Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: security scanner gh token #22060

Draft
wants to merge 201 commits into
base: main
Choose a base branch
from
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
201 commits
Select commit Hold shift + click to select a range
1d05819
Backport of Change the multicluster group to v2 into release/1.18.x (…
hc-github-team-consul-core Feb 1, 2024
379d69d
Backport of Fix typo into release/1.18.x (#20449)
hc-github-team-consul-core Feb 1, 2024
5318873
Backport of Fix SDK iptables.Config marshalling into release/1.18.x (…
hc-github-team-consul-core Feb 2, 2024
9163afe
Backport of missing prefix / into release/1.18.x (#20459)
hc-github-team-consul-core Feb 2, 2024
ef155d2
Backport of Debug failing CICD tests into release/1.18.x (#20463)
hc-github-team-consul-core Feb 2, 2024
f3b80dd
Backport of v2: ensure the controller caches are fully populated befo…
hc-github-team-consul-core Feb 2, 2024
a49f2d0
Backport of catalog: improve the bound workload identity encoding on …
hc-github-team-consul-core Feb 2, 2024
44d1d51
Backport of feat(v2dns): catalog v2 workload query support into relea…
hc-github-team-consul-core Feb 4, 2024
5a2b53b
Backport of internal/hcp: prevent write loop on telemetrystate resour…
hc-github-team-consul-core Feb 5, 2024
0ad0d40
Backport of Fix issue with persisting proxy-defaults into release/1.1…
hc-github-team-consul-core Feb 5, 2024
ddb2987
Manual Backport of Exported services CLI and docs into release/1.18.…
tauhid621 Feb 6, 2024
51419de
Backport of Panic for unregistered types into release/1.18.x (#20504)
hc-github-team-consul-core Feb 6, 2024
d9bedd0
Backport of NET-7631 - Fix Node records that point to external/ non-I…
hc-github-team-consul-core Feb 6, 2024
a118821
Backport of NET-7630 - Fix TXT record creation on node queries into r…
hc-github-team-consul-core Feb 6, 2024
1dcf05d
Backport of add more integration tests into release/1.18.x (#20509)
hc-github-team-consul-core Feb 6, 2024
8d9fdc3
Backport of V1 Compat Exported Services Controller Optimizations into…
hc-github-team-consul-core Feb 7, 2024
19daa99
Backport of add traffic permissions excludes and tests into release/1…
hc-github-team-consul-core Feb 7, 2024
add9380
Backport of [NET-7657] Remove proto definitions for GatewayClass + Ga…
hc-github-team-consul-core Feb 7, 2024
044185e
Backport of [CC-7434] Skip collecting data directory metrics in dev m…
hc-github-team-consul-core Feb 7, 2024
e309d51
Backport of DNS v2 Multiple fixes. into release/1.18.x (#20530)
hc-github-team-consul-core Feb 8, 2024
3ec6faf
Backport of Fix logging when we fail to export metrics to hcp into re…
hc-github-team-consul-core Feb 8, 2024
b8870c4
Backport of Move sameness groups to v2beta1 version into release/1.18…
hc-github-team-consul-core Feb 8, 2024
e72afa6
Backport of Fix: avoid redundant logs on failures to export metrics i…
hc-github-team-consul-core Feb 8, 2024
112201a
Backport of Add default intention policy into release/1.18.x (#20546)
hc-github-team-consul-core Feb 8, 2024
981288e
Backport of NET-7637 / NET-7659/NET-7636/NET-7647/NET-7648/NET-7646/N…
hc-github-team-consul-core Feb 9, 2024
4a22e00
Backport of Decouple xds capacity controller and raft-autopilot into …
hc-github-team-consul-core Feb 9, 2024
4576777
Backport of feat(v2dns): prepared query ttls into release/1.18.x (#20…
hc-github-team-consul-core Feb 9, 2024
8e7814c
Backport of Allow reuse of cache indexes into release/1.18.x (#20567)
hc-github-team-consul-core Feb 9, 2024
ccc3c53
Backport of mesh: add ComputedImplicitDestinations resource for futur…
hc-github-team-consul-core Feb 9, 2024
ac75e94
Backport of docs: Add legacy api gateway deprecation to Consul releas…
hc-github-team-consul-core Feb 9, 2024
1890382
Backport/cc 7146/hcp link item in the nav bar (#20573)
chris-hut Feb 9, 2024
6cc8644
chor: remove temporary CONSUL_HCP_LINK_ENABLED env flag (#20577)
valeriia-ruban Feb 9, 2024
539c5f4
Backport/cc 7147 link to hcp modal/kindly verified snipe manually (#2…
valeriia-ruban Feb 9, 2024
8728d17
Backport of feat(v2dns): catalog v2 service query support into releas…
hc-github-team-consul-core Feb 10, 2024
9191ec6
Backport of set up ent and CE specific DNS tests to be able to run v1…
hc-github-team-consul-core Feb 10, 2024
324c3d8
Backport of use go 1.21.7 into release/1.18.x (#20560)
hc-github-team-consul-core Feb 12, 2024
01bbff3
Backport of Move HCP Manager lifecycle management out of Link control…
hc-github-team-consul-core Feb 12, 2024
5b8e38c
Backport of NET-7644/NET-7634 - Implement query lookup for tagged add…
hc-github-team-consul-core Feb 12, 2024
f5f64e9
Backport of feat(v2dns): enable peering queries into release/1.18.x (…
hc-github-team-consul-core Feb 12, 2024
3a7f0d1
Backport of mesh: use ComputedImplicitDestinations resource in the si…
hc-github-team-consul-core Feb 12, 2024
7a627be
Backport of [NET-7948] Bump Envoy version to address multiple CVEs in…
hc-github-team-consul-core Feb 12, 2024
54532d2
Backport of Updated docs for Consul ECS 0.8.x, architecture, tproxy s…
hc-github-team-consul-core Feb 13, 2024
caf2321
Backport of docs: document behaviour of tls.https.verify_outgoing int…
hc-github-team-consul-core Feb 13, 2024
eb7a11e
Backport of Refactor xTP tests into release/1.18.x (#20616)
hc-github-team-consul-core Feb 13, 2024
013d51f
Backport of [CE] feat(v2dns): add v2 style query metrics into release…
hc-github-team-consul-core Feb 13, 2024
4376f9f
Backport of [NET-7015] DNS v2 + Catalog v2 int test into release/1.18…
hc-github-team-consul-core Feb 13, 2024
c37e51c
Backport of Add BoundReferences to ComputedTrafficPermissions into re…
hc-github-team-consul-core Feb 13, 2024
30f457c
Backport of [CC-7411] Fix environment variable precedence when linkin…
hc-github-team-consul-core Feb 13, 2024
69e7c4d
Backport of Update ComputedTrafficPermissions ACL hooks into release/…
hc-github-team-consul-core Feb 13, 2024
bb932fd
Backport/link to hcp modal error when acls disabled/severely cool spa…
valeriia-ruban Feb 13, 2024
c475b8c
Backport of [CE] Misc cleanup for V2 DNS into release/1.18.x (#20641)
hc-github-team-consul-core Feb 14, 2024
f986506
Backport of Ensure all topics are refreshed on FSM restore and add su…
hc-github-team-consul-core Feb 14, 2024
00a3f24
Backport of fix(v2dns): add node ttl to workloads, comment cleanup, a…
hc-github-team-consul-core Feb 15, 2024
4532ba6
Backport of chor: change cluster name param to have datacenter.name a…
hc-github-team-consul-core Feb 15, 2024
e8d5ccd
[CE] fix(v2dns): allow secondary datacenters (#20657)
DanStough Feb 15, 2024
f969ed4
Backport of Add enterprise docs for deny action into release/1.18.x (…
hc-github-team-consul-core Feb 16, 2024
90024f7
Backport of [NET-6741] make: Add target for updating dependencies acr…
hc-github-team-consul-core Feb 21, 2024
b76388b
Backport of feat: add alert to link to hcp modal to ask a user refres…
hc-github-team-consul-core Feb 21, 2024
1309b6a
Backport of NET-7813 - DNS : SERVFAIL when resolving PTR records into…
hc-github-team-consul-core Feb 21, 2024
7e18797
Backport of docs: GKE Autopilot section into release/1.18.x (#20700)
hc-github-team-consul-core Feb 22, 2024
7fe72df
Backport of Fix malformed MDX in install-k8s into release/1.18.x (#20…
hc-github-team-consul-core Feb 22, 2024
17e8e63
Backport of docs: format API GW tab docs into release/1.18.x (#20709)
hc-github-team-consul-core Feb 22, 2024
971a687
Backport of revert grpc to http into release/1.18.x (#20718)
hc-github-team-consul-core Feb 23, 2024
7eb2496
Backport of [NET-7713] docs: Update v2 K8s docs to use virtual port r…
hc-github-team-consul-core Feb 26, 2024
c5dcba0
Backport of Update API and API Docs regarding disabling gossip for a …
hc-github-team-consul-core Feb 26, 2024
72dbd17
Backport of Use correct enterprise meta on wildcard service update in…
hc-github-team-consul-core Feb 26, 2024
ec37ceb
Backport of docs: Add Consul Enterprise LTS docs into release/1.18.x …
hc-github-team-consul-core Feb 26, 2024
c38a328
Update VERSION for release/1.18.x (#20745)
sarahalsmiller Feb 28, 2024
7514545
Backport of Fix audit-log encoding issue (CC-7337) into release/1.18.…
hc-github-team-consul-core Feb 28, 2024
686ec2f
Backport of docs: v2 and multiport updates for v1.18 into release/1.1…
hc-github-team-consul-core Feb 28, 2024
1001f9c
Backport of docs: v1.18 Consul release notes into release/1.18.x (#20…
hc-github-team-consul-core Feb 28, 2024
1f458b4
Backport of docs: Update release notes for 1.18.x into release/1.18.x…
hc-github-team-consul-core Feb 28, 2024
be15e9f
Backport of docs: add 1.18.0 release date into release/1.18.x (#20755)
hc-github-team-consul-core Feb 28, 2024
9659e85
docs: v2 backport manual fix (#20752)
boruszak Feb 28, 2024
5ab6bd6
Backport of docs: Update v2 Catalog API note to re-iterate beta and a…
hc-github-team-consul-core Feb 28, 2024
2a1f2ad
Backport of docs: Consul on Nomad overview into release/1.18.x (#20760)
hc-github-team-consul-core Feb 29, 2024
c8c72e2
Backport of Retract [email protected] into release/1.18.x (#20763)
hc-github-team-consul-core Feb 29, 2024
a9c4096
Backport of docs: update Helm docs for consul-k8s 1.4.0 into release/…
hc-github-team-consul-core Feb 29, 2024
661fa1a
Backport of docs: Fix version typo in consul-k8s v1.3.x release notes…
hc-github-team-consul-core Mar 1, 2024
6ab2b79
Backport of docs: consul-k8s v1.4.0 release notes into release/1.18.x…
hc-github-team-consul-core Mar 1, 2024
9496055
Backport of docs: 1.18.x cleanup into release/1.18.x (#20775)
hc-github-team-consul-core Mar 1, 2024
72c62fc
Backport of Johnlanda/fault injection docs into release/1.18.x (#20776)
hc-github-team-consul-core Mar 1, 2024
c318c0c
Backport of NET-8056 - v2 DNS Testing Improvements into release/1.18.…
hc-github-team-consul-core Mar 1, 2024
43b5ed1
Backport of DNS v2 - split up router into multiple responsibilities &…
hc-github-team-consul-core Mar 1, 2024
161f240
Hardcode links to CCM to be false - due to CCM deprecation (#20784)
chris-hut Mar 1, 2024
52a1cc9
Backport of Enable callers to control whether per-tenant usage metric…
hc-github-team-consul-core Mar 1, 2024
6c7f22c
Backport of Fix typos in route retry filter docs for APIGW into relea…
hc-github-team-consul-core Mar 1, 2024
68ddfc1
docs: manual backport of relnotes (#20785)
Mar 1, 2024
288bd39
Backport of docs: Update OpenShift compat matrix into release/1.18.x …
hc-github-team-consul-core Mar 1, 2024
6afa71c
Backport of add raw delete api method into release/1.18.x (#20797)
hc-github-team-consul-core Mar 5, 2024
25cf32b
Backport of docs: update 1.4.0 Helm docs with Docs team feedback into…
hc-github-team-consul-core Mar 6, 2024
27665e2
Backport of [NET-8367] security: upgrade google.golang.org/protobuf t…
hc-github-team-consul-core Mar 6, 2024
4e3eefe
Backport of docs: Update GKE Autopliot docs into release/1.18.x (#20818)
hc-github-team-consul-core Mar 7, 2024
f7dbd28
Backport of docs: K8s docs cleanup into release/1.18.x (#20828)
hc-github-team-consul-core Mar 11, 2024
01aba95
Backport of Fix typo in ingress-gateway docs into release/1.18.x (#20…
hc-github-team-consul-core Mar 12, 2024
a91042e
Backport of docs: document support for multiple snapshot destinations…
hc-github-team-consul-core Mar 12, 2024
2b7bc14
Backport of Add API gateway to index of configuration entries into re…
hc-github-team-consul-core Mar 13, 2024
98cce1f
Backport of [NET-8368] security: bump Go version to 1.21.8 into relea…
hc-github-team-consul-core Mar 14, 2024
fbe7dee
Backport of docs: Update release notes for 1.17.x for legacy api gate…
hc-github-team-consul-core Mar 14, 2024
0983686
Backport of K8s v1 Multiport documentation indentation updates into r…
hc-github-team-consul-core Mar 14, 2024
634f6b3
Backport of docs: clarify LTS language into release/1.18.x (#20877)
hc-github-team-consul-core Mar 18, 2024
5e75877
Backport of Fix typo in example yaml for MeshService into release/1.1…
hc-github-team-consul-core Mar 19, 2024
bf51d89
Backport of Update go-jose library into release/1.18.x (#20891)
hc-github-team-consul-core Mar 22, 2024
5948255
Backport of Add docs for default_intention_policy into release/1.18.x…
hc-github-team-consul-core Mar 25, 2024
3171fd8
Backport of security: triage false positive for go-jose/v3 into relea…
hc-github-team-consul-core Mar 26, 2024
16ea523
update changelog and version (#20913)
xwa153 Mar 27, 2024
a271771
Backport of Update Dockerfile: bump alpine into release/1.18.x (#20917)
hc-github-team-consul-core Mar 27, 2024
c78f138
Backport of Update Dockerfile: Base image for dev bump into release/1…
hc-github-team-consul-core Mar 28, 2024
2eb5d24
Backport of GH-20889 - put conditionals are hcp initialization for co…
hc-github-team-consul-core Mar 28, 2024
f1ef0cd
Backport of fix broken link on sameness groups page into release/1.18…
hc-github-team-consul-core Mar 28, 2024
71f00e6
Backport of chore: remove repetitive words into release/1.18.x (#20934)
hc-github-team-consul-core Mar 29, 2024
dc4b69b
Backport of remove self-referencing link on network segments page int…
hc-github-team-consul-core Apr 1, 2024
1eb243f
Backport of Documentation: update python SDKs list into release/1.18.…
hc-github-team-consul-core Apr 2, 2024
f1fdeba
Backport of Consul Kubernetes Datadog Integration Docs Update into re…
hc-github-team-consul-core Apr 3, 2024
0e62661
Backport of [NET-5772] Make tcp external service registered on termin…
hc-github-team-consul-core Apr 3, 2024
6ac4781
Backport of docs: fix apply DNS ACL token via CLI into release/1.18.x…
hc-github-team-consul-core Apr 3, 2024
5e9f438
Backport of NET-8524 Remove registation of api gateway controller int…
hc-github-team-consul-core Apr 4, 2024
aa534eb
Backport of security: bump go, x/net and envoy versions into release/…
dduzgun-security Apr 8, 2024
adc28c1
Backport of ci: fix Envoy int test versions into release/1.18.x (#20968)
hc-github-team-consul-core Apr 8, 2024
97e1621
Backport of security: ignore test and internal tool modules into rele…
hc-github-team-consul-core Apr 8, 2024
c4c1d70
Backport of docs: wrong indentation of to block in example yaml into …
hc-github-team-consul-core Apr 11, 2024
003d753
Backport of fix: consume ignored entries in CE downgrade via Ent snap…
hc-github-team-consul-core Apr 12, 2024
07e3c1e
Backport of test: force IPv4 on Docker 26+ to fix Envoy int tests int…
hc-github-team-consul-core Apr 17, 2024
6e45dfe
Backport of docs: KV tutorial becomes usage doc into release/1.18.x (…
hc-github-team-consul-core Apr 18, 2024
d0b964c
Backport of docs: Initial HCP Rebrand into release/1.18.x (#21002)
hc-github-team-consul-core Apr 22, 2024
be09ab3
Backport of docs: Redirect fix into release/1.18.x (#21009)
hc-github-team-consul-core Apr 23, 2024
2b19231
Backport of Net 6820 customize mesh gateway limits into release/1.18.…
hc-github-team-consul-core Apr 23, 2024
90aed5f
Backport of docs: Enterprise upgrade instruction into release/1.18.x …
hc-github-team-consul-core Apr 24, 2024
6b58a85
Backport of docs: DNS caching tutorial becomes doc into release/1.18.…
hc-github-team-consul-core Apr 24, 2024
e0d46f7
Backport of NET-6821 Disable Terminating Gateway Auto Host Header Rew…
hc-github-team-consul-core Apr 26, 2024
60f4644
Backport of HCP Consul Dedicated Rebrand changes into release/1.18.x …
hc-github-team-consul-core May 1, 2024
8da1b65
Backport of security: bump envoy version and k8s.io/apimachinery into…
dduzgun-security May 2, 2024
e0e68f8
Backport of deployer: ensure the proxy/dns/pause containers do not co…
hc-github-team-consul-core May 3, 2024
e263a09
Backport of add license file into release/1.18.x (#21049)
hc-github-team-consul-core May 3, 2024
a08bcba
Backport of security: fine-tune release scanner and bump coredns into…
hc-github-team-consul-core May 4, 2024
537b50e
Backport of [NET-9098] Narrow scope of peering config on terminating …
hc-github-team-consul-core May 6, 2024
8341e96
Backport of [NET-9141] ci: skip LICENSE copy for Ent linux packages i…
hc-github-team-consul-core May 7, 2024
c52e8fa
Backport of security: Upgrade Go to 1.21.10 into release/1.18.x (#21077)
hc-github-team-consul-core May 9, 2024
8d167ee
Backport of NET-9143 - sameness group queries in DNS do not respect D…
hc-github-team-consul-core May 13, 2024
a15c9c3
Backport of [NET-8601] security: upgrade vault/api to remove go-jose.…
hc-github-team-consul-core May 14, 2024
a683be0
Backport of docs: Fix docs for `-ui-content-path` CLI flag into relea…
hc-github-team-consul-core May 14, 2024
8145cf0
Backport of docs: fix typo in security/acl into release/1.18.x (#21086)
hc-github-team-consul-core May 14, 2024
4c9a4aa
Backport of docs: Add fault injection to Envoy extensions list into r…
hc-github-team-consul-core May 14, 2024
6716981
Backport of Fixed broken link in the ECS documentation into release/1…
hc-github-team-consul-core May 14, 2024
fd6d38e
Backport of build: update gha to latest approved tsccr into release/1…
hc-github-team-consul-core May 14, 2024
e0bbab1
changelog and version (#21105)
xwa153 May 15, 2024
dee6352
regen UI (#21114)
sarahalsmiller May 15, 2024
6ba275d
1.18 UI regen (#21115)
sarahalsmiller May 15, 2024
68ede1c
1.18 UI regen (#21117)
sarahalsmiller May 15, 2024
20a6498
latest ui files in release/1.18.x (#21121)
jmurret May 16, 2024
aa0df1c
revert to previous working version (#21124)
sarahalsmiller May 16, 2024
0266519
try with release engineering optional clean flag (#21126)
sarahalsmiller May 16, 2024
8775caa
Release use releng branch (#21127)
sarahalsmiller May 16, 2024
945d14b
Backport of upgrade deep-copy version, upgrade go to 1.22.3 into rele…
hc-github-team-consul-core May 16, 2024
4c3d699
Backport of docs: Fix two small typos in "What is Consul?" introducti…
hc-github-team-consul-core May 17, 2024
52fe1fb
Backport of docs: FIPS certification into release/1.18.x (#21140)
hc-github-team-consul-core May 20, 2024
51f2470
Backport of docs: Well Architected Framework content migration into r…
hc-github-team-consul-core May 20, 2024
44b3290
Backport of Doc added for Version specific upgrade Consul on Kubernet…
hc-github-team-consul-core May 20, 2024
7aecdad
Backport of chore: fix PR Labeler config into release/1.18.x (#21144)
hc-github-team-consul-core May 21, 2024
1dffeff
Backport of set go toolchain to go1.22.3 into release/1.18.x (#21196)
hc-github-team-consul-core May 21, 2024
7206714
Update VERSION in release/1.18.x (#21133)
sarahalsmiller May 22, 2024
096eb9f
docs: WAF backport correction (#21201)
boruszak May 22, 2024
30ee5a2
Backport of docs: Fix spelling errors into release/1.18.x (#21207)
hc-github-team-consul-core May 23, 2024
5f83df6
Backport of security: enable go stdlib scans into release/1.18.x (#21…
hc-github-team-consul-core May 23, 2024
c5fec4d
Backport of docs: relocate Consul capacity planning page from waf/ to…
hc-github-team-consul-core May 24, 2024
3b3c028
Backport of [NET-9510] Document known OpenShift issue for consul-k8s …
hc-github-team-consul-core May 28, 2024
14a6d11
Backport of docs: Fix heading errors in security models into release/…
hc-github-team-consul-core May 29, 2024
520f404
Backport of update TestHTTPHandlers_AgentMetrics_LeaderShipMetrics to…
hc-github-team-consul-core Jun 3, 2024
d346c6f
Backport of [NET-8953] docs: add backport policy section to CONTRIBUT…
hc-github-team-consul-core Jun 4, 2024
e2a8f64
Backport of Fixes annotation and introduce tabs for static-client spe…
hc-github-team-consul-core Jun 4, 2024
70e89d7
Backport of docs: add a note for DNS resolver recommendations into re…
hc-github-team-consul-core Jun 4, 2024
1986f1e
Backport of security: resolve incorrect type conversions into release…
hc-github-team-consul-core Jun 5, 2024
4d0fdf6
Backport of [NET-8971] docs: update LTS Envoy versions to include 1.2…
hc-github-team-consul-core Jun 6, 2024
1c1de88
Backport of update go version to 1.22.4 into release/1.18.x (#21268)
hc-github-team-consul-core Jun 7, 2024
8cb2e62
Backport of Bump Envoy Versions into release/1.18.x (#21290)
hc-github-team-consul-core Jun 10, 2024
ab888c3
Backport of Use text/template instead of html/template for ACL templa…
hc-github-team-consul-core Jun 11, 2024
405bf5d
Backport of Configure linter to forbid use of html/template into rele…
hc-github-team-consul-core Jun 14, 2024
0c3bacc
Backport of docs: simplify Envoy version support docs into release/1.…
zalimeni Jun 17, 2024
89a30bd
manual backport of updating jwt docs (#21610)
jm96441n Aug 15, 2024
606064b
docs: Update compatibility.mdx for OpenShift (1.18.x) (#21601)
zalimeni Aug 16, 2024
a18d72e
backport of commit d899808cc2f2afded3872834ded8a04060d29278 (#21629)
jm96441n Aug 20, 2024
c05bd5f
Backport of add build support script to print out the submodule versi…
jmurret Aug 22, 2024
f900aef
pull over Validate_Clusters to api package in 1.18.x (#21634)
jmurret Aug 22, 2024
a99a0fe
revert change to website/content/docs/connect/config-entries/mesh.mdx…
jmurret Aug 22, 2024
9392f01
Updating go.mods in release/1.18.x after modules have been released. …
jmurret Aug 23, 2024
07eed10
Update 1.18.x after re-publishing modules (#21663)
jmurret Aug 26, 2024
e7d651b
Manual backport for docs/WAF: failure zones refresh (#21545) (#21651)
boruszak Aug 26, 2024
a9d342a
Backport of run integration tests on push in main and release/* into …
jmurret Aug 26, 2024
5a37661
post-1.18.4 - update changelog and version in 1.18.x (#21678)
jmurret Aug 28, 2024
acf27d6
Backport of Docs CE-709: Remove circular links (#21685) into release/…
aimeeu Aug 29, 2024
5cf67ba
[release/1.18.x] autogenerate helm docs (#21698)
ndhanushkodi Sep 9, 2024
965ebfb
[ui] Regenerate yarn lockfile for 1.18 and lower versions (#21714)
philrenaud Sep 13, 2024
9e67115
[NET-1151 NET-11228] api: Add fields for HTTP request normalization a…
zalimeni Oct 17, 2024
a40e02c
Manual backport of api: remove dependency on proto-public, protobuf, …
zalimeni Oct 17, 2024
b53c1dd
[NET-1151 NET-11046] docs: Add request normalization, L7 headers opti…
zalimeni Oct 28, 2024
ca37fac
Backport of docs: clarify Envoy and dataplane LTS support policy into…
zalimeni Oct 28, 2024
75a36ac
backport to 1.18.x - centos logic to point to vault.centos.org for ce…
jmurret Oct 30, 2024
703641c
fix verify_artifact call to verify_rpm (#21894)
jm96441n Oct 30, 2024
e694ba9
update changelogs (#21899)
jm96441n Oct 30, 2024
f0a49fd
bump version (#21906)
jm96441n Oct 31, 2024
e491444
fix: security scanner gh token
abhishek-hashicorp Jan 7, 2025
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
3 changes: 3 additions & 0 deletions .changelog/19881.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
xds: Make TCP external service registered with terminating gateway reachable from peered cluster
```
3 changes: 3 additions & 0 deletions .changelog/20331.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:feature
cli: Adds new command `exported-services` to list all services exported and their consumers. Refer to the [CLI docs](https://developer.hashicorp.com/consul/commands/exported-services) for more information.
```
3 changes: 3 additions & 0 deletions .changelog/20345.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
audit-logs: **(Enterprise Only)** Fixes non ASCII characters in audit logs because of gzip.
```
3 changes: 3 additions & 0 deletions .changelog/20474.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:breaking-change
ui: Adds a "Link to HCP Consul Central" modal with integration to side-nav and link to HCP banner. There will be an option to disable the Link to HCP banner from the UI in a follow-up release.
```
3 changes: 3 additions & 0 deletions .changelog/20481.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
connect: Fix issue where re-persisting existing proxy-defaults using `http` protocol fails with a protocol-mismatch error.
```
3 changes: 3 additions & 0 deletions .changelog/20511.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
connect: Remove code coupling where the xDS capacity controller could negatively affect raft autopilot performance.
```
3 changes: 3 additions & 0 deletions .changelog/20544.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:feature
agent: Introduces a new agent config default_intention_policy to decouple the default intention behavior from ACLs
```
3 changes: 3 additions & 0 deletions .changelog/20545.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:improvement
Upgrade to use Go 1.21.7.
```
3 changes: 3 additions & 0 deletions .changelog/20589.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:security
mesh: Update Envoy versions to 1.28.1, 1.27.3, and 1.26.7 to address [CVE-2024-23324](https://github.com/envoyproxy/envoy/security/advisories/GHSA-gq3v-vvhj-96j6), [CVE-2024-23325](https://github.com/envoyproxy/envoy/security/advisories/GHSA-5m7c-mrwr-pm26), [CVE-2024-23322](https://github.com/envoyproxy/envoy/security/advisories/GHSA-6p83-mfmh-qv38), [CVE-2024-23323](https://github.com/envoyproxy/envoy/security/advisories/GHSA-x278-4w4x-r7ch), [CVE-2024-23327](https://github.com/envoyproxy/envoy/security/advisories/GHSA-4h5x-x9vh-m29j), and [CVE-2023-44487](https://github.com/envoyproxy/envoy/security/advisories/GHSA-jhv4-f7mr-xx76)
```
7 changes: 7 additions & 0 deletions .changelog/20642.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
```release-note:bug
server: Ensure internal streams are properly terminated on snapshot restore.
```

```release-note:bug
server: Ensure controllers are automatically restarted on internal stream errors.
```
7 changes: 7 additions & 0 deletions .changelog/20643.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
```release-note:feature
dns: adds experimental support for a refactored DNS server that is v1 and v2 Catalog compatible.
Use `v2dns` in the `experiments` agent config to enable.
It will automatically be enabled when using the `resource-apis` (Catalog v2) experiment.
The new DNS implementation will be the default in Consul 1.19.
See the [Consul 1.18.x Release Notes](https://developer.hashicorp.com/consul/docs/release-notes/consul/v1_18_x) for deprecated DNS features.
```
3 changes: 3 additions & 0 deletions .changelog/20669.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:improvement
partitions: **(Enterprise only)** Allow disabling of Gossip per Partition
```
3 changes: 3 additions & 0 deletions .changelog/20672.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note: improvement
xds: Improved the performance of xDS server side load balancing. Its slightly improved in Consul CE with drastic CPU usage reductions in Consul Enterprise.
```
3 changes: 3 additions & 0 deletions .changelog/20679.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
dns: SERVFAIL when resolving not found PTR records.
```
3 changes: 3 additions & 0 deletions .changelog/20801.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:security
Update `google.golang.org/protobuf` to v1.33.0 to address [CVE-2024-24786](https://nvd.nist.gov/vuln/detail/CVE-2024-24786).
```
3 changes: 3 additions & 0 deletions .changelog/20802.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:improvement
connect: Add ability to disable Auto Host Header Rewrite on Terminating Gateway at the service level
```
14 changes: 14 additions & 0 deletions .changelog/20812.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
```release-note:security
Upgrade to use Go `1.21.8`. This resolves CVEs
[CVE-2024-24783](https://nvd.nist.gov/vuln/detail/CVE-2024-24783) (`crypto/x509`).
[CVE-2023-45290](https://nvd.nist.gov/vuln/detail/CVE-2023-45290) (`net/http`).
[CVE-2023-45289](https://nvd.nist.gov/vuln/detail/CVE-2023-45289) (`net/http`, `net/http/cookiejar`).
[CVE-2024-24785](https://nvd.nist.gov/vuln/detail/CVE-2024-24785) (`html/template`).
[CVE-2024-24784](https://nvd.nist.gov/vuln/detail/CVE-2024-24784) (`net/mail`).
```

```release-note:security
Update the Consul Build Go base image to `alpine3.19`. This resolves CVEs
[CVE-2023-52425](https://nvd.nist.gov/vuln/detail/CVE-2023-52425)
[CVE-2023-52426⁠](https://nvd.nist.gov/vuln/detail/CVE-2023-52426)
```
3 changes: 3 additions & 0 deletions .changelog/20897.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:security
Bump Dockerfile base image to `alpine:3.19`.
```
4 changes: 4 additions & 0 deletions .changelog/20910.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
```release-note:security
Update `vault/api` to v1.12.2 to address [CVE-2024-28180](https://nvd.nist.gov/vuln/detail/CVE-2024-28180)
(removes indirect dependency on impacted `go-jose.v2`)
```
3 changes: 3 additions & 0 deletions .changelog/20926.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
error running consul server in 1.18.0: failed to configure SCADA provider user's home directory path: $HOME is not defined
```
3 changes: 3 additions & 0 deletions .changelog/20945.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:enhancement
gateways: service defaults configuration entries can now be used to set default upstream limits for mesh-gateways
```
14 changes: 14 additions & 0 deletions .changelog/20956.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
```release-note:security
Upgrade to use Go `1.21.9`. This resolves CVE
[CVE-2023-45288](https://nvd.nist.gov/vuln/detail/CVE-2023-45288) (`http2`).
```

```release-note:security
Upgrade to support Envoy `1.26.8, 1.27.4, and 1.28.2`. This resolves CVE
[CVE-2024-27919](https://nvd.nist.gov/vuln/detail/CVE-2024-27919) (`http2`).
```

```release-note:security
Upgrade to use golang.org/x/net `v0.24.0`. This resolves CVE
[CVE-2023-45288](https://nvd.nist.gov/vuln/detail/CVE-2023-45288) (`x/net`).
```
3 changes: 3 additions & 0 deletions .changelog/20977.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
server: fix Ent snapshot restore on CE when CE downgrade is enabled
```
9 changes: 9 additions & 0 deletions .changelog/21034.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
```release-note:security
Upgrade to support Envoy `1.27.5 and 1.28.3`. This resolves CVE
[CVE-2024-32475](https://nvd.nist.gov/vuln/detail/CVE-2024-32475) (`auto_sni`).
```

```release-note:security
Upgrade to support k8s.io/apimachinery `v0.18.7 or higher`. This resolves CVE
[CVE-2020-8559](https://nvd.nist.gov/vuln/detail/CVE-2020-8559).
```
5 changes: 5 additions & 0 deletions .changelog/21074.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
```release-note:security
Upgrade Go to use 1.21.10. This addresses CVEs
[CVE-2024-24787](https://nvd.nist.gov/vuln/detail/CVE-2024-24787) and
[CVE-2024-24788](https://nvd.nist.gov/vuln/detail/CVE-2024-24788)
```
3 changes: 3 additions & 0 deletions .changelog/21113.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:enhancement
upgrade go version to v1.22.3.
```
3 changes: 3 additions & 0 deletions .changelog/21251.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
core: Fix multiple incorrect type conversion for potential overflows
```
3 changes: 3 additions & 0 deletions .changelog/21265.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:enhancement
upgrade go version to v1.22.4.
```
3 changes: 3 additions & 0 deletions .changelog/21277.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:enhancement
mesh: update supported envoy version 1.28.4 and 1.27.6.
```
3 changes: 3 additions & 0 deletions .changelog/21780.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:improvement
api: remove dependency on proto-public, protobuf, and grpc
```
3 changes: 3 additions & 0 deletions .changelog/_20721.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
ingress-gateway: **(Enterprise Only)** Fix a bug where on update, Ingress Gateways lost all upstreams for listeners with wildcard services in a different namespace.
```
19 changes: 13 additions & 6 deletions .github/CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -156,13 +156,16 @@ When you're ready to submit a pull request:
5. If there's any reason Consul users might need to know about this change,
[add a changelog entry](../docs/contributing/add-a-changelog-entry.md).
6. Add labels to your pull request. A table of commonly use labels is below.
If you have any questions about which to apply, feel free to call it out in the PR or comments.
| Label | When to Use |
| --- | --- |
| `pr/no-changelog` | This PR does not have an intended changelog entry |
If you have any questions about which to apply, feel free to call it out in the PR or comments. Other labels may automatically be added by GitHub Actions CI.

| Label | When to Use |
|----------------------| --- |
| `pr/no-changelog` | This PR does not have an intended changelog entry |
| `pr/no-backport` | This PR does not have an intended backport target |
| `pr/no-metrics-test` | This PR does not require any testing for metrics |
| `backport/1.12.x` | Backport the changes in this PR to the targeted release branch. Consult the [Consul Release Notes](https://www.consul.io/docs/release-notes) page to view active releases. Website documentation merged to the latest release branch is deployed immediately |
Other labels may automatically be added by the Github Action CI.
| `backport/1.12.x` | Backport the changes in this PR to the targeted release branch. Consult the [Consul Release Notes](https://www.consul.io/docs/release-notes) page and [`versions.hcl`](/.release/versions.hcl) to view active releases. Website documentation merged to the latest release branch is deployed immediately. See [backport policy](#backport-policy) for more information. |
| `backport/all` | If contributing a bug fix or other change applicable to all branches, use `backport/all` to target all active branches automatically. See [backport policy](#backport-policy) for more information. |

7. After you submit, the Consul maintainers team needs time to carefully review your
contribution and ensure it is production-ready, considering factors such as: security,
backwards-compatibility, potential regressions, etc.
Expand All @@ -174,6 +177,10 @@ When you're ready to submit a pull request:
Assuming the tests pass, the PR will be merged automatically.
If the tests fail, it is you responsibility to resolve the issues with backports and request another reviewer.

### Backport Policy

Consul is maintained as a Community Edition (CE) and an Enterprise product. Bug fixes and patches may be backported to the current major release in CE. In Enterprise, bug fixes and patches may be backported to all maintained releases: the N-2 releases and the 2 latest Long-Term Support (LTS) releases. For more information, refer to Consul’s [LTS documentation](https://developer.hashicorp.com/consul/docs/enterprise/long-term-support).

#### Checklists

Some common changes that many PRs require are documented through checklists as
Expand Down
94 changes: 68 additions & 26 deletions .github/pr-labeler.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,65 +2,107 @@
# SPDX-License-Identifier: BUSL-1.1

pr/dependencies:
- vendor/**/*
- go.*
- changed-files:
- any-glob-to-any-file:
- vendor/**/*
- go.*
theme/acls:
- acl/**/*
- changed-files:
- any-glob-to-any-file:
- acl/**/*
theme/agent-cache:
- agent/cache/**/*
- changed-files:
- any-glob-to-any-file:
- agent/cache/**/*
theme/api:
- api/**/*
- changed-files:
- any-glob-to-any-file:
- api/**/*
theme/catalog:
- agent/catalog/**/*
- changed-files:
- any-glob-to-any-file:
- agent/catalog/**/*
theme/certificates:
- tlsutil/**/*
- changed-files:
- any-glob-to-any-file:
- tlsutil/**/*
theme/cli:
- command/**/*
- changed-files:
- any-glob-to-any-file:
- command/**/*
theme/config:
- agent/config/**/*
- changed-files:
- any-glob-to-any-file:
- agent/config/**/*
theme/connect:
- connect/**/*
- agent/connect/**/*
- changed-files:
- any-glob-to-any-file:
- connect/**/*
- agent/connect/**/*
# theme/consul-nomad:
theme/consul-terraform-sync:
- website/content/docs/nia/**/*
- website/content/docs/integrate/nia*
- changed-files:
- any-glob-to-any-file:
- website/content/docs/nia/**/*
- website/content/docs/integrate/nia*
# theme/consul-vault:
theme/contributing:
- .github/**/*
- changed-files:
- any-glob-to-any-file:
- .github/**/*
theme/dns:
- dns/**/*
- changed-files:
- any-glob-to-any-file:
- dns/**/*
theme/envoy/xds:
- agent/xds/**/*
- changed-files:
- any-glob-to-any-file:
- agent/xds/**/*
# theme/federation-usability:
theme/health-checks:
- agent/health*
- api/health*
- changed-files:
- any-glob-to-any-file:
- agent/health*
- api/health*
# theme/ingress-gw:
# theme/internal-cleanup:
theme/internals:
- lib/**/*
- types/**/*
- changed-files:
- any-glob-to-any-file:
- lib/**/*
- types/**/*
# theme/kubernetes:
# theme/mesh-gw:
# theme/operator-usability:
# theme/performance:
# theme/service-metadata:
# theme/streaming:
theme/telemetry:
- logging/**/*
- changed-files:
- any-glob-to-any-file:
- logging/**/*
# theme/terminating-gw:
theme/testing:
- ./*test*/**/*
- changed-files:
- any-glob-to-any-file:
- ./*test*/**/*
theme/tls:
- tlsutil/**/*
- changed-files:
- any-glob-to-any-file:
- tlsutil/**/*
theme/ui:
- ui/**/*
- changed-files:
- any-glob-to-any-file:
- ui/**/*
# theme/windows:
# thinking:
# type/bug:
type/ci:
- .github/workflows/*
- changed-files:
- any-glob-to-any-file:
- .github/workflows/*
# type/crash:
type/docs:
- website/**/*
- changed-files:
- any-glob-to-any-file:
- website/**/*
3 changes: 2 additions & 1 deletion .github/scripts/verify_artifact.sh
Original file line number Diff line number Diff line change
Expand Up @@ -102,7 +102,8 @@ function verify_rpm {
${docker_image} \
/scripts/verify_rpm.sh \
"/workdir/${artifact_path}" \
"${expect_version}"
"${expect_version}" \
"${docker_image}"
}

# Arguments:
Expand Down
17 changes: 17 additions & 0 deletions .github/scripts/verify_rpm.sh
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,10 @@ set -euo pipefail
# report why it failed. This is meant to be run as part of the build workflow to verify the built
# .rpm meets some basic criteria for validity.

# Notably, CentOS 7 is EOL, so we need to point to the vault for updates. It's not clear what alternative
# we may use in the future that supports linux/386 as the platform was dropped in CentOS 8+9. The docker_image
# is passed in as the third argument so that the script can determine if it needs to point to the vault for updates.

# set this so we can locate and execute the verify_bin.sh script for verifying version output
SCRIPT_DIR="$( cd -- "$(dirname "$0")" >/dev/null 2>&1 ; pwd -P )"

Expand All @@ -20,6 +24,7 @@ function usage {
function main {
local rpm_path="${1:-}"
local expect_version="${2:-}"
local docker_image="${3:-}"
local got_version

if [[ -z "${rpm_path}" ]]; then
Expand All @@ -34,6 +39,12 @@ function main {
exit 1
fi

if [[ -z "${docker_image}" ]]; then
echo "ERROR: docker image argument is required"
usage
exit 1
fi

# expand globs for path names, if this fails, the script will exit
rpm_path=$(echo ${rpm_path})

Expand All @@ -43,6 +54,12 @@ function main {
exit 1
fi

# CentOS 7 is EOL, so we need to point to the vault for updates
if [[ "$docker_image" == *centos:7 ]]; then
sed -i 's/mirrorlist/#mirrorlist/g' /etc/yum.repos.d/CentOS-*
sed -i 's|#baseurl=http://mirror.centos.org|baseurl=http://vault.centos.org|g' /etc/yum.repos.d/CentOS-*
fi

yum -y clean all
yum -y update
yum -y install which openssl
Expand Down
Loading
Loading