Skip to content

Release notes

The public site currently serves The Gateway v2.14.0 for linux/amd64 and linux/arm64.

Path Purpose
/install.sh One-shot bootstrap installer. Downloads the verified binary and hands off to the full installer.
/install-gateway.sh Full profile-driven installer for rpi, vps, node, full, and custom installs.
/releases/latest/gatewayd-linux-amd64 Latest amd64 daemon binary.
/releases/latest/gatewayd-linux-arm64 Latest arm64 daemon binary.
/releases/latest/SHA256SUMS Checksums for the latest binaries.
/releases/v2.10.0/ Pinned v2.10.0 archive.
/releases/v2.11.0/ Pinned v2.11.0 archive.
/releases/v2.12.0/ Pinned v2.12.0 archive.
/releases/v2.12.1/ Pinned v2.12.1 archive.
/releases/v2.13.1/ Pinned v2.13.1 archive.
/releases/v2.14.0/ Pinned archive of the current release.

Released 30 September 2026. This release adds priority-based WAN failover and recovery, configured through network.wans or Interfaces → WAN Uplinks & Failover.

  • Internet-reachability probes use per-uplink, device-bound TCP connections rather than relying on first-hop ICMP. Default targets are 1.1.1.1:443 and 8.8.8.8:443; per-uplink probe targets are supported.
  • A single WAN manager chooses the preferred usable uplink, with a 60-second failback hold, a 30-second minimum dwell and flap pinning after three flaps in ten minutes.
  • A shared transition updates the default route, policy uplink routes, NAT, tunnel binding, conntrack and DNS pins.
  • The UI and API expose editable uplinks, manual/automatic mode, health, active/standby state, reasons and timings.
  • Standby addressing, per-uplink firewall scopes and fail-closed handling are covered. Single-uplink nodes retain their previous behaviour.
  • Privacy-rule restoration no longer temporarily clears DoH/DoT and STUN block toggles. Other fixes cover a fail-open routing table, missing leak-monitor tunnel information and OpenVPN route-pin cleanup.

The upstream release record reports three primary-link outages on a Raspberry Pi 4: down detection in 20–22 seconds, failover in 21–24 seconds, and 22 passed / 0 failed node checks, with 9/9 leak checks, on the standby. Protected traffic and gateway DNS pause for approximately 10 seconds while tunnels rebind. These are observations from that configuration, not an SLA or an independent audit.

Not included: WAN load balancing or bonding. weight is stored but not used for distribution. The failover alert is not automatically resolved on failback, and a newly added uplink enters the stall watchdog’s watched set after a daemon restart.

The site’s binaries are stripped builds from tag v2.14.0 (source commit fd2d2ffe). Their SHA256SUMS identify these hosted builds, not the artifacts used on the project’s reference node. See Dual-WAN failover for the supported setup.

v2.13.1 is a verification-driven patch release on top of v2.13.0. Its fixes came from running the product’s own node and leak checks against live reference deployments.

The important operator-facing fixes are:

  • dns.upstream_mode now reaches the DNS plane, so configured DoT/DoH is actually applied at boot.
  • Privacy mode no longer downgrades a configured encrypted DNS upstream to cleartext.
  • Leak checks understand encrypted upstreams instead of reporting them as ISP leaks.
  • /whoami redacts API keys, bearer tokens, cookies, and proxy credentials.
  • The node verifier no longer risks disabling Pi-hole while checking role scope.
  • Automatic rollback stops the service and atomically swaps the binary, avoiding ETXTBSY false-successes.
  • Release tooling now checks the embedded UI, installer heredocs, installer embeds, shell syntax, builds, vet, and tests together.
  • Both reference nodes passed 18/18 verification checks and 9/9 leak checks.

Before upgrading a live gateway:

  1. Take a backup before replacing the binary.

  2. No configuration change is required for an existing single-uplink node. For multiple uplinks, start with wan_failover_mode: manual, confirm the proposed decisions, then enable auto. Keep a recovery path and allow for tunnel/DNS interruption during a move.

  3. Create a diagnostics-role API key at /root/.gateway-api-key before running scripts/verify-node.sh; without it, API-gated checks are skipped.

  4. Prefer the update mode for an already-installed node:

    Terminal window
    curl -fsSL https://thegateway.pro/install.sh | sudo env GATEWAY_UPDATE=1 bash
Terminal window
curl -fsSLO https://thegateway.pro/releases/latest/SHA256SUMS
curl -fsSLO https://thegateway.pro/releases/latest/gatewayd-linux-amd64
shasum -a 256 -c SHA256SUMS --ignore-missing

For arm64, download gatewayd-linux-arm64 instead.