Stable-Releases vom 10. August 2026¶
Alle Änderungen, die am 10. August 2026 im Stable-Kanal erschienen sind — von v2.8.7 bis v2.8.14, neueste zuerst. Installiert wird v2.8.14; die Versionen darunter sind der Weg dorthin.
Stable v2.8.14¶
Per-package email service on/off. Each hosting package can enable or disable the whole mail service. The toggle lives in the Package editor → Email tab and is now clearly labelled "Email service". Turning it off blocks mailbox and forwarder creation for customers on that package (SMTP/IMAP) and hides the Email menu for them — the entire mail service is disabled for the package. (The capability already existed and was fully enforced; this release makes it findable and documents it.)
- feat(packages): clarify the per-package email-service on/off toggle
Stable v2.8.13¶
- feat(dashboard): over-quota tile detail list (which subscriptions exceed quota)
Stable v2.8.12¶
- feat(dashboard): 'What's new' box with newest release highlights
Stable v2.8.11¶
- feat(dashboard): admin operational KPI tiles (over-quota, SSL coverage, mail queue, bans)
- fix(domains): list only real domains; hide alias shadow rows (www.*)
Stable v2.8.10¶
- fix(malware): stop patching maldet's hashed core script; heal damaged systems
- docs(backup,changelog): document BACKUP_PRUNE_MAX_REPACK + narrate v2.8.9
Stable v2.8.9¶
Backup prune always finishes now — even on slow FTP. The background retention prune's pack-repacking is now bounded per run (--max-repack-size), so it completes reliably and reclaims space incrementally across weekly runs instead of grinding for hours on a slow FTP target (fully-unreferenced data is still freed in full immediately). FTP repos get a tight 64M default; S3/local stay unbounded. Tunable per install via BACKUP_PRUNE_MAX_REPACK.
- fix(backup): bound the periodic prune's repack so it always finishes (esp. FTP)
- docs(api): note that the interactive API docs at /api/docs require
ENABLE_API_DOCS=true(off by default for security) - docs(changelog,backup): document the retention/prune model and narrate the SSO + backup-reliability releases
Stable v2.8.8¶
Backups never block on pruning. The weekly, space-reclaiming prune now runs in the background: a backup completes the moment its snapshot is written instead of waiting on a repack that can take many minutes on a slow FTP target. Together with the backup fixes in v2.8.7, retention no longer stalls, delays or wedges backups — even on slow or connection-limited backends.
- fix(backup): run the periodic prune asynchronously so backups never block on it
Stable v2.8.7¶
New: admin Single Sign-On via OpenID Connect. Panel administrators can now sign in through an external identity provider — Keycloak, Authentik, Azure AD / Entra ID, Google Workspace, Auth0 and any other standards-compliant OIDC provider. It's discovery-based, so a single integration covers every provider: enter the issuer URL and client credentials under System → Single Sign-On, and a Single-Sign-On button appears on the login page. Access can be restricted by e-mail domain, address or IdP group, and local password login always stays available as a break-glass path, so a misconfigured provider can never lock you out. Admin-only by design.
Backup reliability overhaul. A series of fixes makes backups robust on slow or connection-limited backends — especially FTP targets, where a slow retention prune could previously wedge an entire schedule:
- feat(auth): admin single sign-on via OpenID Connect (Keycloak, Azure AD, Google, …)
- fix(backup): recover from stale restic locks so a failed run can't wedge all future backups
- fix(backup): serialize restic ops per FTP host to avoid 530 connection-limit failures
- fix(backup): prune only weekly per repo instead of after every backup
- fix(backup): deleting a single snapshot no longer blocks on prune
- fix(backup): deleting a snapshot removes its row from the list immediately