github LanternOps/breeze v0.84.0

latest releases: v0.121.0, v0.120.0, v0.119.0...
3 months ago

Breeze RMM v0.84.0 — a feature release: catalog/quoting gets distributor + Pax8 + AI assists, billing gains bulk actions, an EDR operations surface (SentinelOne + Huntress) lands behind a flag, native ticket auto-replies & canned responses, a working HTTP network proxy, plus reliability, patching, and broad API security hardening.

Summary

  • Quoting & catalog — inline TD SYNNEX EC Express price/availability lookup in the quote editor (#1922), a Pax8 subscription → contract-line picker (#1924), and AI auto-fill for new catalog items from a product name or SKU (#1942).
  • Billing — bulk actions across quotes, invoices, and contracts, plus draft delete from the detail view (#1926).
  • EDR operations (preview) — SentinelOne + Huntress threat/incident surfacing across the fleet, behind a feature flag (#1946).
  • Ticketing — customizable auto-reply and reusable canned responses (#1931).
  • Networking — a working HTTP reverse Network Proxy with a reworked discovery asset modal (#1913), and per-session TLS verification for the tunnel proxy (#1916).
  • Endpoint management — Windows USB blocking enforcement with no kernel driver (#1871), MSI filename-bootstrap enrollment for Windows parity (#1902), and per-device config-policy compliance shown on the device detail page (#1895).
  • Reliability & patching — saner reliability scoring (capped counts, age-aware windows, offender drill-down, de-duplicated events) and patch-list/update-ring fixes.
  • Security hardening — a cluster of API authorization, session-revocation, and secrets-at-rest improvements.

Added

  • Inline TD SYNNEX EC Express price & availability lookup by SKU inside the quote editor (#1922)
  • Pax8 subscription → contract-line picker: link, change, pause, and unlink (#1924)
  • AI catalog auto-fill — draft a new catalog item's fields from a product name or SKU (#1942)
  • Stripe payment keys now live in Integrations → Payments instead of buried in billing settings (#1954)
  • Billing bulk actions on quotes / invoices / contracts, plus draft delete on the detail view (#1926)
  • EDR operations (preview) — SentinelOne + Huntress threats/incidents across the fleet, behind a feature flag (#1946)
  • Ticket auto-reply + canned responses — customizable templated replies with merge variables (#1931)
  • Network Proxy — working HTTP reverse proxy, with a reworked discovery asset modal (#1913)
  • Windows USB blocking enforcement — no kernel driver required (#1871)
  • Per-device config-policy compliance section on the device detail page (#1895)
  • MSI filename-bootstrap enrollment for Windows installer parity (#1902)
  • Reliability card: offender drill-down with age-aware windows and capped alarming counts (#1907, #1921)
  • Viewer: interactive update prompt instead of a silent auto-close (#1909)

Improved

  • PAM: UAC interception now defaults to opt-in for new orgs; existing active orgs are grandfathered to their current behavior (#1914) — see upgrade notes
  • Remote Tools shows all services and has reliable Close / Back navigation (#1911)
  • Tunnel proxy now does per-session TLS verification with an explicit scheme (#1916)
  • Software Library loads correctly in "All Orgs" mode (aggregates across accessible orgs) (#1938)
  • Network Changes has a clearer empty state that points to creating a discovery profile (#1940)
  • Background sync/scheduler work split out of DB transactions to reduce connection pressure during S1 sync and patch scheduling (#1919)

Fixed

  • Patches: selecting an update ring no longer collapses the patch list to 50 items (#1897)
  • Patches: duplicate identical "Default" update rings are de-duplicated (#1939)
  • Reliability: stopped ~1.37× count inflation from events double-counted across the window (#1904, #1905); agent now persists its reliability send cadence across restarts (#1912)
  • Config Policy: Monitoring tab rendering fixed (no more invalid nested controls) (#1937)
  • Catalog: the item drawer blocks saving a bundle when the detail load fails (prevents wiping components) (#1944, #1947); enrichment attributes are shape-validated on create (#1945, #1948)
  • Peripherals: stop shipping an empty policy set on an enqueue-before-commit race (#1882)
  • Database: partner-scope ring/approval migrations are now safe to re-run (#1941)

Security

  • Hardening across the API: additional authorization/authentication gates (RBAC, step-up, signing capabilities), fail-closed mid-session revocation for the tunnel and event WebSockets, tighter cross-org/partner access boundaries, and webhook URLs encrypted at rest and masked on read (#1887, #1888, #1890, #1891, #1892, #1893). Self-hosters are encouraged to upgrade.

Self-Hosting / Upgrade Notes

Standard upgrade — bump BREEZE_VERSION, then docker compose pull api web && docker compose up -d (run pnpm install if you build from source).

  • Database — nothing required. 7 new idempotent migrations apply automatically on boot (autoMigrate, unless AUTO_MIGRATE=false): ticket response templates, tunnel per-session TLS verification, the partner-scope update-ring/approval guards + default-ring de-dup, installer bootstrap-token platform column, and the PAM UAC opt-in grandfathering. No large-table rewrites or backfills.
  • Behavior change — PAM UAC interception (#1914): new organizations default to opt-in for UAC interception. Organizations already active keep their existing behavior (grandfathered). If you rely on UAC interception for a newly-created org, enable it explicitly.
  • EDR operations is a preview behind a flag. It's gated by the web build-time flag PUBLIC_ENABLE_EDR_INTEGRATIONS (off by default). With it off, the fleet EDR pages and dashboard summary are hidden. No server env vars are required for the rest of the release.
  • No new required environment variables.

Full Changelog: v0.83.3...v0.84.0

What's Changed

Full Changelog: v0.83.3...v0.84.0

Don't miss a new breeze release

NewReleases is sending notifications on new releases.