Releases: DerKezorm/nexsift
Releases · DerKezorm/nexsift
Release list
nexsift 0.5.0
New
- Backup and restore. Under Settings, Backup: a copy of the database every night (or weekly, monthly, off; how many automatic copies to keep is a setting), one before every update that changes the database, and one whenever you press "Back up now". "Download" gives you an AES-256 ZIP with the database and
secret.key, protected by a password of at least 12 characters; 7-Zip and WinRAR open it without nexsift. Only such an archive kept on another device is a real backup, the copies in/data/backupsshare the disk with nexsift. - Restore from an archive. Upload it under Settings, Backup, look at what it holds (date, version, sources, rules, targets, lines), then confirm. nexsift keeps a copy of the current state as the way back, ends itself and restores at the next start; source tokens, target credentials and Web Push devices keep working. All browsers are signed out afterwards. The container comes back through
restart: unless-stopped, and also throughon-failure, since nexsift ends with exit code 3. - The log in the interface. Under Settings, Log: the newest lines with a filter by level, search, download and clear. Four levels, switchable without a restart; Detailed and Trace switch themselves off after the chosen time. The file is
/data/logs/nexsift.log, rolls over at 5 MB and is gone after 14 days. - Read-only API keys for dashboards such as nexdeck. Under Settings, API keys: flip the switch (off by default), make one key per dashboard.
GET /api/v1/statusandGET /api/v1/threadswithAuthorization: Bearer nxs_…. A key reads numbers and titles only, no message text, and changes nothing.
Changed
- Every error message names a request id. Search for it under Settings, Log to see exactly that request, including refusals with their code.
NEXSIFT_LOG_LEVELis empty by default. The level is set in the interface; when the variable is set (quiet,normal,detailed,trace, orWARNING,INFO,DEBUG) it wins and locks the choice, as the way out when nexsift does not start.
Security
- Nothing secret goes into the log, on no level. Tokens in addresses (
/api/v1/hook/…, the Discord path, Gotify's?token=, ntfy topics) are masked before a line is written, and the libraries that would print whole addresses or database rows stay at warnings. What a message said is only written at Trace. A test sends tokens through every door at Trace and searches the file for them.
nexsift 0.4.0
New
- Link your account at authentik explicitly. Under Settings, Sign-in, "Your account at authentik": one click on "Link with authentik now", sign in there once, done. From then on exactly this account gets in through "Sign in with authentik", and no other. The link is removed in the same place.
Changed
- No more matching by email address. Until now a matching verified address linked the account on the first sign-in. nexsift's own authentik setup reports every address as verified, so that proved nothing. Already linked: nothing changes. Not linked yet: link once after the update. The address field under Account is gone.
Fixed
- You cannot lock yourself out. Signing in with a password can only be switched off once a provider is linked, and the link only removed while the password counts again.
nexsift 0.3.0
New
- Settings in tabs. Account, sign-in, addresses, retention and languages each have a tab of their own; the tab is in the address, so it can be linked.
- About nexsift. A page of its own in the footer: version, license, links, and every "What's new" so far to read again.
- What's new after every update. Once per version, with what changed and where to find it. A fresh install starts without it.
- Several devices, and signing them off. Every device signed up for Web Push is a target of its own; the same device twice stays one. The device in your hand is marked, and any device can sign any device off, also taking the sign-up back in the browser.
- Signing a device up is one step that saves and sends a test notification right away.
Fixed
- Help texts at the edge of the page or under an upper-case heading are no longer cut off or set in capitals.
- A refused sign-up shows the browser's own reason instead of a general message.
nexsift 0.2.0
New
- Notifications straight to your phone, no extra app (Web Push). Open nexsift over https, add it to the home screen, then under Rules, Forwarding to the phone, add a target "This device" and tap "Sign this device up". Each device signs itself up once and then works like any other target: minimum level, quiet hours, test button. A tap on a notification opens the line in the inbox.
- nexsift is installable as an app on Android, iPhone (iOS 16.4 or later, from the home screen) and desktop browsers.
- Encrypted for each device. Messages are encrypted for the device and signed by nexsift; the push service of Google, Apple or Mozilla only sees that something arrives. Because this way leads out of your network, it has its own switch, off until you allow it.
- A device that left is noticed. If a phone uninstalls the app or takes the permission back, the target switches itself off and says why.
nexsift 0.1.2
New
- The setup dialog warns when senders would go out to the internet. nexsift looks up the address it hands to the senders. If a name like
nexsift.example.comleads to a public address, as it often does even at home behind a reverse proxy, the dialog says so and asks for the server's address at home right there. The same happens when no address is set at all and the hints would carry only a name.
nexsift 0.1.1
New
- An address for senders at home. Under Settings, next to the public address, a second one: the host or IP the devices at home reach nexsift by. Every setup hint uses it. Behind a reverse proxy this is what makes syslog, email and the Gotify and ntfy doors work, since they do not go through the proxy. The setup dialog says when it is missing.
Fixed
- A data folder on a Synology. When the container cannot write to its data folder, the message now names the access list DSM puts on new folders and the command that removes it. The README has a section on Synology and one on running behind a reverse proxy.
nexsift 0.1.0
The first release: one inbox for everything the homelab has to say, and only what matters on the phone.
New
- Many ways in. A webhook, a Gotify API, an ntfy API, Discord webhook addresses, SMTP without sign-in and syslog over UDP and TCP. Senders keep the settings they know and only get nexsift's address.
- Known senders with a step by step setup: Proxmox VE, Synology DSM, Uptime Kuma, Watchtower, Home Assistant and Paperless-ngx, each checked against the real thing.
- Bundling that needs no knowledge of the sender. A source's routine shares one line; warnings and critical messages get one line per subject, and an open problem stays one line until it is resolved.
- All-clears close problems, from Uptime Kuma, Proxmox or your own rules.
- Push to the phone through ntfy, Gotify, Telegram, Apprise or a webhook, with a minimum level, quiet hours and a storm guard that turns a power cut into one message.
- Rules for level, bundling, push and dropping, with a place to try a message before it arrives. Words for failures and trouble come built in, in English and German.
- Unknown senders are listed and become a source with one click.
- One operator account, optionally with OpenID Connect and a one-button setup for authentik.
- German and English interface.
Install
services:
nexsift:
image: ghcr.io/derkezorm/nexsift:0.1.0
restart: unless-stopped
ports:
- "8490:8000"
- "8491:8001"
- "8492:8002"
- "25:2525"
- "514:5514/udp"
- "514:5514/tcp"
volumes:
- ./data:/dataThe full compose file with every option explained is in the repository.