This website requires JavaScript.
265136fc42
Metric history fix, service-failure audit trail, alert channels + secret-retarget hardening
feat/v1-foundation
boban
2026-07-08 22:21:54 +0200
182cb0fedd
UI consistency batch: docker names, chart axis, empty states, control heights
boban
2026-07-08 21:20:18 +0200
4248c83c42
Fresh-install bug batch: prod poller, installer UX, switcher/firewall polish
boban
2026-07-08 18:57:04 +0200
b7e44ca3c2
UI polish + honest service-action reporting
boban
2026-07-06 22:15:57 +0200
40383261bd
feat(ui): live sidebar badges (alerts / threats / update) without a refresh
boban
2026-07-06 21:41:37 +0200
d348e77ad7
fix(mail): force the logo size via inline CSS; brand header inside the card
boban
2026-07-06 21:23:47 +0200
da53b6f7c7
fix(alerts): fresh mailer at queue time (poller!) + branded HTML alert e-mail
boban
2026-07-06 21:14:52 +0200
5024675c94
fix(alerts): send one e-mail per recipient so a bad address can't drop all
boban
2026-07-06 20:56:23 +0200
f9a08a98d2
fix(ui): uniform action-element height + live fleet status / alerts
boban
2026-07-06 20:42:09 +0200
6dbe2303a4
fix(ui): sidebar alert/threat badges update at once, not up to 60s late
boban
2026-07-06 20:22:51 +0200
b0c46f2b18
perf/cleanup: one SSH round-trip for Docker, drop dead i18n, dedupe row
boban
2026-07-06 20:06:27 +0200
4d349eebb9
fix: alert mail on queue, SMTP reset, cert/uptime auto-probe, pill heights, XSS
boban
2026-07-06 19:46:46 +0200
b4c309bd54
feat(nav): 3-group sidebar; split Docker + Terminal into host page + per-server tabs
boban
2026-07-06 19:21:13 +0200
096ba3ca98
harden(compose): scope host-gateway route to the web app only (audit finding)
boban
2026-07-06 01:15:35 +0200
4c67b278bd
fix(docker): admin-gate the host target + honour a "0" key passphrase (Codex review)
boban
2026-07-05 23:43:18 +0200
fd6eba5c29
fix(mariadb): stop logging protocol-normal "Aborted connection" warnings
boban
2026-07-05 23:34:04 +0200
3fae5293e2
refactor(docker): drop the noisy port list from the container row
boban
2026-07-05 22:58:02 +0200
c253e79c0c
feat(docker): show the Clusev host's own containers (host target)
boban
2026-07-05 22:43:36 +0200
7e6c01d5fa
fix(docker): honest "not installed" state instead of a raw shell error
boban
2026-07-05 22:11:53 +0200
4ab255832d
fix(docker): find the docker binary regardless of the login shell PATH
boban
2026-07-05 21:33:45 +0200
7535ee2d63
fix(ui,docker): normalise oversized buttons + surface the real Docker error
boban
2026-07-05 21:22:49 +0200
65b92bc65c
feat(uptime): HTTP/TCP health checks + status board (feature 8/8)
boban
2026-07-05 21:04:14 +0200
3cab72bf46
feat(security): TLS certificate expiry monitoring (feature 7/8)
boban
2026-07-05 20:57:53 +0200
79862ab014
feat(patch): fleet patch view + security-update awareness (feature 6/8)
boban
2026-07-05 20:51:17 +0200
31852fc04c
feat(security): fleet security-posture score (feature 5/8)
boban
2026-07-05 20:43:56 +0200
5e4f29216d
feat(commands): ad-hoc fleet commands + runbooks (feature 4/8)
boban
2026-07-05 20:38:09 +0200
35b7c15598
feat(docker): container management over SSH (feature 3/8)
boban
2026-07-05 20:23:56 +0200
0472b3531a
feat(alerts): threshold alerting + notifications (feature 2/8)
boban
2026-07-05 20:07:54 +0200
40d8dfc96d
feat(fleet): server groups — organise the fleet + filter (feature 1/8)
boban
2026-07-05 19:36:17 +0200
aa854916ce
harden(opsec): disguise the honeypot naming on the Threats + settings pages too
boban
2026-07-05 19:06:46 +0200
bf4366dfc9
harden(opsec): disguise honeypot action labels in the audit log
boban
2026-07-05 18:59:56 +0200
930f78efbd
polish(ui): in-system design refinements from the design review
boban
2026-07-05 18:06:32 +0200
0943d56201
harden(update): verify the self-update commit signature before the root re-exec/build
boban
2026-07-05 17:10:19 +0200
46924135e6
perf(fleet,wg) + i18n(dashboard,update) + a11y(btn): re-audit design/perf cleanups
boban
2026-07-05 17:10:19 +0200
6927987a0d
harden(fleet,infra): enforce credential revocation on the poller + prod container hardening
boban
2026-07-05 17:10:19 +0200
bc2f2b527f
fix(security): close file-read RBAC gap + fail2ban arg-injection + update/HMAC hardening
boban
2026-07-05 16:05:16 +0200
c914790a46
harden honeypot/ban path: close evasions, unmask & audit-DoS vectors
boban
2026-07-05 15:05:35 +0200
f804e25a66
refactor(release): single stable channel — cut internal release candidates (-rc), remove all beta wording
boban
2026-07-05 13:13:09 +0200
e6f6e7f8a4
fix(dev): read VITE_HMR_HOST from the .env FILE (loadEnv), restoring dev HMR assets
boban
2026-07-05 11:06:53 +0200
c63af35194
feat(honeypot): surface login attempts in the dashboard (threats KPI, tried-credentials, sidebar badge)
boban
2026-07-05 10:49:38 +0200
473fa8c0d0
feat(honeypot): trap fake-login submits + capture the attempted credentials
boban
2026-07-05 10:34:05 +0200
6c70d885f7
feat(honeypot): realistic styled decoy pages (WordPress, phpMyAdmin, generic login)
boban
2026-07-05 10:19:18 +0200
1b3e058de6
fix(honeypot): route non-existent .php probes through nginx to the trap
boban
2026-07-05 09:32:23 +0200
72de7b9a22
fix(rbac,honeypot): gate audit-retention + email sendTest; honeytoken scans JSON body
boban
2026-07-05 02:28:13 +0200
e602320c9d
fix(rbac,honeypot): gate settings/release surfaces + per-install canaries, no reflected/auth-user honeypot bans
boban
2026-07-05 02:16:37 +0200
e58d1a4b07
feat(rbac): hide the system-update trigger behind manage-fleet too
boban
2026-07-05 01:51:12 +0200
8b34ed8ef5
feat(rbac): hide gated controls in the UI with @can (operator/viewer see no dead buttons)
boban
2026-07-05 01:49:38 +0200
4f9699d470
feat(honeypot): threats dashboard — probe feed, KPIs, banned-IP management
boban
2026-07-05 01:38:22 +0200
c8e1e07a43
feat(honeypot): decoy routes + instant-ban + deceptive responses + honeytokens
boban
2026-07-05 01:25:07 +0200
61b8419106
feat(rbac): user-management roles UI — role badge, selector, role-change with last-admin guard
boban
2026-07-05 01:15:32 +0200
b529201186
feat(rbac): gate service + file mutations behind operate (viewer read-only)
boban
2026-07-05 01:06:06 +0200
25ded63d87
feat(rbac): gate fleet, host terminal + domain/TLS actions (manage-fleet/operate/manage-panel)
boban
2026-07-05 01:01:24 +0200
27b35e1f72
feat(rbac): gate network + panel actions (manage-network/manage-panel)
boban
2026-07-05 00:52:09 +0200
55c3975d53
feat(rbac): role enum + column + gates foundation (admin>operator>viewer)
boban
2026-07-05 00:42:16 +0200
3c25f097fa
fix(security): close the TOCTOU in the symlink-safe status write (Codex review)
boban
2026-07-04 10:33:16 +0200
a6176341e2
fix(security): keep internal IPs out of shipped code and docs/ out of the public image
boban
2026-07-04 10:25:10 +0200
d7156ddc96
fix(security): harden the update path — signed sentinel, symlink-safe root writes, .env 0600
boban
2026-07-04 10:25:10 +0200
8a814337ff
fix(install): validate release-image digests as ghcr.io/<owner>/<name>@sha256:<64-hex>
boban
2026-07-03 21:37:56 +0200
4af1633ca9
fix(install): harden release-image resolver — safe build fallback, ghcr digest allowlist, lint + CI coverage
boban
2026-07-03 21:27:30 +0200
ace3af5849
feat(install): pull promoted image on public installs via release-images.lock
boban
2026-07-03 21:03:03 +0200
a3cc563883
feat(install): resolve prod image from release-images.lock (pull vs build)
boban
2026-07-03 21:01:26 +0200
383f2fe74a
feat(release): remove the no-op channel selector + dead beta→stable promotion (single stable channel)
boban
2026-07-03 20:43:15 +0200
10486672a5
ci: build+push prod images, gated auto-promote to public
boban
2026-07-03 20:15:03 +0200
fff2d017be
build: export-ignore the promote.sh test scripts too (they invoke the ignored script)
boban
2026-07-03 20:06:14 +0200
4e4023f12d
feat(release): collapse to a single stable channel
boban
2026-07-03 19:58:09 +0200
176b132da9
chore(release): remove every 'gitea' reference from the public tree (comments, test fake-host, redundant ignore)
boban
2026-07-03 19:54:20 +0200
54518c1f30
feat(release): string leak-guard in promote.sh + shell test
boban
2026-07-03 19:49:31 +0200
e02f4d036a
build: export-ignore the full dev-release bridge + its tests from the public tree
boban
2026-07-03 19:42:14 +0200
72b82df7a1
fix(update): surface update failures instead of spinning forever
boban
2026-07-03 18:58:32 +0200
6348d269a5
docs: fix stale first-login copy (random initial password, rotation optional)
boban
2026-07-02 22:50:35 +0200
d08a8a3866
docs: rename the generated password "one-time" → "initial" (rotation is optional)
boban
2026-07-02 22:43:09 +0200
657e659d76
docs: use the short `clusev` host-CLI aliases in the README
boban
2026-07-02 21:26:42 +0200
f3c5fee839
feat(shell): point Help entry at the online docs (docs.clusev.com)
boban
2026-07-02 21:12:29 +0200
9f784ce97a
chore: release 0.11.0-beta1
v0.11.0-beta1
boban
2026-07-02 20:26:34 +0200
0fbf379ae9
docs(readme): match the installer + auth changes (no domain prompt, random install password, web terminal)
boban
2026-07-02 20:20:32 +0200
2a1ad6595b
chore(install): don't prompt for a domain — install over IP, set it later in the dashboard
boban
2026-07-02 20:14:29 +0200
dc26dccaa3
feat(onboarding): first-run spotlight tour — dimmed backdrop, sidebar highlights, relaunchable
boban
2026-07-02 20:00:19 +0200
cc4cc3db4c
security: pin the SSH host key in the terminal sidecar (fail-closed)
boban
2026-07-02 19:33:53 +0200
c3788f5851
security: generate a random install password instead of the literal 'clusev'
boban
2026-07-02 19:33:52 +0200
fd4f6ceb0f
chore: remove dead code — sidecar host-PTY path, node-pty, unused lang keys + component
boban
2026-06-26 07:16:11 +0200
e38409bf31
security: harden proxy trust + model mass-assignment + terminal-token log hygiene
boban
2026-06-26 07:16:10 +0200
f3d2a9592e
feat(auth): drop password complexity — minimum is now just 6 characters
boban
2026-06-26 06:29:33 +0200
6f43b480b1
feat(auth): lower the password minimum from 12 to 6 characters
boban
2026-06-25 21:19:41 +0200
d08670270e
feat(accounts): let the operator set a new user's password directly
boban
2026-06-25 20:29:15 +0200
00a9d8b9a3
feat(ui): shield-only 2FA indicator in the sidebar + terminal search from 2 servers
boban
2026-06-25 20:20:46 +0200
2b1e98c5d4
fix(terminal): make the saved host-login state unmistakable in the modal
boban
2026-06-25 20:08:50 +0200
e1a886671b
refactor(terminal): host login targets the local machine only — drop the HOST/IP field
boban
2026-06-25 20:00:04 +0200
0ec9f3664a
feat(terminal): explain the host-login HOST/IP default in the setup modal
boban
2026-06-25 19:52:13 +0200
142b531d45
feat(auth): make password rotation optional + correct the 2FA copy
boban
2026-06-25 19:47:17 +0200
83626352e2
feat(terminal): Clusev-host SSH login tile + server search; drop the inline hint
boban
2026-06-25 19:46:55 +0200
707b031bd2
ci: bump actions/checkout + actions/setup-node to v5 (drop Node 20 runtime)
boban
2026-06-25 18:55:52 +0200
e3b5aa5902
fix(terminal): correct mobile sizing — fit after web-font load + open PTY at the visible grid
boban
2026-06-25 08:08:12 +0200
05042c3582
fix(terminal): clean Clusev-host shell prompt — node@clusev:~ not node@<hash>:/workspace
boban
2026-06-25 06:31:49 +0200
07fe404ce9
feat(terminal): web terminal — per-server SSH + Clusev host PTY (xterm.js + node sidecar)
boban
2026-06-25 03:21:10 +0200
8dfc11fd5d
fix(versions): keep the changelog series stable on reload (0.10 -> 0.1 bug)
boban
2026-06-25 02:15:41 +0200
d8da46151e
chore: release 0.10.0-beta1
v0.10.0-beta1
boban
2026-06-25 02:03:40 +0200
1697a5d7c2
feat(metrics): persist the history-chart range in the URL
boban
2026-06-25 01:59:39 +0200
fbd9c7e257
fix(metrics): move the history chart x-axis labels below the plot
boban
2026-06-25 01:55:49 +0200
b2c6de64da
refactor(metrics): interactive history chart — smooth, area, tooltip, instant ranges
boban
2026-06-25 01:51:24 +0200
6227505528
feat(metrics): persistent resource-history graph on the Server-Details page
boban
2026-06-25 01:31:27 +0200