| Age | Commit message (Expand) | Author |
| 2026-06-17 | Make VPN+Tunnel firewall chains work correctly when used in tandem | Mel |
| 2026-06-16 | Add agent identity on accessible fleet | Mel |
| 2026-06-16 | Extract renard agent configuration into a foundation module, allowing other h... | Mel |
| 2026-06-16 | Add tools, user to agent, clean-up flake input | Mel |
| 2026-06-14 | Add a SOUL to the Renard agent | Mel |
| 2026-06-14 | Run Renard agent in Hermes harness | Mel |
| 2026-05-17 | Add Claude Code | Mel |
| 2026-05-17 | Mitigate recent kernel exploits with kernel upgrade and blacklisting | Mel |
| 2026-05-02 | Change Xray + Nginx ordering, hide Xray behind Nginx streaming | Mel |
| 2026-05-01 | Add real domain to Xray server names to enable fallbacks | Mel |
| 2026-05-01 | Use egress destination domains in ingress instead of their names | Mel |
| 2026-05-01 | Don't set real_ip headers for Cloudflare on Tunnel egress hosts | Mel |
| 2026-05-01 | Add Docker 29 for nftables, clean-up daemon options | Mel |
| 2026-05-01 | Add Tunnel egress Xray fallback to re-enable all web & Nginx functionality | Mel |
| 2026-05-01 | Re-add simple VPN and simplify module with shared users with tunnel | Mel |
| 2026-04-24 | Migrate fully to systemd-networkd and nftables | Mel |
| 2026-04-24 | Remove generic foundation WireGuard server module, currently replaced by the ... | Mel |
| 2026-04-24 | Force disable Nginx on tunnel egress nodes | Mel |
| 2026-04-24 | Set MTU on all tunnel interfaces on ingress node | Mel |
| 2026-04-24 | Add nftables, iptables, and wireguard-tools | Mel |
| 2026-04-24 | Give the VPN its final name 'Tunnel' | Mel |
| 2026-04-24 | Add the ingress node public key to VPN definition as additional information | Mel |
| 2026-04-23 | Add new VPN user 'Fedor' | Mel |
| 2026-04-23 | Use sing-box gVisor stack for routing instead of system, fixing VPN TCP | Mel |
| 2026-04-23 | Don't shatter VPN ingress packets on local transmission between interfaces | Mel |
| 2026-04-23 | Define VPN egress & ingress default MTUs, routes, reverse paths, ... | Mel |
| 2026-04-22 | Extend Xray config generation service | Mel |
| 2026-04-22 | Let systemd-networkd handle VPN egress interface on ingress machine | Mel |
| 2026-04-22 | Fix VPN ingress private key file permissions | Mel |
| 2026-04-22 | Update sing-box deprecated seperate IPv4 TUN settings key | Mel |
| 2026-04-22 | Remove deprecated network config keys in VPN module | Mel |
| 2026-03-31 | VLESS/Reality VPN configuration for DPI evasion | Mel |
| 2026-02-17 | Fix ACME Tailnet certificate service override naming | Mel |
| 2026-02-14 | Move over deprecated option paths to new paths for 25.11 | Mel |
| 2026-02-14 | Remove options deleted in 25.11 | Mel |
| 2026-01-16 | Nix/NixOS shortcut script `nx` | Mel |
| 2025-10-04 | Factor out common public VPN peers to own module | Mel |
| 2025-10-03 | Make IPv6 forwarding sysctl options in service network configuration 'default' | Mel |
| 2025-09-15 | Add dmidecode | Mel |
| 2025-09-01 | Allow disabling IPv6 for foundation service networks | Mel |
| 2025-08-31 | Make IPv6 custom docker foundation networks work with various ip6tables rules... | Mel |
| 2025-08-31 | Define gateway for foundation docker networks | Mel |
| 2025-08-31 | Add MTU option to foundation service network options | Mel |
| 2025-08-31 | Clean up & integrate service network configuration into foundation module | Mel |
| 2025-08-27 | Move WireGuard server peer definitions to configuration option | Mel |
| 2025-08-22 | Grab real remote IP through Cloudflare proxy | Mel |
| 2025-08-22 | Add goatcounter tracker script to base renard HTML | Mel |
| 2025-08-08 | Update deprecated Klipper configuration options for 25.05 | Mel |
| 2025-07-27 | Configure zibeline WireGuard VPN server | Mel |
| 2025-07-16 | Add WireGuard VPN configuration for taupe | Mel |