Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

v1.29 Backports 2024-11-12 #1006

Merged
merged 4 commits into from
Nov 12, 2024
Merged

Conversation

sayboras
Copy link
Member

[ upstream commit 5e76843 ]

When a header is matched based on a SDS secret and there is no inline
value to use as a backup, the verdict should be deny if the secret is
missing. Also, if the secret value is empty, then the match should be a
presence match only.

Signed-off-by: Jarno Rajahalme <[email protected]>
Signed-off-by: Tam Mach <[email protected]>
[ upstream commit dc83bb3 ]

Add a rate limiter for error logs for UDS reconnects that are currently
spamming the logs during cilium agent restart.

Signed-off-by: Jarno Rajahalme <[email protected]>
Signed-off-by: Tam Mach <[email protected]>
[ upstream commit 0a83534 ]

Add policy stats for number of updates, rejected updates, and update time
limit timeouts.

Make the update time limit configurable via BfpMetadata filter config, as
the policy map is created from there. Default is the same as in Cilium
Agent (100ms).

Signed-off-by: Jarno Rajahalme <[email protected]>
Signed-off-by: Tam Mach <[email protected]>
[ upstream commit c35cf76 ]

Cilium tls_wrapper should allow raw socket to be used if policy allows
without TLS context.

Also check for SNI when getting TLS context so that the one matching the
SNI is used if multiple are available.

Add policy tests validating the policy functionality.

Signed-off-by: Jarno Rajahalme <[email protected]>
Signed-off-by: Tam Mach <[email protected]>
@sayboras sayboras marked this pull request as ready for review November 12, 2024 08:13
@sayboras sayboras requested a review from a team as a code owner November 12, 2024 08:13
Copy link
Member

@jrajahalme jrajahalme left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the backports!

@sayboras sayboras merged commit 2c13e1e into v1.29 Nov 12, 2024
5 checks passed
@sayboras sayboras deleted the pr/v1.29-backport-2024-11-12-07-03 branch November 12, 2024 09:46
sayboras added a commit to cilium/cilium that referenced this pull request Nov 12, 2024
github-merge-queue bot pushed a commit to cilium/cilium that referenced this pull request Nov 12, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants