github LanternOps/breeze v0.85.0

latest releases: v0.120.0, v0.119.0, v0.118.2...
3 months ago

Breeze RMM v0.85.0 — a feature release: one-click Huntress & SentinelOne EDR deployment, a Software Deployment automation action, a "Breeze Defaults" config-policy baseline, billing/catalog polish (markup defaults, catalog images, quote line editing, tax precision), and a substantial reliability-scoring overhaul that makes fault scores actually discriminate between healthy and unhealthy devices.

Summary

  • EDR deployment — built-in Huntress & SentinelOne deployment packages: push the EDR agent to a device from Breeze instead of hand-rolling an installer (#1957).
  • Automations — a new Software Deployment action type, so automations can install software as a step (#1981).
  • Config policy — a virtual "Breeze Defaults" baseline that every policy inherits from, so you can see and override the shipped defaults (#1725).
  • Billing & catalog — partner markup defaults, catalog item images, inline quote-line editing, and a tax-rate precision fix (#1960).
  • Reliability — fault scoring is now rate-normalized by observed up-days and no longer saturates, plus the agent correctly classifies Windows events instead of mislabeling DCOM timeouts as crashes and the whole System log as "hardware" (#1989, #1967).
  • Alerting — metric alerts average across the window instead of requiring every sample, and config-policy offline rules honor their per-rule duration (#1988, #1992).

Added

  • Built-in Huntress & SentinelOne deployment packages — deploy the EDR agent to devices directly from Breeze (#1957)
  • Software Deployment automation action — install software as an automation step (#1981)
  • Config-policy "Breeze Defaults" baseline — a virtual baseline policy showing the shipped defaults, inheritable and overridable (#1725)
  • Billing/catalog: partner markup defaults, catalog item images, inline quote-line editing (#1960)
  • Agent self-heal: an AI tool that restarts a wedged agent via the watchdog (#1966)
  • Devices: a unified default sort for the merged Devices list (#1424)

Improved

  • Reliability scoring is far more accurate — scores are rate-normalized by observed up-days and de-saturated, so a device with 14 faults no longer scores the same as one with 1,400; and the agent now classifies Windows events correctly (DCOM timeouts are no longer counted as crashes, and the System log is no longer blanket-tagged "hardware") (#1989, #1967) — scores will shift once the new agent is promoted; see upgrade notes
  • Metric alerts average across the evaluation window instead of firing only when every sample breaches (#1988)
  • Config-policy offline alert rules honor their per-rule duration and cap it at the re-eval horizon (#1992, #1996)
  • Agent-update maintenance window is now a structured, validated field instead of free text (#1963)
  • Patches page tab state moved to #hash — back button and shareable links work (#1977)

Fixed

  • Tax-rate precision: tax rates are stored at numeric(8,5) so fractional rates round-trip correctly (#1960)
  • Onboarding: the "add your first site" nag is suppressed once an org already has a site (#1978)
  • Auth: /auth#signup is gated on the runtime registration flag (#1979)
  • Billing: corrected tooltip on the disabled Record payment button (#1975)
  • Installer: MSI filename-bootstrap token uses parentheses, not brackets, so it survives MSI's Formatted-field parsing (#1956)
  • Self-hosting compose: CLIENT_AI_ENTRA_CLIENT_ID is mapped into the api service; removed a stale postcss.config.mjs bind mount from the dev stacks (#1972, #1999)

Security & Privacy

  • Scrubbed real customer device data from tracked files (#1968); suppressed documented pnpm install-time CVEs in Trivy with rationale (#1970); enabled the DB_CONTEXTLESS_WRITE_STRICT check suite-wide to catch un-scoped DB writes in CI (#1828).

Self-Hosting / Upgrade Notes

Standard upgrade — bump BREEZE_VERSION, then docker compose pull api web && docker compose up -d (run pnpm install if you build from source).

  • Database — applies automatically, nothing required. 8 new idempotent migrations apply on boot (autoMigrate, unless AUTO_MIGRATE=false): software-catalog partner axis + built-in-catalog partner-read RLS, S1 org-mappings registration token, Huntress deploy account key (stored encrypted, not an env var), partner auto-tax/hardware + default markup, catalog item images, and a tax-rate precision change (ALTER COLUMN … TYPE numeric(8,5) on the small tax-rate tables — instant, no large-table rewrite or backfill).
  • No new required environment variables. If you run Breeze AI for Office, note that CLIENT_AI_ENTRA_CLIENT_ID is now mapped into the api service in the compose file (#1972) — set it in .env if you use that feature; it's optional and defaults to empty otherwise.
  • Behavior change — reliability scores will move (#1967, #1989). Once you promote the new agent, Windows event classification and the scoring formula both change, so device reliability scores will look different (generally more spread out and more accurate). This is expected — it's a correctness fix, not a regression. Until the agent is promoted, behavior is unchanged.
  • No breaking changes.

Full Changelog: v0.84.0...v0.85.0


What's Changed

Full Changelog: v0.84.0...v0.85.0

Don't miss a new breeze release

NewReleases is sending notifications on new releases.