Skip to content

Release notes — 1.1.0

Released 2026-07-22 with DNS Conduit 1.1.0.

Client ACLs and CIDR data sources

  • Optional top-level acls: and per-listener acls: (omit = inherit / admit-all) for host-managed client IP allow/deny/tag using named CIDR views — see Client ACLs.
  • data_sources type: cidr (IPv4 + IPv6 longest-prefix) with Rhai lookup_ip and rules selector client_cidr.
  • Built-in conduit_acl_decisions_total (Prometheus + OTLP) and optional logging.query_access ACL denial levels / sampling.
  • conduitctl acl check (live via CheckAcl, or offline --file) dry-runs effective ACL policy for an IP as pretty JSON — no metrics or denial-log side effects.
  • Documentation: data_sources: config, CSV / CIDR file formats, and load-safety limits now have a dedicated Data sources page shared by ACLs and Rhai; the Rhai Lookups page now focuses on the lookup() / lookup_ip() calling surface.

All changes in this release (automated pull request list).