Fledge v0.9.1.1 "Mews"
Opt-in Linux KVM/libvirt virtual machines join explained account suspensions, delegated administrator access and an optional built-in help desk. A mews is where falcons are kept while they moult: looked after while they are not flying.
Added
- Account suspension. Six reasons, a customer-visible host message, an internal note, a random reference, history and scheduled or payment-based lifting. Suspended customers can sign in to billing, security, data export and permitted deletion, with an urgent ticket-backed appeal. Dark, light and mobile layouts use the existing theme and branding.
- Safe server holds. Stopping uses ordinary node jobs. Account, billing and administrator holds remain independent; only previously running account-held servers restart on lift. Paid provisioning waits until the account is released. SFTP, console streams, API tokens, schedules, placement and failover respect the hold.
- Team. Exactly one super administrator, invitations, live permission switches and presets, revocation, a password-and-fresh-factor email transfer, and an audited shell recovery command. Unknown administrative routes fail closed; token scopes intersect live grants.
- Optional help desk. Customer tickets and articles; an agent queue with search, filters, unread markers, pagination, keyboard navigation and bulk actions; public replies, private notes, attachments, drafts, macros, presence warnings, linked tickets and panel context. Suspension appeals work independently of the general desk.
- Service goals. Standard, Priority and Urgent tiers; timezone-aware business windows and holidays; deadlines pause while waiting for the customer. Plans can grant Priority. Ordered automation rules support conditions and multiple actions, with a visible run history.
- Operations. Thirty-day reports, CSV and Prometheus series; editable mail templates and normal notification channels; a bot-protected public abuse form; configurable ticket retention, export and anonymisation. Signed inbound email is an opt-in bridge endpoint, disabled without a configured secret.
- Documentation, permission reference, API reference and a repeatable screenshot/browser workflow covering the shipped screens.
Upgrade
Follow the upgrade guide. The additive schema is rerunnable. The oldest active, unblocked administrator becomes the super administrator, and other existing administrators keep full grants. Block sign-in keeps the existing hard-lock behavior.
The help desk, public articles, abuse reporting, whole-account billing suspension and automatic retention deletion are off by default. Review Team and support setup before enabling them. Suspension appeals have a separate switch. Retention normally reminds administrators; destructive retention must be explicitly enabled and uses the existing deletion cooling period.
For Stripe, suspended customers need a separately configured restricted portal configuration. If the provider cannot supply a restricted portal, Fledge refuses that portal and preserves invoice payment links. Upgrade the panel and node agent together.
Verified
- API, web and plugin-host TypeScript checks; web production build.
- Mews unit and integration suites against disposable PostgreSQL: default-deny route matrix, tokens, console and SFTP, job guards, upgrade from the previous schema, private-note isolation, diagnostics, attachment rules, business clocks, ordered rules, retention and signed inbound reply replay protection.
- Account/billing/administrator hold interactions, invoice-gated automatic lifting and deferred paid provisioning; real SMTP transfer delivery, receiver identity, both fresh factors and single-use confirmation.
- Chrome browser flows on the shipped production panel: suspension edit/lift, customer and agent replies, private-note isolation, solving, rating, reopening and rule editing; dark, light, phone and reduced-motion screenshots.
- Public abuse submission through Cloudflare's official test widget and verification endpoint, plus rejection without a bot response.
- Documentation code-block and screenshot-reference checks, example plugin validation and production site build; landing links, new hosting tabs and mobile width.
- Linux node agent:
go vet,go testand a release binary build in an isolated Go 1.25 container. - Existing API unit, account, billing, fit, template, autopilot, Rookery, branding, plugin, Discord and updater suites; plugin-host sandbox tests.
Operational limits
Attachments are content-sniffed, size-limited and authorised on every download; there is no antivirus scanner. Diagnostics include only the console lines still retained by the panel and filter known secrets. Inbound email requires a trusted mailbox bridge; Fledge does not poll a mailbox.
Virtual machine runtime and notification completion
- Explicit immutable
container | vmruntime throughout templates, servers, jobs and hosting plan presets. Existing data defaults to containers. - Opt-in x86-64 KVM/libvirt nodes, approved hardware profiles and checksum-verified cloud/ISO/driver media; Linux cloud-init and manual Windows installation with UEFI/TPM profiles.
- Dedicated VM workspace with authenticated noVNC and serial relay, disk growth, allocated NAT ports, routed pools, stopped snapshots and backup-based offline recovery.
- Granular VM grants, holds on guest operations, bounded console traffic and live authorization checks. Optional shared Redis supports API replicas.
- Notification dialogs constrain event lists and keep actions within the viewport. Added suspension, appeal, retention, help-desk and VM events with explicit customer recipients and durable external delivery retries.
VM verification status
HTTP/PostgreSQL VM smoke checks cover placement rejection, runtime compatibility, address exhaustion, console ticket issuance, container-only API refusal, snapshot outcomes and held-account access. Linux agent unit and real guest checks are recorded during the final audit. This workspace has no /dev/kvm; software-emulated guest checks cannot establish hardware KVM behavior. Windows installation, guest Secure Boot trust/PCR behavior and provider-routed public IPs require compatible hardware verification before offering those profiles. Real QEMU/libvirt tests did verify UEFI variable and swtpm-state snapshot recovery and guest restart; they do not establish Windows or hardware KVM behavior.
