ModestTG / heliod-cluster

Test Cluster
MIT License
0 stars 0 forks source link

fix(helm): update chart cilium to 1.14.3 #153

Open renovate[bot] opened 1 year ago

renovate[bot] commented 1 year ago

Mend Renovate

This PR contains the following updates:

Package Update Change
cilium (source) patch 1.14.0 -> 1.14.3

Release Notes

cilium/cilium (cilium) ### [`v1.14.3`](https://togithub.com/cilium/cilium/releases/tag/v1.14.3): 1.14.3 [Compare Source](https://togithub.com/cilium/cilium/compare/1.14.2...1.14.3) We are pleased to release Cilium v1.14.3. This is bug fix release addressing the recent HTTP/2 Stream Cancellation Attack ([CVE-2023-44487](https://nvd.nist.gov/vuln/detail/CVE-2023-44487)) and other bugs: - Envoy [GHSA-jhv4-f7mr-xx76](https://togithub.com/envoyproxy/envoy/security/advisories/GHSA-jhv4-f7mr-xx76) - Go [GHSA-qppj-fm5r-hxr3](https://togithub.com/advisories/GHSA-qppj-fm5r-hxr3) ## Summary of Changes **Minor Changes:** - bump grpc dependency to 1.56.3 to fix security vulnerability https://github.com/advisories/GHSA-qppj-fm5r-hxr3 ([#​28527](https://togithub.com/cilium/cilium/issues/28527), [@​aanm](https://togithub.com/aanm)) - Cut Cilium's initialization time for clusters with a large number of Kubernetes and Cilium Network Policies by 90% (Backport PR [#​28282](https://togithub.com/cilium/cilium/issues/28282), Upstream PR [#​28173](https://togithub.com/cilium/cilium/issues/28173), [@​aanm](https://togithub.com/aanm)) - endpoint: Only perform the full policy map synchronization periodically (every 15 minutes) to reduce overhead with large endpoint policy maps (Backport PR [#​28095](https://togithub.com/cilium/cilium/issues/28095), Upstream PR [#​27693](https://togithub.com/cilium/cilium/issues/27693), [@​joamaki](https://togithub.com/joamaki)) - ipam: report IP owner of non-default pool IPs in multi-pool IPAM (Backport PR [#​28095](https://togithub.com/cilium/cilium/issues/28095), Upstream PR [#​27968](https://togithub.com/cilium/cilium/issues/27968), [@​tklauser](https://togithub.com/tklauser)) - metrics: add a metric for max observed endpoint ifindex (Backport PR [#​28282](https://togithub.com/cilium/cilium/issues/28282), Upstream PR [#​27953](https://togithub.com/cilium/cilium/issues/27953), [@​asauber](https://togithub.com/asauber)) - metrics: Add map pressure metric for auth map (Backport PR [#​28442](https://togithub.com/cilium/cilium/issues/28442), Upstream PR [#​28357](https://togithub.com/cilium/cilium/issues/28357), [@​sayboras](https://togithub.com/sayboras)) - vendor, azure: Bump Azure SDK to Aug 2021 (Backport PR [#​28330](https://togithub.com/cilium/cilium/issues/28330), Upstream PR [#​28311](https://togithub.com/cilium/cilium/issues/28311), [@​christarazi](https://togithub.com/christarazi)) **Bugfixes:** - bpf: lxc: support Pod->Service->Pod hairpinning with endpoint routes (Backport PR [#​28123](https://togithub.com/cilium/cilium/issues/28123), Upstream PR [#​27798](https://togithub.com/cilium/cilium/issues/27798), [@​ti-mo](https://togithub.com/ti-mo)) - bpf: overlay: fix missing DBG_DECAP for Inter-Cluster-SNAT (Backport PR [#​28494](https://togithub.com/cilium/cilium/issues/28494), Upstream PR [#​28466](https://togithub.com/cilium/cilium/issues/28466), [@​julianwiedmann](https://togithub.com/julianwiedmann)) - Change routing-mode and tunnel-protocol based on .Values.tunnel and .Values.routingMode (Backport PR [#​28282](https://togithub.com/cilium/cilium/issues/28282), Upstream PR [#​27841](https://togithub.com/cilium/cilium/issues/27841), [@​macmiranda](https://togithub.com/macmiranda)) - datapath: fix NodePort to remote hostns backend with tunnel config (Backport PR [#​28494](https://togithub.com/cilium/cilium/issues/28494), Upstream PR [#​27323](https://togithub.com/cilium/cilium/issues/27323), [@​michaelasp](https://togithub.com/michaelasp)) - envoy: Sync supported resources to fix not found issue (Backport PR [#​28349](https://togithub.com/cilium/cilium/issues/28349), Upstream PR [#​28272](https://togithub.com/cilium/cilium/issues/28272), [@​sayboras](https://togithub.com/sayboras)) - Fix a bug that causes pod-to-pod traffic between nodes to be dropped when IPsec is enabled and kube-proxy installed rules in both iptables-nft and iptables-legacy. (Backport PR [#​28442](https://togithub.com/cilium/cilium/issues/28442), Upstream PR [#​28258](https://togithub.com/cilium/cilium/issues/28258), [@​pchaigno](https://togithub.com/pchaigno)) - fix bug: pull skb data in cil_from_netdev path for HIGH_SCALE_IPCACHE mode (Backport PR [#​28095](https://togithub.com/cilium/cilium/issues/28095), Upstream PR [#​27913](https://togithub.com/cilium/cilium/issues/27913), [@​sofat1989](https://togithub.com/sofat1989)) - Fix Gateway API HttpRoute cannot strip path prefix. (Backport PR [#​28282](https://togithub.com/cilium/cilium/issues/28282), Upstream PR [#​28018](https://togithub.com/cilium/cilium/issues/28018), [@​chaunceyjiang](https://togithub.com/chaunceyjiang)) - Fix hubble metric labeling when only directed Source/Destination Ingress/Egress options are specified. (Backport PR [#​28095](https://togithub.com/cilium/cilium/issues/28095), Upstream PR [#​27792](https://togithub.com/cilium/cilium/issues/27792), [@​marqc](https://togithub.com/marqc)) - Fix minor bug where the previous Cilium proxy port was not reused (Backport PR [#​28127](https://togithub.com/cilium/cilium/issues/28127), Upstream PR [#​27634](https://togithub.com/cilium/cilium/issues/27634), [@​christarazi](https://togithub.com/christarazi)) - Fix the trace notification for hairpinned reply traffic, to indicate the correct security identity for the client. (Backport PR [#​28282](https://togithub.com/cilium/cilium/issues/28282), Upstream PR [#​28133](https://togithub.com/cilium/cilium/issues/28133), [@​julianwiedmann](https://togithub.com/julianwiedmann)) - Fix wrong host and router IP being used for some IPv6 deployments, which was causing various connectivity problems. (Backport PR [#​28435](https://togithub.com/cilium/cilium/issues/28435), Upstream PR [#​28417](https://togithub.com/cilium/cilium/issues/28417), [@​ti-mo](https://togithub.com/ti-mo)) - Fix: Gateway API double slash while stripping path prefix (Backport PR [#​28442](https://togithub.com/cilium/cilium/issues/28442), Upstream PR [#​28294](https://togithub.com/cilium/cilium/issues/28294), [@​nxy7](https://togithub.com/nxy7)) - Fixes a bug causing panic when counting IPsec keys number via "cilium encrypt status". (Backport PR [#​28282](https://togithub.com/cilium/cilium/issues/28282), Upstream PR [#​27996](https://togithub.com/cilium/cilium/issues/27996), [@​jschwinger233](https://togithub.com/jschwinger233)) - fqdn proxy: fix data race by using separate sessionUDPFactories (Backport PR [#​28282](https://togithub.com/cilium/cilium/issues/28282), Upstream PR [#​28163](https://togithub.com/cilium/cilium/issues/28163), [@​mhofstetter](https://togithub.com/mhofstetter)) - ipam/multipool: Fix bug where allocator was unable to update CiliumNode (Backport PR [#​28095](https://togithub.com/cilium/cilium/issues/28095), Upstream PR [#​27963](https://togithub.com/cilium/cilium/issues/27963), [@​gandro](https://togithub.com/gandro)) - ipcache: fix flapping labels in SelectorCache when reserved:host identity has multiple IPs (Backport PR [#​28418](https://togithub.com/cilium/cilium/issues/28418), Upstream PR [#​28332](https://togithub.com/cilium/cilium/issues/28332), [@​squeed](https://togithub.com/squeed)) - Must have port for Service reference (Backport PR [#​28282](https://togithub.com/cilium/cilium/issues/28282), Upstream PR [#​27959](https://togithub.com/cilium/cilium/issues/27959), [@​chaunceyjiang](https://togithub.com/chaunceyjiang)) - pkg/k8s: use a deep copy of CNP in UpdateStatus to avoid race condition (Backport PR [#​28494](https://togithub.com/cilium/cilium/issues/28494), Upstream PR [#​28364](https://togithub.com/cilium/cilium/issues/28364), [@​aanm](https://togithub.com/aanm)) - pkg/node: Updates GetIPv6AllocCIDRs() to Properly Return Secondary CIDRs (Backport PR [#​28095](https://togithub.com/cilium/cilium/issues/28095), Upstream PR [#​27855](https://togithub.com/cilium/cilium/issues/27855), [@​danehans](https://togithub.com/danehans)) - resource: Fix race condition in handling of Kubernetes object delete event retrying. In the very rare case when an object was created, deleted and re-created with the same name and the handling of the first deletion failed, the handling of delete event may have been retried even though the object was re-created. Only affected features using the Resource-library (LB IPAM, Mutual Auth and ClusterMesh). (Backport PR [#​28494](https://togithub.com/cilium/cilium/issues/28494), Upstream PR [#​27340](https://togithub.com/cilium/cilium/issues/27340), [@​joamaki](https://togithub.com/joamaki)) - Restore host-stack bypass for pod-to-pod traffic in a configuration with kube-proxy, tunnel routing and per-endpoint routes. (Backport PR [#​28095](https://togithub.com/cilium/cilium/issues/28095), Upstream PR [#​27908](https://togithub.com/cilium/cilium/issues/27908), [@​julianwiedmann](https://togithub.com/julianwiedmann)) **CI Changes:** - \[v1.14] ci: Add a call to the update label backport action ([#​27876](https://togithub.com/cilium/cilium/issues/27876), [@​pippolo84](https://togithub.com/pippolo84)) - \[v1.14] GHA: Add clustermesh upgrade and downgrade tests ([#​28355](https://togithub.com/cilium/cilium/issues/28355), [@​giorio94](https://togithub.com/giorio94)) - ci-ipsec-upgrade: Enable IPv6 (Backport PR [#​28095](https://togithub.com/cilium/cilium/issues/28095), Upstream PR [#​27220](https://togithub.com/cilium/cilium/issues/27220), [@​brb](https://togithub.com/brb)) - CI: Add conn-disrupt-test action for reuse (Backport PR [#​28282](https://togithub.com/cilium/cilium/issues/28282), Upstream PR [#​27567](https://togithub.com/cilium/cilium/issues/27567), [@​jschwinger233](https://togithub.com/jschwinger233)) - CI: Add IPsec key rotation test (Backport PR [#​28105](https://togithub.com/cilium/cilium/issues/28105), Upstream PR [#​27203](https://togithub.com/cilium/cilium/issues/27203), [@​jschwinger233](https://togithub.com/jschwinger233)) - CI: Move IPsec CI jobs into separate pipelines (Backport PR [#​28105](https://togithub.com/cilium/cilium/issues/28105), Upstream PR [#​26730](https://togithub.com/cilium/cilium/issues/26730), [@​jschwinger233](https://togithub.com/jschwinger233)) - ci: Run BPF lints on workflow definition changes (Backport PR [#​28282](https://togithub.com/cilium/cilium/issues/28282), Upstream PR [#​28122](https://togithub.com/cilium/cilium/issues/28122), [@​qmonnet](https://togithub.com/qmonnet)) - ci: update k8s versions support for v1.14 ([#​28248](https://togithub.com/cilium/cilium/issues/28248), [@​nbusseneau](https://togithub.com/nbusseneau)) - Do not hardcode the AWS VPC CNI plugin version in the conformance-aws-cni GHA workflow (Backport PR [#​28442](https://togithub.com/cilium/cilium/issues/28442), Upstream PR [#​28392](https://togithub.com/cilium/cilium/issues/28392), [@​giorio94](https://togithub.com/giorio94)) - ginkgo: Remove K8sDatapathCustomCalls (Backport PR [#​28095](https://togithub.com/cilium/cilium/issues/28095), Upstream PR [#​27911](https://togithub.com/cilium/cilium/issues/27911), [@​brb](https://togithub.com/brb)) - Refactor CiliumExecContext() Retry Logic (Backport PR [#​28282](https://togithub.com/cilium/cilium/issues/28282), Upstream PR [#​28131](https://togithub.com/cilium/cilium/issues/28131), [@​carnerito](https://togithub.com/carnerito)) - workflows/ipsec: Add missing `--flush-ct` for key rotation (Backport PR [#​28105](https://togithub.com/cilium/cilium/issues/28105), Upstream PR [#​27883](https://togithub.com/cilium/cilium/issues/27883), [@​pchaigno](https://togithub.com/pchaigno)) **Misc Changes:** - \[Docs] Clarify ClusterMesh troubleshooting steps when KVStoreMesh is enabled (Backport PR [#​28282](https://togithub.com/cilium/cilium/issues/28282), Upstream PR [#​27691](https://togithub.com/cilium/cilium/issues/27691), [@​weizhoublue](https://togithub.com/weizhoublue)) - Add option conntrackGCMaxInterval to allow limiting the maximum connection tracking GC interval. By default the automatic interval calculation may increase the interval up to 12 hours, which may incur an unreasonable delay to releasing of CIDR identities created from ToFQDN policies. Setting this option will limit the interval and ensure such identities are marked unused earlier and removed. (Backport PR [#​28282](https://togithub.com/cilium/cilium/issues/28282), Upstream PR [#​27870](https://togithub.com/cilium/cilium/issues/27870), [@​joamaki](https://togithub.com/joamaki)) - bugtool: various updates to BPF map dump (Backport PR [#​28282](https://togithub.com/cilium/cilium/issues/28282), Upstream PR [#​28065](https://togithub.com/cilium/cilium/issues/28065), [@​julianwiedmann](https://togithub.com/julianwiedmann)) - bump k8s dependencies to 1.27.6 ([#​28560](https://togithub.com/cilium/cilium/issues/28560), [@​aanm](https://togithub.com/aanm)) - chore(deps): update actions/checkout action to v4 (v1.14) ([#​27944](https://togithub.com/cilium/cilium/issues/27944), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update all github action dependencies (v1.14) (minor) ([#​27776](https://togithub.com/cilium/cilium/issues/27776), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update all github action dependencies (v1.14) (patch) ([#​28078](https://togithub.com/cilium/cilium/issues/28078), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update all github action dependencies (v1.14) (patch) ([#​28209](https://togithub.com/cilium/cilium/issues/28209), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update all github action dependencies to v3 (v1.14) (major) ([#​28101](https://togithub.com/cilium/cilium/issues/28101), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update all lvh-images main (v1.14) (patch) ([#​27942](https://togithub.com/cilium/cilium/issues/27942), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update all lvh-images main (v1.14) (patch) ([#​28210](https://togithub.com/cilium/cilium/issues/28210), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update aws-actions/configure-aws-credentials action to v4 (v1.14) ([#​28102](https://togithub.com/cilium/cilium/issues/28102), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update cilium/cilium digest to [`6c12a0f`](https://togithub.com/cilium/cilium/commit/6c12a0f) (v1.14) ([#​28075](https://togithub.com/cilium/cilium/issues/28075), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update cilium/cilium digest to [`8b7844d`](https://togithub.com/cilium/cilium/commit/8b7844d) (v1.14) ([#​28196](https://togithub.com/cilium/cilium/issues/28196), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update dependency cilium/cilium-cli to v0.15.8 (v1.14) ([#​28211](https://togithub.com/cilium/cilium/issues/28211), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update dependency cilium/hubble to v0.12.1 (v1.14) ([#​28521](https://togithub.com/cilium/cilium/issues/28521), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update dependency cilium/hubble to v0.12.2 (v1.14) ([#​28566](https://togithub.com/cilium/cilium/issues/28566), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update docker.io/library/golang:1.20.10 docker digest to [`098d628`](https://togithub.com/cilium/cilium/commit/098d628) (v1.14) ([#​28623](https://togithub.com/cilium/cilium/issues/28623), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update docker.io/library/golang:1.20.8 docker digest to [`6e1a67e`](https://togithub.com/cilium/cilium/commit/6e1a67e) (v1.14) ([#​28197](https://togithub.com/cilium/cilium/issues/28197), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update docker.io/library/ubuntu:22.04 docker digest to [`2b7412e`](https://togithub.com/cilium/cilium/commit/2b7412e) (v1.14) ([#​28630](https://togithub.com/cilium/cilium/issues/28630), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update docker.io/library/ubuntu:22.04 docker digest to [`990350f`](https://togithub.com/cilium/cilium/commit/990350f) (v1.14) ([#​28579](https://togithub.com/cilium/cilium/issues/28579), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update docker.io/library/ubuntu:22.04 docker digest to [`9b8dec3`](https://togithub.com/cilium/cilium/commit/9b8dec3) (v1.14) ([#​28384](https://togithub.com/cilium/cilium/issues/28384), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update docker.io/library/ubuntu:22.04 docker digest to [`aabed32`](https://togithub.com/cilium/cilium/commit/aabed32) (v1.14) ([#​28076](https://togithub.com/cilium/cilium/issues/28076), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update docker/build-push-action action to v5 (v1.14) ([#​28093](https://togithub.com/cilium/cilium/issues/28093), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update gcr.io/distroless/static-debian11:nonroot docker digest to [`92d40ee`](https://togithub.com/cilium/cilium/commit/92d40ee) (v1.14) ([#​27941](https://togithub.com/cilium/cilium/issues/27941), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update go to v1.20.10 (v1.14) (patch) ([#​28515](https://togithub.com/cilium/cilium/issues/28515), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update myrotvorets/set-commit-status-action action to v2 (v1.14) ([#​28082](https://togithub.com/cilium/cilium/issues/28082), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update quay.io/cilium/hubble docker tag to v0.12.1 (v1.14) ([#​28538](https://togithub.com/cilium/cilium/issues/28538), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update quay.io/cilium/hubble docker tag to v0.12.2 (v1.14) ([#​28569](https://togithub.com/cilium/cilium/issues/28569), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update sigstore/cosign-installer action to v3.1.2 (v1.14) ([#​27943](https://togithub.com/cilium/cilium/issues/27943), [@​renovate](https://togithub.com/renovate)\[bot]) - ci: fix AWS EKS K8s versions comment (Backport PR [#​28282](https://togithub.com/cilium/cilium/issues/28282), Upstream PR [#​28249](https://togithub.com/cilium/cilium/issues/28249), [@​nbusseneau](https://togithub.com/nbusseneau)) - docs: Add instructions for running LVH against custom kernel (Backport PR [#​28349](https://togithub.com/cilium/cilium/issues/28349), Upstream PR [#​28305](https://togithub.com/cilium/cilium/issues/28305), [@​brb](https://togithub.com/brb)) - docs: Add Makefile and documentation for "fast" development targets (Backport PR [#​28095](https://togithub.com/cilium/cilium/issues/28095), Upstream PR [#​27931](https://togithub.com/cilium/cilium/issues/27931), [@​aanm](https://togithub.com/aanm)) - docs: Add more details for the Cluster Mesh key rotation (Backport PR [#​28282](https://togithub.com/cilium/cilium/issues/28282), Upstream PR [#​28145](https://togithub.com/cilium/cilium/issues/28145), [@​margamanterola](https://togithub.com/margamanterola)) - docs: egressgw: document incompatibility with Clustermesh (Backport PR [#​28095](https://togithub.com/cilium/cilium/issues/28095), Upstream PR [#​27918](https://togithub.com/cilium/cilium/issues/27918), [@​julianwiedmann](https://togithub.com/julianwiedmann)) - docs: Makefile, check-build.sh clean-ups and perf improvements (Backport PR [#​28282](https://togithub.com/cilium/cilium/issues/28282), Upstream PR [#​28161](https://togithub.com/cilium/cilium/issues/28161), [@​qmonnet](https://togithub.com/qmonnet)) - docs: Mention `RouteTableInterfacesOffset` in system requirements (Backport PR [#​28442](https://togithub.com/cilium/cilium/issues/28442), Upstream PR [#​28358](https://togithub.com/cilium/cilium/issues/28358), [@​gandro](https://togithub.com/gandro)) - docs: rephrasing the hubble intro doc (Backport PR [#​28095](https://togithub.com/cilium/cilium/issues/28095), Upstream PR [#​27712](https://togithub.com/cilium/cilium/issues/27712), [@​vipul-21](https://togithub.com/vipul-21)) - docs: Update Sphinx and its dependencies, Cilium theme (Backport PR [#​28282](https://togithub.com/cilium/cilium/issues/28282), Upstream PR [#​28172](https://togithub.com/cilium/cilium/issues/28172), [@​qmonnet](https://togithub.com/qmonnet)) - endpoint: Fix use of PolicyMapFullReconciliationInterval option (Backport PR [#​28095](https://togithub.com/cilium/cilium/issues/28095), Upstream PR [#​27985](https://togithub.com/cilium/cilium/issues/27985), [@​joamaki](https://togithub.com/joamaki)) - Fix bug when reusing the same cell in multiple hives (Backport PR [#​28282](https://togithub.com/cilium/cilium/issues/28282), Upstream PR [#​27873](https://togithub.com/cilium/cilium/issues/27873), [@​giorio94](https://togithub.com/giorio94)) - Fix potential nil pointer dereference in SelectorManager implementation (Backport PR [#​28095](https://togithub.com/cilium/cilium/issues/28095), Upstream PR [#​27805](https://togithub.com/cilium/cilium/issues/27805), [@​learnitall](https://togithub.com/learnitall)) - fix(deps): update module golang.org/x/net to v0.17.0 \[security] ([#​28550](https://togithub.com/cilium/cilium/issues/28550), [@​aanm](https://togithub.com/aanm)) - fqdn proxy: fix data race detection on TCP fqdn proxy (Backport PR [#​28282](https://togithub.com/cilium/cilium/issues/28282), Upstream PR [#​28219](https://togithub.com/cilium/cilium/issues/28219), [@​mhofstetter](https://togithub.com/mhofstetter)) - Helm: Improved description for tunnel, tunnelProtocol, routingMode flags (Backport PR [#​28349](https://togithub.com/cilium/cilium/issues/28349), Upstream PR [#​27926](https://togithub.com/cilium/cilium/issues/27926), [@​PhilipSchmid](https://togithub.com/PhilipSchmid)) - hubble: Use protobuf GetType() helper in v1.FlowProtocol() to avoid possible panic (Backport PR [#​28095](https://togithub.com/cilium/cilium/issues/28095), Upstream PR [#​27889](https://togithub.com/cilium/cilium/issues/27889), [@​chancez](https://togithub.com/chancez)) - install/kubernetes: add the `cilium/values.yaml` target to `.PHONY` (Backport PR [#​28282](https://togithub.com/cilium/cilium/issues/28282), Upstream PR [#​28225](https://togithub.com/cilium/cilium/issues/28225), [@​nbusseneau](https://togithub.com/nbusseneau)) - ipsec: Atomically upgrade XFRM states with new output-mark (Backport PR [#​28563](https://togithub.com/cilium/cilium/issues/28563), Upstream PR [#​28485](https://togithub.com/cilium/cilium/issues/28485), [@​pchaigno](https://togithub.com/pchaigno)) - Make tolerations configurable in clustermesh-apiserver certgen job (Backport PR [#​28282](https://togithub.com/cilium/cilium/issues/28282), Upstream PR [#​28221](https://togithub.com/cilium/cilium/issues/28221), [@​giorio94](https://togithub.com/giorio94)) - Makefile: fix 'fast' make targets (Backport PR [#​28442](https://togithub.com/cilium/cilium/issues/28442), Upstream PR [#​28380](https://togithub.com/cilium/cilium/issues/28380), [@​aanm](https://togithub.com/aanm)) - policy: Move getNets to selector cache (Backport PR [#​28670](https://togithub.com/cilium/cilium/issues/28670), Upstream PR [#​27670](https://togithub.com/cilium/cilium/issues/27670), [@​jrajahalme](https://togithub.com/jrajahalme)) - Update docs theme (Backport PR [#​28442](https://togithub.com/cilium/cilium/issues/28442), Upstream PR [#​28403](https://togithub.com/cilium/cilium/issues/28403), [@​raphink](https://togithub.com/raphink)) - Update Hubble UI from v0.12.0 to v0.12.1 ([#​28535](https://togithub.com/cilium/cilium/issues/28535), [@​rolinh](https://togithub.com/rolinh)) **Other Changes:** - envoy: Bump envoy version to v1.25.10 ([#​28506](https://togithub.com/cilium/cilium/issues/28506), [@​sayboras](https://togithub.com/sayboras)) - Fix possible cross-cluster connection drops on agents restart when clustermesh is enabled ([#​27611](https://togithub.com/cilium/cilium/issues/27611), [@​giorio94](https://togithub.com/giorio94)) - v1.14: avoid relying on golang.org/exp/slices.SortFunc ([#​28473](https://togithub.com/cilium/cilium/issues/28473), [@​rolinh](https://togithub.com/rolinh)) ### [`v1.14.2`](https://togithub.com/cilium/cilium/releases/tag/v1.14.2): 1.14.2 [Compare Source](https://togithub.com/cilium/cilium/compare/1.14.1...1.14.2) We are pleased to release Cilium v1.14.2. Known IPsec related issues have been fixed. We encourage users to test this release and report any potentially remaining issues. ## Summary of Changes **Minor Changes:** - Add SPIRE connection to `cilium status` (Backport PR [#​27649](https://togithub.com/cilium/cilium/issues/27649), Upstream PR [#​26896](https://togithub.com/cilium/cilium/issues/26896), [@​meyskens](https://togithub.com/meyskens)) - Fix: Affinity in cilium-pre-flight-check daemonset. (Backport PR [#​27629](https://togithub.com/cilium/cilium/issues/27629), Upstream PR [#​27475](https://togithub.com/cilium/cilium/issues/27475), [@​ishuar](https://togithub.com/ishuar)) - gateway-api: Support all the extended features (Backport PR [#​27655](https://togithub.com/cilium/cilium/issues/27655), Upstream PR [#​27472](https://togithub.com/cilium/cilium/issues/27472), [@​sayboras](https://togithub.com/sayboras)) **Bugfixes:** - bpf: nodeport: add RevDNAT-based FIB lookup for reply traffic (Backport PR [#​27381](https://togithub.com/cilium/cilium/issues/27381), Upstream PR [#​26638](https://togithub.com/cilium/cilium/issues/26638), [@​julianwiedmann](https://togithub.com/julianwiedmann)) - cgroups: Fix race to load cgroup.hostRoot option (Backport PR [#​27629](https://togithub.com/cilium/cilium/issues/27629), Upstream PR [#​27561](https://togithub.com/cilium/cilium/issues/27561), [@​kvaps](https://togithub.com/kvaps)) - Do mutual authentication handshake again if mismatch between bpf map and cached map happens (Backport PR [#​27739](https://togithub.com/cilium/cilium/issues/27739), Upstream PR [#​27241](https://togithub.com/cilium/cilium/issues/27241), [@​meyskens](https://togithub.com/meyskens)) - envoy: fix panic writing accesslog without L7 tags (Backport PR [#​27629](https://togithub.com/cilium/cilium/issues/27629), Upstream PR [#​27453](https://togithub.com/cilium/cilium/issues/27453), [@​mhofstetter](https://togithub.com/mhofstetter)) - Fix a bug that could cause an incorrect max. sequence number to be reported by `cilium encrypt status` when IPsec is enabled. (Backport PR [#​27917](https://togithub.com/cilium/cilium/issues/27917), Upstream PR [#​27656](https://togithub.com/cilium/cilium/issues/27656), [@​pchaigno](https://togithub.com/pchaigno)) - Fix a bug where cilium host IP is not read from k8s node annotations (Backport PR [#​27679](https://togithub.com/cilium/cilium/issues/27679), Upstream PR [#​27590](https://togithub.com/cilium/cilium/issues/27590), [@​hemanthmalla](https://togithub.com/hemanthmalla)) - Fix behavior where SPIRE doesn't work when kubelet does not listen on 127.0.0.1 (Backport PR [#​27679](https://togithub.com/cilium/cilium/issues/27679), Upstream PR [#​27583](https://togithub.com/cilium/cilium/issues/27583), [@​weizhoublue](https://togithub.com/weizhoublue)) - Fix bug that could cause packet drops of type XfrmOutPolBlock while rotating the IPsec key. (Backport PR [#​27586](https://togithub.com/cilium/cilium/issues/27586), Upstream PR [#​27319](https://togithub.com/cilium/cilium/issues/27319), [@​jrfastab](https://togithub.com/jrfastab)) - Fix connectivity issues caused by missing conntrack entry when service pod connects to itself via clusterIP. (Backport PR [#​27920](https://togithub.com/cilium/cilium/issues/27920), Upstream PR [#​27602](https://togithub.com/cilium/cilium/issues/27602), [@​julianwiedmann](https://togithub.com/julianwiedmann)) - Fix deletion of tunnel map entries when node has non-zero cluster ID. (Backport PR [#​27629](https://togithub.com/cilium/cilium/issues/27629), Upstream PR [#​27353](https://togithub.com/cilium/cilium/issues/27353), [@​giorio94](https://togithub.com/giorio94)) - Fix Gateway managed services not exposing all ports (Backport PR [#​27917](https://togithub.com/cilium/cilium/issues/27917), Upstream PR [#​27695](https://togithub.com/cilium/cilium/issues/27695), [@​Managarmrr](https://togithub.com/Managarmrr)) - Fix global service incompatibility when v1.14 agents connect to a v1.13 cluster ([#​27882](https://togithub.com/cilium/cilium/issues/27882), [@​giorio94](https://togithub.com/giorio94)) - Fix issue which caused the map reconciliation process to never complete successfully if the error resolved automatically (Backport PR [#​27629](https://togithub.com/cilium/cilium/issues/27629), Upstream PR [#​26742](https://togithub.com/cilium/cilium/issues/26742), [@​giorio94](https://togithub.com/giorio94)) - Fix missing packet trace after `from-container` for reply traffic to the proxy. (Backport PR [#​27917](https://togithub.com/cilium/cilium/issues/27917), Upstream PR [#​27872](https://togithub.com/cilium/cilium/issues/27872), [@​pchaigno](https://togithub.com/pchaigno)) - Fix potential cross-node connectivity issue when IPsec is enabled with ENI or Azure IPAM modes. (Backport PR [#​27924](https://togithub.com/cilium/cilium/issues/27924), Upstream PR [#​26663](https://togithub.com/cilium/cilium/issues/26663), [@​gandro](https://togithub.com/gandro)) - Fix propagation of namespace labels to CEP labels (Backport PR [#​27917](https://togithub.com/cilium/cilium/issues/27917), Upstream PR [#​27831](https://togithub.com/cilium/cilium/issues/27831), [@​tklauser](https://togithub.com/tklauser)) - Fix several paths in the North-South load-balancer where the TTL / hop-limit field of a forwarded packet was not updated. (Backport PR [#​27379](https://togithub.com/cilium/cilium/issues/27379), Upstream PR [#​27299](https://togithub.com/cilium/cilium/issues/27299), [@​julianwiedmann](https://togithub.com/julianwiedmann)) - Fixes a issue that IPsec key rotation can't be triggered. (Backport PR [#​27739](https://togithub.com/cilium/cilium/issues/27739), Upstream PR [#​27694](https://togithub.com/cilium/cilium/issues/27694), [@​jschwinger233](https://togithub.com/jschwinger233)) - gateway-api: Filter routes based on Section Name and port (Backport PR [#​27629](https://togithub.com/cilium/cilium/issues/27629), Upstream PR [#​27309](https://togithub.com/cilium/cilium/issues/27309), [@​sayboras](https://togithub.com/sayboras)) - gateway-api: Merge externally annotations and labels for kubernetes types (Backport PR [#​27629](https://togithub.com/cilium/cilium/issues/27629), Upstream PR [#​27251](https://togithub.com/cilium/cilium/issues/27251), [@​farodin91](https://togithub.com/farodin91)) - helm: fix envoy daemonset loglevel with multiple verbose debug groups (Backport PR [#​27917](https://togithub.com/cilium/cilium/issues/27917), Upstream PR [#​27698](https://togithub.com/cilium/cilium/issues/27698), [@​mhofstetter](https://togithub.com/mhofstetter)) - ingress: fix panic on ingress rule without HTTPIngressRule (Backport PR [#​27917](https://togithub.com/cilium/cilium/issues/27917), Upstream PR [#​27818](https://togithub.com/cilium/cilium/issues/27818), [@​mhofstetter](https://togithub.com/mhofstetter)) - ipam: when a CiliumNode is removed, delete node label from metrics. (Backport PR [#​27917](https://togithub.com/cilium/cilium/issues/27917), Upstream PR [#​27713](https://togithub.com/cilium/cilium/issues/27713), [@​tommyp1ckles](https://togithub.com/tommyp1ckles)) - IPSec fix for race on init resulting in Xfrm*In* errors and dropped packets (Backport PR [#​28021](https://togithub.com/cilium/cilium/issues/28021), Upstream PR [#​28012](https://togithub.com/cilium/cilium/issues/28012), [@​jrfastab](https://togithub.com/jrfastab)) - k8s: Restrict configuring reserved:init policy via CNP (Backport PR [#​28038](https://togithub.com/cilium/cilium/issues/28038), Upstream PR [#​28007](https://togithub.com/cilium/cilium/issues/28007), [@​joestringer](https://togithub.com/joestringer)) - Prioritization of which DNS mappings to keep was suboptimal, leading to evictions of mappings related to alive connections, worsening performance of fqdn policies and causing spurious logging. (Backport PR [#​27917](https://togithub.com/cilium/cilium/issues/27917), Upstream PR [#​27572](https://togithub.com/cilium/cilium/issues/27572), [@​bimmlerd](https://togithub.com/bimmlerd)) - proxy: Ignore visibility annotation if proxy is disabled (Backport PR [#​27679](https://togithub.com/cilium/cilium/issues/27679), Upstream PR [#​27597](https://togithub.com/cilium/cilium/issues/27597), [@​sayboras](https://togithub.com/sayboras)) - Read FQDNRejectResponseCode from config (Backport PR [#​27739](https://togithub.com/cilium/cilium/issues/27739), Upstream PR [#​27362](https://togithub.com/cilium/cilium/issues/27362), [@​ayuspin](https://togithub.com/ayuspin)) **CI Changes:** - .github/workflows: unify time to wait for images to become available (Backport PR [#​27917](https://togithub.com/cilium/cilium/issues/27917), Upstream PR [#​27706](https://togithub.com/cilium/cilium/issues/27706), [@​tklauser](https://togithub.com/tklauser)) - Add missing ariane trigger phrases (Backport PR [#​27917](https://togithub.com/cilium/cilium/issues/27917), Upstream PR [#​27822](https://togithub.com/cilium/cilium/issues/27822), [@​tklauser](https://togithub.com/tklauser)) - Add secondary iface to KIND network (Backport PR [#​27679](https://togithub.com/cilium/cilium/issues/27679), Upstream PR [#​26338](https://togithub.com/cilium/cilium/issues/26338), [@​ysksuzuki](https://togithub.com/ysksuzuki)) - bpf: complexity-tests: set -DHAVE_LARGE_INSN_LIMIT=1 for new kernels (Backport PR [#​27701](https://togithub.com/cilium/cilium/issues/27701), Upstream PR [#​27490](https://togithub.com/cilium/cilium/issues/27490), [@​julianwiedmann](https://togithub.com/julianwiedmann)) - ci-e2e: Add secondary network NodePort tests (Backport PR [#​27917](https://togithub.com/cilium/cilium/issues/27917), Upstream PR [#​27738](https://togithub.com/cilium/cilium/issues/27738), [@​brb](https://togithub.com/brb)) - ci-ipsec-upgrade: Bump CLI to v0.15.5 (Backport PR [#​27629](https://togithub.com/cilium/cilium/issues/27629), Upstream PR [#​27230](https://togithub.com/cilium/cilium/issues/27230), [@​brb](https://togithub.com/brb)) - ci-ipsec-upgrade: Skip upon test/Documentation changes (Backport PR [#​27679](https://togithub.com/cilium/cilium/issues/27679), Upstream PR [#​27644](https://togithub.com/cilium/cilium/issues/27644), [@​brb](https://togithub.com/brb)) - ci: remove unavailable K8s 1.22 from GKE config (Backport PR [#​27629](https://togithub.com/cilium/cilium/issues/27629), Upstream PR [#​27365](https://togithub.com/cilium/cilium/issues/27365), [@​mhofstetter](https://togithub.com/mhofstetter)) - CI: Rename workflow names (Backport PR [#​27739](https://togithub.com/cilium/cilium/issues/27739), Upstream PR [#​27391](https://togithub.com/cilium/cilium/issues/27391), [@​brlbil](https://togithub.com/brlbil)) - CI: Update tested k8s version for aks (Backport PR [#​27629](https://togithub.com/cilium/cilium/issues/27629), Upstream PR [#​27457](https://togithub.com/cilium/cilium/issues/27457), [@​brlbil](https://togithub.com/brlbil)) - Disable the images digest when pushing the development helm chart (Backport PR [#​27739](https://togithub.com/cilium/cilium/issues/27739), Upstream PR [#​27646](https://togithub.com/cilium/cilium/issues/27646), [@​giorio94](https://togithub.com/giorio94)) - gh/actions: Customize cilium-config (Backport PR [#​27917](https://togithub.com/cilium/cilium/issues/27917), Upstream PR [#​27416](https://togithub.com/cilium/cilium/issues/27416), [@​brb](https://togithub.com/brb)) - gh/workflows: Use cilium-config action in ci-ipsec-upgrade (Backport PR [#​27917](https://togithub.com/cilium/cilium/issues/27917), Upstream PR [#​27359](https://togithub.com/cilium/cilium/issues/27359), [@​brb](https://togithub.com/brb)) - gha: fix waiting for images in conformance-gingko (Backport PR [#​27629](https://togithub.com/cilium/cilium/issues/27629), Upstream PR [#​27397](https://togithub.com/cilium/cilium/issues/27397), [@​giorio94](https://togithub.com/giorio94)) - Set kvstoremesh image when pushing the development helm chart (Backport PR [#​27679](https://togithub.com/cilium/cilium/issues/27679), Upstream PR [#​27645](https://togithub.com/cilium/cilium/issues/27645), [@​giorio94](https://togithub.com/giorio94)) - test: print logical instruction count per program (Backport PR [#​27629](https://togithub.com/cilium/cilium/issues/27629), Upstream PR [#​26641](https://togithub.com/cilium/cilium/issues/26641), [@​ti-mo](https://togithub.com/ti-mo)) **Misc Changes:** - \[v1.14] cilium: Fix 16bit ifindex limitation ([#​27880](https://togithub.com/cilium/cilium/issues/27880), [@​borkmann](https://togithub.com/borkmann)) - Add WireGuard to the firewall rules documentation (Backport PR [#​27917](https://togithub.com/cilium/cilium/issues/27917), Upstream PR [#​27170](https://togithub.com/cilium/cilium/issues/27170), [@​joestringer](https://togithub.com/joestringer)) - bpf: egressgw: set trace reason for reply traffic (Backport PR [#​27524](https://togithub.com/cilium/cilium/issues/27524), Upstream PR [#​27218](https://togithub.com/cilium/cilium/issues/27218), [@​julianwiedmann](https://togithub.com/julianwiedmann)) - bpf: nat: enable CT-driven trace aggregation (Backport PR [#​27524](https://togithub.com/cilium/cilium/issues/27524), Upstream PR [#​27178](https://togithub.com/cilium/cilium/issues/27178), [@​julianwiedmann](https://togithub.com/julianwiedmann)) - bpf: nat: let caller determine whether SNATed connection needs CT (Backport PR [#​27524](https://togithub.com/cilium/cilium/issues/27524), Upstream PR [#​27079](https://togithub.com/cilium/cilium/issues/27079), [@​julianwiedmann](https://togithub.com/julianwiedmann)) - bpf: nodeport: consolidate packet rewrite in RevDNAT path (Backport PR [#​27381](https://togithub.com/cilium/cilium/issues/27381), Upstream PR [#​26852](https://togithub.com/cilium/cilium/issues/26852), [@​julianwiedmann](https://togithub.com/julianwiedmann)) - bpf: split complexity configurations into separate files (Backport PR [#​27701](https://togithub.com/cilium/cilium/issues/27701), Upstream PR [#​26925](https://togithub.com/cilium/cilium/issues/26925), [@​lmb](https://togithub.com/lmb)) - chore(deps): update all kind-images main (v1.14) ([#​27746](https://togithub.com/cilium/cilium/issues/27746), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update all kind-images main (v1.14) (patch) ([#​27772](https://togithub.com/cilium/cilium/issues/27772), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update all lvh-images main (v1.14) (patch) ([#​27422](https://togithub.com/cilium/cilium/issues/27422), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update all lvh-images main (v1.14) (patch) ([#​27773](https://togithub.com/cilium/cilium/issues/27773), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update aws-actions/configure-aws-credentials action to v3 (v1.14) ([#​27777](https://togithub.com/cilium/cilium/issues/27777), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update dependency cilium/cilium-cli to v0.15.6 (v1.14) ([#​27769](https://togithub.com/cilium/cilium/issues/27769), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update dependency cilium/cilium-cli to v0.15.7 (v1.14) ([#​27919](https://togithub.com/cilium/cilium/issues/27919), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update dependency google/gops to v0.3.28 (v1.14) ([#​27413](https://togithub.com/cilium/cilium/issues/27413), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update dependency kubernetes/kubernetes to v1.27.5 (v1.14) ([#​27774](https://togithub.com/cilium/cilium/issues/27774), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update dependency ubuntu to v22 (v1.14) ([#​27778](https://togithub.com/cilium/cilium/issues/27778), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update docker.io/library/alpine docker tag to v3.18.3 (v1.14) ([#​27775](https://togithub.com/cilium/cilium/issues/27775), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update docker.io/library/golang:1.20.7 docker digest to [`741d6f9`](https://togithub.com/cilium/cilium/commit/741d6f9) (v1.14) ([#​27768](https://togithub.com/cilium/cilium/issues/27768), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update docker.io/library/golang:1.20.8 docker digest to [`700d726`](https://togithub.com/cilium/cilium/commit/700d726) (v1.14) ([#​28049](https://togithub.com/cilium/cilium/issues/28049), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update docker.io/library/ubuntu:22.04 docker digest to [`ec050c3`](https://togithub.com/cilium/cilium/commit/ec050c3) (v1.14) ([#​27546](https://togithub.com/cilium/cilium/issues/27546), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update go to v1.20.8 (v1.14) (patch) ([#​27990](https://togithub.com/cilium/cilium/issues/27990), [@​renovate](https://togithub.com/renovate)\[bot]) - chore: fixing blank k8sPodName in endpoint logger (Backport PR [#​27629](https://togithub.com/cilium/cilium/issues/27629), Upstream PR [#​26964](https://togithub.com/cilium/cilium/issues/26964), [@​vakalapa](https://togithub.com/vakalapa)) - cilium, docs: Add a note about KPR and nfs dependencies (Backport PR [#​27739](https://togithub.com/cilium/cilium/issues/27739), Upstream PR [#​27678](https://togithub.com/cilium/cilium/issues/27678), [@​borkmann](https://togithub.com/borkmann)) - clean-up: remove check for permissive CCNPs (Backport PR [#​27739](https://togithub.com/cilium/cilium/issues/27739), Upstream PR [#​27690](https://togithub.com/cilium/cilium/issues/27690), [@​shawnh2](https://togithub.com/shawnh2)) - contrib/scripts/kind.sh: specify IPv4 prefix and range on secondary network (Backport PR [#​27679](https://togithub.com/cilium/cilium/issues/27679), Upstream PR [#​27573](https://togithub.com/cilium/cilium/issues/27573), [@​tklauser](https://togithub.com/tklauser)) - Correct cni path in k3s installation documentation for rancher desktop (Backport PR [#​27739](https://togithub.com/cilium/cilium/issues/27739), Upstream PR [#​27702](https://togithub.com/cilium/cilium/issues/27702), [@​RichardoC](https://togithub.com/RichardoC)) - docs: Clean up prerequisites for the Ingress Controller (Backport PR [#​27629](https://togithub.com/cilium/cilium/issues/27629), Upstream PR [#​27222](https://togithub.com/cilium/cilium/issues/27222), [@​qmonnet](https://togithub.com/qmonnet)) - docs: Clean up references to deprecated modes "strict" and "partial" for kube-proxy replacement feature flag (Backport PR [#​27679](https://togithub.com/cilium/cilium/issues/27679), Upstream PR [#​27314](https://togithub.com/cilium/cilium/issues/27314), [@​qmonnet](https://togithub.com/qmonnet)) - docs: Correct comment on toFQDN API definition (Backport PR [#​27629](https://togithub.com/cilium/cilium/issues/27629), Upstream PR [#​27496](https://togithub.com/cilium/cilium/issues/27496), [@​Alex-Waring](https://togithub.com/Alex-Waring)) - docs: Fix config option for spelling filters (Backport PR [#​27629](https://togithub.com/cilium/cilium/issues/27629), Upstream PR [#​27537](https://togithub.com/cilium/cilium/issues/27537), [@​qmonnet](https://togithub.com/qmonnet)) - docs: Fix Documentation Makefile to make Helm reference updates compatible with macOS (Backport PR [#​27629](https://togithub.com/cilium/cilium/issues/27629), Upstream PR [#​27495](https://togithub.com/cilium/cilium/issues/27495), [@​ishuar](https://togithub.com/ishuar)) - docs: Harmonise references to Cilium Slack (Backport PR [#​27629](https://togithub.com/cilium/cilium/issues/27629), Upstream PR [#​27346](https://togithub.com/cilium/cilium/issues/27346), [@​qmonnet](https://togithub.com/qmonnet)) - docs: Improve wording for labels and services policies (Backport PR [#​27917](https://togithub.com/cilium/cilium/issues/27917), Upstream PR [#​27171](https://togithub.com/cilium/cilium/issues/27171), [@​joestringer](https://togithub.com/joestringer)) - docs: Remove proxylib limitation in observability section (Backport PR [#​27629](https://togithub.com/cilium/cilium/issues/27629), Upstream PR [#​27306](https://togithub.com/cilium/cilium/issues/27306), [@​darkrift](https://togithub.com/darkrift)) - docs: update L7 traffic CiliumClusterwideEnvoyConfig example (Backport PR [#​27629](https://togithub.com/cilium/cilium/issues/27629), Upstream PR [#​27409](https://togithub.com/cilium/cilium/issues/27409), [@​tanjunchen](https://togithub.com/tanjunchen)) - docs: Update the microservices-demo link (Backport PR [#​27917](https://togithub.com/cilium/cilium/issues/27917), Upstream PR [#​27814](https://togithub.com/cilium/cilium/issues/27814), [@​haiyuewa](https://togithub.com/haiyuewa)) - docs: Update the mutual authentication key format (Backport PR [#​27679](https://togithub.com/cilium/cilium/issues/27679), Upstream PR [#​27640](https://togithub.com/cilium/cilium/issues/27640), [@​haiyuewa](https://togithub.com/haiyuewa)) - egressgw: small test fixes (Backport PR [#​27701](https://togithub.com/cilium/cilium/issues/27701), Upstream PR [#​27574](https://togithub.com/cilium/cilium/issues/27574), [@​lmb](https://togithub.com/lmb)) - Gatewap API: Implement generic route checks (Backport PR [#​27655](https://togithub.com/cilium/cilium/issues/27655), Upstream PR [#​25885](https://togithub.com/cilium/cilium/issues/25885), [@​meyskens](https://togithub.com/meyskens)) - renovate: Don't exclude github.com/{cilium,vishvananda}/netlink anymore (Backport PR [#​27629](https://togithub.com/cilium/cilium/issues/27629), Upstream PR [#​27342](https://togithub.com/cilium/cilium/issues/27342), [@​lambdanis](https://togithub.com/lambdanis)) - typo: the clustermesh secret name (Backport PR [#​27739](https://togithub.com/cilium/cilium/issues/27739), Upstream PR [#​27658](https://togithub.com/cilium/cilium/issues/27658), [@​weizhoublue](https://togithub.com/weizhoublue)) - Update Cilium certgen from v0.1.8 to v0.1.9 (Backport PR [#​27629](https://togithub.com/cilium/cilium/issues/27629), Upstream PR [#​27511](https://togithub.com/cilium/cilium/issues/27511), [@​rolinh](https://togithub.com/rolinh)) **Other Changes:** - \[1.14] test: add namespace name in pod metadata test ([#​28032](https://togithub.com/cilium/cilium/issues/28032), [@​nebril](https://togithub.com/nebril)) - backport v1.14: gh/workflows: Reusable workflow for ci-e2e and misc changes ([#​27375](https://togithub.com/cilium/cilium/issues/27375), [@​brb](https://togithub.com/brb)) - doc: Migrate to .readthedocs.yaml configuration file v2 ([#​27571](https://togithub.com/cilium/cilium/issues/27571), [@​doniacld](https://togithub.com/doniacld)) - envoy: Update envoy image with newer proxylib builder ([#​27650](https://togithub.com/cilium/cilium/issues/27650), [@​sayboras](https://togithub.com/sayboras)) - install: Update image digests for v1.14.1 ([#​27505](https://togithub.com/cilium/cilium/issues/27505), [@​nebril](https://togithub.com/nebril)) ### [`v1.14.1`](https://togithub.com/cilium/cilium/releases/tag/v1.14.1): 1.14.1 [Compare Source](https://togithub.com/cilium/cilium/compare/1.14.0...1.14.1) We are pleased to release Cilium v1.14.1. This release comes with fixes for IPsec, performance and resilience improvements and many CI and doc changes. Remaining issues on the IPSec stack may cause interrupted connections during key rotations. Users may upgrade to this release only if this is considered acceptable. ## Summary of Changes **Minor Changes:** - gateway-api: Upgrade to v0.7.1 (Backport PR [#​27238](https://togithub.com/cilium/cilium/issues/27238), Upstream PR [#​27157](https://togithub.com/cilium/cilium/issues/27157), [@​sayboras](https://togithub.com/sayboras)) - Prevent Cilium from running with Delegated IPAM at the same time as Ingress (Backport PR [#​27238](https://togithub.com/cilium/cilium/issues/27238), Upstream PR [#​26744](https://togithub.com/cilium/cilium/issues/26744), [@​rickysumho](https://togithub.com/rickysumho)) **Bugfixes:** - Fix a bug that affected the health-check feature in Stand-alone L4LB mode. For certain configurations (eg if both IPv4 and IPv6 support is enabled) health-check traffic would not get IPIP-encapsulated. (Backport PR [#​27190](https://togithub.com/cilium/cilium/issues/27190), Upstream PR [#​27015](https://togithub.com/cilium/cilium/issues/27015), [@​julianwiedmann](https://togithub.com/julianwiedmann)) - Fix a bug that affected the RevDNAT translation of IPv6 packets with extension headers. (Backport PR [#​27345](https://togithub.com/cilium/cilium/issues/27345), Upstream PR [#​27312](https://togithub.com/cilium/cilium/issues/27312), [@​julianwiedmann](https://togithub.com/julianwiedmann)) - Fix a bug that could cause packet drops of type XfrmOutPolBlock when IPsec is enabled and node are recycled. - Fix a bug that could cause IPsec-encrypted packets to be sent to the wrong destination node when node churn is high. (Backport PR [#​27238](https://togithub.com/cilium/cilium/issues/27238), Upstream PR [#​27029](https://togithub.com/cilium/cilium/issues/27029), [@​pchaigno](https://togithub.com/pchaigno)) - Fix agent panic in case malformed objects are retrieved from the kvstore, and improve validation (Backport PR [#​27345](https://togithub.com/cilium/cilium/issues/27345), Upstream PR [#​27237](https://togithub.com/cilium/cilium/issues/27237), [@​giorio94](https://togithub.com/giorio94)) - Fix bug limiting pod-to-pod network performance under high load when tunneling and IPSec are both enabled. (Backport PR [#​27345](https://togithub.com/cilium/cilium/issues/27345), Upstream PR [#​27168](https://togithub.com/cilium/cilium/issues/27168), [@​learnitall](https://togithub.com/learnitall)) - Fix bug where startup CIDR restore logic would mishandle reference counting, leading to persistent packet loss to those CIDRs (Backport PR [#​27419](https://togithub.com/cilium/cilium/issues/27419), Upstream PR [#​27327](https://togithub.com/cilium/cilium/issues/27327), [@​joestringer](https://togithub.com/joestringer)) - Fix generation of the clustermesh config through Helm when kvstoremesh is enabled, and the TLS key/cert pair is manually specified for a given remote cluster (Backport PR [#​27238](https://togithub.com/cilium/cilium/issues/27238), Upstream PR [#​27177](https://togithub.com/cilium/cilium/issues/27177), [@​giorio94](https://togithub.com/giorio94)) - operator: Adjust CiliumEndpoint gc to account for kvstore mode (Backport PR [#​27190](https://togithub.com/cilium/cilium/issues/27190), Upstream PR [#​25324](https://togithub.com/cilium/cilium/issues/25324), [@​learnitall](https://togithub.com/learnitall)) - Resolve a deadlock on startup when local redirect policies are used. (Backport PR [#​27238](https://togithub.com/cilium/cilium/issues/27238), Upstream PR [#​27115](https://togithub.com/cilium/cilium/issues/27115), [@​bimmlerd](https://togithub.com/bimmlerd)) **CI Changes:** - .github: rebuild ginkgo tests in case of cache miss (Backport PR [#​27190](https://togithub.com/cilium/cilium/issues/27190), Upstream PR [#​27158](https://togithub.com/cilium/cilium/issues/27158), [@​sayboras](https://togithub.com/sayboras)) - Add renovate tags for automatic updates of kernel version in v1.14 ([#​27386](https://togithub.com/cilium/cilium/issues/27386), [@​aanm](https://togithub.com/aanm)) - ci: fix and standardize checkouts in privileged workflows (Backport PR [#​27238](https://togithub.com/cilium/cilium/issues/27238), Upstream PR [#​27193](https://togithub.com/cilium/cilium/issues/27193), [@​nbusseneau](https://togithub.com/nbusseneau)) - ci: increase connectivity test timeout in GHA external workload (Backport PR [#​27345](https://togithub.com/cilium/cilium/issues/27345), Upstream PR [#​26975](https://togithub.com/cilium/cilium/issues/26975), [@​mhofstetter](https://togithub.com/mhofstetter)) **Misc Changes:** - Add note for changing IPAM settings (Backport PR [#​27238](https://togithub.com/cilium/cilium/issues/27238), Upstream PR [#​27090](https://togithub.com/cilium/cilium/issues/27090), [@​darox](https://togithub.com/darox)) - chore(deps): update cilium/little-vm-helper action to v0.0.12 (v1.14) ([#​27270](https://togithub.com/cilium/cilium/issues/27270), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update dependency cilium/cilium-cli to v0.15.5 (v1.14) ([#​27271](https://togithub.com/cilium/cilium/issues/27271), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update go to v1.20.6 (v1.14) (patch) ([#​26783](https://togithub.com/cilium/cilium/issues/26783), [@​renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update go to v1.20.7 (v1.14) (patch) ([#​27284](https://togithub.com/cilium/cilium/issues/27284), [@​renovate](https://togithub.com/renovate)\[bot]) - docs/ipsec: Extend troubleshooting for long key rotations (Backport PR [#​27190](https://togithub.com/cilium/cilium/issues/27190), Upstream PR [#​26809](https://togithub.com/cilium/cilium/issues/26809), [@​pchaigno](https://togithub.com/pchaigno)) - docs: Document `DROP_NO_NODE_ID` for IPsec (Backport PR [#​27345](https://togithub.com/cilium/cilium/issues/27345), Upstream PR [#​27184](https://togithub.com/cilium/cilium/issues/27184), [@​pchaigno](https://togithub.com/pchaigno)) - docs: Have Makefile print generated image tags when running with V=0 (Backport PR [#​27345](https://togithub.com/cilium/cilium/issues/27345), Upstream PR [#​27250](https://togithub.com/cilium/cilium/issues/27250), [@​qmonnet](https://togithub.com/qmonnet)) - docs: kpr: remove caveat about XDP + tunnel performance (Backport PR [#​27190](https://togithub.com/cilium/cilium/issues/27190), Upstream PR [#​27091](https://togithub.com/cilium/cilium/issues/27091), [@​julianwiedmann](https://togithub.com/julianwiedmann)) - docs: Replace non-portable "sed -i" in Makefile (Backport PR [#​27238](https://togithub.com/cilium/cilium/issues/27238), Upstream PR [#​27122](https://togithub.com/cilium/cilium/issues/27122), [@​qmonnet](https://togithub.com/qmonnet)) - docs: Simplify clustermesh example (Backport PR [#​27238](https://togithub.com/cilium/cilium/issues/27238), Upstream PR [#​27172](https://togithub.com/cilium/cilium/issues/27172), [@​joestringer](https://togithub.com/joestringer)) - docs: update roadmap after 1.14 release (Backport PR [#​27238](https://togithub.com/cilium/cilium/issues/27238), Upstream PR [#​27089](https://togithub.com/cilium/cilium/issues/27089), [@​lizrice](https://togithub.com/lizrice)) - Documentation: fix the broken links/dead links (Backpor

Configuration

šŸ“… Schedule: Branch creation - "on saturday" (UTC), Automerge - At any time (no schedule defined).

šŸš¦ Automerge: Disabled by config. Please merge this manually once you are satisfied.

ā™» Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

šŸ”• Ignore: Close this PR and you won't be reminded about this update again.



This PR has been generated by Mend Renovate. View repository job log here.