Closed renovate[bot] closed 2 months ago
In order to perform the update(s) described in the table above, Renovate ran the go get
command, which resulted in the following additional change(s):
Details:
Package | Change |
---|---|
github.com/go-jose/go-jose/v3 |
v3.0.1 -> v3.0.3 |
This PR contains the following updates:
v1.14.6
->v1.14.12
GitHub Vulnerability Alerts
CVE-2024-28248
Impact
Cilium's HTTP policies are not consistently applied to all traffic in the scope of the policies, leading to HTTP traffic being incorrectly and intermittently forwarded when it should be dropped.
Patches
This issue affects:
This issue has been patched in:
Workarounds
There is no workaround for this issue ā affected users are strongly encouraged to upgrade.
Acknowledgements
The Cilium community has worked together with members of Isovalent to prepare these mitigations. Special thanks to @romikps for discovering and reporting this issue, and @sayboras and @jrajahalme for preparing the fix.
For more information
If you have any questions or comments about this advisory, please reach out on Slack.
If you think you have found a vulnerability affecting Cilium, we strongly encourage you to report it to our security mailing list at security@cilium.io. This is a private mailing list for the Cilium internal security team, and your report will be treated as top priority.
CVE-2024-28249
Impact
In Cilium clusters with IPsec enabled and traffic matching Layer 7 policies:
Note: For clusters running in native routing mode, IPsec encryption is not applied to connections which are selected by a L7 Egress Network Policy or a DNS Policy. This is a known limitation of Cilium's IPsec encryption which will continue to apply after upgrading to the latest Cilium versions described below.
Patches
This issue affects:
This issue has been resolved in:
Workarounds
There is no workaround to this issue.
Acknowledgements
The Cilium community has worked together with members of Isovalent to prepare these mitigations. Special thanks to @jschwinger233, @julianwiedmann, @giorio94, and @jrajahalme for their work in triaging and resolving this issue.
For more information
If you have any questions or comments about this advisory, please reach out on Slack.
If you think you have found a vulnerability in Cilium, we strongly encourage you to report it to our private security mailing list at security@cilium.io. This is a private mailing list that only members of the Cilium internal security team are subscribed to, and your report will be treated as top priority.
CVE-2024-28250
Impact
In Cilium clusters with WireGuard enabled and traffic matching Layer 7 policies:
Patches
This issue affects:
routingMode=native
):routingMode=tunnel
):encryption.wireguard.encapsulate
is set tofalse
(default).This issue has been resolved in:
routingMode=native
):routingMode=tunnel
):encryption.wireguard.encapsulate
must be set totrue
.Workarounds
There is no workaround to this issue.
Acknowledgements
The Cilium community has worked together with members of Isovalent to prepare these mitigations. Special thanks to @brb, @giorio94, @gandro and @jschwinger233 for their work on triaging and remediating this issue.
For more information
If you have any questions or comments about this advisory, please reach out on Slack.
If you think you found a related vulnerability, we strongly encourage you to report security vulnerabilities to our private security mailing list at security@cilium.io. This is a private mailing list where only members of the Cilium internal security team are subscribed to, and your report will be treated as top priority.
CVE-2024-28860
Impact
Users of IPsec transparent encryption in Cilium may be vulnerable to cryptographic attacks that render the transparent encryption ineffective.
In particular, Cilium is vulnerable to the following attacks by a man-in-the-middle attacker:
These attacks are possible due to an ESP sequence number collision when multiple nodes are configured with the same key. Fixed versions of Cilium use unique keys for each IPsec tunnel established between nodes, resolving all of the above attacks.
Important: After upgrading, users must perform a key rotation using the instructions here to ensure that they are no longer vulnerable to this issue. Please note that the key rotation instructions have recently been updated, and users must use the new instructions to properly establish secure IPsec tunnels. To validate that the new instructions have been followed properly, ensure that the IPsec Kubernetes secret contains a "+" sign.
Patches
All prior versions of Cilium that support IPsec transparent encryption (Cilium 1.4 onwards) are affected by this issue.
Patched versions:
Workarounds
There is no workaround to this issue. IPsec transparent encryption users are strongly encouraged to upgrade.
Acknowledgements
The Cilium community has worked together with members of Cure53 and Isovalent to prepare these mitigations. Special thanks to @NikAleksandrov and @pchaigno for their work on remediating the issue. Thanks to Marsh Ray, Senior Software Developer at Microsoft, for input and guidance on the fix.
For more information
If you have any questions or comments about this advisory, please reach out on Slack.
As usual, if you think you found a related vulnerability, we strongly encourage you to report security vulnerabilities to our private security mailing list: security@cilium.io - first, before disclosing them in any public forums. This is a private mailing list where only members of the Cilium internal security team are subscribed to, and is treated as top priority.
CVE-2024-37307
Impact
The output of
cilium-bugtool
can contain sensitive data when the tool is run (with the--envoy-dump
flag set) against Cilium deployments with the Envoy proxy enabled.Users of the following features are affected:
The sensitive data includes:
cilium-bugtool
is a debugging tool that is typically invoked manually and does not run during the normal operation of a Cilium cluster.Patches
This issue affects:
This issue has been patched in:
Workarounds
There is no workaround to this issue.
Acknowledgements
The Cilium community has worked together with members of Isovalent to prepare these mitigations. Special thanks to @sayboras for their work on triaging and remediating this issue.
For more information
If you have any questions or comments about this advisory, please reach out on Slack.
If you think you have found a vulnerability affecting Cilium, we strongly encourage you to report it to our security mailing list at security@cilium.io. This is a private mailing list for the Cilium security team, and your report will be treated as top priority.
CVE-2024-25630
Impact
For Cilium users who are using CRDs to store Cilium state (the default configuration) and Wireguard transparent encryption, responses from pods to the Ingress and health endpoints are not encrypted. Traffic from the Ingress and health endpoints to pods is not affected by this issue. The health endpoint is only used for Cilium's internal health checks.
Patches
This issue affects Cilium v1.14 before v1.14.7.
This issue has been patched in Cilium v1.14.7.
Workarounds
There is no workaround to this issue - affected users are encouraged to upgrade.
Acknowledgements
The Cilium community has worked together with members of Isovalent to prepare these mitigations. Special thanks to @gandro for their work on triaging and remediating this issue.
For more information
If you have any questions or comments about this advisory, please reach out on Slack.
If you think you have found a vulnerability affecting Cilium, we strongly encourage you to report it to our security mailing list at security@cilium.io. This is a private mailing list where only members of the Cilium internal security team are subscribed to, and your report will be treated as top priority.
CVE-2024-25631
Impact
For Cilium users who have enabled an external kvstore and Wireguard transparent encryption, traffic between pods in the affected cluster is not encrypted.
