Changelog
Version 1.4.7 / Backup & Recovery
Overview
This update strengthens Hostbotica’s remote backup infrastructure by adding server-specific destination verification throughout the Hosting Remote Control backup system. Backup processes can now confirm that the correct remote destination is mounted before performing write, cleanup, archive, or truncation operations.
Highlights
Server-Specific Backup Verification
- Added unique verification files for individual server backup destinations.
- Updated HRC configuration to define the expected verification file for each server.
- Replaced generic backup verification with destination-specific validation.
- Prevented an incorrect backup share from being accepted simply because another valid backup destination is mounted.
Mount Validation & Recovery
- Updated
hrc-backup-connectto validate the destination immediately after mounting. - Invalid backup mounts are automatically rejected and unmounted.
- Updated
hrc-backup-connect-verifyto detect invalid destinations and safely reconnect the configured share. - Continued mobile alerting for failed backup verification.
Backup Job Protection
- Added destination verification to application backups.
- Added verification to database backups.
- Added verification to NGINX configuration, certificate, and log backups.
- Added verification to weekly application backups.
- Added verification before backup cleanup operations.
- Added verification before site log archival and truncation.
Data Safety Improvements
- Rotated NGINX logs are now deleted only after successful archival.
- Site access and error logs are truncated only when their corresponding archive succeeds.
- Failed archive operations retain the original source data.
- Database backup scripts now use centralized HRC database exclusions and credential configuration.
Deployment & Validation
- Updated HRC backup scripts across all applicable servers.
- Updated server-specific backup configuration.
- Deployed unique verification files to the corresponding backup destinations.
- Confirmed all remote backup connections following deployment.
Notes
These changes introduce an additional safety layer between Hostbotica servers and centralized backup storage. A remote destination must now be both available and explicitly identified as the correct destination for that server before backup or cleanup operations are permitted.
Version 1.4.6 / Monitoring, Automation & Server Operations
Overview
This update expands Hostbotica’s server health monitoring and standardizes operational checks through Hosting Remote Control. The work improves visibility across production systems while making routine infrastructure checks more consistent and repeatable.
Highlights
Server Health Checks
- Completed comprehensive health checks across Hostbotica production servers.
- Reviewed system resources, storage, services, connectivity, and general operating health.
- Standardized recurring server inspection procedures.
HRC Monitoring Integration
- Converted server health checks into reusable Hosting Remote Control workflows.
- Centralized health-check behavior through HRC configuration and scripting.
- Improved consistency between WordPress, ColdFusion, NGINX, and supporting server environments.
Monitoring & Alerting
- Expanded operational alerting through mobile notifications.
- Improved visibility into server and backup connectivity issues.
- Verified monitoring behavior across production infrastructure.
Scheduled Maintenance
- Completed scheduled system updates across managed servers.
- Verified production services following maintenance.
- Continued standardization of recurring infrastructure maintenance.
Notes
These changes reduce reliance on manual server inspection and provide a more consistent operational baseline across Hostbotica infrastructure.
Version 1.4.5 / Platform Maintenance & Application Infrastructure
Overview
This update consolidates several Hostbotica platform maintenance initiatives completed throughout early 2026, including hosting failover improvements, ColdFusion platform updates, WordPress maintenance, caching changes, and system communication improvements.
Highlights
Primary Hosting & Failover
- Updated primary hosting infrastructure and routing rules.
- Refined failover behavior for hosted services.
- Verified production routing and application availability following configuration changes.
ColdFusion Platform Maintenance
- Applied ColdFusion 2025 application and Java updates.
- Completed associated database maintenance and compatibility checks.
- Continued modernization of ColdFusion hosting environments.
WordPress Infrastructure
- Updated managed WordPress environments.
- Resolved graphics and rendering issues affecting hosted sites.
- Refined Cloudflare and caching configuration for improved delivery consistency.
System Communications
- Updated Hostbotica system email templates.
- Improved consistency of automated system messaging and operational notifications.
Notes
This maintenance cycle focused on keeping the Hostbotica platform current while improving reliability across ColdFusion, WordPress, caching, routing, and system communication components.
Version 1.4.4 / Network Infrastructure & Operations
Overview
This update improves Hostbotica’s network resilience, maintenance infrastructure, and server management processes. The work focused on routing stability, maintenance automation, backup access, and standardized server configuration.
Highlights
Network & Routing Improvements
- Reconfigured production routing and switch behavior.
- Updated production NIC configuration and resolved related virtual machine connectivity issues.
- Improved failover readiness and internal network consistency.
Maintenance Server Improvements
- Expanded the Hostbotica maintenance server configuration.
- Automated NGINX configuration generation and update processes.
- Standardized maintenance handling across existing hosted domains.
- Updated maintenance-server SSH and hostname configuration.
Backup Infrastructure
- Added dedicated backup access for development systems on centralized backup system.
- Continued standardization of remote backup access and server-specific backup configuration.
WordPress & Hosting Maintenance
- Completed scheduled WordPress updates across Hostbotica-managed environments.
- Continued NGINX and Apache caching adjustments for improved performance and consistency.
- Refined Hosting Remote Control documentation and administrative workflows.
Notes
These changes improve the reliability of Hostbotica’s internal network and maintenance systems while reducing manual configuration work during outages, deployments, and infrastructure changes.
Version 1.4.3 / Security, Infrastructure & Server Operations
Overview
This update completes a major SELinux enforcement and server hardening initiative across all Hostbotica WordPress and ColdFusion environments. The work standardizes SELinux behavior, modernizes NGINX hosting configuration, and introduces new Hostbotica Remote Control (HRC) tooling to ensure consistent, repeatable security posture moving forward.
Highlights
SELinux Activation & Standardization
- Activated SELinux enforcing mode across all WordPress and ColdFusion 2023 servers.
- Completed troubleshooting and remediation of policy conflicts to ensure uninterrupted application operation.
- Standardized SELinux contexts for WordPress and ColdFusion services.
HRC Tooling Enhancements
- Created
hrc-selinux-wordpress-defaultsfor managing baseline SELinux contexts on WordPress systems. - Updated
hrc-server-startupto support SELinux configuration sourced directly from centralized HRC configuration. - Updated
hrc-server-shutdownto ensure correct handling of NGINX services and SELinux boolean capitalization.
NGINX & Hosting Configuration
- Converted NGINX to name-based hosting across all environments for improved scalability and configuration clarity.
- Performed general server and domain cleanup across WordPress and ColdFusion installations.
Server Maintenance & Reliability
- Applied DNF updates across all virtual machines.
- Completed security updates and controlled reboot of the production host.
- Copied VM backups to the master backup system and verified integrity.
Performance & Stability Fixes
- Tuned PHP-FPM on the WordPress systems to resolve CPU overload conditions.
- Deployed updated MU-plugins and NGINX configuration changes as part of WordPress maintenance.
Notes
- All production systems verified under SELinux enforcing mode post-deployment.
- No service interruptions observed during enforcement, migrations, or reboots.
- This update lays the groundwork for future automated compliance and hardened default deployments across Hostbotica infrastructure.
Version 1.4.2 / Security & Compliance
Overview
Expanded plugin integrity and monitoring systems across all WordPress environments.
This update finalizes the integration between the Hostbotica Plugin Audit and Plugin Blocklist MU-plugins, ensuring that all plugin actions are both traceable and compliant with Hostbotica’s security policies.
Highlights
- Blocklist Enforcement Improvements
Prevents disallowed plugins from activating and displays contextual in-dashboard notices for site administrators. - Integrated Plugin Audit Awareness
Plugin Audit now automatically ignores events for blocked plugins, eliminating false activation alerts. - Optimized Event Timing
Moved detection and enforcement hooks toinitandadmin_init, ensuring complete accuracy in plugin state detection during load. - Domain-Tagged Email Reports
All audit and blocklist emails now include the site domain in the subject line for quick identification across environments. - Plaintext Email Standardization
Unified all outgoing audit messages under a clean, structured plaintext format with timestamps, site identifiers, and actor details.
Notes
These updates strengthen Hostbotica’s WordPress governance model, ensuring consistency between automated compliance systems and administrative visibility.
Version 1.3.4 / System & Security Enhancements
Overview
This update addresses upstream Red Hat advisories mirrored in AlmaLinux 9/10 and focuses on critical security updates for database, kernel, and container environments across all Hostbotica production nodes.
Highlights
- MariaDB Security Update (RHSA-2025:19572 / RHSA-2025:19584)
Applied patched builds across all WordPress and ColdFusion database clusters to address privilege escalation and data integrity vulnerabilities. - runC / Containerd Update (RHSA-2025:19927)
Updated container runtime packages to resolve multiple container escape and arbitrary write vulnerabilities (CVE-2025-31133, CVE-2025-52565, CVE-2025-52881). - BIND9 Resolver Update (RHSA-2025:19912 / 19793)
Updated internal DNS resolver packages to prevent potential cache poisoning and query amplification exploits. - Kernel Security Patch (RHSA-2025:19886+)
Rolled out to all AlmaLinux 9/10 systems to mitigate privilege escalation and memory corruption issues. - libssh Library Update (RHSA-2025:19472)
Updated SSH-linked libraries used by Git and system utilities for improved session handling and authentication safety. - Redis Security Update (RHSA-2025:19399)
Prepared for future Redis deployments; applied to staging systems for compatibility verification.
Notes
- All production nodes verified under SELinux enforcing mode post-update.
- No service interruptions were detected during rolling reboots.
- ColdFusion and WordPress application stacks remain fully operational under updated environments.
Upgraded Primary External Data Lines to Provider
Enhanced upstream network capacity and redundancy to improve connection stability.
CRON Log and Schedule Cleanup
Standardized task intervals (1→5 minutes) and optimized log rotation for systemd journals.
Cloudflare Updates
Reduced NGINX load by offloading XML-RPC traffic management through Cloudflare rules.
Version 1.4.1 / Network Infrastructure
Plugin Activity Monitor
Created and deployed a MU-plugin for real-time plugin activation and deactivation tracking.
Version 1.4.0 / WordPress Automation
Updated Configuration for All WordPress Sites
Unified NGINX settings across all installations for consistent performance.
Added Global Security Headers
Updated CSP, X-Frame-Options, and X-Content-Type-Options headers for improved protection.
Version 1.3.9 / Security & Optimization