Cuong Manh Le
e0bdd906f9
config: change the default logging level to INFO ( #902 )
...
config: change the default logging level to INFO
DEBUG logging level is very verbose and potentially logs sensitive data.
We should set default log level to INFO.
Updates #895
Fixes #896
2020-06-15 22:55:18 +07:00
Bobby DeSimone
e57f92486a
envoy: bump envoy to 1.14.2 ( #894 )
...
Signed-off-by: Bobby DeSimone <bobbydesimone@gmail.com>
2020-06-15 07:55:44 -07:00
Aidan Steele
48912dbc33
Fix small typo ( #836 )
2020-06-07 07:46:47 -04:00
Cuong Manh Le
4d5edb0d64
Feature/remove request headers ( #822 )
...
* config: add RemoveRequestHeaders
Currently, we have "set_request_headers" config, which reflects envoy
route.Route.RequestHeadersToAdd. This commit add new config
"remove_request_headers", which reflects envoy RequestHeadersToRemove.
This is also a preparation for future PRs to implement disable user
identity in request headers feature.
* integration: add test for remove_request_headers
* docs: add documentation/changelog for remove_request_headers
2020-06-03 07:46:51 -07:00
Bobby DeSimone
afe22fd24b
posts: 0-9-0 release notes ( #820 )
...
Signed-off-by: Bobby DeSimone <bobbydesimone@gmail.com>
2020-06-01 20:29:50 -07:00
Bobby DeSimone
44cf1fba1f
deployment: prepare 0.9.0 ( #798 )
...
Signed-off-by: Bobby DeSimone <bobbydesimone@gmail.com>
2020-05-30 18:07:57 -07:00
Caleb Doxsey
b88a619c0d
docs: add mTLS recipe ( #807 )
...
* docs: add mTLS recipe
* add argo and mtls to sidebar
2020-05-29 16:10:40 -06:00
Travis Groth
6761cc7a14
telemetry: service label updates ( #802 )
2020-05-29 15:16:22 -04:00
Caleb Doxsey
49c323ae73
docs: add argo recipe ( #803 )
2020-05-29 12:05:14 -06:00
Caleb Doxsey
c1e648e0a9
docs: update dockerfiles for v0.9.0 ( #801 )
...
* docs: update dockerfiles for v0.9.0
* docs: use latest tag for docker files
2020-05-29 08:13:01 -06:00
Joel Bastos
d67bb22342
docs: typo on configuration doc ( #800 )
...
Correct memcached name
2020-05-28 16:28:55 -07:00
Travis Groth
49db9867d7
docs: Expose config parameters in sidebar ( #797 )
2020-05-28 16:37:34 -04:00
Caleb Doxsey
df2b09a906
docs: add note about unsupported platforms ( #799 )
2020-05-28 12:57:03 -06:00
Travis Groth
14432daf26
docs: Update examples ( #796 )
2020-05-28 10:29:10 -04:00
Noah Stride
d85e490640
fix: docs regarding claim headers ( #782 )
2020-05-27 09:58:48 -04:00
Caleb Doxsey
f03f57980c
docs: update traefik example and add note about forwarded headers ( #784 )
2020-05-26 18:14:11 -06:00
Caleb Doxsey
e4832cb4ed
authorize: add client mTLS support ( #751 )
...
* authorize: add client mtls support
* authorize: better error messages for envoy
* switch from function to input
* add TrustedCa to envoy config so that users are prompted for the correct client certificate
* update documentation
* fix invalid ClientCAFile
* regenerate cache protobuf
* avoid recursion, add test
* move comment line
* use http.StatusOK
* various fixes
2020-05-21 16:01:07 -06:00
Bobby DeSimone
3f1faf2e9e
authenticate: add jwks and .well-known endpoint ( #745 )
...
Signed-off-by: Bobby DeSimone <bobbydesimone@gmail.com>
2020-05-21 11:46:29 -07:00
Travis Groth
3e17befff7
envoy: Enable zipkin tracing ( #737 )
...
- Update envoy bootstrap config to protobufs
- Reorganize tracing config to avoid cyclic import
- Push down zipkin config to Envoy
- Update tracing options to provide sample rate
2020-05-21 11:50:07 -04:00
Caleb Doxsey
0895515833
envoy: implement various timeouts ( #732 )
...
* envoy: implement global and route timeouts
* envoy: use the grpc client timeout for the authz service timeout
* fix test
2020-05-19 10:01:37 -06:00
Travis Groth
1f1e63a75b
telemetry/tracing: Add Zipkin tracing support ( #723 )
2020-05-18 21:57:13 -04:00
Caleb Doxsey
ef399380b7
merge master
2020-05-18 17:10:10 -04:00
Travis Groth
96a95c5aff
Update jwt_claims_headers docs ( #705 )
2020-05-18 17:10:10 -04:00
Caleb Doxsey
352c2b851b
envoy: add separate proxy log level option ( #689 )
2020-05-18 17:10:10 -04:00
Caleb Doxsey
02615b8b6c
Merge remote-tracking branch 'origin/master' into feature/envoy
2020-05-18 17:10:10 -04:00
Travis Groth
99e788a9b4
envoy: Initial changes
2020-05-18 17:10:10 -04:00
Bjoern Weidlich
1a1a5a11f9
Documentation around Pomerium/Istio/Grafana ( #675 )
...
* Added an example of how to protect Grafana with Pomerium inside of an Istio mesh
* Added relevant documentation links
2020-05-17 22:26:09 -07:00
Bobby DeSimone
1cba3d50eb
docs: fixes to v0.8.0 docs ( #696 )
...
Signed-off-by: Bobby DeSimone <bobbydesimone@gmail.com>
2020-05-13 12:38:01 -07:00
Bobby DeSimone
80166bcc40
deployment: release v0.8.0 ( #686 )
...
Co-authored-by: Travis Groth <travisgroth@users.noreply.github.com>
2020-05-12 19:10:12 -07:00
Travis Groth
b9b66ec20f
deploy: autocert documentation and defaults ( #658 )
...
* Define AUTOCERT_DIR in dockerfiles
* Add autocert example and compose file
* Update reference docs for defaults
2020-05-05 21:13:28 -04:00
Bobby DeSimone
bf9a6f5e97
cryptutil: add automatic certificate management ( #644 )
...
Signed-off-by: Bobby DeSimone <bobbydesimone@gmail.com>
2020-05-05 12:50:19 -07:00
Ogundele Olumide
5f0c13767b
improvement: update gitlab api scope ( #630 )
2020-04-23 13:26:25 -07:00
Bobby DeSimone
f4868dd4dd
docs: fix favicon ( #626 )
...
* docs: fix favicon
Signed-off-by: Bobby DeSimone <bobbydesimone@gmail.com>
2020-04-21 14:40:54 -07:00
Caleb Doxsey
170f7f07d3
docs: add upgrading documentation for potentially breaking configuration changes
2020-04-20 18:24:36 -06:00
Caleb Doxsey
9e66471c07
docs: add additional path filtering configuration documentation
2020-04-20 18:24:36 -06:00
Bobby DeSimone
15972b9956
v0.7.5 ( #625 )
...
Signed-off-by: Bobby DeSimone <bobbydesimone@gmail.com>
2020-04-20 14:10:31 -07:00
branchmispredictor
0de3c431a6
forward-auth: validate using forwarded uri header ( #600 )
...
Signed-off-by: Bobby DeSimone <bobbydesimone@gmail.com>
Co-authored-by: Bobby DeSimone <bobbydesimone@gmail.com>
2020-04-20 10:56:30 -07:00
Bobby DeSimone
7fe4c5bdaf
docs: add release announcement post ( #617 )
...
* docs: add release announcement post
- add mailchimp newsletter form
- fix wording
- fix mobile
- fix changelog links
- fix release drafter to use our format (GH-$ISSUE)
Signed-off-by: Bobby DeSimone <bobbydesimone@gmail.com>
2020-04-18 11:35:14 -07:00
Bobby DeSimone
d7daf274c0
pomerium-cli: add service account docs ( #613 )
...
Signed-off-by: Bobby DeSimone <bobbydesimone@gmail.com>
2020-04-16 13:28:42 -07:00
Ogundele Olumide
53fd215148
fix retrieve group error: ( #614 )
...
- remove hardcoded gitlab provider url
- update the gitlab identity provider documentation
2020-04-16 11:51:03 -07:00
Bobby DeSimone
47f9765a47
docs: update changelog for v0.7.3 ( #610 )
...
Signed-off-by: Bobby DeSimone <bobbydesimone@gmail.com>
2020-04-14 08:49:08 -07:00
Bobby DeSimone
b423b234e9
docs: update upgrading / changelog to v0.7.2 ( #601 )
...
Signed-off-by: Bobby DeSimone <bobbydesimone@gmail.com>
2020-04-13 16:20:29 -07:00
Ogundele Olumide
e0dd6734d3
an attempt to improve the identity provider docs ( #608 )
2020-04-13 11:30:29 -07:00
Ogundele Olumide
ae4204d42b
internal/identity: implement github provider support ( #582 )
...
Co-authored-by: Bobby DeSimone <bobbydesimone@gmail.com>
2020-04-10 10:48:14 -07:00
Travis Groth
789068e27a
Add configurable JWT claim headers ( #596 )
2020-04-09 23:41:55 -04:00
Bobby DeSimone
ad56322c7e
site: fix site on mobile ( #597 )
...
Signed-off-by: Bobby DeSimone <bobbydesimone@gmail.com>
2020-04-09 10:56:39 -07:00
Bobby DeSimone
d780281fc0
v0.7.0
...
See (#576 )
Signed-off-by: Bobby DeSimone <bobbydesimone@gmail.com>
2020-04-04 20:45:48 -07:00
Ogundele Olumide
3c6431e5bc
change gitlab group unique identifier from name to ID ( #571 )
2020-03-28 12:45:24 -07:00
İlker Göktuğ Öztürk
297b0fd6c7
docs: fix typo ( #566 )
2020-03-26 11:55:55 -07:00
Travis Groth
cc504362e4
Add storage metrics ( #554 )
...
* Add cache storage metrics
- autocache client metrics
- autocache server metrics
- boltdb metrics
- redis client metrics
- refactor metrics registry to be general purpose
2020-03-23 22:07:48 -04:00