github flohoss/gocron v0.13.0
Release v0.13.0

latest release: v0.13.1
6 hours ago

Highlights

Single sign-on with OpenID Connect — GoCron can now protect both the UI and the API behind any OIDC provider (tested against Pocket-ID).

  • New auth.oidc config section: enabled, issuer_url, client_id, client_secret, session_ttl, cookie_secure. Endpoints and signing keys are auto-discovered from the issuer's .well-known/openid-configuration
  • Authorization-code flow with PKCE + state; sessions are opaque, DB-backed, deleted on logout, and expire after session_ttl (default 24h)
  • SPA requires login when SSO is enabled — unauthenticated visitors are redirected to the provider; only the openid scope is requested and the session is keyed on the ID token's sub, so no email claim is needed
  • cookie_secure toggle for HTTPS deployments; any auth.oidc.* value can be overridden via GC_AUTH_OIDC_* env vars
  • Live-reloadable — changes to the auth.oidc section apply on config reload, no restart needed (the provider is re-discovered when issuer_url/client_id change; discovery failures retry on the next request)
  • Config file with comments: the commented reference config/config.example.yaml is embedded via go:embed and written to config/config.yaml on first boot if no config exists. config.yaml is git-ignored so local credentials never get committed
  • Runtime-reloadable schedule and log level: changing time_zone or log_level in config.yaml applies immediately on config reload — the cron scheduler and the default slog handler are rebuilt without a restart
  • Documented in the README with a commented example in config/config.example.yaml

Fixes

  • Scheduled jobs no longer start during shutdown — the scheduler stops accepting runs first and the shutdown channel closes only after all cleanup completes (#59, thanks @bensynapse)
  • Job cancellation now fully finishes before shutdown returns

Improvements

  • Configuration validation errors are translated and formatted for readability
  • Custom validation rules moved into the validate package
  • Coverage reporting excludes generated files; the coverage badge is published in the repo
  • All protected API operations now declare the cookieAuth security scheme in the OpenAPI spec

Behavior changes

  • Cron schedules now run in the configured time_zone, applied on reload — the scheduler is built with cron.WithLocation(...). Previously time_zone only took effect via TZ at startup, so a config edit didn't move existing cron entries until a restart. If you run with a non-UTC time_zone, double-check that schedules land where you expect after upgrading

Notes

  • If you run GoCron behind a reverse proxy and enable SSO, the proxy must forward /api/auth/, and the OIDC callback URL registered at your provider must be the public address (e.g. https://gocron.example.com/api/auth/callback)
  • Logout deletes the session server-side; when the provider advertises an end_session_endpoint the frontend also redirects there to clear the provider-side session
  • Sessions are opaque tokens stored server-side — they expire after session_ttl and are cleaned up hourly
  • No config changes required for existing installations — auth stays disabled unless auth.oidc.enabled: true is set. Your existing config.yaml keeps working as-is

Changes in This Release

Full Changelog: v0.12.0...v0.13.0


Docker Image

docker pull ghcr.io/flohoss/gocron:v0.13.0
docker pull ghcr.io/flohoss/gocron:latest

Binary Downloads

Download one of the attached binaries extracted from the release image:

  • gocron_<version>_linux_amd64
  • gocron_<version>_linux_arm64

Verify with ./gocron_<version>_linux_<arch> --version.

Image digest:

ghcr.io/flohoss/gocron:v0.13.0@sha256:efd2f87ac3df91e95866ae7c2ecd4aff1440d213cdb255c6a39f6c7026991ce8

Build Information

  • Version: v0.13.0
  • Build Time: 2026-09-29T07:17:20Z
  • Repository: https://github.com/flohoss/gocron
  • Platform: linux/amd64,linux/arm64
  • Attestations: SLSA Provenance, SBOM

Don't miss a new gocron release

NewReleases is sending notifications on new releases.