Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[NET-1151 NET-11046] docs: Add request normalization, L7 headers options, and security guidance to release/1.15.x #21858

Open
wants to merge 1 commit into
base: release/1.15.x
Choose a base branch
from

Conversation

zalimeni
Copy link
Member

Description

Docs-only follow-up to #21816, and backport of #21855, combined into a single PR for clarity.

PR Checklist

  • updated test coverage
  • external facing docs updated
  • appropriate backport labels added
  • not a security concern

@zalimeni zalimeni requested a review from a team as a code owner October 18, 2024 13:39
@github-actions github-actions bot added the type/docs Documentation needs to be created/updated/clarified label Oct 18, 2024
@zalimeni zalimeni force-pushed the backport/zalimeni/net-11046-clarify-feature-availability-1.15 branch from 2a3e891 to a66c7d8 Compare October 18, 2024 13:43
@@ -18,10 +18,10 @@ The following outline shows how to format the service intentions configuration e
<Tab heading="HCL and JSON" group="hcl">
Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This file is best viewed w/ whitespace disabled, since I think some commit hooks are fixing trailing whitespace despite me trying to keep the diff tight

@@ -26,6 +26,32 @@ of Consul.

## Checklist
Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This version is missing the following note due to default intentions policies not existing in 1.15 (default ACL policy was the inferred intention policy):

One advantage of using a default deny policy in combination with specific "allow" rules
is that a failure of intentions due to misconfiguration always results in
denied traffic, rather than unwanted allowed traffic.

@zalimeni zalimeni force-pushed the backport/zalimeni/net-11046-clarify-feature-availability-1.15 branch from a66c7d8 to 062eff3 Compare October 18, 2024 14:45
@jmurret jmurret self-assigned this Oct 22, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
pr/no-backport type/docs Documentation needs to be created/updated/clarified
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants