Skip to content

Releases: Reallysec/RST-AI-Copilot-for-Prometheus

v0.2.2

Choose a tag to compare

@sooua sooua released this 08 Oct 11:52
  • Investigations finish with a conclusion: when the AI had used all its query rounds it sometimes kept writing
    its reasoning instead of the verdict, and the result showed as "degraded". The last round now asks for the
    verdict explicitly, and an unreadable reply gets one more try before falling back.
  • License time check uses HTTPS only: trusted time now comes from the license server's signed time or an HTTPS
    Date header, no longer from UDP NTP. Nothing to configure; RSTLIC_NTP is no longer read. Closed networks that
    relied on an internal NTP server set RSTLIC_TIME_URL to an internal HTTPS source instead.

Download and install

File Description
RST-AI-Copilot-for-Prometheus-0.2.2.tar.gz Offline bundle (gateway image and deployment files; Community Edition without a license, Professional or Enterprise once one is imported)
RST-AI-Copilot-for-Prometheus-0.2.2.tar.gz.sha256 SHA-256 checksum
sha256sum -c RST-AI-Copilot-for-Prometheus-0.2.2.tar.gz.sha256
tar xzf RST-AI-Copilot-for-Prometheus-0.2.2.tar.gz && cd RST-AI-Copilot-for-Prometheus-0.2.2 && ./deploy.sh

Documentation: https://reallysec.com/en/docs/prometheus-ai-copilot

v0.2.1

Choose a tag to compare

@sooua sooua released this 08 Oct 10:53
  • Investigation timelines show the right times: the model now receives metric samples and the alert start as
    readable times in the product timezone (RST_TIMEZONE) instead of raw Unix timestamps it sometimes converted wrong.
  • Lost license-server contact falls back to Community: when an online install has not reached the license
    server for longer than the 3-day offline grace period, paid features pause and only one user can sign in, the
    same as an expired license; free features keep working and everything returns once contact resumes. Before,
    paid features kept running while queries were blocked. Offline licenses are not affected.
  • Edition wording matches the product: only AI rule generation needs Professional; writing, approving, writing
    back and rolling back alert rules by hand is free, and the Alert rules menu no longer shows a lock. The reports
    page as a whole needs Professional.
  • Corrected hints: the audit page explains that auditing is controlled by RST_AUDIT_ENABLED in .env; the
    online update card names ./deploy/rst-update.sh; investigation reports are titled "Alert investigation report"
    and pushing a conclusion goes to every destination subscribed to findings.
  • Smaller bundle: vendor test and repository files (deploy/e2e/, deploy/public-repo/) are no longer shipped.

Download and install

File Description
RST-AI-Copilot-for-Prometheus-0.2.1.tar.gz Offline bundle (gateway image and deployment files; Community Edition without a license, Professional or Enterprise once one is imported)
RST-AI-Copilot-for-Prometheus-0.2.1.tar.gz.sha256 SHA-256 checksum
sha256sum -c RST-AI-Copilot-for-Prometheus-0.2.1.tar.gz.sha256
tar xzf RST-AI-Copilot-for-Prometheus-0.2.1.tar.gz && cd RST-AI-Copilot-for-Prometheus-0.2.1 && ./deploy.sh

Documentation: https://reallysec.com/en/docs/prometheus-ai-copilot

v0.2.0

Choose a tag to compare

@sooua sooua released this 08 Oct 08:33
  • New names: the repositories are now Reallysec/RST-AI-Copilot-for-Prometheus (public download) and
    RST-AI-Copilot-for-Prometheus-Enterprise; GitHub redirects the old addresses. The bundle and its top directory
    are RST-AI-Copilot-for-Prometheus-<version>, images and containers rst-ai-copilot-for-prometheus-*, and new
    installs go to /opt/rst-ai-copilot-for-prometheus. The license product ID is unchanged.
  • Upgrading from 0.1.x needs one manual step: a 0.1.x gateway cannot update online to 0.2.0, because it looks for
    the old bundle name. Run install.sh (it upgrades an existing /opt/rst-prometheus-ai-copilot in place) or unpack
    the bundle into the existing install directory and re-run deploy.sh. Keep the install directory: it names the
    data volumes and holds the host fingerprint. Online updates work again from 0.2.0 on. See section 14 of the
    deployment guide.
  • EULA dialog: switching the agreement language switches the whole dialog (title, checkbox, buttons), not only
    the text.

Download and install

File Description
RST-AI-Copilot-for-Prometheus-0.2.0.tar.gz Offline bundle (gateway image and deployment files; Community Edition without a license, Professional or Enterprise once one is imported)
RST-AI-Copilot-for-Prometheus-0.2.0.tar.gz.sha256 SHA-256 checksum
sha256sum -c RST-AI-Copilot-for-Prometheus-0.2.0.tar.gz.sha256
tar xzf RST-AI-Copilot-for-Prometheus-0.2.0.tar.gz && cd RST-AI-Copilot-for-Prometheus-0.2.0 && ./deploy.sh

Documentation: https://reallysec.com/en/docs/prometheus-ai-copilot

v0.1.1

Choose a tag to compare

@sooua sooua released this 07 Oct 16:36
  • Settings in .env now take effect: the gateway in docker-compose.prod.yml reads .env as a whole
    (env_file) in addition to the keys it lists. In 0.1.0, keys documented only in the deployment guide, such as
    RST_CONTENT_AUTO_APPLY and RST_DISCOVERY_INTERVAL_SECONDS, were silently ignored. Works with every
    Docker Compose v2; RST_ENV_FILE can point at another file.

Download and install

File Description
RST-Prometheus-AI-Copilot-0.1.1.tar.gz Offline bundle (gateway image and deployment files; Community Edition without a license, Professional or Enterprise once one is imported)
RST-Prometheus-AI-Copilot-0.1.1.tar.gz.sha256 SHA-256 checksum
sha256sum -c RST-Prometheus-AI-Copilot-0.1.1.tar.gz.sha256
tar xzf RST-Prometheus-AI-Copilot-0.1.1.tar.gz && cd RST-Prometheus-AI-Copilot-0.1.1 && ./deploy.sh

Documentation: https://reallysec.com/en/docs/prometheus-ai-copilot

v0.1.0

Choose a tag to compare

@sooua sooua released this 07 Oct 13:48

First preview of RST AI Copilot for Prometheus, an AI copilot for network operations (switches, routers and
firewalls monitored with snmp_exporter and blackbox_exporter). For demos and pilots, not for production.

  • Data sources: connects to your existing Prometheus and Alertmanager; Grafana is optional and used for links.
    Addresses and Basic / Bearer credentials are asked by deploy.sh or set later under Settings → Data sources,
    with a connection test before saving.
  • Storage: one bundled PostgreSQL 16 with pgvector (pgvector/pgvector:pg16) holds accounts, audit events,
    report history, the notification outbox and knowledge-base vectors. A customer PostgreSQL can be used instead
    through RST_DB_URL.
  • Reports: daily and weekly network operations reports (alert overview, top-utilised links, errors and
    discards, device availability, capacity risk, AI investigation summaries) with history, schedules and export.
  • Notifications: Feishu, DingTalk, WeCom, email and webhook. Only AI output is delivered (investigation
    conclusions, reports); alert routing stays with Alertmanager.
  • Deployment: Caddy TLS front end, optional OIDC single sign-on, an offline all-in-one bundle with SHA-256
    checksum, and docker-compose.lab-demo.yml, which layers 30 simulated network devices on the deployment stack
    for demos.
  • Roles: admin, operator, viewer.
  • Product name: the product is now called RST AI Copilot for Prometheus. Image, bundle, repository and
    configuration names are unchanged (rst-prometheus-ai-copilot-*, RST-Prometheus-AI-Copilot-*).
  • EULA 1.1 (effective 2026-10-06): aligned with the other Reallysec products: Chinese text prevails, liability
    cap (Paid Editions: fees paid in the prior 12 months; Community, trial and preview: the greater of fees paid and
    RMB 50), warranty for the Subscription Term, IP indemnity for Paid Editions, audit terms, export control and
    sanctions, privacy and cross-border sections, and a verified list of what the gateway sends outside your
    network. Every user now confirms the EULA at first sign-in and after each EULA version change; acceptances are
    stored in PostgreSQL and in the audit log.
  • Content packs: RST_CONTENT_AUTO_APPLY=0 stores newer content packs without activating them, so an
    administrator decides when to switch.
  • Model endpoint: there is no built-in default any more; LLM_BASE_URL (or llm_providers.yml) must name the
    endpoint, otherwise no model is configured. A model is optional: without one, queries fall back to keyword
    generation and are marked low-confidence; deploy.sh lets you skip it and configure it later in Settings.
  • EULA dialog: a 中文 | English switch shows either language of the agreement whatever the browser language.
  • Device discovery: runs hourly; an empty or failed run (for example right after installation, before
    Prometheus has data) is retried after 5 minutes.

