Repository navigation
Conversation
- Integrate build management into desktop and mobile interfaces - Support uploads, URL imports and GitHub builds with configured credentials - Add per-device build selection, pinning and update protection - Check runtime compatibility and report installation progress - Track build usage and support review, archiving and removal - Add controlled bulk deployments with pause and cancellation
- Document the agent build catalog, upload methods, and GitHub integration. - Provide usage instructions for device build selection, pinning, and custom policies. - Cover controlled bulk deployments, compatibility checks, and progress monitoring. - Add examples of optional GitHub token configuration in `sample-config-advanced.json`. - Update `readme.md` with a link to the new guide for quick reference. - Extend JSON schema to describe GitHub import settings and clarify token requirements.
…lts. - **Removed** `agents/agents_sep2026/manifest.json` and associated September 2026 agent builds. - **Added** `agents/agent-defaults.json` defining configurable default agents with release information. - **Added** `docs/agent-releases.md` documenting agent release format and publishing workflow. - **Added** `.npmignore` entries to exclude agent binaries and temporary files from npm packages. Focused on streamlining agent configuration and documentation while cleaning up legacy builds.
- **Updated** `docs/agent-releases.md` to clarify tag naming, release workflows, and the treatment of beta releases. - **Improved** default download documentation in `docs/agent-builds.md` to cover private releases, offline setup, and beta file management. - **Extended** `meshcentral-config-schema.json` description for download settings to include release update checks. - **Added** explicit requirements for workflows to reside on default branches for manual runs. - **Adjusted** migration instructions to distinguish between legacy and beta version examples.
…ation for deployment status. ### Changes: - **Enhanced** translation functionality to process `.js` files in addition to existing formats (e.g., `.html`, `.handlebars`, `.txt`). - **Integrated** `agentbuildmanager.js` support into the translation workflow. - **Extended** `extractFromHtml` and minifier logic to include `.js` file handling. - **Updated** JSON translations (`translate.json`) with new entries and location adjustments: - Added agent deployment-related keys. - Adjusted XLoc mappings for various language keys to sync translations. - Introduced new phrases for testing, review workflows, and platform integrations. - **Modified** file handling to embed/unembed scripts during extraction and minification. Streamlined handling of script translations and improved deployment tracking for agent builds.
### Changes: - **Improved** dialog close function to support asynchronous operations: - Added `after` callback to `closeAgentManagerDialog` for queued actions post-modal close. - Updated `agentManagerClose` and `agentManagerDevice` to utilise the callback for smoother navigation post-dialog dismissal. - **Adjusted** height calculations for dialog components: - Refined `p44info` height handling to avoid viewport overshoot due to outdated offset logic. - Updated modal element margins and max heights for compatibility with varied viewport sizes. - **Optimised** flex layouts for scrollable areas: - Increased flex shrink factor on list elements (`p44list`, `agentManagerContent`) to maintain better balance with headers during resizing. - Added padding adjustments for improved spacing consistency. - **Updated** CSS rules for agent build and manager dialogs: - Ensured proper handling of taller windows and varied modal host designs. - Accounted for legacy and modern behaviour via conditional class-based constraints. This improves UI consistency, eliminates unnecessary page scroll disruptions, and supports dynamic modal behaviour across interfaces.
|
the docs folder doesnt need changing or anything being added. edit1: the is also WAY TOO MANY edit2: i keep seeing edit3: clicking add agent then trying to download the 64 windows version results in a 404 file not found? |
### Changes: - **Deleted** `docs/agent-builds.md` and `docs/agent-releases.md`: - Deprecated agent documentation removed to avoid duplication and maintain relevance. - **Removed** unused legacy `agentbinary.js` implementation. This cleanup eliminates redundant files and ensures all relevant guidance is aligned with current features and workflows.
|
Your first comment and edit1 have been done. I will look into edit2. And for edit3, this is expected, currently they are placeholders until the files are bundled and published as a release on github. |
|
@Rambomst thank you! |
|
Oh I thought you meant you were trying to add an agent from github, sure, if thats local then I will look into it. |
|
@Rambomst another idea, when u upload the exe/binary,
then we could run the steps for 2 and 3 accordingly after upload rather than on startup every time!? |
…ults ### Changes: - **Introduced** support for agent branding (custom file icons, logos, version info) and signing: - Server certificates or custom `agentsigningcert.pem` can now sign agents for Windows. - Added customisation to apply branding details during agent uploads or processing workflows. - **Ensured** severability of server startup from agent downloads: - Agent defaults now load from cached/bundled builds while remote downloads complete in the background. - **Extended** support for default file overrides in agent builds: - New APIs allow administrators to set or clear default builds per architecture (e.g., Windows, Linux). - Dynamic reload of agent tables supports live updates to overrides without server restarts. - **Refined** build upload workflow: - Incorporated rule to ensure signing and branding apply only to Windows PE files. - Prevented invalid configurations for incompatible platforms during file reviews. - Enabled hashed recording of agent updates for deployable verification. - **Enhanced** agent build UI: - Added checkboxes for code signing and branding in file upload review. - Updated manage sections to include 'Set as default' and 'Clear default' for streamlined workflows. - Improved branding settings and linked them dynamically to signing behaviour in the UI. - **Improved** catalog state handling: - Added support for tagging and recording the provenance of default server builds in agent catalogs. Provides stronger agent branding support and default management, while improving workflows for both administrators and end users.
