Release notes — 1.5.0
Released 2026-08-14 with DNS Conduit 1.5.0.
Control plane
conduitctlclient config file (YAML): default~/.config/conduit/conduitctl.yaml(XDG /%APPDATA%\conduit\on Windows); override with--config/CONDUITCTL_CONFIG. Precedence: flags → env → file → built-ins for endpoint, API key /api_key_file, and TLS paths.- TLS/mTLS from
conduitctl: HTTPS verifies certificate chain and hostname by default;--tls-ca/ client identity for private CA and mTLS; explicit--tls-insecure(or env / file) opt-out for self-signed servers without a distributed CA. Offlinevalidate/acl check --filestill need no client file. - Apply/reload status: responses include
generationand extensiblenotes(shared by document apply and config primitives). - Pool/backend remove: overlay
remove: trueon a named pool or backend (name preferred, else address); unknown targets fail the apply;exportnever emits tombstones. Typedconduitctl backend remove/ConduitPools.RemoveBackend. - Config primitives (capability gRPC +
conduitctl): pools/backends, orchestrator limits, data sources, events filters/emit on existing sinks, Rhai limits, metrics plan patch, hot cache knobs. Document apply/export/reload unchanged. Restart-pending knobs are omitted from typed writes.
Observability
- Control-plane
control rpcaccess logs includetls=true|false, indicating whether the RPC arrived over TLS (transport encryption). This is separate from requestormtls(client certificate identity). - Failed control-plane connections that never become an RPC (TCP accept errors, TLS handshake failures) log at
warnascontrol plane connection failedwithtls,error, andpeerwhen known. - Rejected config control RPCs (
ApplyConfig,ValidateConfig,ReloadFromFile, mutating primitives) logcontrol rpc outcomeatwarn(outcome=rejected); successful outcomes remain atinfo. The transportcontrol rpcline is unchanged.
All changes in this release (automated pull request list).