Commit Graph

5409 Commits (zalimeni/net-5586-support-virtual-port-xroute-dest)

Author SHA1 Message Date
John Murret abbf85831f
NET-6080 - xds controller golden file inputs into xds resources - destinations (#19244)
1 year ago
Derek Menteer 48c4a5b736
Add grpc keepalive configuration. (#19339)
1 year ago
Semir Patel 96606d114c
resource: default peername to local in list endpoints (#19340)
1 year ago
Dhia Ayachi d5c9f11b59
Tenancy Bridge v2 (#19220)
1 year ago
aahel 1280f45485
added ent to ce downgrade changes (#19311)
1 year ago
Chris S. Kim 9d00b13140
Vault CA bugfixes (#19285)
1 year ago
Michael Zalimeni 5e517c5980
[NET-6221] Ensure LB policy set for locality-aware routing (CE) (#19283)
1 year ago
Eric Haberkorn f45be222bb
Prevent circular dependencies between v2 resources and generate a mermaid diagram with their dependencies (#19230)
1 year ago
John Maguire b78465b491
[NET-5810] CE changes for multiple virtual hosts (#19246)
1 year ago
Semir Patel ad177698f7
resource: enforce lowercase v2 resource names (#19218)
1 year ago
Iryna Shustava 105ebfdd00
catalog, mesh: implement missing ACL hooks (#19143)
1 year ago
R.B. Boyer 20d1fb8c78
server: run the api checks against the path without params (#19205)
1 year ago
Dhia Ayachi 5fbf0c00d3
Add namespace read write tests (#19173)
1 year ago
Thomas Eckert 76c60fdfac
Golden File Tests for TermGW w/ Cluster Peering (#19096)
1 year ago
Nitya Dhanushkodi 95d9b2c7e4
[NET-4931] xdsv2, sidecarproxycontroller, l4 trafficpermissions: support L7 (#19185)
1 year ago
Iryna Shustava 25283f0ec2
get-envoy-bootstrap-params: when v2 is enabled, use computed proxy configuration (#19175)
1 year ago
Chris S. Kim 197bcd4164
Refactor connect_auth.go into agent_endpoint.go (#19166)
1 year ago
John Maguire 7a323c492b
[NET-5457] Golden Files for Multiple Virtual Hosts (#19131)
1 year ago
John Murret 6cbd417f29
NET-5822 - Add default outbound router in TProxy (#19087)
1 year ago
R.B. Boyer b9ab63c55d
server: when the v2 catalog experiment is enabled reject api and rpc requests that are for the v1 catalog (#19129)
1 year ago
John Maguire 8bebfc147d
[NET-5457] Fix CE code for jwt multiple virtual hosts bug (#19123)
1 year ago
Semir Patel 830c4ea81c
v2tenancy: cluster scoped reads (#19082)
1 year ago
Dhia Ayachi 226590541c
Activate verifier when running WAL with experimental features (#19102)
1 year ago
Chris S. Kim 92ce814693
Remove old build tags (#19128)
1 year ago
Chris Thain dcdf2fc6ba
Update Vault CA provider namespace configuration (#19095)
1 year ago
Ashesh Vidyut a30ccdf5dc
NET-4135 - Fix NodeMeta filtering Catalog List Services API (#18322)
1 year ago
Derek Menteer af3439b53d
Ensure that upstream configuration is properly normalized. (#19076)
1 year ago
Dhia Ayachi ed882e2522
Make raft-wal default when `resource-apis` is active (#19090)
1 year ago
Thomas Eckert 342306c312
Allow connections through Terminating Gateways from peered clusters NET-3463 (#18959)
1 year ago
Chris S. Kim aa526db225
Retry flaky tests (#19088)
1 year ago
Chris S. Kim ad26494016
[CE] Add workload bind type and templated policy (#19077)
1 year ago
Eric Haberkorn f2b7b4591a
Fix Traffic Permissions Default Deny (#19028)
1 year ago
John Murret d67e5c6e35
NET-5590 - authorization: check for identity:write in CA certs, xds server, and getting envoy bootstrap params (#19049)
1 year ago
Chris S. Kim 41e6f6cd8b
Reduce number of ports that consul test agents take (#19047)
1 year ago
sarahalsmiller 9addd9ed7c
[NET-5788] Fix needed for JWTAuth in Consul Enterprise (#19038)
1 year ago
Nitya Dhanushkodi 9a48266712
remove log (#19029)
1 year ago
Chris Thain 5e45db18b7
