github kubernetes-sigs/gateway-api v1.7.0-rc.1

pre-release5 hours ago

Major Themes

Graduating to Standard

  • HTTPRoute Retries (GEP-1731): the retry configuration of an HTTPRoute rule (codes, attempts and backoff) is promoted to the Standard channel, together with the HTTPRouteRetryCodes and HTTPRouteRetryConnectionError conformance features. The backoff field is implementation-specific because backoff behavior, especially jitter, varies between implementations. (#5357, @snorwin, #5359, @mikemorris)

New in Experimental

  • Gateway Address Routability (GEP-5093): routability is expressed per Gateway address, so a single Gateway can serve addresses of different scopes. Valid values are empty (implementation default), Cluster, or a domain-prefixed implementation-specific value. (#5304, @rikatz)
  • Standardized Attribute Dictionary (GEP-5253): a shared, vendor-neutral set of traffic attributes, based on OpenTelemetry semantic conventions, for use by features such as XTelemetryPolicy. (#5256, @gkhom)
  • Session Persistence on Backend (GEP-1619 and GEP-4894): session persistence is configured on the XBackend resource, and the route-inline and BackendTrafficPolicy attachment points are deprecated. (#4876, #5298, @gcs278)
  • Pre-routing Filters (GEP-5224): listener filters that run before routing decisions, for use cases such as external authentication and payload processing, with the new GatewayListenerFilters feature. (#5315, @jaellio)
  • ClusterTrustBundle in caCertificateRefs (GEP-5075): BackendTLSPolicy and Gateway frontend TLS validation can reference a ClusterTrustBundle through the existing caCertificateRefs field, instead of copying CA bundles into every namespace. (#5272, #5356, @davidesalerno)
  • TelemetryPolicy for Distributed Tracing (GEP-4768): the XTelemetryPolicy API standardizes tracing configuration for Gateways without vendor-specific CRDs. Metrics and access logs are not covered yet. (#5323, @gkhom)

Major Changes Since v1.6.3

Breaking Changes

  • Experimental API changes (no effect on the Standard channel):
    • SessionPersistence API: sessionName moved to cookie.name (Extended, optional) and header.name (Core, required), cookieConfig renamed to cookie, and HeaderConfig added. (#4873, @gcs278)
    • SessionPersistence API: the cookie Path now defaults to / instead of being computed from route matches, and the new cookie.path field (Extended) allows explicit path configuration. (#5046, @gcs278)
    • SessionPersistence: route-inline and BackendTrafficPolicy session persistence are deprecated in favor of the Backend resource. (#4876, @gcs278)
    • XBackend: spec.port.port was renamed to spec.port.number, spec.port.name was removed, and backendRef.port is now prohibited when referencing an XBackend. (#5287, @gcs278)
  • Go types:
    • BackendAncestorStatus.AncestorRef was renamed in the generated Go types for consistency with docs and JSON/YAML serialization. (#5187, @Stevenjin8)
    • HTTPRouteRetry.Attempts is now a plain int (previously *int) that defaults to 1. (#5269, @snorwin)
    • ForwardBodyConfig.MaxSize changed type from uint16 to int32. (#5099, @arjunxplorer)
  • Conformance features:
    • The HTTPRouteRetry and HTTPRouteRetryBackendTimeout features were removed. HTTPRouteRetryCodes was added and HTTPRouteRetryConnectionError is retained. (#5167, @snorwin)
    • The HTTPRouteBackendRequestRedirect feature and its test were removed. (#5279, @snorwin)
  • Go was upgraded to 1.27 and Kubernetes dependencies to v0.37. (#5297, @snorwin, #5232, @snorwin)

GEP & API Graduation

Feature

  • New Experimental APIs and Fields:
    • Experimental XTelemetryPolicy API (GEP-4768). (#5323, @gkhom, #5345, @robscott)
    • XBackend supports a new EndpointSelector type that routes to in-cluster pods selected by label. (#5255, @gcs278)
    • XBackend supports session persistence for the EndpointSelector type. (#5298, @gcs278)
    • XBackend TLS mode was refactored and its CEL validation fixed. (#5316, @snorwin)
    • Gateway address routability (GEP-5093), including the GatewayAddressRoutability and GatewayAddressRoutabilityCluster features. (#5304, @rikatz)
    • Pre-routing listener filters (GEP-5224), with the new GatewayListenerFilters feature. (#5315, @jaellio)
    • ClusterTrustBundle can be referenced through caCertificateRefs in BackendTLSPolicy and Gateway frontend TLS validation, with the new ClusterTrustBundle feature. (#5272, @davidesalerno, #5356, @davidesalerno)
  • API & Validation Enhancements:
    • Added CEL validation enforcing that TLS is disabled for H2C and enabled for HTTP2. Added a new WSS protocol value for WebSockets over TLS. (#5312, @snorwin)
    • Added the GatewayRouteHostnameIntersectionPrecedence feature so implementations can opt in to resolving *Route precedence using the original Route hostnames instead of the calculated Listener/Route intersection. (#5212, @rostislavbobo)
    • Replaced immutable CEL validation rules with the +k8s:immutable marker. (#4902, @chinmaychahar)
  • Release Artifacts:
    • Releases now contain OpenAPIv2 schema definitions. (#4686, @Rycieos)

Documentation

  • New and Updated Documentation:
    • Added documentation for XBackend. (#4931, @keithmattix)
    • Added TCP and UDP examples and documentation. (#4932, @zac-nixon)
    • Added ListenerSet to the SectionName interpretation table. (#4880, @apkatsikas)
    • Stopped referring to ListenerSet as experimental. (#5228, @linuzctl)
    • Aligned the GRPCRoute hostname cross-serving godoc with the relaxed site docs. (#5176, @lexfrei)
    • Clarified that implementations should only retry HTTPRoute requests on connection errors when it is safe to do so, and that backoff specifies the base interval of a backoff strategy rather than the minimum interval. The precise backoff curve and jitter are implementation-specific, and implementations that retry immediately with no backoff must not advertise support for backoff. (#5269, @snorwin, #5359, @mikemorris)
    • Marked Upstream TLS (BackendTLSPolicy) as Standard channel since v1.4.0. (#4965, @anneheartrecord)
    • Corrected API groups in the GEP-709 ReferenceGrant example. (#5310, @deepujain)
    • Corrected conformance feature selection guidance. (#5175, @immanuwell)
    • Updated the API reference format for readability. (#5156, @youngnick)
  • Site & Project:
  • Implementations & Conformance Reports:
    • Added or updated conformance reports for Agentgateway, Airlock Microgateway, AWS Load Balancer Controller, Calico, Cilium, Cloudflare Tunnel Gateway Controller, GKE Gateway, Gravitee, Higress, Istio, Kgateway, Kong Operator, Linkerd, NGINX Gateway Fabric, Traefik Proxy and WSO2 Gateway.
    • Envoy Gateway moved to Conformant. (#5186, @zirain)
    • HAProxy Ingress was renamed to N42 Gateway. (#5268, @jcmoraisjr)

Bug or Regression

  • Fixed the generator so that inline references are supported on experimental validation, and fixed generator tag recognition for experimental markers. (#5288, #5303, @rikatz)
  • Fixed the backend port name CEL expression and added a unit test. (#5193, @snorwin)
  • Fixed an always-true scheme check in conformance redirect port validation. (#5201, @immanuwell)

Test & Conformance

  • New Conformance Tests:
    • Added a conformance test for GRPCRouteFilterRequestHeaderModifier (new GRPCRouteRequestHeaderModifier feature). (#4060, @salonichf5)
    • Added a BackendTLSPolicy conformance test for GRPCRoute. (#4882, @Thealisyed)
    • Added a BackendTLSPolicy with TLSRoute Terminate conformance test. (#4875, @davidesalerno)
    • Added a Gateway maximum name length conformance test. (#5035, @arjunexplorer)
    • Added an HTTPRoute rule precedence conformance test. (#5128, @thorn3r)
    • Added a conformance test covering shared and dedicated routes across multiple Gateways for GRPCRoute. (#5281, @snorwin)
    • Added conformance tests validating that Gateway resolves HTTPRoute precedence using original route hostname specificity rather than the calculated listener/route hostname intersection. (#5124, @rostislavbobo)
    • Added conformance tests validating that Gateway resolves GRPCRoute precedence using original route hostname specificity rather than the calculated listener/route hostname intersection. (#5346, @rostislavbobo)
    • Added conformance tests validating that Gateway resolves TLSRoute precedence using original route hostname specificity rather than the calculated listener/route hostname intersection. (#5361, @rostislavbobo)
    • Added conformance tests for URLRewrite filters at HTTPBackendRef level (HTTPRouteBackendURLRewrite). (#4823, @Srujan-rai)
    • Added unit tests for the echo response parser. (#4635, @archy-rock3t-cloud)
  • Test Machinery & Framework Updates:
    • The conformance suite now supports an injectable WebSocket dialer (ConformanceOptions.WebSocketDialer). It defaults to the previous websocket.Dial behavior when unset. (#4936, @lexfrei)
    • The conformance gRPC DefaultClient is now safe for concurrent SendRPC and reusable after Close. (#4946, @lexfrei)
    • Base-resource cleanup now waits for deletion to complete, so the suite can be re-run in a single process (go test -count>1). (#4948, @lexfrei)
    • RouteMustHaveParents now runs the observedGeneration check against the status it just read. Implementations whose status lags the Route generation may now fail where they previously passed. (#5206, @lexfrei)
    • Report an error when a conformance manifest is missing from every configured filesystem. (#5216, @immanuwell)
    • Conformance report Implementation.URL is now validated as a well-formed http(s) URL. (#5209, @yashrajshuklaaa)
    • The conformance echo server images moved to a dedicated repository (kubernetes-sigs/gateway-api-conformance-images). (#5090, @snorwin)
    • Use the timeout config more consistently. (#5150, @howardjohn)
    • Preserve = in conformance key-value flags. (#5034, @immanuwell)
  • Updates & Fixes to Existing Tests:
    • Expect RefNotPermitted for a cross-namespace certificateRef to a nonexistent secret. (#5306, @PetrMc)
    • Wait for mesh weighted routes to be programmed. (#5214, @Automaat)
    • Retry the failure-path assertion in the client certificate validation test. (#5097, @yashrajshuklaaa)
    • Added containerPorts to the echo pod in the mesh conformance manifest. (#5055, @AnirbanNandi)
    • Foreign status entries on HTTPRoutes, BackendTLSPolicy and Gateway are now preserved by conformance tests. (#5206, @lexfrei)
    • Removed the HTTPRoute retry tests that required unsafe retries and added a retry-with-backend-timeout case. (#5339, @snorwin)

Other (Cleanup or Flake)


Dependencies

Only changes to modules directly required by the root, conformance, tests and tools modules are listed below.

Changed

  • github.com/miekg/dns: v1.1.72 → v1.1.73
  • github.com/stretchr/testify: v1.11.1 → v1.12.1
  • golang.org/x/mod: v0.36.0 → v0.41.0
  • golang.org/x/net: v0.55.0 → v0.59.0
  • golang.org/x/sync: v0.20.0 → v0.23.0
  • golang.org/x/tools: v0.45.0 → v0.50.0
  • google.golang.org/grpc: v1.81.1 → v1.84.0
  • k8s.io/api: v0.36.1 → v0.37.0
  • k8s.io/apiextensions-apiserver: v0.36.1 → v0.37.0
  • k8s.io/apimachinery: v0.36.1 → v0.37.0
  • k8s.io/client-go: v0.36.1 → v0.37.0
  • k8s.io/code-generator: v0.36.1 → v0.37.0
  • k8s.io/kube-openapi: 927ab1f → d427ff9
  • k8s.io/utils: 28399d8 → be93311
  • sigs.k8s.io/controller-runtime: v0.24.1 → v0.25.1
  • sigs.k8s.io/controller-tools: v0.21.0 → v0.22.0
  • sigs.k8s.io/structured-merge-diff/v6: v6.4.0 → v6.4.2
  • sigs.k8s.io/gateway-api-conformance-images: added at v0.1.0

Don't miss a new gateway-api release

NewReleases is sending notifications on new releases.