2.1.0-rc1 (September 28, 2026)
BREAKING CHANGES:
- cli: Migrated the
consul connect redirect-trafficcommand fromiptables/ip6tablestonftables(nft). The command now uses thesdk/nftablespackage, which applies all IPv4 and IPv6 rules atomically in a single pass via thenftablesinetaddress family, instead of separateiptablesandip6tablesinvocations. [GH-23785] - cli: Transparent proxy exclusions are now validated before rules are applied: user IDs must be numeric and outbound exclusions must be IP addresses or CIDRs.
iptablespreviously also accepted user names, UID ranges, and host names. [GH-23785] - cli:
consul connect redirect-trafficdoes not removeiptables/ip6tablesrules created by earlier Consul versions. This only matters when upgrading an existing host or VM in place. Before running the new command on an existing host or VM, remove any Consul-managediptablesrules first (see the transparent proxy upgrade guide for a reference cleanup script). Leaving both rule sets in place can cause double NAT or inconsistent traffic redirection. [GH-23785] - docker: The official Consul container images now include
nftablesinstead ofiptables. Scripts that runiptablesinside the Consul image must be updated. [GH-23785] - sdk: Replaced the
iptablespackage with a newnftablespackage for transparent proxy traffic redirection. Traffic redirection now requires thenftbinary and a Linux kernel with stateful NAT support innftablesinetfamily chains, available upstream starting with Linux kernel version 5.2 (some distributions backport this support onto an earlier nominal kernel version, for example RHEL 8+, kernel 4.18+, and its derivatives). There is no automatic fallback toiptables/ip6tables, so hosts without this kernel support will fail to set up transparent proxy redirection. [GH-23785]
SECURITY:
- Added debounce behavior to enforce a minimum interval between expensive federation-state anti-entropy sync operations. [GH-23196]
- Update
brace-expansionto address GHSA-rgw5-rvv9-x895 (DoS via unbounded intermediate arrays). [GH-23786] - Update
fast-urito address GHSA-7p8r-x3mc-p8w7 (Host Confusion via backslash authority introducer). [GH-23786] - Update
socket.io-parserto address CVE-2026-69185 (Zero-attachment Memory Exhaustion). [GH-23786]
FEATURES:
- agent: (Enterprise only) Add an inline
aiblock to service definitions, letting a workload declare its AI role (inference-model,mcp-server, orai-agent) and role-specific configuration in a single registration via config files and HTTP APIs. [GH-13032] - api-gateway: Add
http2andgrpcas valid API Gateway listener protocols, enabling end-to-end HTTP/2 and gRPC from client to backend. Previously onlyhttpandtcpwere accepted; the gateway would silently downgrade gRPC/HTTP2 traffic to HTTP/1.1 on the upstream hop. The new protocols render the correct downstream HTTP connection manager (HTTP/2 codec,h2,http/1.1ALPN) and align the upstream cluster to HTTP/2, closing the parity gap with Ingress Gateway. [GH-23784] - api-gateway: Auto-register DNS for services exposed via an API Gateway, resolvable at
<service>.api-gateway.consul. Populates thegateway-servicescatalog mapping for API Gateways and adds DNS SANs to the API Gateway Connect leaf certificate, bringing API Gateway to parity with Ingress Gateway. The feature is version-gated and backfills pre-existing gateways automatically once all servers are upgraded. [GH-23647] - api-gateway: Support zero-touch downstream TLS termination. When
TLS { Enabled = true }is set on anapi-gatewayconfig entry with no inline/file-system/SDS certificate, the gateway terminates downstream TLS using its Connect CA leaf certificate (with*.api-gateway.consulDNS SANs). Explicitly configured certificates continue to take precedence and are served as SNI overrides alongside the leaf default chain. [GH-23647] - api-gateway: add
PassiveHealthCheckto gateway-level default upstream limits and route service-level limit overrides, so passive health checking (Envoy outlier detection) can be configured for services routed through an API gateway. [GH-23783] - cli: (Enterprise only)
consul connect envoy -gateway=inferencelaunches the policy processor alongside Envoy and enforces a minimum Envoy version for the inference gateway. The ext_proc socket is derived per proxy instance;-ext-proc-socket-diroverrides its directory (default/var/run/consul). - connect: (Enterprise only) Added an agent-managed OAuth client lifecycle for services with
ai.roleofai-agentormcp-server, including dynamic client registration with IBM Security Verify, key rotation, JWKS publication, and SDS delivery of the OAuth client credential toai-agentEnvoy sidecars. - connect: (Enterprise only) Deliver OAuth sidecar credentials as AES-256-GCM envelopes. Content-encryption keys are persisted in KV and served via WorkloadKeyService.FetchKey so consul-obo-outbound can decrypt without becoming an SDS client.
- connect: (Enterprise only) Wire consul-obo-outbound and consul-obo-inbound ext_proc filters into connect-proxy xDS for hop-bound on-behalf-of token exchange.
- connect: (Enterprise only) Register services with
ai.roleofai-agentormcp-serverwith IBM Security Verify usingprivate_key_jwt, persist DCR/JWKS in KV, and deliver the client credential to Envoy as SDS GenericSecret JSON forai-agentworkloads. Cluster IAM is an OIDC ACL auth method withEnableServiceDCR=true(agentoauth.iamHCL is rejected). - connect: add
ecdh_curvestomeshconfig entries (MeshDirectionalTLSConfig) andtls_ecdh_curvesto agent TLS configuration (TLSProtocolConfig) to support configuring allowed ECDH/KEM curves for sidecar mTLS and agent RPC/HTTPS/gRPC, with automatic hybrid Post-QuantumX25519MLKEM768curve injection whentls_min_versionis set toTLSv1_3. [GH-23884] - feature-gates: Add Raft-backed dynamic feature gate framework (Phase 1). A new
feature_gates { bootstrap = { ... } }server configuration block seeds the first Raft policy. The leader continuously reconciles desired policy, minimum-version eligibility, and registry defaults into a committed resolved status. Every server runs an atomic cache populated only from committed FSM state; agents consume an indexed resolved snapshot and fail closed until the first generation is delivered. New operator CLI commandsconsul operator feature list,get, andsetprovide CAS-safe, ACL-protected inspection and control of feature gates.
feature-gates: Gate API Gateway HTTPRoute upstream-routing composition (PR #23294) behind the experimental featureapi-gateway-upstream-routing. When disabled (default), the legacy HTTPRoute-to-router shape is preserved exactly. When enabled by an operator after a full datacenter upgrade, service-router rules are composed with HTTPRoute matches, resolver subset definitions are preserved, and discovery-chain watches use the correct HTTP protocol override. Existing agentless API Gateway proxy states are rebuilt automatically when the effective gate value changes.
operator: AddGET /v1/operator/features,GET /v1/operator/feature/:name, andPUT /v1/operator/feature/:nameHTTP endpoints for reading and updating feature gate state. Reads requireoperator:read; writes requireoperator:write. All reads are blocking-query capable. [GH-23791] - inference-gateway: (Enterprise only) Route opted-in external inference models through a terminating gateway. Models marked with the terminating-gateway egress are discovered from the catalog, resolved through the mesh discovery chain, and load-balanced across healthy terminating-gateway replicas, with capability-pool priority tiers and fail-closed behavior when no valid transport is available. A capability pool containing an external model is rejected, and its capability route returns 503, when two of its models render the same endpoint address or its model weights cannot be represented exactly.
- inference-gateway: (Enterprise only) Add the
inference-gatewayservice kind and config entry. The gateway terminates inbound mesh mTLS, enforces intentions, and applies PII and routing policy through an ext_proc filter to a co-located policy processor. Model upstreams are services registered withai.role = "inference-model"that intentions allow and that are reachable through the mesh (connect-enabled or behind a terminating gateway). The gateway connects to them over mTLS and selects them by capability, failing over across providers by priority. - telemetry: (Enterprise only) Added server-side product usage metrics for ACL auth method counts (OIDC, Kubernetes, JWT) and audit logging config.
- telemetry: (Enterprise only) Added server-side product usage metrics for mesh gateway mode counts:
consul.usage.mesh_gateway_remote.countandconsul.usage.mesh_gateway_local.countreport the number of service instances configured to use each mesh gateway mode, andconsul.usage.mesh_gateway_none.countreports the number of service instances with no explicit mesh gateway mode (unset ornone). - telemetry: (Enterprise only) Added server-side product usage metrics for service intention default policy, service intention L7 and JWT counts
- telemetry: (Enterprise only) Added the server-side product usage metric
consul.usage.mesh_gateway_enabled, which reports whether any mesh gateway instance is registered in the cluster. It is independent of the mesh gateway mode counts: those count connect-proxy sidecars by their upstream routing mode, while this reports whether the gateway capability is deployed at all. - terminating-gateway: (Enterprise only) Add Vault-backed credential injection at the terminating gateway egress. A
TerminatingGatewayconfig entry now carries aCredentialInjectionblock (ext_proc processor UDS path and message timeout) and each linked service can declare aCredentialbinding (Mode: "inject"with aBindingID). At egress, an ext_proc filter calls a co-located processor that injects the bound credential (e.g. a provider API key sourced from Vault) into the upstream request, so credentials are never stored in mesh config or exposed to clients. - xds: Add an inline "virtual DNS" UDP listener (127.0.0.1:8653) that serves an in-memory FQDN-to-VIP table derived from the proxy snapshot. It advertises VIPs for explicit upstreams, intention-allowed upstreams in transparent proxy mode, and cluster peering upstreams, while skipping cross-partition VIPs, stale/unauthorized discovery chains, and empty or non-IP entries so DNS responses stay in sync with what the transparent-proxy listener will actually intercept. Add an optional "egress DNS" UDP listener (127.0.0.1:8654) that forwards queries to agent-configured DNS recursors via c-ares when recursors are present. Extend the xDS
ConfigFetcherinterface (and agent implementation) to expose DNS recursors. [GH-23698]
IMPROVEMENTS:
- api-gateway: add
invertfield toHTTPHeaderMatchinhttp-routeconfig entries, enabling negated header match conditions (e.g. "route when header is absent" or "route when header value does NOT match"). Brings API Gateway to parity with the Ingress Gateway's existingInvertsupport inservice-router. [GH-23817] - ci: (Enterprise only) Increased the stale PR automation windows to 90 days before marking a pull request stale and 60 days before closing it. [GH-13119]
- peering: (Enterprise only) Add support for routing traffic to named ports on peered multiport services. [GH-13142]
- telemetry: (Enterprise only) Added three product usage metrics for auto-encrypt visibility.
consul.usage.client_agent_metric_includedreports whether client-agent metrics collection is enabled.consul.usage.client_auto_encrypt_enabled.countandconsul.usage.server_auto_encrypt_enabled.countreports the number of clients and servers, respectively, withauto_encrypt.tlsenabled.consul.usage.auto_encrypt_enabledcombines both counts into a single boolean — true if auto-encrypt is enabled anywhere in the cluster be it client or server. - telemetry: (Enterprise only) Added three server-side product usage metrics,
consul.usage.api_gateway.enabledreports whether any API gateway instances are currently registered in the cluster,consul.usage.mesh.service.percentagereports the percentage of service instances that are connect-proxy sidecars andconsul.usage.transparent_proxy.enabled.percentagereports the percentage of connect-proxy instances that have transparent proxy mode enabled. - ui: Migrate the Consul UI to the HashiCorp Design System (HDS). This covers the global navigation shell and breadcrumbs, the list pages (key/value, peers, auth methods, services, service instances, nodes, intentions, linked services, upstreams, and access control), and the access control, namespace, and admin partition forms. Includes numerous accessibility (A11y) fixes. [GH-23911]
- xds: (Enterprise only) External inference-model upstreams are rendered with a destination-specific mTLS transport socket (per-model SDS validation context and SNI/SAN matching), so the gateway-to-model hop for terminating-gateway-fronted models is mutually authenticated and encrypted per model.
- xds: (Enterprise only) The
builtin/ext-procEnvoy extension now supports Unix domain socket processor targets viaTarget.Path.
BUG FIXES:
- agent/xds: Fixed an issue where cross-cluster and peered requests originating from an API Gateway were rejected with HTTP 403 Forbidden by downstream service RBAC intentions. Trailing semicolon-separated fields in the client certificate component of the
x-forwarded-client-cert(XFCC) header (such as auto-registered DNS SANs) are now properly accepted by the RBAC principal regular expression. [GH-23920] - cli: (Enterprise only)
consul intention createnow creates and replaces intentions via the exact (config-entry) intention API used by the UI, which supports non-default admin partitions (for example-partition team-a). Per-source metadata (-meta) continues to use the deprecated legacy intention API and is only supported in the default partition; combining-metawith a non-default partition now fails with a clear, actionable error. To attach metadata to intentions in an admin partition, use aservice-intentionsconfig entry with entry-levelMetaviaconsul config write. - connect: (Enterprise only) Attach outbound OBO only for identity-plane upstreams (
ai-agent/mcp-server). Explicit HTTP upstreams to inference-gateway or inference-model destinations no longer get consul-obo-outbound and fail closed with "OBO audience not configured". - connect: Fixed a bug where Consul servers ignored the configured
default_intention_policyfor three server-side surfaces — the intention check API (consul intention check,GET /v1/connect/intentions/check), the service topology view (Internal.ServiceTopology), and transparent proxy upstream discovery (Internal.IntentionUpstreams) — and fell back toacl.default_policyinstead. This only changes behavior whendefault_intention_policyandacl.default_policyare set to opposite values; when they agree (ordefault_intention_policyis unset) there is no change. Withdefault_intention_policy=denyandacl.default_policy=allow, the check API and topology previously reported connections as allowed even though they were denied; withdefault_intention_policy=allowandacl.default_policy=deny, transparent proxy sidecars under-provisioned their upstreams and could fail to reach services they were authorized to reach. Envoy RBAC enforcement was not affected and already honoreddefault_intention_policy.