Closed renovate[bot] closed 2 years ago
This PR contains the following updates:
1.11.6
1.12.2
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.
This PR contains the following updates:
1.11.6
->1.12.2
Release Notes
cilium/cilium
### [`v1.12.2`](https://togithub.com/cilium/cilium/releases/tag/v1.12.2) [Compare Source](https://togithub.com/cilium/cilium/compare/v1.12.1...v1.12.2) We are pleased to release Cilium v1.12.2. This release has some improvements around load balancing, quality of life improvements and many fixes for bugs found by our community. ## Summary of Changes **Minor Changes:** - Added `hubble.ui.frontend.server.ipv6.enabled` helm flag to control nginx server ipv6 listener (Backport PR [#21225](https://togithub.com/cilium/cilium/issues/21225), Upstream PR [#21127](https://togithub.com/cilium/cilium/issues/21127), [@geakstr](https://togithub.com/geakstr)) - dnsproxy: stop serving DNS traffic before agent shutdown (Backport PR [#21225](https://togithub.com/cilium/cilium/issues/21225), Upstream PR [#20795](https://togithub.com/cilium/cilium/issues/20795), [@nebril](https://togithub.com/nebril)) - ingress: Propagate required annotations from Ingress to LB Service (Backport PR [#21227](https://togithub.com/cilium/cilium/issues/21227), Upstream PR [#20860](https://togithub.com/cilium/cilium/issues/20860), [@NikhilSharmaWe](https://togithub.com/NikhilSharmaWe)) - ingress: Rename LB annotation to annotation prefixes (Backport PR [#21227](https://togithub.com/cilium/cilium/issues/21227), Upstream PR [#21222](https://togithub.com/cilium/cilium/issues/21222), [@sayboras](https://togithub.com/sayboras)) - install: add TerminationMessagePolicy to cilium pods (Backport PR [#21292](https://togithub.com/cilium/cilium/issues/21292), Upstream PR [#21012](https://togithub.com/cilium/cilium/issues/21012), [@squeed](https://togithub.com/squeed)) - put stderr of iptables command into error instead of merging into stdout (Backport PR [#21053](https://togithub.com/cilium/cilium/issues/21053), Upstream PR [#20895](https://togithub.com/cilium/cilium/issues/20895), [@liuyuan10](https://togithub.com/liuyuan10)) - Support configuring metricsRelabelings on ServiceMonitors (Backport PR [#21225](https://togithub.com/cilium/cilium/issues/21225), Upstream PR [#21051](https://togithub.com/cilium/cilium/issues/21051), [@chancez](https://togithub.com/chancez)) **Bugfixes:** - Cilium-envoy now sets option to allow (source) port reuse when binding to a source address of a pod for upstream connections. (Backport PR [#21292](https://togithub.com/cilium/cilium/issues/21292), Upstream PR [#20996](https://togithub.com/cilium/cilium/issues/20996), [@jrajahalme](https://togithub.com/jrajahalme)) - clustermesh-apiserver: fix key name for delete during k8s->kvstore sync (Backport PR [#21122](https://togithub.com/cilium/cilium/issues/21122), Upstream PR [#21078](https://togithub.com/cilium/cilium/issues/21078), [@tklauser](https://togithub.com/tklauser)) - datapath: allow local NodePort traffic for `eni+` container interfaces with CNI chaining (Backport PR [#21225](https://togithub.com/cilium/cilium/issues/21225), Upstream PR [#21126](https://togithub.com/cilium/cilium/issues/21126), [@ti-mo](https://togithub.com/ti-mo)) - Do not enable health checks if only Terminating backends are present on a Node which is selected by a Service with `externalTrafficPolicy: Local` Service (Backport PR [#21122](https://togithub.com/cilium/cilium/issues/21122), Upstream PR [#21062](https://togithub.com/cilium/cilium/issues/21062), [@zuzzas](https://togithub.com/zuzzas)) - Ensure that the DNS proxy picks a new port if the previously-used port is unavailable. (Backport PR [#21225](https://togithub.com/cilium/cilium/issues/21225), Upstream PR [#20896](https://togithub.com/cilium/cilium/issues/20896), [@NikhilSharmaWe](https://togithub.com/NikhilSharmaWe)) - Fix conflicting routes for multiple ENIs in IPAM mode (Backport PR [#21225](https://togithub.com/cilium/cilium/issues/21225), Upstream PR [#20112](https://togithub.com/cilium/cilium/issues/20112), [@recollir](https://togithub.com/recollir)) - Fix identity garbage collection in clustermesh environments ([#20932](https://togithub.com/cilium/cilium/issues/20932), [@aanm](https://togithub.com/aanm)) - Fix node label synchronization in the KVStore when IPSec configuration changes (Backport PR [#21122](https://togithub.com/cilium/cilium/issues/21122), Upstream PR [#21087](https://togithub.com/cilium/cilium/issues/21087), [@aanm](https://togithub.com/aanm)) - Fix panic during Cilium initialization when a NetworkPolicy with a named-port selected an pod running on that node. (Backport PR [#21053](https://togithub.com/cilium/cilium/issues/21053), Upstream PR [#20911](https://togithub.com/cilium/cilium/issues/20911), [@aanm](https://togithub.com/aanm)) - Fix Wireguard connectivity issues when using kvstore mode (Backport PR [#21225](https://togithub.com/cilium/cilium/issues/21225), Upstream PR [#21080](https://togithub.com/cilium/cilium/issues/21080), [@aanm](https://togithub.com/aanm)) - Fixes typos in enabling fqdn_semaphore_rejected_total metric (Backport PR [#20940](https://togithub.com/cilium/cilium/issues/20940), Upstream PR [#20893](https://togithub.com/cilium/cilium/issues/20893), [@rahulkjoshi](https://togithub.com/rahulkjoshi)) - For configurations with Egress Gateway and Direct-Routing, avoid recreating the cilium_vxlan interface on every restart. (Backport PR [#21122](https://togithub.com/cilium/cilium/issues/21122), Upstream PR [#20780](https://togithub.com/cilium/cilium/issues/20780), [@julianwiedmann](https://togithub.com/julianwiedmann)) - helm: Add check for apparmor annotations (Backport PR [#21122](https://togithub.com/cilium/cilium/issues/21122), Upstream PR [#21008](https://togithub.com/cilium/cilium/issues/21008), [@sayboras](https://togithub.com/sayboras)) - ipsec: Fix incorrect parsing of SPI from mark (Backport PR [#20940](https://togithub.com/cilium/cilium/issues/20940), Upstream PR [#20900](https://togithub.com/cilium/cilium/issues/20900), [@pchaigno](https://togithub.com/pchaigno)) - k8s/watchers: fix panic in CiliumEndpoint labels update (Backport PR [#21053](https://togithub.com/cilium/cilium/issues/21053), Upstream PR [#20865](https://togithub.com/cilium/cilium/issues/20865), [@jaffcheng](https://togithub.com/jaffcheng)) - kvstore/allocator: fix panic on receiving invalid identity entries (Backport PR [#21292](https://togithub.com/cilium/cilium/issues/21292), Upstream PR [#21213](https://togithub.com/cilium/cilium/issues/21213), [@ArthurChiao](https://togithub.com/ArthurChiao)) - metrics: fix ts_events API timestamp only emitting zero and unbounded scope label cardinality issue. (Backport PR [#21053](https://togithub.com/cilium/cilium/issues/21053), Upstream PR [#20977](https://togithub.com/cilium/cilium/issues/20977), [@tommyp1ckles](https://togithub.com/tommyp1ckles)) - operator: do not GC kvstore nodes if CiliumNodes are not available (Backport PR [#21225](https://togithub.com/cilium/cilium/issues/21225), Upstream PR [#21133](https://togithub.com/cilium/cilium/issues/21133), [@aanm](https://togithub.com/aanm)) - operator: update CiliumNode in kvstore without lease (Backport PR [#21225](https://togithub.com/cilium/cilium/issues/21225), Upstream PR [#21202](https://togithub.com/cilium/cilium/issues/21202), [@tklauser](https://togithub.com/tklauser)) - pkg/k8s/watcher: fix deadlock crash that occurs when handling endpoint and service updates. (Backport PR [#21225](https://togithub.com/cilium/cilium/issues/21225), Upstream PR [#21093](https://togithub.com/cilium/cilium/issues/21093), [@tommyp1ckles](https://togithub.com/tommyp1ckles)) - v1.12: operator: fix key name for delete during k8s->kvstore sync ([#20984](https://togithub.com/cilium/cilium/issues/20984), [@tklauser](https://togithub.com/tklauser)) - When systemd-sysctl sets the rp_filter sysctl, tolerate missing lxc_\* / cilium_\* interfaces. (Backport PR [#21225](https://togithub.com/cilium/cilium/issues/21225), Upstream PR [#21146](https://togithub.com/cilium/cilium/issues/21146), [@julianwiedmann](https://togithub.com/julianwiedmann)) **CI Changes:** - \[v1.12] vagrant: Bump 4.9 Vagrant box (Linux 4.9.326, to fix a kernel bug) ([#21260](https://togithub.com/cilium/cilium/issues/21260), [@tklauser](https://togithub.com/tklauser)) - backport v1.12: test: Switch Kind image ([#20918](https://togithub.com/cilium/cilium/issues/20918), [@brb](https://togithub.com/brb)) - gh/workflows: stop using ubuntu-18.04 runner (Backport PR [#21053](https://togithub.com/cilium/cilium/issues/21053), Upstream PR [#21015](https://togithub.com/cilium/cilium/issues/21015), [@julianwiedmann](https://togithub.com/julianwiedmann)) - k8s: fix test flake in TestGenerateToCIDRFromEndpoint. (Backport PR [#21225](https://togithub.com/cilium/cilium/issues/21225), Upstream PR [#21220](https://togithub.com/cilium/cilium/issues/21220), [@tommyp1ckles](https://togithub.com/tommyp1ckles)) - k8s: fix test flake in TestGenerateToCIDRFromEndpoint. (Backport PR [#21292](https://togithub.com/cilium/cilium/issues/21292), Upstream PR [#21220](https://togithub.com/cilium/cilium/issues/21220), [@tommyp1ckles](https://togithub.com/tommyp1ckles)) - Update wrk2 repository ([#21157](https://togithub.com/cilium/cilium/issues/21157), [@michi-covalent](https://togithub.com/michi-covalent)) **Misc Changes:** - Add ArgoCD issues notes in the official documentation (Backport PR [#21053](https://togithub.com/cilium/cilium/issues/21053), Upstream PR [#20313](https://togithub.com/cilium/cilium/issues/20313), [@Kikiodazie](https://togithub.com/Kikiodazie)) - add kvstore TTL flag in cilium-operator (Backport PR [#21122](https://togithub.com/cilium/cilium/issues/21122), Upstream PR [#21006](https://togithub.com/cilium/cilium/issues/21006), [@NikhilSharmaWe](https://togithub.com/NikhilSharmaWe)) - build(deps): bump 