diff --git a/VERSION b/VERSION index dc0208aba..ece0bb00a 100644 --- a/VERSION +++ b/VERSION @@ -1 +1 @@ -6.3.1 +6.4.0-rc.1 diff --git a/deploy/helm/pulse/Chart.yaml b/deploy/helm/pulse/Chart.yaml index b651d3a79..30fa21323 100644 --- a/deploy/helm/pulse/Chart.yaml +++ b/deploy/helm/pulse/Chart.yaml @@ -2,9 +2,9 @@ apiVersion: v2 name: pulse description: Helm chart for deploying the Pulse hub and optional Docker, Kubernetes, or OpenShift monitoring agent. type: application -version: 6.3.1 -appVersion: "6.3.1" -icon: https://raw.githubusercontent.com/rcourtman/Pulse/v6.3.1/docs/images/pulse-logo.svg +version: 6.4.0-rc.1 +appVersion: "6.4.0-rc.1" +icon: https://raw.githubusercontent.com/rcourtman/Pulse/v6.4.0-rc.1/docs/images/pulse-logo.svg keywords: - monitoring - proxmox @@ -32,7 +32,7 @@ annotations: description: Smoke tests with kind cluster deployment artifacthub.io/links: | - name: Documentation - url: https://github.com/rcourtman/Pulse/blob/v6.3.1/docs/KUBERNETES.md + url: https://github.com/rcourtman/Pulse/blob/v6.4.0-rc.1/docs/KUBERNETES.md - name: Support url: https://github.com/rcourtman/Pulse/discussions artifacthub.io/maintainers: | diff --git a/deploy/helm/pulse/README.md b/deploy/helm/pulse/README.md index 0f0aa7fff..e9359672f 100644 --- a/deploy/helm/pulse/README.md +++ b/deploy/helm/pulse/README.md @@ -1,6 +1,6 @@ # pulse -![Version: 6.3.1](https://img.shields.io/badge/Version-6.3.1-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 6.3.1](https://img.shields.io/badge/AppVersion-6.3.1-informational?style=flat-square) +![Version: 6.4.0-rc.1](https://img.shields.io/badge/Version-6.4.0--rc.1-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 6.4.0-rc.1](https://img.shields.io/badge/AppVersion-6.4.0--rc.1-informational?style=flat-square) Helm chart for deploying the Pulse hub and optional Docker, Kubernetes, or OpenShift monitoring agent. diff --git a/docker-compose.yml b/docker-compose.yml index bbecb4ca4..91499f30f 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -2,7 +2,7 @@ version: '3.8' services: pulse: - image: ${PULSE_IMAGE:-rcourtman/pulse:6.3.1} + image: ${PULSE_IMAGE:-rcourtman/pulse:6.4.0-rc.1} container_name: pulse restart: unless-stopped logging: diff --git a/docs/RELEASE_NOTES.md b/docs/RELEASE_NOTES.md index cc83cac7c..aaf09f300 100644 --- a/docs/RELEASE_NOTES.md +++ b/docs/RELEASE_NOTES.md @@ -6,6 +6,10 @@ Pulse release notes live on GitHub: For historical v4 notes that previously lived in this repo, see: `docs/releases/RELEASE_NOTES_v4.md` +For the current v6 release candidate packet (the current v6 support release candidate packet), see: +- `docs/releases/RELEASE_NOTES_v6.4.0-rc.1.md` +- `docs/releases/V6_CHANGELOG_v6.4.0-rc.1.md` + For the current stable v6 packet, see: - `docs/releases/RELEASE_NOTES_v6.3.1.md` - `docs/releases/V6_CHANGELOG_v6.3.1.md` diff --git a/docs/UPGRADE_v6.md b/docs/UPGRADE_v6.md index d5639d3ec..302a87e4d 100644 --- a/docs/UPGRADE_v6.md +++ b/docs/UPGRADE_v6.md @@ -2,6 +2,11 @@ This guide covers practical upgrade steps for existing Pulse installs moving to v6. +For the current v6 release candidate packet (the current v6 support release candidate packet), see: + +- `docs/releases/RELEASE_NOTES_v6.4.0-rc.1.md` +- `docs/releases/V6_CHANGELOG_v6.4.0-rc.1.md` + For the current stable v6 packet, see: - `docs/releases/RELEASE_NOTES_v6.3.1.md` diff --git a/docs/release-control/v6/internal/status.json b/docs/release-control/v6/internal/status.json index f86e20d9b..f8f33403e 100644 --- a/docs/release-control/v6/internal/status.json +++ b/docs/release-control/v6/internal/status.json @@ -9761,7 +9761,21 @@ } ], "candidate_lanes": [], - "work_claims": [], + "work_claims": [ + { + "id": "root-lane-l1", + "agent_id": "root", + "summary": "Prepare and publish the next governed Pulse release candidate from current main.", + "target_id": "v6-product-lane-expansion", + "claimed_at": "2026-08-25T08:42:33Z", + "heartbeat_at": "2026-08-25T08:42:33Z", + "expires_at": "2026-08-25T10:42:33Z", + "work_item": { + "kind": "lane", + "id": "L1" + } + } + ], "open_decisions": [], "source_of_truth_file": "docs/release-control/v6/internal/SOURCE_OF_TRUTH.md", "resolved_decisions": [ diff --git a/docs/release-control/v6/internal/subsystems/deployment-installability.md b/docs/release-control/v6/internal/subsystems/deployment-installability.md index 311f1a871..d1185d97b 100644 --- a/docs/release-control/v6/internal/subsystems/deployment-installability.md +++ b/docs/release-control/v6/internal/subsystems/deployment-installability.md @@ -1721,7 +1721,27 @@ diagnostics. The same release workflow also executes the generated self-signed and custom-CA Windows installer commands through Windows PowerShell 5.1 before release assembly, so the first HTTPS fetch is release proof rather than a string-shape assertion. -The active stable `v6.3.1` cut sets the repo-root `VERSION`, repo-root +The active prerelease `v6.4.0-rc.1` cut sets the repo-root `VERSION`, repo-root +`docker-compose.yml` image default, `scripts/install-docker.sh` fallback, and +Helm chart release metadata to the same `6.4.0-rc.1` release version. It follows +stable `v6.3.1` and opens the published `v6.4.0` candidate line. This prerelease +keeps `rollback_version=v6.3.1`, publishes a versioned public GitHub prerelease +plus versioned Docker and Helm artifacts, and does not move stable/latest +install pointers or stable semver aliases. The candidate makes large-estate +workload, infrastructure, storage, and platform rendering incremental; +canonicalizes table, drawer, touch, disclosure, sorting, and navigation +behavior; fixes fixed-interval scheduling, re-enrollment cleanup, offline-alert +policy, command-intent continuity, and forked-identity discovery lookup; and +moves release compilation behind an isolated immutable artifact handoff. The +changes since `v6.3.1` do not require a Pulse Mobile client change and preserve +the existing mobile, Relay, onboarding, and mobile-facing API contracts, so the +server cut is classified `no-mobile-impact`; no companion upload or public +mobile-store rollout is part of this candidate. The prerelease Windows path +retains exact-SHA, checksum, and detached-signature verification without +Authenticode; stable `v6.4.0` restores mandatory SignPath signing unless a new +version-bound decision is recorded. + +The preceding stable `v6.3.1` cut set the repo-root `VERSION`, repo-root `docker-compose.yml` image default, `scripts/install-docker.sh` fallback, and Helm chart release metadata to the same `6.3.1` release version. This patch release uses the stable hotfix path with `rollback_version=v6.3.0`, @@ -2130,13 +2150,14 @@ For the active stable `v6.1.2` cut, the repo-root compose default and `scripts/install-docker.sh` fallback must both pin `6.1.2` whenever the governed `VERSION` is that stable cut. The stable promotion guard remains in force and rejects leftover `-rc.` defaults. -For the active stable `v6.3.1` cut, the repo-root compose default and -`scripts/install-docker.sh` fallback must both pin `6.3.1` until the next -governed release moves them forward. The stable promotion guard remains in -force and rejects leftover `-rc.` defaults. Each new release moves +For the active prerelease `v6.4.0-rc.1` cut, the repo-root compose default and +`scripts/install-docker.sh` fallback must both pin `6.4.0-rc.1` until the next +governed stable cut moves them forward. Each new release moves these two pins together with the repo-root `VERSION` and the Helm chart metadata in the same commit; a cut that leaves any of the four on a superseded value is a release-packet blocker. +For the preceding stable `v6.3.1` cut, the repo-root compose default and +`scripts/install-docker.sh` fallback both pinned `6.3.1`. For the preceding stable `v6.3.0` cut, the repo-root