Repository navigation
docs: add v1.2 release notes - #2786
Conversation
Add the v1.2 release notes, the first release under the Agent Router name: site data and page, the plain-markdown copy for the GitHub release body, and the release-notes index and navigation. Also fix release-notes pages in dark mode (hard-coded white backgrounds), render the v1.1 breaking change and bug fixes that were in its data but not on its page, and update the release-notes command for the Agent Router name and the latest Envoy Gateway release. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: Erica Hughberg <erica.sundberg.90@gmail.com>
✅ Deploy Preview for theagentrouter ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
|
Related: #2787 |
| - **JWT data in MCP CEL requires `securityPolicy.oauth`** — The gateway reads `request.auth.jwt` claims and scopes, and the session subject, only from a JWT that Envoy has verified. Without `securityPolicy.oauth`, claims are empty, and new CRD validation rejects authorization or `backendSelector` CEL that references `auth.jwt`. Existing routes that break this rule keep their stored spec, but every update is rejected. At runtime their claim lookups fail, and therefore deny, and their scope checks evaluate to false. Add `oauth` or remove the JWT references. MCP sessions are now bound to the verified subject; reusing a session ID as a different user returns 401. | ||
| - **MCP CEL evaluation errors now deny** — An authorization or `backendSelector` CEL expression that fails at runtime, for example by reading a header that isn't present, used to be skipped. It now denies: `tools/call` returns 403, the tool is hidden from `tools/list`, and the backend is left out of the session. Write expressions defensively, for example `"x-team" in request.headers && request.headers["x-team"] == "blocked"`. | ||
| - **MCP OAuth discovery honors `spec.headers`** — On an MCPRoute with both `headers` matches and `oauth`, the OAuth well-known endpoints now apply the same header matches. Clients that run OAuth discovery without those headers get 404. | ||
| - **Cross-namespace Secrets in `BackendSecurityPolicy` need a ReferenceGrant** — `azureCredentials.clientSecretRef`, `gcpCredentials.credentialsFile.secretRef`, and the OIDC `clientSecret` under AWS, Azure, and GCP `oidcExchangeToken` were read from other namespaces without any check. A missing grant now sets the policy to NotAccepted. Already-issued tokens keep working until they expire, so the failure may appear late. Create a ReferenceGrant in the Secret's namespace (see Upgrade Guidance). |
There was a problem hiding this comment.
Could we include #2783. This will make ReferenceGrant complete for all backendSecurityPolicy
There was a problem hiding this comment.
+1. I've already reviewed and I hope we can get the changes soon.
I'm also working on a small referencegrant related issue that I'd also like to push
There was a problem hiding this comment.
@nacx the review changes are pushed to #2783.
For this bullet, #2783 adds the secretRef of apiKey, azureAPIKey, anthropicAPIKey and awsCredentials.credentialsFile to the list. These used to ignore namespace and always read the policy's own namespace, so a policy that names another namespace but keeps its Secret next to the policy needs namespace removed.
**Description** Bump EG dependency to `v1.9.2` **Related Issues/PRs (if applicable)** Release notes PR: #2786 **Special notes for reviewers (if applicable)** N/A --------- Signed-off-by: Ignasi Barrera <ignasi@tetrate.io>
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
Signed-off-by: Ignasi Barrera <ignasi@tetrate.io>
Signed-off-by: Ignasi Barrera <ignasi@tetrate.io>
9e1e092 to
3fc7af4
Compare
Signed-off-by: Ignasi Barrera <ignasi@tetrate.io>
|
/retest |
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: Erica Hughberg <erica.sundberg.90@gmail.com>
|
/retest |
Description
Adds the v1.2 release notes, the first release under the Agent Router name: site data and page, the plain-markdown copy for the GitHub release body, and the release-notes index and navigation.
Also fixes release-notes pages in dark mode (hard-coded white backgrounds), renders the v1.1 breaking change and bug fixes that were in its data but not on its page, and updates the release-notes command for the Agent Router name and the latest Envoy Gateway release.
Related Issues/PRs (if applicable)
Special notes for reviewers (if applicable)
🤖 Generated with Claude Code [1]
1: https://claude.com/claude-code