Skip to content

IRIS Ops Studio 1.3.0 — Bounded Server Guard & Durable Recovery

Choose a tag to compare

@seypherWork seypherWork released this 27 Sep 10:10
· 2 commits to main since this release
d876ba6

IRIS Ops Studio 1.3.0 adds an optional IRIS-native managed endpoint for four
deliberately bounded administrative workflows. Server-owned approvals, fresh
preconditions and native readback make the result inspectable; persistent
receipts let operators investigate an uncertain outcome without resending it.

What's new

  • Server-controlled execution: deployment READ_ONLY/SUSPENDED states,
    native actor authorization, explicit target enrollment and separate,
    short-lived write approval for each guarded workflow.
  • Four bounded workflows: wallet EditResource/UseResource policy;
    availability of one eligible web application; grants on one custom test role;
    selected-role membership of one separate, disabled test account.
  • Recovery without repeat writes: actor/proof-bound operation receipts
    preserve the original result across interruptions and restarts. Inspection
    and reconciliation observe current state; they do not retry a possible write.
  • Independent review bundle: digest-checked source package, guided installer,
    strict TLS and public-only certificate preflight, and ownership-checked stop
    with retained data. No npm dependencies, automatic trust import or login-account
    creation.
  • Final audit corrections: recoverable stop cancellation/retry; accurate
    local-key cleanup warnings; startup failure handling even if the startup
    module never loads; consistent user-profile installation documentation.

Validation

269 JavaScript tests and 20 Linux native-log tests pass. The exact review ZIP
was extracted and installed in fresh IRIS Community 2026.2; 38 integration
checkpoints include authenticated changes, stale/revoked previews, native
readback, interruption/replay/restart recovery and desktop/mobile workflows.
Additional browser checks verify cleanup failures and missing/late startup
modules. See docs/final-audit-remediation-20260927.md for measurements, artifact
hashes, failed harness attempts and untested boundaries.

Install and scope

The standard console/IPM installation and optional managed guard are separate.
The guard is not automatically installed by the standard IPM module and does
not impose a safe mode on every console workspace or other native IRIS tools.
Use the attached review ZIP and its JUDGE-GUIDE.md for the managed evaluation.
Native operator provisioning, target enrollment and CA trust are explicit
administrator tasks. This is not general active-user management, a validated
production deployment or an in-place upgrade. Existing videos show earlier
console versions, not this new guard.

Managed review artifact: irisops-guard-enrolled-review-20260927-c.zip

SHA-256: 5AC960134DD8C27002BC163784CB76B782E7052B6E7F95C9ED3EA0407D85B36E