2.1.0-rc1 (September 29, 2026)
NOTE: Consul K8s 2.1.x is compatible with Consul 2.1.x and Consul Dataplane 2.1.x. Refer to our compatibility matrix for more info.
SECURITY:
- security: update
apisubmodule, and upgradegoogle.golang.org/grpcto v1.83.2,golang.org/x/cryptoto v0.57.0, andgo-discoverto v1.5.0 to address CVEs reported in binary and container scans. [GH-5690] - security: upgrade Python dependencies in the custom gateway-api 0.7.1 module: tornado 6.5.7 -> 6.5.8 to fix GHSA-mpf4-983q-p7j4 (CVE-2026-82397) urlencoded POST body DoS and GHSA-8423-8fgw-73vq multipart form-data memory amplification DoS; mkdocs-material 9.1.12 -> 9.7.7 to fix GHSA-xvg9-69gf-fjrf (CVE-2026-73295) DOM-based XSS in search.suggest; also bumps mkdocs-material-extensions 1.1.1 -> 1.3.1 and Pygments 2.15.1 -> 2.21.0 [GH-5661]
FEATURES:
- api-gateway: Add
RouteUpstreamLimitsFilterCRD and gateway-wide annotation defaults to configure per-service upstream circuit-breaker limits (maxConnections,maxPendingRequests,maxConcurrentRequests) and passive health checks (Envoy outlier detection) on API Gateway backends. [GH-5596] - api-gateway: Add support for
http2andgrpclistener protocols via a per-section annotation on the KubernetesGatewayobject (api-gateway.consul.hashicorp.com/listener-<sectionName>-protocol). Each listener can now independently select its Consul protocol, enabling Envoyhttp2_protocol_optionsand gRPC-specific filters (grpc_stats,grpc_http1_bridge) to be generated for the appropriate listeners. [GH-5594] - api-gateway: Add support for zero-touch downstream TLS termination via the
consul.hashicorp.com/tls-enabled: "true"annotation. When set on aGatewayresource, Consul automatically uses the gateway's Connect leaf certificate to terminate HTTPS — nocertificateRefsor operator-managedSecretrequired. The leaf certificate carries*.api-gateway.<domain>wildcard DNS SANs. Combined with Consul DNS auto-registration (<service>.api-gateway.consul), clients inside the cluster can reach mesh-registered services over CA-verified HTTPS without any manual certificate management. [GH-5597] - api-gateway: add
RouteHeaderMatchInvertFilterCRD to support negated HTTP header match conditions (Invert=true) on API GatewayHTTPRouterules, enabling "route when header is absent" and "route when header value does NOT match" patterns via anExtensionReffilter. [GH-5593] - api-gateway: upgrade the api-gateway operator to support tcproute under v1 under package version 1.6.0 of gateway-api [GH-5532]
- crd: Add
ECDHCurvesfield and OpenAPI validation toMeshDirectionalTLSConfiginMeshCRD for post-quantum hybrid key exchange (X25519MLKEM768). [GH-5639] - helm: Add
global.globalRegistryHelm values to configure Consul server integration with an external global registry service, including support for authenticating via a Kubernetes secret token. [GH-5633] - helm: add
global.acls.authMethod.createto allow using Kubernetes auth methods that were configured outside of the Helm release. When set tofalse, theserver-acl-initjob requires the auth methods to already exist and only manages the ACL policies, roles and binding rules. [GH-5611] - helm: add
global.acls.authMethod.nameto configure the base name of the Kubernetes auth methods created by theserver-acl-initjob. Set this to a unique value per Kubernetes cluster when multiple clusters share a single Consul control plane, so that the clusters do not overwrite each other's auth methods. [GH-5611] - metrics: add a new
consul.hashicorp.com/service-metrics-endpointsannotation that accepts a comma-separated list ofport:pathpairs, allowing a single container to expose metrics on multiple ports for metrics merging. Takes precedence overconsul.hashicorp.com/service-metrics-portandconsul.hashicorp.com/service-metrics-path, which continue to work unchanged. [GH-5664]
IMPROVEMENTS:
- helm: add
global.imageApplyManifestsvalue to allow overriding the container image used by the post-upgrade apply-manifests Job, enabling use of air-gapped or security-approved images in place of the defaultbitnami/kubectl:latest(non-OpenShift) orregistry.redhat.io/openshift4/ose-cli(OpenShift). [GH-5673] - control-plane: Migrate traffic redirection from
iptables/ip6tablestonftables. This requires thenftbinary and Linux kernel support for stateful NAT innftablesinetchains (Linux 5.2+ or distro backports); hosts without this support will fail to set up transparent-proxy traffic redirection. [GH-5554]