Repository navigation
v1.16.3
Fixed
- Crawl4AI (security) - The
crawl4aiservice loaded the whole.envviaenv_file, so the crawler container received every variable of the stack, including all secrets (Postgres, JWT/Supabase, n8n, Open Terminal, Qdrant/Weaviate, OpenClaw, Cloudflare Tunnel, the GOST upstream proxy and more). It now gets onlyCRAWL4AI_API_TOKEN,OPENAI_API_KEYand the proxy variables; the nextmake updateormake restartrecreates it without the rest. If you added other Crawl4AI settings to.env(another LLM provider key,LLM_PROVIDER,CRAWL4AI_*), move them tocrawl4ai.environmentindocker-compose.override.yml. If you have been running thecrawl4aiprofile, treat those values as exposed: rotate external credentials (Cloudflare Tunnel token, OpenRouter and other API keys, bot tokens, SMTP) at the provider; to rotateOPEN_TERMINAL_API_KEY, empty it in.env, runmake update(it generates a new key) and re-enter it in Open WebUI under Admin Settings → Integrations → Open Terminal.POSTGRES_PASSWORD,JWT_SECRETandN8N_ENCRYPTION_KEYcannot be rotated by just editing.env: Postgres keeps its password in the data volume,ANON_KEY/SERVICE_ROLE_KEYare signed withJWT_SECRET, and a newN8N_ENCRYPTION_KEYmakes stored n8n credentials unreadable (issue #137).
Upgrade
Run make update (or make restart): crawl4ai is recreated without the rest of .env. Check that no secret is left in the container (expect no output):
docker inspect crawl4ai -f '{{range .Config.Env}}{{println .}}{{end}}' \
| grep -E 'POSTGRES_PASSWORD|JWT_SECRET|N8N_ENCRYPTION_KEY|QDRANT_API_KEY|OPEN_TERMINAL_API_KEY'If you put other Crawl4AI settings into .env (an LLM provider key other than OPENAI_API_KEY, LLM_PROVIDER, CRAWL4AI_*), they no longer reach the container. Add them under services.crawl4ai.environment in docker-compose.override.yml.
If you have been running the crawl4ai profile, treat the values in .env as exposed to that container. make update does not rotate anything:
- External credentials (Cloudflare Tunnel token, OpenRouter and other API keys, bot tokens, SMTP): rotate at the provider and update
.env. OPEN_TERMINAL_API_KEY: empty it in.env, runmake update(a new key is generated and shown on the Welcome Page), then re-enter it in Open WebUI under Admin Settings → Integrations → Open Terminal.POSTGRES_PASSWORD,JWT_SECRET,N8N_ENCRYPTION_KEY: do not just edit them in.env. Postgres keeps its password in the data volume,ANON_KEY/SERVICE_ROLE_KEYare signed withJWT_SECRET, and a newN8N_ENCRYPTION_KEYmakes stored n8n credentials unreadable.
Full Changelog: v1.16.2...v1.16.3