Skip to content

Releases: max3584/rproxy-api

v0.4.0

Choose a tag to compare

@github-actions github-actions released this 07 Oct 17:08
d2df0d1

追加

  • Kubernetes のコントローラ向けの口(#220)。Kubernetes の Gateway API で rproxy を動かすコントローラ rproxy-gateway v0.4.0 と一緒に使えます。
    • ルールの組 PUT /rulesets/{name}:持っているルールの全体を 1 回で渡すと、rproxy が差分を当てます。generation・If-Match(etag)・?dry_run=true が使え、組のルールを個別に変えると 409 owned です。組は作ったトークンのもので、トークンファイルの allow_rulesets で扱える組の名前を絞れます。
    • ルールの labels(ログ・/metrics に出す印)、conditions(Gateway API の status の形)、GET /readyz。
  • Gateway API 向けの L7・TLS(#237・#239)
    • headers の add、リダイレクトのステータス、ルートごとのタイムアウト、replace_host、サーバごとのミドルウェア、retry のステータス、エラーのステータスのサーバ。
    • 新しいミドルウェア cors・mirror。
    • 転送先への HTTP/2(h2・h2c・auto、トレーラー)とサービスごとの TLS(CA・SNI・SAN の検証、BackendTLSPolicy)。
    • tls.routes の複数の宛先。
    • client_auth: optional_no_verify と X-Client-Verify・X-Forwarded-Client-Cert。
  • L4 の送信元ごとの制限と帯域の上限(#219):ルールの limits(同時接続・新しい接続の速さ)と bandwidth(上り・下り)。利用量の集計のための数(counters_since)。
  • 制御 API の守り(#218):クライアント証明書(mTLS)とトークンの結びつけ、トークンの期限の知らせ、認証の失敗が続く送信元の一時停止(429 locked_out)。
  • GeoIP の許可・拒否(#221):MaxMind 形式のデータベースで、国・AS ごとに許可・拒否できます。
  • 受け身のヘルスチェック(#221):転送の失敗が続いたサーバを一時的に外します(outlier_detection)。
  • 変更前の差分(#222):?dry_run=true、POST /config/plan、rproxy-api --check-config --diff。
  • API で作ったルールの保存(#222):トークンに persist: true を付けると、作ったルールを DB の rproxy_rules に保存し、再起動の後も戻します(origin: "api")。
  • 再起動なしの更新(#223):SIGUSR2 か POST /admin/upgrade で、接続を切らずに新しいバイナリへ引き継ぎます。同じマイナーの中のパッチは、.deb の更新でも引き継ぎます。
  • コンテナの自動更新(#223):入口を rproxy-api launch にして RPROXY_UPDATE=auto にすると、同じ X.Y の最新のパッチを取り、minisign の署名を確かめてから入れ替えます。落ちた版は自動で戻します。リリースの鍵は docs/UPGRADE.md。
  • performance の設定(#223):global.performance(workers・udp_shards・cpu_affinity・busy_poll_usecs・splice)。

修正

  • クライアントが送ってきた X-Client-Verify・X-Forwarded-Client-Cert を、どのルールでも消すようにしました。tls.client_auth のないルールで、偽のクライアント証明書の情報が転送先に届いていました。
  • mirror の写しにも、転送先に付けるヘッダ(X-Forwarded-*・証明書)を付けるようにしました。
  • 転送先が HTTP/2 のとき、ストリームの空きを待ち続けて詰まることがあったのを直しました。
  • 自動更新で試していた版を、止めただけで悪い版として扱っていたのを直しました。
  • そのほか、セキュリティレビューの指摘を直しました(docs/DESIGN-v0.4.md の 17 節)。

変更

  • サービスのユーザーが rproxy から rproxy-api(主グループ rproxy)に変わります。 .deb と install.sh が、uid を変えずに名前だけ変えるので、ファイルの持ち主はそのままです。UI(rproxy-ui)は rproxy グループに入り、グループで読めるファイルを共有できます。
  • ルールが指す証明書・鍵・秘密のファイルを確かめるようになりました(global.files.owner_check: strict、既定)。
    • 持ち主が rproxy-api のファイルだけを使います。グループや他人が書けるファイル、誰でも読める鍵は断ります。
    • おすすめは rproxy-api:rproxy の 0640 です。certbot の証明書は deploy hook で写してください。
    • root が持つファイルを使いたい場所は、global.files.trusted_dirs か RPROXY_FILES_TRUSTED_DIRS で指定できます(Kubernetes の Secret など)。確認を止めるには owner_check: off。
  • v0.3.x から v0.4.0 への更新は、引き継ぎではなく再起動になります(引き継ぎは同じマイナーの中だけ)。
  • 接続の失敗の target.down のログは、reason: connect から reason: outlier と cause: connect に変わりました。
  • v0.4 を入れたことのある機械に v0.3 の .deb を入れ直すと、残った rproxy グループのせいで失敗します。UI v0.4 と組み合わせるときは、rproxy-api も v0.4 にしてください。

UI: TCP-UDP-rproxy-ui v0.4.0 · Kubernetes: rproxy-gateway v0.4.0


Added

  • Hooks for a Kubernetes controller (#220), used by rproxy-gateway v0.4.0 to run rproxy behind the Kubernetes Gateway API.
    • Rule sets PUT /rulesets/{name}: send the whole set of rules at once and rproxy applies the difference. Supports generation, If-Match (etag) and ?dry_run=true; changing a rule of a set on its own gets 409 owned. A set belongs to the token that created it, and allow_rulesets in the token file limits which set names a token may use.
    • Rule labels (shown in logs and /metrics), conditions (in the shape of Gateway API status) and GET /readyz.
  • L7 and TLS for the Gateway API (#237, #239)
    • headers add, redirect status, per-route timeouts, replace_host, per-server middlewares, retry status, error-status servers.
    • New middlewares cors and mirror.
    • HTTP/2 to upstreams (h2, h2c, auto, with trailers) and per-service TLS (CA, SNI and SAN checks; BackendTLSPolicy).
    • Several targets in tls.routes.
    • client_auth: optional_no_verify with X-Client-Verify and X-Forwarded-Client-Cert.
  • Per-source L4 limits and bandwidth caps (#219): rule limits (concurrent connections, new-connection rate) and bandwidth (up and down); counters for usage accounting (counters_since).
  • Control API hardening (#218): tokens bound to client certificates (mTLS), token-expiry notices, and a lockout for sources with repeated auth failures (429 locked_out).
  • GeoIP allow and deny (#221) by country and AS, with MaxMind-format databases.
  • Passive health checks (#221): servers that keep failing are taken out for a while (outlier_detection).
  • Dry runs (#222): ?dry_run=true, POST /config/plan and rproxy-api --check-config --diff.
  • Persistence for API-made rules (#222): with persist: true on a token, the rules it creates are saved in the rproxy_rules table and restored after a restart (origin: "api").
  • Upgrades without a restart (#223): SIGUSR2 or POST /admin/upgrade hands the sockets over to a new binary without dropping connections. Patches within the same minor are handed over by the .deb upgrade too.
  • Self-update for containers (#223): with rproxy-api launch as the entrypoint and RPROXY_UPDATE=auto, rproxy fetches the newest patch of its X.Y, checks its minisign signature and swaps it in; a version that crashes is rolled back. The release key is in docs/en/UPGRADE.md.
  • Performance settings (#223): global.performance (workers, udp_shards, cpu_affinity, busy_poll_usecs, splice).

Fixed

  • X-Client-Verify and X-Forwarded-Client-Cert sent by clients are now removed on every rule; on rules without tls.client_auth, forged client-certificate details reached upstreams.
  • mirror copies now carry the same forwarding headers (X-Forwarded-*, certificate details) as the main request.
  • HTTP/2 upstreams could stall while waiting for a free stream.
  • The self-update no longer marks a version under trial as bad just because it was stopped.
  • Other findings of the security review (docs/en/DESIGN-v0.4.md, section 17).

Changed

  • The service user changes from rproxy to rproxy-api (primary group rproxy). The .deb and install.sh rename the user and keep its uid, so file ownership stays valid. The UI user (rproxy-ui) joins the rproxy group and can read group-readable files.
  • Files that rules point at are now checked (global.files.owner_check: strict, the default).
    • Only files owned by rproxy-api are used. Files writable by the group or others, and keys readable by anyone, are refused.
    • The recommended mode is rproxy-api:rproxy 0640. Copy certbot's certificates with a deploy hook.
    • Directories where root-owned files are acceptable (Kubernetes Secrets, for one) can be listed in global.files.trusted_dirs or RPROXY_FILES_TRUSTED_DIRS. owner_check: off turns the check off.
  • Upgrading from v0.3.x to v0.4.0 restarts the service (handover works only within the same minor).
  • target.down for connection failures now logs reason: outlier with cause: connect instead of reason: connect.
  • Installing a v0.3 .deb again on a machine that had v0.4 fails because of the leftover rproxy group. With UI v0.4, use rproxy-api v0.4 as well.

UI: TCP-UDP-rproxy-ui v0.4.0 · Kubernetes: rproxy-gateway v0.4.0

v0.3.21

Choose a tag to compare

@github-actions github-actions released this 06 Oct 18:29
e919404

追加

  • ACME で証明書を取り、自動で更新できるようになりました(#208)。設定と使い方は docs/ACME.md。
    • challenge:HTTP-01(http のルールか、80 番の小さな待ち受け http01_listen)、TLS-ALPN-01(terminate のルール)、DNS-01。
    • DNS-01 のプロバイダ:PowerDNS の HTTP API、汎用の REST(テンプレート)、RFC 2136(TSIG。応答の署名も確かめる)、acme-dns。_acme-challenge の CNAME をたどって委任先のゾーンに書く。TXT は必ず消し、消し残しは次の起動で消す。
    • 更新:期限の 30 日前(または期間の 3 分の 1)。CA が ARI を出すときはその窓の中。失敗したら間隔を空けて取り直し、その間は今の証明書を使い続ける。
    • 設定:global.acme の accounts・dns_providers・resolvers。ルールは今までどおり tls.certificates[] の {acme: <resolver>, domains}。
    • API:GET /acme(状態。秘密は出さない)、POST /acme/renew・/acme/revoke・/acme/accounts/{name}/register・/deactivate(acme:write、既定で Unix ソケットからだけ)。
  • 守り
    • DNS の秘密は固定の設定からファイルで指すだけで、API・応答・ログに出さない。
    • アカウントと DNS のプロバイダの両方に、発行してよい名前の許可リスト(allowed_names)。外の名前は 400。ワイルドカードは DNS-01 だけ。
    • 新しいスコープ acme:write。発行の回数の上限(既定 1 時間に 10)。acme.*・audit のログ(秘密なし)。
    • 任意で、DNS の秘密を別のユーザーで動く補助プロセス(rproxy-api acme-helper、rproxy-acme-helper.service)に持たせ、本体は秘密を読まない形にできる(docs/PERMISSIONS.md)。
  • Traefik からの変換ツールが certResolver を rproxy の ACME の設定(秘密は入れない骨組み)に変換するようになりました。

変更

  • 「ACME は内蔵しない」方針を変えました。GET /capabilities の features.acme は true です。
  • 前の版の global.acme(一度も動いていなかった形)は使えません。docs/ACME.md の形で書いてください。
  • パッケージに StateDirectory=rproxy(/var/lib/rproxy。ACME のアカウントの鍵と証明書の置き場所)と、補助プロセス用の rproxy-acme ユーザー・サービス(入れるだけで有効にはしない)を足しました。purge で /var/lib/rproxy と /var/lib/rproxy-acme を消します。

UI: TCP-UDP-rproxy-ui v0.3.21


Added

  • Certificates can be obtained and renewed with ACME (#208). See docs/en/ACME.md.
    • Challenges: HTTP-01 (an http rule, or the small http01_listen responder on port 80), TLS-ALPN-01 (terminate rules), DNS-01.
    • DNS-01 providers: PowerDNS HTTP API, generic REST templates, RFC 2136 (TSIG, with signed answers verified) and acme-dns. The _acme-challenge CNAME is followed to the delegated zone; TXT records are always removed, and leftovers are removed at the next start.
    • Renewal 30 days before expiry (or a third of the lifetime), inside the CA's ARI window when offered. Failures retry with backoff while the current certificate stays in use.
    • Config: accounts, dns_providers and resolvers under global.acme. Rules keep {acme: <resolver>, domains} in tls.certificates[].
    • API: GET /acme (state, no secrets); POST /acme/renew, /acme/revoke, /acme/accounts/{name}/register and /deactivate (acme:write, Unix socket only by default).
  • Safeguards
    • DNS secrets are only referenced as files in the fixed config, never in the API, responses or logs.
    • allowed_names allowlists on both the account and the DNS provider; other names get 400; wildcards need DNS-01.
    • New scope acme:write, an issuance rate limit (10 per hour by default), acme.* and audit log events without secrets.
    • Optionally, a helper process running as another user (rproxy-api acme-helper, rproxy-acme-helper.service) holds the DNS secrets so the main process never reads them (docs/en/PERMISSIONS.md).
  • The Traefik converter maps certResolver to an rproxy ACME skeleton (secrets left out).

Changed

  • The "no built-in ACME" policy is reversed; features.acme in GET /capabilities is true.
  • The old global.acme shape (which never worked) is gone; use the shape in docs/en/ACME.md.
  • The package adds StateDirectory=rproxy (/var/lib/rproxy, where ACME keys and certificates live) and an rproxy-acme user and helper service (installed, not enabled). Purge removes /var/lib/rproxy and /var/lib/rproxy-acme.

UI: TCP-UDP-rproxy-ui v0.3.21

v0.3.20

Choose a tag to compare

@github-actions github-actions released this 06 Oct 15:42
fa8d4a1

追加

  • 状態を API とメトリクスで分かるように(#115)
    • GET /rules に all_targets_down(L4 で宛先がすべて down)と down_services(http のルールで、up の転送先がないサービス)
    • GET /config に crowdsec(LAPI に今つながっているか・最後に取れた時刻・最後の誤り・判定の数)
    • /metrics に rproxy_rule_all_targets_down・rproxy_http_service_down・rproxy_crowdsec_connected・rproxy_crowdsec_last_success_timestamp_seconds・rproxy_log_suppressed_total
  • SIEM・CrowdSec 向けのログ(#167 の一部)
    • 制御 API の 401 / 403 を event=audit に出すようにしました(client=送信元の IP、Unix ソケットからは unix、401 は reason=missing / invalid / expired)。トークンは出しません。ルールの変更と設定の読み直しの audit にも client が付きます。
    • http.access に refused_by(断ったミドルウェアの種類)・middleware(設定での名前)・user(basic_auth で通ったユーザー)・auth_error(basic_auth で断った理由)。パスワードは出しません。CrowdSec のパーサーもこれらを読みます。

修正

  • UDP で allow_from と CrowdSec で断ったときの conn.denied が debug でしか出ず、既定のログ・CrowdSec の検知・SIEM に届いていなかったのを直しました(info で出します)。ログは送信元ごと(続けて 20 行、その後は 1 秒 1 行)と全体(続けて 200 行、その後は 1 秒 50 行)で間引き、省いた行の数は次の行の suppressed と /metrics に出します。stats.denied は今までどおり 1 つずつ数えます。

変更

  • allow_listen_ports の範囲外で断ったルールの変更の audit の outcome が error から forbidden になりました。

Added

  • State in the API and metrics (#115)
    • GET /rules adds all_targets_down (all L4 targets down) and down_services (HTTP services with no healthy backend).
    • GET /config adds crowdsec (whether LAPI is reachable now, last success, last error, decision count).
    • /metrics adds rproxy_rule_all_targets_down, rproxy_http_service_down, rproxy_crowdsec_connected, rproxy_crowdsec_last_success_timestamp_seconds and rproxy_log_suppressed_total.
  • Logs for SIEM and CrowdSec (part of #167)
    • Control-API 401 / 403 responses are logged as event=audit with client (peer IP, or unix) and, for 401, reason (missing / invalid / expired). Tokens are never logged. Rule changes and config reloads also get client.
    • http.access adds refused_by (which middleware refused), middleware (its configured name), user (the basic_auth user) and auth_error (why basic_auth refused). Passwords are never logged. The CrowdSec parser reads them.

Fixed

  • UDP conn.denied for allow_from and CrowdSec was only logged at debug, so it never reached the default log, CrowdSec detection or a SIEM. It is now info, throttled per source (20 lines, then 1 per second) and overall (200, then 50 per second); the number of skipped lines goes to the next line's suppressed and to /metrics. stats.denied still counts every datagram.

Changed

  • Rule changes refused by allow_listen_ports now have audit outcome forbidden instead of error.

v0.3.19

Choose a tag to compare

@github-actions github-actions released this 06 Oct 11:09
6795d75

変更(速さとメモリの改善)

v0.3.18 と同じマシンで交互に測った負荷テストの結果を添えます(4 vCPU の GitHub のランナー、名前空間の中の仮想の回線。実際の NIC では差が小さくなる見込みです)。

  • L4 の TCP の転送を作り直しました。 読めるデータがあるときだけ 32 KiB のバッファを借りるようにし(何もしていない接続はバッファを持たない)、大きな転送が続く向きは splice(2) でカーネルの中だけで受け渡すようにしました(plain の TCP だけ。TLS 終端・STARTTLS・L7 は対象外)。
    • TCP 1 本 5.0 → 12.9 Gbit/s、8 本 11.9 → 43.6 Gbit/s。大きな転送の CPU あたりの量は約 7 倍。
    • TCP の接続 1 本あたりのメモリ 17.7 / 25.7 KiB(待機中 / 転送中)→ 7.5 KiB。
    • 小さなやり取りの遅延・新しい接続の数は変わりません。
  • L7(HTTP/2)の CPU を減らしました。 転送先への待機中の接続を多く使い回し(サーバごとに最大 1024 本、4 秒使わなければ閉じる)、リクエストごとの余分な処理を省きました。
    • HTTP/2 の小さなリクエスト +50〜60%、HTTP/1.1 +11%。遅延(p50 / p99)も 30% 前後短くなりました。
    • HTTP/2 over TLS に高い負荷をかけている間は、ピークのメモリが増えます(負荷が終われば戻ります)。
  • UDP をまとめて読み書きするようにしました(recvmmsg / sendmmsg、受信バッファを大きく)。64 バイトの全力の送信で、届く量 +65%、取りこぼし 57% → 21%。セッションあたりのメモリは変わりません。
  • メモリのアロケータに mimalloc を選べるようにしました(ビルドで --features alloc-mimalloc)。既定は今までどおり musl の malloc です。

設定の項目は変わっていません。UDP の待ち受けのソケットの数・splice の切り替えなどの設定の形は v0.4.0 で決めます。


Changed (speed and memory)

Measured against v0.3.18 on the same machine, alternating builds (4-vCPU GitHub runner, virtual links in network namespaces; expect smaller gaps on real NICs).

  • L4 TCP forwarding was rebuilt. A 32 KiB buffer is borrowed only while data is ready (idle connections hold no buffer), and directions with sustained large transfers move to splice(2), staying inside the kernel (plain TCP only; not TLS termination, STARTTLS or L7).
    • TCP 1 stream 5.0 → 12.9 Gbit/s, 8 streams 11.9 → 43.6 Gbit/s; about 7× more data per CPU on large transfers.
    • Memory per TCP connection 17.7 / 25.7 KiB (idle / busy) → 7.5 KiB.
    • Small-message latency and new connections per second are unchanged.
  • Less CPU for L7 (HTTP/2). More idle upstream connections are reused (up to 1024 per server, closed after 4 s unused) and per-request work was trimmed.
    • Small HTTP/2 requests +50–60%, HTTP/1.1 +11%; p50/p99 latency about 30% lower.
    • Peak memory is higher while HTTP/2 over TLS is under heavy load (it goes back down afterwards).
  • UDP now reads and writes in batches (recvmmsg / sendmmsg, larger receive buffer): at full rate with 64-byte packets, +65% delivered and loss 57% → 21%. Memory per session is unchanged.
  • mimalloc can be chosen as the allocator (build with --features alloc-mimalloc). The default stays musl's malloc.

No settings changed. The shape of settings such as the number of UDP listener sockets and the splice switch will be decided in v0.4.0.

v0.3.18

Choose a tag to compare

@github-actions github-actions released this 05 Oct 13:30
76ce2ef

修正

  • メールサーバの EHLO の応答に UTF-8 でないバイトや多バイト文字が混ざると、STARTTLS の接続のタスクが panic で落ちていたのを直しました(ファジングで見つかりました)。
  • match の式を深く入れ子にするとスタックがあふれてプロセス全体が落ちていたのを直しました(#180)。入れ子は 32 段まで、1 つの式の条件は 256 個までで、超えると設定の誤り(API は 400、起動・読み直し・--check-config でも誤り)になります。
  • 時間の値(rate_limit の期間、タイムアウト、health_check、retry、circuit_breaker、CrowdSec の update_interval など)にとても大きな値を書くと、あふれて小さな値になったり、プロセスが落ちたりしていたのを直しました。365 日(8760h)を超える値は設定の誤りになります。

追加

  • GET /capabilities が rproxy-api のバージョン(version)を返すようになりました。管理 UI がバージョンを表示し、組み合わせを確かめるのに使います。

変更

  • rproxy-api と管理 UI のバージョン番号は、それぞれ別に進めるようにしました(docs/RELEASING.md)。組み合わせは UI の画面で確かめられます。

UI の最新: TCP-UDP-rproxy-ui v0.3.18


Fixed

  • A STARTTLS connection task panicked when the mail server's EHLO reply contained non-UTF-8 bytes or multi-byte characters (found by fuzzing).
  • Deeply nested match expressions overflowed the stack and aborted the whole process (#180). Nesting is now limited to 32 levels and an expression to 256 matchers; beyond that it is a configuration error (400 from the API, and an error at startup, on reload and from --check-config).
  • Very large durations (rate_limit periods, timeouts, health_check, retry, circuit_breaker, CrowdSec update_interval, …) could overflow to small values or crash the process. Durations over 365 days (8760h) are now configuration errors.

Added

  • GET /capabilities now returns the rproxy-api version. The management UI shows it and uses it to check compatibility.

Changed

  • rproxy-api and the management UI now have independent version numbers (docs/en/RELEASING.md). The UI shows whether they fit together.

Latest UI: TCP-UDP-rproxy-ui v0.3.18

v0.3.17

Choose a tag to compare

@github-actions github-actions released this 05 Oct 11:30
498467a

修正

  • TCP の転送で TCP_NODELAY を設定しておらず、小さなデータのやり取りで約 40 ms 待つことがあったのを直しました(#176)。L4 の TCP、TLS の終端、STARTTLS、SNI、L7(http のルール)の受け付けた接続と転送先への接続、forward_auth・OIDC・CrowdSec への通信のすべてが対象です。
    • 手元の計測では、TLS のハンドシェイクが 41 ms → 0.6 ms、HTTP/2 の同時 32 リクエストが 41 ms → 1 ms、TCP の転送の速さが約 11 倍になりました。

変更

  • ソースの構成を役割ごとのフォルダに分けました(control/・config/・core/・net/・l4/・tls/・l7/)。動きは変わりません。RPROXY_LOG_LEVEL をモジュール名で絞り込んでいる場合(例 rproxy_api::http=debug)は、新しい名前(rproxy_api::l7=debug)に書き換えてください。
  • バックアップと復旧の手順(docs/BACKUP.md)を足しました。
  • 動くものが変わったほうだけをリリースする決まりにしました(docs/RELEASING.md)。v0.3.16 は UI だけの版で、rproxy-api は v0.3.15 から v0.3.17 に進みます。

対になる UI: v0.3.17


Fixed

  • TCP forwarding did not set TCP_NODELAY, so small exchanges could wait about 40 ms (#176). This covers accepted connections and upstream connections for L4 TCP, TLS termination, STARTTLS, SNI and L7 (http rules), plus calls to forward_auth, OIDC and CrowdSec.
    • In our measurements, the TLS handshake went from 41 ms to 0.6 ms, 32 concurrent HTTP/2 requests from 41 ms to 1 ms, and TCP throughput rose about elevenfold.

