Skip to content

Known Issues

Fabrizio Salmi edited this page Sep 9, 2026 · 2 revisions

Known issues

Open issues that change how you should operate the stack. Check the tracker for the current state; this page is maintained by hand.

The ICAP transport is being replaced

#143, open.

Squid hands requests to the WAF over ICAP, and that transport currently sits on an abandoned go-icap library. Replacing it, with keep-alive, deadlines, preview and streaming, is tracked as phase 2b.

Nothing to do about it as an operator: it is here so that behaviour under load, and the shape of future changes in the WAF path, are not a surprise.

Residual accessibility and UX findings

#219, open.

Medium-severity findings from a pre-release audit round, in the UI rather than the data plane: accessibility, some UX rough edges, and duplication worth removing. None of them affect filtering or the proxy path.

Fixed since this page was written

Kept here because upgrading is the only way to get the fix, and because both used to be listed above as things to work around.

Changing the admin password from the UI works. #230, closed. The handler compared the submitted password against a copy read at startup rather than against the stored hash, so a changed password appeared to save and then did not apply — silently, with the old one still working. Fixed in 23a5f00. Rotating the credential from Settings is now the normal path; there is no longer a reason to edit .env for it.

The installer checks the host ports before starting. #231, closed. A host already serving HTTP made the web container fail to bind, and freeing the port afterwards was not enough because the container stayed in its failed state. deploy/install.sh now checks the ports up front and recreates what did not come up. Fixed in dd6afaf.