DEV Community

Wynne Pirini
Wynne Pirini

Posted on

Calnode v0.10.1: the release our deployers wrote

On Sunday evening, a developer in Rotterdam I had never spoken to opened ten pull requests in sixteen minutes and signed the contributor agreement on all of them. Then he went quiet, presumably back to his weekend.

Those ten PRs became the core of v0.10.0. Two days after that release shipped, v0.10.1 landed: a security sweep plus the one-click module our hosting crowd kept asking for. I wrote less of either than our users did.

What v0.10.0 was

Marijn Bent (WordProof) shipped a coordinated batch across the whole booking surface: destination-provider preference, availability reporting, shared-calendar booking, a mailer relay, calendar rechecking before every booking, ownership transfer without breaking the booking URL, a per-user accent color, an optional phone call for online events, and grouping available times by time of day. Plus the one that tells you where he's from: Europe/Amsterdam added to the timezone picker.

I checked his account while merging. Eleven years old, 78 public repos. This was not a drive-by. It was someone running the software, hitting every rough edge in one sitting, and fixing all of them before dinner.

He is the second deployer of this kind. Minos Chatzidakis spent months reporting bugs with full reproductions and root-cause diagnoses, then started shipping the fixes in his own fork before I merged them upstream. When I asked permission to quote his work, he said: "You can do as you see fit with my issues." That sentence is the highest compliment this project has received.

What v0.10.1 added

A NethServer 8 module. Calnode now installs as a one-click NS8 app: host-based Traefik route with cluster TLS, SQLite on a persistent volume, an encryption key that survives reconfigures, and release tags that pin module and app to the same version. Honest caveat, printed in the release notes themselves: it is preview-grade. The install and configure paths are covered by robot tests, but no live node has run one end to end yet.

If you follow self-hosted schedulers, you know why this matters: the Rust newcomer in this space built its distribution story on exactly this surface. Now the Go binary has one too.

The security sweep

Five fixes, most of them the kind nobody notices until the post-mortem:

  • Public booking lookup is now rate-limited. GET /v1/bookings/{id} needs no auth by design (it carries no PII), but it was the one public route outside any rate limiter - an enumeration free-for-all. It shares the manage-token bucket now.
  • CalDAV connect failures no longer distinguish error classes. Refused vs timeout vs TLS vs auth failures were surfaced verbatim to the member form - a usable LAN-scan oracle. One generic message to the user, detail logged server-side. Timing side-channels are accepted as residual, and the release notes say so.
  • CalDAV no longer sends Basic credentials on cross-origin redirects. A redirect to another origin now drops the Authorization header instead of forwarding your app password to a server you never configured.
  • A short GOOGLE_CLIENT_ID no longer panics at boot. The startup log sliced the first 20 characters unconditionally; an unset or short value crashed the process instead of logging the usual "not configured" warning.
  • Video rooms explain host takeover. Sharing the host link let anyone take over as host, and the demoted side just lost its controls with no explanation. Host-link holders are now warned before joining not to share it, and a demotion names who took over, with a reclaim hint for owners.

The credential-forwarding one is the sort of thing most projects fix silently in a patch release. It is in the changelog because the changelog is for you.

The numbers

100 stars. 17 forks. One static Go binary, embedded SQLite, no Redis, no Postgres, Apache-2.0. Four digits on stars is a rounding error in this field, but every one of them is inside the window that matters to me: people running it.

Why this matters more than its size

Cal.eu closes on November 1. From today that is 32 days, and every EU team that picked Cal.eu for data residency needs an answer, not a debate. I wrote down the practical one three weeks ago: export now, stand up one binary, rebuild your event types, repoint webhooks, cut over one calendar at a time. That playbook is here: Cal.eu is closing on Nov 1. Here is your migration playbook.

If you follow it, v0.10.1 is the version to install, and the NS8 module is there if your hosting crowd thinks in NethServer.

Calnode lives at calnode.com (github.com/Calnode/calnode). If you deploy it and something breaks, file the issue the way Minos does. And as this post went together, a third contributor named jeroenrinzema opened two invitation-feature PRs. The pattern is holding. If you are Marijn, keep your weekends.

Top comments (0)