Skip to content

v0.4.1

Choose a tag to compare

@github-actions github-actions released this 08 Oct 11:32
· 48 commits to master since this release
6a01b74

追加

  • 止まるときに接続を流し終えられるようになりました(#246)。RPROXY_SHUTDOWN_DELAY(--shutdown-delay)と RPROXY_SHUTDOWN_DRAIN(--shutdown-drain)。既定は 0s・0s で、今までどおりすぐ止まります。
    • SIGTERM の後、delay の間は /readyz を 503(draining)にしたまま受け付けを続け、そのあと待ち受けを閉じて、今の接続の終わりを drain まで待ちます。
    • HTTP/1.1 は Connection: close、HTTP/2 は GOAWAY。UDP は今のセッションを運び、新しいセッションは作りません。
    • その間、読むだけの API と /metrics は答え、変更の API は 503 shutting_down。2 回目の SIGTERM ですぐ止まります。
    • systemd で使うときの目安は README に書きました。
  • 証明書の API(#240・#247):PUT/GET/DELETE /certs/{name} で証明書と鍵を渡し、ルールの tls.certificates[] から {"cert": "<name>"} で使えます。
    • 差し替えは接続を切らずに効きます。
    • 保存先は RPROXY_CERT_STORE(既定 /var/lib/rproxy/certs、鍵は 0600)。
    • 新しいスコープ certs:read・certs:write と、トークンの allow_certs(使える名前の先頭)。
    • 鍵を送る PUT は、TLS・loopback・Unix ソケットからだけ受けます。監査のログには名前と指紋だけを残します。
  • ルールの組の保存(#241・#249):persist: true のトークンで PUT /rulesets/{name} した組を DB の rproxy_rule_sets に保存し、再起動の後も戻します(/readyz は戻し終えてから ready)。UI の db/migrations/012_rproxy_rule_sets.sql が要ります。

修正

  • 証明書を消している途中でプロセスが落ちると、証明書の半分が残り、それを使うルールが失敗していたのを直しました。
  • 証明書の削除が途中で失敗したとき、残りを次の起動まで待たずに、次の証明書の書き込みで片付けるようにしました。
  • ACME の更新の途中でプロセスが落ちると、鍵と証明書が組にならず、期限が近づくまで取り直さないことがあったのを直しました(仮の証明書で動かし、すぐ取り直します)。
  • 自動更新の状態(state.json)と、キャッシュの署名・マニフェストを、ディスクに確実に書いてから置き換えるようにしました。途中で止まったダウンロードの一時ファイルも片付けます。

変更

  • コンテナの起動役(rproxy-api launch):試している版のサーバだけが SIGKILL で止まったとき(コンテナのメモリ上限の OOM など)、1 回で悪い版にしていたのを、文書どおり 3 回続いたら悪い版にするようにしました。自分で落ちたとき(終了コード・SIGABRT)は今までどおりすぐ悪い版です。
  • 新しい項目(allow_certs・certs:*・ルールの cert・保存した組)を使い始めたあとで v0.4.0 に戻すと、トークンファイルやルールが読めなくなります。戻す前に外してください。
  • 再起動の後、統計の数は 0 から数え直します(今までと同じ動きを docs/API.md に書きました)。

UI: TCP-UDP-rproxy-ui v0.4.1


Added

  • Graceful shutdown (#246): RPROXY_SHUTDOWN_DELAY (--shutdown-delay) and RPROXY_SHUTDOWN_DRAIN (--shutdown-drain). Both default to 0s, so rproxy still stops at once.
    • After SIGTERM, rproxy keeps accepting for delay with /readyz at 503 (draining), then closes its listeners and waits up to drain for current connections to finish.
    • HTTP/1.1 gets Connection: close, HTTP/2 a GOAWAY. UDP carries existing sessions and starts no new ones.
    • Meanwhile read-only API calls and /metrics keep answering; changes get 503 shutting_down. A second SIGTERM stops at once.
    • Suggested values for systemd are in the README.
  • Certificate API (#240, #247): hand certificates and keys over with PUT/GET/DELETE /certs/{name} and use them from a rule's tls.certificates[] as {"cert": "<name>"}.
    • Replacing one takes effect without dropping connections.
    • Stored under RPROXY_CERT_STORE (default /var/lib/rproxy/certs, keys 0600).
    • New scopes certs:read and certs:write, and allow_certs (name prefixes) on tokens.
    • A PUT, which carries a key, is accepted only over TLS, loopback or the Unix socket. Audit logs keep only the name and fingerprint.
  • Persisted rule sets (#241, #249): rule sets put with a persist: true token are saved in the rproxy_rule_sets table and restored after a restart (/readyz turns ready once they are back). Needs the UI's db/migrations/012_rproxy_rule_sets.sql.

Fixed

  • A crash while deleting a certificate could leave half of it behind, and rules using it failed.
  • A certificate removal that failed half way is now cleaned up at the next certificate write instead of the next start.
  • A crash during an ACME renewal could leave a key and certificate that did not match, and the certificate was not obtained again until close to expiry; rproxy now runs with a placeholder and renews at once.
  • The self-update state (state.json) and the cached signatures and manifests are now flushed to disk before being swapped in, and leftover temporary files of interrupted downloads are removed.

Changed

  • Container launcher (rproxy-api launch): when only the server of a version under trial is SIGKILLed (an OOM kill from a container memory limit, for one), the version now becomes bad after three times in a row, as documented, instead of at once. Crashing on its own (exit code, SIGABRT) still marks it bad at once.
  • After you start using the new items (allow_certs, certs:*, a rule's cert, persisted rule sets), going back to v0.4.0 cannot read those token files or rules; remove them before downgrading.
  • Statistics start from 0 after a restart (unchanged behaviour, now documented in docs/en/API.md).

UI: TCP-UDP-rproxy-ui v0.4.1