github ingres-si/ingressi v2.4.0
Ingressi v2.4.0

2 hours ago

Changes

  • A host's Security tab manages its WAF rule exclusions in place. Add one by finding the rule by its id or name, change its path, variable or reason, or remove it. The rules that matched the host in the last 7 days are listed with how often and on which path, each with Exclude…. The rarely changed WAF settings (global settings, Core Rule Set, body limits, custom directives) moved under Advanced, and rate limiting reads Global limits, Global and this host's, This host's only.
  • Analytics filters by part of a value. The filter box finds hosts, paths, addresses and user agents containing what you type, with their request counts (GET /api/v1/analytics/values). Filters take contains and not_contains, and clicking a filter's operator inverts it. Security events accept the same filters.
  • Choosing hosts by typing: the WAF exclusion form and the alert rule editor search host names and domains instead of a long dropdown. The host lists filter as you type without adding history entries or jumping, and / focuses their search.
  • Alerts: Dismiss dismisses an open alert at once, until it resolves. Dismissing for a while and muting the rule are in the menu next to it.
  • AI
    • Analytics questions can ask about the last N minutes (up to a day) or exact times.
    • OpenAI-compatible providers get 4096 output tokens, so reasoning models have room to answer. Answers sent as content parts are read, and a reply with only reasoning says the model ran out before answering.
    • An HTTP 403 from the provider says a web application firewall in front of it may have refused the prompt.
  • Fixes
    • The web container exits when start-up fails (a rejected ADMIN_PASSWORD or SESSION_SECRET, a failed migration) instead of answering every request with 500.
    • Old /proxy-hosts?edit=<id> links open the host's Routing tab again instead of its overview.

Images

docker pull ghcr.io/ingres-si/ingressi-web:2.4.0
docker pull ghcr.io/ingres-si/ingressi-caddy:2.4.0
docker pull ghcr.io/ingres-si/ingressi-l4-port-manager:2.4.0

For linux/amd64 and linux/arm64. Each image is signed with Sigstore cosign and carries an SBOM and a build provenance attestation. To verify, with cosign 3 or later:

cosign verify ghcr.io/ingres-si/ingressi-web:2.4.0 \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com \
  --certificate-identity-regexp '^https://github\.com/ingres-si/ingressi/\.github/workflows/docker-build-trusted\.yml@refs/(heads|tags)/'

The CycloneDX SBOM of the source tree is attached below.

Upgrading

Back up the data volumes, then run docker compose pull && docker compose up -d. No database migrations. Read the upgrade notes.

Donations

Ingressi is free. If it saves you time or money, please consider supporting it: GitHub Sponsors or Ko-fi.

Don't miss a new ingressi release

NewReleases is sending notifications on new releases.