Cilium
v1.18.6Networking & Messaging2026年1月13日
v1.18.6では、運用時のチェック対象が見直されています。`Cilium Preflight`チェックを利用する環境では、確認内容が従来と異なります。
影響確認 (1)
breaking
Cilium PreflightからEnvoy Configmapsを除外Cilium Preflightチェックを使用している場合に適用されます。Cilium PreflightチェックにEnvoy Configmapsが含まれなくなり、正しく実行しやすくなりました。
その他の記録済み変更 21 件すべてfixes 10 · value changes 6 · additions 2 · constraints 2 · renames 1
fixes (10)
- bpf:wireguard: delivery host packets to bpf_host for ingress policies
- cgroup: don't start watch if KPRConfig.EnableSocketLB is disabled
- Fix a bug with local redirect service entries being created when backend pods weren't ready.
- Fix an issue in proxy NOTRACK iptables rule for aws-cni chaining mode which causes proxy->upstream(outside cluster) traffic not being SNAT'd.
- Fix GC of possible duplicated identities in kvstore mode
- Fixes a deadlock that was causing endpoint to be stuck without progressing with any updates.
- gateway-api: correctly handle CiliumGatewayClassConfig as a namespaced resource.
- xds: fix nil-pointer in
processRequestStream - bpf: prevent cluster ID from being incorrectly retrieved from mark when aliased
- Fix a regression in the new services control plane where loadBalancerSourceRanges was applied by default to all service types.
value changes (6)
- bpf: clear mark content before storing the cluster ID
- chore(deps): update quay.io/cilium/cilium-envoy docker tag to …×2
- the K8s Secret synchronization process now resynchronizes after an hour for synced Secrets.
- deps: bump CNI plugins version to v1.9.0
- install: Update image digests for v1.18.5
additions (2)
- Publish Helm charts to OCI registries
- Add libatomic1 for cilium-envoy dependency
constraints (2)
- route: install ingress proxy routes with WireGuard and L7Proxy
- bpf:hubble: support policy verdict from L3 devices
renames (1)
- release: change OCI registry
Ciliumをスタックに追加
対応が必要なリリースが出たときに、週次メールでお知らせします。 今回の破壊的変更も、その一例です。