Skip to content

v0.8.9

Choose a tag to compare

@auggiesoft auggiesoft released this 28 Feb 01:13
· 310 commits to master since this release

What's New

S3-Compatible Audio Storage

Optional S3 storage backend for call audio files. Works with AWS S3, MinIO, Backblaze B2, Cloudflare R2, and any S3-compatible provider.

  • Tiered architecture — local disk cache + S3 primary storage. Files served from local cache when available, S3 presigned URL redirect as fallback.
  • Async upload — local write returns immediately, background workers upload to S3. A periodic reconciler catches any missed uploads.
  • Cache pruner — automatically evicts local files older than S3_CACHE_RETENTION (default 30 days) after verifying they exist in S3.
  • Transcription integration — transcription workers resolve audio from local cache first, then S3.
  • Zero-config local mode — S3 is entirely optional. Without S3_BUCKET set, everything works as before with local-only storage.

Configure with S3_BUCKET, S3_ENDPOINT, S3_ACCESS_KEY, S3_SECRET_KEY. See sample.env for all options.

Security & Hardening

  • Path traversal protection on local audio storage — keys containing ../ are rejected (d3f273d)
  • S3_UPLOAD_MODE validation — startup rejects invalid values (must be async or sync) (d3f273d)
  • Shutdown safety — sync.Once on all channel close operations, atomic.Bool guard on async uploader enqueue to prevent sends to closed channels (d7658b0)
  • Credential hygiene — S3 keys read from env only, never logged (d7658b0)

Documentation

  • Added full S3 configuration section to sample.env with all 12 settings documented
  • Documented that S3 endpoint must be client-reachable for presigned URL redirects

Fixes (since v0.8.8.1)

  • Fixed presignExpiry field type (was config.S3Config, corrected to time.Duration) (d7658b0)
  • Added timeouts to pruner S3 existence checks (d7658b0)
  • Fixed reconciler timezone handling with time.ParseInLocation (d7658b0)