Skip to content

v1.1.2

Choose a tag to compare

@owine owine released this 06 Jan 15:48
· 156 commits to main since this release
248a48d

Critical Bug Fix

This patch release fixes a critical issue preventing the container from running with read-only root filesystem.

Bug Fixes

  • Fix: Configure lighttpd logging for read-only filesystem compatibility
    • Redirect error log to /dev/stderr instead of file
    • Redirect access log to /dev/stdout instead of file
    • Remove unnecessary /var/log/lighttpd directory creation
    • Enables container to run with --read-only security flag

Security Impact

This fix enables the recommended security hardening practice of running containers with read-only root filesystem:

services:
  nut-cgi:
    image: ghcr.io/owine/nut-cgi:v1.1.2
    read_only: true                       # ✅ Now supported
    tmpfs:
      - /tmp:mode=1777
    security_opt:
      - no-new-privileges:true
    cap_drop:
      - ALL

Technical Details

Build Performance: 59 seconds
Image Size: ~74.5 MB (unchanged)
Platforms: linux/amd64, linux/arm64

Upgrade Notes

This release is fully backward compatible with v1.1.1. Existing deployments will continue to work without changes.

Users running with read_only: true can now upgrade to enable this security hardening.

Images

docker pull ghcr.io/owine/nut-cgi:v1.1.2
docker pull ghcr.io/owine/nut-cgi:v1.1
docker pull ghcr.io/owine/nut-cgi:v1
docker pull ghcr.io/owine/nut-cgi:latest

Full Changelog: v1.1.1...v1.1.2