Welcome to the Hangar Open Beta. Please report any issue you encounter on GitHub!
Avatar for gerolndnr

Free, open-source anti-VPN and country rules. Every decision explained, with an optional free dashboard.

Report connection-guard?

R

0.5.0

0.5.0 — 2026-10-04

Rules, providers and reliability

  • New scoped allow/deny/exempt rules for IPv4/IPv6, CIDR and trusted UUIDs, with persistent time limits. Explicit DENY retains priority over ALLOW; an expired rule never grants access.
  • Source-specific country, ASN, ISP/operator, classification, risk and confidence selectors; explain output keeps missing and conflicting evidence separate.
  • Attributed local address lists and optional Geo/ASN MMDB sources with bounded imports and freshness checks.
  • Optional native IPQualityScore (off by default), ProxyCheck v2/v3 selection and exact decimal risk in local decisions, caches and API observations.
  • Whole-login deadlines, bounded transport/cache queues, shared lookups, circuit pauses and local provider request budgets. UNKNOWN is explicit and follows the scoped OPEN/OBSERVE/CLOSED policy.
  • Optional login admission/cooldown limits; SQLite/Redis namespaced rich-fact storage and Redis TLS selection.
  • Validated whole-draft reloads preserve active settings on rejection, account for native permissions/current connection identity and run Bukkit/Folia work on the correct platform scheduler.
  • Versioned provider, observer and read-only admission APIs. Separate optional LibertyBans and native challenge adapters retain their explicit selection, licensing and documented test limits.
  • German and Spanish messages alongside English; custom files remain intact. Rich decision webhooks use actual completed facts, bounded delivery, mention suppression and private defaults.
  • Bundle and relocate Gson and the bStats runtime; keep the 0.4.11 hotfix in actual source history. All platform versions derive from the same build value.

Optional Cloud dashboard

  • Free dashboard at https://app.connectionguard.net for decisions, provider health, quotas, network rules and supported configuration.
  • Cloud is on by default. Until linked, it sends anonymous installation/platform information, health and aggregate counters; no player IPs or UUIDs. After linking and accepting processing terms, it sends individual decisions with IPs and trusted UUIDs. Full privacy disclosure and plugin controls.
  • Turn it off with cloud.enabled: false, /cg cloud disable (persistent) or CONNECTIONGUARD_CLOUD=false. Logins never wait on Cloud; bounded background sync handles outages.
  • Remote settings are validated atomically and layered over local config without rewriting config.yml. Rejected drafts keep the old configuration. Remote console-command execution is unavailable.
  • Time-limited dashboard rules report rule_expiry, preserve absolute deadlines locally and stop matching offline. Already-expired commands are acknowledged without creating a rule.
  • Advanced IPQualityScore/rich-webhook settings remain local; protocol v1 uses the legacy integer risk display. Exact local policy risk remains unchanged.

Upgrade and rollback

Back up the plugin directory and stop the server/proxy. Replace the old JAR with connection-guard-0.5.0-all.jar; keep only one main JAR. Restart and inspect /cg doctor and /cg cloud status.

New installs start in OBSERVE with an empty country blocklist. Existing files without operation.mode retain ENFORCE. Existing translations, provider keys and actions are preserved. Compare new options with the bundled template; do not replace your config blindly. Native IPQualityScore, local data and optional integrations are disabled until selected.

New rich-fact cache namespaces intentionally do not reuse older Boolean-only entries; expect provider lookups while the new cache warms. Provider budgets are process-local estimates, not account-wide remaining quota. Review provider terms before use.

To roll back, stop the server/proxy, restore the backed-up 0.4.11 plugin directory and its JAR, and restart. 0.4.11 does not understand Cloud, managed access rules or the new native integrations; restore its configuration and remove optional 0.5 addons. Disable Cloud before downgrade if desired.

Qualification

Reproducible builds, structured regression reports, package/version-history gates and selected native runtime tests qualify the exact release artifact. Final release scope records the tests and limits. Synthetic login fixtures do not prove authenticated Java/Bedrock account support, every Minecraft version, provider accuracy or production pilot outcomes.

Verified identity-bound challenge grants, complete replay/shadow/rollback and persistent account-wide API budgets are future work; this release does not claim those full differentiation contracts.

Current compatibility — checked 4 October 2026

Compatibility lists include Minecraft Java releases from 1.8 through 26.3, including every 1.21 patch and the 26.1/26.2 releases. Velocity metadata starts at the required 3.3 API and extends through 4.2.1 (current development snapshot); latest stable is 4.2.0. Waterfall has no upstream platform releases beyond 1.21, so its own platform list ends there. Minecraft snapshots are excluded from the release compatibility list.

The same release JAR passed selected clean startup, commands, reload and shutdown checks on Paper 26.3 build 151, Folia 26.2 build 7, Velocity 4.2.0 build 30 and Velocity 4.2.1-SNAPSHOT build 36 / Java 25, in addition to the detailed earlier native login/Cloud checks on the named 1.21.11/proxy builds. Paper/Folia current builds are upstream BETA builds; a passing smoke check does not turn them into stable upstream releases or prove every historical patch.

Separate optional LibertyBans and Limbo challenge JARs are development previews (0.1.0-dev), with their own licenses and integration requirements; install them only when deliberately selecting the documented integration.

Download and docs: https://connectionguard.net/download

Information

Published
October 4, 2026
Author
0Downloads

Platforms

Paper
Paper
1.8–26.3
Waterfall
Waterfall
1.11–1.21
Velocity
Velocity
3.3–4.2.1

Dependencies

PaperPaper

Dependencies: Paper

Plugins and libraries a server needs for this version to run.

No dependencies

Add anything a server has to install alongside this version.

WaterfallWaterfall

Dependencies: Waterfall

Plugins and libraries a server needs for this version to run.

No dependencies

Add anything a server has to install alongside this version.

VelocityVelocity

Dependencies: Velocity

Plugins and libraries a server needs for this version to run.

No dependencies

Add anything a server has to install alongside this version.