v0.2.0
Pre-releaseThe first release with a data plane on more than one operating system, and the first
with people in it rather than a shared secret.
Still pre-alpha. Every packet goes through a relay — there are no direct peer-to-peer
paths yet, so throughput and latency are worse than any mature mesh and a self-hoster pays
for that bandwidth. There are no mobile clients. Access policy is enforced on Linux only.
macOS is a real data plane
A tunnel (#152), names that resolve (#153), a full-tunnel default route (#166), egress that
is refused unless it goes through the tunnel (#169), recovery from a change of network or a
killed agent (#171), and a launchd daemon so none of it needs a terminal (#197).
Five bugs in the macOS egress claim were found by running it on a laptop rather than in a
test, and fixed in #201, #203, #209 and #210 — cloned routes counted as the plan's, a
route belonging to another tunnel counted as a local network, and a claim could not survive
losing DNS.
Windows is a real data plane
A tunnel over WinTun (#175), names through NRPT (#178), a full-tunnel default route (#180),
egress refused through meshp's own WFP layer (#182), and a service that answers the service
control manager properly (#198).
Each of the three platforms is exercised on a real runner of that operating system in CI,
not cross-compiled.
People, not a shared secret
Local accounts with passwords and sessions (#140), permissions and roles scoped to a
network (#142), API tokens that can never grant more than their owner has (#143), and an
audit trail that names who did it (#141). Sign-in slows an attacker down without ever
locking a real person out (#173).
meshp-control --bootstrap stands a deployment up with no shared secret at all (#163), and
an organisation is created over the API rather than with psql (#132). meshp login mints a
token and keeps it, so the CLI stops asking for the admin credential (#214).
MESHP_ADMIN_TOKEN still works. It is now bootstrap and break-glass rather than the
recommendation — see ADR-0024.
More than one of everything
A change on one control plane reaches agents connected to another (#155), the overview stops
reporting other replicas' devices as disconnected (#157), and a relay can be drained without
a restart (#162). Redundancy is not a paid feature.
Operations
The agent rotates its own log, because on macOS nothing else can (#199). The control plane
has somewhere to keep the certificates it obtains (#192) — the shipped systemd unit could
not previously serve TLS at all. Devices notice a change of network instead of waiting for
the next tick (#184).
Upgrading from v0.1.0
Nothing invalidates an existing deployment. The admin token still works, and the schema
migrates forward on start. Migration 0016 replaces a unique constraint on token names with a
partial index so a revoked token's name becomes free again; its down-migration deliberately
fails rather than silently discarding rows.
What's Changed
- fix(install): a pre-release is an answer, not a missing version by @aswinsam in #111
- feat(api): one endpoint answers whether anything in a network is broken by @aswinsam in #113
- feat(api): a browser gets a cookie, and the cookie can only read by @aswinsam in #114
- feat(web): a page that answers whether anything is broken by @aswinsam in #115
- feat(paths): a device says what its tunnel is actually doing by @aswinsam in #118
- feat(api): the overview says what is wrong, not only what is true by @aswinsam in #119
- test(install): cover the branch that runs when nobody names a version by @aswinsam in #120
- ci(reachability): fail on a mechanism nothing reaches by @aswinsam in #122
- feat(routes): record which candidate a device says it is using by @aswinsam in #123
- feat(routes): a device moving between candidates is auditable by @aswinsam in #124
- feat(api): the audit trail has a reader by @aswinsam in #125
- feat(web): the page shows why something moved by @aswinsam in #126
- feat(dns): the names an administrator writes down by @aswinsam in #127
- docs(reachability): say why the relays table is unread by @aswinsam in #129
- fix(prefixmap): a mapped range must not land on a reachable network by @aswinsam in #130
- feat(cli): meshp down, and the decision it turns on by @aswinsam in #131
- feat(api): an organisation is created over the API, not with psql by @aswinsam in #132
- docs(adr): local user accounts, and what becomes of the admin token by @aswinsam in #133
- feat(auth): people, passwords and sessions by @aswinsam in #140
- feat(audit): the trail names who did it by @aswinsam in #141
