Loga athruithe
Eisiúint history do Fluxheim. Full nótaí eisiúna are on Eisiúintí GitHub.
Eisithe 23 Iúil 2026
- +Leagan tiomnaithe Wasm bunaithe ar an bpróifíl táirgthe iomlán, le crúcaí polasaí teoranta, ACME, méadrachtaí agus OpenTelemetry
- +Cuireann sé cartlanna comhoiriúnacha tar.gz agus ZIP leis, lena n-áirítear leaganacha dúchasacha iomlána agus Wasm do macOS
- +Neartaíonn sé teorainneacha iontrála do líonadh taisce, taisce raoin agus Wasm in aghaidh an vhost
Foilsithe 15 Iúil 2026
- +Cuireann sé meiteashonraí roghnacha, caighdeánbhunaithe leis don taisce, don seachfhreastalaí agus d'achoimrí freagartha
- +Deimhníonn sé athlódáil agus aischur seatanna beo fíordheimhnithe, seiceálacha sláine agus marthanacht tar éis atosaithe
- +Cuireann sé fianaise in-atáirgthe ar innill FIPS agus hardú fairsing ar an am rite dúchasach leis
Eisithe an 14 Iúil 2026
- +Cuireann sé dúnadh rianúil na nasc reatha laistigh de theorainn ama agus aistriú gan aga neamhfhónaimh faoi rialú seiceála ullmhachta leis
- +Cuireann sé gníomhachtú docht soicéad systemd leis, mar aon le fíorú beacht an tsoicéid éisteachta a fuarthas le hoidhreacht
- +Críochnaíonn sé cruachan an pharsálaí HTTP/1 agus neartaíonn sé bainistíocht shaolré na seirbhísí cúlra
Foilsithe 13 Iúil, 2026
- +Cuirtear leis próifílí roghnacha freagartha-slándála HTTP agus CORS bailíochtaithe atá feasach ar iarratas
- +Cobhsaíonn samplaí beartais Wasm inrite agus na tástálacha a éilíonn an geata scaoilte
- +Neartaítear ceanntásca céannachta seolta ar aghaidh, parsáil ceanntásca, agus athiarracht treoir maidir le teorainneacha acmhainne
Arna eisiúint 12 Iúil, 2026
- +Cuirtear samplaí imirce inrite leis le haghaidh post beartais iRules, OpenResty, HAProxy/SPOE, agus ar stíl VCL
- +Cuirtear leis iompar ACME teorantach, sceidealú ARI, diagnóisic saolré, agus glacadh le téarmaí sainráite
- +Cruann sé idirbhearta cuntais agus deimhnithe ACME inghnóthaithe, teorainneacha stórála, agus foilsiú seat
Eisithe an 11 Iúil 2026
- +Cuireann sé tús le teorainn roghnach WASI Preview 1, le ceadanna sainráite don chlog agus don randamacht agus iompórtálacha diúltaithe de réir réamhshocraithe
- +Athchóiríonn sé GeoIP do chliaint iontaofa agus tacaíonn sé le bunachair sonraí chomhcheangailte tíre agus ASN ó CIRCL
- +Neartaíonn sé cosaint SSRF agus cóipeáil srutha, snaipéid fhíordheimhnithe, TLS, PHP-FPM, freastal statach agus teorainneacha acmhainní Wasm
Eisithe 10 Iúil 2026
- +Cuireann sé an réamhamharc roghnach ABI Proxy-Wasm leis, le bailíochtú follasach ar ainmspás glaonna an óstaigh
- +Diúltaíonn sé go cinntitheach do ghlaonna réamhamhairc nach dtacaítear leo sula sroicheann siad freastalaí réamhtheachtach
- +Neartaíonn sé ródú docht óstaigh, glacadh teoranta, muinín cumraíochta, stóráil taisce, GeoIP agus comhbhrú
Eisithe 9 Iúil 2026
- +Cuireann sé aitheantais shoiléire compiled WebAssembly module leis thar plugin digest, ABI, hook feature surface agus leagan Fluxheim
- +Cuireann sé admission budgets cache-hook in aghaidh vhost leis faoin process-wide cache-hook ceiling
- +Leathnaíonn sé Wasm metrics teoranta, infheictheacht admin status agus clúdach cross-family live-chain regression
Eisithe 8 Iúil 2026
- +Cuireann sé host calls teoranta le comhpháirteanna cache-key do leaganacha aicme gléis mobile agus desktop
- +Cuireann sé cache-store TTL, tag agus stored-header metadata seasta leis gan athrú treallach response-header
- +Cuireann sé clúdach live listener le haghaidh aonrú leaganacha, range-cache slices, dul in éag TTL agus teorainneacha metadata fail-closed
Eisithe an 7 Iúil 2026
- +Cuireann sé live native HTTP/1 cache-lookup agus cache-store Wasm hooks leis faoin fluxheim_policy_v1 preview ABI teoranta
- +Cuireann sé torthaí cache do continue, pass, bypass, skip-store agus deny leis gan raw cache keys, TTLs, tags ná metadata stóráilte a nochtadh
- +Scarann sé teorainneacha admission do cache hooks agus coinníonn sé comhiomlánú cache-store mar most-restrictive-wins
Eisithe 6 Iúil 2026
- +Cuireann sé hooks Wasm route-decision HTTP/1 native beo leis faoin preview ABI teoranta fluxheim_policy_v1
- +Cuireann sé roghnú siombalach brainsí cumraithe le haghaidh bealaí canary agus mirror leis gan rochtain upstream dinimiciúil ná shadow-target
- +Coinníonn sé forfheidhmiú Fluxheim ACL, rate-limit, concurrency, body-limit, redirect agus header-policy tar éis roghnú bealaigh
Eisithe an 5 Iúil 2026
- +Cuireann sé Wasm hooks beo native HTTP/1 le haghaidh request-header agus response-header le ceangaltáin vhost agus route
- +Coinníonn sé ABI na header-hook siombalach le hathruithe sintéiseacha ceadaithe seachas rochtain amh ar header nó body
- +Cuireann sé Wasm header-hooks ar leibhéal vhost agus fallback response header policy i bhfeidhm ar fhreagraí PHP-FPM fallback
Eisithe an 4 Iúil 2026
- +Ceanglaíonn sé live native HTTP/1 access-decision hooks le hord tosaíochta, cumasc first-deny-wins agus iompar fail-closed
- +Cuireann sé uasteorainneacha iontrála rith i bhfeidhm ar leibhéal próisis, plugin agus attachment
Eisithe an 3 Iúil 2026
- +Cuireann sé an workspace crate fluxheim-wasm roghnach leis don líne Wasm sandbox
- +tá feature gates wasm, wasm-proxy-abi agus wasm-wasi múchta de réir réamhshocraithe agus neamh-chomhoiriúnach le privacy-mode
- +Luchtaíonn sé comhaid Wasm plugin ó roots iomlána ceadaithe amháin; diúltaítear do symlinks, comhaid neamhghnácha agus modules ró-mhóra
- +Bailíochtaíonn manifestí clóscríofa breiseán Wasm ABI, céim, fail-mode, conair agus teorainneacha sandbox roimh luchtú
- +Cuireann sé rith teoranta Wasmtime leis le teorainneacha fuel, memory, table, instance, compile-timeout, compile-worker agus per-call watchdog
- +Cuireann sé clúdach smoke fíor don Wasm sandbox leis le haghaidh rith rathúil, traps, diúltú table-growth agus diúltú manifest fail-open neamhshábháilte
Eisithe an 3 Iúil 2026
- +Nuashonraíonn sé an Rust toolchain pinnáilte, na réimsí rust-version agus íomhánna tógála coimeádán go Rust 1.96.1
- +Cruann sé ceanglóirí TLS OpenSSL stream-upstream le TLS 1.2 ar a laghad agus allowlist nua-aimseartha cipher TLS 1.2/TLS 1.3
- +Coinníonn sé dintiúir chuntais ACME sraitheáilte i sanitization::SecretVec agus iad á scríobh ar dhiosca
- +Baineann sé na root compatibility shims atá fágtha ionas go n-úsáideann glaoiteoirí fluxheim-common, fluxheim-config, fluxheim-cache, fluxheim-observability agus crates úinéireachta eile go díreach
- +Roinneann sé inmheánacha ACME, observability, cache, load-balancer, PHP-FPM, snapshot, web, stream agus native runtime ina modúil níos lú agus níos dírithe
Foilsithe 30 Meitheamh, 2026
- +Athainmníonn sé sraith shealadach an tseachfhreastalaí dhúchasaigh mar native_proxy agus baineann sé an sean-athonnmhairiú comhoiriúnachta seachfhreastalaí de ghnáth-thógálacha.
- +Bogann sé DTOanna iarratais agus toraidh riaracháin an chothromóra ualaigh isteach sa phacáiste fluxheim-load-balancer.
- +Scriosann sé oiriúnóirí fréimhe neamhghníomhacha ó ré Pingora agus seanchód tástála ama rite díchumasaithe nach n-úsáideann gnáth-thógálacha a thuilleadh.
- +Comhdhlúthaíonn sé stóráil chumraíochta an tseachfhreastalaí dhúchasaigh ionas go n-athnuachan athlódálacha an seat céanna a úsáideann conairí riaracháin na taisce agus an chothromóra ualaigh.
- +Cuireann sé clúdach aischéimnithe leis do róshreabhadh coirp deighilte dúchasaigh HTTP/1 agus ceanglaíonn sé íomhánna tástála inbhraiteachta le clibeanna cinntitheacha.
Foilsithe 30 Meitheamh, 2026
- +Coinníonn sé an gnáth runtime ar Fluxheim-owned listener, TLS, HTTP/1, HTTP/2, WebSocket, cache, load-balancer, admin, metrics, stream, agus cosáin background service
- +Bogann fianán auth, metrics, OpenBao cache, discovery, load-balancer, agus TLS private-key secret buffers i dtreo an sanitization crate
- +Hardens ródú cúlaithe PHP-FPM/static, glasáil purge dúchais disk-cache, sraithiú sócháin same-key disk-cache, agus láimhseáil dúchais HTTP/2 upstream authority
- +Cuireann sé tacaíocht peer-fill shared-secret leis agus éilíonn sé é le haghaidh gnáth-théacs non-loopback peer-fill URLs
- +Síneann sé clúdach tástála privacy, observability, WordPress, load-balancer, smoke-image, randomized-port, agus release-gate don líne stabilization
Eisithe an 29 Meitheamh 2026
- +Bain an Pingora runtime/listener/TLS adapter crates deiridh ó ghnáth-Fluxheim build profiles
- +Coinníonn sé an seachfhreastalaí HTTP/1 agus HTTP/2 dúchais runtime mar an gnáthchosán le haghaidh cumraíochtaí route, cache, load-balancer, TLS, WebSocket, admin, agus metrics tacaithe
- +Sreanga glantóir admin cache dúchais, glantachán diosca stale, cuardach réad cache, agus láimhseálaithe stats/sóchán load-balancer beo chuig lámha Fluxheim-owned runtime
- +Nuashonraíonn geataí scaoileadh dependency-policy ionas go dteipeann ar ghnáth-thógálacha réamhshocraithe, iomlán, imeall, PHP, príobháideachta, RPM, foinse agus coimeádán má thiomsaíonn siad Pingora crates
- +Cruann sé réamhamhairc agus glantacháin admin cache ó dhúchas le meaitseáil óstach normalaithe, réamhamhairc regex-route, seachaint glas purge stale, staid cumraíochta beo fail-closed, agus comhthéacsanna tógála route-proxy clóscríofa
Eisithe an 29 Meitheamh 2026
- +Cuireann sé paireacht dúchais proxy-cache leis le haghaidh cuimhne, diosca córas comhaid, storage-bin, diosca criptithe, OpenBao Transit, agus srathú memory+disk
- +Tacaíonn sé le leaganacha Vary agus request-header, riar sean, glas taisce, taisce slisne raoin, peer-fill, agus buiséid um chosaint tionscnaimh
- +Hardens cead isteach taisce do Authorization, seachbhóthar HEAD, in aghaidh an tsrutha Age stripping, sheiceáil uimhríocht éaga, agus only-if-cached chailleann
- +Cuireann sé paireacht íonachta an taisce dúchais leis le haghaidh innéacsanna cuimhne agus diosca chomh maith le réimír chruinn, toirte, réimír, clib, saoróg, route-scope, agus glantacháin sean
- +Cuireann sé seo inbhraite taisce dúchais le haghaidh cuntair seachfhreastalaí, tomhasairí cuimhne/diosca, histeagraim cuardaigh taisce, agus IDanna réise traceparent athghinte
Eisithe an 28 Meitheamh 2026
- +Adds native runtime dispatch for proxy, admin, metrics, stream, UDP, and load-balancer refresh tasks
- +Adds metrics token-file loading with zeroizing storage and constant-time bearer-token checks
- +Adds native HTTP/1 proxy runtime startup for plaintext, rustls, OpenSSL, and trusted downstream PROXY protocol listeners
- +Rianaíonn sé naisc downstream HTTP/2 TLS roghnaithe isteach san adapter dúchasach multi-stream
- +Cruann sé uasghráduithe WebSocket dúchasacha, teipeanna srutha-áitiúla HTTP/2, sharding rate-limit agus stóráil zeroizing de chorp an iarratais
Eisithe an 24 Meitheamh 2026
- +Moves cache request policy and local-static cache keys into the Pingora-independent
fluxheim-cachecrate - +Moves PHP-FPM parsing, params, path mapping, static offload, error-page policy, and keep-alive pooling into
fluxheim-php-fpm - +Adds native memory local-static cache adapters for route and vhost static-web serving
- +Adds native upstream PROXY protocol v1/v2 send support and native Host router construction
- +Adds native runtime manifest and launch-plan evidence for services, listeners, background tasks, and policy rows
Eisithe 23 Meitheamh 2026
- +Bogann sé plaintext upstream HTTP/2 forwarding isteach i the HTTP/1 dúchasach proxy cosán do h2c/prior-knowledge origins
- +Cuireann sé leis pooled dúchasach upstream H2 connections le teoranta stream capacity agus modh-sábháilte retry tar éis pre-freagra pooled-handle failure
- +Tacaíonn sé le TLS ALPN-negotiated upstream HTTP/2 le existing upstream TLS/SNI/CA beartas
- +Cuireann sé leis an t-aiseolas Uasghrádú h2c sainráite, díchumasaithe de réir réamhshocraithe le haghaidh bunús gnáth-théacs
http1-and-http2 - +Cuireann sé teorainneacha ar dúchasach upstream H2 handshakes, stream-slot waits, keepalive pings, agus setup timeouts
Eisithe 23 Meitheamh 2026
- +Bogann sé inherited domhanda/vhost comhbhrú beartas isteach i the HTTP/1 dúchasach proxy agus bealach proxy
- +Cumascann sé root/vhost/bealach header-beartas inheritance isteach i dúchasach bealach proxy construction
- +Bogann sé sábháilte forwarded-client-IP ownership, trusted-chain append, regex rewrites, ACLs, concurrency, agus rate teorainneacha onto the dúchasach cosán
- +Cuireann sé leis dúchasach ACME HTTP-01 challenge freastal, scáthánú tráchta, auth-iarratas, agus bealach-scoped gRPC validation
Eisithe 21 Meitheamh 2026
- +Moves route-level native response compression onto the HTTP/1 route proxy through
fluxheim-compression - +Moves
proxy.error_pagesonto native HTTP/1 proxy fallback leathanaigh backed byfluxheim-web
Eisithe 21 Meitheamh 2026
- +Adds native HTTP/1 route static-web serving backed by
fluxheim-web - +Adds route request-header mutation, response rewrites, static upstream round-robin, and static upstream weights to the native route proxy
Eisithe 21 Meitheamh 2026
- +Adds native route redirect actions with safe
{uri},{path}, and{query}expansion - +Moves route body limits and response-header overlays onto native HTTP/1 route proxy responses
Eisithe 21 Meitheamh 2026
- +Adds native HTTP/1 route-proxy execution for exact, prefix, and fallback routes with method filters and safe rewrite handling
- +Adds
native-http1-proxy-candidaterows to am rite cutover evidence so remaining compatibility blockers are explicit
Eisithe 20 Meitheamh 2026
- +Ardaíonn sé the HTTP/2 dúchasach downstream safety preview to cutover-ready tar éis focused parity tests
- +Déanann sé the representative am rite dúchasach cutover report blocker-free do simple HTTP/1, HTTP/2, admin, méadrachtaí, stream, agus UDP configurations
Eisithe 20 Meitheamh 2026
- +Cuts stream and UDP proxy service startup over to Fluxheim-owned native task boundaries
- +Adds cancellation-safe native shutdown waiting and abort-on-cancel background task joins
Eisithe 20 Meitheamh 2026
- +Starts native admin and metrics serving behind Fluxheim-owned server primitives
- +Cruann sé dúchasach background handles so dropped critical handles abort instead of silently detaching tasks
Eisithe 20 Meitheamh 2026
- +Adds
NativeBackgroundSupervisordo Fluxheim-owned tasc cúlra orchestration - +Adds critical task watchdog support and hardens shutdown delivery edge cases
Eisithe 20 Meitheamh 2026
- +Adds native runtime cutover evidence gates and
fluxheim-config-tester --runtime-cutover - +Moves remaining Pingora exception targets to a documented multi-release exit plan while keeping policy gates active
Eisithe 19 Meitheamh 2026
- +Adds explicit
pingora-compatfeature gating do the remaining compatibility am rite boundary - +Moves rustls/OpenSSL downstream TLS SNI, certificate storage, reload, PEM parsing, and native HTTP/1 TLS listener previews into Fluxheim-owned code
Eisithe 19 Meitheamh 2026
- +Leanann sé the Pingora-exit slice by shrinking the remaining root compatibility surface do proxy, cache, agus am rite cosáin
- +Roinneann sé dúchasach seiceálacha sláinte isteach i HTTP/gRPC, database, exec, agus TCP/TLS transport helper modules le stricter probe bounds
Eisithe 19 Meitheamh 2026
- +Baineann sé the direct Pingora dependency ó
fluxheim-load-balancer - +Cuireann sé leis Fluxheim-owned teoranta HTTP/1.1 agus h2 gRPC active seiceálacha sláinte le beartas coverage to prevent Pingora reintroduction
Eisithe 19 Meitheamh 2026
- +Cuireann sé leis HTTP/1 dúchasach.1 proxy cutover readiness planning on
ServerPlan - +Teipeann closed do compatibility-amháin proxy features such as auth subrequests, mirroring, redirects, strip/rewrite transforms, agus advanced load-balancer beartas
Eisithe 18 Meitheamh 2026
- +Cuireann sé leis a Fluxheim-owned HTTP/2 dúchasach upstream client primitive le teoranta ceanntásca, bodies, trailers, agus deadlines
- +Cuireann sé leis h2 client/server tests do trailer preservation, oversized responses, stream resets, agus flow-rialú timeout behavior
Eisithe 18 Meitheamh 2026
- +Cuireann sé leis dúchasach rustls/OpenSSL upstream TLS agus mTLS support to the staged HTTP/1.1 proxy cosán
- +Cuireann sé leis ordered static upstream failover do modh sábháiltes plus teoranta no-follow TLS material reads agus hostname-beartas coverage
Eisithe 18 Meitheamh 2026
- +Cuireann sé leis teoranta HTTP/1 dúchasach.1 upstream connection pooling do sábháilte content-length agus no-body origin responses
- +Cuireann sé leis keepalive pool sizing, upstream idle timeout handling, conservative no-reuse guards, agus real socket reuse/expiry tests
Eisithe 18 Meitheamh 2026
- +Cuireann sé leis reusable HTTP/2 dúchasach connection primitives le teoranta iarratas-body collection agus freagra trailer support
- +Cruann sé HTTP/2 freagra lifetime, handler timeout, DATA capacity handling, prohibited ceanntásca/trailers, agus iarratas-body zeroization
Eisithe 17 Meitheamh 2026
- +Cuireann sé leis the HTTP/2 dúchasach am rite preview gate agus h2 stack probe le teoranta ceanntásca, URI, body, streams, frames, buffers, agus rapid reset beartas
- +Cuireann sé leis HTTP/2 preview smoke coverage agus extends HTTP/1 dúchasach behavior coverage do HTTP/1.0 keep-alive/close semantics
Eisithe 17 Meitheamh 2026
- +Cuireann sé leis the teoranta HTTP/1 dúchasach upstream client agus staged proxy dúchasach handler do plain static upstreams
- +Cuireann sé leis proxy dúchasach candidate inventory, Fluxheim-owned proxy ceanntásca, privacy-mode behavior, agus fail-closed eligibility do unsupported beartas layers
Eisithe 17 Meitheamh 2026
- +Cuireann sé leis the HTTP/1 dúchasach connection/éisteoir am rite over Tokio IO agus staged dúchasach static-comhad adapter
- +Mapaíonn sé server teorainneacha isteach i HTTP/1 dúchasach beartas agus adds socket tests do keep-alive, body framing, shutdown, comhad statachs, slow clients, agus connection caps
Eisithe 17 Meitheamh 2026
- +Cuireann sé leis Fluxheim-owned HTTP/1.0/HTTP/1.1 iarratas-head parsing, iarratas-body framing classification, Host validation, persistence handling, agus chunked decoding
- +Cuireann sé leis downstream HTTP/1 beartas defaults agus cruaite dúchasach parser boundaries do amach anseo am rite cutover work
Eisithe 16 Meitheamh 2026
- +Moves server bootstrap planning, listener inventory, service intent, background-task intent, HTTP/2 policy, PROXY protocol policy, and private Unix socket planning into
fluxheim-server - +Coinníonn sé the current am rite as an explicit compatibility adapter agus dúchasach server/éisteoir work continues
Eisithe 16 Meitheamh 2026
- +Adds
fluxheim-tlsas the downstream TLS éisteoir planning agus provider-beartas boundary - +Moves TLS listener plans, SNI selection, wildcard matching, ALPN/cipher/curve policy, and rustls/OpenSSL provider checks into the TLS crate
- +Cruann sé TLS feature gates, SNI fallback behavior, PROXY v2 signature validation, agus trusted PROXY CIDR validation
Eisithe 16 Meitheamh 2026
- +Cuireann sé leis the first dedicated
fluxheim-headersboundary do header beartas helpers - +Bogann sé rewrite algorithms, forwarded-header handling, hop-by-hop iarratas beartas, agus repeated-header joining isteach i Fluxheim-owned header code
- +Bogann sé stream PROXY protocol byte parsers isteach i
fluxheim-protocoland tightens privacy/proxy CIDR validation
Eisithe 15 Meitheamh 2026
- +Bogann sé shared tasc cúlra lifecycle primitives isteach i
fluxheim-runtime - +Moves OTLP metrics export, ACME certificate reload control, admin snapshot validation state, and rollback decisions into Fluxheim-owned runtime/snapshot code
- +Cruann sé the áitiúil teastas reload rialú socket agus príobháideach backend filtering
Eisithe 15 Meitheamh 2026
- +Adds
fluxheim-streamas the internal TCP stream proxy runtime boundary - +Bogann sé stream upstream selection, PROXY protocol parsing/writing, foinse beartas, DNS-rebinding guards, byte accounting, agus timeout handling behind Fluxheim-owned stream code
Eisithe 14 Meitheamh 2026
- +Moves cache key identity, object envelopes, disk index management, storage-bin helpers, tag handling, and cache storage interfaces into
fluxheim-cache - +Cuireann sé leis tástálacha agus geataí scaoilte a fhorfheidhmíonn spriocanna bainte spleáchais Pingora le linn gnáth-ritheann
cargo test
Eisithe 14 Meitheamh 2026
- +Tosaíonn sé the first concrete 1.6.x implementation eisiúint tar éis the foundation tag
- +Removes
pingora-load-balancing/pingora-ketamafrom full and load-balancer image profiles, restores 1.6 load-balancer image builds, and moves TCP health checks plus request-key extraction behind Fluxheim-owned boundaries
Eisithe 14 Meitheamh 2026
- +Cuireadh tús leis an mbunlíne
1.6.xPingora-exit agus iompraíocht ama rite á choinneáil gan athrú - +Cuireadh leis modularity beartas validation, legacy oversized-comhad exceptions, am rite baseline capture, agus performance evidence capture
- +Cuireadh leis eisiúint-gated Pingora dependency exceptions, am rite parity fixtures, agus the extraction dependency graph
- +Added initial
fluxheim-runtimeandfluxheim-serverboundary crates plus typed beartas proof primitives
Meitheamh 2026
- +Introduced the enterprise HTTP/TCP load-balancer line with focused binaries, images, runtime member and weight controls, persistence, health checks, queueing, and migration docs
- +Expanded Fluxheim-owned runtime boundaries across HTTP, stream proxying, load balancing, background tasks, cache interfaces, observability, config, and shared crates
- +Cuireadh leis bainistithe affinity cookies, service discovery, active agus protocol-aware seiceálacha sláinte, restart-persistent state, agus am rite backend mutation rialuithe
- +Added UDP beta guardrails, cache origin-protection budgets, ARM/Linux and macOS developer assets, config tester archives, and broad proxy/cache/PHP-FPM security hardening
Eisithe 25 Bealtaine 2026
- +Production proxy parity release with trusted-proxy-aware ACLs, local rate limits, concurrency limits, bounded queues, and edge policy metrics
- +gzip, Zstandard, and Brotli response compression with vhost/route overrides and cache-safe
Varyhandling - +Load-balancer resilience, TLS/protocol parity, PROXY protocol v1/v2, upstream mTLS, HTTP/2 rialuithe, agus gRPC pass-through
Eisithe 23 Bealtaine 2026
- +Managed php-fpm process supervision under the existing
php-fpmfeature, while external php-fpm remains the default - +Respawn watchdog, teoranta backoff, SIGTERM-roimh-SIGKILL teardown, sanitized environment, agus príobháideach generated pool state
- +Auditable
[vhosts.php.fpm] mode = "managed"config surface do príobháideach sockets, worker comhaireamh, process manager modes, slowlog, temp cosáin, agus pool comhaid - +Expanded WordPress PHP-FPM smoke coverage across external, bainistithe-static, bainistithe-dynamic, bainistithe-ondemand, agus bainistithe-respawn modes
- +Recommended Wolfi PHP image now installs
php-8.5-fpmand uses managed php-fpm container config by default
Eisithe 23 Bealtaine 2026
- +FIPS/ISO-required configs fail closed for unsupported internal cryptography, managed ACME, and local cache encryption
- +Provider-backed admin auth, numeric-local-loopback OTLP exception, and OpenBao Transit cache encryption evidence boundary
- +New compliance evidence template and release evidence package sections for regulated reviews
Eisithe 22 Bealtaine 2026
- +rustls/AWS-LC inneall FIPS-in ann tríd
tls-rustls-fips - +FIPS agus ISO/IEC 19790 rustls próifíl aliases, config examples, diagnostics, agus validation script
Eisithe 21 Bealtaine 2026
- +Bailíochtú TLS atá in ann OpenSSL FIPS/ISO tríd
tls-openssl-fipsagus provider diagnostics - +FIPS deployment guide, config fixtures, validation script, eisiúint evidence, agus OWASP Top 10 2025 baseline
Eisithe 20 Bealtaine 2026
- +PHP-FPM keepalive pooling, upstream retry/failover, agus iarratas body diosca spooling do safer operation under load
