Skip to content

Releases: paulopiriquito/hog

v2.2.0

v2.2.0 Pre-release
Pre-release

Choose a tag to compare

@paulopiriquito paulopiriquito released this 29 Sep 22:48
v2.2.0
8191029

Full Changelog: v2.0.0...v2.2.0

v2.0.0

Choose a tag to compare

@paulopiriquito paulopiriquito released this 08 Jul 23:29
v2.0.0
f462b89

HOG v2.0.0 is a ground-up rewrite on Go 1.26 and the standard library — a single, composable application gateway that serves your frontend and acts as its backend-for-frontend (BFF) and API gateway. It is no longer a fork of KrakenD: v2 drops that lineage for a lean, idiomatic, standard-library-first design with its own architecture, configuration model, and extension system.

📖 Documentation: https://paulopiriquito.github.io/hog/ · 🚀 Quick start · 🧭 Migrating from v1

Highlights

  • One binary, two jobs — a traversal-safe static web server (drop-in in front of an SPA) and a full BFF/API gateway.
  • Kubernetes-style configuration — declarative YAML resources (Gateway, Route, RouteGroup, Policy) with ${ENV} interpolation and label selectors.
  • BFF authentication — OpenID Connect login with PKCE; the session lives in an encrypted, fingerprinted cookie that never reaches your backends. API clients authenticate with a bearer token.
  • Backend mapping & aggregation — reverse-proxy a route to one upstream, or fan an api route out to several backends and merge their responses; identity projected as X-User-*, access token forwarded only when opted in.
  • Authorization — a single access block with built-in group/claim rules plus embedded OPA/Rego policies (kind: Policy); additive, deny-overrides, fail-closed.
  • Observability — opt-in OpenTelemetry traces & metrics over OTLP, W3C context propagation, and a trace-correlated access log.
  • Security by default — enforced trustedProxies, a gateway-wide CSRF (http.CrossOriginProtection) + security-headers stage, SameSite=Lax sessions, POST-only same-origin logout, non-root read-only-friendly images.
  • Compile-time extensibility — extend HOG with Go plugins compiled in via hog-build (no fragile .so loading), or import it as a framework.

Container images (GHCR · multi-arch: linux/amd64 + linux/arm64)

Image Purpose Pull
hog-runtime Secure non-root Alpine runtime base docker pull ghcr.io/paulopiriquito/hog-runtime:v2.0.0
hog-static SPA server out of the box (COPY dist/ /srv/web/) docker pull ghcr.io/paulopiriquito/hog-static:v2.0.0
hog-builder Compose a custom binary from a plugin manifest; bundles kustomize for rendering config from base+overlays docker pull ghcr.io/paulopiriquito/hog-builder:v2.0.0
hog-docs This documentation site, served by hog-static docker pull ghcr.io/paulopiriquito/hog-docs:v2.0.0

Each image is also tagged latest. Serve a SPA in one step:

FROM ghcr.io/paulopiriquito/hog-static:v2.0.0
COPY dist/ /srv/web/

Breaking changes

HOG v2 is a clean-room rewrite and is not backward compatible with v1:

  • Configuration — v1's KrakenD-style JSON is replaced by Kubernetes-style YAML resources. No automatic migration.
  • Extensions — v1's runtime .so plugins are replaced by compile-time Go plugins (hog-build) or framework import.
  • Runtime — a native net/http gateway; the Lura/KrakenD core is gone.

v1 is deprecated and archived under v1/. See the migration guide.

Verify

docker buildx imagetools inspect ghcr.io/paulopiriquito/hog-runtime:v2.0.0   # linux/amd64 + linux/arm64

Full changelog: https://github.com/paulopiriquito/hog/commits/v2.0.0

v1.3.0

Choose a tag to compare

@paulopiriquito paulopiriquito released this 12 Jun 23:35
f421240

This release makes HOG's observability OpenTelemetry-native, adds environment-driven log fields and native Datadog log↔trace correlation, and brings the toolchain and dependencies up to date.

✨ Observability

  • OTEL-native local stack — replaced Grafana/Tempo/Loki/Prometheus/Alloy with a single OpenTelemetry Collector forwarding OTLP to OpenObserve (single-binary UI + store). Fewer services, pinned images, no config drift.
  • Native Datadog support — trace_format: both emits W3C (trace_id/span_id) and Datadog (dd.trace_id/dd.span_id) on every log line, so logs correlate to traces in either backend. Production path documented: ship OTLP to the node-local Datadog Agent (DaemonSet) for native APM.
  • Environment-driven log fields — logging tags values now resolve environment variables (e.g. {"version": "$HOG_VERSION", "pod": "$HOSTNAME"}), stamping per-deployment fields on every gateway and plugin log line.

🔐 Authentication

  • Client-driven PKCE flow — new /oauth/pkce-init endpoint lets a SPA generate its own verifier/challenge and handle its own callback, then exchange via /oauth/token. (Server-driven simple-auth already used PKCE.)
  • Simple-auth fixes (issues present in v1.2.x):
    • Session cookie is now SameSite=Lax instead of Strict — fixes the OAuth redirect chain breaking when the IdP is on a different domain. With Strict the cookie set during the callback wasn't sent on the redirect back to the app, so the user appeared unauthenticated.
    • Expired/stale session cookies no longer cause an infinite redirect loop — handleSimpleAuth now validates the JWT and clears a stale cookie before restarting the flow, instead of treating any decryptable cookie as authenticated.
  • Expanded end-to-end (headless-browser) coverage of the auth, static-content, and protected-API flows (including an expired-session regression test).

🐛 Fixes

  • Local-stack /static route now proxies to the correct e2e-web upstream.
  • Adapted to dependency upgrades: dropped the removed pubsub.OpenCensusViews, and aligned YAML content negotiation with RFC 9512 (application/yaml).

🧰 Dependencies & tooling

  • Bumped lura v2.14, krakend-pubsub v2.3, krakend-otel, krakend-cel/cobra/flexibleconfig, gocloud and others to latest.
  • Upgraded Go to 1.26.3 (Makefile + Dockerfile).
  • Removed the deprecated PluginLoader from ExecutorBuilder and cleaned up unused bins.

🧪 Testing

  • E2E suite now runs cleanly under both Docker and Podman (auto-detects the container runtime and naming convention).

📝 Docs

  • Corrected the authenticator and static-content plugin READMEs (login flows, /oauth/pkce-init, header-forwarding behavior) and rewrote the observability docs for the new stack.

What's Changed

Full Changelog: v1.2.1...v1.3.0

v1.2.0

Choose a tag to compare

@paulopiriquito paulopiriquito released this 24 May 10:46
129f346

Changes

  • Feature: Allow customization of identity headers to endpoint backends, with custom naming and mapping from OIDC claims and context by @joaoPCFrancisco in #23

✨ Features

Forward Headers (pkg/forward) — new module for claim-to-header projection

  • Scaffold pkg/forward module with Config, Header, Rule types and validation
  • Dotted-path claim resolution for nested JWT claims
  • Apply function for claim → header projection
  • Opt-in As field to publish mapped headers to downstream via forward.headers

Authenticator plugin

  • Load and validate forward config from plugin settings
  • Header injection allowlist replaces legacy blanket injection
  • Populate session Sub/Email/Name at login and on token refresh
  • Enrich userinfo response and refresh cookie with identity fields

Session

  • Add Headers, Sub, Email, Name fields to SessionData
  • SetSessionCookie now accepts full SessionData

🔒 Security

  • Strip configured headers before injection to close header-spoofing gap
  • Remove legacy Identity header; read identity from struct fields instead

🔧 Refactoring

  • Extract fetchUserInfo helpers and DRY userinfo utilities
  • Rename Header.Header to Header.Name for clarity
  • Code review polish across both features

📝 Documentation

  • Document forward.headers feature and configuration
  • Document Identity header removal and migration path

🧪 Tests

  • Add real LDAP userinfo fixture and forward-header end-to-end tests
  • Demo-stack fixes and LDAP-DN-shaped groups for dex user
  • Anonymize organizational data in local-stack fixtures

Full Changelog: v1.1.2...v1.2.1

Published packages

Container images:

ghcr.io/paulopiriquito/hog:v1.2.0
ghcr.io/paulopiriquito/hog:v1.2.0-lite

v1.1.2

Choose a tag to compare

@paulopiriquito paulopiriquito released this 14 Jan 22:41
Immutable release. Only release title and notes can be modified.
d9be2cd

Changes

  • Hog authenticator plugin now supports proxy Origin header for callback url resolution

Full Changelog: v1.1.1...v1.1.2

Published packages

Container images:

ghcr.io/paulopiriquito/hog:v1.1.2
ghcr.io/paulopiriquito/hog:v1.1.2-lite

v1.1.1

Choose a tag to compare

@paulopiriquito paulopiriquito released this 14 Jan 17:52
Immutable release. Only release title and notes can be modified.
98723bd

Changes

  • Hog static content plugin now allows for extra special characters to be used in the request URI

Full Changelog: v1.1.0...v1.1.1

Published packages

Container images:

ghcr.io/paulopiriquito/hog:v1.1.1
ghcr.io/paulopiriquito/hog:v1.1.1-lite

v1.1.0

Choose a tag to compare

@paulopiriquito paulopiriquito released this 14 Jan 01:23
Immutable release. Only release title and notes can be modified.
6560dae

What's Changed

New Contributors

Full Changelog: v1.0.0...v1.1.0

v1.0.0

Choose a tag to compare

@paulopiriquito paulopiriquito released this 12 Jan 19:50
Immutable release. Only release title and notes can be modified.
b949ac6

What's Changed

New Contributors

Full Changelog: https://github.com/paulopiriquito/hog/commits/v1.0.0