Skip to content

Tetratefips release 1.26 secfixes#1056

Merged
psbrar99 merged 7 commits intotetratefips-release-1.26from
tetratefips-release-1.26-secfixes
Mar 10, 2026
Merged

Tetratefips release 1.26 secfixes#1056
psbrar99 merged 7 commits intotetratefips-release-1.26from
tetratefips-release-1.26-secfixes

Conversation

@psbrar99
Copy link
Copy Markdown
Collaborator

Please provide a description of this PR:

To help us figure out who should review this PR, please put an X in all the areas that this PR affects.

  • Configuration Infrastructure
  • Docs
  • Installation
  • Networking
  • Performance and Scalability
  • Policies and Telemetry
  • Security
  • Test and Release
  • User Experience
  • Developer Infrastructure

Please check any characteristics that apply to this pull request.

  • Does not have any user-facing changes. This may include CLI changes, API changes, behavior changes, performance improvements, etc.

istio-testing and others added 7 commits March 10, 2026 14:57
…nts (istio#58958)

* fix authorization for Pilot Debug Endpoints

Signed-off-by: Petr McAllister <petr.mcallister@gmail.com>

* release notes

Signed-off-by: Petr McAllister <petr.mcallister@gmail.com>

* address PR comment

Signed-off-by: Petr McAllister <petr.mcallister@gmail.com>

* add flag for kiali compatibility

Signed-off-by: Petr McAllister <petr.mcallister@gmail.com>

* Update pilot/pkg/xds/debug_test.go

Co-authored-by: Jackie Maertens (Elliott) <64559656+jaellio@users.noreply.github.com>

* address PR review comments

Signed-off-by: Petr McAllister <petr.mcallister@gmail.com>

---------

Signed-off-by: Petr McAllister <petr.mcallister@gmail.com>
Co-authored-by: Petr McAllister <petr.mcallister@gmail.com>
Co-authored-by: Petr McAllister <petr@solo.io>
Co-authored-by: Jackie Maertens (Elliott) <64559656+jaellio@users.noreply.github.com>
(cherry picked from commit 7fc7416)
* Implemented SSRF protection

Signed-off-by: Petr McAllister <petr.mcallister@gmail.com>

* adjust filtering logic, add more tests

Signed-off-by: Petr McAllister <petr.mcallister@gmail.com>

* release notes

Signed-off-by: Petr McAllister <petr.mcallister@gmail.com>

* check multiple challenges

Signed-off-by: Petr McAllister <petr.mcallister@gmail.com>

* lint

Signed-off-by: Petr McAllister <petr.mcallister@gmail.com>

---------

Signed-off-by: Petr McAllister <petr.mcallister@gmail.com>
Co-authored-by: Petr McAllister <petr.mcallister@gmail.com>
(cherry picked from commit bb4caf1)
…red (istio#59174)

Signed-off-by: Bharath B <bhb@redhat.com>
Co-authored-by: Bharath B <bhb@redhat.com>
(cherry picked from commit 583c950)
Signed-off-by: Petr McAllister <petr.mcallister@gmail.com>
Co-authored-by: Petr McAllister <petr.mcallister@gmail.com>
(cherry picked from commit d5a166e)
…9281)

* add namespaces option for debug endpoint auth

* added releasenotes

---------

Co-authored-by: Jack Kawell <jack.kawell@solo.io>
(cherry picked from commit 0319e67)
* pass caller namespace to xds debug handler

Signed-off-by: Petr McAllister <petr.mcallister@gmail.com>

* fix jwks private key leak in fallback path

Signed-off-by: Petr McAllister <petr.mcallister@gmail.com>

* address PR review

Signed-off-by: Petr McAllister <petr.mcallister@gmail.com>

* adapt jwks fix for 1.27 - remove CIDR blocking (1.29-only feature)

---------

Signed-off-by: Petr McAllister <petr.mcallister@gmail.com>
(cherry picked from commit a91ea33)
Signed-off-by: Petr McAllister <petr.mcallister@gmail.com>
(cherry picked from commit 4aee98e)
@psbrar99 psbrar99 merged commit 149bf9f into tetratefips-release-1.26 Mar 10, 2026
@psbrar99 psbrar99 deleted the tetratefips-release-1.26-secfixes branch March 10, 2026 22:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants