Skip to content

History / Troubleshooting

Revisions

  • IRIS-NG-v2.8.0 release pass: Changelog row (verified executive summary: writer claims, deterministic checks, verifier role, one automatic revise, review questions with proposed options, the answers pass, Draft / Verified pill, Audit tab, the Verify executive summaries switch + the Case Summary verifier override row, the new API keys and routes; ONE migration c4d9a2e7f1b3; chart 1.8.0), Kubernetes chart 1.8.0 / appVersion / pull examples, AI Features "Executive case summary" rewritten for the pipeline (seven steps, the flag-code table by severity, review questions + the answers pass, status + audit, roles / settings / budgets, the evidence rules updated: counts rendered server-side, names allowed only when sourced, an upgrading paragraph) + the Admin UI override row and checkbox + synthesizer-routing wording + the manual-override Editable cell + two budget-table rows, API Reference "Added in IRIS-NG-v2.8.0" (the GET /summary keys, the verification payload, answer + apply-answers with their 404 / 409 / 400 reasons, the case-details keys, the settings field) + three table rows + the case-details paragraph, Troubleshooting four entries (Draft · not reviewed after the upgrade; generation takes minutes; checks only / verifier unavailable / verifier failed / carried; Apply answers disabled), Getting Started migrations banner + the AI paragraph, Home AI-layer + Settings wording, Architecture hook-table row (the answers pass fires the hook; the two case-payload keys), Development Guide two gotchas (the activity-log timestamp is a wall-clock value in disguise; changing a CHECK constraint is a data migration first)

    @zach115th zach115th committed Oct 10, 2026
  • IRIS-NG-v2.7.0 release pass: Changelog row (any number of AI backends: cards + "+ Add backend", per-card save / delete, the active radio, the ai_backend table, the per-backend admin routes; ONE migration importing the two slots; the slot keys retired; chart 1.7.0), Kubernetes chart 1.7.0 / appVersion / pull examples, AI Features "Admin UI" rewritten for cards (rules: unique labels, the active backend undeletable, first backend becomes active, pins fall back; overrides by label; write-only keys per card; the upgrade paragraph) + "backend" wording in the OpenAI / Bedrock / synthesizer / declines sections, Getting Started AI paragraph + migrations banner (2.7.0 added), Troubleshooting new entry ("Save the backend first" / Delete refuses the active one / the two slots became cards) + backend wording, API Reference "Added in IRIS-NG-v2.7.0" (the five routes, the pointers, the retired keys) + the 2.5.0 row marked replaced, Development Guide gotcha (retiring a declared field from an auto-schema exposes the column), AI Task Suggester + Home wording

    @zach115th zach115th committed Oct 9, 2026
  • IRIS-NG-v2.5.4 + v2.6.0 release pass: Changelog rows (2.5.4 dependency-only: source-map-js 1.2.2, postcss-selector-parser 7.1.6 via npm overrides; 2.6.0: the OpenAI provider with max_completion_tokens and the self-healing chat-completions request shape; no migrations; charts 1.5.4 / 1.6.0), Kubernetes chart 1.6.0 / appVersion / pull examples, AI Features new "OpenAI (api.openai.com)" section + overview, Provider select, supported-backends table and a max_completion_tokens budget note, Troubleshooting entry for "Unsupported parameter: 'max_tokens'" (before 2.6.0 upgrade; since, either provider), API Reference "Added in IRIS-NG-v2.6.0" (openai_api accepted), Dependency Policy UI-dependencies bullet (build-stage PostCSS packages; the overrides pin), Development Guide adapter gotcha (second subclass; memory scope per process vs per instance), Getting Started + Home provider mentions

    @zach115th zach115th committed Oct 9, 2026
  • IRIS-NG-v2.5.3 release pass: Changelog row (the output-limit retry on the six remaining JSON surfaces with raised budgets; Dependabot #139 npm group incl. joi GHSA-wr44-6hxh-3jwq, #140 python group incl. PyJWT 2.15.1, #141 cryptography floor; no migration; chart 1.5.3), Kubernetes chart 1.5.3 / appVersion / pull examples, AI Features budget table (+4 rows incl. the executive summary's specialists / synthesis; prose surfaces note) + timeout rows + the retry paragraph's version line, Troubleshooting entry extended to the 2.5.3 surfaces, Dependency Policy paragraph on PyJWT (OIDC signature mode, per-version probe) and the e2e-only packages

