You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository was archived by the owner on May 20, 2026. It is now read-only.
OpenID Connect 1.0 client registrations incorrectly allowed none as a authorization_signed_response_alg value, this is no longer the case and if you specified this value you'll have to either remove it or update it to the new correct default of RS256.
Bug Fixes
commands: missing header list header (#9956) (6a31393)
configuration: healthchecks for unix are unhealthy (#9988) (76e0702)
Important Note: The v4.39.2 release inadvertently removed the legacy OpenID Connect 1.0 endpoints which have not been documented at least in the last 3 years either at the discovery document or on the website. While these changes were technically unintentional right at this moment they were going to be hard removed at some point before we graduated OpenID Connect 1.0 out of a experimental/beta state and users had previously been notified of this change, as such we're going to leave them as is. Users should refer to our documentation as well as their instances discovery endpoints to obtain the correct URLs. The URLs that potentially may need updating are as follows: the URL /api/oidc/jwks previously handled requests for the JSON Web Key Set Endpoint, the URL /api/oidc/authorize previously also handled requests for the Authorization Endpoint, the URL /api/oidc/introspect previously also handled requests for the Introspection Endpoint, and the URL /api/oidc/revoke previously also handled requests for the Revocation Endpoint.
Important Note: The v4.39.2 release inadvertently removed the legacy OpenID Connect 1.0 endpoints which have not been documented in the last 3 years either at the discovery document or on the website. While these changes were technically unintentional right at this moment they were going to be hard removed at some point before we graduated OpenID Connect 1.0 out of a experimental/beta state, as such we're going to leave them as is. Users should refer to our documentation as well as their instances discovery endpoints to obtain the correct URLs.
Please see the Authelia Blog: 4.39 Release Notes for human readable summaries of the changes. It's important to note some critical changes have occurred in this release that warrant some user attention.
terraform
Running plan in HCP Terraform. Output will stream here. Pressing Ctrl-C
will stop streaming the logs, but will not stop the plan running remotely.
Preparing the remote plan...
The remote workspace is configured to work with configuration at
infra relative to the target repository.
Terraform will upload the contents of the following directory,
excluding files or directories as defined by a .terraformignore file
at /home/runner/work/private_server/private_server/.terraformignore (if it is present),
in order to capture the filesystem context the remote workspace expects:
/home/runner/work/private_server/private_server
To view this run in a browser, visit:
https://app.terraform.io/app/redline/private_server/runs/run-H1hkMyb7P7D6mkBy
Waiting for the plan to start...
Terraform v1.3.2
on linux_amd64
Initializing plugins and modules...
hcloud_ssh_key.ansible: Refreshing state... [id=8957821]
hcloud_firewall.web_firewall: Refreshing state... [id=603891]
cloudflare_zone.personal_domain: Refreshing state... [id=cee2af2644f6a3325416173e2d4b44f7]
cloudflare_record.aliases["traefik"]: Refreshing state... [id=efbdd0b7c842cec43a43af72a450fcc0]
cloudflare_record.aliases["grocy"]: Refreshing state... [id=1a98a4348007c72461ab6752f2c7f9df]
cloudflare_record.aliases["grafana"]: Refreshing state... [id=a63efd438a1e819f0e4215e4835a0f24]
cloudflare_record.aliases["ldap"]: Refreshing state... [id=416e67a40f89597f342029d943e253ed]
cloudflare_record.aliases["photoprism"]: Refreshing state... [id=6c61639959eeaf8d547dd411419bcf9a]
cloudflare_record.aliases["auth"]: Refreshing state... [id=59a6c353a0138b64113ad34f046c17dc]
hcloud_server.web: Refreshing state... [id=51760523]
hcloud_volume.data: Refreshing state... [id=24743811]
hcloud_firewall_attachment.firewall_assignments: Refreshing state... [id=603891]
cloudflare_record.a: Refreshing state... [id=a44b3519c0443db244e9f2dc5bba8a91]
cloudflare_record.aaaa: Refreshing state... [id=1f54f8a3794295291a1b5a18ed363416]
hcloud_server.web: Drift detected (update)
cloudflare_record.a: Drift detected (update)
cloudflare_record.aaaa: Drift detected (update)
cloudflare_record.aliases["photoprism"]: Drift detected (update)
cloudflare_record.aliases["traefik"]: Drift detected (update)
cloudflare_record.aliases["auth"]: Drift detected (update)
cloudflare_record.aliases["grafana"]: Drift detected (update)
cloudflare_record.aliases["grocy"]: Drift detected (update)
cloudflare_record.aliases["ldap"]: Drift detected (update)
hcloud_firewall.web_firewall: Drift detected (update)
No changes. Your infrastructure matches the configuration.
Terraform has compared your real infrastructure against your configuration
and found no differences, so no changes are needed.
─────────────────────────────────────────────────────────────────────────────
Note: You didn't use the -out option to save this plan, so Terraform can't
guarantee to take exactly these actions if you run "terraform apply" now.
renovateBot
changed the title
chore(deps): update authelia/authelia docker tag to v4.39.1
chore(deps): update authelia/authelia docker tag to v4.39.2
May 10, 2025
terraform
Running plan in HCP Terraform. Output will stream here. Pressing Ctrl-C
will stop streaming the logs, but will not stop the plan running remotely.
Preparing the remote plan...
The remote workspace is configured to work with configuration at
infra relative to the target repository.
Terraform will upload the contents of the following directory,
excluding files or directories as defined by a .terraformignore file
at /home/runner/work/private_server/private_server/.terraformignore (if it is present),
in order to capture the filesystem context the remote workspace expects:
/home/runner/work/private_server/private_server
To view this run in a browser, visit:
https://app.terraform.io/app/redline/private_server/runs/run-KFiDncjrwNgF71mh
Waiting for the plan to start...
Terraform v1.3.2
on linux_amd64
Initializing plugins and modules...
cloudflare_zone.personal_domain: Refreshing state... [id=cee2af2644f6a3325416173e2d4b44f7]
hcloud_ssh_key.ansible: Refreshing state... [id=8957821]
hcloud_firewall.web_firewall: Refreshing state... [id=603891]
cloudflare_record.aliases["grocy"]: Refreshing state... [id=1a98a4348007c72461ab6752f2c7f9df]
cloudflare_record.aliases["ldap"]: Refreshing state... [id=416e67a40f89597f342029d943e253ed]
cloudflare_record.aliases["photoprism"]: Refreshing state... [id=6c61639959eeaf8d547dd411419bcf9a]
cloudflare_record.aliases["auth"]: Refreshing state... [id=59a6c353a0138b64113ad34f046c17dc]
cloudflare_record.aliases["traefik"]: Refreshing state... [id=efbdd0b7c842cec43a43af72a450fcc0]
cloudflare_record.aliases["grafana"]: Refreshing state... [id=a63efd438a1e819f0e4215e4835a0f24]
hcloud_server.web: Refreshing state... [id=51760523]
hcloud_firewall_attachment.firewall_assignments: Refreshing state... [id=603891]
hcloud_volume.data: Refreshing state... [id=24743811]
cloudflare_record.aaaa: Refreshing state... [id=1f54f8a3794295291a1b5a18ed363416]
cloudflare_record.a: Refreshing state... [id=a44b3519c0443db244e9f2dc5bba8a91]
cloudflare_record.aliases["grocy"]: Drift detected (update)
cloudflare_record.aliases["ldap"]: Drift detected (update)
cloudflare_record.aliases["photoprism"]: Drift detected (update)
cloudflare_record.aliases["traefik"]: Drift detected (update)
cloudflare_record.aliases["auth"]: Drift detected (update)
cloudflare_record.aliases["grafana"]: Drift detected (update)
cloudflare_record.aaaa: Drift detected (update)
hcloud_firewall.web_firewall: Drift detected (update)
hcloud_server.web: Drift detected (update)
cloudflare_record.a: Drift detected (update)
No changes. Your infrastructure matches the configuration.
Terraform has compared your real infrastructure against your configuration
and found no differences, so no changes are needed.
─────────────────────────────────────────────────────────────────────────────
Note: You didn't use the -out option to save this plan, so Terraform can't
guarantee to take exactly these actions if you run "terraform apply" now.
renovateBot
changed the title
chore(deps): update authelia/authelia docker tag to v4.39.2
chore(deps): update authelia/authelia docker tag to v4.39.3
May 11, 2025
terraform
Running plan in HCP Terraform. Output will stream here. Pressing Ctrl-C
will stop streaming the logs, but will not stop the plan running remotely.
Preparing the remote plan...
The remote workspace is configured to work with configuration at
infra relative to the target repository.
Terraform will upload the contents of the following directory,
excluding files or directories as defined by a .terraformignore file
at /home/runner/work/private_server/private_server/.terraformignore (if it is present),
in order to capture the filesystem context the remote workspace expects:
/home/runner/work/private_server/private_server
To view this run in a browser, visit:
https://app.terraform.io/app/redline/private_server/runs/run-yAGjgsQ3e2N8CoJu
Waiting for the plan to start...
Terraform v1.3.2
on linux_amd64
Initializing plugins and modules...
hcloud_ssh_key.ansible: Refreshing state... [id=8957821]
hcloud_firewall.web_firewall: Refreshing state... [id=603891]
cloudflare_zone.personal_domain: Refreshing state... [id=cee2af2644f6a3325416173e2d4b44f7]
cloudflare_record.aliases["photoprism"]: Refreshing state... [id=6c61639959eeaf8d547dd411419bcf9a]
cloudflare_record.aliases["ldap"]: Refreshing state... [id=416e67a40f89597f342029d943e253ed]
cloudflare_record.aliases["auth"]: Refreshing state... [id=59a6c353a0138b64113ad34f046c17dc]
cloudflare_record.aliases["grafana"]: Refreshing state... [id=a63efd438a1e819f0e4215e4835a0f24]
cloudflare_record.aliases["grocy"]: Refreshing state... [id=1a98a4348007c72461ab6752f2c7f9df]
cloudflare_record.aliases["traefik"]: Refreshing state... [id=efbdd0b7c842cec43a43af72a450fcc0]
hcloud_server.web: Refreshing state... [id=51760523]
hcloud_volume.data: Refreshing state... [id=24743811]
hcloud_firewall_attachment.firewall_assignments: Refreshing state... [id=603891]
cloudflare_record.aaaa: Refreshing state... [id=1f54f8a3794295291a1b5a18ed363416]
cloudflare_record.a: Refreshing state... [id=a44b3519c0443db244e9f2dc5bba8a91]
cloudflare_record.aliases["ldap"]: Drift detected (update)
cloudflare_record.aliases["photoprism"]: Drift detected (update)
cloudflare_record.aliases["traefik"]: Drift detected (update)
cloudflare_record.aliases["auth"]: Drift detected (update)
cloudflare_record.aliases["grafana"]: Drift detected (update)
cloudflare_record.aliases["grocy"]: Drift detected (update)
hcloud_firewall.web_firewall: Drift detected (update)
cloudflare_record.aaaa: Drift detected (update)
hcloud_server.web: Drift detected (update)
cloudflare_record.a: Drift detected (update)
No changes. Your infrastructure matches the configuration.
Terraform has compared your real infrastructure against your configuration
and found no differences, so no changes are needed.
─────────────────────────────────────────────────────────────────────────────
Note: You didn't use the -out option to save this plan, so Terraform can't
guarantee to take exactly these actions if you run "terraform apply" now.
renovateBot
changed the title
chore(deps): update authelia/authelia docker tag to v4.39.3
chore(deps): update authelia/authelia docker tag to v4.39.4
May 25, 2025
terraform
Running plan in HCP Terraform. Output will stream here. Pressing Ctrl-C
will stop streaming the logs, but will not stop the plan running remotely.
Preparing the remote plan...
The remote workspace is configured to work with configuration at
infra relative to the target repository.
Terraform will upload the contents of the following directory,
excluding files or directories as defined by a .terraformignore file
at /home/runner/work/private_server/private_server/.terraformignore (if it is present),
in order to capture the filesystem context the remote workspace expects:
/home/runner/work/private_server/private_server
To view this run in a browser, visit:
https://app.terraform.io/app/redline/private_server/runs/run-zBYXboNezfvySQMC
Waiting for the plan to start...
Terraform v1.3.2
on linux_amd64
Initializing plugins and modules...
cloudflare_zone.personal_domain: Refreshing state... [id=cee2af2644f6a3325416173e2d4b44f7]
hcloud_ssh_key.ansible: Refreshing state... [id=8957821]
hcloud_firewall.web_firewall: Refreshing state... [id=603891]
cloudflare_record.aliases["grocy"]: Refreshing state... [id=1a98a4348007c72461ab6752f2c7f9df]
cloudflare_record.aliases["auth"]: Refreshing state... [id=59a6c353a0138b64113ad34f046c17dc]
cloudflare_record.aliases["grafana"]: Refreshing state... [id=a63efd438a1e819f0e4215e4835a0f24]
cloudflare_record.aliases["ldap"]: Refreshing state... [id=416e67a40f89597f342029d943e253ed]
cloudflare_record.aliases["photoprism"]: Refreshing state... [id=6c61639959eeaf8d547dd411419bcf9a]
cloudflare_record.aliases["traefik"]: Refreshing state... [id=efbdd0b7c842cec43a43af72a450fcc0]
hcloud_server.web: Refreshing state... [id=51760523]
hcloud_volume.data: Refreshing state... [id=24743811]
hcloud_firewall_attachment.firewall_assignments: Refreshing state... [id=603891]
cloudflare_record.aaaa: Refreshing state... [id=1f54f8a3794295291a1b5a18ed363416]
cloudflare_record.a: Refreshing state... [id=a44b3519c0443db244e9f2dc5bba8a91]
cloudflare_record.aliases["traefik"]: Drift detected (update)
cloudflare_record.aliases["auth"]: Drift detected (update)
cloudflare_record.aliases["grafana"]: Drift detected (update)
cloudflare_record.aliases["grocy"]: Drift detected (update)
cloudflare_record.aliases["ldap"]: Drift detected (update)
cloudflare_record.aliases["photoprism"]: Drift detected (update)
hcloud_server.web: Drift detected (update)
hcloud_firewall.web_firewall: Drift detected (update)
cloudflare_record.a: Drift detected (update)
cloudflare_record.aaaa: Drift detected (update)
No changes. Your infrastructure matches the configuration.
Terraform has compared your real infrastructure against your configuration
and found no differences, so no changes are needed.
─────────────────────────────────────────────────────────────────────────────
Note: You didn't use the -out option to save this plan, so Terraform can't
guarantee to take exactly these actions if you run "terraform apply" now.
renovateBot
changed the title
chore(deps): update authelia/authelia docker tag to v4.39.4
chore(deps): update authelia/authelia docker tag to v4.39.5
Jul 13, 2025
terraform
Running plan in HCP Terraform. Output will stream here. Pressing Ctrl-C
will stop streaming the logs, but will not stop the plan running remotely.
Preparing the remote plan...
The remote workspace is configured to work with configuration at
infra relative to the target repository.
Terraform will upload the contents of the following directory,
excluding files or directories as defined by a .terraformignore file
at /home/runner/work/private_server/private_server/.terraformignore (if it is present),
in order to capture the filesystem context the remote workspace expects:
/home/runner/work/private_server/private_server
To view this run in a browser, visit:
https://app.terraform.io/app/redline/private_server/runs/run-bCLMkKgJgAk9aJ3L
Waiting for the plan to start...
