Feroaringslog
Release skiednis foar Fluxheim. Folsleine release-notysjes binne oan GitHub-releases.
Utbrocht op 23 july 2026
- +Aparte Wasm-build op basis fan it folsleine produksjeprofyl, mei beheinde beliedshooks, ACME, metriken en OpenTelemetry
- +Foeget oerienkommende tar.gz- en ZIP-argiven ta, mei native folsleine en Wasm-builds foar macOS
- +Fersterket de talittingsgrinzen foar cache-folling, berik-cache en Wasm per vhost
Utjûn op 15 july 2026
- +Foeget opt-in noarmen-basearre cache, proxy, en antwurd-digest metadata ta
- +Bewiist authentisearre live snapshot opnij laden, weromdraaien, yntegriteitskontrôles en persistinsje opnij starte
- +Foeget reprodusearber FIPS-backend-bewiis ta en brede native runtime-harding
Utjûn op 14 july 2026
- +Foeget it behearske ôfsluten fan besteande ferbiningen binnen in fêste tiid en in troch reeheidskontrôles stjoerde oerdracht sûnder ûnderbrekking ta
- +Foeget strange systemd-socketaktivearring ta mei krekte falidaasje fan oernommen netwurklisteners
- +Foltôget de fersterking fan de HTTP/1-parser en ferbetteret it behear fan eftergrûntsjinsten
Utjûn op 13 july 2026
- +Foeget opsjonele HTTP-antwurdbefeiligingsprofilen ta en validearre CORS-bewuste fersyk
- +Stabilizes runnable Wasm belied foarbylden en de tests easke troch de release poarte
- +Fersterket trochstjoerde identiteitkoppen, parsearjen fan kopteksten, en begelieding opnij besykje foar kapasiteitsgrinzen
Released 12 july 2026
- +Foeget runnable migraasjefoarbylden ta foar iRules, OpenResty, HAProxy/SPOE, en VCL-styl beliedtaken
- +Foeget beheine ACME-ferfier, ARI-skema, libbenssyklusdiagnoaze, en eksplisite akseptaasje fan termen ta
- +Hardens werom te heljen ACME account en sertifikaat transaksjes, opslach grinzen, en snapshot publikaasje
Utbrocht op 11 july 2026
- +Start de opsjonele WASI Preview 1-grins mei dúdlike tastimmingen foar klok en willekeur; ymporten wurde standert wegere
- +Resteurt trusted-client GeoIP en stipet CIRCL-kombinere Country en ASN-databanken
- +Fersterkt stroom-SSRF en kopiearjen, geautentikeerde snapshots, TLS, PHP-FPM, statyske serving, en Wasm-brûkslimitten
Utbrocht op 10 july 2026
- +Foeget de opsjonele Proxy-Wasm ABI-foarbyld ta mei eksplisite falidaasje fan de nammeromte foar host-oanroppen
- +Wegeret net-stipe foarbyldoanroppen deterministysk foardat se in upstream-tsjinner berikke
- +Ferhurdet strange host-routing, beheinde talitting, fertrouwen yn konfiguraasje, cache-opslach, GeoIP en kompresje
Utbrocht op 9 july 2026
- +Foeget eksplisite identiteiten fan kompilearre WebAssembly-modulen ta oer plugin digest, ABI, hook-feature-oerflak en Fluxheim-ferzje
- +Foeget talittingsbudzjetten foar cache-hooks per vhost ta ûnder it prosesbrede cache-hook-plafond
- +Wreidet beheinde Wasm-metriken, admin status-sichtberens en cross-family live-chain-regresjedekking út
Utbrocht op 8 july 2026
- +Foeget beheinde cache-key-component-host-calls ta foar mobile en desktop device-class-farianten
- +Foeget fêste cache-store TTL, tag en stored-header metadata ta sûnder willekeurige response-header-mutaasje
- +Foeget live-listener-dekking ta foar fariant-isolaasje, range-cache slices, TTL-ferrin en fail-closed metadata-limiten
Utbrocht op 7 july 2026
- +Foegje live native HTTP/1 cache-lookup- en cache-store-Wasm-hooks ta ûnder de begrinze fluxheim_policy_v1 preview-ABI
- +Foegje cache-útkomsten ta foar continue, pass, bypass, skip-store en deny, sûnder rauwe cache-keys, TTLs, tags of bewarre metadata bleat te lizzen
- +Skiedt admission-limiten foar cache-hooks en hâldt cache-store-aggregaasje op most-restrictive-wins
Utbrocht op 6 july 2026
- +Foegje live native HTTP/1 route-decision Wasm-hooks ta ûnder de begrinze fluxheim_policy_v1 preview-ABI
- +Foegje symboalyske seleksje fan ynstelde branches ta foar canary- en mirror-routes, sûnder dynamyske upstream- of shadow-target-tagong
- +Hâldt Fluxheim ACL, rate-limit, concurrency, body-limit, redirect en header-policy hanthavening nei routeseleksje
Utbrocht op 5 july 2026
- +Foegt live native HTTP/1 Wasm-hooks foar request-header en response-header ta foar vhost- en route-keppelingen
- +Hâldt de header-hook-ABI symbolysk mei tastiene syntetyske mutaasjes ynstee fan rauwe tagong ta headers of body
- +Past vhost-level Wasm header-hooks en fallback response header policy ta op PHP-FPM fallback-antwurden
Utbrocht op 4 july 2026
- +Ferbynt live native HTTP/1 access-decision hooks mei prioriteitsfolchoarder, first-deny-wins gearstalling en fail-closed gedrach
- +Hanthavet útfieringsadmission-plafonds per proses, plugin en attachment
Utbrocht op 3 july 2026
- +Foegje de opsjonele fluxheim-wasm workspace-crate ta foar de Wasm-sandboxline
- +feature gates wasm, wasm-proxy-abi en wasm-wasi steane standert út en passe net by privacy-mode
- +Laadt Wasm-pluginbestannen allinnich út goedkarde absolute roots; symlinks, net-reguliere bestannen en te grutte modules wurde wegere
- +Typearre Wasm-pluginmanifesten validearje ABI, faze, fail-mode, paad en sandboxlimiten foar it laden
- +Foegje begrinze Wasmtime-útfiering ta mei limiten foar fuel, memory, table, instance, compile-timeout, compile-worker en per-call watchdog
- +Foegje echte Wasm-sandbox-smokedekking ta foar suksesfolle útfiering, traps, wegere table-growth en ôfwizing fan ûnfeilige fail-open-manifesten
Utbrocht op 3 july 2026
- +Fernijt de fêstpinde Rust-toolchain, de rust-version fjilden en de containerbou-ôfbylden nei Rust 1.96.1
- +Ferhurdet OpenSSL stream-upstream TLS-ferbiners mei TLS 1.2 as minimum en in moderne TLS 1.2/TLS 1.3 cipher-allowlist
- +Bewarret serialisearre ACME-akkountgegevens yn sanitization::SecretVec wylst se nei skiif skreaun wurde
- +Hellet de oerbleaune root-kompatibiliteitsshims fuort sadat callers fluxheim-common, fluxheim-config, fluxheim-cache, fluxheim-observability en oare eigener-crates direkt brûke
- +Dielt ACME, observability, cache, load-balancer, PHP-FPM, snapshot, web, stream en native runtime-ynternen op yn lytsere rjochte modules
Utjûn op 30 juni 2026
- +Neamt de tydlike native proxy-tuskenlaach om ta native_proxy en hellet de âlde werútfier foar proxy-kompatibiliteit út gewoane builds
- +Ferpleatst de DTO's foar behearfersiken en -resultaten fan de load-balancer nei de fluxheim-load-balancer-crate
- +Smyt ûnbrûkte root-adapters út it Pingora-tiidrek en ferâldere, útskeakele runtime- en testkoade fuort dy't gewoane builds net mear brûke
- +Foegje de opslach fan native proxy-konfiguraasje gear, sadat opnij laden deselde momintopname ferfarsket dy't de behearpaden foar cache en load-balancer brûke
- +Foegje regresjetests ta foar oerstreaming fan native HTTP/1-bodies mei chunked-kodearring en set observability-smoke-images fêst op deterministyske tags
Utjûn op 30 juni 2026
- +Hâldt de normale runtime op paden Fluxheim-owned listener, TLS, HTTP/1, HTTP/2, WebSocket, cache, load-balancer, admin, metrics, stream, en background service
- +Beweegt auth, metrics, OpenBao cache, discovery, load-balancer cookie, en TLS private-key secret buffers nei de sanitization crate
- +Hardens PHP-FPM/static fallback routing, native disk-cache purge locking, same-key disk-cache mutaasje serialisaasje, en native HTTP/2 upstream authority handling
- +Foeget peer-fill shared-secret-stipe ta en fereasket it foar non-loopback platte tekst peer-fill URLs