- feat(authz): permissions, roles, and the networks they reach by @aswinsam in #142
- feat(authz): API tokens, and what they may never do by @aswinsam in #143
- feat(web): the page stops being read-only by @aswinsam in #147
- docs: stop teaching the admin token by @aswinsam in #149
- feat(dataplane): a tunnel on macOS by @aswinsam in #152
- feat(dns): names resolve on macOS by @aswinsam in #153
- feat(replicas): a change on one control plane reaches agents on another by @aswinsam in #155
- ci: Bump the codeql group across 1 directory with 3 updates by @dependabot[bot] in #150
- feat(replicas): the overview stops calling other replicas' devices disconnected by @aswinsam in #157
- chore: ignore the four binaries when built at the repository root by @aswinsam in #158
- feat(relays): a relay can be drained without a restart by @aswinsam in #162
- feat(control): meshp-control --bootstrap, and a deployment that needs no shared secret by @aswinsam in #163
- ci: every platform-sensitive package runs on macOS, and a test says which by @aswinsam in #164
- feat(dataplane): macOS can take a full-tunnel default route by @aswinsam in #166
- refactor(tunnel): the egress lock is its own collaborator by @aswinsam in #167
- docs(adr): fail-closed egress on macOS lives in a pf anchor under com.apple by @aswinsam in #168
- feat(dataplane): macOS refuses egress that does not go through the tunnel by @aswinsam in #169
- test(meshpd): the daemon's wiring is tested, and its nil checks are reachable by @aswinsam in #170
- fix(dataplane): a macOS laptop that changes networks or is killed recovers by @aswinsam in #171
- feat(api): a guessed-at account slows down, and is never locked out by @aswinsam in #173
- docs(adr): the Windows data plane is WinTun, shipped beside the binary by @aswinsam in #174
- feat(dataplane): Windows brings up a tunnel, and CI proves it by @aswinsam in #175
- docs: say what Windows can do, which is a tunnel and nothing above it by @aswinsam in #176
- fix: meshp doctor start hint is platform-aware by @VedantMadane in #156
- docs(adr): Windows split DNS is NRPT, and the resolver moves to port 53 there by @aswinsam in #177
- feat(dataplane): names resolve on Windows, through NRPT by @aswinsam in #178
- docs: Windows resolves names now, and its resolver is on 53 by @aswinsam in #179
- feat(dataplane): Windows can take a full-tunnel default route by @aswinsam in #180
- docs(adr): fail-closed egress on Windows is meshp's own WFP layer by @aswinsam in #181
- feat(dataplane): Windows refuses egress that does not go through the tunnel by @aswinsam in #182
- docs: Windows is complete, and its lock has no command to remove it by @aswinsam in #183
- feat(dataplane): notice a change of network instead of waiting for the tick by @aswinsam in #184
- ci: lint the platforms this runner is not by @aswinsam in #187
- docs: state what each platform can do once, and check it against the code by @aswinsam in #188
- fix(web): update the page in place instead of rebuilding it every poll by @aswinsam in #189
- fix(deploy): give the control plane somewhere to keep the certificates it obtains by @aswinsam in #192
- fix(dataplane): stop withdrawing the routes the kernel installed itself by @aswinsam in #193
- docs(testing): the first results for the macOS laptop checks, including a failure by @aswinsam in #194
- feat(deploy): a launchd daemon, so the macOS agent runs without a terminal by @aswinsam in #197
- feat(deploy): meshpd answers the Windows service control manager by @aswinsam in #198
- feat(agent): rotate the log, because nothing else can by @aswinsam in #199
- fix(dataplane): claim a full tunnel on macOS, which has never worked by @aswinsam in #201
- fix(dataplane): a route on the meshp interface is not automatically the plan's by @aswinsam in #203
- fix(control): tell devices when a route group is deleted by @aswinsam in #206
- test(dataplane): claim the way a device claims, so CI can see what a laptop saw by @aswinsam in #208
- deps: Bump golang.zx2c4.com/wireguard/windows from 0.5.3 to 1.0.1 by @dependabot[bot] in #190
- ci: Bump the codeql group across 1 directory with 3 updates by @dependabot[bot] in #191
- fix(dataplane): another tunnel on the host is not a local network by @aswinsam in #209
- fix(dataplane): remember the control plane's address, so a claim survives losing DNS by @aswinsam in #210
- feat(cli): meshp login, and the three server defects it found by @aswinsam in #214
New Contributors
- @VedantMadane made their first contribution in #156
Full Changelog: v0.1.0...v0.2.0