Changed

  • The source is now split into folders by role (control/, config/, core/, net/, l4/, tls/, l7/). Behavior is unchanged. If you filter RPROXY_LOG_LEVEL by module name (e.g. rproxy_api::http=debug), switch to the new name (rproxy_api::l7=debug).
  • Backup and restore guide (docs/en/BACKUP.md).
  • Only the side whose running code changed is released now (docs/en/RELEASING.md). v0.3.16 was UI-only; rproxy-api goes from v0.3.15 to v0.3.17.

Paired with UI v0.3.17.

v0.3.15

Choose a tag to compare

@github-actions github-actions released this 03 Oct 18:07
4766c28

追加

  • README にバッジ(CI・相互接続・cargo-deny・リリース・apt・ライセンス・Renovate)を付けました。
  • docs/RELEASING.md に、バージョンを上げるときは Cargo.lock も直す手順を書きました。

この版での rproxy-api の動作の変更はありません。管理 UI のスマホ・タブレット対応は TCP-UDP-rproxy-ui v0.3.15 を見てください。


Added

  • Badges in the README (CI, interop, cargo-deny, release, apt, license, Renovate).
  • docs/RELEASING.md now says to update Cargo.lock when bumping the version.

rproxy-api behaves the same as in v0.3.14. For the admin UI's phone and tablet support, see TCP-UDP-rproxy-ui v0.3.15.

v0.3.14

Choose a tag to compare

@github-actions github-actions released this 03 Oct 09:21
24c28a6

依存の整理の版です。動きは変わりません。

変更

  • 依存のバージョンを Cargo.lock で固定し、リポジトリに入れた。リリースのバイナリと .deb は、このファイルのとおりのバージョンでビルドする(実際に入っている依存を外から確かめられる)
  • メンテナンスが終わった rustls-pemfile をやめ、後継の rustls-pki-types で証明書と鍵を読む(読める形式とエラーのメッセージは同じ)
  • 使っていない依存と機能を外した
  • 主な依存の版:rustls 0.23.45(RUSTSEC-2026-0285 の修正版)、ring 0.17.14、tokio 1.53.1、hyper 1.11.1、quinn 0.11.12、h3 0.0.8、bcrypt 0.19.3、bytes 1.12.1

組み合わせる UI


Dependency cleanup. No behavior change.

Changed

  • Dependency versions are pinned in Cargo.lock, now committed to the repository; release binaries and .debs are built from it (so the dependencies actually shipped can be checked from outside)
  • The unmaintained rustls-pemfile was replaced by rustls-pki-types for reading certificates and keys (same formats and error messages)
  • Unused dependencies and features were removed
  • Key dependency versions: rustls 0.23.45 (the RUSTSEC-2026-0285 fix), ring 0.17.14, tokio 1.53.1, hyper 1.11.1, quinn 0.11.12, h3 0.0.8, bcrypt 0.19.3, bytes 1.12.1

Paired with

v0.3.13

Choose a tag to compare

@github-actions github-actions released this 03 Oct 06:09
d58a6ed

追加

  • ドキュメントの英語版(README.en.md、docs/en/)。.deb では /usr/share/doc/rproxy-api/en/ に入る

修正

  • docs/API.md のルールの項目の表が、途中から表として表示されていなかった

組み合わせる UI


Added

  • English documentation (README.en.md, docs/en/), installed by the .deb under /usr/share/doc/rproxy-api/en/

Fixed

  • Part of the rule-fields table in docs/API.md was not rendered as a table

Paired with

v0.3.12

Choose a tag to compare

@github-actions github-actions released this 03 Oct 05:29
27eeb8c

rproxy-api 側の変更はありません。UI v0.3.12 と組み合わせて使います。

組み合わせる UI


No changes in rproxy-api. Use with UI v0.3.12.

Paired with