Ai-OPs
ai-ops.com
Docs
/
Release Notes
/

Version 1.2

Koios 1.2

ReleaseDateWhat changed
v1.2.5October 1, 2026Device faults kept to one tag, model bindings and history, model import, OPC-UA, Generic CIP, clean shutdown and tag lists
v1.2.4September 28, 2026Startup settings, model input and output checks, license uploads, log access, bulk updates and EtherNet/IP timeouts
v1.2.3September 21, 2026Network diagnostic tools and the navigation scrollbar
v1.2.2September 20, 2026Component stacks, the installer and the pre-upgrade backup
v1.2.1September 19, 2026Installation guide, prediction history, device faults, logs and the canvas
v1.2.0September 16, 2026The feature release, below

Koios 1.2 changes how you build and run components: one workspace, folders for environments, and isolated package stacks so a component can use a library version Koios does not ship. It also adds an audit log, a certificates page, and models whose inputs are sampled at different rates.

Before you upgrade

No new volumes or service file changes are needed. Each of these changes behavior on first boot:

  1. Models with two input bindings that share a binding order stop. Renumber them through a bindings CSV export and import. See Model Configuration Errors.
  2. Renamed built-in roles do not get the new permissions. Grant the stack, audit log and certificate permissions by hand. See Roles & Permissions.
  3. Modbus TCP devices read up to 125 registers at once, where a hidden cap held them to 50. Lower Max Registers Per Read if a device rejects large reads. See Device Parameters.
  4. Logic that reads an OPC-UA tag's error code sees 107 for bad data and 105 for an empty value, where it saw 106. See Creating an OPC-UA Tag.
  5. The component environment list page and its bulk actions are gone. Manage environments from the workspace. See Component Environments.
  6. Integrations that write or group events, or pass removed filter fields, need updating. See For integrators.
  7. Rotate any device password that was in use while Debug logging was on in an earlier version.
  8. The built-in certificate is new, so browsers ask once more. In the Admin Console, sign in to each instance again from its connection settings. See Managing Instances.

Step-by-step instructions: Upgrading to v1.2.0.

Components run in their own package stacks

A stack is a named set of Python packages built from wheels you upload. Attach an environment to one and its components run against exactly those library versions, whatever Koios itself ships. Each stack in use runs in its own process, so a faulty component stops only the environments in that process, and the process restarts on its own. Every build is checked before any component uses it: a stack that would break the component runtime is marked Incompatible, and the previous build keeps running. Backups leave built stacks out and rebuild them on restore.

Each stack in use holds a worker process, so share stacks between environments. See Component Stacks.

Components are built in one workspace

Environments open in one three-pane workspace: the environment rail, the canvas, and the Library and Inspector beside it, with a log pane under the canvas. Environments file into folders up to five levels deep. Saving a running environment lists exactly what changed and applies it within one scan cycle, so component timers and buffers are kept.

See Component Environments and The Canvas.

A model can take inputs sampled at different rates

A model file can declare a structured input space: named inputs, each with its own window length, sample rate and interpolation. A flow sampled every second and a temperature sampled every hour can feed the same model. Uploading a model file offers a Shape step with a visual builder, and each binding carries its own rate and window. In this release, structured models cannot use Memory Only history, and every input is resampled with PCHIP.

See Managing Model Files and Assigning Bindings.

Every accountable action is recorded

The new Audit Log under System is a read-only, append-only record of who did what: sign-ins, user, role and permission changes, licensing, backup and restore, certificate actions and configuration changes, each with a before-and-after comparison. Filter it, search it and export it as CSV or JSON. Records are kept for a year by default and never less than 90 days. The trail starts at the upgrade.

See Audit Log.

Certificates are managed in one place

The new Certificates page under System manages the certificate browsers see, with OPC-UA client certificates on a second tab. Upload your own CA-signed certificate and key; Koios checks the pair before installing it and keeps the previous one if anything fails. The built-in certificate is now generated for each install, so browsers that stored an exception will ask once more. An expired certificate falls back to the built-in one at startup, so the sign-in page is always reachable.

See OPC-UA Certificates.

What else changed

Devices and tags

  • Koios reaches serial, GPIO, I2C and SPI hardware on the host without a privileged container. See Environment Variables.
  • Modbus TCP devices have a Max Registers Per Read setting for gateways that reject large reads. See Device Parameters.
  • One unreadable Modbus register no longer fails the rest of its block.
  • An EDS file attaches by drag and drop, including while the device is being created. See Creating an EtherNet/IP Device.
  • An OPC-UA tag reports the server's status on each reading: an uncertain reading keeps flowing with a warning, and a bad one fails with the reason. See Creating an OPC-UA Tag.
  • OPC-UA runs on the first full release of its client library, with no change to how servers connect.

Models

Components

  • A component can ask for a file, such as a trained model or lookup table, uploaded per instance, versioned and revertible. See Building Components.
  • Components can solve linear and mixed-integer optimization problems through pyomo, added as a library dependency or in a stack. See Component Builder SDK.
  • Whole numbers, decimals and true/false values connect in any direction on the canvas and convert on the way in. See The Canvas.
  • The Core Library is now version 1.0.0. Its components are unchanged, and the new version is installed beside yours and left inactive. See Component Libraries.
  • Component processes left over from an unclean restart are stopped before new ones start, and a license problem stops them with the reason recorded.
  • Every list filters, sorts, pages and counts on the server, with filters in the column header. Filters that did nothing now work.
  • A CSV import opens a review grid with every row and only the columns the file changes. See Importing and exporting tags.
  • An empty trend offers to add its first tag.
  • A trend export downloads as it is produced, keeps no copy on the server, and can reach 10 GB. It needs the new trend export permission, granted to every role that manages trends. See Settings & Export.

Accounts and security

  • Roles can grant every permission Koios enforces, including new ones for stacks, the audit log, certificates and trend export. See Roles & Permissions.
  • Downloading an OPC-UA certificate's private key requires the OPC-UA certificate permission.
  • Editing and deleting discovered network hosts require permission. See Network Diagnostics.
  • Editing, enabling or disabling a user raises an event.

System

  • A backup already on the server restores in place from the backup history. See Backup & Restore.
  • Device logs record a repeated message once, so they keep days of history instead of hours.
  • Failed writes, on-demand reads, configuration changes and previously silent failures are logged, and credentials are masked in logs. See Logs.
  • New settings control log rotation, library log levels and database connection pools. See Environment Variables.
  • Pages load faster, and status filtering and event counts are quicker on large systems.
  • An unreachable server shows one banner and recovers without a reload.
  • The public documentation keeps a copy for each release.

Fixes

Devices and tags

  • A change to a device's connection settings takes effect without a restart.
  • Modbus tags sharing a register no longer show stale values.
  • Bit-level Boolean tags on a shared register all read correctly.
  • Coil and Discrete Input tags no longer read backwards.
  • Testing a Modbus tag reports coils, discrete inputs and holding registers correctly.
  • One bad Modbus tag no longer fails every tag on the device.
  • A Modbus TCP device that stops answering is reported as failed.
  • Modbus writes that partly succeed are recorded as written.
  • Duplicating a generic EtherNet/IP tag keeps its addressing.
  • Testing an EtherNet/IP tag that holds text shows the value.
  • An EtherNet/IP device set up as a Logix controller can be changed to Generic CIP.
  • A new generic EtherNet/IP tag starts at byte offset 0.
  • CAREL BOSS integer output tags with value mapping on write convert correctly.
  • An SQL tag whose column disappears fails with a read error instead of freezing.
  • A tag that fails to read no longer passes its last good value off as current.
  • An in-memory tag is read/write however it was created.
  • Secured OPC-UA connections survive the server being re-created.
  • An OPC-UA device with many tags reads again on servers that limit how much one request can ask for.

Components

  • Component package uploads reject oversized manifests.
  • A value set on an unwired component input holds.
  • Environment status stays correct when a stack is switched.
  • Clearing a filter no longer blanks the page.
  • The Users and Trends lists no longer repeat or skip rows across pages.
  • Explorer finds models, device sets and local values again.
  • An expression's entity picker lists tags again when a tag holds a text reading.
  • The Events list no longer resets while you type, and opens newest first.
  • A decimal typed into a whole-number filter is rounded instead of blanking the page.
  • The Tags list's Protocol filter no longer leaves out tags in a device set.
  • A list no longer pushes the page past the bottom of the window.
  • Column headings stay in place as you scroll a list.
  • Box-zoom on a trend works on Windows and Linux: hold Ctrl and drag.
  • Panning a trend back through history keeps what it loads.
  • A pen moved onto a newly added axis stays there.
  • A trend's hover readout lists only pens with data near the cursor.
  • Trend settings show the sampling window the chart actually requested.
  • A tag's sparkline shows its readings in the color of its current status.
  • An export over the size limit is refused by the server as well as the page.

System

  • Per-device and per-model log lines are no longer duplicated.
  • An entity's name no longer disappears from its own log lines.
  • Service health failures say why.
  • Per-scan Modbus and CAREL BOSS log entries moved to Debug.
  • Service logs rotate instead of growing without bound.
  • Clearing a log no longer stops the service writing it.
  • Automatic log cleanup leaves live log files alone.
  • Deleting a device, model, scan group or component instance removes its log files.
  • A configuration problem is no longer reported as a certificate problem.
  • A restore that cannot replace time-series data fails instead of reporting success.
  • The dark theme uses the Koios colors whatever your system is set to.
  • Keyboard shortcuts no longer depend on Caps Lock.
  • The Server Time card no longer reads as clock drift.

Installation

  • Offline install archives load already named.

For integrators

  • Events can no longer be created or edited through the API, and the root-event grouping header is removed. See Events.
  • Filter and sort inputs that never worked are removed: status on model bindings and models, filename on model files, and the Protocols sort.
  • A trend export is one streaming request. The operations that started, polled, listed and downloaded an export are removed.
  • Bulk component create calls report validation failures as a request error.

See API Clients.

Patch releases

v1.2.1

September 19, 2026
  • Models keep the prediction history their configuration calls for.
  • A failing OPC-UA tag no longer reports a more recent time than a working one.
  • A Modbus device that fails for an internal reason no longer reports a network problem.
  • Service logs keep everything the service produces, so expect them to be larger.
  • The alert dot on the browser tab stays lit for license and resource alerts.
  • A component environment stopped by a license problem says so. See Licensing Problems.
  • Delete removes every selected wire on the canvas.
  • A connector moved to another instance survives undo and redo.
  • Panning a system chart back through history keeps what it loads. See System Health.
  • Capturing an instance's live values as its offline defaults shows them straight away.
  • Action: Stack bundles resolve against the packages this version provides. Build bundles with koios-component-builder 1.3.1 or later.
  • Record dropdowns load up to 5,000 records instead of stopping at 200.
  • A setting written through the API with the wrong value type is refused.
  • The installation guide runs start to finish, can fill in your own addresses, and covers installing without internet access. See Installing Without Internet Access.

v1.2.2

September 20, 2026
  • Component stacks build again. A stack that failed on 1.2.0 or 1.2.1 rebuilds the first time you start this version, with nothing to re-import. See Component Stacks.
  • Asking the installer for a specific version installs that version, or stops.
  • The automatic pre-upgrade backup survives a failed upgrade.

v1.2.3

September 21, 2026
  • Ping, Traceroute and DNS Lookup run. See Network Diagnostics.
  • The navigation scrollbar stays out of the way.

