A substantial operator-facing feature and maintenance release with new DNS proxy, installation, configuration, API, metric, and datapath capabilities. It also changes defaults and compatibility requirements, removes deprecated interfaces, migrates BGP APIs, and updates security-related dependencies.
Action needed (15)
securityThe
github.dependency, updatedcom/containerd/containerd The
github.module is updated to v1.7.29.com/containerd/containerd securityThe
github.dependency, updatedcom/go-viper/mapstructure/v2 The
github.module is updated to v2.4.0.com/go-viper/mapstructure/v2 securityThe
github.dependency, updatedcom/docker/docker The
github.module is updated to v28.3.3+incompatible.com/docker/docker securityThe
golang.dependency, updatedorg/x/crypto The
golang.module is updated to v0.45.0.org/x/crypto securityThe
helm.dependency, updated to v3.18.4sh/helm/v3 The
helm.module is updated to v3.18.4.sh/helm/v3 securityThe
helm.dependency, updated to v3.18.5sh/helm/v3 The
helm.module is updated to v3.18.5.sh/helm/v3 breakingThe
plpmtuddefault, set toblackholeThe default
plpmtudmode is nowblackhole(blackhole-detected).breakingThe
AddressScopeMaxdefault, set to 254The default
AddressScopeMaxis changed to 254, the host scope, for GKE metadata server and HCP use cases. The related setting is--local-max-addr-scope.breakingThe
tls authModedefault, set tomigrationtls authModeis set tomigrationby default.breakingThe CNI deletion timeout, reduced to 1.5 seconds
The CNI deletion timeout is reduced to 1.5 seconds.
breakingThe
policy-default-local-clusterdefaultpolicy-default-local-clusteris now set by default.breakingHost firewall bypass, disabled by default
Host firewall bypass is disabled by default.
breakingFQDN match pattern sanitization
FQDN match pattern sanitization is refactored and tightened.
breakingEncrypted traffic forwarding via
cilium_host, removedForwarding encrypted traffic via
cilium_hosthas been removed.breakingCNI configuration in the container image, removed
The CNI configuration is no longer installed in the container image.
Check if affected (30)
breakingLocal-cluster default for network policy selectors
Applies if you do not set
clusterin network policy selectors.Network policy selectors without an explicit
clusternow allow communication only with the local cluster by default.breakingThe
CiliumBGPPeeringPolicyv1 API, removedApplies if you use
CiliumBGPPeeringPolicy.Support for the older
CiliumBGPPeeringPolicyv1 API is removed. BGP configuration uses thecilium.APIs instead.io/v2 breakingMutual Authentication, disabled by default
Applies if you enable Mutual Authentication.
The out-of-band Mutual Authentication feature is disabled by default pending community feedback.
- + 27 more on the release page
Plan ahead (7)
deprecated
--enable-ipsec-encrypted-overlay, deprecatedremoval date not announcedApplies if you use
--enable-ipsec-encrypted-overlay.The special IPsec mode for enabling encrypted overlay with Multicast, configured by
--enable-ipsec-encrypted-overlay, is deprecated and will be removed in a future release.deprecatedKafka match fields and
ToRequiresandFromRequires, deprecatedApplies if you use
ToRequiresorFromRequires.Kafka protocol match fields (beta), along with the
ToRequiresandFromRequirespolicy fields, are deprecated.deprecatedTLS certificate and key Helm values, deprecated
Applies if you pass TLS certificates or keys in Helm values.
Passing TLS certificates and keys in Helm values is deprecated.
- + 4 more on the release page