Skip to content

v0.4.0 — API key scope, target health, tier-1 UX

Choose a tag to compare

@blink-zero blink-zero released this 06 Jun 13:02
· 93 commits to main since this release
0da6fde

Highlights

New features

  • Per-API-key role override + scope (#57) — every API key can now be issued with a role at or below the owning user's role and a scope band: read-only / action-only / deploy-only / full. JWT (browser) sessions are still full-role + full-scope; the new restrictions apply only to API keys, letting you issue narrow, blast-radius-limited keys for automation. Backwards-compatible: existing keys default to inheriting the owning user's role with full scope.
  • Periodic target health checks (#55) — Forgemill now polls each registered target on a cadence and surfaces the status in the Targets list. The connection-test failure UX in the target form was also rewritten — failures now distinguish between unreachable, auth-failed, and partial-success rather than collapsing everything into a generic error.
  • Tier-1 UX refresh on VMs, Targets, Templates (#51, #52) — table density tuning, sortable columns, better empty states, consistent filter/search behaviour across cards and table views.

UI / UX

  • Permissions help popover on the target creation form (#50, #53, #54) — explains exactly which hypervisor permissions Forgemill needs; rendered via portal so it escapes ancestor stacking contexts, and clamped to the viewport so it never opens off-screen.

Fixes

  • Targets test endpoint (#56) — /api/targets/{id}/test returns HTTP 200 with {success: false} on connection failures rather than throwing an HTTP error; the UI now branches on response.success instead of treating it as a thrown error, so the user sees the actual failure reason.

Internals

  • Backend migration V36 adds role and scope columns to api_keys. Additive, NULL on existing rows = old behaviour.

Deferred

  • Ubuntu 26.04 LTS template support was attempted (#58, #59) but reverted (#60). The early-release mirror pool on releases.ubuntu.com/26.04/ was exceeding Go's default 10 s TLS-handshake timeout for both Forgemill and Packer, causing builds to fail at the ISO download. A complete fix needs Forgemill to pre-download the ISO with retry-aware logic and pass it to Packer via the cache directory. Tracked for a future release once the mirror pool catches up or the pre-download mechanism is in place.

Upgrade

  • docker pull ghcr.io/blink-zero/forgemill:v0.4.0 (or :0.4, :0)
  • Migration V36 runs automatically on startup. Additive — safe to roll back to v0.3.0 if needed.

Full changelog

v0.3.0...v0.4.0 — v0.3.0...v0.4.0