Zum Inhalt

v2026.10.05.04 – v2026.10.05.10 — 2026-10-05

  • Keine Änderungen dokumentiert
  • fix(domains): the leftover scan no longer reports system hosts' mail certificates
  • fix(ui): site_id preselection in the WordPress toolkit and malware scanner, dead navigate targets fail the build
  • docs(notes): review the name-claim, certificate and teardown fixes and queue the residue check
  • fix(domains): deleting a domain removes everything that belongs to its name
  • fix(doctor): update WordPress opens the toolkit, not the dashboard
  • fix(ssl): deleting a site removes its own certificate and private key
  • fix(domains): one name-claim check on every path that creates a hostname
  • docs(notes): record that the suspend fix is reviewed and what the release note must say
  • docs(packages): say what the suspension policy does and that it keeps the files
  • fix(subscriptions): suspending never deletes a site's files
  • docs(adr): custom certificates with a marker next to the certificate
  • docs(notes): a custom certificate does not survive a vhost re-render
  • docs(notes): retract the ProFTPD hook finding and queue the measurements for the web panel server
  • docs(notes): audit of web server, domains, aliases and TLS from the code side
  • fix(ui): brand plate - the logo zone of the sidebar and sign-in tile follows the theme, own logo gets a dark-lettered twin for light ground
  • docs(notes): review the audit fixes and brief the frontend follow-ups
  • docs(notes): status table for the audit findings worked off so far
  • docs: repair and TLS architecture follow the domain teardown, DKIM repair and own-certificate work
  • fix(ssl): panel vhost keeps its certificates with reseller domains, renewed certificates reach separate mail nodes, vhost writes are atomic
  • fix(settings): the panel name can be cleared again
  • fix(ssl): a disabled or suspended site stays held through re-renders, the startup backfill leaves deleted names alone, www shadow rows get no zone
  • feat(dashboard): operator view - open findings table, per-server load history, fleet traffic, enconf logo in the update window
  • feat(ssl): the certificate list names what is served, FTP skips own certificates, expiry and alias warnings for own certificates
  • feat(ssl): reissue, renewal, repair and doctor leave your own certificate alone
  • feat(ssl): your own certificate stays — marker, resolver, validated install with rollback
  • fix(ssl): US spelling in the ssl-off test (lint)
  • fix(delete): subscription and customer deletion stop when the servers keep something, and clean the domain names too
  • feat(traffic): fleet-wide daily traffic summary endpoint for the admin dashboard
  • fix(ssl): turning SSL off removes HTTPS from the vhost even while the certificate stays on disk
  • docs(adr): one source for a site's name set across server_name, certificate and cleanup
  • fix(domains): a live site's primary domain stays, shared names keep their files, admins can force past a dead agent
  • fix(ssl): heal every vhost with a missing certificate in one pass
  • fix(mail): every domain with active mail gets a DKIM key and a published record
  • docs(notes): record why a known domain can lack a DKIM key
  • fix(i18n): name the dashboard sections by action and state in 13 languages
  • fix(dashboard): name the operator bands after the action, not the damage
  • fix(dashboard): the update notice sits with the other alerts again
  • fix(lint): US spelling in the delete-job comment
  • fix(ui): delete dialogs name what the servers kept and force only on a separate button, own-certificate replace needs confirmation, alias and subdomain show the certificate warning, decision counter on the dashboard
  • fix(packages): a new subscription's first site gets its package's slice limits
  • fix(packages): a small tier no longer gets a slice that kills its own PHP master
  • docs(notes): measure slice demand per PHP-FPM and assess AppArmor enforce readiness
  • build(release): refuse a version number the repository already carries
  • fix(agent): a start no longer rewrites healthy vhosts — the body-size migration only touches pre-template vhosts, the panel vhost keeps its security.txt Expires
  • fix(tls): drop the registry row of an own certificate once nothing claims its name
  • docs(notes): measure the mail SNI directories, no leftover on the two test hosts
  • docs(notes): correct the customer count and the final panel vhost hash
  • docs(notes): record the live measurement of own certificates and the vhost self-heal on the test panel
  • fix(subscriptions): only an admin may force a subscription delete past leftovers on the servers
  • fix(sitebuild): a preview host is claimed only while its site has the preview, no prefix shortcut
  • feat(ssl): RepairSSL reconciles the own-certificate marker with the recorded intent, plus the decision counter and the report flag
  • docs(adr): answer step 3 — drift lines may be added, one three-state reachability comes first
  • refactor(sitebuild): one source for the claim question, the request builder reads the NameSet (ADR-011 step 3, behavior unchanged)
  • fix(toolkits): the auto-login helpers carry the enconf prefix, and the panel stops hard-coding the file name
  • fix(changelog): the testing version span comes from testing tags, not from the name of a stable tag
  • feat(sitebuild): the NameSet observation week starts by itself on an undecided install (ADR-011 step 2b)
  • docs(adr): clarify what waits for the shadow week and list the work that does not
  • feat(sitebuild): NameSet shadow mode compares the decided rules with the legacy ones and records the differences (ADR-011 step 2)
  • fix(mail): the certbot deploy hook rebuilds Postfix's SNI map so a renewal reaches Postfix at once
  • refactor(sitebuild): one NameSet derivation behind the name functions (ADR-011 step 1, behavior unchanged)
  • docs(notes): measure the postfix SNI map, the assumption holds this time
  • docs(adr): the client accepts all four recommendations on the name set