Welcome to the Hangar Open Beta. Please report any issue you encounter on GitHub!
Avatar for gerolndnr

Free, open-source anti-VPN and country rules. Every decision explained, with an optional free dashboard.

Report connection-guard?

R

0.6.0

Connection Guard 0.6.0 adds sequential provider failover, signed local intelligence and operator controls for Paper/Spigot, BungeeCord/Waterfall and Velocity.

Release 0.6.0. The maintainer approved publication of this exact artifact on all plugin platforms. The full 692-address competitive benchmark of this exact artifact is still pending; no comparative detection, false-positive or burst-coverage result is claimed.

  • New installations start in ENFORCE: flagged VPN/proxy/Tor connections can be denied immediately. Blackbox's positive aggregate listing also includes hosting/cloud addresses. Hosting-only ProxyCheck/zowi facts stay review evidence. Select operation.mode: OBSERVE explicitly if you want to inspect before acting. Geo lookups start Disabled. Existing installations retain their chosen mode.
  • Sequential VPN failover is the default, including existing files without a strategy choice. Local Tor, then fresh signed Connection Guard Intel, precede network lookups. The new-install network order is ProxyCheck → Blackbox → zowi → IPQuery → IP-API. ip-check.net is disabled by default; explicit opt-in places it between Blackbox and zowi. Each reached service receives the player's IP. A concrete positive or negative ends the chain; failures, exhausted quotas, open circuits and indeterminate answers move to the next available source. Errors can therefore disclose one IP to multiple recipients. The whole-login budget remains 5,000 ms. Set provider.vpn-failover.enabled: false to restore parallel voting with your retained providers and threshold.
  • Additional player-IP recipients: Blackbox (blackbox.ipinfo.app, Cameron Munroe / ipinfo.app), zowi (api.zowi.gay, operated by the developer of competitor FoxGate), IPQuery (api.ipquery.io), and ip-check.net only if explicitly enabled. Blackbox has no published written terms and its listing can include hosting/cloud. ip-check.net publishes neither an operator, terms nor a privacy policy. Set provider.vpn.blackbox.enabled, .zowi.enabled, .ipquery.enabled or .ipcheck.enabled to false to exclude the respective service. Operators must review the services and include selected recipients in their own player privacy information. Existing installations are not silently opted into these services and get a one-time notice. IP-API remains the final option; its free HTTP endpoint has a non-commercial-use restriction.
  • Connection Guard Intel is enabled on new installations; existing installations must opt in and receive a one-time recommendation. Daily background downloads from intel.connectionguard.net send no player IP, name or UUID. The pinned signing key and SHA-256 verification protect atomic list activation. VPN/Tor entries block, hosting-only enriches review, relay entries follow provider.local.connectionguard-intel.relay: ALLOW|VPN. Disable with .enabled: false. Missing or stale lists yield UNKNOWN without waiting on a login.
  • ProxyCheck uses its supported v2 endpoint with vpn=1, with no hard-coded VPN brand list. VPN and ProxyCheck geo share the same response and local request count. Local Tor remains available during API failures.
  • Provider health is visible: warnings and /cg doctor/Cloud status report exhausted budgets and circuits. Allowed UNKNOWN VPN logins have a cumulative reason counter and a periodic five-minute summary. First transport timeouts open the individual circuit; new default HTTP calls are bounded to 1,500 ms and explicit configured timeouts remain unchanged. Multiple previously untested hanging sources can still consume the 5,000 ms ceiling; no universal two-second outage promise is made.
  • Redis can start with a bounded Memory fallback and reconnect in the background. Invalid configuration reloads keep the last active settings. Coalescing continues to share ongoing lookups for one canonical IP.
  • Policy tools: atomic version activation and rollback, synthetic replay and bounded shadow comparison. Shadow/replay do not activate a policy or send new lookups.
  • Cloud setup is prominent in a colored console block and an authorized staff/operator join hint shown once per installation when unlinked. /cg cloud sync requests an immediate background settings sync with a shared ten-second cooldown and a result/version reply; regular sync continues.
  • Anonymous error reports are enabled with Cloud, including existing files without the option. Only bounded exception types and Connection Guard stack metadata are included; exception messages, player data and credentials are excluded. Disable with cloud.error-reports: false or any Cloud off switch. Error-report disclosure.

Upgrade: back up the plugin data directory, stop the server/proxy, replace the main JAR with connection-guard-0.6.0-all.jar, keep only one main JAR and restart. Do not replace an existing configuration with the new-install template. Migration retains existing mode, provider selections/order, keys and explicit lookup/circuit limits; newly available recipients and Intel require opt-in. Missing strategy defaults to failover, and missing cloud.error-reports defaults on while Cloud is on. Inspect /cg doctor and the one-time notices. To roll back, stop and restore both the backed-up JAR and data directory.

Cloud is optional and on by default. Disable it with cloud.enabled: false, /cg cloud disable or CONNECTIONGUARD_CLOUD=false. Detection-provider controls are separate. Plugin privacy disclosure.

Qualification: 863 regression tests passed in the exact release-commit Build CI. The main JAR and both optional addons are reproducible and match the previously qualified candidate byte for byte. Controlled actual-JAR core and HTTP/Intel/Cloud-command checks passed. Start/help/reload/shutdown checks passed with this main JAR on Paper 26.3 build 159, Folia 26.2 build 7, Velocity 4.2.0 build 30 and 4.2.1-SNAPSHOT build 39 (Java 25), plus Paper 1.21.11 build 132 and Velocity 3.4.0 build 566 (Java 21). These are named runtime smoke checks, not qualification of every supported Minecraft/Java combination or real-account login. Version metadata was checked through Minecraft 26.3 and Velocity 4.2.1; 4.2.1-SNAPSHOT is a development runtime.

Known limits: several previously untested hanging providers can take about 4.52 s in controlled component tests, up to the configured 5,000 ms whole-login ceiling. The maintainer accepted this measured boundary; a universal first-outage latency below two seconds is not claimed. The full 692-address, keyed, three-round, all-platform benchmark must be bound to the final source/JAR hash before results or comparative claims are published. Qualification plan and pre-publication evidence.

Artifacts: use connection-guard-0.6.0-all.jar as the main plugin. The LibertyBans and Limbo JARs are separate optional addons and retain their own 0.1.0-dev module version. SHA256SUMS covers all three downloads. Main JAR SHA-256: 8ba9534abde294eeb830aed848c5014e03409213aed514719abb6c63d6e9b2c2.

Download and docs: https://connectionguard.net/download

Information

Published
October 6, 2026
Author
1Downloads

Platforms

Paper
Paper
1.8–26.3
Waterfall
Waterfall
1.11–1.21
Velocity
Velocity
3.3–4.2.1

Dependencies

PaperPaper

Dependencies: Paper

Plugins and libraries a server needs for this version to run.

No dependencies

Add anything a server has to install alongside this version.

WaterfallWaterfall

Dependencies: Waterfall

Plugins and libraries a server needs for this version to run.

No dependencies

Add anything a server has to install alongside this version.

VelocityVelocity

Dependencies: Velocity

Plugins and libraries a server needs for this version to run.

No dependencies

Add anything a server has to install alongside this version.