Releases: zzmzm/tiyi
Release list
Tiyi v3.8.0
Tiyi v3.8.0
Released on 2026-09-22. / 发布日期:2026-09-22。
Upgrade boundary / 升级边界
Fresh state is required. v3.7.2 and earlier state cannot be reused. Back up
the complete installation and matching binary, rebuild the Controller with
empty state, recreate reviewed configuration, and re-enroll every remote Agent
with the same v3.8.0 build. Earlier development snapshots are not a supported
upgrade source. Never restore old databases, metrics, identities, spools or
cached bundles into the new live paths. A binary replacement and restart alone
is insufficient. Keep the old binary and complete archive together for rollback.
必须使用全新状态,不能复用 v3.7.2 及更早版本的状态。 先备份完整安装及匹配的
旧二进制,再以空状态重建 Controller、恢复经审核的配置,并用同一 v3.8.0 构建
重新注册全部远端 Agent。早期开发快照也不属于支持的升级来源。不能把旧数据库、
指标、身份、spool 或配置缓存放入新版本运行目录,也不能只替换二进制后重启。
旧二进制与完整备份必须成套保留,以便回滚。
Follow the English migration guide
or 中文迁移指南.
Highlights
- API Assets combines observed endpoints, explicit catalog membership and
reviewed OpenAPI 3.0/3.1/3.2 or Swagger 2.0 documents. Review mappings,
edit definitions and publish or restore a revision with serving-node results. - Per-endpoint Off/Observe/Enforce validates supported request structures and
types. Unlisted requests have a separate scoped action; unsupported Schema
semantics are reported. This is not full JSON Schema or business authorization. - Bounded JSON learning records structures and counts without field values.
Review versions and export an OpenAPI draft; learning never enables blocking. - Site policy owns body/upload capacity, with native multipart handling,
independent file/field limits and preserved origin request bytes. Light
continues blocking attacks while observing ordinary argument/body-size excess. - Security overview, enforcement decisions and threshold alerts use counters
collected before log sampling. Event Analysis keeps sampled relationship
investigation. Coverage loss is explicit; missing evidence is not zero traffic. - IP enforcement and automatic remediation retain the selected site, time,
attack type and severity scope. Quick actions expose save/application results,
retry and withdrawal; remote-node results still require verification. - Shared protection responses cover six terminal scenarios with configurable
status, titles/messages and HTML/JSON/text/XML formats. Operators can give
visitors a request ID without exposing internal rule or policy details. - Console session recovery, bounded diagnostic output and health probes isolate
slow dependencies. Read queries and the state writer have separate capacity;
configuration publication and investigation avoid unnecessary writer locks. - Node installation commands, DNS retry/renewal, upstream health, account/session
safeguards, settings drafts, audit verification and notification editing show
current results and actionable recovery. Public EN/zh task guides include
copyable templates and complete CLI/API references.
主要变化
- API 资产统一管理已观测接口、显式清单和经审核的 OpenAPI 3.0/3.1/3.2、Swagger 2.0
文档;支持映射审核、定义编辑、发布与历史恢复,并查看实际服务节点结果。 - 接口可选择不校验、仅观察、强制校验支持的请求结构与类型;范围内未纳入请求
有独立动作。不支持的 Schema 语义明确报告,不宣称完整 JSON Schema 或业务鉴权。 - JSON 自动学习只记录有限的结构和计数,不保留字段值;审核版本后可导出
OpenAPI 草稿,不会自动开启拦截。 - 站点策略统一管理正文与上传容量;原生 multipart 处理、独立文件/字段限制
保留送往源站的请求字节。Light 保持攻击拦截,普通参数/正文大小超限默认观察。 - 概览、执行决策与阈值告警使用日志采样前计数;事件分析继续提供采样关系调查。
覆盖缺口明确展示,没有证据不等于没有流量。 - IP 执行与自动处置保留站点、时间、攻击类型和严重程度范围;快捷动作提供保存/
应用结果、重试与撤销,远端实际生效仍需核对节点结果。 - 六类终止场景共用防护响应配置,可设置状态、标题、消息和 HTML/JSON/text/XML
格式,向访客提供请求 ID,并保留内部规则和策略详情的访问边界。 - 会话恢复、有界诊断输出及健康探测隔离慢依赖;状态读取与写入容量分离,
配置发布和调查查询减少不必要的写锁争用。 - 节点安装、DNS 重试续期、源站健康、账户会话保护、设置草稿、审计与通知编辑
展示实际状态和恢复动作。中英文任务文档提供完整模板及 CLI/API 参数参考。
Verify after installation / 安装后验证
Check version and system health, then verify routing, HTTPS, benign traffic,
controlled WAF blocks, and the applied configuration on every serving node.
Schema observe/enforce probes must cover both valid and invalid requests.
The admin UI requires ES2020 and native BigInt support. Linux amd64 and arm64
packages include signed binaries, checksums, signatures and release metadata.
核对版本、系统健康,以及每个服务节点的路由、HTTPS、正常请求、防护拦截和配置
结果;Schema 观察/强制校验要覆盖有效与无效请求。管理浏览器需支持 ES2020 和
原生 BigInt。Linux amd64、arm64 安装包包含签名二进制、校验和、签名及发布元数据。
Tiyi v3.7.2
Tiyi v3.7.2. Verify downloads against SHA256SUMS and SHA256SUMS.sig using release-key.pub (Ed25519). Install: curl -fsSL https://raw.githubusercontent.com/zzmzm/tiyi/main/install.sh | bash
Tiyi v3.7.1
Tiyi v3.7.1. Verify downloads against SHA256SUMS and SHA256SUMS.sig using release-key.pub (Ed25519). Install: curl -fsSL https://raw.githubusercontent.com/zzmzm/tiyi/main/install.sh | bash
Tiyi v3.7.0
Tiyi v3.7.0. Verify downloads against SHA256SUMS and SHA256SUMS.sig using release-key.pub (Ed25519). Install: curl -fsSL https://raw.githubusercontent.com/zzmzm/tiyi/main/install.sh | bash
Tiyi v3.6.0
Tiyi v3.6.0. Verify downloads against SHA256SUMS and SHA256SUMS.sig using release-key.pub (Ed25519). Install: curl -fsSL https://raw.githubusercontent.com/zzmzm/tiyi/main/install.sh | bash
Tiyi v3.5.4
Tiyi v3.5.4. Verify downloads against SHA256SUMS and SHA256SUMS.sig using release-key.pub (Ed25519). Install: curl -fsSL https://raw.githubusercontent.com/zzmzm/tiyi/main/install.sh | bash
Tiyi v3.5.3
Tiyi v3.5.3. Verify downloads against SHA256SUMS and SHA256SUMS.sig using release-key.pub (Ed25519). Install: curl -fsSL https://raw.githubusercontent.com/zzmzm/tiyi/main/install.sh | bash
Tiyi v3.5.2
Tiyi v3.5.2. Verify downloads against SHA256SUMS and SHA256SUMS.sig using release-key.pub (Ed25519). Install: curl -fsSL https://raw.githubusercontent.com/zzmzm/tiyi/main/install.sh | bash
Tiyi v3.5.1
Tiyi v3.5.1. Verify downloads against SHA256SUMS and SHA256SUMS.sig using release-key.pub (Ed25519). Install: curl -fsSL https://raw.githubusercontent.com/zzmzm/tiyi/main/install.sh | bash
Tiyi v3.5.0
Tiyi v3.5.0. Verify downloads against SHA256SUMS and SHA256SUMS.sig using release-key.pub (Ed25519). Install: curl -fsSL https://raw.githubusercontent.com/zzmzm/tiyi/main/install.sh | bash