Changelog

Release history for Fluxheim. Full release notes are on GitHub Releases.

v1.8.0 Latest Stable View on GitHub →

Released July 23, 2026

  • +Dedicated Wasm build based on the full production profile, with bounded policy hooks, ACME, metrics, and OpenTelemetry
  • +Adds matching tar.gz and ZIP archives, including native macOS full and Wasm builds
  • +Strengthens cache-fill, range-cache, and per-vhost Wasm admission boundaries

Released July 15, 2026

  • +Adds opt-in standards-based cache, proxy, and response-digest metadata
  • +Proves authenticated live snapshot reload, rollback, integrity checks, and restart persistence
  • +Adds reproducible FIPS-backend evidence and broad native runtime hardening

Released July 14, 2026

  • +Adds bounded graceful drain and readiness-gated zero-downtime handoff
  • +Adds strict systemd socket activation with exact inherited-listener validation
  • +Completes HTTP/1 parser hardening and strengthens background-service ownership

Released July 13, 2026

  • +Adds optional HTTP response-security profiles and validated request-aware CORS
  • +Stabilizes runnable Wasm policy examples and the tests required by the release gate
  • +Strengthens forwarded identity headers, header parsing, and retry guidance for capacity limits

Released July 12, 2026

  • +Adds runnable migration examples for iRules, OpenResty, HAProxy/SPOE, and VCL-style policy jobs
  • +Adds bounded ACME transport, ARI scheduling, lifecycle diagnostics, and explicit terms acceptance
  • +Hardens recoverable ACME account and certificate transactions, storage boundaries, and snapshot publication

Released July 11, 2026

  • +Starts the opt-in WASI Preview 1 boundary with explicit clock and randomness grants and deny-by-default imports
  • +Restores trusted-client GeoIP and supports CIRCL combined Country and ASN databases
  • +Hardens stream SSRF and copying, authenticated snapshots, TLS, PHP-FPM, static serving, and Wasm resource limits

Released July 10, 2026

  • +Adds the opt-in Proxy-Wasm ABI preview with explicit host-call namespace validation
  • +Rejects unsupported preview calls deterministically before they reach an upstream
  • +Hardens strict host routing, bounded admission, config trust, cache storage, GeoIP, and compression

Released July 9, 2026

  • +Adds explicit compiled WebAssembly module identities across plugin digest, ABI, hook feature surface, and Fluxheim version
  • +Adds per-vhost cache-hook admission budgets under the process-wide cache-hook ceiling
  • +Extends bounded Wasm metrics, admin status visibility, and cross-family live-chain regression coverage

Released July 8, 2026

  • +Adds bounded cache-key component host calls for mobile and desktop device-class variants
  • +Adds fixed cache-store TTL, tag, and stored-header metadata without arbitrary response-header mutation
  • +Adds live listener coverage for variant isolation, range-cache slices, TTL expiry, and fail-closed metadata caps

Released July 7, 2026

  • +Adds live native HTTP/1 cache-lookup and cache-store Wasm hooks under the bounded fluxheim_policy_v1 preview ABI
  • +Adds cache outcomes for continue, pass, bypass, skip-store, and deny without exposing raw cache keys, TTLs, tags, or stored metadata
  • +Separates cache-hook admission limits and keeps cache-store aggregation most-restrictive-wins

Released July 6, 2026

  • +Adds live native HTTP/1 route-decision Wasm hooks under the bounded fluxheim_policy_v1 preview ABI
  • +Adds symbolic configured-branch selection for canary and mirror routes without dynamic upstream or shadow-target access
  • +Preserves Fluxheim ACL, rate-limit, concurrency, body-limit, redirect, and header-policy enforcement after route selection

Released July 5, 2026

  • +Adds live native HTTP/1 request-header and response-header Wasm hooks for vhost and route attachments
  • +Keeps the header-hook ABI symbolic with allow-listed synthetic mutations instead of raw header or body access
  • +Applies vhost-level Wasm header hooks and fallback response header policy to PHP-FPM fallback responses

Released July 4, 2026

  • +Wires live native HTTP/1 access-decision hooks with priority ordering, first-deny-wins composition, and fail-closed behavior
  • +Enforces process-wide, per-plugin, and per-attachment execution admission ceilings

