All notable changes to this project will be documented in this file.
The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
- containers: Show metrics history in container detail (#415)
- config: Expose sandbox backend selection in settings API and UI (#414)
- web: Override brace-expansion and js-yaml to patched versions (#409)
- observability: Prevent ClickHouse Array(Nothing) decode failures (#408)
- clickhouse: Align query result integer types (#416)
- deployments: Preview commits before deployment (#379)
- email: Dedup shared email UI helpers, working event filters, per-domain delivery stats (#307)
- deployments: Preview tag commits before deployment (#383)
- email: Add provider detail page with domains and delivery tracking setup (#382)
- telemetry: Add deploy_cancelled event (#385)
- web: Add metrics storage backend selector to monitoring settings (#399)
- sandbox: Firecracker microVM backend alongside Docker (ADR-029)
- cli: Type email command output and sanitize rendered bodies (#306)
- email: Secure SES SNS event processing with one-click tracking setup (#297)
- email: Stop leaking suppressed recipient addresses via logs/error_message (#380)
- web: Make DNS records table horizontally scroll on mobile (#381)
- email: Correct SES IAM action namespace from sesv2: to ses: (#384)
- analytics: Derive bounce/entry/exit from session pageviews at query time (#398)
- sandbox: Address PR #400 review — CI, OpenAPI/SDK, guard, security
- sandbox: Satisfy clippy + vercel-compat guardrail (PR #400 CI)
- cli: Update sandbox_url tests to canonical plural route
- proxy: Resolve request-log detail by request_id across storage backends (#402)
- audit: Keep audit history when a user account is deleted (#386)
- auth: Remove magic-link login (#375)
- backup: Dump only critical table data in control-plane backups (#367)
- proxy: Trust CF-Connecting-IP from verified Cloudflare egress ranges (#368)
- monitoring: Track container CPU/memory for external services (#371)
- observability: Compress immutable telemetry after 24h (#370)
- telemetry: Aggregated anonymous error_summary event (#373)
- telemetry-api: Accept error_summary event (#374)
- auth: Let deployment tokens call the AI gateway (ai_gateway:execute) (#377)
- compose-security: Cache Docker toolchain layers and prebuild with fast profile (#362)
- skill: Add remote-over-SSH install method to temps-platform-setup (#366)
- core: Resolve request IP trust-awarely for audit/logging (#363)
- skill: Remove piped shell install and explicit credential paths from docs (#365)
- deployments: Emit deploy_succeeded telemetry on the real success path (#372)
- webhooks: Pin delivery to validated IP to close DNS-rebinding SSRF (#332)
- observability: Read active Timescale policies (#378)
- analytics: Add insights panel with stat and AI insights
- analytics: Put insights behind a compact toggle button
- ai-chat: Default-on read-only chat; route analytics AI insights through project chat
- analytics: Add raw event entries drill-down with JSON props view (#359)
- settings: Show web-console banner when a newer release is available (#353)
- analytics: Harden AI insights prompt + warn on partial AI disable
- proxy: Harden preview cookie session handling (#361)
- web: Replace rocketship logo assets with the t brand mark (#358)
- metrics: Time-bound external-service latest-metric queries (#364)
- skills: Add estimate-temps-savings skill (#357)
- backup: Stop stranding failed uploads that block retention cleanup (#356)
- mcp: Remove @temps-sdk/mcp package (#355) [BREAKING]
- error-tracking: Deep-link error alert emails, verify Slack stays HTML-free (#308)
- analytics: Add daily returning visitor metric (#346)
- backups: Add retention cleanup and manual deletion (#336)
- monitoring: Monitor all mounted disks for disk-space alerts (#349)
- settings: Add flat public hostname strategy (#146)
- Remove dependabot auto-merge workflow (#345)
- metrics: Don't UNION checkpoint queries across pg_stat_checkpointer/bgwriter (#290)
- metrics: Use mongodb's re-exported bson instead of a standalone dep (#291)
- migrations: Skip empty visitor deduplication rewrites (#294)
- deployer: Harden compose deployments
- deployer: Close compose security policy bypasses from review
- deployer: Reject interpolation bypass and confine compose paths
- deployer: Prevent compose conflict container deletion
- deployer: Fold inline compose override allow-list into host-escape hardening
- deployer: Close compose host-escape bypasses found in review
- core: Update node pki for rcgen 0.14
- deps: Resolve RustSec advisory updates
- proxy: Update test cert generation for rcgen 0.14
- deployer: Close volumes_from and absolute bind-mount host-escape bypasses
- deployer: Close remaining compose host-escape gaps from review
- deployer: Close compose symlink escape paths
- deployments: Cap hosted website memory by default (#164)
- deps: Unbreak build — pin aws-smithy (schema 0.1.0) and revert sqlx to 0.8 (#333)
- auth: Prevent MFA challenge session from authenticating real requests (#326)
- web: Satisfy ESLint 10 assignment rules
- git: Constant-time comparison for GitHub webhook HMAC signatures (#334)
- auth: Close assign_role privilege-escalation (admin gate + single target) (#324)
- webhooks: Close retry_delivery cross-tenant IDOR (#329)
- otel: Make otel_spans compression effective by dropping trace_id from segmentby (#348)
- compose: Require DB/Redis secrets, stop publishing internal ports on 0.0.0.0 (#330)
- git: Bind webhook tokens to projects (#335)
- query-postgres: Block function-call SQLi bypass in data-explorer WHERE clauses (#328)
- deployer: Narrow compose hardening scope
- deps-dev: Bump @eslint/js from 9.37.0 to 10.0.1 in /web
- web: Lazy-load and paginate proxy traffic-by-project table (#292)
- deployer: Cargo fmt compose policy
- metrics: Regression coverage for pg_stat_checkpointer/bgwriter query (#293)
- otel,proxy: Parameterize ClickHouse retention via per-row retention_days
- web: Add per-dimension web vitals breakdown to speed insights
- analytics-performance: Geo breakdowns and segment filters for speed metrics
- web: World map of web vitals by country on the speed page
- analytics-performance: Read-time bot filtering for speed metrics
- agents: Document Docker safety constraints (#232)
- retention: Remove EE mentions from OSS comments
- web: Adapt chart and replay types to recharts 3 and rrweb-player 2 (#277)
- otel,proxy: Register RetentionResolver via the service registry
- otel,proxy: Defer RetentionResolver lookup past plugin registration order
- analytics: Exclude bots and datacenter IPs from live-visitors (#281)
- proxy: Thread a shared RetentionResolver into the live Pingora proxy
- retention: Write-once guard on RetentionResolverSlot + guardrail docs
- analytics-performance: Group page metrics on performance_metrics columns
- react-analytics: Send pathname field the speed ingest endpoint expects
- security: Close three unauthenticated-access CRITICALs (#288)
- providers: Reject client-supplied internal-only fields on external-service create (#287)
- deps-dev: Bump eslint from 9.37.0 to 10.6.0 in /web (#213)
- deps-dev: Bump @rsbuild/core from 1.5.1 to 2.1.4 in /web (#209)
- deps-dev: Bump @rsbuild/plugin-react from 1.4.0 to 2.1.0 in /web (#217)
- sdk: Bump analytics-browser, kv, blob, node-sdk for npm publish (#286)
- proxy: Serve proxy-log stats from a 1-minute continuous aggregate (#278)
- otel: Make storage quota opt-in, disabled by default (#283)
- web: Add Let's Encrypt contact email to Settings page (#273)
- dns: Add Pebble challtestsrv-backed DNS provider for local testing (#275)
- release: Cut macOS/web build time in release pipeline (#271)
- proxy: Isolate preview connection-pool by sandbox target (#274)
- proxy: Track real body bytes for request/response bandwidth (#276)
- domains: Wire config/DNS services into TlsService for auto-renewal (#270)
- analytics-sdk: Exclude sensitive paths from session replay by default
- auth: Audit concurrent sessions and allow requiring MFA for admins (#189)
- deployments: Add generic DeploymentGate extension point (#229)
- providers: Add managed S3 backend protocol + minIO support (#144)
- auth: Add platform-admin role, key/token rotation, and MCP kill-switch (#191)
- deployments: Add SecretsManagerResolver OSS extension seam (ADR 0009 §1-2) (#252)
- proxy: Hot-path metrics with node dashboard and default alerts (#258)
- auth: Add ProjectAccessChecker trait and project_access_guard! macro (ADR 028 Phase A) (#260)
- ai-chat: Allow AI write tool to provision and link external services (#256)
- auth: Wire project_access_guard! into all project-scoped handlers (ADR 028 Phase B) (#261)
- ai-tools: Expose deployment and node metrics to AI read allowlist (#265)
- auth: Project-scoped permission narrowing (project_permission_guard!) (#268)
- Add dependency and container scanning for Temps' own supply chain (#187)
- Auto-merge dependabot patch/minor PRs once CI passes (#228)
- Reduce rust-cache eviction churn and stop starving PRs of it (#248)
- Fix unit-tests build taking 22m+ due to feature-flag cache mismatch
- Build test binaries once via cargo-nextest, share across all jobs (#253)
- Forbid environment variables for runtime configuration
- Require new features to scale on small resources (#257)
- adr: Project-scoped RBAC enforcement (ADR 028) (#259)
- ci: Make rust-tests reliably fail on test failures
- providers: Bind provisioned service ports to 127.0.0.1 instead of 0.0.0.0 (#190)
- ci: Serialize docker-deployments integration tests to stop Postgres deadlocks (#195)
- test-utils: Disable TimescaleDB background workers in TestDatabase (#196)
- ci: Disable TimescaleDB background workers in integration-tests services container (#197)
- web: Resolve gitlab vs github commit links and trace UI polish (#231)
- web: Add web TypeScript check to CI and fix all errors (#233)
- Resolve stacked dependency-bump compilation breaks on main (#247)
- Repair rcgen 0.14 API breaks on main (#250)
- providers: Persist actual bound port after container creation retry (#254)
- auth: Enforce privilege ceiling on custom API key permissions (#267)
- analytics: Resolve visitor_id on lookup miss instead of dropping it (#269)
- scripts: Add local testcontainer orphan-cleanup script (#246)
- proxy: Remove per-request database dependencies from the hot path (#230)
- otel: Cache storage quota checks to cut ingest DB load (#262)
- auth: Throttle last_used_at writes on every authenticated request (#264)
- Bound proxy-log and monitor-health hypertable lookups by time (#266)
- Gate unauthenticated admin endpoints + expand AI chat allowlist (#249)
- web: Surface AI invocations inline in trace views (#185)
- otel: Label filters and per-series dynamic alerting for metric alerts
- otel: Cross-project trace linking (ADR-027) (#186)
- analytics: Exclude zero-visitor groups from property breakdown
- analytics: Exclude zero-visitor groups from ClickHouse breakdown
- domains: Stop ACME TXT records from stacking across renewals (#182)
- analytics: Stop fabricating +/-100% dashboard trend when there's no baseline
- providers: Harden postgres major upgrades (#151)
- deployer: Make cluster DNS injection opt-in (experimental beta) (#194)
- changelog: Skip preview comment on fork PRs
- deployer: Stop temps-dns-resolver being a container DNS SPOF
- changelog: Generate CHANGELOG.md with git-cliff instead of hand-editing
- notifications: Add Cloudflare Email Sending provider (#160)
- otel: ClickHouse-first OTEL metrics storage with full-fidelity decode
- otel: Temporality-aware rate() and histogram-summary aggregation
- web: Wire metrics explorer to Phase C API + all-metrics overview
- otel: Metric dashboards v1 (sections + metric tiles)
- web: Unify metrics + dashboards into one Metrics surface
- otel: Metric alert rules v1 (threshold alerts + evaluator)
- otel: V1 metric anomaly detection (robust seasonal MAD band)
- web: Make the anomaly alert form legible
- otel: Anomaly backtest — "would this have fired?"
- web: Shade the anomaly band on the metrics explorer
- web: Datadog-style "what's wrong" surface for OTEL metrics
- web: Deploy markers on the metrics explorer chart (Tier 2)
- web: Cross-signal "what changed" strip on the metrics drill-in (Tier 2)
- web: Datadog-style firing status on metric dashboards
- web: Show the anomaly band + breach on the metric chart
- web: Show the anomaly band on standalone metric tiles
- web: Custom date-range filter in the metrics explorer
- otel: Embed a Datadog-style chart in metric-alert emails
- otel: Add x-axis time ticks to alert email chart
- otel: Humanize metric alert notification text (ADR-021 Tier 1)
- ai: General AiService foundation for typed/structured output (ADR-022)
- ai: Add multi-turn streaming (chat_stream) to AiService (ADR-023)
- ai: Ai_conversations + ai_messages schema + project toggle (ADR-023)
- ai: Temps-ai-chat crate — conversation service + provider trait (ADR-023)
- ai: Deployment debug-chat provider + SSE endpoints + plugin (ADR-023)
- projects: Expose ai_alert_summaries_enabled + ai_debug_chat_enabled in project API (ADR-021/023)
- web: AI Assistance settings card — debug chat + alert summary toggles (ADR-021/023)
- web: DeploymentDebugChat — streaming AI debug chat on failed deployments (ADR-023)
- ai: Log-tail enrichment + alert investigation provider (ADR-023)
- web: Generalize DebugChat + mount on alert form (ADR-023)
- ai: Agentic repo tool-calling, live context refresh & cross-project chat list (ADR-023)
- web: AI Providers settings + persistent cross-project assistant dock (ADR-022/023)
- web: Make the AI assistant button global in the top bar (ADR-023)
- ai: Stream tool calls/results to the chat UI + project favicons in the switcher (ADR-023)
- ai: Persist tool calls for reload + chat timestamps + icon-only back button (ADR-023)
- observe: Show only root spans in the feed and search all spans by name
- observability: Storage-agnostic TraceReader (temps-core trait + otel impl)
- ai-chat: Project-level chats, AI trace tools, and write-path security
- otel: Full-fidelity TimescaleDB metrics storage at ClickHouse parity
- ai: Streaming agentic chat + virtual CLI tool, trace UI, alarms, mobile fixes
- multi-node: Harden enrollment, secrets, proxy + mTLS PKI keystone
- multi-node: Node enrollment tokens + registration rate limiting
- multi-node: MTLS cert provisioning — cluster CA + CSR signing (WS-2.1)
- multi-node: MTLS transport — agent TLS serving + CP client (WS-2.1)
- multi-node: Deploy over mTLS — wire CP client into deploy path + IP SAN fix (WS-2.1)
- multi-node: Route node drain through the mTLS deployer factory (WS-2.1)
- multi-node: MTLS for remote log streaming + shared client factory (WS-2.1)
- multi-node: MTLS for the terminal WebSocket proxy (WS-2.1)
- multi-node: Reject edge-route pulls from non-active nodes (WS-3.4, netiso-6)
- deployments: Inject node identity env vars into every container
- nodes: Surface the control plane as a node (id 0) in the admin API
- nodes: Alert operators when a worker node goes offline
- nodes: Alert operators when a worker node recovers (back online)
- nodes: Resource + responsiveness alerts for worker nodes
- nodes: Configurable resource-alert thresholds; defer latency anomaly
- logs: Remote-node container logs in searchable history with container/node filters
- logs: "All containers" live mode — merge per-container streams with source
- monitoring: Control-plane self-metrics (CPU/mem/disk) + alerts
- dns: Control-plane DNS resolver for single-node service discovery (ADR-024)
- ai-api-tools: Add vetted write index + prepare/execute path
- entities,migrations: Ai_pending_actions table + per-project write toggle
- ai-chat: Propose-then-confirm write actions (service+endpoints+tool)
- serve: Wire AI write tool with curated mutation allowlist
- web,projects: Confirm/reject card + per-project write-actions toggle
- web: Enable read-only AI chat inline from the chat surfaces
- web: Enable AI write actions from the chat (confirm-gated)
- web: Label temps_write tool cards with the command, like temps
- web: Show the redacted request params on the proposed-action card
- git: Add list_directory to GitProviderService (GitHub + GitLab)
- ai-chat: General repo-explore tools in every chat (git-connected)
- ai: AI write tools (propose-then-confirm) + chained plans, manual deploys, deploy fixes
- projects: Add project source-type change endpoint
- web: Deployment source card and docker/static deploy UI
- git: Add Gitea, Bitbucket, and Generic git providers (#177)
- Add local build prerequisites (#148)
- changelog: Add Unreleased entry for OpenTelemetry metrics (#158)
- adr: ADR-021 humanized alert notification text
- adr: ADR-022 general AI foundation for typed/structured output
- adr: ADR-023 persistent AI debugging conversations
- changelog: Add full-fidelity TimescaleDB metrics entry (#173)
- adr: Add ADR-020 multi-node deployment hardening + audit
- adr-020: Reassess WS-3 against the Kubernetes routing model
- changelog: Multi-node hardening + worker monitoring
- examples: Add echo-server example + dev-cluster multi-node deploy
- deployer: Note the deliberate get_service for CP DNS bootstrap
- changelog: Add OTel project-scope + AI tool-discovery security entries
- changelog: Document streaming AI chat + temps API tool, trace detail, OTLP log fixes
- changelog: AI propose-then-confirm write actions
- web: Wrap long values in trace span detail panel (#159)
- auth: Constrain deployment token permissions
- auth: Preserve email access and enforce project scope for deployment tokens
- otel: Temporality-correct histogram_summary (no cumulative double-count)
- web: Edit form dropped changed Select values (aggregation, detection)
- web: Keep the project header on one line for long titles
- otel: Qualify service_name in trace WHERE to dodge alias-shadow
- ai: Default model fallback so a provider key alone enables AI (ADR-022)
- ai: PR #158 review — tenant-scope guards, traversal/UTF-8 hardening, typing-bubble + tool-loop tests (ADR-023)
- ai: PR #158 review — medium findings (ADR-022/023)
- cli: Cancel the running migration backend on Ctrl+C
- otel: Scope-guard metric label endpoints + 400 on bad label key
- multi-node: Address security-auditor findings (enrollment/mTLS hardening)
- logs: History filter dropdowns list all sources, not just the current selection
- logs: Chronologically interleave the "All containers" live stream
- mtls: Server-authoritative cert SANs + close #162 review gaps
- security: Patch reachable dependency advisories (postgres, quic, aiohttp)
- notifications: Disambiguate update_email_provider operationId (#163)
- env-vars,dns: 409 on duplicate env var + idempotent DNS publish
- dns: Forward NODATA as NOERROR, not NXDOMAIN
- dns: IPv4-only gateway selection + feeder update-propagation test
- otel,ai: Scope-guard OTel query handlers, permission-aware AI discovery, clippy
- edge: Stop forwarding edge token on asset misses (#169)
- deployments: Enforce container exec scope (#166)
- ai-chat,serve: Harden propose-then-confirm per security review
- ai-chat: Write-actions-on must not block the read-only chat
- ai-write: Add redeploy op, human-readable proposals, better op guidance
- ai-write: Show the full write-op catalog so redeploy is discoverable
- ai-chat,web: Sidebar visibility + redeploy env + write-op diagnostic
- web: Mobile horizontal scroll in deployment job logs
- web: Regenerate SDK for AI chat routes + project AI toggles (ADR-023)
- dev-cluster: Add cluster-formation e2e trace script
- examples: Add OpenTelemetry + error-tracking multi-node demo
- web: Regenerate OpenAPI SDK after merging main
- web/sdk: Add ai_write_actions_enabled to project SDK types
- web/sdk: Regenerate OpenAPI client for AI write actions
- web: Regenerate OpenAPI SDK
- proxy: Cache IP block-list and geolocation to cut per-request DB load (#174)
- otel: Forward-compatible detector schema for metric alert rules
- web: Group project nav into OpenTelemetry + Monitoring
- ai: Extract reusable temps-ai crate with schemas + diagnostics
- analytics-events: Cargo fmt
- web: Full-width metrics + dashboards pages
- otel: Live-ClickHouse round-trip for exp-histogram/summary/exemplar columns
- multi-node: Real container deploy over mTLS (gated live test)
- dev-cluster: From-scratch multi-node e2e harness (mTLS join + deploy)
- providers: Isolate lifecycle tests' ports and container names (#171)
- temps-cli: Per-instance default project, static deploy in
up, full build logs (#154) - deployments: Rebuild from source on rollback for git projects (#155)
- templates: One-click demo deploy for activation (no Git account) (#157)
- agents: Document changelog CI gate and skip-changelog label (#156)
- ci: Serialize heavy provider backup tests + dedupe port selection (#152)
- tls: On-demand certs for the console host + sslip.io auto-enable (#147)
- tls: On-demand HTTP-01 issuance (ADR-018) + renewal-safety fixes (#137)
- monitoring: Enable monitoring by default for new services + DNS/domain UI polish (#142)
- sdk: Add @temps-sdk/api generated OpenAPI client package (#143)
- Anonymous telemetry + Postgres shm_size_mb + custom health-check path (#135)
- serve: Split proxy and console into independent processes (ADR-017 Phase 1)
- proxy: Wire cross-process on-demand wake into
temps proxy(ADR-017 Phase 2) - serve: Version-skew detection +
temps upgrade --splitguidance (ADR-017 Phase 3) - environments: Per-environment attack_mode override
- adr-017: Design Phase 4 — zero-downtime proxy restarts via Pingora graceful upgrade
- deployments: Deploy environments uncapped by default, limits opt-in (#132)
- monitoring: Fire CPU alarms relative to the container CPU limit
- git: SSRF guard + token-drop on GitLab archive redirects
- proxy: Probe app readiness (TCP) before completing on-demand wake (#128)
- proxy: Filter on-demand wake/sleep by node_id + stop leaking detail in 503 bodies
- logs: Filter history logs by deployment id (uuid → i32) (#131)
- web: Improve runtime History log filter layout and multi-day timestamps (#130)
- proxy: Wake on-demand environments via in-process ForceRouteReload to fix first-request 503 (#124)
- deployments: Capture & view logs of previous deployments + security hardening (#123)
- domains: Show actionable card for unclassifiable ACME challenges
- security: Bump vitest to 4.1.0, aiohttp to 3.14.0, pingora to 0.8.1 (#120)
- git: Ignore null-SHA push events to prevent failed 0000000 deployments (#121)
- serve: Remove duplicate backup scheduler + feat(console-kit): headerActions slot (#122)
- onboarding: Setup_complete flag, wizard bypass, per-domain HTTPS, activation checklist
- onboarding: Improve getting-started checklist UX
- proxy: Add AI-agent pages endpoint to proxy logs
- skills: Refresh add-custom-domain and platform-setup skills
- changelog: Record metrics-store mismatch fix, on-demand sandbox build, and related changes
- projects: Send null instead of empty string for git_url when using PAT provider
- projects: Send null instead of empty string for git_url in all create-project paths
- settings: Surface effective metrics store and warn on ClickHouse mismatch
- agents: Build sandbox image on demand only, never at startup
- domains: Renew HTTP-01 certificates via the order-based ACME flow
- deployments: Use project slug for remote deployment hostnames
- web: Console UI polish across palette, activity graph, log viewer, date picker
- agents: Use ghcr.io/gotempsh/temps-preview-gateway image
- deployments: Pass private registry credentials when pulling external images
- Migrate CLI dry-run/confirm/live-progress + chart tooltip fix
- analytics: Add
temps backfill clickhousestandalone migration subcommand (#109) - metrics: Unified database observability — service metrics, OTLP ingest, monitoring UI (#108)
- analytics: AI agents overview — timeline chart, breakdown cards, status (#113)
- logs: Grep -C surrounding lines in log search + trace duration sort (#114)
- clickhouse: Opt-in CH telemetry backends + TimescaleDB trace summaries, backfill, migrate reporting & data-model hardening (#116)
- skills: Fix HIGH-risk security findings in temps-platform-setup skill (#110)
- domains: Recover stuck TLS orders and fix HTTP-01 auto-renewal (#111)
- analytics: Per-project AI Crawler activity feed (#107)
- cli: TEMPS_CONTEXT env override + correct api-key login server
- analytics: AI agent traffic analytics + proxy-log filtering
- analytics: Per-agent breakdown when expanding a crawled page
- analytics: AI agents detail redesign + CLI ai-agents commands
- containers: Live log levels + pause/resume and credential masking
- migrations: Backfill proxy_logs.bot_name with canonical AI-agent names
- changelog: Record fast LB bind + TEMPS_CONTEXT CLI changes
- proxy: Run AI-agent detection on the live proxy-log ingest path
- proxy: Bind the load balancer before loading routes
- migrations: Make AI-agent bot_name backfill a manual script
- auth: Working password reset via email-only delivery (#102)
- git: Vercel-style sticky PR/MR preview comments on deploys (#96)
- proxy: Branded 404 for unknown hosts behind admin gate (#97)
- projects: On-demand preview environments by default
- deployer: Control-plane build concurrency + per-build resource caps
- auth: Per-OIDC-provider trust_idp_email opt-out for email_verified gate
- email: Generic SMTP provider, edit endpoint, and branded health-check email (#101)
- changelog: Record the on-demand previews / cancel comment / build limits work
- security: 0.1.0 hardening pass (29 findings, 3 rounds) (#95)
- security: Close 2 remaining 0.1.0 release blockers (#98)
- git: Update PR preview comment on deployment cancel
- web: GitLab logo + cleaner delete-provider toast
- Bump version, serialize docker tests, dns updates
- auth: OIDC SSO + Keycloak dev tooling + workflow trigger fix (#93)
- web: Change platform logo and favicon to the "t" lettermark
- notifications: Real data aggregation for weekly digest
- email: Native email validation, drop check-if-email-exists
- ai-gateway: Paginate and filter recent requests usage log
- notifications: Rebuild weekly digest email with table-based layout
- otel: Report the configured rate limit in RateLimitExceeded
- deps: Bump idna to 3.15 in Python SDK (CVE-2024-3651 bypass)
- import-docker: Import RestartPolicyNameEnum from bollard::models
- deps: Upgrade hickory-dns to 0.26.1 (DNS CVEs)
- dns: Migrate temps-dns-resolver test files to hickory 0.26
- Remove unused temps-mcp crate (drops rmcp CVE)
- proxy: Remove dead RequestLogger code path
- deployments: Cargo fmt routing-inputs block
- proxy: Fix visitor/session tests to create real DB rows
- sandbox: Bake safe.directory into image and surface chown failures (#83)
- workspace: Chown bind-mount work_dir to sandbox uid on the host (#84)
- ci: Set automatic_deploy=true in E2E project creation (#80)
- deployments: Always trigger initial deployment for new environments (#81)
- ci: Wait for deployment 'completed' state before verifying app (#82)
- observability: Add hide_bots: None to EventFilters constructors in merge_integration tests (#79)
- workspace,sandbox: V0.0.8 security audit + sandbox path centralization + CLI auto-auth (#73)
- cli: Release channels for temps upgrade and install.sh (#74)
- providers: Resource limits + runtime panel for external services (#75)
- analytics: Runtime-toggleable ClickHouse backend (#76)
- workspace,deployer: Preview password encryption + reboot-safe Docker secrets path
- auth: In-app password change with MFA gate and other-session revocation
- Misc improvements across git credential, sandbox, workspace, and log viewers
- changelog: Note runtime logs overhaul + storage UI polish
- auth: Preserve session cookie when clearing mfa_session after verify (#77)
- logs,storage: Runtime logs overhaul (pagination, ordering, density) + storage UI polish
- logs: Satisfy clippy::unnecessary_sort_by on chunk + result reorder
- web: Projects.tsx tweak
- Respect automatic_deploy flag on git push + Observe theme tokens
- cli: Credential-based login (temps login + logout + whoami + context) (#69)
- dns,providers: Internal DNS for HA databases + full cluster lifecycle (provision · scale · promote · backup · restore) (#66)
- observability: Unified Observe page (cockpit + console) (#71)
- deps: Patch 14 dependabot security advisories (#61)
- templates: Image fallbacks and env var generators (#63)
- git: Return 409 when GitHub repo name already exists (#64)
- domains: Show renew action for ACME certificates with non-standard verification_method (#65)
- Keep deployment log stream connected on redeploy and harden project creation (#68)
- operational: Branch picker, container limits + kill reason, GitLab token refresh (#70)
- sandbox: Pin image version, chown /workspace, GHCR channel split (#72)
- startup: Defer blocking subsystem init off the console boot path (#67)
- email-tracking: Add event timeline UI and analytics dashboard (#53)
- agents: AI autopilot agents framework with cron scheduling and autofixer (#58)
- Configurable db pool, multi-preset detection, enter-submit wizards (#52)
- security: Resolve dependency vulns and fix container exec tenant isolation (#54)
- email: Fix event timeline 404 and event type mismatches (#56)
- email: Email tracking fixes, analytics endpoints, SDK regen, settings validation (#57)
- deps: Resolve all 18 dependabot vulnerabilities (#60)
- cli: Fix project resolution in env vars subcommands and services env response (#59)
- ci: Add --clobber to gh release create to prevent duplicate tag failures (#51)
- ci: Add E2E deployment tests workflow
- email: Add open and click tracking for transactional emails
- Remove erroneous -- from git checkout command (#40)
- migrations: Convert duplicate email_events CREATE to ALTER TABLE (#45)
- email: Add deterministic ordering to get_events query (#46)
- presets: Fix Next.js Docker e2e test reliability (#47)
- ci: Generate self-signed certificate for E2E tests (#48)
- ci: Remove duplicate trigger-pipeline call causing vite-e2e cancellation (#49)
- release: Finalize 0.0.7 changelog with missing fixes and updated date
- compose: Add Docker Compose stack management
- compose: Add domain routing, repo-backed stacks, and replace git CLI with git2
- compose: Add repo compose file discovery and sync UI
- compose: Add port conflict validation before deploy
- compose: Add delete button to stack detail view
- compose: Add port overrides for compose stack port remapping
- compose: Add branch listing, fix port parser, improve create UX
- compose: Add docker-compose preset and service_name column (ADR-007)
- deployer: Add ComposeExecutor for docker compose deployments
- compose: Wire docker-compose into deployment pipeline
- compose: Wire DeployComposeJob into workflow execution service
- compose: Add teardown, proxy routing, and UI preset support
- compose: Inject Temps system env vars into all compose containers
- compose: Preserve volumes, add build support, expose service_name
- containers: Add exec and persistent terminal (xterm.js WebSocket)
- compose: Add user-provided compose override, PWD fix, error logging, env-file loading
- ui: Add public repo preset detection and compose override in git settings
- compose: Public repo improvements and session replay fixes
- file-store: Implement content-addressable storage with SHA-256
- deploy: Re-enable persist_static_assets with CAS backend
- cas: Database-backed URL→hash mapping with git-style blob sharding
- cas: DB-backed URL→hash mapping, git-style blob sharding, nightly GC
- api: Add purge asset cache endpoints
- ui: Add Purge Asset Cache button in environment settings
- edge: Add edge CDN proxy with ECIES TLS cert distribution
- compose: Service-specific domain routing, SQL safety, edge hardening
- email: Add open tracking, click tracking, and bounce/complaint webhooks
- monitors: Accept 404/405 as healthy and support custom check paths from .temps.yaml
- Update release checklist with verified items
- Update changelog with all unreleased changes
- changelog: Write v0.0.7 release notes
- compose: Add throwOnError to all stacks API calls
- compose: Throw on API errors in stacks client
- compose: Fix port parser trimming bug and persist tab on refresh
- ui: Hide application port field for docker-compose preset
- ui: Handle preset::path format in compose field visibility
- ui: Send preset_config for docker-compose in all project creation paths
- compose: Read compose file from workflow context, not guessed path
- ui: Fix port validation for docker-compose preset
- ui: Log form validation errors on submit failure
- ui: Allow NaN port value for docker-compose (field is hidden)
- ui: Skip setting port to 0 for docker-compose preset
- compose: Pass deployment_id to MarkDeploymentCompleteJob + add compose path to git settings
- compose: Log errors to deployment stream + fix container conflicts
- compose: Improve error logging and env var availability
- git: Fetch up to 100 branches for public repos
- git: Paginate branch listing for public repos (GitHub + GitLab)
- compose: Always use repo dir for compose commands
- compose: Set PWD env var for compose commands
- ui: Show all presets in fallback list including Docker Compose and Dockerfile
- ui: Show Repository link for public repos using github URL fallback
- ui: Public repo preset detection, compose override persistence, hide git connection for public repos
- docs: Use correct TimescaleDB-HA volume path for data persistence
- compose: Filter compose files by root dir and add screenshot job
- ui: Show URL input for public repo projects in Git Settings
- ui: Show full URL and Public badge for public repo projects
- ui: Fix public repo URL parsing and save in Git Settings
- api: Accept git_url and is_public_repo in update git settings
- compose: Fix preset name comparison, port parsing, and override save
- compose: Use host port (left side) for public port suggestions
- git: Use GitHub connection token for public repo API calls
- git: Validate GitHub token before using for public repo API calls
- projects: Use authenticated GitHub token in trigger-pipeline for public repos
- deploy: Persist_static_assets must not block mark_deployment_complete
- deploy: Fallback to slug-based container teardown for orphaned containers
- deploy: Add detailed logging for container registration in mark_complete
- workflow: Merge parallel job outputs instead of overwriting context
- proxy: Serve stale chunks via DB+CAS instead of filesystem paths
- proxy: Add missing temps-file-store dependency for CAS static serving
- ui: Show actual network throughput rate instead of cumulative total
- ui: Remove CPU/Memory from monitoring page, fix container name truncation
- compose: Inject Temps labels via compose override for log collection
- ui: Align container selector text to the left
- compose: Use correct Docker label keys for log collection
- deploy: Skip persist_static_assets for backend presets, accept 404 as healthy
- deploy: Include Dockerfile preset in persist_static_assets, skip pull for local images
- migrations: Add missing asset manifest and static cache migrations
- Commit remaining unstaged changes from CAS refactor and presets
- ui: Move infrastructure pages under settings layout and sync cmd+k
- file-store: Manifest-based CAS instead of per-path ref files
- ui: Remove standalone Stacks section from sidebar and routes
- Remove standalone temps-compose crate and compose stacks
- Embedded WireGuard, password protection, remote services & public settings (#33)
- changelog: Finalize v0.0.6 release notes
- web: Fix funnel edit page and metrics display (#35)
- web: Add import .env file to project creation wizard
- ai-gateway: Add AI gateway with multi-provider support
- ai-gateway: Add GenAI OTel tracing, deployment promotion, on-demand environments
- changelog: Add entries for GenAI tracing, deployment promotion, on-demand environments
- auth: Update test_role_all assertion for Demo role
- web: Make AI Gateway page responsive for mobile devices
- multinode: Add container reconciliation, scheduling config UI, and integration tests
- External plugins, analytics overview charts, and CRON_SECRET auto-injection (#28)
- multinode: Add multi-node cluster support with worker agents
- security: Encrypt environment variables at rest with AES-256-GCM
- multinode: Add container restart count and node management improvements
- multinode: Add alarm system, container health monitoring, and node management
- multinode: Teardown old containers on remote nodes and improve node management
- changelog: Add entries for multi-node cluster support
- multinode: Skip building remote env vars when no active nodes exist
- deployments: Prevent busy queue from starving route confirmation poll
- deployments: Use non-blocking advisory lock and move teardown outside lock
- multinode: Use Docker container names for cross-node env var rewriting
- web: Clean up env vars settings and add preview flag support
- deployments: Replace PG advisory lock with process-level mutex
- proxy: Add upstream connection timeouts and retry on stale connections
- proxy: Strip content-length from HEAD responses over HTTP/2
- deps: Patch critical and high severity vulnerabilities
- Implement job queue for route table updates and enhance deployment handling
- Add Google Indexing API plugin for Temps
- Enhance Docker deployment process with .temps.yaml support
- Update deployment and monitoring documentation for clarity and accuracy
- domains: Implement paginated domain listing with search functionality
- logs: Add structured log aggregator with Docker container log collection
- logs: Introduce structured log aggregator and frontend log history viewer
- domains: Enhance domain management with wildcard support and pagination
- Add auth rate limiting, external plugin system, docs overhaul, and settings UI
- Update CHANGELOG with proxy batch writer, domain pagination, and DomainSelector
- changelog: Add entry for Dockerfile path fix (#26)
- logs: Use i32 project IDs, restore BuildKit build logs, and add log history UI
- projects: Persist Dockerfile path in project settings
- presets: Fix incorrect corepack command for pnpm
- deployments: Use Dockerfile preset in container logs WebSocket tests
- deployments: Use Dockerfile preset in container logs WebSocket tests
- mcp: Implement MCP server with 210 tools for full platform management
- proxy: Add Accept: text/markdown support for AI agents
- providers,backup,core: Pg_dump sidecar backup, preset registry, and error hardening
- core: Add Next.js docs template to project templates
- external-plugins: Add external plugin system for standalone binary plugins (#20)
- otel: Add OpenTelemetry ingest, query, and frontend traces UI (#18)
- changelog: Add MCP server and security audit entries to changelog
- cli: Simplify closure to function reference in domain list
- skill: Address security audit findings in temps-cli skill
- cli: Escape curly braces in MDX docs output and remove credential path
- cli: Correct package name and command references in CLI docs
- mcp: Fix get_deployment_logs to fetch and parse JSONL log content
- proxy: Fix clippy unnecessary_literal_unwrap in markdown test and update changelog
- proxy: Extract content before HTML-to-Markdown conversion
- core: Lifecycle management, bounded caches, and memory safety across 11 crates
- environments: Remove useless .into() conversions on chrono::Utc::now() in tests
- backup: Switch pg_dump to plain format to fix OOM and add error logging
- backup: Extend command duration for backup sidecar to prevent OOM issues
- Resolve clippy warnings for CI compliance
- docs: Use bash instead of sh in install script commands (#16)
- platform: Proxy log retention, service UX improvements, vulnerability scanner filtering, and resource monitoring (#14)
- ci: Add protoc dependency to release workflow for temps-otel build
- mcp: Update version to 0.1.3 and enhance CLI help documentation
- Update Docker configurations and backup service enhancements
- Simplify Docker Compose configuration for PostgreSQL service
- backup: Update backup file extensions and improve sidecar memory management
- backup: Enhance backup process with direct file writing and improved error handling
- backup: Update backup container configuration for improved access and clarity
- backup: Optimize pg_dump execution to prevent memory issues
- proxy: Add pipeline integration tests for markdown edge cases
- analytics: Improve dashboard with drag-to-zoom, referrer tracking, and UX fixes
- proxy: Remove internal ID headers from proxy responses
- deployments: Add pre-flight image existence check before rollback
- cli: Move logs under deployments subcommand and fix log rendering
- cli: Populate required parameters when creating services in wizard
- cli: Add hardcoded fallback for service required parameters
- tests: Add retry resilience for flaky test failures
- tests: Enhance test resilience with targeted retries and clippy advisory
- README: Add node-sdk package information to the documentation
- workflows: Enable pull request trigger for Rust tests workflow
- deployer: Remove unnecessary u64 cast flagged by clippy
- providers: Cap health check backoff and detect dead containers
- query: Add missing DataSource import in redis and s3 doctests
- dependencies: Update various package versions and clean up Cargo.lock
- gitignore: Add eclipse IDE files to gitignore
- providers: Standardize PostgreSQL default to v18-alpine
- commands: Update data directory handling to use Path instead of PathBuf
- migration: Implement migration command and related functionality
- analytics: Add recent activity endpoint for real-time event tracking
- dependencies: Update package versions and clean up Cargo.lock
- database: Update TimescaleDB Docker images to pg18
- setup: Implement system user creation for webhook context
- analytics: Add visitor journey and page flow analytics endpoints
- analytics: Enhance visitor analytics with EarthGlobe component and new assets
- analytics: Implement date filtering for visitor analytics
- Add Cloud ACME Certificates section for TLS provisioning
- deployments: Route docker image uploads to correct pipeline for git projects
- deployments: Use environment slug for manual deployment URLs
- README: Update documentation with new links and mermaid diagrams
- Update .gitignore to exclude certificate and key files
- Clean up localtemps app by removing unused files and directories
- Remove SKILL.md file to streamline project documentation
- setup: Improve GeoLite2 database download feedback and progress indication
- docker: Enhance image handling and platform validation
- analytics: Update referrer handling for favicon display and naming
- docker: Improve image inspection and metadata handling
- skills: Add new skills for custom domain setup, Node.js SDK integration, React analytics, session recording, and deployment management
- events: Enhance referrer handling in event metrics recording
- deployments: Add local Docker image deployment command and verification job
- deployments: Streamline deployment process and enhance user experience
- setup: Enhance IP address confirmation and password handling in non-interactive mode
- templates: Add project templates configuration and demo mode enhancements
- templates: Introduce template management and TLS enhancements
- demo: Enhance demo mode functionality and UI components
- workflow: Add job configuration with custom dependencies and required flag
- deployments: Introduce remote deployment support and enhance project source types
- deployments: Add support for Docker image and static file deployments
- dependencies: Update Next.js and React versions in package configuration
- blob, kv: Add update functionality for Blob and KV services
- migration: Enhance UTM fields migration using SeaORM API
- blob, kv: Enhance service initialization and status handling
- localtemps: Initialize LocalTemps desktop app with Tauri, React, and TypeScript
- localtemps: Update dependencies and add DMG build script
- localtemps: Integrate analytics features with SeaORM and React Query
- localtemps: Enhance UI components and integrate new dependencies
- analytics: Enhance AnalyticsInspector with session replay and event categorization
- setup: Enhance DNS setup process with propagation verification and cleanup
- screenshot: Introduce NoopScreenshotProvider and enhance Chrome availability check
- serve: Add screenshot provider option to ServeCommand
- temps-blob: Migrate from MinIO to RustFS for blob storage
- redis: Implement pagination for Redis key listing and querying
- demo: Implement demo mode functionality with user role and UI adjustments
- redis: Update Docker image version from 7-alpine to 8-alpine
- migration: Streamline UTM fields index creation and deletion
- rustfs: Implement non-blocking health check for RustFS container
- cli: Enhance setup command with new options and output formats
- cli: Enhance temps-cli with new commands and documentation generation
- analytics: Enhance analytics features with UTM tracking and visitor activity filtering
- blob, kv: Introduce temps-blob and temps-kv services with comprehensive functionality
- cli, services: Update temps-cli and introduce new services for blob and key-value storage
- email: Add email validation service and update related components
- release: Update macOS runner version from 13 to 15 for build jobs
- backup: Integrate urlencoding for password handling in PostgreSQL connections
- backup: Add external service backup functionality
- download-repo: Enhance repository cloning logic with ref-based strategy
- email: Introduce email service with AWS SES and Scaleway support
- email: Add web interface for email management with Mailhog-like capture
- email: Integrate temps-email crate and register EmailPlugin
- email: Update EmailProvidersManagement with new icons and layout enhancements
- email: Add email management endpoints and SDK integration
- email: Add test email functionality for email providers
- email: Enhance test email functionality and error handling
- deployment-tokens: Implement deployment token management and validation
- email: Implement DNS verification utilities and enhance domain management
- dns: Introduce DNS management capabilities with Cloudflare and Namecheap support
- dns: Add DNS provider management and integration
- env-vars: Enhance environment variable management with new commands
- docker: Implement security hardening for Docker images using distroless
- routes: Add route management functionality with new AddRoute page
- url-validation: Introduce comprehensive URL validation to prevent SSRF attacks
- build-image: Enhance Docker image build process with project slug and prune command
- vulnerability-scanner: Introduce vulnerability scanning functionality
- vulnerability-scanner: Enhance vulnerability scanning with Docker image support
- custom-domains: Enhance redirect URL validation and error handling
- vulnerability-scanner: Add deployment_id to vulnerability scans and enhance related functionality
- security: Introduce vulnerability scanning features and UI components
- vulnerability-scanner: Add vulnerability scan completion notifications and trigger scan API
- migrations: Add environments route trigger for deployment updates
- vulnerabilities: Add new fields and notification handler for vulnerability scans
- dns-providers: Add support for Azure and Google Cloud DNS providers
- dns: Integrate DNS provider management and automatic DNS setup for email domains
- setup: Add initial setup command for Temps configuration
- projects: Revamp project creation process with enhanced user prompts and service integration
- docker: Transition to Alpine-based Node.js image for enhanced security
- cli: Enhance project creation with search-based repository selection and auto-sync
- mcp: Add tools handler and Temps API client integration
- domains: Add automatic DNS challenge record provisioning
- setup: Enhance setup command with git connection creation, geolite2 validation, and improved UX
- cli: Add runtime-logs command for container log streaming
- cli: Add environment configuration commands
- backup: Escape special characters in PostgreSQL password for Docker environment
- backup: Update error handling and content type for S3 uploads
- network: Always use container names for services and IPv4 for proxy
- workflows: Comment out pull_request trigger in Rust tests workflow
- docker: Remove prune command for Next.js projects in Dockerfile generation
- command-palette: Format keywords for better readability in navigation items
- release: Correct cache action version in release workflow
- backup: Implement backup management commands in CLI
- dependencies: Update Cargo.toml and Cargo.lock for AWS SDK and new features
- webhooks: Add comprehensive diagnostic logging for webhook delivery troubleshooting
- webhooks: Add endpoint to retrieve specific webhook delivery details
- temps-cli: Set up API client and configuration for improved interaction
- webhooks: Start listener in background to avoid blocking plugin initialization
- tests: Improve Minio client configuration and clean up VisitorsList component
- digest: Update notification digest structure and enhance project statistics
- query: Introduce query service and enhance data browsing capabilities
- ServiceDataBrowser: Add icons for S3 bucket, prefix, and object types
- metadata: Enhance EntityInfo with additional metadata fields and improve error logging
- docker: Add Dockerfile for release and enhance CI/CD workflow
- deployment: Introduce deployment cancellation and preview environment support
- activity-graph: Add deployment activity graph endpoint and frontend component
- import: Implement Docker container import functionality
- projects: Refactor ProjectServiceInfo to include detailed project metadata
- logs: Enhance log line and viewer components with text selection support
- postgres: Update default Docker image to postgres:18-alpine and adjust related configurations
- backup: Auto-create S3 buckets when creating S3 targets
- Add live visitors feature and Docker registry settings
- Add preview environment functionality for projects
- docker: Add support for prebuilt binary to skip Rust compilation
- docker: Enhance Docker deployment with multi-stage builds and GeoLite2 management
- docker: Remove hardcoded database URL and improve Alpine compatibility
- docker: Add build tools and fix bun installation for Alpine Linux
- docker: Simplify Dockerfile by removing dumb-init and fix architecture compatibility
- Streamline wasm-pack installation in CI workflows
- Update CI workflows to ensure WASM build environment is correctly configured
- Refactor project detail components and enhance sidebar functionality
- Enhance CI workflows and service management features
- Implement container management and metrics retrieval features
- Add integration and streaming tests for chunked transfer encoding
- Implement container metrics and management features
- Enhance Docker testing and service configuration management
- Update test for solution verification with realistic difficulty
- Add docker image configuration to Postgres service
- Refactor analytics to utilize proxy logs and introduce visitor ID tracking
- Add once_cell dependency and refactor network name handling
- Implement keyboard shortcut for adding environment variables
- Enhance environment variable logging and add new SDK files
- Improve component rendering and environment variable handling
- Add testing scripts and documentation for Temps MCP Server
- Add unique visitor count to ProjectCard component
- Optimize analytics query for overall stats
- Introduce CAPTCHA protection and IP access control features
- Correct total_count type in SessionLogsResponse
- Enhance user management by excluding soft-deleted users and adding unique email constraint
- Update README and refactor cookie handling in middleware
- Enhance authentication and user management logging
- Remove bcrypt support and enforce Argon2 for password hashing
- Enhance visitor analytics with user agent tracking
- Introduce KbdBadge component and implement keyboard shortcuts across various pages
- Update static deployment paths and enhance TLS settings
- Update installation instructions and release workflow
- Enhance URL construction in DeploymentService
- Refine URL construction logic in DeploymentService
- Remove DomainProvisioning component and related routes
- Add error handling for service deletion with linked projects
- Integrate default crypto provider for TLS in Domains Plugin
- Revise release workflow and enhance deployment metadata
- Update release workflow and dependencies
- Introduce test release workflow and update main release configuration
- Enhance release workflow with existing release deletion and file handling
- Add go/python/flask as examples
- Add basic Flask application example
- Implement Java preset for Nixpacks
- Add timestamps option to container log queries
- Enhance static file deployment support in proxy service
- Add installation script and Homebrew formula generation to release workflow
- Update runner configuration for all tests to use ubuntu-latest-4-cores
- Enhance release workflow with macOS builds and disk cleanup steps
- Add CHANGELOG and release documentation
- Overhaul README for clarity and structure
- Enhance README with streamlined quick start guide
- Update README for improved PostgreSQL setup instructions
- Update ci
- Optimize release profile and clean up CI workflows
- Update TimescaleDB image references to use latest version
- Update dependencies and enhance testing setup
- Enhance CI workflow with disk cleanup and deployment updates
- Update dependencies and enhance project structure
- Update go.sum in example go
- Update go.sum with new dependencies in gin-basic example
- Update dependencies and enhance project structure
- Update dependencies and improve project configurations
- Update dependencies and improve code structure
- Enable cargo formatting and clippy checks in pre-commit configuration
- Remove Nixpacks integration from temps-deployer
- Refactor migration files and update schema definitions
- Simplify log retrieval parameters with structured types
- Update integration tests to use new test configuration service
- Improve code formatting and readability across multiple files
- Update log retrieval tests to use structured logging format