Skip to content

intact-20260615

Choose a tag to compare

@NofLevi10root NofLevi10root released this 21 Jul 14:51
· 1768 commits to main since this release

Intact.AI release — 2026-06-15

Cut from the main branch. Everything from
intact-20260609 plus ~110 commits. This is a
pipeline-hardening release focused on upgrade correctness and air-gap
completeness
: transitive container pins become a single source of truth in
config.yaml, the upgrade flow merges the new release's pins into the operator's
config, and VolWeb YARA + Velociraptor tooling ship inside the package for offline
installs.

This tag intentionally pins to an older module baseline (see Version pins) so it
can be installed first and upgraded forward into a newer tag to exercise the upgrade
flow end-to-end.

Transitive sidecar pins → config.yaml (headline)

The old live-scrape of each module's upstream docker-compose (via
transitive_resolver.py + an in-memory/disk cache + a defaults table) is gone. It
produced silent install-vs-upgrade drift — an operator hit it on 2026-06-14 when
install used postgres:15 (compose default) while upgrade scraped upstream's
postgres:13.0-alpine, and postgres-13 then refused to start against postgres-15 data.

  • Single source of truth: every sidecar (postgres / opensearch / redis /
    nginx / rabbitmq) is now pinned explicitly under versions: in config.yaml
    with a <module>_<sidecar> naming convention.
  • Both online and offline (air-gap) paths read the SAME entries via the bundled
    manifest; pins are stamped into each module's .env before its docker compose up.
  • Prepare-time scraping + the obsolete drift-detection CI workflow were removed.

Config-aware upgrade

  • The upgrade now merges the new release's versions: block into the operator's
    config.yaml
    before prepare reads it, with per-module backup/revert, smart
    insertion, and safety assertions — so a box picks up new pins without clobbering
    operator edits.
  • Prepare reads the target release's config.yaml for transitive pins (not the
    build host's).

Air-gap completeness

  • VolWeb YARA rulesets are bundled and auto-seeded on install and upgrade;
    YARA-Forge is pulled from the release asset, not the source tree.
  • Bundle Velociraptor tools, backfill artifacts, and enable installed modules
    so an offline box comes up complete.

Velociraptor

  • Pre-stage the velociraptor-collector binary for Hunt-collector generation.
  • Collector serves locally (no runtime internet round-trip); VolWeb compose-up race
    gets a retry.
  • Refresh offline-collector downloads on upgrade (fixes the greyed-out musl
    installer button).

Install resilience

  • Wait for the dpkg lock before apt steps; Dockerfile build retries.
  • Preflight + compose-up retry + skip-already-installed + journal dump on failure.
  • install_*_offline bootstraps .env from scratch (fixes UI-driven fresh
    install); timesketch postgres compose default aligned with the upstream pin.
  • Memory pipeline survives a VolWeb restart.

Upgrade pipeline fixes

  • Pre-load all bundled images before the Phase-2 module loop; timesketch + volweb
    offline upgrade load their sidecar image tars.
  • Always restart the backend after an intact upgrade (fixes a split-run footgun);
    intact never no-ops — prepare/online allow an intact-only refresh.
  • Stamp transitive pins in the Phase-2 resume (fixes a missed redis:7-alpine).
  • Add VolWeb to resume_upgrade_workflow's upgrade order.

UI

  • The apply-package modal shows current vs target versions and filters downgrade
    references; the online-upgrade / prepare-package modal flow is streamlined.
  • Null-safe the upgrade-modal x-text expressions (silences Alpine console errors);
    drop the noisy "use the Apply card" hint from the upgrade-package upload log.

Module id cleanup

  • aws_prowler → prowler, azure_dfir_o365rc → o365rc (config keys).

Version pins

This tag pins to an older module baseline (install-then-upgrade testing):

versions:
  elk:          9.4.2      # was 9.3.3
  iris:         v2.4.26    # was v2.4.27   (baseline)
  velociraptor: '0.76.1'   # was 0.76.5    (baseline)
  prowler:      '5.28.1'   # renamed from aws_prowler
  o365rc:       'latest'   # renamed from azure_dfir_o365rc

  # NEW — external sidecar pins now live here (single source of truth):
  timesketch_opensearch: '2.11.0'
  timesketch_postgres:   '13.0-alpine'
  timesketch_redis:      '7-alpine'
  timesketch_nginx:      'alpine'
  iris_rabbitmq:         '3-management-alpine'
  volweb_postgres:       '14.1'
  volweb_redis:          '7'

Backend/module compose files now enforce a stamped .env via ${VAR:?} — stamp
.env before docker compose down.

Known issues

  • Carried over: velociraptor downgrade crash, legacy v0.7.x post-upgrade disable,
    run_command >64 KB stdout deadlock.
  • docker compose down requires a stamped .env (from the ${VAR:?} enforcement
    introduced this release).

Source

intact-20260615