Include RequestTimeout in marshal/unmarshal of ServiceResolverConfigE… (#19031)
1 year ago
Eric Haberkorn 7ce6ebaeb3
Handle Traffic Permissions With Empty Sources Properly (#19024)
1 year ago
Iryna Shustava 06c15d0656
auth: register auth controllers with the server (#19000)
1 year ago
Iryna Shustava e6b724d062
catalog,mesh,auth: Move resource types to the proto-public module (#18935)
1 year ago
R.B. Boyer 7688178ad2
peerstream: fix flaky test related to autopilot integration (#18979)
1 year ago
Iryna Shustava d88888ee8b
catalog,mesh,auth: Bump versions to v2beta1 (#18930)
1 year ago
R.B. Boyer ef6f2494c7
resource: allow for the ACLs.Read hook to request the entire data payload to perform the authz check (#18925)
1 year ago
Nitya Dhanushkodi 0a11499588
net-5689 fix disabling panic threshold logic (#18958)
1 year ago
Chris S. Kim 565e79344f
Dump response body on fail (#18962)
1 year ago
Ronald 276c60a947
skip flaky test (#18949)
1 year ago
John Landa 9eaa8eb026
dns token (#17936)
1 year ago
Dhia Ayachi 341dc28ff9
Add namespace proto and registration (#18848)
1 year ago
R.B. Boyer d574473fd1
mesh: make FailoverPolicy work in xdsv2 and ProxyStateTemplate (#18900)
1 year ago
Ronald c8299522b5
[NET-5332] Add nomad server templated policy (#18888)
1 year ago
Nitya Dhanushkodi 3a2e62053a
v2: various fixes to make K8s tproxy multiport acceptance tests and manual explicit upstreams (single port) tests pass (#18874)
1 year ago
Nick Ethier 1a3081ab32
agent/config: prevent startup if resource-apis experiment and cloud are enabled (#18876)
1 year ago
Blake Covarrubias 019c62e1ba
xds: Use downstream protocol when connecting to local app (#18573)
1 year ago
Eric Haberkorn 170417ac97
Honor Default Traffic Permissions in V2 (#18886)
1 year ago
Iryna Shustava 212793a4ee
mesh: only build tproxy outbound listener once per destination (#18836)
1 year ago
Chris S. Kim 91e6c3a82f
Remove flaky test assertions (#18870)
1 year ago
Semir Patel 62796a1454
resource: mutate and validate before acls on write (#18868)
1 year ago
Ronald 49cb84297f
Move ACL templated policies to hcl files (#18853)
1 year ago
Andrew Stucki 087539fc7b
Fix gateway services cleanup where proxy deregistration happens after service deregistration (#18831)
1 year ago
Dhia Ayachi 4435e4a420
add v2 tenancy bridge Flag and v2 Tenancy Bridge initial implementation (#18830)
1 year ago
Chris S. Kim 461549e304
Adjust metrics test (#18837)
1 year ago
skpratt 1fda2965e8
Allow empty data writes for resources (#18819)
1 year ago
Ronald aff13cd4c2
Use embedded strings for templated policies (#18829)
1 year ago
Eric Haberkorn 21fdbbabbc
Wire up traffic permissions (#18812)
1 year ago
Semir Patel d3dad14030
resource: default peername to "local" for now (#18822)
1 year ago
R.B. Boyer 66e1cdf40c
mesh: Wire ComputedRoutes into the ProxyStateTemplate via the sidecar controller (#18752)
1 year ago
Ronald 1afeb6e040
[NET-5334] Added CLI commands for templated policies (#18816)
1 year ago
Ronald 802122640b
[NET-5329] use acl templated policy under the hood for node/service identities (#18813)
1 year ago
skpratt e5808d85f7
register traffic permission and workload identity types (#18704)
1 year ago
Chris S. Kim d667cc3809
Fix flaky test (#18805)
1 year ago
Chris S. Kim 6748fac43d
Clean up resources in test (#18799)
1 year ago
Derek Menteer 02259ef964
Fix snapshot creation issue. (#18783)
1 year ago
Chris S. Kim 4dfca64ded
Vault CA provider clean up previous default issuers (#18773)
1 year ago
Eric Haberkorn 12be06f8e5
Add V2 TCP traffic permissions (#18771)
1 year ago
Chris S. Kim d090668c37
Add workload identity ACL rules (#18769)
1 year ago
Nitya Dhanushkodi 78b170ad50
xds controller: setup watches for and compute leaf cert references in ProxyStateTemplate, and wire up leaf cert manager dependency (#18756)
1 year ago
Chris Thain 4724a4e169
Add Envoy golden test for OTEL access logging extension (#18760)
1 year ago
John Murret 62062fd4fd
NET-5132 - Configure multiport routing for connect proxies in TProxy mode (#18606)
1 year ago
Ronald 9776c10efb
[NET-5333] Add api to read/list and preview templated policies (#18748)
1 year ago
Dhia Ayachi b1688ad856
Run copyright after running deep-copy as part of the Makefile/CI (#18741)
1 year ago
R.B. Boyer a69e901660
xds: update golden tests to be deterministic (#18707)
1 year ago
Iryna Shustava 1557e1d6a3
sidecar-proxy controller: Add support for transparent proxy (NET-5069) (#18458)
1 year ago
Nathan Coleman ed79c60e78
NET-5530 Generate deep-copy code (#18730)
1 year ago
Ronald 40d7ebc318
[NET-5330] Support templated policies in Binding rules (#18719)
1 year ago
Semir Patel 576ffdf705
fix: emit consul version metric on a regular interval (#18724)
1 year ago
Nathan Coleman e5d26a13cd
NET-5530 Support response header modifiers on http-route config entry (#18646)
1 year ago
Jeremy Jacobson 876c662e36
[CC-6039] Update builtin policy descriptions (#18705)
1 year ago
Iryna Shustava bbc2763b9f
Instantiate secure resource service client after the grpc server (#18712)
1 year ago
Ronald bbef879f85
[NET-5325] ACL templated policies support in tokens and roles (#18708)
1 year ago
Gerard Nguyen 56d6e54ac7
fix: NET-1521 show latest config in /v1/agent/self (#18681)
1 year ago
John Maguire 2c244b6f42
[APIGW] NET-5017 JWT Cleanup/Status Conditions (#18700)
1 year ago
Iryna Shustava 3c70e14713
sidecar-proxy controller: L4 controller with explicit upstreams (NET-3988) (#18352)
1 year ago
Iryna Shustava 4eb2197e82
dataplane: Allow getting bootstrap parameters when using V2 APIs (#18504)
1 year ago
Derek Menteer 56917eb4c9
Add support for querying tokens by service name. (#18667)
1 year ago
Phil Porada 7ea986783d
Add TCP+TLS Healthchecks (#18381)
1 year ago
Derek Menteer a698142325
Add extra logging for mesh health endpoints. (#18647)
1 year ago
Derek Menteer b56fbc7a62
[NET-4958] Fix issue where envoy endpoints would fail to populate after snapshot restore (#18636)
1 year ago
Semir Patel b96cff7436
resource: Require scope for resource registration (#18635)
1 year ago
John Maguire 9876923e23
Add the plumbing for APIGW JWT work (#18609)
1 year ago
Semir Patel 7b9e243297
resource: Allow nil tenancy (#18618)
1 year ago
Dhia Ayachi f8d77f027a
delete all v2 resources type when deleting a namespace (CE) (#18621)
1 year ago
Ashvitha 0f48b7af5e
[HCP Telemetry] Move first TelemetryConfig Fetch into the TelemetryConfigProvider (#18318)
1 year ago
Hardik Shingala 58e5658810
Added OpenTelemetry Access Logging Envoy extension (#18336)
1 year ago
Ashwin Venkatesh 797e42dc24
Watch the ProxyTracker from xDS controller (#18611)
1 year ago
John Murret 0e606504bc
NET-4944 - wire up controllers with proxy tracker (#18603)
1 year ago
Joshua Timmons 48c8a834f5
Reduce the frequency of metric exports to minutely (#18584)
1 year ago
Chris S. Kim ecdcde4309
CE commit (#18583)
1 year ago
John Murret 051f250edb
NET-5338 - NET-5338 - Run a v2 mode xds server (#18579)
1 year ago
Semir Patel 2225bf0550
resource: Make resource writestatus tenancy aware (#18577)
1 year ago
John Maguire 59ab57f350
NET-5147: Added placeholder structs for JWT functionality (#18575)
1 year ago
Semir Patel 067a0112e2
resource: Make resource listbyowner tenancy aware (#18566)
1 year ago
Chris S. Kim 82993fcc4f
CE port of enterprise extension (#18572)
1 year ago
cskh b37587bb2c
bug: prevent go routine leakage due to existing DeferCheck (#18558)
1 year ago
R.B. Boyer 8a931241f2
chore: fix missing/incorrect license headers (#18555)
1 year ago
Ashwin Venkatesh 4f9955d91e
Update trust bundle into proxy-state-template (#18550)
1 year ago
Semir Patel 53e28a4963
OSS -> CE (community edition) changes (#18517)
1 year ago
Semir Patel 6d22179625
resource: Make resource watchlist tenancy aware (#18539)
1 year ago
John Murret 217d305b38
NET-4943 - Implement ProxyTracker (#18535)
1 year ago
John Murret 9ea182f6ad
NET-4858 - xds v2 - implement base connect proxy functionality for routes (#18501)
1 year ago
John Murret 92cfb4a07e
NET-4932 - xds v2 - implement base connect proxy functionality for endpoints (#18500)
1 year ago
John Murret b80c5258fa
NET-4853 - xds v2 - implement base connect proxy functionality for clusters (#18499)
1 year ago
Semir Patel e6c1c479b7
resource: Make resource delete tenancy aware (#18476)
1 year ago
Semir Patel 217107f627
resource: Make resource list tenancy aware (#18475)
1 year ago
Nitya Dhanushkodi 6b7ccd06cf
[NET-4799] [OSS] xdsv2: listeners L4 support for connect proxies (#18436)
1 year ago
hashicorp-copywrite[bot] 5fb9df1640
[COMPLIANCE] License changes (#18443)
1 year ago
John Maguire df11e4e7b4
APIGW: Update HTTPRouteConfigEntry for JWT Auth (#18422)
1 year ago
John Maguire 6c8ca0f89d
NET-4984: Update APIGW Config Entries for JWT Auth (#18366)
1 year ago
Michael Zalimeni 05604eeec1
[NET-5217] [OSS] Derive sidecar proxy locality from parent service (#18437)
1 year ago
Semir Patel bee12c6b1f
resource: Make resource write tenancy aware (#18423)
1 year ago
wangxinyi7 facd5b0ec1
fix the error in ent repo (#18421)
1 year ago
sarahalsmiller e235c8be3c
NET-5115 Add retry + timeout filters for api-gateway (#18324)
1 year ago
cskh 43d8898e08
bump testcontainers-go from 0.22.0 and remove pinned go version in in… (#18395)
1 year ago
Semir Patel 63cc037110
resource: Make resource read tenancy aware (#18397)
1 year ago
Ashesh Vidyut 417ae9fc39
Fix #17730 - Dev mode has new line (#18367)
1 year ago
wangxinyi7 1f28ac2664
expose grpc as http endpoint (#18221)
1 year ago
Jeremy Jacobson 8e5e16de60
Fix policy lookup to allow for slashes (#18347)
1 year ago
Dan Stough 284e3bdb54
[OSS] test: xds coverage for routes (#18369)
1 year ago
Ashvitha 828567c62e
[HCP Telemetry] Periodic Refresh for Dynamic Telemetry Configuration (#18168)
1 year ago
Jeremy Jacobson 6424ef6a56
[CC-5719] Add support for builtin global-read-only policy (#18319)
1 year ago
Michael Zalimeni b1b05f0bac
[NET-4703] Prevent partial application of Envoy extensions (#18068)
1 year ago
cui fliter 18a5edd232
docs: Fix some comments (#17118)
1 year ago
Ronald 356b29bf35
Stop JWT provider from being written in non default namespace (#18325)
1 year ago
Florian Apolloner 6ada2e05ff
Fix topology view when displaying mixed connect-native/normal services. (#13023)
1 year ago
Nathan Coleman 5caa0ae3f5
api-gateway: subscribe to bound-api-gateway only after receiving api-gateway (#18291)
1 year ago
cskh 31d2813714
member cli: add -filter expression to flags (#18223)
1 year ago
Dan Stough 8e3a1ddeb6
[OSS] Improve xDS Code Coverage - Endpoints and Misc (#18222)
1 year ago
Jeremy Jacobson 6671d7ebd7
[CC-5718] Remove HCP token requirement during bootstrap (#18140)
1 year ago
Dan Stough 2793761702
[OSS] Improve xDS Code Coverage - Clusters (#18165)
1 year ago
cskh 5cd287660a
docs: fix the description of client rpc (#18206)
1 year ago
Blake Covarrubias 2c5a09bb0a
Explicitly enable WebSocket upgrades (#18150)
1 year ago