A maintenance release with operator-relevant bug fixes, new configuration and diagnostic capabilities, and dependency and image updates. Two fixes address security-relevant exposure or policy bypass, and no deprecations or removals are announced.
Check if affected (2)
securityWorld-accessible Envoy admin socket
Applies if
envoyruns.The
envoyadmin socket creation is fixed so it is not world-accessible in v1.19.2.securityIngress policy enforcement for local backends
Applies if you use
ingress policiesandlocal backends.Ingress policies no longer bypass enforcement for local backends in v1.19.2.