Fixed
- n8n (security) -
https://<N8N_HOSTNAME>/metricswas publicly reachable without authentication on every release so far: it exposed the n8n version and process metrics, and since 1.10.0 also every workflow name and ID. Caddy now answers 404 for/metricson the n8n host; Prometheus scrapes n8n over the Docker network, so Grafana dashboards and alerts are unaffected.make doctorreports an error if Caddy serves the endpoint, and with thecloudflare-tunnelprofile also if it is public through the tunnel. The documented tunnel route (http://n8n:5678) bypasses Caddy, so cloudflare-instructions.md now has a WAF expression to block it (issue #132).
Upgrade
Run make update, then check with curl -sI https://<N8N_HOSTNAME>/metrics (expect 404) or make doctor. If you added your own block for /metrics as a workaround, you can drop it.
Cloudflare Tunnel users: the tunnel reaches n8n directly, so the Caddy fix does not cover you. Add the "Block n8n metrics" expression from Protecting n8n Webhooks with WAF Rules as a custom WAF rule with action Block; make doctor then confirms it through the public hostname.
Full Changelog: v1.16.0...v1.16.1