Repository navigation
Version 5.2.0
Release description
Airlock Microgateway helps you to protect your services and APIs from unauthorized or malicious access with little effort. It is a lightweight and Kubernetes-native Web Application and API Protection (WAAP) solution designed to overcome the DevSecOps obstacles and to implement ZeroTrust.
Main new features
- GeoIP support
- Opaque token support
- JWT validation for Token Exchange
- Secure handling of path segment parameters
- HTTP request mirroring
- Software Bill of Materials (SBOM)
Breaking changes
- Handling of Path Segment Parameters
A new deny rule blocks requests with semicolons in their path to protect backends from malicious use of path segment parameters.
If your backend requires path segment parameters (also known as matrix parameters, e.g.,/users;id=5/) to work, a deny rule exception forruleKeySANITYoftypePathis required to ensure that requests using such parameters are properly forwarded to the backend.
Gateway API upgrade notes
This release adds support for Kubernetes Gateway API v1.6 and implements all features of the HTTPRoute profile.
If you are upgrading both Microgateway and Gateway API, ensure that Gateway API is upgraded first.
Important
- Downgrading from Gateway API CRDs v1.6 to an earlier version is not supported
- Installing the experimental channel on a cluster where the standard channel CRDs are already installed is not supported
For more information, see Gateway API v1.6.0.
Licensing
Airlock Microgateway Community Edition can be used without a license for ingress-focused setups, such as replacing Ingress NGINX. A license is only required when configuring premium features.
Helpful links
Deny rule changelog
- NEW: AD-540 Added new feature to the sanity deny rule blocking empty path segments
- NEW: AD-541 Added new feature to the sanity deny rule blocking path segment parameters
- FIX: AD-601 Reduced false positives of SQL_001 (CASE-37430, CASE-37293)
Changelog
- NEW: AM-5246 Added support for Gateway addresses to configure a static external load balancer IP address
- NEW: AM-5468 Added support for HTTPRoute request mirroring
- NEW: AM-5574 Added new Session Agent metric "microgateway_active_sessions"
- NEW: AM-5928 JWT validation for token exchange implemented (JWKS, times, issuer)
- NEW: AM-6137 Added support for validating exchanged JWTs
- NEW: AM-6183 Added identity propagation support for individual claims of OIDC access token
- NEW: AM-6264 Validation for ciphers, curves and signature algorithm names in TLS options
- NEW: AM-6963 Added support for validating JWT access tokens obtained by OIDC flow
- NEW: AM-7095 Added support for RequestHeaderModifier, ResponseHeaderModifier and URLRewrite (hostname-only) HTTPRoute filters for BackendRefs
- NEW: AM-7274 Implemented GeoIP lookup and command operators
- NEW: AM-7280 Implemented GeoIP request condition matcher
- NEW: AM-7298 Added additional artifacthub.io metatada to the Helm chart
- NEW: AM-7356 Added support for token exchange of opaque tokens extracted from the request
- NEW: AM-7385 Added support for the experimental XBackend kind in backendRefs of HTTPRoute to reference backends of type ExternalHostname as an alternative approach to Services of type ExternalName
- NEW: AM-7528 Added support for pathSegmentParameter type for DenyRules (built-in checking, overrides, exceptions and custom rules)
- NEW: AM-7653 Added Request Origin data to Threat, Access Control and Downstream Metric Dashboards
- FIX: AM-7590 Corrected handling of Gateway perPort TLS overrides so that an empty tls: {} now disables frontend client certificate validation on that port instead of being ignored
- CHG: AM-5087 Do not remove authorization headers on successful OIDC authentication
- CHG: AM-6460 Added Clear-Site-Data header to response builtin headers allow list
- CHG: AM-7096 HTTPRoute retries are now limited to safe requests and are directed to a different upstream host each time, if possible
- CHG: AM-7204 Changed behavior of Request Conditions matching on paths to ignore path segment parameters
- CHG: AM-7477 Respond with 403 instead 401 on AccessControl authorization condition violations
- CHG: AM-7669 Reduce backend connect timeout to 4 seconds
- CHG: AM-7697 Ignore path segment parameters for route matching
- CHG: AM-7732 JWT validation field 'expirationRequired' is now optional
- UPD: AM-7140 Updated Envoy to v1.39