Release notes
Product-focused release history for hosted TvRMM customer-facing capabilities. These notes summarize major customer-visible milestones from product history and public support docs. Platform behavior still follows the support-state labels on the platform page.
2026-07-22
Hosted service update — production server runtime 0.5.863+g0684be10
- Published hosted production server runtime
0.5.863+g0684be10, build0684be1070f60f2f5ee5ef5a6136f387efad2bf6, on July 22, 2026. - The public stable appliance feed currently advertises server/appliance version
0.5.861+g0d1f8082, build0d1f808268fb70748852e2ddae726283913cccf5, released at2026-07-22T20:49:24Z. - The published Linux agent package remains
0.5.710+ge7c76832, builde7c768322538add8d348aac488b060544b254b7c. No Linux agent update was published with this hosted server runtime update. - Added a dedicated History view for Data Exports so terminal export, delivery, and restore evidence remains reviewable after active work completes. Customers can filter by status and reviewed state. Tenant owners can mark terminal failures reviewed individually or mark the visible terminal failures reviewed as a batch; new terminal failures alert again.
- Moved Google Drive export delivery configuration to Policy Center → Data Storage Connections. Direct tenant owners create, authorize or reconnect, choose the storage root, validate, disconnect, and delete Google Drive connections there. Tenant admins can still use ready connections for permitted redacted export workflows.
- Organized Google Drive export packages under the selected storage root in managed
Exports/YYYY/MMfolders for manual and scheduled exports. Restore browsing starts from the managed Exports folder on the selected ready connection. - Added current service scope, linked customer-managed history, and direct stream embedded customer-managed history choices for tenant exports. Direct self-contained history streams verified provider-backed history into the download and retains job and integrity evidence without retaining a second downloadable server copy.
- Strengthened restore safety before final apply. Final restore commit remains locked until the owner creates the mandatory encrypted safety export and either TvRMM verifies managed-storage delivery immediately before apply or the owner attests that the exact checksum-verified package was retained outside TvRMM with the password stored separately. Owner self-attestation is accepted but weaker than managed verification; downloading alone does not unlock final apply.
- Activated transactional optimized performance writes and portal rollup workers in hosted production while preserving legacy workbench history. There is no historical backfill.
- Deployed gated storage-history foundations for root-revision integrity, provider-bound reads, verified encrypted cache, integrity scrub, compaction bundles, storage provenance, UI state preservation, and latency improvements. Hosted production customer-storage historical retrieval, lifecycle provider replication, lifecycle compaction and organization, and hard-retention enforcement remain unavailable until separately enabled and documented.
See Tenant export and restore for task-oriented export, delivery, schedule, history, and restore guidance.
2026-07-14
Hosted service update — version 0.5.710+ge7c76832
- Released production server/appliance and Linux agent version
0.5.710+ge7c76832. - Added a dedicated tenant export workspace for creating portable exports, managing reusable destinations, configuring recurring schedules, and reviewing delivery status.
- Added Google Drive export delivery. Drive delivery requires customer-encrypted packages and supports priority-ordered saved destinations for scheduled fallback delivery. TvRMM tries lower priority numbers first and stops after a destination succeeds.
- Completed export packages remain available from TvRMM for 72 hours.
- Added an owner-only tenant restore workflow for portable export packages. TvRMM validates the package, encryption password, and any required redacted-value mappings before changes are applied.
- Important: Committing a restore atomically replaces the tenant’s current portable data. Owners should retain a pre-restore export and review validation results before confirming the operation.
- Retired agent-based export delivery in favor of managed destinations and delivery history.
- Improved export progress reporting, large-package processing, resumable Drive uploads, scheduled-delivery reconciliation, and database isolation during export and restore operations.
- Improved installer reliability when retrying trust-endpoint requests.
See Tenant export and restore for task-oriented export, delivery, schedule, and restore guidance.
2026-07-10
Hosted service update — server version 0.5.660+ga674c436
- Released production server/appliance version
0.5.660+ga674c436for hosted customers. The release completed at2026-07-11T03:08:32Z, which is July 10 Pacific time. - Server build identifier:
a674c436899a5532ac04b51faa2051a64586e3b0. The published Linux agent package remains0.5.653+g9cd5bd25with package build identifier9cd5bd25c5c1d2a6652f926b938c4448eca2dd1d. The version difference is expected because this release changed hosted server behavior, not the published agent runtime package. - Added tenant promotion-code inventory and post-signup redemption for authorized tenant owners and admins.
- Added deterministic promotion combination and fallback behavior with customer-visible billing/export provenance.
- Activated the Reddit subscriber campaign in production. The campaign adds 10 included agents, is fully stackable, has no scheduled expiration for redemption, and has no scheduled expiration for the redeemed benefit. Removal or revocation remains available.
- Added stronger auditable records for reboot action decisions and support-access decisions. Customer impact is narrower, clearer authorization and support-access evidence for supported workflows.
2026-07-02
Hosted service update — version 0.5.640+g21bfb1ae
- Released production version
0.5.640+g21bfb1aefor hosted customers. - This entry records the customer-visible production version and release date. Supported behavior remains described by the current platform and help guidance.
2026-06-24
Remote desktop access
- Remote view/control uses policy, session intent, event, transfer, capability, and relay tracking.
- Managed helper support and helper configuration make endpoint capability visible before a control stream is allowed.
- Browser-based remote control uses the authenticated TvRMM relay for supported direct agents.
- Remote access remains gated by policy, endpoint eligibility, helper capability, relay availability, clipboard settings, and file-transfer settings.
Collected logs usability
- Improved collected-log filter affordances and tightened the filter grid.
- Continued reducing collected-log noise so routine audit/heartbeat activity is less likely to bury useful operational evidence.
- Kept collected logs tenant-scoped with source-health, policy-summary, and usage context.
2026-06-23
Hosted billing reaches GA shape
- Completed the hosted billing GA work across account credit, daily snapshots, invoice closeout, split invoice lines, Stripe checkout/portal/webhook handling, and billing resume paths.
- Added self-service agent limits to protect billing from surprise growth.
- Added stale-agent billing exclusion, refund approval handling, manual refund records, and refund evidence preservation.
- Added billing wind-down and cancellation copy so offboarding remains an operational workflow instead of a lockout.
- Added starter policy examples for tenants and organizations across audit, logs, patching, scripts, app-provider inventory, monitoring, deployment, agent updates, and remote access examples.
2026-06-22
Billing ledger and license enforcement
- Added the billing ledger, hosted billing controls, billing-period closeout, split invoice support, and license-state tracking.
- Added active-agent license enforcement so product behavior can align with hosted billing state without blocking cleanup, export, or security work.
- Added Stripe billing-ledger design documentation and webhook contract detail.
Log collection access
- Added scoped access controls for log access.
- Unified collected-log activity history and deduplicated collected-log sources.
- Added platform log-collection policy sources and normalized selected syslog collection paths.
2026-06-17 to 2026-06-18
Policy Center becomes the recurring control plane
- Added the Policy Center catalog, assignment model, resolver, database-backed assignments, and read-only shell.
- Added policy assignment editing and effective-policy display on endpoints.
- Migrated audit cadence, log collection, patch policies, deployment policy surfaces, provider policies, and script policies into the Policy Center direction.
- Added monitoring automation signal support and documentation for the reusable signal platform tenet.
- Added agent repair and identity-merge design/workflow support.
2026-06-15 to 2026-06-16
Installer delivery, cleanup, and identity recovery
- Hosted installer downloads on portal domains and served installer manifests through the portal host.
- Routed appliance installer downloads through the portal and preferred the configured installer download base.
- Combined Windows bootstrap target selection and let the Windows installer select agent architecture.
- Added built-in agent cleanup, instance-aware cleanup targeting, and identity scrub behavior.
- Recovered stale agent identity after installer reruns and improved explicit local agent instance identity.
- Rebuilt production agent packages with production SPKI pins during promotion so packaged agents match the deployed trust boundary.
2026-06-13 to 2026-06-14
Endpoint workbench and patch intelligence
- Improved endpoint workbench usability and policy targeting.
- Improved endpoint performance live charts and modal loading behavior.
- Expanded structured patch-intelligence sources, update matching, and update links.
- Continued making patch evidence and update metadata more durable and explainable.
2026-06-10 to 2026-06-12
Tenant signup, environment clarity, scripts, and deployment pipeline
- Completed branding and environment-switching work so hosted environments are easier to distinguish.
- Added bulk endpoint archive/delete actions.
- Expanded signup policy controls, signup entitlement handling, and dashboard filtering for hosted onboarding.
- Added Azure preview/prod deployment and promotion workflows with smoke checks, version metadata, and promotion guardrails.
- Added script value picker, conditional script steps, script branch editing improvements, and line-ending normalization for script runner reliability.
- Improved dashboard and endpoint workbench UI.
2026-06-08
Platform support expansion
- Added remaining supported platform groups and appliance endpoint logos.
- Added FreeBSD and firewall installer options.
- Added dedicated NAS bootstrap options and fixed TrueNAS installer delegation.
- Improved OS identity, distribution-specific bootstrap options, and specialty Linux detection.
- Fixed FreeBSD service config loading and OS identity.
- Added signup entitlement codes for higher tenant limits.
2026-06-06 to 2026-06-07
Feature wave expansion
- Added server-backed endpoint log tables, collected-log explorer shell, source-health parsing, and log-collection policy status UI.
- Added endpoint source-health table controls and disk risk monitoring.
- Added app-provider inventory/action support and provider policy preview evidence.
- Added deployment automation support, table controls, transfer cleanup work, feature-request surfaces, and FR-019 lab parity evidence.
- Enabled the Windows performance collector by default.
- Expired stale agent update commands and tightened agent package build gating for deployment efficiency.
2026-06-01 to 2026-06-03
Multi-tenant hosted controls
- Added hosted tenant signup with email verification.
- Added tenant self-service export and tenant self-service deletion workflows.
- Hardened tenant isolation guards and tenant deletion lifecycle behavior.
- Added tenant asset and branding support.
- Added tenant user password management and tenant administration navigation polish.
- Added macOS endpoint audit and patch parity work, signed macOS package preservation, and macOS tray maintenance during agent updates.
2026-05-18 to 2026-05-21
Single-tenant and server update support
- Added server release update controls and a single-tenant server update runner.
- Added Azure single-tenant VM deployment and self-contained Azure bootstrap work.
- Added editable agent endpoint relocation and dual endpoint reconnect fallback.
- Added script variables and a Tailscale library script example for reusable automation.
2026-05-15 to 2026-05-17
Patch policy, patch evidence, and scripts
- Added policy-driven agent auto updates and reusable endpoint target filters.
- Split agent update policies from OS policies and improved policy filter-builder previews.
- Made patch approvals global, added auto-approval rules, bulk approval controls, deploy guardrails, durable verification evidence, and patch evidence activity.
- Added basic script automation, global scripts with endpoint-scoped runs, script workspace interactions, and terminal-style log transcripts.
2026-05-03 to 2026-05-05
Agent update recovery, reboot orchestration, and tray companions
- Hardened agent update recovery on Linux, Windows, and Unraid.
- Added robust endpoint reboot orchestration with prompt, schedule, post-reboot scan, and double-reboot support where supported.
- Added Windows tray companion branding and diagnostics.
- Added Linux tray companion support and visibility checks.
2026-04-20 to 2026-04-29
Homelab hosts, guests, terminal relay, and endpoint UI maturity
- Added first-class Unraid and Proxmox VE support.
- Expanded Proxmox collectors for HA, firewall, ZFS, bridges, tasks, storage, guests, and repo posture.
- Added a self-contained Unraid installer and a dedicated Unraid bootstrap command.
- Promoted Unraid and Proxmox guests to first-class endpoint rows, with guest-aware online status and linked direct-agent behavior.
- Added host-relay terminal and patch-scan paths for synthesized guest endpoints where host authority owns the workflow.
- Added per-user timezone picker and expanded selectable columns across agent tables.
- Added cross-process terminal broker support for split-role deployments.
- Added Windows tray icon policy, companion mode, x64 bootstrap support, and improved installer diagnostics.
2026-04-17 to 2026-04-19
Agent trust, deletion, rejoin, and package delivery
- Added soft-delete agent flow with queued uninstall, certificate revocation, CRL survival, and deleted-row hiding.
- Served agent packages from public blob storage and wired installers to current package URLs.
- Served the private CA bundle through a well-known endpoint and wired it through installers.
- Added signed trust bundle, rejoin protocol, proactive renewal, and CA-rotation telemetry.
- Improved agent re-enrollment behavior when credentials are missing, revoked, or rejected.
2026-04-14 to 2026-04-16
Initial hosted RMM build
- Started the Go-based TvRMM server and agent project.
- Added authentication, user/group management, role-based access control, and per-user UI preferences.
- Added Linux agent parity, combined bootstrap UI, and deployment scripts.
- Added Azure deployment support, Key Vault CA persistence, custom-domain support, and DNS behavior for hosted agent paths.
- Added certificate pinning improvements so agents can validate expected trust chains.
Website and docs surface updates
- 2026-06-24: Added public legal and policy pages, expanded promises/platform/security content, and kept public docs customer-facing around the production portal.
- 2026-06-15: Moved the public website toward the standalone Docusaurus structure and migrated help content from static HTML into Docusaurus docs.
- 2026-06-12: Added public help pages for getting started, endpoint support, agent installation, troubleshooting, tenant administration, release notes, and feature request guidance.