Skip to content
Tickwise

Changelog

What's new in Tickwise

Release history of the Tickwise agent, cloud, signature database and website.

On this page

Format: Keep a Changelog.

0.1.0 — unreleased

First MVP code (Beta-0, closed beta). No public release.

Added

  • Documentation. Research and design documentation in docs/ (product, market, architecture, security, diagnostic rules, operations, legal review, phase plans), ADR-001…019, including the Beta-0 decisions on the web app and the data schema (ADR-016…018). Guides in docs/guides/ and docs/operations/signature-authoring.md.
  • Build. Gradle monorepo: agent-core, agent-paper, agent-velocity, kb-tools, cloud. Java 21 (--release 21), Spotless, reproducible archives, pinned dependency versions.
  • agent-core.
    • Log parser, stack trace assembly, local sanitiser (player names, IPs, secrets, paths; fuzz tests).
    • Deterministic fingerprint, deduplication, rate limiting, log storm protection.
    • Protocol v1, prioritised on-disk outbox with at-least-once delivery, HTTPS client, device code linking, agent runtime.
  • Signature Pack. Pack format, signature engine (RE2/J + declarative predicates), Ed25519 signing with a domain prefix, storage with fallback current → previous → built-in.
  • kb-tools. Signature validation, fixture runs with precision checks, deterministic pack build, offline signing, kb/dist verification, fixture sanitisation, log corpus report.
  • Signatures. 42 signatures with positive and negative fixtures, signed pack 2026.09.24-1.
  • agent-paper. Paper/Purpur plugin: log capture, TPS/MSPT sampler, plugin and config inventory, /tickwise commands.
  • agent-velocity. Velocity plugin: backend connection and kick events, backend pings, “no available servers”.
  • cloud.
    • PostgreSQL schema (Flyway), platform layer (job queue, rate limits, identifiers, hashing), device code agent linking, idempotent batch ingestion.
    • Incidents, proxy ↔ backend network correlation, “what changed”, Telegram bot (linking, cards, 👍/👎).
    • Read-only internal incident page API for the web app.
  • web. Next.js site (landing page, privacy, consent) and a read-only incident page /i/{token} with a nonce-based CSP.
    • Error database /errors: a page for every signature (log lines, cause, steps), search, Russian and English.
    • Documentation: agent installation, the Telegram bot, security, changelog (MDX).
    • SEO: per-page canonical and hreflang, sitemap.xml, JSON-LD, link preview images for every page, indexing toggled by TICKWISE_INDEXING.
  • Security. A test that fails the build if any module uses process spawning, dynamic code or Java deserialisation.
  • Deployment. A backup service in compose (daily pg_dump, 30 daily + 12 monthly copies), off-site copies to object storage via restic (deploy/backup/offsite.sh + a systemd timer), restore (deploy/backup/restore.sh) and backup verification on a clean database (deploy/backup/restore-test.sh, D8). Memory limits and PostgreSQL settings for a 6 vCPU / 12 GB VDS. An nginx template for a VDS where 80/443 are already taken. Release workflow (images in GHCR on a v* tag, a draft release with the agent jars) and deploy/deploy.sh with rollback to the previous images.
  • Test rigs. Local compatibility and MSPT rig on real Paper/Purpur/Velocity (deploy/local/run-server.sh, JFR analysis), end-to-end network rig with real agents measuring time to a Telegram card (deploy/local/e2e-network.py, D5/D6).

Changed

  • Product renamed from BlockOps to Tickwise (ADR-019): packages, commands, permissions, jars, protocol headers, environment variables; the pack was re-signed.
  • The incident page moved from the cloud to the web app: the cloud only serves data (ADR-018 supersedes ADR-016).

Fixed

  • Sanitiser false positives found while working on signatures.
  • The incident page no longer crashes on an invalid log fragment link.
  • Reveal animations on the site no longer depend on JavaScript.
  • Link previews for the site pointed to localhost: web now gets TICKWISE_SITE_URL from deploy/.env.
  • Prefetching Russian site pages returned 404.
  • Queue jobs are scheduled by the database clock: when the application clock ran ahead of the PostgreSQL clock (Docker Desktop VM after sleep), fresh jobs got “stuck in the future” and incidents/notifications were not created.
  • Jackson 3.1.7 on top of the Spring Boot 4.1.1 BOM (GHSA-7hhh-6rmp-j9qf, GHSA-cxp5-3px4-pw24 and others).
  • The documentation link in the agent configs pointed to a non-existent file.