github tomasz-c/nft-blackhole v1.5.0

3 hours ago

Warning

Breaking Configuration Change in v1.5.0

  • Configuration file has moved from /etc/nft-blackhole.conf to /etc/nft-blackhole/config.yaml.
  • WHITELIST and BLACKLIST sections now use a new structure: static (direct IP/CIDR), file (local file paths), url (remote URLs).
  • Backward compatibility for the old v4/v6 dictionary format is maintained temporarily (deprecated — will be removed in a future release).
  • Users upgrading from v1.4.1 or earlier must manually migrate and adapt their configuration to the new structure. See config.yaml for a complete reference.

What's Changed

Added

  • Configurable nftables chain priority (PRIORITY option) in configuration and template (#18)
  • Support for static, file, and url source sections in WHITELIST and BLACKLIST (#17)
  • Automatic detection and splitting of IPv4 and IPv6 addresses across all sources without manual IP version separation
  • Support for local file lists in whitelist and blacklist (file section)
  • Support for single IP addresses and subnets directly in blacklist (static section)
  • Support for remote URLs in whitelist (url section)

Changed

  • Relocated configuration file from /etc/nft-blackhole.conf to /etc/nft-blackhole/config.yaml (nft-blackhole.conf renamed to config.yaml)
  • Automatic fallback to legacy /etc/nft-blackhole.conf with migration warning if the old configuration file is present
  • Symmetrical configuration format for WHITELIST and BLACKLIST with temporary fallback support for legacy formats (deprecated)
  • Consolidated nftables set operations into a unified apply_nft_sets() function
  • Unified country IP fetching into get_country_ips() with parallel download of all active IP versions
  • Immediate stop action execution without requiring valid configuration file
  • Optimized comment parsing and native set deduplication

Full Changelog: v1.4.1...v1.5.0

Don't miss a new nft-blackhole release

NewReleases is sending notifications on new releases.