## BlessedRebuS/Krawl — v2.3.1…v2.4.0

_123 commits._

### Features
- **feat(dashboard): open IP Insight when an Overview IP is clicked** (3ae03d7)
- **feat(helm): expose dashboard branding in values** (8a43f0d)
- **feat(dashboard): make the wordmark and contact configurable** (79e07aa)
- **feat: show which pod runs each task in the maintenance panel** (43f5f2e)
- **feat: record which pod last ran each task and expose it on /api/tasks** (fb528ba)
- **feat: fetch external banlists once per cluster and share via Redis** (48ac2cd)
- **feat: mark globally-effecting tasks as single_pod** (6a04cd8)
- **feat: gate single_pod tasks behind a cross-pod lease** (a9124ee)
- **feat: add cross-pod task lease backed by Redis** (8f4ce07)
- **feat: implement in-memory banned IP cache with refresh mechanism and tests** (f36e0d2)
- **feat: campaign min-events threshold, backfill date-range fix, Target column rename** (2c1e3b3)
- **feat: purge orphan campaigns + seed demo threat data** (1d35437)
- **feat: TLSH hashing as scheduled hash-payloads task with watermark backfill** (e306c73)
- **feat: helm chart config for threat-intel capture (TLSH, referer)** (6d19a1f)
- **feat: IP insight — referer history, captured payloads, IP-filtered credentials UI** (c006439)
- **feat: threats dashboard tab — campaign chart, cluster members, similar events, file index** (fbdfad8)
- **feat: dashboard routes — campaign stats, cluster/payload/referer endpoints, IP-filtered credentials** (64e4496)
- **feat: capture pipeline — TLSH payload hashing, referer tracking, file ingestion** (3ce053b)
- **feat: campaign clustering store — TLSH hashing, cluster repository, schema, backfill** (75b9bb1)
- **feat: add support for external map API key management and parameter configuration** (c28cf23)
- **feat: add configurable map API key parameter for tile requests** (c5b2cec)
- **feat: add environment variable for Docker metadata annotations levels** (20fe9c7)
- **feat: enhance Docker build workflow with app version output and metadata labels** (abacb61)
- **feat: rewrite the deception prompt and drop its in-code copy** (fae2454)
- **feat: show the running configuration in the settings panel** (0ce4ce9)
- **feat: enhance PostgreSQL configuration for improved performance and shared memory management** (adfdf16)
- **feat: implement autovacuum tuning for PostgreSQL tables** (71b2cce)
- **feat: add bootstrap analyze for database planner statistics** (775613a)
- **feat: make the map tile source configurable, with an API key (#295)** (6861ef9)
- **feat: group the header actions and move maintenance into a modal** (ee69fc0)
- **feat: add an authenticated maintenance panel to run tasks on demand** (4c0b360)
- **feat: expose memory-growth diagnostics as Prometheus gauges** (02a9476)
- **feat: add ipv6.ignore to drop IPv6 traffic without persisting it** (1124e21)

### Fixes
- **Merge pull request #319 from BlessedRebuS/fix-big-logo** (aa709bf)
- **fix(dashboard): stop a stale stylesheet from blowing up the logo** (21b169e)
- **fix(dashboard): restore the IP referers and payloads routes** (de24315)
- **perf(dashboard): warm the Threats tab** (31cc84f)
- **fix(config): ship the TLSH cluster threshold in config.yaml** (29e102e)
- **fix: keep per-pod analyzer gauges fresh when analyze-ips is skipped** (2e20971)
- **fix: stop wiping the shared cache on every pod startup** (7f494e3)
- **Merge pull request #314 from BlessedRebuS/fix-ram-surge-on-buffer-full** (4a45fa7)
- **fix: update chart version to 2.3.11 for consistency** (965feb3)
- **fix: enhance ban handling by integrating ban_cache for improved performance** (6c069f6)
- **fix: adjust Uvicorn CMD to limit concurrency and backlog to prevent RAM surge** (41b0616)
- **Merge pull request #313 from BlessedRebuS/fix-startup-enrichment-job** (30c144a)
- **fix: update dashboard templates and styles for improved clarity and usability** (c0a49bf)
- **fix: add safe_url filter and update htmx_similar_events to use threshold from config** (38cafc6)
- **fix: prevent OOM crashes by adjusting startup behavior and optimizing log processing** (ad6f0c3)
- **fix: enhance payload processing with MAX_CANDIDATES limit and optimized queries** (9af9bb4)
- **fix: postgres-compatible backfill scalar for campaign clustering** (6457ec2)
- **fix: install build-essential in Docker image for py-tlsh** (263187b)
- **Merge pull request #308 from BlessedRebuS/fix-map-api-key** (2fcbb56)
- **fix: update entrypoint script to conditionally change ownership for non-root uid** (b45693c)
- **fix: serve generated pages with their real content type** (7bf4dad)
- **fix: reconcile the two sources of every config default** (3d5c254)
- **fix: soften the map wheel zoom and share one tile source** (1c91613)
- **fix: give the expanded panels room instead of a cramped scroller** (bf09156)
- **fix: open modals above the expand overlay instead of behind it** (5de28c3)
- **perf: paginate the agg:* dashboard caches inside Redis** (abe3c71)
- **fix: give Redis a memory ceiling and an eviction policy** (cf496c0)
- **perf: track unique_paths with a HyperLogLog instead of an exact set** (7fbc2d2)
- **fix: update database task schedules to improve efficiency** (be2772f)
- **fix: update cron schedules for database tasks to run later in the morning** (5d7a73b)
- **Merge pull request #303 from BlessedRebuS/copilot/fix-fetch-and-pr-job** (a3313fb)
- **Fix fetch-and-pr by setting HOME for create-pull-request** (50523e4)
- **fix: restore normal wheel-zoom speed on the map** (65a564b)
- **Merge pull request #298 from BlessedRebuS/feat-fix-ipv6-flood** (32a5b08)
- **fix: stop the analyzer starving the tail of the address space** (0eaafa8)
- **perf: answer ignored IPs from the ASGI scope, before anything allocates** (659c0c6)
- **fix: bound the request body read, whatever the client declares** (e263e70)
- **perf: stop seven scheduled tasks from also running at every boot** (9747933)
- **fix: cache the ip_stats count so the map does not COUNT(*) per page** (5faf5de)
- **fix: stop krawl log records propagating to the root logger** (a696fcb)
- **fix: stop the startup cleanup scanning the event tables for candidate IPs** (c5dc2d0)
- **fix: bound the in-process state that grew to 4 GiB under the flood** (97ff32c)

### Backend
- **Merge pull request #318 from BlessedRebuS/dev** (4383c78)
- **Merge pull request #317 from BlessedRebuS/feat-release-2.4.0** (be978b5)
- **Merge pull request #316 from BlessedRebuS/feat-shared-task-manager** (339cb32)
- **Merge pull request #312 from BlessedRebuS/feat/threat-intel-enhancement** (51b4088)
- **bumped version** (942f474)
- **Merge pull request #311 from BlessedRebuS/feat/threat-intel-enhancement** (355a4ea)
- **bumped version** (c6d0879)
- **Merge pull request #310 from BlessedRebuS/feat/threat-intel-enhancement** (011eadb)
- **Merge pull request #309 from BlessedRebuS/community-banlist-update** (0243c78)
- **Updated banlist** (09f58f3)
- **Merge pull request #307 from BlessedRebuS/feat-ui-fixes-config-panel** (b1a5d93)
- **Merge pull request #306 from BlessedRebuS/feat-improved-image-build** (9c4b6cc)
- **Merge pull request #305 from BlessedRebuS/feat-improve-db-efficiency** (0575a33)
- **Merge pull request #304 from BlessedRebuS/community-banlist-update** (9485962)
- **Updated banlist** (797fed5)
- **Initial plan** (0645cbd)
- **Merge pull request #301 from BlessedRebuS/feat-improved-attack-map** (bc13759)

### Tests
- **test: cover the ipv6.ignore policy and the four memory ceilings** (d4987fe)

### Docs
- **docs: cover Threats warmup and the Overview IP click** (fe7edfa)
- **docs: bring the documentation up to the 2.4.0 release** (aa9696e)
- **docs: document dashboard branding** (c0d5d1f)
- **docs: describe task synchronization and metric aggregation in scalable mode** (322e16f)
- **docs: update README and architecture to reflect configurable map API key parameter** (a998e5a)
- **docs: explain how to configure the map basemap** (a6c54ca)
- **docs: trim config.yaml comments to two lines per setting** (79e7d5d)

### Chore
- **refactor(dashboard): drop the inline IP dropdown everywhere** (286fed0)
- **style(dashboard): make the Threats tab readable** (fd0eea1)
- **chore(helm): pin the shipped image tag to 2.4.0** (caf9aa0)
- **chore: bump version to 2.4.0 in Chart.yaml** (4d77db0)
- **chore: bump version to 2.3.12 in Chart.yaml** (b7cffb8)
- **style: apply ruff --fix and black auto-fixes [skip ci]** (25b00d5)
- **refactor: fold the reconcile and manual-run locks into task_lock** (b224aa1)
- **chore: bump version to 2.3.10 in Chart.yaml** (f737cf6)
- **style: apply ruff --fix and black auto-fixes [skip ci]** (e9a93f1)
- **style: apply ruff --fix and black auto-fixes [skip ci]** (9e3c66e)
- **style: apply ruff --fix and black auto-fixes [skip ci]** (825a663)
- **chore: bump version to 2.3.6 for krawl-chart** (0e70f79)
- **refactor: streamline Dockerfile with improved labeling and ownership handling** (3946957)
- **chore: update chart version to 2.3.5** (4c8d889)
- **style: trim the PostgreSQL tuning comments in the chart** (dd50efe)
- **chore: update chart version to 2.3.4** (b0ed9bb)
- **style: frame the map wider and cap the load zoom to a global overview** (900c830)
- **chore: update chart version to 2.3.3** (4e684af)
- **style: give the map room and fit the default view to the frame** (a1fe6d0)
- **style: let the basemap recede so the attacker data carries the map** (0dbbde3)
- **style: apply ruff --fix and black auto-fixes [skip ci]** (13dcf5b)
- **chore: update version to 2.3.2 in Chart.yaml** (bf22b69)
- **refactor: log every startup phase with its duration** (e5a7e40)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/BlessedRebuS/Krawl?utm_source=github-action)._