2.4.3 (Oct 12th, 2024)
This version primarily enhances to support for gRPC request timeout parameters in the Nacos client, and dynamically displays the configuration history retention period.
It also fixes several issues related to client modularization, login, and log configuration, and upgrades multiple dependencies to solve dependent security concerns.
Please see the details of the changes below:
[#12103] Enhance nacos client to support grpc request timeout param. [#12614] Display the number of days to retain the configuration history dynamically on the console. [#12716] Refactor grpc server request handler.
[#12551] Fix client modularity problem. [#12625] Fix namespace query SQL problem for no MySQL datasource. [#12670] Fix can't login when domain like 'register.nacos.com' in console. [#12668] Fix Control Plugin log configuration problem. [#12682] Fix nacos client log4j async append configuration problem.
[#12708] Bump commons-io:commons-io from 2.7 to 2.14.0 [#12673] Bump com.google.protobuf:protobuf-java from 3.22.3 to 3.25.5.
- @xiebin123456 made their first contribution in https://github.com/alibaba/nacos/pull/12693
- @juhuan made their first contribution in https://github.com/alibaba/nacos/pull/12671
- @luxiao0000 made their first contribution in https://github.com/alibaba/nacos/pull/12696
Full Changelog: https://github.com/alibaba/nacos/compare/2.4.2.1...2.4.3
2.4.2 (Sep 5th, 2024)
This version primarily fixes a potential deadlock issue during the startup process related to the Raft protocol initialization in version 2.4.1 (#12526). It also rolls back the changes made in version 2.4.1 that lowered the hessian version, which caused startup problems on JDK 17+ versions due to conflicts with hessian dependencies. Additionally, the logic for checking ServerStatus has been optimized to prevent issues from affecting the availability of non-Raft-dependent functionalities due to Raft election failures.
Furthermore, this version includes several usability enhancements and addresses some other bugs.
Please see the details of the changes below:
[#12483] Configuration list adds configuration format. [#12547] Nacos client supports desensitise in logging. [#12555] SwitchManager support http、tcp、mysql HealthParams and pushCSharpVersion update. [#12569] Enhance is exist table logic to support more database. [#12573] Enhance Server status check to avoid affect core features. [#12583] Enhance protocolManager lock logic. [#12608] Enhance configs diff, support to collapse identical rows.
[#12093] Fix reset password success but no message. [#12498][#12503] Revert "Resolve the Hessian package conflict issue. (#12449)". [#12509] Fix nacos-client updating accessToken bug. [#12526] Fix possible dead lock problem during start up. [#12563] Fix paramchecker invalid bug. [#12581] Fix namespace quota and parameter optimize. [#12604] Fix get config labels from env parameters. [#12610] Fix wrong error code for http open api request.
[#12568] Upgrade mysql-connector-j from 8.0.33 to 8.2.0. [#12387] Upgrade logback adapter to 1.1.3 [#12586][#12596] Upgrade spring version to 5.3.39. [#12596] Upgrade tomcat to 9.0.93.
- @XiaZhouxx made their first contribution in https://github.com/alibaba/nacos/pull/12574
- @shengbinxu made their first contribution in https://github.com/alibaba/nacos/pull/12608
Full Changelog: https://github.com/alibaba/nacos/compare/2.4.1...2.4.2
2.4.1 (Aug 15th, 2024)
该版本主要针对部分Jraft请求处理时,会造成任意文件读写的问题进行修复。
该漏洞仅影响7848端口(默认设置下),一般使用时该端口为Nacos集群间Raft协议的通信端口,不承载客户端请求,因此老版本可以通过禁止该端口来自Nacos集群外的请求达到止血目的(如部署时已进行限制或未暴露,则风险可控)。
另外该版本也在2.4.0的基础上针对derby ops接口做了进一步优化,默认限制derby数据库可执行的SQL范围,降低用户在打开derby ops接口后的风险。
变更详情请查看下文:
The version mainly fixes the issue of arbitrary file read and write that can occur during the processing of some Jraft requests.
The vulnerability only affects port 7848 (by default), which is typically used as the communication port for Nacos cluster inter-raft protocol and does not handle client requests. Therefore, the risk can be controlled by disabling requests from outside of Nacos clusters (e.g. by limiting or not exposing the port) in older versions.
Additionally, this version has further optimized the Derby Ops API by restricting the range of executable SQL commands on the Derby database by default, thereby reducing the risk to users when accessing the Derby Ops API.
Please see the details of the changes below:
[#11887] Add some tips when token.secret.key
is not base64. [#12311] Enhance console to support namespace list with selectors. [#12405] LDAP plugin support custom admin user password for default. [#12446] Enhance hint when got Mac Instance with error in default auth plugin. [#12466] Enhance to configurable service metadata and instance metadata length. [#12477] Enhance default auth plugin to support auth_basic
when logout. [#12489] Remove KvStorage and ConsistencyService. [#12490] Enhance derby mode to support limit SQL Type.
[#12301] Fix headlth check for persistent instance for different namespace but groupName and serviceName are same. [#12374] Fix memory calculate error for metrics api. [#12397] Fix the bug of parsing empty connection control rule problem. [#12410] Fix no hint when beta config content is not equal with formal content.
[#12342] Resolve the Hessian package conflict.
- @eltociear made their first contribution in https://github.com/alibaba/nacos/pull/12392
- @Sitosoym made their first contribution in https://github.com/alibaba/nacos/pull/12324
- @cold-l made their first contribution in https://github.com/alibaba/nacos/pull/12434
- @KouShenhai made their first contribution in https://github.com/alibaba/nacos/pull/12386
- @chen10038 made their first contribution in https://github.com/alibaba/nacos/pull/12310
- @LHyphen made their first contribution in https://github.com/alibaba/nacos/pull/12442
- @kangzhaok made their first contribution in https://github.com/alibaba/nacos/pull/12401
- @fuhouyu made their first contribution in https://github.com/alibaba/nacos/pull/12447
- @gongycn made their first contribution in https://github.com/alibaba/nacos/pull/12449
Full Changelog: https://github.com/alibaba/nacos/compare/2.4.0.1...2.4.1
1.4.8 (Aug 15th, 2024)
- update spring-boot-dependencies version to 2.7.18 by @raymondzhangl in https://github.com/alibaba/nacos/pull/12021
- fix typo by @EruDev in https://github.com/alibaba/nacos/pull/12215
- V1.x develop limit storage by @KomachiSion in https://github.com/alibaba/nacos/pull/12492
- Upgrade to 1.4.8. by @KomachiSion in https://github.com/alibaba/nacos/pull/12494
- @raymondzhangl made their first contribution in https://github.com/alibaba/nacos/pull/12021
- @EruDev made their first contribution in https://github.com/alibaba/nacos/pull/12215
Full Changelog: https://github.com/alibaba/nacos/compare/1.4.7...1.4.8
2.4.0.1 (July 22th, 2024)
This version is fast fix for two block issues #12387 and #12395 for 2.4.0, which might cause password can't be changed and can't create new users when not using MySQL database with new table structures.
- Revert "Add an id primary key column to both the roles and permission… by @KomachiSion in https://github.com/alibaba/nacos/pull/12396
- Fix #12395, use request context replace session depend. by @KomachiSion in https://github.com/alibaba/nacos/pull/12398
Full Changelog: https://github.com/alibaba/nacos/compare/2.4.0...2.4.0.1
2.4.0 (July 19th, 2024)
This version is an important version which support many new features.
The most mainly feature is Nacos support maintainer to initialize the admin user nacos
password instead of using default password to improve the default security for deploy nacos clusters.
One more thing is default disabled derby ops API to prevent false alarms regarding corresponding risks for users without authentication enabled when deploying in standalone mode. If maintainers want use this API to maintain and query data in derby, maintainers can use nacos.config.derby.ops.enabled=true
to open this API.
And other mainly features are support TLS Grpc communication between Nacos cluster nodes as an optional feature to improve Nacos security, which means nacos not only support TLS communication between client and server; What's more, Nacos start to support user extend Selector
before callback Subscriber
for naming module, not only can select instance of services by healthy and clusters. And Nacos client support callback service diffs by new event to reduce Subscriber
cache and compare logics.
Third mainly features are support some configs usages in Nacos console and support more enhancement usage for plugins, such as support add all metadata to prometheus sd protocol and support aliyun ram v4 signature.
In addition to substantial feature updates, this version also fixes some bugs from previous versions and upgrades certain dependencies with security vulnerabilities.
Detail see:
[#10374] Support naming custom selectors and support service diff events. [#11456] Support TLS Grpc communication between Nacos cluster nodes. [#11847] Nacos console support publish config with cas. [#11943] Record users for import configs. [#11957] Remove default password for user nacos
. [#12130] Add metadata as labels in prometheus http sd. [#12162] Support aliyun ram v4 signature method.
[#11956] Refactor nacos client logging module, use SPI load current logger adapter. [#12013] Enhance to fast config Nacos memory setting in startup.sh by environment CUSTOM_NACOS_MEMORY. [#12072] Support does not impose any limit when totalCountLimit is less than 0. [#12166] Enhance nacos client init properties logger. [#12177] Update console header link to new nacos.io. [#12178] Add total record count display in pagination. [#12185] Use nacos properties in CacheDirUtil. [#12221] Remove the accessToken from the URL. [#12235] Enhance logging format in the ResponseExceptionHandler. [#12246] Internationalize the display of total counts in the configuration list and service list. [#12321] Enhance log for unexpected exception from NetworkInterface.ifUp. [#12355] Record the cost of ConfigDump in Prometheus. [#12372] Disable derby ops api default. [#12382] Support ram info switch.
[#10639] Fix the encrypted_data_key
is text type so that old version can't upgrade directly. [#11902] Fix leak of request and response for java native runtime for nacos-client. [#11926] Fix Nacos can't triggle self protection when disk full in some OS. [#11951] Fix the problem that the serviceName and groupName are not resolved correctly when deleting an empty service instance. [#11967] Fix Config can't publish and listen when dataId contains some special words in Window OS. [#11968] Fix Multiple config change plugin implementation configuration conflicts problem. [#12022] Fix nacos datasource plugin ClassCastException problem. [#12046] Fix cipher-aes config encrypt plugin not effect when publish config again. [#12060] Fix too large ttl when auth disabled. [#12146] Fix the operation type does not display when rolling back a configuration with a delete operation type. [#12168] Fix the labels of the query conditions on the Permission Control - Role Management page are still displayed in Chinese after switching the system language to English. [#12180] Fix the operator is not recorded during clone and import operations. [#12196] Fix prometheus http sd invalid label names. [#12207] Fix disk failover datasource not keep status. [#12197] Add an id primary key column to both the roles and permissions tables. [#12219] Fix ServerListManager in nacos-client fails to parse the endpoint in the config. [#12253] Add endpoint cluster name for config & naming server list manager. [#12265] Fix nacos client dependencies tree without grpc package. [#12323] Fix nacos client logback configuration will override packagingData problem. [#12333] Fix auth Plugin resource parser can't parser v2 config openAPI namespaceId.
[#11904] Bump Spring Security to 5.7.12. [#11975] Remove unused dependency javatuple. [#11980] Bump spring framework to 5.3.34. [#12135] Upgrade module naocs-console from junit4 to junit5. [#12369] Upgrade grpc to 1.64.2.
- @HMYDK made their first contribution in https://github.com/alibaba/nacos/pull/12203
- @taomaree made their first contribution in https://github.com/alibaba/nacos/pull/12239
- @dingjs made their first contribution in https://github.com/alibaba/nacos/pull/12360
Full Changelog: https://github.com/alibaba/nacos/compare/2.4.0-BETA...2.4.0
2.3.3 (Jun 25th, 2024) (client only)
This version mainly fix one client block bug and support java agent parsing ram info switches.
The client block bug was introduced in client version 2.3.0, as detailed in ISSUE #10792. The intended change was to unify the address server addressing logic for both the registry and the configuration center and to support custom modification of the address server's path.
However, in a Spring Cloud environment, the clusterName
parameter for discovery has a specific business significance: it denotes the clusterName attribute of the registered service instance. When users configure the clusterName attribute for service instances, it simultaneously alters the path used for addressing the address server.
This bug was primarily caused by the previous ambiguity in the Nacos Client's parameter naming definitions.
To resolve this issue, starting from version 2.3.3, parameters used for controlling the address server will be prefixed with "Endpoint". Specifically:
The clusterName
parameter for endpoint will be renamed to endpointClusterName
.
The clusterName
attribute used by the registry for service instances will remain unchanged.
Previous Configuration:
spring.cloud.nacos.discovery.clusterName=my-service-cluster
spring.cloud.nacos.config.clusterName=my-service-cluster
Updated Configuration:
spring.cloud.nacos.discovery.endpointClusterName=my-endpoint-cluster
spring.cloud.nacos.discovery.clusterName=my-service-cluster
spring.cloud.nacos.config.endpointClusterName=my-endpoint-cluster
2.4.0-BETA (Jun 6th, 2024)
This version is an important version which support many new features.
The most mainly feature is Nacos support maintainer to initialize the admin user nacos
password instead of using default password to improve the default security for deploy nacos clusters.
And other mainly features are support TLS Grpc communication between Nacos cluster nodes as an optional feature to improve Nacos security, which means nacos not only support TLS communication between client and server; What's more, Nacos start to support user extend Selector
before callback Subscriber
for naming module, not only can select instance of services by healthy and clusters. And Nacos client support callback service diffs by new event to reduce Subscriber
cache and compare logics.
Third mainly features are support some configs usages in Nacos console and support more enhancement usage for plugins, such as support add all metadata to prometheus sd protocol and support aliyun ram v4 signature.
In addition to substantial feature updates, this version also fixes some bugs from previous versions and upgrades certain dependencies with security vulnerabilities.
Detail see:
[#10374] Support naming custom selectors and support service diff events. [#11456] Support TLS Grpc communication between Nacos cluster nodes. [#11847] Nacos console support publish config with cas. [#11943] Record users for import configs. [#11957] Remove default password for user nacos
. [#12130] Add metadata as labels in prometheus http sd. [#12162] Support aliyun ram v4 signature method.
[#11956] Refactor nacos client logging module, use SPI load current logger adapter. [#12013] Enhance to fast config Nacos memory setting in startup.sh by environment CUSTOM_NACOS_MEMORY. [#12072] Support does not impose any limit when totalCountLimit is less than 0. [#12166] Enhance nacos client init properties logger. [#12177] Update console header link to new nacos.io.
[#10639] Fix the encrypted_data_key
is text type so that old version can't upgrade directly. [#11902] Fix leak of request and response for java native runtime for nacos-client. [#11926] Fix Nacos can't triggle self protection when disk full in some OS. [#11951] Fix the problem that the serviceName and groupName are not resolved correctly when deleting an empty service instance. [#11967] Fix Config can't publish and listen when dataId contains some special words in Window OS. [#11968] Fix Multiple config change plugin implementation configuration conflicts problem. [#12022] Fix nacos datasource plugin ClassCastException problem. [#12060] Fix too large ttl when auth disabled. [#12146] Fix the operation type does not display when rolling back a configuration with a delete operation type. [#12168] Fix the labels of the query conditions on the Permission Control - Role Management page are still displayed in Chinese after switching the system language to English.
[#11904] Bump Spring Security to 5.7.12. [#11975] Remove unused dependency javatuple. [#11980] Bump spring framework to 5.3.34. [#12135] Upgrade module naocs-console from junit4 to junit5.
- @ldyedu made their first contribution in https://github.com/alibaba/nacos/pull/10905
- @bajiejump made their first contribution in https://github.com/alibaba/nacos/pull/11945
- @hnyyghk made their first contribution in https://github.com/alibaba/nacos/pull/11942
- @llzcx made their first contribution in https://github.com/alibaba/nacos/pull/11995
- @syshenyao made their first contribution in https://github.com/alibaba/nacos/pull/12045
- @caoyanan666 made their first contribution in https://github.com/alibaba/nacos/pull/12014
- @ZrBac made their first contribution in https://github.com/alibaba/nacos/pull/12086
- @mikolls made their first contribution in https://github.com/alibaba/nacos/pull/12031
- @DemonHugo made their first contribution in https://github.com/alibaba/nacos/pull/12090
- @xpy01xpy made their first contribution in https://github.com/alibaba/nacos/pull/12148
- @CallMeHFK made their first contribution in https://github.com/alibaba/nacos/pull/12127
- @misakacoder made their first contribution in https://github.com/alibaba/nacos/pull/12164
- @Kurok1 made their first contribution in https://github.com/alibaba/nacos/pull/12144
Full Changelog: https://github.com/alibaba/nacos/compare/2.3.2...2.4.0-BETA
2.3.2 (Apr 3rd, 2024)
This version mainly fix #11880 issue, this issue will make nacos-server frequently push config to nacos-client 2.3.1 version even data no changed so that the client and server resource costs.
And at the same time, This version can fix other usage issues found in 2.3.1 and older version.
Detail see:
[#11752] Enhance contentPath configurable for AddressServerUrl. [#11801] Refactor PageHandlerAdapterFactory. [#11844][#11867][#11903] Refactor connection and client labels content. [#11895] Enhance response for register service instance for non-connected connection.
[#11536] Fix failover triggered problem. [#11821] Fix announcement api not limit path expression. [#11835] Fix service removed after server restarted when service contain metadata. [#11842] Fix response wrong status code for some API. [#11843] Fix nacos/v2/ns/client/*
API response data wrong for batch registered service. [#11853] Fix nacos-client start failed for native GraalVM. [#11880] Fix config module frequently push new config data even config no change.
[#11874] Bump mysql-connnector-java to 8.0.33 [#11811] Bump Spring Web to 5.3.33 [#11913] Bump console ui dependencies to solve security problem with audit fix.
- @heihei180 made their first contribution in https://github.com/alibaba/nacos/pull/11794
- @linqiuping made their first contribution in https://github.com/alibaba/nacos/pull/11824
- @JianweiWang made their first contribution in https://github.com/alibaba/nacos/pull/11838
- @lmm1990 made their first contribution in https://github.com/alibaba/nacos/pull/11860
- @cxhello made their first contribution in https://github.com/alibaba/nacos/pull/11833
- @Tangmingyao1998 made their first contribution in https://github.com/alibaba/nacos/pull/11883
Full Changelog: https://github.com/alibaba/nacos/compare/2.3.1...2.3.2