Skip to content

Releases: toralf/tor-relays

v24.05

09 May 09:07
v24.05
Compare
Choose a tag to compare
NEWS:
  - deploy Snowflake Debian package
  - deploy Tor server

CHANGES:
  - speed up Git clone/update operations
  - use 2 parallel make jobs for 2 GiB systems
  - prefer Debian backported kernel
  - reboot into newer Debian kernel first before continuing the deployment

FIXES:
  - removed broken AppArmor config for Tor relays

v24.03

24 Mar 17:42
v24.03
Compare
Choose a tag to compare
NEWS:
  - use a self-signed CA to sign NGinx certificates, used e.g. by Prometheus
  - add logic to use Tor nighly builds from Tor Debian repository
  - add logrotate logic for Tor log files if compiled from source

CHANGES:
  - lower firewall hash-limit value from 10 to 6
  - don't create IPv6 DNS entries

v24.02

25 Feb 09:23
v24.02
Compare
Choose a tag to compare
NEWS:
  - add AppArmor config for Tor if built from source
  - optionally build Linux kernel from source
  - create a 2 GiB swap file
  - initial support for IONOS
  - firewall hash limit rule for obfs4 port

CHANGES:
  - preroute ipv6 traffic only for Tor relays

FIXES:
  - IPv6 MultiCast firewall rule
  - obfs4 for ports < 1024

v24.01

27 Jan 14:12
v24.01
Compare
Choose a tag to compare

NEWS:

  • metrics encrypted on transit using Nginx
  • use of unstable/experimental kernel

CHANGES:

  • ansible inventory name rules over hostname

FIXES:

  • outdated facts caching

v23.12

28 Dec 17:20
v23.12
Compare
Choose a tag to compare
NEWS:
  - install node_exporter (optional)
  - install additional software (optional)

CHANGES:
  - activate metrics only if port is given

FIXES:
  - Go installation

v23.11

05 Nov 16:34
v23.11
Compare
Choose a tag to compare
CHANGES:
  - Snowflake stats are logged minutely (before: hourly)
  - current IPv6 addresses are no longer stored in unbound config,
    instead <prefix>::1 is used

FIXES:
  - logic to prefer ARM over AMD

v23.10

11 Oct 18:25
v23.10
Compare
Choose a tag to compare
NEWS:
  - use newer Go from backports for snowflake
  - allow patching of Snowflake
  - add IPv6 addreses to DNS too

CHANGES:
  - do not set ssh options on our own

FIXES:
  - remove dst from iptables rule of SSH to allow creating new images from snapshot

v23.09

10 Sep 09:41
v23.09
Compare
Choose a tag to compare

NEW:

  • ipv4 firewall

CHANGES:

  • no limitiation for global scope ipv6 address
  • DNAT /64 tcp (except obfs4 port), UDP and ICMP to it

v23.08

06 Aug 14:09
v23.08
Compare
Choose a tag to compare
Fixes:
  - usage/dep of hcloud context within an Ansible role is removed

Changes:
  - ORPort for public + private bridges is no longer exposed/randomized

New:
  - handling of Snowflake bridges

v23.06

17 Jun 08:43
Compare
Choose a tag to compare
suppress error about non-existing files