NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #77 by repository stars
Last release 3 days ago
01 Oct 2026
Ships on a steady schedule
a new release about every 9 days
Nearly every release is documented
notes for 56 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
12396 releases · first in 2013
cli: consul operator raft list-peers command shows the number of commits each follower is trailing the leader by to aid in troubleshooting. [GH-17582]
FEATURES:
consul operator raft list-peers command shows the number of commits each follower is trailing the leader by to aid in troubleshooting. [GH-17582]IMPROVEMENTS:
BUG FIXES:
PUT /acl/token/:AccessorID (update token), no longer requires AccessorID in the request body. Web UI can now update tokens. [GH-17739]One column per quarter.
…set to outbound in extension configuration. See CVE-2023-2816 changelog entry for more details. [GH-17415]
BREAKING CHANGES:
SECURITY:
go/scanner),
CVE-2023-24538(html/template),
CVE-2023-24534(net/textproto) and
CVE-2023-24536(mime/multipart).
Also, golang.org/x/net has been updated to v0.7.0 to resolve CVEs CVE-2022-41721
, CVE-2022-27664 and [CVE-2022-41723
](https://github.com/advisories/GHSA-vvpx-j8f3-3w6h
.) [GH-17240]FEATURES:
IMPROVEMENTS:
MaxEjectionPercent and BaseEjectionTime to passive health check configs. [GH-15979]agent.server.snapshot to agent.server.raft.snapshot [GH-17236]BUG FIXES:
reflect: call of reflect.Value.Type on zero Value. [GH-17048]api module representation of a namespace.
This fixes an error with the consul namespace list command when a namespace has a deferred deletion timestamp.xds: Allow for configuring connect proxies to send service mesh telemetry to an HCP metrics collection service. [GH-16585]
FEATURES:
BUG FIXES:
/agent/monitor and /agent/metrics endpoints return a Streaming not supported error when audit logs are enabled. This also fixes the delay receiving logs when running consul monitor against an agent with audit logs enabled. [GH-16700]service:write access in the default namespace to query data, which was too restrictive. Now having service:write to any namespace is sufficient to query the peering data.cli: Deprecate the -merge-node-identites and -merge-service-identities flags from the consul token update command in favor of: -append-node-identity a…
IMPROVEMENTS:
-append-policy-id, -append-policy-name, -append-role-name, and -append-role-id flags to the consul token update command.
These flags allow updates to a token's policies/roles without having to override them completely. [GH-16288]-append-service-identity and -append-node-identity flags to the consul token update command.
These flags allow updates to a token's node identities/service identities without having to override them. [GH-16506]DEPRECATIONS:
-merge-node-identites and -merge-service-identities flags from the consul token update command in favor of: -append-node-identity and -append-service-identity. [GH-16506]-merge-policies and -merge-roles flags from the consul token update command in favor of: -append-policy-id, -append-policy-name, -append-role-name, and -append-role-id. [GH-16288]BUG FIXES:
consul connect envoy where a log to STDOUT could malform JSON when used with -bootstrap. [GH-16530]consul connect envoy where grpc-disabled agents were not error-handled correctly. [GH-16530]Upgrade to use Go 1.20.1. This resolves vulnerabilities CVE-2022-41724 in crypto/tls and CVE-2022-41723 in net/http. [GH-16263]
KNOWN ISSUES:
BREAKING CHANGES:
-join, -join-wan, start_join, and start_join_wan.
These options are now aliases of -retry-join, -retry-join-wan, retry_join, and retry_join_wan, respectively. [GH-15598]peer field to service-defaults upstream overrides. The addition of this field makes it possible to apply upstream overrides only to peer services. Prior to this change, overrides would be applied based on matching the namespace and name fields only, which means users could not have different configuration for local versus peer services. With this change, peer upstreams are only affected if the peer field matches the destination peer name. [GH-15956]consul connect envoy command if the Envoy version is incompatible. To ignore this check use flag --ignore-envoy-compatibility [GH-15818]connect.enable_serverless_plugin agent configuration option. Now
Lambda integration is enabled by default. [GH-15710]SECURITY:
crypto/tls and CVE-2022-41723 in net/http. [GH-16263]FEATURES:
acl.tokens.config_file_registration config field which specifies the token used
to register services and checks that are defined in config files. [GH-15828]consul troubleshoot upstreams and consul troubleshoot proxy to troubleshoot Consul's service mesh configuration and network issues. [GH-16284]operator usage instances subcommand for displaying total services, connect service instances and billable service instances in the local datacenter or globally. [GH-16205]proxy-defaults config entry. [GH-15864]consul namespace. [GH-15906]IMPROVEMENTS:
consul connect envoy command the Envoy version will now be checked for compatibility. If incompatible Consul will error and exit. [GH-15818]RESOURCE_EXHAUSTED responses [GH-15892]acl bootstrap command. [GH-14437]_<query id or name>._tcp.query[.<datacenter>].<domain>. [GH-14465]wal backend for log storage. [GH-16176]consul.xds.server.streamsUnauthenticated metric to track
the number of active xDS streams handled by the server that are unauthenticated
because ACLs are not enabled or ACL tokens were missing. [GH-15967]DEPRECATIONS:
token query parameter and warn when it is used for authentication. [GH-16009]-id flag on acl token operations has been changed to -accessor-id for clarity in documentation. The -id flag will continue to work, but operators should use -accessor-id in the future. [GH-16044]BUG FIXES:
Update golang.org/x/net to v0.17.0 to address CVE-2023-39325 / CVE-2023-44487(x/net/http2). [GH-19225]
SECURITY:
golang.org/x/net to v0.17.0 to address CVE-2023-39325
/ CVE-2023-44487(x/net/http2). [GH-19225]net/http). [GH-19225]google.golang.org/grpc to 1.56.3.
This resolves vulnerability CVE-2023-44487. [GH-19414]BUG FIXES:
/v1/catalog/services endpoint [GH-18322]performance.grpc_keepalive_timeout and performance.grpc_keepalive_interval now exist to allow for configuration on how often these dead connections will be cleaned up. [GH-19339]Upgrade to use Go 1.20.8. This resolves CVEs CVE-2023-39320 (cmd/go), CVE-2023-39318 (html/template), CVE-2023-39319 (html/template), CVE-2023-39321 (…
SECURITY:
cmd/go),
CVE-2023-39318 (html/template),
CVE-2023-39319 (html/template),
CVE-2023-39321 (crypto/tls), and
CVE-2023-39322 (crypto/tls) [GH-18742]IMPROVEMENTS:
BUG FIXES:
/v1/agent/self not returning latest configuration [GH-18681]Update golang.org/x/net to v0.13.0 to address CVE-2023-3978. [GH-18358]
SECURITY:
golang.org/x/net to v0.13.0 to address CVE-2023-3978. [GH-18358]net/http) for uses of the standard library.
A separate change updates dependencies on golang.org/x/net to use 0.12.0. [GH-18190]crypto/tls). [GH-18358]FEATURES:
consul members command uses -filter expression to filter members based on bexpr. [GH-18223]consul watch command uses -filter expression to filter response from checks, services, nodes, and service. [GH-17780]IMPROVEMENTS:
BUG FIXES:
Update to UBI base image to 9.2. [GH-17513]
SECURITY:
FEATURES:
consul operator raft list-peers command shows the number of commits each follower is trailing the leader by to aid in troubleshooting. [GH-17582]IMPROVEMENTS:
BUG FIXES:
api module representation of a namespace.
This fixes an error with the consul namespace list command when a namespace has a deferred deletion timestamp.Upgrade to use Go 1.20.4. This resolves vulnerabilities CVE-2023-24537(go/scanner), CVE-2023-24538(html/template), CVE-2023-24534(net/textproto) and C…
SECURITY:
go/scanner),
CVE-2023-24538(html/template),
CVE-2023-24534(net/textproto) and
CVE-2023-24536(mime/multipart).
Also, golang.org/x/net has been updated to v0.7.0 to resolve CVEs CVE-2022-41721
, CVE-2022-27664 and [CVE-2022-41723
](https://github.com/advisories/GHSA-vvpx-j8f3-3w6h
.) [GH-17240]IMPROVEMENTS:
MaxEjectionPercent and BaseEjectionTime to passive health check configs. [GH-15979]agent.server.snapshot to agent.server.raft.snapshot [GH-17236]BUG FIXES:
reflect: call of reflect.Value.Type on zero Value. [GH-17048]audit-logging: (Enterprise only) Fix a bug where /agent/monitor and /agent/metrics endpoints return a Streaming not supported error when audit logs ar
BUG FIXES:
/agent/monitor and /agent/metrics endpoints return a Streaming not supported error when audit logs are enabled. This also fixes the delay receiving logs when running consul monitor against an agent with audit logs enabled. [GH-16700]service:write access in the default namespace to query data, which was too restrictive. Now having service:write to any namespace is sufficient to query the peering data.Upgrade to use Go 1.20.1. This resolves vulnerabilities CVE-2022-41724 in crypto/tls and CVE-2022-41723 in net/http. [GH-16263]
SECURITY:
crypto/tls and CVE-2022-41723 in net/http. [GH-16263]IMPROVEMENTS:
BUG FIXES:
connect: Fix configuration merging for transparent proxy upstreams. Proxy-defaults and service-defaults config entries were not correctly merged for i
BREAKING CHANGES:
name field. Existing peerings with uppercase characters will not be modified, but they may encounter issues in various circumstances. To maintain forward compatibility and avoid issues, it is recommended to destroy and re-create any invalid peering connections so that they do not have a name containing uppercase characters. [GH-15697]FEATURES:
envoy-ready-bind-port and envoy-ready-bind-address to the consul connect envoy command that allows configuration of readiness probe on proxy for any service kind. [GH-16015]IMPROVEMENTS:
WatchServers, WatchRoots and GetSupportedDataplaneFeatures gRPC endpoints to accept any valid ACL token [GH-15346]BUG FIXES:
consul connect envoy was unable to configure TLS over unix-sockets to gRPC. [GH-15913]Upgrade to use Go 1.19.4. This resolves a vulnerability where restricted files can be read on Windows. CVE-2022-41720 [GH-15705]
SECURITY:
golang.org/x/net to prevent a denial of service by excessive memory usage caused by HTTP2 requests. CVE-2022-41717 [GH-15737]FEATURES:
IMPROVEMENTS:
BUG FIXES:
connect: Add local_idle_timeout_ms to allow configuring the Envoy route idle timeout on local_app connect: Add IdleTimeout to service-router to allow
FEATURES:
IMPROVEMENTS:
.service and .node DNS queries. [GH-15596]BUG FIXES:
consul partition update subcommand was not registered and therefore not available through the cli.cli: Fix issue where consul connect envoy incorrectly uses the HTTPS API configuration for xDS connections. [GH-15466]
Ensure that data imported from peers is filtered by ACLs at the UI Nodes/Services endpoints CVE-2022-3920 [GH-15356]
KNOWN ISSUES:
consul connect envoy incorrectly enables TLS for gRPC connections when the HTTP API is TLS-enabled.BREAKING CHANGES:
ports.grpc_tls configuration option.
Introduce a new port to better separate TLS config from the existing ports.grpc config.
The new ports.grpc_tls only supports TLS encrypted communication.
The existing ports.grpc now only supports plain-text communication. [GH-15339]peering and connect by default. [GH-15302]PeerName to Peer on prepared queries and exported services. [GH-14854]SECURITY:
FEATURES:
-consul-dns-port flag to the consul connect redirect-traffic command to allow forwarding DNS traffic to a specific Consul DNS port. [GH-15050]server_type=internal|external label to gRPC metrics. [GH-14922]get-or-empty operation to the txn api. Refer to the API docs for more information. [GH-14474]iptables to forward DNS traffic to a specific DNS port. [GH-15050]IMPROVEMENTS:
xds.update_max_per_second config field) [GH-14960]Failovers and Redirects only
specify Partition and Namespace on Consul Enterprise. This prevents scenarios
where OSS Consul would save service-resolvers that require Consul Enterprise. [GH-14162]RetryOn field for specifying the conditions when Envoy should retry requests beyond specific status codes and generic connection failure which already exists. [GH-12890]<servicename>.virtual.<namespace>.ns.<partition>.ap.<peername>.peer.consul and <servicename>.virtual.<partition>.ap.<peername>.peer.consul. This longer form address that allows specifying .peer would need to be used for tproxy DNS requests made within non-default partitions for imported services.[<tag>.]<service>.service[.<namespace>.ns][.<partition>.ap][.<datacenter>.dc]<domain>. [GH-14679]consul.xds.server.streamStart metric to measure time taken to first generate xDS resources for an xDS stream. [GH-14957]max_ejection_percent on Envoy's outlier detection to 100% for peered services. [GH-14373]alpn_protocols for connect-proxy and ingress-gateway based on service protocol. [GH-14356]BUG FIXES:
NOTES:
Nothing published for this version
connect: Disable peering by default in connect proxies for Consul 1.13. This change was made to prevent inefficient polling queries from having a nega
BREAKING CHANGES:
peering.enabled = true
is set on all clients and servers. [GH-17731]SECURITY:
FEATURES:
IMPROVEMENTS:
BUG FIXES:
api module representation of a namespace.
