Repository navigation
Releases: paulopiriquito/hog
Release list
v2.2.0
v2.0.0
HOG v2.0.0 is a ground-up rewrite on Go 1.26 and the standard library — a single, composable application gateway that serves your frontend and acts as its backend-for-frontend (BFF) and API gateway. It is no longer a fork of KrakenD: v2 drops that lineage for a lean, idiomatic, standard-library-first design with its own architecture, configuration model, and extension system.
📖 Documentation: https://paulopiriquito.github.io/hog/ · 🚀 Quick start · 🧭 Migrating from v1
Highlights
- One binary, two jobs — a traversal-safe static web server (drop-in in front of an SPA) and a full BFF/API gateway.
- Kubernetes-style configuration — declarative YAML resources (
Gateway,Route,RouteGroup,Policy) with${ENV}interpolation and label selectors. - BFF authentication — OpenID Connect login with PKCE; the session lives in an encrypted, fingerprinted cookie that never reaches your backends. API clients authenticate with a bearer token.
- Backend mapping & aggregation — reverse-proxy a route to one upstream, or fan an
apiroute out to several backends and merge their responses; identity projected asX-User-*, access token forwarded only when opted in. - Authorization — a single
accessblock with built-in group/claim rules plus embedded OPA/Rego policies (kind: Policy); additive, deny-overrides, fail-closed. - Observability — opt-in OpenTelemetry traces & metrics over OTLP, W3C context propagation, and a trace-correlated access log.
- Security by default — enforced
trustedProxies, a gateway-wide CSRF (http.CrossOriginProtection) + security-headers stage,SameSite=Laxsessions, POST-only same-origin logout, non-root read-only-friendly images. - Compile-time extensibility — extend HOG with Go plugins compiled in via
hog-build(no fragile.soloading), or import it as a framework.
Container images (GHCR · multi-arch: linux/amd64 + linux/arm64)
| Image | Purpose | Pull |
|---|---|---|
hog-runtime |
Secure non-root Alpine runtime base | docker pull ghcr.io/paulopiriquito/hog-runtime:v2.0.0 |
hog-static |
SPA server out of the box (COPY dist/ /srv/web/) |
docker pull ghcr.io/paulopiriquito/hog-static:v2.0.0 |
hog-builder |
Compose a custom binary from a plugin manifest; bundles kustomize for rendering config from base+overlays |
docker pull ghcr.io/paulopiriquito/hog-builder:v2.0.0 |
hog-docs |
This documentation site, served by hog-static |
docker pull ghcr.io/paulopiriquito/hog-docs:v2.0.0 |
Each image is also tagged latest. Serve a SPA in one step:
FROM ghcr.io/paulopiriquito/hog-static:v2.0.0
COPY dist/ /srv/web/Breaking changes
HOG v2 is a clean-room rewrite and is not backward compatible with v1:
- Configuration — v1's KrakenD-style JSON is replaced by Kubernetes-style YAML resources. No automatic migration.
- Extensions — v1's runtime
.soplugins are replaced by compile-time Go plugins (hog-build) or framework import. - Runtime — a native
net/httpgateway; the Lura/KrakenD core is gone.
v1 is deprecated and archived under v1/. See the migration guide.
Verify
docker buildx imagetools inspect ghcr.io/paulopiriquito/hog-runtime:v2.0.0 # linux/amd64 + linux/arm64Full changelog: https://github.com/paulopiriquito/hog/commits/v2.0.0
v1.3.0
This release makes HOG's observability OpenTelemetry-native, adds environment-driven log fields and native Datadog log↔trace correlation, and brings the toolchain and dependencies up to date.
✨ Observability
- OTEL-native local stack — replaced Grafana/Tempo/Loki/Prometheus/Alloy with a single OpenTelemetry Collector forwarding OTLP to OpenObserve (single-binary UI + store). Fewer services, pinned images, no config drift.
- Native Datadog support —
trace_format: bothemits W3C (trace_id/span_id) and Datadog (dd.trace_id/dd.span_id) on every log line, so logs correlate to traces in either backend. Production path documented: ship OTLP to the node-local Datadog Agent (DaemonSet) for native APM. - Environment-driven log fields — logging
tagsvalues now resolve environment variables (e.g.{"version": "$HOG_VERSION", "pod": "$HOSTNAME"}), stamping per-deployment fields on every gateway and plugin log line.
🔐 Authentication
- Client-driven PKCE flow — new
/oauth/pkce-initendpoint lets a SPA generate its own verifier/challenge and handle its own callback, then exchange via/oauth/token. (Server-driven simple-auth already used PKCE.) - Simple-auth fixes (issues present in v1.2.x):
- Session cookie is now
SameSite=Laxinstead ofStrict— fixes the OAuth redirect chain breaking when the IdP is on a different domain. WithStrictthe cookie set during the callback wasn't sent on the redirect back to the app, so the user appeared unauthenticated. - Expired/stale session cookies no longer cause an infinite redirect loop —
handleSimpleAuthnow validates the JWT and clears a stale cookie before restarting the flow, instead of treating any decryptable cookie as authenticated.
- Session cookie is now
- Expanded end-to-end (headless-browser) coverage of the auth, static-content, and protected-API flows (including an expired-session regression test).
🐛 Fixes
- Local-stack
/staticroute now proxies to the correcte2e-webupstream. - Adapted to dependency upgrades: dropped the removed
pubsub.OpenCensusViews, and aligned YAML content negotiation with RFC 9512 (application/yaml).
🧰 Dependencies & tooling
- Bumped lura v2.14, krakend-pubsub v2.3, krakend-otel, krakend-cel/cobra/flexibleconfig, gocloud and others to latest.
- Upgraded Go to 1.26.3 (Makefile + Dockerfile).
- Removed the deprecated
PluginLoaderfromExecutorBuilderand cleaned up unused bins.
🧪 Testing
- E2E suite now runs cleanly under both Docker and Podman (auto-detects the container runtime and naming convention).
📝 Docs
- Corrected the authenticator and static-content plugin READMEs (login flows,
/oauth/pkce-init, header-forwarding behavior) and rewrote the observability docs for the new stack.
What's Changed
- Update dependencies, logging, and observability features by @paulopiriquito in #24
Full Changelog: v1.2.1...v1.3.0
v1.2.0
Changes
- Feature: Allow customization of identity headers to endpoint backends, with custom naming and mapping from OIDC claims and context by @joaoPCFrancisco in #23
✨ Features
Forward Headers (pkg/forward) — new module for claim-to-header projection
- Scaffold
pkg/forwardmodule withConfig,Header,Ruletypes and validation - Dotted-path claim resolution for nested JWT claims
Applyfunction for claim → header projection- Opt-in
Asfield to publish mapped headers to downstream viaforward.headers
Authenticator plugin
- Load and validate forward config from plugin settings
- Header injection allowlist replaces legacy blanket injection
- Populate session
Sub/Email/Nameat login and on token refresh - Enrich userinfo response and refresh cookie with identity fields
Session
- Add
Headers,Sub,Email,Namefields toSessionData SetSessionCookienow accepts fullSessionData
🔒 Security
- Strip configured headers before injection to close header-spoofing gap
- Remove legacy
Identityheader; read identity from struct fields instead
🔧 Refactoring
- Extract
fetchUserInfohelpers and DRY userinfo utilities - Rename
Header.HeadertoHeader.Namefor clarity - Code review polish across both features
📝 Documentation
- Document
forward.headersfeature and configuration - Document Identity header removal and migration path
🧪 Tests
- Add real LDAP userinfo fixture and forward-header end-to-end tests
- Demo-stack fixes and LDAP-DN-shaped groups for dex user
- Anonymize organizational data in local-stack fixtures
Full Changelog: v1.1.2...v1.2.1
Published packages
Container images:
ghcr.io/paulopiriquito/hog:v1.2.0
ghcr.io/paulopiriquito/hog:v1.2.0-lite
v1.1.2
Changes
- Hog authenticator plugin now supports proxy Origin header for callback url resolution
Full Changelog: v1.1.1...v1.1.2
Published packages
Container images:
ghcr.io/paulopiriquito/hog:v1.1.2
ghcr.io/paulopiriquito/hog:v1.1.2-lite
v1.1.1
Changes
- Hog static content plugin now allows for extra special characters to be used in the request URI
Full Changelog: v1.1.0...v1.1.1
Published packages
Container images:
ghcr.io/paulopiriquito/hog:v1.1.1
ghcr.io/paulopiriquito/hog:v1.1.1-lite
v1.1.0
What's Changed
- Session data includes both access and id token by @joaoPCFrancisco in #21
New Contributors
- @joaoPCFrancisco made their first contribution in #21
Full Changelog: v1.0.0...v1.1.0
v1.0.0
What's Changed
- Feature: Serve static-content by @paulopiriquito in #17
- Feature: Authentication plugin with oidc BFF by @paulopiriquito in #20
New Contributors
- @paulopiriquito made their first contribution in #17
Full Changelog: https://github.com/paulopiriquito/hog/commits/v1.0.0