Repository navigation
v2.3.0
CBM 2.3.0 adds two-factor authentication, agent settings managed from CBM, and smarter handling of disk space on the agent hosts.
Upgrade notes
- Update both the controller and the agents (re-run the install command on each host, or pull
ghcr.io/holo795/cbm-agent:2.3.0). Migrations 0029 and 0030 run automatically when the controller starts (newTwoFactortable, new columns on users, agents and settings). - Agents still on 2.2.x keep working with a 2.3.0 controller, but ignore the settings set in CBM and keep the old disk behaviour until they're updated.
- Settings already set by environment variable on a host (
AGENT_CONCURRENCY,AGENT_MIN_FREE_MB,LOG_LEVEL) keep winning: they show as locked in CBM. Remove them from the agent container to manage them from CBM instead. - Nothing changes for anyone until they turn two-factor on, or an admin requires it.
- Restoring CBM from a recovery file turns two-factor off for every account (its secrets are tied to the old install's
BETTER_AUTH_SECRET); people set it up again from Profile, and accounts the policy covers are asked at sign-in.
Two-factor authentication
- Authenticator app + backup codes. From Profile → Two-factor authentication: scan a QR code (or type the key) in 1Password, Bitwarden, Google Authenticator, Aegis…, confirm with a first code, and keep the 10 single-use backup codes. New backup codes or turning it off are on the same card.
- Asked after every kind of sign-in — password, and also GitHub / Google / GitLab: no session exists until the code is checked, so a compromised provider account isn't enough. Trust this device for 30 days is available; wrong codes lock the account for a few minutes and a code can't be reused.
- Admin policy. Settings → Two-factor authentication: optional, required for admins, or required for everyone. A covered account that hasn't set it up is held on a setup page until it does, and can't turn it off. The section shows how many accounts don't use it yet.
- Admin reset. On Users, members with two-factor carry a 2FA badge; … → Reset two-factor helps someone who lost their phone (their app, backup codes, trusted devices and sessions stop working).
- Accounts that only sign in with a social provider can set it up without a password. API tokens (MCP) and agents are not affected.
Agent settings from CBM
- Agents → Default settings sets, for every agent: jobs at once, free space kept on the host, copy mode and log level. The gear on an agent's row overrides them for that host only; an empty field keeps the default.
- Changes apply on the agent's next heartbeat — no reinstall, no restart.
- A value set by environment variable on the host still wins; the field is then locked and shows the host's value. The agents list shows each host's settings in effect and flags custom ones.
Disk space on the agent host
- Before copying a volume or host folder, the agent now measures it and compares it with the free space on its work dir, before freezing anything.
- Copy mode for tar destinations (new, per agent or by default;
AGENT_STAGING_MODE): Auto copies through the host when it fits and otherwise sends the volume straight to the destination; Local always copies through the host and fails cleanly, with the sizes, when it doesn't fit; Direct always sends straight to the destination. A direct send keeps the containers frozen until the upload ends, and the backup log says so. - Encrypted backups no longer need twice the room: the copy is checked, hashed and encrypted in a single pass.
- The restic engine always needs the local copy: with too little room it now fails cleanly with the sizes instead of filling the disk.
- A failed backup no longer leaves its partial copy in the work dir, and a failed copy no longer leaves a helper container running.
Also
- Social sign-up from an invitation. The invitation page now shows Continue with … for each configured provider; an invitee could only sign up with a password before.
Images
Published to the GitHub Container Registry — also tagged :2.3 and :latest:
docker pull ghcr.io/holo795/cbm-controller:2.3.0
docker pull ghcr.io/holo795/cbm-agent:2.3.0
docker pull ghcr.io/holo795/cbm-mcp:2.3.0- 📦 cbm-controller
- 📦 cbm-agent
- 📦 cbm-mcp