- +Wreidet privacy, observability, WordPress, load-balancer, smoke-image, randomized-port, en release-gate testdekking út foar de stabilization-line
Utbrocht op 29 juny 2026
- +Ferwideret de lêste Pingora runtime/listener/TLS adapter crates fan normale Fluxheim build profiles
- +Hâldt de native HTTP/1 en HTTP/2 proxy runtime as it normale paad foar stipe route, cache, load-balancer, TLS, WebSocket, admin, en metrics konfiguraasjes
- +Wires native admin cache purge, stale disk-cache purge, cache objekt sykjen, en live load-balancer stats / mutaasje handlers nei Fluxheim-owned runtime handgrepen
- +Updates fan dependency-policy-release-poarten, sadat normale standert, folslein, râne, PHP, privacy, RPM, boarne, en kontenerbouwen mislearje as se Pingora crates kompilearje
- +Hardens native admin cache previews en purges mei normalisearre host-oerienkomst, regex-route previews, stale purge lock mijen, fail-closed live config state, en typte route-proxy build konteksten
Utbrocht op 29 juny 2026
- +Foeget native proxy-cache parity ta foar ûnthâld, triemsysteemskiif, storage-bin, fersifere skiif, OpenBao Transit, en memory+disk tiering
- +Unterstützt Vary- en request-header-farianten, ferâldere serving, cache-slûzen, berik slice-cache, peer-fill, en budzjetten foar oarsprongbeskerming
- +Ferhardt cache-tagong foar Authorization, HEAD bypass, streamopôf Age stripping, kontrolearre ferrin arithmetic, en only-if-cached mist
- +Foeget native cache purge parity ta foar ûnthâld- en skiifyndeksen plus eksakte, bulk, prefix, tag, jokerteken, route-scope, en muffe suveringen
- +Foeget native cache-observabiliteit ta foar proxytellers, ûnthâld-/skiifmeters, cache-opsykhistogrammen, en regenerearre traceparent span-ID's
Utbrocht op 28 juny 2026
- +Adds native runtime dispatch for proxy, admin, metrics, stream, UDP, and load-balancer refresh tasks
- +Adds metrics token-file loading with zeroizing storage and constant-time bearer-token checks
- +Adds native HTTP/1 proxy runtime startup for plaintext, rustls, OpenSSL, and trusted downstream PROXY protocol listeners
- +Rûtearret selektearre downstream HTTP/2 TLS-ferbiningen nei de native multi-stream-adapter
- +Ferhurdet native WebSocket-upgrades, HTTP/2 stream-lokale flaters, rate-limit sharding en zeroizing-opslach fan it request-body
Utbrocht op 24 juny 2026
- +Moves cache request policy and local-static cache keys into the Pingora-independent
fluxheim-cachecrate - +Moves PHP-FPM parsing, params, path mapping, static offload, error-page policy, and keep-alive pooling into
fluxheim-php-fpm - +Adds native memory local-static cache adapters for route and vhost static-web serving
- +Adds native upstream PROXY protocol v1/v2 send support and native Host router construction
- +Adds native runtime manifest and launch-plan evidence for services, listeners, background tasks, and policy rows
Utjûn op 23 juni 2026
- +Ferpleatst platte tekst streamopwaarts HTTP/2-trochstjoering yn it eigen HTTP/1-proxypaad foar h2c/foarkennis oarsprong
- +Foeget gearfoege native upstream H2-ferbiningen ta mei beheine streamkapasiteit en op 'e nij besykjen fan feilige metoade nei pre-antwurd mislearre gearfoeging
- +Unterstützt TLS ALPN-ûnderhannele streamop HTTP/2 mei besteande streamopop TLS/SNI/CA-belied
- +Foeget eksplisite, standert útskeakele h2c Upgrade fallback ta foar platte tekst
http1-and-http2oarsprong - +Beheint native upstream H2-handshakes, stream-slot-wachttiden, keepalive-pings, en setup-timeouts
Utjûn op 23 juni 2026
- +Ferpleatst erfde globale / vhost-kompresjebelied yn 'e eigen HTTP/1-proxy en rûteproxy
- +Kombinearret root/vhost/route header-belied erfskip yn native route proxy konstruksje
- +Ferpleatst feilich trochstjoerd-client-IP-eigendom, fertroude keten taheakjen, regex-herskriuwen, ACL's, tagelyk, en taryfgrinzen nei it native paad
- +Foeget native ACME HTTP-01-útdagingsserving ta, ferkearsspegeljen, auth-fersyk, en gRPC-validaasje
Utjûn op 21 juny 2026
- +Moves route-level native response compression onto the HTTP/1 route proxy through
fluxheim-compression - +Moves
proxy.error_pagesonto native HTTP/1 proxy fallback siden stipe trochfluxheim-web
Utjûn op 21 juny 2026
- +Adds native HTTP/1 route static-web serving backed by
fluxheim-web - +Adds route request-header mutation, response rewrites, static upstream round-robin, and static upstream weights to the native route proxy
Utjûn op 21 juny 2026
- +Adds native route redirect actions with safe
{uri},{path}, and{query}expansion - +Moves route body limits and response-header overlays onto native HTTP/1 route proxy responses
Utjûn op 21 juny 2026
- +Adds native HTTP/1 route-proxy execution for exact, prefix, and fallback routes with method filters and safe rewrite handling
- +Adds
native-http1-proxy-candidaterigen nei runtime cutover bewiis, sadat oerbleaune kompatibiliteitsblokkers eksplisyt binne
Utjûn op 20 juny 2026
- +Promovearret de native HTTP/2 downstream feiligensfoarbyld nei cutover-klear nei rjochte pariteitstests
- +Makket it represintative native runtime cutover rapport blockerfrij foar ienfâldige HTTP/1, HTTP/2, admin, metriken, stream, en UDP konfiguraasjes
Utjûn op 20 juny 2026
- +Cuts stream and UDP proxy service startup over to Fluxheim-owned native task boundaries
- +Adds cancellation-safe native shutdown waiting and abort-on-cancel background task joins
Utjûn op 20 juny 2026
- +Starts native admin and metrics serving behind Fluxheim-owned server primitives
- +Ferhurdet native eftergrûnhandgrepen, sadat krityske hânfetten falle ôfbrekke ynstee fan taken stil los te meitsjen
Utjûn op 20 juny 2026
- +Adds
NativeBackgroundSupervisorfoar Fluxheim-eigendom eftergrûn taak orkestraasje - +Adds critical task watchdog support and hardens shutdown delivery edge cases
Utjûn op 20 juny 2026
- +Adds native runtime cutover evidence gates and
fluxheim-config-tester --runtime-cutover - +Moves remaining Pingora exception targets to a documented multi-release exit plan while keeping policy gates active
Utjûn op 19 juny 2026
- +Adds explicit
pingora-compatfunksje gating foar de oerbleaune kompatibiliteit runtime grins - +Moves rustls/OpenSSL downstream TLS SNI, certificate storage, reload, PEM parsing, and native HTTP/1 TLS listener previews into Fluxheim-owned code
Utjûn op 19 juny 2026
- +Ferfolget de Pingora-útgongslice troch it oerbleaune oerflak fan rootkompatibiliteit te krimpen foar proxy-, cache- en runtimepaden
- +Split native sûnenskontrôles yn HTTP/gRPC, database, exec, en TCP/TLS transporthelpermodules mei strangere probegrinzen
Utjûn op 19 juny 2026
- +Ferwiderje de direkte Pingora-ôfhinklikens fan
fluxheim-load-balancer - +Foeget ta beheine HTTP/1.1 en h2 gRPC aktive sûnenskontrôles yn eigendom fan Fluxheim mei beliedsdekking om weryntroduksje fan Pingora te foarkommen
Utjûn op 19 juny 2026
- +Foeget native HTTP/1.1 proxy cutover reewilligens plannen ta oan
ServerPlan - +Mislearre sluten foar kompatibiliteit-allinich proxy-funksjes lykas auth-subrequests, spegeljen, trochferwizings, strip-/herskriuwe-transformaasjes, en avansearre load-balancer-belied
Utjûn op 18 juny 2026
- +Foeget in native HTTP/2 upstream client primitive ta mei Fluxheim-eigendom mei beheinde kopteksten, lichems, trailers en deadlines
- +Foeget h2-kliïnt-/servertests ta foar behâld fan trailers, te grutte antwurden, streamresets, en time-outgedrach foar streamkontrôle
Utjûn op 18 juny 2026
- +Foeget native rustls / OpenSSL upstream TLS en mTLS-stipe ta oan it opstelde HTTP / 1.1 proxypaad
- +Foeget bestelde statyske stroomopwaartse failover ta foar feilige metoaden plus beheinde no-folgjende TLS-materiaallêzen en hostnammebeliedsdekking
Utjûn op 18 juny 2026
- +Foeget begrinzge native HTTP/1.1 upstream ferbining pooling ta foar feilige ynhâld-lingte en gjin-lichem oarsprong antwurden
- +Foeget keepalive swimbad grutte ta, streamopôfhanneling fan idle time-out, konservative net-wergebrûk guards, en echte socket wergebrûk / ferfalstests
Utjûn op 18 juny 2026
- +Foeget werbrûkbere native HTTP/2-ferbiningsprimitiven ta mei beheine fersyk-lichem-kolleksje en antwurd-trailer-stipe
- +Ferhurdet HTTP/2-antwurdlibben, time-out fan handler, ôfhanneling fan DATA-kapasiteit, ferbeane kopteksten / trailers, en nulisaasje fan fersyk-lichem
Utjûn op 17 juny 2026
- +Foeget de native HTTP/2 runtime preview poarte en h2 stack probe ta mei beheine kopteksten, URI, lichem, streamen, frames, buffers, en belied foar rappe reset
- +Foeget HTTP/2 preview smoke dekking ta en wreidet native HTTP/1 gedrachsdekking út foar HTTP/1.0 keep-alive/close semantyk
Utjûn op 17 juny 2026
- +Foeget de begrinzge native HTTP/1 upstream-kliïnt en stadiche native proxy-hantler ta foar gewoane statyske upstreams
- +Foeget native proxy-kandidaatynventaris ta, proxy-headers yn eigendom fan Fluxheim, gedrach yn privacymodus, en mislearre yn oanmerking foar net-stipe beliedslagen
Utjûn op 17 juny 2026
- +Foeget de native HTTP/1-ferbining/harker-runtime ta oer Tokio IO en opstelde native statyske bestânadapter
- +Maps-tsjinner beheint yn eigen HTTP/1-belied en foeget sockettests ta foar keep-alive, body framing, shutdown, statyske bestannen, trage kliïnten, en ferbiningskappen
Utjûn op 17 juny 2026
- +Foeget Fluxheim-eigendom HTTP/1.0/HTTP/1.1-fersyk-kop-parsing ta, klassifikaasje fan fersyk-lichem framing, host-validaasje, persistinsje-ôfhanneling, en chunked dekodearring
- +Foeget streamôfwerts HTTP/1-beliedsstanderts en ferhurde native parsergrinzen ta foar takomstich runtime cutover-wurk
Utjûn op 16 juny 2026
- +Moves server bootstrap planning, listener inventory, service intent, background-task intent, HTTP/2 policy, PROXY protocol policy, and private Unix socket planning into
fluxheim-server - +Hâldt de aktuele runtime as in eksplisite kompatibiliteitsadapter wylst native server/harkerwurk trochgiet
Utjûn op 16 juny 2026
- +Adds
fluxheim-tlsas de streamôfwerts TLS harker planning en provider-belied grins - +Moves TLS listener plans, SNI selection, wildcard matching, ALPN/cipher/curve policy, and rustls/OpenSSL provider checks into the TLS crate
- +Hardens TLS funksje poarten, SNI fallback gedrach, PROXY v2 hantekening falidaasje, en fertroude PROXY CIDR falidaasje
Utjûn op 16 juny 2026
- +Foeget de earste tawijde ta
fluxheim-headersgrins foar header belied helpers - +Ferpleatst herskriuwalgoritmen, ferwurking fan trochstjoerde kopteksten, hop-by-hop fersykbelied, en werhelle koptekst gearfoegje yn kopkoade yn eigendom fan Fluxheim
- +Beweegt stream PROXY protokol byte parsers yn
fluxheim-protocoland tightens privacy/proxy CIDR validation
Utjûn op 15 juny 2026
- +Beweecht dielde eftergrûntaak libbenssyklus primitiven yn
fluxheim-runtime - +Moves OTLP metrics export, ACME certificate reload control, admin snapshot validation state, and rollback decisions into Fluxheim-owned runtime/snapshot code
- +Ferhardt de lokale sertifikaat opnij laden kontrôle socket en privee efterkant filtering
Utjûn op 15 juny 2026
- +Adds
fluxheim-streamas the internal TCP stream proxy runtime boundary - +Ferpleatst streamopstreamseleksje, PROXY-protokol-parsearjen/skriuwen, boarnebelied, DNS-rebining-wachters, byte-accounting, en time-out-ôfhanneling efter streamkoade yn eigendom fan Fluxheim
Utjûn op 14 juny 2026
- +Moves cache key identity, object envelopes, disk index management, storage-bin helpers, tag handling, and cache storage interfaces into
fluxheim-cache - +A foeget tests en poarten ta dy't Pingora-ôfhannelingsferwideringsdoelen ôftwinge tidens normale
cargo test-runs
Utjûn op 14 juny 2026
- +Begjint de earste konkrete 1.6.x ymplemintaasje release nei de stifting tag
- +Removes
pingora-load-balancing/pingora-ketamafrom full and load-balancer image profiles, restores 1.6 load-balancer image builds, and moves TCP health checks plus request-key extraction behind Fluxheim-owned boundaries
Utjûn op 14 juny 2026
- + Begûn de
1.6.xPingora-útgong-stiftingsline, wylst it runtimegedrach net feroare - +Validaasje fan modulariteitsbelied tafoege, útsûnderingen foar legacy te grutte bestannen, runtime baseline capture, en prestaasjesbewiis capture
- +Tafoege release-gated Pingora ôfhinklikens útsûnderings, runtime parity fixtures, en de ekstraksje ôfhinklikens grafyk
- +Added initial
fluxheim-runtimeandfluxheim-servergrins kratten plus typte belied bewiis primitives
juny 2026
- +Introduced the enterprise HTTP/TCP load-balancer line with focused binaries, images, runtime member and weight controls, persistence, health checks, queueing, and migration docs
- +Expanded Fluxheim-owned runtime boundaries across HTTP, stream proxying, load balancing, background tasks, cache interfaces, observability, config, and shared crates
- +Behearde affiniteitskoekjes tafoege, tsjinstûntdekking, aktive en protokol-bewuste sûnenskontrôles, trochstart-persistente steat, en kontrôles foar backend-mutaasje foar runtime
- +Added UDP beta guardrails, cache origin-protection budgets, ARM/Linux and macOS developer assets, config tester archives, and broad proxy/cache/PHP-FPM security hardening
Utjûn op 25 maaie 2026
- +Production proxy parity release with trusted-proxy-aware ACLs, local rate limits, concurrency limits, bounded queues, and edge policy metrics
- +gzip, Zstandard, and Brotli response compression with vhost/route overrides and cache-safe
Varyhandling - +Load-balancer-resilience, TLS/protokolpariteit, PROXY-protokol v1/v2, streamop mTLS, HTTP/2-kontrôles, en gRPC-pass-through
Utjûn op 23 maaie 2026
- +Managed php-fpm process supervision under the existing
php-fpmfeature, while external php-fpm remains the default - +Respawn-wachthûn, beheine backoff, SIGTERM-foar-SIGKILL teardown, sanearre omjouwing, en privee generearre swimbadstatus
- +Auditable
[vhosts.php.fpm] mode = "managed"konfiguraasje-oerflak foar privee sockets, tellen fan arbeiders, modi foar prosesbehearder, slowlog, temppaden, en poolbestannen - +Utwreide WordPress PHP-FPM reekdekking oer eksterne, managed-statyske, managed-dynamyske, managed-ondemand, en managed-respawn-modi
- +Recommended Wolfi PHP image now installs
php-8.5-fpmand uses managed php-fpm container config by default
Utjûn op 23 maaie 2026
- +FIPS/ISO-required configs fail closed for unsupported internal cryptography, managed ACME, and local cache encryption
- +Provider-backed admin auth, numeric-local-loopback OTLP exception, and OpenBao Transit cache encryption evidence boundary
- +New compliance evidence template and release evidence package sections for regulated reviews
Utjûn op 22 maaie 2026
- +rustls / AWS-LC FIPS-kapabel kandidaat-backend troch
tls-rustls-fips - +FIPS en ISO/IEC 19790 rustls profylaliassen, konfiguraasjefoarbylden, diagnostyk en falidaasjeskript
Utjûn op 21 maaie 2026
- +OpenSSL FIPS/ISO-kapabele TLS-validaasje troch
tls-openssl-fipsen provider diagnostyk - +FIPS-ynsetgids, config-armaturen, falidaasjeskript, frijlittingsbewiis, en OWASP Top 10 2025-basisline
Utjûn op 20 maaie 2026
- +PHP-FPM keepalive pooling, upstream opnij besykjen / failover, en fersykje lichemsskiif spooling foar feiliger operaasje ûnder load
- +WordPress routing/cache preset plus PHP application recipes for common framework and forum deployments
- +PHP-metriken en OpenTelemetry-attributen, X-Accel-Redirect, X-Sendfile, en X-Accel-Expires-stipe
Utjûn op 18 maaie 2026
- +
fluxheim-acmestandalone begelieder binêr foar sertifikaatfernijing, status, en ACME reload socket-sinjalearring - +
fluxheim-config-testerstandalone binêr foar falidearjen fan konfiguraasjes yn CI- en konteneryngongspunten sûnder de gateway te begjinnen - +ACME opnij laden Unix-socket - opheljen fan live sertifikaat sûnder gateway opnij starte
- +Nij
profile-phpbouwprofyl —proxy + web + php-fpm + tls-rustls + security - +Security hardening improvements across the request pipeline
Utjûn op 16 maaie 2026
- +Opt-in PHP-FPM FastCGI bridge for WordPress-style front-controller applications
- +Strikte skriptresolúsje en beheine FastCGI-fersyk- / antwurdôfhanneling
- +Browser-validated WordPress proxy/PHP cookie compatibility fixes
- +PHP-FPM kin statyske aktiva tsjinje fan deselde root by it routing fan PHP nei FPM
- +New
php-fpmCargo feature (impliesproxy-laachandweb)
Utjûn op 14 maaie 2026
- +Shared ingress/TLS feature-graph split — focused cache and proxy profiles are now TLS/ACME-capable
- +New
profile-cache-edge— cache without static web module - +New
profile-proxy-edge— focused reverse proxy edge - +Official focused container images for cache and proxy profiles
Mei 2026
v1.2.6
- + Fixed-slice range-cache composition: open-ended, suffix, and multipart byte-range
- + Opt-in
range_slice_cache = truewreidet beheind berik caching út
v1.2.5
- + Bounded range caching for large proxy-cache objects
v1.2.4
- + Distributed cache peer fill with safe
only-if-cachedpeer fetches - + Beheind fail-iepen / mislearre sluten peer-follinggedrach
v1.2.3
- + Optional disk cache encryption with local keys or OpenBao Transit
v1.2.2
- + Storage-bin disk cache backend for larger high-churn caches
v1.2.1
- + Opt-in lokale caching foar statyske bestannen fia
local_static = true
v1.2.0 — Cache & Observability Baseline
- + Vhost/route cache policy, memory/disk/tiered cache backends
- + Cache-slûzen, muffe tsjinje, purge en statuseinpunten
- + Warm cache, kaaibewearing, en opsykje-ark
- + Prometheus metrics listener
- + OpenTelemetry export profiles (metrics + tracing)
2026
- + TLS-beliedsprofilen
- + Multi-certificate rustls SNI
- + Beheare útjefte en fernijing fan ACME-sertifikaat
- + EAB-kapabele útjouwers (Actalis en oaren)
- + TLS-geheimen mei triem-stipe
- +
acme-initbegeliede útjouwer bootstrap ark - + Ferpakte sertifikaatfernijing systemd ienheden
2026
- + Firtuele host-routing troch Host-header mei standert-vhost fallback
- + Route-level static, proxy, and redirect actions
- + Static file serving with MIME detection, ETag, conditional 304, byte ranges
- + Whole-vhost and route-level reverse proxying
- + rustls TLS with SNI, static/bought certificate support
- + Feilige ACME HTTP-01 útdaging trochstjoere
- + Admin control-plane with bearer-token auth and brute-force throttling
- + Feilich oanfraach-/antwurdkoptekstbelied
- + Opsjoneel HTTP → HTTPS trochferwizing mei feilige host-validaasje
- + systemd ienheid, RPM-ferpakking
- + Rootless Podman container images
Wat is folgjende
1.8.0: Aparte Wasm-build op basis fan it folsleine produksjeprofyl, mei beheinde beliedshooks, ACME, metriken en OpenTelemetry.
View full roadmap →