github cilium/cilium v1.10.6
1.10.6

latest releases: v1.16.0-rc.0, 1.16.0-rc.0, v1.13.17...
2 years ago

We are pleased to announce the Cilium v1.10.6 release. This release fixes several known issues in the areas of FQDN policy, Egress Gateway and IPsec which may lead to packet loss in particular circumstances. Additionally, the resource usage of Cilium and the handling of multiple devices on the node have been improved. For full details, see the release notes below.

Summary of Changes

Minor Changes:

Bugfixes:

  • Adds an ACCEPT rule for untracked pkts in filter:CILIUM_OUTPUT (Backport PR #17861, Upstream PR #17585, @Weil0ng)
  • bpf: exclude pod's reply traffic from egress gateway logic (Backport PR #17985, Upstream PR #17869, @jibi)
  • bug/pkg/health: Fix Nil Address Issue in Node Update Mechanism (Backport PR #17861, Upstream PR #17667, @nathanjsweet)
  • bugtool: fix data race occurring when running commands (Backport PR #17985, Upstream PR #17916, @rolinh)
  • bugtool: fix IP route debug gathering commands (Backport PR #18066, Upstream PR #18059, @tklauser)
  • daemon, node: Remove old, discarded router IPs from cilium_host (Backport PR #18088, Upstream PR #17762, @christarazi)
  • Define operator feature flags to allow the operator to register related CRDs. (Backport PR #17861, Upstream PR #17772, @pchaigno)
  • egressgateway: Allow several CENPs with same egress IP (Backport PR #17861, Upstream PR #17773, @pchaigno)
  • egressgateway: fix manager logic (Backport PR #18082, Upstream PR #17813, @jibi)
  • Fix bug where the agents would silently skip all IPv6 masquerading due to an incorrect configuration. (Backport PR #17985, Upstream PR #17906, @pchaigno)
  • Fix identity leak via FQDN selectors (Backport PR #17861, #17987, #18189, Upstream PRs #17699, #17788, #18166, @joestringer)
  • Fix incorrect application of egress gateway policy to internal cluster traffic. Require a 5.2 kernel or later for the egress gateway policy feature. (Backport PR #17861, Upstream PR #17639, @kkourt)
  • Fix issue where local host IPs may be briefly associated with the remote-node identity, causing policy drops when policy should allow traffic from the host. (Backport PR #17861, Upstream PR #17836, @joestringer)
  • Fix several complexity and program size issues when only one of IPv4/IPv6 is enabled. (Backport PR #17652, Upstream PR #17573, @pchaigno)
  • Fixes an issue which can cause traffic to be dropped when running Cilium in ENI mode due to the presence of iptables rules left over by the AWS VPC CNI plugin. Notable features that could be impacted include the egress gateway functionality. (Backport PR #17985, Upstream PR #17845, @bmcustodio)
  • Fixes for IPsec and endpoint routes (Backport PR #17985, Upstream PR #17865, @kkourt)
  • node-init: cleanup snat iptables rules when running in eni mode with masquerading disabled (Backport PR #17861, Upstream PR #16840, @bmcustodio)
  • node: Skip ipcache for remote node IPs if IPsec is enabled (Backport PR #17652, Upstream PR #17511, @pchaigno)

CI Changes:

Misc Changes:

Docker Manifests

cilium

docker.io/cilium/cilium:v1.10.6@sha256:cf52b14bf9bc62e4eb1967661a51e5f5482cbb05b784c0a0e38ee16d66f85773
quay.io/cilium/cilium:v1.10.6@sha256:cf52b14bf9bc62e4eb1967661a51e5f5482cbb05b784c0a0e38ee16d66f85773
docker.io/cilium/cilium:stable@sha256:cf52b14bf9bc62e4eb1967661a51e5f5482cbb05b784c0a0e38ee16d66f85773
quay.io/cilium/cilium:stable@sha256:cf52b14bf9bc62e4eb1967661a51e5f5482cbb05b784c0a0e38ee16d66f85773

clustermesh-apiserver

docker.io/cilium/clustermesh-apiserver:v1.10.6@sha256:07e0ba11f74b8ea00303a3705457994f99e64e423b0ebe7f0e1bfda7a3493dec
quay.io/cilium/clustermesh-apiserver:v1.10.6@sha256:07e0ba11f74b8ea00303a3705457994f99e64e423b0ebe7f0e1bfda7a3493dec
docker.io/cilium/clustermesh-apiserver:stable@sha256:07e0ba11f74b8ea00303a3705457994f99e64e423b0ebe7f0e1bfda7a3493dec
quay.io/cilium/clustermesh-apiserver:stable@sha256:07e0ba11f74b8ea00303a3705457994f99e64e423b0ebe7f0e1bfda7a3493dec

docker-plugin

docker.io/cilium/docker-plugin:v1.10.6@sha256:c48995fe2666cb73f12dc51200d6d05fa11ecb566d9cf978db4cac47ec77746b
quay.io/cilium/docker-plugin:v1.10.6@sha256:c48995fe2666cb73f12dc51200d6d05fa11ecb566d9cf978db4cac47ec77746b
docker.io/cilium/docker-plugin:stable@sha256:c48995fe2666cb73f12dc51200d6d05fa11ecb566d9cf978db4cac47ec77746b
quay.io/cilium/docker-plugin:stable@sha256:c48995fe2666cb73f12dc51200d6d05fa11ecb566d9cf978db4cac47ec77746b

hubble-relay

docker.io/cilium/hubble-relay:v1.10.6@sha256:4d8de723d64e5aecb9de2e12b624e50c0a4388d3e43f697f8e5781be33f7e888
quay.io/cilium/hubble-relay:v1.10.6@sha256:4d8de723d64e5aecb9de2e12b624e50c0a4388d3e43f697f8e5781be33f7e888
docker.io/cilium/hubble-relay:stable@sha256:4d8de723d64e5aecb9de2e12b624e50c0a4388d3e43f697f8e5781be33f7e888
quay.io/cilium/hubble-relay:stable@sha256:4d8de723d64e5aecb9de2e12b624e50c0a4388d3e43f697f8e5781be33f7e888

operator-alibabacloud

docker.io/cilium/operator-alibabacloud:v1.10.6@sha256:16ba99f0ac71562883d45760cb85957249a4f7f1238841ad3cee40a9b5f3a03c
quay.io/cilium/operator-alibabacloud:v1.10.6@sha256:16ba99f0ac71562883d45760cb85957249a4f7f1238841ad3cee40a9b5f3a03c
docker.io/cilium/operator-alibabacloud:stable@sha256:16ba99f0ac71562883d45760cb85957249a4f7f1238841ad3cee40a9b5f3a03c
quay.io/cilium/operator-alibabacloud:stable@sha256:16ba99f0ac71562883d45760cb85957249a4f7f1238841ad3cee40a9b5f3a03c

operator-aws

docker.io/cilium/operator-aws:v1.10.6@sha256:e78b6e2904b694ca08635d2485d5dcd342d06ee3d6a7ef6c5f31cd2901a8fd67
quay.io/cilium/operator-aws:v1.10.6@sha256:e78b6e2904b694ca08635d2485d5dcd342d06ee3d6a7ef6c5f31cd2901a8fd67
docker.io/cilium/operator-aws:stable@sha256:e78b6e2904b694ca08635d2485d5dcd342d06ee3d6a7ef6c5f31cd2901a8fd67
quay.io/cilium/operator-aws:stable@sha256:e78b6e2904b694ca08635d2485d5dcd342d06ee3d6a7ef6c5f31cd2901a8fd67

operator-azure

docker.io/cilium/operator-azure:v1.10.6@sha256:3c7e7a9e23d721e4845793ece54bcd1393ebcb9b3fdf3581a90796c95f356cc0
quay.io/cilium/operator-azure:v1.10.6@sha256:3c7e7a9e23d721e4845793ece54bcd1393ebcb9b3fdf3581a90796c95f356cc0
docker.io/cilium/operator-azure:stable@sha256:3c7e7a9e23d721e4845793ece54bcd1393ebcb9b3fdf3581a90796c95f356cc0
quay.io/cilium/operator-azure:stable@sha256:3c7e7a9e23d721e4845793ece54bcd1393ebcb9b3fdf3581a90796c95f356cc0

operator-generic

docker.io/cilium/operator-generic:v1.10.6@sha256:6bd47edc4d8f8b5b984509c68f5625a4141c0f5a4c8931f012b0453d9b62bd92
quay.io/cilium/operator-generic:v1.10.6@sha256:6bd47edc4d8f8b5b984509c68f5625a4141c0f5a4c8931f012b0453d9b62bd92
docker.io/cilium/operator-generic:stable@sha256:6bd47edc4d8f8b5b984509c68f5625a4141c0f5a4c8931f012b0453d9b62bd92
quay.io/cilium/operator-generic:stable@sha256:6bd47edc4d8f8b5b984509c68f5625a4141c0f5a4c8931f012b0453d9b62bd92

operator

docker.io/cilium/operator:v1.10.6@sha256:037441989e5b3b69893bd1112f5b79684758a1de4c5b793fd16011cbf7e0523b
quay.io/cilium/operator:v1.10.6@sha256:037441989e5b3b69893bd1112f5b79684758a1de4c5b793fd16011cbf7e0523b
docker.io/cilium/operator:stable@sha256:037441989e5b3b69893bd1112f5b79684758a1de4c5b793fd16011cbf7e0523b
quay.io/cilium/operator:stable@sha256:037441989e5b3b69893bd1112f5b79684758a1de4c5b793fd16011cbf7e0523b

Don't miss a new cilium release

NewReleases is sending notifications on new releases.