0.26.5
Live
05.09.2026
Interface
- Action buttons on the Operations page stay visible. The ledger's "Show the
trace" and the audit trail's "Download recording" buttons stay pinned to the right edge
when the table is scrolled horizontally. The operation ledger shows at most ten rows and
scrolls inside the table beyond that; the Approval column now follows the Actor column.
In the audit trail the download column is drawn only when a recorded session exists.
0.26.4
Live
05.09.2026
Governance
- Session recording setting on the cluster screen. At the bottom of the screen that
opens when a cluster is selected, after the GitOps binding section, the terminal session
recording posture is shown: on, off, and whether a missing licence means no new recording
starts. An administrator can turn it on or off from there; the entry in the cluster list
menu remains. Against an older core that does not report the posture the section is not
drawn at all.
0.26.3
Live
04.09.2026
Fixed
- The approval card no longer shows "ticket missing" when an already-applied terminal
plan is opened from the list. The ticket is single-use and is never written to the plan;
on an already-applied record opened from the list or the chat its absence is expected. The
card now expects a ticket only for a plan applied in this very flow; the warning appears only
on a real mismatch.
0.26.2
Live
04.09.2026
Governance (Enterprise)
- The compliance report's scope statement now gives session COUNTS. Terminal
sessions opened in the period, how many started recording, how many opened with
recording off — sessions whose recording state cannot be read from the trail are
counted as "unknown", not unrecorded. The same counts are in the NDJSON summary.
- The guardrail CEL context sees two recording fields.
op.cluster.execRecording carries the cluster's recording POSTURE
(independent of the license); op.cluster.recordingActive carries posture
and the license together — whether this session's recording actually starts. A
closed template ships in the repo (ops.recording-required, off by
default) — it cannot be turned on in place, copy it into your own namespace. Details
on the Policies page.
Fixed
- The policy package signing tool didn't recognize an encrypted private key,
fixed. Given an encrypted PEM (an
ENCRYPTED PRIVATE KEY header, or the
older Proc-Type: 4,ENCRYPTED), the tool failed without ever asking for a
passphrase; it now reads one from YEKE_POLICY_KEY_PASSPHRASE or a secret
prompt.
0.26.1
Live
04.09.2026
Fixed
- Core failed to start on PostgreSQL installations without the archive table; fixed.
The 0.26.0 schema migration assumed
archived_operations exists on every
PostgreSQL installation; on an older installation without it the migration rolled back
and core did not start. The migration now skips that step when the table is absent.
SQLite installations were not affected.
- The compliance report now records an unreadable archive in its scope statement instead of failing.
On the same class of installation the report endpoint returned 500; it now builds the
report from live records and shows an "archive unreadable" line with the error summary.
0.26.0
Live
04.09.2026
Brings all five items of phase E3 (governance): dual approval (four-eyes), maintenance
windows (change-freeze), centralized policy management, terminal session recording, and
compliance reports. Setup steps and operator behavior:
Governance. All five sit behind Enterprise flags —
respectively dual-approval, change-freeze,
policy-central, session-recording, and
compliance-reports.
Dual approval — four-eyes (Enterprise)
- A guardrail policy field can require a second approval. When
requireSecondApproval (with an optional
requiredApproverGroup) matches, the plan is classified with a
secondApproval field; default is OFF, so a single-admin install is never
locked out.
- The second approver GRANTS consent, the OWNER still applies the plan. The
actor-≠-owner gate is unchanged; there is no second applier.
- Consent is tied to the plan's CURRENT hash. If the plan is refreshed and the
hash changes, consent is dropped and must be given again.
- If no eligible approver exists, this is not left to apply time. The plan is
still created and its card says so AT PLAN TIME; the existing notification hook is
queued to reach a second person at the same moment.
- A configured rule stays in force when the license is removed — the only thing
that's cut off is defining a new rule.
Maintenance windows — change-freeze (Enterprise)
- The calendar is defined as
freezes: (a separate file under file
mode, the package's freezes field under central mode); every window's
timezone is REQUIRED.
- An
apply inside the window waits. It gets 409
APPROVAL_HOOK_DENIED plus the window's end time; the plan record stays
unmutated.
- There is no break-glass path. v1 only "waits".
- A configured window stays in force when the license is removed — the only
thing that's cut off is defining a new window.
Centralized policy package (Enterprise)
- The policy set can also be loaded from a signed package instead of a file
(
YEKE_POLICY_MODE=central). The package ({version, policies,
freezes?, signature}) is Ed25519-signed — the key is the organization's own,
separate from the license and air-gap release keys.
- File mode and central mode can't be the source at the same time (giving
YEKE_POLICY_DIR together with central mode stops core with an explicit
error).
- Loading takes effect immediately but never affects a plan already in flight;
every change is logged.
- A package with a broken signature does NOT drop the previous version — it is
rejected, and the previous version keeps being read.
Terminal session recording (Enterprise)
- Full pty recording is opt-in per cluster, OFF by default. Metadata events
(who, which pod) are always written, Community included; when full recording is
turned on, the terminal says so on its opening line — there is no covert recording.
- The download format is asciinema v2
.cast. There is no inline
playback in the browser; customers bring their own player.
- It has its own retention dial
(
YEKE_EXEC_RECORDING_RETENTION_DAYS, default 30 days) and does not enter
E2's archive plane.
- When the license is removed, no new recording starts, but existing recordings
remain readable.
Compliance reports (Enterprise)
- A cluster × period change report is produced from a single endpoint. The
report is a derivative: it writes no new table or event, its sources are the audit
trail and admin approvals.
- Format is a single HTML file (default) or NDJSON. The period cap is 366
days.
- The report carries a chain summary of the range it covers (start/end
canonical hash plus event count) and can be verified with
verify-tool.
- Without a license the report endpoint returns 403; raw trail reads and NDJSON
export (SIEM) are unaffected.