4.2.0

4.2.0 adds WebSocket and Kubernetes / Docker monitoring, splits the SLA into availability and performance, and puts a status timeline on every application. Two changes need a decision before you upgrade: licence usage now counts WebSocket and workload monitors, and the discovery agent’s process I/O metrics changed unit.

Before you upgrade

1. Licence usage now counts WebSocket and workload monitors

From 4.2.0 each WebSocket monitor and each workload monitor costs 1 point, like a URL or TCP monitor.

  • A workload monitor exists once per probe: a workload watched from two probes costs 2 points.
  • The container host itself stays free, like SNMP and WMI devices: only the workloads under it count.

Count your WebSocket and workload monitors before upgrading and compare them with the points you have left (Monitors page, licence tile). Ask for a licence extension first if you need one.

2. Discovery agent process I/O metrics are now throughput (KB/s)

iostatRead and iostatWrite now measure per-process I/O throughput in KB/s. They used to report a per-operation value that was labelled as latency but was not one. Thresholds set on these two metrics compare against a different quantity after the upgrade: review them, or they will grade wrongly.

3. Upgrade order

The webserver calls endpoints that only 4.2.0 probes have (workload monitors, WebSocket monitors, OID verification). Upgrade from the edge inward:

  1. Integrators
  2. Monitor probes
  3. Discovery agents
  4. Webserver
  5. webserver-front, right after its webserver

A 4.2.0 webserver in front of older probes shows the new monitor types but cannot create them on those probes.

4. Set your own internal component secret

_sharedInternal is the password of adminMNS, the machine account the components use to drive each other. Earlier packages shipped one value to every customer, so an install that kept it has an administrator login anyone with a package knows.

  • A new webserver with an empty _sharedInternal generates a random one on first start and saves it in webserver.json. The 4.2.0 packages ship it empty.
  • Every component logs a SECURITY warning at start while it still uses a value that shipped in a package.
  • Changing the value now takes effect everywhere on restart, the webserver included: the old secret stops working.
  • There is no built-in default any more. A probe, integrator or discovery agent whose config has no _sharedInternal used to fall back to a built-in value, or kept an adminMNS account from an earlier config. In 4.2.0 it removes adminMNS at start. Monitoring carries on with the tokens already issued, but Resync tokens, Enable and Push Settings fail with rejected the internal login (HTTP 401) until the value is set.

Before or during the upgrade: put a new random value (for example openssl rand -hex 32) in webserver.json, or empty it to let the webserver generate one, then copy the same value into every monitor.json, integrator.json and discovery_agent.json and restart. See Hardening.

5. Alert emails have a new subject

Alert subjects now lead with the status and the key fact, for example [MAJOR] web-shop · Execution time: 580 ms · probe-paris or [RESOLVED] web-shop is back to OK · probe-paris. Mail rules that match the old Mugnsoft - … status is … subject must be updated. Teams alerts are now Adaptive Cards: existing incoming-webhook URLs keep working, and Power Automate Workflows webhooks (Microsoft’s replacement for Office 365 connectors) are supported.

New

  • WebSocket monitor — opens a session, sends your messages, validates the replies and grades connect, latency and session timing, with certificate expiry and identity checks like the URL monitor. See Monitor types.
  • Container monitoring (Kubernetes & Docker) — a container host device discovers workloads from the Kubernetes apiserver or the Docker Engine API; adopt the ones to watch and each becomes a workload monitor (replicas, restarts, OOM kills, CrashLoopBackOff). Drift is reconciled: new workloads are proposed, vanished ones are kept and disabled. See Container monitoring.
  • Probe inside Kubernetes — a Helm chart and a slim probe image to run a probe in the cluster it monitors. See Install a probe on Kubernetes.
  • Pattern groups (URL & API) — several independent groups of content checks per monitor, the worst group decides the status. See Monitor types.
  • UDP monitor modes — reachability only or request / response, so a UDP status and response time only claim what the protocol can prove.
  • SLA availability and performance — an SLA is now a target plus an impact condition, tracked separately for availability and, optionally, performance. See SLA: availability and performance.
  • Application timelines — status timelines in the application table, the application report and under each application’s status chip in the 3D view. See Reading the application report and Dependency views.
  • Events: service-level root cause — the incident strip on /events names the service, not only the host. See Events page.
  • Testing a monitor — run a URL or API monitor live from its probe before saving, with a step-by-step result panel. See Testing a monitor.
  • Clearer alert notifications - every channel (email, Slack, Teams, PagerDuty) now shows the same facts: status and for how long, target, probe and location, check time, and the message. Emails are colour-coded by severity, carry a plain-text part and no longer list the logo as an attachment; Slack notifications preview the headline; PagerDuty incidents get a one-line title with the facts as details.
  • Better monitor reports - a summary strip (share of OK checks, non-OK checks by severity, response time mean / p95 / min / max), response bars coloured by status, jitter and packet-loss panels on ping reports, and one panel per numeric pattern group on URL, API and DB reports.
  • The UI in French and Spanish - each user picks a language in their profile; toasts, dialogs, tables and tooltips follow it.
  • SMTP “Verify certificate” — a switch in the SMTP settings, honoured by the webserver, probes, integrators and discovery agents. Off by default: mail servers with self-signed certificates keep working.

Fixed

  • The events page could mark the whole estate not reporting when one integrator output was slow.
  • Timelines showed spurious unknown bars.
  • The discovery agent’s /docs page showed the webserver API instead of its own.
  • Pre-release audit fixes across all components, notably alerting, log and folder monitoring.
  • UDP reports were never sent: the report file was never generated.
  • Ping reports showed microsecond values labelled as milliseconds.
  • Linux packages now extract with their programs executable (binaries, scripts, the bundled JDK and ffmpeg): no more chmod +x after unzipping.
  • Backups now copy every database of a component, into one folder per run (dbs/backup/<timestamp>/). The webserver used to skip the SNMP/WMI monitor configurations and container hosts, and the discovery agent its log and folder monitoring history. See Backup and Restore.

Security

All components are built with Go 1.27.1 and updated dependencies. At release, govulncheck reports no known vulnerability reachable from any component.

The adminMNS machine account no longer ships with a shared password (see Set your own internal component secret above). The integrator no longer falls back to a built-in password when _sharedInternal is empty, and a component with no secret removes any adminMNS account left by an earlier configuration. The webserver-front never carries the account.

Backup files are now readable by the service account only: they contain the encryption key with the secrets it protects. Backup all requires the admin role.

Translations