compose default and `scripts/install-docker.sh` fallback both pinned `6.3.0`. For the preceding stable `v6.2.1` cut, the repo-root compose default and diff --git a/docs/releases/RELEASE_NOTES_v6.4.0-rc.1.md b/docs/releases/RELEASE_NOTES_v6.4.0-rc.1.md new file mode 100644 index 000000000..400d33189 --- /dev/null +++ b/docs/releases/RELEASE_NOTES_v6.4.0-rc.1.md @@ -0,0 +1,94 @@ +# Pulse v6.4.0-rc.1 Release Notes + +`v6.4.0-rc.1` is a release candidate for the next Pulse v6 minor line. It +follows stable `v6.3.1` and is the first candidate on the `v6.4.0` line. It +focuses on responsive large-estate operation, consistent infrastructure +tables and detail drawers, monitoring correctness, and a more isolated release +build path. + +## Highlights + +- Large estates render, scroll, search, and update incrementally across workloads, infrastructure, storage, and platform pages. +- Infrastructure tables and drawers share consistent desktop, mobile, touch, sorting, density, and navigation behavior. +- Monitoring and agent re-enrollment fixes preserve configured polling, offline policy, command intent, and resource visibility. + +## Added + +- A weekly scheduled dependency-vulnerability scan now covers the Go, frontend, + integration, and GitHub Actions dependency surfaces. +- Shared windowed platform-list primitives extend bounded rendering to Docker, + Kubernetes, Proxmox, TrueNAS, VMware, standalone agent, availability, alert, + and storage views. +- Canonical object-drawer headers, attention sections, technical-detail + disclosures, sortable-table indicators, and touch-capability helpers provide + one reusable presentation contract across infrastructure surfaces. + +## Improved + +- Workload, Proxmox, infrastructure, and storage views use incremental + navigation, virtualized rows, stable scroll ownership, and adaptive preview + thresholds to keep 50-node estates responsive. +- Platform search and row visibility share the same predicates, including + Proxmox nodes and their visible guests. Navigation tabs remain stable across + WebSocket updates instead of remounting with live state. +- Route-level code splitting remains effective on cold start: the frontend no + longer modulepreloads every lazy route chunk, while integrity coverage stays + enforced for dynamically loaded assets. +- Proxmox backup views use canonical routes, compact healthy-state shields, and + recovery pagination derived from the normalized query limit. +- Mobile and touch layouts keep native page scrolling and gestures, avoid hover + tooltips, use consistent disclosure affordances, and retain reachable table + actions at narrow widths. +- Public and private release payloads compile once on isolated, + credential-free trusted workers, then cross an immutable artifact-identity + boundary before hosted signing, qualification, and publication. + +## Fixed + +- Fixed polling intervals are honored when adaptive scheduling is disabled. +- Re-enrollment clears host-removal blocks from every owning store so a valid + returning agent is not held in a partially removed state. +- Connection alerts can no longer bypass the configured offline-alert policy. +- Agent reinstall and hosted enrollment preserve command-policy intent instead + of silently dropping the command-execution posture. +- Discovery resolves known equivalent forked host identities when matching + resources, preventing an identity spelling difference from hiding current + discovery results. +- Large workload and platform tables no longer leave blank virtualized regions, + lose expanded-row scrolling, or move touch gestures away from the page. +- Notification configuration no longer returns the stored Apprise API key to + the browser after it has been saved. + +## Release Qualification + +- The v6 control plane reports all 44 readiness assertions and all 26 release + gates passed at the candidate cutoff. +- The