- +WordPress routing/cache preset plus PHP application recipes for common framework and forum deployments
- +PHP méadrachtaí agus OpenTelemetry attributes, X-Accel-Redirect, X-Sendfile, agus X-Accel-Expires support
Eisithe 18 Bealtaine 2026
- +
fluxheim-acmestandalone companion binary do teastas renewal, status, agus ACME reload socket signalling - +
fluxheim-config-testerstandalone binary do validating configs in CI agus coimeádán entrypoints gan starting the gateway - +ACME reload Unix socket — live teastas pickup gan gateway restart
- +Próifíl tógála nua
profile-php—proxy + web + php-fpm + tls-rustls + security - +Security hardening improvements across the request pipeline
Eisithe 16 Bealtaine 2026
- +Opt-in PHP-FPM FastCGI bridge for WordPress-style front-controller applications
- +Dian script resolution agus teoranta FastCGI iarratas/freagra handling
- +Browser-validated WordPress proxy/PHP cookie compatibility fixes
- +PHP-FPM can freastal static assets ó same root agus routing PHP to FPM
- +New
php-fpmCargo feature (impliesseachfhreastalaíandweb)
Eisithe 14 Bealtaine 2026
- +Shared ingress/TLS feature-graph split — focused cache and proxy profiles are now TLS/ACME-capable
- +New
profile-cache-edge— cache without static web module - +New
profile-proxy-edge— focused reverse proxy edge - +Official focused container images for cache and proxy profiles
Bealtaine 2026
v1.2.6
- + Fixed-slice range-cache composition: open-ended, suffix, and multipart byte-range
- + Opt-in
range_slice_cache = trueextends teoranta range caching
v1.2.5
- + Bounded range caching for large proxy-cache objects
v1.2.4
- + Distributed cache peer fill with safe
only-if-cachedpeer fetches - + Teoranta fail-open/fail-closed peer fill behavior
v1.2.3
- + Optional disk cache encryption with local keys or OpenBao Transit
v1.2.2
- + Storage-bin disk cache backend for larger high-churn caches
v1.2.1
- + Opt-in áitiúil static-comhad caching via
local_static = true
v1.2.0 — Cache & Observability Baseline
- + Vhost/route cache policy, memory/disk/tiered cache backends
- + Cache locks, stale freastal, purge agus status endpoints
- + Cache warm, key assertion, agus lookup tooling
- + Prometheus metrics listener
- + OpenTelemetry export profiles (metrics + tracing)
2026
- + TLS beartas próifílí
- + Multi-certificate rustls SNI
- + ACME bainistithe teastas issuance agus renewal
- + EAB-capable issuers (Actalis agus others)
- + File-backed TLS rúin
- +
acme-inituirlis bootstrap eisitheora treoraithe - + Packaged teastas renewal aonad systemds
2026
- + Virtual host routing by Host header le réamhshocraithe-vhost fallback
- + Route-level static, proxy, and redirect actions
- + Static file serving with MIME detection, ETag, conditional 304, byte ranges
- + Whole-vhost and route-level reverse proxying
- + rustls TLS with SNI, static/bought certificate support
- + Cur ar aghaidh dúshlán Sábháilte ACME HTTP-01
- + Admin control-plane with bearer-token auth and brute-force throttling
- + Secure iarratas/freagra header beartas
- + Roghnach HTTP → HTTPS redirect le sábháilte Host validation
- + Aonad systemd, pacáistiú RPM
- + Rootless Podman container images
Cad atá romhainn
1.8.0: Leagan tiomnaithe Wasm bunaithe ar an bpróifíl táirgthe iomlán, le crúcaí polasaí teoranta, ACME, méadrachtaí agus OpenTelemetry.
View full roadmap →