From cd24a7870d90631d369385b9748c23855ebb1bf7 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=F0=9F=8F=94=EF=B8=8F=20Peak?= <122374094+peaklabs-dev@users.noreply.github.com> Date: Mon, 23 Feb 2026 19:34:18 +0100 Subject: [PATCH] docs: improve and streamline changelog wording (#8567) --- CHANGELOG.md | 124 +++++++++++++++++++++++++-------------------------- 1 file changed, 61 insertions(+), 63 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index f60c62d07..c20c92ff4 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,77 +4,81 @@ All notable changes to this project will be documented in this file. ## [5.0.0-alpha.1] - 2026-XX-XX -### Release Highlights + + +### Breaking Changes + +- + +### Security - ### Added - **v4 to v5 upgrade migration** - - Added Coolify v4 database as `old_pgsql` connection + - Coolify v4 database as `old_pgsql` connection - -- Worker Servers which replace build servers with servers that can also run jobs (horizon workers) in addition to building docker images +- Worker Servers that replace build servers with servers that can also run jobs (Horizon workers) in addition to building Docker images ### Changed -- Upgraded all Composer and Node dependencies and adopted their latest syntax and features, most notably: PHP to 8.5 (previously 8.2), TailwindCSS to v4.0 (previously v3) and Laravel to v12 (previously v10) -- **Docker:** - - Upgraded all Docker dependencies, most notably: Postgres to v18 (previously v15) and Redis to v8 (previously v7) +- Upgrade PHP from 8.2 to 8.5, TailwindCSS from v3 to v4.0, Laravel from v10 to v12 and all other Composer and Node dependencies to their latest versions and syntax +- **Docker** + - Upgrade Postgres from v15 to v18, Redis from v7 to v8 and all other Docker dependencies to latest - -- **Laravel Configurations:** - - Changed hashing algorithm from `bcrypt` to `argon2id` for enhanced security - - Use Redis for sessions and expire inactive sessions after 24h (previously 14 days) - - Encrypt user sessions data - - Expire password reset tokens after 10 minutes (previously 60 minutes) - - Jobs now wait for all DB transactions to be finished before being dispatched which prevents race conditions - - Normal jobs (backups, emails, etc.) and deployment jobs now use separate supervisor configurations and defaults - - Horizon workers are now restarted after 500 (job workers) or 300 (deployment workers) jobs or after 1 hour to clean up stale memory and CPU usage - - Reduced default queue timeouts from 10h to 60s for jobs and 300s for deployments to prevent stale jobs - - Increased `balanceCooldown` from 1s to 2s for jobs to reduce CPU spikes - - Redirect Laravel logs to `stderr` so they can be viewed in docker logs - - Configured production logging to rotate automatically and keep only the last 10 days of logs to reduce disk usage - - Changed production log level from `debug` to `warning` to reduce disk usage and avoid logging sensitive information - - Configured separate Redis connections for cache, jobs and sessions for easier debugging and separation - - Updated all Laravel config files to the latest version and removed all unused config options -- Changed license from `Apache-2.0` to `AGPL-3.0` +- **Laravel Configurations** + - Hashing algorithm from `bcrypt` to `argon2id` for enhanced security + - Session driver to Redis with inactive sessions expiring after 24h (previously 14 days) + - Encrypted user session data + - Password reset token expiration from 60 minutes to 10 minutes + - Jobs dispatch only after all DB transactions complete, preventing race conditions + - Normal jobs (backups, emails, etc.) and deployment jobs to separate supervisor configurations and defaults + - Horizon worker restart threshold to 500 jobs (job workers) or 300 jobs (deployment workers) or 1 hour to clean up stale memory and CPU usage + - Default queue timeouts from 10h to 60s for jobs and 300s for deployments to prevent stale jobs + - `balanceCooldown` from 1s to 2s for jobs to reduce CPU spikes + - Laravel logs to `stderr` so they can be viewed in Docker logs + - Production logging to rotate automatically and keep only the last 10 days of logs to reduce disk usage + - Production log level from `debug` to `warning` to reduce disk usage and avoid logging sensitive information + - Redis connections to separate instances for cache, jobs and sessions for easier debugging and separation + - Upgrade all Laravel config files to the latest version and remove unused options +- License from `Apache-2.0` to `AGPL-3.0` ### Deprecated - +### Fixed + +- `laravel.log` file growing indefinitely and consuming excessive disk space +- Failed jobs being logged into the database (Horizon already handles this) causing excessive disk usage in some cases +- Maximum concurrent builds setting not being respected when set to more than 4 on v4.x because only 4 Horizon workers are available by default +- + ### Removed - Session cleanup job as we now use Redis for sessions with a TTL - A lot of legacy code, outdated configs and dependencies -### Fixed +### Refactored -- `laravel.log` file growing indefinitely and consuming excessive disk space -- Removed logging of failed jobs into the database as we use Horizon for that and it can cause excessive disk usage in some cases -- On v4 when changing the maximum concurrent builds setting to more than 4 builds the setting is no longer respected because there is a maximum of 4 horizon workers available by default -- - -### Security - -- - -### Performance - -- +- Completely refactor all database migrations for a cleaner, more consistent and stable database schema +- Completely refactor all database models +- Replace hardcoded queue strings with a `ProcessingQueue` enum ### Maintenance -- **Testing:** - - Added custom Architecture test that enforces Laravel & PHP best practices to ensure security and consistency across the codebase -- **Tooling:** - - Added Rector & Rector Laravel with a strict configuration for automatic refactoring of the codebase - - Added a strict custom Laravel Pint preset for consistent PHP formatting across the codebase - - Added Larastan (PHPStan) Level `max` for code analysis and type checking - - Added custom composer scripts to run refactors, formatting, linting, tests and type-coverage - - Added strict `AppServiceProvider.php`: +- **Testing** + - Add custom Architecture test that enforces Laravel and PHP best practices to ensure security and consistency across the codebase +- **Tooling** + - Add Rector & Rector Laravel with a strict configuration for automatic refactoring of the codebase + - Add a strict custom Laravel Pint preset for consistent PHP formatting across the codebase + - Add Larastan (PHPStan) level `max` for code analysis and type checking + - Add custom Composer scripts to run refactors, formatting, linting, tests and type-coverage + - Add strict `AppServiceProvider.php` - Optionally enforce HTTPS for the Coolify dashboard - Enforce strong password validation rules in production - - Disable destructive artisan commands in production + - Disable destructive Artisan commands in production - Automatically eager load all relationships to prevent N+1 queries - Configure models and enforce morph map for polymorphic relationships - Enforce immutable dates globally @@ -83,26 +87,20 @@ All notable changes to this project will be documented in this file. - Prevent exception truncation in development - Use aggressive Vite prefetching for better performance - Only install Ray in development and remove all `ray()` calls from production code via Rector - - Switched Node package manager from `NPM` to `Bun` for improved security and performance - - Added `$schema` to `composer.json` and `package.json` -- **Coolify GitHub Repository:** - - Pinned all GitHub actions to full length git SHAs to minimize the risk of supply chain attacks + - Switch Node package manager from `NPM` to `Bun` for improved security and performance + - Add `$schema` to `composer.json` and `package.json` +- **Coolify GitHub Repository** + - Pin all GitHub Actions to full-length git SHAs to minimize the risk of supply chain attacks - Set permissions explicitly on each GitHub workflow to only give the minimum required permissions - - Renamed all GitHub action workflows for improved clarity + - Rename all GitHub Action workflows for improved clarity - Cancel in-progress action runs when a new run is triggered - - Improved `SECURITY.md` formatting and wording and added the support policy for `v5.x` - - Refactored the GitHub issue templates to use issue types and improved formatting and wording - - Moved `README.md` assets into `.github/assets/` to more easily exclude them from the core repository code - - Removed the `chore-remove-labels-and-assignees-on-close.yml` workflow as labels and assignees are now kept when closing Issues and PRs + - Improve `SECURITY.md` formatting and wording and add the support policy for `v5.x` + - Refactor the GitHub issue templates to use issue types and improve formatting and wording + - Move `README.md` assets into `.github/assets/` to more easily exclude them from the core repository code + - Remove the `chore-remove-labels-and-assignees-on-close.yml` workflow as labels and assignees are now kept when closing issues and PRs -### Refactored +### Issues -- Completely refactored all database migrations for a cleaner, more consistent and stable database schema -- Completely refactored all database models -- Queues are now accessed via an enum instead of hardcoded strings - -## Issues - -- fixed: -- fixed: -- fixed: +- Fixes +- Fixes +- Fixes