Skip to content

Changelog

All notable changes to GoTunnel are documented here.

The format is based on Keep a Changelog, and GoTunnel follows Semantic Versioning.

How this file works

  • Changes land under Unreleased as they are made, grouped by type: Added, Changed, Fixed, Security, Removed, Breaking.
  • When a release is cut, the [Unreleased] heading is renamed to the new version with the release date, and a fresh empty [Unreleased] is started.
  • Versions are ordered newest first. Each version links to its GitHub release.
  • Version numbers follow SemVer: MAJOR for breaking changes, MINOR for backward-compatible features, PATCH for fixes.

Unreleased

Breaking

  • New managed host. The managed server moved from gotunnel-io.hireflw.com to gotunnel.bakaredev.site. Connect with gotunnel --server gotunnel.bakaredev.site --local localhost:3000; public URLs are now https://<id>.gotunnel.bakaredev.site. The old host no longer accepts tunnels.
  • Raw TLS control port removed on the managed host. Port 9443 is closed; clients connect over WebSocket on 443, which is the default for a bare --server host. Self-hosted servers are unaffected.

Changed

  • Downloads and docs moved to https://gotunnel.bakaredev.site/download and https://docs.gotunnel.bakaredev.site.
  • Beta enrollments did not carry over; run the client once to enroll again with your email.

1.0.3 - 2026-07-17

Added

  • Per-tunnel bandwidth limiting on the server (--max-bandwidth / GOTUNNEL_MAX_BANDWIDTH, e.g. 1MB, 500KB) to cap throughput per session.
  • YAML config file support for the server (--config / GOTUNNEL_CONFIG) with explicit precedence (command-line flags > environment variables > file) and startup validation of TLS paths, listen addresses, and limits.
  • Prometheus metrics endpoint (/metrics on the health address) exposing active/total tunnels and streams, auth successes/failures, rejections by reason, listener bind failures, dropped streams, and forwarded HTTP requests by status class. Each session also gets a short correlation ID in the logs.
  • Enrolled accounts now get a stable subdomain derived from their email, so the same account keeps the same public URL across reconnects instead of a new random one each time. Tokenless / self-hosted clients still get a random subdomain.
  • Local request inspector (--inspect, default 127.0.0.1:4040): a self-contained web UI to view the requests flowing through your tunnel — full request/response detail — and replay any request to your local service.

Changed

  • Hardened the server against resource exhaustion: a per-tunnel cap on concurrent streams, tighter frame-size and per-stream buffer limits, a bounded public-port range, and sanitized client-supplied handshake fields.

Fixed

  • Requests to a tunnel whose local service is unreachable now fail fast instead of hanging until timeout.

Security

  • Fixed an integer overflow in handshake decoding that a malicious client could exploit to crash the server with a crafted handshake.

1.0.2 - 2026-07-17

Added

  • Graceful shutdown: pressing q or Ctrl-C shows a brief closing state and a session summary (uptime, requests served, endpoint) before the tunnel closes, instead of exiting instantly.

Fixed

  • Local HTTPS services now work. Point the client at a TLS backend with --local https://localhost:PORT; previously plaintext was sent to the HTTPS port, producing 400 responses.
  • Responses no longer hang. Replies that rely on connection close — chunked, server-streamed, or HTTP/1.0 (server-rendered pages and single-page apps) — were leaving the browser spinning; the server now closes the public connection as soon as the local response completes.
  • Fixed a race that could truncate a response body.

1.0.1 - 2026-07-16

Added

  • Email beta enrollment. Run gotunnel --server gotunnel-io.hireflw.com --local localhost:3000 with no token — enter your Gmail, receive a one-time code by email, type it in, and your device is signed into the beta. Access is limited to one device per Gmail address.
  • HMAC-signed, device-bound access tokens (verified statelessly by the tunnel server); Postgres-backed beta-tester records with SQL migrations (gotunnel migrate); Redis-backed one-time codes with resend cooldown and attempt lockout.
  • Configurable static tokens for self-hosting (--auth-tokens / GOTUNNEL_AUTH_TOKENS), per-IP failed-auth lockout (--max-auth-failures, --auth-lockout), and a concurrent-tunnel cap (--max-connections).
  • Optional mutual TLS (server --tls-client-ca; client --tls-cert / --tls-key) and a configurable client TLS server name (--tls-servername).
  • Read/write deadlines on public-facing and local connections (slowloris / hung-connection mitigation).
  • In-place self-update (gotunnel update) and an automated release pipeline.
  • Colour-coded HTTP methods and per-request timestamps in the client terminal UI; branded colours and a friendlier offline/404 page.

Changed

  • The server sends BindOK only after the public listener has bound, and retries port allocation on collision.
  • Auth tokens are compared in constant time and never logged; inbound protocol frames are validated against the handshake → auth → forwarding state machine.

Security

  • Removed the insecure default dev-token. The server requires an auth method (static tokens or a signing key) and refuses to start otherwise.

Breaking

  • Self-hosted clients must supply a token (--token / GOTUNNEL_TOKEN) or use the managed email enrollment; the old dev-token default no longer works.

1.0.0 - 2026-07-11

Added

  • Initial public beta: reverse TCP tunnelling with a custom binary protocol.
  • Stream multiplexing over a single tunnel connection, multi-client support, and automatic public endpoint assignment.
  • Subdomain (HTTP, over WebSocket/wss) and port exposure modes.
  • Optional TLS encryption, heartbeat-based liveness, and client auto-reconnect with exponential backoff.
  • Live client terminal UI with HTTP request logging, latency, and a metrics summary on exit.