- publishes FirstPartyX509CertValidation/ThirdPartyX509CertValidation usages and
intermediates on router data model public keys, deprecating ClientX509CertValidation
- builds the router first-party cert pool from RDM first-party keys unioned with
ctrl-channel roots; TLS and VerifyClientCert paths share buildClientCertRoots with
fallback to the deprecated usage for old controllers
- trusts the edge enrollment signing CA when verifying the certificate a router
presents on the control channel, so a signing CA outside the controller's own
trust bundle no longer refuses every router; the anchors go into a clone of the
identity's pool, never the pool its live tls.Configs share
- propagates full controller signing cert chains over the mesh via
SigningCertChainHeader and persists them in Controller store CertPem
- sends stored public keys during router sync instead of rebuilding them; publishes
controller certs leaf-only
- stops router controller reconnect loops after shutdown
- gives each in-process controller its own command decoder registry
- adds the ha-3 three-controller harness and first-party cert integration tests
- drains the cli test stdout pipe while commands run; anchors the totp token
issued-at assertion to the test clock
- backports the SPIFFE-capable test PKI from openziti/ziti#3947: --not-before on
ziti pki create, tests/testdata/create-pki.sh/.ps1, and the generated PKI under
tests/testdata/pki including the separate edge signing root and per-controller
signing intermediates; existing config sets stay on the testdata/ca PKI
- skips *.pem, *.cert and *.key files in codespell
- adds a CriticalCommand marker interface for commands that establish base
state, and marks SyncSnapshotCommand (a full snapshot restore) as critical
- makes BoltDbFsm.Apply halt when a critical command fails to apply, rather
than logging the error and persisting the advanced raft index; the failed
apply's in-tx index update is rolled back and left unpersisted, so raft
replays and retries the command on restart instead of the node running
caught-up-on-index but empty-on-data
- attaches the command type to all apply log lines so a failure is
self-contained
(cherry picked from commit 11e049a452)
* Allow routers to request current cluster membership information. Fixes#3503
* Get cluster membership information from raft directly, rather than trying to cache it in the DB. Fixes#3501
* Set a router data model timeline when initializing a new HA setup, rather than letting it stay blank. Fixes#3500
* Reduce router data model full state updates. Fixes#3504
Add more raft config knobs
Refactor peer handles to be consistent with other handlers
Allow inspect to work across controllers
Add config and clusterconfig inspect support