    @zach115th zach115th committed Oct 8, 2026
  • IRIS-NG-v2.5.1 + v2.5.2 release pass: Changelog rows (task-suggester budget + compact retry; the shared output-limit retry across the operational summary, SitRep draft, cluster narrative, alert-cluster triage and ICS pass with raised budgets; no migrations; charts 1.5.1 / 1.5.2), Kubernetes chart 1.5.2 / appVersion / pull examples, AI Features max_tokens section (per-surface budget table, the retry routine, measured Kimi K3 figures) + timeout table rows, Troubleshooting ("returned no JSON object" / "hit the output limit twice" entry; the Bedrock entry points at the retry), Development Guide gotcha (JSON surfaces call ask_json)

    @zach115th zach115th committed Oct 8, 2026
  • IRIS-NG-v2.5.0 release pass: Changelog row (AWS Bedrock provider per AI slot with the inference-profile catalog; write-only AI API keys; war-room Notes rail right-click menus / /note / ?note= #137; one migration; chart 1.5.0), Kubernetes chart 1.5.0 / appVersion / pull examples, Getting Started migrations note + AI backend paragraph, Home settings pointer, AI Features new "AWS Bedrock" section (region / model / key, Load models, IAM permission, reasoning blocks, no guardrail, temperature retry, cached tokens) + overview + supported-backends table + reasoning-format row + write-only keys, API Reference "Added in IRIS-NG-v2.5.0" (settings provider keys, *_api_key_set, catalogs, the catalog endpoint, war-room note content / move), Troubleshooting four AI entries (502 during a restart, ListInferenceProfiles 403, temperature / empty reasoning reply, empty API Key field), War Rooms stream /note + Notes rail menus, Development Guide provider-adapter gotcha

    @zach115th zach115th committed Oct 7, 2026
  • IRIS-NG-v2.4.6 release pass: Changelog row (#138 Executive Case Summary changes fire on_postload_case_update; executive_summary in case payloads; worker-context hook attribution; no migration; chart 1.4.6), Kubernetes chart 1.4.6 / appVersion / pull examples, Architecture hook row, Troubleshooting 'Modules and webhooks' subsection, API Reference ai/summary rows + case-details payload note, AI Features executive-summary hooks paragraph

    @zach115th zach115th committed Oct 6, 2026
  • IRIS-NG-v2.4.2 release pass: Changelog row (Assets Save dropped a changed Compromise Status; no migration; app image rebuild; chart 1.4.2), Kubernetes chart 1.4.2 / appVersion / pull examples, Troubleshooting new Assets section with the Full editor workaround for older versions

    @zach115th zach115th committed Oct 2, 2026
  • IRIS-NG-v2.4.1 release pass: the four 'not yet released' annotations flipped to since IRIS-NG-v2.4.1 (API-Reference, Architecture, Troubleshooting), Changelog row linked to the release + chart 1.4.1, Kubernetes chart 1.4.1 / appVersion / pull examples, Getting Started migrations note adds 2.4.1 (one migration)

    @zach115th zach115th committed Oct 1, 2026
  • Summary edits fire on_postload_case_update (#128, on main, not yet released): Changelog unreleased row (also guest mentions/teams/assignees + the dependency bumps), Architecture hooks table, API-Reference summary route, Troubleshooting "Modules and webhooks" entry, Dependency-Policy SQLAlchemy 2.1 hold

    @zach115th zach115th committed Oct 1, 2026
  • IRIS-NG-v2.4.0 release pass: every 'not yet released' annotation flipped (guests, guest portal, operational summary, update script, STIX fix), chart 1.4.0 / appVersion on Kubernetes, upgrade note lists 2.4.0's four migrations

    @zach115th zach115th committed Sep 30, 2026
  • scripts/update.sh: one-command clone update on Getting Started (with the first-run bootstrap and the by-hand backup line), Home row, Troubleshooting entries, Guest Portal --enable-portal, changelog

    @zach115th zach115th committed Sep 30, 2026
  • Guest Portal page (guests, sign-in, tunnel modes, agent, room addresses, troubleshooting); War Rooms Summary tab and guests; operational summary on AI Features; not-yet-released API families; STIX export fix and the narrative-export defect noted; troubleshooting, changelog, security, upgrade, Kubernetes and dev-guide notes

    @zach115th zach115th committed Sep 30, 2026
  • IRIS-NG-v2.3.0 release pass: note tags (#129) and note-to-IOC links (#130) marked released; #130 sections on AI Features, API Reference, Troubleshooting, Development Guide; chart 1.3.0; migration note on Getting Started; changelog row

    @zach115th zach115th committed Sep 28, 2026
  • Note tags (#129, on main, not yet released): AI Features tag-suggester section (notes, case vocabulary, 6000-token budget + compact retry), API Reference rows (tag-suggestion object_type note; legacy note routes note_tags), Home, Case Export/Import, Troubleshooting entry, Development Guide gotcha

    @zach115th zach115th committed Sep 27, 2026
  • IRIS-NG-v2.2.1 release pass: task suggester, chat follow-ups, SitRep deltas and leadership event marked as released; chart 1.2.1; changelog row; ICS PDF export note corrected to 2.2.0

    @zach115th zach115th committed Sep 27, 2026
  • AI Task Suggester page; case-chat follow-ups, output-limit handling, gateway refusals New page AI-Task-Suggester (41 pages): the review panel, dependencies as task links, how an assignee is proposed (the model tags skills, the server ranks people - no analyst is sent to the backend), what the model's answer is trusted with, caching and staleness, permissions, API with request and response shapes. Linked from Home, AI-Features, API-Reference, Analyst-Skills-and-Teams and Troubleshooting. AI-Features: follow-up question chips and the truncated / Continue handling in the chat section; a Task suggester section; the 6 000-token budget in the reasoning-model notes; task suggester in the timeout table; "A model declines the request" now covers organisational AI gateways that inject their own system prompt (the chat renders prose, so judge a backend on a strict-contract surface). Troubleshooting: a chat answer stops mid-sentence; no follow-up chips; every task suggestion unassigned; task suggestions fail with "did not return JSON". Development-Guide: three gotchas (structured tail on a prose answer; a non-contract reply is an error, not an empty result; the model emits structure, the server picks the person). Analyst-Skills-and-Teams: skills also drive task-assignee proposals. API-Reference: three task-suggestion rows, chat result fields, and a fix - the task-link POST body key is target_task_id (the page said to_task_id). Everything new is annotated as the version after IRIS-NG-v2.2.0, not yet released; the release pass retires the annotations on AI-Task-Suggester, AI-Features, API-Reference, Analyst-Skills-and-Teams, Troubleshooting and Development-Guide.

    @zach115th zach115th committed Sep 18, 2026
  • Release pass IRIS-NG-v2.2.0: every 'not yet released' retired on nine pages, Changelog row, Kubernetes chart 1.2.0 + docker pull examples

    @zach115th zach115th committed Sep 18, 2026
  • IOC Deduplication page (new, 40 pages) + dedup/mentions/default-teams across Home, AI Features, API Reference, Troubleshooting, Getting Started, Version 2 Preview, Development Guide (not yet released) - New IOC-Deduplication: what counts as a duplicate (normalisation table), the modal's three sections, keep vs merge and the link-transfer table, scope/limits, API. - Home: table row + Since-the-1.x-line pointers; AI-Features: link to the feature page; API-Reference: dedup endpoints + legacy war-room-teams row. - Troubleshooting: new Indicators and comments section (CSV import skipped duplicates; a mention notified nobody; case delete FK on ioc_comments — known gap). - Getting-Started: the release after 2.1.1 carries a migration + new dependency (back up, keep --build). - Version-2-Preview: default teams, mention completion, IOC dedup paragraph. - Development-Guide: two gotchas — removing a linked object is a merge in disguise (one pure normaliser); seed rows inside the caller's transaction.

    @zach115th zach115th committed Sep 18, 2026
  • ICS Forms: new page (seed + AI pass, not yet released); War Rooms pointer, AI Features section, API Reference row, Home index row, two Troubleshooting entries, worker-restart note on the async queue

    @zach115th zach115th committed Sep 16, 2026
  • IRIS-NG-v2.1.0 release pass: Changelog row, annotations retired, Kubernetes chart 1.1.0, access-denied troubleshooting entry

    @zach115th zach115th committed Sep 15, 2026
  • v2.0.0 documentation pass: six new feature pages (Mail Rules, Alert Clusters, Investigation Flows, Customer Asset Registry, War Rooms, Notifications); update Home, API Reference, AI Features, Security, Troubleshooting, Dashboard Analytics, IOC Correlation, Case Notifications, Version-2-Preview

    @zach115th zach115th committed Sep 4, 2026
  • IRIS-NG-v1.4.1 release pass: drop the six pre-release banners, link + extend the changelog row (issue #93 fix, gunicorn 26.1.0, npm deps), bump Kubernetes to chart 0.8.1

    @zach115th zach115th committed Aug 31, 2026
  • Add Single Sign-On and Multi-Factor Authentication pages; document v1.4.1 Two new pages, split so the login mechanism and the second factor are not conflated the way the upstream documentation conflates them: Single-Sign-On OIDC, oidc_proxy, LDAP/AD, why none of it is configurable in the GUI Multi-Factor-Authentication TOTP, enrolment, exempt accounts, recovery Written from the source rather than the upstream docs, which surfaced several things that page gets wrong or omits: AUTHENTICATION_LOCAL_FALLBACK is documented without its IRIS_ prefix and does not work under the documented name; auto-provisioned OIDC users are created with no group, so they log in successfully and see nothing, because IRIS_NEW_USERS_DEFAULT_GROUP is applied only on the LDAP path; oidc_proxy calls exit(0) when discovery fails, so the container stops rather than starting; LDAP certificate settings are bare filenames resolved under certificates/ldap/, not paths; and the LDAP provisioning attributes are absent from that page entirely. MFA is TOTP (SHA-1 / 6 digits / 30s), so Microsoft Authenticator and Google Authenticator both work. It is not LDAP - LDAP decides where the password is checked, MFA adds a factor on top, and the two compose. Also documents IRIS-NG-v1.4.1: exempt accounts, the Set up MFA label, and the account actions moved back above the skills catalogue. Security gains a Known trade-offs entry stating the administrator exemption plainly - whoever holds that password bypasses MFA entirely on the most privileged account - with the mitigation of keeping a second administrator, which is subject to enforcement, for day-to-day work. Troubleshooting gains an Authentication section covering the symptoms this actually produced: no QR code on the profile page (there is a button, and before v1.4.1 it sits below ~34 skill checkboxes), a greyed-out MFA button, lockout with no recovery codes, IRIS_MFA_ENABLED appearing to do nothing, and SSO users never being asked for a second factor. v1.4.1 is NOT released. All six mentions of it carry a banner the wiki linter can see, so the release pass is prompted to remove every one. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

    @zach115th zach115th committed Aug 25, 2026
  • Fix three stale version claims the new wiki linter found Troubleshooting cited IRIS-NG-v1.2.3 as the fix version in two more places beyond the one corrected earlier - including a "upgrade, and the migration applies itself" instruction pointing at a version that never existed as an image. AI-Features carried a second "not in a released image yet" banner that a case-sensitive grep had missed, plus a now-false "shipping in the next release" line. Found by scripts/wiki_lint.py, which cross-checks every IRIS-NG-v* mentioned in the wiki against the tags that actually exist.

    @zach115th zach115th committed Aug 25, 2026
  • Document IRIS-NG-v1.3.0; drop the "not in any image" warnings v1.3.0 is tagged and published, so the provisional warnings on Event Triage, AI Features and Home are no longer true and have been replaced with "Available from IRIS-NG-v1.3.0". - Changelog: the unreleased row and the v1.2.3 row become one released v1.3.0 entry. v1.2.3 joins v1.0.3, v1.1.0 and v1.2.1 in the never-released note, with its contents folded forward. - Troubleshooting: the MISP rollback fix was credited to v1.2.3, which shipped nothing. v1.3.0 is the first release that carries it. - Kubernetes: chart 0.7.0, appVersion IRIS-NG-v1.3.0, and the docker pull examples follow. - Dual Timeline: new section on who added an event, and that it is the creator rather than the last editor. - API Reference: creator_name, user and event_added on the timeline list endpoint. - Development Guide: a z-index on the topbar caps every dropdown inside it, because a positioned element with a non-auto z-index creates a stacking context. Anything on a case page above 1001 covers open topbar dropdowns.

    @zach115th zach115th committed Aug 24, 2026
  • Document event triage verdicts; add three debugging rules New page: Event Triage. Timeline events now carry a verdict (To be determined / True positive / False positive) replacing the summary + graph checkboxes and the colour picker. Covers what a verdict gates, what it deliberately does not gate (the per-event drawer still analyses a false positive you open; exports are never filtered), bulk triage, the automatic upgrade backfill, and the API field. Marked as not-yet-released, since it is on main with no tag. Updated: Home - link the new page Dual Timeline - promoted events arrive To be determined, and why AI Features - what the AI is allowed to see, and that it is told when a timeline has been curated API Reference - event_verdict; in_summary/in_graph/colour are now derived Changelog - unreleased row: verdicts, the event colour that never rendered, the DIM Tasks failure icon on every row, deps Troubleshooting - an AI panel showing an authentication error while the backend is fine. The footer saying "cached" is the tell; it is a stored record of a past failure. Flagged that a cached error also reaches the STIX export and MISP push, so re-run before publishing a cluster. Development Guide - three rules that each cost a session: filter nullable booleans with .isnot(False) (== True and != False both silently drop NULL rows); never persist a failed AI call as a cached artifact; an !important stylesheet rule beats a normal inline style, and fixing the cascade may not fix the symptom. Scrubbed by hand as always - no proxy/case-memory references, no lab IPs, no credentials. Verified: 0 control bytes, 0 broken internal links.

    @zach115th zach115th committed Aug 24, 2026
  • Troubleshooting + Development Guide: the DIM Tasks icon, and celery pickles The task list showed a red failure icon on every task, always had, and the modal was the only place the real outcome appeared. Documented as a symptom because that is how it presents - "why is this marked failed when the modal says Success?" - along with the distinction that survives the fix: the list icon is task-level, so a green check beside a module that reported failure is coherent, not a contradiction. Development Guide gains the fact underneath it. result_serializer=json governs transport and does not apply to celery's database result backend, which stores results as pickles regardless. So a task result must never be unpickled in the web process, and reasoning about that column from the serializer setting is how the defect above shipped. Also notes that checking whether a pickle sink survives needs a parser rather than a grep - the fixed file contains three textual matches, all comments explaining why not to reintroduce it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

    @zach115th zach115th committed Aug 20, 2026
  • Troubleshooting + Changelog: the two MISP sync defects The discriminator table I published listed only two hook-failure causes. A third exists, and someone hitting it would have found that neither row matched: PendingRollbackError at core's post-hook commit, which means a module swallowed a database error without rolling back. The traceback names task_hook_wrapper, so it reads as a core failure and is not - the real error is quoted further down as "Original exception was:". Also adds the misp_attribute_link UniqueViolation, with the queries to tell whether a given instance hit it via duplicate IOC values or a recreated IOC, and a note that nothing needs cleaning up by hand. The v1.2.3 changelog row is explicitly marked "not yet released" - it sits unlinked among linked release rows, and without saying so it reads as something installable. No tag, no images exist for it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

    @zach115th zach115th committed Aug 20, 2026
  • IRIS-NG-v1.2.2: correlation TLP rework, Troubleshooting page The TLP documentation was wrong in a way that matters: the correlation page described a green/clear-only filter that no longer exists, and the decay section justified itself partly on that filter being in place. - IOC Correlation: new TLP handling section — access control scopes reads, TLP gates the two outbound paths, most-restrictive-wins, unset is not permission, and both paths report what they withheld - MISP Cluster Publishing + API Reference: same rule at the push and export endpoints; adds the STIX endpoint, which was undocumented - Corrects the claimed 404s: response_api_error() always emits 400 and its second argument is a body field, so those numbers never reach the status line. Development Guide already said this; the endpoint pages contradicted it - Development Guide: the reusable rule behind the rework - Changelog: v1.2.2 row; v1.2.1 recorded as never released - Kubernetes: chart 0.6.2 / appVersion IRIS-NG-v1.2.2 - Dependency Policy: why a vendored-and-copied package breaks the usual byte-identical control, and the npm ci / open-floor traps - New Troubleshooting page, symptom first Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

    @zach115th zach115th committed Aug 13, 2026