บันทึกการเปลี่ยนแปลง

Release history for Fluxheim. เต็ม บันทึกรุ่น are on GitHub รุ่นเผยแพร่.

v1.8.0 เวอร์ชันเสถียรล่าสุด ดูบน GitHub →

เผยแพร่เมื่อวันที่ 23 กรกฎาคม พ.ศ. 2569

  • +รุ่น Wasm โดยเฉพาะซึ่งสร้างจากโปรไฟล์สำหรับการผลิตแบบเต็ม พร้อมจุดเชื่อมนโยบายที่จำกัดขอบเขต ACME เมตริก และ OpenTelemetry
  • +เพิ่มไฟล์ tar.gz และ ZIP ที่ตรงกัน รวมถึงรุ่นเต็มและรุ่น Wasm แบบเนทีฟสำหรับ macOS
  • +เพิ่มความเข้มงวดของขอบเขตการรับเข้าสำหรับการเติมแคช แคชช่วงข้อมูล และ Wasm แยกตาม vhost

เผยแพร่เมื่อวันที่ 15 กรกฎาคม พ.ศ. 2569

  • +เพิ่มแคชตามมาตรฐานที่เลือกใช้ พร็อกซี และข้อมูลเมตาสรุปการตอบกลับ
  • +พิสูจน์การโหลด Live Snapshot ซ้ำ ย้อนกลับ การตรวจสอบความสมบูรณ์ และการรีสตาร์ทอย่างต่อเนื่อง
  • +เพิ่มหลักฐาน FIPS-backend ที่ทำซ้ำได้และการปรับปรุงรันไทม์ดั้งเดิมในวงกว้าง

เผยแพร่เมื่อวันที่ 14 กรกฎาคม 2026

  • +เพิ่มกลไกรอให้การเชื่อมต่อที่กำลังใช้งานเสร็จสิ้นภายในเวลาที่กำหนด และสลับโปรเซสโดยไม่หยุดให้บริการหลังผ่านการตรวจสอบความพร้อม
  • +เพิ่มการเปิดใช้งานซ็อกเก็ตผ่าน systemd แบบเข้มงวด พร้อมตรวจสอบซ็อกเก็ตที่รับการเชื่อมต่อซึ่งสืบทอดมาอย่างแม่นยำ
  • +ปรับปรุงความปลอดภัยของตัวแยกวิเคราะห์ HTTP/1 เสร็จสมบูรณ์ และเสริมการจัดการความเป็นเจ้าของบริการเบื้องหลัง

เผยแพร่เมื่อวันที่ 13 กรกฎาคม 2026

  • +เพิ่มโปรไฟล์ความปลอดภัยในการตอบกลับ HTTP และ CORS ที่รับรู้คำขอที่ได้รับการตรวจสอบแล้ว
  • +ทำให้ตัวอย่างนโยบาย Wasm ที่รันได้เสถียรและการทดสอบที่กำหนดโดยประตูปลดล็อค
  • +เสริมสร้างส่วนหัวข้อมูลประจำตัวที่ส่งต่อ การแยกวิเคราะห์ส่วนหัว และลองคำแนะนำอีกครั้งเพื่อจำกัดความจุ

เผยแพร่เมื่อวันที่ 12 กรกฎาคม 2026

  • +เพิ่มตัวอย่างการย้ายที่รันได้สำหรับงานนโยบายสไตล์ iRules, OpenResty, HAProxy/SPOE และ VCL
  • +เพิ่มการขนส่ง ACME แบบมีขอบเขต, การกำหนดเวลา ARI, การวินิจฉัยวงจรการใช้งาน และการยอมรับข้อกำหนดที่ชัดเจน
  • +ทำให้บัญชี ACME ที่สามารถกู้คืนได้แข็งแกร่งขึ้นและธุรกรรมใบรับรอง ขอบเขตการจัดเก็บ และการเผยแพร่สแนปช็อต

เผยแพร่เมื่อ 11 กรกฎาคม 2026

  • +เริ่มต้น boundary ของ WASI Preview 1 ด้วยการให้อนุญาตเวลาและความสุ่มอย่างชัดเจน และนำเข้าแบบปฏิเสธโดยค่าเริ่มต้น
  • +กู้คืนฐานข้อมูล GeoIP ของไคลเอนต์ที่เชื่อถือได้ และรองรับฐานข้อมูล Country และ ASN แบบรวมจาก CIRCL
  • +เสริมความแข็งแกร่งให้กับการป้องกัน SSRF และการคัดลอกของสตรีม, สแนปชอตที่มีการตรวจสอบสิทธิ์, TLS, PHP-FPM, การให้บริการแบบคงที่ และข้อจำกัดทรัพยากร Wasm

เผยแพร่ 10 กรกฎาคม 2026

  • +เพิ่ม Proxy-Wasm ABI preview แบบเลือกเปิดใช้ พร้อมตรวจสอบ host-call namespace อย่างชัดเจน
  • +ปฏิเสธ preview call ที่ไม่รองรับอย่างแน่นอนก่อนส่งถึง upstream
  • +เสริมความแข็งแกร่งให้ strict host routing, admission แบบมีขอบเขต, ความน่าเชื่อถือของ config, cache storage, GeoIP และ compression

เผยแพร่ 9 กรกฎาคม 2026

  • +เพิ่ม identity ที่ชัดเจนให้ compiled WebAssembly module ตาม plugin digest, ABI, hook feature surface และ Fluxheim version
  • +เพิ่ม cache-hook admission budget ต่อ vhost ภายใต้ process-wide cache-hook ceiling
  • +ขยาย Wasm metrics แบบมีขอบเขต, การมองเห็น admin status และ cross-family live-chain regression coverage

เผยแพร่ 8 กรกฎาคม 2026

  • +เพิ่ม cache-key component host call แบบมีขอบเขตสำหรับ variant ของ device-class บน mobile และ desktop
  • +เพิ่ม cache-store TTL, tag และ stored-header metadata แบบคงที่ โดยไม่อนุญาตการแก้ไข response-header ตามอำเภอใจ
  • +เพิ่ม live listener coverage สำหรับ variant isolation, range-cache slice, TTL expiry และ fail-closed metadata cap

เผยแพร่เมื่อ 7 กรกฎาคม 2026

  • +เพิ่ม Wasm hook แบบ live native HTTP/1 สำหรับ cache-lookup และ cache-store ภายใต้ fluxheim_policy_v1 preview ABI ที่จำกัด
  • +เพิ่มผลลัพธ์ cache แบบ continue, pass, bypass, skip-store และ deny โดยไม่เปิดเผย raw cache keys, TTLs, tags หรือ stored metadata
  • +แยกขีดจำกัด admission ของ cache-hook และคงกฎ most-restrictive-wins ในการรวมผลของ cache-store

เผยแพร่เมื่อ 6 กรกฎาคม 2026

  • +เพิ่ม live native HTTP/1 route-decision Wasm hook ภายใต้ fluxheim_policy_v1 preview ABI ที่จำกัด
  • +เพิ่มการเลือกกิ่งที่กำหนดไว้แบบ symbolic สำหรับ route canary และ mirror โดยไม่มี dynamic upstream หรือ shadow-target access
  • +ยังคงบังคับใช้ Fluxheim ACL, rate-limit, concurrency, body-limit, redirect และ header-policy หลังการเลือก route

เผยแพร่ 5 กรกฎาคม 2026

  • +เพิ่ม Wasm hooks แบบ live native HTTP/1 สำหรับ request-header และ response-header ให้กับ vhost และ route attachment
  • +คง header-hook ABI ให้เป็นแบบ symbolic พร้อม synthetic mutations ที่อยู่ใน allow-list แทนการเข้าถึง raw header หรือ body
  • +ใช้ vhost-level Wasm header hooks และ fallback response header policy กับ PHP-FPM fallback responses

เผยแพร่วันที่ 4 กรกฎาคม 2026

  • +เชื่อมต่อ live native HTTP/1 access-decision hooks พร้อมลำดับ priority, first-deny-wins composition และพฤติกรรม fail-closed
  • +บังคับใช้เพดาน admission ของการรันระดับ process, plugin และ attachment

เผยแพร่เมื่อ 3 กรกฎาคม 2026

  • +เพิ่ม workspace crate fluxheim-wasm แบบเลือกใช้ได้สำหรับสาย Wasm sandbox
  • +feature gates wasm, wasm-proxy-abi และ wasm-wasi ปิดไว้โดยค่าเริ่มต้นและใช้ร่วมกับ privacy-mode ไม่ได้
  • +ไฟล์ปลั๊กอิน Wasm จะโหลดจาก root แบบ absolute ที่อนุมัติแล้วเท่านั้น ส่วน symlink, ไฟล์ที่ไม่ใช่ไฟล์ปกติ และ module ที่ใหญ่เกินไปจะถูกปฏิเสธ
  • +manifest ของปลั๊กอิน Wasm แบบมีชนิดจะตรวจสอบ ABI, phase, fail-mode, path และขีดจำกัด sandbox ก่อนโหลด
  • +จำกัดการรัน Wasmtime ด้วย fuel, memory, table, instance, compile-timeout, compile-worker และ watchdog ต่อการเรียก
  • +เพิ่ม smoke coverage ของ Wasm sandbox จริง เพื่อตรวจการรันสำเร็จ, trap, การปฏิเสธ table growth และการปฏิเสธ manifest แบบ fail-open ที่ไม่ปลอดภัย

