Skip to content

Releases: max3584/TCP-UDP-rproxy-ui

v0.4.2

Choose a tag to compare

@max3584 max3584 released this 08 Oct 15:13
6670826

追加

  • Kubernetes で動かせるようになりました(#136)。手順は docs/KUBERNETES.md。
    • コンテナイメージ ghcr.io/max3584/rproxy-ui:0.4.2(amd64・arm64、root でない利用者、ルートのファイルシステムは読むだけでよい)。
    • Helm chart oci://ghcr.io/max3584/charts/rproxy-ui:UI(既定 2 つ)・Service・PDB、任意で Ingress・HTTPRoute・NetworkPolicy。秘密は existingSecret で渡します。
    • DB は既定で外の MariaDB を使います。任意で公式の mariadb イメージを PVC つきで同梱でき(HA にはしません)、mysqldump のバックアップの CronJob も付けられます。
    • migration は Helm のフックの Job で当てます(db/migrate.mjs。2 回目や同時に流しても何もしません)。.deb でも手で使えます。
  • Kubernetes の rproxy を見られるようになりました:rproxy-gateway v0.4.3 が UI の namespace に書く一覧(Secret rproxy-ui-discovery)を読み、Gateway ごとの rproxy の Pod をノード・グループとして表示します。
    • 見るだけです。 変更・停止・送り直しなどは 409 readonly_node で断ります。管理者にだけ表示します。
    • 利用量は Pod ごとに集め、Gateway ごとにまとめます(終わる Pod の最後の 1 間隔は取りません)。
  • プローブ用の GET /api/healthz(サインイン不要、DB や rproxy には聞きません)。

変更

  • db/migrate.mjs は schema_migrations で当てた migration を覚えます。今の DB に初めて使うときは --baseline が要ります(db/README)。
  • .deb で入れた環境の動きは変わりません。

rproxy-api v0.3.5 以上で動きます。Kubernetes の rproxy を見るには rproxy-gateway v0.4.3 が要ります。


Added

  • Runs on Kubernetes (#136); see docs/en/KUBERNETES.md.
    • Container image ghcr.io/max3584/rproxy-ui:0.4.2 (amd64, arm64, non-root, works with a read-only root filesystem).
    • Helm chart oci://ghcr.io/max3584/charts/rproxy-ui: the UI (2 replicas by default), Service and PDB, with optional Ingress, HTTPRoute and NetworkPolicy. Secrets come through existingSecret.
    • An external MariaDB by default; optionally a bundled official mariadb image with a PVC (no HA), and a mysqldump backup CronJob.
    • Migrations run as a Helm hook Job (db/migrate.mjs; reruns and concurrent runs do nothing). Usable by hand with the .deb too.
  • Kubernetes rproxy in the UI: the UI reads the list rproxy-gateway v0.4.3 writes into its namespace (Secret rproxy-ui-discovery) and shows each Gateway's rproxy pods as nodes and a group.
    • Read-only. Changes, pause and resend get 409 readonly_node. Shown to admins only.
    • Usage is collected per pod and summed per Gateway (the last interval of a terminating pod is not captured).
  • GET /api/healthz for probes (no sign-in; does not ask the DB or rproxy).

Changed

  • db/migrate.mjs records applied migrations in schema_migrations; on an existing database, the first run needs --baseline (db/README).
  • .deb installs behave as before.

Works with rproxy-api v0.3.5 or later. Seeing Kubernetes rproxy needs rproxy-gateway v0.4.3.

v0.4.1

Choose a tag to compare

@max3584 max3584 released this 08 Oct 11:26
93ea4d0

追加

  • rproxy-api v0.4.1 のルールの組の保存のための表 rproxy_rule_sets を足しました(db/migrations/012_rproxy_rule_sets.sql、db/schema.sql)。ノードごとのビュー(db/node-view.mjs)にも含めます。

変更

  • 012 を当てる前にノードのビューを作り直すときは、node-view.mjs に --without-rproxy-rule-sets を付けてください(db/README)。
  • 保存した組を画面に出すのは、まだです(表だけ)。

rproxy-api v0.3.5 以上で動きます。ルールの組の保存を使うには rproxy-api v0.4.1 が要ります。


Added

  • The rproxy_rule_sets table for rproxy-api v0.4.1's persisted rule sets (db/migrations/012_rproxy_rule_sets.sql, db/schema.sql), included in the per-node views (db/node-view.mjs).

Changed

  • To rebuild the per-node views before applying 012, pass --without-rproxy-rule-sets to node-view.mjs (db/README).
  • Persisted rule sets are not shown in the UI yet (table only).

Works with rproxy-api v0.3.5 or later. Persisted rule sets need rproxy-api v0.4.1.

v0.4.0

Choose a tag to compare

@max3584 max3584 released this 07 Oct 17:17
ce742f3

rproxy-api v0.3.5 以上で動きます。v0.4 の項目を使うには rproxy-api v0.4.0 が要ります(使えない項目は画面で知らせます)。

追加

  • rproxy-api v0.4 のルールの項目をフォームと詳細画面で扱えます(#127・#131):送信元ごとの制限(limits)、帯域の上限(bandwidth)、GeoIP、受け身のヘルスチェック、ラベル、状態(conditions)、Gateway API 向けの L7・TLS の項目(headers の add、CORS、ミラー、HTTP/2 の転送先、サービスごとの TLS など)。
  • 変更前の差分(#127):保存の前に、rproxy で何が変わるか(作る・変える・作り直す・消す)を確かめられます。
  • 制御 API の mTLS(#127):RPROXY_API_TLS_* でクライアント証明書を使って rproxy-api に接続できます。
  • rproxy の API で作ったルールを見て変える(#128):rproxy の rproxy_rules(origin: "api")とルールの組のルールを一覧に出し、管理者は rproxy の API を通して変えられます。
  • 利用量の集計(#129・#130):ルールごとの通信量を時間・日・月で集計し、所有者・ラベルごとのグラフと CSV で見られます。

修正

  • rproxy の API やルールの組で作ったルールと同じキーの UI のルールを変えると、そのルールを上書きしていたのを直しました(409 shadowed。削除・停止は UI の DB の行だけを変えます)。
  • 利用者に、設定ファイルのパス・内部のエラーの文・バイナリのハッシュ・トークンの名前を見せないようにしました。
  • ほかのサイトからの書き込みの要求を断るようにしました(CSRF)。
  • 所有者やラベルが変わったとき、前の利用量の記録を書き換えていたのを直しました。
  • RPROXY_API_URL が http:// のときに、mTLS の設定とトークンを平文で送っていたのを、起動時に止めるようにしました。
  • CSV の書き出しで、表計算ソフトの数式として読まれる値をすべて無害化するようにしました。

変更

  • 利用量の集計を使っている環境では、UI を上げる前に db/migrations/011_usage_attr.sql を当ててください。 006〜010(v0.4 の項目、rproxy_rules、利用量の表)もまだなら一緒に当ててください。
  • rproxy-ui ユーザーを rproxy グループに入れ、ユニットに SupplementaryGroups=rproxy を足しました。同じ機械の rproxy-api のトークンは、写さずに RPROXY_API_TOKEN_FILE=/etc/rproxy/tokens をグループの権限で読みます(前の版の設定もそのまま動きます)。
  • UI を別のリバースプロキシの後ろに置いているときは、前のプロキシが Host か X-Forwarded-Host を渡すか、NEXTAUTH_URL を利用者が開く URL にしてください(CSRF の確認のため)。
  • rproxy-api v0.4.0 は、持ち主が rproxy-api でない証明書・鍵のファイルを断ります。画面には直し方(chown rproxy-api:rproxy、0640)を出します。

rproxy-api: v0.4.0


Works with rproxy-api v0.3.5 or later. The v0.4 items need rproxy-api v0.4.0 (the UI says when an item is not available).

Added

  • Forms and detail pages for the rproxy-api v0.4 rule items (#127, #131): per-source limits, bandwidth caps, GeoIP, passive health checks, labels, conditions, and the L7/TLS items for the Gateway API (headers add, CORS, mirror, HTTP/2 upstreams, per-service TLS and more).
  • Dry runs (#127): see what rproxy would create, change, recreate or remove before saving.
  • mTLS to the control API (#127): RPROXY_API_TLS_* connects to rproxy-api with a client certificate.
  • Rules made through rproxy's API (#128): rules from rproxy_rules (origin: "api") and from rule sets are listed, and admins can change them through rproxy's API.
  • Usage accounting (#129, #130): traffic per rule by hour, day and month, with charts and CSV by owner and label.

Fixed

  • Changing a UI rule with the same key as a rule made through rproxy's API or a rule set overwrote that rule; it is now refused (409 shadowed; delete and pause change only the UI's own row).
  • Users no longer see settings file paths, internal error texts, binary hashes or token names.
  • Write requests from other sites are refused (CSRF).
  • A change of owner or labels rewrote earlier usage records.
  • With an http:// RPROXY_API_URL, the mTLS settings and the token were sent in the clear; this is now refused at startup.
  • CSV exports neutralise every value a spreadsheet would read as a formula.

Changed

  • If you use usage accounting, apply db/migrations/011_usage_attr.sql before upgrading the UI. Apply 006 to 010 (v0.4 items, rproxy_rules, usage tables) too if you have not yet.
  • The rproxy-ui user joins the rproxy group, and the unit gets SupplementaryGroups=rproxy. The token of rproxy-api on the same machine is read in place through the group (RPROXY_API_TOKEN_FILE=/etc/rproxy/tokens) instead of being copied; older env files keep working.
  • Behind another reverse proxy, have it pass Host or X-Forwarded-Host, or set NEXTAUTH_URL to the URL users open (for the CSRF check).
  • rproxy-api v0.4.0 refuses certificate and key files not owned by rproxy-api; the UI shows how to fix them (chown rproxy-api:rproxy, 0640).

rproxy-api: v0.4.0

v0.3.21

Choose a tag to compare

@max3584 max3584 released this 06 Oct 18:23
608dab7

必要な rproxy-api: v0.3.5 以上。ACME には v0.3.21 以上。

追加

  • ACME の証明書を画面で扱えるようになりました。
    • ルールの TLS のタブで「ACME の証明書を追加」:resolver(rproxy の GET /acme から。challenge と許可された名前も表示)と名前を選ぶ。保存の前に rproxy と同じ決まり(許可リスト・ワイルドカードは DNS-01)で確かめ、rproxy が断った理由も画面に出す。
    • ルールの詳細:証明書ごとの状態(取得待ち・有効・更新中・失敗)、期限、更新の予定、CA の更新の窓(ARI)、次の試行、最後の誤り。仮の証明書を使っている間はそう出す。
    • ダッシュボード:発行・更新の失敗と、期限が近いのに更新できていないものを「要確認」に。一覧に「ACME 失敗」「ACME 取得待ち」。
    • 秘密・アカウント・失効の操作は画面に出しません(rproxy の固定の設定と Unix ソケットで扱う)。
    • エクスポート / インポートで ACME の証明書もそのまま往復します。
  • UI の rproxy のトークンには、ACME の証明書を使うルールを作る・変えるときに acme:write が要ります。

Requires rproxy-api v0.3.5 or later; ACME needs v0.3.21 or later.

Added

  • ACME certificates in the UI.
    • TLS tab, "Add ACME certificate": pick a resolver (from rproxy's GET /acme, with its challenge and allowed names) and the names. Checked before saving with rproxy's rules (allowlists, wildcards only with DNS-01); rproxy's refusals are explained on screen.
    • Rule detail: per-certificate state (pending, valid, renewing, failed), expiry, planned renewal, the CA's ARI window, next attempt and last error. The stand-in certificate is marked as such.
    • Dashboard: issuance or renewal failures, and certificates near expiry that keep failing to renew, under "needs attention"; "ACME failed" / "ACME pending" badges in the list.
    • No screens for secrets, accounts or revocation (rproxy's fixed config and Unix socket handle those).
    • Export / import round-trips ACME certificates.
  • The UI's rproxy token needs acme:write to create or change rules that use ACME certificates.

v0.3.20

Choose a tag to compare

@max3584 max3584 released this 06 Oct 15:35
e23b586

必要な rproxy-api: v0.3.5 以上(UDP の sni は v0.3.8 以上、バージョンの表示には v0.3.18 以上)。

追加

  • TLS 終端(tcp)のルールで、TLS のオプション(最小の版・暗号スイート)を画面で設定できるようにしました(rproxy が tls_options に対応しているとき)。最小を 1.3 にして TLS 1.3 の暗号スイートがないときは保存できません。
  • basic_auth に realm・user_header・keep_authorization の欄を足しました。

修正

  • rproxy v0.3.8 より前では使えない UDP の sni を選べてしまっていたのを直しました。版の分かる rproxy では古いときに選択肢を出さず、版の分からない rproxy(v0.3.17 以前)では注意を出し、古い rproxy が断ったときは理由の分かるメッセージにします。
  • 英語の画面で、括弧書きの前に空白が入らなかったのを直しました("Backends(…)" → "Backends (…)")。
  • 英語の README などの画面の用語を、実際の画面の言葉に揃えました。

Requires rproxy-api v0.3.5 or later (UDP sni needs v0.3.8, the version display v0.3.18).

Added

  • TLS options (minimum version, cipher suites) can be set on tcp TLS-termination rules (when rproxy supports tls_options). A minimum of 1.3 without a TLS 1.3 suite can't be saved.
  • basic_auth gets realm, user_header and keep_authorization fields.

Fixed

  • UDP sni could be chosen against rproxy older than v0.3.8, which rejects it. With an rproxy that reports its version the option is hidden when too old; with one that doesn't (v0.3.17 and earlier) a note is shown, and an old rproxy's refusal becomes a clear message.
  • Missing space before parentheses in the English UI ("Backends(…)" → "Backends (…)").
  • UI terms in the English README and docs now match the screens.

v0.3.19

Choose a tag to compare

@max3584 max3584 released this 05 Oct 15:00
3046dc6

必要な rproxy-api: v0.3.5 以上(バージョンの表示には v0.3.18 以上)。

変更(更新の前に確認してください)

  • Node.js 22.19.0 以上が必須になりました。 Unix ソケットの接続に使う undici を 8 に上げたためです。.deb の依存も nodejs (>= 22.19.0) になりました。
    • Debian 13(標準の nodejs は 20)や Ubuntu 24.04(18)では、先に NodeSource の nodejs をバージョンを指定して入れてください。手順は README の「インストール」にあります(NODE_MAJOR=24 と apt の pin で、OS の nodejs が選ばれないようにします)。
  • 画面の CSS を Tailwind CSS 4 に移しました。見た目は変えていません。
  • 型チェックを TypeScript 7 に、lint を ESLint 10 に上げました。
  • .deb の Suggests: rproxy-api から版の指定を外しました(UI と rproxy-api の番号は別々に進みます)。

Requires rproxy-api v0.3.5 or later (v0.3.18 or later for the version display).

Changed (check before upgrading)

  • Node.js 22.19.0 or later is now required, because undici (used for the Unix-socket connection) was upgraded to 8. The .deb now depends on nodejs (>= 22.19.0).
    • On Debian 13 (default nodejs 20) or Ubuntu 24.04 (18), install NodeSource's nodejs with a pinned version first. The steps are in the README's install section (NODE_MAJOR=24 plus an apt pin so the distro nodejs is never chosen).
  • The UI's CSS moved to Tailwind CSS 4. The look is unchanged.
  • Type checking now uses TypeScript 7 and linting ESLint 10.
  • The .deb's Suggests: rproxy-api no longer names a version (the UI and rproxy-api versions move independently).

v0.3.18

Choose a tag to compare

@max3584 max3584 released this 05 Oct 13:27
9212e7d

必要な rproxy-api: v0.3.5 以上(バージョンの表示には v0.3.18 以上)。

追加

  • 複数の rproxy の管理(act/stb を含む)(#98・#59・#109)
    • ダッシュボードとルールの詳細に「全体 / ノードごと」のタブ。act と stb の通信量・接続数などを並べて比べられます(ノードが 1 台なら今までどおりの画面)。
    • グループに vip: を書くと、VIP を持っているノードを act と表示します(どれも持っていない・複数が持っているときは注意)。
    • UI の定義と各ノードで動いている設定のずれを表示し、「このノードに送り直す」で直せます(履歴は RESEND)。
    • グループのルールのノードごとの上書き(待ち受けアドレス・転送先・allow_from・このノードだけ一時停止)。
    • ルールの別のノード・グループへのコピー・移動、ノードごとのまとめての停止・再開、ノード・グループ単位のエクスポート。
    • RPROXY_UI_USER_NODES で rproxy-user が触れるノードを絞れます。ノードの一覧に「最後の反映」。
    • act/stb のグループのずれを自動で送り直します(RPROXY_UI_HA_SYNC_SECS、グループごとに auto_resend)。
    • keepalived 向けの確認の口(GET /api/forward/ha/ready・POST /api/forward/ha/notify、RPROXY_UI_HA_TOKEN_FILE)とスクリプト・設定例(/usr/share/doc/rproxy-ui/examples/keepalived/)。ずれている stb の優先度を下げ、昇格した直後に揃えます。
    • failback の確認画面(/ha、管理者だけ)。
    • 複数ノードで使うときは DB の移行 007_log_node.sql・008_overrides.sql を当て、ノードごとのビューを作り直してください(1 台なら不要)。
  • バージョンの表示(#106):サイドバーの下とノードの一覧に UI と各ノードの rproxy-api のバージョン。必要な版より古い・分からないときはダッシュボードに注意(v0.3.17 以前の rproxy-api は「不明」と出ます)。

変更

  • 管理 UI と rproxy-api のバージョン番号は、それぞれ別に進めるようにしました。

Requires rproxy-api v0.3.5 or later (v0.3.18 or later for the version display).

Added

  • Managing several rproxy instances, including act/stb (#98, #59, #109)
    • "All / per-node" tabs on the dashboard and rule detail, comparing act and stb traffic, connections and more side by side (one node: the same screens as before).
    • With vip: on a group, the node holding the VIP is shown as act (with a warning when none or several hold it).
    • Drift between the UI's definition and what each node runs is shown and can be fixed with "resend to this node" (history: RESEND).
    • Per-node overrides for group rules (listen address, targets, allow_from, paused on this node only).
    • Copy or move rules to another node or group, pause/resume everything on a node, export per node or group.
    • RPROXY_UI_USER_NODES limits which nodes rproxy-user may change. "Last applied" in the node list.
    • Drift in act/stb groups is resent automatically (RPROXY_UI_HA_SYNC_SECS, per-group auto_resend).
    • Endpoints for keepalived (GET /api/forward/ha/ready, POST /api/forward/ha/notify, RPROXY_UI_HA_TOKEN_FILE) with scripts and an example config (/usr/share/doc/rproxy-ui/examples/keepalived/): an out-of-sync stb gets a lower priority and is synced right after a promotion.
    • A failback check page (/ha, admins only).
    • For multiple nodes, apply DB migrations 007_log_node.sql and 008_overrides.sql and recreate the per-node views (not needed for one node).
  • Version display (#106): the UI and each node's rproxy-api version at the bottom of the sidebar and in the node list, with a dashboard notice when a node is older than required or unknown (rproxy-api v0.3.17 and earlier show "unknown").

Changed

  • The management UI and rproxy-api now have independent version numbers.

v0.3.17

Choose a tag to compare

@max3584 max3584 released this 05 Oct 11:26
32b4618

追加

  • 複数の rproxy をまとめて管理できるようになりました(#98 の最初の段階)。
    • RPROXY_UI_NODES に指定した YAML / JSON に、ノード(名前・API の URL・トークンファイル)とグループ(single / active_standby)を書きます。
    • ルールはノードかグループに置けます。グループのルールは全員に同じ変更を送り、1 台でも失敗したら成功した台を元に戻します。
    • rproxy-api を変えずに、各 rproxy は自分のノードのルールだけを起動時に読みます(ノードごとの DB のビュー。npm run db:node-view で SQL を出せます)。
    • ノードが 2 台以上のとき、フォームのノードの選択、一覧・詳細・履歴のノードの表示、ノードごとの状態、ダッシュボードのノードの一覧が出ます。
    • 設定しなければ、今までどおり 1 台(RPROXY_API_URL)で動きます。使うときは DB の移行 db/migrations/006_nodes.sql を先に当ててください。
  • バックアップと復旧の手順への案内を README と db/README に足しました。

対になる rproxy-api: v0.3.17


Added

  • Manage several rproxy instances from one UI (first phase of #98).
    • List nodes (name, API URL, token file) and groups (single / active_standby) in the YAML / JSON file named by RPROXY_UI_NODES.
    • A rule belongs to a node or a group. Changes to a group rule go to every member; if one node fails, the nodes that succeeded are rolled back.
    • Without changing rproxy-api, each rproxy restores only its own rules at startup (a per-node DB view; npm run db:node-view prints the SQL).
    • With two or more nodes, the form gets a node selector, and the list, detail and history pages show the node, per-node state and a nodes overview on the dashboard.
    • Without the setting, the UI keeps working with one node (RPROXY_API_URL) as before. Apply the DB migration db/migrations/006_nodes.sql before using it.
  • Pointers to the backup and restore guide in the README and db/README.

Paired with rproxy-api v0.3.17.

v0.3.16

Choose a tag to compare

@max3584 max3584 released this 03 Oct 20:11
57f0ad7

修正

  • 英語の画面に日本語が残っていたところを直しました(#94)。
    • ダッシュボードの件数の「(うち固定 N)」、証明書の期限の文、ヘルスチェックの表示、状態の内訳、source_ip の説明、「(ループバック)」「(重み N)」、停止・再開に失敗したときのメッセージ、L7 の設定の誤りが複数あるときのメッセージ。
    • 変更の履歴の文(例「状態: 有効 → 停止中」)は、画面の言語で出るようになりました(英語では "State: Enabled → Paused")。
    • 英語の文と文の間に空白がなかったところ、語句の区切りが「・」「、」のままだったところ。
    • 訳の取り違え:「再開」のボタンは "Resume"、宛先の状態は "Up" / "Down" になりました。

追加

  • README に画面のスクリーンショット(日本語・英語、スマホの幅を含む)を載せました。

この版は UI だけのリリースです。rproxy-api は v0.3.15 と組み合わせて使います。


Fixed

  • Japanese text left in the English UI (#94).
    • The "(N static)" count on the dashboard, certificate expiry messages, health check details, the state breakdown, the source_ip explanations, "(loopback)" and "(weight N)", the messages when pausing or resuming fails, and the message for several L7 setting errors.
    • History change lines (e.g. "State: Enabled → Paused") now follow the UI language.
    • Missing spaces between English sentences, and lists still joined with Japanese separators.
    • Wrong translations: the resume button is now "Resume", and target states are "Up" / "Down".

Added

  • Screenshots in the README (Japanese and English, including the phone width).

This is a UI-only release. Use it with rproxy-api v0.3.15.

v0.3.15

Choose a tag to compare

@max3584 max3584 released this 03 Oct 18:04
38b56d2

追加

  • スマホ・タブレットの幅でも管理画面を使えるようにしました(#88)。
    • 1024px 未満では、ヘッダーの「メニュー」ボタンでページへのリンクを開閉します。言語の切り替えとサインアウトもメニューの中にあります。メニューは Esc か画面の移動で閉じます。
    • ダッシュボードのカードは縦に並びます。ルールの一覧・宛先・証明書の期限・インポートや履歴の結果など横に長い表は、表の中だけを横にスクロールします。
    • フォームのタブは横にスクロールできます。行の並べ替えや削除のボタンは押しやすい大きさ(44px)になります。
  • README にバッジ(CI・リリース・ライセンス・Node.js・Renovate)を付けました。

修正

  • 転送先の名前が長いと、デスクトップでもページ全体が横にはみ出していたのを直しました。
  • L7 のサービスの重みの欄が、全幅に広がっていたのを直しました。

対になる rproxy-api: v0.3.15


Added

  • The admin UI now works on phone and tablet widths (#88).
    • Below 1024px, the "Menu" button in the header opens and closes the page links. The language switch and sign-out are inside the menu. Esc or moving to another page closes it.
    • Dashboard cards stack vertically. Wide tables (rule list, targets, certificate expiry, import and history results) scroll horizontally inside the table only.
    • Form tabs scroll horizontally. Buttons for reordering and removing rows are larger (44px) so they are easier to tap.
  • Badges in the README (CI, release, license, Node.js, Renovate).

Fixed

  • A long target name made the whole page scroll sideways, even on desktop.
  • The weight field of an L7 service stretched to full width.

Paired with rproxy-api v0.3.15.