Released July 3, 2026

  • +Adds the optional fluxheim-wasm workspace crate
  • +Adds wasm, wasm-proxy-abi, and wasm-wasi feature gates that stay disabled by default and incompatible with privacy-mode
  • +Loads Wasm plugin files only from approved absolute roots with symlink, non-regular file, and module-size rejection
  • +Adds a typed Wasm plugin manifest boundary with ABI, phase, fail-mode, path, and sandbox-limit validation
  • +Adds bounded Wasmtime execution with fuel, memory, table, instance, compile-timeout, compile-worker, and per-call watchdog limits
  • +Adds real Wasm sandbox smoke coverage for successful execution, traps, table-growth denial, and unsafe fail-open manifest rejection

Released July 3, 2026

  • +Updates the pinned Rust toolchain, rust-version fields, and container builder images to Rust 1.96.1
  • +Hardens OpenSSL stream-upstream TLS connectors with a TLS 1.2 minimum and a modern TLS 1.2/TLS 1.3 cipher allowlist
  • +Stores serialized ACME account credentials in sanitization::SecretVec while writing them to disk
  • +Removes remaining root compatibility shims so callers use fluxheim-common, fluxheim-config, fluxheim-cache, fluxheim-observability, and the other owning crates directly
  • +Splits ACME, observability, cache, load-balancer, PHP-FPM, snapshot, web, stream, and native runtime internals into smaller focused modules

Released June 30, 2026

  • +Renames the temporary native proxy shim to native_proxy and removes the old proxy compatibility re-export from normal builds
  • +Moves load-balancer admin request and result DTOs into the fluxheim-load-balancer crate
  • +Deletes inert Pingora-era root adapters and stale disabled runtime/test code that normal builds no longer use
  • +Consolidates native proxy config storage so reloads refresh the same snapshot used by cache and load-balancer admin paths
  • +Adds native HTTP/1 chunked-body overflow regression coverage and pins observability smoke images to deterministic tags

Released June 30, 2026

  • +Keeps the normal runtime on Fluxheim-owned listener, TLS, HTTP/1, HTTP/2, WebSocket, cache, load-balancer, admin, metrics, stream, and background service paths
  • +Moves auth, metrics, OpenBao cache, discovery, load-balancer cookie, and TLS private-key secret buffers toward the sanitization crate
  • +Hardens PHP-FPM/static fallback routing, native disk-cache purge locking, same-key disk-cache mutation serialization, and native HTTP/2 upstream authority handling
  • +Adds peer-fill shared-secret support and requires it for non-loopback plaintext peer-fill URLs
  • +Extends privacy, observability, WordPress, load-balancer, smoke-image, randomized-port, and release-gate test coverage for the stabilization line

Released June 29, 2026

  • +Removes the final Pingora runtime/listener/TLS adapter crates from normal Fluxheim build profiles
  • +Keeps the native HTTP/1 and HTTP/2 proxy runtime as the normal path for supported route, cache, load-balancer, TLS, WebSocket, admin, and metrics configurations
  • +Wires native admin cache purge, stale disk-cache purge, cache object lookup, and live load-balancer stats/mutation handlers to Fluxheim-owned runtime handles
  • +Updates dependency-policy release gates so normal default, full, edge, PHP, privacy, RPM, source, and container builds fail if they compile Pingora crates
  • +Hardens native admin cache previews and purges with normalized host matching, regex-route previews, stale purge lock avoidance, fail-closed live config state, and typed route-proxy build contexts

Released June 29, 2026

  • +Adds native proxy-cache parity for memory, filesystem disk, storage-bin, encrypted disk, OpenBao Transit, and memory+disk tiering
  • +Supports Vary and request-header variants, stale serving, cache locks, range slice cache, peer-fill, and origin-protection budgets
  • +Hardens cache admission for Authorization, HEAD bypass, upstream Age stripping, checked expiry arithmetic, and only-if-cached misses
  • +Adds native cache purge parity for memory and disk indexes plus exact, bulk, prefix, tag, wildcard, route-scope, and stale purges
  • +Adds native cache observability for proxy counters, memory/disk gauges, cache lookup histograms, and regenerated traceparent span IDs

Released June 28, 2026

  • +Adds native runtime dispatch for proxy, admin, metrics, stream, UDP, and load-balancer refresh tasks
  • +Adds metrics token-file loading with zeroizing storage and constant-time bearer-token checks
  • +Adds native HTTP/1 proxy runtime startup for plaintext, rustls, OpenSSL, and trusted downstream PROXY protocol listeners
  • +Routes selected downstream HTTP/2 TLS connections into the native multi-stream adapter
  • +Hardens native WebSocket upgrades, HTTP/2 stream-local failures, rate-limit sharding, and zeroizing request-body storage

Released June 24, 2026

  • +Moves cache request policy and local-static cache keys into the Pingora-independent fluxheim-cache crate
  • +Moves PHP-FPM parsing, params, path mapping, static offload, error-page policy, and keep-alive pooling into fluxheim-php-fpm
  • +Adds native memory local-static cache adapters for route and vhost static-web serving
  • +Adds native upstream PROXY protocol v1/v2 send support and native Host router construction
  • +Adds native runtime manifest and launch-plan evidence for services, listeners, background tasks, and policy rows

Released June 23, 2026

  • +Moves plaintext upstream HTTP/2 forwarding into the native HTTP/1 proxy path for h2c/prior-knowledge origins
  • +Adds pooled native upstream H2 connections with bounded stream capacity and safe-method retry after pre-response pooled-handle failure
  • +Supports TLS ALPN-negotiated upstream HTTP/2 with existing upstream TLS/SNI/CA policy
  • +Adds explicit, disabled-by-default h2c Upgrade fallback for plaintext http1-and-http2 origins
  • +Bounds native upstream H2 handshakes, stream-slot waits, keepalive pings, and setup timeouts

Released June 23, 2026

  • +Moves inherited global/vhost compression policy into the native HTTP/1 proxy and route proxy
  • +Merges root/vhost/route header-policy inheritance into native route proxy construction
  • +Moves safe forwarded-client-IP ownership, trusted-chain append, regex rewrites, ACLs, concurrency, and rate limits onto the native path
  • +Adds native ACME HTTP-01 challenge serving, traffic mirroring, auth-request, and route-scoped gRPC validation

Released June 21, 2026

  • +Moves route-level native response compression onto the HTTP/1 route proxy through fluxheim-compression
  • +Moves proxy.error_pages onto native HTTP/1 proxy fallback pages backed by fluxheim-web

Released June 21, 2026

  • +Adds native HTTP/1 route static-web serving backed by fluxheim-web
  • +Adds route request-header mutation, response rewrites, static upstream round-robin, and static upstream weights to the native route proxy

Released June 21, 2026

  • +Adds native route redirect actions with safe {uri}, {path}, and {query} expansion
  • +Moves route body limits and response-header overlays onto native HTTP/1 route proxy responses

Released June 21, 2026

  • +Adds native HTTP/1 route-proxy execution for exact, prefix, and fallback routes with method filters and safe rewrite handling
  • +Adds native-http1-proxy-candidate rows to runtime cutover evidence so remaining compatibility blockers are explicit

Released June 20, 2026

  • +Promotes the native HTTP/2 downstream safety preview to cutover-ready after focused parity tests
  • +Makes the representative native runtime cutover report blocker-free for simple HTTP/1, HTTP/2, admin, metrics, stream, and UDP configurations

Released June 20, 2026

  • +Cuts stream and UDP proxy service startup over to Fluxheim-owned native task boundaries
  • +Adds cancellation-safe native shutdown waiting and abort-on-cancel background task joins

Released June 20, 2026

  • +Starts native admin and metrics serving behind Fluxheim-owned server primitives
  • +Hardens native background handles so dropped critical handles abort instead of silently detaching tasks

Released June 20, 2026

  • +Adds NativeBackgroundSupervisor for Fluxheim-owned background task orchestration
  • +Adds critical task watchdog support and hardens shutdown delivery edge cases

Released June 20, 2026

  • +Adds native runtime cutover evidence gates and fluxheim-config-tester --runtime-cutover
  • +Moves remaining Pingora exception targets to a documented multi-release exit plan while keeping policy gates active

Released June 19, 2026

  • +Adds explicit pingora-compat feature gating for the remaining compatibility runtime boundary
  • +Moves rustls/OpenSSL downstream TLS SNI, certificate storage, reload, PEM parsing, and native HTTP/1 TLS listener previews into Fluxheim-owned code

Released June 19, 2026

  • +Continues the Pingora-exit slice by shrinking the remaining root compatibility surface for proxy, cache, and runtime paths
  • +Splits native health checks into HTTP/gRPC, database, exec, and TCP/TLS transport helper modules with stricter probe bounds

Released June 19, 2026

  • +Removes the direct Pingora dependency from fluxheim-load-balancer
  • +Adds Fluxheim-owned bounded HTTP/1.1 and h2 gRPC active health checks with policy coverage to prevent Pingora reintroduction

Released June 19, 2026

  • +Adds native HTTP/1.1 proxy cutover readiness planning on ServerPlan
  • +Fails closed for compatibility-only proxy features such as auth subrequests, mirroring, redirects, strip/rewrite transforms, and advanced load-balancer policy

Released June 18, 2026

  • +Adds a Fluxheim-owned native HTTP/2 upstream client primitive with bounded headers, bodies, trailers, and deadlines
  • +Adds h2 client/server tests for trailer preservation, oversized responses, stream resets, and flow-control timeout behavior

Released June 18, 2026

  • +Adds native rustls/OpenSSL upstream TLS and mTLS support to the staged HTTP/1.1 proxy path
  • +Adds ordered static upstream failover for safe methods plus bounded no-follow TLS material reads and hostname-policy coverage

Released June 18, 2026

  • +Adds bounded native HTTP/1.1 upstream connection pooling for safe content-length and no-body origin responses
  • +Adds keepalive pool sizing, upstream idle timeout handling, conservative no-reuse guards, and real socket reuse/expiry tests

Released June 18, 2026

  • +Adds reusable native HTTP/2 connection primitives with bounded request-body collection and response trailer support
  • +Hardens HTTP/2 response lifetime, handler timeout, DATA capacity handling, prohibited headers/trailers, and request-body zeroization

Released June 17, 2026

  • +Adds the native HTTP/2 runtime preview gate and h2 stack probe with bounded headers, URI, body, streams, frames, buffers, and rapid reset policy
  • +Adds HTTP/2 preview smoke coverage and extends native HTTP/1 behavior coverage for HTTP/1.0 keep-alive/close semantics

Released June 17, 2026

  • +Adds the bounded native HTTP/1 upstream client and staged native proxy handler for plain static upstreams
  • +Adds native proxy candidate inventory, Fluxheim-owned proxy headers, privacy-mode behavior, and fail-closed eligibility for unsupported policy layers

Released June 17, 2026

  • +Adds the native HTTP/1 connection/listener runtime over Tokio IO and staged native static-file adapter
  • +Maps server limits into native HTTP/1 policy and adds socket tests for keep-alive, body framing, shutdown, static files, slow clients, and connection caps

Released June 17, 2026

  • +Adds Fluxheim-owned HTTP/1.0/HTTP/1.1 request-head parsing, request-body framing classification, Host validation, persistence handling, and chunked decoding
  • +Adds downstream HTTP/1 policy defaults and hardened native parser boundaries for future runtime cutover work

Released June 16, 2026

  • +Moves server bootstrap planning, listener inventory, service intent, background-task intent, HTTP/2 policy, PROXY protocol policy, and private Unix socket planning into fluxheim-server
  • +Keeps the current runtime as an explicit compatibility adapter while native server/listener work continues

Released June 16, 2026

  • +Adds fluxheim-tls as the downstream TLS listener planning and provider-policy boundary
  • +Moves TLS listener plans, SNI selection, wildcard matching, ALPN/cipher/curve policy, and rustls/OpenSSL provider checks into the TLS crate
  • +Hardens TLS feature gates, SNI fallback behavior, PROXY v2 signature validation, and trusted PROXY CIDR validation

