KamoUniverse is a stop word for related-article suggestions
KbArticleRelationService matches articles on their significant terms and already drops the platform's own names ("kamocrm", "kamo") because every help article s...
A deleted task takes back its comment notifications too
Deleting a task (or clearing done tasks, or deleting their list) withdrew only its TASK_ASSIGNED and TASK_DUE notices. Every TASK_COMMENTED about it stayed in i...
Record links, who wrote each version, readable history, supervisor reads, app gate
A restored version now comes back deciphered, with its links and editor: the editor saves that answer straight back as the note's body, so the ciphertext it use...
Hand a retiring AI member's open tasks to its supervisor (SP02 TASK_HANDOFF)
POST **************** behind the KamoAI secret (KamoaiInternalAuthFilter: 503 unset, 403 mismatch, constant-time). One transaction per task; Inbox tasks move to...
Fold lead_task into tasks — idempotent, encrypted, one row per transaction
The task API — mine, search, create into an Inbox, change, finish, link
A status list with no status in it (status=,) reads as the default instead of reaching the query builder as an empty filter; blank linkKind/linkRef are absent l...
Tasks across lists — create, reassign and move, status, delete, links
A move re-seals the task's words under its own label, since the fallback key is the list owner's and the move changes the owner. A due time sent again unchanged...
Tasks carry status, priority, due, assignee and links; the Inbox keeps its rules
Task notifications after commit, and the org-change signal for internal writes
Who a task can be given to, who supervises whom, and the names tasks show
The SP06 schema — tasks, links, comments, Inbox, note links and authorship
Own NATS login, Redis login, KamoAI secret
NatsConfig's comment now names where the login comes from: svc_kb, from the nats-user-kb Secret, which overrides the shared kamo_svc keys.
Pin kamo-shared-library 1.6.1, the only version that exists
The library moved to 1.6.1 and this service still asked for 1.6.0. There is no window in which both resolve: the library is never published to a remote, so the ...
Stop asking three hot queries one row at a time
Three queries pg_stat_statements showed as kbservice's top production DB cost, all from asking in a loop (or with a plan the legacy YugabyteDB planner picked ba...
KBService presents the NATS login
NATS mapped every credential-less connection to the KAMO account (no_auth_user), and it listens on the host network of k1m1 — so any pod, the desktop VM or a ma...
The checklist API, with prerequisites the server enforces
/api/checklists: list, get, create, update, delete, duplicate, reset, clear-done, sequence ("do in order"), clear links, and per task add, edit, tick/untick, se...
Don't load content_json to build the public tree index, and stop loading it twice
buildPublicTreeIndex builds a small structural index (parent/child, slug path, ancestors) from every public article in the org, but it was loading full KbArticl...
A media presigned URL was not scoped to the caller's org
GET /api/kb/media/{mediaId}/url looked the row up by uid alone (KbMediaService.getPresignedUrl -> **************** unlike every other media read here (presignAl...
Count the marketing site's page views, on the article or on the page
KBService now answers the view counter kamo-marketing shows at the foot of every page. Two endpoints, both {"views": n} with the view just counted included: ...
Liveness probe on /actuator/health/liveness, not the DB-aware aggregate
The aggregate /actuator/health includes the DataSource indicator, so restarting the database failed liveness on every pod at once and restarted the whole platfo...
Release idle Hikari connections now that YSQL pooling is shared
The connection manager no longer pins sessions **************** so idle app connections no longer each hold a database backend. Keep the pool maximum, but stop ...
Accept OCI image indexes when resolving the built digest [skip ci]
The images are pushed as OCI image indexes, so asking the registry for a single image manifest only answered 404, the digest came back empty and the check faile...
Restart when a same-commit rebuild leaves pods on the old digest [skip ci]
The rollout step tried to detect a same-commit rebuild by comparing the Deployment's image reference before and after `set image`. "Apply manifests" has already...
Say which locales each public article is really translated into
The marketing site's sitemap now lists every language version of every help-center, documentation and API-reference article, and each article page names the oth...
Prove the deploy by digest, not by tag
The preceding commit stops `set image` being a silent no-op. This asserts the outcome: after the rollout, the tag is resolved to a digest at the registry and th...
A rebuild of the same commit deployed nothing and reported success
The image is tagged with the commit SHA, so rebuilding the same commit produces an identical image reference. `kubectl set image` then changes nothing, the Depl...
Stop the sweep re-translating the twenty locales that already worked
An article holding 20 of its 21 locales is "incomplete", so the ten-minute sweep re-queued it — and the translator then re-translated all 21, paying twenty time...
Lock the shared sweeps, and run two pods
Every @Scheduled sweep here whose effect is shared now takes a named distributed lease through SingletonTaskRunner before it does anything, so it runs once acro...
Let a rollout finish what the old pod was doing
Deploys replaced the only pod of each service with nothing to catch the requests in flight. Three settings, applied across the fleet: - preStop sleeps 10s befo...
Admit the organization owner, or nobody can turn this on
A brand-new right is granted to NOBODY on the day it deploys. These two are deliberately absent from **************** — seeding them from an existing right woul...
Serve the scripts an agent reads on a call
/api/kb/sales-scripts, gated on the two new rights. Reads take VIEW_SALES_SCRIPTS or MANAGE_SALES_SCRIPTS, writes take MANAGE. SessionHelper.hasRight fails clos...
Stop repeating the ancestor chain on every node of a tree
A node inside a tree already knows where it is -- its position is the tree. Sending the ancestor chain on each one meant every article carried two ancestor refs...
A list read shipped every article's body, and a category page listed nothing
Two defects on the public reads, both visible on kamocrm.com/help-center. The index served 3.9 MB of HTML. tree-by-parent-slug returns every node with its full...
Article translation has never worked
deleteByArticleUidAndLocale is a @Modifying query and JPA refuses to run one outside a transaction. Nothing on this path ever opened one, so every locale of eve...
Saving an article blocked on 21 translation calls
@Async was inert. **************** called translateArticle on the same bean, so the call went straight to this and never reached the proxy that makes it asynchr...
Related articles, and a public path that keeps the tree
Three things, all reaching the same page. Related articles. KbArticleRelationService owns the symmetric "see also" links: list, set, suggest, and a clear that ...
Enforce the audience chips on every human read
The composer has always offered an author three chips under "Visible to" — Members, Team Members, Public. They were written to the row and indexed into Qdrant s...
GET /master takes VIEW_NOTES, like every other read here
It was the one read in this controller that took no right, deliberately: the two master notes were called fixtures of the home launchpad rather than the Notes a...
Pin kamo-shared-library 1.6.0
The library moved to 1.6.0 while every consumer stayed on 1.5.0. Consumer CI builds the library from a fresh clone into a cold ~/.m2 and ci-settings.xml mirrors...
Stop seeding a palette colour on the org master note
Both master notes are painted from the ORGANISATION's brand now — primary for "Our Master Note", secondary for "My Master Note", each as a pastel — so a stored ...
Serve, provision and protect the two master notes
GET /api/notes/master answers both and provisions whichever is missing. PUT /api/notes/master/org writes "Our Master Note", addressed by organisation rather tha...
Keep the encryption key across restarts instead of inventing one
Every note body in production was unreadable. NOTES_MASTER_ENCRYPTION_KEY was never set anywhere - not in the deployment, and the deployed ConfigMap carried no ...
Like what you see shipping?
All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.
