MeshMonitor v4.17.0-rc8
Warning
This is a pre-release for testing. It is not tagged latest. Use it on a test install or with a recent backup.
Summary
This release candidate changes how the Docker image runs: every process inside the container now runs as the unprivileged node user, the image no longer ships development packages (about 0.5 GB smaller), and the base images are patched. Existing installs upgrade in place; the first start fixes the ownership of /data once. New features: Reliable PKI (off by default) sends a node your node info before an encrypted request when the last one failed, local map markers let you plan on the map without sending anything to the mesh, and MQTT settings gain a broker preset for the official Meshtastic broker. Several MQTT saves no longer turn off fields they did not show, automations warn when a step would send nothing, and the Site Planner and Map Analysis work on phones.
Features
- PKI: Reliable PKI — send node info first when a node stops answering encrypted requests, at most once an hour per node and 10 an hour per source (#5702)
- Map: local map markers, per source, never transmitted (#5717)
- MQTT: broker preset chooser with the official Meshtastic broker, plain and TLS (#5700)
Bug Fixes
- Docker: prune dev dependencies, run every process as
node, bump base images, patch runtime CVEs (#5701) - Automations: "Use suggested template", a warning when a step sends nothing, and "nothing sent" in Runs and Trace (#5716)
- Admin: a remote MQTT save keeps client proxy, map reporting and TLS, and reads encryption correctly (#5707)
- Config: a local MQTT save keeps location consent and map report settings; a precision of 0 stays 0 (#5713)
- Config: every config save updates the right cache, so a reload shows what you saved (#5714)
- Site Planner: folds after Predict on phones so the ring shows (#5698); clears the old ring on a new origin and sits beside the map controls (#5706)
- Map Analysis: tool panels stay clear of the map controls and survive a phone/desktop switch (#5710); the detail pane and time slider fit phones (#5712)
CI
- Fix the
onUserConsoleLogteardown flake that failed rc7's pipeline (#5703) - Pull test database images from
mirror.gcr.io(#5705)
Issues Resolved
#5686, #5687, #5689, #5690, #5691, #5692, #5697
Upgrade Notes
- Two new migrations: 198 (
pki_exchange_state) and 199 (map_markers). Both create empty tables. - Docker runs as
node(uid/gid 1000, or yourPUID/PGID).- The first start after upgrading fixes the ownership of
/dataonce and records it; later starts only check the top level. On a large volume the first start takes longer.MESHMONITOR_FORCE_CHOWN=truere-runs the pass. - USB serial devices: the entrypoint grants
nodethe group of each mapped/dev/ttyUSB*//dev/ttyACM*automatically. If you start the container withuser:, add the device's group withgroup_addinstead. cap_drop: [ALL]now needsuser:as well.RUN_AS_ROOT=truerestores the old behaviour while you troubleshoot.- Helm:
runAsGroupandfsGroupChangePolicy: OnRootMismatchare set. The LXC template is unchanged. - See Upgrading to 4.17 in the Updating docs.
- The first start after upgrading fixes the ownership of
- Reliable PKI is off. Turn it on under Global Settings → Security, or per source under that source's Settings. Each priming NodeInfo uses airtime: at most one per node per hour, and at most 10 per source per hour.
- Automations: saving an automation whose message, notification or tapback is empty now asks "Save anyway?". Saved automations are not changed. The API's create, update and import responses carry a
warningslist. - MQTT saves: a remote-admin MQTT save is disabled until that node's MQTT config is loaded. Saves from Device Configuration and Admin Commands now send client proxy, map reporting, map report settings and location consent instead of resetting them.
- Local markers use the source's Waypoints permission: read to see, write to add or edit. Limit 1,000 per source.
- Map controls fold out of the way when the window narrows to phone width.
Thanks
Thanks to NullVoid on Discord for the local markers and empty-template reports.
Full changelog: v4.17.0-rc7...v4.17.0-rc8
🚀 MeshMonitor v4.17.0-rc8
📦 Installation
Docker (recommended):
docker run -d \
--name meshmonitor \
-p 8080:3001 \
-v meshmonitor-data:/data \
ghcr.io/Yeraze/meshmonitor:4.17.0-rc8🧪 Testing
✅ All tests passed
✅ TypeScript checks passed
✅ Docker images built for linux/amd64, linux/arm64, linux/arm/v7
📋 Changes
See commit history for detailed changes.