IRIS-NG-v2.8.0 release pass: Changelog row (verified executive summary: writer claims, deterministic checks, verifier role, one automatic revise, review questions with proposed options, the answers pass, Draft / Verified pill, Audit tab, the Verify executive summaries switch + the Case Summary verifier override row, the new API keys and routes; ONE migration c4d9a2e7f1b3; chart 1.8.0), Kubernetes chart 1.8.0 / appVersion / pull examples, AI Features "Executive case summary" rewritten for the pipeline (seven steps, the flag-code table by severity, review questions + the answers pass, status + audit, roles / settings / budgets, the evidence rules updated: counts rendered server-side, names allowed only when sourced, an upgrading paragraph) + the Admin UI override row and checkbox + synthesizer-routing wording + the manual-override Editable cell + two budget-table rows, API Reference "Added in IRIS-NG-v2.8.0" (the GET /summary keys, the verification payload, answer + apply-answers with their 404 / 409 / 400 reasons, the case-details keys, the settings field) + three table rows + the case-details paragraph, Troubleshooting four entries (Draft · not reviewed after the upgrade; generation takes minutes; checks only / verifier unavailable / verifier failed / carried; Apply answers disabled), Getting Started migrations banner + the AI paragraph, Home AI-layer + Settings wording, Architecture hook-table row (the answers pass fires the hook; the two case-payload keys), Development Guide two gotchas (the activity-log timestamp is a wall-clock value in disguise; changing a CHECK constraint is a data migration first)
IRIS-NG-v2.7.0 release pass: Changelog row (any number of AI backends: cards + "+ Add backend", per-card save / delete, the active radio, the ai_backend table, the per-backend admin routes; ONE migration importing the two slots; the slot keys retired; chart 1.7.0), Kubernetes chart 1.7.0 / appVersion / pull examples, AI Features "Admin UI" rewritten for cards (rules: unique labels, the active backend undeletable, first backend becomes active, pins fall back; overrides by label; write-only keys per card; the upgrade paragraph) + "backend" wording in the OpenAI / Bedrock / synthesizer / declines sections, Getting Started AI paragraph + migrations banner (2.7.0 added), Troubleshooting new entry ("Save the backend first" / Delete refuses the active one / the two slots became cards) + backend wording, API Reference "Added in IRIS-NG-v2.7.0" (the five routes, the pointers, the retired keys) + the 2.5.0 row marked replaced, Development Guide gotcha (retiring a declared field from an auto-schema exposes the column), AI Task Suggester + Home wording
IRIS-NG-v2.5.4 + v2.6.0 release pass: Changelog rows (2.5.4 dependency-only: source-map-js 1.2.2, postcss-selector-parser 7.1.6 via npm overrides; 2.6.0: the OpenAI provider with max_completion_tokens and the self-healing chat-completions request shape; no migrations; charts 1.5.4 / 1.6.0), Kubernetes chart 1.6.0 / appVersion / pull examples, AI Features new "OpenAI (api.openai.com)" section + overview, Provider select, supported-backends table and a max_completion_tokens budget note, Troubleshooting entry for "Unsupported parameter: 'max_tokens'" (before 2.6.0 upgrade; since, either provider), API Reference "Added in IRIS-NG-v2.6.0" (openai_api accepted), Dependency Policy UI-dependencies bullet (build-stage PostCSS packages; the overrides pin), Development Guide adapter gotcha (second subclass; memory scope per process vs per instance), Getting Started + Home provider mentions
IRIS-NG-v2.5.3 release pass: Changelog row (the output-limit retry on the six remaining JSON surfaces with raised budgets; Dependabot #139 npm group incl. joi GHSA-wr44-6hxh-3jwq, #140 python group incl. PyJWT 2.15.1, #141 cryptography floor; no migration; chart 1.5.3), Kubernetes chart 1.5.3 / appVersion / pull examples, AI Features budget table (+4 rows incl. the executive summary's specialists / synthesis; prose surfaces note) + timeout rows + the retry paragraph's version line, Troubleshooting entry extended to the 2.5.3 surfaces, Dependency Policy paragraph on PyJWT (OIDC signature mode, per-version probe) and the e2e-only packages
IRIS-NG-v2.5.1 + v2.5.2 release pass: Changelog rows (task-suggester budget + compact retry; the shared output-limit retry across the operational summary, SitRep draft, cluster narrative, alert-cluster triage and ICS pass with raised budgets; no migrations; charts 1.5.1 / 1.5.2), Kubernetes chart 1.5.2 / appVersion / pull examples, AI Features max_tokens section (per-surface budget table, the retry routine, measured Kimi K3 figures) + timeout table rows, Troubleshooting ("returned no JSON object" / "hit the output limit twice" entry; the Bedrock entry points at the retry), Development Guide gotcha (JSON surfaces call ask_json)
IRIS-NG-v2.5.0 release pass: Changelog row (AWS Bedrock provider per AI slot with the inference-profile catalog; write-only AI API keys; war-room Notes rail right-click menus / /note / ?note= #137; one migration; chart 1.5.0), Kubernetes chart 1.5.0 / appVersion / pull examples, Getting Started migrations note + AI backend paragraph, Home settings pointer, AI Features new "AWS Bedrock" section (region / model / key, Load models, IAM permission, reasoning blocks, no guardrail, temperature retry, cached tokens) + overview + supported-backends table + reasoning-format row + write-only keys, API Reference "Added in IRIS-NG-v2.5.0" (settings provider keys, *_api_key_set, catalogs, the catalog endpoint, war-room note content / move), Troubleshooting four AI entries (502 during a restart, ListInferenceProfiles 403, temperature / empty reasoning reply, empty API Key field), War Rooms stream /note + Notes rail menus, Development Guide provider-adapter gotcha
IRIS-NG-v2.4.6 release pass: Changelog row (#138 Executive Case Summary changes fire on_postload_case_update; executive_summary in case payloads; worker-context hook attribution; no migration; chart 1.4.6), Kubernetes chart 1.4.6 / appVersion / pull examples, Architecture hook row, Troubleshooting 'Modules and webhooks' subsection, API Reference ai/summary rows + case-details payload note, AI Features executive-summary hooks paragraph
IRIS-NG-v2.4.2 release pass: Changelog row (Assets Save dropped a changed Compromise Status; no migration; app image rebuild; chart 1.4.2), Kubernetes chart 1.4.2 / appVersion / pull examples, Troubleshooting new Assets section with the Full editor workaround for older versions
IRIS-NG-v2.4.1 release pass: the four 'not yet released' annotations flipped to since IRIS-NG-v2.4.1 (API-Reference, Architecture, Troubleshooting), Changelog row linked to the release + chart 1.4.1, Kubernetes chart 1.4.1 / appVersion / pull examples, Getting Started migrations note adds 2.4.1 (one migration)
Summary edits fire on_postload_case_update (#128, on main, not yet released): Changelog unreleased row (also guest mentions/teams/assignees + the dependency bumps), Architecture hooks table, API-Reference summary route, Troubleshooting "Modules and webhooks" entry, Dependency-Policy SQLAlchemy 2.1 hold
IRIS-NG-v2.4.0 release pass: every 'not yet released' annotation flipped (guests, guest portal, operational summary, update script, STIX fix), chart 1.4.0 / appVersion on Kubernetes, upgrade note lists 2.4.0's four migrations
scripts/update.sh: one-command clone update on Getting Started (with the first-run bootstrap and the by-hand backup line), Home row, Troubleshooting entries, Guest Portal --enable-portal, changelog
Guest Portal page (guests, sign-in, tunnel modes, agent, room addresses, troubleshooting); War Rooms Summary tab and guests; operational summary on AI Features; not-yet-released API families; STIX export fix and the narrative-export defect noted; troubleshooting, changelog, security, upgrade, Kubernetes and dev-guide notes
IRIS-NG-v2.3.0 release pass: note tags (#129) and note-to-IOC links (#130) marked released; #130 sections on AI Features, API Reference, Troubleshooting, Development Guide; chart 1.3.0; migration note on Getting Started; changelog row
Note tags (#129, on main, not yet released): AI Features tag-suggester section (notes, case vocabulary, 6000-token budget + compact retry), API Reference rows (tag-suggestion object_type note; legacy note routes note_tags), Home, Case Export/Import, Troubleshooting entry, Development Guide gotcha
IRIS-NG-v2.2.1 release pass: task suggester, chat follow-ups, SitRep deltas and leadership event marked as released; chart 1.2.1; changelog row; ICS PDF export note corrected to 2.2.0
AI Task Suggester page; case-chat follow-ups, output-limit handling, gateway refusals
New page AI-Task-Suggester (41 pages): the review panel, dependencies as task
links, how an assignee is proposed (the model tags skills, the server ranks
people - no analyst is sent to the backend), what the model's answer is
trusted with, caching and staleness, permissions, API with request and
response shapes. Linked from Home, AI-Features, API-Reference,
Analyst-Skills-and-Teams and Troubleshooting.
AI-Features: follow-up question chips and the truncated / Continue handling
in the chat section; a Task suggester section; the 6 000-token budget in the
reasoning-model notes; task suggester in the timeout table; "A model declines
the request" now covers organisational AI gateways that inject their own
system prompt (the chat renders prose, so judge a backend on a strict-contract
surface).
Troubleshooting: a chat answer stops mid-sentence; no follow-up chips; every
task suggestion unassigned; task suggestions fail with "did not return JSON".
Development-Guide: three gotchas (structured tail on a prose answer; a
non-contract reply is an error, not an empty result; the model emits
structure, the server picks the person).
Analyst-Skills-and-Teams: skills also drive task-assignee proposals.
API-Reference: three task-suggestion rows, chat result fields, and a fix - the
task-link POST body key is target_task_id (the page said to_task_id).
Everything new is annotated as the version after IRIS-NG-v2.2.0, not yet
released; the release pass retires the annotations on AI-Task-Suggester,
AI-Features, API-Reference, Analyst-Skills-and-Teams, Troubleshooting and
Development-Guide.
Release pass IRIS-NG-v2.2.0: every 'not yet released' retired on nine pages, Changelog row, Kubernetes chart 1.2.0 + docker pull examples
IOC Deduplication page (new, 40 pages) + dedup/mentions/default-teams across Home, AI Features, API Reference, Troubleshooting, Getting Started, Version 2 Preview, Development Guide (not yet released)
- New IOC-Deduplication: what counts as a duplicate (normalisation table), the modal's three sections, keep vs merge and the link-transfer table, scope/limits, API.
- Home: table row + Since-the-1.x-line pointers; AI-Features: link to the feature page; API-Reference: dedup endpoints + legacy war-room-teams row.
- Troubleshooting: new Indicators and comments section (CSV import skipped duplicates; a mention notified nobody; case delete FK on ioc_comments — known gap).
- Getting-Started: the release after 2.1.1 carries a migration + new dependency (back up, keep --build).
- Version-2-Preview: default teams, mention completion, IOC dedup paragraph.
- Development-Guide: two gotchas — removing a linked object is a merge in disguise (one pure normaliser); seed rows inside the caller's transaction.
