Furox
a3a3f2ce2e
feat: make backup retention destination-neutral
2026-09-11 16:27:31 +03:00
Furox
31be3b98dc
feat: route web-server backups through generic destinations
2026-09-11 16:27:31 +03:00
Furox
1753a3e1df
feat: route compose backups through generic destinations
2026-09-11 16:27:31 +03:00
Furox
7008ac6e4e
feat: route libsql backups through generic destinations
2026-09-11 16:27:31 +03:00
Furox
cea07b79c5
feat: route mariadb backups through generic destinations
2026-09-11 16:27:31 +03:00
Furox
460eb913b8
feat: route mongo backups through generic destinations
2026-09-11 16:27:31 +03:00
Furox
2cf6791ff8
feat: route mysql backups through generic destinations
2026-09-11 16:27:31 +03:00
Furox
6dfae93855
feat: route postgres backups through generic destinations
2026-09-11 16:27:31 +03:00
Furox
c99d214e8d
feat: add provider-aware backup destination UI
2026-09-11 16:27:31 +03:00
Furox
88b43d77f0
feat: expose Google Drive OneDrive FTP and SFTP destinations
2026-09-11 16:27:31 +03:00
Furox
7d2b8065e9
feat: test all backup destination types through rclone
2026-09-11 16:27:31 +03:00
Furox
99f036c7c1
fix: redact FTP and SFTP rclone credentials
2026-09-11 16:27:31 +03:00
Furox
f8571c0556
feat: add provider-neutral rclone destination builder
2026-09-11 16:27:31 +03:00
Furox
05605ef239
feat: validate provider-specific backup destinations
2026-09-11 16:27:31 +03:00
Furox
7ca717a375
feat: define non-S3 backup destination providers
2026-09-11 16:27:31 +03:00
Mauricio Siu
853ca33659
Merge pull request #5416 from Dokploy/fix/critical-next-rce-16.3.4
...
Auto PR to main when version changes / create-pr (push) Has been cancelled
Build Docker images / build-and-push-cloud-image (push) Has been cancelled
Build Docker images / build-and-push-schedule-image (push) Has been cancelled
Build Docker images / build-and-push-server-image (push) Has been cancelled
Dokploy Docker Build / docker-amd (push) Has been cancelled
Dokploy Docker Build / docker-arm (push) Has been cancelled
autofix.ci / format (push) Has been cancelled
Dokploy Monitoring Build / docker-amd (push) Has been cancelled
Dokploy Monitoring Build / docker-arm (push) Has been cancelled
Dokploy Docker Build / combine-manifests (push) Has been cancelled
Dokploy Docker Build / generate-release (push) Has been cancelled
Dokploy Docker Build / sync-version (push) Has been cancelled
Dokploy Monitoring Build / combine-manifests (push) Has been cancelled
fix(deps): bump next to 16.3.4 to patch critical RCE advisories
2026-09-11 02:20:20 -06:00
Mauricio Siu
a90c2a662f
Merge pull request #5418 from EgerDev/feat/compose-models
...
feat(compose): support models in Compose specification
2026-09-11 02:20:07 -06:00
EgerDev
45dcdfc5be
test(compose): tighten models types and regression tests
2026-09-11 00:11:40 -07:00
EgerDev
29cdc815db
feat(compose): support AI models in Compose specification
2026-09-10 20:28:28 -07:00
Narciso E. Núñez Arias
9fa98de9c1
Merge pull request #5350 from RezaRahemtola/fix/ntfy-database-backup-newline
...
Auto PR to main when version changes / create-pr (push) Waiting to run
Build Docker images / build-and-push-cloud-image (push) Waiting to run
Build Docker images / build-and-push-schedule-image (push) Waiting to run
Build Docker images / build-and-push-server-image (push) Waiting to run
Dokploy Docker Build / docker-amd (push) Waiting to run
Dokploy Docker Build / docker-arm (push) Waiting to run
Dokploy Docker Build / combine-manifests (push) Blocked by required conditions
Dokploy Docker Build / generate-release (push) Blocked by required conditions
Dokploy Docker Build / sync-version (push) Blocked by required conditions
autofix.ci / format (push) Waiting to run
Dokploy Monitoring Build / docker-amd (push) Waiting to run
Dokploy Monitoring Build / docker-arm (push) Waiting to run
Dokploy Monitoring Build / combine-manifests (push) Blocked by required conditions
fix(notifications): add missing newline to ntfy database backup message
2026-09-10 19:00:08 -04:00
Dokploy Bot
a4a1d15656
chore: sync hotfix from main into canary [skip ci]
2026-09-10 22:40:21 +00:00
Narciso E. Núñez Arias
8075a7ce95
Merge pull request #5358 from KingIronMan2011/patch-1
...
feat: added missing Railpack versions
(cherry picked from commit 326908869d )
[skip ci]
2026-09-10 22:40:19 +00:00
Narciso E. Núñez Arias
326908869d
Merge pull request #5358 from KingIronMan2011/patch-1
...
feat: added missing Railpack versions
2026-09-10 18:40:09 -04:00
Narciso E. Núñez Arias
18d07c7254
Merge pull request #5364 from maks-oleksyuk/chore/ci-update-actions
...
chore(ci): update GitHub Actions to latest versions and harden workflows
2026-09-10 18:32:42 -04:00
Narciso
4cd4b83523
fix(deps): bump next to 16.3.4 to patch critical RCE advisories
...
GHSA-2xp9-vwfh-vxw4 and GHSA-p293-qw3h-jr36
2026-09-10 18:23:38 -04:00
Narciso E. Núñez Arias
f91b2e2ca6
Merge pull request #5414 from aspatari/fix/infisical-imported-secrets
...
fix(vault): read Infisical secrets pulled in through an import
2026-09-10 18:16:08 -04:00
Artur Spatari
e70c880612
test(vault): lock the precedence between two imports
...
Review flagged that multi-import collisions were untested. The order the code
implements is the documented one — Infisical: "If two imports carry a secret
with the same name, the value from the bottom-most import wins" — and the
response lists imports in that order, so sequential assignment matches it.
Added a case with two imports defining the same key. Reversing the merge order
in the client fails it, so the test pins the behaviour rather than restating
the implementation.
vault.test.ts: 58 passed.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-10 10:32:09 +03:00
Artur Spatari
0c1dfe978c
fix(vault): read Infisical secrets pulled in through an import
...
Fixes #5413 . A secret brought into a folder with "Import Secrets" was reported
as not found. Two reasons, and the first is easy to miss:
The list endpoint takes the flag in **snake_case**. `includeImports` is
silently ignored — the request still returns 200, with `imports` present but
empty — so the imported secret looked like it simply did not exist. Measured
against app.infisical.com with a registered import (confirmed via
GET /api/v1/secret-imports):
expandSecretReferences=true imports[] empty
expandSecretReferences=true&includeImports=true imports[] empty
expandSecretReferences=true&include_imports=true imports[] has the secret
Second, imported secrets never appear in `secrets` — they come back in a
separate `imports` array, one entry per source path, which the client did not
read at all.
Imported entries are merged before the folder's own, so a name defined in both
resolves to the local value, matching how Infisical resolves it.
Also measured, for whoever looks next: `/api/v4/secrets` returns imports with
no flag at all, and single-secret reads (`/raw/{name}`) never see an imported
key — 404 on v3, no such route on v4. So a folder listing is the only way to
reach them.
vault.test.ts: 57 passed. Reverting the fix fails the new merge test.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-10 10:26:52 +03:00
Mauricio Siu
88118cdb3f
Merge pull request #5411 from Dokploy/fix/fresh-volumes-danger-zone
...
Auto PR to main when version changes / create-pr (push) Waiting to run
Build Docker images / build-and-push-cloud-image (push) Waiting to run
Build Docker images / build-and-push-schedule-image (push) Waiting to run
Build Docker images / build-and-push-server-image (push) Waiting to run
Dokploy Docker Build / docker-amd (push) Waiting to run
Dokploy Docker Build / docker-arm (push) Waiting to run
Dokploy Docker Build / combine-manifests (push) Blocked by required conditions
Dokploy Docker Build / generate-release (push) Blocked by required conditions
Dokploy Docker Build / sync-version (push) Blocked by required conditions
autofix.ci / format (push) Waiting to run
Dokploy Monitoring Build / docker-amd (push) Waiting to run
Dokploy Monitoring Build / docker-arm (push) Waiting to run
Dokploy Monitoring Build / combine-manifests (push) Blocked by required conditions
Generate and Sync OpenAPI / Generate OpenAPI and commit to Dokploy repo (push) Has been cancelled
fix(compose): move Fresh Volumes into a Danger Zone with typed confirmation
2026-09-09 17:48:16 -06:00
Mauricio Siu
38d157adc0
fix(compose): move Fresh Volumes into a Danger Zone with typed confirmation
2026-09-09 17:47:16 -06:00
Mauricio Siu
3b1fec5409
Merge pull request #5410 from Dokploy/feat/compose-pull-images
...
feat(compose): pull latest images on deploy toggle
2026-09-09 17:14:43 -06:00
Mauricio Siu
49b8214e5d
feat(compose): add pull latest images on deploy toggle
2026-09-09 17:13:24 -06:00
Mauricio Siu
ec31739e0e
Merge pull request #5396 from Dokploy/feat/transfer-service-between-servers
...
Auto PR to main when version changes / create-pr (push) Waiting to run
Build Docker images / build-and-push-cloud-image (push) Waiting to run
Build Docker images / build-and-push-schedule-image (push) Waiting to run
Build Docker images / build-and-push-server-image (push) Waiting to run
Dokploy Docker Build / docker-amd (push) Waiting to run
Dokploy Docker Build / docker-arm (push) Waiting to run
Dokploy Docker Build / combine-manifests (push) Blocked by required conditions
Dokploy Docker Build / generate-release (push) Blocked by required conditions
Dokploy Docker Build / sync-version (push) Blocked by required conditions
autofix.ci / format (push) Waiting to run
Dokploy Monitoring Build / docker-amd (push) Waiting to run
Dokploy Monitoring Build / docker-arm (push) Waiting to run
Dokploy Monitoring Build / combine-manifests (push) Blocked by required conditions
Generate and Sync OpenAPI / Generate OpenAPI and commit to Dokploy repo (push) Waiting to run
feat: transfer services between servers
2026-09-09 13:21:27 -06:00
Narciso E. Núñez Arias
d5328703fa
Merge pull request #5407 from imrja8/fix-sso-flash
2026-09-09 13:15:29 -04:00
Narciso E. Núñez Arias
f4cb26cbf4
Merge pull request #5406 from imrja8/fix-settings-layout-width
2026-09-09 13:12:41 -04:00
Yash Kumar
a6c1f3048f
fix(ui): standardize settings layout widths to full width
2026-09-09 21:24:03 +05:30
Yash Kumar
9cae609a0a
fix(auth): prefetch SSO state in SSR to prevent layout flash
2026-09-09 20:09:23 +05:30
Mauricio Siu
2c234d6e20
test(transfer): shrink pipe payload and set an explicit timeout so the suite does not time out in CI
2026-09-09 02:57:51 -06:00
Mauricio Siu
9dcdb53aa1
feat(transfer): move services between servers with their volumes, mounts and config
...
Adds a Transfer action on every service page that moves an application,
compose or database to another server without S3: volumes, bind mounts
and deployment logs are streamed through the panel (ssh2/spawn pipe),
file mounts and Traefik config are recreated on the target, the source
is cleaned up and the service is deployed on the target. Failures before
cleanup roll back to the source server.
2026-09-09 02:50:29 -06:00
Mauricio Siu
bda8124291
Merge pull request #5351 from Dokploy/fix/dependabot-critical-security-updates
...
Auto PR to main when version changes / create-pr (push) Waiting to run
Build Docker images / build-and-push-cloud-image (push) Waiting to run
Build Docker images / build-and-push-schedule-image (push) Waiting to run
Build Docker images / build-and-push-server-image (push) Waiting to run
Dokploy Docker Build / docker-amd (push) Waiting to run
Dokploy Docker Build / docker-arm (push) Waiting to run
Dokploy Docker Build / combine-manifests (push) Blocked by required conditions
Dokploy Docker Build / generate-release (push) Blocked by required conditions
Dokploy Docker Build / sync-version (push) Blocked by required conditions
autofix.ci / format (push) Waiting to run
Dokploy Monitoring Build / docker-amd (push) Waiting to run
Dokploy Monitoring Build / docker-arm (push) Waiting to run
Dokploy Monitoring Build / combine-manifests (push) Blocked by required conditions
Generate and Sync OpenAPI / Generate OpenAPI and commit to Dokploy repo (push) Waiting to run
fix: resolve 6 critical Dependabot alerts
2026-09-08 16:29:38 -06:00
Mauricio Siu
6dcd0e1859
Merge pull request #5381 from Dokploy/canary
...
Build Docker images / build-and-push-cloud-image (push) Has been cancelled
Build Docker images / build-and-push-schedule-image (push) Has been cancelled
Build Docker images / build-and-push-server-image (push) Has been cancelled
Dokploy Docker Build / docker-amd (push) Has been cancelled
Dokploy Docker Build / docker-arm (push) Has been cancelled
Dokploy Monitoring Build / docker-amd (push) Has been cancelled
Dokploy Monitoring Build / docker-arm (push) Has been cancelled
Generate and Sync OpenAPI / Generate OpenAPI and commit to Dokploy repo (push) Has been cancelled
Dokploy Docker Build / combine-manifests (push) Has been cancelled
Dokploy Docker Build / generate-release (push) Has been cancelled
Dokploy Docker Build / sync-version (push) Has been cancelled
Dokploy Monitoring Build / combine-manifests (push) Has been cancelled
🚀 Release v0.30.6
2026-09-08 16:24:12 -06:00
Mauricio Siu
85786a3196
Merge pull request #5386 from Dokploy/fix/server-health-address-pools
...
fix(server-health): detect custom default-address-pools via docker info
2026-09-08 16:04:50 -06:00
Mauricio Siu
ea3f9f3b53
fix(server-health): detect custom default-address-pools via docker info
...
/etc/docker/daemon.json isn't mounted into the dokploy container, only
docker.sock is, so cat-ing it always failed silently. Read the effective
config over the already-mounted socket instead.
Fixes #5383
2026-09-08 16:01:48 -06:00
Narciso E. Núñez Arias
e99a98e4fe
Merge pull request #5375 from aspatari/feat/infisical-path-in-reference
...
Auto PR to main when version changes / create-pr (push) Waiting to run
Build Docker images / build-and-push-cloud-image (push) Waiting to run
Build Docker images / build-and-push-schedule-image (push) Waiting to run
Build Docker images / build-and-push-server-image (push) Waiting to run
Dokploy Docker Build / docker-amd (push) Waiting to run
Dokploy Docker Build / docker-arm (push) Waiting to run
Dokploy Docker Build / combine-manifests (push) Blocked by required conditions
Dokploy Docker Build / generate-release (push) Blocked by required conditions
Dokploy Docker Build / sync-version (push) Blocked by required conditions
autofix.ci / format (push) Waiting to run
Dokploy Monitoring Build / docker-amd (push) Waiting to run
Dokploy Monitoring Build / docker-arm (push) Waiting to run
Dokploy Monitoring Build / combine-manifests (push) Blocked by required conditions
Generate and Sync OpenAPI / Generate OpenAPI and commit to Dokploy repo (push) Waiting to run
feat(vault): address an Infisical folder from the reference
2026-09-08 16:54:01 -04:00
Artur Spatari
5611662351
feat(vault): address an Infisical folder from the reference
...
An Infisical provider is pinned to one non-recursive `secretPath`, so reading
two folders means two providers, two machine identities and two sets of
credentials to rotate. This lets a reference name the folder instead:
${{vault.my-provider.external/sentry:SENTRY_DSN}}
`<path>:<KEY>` mirrors the HashiCorp client in this directory, which already
documents that exact format. A relative path resolves against the provider's
`secretPath`, a leading slash is absolute, and a ref without a colon keeps its
current meaning — the whole ref is the secret name at the provider's own path.
A dot cannot be the separator here: Infisical accepts dots inside secret names
(`A.B.C` is a valid key), so `provider.a.b.C` cannot be split unambiguously
and would silently break anyone using such a name.
Refs are grouped by resolved path so each path is listed once, and the login
happens once per batch rather than once per path.
Tests cover the bare ref, relative and absolute paths, a provider at `/`,
grouping with a single login, the error naming the path, and a malformed ref.
2026-09-08 21:38:24 +03:00
Narciso E. Núñez Arias
887a457f15
Merge pull request #5374 from aspatari/fix/infisical-expand-secret-references
...
fix(vault): expand Infisical secret references when listing secrets
2026-09-08 14:08:52 -04:00
autofix-ci[bot]
df4e299545
[autofix.ci] apply automated fixes
2026-09-08 17:43:47 +00:00
Narciso E. Núñez Arias
aaff71bbf6
Merge pull request #5382 from imrja8/fix/dns-upsert-preserve-existing-records
...
fix(dns): match record content in upsertRecord to prevent overwriting existing records
2026-09-08 13:39:32 -04:00
Yash Kumar
be128d5a4a
Merge remote-tracking branch 'upstream/canary' into fix/dns-upsert-preserve-existing-records
...
# Conflicts:
# packages/server/src/utils/dns/infomaniak.ts
2026-09-08 22:54:00 +05:30
Narciso E. Núñez Arias
467c80a73d
Merge pull request #5356 from mitc-gjuge/feat/infomaniak-record-filter
...
perf(dns): filter Infomaniak records server-side when upserting
2026-09-08 13:13:43 -04:00