01 Oct 2026
Included Calico versions
Calico version: v3.33.0
Calico Enterprise version: v3.24.0-1.0
Enhancements
- Reduces the time calico-node takes to be marked ready after starting, which shortens calico-node rolling updates on large clusters. #5209 (@caseydavenport)
- Added a FelixIPIPOnly value to Installation clusterRoutingMode, selecting Felix for the cluster routes of IPIP IP pools and confd/BIRD for those of unencapsulated IP pools. #5150 (@nelljerram)
- Reduced operator memory usage by stripping managedFields from cached objects. #5108 (@alexh-tigera)
Breaking changes
- The LogCollector now deploys fluent-bit (calico-fluent-bit in calico-system) in place of fluentd, with operator-rendered configuration and automatic migration of fluentd tail positions. #4910 (@hjiawei)
- Breaking changes and behavior changes in this migration:
- The tigera-fluentd namespace is removed; all log-collector resources are renamed and move to calico-system (DaemonSet/container calico-fluent-bit, TLS secret calico-fluent-bit-tls). Tooling referencing the old names (e.g. kubectl logs -c fluentd) must be updated.
- The LogCollector fluentdDaemonSet override field is deprecated in favor of calicoFluentBitDaemonSet; existing overrides (including legacy container names) keep applying for one release.
- User flow/DNS log filters: the fluentd-filters ConfigMap is no longer read. Filters must be recreated under the new fluent-bit-filters name as fluent-bit YAML filter lists; unparseable content raises a TigeraStatus warning while log shipping continues.
- Log-collector metrics are now fluent-bit's native Prometheus metrics (fluentbit_* metric names, plain HTTP on port 2020 at /api/v2/metrics/prometheus, guarded by NetworkPolicy). Dashboards and alerts keyed on fluentd_* metric names or the 9081 mTLS endpoint must be updated.
- S3 archive object keys change from fluentd's flat layout (<bucketPath>/flows20260101_<n>.gz) to directory-style keys (<bucketPath>/flows/20260101_<uuid>.gz), with non-cluster-host flows archived under their own non_cluster_flows/ directory. Downstream tooling anchored to the old flat patterns needs a one-time update.
- Log buffering moves from fluentd's in-memory buffers to fluent-bit filesystem storage under /var/log/calico/calico-fluent-bit/ on each node: buffered-but-unsent chunks now survive pod restarts, and host disk usage grows accordingly (capped per output by storage.total_limit_size).
- Syslog forwarding no longer applies fluentd's 1024-byte packet-size default. When spec.additionalStores.syslog.packetSize is unset, the fluent-bit syslog output uses its own default for the RFC5424 format the operator renders (2048 bytes), reducing truncation of longer log lines; set packetSize to cap the message size explicitly (messages above the cap are truncated).
Bug fixes
- Fixes the operator leaving stale cluster route programming settings behind in FelixConfiguration and BGPConfiguration when the Installation stops asking for them. #5324 (@caseydavenport)
- Fixes the operator leaving Felix's eBPF kube-proxy health port pinned at zero after a cluster leaves eBPF mode. #5324 (@caseydavenport)
- The operator now records the FelixConfiguration and BGPConfiguration fields it owns in managed fields, and removes the annotations earlier versions used for the same purpose. #5324 (@caseydavenport)
- Fixes a datastore migration becoming permanently stuck if the calico-kube-controllers pod is lost while the migration is in progress. #5318 (@caseydavenport)
- Fix calico-node CrashLoopBackOff during upgrade when the operator set bpfKubeProxyHealthzPort=0 before all nodes were running a version that accepts it. #5315 (@tomastigera)
- Fixes tier-scoped policy roles being denied all access on clusters serving the Calico v3 API through CRDs. #5266 (@caseydavenport)
- Fixes staged network policy writes being denied for tier-scoped roles in Calico. #5266 (@caseydavenport)
- Fixed the Manager policy board rendering empty on managed clusters, where the query server was not permitted egress to Linseed through guardian. #5263 (@tianfeng92)
- Fix Calico webhook admission requests being denied on clusters where the API server connects through konnectivity, including AKS and GKE. #5216 (@caseydavenport)
- Fixes the Calico version reported in the installation status when the Calico variant is installed. #5211 (@caseydavenport)
- Fixed a bug that prevented BGP being disabled on a cluster with only IPIP IP Pools when clusterRoutingMode was left unset. #5201 (@nelljerram)
- Fixed a deadlock on upgrade where the Calico API server was moved before a deprecated policy blocking it was removed, leaving the projectcalico.org/v3 API permanently unavailable. #5143 (@xiumozhan)
- Fixed WAF dashboard cards failing with an access denied error for all users. #5133 (@electricjesus)
- Fixes an issue where components could be deployed with default image tags instead of the images from a configured ImageSet during a Calico Enterprise installation. #5131 (@caseydavenport)
- Fixed continuous rewrites of operator-managed objects shared by multiple owners (pull-secret copies, the tigera-operator-secrets RoleBinding, and gateway trust-bundle ConfigMaps): owner references are now merged in a stable order and per-owner identity labels are no longer written to shared objects, eliminating the resulting API server write and audit-log churn. #5124 (@alexh-tigera)
- Fixes repeated failed-webhook errors in the Kubernetes API server log on Calico (non-Enterprise) clusters, caused by registering an audit admission webhook whose endpoint only exists in Calico Enterprise. #5069 (@caseydavenport)
- Fixed a bug where disabling Gateway WAF left the generated EnvoyExtensionPolicy in place so the gateway kept enforcing WAF. The WAF controller now stays running while disabled so it can tear down what it generated. #4989 (@electricjesus)
- Granted the tigera-network-admin and tigera-ui-user roles RBAC access to the WAF (applicationlayer.projectcalico.org) policy resources. #4964 (@electricjesus)
- Fixes a regression where the Goldmane and Guardian pods were unable to reach DNS or the management cluster, which could break flow visibility (including on Calico Cloud-connected clusters). #4940 (@caseydavenport)
- Fix Goldmane flow uploads to Guardian on Calico Cloud-managed clusters by trusting the management cluster Linseed signer under both its current and legacy secret names. #4936 (@Brian-McM)
- Remove the deprecated waf-http-filter sidecar from the Enterprise Gateway data plane. WAF is now enforced by the Coraza WASM filter on the envoy-proxy. #4925 (@electricjesus)
- Fixed a bug where the Calico Enterprise gateway WAF CRDs (applicationlayer.projectcalico.org) were not installed on standard aggregated-apiserver installations, making the gateway WAF feature unusable. These CRDs are now installed in both CRD modes. #4920 (@electricjesus)
- Fixed an infinite IP pool delete/recreate loop that occurred when an Installation specified an IP pool CIDR in non-canonical form (for example an IPv6 CIDR with leading zeros). #4918 (@tmjd)
Other changes
- Update the bundled Envoy Gateway to v1.9.1 and the Gateway API CRDs to v1.6.1. Envoy Gateway v1.9 raises the minimum supported Kubernetes version to v1.33. #5334 (@electricjesus)
- Operator-managed NetworkPolicies now use the kubernetes.io/metadata.name label for namespace selectors instead of projectcalico.org/name. #5151 (@sivasubramanian95)
- Whisker is now served over HTTPS on port 8443. #5140 (@vara2504)
- Fixes a brief window during a calico-webhooks rollout where policy writes could be rejected. #5138 (@caseydavenport)
- kube-controllers can now watch IPReservations, which it needs to report the ipam_ippool_reserved metric. #5115 (@fasaxc)
- Removed the vulnerable containerd dependency from the operator image by bumping Helm to v3.21.3, and cleared an oras-go CVE by flooring it to v2.6.2. #5100 (@electricjesus)
- The operator-generated CNI config now declares cniVersion 1.0.0 (previously 0.3.1), required for multus compatibility on OpenShift 4.23+. Requires containerd >= 1.6 or CRI-O >= 1.24. A new Installation field, spec.cni.specVersion, allows pinning the version (including back to 0.3.1) or leaving it operator-managed (Auto). #5090 (@sridhartigera)
- Bump Kubernetes dependencies to v1.37.0-beta.0. #5089 (@lucastigera)
- Installation can configure calico-node host paths (calicoNodeRunPath / calicoNodeLibPath); manifest migration accepts microk8s-style snap paths #5086 (@locker95)
- Reduces Tigera operator memory usage in large clusters by no longer caching all Pods in memory. #5082 (@caseydavenport)
- Update the bundled Envoy Gateway to v1.8.2. #5077 (@electricjesus)
- Fixed an issue where a non-canonical storage quantity in the LogStorage CR (e.g. 1024Gi) caused the Elasticsearch NodeSet to be renamed on every reconcile, repeatedly recreating the Elasticsearch StatefulSet and its PVCs. #5073 (@pasanw)
- WAF management UI users can now read Gateway API resources to attach policies and detect Gateway API enablement. #5044 (@electricjesus)
- Add spec.gateway field to Manager CR enabling Calico Ingress Gateway access to the Manager UI. #5032 (@vara2504)
- The ECK operator is updated to v3.4.1. #5009 (@alexh-tigera)
- Mount securityfs into calico-node so Felix can detect kernel lockdown=confidentiality and avoid bpf_trace_printk-related kernel log spam. #4992 (@tomastigera)
- Restore backwards compatibility for the Monitor CRD
alertManagerfield, which was inadvertently renamed toalertmanager. #4985 (@rene-dekker) - New installs on Kubernetes clusters with MutatingAdmissionPolicy support enabled now default to serving the projectcalico.org/v3 API directly via CRDs instead of through the aggregated API server. Existing and upgraded clusters are unaffected. #4973 (@caseydavenport)
- Grant calico-kube-controllers permission to patch tiers. #4972 (@caseydavenport)
- Elasticsearch and Kibana are updated to the v8.19.17 release. #4958 (@hjiawei)
- Bump Go to v1.26.4 and update Kubernetes to v1.36.2. #4930 (@hjiawei)
- Removed the deprecated Compliance feature. #4924 (@caseydavenport)
- Add operator render for Gateway API WAF observability (EV-6650): capture the Coraza audit log from the gateway proxy, and enable the Felix + fluentd legs (WAFEventLogsFileEnabled, WAF_LOG_FILE) so WAF block / would-block decisions land in the tigera_secure_ee_waf index. #4895 (@electricjesus)
- ECK Elasticsearch and Kibana version bumped from 8.19.15 to 8.19.16 for CVE remediation. #4886 (@vara2504)
- Added an opt-in
Manager.spec.rbacManagement.enabledflag that enables the RBAC management UI. When enabled, the operator grants the additional RBAC and LDAP egress the UI requires; it defaults to disabled and is supported in zero-tenant management clusters only. Disabling the flag does not remove RBAC objects already created while it was enabled. #4865 (@dimitri-nicolo) - Bumped bundled Envoy Gateway from v1.7.2 to v1.8.0. Adds first-class
ListenerSetsupport (enables cert-manager and external-dns integration with Gateway-API), thesafe-upgradesValidatingAdmissionPolicy for CRD version migrations, and pulls in the v1.8.0 security and bug-fix rollup. Note: v1.8.0 contains several upstream behavior changes (DirectResponse template interpolation, SecurityPolicy0stimeout semantics, samplingFraction 100x correction, OIDC filter consolidation) — see https://gateway.envoyproxy.io/news/releases/notes/v1.8.0/. #4832 (@electricjesus) - Add L7 log collection for Istio ambient mode waypoint proxies. #4769 (@alexh-tigera)