|
@si458 My latest commit includes fixes/changes for all the things you mentioned. |
|
@Rambomst hmm something isnt right? |
|
If you sign it each time then the hashes will change but the There is also no duplicate check at the moment but I can add it if you want. |
|
@Rambomst ah ok got you! also just discovered the 'Manage Build' text to select which one u want as the default! also still seeing all these messages can we just have them in the server tab and not the in agent build tab? |
|
Yeah I can make them appear in only that one spot. And you will continue to see those messages until github agent releases have been created for the old versions and sept 2026. |
…etails ### Changes: - **Removed** redundant error handling for `catalog.downloads.errors` in `agentcatalog.handlebars`, as it is no longer required. - **Added** functionality to display branding and signing status in agent file details: - Indicate "Server branding applied, re-signed" or "Code-signed by the server" as applicable. - **Extended** metadata in `agentbuilds.js` to include `signed` and `customised` flags for build processing. - **Enhanced** agent build manager UI to show detailed branding and signing status: - Listed agent-specific tags such as "Remote desktop supported", "Server branding applied", and signature details. - Included an abridged update hash preview for better visibility. - **Updated** agent build action HTML generation to display detailed upload metadata, offering better clarity during file review. This improves the clarity of agent branding and signing information throughout the catalog and management workflows.
|
Both done in the latest commit. Let me know if you want more information exposed/changed. |
|
@Rambomst bug edit: also got a random error? |
…management. ### Changes: - **Improved** `recordencryptionrecode` for robust error handling: - Logs recoding errors and prevents data corruption during encryption processes. - Supports asynchronous recoding for various database objects (`user`, `node`, `mesh`, `agentbuilddefault`) with NeDB compaction improvements. - **Enhanced** agent build handling: - Introduced agent default configuration override support. - Refactored dynamic reload of agent tables for efficient updates. - Addressed server default agents' compatibility and refreshing errors during startup. - Standardised handling for server-signed and locally overridden agent builds. - **Modified** UI for agent build catalog: - Display detailed branding and signing metadata, including unavailable builds and defaults. - Added buttons for clearing default builds directly from the catalog. - **Refined** external signing workflows: - Improved error detection and fallback for failing signing jobs. - Enhanced agent signing with retry logic to avoid incomplete states. - **Addressed** performance bottlenecks: - Optimised database queries with encrypted record handling updates. - Improved promise-based execution for critical path logic like signing and encryption. This provides enhanced error resilience, secure workflows, and streamlined agent build management with better UI integration.
|
Defaults now live in the DB and point directly to the stored build, avoiding the executable replacement that caused the Windows error that you got. Removing a default build now requires confirmation and clears its defaults. The records also support DB encryption when configured. |
|
@Rambomst ok amazing so far so good, |
…ild defaults ### Changes: - **Added** `customized` flag support in agent builds to manage branded and default configurations. - **Refactored** `agentTranslations` handling with JSON serialisation for streamlined processing. - **Enhanced** domain-specific customisation logic for agent translations and descriptions. - **Updated** translation fallback mechanism for better alignment with default behaviours. - **Integrated** checks for `customized` flag across various platform-specific workflows: - Included flag validation during agent-related responses and downloads. - Restricted customisation processing to applicable platforms. - **Optimised** execution path for agent defaults, translations, and customisation files: - Moved redundancy checks and serialisation to a centralised logic block. - Enhanced error resilience during dependency lookups and deep copying. These updates streamline agent handling, improve consistency for branded builds, and enhance translation workflows.
|
The download handler was ignoring the builds customization flag. Both standard and customized translations are prepared at startup, then the correct set is selected for the build when downloading. |
### Changes: - **Added** a "Copy Build ID" button to the agent catalog UI to simplify copying build IDs: - Included the button in the `agentcatalog.handlebars` template. - Enabled user-select functionality for build ID with a new `.agent-build-id` CSS rule. - Updated translation keys in `translate.json` for "Build ID" and "Copy Build ID". - **Implemented** `agentManagerCopyBuildId` function in `agentbuildmanager.js` to handle clipboard copying: - Supported fallback mechanism if the `navigator.clipboard` API is unavailable. - **Enhanced** search functionality in agent rows: - Appended build ID (`../id`) to searchable data attributes in `agentcatalog.handlebars`. - **Updated** agent build catalog UI to display build ID metadata for better visibility. This improves usability by allowing quick copying of build IDs directly from the UI.
|
@si458 The UI was hiding the build ID used for the folder name. It’s now shown with a copy button under Source, verification, and Manage build. You can also paste a folder name into the catalog filter to find its build. |
|
hi guys, I have created a script to be used locally in windows to automate this for me while my usb-key always plugged in, the script runs if meshcentral get updated on the linux server, the script allows meshcentral to update normally then allow couple of minutes so MC can apply the customizations to the agents and sign them with that self-signed certificate on the MC server and get's them all placed in the meshcentral-data/signedagents. after that my local script take the rest, by: downloading all the exe files from the signedagents folder using ssh --> sign those files with our EV SSL cert locally and apply server address lock to them --> upload the signed files via ssh to the meshcentral-data/signedagents. now there is also another legacy location for the agents which my script also copy the signed files to on the server which is meshcentral-data/agents the question is, after your implimentation, how should we work around that to have the files get the applied customizations based on the config then sign them locally with the lock enabled and upload them, because if your new feature will alter the uploaded files there, then it will invalidate our signed process and properly mess with the lock we applied. also you have stated that when MC get updated, it will look at this location and download the agents to it from the repo if not existed or compare the agents hashes there against the repo ones and download the repo ones if they are different. means we will always get our signed agents replaced or messed with if the MC work on them on every server startup. it would be nice if you guys explain what people having the same scenario as me should do. because no matter what, we have to sign the files locally then upload them to the MC server as we have to physically use the usb-key to apply the cert and server address lock to those agents and instead of doing all of that manually, we rely on custom script to automate the process locally then upload it via ssh. |
|
@smartekIT we are still working on things and im doing alot of testing my side while @Rambomst does the coding @Rambomst what we need is a DOWNLOAD button in the management page, so it downloads that agent as is directly @smartekIT if @Rambomst does my step above it would help us, @Rambomst can you have a look (seperate PR to this but can extend it) if we could maybe have a websocket api on the control.ashx for the agent build management page? this is NOT priority just a NICE thing to have maybe! |
|
thanks @si458 and @Rambomst for the hard work you do, but my issue is exactly with what you said: "you wont need to touch the agents or signedagents folder anymore as they would be stored in agentbuilds instead and all done through the web ui" simply because i will have to do it manually thru the UI while it's better like what i'm doing now which relies on my automated script which does all the work automatically for me including i have created a AHK script to authenticate with the usb-key so i don't even need to type my cert password or do anything at all. so fully automated with no even a single manual upload! very fast and systematic (download -- sign -- upload -- restart MC service) all within seconds. |
|
@smartekIT ah right ok from my original testing the folder we welcome more community feedback! |
|
thanks @si458 , |
|
we arent getting rid of anything! nothing will change how people use old methods! |
|
this is why, my script process was 100% correct, taking the files after customizations from SignedAgents then sign them and upload them to folder Agents. this way our customized and signed agents will always overwrites and be in use by the server. as long this stays the case then all good. Thanks @si458 and @Rambomst. at least now we all aware of what's going on and the correct steps for people having cases like me to follow. |
### Changes: - **Introduced** promise-based readiness (`agentTablesReady`) to ensure agents' tables load dynamically without blocking server startup. - **Added** `activateAgentDefaults` method to enable hot-swapping and sign agent files without needing a server restart. - **Enhanced** domain configuration: - Allowed deferred activation for agent tables using a `Promise` workflow. - Ensured domain-specific table handling doesn't process half-filled maps during signing. - **Updated** agent catalog UI to reflect live updates: - Replaced "Restart MeshCentral" messages with real-time loading status. - Added download links for agents and artifacts in the catalog view. - **Improved** branding and agent download management: - Streamlined activation logic for updated defaults and re-signing workflows. - Refactored `agentcatalog.handlebars` and `agentbuilds.js` for better modularity. - Enhanced `translate.json` mappings for the new UI elements and workflows. - **Adjusted** CSS for catalog UI: - Added `.agent-file-tools` style improvements for better layout. - Improved responsiveness of file download and metadata indicators. This update provides better agent file management, reduces reliance on restarts, and enhances the user-facing catalog for default agents.
|
Confirming what Simon said, with one exception: a build set as server default in the Agent builds tab outranks the agents folder. Nothing else does. The PR never touches the agents folder, and signedagents is still written only by the server's own signing pass, as before. For the trigger list: startup re-signs when agentFileInfo (icon, logo, version info), the domain title, the signing cert or URL (including the ServerID lock) or the agent release itself changes. agentCustomization (companyName, fileName, colours) goes into the .msh at download time and never changes the signed binary, so a change there needs no new signing run. One timing change: the default agents now download from the pinned release in the background at startup. Files that arrive after the server is up are signed and loaded as soon as they land, and the server logs it, so a fixed delay after an upgrade still works. If you would rather have MeshCentral call you than poll it, externalSignJob (settings) runs with the output path after each server signing, at startup and now also for uploaded builds. A job that copies the file to your Windows box over ssh, runs signtool there and copies it back keeps the token and AHK where they are. @si458 Download button is in. |
|
my cmd script ssh and pull the files from signedagents folder locally to windows. ( with the help of WinScp command-line) simple is that. |
### Changes: - **Improved** modal dialog handling: - Added `.agent-manager-modal` class for enhanced styling of agent manager modals. - Ensured modal class is removed after close to maintain proper class states. - **Updated** CSS layout for agent manager fields: - Adjusted grid column dimensions for improved field alignment and responsiveness. - Introduced targeted `.agent-manager-modal .modal-dialog` styles to optimise modal alignment. - **Modified** input fields in `agentbuildmanager.js`: - Added explicit `type="text"` attributes for increased accessibility and consistency across input elements. - **Refined** agent build filtering in `agentbuilds.js`: - Removed unnecessary condition from the filtering logic for better performance. - Updated filtering to ensure all valid architectures are included without redundant checks. These changes improve usability, visual consistency, and functionality of modal dialogs and the agent build UI.
|
@stephannn Thanks for testing. The dialog was recentering when GitHub settings expanded. I’ve fixed that and aligned the form fields. I reproduced the upload error with NoAgentUpdate enabled. The importer was treating disabled updates as an unsupported agent type. Uploads now work while automatic updates stay disabled. |
…list** - Added APK detection to the agent file inspector. A ZIP with `AndroidManifest.xml`, `classes.dex` and an APK signature is identified as the Android agent (type 14) from its central directory; unsigned APKs and other archives are rejected. - Passed APKs through the import unpacker whole. The 1.2.6 APK has 1090 entries, over the 512-entry budget, so importing it from GitHub failed. - Replaced the free-text GitHub repository field with a select of `Ylianst/MeshAgent`, `Ylianst/MeshCentralAndroidAgent` and Custom, which shows an `owner/repository` field and blocks Find builds until it is filled in. - Made Releases the default build source, since public releases need no token. - Matched release check candidates on the default filenames instead of an `agent-release.json` asset, which the agent repositories no longer publish. Older Android releases only carry versioned APK names, so they stay excluded. - Updated `translate.json`.
- OpenBSD executables keep the System V ABI byte, so the inspector treated them as Linux and offered Linux x86-64 agent types. They are now recognised by their OpenBSD ident note or `/usr/libexec/ld.so` loader and offered as OpenBSD x86-64 (type 37). - Mapped OpenBSD builds to `freebsd` in the compatibility check, since the OpenBSD agent is built with `_FREEBSD` and reports that platform.
…d of selected builds** - Added translations in all 29 languages for every agent build string; the remaining untranslated entries are Handlebars-only fragments. - Marked the catalog filter options `notransval=1` and dropped their entries, since the translate step rewrites option values and would break the filter in translated pages. - Made the run and attempt labels in the import dialog translatable. - Ignored `public/scripts/translations/`, where `translateall` writes the translated agent build manager. - Served files in `meshcentral-data/agents` (and `agents-<domain>`) ahead of builds selected as the server default, so existing overrides keep working. Current defaults shows a notice and marks selected builds that are overridden, and setting a default warns when a file there takes priority.
…dialogs on mobile** - Added Stop using this file to Current defaults rows served from `meshcentral-data/agents` (or `agents-<domain>`). It renames the file to `<name>.disabled` and serves the build set as the server default, or the release file, without a restart. The default domain signs its Windows agents again first. Peered servers refuse it, since it would only rename the file on one of them. - Fixed agent build dialogs running off the right edge in the mobile UI. Its `center()` writes an inline left for a 300px dialog on every resize, which overrode the wider dialog's position. - Updated `translate.json`.










Summary
Relates to:
Issue: #8176
MeshAgent PR: Ylianst/MeshAgent#426
MeshAgentAndroid PR: Ylianst/MeshCentralAndroidAgent#48
The
legacy-1.2.6migration releases must be published inYlianst/MeshAgentandYlianst/MeshCentralAndroidAgentbefore releasing MeshCentral with these defaults.Please follow this checklist to avoid unnecessary back and forth (click to expand)
I understand that I am responsible for and able to explain every line of code I submit.
Screenshots for Visual Changes