Breeze RMM v0.83.1 — the first stable release of the v0.83 line. A hotfix over the v0.83.0 pre-release that unbreaks MFA-required login (a node base-image change had stopped /auth/refresh from round-tripping its cookie under Caddy HTTP/2) and adds an opt-in control to decouple agent-binary publishing from fleet-wide rollout.
Fixes
- fix(docker): revert node base image
156b55f→fb71d01(#1845) — the 0.83.0 node base-image bump was the runtime cause of a forced-MFA enrollment regression where/auth/refreshstopped round-tripping its rotated cookie under Caddy HTTP/2, stranding MFA-required users at login. - fix(auth): forced-MFA enrollment resilience (#1844) — the enrollment page now restores its token on mount and fails closed to a clean re-login instead of firing a request with no Authorization header.
Features
- feat(agents): explicit fleet-rollout promotion (#1846) — new
AGENT_AUTO_PROMOTEflag (defaulttruefor self-host). Whenfalse,binarySynckeeps binaries downloadable but no longer auto-promotes the newest release to the fleet upgrade target; promotion becomes an explicit, audited, MFA-gated platform-admin action (POST /agent-versions/promote). Prevents publishing a release from triggering an uncontrolled fleet-wide agent update.
Self-Hosting / Upgrade Notes
Standard upgrade — bump BREEZE_VERSION, then docker compose pull api web && docker compose up -d. No new migrations and no compose changes.
- Strongly recommended if you deployed v0.83.0. The node base-image bump in v0.83.0 stranded MFA-required users at login under Caddy HTTP/2; this release reverts it (#1845) and hardens the enrollment page to fail closed to a clean re-login (#1844).
- New optional env var
AGENT_AUTO_PROMOTE(defaulttrue; see.env.example). Leave it at the default and behavior is unchanged — registering/syncing a release immediately becomes the fleet upgrade target. Set it tofalseto keep new agent binaries downloadable but require an explicit, audited, MFA-gatedPOST /api/v1/agent-versions/promote { "version": "x.y.z" }before the fleet moves — useful if you want to stage and verify an agent build before it rolls out. As always, if you set it, map it through theapiserviceenvironment:block of your compose file.
Full range: v0.83.0...v0.83.1
What's Changed
- fix(docker): revert node base image to fb71d01 (0.83.1 hotfix) by @ToddHebebrand in #1845
- feat(agents): explicit fleet-rollout promotion (decouple registration from isLatest) by @ToddHebebrand in #1846
- fix(auth): repair forced-MFA enrollment authorization (0.83.1 hotfix) by @ToddHebebrand in #1844
Full Changelog: v0.83.0...v0.83.1