github doctor-io/homeio v1.10.0
Homeio v1.10.0

5 hours ago

Homeio 1.10 rebuilds the Monitor around history, shows the real state of every app on the desktop, follows published releases for updates, and goes back to open source under the AGPL-3.0. Full notes are in CHANGELOG.md; the release post is at homeio.app/homeio-1-10-monitor-release.

Licence

From 1.10.0 Homeio is open source under the AGPL-3.0, replacing the Business Source License used for 1.9.6 and 1.9.7. Use at home or at work is unrestricted; anyone who distributes a modified Homeio, or runs one as a service for others, publishes their changes under the same licence. 1.9.5 and earlier stay MIT, 1.9.6 and 1.9.7 stay BSL.

New

  • Monitor history. CPU, memory, temperature and network are sampled every 5 s in the background, so the Monitor opens on the last 15 min, 1 h or 24 h instead of an empty chart. Charts show current, average and peak values and are drawn as smooth curves.
  • Network tab: live throughput, gateway, DNS, and a card per interface. Disks tab: usage, read/write history, SMART health and temperature per disk. The Docker image now lists the host's disks, read-only.
  • App and container states on the desktop. Stopped, crashed (with exit code), restarting, unhealthy, paused and never started are told apart, for Homeio apps and other containers.
  • Update reminder above the dock, with Update now, Details and Later. Docker installs get the compose command instead.
  • Reconnecting screen when Homeio stops answering, and a reboot or update started on one device now switches every open desktop to the restart screen.

Changed

  • Update checks read the release GitHub marks as Latest, and Update now installs that tag. install.sh and update.sh install the latest release by default; HOMEIO_REPO_BRANCH still pins a branch or tag.
  • The Cloudflare Tunnel connector is a Homeio component (io.homeio.component=cloudflare-tunnel), shown in Settings and no longer on the desktop.
  • Performance: metrics come from /proc and /sys instead of ~130 spawned commands per snapshot; host reads are cached; the log file rotates at 10 MB and the Logs window reads its tail; App Store revalidation, session lookups and the accounts check are shared; nginx keeps upstream connections, closes them before Node does, and allows 4096 connections per worker. Load-tested up to 400 simultaneous users.

Security

  • Security headers on every response: X-Frame-Options: DENY, frame-ancestors 'none', nosniff, Referrer-Policy, Permissions-Policy (camera and microphone denied, geolocation for Homeio's own pages, which the weather uses) and HSTS. nginx hides its version.
  • On script installs nginx asks Homeio (auth_request) before streaming an upload, so a signed-out cookie or a demo visitor can no longer write files.

Fixed

  • fail2ban did not start on Debian 12+ (no /var/log/auth.log); it now reads the systemd journal.
  • Uploads returned 502 after a reboot or a D-Bus helper restart: the upload socket has its own runtime directory, /run/home-server-upload.
  • The update check failed for everyone on a busy server once GitHub's rate limit was hit; the latest version is cached for an hour.
  • The in-app update installed main even on a server following another branch.

Removed

  • The tarball install path. HOMEIO_RELEASE_TAG and HOMEIO_RELEASE_TARBALL_URL now stop the scripts with a message; use HOMEIO_REPO_BRANCH=v1.10.0.
  • 56 files of dead code (unused shadcn components, superseded Files dialogs, old auth widgets).

Upgrading

  • Script installs on 1.9.x: run curl -fsSL https://raw.githubusercontent.com/doctor-io/homeio/main/scripts/update.sh | sudo bash. Update now in Settings also installs 1.10, but it runs the 1.9 update script already on the server, so the nginx, upload and fail2ban changes only land with the next update. Running the command once completes them.
  • Docker: docker compose pull && docker compose up -d. The 1.9.7 image was never published (the build hung under QEMU), so Docker installs move from 1.9.6 straight to 1.10.0. The image job now times out after 45 minutes instead of 6 hours.

Tested

  • CI steps locally: lint (0 errors), 993 tests in 215 files, production build.
  • Docker image (arm64, built from this branch): fresh install, registration, login, desktop, Monitor tabs, store catalog, update status (1.10.0, canSelfUpdate: false) and security headers. Upgrade from the published latest image (1.9.6) with an existing database: migrations run, the existing account logs in.
  • Fresh install on Debian 12 (install.sh, real systemd VM): all six services active, fail2ban running with the systemd backend, nginx version hidden, upload with a session 200, without one 401, same cookie after logout 401.
  • Upgrade 1.9.7 → 1.10.0 on Debian 12: 1.9.7's own update.sh (what Update now runs) brings the app to 1.10.0 with login and uploads working; running the 1.10 update.sh afterwards applies the nginx, upload and fail2ban changes. On the 1.9.7 baseline fail2ban was down and uploads returned 502, as described above.

Don't miss a new homeio release

NewReleases is sending notifications on new releases.