github LanternOps/breeze v0.88.0

latest releases: v0.121.1-hotfix.2, v0.121.1-hotfix.1, v0.121.0...
3 months ago

Breeze RMM v0.88.0 — self-hosted UniFi controllers, EDR-aware incident response, and exclusive Windows Update control.

Summary

  • Networking — Breeze can now manage a self-hosted UniFi Network controller (one VM serving many customer sites) entirely through an on-LAN agent, with no UniFi cloud key, and fans that one controller out to many orgs for inventory and telemetry (#2097). Network-discovered devices get a native detail page (#1998), and DNS Security gains a Pi-hole v6 client (#2069).
  • Patch management — a Configuration Policy toggle lets you manage Windows Update exclusively through Breeze, suppressing the OS's native auto-install channel so updates only flow through your approval rings (#2079). Windows Update scanning is more accurate: correct category classification, populated release dates, and firmware/driver-only sources now fail loud instead of silently doing nothing (#2118, #2114, #2116, #2119).
  • Incident response — the Incidents page is now EDR-aware, rendering a unified feed that unions live EDR detections with tracked incident records, with deep links back to the originating EDR console (#2095).
  • MSP workflows — Security & Compliance Posture report in the UI (#2087), partner-wide ("all orgs") config-policy ownership (#2064), maintenance-window reboots for pending-reboot devices (#2096), plus billing/contracts and ticketing polish.

Added

  • Self-hosted UniFi controller support — agent-mediated, no cloud key; one controller → many customer orgs for inventory and deep telemetry (#2097)
  • EDR-aware Incidents page — new GET /incidents/feed unions live EDR detections with tracked incidents, severity-ranked, with EDR console link-out (#2095)
  • Exclusive Windows Update source — Patches-tab toggle "Manage Windows Update exclusively through Breeze" so updates flow only through Breeze's rings (#2079)
  • Native detail page for network-discovered devices — richer view for assets found via network discovery (#1998)
  • Pi-hole v6 DNS Security client — REST API integration for Pi-hole v6 (#2069)
  • Security & Compliance Posture report — now exposed in the UI (#2087)
  • Software detection rules for .exe/.msi deployments, plus a reboot-code fix (#2088)
  • Maintenance-window reboots — optionally reboot devices with a pending reboot during their maintenance window (#2096)
  • Ticketing: drop-unknown-sender & DMARC-fail drop — new drop mode for unmatched senders and a drop-on-verification-failure toggle; inbound review queue moved into the Tickets tab (#2105)
  • Catalog AI enrichment on distributor imports plus a "Polish with AI" helper (#2081)
  • Partner-wide config-policy ownership — "all orgs" owner option when creating a config policy (#2064)
  • Elastic Defend recognized as an antivirus provider (#2068)
  • PAM signer thumbprint pinning — match by certificate thumbprint, not just subject CN (#2080)
  • Contracts — prefill the Pax8 sell price in the subscription-link modal (#2084)
  • Billing — full-width, expandable line-description boxes for quotes and invoices (#2072)

Improved

  • Ticketing — partner-level SLAs surfaced in Priorities settings, with a corrected precedence note (#2076)
  • Agent update policy — mode labels relabeled to match actual behavior (#2086)
  • Inbound email — trust real Mailgun inbound MX authserv-ids and scan all Authentication-Results headers (#2099)
  • Network inventory — interface_name widened from varchar(100) to text for long interface names (#2065)

Fixed

  • AI patch tooling — manage_patches list is now scoped to the tenant/device instead of the global catalog (#2115)
  • Patch categories — reconcile ring definition category with the agent's definitions, and classify Windows Update categories from all WUA categories (#2119, #2118)
  • Alerts — resolved alerts are no longer un-muteable; added a "Forever" suppression option and an expiry reaper (#2110)
  • MCP org-scoped keys — resolve the owning partner under system context, and resolve a membership-less Partner Admin role (#2108, #2109, #2104)
  • Config policy — ownership reconciled with the Assignments tab, and web FeatureType parity enforced against the canonical list (#2107, #2070)
  • UniFi (cloud) — corrected Site Manager API integration: parsing, paths, mapping UX, and a safe replace-all (#2103)
  • Reports — GET /reports/templates implemented (was 500ing via a /:id uuid cast) (#2102)
  • Devices — Connect Desktop & Power actions disabled for offline devices (#2077)
  • Security providers — match Bitdefender before Defender in provider detection (#2085)
  • API keys — API-key auth can now write device custom-field values (#2071)

Security

  • PAM — pin certificate thumbprint for signer matching, hardening rule evaluation against subject-CN spoofing (#2080)
  • Tenant isolation — AI manage_patches list scoped to tenant/device rather than the global catalog (#2115)
  • Dependencies — bump anyhow to 1.0.103 (RUSTSEC-2026-0190) (#2073)

Self-hosters are encouraged to upgrade.

Self-Hosting / Upgrade Notes

Upgrade command. Bump BREEZE_VERSION=0.88.0 in your .env, then:

docker compose pull api web && docker compose up -d

(If you build from source, run pnpm install first.)

Database — 12 migrations, idempotent, auto-apply on boot via autoMigrate (unless AUTO_MIGRATE=false). All are additive and fast: ADD COLUMN IF NOT EXISTS (metadata-only defaults), two varchar(100)→text widenings (no table rewrite in Postgres), one new RLS-protected table (unifi_controller_sites), and one small partial index on suppressed alerts. No backfills or full-table rewrites — no long stall on boot.

No new required environment variables. The config validator is unchanged this release.

Behavior changes & feature flags.

  • Exclusive Windows Update (#2079) — gated behind a new Configuration Policy toggle, "Manage Windows Update exclusively through Breeze," which defaults OFF. Existing policies are unaffected (grandfathered). When enabled, the Windows agent sets NoAutoUpdate=1 under HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU to suppress the OS auto-install channel; Breeze's own ring-based installs continue as normal.
  • Ticketing unknown-sender handling (#2105) — the default remains quarantine (review queue), so behavior is unchanged unless you opt into the new drop mode. The new dropUnverifiedSenders (SPF/DKIM/DMARC-fail drop) toggle also defaults off.

No breaking changes.

Full Changelog: v0.87.0...v0.88.0

What's Changed

Full Changelog: v0.87.0...v0.88.0

Don't miss a new breeze release

NewReleases is sending notifications on new releases.