Skip to main content

Spider system changelog

Available system releases

Spider installation is done with a Helm chart.
Use the value in version column to load the appropriate version.

VersionDescriptionHelm chart
latestAlways latest8.0.0
2026.08.17Redis, gRPC and Kafka parsing + automatic correlation + arm64 + licensing7.3.0
2026.05.13GUI modernization + L7 unifiedview + Waterfall view - BO modernization in GO + GRPC6.4.0
2026.01.14PostgreSQL live parsing and analysis views6.0.0
2025.09.05Technical release5.0.0
2025.05.31Service Accounts for third parties4.9.0
2025.05.18Security enhancements, Go upgrade, OpenSSL upgrade4.8.0
2025.04.12PKCS8, ArgoCD, Network usage4.7.0
2024.12.22Agents logs, UDP capture, local agents4.4.2
2024.11.23Improved TLS deciphering - TLS 1.2 & 1.34.2.0
2024.10.20Gocipher + Improved parsing quality4.1.0
2024.07.17Gossiper + bug fixes3.1.1
2024.05.13Whisperer creation form + TCP payload decode + Timezone + UX3.0.0
2024.04.22-2Public links + Data storage policies + UX improvements3.0.0
2024.03.10-2Bug fixes + UX improvements2.13.0
2024.03.05Access filters + bug fixes + UX improvements2.13.0
2024.02.18Health API + bug fixes + UX improvements2.11.0
2023.12.21Refactoring and bug fixes2.7.0
2023.12.04Parsing bug fixes + UI improvements2.4.2
2023.11.19Dashboard delivery + bug fixes2.4.0
2023.11.01Fixes in PODs attachments management in Controller2.3.0
2023.10.26Management of 'missings' in filters + bug fixes2.2.0
2023.10.18Add Daemonsets in Controllers + some UI fixes2.2.0
2023.10.03Fixes in config schemas to allow empty oidc providers array2.2.0
2023.09.21Redis memory & CPU optimisations2.1.0
2023.09.03-2Controller release2.0.0
2023.07.25OpenID Connect release
Benched at 200 000 HTTP coms /min
1.3.2
2023.06.07Spider compatible Helmchart release1.0.7
2023.05.11Plugins store releaseN/A

Available Gocipher releases

Gocipher is the agent that captures TLS keys and send them.
It may be deployed through Docker, but also as a standalone binary.
The binary requires eBPF to be available on the Linux kernel of the system to observe.

VersionDescriptionamd64arm64
1.10.0Network usage transport + UDP directiondownloaddownload
1.9.5Go crypto/tls capture + arm64downloaddownload
1.8.3Go 1.26.3download-
1.8.2Go 1.25.1 + Manage ephemeral processes in containersdownload-
1.7.0Perf improvementsdownload-
1.6.0Go upgrade + OpenSSL coveragedownload-
1.5.0Network usagedownload-
1.3.3TLS 1.2 + better observabilitydownload-
1.0.0First release of Gocipherdownload-

Available Gossiper releases

Gossiper is the agent that captures network communications and send them.
It may be deployed through Docker, but also as a standalone binary.
The binary requires libpcap to be available on the system to observe - when you choose LIBPCAP capture mode.

Two versions are built:

  • For libc 2.23
  • For libc 2.35
VersionDescriptionamd64arm64
7.13.0Capturing controller stamped on the data pathdownloaddownload
7.12.0ServerHello extraction + arm64downloaddownload
7.11.0Go 1.26.3 + GRPC to serverdownload-
7.7.0Go 1.25.1download-
7.6.0Perf improvementdownload-
7.5.0Go upgradedownload-
7.4.0Rate limiter + support PKCS8download-
7.3.0 libc 2.23Special version for old libc (Ubuntu 16.04)download-
7.3.0UDP + Robustness + Spider server IP change mgtdownload-
7.1.4Decode TLS packets to extract client randomdownload-
7.0.0First release of Gossiper, as a major version of Whispererdownload-

Tools

2026

  • 2026-09
    • New - Spider CLI - stream messages across the five verbs.
      • spider get|search|stats|aggs|outliers webmessagestream, with the same flags as the other protocols.
      • --include-streams on spider search http lifts the default stream exclusion, matching the UI setting.
      • --transaction fetches one stream's messages, scoped to the owning whisperer.
  • 2026-08
    • New - Spider CLI - spider detach, the counterpart of spider attach.
      • Detaches a whisperer from a workload and sets it back to STOPPED when no attachment remains.
      • Narrow with --namespace/--collection/--target, or --attachment for an exact one; --all is required when several match.
      • Spider Claude Plugin skills now detach after capturing.
    • Fix - Spider CLI - spider login -p <profile> authenticated the default profile, not the named one.
      • login read only its positional argument and silently ignored the global -p/--profile flag.
      • Both forms now work: spider login demo and spider login -p demo.
  • 2026-06
    • New - Spider CLI
      • redis, grpc and kafka are now first-class data resources.
      • spider login - log in via the browser. No need to store credentials localy.
      • spider login oidc - OIDC + SSO proxy authentication
      • spider login proxy - SSO proxy session cookies
      • spider logout
      • spider search l7 (plus stats, aggs and outliers l7) - Query all layer-7 communications at once
    • New - spider-mon CLI - Redis, gRPC and Kafka parsing status, processing speed.
  • 2026-05
    • New - spider-mon CLI for querying Spider monitoring data
    • New - spider-mon Claude Code plugin: skills + agents to review self-monitoring, compare periods, decode alerts, propose tuning.
  • 2026-04
    • New - Spider CLI (spider): standalone binary for querying captured traffic from the command line
    • New - Spider Claude Plugin: Claude Code plugin for autonomous agent-driven traffic analysis

Helmcharts

2026

  • 2026-09
    • spider-analyzer - 8.0.0
      • New - global.flips.feedback: the Send feedback button in Network-View. On by default, deploys nothing.
      • Fix - Traefik's dashboard and its unauthenticated API are no longer exposed by global.isDev.
        • They now need the new global.traefikDashboard, off by default.
        • An install running isDev: true while reachable from outside was publishing its whole routing table at /dashboard and /api.
  • 2026-08
    • spider-analyzer - 8.0.0
      • New - global.cluster.ipRanges: the cluster's internal CIDR ranges, the cidr rung of workload resolution.
        • Left empty, every address matching no Kubernetes object reports as externals - your own pod IPs included.
        • The capture map's Group by control then renders every mode like IP address.
      • New - global.flips.otelExport and the global.otelExport block: the OTLP export deployment.
        • Its three configuration indices, and the otelExportStale / otelExportDropping alert probes.
        • credentialKey seals collector credentials; credentialKeysPrevious holds the rotation list.
        • Tuning: maxSeries, maxCatchupWindows, lag and their usage* twins, plus two Controls timeouts.
        • The export service refuses to start with the flip on and no credentialKey.
      • New - Workload identity, the capturing controller, transport and directionConfidence are mapped.
        • On the packet, TCP session, communication and parsing-log index templates.
        • Workload names are copied into _quick_search, from each index's next rollover onwards.
      • New - parsers.web is mapped on the TCP session index, with parsers.web.itemsByProtocol.
        • The kafka and grpc parser slots are mapped for the first time.
      • Imp - web-write renamed web-parser; the self-monitoring topology map follows the rename.
      • Imp - The grpc-parser deployment is retired.
        • servicesToExpose gains an optional backend, so /grpc-parser/... now forwards to the web parser.
        • Only the playground path moved, to /grpc-parser/v1/grpc-playground.
      • Imp - The gRPC parsing-status index template, its lifecycle policy and its probes are removed.
        • Nothing has written that stream since the web parser absorbed gRPC.
        • Existing spider-parsing-status-grpcparsing-* indices stay readable and age out on their own ILM.
    • spider-analyzer - 7.3.0
      • Elastic stack 9.5.1, and ECK 3.5.0 for the optional namespace-scoped operator
      • Traefik v3.7 (CVE-2026-71327, CVE-2026-71325)
      • Redis 8.10, pinned to an exact image tag rather than a floating one.
        • An upgrade now reaches nodes that had already pulled the previous tag.
      • Kafka record headers stored unindexed on spider-kafkacomcontent-*
      • Fix - spider-raw-ciphers-status-* named a lifecycle policy the chart never creates.
        • It never rolled over and grew without bound; it now uses MonitoringILM.
        • The index written before the upgrade has to be removed by hand.
  • 2026-06
    • spider-analyzer
      • Redis Parsing
        • Deploy Redis parsing components
        • redisParsing feature flip
        • Redis parsing on Self-Monitoring
      • gRPC parsing
        • Deploy gRPC parsing components
        • grpcParsing feature flip
        • gRPC parsing on Self-Monitoring
      • kafka parsing
        • Deploy Kafka parsing components
        • kafkaParsing feature flip
        • Kafka parsing on Self-Monitoring
  • 2026-05
    • spider-analyzer - 6.4.0
      • Go services, GRPC and Playground APIs
      • Schemas service deployment + spider-schemas index mapping
      • Schemas service routed through the gateway (/schemas/*)
      • Schemas + ES Schemas surfaced on the Self-Monitoring main dashboard
      • spider-go-service sub-chart gains the same init-es initContainer pattern as spider-service
  • 2026-03
    • spider-analyzer - 6.3.0
      • New Multi-Read service + corresponding ES aliases
  • 2026-02
    • spider-analyzer - 6.2.0
      • Optional built-in ECK operator: Spider can install a namespace-scoped ECK (v3.2) alongside itself - for clusters with no existing operator, or with a namespace-scoped one that does not watch Spider's namespace. Preflight guards abort the install if a conflicting operator is detected.
  • 2026-01
    • spider-analyzer - 6.1.0
      • New Pg Upload service

2025

  • 2025-11
    • spider-analyzer - 6.0.0
      • Deploy postgresql parsing components
      • Add feature flip to deploy those or not to
  • 2025-09
    • spider-analyzer - 5.0.1
      • Accept special chars in Redis passwords
      • Move redis.conf files to secrets
    • spider-analyzer - 5.0.0
      • ES 9
      • Redis 8 + Authenticated connections
      • Allows deploying 2 Spider system on same cluster (for tests)
  • 2025-05
    • spider-analyzer - 4.9.0
      • Manage Service Accounts
    • spider-analyzer - 4.8.0
      • Use kube projected tokens to secure first service calls
      • Use refresh tokens to enhance security
  • 2025-03
    • spider-analyzer - 4.7.0
      • Possibility to use a proxy for Docker registry
    • spider-analyzer - 4.6.0
      • Manage Network Usage
      • New indices
      • New API endpoints
      • New configurations
      • Upgrade to ES 7.17.28

2024

  • 2024-01
    • spider-analyzer - 4.5.0
      • manage renewal of security keys for Gocipher & Controller
      • change default keys to PKCS#8
    • spider-analyzer - 4.5.0
      • Whisperer default config endpoint
      • packetsDiscarded field on Whisp status

2024

  • 2024-12

    • spider-analyzer - 4.4.2
      • WHISPERER env variable on Whisperer sidecars
      • APIs to get logs from Controllers
      • Configure restore job to restore Ciphers
      • Added local agents flags to Whisp, Ciphers, Controls and Customers indices
      • Optimised resource requests
    • spider-gocipher - 1.1.1
      • GOCIPHER & CONTROLLER env variables for Gociphers
      • Optimised resource requests
    • spider-controller - 1.5.2
      • RBAC to access logs
      • Optimised resource requests
  • 2024-11

    • spider-analyzer - 4.2.0
      • Purge Gocipher statuses older than 7 days
  • 2024-10

    • spider-analyzer - 4.1.0
      • Include Gocipher Helmchart
      • New services to manage Gocipher and TLS keys
    • spider-controller - 1.4.0
      • Manage several Controllers on same cluster
    • spider-gocipher - 1.0.0
      • Initial release
  • 2024-07

    • spider-analyzer - 3.1.1
      • Upgrade controller embedded helmchart
    • spider-controller - 1.3.1
      • Use non privileged port for dns port in controller port
  • 2024-06

    • spider-analyzer - 3.1.0
      • Allow deploying Gossipers instead of Whisperers for debug and demo
  • 2024-04

    • spider-analyzer - 3.0.0
      • Data storage policies - ability to define policies for TTL of whisperer data
        • Helm chart values breaking changes
        • Configuration of pollers, whisp service and network view UI
      • Index migration for DSP
    • spider-analyzer - 2.15.0
      • Link service configuration changes for Public-Links deployment
        • Changes in Login, Links, NetworkView and many services
      • Index migration for link
  • 2024-03

    • spider-analyzer - 2.14.0
      • Increase limits for development only for images of which the sources are injected
    • spider-analyzer - 2.13.0 + spider-controller - 1.3.0
      • Reduce daemonsets and init containers requests and limits
      • Easier management of mounting dev folders when doing local dev
  • 2024-02

    • spider-analyzer - 2.11.0 + spider-controller - 1.2.0
      • Allow overriding imagePullPolicy for local dev
      • Add targets for backup and restore jobs
      • Upgrade Traefik
  • 2024-01

    • spider-analyzer - 2.8.1
      • Health API exposing Spider probes status
      • Expose Traefik dashboard in /dashboard when isDev is true
      • Add option to activate auth on the API

2023

  • 2023-12
    • spider-analyzer - 2.7.0
      • Refactoring of Licence management
      • Bug fixes
      • Use version in Whisperer deployments
  • 2023-11
    • spider-analyzer - 2.4.0
      • Add flag to avoid localController resource generation for manifest / deployment stability in Argo (dates generation)
  • 2023-10
    • spider-analyzer - 2.3.0
    • spider-controller - 1.1.0
      • Improvements for local development deployments
  • 2023-10
    • spider-analyzer - 2.2.0
      • Better management of setup without secured smtp
      • Better management of setup without OIDC auth
  • 2023-09
    • spider-analyzer - 2.1.0
      • Added Controller component
      • Setup local-controller by default
      • Move Whisperer and Controller to public images
      • Removed Whisperer registry auth
      • Possibility to compress redis payload and avoid compression on main APIs used
    • spider-controller - 1.0.0
      • Allow to deploy a controller on any K8S
  • 2023-07
    • 1.3.2 - Restart services pushing demo data when demo flag changes
    • 1.3.0 - Allow changing any default service configuration using extraConfiguration key
    • 1.2.0 - Changed application configurations from JSON to YAML. Transform into JSON in Helm.
    • 1.1.0 - Add OIDC providers parameters
  • 2023-06
    • 1.0.7
      • Fix nodeport for debug.
      • Change resources RAM limit for microservices to allow debug of UIs.
      • Remove automatic restart of Config on update.
    • 1.0.6 - Add checksum for demo whisperer config
    • 1.0.5 - Refactor extra-ca-certs
    • 1.0.4 - Restructure Values to allow compute checksum of secrets for automatic redeploy on secret/config changes
    • 1.0.3 - Fix ingress host variable! Ingress was not working, but ingress controller failed to see the change :-/
    • 1.0.2 - Fix self-monitoring config file
    • 1.0.1 - Fix SMTP settings and add smtp.type value
    • 1.0.0 - Helmchart setup with demo, dev, debug, restore backup...

Gociphers

2026

  • 2026-08 - v1.10.0

    • Network usage records each flow's transport, tcp or udp, read from the socket's own protocol.
    • UDP client/server direction comes from the socket's state, not from comparing port numbers.
      • A connected socket is the client; an unconnected socket below the ephemeral range is a listener.
      • A flow resolvable neither way is reported as heuristic, so a known direction reads apart from an inferred one.
    • cilium/ebpf updated from v0.16.0 to v0.22.0, clearing advisory GO-2026-6238.
    • Never send a TLS secret with no version.
      • A Go handshake seen only through its EXPORTER_SECRET produced a key with an empty tlsVersion.
      • No parser can use it, the backend refuses it, and it took every other key of the batch down with it.
    • A batch of TLS keys accepted only in part (HTTP 207) now counts as delivered.
      • The number of keys dropped is logged, instead of a send error leaving the batch to be replayed.
  • 2026-08 - v1.9.5

    • Fix TLS capture stopping for good after the watched list changed.
      • Only newly discovered whisperers were published, so the second update sent an empty set.
      • Configurations were never fetched again, and capture stayed stopped until Gocipher was restarted.
    • Fix whisperer configurations being lost when a delivery was interrupted, the next fetch short-circuiting on "no change in config".
  • 2026-07 - v1.9.4

    • Say why TLS capture did not start. The three early returns that stopped capture (no BASIC capability, no TLS_DECRYPT, and tlsKeys.track disabled by the server) used to return silently. They now log, with the licence status reported by the server.
  • 2026-07 - v1.9.3

    • Fix a startup deadlock. When TLS capture did not start (unlicensed or disabled), the job fetching the to-watch list blocked forever on its first non-empty send, because the capture session it writes to is its only consumer and had not been started. The list was fetched exactly once and never refreshed.
  • 2026-07 - v1.9.2

    • arm64 support. Gocipher now builds and captures on arm64 (aarch64), for all three modes (OpenSSL, Node.js and Go crypto/tls) under both glibc and musl. The Go handler decodes the arm64 ABIInternal register file; the OpenSSL struct offsets are identical to x86_64 on every supported version. Validated live on AWS Graviton (kernel 6.8) with all five protocols decrypting. Container image only - the standalone tarball below is still x86_64.
    • Fix Network Usage map showing spurious "port 0" links (and a 0.0.0.0 node). Flows whose server port could not be resolved (unconnected UDP, and packets read around connection setup/teardown) are no longer reported.
  • 2026-07 - v1.9.1

    • Fix Network Usage map showing double-sided arrows between services that only talk one way. Client/server roles are now determined from the connection handshake (connect/accept) instead of guessing from port numbers, which was wrong for servers listening on high ports (e.g. gRPC).
  • 2026-06 - v1.9.0

    • Capture TLS master secrets from Go programs that use the standard library crypto/tls (not OpenSSL)
    • Fix out-of-memory kills during startup discovery.
    • A single agent could get wedged on a half-dead keep-alive connection to the hub (repeated 502 Bad Gateway). Retry in place.
  • 2026-05 - v1.8.3

    • Go 1.26.3
  • 2026-01 - v1.8.2

    • Do not start network usage capture when URL is not defined in environment
    • Manage ephemeral processes in containers when doing discovery

2025

  • 2025-10 - v1.8
    • Upgrade to Go 1.25.1
  • 2025-09 - v1.7
    • Add randomization to Network Usage sending to Controller to smoothen load
    • Add DNS cache for outbound requests
  • 2025-05 - v1.6
    • Upgrade to Go v0.24. Improved performance.
    • Added management of OpenSSL versions: 3.3.0 -> 3.3.3, 3.4.0 -> 3.4.2, 3.5.0
    • Added management of Node OpenSSL embedded versions: 1.1.1a -> 3.0.16, included +quic versions
  • 2025-03 - v1.5
    • Capture and send Network usage
    • Manage service activation options in config
    • Optimise memory allocation for TLS capture
  • 2025-01 - v1.4
    • Manage PKCS#8 private key format

2024

  • 2024-11 - v1.3
    • Extract TLS1.2 mastersecret and manage Mozilla recommended cipher suites
    • Extract EncryptThenMac flags from TLS sessions
  • 2024-10 - v1.0
    • First release
    • Capture TLS keys using eBPF
    • TLS 1.3 support from OpenSSL 1.1.1 to 3.0.x
    • Supports targets as containers, pid or executable path
    • Complete with status, multi targets etc.

Gossipers

2026

  • 2026-08 - v7.14.0
    • Fix - A long one-way stream stopped being captured after 10 MB, silently and permanently.
      • A packet lot only ever ended when the traffic changed direction, so on a connection that only sends one way it never ended at all.
      • Past the maxPlLength limit every further packet was refused by the backend for the rest of the connection's life, with no error anywhere.
      • With pack.savePackets on, those packets were stored but never queued for parsing; with it off, they were never stored at all.
      • Server-sent events, server-push WebSocket feeds, Redis pub/sub and Kafka consumer streams were all affected; ordinary request/response traffic was not.
      • A packet lot now also ends when it reaches the size limit, which keeps the same memory bound and discards nothing.
    • Imp - Retransmitted packets are matched to their original packet lot over a much longer window.
      • The agent remembered the last 20 packet lots, which on a busy connection can be under a second.
      • It now keeps two minutes of history, up to 200 lots, whichever limit comes first.
  • 2026-08 - v7.13.0
    • Stamp the capturing controller on every session and packet.
      • It is the key the backend uses to look an endpoint up in that controller's workload map.
      • A standalone gossiper sends an empty controller; nothing downstream substitutes a default for it.
    • Fix - A malformed TLS ClientHello can no longer take capture down.
      • ClientHello parsing is bounded and decoder panics are contained.
      • gopacket updated to v1.6.1, closing two remote DoS advisories reachable from traffic on the wire.
  • 2026-06 - v7.12
    • Capture ServerHello serverRandom + cipher id into session handshakes
  • 2026-05 - v7.11
    • Go 1.26.3
    • GRPC with for packets and tcp sessions

2025

  • 2025-10 - v7.7
    • Upgrade to Go 1.25.1
  • 2025-09 - v7.6
    • Add DNS cache for outbound requests
  • 2025-05 - v7.5
    • Upgrade to Go v0.24. Improved performance.
  • 2025-01 - v7.4
    • Manage PKCS#8 private key format
    • Throughput limiter to set a max of x MB/min of traffic capture

2024

  • 2024-12 - v7.3
    • Parses packets UDP layer to get src and dst ports
  • 2024-11 - v7.2
    • Avoid restarting when DNS calls fails (when contacting Controller)
    • Check for server Ip change and restart Capture in such a case
    • Manage several Ips for Spider server
  • 2024-11 - v7.1
    • Manage AF_PACKET metrics v3
    • Parse TLS application layer to extract client random
    • Add client random to TCP sessions
  • 2024-06 - v7.0
    • New agent in Golang
    • All features from Whisperers except
      • Pod name resolution (done by Controller)
      • Host preloading
      • VXLan
    • Lighter, less resource usage, faster
    • Manage new method of Capture: AF_NET
      • Accepts it in configuration
      • Reports it in status

Whisperers (deprecated)

2024

  • 2024-02 - v6.2
    • Fix to allow defining DNSCACHE_HOST using a hostname rather than an IP at start. Hostname is resolved on regular DNS.
  • 2024-01 - v6.1
    • Report meaningful status when starting without license
  • 2024-01 - v6.0.5
    • Changed API names

2023

  • 2023-10 - v6.0.4
    • Changed the default value for local hostname of whisperer to instanceId (on Kube - the pod name)
  • 2023-09 - v6.0
    • Manage ephemeral whisperers
      • Initial connection by token + renewal
      • Allow to use controller DNS
        • To resolve Pods IPs and names.
        • To connect to Spider (no need for Host Aliases)
        • Uses DNSCACHE_HOST & DNSCACHE_PORT env variables
        • If DNSCACHE_HOST is a hostname, it is resolved on standard DNS first.
      • Attachment status job checking Controller if we should stop whisperer
      • Status content upgraded
    • New WATCH_K8S_PODS to tell if we should not watch for k8s pods, even if not ephemeral (when = 0)
    • Manage limited time Attachments
    • Public image
  • 2023-06 - v5.7
    • When DNS answers several names for a single IP, take first one in alphabetical order

2022

  • 2022-11 - v5.6
    • New - Upgrade to Node 18
    • New - Smaller docker image
    • New - New build target: i386 for 32 bits systems
    • New - When in Kubernetes env, connect to Kube API to fetch and cache namespaced pod list to resolve PODs IPs instead of using DNS
  • 2022-11 - v5.5
    • Imp - Improve queue management when server is under pressure
  • 2022-01 - v5.4
    • Imp - Adjust packetLot to -2 when packet is late - after next pL
  • 2022-01 - v5.3
    • Imp - Add relativeAck to packets
  • 2022-01 - v5.2
    • Imp - Add option not to capture / send packet without data to spare CPU and network.
    • Imp - Do not ask for parsing of packets belonging to a packetLot over a certain size
  • 2022-01 - v5.1
    • New - Option to avoid duplicated Tcp sessions when capturing both sides of the same communication
  • 2022-01 - v5.0
    • Imp - Parsing v2 - New format of Packet and TcpSession

2021

  • 2021-09 - Imp - Upgrade to Node 16
  • 2021-02 - Imp - Webpack bundling

2020

  • 2020-05 - Imp - Default filters not to capture communications to Spider servers
  • 2020-03 - Imp - Upgrade to Node Pcap v3
  • 2020-03 - Imp - Upgrade to Node 12

2019

  • 2019-07 - Imp - Upgrade to Node 10 and migration to async await
  • 2019-07 - New - Whisperers send their version to BO
  • 2019-02 - New - Add hostnames to TCP sessions

2018

  • 2018-12 - Imp - Better DNS reverse query
  • 2018-12 - New - Host preloading
  • 2018-11 - New - Token renewal job
  • 2018-08 - New - Circuit breakers on CPU & RAM
  • 2018-08 - New - Wait for IP resolving + track unresolved parameters
  • 2018-05 - Imp - Total error counts for monitoring
  • 2018-02 - New - Custom DNS / standard DNS

2017

  • 2017-10 - New - Whisperer status sent to BO
  • 2017-09 - New - Remove control
  • 2017-09 - New - Queues to buffer sending packets and sessions
  • 2017-09 - New - Hosts filtering
  • 2017-06 - New - Custom reverse DNS
  • 2017-06 - New - VXLan parsing
  • 2017-03 - New - Slowness factor when playing files
  • 2017-01 - Imp - Technical improvements: Joi, Bunyan...

2016

  • 2016-12 - New - Docker
  • 2016-06 - Imp - Update to Node 6
  • 2016-04 - New - Get config from Spider, API key, JWT
  • 2016-03 - Imp - Refactor, technical dev, move to promises
  • 2016-02 - New - Initial release

Controllers

2026

  • 2026-09 - v3.2.0
    • New - The controller republishes its whole workload map on demand, when Controls asks for it.
      • Controls asks after its cache restarts, which empties the map entirely -- see the Back-End entry for why.
      • A new requestWorkloadMapSnapshot websocket request triggers the same full snapshot the reconcile timer already sends, over the same chunked HTTP path.
      • The request is acknowledged immediately and the snapshot is built off the websocket read loop, so a large map cannot stall controller status.
      • A controller that predates the request logs it and carries on, so controllers and Controls can be upgraded in either order.
  • 2026-08 - v3.1.0
    • New - The controller publishes its IP-to-workload map, as validity intervals.
      • A parser can ask who held an address when a packet was captured, not who holds it now.
      • Until now that knowledge only ever left the controller flattened into network-usage documents.
      • Sent over HTTP in chunks under a shared generation, not over the control websocket.
      • So a megabyte-scale snapshot cannot close the connection carrying controller status.
      • Deltas come from diffing the cache on the flush timer, so a missed event heals at the next reconcile.
    • New - Network usage attributes Service traffic to the pods behind the Service.
      • A Service's ports and backing pods are snapshotted at enrich time.
      • A published port is resolved to its targetPort.
    • New - Network usage carries transport (tcp/udp) and directionConfidence (resolved/heuristic).
      • Both join the merge key, so two flows differing only in transport are no longer merged.
    • New - client.networkUsage.flushMargin (default PT45S): how long past a minute's end to wait.
      • A straggling node's rows are no longer dropped from a minute already declared complete.
    • Imp - A ClusterIP hop is no longer counted twice.
      • A pre-DNAT row with a pod-side twin is dropped at source, so Service traffic is reported once, against the pod.
    • Imp - A batch arriving after its minute was published is folded into the next publish, not discarded.
      • A bounded cap backstops a pathological node; a lost chunk is logged loudly rather than silently absorbed.
  • 2026-07 - New - A local agent now stops when it finds more than one node in the cluster. It is meant to run on a single-node setup.
  • 2026-05 - v3.0.1
    • Go 1.26.3
  • 2026-03 - v3.0.0
    • Recoded in Go, drop in replacement

2025

  • 2025-12 - v2.3.2
    • Avoid resetting in memory state regularly, not needed anymore
    • Enforce object allowed parents to prevent Zalando operator to ruin the internal state.
  • 2025-10 - v2.3.1
    • Adapt to regression in Kubernetes lib on Error management
  • 2025-08 - v2.3
    • Improve reactivity by giving back the hand to event loop more often when integrating network usage
  • 2025-08 - v2.2
    • Imp - Technical debt
  • 2025-03 - v2.0
    • New - Gather network usage from Gociphers, enrich them and send to Controls
    • New - Configuration option for cluster PODs IP range(s)
    • Imp - Overwrite security context when spawning Whisperers to allow root execution even when POD does not allow it
    • Imp - Manage new SideCar pattern introduced with Kubernetes 1.29 when looking for sidecars Whisperers
  • 2025-01 - v1.8
    • Imp - Enhance status with Sidecars, Gociphers and Nodes IPs
    • New - Stop Controller if localAgent and more than 1 node. Stop running attachments and forbid new ones.

2024

  • 2024-12 - v1.7
    • Imp - Manage many Controllers on same host / cluster - do not send not managed attachments to Gocipher
  • 2024-12 - v1.6
    • New - Give Sidecar Whisperers in API for Gocipher to allow TLS deciphering for Sidecars
    • New - Track Gociphers & Sidecar Whisperers
    • New - Allow getting logs from Controller, Attachments, Sidecars & Gociphers
    • New - When an Ephemeral Whisperer fails twice in 5 minutes, the Controller stops restarting it to avoid overloading the POD manifest
  • 2024-10 - v1.5
    • Imp - Node 20, Alpine 3.20
    • New - API for Gocipher to get list of Pods to target
  • 2024-07 - v1.4
    • New - Automatic reset of state every 5 min
  • 2024-06 - v1.3
    • Imp - Use standard user in container
    • New - Support Gossiper agent deployment
  • 2024-02 - v1.2
    • Imp - Use k8s resourceversion to capture past events when reconnecting. Manage restart from scratch when resourceVersion is too old.
  • 2024-02 - v1.1.1
    • Fix - Manage race condition when Controls and Controllers are restarted at once. Controllers were not connecting.

2023

  • 2023-11 - Imp - Restart whisperer when ephemeral container reaches end of life, or when POD restart with same name
  • 2023-11 - Imp - Take POD attachments into account when searching for attachments on POD events
  • 2023-10 - Imp - Fix uniqueness of whisperers container names. Avoid seeing only one in memeory if many are created in the same second for a daemonset.
  • 2023-09 - New - First release of Spider Controller for Kubernetes with namespaces filtering, time to live, watch of Kubernetes objects etc.

Back-End

2026

  • 2026-09 - New - WebSocket and Server-Sent Events are parsed over HTTP/2, not only over HTTP/1.1.
    • A WebSocket stream opened with RFC 8441 extended CONNECT (:method: CONNECT, :protocol: websocket) yields the same messages as a 101 upgrade does over HTTP/1.1 - the frame decoder is shared, and the accepted CONNECT stream is the handshake communication.
    • Recognition requires the server's SETTINGS_ENABLE_CONNECT_PROTOCOL advertisement and a 2xx answer, so an unanswered or refused upgrade is never mistaken for a frame stream.
    • An HTTP/2 response whose content-type is text/event-stream is split into SSE messages, as HTTP/1.1 already was.
    • Recognition is per HTTP/2 stream, not per connection: a WebSocket stream, an SSE stream and ordinary request/response streams can share one connection concurrently.
    • This closes a defect rather than filling a gap. An HTTP/2 message stream used to accumulate into one communication body that was re-written to the cache on every parsing pass, until it reached 16 MB and stopped - the growing-body problem stream messages exist to fix, with a persistence cost per pass on top.
    • Every stream message carries connectionMetadata.transport, h1 or h2. The documents are otherwise identical across transports by design, which is why the transport is recorded at all.
    • No new switch. server.webSocket.parseWebSocket + global.flips.webSocketParsing and server.sse.parseSse + global.flips.webMessageStreamParsing gate their member over either transport - a transport is not a feature.
    • HTTP/3 is not covered: there is no QUIC capture path.
    • Validated end to end in a dedicated capture lab, h2c and h2 over TLS: SSE and WebSocket streams sharing one HTTP/2 connection with ordinary request/response streams, plus fragmentation across DATA frames, permessage-deflate, control frames, every close code and an abnormal RST_STREAM termination.
  • 2026-09 - Imp - An HTTP/2 communication is recorded while its stream is still open.
    • An ordinary HTTP/2 stream produced no document at all until it closed, so a slow or long-lived exchange was invisible until it finished. HTTP/1.x has always emitted progressively, and HTTP/2 is what browsers actually negotiate.
    • The communication is re-emitted as it grows under the same id, so it is one document being updated, not a row per parsing pass.
    • A pass that brought nothing new for a stream emits nothing, and a stream whose response has ended while its request is still being uploaded still waits for the close, so session counters do not double-count.
    • Request and response part statuses now come from the END_STREAM flag instead of being assumed complete, so a partial communication reads as partial.
    • Cost, stated rather than hidden: a long-lived exchange is now written once per pass that changed it, with its accumulated body, up to the 16 MB cap - the same amplification HTTP/1.x has always had for the same traffic.
  • 2026-09 - New - The public demo shop's storefront shows a live order feed over WebSocket.
    • order publishes every status transition to a shared Redis channel; storefront relays each one to the WebSocket clients watching that order at GET /ws/orders/{id}, adding WebSocket to the protocols the demo shows alongside HTTP, gRPC, Redis, PostgreSQL and Kafka.
    • The subscriber connection is recycled every 90 seconds to stay decryptable, and re-reads every watched order's status on each resubscribe since Redis pub/sub has no offset.
  • 2026-09 - New - Compressed WebSocket messages are decoded, and socket.io envelopes are read.
    • A permessage-deflate message used to be stored as its raw compressed bytes and labelled 200 Undecoded. It is now inflated and readable, and its size is the decoded size.
    • Only a connection that negotiated no_context_takeover is decoded, per direction, and this is a permanent limit rather than a gap: carrying the compression window across a parsing pass is not possible with the compression library in use. A connection without it keeps the 200 Undecoded label and its raw payload, which is a truthful record rather than a failure — as does a message that fails to inflate. One direction may decode while the other does not, on the same connection; that is normal and not an error.
    • Inflated payloads can be an order of magnitude larger than the bytes on the wire. server.webSocket.saveWebSocketContent is the only control over that volume.
    • The negotiated compression parameters are now recorded on every message of the connection, so they can be searched. An extension Spider does not implement is recorded by name rather than passed over in silence.
    • socket.io v4 envelopes on text messages are decoded into their packet type, namespace, event name and ack id, all searchable and shown in the message detail view. Detection requires the whole envelope to parse, so an ordinary message that merely starts with a digit is never mislabelled. Only an EVENT carries an event name — an ACK's payload is the acknowledgement's arguments, so its event is empty rather than its first argument.
  • 2026-09 - New - WebSocket and SSE messages can be named and tagged by their own rules.
    • server.webSocket.reqTemplates and server.webSocket.tags match on the connection URI, the message direction, its opcode and its payload. Direction is the part SSE has no use for: an SSE message only ever travels one way.
    • A rule that does not match leaves the message with the template of the HTTP request that opened the connection — never blank. $t in a rule name inserts that inherited template.
    • Editable in the SSE & WebSocket parser configuration panel and testable in the rules playground, alongside the SSE rules.
  • 2026-09 - Fix - Tags on SSE and WebSocket messages were never searchable.
    • They were stored and displayed, but the storage index never indexed them, so no query or aggregation could match one — which is what a tag is for. Every SSE message tag has been in that state since the feature shipped.
    • Existing data is searchable again without re-parsing.
  • 2026-09 - Fix - The message timeline of a WebSocket connection read out of order.
    • Messages were ordered by their position within their own direction, so on a two-way conversation a client message could appear ahead of a server message that arrived a second earlier, and the gaps shown between messages were computed across that inversion.
    • Ordered by time now. SSE was never affected: it has one direction.
  • 2026-09 - Fix - WebSocket messages showed no opcode in the connection view, and SSE messages showed no event type.
    • The message list and the connection flow read those fields from the wrong side of a message, which yields nothing rather than an error. Text, binary and close messages were indistinguishable in a flow, and no SSE event type has been shown in the per-connection message list since it shipped.
  • 2026-09 - New - WebSocket messages (RFC 6455) are parsed over HTTP/1.1.
    • One communication per data frame and per close frame, kind: WEBSOCKET, parsed by the web parser from the 101 handshake on the same TCP sessions as HTTP/1.x, HTTP/2 and gRPC. Each message links back to the handshake communication by transactionId.
    • Fragmented messages are reassembled. The payload lives on the side named by the message's direction - WebSocket is the family's first genuinely bidirectional member - while identity (method, uri, hash, template) stays on req for both directions.
    • Ping and pong frames are counted but produce no communication unless server.webSocket.parseControlFrames is turned on. At the usual ten-second heartbeat that switch is worth some 17,000 keepalive documents a day per connection.
    • The close frame carries closeCode and closeReason. A close with no status code is recorded as 1005, never 0, which is the code for an incomplete message.
    • Gated per whisperer by server.webSocket.parseWebSocket, on by default, and cluster-wide by global.flips.webSocketParsing, off by default - deliberately a different flip from webMessageStreamParsing, so a misbehaving WebSocket engine can be turned off without taking live SSE down.
    • A connection whose opening handshake was not captured cannot be parsed at all: a frame stream cannot be joined mid-flight, and there is no retroactive fix. Restart the client after attaching a whisperer.
  • 2026-09 - New - Controls rebuilds the workload map after its cache restarts.
    • The cache holding the map has no persistent volume, so a restart empties every workload-map key. Replaying the updates queued during the outage would rebuild them onto a map that is no longer there.
    • Controls now asks every connected controller for a fresh full snapshot as soon as its cache connection is back and its Lua scripts have been reloaded.
    • The requests are spread over a window that grows with the size of the fleet, so the recovery does not aim a synchronised burst of snapshots at a cache that has only just restarted.
    • A controller that is disconnected at that moment is skipped and heals on its own reconcile timer.
  • 2026-09 - Fix - SSE message content is no longer gated by HTTP's saveContent.
    • An SSE message payload can't be rebuilt from packets afterwards the way an HTTP body can, so it silently disappeared the moment an operator turned off HTTP body storage for any other reason.
    • Gated by its own server.sse.saveSseContent, on by default, independent of server.webStreams.saveContent.
  • 2026-09 - Fix - Controls: a force-closed workload-map generation was never announced to the parsers.
    • A stalled generation is closed on its own timer, but only a controller's own chunk published anything.
    • Parsers went on resolving every closed address to a workload that had gone, until their next full snapshot.
    • The forced closes now go out on the same stream as any other change.
  • 2026-09 - New - Server-Sent Events are parsed into individual stream messages.
    • A text/event-stream response used to be one HTTP communication whose body grew for the life of the stream. Each event is now its own WebMessageStreamCom, linked to the HTTP communication that opened it by transactionId.
    • Each message carries its direction, its index within that direction, its global txSeq, whether it is terminal, the SSE event:/id:/retry: fields, and its own payload.
    • The payload lives on the side named by the message's directionres for a server-pushed SSE event — so direction-based byte accounting over spider-search-httpcom and spider-search-multicoms is correct.
    • Identity (method, uri, hash, template) stays on req for both directions: it describes the connection, not one direction. method is the synthesized SRV_PUSH/CLT_PUSH label; uri appends the event type as a URI fragment.
    • Parsed by the web parser on the same ports and the same TCP sessions as HTTP/1.x, HTTP/2 and gRPC. SSE over TLS is decrypted with Gocipher's master secrets, as for the other web protocols.
    • Gated per whisperer by server.sse.parseSse, on by default, and cluster-wide by the webMessageStreamParsing flip. With it off, the old single-communication behaviour is unchanged.
    • A connection captured mid-flight is not split: the stream is recognised from the response's Content-Type: text/event-stream header, which was never seen.
    • WebSocket shares the storage shape and the kind discriminator, and gets its own engine in this same release.
  • 2026-09 - New - Stream messages get their own storage, read API and poller.
    • New indices spider-webmessagestreamcom* and spider-webmessagestreamcomcontent*, joined to the spider-search-httpcom and spider-search-multicoms aliases, with their own ILM and Data Storage Policies.
    • New read endpoints: GET /v1/webmessagestream-com/{id}, GET /v1/webmessagestream-transaction/{id} and GET /v1/http-com/{comIdWithContent}/webmessagestream-messages.
    • Stream kinds are excluded from the default HTTP search view; includeStreams lifts the exclusion.
    • A new poller-webmessagestream drains the four member queues to Elasticsearch, and HTTP's own caches move off redis-shared onto a dedicated redis-web.
  • 2026-09 - Imp - The web parser's templates and tags playground moves to POST /v1/http-playground, and stream messages get their own at POST /v1/wms-playground.
    • POST /v1/playground is gone. The published /web-parser/... gateway paths are unchanged for every other route.
  • 2026-09 - Fix - Controls: the workload map could close an address that had only just been announced.
    • Only snapshot chunks register in a generation, so an address announced between two snapshots belonged to none.
    • Reconciling that generation then closed its interval, and a forced close on a stalled generation could take up to 12 minutes of them at once.
    • Retention deleted the closed interval before the next snapshot reopened it, so an as-of-capture lookup resolved to nothing rather than to something stale.
    • An interval that opened after its generation started is now left alone.
  • 2026-09 - Imp - Controls: the workload map's Redis calls report into the service's circuit breakers.
    • They had become the bulk of Controls' Redis traffic while contributing no requests, latency or errors to the monitoring map.
  • 2026-08 - New - SSE stream messages support per-message templates and tags.
    • Each message gets its own req.template and stats.tags, inheriting the handshake HTTP com's values and layering server.sse rules on top.
  • 2026-08 - Fix - The backend no longer refuses to store packets a capture agent marked as belonging to an oversized packet lot.
    • Those packets never reached a parser, which is what made a long one-way stream go dark after 10 MB.
      • With pack.savePackets on they were stored but never queued for parsing; with it off they were dropped on arrival.
    • The plTooBig marker is retired end to end: agents stop setting it, services stop reading it, and the packet views stop hiding and flagging it.
    • Capture agents older than 7.14.0 keep setting it; their packets are now stored anyway, so they lose less data than before, but they still need updating for the fix itself.
    • Those packets resume mid-stream, so while an updated backend runs against older agents, expect a temporary rise in degraded and errored sessions. It is bounded, and it replaces silence with a visible error rather than causing new loss.
  • 2026-08 - Fix - HTTP/1.x parsing now keeps its connection state between passes.
    • A request or response split across a packet-lot boundary is carried over and finished, instead of being dropped.
    • Keep-alive connections with several exchanges in flight pair each response to the right request.
    • Long-lived chunked and SSE responses report their communication as soon as each pass advances them.
    • A malformed connection is marked degraded and stops, rather than growing an unbounded buffer forever.
  • 2026-08 - Fix - Communications captured over TLS reported a duration of zero.
    • Every byte of a decrypted packet lot was dated with the same timestamp, so res.end equalled res.start.
    • Timings are now resolved per TLS record and per packet, as they already were for cleartext.
    • The TLS 1.3 close_notify alert no longer drags a communication's end onto the connection teardown.
  • 2026-08 - Fix - shouldParseTls was always false on HTTP parsing logs.
    • Decryption itself was never affected; only the field written to Elasticsearch was.
    • It now reports the same value the PostgreSQL, Redis and Kafka parsers write.
  • 2026-08 - New - Kubernetes workload identity on every TCP session, packet and communication.
    • Both endpoints carry a namespace, kind, name and cluster node.
    • Resolved when the traffic is captured, not when it is read, so a range change affects new captures only.
    • Four rungs: live Kubernetes object (workload), reverse DNS (dns), configured ranges (cidr), address (ip).
    • The cidr rung needs global.cluster.ipRanges; without it your own pod IPs resolve as externals.
  • 2026-08 - New - Controls carries the workload map, from the controllers to the parsers.
    • Controllers POST it in chunks to POST /v1/controllers/{controllerId}/workload-map.
    • Parsers follow it over SSE, on GET /v1/workload-map/subscribe.
    • It lives in Redis, not process memory: Controls autoscales, and chunks land on different replicas.
    • Chunks upsert and never replace, so a half-arrived snapshot cannot read as a map that lost entries.
    • Only a complete generation closes the intervals it omits.
  • 2026-08 - New - Whisps: a whisperer can declare its own internal CIDR ranges.
    • For an agent sitting on a network the cluster-wide global.cluster.ipRanges does not describe.
  • 2026-08 - Imp - One web parser slot on the TCP session: parsers.http becomes parsers.web.
    • It carries HTTP/1.x, HTTP/2 and gRPC, broken down under parsers.web.itemsByProtocol.
    • parsers.grpc is still read and emitted so in-flight sessions keep their watermarks; nothing new is written.
    • The httpParsingStatus and grpcParsingStatus fields are gone.
  • 2026-08 - Fix - Poller: a CLOSED session whose protocol the poller could not see was destroyed before parsing.
    • The protocol list comes from the served configuration, and a stale one unlinked closed gRPC and Kafka sessions.
    • They were unlinked before the parser reached them, and their communications were lost silently.
  • 2026-08 - Fix - Customers: spider login could permanently break the session it had just created.
    • The browser hand-off minted one refresh token and gave it to both the CLI and the browser.
    • Rotation deletes on use, so whichever refreshed first destroyed the other's credential.
    • It surfaced hours later, with no recovery but a fresh login.
    • The browser's credential is now only verified, and the CLI gets its own grant on the same session.
    • One logout still revokes both, and repeating the hand-off URL is safe.
  • 2026-08 - Fix - Controls: the controller websocket endpoint accepted unauthenticated upgrades.
    • It now rejects an upgrade carrying no valid credential, and bounds its shutdown instead of hanging.
  • 2026-08 - Fix - Kubernetes workload identity now resolves for traffic captured by a sidecar Gossiper.
    • The workload map is keyed per controller, and a sidecar in your own pod spec is not created by Spider.
    • It had no controller name to stamp, so every lookup missed and endpoints fell back to the CIDR tier.
    • Controls now polls each connected controller for its sidecar inventory.
    • It publishes a whisperer + instanceId -> controller map on the existing workload-map stream.
    • Parsers use it whenever no controller was stamped. Agents attached by Spider are unaffected.
    • No configuration change is needed.
  • 2026-08 - New - HTTP/2 traffic is now captured, parsed and displayed like HTTP/1.x.
    • Requests, responses, headers, bodies, templates, tags and transcoding.
    • HTTP/2 over TLS is decrypted and parsed on the same ports, with no configuration change.
  • 2026-08 - Imp - One web parser now handles HTTP/1.x, HTTP/2 and gRPC.
    • Whisperer port configuration is a single list under Web traffic parsing, not one list per protocol.
    • Protocol switches choose which detected protocols are saved; existing configurations migrate.
  • 2026-08 - Fix - TlsKeys: a POST of TLS keys is now validated key by key.
    • One malformed key used to fail the whole array, so a single unusable key could black out decryption.
    • Usable keys are now stored and the answer is 207, carrying saved and rejected counts.
    • Only a batch with nothing usable in it is still a 422.
    • Ownership stays all-or-nothing: a batch carrying another agent's key is refused whole with a 403.
  • 2026-08 - New - RED metrics export over OTLP, from captured traffic to your own collectors.
    • An administrator registers OTLP/HTTP collector endpoints and shares them with teams.
    • A team selects the traffic aggregated into request-rate, error-rate and duration, pushed every minute.
    • Metrics only - spans are out of scope by design.
    • Every exporter carries the author's own access filter, applied server-side to everything it pushes.
    • That filter is server-owned, cannot be edited through the API, and is frozen at the last save.
    • Narrowing or revoking the author's access does not narrow an existing exporter until someone re-saves it.
    • The destination must accept delta temporality: a Collector needs the deltatocumulative processor.
    • Metrics lag two minutes behind real time, so a window is complete before it is pushed.
    • Requires an ENTERPRISE licence (OTEL_EXPORT) and global.flips.otelExport.
  • 2026-08 - New - Collector credentials are write-only end to end.
    • Sealed at rest with a key from global.otelExport.credentialKey, never returned by a read.
    • Never sent to a browser, which is why Test connection runs the handshake server-side.
    • It reports only whether it worked, the status code and the latency.
  • 2026-08 - New - Alert: two probes for the export pipeline.
    • otelExportStale fires when a target falls more than maxWindowsBehind one-minute windows behind.
    • It publishes spider_otel_export_staleness_windows per exporter and target.
    • otelExportDropping fires when an exporter overflows its per-window series budget.
    • It publishes spider_otel_export_dropped_series.
    • Both resolve inactive - never unknown - where the export service is not deployed.
  • 2026-08 - New - Network usage export over OTLP: raw byte and packet counters, not just parsed protocols.
    • A usage exporter selects one controller and a subset of the namespaces the team is granted on it.
    • It publishes spider.network.server.* and spider.network.client.*, by port and direction.
    • The peer's namespace can be added as a label, answering questions parsed traffic cannot.
    • Same OTel targets, delta temporality, per-target watermark and OTEL_EXPORT token as RED export.
    • It is a second data source on the existing feature, not a new one.
    • Lags four minutes rather than two: node batching, a per-minute Controller merge, then the index refresh.
  • 2026-08 - New - Automatic correlation, with nothing configured.
    • A whisperer created with the defaults extracts traceparent, X-Request-ID and X-Correlation-ID.
    • Into a correlationId tag, from HTTP headers, gRPC metadata and Kafka record headers.
    • And from sqlcommenter PostgreSQL query comments.
    • Only the stable 32-hex trace id is taken from a traceparent: its span id changes at every hop.
    • Redis is not correlated: RESP has nowhere to carry a propagation header.
  • 2026-08 - New - gRPC and Kafka tag rules accept an optional pattern.
    • The gjson path selects a value, and the regular expression narrows it to capture group 1.
    • With no capture group the pattern acts as a filter, keeping a matching value and dropping the rest.
    • Rules with no pattern behave exactly as before.
  • 2026-08 - New - PostgreSQL tag rules accept an optional pattern, plus a query source.
    • query matches the raw SQL text of the request instead of resolving a table field.
    • Extraction stays local to the message carrying the text.
    • A cached prepared-statement re-execution produces no tag, rather than one borrowed from elsewhere.
  • 2026-08 - New - Kafka: record headers are decoded and exposed to tag rules as records.#.headers.<key>.
    • No schema binding is needed.
  • 2026-08 - Fix - Links: an expired session token now reports "Session expired".
    • It used to report "You do not have rights to access this service", indistinguishable from a real denial.
  • 2026-08 - New - BASIC now includes every protocol parser, gRPC and Kafka among them.
    • Plus TLS decryption, binary transcoding, the cross-protocol correlated view and keyed PCAP-NG export.
    • Plain PCAP export and PCAP-NG import were already free.
    • In exchange, BASIC carries a ceiling of 1 TB of captured volume per calendar month, per organisation.
    • Passing it pauses new capture only - every read path keeps working.
    • Capture resumes at the start of next month, or by subscribing to remove the ceiling.
  • 2026-08 - Imp - A licence that stops being validated now stops data capture only.
    • No usage reported, expired, or unreachable - all three behave the same way.
    • Every licensed feature is kept: reading captured data, teams, links, SSO, alerting and backups.
    • The reason is shown as a banner in the UI.
  • 2026-08 - New - Network usage now records the transport (TCP/UDP) of each flow.
    • And whether the client/server direction was resolved from the connection or inferred from port ordering.
  • 2026-07 - New - arm64 support: every Spider container image is now a multi-arch manifest (linux/amd64 + linux/arm64), so a Helm install on an arm64 cluster pulls arm64 images with no configuration change. Validated end to end on AWS Graviton, including eBPF TLS capture and all five protocol parsers. The standalone agent tarballs for VM / bare-metal installs remain x86_64-only.
  • 2026-07 - New - Config: the served licence now carries a status (ACTIVE, EXPIRED, NO_STATS, UNREACHABLE, PENDING), so an empty capability list can be told apart from one that never resolved. Licence-fetch errors now name the endpoint that was queried.
  • 2026-07 - New - Controls: optional cap on concurrent whisperer attachments (global and per-customer). Disabled by default.
  • 2026-07 - New - Customers: OIDC providers accept createAccountIfNotExists to refuse sign-in from an address with no account. Defaults to on, as before.
  • 2026-07 - New - Customers: OIDC providers accept timeoutMs to set the HTTP timeout for the token, JWKS and userinfo calls. Defaults to 2000, as before.
  • 2026-07 - Imp - Whisps: the attachment lifetime of a local agent is now admin-only, like its throughput limits.
  • 2026-07 - New - Self-serve licensing: get a free Spider licence, your own registry credentials and a pre-filled values.yaml from the Floocus portal, and start a 14-day trial of the paid features whenever you are ready.
  • 2026-07 - Fix - Installation docs showed PKCS#1 (BEGIN RSA PUBLIC KEY) for the JWT keypair; Spider's Go services require PKCS#8/SPKI and would reject it.
  • 2026-07 - New - Public links can now grant scoped access to network usage data (a chosen controller + selected namespaces), combinable with protocol communication grants.
  • 2026-07 - Fix - PostgreSQL: binary-format query parameter values (e.g. an int4 quantity sent by drivers such as pgx) are now decoded to their canonical text, so parameters that previously showed as garbage in the request detail view render as real values. The parameter type is taken from the server's parameter description captured at prepare time; parameters whose type could not be captured fall back to a \x-hex form rather than corrupting.
  • 2026-07 - Fix - PostgreSQL: the request detail view no longer errors on a prepared statement that takes no parameters (the parameters table is now omitted instead of rendering empty).
  • 2026-07 - Fix - PostgreSQL: binary-format result values (e.g. integers, timestamps, UUIDs, numerics sent by drivers such as pgx) are now decoded to their canonical text at parse time, so columns that previously showed as garbage or blank (invalid UTF-8 replaced before storage) now render as real values. Text values are unchanged; unsupported binary types fall back to a \x-hex form rather than corrupting.
  • 2026-07 - Fix - PostgreSQL: cached prepared-statement re-executions (Bind/Execute) now reuse the column metadata (RowDescription) captured at prepare time. The server sends RowDescription only once, at Describe, so repeated executions previously had no column names - leaving the result table blank and payload tags unextracted.
  • 2026-06 - New - New stuckGocipher alert - fires when a single gocipher instance is persistently failing to send its TLS secrets
  • 2026-06 - New - TLS keys for key-log-only sources (Go crypto/tls, NSS SSLKEYLOGFILE): serverRandom and the negotiated cipher are now read from the cleartext ServerHello (TLS 1.2 & 1.3) and carried on the TCP session.
  • 2026-06 - New - Apache Kafka live parsing
  • 2026-06 - New - Redis (RESP) live parsing
  • 2026-05 - Imp - Web-Upload and Pg-Upload merged into web-write-go and pg-parser-go.
  • 2026-05 - Imp - Poller now runs several pollings at once inside one process, instead of one pod per data type (communications, parsing logs, statuses, TCP sessions, packets, hosts).
  • 2026-05 - Imp - Common parser plumbing (session-parsing loop, Redis/Elasticsearch DAO, TLS decryption, service lifecycle, circuit breakers, stats, HTTP server skeleton) extracted into the shared parsers-core-go library consumed by both Web-Write-Go and Pg-Parser-Go, so fixes land once and the upcoming Redis/gRPC parsers build on it rather than copy from it.
  • 2026-05 - Imp - Web-Read migrated from Node.js to Go (~10x lower memory, ~10x faster startup).
  • 2026-05 - New - HTTP body transcoding via uploaded protobuf/MessagePack schemas; tags and templates now extract from JSON form of binary bodies.
  • 2026-05 - New - Schemas service: content-addressed schema file store.
  • 2026-05 - Imp - Schemas: extracts and indexes the protobuf message types declared by an uploaded bundle, so the UI binding form can populate the Message dropdown.
  • 2026-05 - Imp - Schemas: list endpoint returns all filenames in a bundle (not just the first), enabling clearer picker labels in the UI.
  • 2026-05 - Imp - Schemas: per-operation Elasticsearch circuit breakers (ESUpsert, ESGet, ESSearch) plus startup index ping with retry - the service crash-loops fast if ES is unreachable or the spider-schemas index has not been provisioned.
  • 2026-05 - Imp - Web-Write playground: returned schema resolution now includes the matched binding's display name, and surfaces an explicit "body not stored - enable Save Content on the whisperer" error when a binding fires against an empty stored body.
  • 2026-05 - Fix - Schemas: ES requests now carry HTTP Basic auth (was silently sending unauthenticated requests, every write/read hit a 401).
  • 2026-05 - Fix - Web-Write: schemas service URI is the service host only - the client appends /v1/schemas/{id} itself. The previous default included the path template, so every schema fetch 404'd and protobuf bindings silently fell back to "no body".
  • 2026-05 - Fix - TlsKeys-Linker: stop counting "no TCP session found for a captured TLS key" as a parsing error (expected case, not actionable) - reduces phantom errors in monitoring.
  • 2026-05 - New - Web-Read-Go ?view=transcoded body endpoint and transcode hint on the single-com GET - surfaces decoded JSON for binary bodies bound to a schema.
  • 2026-05 - New - Playground validation API on the Go parsers (web-parser / pg-parser): POST /v1/playground tests tag & template rules against the actual parsing engine and flags regexes the parser cannot use (e.g. backreferences / lookaround, which RE2 rejects).
  • 2026-05 - New - Changed communication protocol from REST+JSON to GRPC between parsers (Web-Write & Pg-Parser) and Pack-Read / Tcp-Update
  • 2026-05 - New - Change serialization format of communications from JSON to Protobuf for: Packets, TcpSessions, Http coms & parsing log
  • 2026-05 - New - Rewrite in Go of major services used in parsing flow: Pack-Write, Pack-Read, Tcp-Write, Tcp-Update, Web-Write Pg-Parser, Tls-Keys-Linker
  • 2026-02 - New - MultiRead service (multi-read) to search HTTP and PostgreSQL communications in a unified view via a single ES alias (spider-search-multicoms).
  • 2026-02 - Imp - Reduce CPU usage of Whisps-Status-Agg, Ciphers-Status-Agg and Hosts-Agg services.
  • 2026-01 - Fixes
    • Fix bug with Gocipher status aggregation when Gocipher is deployed as standalone
    • Fix error when installing plugins (was returning 401 when getting manifest)
    • Fix bug that caused TCP Parsing Status not to be saved

2025

  • 2025-11 - New - New components, services and indices to manage postgresql parsing
  • 2025-11 - Imp - Refactor protocol parsing configuration to easily manage new parser in TcpWrite, TcpUpdate, TcpPoller
  • 2025-11 - Imp - Add feature flips to monitor write not to alert on optional components when not deployed
  • 2025-09 - Imp - All services & UIs - Technical debt removal
    • Moment -> Luxon
    • Request -> Undici
    • Upgrade of libraries to latest
    • Node 22
    • Alpine 3.22
    • Redis 8.2
    • Elasticsearch 9.1
    • Traefik 3.5
  • 2025-05 - New - Service Accounts may now be created and used to connect and call Spiders APIs.
  • 2025-05 - New - Use Kube projected tokens to secure first service calls
  • 2025-05 - New - Use refresh tokens to enhance security
  • 2025-03 - New - Network usage features + status metrics
  • 2025-03 - New - Manage configuration of Controllers & Gociphers
  • 2025-01 - Imp - Default PEM format changed to PKCS#8
  • 2025-01 - New - Throughput limiter config & discarded packets stats capture & aggregation

2024

  • 2024-12 - New - Manage local agents flags on Controls, Ciphers, Whisp, Customers
  • 2024-12 - New - Controls APIs to:
    • Get logs from Controllers, Gociphers, Sidecar whisperers & Ephemeral Whisperers
    • Get listing of Gociphers & Sidecar Whisperers seen by the Controller
  • 2024-11 - New - Decrypt TLS 1.2 for Mozilla recommended cipher suites
  • 2024-11 - Imp - Improve TLS discovery report in CipherStatus
  • 2024-10 - Imp - Remove WebWriteWarning as parsing quality is great
  • 2024-10 - Imp - Whisps, PackWrite, WebWrite, TcpUpdate, TcpWrite, TcpRead: manage TLS parsing
  • 2024-10 - New - Ciphers-Status poller, Ciphers-Raw-Status-Poller to synchronise statuses to ElasticSearch
  • 2024-10 - New - Ciphers-Status-Agg service to aggregate Gociphers statuses
  • 2024-10 - New - Ciphers-Status service to store Gociphers status
  • 2024-10 - New - Ciphers service to manage Gociphers
  • 2024-10 - New - Tls-Keys-Linker service to link Tls Keys to Tcp sessions
  • 2024-10 - New - Tls-Keys service to receive Keys from Gocipher
  • 2024-10 - Imp - Rework Tcp Parsers storage in Redis to allow parallel parsing / update
  • 2024-06 - New - Manage choice of captureMethod for Whisperer + manage it in status
  • 2024-06 - New - Support Gossiper agent
  • 2024-04 - Imp - Add a permission on Controllers to allow someone else than Admin and Controller
  • 2024-04 - New - Data storage policies for Whisperers. Many indices impacts + pollers changes.
  • 2024-04 - Imp - Changed link index from Rotated to Static + add purge. To manage link deletion and limit index count
  • 2024-03 - New - Public link features and APIs + restrictive access in many data and config API
  • 2024-03 - New - Access filters to restrict data access
  • 2024-02 - New - Add job to clean teams and customers that have deleted whisperers older than 1 week
  • 2024-02 - Imp - Add controllers and active attachments to backup
  • 2024-01 - Imp - Add deleted whisperers, controllers and attachments to purge
  • 2024-01 - New - /health API exposing probes status
  • 2024-01 - Imp - Change BO to start correctly even when no change, but block Whisperers from capturing.
  • 2024-01 - Imp - Controls clean shut down - Controls was not closing websockets connection on close.

2023

  • 2023-12 - Imp - Add deployment system version in statistics sent to central
  • 2023-12 - New - Survey checker proxy in NetworkView BFF + refactor of service account token
  • 2023-11 - Imp - Add license name in Mails sent by Spider
  • 2023-11 - Imp - Fixed various race conditions that was communications without responses
  • 2023-09 - Imp - Add possibility to compress Redis payloads using Snappy.
  • 2023-09 - Imp - Add possibility to avoid compression of main API calls.
  • 2023-09 - Imp - New Controls component to manage Controllers. Impacted many.
  • 2023-07 - Imp - Do not take DELETED users into account on users creation or getByEmail
  • 2023-07 - New - Manage OpenId providers for user auth and account creation.
  • 2023-07 - Imp - Fixes under high load - benched at 200 000 HTTP coms /min
  • 2023-07 - Imp - Fixes for recovery after failures: removed expired items from queues
  • 2023-07 - Imp - Upgrade to Node 18
  • 2023-06 - Imp - Add prometheus /metrics page on Alert service
  • 2023-05 - New - Plugins store service
  • 2023-04 - New - Add shutdownDelay option
  • 2023-03 - Imp - Filters headers only after parsing
  • 2023-03 - Imp - False negative in parsing quelity are removed
  • 2023-03 - New - Management of 100 continue when client sent the body anyway ?!
  • 2023-03 - New - New alert firing when polling queues are getting too full
  • 2023-02 - Imp - Parsing status is disabled for Upload whisperers
  • 2023-01 - New - Monitoring supports Kubernetes deployments

2022

  • 2022-11 - New - Decode x-ssl-cert header to extract CN into identification field
  • 2022-09 - New - Maintenance service to perform purge and indices cleaning
  • 2022-09 - New - Stats-Collector service to collect stats and send to Floocus
  • 2022-09 - New - Check license regularly and stop parsing activities when licence is invalid
  • 2022-08 - New - Allow creation of trainee and training team, allow deletion with automatic whisperer deletion.
  • 2022-08 - Imp - Allow import of hosts files
  • 2022-08 - Imp - Improve renaming of hosts with management of cache
  • 2022-07 - Imp - Ignore packets arriving late - after the next pL is started
  • 2022-07 - Imp - Tags cardinality & count
  • 2022-05 - Imp - Upgrade to Redis 7 and ES 7.17.4
  • 2022-04 - Imp - Manage authorized ES connections
  • 2022-04 - New - Protect against big packets lots - limit to 10Mb by default
  • 2022-03 - Imp - Improve Http parsing log streaming management & overhead, as well as parsing logs
  • 2022-03 - Imp - Improve scalability in parsing status mgt
  • 2022-01 - New - Parsers metrics (API, index, monitor job)
  • 2022-01 - New - Option to avoid duplicated packets when capturing both sides of the same communication
  • 2022-01 - Imp - Rework of parsing (v2) with many changes in data model and APIs. Improve performance and footprint! Fixed long tcp sessions issues, better code quality, and improved streaming of parsing.

2021

  • 2021-09 - Imp - Upgrade to Node 16
  • 2021-04 - Imp - Upgraded to Traefik 2.4.8, Metric/Filebeat 7.11
  • 2021-04 - Imp - Move Redis back in Cluster for better maintenance
  • 2021-04 - Imp - Remove coupling between config service and infrastructure
  • 2021-04 - Imp - Upgrade to Redis 6.2
  • 2021-04 - Imp - Migrate to new component and index template since ES 7.8
  • 2021-03 - New - Customer GET user-token API for better impersonating. Manage in all services.
  • 2021-03 - New - Team service + Whisp team management
  • 2021-02 - Imp - Remove unnecessary fields from Customer (UI, Setup, Customer service)
  • 2021-02 - Imp - Upgrade to Docker 20.10.3
  • 2021-02 - Imp - Upgrade to ES 7.11
  • 2021-02 - Imp - Webpack bundling of deliverables - Smaller dockers

2020

  • 2020-12 - Imp - Send mail to admin when new account is created (option)
  • 2020-11 - Imp - Merge Tags extracted from Httpcoms into single stats.tags object. Removed duplicates.
  • 2020-06 - New - New Alert services that send mail to administrator when a probe detects an error
  • 2020-06 - New - New field to index dates in minute resolution to fasten some queries
  • 2020-05 - New - Allow async searches on WebRead, TcpRead, PackRead, Hosts, WhispsStatus
  • 2020-05 - Imp - Replaced Redis DEL with UNLINK
  • 2020-05 - Imp - Upgrade to ES stack 7.7 (ES, Kibana, Beats)
  • 2020-05 - Imp - Output logs in Docker STDOUT and capture them from it. Improve Filebeat and Metricbeat config & index.
  • 2020-04 - Imp - Automatic renew token if cluster was asleep during renew time (Dev platforms)
  • 2020-04 - Imp - Externalized HttpCom raw content and headers storage to another index for performance in searches. New poller.
  • 2020-04 - Imp - Replaced Status Rollup by own implementation with Capture status poller as RollUp search was the slowest search of all
  • 2020-04 - Imp - Use local volumes for logs and filebeat for easier setup
  • 2020-04 - Imp - Do not store _source for metrics
  • 2020-04 - Imp - Refactor DAO, API, Config and CBStats
  • 2020-04 - Imp - Codes in log to aggregate info and ease analysis
  • 2020-03 - Imp - Restart services in case of configuration change
  • 2020-03 - Imp - API stats gathering
  • 2020-02 - Imp - Upgrade to Node 12
  • 2020-02 - Imp - Upgrade to Traefik v2.1
  • 2020-01 - Imp - Allow not saving TCP and HTTPPers
  • 2020-01 - Imp - Dedicated indices for Upload (longer TTL, and purge possible)
  • 2020-01 - Imp - Replicas reduction

2019

  • 2019-11 - New - LDAP authentication
  • 2019-10 - New - Res Templates computing while parsing
  • 2019-10 - New - Req and Res Tags extracted while parsing
  • 2019-10 - New - Allows saving raw headers in resource, and when not to
  • 2019-09 - Imp - Use Elastic ILM to manage Spider indices
  • 2019-09 - New - Whisperers conf can now be used by many instances. 2 new services for status and dns.
  • 2019-07 - New - Expect 100 continue HTTP pattern is now understood
  • 2019-07 - Imp - Services check, at start, for their index in ES before connecting
  • 2019-07 - Imp - Redis reconnection works better
  • 2019-07 - Imp - Upgrade to metricbeat and filebeat 7.2
  • 2019-07 - Imp - Migration to ES 7.2
  • 2019-07 - Imp - New GuiSettings service to save user GUI settings
  • 2019-05 - Imp - Removed dependency to OpenSSL for API key generation and validation
  • 2019-05 - New - Admin may confirm account creation after notification by mail on creation/edition
  • 2019-05 - New - Confirm email address by mail on creation/edition
  • 2019-05 - New - Customers API now allows reinitialisation of passwords with secured process
  • 2019-05 - Imp - Confirmation/Alert email is sent when a password/email has been changed
  • 2019-05 - New - MailSender service to send emails
  • 2019-05 - Imp - Check email unicity when email is changed
  • 2019-04 - Imp - Use bcrypt to store and check passwords
  • 2019-03 - New - GuiLogs service to track errors in GUI
  • 2019-03 - Imp - Removed cookie creation and usage
  • 2019-02 - Imp - Force merge indices with many updates
  • 2019-02 - Imp - Change node process titles for easier monitoring
  • 2019-01 - Imp - End of migration of all BackEnd services to Node 10
  • 2019-01 - Imp - Second phase TCP parsing is now using a Redis queue to avoid parallel parsing and concurrency issues on saving

2018

  • 2018-12 - Imp - Move from NGINX to Traefik
  • 2018-09 - Imp - Upgrade to ES 6.4
  • 2018-09 - Imp - Split Whisps service monolith into 3: Whisp, Whisp status, Host
  • 2018-02 - New - Rights managements on Whisperers
  • 2018-01 - New - Monitoring SSS production !!!
  • 2018-01 - New - Authorization and Rights Management !!
  • 2018-01 - New - Architecture fixes (concurrency)

2017

  • 2017-12 - Imp - Filtering and not saving packets on Whisperers
  • 2017-11 - New - Links service
  • 2017-11 - Imp - Architecture rework: avoid retries, Node eventloop, Redis usage optimisation (Delete, Lua..)
  • 2017-11 - Imp - Architecture rework: automatic ids, ES refresh rate, Pollers rate, NGINX settings, OCC in Redis, Parsing in WebWrite
  • 2017-08 - New - Integrated monitoring APIs (and Kibana)
  • 2017-08 - Imp - Architecture upgrade with Redis and Pollers introduction for better performance
  • 2017-08 - New - Clusterisation with Swarm
  • 2017-07 - New - First release in Parkeon project team: CQRS, HTTP Parsing, UI with login..

2016

  • 2016-02 - New - Starting Spider :-)

UI

2026

  • 2026-09 - New - Send feedback to the Spider team from Network-View - see the blog post.
    • A Send feedback button in the bottom rail opens a panel: a category, a message, and an optional link to the current view.
    • The context attached - version, screen, current selection, licence and your last 20 actions - is shown in full before sending, and can be left out.
    • Search queries, filters and captured traffic are never attached.
    • An optional screenshot is downscaled in the browser, capped at 5 MB, and expires after 90 days.
    • Answers come back to your account address only if you tick Reply to me; the ticket carries a tracking id you can follow.
    • On by default from the chart; turn it off with global.flips.feedback: false. Hidden on an install with no valid licence.
  • 2026-09 - New - Analysis UI: a Save SSE content switch, independent of HTTP's Save content.
    • Lives in the SSE & WebSocket parser configuration panel (renamed from WEBMESSAGESTREAM), on by default.
    • A message's Payload tab now shows a themed "content not saved" hint instead of a plain grey line, and disables itself when the message genuinely has no payload.
  • 2026-09 - Imp - Whisperer parsing-config folds: readable titles and a fold/unfold icon.
    • A fold now reads a real protocol name ("SSE & WebSocket", "gRPC", "PostgreSQL", ...) instead of the raw collection code, matching its name in the view navigation.
    • Each fold shows the same fold/unfold icon as the grid filter menu.
  • 2026-09 - New - Analysis UI: stream messages are a first-class collection.
    • They render in the All grid with every other protocol, and in the HTTP grid behind a persisted Show stream messages in HTTP search setting — off by default, so a chatty stream cannot flood a grid you opened to look at requests.
    • The navigation timeline follows the same setting, so its counts match what the grid lists.
    • A stream message opens in its own detail view — Overview, Payload, Packets, Source — instead of rendering the HTTP view against a document with no request, no response and no headers.
    • A handshake HTTP communication gains a Stream Messages tab listing every message pushed on that stream.
    • Selecting the stream opens a stream transaction view: Global, Flow and Source, with a scrolling timeline that draws the handshake without counting it.
  • 2026-09 - New - Analysis UI: per-whisperer SSE message templates and tags.
    • An SSE & WebSocket parser configuration panel edits server.sse.reqTemplates and server.sse.tags, matching on URI, event type, last-event-id and payload.
    • A Save SSE communications switch sits in the Web traffic parsing panel next to its HTTP and gRPC siblings — all three gate the same engine.
    • Both rule sets are testable in the Templates & Tags playground before being applied.
  • 2026-09 - Fix - Monitoring UI: the topology map drew an arrow head with no line behind it.
    • A link between two nodes on the same vertical had no angle, so its head was placed at the map origin.
  • 2026-09 - Fix - Monitoring UI: the web message stream poller was missing its storage links.
    • The web parser writes the stream's communications and contents to Redis; the poller reads them and saves them to Elasticsearch.
    • Where two links shared a source and a target the map drew them twice and reported only one's statistics; they are now merged.
  • 2026-09 - Imp - Monitoring UI: the topology map is laid out in columns - capture, then parsers, then storage and services.
    • Pollers align on one column, and the nodes whose names overlapped their neighbours are shortened.
  • 2026-08 - New - Analysis UI: a whisperer's parsing configuration has one Web traffic ports panel.
    • It replaces the separate HTTP and gRPC panels, which each owned their own ports.
    • Protocol switches choose which of the detected protocols are saved; existing configurations migrate.
  • 2026-08 - New - Analysis UI: the team Metrics export tab gains a network usage exporter.
    • It selects one controller and a subset of the namespaces the team is granted there.
    • The existing exporter, on whisperers and a filter, is unchanged.
  • 2026-08 - Imp - Analysis UI: the capture screen opens on the All view rather than HTTP.
  • 2026-08 - Imp - Monitoring UI: the parsing charts name the web parser instead of labelling it HTTP.
    • It now parses HTTP/1.x, HTTP/2 and gRPC on one connection.
  • 2026-08 - Imp - Monitoring UI: the three gRPC parsing panels are removed.
    • gRPC packet lots parsing status, gRPC parsing speed and gRPC parsing errors.
    • Packet lots are counted in the web parsing status, communications under the web parser.
    • Nothing is lost, whereas a panel pinned at zero read as "no gRPC traffic".
  • 2026-08 - Fix - Monitoring UI: the parsingSpeedTotal chart summed a parser set that never included Kafka.
    • On any install parsing Kafka, the "total" understated real throughput.
  • 2026-08 - Fix - Sequence diagram: the actor header tooltip now opens reliably on hover.
    • Hovering rebuilt the header instead of raising it, cancelling the tooltip's hover delay.
    • It only showed when something else redrew the view, typically an automatic refresh.
    • A stale duplicate header could also linger after a refresh.
  • 2026-08 - Fix - Sequence diagram: a host or replica opened from an actor header tooltip opens its detail panel.
    • It used to raise "No configuration to load resource of type undefined".
  • 2026-08 - New - Transport (TCP/UDP) across the Network Usage views, logical and physical.
    • A Transport filter in the Both band, and a Transport statistics group-by axis.
    • A Transport grid column, listing what a client-server pair used: tcp, or tcp, udp for both.
    • A Traffic by transport dashboard widget, splitting the window's bytes between TCP and UDP.
    • Traffic captured before the field shipped carries no transport and cannot be backfilled.
    • It forms no bucket, and a transport filter excludes it rather than counting it as unknown.
  • 2026-08 - Fix - The TCP and UDP map toggles now work on the Network Usage Physical view.
    • They were rendered on both views but wired only to the logical one, so they changed nothing there.
    • Link tooltips there also name the transport of each port, as they already did on the logical map.
  • 2026-08 - New - Waterfall and sequence diagram can identify actors by Kubernetes workload or instance.
    • Replicas of one workload collapse onto a single lane / lifeline.
    • Clicking an actor filters on the workload, and Merge replicas is disabled while an identity is active.
  • 2026-08 - Imp - OTel target detail view rebuilt on the standard detail-view components.
    • Edit / Save + Cancel button bar at the top, and team sharing on its own Share tab.
    • The last connection test result is decomposed rather than shown raw.
  • 2026-08 - Imp - Team "Metrics export" tab and the exporter form rebuilt to match the Access filters tab.
    • Exporter cards, standard multi-selects and resolved whisperer names.
    • A Lucene-highlighted filter with a copy button.
  • 2026-08 - New - OTel targets admin collection in the left band.
    • Register, share, enable and delete OTLP collector endpoints, and test the connection to one.
    • The credential field is write-only: it always opens empty, with an unchanged placeholder.
    • Leaving it that way keeps the stored secret rather than clearing it.
    • The collection is absent, not disabled, without an ENTERPRISE licence or with the feature undeployed.
  • 2026-08 - New - Metrics export tab on a team, listing its exporters and authoring new ones.
    • Each exporter shows its per-target push status and last error.
    • Whisperer choice is limited to the team's own INTERFACE whisperers that you can already read.
    • The filter is seeded from your access filter; Use my current filter copies what the grid is on.
    • Preview runs the real aggregation over the next window without saving.
    • It warns when the exporter would overflow its series budget - past the cap, overflow is dropped, not sampled.
    • Authoring needs the team's settings right.
  • 2026-08 - New - The Network Capture map gains a Group by control.
    • IP address, Workload, Instance, Namespace or Cluster node.
    • Nodes cluster on the chosen dimension instead of one node per IP address.
    • namespace/name in Workload mode, namespace/pod-name in Instance mode, the bare name otherwise.
    • Endpoints resolving to no workload are bucketed under Unresolved rather than dropped.
    • Grouping needs global.cluster.ipRanges; without it every mode renders like IP address.
  • 2026-08 - New - Grouped map nodes show a xN replica count on hover.
    • They open the multi-host detail view, one tab per member address.
    • Workload and Instance nodes carry a kind icon: deployment, statefulset, daemonset...
    • Nodes are clustered and coloured by namespace.
  • 2026-08 - New - Cross-map navigation between Network Capture and Network Usage, both directions.
    • A capture-map node tooltip can show the same workload on the usage map.
    • Only on resolved Workload and Instance nodes, and only for traffic from a single controller you can see.
    • The usage map's node popper gains a Show captured traffic row.
    • It selects that controller's whisperers, moves to the HTTP dashboard and filters on the workload.
  • 2026-08 - Imp - The chosen grouping mode is remembered per collection and restored on reload.
    • It is carried in share links and public links.
    • Pinned node positions are kept per grouping mode, so each mode keeps its own layout.
  • 2026-08 - Imp - Hide reverse proxies and Merge replicas are disabled while the capture map is grouped.
    • They are ignored end to end, not just greyed out.
    • A grouped map already keys the client side on the client's own workload.
    • Node identity comes from the workload key rather than from a name regex.
    • Both keep working in IP address mode, and the sequence diagram's own toggle is unaffected.
  • 2026-08 - Imp - The workload block in every detail view's Global tab is trimmed.
    • The instance key is gone: it repeated the namespace, kind, name and cluster node shown above it.
    • The resolved by <source> line is gone: it named an internal enrichment path.
    • The cluster node is now labelled Cluster node:.
    • Detail views no longer report which resolution tier produced the workload; the workload itself is unchanged.
  • 2026-08 - New - Kubernetes workload identity is now available throughout Network-View.
    • Grid columns, Clients/Servers filter bands, and statistics group-by axes and dashboard widgets.
    • Communication, TCP session, packet and host details.
  • 2026-08 - Imp - Free-text search over workload names covers only indices created after their next ILM rollover.
    • Existing indices are unaffected until they roll.
  • 2026-08 - Imp - The internals/externals resolution tier requires global.cluster.ipRanges to be configured.
    • Without it, addresses resolve to a less specific tier instead.
  • 2026-08 - New - Correlation ids now come from extracted tags instead of HTTP headers.
    • The link in the grid works on every protocol rather than HTTP alone, and follows a traceparent correctly.
    • It no longer needs raw header saving to be on.
    • Click shows the whole chain in the All view; shift-click shows it as a sequence diagram.
    • Both replace the active filters rather than combining with them.
    • Action required if you configured correlation headers - see the release note.
  • 2026-08 - New - The correlation setting moved from HTTP settings to Global settings.
    • It now lists tag names rather than header names, defaulting to correlationId.
    • It stays a display setting, so pointing it at a tag extracted months ago lights up old captures at once.
    • Extraction rules can never do that.
  • 2026-08 - New - A Links column ships visible in all six grids: HTTP, gRPC, PostgreSQL, Redis, Kafka and All.
    • It renders a button only on communications carrying a configured correlation tag.
    • Its tooltip names only the tags that matched on that row.
  • 2026-08 - New - The whisperer creation form gains an Extract correlation ids switch, on by default.
    • Each protocol's tag section gains an Add default correlation tags button.
    • The button is idempotent: pressing it twice cannot duplicate a rule and inflate a tag's cardinality.
    • There is no bulk backfill of existing whisperers, on purpose.
  • 2026-08 - New - Pattern column in the gRPC, Kafka and PostgreSQL tag editors.
    • It narrows a selected value with a regular expression.
    • PostgreSQL also gains a Query option, matching the raw SQL text of the request.
  • 2026-08 - New - Kafka record detail shows a Headers column on the record table.
  • 2026-08 - Fix - The correlation link column was never registered in five of the six grids.
    • gRPC, Kafka, PostgreSQL, Redis and All: it rendered nowhere and was absent from the column chooser.
  • 2026-08 - Fix - Excel export failed outright on a visible dynamic tag column whose tag left the data.
    • The stale column is now skipped instead of killing the whole file.
  • 2026-08 - Fix - Creating a public link could fail with "Invalid security token".
    • It happened when the form had been open longer than the session token's lifetime.
    • The token is now read at save time.
  • 2026-07 - New - Public links can now grant scoped access to network usage data (a chosen controller + selected namespaces), combinable with protocol communication grants.
  • 2026-07 - Imp - PostgreSQL detail: type OIDs shown in Parse "Parameter OIDs", Bind "↳ Parameter OIDs" and the ParameterDescription "Types" list now display the PostgreSQL type name alongside the number (e.g. text (25) instead of 25).
  • 2026-07 - Imp - PostgreSQL detail: the result table now renders for cached prepared-statement re-executions, with an info badge on the reconstructed column block noting the columns were reused from the prepared statement (no RowDescription was sent on that execution).
  • 2026-06 - New - Redis, gRPC and Kafka views and parsing
    • Whisperer parsing parameters (capture toggle, content-save toggles, content-schema bindings, templates and tags)
    • Parsing info in TCP details + grid
    • Communications in the unified "All" multi-protocol grid
    • Timeline, Grid, Filters, Sequence diagram, Stats, Dashboard, Playground...
    • Detail panels
  • 2026-06 - New - Gocipher Capture config: new advanced Discovery settings group with "Max concurrent discoveries", bounding how many application binaries the Gocipher inspects at once during discovery.
  • 2026-06 - New - pcapng import & export now use a standard NSS key-log in the Decryption Secrets Block - exported captures decrypt directly in Wireshark, and any standard pcapng + key-log (Wireshark / SSLKEYLOGFILE) can be imported and decrypted, not just Spider's own exports. serverRandom and the cipher are recovered from the ServerHello in the captured packets, so no Spider-specific key-log fields are required.
  • 2026-05 - New - Transcoded view for MessagePack and Protobuf
  • 2026-05 - New - Schema bindings in Whisperer parsing configuration
  • 2026-04 - Imp - Network-View v15.0.0 - major frontend modernization:
    • Upgrade React 16 → 18 (createRoot, concurrent features)
    • Migrate Material-UI v4 → MUI v7 (styled() API, Emotion, no makeStyles)
    • Adopt Redux Toolkit: createSlice for all reducers/actions, configureStore
    • Migrate all connect() containers to React hooks (eliminated ~170 Container files)
    • Replace Moment.js with Luxon for date/time handling
    • Replace Webpack with Rspack for GUI build
  • 2026-05 - New - Content Schemas panel in whisperer parsing config: bind protobuf/MessagePack schemas to (method, uri-template, content-type) tuples.
  • 2026-05 - New - Read-only Schemas admin page.
  • 2026-05 - Imp - Playground previews transcoded body + schema resolution.
  • 2026-05 - Imp - Content Schema binding editor moved into the details panel as a dedicated full-tab form (matches the Team Access Filter pattern, replaces the fullscreen modal).
  • 2026-05 - Imp - Schema picker shared between request and response sides - an upload on one side immediately surfaces on the other; multi-file upload bundles N .proto files as one schema.
  • 2026-05 - Imp - Binding Name auto-fills as <METHOD or ANY> <uri-template> and freezes once edited.
  • 2026-05 - Imp - Message field becomes a dropdown populated from the uploaded bundle's message types (no more typing FQNs by hand).
  • 2026-05 - Imp - Content-Type field uses a creatable select with curated MIME suggestions for consistency with the other selects.
  • 2026-05 - Imp - Playground binding details collapsed behind a "Show binding details" toggle (rows with errors always render); transcoded JSON shown in a syntax-highlighted Ace editor; resolution lines name the matched binding instead of an index; tag values stack one per line for readability.
  • 2026-05 - Imp - Info / error messages from schema upload + listing routed through the standard toast mechanism.
  • 2026-05 - New - HTTP Com Body tab "Transcoded" view - auto-defaults when the com is bound to a schema; falls back to Raw with a banner when the binding misses or decoding fails.
  • 2026-05 - Imp - Whisperer Config Playground now validates Templates and Tags against the actual Go parsing engine (web-parser / pg-parser /v1/playground) - no more false positives; regexes the parser cannot use (backreferences / lookaround) are now flagged
  • 2026-03 - New - Add Playground in Whisperer Config to test Templates and Tags configuration
  • 2026-03 - New - Enhance pcap filter editor in Create Whisperer & Whisperer Capture Config tabs
  • 2026-03 - Imp - Color scale to numeric columns in Grid
  • 2026-03 - Imp - Save filters associated to view when switching views
  • 2026-03 - Imp - Option to show Template in sequence diagram
  • 2026-03 - Imp - Horizontal scroll to sequence diagram
  • 2026-03 - Imp - Drag and drop of actors in Sequence Diagram
  • 2026-03 - Imp - Drag and drop of columns in Columns selection
  • 2026-03 - Imp - Drag and drop of widgets in Dashboard configuration
  • 2026-03 - New - Waterfall view
  • 2026-02 - New - Multi-protocol communications view (label: "All") - unified grid showing HTTP and PostgreSQL communications together, with detail views delegating to the appropriate per-protocol view.
  • 2026-01 - New - PSQL view and parsing - v13
    • Whisperer parsing parameters for PostgreSQL
    • PSQL parsing info in TCP details + grid
    • PSQL view: Timeline, Grid, Snippets, Filters, Sequence diagram, Stats, Dashboard, Diff, Filter views, Public Links
  • 2026-01 - New - Button to get API key for Gociphers in JSON (for standalone ones)
  • 2026-01 - Imp - Add infinite scroll to Controller Attachments and Gociphers TLS targets
  • 2026-01 - Fix - Take selected timezone into account when free entering timespan
  • 2026-01 - Fix - Fixed removing stats issue when reloading was in progress
  • 2026-01 - Fix - Fixed non visibility of tooltips in Plugins params
  • 2026-01 - Fix - Fixed messy timeline X axis in Heatmaps when timerange was below 1s

2025

  • 2025-09 - Imp - Technical debt of UI server
  • 2025-05 - New - Service Accounts management for third party integration
  • 2025-05 - New - Refresh tokens

2024

  • 2024-04 - New - Loading dialog for network map
  • 2024-04 - New - Filter dropdown may load values from multiple fields
  • 2024-04 - New - Network usage physical view
  • 2024-03 - Imp - Gociphers details - New Config permission
  • 2024-03 - New - Gociphers details - New Config tab
  • 2024-03 - Imp - Controllers details - New Config, Monitor & Attach permissions
  • 2024-03 - New - Controllers details - New Config tab
  • 2024-03 - New - Workload details + link to attach Whisperer
  • 2024-03 - New - New Network usage screen, with logical view map + grid + dashboard + stats
  • 2024-03 - New - Refactor navigation to allow selection of Whisperer or Controller
  • 2024-03 - New - New Help screen when no agent is selected
  • 2024-01 - New - Add Throughput limiter settings for Whisperers
  • 2024-01 - Imp - State, Nodes count, sidecars whisperers & gociphers count are added to Controller status
  • 2024-01 - New - Add Display option not to display local agents in agents list.

2024

  • 2024-12 - New - Add feature to create local agents for local capture on Dev workstations
  • 2024-12 - New - Add decoder on Packet content tab (same as TCP, but no plugin for now). First one: DNS decoder
  • 2024-12 - New - Show DNS info in Packet grid when UDP port 53
  • 2024-12 - Imp - Add 95 percentiles in stats tables (perf team request)
  • 2024-12 - New - Controller log fetching feature, for Controller, Attachments, Sidecar Whisperers and Gociphers
  • 2024-12 - New - Controller Gociphers tab - List Gociphers seen by the Controller
  • 2024-12 - New - Controller Sidecars tab - List Sidecar Whisperers seen by the Controller
  • 2024-11 - New - TCP content tab - Decrypt TLS1.2 communication
  • 2024-11 - Imp - TCP content tab - Decode TLS1.2 handshake
  • 2024-11 - Imp - TCP global tab - Add TLS session information
  • 2024-11 - Imp - Http headers tab - Add JWT header in decoded token JSON view
  • 2024-11 - Imp - Http Diff tab - Add JWT header in decoded token
  • 2024-11 - Imp - Http global tab - Timeline displays req and res on two line when they overlap, as during handshake
  • 2024-11 - Imp - Better report of TLS target discovery in targets lists
  • 2024-11 - Imp - Parsing of TLS 1.2 handshakes extensions, more safeguards in extensions parsing errors
  • 2024-10 - New - TLS tab in Whisperers details to list Targets linked to this Whisperer
  • 2024-10 - New - Gociphers tab in user profile
  • 2024-10 - New - Manage TLS capture configuration on Whisperers + few improvements related to TLS
  • 2024-10 - New - Decode TLS sessions in TCP content tab
  • 2024-10 - New - Manage Gociphers: create, status, targets list, share, installation
  • 2024-06 - New - Manage choice of captureMethod for Whisperer + manage it in status
  • 2024-06 - Support Gossiper agent when attaching a Whisperer
  • 2024-05 - Imp - Decode JWT dates fields in HTTP Headers tab
  • 2024-05 - New - Adjust timezone of dates, per Whisperer or Globally
  • 2024-05 - New - New plugin slot to decode TCP payloads
    • Plugins released for HTTP, MQTT, Redis
  • 2024-05 - Imp - Tcp Content tab
    • Timeline
    • New handle on timeline cursor to move through time
    • Headers on top pf packetLots
    • Delay between 2 packetLots
    • Filter on packetLot
  • 2024-05 - Imp - Tcp Details - New handle on timeline cursor to move through time
  • 2024-05 - Imp - Tcp global tab - Progressive loading of parsed items inside the timeline
  • 2024-04 - New - Add form to make Whisperer creation more simple
  • 2024-04 - New - Data storage policy in Parsing configuration of Whisperers
  • 2024-04 - New - Public link feature
    • Ability to create a public link to share a link to someone not having a Spider account
    • Publishing permission on Whisperers and Teams
    • Open the link and limit access
    • Browse, search and delete links
    • Specific terms & conditions with new BFF API and saving in Central
  • 2024-03 - Imp - Improved matrix input component
  • 2024-03 - New - Access filters on team
    • Define access filters to limit users access to a subset of data
    • Show filters in User profile Teams tab
  • 2024-03 - Imp - Improve breadcrumb to keep remember opened tab
  • 2024-02 - Imp - User administration enhancements
    • Admin
      • is able to update others profile even when user is ACTIVE.
      • can remove email confirmation need
      • can validate the mail manually
      • can set password manually (when not ldap)
      • can set if user uses LDAP authentication
    • New user access tabs showing all access & rights a user has
      • User can see their own rights
      • Administrators can see and edit other users rights from these tabs
        • They may, this way, perform bulk update of access rights from the same user
    • Share tabs of Controllers, Whisperers & Teams now use tabs to display Teams & Users.
  • 2024-01 - Imp - Use hosts names from coms when listing servers and clients. Changed HTTP server filter to filter only on servers.
  • 2024-01 - Imp - Add helper info message when timeline loading takes to long telling to zoom or refine filters
  • 2024-01 - Imp - Add helper info message when no Whisperer is selected
  • 2024-01 - Imp - New icons to show that menu can be folded / unfolded
  • 2024-01 - Imp - Limit stats that can be opened at once to 10
  • 2024-01 - Imp - Save, reload and share dashboards

2023

  • 2023-12 - Imp - English privacy terms
  • 2023-11 - New - Survey checker
  • 2023-11 - Imp - Dashboard loader
  • 2023-11 - Imp - Fixes in seq. diagrams
  • 2023-10 - New - Add 'missing' in list of values for some filters in HTTP view. A - Missing - is displayed in list. When selected, a special clause is added to see items without any value in this field.
  • 2023-10 - Imp - New columns to display, in HTTP view, new computed fields (without filters or sort)
    • duration of request (first packet -> last packet)
    • duration of response (first packet -> last packet)
    • latency between last packet of request and first of response
  • 2023-10 - New - Dashboard as an alternative of Map v10.0
  • 2023-10 - Imp - Hover on the header of the life line in the sequence diagram highlight the header and puts it on top
  • 2023-09 - New - Controller feature (see UI RNO) - v9.0
  • 2023-09 - Imp - Improved component used for sharing and tag & templates. Added Hz scroll when to many options.
  • 2023-07 - Imp - Make it impossible to change Whisperer type
  • 2023-07 - Imp - Move purge button to whisperer box, having it only active when purge on this whisperer is possible
  • 2023-07 - New - Redirect to login page on page load when using OIDC and token > 1min
  • 2023-07 - New - Login - Allow connection by OpenId Connect to various providers. Tested with Google, Gitlab, Github & Keycloak.
  • 2023-05 - New - Plugins store UI - v8.0
  • 2023-04 - New - Filter for column selection and UX improvements
  • 2023-04 - New - Badges for selected user, team and whisperer
  • 2023-03 - New - Dynamic HTTP tags filters in menu
  • 2023-02 - Imp - Upload improvements
    • Filter on instance after upload
    • Better timeline mgt
  • 2023-02 - Imp - Fixes after training
    • Delete the name of a host
    • Don't lose edition focus when whisperer is refreshed
    • No more errors when changing team and details opened

2022

  • 2022-09 - New - License information in help panel + display pop in when invalid license
  • 2022-08 - New - Create trainees and training team
  • 2022-07 - New - Import & export hosts of a whisperer
  • 2022-07 - New - New hosts tab in whisperer details to show captured hosts and allow renaming
  • 2022-07 - Imp - Mark packets in wrong order in tcp details and content
  • 2022-07 - Imp - New TCP fields in Packet details and grid
  • 2022-07 - Imp - Tags cardinality & count
  • 2022-07 - New - Grid column ordering
  • 2022-06 - New - Add Whisperer option not to capture / send packet without data to spare CPU and network.
  • 2022-04 - New - Location link in HTTP details
  • 2022-04 - New - Progressive loading of Map and Timeline
  • 2022-04 - New - New plugin hook for client enrichment
  • 2022-04 - New - Manage too big packetLots
  • 2022-03 - Imp - Logo change
  • 2022-03 - New - Help, privacy terms, FOSS page
  • 2022-03 - Imp - Filters & undo improvements
  • 2022-03 - Imp - Option to anonymise user stats per user
  • 2022-02 - Imp - Free time selection improvement: validation / cancellation / size check...
  • 2022-01 - New - Option to anonymize user statistics globally
  • 2022-01 - New - Option to avoid duplicated communications or packets when capturing both sides of the same communication
  • 2022-01 - Imp - Adapt to parsing v2 API for upload, packets download and TCP details and content

2021

  • 2021-12 - New - Display changelog
  • 2021-12 - New - Import / export of whisperer configuration from / to file
  • 2021-12 - New - Allow copying Teams conf to user, and allow user not to use team conf
  • 2021-10 - New - Check for updates when ui got focus
  • 2021-09 - Imp - Upgrade to Node 16 - latest libs
  • 2021-05 - Imp - Refactored UpdateView process
  • 2021-04 - Imp - Timeline zoomout + timeline tooltips
  • 2021-04 - Imp - Better impersonification
  • 2021-04 - New - Team feature + team common settings - v7.0
  • 2021-03 - Imp - Allow saving passwords for plugin params
  • 2021-02 - Imp - Login - Migrated to latest lib version + Hooks + Material UI v4 + common structure and components - v4.0
  • 2021-02 - Imp - Remove unnecessary fields from customer
  • 2021-02 - Imp - Webpack5 + fast-refresh
  • 2021-01 - Imp - Add windowing feature to grids for performance.
  • 2021-01 - New - Allow plugins for Tag enrichment decoding.
  • 2021-01 - Imp - Allow API calls in HTTP headers decoding plugins.
  • 2021-01 - Imp - Map visual improvements: latency on link, tooltip actions, details views of links and nodes, fixed positions stored in user settings.
  • 2021-01 - New - Certificate decoder plugin.
  • 2021-01 - Imp - Pause background tasks when not visible.

2020

  • 2020-12 - New - Allow plugins for HTTP headers decoding.
  • 2020-12 - New - Plugins framework. - v6.0
  • 2020-12 - Imp - Added export to clipboard to complex config inputs (those that accept copy/paste inside)
  • 2020-12 - Imp - HTTP Body is loaded as blob to allow displaying raw / images or anything in only 1 request to server.
  • 2020-12 - Imp - Timeline can zoomout indefinitely. Set default timespan for INTERFACE whisp and remove costly timespan request.
  • 2020-12 - New - Possibility to define custom content-type when no header present in the com.
  • 2020-12 - Imp - Refactor dynamic columns and filters. Works with smartfilters.
  • 2020-12 - New - Excel export of grid with formatters and columns width
  • 2020-11 - Imp - Possibility to change JSON-LD contexts in one place
  • 2020-11 - Imp - HTTP allows duration in ms
  • 2020-11 - Imp - Resize handlers on bottom drawer and details
  • 2020-11 - Imp - Neater bread crumbs
  • 2020-11 - New - Possibility to get bottom drawer to full screen (grid, seq.diag, stats)
  • 2020-11 - New - Click on grid on same item than opened details will close details
  • 2020-11 - New - Dark theme - v5.0
  • 2020-11 - Imp - Restructure all processing and display dedicated to a protocol (HTTP) into a common folder
  • 2020-11 - Imp - Migrated to latest lib version + Hooks + Material UI v4
  • 2020-08 - Imp - Restructure code for better maintenance
  • 2020-05 - New - Use asyncsearch on long timerange queries: Map, TimeLine & Hosts
  • 2020-05 - New - Smartfilters & filters refactor - v4.0
  • 2020-03 - Imp - Better show long communications on Timeline

2019

  • 2019-11 - Imp - Tabs improvements with multiline
  • 2019-11 - Imp - Parsing quality on timeline
  • 2019-11 - Imp - Better tooltips on network map with templates
  • 2019-10 - New - Template and tags config, columns, selection on stats, fields in details
  • 2019-10 - New - Allow custom contexts for JSON-LD payloads
  • 2019-10 - New - Save headers config
  • 2019-08 - Imp - Allow easier filtering on Whisperers and Users: lowercase, split on whitespace...
  • 2019-08 - Imp - Performance improvement in fetching Whisp Status, and Map query for HTTP
  • 2019-08 - Imp - Improved rollup of TCP sessions for monitoring display
  • 2019-07 - Imp - Don't save settings when loading a link
  • 2019-07 - New - Load settings at start
  • 2019-07 - New - Save settings automatically in NetworkView - v3.0
  • 2019-06 - New - Clone Whisp conf
  • 2019-06 - Imp - Improved Lucene parser and autocompletion
  • 2019-06 - Imp - Filters: List of filters values do still take account all others filters when listing values, but do not take into account current filter selected values. This allow adding values on an already selected filters.
  • 2019-05 - New - Saved queries in NetworkView
  • 2019-05 - New - Login UI now offers to reinitialise a forgotten password - v3.0
  • 2019-05 - New - Login UI now offers to create an account
  • 2019-05 - New - Changed lib for toast, and adapted color to message importance. Refactor.
  • 2019-04 - Imp - Refactored and improved error handling in sagas + fallbacks not to block dependent sagas
  • 2019-04 - Imp - Added Error boundaries to Network UI
  • 2019-04 - Imp - Upgraded Network UI to latest React, D3, ..., Webpack, Koa, Node 10, and optimised bundle - from 10MB to 2MB. - v2.0
  • 2019-04 - Imp - Upgraded Login UI to latest React, Webpack, Koa, Node 10, and optimised bundle. - v2.0
  • 2019-03 - Imp - GUILogs are sent by NetworkView, Monitoring and Login in case of errors
  • 2019-03 - Imp - Errors in View or Controller are sent to GuiLogs service for tracking
  • 2019-03 - Imp - Login UI refactored and GUILogs added
  • 2019-03 - Imp - Removed need for Cookie
  • 2019-03 - Imp - Removed Google Analytics
  • 2019-03 - Imp - Search color highlighting improvements
  • 2019-03 - Imp - Compatibility of UI with Chrome, FF, Chromium and Opera
  • 2019-02 - Imp - Clicking on map nodes for filtering works better, in all configuration.
  • 2019-02 - Imp - Clicking on Seq. Diagram headers now acts the same as for map nodes. With the exception of clients headers in hide gateways mode.
  • 2019-01 - Imp - Stats: Can lock independently time selection and filters / stat settings

2018

  • 2018-11 - New - Goto feature
  • 2018-09 - New - Timescale on sequence diagrams
  • 2018-09 - New - Select all on Grid
  • 2018-07 - New - Import/Export of HTTP coms
  • 2018-07 - Imp - Merging clients on map
  • 2018-05 - New - Excel export of stats
  • 2018-05 - Imp - Display delta since start in sequence diagrams
  • 2018-04 - New - Quick filters on correlation Ids
  • 2018-04 - New - Filters inside columns headers
  • 2018-04 - New - Auto completion in search
  • 2018-04 - New - Color highlighting in search
  • 2018-03 - New - Diff feature between items
  • 2018-03 - New - Grid selection with persistence
  • 2018-03 - New - Loading screen ;-)
  • 2018-03 - Imp - Added Unmatched URIs in stats
  • 2018-03 - New - URI templates
  • 2018-03 - Imp - Node detail panel improvement when many whisperers selected
  • 2018-03 - New - Merged replicas host detail panel
  • 2018-03 - New - Quick filter on client identification
  • 2018-03 - Rmv - Hosts stats panel has been removed
  • 2018-03 - New - Stats bar for faster navigation
  • 2018-03 - New - Export sequence diagram in SVG or PNG
  • 2018-03 - New - History drop down to search
  • 2018-03 - New - Statistics panel
  • 2018-02 - Imp - Better UX for locked Nodes
  • 2018-02 - New - Whisperer settings icon
  • 2018-02 - Imp - Shortened client identification
  • 2018-02 - New - Customise Timeline metric
  • 2018-02 - New - Rights managements on Whisperers
  • 2018-02 - New - Search box for JSON tabs and HTTP req/response
  • 2018-01 - New - Display clients on map
  • 2018-01 - New - Filter on aggregated replicas
  • 2018-01 - Imp - Prevent user selection on map
  • 2018-01 - Imp - Quick filters on status on map
  • 2018-01 - New - Global settings tab
  • 2018-01 - New - Merge replicas mode (Map + Seq diagram)
  • 2018-01 - New - Multi whisperers selection
  • 2018-01 - New - Reset time and zoom on timeline
  • 2018-01 - New - Filters for Whisperers and Users list
  • 2018-01 - New - Drag on timeline
  • 2018-01 - New - Authorization and Rights Management !! - v1.0

2017

  • 2017-12 - Imp - Intermediate times in sequence diagrams
  • 2017-12 - New - Filtering and not saving packets on Config
  • 2017-12 - New - Automatic refresh
  • 2017-12 - New - Negations on quick filters
  • 2017-11 - New - Sequence diagrams!
  • 2017-11 - Imp - URL encoding display
  • 2017-11 - New - Sticky details panel
  • 2017-11 - New - Share your state (links)
  • 2017-10 - New - Whisperer creation, config, remote controls and installation forms
  • 2017-08 - New - API documentation
  • 2017-07 - New - First release in Parkeon project team

2016

  • 2016-11 - New - Starting Login UI
  • 2016-08 - New - Starting Networkview UI

Monitoring UI

2026

  • 2026-06 - New - Redis, gRPC and Kafka parsing on the topology map, parsing-status rows and datastore charts
  • 2026-06 - Imp - Reorganised map, and added foldable blocks for top gauges
  • 2026-06 - Imp - Parser self-monitoring now reports true per-session phase times (build / fetch / parse) and sessions-per-batch.
  • 2026-01 - New - Postgresql parsing stack in Summary screen
  • 2026-01 - New - Postgresql parsing charts in Parsing screen

2025

  • 2025-09 - Imp - Technical debt of UI server
  • 2025-05 - New - Refresh tokens
  • 2025-01 - New - Network usage stats in Gocipher view + map

2024

  • 2024-10 - New - Gocipher view
  • 2024-10 - Imp - Add TLS parsing info
  • 2024-10 - Imp - Add Gociphers, Ciphers* & TLS* services to map
  • 2024-04 - New - Data storage policies total size graphics
  • 2024-04 - Imp - Added sections to groups graphics and tables. Avoid API requests for graphs when sections are closed.
  • 2024-01 - New - Alert probes status displayed in the top right of main dashboard
  • 2024-01 - Imp - Stats of Whisperers talking to Controller & Controls talking to Whisp
  • 2024-01 - Imp - Upgraded free time selection component to match main UI

2023

  • 2023-07 - New - Redirect to login page on page load when using OIDC and token > 1min
  • 2023-03 - Imp - Mgt of Elasticsearch metrics in Kube pods
  • 2023-03 - Imp - Add Redis status on main dashboard
  • 2023-03 - Imp - Aggregate Logs by service and whisperer
  • 2023-03 - Imp -Aggregate data upload by Whisperer
  • 2023-01 - New - Supports Kubernetes deployment

2022

  • 2022-06 - New - New Whisperer aggregated CPU and RAM view
  • 2022-01 - New - New parsing tab with speed, delay and duration. New parsing gauges in main.
  • 2022-01 - New - Fix Http parsing status gauge and add Tcp parsing status gauge to main.

2021

  • 2021-09 - Imp - Upgrade to Node 16 - latest libs
  • 2021-04 - New - Added new view: Performance to get statistics in one place of APIs response times, Inter services coms, datastore latency and services usage.
  • 2021-02 - New - Excel export to all grids
  • 2021-02 - Imp - Common structure and components with main UI - 5.0

2020

  • 2020-08 - New - Dark theme - 4.0
  • 2020-08 - Imp - Migrated to latest lib version + Hooks + Material UI v4
  • 2020-05 - Imp - Refactor to improve maintenance. Enhance logs integration. - 3.0
  • 2020-05 - Imp - Add more ES processing in load graph
  • 2020-04 - New - Grid to show logs aggregated by codes. Show code in log grid
  • 2020-03 - New - Services API stats in graph and map
  • 2020-03 - New - Servers & services grids

2019

  • 2019-10 - Imp - Use main cluster API to collect ES nodes stats and not _cat/ summary endpoint
  • 2019-09 - New - Extract logs to a specific view
  • 2019-08 - Imp - Time shift between client and server in Whisp current status.
  • 2019-07 - Imp - Long disconnected Whisp are shown with orange / red colors
  • 2019-07 - Imp - Version of Whisp in Whisp current status.
  • 2019-05 - New - On Map, Browser node show GuiLogs and is Red if errors
  • 2019-04 - Imp - Upgraded Monitoring UI to latest React, D3, ..., Webpack, Koa, Node 10, and optimised bundle - 2.0
  • 2019-04 - New - New grid for GuiLogs tracking
  • 2019-03 - New - CPU and RAM of ES nodes in Map and Servers view
  • 2019-03 - New - Rollup index to speed up monitoring timeline
  • 2019-03 - New - Graph with dockers cpu load and ram
  • 2019-03 - New - Cpu and Ram tracking of Traefik, Beats and UIs
  • 2019-03 - New - Metricbeat integration in Docker cluster to track dockers and nodes metrics
  • 2019-03 - New - Filebeat integration in Docker Cluster - for app monitoring.
  • 2019-02 - New - Graph with Redis load/s
  • 2019-02 - New - Graph with Services load/s

2018

  • 2018-10_11_12 - New - New graphs, services...
  • 2018-09 - New - Hosts grids
  • 2018-08 - New - UI view - 1.0
  • 2018-07 - New - Map view
  • 2018-06 - New - Whisperers, Apps, Servers, Logs view
  • 2018-05 - New - Starting Monitoring UI

Home made setup (deprecated)

2023

  • 2023-04 - Imp - Add possibility to update a Kube installation without only the setup.yml file. No need to have previous environment folder.
  • 2023-04 - New - Add possibility to add extra certificates to the S3 connection used for backups
  • 2023-04 - New - Add shutdownDelay option on Kube
  • 2023-04 - New - Add readiness and liveness probes on Kube
  • 2023-04 - New - Distinct samples for Swarm and Kube
  • 2023-03 - New - Polling queue alert
  • 2023-02 - New - Autoscaling on Kube
  • 2023-01 - New - Support Kubernetes deployments

2022

  • 2022-04 - Imp - Manage authorized ES connections
  • 2022-02 - New - New parsingDelay alert
  • 2022-01 - Imp - Manage Redis instances and maxmemory

2021

  • 2021-12 - Imp - Migrate automation scripts to Node with xs lib
  • 2021-04 - Imp - Maintain docker configs in the stacks of config change. Generate config service docker configs.
  • 2021-04 - Imp - Manage index & component templates. Manage migration from legacy to new templates.

2020

  • 2020-04 - Imp - Manage system versions in setup and update
  • 2020-03 - Imp - Script to create system versions
  • 2020-01 - New - Simplified cluster configuration with setup.yml file (apps + elastic + crons + init + demo)

Swarm Watchdog (deprecated)

2024

  • Change docker registry for Whisperers images

2023

  • Deprecated (but still works)

2021

  • Imp - Reload config every minute

2020

  • Imp - Manage local setup for SSS prod

2019

  • New - Manage multi instance whisperers

2018

  • New - Creation of a watchdog to keep Whisperers alive through client cluster restart