Major Themes
Graduating to Standard
- HTTPRoute Retries (GEP-1731): the
retryconfiguration of an HTTPRoute rule (codes,attemptsandbackoff) is promoted to the Standard channel, together with theHTTPRouteRetryCodesandHTTPRouteRetryConnectionErrorconformance features. Thebackofffield is implementation-specific because backoff behavior, especially jitter, varies between implementations. (#5357, @snorwin, #5359, @mikemorris)
New in Experimental
- Gateway Address Routability (GEP-5093): routability is expressed per Gateway address, so a single Gateway can serve addresses of different scopes. Valid values are empty (implementation default),
Cluster, or a domain-prefixed implementation-specific value. (#5304, @rikatz) - Standardized Attribute Dictionary (GEP-5253): a shared, vendor-neutral set of traffic attributes, based on OpenTelemetry semantic conventions, for use by features such as
XTelemetryPolicy. (#5256, @gkhom) - Session Persistence on Backend (GEP-1619 and GEP-4894): session persistence is configured on the
XBackendresource, and the route-inline andBackendTrafficPolicyattachment points are deprecated. (#4876, #5298, @gcs278) - Pre-routing Filters (GEP-5224): listener filters that run before routing decisions, for use cases such as external authentication and payload processing, with the new
GatewayListenerFiltersfeature. (#5315, @jaellio) - ClusterTrustBundle in
caCertificateRefs(GEP-5075):BackendTLSPolicyand Gateway frontend TLS validation can reference aClusterTrustBundlethrough the existingcaCertificateRefsfield, instead of copying CA bundles into every namespace. (#5272, #5356, @davidesalerno) - TelemetryPolicy for Distributed Tracing (GEP-4768): the
XTelemetryPolicyAPI standardizes tracing configuration for Gateways without vendor-specific CRDs. Metrics and access logs are not covered yet. (#5323, @gkhom)
Major Changes Since v1.6.3
Breaking Changes
- Experimental API changes (no effect on the Standard channel):
- SessionPersistence API:
sessionNamemoved tocookie.name(Extended, optional) andheader.name(Core, required),cookieConfigrenamed tocookie, andHeaderConfigadded. (#4873, @gcs278) - SessionPersistence API: the cookie
Pathnow defaults to/instead of being computed from route matches, and the newcookie.pathfield (Extended) allows explicit path configuration. (#5046, @gcs278) - SessionPersistence: route-inline and
BackendTrafficPolicysession persistence are deprecated in favor of the Backend resource. (#4876, @gcs278) XBackend:spec.port.portwas renamed tospec.port.number,spec.port.namewas removed, andbackendRef.portis now prohibited when referencing anXBackend. (#5287, @gcs278)
- SessionPersistence API:
- Go types:
BackendAncestorStatus.AncestorRefwas renamed in the generated Go types for consistency with docs and JSON/YAML serialization. (#5187, @Stevenjin8)HTTPRouteRetry.Attemptsis now a plainint(previously*int) that defaults to1. (#5269, @snorwin)ForwardBodyConfig.MaxSizechanged type fromuint16toint32. (#5099, @arjunxplorer)
- Conformance features:
- Go was upgraded to 1.27 and Kubernetes dependencies to v0.37. (#5297, @snorwin, #5232, @snorwin)
GEP & API Graduation
- GEP Status Updates:
- GEP-4768 (TelemetryPolicy): add the proposal, then the experimental
XTelemetryPolicyAPI (#4872, @gkhom, #5323, #5345, @robscott) - GEP-5093 (Gateway Address Routability): add as Provisional, move to Implementable, then to Experimental. (#5094, @usize, #5263, @rikatz, #5304, @rikatz)
- GEP-5224 (Pre-routing filters): add as Provisional, move to Implementable, then to Experimental. (#5235, @jaellio, #5271, @jaellio, #5315, @jaellio)
- GEP-5075 (ClusterTrustBundle
caCertificateRef): add as Provisional, move to Experimental, then usecaCertificateRefsinstead of a dedicated reference type. (#5259, @davidesalerno, #5272, @davidesalerno, #5356, @davidesalerno) - GEP-5253: Standardized Attribute Dictionary. (#5256, @gkhom)
- GEP-4359: Gateway API Regex. (#4764, @Stevenjin8)
- GEP-4360: Regex-based Path Rewrites. (#4695, @Stevenjin8)
- GEP-1619 (Session Persistence): synced with API updates and made the Backend the attachment point. (#4870, #4876, @gcs278)
- GEP-1731 (HTTPRoute Retries): aligned retry semantics with implementations, then loosened the
backoffdefinition so it no longer requires an exponential strategy, and promoted the retry configuration, includingbackoff, to the Standard channel. (#5167, @snorwin, #5359, @mikemorris) - GEP-4894 (Backend): deferred
SelectorRefin favor of theSelectorfield. (#5158, @gcs278)
- GEP-4768 (TelemetryPolicy): add the proposal, then the experimental
- Graduations to Standard:
- HTTPRoute retry configuration (
retry.codesandretry.attempts) is promoted to the Standard channel, and theHTTPRouteRetryCodesandHTTPRouteRetryConnectionErrorfeatures are now Standard.retry.backoff(implementation-specific) is promoted with them. (#5357, @snorwin) - HTTPRoute and GRPCRoute rule
nameuniqueness validation is now enforced in the Standard channel. (#5009, @snorwin) - BackendTLSPolicy SANs and TLS options are now marked as Standard channel. (#4999, @Suvink)
- HTTPRoute retry configuration (
Feature
- New Experimental APIs and Fields:
- Experimental
XTelemetryPolicyAPI (GEP-4768). (#5323, @gkhom, #5345, @robscott) XBackendsupports a newEndpointSelectortype that routes to in-cluster pods selected by label. (#5255, @gcs278)XBackendsupports session persistence for theEndpointSelectortype. (#5298, @gcs278)XBackendTLS mode was refactored and its CEL validation fixed. (#5316, @snorwin)- Gateway address
routability(GEP-5093), including theGatewayAddressRoutabilityandGatewayAddressRoutabilityClusterfeatures. (#5304, @rikatz) - Pre-routing listener filters (GEP-5224), with the new
GatewayListenerFiltersfeature. (#5315, @jaellio) ClusterTrustBundlecan be referenced throughcaCertificateRefsinBackendTLSPolicyand Gateway frontend TLS validation, with the newClusterTrustBundlefeature. (#5272, @davidesalerno, #5356, @davidesalerno)
- Experimental
- API & Validation Enhancements:
- Added CEL validation enforcing that TLS is disabled for H2C and enabled for HTTP2. Added a new
WSSprotocol value for WebSockets over TLS. (#5312, @snorwin) - Added the
GatewayRouteHostnameIntersectionPrecedencefeature so implementations can opt in to resolving *Route precedence using the original Route hostnames instead of the calculated Listener/Route intersection. (#5212, @rostislavbobo) - Replaced immutable CEL validation rules with the
+k8s:immutablemarker. (#4902, @chinmaychahar)
- Added CEL validation enforcing that TLS is disabled for H2C and enabled for HTTP2. Added a new
- Release Artifacts:
Documentation
- New and Updated Documentation:
- Added documentation for
XBackend. (#4931, @keithmattix) - Added TCP and UDP examples and documentation. (#4932, @zac-nixon)
- Added
ListenerSetto the SectionName interpretation table. (#4880, @apkatsikas) - Stopped referring to
ListenerSetas experimental. (#5228, @linuzctl) - Aligned the GRPCRoute hostname cross-serving godoc with the relaxed site docs. (#5176, @lexfrei)
- Clarified that implementations should only retry HTTPRoute requests on connection errors when it is safe to do so, and that
backoffspecifies the base interval of a backoff strategy rather than the minimum interval. The precise backoff curve and jitter are implementation-specific, and implementations that retry immediately with no backoff must not advertise support forbackoff. (#5269, @snorwin, #5359, @mikemorris) - Marked Upstream TLS (BackendTLSPolicy) as Standard channel since v1.4.0. (#4965, @anneheartrecord)
- Corrected API groups in the GEP-709 ReferenceGrant example. (#5310, @deepujain)
- Corrected conformance feature selection guidance. (#5175, @immanuwell)
- Updated the API reference format for readability. (#5156, @youngnick)
- Added documentation for
- Site & Project:
- Removed the old MkDocs and Python environments. (#5165, @rikatz)
- Added dark mode image support. (#5203, @robscott)
- Added a GitHub repository link to the site navbar. (#5305, @yashrajshuklaaa)
- Added an AI Policy document and AI disclosure to the pull request template. (#5151, @youngnick, #5208, @youngnick)
- Implementations & Conformance Reports:
- Added or updated conformance reports for Agentgateway, Airlock Microgateway, AWS Load Balancer Controller, Calico, Cilium, Cloudflare Tunnel Gateway Controller, GKE Gateway, Gravitee, Higress, Istio, Kgateway, Kong Operator, Linkerd, NGINX Gateway Fabric, Traefik Proxy and WSO2 Gateway.
- Envoy Gateway moved to Conformant. (#5186, @zirain)
- HAProxy Ingress was renamed to N42 Gateway. (#5268, @jcmoraisjr)
Bug or Regression
- Fixed the generator so that inline references are supported on experimental validation, and fixed generator tag recognition for experimental markers. (#5288, #5303, @rikatz)
- Fixed the backend port name CEL expression and added a unit test. (#5193, @snorwin)
- Fixed an always-true scheme check in conformance redirect port validation. (#5201, @immanuwell)
Test & Conformance
- New Conformance Tests:
- Added a conformance test for
GRPCRouteFilterRequestHeaderModifier(newGRPCRouteRequestHeaderModifierfeature). (#4060, @salonichf5) - Added a
BackendTLSPolicyconformance test for GRPCRoute. (#4882, @Thealisyed) - Added a
BackendTLSPolicywith TLSRoute Terminate conformance test. (#4875, @davidesalerno) - Added a Gateway maximum name length conformance test. (#5035, @arjunexplorer)
- Added an HTTPRoute rule precedence conformance test. (#5128, @thorn3r)
- Added a conformance test covering shared and dedicated routes across multiple Gateways for GRPCRoute. (#5281, @snorwin)
- Added conformance tests validating that Gateway resolves HTTPRoute precedence using original route hostname specificity rather than the calculated listener/route hostname intersection. (#5124, @rostislavbobo)
- Added conformance tests validating that Gateway resolves GRPCRoute precedence using original route hostname specificity rather than the calculated listener/route hostname intersection. (#5346, @rostislavbobo)
- Added conformance tests validating that Gateway resolves TLSRoute precedence using original route hostname specificity rather than the calculated listener/route hostname intersection. (#5361, @rostislavbobo)
- Added conformance tests for
URLRewritefilters at HTTPBackendRef level (HTTPRouteBackendURLRewrite). (#4823, @Srujan-rai) - Added unit tests for the echo response parser. (#4635, @archy-rock3t-cloud)
- Added a conformance test for
- Test Machinery & Framework Updates:
- The conformance suite now supports an injectable WebSocket dialer (
ConformanceOptions.WebSocketDialer). It defaults to the previouswebsocket.Dialbehavior when unset. (#4936, @lexfrei) - The conformance gRPC
DefaultClientis now safe for concurrentSendRPCand reusable afterClose. (#4946, @lexfrei) - Base-resource cleanup now waits for deletion to complete, so the suite can be re-run in a single process (
go test -count>1). (#4948, @lexfrei) RouteMustHaveParentsnow runs theobservedGenerationcheck against the status it just read. Implementations whose status lags the Route generation may now fail where they previously passed. (#5206, @lexfrei)- Report an error when a conformance manifest is missing from every configured filesystem. (#5216, @immanuwell)
- Conformance report
Implementation.URLis now validated as a well-formed http(s) URL. (#5209, @yashrajshuklaaa) - The conformance echo server images moved to a dedicated repository (
kubernetes-sigs/gateway-api-conformance-images). (#5090, @snorwin) - Use the timeout config more consistently. (#5150, @howardjohn)
- Preserve
=in conformance key-value flags. (#5034, @immanuwell)
- The conformance suite now supports an injectable WebSocket dialer (
- Updates & Fixes to Existing Tests:
- Expect
RefNotPermittedfor a cross-namespacecertificateRefto a nonexistent secret. (#5306, @PetrMc) - Wait for mesh weighted routes to be programmed. (#5214, @Automaat)
- Retry the failure-path assertion in the client certificate validation test. (#5097, @yashrajshuklaaa)
- Added
containerPorts to the echo pod in the mesh conformance manifest. (#5055, @AnirbanNandi) - Foreign status entries on HTTPRoutes, BackendTLSPolicy and Gateway are now preserved by conformance tests. (#5206, @lexfrei)
- Removed the HTTPRoute retry tests that required unsafe retries and added a retry-with-backend-timeout case. (#5339, @snorwin)
- Expect
Other (Cleanup or Flake)
- Mark
HTTPRouteBackendURLRewritetests as provisional. (#5270, @snorwin) - Added a
make linttarget. (#5198, @youngnick) - Added a new
implisttool. (#5191, @youngnick) - Fixed the package declared as
mainso that it can be imported asutils. (#5275, @yashrajshuklaaa) - Bumped the Go toolchain to 1.26.8 to fix stdlib CVEs. (#5280, @yashrajshuklaaa)
- Marked generated OpenAPI files as generated in PRs. (#5261, @youngnick)
Dependencies
Only changes to modules directly required by the root, conformance, tests and tools modules are listed below.
Changed
- github.com/miekg/dns: v1.1.72 → v1.1.73
- github.com/stretchr/testify: v1.11.1 → v1.12.1
- golang.org/x/mod: v0.36.0 → v0.41.0
- golang.org/x/net: v0.55.0 → v0.59.0
- golang.org/x/sync: v0.20.0 → v0.23.0
- golang.org/x/tools: v0.45.0 → v0.50.0
- google.golang.org/grpc: v1.81.1 → v1.84.0
- k8s.io/api: v0.36.1 → v0.37.0
- k8s.io/apiextensions-apiserver: v0.36.1 → v0.37.0
- k8s.io/apimachinery: v0.36.1 → v0.37.0
- k8s.io/client-go: v0.36.1 → v0.37.0
- k8s.io/code-generator: v0.36.1 → v0.37.0
- k8s.io/kube-openapi: 927ab1f → d427ff9
- k8s.io/utils: 28399d8 → be93311
- sigs.k8s.io/controller-runtime: v0.24.1 → v0.25.1
- sigs.k8s.io/controller-tools: v0.21.0 → v0.22.0
- sigs.k8s.io/structured-merge-diff/v6: v6.4.0 → v6.4.2
- sigs.k8s.io/gateway-api-conformance-images: added at v0.1.0