Vicarian 0.6.0 is out. Vicarian is a batteries-included reverse-proxy aimed mostly at self-hosting. It has built-in ACME/LetsEncrypt support, including DNS-based certificate generation. Since I last mentioned Vicarian on here there have a been a lot of bug-fixes and a few notable features: * The configuration language has been changed from Corn to HCL. See vicarian-full.hcl for a full documented example. Environment injection now is fully supported, including integers (e.g. port numbers). ACME/Letsencrypt configuration blocks are reusable across vhosts. * Speaking of port numbers these can now be overridden on the command-line. * ACME/Letsencrypt wildcard certificates are now supported.
Show more of this post
* Serving static files is now supported natively. * Native Prometheus stats are now supported, including ACME time-to-renewal counters. * Listening on an interface rather than an IP is now supported. * Debian packages are now provided; see the README for details. * Many bug fixes and protocol handling improvements. Test coverage has been greatly expanded. To recap its key features: * Native support for ACME/Letsencrypt, including DNS-based challenges (DNS-01 is supported, DNS-PERSIST-01 to be added once support is more widely available). * Automatic certificate reloading for externally generated certificates. * Do The Right Thing by default; if a particular header or setting was usually required by, say, nginx then it should be the default. e.g. X-Forwarded-For and HSTS. With this release I'm confident enough to declare Vicarian as pre-1.0 beta status; it is feature-complete for my own use-cases, although some features may be added along the way. Possible future features may include: * DNS-PERSIST-01, DEVICE-ATTEST-01, and TLS-ALPN-01 support. * Additional credential sources (e.g. Vault/OpenBao, TPM2/systemd-creds). Vicarian (and this announcement) was written by a human (me, Steve). The Vicarian project has a no-AI-in-production-code rule. I wrote this to scratch my own itch, but hopefully it may be of use to others. github.com/tarka/vicarian