Skip to content

v0.2.1

Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 02 Sep 02:37
· 14 commits to main since this release
faeb7e7

Three changes on top of v0.2.0. One of them is a security fix that matters if you ran the
compose stack anywhere other than your own laptop.

If you used docker-compose.yml, read this (#217)

docker-compose.yml published three things on every interface rather than on loopback:

  • PostgreSQL on 5432, holding enrolment tokens, access policies and password hashes,
    with the credentials written three lines above it in the same file.
  • The control plane API on 8080, which mints enrolment tokens, in plaintext.
  • The relay's admin endpoint on 9090, which is health and statistics and is not
    authenticated. The binary defaults it to 127.0.0.1:9090 and says why; the compose file
    overrode that and published it, undoing the decision without recording one.

On a laptop that means anybody on the same café wifi. On a VPS it means the internet.

All three are now bound to 127.0.0.1, and the relay's admin address is left unset so the
binary's own default applies. Read the relay's stats with
docker compose exec relay wget -qO- http://127.0.0.1:9090/stats.

This file is how somebody tries meshp. A real deployment is docs/self-hosting.md, which
serves TLS and does not use it.

A device can be erased, not only revoked (#218)

Nothing could delete a device. DELETE /networks/{id}/devices/{id} revokes, the listing
keeps revoked memberships on purpose so an administrator can see a device is out, and no
query anywhere issued DELETE FROM devices. "Take this laptop off the system" had no answer.

DELETE /api/v1/organizations/{organizationID}/devices/{deviceID} erases a device, its
memberships, its keys and its route advertisements in every network at once, behind a new
organization.devices.forget permission held by administrators and owners. The page grows a
Forget button, which appears once a device is revoked.

Organisation-scoped rather than network-scoped, because a device holds memberships in several
networks (ADR-0004) and no one of them owns it.

The audit trail survives the erasure — it records labels rather than foreign keys — so what
was removed, by whom, and which keys were withdrawn is still answerable afterwards. That is
what makes this a real delete rather than a tombstone.

Migration 0017 changes state_changes.membership_id to ON DELETE CASCADE. It was
SET NULL, which combined with the table's own CHECK made deleting a device impossible: a
referential SET NULL is an UPDATE, CHECK constraints run on UPDATE, and the delete failed on
the device's own enrolment row. Applies automatically on start.

The README says which platforms carry traffic (#215)

It claimed too much in one place and too little in three. The header offered "Linux, Windows,
macOS, Android and iOS" as a feature list when two of those have no data plane; the status
section opened by describing a Linux-only agent four paragraphs above the text correctly
saying three platforms carry traffic; and "full-tunnel egress works on Linux" had been wrong
since #166 and #180.

Upgrading from v0.2.0

Nothing invalidates an existing deployment. The schema migrates forward on start. If you run
the compose stack and had reached it from another machine, that will stop working — which is
the point.

What's Changed

  • docs: the README says which platforms carry traffic, in both directions by @aswinsam in #215
  • fix(compose): the database and the relay's admin endpoint stop listening to the network by @aswinsam in #217
  • feat(devices): a device can be erased, not only revoked by @aswinsam in #218

Full Changelog: v0.2.0...v0.2.1