# Changelog All notable changes to this project will be documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/), and this project adheres to date-based versioning (YYYY-MM.x). ## [2026-08.1] - 2026-08-01 ### Added - **Native deployment type**: Wallarm filtering node can now be deployed directly on the OS **without Docker** - `native/wallarm-ct-check.sh` – Preflight validation for native deployment (no Docker artifact checks) - `native/wallarm-ct-deploy.sh` – Downloads and runs the official Wallarm all-in-one installer (`meganode.wallarm.com`, version configurable via `WALLARM_VERSION`), configures the NGINX server block, reloads and verifies the node - `native/wallarm-ct-reconfigure.sh` – Update trusted proxies / `wallarm_mode` via NGINX test + reload - `native/wallarm-ct-uninstall.sh` – Remove NGINX config, Wallarm packages/repos, and `/opt/wallarm` data - **Unified node manager**: `native/wallarm-native.sh` – single-script manager for the Wallarm Native Node (go-node, connector-server mode) - `--preflight` checks (root, systemd, architecture, required commands, installer + Wallarm cloud connectivity, disk/memory, listen-port availability); auto-run before `--install` - Interactive parallel multi-node installation with per-node systemd template units (`wallarm-node@.service`) - `--config` (address/token/labels, safe env rewrite), `--remove`, `--status [NODE]` - All-in-one installer from `repo.wallarm.com` (overridable via `WALLARM_INSTALLER_URL`/`WALLARM_INSTALLER_ARCH`) - **Shared library**: `common/wallarm-lib.sh` extracted and reused by both deployment types - Colors, logging (`log_message`, `fail_with_remediation`), early error handler - System detection (OS/arch/init), network connectivity tests - Preflight `.env` parsing (`load_env_file`), cloud region selection (`select_cloud_region`) - Validation helpers (IP, CIDR, port), artifact download + checksum verification ### Changed - **Repository structure** now separates deployment types: - `docker/` – all Docker-based scripts moved here (`git mv`, history preserved) - `docker/binaries/` and `docker/images/` – Docker artifacts moved into the Docker tree - `native/` – new native (no-Docker) deployment scripts - `common/` – shared library - **Artifact URLs** updated to the `docker/` prefix (`/docker/binaries/...`, `/docker/images/...`) - **Docker scripts** refactored to source `common/wallarm-lib.sh` (removed duplicated helper functions; behavior preserved) - **setup.sh** now prompts for a deployment type (`docker` or `native`), downloads the matching scripts into `docker/` or `native/` (native now includes `wallarm-native.sh`); supports `DEPLOYMENT_TYPE=native` for non-interactive use - **README.md** rewritten to document both deployment types, the new structure, the unified manager, and native-specific usage ### Notes - Native deployment supports one node per host (system NGINX); multi-node remains a Docker feature - Native installer version defaults to `6.12.7` and can be pinned via `WALLARM_VERSION` - Docker deployment behavior is unchanged apart from the new directory layout - The unified manager targets the Wallarm **Native Node** product; the `native/wallarm-ct-*.sh` scripts target the **NGINX-module** native deployment. Both are no-Docker options ## [2026-04.1] - 2026-04-21 ### Added - Initial changelog file with versioning schema - Date-based versioning system (YYYY-MM.x) ### Changed - **Variable renaming**: All `GITLAB_*` variables renamed to `GIT_*` prefix - `GITLAB_BASE_URL` → `GIT_BASE_URL` - `GITLAB_RAW_URL` → `GIT_RAW_URL` (with updated path) - `GITLAB_DOCKER_BINARY_URL` → `GIT_DOCKER_BINARY_URL` - `GITLAB_DOCKER_CHECKSUM_URL` → `GIT_DOCKER_CHECKSUM_URL` - `GITLAB_WALLARM_IMAGE_URL` → `GIT_WALLARM_IMAGE_URL` - `GITLAB_WALLARM_CHECKSUM_URL` → `GIT_WALLARM_CHECKSUM_URL` - `GITLAB_REACHABLE` → `GIT_REACHABLE` - **URL structure**: Updated `GIT_RAW_URL` from `/-/raw/main` to `/raw/branch/main` path (corrected for download compatibility) - **Terminology**: Replaced all "GitLab" references in comments and log messages with "Git Repositorys" - **Documentation**: Updated README.md to reflect new terminology - **URL correction**: Corrected setup.sh download URL in README.md back to `/raw/branch/main/` pattern for download compatibility - **Branding**: Removed all Forgejo references from codebase and documentation for neutrality - **Fallback chains**: Simplified from three-tier to two-tier approach - Docker binary: `Git Repositorys → local dir → current dir` (removed `→ internal proxy`) - Wallarm image: `Git Repositorys → local dir → current dir` (removed `→ internal registry`) ### Removed - Internal registry fallback options and related variables: - `INTERNAL_DOCKER_REGISTRY` and `INTERNAL_DOCKER_DOWNLOAD` - `DOCKER_REGISTRY_HOST` and `DOCKER_DOWNLOAD_HOST` - `DOCKER_STATIC_BASE_URL` and `WALLARM_IMAGE_SOURCE` - Connectivity tests for internal registry/download servers - Remediation instructions mentioning internal fallback options - All references to internal proxy/registry in error messages ### Technical Details - **Commits**: - `3158ee7` (chore: refactor git references and remove internal registry fallback) - `509909d` (chore: remove Forgejo references and fix setup URL) - **Files modified**: 4 files changed, additional modifications - `README.md` - Documentation updates and URL fixes - `setup.sh` - URL base update and Forgejo reference removal - `wallarm-ct-check.sh` - Variable renaming and logic simplification - `wallarm-ct-deploy.sh` - Variable renaming and fallback chain updates ### Notes - Scripts maintain backward compatibility with existing artifact URLs - Simplified error handling focuses on primary Git Repositorys source and local files - No functional changes to core deployment logic