Breaking changes
Configuration
- Host-isolated handler directives: backend/handler selectors (
proxy,fcgi,fcgi_php,cgi,scgi,forward_proxy,root,index,basic_auth,rate_limit_backend, static-file tunables,client_ip_from_header,trace_id_header,https_redirect,trailing_slash_redirect,disable_symlinks,directory_listing) no longer inherit from the wildcard*host into named hosts, while global-scope defaults andlocation-from-host inheritance keep working. Previously,* { proxy ... }would unexpectedly reverse-proxy a named host that only setroot. Note: a named host no longer inheritsrootfrom*, so give each host its ownroot(or set it globally).
Added
Access control
- Basic auth bcrypt hashes: bcrypt hash formats
$2a$,$2b$,$2x$,$2y$are now supported for Basic Auth. This allows using Ferron with control planes and services that expect bcrypt password hashes.
Changed
HTTP cache
- Zero-result cache purge metric: purges with zero results are now visible via a
ferron.cache.zero_purgemetric, which can help debug or monitor cache purge requests that did not match any entries.
Fixed
Configuration
- Spurious configuration file hot-reload fix: previously, the server would sometimes hot-reload the configuration even when no changes were made to the configuration file (something would just read the file). This has been fixed.
Admin API
- Admin API listen fail fix: previously, when configuration is reloaded very frequently, the admin API listener would sometimes fail to bind to the configured address due to a race condition.
Observability
- Prometheus reload listen fail fix: previously, when configuration is reloaded very frequently, the Prometheus listener would sometimes fail to bind to the configured address due to a race condition.