Documentation : https://docs.bunkerweb.io/1.6.16~rc3/
Docker tags :
- All-in-one :
bunkerity/bunkerweb-all-in-one:1.6.16-rc3orghcr.io/bunkerity/bunkerweb-all-in-one:1.6.16-rc3 - BunkerWeb :
bunkerity/bunkerweb:1.6.16-rc3orghcr.io/bunkerity/bunkerweb:1.6.16-rc3 - Scheduler :
bunkerity/bunkerweb-scheduler:1.6.16-rc3orghcr.io/bunkerity/bunkerweb-scheduler:1.6.16-rc3 - Autoconf :
bunkerity/bunkerweb-autoconf:1.6.16-rc3orghcr.io/bunkerity/bunkerweb-autoconf:1.6.16-rc3 - UI :
bunkerity/bunkerweb-ui:1.6.16-rc3orghcr.io/bunkerity/bunkerweb-ui:1.6.16-rc3 - API :
bunkerity/bunkerweb-api:1.6.16-rc3orghcr.io/bunkerity/bunkerweb-api:1.6.16-rc3
GitLab mirror :registry.gitlab.com/bunkerity/bunkerweb/<image>:1.6.16-rc3(same digests)
Linux packages : https://packagecloud.io/app/bunkerity/bunkerweb/search?q=1.6.16~rc3&filter=all&dist=
Changelog :
- [SECURITY] A restart with
KEEP_CONFIG_ON_RESTART=yeskeeps every access control enforced instead of disabling most of them until the next config push. - [FEATURE]
headers: the defaultPERMISSIONS_POLICYalso deniespublickey-credentials-remote-client-data-json. - [FEATURE]
letsencrypt: certificates for public IPv4 addresses inSERVER_NAME, with theshortlivedprofile and thehttpchallenge. (Fixes #3628) - [FEATURE]
realip,blacklist,whitelist,greylist: IP list URLs also read JSON, JSON lines, CSV and tab-separated lists, with a#key=valuefilter. - [FEATURE]
redis: Redis Cluster support via the newREDIS_CLUSTER_NODESsetting. - [FEATURE]
scheduler: a job can exit with code 3 to request a reload while still being reported as failed. - [BUGFIX]
/healthzanswersokduring a graceful reload instead ofloading, so readiness probes no longer fail on every reload. (Refs bunkerity/bunkerweb-helm#97) - [BUGFIX] The loading page answers 503 with
Retry-Afterinstead of 200. (Fixes #3988) - [BUGFIX] Jobs no longer load every plugin's cached files at startup, which could get the scheduler OOM-killed.
- [BUGFIX] A PRO force update no longer deletes unchanged PRO plugin pages.
- [BUGFIX] The scheduler and autoconf log a warning when two services share a server name.
- [BUGFIX] In single-site mode every
SERVER_NAMEentry is served and covered by the certificate, not only the first one. - [BUGFIX]
autoconf: Gateway API backends useKUBERNETES_SERVICE_PROTOCOLinstead of the listener protocol, so an HTTPS listener no longer breaks HTTP backends. (Fixes bunkerity/bunkerweb-helm#121) - [BUGFIX]
backup: the built-in backup no longer fails on MySQL 26.x. - [BUGFIX]
blacklist:BLACKLIST_IGNORE_USER_AGENT_URLSentries are no longer cut at their first space, which exempted most browsers. - [BUGFIX]
bunkernet: the queue of unsent reports keeps the newest 10,000 instead of growing without limit. - [BUGFIX]
db: large blobs are stored in chunks, so PRO plugin updates no longer need a raisedmax_allowed_packeton MariaDB/MySQL. (Fixes #3965) - [BUGFIX]
errors: a custom error page is served to blocked POST and PUT requests instead of a 405. - [BUGFIX]
grpc,reverseproxy: new or rotated upstream CA, CRL or client certificate files are applied even when another service's files fail. - [BUGFIX]
headers: cookie flags such asSameSite=Laxare no longer randomly missing fromSet-Cookie. - [BUGFIX]
headers:COOKIE_FLAGSrefusesExpires,Domain,Pathand entries without a flag, which used to fail the reload and keep the old configuration. - [BUGFIX]
letsencrypt: renewed certificates reach the instances right after the renewal instead of at the next reload. - [BUGFIX]
letsencrypt: adding names to a certificate expands it instead of deleting it first, so a failing new name keeps the current one. - [BUGFIX]
metrics: instances sharing one Redis no longer overwrite each other's metrics; give each instance a distinct hostname. - [BUGFIX]
misc: the default server serves its placeholder page only on/and answers 404 elsewhere instead of 200. (Fixes #3992) - [BUGFIX]
ui,api: editing a service no longer deletes another one sharing a server name; shared server names are refused. - [BUGFIX]
ui: creating or deleting a service no longer rewrites the other services' settings. (Fixes #3986) - [BUGFIX]
ui: renaming a service no longer drops the settings of services whose name starts with the old one. - [BUGFIX]
ui: after saving a setting, the page shows the new value instead of the old one until a refresh. (Fixes #3991) - [BUGFIX]
ui: logins no longer fail with "The CSRF session token is missing" on a fresh worker or with mixed proxied and direct access. - [BUGFIX]
ui: for signed-in users, a form field over 500 kB, such as a large Easy Resolve request, no longer fails with 413. - [BUGFIX]
ui: the Web UI of the all-in-one image starts again instead of failing withNo module named '_zstd'. - [BUGFIX]
ui: the "More info" link of core and PRO plugins opens their section of the Features page. (Fixes #3990) - [BUGFIX]
ui: country flags load again on the reports, bans and plugin pages. - [BUGFIX]
ui: raw translation keys no longer flash on page load. (Fixes #3963) - [BUGFIX]
ui: wrapped table toolbars keep their controls aligned. (Fixes #3969) - [BUGFIX]
ui: plugins without a page (e.g. PRO Maintenance) no longer ask to restart the Web UI. - [BUGFIX]
ui: the Global config breadcrumb and the service conversion and cache deletion modals are translated. - [BUGFIX]
ui: the active PRO plugin entry in the dark-mode menu is readable again. - [BUGFIX]
ui: the bans table header and country tooltips now show. - [BUGFIX]
ui: the RAW editor's draft help is translated in every language. - [BUGFIX]
ui: PRO and external plugin pages no longer stay outdated when two plugin updates land a few seconds apart. - [PERF]
ui: the reports table no longer rebuilds every tooltip on each draw, which also stops its memory growth. - [PERF]
ui: restoring saved hidden columns measures the table once instead of once per column. - [DEPS]
modsecurity: libmodsecurity v3.0.17 (security fixes); custom rules selectingMULTIPART_FILENAMEby file name must use the field name. - [DEPS] Update libmaxminddb to v1.14.1.
- [DEPS] Added resty-redis-cluster v1.6.1 (Kong) for Redis Cluster support.
- [CONTRIBUTION] Thank you @MageInt for syncing metrics to Redis incrementally. (#3972)
- [CONTRIBUTION] Thank you @rayshoo for adding
SameSite=NonetoCOOKIE_FLAGS. (#3066)