Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Backport of Dockerfile: bump up to ubi-minimal:9.3 into release/1.17.x #20026

Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
298 commits
Select commit Hold shift + click to select a range
48c4a5b
Add grpc keepalive configuration. (#19339)
hashi-derek Oct 24, 2023
12ef115
bump raft-wal version to 0.4.1 (#19314)
dhiaayachi Oct 24, 2023
9775758
NET-5397 - wire up destination golden tests from sidecar-proxy contro…
jmurret Oct 24, 2023
9417fc2
gvk partial inference (#19058)
xwa153 Oct 24, 2023
59d4962
NET-6079 - wire up sidecarproxy golden file inputs into xds controlle…
jmurret Oct 24, 2023
abbf858
NET-6080 - xds controller golden file inputs into xds resources - des…
jmurret Oct 24, 2023
dc00be0
NET-6081 - xds controller golden file inputs into xds resources - sou…
jmurret Oct 24, 2023
e414cbe
Use strict DNS for mesh gateways with hostnames (#19268)
Oct 24, 2023
a7803bd
[NET-6305] xds: Ensure v2 route match and protocol are populated for …
zalimeni Oct 25, 2023
6360c74
Add clarification for route match behavior (#19363)
Oct 25, 2023
6d5c01e
Fix 1.17.x release notes and added templated policies (#19370)
roncodingenthusiast Oct 25, 2023
0fefaa6
docs - release notes (add enterprise label and example of non compati…
Oct 26, 2023
b5023b6
feat: read resource namespace (#19320)
JadhavPoonam Oct 26, 2023
0295b95
Net 5875 - Create the Exported Services Resources (#19117)
absolutelightning Oct 26, 2023
1806bcb
test: add missing tests for list endpoint (#19364)
JadhavPoonam Oct 26, 2023
4096c96
Add enterprise label for rate limiting (#19384)
Oct 26, 2023
3b806d4
test deployer: fix a bug when deploying cluster with various ent imag…
huikang Oct 26, 2023
ea91e58
Stop use of templated-policy and templated-policy-file simultaneously…
roncodingenthusiast Oct 26, 2023
5698353
Resource Hook Pre-Decode Utilities (#18548)
mkeeler Oct 26, 2023
0abd96c
resource: resource service now checks for `v2tenancy` feature flag (#…
analogue Oct 27, 2023
01bfa2c
Fix casing in example yaml config (#19369)
nathancoleman Oct 27, 2023
1a6225a
Delete unused files (#19402)
Oct 27, 2023
f0cf8f2
NET-6294 - v1 Agentless proxycfg datasource errors after v2 changes (…
jmurret Oct 27, 2023
3350a91
increasing unit tests timeout from 10m to 30m (#19423)
jmurret Oct 27, 2023
42647de
[NET-6138] security: Bump `google.golang.org/grpc` to 1.56.3 (CVE-202…
zalimeni Oct 30, 2023
e18901b
Update multi-port examples to remove spec.template.metadata.name (#19…
im2nguyen Oct 30, 2023
4b26ed8
integ test: snapshot mesh frozen bug test (#19435)
huikang Oct 30, 2023
7a5d0a6
docs - Update k8s compat matrix (#19378)
Oct 31, 2023
54717e6
Update README.md (#19413)
Oct 31, 2023
97d92ad
Fix typo in kind for JWT config on API Gateway (#19441)
nathancoleman Oct 31, 2023
ca655ca
NET-5186 Add NET_BIND_SERVICE capability to consul-dataplane requirem…
nathancoleman Oct 31, 2023
65605c5
added redirect for conf entries 1.8.x (#19460)
trujillo-adam Nov 1, 2023
413e2a7
Update docs for service splitter example typo (#19469)
jm96441n Nov 1, 2023
815c52a
Regen expired test certs (#19476)
analogue Nov 2, 2023
bb3d5a1
build: ensure we pull through the hashicorp proxy instead of going di…
rboyer Nov 2, 2023
896d8f5
temporarily disallow L7 traffic permissions (#19322)
skpratt Nov 2, 2023
77e9a50
Source / local_app golden tests to include all protocols. (#19436)
jmurret Nov 2, 2023
8f4c437
[NET-5916] Fix locality-aware routing config and tests (CE) (#19483)
hashi-derek Nov 2, 2023
a72f868
testing/deployer: update deployer to use v2 catalog constructs when r…
rboyer Nov 2, 2023
aaac20f
resource: misc finalizer apis (#19474)
analogue Nov 2, 2023
4b85aa5
testing/deployer: support tproxy in v2 for dataplane (#19094)
rboyer Nov 2, 2023
2bc0bc3
update v2 changelog (#19446)
ndhanushkodi Nov 2, 2023
d94d316
NET-6319 - L7 routes have statePrefix of upstream. and should have a …
jmurret Nov 3, 2023
ef35525
resource: finalizer aware delete endpoint (2 of 5) (#19493)
analogue Nov 3, 2023
fd128f4
build: dependency updates for 1.17.0 (#19453)
DanStough Nov 3, 2023
65592d9
chore: apply enterprise changes that were missed to some testing file…
rboyer Nov 3, 2023
c3c836e
Net-6291/fix/watch resources (#19467)
JadhavPoonam Nov 3, 2023
74daaa5
XDS V1 should not make runs for TCP Disco Chains. (#19496)
jmurret Nov 3, 2023
6f4e037
testing: disable v2 linkage to nodes in integration tests (#19509)
rboyer Nov 3, 2023
395d32e
Shuffle CICD tests to spread worker load. (#19501)
hashi-derek Nov 6, 2023
6baf695
[NET-6459] Fix issue with wanfed lan ip conflicts. (#19503)
hashi-derek Nov 6, 2023
e5948e8
CC-5545: Side Nav (#19342)
Nov 6, 2023
28b1469
fixed typos in redirect for api gateways (#19526)
trujillo-adam Nov 6, 2023
c9f2a6a
[NET-5916] Update locality-aware routing docs (#19529)
zalimeni Nov 6, 2023
90aa83f
[NET-5916] docs: Remove locality proxy startup section (#19534)
zalimeni Nov 6, 2023
38d9428
Ci upgrade test 1 17 (#19536)
huikang Nov 6, 2023
24df835
added 1.17 features to enterprise overview (#19514)
trujillo-adam Nov 6, 2023
5352ff9
Added tenancy tests for WorkloadHealth controller (#19530)
Ganeshrockz Nov 7, 2023
2da7dd0
v2tenancy: register tenancy controller deps (#19531)
analogue Nov 7, 2023
f115cdb
NET-6385 - Static routes that are inlined in listener filters are als…
jmurret Nov 7, 2023
64db2d9
Add kubebuilder annotations to enums (#19454)
Nov 7, 2023
a66cb58
test: fix some of the peering topology tests to safely run without te…
rboyer Nov 7, 2023
393f7a4
Fix more test flakes (#19533)
hashi-derek Nov 7, 2023
028f1d8
NET-6390 Initialize MeshGateway proto (#19548)
nathancoleman Nov 7, 2023
1f5aa83
ui: clear peer on home link (#19549)
Nov 7, 2023
4d7754a
test: update makefile to include ways to trigger deployer integration…
rboyer Nov 7, 2023
d203c0a
test: update deployer default images (#19554)
rboyer Nov 7, 2023
20f43d8
test: update certs for 10 year expiry (#19481)
DanStough Nov 7, 2023
6e2a44e
Update enterprise features table with 1.17 features (#19558)
im2nguyen Nov 7, 2023
f2f7235
Fix typo in GatewayClassConfig docs (#19563)
nathancoleman Nov 7, 2023
48d7d4a
docs: Multi-port support for v1.17 GA (#19401)
boruszak Nov 7, 2023
8d6545e
test/deployer: add the method of deregistering services (#19525)
huikang Nov 7, 2023
caaff73
add DeliverLatest as common function for use by Manager and ProxyTrac…
jmurret Nov 7, 2023
7bc2581
Migrate individual resource tests for Discovery Chains to TestAllReso…
jmurret Nov 8, 2023
985aa76
NET 6354 - Add tenancy in Node Health Controller (#19457)
absolutelightning Nov 8, 2023
09f73d1
Migrate individual resource tests for expose paths and checks to Test…
jmurret Nov 8, 2023
a7774a9
Introduce randomized timings and reproducible randomization into cont…
mkeeler Nov 8, 2023
903ff7f
Migrate individual resource tests for custom configuration to TestAll…
jmurret Nov 8, 2023
873b705
Update Helm docs for consul-k8s 1.3.0 (#19581)
nathancoleman Nov 8, 2023
5aff19f
Migrate individual resource tests for JWT Provider to TestAllResource…
jmurret Nov 8, 2023
7de0b45
Fix xds v2 from creating envoy endpoint resources when already inline…
jmurret Nov 8, 2023
a7f3069
test: add a v2 container integration test of xRoute splits (#19570)
rboyer Nov 8, 2023
2296bd5
docs: spike of info about how to use deployer topology tests (#19576)
rboyer Nov 8, 2023
515eed8
Net 6439 (#19517)
absolutelightning Nov 9, 2023
2553d6e
Migrate individual resource tests for Terminating Gateway to TestAllR…
jmurret Nov 9, 2023
4aa95f3
Migrate individual resource tests for Ingress Gateway to TestAllResou…
jmurret Nov 9, 2023
5b581e0
Update links and fix route kind for APIGW JWT Docs (#19585)
jm96441n Nov 9, 2023
a94fa4c
Migrate individual resource tests for Mesh Gateway to TestAllResource…
jmurret Nov 9, 2023
f5bf256
Migrate individual resource tests for API Gateway to TestAllResources…
jmurret Nov 9, 2023
4273616
toil: use pre-commit to maintain properly formatted imports (#17940)
analogue Nov 9, 2023
f09dbb9
[NET-6356] Add tenancy to Failover Tests (#19547)
kkavish Nov 9, 2023
3df8b58
[NET-6444] Add tenancy to Reaper Tests (#19550)
kkavish Nov 9, 2023
780e916
Migrate remaining individual resource tests for service mesh to TestA…
jmurret Nov 9, 2023
40c57f1
NET-6391 Initialize controller for MeshGateway resource (#19552)
nathancoleman Nov 9, 2023
cb86b29
REPLAT-962 Update LICENSE text (#19574)
hc-github-team-es-release-engineering Nov 9, 2023
7699fb1
NET-5414: sameness group service show (#19586)
Nov 9, 2023
5ba42b4
Integ test - use asserter (#19597)
huikang Nov 9, 2023
4d64ef0
ui: move queries for selectors within the dropdowns (#19594)
Nov 10, 2023
005e1b9
added exported svc controller (#19589)
aahel Nov 10, 2023
68e7f27
[NET-6438] Add tenancy to xDS Tests (#19551)
kkavish Nov 10, 2023
b2979f6
testing/deployer: rename various terms to better align with v2 and av…
rboyer Nov 10, 2023
af2086f
docs: Fix nav link for L7 traffic (#19606)
boruszak Nov 10, 2023
b21851c
test: add test helper to detect if the current build is enterprise (#…
rboyer Nov 13, 2023
219283d
unhack: fix broken `make lint` on macbooks (#19611)
analogue Nov 13, 2023
5253966
DNS token doc updates (#19592)
johnlanda Nov 13, 2023
c302ffb
[NET-6232] docs: Update consul-k8s Helm chart docs (#19577)
zalimeni Nov 13, 2023
bcf6f62
Fix parts of admin-partitions guide (#19621)
Nov 14, 2023
2ff6ab1
fix runner count logic in set_test_package_matrix.sh from adding an a…
jmurret Nov 14, 2023
c835c90
[Docs] Update admin-partitions.mdx (#18430)
am-ak Nov 14, 2023
dc42429
Fix ACL permissions for ECS controller (#19636)
Ganeshrockz Nov 14, 2023
c7307ca
unhack: remove consulprem build tag (#19633)
analogue Nov 14, 2023
9ca62aa
Adds proto for the GatewayClass based on the GAMMA Kubernetes Sig (#1…
missylbytes Nov 14, 2023
bc26fbc
notify on go-tests failure on main and release branches. (#19640)
jmurret Nov 15, 2023
fbc2a58
NET 6442 - Add tenancy to explicit destinations controller (#19644)
absolutelightning Nov 15, 2023
4434613
NET 6525 (#19645)
absolutelightning Nov 15, 2023
d68a23a
NET 6539 - Add tenancy tests for folder - internal/mesh/internal/cont…
absolutelightning Nov 15, 2023
4ab7ada
upgrade test: remove duplicate test case (#19643)
huikang Nov 15, 2023
7628fed
Updates GatewayClass protobuf to set optional fields to optional (#19…
missylbytes Nov 15, 2023
2e28aec
Added tenancy tests for endpoints controller (#19650)
Ganeshrockz Nov 15, 2023
4020c00
Add tenancy tests for proxy cfg controller (#19649)
Ganeshrockz Nov 15, 2023
da8700f
test: fix some multiport deployer bugs and remove a container test al…
rboyer Nov 15, 2023
4f929f8
unhack: add pre-commit guidelines (#19617)
analogue Nov 15, 2023
1eed205
resource: freeze resources after marked for deletion (4 of 5) (#19603)
analogue Nov 15, 2023
29042b2
NET-6550 generate stubs for GatewayClassConfig (#19602)
sarahalsmiller Nov 15, 2023
5e5701e
Timeout Docs Update (#19601)
sarahalsmiller Nov 15, 2023
2591318
Skip tests with p95 greater than 30 seconds outside of main and relea…
jmurret Nov 15, 2023
04a3a3e
Integ test (test/deployer): upgrade test with service mesh (#19658)
huikang Nov 16, 2023
0c67543
Added Gatewayclassconfig resource type to proto package (#19664)
sarahalsmiller Nov 16, 2023
d9432f9
Add stub for MeshConfiguration proto (#19642)
Nov 16, 2023
ea0caa3
[NET-6103] Enable query tokens by service name using templated policy…
roncodingenthusiast Nov 16, 2023
ecfeb7a
Integ test: enable upgrade test deployer 1.17 (#19669)
huikang Nov 16, 2023
c061168
Add tests for traffic permissions controller (#19672)
Ganeshrockz Nov 17, 2023
75c2def
resource: preserve deferred deletion metadata on non-CAS writes (#19674)
analogue Nov 17, 2023
ce66433
integ-test: fix upgrade test for CE (#19673)
huikang Nov 17, 2023
d05f67c
Add engineering docs for controllers and v2 architecture (#19671)
ishustava Nov 18, 2023
4dcbacf
fix: temporary remove token policy test (#19683)
valeriia-ruban Nov 18, 2023
b45a6a3
Update ECS compat matrix (#19675)
Ganeshrockz Nov 19, 2023
0058045
fix: remove 2 tests to unblock consul-enterprise merges (#19687)
valeriia-ruban Nov 20, 2023
302f994
[NET-6640] Adds "Policy" BindType to BindingRule (#19499)
mikenomitch Nov 20, 2023
415491f
[NET-6640] Add docs for binding type policy (#19677)
roncodingenthusiast Nov 20, 2023
f027d61
fix a panic in the CLI when deleting an acl policy with an unknown na…
dhiaayachi Nov 20, 2023
2f9bc5b
Switch to github-actions format (#19667)
Nov 20, 2023
5d7b117
Switch to github-actions format for integration tests (#19693)
Nov 20, 2023
d7323ca
do not auto merge backports (#19694)
dhiaayachi Nov 20, 2023
bfb3a43
Default "stats_flush_interval" to 1 minute for Consul Telemetry Colle…
Achooo Nov 20, 2023
58cc6ed
[SECVULN-1532] chore: Remove TODO comments for OIDC/JWT auth (#19700)
zalimeni Nov 20, 2023
a28f4b7
optimized fetching services in exported service controller (#19695)
aahel Nov 21, 2023
8a89465
[SECVULN-1533] chore: Clarify iptables Provider interface docs (#19704)
zalimeni Nov 21, 2023
d3bf47f
cli: add a string method to gvk struct (#19696)
huikang Nov 21, 2023
f69c68e
chore: add suffix to consul version in sidenav (#19660)
valeriia-ruban Nov 21, 2023
0fdc2ac
v2tenancy: namespace deletion using finalizers (#19714)
analogue Nov 22, 2023
ba24225
Add tenancy tests for routes controller (#19706)
Ganeshrockz Nov 22, 2023
7cf48bc
Fix failing test in command/resource/read (#19722)
analogue Nov 22, 2023
8fe0bd1
Add docs for identity acl rules (#19713)
Nov 22, 2023
78f918a
feat: create a default namespace (#19681)
JadhavPoonam Nov 22, 2023
c1dbf00
NET-6251 API gateway templated policy (#19728)
roncodingenthusiast Nov 24, 2023
eded2ff
[NET-6249] Add templated policies description (#19735)
roncodingenthusiast Nov 27, 2023
cc14ccf
[NET-6617] security: Bump github.com/golang-jwt/jwt/v4 to 4.5.0 (#19705)
zalimeni Nov 27, 2023
3f0a752
Adds GatewayClassName field to MeshGateway Proto (#19738)
missylbytes Nov 27, 2023
5930748
resource: ListByOwner returns empty list on non-existent tenancy (#19…
analogue Nov 27, 2023
af27121
add nightly integ tests for peering_commontopo [NET-6628] (#19724)
nfi-hashicorp Nov 27, 2023
2732376
ci: Run `go mod tidy` check on submodules (#19744)
zalimeni Nov 27, 2023
991dfff
added ent to ce downgrade doc (#19590)
aahel Nov 28, 2023
5107764
Move test setup out of subtest (#19753)
Nov 28, 2023
419677c
[NET-6420] Add MeshConfiguration Controller stub (#19745)
Nov 28, 2023
9dc2444
grpc client default in plaintext mode (#19412)
xwa153 Nov 28, 2023
66306a8
[NET-5916] docs: Add locality examples and troubleshooting (#19605)
zalimeni Nov 28, 2023
39136f4
license file updates (#19750)
hc-github-team-es-release-engineering Nov 28, 2023
fd1d97c
Add Kubebuilder tags to Gatewayclassconfig proto messages (#19725)
sarahalsmiller Nov 28, 2023
a0240e3
[NET-5688] APIGateway UI Topology Fixes (#19657)
jm96441n Nov 28, 2023
d1f2fa1
[NET-6725] test: Address occasional flakes in sidecarproxy/controller…
zalimeni Nov 29, 2023
54f13eb
docs: Rename locality docs observe section to verification (#19769)
zalimeni Nov 29, 2023
69b1d20
[V2] Move resource field on gateway class config from repeated map to…
jm96441n Nov 29, 2023
790cb30
Docs: FIPS - add cluster peering info (#19768)
Jeff-Apple Nov 29, 2023
8f7f15e
Pin lint-consul-retry to v1.3.0 (#19781)
mkeeler Nov 29, 2023
2d1f308
resource: add v2tenancy feature flag to deployer tests (#19774)
analogue Nov 30, 2023
2eebdb2
Remove Duplicate UBI Tags (#19737)
emilymianeil Nov 30, 2023
c9f85eb
NET-6692: Ensure 'upload test results' step is always run (#19783)
ksmanoj Dec 1, 2023
ac9261a
made node parition scoped (#19794)
aahel Dec 1, 2023
82f6a8d
Net 6585 (#19797)
absolutelightning Dec 1, 2023
65c06f6
docs: improvements to v2 catalog explanation (#19678)
boruszak Dec 1, 2023
7936e55
added node health resource (#19803)
aahel Dec 2, 2023
edf4610
[Cloud][CC-6925] Updates to pushing server state (#19682)
lornasong Dec 4, 2023
649aa56
skip TestCatalogUpgrade for consul versions < 1.18.0 (#19811)
aahel Dec 4, 2023
aca8a18
ci: fix test failure Slack notifications (#19766)
zalimeni Dec 5, 2023
c1bbda8
resource: block default namespace deletion + test refactorings (#19822)
analogue Dec 5, 2023
b5edf5c
doc: clarify the portNames used in trafficpermission V2 (#19807)
huikang Dec 5, 2023
6c88122
NET-3860 - [Supportability] consul troubleshoot CLI for verifying por…
absolutelightning Dec 6, 2023
334de14
update l7expplicit dest test to test cross tenancy (#19834)
aahel Dec 6, 2023
dc02fa6
[NET-6251] Nomad client templated policy (#19827)
roncodingenthusiast Dec 6, 2023
efe279f
Retry lint fixes (#19151)
mkeeler Dec 6, 2023
d3e658b
improve client RPC metrics consistency (#19721)
jkirschner-hashicorp Dec 6, 2023
053367a
[NET-6650] Bump go version to 1.20.12 (#19840)
roncodingenthusiast Dec 6, 2023
04d4412
NET-6643: upgrade test from 1.10 to 1.15 (lts) of a single cluster (#…
huikang Dec 6, 2023
3a78446
ci: fix escaping for Slack failure notifications (#19838)
zalimeni Dec 6, 2023
ab68ddf
NET-6784: Adding cli command to list exported services to a peer (#19…
tauhid621 Dec 7, 2023
645cbf9
chore: update changelog for patch releases (#19855)
zalimeni Dec 7, 2023
06b3038
Net-6730/namespace intg test (#19798)
JadhavPoonam Dec 7, 2023
bfad6a4
Ensure that the default namespace always exists even prior to resourc…
mkeeler Dec 7, 2023
d93f7f7
parse config protocol on write to optimize disco-chain compilation (#…
dhiaayachi Dec 7, 2023
8125a32
Add CE version of Gateway Upstream Disambiguation (#19860)
Dec 7, 2023
d4fda94
Fix a test flake where a retry timer was being reused causing tests a…
mkeeler Dec 8, 2023
0ca070b
upgrade test(LTS): add segments to version 1.10 (#19861)
huikang Dec 8, 2023
0ac958f
Fix xDS missing endpoint race condition. (#19866)
hashi-derek Dec 8, 2023
1d9234a
ci: sanitize commit message for Slack failure alerts (#19876)
zalimeni Dec 8, 2023
5ec84db
security: update supported envoy version 1.28.0 in addition to 1.25.1…
jmurret Dec 8, 2023
dfab5ad
Fix ClusterLoadAssignment timeouts dropping endpoints. (#19871)
hashi-derek Dec 11, 2023
195e3aa
[NET-6842] splitting go version on different lines (#19887)
roncodingenthusiast Dec 11, 2023
ccb2bf6
Add documentation for proxy-config-map and xds_fetch_timeout_ms. (#19…
hashi-derek Dec 11, 2023
659868e
docs: Updates to required ports (#19755)
boruszak Dec 11, 2023
e13fbc7
Remove warning for consul 1.17 deprecation (#19897)
roncodingenthusiast Dec 11, 2023
a6d6164
fix: remove test to unblock CI (#19908)
valeriia-ruban Dec 12, 2023
c5cce63
NET 6761 (#19837)
absolutelightning Dec 12, 2023
1484c6d
NET-6771 - Adding sameness group protobuff in consul CE (#19883)
tauhid621 Dec 12, 2023
173fe11
Refactor exported services controller tests (#19906)
Ganeshrockz Dec 12, 2023
9001058
Move enterprise multicluster types to Register function (#19913)
Ganeshrockz Dec 12, 2023
f2b26ac
Hash based config entry replication (#19795)
dhiaayachi Dec 12, 2023
e8164c7
NET-6900: stop reconciling services when peering is enabled (#19907)
Dec 12, 2023
d7e0fca
fix: token list in Role details page is updated with tokens linked to…
valeriia-ruban Dec 12, 2023
a5d5fd3
fix actions to no longer use envoy 1.24.x to match supported versions…
jmurret Dec 12, 2023
69e3f93
resource: add partition resource to proto-public to keep ENT and CE i…
analogue Dec 12, 2023
c870c00
docs: service rate limiting examples (#19925)
boruszak Dec 12, 2023
123bc95
Add Common Controller Caching Infrastructure (#19767)
mkeeler Dec 13, 2023
3443db7
NET 6762 (#19931)
absolutelightning Dec 14, 2023
33a90ed
Upgrade test(LTS): use network area to federate cluster (#19934)
huikang Dec 14, 2023
a649689
added tenancy to TestBuildL4TrafficPermissions (#19932)
aahel Dec 14, 2023
0250e23
NET-6785: updating peering docs to include stream status and remote d…
tauhid621 Dec 14, 2023
afc6fe8
Update telemetry.mdx RPC Metrics (#19593)
natemollica-nm Dec 14, 2023
a995505
NET-6317 - update usage of deprecated fields: http2_protocol_options …
jmurret Dec 14, 2023
83cbe15
cli: Deprecate the `-admin-access-log-path` flag from `consul connect…
jmurret Dec 14, 2023
02d4520
Fix typo in service-defaults documentation (#19957)
nathancoleman Dec 14, 2023
79e02f8
ci: upload test results to DataDog on test failure (#19956)
zalimeni Dec 14, 2023
bbdbf3e
Fix bug with prepared queries using sameness-groups. (#19970)
hashi-derek Dec 15, 2023
cae2382
update changelog (#19966)
xwa153 Dec 15, 2023
ae998a6
added computed failover policy resource (#19975)
aahel Dec 18, 2023
de86ba7
docs: typo formatting consul-k8s docs (#19973)
Dec 18, 2023
010bf53
NET-6663 Modify sidecarproxy controller to skip xGateway resources (#…
nathancoleman Dec 18, 2023
f1dee1a
Net 6603 (#19718)
absolutelightning Dec 18, 2023
a3fa683
docs: Update network segments in compat matrix for Enterprise feature…
Dec 18, 2023
4e451f2
NET 6409 (#19515)
absolutelightning Dec 18, 2023
cff8727
agent: prevent empty server_metadata.json (#19935)
huikang Dec 19, 2023
013bcef
grpc client in tls mode (#19680)
xwa153 Dec 19, 2023
9975b8b
[NET-5455] Allow disabling request and idle timeouts with negative va…
ndhanushkodi Dec 19, 2023
a87ab8b
feat: updated github checks with frontend-test-ce end frontend-test-e…
valeriia-ruban Dec 20, 2023
54c38e5
Update Dockerfile
Dec 21, 2023
f7e0144
backport of commit 54c38e55e03460f7f105b7feb4526554e870625b
Dec 21, 2023
c53e909
backport of commit 0f79688848b29854b8e36e3b5df09520ea39035c
Dec 21, 2023
489bcfb
backport of commit ac3cfc3ed3e3160e49d69fca5c6af81fee23b91a
Dec 21, 2023
8c7fd5f
Merge 54c38e55e03460f7f105b7feb4526554e870625b into backport/dyu/ubi/…
hc-github-team-consul-core Dec 21, 2023
0ce628f
backport of commit 7a446d30e803b871631d027c73c908c4de8b501e
Dec 21, 2023
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
6 changes: 0 additions & 6 deletions .changelog/18994.txt
Original file line number Diff line number Diff line change
Expand Up @@ -12,12 +12,6 @@ environments.
* The v1 and v2 catalog APIs cannot run concurrently.
* The Consul UI does not support multi-port services or the v2 catalog API in this release.
* HCP Consul does not support multi-port services or the v2 catalog API in this release.
* The v2 API only supports transparent proxy mode where services that have permissions to connect to each other can use
Kube DNS to connect.

### Known Issues
* When using the v2 API with transparent proxy, Kubernetes pods cannot use L7 liveness, readiness, or startup probes.


[[Catalog resource controllers]](https://github.com/hashicorp/consul/tree/e6b724d06249d3e62cd75afe3ee6042ba1fd5415/internal/catalog/internal/controllers)
[[Mesh resource controllers]](https://github.com/hashicorp/consul/tree/e6b724d06249d3e62cd75afe3ee6042ba1fd5415/internal/mesh/internal/controllers)
Expand Down
9 changes: 9 additions & 0 deletions .changelog/19225.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
```release-note:security
Upgrade Go to 1.20.10.
This resolves vulnerability [CVE-2023-39325](https://nvd.nist.gov/vuln/detail/CVE-2023-39325)
/ [CVE-2023-44487](https://nvd.nist.gov/vuln/detail/CVE-2023-44487)(`net/http`).
```
```release-note:security
Update `golang.org/x/net` to v0.17.0 to address [CVE-2023-39325](https://nvd.nist.gov/vuln/detail/CVE-2023-39325)
/ [CVE-2023-44487](https://nvd.nist.gov/vuln/detail/CVE-2023-44487)(`x/net/http2`).
```
3 changes: 3 additions & 0 deletions .changelog/19268.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
Mesh Gateways: Fix a bug where replicated and peered mesh gateways with hostname-based WAN addresses fail to initialize.
```
3 changes: 3 additions & 0 deletions .changelog/19274.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:security
connect: update supported envoy versions to 1.24.12, 1.25.11, 1.26.6, 1.27.2 to address [CVE-2023-44487](https://github.com/envoyproxy/envoy/security/advisories/GHSA-jhv4-f7mr-xx76)
```
7 changes: 7 additions & 0 deletions .changelog/19285.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
```release-note:bug
ca: Fix bug with Vault CA provider where token renewal goroutines could leak if CA failed to initialize.
```

```release-note:bug
ca: Fix bug with Vault CA provider where renewing a retracted token would cause retries in a tight loop, degrading performance.
```
3 changes: 3 additions & 0 deletions .changelog/19314.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:enhancement
raft: upgrade raft-wal library version to 0.4.1.
```
4 changes: 4 additions & 0 deletions .changelog/19339.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
```release-note:bug
connect: Fix bug where uncleanly closed xDS connections would influence connection balancing for too long and prevent envoy instances from starting. Two new configuration fields
`performance.grpc_keepalive_timeout` and `performance.grpc_keepalive_interval` now exist to allow for configuration on how often these dead connections will be cleaned up.
```
3 changes: 3 additions & 0 deletions .changelog/19342.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:improvement
Replaces UI Side Nav with Helios Design System Side Nav. Adds dc/partition/namespace searching in Side Nav.
```
3 changes: 3 additions & 0 deletions .changelog/19389.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:improvement
cli: stop simultaneous usage of -templated-policy and -templated-policy-file when creating a role or token.
```
4 changes: 4 additions & 0 deletions .changelog/19414.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
```release-note:security
Upgrade `google.golang.org/grpc` to 1.56.3.
This resolves vulnerability [CVE-2023-44487](https://nvd.nist.gov/vuln/detail/CVE-2023-44487).
```
3 changes: 3 additions & 0 deletions .changelog/19503.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
wan-federation: Fix a bug where servers wan-federated through mesh-gateways could crash due to overlapping LAN IP addresses.
```
3 changes: 3 additions & 0 deletions .changelog/19549.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
ui: clear peer on home logo link
```
3 changes: 3 additions & 0 deletions .changelog/19586.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
ui: fix being able to view peered services from non-default namnespaces
```
3 changes: 3 additions & 0 deletions .changelog/19594.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:improvement
ui: move nspace and partitions requests into their selector menus
```
3 changes: 3 additions & 0 deletions .changelog/19663.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:improvement
connect: Default `stats_flush_interval` to 60 seconds when using the Consul Telemetry Collector, unless custom stats sink are present or an explicit flush interval is configured.
```
3 changes: 3 additions & 0 deletions .changelog/19666.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:improvement
api: Add support for listing ACL tokens by service name when using templated policies.
```
3 changes: 3 additions & 0 deletions .changelog/19679.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
CLI: fix a panic when deleting a non existing policy by name.
```
3 changes: 3 additions & 0 deletions .changelog/19682.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:improvement
cloud: push additional server TLS metadata to HCP
```
3 changes: 3 additions & 0 deletions .changelog/19705.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:security
Update `github.com/golang-jwt/jwt/v4` to v4.5.0 to address [PRISMA-2022-0270](https://github.com/golang-jwt/jwt/issues/258).
```
6 changes: 6 additions & 0 deletions .changelog/19721.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
```release-note:improvement
metrics: modify consul.client.rpc metric to exclude internal retries for consistency with consul.client.rpc.exceeded and consul.client.rpc.failed
```
```release-note:improvement
metrics: increment consul.client.rpc.failed if RPC fails because no servers are accessible
```
3 changes: 3 additions & 0 deletions .changelog/19728.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:improvement
acl: add api-gateway templated policy
```
3 changes: 3 additions & 0 deletions .changelog/19735.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:improvement
acl: add templated policy descriptions
```
3 changes: 3 additions & 0 deletions .changelog/19795.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:enhancement
wan-federation: use a hash to diff config entries when replicating in the secondary DC to avoid unnecessary writes..
```
3 changes: 3 additions & 0 deletions .changelog/19821.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:feature
cli: Adds new subcommand `peering exported-services` to list services exported to a peer . Refer to the [CLI docs](https://developer.hashicorp.com/consul/commands/peering) for more information.
```
3 changes: 3 additions & 0 deletions .changelog/19827.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:feature
acl: Adds nomad client templated policy
```
3 changes: 3 additions & 0 deletions .changelog/19829.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:enhancement
mesh: parse the proxy-defaults protocol when write the config-entry to avoid parsing it when compiling the discovery chain.
```
7 changes: 7 additions & 0 deletions .changelog/19840.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
```release-note:security
Upgrade to use Go 1.20.12. This resolves CVEs
[CVE-2023-45283](https://nvd.nist.gov/vuln/detail/CVE-2023-45283): (`path/filepath`) recognize \??\ as a Root Local Device path prefix (Windows)
[CVE-2023-45284](https://nvd.nist.gov/vuln/detail/CVE-2023-45285): recognize device names with trailing spaces and superscripts (Windows)
[CVE-2023-39326](https://nvd.nist.gov/vuln/detail/CVE-2023-39326): (`net/http`) limit chunked data overhead
[CVE-2023-45285](https://nvd.nist.gov/vuln/detail/CVE-2023-45285): (`cmd/go`) go get may unexpectedly fallback to insecure git
```
3 changes: 3 additions & 0 deletions .changelog/19860.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
connect: Solves an issue where two upstream services with the same name in different namespaces were not getting routed to correctly by API Gateways.
```
3 changes: 3 additions & 0 deletions .changelog/19866.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
xds: ensure child resources are re-sent to Envoy when the parent is updated even if the child already has pending updates.
```
3 changes: 3 additions & 0 deletions .changelog/19871.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
xds: Add configurable `xds_fetch_timeout_ms` option to proxy registrations that allows users to prevent endpoints from dropping when they have proxies with a large number of upstreams.
```
3 changes: 3 additions & 0 deletions .changelog/19907.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
ui: stop manually reconciling services if peering is enabled
```
3 changes: 3 additions & 0 deletions .changelog/19912.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
ui: update token list on Role details page to show only linked tokens
```
3 changes: 3 additions & 0 deletions .changelog/19940.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:improvement
xds: remove usages of deprecated Envoy fields: `envoy.config.cluster.v3.Cluster.http2_protocol_options`, `envoy.config.bootstrap.v3.Admin.access_log_path`
```
3 changes: 3 additions & 0 deletions .changelog/19943.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:deprecation
cli: Deprecate the `-admin-access-log-path` flag from `consul connect envoy` command in favor of: `-admin-access-log-config`.
```
3 changes: 3 additions & 0 deletions .changelog/20014.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:security
Upgrade OpenShift container images to use `ubi9-minimal:9.3` as the base image.
```
3 changes: 3 additions & 0 deletions .changelog/_7406.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
server: **(Enterprise Only)** Fixed an issue where snake case keys were rejected when configuring the control-plane-request-limit config entry
```
3 changes: 3 additions & 0 deletions .changelog/_7773.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
prepared-query: (Enterprise-only) Fix issue where sameness-group failover targets to peers would attempt to query data from the default partition, rather than the sameness-group's partition always.
```
2 changes: 1 addition & 1 deletion .github/scripts/set_test_package_matrix.sh
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,6 @@ set -euo pipefail
export RUNNER_COUNT=$1

# set matrix var to list of unique packages containing tests
matrix="$(go list -json="ImportPath,TestGoFiles" ./... | jq --compact-output '. | select(.TestGoFiles != null) | .ImportPath' | jq --slurp --compact-output '.' | jq --argjson runnercount $RUNNER_COUNT -cM '[_nwise(length / $runnercount | floor)]'))"
matrix="$(go list -json="ImportPath,TestGoFiles" ./... | jq --compact-output '. | select(.TestGoFiles != null) | .ImportPath' | shuf | jq --slurp --compact-output '.' | jq --argjson runnercount $RUNNER_COUNT -cM '[_nwise(length / $runnercount | floor)]'))"

echo "matrix=${matrix}" >> "${GITHUB_OUTPUT}"
14 changes: 9 additions & 5 deletions .github/scripts/verify_envoy_version.sh
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@

set -euo pipefail

current_branch=$GITHUB_REF
current_branch=$GITHUB_REF_NAME
GITHUB_DEFAULT_BRANCH='main'

if [ -z "$GITHUB_TOKEN" ]; then
Expand All @@ -13,10 +13,15 @@ if [ -z "$GITHUB_TOKEN" ]; then
fi

if [ -z "$current_branch" ]; then
echo "GITHUB_REF must be set"
echo "GITHUB_REF_NAME must be set"
exit 1
fi

if [[ "$SKIP_VERIFY_ENVOY_VERSION" = "true" ]]; then
echo -e "*************** VERIFY ENVOY VERSION IS DISABLED. To enable, update environment variable in Github settings *****************"
exit 0
fi

# Get Consul and Envoy version
SCRIPT_DIR="$( cd -- "$(dirname "$0")" >/dev/null 2>&1 ; pwd -P )"
pushd $SCRIPT_DIR/../.. # repository root
Expand Down Expand Up @@ -76,7 +81,6 @@ released_envoy_version=$(get_latest_envoy_version)
major_released_envoy_version="${released_envoy_version[@]:1:4}"

validate_envoy_version_main(){
echo "verify "main" GitHub branch has latest envoy version"
# Get envoy version for current branch
ENVOY_VERSIONS=$(sanitize_consul_envoy_version | awk '{print $2}' | tr ',' ' ')
envoy_version_main_branch=$(get_major_version ${ENVOY_VERSIONS})
Expand Down Expand Up @@ -118,8 +122,8 @@ echo checking out branch: "${current_branch}"
git checkout "${current_branch}"

echo
echo "Branch ${current_branch} =>Consul version: ${CONSUL_VERSION}; Envoy Version: ${ENVOY_VERSIONS}"
echo "Branch ${GITHUB_DEFAULT_BRANCH} =>Consul version: ${CONSUL_VERSION_DEFAULT_BRANCH}; Envoy Version: ${ENVOY_VERSIONS_DEFAULT_BRANCH}"
echo "Branch ${current_branch} => Consul version: ${CONSUL_VERSION}; Envoy Version: ${ENVOY_VERSIONS}"
echo "Branch ${GITHUB_DEFAULT_BRANCH} => Consul version: ${CONSUL_VERSION_DEFAULT_BRANCH}; Envoy Version: ${ENVOY_VERSIONS_DEFAULT_BRANCH}"

## Get major Consul and Envoy versions on release and default branch
MAJOR_CONSUL_VERSION=$(get_major_version ${CONSUL_VERSION})
Expand Down
Loading
Loading