Released June 16, 2026

  • +Adds the first dedicated fluxheim-headers boundary for header policy helpers
  • +Moves rewrite algorithms, forwarded-header handling, hop-by-hop request policy, and repeated-header joining into Fluxheim-owned header code
  • +Moves stream PROXY protocol byte parsers into fluxheim-protocol and tightens privacy/proxy CIDR validation

Released June 15, 2026

  • +Moves shared background task lifecycle primitives into fluxheim-runtime
  • +Moves OTLP metrics export, ACME certificate reload control, admin snapshot validation state, and rollback decisions into Fluxheim-owned runtime/snapshot code
  • +Hardens the local certificate reload control socket and private backend filtering

Released June 15, 2026

  • +Adds fluxheim-stream as the internal TCP stream proxy runtime boundary
  • +Moves stream upstream selection, PROXY protocol parsing/writing, source policy, DNS-rebinding guards, byte accounting, and timeout handling behind Fluxheim-owned stream code

Released June 14, 2026

  • +Moves cache key identity, object envelopes, disk index management, storage-bin helpers, tag handling, and cache storage interfaces into fluxheim-cache
  • +Adds tests and release gates that enforce Pingora dependency removal targets during normal cargo test runs

Released June 14, 2026

  • +Starts the first concrete 1.6.x implementation release after the foundation tag
  • +Removes pingora-load-balancing/pingora-ketama from full and load-balancer image profiles, restores 1.6 load-balancer image builds, and moves TCP health checks plus request-key extraction behind Fluxheim-owned boundaries

Released June 14, 2026

  • +Started the 1.6.x Pingora-exit foundation line while keeping runtime behavior unchanged
  • +Added modularity policy validation, legacy oversized-file exceptions, runtime baseline capture, and performance evidence capture
  • +Added release-gated Pingora dependency exceptions, runtime parity fixtures, and the extraction dependency graph
  • +Added initial fluxheim-runtime and fluxheim-server boundary crates plus typed policy proof primitives
v1.5.0 - v1.5.23 All on GitHub ->

June 2026

  • +Introduced the enterprise HTTP/TCP load-balancer line with focused binaries, images, runtime member and weight controls, persistence, health checks, queueing, and migration docs
  • +Expanded Fluxheim-owned runtime boundaries across HTTP, stream proxying, load balancing, background tasks, cache interfaces, observability, config, and shared crates
  • +Added managed affinity cookies, service discovery, active and protocol-aware health checks, restart-persistent state, and runtime backend mutation controls
  • +Added UDP beta guardrails, cache origin-protection budgets, ARM/Linux and macOS developer assets, config tester archives, and broad proxy/cache/PHP-FPM security hardening

Released May 25, 2026

  • +Production proxy parity release with trusted-proxy-aware ACLs, local rate limits, concurrency limits, bounded queues, and edge policy metrics
  • +gzip, Zstandard, and Brotli response compression with vhost/route overrides and cache-safe Vary handling
  • +Load-balancer resilience, TLS/protocol parity, PROXY protocol v1/v2, upstream mTLS, HTTP/2 controls, and gRPC pass-through

Released May 23, 2026

  • +Managed php-fpm process supervision under the existing php-fpm feature, while external php-fpm remains the default
  • +Respawn watchdog, bounded backoff, SIGTERM-before-SIGKILL teardown, sanitized environment, and private generated pool state
  • +Auditable [vhosts.php.fpm] mode = "managed" config surface for private sockets, worker counts, process manager modes, slowlog, temp paths, and pool files
  • +Expanded WordPress PHP-FPM smoke coverage across external, managed-static, managed-dynamic, managed-ondemand, and managed-respawn modes
  • +Recommended Wolfi PHP image now installs php-8.5-fpm and uses managed php-fpm container config by default

Released May 23, 2026

  • +FIPS/ISO-required configs fail closed for unsupported internal cryptography, managed ACME, and local cache encryption
  • +Provider-backed admin auth, numeric-local-loopback OTLP exception, and OpenBao Transit cache encryption evidence boundary
  • +New compliance evidence template and release evidence package sections for regulated reviews

Released May 22, 2026

  • +rustls/AWS-LC FIPS-capable candidate backend through tls-rustls-fips
  • +FIPS and ISO/IEC 19790 rustls profile aliases, config examples, diagnostics, and validation script

Released May 21, 2026

  • +OpenSSL FIPS/ISO-capable TLS validation through tls-openssl-fips and provider diagnostics
  • +FIPS deployment guide, config fixtures, validation script, release evidence, and OWASP Top 10 2025 baseline

Released May 20, 2026

  • +PHP-FPM keepalive pooling, upstream retry/failover, and request body disk spooling for safer operation under load
  • +WordPress routing/cache preset plus PHP application recipes for common framework and forum deployments
  • +PHP metrics and OpenTelemetry attributes, X-Accel-Redirect, X-Sendfile, and X-Accel-Expires support

Released May 18, 2026

  • +fluxheim-acme standalone companion binary for certificate renewal, status, and ACME reload socket signalling
  • +fluxheim-config-tester standalone binary for validating configs in CI and container entrypoints without starting the gateway
  • +ACME reload Unix socket — live certificate pickup without gateway restart
  • +New profile-php build profile — proxy + web + php-fpm + tls-rustls + security
  • +Security hardening improvements across the request pipeline

Released May 16, 2026

  • +Opt-in PHP-FPM FastCGI bridge for WordPress-style front-controller applications
  • +Strict script resolution and bounded FastCGI request/response handling
  • +Browser-validated WordPress proxy/PHP cookie compatibility fixes
  • +PHP-FPM can serve static assets from same root while routing PHP to FPM
  • +New php-fpm Cargo feature (implies proxy and web)

Released May 14, 2026

  • +Shared ingress/TLS feature-graph split — focused cache and proxy profiles are now TLS/ACME-capable
  • +New profile-cache-edge — cache without static web module
  • +New profile-proxy-edge — focused reverse proxy edge
  • +Official focused container images for cache and proxy profiles
v1.2.x Series

May 2026

v1.2.6

  • + Fixed-slice range-cache composition: open-ended, suffix, and multipart byte-range
  • + Opt-in range_slice_cache = true extends bounded range caching

v1.2.5

  • + Bounded range caching for large proxy-cache objects

v1.2.4

  • + Distributed cache peer fill with safe only-if-cached peer fetches
  • + Bounded fail-open/fail-closed peer fill behavior

v1.2.3

  • + Optional disk cache encryption with local keys or OpenBao Transit

v1.2.2

  • + Storage-bin disk cache backend for larger high-churn caches

v1.2.1

  • + Opt-in local static-file caching via local_static = true

v1.2.0 — Cache & Observability Baseline

  • + Vhost/route cache policy, memory/disk/tiered cache backends
  • + Cache locks, stale serving, purge and status endpoints
  • + Cache warm, key assertion, and lookup tooling
  • + Prometheus metrics listener
  • + OpenTelemetry export profiles (metrics + tracing)
v1.1 — Certificate Operations

2026

  • + TLS policy profiles
  • + Multi-certificate rustls SNI
  • + Managed ACME certificate issuance and renewal
  • + EAB-capable issuers (Actalis and others)
  • + File-backed TLS secrets
  • + acme-init guided issuer bootstrap tool
  • + Packaged certificate renewal systemd units
v1.0 — Gateway Foundation Initial Stable

2026

  • + Virtual host routing by Host header with default-vhost fallback
  • + Route-level static, proxy, and redirect actions
  • + Static file serving with MIME detection, ETag, conditional 304, byte ranges
  • + Whole-vhost and route-level reverse proxying
  • + rustls TLS with SNI, static/bought certificate support
  • + Safe ACME HTTP-01 challenge forwarding
  • + Admin control-plane with bearer-token auth and brute-force throttling
  • + Secure request/response header policy
  • + Optional HTTP → HTTPS redirect with safe Host validation
  • + Systemd unit, RPM packaging
  • + Rootless Podman container images

What's Next

1.8.0: Dedicated Wasm build based on the full production profile, with bounded policy hooks, ACME, metrics, and OpenTelemetry.

View full roadmap →
English (US)