Forwarder 2.0.4
Forwarder 2.0.4
Release date: October 7, 2026
This is a hotfix release that improves connectivity in environments with TLS-intercepting proxies. It also enables JAR load event deduplication by default, which reduces network traffic between the Forwarder and Azul Intelligence Cloud.
Bug Fixes
-
TLS-intercepting proxies: If the Forwarder does not trust the certificate chain that a TLS-intercepting proxy presents, it now logs a diagnostic hint. The hint shows the presented issuer and root CA, and suggests two remedies: exempt
*.api.ic.azul.comfrom TLS inspection, or import the proxy’s root CA into the JDK truststore. Previously, the connection failed with aPKIX path building failederror without further guidance. -
Connection stability: If a TLS-intercepting proxy injects extra HTTP/2
SETTINGSframes after the initial handshake, the Forwarder now discards the unexpected frames with a warning and keeps the connection open. Previously, the extra frames caused an error that dropped the shared connection to Intelligence Cloud for all in-flight requests.
Improvements
-
JAR load event deduplication: Deduplication of JAR load events is now enabled by default. Previously, every JVM that loaded a shared JAR generated a full round trip to Intelligence Cloud, even when other JVMs had already reported the same JAR. The Forwarder now identifies JARs by a hash of their central directory and forwards only unique JAR load events. The Forwarder suppresses duplicate JAR load requests and the resulting artifact uploads. Deduplication reuses the caches that
azul.deduplication.pipelineconfigures, so you do not need a separate cache. -
JAR deduplication options: Use
azul.deduplication.jar.enabledto turn JAR load event deduplication on or off, andazul.deduplication.jar.filterMinimalto control the suppression of lightweight JAR probe events. For all options and their environment variables, see All Configuration Options. -
Immediate agent response for suppressed requests: When the Forwarder suppresses a duplicate JAR load request, it immediately sends the agent a response that no details are needed. The agent can then release the resources it holds without waiting for Intelligence Cloud.