Skip to content

v0.4.3

Choose a tag to compare

@github-actions github-actions released this 09 Oct 05:12
· 28 commits to master since this release
14cad36

追加

  • ほかのリスナーの名前のリクエストに 421 を返せるようになりました(#256)。tls.misdirected(http と tls.mode: terminate のルール)。HTTP/2 の接続の使い回しで、SNI と Host(:authority)が別のリスナーの名前に当たるとき、ルートもミドルウェアも通さずに 421 を返します(アクセスログ refused_by: misdirected)。省略すれば今までどおりです。features.http_options に misdirected。
  • 転送先ごとのミドルウェアに cors・redirect_scheme・redirect_regex・mirror を足しました(#258)。servers[].middlewares で使えます。features.server_middleware_kinds に使える種類の一覧。
  • forward_auth が Envoy の ext_authz の形で書けるようになりました(#259)。HTTP(送るヘッダ・本文・通す応答の選び方、["*"])と gRPC(envoy.service.auth.v3.Authorization/Check)。転送先ごとのミドルウェアにも書けます。features.forward_auth に使える項目の名前。
  • まだノードにないアドレスで待ち受けられるようになりました(#257)。ルールの "listen_freebind": true(IP_FREEBIND / IPV6_FREEBIND、TCP・UDP)。アドレスがあとから来ても、そのまま届きます。同じポートをアドレスごとに別のルールで使えます(tcp/192.0.2.10:443 と tcp/192.0.2.11:443)。0.0.0.0 / :: と同じポートの特定のアドレスは、今までどおり 409 already_exists(重なる相手を誤りの文に出します)。
  • TCP のルールの connect_timeout(#257、100ms〜10m、PATCH でその場で変わります)。止まったノードの宛先は SYN に答えないので、これまで 5 秒(宛先が複数)か OS の再送(約 2 分、宛先が 1 つ)まで待っていました。

UI: TCP-UDP-rproxy-ui v0.4.2 · Kubernetes: rproxy-gateway


Added

  • 421 for requests naming another listener (#256): tls.misdirected on http and tls.mode: terminate rules. When HTTP/2 connection coalescing makes the SNI and Host (:authority) fall into different listeners' names, rproxy answers 421 without running routes or middlewares (access log refused_by: misdirected). Unchanged when omitted. misdirected in features.http_options.
  • Per-server middlewares gain cors, redirect_scheme, redirect_regex and mirror (#258) in servers[].middlewares; features.server_middleware_kinds lists the kinds.
  • forward_auth takes Envoy ext_authz shapes (#259): HTTP (which headers and body to send, which answers to pass, ["*"]) and gRPC (envoy.service.auth.v3.Authorization/Check), also as a per-server middleware. features.forward_auth lists the fields.
  • Listening on addresses not on the node yet (#257): "listen_freebind": true on a rule (IP_FREEBIND / IPV6_FREEBIND, TCP and UDP); traffic flows once the address arrives. The same port can be used per address by different rules (tcp/192.0.2.10:443 and tcp/192.0.2.11:443). A specific address on the same port as 0.0.0.0 / :: still gets 409 already_exists, naming the overlapping rule.
  • connect_timeout on TCP rules (#257, 100ms–10m, changeable live with PATCH). Targets on a dead node do not answer SYNs, so rproxy used to wait 5 s (several targets) or the OS retries (about 2 min, one target).

UI: TCP-UDP-rproxy-ui v0.4.2 · Kubernetes: rproxy-gateway