Keep up with latest product news
80:80.
http://+:80/), the Docker daemon (a user process) cannot bind port 80 and docker compose up failed with:listen tcp 0.0.0.0:80: bind: An attempt was made to access a socket in a way forbidden by its access permissions (WSA_EACCES / 10013).80:80 and free port 80 first, e.g. stop IIS).HttpListener holding http://+:80/ (the http.sys kernel driver — the same mechanism IIS uses), docker run -p 80:80 fails with the identical error; a plain user-process socket holding 80 does not block Docker (SO_REUSEADDR coexistence), and the Windows firewall has no effect.Restrain the agent your way


Branch feat/spec010 (uncommitted). Frontend only; nothing changed under src/ or in openapi.yaml.
Untitled flow YYYY-MM-DD HH:MM:SS, with (2), (3)… added on a clash) and removes the flow from the address.sessionStorage). No password, access token, user name, role or permission is stored.minFreePercent: 10; Database size report has no parameters. It validates with 0 errors and completes in about 1.7 s, with no destructive confirmation.%SYS label and the revision/saved-time line sit under the flow name.Modal.svelte (the dialog frame, with focus handling and Escape), MenuButton.svelte (keyboard-accessible menu button) and dialog.css (shared dialog look, theme tokens only).us17–us21. The full suite has 64 passed, 1 skipped (the opt-in 900 s expiry test, which passed on its own), 0 failed.us7-catalog: a reload and a same-tab navigation no longer need a new sign-in.us15-targets: the "no credential left in the browser" check now targets target credentials specifically, allowing only the tab's own kept refresh token. It also registers iris-target itself, so it no longer depends on test order.signIn can pre-dismiss the guide.deleteFlowWithRuns deletes a flow and its runs. It refuses to run unless on the local dev instance, in the IRISAPP namespace, and on a flow whose exact name has a known test prefix.docs/limitations.md: new entries on sign-in across reloads (including that a browser crash requires signing in again) and on the example flow (its 10% free-space threshold).evidence/ holds the test records, performance numbers and the Constitution review.^sentai("config","allowInsecureTargets")=1 was set by hand on the dev instance. The running iris image predates the iris.script line that sets it, so it disappears if the container is recreated from this image.
/csp/sentai/. There is no separate web server.storage-headroom-check (Embedded Python), db-size-report, switch-journal andpurge-task-history./opt/sentai-web and served bysentai.web.StaticFiles.label, executorplatform-api | in-process) and a parameters schema.%SYS cannot leakstorage-headroom-check: read-only. It fails when a database directory or the journalminFreePercent (0–100, default 10), and namesshutil.disk_usage).db-size-report: read-only. result.databases lists every database with sizeMB andfreeMB.switch-journal and purge-task-history (keepDays, integer ≥ 0, default 30) now runPARAM_REQUIRED,PARAM_TYPE_MISMATCH, PARAM_OUT_OF_RANGE and PARAM_UNKNOWN. Each finding carries aparameter field.STEP_TYPE_NOT_SUPPORTED_ON_TARGET.GET /runs/{guid} → steps[]) show executedAs (who ran the step) and result"truncated": true).timeoutMinutes defaults to 60 when set to 0 and counts fromrunning, so it includes the time spent waiting for a worker. Terminal transitions are locked,GET /catalog/tasks and GET /catalog/tasks/{id} return the platform's own values: class,runAsUser, timePeriod, nextRun, lastStarted, lastFinished, status, lastError,suspended, and history on the item read.destructive and destructiveUnknown are derived from the step-type catalog.origin links a task created by SentaiTask back to its flow and step.unavailable entries and the platform's reason.POST /catalog/tasks/{id}/suspend suspends or resumes a task through the platform's real400 INVALID_FILTER, 502 SUSPEND_NOT_APPLIED, 502 PLATFORM_UNREACHABLE.?view=catalog&task=<id>. It offers filters, sorting, a detail view with an origin link, andparameter. A legacy custom step shows its class read-only.GET/POST /targetsGET/PUT/DELETE /targets/{name}POST /targets/{name}/onlinePOST /targets/{name}/sign-in (keeps nothing)GET /targets/{name}/status (the target's token travels inX-Sentai-Target-Authorization)target. Platform-executed types (in v1: integrity-check) start, poll,remoteCapable field.targetCredentials. It redeems one credential per target the flow uses andexecutedOn (local or the target's name). Platform steps now keep theirTARGET_NOT_FOUND, TARGET_OFFLINE, TARGET_UNREACHABLE, TARGET_REFUSEDTARGET_NOT_VERIFIED (a warning when /validate has no credential for the target)TARGET_CREDENTIAL_MISSING, TARGET_CREDENTIAL_USER_MISMATCHSTEP_TYPE_NOT_REMOTE_CAPABLE, INVALID_TARGET, TARGET_EXISTSCONTROL_REFUSED (502 when a target refuses a cancel or pause)?view=targets) to list, add, edit and delete targets, switch themexecutedOn.iris-target.POST /flows/{id}/dispatch accepts runCredential.refreshToken, the refresh token of aintegrity-check, switch-journal,storage-headroom-check, db-size-report and purge-task-history. Before, onlyintegrity-check was available. The refusal message lists the available types instead of a/schedule creates native tasks through the platform (POST /api/admin/v2/task) with the/dispatch redeems the runCredential before creating the run and refuses a credential that403 RUN_CREDENTIAL_USER_MISMATCH.403 RERUN_NOT_BY_DISPATCHER.IN_PROCESS_NOT_SCHEDULABLE), because a scheduled runpurge-task-history is no longer pausable, since there is no pause for in-process work.purge-audit-records declares daysToKeep (required, integer ≥ 1) for the canvas. Its class%SYS.Task.PurgeAudit; the type is still unavailable.GET /catalog/tasks: the invented fields className and state were removed. Use classstatus / lastError / lastStarted / lastFinished instead. isDestructive andlastRun remain as deprecated aliases of destructive and lastFinished./dispatch with a runCredential of a different user now returns 403 instead of starting a/rerun by anyone other than the run's dispatcher now returns 403./csp/sentai/.cancelled, not completed. failed outranks cancelled, whichcompleted./dispatch validates the flow with the freshly redeemed access token. Redeeming the runCATEGORY_NOT_FOUND.iris-main.log boot loop.running runs left on the dev instance by earlier suites werecustom step's customClass is never read on any execution path, which a testXecute.SENTAIWEB database (resource %DB_SENTAIWEB,IRISAPP_CODE and IRISAPP_DATA keep no public access, and the file server/opt/sentai-web and sends nosniff and X-Frame-Options headers.https:// with peer verification (TLS configuration SentaiTargets). Plainhttp is accepted only for loopback targets or when ^sentai("config","allowInsecureTargets")IRISTEMP (never journaled, lost on restart) and are erased wheniris.script creates:
SENTAIWEB database, its resource, and the mapping of the sentai.web package to itSentaiWebPage roleSentaiTargets TLS client configurationdocker-compose.yml adds the iris-target service (demo only) and sets the runtimeworking_dir.The full list is in docs/limitations.md. The most relevant:
runCredential (for example plain curl) is limited by the 60 s access%Admin_Manage:USE and read access on IRISSYS, because%Admin_Operate:USE.integrity-check can run on a target. Declared in-process types are refused withSTEP_TYPE_NOT_REMOTE_CAPABLE.ERROR #7802 at severity 2, which puts thedo $SYSTEM.Monitor.Clear() in %SYS.compact-globals, defragment-globals, purge-audit-records and legacy custom remain%UnitTest suite grew from 115 to 269 methods. It runs against a test double ofHenrique Dias, Henry Hamon, José R. Pereira Jr.
IRIS Ops Studio 1.3.1 — bounded one-hour guard session and jury route
The optional HTTPS managed guard now has a fixed maximum one-hour navigation session. Bounded native access can renew read-only while a tab is visible and idle; it cannot extend the family deadline or repeat a write. Per-workflow write approval remains limited to 60 seconds and exact-target previews to 30 seconds. Guard navigation shows only its supported Wallet, Web apps, Access control and local Session journal views. The full direct SysAdmin console remains a separate installation and URL.
The README and docs/JURY-EVALUATION.md distinguish three evaluation routes: labeled Safe demo, full direct console, and optional managed guard. The GitHub v1.3.1 release includes the separate review ZIP, judge guide and SHA-256 748A1B361198AA6AEA850E6AA32CB538724C9A47C21C25D0364E662571B655DE. Historical v1.3.0 remains available.
Verification and limits: 270 JavaScript tests and 12 syntax checks pass; the exact ZIP passed independent extraction and verification. Eighteen native renewal checks ran on disposable IRIS Community 2026.2. One real browser session reached the one-hour boundary on the preceding local bundle; the exact new ZIP was not reinstalled for another live-IRIS pass, and the separate scripted long-duration test remains unrun. The optional guard reports productionReady: false. This is a bounded technical review package, not an automatic IPM upgrade, whole-console guard or general production-readiness claim.
Video guides: The three earlier videos describe previous console workflows. Two new illustrated 1.3.1 guides use synthetic narration and are not live test footage: Install and Evaluate the Contest Entry and How the Bounded Server Guard Verifies a Change. The written judge guide and validation record remain the technical evidence.
2026-09-27 —
Verified IRIS 2026.2 reactor
This release makes the contest workflow reproducible and live-tested on IRIS 2026.2. The only supported change is DEPLOY_WEB_APP for /anvil-demo, with the declared USER namespace, Anvil.REST dispatch class, and enabled state.
Added
Fixed
Hardened
Verified
The live smoke path passed on IRIS Community 2026.2 (Build 221U): it rejected an out-of-scope proposal, confirmed a planned proposal was unverified, performed the official SysAdmin PUT and GET, sealed an independently checked receipt, replayed it without changing the receipt, and read process and task inventories.
Upgrade notes and limits
Pull the 2026.2 image and recreate the demo container before bootstrapping. The generated AnvilDemo account has %All and belongs only in the dedicated local demo container. Ports now bind to localhost by default.
The only mutation remains /anvil-demo. Process and task features are read-only; optional Sling/Oak mirroring is outside the mutation trust boundary.

Optional IRIS-native managed guard with four bounded workflows, server READ_ONLY,
per-workflow approvals, native authorization/readback and persistent recovery
without repeating uncertain changes. Guided review installer and final audit
fixes for stop retry, startup failures, key-cleanup reporting and profile docs.
Validated on a fresh IRIS Community 2026.2 instance; 269 JavaScript and 20 Linux
log-reader tests pass. Separate managed bundle; not an automatic IPM upgrade,
general active-user editor or production-readiness claim. See the release and
final remediation report for exact artifact hashes and limits.
We are excited to announce the first release of IRIS Portico, a web-based management portal and admin console for InterSystems IRIS.
Please refer to the README and Documentation for detailed installation and usage instructions.
This is the initial release. Feedback and contributions are welcome!
Initial public release of Armada Battery, an evidence-driven operations console for InterSystems IRIS.
Includes a Docker Compose setup with IRIS Community Edition, read-only instance observations, four bounded administrative workflows, and auditable outcome receipts.
Changes are disabled by default. Workflow tests use synthetic fixtures; live verification covers read-only observations and blocked preflight. Installation instructions and current limitations are documented in the README.


Release 1.0.1
The live demo at https://ocupilot.org runs this release.

ValhallISC mounts InterSystems IRIS servers as local folders. Namespaces show up as folders, packages as subfolders, and classes and routines as .xml files. Copying a file out gives its XML export; copying an .xml file in imports and compiles it. You manage profiles from a tray / menu-bar app, or from the command line (valhallisc --help).


