Release v1.2.0
Release v1.2.0
This minor release includes significant improvements to health checks, CI/CD workflows, and overall reliability.
✨ Added
-
Enhanced 5-tier health check validation
- Basic mode: Infrastructure-only validation (web server + CGI execution)
- Strict mode: Infrastructure + UPS connectivity validation
- HTTP headers validation
- Comprehensive error detection and reporting
-
lighttpd performance tuning for resource-constrained environments
server.max-connections = 16(reduced from 1024)server.max-keep-alive-requests = 4server.max-worker = 2(reduced from 4)server.max-fds = 128(reduced from 1024)
-
Comprehensive functional testing suite in CI/CD pipeline
- Container health verification
- Web server response testing
- HTTP headers validation
- CGI execution testing
- Health check script testing (basic and strict modes)
- Non-root user verification
- Read-only filesystem compatibility testing
-
Documentation improvements
hosts.conf.examplewith comprehensive UPS monitoring examplesSECURITY.mdwith vulnerability reporting policy and security best practicesCHANGELOG.mdfollowing Keep a Changelog format- Enhanced Renovate configuration with better commit messages
🔄 Changed
-
CI/CD workflow restructured to build-test-promote pattern
- Build creates
sha-<commit>tag only - Functional testing and security scanning run in parallel on same image
- Image promotion with additional tags only occurs after all tests pass
- No rebuild for testing (faster, more consistent)
- Build creates
-
Docker image tagging strategy refined
:main- Latest tested main branch build:latest- Latest tested release (recommended for production):v1.2.0- Exact version pinning:v1.2- Latest patch in v1.2.x series:v1- Latest minor in v1.x series:sha-<commit>- Specific commit builds (for debugging/pinning)
-
docker-compose.yml now includes
HEALTHCHECK_MODEenvironment variable documentation
🐛 Fixed
- Renovate repology configuration for Alpine 3.23 package tracking
- Renovate custom manager conflict with native Dockerfile manager for Alpine base image
📦 Container Images
All images have been built, tested, and published to GitHub Container Registry:
# Recommended for production (latest tested release)
docker pull ghcr.io/owine/nut-cgi:latest
# Pin to exact version
docker pull ghcr.io/owine/nut-cgi:v1.2.0
# Receive patch updates automatically
docker pull ghcr.io/owine/nut-cgi:v1.2
# Receive all v1.x updates automatically
docker pull ghcr.io/owine/nut-cgi:v1Supported architectures: linux/amd64, linux/arm64
🔒 Security
- All images scanned with Trivy (no HIGH/CRITICAL vulnerabilities)
- Non-root user (UID 1000)
- Read-only root filesystem compatible
- All capabilities dropped in production deployments
📝 Full Changelog
See CHANGELOG.md for complete details.
🙏 Acknowledgments
Built with ❤️ using Alpine Linux 3.23, Network UPS Tools 2.8.4, and lighttpd 1.4.82.