Skip to main content

Milestone AI Bridge integrator manual

Release notes

Last Updated: 14 minute read

Milestone AI Bridge 4.0.0

Kafka integration removed

As announced in the 3.0.1 release notes, the Kafka integration for event and metadata ingestion is no longer supported. Apps must now send events, metadata, and video through the REST or gRPC endpoints provided by the Milestone AI Bridge Broker container.

The following changes apply:

  • The kafka field has been removed from the TopicAvailability type in the GraphQL API. Queries that reference this field are now invalid and will be rejected. Use the rest or grpc fields instead. The sourceStreamID argument of MetadataTopic.topicAvailability is unchanged and continues to provide a source-specific REST endpoint.

  • Metadata kafka topics created by earlier versions are retained during the upgrade. They are no longer used and can be deleted at your convenience. After the configured log-retention period expires, they will no longer contain data.

  • Kafka is still used for communication between Milestone AI Bridge containers and is not affected by this change.

Updated Go RTSP package

The Milestone AI Bridge Streaming container has been updated to use github.com/bluenviron/gortsplib/v4 v4.16.2.

As part of this update:

  • The rtsp-write-buffer-count parameter has been renamed to rtsp-write-queue-size to align with the naming used by the updated Go RTSP package. The parameter's behavior and default value (1024) remain unchanged.

GraphQL Yoga upgrade

The Milestone AI Bridge Webservice container now uses graphql-yoga 5.21.2 (upgraded from 3.9.1). There are no changes to the public GraphQL API or endpoint configuration.

  • Resolved an issue with relaying multiple RTSP feeds during startup. A burst of simultaneous RTSP requests (for example, when many clients reconnect after a restart) could overwhelm the Recording Server and cause stream start-ups to time out. 

    The Milestone AI Bridge Connector container now accepts a new argument, max-concurrent-stream-starts (default 64), that controls how many camera streams can start at the same time. This limits simultaneous stream start-ups and not the number of live cameras that can run concurrently. Once a stream has started, it no longer counts against the limit. The default suits most installations, but you can consider raising it only for large deployments where many cameras are started at the same time (for example, a reconnect burst after a restart), and only if your  Recording Server can handle the extra simultaneous connections.

  • The Milestone AI Bridge Web Service container has been upgraded from Node.js 22.16 to Node.js 24.18.

  • All Milestone AI Bridge Go-based containers now use Go 1.26.4.

  • The WebRTC protocol is no longer supported.

  • The kafka integration (used for event and metadata ingestion) is deprecated and will no longer be supported starting with the next release of Milestone AI Bridge. Existing REST and gRPC integrations will continue to be supported.

New Kubernetes cluster version

Installing Milestone AI Bridge along with the pre-defined ingress gateway, requires a Kubernetes cluster version of 1.31 (or higher). Since ingress-nginx has reached its end-of-life, it is now removed from Milestone AI Bridge. For ingress Milestone AI Bridge comes now with pre-defined installation of NGINX Gateway Fabric (v.2.5.0) which implements the new Gateway API (v.1.5.1).

Added support for configuring a storage provisioner when deploying Milestone AI Bridge on Kubernetes.

Issues were identified during restarts of Kafka and Fuseki pods (or when nodes hosting these pods were restarted) when no persistent storage was configured. To prevent data loss and instability, you must explicitly specify a storage Class in the values.yaml file.

For more information about installing and using the appropriate storage provisioner for single‑node or multi‑node deployments, go to: https://kubernetes.io/docs/concepts/storage/storage-classes/.

Updates in containers

  • The Milestone AI Bridge Web Service container has been upgraded from Node.js 20 to Node.js 22.16.

  • The Milestone AI Bridge Streaming container is now updated to use newer versions of the Go RTSP package: github.com/bluenviron/gortsplib/v3 v3.11.0

  • All Milestone AI Bridge containers’ logs now use structured logging.

Improved error handling

The AI Bridge GraphQL API now features more robust error handling with customized error messages. If a failure occurs, a corresponding error message will be included in the API JSON response. Example:

{
  "errors": [
    {
      "message": "<You will find the error message here>",
      ...
    }
  ],
  "data": null
}

In the next release

The WebRTC protocol will no longer be supported and will be discontinued from the next release of Milestone AI Bridge.

This is a bug-fix release that addresses the bugs described below.

  • Resolved a deadlock issue in the Milestone AI Bridge Streaming container that occurred when handling multiple simultaneous RTSP connections.

  • Fixed an issue where Milestone AI Bridge would sync twice with connected VMS systems on startup.

  • Addressed critical vulnerabilities identified as CVE-2026-33186 and CVE-2026-25896. To learn more, go to https://nvd.nist.gov/.

This is a bug-fix release that addresses the bugs described below.

Incorrect GPS coordinates in GraphQL response

In some cases, the GPS latitude and longitude values were swapped in the GraphQL response, leading to incorrect GPS coordinates. This has been fixed.

Uppercase letters in topic names caused integration issues

Integration issues occurred when ApplicationID or topic names contained uppercase letters. This bug was inadvertently introduced in Milestone AI Bridge 2.0.2 during the upgrade to Apache Jena Fuseki 5.3.0.

ApplicationID and topic names are now handled correctly regardless of letter casing.

Resource limits set for Milestone AI Bridge Fuseki, Kafka Broker, and Kafka Zookeeper.

The following resource limits have been set to improved memory management:

  • Milestone AI Bridge Fuseki: 512 MB limit

  • Milestone AI Bridge Kafka Broker: 1 GB limit

  • Milestone AI Bridge Kafka Zookeeper: 512 MB limit

This release of Milestone AI Bridge includes updates focusing on security hardening, performance optimization, and keeping up-to-date with the operating systems used by Milestone AI Bridge.

Discontinued AI Bridge Kafka zookeeper container

The AI Bridge Kafka zookeeper container has been discontinued and is no longer part of the Milestone AI Bridge download package. Broker management tasks have been moved into the Kafka broker container image, which uses Apache Kafka Raft to reduce dependency on zookeeper for metadata management.

As a result, port 2181 is no longer used by Milestone AI Bridge.

New location for the AI Bridge Kafka broker container image:

The URL to the alternative location of the AI Bridge Kafka broker container image has been changed from https://hub.docker.com/r/confluentinc/cp-kafka/. to https://hub.docker.com/r/bitnami/kafka.

Expanded list of Kafka parameters

The Kafka section of the sample values.yaml file now lists more of the most important and configurable Kafka parameters.

Port 29092 no longer exposed

Milestone AI Bridge will no longer expose port 29092, which was used to enable external access to the broker, often to enable debugging situations.

Port 9092 can be used for this purpose instead, but only if the external access is specifically enabled in the docker-compose.yml file (if you are using Docker) or in the values.yaml file (if you are using Kubernetes).

New Fuseki image

Milestone AI Bridge now utilizes the commonly available secoresearch/fuseki image instead of a custom-built Fuseki image.

As a result, the Fuseki version was also upgraded from 4.7.0 to 5.3.0 and the fuseki (aibridge-fuseki-1) container entrypoint has been changed from "./entrypoint.sh--u.."to "/docker-entrypoint.…".

New Linux distribution used for all container images

To reduce image sizes and facilitate faster downloads and initialization, all Milestone AI Bridge containers are now based on Alpine Linux 3.22 instead of the previously used Ubuntu Linux 22.04.

The streaming container is still based on Ubuntu Linux 22.04.1.

Milestone AI Bridge Web Service upgraded to Node.js 22.16

The Milestone AI Bridge web service container has been upgraded from Node.js 20 to Node.js 22.16.

New Fuseki image

Milestone AI Bridge now utilizes the commonly available secoresearch/fuseki image instead of a custom-built Fuseki image.

As a result, the Fuseki version was also upgraded from 4.7.0 to 5.3.0 and the fuseki (aibridge-fuseki-1) container entrypoint has been changed from "./entrypoint.sh--u.."to "/docker-entrypoint.…".

Improved compatibility with IPv6-only environments

When operating in a IPv6-only environment, outbound IP detection in pure IPv6 setups prevented video streaming and proxy functionality from working correctly. Now, the mechanism for determining the local IP address has been updated to avoid failures during RTSP setup.

Enhanced stability when connecting to multiple VMS instances.

Metadata subscription failures and instability could occur when the same IVA app was registered across two video management systems. Now, Milestone AI Bridge correctly handles duplicated topics and avoids erroneous identification of devices and streams.

RTSP streams with different codecs could not be streamed

RTSP streams from cameras using different codecs (h264, h265, and MJPEG) could not be streamed at the same time.

Now, RSTP streams from cameras using different codecs are streamed simultaneously.

Processing Server Admin plugin

A Create AI Bridge role menu option has been included in the Processing Server Admin plugin.

The new Create AI Bridge role menu option is accessed from Management Client > Processing Servers and enables a system administrator to create a role that, by default contains the least amount of permissions required for Milestone AI Bridge connectivity.

The new AI Bridge role is an XProtect role and like all other XProtect roles, can be edited and assigned to other users.

A basic user for Milestone AI Bridge integration must still be created and assigned to the new AI Bridge role.

Breaking change: Manufacturer id field removed

The manufacturer.id field added in Milestone AI Bridge 1.7.0` which was used for Milestone Installed Integrations Insights has been removed. If you have used the manufacturer.id parameter in your IVA code, you must remove all the references to the parameter.

Note

The manufacturer.name parameter is still present and is still used to contain the name of the IVA manufacturer.

Breaking change: New name format for analytic events

Analytics events created by Milestone AI Bridge in the Milestone XProtect VMS will follow a new format: app-name / event-name.

Important

You must include a space before and after the slash.

If you do not include these spaces, for example using app-name/event-name, you will not receive IVA analytical events.

The new naming format will help Milestone XProtect users identify analytics events across the Milestone XProtect VMS.

As a result of this naming change, you must update your Processing Server Admin plugin (VideoOS.ProcessingServer.Plugin.Admin.Installer) to the latest version.

To continue receiving analytics events fromMilestone AI Bridge, you can either rename your IVA analytical events to the new naming format `app-name / event-name` in your Management Client, or you can unsubscribe all your former analytic event topics and then subscribe to the topics again.

If you have created rules or alarm definitions that reference these analytics topics and didn't rename your IVA analytic events, you must update the rules or alarm definitions to the new analytic event name format.

Milestone AI Bridge registered Milestone Installed Integrations Insights` platform

Milestone AI Bridge is now registered on the Milestone Installed Integrations Insights platform when a license is activated and the processing server is registered.

enforce-oauth parameter not used when getting camera's snapshots

The enforce-oauth parameter in the Milestone AI Bridge Streaming container is no longer used when getting camera's snapshots.

New EXTERNAL_ROOT_PATH environment variable

A new environment variable called EXTERNAL_ROOT_PATH has been introduced to enable the creation of Milestone AI Bridge's ingress rules based on a common segmentation path. The default value of the EXTERNAL_ROOT_PATH environment variable is “/processing-server”.

If you have hardware that was created based on a Milestone AI Bridge subscription (metadata or video topics), you must either:

  • Set the environment variable EXTERNAL_ROOT_PATH to "" (ie empty) in your .env file or

  • Update all your currentMilestone AI Bridge's VPS-related hardware URLs.

Example

Description

For video-related hardware

In the properties of hardware, add '/processing-server' to the path, changing the URLs from:

<br/>VPSNODES,http://[AiBridgeHost]/video/[guid]/[topic]/[format]/[guid]/[guid]<br/>

to

<br/>VPSNODES,http://[AiBridgeHost]/processing-server/video/[guid]/[topic]/[format]/[guid]/[guid]<br/><br/>

For metatada-related hardware

In the properties of hardware, add '/processing-server' to the path, changing the URLs from:

<br/>VPSNODES,http://[AiBridgeHost]/metadata/[guid]/[topic]/[format]/[guid]/[guid]<br/>

to

<br/>VPSNODES,http://[AiBridgeHost]/processing-server/metadata/[guid]/[topic]/[format]/[guid]/[guid]<br/>

Storing log files when using docker compose deployments.

Storing log files at /var/log/aib/[container-name]/ is now only enabled when using docker compose deployments.

New log-file-enabled parameter doe docker compose yaml files

The log-file-enabled parameter has been introduced to the docker compose yaml files. This boolean parameter enables or disables the generation of log files.

Unregistering a processing server from the Management Client

XProtect system administrators can now unregister a processing server in the XProtectManagement Client.

Unregistering an IVA application from the Management Client

XProtect system administrators can now unregister processing server IVA applications in the XProtectManagement Client.

Milestone AI Bridge container uses newer versions of the gortsplib package

The Milestone AI Bridge Streaming container is now updated to use newer versions of the gortsplib package: github.com/aler9/gortsplib/v2 v2.0.0

New optional logging parameters

Four new optional parameters added to setup logging to a file in all Milestone AI Bridge containers:

  • log-max-size: numeric, expressed in megabytes, the maximum file size for a single log file - default 100.

  • log-max-backups: numeric, the maximum number of files to keep stored before removing them - default 15.

  • log-max-age: numeric, expressed in days, the maximum amount of days to remove files - default 15. Not applicable on Milestone AI Bridge Webservice container.

  • log-level: string, log level to use (error, warn, info, debug). Just applicable on Milestone AI Bridge Webservice container.

Log files

Log files are mounted in volumes, on the host: /var/log/aib/[container-name]/- for example /var/log/aib/aibridge-webservice/webservice.log for the Milestone AI Bridge Webservice container.

Unregistering IAV apps

New behavior in Milestone AI Bridge when an IVA app unregisters. Now, the following happens:

  • In the VMS system, the analytics cameras created when you subscribed to the IVA app’s analytics topics are disabled. Disabled analytics cameras no longer listen for analytics data, but you can still access all previously received analytics data.

  • Information about which of the IVA app’s analytics topics you subscribed to is cleared. You must re-subscribe to analytics topics when the IVA app is registered again. Re-subscribing to a topic also enables the existing analytics topic-related analytics camera.

New parameter for controlling and queuing internal RTSP buffers with video from a VMS system.

The new rtsp-write-buffer-count parameter is added to the Milestone AI Bridge Streaming container. The parameter's default length is 1024. If you want to use a different length, use lengths that are a power of two (512, 1024, 2048, and so on).

Whenever this buffer is not long enough for your video packages, the Milestone AI Bridge Streaming container logs the following message in the /var/log/aib/aibridge-streaming/streaming.log log file on the host running Milestone AI Bridge or inside the container:

"RTSP buffer (Camera ID: [XXX-AAAA] - Stream ID: [YYY-BBB]): The VMS system has sent a video package with the length of '[Integer-Value-Here]'. However, Milestone AI Bridge can only handle packages whose maximum length is '[IntegerValue-Here]'. Increase the length of the 'rtsp-write-buffer-count' parameter in the Milestone AI Bridge Streaming container to handle longer video packages."

Newer version of Go RTP packages used

The Milestone AI Bridge Streaming container is now updated to use newer versions of the Go RTP Packages:

  • github.com/pion/interceptor v0.1.29

  • github.com/pion/rtcp v1.2.14

  • github.com/pion/rtp v1.8.7

All Milestone AI Bridge Go-based containers now use Go 1.22.5.

Executive Order 14028 compliant

Milestone AI Bridge now complies with Executive Order 14028 about improved cybersecurity. For more information, visit: https://www.whitehouse.gov/briefing-room/presidential-actions/2021/05/12/executive-order-on-improving-the-nations-cybersecurity/

Containers run Ubuntu 22.04

The Milestone AI Bridge containers are upgraded from Ubuntu 20.04 to 22.04.

Improved synchronization with XProtect VMS

The synchronization between Milestone AI Bridge and the XProtect VMS system is improved. Fewer amounts of synchronization are now needed.

OAuth token validation improved

The Milestone XProtect Identity Provider is now handling the issuer validation. Before, the validation relied on verifying the Milestone XProtect Management Server hostname.

Topics in the App subscription list sorted by type

On the Processing server tab, the Milestone AI Bridge topics in the App subscription list are now sorted by type (event, metadata, and video) and displayed alphabetically for easy selection and navigation.

Webservice container upgraded to Node.js 20

The Milestone AI Bridge Webservice container is upgraded from Node.js 16 to 20.

Installer updated

The Processing Server Admin plugin (VideoOS.ProcessingServer.Plugin.Admin.Installer) installer now requires and verifies the installation of Microsoft Edge WebView2.

Latest graphql-yoga used in Webservice container

Switch from deprecated NPM package express-graphql to the latest graphql-yoga in the Milestone AI Bridge Webservice container.

Fuseki container updated to Jena Fuseki 4.7.0

The Milestone AI Bridge Fuseki container now uses Jena Fuseki version 4.7.0 (previously 4.4.0).

New register.graphql parameters

The register.graphql file has three new parameters: version, manufacturer.id, and manufacturer.name. IVA manufacturers can use the parameters to register their companies on the Milestone Installed Integrations Insights platform.

  • The first version of the Milestone AI Bridge Integrator and Administrator documentation.