เผยแพร่เมื่อ 3 กรกฎาคม 2026

  • +อัปเดต Rust toolchain ที่ pin ไว้, ฟิลด์ rust-version และ container builder images เป็น Rust 1.96.1
  • +เพิ่มความแข็งแรงให้ OpenSSL stream-upstream TLS connectors ด้วย TLS 1.2 เป็นขั้นต่ำและ allowlist cipher TLS 1.2/TLS 1.3 สมัยใหม่
  • +เก็บ ACME account credentials ที่ serialize แล้วไว้ใน sanitization::SecretVec ระหว่างเขียนลงดิสก์
  • +ลบ root compatibility shims ที่เหลือ เพื่อให้ caller ใช้ fluxheim-common, fluxheim-config, fluxheim-cache, fluxheim-observability และ owning crates อื่นโดยตรง
  • +แยก internals ของ ACME, observability, cache, load-balancer, PHP-FPM, snapshot, web, stream และ native runtime เป็นโมดูลเล็กลงและโฟกัสชัดขึ้น

เผยแพร่เมื่อวันที่ 30 มิถุนายน 2026

  • +เปลี่ยนชื่อ shim ชั่วคราวของ native proxy เป็น native_proxy และนำ proxy compatibility re-export เก่าออกจาก build ปกติ
  • +ย้าย DTO ของคำขอและผลลัพธ์ส่วนดูแล load balancer ไปยัง crate fluxheim-load-balancer
  • +ลบ root adapter ยุค Pingora ที่ไม่ทำงานและโค้ด runtime/test เก่าที่ปิดไว้ซึ่ง build ปกติไม่ใช้อีก
  • +รวม native proxy config storage เพื่อให้ reload รีเฟรช snapshot เดียวที่เส้นทางดูแล cache และ load balancer ใช้
  • +เพิ่ม regression coverage สำหรับ native HTTP/1 chunked body overflow และตรึง observability smoke image กับ tag ที่แน่นอน

เผยแพร่เมื่อวันที่ 30 มิถุนายน 2026

  • +เก็บ runtime ปกติไว้บนเส้นทาง Fluxheim-owned listener, TLS, HTTP/1, HTTP/2, WebSocket, cache, load-balancer, admin, metrics, stream และ background service
  • +ย้ายคุกกี้ auth, metrics, OpenBao cache, discovery, load-balancer และ TLS private-key secret buffers ไปยัง sanitization crate
  • +ทำให้การกำหนดเส้นทางสำรองของ PHP-FPM/static แข็งขึ้น, การล็อกล้างข้อมูล disk-cache แบบเนทีฟ, การทำให้เป็นอนุกรมการกลายพันธุ์ของ same-key disk-cache และการจัดการ HTTP/2 upstream authority แบบเนทีฟ
  • +เพิ่มการรองรับ peer-fill shared-secret และต้องการสำหรับข้อความธรรมดา non-loopback peer-fill URLs
  • +ขยายความครอบคลุมการทดสอบ privacy, observability, WordPress, load-balancer, smoke-image, randomized-port และ release-gate สำหรับกลุ่มผลิตภัณฑ์ stabilization

เผยแพร่เมื่อ 29 มิถุนายน 2026

  • +ลบ Pingora runtime/listener/TLS adapter crates สุดท้ายออกจาก Fluxheim build profiles ปกติ
  • +คงพร็อกซี HTTP/1 และ HTTP/2 ดั้งเดิม runtime ไว้เป็นเส้นทางปกติสำหรับการกำหนดค่า route, cache, load-balancer, TLS, WebSocket, admin และ metrics ที่รองรับ
  • +เดินสายการล้างข้อมูล admin cache ดั้งเดิม, การล้างดิสก์ stale-cache, การค้นหาวัตถุ cache และตัวจัดการสถิติ/การกลายพันธุ์ของ load-balancer แบบสดไปยังตัวจัดการ Fluxheim-owned runtime
  • +อัปเดตประตูปล่อย dependency-policy ดังนั้นค่าเริ่มต้นปกติ, เต็ม, ขอบ, PHP, ความเป็นส่วนตัว, RPM, แหล่งที่มาและการสร้างคอนเทนเนอร์จะล้มเหลวหากรวบรวม Pingora crates
  • +เพิ่มความแข็งแกร่งให้กับการแสดงตัวอย่าง admin cache และล้างข้อมูลด้วยการจับคู่โฮสต์มาตรฐาน, การแสดงตัวอย่าง regex-route, การหลีกเลี่ยงการล็อกการล้างข้อมูล stale, สถานะการกำหนดค่าสดของ fail-closed และบริบทการสร้าง route-proxy ที่พิมพ์

เผยแพร่เมื่อ 29 มิถุนายน 2026

  • +เพิ่มความเทียบเท่าของฟีเจอร์ proxy-cache แบบเนทีฟสำหรับหน่วยความจำ ดิสก์ระบบไฟล์ storage-bin ดิสก์เข้ารหัส OpenBao Transit และการจัดชั้น memory+disk
  • +รองรับตัวแปร Vary และ request-header, การให้บริการเก่า, การล็อคแคช, แคชการแบ่งช่วง, peer-fill และงบประมาณการป้องกันต้นทาง
  • +ทำให้การรับแคชแข็งขึ้นสำหรับ Authorization, HEAD บายพาส, อัพสตรีม Age การแยกส่วน, ตรวจสอบเลขคณิตการหมดอายุ และ only-if-cached พลาด
  • +เพิ่มความเทียบเท่าของฟีเจอร์ล้างแคชแบบเนทีฟสำหรับดัชนีหน่วยความจำและดิสก์ รวมถึง exact, bulk, prefix, tag, wildcard, route-scope และ stale purges
  • +เพิ่มความสามารถในการสังเกตแคชดั้งเดิมสำหรับตัวนับพร็อกซี หน่วยความจำ/ดิสก์เกจ ฮิสโตแกรมการค้นหาแคช และสร้างใหม่ traceparent span ID

เผยแพร่เมื่อ 28 มิถุนายน 2026

  • +Adds native runtime dispatch for proxy, admin, metrics, stream, UDP, and load-balancer refresh tasks
  • +Adds metrics token-file loading with zeroizing storage and constant-time bearer-token checks
  • +Adds native HTTP/1 proxy runtime startup for plaintext, rustls, OpenSSL, and trusted downstream PROXY protocol listeners
  • +กำหนดเส้นทางการเชื่อมต่อปลายน้ำ HTTP/2 TLS ที่เลือกไปยังอะแดปเตอร์หลายสตรีมแบบเนทีฟ
  • +เสริมความแข็งแกร่งให้การอัปเกรด WebSocket แบบเนทีฟ การจัดการข้อผิดพลาดภายในสตรีม HTTP/2 การแบ่งชาร์ดขีดจำกัดอัตรา และการจัดเก็บเนื้อหาคำขอแบบ zeroizing

เผยแพร่เมื่อ 24 มิถุนายน 2026

  • +Moves cache request policy and local-static cache keys into the Pingora-independent fluxheim-cache crate
  • +Moves PHP-FPM parsing, params, path mapping, static offload, error-page policy, and keep-alive pooling into fluxheim-php-fpm
  • +Adds native memory local-static cache adapters for route and vhost static-web serving
  • +Adds native upstream PROXY protocol v1/v2 send support and native Host router construction
  • +Adds native runtime manifest and launch-plan evidence for services, listeners, background tasks, and policy rows

เผยแพร่เมื่อวันที่ 23 มิถุนายน 2026

  • +ย้ายการส่งต่อ HTTP/2 อัปสตรีมแบบ plaintext ไปไว้ในเส้นทางพร็อกซี HTTP/1 แบบเนทีฟสำหรับต้นทาง h2c/prior-knowledge
  • +เพิ่ม pooled native upstream H2 connection พร้อมขีดจำกัด stream capacity และ retry สำหรับ safe method หลัง pooled handle ล้มเหลวก่อน response
  • +รองรับ upstream HTTP/2 ที่เจรจาผ่าน TLS ALPN โดยใช้นโยบาย TLS/SNI/CA ของ upstream ที่มีอยู่
  • +เพิ่ม h2c Upgrade fallback แบบชัดเจนที่ปิดไว้ตามค่าเริ่มต้น สำหรับ plaintext http1-and-http2 origins
  • +จำกัด handshake ของ native upstream H2, เวลารอ stream slot, keepalive ping และ timeout ระหว่างตั้งค่า

เผยแพร่เมื่อวันที่ 23 มิถุนายน 2026

  • +ย้ายนโยบาย compression ระดับ global/vhost ที่สืบทอดมาไปยัง native HTTP/1 proxy และ route proxy
  • +ผสานการสืบทอดนโยบายส่วนหัว root/vhost/route เข้ากับการสร้างพร็อกซีเส้นทางดั้งเดิม
  • +ย้ายความเป็นเจ้าของ forwarded-client-IP ที่ปลอดภัย การต่อ trusted-chain การเขียน regex ใหม่ ACL concurrency และ rate limit ไปยังเส้นทางเนทีฟ
  • +เพิ่มการให้บริการ ACME HTTP-01 challenge แบบเนทีฟ, การทำ traffic mirroring, auth-request และการตรวจสอบ gRPC ระดับ route

เผยแพร่เมื่อวันที่ 21 มิถุนายน 2026

  • +Moves route-level native response compression onto the HTTP/1 route proxy through fluxheim-compression
  • +Moves proxy.error_pages onto native HTTP/1 proxy หน้าทางเลือกที่ได้รับการสนับสนุนโดย fluxheim-web

เผยแพร่เมื่อวันที่ 21 มิถุนายน 2026

  • +Adds native HTTP/1 route static-web serving backed by fluxheim-web
  • +Adds route request-header mutation, response rewrites, static upstream round-robin, and static upstream weights to the native route proxy

เผยแพร่เมื่อวันที่ 21 มิถุนายน 2026

  • +Adds native route redirect actions with safe {uri}, {path}, and {query} expansion
  • +Moves route body limits and response-header overlays onto native HTTP/1 route proxy responses

เผยแพร่เมื่อวันที่ 21 มิถุนายน 2026

  • +Adds native HTTP/1 route-proxy execution for exact, prefix, and fallback routes with method filters and safe rewrite handling
  • +Adds native-http1-proxy-candidate หลักฐานการตัดแถวไปจนถึงรันไทม์ ดังนั้นตัวบล็อกความเข้ากันได้ที่เหลืออยู่จึงมีความชัดเจน

เผยแพร่ 20 มิถุนายน 2026

  • +Promotes the native HTTP/2 downstream ปลอดภัยty preview to cutover-ready after focused parity tests
  • +Makes the representative native runtime cutover report blocker-free for simple HTTP/1, HTTP/2, admin, เมตริก, stream, and UDP การกำหนดค่าs

เผยแพร่ 20 มิถุนายน 2026

  • +Cuts stream and UDP proxy service startup over to Fluxheim-owned native task boundaries
  • +Adds cancellation-safe native shutdown waiting and abort-on-cancel background task joins

เผยแพร่ 20 มิถุนายน 2026

  • +Starts native admin and metrics serving behind Fluxheim-owned server primitives
  • +เสริมความแข็งแรง native background handles so dropped critical handles abort instead of silently detaching tasks

เผยแพร่ 20 มิถุนายน 2026

  • +Adds NativeBackgroundSupervisor สำหรับการประสานงานเบื้องหลังที่ Fluxheim เป็นเจ้าของ
  • +Adds critical task watchdog support and hardens shutdown delivery edge cases

เผยแพร่ 20 มิถุนายน 2026

  • +Adds native runtime cutover evidence gates and fluxheim-config-tester --runtime-cutover
  • +Moves remaining Pingora exception targets to a documented multi-release exit plan while keeping policy gates active

เผยแพร่ 19 มิถุนายน 2026

  • +Adds explicit pingora-compat คุณลักษณะ gating สำหรับขอบเขตรันไทม์ความเข้ากันได้ที่เหลืออยู่
  • +Moves rustls/OpenSSL downstream TLS SNI, certificate storage, reload, PEM parsing, and native HTTP/1 TLS listener previews into Fluxheim-owned code

เผยแพร่ 19 มิถุนายน 2026

  • +Continues the Pingora-exit slice by shrinking the remaining root compatibility surface for proxy, แคช, and runtime paths
  • +Splits native การตรวจสุขภาพ into HTTP/gRPC, database, exec, and TCP/TLS transport helper modules with stricter probe bounds

เผยแพร่ 19 มิถุนายน 2026

  • +ลบ the direct Pingora dependency from fluxheim-load-balancer
  • +เพิ่ม Fluxheim-owned bounded HTTP/1.1 and h2 gRPC active การตรวจสุขภาพ with policy coverage to prevent Pingora reintroduction

เผยแพร่ 19 มิถุนายน 2026

  • +เพิ่ม native HTTP/1.1 proxy cutover readiness planning on ServerPlan
  • +Fails closed for compatibility-only proxy features such as auth subคำขอ, mirroring, redirects, strip/rewrite transforms, and advanced load-balancer policy

เผยแพร่ 18 มิถุนายน 2026

  • +เพิ่ม a Fluxheim-owned native HTTP/2 อัปสตรีม client primitive with bounded headers, bodies, trailers, and deadlines
  • +เพิ่ม h2 client/server tests สำหรับ trailer preservation, oversized responses, stream resets และ flow-control timeout behavior

เผยแพร่ 18 มิถุนายน 2026

  • +เพิ่ม native rustls/OpenSSL อัปสตรีม TLS and mTLS support to the staged HTTP/1.1 proxy path
  • +เพิ่ม ordered static อัปสตรีม failover for ปลอดภัย methods plus bounded no-follow TLS material reads and hostname-policy coverage

เผยแพร่ 18 มิถุนายน 2026

  • +เพิ่ม connection pooling ของ upstream แบบ native HTTP/1.1 ที่จำกัด สำหรับ content-length ที่ปลอดภัยและ origin response ที่ไม่มี body
  • +เพิ่ม keepalive pool sizing, อัปสตรีม idle timeout handling, conservative no-reuse guards, and real socket reuse/expiry tests

เผยแพร่ 18 มิถุนายน 2026

  • +เพิ่ม reusable native HTTP/2 connection primitives with bounded คำขอ-body collection and การตอบกลับ trailer support
  • +Hardens HTTP/2 การตอบกลับ lifetime, handler timeout, DATA capacity handling, prohibited headers/trailers, and คำขอ-body zeroization

เผยแพร่ 17 มิถุนายน 2026

  • +เพิ่ม the native HTTP/2 runtime preview gate and h2 stack probe with bounded headers, URI, body, streams, frames, buffers, and rapid reset policy
  • +เพิ่ม HTTP/2 preview smoke coverage and extends native HTTP/1 behavior coverage for HTTP/1.0 keep-alive/close semantics

เผยแพร่ 17 มิถุนายน 2026

  • +เพิ่ม upstream client แบบ native HTTP/1 ที่จำกัด และ staged native proxy handler สำหรับ upstream แบบ plain static
  • +เพิ่ม native proxy candidate inventory, Fluxheim-owned proxy headers, privacy-mode behavior, and fail-closed eligibility for unsupported policy layers

เผยแพร่ 17 มิถุนายน 2026

  • +เพิ่ม the native HTTP/1 connection/listener runtime over Tokio IO and staged native static-file adapter
  • +เซิร์ฟเวอร์ Maps จำกัดนโยบาย HTTP/1 ดั้งเดิม และเพิ่มการทดสอบซ็อกเก็ตสำหรับ Keep-alive, Body Framing, การปิดระบบ, ไฟล์คงที่, ไคลเอนต์ที่ช้า และขีดจำกัดการเชื่อมต่อ

เผยแพร่ 17 มิถุนายน 2026

  • +เพิ่ม Fluxheim-owned HTTP/1.0/HTTP/1.1 คำขอ-head parsing, คำขอ-body framing classification, Host validation, persistence handling, and chunked decoding
  • +เพิ่ม downstream HTTP/1 policy defaults and hardened native parser boundaries for future runtime cutover work

เผยแพร่ 16 มิถุนายน 2026

  • +Moves server bootstrap planning, listener inventory, service intent, background-task intent, HTTP/2 policy, PROXY protocol policy, and private Unix socket planning into fluxheim-server
  • +คงรันไทม์ปัจจุบันไว้เป็นอะแดปเตอร์ความเข้ากันได้ที่ชัดเจน ในขณะที่เซิร์ฟเวอร์/ตัวฟังดั้งเดิมยังคงทำงานต่อไป

เผยแพร่ 16 มิถุนายน 2026

  • +Adds fluxheim-tls เป็นการวางแผนผู้ฟัง TLS ดาวน์สตรีมและขอบเขตนโยบายของผู้ให้บริการ
  • +Moves TLS listener plans, SNI selection, wildcard matching, ALPN/cipher/curve policy, and rustls/OpenSSL provider checks into the TLS crate
  • +เสริมความแข็งแรง TLS feature gates, SNI fallback behavior, PROXY v2 signature validation, and trusted PROXY CIDR validation

เผยแพร่ 16 มิถุนายน 2026

  • +เพิ่ม the first dedicated fluxheim-headers ขอบเขตสำหรับผู้ช่วยนโยบายส่วนหัว
  • +ย้ายอัลกอริทึม rewrite การจัดการ forwarded-header นโยบายคำขอแบบ hop-by-hop และการรวม repeated-header ไปไว้ในโค้ดส่วนหัวที่ Fluxheim เป็นเจ้าของ
  • +ย้าย stream PROXY protocol byte parsers into fluxheim-protocol and tightens privacy/proxy CIDR validation

เผยแพร่ 15 มิถุนายน 2026

  • +ย้าย shared background task lifecycle primitives into fluxheim-runtime
  • +Moves OTLP metrics export, ACME certificate reload control, admin snapshot validation state, and rollback decisions into Fluxheim-owned runtime/snapshot code
  • +Hardens the local certificate reload control socket and ส่วนตัว แบ็กเอนด์ filtering

เผยแพร่ 15 มิถุนายน 2026

  • +Adds fluxheim-stream as the internal TCP stream proxy runtime boundary
  • +ย้ายการเลือกอัปสตรีมของสตรีม การอ่าน/เขียน PROXY protocol นโยบายต้นทาง การป้องกัน DNS rebinding การนับไบต์ และการจัดการ timeout ไปไว้หลังโค้ดสตรีมที่ Fluxheim เป็นเจ้าของ

เผยแพร่ 14 มิถุนายน 2026

  • +Moves cache key identity, object envelopes, disk index management, storage-bin helpers, tag handling, and cache storage interfaces into fluxheim-cache
  • +เพิ่ม tests and release gates that enforce Pingora dependency removal targets during normal cargo test runs

เผยแพร่ 14 มิถุนายน 2026

  • +เริ่มการเปิดตัวการใช้งาน 1.6.x อย่างเป็นรูปธรรมครั้งแรกหลังแท็กรองพื้น
  • +Removes pingora-load-balancing/pingora-ketama from full and load-balancer image profiles, restores 1.6 load-balancer image builds, and moves TCP health checks plus request-key extraction behind Fluxheim-owned boundaries

เผยแพร่ 14 มิถุนายน 2026

  • +Started the 1.6.xบรรทัดพื้นฐาน Pingora-exit ในขณะที่ยังคงรักษาพฤติกรรมรันไทม์ไม่เปลี่ยนแปลง
  • +Added แบบโมดูลาร์ity policy validation, legacy oversized-file exceptions, runtime baseline capture, and performance evidence capture
  • +เพิ่มข้อยกเว้นการพึ่งพา Pingora แบบ release-gated, การติดตั้งพาริตีรันไทม์ และกราฟการพึ่งพาการแยกข้อมูล
  • +Added initial fluxheim-runtime and fluxheim-server ลังขอบเขตบวกพิมพ์หลักฐานนโยบายดั้งเดิม

มิถุนายน 2026

  • +Introduced the enterprise HTTP/TCP load-balancer line with focused binaries, images, runtime member and weight controls, persistence, health checks, queueing, and migration docs
  • +Expanded Fluxheim-owned runtime boundaries across HTTP, stream proxying, load balancing, background tasks, cache interfaces, observability, config, and shared crates
  • +Added managed affinity cookies, service discovery, active and protocol-aware การตรวจสุขภาพ, restart-persistent state, and runtime แบ็กเอนด์ mutation controls
  • +Added UDP beta guardrails, cache origin-protection budgets, ARM/Linux and macOS developer assets, config tester archives, and broad proxy/cache/PHP-FPM security hardening

เผยแพร่ 25 พฤษภาคม 2026

  • +Production proxy parity release with trusted-proxy-aware ACLs, local rate limits, concurrency limits, bounded queues, and edge policy metrics
  • +gzip, Zstandard, and Brotli response compression with vhost/route overrides and cache-safe Vary handling
  • +Load-balancer resilience, TLS/protocol parity, PROXY protocol v1/v2, อัปสตรีม mTLS, HTTP/2 controls, and gRPC pass-through

เผยแพร่ 23 พฤษภาคม 2026

  • +Managed php-fpm process supervision under the existing php-fpm feature, while external php-fpm remains the default
  • +Respawn watchdog, bounded backoff, SIGTERM-before-SIGKILL teardown, sanitized environment, and ส่วนตัว generated pool state
  • +Auditable [vhosts.php.fpm] mode = "managed" config surface for ส่วนตัว sockets, worker counts, process manager modes, slowlog, temp paths, and pool files
  • +ขยายการครอบคลุมควัน WordPress PHP-FPM ในโหมดภายนอก, โหมดการจัดการคงที่, โหมดการจัดการไดนามิก, โหมดการจัดการตามความต้องการ และโหมดการจัดการการตอบสนอง
  • +Recommended Wolfi PHP image now installs php-8.5-fpm and uses managed php-fpm container config by default

เผยแพร่ 23 พฤษภาคม 2026

  • +FIPS/ISO-required configs fail closed for unsupported internal cryptography, managed ACME, and local cache encryption
  • +Provider-backed admin auth, numeric-local-loopback OTLP exception, and OpenBao Transit cache encryption evidence boundary
  • +New compliance evidence template and release evidence package sections for regulated reviews

เผยแพร่ 22 พฤษภาคม 2026

  • +rustls/AWS-LC FIPS-capable candidate แบ็กเอนด์ through tls-rustls-fips
  • +นามแฝงโปรไฟล์ FIPS และ ISO/IEC 19790, ตัวอย่างการกำหนดค่า, การวินิจฉัย และสคริปต์การตรวจสอบ

เผยแพร่ 21 พฤษภาคม 2026

  • +การตรวจสอบ TLS ที่รองรับ OpenSSL FIPS/ISO tls-openssl-fips และการวินิจฉัยผู้ให้บริการ
  • +คู่มือการปรับใช้ FIPS, โปรแกรมติดตั้งการกำหนดค่า, สคริปต์การตรวจสอบ, หลักฐานการเผยแพร่ และข้อมูลพื้นฐาน 10 อันดับแรกปี 2025 ของ OWASP

เผยแพร่ 20 พฤษภาคม 2026

  • +PHP-FPM keepalive pooling, อัปสตรีม retry/failover, and คำขอ body disk spooling for ปลอดภัยr operation under load
  • +WordPress routing/cache preset plus PHP application recipes for common framework and forum deployments
  • +PHP เมตริก and OpenTelemetry attributes, X-Accel-Redirect, X-Sendfile, and X-Accel-Expires support

เผยแพร่ 18 พฤษภาคม 2026

  • +fluxheim-acme ไบนารีคู่หูแบบสแตนด์อโลนสำหรับการต่ออายุใบรับรอง สถานะ และการส่งสัญญาณซ็อกเก็ตรีโหลด ACME
  • +fluxheim-config-tester standalone binary for validating configs in CI and คอนเทนเนอร์ entrypoints without starting the gateway
  • +ACME รีโหลดซ็อกเก็ต Unix — รับใบรับรองสดโดยไม่ต้องรีสตาร์ทเกตเวย์
  • +ใหม่ profile-php build profile — proxy + web + php-fpm + tls-rustls + security
  • +Security hardening improvements across the request pipeline

เผยแพร่ 16 พฤษภาคม 2026

  • +Opt-in PHP-FPM FastCGI bridge for WordPress-style front-controller applications
  • +Strict script resolution and bounded FastCGI คำขอ/การตอบกลับ handling
  • +Browser-validated WordPress proxy/PHP cookie compatibility fixes
  • +PHP-FPM สามารถให้บริการสินทรัพย์คงที่จากรูทเดียวกันในขณะที่กำหนดเส้นทาง PHP ไปยัง FPM
  • +New php-fpm Cargo feature (implies พร็อกซี and web)

เผยแพร่ 14 พฤษภาคม 2026

  • +Shared ingress/TLS feature-graph split — focused cache and proxy profiles are now TLS/ACME-capable
  • +New profile-cache-edge — cache without static web module
  • +New profile-proxy-edge — focused reverse proxy edge
  • +Official focused container images for cache and proxy profiles
v1.2.x ซีรีส์

พฤษภาคม 2026

v1.2.6

  • + Fixed-slice range-cache composition: open-ended, suffix, and multipart byte-range
  • + Opt-in range_slice_cache = true ขยายขอบเขตแคช

v1.2.5

  • + Bounded range caching for large proxy-cache objects

v1.2.4

  • + Distributed cache peer fill with safe only-if-cached peer fetches
  • + พฤติกรรมการเติมเพียร์ที่เปิดล้มเหลว/ล้มเหลวที่ถูกปิดแบบมีขอบเขต

v1.2.3

  • + Optional disk cache encryption with local keys or OpenBao Transit

v1.2.2

  • + Storage-bin disk cache backend for larger high-churn caches

v1.2.1

  • + เลือกใช้การแคชไฟล์คงที่ในเครื่องผ่าน local_static = true

v1.2.0 — Cache & Observability Baseline

  • + Vhost/route cache policy, memory/disk/tiered cache backends
  • + แคช locks, stale serving, purge and status endpoints
  • + แคช warm, key assertion, and lookup tooling
  • + Prometheus metrics listener
  • + OpenTelemetry export profiles (metrics + tracing)
v1.1 — Certificate Operations

2026

  • + โปรไฟล์นโยบาย TLS
  • + Multi-certificate rustls SNI
  • + การออกและการต่ออายุใบรับรอง ACME ที่มีการจัดการ
  • + ผู้ออกที่รองรับ EAB (Actalis และอื่น ๆ )
  • + ความลับ TLS ที่สำรองไฟล์
  • + acme-init เครื่องมือบูตสแตรปของผู้ออกที่แนะนำ
  • + หน่วยระบบการต่ออายุใบรับรองแบบแพ็กเกจ
v1.0 — Gateway Foundation มีเสถียรภาพเริ่มต้น

2026

  • + การกำหนดเส้นทางโฮสต์เสมือนโดยส่วนหัวของโฮสต์พร้อมทางเลือกสำรอง vhost เริ่มต้น
  • + Route-level static, proxy, and redirect actions
  • + Static file serving with MIME detection, ETag, conditional 304, byte ranges
  • + Whole-vhost and route-level reverse proxying
  • + rustls TLS with SNI, static/bought certificate support
  • + การส่งต่อความท้าทาย ACME HTTP-01 ที่ปลอดภัย
  • + Admin control-plane with bearer-token auth and brute-force throttling
  • + Secure คำขอ/การตอบกลับ header policy
  • + การเปลี่ยนเส้นทาง HTTP → HTTPS แบบเลือกเปิดได้พร้อมการตรวจสอบ Host ที่ปลอดภัย
  • + หน่วย Systemd, บรรจุภัณฑ์ RPM
  • + Rootless Podman container images

อะไรต่อไป

1.8.0: รุ่น Wasm โดยเฉพาะซึ่งสร้างจากโปรไฟล์สำหรับการผลิตแบบเต็ม พร้อมจุดเชื่อมนโยบายที่จำกัดขอบเขต ACME เมตริก และ OpenTelemetry.

View full roadmap →
ไทย