RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Sep 2026Clear ×
Ciliumv1.19.8Networking & MessagingTodaySep 16, 2026

A maintenance release focused on correctness fixes and dependency updates, with a small number of new extension points. It does not introduce broad operator-facing configuration changes.

Action needed (1)

  • breakingRemoval of the Ingress HostFW Policy between RevSNAT and RevDNAT

    The BPF NodePort path removes the Ingress HostFW Policy between RevSNAT and RevDNAT.

Source
Ciliumv1.18.14Networking & MessagingTodaySep 16, 2026

A maintenance release focused on bug fixes, dependency updates, and image refreshes. It also removes a datapath behavior and includes security dependency fixes that may require operator attention.

Action needed (3)

  • securityThe google.golang.org/grpc module, updated to v1.83.1

    The google.golang.org/grpc module is updated to v1.83.1 in this release as a security dependency fix.

  • securityThe google.golang.org/grpc module, updated to v1.83.2

    The google.golang.org/grpc module is updated to v1.83.2 in this release as a security dependency fix.

  • breakingThe Ingress HostFW Policy between RevSNAT and RevDNAT, removed

    The Ingress HostFW Policy between RevSNAT and RevDNAT is removed in this release.

Source
gRPCv1.84.0Networking & MessagingSep 11, 2026

A maintenance release that enables gRPC capabilities and observability, broadens xDS matching, removes a WRR guard, and corrects proxy hostname handling. It also updates connection scaling service configuration and server listener matching.

Action needed (2)

  • breakingThe v2_non_owning_waker_implementation experiment enabled

    The v2_non_owning_waker_implementation experiment is enabled in the promise-based filter.

  • breakingThe WRR custom backend metrics guard removed

    The release removes the WRR environment-variable guard for custom backend metrics.

Source
Contourv1.33.7Networking & MessagingSep 7, 2026

A security maintenance release updates Envoy, Go, and other dependencies to address CVEs. It is tested against Kubernetes 1.32 through 1.34, with no stated operator configuration changes.

Action needed (3)

  • securityThe Envoy version, updated to v1.38.4

    Envoy is updated to v1.38.4 to address CVEs. The update ships in this release.

  • securityThe Go version, updated to 1.26.8

    Go is updated to 1.26.8 to address CVEs. The update ships in this release.

  • securityDependency updates for CVE fixes

    Dependencies are updated to address CVEs. The dependency updates ship in this release.

Source
Linkerdedge-26.9.1Networking & MessagingSep 4, 2026

A maintenance release updates the proxy and dependencies, fixes destination behavior, and tightens multicluster credential and Link resource handling. The changes concern proxy, destination, and multicluster components, alongside routine dependency updates.

Action needed (2)

  • breakingCluster credential secrets and the exec auth provider

    Cluster credential secrets created by linkerd multicluster link use the token auth provider. The exec auth provider is disallowed because it is not used or necessary.

  • breakingLink resource lookup scope

    Link resource lookups are restricted to the linkerd-multicluster namespace.

Source
Browse by month