Skip to content

fix(container): update image qmcgaw/gluetun ( v3.41.1 → v3.41.3 ) - #3042

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/qmcgaw-gluetun-3.x
Open

fix(container): update image qmcgaw/gluetun ( v3.41.1 → v3.41.3 )#3042
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/qmcgaw-gluetun-3.x

Conversation

@renovate

@renovate renovate Bot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
qmcgaw/gluetun patch v3.41.1v3.41.3

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

passteque/gluetun (qmcgaw/gluetun)

v3.41.3

Compare Source

This fixes a VPN server port forwarding deadlock bug introduced whilst back-porting a fix from the master branch (:latest image) to v3.41.2. Credits to @​robinostlund for reporting the bug and even nailing down what it was! (#​3416)

Refer to v3.41.2 fixes in case you haven't checked.

v3.41.2

Compare Source

⚠️ there is a deadlock bug in the port forwarding if you use the up or down command, I will release v3.41.3 shortly

Fixes

  • Wireguard:
    • support IPv6 address formatting from config files (#​3273)
    • ignore empty address strings
    • skip tun device checks when using kernelspace
  • OpenVPN:
    • bundle provider CA certificates in one block (#​3258)
    • trim spaces in config lines before parsing (#​3327)
    • fix support for tcp-client
      • always use proto tcp-client when using TCP
      • parses tcp-client (on top of tcp, tcp4, tcp6) as meaning TCP
  • Custom openvpn: restrict custom openvpn config protocol to tcp or udp internally
  • Firewall: shared mutex for both iptables and ip6tables to prevent race conditions
  • Healthcheck:
    • correct behavior when HEALTH_RESTART_VPN=off and startup check fails
    • prevent race condition on the healthchecker (#​3400)
  • DNS:
    • skip blocking if block lists download fails
    • correct error wrapping for DNS listening address validation
    • DNS over TLS pool behavior fixed
      • handle timed out connections the same as closed connections
      • close connection on TLS handshake failure
      • improve mutex handling during connection renewal and retrieval
  • VPN port forwarding:
    • no longer stuck after failed port forwarding
    • handle empty ports without panicing
  • Updater: only uses DoH to cloudflare+google
    • prevent dns plaintext manipulation both the periodic update and when running in cli mode
    • possibly higher reliability on poor connections versus UDP
    • drop -dns flag in update command
    • for now no configuration allowed since it makes everything rather complex
  • Control server:
    • use port and ports for both single port and multiple ports forwarded
    • authentication: return 404 or 405 depending on route
  • Increase global http client timeout to 35s and precise lower timeouts where needed
    • Fix DNS blocklists slow downloads
    • Leave 35s timeout for updaters
    • Set timeouts to 1s for local calls
    • Set timeouts to 5s for LAN VPN calls and small external calls
    • Set timeouts to 10s external VPN API calls
  • Kernel modules: probe searches for features built-in the kernel
  • CI: set hash of PR commit instead of synthetic commit in docker build argument
  • internal/command: fix rare race condition on log line stream at command completion
Provider specific fixes
  • AirVPN: update servers data (#​3186)
  • ExpressVPN:
    • add new CA3 certificate to fix TLS handshake failure (#​3184, #​3192)
    • remove pakistan server
  • Privado:
    • servers data updated using JSON API
    • allow OpenVPN TCP protocol
    • allow additional OpenVPN ports 443, 8080 and 8443 for both tcp and udp
  • Private Internet Access:
    • remove none encryption preset
    • use AES-GCM for all presets
    • allow ports 501 and 502 as custom ports given they are the defaults
    • try x.y.128.1 and x.y.0.1 from the gateway IP to find the API IP address
    • fix servers data updater and update servers data
    • update default OpenVPN ports: 8080 for UDP, 8443 for TCP (according to pia-foss/manual-connections@8a75e46)
    • handle "port is busy" messages and retry port forwarding logic
  • ProtonVPN: fix updater code
  • Vyprvpn: update OpenVPN configs zip URL (#​3264)

PS:

  • No time to make a video or a rant section yet, but will do for v3.42.0 for sure!
  • v3.42 probably coming end of August/early September!
  • Sorry for the spam, first few v3.41.2 release attempts decided to give me a bunch of surprises in the CI, so here it is again

Configuration

📅 Schedule: (in timezone Europe/Moscow)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@mglants-bot

mglants-bot Bot commented Jul 29, 2026

Copy link
Copy Markdown
--- HelmRelease: networking/vpn-gateway Deployment: networking/vpn-gateway-pod-gateway

+++ HelmRelease: networking/vpn-gateway Deployment: networking/vpn-gateway-pod-gateway

@@ -70,13 +70,13 @@

           value: 'off'
         - name: DOT
           value: 'off'
         envFrom:
         - secretRef:
             name: vpn-gateway-secret
-        image: qmcgaw/gluetun:v3.41.1
+        image: qmcgaw/gluetun:v3.41.3
         imagePullPolicy: null
         name: gluetun
         securityContext:
           capabilities:
             add:
             - NET_ADMIN

@mglants-bot

mglants-bot Bot commented Jul 29, 2026

Copy link
Copy Markdown
--- kubernetes/subterra/apps/networking/vpn-gateway/app Kustomization: flux-system/cluster-apps-vpn-gateway HelmRelease: networking/vpn-gateway

+++ kubernetes/subterra/apps/networking/vpn-gateway/app Kustomization: flux-system/cluster-apps-vpn-gateway HelmRelease: networking/vpn-gateway

@@ -39,13 +39,13 @@

         - secretRef:
             name: vpn-gateway-secret
         gluetun:
           image:
             pullPolicy: Always
             repository: qmcgaw/gluetun
-            tag: v3.41.1
+            tag: v3.41.3
         networkPolicy:
           enabled: false
         securityContext:
           capabilities:
             add:
             - NET_ADMIN

| datasource | package        | from    | to      |
| ---------- | -------------- | ------- | ------- |
| docker     | qmcgaw/gluetun | v3.41.1 | v3.41.3 |
@renovate renovate Bot changed the title fix(container): update image qmcgaw/gluetun ( v3.41.1 → v3.41.2 ) fix(container): update image qmcgaw/gluetun ( v3.41.1 → v3.41.3 ) Jul 30, 2026
@renovate
renovate Bot force-pushed the renovate/qmcgaw-gluetun-3.x branch from 687b1f8 to 098d5d4 Compare July 30, 2026 18:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants