- Add Default and Secure Docker runtime profiles with gVisor isolation, hardened container defaults, compatibility preflight, guided installation, and persistent setup progress
- Introduce Gateway-managed Docker volumes, preserve compatible legacy mounts, provide safe migration actions, and prevent destructive volume conflicts
- Improve Docker container, deployment, node, runtime, GPU, responsive layout, action priority, and navigation attention states
- Add independent Gateway and Relay update controls with compatibility gating, explicit restart warnings, and persisted server-side update state
- Recover Secure Links after workload restarts
- Add folder- and resource-scoped RBAC while preserving nested resource placement
- Add protected user impersonation with explicit administrative boundaries
- Complete AI Workspace scenarios, skills, connector setup, runtime recovery, and configured external-research guidance
- Add multi-node domain routing through selected Nginx ingress nodes and stabilize DNS, TLS, integration, and database workflows
- Make global search use cached resource snapshots instead of synchronous daemon requests and keep Ask AI available with a guided setup fallback
- Harden release upgrades, legacy compatibility, managed-resource migrations, and update-state handling