This fixes an error with the consul namespace list command when a namespace has a deferred deletion timestamp.Upgrade to use Go 1.20.1. This resolves vulnerabilities CVE-2022-41724 in crypto/tls and CVE-2022-41723 in net/http. [GH-16263]
SECURITY:
crypto/tls and CVE-2022-41723 in net/http. [GH-16263]go/scanner),
CVE-2023-24538(html/template),
CVE-2023-24534(net/textproto) and
CVE-2023-24536(mime/multipart).
Also, golang.org/x/net has been updated to v0.7.0 to resolve CVEs CVE-2022-41721
, CVE-2022-27664 and [CVE-2022-41723
](https://github.com/advisories/GHSA-vvpx-j8f3-3w6h
.) [GH-17240]IMPROVEMENTS:
BUG FIXES:
reflect: call of reflect.Value.Type on zero Value. [GH-17048]/agent/monitor and /agent/metrics endpoints return a Streaming not supported error when audit logs are enabled. This also fixes the delay receiving logs when running consul monitor against an agent with audit logs enabled. [GH-16700]Upgrade to use Go 1.19.6. This resolves vulnerabilities CVE-2022-41724 in crypto/tls and CVE-2022-41723 in net/http. [GH-16299]
SECURITY:
crypto/tls and CVE-2022-41723 in net/http. [GH-16299]IMPROVEMENTS:
BUG FIXES:
connect: add flags envoy-ready-bind-port and envoy-ready-bind-address to the consul connect envoy command that allows configuration of readiness probe
FEATURES:
envoy-ready-bind-port and envoy-ready-bind-address to the consul connect envoy command that allows configuration of readiness probe on proxy for any service kind. [GH-16015]IMPROVEMENTS:
BUG FIXES:
Upgrade to use Go 1.18.9. This resolves a vulnerability where restricted files can be read on Windows. CVE-2022-41720 [GH-15706]
SECURITY:
golang.org/x/net to prevent a denial of service by excessive memory usage caused by HTTP2 requests. CVE-2022-41717 [GH-15743]IMPROVEMENTS:
BUG FIXES:
consul partition update subcommand was not registered and therefore not available through the cli.auto-config: Relax the validation on auto-config JWT authorization to allow non-whitespace, non-quote characters in node names. [GH-15370]
IMPROVEMENTS:
BUG FIXES:
agent: Added a new config option rpc_client_timeout to tune timeouts for client RPC requests [GH-14965]
FEATURES:
rpc_client_timeout to tune timeouts for client RPC requests [GH-14965]max_connections for upstream clusters [GH-14749]IMPROVEMENTS:
BUG FIXES:
api: Fix a breaking change caused by renaming QueryDatacenterOptions to QueryFailoverOptions. This adds QueryDatacenterOptions back as an alias to Que…
BREAKING CHANGES:
update capability on the intermediate PKI's tune mount configuration endpoint, such as /sys/mounts/connect_inter/tune. The breaking nature of this change is resolved in 1.13.3. Refer to upgrade guidance for more information.SECURITY:
AutoConfig.InitialConfiguration endpoint. Now, only a subset of characters are allowed for the input before evaluating the bexpr. [GH-14577]ConnectCA.Sign endpoint. The endpoint now only allows for exactly one SAN URI to be specified. [GH-14579]FEATURES:
peering workflows. Refer to the CLI docs for more information. [GH-14423]local_request_timeout_ms and
local_connect_timeout_ms in servicedefaults config entry [GH-14395]IMPROVEMENTS:
BUG FIXES:
QueryDatacenterOptions to
QueryFailoverOptions. This adds QueryDatacenterOptions back as an alias to
QueryFailoverOptions and marks it as deprecated. [GH-14378]consul connect envoy or consul connect proxy, the -sidecar-for service ID argument is now treated as case-insensitive. [GH-14034]auto_config and auto_encrypt could unintentionally enable TLS for gRPC xDS connections. [GH-14269]agent: Fixed a compatibility issue when restoring snapshots from pre-1.13.0 versions of Consul [GH-14107] [GH-14149]
config-entry: Exporting a specific service name across all namespace is invalid.
