A rebuilt core, node API keys, HTTPS by default and extensions that run as services

v0.2.0
•Platform

Features

  • Core: the database core that stores your configuration and syncs it between nodes has been rebuilt. Snapshots are taken incrementally so they no longer pause the system, files are stored next to the field that holds them, and nodes advertise themselves on the local network. Peers can also connect through the VPN.
  • Services: the built-in protocol and management services have been reimplemented on a common foundation. This covers Modbus, OPC UA, MQTT, BACnet, DNP3, EtherNet/IP, CoAP, NATS, HTTP, SMTP, the PostgreSQL-compatible SQL service, Bluetooth, mDNS, SSDP, push notifications, voice assistant, network scan, alarms, historian, device manager, session manager, extension manager, certificates and the VPN.
  • Configuration: configuration is split into three spaces with one owner each. The system space belongs to the platform release, the application space to each installed extension, and the user space to you. A new configuration manager keeps a linear history of user configuration, and restore progress is recorded as regular records that follow the cluster.
  • API keys: nodes issue API keys that can be created and revoked from a new API Keys window in the start menu and the mobile profile sheet. The command-line tools for the store, files, snapshots and the write-ahead log can connect to a remote node with a key, and diagnostic and asset downloads accept keys too. Tools trust a node through a pinned certificate or a CA file.
  • HTTPS: the node web server now starts with HTTPS on by default. A new Web Server tab in Certificate Manager lets you describe, change and download the HTTPS setup. The served certificate follows renewals, the default certificate rotates before it expires, and forwarding to other HTTPS nodes is pinned to their certificate. Importing a certificate checks that the private key matches and never deletes the entity if it refuses.
  • Sign-in: LDAP users sign in by binding to their directory. A user whose provider maps groups gets exactly the roles their directory groups grant, and the mappings are edited as individual records.
  • Extensions: extensions now run as their own services, and one extension can run several. Installing and uninstalling is journaled, so an uninstall removes what the install created and an interrupted action is cleaned up before the next one starts. Weather (Open-Meteo, WeatherAPI), Google TTS, AlAdhan, Telegram Bot, ESPHome, Z-Wave JS UI, Zigbee2MQTT, SMTP, PulseAudio, the SQL service, speaker keep-alive and the demo each run as a dedicated service.
  • Apps: Alarm History, Chart Builder, Database Search, Reports, Schema Editor, Historian and the VPN extension install from declared content instead of an install program.
  • Settings as fields: settings that used to be a block of text are now individual fields you can see and change one at a time. This covers service environment variables, HTTP default headers, integration connection settings, historian context columns, LDAP group mappings, calendar overrides, exclusions and pre-start leads, Google TTS cached clips, SSH host keys and the node deploy key for Git sync, the certificate account, the web server configuration, the VPN state and SMTP read positions.
  • Calendar: the Calendar app edits overrides, excluded dates and pre-start leads directly. AlAdhan places each day's prayer time and reminder leads on the calendar, and the assistant's calendar tool edits the same records.
  • Device Manager: the device panel has a Settings section for a device's own configuration fields, deletes run as the requesting user, and an integration is tied to its controller by reference instead of by name. Owner, Administrator and Playing With Fire can delete folders and integrations. Device templates have been removed.
  • Database browser: one lazy tree with type icons replaces the column view. Every shipped entity type declares its icon, and types created in the Schema Editor can declare theirs.
  • VPN: tailnet state is held in the store instead of on a node's disk, and the VPN panel shows the not-installed and installed-held states before the tailnet status.
  • Extension Marketplace: the marketplace can open directly on a given extension.
  • Assistant: extension installs that are already present are reported before asking for approval, and permission denials name the subject that was checked and the grant that was missing.
  • Logging: a single logger service owns every node-local log file, services rotate their own logs, and managed service error output is consolidated.

Bug Fixes

  • Authorization: scoped batch writes and deletes touch only rows the caller may change, every hop of an indirect field path is authorized on the entity it reaches, the writer of every web write is the authenticated user, and totals count only rows the caller may see. Deleting or renaming platform-owned entities is refused over the SQL service as well.
  • Store: creating or deleting an entity now notifies subscribers of its parent's children. Notifications reach the browser in the shape the UI expects, and file metadata is read consistently.
  • Clusters: a peer's replicated records wait for an inbound full sync, an idle sync is abandoned, and a sync from a peer that is no longer the source is discarded.
  • Setup: setup wizard requests time out instead of spinning forever, and a failed claim session is retried without sending the credential again.
  • Device Manager: Test Connection tries every resolved address, discovery waits for the new controller to connect, deleting a device removes its mappers, deleting a connection removes its devices, and the wizard's OAuth connect uses the endpoint the provisioning reply names. Devices provisioned side by side no longer collide on a capability name, and provisioning a device adds to its model type instead of replacing it.
  • Integrations: a failed ESPHome provisioning never rolls back a controller it only re-pointed. API keys and bot tokens are stored only in secret fields, one connection is used per key, and errors and logs never show them. A Telegram bot is named by its public id, never by a piece of its token.
  • MQTT: broker packets up to 16 MiB are accepted, so a large Z-Wave JS UI node dump no longer drops the connection.
  • Services: store-configured environment values cannot override reserved platform variables, and deleting a service row stops its process gracefully instead of killing it.
  • Web server: a failed web server change writes the previous configuration back.
  • Interface: field pickers and the details panel no longer list Mailbox fields, database edits keep server timestamps, and the command-line tree view shows choice labels.
  • Extensions: a later schema step can add choice labels, extension names containing a slash work, and schema types are applied parents first.
  • Assistant tools: reading logs finds program logs, and store writes through multi-hop paths are authorized.

Performance

  • Core: the write, notification and routing paths do less work, checkpoints no longer halt the core, the write-ahead log flushes after the reply is sent, and snapshot markers are indexed from whole-file reads.
  • Services: the extension manager filters and batches its pending-request sweep, automations read rule and runner entities in batches, and the VPN filters routed entities on the server.

⚠️ Breaking Changes

  • The browser Shell app, its PTY sessions and the AI launch controls have been removed. Use the API-key tools from your own terminal.
  • SSH remote access has been replaced by revocable API keys.
  • Script-based automations and extension installers have been replaced by compiled programs, and extensions now ship as services. Custom script-based extensions must be rewritten.
  • Device templates have been removed.
  • The node web server now uses HTTPS by default.