Fluxheim 1.6.35 #112
Closed
eldryoth
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Fluxheim 1.6.35 Release Notes
Fluxheim 1.6.35 is the first stabilization checkpoint after the Pingora-free
runtime proof release.
This release is intentionally scoped to security cleanup, soak-test evidence,
performance/regression checks, dependency hygiene, and documentation clarity
before the 1.6.36 structural cleanup removes the temporary native proxy shim.
Highlights
WebSocket, cache, load-balancer, admin, metrics, stream, and background
service paths introduced by the 1.6.34 Pingora-free proof release.
zeroizecalls toward Fluxheim's
sanitizationcrate where the replacement ispractical and testable.
direct
zeroizewrappers tosanitization::SecretString.containers to
sanitization::SecretString.candidate buffers to
sanitizationsecret containers.zeroizecalls tosanitization::SecureSanitize.header assembly to
sanitization::SecretString.sanitization::SecretStringwhile preserving the existing OpenBao requestbehavior.
migration so both cache code paths use
sanitization::SecretString.zeroizederive path to anexplicit
sanitization::SecureSanitizedrop implementation.sanitization::ctfor futureconstant-time secret comparisons, and drop an unused
zeroizederive featurefrom the load-balancer crate.
OpenSSL backends to
sanitization::SecretVec.and OpenSSL backends to
sanitization::SecretVec.auth_requestresponse-header application cannot access itssecret container, matching other poisoned security-control locks and avoiding
a repeated inconsistent 502 path.
sanitization::SecureSanitizeduring drop.building the
profile-load-balancerrelease profile by default.PHP directory redirects, denied PHP paths, and fail-closed resolution errors
stay on the PHP-FPM path, while non-PHP static files can still be served by
[vhosts.web].so vhost PHP/static routing does not resolve the same path twice across a
deployment race window.
validate_runtime_config()run the central structuralConfig::validate()checks itself, so standalone runtime validation catchescross-field invariants such as peer-fill policy shape before startup.
stale and indexed maintenance batches no longer hold the global purge
registry mutex while deleting cache objects.
store, purge, and eviction cannot interleave state updates with filesystem
object removal for the same combined cache key.
Hostas the HTTP/2 upstream:authority,matching the documented upstream virtual-hosting behavior already used by the
native HTTP/1 and WebSocket paths.
explicit or protected PHP targets still avoid static source exposure, while
ordinary non-PHP front-controller probe errors defer to static fallback first.
opt-in and MariaDB readiness waiting, and verify full native WordPress
PHP-FPM plus proxy/TLS smoke coverage.
1.6.35arenot interpreted as regex backreferences during automated metadata updates.
scripts/test_starter.py, a human-facing selector for the maintainedlive smoke scripts and release gates.
scripts/check_smoke_images.shso maintainers can pull and record theconfigured WordPress, OpenBao, MariaDB, PostgreSQL, and Valkey smoke images.
profile-privacy, verifiesclient-IP headers are stripped before the upstream, and checks Fluxheim logs
do not retain the test IP, path, cookie, user-agent, or request ID.
nginx-compatible Ketama coverage, and extend the container smoke with
backend failover, recovery, and all-down 503 checks.
checks, WordPress, PHP Wolfi, RPM build, privacy mode, and smoke dependency
image freshness.
Prometheus and Jaeger containers when external URLs are not configured,
requiring Prometheus scrape plus OTLP metrics ingestion and keeping Jaeger
trace ingestion opt-in until native span export is implemented.
cache.peer_fill.shared_secret_filefor non-loopbackhttp://peer-fill URLs, closing the remaining unauthenticated cross-host plaintext
peer-fill cache-poisoning configuration.
cache.peer_fill.shared_secret_fileso peer-fill clusters can requireresponse-bound HMAC verification: outbound peer-fill requests include a
nonce/request signature, peers sign the status, canonical response headers,
and body digest, and unsigned or tampered peer responses are discarded before
cache storage.
scripts/smoke_ports.pyand wire the newer privacy, observability, andload-balancer container smokes through the shared randomized localhost port
allocator instead of repeating ad-hoc allocation snippets.
evidence for the stabilization line.
Compatibility Notes
zeroizeuse inside dependencies such as rustls,AWS-LC, and other cryptographic crates remains untouched.
temporary native proxy shim, moving remaining DTOs/helpers into owning crates,
and removing inert Pingora-era root code.
Verification
scripts/validate-release-metadata.shscripts/validate-pingora-dependency-policy.shscripts/validate-native-runtime-cutover.shscripts/capture-runtime-baseline.sh releasescripts/stable_release_gate.sh checkscripts/smoke_privacy_mode.shscripts/check_smoke_images.shscripts/smoke_load_balancer.shscripts/smoke_load_balancer_container.shscripts/smoke_openbao_cache_encryption.shscripts/smoke_redis_health_check.shscripts/smoke_mysql_health_check.shscripts/smoke_postgres_health_check.shscripts/smoke_observability_local.shscripts/smoke_wordpress_php_fpm.sh bothscripts/smoke_wordpress_proxy_tls.shChecksums And Signatures
ff52c18a83376e44eda25ab4c9fdbebecb70e2ae[MANUAL_SHA256] fluxheim-1.6.35.tar.gz[MANUAL_SHA256] fluxheim-1.6.35.zip0d4e05623fc8533ca0e497e872dce741783dfdb131ef557756bf70a8e5d0b8ed fluxheim-1.6.35-full-x86_64-linux.tar.gzc52ba34cbeee85b8f553f45f5a7de0fc12fcf1e976a8e078b3cabecca49a48e2 fluxheim-1.6.35-cache-x86_64-linux.tar.gzcb8b46c18b29468407b10c5ace693e092fe88f2a55666569d87c125e673affb0 fluxheim-1.6.35-proxy-x86_64-linux.tar.gz39da8968439ec10a8a9cb579a268338e25c2d3f92d5be6359fd9f02d3a80285b fluxheim-1.6.35-php-x86_64-linux.tar.gz9541d9a78c8c3abc9402483dec9970fb2293a285cdab2364517f4f83c1e0c480 fluxheim-1.6.35-load-balancer-x86_64-linux.tar.gzea76e0ed84929d392967d3e88a2540504a6f67e5366bcd6d779430c3741cc00e fluxheim-1.6.35-config-tester-x86_64-linux.tar.gz84276a98a971a0b4bb546d295a5acf70b314706fa08f75a40327d1e4e40bfeb4 fluxheim-1.6.35-full-aarch64-linux.tar.gz9504df2b2e6ee8a7dcf15db827ec7b0c4ca7d0c8f52c0d6948fa0391a931733a fluxheim-1.6.35-cache-aarch64-linux.tar.gz1a39f518765579436795fa24bac6844d437c9ee56f367e04a35504b9fe4f1052 fluxheim-1.6.35-proxy-aarch64-linux.tar.gza5a71567a0099ae79c1d993017f02f9b6506e79b3fb01d47fb9f201e2481e37e fluxheim-1.6.35-php-aarch64-linux.tar.gz9049820f0f43bb8241c3de2d8967e4370da5a0da92769ed9d617a7c8b7fcaa73 fluxheim-1.6.35-load-balancer-aarch64-linux.tar.gzdff3684fa6433705319bad9f8b33622ab05eb03c368b5f0861f5acccb46a73d4 fluxheim-1.6.35-config-tester-aarch64-linux.tar.gzdfa84545737fc151d8350c6508a60d35a17aa5eebd8e764ebe0fb59a868ec572 fluxheim-1.6.35-dev-aarch64-macos.tar.gz04e812f1f00318cf52b10d547a7527f93483a1d7d50e5c795efc6ab7b753c097 fluxheim.spdx.jsond4a9d74193fd2d5b9fbb8c81cf3b8f201abca3cb50a0a8a61070946c8160576e fluxheim.cyclonedx.json5325d2a4022b2414aeaa4c7db4f9c15e4188d4642c5b8b318316d4834ba4147dx86_649dc8efb9ef09076f21e71c1f54cf2ebfd89525f0184912f609de11bcd61de98faarch64c028258f99a1ab95e78269b28f40027b6fd71b3a1f9678d622006dd602e6b7dcmacosghcr.io/valkyoth/fluxheim@sha256:8dbbeec3dcf1a651d183b105ddcd79406e190528acc9d5a38fc9bcb69902fe54ghcr.io/valkyoth/fluxheim@sha256:6eaae5520e18b85e740c2dcbdb097875cc03765238dd7f7a819ae36dd4bbf3d4ghcr.io/valkyoth/fluxheim@sha256:79dba6f376a054e8125444e0367514adf51cd7d4ac6778e3a14ae2175f7c769eghcr.io/valkyoth/fluxheim@sha256:6439f2ba2d4ceb770d0b7040916977204e4a9ca6d2b08daadb034fe657b0ecffghcr.io/valkyoth/fluxheim@sha256:dd2291e8aa0d28221b50f254c2ce8ae3d68bfeb8ababf517584bb75534e5bbe1ghcr.io/valkyoth/fluxheim@sha256:a036b46063968f958816c53737ddac3c312b004a30fe9119c16ee8c2dbc36c85ghcr.io/valkyoth/fluxheim@sha256:cd4765c78ee8354c70574838fab7cb306866132051c384ae34e8494b18b60b91ghcr.io/valkyoth/fluxheim@sha256:2549e3d8da159bbb5f07f080c7470771c56c15b22a59d42979fa4c1c9246c77eghcr.io/valkyoth/fluxheim@sha256:04794d8dec53c8ca83b26aae46b51b2d3c55d75935f0a52738942d530dea01e0ghcr.io/valkyoth/fluxheim@sha256:468a7f659d8ba827fbf9023d264631c14c1f18202b1495caee7b9c409b51ab70ghcr.io/valkyoth/fluxheim@sha256:3b1c872df58a273ac815e47ba810278d9c28ac907053e222f65b3df7539b3fe7ghcr.io/valkyoth/fluxheim@sha256:735d08a9f47f30993d056c68587a1d5be62a439030f17e97a9d2fe7f3a70ea9aghcr.io/valkyoth/fluxheim@sha256:bf685a76b71b94ca032def9168be0d566883a74d5c1a28d2e33d7b138200f43fghcr.io/valkyoth/fluxheim@sha256:3833b70d1b061d6986f46c0512484e036b05024bd7f3dce3082b16d9002557faghcr.io/valkyoth/fluxheim@sha256:4bd080455de5eea25e9ac09a365481d20ce0511574d2acc9c88605d419090bdcghcr.io/valkyoth/fluxheim@sha256:14f387191aff862869886640c5daab599fa93fefe546954560c1c8ad2ca837e8ghcr.io/valkyoth/fluxheim@sha256:0a6de1c407467a2ab57b8073bd49f0facb1de0c09894aee6f37ee400ab140726ghcr.io/valkyoth/fluxheim@sha256:915d2e8103c99e92bc4810e2bd931fb6271c1e391c38f88f834dc7485bba841bghcr.io/valkyoth/fluxheim@sha256:40e7f24f21ce5b3da9229e19708daf59860151d4424c36147dfd6b156c7a56beghcr.io/valkyoth/fluxheim@sha256:38371dba542beadda826aa11cb90bd2444278b951f73980b34932e56bdf544d6Good "git" signature for 1921261+eldryoth@users.noreply.github.com with ED25519 key SHA256:EoLRQ5k4J5pYz3UMFmkrV798gYFNkToGS2xEPvebqB4This discussion was created from the release Fluxheim 1.6.35.
All reactions