github cilium/cilium v1.7.5
1.7.5

latest releases: v1.13.15, v1.14.10, v1.15.4...
3 years ago

Summary of Changes

Minor Changes:

  • Add "--iptables-lock-timeout" to configure iptables --wait parameter (Backport PR #11855, Upstream PR #11701, @joestringer)
  • bump k8s dependencies to v1.15.12, v1.16.10 and v1.17.6 (#11680, @aanm)
  • cilium: Add CLI to introspect IP <-> Identity cache (Backport PR #11630, Upstream PR #11566, @joestringer)
  • connectivity-check: Do not perform hostport in standard check (Backport PR #11855, Upstream PR #11715, @tgraf)
  • daemon: Clarify log msg how to use only TCP socket-lb (Backport PR #11971, Upstream PR #11918, @brb)
  • Envoy is updated to release 1.13.2. (Backport PR #12009, Upstream PR #11973, @jrajahalme)
  • Support DNS matchPattern="*" to match "." (Backport PR #11855, Upstream PR #11633, @joestringer)

Bugfixes:

  • 'identity does not exist' warning messages are not logged if the allocation attempt is not at max (#11580, @djboris9)
  • Avoid duplication of generated toCIDRs when using a toServices based CNP (or CCNP) (Backport PR #11971, Upstream PR #11901, @aanm)
  • datapath: Accept proxy traffic if enable-endpoint-routes are enabled (Backport PR #11855, Upstream PR #11819, @tgraf)
  • datapath: Only NOTRACK proxy return traffic going to Cilium datapath (Backport PR #11971, Upstream PR #11899, @jrajahalme)
  • endpoint: Fix data races while accessing GetIdentity() (Backport PR #11971, Upstream PR #11941, @tgraf)
  • envoy: Take xds mutator lock for map access (Backport PR #11630, Upstream PR #11541, @jrajahalme)
  • etcd: Increase status check timeout to 10 seconds (Backport PR #11855, Upstream PR #11750, @tgraf)
  • Fix issue when Cilium randomly stops doing service translation in k8s 1.18 (Backport PR #12019, Upstream PR #11947, @aanm)
  • Fix issue where Cilium-agent fails to start on nodes without a default gateway (Backport PR #11855, Upstream PR #11632, @soumynathan)
  • Fix issue where traffic from a pod could be dropped despite allow policy when DNS L7 rules are used (Backport PR #11855, Upstream PR #11764, @joestringer)
  • Fix leaking endpoint state metric (Backport PR #11930, Upstream PR #11884, @christarazi)
  • Fix pre-flight deployment for users upgrading from < 1.7 (Backport PR #11630, Upstream PR #11599, @aanm)
  • fix transparent encryption related bugs (Backport PR #12019, Upstream PR #11974, @jrfastab)
  • IPAM related bugfixes (Backport PR #11766, Upstream PR #10587, @tgraf)
  • ipcache: Fix deadlock when ipcache GC results in datapath reload (Backport PR #11971, Upstream PR #11950, @tgraf)
  • Istio integration has been updated to Istio release 1.5.4 (Backport PR #11630, Upstream PR #11530, @jrajahalme)
  • Properly cancel endpoint creations as they become obsolete (Backport PR #11971, Upstream PR #11920, @tgraf)
  • proxy: Do not decrement proxy port reference count when reverting. (Backport PR #11855, Upstream PR #11753, @jrajahalme)
  • proxy: Keep DNS port allocated (Backport PR #11855, Upstream PR #11661, @jrajahalme)
  • service: Fix wrong localEndpoints count in HealthCheckNodePort (Backport PR #11906, Upstream PR #11863, @gandro)

CI Changes:

Misc Changes:

Other Changes:

Don't miss a new cilium release

NewReleases is sending notifications on new releases.