Release notes
The public site currently serves The Gateway v2.14.0 for linux/amd64 and linux/arm64.
Download paths
Section titled “Download paths”| Path | Purpose |
|---|---|
/install.sh |
One-shot bootstrap installer. Downloads the verified binary and hands off to the full installer. |
/install-gateway.sh |
Full profile-driven installer for rpi, vps, node, full, and custom installs. |
/releases/latest/gatewayd-linux-amd64 |
Latest amd64 daemon binary. |
/releases/latest/gatewayd-linux-arm64 |
Latest arm64 daemon binary. |
/releases/latest/SHA256SUMS |
Checksums for the latest binaries. |
/releases/v2.10.0/ |
Pinned v2.10.0 archive. |
/releases/v2.11.0/ |
Pinned v2.11.0 archive. |
/releases/v2.12.0/ |
Pinned v2.12.0 archive. |
/releases/v2.12.1/ |
Pinned v2.12.1 archive. |
/releases/v2.13.1/ |
Pinned v2.13.1 archive. |
/releases/v2.14.0/ |
Pinned archive of the current release. |
v2.14.0 summary
Section titled “v2.14.0 summary”Released 30 September 2026. This release adds priority-based WAN failover and recovery, configured through network.wans or Interfaces → WAN Uplinks & Failover.
- Internet-reachability probes use per-uplink, device-bound TCP connections rather than relying on first-hop ICMP. Default targets are
1.1.1.1:443and8.8.8.8:443; per-uplink probe targets are supported. - A single WAN manager chooses the preferred usable uplink, with a 60-second failback hold, a 30-second minimum dwell and flap pinning after three flaps in ten minutes.
- A shared transition updates the default route, policy uplink routes, NAT, tunnel binding, conntrack and DNS pins.
- The UI and API expose editable uplinks, manual/automatic mode, health, active/standby state, reasons and timings.
- Standby addressing, per-uplink firewall scopes and fail-closed handling are covered. Single-uplink nodes retain their previous behaviour.
- Privacy-rule restoration no longer temporarily clears DoH/DoT and STUN block toggles. Other fixes cover a fail-open routing table, missing leak-monitor tunnel information and OpenVPN route-pin cleanup.
The upstream release record reports three primary-link outages on a Raspberry Pi 4: down detection in 20–22 seconds, failover in 21–24 seconds, and 22 passed / 0 failed node checks, with 9/9 leak checks, on the standby. Protected traffic and gateway DNS pause for approximately 10 seconds while tunnels rebind. These are observations from that configuration, not an SLA or an independent audit.
Not included: WAN load balancing or bonding. weight is stored but not used for distribution. The failover alert is not automatically resolved on failback, and a newly added uplink enters the stall watchdog’s watched set after a daemon restart.
The site’s binaries are stripped builds from tag v2.14.0 (source commit fd2d2ffe). Their SHA256SUMS identify these hosted builds, not the artifacts used on the project’s reference node. See Dual-WAN failover for the supported setup.
v2.13.1 summary
Section titled “v2.13.1 summary”v2.13.1 is a verification-driven patch release on top of v2.13.0. Its fixes came from running the product’s own node and leak checks against live reference deployments.
The important operator-facing fixes are:
dns.upstream_modenow reaches the DNS plane, so configured DoT/DoH is actually applied at boot.- Privacy mode no longer downgrades a configured encrypted DNS upstream to cleartext.
- Leak checks understand encrypted upstreams instead of reporting them as ISP leaks.
/whoamiredacts API keys, bearer tokens, cookies, and proxy credentials.- The node verifier no longer risks disabling Pi-hole while checking role scope.
- Automatic rollback stops the service and atomically swaps the binary, avoiding
ETXTBSYfalse-successes. - Release tooling now checks the embedded UI, installer heredocs, installer embeds, shell syntax, builds, vet, and tests together.
- Both reference nodes passed 18/18 verification checks and 9/9 leak checks.
Upgrade notes
Section titled “Upgrade notes”Before upgrading a live gateway:
-
Take a backup before replacing the binary.
-
No configuration change is required for an existing single-uplink node. For multiple uplinks, start with
wan_failover_mode: manual, confirm the proposed decisions, then enableauto. Keep a recovery path and allow for tunnel/DNS interruption during a move. -
Create a diagnostics-role API key at
/root/.gateway-api-keybefore runningscripts/verify-node.sh; without it, API-gated checks are skipped. -
Prefer the update mode for an already-installed node:
Terminal window curl -fsSL https://thegateway.pro/install.sh | sudo env GATEWAY_UPDATE=1 bash
Verify checksums
Section titled “Verify checksums”curl -fsSLO https://thegateway.pro/releases/latest/SHA256SUMScurl -fsSLO https://thegateway.pro/releases/latest/gatewayd-linux-amd64shasum -a 256 -c SHA256SUMS --ignore-missingFor arm64, download gatewayd-linux-arm64 instead.
Related
Section titled “Related”- Installation — install and update commands.
- Security disclosure — how to report a security issue.
- Operations playbook — routine operational checks.
- Performance evidence & release verification — scope of current and historical release results and a reproducible test method.
- Troubleshooting — diagnostics for common failures.