Remove forced WebSocket headers from media middleware
Traefik v3 handles WebSocket Upgrade/Connection headers natively. Remove forced headers that broke non-WebSocket API requests.
Add system account to all NATS configs
Add $SYS account with admin credentials to k0m1, k1m1, and k2m1 NATS configs. Enables nats CLI cluster management operations (peer removal, step-down, etc.) for...
Resilient probes so cluster stays up when one node is offline
- Liveness: tcpSocket on 4222 (do not depend on JetStream meta leader) - Readiness: initialDelay 90s, period 15s, failureThreshold 10 so k0m1+k1m1 can form qu...
Update Traefik routes: themes.* assets now only load from k1m1 minio instead of balancing across k0m1, k1m1, and k2m1
Use VPN addresses for k0m1/k2m1 minio-public backends
- Endpoints: k0m1 10.8.0.1, k2m1 10.8.2.1 (VPN); k1m1 stays local - IngressRoute host match: 100.64.x.x -> 10.8.0.1, 10.8.1.1, 10.8.2.1
Skip CockroachDB init job if any pods exist - cluster already initialized
Improve CockroachDB init check to wait for pods and verify cluster state
Prevent CockroachDB init job from running when cluster is already initialized
Update CockroachDB probes, HTTP redirect, and MinIO service endpoints
Add CORS middleware to theme routes to allow cross-origin access from all websites
Add HTTP to HTTPS redirect middleware and IngressRoute
- Create redirect-to-https middleware for permanent redirects - Add catch-all IngressRoute on web entrypoint to redirect all kamocrm.com domains to HTTPS - Fixe...
Remove hostPort from Traefik deployment
- Port 443 is already bound by ingress-nginx via CNI hostPort - Keep standard containerPort configuration
Change Traefik service to LoadBalancer with externalIPs for direct access
- Use LoadBalancer type with externalIPs instead of NodePort - Allows router to forward port 443 directly to service IP - This should bypass ingress-nginx hostP...
Add hostPort to Traefik deployment for direct port access
- Use hostPort 443 for websecure entrypoint to bypass NodePort - Allows router to forward port 443 directly to Traefik - Also set hostPort for web (30080) and a...
Đặt chính sách giao thông bên ngoài thành địa phương cho dịch vụ Bồ Đào Nha Traefik
- Cho phép dự đoán chính xác giao thông bên ngoài từ bộ định tuyến - Bảo tồn địa chỉ IP nguồn để đăng nhập tốt hơn
Update CockroachDB StatefulSet to use dynamic VPN IP based on node hostname
- Fix advertise-addr to use VPN IP (10.8.1.1 for k1m1, 10.8.2.1 for k2m1) - Update join parameter to use VPN IPs instead of hostnames - Update node certificate ...
Kích hoạt đường ống dẫn để triển khai Traefik CRD sau khi thiết lập lại v.v
Thêm chứng nhận nút để tạo bí mật CockroachDB
- Thêm nút.cert và nút.key vào thư mục gián - Cập nhật dòng làm việc của CIA/CD bao gồm chứng nhận nút khi tạo bí mật *** - Sửa con gà trống và con gà trống
Xử lý lùi LumitExd bằng cách xóa công việc và thử lại bị lỗi
- Khi công việc thất bại với việc sử dụng BackoffLimitted và kén được dọn sạch, xóa và tái tạo công việc - Điều này cho phép chúng tôi có được các bản ghi mới t...
Xử lý trở lại LumitExd bằng cách xóa và thử lại công việc
- Khi công việc thất bại với việc sử dụng BackoffLimitted và kén được dọn sạch, xóa và tái tạo công việc - Điều này cho phép công việc để thử lại và thành công ...
Improve CockroachDB init job error handling when pods are cleaned up
- Check previous pod logs if current pods are not found - Test cluster connectivity to verify if already initialized - Better handling of failed jobs with clean...
MinIO secret creation from workflow (MinIO is managed manually)
Add automatic *** secret creation
- Create *** secret on both k1m1 and k2m1 - Secret contains MINIO_CURRENT_HOST pointing to k0m1 MinIO instance (http://10.8.0.1:9000) - Fixes kamowssecurity-dep...
Resolve Traefik, NATS, and CockroachDB deployment issues
- Remove hostPort from Traefik deployment (conflicts with NodePort service) - Fix NATS deployment to only deploy server-specific statefulsets (nats-k1m1, nats-k...
Improve CockroachDB init job error handling - check pod status and logs after timeout
Update IP addresses from Tailscale (100.64.x.x) to WireGuard VPN (10.8.x.x) for NATS, CockroachDB, and CI/CD workflows
Thêm biểu tượng Kamo đầy đủ SVG với tất cả 14 đường
Đính toàn bộ nội dung SVG trực tiếp thay vì các đường dẫn bộ phận
Dùng biểu tượng Kamo chỉ dùng cách tiếp cận CSS
Đã gỡ bỏ gắn kết tập tin SVG bị hỏng, dùng ảnh nền của CN để tải biểu tượng bên ngoài trực tiếp trên #logo yếu tố
Sửa biểu tượng.svg để tham khảo biểu tượng của Kamo
Dùng yếu tố ảnh SVG để nhúng biểu tượng bên ngoài thay vì những con đường phức tạp với những biến đổi bị hỏng
Thay thế biểu tượng hình tròn.svg với logo Kamo SVG
Kết nối để thay thế biểu tượng hình tròn
Tự chọn
- Tạo ra các công ty tự chọn với quyền ghi đè - Lắp tập tin CSS vào /var/www/html/custom.css - Cấu hình Roundcube để tải các mẫu tinh tế bổ sung
Mẫu
Cập nhật định dạng da logo để bao gồm: - logo đầu trang chính - logo tiêu đề nhỏ - logo mạch nước/mặt sau
Thêm tiểu dụng thư vào danh sách tự động ký tự
Bật tạo chứng nhận SSL tự động cho thư.kamocram.com
Name
Qua Postfix cục bộ để gửi thư đi, kết nối trực tiếp tới smtp.mailgun.org với TLS trên cổng 587
Chuyển đổi Postfix sang việc triển khai dựa trên Alpine với khả năng mã hoá mã định dạng
Tương tự như Dovecot, sử dụng Alpine 3.18 với gói postfix-mysql đã cài đặt vào lúc chạy để hỗ trợ bản đồ ảo ICC đáng tin cậy
Fix postfix command to use apt-get instead of apk
boky/postfix is Debian-based, not Alpine
Add postfix-mysql support for MySQL virtual maps
Installed postfix-mysql package at container startup to enable MySQL dictionary lookups for virtual domains/users/aliases
Như những gì anh thấy vận chuyển?
Mỗi một bản cập nhật này đều được tự động cập nhật trong không gian làm việc của bạn. Bắt đầu tự do và xem nó lớn lên tuần này qua tuần khác.