Skip to content

Release v1.2.0

Choose a tag to compare

@owine owine released this 06 Jan 20:36
· 146 commits to main since this release
459f58e

Release v1.2.0

This minor release includes significant improvements to health checks, CI/CD workflows, and overall reliability.

✨ Added

  • Enhanced 5-tier health check validation

    • Basic mode: Infrastructure-only validation (web server + CGI execution)
    • Strict mode: Infrastructure + UPS connectivity validation
    • HTTP headers validation
    • Comprehensive error detection and reporting
  • lighttpd performance tuning for resource-constrained environments

    • server.max-connections = 16 (reduced from 1024)
    • server.max-keep-alive-requests = 4
    • server.max-worker = 2 (reduced from 4)
    • server.max-fds = 128 (reduced from 1024)
  • Comprehensive functional testing suite in CI/CD pipeline

    • Container health verification
    • Web server response testing
    • HTTP headers validation
    • CGI execution testing
    • Health check script testing (basic and strict modes)
    • Non-root user verification
    • Read-only filesystem compatibility testing
  • Documentation improvements

    • hosts.conf.example with comprehensive UPS monitoring examples
    • SECURITY.md with vulnerability reporting policy and security best practices
    • CHANGELOG.md following Keep a Changelog format
    • Enhanced Renovate configuration with better commit messages

🔄 Changed

  • CI/CD workflow restructured to build-test-promote pattern

    • Build creates sha-<commit> tag only
    • Functional testing and security scanning run in parallel on same image
    • Image promotion with additional tags only occurs after all tests pass
    • No rebuild for testing (faster, more consistent)
  • Docker image tagging strategy refined

    • :main - Latest tested main branch build
    • :latest - Latest tested release (recommended for production)
    • :v1.2.0 - Exact version pinning
    • :v1.2 - Latest patch in v1.2.x series
    • :v1 - Latest minor in v1.x series
    • :sha-<commit> - Specific commit builds (for debugging/pinning)
  • docker-compose.yml now includes HEALTHCHECK_MODE environment variable documentation

🐛 Fixed

  • Renovate repology configuration for Alpine 3.23 package tracking
  • Renovate custom manager conflict with native Dockerfile manager for Alpine base image

📦 Container Images

All images have been built, tested, and published to GitHub Container Registry:

# Recommended for production (latest tested release)
docker pull ghcr.io/owine/nut-cgi:latest

# Pin to exact version
docker pull ghcr.io/owine/nut-cgi:v1.2.0

# Receive patch updates automatically
docker pull ghcr.io/owine/nut-cgi:v1.2

# Receive all v1.x updates automatically
docker pull ghcr.io/owine/nut-cgi:v1

Supported architectures: linux/amd64, linux/arm64

🔒 Security

  • All images scanned with Trivy (no HIGH/CRITICAL vulnerabilities)
  • Non-root user (UID 1000)
  • Read-only root filesystem compatible
  • All capabilities dropped in production deployments

📝 Full Changelog

See CHANGELOG.md for complete details.

🙏 Acknowledgments

Built with ❤️ using Alpine Linux 3.23, Network UPS Tools 2.8.4, and lighttpd 1.4.82.