v2.0.0
RemoteAppClient 2.0.0
A survivability release. The fleet now rides out the things that used to need a human — a network blip, a lost report, an expired session — and, for the first time, an OS swap under the server. All components are 2.0.0.0.
No database schema change since 1.9.0 — nothing to migrate.
Surviving the server's own OS
deploy/backup.sh+deploy/restore.shcapture and re-adopt the fleet's identity: the CA that issued every client certificate, the command-signing key, the bastion SSH host key each agent pins, and the database. Devices are never "imported" — their identity lives on the device. Restore these and an OS swap is invisible to all of them; miss the SSH host key and every tunnel breaks.- The order is the trick:
04-serveronly generates secrets that are missing and rebuildsbastion.envfrom whichever host key is present, so restoring first makes the installer adopt the fleet instead of locking it out. - The same backup from the console (Server settings → Backup). A root helper does the privileged part — the server cannot read the host key — and the archive is always passphrase-encrypted: it leaves the box through an 8-hour admin session, and the keys inside cannot be revoked. The server keeps no copy of the passphrase and drops the archive as it hands it over.
VNC that comes back on its own
- A network blip no longer kills VNC for ~6 minutes. The bastion released a dropped session's reverse-forward port only after a 120s × 3 keepalive, while the agent gave the link up in 45s — so a returning agent could not rebind its own (deterministic) port and
ExitOnForwardFailurekilled the fresh tunnel. Now the bastion mirrors the agent (15 × 3), the agent retries across the window, and the console waits for the RFB greeting instead of launching a viewer at a tunnel that isn't there. - The VNC-secret report retries until the server confirms receipt. A lost one-shot report used to leave a device with TightVNC running but no server-side password until someone restarted the agent — the failure mode of fresh installs on mobile / CG-NAT links.
Fewer dead ends
- Restart RACD (Devices → Commands): restarts VNC → Helper → agent, in that order, and verifies the Helper is alive before the agent goes down — it is the only thing that can revive a stopped agent. Windows is not rebooted.
- An expired session says so and returns to sign-in, instead of surfacing a raw
401. - Dependency bumps (NuGet + GitHub Actions, Avalonia 12.1) and a warning-free Linux console build.
Upgrading
Server and agents are backward compatible; there is no schema change. The bastion keepalive lives in deploy/steps/05-bastion.sh — a box built before 2.0.0 should get ClientAliveInterval 15 / ClientAliveCountMax 3, or re-run ./deploy/setup.sh 05-bastion 12-backup.
Artifacts
RemoteAgent.exe,RemoteAgent.Updater.exe,RemoteClient.exe,RemoteClient.Lite.exe— Windows x64, self-contained single-fileRemoteServer-linux-x64.tar.gz— serverremoteclient_2.0.0_amd64.deb— Linux operator console