บันทึกการเปลี่ยนแปลง
Release history for Fluxheim. เต็ม บันทึกรุ่น are on GitHub รุ่นเผยแพร่.
เผยแพร่เมื่อวันที่ 23 กรกฎาคม พ.ศ. 2569
- +รุ่น Wasm โดยเฉพาะซึ่งสร้างจากโปรไฟล์สำหรับการผลิตแบบเต็ม พร้อมจุดเชื่อมนโยบายที่จำกัดขอบเขต ACME เมตริก และ OpenTelemetry
- +เพิ่มไฟล์ tar.gz และ ZIP ที่ตรงกัน รวมถึงรุ่นเต็มและรุ่น Wasm แบบเนทีฟสำหรับ macOS
- +เพิ่มความเข้มงวดของขอบเขตการรับเข้าสำหรับการเติมแคช แคชช่วงข้อมูล และ Wasm แยกตาม vhost
เผยแพร่เมื่อวันที่ 15 กรกฎาคม พ.ศ. 2569
- +เพิ่มแคชตามมาตรฐานที่เลือกใช้ พร็อกซี และข้อมูลเมตาสรุปการตอบกลับ
- +พิสูจน์การโหลด Live Snapshot ซ้ำ ย้อนกลับ การตรวจสอบความสมบูรณ์ และการรีสตาร์ทอย่างต่อเนื่อง
- +เพิ่มหลักฐาน FIPS-backend ที่ทำซ้ำได้และการปรับปรุงรันไทม์ดั้งเดิมในวงกว้าง
เผยแพร่เมื่อวันที่ 14 กรกฎาคม 2026
- +เพิ่มกลไกรอให้การเชื่อมต่อที่กำลังใช้งานเสร็จสิ้นภายในเวลาที่กำหนด และสลับโปรเซสโดยไม่หยุดให้บริการหลังผ่านการตรวจสอบความพร้อม
- +เพิ่มการเปิดใช้งานซ็อกเก็ตผ่าน systemd แบบเข้มงวด พร้อมตรวจสอบซ็อกเก็ตที่รับการเชื่อมต่อซึ่งสืบทอดมาอย่างแม่นยำ
- +ปรับปรุงความปลอดภัยของตัวแยกวิเคราะห์ HTTP/1 เสร็จสมบูรณ์ และเสริมการจัดการความเป็นเจ้าของบริการเบื้องหลัง
เผยแพร่เมื่อวันที่ 13 กรกฎาคม 2026
- +เพิ่มโปรไฟล์ความปลอดภัยในการตอบกลับ HTTP และ CORS ที่รับรู้คำขอที่ได้รับการตรวจสอบแล้ว
- +ทำให้ตัวอย่างนโยบาย Wasm ที่รันได้เสถียรและการทดสอบที่กำหนดโดยประตูปลดล็อค
- +เสริมสร้างส่วนหัวข้อมูลประจำตัวที่ส่งต่อ การแยกวิเคราะห์ส่วนหัว และลองคำแนะนำอีกครั้งเพื่อจำกัดความจุ
เผยแพร่เมื่อวันที่ 12 กรกฎาคม 2026
- +เพิ่มตัวอย่างการย้ายที่รันได้สำหรับงานนโยบายสไตล์ iRules, OpenResty, HAProxy/SPOE และ VCL
- +เพิ่มการขนส่ง ACME แบบมีขอบเขต, การกำหนดเวลา ARI, การวินิจฉัยวงจรการใช้งาน และการยอมรับข้อกำหนดที่ชัดเจน
- +ทำให้บัญชี ACME ที่สามารถกู้คืนได้แข็งแกร่งขึ้นและธุรกรรมใบรับรอง ขอบเขตการจัดเก็บ และการเผยแพร่สแนปช็อต
เผยแพร่เมื่อ 11 กรกฎาคม 2026
- +เริ่มต้น boundary ของ WASI Preview 1 ด้วยการให้อนุญาตเวลาและความสุ่มอย่างชัดเจน และนำเข้าแบบปฏิเสธโดยค่าเริ่มต้น
- +กู้คืนฐานข้อมูล GeoIP ของไคลเอนต์ที่เชื่อถือได้ และรองรับฐานข้อมูล Country และ ASN แบบรวมจาก CIRCL
- +เสริมความแข็งแกร่งให้กับการป้องกัน SSRF และการคัดลอกของสตรีม, สแนปชอตที่มีการตรวจสอบสิทธิ์, TLS, PHP-FPM, การให้บริการแบบคงที่ และข้อจำกัดทรัพยากร Wasm
เผยแพร่ 10 กรกฎาคม 2026
- +เพิ่ม Proxy-Wasm ABI preview แบบเลือกเปิดใช้ พร้อมตรวจสอบ host-call namespace อย่างชัดเจน
- +ปฏิเสธ preview call ที่ไม่รองรับอย่างแน่นอนก่อนส่งถึง upstream
- +เสริมความแข็งแกร่งให้ strict host routing, admission แบบมีขอบเขต, ความน่าเชื่อถือของ config, cache storage, GeoIP และ compression
เผยแพร่ 9 กรกฎาคม 2026
- +เพิ่ม identity ที่ชัดเจนให้ compiled WebAssembly module ตาม plugin digest, ABI, hook feature surface และ Fluxheim version
- +เพิ่ม cache-hook admission budget ต่อ vhost ภายใต้ process-wide cache-hook ceiling
- +ขยาย Wasm metrics แบบมีขอบเขต, การมองเห็น admin status และ cross-family live-chain regression coverage
เผยแพร่ 8 กรกฎาคม 2026
- +เพิ่ม cache-key component host call แบบมีขอบเขตสำหรับ variant ของ device-class บน mobile และ desktop
- +เพิ่ม cache-store TTL, tag และ stored-header metadata แบบคงที่ โดยไม่อนุญาตการแก้ไข response-header ตามอำเภอใจ
- +เพิ่ม live listener coverage สำหรับ variant isolation, range-cache slice, TTL expiry และ fail-closed metadata cap
เผยแพร่เมื่อ 7 กรกฎาคม 2026
- +เพิ่ม Wasm hook แบบ live native HTTP/1 สำหรับ cache-lookup และ cache-store ภายใต้ fluxheim_policy_v1 preview ABI ที่จำกัด
- +เพิ่มผลลัพธ์ cache แบบ continue, pass, bypass, skip-store และ deny โดยไม่เปิดเผย raw cache keys, TTLs, tags หรือ stored metadata
- +แยกขีดจำกัด admission ของ cache-hook และคงกฎ most-restrictive-wins ในการรวมผลของ cache-store
เผยแพร่เมื่อ 6 กรกฎาคม 2026
- +เพิ่ม live native HTTP/1 route-decision Wasm hook ภายใต้ fluxheim_policy_v1 preview ABI ที่จำกัด
- +เพิ่มการเลือกกิ่งที่กำหนดไว้แบบ symbolic สำหรับ route canary และ mirror โดยไม่มี dynamic upstream หรือ shadow-target access
- +ยังคงบังคับใช้ Fluxheim ACL, rate-limit, concurrency, body-limit, redirect และ header-policy หลังการเลือก route
เผยแพร่ 5 กรกฎาคม 2026
- +เพิ่ม Wasm hooks แบบ live native HTTP/1 สำหรับ request-header และ response-header ให้กับ vhost และ route attachment
- +คง header-hook ABI ให้เป็นแบบ symbolic พร้อม synthetic mutations ที่อยู่ใน allow-list แทนการเข้าถึง raw header หรือ body
- +ใช้ vhost-level Wasm header hooks และ fallback response header policy กับ PHP-FPM fallback responses
เผยแพร่วันที่ 4 กรกฎาคม 2026
- +เชื่อมต่อ live native HTTP/1 access-decision hooks พร้อมลำดับ priority, first-deny-wins composition และพฤติกรรม fail-closed
- +บังคับใช้เพดาน admission ของการรันระดับ process, plugin และ attachment
เผยแพร่เมื่อ 3 กรกฎาคม 2026
- +เพิ่ม workspace crate fluxheim-wasm แบบเลือกใช้ได้สำหรับสาย Wasm sandbox
- +feature gates wasm, wasm-proxy-abi และ wasm-wasi ปิดไว้โดยค่าเริ่มต้นและใช้ร่วมกับ privacy-mode ไม่ได้
- +ไฟล์ปลั๊กอิน Wasm จะโหลดจาก root แบบ absolute ที่อนุมัติแล้วเท่านั้น ส่วน symlink, ไฟล์ที่ไม่ใช่ไฟล์ปกติ และ module ที่ใหญ่เกินไปจะถูกปฏิเสธ
- +manifest ของปลั๊กอิน Wasm แบบมีชนิดจะตรวจสอบ ABI, phase, fail-mode, path และขีดจำกัด sandbox ก่อนโหลด
- +จำกัดการรัน Wasmtime ด้วย fuel, memory, table, instance, compile-timeout, compile-worker และ watchdog ต่อการเรียก
- +เพิ่ม smoke coverage ของ Wasm sandbox จริง เพื่อตรวจการรันสำเร็จ, trap, การปฏิเสธ table growth และการปฏิเสธ manifest แบบ fail-open ที่ไม่ปลอดภัย
เผยแพร่เมื่อ 3 กรกฎาคม 2026
- +อัปเดต Rust toolchain ที่ pin ไว้, ฟิลด์ rust-version และ container builder images เป็น Rust 1.96.1
- +เพิ่มความแข็งแรงให้ OpenSSL stream-upstream TLS connectors ด้วย TLS 1.2 เป็นขั้นต่ำและ allowlist cipher TLS 1.2/TLS 1.3 สมัยใหม่
- +เก็บ ACME account credentials ที่ serialize แล้วไว้ใน sanitization::SecretVec ระหว่างเขียนลงดิสก์
- +ลบ root compatibility shims ที่เหลือ เพื่อให้ caller ใช้ fluxheim-common, fluxheim-config, fluxheim-cache, fluxheim-observability และ owning crates อื่นโดยตรง
- +แยก internals ของ ACME, observability, cache, load-balancer, PHP-FPM, snapshot, web, stream และ native runtime เป็นโมดูลเล็กลงและโฟกัสชัดขึ้น
เผยแพร่เมื่อวันที่ 30 มิถุนายน 2026
- +เปลี่ยนชื่อ shim ชั่วคราวของ native proxy เป็น native_proxy และนำ proxy compatibility re-export เก่าออกจาก build ปกติ
- +ย้าย DTO ของคำขอและผลลัพธ์ส่วนดูแล load balancer ไปยัง crate fluxheim-load-balancer
- +ลบ root adapter ยุค Pingora ที่ไม่ทำงานและโค้ด runtime/test เก่าที่ปิดไว้ซึ่ง build ปกติไม่ใช้อีก
- +รวม native proxy config storage เพื่อให้ reload รีเฟรช snapshot เดียวที่เส้นทางดูแล cache และ load balancer ใช้
- +เพิ่ม regression coverage สำหรับ native HTTP/1 chunked body overflow และตรึง observability smoke image กับ tag ที่แน่นอน
เผยแพร่เมื่อวันที่ 30 มิถุนายน 2026
- +เก็บ runtime ปกติไว้บนเส้นทาง Fluxheim-owned listener, TLS, HTTP/1, HTTP/2, WebSocket, cache, load-balancer, admin, metrics, stream และ background service
- +ย้ายคุกกี้ auth, metrics, OpenBao cache, discovery, load-balancer และ TLS private-key secret buffers ไปยัง sanitization crate
- +ทำให้การกำหนดเส้นทางสำรองของ PHP-FPM/static แข็งขึ้น, การล็อกล้างข้อมูล disk-cache แบบเนทีฟ, การทำให้เป็นอนุกรมการกลายพันธุ์ของ same-key disk-cache และการจัดการ HTTP/2 upstream authority แบบเนทีฟ
- +เพิ่มการรองรับ peer-fill shared-secret และต้องการสำหรับข้อความธรรมดา non-loopback peer-fill URLs
- +ขยายความครอบคลุมการทดสอบ privacy, observability, WordPress, load-balancer, smoke-image, randomized-port และ release-gate สำหรับกลุ่มผลิตภัณฑ์ stabilization
เผยแพร่เมื่อ 29 มิถุนายน 2026
- +ลบ Pingora runtime/listener/TLS adapter crates สุดท้ายออกจาก Fluxheim build profiles ปกติ
- +คงพร็อกซี HTTP/1 และ HTTP/2 ดั้งเดิม runtime ไว้เป็นเส้นทางปกติสำหรับการกำหนดค่า route, cache, load-balancer, TLS, WebSocket, admin และ metrics ที่รองรับ
- +เดินสายการล้างข้อมูล admin cache ดั้งเดิม, การล้างดิสก์ stale-cache, การค้นหาวัตถุ cache และตัวจัดการสถิติ/การกลายพันธุ์ของ load-balancer แบบสดไปยังตัวจัดการ Fluxheim-owned runtime
- +อัปเดตประตูปล่อย dependency-policy ดังนั้นค่าเริ่มต้นปกติ, เต็ม, ขอบ, PHP, ความเป็นส่วนตัว, RPM, แหล่งที่มาและการสร้างคอนเทนเนอร์จะล้มเหลวหากรวบรวม Pingora crates
- +เพิ่มความแข็งแกร่งให้กับการแสดงตัวอย่าง admin cache และล้างข้อมูลด้วยการจับคู่โฮสต์มาตรฐาน, การแสดงตัวอย่าง regex-route, การหลีกเลี่ยงการล็อกการล้างข้อมูล stale, สถานะการกำหนดค่าสดของ fail-closed และบริบทการสร้าง route-proxy ที่พิมพ์
เผยแพร่เมื่อ 29 มิถุนายน 2026
- +เพิ่มความเทียบเท่าของฟีเจอร์ proxy-cache แบบเนทีฟสำหรับหน่วยความจำ ดิสก์ระบบไฟล์ storage-bin ดิสก์เข้ารหัส OpenBao Transit และการจัดชั้น memory+disk
- +รองรับตัวแปร Vary และ request-header, การให้บริการเก่า, การล็อคแคช, แคชการแบ่งช่วง, peer-fill และงบประมาณการป้องกันต้นทาง
- +ทำให้การรับแคชแข็งขึ้นสำหรับ Authorization, HEAD บายพาส, อัพสตรีม Age การแยกส่วน, ตรวจสอบเลขคณิตการหมดอายุ และ only-if-cached พลาด
- +เพิ่มความเทียบเท่าของฟีเจอร์ล้างแคชแบบเนทีฟสำหรับดัชนีหน่วยความจำและดิสก์ รวมถึง exact, bulk, prefix, tag, wildcard, route-scope และ stale purges
- +เพิ่มความสามารถในการสังเกตแคชดั้งเดิมสำหรับตัวนับพร็อกซี หน่วยความจำ/ดิสก์เกจ ฮิสโตแกรมการค้นหาแคช และสร้างใหม่ traceparent span ID
เผยแพร่เมื่อ 28 มิถุนายน 2026
- +Adds native runtime dispatch for proxy, admin, metrics, stream, UDP, and load-balancer refresh tasks
- +Adds metrics token-file loading with zeroizing storage and constant-time bearer-token checks
- +Adds native HTTP/1 proxy runtime startup for plaintext, rustls, OpenSSL, and trusted downstream PROXY protocol listeners
- +กำหนดเส้นทางการเชื่อมต่อปลายน้ำ HTTP/2 TLS ที่เลือกไปยังอะแดปเตอร์หลายสตรีมแบบเนทีฟ
- +เสริมความแข็งแกร่งให้การอัปเกรด WebSocket แบบเนทีฟ การจัดการข้อผิดพลาดภายในสตรีม HTTP/2 การแบ่งชาร์ดขีดจำกัดอัตรา และการจัดเก็บเนื้อหาคำขอแบบ zeroizing
เผยแพร่เมื่อ 24 มิถุนายน 2026
- +Moves cache request policy and local-static cache keys into the Pingora-independent
fluxheim-cachecrate - +Moves PHP-FPM parsing, params, path mapping, static offload, error-page policy, and keep-alive pooling into
fluxheim-php-fpm - +Adds native memory local-static cache adapters for route and vhost static-web serving
- +Adds native upstream PROXY protocol v1/v2 send support and native Host router construction
- +Adds native runtime manifest and launch-plan evidence for services, listeners, background tasks, and policy rows
เผยแพร่เมื่อวันที่ 23 มิถุนายน 2026
- +ย้ายการส่งต่อ HTTP/2 อัปสตรีมแบบ plaintext ไปไว้ในเส้นทางพร็อกซี HTTP/1 แบบเนทีฟสำหรับต้นทาง h2c/prior-knowledge
- +เพิ่ม pooled native upstream H2 connection พร้อมขีดจำกัด stream capacity และ retry สำหรับ safe method หลัง pooled handle ล้มเหลวก่อน response
- +รองรับ upstream HTTP/2 ที่เจรจาผ่าน TLS ALPN โดยใช้นโยบาย TLS/SNI/CA ของ upstream ที่มีอยู่
- +เพิ่ม h2c Upgrade fallback แบบชัดเจนที่ปิดไว้ตามค่าเริ่มต้น สำหรับ plaintext
http1-and-http2origins - +จำกัด handshake ของ native upstream H2, เวลารอ stream slot, keepalive ping และ timeout ระหว่างตั้งค่า
เผยแพร่เมื่อวันที่ 23 มิถุนายน 2026
- +ย้ายนโยบาย compression ระดับ global/vhost ที่สืบทอดมาไปยัง native HTTP/1 proxy และ route proxy
- +ผสานการสืบทอดนโยบายส่วนหัว root/vhost/route เข้ากับการสร้างพร็อกซีเส้นทางดั้งเดิม
- +ย้ายความเป็นเจ้าของ forwarded-client-IP ที่ปลอดภัย การต่อ trusted-chain การเขียน regex ใหม่ ACL concurrency และ rate limit ไปยังเส้นทางเนทีฟ
- +เพิ่มการให้บริการ ACME HTTP-01 challenge แบบเนทีฟ, การทำ traffic mirroring, auth-request และการตรวจสอบ gRPC ระดับ route
เผยแพร่เมื่อวันที่ 21 มิถุนายน 2026
- +Moves route-level native response compression onto the HTTP/1 route proxy through
fluxheim-compression - +Moves
proxy.error_pagesonto native HTTP/1 proxy หน้าทางเลือกที่ได้รับการสนับสนุนโดยfluxheim-web
เผยแพร่เมื่อวันที่ 21 มิถุนายน 2026
- +Adds native HTTP/1 route static-web serving backed by
fluxheim-web - +Adds route request-header mutation, response rewrites, static upstream round-robin, and static upstream weights to the native route proxy
เผยแพร่เมื่อวันที่ 21 มิถุนายน 2026
- +Adds native route redirect actions with safe
{uri},{path}, and{query}expansion - +Moves route body limits and response-header overlays onto native HTTP/1 route proxy responses
เผยแพร่เมื่อวันที่ 21 มิถุนายน 2026
- +Adds native HTTP/1 route-proxy execution for exact, prefix, and fallback routes with method filters and safe rewrite handling
- +Adds
native-http1-proxy-candidateหลักฐานการตัดแถวไปจนถึงรันไทม์ ดังนั้นตัวบล็อกความเข้ากันได้ที่เหลืออยู่จึงมีความชัดเจน
เผยแพร่ 20 มิถุนายน 2026
- +Promotes the native HTTP/2 downstream ปลอดภัยty preview to cutover-ready after focused parity tests
- +Makes the representative native runtime cutover report blocker-free for simple HTTP/1, HTTP/2, admin, เมตริก, stream, and UDP การกำหนดค่าs
เผยแพร่ 20 มิถุนายน 2026
- +Cuts stream and UDP proxy service startup over to Fluxheim-owned native task boundaries
- +Adds cancellation-safe native shutdown waiting and abort-on-cancel background task joins
เผยแพร่ 20 มิถุนายน 2026
- +Starts native admin and metrics serving behind Fluxheim-owned server primitives
- +เสริมความแข็งแรง native background handles so dropped critical handles abort instead of silently detaching tasks
เผยแพร่ 20 มิถุนายน 2026
- +Adds
NativeBackgroundSupervisorสำหรับการประสานงานเบื้องหลังที่ Fluxheim เป็นเจ้าของ - +Adds critical task watchdog support and hardens shutdown delivery edge cases
เผยแพร่ 20 มิถุนายน 2026
- +Adds native runtime cutover evidence gates and
fluxheim-config-tester --runtime-cutover - +Moves remaining Pingora exception targets to a documented multi-release exit plan while keeping policy gates active
เผยแพร่ 19 มิถุนายน 2026
- +Adds explicit
pingora-compatคุณลักษณะ gating สำหรับขอบเขตรันไทม์ความเข้ากันได้ที่เหลืออยู่ - +Moves rustls/OpenSSL downstream TLS SNI, certificate storage, reload, PEM parsing, and native HTTP/1 TLS listener previews into Fluxheim-owned code
เผยแพร่ 19 มิถุนายน 2026
- +Continues the Pingora-exit slice by shrinking the remaining root compatibility surface for proxy, แคช, and runtime paths
- +Splits native การตรวจสุขภาพ into HTTP/gRPC, database, exec, and TCP/TLS transport helper modules with stricter probe bounds
เผยแพร่ 19 มิถุนายน 2026
- +ลบ the direct Pingora dependency from
fluxheim-load-balancer - +เพิ่ม Fluxheim-owned bounded HTTP/1.1 and h2 gRPC active การตรวจสุขภาพ with policy coverage to prevent Pingora reintroduction
เผยแพร่ 19 มิถุนายน 2026
- +เพิ่ม native HTTP/1.1 proxy cutover readiness planning on
ServerPlan - +Fails closed for compatibility-only proxy features such as auth subคำขอ, mirroring, redirects, strip/rewrite transforms, and advanced load-balancer policy
เผยแพร่ 18 มิถุนายน 2026
- +เพิ่ม a Fluxheim-owned native HTTP/2 อัปสตรีม client primitive with bounded headers, bodies, trailers, and deadlines
- +เพิ่ม h2 client/server tests สำหรับ trailer preservation, oversized responses, stream resets และ flow-control timeout behavior
เผยแพร่ 18 มิถุนายน 2026
- +เพิ่ม native rustls/OpenSSL อัปสตรีม TLS and mTLS support to the staged HTTP/1.1 proxy path
- +เพิ่ม ordered static อัปสตรีม failover for ปลอดภัย methods plus bounded no-follow TLS material reads and hostname-policy coverage
เผยแพร่ 18 มิถุนายน 2026
- +เพิ่ม connection pooling ของ upstream แบบ native HTTP/1.1 ที่จำกัด สำหรับ content-length ที่ปลอดภัยและ origin response ที่ไม่มี body
- +เพิ่ม keepalive pool sizing, อัปสตรีม idle timeout handling, conservative no-reuse guards, and real socket reuse/expiry tests
เผยแพร่ 18 มิถุนายน 2026
- +เพิ่ม reusable native HTTP/2 connection primitives with bounded คำขอ-body collection and การตอบกลับ trailer support
- +Hardens HTTP/2 การตอบกลับ lifetime, handler timeout, DATA capacity handling, prohibited headers/trailers, and คำขอ-body zeroization
เผยแพร่ 17 มิถุนายน 2026
- +เพิ่ม the native HTTP/2 runtime preview gate and h2 stack probe with bounded headers, URI, body, streams, frames, buffers, and rapid reset policy
- +เพิ่ม HTTP/2 preview smoke coverage and extends native HTTP/1 behavior coverage for HTTP/1.0 keep-alive/close semantics
เผยแพร่ 17 มิถุนายน 2026
- +เพิ่ม upstream client แบบ native HTTP/1 ที่จำกัด และ staged native proxy handler สำหรับ upstream แบบ plain static
- +เพิ่ม native proxy candidate inventory, Fluxheim-owned proxy headers, privacy-mode behavior, and fail-closed eligibility for unsupported policy layers
เผยแพร่ 17 มิถุนายน 2026
- +เพิ่ม the native HTTP/1 connection/listener runtime over Tokio IO and staged native static-file adapter
- +เซิร์ฟเวอร์ Maps จำกัดนโยบาย HTTP/1 ดั้งเดิม และเพิ่มการทดสอบซ็อกเก็ตสำหรับ Keep-alive, Body Framing, การปิดระบบ, ไฟล์คงที่, ไคลเอนต์ที่ช้า และขีดจำกัดการเชื่อมต่อ
เผยแพร่ 17 มิถุนายน 2026
- +เพิ่ม Fluxheim-owned HTTP/1.0/HTTP/1.1 คำขอ-head parsing, คำขอ-body framing classification, Host validation, persistence handling, and chunked decoding
- +เพิ่ม downstream HTTP/1 policy defaults and hardened native parser boundaries for future runtime cutover work
เผยแพร่ 16 มิถุนายน 2026
- +Moves server bootstrap planning, listener inventory, service intent, background-task intent, HTTP/2 policy, PROXY protocol policy, and private Unix socket planning into
fluxheim-server - +คงรันไทม์ปัจจุบันไว้เป็นอะแดปเตอร์ความเข้ากันได้ที่ชัดเจน ในขณะที่เซิร์ฟเวอร์/ตัวฟังดั้งเดิมยังคงทำงานต่อไป
เผยแพร่ 16 มิถุนายน 2026
- +Adds
fluxheim-tlsเป็นการวางแผนผู้ฟัง TLS ดาวน์สตรีมและขอบเขตนโยบายของผู้ให้บริการ - +Moves TLS listener plans, SNI selection, wildcard matching, ALPN/cipher/curve policy, and rustls/OpenSSL provider checks into the TLS crate
- +เสริมความแข็งแรง TLS feature gates, SNI fallback behavior, PROXY v2 signature validation, and trusted PROXY CIDR validation
เผยแพร่ 16 มิถุนายน 2026
- +เพิ่ม the first dedicated
fluxheim-headersขอบเขตสำหรับผู้ช่วยนโยบายส่วนหัว - +ย้ายอัลกอริทึม rewrite การจัดการ forwarded-header นโยบายคำขอแบบ hop-by-hop และการรวม repeated-header ไปไว้ในโค้ดส่วนหัวที่ Fluxheim เป็นเจ้าของ
- +ย้าย stream PROXY protocol byte parsers into
fluxheim-protocoland tightens privacy/proxy CIDR validation
เผยแพร่ 15 มิถุนายน 2026
- +ย้าย shared background task lifecycle primitives into
fluxheim-runtime - +Moves OTLP metrics export, ACME certificate reload control, admin snapshot validation state, and rollback decisions into Fluxheim-owned runtime/snapshot code
- +Hardens the local certificate reload control socket and ส่วนตัว แบ็กเอนด์ filtering
เผยแพร่ 15 มิถุนายน 2026
- +Adds
fluxheim-streamas the internal TCP stream proxy runtime boundary - +ย้ายการเลือกอัปสตรีมของสตรีม การอ่าน/เขียน PROXY protocol นโยบายต้นทาง การป้องกัน DNS rebinding การนับไบต์ และการจัดการ timeout ไปไว้หลังโค้ดสตรีมที่ Fluxheim เป็นเจ้าของ
เผยแพร่ 14 มิถุนายน 2026
- +Moves cache key identity, object envelopes, disk index management, storage-bin helpers, tag handling, and cache storage interfaces into
fluxheim-cache - +เพิ่ม tests and release gates that enforce Pingora dependency removal targets during normal
cargo testruns
เผยแพร่ 14 มิถุนายน 2026
- +เริ่มการเปิดตัวการใช้งาน 1.6.x อย่างเป็นรูปธรรมครั้งแรกหลังแท็กรองพื้น
- +Removes
pingora-load-balancing/pingora-ketamafrom full and load-balancer image profiles, restores 1.6 load-balancer image builds, and moves TCP health checks plus request-key extraction behind Fluxheim-owned boundaries
เผยแพร่ 14 มิถุนายน 2026
- +Started the
1.6.xบรรทัดพื้นฐาน Pingora-exit ในขณะที่ยังคงรักษาพฤติกรรมรันไทม์ไม่เปลี่ยนแปลง - +Added แบบโมดูลาร์ity policy validation, legacy oversized-file exceptions, runtime baseline capture, and performance evidence capture
- +เพิ่มข้อยกเว้นการพึ่งพา Pingora แบบ release-gated, การติดตั้งพาริตีรันไทม์ และกราฟการพึ่งพาการแยกข้อมูล
- +Added initial
fluxheim-runtimeandfluxheim-serverลังขอบเขตบวกพิมพ์หลักฐานนโยบายดั้งเดิม
มิถุนายน 2026
- +Introduced the enterprise HTTP/TCP load-balancer line with focused binaries, images, runtime member and weight controls, persistence, health checks, queueing, and migration docs
- +Expanded Fluxheim-owned runtime boundaries across HTTP, stream proxying, load balancing, background tasks, cache interfaces, observability, config, and shared crates
- +Added managed affinity cookies, service discovery, active and protocol-aware การตรวจสุขภาพ, restart-persistent state, and runtime แบ็กเอนด์ mutation controls
- +Added UDP beta guardrails, cache origin-protection budgets, ARM/Linux and macOS developer assets, config tester archives, and broad proxy/cache/PHP-FPM security hardening
เผยแพร่ 25 พฤษภาคม 2026
- +Production proxy parity release with trusted-proxy-aware ACLs, local rate limits, concurrency limits, bounded queues, and edge policy metrics
- +gzip, Zstandard, and Brotli response compression with vhost/route overrides and cache-safe
Varyhandling - +Load-balancer resilience, TLS/protocol parity, PROXY protocol v1/v2, อัปสตรีม mTLS, HTTP/2 controls, and gRPC pass-through
เผยแพร่ 23 พฤษภาคม 2026
- +Managed php-fpm process supervision under the existing
php-fpmfeature, while external php-fpm remains the default - +Respawn watchdog, bounded backoff, SIGTERM-before-SIGKILL teardown, sanitized environment, and ส่วนตัว generated pool state
- +Auditable
[vhosts.php.fpm] mode = "managed"config surface for ส่วนตัว sockets, worker counts, process manager modes, slowlog, temp paths, and pool files - +ขยายการครอบคลุมควัน WordPress PHP-FPM ในโหมดภายนอก, โหมดการจัดการคงที่, โหมดการจัดการไดนามิก, โหมดการจัดการตามความต้องการ และโหมดการจัดการการตอบสนอง
- +Recommended Wolfi PHP image now installs
php-8.5-fpmand uses managed php-fpm container config by default
เผยแพร่ 23 พฤษภาคม 2026
- +FIPS/ISO-required configs fail closed for unsupported internal cryptography, managed ACME, and local cache encryption
- +Provider-backed admin auth, numeric-local-loopback OTLP exception, and OpenBao Transit cache encryption evidence boundary
- +New compliance evidence template and release evidence package sections for regulated reviews
เผยแพร่ 22 พฤษภาคม 2026
- +rustls/AWS-LC FIPS-capable candidate แบ็กเอนด์ through
tls-rustls-fips - +นามแฝงโปรไฟล์ FIPS และ ISO/IEC 19790, ตัวอย่างการกำหนดค่า, การวินิจฉัย และสคริปต์การตรวจสอบ
เผยแพร่ 21 พฤษภาคม 2026
- +การตรวจสอบ TLS ที่รองรับ OpenSSL FIPS/ISO
tls-openssl-fipsและการวินิจฉัยผู้ให้บริการ - +คู่มือการปรับใช้ FIPS, โปรแกรมติดตั้งการกำหนดค่า, สคริปต์การตรวจสอบ, หลักฐานการเผยแพร่ และข้อมูลพื้นฐาน 10 อันดับแรกปี 2025 ของ OWASP
เผยแพร่ 20 พฤษภาคม 2026
- +PHP-FPM keepalive pooling, อัปสตรีม retry/failover, and คำขอ body disk spooling for ปลอดภัยr operation under load
- +WordPress routing/cache preset plus PHP application recipes for common framework and forum deployments
- +PHP เมตริก and OpenTelemetry attributes, X-Accel-Redirect, X-Sendfile, and X-Accel-Expires support
เผยแพร่ 18 พฤษภาคม 2026
- +
fluxheim-acmeไบนารีคู่หูแบบสแตนด์อโลนสำหรับการต่ออายุใบรับรอง สถานะ และการส่งสัญญาณซ็อกเก็ตรีโหลด ACME - +
fluxheim-config-testerstandalone binary for validating configs in CI and คอนเทนเนอร์ entrypoints without starting the gateway - +ACME รีโหลดซ็อกเก็ต Unix — รับใบรับรองสดโดยไม่ต้องรีสตาร์ทเกตเวย์
- +ใหม่
profile-phpbuild profile —proxy + web + php-fpm + tls-rustls + security - +Security hardening improvements across the request pipeline
เผยแพร่ 16 พฤษภาคม 2026
- +Opt-in PHP-FPM FastCGI bridge for WordPress-style front-controller applications
- +Strict script resolution and bounded FastCGI คำขอ/การตอบกลับ handling
- +Browser-validated WordPress proxy/PHP cookie compatibility fixes
- +PHP-FPM สามารถให้บริการสินทรัพย์คงที่จากรูทเดียวกันในขณะที่กำหนดเส้นทาง PHP ไปยัง FPM
- +New
php-fpmCargo feature (impliesพร็อกซีandweb)
เผยแพร่ 14 พฤษภาคม 2026
- +Shared ingress/TLS feature-graph split — focused cache and proxy profiles are now TLS/ACME-capable
- +New
profile-cache-edge— cache without static web module - +New
profile-proxy-edge— focused reverse proxy edge - +Official focused container images for cache and proxy profiles
พฤษภาคม 2026
v1.2.6
- + Fixed-slice range-cache composition: open-ended, suffix, and multipart byte-range
- + Opt-in
range_slice_cache = trueขยายขอบเขตแคช
v1.2.5
- + Bounded range caching for large proxy-cache objects
v1.2.4
- + Distributed cache peer fill with safe
only-if-cachedpeer fetches - + พฤติกรรมการเติมเพียร์ที่เปิดล้มเหลว/ล้มเหลวที่ถูกปิดแบบมีขอบเขต
v1.2.3
- + Optional disk cache encryption with local keys or OpenBao Transit
v1.2.2
- + Storage-bin disk cache backend for larger high-churn caches
v1.2.1
- + เลือกใช้การแคชไฟล์คงที่ในเครื่องผ่าน
local_static = true
v1.2.0 — Cache & Observability Baseline
- + Vhost/route cache policy, memory/disk/tiered cache backends
- + แคช locks, stale serving, purge and status endpoints
- + แคช warm, key assertion, and lookup tooling
- + Prometheus metrics listener
- + OpenTelemetry export profiles (metrics + tracing)
2026
- + โปรไฟล์นโยบาย TLS
- + Multi-certificate rustls SNI
- + การออกและการต่ออายุใบรับรอง ACME ที่มีการจัดการ
- + ผู้ออกที่รองรับ EAB (Actalis และอื่น ๆ )
- + ความลับ TLS ที่สำรองไฟล์
- +
acme-initเครื่องมือบูตสแตรปของผู้ออกที่แนะนำ - + หน่วยระบบการต่ออายุใบรับรองแบบแพ็กเกจ
2026
- + การกำหนดเส้นทางโฮสต์เสมือนโดยส่วนหัวของโฮสต์พร้อมทางเลือกสำรอง vhost เริ่มต้น
- + Route-level static, proxy, and redirect actions
- + Static file serving with MIME detection, ETag, conditional 304, byte ranges
- + Whole-vhost and route-level reverse proxying
- + rustls TLS with SNI, static/bought certificate support
- + การส่งต่อความท้าทาย ACME HTTP-01 ที่ปลอดภัย
- + Admin control-plane with bearer-token auth and brute-force throttling
- + Secure คำขอ/การตอบกลับ header policy
- + การเปลี่ยนเส้นทาง HTTP → HTTPS แบบเลือกเปิดได้พร้อมการตรวจสอบ Host ที่ปลอดภัย
- + หน่วย Systemd, บรรจุภัณฑ์ RPM
- + Rootless Podman container images
อะไรต่อไป
1.8.0: รุ่น Wasm โดยเฉพาะซึ่งสร้างจากโปรไฟล์สำหรับการผลิตแบบเต็ม พร้อมจุดเชื่อมนโยบายที่จำกัดขอบเขต ACME เมตริก และ OpenTelemetry.
View full roadmap →