Andrew Martinez
f116212ed4
fix #3231 use root controller server certs for OIDC signing ( #3236 )
...
* fix #3231 use root controller server certs for OIDC signing
- addresses HA vs non-HA signing
- fixes issue where APIs server w/ difference certs than the root
identity
- adds documentation for env/appenv
- adds a new composite type for TLSCert JWT signers
* address possible nil reference
* remove ineff assignment on jwt signing method
2025-08-26 09:29:50 -04:00
Paul Lorenz
e647d67325
Update to channel/v4
2025-04-02 15:28:59 -04:00
Paul Lorenz
32eddd61ca
HA SDK terminators test. Fixes #2217 . Fixes #2533
2024-11-12 18:45:08 -05:00
Paul Lorenz
74386da333
Update deps and changelog. Test fixes and spiffe id check
2024-11-01 15:21:24 -04:00
Paul Lorenz
16f0a858e6
Add controller connect events. Fixes #1835 . Fixes #2234
2024-11-01 15:21:01 -04:00
Paul Lorenz
0a2f1393d4
Fix identity service config overrides referential integrity issue. Fixes #2506
2024-10-29 11:49:37 -04:00
Andrew Martinez
778807d80f
fix tests
2024-10-04 21:41:09 -04:00
Andrew Martinez
6c85940931
fixes #2468 locates the correct server certificate for enrollments
...
- determines certificate for signing based on all identity server certs
- does not cache as certificates may reload
2024-10-04 15:24:07 -04:00
Paul Lorenz
694b9dc18d
Add events for JWT session for create/refresh/exchange. Fixes #2119
2024-09-30 15:32:48 -04:00
Paul Lorenz
cccf0c06af
Update to channel/v3. Fixes #2390
2024-09-09 12:23:25 -04:00
Paul Lorenz
c3b43133d1
Merge fabric and controller model code. Fixes #2205
2024-07-09 16:11:01 -04:00
Andrew Martinez
6ecca65c85
fixes #2165 adds network id configuration/spiffe id look up
...
- adds support for trust domain lookup on x509 chain
- adds support for non-ha trustDomain configuration
- adds default generated trust domain for non-ha controllers
- non-HA controllers will generate a trust domain from the root CA if
possible
- additionalTrustDomains has been added for transitioning between trust
domains
update changelog.md
2024-07-03 10:23:50 -04:00
Paul Lorenz
3d81cc39a4
Load test for controller with links, terminators, clients and traffic
2024-04-09 16:58:18 -04:00
Andrew Martinez
8c7b3b2e84
reduces prerms from admin to authenticated on list controllers
...
- updated public key sync to use controller list data instead of mesh peer
- fixes perms on controller list to not be admin only
2024-03-26 10:55:50 -04:00
Andrew Martinez
09542c7728
consolidated ha changes
2024-02-29 09:27:56 -05:00
Paul Lorenz
a84369a6e9
Consolidate fabric and edge persistence code. Fixes #1555
2023-12-06 17:36:37 -05:00
Paul Lorenz
f3d67b7f49
Update fabric imports
2023-09-28 23:34:28 -04:00
Paul Lorenz
07da3cd513
Merge remote-tracking branch 'edge/main' into merge-edge
...
Updated package names
Merged golangci-lint configurations
2023-09-27 16:54:53 -04:00
Paul Lorenz
81baa1843b
Add default identity type. Remove user,service,device types. Fixes #1428
2023-08-22 20:40:33 -04:00
Paul Lorenz
b061fe9a39
Move internal/certs to common. Remove some incidental files that weren't used.
2023-08-07 10:20:06 -04:00
Paul Lorenz
03b58ebcd3
Move jwtsigner package to controller
2023-08-04 17:04:44 -04:00
Paul Lorenz
8b3092a3d9
Merge pull request #1566 from openziti/prep-for-ziti-merge-p2
...
Move eid to common
2023-08-04 16:35:26 -04:00
Paul Lorenz
1f5eed5956
Move eid to common
2023-08-04 11:46:53 -04:00
Andrew Martinez
414cff49d7
adds support OIDC authentication, api access, and ER connections
2023-07-20 09:41:12 -04:00
Paul Lorenz
7d6901be3d
Add edge code needed for entity change events. Fixes #629
2023-04-25 22:34:02 -04:00
Paul Lorenz
63f9dad3df
Updated model for storage api changes
2023-04-25 13:26:02 -04:00
Paul Lorenz
d76b9bc272
Cache api sessions for router/tunneler. Fixes #1364
2023-03-23 10:22:46 -04:00
Paul Lorenz
34cc021b3e
Make session creates idempotent. Fixes #1359
2023-03-23 09:50:05 -04:00
Paul Lorenz
90e7b0f0a6
Fill in client cert chains when enrolling
2022-11-11 14:30:55 -05:00
Paul Lorenz
0b8a65207a
Change bootstrap check. Add hooks for isRaftEnabled
2022-08-22 12:14:40 -04:00
Paul Lorenz
2e578ab784
Update identities to use raft commands. Fixes #1131
2022-08-09 14:58:23 -04:00
Paul Lorenz
d3a4c7d0ac
Update edge routers to use raft commands. Fixes #1107
2022-08-04 10:43:21 -04:00
Paul Lorenz
d068397cd0
Rename controller model handler types to manager. Fixes #1124
2022-08-01 14:00:01 -04:00
Paul Lorenz
cb0a634414
Update edge services to use raft commands. Fixes #1118
2022-07-29 15:56:09 -04:00
Paul Lorenz
d0ed5aa00e
Update service edge router policies to use raft commands. Fixes #1110
2022-07-28 18:31:19 -04:00
Paul Lorenz
e198f16c3d
Convert edge router policies to raft commands. Fixes #1108
2022-07-28 18:30:26 -04:00
Paul Lorenz
bae7e40b61
Update for foundation changes
2022-07-01 15:55:30 -04:00
Paul Lorenz
12df770d04
Update copyright
2022-06-30 17:45:08 -04:00
Paul Lorenz
2f6a3bc828
Update handler -> manager for base types and config
2022-06-02 00:05:54 -04:00
Paul Lorenz
7cf9dc135d
Initial support for raft and command style architecture
2022-06-01 23:52:07 -04:00
Andrew Martinez
1f784d89ce
adds asynchronous eventer to controller
...
- emits events for processing progress/state for metric instrumentation
- emits events for eventual event backlog state for metrics
- alters Trigger() to return a channel that can be waited upon
- adds ability to add eventual events within a specific bbolt
transaction
- splits session lookup and delete into view/update transactions
- add eventual event gauge
- use CascadeCreateUpdate
- adds named functions
- documentation for 500us timeout
- grammar fixes
2022-01-18 14:19:36 -05:00
Paul Lorenz
2d4260e76e
Allow using a specific bolt db file for tests
2021-10-26 14:19:24 -04:00
Paul Lorenz
782f43cb26
Fix time check on list tunnel. Add policy enforcer test. Add update session test
2021-09-01 16:20:43 -04:00
Paul Lorenz
7cb0b12d5c
Update for JWT lib changes
2021-07-30 10:04:45 -04:00
Paul Lorenz
f2670e66a0
Make policy semantic required for POST/PUT. Fix evaluation on policy PUT if semantic not provided
2021-07-30 09:44:21 -04:00
Andrew Martinez
47499bc4f1
add mfa options
...
- allow timeouts for MFA posture checks
- allow wake/unlocked MFA options
- allow legacy toggle for SDKs that don't supply endpoint state
- supply timeouts on posture checks
- posture data now caches session state
2021-07-07 08:39:39 -04:00
Andrew Martinez
177379aa8e
fix durations w/ no units
2021-06-03 08:52:24 -04:00
Andrew Martinez
6625084569
use xweb for Edge Client and Management APIs
...
- use xweb for run
- use xweb for api tests
- use time.ParseDuration for edge configuration
- use CORS defaults in Client/Management API handlers
2021-05-06 16:45:48 -04:00
Andrew Martinez
1100d6f388
update service update on posture data change, tests
2021-03-23 09:54:47 -04:00
Andrew Martinez
623681db87
add lastActivityAt
...
- as updates to API Sessions can now happen later than the last time
they were active, updatedAt is no longer the correct representation of
the last activity an API Session had
- move all logic that used updatedAt to lastActivityAt
- add migration to set lastActivityAt
2021-03-17 13:49:12 -04:00