Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Backport of [CC-5718] Remove HCP token requirement during bootstrap into release/1.14.x #18227

Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
1114 commits
Select commit Hold shift + click to select a range
17f06b8
upgrade test: fix on-the-fly-image build and downsize runner (#17331)
huikang May 15, 2023
d37572b
Add a Node health controller (#17214)
mkeeler May 15, 2023
abeccb4
Support update resource with change in GroupVersion (#17330)
analogue May 15, 2023
be7d2a4
fix(connect envoy): set initial_fetch_timeout to wait for initial xDS…
DanStough May 15, 2023
70ed184
counterpart of the ent in oss (#17367)
xwa153 May 15, 2023
59db5e1
integ-test CI: retry if fail to install packages (#17359)
huikang May 15, 2023
8dee353
agent: don't write server metadata in dev mode (#17383)
loshz May 16, 2023
06481bf
test: fix oss/ent drift in gateway container tests (#17365)
rboyer May 16, 2023
0789661
Rename hcp-metrics-collector to consul-telemetry-collector (#17327)
clly May 16, 2023
8f6b9fe
Add ACLs Enabled field to consul agent startup status message (#17086)
johnlanda May 16, 2023
2f5256e
test: slight refactoring ahead of peering testing improvements (#17387)
rboyer May 16, 2023
21c6e0e
fix two typos (#17389)
rboyer May 17, 2023
2904d0a
Pull virtual IPs for filter chains from discovery chains (#17375)
kyhavlov May 17, 2023
1339c79
consul-container test: no splitting and on single runner (#17394)
huikang May 17, 2023
94ea0a9
Docs/igw docs day refactor (#17259)
trujillo-adam May 17, 2023
bd5a3c1
docs: Reference pages for service-router and service-resolver config …
boruszak May 17, 2023
a152e0e
Add changelog entries for Consul 1.13.8 + 1.14.7 (#17399)
nathancoleman May 17, 2023
d20e3df
updates to links in services overview description paragraph (#17406)
trujillo-adam May 18, 2023
1d6a0c8
Add the workload health controller (#17215)
mkeeler May 19, 2023
134aac7
xds: generate endpoints directly from API gateway snapshot (#17390)
sarahalsmiller May 19, 2023
113202d
JWT Authentication with service intentions: xds package update (#17414)
roncodingenthusiast May 19, 2023
93bad3e
Allow resource updates to omit an owner refs UID (#17423)
mkeeler May 22, 2023
d34bde0
xds: generate clusters directly from API gateway snapshot (#17391)
sarahalsmiller May 22, 2023
e00280e
prototest: fix early return condition in AssertElementsMatch (#17416)
rboyer May 22, 2023
e2a81aa
xds: generate listeners directly from API gateway snapshot (#17398)
sarahalsmiller May 22, 2023
b8d2640
Disable remote proxy patching except AWS Lambda (#17415)
zalimeni May 23, 2023
7f4fd27
Only synthesize anonymous token in primary DC (#17231)
May 23, 2023
f0ba3f4
Integration test for permissive mTLS (#17205)
May 23, 2023
304d641
extract some config entry helpers into package (#17434)
rboyer May 23, 2023
f526dfd
add necessary plumbing to implement per server ip based rate limiting…
dhiaayachi May 23, 2023
d935c7b
[OSS] gRPC Blocking Queries (#17426)
DanStough May 23, 2023
ddb25ce
[NET-3092] Improve jwt-provider tests (#17430)
roncodingenthusiast May 24, 2023
f9d1451
docs: first pass at a resource/controller developer guide (#17395)
boxofrad May 24, 2023
b74e41e
Update service-intentions.mdx (#17443)
lkysow May 24, 2023
0420b97
support ent debug mode (#17411)
xwa153 May 24, 2023
07ff9d3
Use original_dst filter instead of use_original_dst field (#17433)
May 24, 2023
7166582
CI: upload test results to datadog (#17438)
huikang May 24, 2023
b8eb98f
CI: do not upload test metrics to datadog on forks (#17448)
jmurret May 24, 2023
e2f15cf
Fix namespaced peer service updates / deletes. (#17456)
hashi-derek May 24, 2023
a90c9ce
Fix ACL check on health endpoint (#17424)
hashi-derek May 24, 2023
7a8f33f
chore(ci): skip cache for lint workflow (#17459)
DanStough May 25, 2023
6d35edc
xds: generate routes directly from API gateway snapshot (#17392)
sarahalsmiller May 25, 2023
127eba6
docs: update the defaults for request limits (#17437)
jmurret May 25, 2023
b147323
xds: Remove APIGateway ToIngress function (#17453)
sarahalsmiller May 25, 2023
9327f85
Update common-errors.mdx (#17467)
lkysow May 25, 2023
1c80892
fix tproxy sameness groups (#17468)
erichaberkorn May 25, 2023
17a280d
This fixes an issue where TCP services that are exported cannot be co…
erichaberkorn May 25, 2023
c7bb365
add docs for consul-k8s config read command (#17461)
hanshasselberg May 25, 2023
720dda7
Update index.mdx (#17477)
lkysow May 25, 2023
7177aad
ci: update backport assistant to 0.3.4 (#17486)
jmurret May 26, 2023
3605fde
perf: Remove expensive reflection from raft/mesh hot path (#16552)
lstoll May 26, 2023
2740d12
ENT->OSS merge for Consolidate `ListEnvoyExtender` into `BasicEnvoyEx…
cthain May 26, 2023
516eb4f
Add `builtin/ext-authz` Envoy Extension (#17495)
cthain May 26, 2023
5a46a8c
Add `builtin/property-override` Envoy Extension (#17487)
zalimeni May 26, 2023
e1df0f2
Support `Listener` and `ClusterLoadAssignment` in `property-override`…
zalimeni May 29, 2023
0944f71
fips oss version changes (#17500)
skpratt May 29, 2023
091925b
HCP Telemetry Feature (#17460)
Achooo May 29, 2023
65b8ccd
Enable Network filters for Wasm Envoy Extension (#17505)
cthain May 30, 2023
b74e87b
remove deprecated set-output calls in gha (#17494)
modrake May 30, 2023
bc9bb99
build(deps): update UBI base image to 9.2 (#17513)
DanStough May 30, 2023
55e283d
[NET-3092] JWT Verify claims handling (#17452)
roncodingenthusiast May 30, 2023
85cfec6
Add safety checks for the client telemetry gateway payload in case it…
Achooo May 30, 2023
44f9013
hoststats: add package for collecting host statistics including cpu m…
nickethier May 30, 2023
d99312b
Add Upstream Service Targeting to Property Override Extension (#17517)
erichaberkorn May 30, 2023
04a0d01
fix isServer to exclude local address (#17519)
dhiaayachi May 30, 2023
e559c59
Add version endpoint (#17506)
skpratt May 30, 2023
a46ac4b
FIPS gossip changes (#17507)
skpratt May 30, 2023
fdda7ad
issue a warning if major FIPS assumptions are broken (#17524)
skpratt May 31, 2023
b9c9d79
Accept ap, datacenter, and namespace query params (#17525)
jkirschner-hashicorp May 31, 2023
a065eef
add FIPS to dataplane features (#17522)
skpratt May 31, 2023
217248b
feat: expose logs method on container interface (#17526)
JadhavPoonam May 31, 2023
da94cbd
add changelog (#17528)
dhiaayachi May 31, 2023
b438a07
Export peering cli (#15654)
nathancoleman May 31, 2023
ba26e18
Fix tproxy failover issue with sameness groups (#17533)
hashi-derek May 31, 2023
ca12ce9
[API Gateway] Fix use of virtual resolvers in HTTPRoutes (#17055)
May 31, 2023
ad03a5d
Avoid panic applying TProxy Envoy extensions (#17537)
zalimeni Jun 1, 2023
a043981
Revert "fix(connect envoy): set initial_fetch_timeout to wait for ini…
DanStough Jun 1, 2023
7293e1a
docs: add note about Nomad support for Consul 1.13.8 (#17512)
lgfa29 Jun 1, 2023
d9e18b4
changelog: add changelog for reporting (#17535)
JadhavPoonam Jun 2, 2023
cf4059f
chore: fix the error message format (#17554)
huikang Jun 2, 2023
a55d368
Resolves issue-16844 - systemd notify by default (#16845)
drawks Jun 2, 2023
88951bf
add changelog entries for 1.15.3 (#17558)
Jun 2, 2023
4ddb88e
Fix up case where subscription is terminated due to ACLs changing or …
Jun 5, 2023
8617f8a
continue anti-entropy sync when failures exist (#17560)
Jun 5, 2023
caa044f
Generate helm docs for release consul-k8s 1.1.2 (#17568)
curtbushko Jun 5, 2023
77f44fa
Various bits of cleanup detected when using Go Workspaces (#17462)
mkeeler Jun 5, 2023
dd71bb8
docs: clarify the behavior of prepending hostname to metrics (#17521)
huikang Jun 5, 2023
f9d9d4d
Fix subscribing/fetching objects not in the default partition (#17581)
Jun 6, 2023
8e52d48
Add Prop Override Envoy extension integration test (#17569)
zalimeni Jun 6, 2023
7a2ee14
Fix metric names in Consul agent telemetry docs (#17577)
Jun 6, 2023
2dd5551
Fix Property Override Services parsing (#17584)
zalimeni Jun 6, 2023
a5ba889
Implement the service endpoints controller (#17216)
mkeeler Jun 6, 2023
a35cafa
update tests for fips (#17592)
skpratt Jun 7, 2023
39d4aaf
fix rate limiting mapping to be the same between api and struct packa…
dhiaayachi Jun 7, 2023
820cdf5
fix some testing.T retry.R mixups (#17600)
rboyer Jun 7, 2023
1db02a0
Disable terminating-gateway for property-override (#17605)
zalimeni Jun 7, 2023
1e920a7
[OSS] Post Consul 1.16 updates (#17606)
zalimeni Jun 7, 2023
8118aae
Add writeAuditRPCEvent to agent_oss (#17607)
roncodingenthusiast Jun 7, 2023
779647b
Add Envoy and Consul version constraints to Envoy extensions (#17612)
erichaberkorn Jun 8, 2023
9a4f503
[API Gateway] Fix trust domain for external peered services in synthe…
Jun 8, 2023
17f4689
backport ent changes to oss (#17614)
roncodingenthusiast Jun 8, 2023
8598288
Update intentions.mdx (#17619)
lkysow Jun 8, 2023
7ae457c
enterprise changelog update for audit (#17625)
roncodingenthusiast Jun 8, 2023
30e0c23
Update list of Envoy versions (#17546)
zalimeni Jun 9, 2023
3cb7056
[API Gateway] Fix rate limiting for API gateways (#17631)
Jun 9, 2023
ec347ef
sort some imports that are wonky between oss and ent (#17637)
rboyer Jun 9, 2023
5e84674
PmTLS and tproxy improvements with failover and L7 traffic mgmt for k…
trujillo-adam Jun 10, 2023
b1d3ec0
Delete check-legacy-links-format.yml (#17647)
Jun 12, 2023
809c188
docs: Reference doc updates for permissive mTLS settings (#17371)
Jun 12, 2023
baaf6d8
Add generic experiments configuration and use it to enable catalog v2…
mkeeler Jun 12, 2023
1074252
api-gateway: stop adding all header filters to virtual host when gene…
nathancoleman Jun 12, 2023
f8d3721
fix: add agent info reporting log (#17654)
JadhavPoonam Jun 12, 2023
862e78f
Add new Consul 1.16 docs (#17651)
im2nguyen Jun 12, 2023
c04c122
Default `ProxyType` for builtin extensions (#17657)
cthain Jun 12, 2023
446a640
Post 1.16.0-rc1 updates (#17663)
zalimeni Jun 12, 2023
290ba0e
Update service-defaults.mdx (#17656)
ramramhariram Jun 12, 2023
ef77f9a
docs: Sameness Groups (#17628)
boruszak Jun 12, 2023
c384f24
Remove "BETA" marker from config entries (#17670)
Jun 12, 2023
27206d9
CAPIgw for K8s installation updates for 1.16 (#17627)
trujillo-adam Jun 12, 2023
b678742
additional feedback on API gateway upgrades (#17677)
trujillo-adam Jun 12, 2023
66704e5
docs: JWT Authorization for intentions (#17643)
boruszak Jun 12, 2023
37a13dc
docs: minor fixes to JWT auth docs (#17680)
boruszak Jun 12, 2023
28d81ec
Fix two WAL metrics in docs/agent/telemetry.mdx (#17593)
Jun 12, 2023
0ddafcf
updated failover for k8s w-tproxy page title (#17683)
trujillo-adam Jun 13, 2023
3a8fc61
Add release notes 1.16 rc (#17665)
im2nguyen Jun 13, 2023
421e9d8
fix release notes links (#17687)
im2nguyen Jun 13, 2023
11764a4
adding redirects for tproxy and envoy extensions (#17688)
trujillo-adam Jun 13, 2023
4b843ae
Fix FIPS copy (#17691)
im2nguyen Jun 13, 2023
d54d5fb
[NET-4107][Supportability] Log Level set to TRACE and duration set to…
absolutelightning Jun 13, 2023
a8f1350
ENT merge of ext-authz extension updates (#17684)
cthain Jun 13, 2023
ddce431
docs: Update default values for Envoy extension proxy types (#17676)
cthain Jun 13, 2023
bba5cd8
fix: stop peering delete routine on leader loss (#17483)
DanStough Jun 13, 2023
0a1efe7
Refactor disco chain prioritize by locality structs (#17696)
erichaberkorn Jun 13, 2023
72f991d
agent: remove agent cache dependency from service mesh leaf certifica…
rboyer Jun 13, 2023
0c15748
[core]: Pin github action workflows (#17695)
curtbushko Jun 13, 2023
d497623
docs: missing changelog for _5517 (#17706)
DanStough Jun 13, 2023
ab909b4
add enterprise notes for IP-based rate limits (#17711)
trujillo-adam Jun 13, 2023
28647ef
Update compatibility.mdx (#17713)
Jun 13, 2023
9acbe76
Remove extraneous version info for Config entries (#17716)
Jun 13, 2023
8d9f2eb
fix: typo in link to section (#17527)
tcraxs Jun 14, 2023
212e090
Bump Alpine to 3.18 (#17719)
Jun 14, 2023
6a90c23
NET-1825: New ACL token creation docs (#16465)
Jun 14, 2023
fa40654
[NET-3865] [Supportability] Additional Information in the output of '…
absolutelightning Jun 14, 2023
9289e68
OSS merge: Update error handling login when applying extensions (#17740)
cthain Jun 14, 2023
abb05de
Bump atlassian/gajira-transition from 3.0.0 to 3.0.1 (#17741)
dependabot[bot] Jun 14, 2023
7ab287c
Add truncation to body (#17723)
chapmanc Jun 14, 2023
a633347
docs: Failover overview minor fix (#17743)
boruszak Jun 14, 2023
37bd0e1
docs - update Envoy and Dataplane compat matrix (#17752)
Jun 15, 2023
0994ccf
validate localities on agent configs and registration endpoints (#17712)
erichaberkorn Jun 15, 2023
fdde92c
Updated docs added explanation. (#17751)
absolutelightning Jun 15, 2023
0e9a012
Update index.mdx (#17749)
lkysow Jun 15, 2023
7dec75f
added redirects and updated links (#17764)
trujillo-adam Jun 15, 2023
8c74a1d
Add transparent proxy enhancements changelog (#17757)
hashi-derek Jun 15, 2023
ad0a277
docs - remove use of consul leave during upgrade instructions (#17758)
jmurret Jun 15, 2023
04edace
Fix issue with streaming service health watches. (#17775)
hashi-derek Jun 15, 2023
f9aa7ae
Property Override validation improvements (#17759)
zalimeni Jun 15, 2023
414a61d
Fixes (#17765)
boruszak Jun 15, 2023
730c599
Update license get explanation (#17782)
markcampv Jun 15, 2023
265c003
Add Patch index to Prop Override validation errors (#17777)
zalimeni Jun 16, 2023
5f95f5f
Stop referenced jwt providers from being deleted (#17755)
roncodingenthusiast Jun 16, 2023
653a886
Implement a Catalog Controllers Lifecycle Integration Test (#17435)
mkeeler Jun 16, 2023
5352ccf
HCP Add node id/name to config (#17750)
chapmanc Jun 16, 2023
37636ea
Catalog V2 Container Based Integration Test (#17674)
mkeeler Jun 16, 2023
00c8575
Fix Docs for Trails Leader By (#17763)
absolutelightning Jun 17, 2023
18b1555
Improve Prop Override docs examples (#17799)
zalimeni Jun 20, 2023
d2363eb
Test permissive mTLS filter chain not configured with tproxy disabled…
Jun 20, 2023
6d39328
Add documentation for remote debugging of integration tests. (#17800)
jmurret Jun 20, 2023
e4c9793
Clarify limitations of Prop Override extension (#17801)
zalimeni Jun 20, 2023
2a94ffa
Fix formatting for webhook-certs Consul tutorial (#17810)
stevenzamborsky Jun 20, 2023
ee95bc7
Add jwt-authn metrics to jwt-provider docs (#17816)
roncodingenthusiast Jun 20, 2023
f17b7f3
Change URLs for redirects from RC to default latest (#17822)
trujillo-adam Jun 20, 2023
500dcb1
Set GOPRIVATE for all hashicorp repos in CI (#17817)
zalimeni Jun 21, 2023
a3ba559
Make locality aware routing xDS changes (#17826)
erichaberkorn Jun 21, 2023
d0797c4
Fixup consul-container/test/debugging.md (#17815)
zalimeni Jun 21, 2023
82441a2
fixes #17732 - AccessorID in request body should be optional when upd…
gbolo Jun 21, 2023
a4653de
CA provider doc updates and Vault provider minor update (#17831)
Jun 21, 2023
366bd6f
ext-authz Envoy extension: support `localhost` as a valid target URI.…
cthain Jun 21, 2023
1864874
CI Updates (#17834)
mkeeler Jun 22, 2023
b782f2e
counter part of ent pr (#17618)
xwa153 Jun 22, 2023
f16c5d8
watch: support -filter for consul watch: checks, services, nodes, ser…
huikang Jun 23, 2023
1f63671
Trigger OSS => ENT merge for all release branches (#17853)
nathancoleman Jun 23, 2023
2e2cbc1
Update service-mesh.mdx (#17845)
cn0047 Jun 23, 2023
94eb36b
Add docs for sameness groups with resolvers. (#17851)
hashi-derek Jun 23, 2023
5244ede
docs: add note about path prefix matching behavior for HTTPRoute conf…
nathancoleman Jun 23, 2023
d5d3a3d
docs: update upgrade to consul-dataplane docs on k8s (#17852)
ishustava Jun 23, 2023
48445df
resource: add `AuthorizerContext` helper method (#17393)
boxofrad Jun 26, 2023
b117eb0
resource: enforce consistent naming of resource types (#17611)
boxofrad Jun 26, 2023
ce24646
tooling: generate protoset file (#17364)
boxofrad Jun 26, 2023
33a2d90
Fix a bug that wrongly trims domains when there is an overlap with DC…
shamil Jun 26, 2023
8e02a0e
deps: aws-sdk-go v1.44.289 (#17876)
loshz Jun 26, 2023
e552e3d
api-gateway: add operation cannot be fulfilled error to common errors…
sarahalsmiller Jun 26, 2023
08c5048
api-gateway: add step to upgrade instructions for creating intentions…
nathancoleman Jun 26, 2023
a96a9e7
Changelog - add 1.13.9, 1.14.8, and 1.15.4 (#17889)
jmurret Jun 27, 2023
6bc2222
docs: update config enable_debug (#17866)
nvanthao Jun 27, 2023
601490b
Update wording on WAN fed and intermediate_pki_path (#17850)
Jun 27, 2023
767ef2d
Allow service identity tokens the ability to read jwt-providers (#17893)
roncodingenthusiast Jun 27, 2023
c8cfa60
Update docs (#17476)
mr-miles Jun 27, 2023
55056be
Add emit_tags_as_labels to envoy bootstrap config when using Consul T…
Jun 27, 2023
abeeea1
Fix command from kg to kubectl get (#17903)
lkysow Jun 27, 2023
1c819e6
Create and update release notes for 1.16 and 1.2 (#17895)
im2nguyen Jun 27, 2023
b76c4d7
Propose new changes to APIgw upgrade instructions (#17693)
im2nguyen Jun 27, 2023
3368f14
Add workflow to verify linux release packages (#17904)
jmurret Jun 27, 2023
f787088
Reference hashicorp/consul instead of consul for Docker image (#17914)
nathancoleman Jun 27, 2023
310bc68
Update Consul K8s Upgrade Doc Updates (#17921)
natemollica-nm Jun 27, 2023
6f5da97
Update sameness-group.mdx (#17915)
Jun 28, 2023
b168132
Update create-sameness-groups.mdx (#17927)
Jun 28, 2023
7dbba6c
deps: coredns v1.10.1 (#17912)
loshz Jun 28, 2023
67a239a
Ensure RSA keys are at least 2048 bits in length (#17911)
jm96441n Jun 28, 2023
f019457
tlsutil: Fix check TLS configuration (#17481)
beautifulentropy Jun 28, 2023
6f660e5
docs: Deprecations for connect-native SDK and specific connect native…
Jun 28, 2023
bdf4fad
Revert "Add workflow to verify linux release packages (#17904)" (#17942)
jmurret Jun 28, 2023
1b1f33f
Fixes Secondary ConnectCA update (#17846)
Ranjandas Jun 29, 2023
a60b363
fixing typo in link to jwt-validations-with-intentions doc (#17955)
jm96441n Jun 29, 2023
85b78fe
Fix streaming backend link (#17958)
Jun 29, 2023
1512ea3
Dynamically create jwks clusters for jwt-providers (#17944)
roncodingenthusiast Jun 29, 2023
f7305b2
website: remove deprecated agent rpc docs (#17962)
loshz Jun 29, 2023
2736e64
Fix missing BalanceOutboundConnections in v2 catalog. (#17964)
hashi-derek Jun 29, 2023
2af6bc4
feature - [NET - 4005] - [Supportability] Reloadable Configuration -…
absolutelightning Jun 30, 2023
5b7f360
Fix formatting codeblocks on APIgw docs (#17970)
im2nguyen Jun 30, 2023
50a9d1b
Remove POC code (#17974)
Jun 30, 2023
9ce89c4
update doc (#17910)
xwa153 Jun 30, 2023
0b1299c
Remove duplicate and unused newDecodeConfigEntry func (#17979)
cthain Jun 30, 2023
f096fc5
docs: samenessGroup YAML examples (#17984)
boruszak Jun 30, 2023
df85dd8
Add changelog entry for 1.16.0 (#17987)
nathancoleman Jun 30, 2023
dc6ea1b
Fix typo (#17198)
evanphx Jul 1, 2023
8039427
Expose JWKS cluster config through JWTProviderConfigEntry (#17978)
roncodingenthusiast Jul 4, 2023
4f0bdd3
Integration test for ext-authz Envoy extension (#17980)
cthain Jul 4, 2023
0094dbf
Fix incorrect protocol for transparent proxy upstreams. (#17894)
hashi-derek Jul 5, 2023
8af4ad1
feat: include nodes count in operator usage endpoint and cli command …
JadhavPoonam Jul 5, 2023
b94095d
[OSS] Improve Gateway Test Coverage of Catalog Health (#18011)
DanStough Jul 5, 2023
7f3446e
Fixes Traffic rate limitting docs (#17997)
Ranjandas Jul 5, 2023
2c2e628
Fix removed service-to-service peering links (#17221)
karras Jul 5, 2023
7ef807d
docs: Sameness "beta" warning (#18017)
boruszak Jul 5, 2023
548829a
updated typo in tab heading (#18022)
trujillo-adam Jul 5, 2023
7689a5e
Document that DNS lookups can target cluster peers (#17990)
jcjones Jul 5, 2023
ada3938
Add first integration test for jwt auth with intention (#18005)
roncodingenthusiast Jul 6, 2023
f7d399f
fix stand-in text for name field (#18030)
trujillo-adam Jul 6, 2023
820cdbb
removed sameness conf entry from failover nav (#18033)
trujillo-adam Jul 6, 2023
85f2ae0
docs - add service sync annotations and k8s service weight annotation…
Jul 6, 2023
b9a6a74
docs - add jobs use case for service mesh k8s (#18037)
Jul 7, 2023
b0a2e33
address feedback (#18045)
Jul 7, 2023
f4b0804
Add verify server hostname to tls default (#17155)
fulviodenza Jul 10, 2023
a8c6609
[CC-5718] Remove HCP token requirement during bootstrap
jjacobson93 Jul 14, 2023
f1225f5
Re-add error for loading HCP management token
jjacobson93 Jul 17, 2023
fc680e8
Remove old comment
jjacobson93 Jul 17, 2023
75e3629
backport of commit fc680e806ee6428c3a363d066f6b093fbe2fdd20
jjacobson93 Jul 17, 2023
56ed094
backport of commit 536e6f3b3b68754cb9958f83e225e6f7d1565c08
jjacobson93 Jul 19, 2023
39335fc
backport of commit a99dd82929013249c8f57f1867da8a8ed4fb93d9
jjacobson93 Jul 20, 2023
9131043
Merge fc680e806ee6428c3a363d066f6b093fbe2fdd20 into backport/jer/ccm-…
hc-github-team-consul-core Jul 21, 2023
0b321a9
backport of commit 5958ae0921522707652794668233741298863ade
jjacobson93 Jul 19, 2023
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
3 changes: 3 additions & 0 deletions .changelog/13782.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:feature
deps: update to latest go-discover to provide ECS auto-discover capabilities.
```
4 changes: 4 additions & 0 deletions .changelog/14340.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
```release-note:feature
connect: Add local_idle_timeout_ms to allow configuring the Envoy route idle timeout on local_app
connect: Add IdleTimeout to service-router to allow configuring the Envoy route idle timeout
```
6 changes: 3 additions & 3 deletions .changelog/14679.txt
Original file line number Diff line number Diff line change
@@ -1,3 +1,3 @@
```release-note:improvement
dns: **(Enterprise Only)** All enterprise locality labels are now optional in DNS lookups. For example, service lookups support the following format: <tag>.]<service>.service[.<namespace>.ns][.<partition>.ap][.<datacenter>.dc]<domain>`.
```
```release-note:improvement
dns: **(Enterprise Only)** All enterprise locality labels are now optional in DNS lookups. For example, service lookups support the following format: `[<tag>.]<service>.service[.<namespace>.ns][.<partition>.ap][.<datacenter>.dc]<domain>`.
```
1 change: 0 additions & 1 deletion .changelog/14930.txt

This file was deleted.

6 changes: 6 additions & 0 deletions .changelog/15050.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
```release-note:feature
cli: Add `-consul-dns-port` flag to the `consul connect redirect-traffic` command to allow forwarding DNS traffic to a specific Consul DNS port.
```
```release-note:feature
sdk: Configure `iptables` to forward DNS traffic to a specific DNS port.
```
3 changes: 3 additions & 0 deletions .changelog/15083.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
connect: fixed bug where endpoint updates for new xDS clusters could block for 15s before being sent to Envoy.
```
3 changes: 3 additions & 0 deletions .changelog/15090.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:note
deps: Upgrade to use Go 1.19.2
```
6 changes: 6 additions & 0 deletions .changelog/15093.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
```release-note: improvement
connect: Add Envoy 1.24.0 to support matrix
```
```release-note: breaking-change
connect: Removes support for Envoy 1.20
```
3 changes: 3 additions & 0 deletions .changelog/15108.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
peering: when wan address is set, peering stream should use the wan address.
```
3 changes: 3 additions & 0 deletions .changelog/15155.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
debug: fixed bug that caused consul debug CLI to error on ACL-disabled clusters
```
3 changes: 3 additions & 0 deletions .changelog/15160.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
peering: fix nil pointer in calling handleUpdateService
```
3 changes: 3 additions & 0 deletions .changelog/15178.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
peering: Fix a bug that resulted in /v1/agent/metrics returning an error.
```
3 changes: 3 additions & 0 deletions .changelog/15186.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
connect: Fix issue where mesh-gateway settings were not properly inherited from configuration entries.
```
3 changes: 3 additions & 0 deletions .changelog/15233.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note: improvement
integ test: fix flakiness due to test condition from retry app endoint
```
3 changes: 3 additions & 0 deletions .changelog/15253.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
connect: Fixed issue where using Vault 1.11+ as CA provider would eventually break Intermediate CAs [[GH-15217](https://github.com/hashicorp/consul/issues/15217)]
```
3 changes: 3 additions & 0 deletions .changelog/15272.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
proxycfg(mesh-gateway): Fix issue where deregistered services are not removed from mesh-gateway clusters.
```
7 changes: 7 additions & 0 deletions .changelog/15302.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
```release-note:breaking-change
config: update 1.14 config defaults: Enable `peering` and `connect` by default.
```

```release-note:breaking-change
config: update 1.14 config defaults: Set gRPC TLS port default value to 8503
```
3 changes: 3 additions & 0 deletions .changelog/15317.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:improvements
acl: Allow reading imported services and nodes from cluster peers with read all permissions
```
3 changes: 3 additions & 0 deletions .changelog/15320.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
connect: strip port from DNS SANs for ingress gateway leaf certificate to avoid an invalid hostname error when using the Vault provider.
```
2 changes: 1 addition & 1 deletion .changelog/14294.txt → .changelog/15339.txt
Original file line number Diff line number Diff line change
Expand Up @@ -2,5 +2,5 @@
config: Add new `ports.grpc_tls` configuration option.
Introduce a new port to better separate TLS config from the existing `ports.grpc` config.
The new `ports.grpc_tls` only supports TLS encrypted communication.
The existing `ports.grpc` currently supports both plain-text and tls communication, but tls support will be removed in a future release.
The existing `ports.grpc` now only supports plain-text communication.
```
3 changes: 3 additions & 0 deletions .changelog/15346.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:enhancement
acl: relax permissions on the `WatchServers`, `WatchRoots` and `GetSupportedDataplaneFeatures` gRPC endpoints to accept *any* valid ACL token
```
3 changes: 3 additions & 0 deletions .changelog/15356.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:security
Ensure that data imported from peers is filtered by ACLs at the UI Nodes/Services endpoints [CVE-2022-3920](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3920)
```
3 changes: 3 additions & 0 deletions .changelog/15370.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:improvement
auto-config: Relax the validation on auto-config JWT authorization to allow non-whitespace, non-quote characters in node names.
```
3 changes: 3 additions & 0 deletions .changelog/15423.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
sdk: Fix SDK testutil backwards compatibility by only configuring grpc_tls port for new Consul versions.
```
3 changes: 3 additions & 0 deletions .changelog/15466.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
cli: Fix issue where `consul connect envoy` incorrectly uses the HTTPS API configuration for xDS connections.
```
3 changes: 3 additions & 0 deletions .changelog/15503.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
peering: fix the limit of replication gRPC message; set to 8MB
```
3 changes: 3 additions & 0 deletions .changelog/15525.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
ca: Fixed issue where using Vault as Connect CA with Vault-managed policies would error on start-up if the intermediate PKI mount existed but was empty
```
3 changes: 3 additions & 0 deletions .changelog/15541.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
agent: Fixed issue where blocking queries with short waits could timeout on the client
```
3 changes: 3 additions & 0 deletions .changelog/15555.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:feature
ui: Add field for fallback server addresses to peer token generation form
```
3 changes: 3 additions & 0 deletions .changelog/15596.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:improvement
dns: Add support for cluster peering `.service` and `.node` DNS queries.
```
3 changes: 3 additions & 0 deletions .changelog/15610.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
acl: avoid debug log spam in secondary datacenter servers due to management token not being initialized.
```
3 changes: 3 additions & 0 deletions .changelog/15615.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
peering: better represent non-passing states during peer check flattening
```
3 changes: 3 additions & 0 deletions .changelog/15659.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:improvement
connect: Add support for ConsulResolver to specifies a filter expression
```
3 changes: 3 additions & 0 deletions .changelog/15661.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
connect: Fixed issue where using Vault 1.11+ as CA provider in a secondary datacenter would eventually break Intermediate CAs
```
3 changes: 3 additions & 0 deletions .changelog/15669.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:improvement
connect: ensure all vault connect CA tests use limited privilege tokens
```
3 changes: 3 additions & 0 deletions .changelog/15690.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
connect: Fix peering failovers ignoring local mesh gateway configuration.
```
3 changes: 3 additions & 0 deletions .changelog/15697.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:breaking-change
peering: Newly created peering connections must use only lowercase characters in the `name` field. Existing peerings with uppercase characters will not be modified, but they may encounter issues in various circumstances. To maintain forward compatibility and avoid issues, it is recommended to destroy and re-create any invalid peering connections so that they do not have a name containing uppercase characters.
```
3 changes: 3 additions & 0 deletions .changelog/15701.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:improvement
grpc: Use new balancer implementation to reduce periodic WARN logs when shuffling servers.
```
3 changes: 3 additions & 0 deletions .changelog/15705.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:security
Upgrade to use Go 1.19.4. This resolves a vulnerability where restricted files can be read on Windows. [CVE-2022-41720](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41720)
```
4 changes: 4 additions & 0 deletions .changelog/15737.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
```release-note:security
Upgrades `golang.org/x/net` to prevent a denial of service by excessive memory usage caused by HTTP2 requests. [CVE-2022-41717](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41717)
```

3 changes: 3 additions & 0 deletions .changelog/15760.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
connect: Fix issue where DialedDirectly configuration was not used by Consul Dataplane.
```
3 changes: 3 additions & 0 deletions .changelog/15769.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
agent: Fix assignment of error when auto-reloading cert and key file changes.
```
3 changes: 3 additions & 0 deletions .changelog/15789.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
xds: fix bug where sessions for locally-managed services could fail with "this server has too many xDS streams open"
```
3 changes: 3 additions & 0 deletions .changelog/15833.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
connect: Fix issue where service-resolver protocol checks incorrectly errored for failover peer targets.
```
3 changes: 3 additions & 0 deletions .changelog/15865.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
connect: Fix issue where watches on upstream failover peer targets did not always query the correct data.
```
3 changes: 3 additions & 0 deletions .changelog/15866.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
agent: Fix issue where the agent cache would incorrectly mark protobuf objects as updated.
```
3 changes: 3 additions & 0 deletions .changelog/15913.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
cli: Fix issue where `consul connect envoy` was unable to configure TLS over unix-sockets to gRPC.
```
3 changes: 3 additions & 0 deletions .changelog/15979.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:improvement
envoy: add `MaxEjectionPercent` and `BaseEjectionTime` to passive health check configs.
```
3 changes: 3 additions & 0 deletions .changelog/15988.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:improvements
cli: Added a flag, `-enable-config-gen-logging`, to the `connect envoy` command to display log messages when generating the bootstrap config.
```
3 changes: 3 additions & 0 deletions .changelog/16000.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:breaking-change
connect: Fix configuration merging for transparent proxy upstreams. Proxy-defaults and service-defaults config entries were not correctly merged for implicit upstreams in transparent proxy mode and would result in some configuration not being applied. To avoid issues when upgrading, ensure that any proxy-defaults or service-defaults have correct configuration for upstreams, since all fields will now be properly used to configure proxies.
```
3 changes: 3 additions & 0 deletions .changelog/16015.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:feature
connect: add flags `envoy-ready-bind-port` and `envoy-ready-bind-address` to the `consul connect envoy` command that allows configuration of readiness probe on proxy for any service kind.
```
4 changes: 4 additions & 0 deletions .changelog/16024.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
```release-note:improvement
partitiion: **(Consul Enterprise only)** when loading service from on-disk config file or sending API request to agent endpoint,
if the partition is unspecified, consul will default the partition in the request to agent's partition
```
3 changes: 3 additions & 0 deletions .changelog/16230.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
peering: Fix issue where secondary wan-federated datacenters could not be used as peering acceptors.
```
3 changes: 3 additions & 0 deletions .changelog/16257.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
peering: Fix issue where mesh gateways would use the wrong address when contacting a remote peer with the same datacenter name.
```
4 changes: 4 additions & 0 deletions .changelog/16263.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
```release-note:security
Upgrade to use Go 1.20.1.
This resolves vulnerabilities [CVE-2022-41724](https://go.dev/issue/58001) in `crypto/tls` and [CVE-2022-41723](https://go.dev/issue/57855) in `net/http`.
```
3 changes: 3 additions & 0 deletions .changelog/16339.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
peering: Fix bug where services were incorrectly imported as connect-enabled.
```
3 changes: 3 additions & 0 deletions .changelog/16358.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:improvement
container: Upgrade container image to use to Alpine 3.17.
```
3 changes: 3 additions & 0 deletions .changelog/16495.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:improvement
mesh: Add ServiceResolver RequestTimeout for route timeouts to make request timeouts configurable
```
3 changes: 3 additions & 0 deletions .changelog/16497.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
proxycfg: ensure that an irrecoverable error in proxycfg closes the xds session and triggers a replacement proxycfg watcher
```
3 changes: 3 additions & 0 deletions .changelog/16498.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
proxycfg: fix a bug where terminating gateways were not cleaning up deleted service resolvers for their referenced services
```
3 changes: 3 additions & 0 deletions .changelog/16499.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
mesh: Fix resolution of service resolvers with subsets for external upstreams
```
3 changes: 3 additions & 0 deletions .changelog/16552.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:improvement
raft: Remove expensive reflection from raft/mesh hot path
```
3 changes: 3 additions & 0 deletions .changelog/16570.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
peering: Fixes a bug that can lead to peering service deletes impacting the state of local services
```
3 changes: 3 additions & 0 deletions .changelog/16592.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
ca: Fixes a bug where updating Vault CA Provider config would cause TLS issues in the service mesh
```
3 changes: 3 additions & 0 deletions .changelog/16660.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
ui: fix PUT token request with adding missed AccessorID property to requestBody
```
3 changes: 3 additions & 0 deletions .changelog/16693.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
peering: Fixes a bug where the importing partition was not added to peered failover targets, which causes issues when the importing partition is a non-default partition.
```
3 changes: 3 additions & 0 deletions .changelog/16700.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
audit-logging: (Enterprise only) Fix a bug where `/agent/monitor` and `/agent/metrics` endpoints return a `Streaming not supported` error when audit logs are enabled. This also fixes the delay receiving logs when running `consul monitor` against an agent with audit logs enabled.
```
3 changes: 3 additions & 0 deletions .changelog/16729.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
peering: Fix issue resulting in prepared query failover to cluster peers never un-failing over.
```
3 changes: 3 additions & 0 deletions .changelog/16776.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:improvement
peering: allow re-establishing terminated peering from new token without deleting existing peering first.
```
3 changes: 3 additions & 0 deletions .changelog/16845.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:improvement
systemd: set service type to notify.
```
3 changes: 3 additions & 0 deletions .changelog/16888.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:improvement
connect: update supported envoy versions to 1.21.6, 1.22.11, 1.23.8, 1.24.6
```
3 changes: 3 additions & 0 deletions .changelog/16916.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:improvement
hcp: Add support for linking existing Consul clusters to HCP management plane.
```
3 changes: 3 additions & 0 deletions .changelog/17048.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
Fix an bug where decoding some Config structs with unset pointer fields could fail with `reflect: call of reflect.Value.Type on zero Value`.
```
3 changes: 3 additions & 0 deletions .changelog/17160.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
Fix a bug that wrongly trims domains when there is an overlap with DC name.
```
3 changes: 3 additions & 0 deletions .changelog/17185.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
xds: Fix possible panic that can when generating clusters before the root certificates have been fetched.
```
3 changes: 3 additions & 0 deletions .changelog/17235.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
peering: Fix issue where peer streams could incorrectly deregister services in various scenarios.
```
3 changes: 3 additions & 0 deletions .changelog/17236.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:improvement
logging: change snapshot log header from `agent.server.snapshot` to `agent.server.raft.snapshot`
```
12 changes: 12 additions & 0 deletions .changelog/17240.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
```release-note:security
Upgrade to use Go 1.20.4.
This resolves vulnerabilities [CVE-2023-24537](https://github.com/advisories/GHSA-9f7g-gqwh-jpf5)(`go/scanner`),
[CVE-2023-24538](https://github.com/advisories/GHSA-v4m2-x4rp-hv22)(`html/template`),
[CVE-2023-24534](https://github.com/advisories/GHSA-8v5j-pwr7-w5f8)(`net/textproto`) and
[CVE-2023-24536](https://github.com/advisories/GHSA-9f7g-gqwh-jpf5)(`mime/multipart`).
Also, `golang.org/x/net` has been updated to v0.7.0 to resolve CVEs [CVE-2022-41721
](https://github.com/advisories/GHSA-fxg5-wq6x-vr4w
), [CVE-2022-27664](https://github.com/advisories/GHSA-69cg-p879-7622) and [CVE-2022-41723
](https://github.com/advisories/GHSA-vvpx-j8f3-3w6h
.)
```
3 changes: 3 additions & 0 deletions .changelog/17241.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
connect: Fix multiple inefficient behaviors when querying service health.
```
3 changes: 3 additions & 0 deletions .changelog/17270.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
grpc: ensure grpc resolver correctly uses lan/wan addresses on servers
```
3 changes: 3 additions & 0 deletions .changelog/17317.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
connect: fix a bug with Envoy potentially starting with incomplete configuration by not waiting enough for initial xDS configuration.
```
5 changes: 5 additions & 0 deletions .changelog/17426.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
```release-note:improvement
peering: gRPC queries for TrustBundleList, TrustBundleRead, PeeringList, and PeeringRead now support blocking semantics,
reducing network and CPU demand.
The HTTP APIs for Peering List and Read have been updated to support blocking.
```
3 changes: 3 additions & 0 deletions .changelog/17456.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
peering: Fix issue where modifying the list of exported services did not correctly replicate changes for services that exist in a non-default namespace.
```
3 changes: 3 additions & 0 deletions .changelog/17483.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
peering: Fix a bug that caused server agents to continue cleaning up peering resources even after loss of leadership.
```
3 changes: 3 additions & 0 deletions .changelog/17513.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:security
Update to UBI base image to 9.2.
```
3 changes: 3 additions & 0 deletions .changelog/17541.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
connect: reverts #17317 fix that caused a downstream error for Ingress/Mesh/Terminating GWs when their respective config entry does not already exist.
```
3 changes: 3 additions & 0 deletions .changelog/17547.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:improvement
connect: update supported envoy versions to 1.21.6, 1.22.11, 1.23.9, 1.24.7
```
Loading