Breeze RMM v0.88.0 — self-hosted UniFi controllers, EDR-aware incident response, and exclusive Windows Update control.
Summary
- Networking — Breeze can now manage a self-hosted UniFi Network controller (one VM serving many customer sites) entirely through an on-LAN agent, with no UniFi cloud key, and fans that one controller out to many orgs for inventory and telemetry (#2097). Network-discovered devices get a native detail page (#1998), and DNS Security gains a Pi-hole v6 client (#2069).
- Patch management — a Configuration Policy toggle lets you manage Windows Update exclusively through Breeze, suppressing the OS's native auto-install channel so updates only flow through your approval rings (#2079). Windows Update scanning is more accurate: correct category classification, populated release dates, and firmware/driver-only sources now fail loud instead of silently doing nothing (#2118, #2114, #2116, #2119).
- Incident response — the Incidents page is now EDR-aware, rendering a unified feed that unions live EDR detections with tracked incident records, with deep links back to the originating EDR console (#2095).
- MSP workflows — Security & Compliance Posture report in the UI (#2087), partner-wide ("all orgs") config-policy ownership (#2064), maintenance-window reboots for pending-reboot devices (#2096), plus billing/contracts and ticketing polish.
Added
- Self-hosted UniFi controller support — agent-mediated, no cloud key; one controller → many customer orgs for inventory and deep telemetry (#2097)
- EDR-aware Incidents page — new
GET /incidents/feedunions live EDR detections with tracked incidents, severity-ranked, with EDR console link-out (#2095) - Exclusive Windows Update source — Patches-tab toggle "Manage Windows Update exclusively through Breeze" so updates flow only through Breeze's rings (#2079)
- Native detail page for network-discovered devices — richer view for assets found via network discovery (#1998)
- Pi-hole v6 DNS Security client — REST API integration for Pi-hole v6 (#2069)
- Security & Compliance Posture report — now exposed in the UI (#2087)
- Software detection rules for
.exe/.msideployments, plus a reboot-code fix (#2088) - Maintenance-window reboots — optionally reboot devices with a pending reboot during their maintenance window (#2096)
- Ticketing: drop-unknown-sender & DMARC-fail drop — new
dropmode for unmatched senders and a drop-on-verification-failure toggle; inbound review queue moved into the Tickets tab (#2105) - Catalog AI enrichment on distributor imports plus a "Polish with AI" helper (#2081)
- Partner-wide config-policy ownership — "all orgs" owner option when creating a config policy (#2064)
- Elastic Defend recognized as an antivirus provider (#2068)
- PAM signer thumbprint pinning — match by certificate thumbprint, not just subject CN (#2080)
- Contracts — prefill the Pax8 sell price in the subscription-link modal (#2084)
- Billing — full-width, expandable line-description boxes for quotes and invoices (#2072)
Improved
- Ticketing — partner-level SLAs surfaced in Priorities settings, with a corrected precedence note (#2076)
- Agent update policy — mode labels relabeled to match actual behavior (#2086)
- Inbound email — trust real Mailgun inbound MX authserv-ids and scan all
Authentication-Resultsheaders (#2099) - Network inventory —
interface_namewidened fromvarchar(100)totextfor long interface names (#2065)
Fixed
- AI patch tooling —
manage_patcheslistis now scoped to the tenant/device instead of the global catalog (#2115) - Patch categories — reconcile ring
definitioncategory with the agent'sdefinitions, and classify Windows Update categories from all WUA categories (#2119, #2118) - Alerts — resolved alerts are no longer un-muteable; added a "Forever" suppression option and an expiry reaper (#2110)
- MCP org-scoped keys — resolve the owning partner under system context, and resolve a membership-less Partner Admin role (#2108, #2109, #2104)
- Config policy — ownership reconciled with the Assignments tab, and web
FeatureTypeparity enforced against the canonical list (#2107, #2070) - UniFi (cloud) — corrected Site Manager API integration: parsing, paths, mapping UX, and a safe replace-all (#2103)
- Reports —
GET /reports/templatesimplemented (was 500ing via a/:iduuid cast) (#2102) - Devices — Connect Desktop & Power actions disabled for offline devices (#2077)
- Security providers — match Bitdefender before Defender in provider detection (#2085)
- API keys — API-key auth can now write device custom-field values (#2071)
Security
- PAM — pin certificate thumbprint for signer matching, hardening rule evaluation against subject-CN spoofing (#2080)
- Tenant isolation — AI
manage_patcheslistscoped to tenant/device rather than the global catalog (#2115) - Dependencies — bump
anyhowto 1.0.103 (RUSTSEC-2026-0190) (#2073)
Self-hosters are encouraged to upgrade.
Self-Hosting / Upgrade Notes
Upgrade command. Bump BREEZE_VERSION=0.88.0 in your .env, then:
docker compose pull api web && docker compose up -d(If you build from source, run pnpm install first.)
Database — 12 migrations, idempotent, auto-apply on boot via autoMigrate (unless AUTO_MIGRATE=false). All are additive and fast: ADD COLUMN IF NOT EXISTS (metadata-only defaults), two varchar(100)→text widenings (no table rewrite in Postgres), one new RLS-protected table (unifi_controller_sites), and one small partial index on suppressed alerts. No backfills or full-table rewrites — no long stall on boot.
No new required environment variables. The config validator is unchanged this release.
Behavior changes & feature flags.
- Exclusive Windows Update (#2079) — gated behind a new Configuration Policy toggle, "Manage Windows Update exclusively through Breeze," which defaults OFF. Existing policies are unaffected (grandfathered). When enabled, the Windows agent sets
NoAutoUpdate=1underHKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AUto suppress the OS auto-install channel; Breeze's own ring-based installs continue as normal. - Ticketing unknown-sender handling (#2105) — the default remains
quarantine(review queue), so behavior is unchanged unless you opt into the newdropmode. The newdropUnverifiedSenders(SPF/DKIM/DMARC-fail drop) toggle also defaults off.
No breaking changes.
Full Changelog: v0.87.0...v0.88.0
What's Changed
- docs: sync technical docs for v0.87.0 by @ToddHebebrand in #2063
- chore(addins,viewer): migrate Office add-ins + viewer to Tailwind 4 (#2057) by @ToddHebebrand in #2067
- fix(security): bump anyhow to 1.0.103 (RUSTSEC-2026-0190) by @ToddHebebrand in #2073
- fix(docs): upgrade docs site to Astro 7 (fixes Cloudflare Pages build) by @ToddHebebrand in #2074
- feat(dns-security): add Pi-hole v6 REST API client (#2017) by @ToddHebebrand in #2069
- fix(api): allow API-key auth to write device custom-field values (#2066) by @ToddHebebrand in #2071
- feat(pam): pin cert thumbprint for signer matching, not just subject CN (#1776) by @ToddHebebrand in #2080
- fix(api): widen interface_name from varchar(100) to text (#2006) by @ToddHebebrand in #2065
- feat(security): recognize Elastic Defend as an antivirus provider (#2018) by @ToddHebebrand in #2068
- fix(agent): match bitdefender before defender in providerFromName (#2075) by @ToddHebebrand in #2085
- chore(deps): bump cloud.google.com/go/storage from 1.62.3 to 1.63.0 in /agent by @dependabot[bot] in #2094
- chore(deps): bump github.com/pion/webrtc/v4 from 4.2.15 to 4.2.16 in /agent by @dependabot[bot] in #2093
- chore(deps): bump the aws-sdk group in /agent with 4 updates by @dependabot[bot] in #2091
- feat(web): native detail page for network-discovered devices — #1424 slice 2 of 4 by @ToddHebebrand in #1998
- fix(web): relabel agent update policy modes to match actual behavior (#1962) by @ToddHebebrand in #2086
- feat(reports): expose Security & Compliance Posture report in the UI by @ToddHebebrand in #2087
- feat(software): detection rules for .exe/.msi deploys + reboot-code fix (#2022) by @ToddHebebrand in #2088
- fix(config): enforce web FeatureType parity with canonical CONFIG_FEATURE_TYPES (#2004) by @ToddHebebrand in #2070
- feat(web): partner-wide ("all orgs") owner option on config policy create by @ToddHebebrand in #2064
- fix(web): disable Connect Desktop & Power for offline devices (#2013) by @ToddHebebrand in #2077
- fix(tickets): surface partner-level SLAs in Priorities settings + correct precedence note by @ToddHebebrand in #2076
- feat(billing): full-width, expandable line description boxes for quotes & invoices by @ToddHebebrand in #2072
- feat(contracts): prefill Pax8 sell price in subscription-link modal by @ToddHebebrand in #2084
- chore(deps): bump github.com/pion/rtcp from 1.2.16 to 1.2.17 in /agent by @dependabot[bot] in #2092
- feat(maintenance): reboot devices with a pending reboot during maintenance windows by @ToddHebebrand in #2096
- feat(patches): enforce Breeze as sole Windows Update source (#1872) by @ToddHebebrand in #2079
- feat(catalog): AI enrichment on distributor imports + "Polish with AI" helper by @ToddHebebrand in #2081
- feat(unifi): self-hosted controller support (agent-mediated, no cloud key) by @ToddHebebrand in #2097
- feat(incidents): EDR-aware Incidents page with unified feed by @ToddHebebrand in #2095
- fix(tenancy): enroll unifi_controller_sites in ORG_CASCADE_DELETE_ORDER by @ToddHebebrand in #2106
- fix(inbound-email): trust real Mailgun inbound MX authserv-ids + scan all Authentication-Results headers by @ToddHebebrand in #2099
- fix(reports): implement GET /reports/templates (was 500 via /:id uuid cast) (#2100) by @ToddHebebrand in #2102
- fix(unifi): correct cloud Site Manager API integration (parsing, paths, mapping UX, safe replace-all) by @ToddHebebrand in #2103
- fix(mcp): resolve membership-less Partner Admin role on org-scoped MCP keys (#2019) by @ToddHebebrand in #2104
- feat(ticketing): drop-unknown-sender mode + DMARC-fail drop; inbound review queue → Tickets tab by @ToddHebebrand in #2105
- fix(config): reconcile config-policy ownership with the Assignments tab by @ToddHebebrand in #2107
- fix(mcp): resolve owning partner for org-scoped keys under system context (#2108) by @ToddHebebrand in #2109
- fix(alerts): unmuteable resolved alerts + "Forever" suppression + expiry reaper by @ToddHebebrand in #2110
- fix(agent): populate releaseDate on Windows Update scan path by @ToddHebebrand in #2114
- fix(shared): reject firmware/drivers-only patch sources (fail loud) by @ToddHebebrand in #2116
- fix(agent): classify Windows Update categories from all WUA categories by @ToddHebebrand in #2118
- fix(patch): reconcile ring 'definition' category with agent 'definitions' by @ToddHebebrand in #2119
- fix(api): scope AI manage_patches 'list' to tenant/device, not the global catalog by @ToddHebebrand in #2115
- fix(helper): declare own tailwindcss/autoprefixer/postcss devDeps by @ToddHebebrand in #2120
Full Changelog: v0.87.0...v0.88.0