Changes
- Alerts are the issues of your install. Built-in rules watch expiring certificates, a failed Caddy apply, server errors, failing upstreams, failed backups and the fleet (WAF block spike is added disabled). They notify nobody until you pick channels. Needs attention on the overview lists the open alerts with links to their pages, and dismissing one dismisses it for everyone until it resolves (
POST /api/v1/alert-silences). - The Alerts page has the tabs Open, History, Rules and Channels, with the daily digest on Channels. Test a channel before saving it (
POST /api/v1/alert-channels/test). The AI provider and analytics questions moved to AI settings (/settings/ai). - A proxy host's page holds its editor. Overview, Routing, Security, Access, Certificate, Headers, Advanced and History are tabs that switch in place. Unsaved changes survive switching tabs, the save bar appears only when something changed, and leaving with unsaved changes asks first. Geo blocking moved to Security. A host saved while Caddy is unreachable is reported as saved but not live.
- L4 hosts get the same page:
/l4-proxy-hosts/<id>with Overview, Routing, Load balancing, Security, Advanced and History tabs; new hosts and duplicates at/l4-proxy-hosts/new. - Security events: a WAF event shows each matched rule with what it matched where (control characters shown as escapes). Exclude N rules… reviews all the suggested exclusions together and adds them with one apply (
POST /api/v1/waf/exclusions/batch). Blocking a Cloudflare address warns first. - Analytics: the request log folds runs of identical requests into one row with a count, and a blocked request's WAF rule links to its events.
- WAF: bodies with a content type that is not form, multipart, JSON or XML (protobuf such as OpenTelemetry traces, octet-stream, gRPC) are inspected as they are instead of being parsed as form data, which made dozens of attack rules match binary data.
- Fixes
- A deleted primary admin is no longer created again on every start; changing
ADMIN_PASSWORDorADMIN_USERNAMEstill recreates it (account recovery). - The web server keeps idle connections for 125 seconds (
KEEP_ALIVE_TIMEOUT), so a proxy host in front of the dashboard no longer gets an occasional 502 from a connection the server had just closed. - The editors warn that passive health checks on a host with one upstream make Caddy refuse every request for the fail duration after a single failure.
- A deleted primary admin is no longer created again on every start; changing
- Layout consistency across the dashboard: host list rows stay on one line, shared page headers and banners, one control for picking the WAF mode.
Images
docker pull ghcr.io/ingres-si/ingressi-web:2.3.0
docker pull ghcr.io/ingres-si/ingressi-caddy:2.3.0
docker pull ghcr.io/ingres-si/ingressi-l4-port-manager:2.3.0For linux/amd64 and linux/arm64. Each image is signed with Sigstore cosign and carries an SBOM and a build provenance attestation. To verify, with cosign 3 or later:
cosign verify ghcr.io/ingres-si/ingressi-web:2.3.0 \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
--certificate-identity-regexp '^https://github\.com/ingres-si/ingressi/\.github/workflows/docker-build-trusted\.yml@refs/(heads|tags)/'The CycloneDX SBOM of the source tree is attached below.
Upgrading
Back up the data volumes, then run docker compose pull && docker compose up -d. One database migration runs on start: it drops the per-account dismissals of v2.2.0. Read the upgrade notes.
Donations
Ingressi is free. If it saves you time or money, please consider supporting it: GitHub Sponsors or Ko-fi.