Known limits of the preview: several pages are still being reworked for network operations; the edition matrix
for this product is not final.

Download and install

File Description
RST-Prometheus-AI-Copilot-0.1.0.tar.gz Offline bundle (gateway image and deployment files; Community Edition without a license, Professional or Enterprise once one is imported)
RST-Prometheus-AI-Copilot-0.1.0.tar.gz.sha256 SHA-256 checksum
sha256sum -c RST-Prometheus-AI-Copilot-0.1.0.tar.gz.sha256
tar xzf RST-Prometheus-AI-Copilot-0.1.0.tar.gz && cd RST-Prometheus-AI-Copilot-0.1.0 && ./deploy.sh

Documentation: https://reallysec.com/en/docs/prometheus-ai-copilot

中文说明

RST AI Copilot for Prometheus 首个预览版:面向网络运维(交换机、路由器、防火墙,用 snmp_exporter 和 blackbox_exporter
采集)的 AI 副驾。用于演示和试点,不建议用于生产。

  • 数据源:连接已有的 Prometheus 和 Alertmanager,Grafana 可选(用于跳转链接)。地址和 Basic / Bearer 认证由
    deploy.sh 询问,也可以之后在「设置 → 数据源连接」里填,保存前先测连通。
  • 存储:自带一套 PostgreSQL 16 + pgvector(pgvector/pgvector:pg16),存账号、审计事件、报表历史、通知出站队列和
    知识库向量;也可以通过 RST_DB_URL 改用客户自己的 PostgreSQL。
  • 报表:网络运维日报、周报(告警概况、利用率 TOP 链路、错包 / 丢包、设备可用率、容量风险、AI 调查结论摘要),
    支持历史、定时生成和导出。
  • 通知:飞书、钉钉、企业微信、邮件、Webhook。只投递 AI 产出(调查结论、报表),告警路由仍由 Alertmanager 负责。
  • 部署:Caddy TLS 入口、可选 OIDC 单点登录、带 SHA-256 校验的离线一体包,以及 docker-compose.lab-demo.yml:
    在部署栈上叠加 30 台模拟网络设备做演示。
  • 角色:admin(管理员)、operator(运维工程师)、viewer(只读)。
  • 产品名称:产品更名为 RST AI Copilot for Prometheus。镜像、交付包、仓库和配置名称不变
    (rst-prometheus-ai-copilot-*、RST-Prometheus-AI-Copilot-*)。
  • EULA 1.1(2026-10-06 生效):与斯普朗克其他产品对齐:以中文文本为准;责任上限(付费版本为前 12 个月实付,
    社区版、试用和预览功能为实付与人民币 50 元取高);付费版本订阅期内担保;付费版本知识产权赔偿;审计条款;出口
    管制与制裁;隐私与数据出境条款;以及按代码核实的数据外发清单。每位用户首次登录及 EULA 版本变更后都需勾选同意,
    同意记录写入 PostgreSQL 和审计日志。
  • 内容包:RST_CONTENT_AUTO_APPLY=0 时较新的内容包只保存不启用,由管理员决定何时切换。
  • 模型端点:不再有内置默认端点,须通过 LLM_BASE_URL(或 llm_providers.yml)指定,否则视为未配置模型。
    模型是可选的:不配时查询退回关键词生成并标为低可信度;deploy.sh 可以跳过,之后在「设置」里再配。
  • EULA 弹窗:可在「中文 | English」之间切换协议正文,不受浏览器语言限制。
  • 设备自动发现:每小时一次;某次结果为空或失败(例如刚安装、Prometheus 还没有数据)时,5 分钟后重试。

预览版已知限制:部分页面仍在按网络运维场景改造;本产品的版本功能矩阵尚未最终确定。

下载与安装

文件 说明
RST-Prometheus-AI-Copilot-0.1.0.tar.gz 离线一体包(网关镜像 + 部署文件;不导入许可为社区版,导入许可解锁专业版或企业版)
RST-Prometheus-AI-Copilot-0.1.0.tar.gz.sha256 SHA-256 校验文件
sha256sum -c RST-Prometheus-AI-Copilot-0.1.0.tar.gz.sha256
tar xzf RST-Prometheus-AI-Copilot-0.1.0.tar.gz && cd RST-Prometheus-AI-Copilot-0.1.0 && ./deploy.sh

文档:https://reallysec.com/docs/prometheus-ai-copilot