Terraform v1.3.2
on linux_amd64
Initializing plugins and modules...
cloudflare_zone.personal_domain: Refreshing state... [id=cee2af2644f6a3325416173e2d4b44f7]
hcloud_ssh_key.ansible: Refreshing state... [id=8957821]
hcloud_firewall.web_firewall: Refreshing state... [id=603891]
cloudflare_record.aliases["photoprism"]: Refreshing state... [id=6c61639959eeaf8d547dd411419bcf9a]
cloudflare_record.aliases["grocy"]: Refreshing state... [id=1a98a4348007c72461ab6752f2c7f9df]
cloudflare_record.aliases["grafana"]: Refreshing state... [id=a63efd438a1e819f0e4215e4835a0f24]
cloudflare_record.aliases["ldap"]: Refreshing state... [id=416e67a40f89597f342029d943e253ed]
cloudflare_record.aliases["traefik"]: Refreshing state... [id=efbdd0b7c842cec43a43af72a450fcc0]
cloudflare_record.aliases["auth"]: Refreshing state... [id=59a6c353a0138b64113ad34f046c17dc]
hcloud_server.web: Refreshing state... [id=51760523]
hcloud_firewall_attachment.firewall_assignments: Refreshing state... [id=603891]
hcloud_volume.data: Refreshing state... [id=24743811]
cloudflare_record.a: Refreshing state... [id=a44b3519c0443db244e9f2dc5bba8a91]
cloudflare_record.aaaa: Refreshing state... [id=1f54f8a3794295291a1b5a18ed363416]
cloudflare_record.a: Drift detected (update)
cloudflare_record.aaaa: Drift detected (update)
cloudflare_record.aliases["photoprism"]: Drift detected (update)
cloudflare_record.aliases["traefik"]: Drift detected (update)
cloudflare_record.aliases["auth"]: Drift detected (update)
cloudflare_record.aliases["grafana"]: Drift detected (update)
cloudflare_record.aliases["grocy"]: Drift detected (update)
cloudflare_record.aliases["ldap"]: Drift detected (update)
hcloud_firewall.web_firewall: Drift detected (update)
hcloud_server.web: Drift detected (update)
No changes. Your infrastructure matches the configuration.
Terraform has compared your real infrastructure against your configuration
and found no differences, so no changes are needed.
─────────────────────────────────────────────────────────────────────────────
Note: You didn't use the -out option to save this plan, so Terraform can't
guarantee to take exactly these actions if you run "terraform apply" now.
renovateBot
changed the title
chore(deps): update authelia/authelia docker tag to v4.39.5
chore(deps): update authelia/authelia docker tag to v4.39.6
Aug 9, 2025
terraform
Running plan in HCP Terraform. Output will stream here. Pressing Ctrl-C
will stop streaming the logs, but will not stop the plan running remotely.
Preparing the remote plan...
The remote workspace is configured to work with configuration at
infra relative to the target repository.
Terraform will upload the contents of the following directory,
excluding files or directories as defined by a .terraformignore file
at /home/runner/work/private_server/private_server/.terraformignore (if it is present),
in order to capture the filesystem context the remote workspace expects:
/home/runner/work/private_server/private_server
To view this run in a browser, visit:
https://app.terraform.io/app/redline/private_server/runs/run-RgtayauE8m3w31gq
Waiting for the plan to start...
Terraform v1.3.2
on linux_amd64
Initializing plugins and modules...
cloudflare_zone.personal_domain: Refreshing state... [id=cee2af2644f6a3325416173e2d4b44f7]
hcloud_ssh_key.ansible: Refreshing state... [id=8957821]
hcloud_firewall.web_firewall: Refreshing state... [id=603891]
cloudflare_record.aliases["auth"]: Refreshing state... [id=59a6c353a0138b64113ad34f046c17dc]
cloudflare_record.aliases["photoprism"]: Refreshing state... [id=6c61639959eeaf8d547dd411419bcf9a]
cloudflare_record.aliases["ldap"]: Refreshing state... [id=416e67a40f89597f342029d943e253ed]
cloudflare_record.aliases["traefik"]: Refreshing state... [id=efbdd0b7c842cec43a43af72a450fcc0]
cloudflare_record.aliases["grafana"]: Refreshing state... [id=a63efd438a1e819f0e4215e4835a0f24]
cloudflare_record.aliases["grocy"]: Refreshing state... [id=1a98a4348007c72461ab6752f2c7f9df]
hcloud_server.web: Refreshing state... [id=51760523]
hcloud_firewall_attachment.firewall_assignments: Refreshing state... [id=603891]
hcloud_volume.data: Refreshing state... [id=24743811]
cloudflare_record.a: Refreshing state... [id=a44b3519c0443db244e9f2dc5bba8a91]
cloudflare_record.aaaa: Refreshing state... [id=1f54f8a3794295291a1b5a18ed363416]
cloudflare_record.aaaa: Drift detected (update)
cloudflare_record.aliases["grafana"]: Drift detected (update)
cloudflare_record.aliases["grocy"]: Drift detected (update)
cloudflare_record.aliases["ldap"]: Drift detected (update)
cloudflare_record.aliases["photoprism"]: Drift detected (update)
cloudflare_record.aliases["traefik"]: Drift detected (update)
cloudflare_record.aliases["auth"]: Drift detected (update)
hcloud_firewall.web_firewall: Drift detected (update)
cloudflare_record.a: Drift detected (update)
hcloud_server.web: Drift detected (update)
No changes. Your infrastructure matches the configuration.
Terraform has compared your real infrastructure against your configuration
and found no differences, so no changes are needed.
─────────────────────────────────────────────────────────────────────────────
Note: You didn't use the -out option to save this plan, so Terraform can't
guarantee to take exactly these actions if you run "terraform apply" now.
renovateBot
changed the title
chore(deps): update authelia/authelia docker tag to v4.39.6
chore(deps): update authelia/authelia docker tag to v4.39.7
Aug 31, 2025
terraform
Running plan in HCP Terraform. Output will stream here. Pressing Ctrl-C
will stop streaming the logs, but will not stop the plan running remotely.
Preparing the remote plan...
The remote workspace is configured to work with configuration at
infra relative to the target repository.
Terraform will upload the contents of the following directory,
excluding files or directories as defined by a .terraformignore file
at /home/runner/work/private_server/private_server/.terraformignore (if it is present),
in order to capture the filesystem context the remote workspace expects:
/home/runner/work/private_server/private_server
To view this run in a browser, visit:
https://app.terraform.io/app/redline/private_server/runs/run-Z3KYVDTALfue8FEY
Waiting for the plan to start...
Terraform v1.3.2
on linux_amd64
Initializing plugins and modules...
hcloud_ssh_key.ansible: Refreshing state... [id=8957821]
hcloud_firewall.web_firewall: Refreshing state... [id=603891]
cloudflare_zone.personal_domain: Refreshing state... [id=cee2af2644f6a3325416173e2d4b44f7]
cloudflare_record.aliases["grocy"]: Refreshing state... [id=1a98a4348007c72461ab6752f2c7f9df]
cloudflare_record.aliases["photoprism"]: Refreshing state... [id=6c61639959eeaf8d547dd411419bcf9a]
cloudflare_record.aliases["grafana"]: Refreshing state... [id=a63efd438a1e819f0e4215e4835a0f24]
cloudflare_record.aliases["auth"]: Refreshing state... [id=59a6c353a0138b64113ad34f046c17dc]
cloudflare_record.aliases["ldap"]: Refreshing state... [id=416e67a40f89597f342029d943e253ed]
cloudflare_record.aliases["traefik"]: Refreshing state... [id=efbdd0b7c842cec43a43af72a450fcc0]
hcloud_server.web: Refreshing state... [id=51760523]
hcloud_firewall_attachment.firewall_assignments: Refreshing state... [id=603891]
hcloud_volume.data: Refreshing state... [id=24743811]
cloudflare_record.a: Refreshing state... [id=a44b3519c0443db244e9f2dc5bba8a91]
cloudflare_record.aaaa: Refreshing state... [id=1f54f8a3794295291a1b5a18ed363416]
hcloud_server.web: Drift detected (update)
cloudflare_record.aaaa: Drift detected (update)
cloudflare_record.aliases["grocy"]: Drift detected (update)
cloudflare_record.aliases["ldap"]: Drift detected (update)
cloudflare_record.aliases["photoprism"]: Drift detected (update)
cloudflare_record.aliases["traefik"]: Drift detected (update)
cloudflare_record.aliases["auth"]: Drift detected (update)
cloudflare_record.aliases["grafana"]: Drift detected (update)
cloudflare_record.a: Drift detected (update)
hcloud_firewall.web_firewall: Drift detected (update)
No changes. Your infrastructure matches the configuration.
Terraform has compared your real infrastructure against your configuration
and found no differences, so no changes are needed.
─────────────────────────────────────────────────────────────────────────────
Note: You didn't use the -out option to save this plan, so Terraform can't
guarantee to take exactly these actions if you run "terraform apply" now.
terraform
Running plan in HCP Terraform. Output will stream here. Pressing Ctrl-C
will stop streaming the logs, but will not stop the plan running remotely.
Preparing the remote plan...
The remote workspace is configured to work with configuration at
infra relative to the target repository.
Terraform will upload the contents of the following directory,
excluding files or directories as defined by a .terraformignore file
at /home/runner/work/private_server/private_server/.terraformignore (if it is present),
in order to capture the filesystem context the remote workspace expects:
/home/runner/work/private_server/private_server
To view this run in a browser, visit:
https://app.terraform.io/app/redline/private_server/runs/run-kTpVKq9oKNPjVwug
Waiting for the plan to start...
Terraform v1.3.2
on linux_amd64
Initializing plugins and modules...
cloudflare_zone.personal_domain: Refreshing state... [id=cee2af2644f6a3325416173e2d4b44f7]
hcloud_ssh_key.ansible: Refreshing state... [id=8957821]
hcloud_firewall.web_firewall: Refreshing state... [id=603891]
cloudflare_record.aliases["traefik"]: Refreshing state... [id=efbdd0b7c842cec43a43af72a450fcc0]
cloudflare_record.aliases["ldap"]: Refreshing state... [id=416e67a40f89597f342029d943e253ed]
cloudflare_record.aliases["grafana"]: Refreshing state... [id=a63efd438a1e819f0e4215e4835a0f24]
cloudflare_record.aliases["grocy"]: Refreshing state... [id=1a98a4348007c72461ab6752f2c7f9df]
cloudflare_record.aliases["auth"]: Refreshing state... [id=59a6c353a0138b64113ad34f046c17dc]
cloudflare_record.aliases["photoprism"]: Refreshing state... [id=6c61639959eeaf8d547dd411419bcf9a]
hcloud_server.web: Refreshing state... [id=51760523]
hcloud_firewall_attachment.firewall_assignments: Refreshing state... [id=603891]
hcloud_volume.data: Refreshing state... [id=24743811]
cloudflare_record.a: Refreshing state... [id=a44b3519c0443db244e9f2dc5bba8a91]
cloudflare_record.aaaa: Refreshing state... [id=1f54f8a3794295291a1b5a18ed363416]
cloudflare_record.a: Drift detected (update)
hcloud_firewall.web_firewall: Drift detected (update)
hcloud_server.web: Drift detected (update)
cloudflare_record.aliases["traefik"]: Drift detected (update)
cloudflare_record.aliases["auth"]: Drift detected (update)
cloudflare_record.aliases["grafana"]: Drift detected (update)
cloudflare_record.aliases["grocy"]: Drift detected (update)
cloudflare_record.aliases["ldap"]: Drift detected (update)
cloudflare_record.aliases["photoprism"]: Drift detected (update)
cloudflare_record.aaaa: Drift detected (update)
No changes. Your infrastructure matches the configuration.
Terraform has compared your real infrastructure against your configuration
and found no differences, so no changes are needed.
─────────────────────────────────────────────────────────────────────────────
Note: You didn't use the -out option to save this plan, so Terraform can't
guarantee to take exactly these actions if you run "terraform apply" now.
renovateBot
changed the title
chore(deps): update authelia/authelia docker tag to v4.39.12
chore(deps): update authelia/authelia docker tag to v4.39.13
Oct 12, 2025
terraform
Running plan in HCP Terraform. Output will stream here. Pressing Ctrl-C
will stop streaming the logs, but will not stop the plan running remotely.
Preparing the remote plan...
The remote workspace is configured to work with configuration at
infra relative to the target repository.
Terraform will upload the contents of the following directory,
excluding files or directories as defined by a .terraformignore file
at /home/runner/work/private_server/private_server/.terraformignore (if it is present),
in order to capture the filesystem context the remote workspace expects:
/home/runner/work/private_server/private_server
To view this run in a browser, visit:
https://app.terraform.io/app/redline/private_server/runs/run-NBGWwrdEHEUxJLR4
Waiting for the plan to start...
Terraform v1.3.2
on linux_amd64
Initializing plugins and modules...
cloudflare_zone.personal_domain: Refreshing state... [id=cee2af2644f6a3325416173e2d4b44f7]
hcloud_ssh_key.ansible: Refreshing state... [id=8957821]
hcloud_firewall.web_firewall: Refreshing state... [id=603891]
hcloud_server.web: Refreshing state... [id=51760523]
hcloud_volume.data: Refreshing state... [id=24743811]
hcloud_firewall_attachment.firewall_assignments: Refreshing state... [id=603891]
cloudflare_record.aaaa: Refreshing state... [id=1f54f8a3794295291a1b5a18ed363416]
cloudflare_record.a: Refreshing state... [id=a44b3519c0443db244e9f2dc5bba8a91]
cloudflare_record.aliases["ldap"]: Refreshing state... [id=416e67a40f89597f342029d943e253ed]
cloudflare_record.aliases["grafana"]: Refreshing state... [id=a63efd438a1e819f0e4215e4835a0f24]
cloudflare_record.aliases["grocy"]: Refreshing state... [id=1a98a4348007c72461ab6752f2c7f9df]
cloudflare_record.aliases["photoprism"]: Refreshing state... [id=6c61639959eeaf8d547dd411419bcf9a]
cloudflare_record.aliases["traefik"]: Refreshing state... [id=efbdd0b7c842cec43a43af72a450fcc0]
cloudflare_record.aliases["auth"]: Refreshing state... [id=59a6c353a0138b64113ad34f046c17dc]
cloudflare_record.aaaa: Drift detected (delete)
cloudflare_record.a: Drift detected (delete)
cloudflare_record.aliases["auth"]: Drift detected (delete)
cloudflare_record.aliases["grafana"]: Drift detected (delete)
cloudflare_record.aliases["grocy"]: Drift detected (delete)
cloudflare_record.aliases["ldap"]: Drift detected (delete)
cloudflare_record.aliases["photoprism"]: Drift detected (delete)
cloudflare_record.aliases["traefik"]: Drift detected (delete)
hcloud_server.web: Drift detected (update)
hcloud_firewall.web_firewall: Drift detected (update)
Terraform used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
+ create
Terraform will perform the following actions:
# cloudflare_record.a will be created
+ resource "cloudflare_record" "a" {
+ allow_overwrite = false
+ content = "78.47.192.97"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "pascal.build"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "A"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aaaa will be created
+ resource "cloudflare_record" "aaaa" {
+ allow_overwrite = false
+ content = "2a01:4f8:c2c:1ff1::1"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "pascal.build"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "AAAA"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["auth"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "auth"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["grafana"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "grafana"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["grocy"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "grocy"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["ldap"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "ldap"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["photoprism"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "photoprism"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["traefik"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "traefik"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
Plan: 8 to add, 0 to change, 0 to destroy.
─────────────────────────────────────────────────────────────────────────────
Note: You didn't use the -out option to save this plan, so Terraform can't
guarantee to take exactly these actions if you run "terraform apply" now.
renovateBot
changed the title
chore(deps): update authelia/authelia docker tag to v4.39.13
chore(deps): update authelia/authelia docker tag to v4.39.14
Nov 9, 2025
terraform
Running plan in HCP Terraform. Output will stream here. Pressing Ctrl-C
will stop streaming the logs, but will not stop the plan running remotely.
Preparing the remote plan...
The remote workspace is configured to work with configuration at
infra relative to the target repository.
Terraform will upload the contents of the following directory,
excluding files or directories as defined by a .terraformignore file
at /home/runner/work/private_server/private_server/.terraformignore (if it is present),
in order to capture the filesystem context the remote workspace expects:
/home/runner/work/private_server/private_server
To view this run in a browser, visit:
https://app.terraform.io/app/redline/private_server/runs/run-SjayQEWo5knYq2TN
Waiting for the plan to start...
Terraform v1.3.2
on linux_amd64
Initializing plugins and modules...
cloudflare_zone.personal_domain: Refreshing state... [id=cee2af2644f6a3325416173e2d4b44f7]
hcloud_ssh_key.ansible: Refreshing state... [id=8957821]
hcloud_firewall.web_firewall: Refreshing state... [id=603891]
cloudflare_record.aliases["traefik"]: Refreshing state... [id=efbdd0b7c842cec43a43af72a450fcc0]
cloudflare_record.aliases["grocy"]: Refreshing state... [id=1a98a4348007c72461ab6752f2c7f9df]
cloudflare_record.aliases["auth"]: Refreshing state... [id=59a6c353a0138b64113ad34f046c17dc]
cloudflare_record.aliases["grafana"]: Refreshing state... [id=a63efd438a1e819f0e4215e4835a0f24]
cloudflare_record.aliases["photoprism"]: Refreshing state... [id=6c61639959eeaf8d547dd411419bcf9a]
cloudflare_record.aliases["ldap"]: Refreshing state... [id=416e67a40f89597f342029d943e253ed]
hcloud_server.web: Refreshing state... [id=51760523]
hcloud_firewall_attachment.firewall_assignments: Refreshing state... [id=603891]
hcloud_volume.data: Refreshing state... [id=24743811]
cloudflare_record.aaaa: Refreshing state... [id=1f54f8a3794295291a1b5a18ed363416]
cloudflare_record.a: Refreshing state... [id=a44b3519c0443db244e9f2dc5bba8a91]
hcloud_firewall.web_firewall: Drift detected (update)
hcloud_server.web: Drift detected (update)
cloudflare_record.aaaa: Drift detected (delete)
cloudflare_record.aliases["auth"]: Drift detected (delete)
cloudflare_record.aliases["grafana"]: Drift detected (delete)
cloudflare_record.aliases["grocy"]: Drift detected (delete)
cloudflare_record.aliases["ldap"]: Drift detected (delete)
cloudflare_record.aliases["photoprism"]: Drift detected (delete)
cloudflare_record.aliases["traefik"]: Drift detected (delete)
cloudflare_record.a: Drift detected (delete)
Terraform used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
+ create
Terraform will perform the following actions:
# cloudflare_record.a will be created
+ resource "cloudflare_record" "a" {
+ allow_overwrite = false
+ content = "78.47.192.97"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "pascal.build"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "A"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aaaa will be created
+ resource "cloudflare_record" "aaaa" {
+ allow_overwrite = false
+ content = "2a01:4f8:c2c:1ff1::1"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "pascal.build"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "AAAA"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["auth"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "auth"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["grafana"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "grafana"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["grocy"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "grocy"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["ldap"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "ldap"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["photoprism"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "photoprism"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["traefik"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "traefik"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
Plan: 8 to add, 0 to change, 0 to destroy.
─────────────────────────────────────────────────────────────────────────────
Note: You didn't use the -out option to save this plan, so Terraform can't
guarantee to take exactly these actions if you run "terraform apply" now.
renovateBot
changed the title
chore(deps): update authelia/authelia docker tag to v4.39.14
chore(deps): update authelia/authelia docker tag to v4.39.15
Nov 29, 2025
terraform
Running plan in HCP Terraform. Output will stream here. Pressing Ctrl-C
will stop streaming the logs, but will not stop the plan running remotely.
Preparing the remote plan...
The remote workspace is configured to work with configuration at
infra relative to the target repository.
Terraform will upload the contents of the following directory,
excluding files or directories as defined by a .terraformignore file
at /home/runner/work/private_server/private_server/.terraformignore (if it is present),
in order to capture the filesystem context the remote workspace expects:
/home/runner/work/private_server/private_server
To view this run in a browser, visit:
https://app.terraform.io/app/redline/private_server/runs/run-P7Vj5fSnZYCc3mxe
Waiting for the plan to start...
Terraform v1.3.2
on linux_amd64
Initializing plugins and modules...
hcloud_ssh_key.ansible: Refreshing state... [id=8957821]
hcloud_firewall.web_firewall: Refreshing state... [id=603891]
cloudflare_zone.personal_domain: Refreshing state... [id=cee2af2644f6a3325416173e2d4b44f7]
cloudflare_record.aliases["grocy"]: Refreshing state... [id=1a98a4348007c72461ab6752f2c7f9df]
cloudflare_record.aliases["grafana"]: Refreshing state... [id=a63efd438a1e819f0e4215e4835a0f24]
cloudflare_record.aliases["traefik"]: Refreshing state... [id=efbdd0b7c842cec43a43af72a450fcc0]
cloudflare_record.aliases["auth"]: Refreshing state... [id=59a6c353a0138b64113ad34f046c17dc]
cloudflare_record.aliases["photoprism"]: Refreshing state... [id=6c61639959eeaf8d547dd411419bcf9a]
cloudflare_record.aliases["ldap"]: Refreshing state... [id=416e67a40f89597f342029d943e253ed]
hcloud_server.web: Refreshing state... [id=51760523]
hcloud_volume.data: Refreshing state... [id=24743811]
hcloud_firewall_attachment.firewall_assignments: Refreshing state... [id=603891]
cloudflare_record.a: Refreshing state... [id=a44b3519c0443db244e9f2dc5bba8a91]
cloudflare_record.aaaa: Refreshing state... [id=1f54f8a3794295291a1b5a18ed363416]
hcloud_server.web: Drift detected (update)
cloudflare_record.aliases["ldap"]: Drift detected (delete)
cloudflare_record.aliases["photoprism"]: Drift detected (delete)
cloudflare_record.aliases["traefik"]: Drift detected (delete)
cloudflare_record.aliases["auth"]: Drift detected (delete)
cloudflare_record.aliases["grafana"]: Drift detected (delete)
cloudflare_record.aliases["grocy"]: Drift detected (delete)
hcloud_firewall.web_firewall: Drift detected (update)
cloudflare_record.aaaa: Drift detected (delete)
cloudflare_record.a: Drift detected (delete)
Terraform used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
+ create
Terraform will perform the following actions:
# cloudflare_record.a will be created
+ resource "cloudflare_record" "a" {
+ allow_overwrite = false
+ content = "78.47.192.97"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "pascal.build"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "A"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aaaa will be created
+ resource "cloudflare_record" "aaaa" {
+ allow_overwrite = false
+ content = "2a01:4f8:c2c:1ff1::1"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "pascal.build"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "AAAA"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["auth"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "auth"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["grafana"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "grafana"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["grocy"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "grocy"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["ldap"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "ldap"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["photoprism"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "photoprism"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["traefik"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "traefik"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
Plan: 8 to add, 0 to change, 0 to destroy.
