-
Notifications
You must be signed in to change notification settings - Fork 2.8k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
v1.14 Backports 2024-01-16 #30265
Merged
Merged
v1.14 Backports 2024-01-16 #30265
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
[ upstream commit e71407b ] This change adds a check in the auth manager not to do authentication for either IDs if they are reserved. This could have caused failed handshakes to happen should any of these entities be allowed by policy but with mutual auth enabled. These IDs do are not able to ever complete a handshake as they are not generated by design. This commit also replaces all IDs used in tests to be high enough that they do not conflict with reserve IDs. Signed-off-by: Maartje Eyskens <maartje@eyskens.me> Signed-off-by: Sebastian Wicki <sebastian@isovalent.com>
[ upstream commit 680b0d1 ] Bump the timeout to fix cancelled test runs that have started to pop up in CI. Signed-off-by: Julian Wiedmann <jwi@isovalent.com> Signed-off-by: Sebastian Wicki <sebastian@isovalent.com>
[ upstream commit 284b41d ] This removed level=error errors from the spire-client system in the operator. As it is expected to fail on initial startup of SPIRE to have connection issues Cilium will retry. Some errors also came from the SPIFFE library itself which is why a wrapper to log them as warnings instead was added. Signed-off-by: Maartje Eyskens <maartje.eyskens@isovalent.com> Signed-off-by: Sebastian Wicki <sebastian@isovalent.com>
[ upstream commit a255997 ] We previously looked up the chaining mode by name, but this is non-obvious and unnecessary. So, we added the CHI chaining-mode parameter. But, we failed to update the docs to reference this. Fixes: #28714 Signed-off-by: Casey Callendrello <cdc@isovalent.com> Signed-off-by: Sebastian Wicki <sebastian@isovalent.com>
julianwiedmann
approved these changes
Jan 16, 2024
/test-backport-1.14 |
brlbil
approved these changes
Jan 16, 2024
squeed
approved these changes
Jan 16, 2024
meyskens
approved these changes
Jan 17, 2024
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM for my changes!
CI is green, remaining reviews are trivial. Merging this to unblock the release. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
backport/1.14
This PR represents a backport for Cilium 1.14.x of a PR that was merged to main.
kind/backports
This PR provides functionality previously merged into master.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
manager_test.go
:ReservedIdentityWorldIPv6
toReservedIdentityWorld
for v1.14Test_authManager_handleCertificateDeletionEvent
as that test function does not exist in v1.14Once this PR is merged, a GitHub action will update the labels of these PRs: