A maintenance release with a Linkerd proxy version update. It has no explicitly stated operator behavior change.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
A maintenance release focused on correctness fixes, reliability improvements, dependency updates, and additive configuration and integration capabilities. It contains no disclosed vulnerability details.
Source ↗A maintenance release focused on correctness fixes and dependency updates, with a small number of new extension points. It does not introduce broad operator-facing configuration changes.
Action needed (1)
breakingRemoval of the
Ingress HostFW PolicybetweenRevSNATandRevDNATThe BPF NodePort path removes the
Ingress HostFW PolicybetweenRevSNATandRevDNAT.
A maintenance release focused on bug fixes, dependency updates, and image refreshes. It also removes a datapath behavior and includes security dependency fixes that may require operator attention.
Action needed (3)
securityThe
google.module, updated to v1.83.1golang. org/grpc The
google.module is updated to v1.83.1 in this release as a security dependency fix.golang. org/grpc securityThe
google.module, updated to v1.83.2golang. org/grpc The
google.module is updated to v1.83.2 in this release as a security dependency fix.golang. org/grpc breakingThe
Ingress HostFW Policybetween RevSNAT and RevDNAT, removedThe
Ingress HostFW Policybetween RevSNAT and RevDNAT is removed in this release.
A maintenance release focused on JetStream compatibility, performance improvements, and correctness fixes. It also updates the toolchain and dependencies, with no stated operator-breaking changes.
Source ↗A maintenance release focused on dependency upgrades, including proxy-init and CNI components. It does not state changes to operator behavior.
Source ↗A maintenance release that enables gRPC capabilities and observability, broadens xDS matching, removes a WRR guard, and corrects proxy hostname handling. It also updates connection scaling service configuration and server listener matching.
Action needed (2)
breakingThe
v2_non_owning_waker_implementationexperiment enabledThe
v2_non_owning_waker_implementationexperiment is enabled in the promise-based filter.breakingThe
WRRcustom backend metrics guard removedThe release removes the
WRRenvironment-variable guard for custom backend metrics.
A security maintenance release updates Envoy, Go, and other dependencies to address CVEs. It is tested against Kubernetes 1.32 through 1.34, with no stated operator configuration changes.
Action needed (3)
securityThe
Envoyversion, updated tov1.38. 4 Envoyis updated tov1.to address CVEs. The update ships in this release.38. 4 securityThe
Goversion, updated to1.26. 8 Gois updated to1.to address CVEs. The update ships in this release.26. 8 securityDependency updates for CVE fixes
Dependencies are updated to address CVEs. The dependency updates ship in this release.
A maintenance release updates the proxy and dependencies, fixes destination behavior, and tightens multicluster credential and Link resource handling. The changes concern proxy, destination, and multicluster components, alongside routine dependency updates.
Action needed (2)
breakingCluster credential secrets and the
execauth providerCluster credential secrets created by
linkerd multicluster linkuse the token auth provider. Theexecauth provider is disallowed because it is not used or necessary.breaking
Linkresource lookup scopeLinkresource lookups are restricted to thelinkerd-multiclusternamespace.
A small maintenance release that clarifies the CNI specification, adds STATUS error codes and execution-error behavior, and improves tolerance of invalid cached data.