ICS Forms: new page (seed + AI pass, not yet released); War Rooms pointer, AI Features section, API Reference row, Home index row, two Troubleshooting entries, worker-restart note on the async queue
IRIS-NG-v2.1.0 release pass: Changelog row, annotations retired, Kubernetes chart 1.1.0, access-denied troubleshooting entry
v2.0.0 documentation pass: six new feature pages (Mail Rules, Alert Clusters, Investigation Flows, Customer Asset Registry, War Rooms, Notifications); update Home, API Reference, AI Features, Security, Troubleshooting, Dashboard Analytics, IOC Correlation, Case Notifications, Version-2-Preview
IRIS-NG-v1.4.1 release pass: drop the six pre-release banners, link + extend the changelog row (issue #93 fix, gunicorn 26.1.0, npm deps), bump Kubernetes to chart 0.8.1
Add Single Sign-On and Multi-Factor Authentication pages; document v1.4.1
Two new pages, split so the login mechanism and the second factor are not
conflated the way the upstream documentation conflates them:
Single-Sign-On OIDC, oidc_proxy, LDAP/AD, why none of it is
configurable in the GUI
Multi-Factor-Authentication TOTP, enrolment, exempt accounts, recovery
Written from the source rather than the upstream docs, which surfaced several
things that page gets wrong or omits: AUTHENTICATION_LOCAL_FALLBACK is
documented without its IRIS_ prefix and does not work under the documented
name; auto-provisioned OIDC users are created with no group, so they log in
successfully and see nothing, because IRIS_NEW_USERS_DEFAULT_GROUP is applied
only on the LDAP path; oidc_proxy calls exit(0) when discovery fails, so the
container stops rather than starting; LDAP certificate settings are bare
filenames resolved under certificates/ldap/, not paths; and the LDAP
provisioning attributes are absent from that page entirely.
MFA is TOTP (SHA-1 / 6 digits / 30s), so Microsoft Authenticator and Google
Authenticator both work. It is not LDAP - LDAP decides where the password is
checked, MFA adds a factor on top, and the two compose.
Also documents IRIS-NG-v1.4.1: exempt accounts, the Set up MFA label, and the
account actions moved back above the skills catalogue.
Security gains a Known trade-offs entry stating the administrator exemption
plainly - whoever holds that password bypasses MFA entirely on the most
privileged account - with the mitigation of keeping a second administrator,
which is subject to enforcement, for day-to-day work.
Troubleshooting gains an Authentication section covering the symptoms this
actually produced: no QR code on the profile page (there is a button, and
before v1.4.1 it sits below ~34 skill checkboxes), a greyed-out MFA button,
lockout with no recovery codes, IRIS_MFA_ENABLED appearing to do nothing, and
SSO users never being asked for a second factor.
v1.4.1 is NOT released. All six mentions of it carry a banner the wiki linter
can see, so the release pass is prompted to remove every one.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Fix three stale version claims the new wiki linter found
Troubleshooting cited IRIS-NG-v1.2.3 as the fix version in two more places
beyond the one corrected earlier - including a "upgrade, and the migration
applies itself" instruction pointing at a version that never existed as an
image. AI-Features carried a second "not in a released image yet" banner
that a case-sensitive grep had missed, plus a now-false "shipping in the
next release" line.
Found by scripts/wiki_lint.py, which cross-checks every IRIS-NG-v* mentioned
in the wiki against the tags that actually exist.
Document IRIS-NG-v1.3.0; drop the "not in any image" warnings
v1.3.0 is tagged and published, so the provisional warnings on Event
Triage, AI Features and Home are no longer true and have been replaced
with "Available from IRIS-NG-v1.3.0".
- Changelog: the unreleased row and the v1.2.3 row become one released
v1.3.0 entry. v1.2.3 joins v1.0.3, v1.1.0 and v1.2.1 in the
never-released note, with its contents folded forward.
- Troubleshooting: the MISP rollback fix was credited to v1.2.3, which
shipped nothing. v1.3.0 is the first release that carries it.
- Kubernetes: chart 0.7.0, appVersion IRIS-NG-v1.3.0, and the docker
pull examples follow.
- Dual Timeline: new section on who added an event, and that it is the
creator rather than the last editor.
- API Reference: creator_name, user and event_added on the timeline
list endpoint.
- Development Guide: a z-index on the topbar caps every dropdown inside
it, because a positioned element with a non-auto z-index creates a
stacking context. Anything on a case page above 1001 covers open
topbar dropdowns.
Document event triage verdicts; add three debugging rules
New page: Event Triage. Timeline events now carry a verdict (To be determined /
True positive / False positive) replacing the summary + graph checkboxes and the
colour picker. Covers what a verdict gates, what it deliberately does not gate
(the per-event drawer still analyses a false positive you open; exports are
never filtered), bulk triage, the automatic upgrade backfill, and the API field.
Marked as not-yet-released, since it is on main with no tag.
Updated:
Home - link the new page
Dual Timeline - promoted events arrive To be determined, and why
AI Features - what the AI is allowed to see, and that it is told when a
timeline has been curated
API Reference - event_verdict; in_summary/in_graph/colour are now derived
Changelog - unreleased row: verdicts, the event colour that never
rendered, the DIM Tasks failure icon on every row, deps
Troubleshooting - an AI panel showing an authentication error while the
backend is fine. The footer saying "cached" is the tell;
it is a stored record of a past failure. Flagged that a
cached error also reaches the STIX export and MISP push,
so re-run before publishing a cluster.
Development Guide - three rules that each cost a session: filter nullable
booleans with .isnot(False) (== True and != False both
silently drop NULL rows); never persist a failed AI call
as a cached artifact; an !important stylesheet rule beats
a normal inline style, and fixing the cascade may not fix
the symptom.
Scrubbed by hand as always - no proxy/case-memory references, no lab IPs, no
credentials. Verified: 0 control bytes, 0 broken internal links.
Troubleshooting + Development Guide: the DIM Tasks icon, and celery pickles
The task list showed a red failure icon on every task, always had, and the
modal was the only place the real outcome appeared. Documented as a
symptom because that is how it presents - "why is this marked failed when
the modal says Success?" - along with the distinction that survives the
fix: the list icon is task-level, so a green check beside a module that
reported failure is coherent, not a contradiction.
Development Guide gains the fact underneath it. result_serializer=json
governs transport and does not apply to celery's database result backend,
which stores results as pickles regardless. So a task result must never be
unpickled in the web process, and reasoning about that column from the
serializer setting is how the defect above shipped.
Also notes that checking whether a pickle sink survives needs a parser
rather than a grep - the fixed file contains three textual matches, all
comments explaining why not to reintroduce it.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Troubleshooting + Changelog: the two MISP sync defects
The discriminator table I published listed only two hook-failure causes.
A third exists, and someone hitting it would have found that neither row
matched: PendingRollbackError at core's post-hook commit, which means a
module swallowed a database error without rolling back. The traceback
names task_hook_wrapper, so it reads as a core failure and is not - the
real error is quoted further down as "Original exception was:".
Also adds the misp_attribute_link UniqueViolation, with the queries to
tell whether a given instance hit it via duplicate IOC values or a
recreated IOC, and a note that nothing needs cleaning up by hand.
The v1.2.3 changelog row is explicitly marked "not yet released" - it sits
unlinked among linked release rows, and without saying so it reads as
something installable. No tag, no images exist for it.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
IRIS-NG-v1.2.2: correlation TLP rework, Troubleshooting page
The TLP documentation was wrong in a way that matters: the correlation
page described a green/clear-only filter that no longer exists, and the
decay section justified itself partly on that filter being in place.
- IOC Correlation: new TLP handling section — access control scopes
reads, TLP gates the two outbound paths, most-restrictive-wins,
unset is not permission, and both paths report what they withheld
- MISP Cluster Publishing + API Reference: same rule at the push and
export endpoints; adds the STIX endpoint, which was undocumented
- Corrects the claimed 404s: response_api_error() always emits 400 and
its second argument is a body field, so those numbers never reach
the status line. Development Guide already said this; the endpoint
pages contradicted it
- Development Guide: the reusable rule behind the rework
- Changelog: v1.2.2 row; v1.2.1 recorded as never released
- Kubernetes: chart 0.6.2 / appVersion IRIS-NG-v1.2.2
- Dependency Policy: why a vendored-and-copied package breaks the
usual byte-identical control, and the npm ci / open-floor traps
- New Troubleshooting page, symptom first
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>