8398a7/action-slack from 3.13.0 to 3.13.2 ([#21035](https://togithub.com/cilium/cilium/issues/21035), [@dependabot](https://togithub.com/dependabot)\[bot]) - build(deps): bump actions/cache from 3.0.7 to 3.0.8 ([#21029](https://togithub.com/cilium/cilium/issues/21029), [@dependabot](https://togithub.com/dependabot)\[bot]) - build(deps): bump actions/setup-go from 3.2.1 to 3.3.0 ([#21048](https://togithub.com/cilium/cilium/issues/21048), [@dependabot](https://togithub.com/dependabot)\[bot]) - build(deps): bump github/codeql-action from 2.1.18 to 2.1.19 ([#20989](https://togithub.com/cilium/cilium/issues/20989), [@dependabot](https://togithub.com/dependabot)\[bot]) - build(deps): bump github/codeql-action from 2.1.19 to 2.1.20 ([#21030](https://togithub.com/cilium/cilium/issues/21030), [@dependabot](https://togithub.com/dependabot)\[bot]) - build(deps): bump github/codeql-action from 2.1.20 to 2.1.21 ([#21092](https://togithub.com/cilium/cilium/issues/21092), [@dependabot](https://togithub.com/dependabot)\[bot]) - build(deps): bump github/codeql-action from 2.1.21 to 2.1.22 ([#21173](https://togithub.com/cilium/cilium/issues/21173), [@dependabot](https://togithub.com/dependabot)\[bot]) - Change message for the status of the policy enforcement in CEPs to be more accurate. (Backport PR [#21122](https://togithub.com/cilium/cilium/issues/21122), Upstream PR [#21003](https://togithub.com/cilium/cilium/issues/21003), [@aanm](https://togithub.com/aanm)) - Coalesce of health endpoint CIDRs (Backport PR [#21225](https://togithub.com/cilium/cilium/issues/21225), Upstream PR [#20848](https://togithub.com/cilium/cilium/issues/20848), [@dezmodue](https://togithub.com/dezmodue)) - docs(bandwidth-manager): add note on per-pod limits (Backport PR [#20940](https://togithub.com/cilium/cilium/issues/20940), Upstream PR [#20916](https://togithub.com/cilium/cilium/issues/20916), [@raphink](https://togithub.com/raphink)) - docs: Add available options for Ingress Controller annotations (Backport PR [#21053](https://togithub.com/cilium/cilium/issues/21053), Upstream PR [#20973](https://togithub.com/cilium/cilium/issues/20973), [@NikhilSharmaWe](https://togithub.com/NikhilSharmaWe)) - docs: Added `Default` column in metrics details (Backport PR [#20940](https://togithub.com/cilium/cilium/issues/20940), Upstream PR [#20255](https://togithub.com/cilium/cilium/issues/20255), [@kanurag94](https://togithub.com/kanurag94)) - docs: fix check-crd-compat-table script (Backport PR [#21292](https://togithub.com/cilium/cilium/issues/21292), Upstream PR [#21208](https://togithub.com/cilium/cilium/issues/21208), [@aanm](https://togithub.com/aanm)) - docs: second set of video contents added (Backport PR [#21053](https://togithub.com/cilium/cilium/issues/21053), Upstream PR [#20623](https://togithub.com/cilium/cilium/issues/20623), [@Kikiodazie](https://togithub.com/Kikiodazie)) - docs: Switch to our own fork of sphinxcontrib-openapi (Backport PR [#20940](https://togithub.com/cilium/cilium/issues/20940), Upstream PR [#20868](https://togithub.com/cilium/cilium/issues/20868), [@qmonnet](https://togithub.com/qmonnet)) - docs: Update ToServices docs section (Backport PR [#21122](https://togithub.com/cilium/cilium/issues/21122), Upstream PR [#21052](https://togithub.com/cilium/cilium/issues/21052), [@joestringer](https://togithub.com/joestringer)) - Document existing FQDN metrics (Backport PR [#20940](https://togithub.com/cilium/cilium/issues/20940), Upstream PR [#20516](https://togithub.com/cilium/cilium/issues/20516), [@christarazi](https://togithub.com/christarazi)) - Document per-endpoint route requirement in aws-cni Helm snippet (Backport PR [#21292](https://togithub.com/cilium/cilium/issues/21292), Upstream PR [#21276](https://togithub.com/cilium/cilium/issues/21276), [@ti-mo](https://togithub.com/ti-mo)) - EgressGW: make logging less verbose (Backport PR [#21225](https://togithub.com/cilium/cilium/issues/21225), Upstream PR [#21115](https://togithub.com/cilium/cilium/issues/21115), [@julianwiedmann](https://togithub.com/julianwiedmann)) - Expand documentation around CODEOWNERS and review expectations (Backport PR [#21292](https://togithub.com/cilium/cilium/issues/21292), Upstream PR [#21057](https://togithub.com/cilium/cilium/issues/21057), [@joestringer](https://togithub.com/joestringer)) - filter out pod labels from synchronizing with cilium endpoint labels (Backport PR [#21225](https://togithub.com/cilium/cilium/issues/21225), Upstream PR [#21135](https://togithub.com/cilium/cilium/issues/21135), [@NikhilSharmaWe](https://togithub.com/NikhilSharmaWe)) - Highlight Non-Overlapping Functionality Between K8s and Cilium Network Policies (Backport PR [#21122](https://togithub.com/cilium/cilium/issues/21122), Upstream PR [#21001](https://togithub.com/cilium/cilium/issues/21001), [@nathanjsweet](https://togithub.com/nathanjsweet)) - Improve CRD schema update automation during release process (Backport PR [#20940](https://togithub.com/cilium/cilium/issues/20940), Upstream PR [#20875](https://togithub.com/cilium/cilium/issues/20875), [@joestringer](https://togithub.com/joestringer)) - kubectl get cep returns empty columns of policies statuses (Backport PR [#20940](https://togithub.com/cilium/cilium/issues/20940), Upstream PR [#20548](https://togithub.com/cilium/cilium/issues/20548), [@romanspb80](https://togithub.com/romanspb80)) - metallb: bump to latest metallb version (Backport PR [#21225](https://togithub.com/cilium/cilium/issues/21225), Upstream PR [#21131](https://togithub.com/cilium/cilium/issues/21131), [@ldelossa](https://togithub.com/ldelossa)) - pkg/bgpv1/annotations: Optimize annotations Errors (Backport PR [#21225](https://togithub.com/cilium/cilium/issues/21225), Upstream PR [#20819](https://togithub.com/cilium/cilium/issues/20819), [@MikeLing](https://togithub.com/MikeLing)) - pkg/nodediscovery: protect variable against concurrent access (Backport PR [#21122](https://togithub.com/cilium/cilium/issues/21122), Upstream PR [#21086](https://togithub.com/cilium/cilium/issues/21086), [@aanm](https://togithub.com/aanm)) - Spring cleaning for the contributor guide (Backport PR [#21122](https://togithub.com/cilium/cilium/issues/21122), Upstream PR [#21056](https://togithub.com/cilium/cilium/issues/21056), [@joestringer](https://togithub.com/joestringer)) - test: update k8s versions to the latest patched releases ([#21102](https://togithub.com/cilium/cilium/issues/21102), [@aanm](https://togithub.com/aanm)) - Use pod Deployment name as workload name for flow workload field (Backport PR [#21225](https://togithub.com/cilium/cilium/issues/21225), Upstream PR [#21124](https://togithub.com/cilium/cilium/issues/21124), [@chancez](https://togithub.com/chancez)) - v1.12: Update Go to 1.18.6 ([#21228](https://togithub.com/cilium/cilium/issues/21228), [@tklauser](https://togithub.com/tklauser)) **Other Changes:** - install: Update image digests for v1.12.1 ([#20928](https://togithub.com/cilium/cilium/issues/20928), [@joestringer](https://togithub.com/joestringer)) #### Docker Manifests ##### cilium `docker.io/cilium/cilium:v1.12.2@sha256:986f8b04cfdb35cf714701e58e35da0ee63da2b8a048ab596ccb49de58d5ba36` `quay.io/cilium/cilium:v1.12.2@sha256:986f8b04cfdb35cf714701e58e35da0ee63da2b8a048ab596ccb49de58d5ba36` `docker.io/cilium/cilium:stable@sha256:986f8b04cfdb35cf714701e58e35da0ee63da2b8a048ab596ccb49de58d5ba36` `quay.io/cilium/cilium:stable@sha256:986f8b04cfdb35cf714701e58e35da0ee63da2b8a048ab596ccb49de58d5ba36` ##### clustermesh-apiserver `docker.io/cilium/clustermesh-apiserver:v1.12.2@sha256:9068b861e468a8d53421673aa9a6b576f91a5574a030b2af236c973d63c81747` `quay.io/cilium/clustermesh-apiserver:v1.12.2@sha256:9068b861e468a8d53421673aa9a6b576f91a5574a030b2af236c973d63c81747` `docker.io/cilium/clustermesh-apiserver:stable@sha256:9068b861e468a8d53421673aa9a6b576f91a5574a030b2af236c973d63c81747` `quay.io/cilium/clustermesh-apiserver:stable@sha256:9068b861e468a8d53421673aa9a6b576f91a5574a030b2af236c973d63c81747` ##### docker-plugin `docker.io/cilium/docker-plugin:v1.12.2@sha256:448fde6771bb98eb2d9bb6516d4ba1f12143c1eb4656e8a6ab129241281f9ed3` `quay.io/cilium/docker-plugin:v1.12.2@sha256:448fde6771bb98eb2d9bb6516d4ba1f12143c1eb4656e8a6ab129241281f9ed3` `docker.io/cilium/docker-plugin:stable@sha256:448fde6771bb98eb2d9bb6516d4ba1f12143c1eb4656e8a6ab129241281f9ed3` `quay.io/cilium/docker-plugin:stable@sha256:448fde6771bb98eb2d9bb6516d4ba1f12143c1eb4656e8a6ab129241281f9ed3` ##### hubble-relay `docker.io/cilium/hubble-relay:v1.12.2@sha256:6f3496c28f23542f2645d614c0a9e79e3b0ae2732080da794db41c33e4379e5c` `quay.io/cilium/hubble-relay:v1.12.2@sha256:6f3496c28f23542f2645d614c0a9e79e3b0ae2732080da794db41c33e4379e5c` `docker.io/cilium/hubble-relay:stable@sha256:6f3496c28f23542f2645d614c0a9e79e3b0ae2732080da794db41c33e4379e5c` `quay.io/cilium/hubble-relay:stable@sha256:6f3496c28f23542f2645d614c0a9e79e3b0ae2732080da794db41c33e4379e5c` ##### operator-alibabacloud `docker.io/cilium/operator-alibabacloud:v1.12.2@sha256:8c5d6fd3eb1e9a664ceb5e60af34e7b3f6c78a7c5655a1601437641ddf5729ea` `quay.io/cilium/operator-alibabacloud:v1.12.2@sha256:8c5d6fd3eb1e9a664ceb5e60af34e7b3f6c78a7c5655a1601437641ddf5729ea` `docker.io/cilium/operator-alibabacloud:stable@sha256:8c5d6fd3eb1e9a664ceb5e60af34e7b3f6c78a7c5655a1601437641ddf5729ea` `quay.io/cilium/operator-alibabacloud:stable@sha256:8c5d6fd3eb1e9a664ceb5e60af34e7b3f6c78a7c5655a1601437641ddf5729ea` ##### operator-aws `docker.io/cilium/operator-aws:v1.12.2@sha256:ad1f7599aa02e5a3917d8519ab20ca645af5aaf0f47dfabea81428838065d875` `quay.io/cilium/operator-aws:v1.12.2@sha256:ad1f7599aa02e5a3917d8519ab20ca645af5aaf0f47dfabea81428838065d875` `docker.io/cilium/operator-aws:stable@sha256:ad1f7599aa02e5a3917d8519ab20ca645af5aaf0f47dfabea81428838065d875` `quay.io/cilium/operator-aws:stable@sha256:ad1f7599aa02e5a3917d8519ab20ca645af5aaf0f47dfabea81428838065d875` ##### operator-azure `docker.io/cilium/operator-azure:v1.12.2@sha256:7c33597aa928aade697a7acb382eccd2af4147ddc9e29858c21356a1d4884d0a` `quay.io/cilium/operator-azure:v1.12.2@sha256:7c33597aa928aade697a7acb382eccd2af4147ddc9e29858c21356a1d4884d0a` `docker.io/cilium/operator-azure:stable@sha256:7c33597aa928aade697a7acb382eccd2af4147ddc9e29858c21356a1d4884d0a` `quay.io/cilium/operator-azure:stable@sha256:7c33597aa928aade697a7acb382eccd2af4147ddc9e29858c21356a1d4884d0a` ##### operator-generic `docker.io/cilium/operator-generic:v1.12.2@sha256:00508f78dae5412161fa40ee30069c2802aef20f7bdd20e91423103ba8c0df6e` `quay.io/cilium/operator-generic:v1.12.2@sha256:00508f78dae5412161fa40ee30069c2802aef20f7bdd20e91423103ba8c0df6e` `docker.io/cilium/operator-generic:stable@sha256:00508f78dae5412161fa40ee30069c2802aef20f7bdd20e91423103ba8c0df6e` `quay.io/cilium/operator-generic:stable@sha256:00508f78dae5412161fa40ee30069c2802aef20f7bdd20e91423103ba8c0df6e` ##### operator `docker.io/cilium/operator:v1.12.2@sha256:ca075c8fed919ac5f78e6859783ec60fdcf0e57e9a8739489f2c914c0a3dffd3` `quay.io/cilium/operator:v1.12.2@sha256:ca075c8fed919ac5f78e6859783ec60fdcf0e57e9a8739489f2c914c0a3dffd3` `docker.io/cilium/operator:stable@sha256:ca075c8fed919ac5f78e6859783ec60fdcf0e57e9a8739489f2c914c0a3dffd3` `quay.io/cilium/operator:stable@sha256:ca075c8fed919ac5f78e6859783ec60fdcf0e57e9a8739489f2c914c0a3dffd3` ### [`v1.12.1`](https://togithub.com/cilium/cilium/releases/tag/v1.12.1) [Compare Source](https://togithub.com/cilium/cilium/compare/v1.12.0...v1.12.1) We are pleased to release Cilium v1.12.1. This release fixes a moderate severity security issue [GHSA-pfhr-pccp-hwmh](https://togithub.com/cilium/cilium/security/advisories/GHSA-pfhr-pccp-hwmh), adds websockets support for Ingress, and fixes a range of bugs that have been recently reported in the community. See the notes below for a full description of the changes. ## Summary of Changes **Minor Changes:** - envoy: Bump envoy version to 1.21.5 (Backport PR [#20851](https://togithub.com/cilium/cilium/issues/20851), Upstream PR [#20771](https://togithub.com/cilium/cilium/issues/20771), [@sayboras](https://togithub.com/sayboras)) - fqdn/metrics: Fix ProxyUpstreamTime error=timeout (Backport PR [#20851](https://togithub.com/cilium/cilium/issues/20851), Upstream PR [#20752](https://togithub.com/cilium/cilium/issues/20752), [@joestringer](https://togithub.com/joestringer)) - ingress: add websockets configuration (Backport PR [#20867](https://togithub.com/cilium/cilium/issues/20867), Upstream PR [#20814](https://togithub.com/cilium/cilium/issues/20814), [@nikhiljha](https://togithub.com/nikhiljha)) - Remove check on intSlice type from config map validation (Backport PR [#20851](https://togithub.com/cilium/cilium/issues/20851), Upstream PR [#20638](https://togithub.com/cilium/cilium/issues/20638), [@pippolo84](https://togithub.com/pippolo84)) - Remove IPVLAN support following the deprecation in v1.11. (Backport PR [#20656](https://togithub.com/cilium/cilium/issues/20656), Upstream PR [#20453](https://togithub.com/cilium/cilium/issues/20453), [@pchaigno](https://togithub.com/pchaigno)) **Bugfixes:** - Add EndpointSlice support for clustermesh-apiserver (Backport PR [#20851](https://togithub.com/cilium/cilium/issues/20851), Upstream PR [#20697](https://togithub.com/cilium/cilium/issues/20697), [@YutaroHayakawa](https://togithub.com/YutaroHayakawa)) - bpf: Add send_trace_notify hook for redirect_direct\_{v4,v6} (Backport PR [#20851](https://togithub.com/cilium/cilium/issues/20851), Upstream PR [#20479](https://togithub.com/cilium/cilium/issues/20479), [@qmonnet](https://togithub.com/qmonnet)) - Ensure that Cilium CNI in delegated-plugin IPAM mode avoids leaking IPs even when the network namespace has been deleted. (Backport PR [#20851](https://togithub.com/cilium/cilium/issues/20851), Upstream PR [#20630](https://togithub.com/cilium/cilium/issues/20630), [@wedaly](https://togithub.com/wedaly)) - Fix bug where Cilium would crash on startup with an error about being unable to delete iptables rules. (Backport PR [#20890](https://togithub.com/cilium/cilium/issues/20890), Upstream PR [#20885](https://togithub.com/cilium/cilium/issues/20885), [@jibi](https://togithub.com/jibi)) - Fix bug where network policies that select namespace labels may incorrectly select identities ([Advisory](https://togithub.com/cilium/cilium/security/advisories/GHSA-pfhr-pccp-hwmh), commit [`2494ce4`](https://togithub.com/cilium/cilium/commit/2494ce4dca59)) - Fix bug where traffic sent outside the cluster via ToFQDNs policy would be denied despite a policy that allows it (Backport PR [#20851](https://togithub.com/cilium/cilium/issues/20851), Upstream PR [#20721](https://togithub.com/cilium/cilium/issues/20721), [@joestringer](https://togithub.com/joestringer)) - Fix ineffective post-start hook in ENI mode (Backport PR [#20851](https://togithub.com/cilium/cilium/issues/20851), Upstream PR [#20741](https://togithub.com/cilium/cilium/issues/20741), [@bmcustodio](https://togithub.com/bmcustodio)) - fix k8s latency metrics label cardinality (Backport PR [#20851](https://togithub.com/cilium/cilium/issues/20851), Upstream PR [#20831](https://togithub.com/cilium/cilium/issues/20831), [@aanm](https://togithub.com/aanm)) - Fix parsing of string map command line options when more than one separator is present. (Backport PR [#20851](https://togithub.com/cilium/cilium/issues/20851), Upstream PR [#20673](https://togithub.com/cilium/cilium/issues/20673), [@tklauser](https://togithub.com/tklauser)) - Fix regression with cilium-health-probe controller in IPv6-only clusters (Backport PR [#20867](https://togithub.com/cilium/cilium/issues/20867), Upstream PR [#20849](https://togithub.com/cilium/cilium/issues/20849), [@aanm](https://togithub.com/aanm)) - helm: Guard apply sysctl init container (Backport PR [#20851](https://togithub.com/cilium/cilium/issues/20851), Upstream PR [#20643](https://togithub.com/cilium/cilium/issues/20643), [@sayboras](https://togithub.com/sayboras)) - helm: Set KPR default to "disabled" for >= 1.12 (Backport PR [#20851](https://togithub.com/cilium/cilium/issues/20851), Upstream PR [#20610](https://togithub.com/cilium/cilium/issues/20610), [@brb](https://togithub.com/brb)) - Helm: Use the correct operator.dnsPolicy value for the operator deployment template (Backport PR [#20867](https://togithub.com/cilium/cilium/issues/20867), Upstream PR [#20844](https://togithub.com/cilium/cilium/issues/20844), [@michi-covalent](https://togithub.com/michi-covalent)) - ipcache/kvstore: fix panic when processing ip=Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.