Repository navigation
v0.4.3
追加
- ほかのリスナーの名前のリクエストに 421 を返せるようになりました(#256)。
tls.misdirected(httpとtls.mode: terminateのルール)。HTTP/2 の接続の使い回しで、SNI と Host(:authority)が別のリスナーの名前に当たるとき、ルートもミドルウェアも通さずに 421 を返します(アクセスログrefused_by: misdirected)。省略すれば今までどおりです。features.http_optionsにmisdirected。 - 転送先ごとのミドルウェアに
cors・redirect_scheme・redirect_regex・mirrorを足しました(#258)。servers[].middlewaresで使えます。features.server_middleware_kindsに使える種類の一覧。 forward_authが Envoy の ext_authz の形で書けるようになりました(#259)。HTTP(送るヘッダ・本文・通す応答の選び方、["*"])と gRPC(envoy.service.auth.v3.Authorization/Check)。転送先ごとのミドルウェアにも書けます。features.forward_authに使える項目の名前。- まだノードにないアドレスで待ち受けられるようになりました(#257)。ルールの
"listen_freebind": true(IP_FREEBIND/IPV6_FREEBIND、TCP・UDP)。アドレスがあとから来ても、そのまま届きます。同じポートをアドレスごとに別のルールで使えます(tcp/192.0.2.10:443とtcp/192.0.2.11:443)。0.0.0.0 /::と同じポートの特定のアドレスは、今までどおり409 already_exists(重なる相手を誤りの文に出します)。 - TCP のルールの
connect_timeout(#257、100ms〜10m、PATCH でその場で変わります)。止まったノードの宛先は SYN に答えないので、これまで 5 秒(宛先が複数)か OS の再送(約 2 分、宛先が 1 つ)まで待っていました。
UI: TCP-UDP-rproxy-ui v0.4.2 · Kubernetes: rproxy-gateway
Added
- 421 for requests naming another listener (#256):
tls.misdirectedonhttpandtls.mode: terminaterules. When HTTP/2 connection coalescing makes the SNI and Host (:authority) fall into different listeners' names, rproxy answers 421 without running routes or middlewares (access logrefused_by: misdirected). Unchanged when omitted.misdirectedinfeatures.http_options. - Per-server middlewares gain
cors,redirect_scheme,redirect_regexandmirror(#258) inservers[].middlewares;features.server_middleware_kindslists the kinds. forward_authtakes Envoy ext_authz shapes (#259): HTTP (which headers and body to send, which answers to pass,["*"]) and gRPC (envoy.service.auth.v3.Authorization/Check), also as a per-server middleware.features.forward_authlists the fields.- Listening on addresses not on the node yet (#257):
"listen_freebind": trueon a rule (IP_FREEBIND/IPV6_FREEBIND, TCP and UDP); traffic flows once the address arrives. The same port can be used per address by different rules (tcp/192.0.2.10:443andtcp/192.0.2.11:443). A specific address on the same port as 0.0.0.0 /::still gets409 already_exists, naming the overlapping rule. connect_timeouton TCP rules (#257,100ms–10m, changeable live with PATCH). Targets on a dead node do not answer SYNs, so rproxy used to wait 5 s (several targets) or the OS retries (about 2 min, one target).
UI: TCP-UDP-rproxy-ui v0.4.2 · Kubernetes: rproxy-gateway