Announcing Istio 1.19.1
Istio 1.19.1 patch release.
This release note describes what’s different between Istio 1.19.0 and 1.19.1.
BEFORE YOU UPGRADE
Things to know and prepare before upgrading.
DOWNLOAD
Download and install this release.
DOCS
Visit the documentation for this release.
SOURCE CHANGES
Inspect the full set of source code changes.
Changes
Added the ability to install the Gateway Helm chart with a dual-stack service definition.
Added a new configuration to
ProxyConfig
andProxyHeaders
. This allows customization of headers likeserver
,x-forwarded-client-cert
, etc. Most notably, these can now be disabled so that they are not modified.Added a new configuration to
ProxyHeaders
andMetadataExchangeHeaders
. TheIN_MESH
mode ensuresx-envoy-peer-metadata
andx-envoy-peer-metadata-id
headers will not be added to outbound requests from sidecars to destination services considered mesh external. (Issue #17635)Fixed an issue where the upgrade warning is given incorrectly between default and revisioned control planes.
Fixed an issue where ambient pods are incorrectly processed when the ambient namespace label is changed.
Fixed an issue where the Istio CNI plugin was not writing IPv6 iptables rules for dual stack clusters. (Issue #46625)
Fixed an issue where
meshConfig.defaultConfig.sampling
is ignored when there’s only default providers. (Issue #46653)Fixed SDS fetching timeout when we do not push back invalid certificate to Envoy. (Issue #46868)
Fixed an issue where the installation process was failing due to failed verification of the
NetworkAttachmentDefinition
resource. (Issue #46859)Fixed metric
DNSNoEndpointClusters
not working. (Issue #46960)Fixed the output of
istioctl proxy-config all
to include EDS configuration when the--json
or--yaml
flags are used.Fixed an issue in control plane metrics causing gauge types to emit zero values without labels in addition to the expected metrics. (Issue #46977)
Security updates
There are no security updates in this release.