- Name: Domain-Scoped mTLS for GoRouter
- Start Date: 2026-02-16
- Author(s): @rkoster, @beyhan, @maxmoehl
- Status: Draft
- RFC Pull Request: community#1438
Cloud Foundry's RFC for Domain-Scoped mTLS on GoRouter proposes scope-based authorization that uses GoRouter's existing route-emitter tags (organization_id, space_id) to enforce "same org/space" boundary checks at the domain level. This experiment verifies that the tags carry the correct information when routes are shared across spaces.
When a route is shared from Space A to Space B (and both spaces have apps mapped to it), do the GoRouter route table tags reflect:
- (a) The route owner's org/space (Space A for all endpoints), or
The operations/use-compiled-releases.yml file in cf-deployment references stemcell version 1.423 for all compiled releases, even though newer stemcells are available. This is due to how the CI pipeline is configured to only recompile all releases on major stemcell version bumps.
Both PRs address NVMe device discovery challenges but for different cloud providers with fundamentally different approaches.
| Aspect | PR #396 (AWS) | PR #402 (Azure) |
|---|---|---|
| URL | cloudfoundry/bosh-agent#396 | cloudfoundry/bosh-agent#402 |
| Cloud Provider | AWS | Azure |
- Name: Domain-Scoped mTLS for GoRouter
- Start Date: 2026-02-16
- Author(s): @rkoster, @beyhan, @maxmoehl
- Status: Draft
- RFC Pull Request: community#1438
| use nix |
| https://packages.ubuntu.com/xenial/linux-aws-source-4.4.0 ixgbevf 2.12.1-k | |
| ❯ diff ubuntu/linux-4.4/drivers/net/ethernet/intel/ixgbevf upstream/ixgbevf-2.12.1/src | wc -l | |
| 3424 | |
| ❯ diff ubuntu/linux-4.4/drivers/net/ethernet/intel/ixgbevf upstream/ixgbevf-4.1.2/src | wc -l | |
| 3897 | |
| ❯ diff ubuntu/linux-4.4/drivers/net/ethernet/intel/ixgbevf upstream/ixgbevf-4.6.3/src | wc -l | |
| 5348 | |
| ❯ diff ubuntu/linux-4.4/drivers/net/ethernet/intel/ixgbevf upstream/ixgbevf-4.8.1/src | wc -l | |
| 5475 |
| Verifying my Blockstack ID is secured with the address 1NVzvRRTvvoQ6UgngVVarthwGkpqLNy3uM https://explorer.blockstack.org/address/1NVzvRRTvvoQ6UgngVVarthwGkpqLNy3uM |
| Verifying my Blockstack ID is secured with the address 1NVzvRRTvvoQ6UgngVVarthwGkpqLNy3uM https://explorer.blockstack.org/address/1NVzvRRTvvoQ6UgngVVarthwGkpqLNy3uM |
| { | |
| "receiver": "default-receiver", | |
| "status": "resolved", | |
| "alerts": [ | |
| { | |
| "status": "resolved", | |
| "labels": { | |
| "alertname": "BOSHJobProcessUnhealthy", | |
| "bosh_deployment": "cf", | |
| "bosh_job_index": "0", |