github bunkerity/bunkerweb v1.6.16-rc3

pre-release4 hours ago

Documentation : https://docs.bunkerweb.io/1.6.16~rc3/

Docker tags :

  • All-in-one : bunkerity/bunkerweb-all-in-one:1.6.16-rc3 or ghcr.io/bunkerity/bunkerweb-all-in-one:1.6.16-rc3
  • BunkerWeb : bunkerity/bunkerweb:1.6.16-rc3 or ghcr.io/bunkerity/bunkerweb:1.6.16-rc3
  • Scheduler : bunkerity/bunkerweb-scheduler:1.6.16-rc3 or ghcr.io/bunkerity/bunkerweb-scheduler:1.6.16-rc3
  • Autoconf : bunkerity/bunkerweb-autoconf:1.6.16-rc3 or ghcr.io/bunkerity/bunkerweb-autoconf:1.6.16-rc3
  • UI : bunkerity/bunkerweb-ui:1.6.16-rc3 or ghcr.io/bunkerity/bunkerweb-ui:1.6.16-rc3
  • API : bunkerity/bunkerweb-api:1.6.16-rc3 or ghcr.io/bunkerity/bunkerweb-api:1.6.16-rc3
    GitLab mirror : registry.gitlab.com/bunkerity/bunkerweb/<image>:1.6.16-rc3 (same digests)

Linux packages : https://packagecloud.io/app/bunkerity/bunkerweb/search?q=1.6.16~rc3&filter=all&dist=

Changelog :

  • [SECURITY] A restart with KEEP_CONFIG_ON_RESTART=yes keeps every access control enforced instead of disabling most of them until the next config push.
  • [FEATURE] headers: the default PERMISSIONS_POLICY also denies publickey-credentials-remote-client-data-json.
  • [FEATURE] letsencrypt: certificates for public IPv4 addresses in SERVER_NAME, with the shortlived profile and the http challenge. (Fixes #3628)
  • [FEATURE] realip, blacklist, whitelist, greylist: IP list URLs also read JSON, JSON lines, CSV and tab-separated lists, with a #key=value filter.
  • [FEATURE] redis: Redis Cluster support via the new REDIS_CLUSTER_NODES setting.
  • [FEATURE] scheduler: a job can exit with code 3 to request a reload while still being reported as failed.
  • [BUGFIX] /healthz answers ok during a graceful reload instead of loading, so readiness probes no longer fail on every reload. (Refs bunkerity/bunkerweb-helm#97)
  • [BUGFIX] The loading page answers 503 with Retry-After instead of 200. (Fixes #3988)
  • [BUGFIX] Jobs no longer load every plugin's cached files at startup, which could get the scheduler OOM-killed.
  • [BUGFIX] A PRO force update no longer deletes unchanged PRO plugin pages.
  • [BUGFIX] The scheduler and autoconf log a warning when two services share a server name.
  • [BUGFIX] In single-site mode every SERVER_NAME entry is served and covered by the certificate, not only the first one.
  • [BUGFIX] autoconf: Gateway API backends use KUBERNETES_SERVICE_PROTOCOL instead of the listener protocol, so an HTTPS listener no longer breaks HTTP backends. (Fixes bunkerity/bunkerweb-helm#121)
  • [BUGFIX] backup: the built-in backup no longer fails on MySQL 26.x.
  • [BUGFIX] blacklist: BLACKLIST_IGNORE_USER_AGENT_URLS entries are no longer cut at their first space, which exempted most browsers.
  • [BUGFIX] bunkernet: the queue of unsent reports keeps the newest 10,000 instead of growing without limit.
  • [BUGFIX] db: large blobs are stored in chunks, so PRO plugin updates no longer need a raised max_allowed_packet on MariaDB/MySQL. (Fixes #3965)
  • [BUGFIX] errors: a custom error page is served to blocked POST and PUT requests instead of a 405.
  • [BUGFIX] grpc, reverseproxy: new or rotated upstream CA, CRL or client certificate files are applied even when another service's files fail.
  • [BUGFIX] headers: cookie flags such as SameSite=Lax are no longer randomly missing from Set-Cookie.
  • [BUGFIX] headers: COOKIE_FLAGS refuses Expires, Domain, Path and entries without a flag, which used to fail the reload and keep the old configuration.
  • [BUGFIX] letsencrypt: renewed certificates reach the instances right after the renewal instead of at the next reload.
  • [BUGFIX] letsencrypt: adding names to a certificate expands it instead of deleting it first, so a failing new name keeps the current one.
  • [BUGFIX] metrics: instances sharing one Redis no longer overwrite each other's metrics; give each instance a distinct hostname.
  • [BUGFIX] misc: the default server serves its placeholder page only on / and answers 404 elsewhere instead of 200. (Fixes #3992)
  • [BUGFIX] ui, api: editing a service no longer deletes another one sharing a server name; shared server names are refused.
  • [BUGFIX] ui: creating or deleting a service no longer rewrites the other services' settings. (Fixes #3986)
  • [BUGFIX] ui: renaming a service no longer drops the settings of services whose name starts with the old one.
  • [BUGFIX] ui: after saving a setting, the page shows the new value instead of the old one until a refresh. (Fixes #3991)
  • [BUGFIX] ui: logins no longer fail with "The CSRF session token is missing" on a fresh worker or with mixed proxied and direct access.
  • [BUGFIX] ui: for signed-in users, a form field over 500 kB, such as a large Easy Resolve request, no longer fails with 413.
  • [BUGFIX] ui: the Web UI of the all-in-one image starts again instead of failing with No module named '_zstd'.
  • [BUGFIX] ui: the "More info" link of core and PRO plugins opens their section of the Features page. (Fixes #3990)
  • [BUGFIX] ui: country flags load again on the reports, bans and plugin pages.
  • [BUGFIX] ui: raw translation keys no longer flash on page load. (Fixes #3963)
  • [BUGFIX] ui: wrapped table toolbars keep their controls aligned. (Fixes #3969)
  • [BUGFIX] ui: plugins without a page (e.g. PRO Maintenance) no longer ask to restart the Web UI.
  • [BUGFIX] ui: the Global config breadcrumb and the service conversion and cache deletion modals are translated.
  • [BUGFIX] ui: the active PRO plugin entry in the dark-mode menu is readable again.
  • [BUGFIX] ui: the bans table header and country tooltips now show.
  • [BUGFIX] ui: the RAW editor's draft help is translated in every language.
  • [BUGFIX] ui: PRO and external plugin pages no longer stay outdated when two plugin updates land a few seconds apart.
  • [PERF] ui: the reports table no longer rebuilds every tooltip on each draw, which also stops its memory growth.
  • [PERF] ui: restoring saved hidden columns measures the table once instead of once per column.
  • [DEPS] modsecurity: libmodsecurity v3.0.17 (security fixes); custom rules selecting MULTIPART_FILENAME by file name must use the field name.
  • [DEPS] Update libmaxminddb to v1.14.1.
  • [DEPS] Added resty-redis-cluster v1.6.1 (Kong) for Redis Cluster support.
  • [CONTRIBUTION] Thank you @MageInt for syncing metrics to Redis incrementally. (#3972)
  • [CONTRIBUTION] Thank you @rayshoo for adding SameSite=None to COOKIE_FLAGS. (#3066)

Don't miss a new bunkerweb release

NewReleases is sending notifications on new releases.