sdk/v0.19.0-rc1: Backport terminating gateway credential injection structs (#23939)
Checked 6 Oct 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.
Open the official publisher sourcePUBLISHER UPDATE · CONSUL-0.19.0-RC1
sdk/v0.19.0-rc1: Backport terminating gateway credential injection structs (#23939)
Scope: HashiCorp Consul. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.
structs: backport inference gateway types to CE Adds the inference-gateway service kind, config entry kind, and their API, structs, agent-config, and proto surface so consumers such as consul-k8s can build against them. The inference gateway is an enterprise feature: CE rejects the config entry in Validate and the service kind in NodeService.Validate. Mirrors the CAMP structs backport ( #23842 ). The api types and the proto messages match Consul Enterprise so later proto changes backport cleanly. fsm: drop inference-gateway entries on CE downgrade replay decodeConfigEntryOperation resolves every config entry in an enterprise raft log through MakeShadowConfigEntry, and applyConfigEntryOperation panics on any error other than ErrDroppingTenantedReq. inference-gateway had no case there, so a downgraded CE server replaying a log that contains one would crash instead of dropping the entry. Drop it, the same way control-plane-request-limit is dropped: CE defines the type so API consumers compile against it, but a CE server never stores the entry, so there is nothing to decode into. The new test walks AllConfigEntryKinds and fails for any kind that reaches the factory's default arm, so the next enterprise-only kind cannot reintroduce this. proto: regenerate config entry bindings after the import reorder The wrappers import moved ahead of private/pbcommon in config_entry.proto to match the order upstream uses, but the generated bindings were not regenerated, so the embedded descriptor still listed it last and check-generated-protobuf failed. test: expect inference-gateway in the connect-instance usage counts allConnectKind now includes inference-gateway, so /v1/operator/usage reports a zero count for it. Both expectations assert the whole map, so they list the new kind, matching the enterprise change that added it. structs: backport terminating gateway credential injection types to CE Add the shared config entry surface needed by the enterprise CAMP terminating-gateway credential injection feature so CE and ENT stay in sync: structs/api: GatewayCredentialInjection and GatewayServiceCredential, TerminatingGatewayConfigEntry.CredentialInjection, LinkedService.Credential and GatewayService credential fields with validation, clone and equality support structs/api: ExtProcMetadataKV and ExtProcOverrides.GRPCInitialMetadata proto: TerminatingGateway config entry kind and messages, ext_proc initial metadata, and regenerated bindings regenerated structs deep copy Runtime behavior (state store propagation, proxycfg and xDS rendering) remains enterprise-only. fsm: strip terminating gateway credential injection on CE downgrade Now that CE carries the credential injection types, a CE server running in downgrade mode (CONSUL_ENTERPRISE_DOWNGRADE_TO_CE) would decode and store CredentialInjection and LinkedService.Credential from an enterprise raft log or snapshot. Previously msgpack silently dropped them as unknown fields. Strip both fields during raft log replay (ShadowTerminatingGateway ConfigEntry.GetRealConfigEntry) and snapshot restore (restoreConfigEntry), keeping the plain terminating gateway, so a CE server never stores the enterprise-only configuration. structs: sync inference gateway types with the enterprise entry shape Follows the enterprise entry as it stands today: RequestTimeout bounds one request across every failover attempt, so a long or streaming inference response is not cut off by Envoy's 15s route default. PII Scope and DefaultAction/Action become named string types with constants, and cross the wire as proto enums whose zero value is "unset". A PII detector needs a Regex unless Name is one of the built-ins. The metrics scrape path and semconv version are pinned to what the processor implements; Path is retained for wire compatibility only. CE keeps carrying the types, and Validate still rejects the entry as an enterprise feature, so only the type surface and its proto bindings move here. state: backport terminating gateway cr
Not stated. The verified publisher record does not contain a known-issues statement.
Review the official publisher document before deployment.
Checked 6 Oct 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.
Open the official publisher source