NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #560 by repository stars
Last release 8 days ago
29 Sep 2026
Release timing varies
gaps range from 8 days to 2 months
Nearly every release is documented
notes for 26 of 26 stable releases
21 versions withdrawn
withdrawn after publishing
5 years old
274 releases · first in 2021
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release improves Cloudflare trace IP detection, adds a GitHub Container Registry mirror, and makes configuration errors easier to diagnose.
This release improves Cloudflare trace IP detection, adds a GitHub Container Registry mirror, and makes configuration errors easier to diagnose.
cloudflare.trace provider now tries multiple Cloudflare endpoints and uses the first validated response, allowing detection to succeed when an endpoint is slow or unavailable. This also removes cloudflare.trace:<url>, an unofficial workaround for past temporary Cloudflare server outages. (#1262, #1263)ghcr.io/favonia/cloudflare-ddns, with the same tags as Docker Hub and cosign verification for release images. (#1264)hostid6 values missing leading colons. (#1282)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release adds experimental controls for per-domain IPv6 host IDs and detected-address filtering, and makes advanced configuration easier to valida
This release adds experimental controls for per-domain IPv6 host IDs and detected-address filtering, and makes advanced configuration easier to validate. It also removes the startup token-verification request that produced misleading warnings for valid account API tokens.
AAAA records by adding the experimental hostid6 field to entries in DOMAINS or IP6_DOMAINS, for example example.org{hostid6=::1}. A domain can preserve the detected host bits, replace them with a fixed host ID, or derive one from a MAC address. This changes only AAAA record derivation; WAF lists continue to use the raw detected prefixes. (#1224)IP4_DETECTION_FILTER and IP6_DETECTION_FILTER expressions select detected addresses before both DNS and WAF reconciliation. If a filter removes every address for one family, the updater preserves that family's existing managed content for the round. (#1231)PROXIED. The updater now warns about suspicious boolean expressions, including constant results and redundant or subsumed terms. (#1235)SHOUTRRR_FILE reads Shoutrrr notification URLs from a file, making mounted secrets usable without putting token-bearing URLs in environment values. If SHOUTRRR and SHOUTRRR_FILE are both set, they must specify the same URLs. (#1241)HEALTHCHECKS and UPTIMEKUMA are configured, a failure from either service no longer prevents the updater from contacting the other. (#1249)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This is a quick bugfix release for users affected by a startup regression in 1.16.0. If 1.16.0 or 1.16.1 reports that your Cloudflare API token is inv
This is a quick bugfix release for users affected by a startup regression in 1.16.0. If 1.16.0 or 1.16.1 reports that your Cloudflare API token is invalid during startup even though the token had worked before 1.16.0, upgrade to 1.16.2. If version 1.16.0 or 1.16.1 is working well for you, there is no rush.
We will continue investigating the unexpected behavior around Cloudflare’s token-verification endpoint; see #1197.
Nothing published for this version
This is a bugfix release for the new static.empty provider introduced in 1.16.0. If you are not using static.empty , this release should not affect yo
This is a bugfix release for the new static.empty provider introduced in 1.16.0. If you are not using static.empty, this release should not affect you. A nice consequence of these fixes is the following one-shot wipe-all workflow:
UPDATE_CRON=@once for a single-run execution.IP4_PROVIDER=static.empty and IP6_PROVIDER=static.empty to clear all managed DNS records and WAF items.DELETE_ON_STOP=true to make the updater also try to delete the WAF lists themselves.Note: this workflow is for using the updater as a single-run command, not as a long-running Docker deployment.
Please provide feedback on the proposed syntax of upcoming features:
IP6_DOMAINS=sub.example.com{hostid6=::2}IP4_DETECTION_FILTER=!addr-in(10.0.0.0/8)If you are still using PUID and PGID, please migrate to Docker’s built-in security mechanism; see the changelogs of previous versions.
static.empty no longer creates a missing WAF list. In addition, DELETE_ON_STOP=true with UPDATE_CRON=@once is now accepted when every managed IP family uses static.empty or none. (#1190)Despite the gap of over a year since the last release, we are not aware of any security vulnerability affecting the default configuration. As always,…
Despite the gap of over a year since the last release, we are not aware of any security vulnerability affecting the default configuration. As always, please review the changelog and watch for warnings or errors when upgrading.
IP4_DEFAULT_PREFIX_LEN (default /32) and IP6_DEFAULT_PREFIX_LEN (default /64) control how bare addresses are stored in WAF lists. Users can now set IP6_DEFAULT_PREFIX_LEN to 128 for per-address granularity. DNS records currently ignore prefix lengths, but will use these in the future.MANAGED_RECORDS_COMMENT_REGEX and MANAGED_WAF_LIST_ITEMS_COMMENT_REGEX let multiple updater instances safely share the same domain or WAF list, each managing only records or items with matching comments. New WAF_LIST_ITEM_COMMENT provides a fallback comment for WAF list items, similar to how RECORD_COMMENT serves as a fallback for DNS records.local.iface provider now collects all matching global unicast addresses from the specified interface, instead of just the first one. Multi-address support in url: and file: providers is also experimental.file: provider. Reads IP addresses from a local file, re-reading each detection cycle. This enables integration with external scripts or monitoring systems without restarting the updater. (Multi-address support is experimental.)url: (url.via4: and url.via6:) for transport overrides. By default, url:<url> connects using the same IP family as the address being detected. Override the IP family used to connect with url.via4:<url> or url.via6:<url> (e.g., get an IPv6 address over an IPv4 connection). (Multi-address support in URL-based providers is experimental.)The IP prefix length work in this release lays the groundwork for several upcoming features. We’d love your input on the proposed configuration syntax:
IP6_DOMAINS=sub.example.com{hostid6=::2}IP6_DOMAINS=sub.example.com{hostid6=preserve} (keep the detected host IDs)IP6_DOMAINS=sub.example.com{hostid6=mac(77:cc:a7:f9:45:94)} (compute an EUI-64 host ID from a MAC address)DOMAINS=sub1.example.com{hostid6=::aad1},sub2.example.com{hostid6=preserve}IP6_DETECTION_FILTER=keep-allIP6_DETECTION_FILTER=!addr-in(fc00::/7)IP6_DETECTION_FILTER=subnet-in(2001:db8:abcd::/48)IP4_DETECTION_FILTER=!addr-in(10.0.0.0/8) && !addr-in(192.168.0.0/16)IP6_DETECTION_FILTER=contains(2002:dead:beef::/100) || contains(2005:dead:beef::/100)| input | addr-in(1.1.0.0/16) |
subnet-in(1.1.0.0/16) |
contains(1.1.0.0/16) |
|---|---|---|---|
1.1.1.1/8 |
✔️ | ❌️ | ✔️ |
1.1.1.1/16 |
✔️ | ✔️ | ✔️ |
1.1.1.1/24 |
✔️ | ✔️ | ❌️ |
1.2.2.2/8 |
❌️ (1.2.2.2 not in 1.1.0.0/16) |
❌️ | ✔️ |
Also planned: a linter for boolean expressions targeting advanced usage of PROXIED and the upcoming IP4/6_DETECTION_FILTER, and further robustness improvements to the default cloudflare.trace provider.
As a reminder, since 1.13.0, the updater no longer drops privileges internally, and PUID and PGID are ignored. Please use Docker’s built-in mechanism to drop privileges. The old Docker Compose template may grant unneeded privileges to the new updater, which is not recommended. Please review the new, simpler, and more secure template in README. In a nutshell, remove the cap_add attribute and replace the environment variables PUID and PGID with the user: "UID:GID" attribute. Similar options may exist for systems not using Docker Compose.
Shoutrrr support is no longer experimental. The shoutrrr notification integration, introduced in 1.12.0, is now considered stable.
IP4_DEFAULT_PREFIX_LEN and IP6_DEFAULT_PREFIX_LEN settings control how bare addresses are stored in WAF lists. (#1144) (#1156)file: provider reads IP addresses from a local file. (#1148)static:<ip1>,<ip2>,... and static.empty providers have been added. static.empty actively clears managed content for a given IP family. (#1102) (#1135)url:, file:, and static: providers now accept addresses in CIDR notation (e.g., 198.51.100.1/24). (#1159) (#1169)local.iface provider now collects all matching global unicast addresses. (#1095)MANAGED_RECORDS_COMMENT_REGEX selects only DNS records whose comments match a regex. (#1103)MANAGED_WAF_LIST_ITEMS_COMMENT_REGEX and WAF_LIST_ITEM_COMMENT provide the same comment-based selection for WAF list items. (#1106)url.via4:<url> and url.via6:<url> providers override the IP family used to connect to a custom URL. (#1131)SHOUTRRR values. (#1111)a,,b) except for trailing commas, which were silently ignored. (#1177)EMOJI or QUIET is invalid. (#1174)cloudflare.trace and cloudflare.doh) now validate detected IP addresses more strictly. (#1097) (#1099) (#1101) (#1151)Nothing published for this version
Nothing published for this version
Nothing published for this version
This is a minor release that modifies the Cloudflare URLs used by the IP providers cloudflare.trace (the default) and cloudflare.doh . The IP provider
This is a minor release that modifies the Cloudflare URLs used by the IP providers cloudflare.trace (the default) and cloudflare.doh. The IP provider cloudflare.trace was updated to address recent mysterious 1034 errors from Cloudflare servers. Additionally, both providers have been switched away from 1.1.1.1, eliminating the need for a detection algorithm to determine whether 1.0.0.1 is a more suitable alternative. This simplification results in cleaner code and potentially lower resource usage.
For enhanced debugging capabilities, we have introduced a new Docker tag, edge-alpine. This tag provides a full Alpine Linux environment, offering basic system tools and libraries. Please note that this image is larger than the standard development tag edge and is not minimal.
As a reminder, since 1.13.0, the updater no longer drops superuser privileges and PUID and PGID are ignored. Please use Docker’s built-in mechanism to drop privileges. The old Docker Compose template may grant unneeded privileges to the new updater, which is not recommended. Please review the new, simpler, and more secure template in README. In a nutshell, remove the cap_add attribute and replace the environment variables PUID and PGID with the user: "UID:GID" attribute. Similar options may exist for systems not using Docker Compose.
cloudflare.doh and cloudflare.trace URLs (#994) (eaa9c61)edge-alpine that contains Alpine Linux (not minimal) (#978) (#980) (21d9f94) (7d8ef9a) (#981) (c9f4f12) (#982) (73a4ba3) (#998) (bd85cad)debug.const provider (#966) (638c1a2)cloudflare.trace:URL provider (#988) (7afb1d2)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
The old CF_API_TOKEN and CF_API_TOKEN_FILE will still be fully supported until 2.0.0, then deprecated (but still supported) until 3.0.0.
This is a major release with many improvements:
CLOUDFLARE_* variables: Cloudflare is transitioning its tools to use the new prefix CLOUDFLARE_*. Therefore, the updater now accepts CLOUDFLARE_API_TOKEN and CLOUDFLARE_API_TOKEN_FILE. The old CF_API_TOKEN and CF_API_TOKEN_FILE will still be fully supported until 2.0.0, then deprecated (but still supported) until 3.0.0.url:<URL>. This solves a long-standing issue where custom providers couldn't be used on dual-stack machines supporting both IPv4 and IPv6. This enforcement ensures predictable IPv4/IPv6 detection on such machines.local provider. The syntax for this feature is under development and will not be finalized until 1.16.0. Please refer to README and join the discussion on GitHub issue #713 if you are interested.As a reminder, since 1.13.0, the updater no longer drops superuser privileges and PUID and PGID are ignored. Please use Docker’s built-in mechanism to drop privileges. The old Docker Compose template may grant unneeded privileges to the new updater, which is not recommended. Please review the new, simpler, and more secure template in README. In a nutshell, remove the cap_add attribute and replace the environment variables PUID and PGID with the user: "UID:GID" attribute. Similar options may exist for systems not using Docker Compose.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This is an urgent hotfix that resolves a nil pointer dereference issue introduced in version 1.14.1.
Nothing published for this version
This version is buggy; use version 1.14.2 instead.
This version is buggy; use version 1.14.2 instead.
This is a minor release that addresses minor issues and improves the usability of the new feature for managing WAF lists, which was initially introduced in version 1.14.0.
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →