⚠️ Action Required
CRD Updates (Required)
There is no Gateway API graduation in this release -- the controller remains built against Gateway API CRDs v1.6.0 (unchanged from v3.5.0). As a safety measure, we recommend applying the latest AWS-vended CRDs before upgrading the controller.
Apply the latest AWS-vended CRD definitions:
Action :
kubectl apply -k "github.com/aws/eks-charts/stable/aws-load-balancer-controller/crds?ref=master"kubectl apply -f https://raw.githubusercontent.com/kubernetes-sigs/aws-load-balancer-controller/refs/heads/main/config/crd/gateway/gateway-crds.yaml
🚀 What's New
Cross-account TargetGroupBinding -- AZ-aware IP registration (opt-in)
Cross-account TargetGroupBinding IP targets can now be registered with the pod's actual Availability Zone, improving cross-account zonal routing. Opt-in to preserve existing behavior by default. (#4877, @cqi1217)
frontend-nlb-status-only annotation for Ingress
New annotation to control whether the Ingress status hostname exposes only the frontend NLB -- fixes ExternalDNS record creation when fronting an ALB Ingress with an NLB. If the NLB is not yet provisioned, no hostname is written. (#4849, @dominikhei)
Gateway API customization for downstream/automode importers
Importers embedding the controller can now customize Gateway names, customize finalizers, and customize the Gateway controller wiring - enabling consumers to extend Gateway behavior. ReferenceGrant now uses the v1 apiVersion. (#4878, #4886, #4887, @zac-nixon)
🔧 Enhancements and Fixes
Gateway
- Avoid
DuplicateTargetGroupNamefor Services with multiple named target ports (#4876) - Use
v1for the ReferenceGrant apiVersion; allow finalizers to be customized (#4886) - Use a
/separator in Gateway route-loader cache keys to avoid cache-key collisions (#4916) - Fix the deletion guard for Gateway
TargetGroupConfigurations still referenced by TCPRoutes (#4802) - Ignore unpermitted cross-namespace TCPRoutes in the Gateway TGC deletion guard, so a TCPRoute without a
ReferenceGrantcan no longer pin another namespace's TGC finalizer (#4919)
**AWS Certificates Management **
- Use the public Route 53 zone for Amazon-issued ACM DNS validation in split-horizon DNS setups (#4847)
Networking / TargetGroupBinding
- Canonicalize CIDRs for security-group inbound rules to avoid spurious reconciliation failures (#4904)
- Fix TargetGroupBinding networking with empty ports (#4909)
WAF
- Ignore a WAF ACL set to an empty string (treat as unset) (#4888)
Controller / Informer robustness
- Handle
DeletedFinalStateUnknowntombstones inTypedInformer'sDeleteFunc(#4879) - Make the pod informer transform idempotent so WatchList streaming sync no longer falls back to a full
LIST(#4881)
Misc
- Clearer OIDC permission messaging (#4912)
📖 Documentation Updates
- Warn against manually deleting controller-generated
TargetGroupBindingobjects (#4902) - Document security/trust implications of
AllowedRoutes.Namespaces.From: All(#4872) - Remove unsupported
vpcIdfield fromLoadBalancerConfigurationdocs (#4760) - Fix wrong default for
frontend-nlb-eip-allocationsin annotation docs (#4871) - Fix
ipam-ipv4-pool-idexample plus tip/note block spacing (#4752)
What's Changed
- Document security/trust implications of AllowedRoutes.Namespaces.From… by @wweiwei-li in #4872
- docs: Remove vpcId from LoadBalancerConfiguration documentation by @dominikhei in #4760
- fix(gateway): avoid DuplicateTargetGroupName for Services with multiple named targetPorts by @legal90 in #4876
- fix: ipam-ipv4-pool-id example, tip and note block spacing by @wind0r in #4752
- feat(gateway custom): allow importers to customize gateway names by @zac-nixon in #4878
- fix: handle DeletedFinalStateUnknown tombstones in TypedInformer's DeleteFunc by @ginbear in #4879
- Make pod informer transform idempotent so WatchList streaming sync does not fall back to full LIST by @yash97 in #4881
- use v1 for referencegrant apiversion, allow finalizers to be customized for gateway api by @zac-nixon in #4886
- refactor: Allow automode controllers to customize the gateway controller by @zac-nixon in #4887
- fix(waf): ignore waf acl set to empty string by @zac-nixon in #4888
- refactor: making tests configurable to run on eks auto framework by @jupdec in #4891
- test: mirror UDP/GRPC test images to networking-e2e-test-images by @jupdec in #4894
- test/gateway: make e2e suite partition-aware and register ECR tag resolver by @jupdec in #4908
- chore: OIDC permission messaging by @zac-nixon in #4912
- fix: canonicalize CIDRs for security group inbound rules to avoid reconciliation failures by @bobert-2 in #4904
- test: default GRPC/UDP images to public ECR to fix the tests by @shraddhabang in #4911
- Fix TGB networking with empty ports by @dlanov in #4909
- docs: warn against manually deleting controller-generated TargetGroupBinding by @shashankvarma499 in #4902
- Register cross-account TargetGroupBinding IP targets with the pod's availability zone (opt-in) by @cqi1217 in #4877
- Fixed wrong default for frontend-nlb-eip-allocations in annotation docs by @dominikhei in #4871
- Added frontend-nlb-status-only annotation to fix ExternalDNS record creation when using a frontend NLB by @dominikhei in #4849
- fix: use '/' separator in Gateway route-loader cache keys to avoid co… by @wweiwei-li in #4916
- fix: use public Route 53 zone for Amazon-issued ACM DNS validation in split-horizon DNS by @niv1612 in #4847
- Fix deletion guard for Gateway TargetGroupConfigurations still referenced by TCPRoutes by @immanuwell in #4802
- fix: ignore unpermitted cross namespace TCPRoutes in gateway target TGC deletion guard by @shraddhabang in #4919
- cut v3.6.0 release by @shraddhabang in #4921
New Contributors
- @dominikhei made their first contribution in #4760
- @legal90 made their first contribution in #4876
- @wind0r made their first contribution in #4752
- @ginbear made their first contribution in #4879
- @yash97 made their first contribution in #4881
- @dlanov made their first contribution in #4909
- @shashankvarma499 made their first contribution in #4902
- @cqi1217 made their first contribution in #4877
- @niv1612 made their first contribution in #4847
Full Changelog: v3.5.0...v3.6.0