Skip to content

Fledge v0.9.1.1 "Mews" ​

Opt-in Linux KVM/libvirt virtual machines join explained account suspensions, delegated administrator access and an optional built-in help desk. A mews is where falcons are kept while they moult: looked after while they are not flying.

Added ​

  • Account suspension. Six reasons, a customer-visible host message, an internal note, a random reference, history and scheduled or payment-based lifting. Suspended customers can sign in to billing, security, data export and permitted deletion, with an urgent ticket-backed appeal. Dark, light and mobile layouts use the existing theme and branding.
  • Safe server holds. Stopping uses ordinary node jobs. Account, billing and administrator holds remain independent; only previously running account-held servers restart on lift. Paid provisioning waits until the account is released. SFTP, console streams, API tokens, schedules, placement and failover respect the hold.
  • Team. Exactly one super administrator, invitations, live permission switches and presets, revocation, a password-and-fresh-factor email transfer, and an audited shell recovery command. Unknown administrative routes fail closed; token scopes intersect live grants.
  • Optional help desk. Customer tickets and articles; an agent queue with search, filters, unread markers, pagination, keyboard navigation and bulk actions; public replies, private notes, attachments, drafts, macros, presence warnings, linked tickets and panel context. Suspension appeals work independently of the general desk.
  • Service goals. Standard, Priority and Urgent tiers; timezone-aware business windows and holidays; deadlines pause while waiting for the customer. Plans can grant Priority. Ordered automation rules support conditions and multiple actions, with a visible run history.
  • Operations. Thirty-day reports, CSV and Prometheus series; editable mail templates and normal notification channels; a bot-protected public abuse form; configurable ticket retention, export and anonymisation. Signed inbound email is an opt-in bridge endpoint, disabled without a configured secret.
  • Documentation, permission reference, API reference and a repeatable screenshot/browser workflow covering the shipped screens.

Upgrade ​

Follow the upgrade guide. The additive schema is rerunnable. The oldest active, unblocked administrator becomes the super administrator, and other existing administrators keep full grants. Block sign-in keeps the existing hard-lock behavior.

The help desk, public articles, abuse reporting, whole-account billing suspension and automatic retention deletion are off by default. Review Team and support setup before enabling them. Suspension appeals have a separate switch. Retention normally reminds administrators; destructive retention must be explicitly enabled and uses the existing deletion cooling period.

For Stripe, suspended customers need a separately configured restricted portal configuration. If the provider cannot supply a restricted portal, Fledge refuses that portal and preserves invoice payment links. Upgrade the panel and node agent together.

Verified ​

  • API, web and plugin-host TypeScript checks; web production build.
  • Mews unit and integration suites against disposable PostgreSQL: default-deny route matrix, tokens, console and SFTP, job guards, upgrade from the previous schema, private-note isolation, diagnostics, attachment rules, business clocks, ordered rules, retention and signed inbound reply replay protection.
  • Account/billing/administrator hold interactions, invoice-gated automatic lifting and deferred paid provisioning; real SMTP transfer delivery, receiver identity, both fresh factors and single-use confirmation.
  • Chrome browser flows on the shipped production panel: suspension edit/lift, customer and agent replies, private-note isolation, solving, rating, reopening and rule editing; dark, light, phone and reduced-motion screenshots.
  • Public abuse submission through Cloudflare's official test widget and verification endpoint, plus rejection without a bot response.
  • Documentation code-block and screenshot-reference checks, example plugin validation and production site build; landing links, new hosting tabs and mobile width.
  • Linux node agent: go vet, go test and a release binary build in an isolated Go 1.25 container.
  • Existing API unit, account, billing, fit, template, autopilot, Rookery, branding, plugin, Discord and updater suites; plugin-host sandbox tests.

Operational limits ​

Attachments are content-sniffed, size-limited and authorised on every download; there is no antivirus scanner. Diagnostics include only the console lines still retained by the panel and filter known secrets. Inbound email requires a trusted mailbox bridge; Fledge does not poll a mailbox.

Virtual machine runtime and notification completion ​

  • Explicit immutable container | vm runtime throughout templates, servers, jobs and hosting plan presets. Existing data defaults to containers.
  • Opt-in x86-64 KVM/libvirt nodes, approved hardware profiles and checksum-verified cloud/ISO/driver media; Linux cloud-init and manual Windows installation with UEFI/TPM profiles.
  • Dedicated VM workspace with authenticated noVNC and serial relay, disk growth, allocated NAT ports, routed pools, stopped snapshots and backup-based offline recovery.
  • Granular VM grants, holds on guest operations, bounded console traffic and live authorization checks. Optional shared Redis supports API replicas.
  • Notification dialogs constrain event lists and keep actions within the viewport. Added suspension, appeal, retention, help-desk and VM events with explicit customer recipients and durable external delivery retries.

VM verification status ​

HTTP/PostgreSQL VM smoke checks cover placement rejection, runtime compatibility, address exhaustion, console ticket issuance, container-only API refusal, snapshot outcomes and held-account access. Linux agent unit and real guest checks are recorded during the final audit. This workspace has no /dev/kvm; software-emulated guest checks cannot establish hardware KVM behavior. Windows installation, guest Secure Boot trust/PCR behavior and provider-routed public IPs require compatible hardware verification before offering those profiles. Real QEMU/libvirt tests did verify UEFI variable and swtpm-state snapshot recovery and guest restart; they do not establish Windows or hardware KVM behavior.

Released under the AGPL-3.0-only license.