更新記錄
Release history for Fluxheim. 完整 發布說明 are on GitHub 發布.
2026年7月23日發布
- +以完整生產設定檔為基礎嘅專用 Wasm 組建,設有限定範圍嘅政策掛接點,並支援 ACME、指標同 OpenTelemetry
- +加入對應嘅 tar.gz 同 ZIP 壓縮檔,包括 macOS 原生完整組建同 Wasm 組建
- +加強快取填入、範圍快取同每個 vhost 嘅 Wasm 准入邊界
2026 年 7 月 15 號發佈
- +加入可選擇啟用、符合標準嘅快取、代理同回應摘要元數據
- +驗證經身份認證嘅線上快照重新載入同回復、完整性檢查,以及重新啟動後嘅持久性
- +加入可重現嘅 FIPS 後端證據,並全面強化原生執行環境
2026 年 7 月 14 號發布
- +加入限時等現有連線完成處理嘅平穩下線機制,同埋通過就緒檢查先進行嘅零停機切換
- +加入嚴格嘅 systemd socket 啟動,準確驗證繼承返嚟嘅監聽端點
- +完成 HTTP/1 解析器加固,並加強背景服務嘅歸屬管理
喺2026年7月13號發佈
- +加入咗可選嘅 HTTP 回應安全設定檔同埋經過驗證嘅請求感知 CORS
- +穩定可執行嘅 Wasm 政策例子同埋發佈閘所需嘅測試
- +加強轉寄嘅身分標題、標題解析同埋容量限制嘅重試指引
2026年7月12日發佈
- +為 iRules 、 OpenResty 、 HAProxy/SPOE 同埋 VCL 式策略作業加入可執行嘅轉移例子
- +加入有界 ACME 傳輸、 ARI 調度、生命週期診斷同埋明確嘅條款接受
- +硬化可恢復嘅 ACME 帳戶同憑證交易、儲存邊界同埋快照發佈
發佈於 2026 年 7 月 11 日
- +啟動 opt-in WASI Preview 1 邊界,明確授予時鐘與隨機數功能,並採用預設拒絕的導入方式
- +恢復受信任客戶端 GeoIP 功能,支援 CIRCL 組合的國家與 ASN 資料庫
- +加強串流 SSRF 及複製、認證快照、TLS、PHP-FPM、靜態服務及 Wasm 資源限制
2026 年 7 月 10 日發佈
- +加入可自行啟用嘅 Proxy-Wasm ABI preview,並明確驗證 host-call namespace
- +喺唔支援嘅 preview call 去到 upstream 之前,以確定方式拒絕
- +加強 strict host routing、受限 admission、config 信任、cache storage、GeoIP 同 compression
2026 年 7 月 9 日發布
- +為 compiled WebAssembly module 加入明確 identity,範圍包括 plugin digest、ABI、hook feature surface 同 Fluxheim version
- +喺 process-wide cache-hook ceiling 之下加入每個 vhost 嘅 cache-hook admission budget
- +擴充受限 Wasm metrics、admin status visibility 同 cross-family live-chain regression coverage
2026 年 7 月 8 日發布
- +為 mobile 同 desktop device-class variant 加入受限 cache-key component host call
- +加入固定 cache-store TTL、tag 同 stored-header metadata,而唔容許任意 response-header mutation
- +加入 live listener coverage,驗證 variant isolation、range-cache slice、TTL expiry 同 fail-closed metadata cap
2026 年 7 月 7 日發佈
- +喺受限嘅 fluxheim_policy_v1 preview ABI 下加入即時 native HTTP/1 cache-lookup 同 cache-store Wasm hook
- +加入 continue、pass、bypass、skip-store 同 deny 呢啲 cache 結果,同時唔暴露原始 cache key、TTL、tag 或已儲存 metadata
- +分開 cache-hook admission 限制,並保留 cache-store 彙總嘅 most-restrictive-wins 規則
2026 年 7 月 6 日發布
- +喺受限嘅 fluxheim_policy_v1 preview ABI 下加入即時 native HTTP/1 route-decision Wasm hook
- +為 canary 同 mirror 路由加入已設定分支嘅符號式選擇,唔提供動態 upstream 或 shadow-target 存取
- +路由選擇後繼續執行 Fluxheim ACL、rate-limit、concurrency、body-limit、redirect 同 header-policy
2026 年 7 月 5 日發佈
- +為 vhost 同 route attachment 加入即時 native HTTP/1 request-header 同 response-header Wasm hook
- +保持 header-hook ABI 做 symbolic,只允許 allow-list 入面嘅 synthetic mutation,而唔係 raw header 或 body 存取
- +將 vhost-level Wasm header hooks 同 fallback response header policy 套用到 PHP-FPM fallback responses
2026 年 7 月 4 日發布
- +接入 live native HTTP/1 access-decision hooks,有優先次序、first-deny-wins 組合同 fail-closed 行為
- +強制 process、plugin 同 attachment 級嘅執行 admission 上限
2026 年 7 月 3 日發佈
- +為 Wasm sandbox 線加入可選嘅 fluxheim-wasm workspace crate
- +wasm、wasm-proxy-abi 同 wasm-wasi feature gate 預設關閉,而且唔兼容 privacy-mode
- +Wasm plugin 檔案只會由已核准嘅絕對 root 載入;symlink、非一般檔案同過大 module 都會被拒絕
- +有型別嘅 Wasm plugin manifest 會喺載入前驗證 ABI、phase、fail-mode、path 同 sandbox 限制
- +以 fuel、memory、table、instance、compile-timeout、compile-worker 同每次呼叫 watchdog 限制 Wasmtime 執行
- +加入真實 Wasm sandbox smoke 覆蓋,檢查成功執行、trap、拒絕 table 增長,以及拒絕唔安全嘅 fail-open manifest
2026 年 7 月 3 日發佈
- +將固定咗嘅 Rust toolchain、rust-version 欄位同 container builder images 更新到 Rust 1.96.1
