github ingres-si/ingressi v2.0.2
Ingressi v2.0.2

latest release: v2.0.3
pre-release2 hours ago

One install per license

A license from ingres.si is active on one install at a time: one dashboard, with the nodes it manages and its replicas.

  • The daily license check also sends a random id of the install. The license server keeps only a keyed hash of it.
  • Another install that uses the same license shows In use on another install, and its paid settings are read-only. The customer gets an e-mail, at most once a day.
  • To move a license, select Deactivate on this install on the License page of the old install, then install the key on the new one. API: POST /api/v1/license/deactivate. Removing the key also releases it.
  • An install that has not confirmed the license for 14 days releases it by itself, for example after a failed server.
  • Customers get an e-mail when a license is revoked or restored.
  • Keys from ingres.si need this release: v2.0.1 can no longer confirm them.

Traffic and paid features already set up keep working in every license state.

Other changes

  • Coraza 3.8.1.
  • Plainer text in the dashboard, the alert e-mails and the documentation.
  • Alerts for a revoked or unconfirmed license no longer ask you to renew it.

Images

docker pull ghcr.io/ingres-si/ingressi-web:2.0.2
docker pull ghcr.io/ingres-si/ingressi-caddy:2.0.2
docker pull ghcr.io/ingres-si/ingressi-l4-port-manager:2.0.2

For linux/amd64 and linux/arm64. Each image is signed with Sigstore cosign and carries an SBOM and a build provenance attestation. To verify, with cosign 3 or later:

cosign verify ghcr.io/ingres-si/ingressi-web:2.0.2 \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com \
  --certificate-identity-regexp '^https://github\.com/ingres-si/ingressi/\.github/workflows/docker-build-trusted\.yml@refs/(heads|tags)/'

The CycloneDX SBOM of the source tree is attached below.

Upgrading

Back up the data volumes, then run docker compose pull && docker compose up -d. An install with a key from ingres.si needs outbound HTTPS to license.ingres.si.

Don't miss a new ingressi release

NewReleases is sending notifications on new releases.