diff --git a/docs/configuration.md b/docs/configuration.md index 29fa820..2b87fa8 100644 --- a/docs/configuration.md +++ b/docs/configuration.md @@ -97,7 +97,7 @@ These variables configure Docker Compose behavior only (not passed to containers | `DC_MONGODB_IMAGE` | string | `mongo:8.2.3` | MongoDB image | | `DC_REDIS_IMAGE` | string | `redis/redis-stack-server:7.4.0-v8` | Redis image | | `DC_CLICKHOUSE_IMAGE` | string | `clickhouse/clickhouse-server:25.8` | ClickHouse image | -| `DC_RUSTFS_IMAGE` | string | `rustfs/rustfs:1.0.0-alpha.79` | RustFS image | +| `DC_RUSTFS_IMAGE` | string | `rustfs/rustfs:1.0.1` | RustFS image | | `DC_AWS_CLI_IMAGE` | string | `amazon/aws-cli:latest` | AWS CLI image (for bucket init) | #### Port Configuration diff --git a/on-prem/.env.example b/on-prem/.env.example index 6c8dcc8..88b9178 100644 --- a/on-prem/.env.example +++ b/on-prem/.env.example @@ -165,7 +165,7 @@ INVITE_EXPIRATION_DAYS= # DC_MONGODB_IMAGE=mongo:8.2.3 # DC_REDIS_IMAGE=redis/redis-stack-server:7.4.0-v8 # DC_CLICKHOUSE_IMAGE=clickhouse/clickhouse-server:25.8 -# DC_RUSTFS_IMAGE=rustfs/rustfs:1.0.0-alpha.79 +# DC_RUSTFS_IMAGE=rustfs/rustfs:1.0.1 # DC_AWS_CLI_IMAGE=amazon/aws-cli:latest # Port Configuration diff --git a/on-prem/CHANGELOG.md b/on-prem/CHANGELOG.md index 0177bc2..cef5b61 100644 --- a/on-prem/CHANGELOG.md +++ b/on-prem/CHANGELOG.md @@ -6,6 +6,17 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/). ## [Unreleased] +### Compose File Changes +- The bundled RustFS image is `rustfs/rustfs:1.0.1` (requires `./scripts/generate-compose.sh` if using custom templates) +- The `rustfs` service sets `RUSTFS_CORS_ALLOWED_ORIGINS: "*"`. `1.0.1` sends no CORS headers without it, which breaks trace.playwright.dev and the dashboard's stdout and attachment previews. If you run `1.0.1` from your own compose file, add it there too. + +### Changed Environment Variables +- `DC_RUSTFS_IMAGE` defaults to `rustfs/rustfs:1.0.1`. If your `.env` sets it, update the value to pick up the fixes below. + +### Fixed +- The bundled RustFS enforces bucket lifecycle rules. `1.0.0-alpha.79` accepted a lifecycle configuration and returned it from `GetBucketLifecycleConfiguration`, but never expired the matching objects. +- The bundled RustFS includes the fix for CVE-2026-73288, where lifecycle and scanner sweeps could expire objects under COMPLIANCE retention when lock metadata was missing or unreadable. + ## [2026-07-26-006] - 2026-10-07 Image-only update: no compose file or environment variable changes. Update `DC_CURRENTS_IMAGE_TAG`, then `docker compose pull && docker compose up -d`. diff --git a/on-prem/docker-compose.full.yml b/on-prem/docker-compose.full.yml index 5571c9e..add57cd 100644 --- a/on-prem/docker-compose.full.yml +++ b/on-prem/docker-compose.full.yml @@ -270,7 +270,7 @@ services: - ${DC_REDIS_VOLUME:-./data/redis}:/data rustfs: hostname: rustfs - image: ${DC_RUSTFS_IMAGE:-rustfs/rustfs:1.0.0-alpha.79} + image: ${DC_RUSTFS_IMAGE:-rustfs/rustfs:1.0.1} ports: - ${DC_RUSTFS_S3_PORT:-9000}:9000 # S3 API port - ${DC_RUSTFS_CONSOLE_PORT:-9001}:9001 # Web console port @@ -278,6 +278,10 @@ services: RUSTFS_CONSOLE_ENABLE: "true" RUSTFS_ACCESS_KEY: ${RUSTFS_ACCESS_KEY} RUSTFS_SECRET_KEY: ${RUSTFS_SECRET_KEY} + # The dashboard and https://trace.playwright.dev fetch objects from the + # browser through presigned URLs. RustFS sends no CORS headers unless this + # or a bucket CORS rule is set. + RUSTFS_CORS_ALLOWED_ORIGINS: "*" env_file: - .env networks: diff --git a/on-prem/templates/compose.rustfs.yml b/on-prem/templates/compose.rustfs.yml index b778cc3..0b641bf 100644 --- a/on-prem/templates/compose.rustfs.yml +++ b/on-prem/templates/compose.rustfs.yml @@ -4,7 +4,7 @@ services: rustfs: hostname: rustfs - image: ${DC_RUSTFS_IMAGE:-rustfs/rustfs:1.0.0-alpha.79} + image: ${DC_RUSTFS_IMAGE:-rustfs/rustfs:1.0.1} ports: - ${DC_RUSTFS_S3_PORT:-9000}:9000 # S3 API port - ${DC_RUSTFS_CONSOLE_PORT:-9001}:9001 # Web console port @@ -12,6 +12,10 @@ services: RUSTFS_CONSOLE_ENABLE: "true" RUSTFS_ACCESS_KEY: ${RUSTFS_ACCESS_KEY} RUSTFS_SECRET_KEY: ${RUSTFS_SECRET_KEY} + # The dashboard and https://trace.playwright.dev fetch objects from the + # browser through presigned URLs. RustFS sends no CORS headers unless this + # or a bucket CORS rule is set. + RUSTFS_CORS_ALLOWED_ORIGINS: "*" env_file: - .env networks: