A maintenance release focused primarily on dependency version updates across the project. The Linkerd proxy is updated to v2.366.0, with no security advisories or operator-enforced breaking changes described.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
This release removes legacy CRD API versions and resource state metrics, and changes defaults for token mounting, feature gates, and container security contexts. It also adds Kafka and configuration capabilities and updates shipped dependencies.
Action needed (2)
breakingService Account token mounting
Service Account tokens are no longer auto-mounted into Pods. They are mounted through a volume instead.
breakingThe
ServerSideApplyPhase1feature gate, permanently enabledThe
ServerSideApplyPhase1feature gate has moved to GA and is permanently enabled. It can no longer be disabled.
Check if affected (3)
breakingLegacy CRD API versions, no longer supported
Applies before upgrading to Strimzi 1.0.0 or later if you use the
v1beta2,v1beta1, orv1alpha1APIs.breakingResource state metrics, removed
Applicability is not stated in the release notes.
breakingDefault
securityContextfor operator installationsApplies if you use the Cluster, Topic, and User Operator YAML installation files or the Cluster Operator Helm Chart.
A maintenance release with numerous operator-facing bug fixes and behavior corrections, alongside dependency and image updates. It also introduces a decoder-memory limit and fixes a CIDR policy bypass that could cause traffic drops after an agent restart.
Check if affected (1)
securityThe
endpointCIDR policy bypass, fixedApplicability is not stated in the release notes.
A maintenance release with bug fixes, diagnostic improvements, dependency and image updates, and improved DNS request validation. It contains no security advisories or explicitly described vulnerabilities.
Source ↗A maintenance release that adds host-firewall protocol support, corrects networking and stability defects, and changes runtime behavior and observability. It also updates dependencies and container images, including a gRPC security fix with no disclosed vulnerability.
Action needed (1)
securityThe
google.dependency, updated togolang. org/grpc v1.82. 1 The
google.module is updated togolang. org/grpc v1.in the v1.18 release line. The release note marks this dependency update as a security fix, but does not disclose the vulnerability.82. 1
A maintenance release with routine dependency updates, a destination informer correction, and policy-controller behavior changes. It also expands Kubernetes and Gateway API support, with no disclosed security advisories or security-specific fixes.
Source ↗A maintenance release with a security fix for an external authorization bypass and dependency updates for CVE fixes. It also updates the tested Kubernetes range to 1.32 through 1.34, Go to 1.25.12, and Envoy to v1.38.3.
Action needed (1)
securityDependency updates for CVE fixes
Dependencies were updated to fix CVEs. The updates ship in Contour v1.33.6.
Check if affected (1)
securityExternal authorization bypass with disabled
authPolicyApplies if
authPolicyis not configured.
NATS v2.14.5 updates the Go toolchain and two dependencies, and adds a configurable leafnode dial timeout for high-latency links. It fixes a logger deadlock and a JetStream defect involving idempotent stream creation, with no security advisories or security-specific fixes disclosed.
NATS v2.12.15 updates the Go toolchain and dependency manifests. It also fixes deadlocks in logging and a JetStream data-loss bug related to idempotent stream creation when an offline node catches up from a metalayer snapshot.
Source ↗Linkerd edge-26.8.1 updates third-party dependencies and the Linkerd proxy component. No security advisories or operator action are identified for this release.
Source ↗A maintenance release with dependency and toolchain updates, JetStream performance and configuration improvements, and broad correctness fixes. It also includes authentication and permission fixes.
Check if affected (4)
security
JWTvalidation with whitespace-only permissionsApplies if you use JWT validation.
security
verify_and_mapauthentication with blank passwordsApplies if TLS
verify_and_mapis configured.securityMQTT subscription restriction for
$MQTT.subjects> Applies if you use
MQTT.- + 1 more on the release page
A maintenance release with a Go toolchain update, dependency manifest updates, JetStream performance and configuration changes, and numerous correctness fixes. Authentication fixes address security flaws and require upgrading.
Action needed (1)
breakingThe disk concurrency semaphore, increased to 4096 slots
The disk concurrency semaphore is now set to 4096 slots, up from the previous CPU-scaled count. This performance change ships in v2.12.14.
Check if affected (2)
securityAuthentication checks with
no_auth_userand auth calloutsApplies if you configure
no_auth_userand use auth callouts.securityTLS
verify_and_mapauthentication with blank passwordsApplies if you use TLS and configure
verify_and_map.
A substantial feature and maintenance release with Gateway API, networking, IPAM, policy, observability, and datapath changes, alongside correctness and performance fixes. Operators should review removed or renamed options, changed defaults and requirements, removed metrics and integrations, and the dependency updates addressing security-related issues.
Action needed (11)
security
google.v1.79.3golang. org/grpc The
google.module is updated to v1.79.3 in the main branch.golang. org/grpc security
google.v1.82.1golang. org/grpc The
google.module is updated to v1.82.1 in the v1.20 branch.golang. org/grpc security
helm.v4.1.4sh/helm/v4 The
helm.module is updated to v4.1.4 in the main branch.sh/helm/v4 security
github.v1.6.3com/cloudflare/circl The
github.module is updated to v1.6.3.com/cloudflare/circl security
github.v4.1.4com/go-jose/go-jose/v4 The
github.module is updated to v4.1.4.com/go-jose/go-jose/v4 security
github.v0.5.1com/moby/spdystream The
github.module is updated to v0.5.1.com/moby/spdystream breaking
cni.CNI configuration versioncustomConf The default CNI configuration version for
cni.changes from 0.3.1 to 1.0.0.customConf breakingCilium operator IPAM metrics removal
The IPAM metrics
cilium_operator_ipam_ipsandcilium_operator_ipam_available_interfacesare removed.breakingDefault CNI configuration version
The default CNI configuration version changes from 0.3.1 to 1.0.0.
breakingNative histogram default
Native histograms are emitted for all histograms by default.
breakingAgent bootstrap metrics removal
Agent bootstrap metrics are removed.
Check if affected (28)
security
tbidtraffic host namespace handlingApplies if you use
tbidtraffic.breakingDocker libnetwork plugin removal
Applies if you use the Docker libnetwork plugin.
breaking
ces-slice-moderemovalApplies if you configure
ces-slice-mode.- + 25 more on the release page
Plan ahead (6)
deprecatedBeta Mutual Auth deprecationremoval date not announced
Applies if you use Mutual Auth.
deprecatedDeprecated address and interface CIDR fields
Applies if you configure
addresses[].orsubnet interfaces[]..cidr deprecatedLocal REST BGP API deprecationremoval date not announced
Applies if you use the local REST BGP APIs.
- + 3 more on the release page
Linkerd edge-26.7.2 contains no functional changes. It updates runtime, build, and development dependencies, with no security advisories disclosed or referenced.
Source ↗This release includes a security-related default change in TLS key exchange. The change affects deployments that use TLS key exchange.
Check if affected (1)
securityPost-Quantum Cryptography as the default for TLS key exchange
Applies when TLS key exchange is used.
This release tightens Gateway API and service-port handling and corrects tracing identity construction. It also updates dependencies and shipped components, with no security advisories or explicitly described vulnerabilities.
Action needed (1)
breakingUndefined service port requests disallowed
The
destinationcomponent now disallows requests to service ports that are not defined.
Check if affected (1)
breakingGateway API checks during
HelminstallationApplies when you use
Helm.
A maintenance release with numerous correctness fixes, Gateway API and telemetry additions, dependency and image updates, and internal behavior changes. No security advisories or explicitly described vulnerabilities are present.
Check if affected (1)
breakingHelm handling of
hostFirewall.disablementenabled Applies when you use Helm to disable
hostFirewall., toggling it from true to false.enabled
Cilium v1.18.12 adds Gateway access-log configuration and BYOCNI loopback support. It also fixes policy, startup, Gateway validation, IPAM, and metric-label defects, while updating shipped images and dependencies; no security advisories or security-specific flaws are disclosed.
Source ↗Cilium v1.17.18 contains ordinary correctness fixes, a new BYOCNI loopback capability, and dependency and image updates. No security advisories or operator actions are identified.
Source ↗Istio 1.29.6 is a correctness-focused maintenance release. The fixes address ambient traffic draining, HBONE capability propagation, ambient CNI responsiveness, Istiod memory use, and cross-network traffic through east-west gateways.
Source ↗Istio 1.30.3 is a maintenance release focused on operator-facing updates, performance work, and defect corrections. The listed release material includes fixes across certificate rotation, ambient mode, waypoint routing, multicluster behavior, and Istiod scalability.
Source ↗A broad release with operator-facing changes across configuration, protocols, extensions, networking, and observability. Security fixes address multiple identified CVEs and a GHSA, while changed defaults, stricter input validation, and removed functionality may affect existing deployments.
Check if affected (11)
securityhigh
HTTP/2header limits and flood protectionApplies if you use
HTTP/2.securityhigh
HTTP/3QPACK andcontent-lengthsecurity fixesApplies if you use
HTTP/3.securityhighAdditional protocol, parser, formatter, and decompression security fixes
Applies if you use DNS query validation, JSON nesting limits, PROXY protocol TLV, the formatter, TCP StatsD, TLS SAN, or Zstd decompression.
- + 8 more on the release page
A dependency-focused release raises the minimum supported Python protobuf version. The headings contain no operator-facing changes.
Check if affected (1)
breakingThe Python
protobufdependency lower bound, raisedApplies if you use Python.
A feature and maintenance release that adds and changes capabilities across Core, PHP, Python, and Ruby, corrects runtime defects, and upgrades protobuf dependencies. The Python 1. package was removed from PyPI.
Check if affected (1)
breakinggRPC Python release
1., yanked from PyPI82. 0 Applies if you use
gRPC Python release 1..82. 0
Istio 1.28.10 contains an operator-relevant correctness fix in the krt controller framework. The available release information does not include a standalone change item for this fix.
Source ↗A maintenance release with a dependency and toolchain update, broad defect corrections, and behavior improvements across authentication, routing, monitoring, clustering, and JetStream. It also removes JSONP monitoring callbacks and addresses MQTT and authorization-related connection and permission handling.
Check if affected (3)
security
Nats-Trace-Destpublish permission checks for leaf connectionsApplies if you use Leaf connections.
security
MQTTsubscribe deny rules on retained message and QoS replay pathsApplies if you use
MQTT.breakingThe
JSONPcallback support in monitoring endpoints, removedApplies if you use JSONP callback support.
A maintenance release with dependency updates, operational behavior changes, and correctness fixes across General, MQTT, Monitoring, and JetStream. It also removes JSONP callback support from monitoring endpoints.
Check if affected (1)
breakingThe
JSONPcallback support in monitoring endpoints, removedApplies if you use
JSONPcallback support.
This release adds operator-facing configuration and feature capabilities while updating supported Apache Kafka versions and related integrations. It also changes TLS file handling for KafkaBridge and KafkaMirrorMaker2 and renames entity-operator healthcheck ports, so those areas may require attention.
Check if affected (3)
breakingSupport for
Kafka 4.removed1. x Applies if you use
Kafka 4..1. x breakingPEM-based TLS files for
KafkaBridgeandKafkaMirrorMaker2Applies if you use
KafkaBridgeorKafkaMirrorMaker2with TLS authentication or a TLS truststore.breakingEntity-operator healthcheck port names
Applies if you use entity-operator healthcheck ports.
A maintenance release with disclosed Envoy security fixes across HTTP/3 processing, protocol handling, filters, decompression, certificates, and statistics. The corrections are available through an upgrade to this release.
Action needed (7)
securityhighCVE-2026-48044, Zstd decompressor ratio enforcement
CVE-2026-48044 fixes memory exhaustion in the
Zstd decompressorby enforcing theMaxInflateRatiolimit inside the decompression loop.securitymediumCVE-2026-47692, PROXY protocol TLV length validation
CVE-2026-47692 fixes a length mismatch when passthrough TLVs and added TLVs exceed the maximum length in the PROXY protocol header.
securitymediumCVE-2026-47221, HTTP 303 body-less redirect handling
CVE-2026-47221 fixes a segmentation fault when handling
HTTP 303internal redirects for requests without a body.securitymediumCVE-2026-48090, asynchronous token callback lifetime
CVE-2026-48090 fixes a callback that could run after the filter was torn down, preventing access to dangling pointers and the resulting use-after-free crash.
securitymediumCVE-2026-47778, peer certificate SAN validation
CVE-2026-47778 fixes validation of a peer certificate's Subject Alternative Name when the SAN contains an embedded NUL byte.
securitymediumCVE-2026-48497, query name length checking
CVE-2026-48497 adds sanity checking for query name length and uses
ENVOY_BUGwhen the check fails, avoiding abnormal process termination.securityGHSA-p7c7-7c47-pwch, QPACK blocked decoding fix
GHSA-p7c7-7c47-pwch fixes a denial-of-service vulnerability in Envoy's
HTTP/3stack caused by QPACK blocked decoding and unbounded memory growth.
Check if affected (7)
securityhighCVE-2026-48743, HTTP/3 headers-only content-length validation
Applies if you enable
envoy..reloadable_features. quic_validate_headers_only_content_length securityhighCVE-2026-48042, JSON parser nesting depth limit
Applies if you set
envoy.to false.reloadable_features. limit_json_parser_nesting_depth securitymediumCVE-2026-47207,
ext_proc serverresponse handlingApplies if you use the
ext_proc server.- + 4 more on the release page
A maintenance release with Envoy security fixes and five ordinary defect corrections. The security fixes require upgrading, while no deprecations or forced operator configuration changes are announced.
Action needed (4)
securitymediumCVE-2026-47221 in HTTP 303 internal redirects
CVE-2026-47221 fixes handling of HTTP 303 internal redirects for body-less requests. The redirect code no longer attempts to drain an unallocated request body buffer.
securitymediumCVE-2026-48090 in asynchronous token change callbacks
CVE-2026-48090 fixes a bug where an asynchronous token change callback could run after the filter was torn down by
onDestroy(), causing dangling-pointer access and a crash.securitymediumCVE-2026-47778 in peer certificate SAN validation
CVE-2026-47778 fixes validation of a peer certificate's Subject Alternative Name when the SAN contains an embedded NUL byte. SAN parsing no longer permits NUL byte truncation to produce incorrect trust decisions.
securitymediumCVE-2026-48497 query name length checking
CVE-2026-48497 adds sanity checking for query name length to avoid abnormal process termination. The check uses
ENVOY_BUGwhen it fails.
Check if affected (11)
securityhighCVE-2026-47220 in the
%REQUESTED_SERVER_NAME%formatterApplies if you configure the
%REQUESTED_SERVER_NAME%formatter.securityhighCVE-2026-48044 in the Zstd decompressor
Applies if you use the Zstd decompressor.
securityhighCVE-2026-48743 HTTP/3 headers-only content-length validation
Applies if you use HTTP/3 and enable
envoy..reloadable_features. quic_validate_headers_only_content_length - + 8 more on the release page
A maintenance release with a changed logging default, operator-facing additions and fixes, and a restriction on pilot-agent metric content types. It also includes Envoy security fixes covering denial-of-service, crashes, validation issues, memory exhaustion, and other vulnerabilities.
Action needed (12)
securityhighCVE-2026-47220 crash bug fix
The Envoy security update fixes the crash bug described by CVE-2026-47220.
securityhighCVE-2026-48044 memory exhaustion fix
The Envoy security update fixes the memory exhaustion vulnerability described by CVE-2026-48044.
securityhighCVE-2026-48042 JSON nesting-depth limit
The Envoy security update limits JSON nesting depth to 1000 through
envoy..reloadable_features. limit_json_parser_nesting_depth securitymediumCVE-2026-47692 bug fix
The Envoy security update fixes the bug described by CVE-2026-47692.
securitymediumCVE-2026-47205 use-after-free crash fix
The Envoy security update fixes the use-after-free crash described by CVE-2026-47205.
securitymediumCVE-2026-48090 asynchronous token callback handling
The Envoy security update fixes a bug where the asynchronous token change callback could be triggered after the filter had been torn down.
securitymediumCVE-2026-47778 Subject Alternative Name validation
The Envoy security update fixes an issue where Envoy could fail to validate the Subject Alternative Name (SAN).
securitymediumCVE-2026-47204 crash and use-after-free fix
The Envoy security update fixes a crash or use-after-free described by CVE-2026-47204.
securitymediumCVE-2026-48497 query name length checking
The Envoy security update fixes sanity checking of the query name length.
securitymediumCVE-2026-47775 padding oracle
The Envoy security update addresses a padding oracle described by CVE-2026-47775.
securityGHSA-p7c7-7c47-pwch denial-of-service fix
The Envoy security update fixes the denial-of-service vulnerability described by GHSA-p7c7-7c47-pwch.
breakingWarn-level message logging
The message is now logged at
warnlevel.
Check if affected (5)
securityhighCVE-2026-48743 HTTP/3 content-length validation
Applies if you use HTTP/3.
securitymediumCVE-2026-47207
ext_procresponse handlingApplies if you use the
ext_procextension.securitymediumCVE-2026-47221 HTTP 303 redirect handling
Applicability is not stated in the release notes.
- + 2 more on the release page
A maintenance release with multiple disclosed security fixes and a security-related Wasmtime dependency update. It also removes the Intel DLB connection-balancer extension from all builds and disables TLS certificate compression by default.
Action needed (16)
securityhighThe
com_github_wasmtimedependency updateThe Wasmtime dependency
com_github_wasmtimewas updated to resolve CVE-2026-47261. The update ships in the WebAssembly build.securityhigh
REQUESTED_SERVER_NAMEcrash, CVE-2026-47220The
REQUESTED_SERVER_NAMEcrash was corrected in Envoy. The change addresses CVE-2026-47220 and GHSA-j9wh-4qfm-wf2v.securityhighzstd RLE zip bomb, CVE-2026-48044
The zstd RLE zip bomb issue was corrected in Envoy. The change addresses CVE-2026-48044 and GHSA-m3p9-47wh-88wg.
securityhighHighly nested JSON destructor stack overflow, CVE-2026-48042
The stack overflow in the destructor of highly nested JSON was corrected in Envoy. The change addresses CVE-2026-48042 and GHSA-f24p-rxw2-g6pv.
securityhighHTTP/3 to HTTP/1 request smuggling, CVE-2026-48743
The HTTP/3 to HTTP/1 request smuggling issue involving a headers-only request with a nonzero
Content-Lengthwas corrected in Envoy. The change addresses CVE-2026-48743 and GHSA-8phg-2h2q-jgxf.securitymediumAuthz per route crash, CVE-2026-47205
The Authz per route crash was corrected in Envoy. The change addresses CVE-2026-47205 and GHSA-mvh9-767w-x47j.
securitymediumThe ext_proc response issue, CVE-2026-47207
The ext_proc response handling issue involving one gRPC message was corrected in Envoy. The change addresses CVE-2026-47207 and GHSA-68cv-hq5f-g6xv.
securitymediumRouter internal redirects crash, CVE-2026-47221
The router internal redirects crash was corrected in Envoy. The change addresses CVE-2026-47221 and GHSA-rcff-gw58-pjpr.
securitymediumOAuth2 code verifier padding oracle, CVE-2026-47775
The OAuth2 code verifier padding oracle issue was corrected in Envoy. The change addresses CVE-2026-47775 and GHSA-396h-jpq4-vc7p.
securitymediumThe
grpc_statsfilter segfault, CVE-2026-47204The
grpc_statsfilter segfault on Connect protocol requests todirect_responseroutes was corrected in Envoy. The change addresses CVE-2026-47204 and GHSA-3jxh-8p6x-7pf6.securitymediumPROXY Protocol v2 skipped TLVs, CVE-2026-47692
The PROXY Protocol v2 header generator issue involving skipped TLVs and attacker-controlled spillover into the upstream application stream was corrected in Envoy. The change addresses CVE-2026-47692 and GHSA-wh36-hm39-mm3r.
securitymediumEmbedded NUL in TLS SAN truncation, CVE-2026-47778
The embedded NUL issue in TLS SAN truncation that could cause an authorization bypass was corrected in Envoy. The change addresses CVE-2026-47778 and GHSA-f8x4-rw5x-f3r7.
securitymediumOAuth2 filter late token completion, CVE-2026-48090
The OAuth2 filter issue involving late asynchronous token completion after stream teardown was corrected in Envoy. The change addresses CVE-2026-48090 and GHSA-3cj2-c63f-q26f.
securitymediumDNS UDP filter abnormal process termination, CVE-2026-48497
The abnormal process termination in the DNS UDP filter was corrected in Envoy. The change addresses CVE-2026-48497 and GHSA-j6g2-wf95-q66q.
securitymediumThe
TcpStatsdSinkheap buffer overflow, CVE-2026-48706The heap buffer overflow in
TcpStatsdSinkwas corrected in Envoy. The change addresses CVE-2026-48706 and GHSA-7q3f-gwg7-j8g4.securityHTTP/3 QPACK blocked decoding, GHSA-p7c7-7c47-pwch
The HTTP/3 stack issue involving QPACK blocked decoding was corrected in Envoy. The change addresses GHSA-p7c7-7c47-pwch.
Check if affected (2)
breakingThe
envoy.extension removalnetwork. connection_balance. dlb Applies if you use
envoy..network. connection_balance. dlb breakingThe
envoy.defaultreloadable_features. tls_certificate_compression_brotli Applies if you do not configure
envoy..reloadable_features. tls_certificate_compression_brotli
A security-focused release with fixes for multiple Envoy components, extensions, protocols, and dependencies. It also disables the broken envoy. contrib extension at the Bazel layer for all builds and platforms.
Action needed (1)
securityhigh
com_github_wasmtimedependency update, CVE-2026-47261The
com_github_wasmtimedependency was bumped to resolve CVE-2026-47261.
Check if affected (16)
securityhigh
REQUESTED_SERVER_NAMEcrash fix, CVE-2026-47220Applies if you configure
REQUESTED_SERVER_NAME.securityhighzstd RLE zip bomb fix, CVE-2026-48044
Applies if you depend on
zstd.securityhighHighly nested JSON destructor stack overflow fix, CVE-2026-48042
Applies if you use JSON.
- + 13 more on the release page
A security-focused release with fixes for crashes, request handling, protocol processing, authentication, and parsing, plus a security-related wasm dependency update. The contrib extension envoy. is disabled in all builds.
Action needed (1)
securityhighHighly nested JSON destructor stack overflow
The stack overflow in the destructor of highly nested JSON is corrected in connection with CVE-2026-48042 and GHSA-f24p-rxw2-g6pv.
Check if affected (15)
securityhighzstd RLE zip bomb correction
Applies if you use
zstd.securityhighHTTP/3 to HTTP/1 request smuggling
Applies if you use
HTTP/3andHTTP/1.securityhigh
com_github_wasmtimedependency updateApplies if you use
wasm.- + 12 more on the release page
A security-focused maintenance release with fixes across filters, protocol handling, request processing, and JSON parsing. It also updates the Wasmtime dependency and disables the contrib extension envoy..
Action needed (1)
securityhighHighly nested JSON destructor stack overflow, corrected for CVE-2026-48042
This release corrects the stack overflow in the destructor of highly nested JSON described by CVE-2026-48042 and GHSA-f24p-rxw2-g6pv.
Check if affected (14)
securityhighzstd RLE zip bomb, corrected for CVE-2026-48044
Applies if you use
zstd.securityhighHTTP/3 headers-only content-length validation, corrected for CVE-2026-48743
Applies if you use
HTTP/3.securityhigh
com_github_wasmtimedependency update for CVE-2026-47261Applies if you use
wasm.- + 11 more on the release page
This edge release completes functionality for rate-limit-aware load balancing in Linkerd 2.20. It updates the proxy and several third-party dependencies, with no security advisories or security flaws identified.
Source ↗A release focused on CRD compatibility and Entity Operator watching defaults, with fixes for disclosed security vulnerabilities. It affects deployments using older CRD APIs or configuring cross-namespace watching.
Action needed (2)
securityhighFix for CVE-2026-55225
The release fixes CVE-2026-55225, also identified as GHSA-mw9r-p8xp-wx96.
securitymediumFix for CVE-2026-55226
The release fixes CVE-2026-55226, also identified as GHSA-r427-j2h7-wv3m.
Check if affected (2)
breakingSupported CRD API versions narrowed
Applies if you use the
v1beta2,v1beta1, orv1alpha1CRD APIs.breakingEntity Operator cross-namespace watching default
Applies if you configure
STRIMZI_ENTITY_OPERATOR_WATCHED_NAMESPACE_ENABLEDorwatchedNamespace.
A maintenance-focused release with correctness fixes, dependency updates, operator troubleshooting improvements, and a security fix for a namespace-bypass issue. It also removes obsolete Helm settings, so configurations using those values need review.
Check if affected (3)
securityWildcard namespace bypass for selectorless
ipBlockrules, fixedApplies if you configure
ipBlock.breakingThe
loadBalancer.Helm option, removedstandalone Applies if you configure
loadBalancer..standalone breakingThe
l2podAnnouncements.Helm value, replaced byinterface l2podAnnouncements.interfacePattern Applies if you configure
l2podAnnouncements.and enable L2 pod announcements.interface
Cilium v1.18.11 is a maintenance release with operator-relevant bug fixes and expanded information reporting for troubleshooting commands. It also updates dependencies, container images, and the proxy version, with no security advisories or explicitly described security flaws.
Source ↗Cilium v1.17.17 updates troubleshooting information, Helm chart configurability, proxy and dependency versions, and installation image digests. It also fixes retries for CiliumNode Get errors in multipool.
Source ↗