Changelog¶
All notable changes to GoTunnel are documented here.
The format is based on Keep a Changelog, and GoTunnel follows Semantic Versioning.
How this file works¶
- Changes land under Unreleased as they are made, grouped by type: Added, Changed, Fixed, Security, Removed, Breaking.
- When a release is cut, the
[Unreleased]heading is renamed to the new version with the release date, and a fresh empty[Unreleased]is started. - Versions are ordered newest first. Each version links to its GitHub release.
- Version numbers follow SemVer: MAJOR for breaking changes, MINOR for backward-compatible features, PATCH for fixes.
Unreleased¶
Breaking¶
- New managed host. The managed server moved from
gotunnel-io.hireflw.comtogotunnel.bakaredev.site. Connect withgotunnel --server gotunnel.bakaredev.site --local localhost:3000; public URLs are nowhttps://<id>.gotunnel.bakaredev.site. The old host no longer accepts tunnels. - Raw TLS control port removed on the managed host. Port 9443 is closed; clients connect over WebSocket on 443, which is the default for a bare
--serverhost. Self-hosted servers are unaffected.
Changed¶
- Downloads and docs moved to
https://gotunnel.bakaredev.site/downloadandhttps://docs.gotunnel.bakaredev.site. - Beta enrollments did not carry over; run the client once to enroll again with your email.
1.0.3 - 2026-07-17¶
Added¶
- Per-tunnel bandwidth limiting on the server (
--max-bandwidth/GOTUNNEL_MAX_BANDWIDTH, e.g.1MB,500KB) to cap throughput per session. - YAML config file support for the server (
--config/GOTUNNEL_CONFIG) with explicit precedence (command-line flags > environment variables > file) and startup validation of TLS paths, listen addresses, and limits. - Prometheus metrics endpoint (
/metricson the health address) exposing active/total tunnels and streams, auth successes/failures, rejections by reason, listener bind failures, dropped streams, and forwarded HTTP requests by status class. Each session also gets a short correlation ID in the logs. - Enrolled accounts now get a stable subdomain derived from their email, so the same account keeps the same public URL across reconnects instead of a new random one each time. Tokenless / self-hosted clients still get a random subdomain.
- Local request inspector (
--inspect, default127.0.0.1:4040): a self-contained web UI to view the requests flowing through your tunnel — full request/response detail — and replay any request to your local service.
Changed¶
- Hardened the server against resource exhaustion: a per-tunnel cap on concurrent streams, tighter frame-size and per-stream buffer limits, a bounded public-port range, and sanitized client-supplied handshake fields.
Fixed¶
- Requests to a tunnel whose local service is unreachable now fail fast instead of hanging until timeout.
Security¶
- Fixed an integer overflow in handshake decoding that a malicious client could exploit to crash the server with a crafted handshake.
1.0.2 - 2026-07-17¶
Added¶
- Graceful shutdown: pressing
qorCtrl-Cshows a brief closing state and a session summary (uptime, requests served, endpoint) before the tunnel closes, instead of exiting instantly.
Fixed¶
- Local HTTPS services now work. Point the client at a TLS backend with
--local https://localhost:PORT; previously plaintext was sent to the HTTPS port, producing400responses. - Responses no longer hang. Replies that rely on connection close — chunked, server-streamed, or HTTP/1.0 (server-rendered pages and single-page apps) — were leaving the browser spinning; the server now closes the public connection as soon as the local response completes.
- Fixed a race that could truncate a response body.
1.0.1 - 2026-07-16¶
Added¶
- Email beta enrollment. Run
gotunnel --server gotunnel-io.hireflw.com --local localhost:3000with no token — enter your Gmail, receive a one-time code by email, type it in, and your device is signed into the beta. Access is limited to one device per Gmail address. - HMAC-signed, device-bound access tokens (verified statelessly by the tunnel server); Postgres-backed beta-tester records with SQL migrations (
gotunnel migrate); Redis-backed one-time codes with resend cooldown and attempt lockout. - Configurable static tokens for self-hosting (
--auth-tokens/GOTUNNEL_AUTH_TOKENS), per-IP failed-auth lockout (--max-auth-failures,--auth-lockout), and a concurrent-tunnel cap (--max-connections). - Optional mutual TLS (server
--tls-client-ca; client--tls-cert/--tls-key) and a configurable client TLS server name (--tls-servername). - Read/write deadlines on public-facing and local connections (slowloris / hung-connection mitigation).
- In-place self-update (
gotunnel update) and an automated release pipeline. - Colour-coded HTTP methods and per-request timestamps in the client terminal UI; branded colours and a friendlier offline/404 page.
Changed¶
- The server sends
BindOKonly after the public listener has bound, and retries port allocation on collision. - Auth tokens are compared in constant time and never logged; inbound protocol frames are validated against the handshake → auth → forwarding state machine.
Security¶
- Removed the insecure default
dev-token. The server requires an auth method (static tokens or a signing key) and refuses to start otherwise.
Breaking¶
- Self-hosted clients must supply a token (
--token/GOTUNNEL_TOKEN) or use the managed email enrollment; the olddev-tokendefault no longer works.
1.0.0 - 2026-07-11¶
Added¶
- Initial public beta: reverse TCP tunnelling with a custom binary protocol.
- Stream multiplexing over a single tunnel connection, multi-client support, and automatic public endpoint assignment.
- Subdomain (HTTP, over WebSocket/wss) and port exposure modes.
- Optional TLS encryption, heartbeat-based liveness, and client auto-reconnect with exponential backoff.
- Live client terminal UI with HTTP request logging, latency, and a metrics summary on exit.