github LanternOps/breeze v0.83.1

latest releases: v0.118.2, v0.118.1, v0.118.0...
3 months ago

Breeze RMM v0.83.1 — the first stable release of the v0.83 line. A hotfix over the v0.83.0 pre-release that unbreaks MFA-required login (a node base-image change had stopped /auth/refresh from round-tripping its cookie under Caddy HTTP/2) and adds an opt-in control to decouple agent-binary publishing from fleet-wide rollout.

Fixes

  • fix(docker): revert node base image 156b55f → fb71d01 (#1845) — the 0.83.0 node base-image bump was the runtime cause of a forced-MFA enrollment regression where /auth/refresh stopped round-tripping its rotated cookie under Caddy HTTP/2, stranding MFA-required users at login.
  • fix(auth): forced-MFA enrollment resilience (#1844) — the enrollment page now restores its token on mount and fails closed to a clean re-login instead of firing a request with no Authorization header.

Features

  • feat(agents): explicit fleet-rollout promotion (#1846) — new AGENT_AUTO_PROMOTE flag (default true for self-host). When false, binarySync keeps binaries downloadable but no longer auto-promotes the newest release to the fleet upgrade target; promotion becomes an explicit, audited, MFA-gated platform-admin action (POST /agent-versions/promote). Prevents publishing a release from triggering an uncontrolled fleet-wide agent update.

Self-Hosting / Upgrade Notes

Standard upgrade — bump BREEZE_VERSION, then docker compose pull api web && docker compose up -d. No new migrations and no compose changes.

  • Strongly recommended if you deployed v0.83.0. The node base-image bump in v0.83.0 stranded MFA-required users at login under Caddy HTTP/2; this release reverts it (#1845) and hardens the enrollment page to fail closed to a clean re-login (#1844).
  • New optional env var AGENT_AUTO_PROMOTE (default true; see .env.example). Leave it at the default and behavior is unchanged — registering/syncing a release immediately becomes the fleet upgrade target. Set it to false to keep new agent binaries downloadable but require an explicit, audited, MFA-gated POST /api/v1/agent-versions/promote { "version": "x.y.z" } before the fleet moves — useful if you want to stage and verify an agent build before it rolls out. As always, if you set it, map it through the api service environment: block of your compose file.

Full range: v0.83.0...v0.83.1

What's Changed

  • fix(docker): revert node base image to fb71d01 (0.83.1 hotfix) by @ToddHebebrand in #1845
  • feat(agents): explicit fleet-rollout promotion (decouple registration from isLatest) by @ToddHebebrand in #1846
  • fix(auth): repair forced-MFA enrollment authorization (0.83.1 hotfix) by @ToddHebebrand in #1844

Full Changelog: v0.83.0...v0.83.1

Don't miss a new breeze release

NewReleases is sending notifications on new releases.