KamoCRM

Live Change Log

Every feature, fix and improvement, posted as it ships. Nothing is held back for a launch.

15,120
Total Changes
5,169
Features
4,935
Fixes
30
Projects
Filter by project
All Projects15,120AIService197APIService161BillingService143ConversionService107DaemonService129DocsService215ESigService88EmailService518InitializerService318KBService105KlusterServices697MCPGatewayService85MediaService546RAGService71SecurityService1,658TranslateService55VOIPService205VectorService11kamo-apps25kamo-asterisk-support24kamo-capcha17kamo-capcha-widget4kamo-internal6,937kamo-login330kamo-marketing625kamo-nowww20kamo-register213kamo-shared-library1,455kamo-signer-monorepo53kamolos108
Filter by type
All TypesBuild11CI523Chore738Docs2,167Feature5,169Fix4,935Other986Performance157Refactor274Revert23Style42Test94Upgrade1
September 24, 2026
FixKlusterServices

Two threads rebuilt the initrd at once and destroyed the machine

A computer provisioned, came up, and panicked on its next boot: Run /init as init process Failed to execute /init (error -2) Kernel panic - not syn...

Kamo·5d ago
FixKlusterServices

The restart could land mid-initramfs and leave a computer unbootable

A brand new computer provisioned, came up, reported AWAKE, and ninety seconds later panicked: Kernel panic - not syncing: No working init found. I caused ...

Kamo·5d ago
DocsKlusterServices

Kamo-internal's session-handle secret

kamo-internal 3e3c3e7a mounts **************** (SESSION_HANDLE_SECRET), which seals the per-tab session handles that replace the *** id in page script. Created ...

Kamo·5d ago
September 23, 2026
FixKlusterServices

A resumed computer went straight back to sleep

Thirty seconds after the first real resume, from the machine's own log: kamo-hc-agent: idle 13202s >= 1800s — going to sleep PM: hibernation: hibernati...

Kamo·5d ago
FixKlusterServices

Kamouniverse.com redirect was losing to the www.* catch-all

www.kamouniverse.com was served by the kamocrm.com marketing app instead of redirecting: kamo-marketing-route's HostRegexp(\`^www[.].+\$\`) at priority 24 match...

Kamo·5d ago
FeatureKlusterServices

Add kamouniverse.com as a second regular-mail domain

Adds kamouniverse.com to postfix's virtual_alias_domains with a local-part-preserving regexp so any address on it lands in the identical kamocrm.com mailbox (no...

Kamo·5d ago
FeatureKlusterServices

Forward kamouniverse.com to kamocrm.com

DNS for the apex and www now point at k1m1's public IP. Add a redirectRegex route on both entrypoints (301, path/query preserved, ACME challenge path excluded o...

Kamo·5d ago
FixKlusterServices

The login greeter was counting as a member using the computer

rdp_sessions() collected every Xorg process with a display argument. The image installs lightdm and lightdm-gtk-greeter, so lightdm runs its own Xorg on :0 on e...

Kamo·5d ago
FixKlusterServices

A stale resume_offset would hibernate into the wrong place

resume_configured() checked that `resume=` and `resume_offset=` were present on the running kernel's command line. Present, not correct — and the difference is ...

Kamo·5d ago
FixKlusterServices

Root could not read a member's idle time, so nothing ever slept

The first computer reported its idle time as 13.9, then 29.2, then 14.4 seconds over three minutes while nobody was touching it. That is not a person — it is a ...

Kamo·5d ago
FixKlusterServices

The swap file was smaller than the check that measures it

With the restart landing, the first computer came up with resumeConfigured true and stopped on the next precondition — which turns out to be unsatisfiable by co...

Kamo·5d ago
FixKlusterServices

A computer could never restart into being able to sleep

The first real Hosted Computer reached AWAKE and then stayed awake forever. Hibernation reported resumeConfigured: false, IdleWatcher only arms when readiness i...

Kamo·5d ago
FixKlusterServices

Start probing at 15s, not 190 — nothing could open on its first wake

A woken computer is only reachable once its Service has endpoints, and that happens when the readiness probe on 3389 first passes. initialDelaySeconds was 180, ...

Kamo·5d ago
OtherKlusterServices

Rename apps DNS alias to apply

auto-cert's SUBDOMAINS list, the availability health-check URL and the middleware comment now match the apps -> apply subdomain rename in kamo-internal and secu...

Kamo·5d ago
FixKlusterServices

Xorg may not start from a remote session, so no computer opened

Guacamole connected, authenticated, and was hung up on: guacd: Security mode: Negotiate (ANY) guacd: Loading keymap "en-us-qwerty" guacd: RDP serve...

Kamo·5d ago
FixKlusterServices

Traefik could not see the gateway, and it served at the wrong path

Opening a computer landed on the redirect service's fallback page — "the request reached the fallback page instead of being redirected. Check the Host header." ...

Kamo·5d ago
FeatureKlusterServices

An org's own computers host gets a certificate and a route

computers is a standard alias now — every white-label org is told to point one at Kamo on /setup/dns, the way it points meet and sign — so two things had to fol...

Kamo·5d ago
CIKlusterServices

Apply the auto-cert mirror Role on deploy

Applied to the cluster by hand when the gateway certificate was set up; this is the same grant in the deploy step, so a rebuilt cluster does not have to redisco...

Kamo·5d ago
FixKlusterServices

Let auto-cert mirror the gateway certificate into this namespace

Listing computers.kamocrm.com for issuance is only half of it. Traefik requires a TLS secret in the IngressRoute's OWN namespace, so the cert is issued in `kamo...

Kamo·5d ago
FeatureKlusterServices

Issue and mirror the certificate for computers.kamocrm.com

Opening a Hosted Computer produced a browser tab that appeared and vanished. The launch link is correct and so is the token: SecurityService builds ************...

Kamo·5d ago
FixKlusterServices

A computer that has never restarted can never sleep

prepare-sleep writes the swap file and the resume wiring, then reports readiness — and readiness reads `resume=` from /proc/cmdline, which the kernel fixed at b...

Kamo·5d ago
FixKlusterServices

Reinstall grub after virt-resize, or the guest boots to a rescue prompt

virt-resize renumbers partitions. Canonical's image is laid out p14 (BIOS boot), p15 (ESP), p16 (/boot) and then p1 (root) physically last, and virt-resize rewr...

Kamo·5d ago
FixKlusterServices

The golden disk has to be RAW, or nothing boots and nothing says so

The job wrote the compressed qcow2 the build produces straight into the golden claim. KubeVirt attaches a Filesystem-PVC disk with <driver type='raw'> — always,...

Kamo·5d ago
FixKlusterServices

Only the platform reaches the database's and NATS's admin ports

YugabyteDB and NATS run on k1m1's host network, so every pod in every namespace could open every port they listen on. The client ports authenticate (YSQL :5433 ...

Kamo·5d ago
FixKlusterServices

NATS refuses anonymous clients — no_auth_user is gone

Second half of 926986d. Every client now presents the kamo_svc login: the Java services through the shared library's NatsConfig (NATS_USERNAME / NATS_PASSWORD f...

Kamo·5d ago
FixKlusterServices

Three RBAC grants no provision had ever needed

Nothing had ever been provisioned, so every grant past the namespace was untested. Each of these refused at exactly the point the previous fix unblocked. `patc...

Kamo·5d ago
FixKlusterServices

NATS clients authenticate — first half of retiring no_auth_user

NATS runs on the host network of k1m1 and listens on 0.0.0.0, and its config mapped every credential-less connection to the KAMO account (no_auth_user: anon). S...

Kamo·5d ago
FixKlusterServices

Only the platform can reach the session Redis

The `kamo` Redis holds every *** session and OTK and has no password. Nothing restricted who could connect to it: from a pod in the `desktop` namespace (where t...

Kamo·5d ago
FixKlusterServices

Five reasons the golden image had never actually been built

The build had never been run. Running it found one bug per attempt, and the first three would each have produced a plausible-looking image with something missin...

Kamo·5d ago
FeatureKlusterServices

A way to actually build the golden image

build-golden-image.sh said "Run by CI (see ../../.forgejo/workflows/)". No such workflow was ever written. It needs libguestfs, qemu-img and virt-customize, non...

Kamo·5d ago
FixKlusterServices

The three templates that never got committed

service-template.yaml, cloud-init.userdata.yaml and cloud-init.networkdata.yaml. They were written into a second worktree and committed from neither — the earli...

Kamo·5d ago
CIKlusterServices

Apply the shared infrastructure on deploy

The namespace, the single-replica StorageClass, the clusterwide seal, computeservice's RBAC and the tenant gateway. Guarded on the hosted-computers/ directory c...

Kamo·5d ago
FeatureKlusterServices

Per-org VM islands, suspend-to-disk, and a white-labeled golden image

A member's own Linux computer, running as a KubeVirt VM in its organization's namespace and opened from the browser. Separate from desktop/ in every way that ma...

Kamo·6d ago
September 17, 2026
FeatureKlusterServices

Encode the kamo14 reel

The marketing reel was recut (new closing logo shot) and uploaded as public/kamo14.mp4. It gets a new name instead of replacing kamo13 in place because the ladd...

Kamo·1w ago
September 16, 2026
FixKlusterServices

A reply to a sending domain is refused as the recipient, in words that fit NoReply

Campaigns now send Reply-To: NoReply@<their From's domain> by default, and those replies reach postfix-k3m1-inbound. The refusal said "Sender address rejected: ...

Kamo·1w ago
OtherKlusterServices

universe backup: pull mc from quay.io, docker.io/minio/mc is gone [skip ci]

MinIO withdrew its Docker Hub images, so the backup's upload container sat in ImagePullBackOff from 2026-09-12. With concurrencyPolicy Forbid that one stuck job...

Kamo·1w ago
OtherKlusterServices

node-config: registry prune must not garbage-collect with --delete-untagged [skip ci]

The nightly prune on k1m1 lived only on the host. Its garbage-collect ran with --delete-untagged, which deletes the per-platform manifests an OCI image index re...

Kamo·1w ago
OtherKlusterServices

auto-cert: stop provisioning www.stack.loans

The ratestack estate has been scaled to 0 since 2026-08-04, so nothing answers HTTP-01 for stack.loans. Its Certificates expired on 2026-08-02 and their orders ...

Kamo·1w ago
OtherKlusterServices

Disable node-exporter's xfs collector [skip ci]

It cannot parse this kernel's /proc/fs/xfs/stat ("xpc") and logged an error on every scrape, ~240/h per node. Filesystem usage is unaffected (filesystem collect...

Kamo·1w ago
OtherKlusterServices

Kamo_app owns the ocr_* tables [skip ci]

OCRService (web and worker) alters its own ocr_* tables at startup and refuses to start without ownership; after the switch to kamo_app the worker crash-looped ...

Kamo·1w ago
OtherKlusterServices

Non-superuser kamo_app role for all application workloads [skip ci]

Services connected as the superuser kamo. Add an idempotent script that creates kamo_app (no superuser, not a member of kamo so it cannot SET ROLE back) with gr...

Kamo·1w ago
FeatureKlusterServices

Bounces for organizations' sending domains reach EmailService through postfix-k3m1-inbound

A campaign sent through the shared relay has its From at the organization's sending domain as its envelope sender, and that domain is a CNAME to contact.kamocrm...

Kamo·1w ago
OtherKlusterServices

Scrape YugabyteDB tserver/YSQL and SecurityService pool metrics [skip ci]

Connection sizing had no data behind it: nothing scraped the database or the Hikari pools. Add a curated server-level tserver job (the full endpoint is ~3.25M l...

Kamo·1w ago
FeatureKlusterServices

Postmaster@ and abuse@contact.kamocrm.com reach KamoCRM — the shared relay's name receives its checks

contact.kamocrm.com is the shared org relay's name (47.181.8.86's PTR, MX contact.kamocrm.com), and its MX is 47.181.8.86 → k3m1, where postfix-k3m1-inbound ans...

Kamo·1w ago
FeatureKlusterServices

Postfix-orgs, the shared bulk relay every organization sends through as 47.181.8.86

KamoCRM's own campaign mail keeps leaving through postfix-bulk (47.181.8.87) and regular mail through postfix (47.181.8.84). Every other organization's campaign...

Kamo·1w ago
OtherKlusterServices

node-config(k3m1-ext): eno1 on DHCP as k3m1-ext, used only by traffic from its own address

k3m1's third cable is the port the shared bulk relay (postfix-orgs, 47.181.8.86) sends through. DHCP gives it an address and nothing else, so the main table is ...

Kamo·1w ago
FixKlusterServices

Prune unused images on k3m1 too, and stop bulk removals timing out

k3m1 had no prune job, and kubelet image GC waits for 85% disk, so every deploy's SHA-tagged image piled up: 3,368 images (539G), 86 in use. Add a daily k3m1-im...

Kamo·1w ago
September 13, 2026
FeatureKlusterServices

Sign Feedback-ID in DKIM signatures

Gmail counts a campaign message toward its Feedback Loop only when the Feedback-ID header is covered by the sending domain's DKIM signature. local.d/dkim.conf k...

Kamo·2w ago
FeatureKlusterServices

Receive postmaster@/abuse@stack.loans on k3m1 for the bulk IP's checks

47.181.8.87's reverse DNS is mail.stack.loans and the router forwards its port 25 to k3m1, but nothing there accepted mail, so a provider verifying who runs the...

Kamo·2w ago
FeatureKlusterServices

Route fbl@/abuse@hello.kamocrm.com complaint reports to EmailService

Spam-complaint feedback-loop reports (ARF, RFC 5965) and abuse reports sent to fbl@ and abuse@hello.kamocrm.com are rewritten to complaints-mail.invalid and han...

Kamo·2w ago

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing