Live Change Log

See what we're building, in real-time. Every feature, fix, and improvement shipped across the platform.

17,978
Total Changes
4,641
Features
4,556
Fixes
32
Projects
Filter by project
All Projects17,978AIService112APIService138BillingService133ConversionService85DaemonService107DocsService189ESigService78EmailService385InitializerService301KBService74KlusterServices547MCPGatewayService43MediaService462RAGService61SecurityService1,527TranslateService45VOIPService173VectorService8kamo-analytics6,157kamo-apps18kamo-asterisk-support19kamo-capcha17kamo-capcha-widget4kamo-internal4,596kamo-login319kamo-marketing588kamo-meet90kamo-nowww18kamo-register206kamo-shared-library1,326kamo-signer-monorepo50kamolos102
Filter by type
All TypesBuild24CI523Chore670Docs230Feature4,641Fix4,556Other6,781Performance136Refactor274Revert23Style48Test71Upgrade1
September 4, 2026
FeatureSecurityService

Serve each org the callback URL on its own domain

This endpoint is where a member finds the string they paste into Google's console, so it is the endpoint that was wrong: it returned only the redirect the org h...

Kamo·1w ago
FeatureVOIPService

Fall back to the org's own hostname for the Teams redirect

A redirect the org typed into its own registration still wins outright — Microsoft requires the URI replayed on the token exchange to match the authorization by...

Kamo·1w ago
FeatureMediaService

Send an org's own hostname as the meeting OAuth redirect

The same rule the mailbox flow now follows, for Zoom and Teams meetings: an organization on its OWN app registered that app against api.<its own domain>, so tha...

Kamo·1w ago
FeatureEmailService

Send an org's own hostname as the mailbox OAuth redirect

An organization that brought its own Google or Entra app registered that app in its own account, under its own brand, and is now told on its settings screen to ...

Kamo·1w ago
Featurekamo-shared-library

Address an org's OAuth callbacks to its own domain

An OAuth redirect URI is held by a third party. A member pastes it into Google's or Microsoft's console, and from then on the value the service sends on the aut...

Kamo·1w ago
FeatureSecurityService

User-account details belong to their owner, or to an operator

One rule, in one place, for the three endpoints that write a USER account: the profile's member update, the profile's personal address, and the platform Users t...

Kamo·1w ago
Featurekamo-shared-library

A detection rule an org cannot switch off, and the letter it sends

PROGRESSIVE_LOGIN_LOCKOUT joins DetectionRuleType. Every other value on that enum describes something a tenant opts into; this one describes a control SecurityS...

Kamo·1w ago
Featurekamo-internal

An operator may set a personal address, and ask about the right account

Two changes to the member profile, both about the same confusion: which person a question is being asked about. The personal email card is no longer self-only....

Kamo·1w ago
FeatureSecurityService

Let a god operator and the System User set somebody's address

The personal address was self-only. It is also the address an administrator has to be able to correct — a member who has lost the mailbox on their account canno...

Kamo·1w ago
FeatureKlusterServices

Budget the last four services to gain a second replica

BillingService, EmailService, KamoLOS and SecurityService now run two pods, each having put its shared-effect scheduled sweeps behind a distributed lease first....

Kamo·1w ago
FeatureSecurityService

Lock the shared sweeps, and run two pods

Sixteen of SecurityService's seventeen scheduled sweeps have a shared effect and now take a named distributed lease before running. There is no ShedLock anywher...

Kamo·1w ago
Featurekamolos

Lock every cron job that moves money, and run two pods

KamoLOS ran one pod and its ten cron jobs were correct only because of it. There is no ShedLock anywhere on this platform, so a second replica would have run ea...

Kamo·1w ago
FeatureEmailService

Lock the shared sweeps, and run two pods

Nine of EmailService's ten scheduled sweeps have a shared effect and now take a named lease before running. The most consequential is CampaignDispatcher: at two...

Kamo·1w ago
FeatureBillingService

Lock every money-moving sweep, and run two pods

BillingService ran one pod and its seven scheduled sweeps were correct only because of it. There is no ShedLock anywhere on this platform, so a second replica w...

Kamo·1w ago
FeatureKlusterServices

Budget the six services that just gained a second replica

AIService, KBService, ESigService, VOIPService, DocsService and TranslateService now run two pods, so a drain of either node must evict them one at a time rathe...

Kamo·1w ago
FeatureTranslateService

Run two pods

The one @Scheduled method here, **************** populates a map held in this pod's own memory. It is supposed to run on every pod, there is nothing shared for ...

Kamo·1w ago
FeatureDocsService

Lock the shared sweeps, and run two pods

Every @Scheduled sweep here whose effect is shared now takes a named distributed lease through SingletonTaskRunner before it does anything, so it runs once acro...

Kamo·1w ago
FeatureVOIPService

Lock the shared sweeps, and run two pods

Every @Scheduled sweep here whose effect is shared now takes a named distributed lease through SingletonTaskRunner before it does anything, so it runs once acro...

Kamo·1w ago
FeatureKBService

Lock the shared sweeps, and run two pods

Every @Scheduled sweep here whose effect is shared now takes a named distributed lease through SingletonTaskRunner before it does anything, so it runs once acro...

Kamo·1w ago
FeatureESigService

Lock the shared sweeps, and run two pods

Every @Scheduled sweep here whose effect is shared now takes a named distributed lease through SingletonTaskRunner before it does anything, so it runs once acro...

Kamo·1w ago
FeatureAIService

Lock the shared sweeps, and run two pods

Every @Scheduled sweep here whose effect is shared now takes a named distributed lease through SingletonTaskRunner before it does anything, so it runs once acro...

Kamo·1w ago
Featurekamo-internal

coder sessions beside the running shells, and a scrollbar that reaches both ends

## Terminals is now two views of one machine Sub-tabs rather than two top-level tabs, because they are not two destinations: a terminal is a shell that may be ...

Kamo·1w ago
FeatureSecurityService

List a member's coder sessions, and open one in a terminal

Two endpoints beside the terminal ones, and they follow the same rule those do: the Linux account is resolved from the CALLER'S OWN SESSION and no account name ...

Kamo·1w ago
FeatureKlusterServices

Measure whether a deploy actually costs anyone a request

Every fix in this programme is a claim about what happens during a rollout. Until now those claims were untested: MediaService shipped with strategy Recreate at...

Kamo·1w ago
FeatureKlusterServices

coder sessions on the dev machine, listed and resumable

is here, because the machine is the only thing that knows any of it. ## The session index home, exactly as their terminals are whatever tmux is running. No ta...

Kamo·1w ago
FeatureKlusterServices

Budget every drain, and fail a deploy that regresses rollout safety

PodDisruptionBudgets for the 25 Deployments that now genuinely run two replicas. minAvailable: 1 lets a drain evict one pod and wait for its replacement instead...

Kamo·1w ago
FeatureRAGService

Share the indexing consumers, and run two pods

RAGService binds two JetStream durables of its own — rag-note-consumer and rag-kb-consumer — and a durable push consumer with no deliver group admits exactly ON...

Kamo·1w ago
FeatureVectorService

Run two pods

replicas 1 -> 2. This service runs no @Scheduled work and binds no exclusive NATS durable, so a second pod duplicates nothing — it is stateless request serving,...

Kamo·1w ago
FeatureConversionService

Run two pods

replicas 1 -> 2. This service runs no @Scheduled work and binds no exclusive NATS durable, so a second pod duplicates nothing — it is stateless request serving,...

Kamo·1w ago
FeatureAPIService

Run two pods

replicas 1 -> 2. This service runs no @Scheduled work and binds no exclusive NATS durable, so a second pod duplicates nothing — it is stateless request serving,...

Kamo·1w ago
Featurekamo-internal

Answer a readiness probe, and run two pods

This deployment had no readiness probe, so a pod counted as Ready the instant its container process started. With maxUnavailable 0 Kubernetes reads that as "the...

Kamo·1w ago
Featurekamo-meet

Answer a readiness probe, and run two pods

This deployment had no readiness probe, so a pod counted as Ready the instant its container process started. With maxUnavailable 0 Kubernetes reads that as "the...

Kamo·1w ago
Featurekamo-marketing

Drain on SIGTERM, and run two pods

Next handles SIGTERM with a bare process.exit(143), so every deploy severed whatever this pod had in flight — a form post, a server action, a streamed RSC paylo...

Kamo·1w ago
Featurekamo-capcha

Run two pods

replicas 1 -> 2. Server-side state lives in Redis, not in the pod, and there is no scheduled work to duplicate, so a second replica changes nothing except that ...

Kamo·1w ago
Featurekamo-register

Drain on SIGTERM, answer a readiness probe, and run two pods

Next handles SIGTERM with a bare process.exit(143), so every deploy severed whatever this pod had in flight — a form post, a server action, a streamed RSC paylo...

Kamo·1w ago
Featurekamo-login

Drain on SIGTERM, answer a readiness probe, and run two pods

Next handles SIGTERM with a bare process.exit(143), so every deploy severed whatever this pod had in flight — a form post, a server action, a streamed RSC paylo...

Kamo·1w ago
Featurekamo-nowww

Drain on SIGTERM, and answer a readiness probe

Next handles SIGTERM with a bare process.exit(143), so every deploy severed whatever this pod had in flight — a form post, a server action, a streamed RSC paylo...

Kamo·1w ago
Featurekamo-shared-library

A distributed lock, so a scheduled sweep can survive a second replica

There is no ShedLock anywhere on this platform and there never has been. All 97 @Scheduled sweeps across 18 services are correct only because each service runs ...

Kamo·1w ago
Featurekamo-register

Paint every logo on the sign-up site in the org's overlay colour

The org chooses "Register Site Logo Overlay" in kamo-internal beside the home page and loading screen overlays. One setting for the whole site: every step of th...

Kamo·1w ago
Featurekamo-login

Paint every logo on the sign-in site in the org's overlay colour

The org chooses "Login Site Logo Overlay" in kamo-internal beside the home page and loading screen overlays. One setting for the whole site: the sign-in form, t...

Kamo·1w ago
Featurekamo-internal

Choose a logo overlay for the sign-in and sign-up sites

A fourth and fifth surface beside the home page, loading screen and KamoMeets overlays, sharing their thirteen-token vocabulary and their live swatches. Both a...

Kamo·1w ago
FeatureMediaService

Make MediaService correct on more than one pod, and run two

MediaService has only ever run a single replica, so a deploy of it was a total chat outage and an OOM was the same. It could not run two, for reasons that were ...

Kamo·1w ago
FeatureSecurityService

Bake the sign-in and sign-up logo overlays into config.json

kamo-login and kamo-register run on their own hosts with no OrgContext, so this file is the only route their branding takes - the same one KamoMeet already uses...

Kamo·1w ago
Featurekamo-shared-library

A logo overlay for the sign-in and sign-up sites

Two more columns in the vocabulary home_logo_overlay already established: a token, not a hex, so an org that rebrands keeps an overlay matching its new colours....

Kamo·1w ago
Featurekamo-login

Answer the link in an address-change letter

/verify-email-change spends the token in a change-of-address letter and says what happened. It lives here rather than in the workspace because the letter goes t...

Kamo·1w ago
Featurekamo-internal

Change your own address, and a platform tab for every account

Two surfaces, joined by one distinction the platform has never explained to anybody: a user account is the PERSON, and a member is one organization's relationsh...

Kamo·1w ago
Featurekamo-shared-library

Add a queue-group subscribe, so work is shared rather than pinned to one pod

Companion to subscribeEphemeral. Two different jobs, two different consumers: subscribeEphemeral every pod must see every message (anything ending in a STO...

Kamo·1w ago
Featurekamo-shared-library

Add an ephemeral subscribe, so more than one pod can serve a conversation

A durable push consumer admits exactly ONE subscriber. The second pod to bind the same name is refused with [SUB-90012] Consumer is already bound to a subscript...

Kamo·1w ago
Featurekamo-internal

"What happened?" fills the window, so maximizing enlarges it

Every other field on the report form is sized by its content. The description is the one somebody is actually writing in, so it now takes whatever height is lef...

Kamo·1w ago
FeatureSecurityService

Change a personal address by proving it, and administer accounts

Two surfaces on the USER account, which until now had no server of its own — the account's fields were reachable only through MemberController, an endpoint scop...

Kamo·1w ago

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing