mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-09-18 04:42:30 +03:00
docker-compose.yml and docker-compose.prod.yml defaulted API_HOST/LIVE_WS_HOST/ HOSTNAME to 0.0.0.0 and published the dashboard/API/live-WS ports with bare, unscoped specs, which Docker expands to every interface. Combined with REQUIRE_API_KEY=false shipping as the .env.example default, this exposed the anonymous /v1 LLM proxy to the whole LAN/WAN (#12568). The optional cliproxyapi sidecar had the same unscoped publish spec plus no forwarded auth env var, exposing a credential-bearing service the same way (#12578); qdrant and bifrost had the identical gap. Applies the existing Redis loopback-bind precedent (tests/unit/compose-redis- loopback-bind.test.ts) to the app's own ports and to cliproxyapi/qdrant/bifrost: - New APP_BIND_HOST / CLIPROXY_BIND_HOST / QDRANT_BIND_HOST / BIFROST_BIND_HOST opt-in vars, defaulting to 127.0.0.1, documented in .env.example and docs/reference/ENVIRONMENT.md. - API_HOST/LIVE_WS_HOST default to 127.0.0.1 in both compose files; the prod file no longer hardcodes HOSTNAME=0.0.0.0. - cliproxyapi now forwards CLIPROXYAPI_MANAGEMENT_KEY as MANAGEMENT_PASSWORD, the one env var the pinned image actually reads for its management API. - A new boot-time guard (src/lib/startup/nonLoopbackApiKeyGuard.ts) logs a warning — never a hard failure — when the API bridge or live-WS server ends up bound to a non-loopback host while REQUIRE_API_KEY is disabled. ⚠️ base-red inherited: #12732 — unit #12058, integration codex-cache, package-artifact, tarball-smoke, agent-skills-sync Closes #12568 Closes #12578
changelog.d/ — changelog fragments
A PR never edits CHANGELOG.md directly during the cycle. Instead it adds ONE new
file here — its changelog entry as a fragment. Two PRs never touch the same file, so
changelog merge conflicts (the "CHANGELOG-eat" cascade that forced a re-sync push + full
CI re-run after every sibling merge) are structurally impossible.
Convention
| Directory | Aggregates under |
|---|---|
features/ |
### ✨ New Features |
fixes/ |
### 🐛 Bug Fixes |
maintenance/ |
### 📝 Maintenance |
- Filename:
<PR-number>-<short-slug>.md(e.g.fixes/6700-dockerfile-better-sqlite3.md). The PR number prefix keeps aggregation order deterministic. - Content: the exact bullet line(s) that should land in
CHANGELOG.md, starting with-. Multi-line (continuation) bullets are fine. Keep the repo's credit format:(#PR — thanks @user). - One fragment per PR (rarely more, e.g. a PR that both fixes and adds).
Example
changelog.d/fixes/6496-cloudflare-relay-worker-syntax.md:
- **fix(providers):** Cloudflare relay Worker deploys use Service Worker syntax with `body_part` metadata ([#6496](https://github.com/diegosouzapw/OmniRoute/pull/6496)) — thanks @SeaXen
Aggregation
The release captain (or /generate-release) folds all fragments into CHANGELOG.md and
deletes them:
node scripts/release/aggregate-changelog.mjs # write + delete fragments
node scripts/release/aggregate-changelog.mjs --dry-run # preview only
Fragment well-formedness is enforced by npm run check:changelog-integrity (the same
gate that guards against CHANGELOG-eat for legacy direct edits).