Repository navigation
Conversation
blaipr
force-pushed
the
feat/modernise-the-ui
branch
from
September 29, 2026 20:43
7fa8d47 to
3b4ad07
Compare
Collaborator
|
I will discuss this one with the Team. While I like a lot of what is done here, there are some things that will need to be debated, such as changing Jobs to Runs, etc... as that's a terminology change for existing users. |
Contributor
Author
|
Sure! I understand there are too many changes @cigamit. Let me know if you want something changed/reverted. I started by fixing UI bugs, added the buttons that a user asked for, added some other new buttons that I was missing myself and saw opportunities here and there and didn't feel like making 100 little PRs. Thanks for your patience 😄 |
A rework of the web UI on top of main, with the small set of API changes the screens needed. The full list is in the pull request. - Breaking: RADIUS and TACACS+ authentication are removed. Jobs is Runs at /runs and data retention is Cleanup Jobs at /cleanup_jobs; every old address redirects to its new one. - A rebuilt navigation rail, one toolbar and one vocabulary on every list and tab: Add and Delete create and destroy, Associate and Disassociate link and unlink, and every Runs tab runs what it belongs to. - A Run button and launch wizard for every kind of run, toolbar Sync that follows permissions and search, Cancel and Delete that follow the api, and job output that shows every event from line one. - Schedules added from the schedules screen, with template prompts as wizard steps; Cleanup Jobs, Roles and Settings as screens of their own; instances, instance groups, notifications, access and tokens gated on what the api allows. - Lists that read what is there now, search by any part of a name, deliver every live update and keep their ticks to what is on screen; forms that save what they hold; Title Case labels, and fixes across all four themes. - API: a cancel user capability on runs and can_cancel_workflow on approvals, UI defaults in /api/v2/config/ for every user, type__in matching each listed type, a 400 rather than a 500 for an unusable role_level filter, and an approvals list at a fixed number of queries. - Relabelled text keeps its translations; new text is not translated yet.
blaipr
force-pushed
the
feat/modernise-the-ui
branch
from
October 4, 2026 21:37
3b4ad07 to
c5bdaee
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A modernised UI, in line with the API
Everything this change adds over
main, by the part of the product it touches.After you validate this PR, v25.7.0 can be released.
Scope
This is mostly interface work on top of
main, with a small set of API changes the interface needed.It is one commit over 1,101 files. The regenerated message catalogues account for most of the volume: outside
ui/src/localesthe change is 1,083 files, adding 48,657 lines and removing 12,973. The backend part is 34 files,adding 1,772 lines and removing 582, and is the part that most needs a reviewer who knows the API.
Breaking changes
Two changes affect installations or integrations rather than only the screens.
served them. Old RADIUS and TACACS+ settings addresses in the UI land on Authentication.
/runs), and the data retention screen is Cleanup Jobs(
/cleanup_jobs). Every old address,/jobs,/data_retentionand/management_jobsincluded, redirects to itsnew one with whatever followed it, so saved links still land.
Navigation and layout
The rail down the left is the frame everything else sits in, and it was rebuilt first.
own tabs is open.
under one rail item instead of four. Users who are not administrators, who cannot open Instances or Topology, get
Instance Groups in the rail with Container Groups as its tab, and no tab that leads to a screen they cannot open.
where a row starts rather than eight pixels lower.
highlighted Back tab. Every object screen has a Not Found page, notification templates, execution environments,
credential types, applications and roles included.
Buttons and tabs
Every list and tab uses the same toolbar, with words that say what a click does.
Access, a user's and a team's Roles, a user's Organizations and Teams, a host's Groups, an instance group's
Instances, an instance's Peers and Instance Groups. The dialogs, errors and empty messages use the same words.
held both.
lets use them: an organization's Teams and Execution Environments, every Notifications tab, an application's
Tokens, and Delete with tick boxes on the Roles and Access tabs.
execution environments and notification templates. A token added from an application returns to the
application.
syncs, a cleanup job runs, and an inventory or host opens a Run menu aimed at it. Screens where nothing can be
run, an instance or an instance group, show no Run button.
and Runs last.
"Associate Role", "Run Job Template").
Lists and search
The lists read what is there now, keep their ticks to what is on screen, and search the way people type.
way back, and each tab reads its own resource rather than the last one cached.
steps back a page when its last page empties.
wizard offers only searches the API accepts.
Type combined with a Status narrows the list rather than widening it.
Runs
The runs list gained a way to start anything, and the launch wizard was rebuilt around what a run is aimed at.
Sync and Cleanup Job, in that order wherever they are listed, the type search included.
template: whole inventories where it prompts for one, the hosts and groups of its own inventory where it prompts
for a limit, and nothing at all where it prompts for neither, in which case there is no step.
number of days of records ask for it once between them. Runs the API refuses are named, with the API's reason,
after the others start, and a run aimed at several inventories starts on every one it can.
and Delete once it can be deleted. A run in the new state offers both. Relaunch is not offered where it cannot
work, such as on a cleanup job.
schedule, so a node limited to some hosts no longer runs against its whole inventory.
Job output
The output of a run shows all of it, from its first line.
large run are always there.
and downloaded.
Templates
The templates screen holds two kinds of thing, and says which is which without repeating itself.
whose sort put the rows back where it found them.
reader to add a template: what the search matched, the limit a run aimed at hosts needs, or the inventory a
template has to be able to reach.
the UI, cleanup job nodes are marked C, and an approval node shows its timeout action, required approvals and
context.
Hosts and groups
The four host lists and the three group lists all start runs the same way.
group or host a tab belongs to rather than the whole inventory, and the tooltip says which.
inventory is offered.
Inventories and projects
Both lists sync from the toolbar rather than one row at a time.
the user may sync, follows the list's search across every page, starts five syncs at a time rather than all at
once, and says what it skipped and why.
Schedules
The schedules screen lists every schedule there is, and now makes them too.
add one before.
cleanup jobs a schedule can hang on.
what it will run with, where a Prompt button opened a second wizard.
from 0 to 99,999.
Cleanup jobs
Cleanup jobs are a screen of their own, named the way the runs list names them.
/cleanup_jobs, with tick boxes and a Run button, so several run at once with onequestion about days between them.
delete all history.
Instances and instance groups
The screens for the machinery that runs jobs follow what the API allows.
says why it is off.
defaultandcontrolplanegroup forms lock the name and policy percentage the API refuses to change.themselves throughout.
Notifications
Notification templates are one thing with one name, and every screen names their types alike.
rather than saving untouched messages as blank.
Access, users and tokens
The access screens offer only what the API will do.
organization or team concerned.
Add, and a token opened from an application returns there.
only once nothing carries it; deleting one still in use is refused with a message saying why.
Roles
Roles became something that can be read rather than a table to scroll.
Settings
Settings became screens rather than one list of links.
Disable Local Authentication included, from the Session tab.
admin changed on another tab.
?tab=links stillland on their tab.
administrators could read before.
Authentication
The authentication settings were split up, and two providers were removed.
tab of their own.
Forms and details
Forms save what they hold and check what they declare, and details say what they mean.
project, application or user can no longer be saved without its organization.
the same link buttons on every form.
Themes
All four themes were touched, and the rules that differed between them were brought together.
text under it in the light themes, and the search extension painted every other copy of the selected text a
solid green over the text rather than behind it.
hover alike.
darkening under the pointer.
API
The backend changes are small, and each one serves the interface.
canceluser capability, computed as the cancel endpoints decide, and workflow approvals reportcan_cancel_workflow. On the runs and approvals lists these are answered once per page, not once per row.DELETE /api/v2/labels/<id>/, by a superuser or an admin of the label'sorganization, and only while nothing carries the label: a label in use answers 409. Labels report
editanddeleteuser capabilities./api/v2/config/carries the default UI theme, language and editor size for every signed-in user.type__inon unified jobs and templates matches each type it lists, where it matched nothing.role_levelfilter a model cannot take answers 400 rather than 500.the same permission answers as before. A test holds the batched answers to the per row ones for every kind of
user and approval.
AWXModelBackendname only restores sessions made before the rename, instead of checking every failedpassword a second time.
Translations
Relabelled text keeps its translations, but new text is not translated yet.
wherever only the case, spacing or end mark changed.
mainhas about 25.Until they are translated, those parts show in English in every language.
Under the hood
The work that does not show, but that the rest of it stands on.
the lint.
Verification
Every job the CI workflow runs was run locally on this commit, on top of the current
main.main.What is not here
One thing was deliberately left, and is worth knowing before picking the work up again.
websocket and the virtualiser together. It was verified against a running installation instead.