Skip to content

Releases: marvinli001/edgeweir-node

v0.2.1

Choose a tag to compare

@github-actions github-actions released this 04 Oct 05:43

Changelog

  • c05e2b8 build(proto): regenerate from proto/v0.21.0
  • e1aee1f feat(lua): the origin layer of the site's protocol, gRPC end to end
  • 6fde8d1 feat: HTTP/2 and gRPC towards the origins, announce origin-http2-v1
  • b6b6514 fix(render): no keep-alive from the edge to the origin layer
  • 21a740c test(e2e): smoke checks for HTTP/2 and gRPC to origins

Verify

cosign verify-blob \
  --bundle checksums.txt.sigstore.json \
  --certificate-identity-regexp '^https://github\.com/marvinli001/edgeweir-node/\.github/workflows/release\.yml@refs/tags/v' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com \
  checksums.txt
sha256sum --ignore-missing -c checksums.txt
gh attestation verify <artifact> --repo marvinli001/edgeweir-node

v0.2.0

Choose a tag to compare

@github-actions github-actions released this 04 Oct 01:24

Changelog

  • 5e86ed4 feat(controlplane): connect through the console's WebSocket entry (wss://, ws://)

Verify

cosign verify-blob \
  --bundle checksums.txt.sigstore.json \
  --certificate-identity-regexp '^https://github\.com/marvinli001/edgeweir-node/\.github/workflows/release\.yml@refs/tags/v' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com \
  checksums.txt
sha256sum --ignore-missing -c checksums.txt
gh attestation verify <artifact> --repo marvinli001/edgeweir-node

v0.1.0

Choose a tag to compare

@github-actions github-actions released this 03 Oct 22:07

Changelog

  • f801c19 Merge branch 'fix/audit-p0'
  • 72a09ee Merge fix/audit-p1-node-om (audit P1-15: renew a due certificate while the console refuses heartbeats)
  • 42d49fb Merge master (rules-v2) into the audit fixes
  • f2c692c build(docker): node image on Debian with edgeweir-openresty
  • d142f1f build(openresty): fail when libmodsecurity needs a newer libstdc++ than EL9's
  • 9f09a0e build(openresty): one release number for both packages
  • 397ec43 build(openresty): reproducible edgeweir-openresty packages
  • fd19058 build(proto): consume proto/v0.2.0
  • 9cfd1ec build(proto): consume proto/v0.2.1
  • 9198cbd build(proto): consume proto/v0.2.2
  • a89bfea build(proto): regenerate from proto/v0.13.0
  • eb884d5 build(proto): regenerate from proto/v0.15.0
  • 82c26e8 build(proto): regenerate from proto/v0.15.1 (comments only)
  • 60ad3c5 build(proto): regenerate from proto/v0.16.0
  • 083d8aa build(proto): regenerate from proto/v0.17.0
  • a7f2c8d build(proto): regenerate from proto/v0.18.0
  • f54d54a build(proto): regenerate from proto/v0.19.0
  • 39a7fd5 build(release): release edgeweir-openresty next to edgeweir-node
  • c72e281 build(release): systemd unit and image directory for probe mode
  • a19f922 build: add goreleaser config
  • b903c6e build: add make adr-check for the ADR mirror
  • ed30e7e build: add node container image
  • b649683 build: add systemd unit and deb/rpm maintainer scripts
  • 0157a1f build: pin the Go toolchain patch release (go 1.27.1)
  • 94df55f build: pin third-party images by digest and actions by commit SHA
  • bd2a2b3 build: pin-check accepts the e2e node image variable
  • df49792 build: ship nftables for kernel bans
  • 59599f7 catchup
  • 383fd22 chore(proto): regenerate from proto/v0.10.0
  • 6da3403 chore(proto): regenerate from proto/v0.10.1
  • 7c7471c chore(proto): regenerate from proto/v0.11.0
  • 74c601a chore(proto): regenerate from proto/v0.12.0
  • b1ddc6c chore(proto): regenerate from proto/v0.8.0
  • c09e645 chore(proto): regenerate from proto/v0.9.0
  • 9a62e16 ci(release): build edgeweir-openresty and the image natively per architecture
  • 209a12d docs(adr): mirror the eighteen architecture decisions from edgeweir
  • fb6f81b docs(adr): sync ADRs 0002, 0003, 0005, 0007, 0008 and 0011 from edgeweir
  • 440473c docs(architecture): real apply order and the missing packages
  • 341908e docs(architecture): record the P1-57 to P1-62 fixes
  • 10a4d4b docs(claude): docs/adr is a generated mirror of the console's ADRs
  • 557e3c7 docs(roadmap): prefix/full prefetch is v1, node self-check is done
  • 1ec181b docs(security): no SSH install, purge.json loss, config/ modes, --allow-unsigned
  • cd73dd1 feat(agent): accept domains the certificate does not cover yet
  • 0469500 feat(agent): challenge keys, captcha pools and CC events
  • a34b01b feat(agent): follow the console's ban channel
  • 1887df3 feat(agent): host metrics in every heartbeat (metrics-v1)
  • 8fdf6c2 feat(agent): layer-4 tables and statistics (l4-v1)
  • bc46270 feat(agent): origin credentials, typed purge and prefetch tasks, origin health
  • 9a8f089 feat(agent): prefetch device variants and https URLs
  • 7750d10 feat(agent): probe the other nodes when the console asks
  • dd94051 feat(agent): purge by Host and Cache-Tag
  • 201e263 feat(agent): report brotli-v1, zstd-v1 and modsecurity-v1, CRS rule hits
  • a14037e feat(agent): report log rule matches and announce rule-log-v1
  • cf2212a feat(agent): report the statistics watermark after every acknowledged drain
  • 6ff3c92 feat(agent): run active health checks, push their marks and report them
  • f2d8ce6 feat(agent): run loop with watch, poll, apply, report and renewal
  • 7b7673a feat(agent): send ban deltas against what the data plane holds
  • bcd574d feat(agent): sitemap prefetch tasks
  • ef496c7 feat(bans): group bans with the same key into one data plane entry
  • a833cef feat(bans): keep the console's dynamic bans with their sequence
  • e65b8c8 feat(captcha): draw image captchas with the standard library
  • d89986d feat(cli): add enroll, run, healthcheck and version commands
  • e30d8fd feat(cli): report the OpenResty version with the enrollment
  • 58fcc61 feat(cli): take the enrollment token from EDGEWEIR_TOKEN or --token-file
  • 6370c53 feat(cmd): --modsecurity-module and --crs-dir
  • d07c2f4 feat(cmd): --purge-tags-per-site bounds a site's tag markers
  • 71f8624 feat(cmd): --sites-dict-mb sizes the site table store
  • 9137bfb feat(cmd): --tag-dict-mb sizes the Cache-Tag index
  • f3484c0 feat(cmd): default --nginx-bin to edgeweir-openresty when it is installed
  • 2ab65af feat(cmd): flags for the ban store and kernel bans
  • 4265710 feat(cmd): flags for the challenge and CC stores
  • 0c43444 feat(cmd): print the data plane's ban status
  • 86e2ed5 feat(cmd): print the data plane's challenge and CC state
  • 14fd0e1 feat(configir): announce purge-tag-v1 and prefetch-v2
  • 1f23dce feat(configir): announce rules-v2
  • 385a59c feat(configir): canonical order and diffs of the v0.12.0 fields
  • ba87de9 feat(configir): canonical ordering, content hash, diff apply and validation
  • 94cc131 feat(configir): canonical origin allow list and the v0.2.1 hash vector
  • 3880b64 feat(configir): layer-4 applications (l4-v1)
  • 2826d53 feat(configir): plan error pages, offline hosts, active health checks and session affinity
  • 5678b63 feat(configir): plan origin pool settings, S3 auth, cache keys and rule conditions
  • 89d402d feat(configir): validate Brotli, Zstandard and OWASP CRS settings
  • 34bb2df feat(configir): validate challenges, CC policies, challenge keys and JA4 rules
  • 53238a6 feat(configir): validate rules-v2 expressions, actions and site fields
  • c696a20 feat(configstore): persist last-known-good config with backup
  • c475ea1 feat(dataplane): G4 site table fields, tag markers, active health and request ids
  • e49057f feat(dataplane): add unix-socket client for the Lua control API
  • afb9500 feat(dataplane): client for the ban control endpoints
  • 7efaf34 feat(dataplane): client for the challenge and security endpoints
  • 3ddc218 feat(engine): detect Brotli and Zstandard, summarize CRS denials
  • 281f55a feat(engine): test, reload and supervise OpenResty
  • 93b42e8 feat(enroll): enroll nodes with a single-use token over a pinned channel
  • b3cac27 feat(enroll): enroll probes through ProbeService
  • 0747c92 feat(geoip): bundle IPinfo Lite at image build time
  • 36aca2c feat(geoip): merge IPinfo Lite bundling
  • 954d928 feat(healthcheck): active origin health checks
  • 5393fd2 feat(lua): a statistics drain can take the current minute
  • 450debf feat(lua): balancer-based origin layer, cache keys, purge markers and passive health
  • a138425 feat(lua): challenge, CC and JA4 at the edge layer
  • 8b24dc6 feat(lua): challenges and passes
  • afbf8e5...
Read more