Skip to content

v1.9.5 — per-service TLS options for call_service

Choose a tag to compare

@IkarusMK IkarusMK released this 07 Jul 13:11
· 13 commits to main since this release

Added

  • Per-service TLS options — service_add now accepts tls_insecure and ca_bundle, and call_service honours them via the existing netguard.tls_verify() resolver (secure by default, #10 pattern — same as scan_add/webdav_add). This makes self-signed LAN services (e.g. a Crafty panel, which failed with SSL: CERTIFICATE_VERIFY_FAILED) reachable without weakening the default: verification stays ON unless an admin explicitly opts out, ca_bundle (pinned cert) takes precedence over tls_insecure, and service_list visibly flags such services with [TLS-INSECURE]. Merge-safe: updating other fields never resets a configured TLS opt-out. New tests: tests/test_service_tls.py.

Changed

  • netguard.tls_verify docstring now lists service_add among the admin-only writers of TLS opt-out configs.

Deploy: docker compose pull aicortex && docker compose up -d aicortex — then ping = v1.9.5. A self-signed service is then reachable via service_add(name, base_url, tls_insecure=true) (admin-only).