Skip to content

Releases: InteractionLabs/traversal-connector

v0.8.9

Choose a tag to compare

@github-actions github-actions released this 29 Sep 17:26
0879dc5

accept upstream TLS CA from a file via UPSTREAM_TLS_CA_FILE

v0.8.8

Choose a tag to compare

@github-actions github-actions released this 26 Sep 16:18
6af233c

Use HTTP and HTTPS proxy when set for upstream requests.

v0.8.7

Choose a tag to compare

@github-actions github-actions released this 23 Sep 19:43
ae9eb58

Adds optional curl-style connect-to overrides for the controller and OTLP telemetry. Operators can connect sockets directly to local Kubernetes gateway Services while preserving the external logical hostname for TLS verification and HTTP/gRPC routing identity.

v0.8.6

Choose a tag to compare

@github-actions github-actions released this 22 Sep 22:46
1bf4332

Extend controller TLS system roots with custom CA roots while preserving the connector container system trust store.

v0.8.5

Choose a tag to compare

@github-actions github-actions released this 22 Sep 13:58
63400f5

Changes

  • Extend the connector container's system CA roots with configured upstream CA certificates instead of replacing them.
  • Restart connector pods when inline controller or upstream TLS certificate values change.

Compatibility

Existing upstreamTLS.caPEM and upstreamTLS.existingSecret configuration remains compatible.

v0.8.4

Choose a tag to compare

@github-actions github-actions released this 14 Sep 21:49
deaadb9
  • Reject oversized tunnel messages before deserialization
  • Match redaction hostnames the way DNS does, and refuse a JSON-declared body that is not one complete document.
  • Record the destination host instead of the full request URL in telemetry.

Helm chart published retroactively during PLAT-2102 from the final historical chart snapshot in InteractionLabs/go-traversal@c000cc486f76283105a2e2ce1a31562d99a5b3fa. The chart was not rebuilt from current source or modernized during migration.

v0.8.3

Choose a tag to compare

@github-actions github-actions released this 10 Sep 23:59
39ac395

Ship signed connector image

v0.8.2

Choose a tag to compare

@github-actions github-actions released this 03 Sep 16:34
b6103ac

Remove the remaining vulnerability findings from the Connector image by updating its Go dependencies.

v0.8.1

Choose a tag to compare

@github-actions github-actions released this 02 Sep 16:52
584a2e1

Update the Go toolchain and dependencies.

v0.8.0

Choose a tag to compare

@github-actions github-actions released this 01 Sep 22:36
b9f4783

Redaction now covers gzip-compressed response bodies. A gzip response previously bypassed redaction entirely and left the customer network unredacted.

Responses in a coding the connector cannot decode (deflate, zstd, br, or stacked codings) are now dropped rather than forwarded, as are 206 Partial Content responses on hosts with redaction rules.

Two new settings bound response reads: MAX_RESPONSE_BODY_SIZE_MB (default 32) and MAX_DECODED_RESPONSE_BODY_SIZE_MB (default 256).

Helm chart published retroactively during PLAT-2102 from the final historical chart snapshot in InteractionLabs/go-traversal@3cd51e02cefd79ca88523411e7893c10ee5326a1. The chart was not rebuilt from current source or modernized during migration.