Join the discord to stay up to date and have early previews
Changelog
Hey all, been a while 👀
Sorry for the radio silence, I was building, just silently and in the background, my productivity seriously slowed down in the past few months due to some personal stuff (some of you may have read old release notes on here and other apps), but regardless, things are a bit more stable now and I do have a bit more time!
This is a pretty major release and it should solve a lot of issues both logical and visual. It also sorts out some security concerns that were building due to dependencies getting cves and outdated node/next versions.
There are some minor/medium features and some optional hardening you can do with env vars.
Please make sure to back up your crontab files before updating as you always should and triple check everything works, cronmaster is a bit of a wild one to release as every environment tends to do cron slightly differently, so I can't predict it all even if you run this within docker.
features
- Disk space and inode usage in the sidebar. Only
/by default, add more mounts withDISK_MOUNTS, turn it off withDISABLE_DISK_STATS=true#107 - Schedule a script straight from the Scripts Library, and the edit modal can now pick a library script too #9
- "Run now" works for users with no login shell (
nologin,false), falls back to/bin/shautomatically, or force a shell withEXECUTION_SHELL#66 - Translations everywhere: every hardcoded string in the UI now goes through the translation files, Chinese cron descriptions are actually Chinese now, and status colours work in every language #89
HOST_DATA_DIRandHOST_SCRIPTS_DIRto set the host paths yourself instead of relying ondocker inspect#87 #109- Proper system logs with levels and scopes like
[cr*nmaster:job].LOG_LEVEL(error, warn, info, debug),LOG_FORMAT=json,NO_COLOR. Warnings show in orange, secrets are never logged. Seehowto/LOGGING.md - Restyled logs viewer that matches the rest of the app a bit better
- Minor mobile layout fixes
- You can now restrict SSO access with
OIDC_USER_GROUPS/OIDC_USER_ROLES(basically same as Jotty if you use it) - Optional login rate limiting with
AUTH_MAX_LOGIN_ATTEMPTSandAUTH_LOCKOUT_MINUTES - Optional
SESSION_MAX_AGE_DAYS(default 30, same as before) - Optional
STRICT_EXECUTION_USER=trueto refuse running a job as root when its user can't be found on the host - Optional
FRAME_ANCESTORSto control who can embed Cr*nMaster in an iframe
bugfix
- Prevent container logging paths from reaching the host crontab - Thank you @bensynapse
- "Create and start" no longer fails with a generic Server Components error, and failed runs say why (exit code, timeout, signal) #92
- Logs no longer get deleted when you refresh the page on filesystems that don't record creation time (NFS, CIFS, some NAS setups) #94
- Logging in Docker refuses to save a job when the host data path can't be found, instead of writing a path the host can't use, and the real error now shows in the UI #87
- Cloned jobs keep their logging and get their own log folder
- Live logs no longer show duplicated lines and no longer forget the job already finished
- Escape now properly closes modals, so they open again afterwards
- SSO logout actually ends the SSO session, and SSO-only users get a logout button
- The service worker no longer returns a 500
DELETE /api/cronjobs/[id]works, andPATCHaccepts partial updates- The script path preview in Docker now shows the path that actually gets written to the crontab
- Overall system status now takes disk usage into account
- Various minor/medium security hardening
- Paths with spaces are quoted in new cron lines, hopefully this doesn't break anything for anyone, but spaces were basically broken to begin with.
security
- Made sure all deps with fixes have now been addressed so
yarn auditis as clean as it can possibly be - Node 24 upgrade in Docker and CI