License keys from ingres.si are confirmed once a day
Keys bought or requested as a trial on ingres.si are online keys. Once a day, the install sends the license id and the SHA-256 of its key to license.ingres.si and gets back a signed answer: active or revoked.
- Revoked license (refund, chargeback, or a key shared beyond the license): paid settings become read-only at once. Paid features already set up keep running, and traffic is never affected.
- No confirmation for 14 days, or within 7 days of installing a key: paid settings become read-only until a check succeeds.
- The License page shows the last confirmation and has a Check now button. API:
POST /api/v1/license/check. - Offline keys, for air-gapped Enterprise installs, are never checked online.
- v2.0.0 refuses keys from ingres.si with "This license key needs a newer version of Ingressi".
Images
docker pull ghcr.io/ingres-si/ingressi-web:2.0.1
docker pull ghcr.io/ingres-si/ingressi-caddy:2.0.1
docker pull ghcr.io/ingres-si/ingressi-l4-port-manager:2.0.1For linux/amd64 and linux/arm64. Each image is signed with Sigstore cosign and carries an SBOM and a build provenance attestation. To verify, with cosign 3 or later:
cosign verify ghcr.io/ingres-si/ingressi-web:2.0.1 \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
--certificate-identity-regexp '^https://github\.com/ingres-si/ingressi/\.github/workflows/docker-build-trusted\.yml@refs/(heads|tags)/'The CycloneDX SBOM of the source tree is attached below.
Upgrading
Back up the data volumes, then run docker compose pull && docker compose up -d. An install with a key from ingres.si needs outbound HTTPS to license.ingres.si.