Patches
This issue affects Cilium v1.14 before v1.14.7.
This issue has been patched in Cilium v1.14.7.
Workarounds
There is no workaround to this issue - affected users are encouraged to upgrade.
Acknowledgements
The Cilium community has worked together with members of Isovalent to prepare these mitigations. Special thanks to @giorio94 and @gandro for their work on triaging and remediating this issue.
For more information
If you have any questions or comments about this advisory, please reach out on Slack.
If you think you found a related vulnerability, we strongly encourage you to report security vulnerabilities to our private security mailing list at security@cilium.io. This is a private mailing list where only members of the Cilium internal security team are subscribed to, and your report will be treated as top priority.
Release Notes
cilium/cilium (github.com/cilium/cilium)
### [`v1.14.12`](https://togithub.com/cilium/cilium/releases/tag/v1.14.12): 1.14.12 [Compare Source](https://togithub.com/cilium/cilium/compare/1.14.11...1.14.12) We are pleased to release Cilium v1.14.12 that improves background resynchronization of nodes, improves the CLI to troubleshoot connectivity issues, lowers CPU consumption with IPsec for large clusters, and brings a number of additional fixes. Thanks to all contributors, reviewers, testers, and users! :heart: ## Summary of Changes **Minor Changes:** - (v1.14) Generate SBOMs using Syft instead of bom ([#32750](https://togithub.com/cilium/cilium/issues/32750), [@ferozsalam](https://togithub.com/ferozsalam)) - Improved background resynchronization of nodes. Before all nodes were being updated at the same time, now we spread updates over time to average out CPU usage. (Backport PR [#32874](https://togithub.com/cilium/cilium/issues/32874), Upstream PR [#32577](https://togithub.com/cilium/cilium/issues/32577), [@marseel](https://togithub.com/marseel)) - Introduce CLI commands to troubleshoot connectivity issues to the etcd kvstore and clustermesh control plane (Backport PR [#32571](https://togithub.com/cilium/cilium/issues/32571), Upstream PR [#32336](https://togithub.com/cilium/cilium/issues/32336), [@giorio94](https://togithub.com/giorio94)) - ipsec: Improve CPU usage of cilum-agent in large clusters (Backport PR [#32883](https://togithub.com/cilium/cilium/issues/32883), Upstream PR [#32588](https://togithub.com/cilium/cilium/issues/32588), [@marseel](https://togithub.com/marseel)) - pkg/labels: print all leaf CIDRs, not just the last one. (Backport PR [#32511](https://togithub.com/cilium/cilium/issues/32511), Upstream PR [#28224](https://togithub.com/cilium/cilium/issues/28224), [@squeed](https://togithub.com/squeed)) **Bugfixes:** - .github/workflows: fix digests file creation (Backport PR [#32888](https://togithub.com/cilium/cilium/issues/32888), Upstream PR [#32860](https://togithub.com/cilium/cilium/issues/32860), [@aanm](https://togithub.com/aanm)) - \[v1.14] iptables: Do not install NOTRACK rules if IPv4NativeRoutingCIDR is nil ([#32650](https://togithub.com/cilium/cilium/issues/32650), [@pippolo84](https://togithub.com/pippolo84)) - cni: Reserve local ports for DNS proxy even if IPv6 is disabled (Backport PR [#32787](https://togithub.com/cilium/cilium/issues/32787), Upstream PR [#32725](https://togithub.com/cilium/cilium/issues/32725), [@gandro](https://togithub.com/gandro)) - Fix PromQL query in Cilium Metrics dashboard (Backport PR [#32695](https://togithub.com/cilium/cilium/issues/32695), Upstream PR [#32017](https://togithub.com/cilium/cilium/issues/32017), [@mikemykhaylov](https://togithub.com/mikemykhaylov)) - Fix rare race condition afflicting clustermesh when disconnecting from a remote cluster, possibly causing the agent to panic (Backport PR [#32695](https://togithub.com/cilium/cilium/issues/32695), Upstream PR [#32513](https://togithub.com/cilium/cilium/issues/32513), [@giorio94](https://togithub.com/giorio94)) - Fix: Ensure enabling metrics turns on identity GC metrics ([#32447](https://togithub.com/cilium/cilium/issues/32447), [@jaredledvina](https://togithub.com/jaredledvina)) - Fixes accidentally ignoring the preflight.nodeSelector Helm value. (Backport PR [#32695](https://togithub.com/cilium/cilium/issues/32695), Upstream PR [#32548](https://togithub.com/cilium/cilium/issues/32548), [@squeed](https://togithub.com/squeed)) - ipsec: Safely delete Xfrm state (Backport PR [#32704](https://togithub.com/cilium/cilium/issues/32704), Upstream PR [#32450](https://togithub.com/cilium/cilium/issues/32450), [@jschwinger233](https://togithub.com/jschwinger233)) - proxy: Re-enable proxy rule installation in native-routing mode for CEC (Backport PR [#32483](https://togithub.com/cilium/cilium/issues/32483), Upstream PR [#32367](https://togithub.com/cilium/cilium/issues/32367), [@sayboras](https://togithub.com/sayboras)) - Remove deprecated `hubble.ui.securityContext.enabled` from hubble-ui deployment template (Backport PR [#32888](https://togithub.com/cilium/cilium/issues/32888), Upstream PR [#32338](https://togithub.com/cilium/cilium/issues/32338), [@stelucz](https://togithub.com/stelucz)) **CI Changes:** - ci: Filter supported versions of EKS (Backport PR [#32888](https://togithub.com/cilium/cilium/issues/32888), Upstream PR [#32304](https://togithub.com/cilium/cilium/issues/32304), [@marseel](https://togithub.com/marseel)) - ci: Filter supported versions of GKE (Backport PR [#32695](https://togithub.com/cilium/cilium/issues/32695), Upstream PR [#32302](https://togithub.com/cilium/cilium/issues/32302), [@marseel](https://togithub.com/marseel)) - ci: l4lb: Don't hang on gathering logs forever (Backport PR [#32968](https://togithub.com/cilium/cilium/issues/32968), Upstream PR [#32947](https://togithub.com/cilium/cilium/issues/32947), [@joestringer](https://togithub.com/joestringer)) - ci: l4lb: gather more infos about docker-in-docker issues (Backport PR [#32695](https://togithub.com/cilium/cilium/issues/32695), Upstream PR [#32570](https://togithub.com/cilium/cilium/issues/32570), [@mhofstetter](https://togithub.com/mhofstetter)) - ci: l4lb: restart docker-in-docker container on failure (Backport PR [#32695](https://togithub.com/cilium/cilium/issues/32695), Upstream PR [#32600](https://togithub.com/cilium/cilium/issues/32600), [@mhofstetter](https://togithub.com/mhofstetter)) - eks: Don't use spot instances (Backport PR [#32695](https://togithub.com/cilium/cilium/issues/32695), Upstream PR [#32553](https://togithub.com/cilium/cilium/issues/32553), [@michi-covalent](https://togithub.com/michi-covalent)) - GCP OIDC instead of SA creds. (Backport PR [#32708](https://togithub.com/cilium/cilium/issues/32708), Upstream PR [#30809](https://togithub.com/cilium/cilium/issues/30809), [@viktor-kurchenko](https://togithub.com/viktor-kurchenko)) - gha: test certificate generation methods in conformance clustermesh (Backport PR [#32787](https://togithub.com/cilium/cilium/issues/32787), Upstream PR [#32654](https://togithub.com/cilium/cilium/issues/32654), [@giorio94](https://togithub.com/giorio94)) - Modify GitHub Actions Workflows to echo the inputs they are given when triggered by a `workflow_dispatch` event. (Backport PR [#32503](https://togithub.com/cilium/cilium/issues/32503), Upstream PR [#31424](https://togithub.com/cilium/cilium/issues/31424), [@learnitall](https://togithub.com/learnitall)) - Use GH_RUNNER_EXTRA_POWER for CI image workflow (Backport PR [#32503](https://togithub.com/cilium/cilium/issues/32503), Upstream PR [#32402](https://togithub.com/cilium/cilium/issues/32402), [@michi-covalent](https://togithub.com/michi-covalent)) - workflows: ignore "No egress gateway found" drops (Backport PR [#32695](https://togithub.com/cilium/cilium/issues/32695), Upstream PR [#32564](https://togithub.com/cilium/cilium/issues/32564), [@jibi](https://togithub.com/jibi)) - workflows: Remove stale CodeQL workflow (Backport PR [#32695](https://togithub.com/cilium/cilium/issues/32695), Upstream PR [#32084](https://togithub.com/cilium/cilium/issues/32084), [@pchaigno](https://togithub.com/pchaigno)) **Misc Changes:** - (v1.14) Bump golang.org/x/net ([#32792](https://togithub.com/cilium/cilium/issues/32792), [@ferozsalam](https://togithub.com/ferozsalam)) - background-sync: fix bootstrap issue and edge-case with 1 node (Backport PR [#32874](https://togithub.com/cilium/cilium/issues/32874), Upstream PR [#32630](https://togithub.com/cilium/cilium/issues/32630), [@marseel](https://togithub.com/marseel)) - bump cni plugins to v1.5.0 (Backport PR [#32695](https://togithub.com/cilium/cilium/issues/32695), Upstream PR [#32629](https://togithub.com/cilium/cilium/issues/32629), [@antonipp](https://togithub.com/antonipp)) - Bump timeout of lint-build-commits.yaml (Backport PR [#32787](https://togithub.com/cilium/cilium/issues/32787), Upstream PR [#32746](https://togithub.com/cilium/cilium/issues/32746), [@YutaroHayakawa](https://togithub.com/YutaroHayakawa)) - chore(deps): update all github action dependencies (v1.14) ([#32495](https://togithub.com/cilium/cilium/issues/32495), [@renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update all github action dependencies (v1.14) ([#32637](https://togithub.com/cilium/cilium/issues/32637), [@renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update all github action dependencies (v1.14) ([#32720](https://togithub.com/cilium/cilium/issues/32720), [@renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update all github action dependencies (v1.14) ([#32741](https://togithub.com/cilium/cilium/issues/32741), [@renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update all github action dependencies (v1.14) ([#32842](https://togithub.com/cilium/cilium/issues/32842), [@renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update all github action dependencies (v1.14) ([#32925](https://togithub.com/cilium/cilium/issues/32925), [@renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update all github action dependencies (v1.14) (patch) ([#32638](https://togithub.com/cilium/cilium/issues/32638), [@renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update cilium/cilium-cli action to v0.16.7 (v1.14) ([#32496](https://togithub.com/cilium/cilium/issues/32496), [@renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update cilium/little-vm-helper action to v0.0.18 (v1.14) ([#32581](https://togithub.com/cilium/cilium/issues/32581), [@renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update dependency cilium/cilium-cli to v0.16.9 (v1.14) ([#32836](https://togithub.com/cilium/cilium/issues/32836), [@renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update dependency cilium/hubble to v0.13.5 (v1.14) ([#32949](https://togithub.com/cilium/cilium/issues/32949), [@cilium-renovate](https://togithub.com/cilium-renovate)\[bot]) - chore(deps): update docker.io/library/golang:1.21.10 docker digest to [`16438a8`](https://togithub.com/cilium/cilium/commit/16438a8) (v1.14) ([#32636](https://togithub.com/cilium/cilium/issues/32636), [@renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update docker.io/library/ubuntu:22.04 docker digest to [`19478ce`](https://togithub.com/cilium/cilium/commit/19478ce) (v1.14) ([#32924](https://togithub.com/cilium/cilium/issues/32924), [@renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update docker.io/library/ubuntu:22.04 docker digest to [`a6d2b38`](https://togithub.com/cilium/cilium/commit/a6d2b38) (v1.14) ([#32369](https://togithub.com/cilium/cilium/issues/32369), [@renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update github/codeql-action action to v3.25.5 (v1.14) ([#32510](https://togithub.com/cilium/cilium/issues/32510), [@renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update go to v1.21.11 (v1.14) ([#32895](https://togithub.com/cilium/cilium/issues/32895), [@renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update hubble cli to v0.13.4 (v1.14) ([#32722](https://togithub.com/cilium/cilium/issues/32722), [@renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update stable lvh-images (v1.14) (patch) ([#32723](https://togithub.com/cilium/cilium/issues/32723), [@renovate](https://togithub.com/renovate)\[bot]) - contrib: Remove CHARTS_PATH dependency (Backport PR [#32695](https://togithub.com/cilium/cilium/issues/32695), Upstream PR [#32328](https://togithub.com/cilium/cilium/issues/32328), [@joestringer](https://togithub.com/joestringer)) - Docs: add note about AKS kube-apiserver entity (Backport PR [#32695](https://togithub.com/cilium/cilium/issues/32695), Upstream PR [#32464](https://togithub.com/cilium/cilium/issues/32464), [@darox](https://togithub.com/darox)) - docs: ipsec: remove limitation for native-routing with L7 egress policy (Backport PR [#32956](https://togithub.com/cilium/cilium/issues/32956), Upstream PR [#32906](https://togithub.com/cilium/cilium/issues/32906), [@julianwiedmann](https://togithub.com/julianwiedmann)) - Miscellaneous improvements to the clustermesh troubleshooting guide (Backport PR [#32571](https://togithub.com/cilium/cilium/issues/32571), Upstream PR [#32552](https://togithub.com/cilium/cilium/issues/32552), [@giorio94](https://togithub.com/giorio94)) - Remove release scripts (Backport PR [#32968](https://togithub.com/cilium/cilium/issues/32968), Upstream PR [#32938](https://togithub.com/cilium/cilium/issues/32938), [@aanm](https://togithub.com/aanm)) **Other Changes:** - \[1.14-backport] ipsec: Fix unencrypted traffic when IPsec is used with L7 egress proxy ([#31976](https://togithub.com/cilium/cilium/issues/31976), [@jschwinger233](https://togithub.com/jschwinger233)) - \[v1.14] bugtool: Avoid sensitive data in envoy config dump ([#32965](https://togithub.com/cilium/cilium/issues/32965), [@sayboras](https://togithub.com/sayboras)) - \[v1.14] envoy: Bump envoy version to v1.28.4 ([#32910](https://togithub.com/cilium/cilium/issues/32910), [@sayboras](https://togithub.com/sayboras)) - envoy: Update envoy 1.27.x to 1.28.3 ([#32482](https://togithub.com/cilium/cilium/issues/32482), [@sayboras](https://togithub.com/sayboras)) - install: Update image digests for v1.14.11 ([#32545](https://togithub.com/cilium/cilium/issues/32545), [@nebril](https://togithub.com/nebril)) #### v1.14.12 #### Docker Manifests ##### cilium `docker.io/cilium/cilium:v1.14.12@sha256:9c9612ed763a9ff823aca5e56aff6bb1e8ca36516282ed7f5c1b8866d011752c` `quay.io/cilium/cilium:v1.14.12@sha256:9c9612ed763a9ff823aca5e56aff6bb1e8ca36516282ed7f5c1b8866d011752c` ##### clustermesh-apiserver `docker.io/cilium/clustermesh-apiserver:v1.14.12@sha256:39e4ddad59cc3a4c05e7f44333fcbc8e1e64ee5eed8b9614916ed9673bb10a92` `quay.io/cilium/clustermesh-apiserver:v1.14.12@sha256:39e4ddad59cc3a4c05e7f44333fcbc8e1e64ee5eed8b9614916ed9673bb10a92` ##### docker-plugin `docker.io/cilium/docker-plugin:v1.14.12@sha256:7f358167a6c57fab052c524ee9b638784f90f904631423c7cf51f8fe301e1107` `quay.io/cilium/docker-plugin:v1.14.12@sha256:7f358167a6c57fab052c524ee9b638784f90f904631423c7cf51f8fe301e1107` ##### hubble-relay `docker.io/cilium/hubble-relay:v1.14.12@sha256:63749d9af901846b8a9229e01210afce2f9b1769419deaf55571dd16b7864574` `quay.io/cilium/hubble-relay:v1.14.12@sha256:63749d9af901846b8a9229e01210afce2f9b1769419deaf55571dd16b7864574` ##### kvstoremesh `docker.io/cilium/kvstoremesh:v1.14.12@sha256:c46f1939edd78d38f537e52b12ea051bafc591611b75e197bebb1e508764b565` `quay.io/cilium/kvstoremesh:v1.14.12@sha256:c46f1939edd78d38f537e52b12ea051bafc591611b75e197bebb1e508764b565` ##### operator-alibabacloud `docker.io/cilium/operator-alibabacloud:v1.14.12@sha256:e01302d3c00ce5b8e29703d4fdafefb0e9f4e65d1849a5551e0ad4d45a7af42c` `quay.io/cilium/operator-alibabacloud:v1.14.12@sha256:e01302d3c00ce5b8e29703d4fdafefb0e9f4e65d1849a5551e0ad4d45a7af42c` ##### operator-aws `docker.io/cilium/operator-aws:v1.14.12@sha256:a922c610fbc6e3e8bfda1876c6b2644f605b0cdec78f49854b9ce02213dc0abe` `quay.io/cilium/operator-aws:v1.14.12@sha256:a922c610fbc6e3e8bfda1876c6b2644f605b0cdec78f49854b9ce02213dc0abe` ##### operator-azure `docker.io/cilium/operator-azure:v1.14.12@sha256:416a39117ab7d261aacafc6e70e58bb0979c81c3c9d5cc4769f626de3f8015dd` `quay.io/cilium/operator-azure:v1.14.12@sha256:416a39117ab7d261aacafc6e70e58bb0979c81c3c9d5cc4769f626de3f8015dd` ##### operator-generic `docker.io/cilium/operator-generic:v1.14.12@sha256:0dd45f29aadeca7b9ef9f42991130ca135e54801c65416bd727add19e4727ba6` `quay.io/cilium/operator-generic:v1.14.12@sha256:0dd45f29aadeca7b9ef9f42991130ca135e54801c65416bd727add19e4727ba6` ##### operator `docker.io/cilium/operator:v1.14.12@sha256:5e1552ebb3e95655ec301637b2a9f90669e214d0d2f4c5397e867f4ae36bf262` `quay.io/cilium/operator:v1.14.12@sha256:5e1552ebb3e95655ec301637b2a9f90669e214d0d2f4c5397e867f4ae36bf262` ### [`v1.14.11`](https://togithub.com/cilium/cilium/releases/tag/v1.14.11): 1.14.11 [Compare Source](https://togithub.com/cilium/cilium/compare/1.14.10...1.14.11) We are pleased to release Cilium v1.14.11. This release brings us reducing pressure on the BPF connection tracking and NAT maps, as well as fixes for failing service connections, HostFirewall policy updates and many more. ## Security Advisories This release addresses following security vulnerabilities: - https://github.com/envoyproxy/envoy/security/advisories/GHSA-3mh5-6q8v-25wj - https://github.com/advisories/GHSA-5fq7-4mxc-535h ## Summary of Changes **Minor Changes:** - envoy: Bump go version to 1.21.10 ([#32414](https://togithub.com/cilium/cilium/issues/32414), [@sayboras](https://togithub.com/sayboras)) - Skip overlay traffic in the BPF SNAT processing, and thus reduce pressure on the BPF Connection tracking and NAT maps. (Backport PR [#31797](https://togithub.com/cilium/cilium/issues/31797), Upstream PR [#31082](https://togithub.com/cilium/cilium/issues/31082), [@julianwiedmann](https://togithub.com/julianwiedmann)) **Bugfixes:** - Agent: add kubeconfigPath to initContainers (Backport PR [#32251](https://togithub.com/cilium/cilium/issues/32251), Upstream PR [#32008](https://togithub.com/cilium/cilium/issues/32008), [@darox](https://togithub.com/darox)) - cilium-cni: Reserve ports that can conflict with transparent DNS proxy (Backport PR [#32419](https://togithub.com/cilium/cilium/issues/32419), Upstream PR [#32128](https://togithub.com/cilium/cilium/issues/32128), [@gandro](https://togithub.com/gandro)) - cni: Use correct route MTU when ENI, Azure or Alibaba Cloud IPAM is enabled (Backport PR [#32385](https://togithub.com/cilium/cilium/issues/32385), Upstream PR [#32244](https://togithub.com/cilium/cilium/issues/32244), [@learnitall](https://togithub.com/learnitall)) - dnsproxy: Fix bug where DNS request timed out too soon (Backport PR [#32251](https://togithub.com/cilium/cilium/issues/32251), Upstream PR [#31999](https://togithub.com/cilium/cilium/issues/31999), [@gandro](https://togithub.com/gandro)) - Envoy upstream connections are now unique for each downstream connection when using the original source address of a source pod. (Backport PR [#32314](https://togithub.com/cilium/cilium/issues/32314), Upstream PR [#32270](https://togithub.com/cilium/cilium/issues/32270), [@jrajahalme](https://togithub.com/jrajahalme)) - envoy: pass idle timeout configuration option to cilium configmap (Backport PR [#32251](https://togithub.com/cilium/cilium/issues/32251), Upstream PR [#32203](https://togithub.com/cilium/cilium/issues/32203), [@mhofstetter](https://togithub.com/mhofstetter)) - Fix failing service connections, when the service requests are transported via cilium's overlay network. (Backport PR [#31797](https://togithub.com/cilium/cilium/issues/31797), Upstream PR [#32116](https://togithub.com/cilium/cilium/issues/32116), [@julianwiedmann](https://togithub.com/julianwiedmann)) - Fixes a bug where Cilium in chained mode removed the `agent-not-ready` taint too early if the primary network is slow in deploying. (Backport PR [#32251](https://togithub.com/cilium/cilium/issues/32251), Upstream PR [#32168](https://togithub.com/cilium/cilium/issues/32168), [@squeed](https://togithub.com/squeed)) - Fixes an (unlikely) bug where HostFirewall policies may miss updates to a node's labels. (Backport PR [#32385](https://togithub.com/cilium/cilium/issues/32385), Upstream PR [#30548](https://togithub.com/cilium/cilium/issues/30548), [@squeed](https://togithub.com/squeed)) - fqdn: fix memory leak in transparent mode when there was a moderately high number of parallel DNS requests (>100). (Backport PR [#32104](https://togithub.com/cilium/cilium/issues/32104), Upstream PR [#31959](https://togithub.com/cilium/cilium/issues/31959), [@marseel](https://togithub.com/marseel)) - ipam: retry netlink.LinkList call when setting up ENI devices (Backport PR [#32251](https://togithub.com/cilium/cilium/issues/32251), Upstream PR [#32099](https://togithub.com/cilium/cilium/issues/32099), [@jasonaliyetti](https://togithub.com/jasonaliyetti)) - operator: fix errors/warnings metric. (Backport PR [#31907](https://togithub.com/cilium/cilium/issues/31907), Upstream PR [#31214](https://togithub.com/cilium/cilium/issues/31214), [@tommyp1ckles](https://togithub.com/tommyp1ckles)) **CI Changes:** - alibabacloud/eni: avoid racing node mgr in test (Backport PR [#31987](https://togithub.com/cilium/cilium/issues/31987), Upstream PR [#31877](https://togithub.com/cilium/cilium/issues/31877), [@bimmlerd](https://togithub.com/bimmlerd)) - ci: Filter supported versions of AKS (Backport PR [#32385](https://togithub.com/cilium/cilium/issues/32385), Upstream PR [#32303](https://togithub.com/cilium/cilium/issues/32303), [@marseel](https://togithub.com/marseel)) - ci: Increase timeout for images for l4lb test (Backport PR [#32251](https://togithub.com/cilium/cilium/issues/32251), Upstream PR [#32201](https://togithub.com/cilium/cilium/issues/32201), [@marseel](https://togithub.com/marseel)) - gha: configure fully-qualified DNS names as external targets (Backport PR [#32104](https://togithub.com/cilium/cilium/issues/32104), Upstream PR [#31510](https://togithub.com/cilium/cilium/issues/31510), [@giorio94](https://togithub.com/giorio94)) - gha: drop double installation of Cilium CLI in conformance-eks (Backport PR [#32104](https://togithub.com/cilium/cilium/issues/32104), Upstream PR [#32042](https://togithub.com/cilium/cilium/issues/32042), [@giorio94](https://togithub.com/giorio94)) - Miscellaneous improvements to the clustermesh upgrade/downgrade test (Backport PR [#32104](https://togithub.com/cilium/cilium/issues/32104), Upstream PR [#31958](https://togithub.com/cilium/cilium/issues/31958), [@giorio94](https://togithub.com/giorio94)) - test: De-flake xds server_e2e_test (Backport PR [#32104](https://togithub.com/cilium/cilium/issues/32104), Upstream PR [#32004](https://togithub.com/cilium/cilium/issues/32004), [@jrajahalme](https://togithub.com/jrajahalme)) - workflows: Fix CI jobs for push events on private forks (Backport PR [#32251](https://togithub.com/cilium/cilium/issues/32251), Upstream PR [#32085](https://togithub.com/cilium/cilium/issues/32085), [@pchaigno](https://togithub.com/pchaigno)) **Misc Changes:** - bpf: host: restore HostFW for overlay traffic in to-netdev (Backport PR [#31797](https://togithub.com/cilium/cilium/issues/31797), Upstream PR [#31818](https://togithub.com/cilium/cilium/issues/31818), [@julianwiedmann](https://togithub.com/julianwiedmann)) - bpf: tests: don't define HAVE_ENCAP in IPsec tests (Backport PR [#31797](https://togithub.com/cilium/cilium/issues/31797), Upstream PR [#31737](https://togithub.com/cilium/cilium/issues/31737), [@julianwiedmann](https://togithub.com/julianwiedmann)) - build(deps): bump pydantic from 2.3.0 to 2.4.0 in /Documentation (Backport PR [#32251](https://togithub.com/cilium/cilium/issues/32251), Upstream PR [#32176](https://togithub.com/cilium/cilium/issues/32176), [@dependabot](https://togithub.com/dependabot)\[bot]) - chore(deps): update all github action dependencies (v1.14) ([#31997](https://togithub.com/cilium/cilium/issues/31997), [@renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update all github action dependencies (v1.14) ([#32109](https://togithub.com/cilium/cilium/issues/32109), [@renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update all github action dependencies (v1.14) ([#32373](https://togithub.com/cilium/cilium/issues/32373), [@renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update all-dependencies (v1.14) ([#31996](https://togithub.com/cilium/cilium/issues/31996), [@renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update cilium/cilium-cli action to v0.16.4 (v1.14) ([#32110](https://togithub.com/cilium/cilium/issues/32110), [@renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update dependency cilium/cilium-cli to v0.16.6 (v1.14) ([#32370](https://togithub.com/cilium/cilium/issues/32370), [@renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update docker.io/library/golang:1.21.9 docker digest to [`81811f8`](https://togithub.com/cilium/cilium/commit/81811f8) (v1.14) ([#31995](https://togithub.com/cilium/cilium/issues/31995), [@renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update go to v1.21.10 (v1.14) ([#32368](https://togithub.com/cilium/cilium/issues/32368), [@renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update golangci/golangci-lint-action action to v6 (v1.14) ([#32397](https://togithub.com/cilium/cilium/issues/32397), [@renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update hubble cli to v0.13.3 (v1.14) ([#32111](https://togithub.com/cilium/cilium/issues/32111), [@renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update stable lvh-images (v1.14) (patch) ([#31823](https://togithub.com/cilium/cilium/issues/31823), [@renovate](https://togithub.com/renovate)\[bot]) - CI: bump default FQDN datapath timeout from 100 to 250ms (Backport PR [#32251](https://togithub.com/cilium/cilium/issues/32251), Upstream PR [#31866](https://togithub.com/cilium/cilium/issues/31866), [@squeed](https://togithub.com/squeed)) - docs: Add annotation for Ingress endpoint (Backport PR [#32385](https://togithub.com/cilium/cilium/issues/32385), Upstream PR [#32284](https://togithub.com/cilium/cilium/issues/32284), [@sayboras](https://togithub.com/sayboras)) - docs: Fix prometheus port regex (Backport PR [#32251](https://togithub.com/cilium/cilium/issues/32251), Upstream PR [#32030](https://togithub.com/cilium/cilium/issues/32030), [@JBodkin-Amphora](https://togithub.com/JBodkin-Amphora)) - Docs: mark Tetragon as Stable (Backport PR [#31987](https://togithub.com/cilium/cilium/issues/31987), Upstream PR [#31886](https://togithub.com/cilium/cilium/issues/31886), [@sharlns](https://togithub.com/sharlns)) - Document Cluster Mesh global services limitations when KPR=false (Backport PR [#31987](https://togithub.com/cilium/cilium/issues/31987), Upstream PR [#31798](https://togithub.com/cilium/cilium/issues/31798), [@giorio94](https://togithub.com/giorio94)) - endpoint: Skip build queue warning log is context is canceled (Backport PR [#32251](https://togithub.com/cilium/cilium/issues/32251), Upstream PR [#32132](https://togithub.com/cilium/cilium/issues/32132), [@jrajahalme](https://togithub.com/jrajahalme)) - fqdn: Change error log to warning (Backport PR [#32385](https://togithub.com/cilium/cilium/issues/32385), Upstream PR [#32333](https://togithub.com/cilium/cilium/issues/32333), [@jrajahalme](https://togithub.com/jrajahalme)) - fqdn: Fix Upgrade Issue Between PortProto Versions (Backport PR [#32385](https://togithub.com/cilium/cilium/issues/32385), Upstream PR [#32325](https://togithub.com/cilium/cilium/issues/32325), [@nathanjsweet](https://togithub.com/nathanjsweet)) - golangci: Enable errorlint (Backport PR [#31793](https://togithub.com/cilium/cilium/issues/31793), Upstream PR [#31458](https://togithub.com/cilium/cilium/issues/31458), [@jrajahalme](https://togithub.com/jrajahalme)) - Improve release organization page (Backport PR [#31987](https://togithub.com/cilium/cilium/issues/31987), Upstream PR [#31970](https://togithub.com/cilium/cilium/issues/31970), [@joestringer](https://togithub.com/joestringer)) - install/kubernetes: update nodeinit image to latest version (Backport PR [#32251](https://togithub.com/cilium/cilium/issues/32251), Upstream PR [#32181](https://togithub.com/cilium/cilium/issues/32181), [@tklauser](https://togithub.com/tklauser)) - ipsec: Debug info for transient IPsec upgrade drops (Backport PR [#32385](https://togithub.com/cilium/cilium/issues/32385), Upstream PR [#32240](https://togithub.com/cilium/cilium/issues/32240), [@pchaigno](https://togithub.com/pchaigno)) - l7 policy: add possibility to configure Envoy proxy xff-num-trusted-hops (Backport PR [#32265](https://togithub.com/cilium/cilium/issues/32265), Upstream PR [#32200](https://togithub.com/cilium/cilium/issues/32200), [@mhofstetter](https://togithub.com/mhofstetter)) - Remove aks-preview from AKS workflows (Backport PR [#32251](https://togithub.com/cilium/cilium/issues/32251), Upstream PR [#32118](https://togithub.com/cilium/cilium/issues/32118), [@marseel](https://togithub.com/marseel)) - Remove cilium/build from codeowners ([#32146](https://togithub.com/cilium/cilium/issues/32146), [@joestringer](https://togithub.com/joestringer)) **Other Changes:** - \[1.14] images: update cilium-{runtime,builder} ([#32443](https://togithub.com/cilium/cilium/issues/32443), [@nebril](https://togithub.com/nebril)) - \[1.14] operator: propagate CiliumClusterConfig when in kvstore mode ([#32349](https://togithub.com/cilium/cilium/issues/32349), [@hemanthmalla](https://togithub.com/hemanthmalla)) - \[v1.14-backport] Introduce fromEgressProxyRule ([#31926](https://togithub.com/cilium/cilium/issues/31926), [@jschwinger233](https://togithub.com/jschwinger233)) - ci: no longer suppported v1.25 in GKE ([#32183](https://togithub.com/cilium/cilium/issues/32183), [@marseel](https://togithub.com/marseel)) - envoy: Bump envoy version to v1.27.5 ([#32078](https://togithub.com/cilium/cilium/issues/32078), [@sayboras](https://togithub.com/sayboras)) - fix k8s versions tested in CI ([#31969](https://togithub.com/cilium/cilium/issues/31969), [@nbusseneau](https://togithub.com/nbusseneau)) - install: Update image digests for v1.14.10 ([#31914](https://togithub.com/cilium/cilium/issues/31914), [@asauber](https://togithub.com/asauber)) ### [`v1.14.10`](https://togithub.com/cilium/cilium/releases/tag/v1.14.10): 1.14.10 [Compare Source](https://togithub.com/cilium/cilium/compare/1.14.9...1.14.10) We are pleased to announce the release of Cilium v1.14.10. This release includes hubble metrics when using `cilium sysdump`, and a fix to an issue with overlapping keys that may have affected the ability to recover from a full Service map. Bugfixes include improved behavior for overlapping and restored DNS policies, a fix to a race condition in Service updates for L7 LB, and a fix to the retry logic in the cilium health controllers. ## Security Advisories This release addresses a security vulnerability. For more information, see [GHSA-j654-3ccm-vfmm](https://togithub.com/envoyproxy/envoy/security/advisories/GHSA-j654-3ccm-vfmm) ## Summary of Changes **Minor Changes:** - bugtool: Collect hubble metrics (Backport PR [#31888](https://togithub.com/cilium/cilium/issues/31888), Upstream PR [#31533](https://togithub.com/cilium/cilium/issues/31533), [@chancez](https://togithub.com/chancez)) - Fix overlapping keys in agent-side service BPF map cache used for retries. In rare cases this bug may have caused retrying of a failed BPF map update for a services entry to be skipped leading to a missing entry. This may have, for example, adversely affected recovering from a full BPF service map after excess services were removed. (Backport PR [#31888](https://togithub.com/cilium/cilium/issues/31888), Upstream PR [#29581](https://togithub.com/cilium/cilium/issues/29581), [@xyz-li](https://togithub.com/xyz-li)) - Update to Envoy 1.27.0, run cilium-envoy process without any privileges. (Backport PR [#31007](https://togithub.com/cilium/cilium/issues/31007), Upstream PR [#27498](https://togithub.com/cilium/cilium/issues/27498), [@jrajahalme](https://togithub.com/jrajahalme)) **Bugfixes:** - cilium-health: Fix broken retry loop in `cilium-health-ep` controller (Backport PR [#31724](https://togithub.com/cilium/cilium/issues/31724), Upstream PR [#31622](https://togithub.com/cilium/cilium/issues/31622), [@gandro](https://togithub.com/gandro)) - cni: Allow text-ts log format value (Backport PR [#31888](https://togithub.com/cilium/cilium/issues/31888), Upstream PR [#31686](https://togithub.com/cilium/cilium/issues/31686), [@sayboras](https://togithub.com/sayboras)) - fix: Delegated ipam not configure ipv6 if ipv6 disabled in agent (Backport PR [#31724](https://togithub.com/cilium/cilium/issues/31724), Upstream PR [#31104](https://togithub.com/cilium/cilium/issues/31104), [@tamilmani1989](https://togithub.com/tamilmani1989)) - Fixed a race condition in service updates for L7 LB. (Backport PR [#31861](https://togithub.com/cilium/cilium/issues/31861), Upstream PR [#31744](https://togithub.com/cilium/cilium/issues/31744), [@jrajahalme](https://togithub.com/jrajahalme)) - Fixed issue with assigning 0 nodeID when corresponding bpf map run out of space. Potentially it could have impacted connectivity in large clusters (>4k nodes) with IPSec or Mutual Auth enabled. Otherwise, it was merely generating unnecessary error log messages. (Backport PR [#31656](https://togithub.com/cilium/cilium/issues/31656), Upstream PR [#31380](https://togithub.com/cilium/cilium/issues/31380), [@marseel](https://togithub.com/marseel)) - fqdn: Fix minor restore bug that causes false negative checks against a restored DNS IP map. ([#31871](https://togithub.com/cilium/cilium/issues/31871), [@nathanjsweet](https://togithub.com/nathanjsweet)) - fqdn: Fixed bug that caused DNS Proxy to be overly restrictive on allowed DNS selectors. ([#31801](https://togithub.com/cilium/cilium/issues/31801), [@nathanjsweet](https://togithub.com/nathanjsweet)) - metric: Avoid memory leak/increase in cilium-agent (Backport PR [#31888](https://togithub.com/cilium/cilium/issues/31888), Upstream PR [#31714](https://togithub.com/cilium/cilium/issues/31714), [@sayboras](https://togithub.com/sayboras)) **CI Changes:** - ci-e2e: Add e2e test with WireGuard + Host Firewall (Backport PR [#31724](https://togithub.com/cilium/cilium/issues/31724), Upstream PR [#31594](https://togithub.com/cilium/cilium/issues/31594), [@qmonnet](https://togithub.com/qmonnet)) - ci-e2e: Enable Ingress Controller test for more setup (Backport PR [#31658](https://togithub.com/cilium/cilium/issues/31658), Upstream PR [#30657](https://togithub.com/cilium/cilium/issues/30657), [@sayboras](https://togithub.com/sayboras)) - ci-ipsec-e2e: Misc refactor + more keys (Backport PR [#31429](https://togithub.com/cilium/cilium/issues/31429), Upstream PR [#29592](https://togithub.com/cilium/cilium/issues/29592), [@brb](https://togithub.com/brb)) - ci/ipsec: Print more info to debug credentials removal check failures (Backport PR [#31724](https://togithub.com/cilium/cilium/issues/31724), Upstream PR [#31652](https://togithub.com/cilium/cilium/issues/31652), [@qmonnet](https://togithub.com/qmonnet)) - deflake endpointmanager tests (Backport PR [#31724](https://togithub.com/cilium/cilium/issues/31724), Upstream PR [#31488](https://togithub.com/cilium/cilium/issues/31488), [@bimmlerd](https://togithub.com/bimmlerd)) - gh/workflows: Add IPsec key rotation action and use it in ci-eks / ci-ipsec-e2e (Backport PR [#31429](https://togithub.com/cilium/cilium/issues/31429), Upstream PR [#29704](https://togithub.com/cilium/cilium/issues/29704), [@brb](https://togithub.com/brb)) - gha: Enable Ingress Controller tests in conformance-e2e (Backport PR [#31658](https://togithub.com/cilium/cilium/issues/31658), Upstream PR [#29130](https://togithub.com/cilium/cilium/issues/29130), [@sayboras](https://togithub.com/sayboras)) - workflows: Debug info for key rotations (Backport PR [#31724](https://togithub.com/cilium/cilium/issues/31724), Upstream PR [#31627](https://togithub.com/cilium/cilium/issues/31627), [@pchaigno](https://togithub.com/pchaigno)) **Misc Changes:** - bitlpm: Document and Fix Descendants Bug (Backport PR [#31888](https://togithub.com/cilium/cilium/issues/31888), Upstream PR [#31851](https://togithub.com/cilium/cilium/issues/31851), [@nathanjsweet](https://togithub.com/nathanjsweet)) - Bump go-jose to v3.0.3 (v1.14) ([#31881](https://togithub.com/cilium/cilium/issues/31881), [@ferozsalam](https://togithub.com/ferozsalam)) - chore(deps): update all github action dependencies (v1.14) ([#31824](https://togithub.com/cilium/cilium/issues/31824), [@renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update cilium/little-vm-helper action to v0.0.17 (v1.14) ([#31707](https://togithub.com/cilium/cilium/issues/31707), [@renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update dependency cilium/cilium-cli to v0.16.4 (v1.14) ([#31675](https://togithub.com/cilium/cilium/issues/31675), [@renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update gcr.io/distroless/static-debian11:nonroot docker digest to [`f41b84c`](https://togithub.com/cilium/cilium/commit/f41b84c) (v1.14) ([#31748](https://togithub.com/cilium/cilium/issues/31748), [@renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update go to v1.21.9 (v1.14) ([#31765](https://togithub.com/cilium/cilium/issues/31765), [@renovate](https://togithub.com/renovate)\[bot]) - chore(deps): update stable lvh-images (v1.14) (patch) ([#31708](https://togithub.com/cilium/cilium/issues/31708), [@renovate](https://togithub.com/renovate)\[bot]) - cilium-dbg: avoid leaking file resources (Backport PR [#31888](https://togithub.com/cilium/cilium/issues/31888), Upstream PR [#31750](https://togithub.com/cilium/cilium/issues/31750), [@tklauser](https://togithub.com/tklauser)) - docs: Document `No node ID found` drops in case of remote node deletion (Backport PR [#31724](https://togithub.com/cilium/cilium/issues/31724), Upstream PR [#31635](https://togithub.com/cilium/cilium/issues/31635), [@pchaigno](https://togithub.com/pchaigno)) - docs: ipsec: document native-routing + Egress proxy case (Backport PR [#31724](https://togithub.com/cilium/cilium/issues/31724), Upstream PR [#31478](https://togithub.com/cilium/cilium/issues/31478), [@julianwiedmann](https://togithub.com/julianwiedmann)) - Fix spelling in DNS-based proxy info (Backport PR [#31888](https://togithub.com/cilium/cilium/issues/31888), Upstream PR [#31728](https://togithub.com/cilium/cilium/issues/31728), [@saintdle](https://togithub.com/saintdle)) - helm: update nodeinit image using renovate (Backport PR [#31724](https://togithub.com/cilium/cilium/issues/31724), Upstream PR [#31641](https://togithub.com/cilium/cilium/issues/31641), [@tklauser](https://togithub.com/tklauser)) - Move governance docs to the Cilium community repo (Backport PR [#31888](https://togithub.com/cilium/cilium/issues/31888), Upstream PR [#31692](https://togithub.com/cilium/cilium/issues/31692), [@katiestruthers](https://togithub.com/katiestruthers)) - Remove Hubble-OTel from the roadmap (Backport PR [#31888](https://togithub.com/cilium/cilium/issues/31888), Upstream PR [#31847](https://togithub.com/cilium/cilium/issues/31847), [@xmulligan](https://togithub.com/xmulligan)) - Restructure OpenShift installation instructions to point to Red Hat Ecosystem Catalog (Backport PR [#31724](https://togithub.com/cilium/cilium/issues/31724), Upstream PR [#29300](https://togithub.com/cilium/cilium/issues/29300), [@learnitall](https://togithub.com/learnitall)) - Support for batch deletion of endpoints (Backport PR [#31585](https://togithub.com/cilium/cilium/issues/31585), Upstream PR [#27351](https://togithub.com/cilium/cilium/issues/27351), [@tklauser](https://togithub.com/tklauser)) - v1.14: update cilium/certgen to v0.1.11 ([#31883](https://togithub.com/cilium/cilium/issues/31883), [@rolinh](https://togithub.com/rolinh)) **Other Changes:** - \[v1.14] envoy: Bump envoy image for golang 1.21.9 ([#31771](https://togithub.com/cilium/cilium/issues/31771), [@sayboras](https://togithub.com/sayboras)) - \[v1.14] fix unsupported aws region ([#31742](https://togithub.com/cilium/cilium/issues/31742), [@brlbil](https://togithub.com/brlbil)) - \[v1.15] envoy: Bump golang version to 1.21.8 (Backport PR [#31007](https://togithub.com/cilium/cilium/issues/31007), Upstream PR [#31221](https://togithub.com/cilium/cilium/issues/31221), [@sayboras](https://togithub.com/sayboras)) - CI: Remove unsupported k8s version ([#31829](https://togithub.com/cilium/cilium/issues/31829), [@brlbil](https://togithub.com/brlbil)) - envoy: Bump envoy version to v1.27.4 ([#31808](https://togithub.com/cilium/cilium/issues/31808), [@sayboras](https://togithub.com/sayboras)) - install: Update image digests for v1.14.9 ([#31629](https://togithub.com/cilium/cilium/issues/31629), [@jrajahalme](https://togithub.com/jrajahalme)) #### Docker Manifests ##### cilium `docker.io/cilium/cilium:v1.14.10@sha256:0a1bcd2859c6d18d60dba6650cca8c707101716a3e47b126679040cbd621c031` `quay.io/cilium/cilium:v1.14.10@sha256:0a1bcd2859c6d18d60dba6650cca8c707101716a3e47b126679040cbd621c031` ##### clustermesh-apiserver `docker.io/cilium/clustermesh-apiserver:v1.14.10@sha256:609fea274caa016f15646f6e0b0f1f7c56b238c551e7b261bc1e99ce64f7b798` `quay.io/cilium/clustermesh-apiserver:v1.14.10@sha256:609fea274caa016f15646f6e0b0f1f7c56b238c551e7b261bc1e99ce64f7b798` ##### docker-plugin `docker.io/cilium/docker-plugin:v1.14.10@sha256:8aa57cb38a30dbe56345b5d549054beaea96a210c15a1e4ca5224b4f858cdcda` `quay.io/cilium/docker-plugin:v1.14.10@sha256:8aa57cb38a30dbe56345b5d549054beaea96a210c15a1e4ca5224b4f858cdcda` ##### hubble-relay `docker.io/cilium/hubble-relay:v1.14.10@sha256:c156c4fc2da520d2876142ea17490440b95431a1be755d2050e72115a495cfd0` `quay.io/cilium/hubble-relay:v1.14.10@sha256:c156c4fc2da520d2876142ea17490440b95431a1be755d2050e72115a495cfd0` ##### operator-alibabacloud `docker.io/cilium/operator-alibabacloud:v1.14.10@sha256:2fbb53c2fc9c7203db9065c4e6cedb8e98d32d5ebc64549949636b5344cd1f14` `quay.io/cilium/operator-alibabacloud:v1.14.10@sha256:2fbb53c2fc9c7203db9065c4e6cedb8e98d32d5ebc64549949636b5344cd1f14` ##### operator-aws `docker.io/cilium/operator-aws:v1.14.10@sha256:72440aa4cb8a42dddb05cfc74c6fba0a18d0902b1e434f5dcde8dca0354a8be6` `quay.io/cilium/operator-aws:v1.14.10@sha256:72440aa4cb8Configuration
š Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
š¦ Automerge: Enabled.
ā» Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
š Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.