Skip to content

feat(container): update image ghcr.io/qdm12/gluetun ( v3.38.0 → v3.41.3 ) - #5379

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/cluster-0-ghcr.io-qdm12-gluetun-3.x
Open

feat(container): update image ghcr.io/qdm12/gluetun ( v3.38.0 → v3.41.3 )#5379
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/cluster-0-ghcr.io-qdm12-gluetun-3.x

Conversation

@renovate

@renovate renovate Bot commented Aug 9, 2024

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
ghcr.io/qdm12/gluetun minor v3.38.0v3.41.3

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

passteque/gluetun (ghcr.io/qdm12/gluetun)

v3.41.3

Compare Source

This fixes a VPN server port forwarding deadlock bug introduced whilst back-porting a fix from the master branch (:latest image) to v3.41.2. Credits to @​robinostlund for reporting the bug and even nailing down what it was! (#​3416)

Refer to v3.41.2 fixes in case you haven't checked.

v3.41.2

Compare Source

⚠️ there is a deadlock bug in the port forwarding if you use the up or down command, I will release v3.41.3 shortly

Fixes

  • Wireguard:
    • support IPv6 address formatting from config files (#​3273)
    • ignore empty address strings
    • skip tun device checks when using kernelspace
  • OpenVPN:
    • bundle provider CA certificates in one block (#​3258)
    • trim spaces in config lines before parsing (#​3327)
    • fix support for tcp-client
      • always use proto tcp-client when using TCP
      • parses tcp-client (on top of tcp, tcp4, tcp6) as meaning TCP
  • Custom openvpn: restrict custom openvpn config protocol to tcp or udp internally
  • Firewall: shared mutex for both iptables and ip6tables to prevent race conditions
  • Healthcheck:
    • correct behavior when HEALTH_RESTART_VPN=off and startup check fails
    • prevent race condition on the healthchecker (#​3400)
  • DNS:
    • skip blocking if block lists download fails
    • correct error wrapping for DNS listening address validation
    • DNS over TLS pool behavior fixed
      • handle timed out connections the same as closed connections
      • close connection on TLS handshake failure
      • improve mutex handling during connection renewal and retrieval
  • VPN port forwarding:
    • no longer stuck after failed port forwarding
    • handle empty ports without panicing
  • Updater: only uses DoH to cloudflare+google
    • prevent dns plaintext manipulation both the periodic update and when running in cli mode
    • possibly higher reliability on poor connections versus UDP
    • drop -dns flag in update command
    • for now no configuration allowed since it makes everything rather complex
  • Control server:
    • use port and ports for both single port and multiple ports forwarded
    • authentication: return 404 or 405 depending on route
  • Increase global http client timeout to 35s and precise lower timeouts where needed
    • Fix DNS blocklists slow downloads
    • Leave 35s timeout for updaters
    • Set timeouts to 1s for local calls
    • Set timeouts to 5s for LAN VPN calls and small external calls
    • Set timeouts to 10s external VPN API calls
  • Kernel modules: probe searches for features built-in the kernel
  • CI: set hash of PR commit instead of synthetic commit in docker build argument
  • internal/command: fix rare race condition on log line stream at command completion
Provider specific fixes
  • AirVPN: update servers data (#​3186)
  • ExpressVPN:
    • add new CA3 certificate to fix TLS handshake failure (#​3184, #​3192)
    • remove pakistan server
  • Privado:
    • servers data updated using JSON API
    • allow OpenVPN TCP protocol
    • allow additional OpenVPN ports 443, 8080 and 8443 for both tcp and udp
  • Private Internet Access:
    • remove none encryption preset
    • use AES-GCM for all presets
    • allow ports 501 and 502 as custom ports given they are the defaults
    • try x.y.128.1 and x.y.0.1 from the gateway IP to find the API IP address
    • fix servers data updater and update servers data
    • update default OpenVPN ports: 8080 for UDP, 8443 for TCP (according to pia-foss/manual-connections@8a75e46)
    • handle "port is busy" messages and retry port forwarding logic
  • ProtonVPN: fix updater code
  • Vyprvpn: update OpenVPN configs zip URL (#​3264)

PS:

  • No time to make a video or a rant section yet, but will do for v3.42.0 for sure!
  • v3.42 probably coming end of August/early September!
  • Sorry for the spam, first few v3.41.2 release attempts decided to give me a bunch of surprises in the CI, so here it is again

v3.41.1

Compare Source

Fixes

  • Healthcheck: prevent race condition making Gluetun hang completely (#​3123)
  • Wireguard kernelspace detection fixed in some cases
  • OpenVPN 2.5 is not needed as long as it's not to be used, resolving some kernel incompatibilities
  • HTTP proxy: remove info log when no Proxy-Authorization header is present
  • ProtonVPN:
    • update OpenVPN settings (#​3120)
    • support port 51820 for UDP OpenVPN connections

v3.41.0

Compare Source

Video of me reading out this release

Thank you all for your patience for this release which took its sweet time 🙏⏲️

I have been rather absent in a good part of 2025 due to work and life getting in the way, and I would like to thank many of you for helping out around in issues and discussions, and for the few code contributors whilst I was away.

On this release, many of the features you see are the result of behind-the-scene work of the last few years (notably on dns) and I'm super glad they are finally in Gluetun! A lot more to come in v3.42.0, there is already a pile of pull requests waiting 🚀

Final note, introducing the RANTING SECTION at the bottom of this changelog. This section might also be in the future releases (unfortunately)!

Happy holidays! 🎄 🎅 ❄️ ⛄

Features
  • DNS
    • (K8s users read this) Local network names resolution using private DNS resolvers found at container start (#​2970)
    • DNS over HTTPS support (see DNS_UPSTREAM_RESOLVER_TYPE below)
    • DNS_UPSTREAM_RESOLVER_TYPE option which can be dot (DNS over TLS), doh (DNS over HTTPS) or plain (plaintext over UDP)
    • DNS over TLS re-uses TCP connections which should put less stress on TCP-connections-rate-limiting by the VPN server
    • DNS requests blocked are logged with a reason
    • DNS rebinding protection is always enabled, but hostnames can be excluded with DNS_REBINDING_PROTECTION_EXEMPT_HOSTNAMES
    • i/o timeout errors are now logged at the debug level instead of warn level
  • healthcheck system reworked: more robust and less impact on other applications (#​2923)
    • Three checks are performed:
      • startup full check: when the VPN connection is first established, perform a TCP+TLS dial to HEALTH_TARGET_ADDRESSES with a timeout of 6 seconds
      • periodic full check: every 5 minutes, perform a TCP+TLS dial to HEALTH_TARGET_ADDRESSES, with up to 3 tries of 10s, 15s, and 30s timeouts
      • periodic small check: every minute, perform ICMP pings to HEALTH_ICMP_TARGET_IPS, with a fallback to plain DNS (UDP) lookups of github.com to cloudflare+google, with up to 10 tries of 5s, 5s, 5s, 10s, 10s, 10s, 15s, 15s, 15s, and 30s timeouts
    • If any of these checks fail, the VPN connection is restarted
    • Reduced impact on TCP to allow for higher bandwidth in TCP torrenting
    • New option HEALTH_TARGET_ADDRESSES=cloudflare.com:443,github.com:443 to have a fallback address
    • New option HEALTH_ICMP_TARGET_IPS=1.1.1.1,8.8.8.8 to have 8.8.8.8 as a fallback address
    • New option HEALTH_SMALL_CHECK_TYPE which can be dns or icmp. By default it uses icmp and falls back to dns if icmp isn't permitted.
    • New option HEALTH_RESTART_VPN: you should really leave it to on, unless you have trust issues with the healthcheck.
  • built-in servers data updates:
    • Cyberghost
    • ExpressVPN
    • Mullvad
    • Privado
    • Private Internet Access
    • SlickVPN (mere 29 hardcoded servers 🤷)
    • ProtonVPN
    • Surfshark
    • Torguard
  • control server:
    • HTTP_CONTROL_SERVER_AUTH_DEFAULT_ROLE option (JSON encoded). For example: {"auth":"basic","username":"me","password":"pass"} or {"auth":"apiKey","apikey":"xyz"} or {"auth":"none"}.
    • log number of roles read from auth file
  • VPN server side port forwarding:
    • support {{PORT}} template variable on top of {{PORTS}}
    • support {{VPN_INTERFACE}} template variable which is by default tun0
  • Public IP data fetcher queries all data sources in parallel and picks the most popular result
  • bump Alpine from 3.20 to 3.22
  • wireguard: on error parsing WIREGUARD_ENDPOINT_IP, mention it must be an IP address for the time being
  • new ascii logo logged out at program exit... did any of you spot it? 👀
Fixes
  • Wireguard:
    • specify IP family for new route (#​2629)
    • WIREGUARD_ENDPOINT_IP regression (v3.39.0) fixed to override the IP address of a picked connection
  • Providers specific:
    • Cyberghost: log warnings from updater resolver but not for "no such host" which happen quite a lot
    • ExpressVPN: update hardcoded servers data (#​2888)
    • ProtonVPN: authenticated servers data updating
      • If updating servers data periodically, use UPDATER_PROTONVPN_EMAIL and UPDATER_PROTONVPN_PASSWORD
      • If using the CLI, use -proton-email and -proton-password flags
    • PureVPN:
      • update OpenVPN configuration settings (from #​2991 credits to @​mlapaj)
      • updater parses country and city from hostname and merges with ip address information (#​2991)
    • VPN Unlimited: update certificates value (#​2835) and remove no longer valid hardcoded hosts
    • VPN Secure updater fixed by allowing their website servers list to have "N / A" region/city
    • WeVPN: removed since it decomissioned
  • Servers storage: do not crash the container but log a warning if flushing merged servers to file fails
  • VPN server side port forwarding:
    • clear port file instead of removing it (see why)
    • remove double log when clearing port forward file
  • Control server:
    • log out full URL path not just bottom request URI
    • change route with retrocompatibility from /v1/openvpn/portforwarded to /v1/portforward: this route has nothing to do with openvpn specifically, removed the ed in portforwarded to accomodate future routes such as changing the state of port forwarding
  • PUBLICIP_ENABLED is now respected
  • publicip/api/cloudflare: add now required Referer header (#​3058)
  • cli openvpnconfig command no longer panics due to missing SetDefaults call
  • DNS:
    • retry on next period if a blocklists update failed previously
    • fix DNS_KEEP_NAMESERVER behavior (by the way, you should no longer need to use this option!)
      • no longer hangs the code when establishing the VPN connection
      • no longer makes Gluetun panic when exiting
  • Healthcheck:
Documentation
  • Readme
    • remove no longer valid LoC badge
    • update Alpine version and image size
    • warning on "official" websites which are scams
    • add star history graph because it's fun
  • Dockerfile: specify default PUID and PGID to avoid confusion, since both are already defaulted to 1000 in the Go code
  • add pull request template (#​2918)
  • update provider issue template
Maintenance
  • Code
    • Change DNS option names with retro-compatibility:
      • DOT to DNS_SERVER
      • DOT_PROVIDERS to DNS_UPSTREAM_RESOLVERS
      • DOT_PRIVATE_ADDRESS to DNS_PRIVATE_ADDRESSES
      • DOT_CACHING to DNS_CACHING
      • DOT_IPV6 to DNS_UPSTREAM_IPV6
      • DOT_PRIVATE_ADDRESS split into DNS_BLOCK_IPS and DNS_BLOCK_IP_PREFIXES
      • UNBLOCK with DNS_UNBLOCK_HOSTNAMES
    • clear DNS_BLOCK_IP_PREFIXES values since DNS rebinding protection is built-in the filter middleware
    • internal/vpn: rename openvpn* to vpn* variables
    • internal/configuration/settings:
      • merge DoT settings with DNS settings
      • remove unneeded Health struct fields
    • internal/storage:
      • do not read/write to user file when updating in maintainer mode
      • ignore persisted servers data with a timestamp in the future
    • internal/publicip/api/ip2location: rename countries to match standard country names from the mapping constants.CountryCodes()`
  • dependencies
    • bump Go from 1.23 to 1.25
    • bump github.com/breml/rootcerts from 0.2.19 to 0.3.3 (#​2683, #​2964)
    • bump github.com/klauspost/compress from 1.17.11 to 1.18.1 (#​2957)
    • bump github.com/pelletier/go-toml/v2 from 2.2.3 to 2.2.4 (#​2958)
    • bump github.com/qdm12/dns from v2.0.0-rc8 to v2.0.0-rc10
    • bump github.com/stretchr/testify from 1.10.0 to 1.11.1 (#​2959)
    • bump github.com/ulikunitz/xz from 0.5.11 to 0.5.15 (#​2955)
    • bump github.com/vishvananda/netlink from 1.2.1 to 1.3.1 (#​2932)
    • bump golang.org/x/crypto from 0.29.0 to 0.45.0 (#​2619, #​2999)
    • bump golang.org/x/net from 0.31.0 to 0.47.0 (#​2648, #​2937, #​2976)
    • bump golang.org/x/sys from 0.29.0 to 0.38.0 (#​2939, #​2973)
    • bump golang.org/x/text from 0.21.0 to 0.31.0 (#​2938, #​2975)
  • upgrade linter to v2.4.0
    • migrate configuration file
    • fix existing code issues
    • add exclusion rules
    • update linter names
  • CI
    • run container and wait for it to connect for both Mullvad and ProtonVPN (#​2956)
    • bump github actions and use go.mod Go version (#​2880)
    • pull container images at build time from ghcr.io when possible
      • reduce silly image pull rate limiting from docker hub registry
      • still rely on docker hub registry to pull golang and alpine images since these are not on ghcr.io
    • ignore .github/pull_request_template.md with markdown linter
    • consider 429 as valid status code for markdown links
    • bump actions/setup-go from 5 to 6 (#​2929)
    • bump actions/checkout from 5 to 6 (#​3001)
    • bump DavidAnson/markdownlint-cli2-action from 18 to 21 (#​2632, #​2984)
    • bump github/codeql-action from 3 to 4 (#​2935)
    • bump peter-evans/create-or-update-comment from 4 to 5 (#​2931)
  • dev setup
    • upgrade dev container to v0.21
    • convert .vscode/launch.json to tasks.json
    • add vscode git remote add task
The ranting section
🥀 this is a new section in which I'll share my rant among various Gluetun-related things 🌻 💁 expect a lot of uppercasing, heavy punctuation and no structure whatsoever. Enjoy the read ❗

ALPINE!!! STOP BREAKING IPTABLES ON EVERY TWO RELEASES! When I enter iptables -nL, -n means NUMERIC! Then why the hell did 0 become all on Alpine 3.22??!!!?!
Gluetun was configured like clockwork to parse these numeric values, and all hell broke lose on some systems where it would return TEXTUAL values!

💁 2e2e5f9 and 6712adf for more information


PUREVPN did change everything for OpenVPN: certificates, keys, CAs. Like, can't you keep the previous ones working instead of breaking everyone? No-one was really warned on this as far as I know, so obviously Gluetun started failing more and more with PureVPN. Thanks to @​mlapaj for patching this and notifying me.


SlickVPN: Ok fine you're going bankrupt or something, but I spent hours programming code to scrape your locations webpage for you to just add some ugly-ass text directly to list your mere 11 servers left? Couldn't you update the table on your website, which, by the way, is still there below, but empty!!? What the heck!? I ended up throwing all my code and just hardcoding their silly 11 29 servers in Gluetun, because I'm not spending more hours fixing this scrapper, this is ridiculous.

https://www.slickvpn.com/locations/


Ok I'm not going to write the url here but it's h**ps://gluetun.com. It's an AI generated bullshlt website from some Pakistani idiot in the UK, trying to advertise for themselves to sell "website development" (=AI prompts). I did reach out to them telling them to please shut it down, no answer obviously. I suppose I should trademark gluetun... At least, since it's fully AI-generated, it's almost decent information and there is a bit of honesty in there, like "Not affiliated with Gluetun" at the bottom, although it also says "We at Gluetun" 😄


And keeping the best for last: PROTON!... Ah Proton... Proton Proton Proton...

First of all, let's start with Proton blocking their VPN servers data behind a login wall.
There is no reason for this. None. Zip. Zero. Nada.
You can literally connect to a VPN server with a free account.
And anyone with a paid account, including me, could just get that list and share it.
Absolute non-sense of a choice.

But, fine, let's see what's next...

I exchange with other Gluetun users trying to debug how to access this list, how to login programmatically to get that stupid list.
We all throw our keyboards at our monitor out of frustration because Proton's login system is an overly complex thing.
I decide to contact Proton support.

Ah, Proton "support"...
It's like subconsciously they want their users to run away.

I opened a support ticket explaining the situation, very politely of course, and simply asking for a tiny bit of guidance on helping out with the curl commands necessary to login and obtain a valid token.

Their answer? Polite "go away leave us alone" message:

Public access to the https://api.protonvpn.ch/vpn/logicals endpoint is no longer available due to internal changes and security reasons.

WHAT SECURITY REASONS!??? You are making a fool of yourselves Proton!

Additionally, the setup in question is not officially supported on our end; therefore, I will be unable to provide any steps on how to achieve it, nor guarantee that it will work.

DO YOU THINK I AM STUPID PROTON!??? AND THANKS FOR BEING SO HELPFUL YOU BUNCH OF 10-NEURONS SUPPORT!

We strongly recommend using the native Proton VPN apps on your devices or utilizing one of the downloaded configuration files if you wish to set up a manual connection https://account.protonvpn.com/downloads.

You sweet sweet summer child... Really, are you pretending to be a child now? PROTONNNNNN you are just an embarassment to the tech scene.

Have a nice weekend!

Yeah thanks for nothing and not even budging a tiny bit on anything.

I even then told them I would tell my users to avoid Proton like the plague because of this ridiculous behavior.
The answer? Basically same thing, reworded.

Guess what?

Well we figured out your authentication (#​2878), you unhelpful spineless wonders, so have fun blocking your own users from using your own VPN servers data...

But wait.... this is not even over; A few days later, a Gluetun user notices paid servers are not part of the Gluetun servers data.

Because Proton decided to hide away paid servers data from free users. Mind blown 🤯 This is absolutely stupid to its finest extent.

Anyway, I signed in with a paid account, re-updated the servers data. Done. Now your list is public. Congratulations Proton for your security measures, completely useless.

In conclusion... Proton is unhelpful and takes security decisions that make absolutely no sense.

Please migrate away from Proton whenever you can.


v3.40.4

Compare Source

Fixes

  • DNS:
    • prevent restart crash if DOT=off and DNS_KEEP_NAMESERVER=off
    • retry on next period the blocklists update after a failed update
  • WIREGUARD_ENDPOINT_IP overrides the IP address correctly (regression introduced in v3.39.0)
  • ExpressVPN hardcoded servers data updated (#​2888 - huge thanks to the manual work of @​Lobstrosity)
  • PureVPN OpenVPN configuration updated (from #​2991, credits to @​mlapaj)
  • SlickVPN updater: only keep 11 servers hardcoded and drop website scraping code
  • VPNSecure updater fixed, with region and city data allowed to be set to N / A
  • VPN Unlimited updater: no longer valid hardcoded hosts removed

v3.40.3

Compare Source

Fixes
  • Fixed previous fix on ProtonVPN: credentials are not required to be set.

v3.40.2

Compare Source

Fixes
  • DNS: fix DNS_KEEP_NAMESERVER behavior
    • no longer hangs the code when establishing the VPN connection
    • no longer makes Gluetun panic when exiting
  • ProtonVPN:
    • updater authentication fixed for some accounts
      • If updating servers data periodically, use UPDATER_PROTONVPN_EMAIL instead of UPDATER_PROTONVPN_USERNAME (retrocompatibility maintained)
      • If using the CLI, use -proton-email instead of -proton-username (retrocompatibility maintained)
    • ProtonVPN servers data updated to include paid servers
  • Servers storage: do not crash the container but log a warning if flushing merged servers to file fails

v3.40.1

Compare Source

Bug-fix-only release on top of v3.40.0.

v3.41.0 coming soon 🎉 If you have any issues with v3.40.0 please report it rather soon please 🙏 !

Fixes
  • Wireguard: specify IP family for new route (#​2629)
  • PUBLICIP_ENABLED is now respected
  • Port forwarding: clear port file instead of removing it (see why)
  • Control server: log out full URL path not just bottom request URI
  • cli openvpnconfig command no longer panics due to missing SetDefaults call
  • Providers specific:
    • Cyberghost: log warnings from updater resolver
    • ExpressVPN: update hardcoded servers data (#​2888) My mistake, the commit was forgotten. It will be part of v3.40.4. For now use the latest image.
    • ProtonVPN: authenticated servers data updating (#​2878)
    • VPN Unlimited: update certificates value (#​2835)

PS: sorry for the double notification, CI failed on the first release try

v3.40.0

Compare Source

Happy holidays release time 🎄 🎅 🎁

💁 If anything doesn't work compared to previous release, please create an issue and revert to using v3.39.1 😉

ℹ️ Life is pretty busy all around currently (moving soon, new job, ill parent) so I might be even slower than usual until summer 2025, I'll do my best!

Features
  • VPN: run WaitForDNS before querying the public ip address (partly address #​2325)
  • DNS: replace unbound with qdm12/dns@​v2.0.0-rc8 (#​1742 & later commits)
    • Faster start up
    • Clearer error messages
    • Allow for more Gluetun-specific customization
  • Port forwarding:
    • VPN_PORT_FORWARDING_UP_COMMAND option (#​2399)
    • VPN_PORT_FORWARDING_DOWN_COMMAND option
  • Config allow irrelevant server filters to be set (see #​2337)
    • Disallow setting a server filter when there is no choice available
    • Allow setting an invalid server filter when there is at least one choice available
    • Log at warn level when an invalid server filter is set
  • Firewall: support custom ICMP rules
  • Healthcheck:
    • log out last error when auto healing VPN
    • run TLS handshake after TCP dial if address has 443 port
  • Public IP:
    • retry fetching information when connection refused error is encountered (partly address #​2325)
    • support custom API url echoip#https://... (#​2529)
    • resilient public ip fetcher with backup sources (#​2518)
    • add ifconfigco option and cloudflare option (#​2502)
    • PUBLICIP_ENABLED replaces PUBLICIP_PERIOD
      • PUBLICIP_ENABLED (on, off) can be set to enable or not public ip data fetching on VPN connection
      • PUBLICIP_PERIOD=0 still works to indicate to disable public ip fetching
      • PUBLICIP_PERIOD != 0 means to enable public ip fetching
      • Warnings logged when using PUBLICIP_PERIOD
  • STORAGE_FILEPATH option (#​2416)
    • STORAGE_FILEPATH= disables storing to and reading from a local servers.json file
    • STORAGE_FILEPATH defaults to /gluetun/servers.json
  • Netlink: debug rule logs contain the ip family
  • internal/tun: mention in 'operation not permitted' error the user should specify --device /dev/net/tun (resolves #​2606)
  • Control server role based authentication system (#​2434) (part of v3.39.1 as a bugfix)
  • FastestVPN: add aes-256-gcm to OpenVPN ciphers list
  • Private Internet Access updater: use v6 API to get servers data
  • IPVanish: update servers data
  • PrivateVPN: native port forwarding support (#​2285)
  • Privado: update servers data
  • format-servers command supports the json format option
Fixes
  • Wireguard: change default WIREGUARD_MTU from 1400 to 1320 (partially address #​2533)
  • OpenVPN: set default mssfix to 1320 for all providers with no default already set (partially address #​2533)
  • Control server: fix logged wiki authentication section link
  • Firewall:
    • iptables list uses -n flag for testing iptables path (#​2574)
    • deduplicate VPN address accept rule for multiple default routes with the same network interface
    • deduplicate ipv6 multicast output accept rules
    • ipv6 multicast output address value fixed
    • log warning if ipv6 nat filter is not supported instead of returning an error (allow to port forward redirect for IPv4 and not IPv6 if IPv6 NAT is not supported and fixed #​2503)
  • Wireguard:
    • Point to Kubernetes wiki page when encountering IP rule add file exists error (#​2526)
  • IPVanish:
    • fix openvpn configuration by updating CA value and add comp-lzo option
    • update openvpn zip file url for updater
  • Perfect Privacy: update openvpn expired certificates (#​2542)
  • Public IP: lock settings during entire update to prevent race conditions
Documentation
  • Dockerfile
    • add missing OPENVPN_MSSFIX environment variable
    • add missing option definitions
      • STREAM_ONLY
      • FREE_ONLY
    • Document PORT_FORWARD_ONLY is for both PIA and ProtonVPN
Maintenance
Code quality
  • Remove github.com/qdm12/golibs dependency
    • Implement friendly duration formatting locally
    • implement github.com/qdm12/golibs/command locally (#​2418)
  • internal/natpmp: fix determinism for test Test_Client_ExternalAddress
  • let system handle OS signals after first one to request a program stop
  • internal/routing: remove redundant rule ip rule in error messages
  • internal/netlink debug log ip rule commands in netlink instead of routing package
  • internal/server: move log middleware to internal/server/middlewares/log
  • use gofumpt for code formatting
  • Fix gopls govet errors
  • Upgrade linter from v1.56.2 to v1.61.0
    • Remove no longer needed exclude rules
    • Add new exclude rules for printf govet errors
    • Remove deprecated linters execinquery and exportloopref
    • Rename linter goerr113 to err113 and gomnd to mnd
    • Add new linters and update codebase: canonicalheader, copyloopvar, fatcontext, intrange
Dependencies
  • Upgrade Go from 1.22 to 1.23
  • Bump vishvananda/netlink from v1.2.1-beta.2 to v1.2.1
  • Bump github.com/qdm12/gosettings from v0.4.3 to v0.4.4
    • Better support for quote expressions especially for commands such as VPN_PORT_FORWARDING_UP_COMMAND
  • Bump github.com/breml/rootcerts from 0.2.18 to 0.2.19 (#​2601)
  • Bump golang.org/x/net from 0.25.0 to 0.31.0 (#​2401, #​2578)
  • Bump golang.org/x/sys from 0.260.0 to 0.27.0 (#​2404, #​2573)
  • Bump golang.org/x/text from 0.15.0 to 0.17.0 (#​2400)
  • Bump github.com/klauspost/compress from 1.17.8 to 1.17.11 (#​2319, #​2550)
  • Bump github.com/pelletier/go-toml/v2 from 2.2.2 to 2.2.3 (#​2549)
  • Bump google.golang.org/protobuf from 1.30.0 to 1.33.0 (#​2428)
  • Bump github.com/stretchr/testify from 1.9.0 to 1.10.0 (#​2600)
CI
  • Linting: remove canonicalheader since it's not reliable
  • Use --device /dev/net/tun for test container
  • Bump DavidAnson/markdownlint-cli2-action from 16 to 18 (#​2588)
  • Bump docker/build-push-action from 5 to 6 (#​2324)
Development setup
  • dev container
    • pin godevcontainer image to tag :v0.20-alpine
    • drop requirement for docker-compose and use devcontainer.json settings directly
    • readme update
      • remove Windows without WSL step
      • update 'remote containers extension' to 'dev containers extension'
      • remove invalid warning on directories creation
      • simplify customizations section
        • remove "publish a port" since it can be done at runtime now
        • remove "run other services" since it's rather unneeded in this case
        • expand documentation on custom welcome script and where to specify the bind mount
          • use bullet points instead of subsections headings
  • Github labels
    • change "config problem" to "user error"
    • add "performance", "investigation", "servers storage" and "nearly resolved" categories

v3.39.1

Compare Source

🎥 https://youtu.be/O09rP1DlcFU?si=qPdzWUWnzciNxAc7

Fixes
  • Firewall: delete chain rules by line number (#​2411)
  • Control server: require authentication for vulnerable routes (#​2434)
  • NordVPN: remove commas from region values
  • IVPN: split city into city and region
    • Fix bad city values containing a comma
    • update ivpn servers data
  • Private Internet Access: support port forwarding using custom Wireguard (#​2420)
  • ProtonVPN: prevent using FREE_ONLY and PORT_FORWARD_ONLY together (see #​2470)
  • internal/storage: add missing selection fields to build noServerFoundError (see #​2470)

v3.39.0

Compare Source

🎥 Youtube video explaining all this

Features
  • OpenVPN: default version changed from 2.5 to 2.6
  • Alpine upgraded from 3.18 to 3.20 (3.19 got skipped due to buggy iptables)
  • Healthcheck: change timeout mechanism
    • Healthcheck timeout is no longer fixed to 3 seconds
    • Healthcheck timeout increases from 2s to 4s, 6s, 8s, 10s
    • No 1 second wait time between check retries after failure
    • VPN internal restart may be delayed by a maximum of 10 seconds
  • Firewall:
    • Query iptables binary variants to find which one to use depending on the kernel
    • Prefer using iptables-nft over iptables-legacy (Alpine new default is nft backend iptables)
  • Wireguard:
    • WIREGUARD_PERSISTENT_KEEPALIVE_INTERVAL option
    • read configuration file without case sensitivity
  • VPN Port forwarding: only use port forwarding enabled servers if VPN_PORT_FORWARDING=on (applies only to PIA and ProtonVPN for now)
  • FastestVPN:
    • Wireguard support (#​2383 - Credits to @​Zerauskire for the initial investigation and @​jvanderzande for an initial implementation as well as reviewing the pull request)
    • use API instead of openvpn zip file to fetch servers data
    • add city filter SERVER_CITY
    • update built-in servers data
  • Perfect Privacy: port forwarding support with VPN_PORT_FORWARDING=on (#​2378)
  • Private Internet Access: port forwarding options VPN_PORT_FORWARDING_USERNAME and VPN_PORT_FORWARDING_PASSWORD (retro-compatible with OPENVPN_USER and OPENVPN_PASSWORD)
  • ProtonVPN:
    • Wireguard support (#​2390)
    • feature filters SECURE_CORE_ONLY, TOR_ONLY and PORT_FORWARD_ONLY (#​2182)
    • determine "free" status using API tier value
    • update built-in servers data
  • Surfshark: servers data update
  • VPNSecure: servers data update
  • VPN_ENDPOINT_IP split into OPENVPN_ENDPOINT_IP and WIREGUARD_ENDPOINT_IP
  • VPN_ENDPOINT_PORT split into OPENVPN_ENDPOINT_PORT and WIREGUARD_ENDPOINT_PORT
Fixes
  • VPN_PORT_FORWARDING_LISTENING_PORT fixed
  • IPv6 support detection ignores loopback route destinations
  • Custom provider:
    • handle port option line for OpenVPN
    • ignore comments in an OpenVPN configuration file
    • assume port forwarding is always supported by a custom server
  • VPN Unlimited:
    • change default UDP port from 1194 to 1197
    • allow OpenVPN TCP on port 1197
  • Private Internet Access Wireguard and port forwarding
    • Set server name if names filter is set with the custom provider (see #​2147)
  • PrivateVPN: updater now sets openvpn vpn type for the no-hostname server
  • Torguard: update OpenVPN configuration
    • add aes-128-gcm and aes-128-cbc ciphers
    • remove mssfix, sndbuf, rcvbuf, ping and reneg options
  • VPNSecure: associate N / A with no data for servers
  • AirVPN: set default mssfix to 1320-28=1292
  • Surfshark: remove outdated hardcoded retro servers
  • Public IP echo:
    • ip2location parsing for latitude and longitude fixed
    • abort ip data fetch if vpn context is canceled (prevents requesting the public IP address N times after N VPN failures)
  • internal/server: /openvpn route status get and put
    • get status return stopped if running Wireguard
    • put status changes vpn type if running Wireguard
  • Log out if PORT_FORWARD_ONLY is enabled in the server filtering tree of settings
  • Log last Gluetun release by tag name alphabetically instead of by release date
  • format-servers fixed missing VPN type header for providers supporting Wireguard: NordVPN and Surfshark
  • internal/tun: only create tun device if it does not exist, do not create if it exists and does not work
Documentation
  • readme:
    • clarify shadowsocks proxy is a server, not a client
    • update list of providers supporting Wireguard with the custom provider
    • add protonvpn as custom port forwarding implementation
  • disable Github blank issues
  • Bump github.com/qdm12/gosplash to v0.2.0
    • Add /choose suffix to github links in logs
  • add Github labels: "Custom provider", "Category: logs" and "Before next release"
  • rename FIREWALL_ENABLED to FIREWALL_ENABLED_DISABLING_IT_SHOOTS_YOU_IN_YOUR_FOOT due to the sheer amount of users misusing it. FIREWALL_ENABLED won't do anything anymore. At least you've been warned not to use it...
Maintenance
  • Code health
    • PIA port forwarding:
      • remove dependency on storage package
      • return an error to port forwarding loop if server cannot port forward
    • internal/config:
      • upgrade to github.com/qdm12/gosettings v0.4.2
        • drop github.com/qdm12/govalid dependency
        • upgrade github.com/qdm12/ss-server to v0.6.0
        • do not un-set sensitive config settings anymore
      • removed bad/invalid retro-compatible keys CONTROL_SERVER_ADDRESS and CONTROL_SERVER_PORT
      • OpenVPN protocol field is now a string instead of a TCP boolean
      • Split server filter validation for features and subscription-tier
      • provider name field as string instead of string pointer
    • internal/portforward: support multiple ports forwarded
    • Fix typos in code comments (#​2216)
    • internal/tun: fix unit test for unprivileged user
  • Development environment
    • fix source.organizeImports vscode setting value
    • linter: remove now invalid skip-dirs configuration block
  • Dependencies
    • Bump Wireguard Go dependencies
    • Bump Go from 1.21 to 1.22
    • Bump golang.org/x/net from 0.19.0 to 0.25.0 (#​2138, #​2208, #​2269)
    • Bump golang.org/x/sys from 0.15.0 to 0.18.0 (#​2139)
    • Bump github.com/klauspost/compress from 1.17.4 to 1.17.8 (#​2178, #​2218)
    • Bump github.com/fatih/color from 1.16.0 to 1.17.0 (#​2279)
    • Bump github.com/stretchr/testify to v1.9.0
    • Do not upgrade busybox since vulnerabilities are fixed now with Alpine 3.19+
  • CI
    • Bump DavidAnson/markdownlint-cli2-action from 14 to 16 (#​2214)
    • Bump peter-evans/dockerhub-description from 3 to 4 (#​2075)
  • Github
    • remove empty label description fields
    • add /choose suffix to issue and discussion links
    • review all issue labels: add closed labels, add category labels, rename labels, add label category prefix, add emojis for each label
    • Add issue labels: Popularity extreme and high, Closed cannot be done, Categories kernel and public IP service

v3.38.1

Compare Source

ℹ️ This is a bugfix release for v3.38.0. If you can, please instead use release v3.39.0

Fixes
  • VPN_PORT_FORWARDING_LISTENING_PORT fixed
  • IPv6 support detection ignores loopback route destinations
  • Custom provider:
    • handle port option line for OpenVPN
    • ignore comments in an OpenVPN configuration file
    • assume port forwarding is always supported by a custom server
  • VPN Unlimited:
    • change default UDP port from 1194 to 1197
    • allow OpenVPN TCP on port 1197
  • Private Internet Access Wireguard and port forwarding
    • Set server name if names filter is set with the custom provider (see #​2147)
  • PrivateVPN: updater now sets openvpn vpn type for the no-hostname server
  • Torguard: update OpenVPN configuration
    • add aes-128-gcm and aes-128-cbc ciphers
    • remove mssfix, sndbuf, rcvbuf, ping and reneg options
  • VPNSecure: associate N / A with no data for servers
  • AirVPN: set default mssfix to 1320-28=1292
  • Surfshark: remove outdated hardcoded retro servers
  • Public IP echo:
    • ip2location parsing for latitude and longitude fixed
    • abort ip data fetch if vpn context is canceled (prevents requesting the public IP address N times after N VPN failures)
  • internal/server: /openvpn route status get and put
    • get status return stopped if running Wireguard
    • put status changes vpn type if running Wireguard
  • Log out if PORT_FORWARD_ONLY is enabled in the server filtering tree of settings
  • Log last Gluetun release by tag name alphabetically instead of by release date
  • format-servers fixed missing VPN type header for providers supporting Wireguard: NordVPN and Surfshark
  • internal/tun: only create tun device if it does not exist, do not create if it exists and does not work

Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@carpenike-bot

carpenike-bot Bot commented Aug 9, 2024

Copy link
Copy Markdown
Contributor
--- kubernetes/cluster-0/apps/vpn/pod-gateway/media Kustomization: flux-system/cluster-apps-pod-gateway-media HelmRelease: vpn/media-gateway

+++ kubernetes/cluster-0/apps/vpn/pod-gateway/media Kustomization: flux-system/cluster-apps-pod-gateway-media HelmRelease: vpn/media-gateway

@@ -57,13 +57,13 @@

           valueFrom:
             secretKeyRef:
               key: WIREGUARD_ADDRESSES
               name: media-gateway-vpnconfig
         image:
           repository: ghcr.io/qdm12/gluetun
-          tag: v3.38.0@sha256:5522794f5cce6d84bc7f06b1e3a3b836ede9100c64aec94543cb503bb2ecb72f
+          tag: v3.40.0@sha256:2b42bfa046757145a5155acece417b65b4443c8033fb88661a8e9dcf7fda5a00
         resources:
           limits:
             memory: 128M
           requests:
             cpu: 5m
             memory: 128M

@carpenike-bot

carpenike-bot Bot commented Aug 9, 2024

Copy link
Copy Markdown
Contributor

🦙 MegaLinter status: ❌ ERROR

Descriptor Linter Files Fixed Errors Warnings Elapsed time
❌ COPYPASTE jscpd yes 2 no 1.48s
✅ REPOSITORY git_diff yes no no 0.05s
✅ REPOSITORY secretlint yes no no 3.86s
✅ YAML prettier 1 0 0 0.54s
✅ YAML yamllint 1 0 0 0.64s

See detailed report in MegaLinter reports
Set VALIDATE_ALL_CODEBASE: true in mega-linter.yml to validate all sources, not only the diff

MegaLinter is graciously provided by OX Security

@renovate
renovate Bot force-pushed the renovate/cluster-0-ghcr.io-qdm12-gluetun-3.x branch from 775238b to cec2222 Compare September 29, 2024 19:25
@renovate renovate Bot changed the title feat(container): update image ghcr.io/qdm12/gluetun ( v3.38.0 → v3.39.0 ) feat(container): update image ghcr.io/qdm12/gluetun ( v3.38.0 → v3.39.1 ) Sep 29, 2024
@renovate
renovate Bot force-pushed the renovate/cluster-0-ghcr.io-qdm12-gluetun-3.x branch from cec2222 to cc246be Compare December 25, 2024 23:03
@renovate renovate Bot changed the title feat(container): update image ghcr.io/qdm12/gluetun ( v3.38.0 → v3.39.1 ) feat(container): update image ghcr.io/qdm12/gluetun ( v3.38.0 → v3.40.0 ) Dec 25, 2024
@renovate
renovate Bot force-pushed the renovate/cluster-0-ghcr.io-qdm12-gluetun-3.x branch from cc246be to 3236346 Compare November 15, 2025 18:47
@renovate renovate Bot changed the title feat(container): update image ghcr.io/qdm12/gluetun ( v3.38.0 → v3.40.0 ) feat(container): update image ghcr.io/qdm12/gluetun ( v3.38.0 → v3.40.1 ) Nov 15, 2025
@renovate renovate Bot changed the title feat(container): update image ghcr.io/qdm12/gluetun ( v3.38.0 → v3.40.1 ) feat(container): update image ghcr.io/qdm12/gluetun ( v3.38.0 → v3.40.3 ) Nov 19, 2025
@renovate
renovate Bot force-pushed the renovate/cluster-0-ghcr.io-qdm12-gluetun-3.x branch from 3236346 to 3890f6f Compare November 19, 2025 00:57
@renovate
renovate Bot force-pushed the renovate/cluster-0-ghcr.io-qdm12-gluetun-3.x branch from 3890f6f to 309306f Compare December 24, 2025 04:27
@renovate renovate Bot changed the title feat(container): update image ghcr.io/qdm12/gluetun ( v3.38.0 → v3.40.3 ) feat(container): update image ghcr.io/qdm12/gluetun ( v3.38.0 → v3.40.4 ) Dec 24, 2025
@renovate
renovate Bot force-pushed the renovate/cluster-0-ghcr.io-qdm12-gluetun-3.x branch from 309306f to 909be77 Compare December 25, 2025 01:30
@renovate renovate Bot changed the title feat(container): update image ghcr.io/qdm12/gluetun ( v3.38.0 → v3.40.4 ) feat(container): update image ghcr.io/qdm12/gluetun ( v3.38.0 → v3.41.0 ) Dec 25, 2025
@renovate renovate Bot changed the title feat(container): update image ghcr.io/qdm12/gluetun ( v3.38.0 → v3.41.0 ) feat(container): update image ghcr.io/qdm12/gluetun ( v3.38.0 → v3.41.1 ) Feb 11, 2026
@renovate
renovate Bot force-pushed the renovate/cluster-0-ghcr.io-qdm12-gluetun-3.x branch from 909be77 to 2ea25b9 Compare February 11, 2026 15:04
@renovate
renovate Bot force-pushed the renovate/cluster-0-ghcr.io-qdm12-gluetun-3.x branch from 2ea25b9 to 06479c9 Compare June 22, 2026 17:40
@renovate
renovate Bot force-pushed the renovate/cluster-0-ghcr.io-qdm12-gluetun-3.x branch from 06479c9 to 4d0a91e Compare July 20, 2026 21:52
@renovate
renovate Bot force-pushed the renovate/cluster-0-ghcr.io-qdm12-gluetun-3.x branch from 4d0a91e to dee13d5 Compare July 29, 2026 14:05
@renovate renovate Bot changed the title feat(container): update image ghcr.io/qdm12/gluetun ( v3.38.0 → v3.41.1 ) feat(container): update image ghcr.io/qdm12/gluetun ( v3.38.0 → v3.41.2 ) Jul 29, 2026
@renovate renovate Bot changed the title feat(container): update image ghcr.io/qdm12/gluetun ( v3.38.0 → v3.41.2 ) feat(container): update image ghcr.io/qdm12/gluetun ( v3.38.0 → v3.41.3 ) Jul 30, 2026
@renovate
renovate Bot force-pushed the renovate/cluster-0-ghcr.io-qdm12-gluetun-3.x branch from dee13d5 to e625bfa Compare July 30, 2026 17:52
@renovate renovate Bot changed the title feat(container): update image ghcr.io/qdm12/gluetun ( v3.38.0 → v3.41.3 ) feat(container): update image ghcr.io/qdm12/gluetun ( v3.38.0 → v3.41.3 ) - autoclosed Aug 10, 2026
@renovate renovate Bot closed this Aug 10, 2026
@renovate
renovate Bot deleted the renovate/cluster-0-ghcr.io-qdm12-gluetun-3.x branch August 10, 2026 19:14
….3 )

| datasource | package               | from    | to      |
| ---------- | --------------------- | ------- | ------- |
| docker     | ghcr.io/qdm12/gluetun | v3.38.0 | v3.41.3 |
@renovate renovate Bot changed the title feat(container): update image ghcr.io/qdm12/gluetun ( v3.38.0 → v3.41.3 ) - autoclosed feat(container): update image ghcr.io/qdm12/gluetun ( v3.38.0 → v3.41.3 ) Aug 10, 2026
@renovate renovate Bot reopened this Aug 10, 2026
@renovate
renovate Bot force-pushed the renovate/cluster-0-ghcr.io-qdm12-gluetun-3.x branch 2 times, most recently from e625bfa to eb785a8 Compare August 10, 2026 23:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants