Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 8 additions & 8 deletions .env.example
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
XRAY_IMAGE=ghcr.io/xtls/xray-core:26.7.28
OVPN_AGENT_IMAGE=alpine:3.23.4
OVPN_TELEGRAM_BOT_IMAGE=alpine:3.23.4
OVPN_WEB_IMAGE=nginx:1.29-alpine
OVPN_AGENT_IMAGE=alpine:3.24.2
OVPN_TELEGRAM_BOT_IMAGE=alpine:3.24.2
OVPN_WEB_IMAGE=nginx:1.30.5-alpine
OVPN_AGENT_LOG_LEVEL=info
# Bearer token that guards the ovpn-agent mutating endpoints. The CLI auto-generates and persists
# one under ~/.ovpn/secrets/agent-token and renders it here on deploy; set it explicitly to manage
Expand All @@ -15,11 +15,11 @@ OVPN_TLS_SELFSNI_CERT_DIR=/opt/ovpn/certs
OVPN_CAMOUFLAGE_SITE_DIR=/opt/ovpn/camouflage-site
OVPN_SECURITY_PROFILE=minimal
OVPN_THREAT_DNS_SERVERS=9.9.9.9,149.112.112.112
PROMETHEUS_IMAGE=prom/prometheus:v3.11.2
ALERTMANAGER_IMAGE=prom/alertmanager:v0.32.0
GRAFANA_IMAGE=grafana/grafana:12.4.3
NODE_EXPORTER_IMAGE=prom/node-exporter:v1.11.1
CADVISOR_IMAGE=ghcr.io/google/cadvisor:0.56.2
PROMETHEUS_IMAGE=prom/prometheus:v3.15.0
ALERTMANAGER_IMAGE=prom/alertmanager:v0.34.1
GRAFANA_IMAGE=grafana/grafana:12.4.12
NODE_EXPORTER_IMAGE=prom/node-exporter:v1.12.1
CADVISOR_IMAGE=ghcr.io/google/cadvisor:0.60.6
GRAFANA_ADMIN_USER=ovpn
GRAFANA_ADMIN_PASSWORD=change-me-now
GRAFANA_PORT=3000
Expand Down
11 changes: 8 additions & 3 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -95,6 +95,11 @@ jobs:
set -euo pipefail
go test -json -covermode=atomic -coverprofile=coverage.out ./... | tee test-report.jsonl

- name: Docker geodata permission regression
env:
OVPN_TEST_DOCKER: '1'
run: go test -v ./internal/deploy -run '^TestValidateConfigWithDockerPrivateGeodata$'

- name: Test embedded runtime asset path
id: runtimeassets_test
run: |
Expand Down Expand Up @@ -143,16 +148,16 @@ jobs:
- name: GolangCI-Lint
id: golangci
# golangci/golangci-lint-action v9.3.0
uses: golangci/golangci-lint-action@d583c34f0599d37dbac4a198b9c83201be380893
uses: golangci/golangci-lint-action@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a
with:
version: v2.12.2
version: v2.14.0
args: --timeout=5m

- name: Install gosec
id: install_gosec
run: |
echo "$(go env GOPATH)/bin" >> "$GITHUB_PATH"
go install github.com/securego/gosec/v2/cmd/gosec@v2.27.1
go install github.com/securego/gosec/v2/cmd/gosec@v2.29.0

- name: Gosec gate (high confidence/high severity)
id: gosec_gate
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/security.yml
Original file line number Diff line number Diff line change
Expand Up @@ -72,7 +72,7 @@ jobs:
- name: Install govulncheck
run: |
echo "$(go env GOPATH)/bin" >> "$GITHUB_PATH"
go install golang.org/x/vuln/cmd/govulncheck@v1.3.0
go install golang.org/x/vuln/cmd/govulncheck@v1.8.0

- name: Run govulncheck
run: govulncheck ./...
Expand All @@ -86,7 +86,7 @@ jobs:
actions: read
security-events: write
env:
TRIVY_VERSION: v0.71.0
TRIVY_VERSION: v0.75.0
TRIVY_CACHE_DIR: .cache/trivy
DOCKER_CONFIG: /tmp/trivy-docker-config

Expand Down Expand Up @@ -174,8 +174,8 @@ jobs:
id: upload_trivy_sarif
if: ${{ always() && steps.sarif_policy.outputs.allowed == 'true' }}
continue-on-error: true
# github/codeql-action v4.36.1
uses: github/codeql-action/upload-sarif@8aad20d150bbac5944a9f9d289da16a4b0d87c1e
# github/codeql-action v4.38.2
uses: github/codeql-action/upload-sarif@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2
with:
sarif_file: trivy-results.sarif

Expand Down
11 changes: 11 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,17 @@ The format is based on Keep a Changelog and this repository uses plain semantic

## Unreleased

## 1.10.0

### Fixed
- Local config validation uses the CLI user's UID/GID to read owner-only geodata without changing file permissions (#44).
- Geodata permission errors now point to filesystem access instead of disabling the security profile.

### Security
- Validation configs use private temporary directories and `0600` permissions, with automatic cleanup.
- Updated Go to `1.27.1`, dependencies, pinned Actions, security tools and runtime images; consolidated Dependabot #39, #41 and #43.
- Aligned the Xray Go module with runtime `26.7.28`, including its TLS pinning fix; retained patched gRPC `1.83.2`.

## 1.9.0

### Added
Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -117,7 +117,7 @@ flowchart LR

## Versioning

- Current pinned version: `1.9.0`
- Current pinned version: `1.10.0`
- Check locally: `./ovpn version`
- Release source of truth:
- `VERSION`
Expand Down
2 changes: 1 addition & 1 deletion VERSION
Original file line number Diff line number Diff line change
@@ -1 +1 @@
1.9.0
1.10.0
2 changes: 1 addition & 1 deletion ansible/inventories/example/group_vars/all.yml
Original file line number Diff line number Diff line change
Expand Up @@ -107,7 +107,7 @@ ovpn_disable_motd_news: true
ovpn_prepare_base_stack: false
ovpn_base_stack_compose_filename: "docker-compose.base.yml"
ovpn_base_bundle_src: ""
ovpn_agent_image: "alpine:3.23.4"
ovpn_agent_image: "alpine:3.24.2"
ovpn_agent_log_level: "info"

# Xray/runtime defaults (kept in all.yml so bootstrap has required vars even
Expand Down
16 changes: 16 additions & 0 deletions docs/cli.md
Original file line number Diff line number Diff line change
Expand Up @@ -638,3 +638,19 @@ For a shared profile:

Do not leave targeted debug running longer than needed.
Use `debug list` during support and `debug stop` when finished.

## Local config validation

Validation uses local geodata and the CLI user's UID/GID. Files with owner-only
permissions remain readable without changing their permissions. Custom geodata
paths use `OVPN_PROXY_GEOSITE_PATH` and `OVPN_PROXY_GEOIP_PATH`.

With Docker running and CLI version `1.10.0` or later, replace `<server>` with
the existing local proxy name:

```bash
OVPN_SECURITY_PROFILE=minimal ./ovpn config validate --server <server>
```

Expected result: `config valid`. If access is denied, check local file ownership
and read permissions; keep the security profile enabled.
9 changes: 9 additions & 0 deletions docs/upgrades.md
Original file line number Diff line number Diff line change
Expand Up @@ -208,3 +208,12 @@ Quota semantics are rolling 30d. Updated public fields/metrics:
- Metrics:
- `ovpn_agent_user_window_30d_usage_bytes`
- `ovpn_agent_user_window_30d_quota_bytes`

## Dependency pins

Go and library versions are defined in `go.mod`; runtime images are defined in
`internal/defaults/images.go`. Updated image defaults take effect on deployment.
Keep Xray API dependencies aligned with the pinned runtime revision.

gRPC remains on patched `1.83.2` because [GO-2026-6443](https://pkg.go.dev/vuln/GO-2026-6443)
lists `1.84.0` as affected.
16 changes: 8 additions & 8 deletions examples/.env.example
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
XRAY_IMAGE=ghcr.io/xtls/xray-core:26.7.28
OVPN_AGENT_IMAGE=alpine:3.23.4
OVPN_TELEGRAM_BOT_IMAGE=alpine:3.23.4
OVPN_WEB_IMAGE=nginx:1.29-alpine
OVPN_AGENT_IMAGE=alpine:3.24.2
OVPN_TELEGRAM_BOT_IMAGE=alpine:3.24.2
OVPN_WEB_IMAGE=nginx:1.30.5-alpine
OVPN_AGENT_LOG_LEVEL=info
OVPN_AGENT_HOST_PORT=19000
OVPN_TELEGRAM_BOT_HOST_PORT=19001
Expand All @@ -11,11 +11,11 @@ OVPN_TLS_SELFSNI_CERT_DIR=/opt/ovpn/certs
OVPN_CAMOUFLAGE_SITE_DIR=/opt/ovpn/camouflage-site
OVPN_SECURITY_PROFILE=minimal
OVPN_THREAT_DNS_SERVERS=9.9.9.9,149.112.112.112
PROMETHEUS_IMAGE=prom/prometheus:v3.11.2
ALERTMANAGER_IMAGE=prom/alertmanager:v0.32.0
GRAFANA_IMAGE=grafana/grafana:12.4.3
NODE_EXPORTER_IMAGE=prom/node-exporter:v1.11.1
CADVISOR_IMAGE=ghcr.io/google/cadvisor:0.56.2
PROMETHEUS_IMAGE=prom/prometheus:v3.15.0
ALERTMANAGER_IMAGE=prom/alertmanager:v0.34.1
GRAFANA_IMAGE=grafana/grafana:12.4.12
NODE_EXPORTER_IMAGE=prom/node-exporter:v1.12.1
CADVISOR_IMAGE=ghcr.io/google/cadvisor:0.60.6
GRAFANA_ADMIN_USER=ovpn
GRAFANA_ADMIN_PASSWORD=change-me-now
GRAFANA_PORT=3000
Expand Down
50 changes: 25 additions & 25 deletions go.mod
Original file line number Diff line number Diff line change
@@ -1,56 +1,56 @@
module ovpn

go 1.26.5
go 1.27.1

require (
github.com/google/uuid v1.6.0
github.com/jedib0t/go-pretty/v6 v6.8.3
github.com/prometheus/client_golang v1.24.0
github.com/prometheus/client_golang v1.24.1
github.com/skip2/go-qrcode v0.0.0-20200617195104-da1b6568686e
github.com/spf13/cobra v1.10.2
github.com/xtls/xray-core v1.260327.0
golang.org/x/crypto v0.54.0
google.golang.org/grpc v1.82.1
modernc.org/sqlite v1.54.0
github.com/xtls/xray-core v1.260327.1-0.20260728075948-5ca6f4b7d4dc
golang.org/x/crypto v0.57.0
google.golang.org/grpc v1.83.2
google.golang.org/protobuf v1.36.12
modernc.org/sqlite v1.60.1
)

require (
github.com/andybalholm/brotli v1.2.1 // indirect
github.com/apernet/quic-go v0.59.1-0.20260217092621-db4786c77a22 // indirect
github.com/apernet/quic-go v0.59.1-0.20260425001925-6c6cc9bcb716 // indirect
github.com/beorn7/perks v1.0.1 // indirect
github.com/cespare/xxhash/v2 v2.3.0 // indirect
github.com/clipperhouse/uax29/v2 v2.7.0 // indirect
github.com/cloudflare/circl v1.6.3 // indirect
github.com/cloudflare/circl v1.6.4 // indirect
github.com/dustin/go-humanize v1.0.1 // indirect
github.com/inconshreveable/mousetrap v1.1.0 // indirect
github.com/juju/ratelimit v1.0.2 // indirect
github.com/klauspost/compress v1.19.0 // indirect
github.com/klauspost/cpuid/v2 v2.3.0 // indirect
github.com/klauspost/compress v1.20.1 // indirect
github.com/klauspost/cpuid/v2 v2.4.0 // indirect
github.com/kylelemons/godebug v1.1.0 // indirect
github.com/mattn/go-isatty v0.0.22 // indirect
github.com/mattn/go-isatty v0.0.24 // indirect
github.com/mattn/go-runewidth v0.0.23 // indirect
github.com/miekg/dns v1.1.72 // indirect
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
github.com/ncruces/go-strftime v1.0.0 // indirect
github.com/pires/go-proxyproto v0.12.0 // indirect
github.com/prometheus/client_model v0.6.2 // indirect
github.com/prometheus/common v0.70.0 // indirect
github.com/pires/go-proxyproto v0.15.0 // indirect
github.com/prometheus/client_model v0.6.3 // indirect
github.com/prometheus/common v0.72.0 // indirect
github.com/prometheus/procfs v0.21.1 // indirect
github.com/refraction-networking/utls v1.8.3-0.20260301010127-aa6edf4b11af // indirect
github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec // indirect
github.com/sagernet/sing v0.5.1 // indirect
github.com/spf13/pflag v1.0.10 // indirect
github.com/xtls/reality v0.0.0-20260322125925-9234c772ba8f // indirect
golang.org/x/mod v0.37.0 // indirect
golang.org/x/net v0.56.0 // indirect
golang.org/x/sync v0.22.0 // indirect
golang.org/x/sys v0.47.0 // indirect
golang.org/x/text v0.40.0 // indirect
golang.org/x/tools v0.47.0 // indirect
google.golang.org/genproto/googleapis/rpc v0.0.0-20260511170946-3700d4141b60 // indirect
google.golang.org/protobuf v1.36.11 // indirect
go4.org/netipx v0.0.0-20231129151722-fdeea329fbba // indirect
golang.org/x/mod v0.41.0 // indirect
golang.org/x/net v0.59.0 // indirect
golang.org/x/sync v0.23.0 // indirect
golang.org/x/sys v0.48.0 // indirect
golang.org/x/text v0.42.0 // indirect
golang.org/x/tools v0.51.0 // indirect
google.golang.org/genproto/googleapis/rpc v0.0.0-20260706201446-f0a921348800 // indirect
lukechampine.com/blake3 v1.4.1 // indirect
modernc.org/libc v1.74.1 // indirect
modernc.org/libc v1.77.1 // indirect
modernc.org/mathutil v1.7.1 // indirect
modernc.org/memory v1.11.0 // indirect
modernc.org/memory v1.12.1 // indirect
)
Loading
Loading