feat(container): update image ghcr.io/qdm12/gluetun ( v3.38.0 → v3.41.3 ) - #5379
Open
renovate[bot] wants to merge 1 commit into
Open
feat(container): update image ghcr.io/qdm12/gluetun ( v3.38.0 → v3.41.3 )#5379renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
Contributor
--- kubernetes/cluster-0/apps/vpn/pod-gateway/media Kustomization: flux-system/cluster-apps-pod-gateway-media HelmRelease: vpn/media-gateway
+++ kubernetes/cluster-0/apps/vpn/pod-gateway/media Kustomization: flux-system/cluster-apps-pod-gateway-media HelmRelease: vpn/media-gateway
@@ -57,13 +57,13 @@
valueFrom:
secretKeyRef:
key: WIREGUARD_ADDRESSES
name: media-gateway-vpnconfig
image:
repository: ghcr.io/qdm12/gluetun
- tag: v3.38.0@sha256:5522794f5cce6d84bc7f06b1e3a3b836ede9100c64aec94543cb503bb2ecb72f
+ tag: v3.40.0@sha256:2b42bfa046757145a5155acece417b65b4443c8033fb88661a8e9dcf7fda5a00
resources:
limits:
memory: 128M
requests:
cpu: 5m
memory: 128M |
Contributor
🦙 MegaLinter status: ❌ ERROR
See detailed report in MegaLinter reports |
renovate
Bot
force-pushed
the
renovate/cluster-0-ghcr.io-qdm12-gluetun-3.x
branch
from
September 29, 2024 19:25
775238b to
cec2222
Compare
renovate
Bot
force-pushed
the
renovate/cluster-0-ghcr.io-qdm12-gluetun-3.x
branch
from
December 25, 2024 23:03
cec2222 to
cc246be
Compare
renovate
Bot
force-pushed
the
renovate/cluster-0-ghcr.io-qdm12-gluetun-3.x
branch
from
November 15, 2025 18:47
cc246be to
3236346
Compare
renovate
Bot
force-pushed
the
renovate/cluster-0-ghcr.io-qdm12-gluetun-3.x
branch
from
November 19, 2025 00:57
3236346 to
3890f6f
Compare
renovate
Bot
force-pushed
the
renovate/cluster-0-ghcr.io-qdm12-gluetun-3.x
branch
from
December 24, 2025 04:27
3890f6f to
309306f
Compare
renovate
Bot
force-pushed
the
renovate/cluster-0-ghcr.io-qdm12-gluetun-3.x
branch
from
December 25, 2025 01:30
309306f to
909be77
Compare
renovate
Bot
force-pushed
the
renovate/cluster-0-ghcr.io-qdm12-gluetun-3.x
branch
from
February 11, 2026 15:04
909be77 to
2ea25b9
Compare
renovate
Bot
force-pushed
the
renovate/cluster-0-ghcr.io-qdm12-gluetun-3.x
branch
from
June 22, 2026 17:40
2ea25b9 to
06479c9
Compare
renovate
Bot
force-pushed
the
renovate/cluster-0-ghcr.io-qdm12-gluetun-3.x
branch
from
July 20, 2026 21:52
06479c9 to
4d0a91e
Compare
renovate
Bot
force-pushed
the
renovate/cluster-0-ghcr.io-qdm12-gluetun-3.x
branch
from
July 29, 2026 14:05
4d0a91e to
dee13d5
Compare
renovate
Bot
force-pushed
the
renovate/cluster-0-ghcr.io-qdm12-gluetun-3.x
branch
from
July 30, 2026 17:52
dee13d5 to
e625bfa
Compare
….3 ) | datasource | package | from | to | | ---------- | --------------------- | ------- | ------- | | docker | ghcr.io/qdm12/gluetun | v3.38.0 | v3.41.3 |
renovate
Bot
force-pushed
the
renovate/cluster-0-ghcr.io-qdm12-gluetun-3.x
branch
2 times, most recently
from
August 10, 2026 23:03
e625bfa to
eb785a8
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

This PR contains the following updates:
v3.38.0→v3.41.3Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
passteque/gluetun (ghcr.io/qdm12/gluetun)
v3.41.3Compare Source
This fixes a VPN server port forwarding deadlock bug introduced whilst back-porting a fix from the
masterbranch (:latestimage) tov3.41.2. Credits to @robinostlund for reporting the bug and even nailing down what it was! (#3416)Refer to v3.41.2 fixes in case you haven't checked.
v3.41.2Compare Source
Fixes
tcp-clientproto tcp-clientwhen using TCPtcp-client(on top oftcp,tcp4,tcp6) as meaning TCP-dnsflag in update commandportandportsfor both single port and multiple ports forwardedinternal/command: fix rare race condition on log line stream at command completionProvider specific fixes
8a75e46)PS:
v3.41.1Compare Source
Fixes
v3.41.0Compare Source
Video of me reading out this release
Thank you all for your patience for this release which took its sweet time 🙏⏲️
I have been rather absent in a good part of 2025 due to work and life getting in the way, and I would like to thank many of you for helping out around in issues and discussions, and for the few code contributors whilst I was away.
On this release, many of the features you see are the result of behind-the-scene work of the last few years (notably on dns) and I'm super glad they are finally in Gluetun! A lot more to come in v3.42.0, there is already a pile of pull requests waiting 🚀
Final note, introducing the RANTING SECTION at the bottom of this changelog. This section might also be in the future releases (unfortunately)!
Happy holidays! 🎄 🎅 ❄️ ⛄
Features
DNS_UPSTREAM_RESOLVER_TYPEbelow)DNS_UPSTREAM_RESOLVER_TYPEoption which can bedot(DNS over TLS),doh(DNS over HTTPS) orplain(plaintext over UDP)DNS_REBINDING_PROTECTION_EXEMPT_HOSTNAMESi/o timeouterrors are now logged at the debug level instead of warn levelHEALTH_TARGET_ADDRESSESwith a timeout of 6 secondsHEALTH_TARGET_ADDRESSES, with up to 3 tries of 10s, 15s, and 30s timeoutsHEALTH_ICMP_TARGET_IPS, with a fallback to plain DNS (UDP) lookups ofgithub.comto cloudflare+google, with up to 10 tries of 5s, 5s, 5s, 10s, 10s, 10s, 15s, 15s, 15s, and 30s timeoutsHEALTH_TARGET_ADDRESSES=cloudflare.com:443,github.com:443to have a fallback addressHEALTH_ICMP_TARGET_IPS=1.1.1.1,8.8.8.8to have8.8.8.8as a fallback addressHEALTH_SMALL_CHECK_TYPEwhich can bednsoricmp. By default it uses icmp and falls back to dns if icmp isn't permitted.HEALTH_RESTART_VPN: you should really leave it toon, unless you have trust issues with the healthcheck.HTTP_CONTROL_SERVER_AUTH_DEFAULT_ROLEoption (JSON encoded). For example:{"auth":"basic","username":"me","password":"pass"}or{"auth":"apiKey","apikey":"xyz"}or{"auth":"none"}.{{PORT}}template variable on top of{{PORTS}}{{VPN_INTERFACE}}template variable which is by defaulttun0WIREGUARD_ENDPOINT_IP, mention it must be an IP address for the time beingFixes
WIREGUARD_ENDPOINT_IPregression (v3.39.0) fixed to override the IP address of a picked connectionUPDATER_PROTONVPN_EMAILandUPDATER_PROTONVPN_PASSWORD-proton-emailand-proton-passwordflags/v1/openvpn/portforwardedto/v1/portforward: this route has nothing to do with openvpn specifically, removed theedinportforwardedto accomodate future routes such as changing the state of port forwardingPUBLICIP_ENABLEDis now respectedRefererheader (#3058)openvpnconfigcommand no longer panics due to missingSetDefaultscallDNS_KEEP_NAMESERVERbehavior (by the way, you should no longer need to use this option!)Documentation
Maintenance
DOTtoDNS_SERVERDOT_PROVIDERStoDNS_UPSTREAM_RESOLVERSDOT_PRIVATE_ADDRESStoDNS_PRIVATE_ADDRESSESDOT_CACHINGtoDNS_CACHINGDOT_IPV6toDNS_UPSTREAM_IPV6DOT_PRIVATE_ADDRESSsplit intoDNS_BLOCK_IPSandDNS_BLOCK_IP_PREFIXESUNBLOCKwithDNS_UNBLOCK_HOSTNAMESDNS_BLOCK_IP_PREFIXESvalues since DNS rebinding protection is built-in the filter middlewareopenvpn*tovpn*variablesinternal/storage:internal/publicip/api/ip2location: rename countries to match standard country names from the mappingconstants.CountryCodes()`git remote addtaskThe ranting section
🥀 this is a new section in which I'll share my rant among various Gluetun-related things 🌻 💁 expect a lot of uppercasing, heavy punctuation and no structure whatsoever. Enjoy the read ❗
ALPINE!!! STOP BREAKING IPTABLES ON EVERY TWO RELEASES! When I enter
iptables -nL,-nmeans NUMERIC! Then why the hell did0becomeallon Alpine 3.22??!!!?!Gluetun was configured like clockwork to parse these numeric values, and all hell broke lose on some systems where it would return TEXTUAL values!
💁
2e2e5f9and6712adffor more informationPUREVPN did change everything for OpenVPN: certificates, keys, CAs. Like, can't you keep the previous ones working instead of breaking everyone? No-one was really warned on this as far as I know, so obviously Gluetun started failing more and more with PureVPN. Thanks to @mlapaj for patching this and notifying me.
SlickVPN: Ok fine you're going bankrupt or something, but I spent hours programming code to scrape your locations webpage for you to just add some ugly-ass text directly to list your mere 11 servers left? Couldn't you update the table on your website, which, by the way, is still there below, but empty!!? What the heck!? I ended up throwing all my code and just hardcoding their silly
1129 servers in Gluetun, because I'm not spending more hours fixing this scrapper, this is ridiculous.https://www.slickvpn.com/locations/
Ok I'm not going to write the url here but it's
h**ps://gluetun.com. It's an AI generated bullshlt website from some Pakistani idiot in the UK, trying to advertise for themselves to sell "website development" (=AI prompts). I did reach out to them telling them to please shut it down, no answer obviously. I suppose I should trademark gluetun... At least, since it's fully AI-generated, it's almost decent information and there is a bit of honesty in there, like "Not affiliated with Gluetun" at the bottom, although it also says "We at Gluetun" 😄And keeping the best for last: PROTON!... Ah Proton... Proton Proton Proton...
First of all, let's start with Proton blocking their VPN servers data behind a login wall.
There is no reason for this. None. Zip. Zero. Nada.
You can literally connect to a VPN server with a free account.
And anyone with a paid account, including me, could just get that list and share it.
Absolute non-sense of a choice.
But, fine, let's see what's next...
I exchange with other Gluetun users trying to debug how to access this list, how to login programmatically to get that stupid list.
We all throw our keyboards at our monitor out of frustration because Proton's login system is an overly complex thing.
I decide to contact Proton support.
Ah, Proton "support"...
It's like subconsciously they want their users to run away.
I opened a support ticket explaining the situation, very politely of course, and simply asking for a tiny bit of guidance on helping out with the
curlcommands necessary to login and obtain a valid token.Their answer? Polite "go away leave us alone" message:
WHAT SECURITY REASONS!??? You are making a fool of yourselves Proton!
DO YOU THINK I AM STUPID PROTON!??? AND THANKS FOR BEING SO HELPFUL YOU BUNCH OF 10-NEURONS SUPPORT!
You sweet sweet summer child... Really, are you pretending to be a child now? PROTONNNNNN you are just an embarassment to the tech scene.
Yeah thanks for nothing and not even budging a tiny bit on anything.
I even then told them I would tell my users to avoid Proton like the plague because of this ridiculous behavior.
The answer? Basically same thing, reworded.
Guess what?
Well we figured out your authentication (#2878), you unhelpful spineless wonders, so have fun blocking your own users from using your own VPN servers data...
But wait.... this is not even over; A few days later, a Gluetun user notices paid servers are not part of the Gluetun servers data.
Because Proton decided to hide away paid servers data from free users. Mind blown 🤯 This is absolutely stupid to its finest extent.
Anyway, I signed in with a paid account, re-updated the servers data. Done. Now your list is public. Congratulations Proton for your security measures, completely useless.
In conclusion... Proton is unhelpful and takes security decisions that make absolutely no sense.
Please migrate away from Proton whenever you can.
v3.40.4Compare Source
Fixes
DOT=offandDNS_KEEP_NAMESERVER=offWIREGUARD_ENDPOINT_IPoverrides the IP address correctly (regression introduced in v3.39.0)N / Av3.40.3Compare Source
Fixes
v3.40.2Compare Source
Fixes
DNS_KEEP_NAMESERVERbehaviorUPDATER_PROTONVPN_EMAILinstead ofUPDATER_PROTONVPN_USERNAME(retrocompatibility maintained)-proton-emailinstead of-proton-username(retrocompatibility maintained)v3.40.1Compare Source
Bug-fix-only release on top of v3.40.0.
v3.41.0 coming soon 🎉 If you have any issues with v3.40.0 please report it rather soon please 🙏 !
Fixes
PUBLICIP_ENABLEDis now respectedopenvpnconfigcommand no longer panics due to missingSetDefaultscallExpressVPN: update hardcoded servers data (#2888)My mistake, the commit was forgotten. It will be part of v3.40.4. For now use the latest image.PS: sorry for the double notification, CI failed on the first release try
v3.40.0Compare Source
Happy holidays release time 🎄 🎅 🎁
💁 If anything doesn't work compared to previous release, please create an issue and revert to using v3.39.1 😉
ℹ️ Life is pretty busy all around currently (moving soon, new job, ill parent) so I might be even slower than usual until summer 2025, I'll do my best!
Features
WaitForDNSbefore querying the public ip address (partly address #2325)VPN_PORT_FORWARDING_UP_COMMANDoption (#2399)VPN_PORT_FORWARDING_DOWN_COMMANDoptionconnection refusederror is encountered (partly address #2325)echoip#https://...(#2529)ifconfigcooption andcloudflareoption (#2502)PUBLICIP_ENABLEDreplacesPUBLICIP_PERIODPUBLICIP_ENABLED(on, off) can be set to enable or not public ip data fetching on VPN connectionPUBLICIP_PERIOD=0still works to indicate to disable public ip fetchingPUBLICIP_PERIOD!= 0 means to enable public ip fetchingPUBLICIP_PERIODSTORAGE_FILEPATHoption (#2416)STORAGE_FILEPATH=disables storing to and reading from a local servers.json fileSTORAGE_FILEPATHdefaults to/gluetun/servers.jsoninternal/tun: mention in 'operation not permitted' error the user should specify--device /dev/net/tun(resolves #2606)genkeycommand to generate API keysaes-256-gcmto OpenVPN ciphers listformat-serverscommand supports the json format optionFixes
WIREGUARD_MTUfrom1400to1320(partially address #2533)-nflag for testing iptables path (#2574)comp-lzooptionDocumentation
OPENVPN_MSSFIXenvironment variableSTREAM_ONLYFREE_ONLYPORT_FORWARD_ONLYis for both PIA and ProtonVPNMaintenance
Code quality
github.com/qdm12/golibs/commandlocally (#2418)internal/natpmp: fix determinism for testTest_Client_ExternalAddressinternal/routing: remove redundantrule ip rulein error messagesinternal/netlinkdebug log ip rule commands in netlink instead of routing packageinternal/server: move log middleware tointernal/server/middlewares/loggofumptfor code formattingexecinqueryandexportlooprefgoerr113toerr113andgomndtomndcanonicalheader,copyloopvar,fatcontext,intrangeDependencies
VPN_PORT_FORWARDING_UP_COMMANDCI
canonicalheadersince it's not reliable--device /dev/net/tunfor test containerDevelopment setup
:v0.20-alpinedevcontainer.jsonsettings directlyv3.39.1Compare Source
🎥 https://youtu.be/O09rP1DlcFU?si=qPdzWUWnzciNxAc7
Fixes
internal/storage: add missing selection fields to buildnoServerFoundError(see #2470)v3.39.0Compare Source
🎥 Youtube video explaining all this
Features
iptables)iptables-nftoveriptables-legacy(Alpine new default is nft backend iptables)WIREGUARD_PERSISTENT_KEEPALIVE_INTERVALoptionVPN_PORT_FORWARDING=on(applies only to PIA and ProtonVPN for now)SERVER_CITYVPN_PORT_FORWARDING=on(#2378)VPN_PORT_FORWARDING_USERNAMEandVPN_PORT_FORWARDING_PASSWORD(retro-compatible withOPENVPN_USERandOPENVPN_PASSWORD)SECURE_CORE_ONLY,TOR_ONLYandPORT_FORWARD_ONLY(#2182)VPN_ENDPOINT_IPsplit intoOPENVPN_ENDPOINT_IPandWIREGUARD_ENDPOINT_IPVPN_ENDPOINT_PORTsplit intoOPENVPN_ENDPOINT_PORTandWIREGUARD_ENDPOINT_PORTFixes
VPN_PORT_FORWARDING_LISTENING_PORTfixedportoption line for OpenVPNN / Awith no data for serversinternal/server:/openvpnroute status get and putPORT_FORWARD_ONLYis enabled in the server filtering tree of settingsformat-serversfixed missing VPN type header for providers supporting Wireguard: NordVPN and Surfsharkinternal/tun: only create tun device if it does not exist, do not create if it exists and does not workDocumentation
/choosesuffix to github links in logsFIREWALL_ENABLEDtoFIREWALL_ENABLED_DISABLING_IT_SHOOTS_YOU_IN_YOUR_FOOTdue to the sheer amount of users misusing it.FIREWALL_ENABLEDwon't do anything anymore. At least you've been warned not to use it...Maintenance
internal/config:github.com/qdm12/gosettingsv0.4.2github.com/qdm12/govaliddependencygithub.com/qdm12/ss-serverto v0.6.0CONTROL_SERVER_ADDRESSandCONTROL_SERVER_PORTinternal/portforward: support multiple ports forwardedinternal/tun: fix unit test for unprivileged usersource.organizeImportsvscode setting value/choosesuffix to issue and discussion linksv3.38.1Compare Source
ℹ️ This is a bugfix release for v3.38.0. If you can, please instead use release v3.39.0
Fixes
VPN_PORT_FORWARDING_LISTENING_PORTfixedportoption line for OpenVPNN / Awith no data for serversinternal/server:/openvpnroute status get and putPORT_FORWARD_ONLYis enabled in the server filtering tree of settingsformat-serversfixed missing VPN type header for providers supporting Wireguard: NordVPN and Surfsharkinternal/tun: only create tun device if it does not exist, do not create if it exists and does not workConfiguration
📅 Schedule: (in timezone America/New_York)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.