Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps - Status | Demo | Docs | Install
  1. Cloudron Forum
  2. Announcements
  3. What's coming in Cloudron 10

What's coming in Cloudron 10

Scheduled Pinned Locked Moved Announcements
56 Posts 23 Posters 8.6k Views 23 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • subvenS Offline
    subvenS Offline
    subven
    wrote on last edited by
    #47

    While I appreciate the upcoming mail related features and fixes, there is still one crucial feature left out that was talked about for years: Auto/Custom BCC for incoming/outgoing mail

    We need to make them archivable to comply with german GoBD law. Setting this at client level would not pass as the law requires seamless documentation without user influence. This is not limited to german law but is generally useful for any company that needs to document business processes comprehensively. I know a lot of companys and freelancers lacking DMS systems, mostly because its complicated and can be very expensive.

    Best case would be the ability to set global BCC per mailbox within Cloudron.

    1 Reply Last reply
    4
    • girishG girish

      Since we are getting swarmed by bots and crawlers (including our gitlab/forum/crm), we decided to include some features that will help in protecting apps. The first one is VPN protection. With this feature, people can access apps only via the VPN.

      In the network UI, there is a setting called "VPN protection". First enable the feature and select how to route the client traffic.

      bad90d16-a1cb-4055-8eb2-815f3ca731da-image.jpeg

      There is a per-app checkbox to VPN protect the app:

      f5aa3260-511b-4e34-80ad-05aed0ac9d53-image.jpeg

      If you try to access mautic now without a VPN connection, you will see (placeholder):

      32b32be8-28ed-4caa-9130-9ccc1181aceb-image.jpeg

      With OpenVPN/Wireguard connection, you will see mautic .

      Of course, this feature is mostly useful for internal apps. For public facing apps (like ghost, gitlab, nodebb), we are working on a different solution.

      robiR Offline
      robiR Offline
      robi
      wrote last edited by
      #48

      @girish does this help with the suite of VPN tools?

      https://github.com/jedisct1/dsvpn

      Conscious tech

      1 Reply Last reply
      1
      • d19dotcaD Offline
        d19dotcaD Offline
        d19dotca
        wrote last edited by
        #49

        I love the idea of handling bots. Currently I use a script from some sites but it’s more spam-based and unfortunately the API in Cloudron will only handle so many network addresses (or specifically a max size of PUT I believe) so I can’t keep expanding the list of IP firewall lists I want to use for blocking traffic.

        Lately this has become an issue for me for a few reasons but notably I’m finding too much bot traffic showing up in website analytics when using Matomo or Umami, and even third-party app Rybbit, and I have been trying to find a way to fight this so that the analytics is more accurate. If there’s a way to better fight this at the network layer in Cloudron I think that would be fantastic. At the very least though I think increasing the size allowed for network lists would be very helpful so that we can include more IP addresses.

        Also, I love that mail is finally getting the attention it much deserves. Looking forward to that.

        I think apart from what one person mentioned which is domain-based SpamAssassin rules or changing scores for example depending on the type of spam they receive, it’d be really nice if we could easily configure SpamAssaasin in the UI for resetting training data and forcing a rescan of spam and ham folders, as well as the ability to note which folders should or should not be treated as ham or spam so that we can add in our own for example.

        Just something else to consider. 😇

        Thank you for all the hard work! Looking forward to v10.

        --
        Dustin Dauncey
        www.d19.ca

        1 Reply Last reply
        3
        • girishG girish

          Since we are getting swarmed by bots and crawlers (including our gitlab/forum/crm), we decided to include some features that will help in protecting apps. The first one is VPN protection. With this feature, people can access apps only via the VPN.

          In the network UI, there is a setting called "VPN protection". First enable the feature and select how to route the client traffic.

          bad90d16-a1cb-4055-8eb2-815f3ca731da-image.jpeg

          There is a per-app checkbox to VPN protect the app:

          f5aa3260-511b-4e34-80ad-05aed0ac9d53-image.jpeg

          If you try to access mautic now without a VPN connection, you will see (placeholder):

          32b32be8-28ed-4caa-9130-9ccc1181aceb-image.jpeg

          With OpenVPN/Wireguard connection, you will see mautic .

          Of course, this feature is mostly useful for internal apps. For public facing apps (like ghost, gitlab, nodebb), we are working on a different solution.

          I Offline
          I Offline
          IniBudi
          translator
          wrote last edited by
          #50

          @girish I'd like to ask regarding this feature.

          • Could we enable the VPN to protect my.cloudron.app?
          • Is it possible to make custom rules? I mean if I want to protect WP-login.php and WP-admin, but I need to exclude this file /wp-admin/admin-ajax.php.

          Thank you for making awesome feature!

          girishG 1 Reply Last reply
          1
          • I IniBudi

            @girish I'd like to ask regarding this feature.

            • Could we enable the VPN to protect my.cloudron.app?
            • Is it possible to make custom rules? I mean if I want to protect WP-login.php and WP-admin, but I need to exclude this file /wp-admin/admin-ajax.php.

            Thank you for making awesome feature!

            girishG Offline
            girishG Offline
            girish
            Staff
            wrote last edited by
            #51

            @IniBudi I think we will have to implement that in a future release. It's quite a bit more complex to protect specific paths. We have to build some sort of WAF for that. The VPN protection works more at a network level and not much in the http level.

            1 Reply Last reply
            2
            • girishG girish

              girish said:

              Ubuntu 26.04 support

              We will have Ubuntu 26.04 LTS Resolute Raccoon support next release. I have managed to test this across most of the providers we support. We will have a guide during release time to upgrade manually from Ubuntu 24.04.

              Before someone asks, I don't know the ETA for Cloudron 10 yet, I think we will need 2-3 weeks more at least.

              H Offline
              H Offline
              hcj-online
              wrote last edited by
              #52

              @girish said:

              I don't know the ETA for Cloudron 10 yet, I think we will need 2-3 weeks more at least.

              Is there an updated ETA? 👼
              I want to set up a new Cloudron instance and take advantage of the Ubuntu 26.04 support.

              1 Reply Last reply
              0
              • U Offline
                U Offline
                umnz
                wrote last edited by
                #53

                Since networking/vpn/security is currently being worked on is there any opportunity here to provide native Tailscale support as an option? Specifically we offload heavy compute to external boxes (think AI compute hosted elsewhere) and I'd like to add Cloudron to my Tailnet so that Open WebUI running on Cloudron for example, can have access to some private compute and resources without having to worry about persisting through updates/backups/breaking Cloudron DNS etc.

                1 Reply Last reply
                1
                • girishG Offline
                  girishG Offline
                  girish
                  Staff
                  wrote last edited by
                  #54

                  @umnz it's in the roadmap to be able to join a network i.e where the server becomes a client/node - openvpn/wireguard/tailscale. Right now, it's mostly a "server". In the interest of getting Cloudron 10 out, it won't be in this release atleast.

                  1 Reply Last reply
                  1
                  • girishG girish

                    Since we are getting swarmed by bots and crawlers (including our gitlab/forum/crm), we decided to include some features that will help in protecting apps. The first one is VPN protection. With this feature, people can access apps only via the VPN.

                    In the network UI, there is a setting called "VPN protection". First enable the feature and select how to route the client traffic.

                    bad90d16-a1cb-4055-8eb2-815f3ca731da-image.jpeg

                    There is a per-app checkbox to VPN protect the app:

                    f5aa3260-511b-4e34-80ad-05aed0ac9d53-image.jpeg

                    If you try to access mautic now without a VPN connection, you will see (placeholder):

                    32b32be8-28ed-4caa-9130-9ccc1181aceb-image.jpeg

                    With OpenVPN/Wireguard connection, you will see mautic .

                    Of course, this feature is mostly useful for internal apps. For public facing apps (like ghost, gitlab, nodebb), we are working on a different solution.

                    dsp76D Offline
                    dsp76D Offline
                    dsp76
                    wrote last edited by
                    #55

                    @girish you selected mautic for this example in the screenshot. Is it possible to differentiate already between different paths? As link redirects, assets etc. would still need to be served publicly - but the admin interface not.

                    Thanks for clarification!

                    (Ask me about B2B marketing automation & low code business solutions, if thats interesting for you.)

                    girishG 1 Reply Last reply
                    1
                    • dsp76D dsp76

                      @girish you selected mautic for this example in the screenshot. Is it possible to differentiate already between different paths? As link redirects, assets etc. would still need to be served publicly - but the admin interface not.

                      Thanks for clarification!

                      girishG Offline
                      girishG Offline
                      girish
                      Staff
                      wrote last edited by
                      #56

                      @dsp76 Good point about the matuc example. But I think URL based protection is more complicated because we will need help from the apps. For example, it will require all of mautic admin and it's assets to be designed to be served from under a specific subpath. I haven't really investigated how friendly apps are in this regard but most likely we will have to handle this package by package (in a future release).

                      1 Reply Last reply
                      0

                      Hello! It looks like you're interested in this conversation, but you don't have an account yet.

                      Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

                      With your input, this post could be even better 💗

                      Register Login
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Don't have an account? Register

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • Bookmarks
                      • Search