github cloudfoundry/cf-networking-release 2.18.0

latest releases: v3.11.0, v3.10.0, v3.9.0...
5 years ago

This release includes the following features

  • Update destination object API is now available for configuring dynamic egress policy configuration
  • Service accounts can now be used to access the policy server APIs
  • Policy server can now connect to databases on Google or Azure clouds with TLS enabled
    Tested with silk-release v2.18.0

Significant Changes

Manifest changes

  • An optional parameter has been added to the bosh-dns-adapter job to allow for internal service mesh domains. Routes created with these domains will be proxied through the sidecar envoy. This is a part of istio integration. Defaults to []
    • internal_service_mesh_domains
  • An optional parameter has been added to the policy-server job to skip host name validation when using ssl validation. The policy-server-internal uses the same configuration applied to policy-server via bosh links.
    • database.skip_hostname_validation

Dynamic Egress Policy Configuration

TLS connection from policy server

Allow service accounts to access policy server APIs

Miscellaneous

Don't miss a new cf-networking-release release

NewReleases is sending notifications on new releases.