github openziti/zrok v2.0.7

2 hours ago

CHANGELOG

FIX: zrok2 admin gc now decides which share an OpenZiti object belongs to by its zrokShareToken tag rather than its name, so it no longer deletes the bind, dial and service edge router policies of live shares; objects with no share token, such as agent-remote services and policies, are never touched. It now reads every object rather than the first page of ten of each kind. It is a dry run by default that prints what it would remove, grouped by share token, and deletes only with --delete. Orphaned objects younger than --min-age (default 24 hours) are skipped, so a share being created at the time of the run is not collected. Tearing down a share with more than ten OpenZiti objects of one kind, such as a share with many access dial policies, now removes all of them rather than the first ten.

FIX: Accounts holding public shares are now released when their bandwidth usage falls back under the limit. Previously the relax cycle failed for every public share created by v2, because it looked for the v1 frontend selection those shares never have, so the account stayed limited indefinitely after its usage had recovered and its journal entry had to be cleared by hand. The relax now restores a public share's dial policy from the share's names and the frontends serving their namespaces, the same way the share was created; a share created by v1 is still restored from its frontend selection, and a share that has neither had no dial policy to restore and no longer holds the account back.

FIX: When a limited account is released, the private accesses to its public shares (zrok2 access private against a public share) now get their access back too. Previously only accesses to private shares were restored, and the others stayed unable to connect until they were recreated.

FIX: The limits agent's InfluxDB queries now have a deadline, limits.query_timeout (default 30 seconds), and are cancelled when the controller shuts down. Previously an InfluxDB that accepted a query and never answered held the relax cycle, and so every limit enforcement behind it, open indefinitely and kept the controller from stopping. A query that fails or times out part-way through its result is now reported as a failure rather than as zero usage, so it can no longer release a limited account.

FEATURE: zrok2 admin repair-dial-policies <configPath> finds live shares that are missing the dial policies their frontends and private accesses need, such as shares left without them by a limit that was cleared by hand or by a relax that stopped part-way, and with --apply recreates them. It is a dry run by default that lists each missing policy by account, share and policy name. Accounts the bandwidth limit journal holds limited, and shares of a backend mode a scoped limit class holds limited, are skipped and listed, so the command never lifts a limit. It never deletes anything, continues past individual OpenZiti failures and past v1 shares whose selected frontend no longer exists (each listed as failed with the frontend it selects), reports how many policies it checked, found missing, created and failed to create, and exits with an error if any failed. Running it again reports nothing missing.

FIX: share, unshare, access, unaccess, enable and disable now answer 503 Service Unavailable with a Retry-After header (five seconds) when the OpenZiti controller is rate limiting the zrok controller, instead of 500. A client can now tell a busy controller from a broken one and try again later. The failed request is undone as before: a share or access that fails removes what it created, and a share or environment delete that fails leaves everything in place for the retry. The controller log names the OpenZiti limiter that answered, along with the method and path of the refused request.

FIX: A private access (zrok2 access private) that fails after its dial policy has been created in OpenZiti now deletes that dial policy. Previously a failure to record the access left the policy behind with no access owning it. Likewise, enabling an environment (zrok2 enable) that fails after its OpenZiti identity has been created now deletes the identity and its edge router policy, where previously they were left behind with no environment owning them.

CHANGE: The admin profile endpoint's /debug/vars now includes zrok.ziti.rate_limited, the number of OpenZiti management requests the controller has had refused by an OpenZiti rate limiter (HTTP 429) since it started, counting both the command and authentication limiters.

Don't miss a new zrok release

NewReleases is sending notifications on new releases.