- +用 TLS 1.2 最低要求同現代 TLS 1.2/TLS 1.3 cipher allowlist,加固 OpenSSL stream-upstream TLS connectors
- +寫入磁碟嗰陣,將序列化咗嘅 ACME 帳戶憑證放喺 sanitization::SecretVec 入面
- +移除淨低嘅 root compatibility shims,等 caller 可以直接用 fluxheim-common、fluxheim-config、fluxheim-cache、fluxheim-observability 同其他 owning crates
- +將 ACME、observability、cache、load-balancer、PHP-FPM、snapshot、web、stream 同 native runtime 內部拆細做更集中嘅 modules
2026 年 6 月 30 日發佈
- +將臨時 native proxy 轉接層改名做 native_proxy,並喺一般建置入面移除舊有 proxy 相容性嘅重新匯出
- +將負載平衡器管理介面嘅請求同結果 DTO 移入 fluxheim-load-balancer crate
- +刪除一般建置已經唔再使用嘅 Pingora 時代失效根轉接器,同埋過時而且已停用嘅執行階段及測試程式碼
- +整合 native proxy 設定儲存,等重新載入時會更新快取同負載平衡器管理路徑共同使用嘅同一份快照
- +加入原生 HTTP/1 chunked body 溢位嘅迴歸測試,並將可觀測性冒煙測試映像固定到可重現嘅標籤
2026 年 6 月 30 日發佈
- +將 normal runtime 保持喺 Fluxheim-owned listener、TLS、HTTP/1、HTTP/2、WebSocket、cache、load-balancer、admin、metrics、stream 同 background service paths
- +將 auth、metrics、OpenBao cache、discovery、load-balancer cookie 同 TLS private-key secret buffers 遷移去 sanitization crate
- +強化 PHP-FPM/static fallback routing、native disk-cache purge locking、same-key disk-cache mutation serialization 同 native HTTP/2 upstream authority handling
- +加入 peer-fill shared-secret 支援,並要求 non-loopback plaintext peer-fill URLs 必須使用
- +為 stabilization line 擴展 privacy、observability、WordPress、load-balancer、smoke-image、randomized-port 同 release-gate test coverage
2026年6月29日發佈
- +移除正常 Fluxheim build profiles 入面最後嘅 Pingora runtime/listener/TLS adapter crates
- +將原生 HTTP/1 同 HTTP/2 proxy runtime 保持為受支援 route、cache、load-balancer、TLS、WebSocket、admin 同 metrics 配置嘅正常路徑
- +將原生 admin cache purge、stale disk-cache purge、cache object lookup 同即時 load-balancer stats/mutation handlers 接到 Fluxheim-owned runtime handles
- +更新 dependency-policy release gates,令 normal default、full、edge、PHP、privacy、RPM、source 同 container builds 如果編譯 Pingora crates 就會失敗
- +用標準化 host matching、regex-route previews、stale purge lock avoidance、fail-closed live config state 同 typed route-proxy build contexts 強化原生 admin cache previews 同 purges
2026年6月29日發佈
- +為記憶體、檔案系統磁碟、storage-bin、加密磁碟、OpenBao Transit 同 memory+disk 分層加入原生 proxy-cache 功能對齊
- +支援 Vary 同 request-header 變種、過時服務、快取鎖、範圍切片快取、 peer-fill 同埋原點保護預算
- +哈登斯緩存入場,包括 Authorization 、 HEAD 繞過、上游 Age 剝離、檢查到期算數同埋 only-if-cached 錯過
- +為記憶體同磁碟索引加入原生快取清除功能對齊,並支援 exact、bulk、prefix、tag、wildcard、route-scope 同 stale purges
- +為代理計數器、記憶體/磁碟計量器、快取查找直方圖同埋重新生成嘅 traceparent 跨度 ID 加入原生快取可觀察性
2026年6月28日發佈
- +Adds native runtime dispatch for proxy, admin, metrics, stream, UDP, and load-balancer refresh tasks
- +Adds metrics token-file loading with zeroizing storage and constant-time bearer-token checks
- +Adds native HTTP/1 proxy runtime startup for plaintext, rustls, OpenSSL, and trusted downstream PROXY protocol listeners
- +將揀選嘅下游 HTTP/2 TLS 連線路由到原生多串流適配器
- +加強原生 WebSocket 升級、HTTP/2 串流內故障處理、速率限制分片同請求主體嘅 zeroizing 儲存
2026年6月24日發佈
- +Moves cache request policy and local-static cache keys into the Pingora-independent
fluxheim-cachecrate - +Moves PHP-FPM parsing, params, path mapping, static offload, error-page policy, and keep-alive pooling into
fluxheim-php-fpm - +Adds native memory local-static cache adapters for route and vhost static-web serving
- +Adds native upstream PROXY protocol v1/v2 send support and native Host router construction
- +Adds native runtime manifest and launch-plan evidence for services, listeners, background tasks, and policy rows
發售日期:2026 年 6 月 23 日
- +將 plaintext 上游 HTTP/2 轉發移入 h2c/prior-knowledge origin 用嘅原生 HTTP/1 proxy path
- +加入 pooled native upstream H2 connection,限制 stream capacity,並喺 response 前 pooled handle 失敗後為 safe method retry
- +支援用現有上游 TLS/SNI/CA policy,經 TLS ALPN 協商嘅上游 HTTP/2
- +為 plaintext
http1-and-http2origins 加入明確、預設關閉嘅 h2c Upgrade fallback - +限制原生上游 H2 handshake、stream-slot 等候、keepalive ping 同設定 timeout
發售日期:2026 年 6 月 23 日
- +移動 inherited global/vhost compression policy into the native HTTP/1 代理 and route 代理
- +Merges root/vhost/route header-policy inheritance into native route 代理 construction
- +將安全 forwarded-client-IP 擁有權、trusted-chain append、regex rewrite、ACL、concurrency 同 rate limit 移到原生路徑
- +加入 native ACME HTTP-01 challenge serving, 流量 mirroring, auth-請求, and route-scoped gRPC validation
發售日期:2026 年 6 月 21 日
- +Moves route-level native response compression onto the HTTP/1 route proxy through
fluxheim-compression - +Moves
proxy.error_pagesonto native HTTP/1 proxy 後備頁面支持fluxheim-web
發售日期:2026 年 6 月 21 日
- +Adds native HTTP/1 route static-web serving backed by
fluxheim-web - +Adds route request-header mutation, response rewrites, static upstream round-robin, and static upstream weights to the native route proxy
發售日期:2026 年 6 月 21 日
- +Adds native route redirect actions with safe
{uri},{path}, and{query}expansion - +Moves route body limits and response-header overlays onto native HTTP/1 route proxy responses
發售日期:2026 年 6 月 21 日
- +Adds native HTTP/1 route-proxy execution for exact, prefix, and fallback routes with method filters and safe rewrite handling
- +Adds
native-http1-proxy-candidate行到運行時切換證據,因此剩餘的兼容性阻止程序是明確的
2026 年 6 月 20 日發布
- +Promotes the native HTTP/2 downstream 安全ty preview to cutover-ready after focused parity tests
- +Makes the representative native runtime cutover report blocker-free for simple HTTP/1, HTTP/2, admin, 指標, stream, and UDP 設定s
2026 年 6 月 20 日發布
- +Cuts stream and UDP proxy service startup over to Fluxheim-owned native task boundaries
- +Adds cancellation-safe native shutdown waiting and abort-on-cancel background task joins
2026 年 6 月 20 日發布
- +Starts native admin and metrics serving behind Fluxheim-owned server primitives
- +加固 native background handles so dropped critical handles abort instead of silently detaching tasks
2026 年 6 月 20 日發布
- +Adds
NativeBackgroundSupervisor用於 Fluxheim 擁有的後台任務編排 - +Adds critical task watchdog support and hardens shutdown delivery edge cases
2026 年 6 月 20 日發布
- +Adds native runtime cutover evidence gates and
fluxheim-config-tester --runtime-cutover - +Moves remaining Pingora exception targets to a documented multi-release exit plan while keeping policy gates active
2026 年 6 月 19 日發布
- +Adds explicit
pingora-compat剩餘相容性運作時邊界的功能門控 - +Moves rustls/OpenSSL downstream TLS SNI, certificate storage, reload, PEM parsing, and native HTTP/1 TLS listener previews into Fluxheim-owned code
2026 年 6 月 19 日發布
- +Continues the Pingora-exit slice by shrinking the remaining root compatibility surface for proxy, 快取, and runtime paths
- +Splits native 健康檢查 into HTTP/gRPC, database, exec, and TCP/TLS transport helper modules with stricter probe bounds
2026 年 6 月 19 日發布
- +移除 the direct Pingora dependency from
fluxheim-load-balancer - +加入 Fluxheim-owned bounded HTTP/1.1 and h2 gRPC active 健康檢查 with policy coverage to prevent Pingora reintroduction
2026 年 6 月 19 日發布
- +加入 native HTTP/1.1 proxy cutover readiness planning on
ServerPlan - +Fails closed for compatibility-only proxy features such as auth sub請求, mirroring, redirects, strip/rewrite transforms, and advanced load-balancer policy
2026 年 6 月 18 日發布
- +加入 a Fluxheim-owned native HTTP/2 上游 client primitive with bounded headers, bodies, trailers, and deadlines
- +加入 h2 client/server tests for trailer preservation, oversized 回應s, stream resets, and flow-control timeout behavior
2026 年 6 月 18 日發布
- +加入 native rustls/OpenSSL 上游 TLS and mTLS support to the staged HTTP/1.1 proxy path
- +加入 ordered static 上游 failover for 安全 methods plus bounded no-follow TLS material reads and hostname-policy coverage
2026 年 6 月 18 日發布
- +加入受限 native HTTP/1.1 上游連線池,用於安全 content-length 同無 body 嘅 origin 回應
- +加入 keepalive pool sizing, 上游 idle timeout handling, conservative no-reuse guards, and real socket reuse/expiry tests
2026 年 6 月 18 日發布
- +加入 reusable native HTTP/2 connection primitives with bounded 請求-body collection and 回應 trailer support
- +Hardens HTTP/2 回應 lifetime, handler timeout, DATA capacity handling, prohibited headers/trailers, and 請求-body zeroization
2026 年 6 月 17 日發布
- +加入 the native HTTP/2 runtime preview gate and h2 stack probe with bounded headers, URI, body, streams, frames, buffers, and rapid reset policy
- +加入 HTTP/2 preview smoke coverage and extends native HTTP/1 behavior coverage for HTTP/1.0 keep-alive/close semantics
2026 年 6 月 17 日發布
- +加入受限 native HTTP/1 上游 client,以及用於 plain static 上游嘅 staged native proxy handler
- +加入 native proxy candidate inventory, Fluxheim-owned proxy headers, privacy-mode behavior, and fail-closed eligibility for unsupported policy layers
2026 年 6 月 17 日發布
- +加入 the native HTTP/1 connection/listener runtime over Tokio IO and staged native static-file adapter
- +將伺服器限制對應到本機 HTTP/1 策略,並新增用於保持活動、正文框架、關閉、靜態檔案、慢速客戶端和連線上限的套接字測試
2026 年 6 月 17 日發布
- +加入 Fluxheim-owned HTTP/1.0/HTTP/1.1 請求-head parsing, 請求-body framing classification, Host validation, persistence handling, and chunked decoding
- +加入 downstream HTTP/1 policy defaults and hardened native parser boundaries for future runtime cutover work
2026 年 6 月 16 日發布
- +Moves server bootstrap planning, listener inventory, service intent, background-task intent, HTTP/2 policy, PROXY protocol policy, and private Unix socket planning into
fluxheim-server - +在本機伺服器/偵聽器工作繼續的同時,將目前運行時保持為顯式相容性適配器
2026 年 6 月 16 日發布
- +Adds
fluxheim-tls作為下游 TLS 偵聽器規劃和提供者策略邊界 - +Moves TLS listener plans, SNI selection, wildcard matching, ALPN/cipher/curve policy, and rustls/OpenSSL provider checks into the TLS crate
- +加固 TLS feature gates, SNI fallback behavior, PROXY v2 signature validation, and trusted PROXY CIDR validation
2026 年 6 月 16 日發布
- +加入 the first dedicated
fluxheim-headers標頭策略助手的邊界 - +將 rewrite 演算法、forwarded-header 處理、hop-by-hop 請求政策同 repeated-header 合併移入 Fluxheim 自家 header 程式碼
- +移動 stream PROXY protocol byte parsers into
fluxheim-protocoland tightens privacy/proxy CIDR validation
2026 年 6 月 15 日發布
- +移動 shared background task lifecycle primitives into
fluxheim-runtime - +Moves OTLP metrics export, ACME certificate reload control, admin snapshot validation state, and rollback decisions into Fluxheim-owned runtime/snapshot code
- +Hardens the local certificate reload control socket and 私有 後端 filtering
2026 年 6 月 15 日發布
- +Adds
fluxheim-streamas the internal TCP stream proxy runtime boundary - +將 stream 上游選擇、PROXY protocol 解析/寫入、來源政策、DNS rebinding 防護、位元組計數同 timeout 處理放到 Fluxheim 自家 stream 程式碼之後
2026 年 6 月 14 日發布
- +Moves cache key identity, object envelopes, disk index management, storage-bin helpers, tag handling, and cache storage interfaces into
fluxheim-cache - +加入 tests and release gates that enforce Pingora dependency removal targets during normal
cargo testruns
2026 年 6 月 14 日發布
- +在基礎標籤之後啟動第一個具體的 1.6.x 實作版本
- +Removes
pingora-load-balancing/pingora-ketamafrom full and load-balancer image profiles, restores 1.6 load-balancer image builds, and moves TCP health checks plus request-key extraction behind Fluxheim-owned boundaries
2026 年 6 月 14 日發布
- +Started the
1.6.xPingora-exit 基礎線,同時保持運行時行為不變 - +Added 模組化ity policy validation, legacy oversized-file exceptions, runtime baseline capture, and performance evidence capture
- +新增了發布控制的 Pingora 依賴異常、運行時奇偶校驗裝置和提取依賴關係圖
- +Added initial
fluxheim-runtimeandfluxheim-server邊界箱加上型別策略證明原語
2026 年 6 月
- +Introduced the enterprise HTTP/TCP load-balancer line with focused binaries, images, runtime member and weight controls, persistence, health checks, queueing, and migration docs
- +Expanded Fluxheim-owned runtime boundaries across HTTP, stream proxying, load balancing, background tasks, cache interfaces, observability, config, and shared crates
- +Added managed affinity cookies, service discovery, active and protocol-aware 健康檢查, restart-persistent state, and runtime 後端 mutation controls
- +Added UDP beta guardrails, cache origin-protection budgets, ARM/Linux and macOS developer assets, config tester archives, and broad proxy/cache/PHP-FPM security hardening
2026 年 5 月 25 日發布
- +Production proxy parity release with trusted-proxy-aware ACLs, local rate limits, concurrency limits, bounded queues, and edge policy metrics
- +gzip, Zstandard, and Brotli response compression with vhost/route overrides and cache-safe
Varyhandling - +Load-balancer resilience, TLS/protocol parity, PROXY protocol v1/v2, 上游 mTLS, HTTP/2 controls, and gRPC pass-through
2026 年 5 月 23 日發布
- +Managed php-fpm process supervision under the existing
php-fpmfeature, while external php-fpm remains the default - +Respawn watchdog, bounded backoff, SIGTERM-before-SIGKILL teardown, sanitized environment, and 私有 generated pool state
- +Auditable
[vhosts.php.fpm] mode = "managed"config surface for 私有 sockets, worker counts, process manager modes, slowlog, temp paths, and pool files - +擴展了 WordPress PHP-FPM 煙霧覆蓋範圍,涵蓋外部、託管靜態、託管動態、託管按需和託管重生模式
- +Recommended Wolfi PHP image now installs
php-8.5-fpmand uses managed php-fpm container config by default
2026 年 5 月 23 日發布
- +FIPS/ISO-required configs fail closed for unsupported internal cryptography, managed ACME, and local cache encryption
- +Provider-backed admin auth, numeric-local-loopback OTLP exception, and OpenBao Transit cache encryption evidence boundary
- +New compliance evidence template and release evidence package sections for regulated reviews
2026 年 5 月 22 日發布
- +rustls/AWS-LC FIPS-capable candidate 後端 through
tls-rustls-fips - +FIPS 和 ISO/IEC 19790 rustls 設定檔別名、設定範例、診斷和驗證腳本
2026 年 5 月 21 日發布
- +OpenSSL 透過 FIPS/ISO 進行 TLS 驗證
tls-openssl-fips和提供者診斷 - +FIPS 部署指南、設定裝置、驗證腳本、發布證據和 OWASP Top 10 2025 基線
2026 年 5 月 20 日發布
- +PHP-FPM keepalive pooling, 上游 retry/failover, and 請求 body disk spooling for 安全r operation under load
- +WordPress routing/cache preset plus PHP application recipes for common framework and forum deployments
- +PHP 指標 and OpenTelemetry attributes, X-Accel-Redirect, X-Sendfile, and X-Accel-Expires support
2026 年 5 月 18 日發布
- +
fluxheim-acme用於證書更新、狀態和 ACME 重新加載套接字訊號的獨立配套二進位文件 - +
fluxheim-config-testerstandalone binary for validating configs in CI and 容器 entrypoints without starting the gateway - +ACME 重新載入 Unix 套接字 — 無需重新啟動閘道即可取得即時證書
- +新增
profile-phpbuild profile —proxy + web + php-fpm + tls-rustls + security - +Security hardening improvements across the request pipeline
2026 年 5 月 16 日發布
- +Opt-in PHP-FPM FastCGI bridge for WordPress-style front-controller applications
- +Strict script resolution and bounded FastCGI 請求/回應 handling
- +Browser-validated WordPress proxy/PHP cookie compatibility fixes
- +PHP-FPM 可以在將 PHP 路由到 FPM 的同時從同一根提供靜態資源
- +New
php-fpmCargo feature (implies代理andweb)
2026 年 5 月 14 日發布
- +Shared ingress/TLS feature-graph split — focused cache and proxy profiles are now TLS/ACME-capable
- +New
profile-cache-edge— cache without static web module - +New
profile-proxy-edge— focused reverse proxy edge - +Official focused container images for cache and proxy profiles
2026 年 5 月
v1.2.6
- + Fixed-slice range-cache composition: open-ended, suffix, and multipart byte-range
- + Opt-in
range_slice_cache = true擴展有界範圍緩存
v1.2.5
- + Bounded range caching for large proxy-cache objects
v1.2.4
- + Distributed cache peer fill with safe
only-if-cachedpeer fetches - + 有界的失敗開啟/失敗關閉對等填充行為
v1.2.3
- + Optional disk cache encryption with local keys or OpenBao Transit
v1.2.2
- + Storage-bin disk cache backend for larger high-churn caches
v1.2.1
- + 透過選擇加入本機靜態檔案快取
local_static = true
v1.2.0 — Cache & Observability Baseline
- + Vhost/route cache policy, memory/disk/tiered cache backends
- + 快取 locks, stale serving, purge and status endpoints
- + 快取 warm, key assertion, and lookup tooling
- + Prometheus metrics listener
- + OpenTelemetry export profiles (metrics + tracing)
2026
- + TLS 策略設定檔
- + Multi-certificate rustls SNI
- + 管理 ACME 憑證授權和更新
- + 具備 EAB 能力的發行人(Actalis 等)
- + 檔案支援的 TLS 機密
- +
acme-init引導發行人引導工具 - + 打包證書更新 systemd 單元
2026
- + 透過具有預設虛擬主機回退功能的主機標頭進行虛擬主機路由
- + Route-level static, proxy, and redirect actions
- + Static file serving with MIME detection, ETag, conditional 304, byte ranges
- + Whole-vhost and route-level reverse proxying
- + rustls TLS with SNI, static/bought certificate support
- + 安全性 ACME HTTP-01 挑戰轉發
- + Admin control-plane with bearer-token auth and brute-force throttling
- + Secure 請求/回應 header policy
- + 可選 HTTP → HTTPS 重新導向,並有安全 Host 驗證
- + Systemd 單元,RPM 打包
- + Rootless Podman container images