v1.2.4

September 28, 2026
  • Action: A model's newest input sample is the tag's latest reading and is range-checked like the rest, so an out-of-bounds reading now stops the model. Raise the binding's debounce count if it should not. See Assigning Bindings.
  • Action: Settings passed at startup now take effect on every installation: log forwarding, and the CSRF, session cookie and HTTPS redirect settings. Review any you set before upgrading. See Environment Variables.
  • A model output that is not a finite number fails that scan and writes nothing for that output, even when clamped. A non-finite input reading blocks the whole prediction. See A Model or Binding Isn't Running.
  • Koios checks a license file before installing it: a file it refuses is not installed, the upload says why, and the current license keeps running. See Licensing Problems.
  • Enabling some tags, devices, models, scan groups, environments or API clients and disabling others in one API request applies each item's own setting. A request that lists an item as both enabled and disabled is refused.
  • When a list's filter matches more than 50,000 rows, selecting all rows selects none rather than the first 50,000, so a bulk action never covers part of a selection. Narrow the filter first.
  • Viewing, downloading and deleting a log file are limited to the logs the Logs page lists and their rotated copies. See Logs.
  • HTML in library documentation is limited to formatting. See Libraries.
  • Engineers, and any role or API client that can manage component libraries, can upload one. See Roles & Permissions.
  • EtherNet/IP devices use their own connection timeout instead of a fixed 5 seconds. A device left at the 3-second default may need it raised on a slow link. See EtherNet/IP.
  • Write Always is offered only on Read/Write device tags. In-memory and expression tags have no device to write to, so it never had an effect on them. See Tags.

v1.2.5

October 1, 2026
  • Action: A binding with an output index or binding order below 1 fails instead of writing another output's value, and imports refuse such values. Correct it with a bindings import. See Assigning Bindings.
  • An OPC-UA value its tag's data type cannot hold, such as 300 for a Byte, fails only that tag, with the reason. Byte and SByte tags accept writes; a tag with no data type is refused. See OPC-UA Tags.
  • One OPC-UA tag no longer stops its whole device: a numeric node ID out of range, a server's "not set" source timestamp, or text in an unexpected encoding now affects only that tag.
  • On EtherNet/IP, BOSS and Modbus devices, a write the device cannot take fails only its tag, and the other outputs, including the rest of a generic assembly, are still sent.
  • A tag whose write is refused shows as failed even when its reading succeeds. See Tag Values.
  • An OPC-UA Boolean written through reverse value mapping gets the pattern's meaning, so Off, false, no or 0 writes false. Text with no true or false meaning fails that tag. See OPC-UA Tags.
  • An OPC-UA tag on Source Timestamp whose device clock runs ahead records each reading when it arrives, with a warning, and a model input stamped in the future fails instead of running. See OPC-UA Tags.
  • Strict Generic CIP devices no longer refuse reads, writes and connection checks. A reply that misses the timeout ends the scan and reconnects instead of being taken as the next assembly's data. See EtherNet/IP.
  • A model-bound tag whose readings are older than the model's history window no longer stops its device. The model skips those readings and the tag shows a warning. See Data Is Stale, Frozen, or Has Gaps.
  • Clamp Output on an output with no scaling holds predictions to the failure bounds the model file declares, not a fixed 0 to 100. Without declared bounds, predictions are written unclamped. See Assigning Bindings.
  • Settings saved together with enabling a model or scan group now take effect, and creating or deleting a model while the license is re-checked no longer stops every model.
  • Models sampled faster than once a second use their actual readings, an input moved to another tag reads only that tag's history, and filling a new model's window from long-term history retries until it succeeds.
  • Models reading an in-memory tag fed by a parameter mapping no longer report stale data while the mapped value holds steady.
  • An input reading NaN or infinity fails a Memory Only model for one scan, and a starting model fills its window once the reading is valid, instead of waiting a whole window. See A Model or Binding Isn't Running.
  • An expression fails when its source device is disabled, instead of sometimes staying Running with its last value.
  • An expression whose result is not a finite number, such as an overflow to infinity, fails instead of staying Running, and runs again on the next finite result, filter functions included. See Expression & Value-Mapping Errors.
  • Components no longer run from a half-unpacked library when the library's own code is damaged or too large, or while another environment is still unpacking it. Such a library fails every time, with the reason. See Component Libraries.
  • Components whose bundled packages are damaged or too large show the reason and do not run, instead of running against the platform's copy of a package or retrying the install every cycle. See Component Libraries.
  • Tags mapped to a device set's active device, priority or status follow failover as it happens, and a tag mapped to License Days Remaining counts down.
  • Audit records now show the address each request came from, failed sign-ins included, and a client cannot set it by sending its own forwarding headers. See Audit Log.
  • Action: Only users and API clients that can manage devices see stored device passwords or export and import device configuration. Give any API client that exports or imports devices permission to manage devices. See Importing & Exporting Devices.
  • A model file whose training details or input space hold lists or objects where text is expected no longer stops the model's pages or the upload dialog from loading. The values show as written. See Managing Model Files.
  • Model import no longer changes a model's active file or moves a binding to another model, and a ZIP import saves models and bindings together or not at all. See Importing & Exporting Models.
  • An unrecognized model file setting falls back to its default with a warning. Unreadable or wrongly structured metadata, such as NaN values, is skipped with a warning instead of breaking the upload or Metadata tab. See Managing Model Files.
  • A Z-Score input set up from a model file's metadata uses the file's mean and standard deviation, instead of reporting them missing when the model runs. See Managing Model Files.
  • Confirming a CSV or ZIP import now accepts only the file the preview step returned, so a crafted request can no longer make the server open a file outside that import. Everyday tag, device and model imports are unaffected.
  • Inside the container, service credentials and raw-packet access are limited to Koios's own service accounts, which can no longer alter the settings and scripts Koios runs with administrator rights or redirect the logs those programs write. See Network.
  • Koios no longer raises a CPU alarm each time it starts or restarts. The alarm now opens only when CPU usage stays over its limit for a full minute. See System Health.
  • Action: Refused API requests no longer write the passwords they carried to the log, and the web application's log masks credentials like the others. If scripts sent passwords, delete that log's files and change those passwords. See Logs.
  • Action: The documented service file now gives Koios 60 seconds to shut down, not 10. Before upgrading, add --stop-timeout 60 -e KOIOS_STOP_TIMEOUT=60 to ExecStart and -t 60 to ExecStop, then reload systemd. See Running Koios as a Service.
  • Koios stops its databases cleanly within Docker's default 10 seconds, and gives any extra time set with KOIOS_STOP_TIMEOUT to its services, such as data collection. See Environment Variables.
  • Log forwarding needs a remote endpoint. Without one, Koios logs one warning at startup instead of filling service logs with send errors and slowing shutdown. See Environment Variables.
  • A backup that needs a newer Koios version than the one running is refused before the restore changes anything, naming both versions, instead of leaving Koios unable to start. See Backup & Restore.
  • The offline installer stops a running Koios cleanly before upgrading it.
  • The database copy saved before an upgrade is no longer replaced by restarts, a rollback or a lost database volume, and v1.1 and v1.0 refuse a database v1.2 has upgraded. See Downgrade to a Previous Version.
  • A new installation stopped early in its first start, while creating its databases, by a power cut or a forced stop, starts normally the next time. The installer no longer restarts a new installation moments after starting it.
  • Running several instances on one host now covers giving each its own address and hostname, sizing the host, and upgrading one instance at a time. See Running Multiple Instances.
  • Action: Check no other program on the host uses port 5432, 6379 or 8086 before upgrading: Koios now stops at startup, naming the port. Its internal services answer only inside Koios, and none contacts its vendor. See Network Configuration.
  • Action: An instance upgraded from v1.0 or v1.1 has a new certificate. If the Admin Console monitors it, sign in to it again from its connection settings there. See Managing Instances.
  • Tag lists that load as you scroll keep your place and load more only when you reach the end. Each tag names its device on its own row instead of under a device heading.