[{"data":1,"prerenderedAt":861},["ShallowReactive",2],{"changelog-\u002Fchangelog\u002F2026\u002F02\u002Frestoring-snapshots-to-remote-instances\u002F":3,"changelog-recent":69},{"id":4,"title":5,"authors":6,"body":8,"date":54,"description":55,"extension":56,"issues":57,"meta":59,"navigation":62,"path":63,"seo":64,"sitemap":65,"stem":66,"subtitle":67,"__hash__":68},"changelog\u002Fchangelog\u002F2026\u002F02\u002Frestoring-snapshots-to-remote-instances.md","Restoring snapshots to developer-mode Remote Instances",[7],"nick-oleary",{"type":9,"value":10,"toc":51},"minimark",[11,15,18,21,24,37,40],[12,13,14],"p",{},"Device Agent version 3.8.0 has been released which brings a significant workflow improvement when editing your flows.",[12,16,17],{},"When the ability to remotely edit flows was introduced - known as 'developer mode' - we blocked the ability to push snapshots to a remote instance whilst in this mode. This protection makes sense when you're working on a remote instance, but still need to push updates out to the rest of your fleet through a pipeline deployment - you don't want the deployment from overwriting the work you're in the middle of.",[12,19,20],{},"However, there are cases where you want to rollback changes you've been making to a remote instance. Previously that would involve taking the instance out of developer mode, restoring the snapshot, then putting it back into developer mode to continue working. This is a lot of unnecessary steps and not an obvious workflow.",[12,22,23],{},"With the new v3.8.0 release of the Device Agent, it is now possible to manually restore snapshots without leaving developer mode:",[25,26,27,31,34],"ul",{},[28,29,30],"li",{},"Open the Version History tab for the Remote Instance and switch the Snapshots view",[28,32,33],{},"Click on the snapshot you want to use",[28,35,36],{},"Click on the restore button in the snapshot sidebar",[12,38,39],{},"The existing protection that blocks pipeline-driven deploys of snapshots is still in place.",[12,41,42,48],{},[43,44],"img",{"alt":45,"dataZoomable":46,"src":47},"Restoring a snapshot to a Developer-Mode Remote Instance","","\u002Fchangelog\u002F2026\u002F02\u002Fimages\u002Fsnapshot-restore.png",[49,50,45],"em",{},{"title":46,"searchDepth":52,"depth":52,"links":53},4,[],"2026-02-12","A significant workflow improvement introduced by Device Agent v3.8.0","md",[58],"https:\u002F\u002Fgithub.com\u002FFlowFuse\u002Fflowfuse\u002Fissues\u002F6496",{"tags":60},[61],"changelog",true,"\u002Fchangelog\u002F2026\u002F02\u002Frestoring-snapshots-to-remote-instances",{"title":5,"description":55},{"loc":63},"changelog\u002F2026\u002F02\u002Frestoring-snapshots-to-remote-instances",null,"Ee8xXoWht32VTAg-DLNnCRipY5XBfis0PvmMCYYMfdY",[70,137,212,523,597,781],{"id":71,"title":72,"authors":73,"body":75,"date":126,"description":127,"extension":56,"issues":128,"meta":130,"navigation":62,"path":132,"seo":133,"sitemap":134,"stem":135,"subtitle":67,"__hash__":136},"changelog\u002Fchangelog\u002F2026\u002F07\u002Fteam-and-application-dashboards.md","A Dedicated Home for Your Dashboards",[74],"noley-holland",{"type":9,"value":76,"toc":122},[77,88,91,100,105,108,117],[12,78,79,80,84,85,87],{},"Your dashboards now have a home. A new ",[81,82,83],"strong",{},"Dashboards"," entry in the team navigation lists every dashboard across your hosted instances in one place. Open one and it loads right inside FlowFuse, not in a separate browser tab. Each application also has its own ",[81,86,83],{}," tab, showing just the dashboards from that application's instances.",[12,89,90],{},"Until now, dashboards were tucked behind an \"Open Dashboard\" button on individual instance pages. Finding the one you wanted meant hunting through instances, and each one opened in a new tab. Now you get one place that shows them all, at the team or application level.",[12,92,93,97],{},[43,94],{"alt":95,"dataZoomable":46,"src":96},"The Dashboards view listing all dashboards across the team","\u002Fchangelog\u002F2026\u002F07\u002Fimages\u002Fteam-dashboards.png",[49,98,99],{},"Every dashboard in the team, each showing whether its instance is currently running",[101,102,104],"h2",{"id":103},"switch-between-dashboards-in-place","Switch between dashboards in place",[12,106,107],{},"A drawer lets you switch to any other dashboard in a single click, without returning to the list. Jump from your \"Line 3 OEE\" dashboard to \"Energy Monitoring\" and back without losing your place. Instance status updates live in the drawer, so you can see at a glance which dashboards are ready.",[12,109,110,114],{},[43,111],{"alt":112,"dataZoomable":46,"src":113},"An embedded dashboard with the drawer open to switch between dashboards","\u002Fchangelog\u002F2026\u002F07\u002Fimages\u002Fdashboard-drawer.png",[49,115,116],{},"The drawer stays open alongside the dashboard, so switching doesn't cover what you're viewing",[12,118,119],{},[49,120,121],{},"This feature is available to all users of FlowFuse Cloud and all Self Hosted users from v2.33.",{"title":46,"searchDepth":52,"depth":52,"links":123},[124],{"id":103,"depth":125,"text":104},2,"2026-07-22","Browse and open every dashboard across your team from a new Dashboards view, without leaving FlowFuse.",[129],"https:\u002F\u002Fgithub.com\u002FFlowFuse\u002Fflowfuse\u002Fissues\u002F7665",{"tags":131},[61],"\u002Fchangelog\u002F2026\u002F07\u002Fteam-and-application-dashboards",{"title":72,"description":127},{"loc":132},"changelog\u002F2026\u002F07\u002Fteam-and-application-dashboards","cJ_6FJG9x11-C52tpKQfl3bD7sCl4JAcJI72vUyRI3Q",{"id":138,"title":139,"authors":140,"body":142,"date":201,"description":202,"extension":56,"issues":203,"meta":205,"navigation":62,"path":207,"seo":208,"sitemap":209,"stem":210,"subtitle":67,"__hash__":211},"changelog\u002Fchangelog\u002F2026\u002F07\u002Fapplication-sso-groups.md","Application Roles from SSO Groups",[141],"ben-hardill",{"type":9,"value":143,"toc":199},[144,147,150,161,184,196],[12,145,146],{},"Application level Role overrides can now be managed by SSO Group membership.",[12,148,149],{},"As well as Team wide Role membership additional groups can be used to apply Role overrides to specific Applications.",[12,151,152,153,160],{},"This works for both SAML and LDAP based SSO, the documentation outlining the required group naming can be found ",[154,155,159],"a",{"href":156,"rel":157},"https:\u002F\u002Fflowfuse.com\u002Fdocs\u002Fadmin\u002Fsso",[158],"nofollow","here",".",[12,162,163,164,168,169,172,173,176,177,180,181,183],{},"For example for a Team with the slug ",[165,166,167],"code",{},"development"," and an application called ",[165,170,171],{},"test"," a user in the following groups would have ",[165,174,175],{},"member"," level access to the Team and ",[165,178,179],{},"owner"," level access to the ",[165,182,171],{}," Application.",[25,185,186,191],{},[28,187,188],{},[165,189,190],{},"ff-development-member",[28,192,193],{},[165,194,195],{},"ff-development[test]-owner",[12,197,198],{},"This is available to FlowFuse Cloud Teams now and will be available to Self Hosted customers from version 2.33.0 onwards.",{"title":46,"searchDepth":52,"depth":52,"links":200},[],"2026-07-15","Control Application level Role overrides from SSO Groups",[204],"https:\u002F\u002Fgithub.com\u002FFlowFuse\u002Fflowfuse\u002Fissues\u002F7396",{"tags":206},[61],"\u002Fchangelog\u002F2026\u002F07\u002Fapplication-sso-groups",{"title":139,"description":202},{"loc":207},"changelog\u002F2026\u002F07\u002Fapplication-sso-groups","Ai8qxgCGkacybac36MZJ1JbjFUhFFKEU4WIGJ4DncKo",{"id":213,"title":214,"authors":215,"body":219,"date":514,"description":515,"extension":56,"issues":67,"meta":516,"navigation":62,"path":518,"seo":519,"sitemap":520,"stem":521,"subtitle":67,"__hash__":522},"changelog\u002Fchangelog\u002F2026\u002F07\u002Fexpert-enhancements.md","FlowFuse Expert Enhancements",[216,217,218],"stephen-mclaughlin","serban-costin","andrea-palmieri",{"type":9,"value":220,"toc":504},[221,225,228,239,247,255,264,268,271,288,291,295,298,303,306,312,338,341,350,354,357,360,371,381,390,394,397,400,420,423,432,444,453,487,496,499],[101,222,224],{"id":223},"insights","Insights",[12,226,227],{},"With the release of device-agent 4.0.0 and FlowFuse 2.32.0, FlowFuse Expert Insights Agent can now work with Remote Instances and Self Hosted Instances.",[229,230,231,236],"caution",{},[12,232,233],{},[81,234,235],{},"Important:",[12,237,238],{},"In order to achieve Insights on Remote Instances and Self Hosted Instances,  we had to modify how data is routed through the platform. Your old Hosted Instances on FlowFuse Cloud will require an update to the latest Launcher Version (2.23.0 or greater) to continue working.",[12,240,241,245],{},[43,242],{"alt":243,"dataZoomable":46,"src":244},"Resource from Hosted and Remote Instances can now be selected","\u002Fchangelog\u002F2026\u002F07\u002Fimages\u002Finsights-1.png",[49,246,243],{},[12,248,249,253],{},[43,250],{"alt":251,"dataZoomable":46,"src":252},"Insights querying a Remote Instance","\u002Fchangelog\u002F2026\u002F07\u002Fimages\u002Finsights-2.png",[49,254,251],{},[12,256,257,261],{},[43,258],{"alt":259,"dataZoomable":46,"src":260},"Insights in an action","\u002Fchangelog\u002F2026\u002F07\u002Fimages\u002Finsights.gif",[49,262,263],{},"Insights in an action - querying a Remote Instance",[101,265,267],{"id":266},"platform-automations","Platform Automations",[12,269,270],{},"The Expert can now take action on your FlowFuse platform directly. Instead of telling you which buttons to click, it can create instances, register devices, take snapshots, and manage applications on your behalf. You can ask the Expert to:",[25,272,273,276,279,282,285],{},[28,274,275],{},"Create hosted instances with the right type, stack, and template, optionally starting from a flow blueprint",[28,277,278],{},"Register remote instances (devices) and assign them to applications",[28,280,281],{},"Take and list snapshots of both hosted and remote instances",[28,283,284],{},"Create applications, list what's running inside them, and check their audit logs",[28,286,287],{},"Look up live status and logs for any hosted instance, or query a remote instance's state over MQTT",[12,289,290],{},"Behind the scenes, FlowFuse exposes over 30 automation tools covering instances, devices, applications, snapshots, teams, and configuration. When you ask the Expert to do something, it picks the right tools, calls them with your permissions, and reports back.",[101,292,294],{"id":293},"support-agent","Support Agent",[12,296,297],{},"We have added three ways to stay in control of what the Expert does while it works alongside you in the editor.",[299,300,302],"h3",{"id":301},"plan-mode","Plan Mode",[12,304,305],{},"The Expert can now propose a plan before it changes anything, so you can review the approach before it touches your flows.",[12,307,308,309,311],{},"Turn on ",[81,310,302],{}," with the toggle in the chat composer. Instead of acting straight away, the Expert lays out what it intends to do as a plan you can read through. From there you can:",[25,313,314,320,326,332],{},[28,315,316,319],{},[81,317,318],{},"Approve",": the Expert proceeds with the plan.",[28,321,322,325],{},[81,323,324],{},"Edit",": open the plan in the composer, adjust the wording yourself, and send it back.",[28,327,328,331],{},[81,329,330],{},"Request changes",": describe what you would like to be different, and the Expert proposes an updated plan.",[28,333,334,337],{},[81,335,336],{},"Reject",": discard the plan and start again.",[12,339,340],{},"This is ideal for larger or unfamiliar changes, where you want to agree on the approach before any work happens.",[12,342,343,347],{},[43,344],{"alt":345,"dataZoomable":46,"src":346},"The Expert proposing a plan, with Approve, Edit, Request changes, and Reject actions","\u002Fchangelog\u002F2026\u002F07\u002Fimages\u002Fplan.png",[49,348,349],{},"The Expert proposes a plan and waits for your approval before making any changes",[299,351,353],{"id":352},"clarifying-questions","Clarifying Questions",[12,355,356],{},"The Expert now asks clarifying questions when a request could go more than one way, rather than guessing and building the wrong thing.",[12,358,359],{},"When it needs more detail, the Expert presents up to four questions in a single turn, each as a set of options you pick from, either single choice or multiple choice. You answer them all together, and it uses your answers to get the result right the first time. For example:",[25,361,362,365,368],{},[28,363,364],{},"Which flow should this run in?",[28,366,367],{},"Should the incoming payload be stored, forwarded, or both?",[28,369,370],{},"Which of these nodes should trigger the alert?",[12,372,373,374,377,378,160],{},"You can revisit and change your answers before continuing, and you decide the pace: use the follow-up questions setting in the composer menu to have the Expert ask everything ",[81,375,376],{},"all at once"," or ",[81,379,380],{},"one at a time",[12,382,383,387],{},[43,384],{"alt":385,"dataZoomable":46,"src":386},"The Expert asking grouped clarifying questions with single and multiple choice options","\u002Fchangelog\u002F2026\u002F07\u002Fimages\u002Fquestions.png",[49,388,389],{},"The Expert asks clarifying questions and collects your answers before acting",[299,391,393],{"id":392},"human-in-the-loop","Human in the Loop",[12,395,396],{},"You are now in charge of exactly which actions the Expert is allowed to take on your flows, so no change happens that you did not permit.",[12,398,399],{},"When the Expert wants to run an action that needs your sign-off, it pauses and shows an approval card in the chat. The card names the action, whether it reads, writes, or deletes, and the exact details of what it will do, with four choices:",[25,401,402,411],{},[28,403,404,377,407,410],{},[81,405,406],{},"Allow",[81,408,409],{},"Deny",": approve or refuse this one action.",[28,412,413,377,416,419],{},[81,414,415],{},"Always allow",[81,417,418],{},"Always deny",": apply your choice to every matching action.",[12,421,422],{},"The Expert waits for your decision however long you need, and you can cancel a pending action at any time with the stop button.",[12,424,425,429],{},[43,426],{"alt":427,"dataZoomable":46,"src":428},"An inline approval card showing the action, its type, and Allow, Always allow, Deny, and Always deny choices","\u002Fchangelog\u002F2026\u002F07\u002Fimages\u002Fapproval-card.png",[49,430,431],{},"The Expert pauses and asks for approval before running an action that needs your sign-off",[12,433,434,435,377,437,439,440,443],{},"An ",[81,436,415],{},[81,438,418],{}," you set from a card applies to the current chat only, and resets when you refresh or start over. If you want to keep it, click ",[81,441,442],{},"Make permanent"," to save that choice for future chats.",[12,445,446,450],{},[43,447],{"alt":448,"dataZoomable":46,"src":449},"Clicking Make permanent on a granted action to save it for future chats","\u002Fchangelog\u002F2026\u002F07\u002Fimages\u002Fmake-permanent.gif",[49,451,452],{},"Make a per-chat permission permanent so it carries over to future chats",[12,454,455,456,459,460,463,464,467,468,471,472,463,475,478,479,482,483,486],{},"You can also set your permissions ahead of time. Open ",[81,457,458],{},"Tool permissions"," in the Expert settings and choose a default for ",[81,461,462],{},"Read",", ",[81,465,466],{},"Write",", and ",[81,469,470],{},"Delete"," actions: ",[81,473,474],{},"always allow",[81,476,477],{},"ask",", or ",[81,480,481],{},"always deny",". Out of the box the Expert can read freely but asks before it writes or deletes anything. Flow building and platform actions each have their own defaults, and you can expand ",[81,484,485],{},"Individual tools"," to override the default for a specific action, which then stays put until you reset it. These settings are saved for you and persist across chats within the team you are working in; switching to another team starts from the defaults again.",[12,488,489,493],{},[43,490],{"alt":491,"dataZoomable":46,"src":492},"The Tool permissions panel in Expert settings, with default Read, Write, and Delete permissions for flow building and platform tools","\u002Fchangelog\u002F2026\u002F07\u002Fimages\u002Ftools-permissions.png",[49,494,495],{},"Set default permissions per action type, and override individual tools where you need to",[497,498],"hr",{},[12,500,501],{},[49,502,503],{},"All of these new features are available to FlowFuse Cloud users and Self-Hosted users from v2.32.",{"title":46,"searchDepth":52,"depth":52,"links":505},[506,507,508],{"id":223,"depth":125,"text":224},{"id":266,"depth":125,"text":267},{"id":293,"depth":125,"text":294,"children":509},[510,512,513],{"id":301,"depth":511,"text":302},3,{"id":352,"depth":511,"text":353},{"id":392,"depth":511,"text":393},"2026-07-02","FlowFuse Expert now supports Insights on your devices, Platform automations, Plan Mode, Human in the Loop and more...",{"tags":517},[61],"\u002Fchangelog\u002F2026\u002F07\u002Fexpert-enhancements",{"title":214,"description":515},{"loc":518},"changelog\u002F2026\u002F07\u002Fexpert-enhancements","oZwktdlktOZxw3Wk9GXZAficSYOkt60RgKw0TptRD7A",{"id":524,"title":214,"authors":525,"body":526,"date":514,"description":515,"extension":56,"issues":588,"meta":590,"navigation":62,"path":592,"seo":593,"sitemap":594,"stem":595,"subtitle":67,"__hash__":596},"changelog\u002Fchangelog\u002F2026\u002F07\u002Fscoped-pats.md",[217],{"type":9,"value":527,"toc":582},[528,531,535,538,541,545,548,552,555,558,562,565,571,574],[12,529,530],{},"Personal Access Tokens now support fine-grained scoping. You can restrict a token to specific teams, limit it to read-only operations, or control whether it\ncarries admin privileges. This is especially useful when handing tokens to AI agents or MCP clients, where you want to limit what the token can reach.",[101,532,534],{"id":533},"team-scoping","Team scoping",[12,536,537],{},"You can now scope a token to one or more teams. A scoped token can only access resources within those teams. If you don't select any teams, the token works\nacross all teams you belong to, same as before.",[12,539,540],{},"When you're added to a new team, scoped tokens don't automatically pick it up. You need to explicitly add the new team to any token that should have access.",[101,542,544],{"id":543},"read-only-mode","Read-only mode",[12,546,547],{},"A new toggle lets you mark a token as read-only. When enabled, the token can only perform read operations across all resources it has access to. Any write\noperation will be rejected.",[101,549,551],{"id":550},"admin-opt-in","Admin opt-in",[12,553,554],{},"Tokens created by admin users no longer carry admin privileges by default. When you create a new token, it behaves as a regular user token, using your team\nroles instead of full admin access. If you need the token to have admin capabilities, you have to explicitly check the admin opt-in option.",[12,556,557],{},"Existing admin-owned tokens have been migrated with admin opt-in enabled, so they continue to work as before. Only newly created tokens default to\nnon-admin.",[101,559,561],{"id":560},"how-scoping-works","How scoping works",[12,563,564],{},"These options allow you to narrow the scope of a token's permissions; you cannot create a token with more access than your user has.",[12,566,567,568,160],{},"You can create and manage your tokens under ",[81,569,570],{},"User Settings > Security > Personal Access Tokens",[12,572,573],{},"This feature is available to FlowFuse Cloud users as of now and Self-Hosted users from v2.33.",[12,575,576,580],{},[43,577],{"alt":578,"dataZoomable":46,"src":579},"Creating a new scoped Personal Access Token","\u002Fchangelog\u002F2026\u002F07\u002Fimages\u002Fscoped-pats.png",[49,581,578],{},{"title":46,"searchDepth":52,"depth":52,"links":583},[584,585,586,587],{"id":533,"depth":125,"text":534},{"id":543,"depth":125,"text":544},{"id":550,"depth":125,"text":551},{"id":560,"depth":125,"text":561},[589],"https:\u002F\u002Fgithub.com\u002FFlowFuse\u002Fflowfuse\u002Fissues\u002F7411",{"tags":591},[61],"\u002Fchangelog\u002F2026\u002F07\u002Fscoped-pats",{"title":214,"description":515},{"loc":592},"changelog\u002F2026\u002F07\u002Fscoped-pats","SWS24JifltxnWHGl4jp189QGuolpRZWqNjTO-4o1UpI",{"id":598,"title":599,"authors":600,"body":601,"date":763,"description":764,"extension":56,"issues":765,"meta":767,"navigation":62,"path":775,"seo":776,"sitemap":777,"stem":778,"subtitle":779,"__hash__":780},"changelog\u002Fchangelog\u002F2026\u002F06\u002Fdevice-agent-v4-released.md","Device Agent v4 released",[7],{"type":9,"value":602,"toc":755},[603,611,615,618,643,648,657,660,664,671,674,677,686,690,693,696,707,710,714,717,719,723,726,738,744,746],[12,604,605,606,610],{},"Device Agent v4 is a major release. It brings a modern Node.js runtime, structured logging for production observability, a new authentication method, and a more secure container deployment model. There are breaking changes - check the ",[154,607,609],{"href":608},"#upgrading-to-v4","upgrade notes"," before updating your remote instances.",[101,612,614],{"id":613},"nodejs-22-is-now-the-default-runtime","Node.js 22 is now the default runtime",[12,616,617],{},"The Device Agent installer and official Docker image now default to Node.js 22. Node.js 20 reached end-of-life in April 2026, and continuing to ship it as the default would leave devices running on an unsupported runtime without security patches. It is also the minimum version required by Node-RED v5.",[229,619,620,630,633,636,640],{},[12,621,622,625,626,629],{},[81,623,624],{},"Breaking change:"," The Device Agent Docker image tagged ",[165,627,628],{},"latest"," now uses a Node.js 22 base image. If you do not pin your container image to a specific version tag, review your deployment configuration before upgrading.\n{% endcaution %}",[12,631,632],{},"We also continue to build, and tag, containers for a range of Node.js versions - 18, 20, 22 and 24.",[12,634,635],{},"If you use the Device Agent installer, it will now default to Node.js 22. Existing installations using the installer will need to download the latest version and re-run the installer.",[101,637,639],{"id":638},"containers-now-run-as-an-unprivileged-user","Containers now run as an unprivileged user",[12,641,642],{},"The Device Agent Docker container no longer runs as the root user. Following best practices, processes inside the container now execute as an unprivileged user.",[12,644,645,647],{},[81,646,624],{}," If your container deployment mounts volumes or relies on file permissions set for the root user, you'll need to update those permissions to match the new unprivileged user.",[12,649,650,651,656],{},"More details are available in the ",[154,652,655],{"href":653,"rel":654},"https:\u002F\u002Fgithub.com\u002FFlowFuse\u002Fdevice-agent\u002Ftree\u002Fedf987872b7c93170b5ced56061b211619e7e106#docker",[158],"Device Agent readme",".\n{% endcaution %}",[12,658,659],{},"This is a security hardening change with no functional impact on normal Device Agent operation.",[101,661,663],{"id":662},"structured-json-logging","Structured JSON logging",[12,665,666,667,670],{},"The Device Agent now supports a JSON logging format, selectable via the ",[165,668,669],{},"--log-format json"," CLI flag.",[12,672,673],{},"Previously, all agent output was plain-text - readable in a terminal but difficult to ingest reliably into log aggregation tools like Grafana Loki, Elastic, or AWS CloudWatch. Parsing unstructured log lines with regex is fragile and breaks whenever the message format changes.",[12,675,676],{},"With JSON logging enabled, every log entry is a machine-readable object with consistent fields. Pipe agent output directly into your existing observability stack without any custom parsing rules.",[678,679,684],"pre",{"className":680,"code":682,"language":683},[681],"language-text","device-agent --log-format json\n","text",[165,685,682],{"__ignoreMap":46},[101,687,689],{"id":688},"bearer-token-authentication","Bearer token authentication",[12,691,692],{},"The Device Agent now supports bearer tokens as an authentication method for HTTP endpoints, alongside the existing credential model.",[12,694,695],{},"This allows you to create HTTP endpoints in your Node-RED flows that can be accessed securely by other applications without needing to manually authenticate first. This is a capability we've had in Hosted Instances for a while - this release makes it available to Remote Instances as well.",[12,697,698,699,702,703,706],{},"You can configure the tokens via the FlowFuse dashboard for your remote instance under the ",[165,700,701],{},"Settings->Security"," section. Enable the ",[165,704,705],{},"FlowFuse User Authentication"," option, then you can create and manage the tokens.",[12,708,709],{},"This requires the FlowFuse v2.32 release, coming later this week, when running in a self-hosted environment, but already available on FlowFuse Cloud.",[101,711,713],{"id":712},"editor-theme-fix","Editor theme fix",[12,715,716],{},"A bug caused the FlowFuse editor theme to fail to load in certain configurations - particularly when switching between Node-RED 5 and legacy versions. This is now resolved. The correct theme loads regardless of which Node-RED version the device is running.",[497,718],{},[101,720,722],{"id":721},"upgrading-to-v4","Upgrading to v4",[12,724,725],{},"Before upgrading, check the following:",[12,727,728,731,732,734,735,160],{},[81,729,730],{},"Docker users:"," The ",[165,733,628],{}," container image now uses a Node.js 22 base and runs as an unprivileged user. Review volume mount permissions and update any configurations that assume a root user or an earlier Node.js version. Details available in the ",[154,736,655],{"href":653,"rel":737},[158],[12,739,740,743],{},[81,741,742],{},"Installer users:"," Download the latest version of the installer and re-run it if you want to stay aligned with the new default.",[497,745],{},[12,747,748,749,754],{},"Device Agent v4 is available now. Update via the ",[154,750,753],{"href":751,"rel":752},"https:\u002F\u002Fgithub.com\u002FFlowFuse\u002Fdevice-agent",[158],"Device Agent installer"," or pull the latest Docker image.",{"title":46,"searchDepth":52,"depth":52,"links":756},[757,758,759,760,761,762],{"id":613,"depth":125,"text":614},{"id":638,"depth":125,"text":639},{"id":662,"depth":125,"text":663},{"id":688,"depth":125,"text":689},{"id":712,"depth":125,"text":713},{"id":721,"depth":125,"text":722},"2026-06-29","Device Agent v4 ships with Node.js 22 as the default runtime, structured JSON logging, bearer token authentication, and a hardened container security model. This is a major release with breaking changes - read on to know what to update before upgrading.",[766],"https:\u002F\u002Fgithub.com\u002FFlowFuse\u002Fdevice-agent\u002Fissues\u002F650",{"tags":768,"excerpt":769},[61],{"type":9,"value":770},[771],[12,772,605,773,610],{},[154,774,609],{"href":608},"\u002Fchangelog\u002F2026\u002F06\u002Fdevice-agent-v4-released",{"title":599,"description":764},{"loc":775},"changelog\u002F2026\u002F06\u002Fdevice-agent-v4-released","Updated Node.js, JSON logging, bearer token auth, and a more secure container runtime.","mRrZn5UeaJmKpfaxohewP2cLPJ9DJDE60u2H7OkSoYE",{"id":782,"title":783,"authors":784,"body":785,"date":763,"description":851,"extension":56,"issues":852,"meta":854,"navigation":62,"path":856,"seo":857,"sitemap":858,"stem":859,"subtitle":67,"__hash__":860},"changelog\u002Fchangelog\u002F2026\u002F06\u002Fgeneric-git-server-support.md","Connect Pipelines to Any Git Server",[74],{"type":9,"value":786,"toc":849},[787,794,797,800,803,837,846],[12,788,789,790,793],{},"DevOps Pipeline Git Repository stages now connect to ",[81,791,792],{},"any Git server that speaks HTTPS",", GitLab, Bitbucket, Gitea, or a self-hosted instance, not just GitHub and Azure DevOps.",[12,795,796],{},"Previously, Git integration only worked with those two providers. If your team backs up flows to a self-hosted GitLab or an on-prem Bitbucket, you were stuck. Now you can point a pipeline at any HTTPS Git repository to back up and deploy your flows.",[12,798,799],{},"For servers that use a private certificate authority, you can paste in a CA certificate so FlowFuse trusts the connection, no infrastructure changes required.",[12,801,802],{},"To get started:",[804,805,806,812,823,830],"ol",{},[28,807,808,809,160],{},"Go to ",[81,810,811],{},"Team Settings → Integrations → Add Token",[28,813,814,815,818,819,822],{},"Choose ",[81,816,817],{},"Other",", then enter the repository ",[81,820,821],{},"username"," and a personal access token (or app password).",[28,824,825,826,829],{},"If your server uses a private CA, paste its certificate into the ",[81,827,828],{},"CA Certificate"," field.",[28,831,832,833,836],{},"Add a ",[81,834,835],{},"Git Repository"," stage to a pipeline, select your token, and enter the repository URL.",[12,838,839,843],{},[43,840],{"alt":841,"src":842},"The Add Git Token dialog showing the GitHub, Azure DevOps, and Other provider options, with the Other option selected and the username and CA certificate fields visible","\u002Fchangelog\u002F2026\u002F06\u002Fimages\u002Fgeneric-git-provider.png",[49,844,845],{},"Creating a generic Git token for a self-hosted server.",[12,847,848],{},"This feature is available to Team and Enterprise tier users of FlowFuse Cloud and Enterprise Licensed Self Hosted users from v2.32.",{"title":46,"searchDepth":52,"depth":52,"links":850},[],"DevOps Pipeline Git stages now push and pull snapshots to any HTTPS Git server, GitLab, Bitbucket, Gitea, or self-hosted, including servers behind a private certificate authority.",[853],"https:\u002F\u002Fgithub.com\u002FFlowFuse\u002Fflowfuse\u002Fissues\u002F5294",{"tags":855},[61],"\u002Fchangelog\u002F2026\u002F06\u002Fgeneric-git-server-support",{"title":783,"description":851},{"loc":856},"changelog\u002F2026\u002F06\u002Fgeneric-git-server-support","WslTXmfmPDTuF9mUsg8uiEDD8pysVlXy1cmhZkP_bt8",1785506846860]