Clearplane 1.0.0-alpha3

· Prerelease

Highlights

Alpha3 adds HTTP/3, wildcard proxy routes, and simpler DNS certificate credentials. It also removes manual Docker socket group configuration and improves log browsing and clearing on larger installations.

Changes

  • Enable HTTP/1.1, HTTP/2, and HTTP/3 independently through Edge settings or environment variables. All three default to enabled where QUIC is available; listener changes require an Edge restart.
  • Publish wildcard proxy hosts such as *.example.com. A wildcard matches one subdomain level; add the apex hostname separately when needed.
  • Configure DNS-01 certificate credentials through numbered shared Core profiles or labels on the application container. Container-owned credentials are encrypted in Core and remain available for certificate renewal.
  • Detect the mounted Docker socket's group when ContainerProxy starts. The launcher then starts the application and health checks as app with all capabilities dropped.
  • Browse indexed logs without waiting for ingestion or counting every matching row. Log clears run in resumable background batches, and the default retention job runs hourly while preserving custom schedules.
  • Preserve the selected route when browsing cache bins, and retain encoded request paths in cache entries.
  • Stop dashboard error loops after a session expires. Add a persistent installation ID and optional privacy consent settings for future telemetry and community security features.
  • Move operator documentation and its LLM versions to the public website, and improve ARM64 image build reliability.

Upgrade instructions

Use the alpha3 release's compose.yaml and preserve your Compose overrides, named volumes, canonical service aliases, databases, keys, and certificates. Alpha1 installations must first follow the alpha2 layout migration.

  1. Remove the old CLEARPLANE_COMPOSE_CONTAINER_PROXY_SOCKET_GROUP_ID setting and manual group_add override. Use the new ContainerProxy launcher, health check, and SETUID, SETGID, and SETPCAP capabilities from the released Compose file. Retain CLEARPLANE_CONTAINER_PROXY_SOCKET_PATH for a nondefault socket.
  2. Update any explicit image pins or CLEARPLANE_IMAGE_TAG setting to 1.0.0-alpha3 for all four services.
  3. To use HTTP/3, retain the UDP 443 mapping from the released Compose file and allow UDP 443 through the host firewall and upstream network. Review the HTTPS protocol settings.
  4. Validate and update the deployment:
docker compose config --quiet &&
docker compose pull &&
docker compose up -d --wait

Core applies forward migrations for protocol settings, DNS profile ownership, log clearing, and privacy settings. Keep the existing persistent state together; changing image tags does not reverse these migrations. The installation ID is generated once and preserved across upgrades. The new privacy choices default to off.

Use the installation guide and CLI reference for operating procedures. Those guides track the latest version; alpha3's privacy choices only save consent and do not connect to Cloud or upload reports.

Known issues

  • Browser setup can fail with an asynchronous validation exception. Complete setup with docker compose exec clearplane-core clearplane administrator create, or upgrade to alpha4, which fixes the form validation path. Substitute your Core service key if renamed.
  • Telemetry collection, community protection, and Cloud error reporting are unavailable in alpha3.
  • Alpha downloads and images require an authorized GitHub account. The supported target remains one Linux Docker host on x64 or arm64; high availability, multiple hosts, rolling upgrades, and a supported matched backup and restore workflow remain unavailable.
  • Native WAF inspection and Basic/JWT authentication for proxied applications remain outside the supported alpha evaluation scope. Forward authentication and client-certificate authentication for customer routes are not implemented in this release.

Release downloads · Changes since alpha2