Cilium - v1.12.5


Summary of Changes

Minor Changes:
* bpf: Implement downgrading path from v3 to v2 backend map (#22416, @YutaroHayakawa)

Bugfixes:
* Clear stale CNP status nodes if updates have been disabled (Backport PR #22500, Upstream PR #20366, @pippolo84)
* docs: Update Cilium Sphinx RTD Theme reference (Backport PR #22500, Upstream PR #22321, @kimstacy)
* Fail validate-cnp preflight check if a CiliumClusterwideNetworkPolicy is using an empty toEndpoints/fromEndpoints selector (Backport PR #22500, Upstream PR #21990, @thorn3r)
* Fix bug that could lead to inconsistent pod IP information between agents, sometimes leading to a failure to decrypt IPsec traffic. (Backport PR #22308, Upstream PR #22127, @aanm)
* Fix bug where configuring the API rate limiter options could fail when providing multiple options (Backport PR #22696, Upstream PR #22299, @thorn3r)
* Fix Cilium fatal "Could not create or update CiliumNode resource, despite retries" on environments with enable-ipv4-egress-gateway (Backport PR #22308, Upstream PR #22298, @aanm)
* Fix forwarding of the security identity by the DNS proxy which could cause random policy denials (Backport PR #22407, Upstream PR #22361, @aspsk)
* Fix GC of CEPs that were not GCed by kube-apiserver (Backport PR #22308, Upstream PR #22213, @aanm)
* fix: some tofqdn flags not being parsed (Backport PR #22500, Upstream PR #22346, @carloscastrojumo)
* helm: Add relabelings config to ServiceMonitors and re-introduce node label on cilium/hubble metrics (Backport PR #22506, Upstream PR #22297, @chancez)
* Improve garbage collection for FQDNs particularly with high-churn IP names such as Amazon S3. (Backport PR #22730, Upstream PR #22510, @joestringer)
* Prevent cilium operator crash in AWS region with IPv6-only ENIs without subnet filters. (Backport PR #22308, Upstream PR #22075, @bimmlerd)

CI Changes:
* .github: Explicitly set build-commits job runner image version and install libtinfo5 (Backport PR #22328, Upstream PR #22315, @chancez)
* .github: fix bpf-checks on ubuntu-latest runner (Backport PR #22328, Upstream PR #22322, @julianwiedmann)
* Fix CODEOWNERS (#22292, @michi-covalent)

Misc Changes:
* .github/workflows: split the image tag update in two steps (Backport PR #22260, Upstream PR #22268, @aanm)
* Add automatic creation of Cilium base images (Backport PR #22260, Upstream PR #22179, @aanm)
* bpf: Remove FIB lookup for IPsec (Backport PR #22308, Upstream PR #22069, @pchaigno)
* build(deps): bump actions/setup-go from 3.3.1 to 3.4.0 (#22486, @dependabot[bot])
* build(deps): bump actions/setup-go from 3.4.0 to 3.5.0 (#22715, @dependabot[bot])
* build(deps): bump actions/upload-artifact from 3.1.0 to 3.1.1 (#22271, @dependabot[bot])
* build(deps): bump github/codeql-action from 2.1.32 to 2.1.35 (#22497, @dependabot[bot])
* build(deps): bump github/codeql-action from 2.1.35 to 2.1.36 (#22632, @dependabot[bot])
* build(deps): bump helm/kind-action from 1.4.0 to 1.5.0 (#22716, @dependabot[bot])
* build(deps): bump KyleMayes/install-llvm-action from 1.6.0 to 1.6.1 (#22595, @dependabot[bot])
* chore(deps): update base-images (v1.12) (#22167, @renovate[bot])
* chore(deps): update docker.io/library/golang:1.18.8 docker digest to 0936e74 (v1.12) (#22198, @renovate[bot])
* chore(deps): update docker.io/library/golang:1.18.9 docker digest to c492f6b (v1.12) (#22728, @renovate[bot])
* daemon/cmd: Fix error handling for getting proxy port (Backport PR #22500, Upstream PR #22296, @christarazi)
* doc: add section to show how to customize cilium-agent metrics (Backport PR #22308, Upstream PR #22178, @ArthurChiao)
* docs: add instructions to build the base images from external forks (Backport PR #22500, Upstream PR #22304, @aanm)
* docs: clarifications about CNCF maintainer status (Backport PR #22500, Upstream PR #22351, @lizrice)
* docs: Clarify wildcards and subdomains in FQDN policies (Backport PR #22308, Upstream PR #22206, @felfa01)
* docs: describe Cilium Feature Proposals (Backport PR #22500, Upstream PR #22443, @lizrice)
* docs: Fix kubectl create output in docs after some deployments have moved from K8s "extensions" to "apps". (Backport PR #22500, Upstream PR #22002, @cleverhu)
* docs: update roadmap for graduation application (Backport PR #22500, Upstream PR #22422, @xmulligan)
* fix 'egressIP' field indentation (Backport PR #22500, Upstream PR #22303, @yulng)
* gha: Pin ubuntu-20.04 for conformance-test-ipv6 (Backport PR #22328, Upstream PR #22324, @sayboras)
* Google Season of Docs is now over so it is removed from the docs (Backport PR #22500, Upstream PR #22442, @xmulligan)
* Include DeleteNetworkInterface in ENI Required Privileges Docs (Backport PR #22500, Upstream PR #20472, @espringsteen)
* k8s: don't consider 4xx a successful interaction (Backport PR #22500, Upstream PR #22393, @bimmlerd)
* mtu, node: fix build on all non-linux platforms (Backport PR #22308, Upstream PR #22232, @tklauser)
* pkg/datapath: return specific error message (Backport PR #22308, Upstream PR #22137, @aanm)
* Update documentation related to metrics; fix incorrect FQDN metrics reference (Backport PR #22308, Upstream PR #22300, @christarazi)
* v1.12: Update Go to 1.18.9 (#22599, @tklauser)

Other Changes:
* install: Update image digests for v1.12.4 (#22238, @michi-covalent)
* v1.12: Update k8s versions in tests and vendored libraries (#22581, @tklauser)

Docker Manifests

cilium

docker.io/cilium/cilium:v1.12.5@sha256:06ce2b0a0a472e73334a7504ee5c5d8b2e2d7b72ef728ad94e564740dd505be5
quay.io/cilium/cilium:v1.12.5@sha256:06ce2b0a0a472e73334a7504ee5c5d8b2e2d7b72ef728ad94e564740dd505be5
docker.io/cilium/cilium:stable@sha256:06ce2b0a0a472e73334a7504ee5c5d8b2e2d7b72ef728ad94e564740dd505be5
quay.io/cilium/cilium:stable@sha256:06ce2b0a0a472e73334a7504ee5c5d8b2e2d7b72ef728ad94e564740dd505be5

clustermesh-apiserver

docker.io/cilium/clustermesh-apiserver:v1.12.5@sha256:15c5d7fc2e78bce33b5351eb8788ac06f39c19cea5fef70da7f1beabdd106dd3
quay.io/cilium/clustermesh-apiserver:v1.12.5@sha256:15c5d7fc2e78bce33b5351eb8788ac06f39c19cea5fef70da7f1beabdd106dd3
docker.io/cilium/clustermesh-apiserver:stable@sha256:15c5d7fc2e78bce33b5351eb8788ac06f39c19cea5fef70da7f1beabdd106dd3
quay.io/cilium/clustermesh-apiserver:stable@sha256:15c5d7fc2e78bce33b5351eb8788ac06f39c19cea5fef70da7f1beabdd106dd3

docker-plugin

docker.io/cilium/docker-plugin:v1.12.5@sha256:1b4fd6bdb8966694ece71095804bed2337cee6cb9c96f02db7158351f6104ecd
quay.io/cilium/docker-plugin:v1.12.5@sha256:1b4fd6bdb8966694ece71095804bed2337cee6cb9c96f02db7158351f6104ecd
docker.io/cilium/docker-plugin:stable@sha256:1b4fd6bdb8966694ece71095804bed2337cee6cb9c96f02db7158351f6104ecd
quay.io/cilium/docker-plugin:stable@sha256:1b4fd6bdb8966694ece71095804bed2337cee6cb9c96f02db7158351f6104ecd

hubble-relay

docker.io/cilium/hubble-relay:v1.12.5@sha256:22039a7a6cb1322badd6b0e5149ba7b11d35a54cf3ac93ce651bebe5a71ac91a
quay.io/cilium/hubble-relay:v1.12.5@sha256:22039a7a6cb1322badd6b0e5149ba7b11d35a54cf3ac93ce651bebe5a71ac91a
docker.io/cilium/hubble-relay:stable@sha256:22039a7a6cb1322badd6b0e5149ba7b11d35a54cf3ac93ce651bebe5a71ac91a
quay.io/cilium/hubble-relay:stable@sha256:22039a7a6cb1322badd6b0e5149ba7b11d35a54cf3ac93ce651bebe5a71ac91a

operator-alibabacloud

docker.io/cilium/operator-alibabacloud:v1.12.5@sha256:a452b58e2de9aca5ea0a2d84ab999442fe0293723f028f288992bf546ee72a4a
quay.io/cilium/operator-alibabacloud:v1.12.5@sha256:a452b58e2de9aca5ea0a2d84ab999442fe0293723f028f288992bf546ee72a4a
docker.io/cilium/operator-alibabacloud:stable@sha256:a452b58e2de9aca5ea0a2d84ab999442fe0293723f028f288992bf546ee72a4a
quay.io/cilium/operator-alibabacloud:stable@sha256:a452b58e2de9aca5ea0a2d84ab999442fe0293723f028f288992bf546ee72a4a

operator-aws

docker.io/cilium/operator-aws:v1.12.5@sha256:adbcd8bd2852cf9e39b02482ff1d3c7fc90ffac6675ea7512ef28aff50b7f492
quay.io/cilium/operator-aws:v1.12.5@sha256:adbcd8bd2852cf9e39b02482ff1d3c7fc90ffac6675ea7512ef28aff50b7f492
docker.io/cilium/operator-aws:stable@sha256:adbcd8bd2852cf9e39b02482ff1d3c7fc90ffac6675ea7512ef28aff50b7f492
quay.io/cilium/operator-aws:stable@sha256:adbcd8bd2852cf9e39b02482ff1d3c7fc90ffac6675ea7512ef28aff50b7f492

operator-azure

docker.io/cilium/operator-azure:v1.12.5@sha256:60dee3a53aefc3b8cda426ee87c55fd61a19a6c8d7e0995348345e1af93b451f
quay.io/cilium/operator-azure:v1.12.5@sha256:60dee3a53aefc3b8cda426ee87c55fd61a19a6c8d7e0995348345e1af93b451f
docker.io/cilium/operator-azure:stable@sha256:60dee3a53aefc3b8cda426ee87c55fd61a19a6c8d7e0995348345e1af93b451f
quay.io/cilium/operator-azure:stable@sha256:60dee3a53aefc3b8cda426ee87c55fd61a19a6c8d7e0995348345e1af93b451f

operator-generic

docker.io/cilium/operator-generic:v1.12.5@sha256:b296eb7f0f7656a5cc19724f40a8a7121b7fd725278b7d61dc91fe0b7ffd7c0e
quay.io/cilium/operator-generic:v1.12.5@sha256:b296eb7f0f7656a5cc19724f40a8a7121b7fd725278b7d61dc91fe0b7ffd7c0e
docker.io/cilium/operator-generic:stable@sha256:b296eb7f0f7656a5cc19724f40a8a7121b7fd725278b7d61dc91fe0b7ffd7c0e
quay.io/cilium/operator-generic:stable@sha256:b296eb7f0f7656a5cc19724f40a8a7121b7fd725278b7d61dc91fe0b7ffd7c0e

operator

docker.io/cilium/operator:v1.12.5@sha256:a6d24a006a6b92967ac90786b49bc1ac26e5477cf028cd1186efcfc2466484db
quay.io/cilium/operator:v1.12.5@sha256:a6d24a006a6b92967ac90786b49bc1ac26e5477cf028cd1186efcfc2466484db
docker.io/cilium/operator:stable@sha256:a6d24a006a6b92967ac90786b49bc1ac26e5477cf028cd1186efcfc2466484db
quay.io/cilium/operator:stable@sha256:a6d24a006a6b92967ac90786b49bc1ac26e5477cf028cd1186efcfc2466484db


Details

date
Dec. 20, 2022, 11:08 p.m.
name
type
Patch
👇
Register or login to:
  • 🔍View and search all Cilium releases.
  • 🛠️Create and share lists to track your tools.
  • 🚨Setup notifications for major, security, feature or patch updates.
  • 🚀Much more coming soon!
Continue with GitHub
Continue with Google
or