Postgres Enterprise Manager 10.6.0 release notes v10.6

Released: 29 September 2026

New features, enhancements, bug fixes, and security fixes in Postgres Enterprise Manager 10.6.0 include the following:

Highlights

  • Support for RHEL 10 and Debian 13
  • New Job Templates to create reusable job definitions
  • Improved self-monitoring capabilities via the new Probe Diagnostics feature
  • Monitor log errors and autovacuum with new built-in probes and alerts

Enhancements

Description
Introduced Job Templates for agent-agnostic, reusable job definitions that can fan out to multiple targets.

Job Templates let a single job definition run across many agents instead of requiring a separate job per target. Import and export of Job Templates is also supported.

Added the Probe Diagnostics UI for per-probe health and performance investigation.
Introduced end-to-end password-in-transit encryption.

Browser-to-server credentials are now encrypted with RSA-OAEP: the server generates per-session RSA keypairs and the client uses the Web Crypto API, with un-decryptable ciphertext rejected as a bad request. Feature-gated via PEM_ENCRYPT_PASSWORDS_IN_TRANSIT, with an optional PEM_REQUIRE_TRANSIT_ENCRYPTION strict-enforcement mode. Operators can also supply a custom encryption key for the ASB password store, replacing the previously fixed key with an operator-controlled one.

Added threshold-aware autovacuum and autoanalyze overdue alerts.

Both alerts now consider per-table size rather than raw time-since-last-run, so noisy small tables no longer generate false positives while large tables with a genuine backlog surface promptly.

Added the server_log_severity_scan probe for near-real-time PANIC/FATAL/ERROR log alerting.

A format-aware log parser scans server log files continuously, detects and cleanly recovers from log rotation, and stores events in pemdata.server_log_severity_scan. Timestamp comparison is DateStyle-aware so both PostgreSQL and EPAS work correctly.

Added pem_advisor, a standalone CLI tuning tool for the PEM backend database.

The tool connects read-only and analyzes memory, connections, WAL and checkpoints, autovacuum, planner settings, logging, background writer, JIT, and replication settings, producing a tiered terminal report as well as markdown, SQL, and JSON output. It is compatible with PostgreSQL 17 and EPAS, and is installed at /usr/edb/pem/maintenance_tool/bin/pem_advisor.

Added the ability to email scheduled reports over SMTP.

Scheduled reports can now be sent as HTML or JSON file attachments over SMTP, with the report rendered entirely in the database.

Added Kerberos service-ticket authentication mode.

The PEM web tier can now maintain a single shared credential cache from a service keytab and connect to the PEM backend as a service principal, while PostgreSQL maps the SPN to a database role via pg_ident.conf and the DSN carries the end user in the user= field. Three new configuration keys — PEM_KRB_USE_SERVICE_TICKET, PEM_KRB_SERVICE_CACHE_NAME, and PEM_USER_KRB_INCLUDE_REALM — control the behaviour.

Added monitoring support for PostgreSQL 19 and EPAS 19.

The probe and alert template surface has been updated to cover the new server version.

Added support for custom, user-managed encryption keys for Agent Server Binding (ASB) passwords.

Encryption keys can now be supplied via PEM_ENC_FILE or PEM_ENC_SCRIPT, enabling key rotation via a key index embedded in the encrypted payload.

Added a recurring system job to purge data belonging to deleted agents, servers, and Barman tools.

The "Purge deleted objects" job runs every 15 minutes and re-evaluates the deleted_objects_data_retention_time setting on each run, so changing the retention threshold also affects entities already awaiting purge. Children are drained in bounded batches before the parent row is removed, and cleanup covers both the pem catalog schema and the pemdata / pemhistory schemas.

Added support for Debian 13 (Trixie) as a customer runtime platform.

New runtime requirements files ship for debian-13-amd64 and debian-13-arm64.

Bundled HTTPD 2.4.68 with the PEM installer for Windows.
Added support for RHEL 10 on arm64, ppc64le, and s390x platforms.
Enhanced the agent watchdog subsystem for improved process resilience and observability.
Added threshold ordering validation to the Profile PUT API.

The endpoint now rejects mis-ordered thresholds (ascending required for the > operator, descending for <) on both newly added and modified alert configurations, catching mis-configurations at write time instead of at alert dispatch time.

Improved the performance of the Grid View in dialogues.
Duplicate webhook name validation now runs on Add rather than only on Save, so the user is warned earlier in the flow.
Custom probes can now carry a user-specified internal name.

The create dialog adds an "Internal name" field that auto-populates as cp_ plus a slug and is editable during creation (read-only afterwards). The cp_ prefix is mandatory and the remainder must match [a-z0-9_]+.

Users holding the Scheduled Tasks role can now see and manage jobs on their own agents.

System jobs remain admin-only, and schedule exceptions (skip dates) are covered by the same scope.

Added a portable way to check whether IPv6 is enabled.
Added indexes on pem.probe_target_view to improve performance.

New indexes on the agent_id and probe_internal_name columns speed up probe-target lookups.

Security Fixes

Description
Fixed CVE-2026-86861, a symlink time-of-check-to-time-of-use (TOCTOU) vulnerability in the File Manager.

Closed a race window in save_file that could allow a leaf symlink to redirect a save operation to an unintended path.

Fixed CVE-2026-86864, a vulnerability whereby the backup database was not passed via PGDATABASE.
Fixed CVE-2026-86862, a vulnerability whereby the restore/maintenance database was not passed via PGDATABASE.

Changes

DescriptionAddresses
Hardcoded both the agent heartbeat and server heartbeat intervals to 15 seconds for consistency.

This removes the previous mismatch where the two intervals could drift apart under configuration overrides. You can still configure the heartbeat tolerance as in previous versions, but this now affect only the tolerance and not the underlying heartbeat intervals.

Removed the 24-hour cap on scheduled alert blackout duration.

The REST API v17 endpoint now accepts any positive integer number of hours; the legacy endpoint still accepts the "N hour(s)" string form; and the UI field validates a minimum of 1. Operators can now schedule multi-day maintenance windows in a single blackout.

62855
Hardened the Content Security Policy with per-request nonces.

The default policy no longer includes 'unsafe-inline' or 'unsafe-eval'. Every inline script and style across base templates and tool-specific templates (Profiler, Dashboards, Cluster Topology, Reports, REST API docs, Barman) is now tagged with a per-request nonce. style-src retains 'unsafe-inline' to accommodate MUI runtime styles; 'unsafe-eval' is added only in DEBUG builds.

Bug Fixes

DescriptionAddresses
Applied the Object Explorer tag filter to agent nodes.

Tag-based filtering now behaves consistently across all node types. Previously agents were skipped by the filter and remained visible regardless of the selected tags.

Fixed an issue whereby customer-customised system-job schedules, jobenabled flags, and step code could be silently overwritten across reseed events.61176
Fixed an issue whereby an upgrade left a stale pem.jobstep row referencing the dropped function pem.purge_obsolete_data(), causing recurring job failures post-upgrade.
Corrected the display of alert timestamps under non-UTC session settings.
Fixed an issue whereby a changed agent working directory could break subsequent operations because agent_ssl_key and agent_ssl_cert were stored as relative rather than absolute paths.

These values are now converted to absolute paths during agent registration.

Prevented duplicate server_group rows from being created when multiple agents register concurrently against the same server group.
Scoped the PGD raft leader-id alert per node group.

PGD 5 raft subgroups elect leaders independently, so the alert now includes node_group_name in the probe key columns, the data and history tables, the chart, and the alert template.

63967
Fixed a crash in the Performance Diagnostics Query Dashboard that fired when a collected sample had no matching active session.

The wait-events timeline drill-down is also hardened against similar null cases.

Resolved dashboard tab titles on the backend so remotely monitored servers open the correct dashboard tab.

Previously the tab could resolve to the wrong monitored server.

64640
Fixed the Database cleanup upgrade script to use CALL instead of SELECT for stored-procedure invocations, matching the procedure-vs-function change for pem.purge_probe_history.

A subsequent update fixes any already-upgraded systems whose steps were left using SELECT.

65129
Fixed a schedule with only a start date so it runs once at the specified time instead of firing every two minutes.

Empty pattern arrays are no longer implicitly treated as wildcards.

Fixed an issue whereby agents could open two heartbeat connections (and two main-thread connections) instead of one.

The heartbeat thread now waits for the old thread to exit before recreating it, so two threads holding separate connections can no longer coexist.

Fixed an issue whereby agent registration could hang or fail with a lock timeout while the probe target materialized view was refreshing on large fleets.
Fixed an issue whereby the Available Metric tree in Manage Charts (Line Charts) did not populate or allow selection, blocking metric selection for line-chart configurations.
Silenced a benign SAWarning surfaced during EPAS schema reflection in Alembic migrations.

The warning was harmless but polluted upgrade logs.

Fixed an issue whereby empty agent, database, schema, or object name fields in SNMP trap generation produced "value(s) do not match OID(s)" errors at the notification receiver.

An empty field previously collapsed the varbinding; a NULL placeholder is now substituted instead.

Disabled editing of the Alternate Code tab for system probes in the UI.

The backend already silently rejected such edits; the SQL editor is now read-only for system probes so the UI affordance matches the actual permission.

Fixed the column misalignment in the Grid View when column groups are present.
Fixed an issue whereby special characters (backslash, newline, carriage return, tab, and other control characters) in webhook payload values could produce invalid JSON and cause the webhook target to reject the payload.

These characters are now correctly escaped when substituted into webhook payloads.

The REST API token endpoint now returns HTTP 403 with an actionable "GRANT pem_rest_api to ..." message when the caller is missing the required role, instead of a misleading HTTP 401.
Fixed the Validate Binary Path modal so it renders its message as HTML instead of showing the raw markup to the user.
Fixed the Alert History Report selection semantics.

Choosing Global + servers/agents now returns all matching alerts (previously only global alerts were returned); a Global selection no longer overrides other selections; Cleared alerts are preserved in the summary; and the output now includes target level, unit, and database/schema/object context columns.

Fixed duplicate and unfiltered Alert Template options in the Profile dialog dropdown.
Fixed a crash on the Custom Dashboard page when a chart without a description was added.

The missing description now renders safely instead of aborting the page load.

Limited the markdown syntax accepted in chart descriptions so free-form markdown cannot break the rendering pipeline or introduce style bleed into the surrounding UI.
The Manage Charts table now auto-refreshes when a new custom chart is created, so the newly-created chart appears without requiring a manual reload.
Fixed empty chart description tooltips for custom charts added to Custom Dashboards.

The tooltip now shows the chart's description text.

Chart description tooltips in the Custom Dashboard editor can now be hovered and scrolled, allowing users to read long descriptions in full.
Inherited table columns are now correctly read-only and non-removable across every entry point.

The hardcoded OID and Definition-tab type restriction were removed and replaced with proper checks on both the inheritedfrom and inheritedfromtable gates. Foreign-table inline edit_types filtering is also fixed, along with readonly checks for attstattarget and attstorage. An ERD regression caused by the same issue was also corrected.

Timestamps in alert and BDR nested detail tables are now localised to the user's session timezone.
Fixed the Manage Profiles grid not extending to the panel bottom, and the error toast overlapping data rows.
Fixed an issue whereby non-2xx webhook responses were silently marked as a successful delivery.

HTTP error response handling for webhook payloads now correctly reports non-2xx responses as failures.

Fixed login for Kerberos users whose email in the PEM directory is stored as user@REALM.

When PEM_USER_KRB_INCLUDE_REALM is False, the realm is now stripped from the username used for role lookup, but the full principal is retained as the email so user validation succeeds.

Fixed an issue whereby alert row expansion could collapse or jump to the wrong row when the underlying data refreshed.

Row expansion is now bound to row identity rather than display position.

Fixed an issue whereby new server registrations could produce a template error because post_connection_sql was not set on server_optionsinsert.
Fixed the Dashboard tab restore path so that, after a browser refresh, the correct content is shown for each restored tab.

Previously a restored tab could show the content from a different tab.

Fixed settings.get_tool_data returning HTTP 404 for dashboard tabs, which broke PEM tab restore on page reload.
Documented the required fields for probe_columns in the v17 OpenAPI spec and corrected the HTTP status returned for column validation failures from 500 to 400.
Fixed the Auto Create toggle not appearing on Server-level and Agent-level alert templates.
Fixed alert template PUT returning HTTP 500 due to a positional dict-row index.

Probe lookup is now keyed on column name instead of position.

Preserved job-step run history when a step is removed from a job.

Deleted steps are now parked (marked as removed and disabled) so they disappear from the UI, while the job step log history survives for audit and troubleshooting.

Fixed schedule exceptions not appearing in the job dialog.

The server sends exceptions as three arrays; these are now correctly converted for display when a job's properties are loaded, not only when saved. Also fixed saving exceptions on a newly-added schedule during a job update.

Fixed an issue whereby the os_info probe incorrectly populated os_start_time with a 12-hour based timestamp value.
Fixed an issue whereby Reset Layout only reset the default workspace docker.
Fixed an issue whereby the job properties tab showed Last Result as Failure for jobs that never ran.
Fixed an issue whereby the Scheduled Task log file showed an "invalid date".
Fixed an issue whereby the UI accepted a negative or zero value for agent heartbeat tolerance.
Fixed an issue whereby some tree icons were missing.

Deprecations

Description
Removed BART (Backup and Recovery Tool) support.

All BART references have been retired from the agent, server schema, web UI, and packaging.