Skip to content

Releases: heyvaldemar/game-server-wireguard-relay-docker-compose

v1.3.6

Choose a tag to compare

@heyvaldemar heyvaldemar released this 25 Sep 17:33

Security

  • itzg/minecraft-server:java25 was rebuilt upstream; the pin moved from sha256:c8ace6eaf0e9… to sha256:8d0500eb1df7…. Same version, same tag, a rebuilt base image — the usual shape of a security fix in a base layer.

Upgrading

git pull (or ./update.sh), then docker compose up -d. Containers on a refreshed image are recreated; data volumes and .env are untouched. This release was cut by fleet triage after the deploy job booted the stack on the refreshed images.

Full history in CHANGELOG.md.

v1.3.5

Choose a tag to compare

@heyvaldemar heyvaldemar released this 23 Sep 21:24

Changed

  • The freshness check has its own workflow, Pin Freshness. It ran inside Deployment Verification, whose badge is the one at the top of this README. Across the fleet, nine red runs in ten were a pin one version behind - which the fleet's triage moves within the day - and a reader cannot tell that from a stack that does not boot. The badge now says whether the stack boots. The job itself is unchanged.

Security

  • itzg/minecraft-server:java25 was rebuilt upstream; the pin moved from sha256:77280d10744f… to sha256:c8ace6eaf0e9…. Same version, same tag, a rebuilt base image — the usual shape of a security fix in a base layer.

Upgrading

git pull (or ./update.sh), then docker compose up -d. Containers on a refreshed image are recreated; data volumes and .env are untouched. This release was cut by fleet triage after the deploy job booted the stack on the refreshed images.

Full history in CHANGELOG.md.

v1.3.4

Choose a tag to compare

@heyvaldemar heyvaldemar released this 20 Sep 16:40

Security

  • itzg/minecraft-server:java25 was rebuilt upstream; the pin moved from sha256:dc7913a69c87… to sha256:77280d10744f…. Same version, same tag, a rebuilt base image — the usual shape of a security fix in a base layer.

Upgrading

git pull (or ./update.sh), then docker compose up -d. Containers on a refreshed image are recreated; data volumes and .env are untouched. This release was cut by fleet triage after the deploy job booted the stack on the refreshed images.

Full history in CHANGELOG.md.

v1.3.3

Choose a tag to compare

@heyvaldemar heyvaldemar released this 18 Sep 14:52

Security

  • itzg/minecraft-server:java25 was rebuilt upstream; the pin moved from sha256:46919d151d39… to sha256:dc7913a69c87…. Same version, same tag, a rebuilt base image — the usual shape of a security fix in a base layer.

Upgrading

git pull (or ./update.sh), then docker compose up -d. Containers on a refreshed image are recreated; data volumes and .env are untouched. This release was cut by fleet triage after the deploy job booted the stack on the refreshed images.

Full history in CHANGELOG.md.

v1.3.2

Choose a tag to compare

@heyvaldemar heyvaldemar released this 16 Sep 17:26

Security

  • itzg/minecraft-server:java25 was rebuilt upstream; the pin moved from sha256:769a826c3405… to sha256:46919d151d39…. Same version, same tag, a rebuilt base image — the usual shape of a security fix in a base layer.

Upgrading

git pull (or ./update.sh), then docker compose up -d. Containers on a refreshed image are recreated; data volumes and .env are untouched. This release was cut by fleet triage after the deploy job booted the stack on the refreshed images.

Full history in CHANGELOG.md.

v1.3.1

Choose a tag to compare

@heyvaldemar heyvaldemar released this 14 Sep 13:49

Security

  • itzg/minecraft-server:java25 was rebuilt upstream; the pin moved from sha256:c1a267d9ed6d… to sha256:769a826c3405…. Same version, same tag, a rebuilt base image — the usual shape of a security fix in a base layer.

Upgrading

git pull (or ./update.sh), then docker compose up -d. Containers on a refreshed image are recreated; data volumes and .env are untouched. This release was cut by fleet triage after the deploy job booted the stack on the refreshed images.

Full history in CHANGELOG.md.

v1.3.0

Choose a tag to compare

@heyvaldemar heyvaldemar released this 13 Sep 15:44

An update is not finished until the tunnel is carrying traffic.

docker compose up -d returning 0 says a request was accepted. It says nothing about whether packets are moving, and this sidecar is the game's only network: network_mode: service:relay-wg means the game has no interface of its own, so a sidecar that comes back with no working tunnel is a server nobody can reach.

It comes back looking fine. A key the relay no longer knows, a configuration the new image reads differently, a peer that never answers: the container runs, the process is alive, and every check short of reading the interface says yes. On one host, eight PostUp lines sitting in the wrong block of a wg0.conf produced exactly that. The zero exit code hid it, and it stayed hidden for thirteen days with the server unreachable from the internet the whole time.

What verify-tunnel.sh reads

In the order a packet needs it. The container is running, judged by its state and never by an exit code. wg0 carries an address, so the interface was configured rather than read and rejected. The peer handshaked inside HANDSHAKE_MAX, three minutes by default, which PersistentKeepalive at 25 seconds makes a generous window. And the game port answers on the relay's public address, because everything above can pass while the relay is simply not forwarding it, which is a firewall rule on somebody else's machine and the most common thing left undone.

A UDP game is reported as untested rather than passed. An open UDP port and a dropped one look the same from here, and a check that cannot fail is worse than no check at all.

./verify-tunnel.sh

update.sh waits for it after up -d, and when the tunnel does not come back it says so and prints the exact command that puts the previous release back. Somebody who has just lost their server should not have to go and look up what they were running an hour ago.

The isolation suite gains the scenario this is all for: with the relay taken away, the sidecar is still running and still looks healthy to anything watching the process, and verify-tunnel.sh refuses it.

Upgrading: ./update.sh, which now ends by proving the tunnel rather than by reporting an exit code.

v1.2.2

Choose a tag to compare

@heyvaldemar heyvaldemar released this 10 Sep 12:08

Security

  • itzg/minecraft-server:java25 was rebuilt upstream; the pin moved from sha256:d686c51f034d… to sha256:c1a267d9ed6d…. Same version, same tag, a rebuilt base image — the usual shape of a security fix in a base layer.

Upgrading

git pull (or ./update.sh), then docker compose up -d. Containers on a refreshed image are recreated; data volumes and .env are untouched. This release was cut by fleet triage after the deploy job booted the stack on the refreshed images.

Full history in CHANGELOG.md.

v1.2.1

Choose a tag to compare

@heyvaldemar heyvaldemar released this 08 Sep 16:10

Security

  • itzg/minecraft-server:java25 was rebuilt upstream; the pin moved from sha256:8672e335dbef… to sha256:d686c51f034d…. Same version, same tag, a rebuilt base image — the usual shape of a security fix in a base layer.

Upgrading

git pull (or ./update.sh), then docker compose up -d. Containers on a refreshed image are recreated; data volumes and .env are untouched. This release was cut by fleet triage after the deploy job booted the stack on the refreshed images.

Full history in CHANGELOG.md.

v1.2.0

Choose a tag to compare

@heyvaldemar heyvaldemar released this 07 Sep 20:39

Added

  • update.sh: move between release tags on purpose. It updates to the latest release (a combination this repository's CI has booted and smoke-tested), refuses to cross a major version unattended, refuses to run over local changes, and names any new required variable before anything has moved. --dry-run says what would happen.

Upgrading

git pull (or ./update.sh). Nothing running changes: this release adds or extends the update script and touches no image pin.

Full history in CHANGELOG.md.