Releases: kevindraai/exitlane
Release list
ExitLane v0.2.0-beta.5
Summary
ExitLane 0.2.0-beta.5 is a release-assurance and installation-hardening prerelease.
This release:
- contains the complete beta.4 UX, accessibility, design-system and integrated-documentation baseline;
- restores the release-governance chain that prevented beta.4 from being published;
- strengthens required checks and automatic CodeQL validation on
main; - adds clean-install evidence for the supported Debian 13
amd64appliance baseline; - therefore marks an important beta milestone.
The candidate was qualified through required hosted checks, an independent pre-merge APPROVE, a clean installation on Debian 13 amd64, and repeated local, hosted and appliance validation on the exact merged main commit.
Release governance and security
- The active
mainruleset requires the exact CI, CodeQL, supply-chain and ZAP job contexts and requires the branch to be current before merge. - CI, CodeQL, supply-chain and ZAP validation run on pull requests and automatically on every relevant push to
main. - Repository Actions policy requires full commit-SHA references, permits GitHub-owned actions and explicitly allowlists only the external Gitleaks action used by the current workflows.
- A deterministic workflow-security check prevents mutable Action references and accidental removal of any required final-main trigger.
- The release record distinguishes pre-merge PR evidence from new hosted final-main evidence and does not reuse older green runs for a newer commit.
Supported installation evidence
- The supported beta.5 appliance baseline is Debian 13 on
amd64. Debian 12 is not a supported beta.5 release target. - Clean-install evidence covers prerequisites, installer and package versions, first service start, health, first-run routing, database initialization, filesystem permissions, systemd units, WireGuard prerequisites, onboarding entry, stop/start resume, injected rollback and idempotent rerun.
- The installer explicitly supplies
procpsand thesysctl.dpath required to configure IPv4 forwarding on an otherwise minimal supported Debian installation. - The existing beta.4 appliance was upgraded transactionally with exact merged-main source and retained its database, key, user/session/settings state, VPN cache and WireGuard configurations. An idempotent rerun and injected-failure automatic rollback also passed.
- No real Speedtest was run during this release qualification.
Inherited beta.4 baseline
Beta.5 includes beta.4's Cobalt / Slate interface theme, UX and accessibility polish, authenticated integrated documentation, contextual help links, Diagnostics hierarchy improvements and related security regressions. These are inherited capabilities rather than new beta.5 feature claims.
Release evidence
- Pull request: #57
- Final PR head:
dd0d781f5b99ead8f83887947939c835655675b7 - Merged
main:6f00b346bfd39b6ae4ed2970728d3589f67b39ed - Qualified tree:
3a9176c3840c8eac60b052876782feae6e568600 - Annotated tag object:
3d137872b81410e48b838a809ee9a5910580f817 - Independent review:
APPROVEon the exact final PR head - Debian 13 clean-install evidence: LXC 123 evidence
- Final merged-main and appliance evidence: qualification record
- Final-main runs: CI 32860427841, CodeQL 32860427724, supply chain 32860427758, ZAP 32860427726
Limitations
ExitLane remains beta software for a trusted management network and must not be exposed directly to the public Internet. There is no signed automatic-update channel. A real Safari/WebKit runtime was not available for the inherited browser qualification; no compatibility defect is known and the existing responsive regression evidence remains the recorded residual limitation.
ExitLane 0.2.0
ExitLane 0.2.0
ExitLane 0.2.0 is the first stable release after the alpha, beta, and release-candidate cycle. It turns a Debian appliance into a self-hosted network-egress gateway with a focused browser-based management experience.
What is included
- NordVPN management on a provider-neutral abstraction foundation, with country and latency-based selection.
- WireGuard ingress, VPN killswitch protection, dashboard status, traffic visibility, health monitoring, and connection diagnostics.
- Managed Ookla Speedtest as an explicit confirmed action, with download, upload, and ping results.
- Authentication hardening with MFA, recovery codes, and session management.
- Encrypted backup and restore, transactional upgrades, protected recovery snapshots, and automatic rollback on failed upgrades.
- Integrated administrator documentation and N/L Foundry UX and design-system alignment.
Platform and assurance
The supported baseline is Debian 13 amd64, including Proxmox LXC deployments with the documented networking capabilities. Appliance and application timezone state now remain consistent through Settings, startup reconciliation, upgrades, and rollback.
This stable tree passed backend and frontend tests, package and dependency audits, CodeQL, supply-chain and secrets checks, ZAP passive scanning, clean-install and upgrade qualification, rollback injection, and live reference-appliance validation.
Direct Internet exposure remains unsupported. Deploy the management interface on a trusted network and use the documented HTTPS reverse-proxy configuration when remote browser access is required.
ExitLane 0.2.0-rc.1
ExitLane 0.2.0-rc.1
ExitLane 0.2.0-rc.1 is the final release candidate for the first stable 0.2.0 release. It keeps the
complete beta.5 product and assurance baseline while closing the appliance-timezone consistency
gap.
Timezone consistency
- Settings now controls Debian. A timezone selected in ExitLane is validated as an installed
IANA zone and applied through Debian's fixedtimedatectlinterface before it is persisted. - No half-applied state. A failed system operation leaves the stored value untouched. A storage
failure restores the previous system timezone, and every failure path is visible and audited. - Existing appliances converge safely. At startup, an explicit valid ExitLane timezone is
reconciled to the appliance. Invalid or unreadable state remains visible instead of silently
assuming UTC. - Upgrade and rollback preserve time configuration. The transaction snapshot records the
pre-upgrade appliance timezone and restores it alongside the application state when rollback is
required.
Diagnostics and interface corrections
- Successful Speedtests now show download, upload, and ping together, with download and upload as
the primary results. Speedtest remains an explicit, confirmed action and never runs automatically. - Compact cards keep normal hostnames and IPv4 endpoints readable without arbitrary single-character
wrapping. Longer technical values use accessible disclosure rather than destructivebreak-all
behavior.
Updated product presentation
The README and promotional images now show the current Cobalt / Slate interface on a working
ExitLane installation: live appliance health, an active NordVPN tunnel, an operational WireGuard
peer, real connection diagnostics, and integrated documentation. No core status was fabricated and
no Speedtest was run for the screenshots.
Supported platform and upgrade
The supported appliance baseline remains Debian 13 on amd64, primarily a Proxmox LXC with
/dev/net/tun and permission to create WireGuard interfaces. Upgrade with the trusted RC checkout:
sudo ./installer/install-debian.shCreate and verify an encrypted backup first. The installer creates a root-only pre-upgrade recovery
snapshot and automatically rolls back when the transaction cannot complete.
Direct Internet exposure remains unsupported. Keep the management interface on a trusted network
and use the documented HTTPS reverse-proxy configuration where remote browser access is required.
ExitLane v0.2.0-beta.3
ExitLane 0.2.0-beta.3 release notes
Summary
Beta.3 adds a managed path for the official Ookla Speedtest CLI and keeps installation and network
measurement as two distinct administrator actions. It is a prerelease for trusted management
networks; it is not an automatic-update channel and does not make ExitLane suitable for public
Internet exposure.
What changed
- On Debian 13
amd64, an authenticated administrator can explicitly install exactly one reviewed
official Ookla Debian artifact after confirming the package change, personal non-commercial
eligibility, license/EULA acceptance, and privacy/GDPR terms. - The installer uses the Packagecloud download endpoint, verifies the pinned SHA-256, shares the
ExitLane package-operation lock, and validates the installed executable's exact package ownership
and version. It does not run a repository script or retain a repository or signing key. - A successful installation never runs Speedtest. Each measurement requires a new deliberate
selection and all terms plus bandwidth confirmations, and only one measurement may run at once. - The Diagnostics UI presents accessible installation state, reload-safe polling, translated stable
errors, and external terms links with safe new-tab attributes.
Operator notes and limitations
Ookla's terms govern use of its CLI. ExitLane supports this managed path only for personal,
non-commercial use unless the operator has separate suitable permission. The proprietary package is
pinned and has no automatic updates; review a new artifact and digest before any future change.
After merge and all release gates pass, beta.3 appliance QA verifies the missing-tool UI and
installs the pinned package on the designated test appliance 172.16.130.81 exclusively through
the managed confirmation flow. It then verifies installation status and CLI availability, with
proof that no Speedtest measurement is invoked. No real Speedtest is permitted.
Integrated, versioned in-app documentation and error-to-document deep links remain a follow-up;
these reviewed Markdown release notes are the beta.3 release-notes source.
ExitLane v0.2.0-beta.2
ExitLane v0.2.0-beta.2
ExitLane v0.2.0-beta.2 is a beta stabilization release focused on NordVPN
latency visibility, provider authentication feedback, appliance management,
password recovery guidance, and international maintainer-facing output.
This release includes the implementation from PR #42 and the updated
evidence-driven release process from PR #43.
Highlights
- Automatically loads quick-choice country latencies.
- Measures and displays latency for the exact active NordVPN server.
- Deduplicates active-server measurements and avoids request storms.
- Preserves VPN connected state when optional latency telemetry fails.
- Provides localized feedback for invalid, expired, and revoked NordVPN tokens.
- Recognizes the current NordVPN Linux CLI wording for invalid access tokens.
- Prevents provider stdout, stderr, tokens, or raw CLI output from reaching
browser feedback or logs. - Adds local password-recovery guidance.
- Adds protected restart, reboot, and shutdown actions under Settings > System.
- Standardizes Debian installer output and maintainer comments in English.
Security
- Provider authentication accepts only allowlisted stable error codes and
redacts tokens and raw provider output. - Restart, reboot, and shutdown use authenticated, CSRF-protected POST routes
with a fixed action allowlist. - System actions execute fixed absolute
systemctlargument vectors without a
shell or user-controlled command string. - Accepted, started, and failed system actions are recorded in the audit log.
- No free-form privileged command execution or broad new sudo permission was
introduced.
Upgrade notes
- No database schema migration is required.
- Existing installations can use the documented Debian upgrade procedure.
- A current backup or Proxmox snapshot is recommended before upgrading beta
systems.
Verification
- Final release commit:
f01e6bf4d49183952613fe54085866b69f445424. - 339 backend tests passed.
- 26 frontend test files passed.
- Ruff lint and formatting, Python compilation, JavaScript syntax, JSON and
EN/NL i18n validation, Bash syntax, and ShellCheck passed. - Bandit reported no findings; pip-audit reported no known vulnerabilities.
- Network-namespace killswitch syntax, idempotence, DNS, IPv4, IPv6, and reboot
restoration checks passed. - Wheel and source distribution built successfully with package version
0.2.0b2; package-content inspection found no instance data or secrets. - Final-main CI, CodeQL, dependency review, Gitleaks, Python audit, package
build, and ZAP passive baseline checks passed. - Safe-instance verification covered automatic quick-choice latency, localized
provider feedback, password recovery, application restart, reboot, shutdown,
and recovery. - The exact active server changed from
fr825.nordvpn.comto
fr770.nordvpn.comafter reconnect; fresh snapshots reported the matching
server latencies while repeated reads reused the fresh cache.
Known beta limitations
- ExitLane has no signed automatic update channel; operators must verify that
upgrade source code comes from the trusted repository. - TLS termination remains external to ExitLane. Direct Internet exposure is not
supported. - Independent security review and penetration testing remain future work.
Feedback
Please report reproducible problems through GitHub Issues and include:
- the ExitLane version;
- the Debian version;
- whether the installation was clean or upgraded;
- clear reproduction steps;
- relevant redacted logs.
ExitLane v0.2.0-beta
ExitLane 0.2.0-beta.1
This is the first beta release of ExitLane.
Highlights
- Browser-based installation and first-run setup wizard.
- Provider-neutral VPN management with NordVPN as the first provider, including NordLynx connection, country selection, status, reconnect, and sign-out flows.
- Independent WireGuard ingress and authenticated client-configuration management.
- ExitLane-owned fail-closed VPN killswitch behavior with tunnel-loss recovery.
- Local administrator authentication, password recovery, TOTP MFA, one-time recovery codes, session management, trusted-proxy support, and security hardening.
- Root-only encrypted appliance backups, strictly validated restore, schema compatibility checks, protected alpha-to-beta upgrade snapshots, and automatic rollback after installer failure.
- English and Dutch localization, Activity history, operational health information, and responsive light/dark UI.
- Debian 12 and 13 installation support, with the primary appliance validation performed on a Debian 13 Proxmox LXC.
- Automated backend, frontend, installer, dependency, CodeQL, secret-scanning, and passive ZAP checks.
Beta notice
This is a prerelease. Validate ExitLane carefully in a non-production environment before relying on it for network egress. Create and verify an encrypted appliance backup before upgrading, and retain the protected local recovery snapshot until post-upgrade validation is complete. Report product bugs through GitHub Issues; report security vulnerabilities privately according to SECURITY.md.
Upgrade or installation notes
Install from a trusted checkout on Debian 12 or 13:
sudo ./installer/install-debian.shThe supported in-place upgrade path is from the accepted 0.2.0-alpha.1 baseline to 0.2.0-beta.1. Before upgrading, create and verify an encrypted backup with the root-only exitlane-cli backup commands. Do not run backup, restore, or multiple installers concurrently. A Proxmox LXC requires /dev/net/tun and permission to create WireGuard interfaces.
Known limitations
- No signed automatic update channel.
- Local recovery snapshots are host-bound, contain plaintext appliance state, and must remain root-only.
- TLS termination is external; direct public-Internet exposure is unsupported.
- Root or hypervisor compromise is outside the application security boundary.
- TOTP is not phishing-resistant.
- No independent penetration test, WebAuthn, high availability, public API, plugin system, or additional VPN provider is included in this beta.
Release commit: ebe29517eae6456e4a332241cd28bb79f65c9551
What's Changed
- feat(activity): add structured application event log by @kevindraai in #4
- refactor(frontend): split monolithic index.html into server-side partials by @kevindraai in #5
- security: add hardening and security assurance baseline by @kevindraai in #6
- build(deps): bump github/codeql-action/init from 3b0bd1d116c0bde30213346b22d4f634d96a2fb0 to 4187e74d05793876e9989daffde9c3e66b4acd07 by @dependabot[bot] in #7
- build(deps): bump github/codeql-action/analyze from 3b0bd1d116c0bde30213346b22d4f634d96a2fb0 to 4187e74d05793876e9989daffde9c3e66b4acd07 by @dependabot[bot] in #8
- build(deps): bump actions/dependency-review-action from 4.9.0 to 5.0.0 by @dependabot[bot] in #11
- build(deps): bump actions/setup-python from 5.6.0 to 7.0.0 by @dependabot[bot] in #10
- build(deps): bump actions/upload-artifact from 4.6.2 to 7.0.1 by @dependabot[bot] in #12
- build(deps): bump python from 3.13-slim to 3.14-slim in /docker by @dependabot[bot] in #9
- feat(vpn): add resilient country selection and provider recovery by @kevindraai in #18
- build(deps): bump actions/checkout from 4.4.0 to 7.0.1 by @dependabot[bot] in #14
- build(deps): bump gitleaks/gitleaks-action from dcedce43c6f43de0b836d1fe38946645c9c638dc to ff98106e4c7b2bc287b24eaf42907196329070c7 by @dependabot[bot] in #16
- build(deps): bump actions/setup-node from 4.4.0 to 7.0.0 by @dependabot[bot] in #15
- WireGuard-clientconfiguratie veilig beheren by @kevindraai in #19
- feat(settings): add self-service credential and provider management by @kevindraai in #20
- refactor(vpn): introduce provider abstraction by @kevindraai in #21
- feat(auth): add MFA and safe reverse proxy configuration by @kevindraai in #22
- refactor(settings): reorganize settings navigation by @kevindraai in #23
- feat(vpn): add provider-independent killswitch by @kevindraai in #24
- Reset navigation state after authentication by @kevindraai in #25
- Add managed reverse-proxy settings by @kevindraai in #26
- Fix reverse proxy environment defaults by @kevindraai in #27
- Add provider-managed NordVPN installation by @kevindraai in #28
- Fix NordVPN installation reconciliation by @kevindraai in #29
- Improve NordVPN installation checklist by @kevindraai in #30
- Fix NordVPN installation flow and gateway settings by @kevindraai in #31
- Polish provider readiness, navigation, and killswitch UX by @kevindraai in #32
- Add NordVPN provider logo and stabilize Safari sidebar rendering by @kevindraai in #33
- Prepare ExitLane v0.2.0-beta.1 by @kevindraai in #34
- chore(release): prepare v0.2.0-beta.1 by @kevindraai in #35
New Contributors
- @dependabot[bot] made their first contribution in #7
Full Changelog: v0.2.0-alpha.2...v0.2.0-beta.1
Exitlane v0.2.0-alpha.2
Documentation and release consistency
This maintenance alpha aligns the repository documentation and metadata with the current Exitlane architecture.
Changed
- Expanded architecture documentation
- Documented application state and startup lifecycle
- Updated lifecycle-aware polling documentation
- Updated README, roadmap, changelog and security guidance
- Aligned Debian 12 and 13 support information
- Removed the obsolete test-LXC deployment script
No runtime application behavior was intentionally changed.
Exitlane v0.2.0-alpha.1
🚀 Highlights
This release marks the completion of Exitlane's core application architecture.
✨ New
- Session-based authentication
- Dashboard 2.0
- Settings page
- Improved first-run wizard
- Theme & language support
- Central application state
🏗 Architecture
- Startup lifecycle redesigned
- Lazy loading based on application mode
- Centralized polling
- Shared frontend state store
- Improved lifecycle management
🔒 Security
- HttpOnly server-side sessions
- CSRF protection
- Central authentication handling
🧪 Quality
- Backend test suite expanded
- Frontend unit tests
- i18n validation
- CI improvements
- Automated deployment to a dedicated test environment
This is an alpha release intended for testing and evaluation.