wallarm/changelog.md
Sechpoint Admin 537beed957 fix: make setup.sh download both deployment types under curl|bash
The interactive deployment-type prompt read from stdin, which is the script
pipe (not the terminal) when piped to bash, so it was silently skipped and
only Docker scripts were downloaded. setup.sh is now non-interactive by
default and downloads BOTH deployment types (docker/ + native/) so the native
option is always available; DEPLOYMENT_TYPE=docker|native restricts to one.
Also guard clear and drop the broken overwrite confirmation.
2026-08-01 08:45:29 +01:00

6.3 KiB
Raw Blame History

Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to date-based versioning (YYYY-MM.x).

[2026-08.1] - 2026-08-01

Fixed

  • setup.sh interactive prompt broken under curl ... | bash: the deployment-type prompt and overwrite confirmation read from stdin, which is the script pipe (not the terminal) when piped to bash — the prompt was silently skipped and only Docker scripts were downloaded. setup.sh is now non-interactive by default and downloads BOTH deployment types (docker/ + native/), so the native option is always available. Use DEPLOYMENT_TYPE=docker|native to download only one type.

Added

  • Native deployment type: Wallarm filtering node can now be deployed directly on the OS without Docker
    • native/wallarm-ct-check.sh Preflight validation for native deployment (no Docker artifact checks)
    • native/wallarm-ct-deploy.sh Downloads and runs the official Wallarm all-in-one installer (meganode.wallarm.com, version configurable via WALLARM_VERSION), configures the NGINX server block, reloads and verifies the node
    • native/wallarm-ct-reconfigure.sh Update trusted proxies / wallarm_mode via NGINX test + reload
    • native/wallarm-ct-uninstall.sh Remove NGINX config, Wallarm packages/repos, and /opt/wallarm data
  • Unified node manager: native/wallarm-native.sh single-script manager for the Wallarm Native Node (go-node, connector-server mode)
    • --preflight checks (root, systemd, architecture, required commands, installer + Wallarm cloud connectivity, disk/memory, listen-port availability); auto-run before --install
    • Interactive parallel multi-node installation with per-node systemd template units (wallarm-node@<name>.service)
    • --config (address/token/labels, safe env rewrite), --remove, --status [NODE]
    • All-in-one installer from repo.wallarm.com (overridable via WALLARM_INSTALLER_URL/WALLARM_INSTALLER_ARCH)
  • Shared library: common/wallarm-lib.sh extracted and reused by both deployment types
    • Colors, logging (log_message, fail_with_remediation), early error handler
    • System detection (OS/arch/init), network connectivity tests
    • Preflight .env parsing (load_env_file), cloud region selection (select_cloud_region)
    • Validation helpers (IP, CIDR, port), artifact download + checksum verification

Changed

  • Repository structure now separates deployment types:
    • docker/ all Docker-based scripts moved here (git mv, history preserved)
    • docker/binaries/ and docker/images/ Docker artifacts moved into the Docker tree
    • native/ new native (no-Docker) deployment scripts
    • common/ shared library
  • Artifact URLs updated to the docker/ prefix (/docker/binaries/..., /docker/images/...)
  • Docker scripts refactored to source common/wallarm-lib.sh (removed duplicated helper functions; behavior preserved)
  • setup.sh downloads the shared library and scripts per deployment type into docker//native/ (native includes wallarm-native.sh); supports DEPLOYMENT_TYPE=docker|native to download only one type
  • README.md rewritten to document both deployment types, the new structure, the unified manager, and native-specific usage

Notes

  • Native deployment supports one node per host (system NGINX); multi-node remains a Docker feature
  • Native installer version defaults to 6.12.7 and can be pinned via WALLARM_VERSION
  • Docker deployment behavior is unchanged apart from the new directory layout
  • The unified manager targets the Wallarm Native Node product; the native/wallarm-ct-*.sh scripts target the NGINX-module native deployment. Both are no-Docker options

[2026-04.1] - 2026-04-21

Added

  • Initial changelog file with versioning schema
  • Date-based versioning system (YYYY-MM.x)

Changed

  • Variable renaming: All GITLAB_* variables renamed to GIT_* prefix
    • GITLAB_BASE_URLGIT_BASE_URL
    • GITLAB_RAW_URLGIT_RAW_URL (with updated path)
    • GITLAB_DOCKER_BINARY_URLGIT_DOCKER_BINARY_URL
    • GITLAB_DOCKER_CHECKSUM_URLGIT_DOCKER_CHECKSUM_URL
    • GITLAB_WALLARM_IMAGE_URLGIT_WALLARM_IMAGE_URL
    • GITLAB_WALLARM_CHECKSUM_URLGIT_WALLARM_CHECKSUM_URL
    • GITLAB_REACHABLEGIT_REACHABLE
  • URL structure: Updated GIT_RAW_URL from /-/raw/main to /raw/branch/main path (corrected for download compatibility)
  • Terminology: Replaced all "GitLab" references in comments and log messages with "Git Repositorys"
  • Documentation: Updated README.md to reflect new terminology
  • URL correction: Corrected setup.sh download URL in README.md back to /raw/branch/main/ pattern for download compatibility
  • Branding: Removed all Forgejo references from codebase and documentation for neutrality
  • Fallback chains: Simplified from three-tier to two-tier approach
    • Docker binary: Git Repositorys → local dir → current dir (removed → internal proxy)
    • Wallarm image: Git Repositorys → local dir → current dir (removed → internal registry)

Removed

  • Internal registry fallback options and related variables:
    • INTERNAL_DOCKER_REGISTRY and INTERNAL_DOCKER_DOWNLOAD
    • DOCKER_REGISTRY_HOST and DOCKER_DOWNLOAD_HOST
    • DOCKER_STATIC_BASE_URL and WALLARM_IMAGE_SOURCE
  • Connectivity tests for internal registry/download servers
  • Remediation instructions mentioning internal fallback options
  • All references to internal proxy/registry in error messages

Technical Details

  • Commits:
    • 3158ee7 (chore: refactor git references and remove internal registry fallback)
    • 509909d (chore: remove Forgejo references and fix setup URL)
  • Files modified: 4 files changed, additional modifications
    • README.md - Documentation updates and URL fixes
    • setup.sh - URL base update and Forgejo reference removal
    • wallarm-ct-check.sh - Variable renaming and logic simplification
    • wallarm-ct-deploy.sh - Variable renaming and fallback chain updates

Notes

  • Scripts maintain backward compatibility with existing artifact URLs
  • Simplified error handling focuses on primary Git Repositorys source and local files
  • No functional changes to core deployment logic