upload or public mobile-store rollout is part of
this candidate.
- The changes since `v6.3.1` do not require a Pulse Mobile client change and
preserve the existing mobile, Relay, onboarding, and mobile-facing API
contracts.
- Windows Unified Agent binaries in this prerelease retain exact-SHA, checksum,
and detached-signature verification but are not Authenticode-signed. Stable
`v6.4.0` still requires the normal SignPath Authenticode lane unless a new
explicit version-bound owner decision is recorded.
## Upgrade Notes
Use the normal v6 install or update flow for `v6.4.0-rc.1` only when you are
comfortable testing an RC. Existing configurations remain valid and no manual
data migration is required.
The rollback target is `v6.3.1`. The exact rollback reinstall command is:
```bash
./scripts/install.sh --version v6.3.1
```
Paid Pulse Pro, Relay, and eligible legacy customers should continue to use the
private download page and private runtime image for paid runtime features.

View file

@ -0,0 +1,55 @@
# Pulse v6.4.0-rc.1
_This changelog describes the changes since `v6.3.1` included in
`v6.4.0-rc.1`._
## Added
- A scheduled weekly dependency-vulnerability scan covers the Go, frontend,
integration, and GitHub Actions dependency surfaces.
- Shared platform windowing, object-drawer headers, attention sections,
technical-detail disclosures, sortable indicators, and touch-capability
helpers establish reusable infrastructure presentation contracts.
## Changed
- Large-estate workloads, infrastructure, storage, and platform lists render,
navigate, search, and receive live updates incrementally.
- Proxmox node search shares the workload visibility predicate, backup views
use canonical routes, and recovery pagination follows the normalized limit.
- Docker, Kubernetes, Proxmox, TrueNAS, VMware, standalone agent,
availability, alert, and storage tables share consistent density, disclosure,
drawer, and narrow-viewport behavior.
- Mobile and touch layouts retain native page scrolling and gestures while
hover-only tooltips stay disabled on touch interactions.
- Cold start preloads only the entry module's static import graph while the
import-map integrity block continues to cover every built JavaScript asset.
- Public and private release payload compilation runs once on isolated,
credential-free trusted workers and crosses an immutable artifact-identity
boundary before hosted signing or publication.
## Fixed
- Fixed poll intervals remain fixed when adaptive scheduling is disabled.
- Agent re-enrollment clears host-removal blocks from every owning store.
- Connection alerts respect the configured offline-alert policy.
- Reinstall and hosted enrollment preserve agent command-policy intent.
- Discovery lookups resolve known equivalent forked host identities.
- Windowed tables no longer leave blank regions, lose expanded-row scroll
ownership, or detach touch gestures from the page.
- The notifications API no longer returns the stored Apprise API key.
## Release Metadata
- Version: `v6.4.0-rc.1`
- Previous stable: `v6.3.1`
- Rollback target: `v6.3.1`
- Rollback command: `./scripts/install.sh --version v6.3.1`
- Promotion path: exact-SHA single-build release candidate from `main`
- Windows signing decision: the standing prerelease path publishes exact-SHA,
checksum, and detached-signature verified Windows agents without
Authenticode; stable `v6.4.0` restores mandatory SignPath signing unless a
new version-bound owner decision is recorded
- Mobile decision: `no-mobile-impact`; changes since `v6.3.1` preserve the
existing mobile, Relay, onboarding, and mobile-facing API contracts, so no
companion upload or public store rollout is required

View file

@ -2,6 +2,11 @@
This guide covers practical upgrade steps for existing Pulse installs moving to v6.
For the current v6 release candidate packet (the current v6 support release candidate packet), see:
- `docs/releases/RELEASE_NOTES_v6.4.0-rc.1.md`
- `docs/releases/V6_CHANGELOG_v6.4.0-rc.1.md`
For the current stable v6 packet, see:
- `docs/releases/RELEASE_NOTES_v6.3.1.md`

View file

@ -6,7 +6,7 @@ set -euo pipefail
SCRIPT_DIR="$(CDPATH= cd -- "$(dirname -- "$0")" && pwd)"
DOCKER_IMAGE_REPO="${DOCKER_IMAGE_REPO:-rcourtman/pulse}"
CANONICAL_DEFAULT_PULSE_VERSION="6.3.1"
CANONICAL_DEFAULT_PULSE_VERSION="6.4.0-rc.1"
resolve_default_pulse_version() {
if [ -n "${PULSE_IMAGE_VERSION:-}" ]; then

View file

@ -885,15 +885,16 @@ func TestCurrentPrereleasePacketTracksInstallMetadata(t *testing.T) {
"`v"+version+"` is a release candidate",
"## Highlights",
"stable `v"+previous+"`",
"Patrol now works from durable outcomes, scoped investigations",
"Read-only observers extend Patrol coverage between full model investigations without granting mutation authority.",
"Actions and Patrol identify whether a decision originated from a finding, alert, objective, or explicit operator request",
"Action refusal telemetry now classifies target changes, prerequisites, contract failures",
"Subscription-backed turns now complete their idle timeout promptly",
"Platform pages now lead with estate totals, status facets, and search that share the same predicates as their underlying tables.",
"Notification settings show the outcome of real delivery attempts instead of relying on test sends as a proxy for live delivery health.",
"Docker-in-LXC discovery is explicitly controlled and backs off against slow or failing Proxmox hosts instead of creating a probe storm.",
"Unified Agent installs can opt into a supported least-privilege profile with narrowly scoped elevation for the capabilities that require it.",
"Large estates render, scroll, search, and update incrementally",
"Infrastructure tables and drawers share consistent desktop, mobile, touch, sorting, density, and navigation behavior.",
"Monitoring and agent re-enrollment fixes preserve configured polling, offline policy, command intent, and resource visibility.",
"weekly scheduled dependency-vulnerability scan",
"Shared windowed platform-list primitives",
"Workload, Proxmox, infrastructure, and storage views use incremental navigation, virtualized rows, stable scroll ownership",
"the frontend no longer modulepreloads every lazy route chunk",
"Fixed polling intervals are honored when adaptive scheduling is disabled.",
"Re-enrollment clears host-removal blocks from every owning store",
"Notification configuration no longer returns the stored Apprise API key",
"The rollback target is `v"+previous+"`",
"The changes since `v"+comparisonVersion+"` do not require a Pulse Mobile client change",
"preserve the existing mobile, Relay, onboarding, and mobile-facing API contracts",
@ -907,13 +908,13 @@ func TestCurrentPrereleasePacketTracksInstallMetadata(t *testing.T) {
"Rollback target: `v"+previous+"`",
"Promotion path: exact-SHA single-build release candidate from `main`",
"This changelog describes the changes since `v"+comparisonVersion+"`",
"Durable, scoped Patrol objectives and validated read-only observer missions",
"A primary Actions workspace for approvals, governed plans, and action records",
"Typed Unified Agent action preflight for supported host and Docker operations",
"Stable pre-mutation refusal codes and fleet telemetry buckets",
"Estate summaries, status facets, and canonical search on the primary infrastructure platform pages",
"A seven-day delivery log for real alert notification attempts",
"A supported least-privilege Unified Agent installation profile",
"scheduled weekly dependency-vulnerability scan",
"Shared platform windowing, object-drawer headers, attention sections",
"Large-estate workloads, infrastructure, storage, and platform lists render, navigate, search, and receive live updates incrementally.",
"Cold start preloads only the entry module's static import graph",
"Fixed poll intervals remain fixed when adaptive scheduling is disabled.",
"Agent re-enrollment clears host-removal blocks from every owning store.",
"The notifications API no longer returns the stored Apprise API key.",
"Windows signing decision: the standing prerelease path publishes exact-SHA, checksum, and detached-signature verified Windows agents without Authenticode; stable `v"+stableTarget+"` restores mandatory SignPath signing",
"Mobile decision: `no-mobile-impact`",
"changes since `v"+comparisonVersion+"` preserve the existing mobile, Relay, onboarding, and mobile-facing API contracts",

View file

@ -141,6 +141,7 @@ func TestPreviousStableForPrereleaseVersionCrossesMinorBoundaries(t *testing.T)
{version: "6.2.2-rc.3", want: "6.2.1"},
{version: "6.3.0-rc.1", want: "6.2.1"},
{version: "6.3.0-rc.2", want: "6.2.1"},
{version: "6.4.0-rc.1", want: "6.3.1"},
}
for _, test := range tests {
@ -367,7 +368,7 @@ func TestInstallDockerProofTracksPrereleaseContract(t *testing.T) {
assertFileContainsAllNormalized(t, repoFile("docs", "release-control", "v6", "internal", "subsystems", "deployment-installability.md"),
"The active prerelease `v"+version+"` cut sets the repo-root `VERSION`, repo-root `docker-compose.yml` image default, `scripts/install-docker.sh` fallback, and Helm chart release metadata to the same `"+version+"` release version.",
"It follows `v"+comparisonVersion+"` on the published 6.3 candidate line",
"It follows stable `v"+comparisonVersion+"` and opens the published `v"+stableTarget+"` candidate line.",
"This prerelease keeps `rollback_version=v"+previous+"`, publishes a versioned public GitHub prerelease plus versioned Docker and Helm artifacts, and does not move stable/latest install pointers or stable semver aliases.",
"The changes since `v"+comparisonVersion+"` do not require a Pulse Mobile client change and preserve the existing mobile, Relay, onboarding, and mobile-facing API contracts, so the server cut is classified `no-mobile-impact`; no companion upload or public mobile-store rollout is part of this candidate.",
"The prerelease Windows path retains exact-SHA, checksum, and detached-signature verification without Authenticode; stable `v"+stableTarget+"` restores mandatory SignPath signing unless a new version-bound decision is recorded.",