BREAKING CHANGES:
telemetry { disable_compat_1.9 = (true|false) } has been removed. Before upgrading you should remove this flag from your config if the flag is being used. [GH-13532]FEATURES:
consul version commands
to report this. Agent also reports build date in log on startup. [GH-13357]Sign [GH-12787]destination field to the service-default config entry that allows routing egress traffic
through a terminating gateway in transparent proxy mode without modifying the catalog. [GH-13613]ingress-gateway, mesh, service-intentions and service-resolver config entry events. [GH-13658]IMPROVEMENTS:
merge-central-config query parameter support added to /catalog/node-services/:node-name API, to view a fully resolved service definition (especially when not written into the catalog that way). [GH-13450]merge-central-config query parameter support added to /catalog/node-services/:node-name API, to view a fully resolved service definition (especially when not written into the catalog that way). [GH-2046]merge-central-config query parameter support added to some catalog and health endpoints to view a fully resolved service definition (especially when not written into the catalog that way). [GH-13001]consul connect envoy command.
Adds the -prometheus-ca-file, -prometheus-ca-path, -prometheus-cert-file and -prometheus-key-file flags. [GH-13481]max_inbound_connections setting to service-defaults for limiting the number of concurrent inbound connections to each service instance. [GH-13143]consul.raft.thread.main.saturation and consul.raft.thread.fsm.saturation metrics to measure approximate saturation of the Raft goroutines [GH-12865]BUG FIXES:
acl token read is used with the -self and -expanded flags, return an error instead of panicking [GH-13787]Nothing published for this version
Nothing published for this version
deps: update to latest go-discover to provide ECS auto-discover capabilities. [GH-13782]
FEATURES:
IMPROVEMENTS:
BUG FIXES:
Upgrade to use Go 1.18.9. This resolves a vulnerability where restricted files can be read on Windows. CVE-2022-41720 [GH-15727]
SECURITY:
golang.org/x/net to prevent a denial of service by excessive memory usage caused by HTTP2 requests. CVE-2022-41717 [GH-15746]IMPROVEMENTS:
BUG FIXES:
consul partition update subcommand was not registered and therefore not available through the cli.agent: Fixed issue where blocking queries with short waits could timeout on the client [GH-15541]
BUG FIXES:
agent: Added a new config option rpc_client_timeout to tune timeouts for client RPC requests [GH-14965]
FEATURES:
rpc_client_timeout to tune timeouts for client RPC requests [GH-14965]consul version commands
to report this. Agent also reports build date in log on startup. [GH-13357]max_connections for upstream clusters [GH-14749]IMPROVEMENTS:
BUG FIXES:
ca: If using Vault as the service mesh CA provider, the Vault policy used by Consul now requires the update capability on the intermediate PKI's tune
BREAKING CHANGES:
update capability on the intermediate PKI's tune mount configuration endpoint, such as /sys/mounts/connect_inter/tune. The breaking nature of this change is resolved in 1.12.6. Refer to upgrade guidance for more information.SECURITY:
AutoConfig.InitialConfiguration endpoint. Now, only a subset of characters are allowed for the input before evaluating the bexpr. [GH-14577]ConnectCA.Sign endpoint. The endpoint now only allows for exactly one SAN URI to be specified. [GH-14579]IMPROVEMENTS:
BUG FIXES:
consul connect envoy or consul connect proxy, the -sidecar-for service ID argument is now treated as case-insensitive. [GH-14034]cli: when acl token read is used with the -self and -expanded flags, return an error instead of panicking [GH-13787]
BUG FIXES:
acl token read is used with the -self and -expanded flags, return an error instead of panicking [GH-13787]Support Vault namespaces in Connect CA by adding RootPKINamespace and IntermediatePKINamespace fields to the config. [GH-12904]
IMPROVEMENTS:
consul.server.isLeader metric to track if a server is a leader or not. [GH-13304]BUG FIXES:
grpc or http2 ingress gateway listeners with multiple services [GH-13127]http2. [GH-13699]kvs: Fixed a bug where query options were not being applied to KVS.Get RPC operations. [GH-13344]
BUG FIXES:
config: fix backwards compatibility bug where setting the (deprecated) top-level verify_incoming option would enable TLS client authentication on the…
FEATURES:
IMPROVEMENTS:
telemetry.retry_failed_connection in agent configuration to
retry on failed connection to any telemetry backend. This prevents the agent from
exiting if the given DogStatsD DNS name is unresolvable, for example. [GH-13091]BUG FIXES:
add_headers directive named Host the header is not set for v1/internal/ui/metrics-proxy/ endpoint. [GH-13071]verify_incoming option would enable TLS client authentication on the gRPC port [GH-13118]NOTES:
deps: update to latest go-discover to fix vulnerable transitive jwt-go dependency [GH-12739]
BREAKING CHANGES:
ACLMasterToken, renamed Master to InitialManagement, and AgentMaster to AgentRecovery) [GH-11827]consul.http... metrics can still be enabled by setting disable_compat_1.9 = false. However, we will remove these metrics in 1.13. [GH-12675]FEATURES:
WatchRoots [GH-12678]token read command now supports the -expanded flag to display detailed role and policy information for the token. [GH-12670]auto-reload-config CLI flag or auto_reload_config config option. [GH-12329]Meta is returned with the response to the ConfigEntry.ResolveServiceConfig RPC. [GH-12529]tls stanza [GH-12504]IMPROVEMENTS:
STSRegion field was removed from the auth method config. [GH-12774]autopilot.healthy and autopilot.failure_tolerance metrics are now
regularly emitted by all servers. [GH-12617]consul.raft.boltdb.writeCapacity metric was added and indicates a theoretical number of writes/second that can be performed to Consul. [GH-12646]Partition and RetryJoin to the TestServerConfig struct. [GH-12126]leader label to consul.rpc.server.call and optional target_datacenter, locality,
allow_stale, and blocking optional labels. [GH-12727]DEPRECATIONS:
consul.acl.ResolveTokenToIdentity metric is no longer reported. The values that were previous reported as part of this metric will now be part of the consul.acl.ResolveToken metric. [GH-12166]cert_file, key_file, ca_file, ca_path, tls_min_version, tls_cipher_suites, verify_incoming, verify_incoming_rpc, verify_incoming_https, verify_outgoing and verify_server_hostname at the top-level is now deprecated, use the tls stanza instead [GH-12504]BUG FIXES:
NOTES:
Nothing published for this version
agent: Added a new config option rpc_client_timeout to tune timeouts for client RPC requests [GH-14965]
FEATURES:
rpc_client_timeout to tune timeouts for client RPC requests [GH-14965]max_connections for upstream clusters [GH-14749]IMPROVEMENTS:
BUG FIXES:
kvs: Fixed a bug where query options were not being applied to KVS.Get RPC operations. [GH-13344]
BUG FIXES:
ca: If using Vault as the service mesh CA provider, the Vault policy used by Consul now requires the update capability on the intermediate PKI's tune
BREAKING CHANGES:
update capability on the intermediate PKI's tune mount configuration endpoint, such as /sys/mounts/connect_inter/tune. The breaking nature of this change is resolved in 1.11.11. Refer to upgrade guidance for more information.SECURITY:
AutoConfig.InitialConfiguration endpoint. Now, only a subset of characters are allowed for the input before evaluating the bexpr. [GH-14577]ConnectCA.Sign endpoint. The endpoint now only allows for exactly one SAN URI to be specified. [[GH-14579](https://github.com/[Ihashicorp/consul/issues/14579)]IMPROVEMENTS:
BUG FIXES:
consul connect envoy or consul connect proxy, the -sidecar-for service ID argument is now treated as case-insensitive. [GH-14034]connect: Fixed a goroutine/memory leak that would occur when using the ingress gateway. [GH-13847]
BUG FIXES:
connect: Update supported Envoy versions to 1.20.4, 1.19.5, 1.18.6, 1.17.4 [GH-13434]
IMPROVEMENTS:
BUG FIXES:
grpc or http2 ingress gateway listeners with multiple services [GH-13127]http2. [GH-13699]sentinel: (Enterprise Only) Sentinel now uses SHA256 to generate policy ids
IMPROVEMENTS:
BUG FIXES:
add_headers directive named Host the header is not set for v1/internal/ui/metrics-proxy/ endpoint. [GH-13071]NOTES:
agent: Added a new check field, disable_redirects, that allows for disabling the following of redirects for HTTP checks. The intention is to default t
SECURITY:
disable_redirects, that allows for disabling the following of redirects for HTTP checks. The intention is to default this to true in a future release so that redirects must explicitly be enabled. [GH-12685]IMPROVEMENTS:
BUG FIXES:
consul namespace to allow K8s namespace mirroring when deploying in consul K8s namespace .ca: support using an external root CA with the vault CA provider [GH-11910]
FEATURES:
IMPROVEMENTS:
BUG FIXES:
connect: update Envoy supported version of 1.20 to 1.20.1 [GH-11895]
IMPROVEMENTS:
BUG FIXES:
ingress: allow setting TLS min version and cipher suites in ingress gateway config entries [GH-11576]
FEATURES:
IMPROVEMENTS:
BUG FIXES:
NodeService struct properly to avoid a data race. [GH-11940]1.3.3 which fixes a bug where a read replica node can trigger a raft election and become a leader. [GH-11958]consul acl token list. [GH-11926]snapshot save command now saves the snapshot with read permission for only the current user. [GH-11918]Nothing published for this version
Nothing published for this version
Nothing published for this version
ci: Upgrade golang.org/x/net to address CVE-2021-44716 [GH-11854]
SECURITY:
FEATURES:
segment_limit configurable, cap at 256.BUG FIXES:
…in the default namespace. This change fixes CVE-2021-41805.
BREAKING CHANGES:
consul acl set-agent-token master has been replaced with consul acl set-agent-token recovery [GH-11669]SECURITY:
acl:write permission in the default namespace. This change fixes CVE-2021-41805.FEATURES:
IMPROVEMENTS:
X-Consul-Results-Filtered-By-ACLs header [GH-11569]-cas and -modify-index flags to the consul config delete command to support Check-And-Set (CAS) deletion of config entries [GH-11419]dns_config.recursor_strategy flag to control the order which DNS recursors are queried [GH-10611]virtual endpoint for querying the assigned virtual IP for a service. [GH-11725]agent.tls.cert.expiry metric for tracking when the Agent TLS certificate expires. [GH-10768]mesh.active-root-ca.expiry metric for tracking when the root certificate expires. [GH-9924]- to _ [GH-11801]DEPRECATIONS:
/v1/agent/token/agent_master is deprecated and will be removed in a future major release - use /v1/agent/token/agent_recovery instead [GH-11669]acl.tokens.master has been renamed to acl.tokens.initial_management, and acl.tokens.agent_master has been renamed to acl.tokens.agent_recovery - the old field names are now deprecated and will be removed in a future major release [GH-11665]tls_cipher_suites will no longer be honored, and tls_prefer_server_cipher_suites is now ignored. [GH-11364]BUG FIXES:
/v1/operator/autopilot/configuration) [GH-10558] [GH-10559]license_path setting in config filesService.Namespace into available variables for dashboard_url_templates [GH-11640]NOTES:
agent_master field to agent_recovery in the acl-tokens.json file in which tokens are persisted on-disk (when acl.enable_token_persistence is enabled) [GH-11744]Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →