Skip to content

v1.1.0: elevate production — certs, discovery, maps, identity, integrations - #1

Merged
bjorngluck merged 30 commits into
mainfrom
v1.1.0-dev
Aug 8, 2026
Merged

v1.1.0: elevate production — certs, discovery, maps, identity, integrations#1
bjorngluck merged 30 commits into
mainfrom
v1.1.0-dev

Conversation

@bjorngluck

Copy link
Copy Markdown
Owner

Summary

First minor after production (v1.0.0). Integrates the elevate production train from v1.1.0-dev: certs deploy/verify, discovery hygiene, operator UX (pins · schedules · jump), topology/maps (icons · pop-out · progressive ports), identity Cap channels, generic URL integrations, and docs/wiki.

Not a version bump commit by itself — tag v1.1.0 / image tags at freeze after sign-off (see docs/PLAN_v1.1.0.md).

Stream Highlights
A · Certs Deploy-target wizard · one layout per target · top Deploy / Replace PEM · post-deploy verify + TLS port probe · sudoers path alignment · cert alerts
B · Discovery Last-seen · hide/unhide · purge + bulk offline · filter chips with honest counts
C · Identity Trusted-device detail + edit polish · fixed password policy · Cap: webhook alerts · SMTP + test · email password reset
D · Operator UX Human-readable cron · ★ favourites / pins · cross-host jump · Cap/nav polish
G · Maps Canned kind icons · focus pop-out (~1.30×) · progressive host/device ports (compact → ports-only → by-service) · sticky PortAnnotation · stack cont
I · Integrations Bearer “Try a token” + OpenAPI/ReDoc links · generic_url (HA / Frigate / n8n / custom)
Docs PLAN_v1.1 · wiki (certs ACME cookbook, maps ports, pins, alerts) · ROADMAP / ADMIN sync · ACME-in-herder parked v1.3+

Map interactivity (latest QA focus)

Progressive Hosts map ports (touch-friendly):

  1. Lock fleet host or discovered chip → compact callout (whole box is the hit target)
  2. Tapports-only list on the map
  3. Services (when stacks own ports) → by-service fan · Edit → sticky-role panel

Also: discovered devices (cams, etc.) via nmap · app-path containers with published ports · pop-out scale ~1.30×.

Wiki: Network maps — progressive ports · plan: FEATURE_PLAN_MAP_INTERACTIVITY.md.

Migrations (apply on deploy)

Rev Purpose
032 Cert target verify fields
033 User favourites / pins
034 Favourite feature length
035 Password reset tokens
036 PortAnnotation sticky roles

Test plan

Freeze / CI

  • Unit suite green; coverage still ≥ 55% bar
  • Playwright E2E on touched surfaces (shell, nav, nmap list as available — no live SSH/nmap/NPM in CI)
  • mkdocs build --strict (docs freeze)
  • Fresh deploy path: migrate 032036 cleanly on empty + upgrade from v1.0.0

Operator QA (sign-off)

  • Certs: deploy target wizard · Deploy · verify (host + optional TLS probe) · sudoers preview matches server truth
  • Discovery: last-seen · hide · purge · filters; Hosts map radar + discovered chips
  • Maps (priority):
    • Lock host → compact callout → tap → ports list → Services / Edit / Back
    • Lock discovered cam/printer with inventory ports
    • App path → stack fan with port chips; container with ports → scoped callout
    • Pop-out scale / second-click clear focus (desktop + mobile)
    • Compact footer chrome readable (Back · Edit · Services not oversized)
  • Pins / jump: ★ Hosts/Path #map · cross-host jump feature flags
  • Alerts Cap: webhook event filter · SMTP test · password reset when SMTP OK
  • Generic links: add HA/Frigate-style URL · probe · binding surface
  • API: Settings → Try a token + OpenAPI/ReDoc links

Mobile

  • Hosts map ports: whole-callout expand; no tiny Expand target only
  • Fullscreen map + hamburger still exits cleanly

Out of scope (deferred)

  • M5 custom map icon pack
  • WebAuthn / passkeys (v1.2)
  • ACME-in-herder product path (v1.3+; education cookbook only)
  • Templates mega · host lifecycle mega · HA REST / k8s

Merge checklist

  • Operator sign-off on Hosts map progressive ports + residual train QA
  • RELEASE_v1.1.0.md drafted / freeze notes
  • Version bump to 1.1.0 in package / image metadata
  • Merge v1.1.0-devmain
  • Tag v1.1.0 · publish Hub 1.1.0 · 1.1 · latest
  • Keep 1.0 / 1.0.x pins valid for existing deploys

How to test (local)

# rebuild after pull
docker compose build web && docker compose up -d web
# maps: Catalog → Network → Hosts map
# hard-refresh for static cache (fabric-host-ports-expand.js / fabric.css)

Lock streams A/B/C/D/G/I (certs, discovery, identity, operator UX,
topology/maps, integrations/API). Defer enhanced themes to v1.2/v1.3
paths. Phase A1 certs is the first implementation slice.
Share path helpers for home resolution, ~ expansion, and cert-stage
dirs so sudoers snippets match live SSH $HOME (including custom home
and root). Improve stage_sudo install error copy. Unit tests cover
helpers and custom-home snippet alignment.
Record P-acme as desired but out of this train. Challenge model open
(human-assisted vs DNS automation vs hybrid); NPM remains preferred
multi-provider issuer. PLAN §6.1 + ROADMAP decision.
Wiki cookbook + optional Certbot helper can ship independently of
P-acme; prefer EFF/LE upstream links; novice path into vault+deploy.
Fix corrupted PLAN from prior edit; re-add pre-product ACME wiki
cookbook + optional Certbot helper notes under §6.1.
Novice-friendly wiki for HTTP-01/DNS-01, upstream EFF/LE links, and
scripts/obtain-acme-cert.sh (Docker Certbot → PEMs for vault upload).
Shows PiHerder value: educate, then vault and deploy — not replace NPM.
Land cert deploy-target wizard and verify, discovery S1–S4, trusted-device
detail, human-readable schedules, user pins with map #map deep links,
cross-host jump, stack port chips and cross-host edges, API try/ReDoc.

Document on PLAN, ADMIN, ROADMAP, and wiki (new Pins & host jump page);
migrations 032–034.
Add generic_url integrations (Home Assistant, Frigate, n8n, custom)
with health probe, Services bindings, and Catalog UI. Remove
favourite_toggled query flash after pin (star state is feedback).
Lock and land train Cap (WebAuthn → v1.2): trusted-device ✎ rename UX;
Settings → Alerts for webhook (Wh-lite) and SMTP (H-lite); email
password recovery (G1-lite) with hashed 1h tokens; migration 035.
Reflect AB-polish, Settings Alerts (Wh/H-lite), G1-lite recovery,
and generic links across ROADMAP, ADMIN, IAM plan notes, and wiki.
Trusted devices: larger rename control, collapsible UA, rename flash.
Settings Alerts: status chips, tab-scoped banners, section anchors.
Pins empty copy; generic links product pills + Probe + docker scope
collapsed; minor form hints.
M1–M3-lite for map interactivity on v1.1.0-dev: SVG glyphs by
device_kind on Hosts map and racks, ~1.18× scale on locked focus
(hover stays stroke-only), and stack panel port role heuristics
(DNS/web/db/etc). Custom packs and sticky annotations remain roadmap.
Edge geometry assertion used pre-icon host_hh=30; mesh uses 34.
Add PortAnnotation (migration 036) and host inventory that unions
Docker published ports with linked nmap observations. Operators set
sticky roles from the host ports panel; stack chips and map focus
callout show summaries. Custom icon packs remain M5 roadmap.
Stop burying ports in drawers as the main story. Clicking a fleet host
now expands a host→port→stack fan on the Hosts map (roles, owners,
observed nmap). Path click still fans containers and deps. Drawer is
optional edit (sticky roles), not discovery.
Group host expand by service/container with up to 5 ports listed
cleanly (no obs + observed-only spam). Nmap-only ports share one
Observed card. Stack container boxes are taller so role chip, name,
and ports no longer overlap.
…cards

Revert stack container card sizing. Fix Hosts map app satellites so the
icon sits left of the FQDN (no squash). Host ports fan starts further
from the host; each service card fully contains its port chips.
Keep icon and labels centered as before. Taller app card so icon
sits above the FQDN instead of redesigning the layout.
Lock host or discovered chip for compact callout → ports-only list →
optional by-service fan; pop-out ~1.30×; stack containers show ports.
Touch uses whole-callout hit targets and compact footer chrome.
Docs/wiki cover progressive flow, discovery ports, and implementation.
@bjorngluck bjorngluck self-assigned this Aug 1, 2026
…N_v1.2.0

Map: skip viewport pointer capture and capture-phase focus steal on host
ports / stack expand overlays so desktop "Tap for ports" works; activate on
pointerdown for mouse/pen (cache-bust dns_physical assets).

Backup: prefer concrete rsync file errors over generic code-23 summary;
wiki troubleshooting for I/O on mounts; unit coverage.

Docs: approve v1.2 big train (WebAuthn, SSO, webshell, CF-gated demo) and
point ROADMAP at PLAN_v1.2.0 — feature work stays post-1.1 freeze.
Document that rsync can fail when files disappear mid-transfer on live
trees (e.g. Frigate NVR recordings). Ship as accepted known issue in
RELEASE_v1.1.0; operator guidance in wiki; carry retry/soft-success to
v1.2 as B-retry.
Expand release notes with stream highlights (certs, discovery, identity
Cap, nav, maps M1–M4, integrations), upgrade/migrations, verify smoke,
known issue KI-rsync-vanished, out-of-scope, and freeze checklist.
Status remains Draft until PR/tag approval.
List must-update PNGs (certs, maps icons/ports, discovery filters,
trusted devices), recommended new shots (wizard, alerts, API, generic
URL, host ports expand), skip list, expected 1.1 chrome, and capture
from v1.1.0-dev rebuild. Point wiki README at RELEASE_v1.1.0 + this guide.
Self-backup is a selective JSON snapshot, not pg_dump. Audit against
all SQLModel tables: add UserFavourite, ApiToken, NmapScanSchedule,
NmapDevice, NmapScriptResult; list port_annotations in manifest;
restore + sequence fix; document intentional excludes (jobs, reset
tokens, scan runs). Tests + wiki updated.
Expand Self-backup & DR with honest scenarios (min pack, fleet files,
comfort pack), what fully functional means, include/exclude tables,
and restore caveats. Align Journey F and Volumes with the same story.
Bump APP_VERSION/pyproject to 1.1.0; README/wiki/SECURITY/CONTRIBUTING/
ROADMAP/RELEASE/PUBLISH pins. Wire 1.1 screenshot pack into wiki pages.

CI fixes:
- Docs: external GitHub links for maintainer docs (mkdocs --strict)
- Tests: fleet_link_targets tolerant of mock rows; stack panel unit fix
- E2E: LAN filter chips include counts; topology seed sets created_at/updated_at
@bjorngluck
bjorngluck marked this pull request as ready for review August 8, 2026 13:29
@bjorngluck
bjorngluck merged commit 5b95b9b into main Aug 8, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant