This release adds MQTT topic permissions, negative x-stream-offset values to read the last N stream messages, a state filter on the queue list endpoints and an API endpoint to close a single channel. It adds Prometheus metrics for per-queue deliveries and inter-node replication. Shovels get reworked HTTP destinations and error handling, with classified delivery outcomes, a dest-timeout setting and an aborted state. It also fixes purged messages that came back after a restart, a stream consumer that could starve other fibers during a fast replay, and an AMQP reply text over 255 bytes that broke the frame it travelled in.
Added
Negative x-stream-offset values to consume the last N stream messages #1941
Tab navigation on queue detail pages in the management UI #2006
client_id_validation MQTT config option to require the client ID to match the authenticated username #2038
tls_prefer_server_ciphers config option that makes the server's cipher order decide the negotiated cipher #2204
API endpoint and management UI action to close a single channel #2212
state query parameter on GET /api/queues and GET /api/queues/:vhost to filter queues by state, e.g. ?state=closed or ?state=paused,closed#2234
Per-queue delivered and acked totals in Prometheus metrics #1837
Inter-node replication byte metrics in Prometheus #2051
Shovel dest-timeout setting for HTTP destinations, editable in the management UI, and runtime delivery outcome counters in the shovel API #2128
MQTT topic permissions: per-user, per-topic-filter authorization managed via /api/mqtt/permission-groups. Every vhost gets a default group that allows all topics, delete it to lock the vhost down #2126
Changed
Shovel deliveries are classified into outcomes: a 2xx HTTP response acks the message, 408, 429, 5xx and transport failures requeue it with backoff, statuses that describe the message itself dead-letter it, and repeated unusable-destination outcomes stop the shovel in a new aborted state that is resumed via the API or the management UI. A dead-lettered message is dropped if the source queue has no dead-letter exchange #2128
Overview page card design updates in the management UI #2145#2174
The management UI version is advertised via the LavinMQ-Version response header instead of being injected at build time #2123
Fixed
An AMQP reply_text longer than 255 bytes broke the frame after the header was written and dropped the connection. A passive declare of a missing queue with a long name reaches it, as do the X-Reason headers on DELETE /api/channels/:name and DELETE /api/connections/:name. The text is now truncated on a codepoint boundary #2263
Boolean values in an [sni:...] config section were parsed case-sensitively, so TRUE read as false for 8 keys, including tls_verify_peer where it silently disabled mTLS #2264
A shovel kept reporting the error it had stopped with after it recovered or was resumed #2264
Purged messages that had been requeued came back after a restart, because purge_all dropped them from memory without writing an ack record. The queue size counter could also underflow #2247
A stream consumer replaying from an old offset yielded to other fibers only every 32768 messages, so a fast replay of large messages could starve publishers, other consumers and GC #2227
Configuration
📅Schedule: (UTC)
Branch creation
At any time (no schedule defined)
Automerge
At any time (no schedule defined)
🚦Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕Ignore: Close this PR and you won't be reminded about this update again.
If you want to rebase/retry this PR, check this box
This PR contains the following updates:
| Package | Update | Change |
|---|---|---|
| [cloudamqp/lavinmq](https://github.com/cloudamqp/lavinmq) | minor | `2.9.3` → `2.10.0` |
---
### Release Notes
<details>
<summary>cloudamqp/lavinmq (cloudamqp/lavinmq)</summary>
### [`v2.10.0`](https://github.com/cloudamqp/lavinmq/blob/HEAD/CHANGELOG.md#2100---2026-09-25)
[Compare Source](https://github.com/cloudamqp/lavinmq/compare/v2.9.3...v2.10.0)
This release adds MQTT topic permissions, negative `x-stream-offset` values to read the last N stream messages, a `state` filter on the queue list endpoints and an API endpoint to close a single channel. It adds Prometheus metrics for per-queue deliveries and inter-node replication. Shovels get reworked HTTP destinations and error handling, with classified delivery outcomes, a `dest-timeout` setting and an `aborted` state. It also fixes purged messages that came back after a restart, a stream consumer that could starve other fibers during a fast replay, and an AMQP reply text over 255 bytes that broke the frame it travelled in.
##### Added
- Negative `x-stream-offset` values to consume the last N stream messages [#​1941](https://github.com/cloudamqp/lavinmq/pull/1941)
- Tab navigation on queue detail pages in the management UI [#​2006](https://github.com/cloudamqp/lavinmq/pull/2006)
- `client_id_validation` MQTT config option to require the client ID to match the authenticated username [#​2038](https://github.com/cloudamqp/lavinmq/pull/2038)
- `tls_prefer_server_ciphers` config option that makes the server's cipher order decide the negotiated cipher [#​2204](https://github.com/cloudamqp/lavinmq/pull/2204)
- API endpoint and management UI action to close a single channel [#​2212](https://github.com/cloudamqp/lavinmq/pull/2212)
- `state` query parameter on `GET /api/queues` and `GET /api/queues/:vhost` to filter queues by state, e.g. `?state=closed` or `?state=paused,closed` [#​2234](https://github.com/cloudamqp/lavinmq/pull/2234)
- Per-queue delivered and acked totals in Prometheus metrics [#​1837](https://github.com/cloudamqp/lavinmq/pull/1837)
- Inter-node replication byte metrics in Prometheus [#​2051](https://github.com/cloudamqp/lavinmq/pull/2051)
- Shovel `dest-timeout` setting for HTTP destinations, editable in the management UI, and runtime delivery outcome counters in the shovel API [#​2128](https://github.com/cloudamqp/lavinmq/pull/2128)
- MQTT topic permissions: per-user, per-topic-filter authorization managed via `/api/mqtt/permission-groups`. Every vhost gets a `default` group that allows all topics, delete it to lock the vhost down [#​2126](https://github.com/cloudamqp/lavinmq/pull/2126)
##### Changed
- Shovel deliveries are classified into outcomes: a `2xx` HTTP response acks the message, `408`, `429`, `5xx` and transport failures requeue it with backoff, statuses that describe the message itself dead-letter it, and repeated unusable-destination outcomes stop the shovel in a new `aborted` state that is resumed via the API or the management UI. A dead-lettered message is dropped if the source queue has no dead-letter exchange [#​2128](https://github.com/cloudamqp/lavinmq/pull/2128)
- Overview page card design updates in the management UI [#​2145](https://github.com/cloudamqp/lavinmq/pull/2145) [#​2174](https://github.com/cloudamqp/lavinmq/pull/2174)
- The management UI version is advertised via the `LavinMQ-Version` response header instead of being injected at build time [#​2123](https://github.com/cloudamqp/lavinmq/pull/2123)
##### Fixed
- An AMQP `reply_text` longer than 255 bytes broke the frame after the header was written and dropped the connection. A passive declare of a missing queue with a long name reaches it, as do the `X-Reason` headers on `DELETE /api/channels/:name` and `DELETE /api/connections/:name`. The text is now truncated on a codepoint boundary [#​2263](https://github.com/cloudamqp/lavinmq/pull/2263)
- Boolean values in an `[sni:...]` config section were parsed case-sensitively, so `TRUE` read as false for 8 keys, including `tls_verify_peer` where it silently disabled mTLS [#​2264](https://github.com/cloudamqp/lavinmq/pull/2264)
- A shovel kept reporting the `error` it had stopped with after it recovered or was resumed [#​2264](https://github.com/cloudamqp/lavinmq/pull/2264)
- Purged messages that had been requeued came back after a restart, because `purge_all` dropped them from memory without writing an ack record. The queue size counter could also underflow [#​2247](https://github.com/cloudamqp/lavinmq/pull/2247)
- A stream consumer replaying from an old offset yielded to other fibers only every 32768 messages, so a fast replay of large messages could starve publishers, other consumers and GC [#​2227](https://github.com/cloudamqp/lavinmq/issues/2227)
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTUuMTMiLCJ1cGRhdGVkSW5WZXIiOiI0NC4xMTUuMTMiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbXX0=-->
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
This PR contains the following updates:
2.9.3→2.10.0Release Notes
cloudamqp/lavinmq (cloudamqp/lavinmq)
v2.10.0Compare Source
This release adds MQTT topic permissions, negative
x-stream-offsetvalues to read the last N stream messages, astatefilter on the queue list endpoints and an API endpoint to close a single channel. It adds Prometheus metrics for per-queue deliveries and inter-node replication. Shovels get reworked HTTP destinations and error handling, with classified delivery outcomes, adest-timeoutsetting and anabortedstate. It also fixes purged messages that came back after a restart, a stream consumer that could starve other fibers during a fast replay, and an AMQP reply text over 255 bytes that broke the frame it travelled in.Added
x-stream-offsetvalues to consume the last N stream messages #1941client_id_validationMQTT config option to require the client ID to match the authenticated username #2038tls_prefer_server_ciphersconfig option that makes the server's cipher order decide the negotiated cipher #2204statequery parameter onGET /api/queuesandGET /api/queues/:vhostto filter queues by state, e.g.?state=closedor?state=paused,closed#2234dest-timeoutsetting for HTTP destinations, editable in the management UI, and runtime delivery outcome counters in the shovel API #2128/api/mqtt/permission-groups. Every vhost gets adefaultgroup that allows all topics, delete it to lock the vhost down #2126Changed
2xxHTTP response acks the message,408,429,5xxand transport failures requeue it with backoff, statuses that describe the message itself dead-letter it, and repeated unusable-destination outcomes stop the shovel in a newabortedstate that is resumed via the API or the management UI. A dead-lettered message is dropped if the source queue has no dead-letter exchange #2128LavinMQ-Versionresponse header instead of being injected at build time #2123Fixed
reply_textlonger than 255 bytes broke the frame after the header was written and dropped the connection. A passive declare of a missing queue with a long name reaches it, as do theX-Reasonheaders onDELETE /api/channels/:nameandDELETE /api/connections/:name. The text is now truncated on a codepoint boundary #2263[sni:...]config section were parsed case-sensitively, soTRUEread as false for 8 keys, includingtls_verify_peerwhere it silently disabled mTLS #2264errorit had stopped with after it recovered or was resumed #2264purge_alldropped them from memory without writing an ack record. The queue size counter could also underflow #2247Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.