Web Console provides the browser interface for compatible environments, hosts, stacks, services, containers, catalogs, storage, networking, access control, and administration.
PastureStack is an independent community effort to preserve, audit, and modernize the Rancher 1.6 ecosystem. It is not affiliated with or endorsed by Rancher Labs or SUSE.
Upstream: rancher/ui, preserved from its 1.6-dev line. This GitHub fork retains upstream history, authorship, dates, tags, licenses, and dependency notices. PastureStack maintenance is consolidated into one commit after the preserved upstream boundary.
The current published release is 1.6.160. It retains the existing Node 24, Ember, Sass,
dependency, browser-smoke, terminal, console, and test-harness modernization.
It adds a provider-neutral OpenID Connect administration and sign-in flow with
PKCE S256, staged configuration validation, a real test login before
activation, and local-authentication recovery. Product-owned names, logos,
icons, package metadata, and visible text use PastureStack branding. API
models and protocol fields remain compatible.
Release 1.6.160 adds a clear, localized explanation when the API rejects
deleting a certificate still referenced by a load balancer. It tells the user
to remove those references first, without exposing service names. Denied or
missing resources and unrelated action failures retain neutral messages;
authorization, delete behavior, session and MFA contracts do not change. See
the release note.
The official numeric release 1.6.160
is published from source commit 63964fa3a6da5cbd452cdc1061c1e18340055362.
The web-console-1.6.160.tar.gz archive has SHA-256
705946b96e693c55a8ab5de3bc96b14020a52a050bf3992c302b9fb3c1408a51.
Official validation run 36702030007
passed 725/725 tests and produced two byte-identical archives. The published
asset's hash was independently read back and matched. Server artifact and
isolated browser acceptance remain pending; this component publication does
not complete the resource/role matrix.
Release 1.6.159 preserves an existing Registry credential's password when
the editor changes only its username or leaves the password input blank. The
editor submits a password only when a new nonempty value is entered, preserving
its literal whitespace. It retains the exact-resource, parent-registry,
project and current update-capability checks. This is a browser payload fix;
Server authorization and Registry credential creation are unchanged. See the
release note.
The official numeric release 1.6.159
is published from source commit aab95cf41ebc45e4c51513d9589602ab990399c9.
The web-console-1.6.159.tar.gz archive has SHA-256
f014083480e10430701e3a08588cf617242188938d9f935fbaac42a3b5feeb90.
Official validation run 36686121660
passed all 723 tests (723/723) and verified deterministic packaging. The earlier
7/7 result covered only the focused Registry editor tests. Published Server
v1.6.493
packages this archive at immutable image digest
sha256:61067362a2d91b791c7e80cb2ec4a5a907bc03884774d2019dccf1bf0e29788f.
Scoped Registry acceptance on isolated QA 8080 passed 24 GET checks across six
roles and both API roots, eight no-access PUT/DELETE denials with HTTP 403, two
API password replacements, and one owner browser username-only save that omitted
secretValue. Eight readonly write cases returned HTTP 405 because the schema
omits those methods; they remain N/A, not authorization passes. Cancel, refresh,
credential and parent Registry identity preservation passed. The password hint
and controls fit in English, Traditional Chinese and Japanese at 1440px and
390px. Both disposable fixture resources reached their terminal cleanup states.
Other workflows and the broader role/resource matrix still require acceptance.
The same release also pins official compatible High-severity security fixes for the build
and test graph: brace-expansion 1.1.21 / 2.1.7 / 5.0.12 on their existing
major lines, and engine.io 6.6.10. The reviewed lock baseline and dependency
gates cover these pins; the live npm audit --audit-level=high gate remains
unchanged. This does not claim that remaining Moderate advisories are fixed.
Release 1.6.158 gives Service direct-ID and Secrets-list load failures
the same localized, resource-safe handling already used for Stack loads. It
also gives HTTP 405 save and action failures the existing translated
unavailable messages. Focused source tests cover English, Traditional Chinese,
and Japanese. The official archive is published with SHA-256
286833d3313c5bc04469a8fafd41bab7de1c4b60527f91aae9eef8a4016b17f6;
Server packaging and live browser acceptance remain separate. See the
release note.
Release 1.6.157 mounts authenticated-page notices when their component enters
the DOM. This covers the fresh direct-URL denial missed by 1.6.156's route
render callback while keeping login/MFA notices on the body. The focused source
tests pass, and the official archive is packaged in Server v1.6.491. Isolated
8080 QA on that image passed 14 scoped Stack and Service direct-create notice
cases with zero resource writes. This does not establish the broader role and
resource matrix or a formal company-site deployment. See the
release note.
Release 1.6.156 introduced the in-flow authenticated notice layout, but
Server v1.6.490 QA found that a fresh readonly direct create URL still left
the notice fixed on the body and overlapping header actions. An in-app
transition did mount it correctly. See the
1.6.156 release note.
Release 1.6.155 moved global notices below the navigation bar and bounded
their width. QA 8080 browser acceptance subsequently found that the fixed
notice still covered the mobile page title and desktop header actions. It is
not the accepted layout; see the
1.6.155 release note.
Release 1.6.154 shows a localized, persistent permission error when a direct
Stack or Service creation URL is denied, then returns to the Stacks list.
Service upgrade URLs continue to use update permission and receive an update
error only when that permission is absent. The shared message covers all
resource types using the route guard. See the
release note for source test evidence.
It was packaged in Server v1.6.488; its 8080 browser acceptance identified
the notification/navbar overlap addressed by 1.6.155.
Release 1.6.153 makes Stack, Service, and Container write controls check
their current project/resource capability when the user acts; delayed project
upgrades and service scaling cannot carry a click into a different selected
project. It improves Registry edit recovery, localized errors and Japanese
form labels, and shows an unavailable state when host/container monitoring
cannot connect instead of leaving a spinner. These are browser-console
changes, not a substitute for Server-side per-resource authorization. See
the release note for test evidence
and the remaining 8080 acceptance boundary.
Release 1.6.152 uses each Stack, Service, and Container form's visible,
translated name label in its required-field error. This closes the
Chinese/Japanese Stack mismatch observed on isolated Server v1.6.485 QA;
it does not change request payloads, server authorization, or other fields.
See the release note. Source tests
alone do not establish acceptance of a packaged Server image.
Release 1.6.151 restores Secret Edit when the current resource schema
allows PUT and the active Secret has a self link. Secret Remove still follows
the API's explicit remove action. This matches the API's existing Secret
write contract without granting Edit to read-only users or changing Secret
payloads. See the release note.
Source tests and the earlier API-only QA do not by themselves establish
browser acceptance of a newly packaged Server image.
Release 1.6.150 limits Certificate Edit and existing RegistryCredential
Edit to the fields shown in their forms. Their PUT requests no longer resubmit
cloned server-owned IDs, state, timestamps, or unrelated model metadata.
RegistryCredential creation after a missing credential retains its existing
readback and uncertain-write safeguards. See the
release note; source tests do not by
themselves establish browser or API acceptance.
The 1.6.149 source change makes Registry creation recoverable when its
separate credential request fails: it never automatically deletes a registry
or blindly repeats an uncertain credential write. New Registry, Certificate,
and Secret records are refreshed by ID so their action links are available
after creation; Certificate Edit also rejects encrypted private keys. See the
source release note. Browser acceptance
and publication are separate steps.
Release 1.6.148 makes Secret Edit follow the current Secret schema: the name
is shown read-only with an explanation, and Save sends only the editable
description. A successful Save updates the listed Secret; a rejected Save
leaves the form open. Secret Add continues to accept a name and value. This
builds on the 1.6.147 Service Edit fix without changing the Server API.
See the release note.
Release 1.6.147 limits Service Edit to the editable name, description, and
scale fields so saving does not resubmit cloned launch configuration or upgrade
strategy. The scale form preserves an initial value of zero and applies quick
scale selections during editing; quick scale writes submit only the scale
field. See the release note for
the change scope and validation boundary.
Release 1.6.146 makes required-field errors use the visible translated form
labels for Secret, Certificate, Registry, and RegistryCredential instead of
schema-derived English names. It retains model-specific translations and the
existing fallback for fields without a form label. The encrypted-key error on
Certificate submission is localized as well. See the
release note. Browser acceptance is
tracked separately from the unit test.
Release 1.6.145 normalizes resource type names before checking the cached
project schema. It restores Registry Add for authorized users while retaining
the Registry plus RegistryCredential POST requirement and direct-route denial
for unauthorized users. See the release note.
Release 1.6.144 introduced schema-gated Secret, Certificate, and Registry
Add controls and localized 403 errors on denied direct Add URLs. Secret Edit
also began following its update action link. Isolated 8080 acceptance found
that Registry Add was incorrectly hidden even for authorized users because
the cached schema ID was lowercase. See the release note.
That regression is addressed by 1.6.145; its browser acceptance must be
recorded separately.
Release 1.6.143 creates a private ProjectTemplate from editable fields only.
It deep-copies the Default template's stacks without sending the Default's
creation time, lifecycle state, or identity in the new resource request. See
the release note.
New-resource clones also omit server-owned lifecycle fields across Host,
Service, Container, and VM forms. Receiver clones exclude inactive driver
settings; unsupported Receiver drivers cannot be submitted from the form.
Release 1.6.142 stops a cloned Receiver from reusing its source's issued
webhook URL or lifecycle state; the server issues the new URL. It also keeps
the container table's actions visible during horizontal scrolling without
changing data-column widths, clears catalog identity when creating a private
ProjectTemplate, and shows localized denial for direct create routes and an
inaccessible environment. See the release note.
Release 1.6.141 gives denied or missing ProjectTemplate edit URLs the same
localized message in English and Traditional Chinese. Failed API-key saves now
show the existing API error in the modal; a failed creation does not display
key values. See the release note.
Version 1.6.140 shows ProjectTemplate edit and remove controls only to
administrators or the template's account owner, including when the Server
omits isPublic from non-administrator responses. Direct edit URLs repeat the
ownership check before loading the editor. Closing an API-key modal before its
delayed focus runs no longer attempts to focus a removed input; cancellation
remains write-free.
Release 1.6.139 derives Container, project API-key, and Receiver Hook write
controls from the current project's API schema. Direct routes repeat capability
checks instead of relying on hidden buttons. Receiver role-aware controls require
Webhook Automation Service v0.10.3 or newer; the Server remains responsible
for authorization. Container editing now waits for its dependent saves and keeps
the form open on a failed update. See the release note
for the precise behavior and retry boundary.
Release 1.6.138 keeps delete confirmation open while requests run, prevents
duplicate submissions, and allows retry after a failed deletion. Denied and
missing resource pages keep their shared 404 presentation when the language
finishes loading; the authenticated route waits for that language setup.
Release 1.6.137 lets empty pod-list messages wrap within narrow screens.
This fixes a Russian no-hosts message that caused 6px of horizontal overflow
at 320px. Pod columns keep their existing layout, and the environment switcher
and error-page behavior from 1.6.136 are unchanged.
Release 1.6.136 keeps the environment switcher inside the viewport in
left-to-right and right-to-left layouts, including narrow screens and long
environment names. It also preserves right-to-left text direction on the
shared error page. A stored environment selection is rechecked with the API;
when the authenticated console loads after access is revoked, it selects an
accessible fallback. The environment management list uses a fresh collection
without resetting the active environment's schema. Authentication and server
failures still surface as errors. Server authorization is unchanged.
Release 1.6.135 keeps the administrator environment switcher behavior from
1.6.134 and corrects the switcher list labels in French and Russian. The
French labels no longer mix English words into French; the Russian labels
identify all environments and your environments using the same term as the
switcher. No API or permission behavior changes in this release.
Release 1.6.134 includes every active environment in the switcher for an
authenticated site administrator, including environments where that account
is not a direct member. Other signed-in users continue to see their member
environments. The Server still authorizes the all=true collection request.
Release 1.6.133 uses the active environment's API schema to show host
creation and cloning only to users who can create hosts. A direct add-host URL
now returns a translated access error before loading registration data when
creation is forbidden. Project schema loads are generation-checked so a late
response cannot restore an earlier environment's controls. Environment detail
waits for its project lookup before reading related resources. Error layout is
usable on narrow screens and in right-to-left locales. Server authorization
is unchanged.
Release 1.6.132 loads an environment's network policy under that project's
API context, just as the policy-manager lookup and network save already do.
Without the project header, a project member's network list was empty even
though the same token could read and update the network in its project. The
form still follows the returned update capability: readonly members cannot
edit policy. No Server authorization rule is relaxed.
Release 1.6.131 limits account identity-link lookups to the user and admin
rows that the account page actually displays. The account API also returns
project accounts, whose identity-link lookup correctly returns 404; that 404
previously blocked the whole page. The list still surfaces authorization and
backend errors for visible accounts instead of hiding them.
Release 1.6.130 makes direct stack, account-list, and account-security load
failures show translated, actionable messages. A denied identity-link lookup
no longer appears as an empty identity; only a confirmed missing link on an
inactive account is treated as historical data. Account and environment-member
validation errors now use the selected language. These are display and
error-handling changes; API authorization remains enforced by the Server.
Release 1.6.129 adds an Edit link to the environment detail header when the
network policy is editable but project metadata and members are not. The link
opens the existing edit form for that environment; it does not change API
permissions or duplicate the Edit action for project and member editors.
Release 1.6.128 makes the environment edit page follow API capabilities even
when opened directly with ?editing=true. Existing members stay visible, but
adding, changing roles, and removing members require the project's setmembers
action link. Project metadata and network policy controls follow their own
update links. A fully read-only edit page keeps an exit action without offering
a save button. Focused browser-template and component tests cover the separate
capabilities and new-environment creation flow.
Release 1.6.127 makes environment permission failures understandable in the
existing page and form error surfaces. An inaccessible or missing environment
or member list no longer exposes raw API details; a failed member or network
policy update explains that earlier steps may already have saved. Identity
search distinguishes no matching identity, insufficient permission, expired
session, and temporary service failure. Route-level HTTP 401 retains the
existing session recovery path. Pair this release with Engine
0.183.320 and Server v1.6.464 for the tested project-member authorization
boundary.
Release 1.6.126 treats an authenticated account with no active environment
as a valid empty state. It clears stale tab and store scope, skips every
project-scoped request, and avoids a permanent loading error. Account rows use
the authoritative login identity fallback order name, login, then
externalId only when the account name is empty. Descriptions continue to
show only the real account.description; identity names and e-mail addresses
are never substituted. Pair this release with Engine 0.183.319 and Server
v1.6.462.
Release 1.6.125 keeps account administration available when the account
inventory contains an inactive historical row. The page still loads fresh,
account-scoped authentication identities for every readable account, but an
expected AccountNotFound from the identity-link endpoint is isolated to that
single row and falls back to its embedded identity fields. Authorization,
authentication, and server failures other than HTTP 404 still reject the route
and remain diagnosable. Pair this release with Engine 0.183.318 and Server
v1.6.461.
Release 1.6.124 restores direct navigation and refreshes for every
/env/:project_id page after the Ember 7 transition upgrade. The authenticated
parent route now reads the requested environment from the public RouteInfo
tree, rather than the removed legacy transition parameter bag, before it
considers a tab or user default. A permitted non-default environment therefore
remains selected across direct links and reloads, while inaccessible IDs still
fall through the existing server-authorized selection path. Pair this release
with Engine 0.183.317 and Server v1.6.459.
Release 1.6.123 makes environment and workload entry points follow the
effective API schema instead of assuming every signed-in account can create or
update resources. Stack, service, load-balancer, alias, external-service,
virtual-machine, and catalog launch routes reject direct navigation when the
current environment omits the required POST or PUT method; their matching
buttons are hidden from read-only and no-access roles. Catalog refresh and
environment-catalog management additionally require a project management
action. The account administration table now displays description and all
authoritative linked login identities for both local and OpenID Connect
accounts. Pair this release with Engine 0.183.317 and Server v1.6.458, which
place new and returning external users in the shared Default environment while
preserving explicit group or direct roles and existing environments.
Release 1.6.122 restores environment view and edit loading after the Ember 7
compatibility migration. Promise-to-callback adapters now distinguish source
Promise rejection from exceptions raised by downstream async completion, so
one operation can call its callback only once and the original error remains
diagnosable. The project route imports members through the supported
followLink contract before cloning the editable model; the removed
importLink helper can no longer leave the transition pending. Synchronous and
asynchronous failures from projects, members, networks, and policy managers now
reject the route and reach the normal error page instead of leaving the static
loading overlay in place. Focused tests cover resolved, rejected, downstream
callback, concurrent async.auto, every environment-loading dependency, and
the adjacent authenticated initialization path. The shared create/edit mixin
now returns one owned Promise across validation, persistence, dependent saves,
completion, error handling, and cleanup. Duplicate submissions cannot release
another request's saving lock, while synchronous hook, callback, and finalizer
exceptions remain diagnosable. Environment and load-balancer component tests
exercise the same lifecycle used by the browser. Pair this release with
Authentication Service v0.4.41 and Engine 0.183.309 or newer.
Release 1.6.121 closes the expired-session loading loop without changing the
server authentication contract. GET /token may return HTTP 200 with provider
login options when a Cookie is missing, invalid, or expired; the console now
requires an identity-bearing accountId, user, or userIdentity before it
adopts that response as an authenticated session. The unauthenticated object is
normalized to the existing local 401 path, where the origin-level mutex clears
only a still-matching Cookie and generation before routing to the login page.
Passive failures still issue no DELETE, and a delayed result cannot clear a
newer session. Deterministic tests cover simultaneous 401 recovery, single
invalidation, newer-generation protection, masked JWT responses, and the
existing TOTP, Passkey, callback, explicit-logout, and 403 boundaries. Pair this
release with Authentication Service v0.4.41 and Engine 0.183.309 or newer.
Release 1.6.120 completes the cross-tab session boundary under real browser
ordering. Shared cookie and generation reads now occur only after acquiring the
same origin-level mutex used by login commit, so a peer cannot cache a
half-written session. Storage events and BroadcastChannel feed one serialized
reconciliation path; a tab entering the login route also revalidates an already
committed cookie, covering refreshes and events missed during navigation.
Initial-transition 401 handling stays generation-aware, passive failures never
revoke a token, and explicit logout remains generation-bound and coalesced to a
single DELETE. Deterministic delayed-401 coverage runs TOTP and Passkey orderings
100 times, and the production browser smoke validates three-tab adoption,
refresh recovery, API access, WebSocket connectivity, and one explicit logout.
Pair this release with Authentication Service v0.4.39 and Engine 0.183.309
or newer.
Release 1.6.119 closes three persistence regressions found during the
1.6.442 integrated runtime review. External-service API hydration can now
replace the local healthy default, including with null, without assigning to
a getter-only computed property. OIDC site-access updates retain stable error
codes and bound MFA request digests when a rejection object is returned at the
top level. Load-balancer backend selection now follows an explicit child action
to the owning PortRule, so edit and upgrade PUT payloads retain the selected
serviceId. Browser tests cover the real model setter, the strict one-retry MFA
boundary, and the production DOM selector through the submitted API payload.
Pair this release with Authentication Service v0.4.38 and Engine 0.183.304
or newer.
Release 1.6.118 fixes OIDC site-access policy editing without weakening the
provider enablement boundary. Unrestricted mode clears stale authorized
identities before saving; restricted and required entries are normalized and
deduplicated by OIDC principal type and immutable external ID. Access expansion
opens the existing MFA security-confirmation dialog with a purpose and canonical
request digest supplied by the authentication service, retries exactly once,
and never retains the one-time ticket after completion or failure. Stable backend
codes are rendered as localized, actionable errors without exposing raw response
bodies. Pair this release with Authentication Service v0.4.37 and Engine
0.183.303 or newer.
Release 1.6.117 prevents an older same-origin browser tab from revoking or
clearing a session that a newer tab has just established. Explicit user logout
is now the only browser path that requests server-side token revocation. Passive
401, storage, WebSocket, timer, and route failures reconcile against a
non-sensitive session generation; ordinary 403 permission failures remain local
to the failed request. Login, cookie readback, generation commit, session
adoption, and explicit logout share one cross-tab mutex, with a tested
IndexedDB lease fallback when Web Locks is unavailable. OIDC transactions retain
the generation captured before leaving the origin, stale callbacks cannot
overwrite a newer login, and waiting tabs validate the shared cookie before
adopting it. JWTs remain cookie- and memory-only and are never persisted in Web
Storage. A precise 409 ClientSessionSuperseded response from the Engine is
treated as a stale completion rather than a failed active login, and request
options cannot override the provider, authorization value, or captured
generation. Pair this release with Engine 0.183.302 or newer for
session-bound, ordered, idempotent server logout protection.
Release 1.6.116 recognizes the MFA API's structured error code even when
the transport wraps it in a generic error. Sensitive settings updates open
the security-confirmation dialog and retry only after successful confirmation;
cancellation never resubmits the update. Unexpected API failures retain a
localized explanation with bounded HTTP status/code diagnostics, without
displaying raw response bodies. Use Engine 0.183.298 or newer for the
matching live v2-beta MFA settings and confirmation schema repair.
Release 1.6.115 closes the global resource-action menu before dispatching
the selected action. This prevents the row menu from remaining above account
edit and other modal forms, while preserving the selected resource and action
receiver. The same shared fix covers every resource table which uses this
menu; focused tests verify that the menu, trigger state, and anchor are closed
before the modal action executes.
Release 1.6.114 fixes the exact post-create exception captured during a real
ranchernode22 service creation. The live global service collection can contain
a transient empty slot while the API store merges a newly created resource; the
page-header observer now ignores only those unreadable entries before examining
application-service metadata. The same guard covers both observer and navigation
tree rebuild paths. Completion no longer performs the unrelated service reload
introduced by the two superseded diagnostic releases, while the saved payload,
route callback, hardware controls, and other page regions remain unchanged.
Release 1.6.113 force-loaded the saved service by API ID while diagnosing the
post-create failure. Instrumented browser evidence later located the exception
in the page-header observer before completion navigation, so the extra request
is removed in 1.6.114; 1.6.113 remains a diagnostic boundary.
Release 1.6.112 introduced the first-create refresh boundary found by the
formal ranchernode22 acceptance test. The API could return a deliberately
sparse service while that same record was already visible to the destination
stack, causing its computed fields to render before the launch configuration
was hydrated. The shared create/upgrade form now refreshes the persisted
service before navigation and treats an optional refresh failure as
non-authoritative because the save itself has already succeeded. Focused tests
cover the intended refresh ordering, fallback behaviour, receiver binding, and
unchanged hardware payloads. Real-host acceptance later proved Resource reload
could not hydrate a response without a self link; 1.6.112 is retained as that
diagnostic boundary. The Traditional Chinese capability label now describes
mknod as creating a device node instead of presenting a misleading phonetic
transliteration.
Release 1.6.111 fixes the post-save callback receiver boundary found by creating a real
service on a managed host. The API and node correctly created the service, but
the legacy component action target could lose its controller receiver before
navigation. All four container and virtual-machine create routes now pass
receiver-bound completion and cancellation callbacks to the shared form. The
resource and hardware payload is unchanged. Real-host acceptance subsequently
found a separate sparse-response render race; 1.6.111 is retained as that
diagnostic boundary rather than the current compatibility target.
Release 1.6.110 restores the classic (action (mut ...)) contract used by
command and environment editors, and accepts the modern array-like browser
clipboard type list used by key/value inputs. This closes the two client-side
exceptions found while filling the complete hardware/runtime form on a real
host; it retains the INIT spacing and completion fixes from 1.6.109.
Release 1.6.109 corrects the create and upgrade completion contract exposed by
real-host acceptance testing. Top-level create routes now pass classic named
actions to the shared form so Ember dispatch preserves the controller receiver;
the compatibility layer also refuses to forward a component prototype callback
as an action name. This prevents a successfully persisted service from leaving
the form open with undefined.get or a template-action error. A regression test
exercises the controller transition, and the init-process control has additional
desktop separation from the adjacent process-limit input without changing its
payload binding.
Release 1.6.108 attempted to close the first-create completion failure with a
closure callback. Real-host acceptance testing subsequently showed that the
legacy action compatibility path could still misroute the callback after the
service was already persisted. It is retained as a superseded diagnostic step,
not as the current compatibility target.
Release 1.6.107 removed saved-response dereferences from route selection, but
real-host acceptance testing showed that the deprecated callback dispatch still
failed after persistence. It is retained only as a superseded diagnostic step,
not as the current compatibility target.
Release 1.6.106 fixes the real first-service creation completion path. An
empty service-link set no longer sends a redundant action after the service is
already persisted, and a non-empty link update preserves the stack route
identity even if the API returns a partial resource. The route also keeps its
original stack ID independently of the mutable service response. A successful
first click therefore leaves the form instead of showing an error that could
invite a duplicate service submission.
Release 1.6.105 fixes the post-save transition for a newly created service:
the persisted service now remains in the completion chain instead of being
discarded by the service-link action. Stack-scoped create routes also fall back
to their stable stack query parameter, and advanced key/value inputs render
localized placeholders. The create and upgrade resource payloads remain
unchanged.
Release 1.6.104 keeps the authenticated browser-session and OIDC corrections
from 1.6.103. It also keeps the init-process checkbox inside its own resource
grid column, with the launch-configuration binding unchanged, so the control no
longer touches the adjacent process-limit input on create or upgrade forms.
Release 1.6.103 keeps an authenticated browser session when a non-auth API
request fails during startup, displays the nested OIDC/API explanation instead
of an empty alert, and activates a newly verified provider in unrestricted mode
so every identity accepted by that provider can sign in. Administrators can
still narrow access afterward with the existing site-access controls.
The language picker includes English, German, Persian, Filipino, French, Hungarian, Japanese, Korean, Brazilian Portuguese, Russian, Ukrainian, Simplified Chinese, and Traditional Chinese for Taiwan. Every selectable locale must satisfy the complete message contract and regional formatting gates documented in Localization. New security-sensitive authentication text is maintained in English and Traditional Chinese first; other locales inherit the complete English text until a reviewed translation is available, rather than displaying missing translation keys.
The manually dispatched validation workflow tests and builds the exact selected commit on a GitHub-hosted runner and retains the reviewed candidate for 30 days. Release publication remains a separate reviewed step.
npm ci --ignore-scripts
npm run build -- --environment=production
npm test
package_version=$(node -p 'require("./package.json").version')
bash scripts/package-static-candidate \
"$package_version" dist "build/ui/${package_version}.tar.gz"The packaging command uses the current Git commit timestamp by default, or an
explicit SOURCE_DATE_EPOCH, and emits a deterministic tarball plus a portable
SHA-256 file. It creates a candidate only; publishing remains a separate,
reviewed release step. The archive root and VERSION.txt must equal the
numeric package version; a preserved compatibility version must not be
silently substituted into a new release artifact.
Catalog cards and launch pages read optional
io.pasturestack.catalog.name.<locale> and
io.pasturestack.catalog.description.<locale> labels. Unknown locales and
third-party catalogs fall back to their canonical metadata instead of showing
an empty string or an untranslated key.
Container terminals, container logs, and virtual machine consoles use the movable window system documented in Console workspace. Terminal and log sessions can be reopened after a tab refresh or browser restart, and active output is shared across signed-in tabs without persisting upstream access tokens.
Host storage pages provide checkbox selection, state filtering, search, pagination, and one operator-confirmed removal action. Selection rules, preview behavior, and the concurrency limit are documented in operator-selected storage removal.
Linux shared memory, runtimes, GPU/graphics devices and advanced container limits use the shared Resources and hardware form. The guide covers coordinated agent/API rollout and the distinction between device visibility and exclusive GPU allocation.
OpenID Connect configuration, stable account-to-identity assignment, safe provider switching, and local recovery are documented in OpenID Connect. TOTP, passkeys, recovery codes, email account recovery, and administrator controls are documented in Multi-factor authentication.
The repository includes explicit modernization gates because its historical frontend toolchain cannot be trusted without review. See COMPATIBILITY.md, SECURITY.md, and ORIGIN.md.
The inherited project remains licensed under Apache License 2.0, with additional attribution in COPYRIGHT_DETAILS.md. Bundled dependencies retain their own licenses and notices. PastureStack contributors claim authorship only for their own changes.