v2.1.0
2026-10-02
● stable
What changed
Added
- **Gitea 28 support.** Gitea 28.0.0 (the successor of 1.27 — upstream dropped the `1.` prefix) is validated across install, upgrade (including the consented 1.27 → 28 crossing), config, serving and backup/restore. `gtcnsl gitea install` without `--to` now installs the newest 28.x.
- **Gitea Runner 4.x support.** Runner 4.1.0 is validated across the matrix (host, docker, dind-rootless); `runner install` without `--to` now installs the newest 4.x.
- **SECRET_KEY re-encryption covers Gitea 28.0.** Its crypto was swept against the 28.0.0 source and is unchanged.
Changed
- **`gitea enable-https` takes the domain from `ROOT_URL` first.** Gitea 28 no longer reads `[server] DOMAIN`, so without `--domain` the host now comes from the live `ROOT_URL`, then `DOMAIN`.
- **Domain advice points at `ROOT_URL`.** Quickstart, configuration docs and `config set` help now set `server.ROOT_URL`; on Gitea 1.x set `DOMAIN` too.
- **The re-encryption envelope is an explicit list of verified Gitea lines** (`1.24–1.27, 28.0`), not a range, so versions Gitea never released (1.28, 2.x–27.x) can never count as verified (ADR 0047).
Download
Pick your architecture. Direct links point at the release assets.
$ curl -fsSL https://dl.gtcnsl.com/v2.1.0/gtcnsl-v2.1.0-linux-amd64 -o /usr/local/bin/gtcnsl && chmod +x /usr/local/bin/gtcnsl
i
Verify
Compare against the checksum manifest before you run anything.
checksums.txt