github kossakovsky/selfhost-ai v1.16.1

4 hours ago

Fixed

  • n8n (security) - https://<N8N_HOSTNAME>/metrics was publicly reachable without authentication on every release so far: it exposed the n8n version and process metrics, and since 1.10.0 also every workflow name and ID. Caddy now answers 404 for /metrics on the n8n host; Prometheus scrapes n8n over the Docker network, so Grafana dashboards and alerts are unaffected. make doctor reports an error if Caddy serves the endpoint, and with the cloudflare-tunnel profile also if it is public through the tunnel. The documented tunnel route (http://n8n:5678) bypasses Caddy, so cloudflare-instructions.md now has a WAF expression to block it (issue #132).

Upgrade

Run make update, then check with curl -sI https://<N8N_HOSTNAME>/metrics (expect 404) or make doctor. If you added your own block for /metrics as a workaround, you can drop it.

Cloudflare Tunnel users: the tunnel reaches n8n directly, so the Caddy fix does not cover you. Add the "Block n8n metrics" expression from Protecting n8n Webhooks with WAF Rules as a custom WAF rule with action Block; make doctor then confirms it through the public hostname.

Full Changelog: v1.16.0...v1.16.1

Don't miss a new selfhost-ai release

NewReleases is sending notifications on new releases.