single-build release workflow must pass its self-contained frontend, + backend, mobile-decision, immutable-candidate, container, Helm, installer, + public/private staging, and activation checks before publication. +- The release decision is `no-mobile-impact`: no Pulse Mobile API, Relay, + pairing, push, authentication, approval, or onboarding contract changed from + `v6.3.1`, and no companion upload or public mobile-store rollout is part of + this candidate. +- The changes since `v6.3.1` do not require a Pulse Mobile client change and + preserve the existing mobile, Relay, onboarding, and mobile-facing API + contracts. +- Windows Unified Agent binaries in this prerelease retain exact-SHA, checksum, + and detached-signature verification but are not Authenticode-signed. Stable + `v6.4.0` still requires the normal SignPath Authenticode lane unless a new + explicit version-bound owner decision is recorded. + +## Upgrade Notes + +Use the normal v6 install or update flow for `v6.4.0-rc.1` only when you are +comfortable testing an RC. Existing configurations remain valid and no manual +data migration is required. + +The rollback target is `v6.3.1`. The exact rollback reinstall command is: + +```bash +./scripts/install.sh --version v6.3.1 +``` + +Paid Pulse Pro, Relay, and eligible legacy customers should continue to use the +private download page and private runtime image for paid runtime features. diff --git a/docs/releases/V6_CHANGELOG_v6.4.0-rc.1.md b/docs/releases/V6_CHANGELOG_v6.4.0-rc.1.md new file mode 100644 index 000000000..07cb93a18 --- /dev/null +++ b/docs/releases/V6_CHANGELOG_v6.4.0-rc.1.md @@ -0,0 +1,55 @@ +# Pulse v6.4.0-rc.1 + +_This changelog describes the changes since `v6.3.1` included in +`v6.4.0-rc.1`._ + +## Added + +- A scheduled weekly dependency-vulnerability scan covers the Go, frontend, + integration, and GitHub Actions dependency surfaces. +- Shared platform windowing, object-drawer headers, attention sections, + technical-detail disclosures, sortable indicators, and touch-capability + helpers establish reusable infrastructure presentation contracts. + +## Changed + +- Large-estate workloads, infrastructure, storage, and platform lists render, + navigate, search, and receive live updates incrementally. +- Proxmox node search shares the workload visibility predicate, backup views + use canonical routes, and recovery pagination follows the normalized limit. +- Docker, Kubernetes, Proxmox, TrueNAS, VMware, standalone agent, + availability, alert, and storage tables share consistent density, disclosure, + drawer, and narrow-viewport behavior. +- Mobile and touch layouts retain native page scrolling and gestures while + hover-only tooltips stay disabled on touch interactions. +- Cold start preloads only the entry module's static import graph while the + import-map integrity block continues to cover every built JavaScript asset. +- Public and private release payload compilation runs once on isolated, + credential-free trusted workers and crosses an immutable artifact-identity + boundary before hosted signing or publication. + +## Fixed + +- Fixed poll intervals remain fixed when adaptive scheduling is disabled. +- Agent re-enrollment clears host-removal blocks from every owning store. +- Connection alerts respect the configured offline-alert policy. +- Reinstall and hosted enrollment preserve agent command-policy intent. +- Discovery lookups resolve known equivalent forked host identities. +- Windowed tables no longer leave blank regions, lose expanded-row scroll + ownership, or detach touch gestures from the page. +- The notifications API no longer returns the stored Apprise API key. + +## Release Metadata + +- Version: `v6.4.0-rc.1` +- Previous stable: `v6.3.1` +- Rollback target: `v6.3.1` +- Rollback command: `./scripts/install.sh --version v6.3.1` +- Promotion path: exact-SHA single-build release candidate from `main` +- Windows signing decision: the standing prerelease path publishes exact-SHA, + checksum, and detached-signature verified Windows agents without + Authenticode; stable `v6.4.0` restores mandatory SignPath signing unless a + new version-bound owner decision is recorded +- Mobile decision: `no-mobile-impact`; changes since `v6.3.1` preserve the + existing mobile, Relay, onboarding, and mobile-facing API contracts, so no + companion upload or public store rollout is required diff --git a/frontend-modern/public/docs/UPGRADE_v6.md b/frontend-modern/public/docs/UPGRADE_v6.md index d5639d3ec..302a87e4d 100644 --- a/frontend-modern/public/docs/UPGRADE_v6.md +++ b/frontend-modern/public/docs/UPGRADE_v6.md @@ -2,6 +2,11 @@ This guide covers practical upgrade steps for existing Pulse installs moving to v6. +For the current v6 release candidate packet (the current v6 support release candidate packet), see: + +- `docs/releases/RELEASE_NOTES_v6.4.0-rc.1.md` +- `docs/releases/V6_CHANGELOG_v6.4.0-rc.1.md` + For the current stable v6 packet, see: - `docs/releases/RELEASE_NOTES_v6.3.1.md` diff --git a/scripts/install-docker.sh b/scripts/install-docker.sh index 7a91bad7d..17cf7e2ff 100755 --- a/scripts/install-docker.sh +++ b/scripts/install-docker.sh @@ -6,7 +6,7 @@ set -euo pipefail SCRIPT_DIR="$(CDPATH= cd -- "$(dirname -- "$0")" && pwd)" DOCKER_IMAGE_REPO="${DOCKER_IMAGE_REPO:-rcourtman/pulse}" -CANONICAL_DEFAULT_PULSE_VERSION="6.3.1" +CANONICAL_DEFAULT_PULSE_VERSION="6.4.0-rc.1" resolve_default_pulse_version() { if [ -n "${PULSE_IMAGE_VERSION:-}" ]; then diff --git a/scripts/installtests/build_release_assets_test.go b/scripts/installtests/build_release_assets_test.go index 86978e793..e0cbe1bb1 100644 --- a/scripts/installtests/build_release_assets_test.go +++ b/scripts/installtests/build_release_assets_test.go @@ -885,15 +885,16 @@ func TestCurrentPrereleasePacketTracksInstallMetadata(t *testing.T) { "`v"+version+"` is a release candidate", "## Highlights", "stable `v"+previous+"`", - "Patrol now works from durable outcomes, scoped investigations", - "Read-only observers extend Patrol coverage between full model investigations without granting mutation authority.", - "Actions and Patrol identify whether a decision originated from a finding, alert, objective, or explicit operator request", - "Action refusal telemetry now classifies target changes, prerequisites, contract failures", - "Subscription-backed turns now complete their idle timeout promptly", - "Platform pages now lead with estate totals, status facets, and search that share the same predicates as their underlying tables.", - "Notification settings show the outcome of real delivery attempts instead of relying on test sends as a proxy for live delivery health.", - "Docker-in-LXC discovery is explicitly controlled and backs off against slow or failing Proxmox hosts instead of creating a probe storm.", - "Unified Agent installs can opt into a supported least-privilege profile with narrowly scoped elevation for the capabilities that require it.", + "Large estates render, scroll, search, and update incrementally", + "Infrastructure tables and drawers share consistent desktop, mobile, touch, sorting, density, and navigation behavior.", + "Monitoring and agent re-enrollment fixes preserve configured polling, offline policy, command intent, and resource visibility.", + "weekly scheduled dependency-vulnerability scan", + "Shared windowed platform-list primitives", + "Workload, Proxmox, infrastructure, and storage views use incremental navigation, virtualized rows, stable scroll ownership", + "the frontend no longer modulepreloads every lazy route chunk", + "Fixed polling intervals are honored when adaptive scheduling is disabled.", + "Re-enrollment clears host-removal blocks from every owning store", + "Notification configuration no longer returns the stored Apprise API key", "The rollback target is `v"+previous+"`", "The changes since `v"+comparisonVersion+"` do not require a Pulse Mobile client change", "preserve the existing mobile, Relay, onboarding, and mobile-facing API contracts", @@ -907,13 +908,13 @@ func TestCurrentPrereleasePacketTracksInstallMetadata(t *testing.T) { "Rollback target: `v"+previous+"`", "Promotion path: exact-SHA single-build release candidate from `main`", "This changelog describes the changes since `v"+comparisonVersion+"`", - "Durable, scoped Patrol objectives and validated read-only observer missions", - "A primary Actions workspace for approvals, governed plans, and action records", - "Typed Unified Agent action preflight for supported host and Docker operations", - "Stable pre-mutation refusal codes and fleet telemetry buckets", - "Estate summaries, status facets, and canonical search on the primary infrastructure platform pages", - "A seven-day delivery log for real alert notification attempts", - "A supported least-privilege Unified Agent installation profile", + "scheduled weekly dependency-vulnerability scan", + "Shared platform windowing, object-drawer headers, attention sections", + "Large-estate workloads, infrastructure, storage, and platform lists render, navigate, search, and receive live updates incrementally.", + "Cold start preloads only the entry module's static import graph", + "Fixed poll intervals remain fixed when adaptive scheduling is disabled.", + "Agent re-enrollment clears host-removal blocks from every owning store.", + "The notifications API no longer returns the stored Apprise API key.", "Windows signing decision: the standing prerelease path publishes exact-SHA, checksum, and detached-signature verified Windows agents without Authenticode; stable `v"+stableTarget+"` restores mandatory SignPath signing", "Mobile decision: `no-mobile-impact`", "changes since `v"+comparisonVersion+"` preserve the existing mobile, Relay, onboarding, and mobile-facing API contracts", diff --git a/scripts/installtests/install_docker_sh_test.go b/scripts/installtests/install_docker_sh_test.go index c6b9a8c7e..99a4b627c 100644 --- a/scripts/installtests/install_docker_sh_test.go +++ b/scripts/installtests/install_docker_sh_test.go @@ -141,6 +141,7 @@ func TestPreviousStableForPrereleaseVersionCrossesMinorBoundaries(t *testing.T) {version: "6.2.2-rc.3", want: "6.2.1"}, {version: "6.3.0-rc.1", want: "6.2.1"}, {version: "6.3.0-rc.2", want: "6.2.1"}, + {version: "6.4.0-rc.1", want: "6.3.1"}, } for _, test := range tests { @@ -367,7 +368,7 @@ func TestInstallDockerProofTracksPrereleaseContract(t *testing.T) { assertFileContainsAllNormalized(t, repoFile("docs", "release-control", "v6", "internal", "subsystems", "deployment-installability.md"), "The active prerelease `v"+version+"` cut sets the repo-root `VERSION`, repo-root `docker-compose.yml` image default, `scripts/install-docker.sh` fallback, and Helm chart release metadata to the same `"+version+"` release version.", - "It follows `v"+comparisonVersion+"` on the published 6.3 candidate line", + "It follows stable `v"+comparisonVersion+"` and opens the published `v"+stableTarget+"` candidate line.", "This prerelease keeps `rollback_version=v"+previous+"`, publishes a versioned public GitHub prerelease plus versioned Docker and Helm artifacts, and does not move stable/latest install pointers or stable semver aliases.", "The changes since `v"+comparisonVersion+"` do not require a Pulse Mobile client change and preserve the existing mobile, Relay, onboarding, and mobile-facing API contracts, so the server cut is classified `no-mobile-impact`; no companion upload or public mobile-store rollout is part of this candidate.", "The prerelease Windows path retains exact-SHA, checksum, and detached-signature verification without Authenticode; stable `v"+stableTarget+"` restores mandatory SignPath signing unless a new version-bound decision is recorded.",