─────────────────────────────────────────────────────────────────────────────
Note: You didn't use the -out option to save this plan, so Terraform can't
guarantee to take exactly these actions if you run "terraform apply" now.
renovateBot
changed the title
chore(deps): update authelia/authelia docker tag to v4.39.15
chore(deps): update authelia/authelia docker tag to v4.39.16
Mar 14, 2026
terraform
Running plan in HCP Terraform. Output will stream here. Pressing Ctrl-C
will stop streaming the logs, but will not stop the plan running remotely.
Preparing the remote plan...
The remote workspace is configured to work with configuration at
infra relative to the target repository.
Terraform will upload the contents of the following directory,
excluding files or directories as defined by a .terraformignore file
at /home/runner/work/private_server/private_server/.terraformignore (if it is present),
in order to capture the filesystem context the remote workspace expects:
/home/runner/work/private_server/private_server
To view this run in a browser, visit:
https://app.terraform.io/app/redline/private_server/runs/run-giyqAuJbmfwMQMo4
Waiting for the plan to start...
Terraform v1.3.2
on linux_amd64
Initializing plugins and modules...
cloudflare_zone.personal_domain: Refreshing state... [id=cee2af2644f6a3325416173e2d4b44f7]
hcloud_ssh_key.ansible: Refreshing state... [id=8957821]
hcloud_firewall.web_firewall: Refreshing state... [id=603891]
cloudflare_record.aliases["traefik"]: Refreshing state... [id=efbdd0b7c842cec43a43af72a450fcc0]
cloudflare_record.aliases["grafana"]: Refreshing state... [id=a63efd438a1e819f0e4215e4835a0f24]
cloudflare_record.aliases["grocy"]: Refreshing state... [id=1a98a4348007c72461ab6752f2c7f9df]
cloudflare_record.aliases["photoprism"]: Refreshing state... [id=6c61639959eeaf8d547dd411419bcf9a]
cloudflare_record.aliases["ldap"]: Refreshing state... [id=416e67a40f89597f342029d943e253ed]
cloudflare_record.aliases["auth"]: Refreshing state... [id=59a6c353a0138b64113ad34f046c17dc]
hcloud_server.web: Refreshing state... [id=51760523]
hcloud_firewall_attachment.firewall_assignments: Refreshing state... [id=603891]
hcloud_volume.data: Refreshing state... [id=24743811]
cloudflare_record.a: Refreshing state... [id=a44b3519c0443db244e9f2dc5bba8a91]
cloudflare_record.aaaa: Refreshing state... [id=1f54f8a3794295291a1b5a18ed363416]
hcloud_server.web: Drift detected (update)
cloudflare_record.a: Drift detected (delete)
cloudflare_record.aaaa: Drift detected (delete)
cloudflare_record.aliases["grafana"]: Drift detected (delete)
cloudflare_record.aliases["grocy"]: Drift detected (delete)
cloudflare_record.aliases["ldap"]: Drift detected (delete)
cloudflare_record.aliases["photoprism"]: Drift detected (delete)
cloudflare_record.aliases["traefik"]: Drift detected (delete)
cloudflare_record.aliases["auth"]: Drift detected (delete)
hcloud_firewall.web_firewall: Drift detected (update)
Terraform used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
+ create
Terraform will perform the following actions:
# cloudflare_record.a will be created
+ resource "cloudflare_record" "a" {
+ allow_overwrite = false
+ content = "78.47.192.97"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "pascal.build"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "A"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aaaa will be created
+ resource "cloudflare_record" "aaaa" {
+ allow_overwrite = false
+ content = "2a01:4f8:c2c:1ff1::1"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "pascal.build"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "AAAA"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["auth"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "auth"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["grafana"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "grafana"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["grocy"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "grocy"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["ldap"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "ldap"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["photoprism"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "photoprism"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["traefik"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "traefik"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
Plan: 8 to add, 0 to change, 0 to destroy.
─────────────────────────────────────────────────────────────────────────────
Note: You didn't use the -out option to save this plan, so Terraform can't
guarantee to take exactly these actions if you run "terraform apply" now.
renovateBot
changed the title
chore(deps): update authelia/authelia docker tag to v4.39.16
chore(deps): update authelia/authelia docker tag to v4.39.17
Apr 9, 2026
terraform
Running plan in HCP Terraform. Output will stream here. Pressing Ctrl-C
will stop streaming the logs, but will not stop the plan running remotely.
Preparing the remote plan...
The remote workspace is configured to work with configuration at
infra relative to the target repository.
Terraform will upload the contents of the following directory,
excluding files or directories as defined by a .terraformignore file
at /home/runner/work/private_server/private_server/.terraformignore (if it is present),
in order to capture the filesystem context the remote workspace expects:
/home/runner/work/private_server/private_server
To view this run in a browser, visit:
https://app.terraform.io/app/redline/private_server/runs/run-ovD4uvLSdwURVdpR
Waiting for the plan to start...
Terraform v1.3.2
on linux_amd64
Initializing plugins and modules...
cloudflare_zone.personal_domain: Refreshing state... [id=cee2af2644f6a3325416173e2d4b44f7]
hcloud_ssh_key.ansible: Refreshing state... [id=8957821]
hcloud_firewall.web_firewall: Refreshing state... [id=603891]
cloudflare_record.aliases["auth"]: Refreshing state... [id=59a6c353a0138b64113ad34f046c17dc]
cloudflare_record.aliases["grocy"]: Refreshing state... [id=1a98a4348007c72461ab6752f2c7f9df]
cloudflare_record.aliases["ldap"]: Refreshing state... [id=416e67a40f89597f342029d943e253ed]
cloudflare_record.aliases["photoprism"]: Refreshing state... [id=6c61639959eeaf8d547dd411419bcf9a]
cloudflare_record.aliases["traefik"]: Refreshing state... [id=efbdd0b7c842cec43a43af72a450fcc0]
cloudflare_record.aliases["grafana"]: Refreshing state... [id=a63efd438a1e819f0e4215e4835a0f24]
hcloud_server.web: Refreshing state... [id=51760523]
hcloud_firewall_attachment.firewall_assignments: Refreshing state... [id=603891]
hcloud_volume.data: Refreshing state... [id=24743811]
cloudflare_record.a: Refreshing state... [id=a44b3519c0443db244e9f2dc5bba8a91]
cloudflare_record.aaaa: Refreshing state... [id=1f54f8a3794295291a1b5a18ed363416]
cloudflare_record.aaaa: Drift detected (delete)
hcloud_firewall.web_firewall: Drift detected (update)
cloudflare_record.a: Drift detected (delete)
cloudflare_record.aliases["grocy"]: Drift detected (delete)
cloudflare_record.aliases["ldap"]: Drift detected (delete)
cloudflare_record.aliases["photoprism"]: Drift detected (delete)
cloudflare_record.aliases["traefik"]: Drift detected (delete)
cloudflare_record.aliases["auth"]: Drift detected (delete)
cloudflare_record.aliases["grafana"]: Drift detected (delete)
hcloud_server.web: Drift detected (update)
Terraform used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
+ create
Terraform will perform the following actions:
# cloudflare_record.a will be created
+ resource "cloudflare_record" "a" {
+ allow_overwrite = false
+ content = "78.47.192.97"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "pascal.build"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "A"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aaaa will be created
+ resource "cloudflare_record" "aaaa" {
+ allow_overwrite = false
+ content = "2a01:4f8:c2c:1ff1::1"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "pascal.build"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "AAAA"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["auth"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "auth"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["grafana"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "grafana"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["grocy"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "grocy"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["ldap"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "ldap"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["photoprism"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "photoprism"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["traefik"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "traefik"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
Plan: 8 to add, 0 to change, 0 to destroy.
------------------------------------------------------------------------
Cost Estimation:
Resources: 0 of 14 estimated
$0.0/mo +$0.0
─────────────────────────────────────────────────────────────────────────────
Note: You didn't use the -out option to save this plan, so Terraform can't
guarantee to take exactly these actions if you run "terraform apply" now.
renovateBot
changed the title
chore(deps): update authelia/authelia docker tag to v4.39.17
chore(deps): update authelia/authelia docker tag to v4.39.18
Apr 10, 2026
terraform
Running plan in HCP Terraform. Output will stream here. Pressing Ctrl-C
will stop streaming the logs, but will not stop the plan running remotely.
Preparing the remote plan...
The remote workspace is configured to work with configuration at
infra relative to the target repository.
Terraform will upload the contents of the following directory,
excluding files or directories as defined by a .terraformignore file
at /home/runner/work/private_server/private_server/.terraformignore (if it is present),
in order to capture the filesystem context the remote workspace expects:
/home/runner/work/private_server/private_server
To view this run in a browser, visit:
https://app.terraform.io/app/redline/private_server/runs/run-eVjK9LYadQ67p1ie
Waiting for the plan to start...
Terraform v1.3.2
on linux_amd64
Initializing plugins and modules...
cloudflare_zone.personal_domain: Refreshing state... [id=cee2af2644f6a3325416173e2d4b44f7]
hcloud_ssh_key.ansible: Refreshing state... [id=8957821]
hcloud_firewall.web_firewall: Refreshing state... [id=603891]
cloudflare_record.aliases["traefik"]: Refreshing state... [id=efbdd0b7c842cec43a43af72a450fcc0]
cloudflare_record.aliases["auth"]: Refreshing state... [id=59a6c353a0138b64113ad34f046c17dc]
cloudflare_record.aliases["ldap"]: Refreshing state... [id=416e67a40f89597f342029d943e253ed]
cloudflare_record.aliases["grocy"]: Refreshing state... [id=1a98a4348007c72461ab6752f2c7f9df]
cloudflare_record.aliases["grafana"]: Refreshing state... [id=a63efd438a1e819f0e4215e4835a0f24]
cloudflare_record.aliases["photoprism"]: Refreshing state... [id=6c61639959eeaf8d547dd411419bcf9a]
hcloud_server.web: Refreshing state... [id=51760523]
hcloud_firewall_attachment.firewall_assignments: Refreshing state... [id=603891]
hcloud_volume.data: Refreshing state... [id=24743811]
cloudflare_record.aaaa: Refreshing state... [id=1f54f8a3794295291a1b5a18ed363416]
cloudflare_record.a: Refreshing state... [id=a44b3519c0443db244e9f2dc5bba8a91]
cloudflare_record.aliases["auth"]: Drift detected (delete)
cloudflare_record.aliases["grafana"]: Drift detected (delete)
cloudflare_record.aliases["grocy"]: Drift detected (delete)
cloudflare_record.aliases["ldap"]: Drift detected (delete)
cloudflare_record.aliases["photoprism"]: Drift detected (delete)
cloudflare_record.aliases["traefik"]: Drift detected (delete)
cloudflare_record.a: Drift detected (delete)
hcloud_firewall.web_firewall: Drift detected (update)
cloudflare_record.aaaa: Drift detected (delete)
hcloud_server.web: Drift detected (update)
Terraform used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
+ create
Terraform will perform the following actions:
# cloudflare_record.a will be created
+ resource "cloudflare_record" "a" {
+ allow_overwrite = false
+ content = "78.47.192.97"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "pascal.build"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "A"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aaaa will be created
+ resource "cloudflare_record" "aaaa" {
+ allow_overwrite = false
+ content = "2a01:4f8:c2c:1ff1::1"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "pascal.build"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "AAAA"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["auth"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "auth"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["grafana"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "grafana"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["grocy"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "grocy"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["ldap"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "ldap"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["photoprism"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "photoprism"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["traefik"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "traefik"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
Plan: 8 to add, 0 to change, 0 to destroy.
------------------------------------------------------------------------
Cost Estimation:
Resources: 0 of 14 estimated
$0.0/mo +$0.0
─────────────────────────────────────────────────────────────────────────────
Note: You didn't use the -out option to save this plan, so Terraform can't
guarantee to take exactly these actions if you run "terraform apply" now.
renovateBot
changed the title
chore(deps): update authelia/authelia docker tag to v4.39.18
chore(deps): update authelia/authelia docker tag to v4.39.19
Apr 12, 2026
terraform
Running plan in HCP Terraform. Output will stream here. Pressing Ctrl-C
will stop streaming the logs, but will not stop the plan running remotely.
Preparing the remote plan...
The remote workspace is configured to work with configuration at
infra relative to the target repository.
Terraform will upload the contents of the following directory,
excluding files or directories as defined by a .terraformignore file
at /home/runner/work/private_server/private_server/.terraformignore (if it is present),
in order to capture the filesystem context the remote workspace expects:
/home/runner/work/private_server/private_server
To view this run in a browser, visit:
https://app.terraform.io/app/redline/private_server/runs/run-peRXCHxUiQns4zHk
Waiting for the plan to start...
Terraform v1.3.2
on linux_amd64
Initializing plugins and modules...
cloudflare_zone.personal_domain: Refreshing state... [id=cee2af2644f6a3325416173e2d4b44f7]
hcloud_ssh_key.ansible: Refreshing state... [id=8957821]
hcloud_firewall.web_firewall: Refreshing state... [id=603891]
cloudflare_record.aliases["grocy"]: Refreshing state... [id=1a98a4348007c72461ab6752f2c7f9df]
cloudflare_record.aliases["traefik"]: Refreshing state... [id=efbdd0b7c842cec43a43af72a450fcc0]
cloudflare_record.aliases["grafana"]: Refreshing state... [id=a63efd438a1e819f0e4215e4835a0f24]
cloudflare_record.aliases["auth"]: Refreshing state... [id=59a6c353a0138b64113ad34f046c17dc]
cloudflare_record.aliases["photoprism"]: Refreshing state... [id=6c61639959eeaf8d547dd411419bcf9a]
cloudflare_record.aliases["ldap"]: Refreshing state... [id=416e67a40f89597f342029d943e253ed]
hcloud_server.web: Refreshing state... [id=51760523]
hcloud_volume.data: Refreshing state... [id=24743811]
hcloud_firewall_attachment.firewall_assignments: Refreshing state... [id=603891]
cloudflare_record.aaaa: Refreshing state... [id=1f54f8a3794295291a1b5a18ed363416]
cloudflare_record.a: Refreshing state... [id=a44b3519c0443db244e9f2dc5bba8a91]
cloudflare_record.a: Drift detected (delete)
hcloud_firewall.web_firewall: Drift detected (update)
cloudflare_record.aliases["traefik"]: Drift detected (delete)
cloudflare_record.aliases["auth"]: Drift detected (delete)
cloudflare_record.aliases["grafana"]: Drift detected (delete)
cloudflare_record.aliases["grocy"]: Drift detected (delete)
cloudflare_record.aliases["ldap"]: Drift detected (delete)
cloudflare_record.aliases["photoprism"]: Drift detected (delete)
hcloud_server.web: Drift detected (update)
cloudflare_record.aaaa: Drift detected (delete)
Terraform used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
+ create
Terraform will perform the following actions:
# cloudflare_record.a will be created
+ resource "cloudflare_record" "a" {
+ allow_overwrite = false
+ content = "78.47.192.97"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "pascal.build"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "A"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aaaa will be created
+ resource "cloudflare_record" "aaaa" {
+ allow_overwrite = false
+ content = "2a01:4f8:c2c:1ff1::1"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "pascal.build"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "AAAA"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["auth"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "auth"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["grafana"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "grafana"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["grocy"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "grocy"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["ldap"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "ldap"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["photoprism"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "photoprism"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
# cloudflare_record.aliases["traefik"] will be created
+ resource "cloudflare_record" "aliases" {
+ allow_overwrite = false
+ content = "pascal.build"
+ created_on = (known after apply)
+ hostname = (known after apply)
+ id = (known after apply)
+ metadata = (known after apply)
+ modified_on = (known after apply)
+ name = "traefik"
+ proxiable = (known after apply)
+ ttl = 300
+ type = "CNAME"
+ value = (known after apply)
+ zone_id = "cee2af2644f6a3325416173e2d4b44f7"
}
Plan: 8 to add, 0 to change, 0 to destroy.
------------------------------------------------------------------------
Cost Estimation:
Resources: 0 of 14 estimated
$0.0/mo +$0.0
─────────────────────────────────────────────────────────────────────────────
Note: You didn't use the -out option to save this plan, so Terraform can't
guarantee to take exactly these actions if you run "terraform apply" now.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for freeto subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Labels
None yet
0 participants
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.38.10→4.39.19Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
authelia/authelia (authelia/authelia)
v4.39.19Compare Source
Bug Fixes
Docker Container
docker pull authelia/authelia:4.39.19docker pull ghcr.io/authelia/authelia:4.39.19v4.39.18Compare Source
Bug Fixes
Docker Container
docker pull authelia/authelia:4.39.18docker pull ghcr.io/authelia/authelia:4.39.18v4.39.17Compare Source
Bug Fixes
Docker Container
docker pull authelia/authelia:4.39.17docker pull ghcr.io/authelia/authelia:4.39.17v4.39.16Compare Source
Security Fixes
This release fixes security issues. For more information please see GHSA-gmfg-3v4q-9qr4.
Bug Fixes
Docker Container
docker pull authelia/authelia:4.39.16docker pull ghcr.io/authelia/authelia:4.39.16v4.39.15Compare Source
Bug Fixes
Docker Container
docker pull authelia/authelia:4.39.15docker pull ghcr.io/authelia/authelia:4.39.15v4.39.14Compare Source
Bug Fixes
Docker Container
docker pull authelia/authelia:4.39.14docker pull ghcr.io/authelia/authelia:4.39.14v4.39.13Compare Source
Bug Fixes
Docker Container
docker pull authelia/authelia:4.39.13docker pull ghcr.io/authelia/authelia:4.39.13v4.39.12Compare Source
Bug Fixes
Docker Container
docker pull authelia/authelia:4.39.12docker pull ghcr.io/authelia/authelia:4.39.12v4.39.11Compare Source
Bug Fixes
Docker Container
docker pull authelia/authelia:4.39.11docker pull ghcr.io/authelia/authelia:4.39.11v4.39.10Compare Source
Bug Fixes
Docker Container
docker pull authelia/authelia:4.39.10docker pull ghcr.io/authelia/authelia:4.39.10v4.39.9Compare Source
Bug Fixes
Docker Container
docker pull authelia/authelia:4.39.9docker pull ghcr.io/authelia/authelia:4.39.9v4.39.8Compare Source
Bug Fixes
Docker Container
docker pull authelia/authelia:4.39.8docker pull ghcr.io/authelia/authelia:4.39.8v4.39.7Compare Source
Bug Fixes
Docker Container
docker pull authelia/authelia:4.39.7docker pull ghcr.io/authelia/authelia:4.39.7v4.39.6Compare Source
Notable Changes
OpenID Connect 1.0 client registrations incorrectly allowed
noneas aauthorization_signed_response_algvalue, this is no longer the case and if you specified this value you'll have to either remove it or update it to the new correct default ofRS256.Bug Fixes
Docker Container
docker pull authelia/authelia:4.39.6docker pull ghcr.io/authelia/authelia:4.39.6v4.39.5Compare Source
Bug Fixes
Docker Container
docker pull authelia/authelia:4.39.5docker pull ghcr.io/authelia/authelia:4.39.5v4.39.4Compare Source
Bug Fixes
Docker Container
docker pull authelia/authelia:4.39.4docker pull ghcr.io/authelia/authelia:4.39.4v4.39.3Compare Source
Important Note: The v4.39.2 release inadvertently removed the legacy OpenID Connect 1.0 endpoints which have not been documented at least in the last 3 years either at the discovery document or on the website. While these changes were technically unintentional right at this moment they were going to be hard removed at some point before we graduated OpenID Connect 1.0 out of a experimental/beta state and users had previously been notified of this change, as such we're going to leave them as is. Users should refer to our documentation as well as their instances discovery endpoints to obtain the correct URLs. The URLs that potentially may need updating are as follows: the URL
/api/oidc/jwkspreviously handled requests for the JSON Web Key Set Endpoint, the URL/api/oidc/authorizepreviously also handled requests for the Authorization Endpoint, the URL/api/oidc/introspectpreviously also handled requests for the Introspection Endpoint, and the URL/api/oidc/revokepreviously also handled requests for the Revocation Endpoint.Bug Fixes
Docker Container
docker pull authelia/authelia:4.39.3docker pull ghcr.io/authelia/authelia:4.39.3v4.39.2Compare Source
Important Note: The v4.39.2 release inadvertently removed the legacy OpenID Connect 1.0 endpoints which have not been documented in the last 3 years either at the discovery document or on the website. While these changes were technically unintentional right at this moment they were going to be hard removed at some point before we graduated OpenID Connect 1.0 out of a experimental/beta state, as such we're going to leave them as is. Users should refer to our documentation as well as their instances discovery endpoints to obtain the correct URLs.
Bug Fixes
Performance Improvements
Docker Container
docker pull authelia/authelia:4.39.2docker pull ghcr.io/authelia/authelia:4.39.2v4.39.1Compare Source
Bug Fixes
Docker Container
docker pull authelia/authelia:4.39.1docker pull ghcr.io/authelia/authelia:4.39.1v4.39.0Compare Source
Summary
Please see the Authelia Blog: 4.39 Release Notes for human readable summaries of the changes. It's important to note some critical changes have occurred in this release that warrant some user attention.
Specific critical changes which are detailed in the Authelia Blog: 4.39 Release Notes to watch out for:
Detailed Changes
Bug Fixes
Features
Docker Container
docker pull authelia/authelia:4.39.0docker pull ghcr.io/authelia/authelia:4.39.0v4.38.19Compare Source
Bug Fixes
Docker Container
docker pull authelia/authelia:4.38.19docker pull ghcr.io/authelia/authelia:4.38.19v4.38.18Compare Source
Bug Fixes
Docker Container
docker pull authelia/authelia:4.38.18docker pull ghcr.io/authelia/authelia:4.38.18v4.38.17Compare Source
Bug Fixes
Docker Container
docker pull authelia/authelia:4.38.17docker pull ghcr.io/authelia/authelia:4.38.17v4.38.16Compare Source
Bug Fixes
Docker Container
docker pull authelia/authelia:4.38.16docker pull ghcr.io/authelia/authelia:4.38.16v4.38.15Compare Source
Bug Fixes
Docker Container
docker pull authelia/authelia:4.38.15docker pull ghcr.io/authelia/authelia:4.38.15v4.38.14Compare Source
Bug Fixes
Docker Container
docker pull authelia/authelia:4.38.14docker pull ghcr.io/authelia/authelia:4.38.14v4.38.13Compare Source
Bug Fixes
Docker Container
docker pull authelia/authelia:4.38.13docker pull ghcr.io/authelia/authelia:4.38.13v4.38.12Compare Source
Bug Fixes
Docker Container
docker pull authelia/authelia:4.38.12docker pull ghcr.io/authelia/authelia:4.38.12v4.38.11Compare Source
Bug Fixes
Docker Container
docker pull authelia/authelia:4.38.11docker pull ghcr.io/authelia/authelia:4.38.11Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.