Cilium
v1.18.6Networking & Messaging2026년 1월 13일
이번 v1.18.6에서는 점검 과정의 검사 항목이 바뀝니다. `Cilium Preflight` 검사를 사용하는 환경에서 이 변경이 적용됩니다.
영향 확인 (1)
breaking
Cilium Preflight검사에서Envoy Configmaps제외Cilium Preflight검사를 사용하는 경우에 적용됩니다.Cilium Preflight검사에서Envoy Configmaps를 더는 검사 항목에 넣지 않아 올바르게 실행하기 쉬워졌습니다.
그 외 기록된 변경 21건 전체fixes 10 · value changes 6 · additions 2 · constraints 2 · renames 1
fixes (10)
- bpf:wireguard: delivery host packets to bpf_host for ingress policies
- cgroup: don't start watch if KPRConfig.EnableSocketLB is disabled
- Fix a bug with local redirect service entries being created when backend pods weren't ready.
- Fix an issue in proxy NOTRACK iptables rule for aws-cni chaining mode which causes proxy->upstream(outside cluster) traffic not being SNAT'd.
- Fix GC of possible duplicated identities in kvstore mode
- Fixes a deadlock that was causing endpoint to be stuck without progressing with any updates.
- gateway-api: correctly handle CiliumGatewayClassConfig as a namespaced resource.
- xds: fix nil-pointer in
processRequestStream - bpf: prevent cluster ID from being incorrectly retrieved from mark when aliased
- Fix a regression in the new services control plane where loadBalancerSourceRanges was applied by default to all service types.
value changes (6)
- bpf: clear mark content before storing the cluster ID
- chore(deps): update quay.io/cilium/cilium-envoy docker tag to …×2
- the K8s Secret synchronization process now resynchronizes after an hour for synced Secrets.
- deps: bump CNI plugins version to v1.9.0
- install: Update image digests for v1.18.5
additions (2)
- Publish Helm charts to OCI registries
- Add libatomic1 for cilium-envoy dependency
constraints (2)
- route: install ingress proxy routes with WireGuard and L7Proxy
- bpf:hubble: support policy verdict from L3 devices
renames (1)
- release: change OCI registry
Cilium 스택에 추가
조치가 필요한 릴리스가 나왔을 때 주간 메일로 알려드립니다. 이번 릴리스의 브레이킹 체인지 같은 것들입니다.