Skip to content

docs: add v1.2 release notes - #2786

Merged
missBerg merged 6 commits into
theagentrouter:mainfrom
missBerg:docs/v1.2-release-notes
Oct 6, 2026
Merged

missBerg merged 6 commits into
theagentrouter:mainfrom
missBerg:docs/v1.2-release-notes

Conversation

@missBerg

@missBerg missBerg commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Description

Adds the v1.2 release notes, the first release under the Agent Router name: site data and page, the plain-markdown copy for the GitHub release body, and the release-notes index and navigation.

Also fixes release-notes pages in dark mode (hard-coded white backgrounds), renders the v1.1 breaking change and bug fixes that were in its data but not on its page, and updates the release-notes command for the Agent Router name and the latest Envoy Gateway release.

Related Issues/PRs (if applicable)

Special notes for reviewers (if applicable)

🤖 Generated with Claude Code [1]

1: https://claude.com/claude-code

Add the v1.2 release notes, the first release under the Agent Router
name: site data and page, the plain-markdown copy for the GitHub release
body, and the release-notes index and navigation.

Also fix release-notes pages in dark mode (hard-coded white
backgrounds), render the v1.1 breaking change and bug fixes that were in
its data but not on its page, and update the release-notes command for
the Agent Router name and the latest Envoy Gateway release.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Erica Hughberg <erica.sundberg.90@gmail.com>
@netlify

netlify Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for theagentrouter ready!

Name Link
🔨 Latest commit f848d38
🔍 Latest deploy log https://app.netlify.com/projects/theagentrouter/deploys/6ac4e114f6701d00083e1db5
😎 Deploy Preview https://deploy-preview-2786--theagentrouter.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@nacx

nacx commented Oct 5, 2026

Copy link
Copy Markdown
Member

Related: #2787

@nacx nacx mentioned this pull request Oct 5, 2026
Comment thread release-notes/v1.2.0.md Outdated
- **JWT data in MCP CEL requires `securityPolicy.oauth`** — The gateway reads `request.auth.jwt` claims and scopes, and the session subject, only from a JWT that Envoy has verified. Without `securityPolicy.oauth`, claims are empty, and new CRD validation rejects authorization or `backendSelector` CEL that references `auth.jwt`. Existing routes that break this rule keep their stored spec, but every update is rejected. At runtime their claim lookups fail, and therefore deny, and their scope checks evaluate to false. Add `oauth` or remove the JWT references. MCP sessions are now bound to the verified subject; reusing a session ID as a different user returns 401.
- **MCP CEL evaluation errors now deny** — An authorization or `backendSelector` CEL expression that fails at runtime, for example by reading a header that isn't present, used to be skipped. It now denies: `tools/call` returns 403, the tool is hidden from `tools/list`, and the backend is left out of the session. Write expressions defensively, for example `"x-team" in request.headers && request.headers["x-team"] == "blocked"`.
- **MCP OAuth discovery honors `spec.headers`** — On an MCPRoute with both `headers` matches and `oauth`, the OAuth well-known endpoints now apply the same header matches. Clients that run OAuth discovery without those headers get 404.
- **Cross-namespace Secrets in `BackendSecurityPolicy` need a ReferenceGrant** — `azureCredentials.clientSecretRef`, `gcpCredentials.credentialsFile.secretRef`, and the OIDC `clientSecret` under AWS, Azure, and GCP `oidcExchangeToken` were read from other namespaces without any check. A missing grant now sets the policy to NotAccepted. Already-issued tokens keep working until they expire, so the failure may appear late. Create a ReferenceGrant in the Secret's namespace (see Upgrade Guidance).

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could we include #2783. This will make ReferenceGrant complete for all backendSecurityPolicy

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

+1. I've already reviewed and I hope we can get the changes soon.
I'm also working on a small referencegrant related issue that I'd also like to push

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@nacx the review changes are pushed to #2783.

For this bullet, #2783 adds the secretRef of apiKey, azureAPIKey, anthropicAPIKey and awsCredentials.credentialsFile to the list. These used to ignore namespace and always read the policy's own namespace, so a policy that names another namespace but keeps its Secret next to the policy needs namespace removed.

nacx added a commit that referenced this pull request Oct 5, 2026
**Description**

Bump EG dependency to `v1.9.2`

**Related Issues/PRs (if applicable)**

Release notes PR:
#2786

**Special notes for reviewers (if applicable)**

N/A

---------

Signed-off-by: Ignasi Barrera <ignasi@tetrate.io>
@codecov

codecov Bot commented Oct 6, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

Signed-off-by: Ignasi Barrera <ignasi@tetrate.io>
@nacx
nacx marked this pull request as ready for review October 6, 2026 08:19
@nacx
nacx requested a review from a team as a code owner October 6, 2026 08:19
Signed-off-by: Ignasi Barrera <ignasi@tetrate.io>
@nacx
nacx force-pushed the docs/v1.2-release-notes branch from 9e1e092 to 3fc7af4 Compare October 6, 2026 08:27
Signed-off-by: Ignasi Barrera <ignasi@tetrate.io>
@nacx

nacx commented Oct 6, 2026

Copy link
Copy Markdown
Member

/retest

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Erica Hughberg <erica.sundberg.90@gmail.com>
@missBerg
missBerg enabled auto-merge (squash) October 6, 2026 11:55
@missBerg

missBerg commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

/retest

@missBerg
missBerg merged commit 757aa08 into theagentrouter:main Oct 6, 2026
40 of 42 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants