v2.5.1

caddyserver/caddyv2.5.1May 6, 2022by github-actions[bot]

AI Summary

A minor patch release that fixes regressions in admin endpoints and the `caddy trust` command, while enhancing the reverse proxy with improved hashing algorithms and a new `forward_auth` wrapper directive for forward authentication.

Key Highlights

  • Fixed regressions in Unix socket admin endpoints and `caddy trust` commands.
  • Improved hash-based load balancing policies (HRW algorithm) for consistent upstream mapping.
  • Added `forward_auth` wrapper directive to simplify forward authentication patterns (e.g., with Authelia).
  • Added `copy_response` and `copy_response_headers` handlers for response interception.

New Features

  • New `forward_auth` directive for authentication providers.
  • New `copy_response` and `copy_response_headers` response handlers.
  • Improved HRW hashing for load balancing policies (ip_hash, uri_hash, header, cookie).

Full Release Notes

This is a minor patch release that fixes some bugs and also enhances `reverse_proxy` with capabilities that weren't ready in time for v2.5.0.

### Highlights

- Fixed regression in Unix socket admin endpoints.
- Fixed regression in `caddy trust` commands.
- Hash-based load balancing policies (ip_hash, uri_hash, header, and cookie) use an improved highest-random-weight (HRW) algorithm for increased consistency. The new rendezvous hash will ensure a client or request is _consistently_ mapped to a particular upstream even if the list of upstreams changes.
- The reverse proxy is now able to rewrite the method and URI on its internal copy of the request that goes to the upstream. Combined with new `handle_response` capabilities, this enables the reverse proxy to fire off ["pre-check requests"](https://github.com/caddyserver/caddy/pull/4739) (for lack of a better term) to make routing decisions based on the results of that call. This enables a commonly-emerging pattern called _forward authentication_ wherein a backend is queried to assess a client's authorization to be proxied. The [full, verbose config for this](https://github.com/caddyserver/caddy/pull/4739#issuecomment-1113901951) is very flexible but tedious, so we made a new wrapper directive called `forward_auth` that eliminates the boilerplate (very similar to the [`php_fastcgi` directive](https://caddyserver.com/docs/caddyfile/directives/php_fastcgi#expanded-form)):
```
forward_auth authelia:9091 {
	uri /api/verify?rd=https://auth.example.com
	copy_headers Remote-User Remote-Groups Remote-Name Remote-Email
}
```
This works with authentication providers like Authelia, and more.

## What's Changed
* caddypki: Fix `caddy trust` command to use the correct API endpoint by @francislavoie in https://github.com/caddyserver/caddy/pull/4730
* reverseproxy: Improve hashing LB policies with HRW by @mholt in https://github.com/caddyserver/caddy/pull/4724
* Add missing backticks by @mahgoh in https://github.com/caddyserver/caddy/pull/4737
* caddyhttp: Improve listen addr error message for IPv6 by @francislavoie in https://github.com/caddyserver/caddy/pull/4740
* cmd: Fix unix socket addresses for admin API requests by @francislavoie in https://github.com/caddyserver/caddy/pull/4742
* logging: Use `RedirectStdLog` by @francislavoie in https://github.com/caddyserver/caddy/pull/4732
* logging: Implement rename filter, changes field key names by @francislavoie in https://github.com/caddyserver/caddy/pull/4745
* httpcaddyfile: Fix duplicate access log when debug is on by @francislavoie in https://github.com/caddyserver/caddy/pull/4746
* reverseproxy: Fix Caddyfile support for `replace_status` by @francislavoie in https://github.com/caddyserver/caddy/pull/4754
* templates: Add custom template function registration by @kroppt in https://github.com/caddyserver/caddy/pull/4757
* reverseproxy: Permit resolver addresses to not specify a port by @francislavoie in https://github.com/caddyserver/caddy/pull/4760
* caddyfile: Shortcut for `remote_ip` for private IP ranges by @francislavoie in https://github.com/caddyserver/caddy/pull/4753
* reverseproxy: Support performing pre-check requests by @francislavoie in https://github.com/caddyserver/caddy/pull/4739
* map: Prevent output destinations overlap with Caddyfile shorthands by @francislavoie in https://github.com/caddyserver/caddy/pull/4657

## New Contributors
* @mahgoh made their first contribution in https://github.com/caddyserver/caddy/pull/4737

## Changelog
* ec86a2f7 caddyfile: Shortcut for `remote_ip` for private IP ranges (#4753)
* dcc98da4 caddyhttp: Improve listen addr error message for IPv6 (#4740)
* d543ad1f caddypki: Fix `caddy trust` command to use the correct API endpoint (#4730)
* 2e4c0915 cmd: Fix unix socket addresses for admin API requests (#4742)
* af732151 httpcaddyfile: Fix duplicate access log when debug is on (#4746)
* 0be3d995 logging: Implement rename filter, changes field key names (#4745)
* 3017b245 logging: Use `RedirectStdLog` to capture more stdlib logs (#4732)
* f7be0ee1 map: Prevent output destinations overlap with Caddyfile shorthands (#4657)
* 4a223f52 reverseproxy: Fix Caddyfile support for `replace_status` (#4754)
* 40b193fb reverseproxy: Improve hashing LB policies with HRW (#4724)
* e7fbee8c reverseproxy: Permit resolver addresses to not specify a port (#4760)
* f6900fcf reverseproxy: Support performing pre-check requests (#4739)
* e84e19a0 templates: Add custom template function registration (#4757)
* 3ab64838 templates: Add missing backticks in docs (#4737)

**Full Changelog**: https://github.com/caddyserver/caddy/compare/v2.5.0...v2.5.1