NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
NuGet · #2022 most downloaded on NuGet
Ocelot is an API gateway based on ASP.NET Core stack.
Last release 23 days ago
14 Sep 2026
Release timing varies
gaps range from 8 days to 7 months
Some releases are documented
notes for 10 of 33 stable releases
512 versions withdrawn
withdrawn after publishing
127 years old
545 releases · first in 1900
Ocelot.QualityOfService.Polly version 25.0.1
Version 25.0.1 includes upgraded solutions of all Ocelot packages based on .NET SDK 10.0.401, released on September 8, 2026. For more details about SDK 10.0.401 a.k.a. Runtime 10.0.12, see the .NET 10.0.12 Release Notes as part of .NET 10 Release Notes.
Full Changelog: 25.0.0...25.0.1
One column per quarter.
Please note that some of the packages are deprecated! To watch the status of each package and its repository, go to the Release Radar status page. Kub…
net10.0, version 25.0) a.k.a. the .NET 10 releaseMilestone: .NET 10 👈
Codenamed: .NET 10
Read the Docs: Ocelot 25.0 with PDF
Target Framework Monikers:net8.0,net9.0,net10.0
On November 11th, 2025, the .NET team announced the release of the .NET 10 framework:
This major release upgrades the Ocelot package TFMs to net10.0 in addition to the current net8.0 and net9.0. Thus, the current Ocelot supported frameworks are .NET 8 LTS, .NET 9 STS, and .NET 10 LTS.
Additionally, in this major release the Ocelot team focused on preparing the codebase and its ecosystem for the .NET 10 SDK (.NET 10 milestone), while also extracting several integrated extension packages from the v24.1 monorepo into their own dedicated repositories to speed up delivery and reduce release coupling. As a result of these DevOps activities, the Ocelot repository now hosts only two package projects — Ocelot (src folder) and Ocelot.Testing (testing folder) — along with two solutions, Ocelot.slnx and Ocelot.Samples.slnx, which can be opened or built only if the .NET 10 SDK is installed. Since the extension packages now live in separate repositories, a new Release Radar status page has been introduced to track their progress.
This major version also includes the following feature updates:
ocelot.*.json files, keeping users' extended properties available during Ocelot app startup and at runtime via the standard IConfiguration service in the DI container.Finally, because the repository has a new folder structure, the development team recommends recloning or even reforking the Ocelot repository for a successful upgrade to the new version in order to avoid potential build errors.
As a best practice, the release strategy has been aligned with .NET SDK monthly patches (usually available between the 10th and 15th of each month). The development team will therefore also aim to roll out monthly Ocelot patches that reference the new .NET SDK patched versions. Ocelot patches will follow the form of a beta or patched version major.minor.*, where * is the Ocelot patch number corresponding to the newly available .NET SDK patch.
Ideally, the Ocelot team expects accelerated releases with more frequent minor/patch versions, because DevOps is now prepared for the new release strategy and offers fast delivery.
For successful contributions, maintainers will announce an identity-verification procedure (details for first-time contributors will be published soon).
Ocelot's QoS schema no longer strictly depends on the external Ocelot.QualityOfService.Polly package to provide circuit breaking and timeout enforcement. A lightweight, thread-safe circuit breaker (Closed → Open → HalfOpen → Closed) ships in the Ocelot core package, supporting both count-based and FailureRatio-based modes.
The two implementations are mutually exclusive: the last of AddQualityOfService() or AddPolly() registered on the OcelotBuilder wins.
See the built-in QoS documentation for full details, including the AddQualityOfService<THandler>() extensibility point for overriding server error codes.
The previously hard-coded DefaultWebSocketBufferSize is now a protected virtual property that can be overridden by subclassing.
The Middleware Injection feature was extended with a WebSocketsProxyMiddleware override on the OcelotPipelineConfiguration class, allowing a fully custom WebSocket middleware to be injected into the pipeline.
Refer to the "Sample" section to understand how to utilize the new feature.
Previously, IP allow/block-list Routing "Security Options" were not enforced for WebSocket upgrade requests (a.k.a. the CONNECT HTTP method), allowing them to bypass IP security. WebSocket upgrade requests are now intercepted by the same IPSecurityPolicy used for regular HTTP requests, and denied upgrades now correctly return 403 Forbidden.
Ocelot's configuration builder now merges custom (non-schema) JSON properties defined across multiple ocelot.*.json files using Newtonsoft's JToken merge functionality, instead of the last-loaded file silently overwriting properties from previous files in the Routes collection.
This also applies to the DynamicRoutes collection and the GlobalConfiguration section. See the updated Configuration documentation, especially the "Extend configuration with Custom Properties" section, and the Configuration Sample app for details.
While working on bug #2248 in pull request #2328 by @NandanDevHub, the development team uncovered an undocumented feature in the Multiplexer namespace and decided to publish this pilot feature in the "Aggregate Manually?" documentation. The feature is based on the IResponseAggregator interface, whose correct application is currently unclear.
The Ocelot team will test it further in upcoming releases, develop best practices, create a sample app, and inform the community. For this reason we warn that the feature is still in pilot status. ✈️
The Ocelot team continued extracting integrated extension packages out of the monorepo into their own dedicated repositories, each with an independent release cycle:
Ocelot.Provider.Eureka, see issue #2371) in pull request #2372Ocelot.Provider.Polly, see issue #2378) in pull request #2380Ocelot.Provider.Consul, see issue #2378) in pull request #2388Ocelot.Provider.Kubernetes, see issue #2378) in pull request #2404 This keeps the Ocelot core repository lean, avoids delays caused by the integrated packages' own release schedules, and lets each provider evolve independently. Consult the Caching, Tracing, Service Discovery, and Kubernetes chapters for package-specific upgrade notes.
Please note that some of the packages are deprecated! To watch the status of each package and its repository, go to the Release Radar status page.
The PollKube discovery provider was redesigned to utilize PeriodicTimer (introduced in .NET 6). The provider is based on an "active polling" strategy that requires stable behavior and careful management of timing events in multi-threaded scenarios. The new PeriodicTimer is designed for thread safety, and its callbacks replace the old Timer callbacks, which work fine in a synchronous flow.
Please note that the PollKube discovery provider is now part of the Ocelot.Discovery.KubeClient package.
.sln → .slnx), by @raman-m in pull request #2354.Microsoft.Testing.Platform framework (by @raman-m in #2392).coverlet.runsettings (by @ocelot-ot in #2365).10.0.* (.NET Runtime 10.0.*), by @raman-m and @ocelot-ot in pull requests #2367, #2389, #2402, and #2409.The updated documentation also highlights the deprecation of certain packages through multiple notes and warnings. With the Obsolete attributes in place, C# developers will notice several warnings in the build logs during compilation.
This fixes a bug where downstream URL query parameter names could be corrupted if they contained a placeholder with a non-empty value.
The DownstreamUrlCreatorMiddleware query-string merging algorithm was refactored to take full advantage of ASP.NET Core's QueryHelpers.
Requests containing non-ASCII characters in HTTP header values previously surfaced as an unhandled HttpRequestException and an HTTP 502 Bad Gateway response.
Ocelot now catches this HttpRequestException and maps it to a 400 Bad Request response, in line with RFC 7230 "Field Parsing" rules.
Previously, IP allow/block-list Routing "Security Options" were not enforced for WebSocket upgrade requests, allowing them to bypass IP security. WebSocket upgrade requests are now intercepted by the same IPSecurityPolicy used for regular HTTP requests, and denied upgrades now correctly return 403 Forbidden.
This critical security issue was detected by security scanners on GitHub after the bug was reported. 🙈
Many thanks to George Chen (@geo-chen) for reporting this critical bug.
Complex Aggregation routes configured with the RouteKeysConfig array now correctly map route keys to the corresponding aggregator context, fixing a bug where keys could be mismatched or dropped during multiplexing.
The {adminPath}/configuration and {adminPath}/outputcache/{region} endpoints are now decorated with [ApiExplorerSettings(IgnoreApi = true)] so that they no longer appear in Swagger/OpenAPI documentation generated for the downstream API surface.
1st 🥇 goes to Ocelot Robot for delivering 3 features
2nd🥈 goes to Jolanta Łukawska for delivering 1 feature in 32 files changed
3rd 🥉 goes to Eran Nevo for delivering 1 feature in 21 files changed
4th 🧡 goes to Majdi Zlitni for delivering 1 feature in 17 files changed
5th 💛 goes to Curtis Oliver for delivering 1 feature in 15 files changed
⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐ Raman Maksimchuk
⭐⭐⭐⭐⭐⭐⭐ Ocelot Robot, @ocelot-ot
⭐ Jolanta Łukawska, @jlukawska
⭐ Eran Nevo, @erannevo
⭐ Majdi Zlitni, @Majdi-Zlitni
⭐ Curtis Oliver, @CurtisRobertOliver
⭐ Methran G., @methran1304
⭐ Nandan Parmar, @NandanDevHub
⭐ Bhargav Polara, @bhargav-polara
⭐ Mustafa Şenoğlu, @mmustafasenoglu
⭐ Miňo Martiniak, @Burgyn
MMLib.SwaggerForOcelot package to the Introduction "Not Supported" chapter (#1429)SecurityOptions support to the WebSocket pipeline (#2406)FileConfigurationPoller against timer reentrancy and callback thread leaks, and stabilize TimeoutDelegatingHandler timeout test (#2394)HttpRequestException to 400 Bad Request according to RFC 7230 (#2379)Note truncated.
The updated documentation highlights the deprecation of certain options through multiple notes and warnings. This deprecation process will be complete…
Milestone: Summer'25 👈
Codenamed: Globality
Read the Docs: Ocelot 24.1 with PDF
In this minor release, the Ocelot team put the spotlight on the Configuration feature as part of their semi-annual 2025 effort, with a particular focus on the Global Configuration Schema. This release enhances support for global configurations across both routing modes: the classic static Routing and the service discovery-based Dynamic Routing.
The updated documentation highlights the deprecation of certain options through multiple notes and warnings. This deprecation process will be completed in the upcoming .NET 10 release. With the [Obsolete] attributes in place, C# developers will notice several warnings in the build logs during compilation.
On top of that, this release brings a great enhancement to the Kubernetes provider, also known as the Ocelot.Provider.Kubernetes package.
This update brings changes to the Dynamic Route Schema and Global Configuration Schema, while the Route Schema stays the same apart from deprecation updates. All work was coordinated under issue #585, which addressed the challenges of configuring Ocelot's most popular features globally before version 24.1, when dynamic routing gained global configuration partial support, but static routing mostly lacked it. A key outcome of #585 is the ability to override global configuration options within the DynamicRoutes collection. This ongoing issue will continue to require attention, as adapting static route global configurations for dynamic routing is complex and, in some cases, impossible. This will be a challenge for future Ocelot releases and the community.
The Ocelot.Provider.Kubernetes package now features a new WatchKube provider for Kubernetes service discovery. This provider is a great fit for high-load environments where the older Kube and PollKube providers struggle to handle heavy traffic, often leading to increased log errors, HTTP 500 issues, and potential Ocelot instance failures. WatchKube is the next step in the evolution of these providers, leveraging the reactive capabilities of the KubeClient API. For guidance on choosing the right provider for your Kubernetes setup, check out the "Comparing providers" section in the documentation.
In the past, the Timeout setting in the Route Schema didn't actually stop requests, defaulting instead to a fixed 90 seconds. Custom timeouts were handled using the Quality of Service Timeout strategy, and this only applied if Polly and the Ocelot.Provider.Polly package were used. Now, the Timeout option (in seconds) can be set at the route, global, and QoS levels. The Global Configuration Schema and Dynamic Route Schema also include the new Timeout setting, making it possible to configure default timeouts for dynamic routing as well.
Starting with version 24.1, two new parameters in QoSOptions, FailureRatio and SamplingDuration, let you fine-tune the behavior of the Circuit Breaker strategy. Both can be configured globally, even with dynamic routing.
Please note that DurationOfBreak, ExceptionsAllowedBeforeBreaking, and TimeoutValue are now deprecated in 24.1, so check the QoSOptions Schema documentation for details.
The updated docs now highlight these deprecated options with multiple notes and warnings. The v24.1 deprecation process will wrap up in the upcoming .NET 10 release. Due to the Obsolete attributes, C# developers will notice several build warnings during compilation.
The project was removed from the main repo and moved to its own Ocelot.Testing repository. This change allows the Ocelot.Testing package to be shared independently for extension package delivery. The Ocelot team also plans to deprecate more projects and move them to separate repos because: a) despite the fact that a monorepo enables faster builds and quicker delivery; b) but the release process can be delayed by missing versions of integrated libraries in extension packages. The goal is for the Ocelot repo to only contain essential projects, avoiding delays caused by integrated package release schedules. Legacy or abandoned integrated packages should be deprecated and maintained in their own repos with independent release cycles.
Headers Transformation: Added global configuration by @marklonquist in PR #1659.The Global Configuration Schema now includes new DownstreamHeaderTransform and UpstreamHeaderTransform options. These work only with static routes, meaning the Routes collection (see Route Schema). They aren't supported for dynamic routes because they're not part of the Dynamic Route Schema, and Ocelot Core doesn't read global configuration of this feature in dynamic routing mode. This is noted in the Roadmap documentation.
The Global Configuration Schema now includes a new AuthenticationOptions property for setting up static routes globally. This also introduces the AllowAnonymous boolean option within AuthenticationOptions to control static route authentication. Later, PR #2336 extended global authentication support to dynamic routes.
Note: The AuthenticationProviderKey option is deprecated in version 24.1—see the AuthenticationOptions Schema documentation for details.
The Global Configuration Schema now includes a new RateLimitOptions property for both static and dynamic routes. Previously, global configuration was available through RateLimitOptions in dynamic routing mode, while route overriding used the now-deprecated RateLimitRule from the Dynamic Route Schema.
This marks the second major overhaul of the Rate Limiting feature since the first update in PR #1592. A new Wait option has been added, replacing the deprecated PeriodTimespan, to enhance the Fixed Window algorithm. The full list of deprecated options can be found in the Deprecated Options documentation.
The Global Configuration Schema now includes a new LoadBalancerOptions property for both static and dynamic routes. Previously, global configuration was available through LoadBalancerOptions in dynamic routing mode without dynamic route overrides. Starting with version 24.1, the Dynamic Route Schema also supports LoadBalancerOptions for overriding, and global configuration for static routes is now supported as well.
The Global Configuration Schema now includes a new CacheOptions property for both static and dynamic routes. Global configuration has been available for static routes since version 23.3, but starting with version 24.1, the Dynamic Route Schema also supports CacheOptions for overriding.
Note that the FileCacheOptions property in the Route Schema (static routes) is deprecated in version 24.1. For more details, see the caching Configuration documentation.
The Global Configuration Schema now includes a new HttpHandlerOptions property for both static and dynamic routes. Previously, global configuration was available through HttpHandlerOptions in dynamic routing mode without dynamic route overriding. Starting with version 24.1, the Dynamic Route Schema also supports HttpHandlerOptions for overriding, and global configuration is now available for static routes as well.
The Global Configuration Schema now includes a new AuthenticationOptions property for both static and dynamic routes. Starting with version 24.1, the Dynamic Route Schema also supports AuthenticationOptions to override global settings.
Note that the AuthenticationProviderKey option is deprecated in version 24.1, so check the AuthenticationOptions Schema documentation for details.
The Global Configuration Schema now includes a new QoSOptions property for both static and dynamic routes. Previously, global configuration was available through QoSOptions in dynamic routing mode without the option for dynamic route overrides. Starting with version 24.1, the Dynamic Route Schema supports QoSOptions for overriding, and global configuration support is now available for static routes as well.
Note that the DurationOfBreak, ExceptionsAllowedBeforeBreaking, and TimeoutValue options are deprecated in version 24.1. For details, see the QoSOptions Schema documentation.
These efforts kept the CI/CD builds in GitHub Actions stable, targeting the beta release of version 24.1. The CI/CD environment was set up and tested GH-Actions workflows in advance for the beta release, which is the goal of PR #2347.
This update removes the troublesome System.Net.WebSockets.WebSocketException from logs, preventing Ocelot from running into 500 status disasters. The issue stemmed from client-side or network events that Ocelot's WebSocketsProxyMiddleware couldn't anticipate on the server side. The patch now checks for incorrect connection statuses, attempting to close the connection and end server-side tasks gracefully without errors.
This update fixes the PollKube provider to address a bug with the first cold request, where the winning thread got an empty collection before the initial callback was triggered. The solution is to call the integrated discovery provider for the first cold request when the queue is empty.
Starting with version 24.1, Ocelot now supports RFC 8693 (OAuth 2.0 Token Exchange) for the scope claim in the ScopesAuthorizer service, also referred to as the IScopesAuthorizer service in the DI container.
1st 🥇 goes to Zhannur Akhmetkhanov for delivering 2 features
2nd 🥈 goes to Milad Rivandi for delivering 1 feature in 136 files changed
3rd 🥉 goes to Jolanta Łukawska for delivering 1 feature in 39 files changed
⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐ Raman Maksimchuk, @raman-m
⭐⭐ Zhannur Akhmetkhanov, @hogwartsdeveloper
⭐ Milad Rivandi, @MiladRv
⭐ Jolanta Łukawska, @jlukawska
⭐ Nikolay Kuksov, @kick2nick
⭐ Mehmet Yasin Akar, @mehyaa
⭐ Harris Zhang, @harris2012
⭐ Mark Bøg Lønquist, @marklonquist
⭐ Raynald Messié, @RaynaldM
WatchKube provider for Kubernetes service discovery (#2174)developWatchKube provider for Kubernetes service discovery by @kick2nick in #2174FailureRatio and SamplingDuration V8 parameters to fine-tune Polly's circuit-breaker strategy via route-level and global QoS options by @RaynaldM in #2081Note truncated.
Upgrade to .NET 9 with supported TFMs (net8.0;net9.0)
Upgrade to .NET 9 with supported TFMs (net8.0;net9.0)
Ocelot release: 24.0.0
Ocelot.Administration.IdentityServer4 release: 24.0.1
NuGet package: Ocelot.Administration.IdentityServer4.24.0.1
The Ocelot.Administration extension package has been renamed to Ocelot.Administration.IdentityServer4 ❗
All IdentityServer4-related vulnerabilities (issue #2218) were addressed. The Ocelot.Administration source code has been moved out of the Ocelot repository (pull request #2274) and transferred to the Ocelot.Administration.IdentityServer4 repository.
Currently, the Administration feature is solely based on the IdentityServer4 package, whose repository was archived by its owner on July 31, 2024. In this release, the Ocelot team deprecated the Ocelot.Administration.IdentityServer4 extension package after the current Ocelot v24.0 release; however, the repository is/will not be archived, allowing for potential patches in the future.
Note: In upcoming releases, the Ocelot team plans to utilize the ASP.NET Core Identity framework for Administration feature development and in Ocelot's acceptance testing project to align with .NET industry standards. As a result, the IdentityServer4 library is intended to be replaced with ASP.NET Core Identity, which also supports Bearer tokens, commonly known as
JwtBearerHandlerfrom the Microsoft.AspNetCore.Authentication.JwtBearer namespace.
Milestone: .NET 9
Hot fixed version: 24.0.0
Read the Docs: Ocelot 24.0 with PDF
🔥 Hot fixed issue: #2299
❤️ A sincere and heartfelt "Thank You" to Gracjan Bryłka, @font3r for reporting the bug.
Interface Breaking Changes:
IKubeApiClientFactory interface removal: The ServiceAccountPath property was removed because it was not intended for public use.Ocelot.Provider.Kubernetes.Interfaces.IKubeApiClientFactoryOcelot.Provider.Kubernetes.Interfaces.IKubeApiClientFactory.ServiceAccountPathServiceAccountPath as a protected property of the factory to stabilize KubeApiClient creation in the Kubernetes provider by @raman-m in #2302Full Changelog: 24.0.0...24.0.1
Upgrade to .NET 9 with supported TFMs (net8.0;net9.0)
Upgrade to .NET 9 with supported TFMs (net8.0;net9.0)
net9.0, version 24.0) a.k.a. the .NET 9 releaseMilestone: .NET 9 👈
Codenamed: .NET 9
Read the Docs: Ocelot 24.0 with PDF
Target Framework Monikers:net8.0,net9.0
On November 12th, 2024, the .NET team announced the release of the .NET 9 framework:
This major release upgrades Ocelot package TFMs to net9.0 in addition to the current net8.0. Thus, the current Ocelot supported frameworks are .NET 8 LTS and .NET 9 STS. According to the .NET Support Policy, the Ocelot team has discontinued support of .NET 6 and .NET 7 by providing the version 23.4.3 which targets those .NET versions.
Ocelot's previous CI/CD provider, CircleCI, facilitated professional and seamless development, build processes, and delivery of Ocelot versions for seven years, starting in March 2018. But last year, in January 2025, after patching Ocelot with version 23.4.3, our team encountered legal issues related to CircleCI Co's policies, leading to this CI/CD provider stopping the build process for the Ocelot project. This legal issue and technical incident were unforeseen on our part because Ocelot is open-source software (OSS), and forcibly stopping the project's build process and blocking accounts appears to be an unfortunate breach of OSS principles. We strongly believe that any developer or user, from any country, should be able to use software providers that support the OSS movement by offering free or other cost-free plans and serving the accounts of these users, OSS teams, and OSS projects 24/7, 365 days a year. We consider this legal issue and the resulting technical incidents involving CircleCI to be a serious breach of OSS principles and an act of discrimination against Ocelot users, developers, and customers who rely on Ocelot OSS, ultimately causing delays to the current release. As a team, we do not recommend using CircleCI for OSS projects, as there is no guarantee that these projects will not face discrimination from this U.S. company.
For all developers, team leads, architects, and managers of any OSS projects—at least on GitHub—we recommend utilizing the built-in GitHub Actions CI/CD infrastructure. Since its founding, GitHub has supported OSS projects. Today, GitHub provides 2,000 minutes of free CI/CD build time per month for OSS repositories (public repos). Also, we strongly believe that GitHub will never violate its OSS policies without a notice period, nor fail to inform owners and maintainers that certain policies must be met by Ocelot's owners. In addition, we want to acknowledge that we are monitoring U.S. government regulations. Unfortunately, we must state that some GitHub products are unavailable in certain countries, even if the project is OSS and GitHub claims these products are free for OSS. Since the Ocelot team does not utilize these non-critical products (we prefer to energize our brains rather than rely on AI-driven products), and since the Ocelot project is currently well-served by GitHub Co, the Ocelot team affirms that Ocelot will remain on GitHub as long as its OSS-friendly policies continue. As a team, we hope that GitHub will never enforce extra rules on our project or other OSS projects.
Regardless, we remain on GitHub!
Starting from version 24.0, all pull requests, development commits, and releases will be built using GitHub Actions workflows (documentation). We currently have three workflows: one for pull requests (PR), one for the develop branch (Develop), and one for the main branch (Release). All workflow runs are available on the Actions dashboard.
The PR workflow will track code coverage using Coveralls. After opening a pull request or submitting a new commit to a pull request, Coveralls will publish a short message with the current code coverage once the top commit is built. Considering that Coveralls retains the entire history but does not fail the build if coverage falls below the threshold, all workflows have a built-in 80% threshold, applied internally within the build-cake job, particularly during the "Cake Build" step-action. If the code coverage of a newly opened pull request drops below the 80% threshold, the build-cake job will fail, logging an appropriate message in the "Cake Build" step. For your information, the current code coverage of the Ocelot project is around 85-86%. The coverage threshold is subject to change in upcoming releases. All Coveralls builds can be viewed by navigating to the ThreeMammals/Ocelot project on Coveralls.io.
The main Ocelot package and all extension packages reference net8.0 and net9.0 target framework monikers (TFMs). Refer to TargetFrameworks to verify this. The net6.0 and net7.0 TFMs have been removed. If your project still relies on these outdated TFMs, please continue using version 23.4.3.
Testing of Identity Server Bearer Tokens functionality was stopped due to vulnerabilities reported by Dependabot, specifically the "IdentityServer Open Redirect vulnerability" security issue. More technical details were provided in the 23.4.3 release notes, where we notified the community. Ultimately, issue #2218 was addressed via pull request #2274.
Administration:Note: In upcoming releases, we plan to utilize the ASP.NET Core Identity framework in our acceptance testing project to align with .NET industry standards. As a result, we intend to replace the IdentityServer4 library with ASP.NET Core Identity, which also supports Bearer tokens, also known as
JwtBearerHandlerfrom the Microsoft.AspNetCore.Authentication.JwtBearer namespace.
The Ocelot.Administration extension package has been renamed to Ocelot.Administration.IdentityServer4 (it is scheduled for deprecation) to address all IdentityServer4-related vulnerabilities (issue #2218). The package's source code has been moved out of the Ocelot repository (pull request #2274) and transferred to the newly created Ocelot.Administration.IdentityServer4 repository.
Kubernetes:Note: Currently, the Administration feature is solely based on the IdentityServer4 package, whose repository was archived by its owner on July 31, 2024. The Ocelot team will deprecate the new Ocelot.Administration.IdentityServer4 extension package after the current Ocelot release; however, the repository will not be archived, allowing for potential patches in the future.
KubeClient, which is created from the pod account during Install-ation. As a team, we decided to add the new AddKubernetes(Action<KubeClientOptions>) method, which handles different user scenarios. It is now possible to provide manually configured KubeClientOptions in C# during Install-ation, but users can also reuse ServiceDiscoveryProvider options from the global configuration, including the Host option to construct the kubernetes endpoint address. The new overloaded AddKubernetes(Action<KubeClientOptions>) method was implemented in pull request #2257.KubeClient dependency library version was upgraded to 3.0.x, which requires .NET 8.0 and .NET 9.0 TFMs for the current Ocelot version 24.0. KubeClient v3 was internally reviewed and released specifically to meet Ocelot's needs for this release. Thanks to Adam Friedman (@tintoy) for his collaboration! This package upgrade was implemented in pull request #2266.The learning Samples projects were reviewed, rewritten, and refactored due to issue #1912. The community brought to our attention that the documentation and samples were outdated, as .NET 8 allows the Program.cs file to be minimized using the "Top-level statements" feature. This was ultimately addressed in pull requests #2244 and #2258.
📓 Due to the major version increase to v24, all documentation chapters were reviewed to improve readability, eliminate ambiguity, provide more useful tables and data schemas, update code snippets with the syntax of Top-level statements, and add handy samples, among other enhancements. The entire documentation is designed to be truly professional for senior developers while remaining easy to read for junior developers and newcomers who are starting to use the Ocelot gateway.
We believe that Ocelot students will ask fewer questions in 2025 😉
For students, we always recommend finding answers in Q&A category first. Honestly, it is advised to read existing discussions before opening a new question in repo discussions.
For true Ocelot patriots, we have added a README link to the smart Ocelot AI Guru assistant, which is always ready to answer any of your questions. Feel free to explore and interact with it! 😊
1st 🥇 goes to Adam Friedman for delivering 1 feature in 10 files changed
2nd 🥈 goes to Finn Fiedler for delivering 1 feature in 3 files changed
3rd 🥉 goes to J. Vanderlei for delivering 1 feature in 1 file changed with 49 insertions
⭐⭐⭐ Raman Maksimchuk, @raman-m
⭐ Adam Friedman, @tintoy
⭐ Finn Fiedler, @int0x81
⭐ J. Vanderlei, @jvanderlei
⭐ Kursat Aktas, @kursataktas
net9.0 TFM | .NET 9 release | +semver: majornet9.0 TFM | .NET 9 release | +semver: breaking (#2286)AddKubernetes method with KubeClientOptions param for the discovery provider (#2257)JwtSecurityTokenHandler with JsonWebTokenHandler in the Authentication docs according to breaking changes in .NET 8 Auth (#2238)UpstreamTemplatePatternCreator (#2225)net8.0, net9.0 target frameworks (#2230)StringExtensions (#2222)StringExtensions by @raman-m in #2222UpstreamTemplatePatternCreator by @int0x81 in #2225JwtSecurityTokenHandler with JsonWebTokenHandler in the Authentication docs according to breaking changes in .NET 8 Auth by @jvanderlei in #2238AddKubernetes method with KubeClientOptions param for the discovery provider by @raman-m in #2257IdentityServer4 packages and deactivate their functionality | IdentityServer Open Redirect vulnerability by @raman-m in #2274net9.0 TFM | .NET 9 release | +semver: breaking by @raman-m in #2286Full Changelog: 23.4.3...24.0.0
Upgrading from 23.4.0 - 23.4.2 to 23.4.3 introduces no breaking changes . However, some internal interfaces have been updated, which should not introd…
Milestone: Nov-December'24
Hot fixed versions: 23.4.0 — 23.4.2
Read the Docs: Ocelot 23.4 with PDF
🔥 Hot fixed issue: #2246
❤️ A sincere and heartfelt "Thank You" to Donny Tian, @donnytian for reporting the bug.
Upgrading from 23.4.0-23.4.2 to 23.4.3 introduces no breaking changes. However, some internal interfaces have been updated, which should not introduce IBC for 99.99% of projects. For further information, refer to the source code.
Regex caching by @raman-m in #2251Full Changelog: 23.4.2...23.4.3
Dependabot alerts concerning reported vulnerabilities related to IdentityServer4 have not yet been addressed; these will be resolved in the next major…
Milestone: Nov-December'24
Hot fixed version: 23.4.1
Read the Docs: Ocelot 23.4 with PDF
This is the last patched version for .NET 6 and 7 frameworks. The upcoming major release, version 24.0, will target .NET 9 alongside the LTS .NET 8. Projects targeting .NET 6 or 7 should update to this version while considering an upgrade to .NET 8 or 9 in the future.
net6.0 and net7.0 frameworks, along with the LTS net8.0.IdentityServer4 have not yet been addressed; these will be resolved in the next major release (refer to Warnings further information).23.4.* is possible.IdentityServer4, allowing Ocelot users to utilize any authentication provider, as Ocelot's Authentication feature is provider-agnostic.IdentityServer4 library.Ocelot.Cache.CacheManager, Ocelot.Tracing.Butterfly, and Ocelot.Tracing.OpenTracing.net6.0 and net7.0 target frameworks and bump all packages by @raman-m in #2220Full Changelog: 23.4.1...23.4.2
📦 Routing patch (version 23.4.1 ) for v 23.4.0
Milestone: Nov-December'24
Read the Docs: Ocelot 23.4 with PDF
Hot fixed version: 23.4.0
❤️ A heartfelt "Thank You" to Guillaume Gnaegi (@ggnaegi)
🔥 Hot fixed issues: #2165, #2209, #2212
SecurityOptions by @Fabman08 in #2170Full Changelog: 23.4.0...23.4.1
🔀 Routing Update (version 23.4 ) a.k.a. the McDonald's release
Milestone: Nov-December'24 👈
Codenamed: McDonald's
Read the Docs: Ocelot 23.4 with PDF
This minor release significantly upgrades the Routing feature by supporting embedded placeholders within path segments (between slashes). Additionally, the team has focused on enhancing the performance of Regex objects.
/{url}-2/ for /y-2/ would yield {url} = y-2. We are excited to introduce an enhanced method for evaluating placeholders that allows for the resolution of placeholders within complex URLs.Regex logic has been refactored by @EngRajabi.Regex objects, striving to adhere to the Best Practices for Regular Expressions in .NET. It is estimated that each request could save from 1 to over 10 microseconds in processing time (though no benchmarks have been developed to measure this).X-Rate-Limit-* headers (found in the RateLimitingHeaders class) in the RateLimitingMiddleware's response. For more details, see PR #1307.OcelotPipelineConfiguration.ClaimsToHeadersMiddleware property has been introduced by @kesskalli.1st 🥇 goes to Mohsen Rajabi for delivering 1 feature in 12 files changed
2nd 🥈 goes to Jolanta Łukawska for delivering 1 feature in 8 files changed
3rd 🥉 goes to Karim Esskalli for delivering 1 feature in 6 files changed
⭐ Mohsen Rajabi, @EngRajabi
⭐ Jolanta Łukawska, @jlukawska
⭐ Raman Maksimchuk, @raman-m
⭐ Karim Esskalli, @kesskalli
⭐ Guillaume Gnaegi, @ggnaegi
Regex performance review (#1348)HttpContext response accessed via IHttpContextAccessor (#1307)ClaimsToHeadersMiddleware by the OcelotPipelineConfiguration settings (#1403)ClaimsToHeadersMiddleware by the OcelotPipelineConfiguration settings by @kesskalli in #1403HttpContext response accessed via IHttpContextAccessor by @jlukawska in #1307Regex performance review by @EngRajabi in #1348Full Changelog: 23.3.6...23.4.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This commit was created on GitHub.com and signed with GitHub’s verified signature .
d2a79ac
This commit was created on GitHub.com and signed with GitHub’s verified signature .
GPG key ID: B5690EEEBB952194
Verified Learn about vigilant mode .
Milestone: February'24 👈 Codenamed: Lunar Eclipse Read the Docs: Ocelot 23.2 with PDF
Configuration : A brand new Merging files to memory feature by @ebjornset as a part of the Merging Configuration Files one. The AddOcelot method merges the ocelot.*.json files into a single ocelot.json file as the primary configuration file, which is written back to disk and then added to the IConfigurationBuilder for the well-known IConfiguration . You can now call another AddOcelot method that adds the merged JSON directly from memory to the IConfigurationBuilder , using AddJsonStream instead. See more details in Configuration Overview of Dependency Injection .
Service Fabric : Published old undocumented " Placeholders in Service Name " feature of Service Fabric service discovery provider . This feature by @FelixBoers is available starting from version 13.0.0 .
Quality of Service : A brand new Polly v8 pipelines Extensibility feature by @RaynaldM
Updates of the features : Configuration, Dependency Injection and QoS
Configuration : New Merging files to memory feature by @ebjornset
Dependency Injection : Added new overloaded AddOcelot methods by @ebjornset
Quality of Service : Support of new Polly v8 syntax and new Extensibility feature by @RaynaldM Ocelot extra packages
Ocelot.Provider.Polly : Support of new Polly v8 syntax. Polly 8.0+ versions introduced the concept of resilience pipelines . All AddPolly extensions have been automatically migrated from v7 to v8 . Please note that older v7 extensions are marked with the [Obsolete] attribute and renamed using the V7 suffix. And the old v7 implementation has been moved to the v7 namespace . See more details in Polly v7 vs v8 section of Quality of Service chapter. Stabilization aka bug fixing
683 by PR 1927 New rules have been added to Ocelot's configuration validation logic to find duplicate placeholders in path templates. See more in the FileConfigurationFluentValidator class. Thanks to @AlyHKafoury !
1518 hotfix by PR 1986 Using the default IServiceCollection DI extensions to register Ocelot services resulted in the ServiceCollection provider being forced to be created by calling BuildServiceProvider() . This resulted in problems with dependency injection libraries, or worse, causing the Ocelot app to crash! See more in the ServiceCollectionExtensions class. Thanks to @ArwynFr !
See all bugs of the February'24 milestone
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →