artifacthub helm/cilium/cilium 1.8.6

latest releases: 1.16.0-pre.2, 1.15.4, 1.14.10...
3 years ago

Summary of Changes

Major Changes:

  • change default docker image repository from docker.io to quay.io (Backport PR #14022, Upstream PR #13937, @aanm)

Minor Changes:

Bugfixes:

  • bpf: Fix --force-local-policy-eval-at-source=false (Backport PR #13875, Upstream PR #13769, @joestringer)
  • bpf: fix disable PolicyVerdictNotification broken (Backport PR #13951, Upstream PR #13921, @ArthurChiao)
  • ctmap: GC orphan SNAT entries (Backport PR #14022, Upstream PR #13912, @brb)
  • Fix bug in cluster-pool IPAM mode where the user is never alerted of a node CIDR allocation failure (Backport PR #14022, Upstream PR #13916, @christarazi)
  • Fix bug where Cilium on smaller instance types cannot allocate IPs (Backport PR #14059, Upstream PR #13865, @christarazi)
  • Fix dynamic NAT table size calculation if CT map sizes are configured statically. (Backport PR #13875, Upstream PR #13844, @tklauser)
  • Fix etcd's auth token invalid after watch reconnects (Backport PR #14249, Upstream PR #14238, @aanm)
  • Fix panic on cilium-agent startup when restoring LB source range maps (Backport PR #13875, Upstream PR #13842, @aanm)
  • Fixed Goroutine leak for unresponded ARP pings. (Backport PR #14249, Upstream PR #14222, @jrajahalme)
  • Fixed installation instructions for K3s and Kubernetes Network Policy enforcement (Backport PR #13875, Upstream PR #13783, @aanm)
  • FQDN rule restoration IP limit has been made configurable (--tofqdns-max-ips-per-restored-rule, default 1000). (Backport PR #14022, Upstream PR #13992, @jrajahalme)
  • fqdn: Add a nil check for security id lookup (Backport PR #13951, Upstream PR #13886, @aditighag)
  • fqdn: Delay ipcache upserts until policies have been updated (Backport PR #14213, Upstream PR #14110, @jrajahalme)
  • fqdn: keep IPs alive if their name is alive (Backport PR #13951, Upstream PR #13914, @kkourt)
  • go.mod: update cilium/ipam library with bug fixes (Backport PR #13875, Upstream PR #13810, @aanm)
  • Hubble-relay now proxies the GRPC context to its servers. (Backport PR #13951, Upstream PR #12865, @nathanjsweet)
  • hubble/parser: Always preserve datapath numeric identity (Backport PR #14213, Upstream PR #14090, @gandro)
  • hubble: Fix reply state unknown being interpreted as false (Backport PR #13876, Upstream PR #13750, @gandro)
  • Increment the default value of maximum garbage collected security identities from 250 to 2500 per minute (Backport PR #13951, Upstream PR #13907, @aanm)
  • kpr: ensure DirectRoutingDevice is in devices (Backport PR #14249, Upstream PR #14054, @kkourt)
  • Trim spaces from loadBalancerSourceRanges when parsing its values. (Backport PR #14059, Upstream PR #13996, @aanm)

CI Changes:

Misc Changes:

Other Changes:

  • [v1.8] backporting: Escape commit message when used as regex (#13873, @tklauser)
  • [v1.8] contrib: Sort authors without depending on locale (#13802, @christarazi)
  • v1.8: hubble/relay: flush old flows when the buffer drain timeout is reached (#13877, @rolinh)

Don't miss a new cilium release

NewReleases is sending notifications on new releases.