Repository navigation
intact-20260615
Intact.AI release — 2026-06-15
Cut from the main branch. Everything from
intact-20260609 plus ~110 commits. This is a
pipeline-hardening release focused on upgrade correctness and air-gap
completeness: transitive container pins become a single source of truth in
config.yaml, the upgrade flow merges the new release's pins into the operator's
config, and VolWeb YARA + Velociraptor tooling ship inside the package for offline
installs.
This tag intentionally pins to an older module baseline (see Version pins) so it
can be installed first and upgraded forward into a newer tag to exercise the upgrade
flow end-to-end.
Transitive sidecar pins → config.yaml (headline)
The old live-scrape of each module's upstream docker-compose (via
transitive_resolver.py + an in-memory/disk cache + a defaults table) is gone. It
produced silent install-vs-upgrade drift — an operator hit it on 2026-06-14 when
install used postgres:15 (compose default) while upgrade scraped upstream's
postgres:13.0-alpine, and postgres-13 then refused to start against postgres-15 data.
- Single source of truth: every sidecar (
postgres/opensearch/redis/
nginx/rabbitmq) is now pinned explicitly underversions:inconfig.yaml
with a<module>_<sidecar>naming convention. - Both online and offline (air-gap) paths read the SAME entries via the bundled
manifest; pins are stamped into each module's.envbefore itsdocker compose up. - Prepare-time scraping + the obsolete drift-detection CI workflow were removed.
Config-aware upgrade
- The upgrade now merges the new release's
versions:block into the operator's
config.yamlbefore prepare reads it, with per-module backup/revert, smart
insertion, and safety assertions — so a box picks up new pins without clobbering
operator edits. - Prepare reads the target release's
config.yamlfor transitive pins (not the
build host's).
Air-gap completeness
- VolWeb YARA rulesets are bundled and auto-seeded on install and upgrade;
YARA-Forge is pulled from the release asset, not the source tree. - Bundle Velociraptor tools, backfill artifacts, and enable installed modules
so an offline box comes up complete.
Velociraptor
- Pre-stage the
velociraptor-collectorbinary for Hunt-collector generation. - Collector serves locally (no runtime internet round-trip); VolWeb compose-up race
gets a retry. - Refresh offline-collector downloads on upgrade (fixes the greyed-out musl
installer button).
Install resilience
- Wait for the dpkg lock before apt steps; Dockerfile build retries.
- Preflight + compose-up retry + skip-already-installed + journal dump on failure.
install_*_offlinebootstraps.envfrom scratch (fixes UI-driven fresh
install); timesketch postgres compose default aligned with the upstream pin.- Memory pipeline survives a VolWeb restart.
Upgrade pipeline fixes
- Pre-load all bundled images before the Phase-2 module loop; timesketch + volweb
offline upgrade load their sidecar image tars. - Always restart the backend after an intact upgrade (fixes a split-run footgun);
intactnever no-ops — prepare/online allow an intact-only refresh. - Stamp transitive pins in the Phase-2 resume (fixes a missed
redis:7-alpine). - Add VolWeb to
resume_upgrade_workflow's upgrade order.
UI
- The apply-package modal shows current vs target versions and filters downgrade
references; the online-upgrade / prepare-package modal flow is streamlined. - Null-safe the upgrade-modal
x-textexpressions (silences Alpine console errors);
drop the noisy "use the Apply card" hint from the upgrade-package upload log.
Module id cleanup
aws_prowler→prowler,azure_dfir_o365rc→o365rc(config keys).
Version pins
This tag pins to an older module baseline (install-then-upgrade testing):
versions:
elk: 9.4.2 # was 9.3.3
iris: v2.4.26 # was v2.4.27 (baseline)
velociraptor: '0.76.1' # was 0.76.5 (baseline)
prowler: '5.28.1' # renamed from aws_prowler
o365rc: 'latest' # renamed from azure_dfir_o365rc
# NEW — external sidecar pins now live here (single source of truth):
timesketch_opensearch: '2.11.0'
timesketch_postgres: '13.0-alpine'
timesketch_redis: '7-alpine'
timesketch_nginx: 'alpine'
iris_rabbitmq: '3-management-alpine'
volweb_postgres: '14.1'
volweb_redis: '7'Backend/module compose files now enforce a stamped .env via ${VAR:?} — stamp
.env before docker compose down.
Known issues
- Carried over: velociraptor downgrade crash, legacy v0.7.x post-upgrade disable,
run_command>64 KB stdout deadlock. docker compose downrequires a stamped.env(from the${VAR:?}enforcement
introduced this release).