Bug Fixes
- Core/Routes: Partial file-provider reload failures preserve existing routes. (7adbf19, 4edd178, #273)
- Valid additions and updates still apply; deletions wait for a clean reload.
- Clean empty files still remove all file routes, and Docker/agent removals remain supported during partial failures.
- Core/Configuration: Explicit empty lists remain distinct from omitted or null values when converting configuration values. (49e22e0)
- Empty lists can disable inherited idlewatcher notification targets.
- Deployment/Docker: The main image sets HOME=/app so the OVH SDK can check its optional configuration without permission errors when running as a non-root user. (ec19a07, #275)
- WebUI/Certificates: Main and extra certificate forms offer backend-registered providers and provider-specific option fields. (3a41264, 5974829, #274, yusing/godoxy-webui@b79f285)
- Structured options, including arrays and nested objects, are supported while option values remain redacted in JSON/YAML output.
- Boolean provider options use labeled checkboxes in both forms, supporting existing boolean and string values while saving edits as booleans. (yusing/godoxy-webui@b79f285)
- Switching providers refreshes option controls and clears old option values in the selected certificate form without changing the other form. (yusing/godoxy-webui@b79f285)
- Inferred field labels use spaced words, such as Zone Token and Polling Interval. Generic duration guidance no longer replaces duration field names; other descriptions and raw configuration keys stay unchanged. (yusing/godoxy-webui@b79f285)
- WebUI/Search: Apps without display names can be found by their aliases. (yusing/godoxy-webui@176f390, webui #21)
- Core/Agents: Recovered agents retain their discovered names. (d579b86, #269)
- Recovered names appear in provider logs, route metadata, and statistics.
- Core/Agents: Agent v0.18.6 receives the correct upstream protocol, including h2c. (yusing/goutils@05a7cb0, cfae89e)
- Core/Networking: Generated listener URLs preserve IPv6 brackets. (yusing/goutils@71fa4fe, cdeac60)
- Core/GeoIP: Repeated MaxMind reloads no longer hit a cache-limit panic. (yusing/goutils@afabe72, yusing/goutils@9450745, 56fd47b)
- Stopped MaxMind runtimes release cached data and callbacks.
- Core/Events: Event streams continue after route or node removals. (yusing/goutils@32bb351, yusing/godoxy-webui@9c0b122)
- Dashboard events show the names of removed routes and Proxmox nodes. (yusing/godoxy-webui@9c0b122)
- Concurrent registry additions and removals no longer overwrite each other.
- Listing a cleared registry no longer panics after removals.
- Core/Rules: Repeated Basic Auth checks no longer panic on missing or invalid credentials. (yusing/goutils@1ab11c9)
- Core/API: API error responses no longer fail when an error cause is absent. (yusing/goutils@78359dd)
- Core/Listeners: HTTPS listeners support PROXY protocol without startup panics. (yusing/goutils@8803127)
- Core/Events: Event IDs avoid deterministic collisions across processes. (yusing/goutils@c71a1e5)
New Features
- Core/Idlewatcher: Optional sleep/pause and wake notifications use configured notification providers. (1025dc0, #264)
- Enable them globally with
defaults.idlewatcher.notifyor per route withidlewatcher.notify; they are off by default. - Set
toto provider names. An absent route block inherits global settings; an empty block inherits global targets, or uses all current providers at send time when neither block specifies targets. - Set
notify: {to: []}to disable notifications and override global targets. A route with named targets can override a disabled global default. - Docker routes with
proxy.idle_timeoutcan select targets withproxy.idle_notify_to: gotify,ntfy, or disable notifications withproxy.idle_notify_to: "". - Initial status, reloads, and dependency-only watchers stay silent; notifications report transitions rather than readiness or errors.
- Enable them globally with
- WebUI/Navigation: Header branding links to GitHub, and the version links to releases. (yusing/godoxy-webui@12f944b, webui #22)
- Core/Logging: Startup logs show effective environment settings and their sources. (4824673, e60a798)
- Sensitive setting values are redacted.
- Unknown GODOXY_ variables produce name-only warnings.
- Selected unprefixed app variables produce migration warnings but remain supported.
Breaking Changes
- Core/Listeners: HTTPS startup requires a valid certificate. (yusing/goutils@8803127, e3d7700, 1c70409, cfae89e)
- Set GODOXY_HTTPS_ADDR= for HTTP-only operation without a certificate.
- An explicitly empty HTTPS address disables shared HTTP/3 and TCP SNI routing.
- Dedicated route listeners are unaffected by disabling shared HTTPS.
- The redirectHTTP middleware skips redirects when shared HTTPS is disabled.
- Direct HTTP login requires GODOXY_API_JWT_SECURE=false.
- Keep secure login cookies when clients connect through an external TLS-terminating proxy.
- Failed startup closes partially started servers without disrupting existing TCP SNI routes.
- Core/GeoIP: MaxMind downloads City databases by default. (4824673)
- Set GODOXY_MAXMIND_COUNTRY_ONLY=true where City downloads are unavailable or Country-only data is required.
- An existing Country database does not satisfy the new default, so a City database must be downloaded.
- City databases provide the location data needed by timezone ACL rules.
- City databases can exceed 100 MiB.
- Deployment/Compose: The updated Compose example requires explicit deployment settings. (4824673)
- When adopting the updated example, populate TAG, GODOXY_UID, GODOXY_GID, DOCKER_SOCKET, and LISTEN_ADDR in .env.
- Set GODOXY_DOCKER_HOST in .env because Compose no longer injects a Docker endpoint.
Security
- Core/ACL: Later country and timezone ACL rules match correctly. (3723f81, #270)
- A nonmatching geographic rule no longer prevents a later deny or allow rule from matching.
- Core/WebSocket: Local WebSocket endpoints reject cross-host origins. (yusing/goutils@7967281)
- External reverse proxies must preserve the public Host header for same-host origin checks.
- Closed WebSocket streams report closure instead of successful empty reads or writes.
- Core/Redaction: Redacted output fully masks one- and two-character secrets. (yusing/goutils@c71a1e5)
- Unicode redaction preserves valid character boundaries and JSON output.
CI
- Contract Checks: Certificate-provider and environment contract checks run on pushes to main only when matching source, dependency, checked-output, workflow, or submodule-pointer paths change. Pull-request checks and all job steps remain unchanged. (881a4ca)
Full Changelog
- c3b184d chore(webui): track reorganized main history
- 881a4ca ci: limit contract checks to relevant push changes
- b406ad2 fix(autocert): keep duration guidance out of field labels
- b28305a fix(autocert): integrate provider form corrections
- 5974829 fix(autocert): keep concrete provider options in sync
- 3a41264 fix(autocert): guard schema-generated provider choices
- ec19a07 fix(docker): set an accessible home for the main runtime
- 1025dc0 Merge pull request #264 from taljaards/feat/idlewatcher-sleep-notifications
- d4aed0d docs(config): clarify notification and environment examples
- 518f42e Merge remote-tracking branch 'origin/main' into feat/idlewatcher-sleep-notifications
- 49e22e0 fix(serialization): preserve explicit empty slices
- 733a32f docs(idlewatcher): clarify default notification targets
- 4c884cb refactor(idlewatcher): resolve notifier from task context
- 4d4f916 refactor(idlewatcher): infer notification opt-in from targets
- 2ef64af fix(serialization): preserve explicit empty slices
- 8bdf61b refactor(idlewatcher): simplify sleep and wake notifications
- 958498c Merge remote-tracking branch 'origin/main' into feat/idlewatcher-sleep-notifications
- 8f28521 Merge pull request #273 from taljaards/codex/preserve-routes-on-partial-reload
- fbb38ea chore: merge main into partial reload fix
- 1de7944 chore(deps): update webui submodule
- 4edd178 fix(provider): limit partial reload retention to file routes
- 948dd3a chore: go mod tidy
- fcab449 chore(deps): update webui submodule (#272)
- 7adbf19 fix: preserve routes after partial reload failures
- 46399bd feat(idlewatcher)!: drop the notify event filter
- d7d6774 refactor(idlewatcher): tighten notify code and tests
- 1773b1f fix(idlewatcher): inherit global notify events
- 29e8571 chore(swagger): regenerate for idlewatcher notify config
- 0197458 feat(docker): add proxy.idle_notify labels
- 5aeffb7 feat(config): add defaults.idlewatcher.notify
- 60572b9 feat(idlewatcher): notify on sleep and wake transitions
- c1e07ca feat(idlewatcher): add sleep/wake notify config
- fce8568 fix(wiki): quote generated frontmatter metadata
- 378ac69 chore(idlewatcher): refresh minified loading script
- 11b0a93 docs(wiki): refresh dependency migration documentation
- 0b3fcfb chore(deps): update frontend tooling and webui gitlink
- e454b5d chore(deps): update backend modules and migrate major APIs
- e1557ba chore(deps): update webui submodule
- 1c70409 fix(env): support explicitly disabling shared HTTPS
- e3d7700 fix(entrypoint): preserve shared SNI listeners on startup failure
- cdeac60 fix(env): bracket IPv6 hosts in generated URLs
- 56fd47b fix(maxmind): release lookup caches on runtime cancellation
- cfae89e test(goutils): adapt fixtures to strict HTTPS startup
- 8e02291 chore(integration): align module requirements and package docs
- e60a798 feat(logging): report safe effective environment settings
- 4824673 feat(env): consume registry and generate deployment documentation
- 3723f81 fix(acl): reuse resolved country data across geographic rules
- d579b86 fix(provider): publish recovered agent names safely
- 721f423 chore(deps): sync goutils release verification budget
- d4a2571 chore(deps): advance goutils to CI-managed v0.8.0 release
- d0ff796 refactor(goutils): integrate dependency-light utility modules
- aba92f5 chore(release): prepare v0.9.3 modules
- 4850351 chore(release): normalize Go version directives to 1.27
- 6199c93 chore(release): prepare v0.9.2 modules
- cdcf062 chore(deps): update modules and migrate backoff to v6
- 75d2b8a chore(release): prepare v0.9.1 modules
- 9450745 fix(cache): release janitor registrations for runtime-owned caches
- a21196e chore(release): prepare v0.9.0 modules
- 54a0142 docs(goutils): update package behavior references
- afabe72 fix(cache): remove janitor state limit and handle concurrent registration
- 7967281 fix(websocket): correct shutdown, reader, and origin handling
- 885fea3 fix(task): allow finishing test tasks without root children
- 32bb351 fix(pool): make registry mutations atomic per key
- 78359dd fix(apitypes): skip nil errors in Error response builder
- 71fa4fe fix(env): preserve IPv6 brackets in address URLs
- 7c712ca fix(errs): handle nil unwrapped errors and empty field hints
- fae0430 docs(eventqueue): clarify queue lifecycle and callback behavior
- 04d7768 fix(fs): skip hidden entries at every directory level
- 1ab11c9 fix(http): return nil for repeated BasicAuth cache misses
- b2c17a6 fix(reverseproxy): simplify request docs and upstream scheme error log
- e7a3234 docs(intern): clarify generic handle documentation
- b573731 docs(num): clarify percentage precision and value count
- 8803127 fix(server): validate startup and roll back partial server starts
- c71a1e5 fix(strings): correct formatting, redaction, JSON encoding, and UUID generation
- 62cfe86 fix(synk): stop intercepting interrupts in pprof reporter
- 6042a0f fix(workerpool): serialize concurrent Wait calls and validate worker counts
- 05a7cb0 fix(version): make older comparisons strict
- bc3002d fix(testing): require lossless numeric equality conversions
- 2815616 docs: add goutils agent skill and package guides
- d5210f8 docs: expand package READMEs with usage and behavior guides
- 82727b3 fix(ci): cover observed Go checksum propagation delays
- 6d8914e fix(ci): allow Go publication services to observe release tags
- aa4e3bd chore(release): prepare v0.8.0 modules
- 3c23076 fix(release): reject permanently recorded Go module versions
- b0ad3b1 chore(release): prepare v0.1.0 modules
- 7260a77 ci: manage multi-module validation and releases with GitHub Actions
- 743b861 refactor!: minimize root dependencies and decouple logging
- b79f285 fix(autocert): generate and refresh concrete provider forms
- 62c54c3 docs(wiki): sync notification and deployment guidance
- a88f7f9 feat(idlewatcher): add sleep/wake notification config (#20)
- 8c80b73 docs(wiki): sync slice conversion semantics
- ce8b6af docs(wiki): sync provider reload semantics
- 12f944b Link header branding to GitHub and releases (#22)
- 176f390 fix: search app aliases when display names are empty (#21)
- de2392a chore(deps): update wiki submodule
- bba79c8 docs(wiki): sync backend dependency migration examples
- 4f366a2 chore(deps): refresh frontend dependencies and migrate openapi
- 025e9cc docs(wiki): integrate HTTP-only deployment guidance
- 9c0b122 fix(events): display names for removed pool entries
- 913eee3 docs(wiki): sync integrated implementation guides
- 1c6c013 docs(wiki): update environment contract
- fbed24b docs(wiki): update goutils dependency documentation