Skip to content

Fledge v0.9.1.2 ​

This patch makes the Mews administration flows easier to complete in the panel and fixes overview access for delegated operators.

Fixed and improved ​

  • VM setup in the panel. Ready Linux nodes now have an audited Allow new VMs on this node switch under Virtual machines → Nodes. New placement and migration require that switch; it defaults off. The switch is available only after the connected agent reports KVM, libvirt, x86-64 and native network isolation. Disabling it does not stop existing guests.
  • No VM enablement environment flag. The agent discovers host capabilities automatically. Host packages, firmware and libvirt networks still need to be prepared on the Linux node, and placement remains blocked until checks pass. The panel links directly to the VM host guide, now also listed in the operator docs navigation.
  • Usage reporting setup. The prepared GitHub intake, public App Client ID and encryption key are available as defaults. Super administrators can review or change these public coordinates in Settings → Panel → Usage reporting; deployments no longer need usage-specific .env values. Reporting remains off until explicit consent and GitHub device authorization. OAuth tokens remain encrypted in the database; private keys are never entered in Fledge.
  • Inbound support email setup. Generate, enable, disable and rotate the signed inbox-bridge secret in Help desk → Settings → Inbound. The key is encrypted in the database and shown only once. Existing SUPPORT_INBOUND_SECRET values remain a legacy fallback until the panel setting is saved.
  • Operator overview access. The overview uses a limited activity summary protected by servers.view; the full audit feed still requires audit.view. The summary excludes actor identities and event details.
  • Workspace navigation. Customer and administrator destinations are grouped and ordered around their common tasks.

Upgrade ​

Update the panel and Linux agent to 0.9.1.2. The database change adds nodes.vm_enabled with a default of false; it is additive and existing nodes do not begin receiving new VM placements. Run the normal update procedure. Remove the obsolete VM_ENABLED agent setting if present; it is no longer used. Existing optional USAGE_* environment values are harmless, but no longer required.

Verification ​

  • API and web type checks and production builds.
  • VM HTTP/PostgreSQL tests for default-off placement, readiness-gated panel enablement, allowed placement and compatible migration targets.
  • Usage reporting tests for built-in intake defaults, configuration validation, explicit opt-in, GitHub authorization and withdrawal behavior; support tests verify the inbox secret stays encrypted, starts off, and can be enabled and disabled in the panel.
  • Delegated Operator browser/API authorization checks; full audit access remains restricted.
  • Linux agent vet/tests/build, a disposable browser pass with refreshed Mews screenshots, and documentation link/build checks.

Released under the AGPL-3.0-only license.