- Restructure repo into docker/ and native/ deployment types with a shared common/wallarm-lib.sh (logging, detection, validation, connectivity, env parsing) - Move Docker scripts + artifacts (binaries/, images/) under docker/ (git mv, history preserved) - Refactor Docker scripts to source the shared library; update artifact URLs - Add native/ scripts for no-Docker deployment using the Wallarm all-in-one installer (check, deploy, reconfigure, uninstall) with version pinning via WALLARM_VERSION - Add native/wallarm-native.sh unified node manager (Wallarm Native Node, connector mode) with preflight checks, parallel multi-node install, config/remove/status - Update setup.sh to download scripts per deployment type (DEPLOYMENT_TYPE=...) - Update README.md and changelog.md
5.8 KiB
5.8 KiB
Changelog
All notable changes to this project will be documented in this file.
The format is based on Keep a Changelog, and this project adheres to date-based versioning (YYYY-MM.x).
[2026-08.1] - 2026-08-01
Added
- Native deployment type: Wallarm filtering node can now be deployed directly on the OS without Docker
native/wallarm-ct-check.sh– Preflight validation for native deployment (no Docker artifact checks)native/wallarm-ct-deploy.sh– Downloads and runs the official Wallarm all-in-one installer (meganode.wallarm.com, version configurable viaWALLARM_VERSION), configures the NGINX server block, reloads and verifies the nodenative/wallarm-ct-reconfigure.sh– Update trusted proxies /wallarm_modevia NGINX test + reloadnative/wallarm-ct-uninstall.sh– Remove NGINX config, Wallarm packages/repos, and/opt/wallarmdata
- Unified node manager:
native/wallarm-native.sh– single-script manager for the Wallarm Native Node (go-node, connector-server mode)--preflightchecks (root, systemd, architecture, required commands, installer + Wallarm cloud connectivity, disk/memory, listen-port availability); auto-run before--install- Interactive parallel multi-node installation with per-node systemd template units (
wallarm-node@<name>.service) --config(address/token/labels, safe env rewrite),--remove,--status [NODE]- All-in-one installer from
repo.wallarm.com(overridable viaWALLARM_INSTALLER_URL/WALLARM_INSTALLER_ARCH)
- Shared library:
common/wallarm-lib.shextracted and reused by both deployment types- Colors, logging (
log_message,fail_with_remediation), early error handler - System detection (OS/arch/init), network connectivity tests
- Preflight
.envparsing (load_env_file), cloud region selection (select_cloud_region) - Validation helpers (IP, CIDR, port), artifact download + checksum verification
- Colors, logging (
Changed
- Repository structure now separates deployment types:
docker/– all Docker-based scripts moved here (git mv, history preserved)docker/binaries/anddocker/images/– Docker artifacts moved into the Docker treenative/– new native (no-Docker) deployment scriptscommon/– shared library
- Artifact URLs updated to the
docker/prefix (/docker/binaries/...,/docker/images/...) - Docker scripts refactored to source
common/wallarm-lib.sh(removed duplicated helper functions; behavior preserved) - setup.sh now prompts for a deployment type (
dockerornative), downloads the matching scripts intodocker/ornative/(native now includeswallarm-native.sh); supportsDEPLOYMENT_TYPE=nativefor non-interactive use - README.md rewritten to document both deployment types, the new structure, the unified manager, and native-specific usage
Notes
- Native deployment supports one node per host (system NGINX); multi-node remains a Docker feature
- Native installer version defaults to
6.12.7and can be pinned viaWALLARM_VERSION - Docker deployment behavior is unchanged apart from the new directory layout
- The unified manager targets the Wallarm Native Node product; the
native/wallarm-ct-*.shscripts target the NGINX-module native deployment. Both are no-Docker options
[2026-04.1] - 2026-04-21
Added
- Initial changelog file with versioning schema
- Date-based versioning system (YYYY-MM.x)
Changed
- Variable renaming: All
GITLAB_*variables renamed toGIT_*prefixGITLAB_BASE_URL→GIT_BASE_URLGITLAB_RAW_URL→GIT_RAW_URL(with updated path)GITLAB_DOCKER_BINARY_URL→GIT_DOCKER_BINARY_URLGITLAB_DOCKER_CHECKSUM_URL→GIT_DOCKER_CHECKSUM_URLGITLAB_WALLARM_IMAGE_URL→GIT_WALLARM_IMAGE_URLGITLAB_WALLARM_CHECKSUM_URL→GIT_WALLARM_CHECKSUM_URLGITLAB_REACHABLE→GIT_REACHABLE
- URL structure: Updated
GIT_RAW_URLfrom/-/raw/mainto/raw/branch/mainpath (corrected for download compatibility) - Terminology: Replaced all "GitLab" references in comments and log messages with "Git Repositorys"
- Documentation: Updated README.md to reflect new terminology
- URL correction: Corrected setup.sh download URL in README.md back to
/raw/branch/main/pattern for download compatibility - Branding: Removed all Forgejo references from codebase and documentation for neutrality
- Fallback chains: Simplified from three-tier to two-tier approach
- Docker binary:
Git Repositorys → local dir → current dir(removed→ internal proxy) - Wallarm image:
Git Repositorys → local dir → current dir(removed→ internal registry)
- Docker binary:
Removed
- Internal registry fallback options and related variables:
INTERNAL_DOCKER_REGISTRYandINTERNAL_DOCKER_DOWNLOADDOCKER_REGISTRY_HOSTandDOCKER_DOWNLOAD_HOSTDOCKER_STATIC_BASE_URLandWALLARM_IMAGE_SOURCE
- Connectivity tests for internal registry/download servers
- Remediation instructions mentioning internal fallback options
- All references to internal proxy/registry in error messages
Technical Details
- Commits:
3158ee7(chore: refactor git references and remove internal registry fallback)509909d(chore: remove Forgejo references and fix setup URL)
- Files modified: 4 files changed, additional modifications
README.md- Documentation updates and URL fixessetup.sh- URL base update and Forgejo reference removalwallarm-ct-check.sh- Variable renaming and logic simplificationwallarm-ct-deploy.sh- Variable renaming and fallback chain updates
Notes
- Scripts maintain backward compatibility with existing artifact URLs
- Simplified error handling focuses on primary Git Repositorys source and local files
- No functional changes to core deployment logic