Skip to content

policy: Add support for tiers and pass verdicts#42896

Merged
jrajahalme merged 9 commits intocilium:mainfrom
jrajahalme:policy-pass-wip
Jan 6, 2026
Merged

policy: Add support for tiers and pass verdicts#42896
jrajahalme merged 9 commits intocilium:mainfrom
jrajahalme:policy-pass-wip

Conversation

@jrajahalme
Copy link
Copy Markdown
Member

@jrajahalme jrajahalme commented Nov 20, 2025

Add support for arbitrary number of policy tiers and pass verdicts.

This is work-in-progress. The following items are still to be done:

  • always insert a default rule so that admin tier rules after a PASS verdict will always be bypassed
  • Envoy policies do not yet support policy tiers or pass verdicts
Policy engine adds support for tiers and pass verdicts for ClusterNetworkPolicies

@jrajahalme jrajahalme requested a review from a team as a code owner November 20, 2025 16:10
@jrajahalme jrajahalme added release-note/major This PR introduces major new functionality to Cilium. sig/policy Impacts whether traffic is allowed or denied based on user-defined policies. labels Nov 20, 2025
@jrajahalme jrajahalme requested review from a team as code owners November 20, 2025 16:10
@jrajahalme jrajahalme added the dont-merge/preview-only Only for preview or testing, don't merge it. label Nov 20, 2025
@jrajahalme jrajahalme marked this pull request as draft November 20, 2025 16:10
@jrajahalme jrajahalme requested a review from jrife November 20, 2025 16:10
@jrajahalme jrajahalme added the dont-merge/blocked Another PR must be merged before this one. label Nov 20, 2025
@jrajahalme jrajahalme changed the title policy: Add support for pass verdict policy: Add support for tiers and pass verdicts Dec 9, 2025
@jrajahalme jrajahalme added dont-merge/preview-only Only for preview or testing, don't merge it. and removed dont-merge/blocked Another PR must be merged before this one. dont-merge/preview-only Only for preview or testing, don't merge it. labels Dec 9, 2025
@jrajahalme jrajahalme force-pushed the policy-pass-wip branch 3 times, most recently from a279b34 to 2cdec1a Compare December 9, 2025 15:57
@jrajahalme
Copy link
Copy Markdown
Member Author

/test

@jrajahalme
Copy link
Copy Markdown
Member Author

Split refactor commits out of the last commit to make it more readable.

@jrajahalme
Copy link
Copy Markdown
Member Author

/test

@jrajahalme
Copy link
Copy Markdown
Member Author

Rebased due to revert in #43237.

@jrajahalme
Copy link
Copy Markdown
Member Author

/test

Copy link
Copy Markdown
Contributor

@squeed squeed left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I will note there are a few things to clean up (some panics, some XXX comments) but this looks basically great :-)

@TheBeeZee
Copy link
Copy Markdown
Contributor

@TheBeeZee Updated, could you have another look?

Unfortunately this version fails all Admin and mixed tier 'pass' tests, but works for baseline tier. I tried to debug it in the limited time I had available but couldn't figure it out.

It seems like the default-allow policy that should be applied when DefaultDeny=false doesn't make it to the Dataplane. The log message 'Only default-allow policies, synthesizing egress wildcard-allow rule' is in the log, but my interpretation of bpftool map dump shows that the default-allow doesn't make it to the Dataplane.

rulesEgress = append(rulesEgress, wildcardRule(securityIdentity.LabelArray, false /*egress*/))
// User the lowest tier and priority
lastRule := rulesEgress[len(rulesEgress)-1]
tier, priority := lastRule.Tier, lastRule.Priority
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The above ingress logic of creating a tier+1 and priority=0 allow rule needs to be applied here, too.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Will fix in a follow-up.

lastTier := types.Tier(0)
var tierPriorityLevels []int
numPassVerdicts := make([]int, 1)
{
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think it would help readability if this code block was a function instead.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Will consider in a follow-up, thanks!


// sort rules (in place) by priority
rules.sort()
func ensureSlice[E any, S ~[]E, I ~uint | ~uint8](s *S, index I) {
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If I'm reading correctly, this just ensures that the slice "S" of type "E" has "index" elements. A short comment would likely help future readers.

Also, here's a slightly more efficient variant:

func ensureSlice[E any, S ~[]E, I ~uint | ~uint8](s *S, index I) {
newS := make([]E, index+1)
copy(newS, *s)
*s = S(newS)
}

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For most calls the allocation and copy are not needed, while the one above does it every time?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added a comment in the follow-up.

Copy link
Copy Markdown
Member

@sayboras sayboras left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good for proxy related changes

@julianwiedmann julianwiedmann removed request for a team and jrife January 6, 2026 06:08
@maintainer-s-little-helper maintainer-s-little-helper bot added the ready-to-merge This PR has passed all tests and received consensus from code owners to merge. label Jan 6, 2026
@jrajahalme jrajahalme enabled auto-merge January 6, 2026 14:55
@jrajahalme jrajahalme added this pull request to the merge queue Jan 6, 2026
Merged via the queue into cilium:main with commit 1f67b74 Jan 6, 2026
82 of 83 checks passed
@jrajahalme jrajahalme deleted the policy-pass-wip branch January 6, 2026 15:11
@jrajahalme jrajahalme mentioned this pull request Jan 6, 2026
@jrajahalme
Copy link
Copy Markdown
Member Author

@squeed @TheBeeZee Addressed the remaining comments in a follow-up PR: #43589

@joestringer
Copy link
Copy Markdown
Member

@jrajahalme Is this a user-facing change? Similar to this comment I wonder whether how to appropriately communicate the changes to users. If the user can't use the functionality, I don't think we should elevate the release note in the list. At the same time I think it would be valuable to inform users that there is ongoing work in this area. Maybe we can set to release-note/misc but then in the final v1.19.0 announcement we just note that there is ongoing work within the policy engine to prepare for KCNP support?

@joestringer joestringer added release-note/misc This PR makes changes that have no direct user impact. and removed release-note/major This PR introduces major new functionality to Cilium. labels Jan 22, 2026
@cilium-release-bot cilium-release-bot bot moved this to Released in cilium v1.19.0 Feb 3, 2026
alexlebens pushed a commit to alexlebens/infrastructure that referenced this pull request Feb 5, 2026
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [cilium](https://cilium.io/) ([source](https://github.com/cilium/cilium)) | minor | `1.18.6` → `1.19.0` |

---

### Release Notes

<details>
<summary>cilium/cilium (cilium)</summary>

### [`v1.19.0`](https://github.com/cilium/cilium/releases/tag/v1.19.0): 1.19.0

[Compare Source](cilium/cilium@1.18.6...1.19.0)

🎉 **Release Announcement** 🎉: We are excited to announce the [Cilium 1.19.0](https://github.com/cilium/cilium/releases/tag/v1.19.0) release!

A total of **2934 new commits** have been contributed to this release by a growing community of over **1010 developers** and over **23,600 GitHub stars**! 🤩

⚠️ You may need to take action during upgrade to Cilium v1.19 if you use Network Policies, Cluster Mesh, LoadBalancer IPAM or BGP. See the [Upgrade Guide](https://docs.cilium.io/en/v1.19/operations/upgrade/#upgrade-notes) for more details.

The full changelog can be found [here](https://github.com/cilium/cilium/blob/v1.19/CHANGELOG.md).

Here are some of the highlights:

- 🛡️ **Network Policy**
  - 🃏 **Multi-Level DNS Matches**: DNS Policies match pattern now support a wildcard prefix(*`**.`*) to match multilevel subdomain as pattern prefix. ([cilium/cilium#43420](cilium/cilium#43420), [@&#8203;fristonio](https://github.com/fristonio))
  - 📡 **Match New Protocols**: You can now match VRRP and IGMP protocols in host firewall rules. ([cilium/cilium#39872](cilium/cilium#39872), [@&#8203;aditighag](https://github.com/aditighag); [cilium/cilium#41949](cilium/cilium#41949), [@&#8203;kyounghunJang](https://github.com/kyounghunJang))
  - ⛔ **Actively Deny Connections**: When Network Policies deny a connection, Cilium can return ICMPv4 "Destination unreachable" messages for a friendlier deny. ([cilium/cilium#41406](cilium/cilium#41406), [@&#8203;antonipp](https://github.com/antonipp))
  - 🌐 **Select Clusters Explicitly**: When network policy selectors don't explicitly define a cluster for communication to be allowed, they will now default to only allowing the local cluster. ([cilium/cilium#40609](cilium/cilium#40609), [@&#8203;MrFreezeex](https://github.com/MrFreezeex))
  - 🔧 **Unlock Future Work**: This release brings several internal improvements to the network policy engine in preparation for features planned in the next Cilium minor release ([cilium/cilium#39906](cilium/cilium#39906), [@&#8203;vipul-21](https://github.com/vipul-21); [cilium/cilium#42784](cilium/cilium#42784), [cilium/cilium#42896](cilium/cilium#42896), [@&#8203;jrajahalme](https://github.com/jrajahalme))
  - ⚠️ **Deprecate underutilized features**: To focus on solving common problems Cilium users face, this release deprecates the Kafka protocol match fields (beta), as well as the `ToRequires` and `FromRequires` policy fields. ([cilium/cilium#43167](cilium/cilium#43167), [@&#8203;sayboras](https://github.com/sayboras); [cilium/cilium#40967](cilium/cilium#40967), [@&#8203;TheBeeZee](https://github.com/TheBeeZee))

- 🔒 **Encryption & Authentication**
  - 🔐 **Encryption Strict Modes**: Both IPsec and WireGuard transparent encryption modes now support a "strict mode" to require traffic to be encrypted between nodes. Unencrypted traffic will be dropped in this mode. ([cilium/cilium#39239](cilium/cilium#39239), [cilium/cilium#42115](cilium/cilium#42115), [@&#8203;rgo3](https://github.com/rgo3), [@&#8203;julianwiedmann](https://github.com/julianwiedmann))
  - 🚇 **Ztunnel Beta**: You can enroll namespaces into Ztunnel, which enables TCP connections between workloads to be transparently encrypted and authenticated. ([cilium/cilium#42766](cilium/cilium#42766), [cilium/cilium#42819](cilium/cilium#42819), [cilium/cilium#43227](cilium/cilium#43227) and others,  [@&#8203;ldelossa](https://github.com/ldelossa), [@&#8203;rgo3](https://github.com/rgo3), [@&#8203;nddq](https://github.com/nddq))
  - 👥 **Mutual Authentication**: The out-of-band [Mutual Authentication](https://docs.cilium.io/en/v1.19.0/network/servicemesh/mutual-authentication/mutual-authentication/) feature is now disabled by default, pending community feedback. If you have a requirement for mTLS, consider trying the new Ztunnel integration. ([cilium/cilium#42665](cilium/cilium#42665), [@&#8203;christarazi](https://github.com/christarazi))
  - ↪️ **Accelerate IPsec**: The IPsec encryption mode now supports BPF Host Routing for faster route lookups ([cilium/cilium#41997](cilium/cilium#41997), [@&#8203;pchaigno](https://github.com/pchaigno))

- 🚠 **Networking**
  - 🚀  **BIG TCP in Tunnels**: Leverage upcoming Linux support for BIG TCP when communicating over UDP-based tunnels such as VXLAN and Geneve. ([cilium/cilium#43416](cilium/cilium#43416), [@&#8203;gentoo-root](https://github.com/gentoo-root))
  - 🥌 **Packetization-Layer Path MTU Discovery**: Detect maximum transmission unit (MTU) sizes for network paths using TCP. ([cilium/cilium#42012](cilium/cilium#42012), [cilium/cilium#43710](cilium/cilium#43710), [@&#8203;tommyp1ckles](https://github.com/tommyp1ckles))
  - 🚆 **IPv6 Underlay**: You can now choose IPv6 for the tunnel underlay address family on dual-stack clusters. ([cilium/cilium#40324](cilium/cilium#40324), [@&#8203;pchaigno](https://github.com/pchaigno))
  - 🏷️ **Multi-Pool IPAM is ready for wider use**: Update the Multi-Pool IPAM feature to work with IPsec and direct routing modes, and promote it from Beta to Stable. ([cilium/cilium#40460](cilium/cilium#40460), [cilium/cilium#42191](cilium/cilium#42191), [@&#8203;pippolo84](https://github.com/pippolo84))
  - 🎭 **More Configurable Masquerade**: IP Masquerade configuration can now be customized for traffic sent to nodes in other IP subnets, and addresses in IPAM pools can be excluded from masquerade ([cilium/cilium#37568](cilium/cilium#37568), [@&#8203;behzad-mir](https://github.com/behzad-mir); [cilium/cilium#43380](cilium/cilium#43380), [@&#8203;alimehrabikoshki](https://github.com/alimehrabikoshki))

- 🕸️ **Services and Service Mesh**
  - 📣 **Layer-2 Announcements**: Add support for Neighbor Discovery Advertisements for IPv6 Layer-2 Announcements. ([cilium/cilium#39648](cilium/cilium#39648), [@&#8203;msune](https://github.com/msune))
  - 🔁 **IPv6 Service Loopback**: Pods can now connect to themselves via a Kubernetes "loopback service" using IPv6. ([cilium/cilium#39594](cilium/cilium#39594), [@&#8203;saiaunghlyanhtet](https://github.com/saiaunghlyanhtet))
  - ⛩️ **Gateway API Enhancements**: Cilium's GAMMA support now includes support for using GRPCRoute as well as HTTPRoute. ([cilium/cilium#41936](cilium/cilium#41936), [@&#8203;youngnick](https://github.com/youngnick))

- 🛣️ **Border Gateway Protocol (BGP)**
  - 🔌 **Advertise Addresses from Interfaces**: There's a new Interface BGP advertisement type that allows advertisement of IPs assigned on local interfaces. This can be useful for example in multi-homing setups, where a common node's loopback address can be advertised via multiple BGP sessions over different network interfaces. ([cilium/cilium#42469](cilium/cilium#42469), [@&#8203;rastislavs](https://github.com/rastislavs))
  - ✉️ **Override Source IP addresses**: You can override the auto-generated BGP session source IP with the IP address applied on the configured `sourceInterface` to allow binding the BGP connection to the loopback address which is not tied to the specific physical interface's lifecycle ([cilium/cilium#42583](cilium/cilium#42583), [@&#8203;rastislavs](https://github.com/rastislavs))
  - 🔁 **Withdraw Empty Routes**: Optionally withdraw BGP routes when a service has 0 endpoints, to allow balancing to a different DC/cluster with `externalTrafficPolicy=Cluster` ([cilium/cilium#40717](cilium/cilium#40717), [@&#8203;oblazek](https://github.com/oblazek))
  - ⚠️ **Move to `cilium.io/v2` API**: The support for the older `CiliumBGPPeeringPolicy` v1 API is now removed and should be replaced with v2 APIs. ([cilium/cilium#42278](cilium/cilium#42278), [@&#8203;rastislavs](https://github.com/rastislavs))

- 🛰️ **Observability**
  - 🔬 **Trace IP Options**: Configure Cilium and Hubble to trace specific packets through the cluster using IP Options. ([cilium/cilium#41306](cilium/cilium#41306), [@&#8203;Bigdelle](https://github.com/Bigdelle))
  - 🚩 **Filter Encrypted Flows**: Filter flows when using the `hubble` command line to understand the encryption status of the traffic, either `--encrypted` or `--unencrypted`. ([cilium/cilium#43096](cilium/cilium#43096), [@&#8203;SRodi](https://github.com/SRodi))
  - 🔖 **Tag Drops with Policy Names**: Hubble v1.Events drop messages now include which Network Policy caused the drop. ([cilium/cilium#41693](cilium/cilium#41693), [@&#8203;41ks](https://github.com/41ks))

- 🌅 **Performance and Scale**
  - ⚡ **Faster Network Policy Computation**: Improve Cilium resource usage for handling selectors in network policies. ([cilium/cilium#42008](cilium/cilium#42008), [@&#8203;jrajahalme](https://github.com/jrajahalme); [cilium/cilium#42580](cilium/cilium#42580), [@&#8203;odinuge](https://github.com/odinuge))
  - 🔌 **More Efficient Connection Tracking**: Several improvements have been made to reduce the number of connections being tracked by Cilium, particularly when using Geneve, VXLAN or WireGuard. ([cilium/cilium#38782](cilium/cilium#38782), [@&#8203;BenoitKnecht](https://github.com/BenoitKnecht); [cilium/cilium#41990](cilium/cilium#41990), [@&#8203;bersoare](https://github.com/bersoare))
  - 💾 **Better Scale in AWS**: Reduce memory usage for cilium-operator in large AWS environments with many resources. ([cilium/cilium#42529](cilium/cilium#42529), [@&#8203;liyihuang](https://github.com/liyihuang))

- ⚙️ **Operations**
  - 📦 **Access Helm charts via Registry**: Helm charts are also available under `quay.io/cilium/charts/cilium` ([cilium/cilium#43624](cilium/cilium#43624), [@&#8203;aanm](https://github.com/aanm))
  - 📊 **Metrics Encryption**: Add TLS/mTLS support for Prometheus metrics exposed by the Cilium Operator. ([cilium/cilium#42077](cilium/cilium#42077), [@&#8203;phuhung273](https://github.com/phuhung273))
  - 🤖 **Easier Multi-Cluster install**: There's now support for auto-installing the Custom Resource Definitions (CRDs) for Multi-Cluster  Services (MCS). ([cilium/cilium#40729](cilium/cilium#40729), [@&#8203;MrFreezeex](https://github.com/MrFreezeex))
  - 📜 **Simpler Certificate Management**: Streamline Cluster Mesh and Hubble certificate generation when using GitOps approaches. ([cilium/cilium#42298](cilium/cilium#42298), [@&#8203;MrFreezeex](https://github.com/MrFreezeex))
  - 🛠️ **Cilium dependencies** were updated to Kubernetes v1.35, Envoy v1.35, Gateway API v1.4, and GoBGP v3.37. ([cilium/cilium#43422](cilium/cilium#43422), [@&#8203;aanm](https://github.com/aanm); [cilium/cilium#40569](cilium/cilium#40569), [@&#8203;sayboras](https://github.com/sayboras); [cilium/cilium#41936](cilium/cilium#41936), [@&#8203;youngnick](https://github.com/youngnick); [cilium/cilium#42824](cilium/cilium#42824), [@&#8203;rastislavs](https://github.com/rastislavs)).

- 🏠 **Community**
  - ❤️ **Production Case Studies**: Many end-users have stepped forward to tell their stories running Cilium in production. If your company wants to submit their case studies let us know. We would love to hear your feedback!
  - 📰 See studies with [Airbnb](https://youtu.be/7KHenRXNGAw?si=ldTS-X_W0svxo429\&t=546), [Cloudera](https://aws.amazon.com/blogs/migration-and-modernization/scaling-clouderas-development-environment-leveraging-amazon-eks-karpenter-bottlerocket-and-cilium-for-hybrid-cloud/),[ Cybozu](https://www.cncf.io/case-studies/cybozu/), [ESnet](https://www.cncf.io/case-studies/esnet/),[ Nutanix](https://www.cncf.io/case-studies/nutanix/), [OVHcloud](https://corporate.ovhcloud.com/en-gb/newsroom/news/ovhcloud-managed-kubernetes-service-standard-3az/), [TikTok](https://www.youtube.com/watch?v=y0qlhiKtDGo), [University of Wisconsin–Madison](https://www.cncf.io/case-studies/university-of-wisconsin-madison/).
  - 🇺🇸 **Atlanta Events**: The community gathered at [CiliumCon](https://www.youtube.com/playlist?list=PLDg_GiBbAx-mOnWuzd_NXoRfuW9HZAxeZ) and the [Cilium Developer Summit](https://github.com/cilium/dev-summits/blob/main/2025-NA/README.md) in Atlanta.
  - 🇳🇱 **Amsterdam Events**: Meet us at the upcoming [CiliumCon](https://events.linuxfoundation.org/kubecon-cloudnativecon-europe/co-located-events/ciliumcon/) and [Cilium Developer Summit](https://github.com/cilium/dev-summits/tree/main/2026-EU) in Amsterdam, March 23-27. [Read more](https://cilium.io/blog/2026/01/23/cilium-at-kubecon-eu-2026/) about where to find Cilium during the show.
  - 🔟 **Cilium is 10**: Read the [2025 Cilium Annual Report](https://www.cncf.io/wp-content/uploads/2025/12/cilium-annual-report-2025-final.pdf) to see the latest project milestones, a decade on from its first commit.

To keep up to date with all the latest Cilium releases, join #release 🎉

:birthday::heart::heart::heart::birthday:
This is a very special release for Cilium, as it celebrates **10 years** since the first commit. We couldn’t be more proud of what this project has accomplished. All the GitHub issues, pull requests, reviews, stars, forks, Docker pulls, Helm installs, Kubernetes applies, CI runs, bug reports, design docs, discussions, meetings, Slack messages, YouTube streams, eCHO episodes, conference talks, blog posts, demos, and presentations have made the project the success it is today.
:birthday::heart::heart::heart::birthday:

##### Docker Manifests

##### cilium

`quay.io/cilium/cilium:v1.19.0@&#8203;sha256:be9f8571c2e114b3e12e41f785f2356ade703b2eac936aa878805565f0468c60`

##### clustermesh-apiserver

`quay.io/cilium/clustermesh-apiserver:v1.19.0@&#8203;sha256:0e3b89fdb116eb0f5579fe8ee3fabb1a7c4d97987a1ae927491d9185785d4a49`

##### docker-plugin

`quay.io/cilium/docker-plugin:v1.19.0@&#8203;sha256:35727047384f3d7a2684885003b266bf7a7add8fc66ca564b222f71c16057f50`

##### hubble-relay

`quay.io/cilium/hubble-relay:v1.19.0@&#8203;sha256:7f17e5bb51a9f35bbc8e7a9ad5e347f03ff8003c2e5cc81171e8727a10bf03b4`

##### operator-alibabacloud

`quay.io/cilium/operator-alibabacloud:v1.19.0@&#8203;sha256:5cb3d6981c233616037f3e13b5bc0020d114ad8db1b7360618b224e4c0b02ef0`

##### operator-aws

`quay.io/cilium/operator-aws:v1.19.0@&#8203;sha256:7a236ae256a4fbd3f72d516921131eba5b43f401ba37cdee5cd0e8c26f9263e6`

##### operator-azure

`quay.io/cilium/operator-azure:v1.19.0@&#8203;sha256:6ae7e0d75c74836af3600b775201c89ea7fcc13d6e08fdb0c52927309f31cd2a`

##### operator-generic

`quay.io/cilium/operator-generic:v1.19.0@&#8203;sha256:5b04006015e5800307dc6314676edc4c0bb7ac2fc7848be2b94b43bb030ab648`

##### operator

`quay.io/cilium/operator:v1.19.0@&#8203;sha256:deca84f442752dca0745dd09b13e8004569414839019ad79ac58f9fcaa3b9d65`

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4wLjIiLCJ1cGRhdGVkSW5WZXIiOiI0My4wLjMiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbImNoYXJ0Il19-->

Reviewed-on: https://gitea.alexlebens.dev/alexlebens/infrastructure/pulls/3699
Co-authored-by: Renovate Bot <[email protected]>
Co-committed-by: Renovate Bot <[email protected]>
alexlebens pushed a commit to alexlebens/infrastructure that referenced this pull request Feb 5, 2026
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [cilium/cilium](https://github.com/cilium/cilium) | minor | `1.18.6` → `1.19.0` |

---

### Release Notes

<details>
<summary>cilium/cilium (cilium/cilium)</summary>

### [`v1.19.0`](https://github.com/cilium/cilium/releases/tag/v1.19.0): 1.19.0

[Compare Source](cilium/cilium@1.18.6...1.19.0)

🎉 **Release Announcement** 🎉: We are excited to announce the [Cilium 1.19.0](https://github.com/cilium/cilium/releases/tag/v1.19.0) release!

A total of **2934 new commits** have been contributed to this release by a growing community of over **1010 developers** and over **23,600 GitHub stars**! 🤩

⚠️ You may need to take action during upgrade to Cilium v1.19 if you use Network Policies, Cluster Mesh, LoadBalancer IPAM or BGP. See the [Upgrade Guide](https://docs.cilium.io/en/v1.19/operations/upgrade/#upgrade-notes) for more details.

The full changelog can be found [here](https://github.com/cilium/cilium/blob/v1.19/CHANGELOG.md).

Here are some of the highlights:

- 🛡️ **Network Policy**
  - 🃏 **Multi-Level DNS Matches**: DNS Policies match pattern now support a wildcard prefix(*`**.`*) to match multilevel subdomain as pattern prefix. ([cilium/cilium#43420](cilium/cilium#43420), [@&#8203;fristonio](https://github.com/fristonio))
  - 📡 **Match New Protocols**: You can now match VRRP and IGMP protocols in host firewall rules. ([cilium/cilium#39872](cilium/cilium#39872), [@&#8203;aditighag](https://github.com/aditighag); [cilium/cilium#41949](cilium/cilium#41949), [@&#8203;kyounghunJang](https://github.com/kyounghunJang))
  - ⛔ **Actively Deny Connections**: When Network Policies deny a connection, Cilium can return ICMPv4 "Destination unreachable" messages for a friendlier deny. ([cilium/cilium#41406](cilium/cilium#41406), [@&#8203;antonipp](https://github.com/antonipp))
  - 🌐 **Select Clusters Explicitly**: When network policy selectors don't explicitly define a cluster for communication to be allowed, they will now default to only allowing the local cluster. ([cilium/cilium#40609](cilium/cilium#40609), [@&#8203;MrFreezeex](https://github.com/MrFreezeex))
  - 🔧 **Unlock Future Work**: This release brings several internal improvements to the network policy engine in preparation for features planned in the next Cilium minor release ([cilium/cilium#39906](cilium/cilium#39906), [@&#8203;vipul-21](https://github.com/vipul-21); [cilium/cilium#42784](cilium/cilium#42784), [cilium/cilium#42896](cilium/cilium#42896), [@&#8203;jrajahalme](https://github.com/jrajahalme))
  - ⚠️ **Deprecate underutilized features**: To focus on solving common problems Cilium users face, this release deprecates the Kafka protocol match fields (beta), as well as the `ToRequires` and `FromRequires` policy fields. ([cilium/cilium#43167](cilium/cilium#43167), [@&#8203;sayboras](https://github.com/sayboras); [cilium/cilium#40967](cilium/cilium#40967), [@&#8203;TheBeeZee](https://github.com/TheBeeZee))

- 🔒 **Encryption & Authentication**
  - 🔐 **Encryption Strict Modes**: Both IPsec and WireGuard transparent encryption modes now support a "strict mode" to require traffic to be encrypted between nodes. Unencrypted traffic will be dropped in this mode. ([cilium/cilium#39239](cilium/cilium#39239), [cilium/cilium#42115](cilium/cilium#42115), [@&#8203;rgo3](https://github.com/rgo3), [@&#8203;julianwiedmann](https://github.com/julianwiedmann))
  - 🚇 **Ztunnel Beta**: You can enroll namespaces into Ztunnel, which enables TCP connections between workloads to be transparently encrypted and authenticated. ([cilium/cilium#42766](cilium/cilium#42766), [cilium/cilium#42819](cilium/cilium#42819), [cilium/cilium#43227](cilium/cilium#43227) and others,  [@&#8203;ldelossa](https://github.com/ldelossa), [@&#8203;rgo3](https://github.com/rgo3), [@&#8203;nddq](https://github.com/nddq))
  - 👥 **Mutual Authentication**: The out-of-band [Mutual Authentication](https://docs.cilium.io/en/v1.19.0/network/servicemesh/mutual-authentication/mutual-authentication/) feature is now disabled by default, pending community feedback. If you have a requirement for mTLS, consider trying the new Ztunnel integration. ([cilium/cilium#42665](cilium/cilium#42665), [@&#8203;christarazi](https://github.com/christarazi))
  - ↪️ **Accelerate IPsec**: The IPsec encryption mode now supports BPF Host Routing for faster route lookups ([cilium/cilium#41997](cilium/cilium#41997), [@&#8203;pchaigno](https://github.com/pchaigno))

- 🚠 **Networking**
  - 🚀  **BIG TCP in Tunnels**: Leverage upcoming Linux support for BIG TCP when communicating over UDP-based tunnels such as VXLAN and Geneve. ([cilium/cilium#43416](cilium/cilium#43416), [@&#8203;gentoo-root](https://github.com/gentoo-root))
  - 🥌 **Packetization-Layer Path MTU Discovery**: Detect maximum transmission unit (MTU) sizes for network paths using TCP. ([cilium/cilium#42012](cilium/cilium#42012), [cilium/cilium#43710](cilium/cilium#43710), [@&#8203;tommyp1ckles](https://github.com/tommyp1ckles))
  - 🚆 **IPv6 Underlay**: You can now choose IPv6 for the tunnel underlay address family on dual-stack clusters. ([cilium/cilium#40324](cilium/cilium#40324), [@&#8203;pchaigno](https://github.com/pchaigno))
  - 🏷️ **Multi-Pool IPAM is ready for wider use**: Update the Multi-Pool IPAM feature to work with IPsec and direct routing modes, and promote it from Beta to Stable. ([cilium/cilium#40460](cilium/cilium#40460), [cilium/cilium#42191](cilium/cilium#42191), [@&#8203;pippolo84](https://github.com/pippolo84))
  - 🎭 **More Configurable Masquerade**: IP Masquerade configuration can now be customized for traffic sent to nodes in other IP subnets, and addresses in IPAM pools can be excluded from masquerade ([cilium/cilium#37568](cilium/cilium#37568), [@&#8203;behzad-mir](https://github.com/behzad-mir); [cilium/cilium#43380](cilium/cilium#43380), [@&#8203;alimehrabikoshki](https://github.com/alimehrabikoshki))

- 🕸️ **Services and Service Mesh**
  - 📣 **Layer-2 Announcements**: Add support for Neighbor Discovery Advertisements for IPv6 Layer-2 Announcements. ([cilium/cilium#39648](cilium/cilium#39648), [@&#8203;msune](https://github.com/msune))
  - 🔁 **IPv6 Service Loopback**: Pods can now connect to themselves via a Kubernetes "loopback service" using IPv6. ([cilium/cilium#39594](cilium/cilium#39594), [@&#8203;saiaunghlyanhtet](https://github.com/saiaunghlyanhtet))
  - ⛩️ **Gateway API Enhancements**: Cilium's GAMMA support now includes support for using GRPCRoute as well as HTTPRoute. ([cilium/cilium#41936](cilium/cilium#41936), [@&#8203;youngnick](https://github.com/youngnick))

- 🛣️ **Border Gateway Protocol (BGP)**
  - 🔌 **Advertise Addresses from Interfaces**: There's a new Interface BGP advertisement type that allows advertisement of IPs assigned on local interfaces. This can be useful for example in multi-homing setups, where a common node's loopback address can be advertised via multiple BGP sessions over different network interfaces. ([cilium/cilium#42469](cilium/cilium#42469), [@&#8203;rastislavs](https://github.com/rastislavs))
  - ✉️ **Override Source IP addresses**: You can override the auto-generated BGP session source IP with the IP address applied on the configured `sourceInterface` to allow binding the BGP connection to the loopback address which is not tied to the specific physical interface's lifecycle ([cilium/cilium#42583](cilium/cilium#42583), [@&#8203;rastislavs](https://github.com/rastislavs))
  - 🔁 **Withdraw Empty Routes**: Optionally withdraw BGP routes when a service has 0 endpoints, to allow balancing to a different DC/cluster with `externalTrafficPolicy=Cluster` ([cilium/cilium#40717](cilium/cilium#40717), [@&#8203;oblazek](https://github.com/oblazek))
  - ⚠️ **Move to `cilium.io/v2` API**: The support for the older `CiliumBGPPeeringPolicy` v1 API is now removed and should be replaced with v2 APIs. ([cilium/cilium#42278](cilium/cilium#42278), [@&#8203;rastislavs](https://github.com/rastislavs))

- 🛰️ **Observability**
  - 🔬 **Trace IP Options**: Configure Cilium and Hubble to trace specific packets through the cluster using IP Options. ([cilium/cilium#41306](cilium/cilium#41306), [@&#8203;Bigdelle](https://github.com/Bigdelle))
  - 🚩 **Filter Encrypted Flows**: Filter flows when using the `hubble` command line to understand the encryption status of the traffic, either `--encrypted` or `--unencrypted`. ([cilium/cilium#43096](cilium/cilium#43096), [@&#8203;SRodi](https://github.com/SRodi))
  - 🔖 **Tag Drops with Policy Names**: Hubble v1.Events drop messages now include which Network Policy caused the drop. ([cilium/cilium#41693](cilium/cilium#41693), [@&#8203;41ks](https://github.com/41ks))

- 🌅 **Performance and Scale**
  - ⚡ **Faster Network Policy Computation**: Improve Cilium resource usage for handling selectors in network policies. ([cilium/cilium#42008](cilium/cilium#42008), [@&#8203;jrajahalme](https://github.com/jrajahalme); [cilium/cilium#42580](cilium/cilium#42580), [@&#8203;odinuge](https://github.com/odinuge))
  - 🔌 **More Efficient Connection Tracking**: Several improvements have been made to reduce the number of connections being tracked by Cilium, particularly when using Geneve, VXLAN or WireGuard. ([cilium/cilium#38782](cilium/cilium#38782), [@&#8203;BenoitKnecht](https://github.com/BenoitKnecht); [cilium/cilium#41990](cilium/cilium#41990), [@&#8203;bersoare](https://github.com/bersoare))
  - 💾 **Better Scale in AWS**: Reduce memory usage for cilium-operator in large AWS environments with many resources. ([cilium/cilium#42529](cilium/cilium#42529), [@&#8203;liyihuang](https://github.com/liyihuang))

- ⚙️ **Operations**
  - 📦 **Access Helm charts via Registry**: Helm charts are also available under `quay.io/cilium/charts/cilium` ([cilium/cilium#43624](cilium/cilium#43624), [@&#8203;aanm](https://github.com/aanm))
  - 📊 **Metrics Encryption**: Add TLS/mTLS support for Prometheus metrics exposed by the Cilium Operator. ([cilium/cilium#42077](cilium/cilium#42077), [@&#8203;phuhung273](https://github.com/phuhung273))
  - 🤖 **Easier Multi-Cluster install**: There's now support for auto-installing the Custom Resource Definitions (CRDs) for Multi-Cluster  Services (MCS). ([cilium/cilium#40729](cilium/cilium#40729), [@&#8203;MrFreezeex](https://github.com/MrFreezeex))
  - 📜 **Simpler Certificate Management**: Streamline Cluster Mesh and Hubble certificate generation when using GitOps approaches. ([cilium/cilium#42298](cilium/cilium#42298), [@&#8203;MrFreezeex](https://github.com/MrFreezeex))
  - 🛠️ **Cilium dependencies** were updated to Kubernetes v1.35, Envoy v1.35, Gateway API v1.4, and GoBGP v3.37. ([cilium/cilium#43422](cilium/cilium#43422), [@&#8203;aanm](https://github.com/aanm); [cilium/cilium#40569](cilium/cilium#40569), [@&#8203;sayboras](https://github.com/sayboras); [cilium/cilium#41936](cilium/cilium#41936), [@&#8203;youngnick](https://github.com/youngnick); [cilium/cilium#42824](cilium/cilium#42824), [@&#8203;rastislavs](https://github.com/rastislavs)).

- 🏠 **Community**
  - ❤️ **Production Case Studies**: Many end-users have stepped forward to tell their stories running Cilium in production. If your company wants to submit their case studies let us know. We would love to hear your feedback!
  - 📰 See studies with [Airbnb](https://youtu.be/7KHenRXNGAw?si=ldTS-X_W0svxo429\&t=546), [Cloudera](https://aws.amazon.com/blogs/migration-and-modernization/scaling-clouderas-development-environment-leveraging-amazon-eks-karpenter-bottlerocket-and-cilium-for-hybrid-cloud/),[ Cybozu](https://www.cncf.io/case-studies/cybozu/), [ESnet](https://www.cncf.io/case-studies/esnet/),[ Nutanix](https://www.cncf.io/case-studies/nutanix/), [OVHcloud](https://corporate.ovhcloud.com/en-gb/newsroom/news/ovhcloud-managed-kubernetes-service-standard-3az/), [TikTok](https://www.youtube.com/watch?v=y0qlhiKtDGo), [University of Wisconsin–Madison](https://www.cncf.io/case-studies/university-of-wisconsin-madison/).
  - 🇺🇸 **Atlanta Events**: The community gathered at [CiliumCon](https://www.youtube.com/playlist?list=PLDg_GiBbAx-mOnWuzd_NXoRfuW9HZAxeZ) and the [Cilium Developer Summit](https://github.com/cilium/dev-summits/blob/main/2025-NA/README.md) in Atlanta.
  - 🇳🇱 **Amsterdam Events**: Meet us at the upcoming [CiliumCon](https://events.linuxfoundation.org/kubecon-cloudnativecon-europe/co-located-events/ciliumcon/) and [Cilium Developer Summit](https://github.com/cilium/dev-summits/tree/main/2026-EU) in Amsterdam, March 23-27. [Read more](https://cilium.io/blog/2026/01/23/cilium-at-kubecon-eu-2026/) about where to find Cilium during the show.
  - 🔟 **Cilium is 10**: Read the [2025 Cilium Annual Report](https://www.cncf.io/wp-content/uploads/2025/12/cilium-annual-report-2025-final.pdf) to see the latest project milestones, a decade on from its first commit.

To keep up to date with all the latest Cilium releases, join #release 🎉

:birthday::heart::heart::heart::birthday:
This is a very special release for Cilium, as it celebrates **10 years** since the first commit. We couldn’t be more proud of what this project has accomplished. All the GitHub issues, pull requests, reviews, stars, forks, Docker pulls, Helm installs, Kubernetes applies, CI runs, bug reports, design docs, discussions, meetings, Slack messages, YouTube streams, eCHO episodes, conference talks, blog posts, demos, and presentations have made the project the success it is today.
:birthday::heart::heart::heart::birthday:

#### Docker Manifests

##### cilium

`quay.io/cilium/cilium:v1.19.0@&#8203;sha256:be9f8571c2e114b3e12e41f785f2356ade703b2eac936aa878805565f0468c60`

##### clustermesh-apiserver

`quay.io/cilium/clustermesh-apiserver:v1.19.0@&#8203;sha256:0e3b89fdb116eb0f5579fe8ee3fabb1a7c4d97987a1ae927491d9185785d4a49`

##### docker-plugin

`quay.io/cilium/docker-plugin:v1.19.0@&#8203;sha256:35727047384f3d7a2684885003b266bf7a7add8fc66ca564b222f71c16057f50`

##### hubble-relay

`quay.io/cilium/hubble-relay:v1.19.0@&#8203;sha256:7f17e5bb51a9f35bbc8e7a9ad5e347f03ff8003c2e5cc81171e8727a10bf03b4`

##### operator-alibabacloud

`quay.io/cilium/operator-alibabacloud:v1.19.0@&#8203;sha256:5cb3d6981c233616037f3e13b5bc0020d114ad8db1b7360618b224e4c0b02ef0`

##### operator-aws

`quay.io/cilium/operator-aws:v1.19.0@&#8203;sha256:7a236ae256a4fbd3f72d516921131eba5b43f401ba37cdee5cd0e8c26f9263e6`

##### operator-azure

`quay.io/cilium/operator-azure:v1.19.0@&#8203;sha256:6ae7e0d75c74836af3600b775201c89ea7fcc13d6e08fdb0c52927309f31cd2a`

##### operator-generic

`quay.io/cilium/operator-generic:v1.19.0@&#8203;sha256:5b04006015e5800307dc6314676edc4c0bb7ac2fc7848be2b94b43bb030ab648`

##### operator

`quay.io/cilium/operator:v1.19.0@&#8203;sha256:deca84f442752dca0745dd09b13e8004569414839019ad79ac58f9fcaa3b9d65`

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4wLjMiLCJ1cGRhdGVkSW5WZXIiOiI0My4wLjMiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbImltYWdlIl19-->

Reviewed-on: https://gitea.alexlebens.dev/alexlebens/infrastructure/pulls/3715
Co-authored-by: Renovate Bot <[email protected]>
Co-committed-by: Renovate Bot <[email protected]>
lumiere-bot bot added a commit to coolguy1771/home-ops that referenced this pull request Feb 6, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [cilium](https://cilium.io/)
([source](https://redirect.github.com/cilium/cilium)) | HelmChart |
minor | `1.18.6` → `1.19.0` |

---

### Release Notes

<details>
<summary>cilium/cilium (cilium)</summary>

###
[`v1.19.0`](https://redirect.github.com/cilium/cilium/releases/tag/v1.19.0):
1.19.0

[Compare
Source](https://redirect.github.com/cilium/cilium/compare/1.18.6...1.19.0)

🎉 **Release Announcement** 🎉: We are excited to announce the [Cilium
1.19.0](https://redirect.github.com/cilium/cilium/releases/tag/v1.19.0)
release!

A total of **2934 new commits** have been contributed to this release by
a growing community of over **1010 developers** and over **23,600 GitHub
stars**! 🤩

⚠️ You may need to take action during upgrade to Cilium v1.19 if you use
Network Policies, Cluster Mesh, LoadBalancer IPAM or BGP. See the
[Upgrade
Guide](https://docs.cilium.io/en/v1.19/operations/upgrade/#upgrade-notes)
for more details.

The full changelog can be found
[here](https://redirect.github.com/cilium/cilium/blob/v1.19/CHANGELOG.md).

Here are some of the highlights:

- 🛡️ **Network Policy**
- 🃏 **Multi-Level DNS Matches**: DNS Policies match pattern now support
a wildcard prefix(*`**.`*) to match multilevel subdomain as pattern
prefix.
([cilium/cilium#43420](https://redirect.github.com/cilium/cilium/pull/43420),
[@&#8203;fristonio](https://redirect.github.com/fristonio))
- 📡 **Match New Protocols**: You can now match VRRP and IGMP protocols
in host firewall rules.
([cilium/cilium#39872](https://redirect.github.com/cilium/cilium/pull/39872),
[@&#8203;aditighag](https://redirect.github.com/aditighag);
[cilium/cilium#41949](https://redirect.github.com/cilium/cilium/pull/41949),
[@&#8203;kyounghunJang](https://redirect.github.com/kyounghunJang))
- ⛔ **Actively Deny Connections**: When Network Policies deny a
connection, Cilium can return ICMPv4 "Destination unreachable" messages
for a friendlier deny.
([cilium/cilium#41406](https://redirect.github.com/cilium/cilium/pull/41406),
[@&#8203;antonipp](https://redirect.github.com/antonipp))
- 🌐 **Select Clusters Explicitly**: When network policy selectors don't
explicitly define a cluster for communication to be allowed, they will
now default to only allowing the local cluster.
([cilium/cilium#40609](https://redirect.github.com/cilium/cilium/pull/40609),
[@&#8203;MrFreezeex](https://redirect.github.com/MrFreezeex))
- 🔧 **Unlock Future Work**: This release brings several internal
improvements to the network policy engine in preparation for features
planned in the next Cilium minor release
([cilium/cilium#39906](https://redirect.github.com/cilium/cilium/pull/39906),
[@&#8203;vipul-21](https://redirect.github.com/vipul-21);
[cilium/cilium#42784](https://redirect.github.com/cilium/cilium/pull/42784),
[cilium/cilium#42896](https://redirect.github.com/cilium/cilium/pull/42896),
[@&#8203;jrajahalme](https://redirect.github.com/jrajahalme))
- ⚠️ **Deprecate underutilized features**: To focus on solving common
problems Cilium users face, this release deprecates the Kafka protocol
match fields (beta), as well as the `ToRequires` and `FromRequires`
policy fields.
([cilium/cilium#43167](https://redirect.github.com/cilium/cilium/pull/43167),
[@&#8203;sayboras](https://redirect.github.com/sayboras);
[cilium/cilium#40967](https://redirect.github.com/cilium/cilium/pull/40967),
[@&#8203;TheBeeZee](https://redirect.github.com/TheBeeZee))

- 🔒 **Encryption & Authentication**
- 🔐 **Encryption Strict Modes**: Both IPsec and WireGuard transparent
encryption modes now support a "strict mode" to require traffic to be
encrypted between nodes. Unencrypted traffic will be dropped in this
mode.
([cilium/cilium#39239](https://redirect.github.com/cilium/cilium/pull/39239),
[cilium/cilium#42115](https://redirect.github.com/cilium/cilium/pull/42115),
[@&#8203;rgo3](https://redirect.github.com/rgo3),
[@&#8203;julianwiedmann](https://redirect.github.com/julianwiedmann))
- 🚇 **Ztunnel Beta**: You can enroll namespaces into Ztunnel, which
enables TCP connections between workloads to be transparently encrypted
and authenticated.
([cilium/cilium#42766](https://redirect.github.com/cilium/cilium/pull/42766),
[cilium/cilium#42819](https://redirect.github.com/cilium/cilium/pull/42819),
[cilium/cilium#43227](https://redirect.github.com/cilium/cilium/pull/43227)
and others, [@&#8203;ldelossa](https://redirect.github.com/ldelossa),
[@&#8203;rgo3](https://redirect.github.com/rgo3),
[@&#8203;nddq](https://redirect.github.com/nddq))
- 👥 **Mutual Authentication**: The out-of-band [Mutual
Authentication](https://docs.cilium.io/en/v1.19/network/servicemesh/mutual-authentication/mutual-authentication/)
feature is now disabled by default, pending community feedback. If you
have a requirement for mTLS, consider trying the new Ztunnel
integration.
([cilium/cilium#42665](https://redirect.github.com/cilium/cilium/pull/42665),
[@&#8203;christarazi](https://redirect.github.com/christarazi))
- ↪️ **Accelerate IPsec**: The IPsec encryption mode now supports BPF
Host Routing for faster route lookups
([cilium/cilium#41997](https://redirect.github.com/cilium/cilium/pull/41997),
[@&#8203;pchaigno](https://redirect.github.com/pchaigno))

- 🚠 **Networking**
- 🚀 **BIG TCP in Tunnels**: Leverage upcoming Linux support for BIG TCP
when communicating over UDP-based tunnels such as VXLAN and Geneve.
([cilium/cilium#43416](https://redirect.github.com/cilium/cilium/pull/43416),
[@&#8203;gentoo-root](https://redirect.github.com/gentoo-root))
- 🥌 **Packetization-Layer Path MTU Discovery**: Detect maximum
transmission unit (MTU) sizes for network paths using TCP.
([cilium/cilium#42012](https://redirect.github.com/cilium/cilium/pull/42012),
[cilium/cilium#43710](https://redirect.github.com/cilium/cilium/pull/43710),
[@&#8203;tommyp1ckles](https://redirect.github.com/tommyp1ckles))
- 🚆 **IPv6 Underlay**: You can now choose IPv6 for the tunnel underlay
address family on dual-stack clusters.
([cilium/cilium#40324](https://redirect.github.com/cilium/cilium/pull/40324),
[@&#8203;pchaigno](https://redirect.github.com/pchaigno))
- 🏷️ **Multi-Pool IPAM is ready for wider use**: Update the Multi-Pool
IPAM feature to work with IPsec and direct routing modes, and promote it
from Beta to Stable.
([cilium/cilium#40460](https://redirect.github.com/cilium/cilium/pull/40460),
[cilium/cilium#42191](https://redirect.github.com/cilium/cilium/pull/42191),
[@&#8203;pippolo84](https://redirect.github.com/pippolo84))
- 🎭 **More Configurable Masquerade**: IP Masquerade configuration can
now be customized for traffic sent to nodes in other IP subnets, and
addresses in IPAM pools can be excluded from masquerade
([cilium/cilium#37568](https://redirect.github.com/cilium/cilium/pull/37568),
[@&#8203;behzad-mir](https://redirect.github.com/behzad-mir);
[cilium/cilium#43380](https://redirect.github.com/cilium/cilium/pull/43380),
[@&#8203;alimehrabikoshki](https://redirect.github.com/alimehrabikoshki))

- 🕸️ **Services and Service Mesh**
- 📣 **Layer-2 Announcements**: Add support for Neighbor Discovery
Advertisements for IPv6 Layer-2 Announcements.
([cilium/cilium#39648](https://redirect.github.com/cilium/cilium/pull/39648),
[@&#8203;msune](https://redirect.github.com/msune))
- 🔁 **IPv6 Service Loopback**: Pods can now connect to themselves via a
Kubernetes "loopback service" using IPv6.
([cilium/cilium#39594](https://redirect.github.com/cilium/cilium/pull/39594),
[@&#8203;saiaunghlyanhtet](https://redirect.github.com/saiaunghlyanhtet))
- ⛩️ **Gateway API Enhancements**: Cilium's GAMMA support now includes
support for using GRPCRoute as well as HTTPRoute.
([cilium/cilium#41936](https://redirect.github.com/cilium/cilium/pull/41936),
[@&#8203;youngnick](https://redirect.github.com/youngnick))

- 🛣️ **Border Gateway Protocol (BGP)**
- 🔌 **Advertise Addresses from Interfaces**: There's a new Interface BGP
advertisement type that allows advertisement of IPs assigned on local
interfaces. This can be useful for example in multi-homing setups, where
a common node's loopback address can be advertised via multiple BGP
sessions over different network interfaces.
([cilium/cilium#42469](https://redirect.github.com/cilium/cilium/pull/42469),
[@&#8203;rastislavs](https://redirect.github.com/rastislavs))
- ✉️ **Override Source IP addresses**: You can override the
auto-generated BGP session source IP with the IP address applied on the
configured `sourceInterface` to allow binding the BGP connection to the
loopback address which is not tied to the specific physical interface's
lifecycle
([cilium/cilium#42583](https://redirect.github.com/cilium/cilium/pull/42583),
[@&#8203;rastislavs](https://redirect.github.com/rastislavs))
- 🔁 **Withdraw Empty Routes**: Optionally withdraw BGP routes when a
service has 0 endpoints, to allow balancing to a different DC/cluster
with `externalTrafficPolicy=Cluster`
([cilium/cilium#40717](https://redirect.github.com/cilium/cilium/pull/40717),
[@&#8203;oblazek](https://redirect.github.com/oblazek))
- ⚠️ **Move to `cilium.io/v2` API**: The support for the older
`CiliumBGPPeeringPolicy` v1 API is now removed and should be replaced
with v2 APIs.
([cilium/cilium#42278](https://redirect.github.com/cilium/cilium/pull/42278),
[@&#8203;rastislavs](https://redirect.github.com/rastislavs))

- 🛰️ **Observability**
- 🔬 **Trace IP Options**: Configure Cilium and Hubble to trace specific
packets through the cluster using IP Options.
([cilium/cilium#41306](https://redirect.github.com/cilium/cilium/pull/41306),
[@&#8203;Bigdelle](https://redirect.github.com/Bigdelle))
- 🚩 **Filter Encrypted Flows**: Filter flows when using the `hubble`
command line to understand the encryption status of the traffic, either
`--encrypted` or `--unencrypted`.
([cilium/cilium#43096](https://redirect.github.com/cilium/cilium/pull/43096),
[@&#8203;SRodi](https://redirect.github.com/SRodi))
- 🔖 **Tag Drops with Policy Names**: Hubble v1.Events drop messages now
include which Network Policy caused the drop.
([cilium/cilium#41693](https://redirect.github.com/cilium/cilium/pull/41693),
[@&#8203;41ks](https://redirect.github.com/41ks))

- 🌅 **Performance and Scale**
- ⚡ **Faster Network Policy Computation**: Improve Cilium resource usage
for handling selectors in network policies.
([cilium/cilium#42008](https://redirect.github.com/cilium/cilium/pull/42008),
[@&#8203;jrajahalme](https://redirect.github.com/jrajahalme);
[cilium/cilium#42580](https://redirect.github.com/cilium/cilium/pull/42580),
[@&#8203;odinuge](https://redirect.github.com/odinuge))
- 🔌 **More Efficient Connection Tracking**: Several improvements have
been made to reduce the number of connections being tracked by Cilium,
particularly when using Geneve, VXLAN or WireGuard.
([cilium/cilium#38782](https://redirect.github.com/cilium/cilium/pull/38782),
[@&#8203;BenoitKnecht](https://redirect.github.com/BenoitKnecht);
[cilium/cilium#41990](https://redirect.github.com/cilium/cilium/pull/41990),
[@&#8203;bersoare](https://redirect.github.com/bersoare))
- 💾 **Better Scale in AWS**: Reduce memory usage for cilium-operator in
large AWS environments with many resources.
([cilium/cilium#42529](https://redirect.github.com/cilium/cilium/pull/42529),
[@&#8203;liyihuang](https://redirect.github.com/liyihuang))

- ⚙️ **Operations**
- 📦 **Access Helm charts via Registry**: Helm charts are also available
under `quay.io/cilium/charts/cilium`
([cilium/cilium#43624](https://redirect.github.com/cilium/cilium/pull/43624),
[@&#8203;aanm](https://redirect.github.com/aanm))
- 📊 **Metrics Encryption**: Add TLS/mTLS support for Prometheus metrics
exposed by the Cilium Operator.
([cilium/cilium#42077](https://redirect.github.com/cilium/cilium/pull/42077),
[@&#8203;phuhung273](https://redirect.github.com/phuhung273))
- 🤖 **Easier Multi-Cluster install**: There's now support for
auto-installing the Custom Resource Definitions (CRDs) for Multi-Cluster
Services (MCS).
([cilium/cilium#40729](https://redirect.github.com/cilium/cilium/pull/40729),
[@&#8203;MrFreezeex](https://redirect.github.com/MrFreezeex))
- 📜 **Simpler Certificate Management**: Streamline Cluster Mesh and
Hubble certificate generation when using GitOps approaches.
([cilium/cilium#42298](https://redirect.github.com/cilium/cilium/pull/42298),
[@&#8203;MrFreezeex](https://redirect.github.com/MrFreezeex))
- 🛠️ **Cilium dependencies** were updated to Kubernetes v1.35, Envoy
v1.35, Gateway API v1.4, and GoBGP v3.37.
([cilium/cilium#43422](https://redirect.github.com/cilium/cilium/pull/43422),
[@&#8203;aanm](https://redirect.github.com/aanm);
[cilium/cilium#40569](https://redirect.github.com/cilium/cilium/pull/40569),
[@&#8203;sayboras](https://redirect.github.com/sayboras);
[cilium/cilium#41936](https://redirect.github.com/cilium/cilium/pull/41936),
[@&#8203;youngnick](https://redirect.github.com/youngnick);
[cilium/cilium#42824](https://redirect.github.com/cilium/cilium/pull/42824),
[@&#8203;rastislavs](https://redirect.github.com/rastislavs)).

- 🏠 **Community**
- ❤️ **Production Case Studies**: Many end-users have stepped forward to
tell their stories running Cilium in production. If your company wants
to submit their case studies let us know. We would love to hear your
feedback!
- 📰 See studies with
[Airbnb](https://youtu.be/7KHenRXNGAw?si=ldTS-X_W0svxo429\&t=546),
[Cloudera](https://aws.amazon.com/blogs/migration-and-modernization/scaling-clouderas-development-environment-leveraging-amazon-eks-karpenter-bottlerocket-and-cilium-for-hybrid-cloud/),[
Cybozu](https://www.cncf.io/case-studies/cybozu/),
[ESnet](https://www.cncf.io/case-studies/esnet/),[
Nutanix](https://www.cncf.io/case-studies/nutanix/),
[OVHcloud](https://corporate.ovhcloud.com/en-gb/newsroom/news/ovhcloud-managed-kubernetes-service-standard-3az/),
[TikTok](https://www.youtube.com/watch?v=y0qlhiKtDGo), [University of
Wisconsin–Madison](https://www.cncf.io/case-studies/university-of-wisconsin-madison/).
- 🇺🇸 **Atlanta Events**: The community gathered at
[CiliumCon](https://www.youtube.com/playlist?list=PLDg_GiBbAx-mOnWuzd_NXoRfuW9HZAxeZ)
and the [Cilium Developer
Summit](https://redirect.github.com/cilium/dev-summits/blob/main/2025-NA/README.md)
in Atlanta.
- 🇳🇱 **Amsterdam Events**: Meet us at the upcoming
[CiliumCon](https://events.linuxfoundation.org/kubecon-cloudnativecon-europe/co-located-events/ciliumcon/)
and [Cilium Developer
Summit](https://redirect.github.com/cilium/dev-summits/tree/main/2026-EU)
in Amsterdam, March 23-27. [Read
more](https://cilium.io/blog/2026/01/23/cilium-at-kubecon-eu-2026/)
about where to find Cilium during the show.
- 🔟 **Cilium is 10**: Read the [2025 Cilium Annual
Report](https://www.cncf.io/wp-content/uploads/2025/12/cilium-annual-report-2025-final.pdf)
to see the latest project milestones, a decade on from its first commit.

To keep up to date with all the latest Cilium releases, join #release 🎉

:birthday::heart::heart::heart::birthday:
This is a very special release for Cilium, as it celebrates **10 years**
since the first commit. We couldn’t be more proud of what this project
has accomplished. All the GitHub issues, pull requests, reviews, stars,
forks, Docker pulls, Helm installs, Kubernetes applies, CI runs, bug
reports, design docs, discussions, meetings, Slack messages, YouTube
streams, eCHO episodes, conference talks, blog posts, demos, and
presentations have made the project the success it is today.
:birthday::heart::heart::heart::birthday:

#### Docker Manifests

##### cilium


`quay.io/cilium/cilium:v1.19.0@&#8203;sha256:be9f8571c2e114b3e12e41f785f2356ade703b2eac936aa878805565f0468c60`

##### clustermesh-apiserver


`quay.io/cilium/clustermesh-apiserver:v1.19.0@&#8203;sha256:0e3b89fdb116eb0f5579fe8ee3fabb1a7c4d97987a1ae927491d9185785d4a49`

##### docker-plugin


`quay.io/cilium/docker-plugin:v1.19.0@&#8203;sha256:35727047384f3d7a2684885003b266bf7a7add8fc66ca564b222f71c16057f50`

##### hubble-relay


`quay.io/cilium/hubble-relay:v1.19.0@&#8203;sha256:7f17e5bb51a9f35bbc8e7a9ad5e347f03ff8003c2e5cc81171e8727a10bf03b4`

##### operator-alibabacloud


`quay.io/cilium/operator-alibabacloud:v1.19.0@&#8203;sha256:5cb3d6981c233616037f3e13b5bc0020d114ad8db1b7360618b224e4c0b02ef0`

##### operator-aws


`quay.io/cilium/operator-aws:v1.19.0@&#8203;sha256:7a236ae256a4fbd3f72d516921131eba5b43f401ba37cdee5cd0e8c26f9263e6`

##### operator-azure


`quay.io/cilium/operator-azure:v1.19.0@&#8203;sha256:6ae7e0d75c74836af3600b775201c89ea7fcc13d6e08fdb0c52927309f31cd2a`

##### operator-generic


`quay.io/cilium/operator-generic:v1.19.0@&#8203;sha256:5b04006015e5800307dc6314676edc4c0bb7ac2fc7848be2b94b43bb030ab648`

##### operator


`quay.io/cilium/operator:v1.19.0@&#8203;sha256:deca84f442752dca0745dd09b13e8004569414839019ad79ac58f9fcaa3b9d65`

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yLjYiLCJ1cGRhdGVkSW5WZXIiOiI0My4zLjQiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbInJlbm92YXRlL2hlbG0iLCJ0eXBlL21pbm9yIl19-->

Co-authored-by: lumiere-bot[bot] <98047013+lumiere-bot[bot]@users.noreply.github.com>
nicolerenee pushed a commit to nicolerenee/infra that referenced this pull request Feb 7, 2026
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [cilium](https://cilium.io/)
([source](https://redirect.github.com/cilium/cilium)) | minor | `1.18.6`
→ `1.19.0` |

---

### Release Notes

<details>
<summary>cilium/cilium (cilium)</summary>

###
[`v1.19.0`](https://redirect.github.com/cilium/cilium/releases/tag/v1.19.0):
1.19.0

[Compare
Source](https://redirect.github.com/cilium/cilium/compare/1.18.6...1.19.0)

🎉 **Release Announcement** 🎉: We are excited to announce the [Cilium
1.19.0](https://redirect.github.com/cilium/cilium/releases/tag/v1.19.0)
release!

A total of **2934 new commits** have been contributed to this release by
a growing community of over **1010 developers** and over **23,600 GitHub
stars**! 🤩

⚠️ You may need to take action during upgrade to Cilium v1.19 if you use
Network Policies, Cluster Mesh, LoadBalancer IPAM or BGP. See the
[Upgrade
Guide](https://docs.cilium.io/en/v1.19/operations/upgrade/#upgrade-notes)
for more details.

The full changelog can be found
[here](https://redirect.github.com/cilium/cilium/blob/v1.19/CHANGELOG.md).

Here are some of the highlights:

- 🛡️ **Network Policy**
- 🃏 **Multi-Level DNS Matches**: DNS Policies match pattern now support
a wildcard prefix(*`**.`*) to match multilevel subdomain as pattern
prefix.
([cilium/cilium#43420](https://redirect.github.com/cilium/cilium/pull/43420),
[@&#8203;fristonio](https://redirect.github.com/fristonio))
- 📡 **Match New Protocols**: You can now match VRRP and IGMP protocols
in host firewall rules.
([cilium/cilium#39872](https://redirect.github.com/cilium/cilium/pull/39872),
[@&#8203;aditighag](https://redirect.github.com/aditighag);
[cilium/cilium#41949](https://redirect.github.com/cilium/cilium/pull/41949),
[@&#8203;kyounghunJang](https://redirect.github.com/kyounghunJang))
- ⛔ **Actively Deny Connections**: When Network Policies deny a
connection, Cilium can return ICMPv4 "Destination unreachable" messages
for a friendlier deny.
([cilium/cilium#41406](https://redirect.github.com/cilium/cilium/pull/41406),
[@&#8203;antonipp](https://redirect.github.com/antonipp))
- 🌐 **Select Clusters Explicitly**: When network policy selectors don't
explicitly define a cluster for communication to be allowed, they will
now default to only allowing the local cluster.
([cilium/cilium#40609](https://redirect.github.com/cilium/cilium/pull/40609),
[@&#8203;MrFreezeex](https://redirect.github.com/MrFreezeex))
- 🔧 **Unlock Future Work**: This release brings several internal
improvements to the network policy engine in preparation for features
planned in the next Cilium minor release
([cilium/cilium#39906](https://redirect.github.com/cilium/cilium/pull/39906),
[@&#8203;vipul-21](https://redirect.github.com/vipul-21);
[cilium/cilium#42784](https://redirect.github.com/cilium/cilium/pull/42784),
[cilium/cilium#42896](https://redirect.github.com/cilium/cilium/pull/42896),
[@&#8203;jrajahalme](https://redirect.github.com/jrajahalme))
- ⚠️ **Deprecate underutilized features**: To focus on solving common
problems Cilium users face, this release deprecates the Kafka protocol
match fields (beta), as well as the `ToRequires` and `FromRequires`
policy fields.
([cilium/cilium#43167](https://redirect.github.com/cilium/cilium/pull/43167),
[@&#8203;sayboras](https://redirect.github.com/sayboras);
[cilium/cilium#40967](https://redirect.github.com/cilium/cilium/pull/40967),
[@&#8203;TheBeeZee](https://redirect.github.com/TheBeeZee))

- 🔒 **Encryption & Authentication**
- 🔐 **Encryption Strict Modes**: Both IPsec and WireGuard transparent
encryption modes now support a "strict mode" to require traffic to be
encrypted between nodes. Unencrypted traffic will be dropped in this
mode.
([cilium/cilium#39239](https://redirect.github.com/cilium/cilium/pull/39239),
[cilium/cilium#42115](https://redirect.github.com/cilium/cilium/pull/42115),
[@&#8203;rgo3](https://redirect.github.com/rgo3),
[@&#8203;julianwiedmann](https://redirect.github.com/julianwiedmann))
- 🚇 **Ztunnel Beta**: You can enroll namespaces into Ztunnel, which
enables TCP connections between workloads to be transparently encrypted
and authenticated.
([cilium/cilium#42766](https://redirect.github.com/cilium/cilium/pull/42766),
[cilium/cilium#42819](https://redirect.github.com/cilium/cilium/pull/42819),
[cilium/cilium#43227](https://redirect.github.com/cilium/cilium/pull/43227)
and others, [@&#8203;ldelossa](https://redirect.github.com/ldelossa),
[@&#8203;rgo3](https://redirect.github.com/rgo3),
[@&#8203;nddq](https://redirect.github.com/nddq))
- 👥 **Mutual Authentication**: The out-of-band [Mutual
Authentication](https://docs.cilium.io/en/v1.19/network/servicemesh/mutual-authentication/mutual-authentication/)
feature is now disabled by default, pending community feedback. If you
have a requirement for mTLS, consider trying the new Ztunnel
integration.
([cilium/cilium#42665](https://redirect.github.com/cilium/cilium/pull/42665),
[@&#8203;christarazi](https://redirect.github.com/christarazi))
- ↪️ **Accelerate IPsec**: The IPsec encryption mode now supports BPF
Host Routing for faster route lookups
([cilium/cilium#41997](https://redirect.github.com/cilium/cilium/pull/41997),
[@&#8203;pchaigno](https://redirect.github.com/pchaigno))

- 🚠 **Networking**
- 🚀 **BIG TCP in Tunnels**: Leverage upcoming Linux support for BIG TCP
when communicating over UDP-based tunnels such as VXLAN and Geneve.
([cilium/cilium#43416](https://redirect.github.com/cilium/cilium/pull/43416),
[@&#8203;gentoo-root](https://redirect.github.com/gentoo-root))
- 🥌 **Packetization-Layer Path MTU Discovery**: Detect maximum
transmission unit (MTU) sizes for network paths using TCP.
([cilium/cilium#42012](https://redirect.github.com/cilium/cilium/pull/42012),
[cilium/cilium#43710](https://redirect.github.com/cilium/cilium/pull/43710),
[@&#8203;tommyp1ckles](https://redirect.github.com/tommyp1ckles))
- 🚆 **IPv6 Underlay**: You can now choose IPv6 for the tunnel underlay
address family on dual-stack clusters.
([cilium/cilium#40324](https://redirect.github.com/cilium/cilium/pull/40324),
[@&#8203;pchaigno](https://redirect.github.com/pchaigno))
- 🏷️ **Multi-Pool IPAM is ready for wider use**: Update the Multi-Pool
IPAM feature to work with IPsec and direct routing modes, and promote it
from Beta to Stable.
([cilium/cilium#40460](https://redirect.github.com/cilium/cilium/pull/40460),
[cilium/cilium#42191](https://redirect.github.com/cilium/cilium/pull/42191),
[@&#8203;pippolo84](https://redirect.github.com/pippolo84))
- 🎭 **More Configurable Masquerade**: IP Masquerade configuration can
now be customized for traffic sent to nodes in other IP subnets, and
addresses in IPAM pools can be excluded from masquerade
([cilium/cilium#37568](https://redirect.github.com/cilium/cilium/pull/37568),
[@&#8203;behzad-mir](https://redirect.github.com/behzad-mir);
[cilium/cilium#43380](https://redirect.github.com/cilium/cilium/pull/43380),
[@&#8203;alimehrabikoshki](https://redirect.github.com/alimehrabikoshki))

- 🕸️ **Services and Service Mesh**
- 📣 **Layer-2 Announcements**: Add support for Neighbor Discovery
Advertisements for IPv6 Layer-2 Announcements.
([cilium/cilium#39648](https://redirect.github.com/cilium/cilium/pull/39648),
[@&#8203;msune](https://redirect.github.com/msune))
- 🔁 **IPv6 Service Loopback**: Pods can now connect to themselves via a
Kubernetes "loopback service" using IPv6.
([cilium/cilium#39594](https://redirect.github.com/cilium/cilium/pull/39594),
[@&#8203;saiaunghlyanhtet](https://redirect.github.com/saiaunghlyanhtet))
- ⛩️ **Gateway API Enhancements**: Cilium's GAMMA support now includes
support for using GRPCRoute as well as HTTPRoute.
([cilium/cilium#41936](https://redirect.github.com/cilium/cilium/pull/41936),
[@&#8203;youngnick](https://redirect.github.com/youngnick))

- 🛣️ **Border Gateway Protocol (BGP)**
- 🔌 **Advertise Addresses from Interfaces**: There's a new Interface BGP
advertisement type that allows advertisement of IPs assigned on local
interfaces. This can be useful for example in multi-homing setups, where
a common node's loopback address can be advertised via multiple BGP
sessions over different network interfaces.
([cilium/cilium#42469](https://redirect.github.com/cilium/cilium/pull/42469),
[@&#8203;rastislavs](https://redirect.github.com/rastislavs))
- ✉️ **Override Source IP addresses**: You can override the
auto-generated BGP session source IP with the IP address applied on the
configured `sourceInterface` to allow binding the BGP connection to the
loopback address which is not tied to the specific physical interface's
lifecycle
([cilium/cilium#42583](https://redirect.github.com/cilium/cilium/pull/42583),
[@&#8203;rastislavs](https://redirect.github.com/rastislavs))
- 🔁 **Withdraw Empty Routes**: Optionally withdraw BGP routes when a
service has 0 endpoints, to allow balancing to a different DC/cluster
with `externalTrafficPolicy=Cluster`
([cilium/cilium#40717](https://redirect.github.com/cilium/cilium/pull/40717),
[@&#8203;oblazek](https://redirect.github.com/oblazek))
- ⚠️ **Move to `cilium.io/v2` API**: The support for the older
`CiliumBGPPeeringPolicy` v1 API is now removed and should be replaced
with v2 APIs.
([cilium/cilium#42278](https://redirect.github.com/cilium/cilium/pull/42278),
[@&#8203;rastislavs](https://redirect.github.com/rastislavs))

- 🛰️ **Observability**
- 🔬 **Trace IP Options**: Configure Cilium and Hubble to trace specific
packets through the cluster using IP Options.
([cilium/cilium#41306](https://redirect.github.com/cilium/cilium/pull/41306),
[@&#8203;Bigdelle](https://redirect.github.com/Bigdelle))
- 🚩 **Filter Encrypted Flows**: Filter flows when using the `hubble`
command line to understand the encryption status of the traffic, either
`--encrypted` or `--unencrypted`.
([cilium/cilium#43096](https://redirect.github.com/cilium/cilium/pull/43096),
[@&#8203;SRodi](https://redirect.github.com/SRodi))
- 🔖 **Tag Drops with Policy Names**: Hubble v1.Events drop messages now
include which Network Policy caused the drop.
([cilium/cilium#41693](https://redirect.github.com/cilium/cilium/pull/41693),
[@&#8203;41ks](https://redirect.github.com/41ks))

- 🌅 **Performance and Scale**
- ⚡ **Faster Network Policy Computation**: Improve Cilium resource usage
for handling selectors in network policies.
([cilium/cilium#42008](https://redirect.github.com/cilium/cilium/pull/42008),
[@&#8203;jrajahalme](https://redirect.github.com/jrajahalme);
[cilium/cilium#42580](https://redirect.github.com/cilium/cilium/pull/42580),
[@&#8203;odinuge](https://redirect.github.com/odinuge))
- 🔌 **More Efficient Connection Tracking**: Several improvements have
been made to reduce the number of connections being tracked by Cilium,
particularly when using Geneve, VXLAN or WireGuard.
([cilium/cilium#38782](https://redirect.github.com/cilium/cilium/pull/38782),
[@&#8203;BenoitKnecht](https://redirect.github.com/BenoitKnecht);
[cilium/cilium#41990](https://redirect.github.com/cilium/cilium/pull/41990),
[@&#8203;bersoare](https://redirect.github.com/bersoare))
- 💾 **Better Scale in AWS**: Reduce memory usage for cilium-operator in
large AWS environments with many resources.
([cilium/cilium#42529](https://redirect.github.com/cilium/cilium/pull/42529),
[@&#8203;liyihuang](https://redirect.github.com/liyihuang))

- ⚙️ **Operations**
- 📦 **Access Helm charts via Registry**: Helm charts are also available
under `quay.io/cilium/charts/cilium`
([cilium/cilium#43624](https://redirect.github.com/cilium/cilium/pull/43624),
[@&#8203;aanm](https://redirect.github.com/aanm))
- 📊 **Metrics Encryption**: Add TLS/mTLS support for Prometheus metrics
exposed by the Cilium Operator.
([cilium/cilium#42077](https://redirect.github.com/cilium/cilium/pull/42077),
[@&#8203;phuhung273](https://redirect.github.com/phuhung273))
- 🤖 **Easier Multi-Cluster install**: There's now support for
auto-installing the Custom Resource Definitions (CRDs) for Multi-Cluster
Services (MCS).
([cilium/cilium#40729](https://redirect.github.com/cilium/cilium/pull/40729),
[@&#8203;MrFreezeex](https://redirect.github.com/MrFreezeex))
- 📜 **Simpler Certificate Management**: Streamline Cluster Mesh and
Hubble certificate generation when using GitOps approaches.
([cilium/cilium#42298](https://redirect.github.com/cilium/cilium/pull/42298),
[@&#8203;MrFreezeex](https://redirect.github.com/MrFreezeex))
- 🛠️ **Cilium dependencies** were updated to Kubernetes v1.35, Envoy
v1.35, Gateway API v1.4, and GoBGP v3.37.
([cilium/cilium#43422](https://redirect.github.com/cilium/cilium/pull/43422),
[@&#8203;aanm](https://redirect.github.com/aanm);
[cilium/cilium#40569](https://redirect.github.com/cilium/cilium/pull/40569),
[@&#8203;sayboras](https://redirect.github.com/sayboras);
[cilium/cilium#41936](https://redirect.github.com/cilium/cilium/pull/41936),
[@&#8203;youngnick](https://redirect.github.com/youngnick);
[cilium/cilium#42824](https://redirect.github.com/cilium/cilium/pull/42824),
[@&#8203;rastislavs](https://redirect.github.com/rastislavs)).

- 🏠 **Community**
- ❤️ **Production Case Studies**: Many end-users have stepped forward to
tell their stories running Cilium in production. If your company wants
to submit their case studies let us know. We would love to hear your
feedback!
- 📰 See studies with
[Airbnb](https://youtu.be/7KHenRXNGAw?si=ldTS-X_W0svxo429\&t=546),
[Cloudera](https://aws.amazon.com/blogs/migration-and-modernization/scaling-clouderas-development-environment-leveraging-amazon-eks-karpenter-bottlerocket-and-cilium-for-hybrid-cloud/),[
Cybozu](https://www.cncf.io/case-studies/cybozu/),
[ESnet](https://www.cncf.io/case-studies/esnet/),[
Nutanix](https://www.cncf.io/case-studies/nutanix/),
[OVHcloud](https://corporate.ovhcloud.com/en-gb/newsroom/news/ovhcloud-managed-kubernetes-service-standard-3az/),
[TikTok](https://www.youtube.com/watch?v=y0qlhiKtDGo), [University of
Wisconsin–Madison](https://www.cncf.io/case-studies/university-of-wisconsin-madison/).
- 🇺🇸 **Atlanta Events**: The community gathered at
[CiliumCon](https://www.youtube.com/playlist?list=PLDg_GiBbAx-mOnWuzd_NXoRfuW9HZAxeZ)
and the [Cilium Developer
Summit](https://redirect.github.com/cilium/dev-summits/blob/main/2025-NA/README.md)
in Atlanta.
- 🇳🇱 **Amsterdam Events**: Meet us at the upcoming
[CiliumCon](https://events.linuxfoundation.org/kubecon-cloudnativecon-europe/co-located-events/ciliumcon/)
and [Cilium Developer
Summit](https://redirect.github.com/cilium/dev-summits/tree/main/2026-EU)
in Amsterdam, March 23-27. [Read
more](https://cilium.io/blog/2026/01/23/cilium-at-kubecon-eu-2026/)
about where to find Cilium during the show.
- 🔟 **Cilium is 10**: Read the [2025 Cilium Annual
Report](https://www.cncf.io/wp-content/uploads/2025/12/cilium-annual-report-2025-final.pdf)
to see the latest project milestones, a decade on from its first commit.

To keep up to date with all the latest Cilium releases, join #release 🎉

:birthday::heart::heart::heart::birthday:
This is a very special release for Cilium, as it celebrates **10 years**
since the first commit. We couldn’t be more proud of what this project
has accomplished. All the GitHub issues, pull requests, reviews, stars,
forks, Docker pulls, Helm installs, Kubernetes applies, CI runs, bug
reports, design docs, discussions, meetings, Slack messages, YouTube
streams, eCHO episodes, conference talks, blog posts, demos, and
presentations have made the project the success it is today.
:birthday::heart::heart::heart::birthday:

#### Docker Manifests

##### cilium


`quay.io/cilium/cilium:v1.19.0@&#8203;sha256:be9f8571c2e114b3e12e41f785f2356ade703b2eac936aa878805565f0468c60`

##### clustermesh-apiserver


`quay.io/cilium/clustermesh-apiserver:v1.19.0@&#8203;sha256:0e3b89fdb116eb0f5579fe8ee3fabb1a7c4d97987a1ae927491d9185785d4a49`

##### docker-plugin


`quay.io/cilium/docker-plugin:v1.19.0@&#8203;sha256:35727047384f3d7a2684885003b266bf7a7add8fc66ca564b222f71c16057f50`

##### hubble-relay


`quay.io/cilium/hubble-relay:v1.19.0@&#8203;sha256:7f17e5bb51a9f35bbc8e7a9ad5e347f03ff8003c2e5cc81171e8727a10bf03b4`

##### operator-alibabacloud


`quay.io/cilium/operator-alibabacloud:v1.19.0@&#8203;sha256:5cb3d6981c233616037f3e13b5bc0020d114ad8db1b7360618b224e4c0b02ef0`

##### operator-aws


`quay.io/cilium/operator-aws:v1.19.0@&#8203;sha256:7a236ae256a4fbd3f72d516921131eba5b43f401ba37cdee5cd0e8c26f9263e6`

##### operator-azure


`quay.io/cilium/operator-azure:v1.19.0@&#8203;sha256:6ae7e0d75c74836af3600b775201c89ea7fcc13d6e08fdb0c52927309f31cd2a`

##### operator-generic


`quay.io/cilium/operator-generic:v1.19.0@&#8203;sha256:5b04006015e5800307dc6314676edc4c0bb7ac2fc7848be2b94b43bb030ab648`

##### operator


`quay.io/cilium/operator:v1.19.0@&#8203;sha256:deca84f442752dca0745dd09b13e8004569414839019ad79ac58f9fcaa3b9d65`

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yLjYiLCJ1cGRhdGVkSW5WZXIiOiI0My4zLjQiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbInJlbm92YXRlL2hlbG0iLCJ0eXBlL21pbm9yIl19-->

Co-authored-by: bot-nicole[bot] <205127124+bot-nicole[bot]@users.noreply.github.com>
enchantednatures pushed a commit to enchantednatures/HomeCluster that referenced this pull request Feb 9, 2026
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [cilium](https://cilium.io/)
([source](https://redirect.github.com/cilium/cilium)) | minor | `1.18.6`
→ `1.19.0` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>cilium/cilium (cilium)</summary>

###
[`v1.19.0`](https://redirect.github.com/cilium/cilium/releases/tag/v1.19.0):
1.19.0

[Compare
Source](https://redirect.github.com/cilium/cilium/compare/1.18.6...1.19.0)

🎉 **Release Announcement** 🎉: We are excited to announce the [Cilium
1.19.0](https://redirect.github.com/cilium/cilium/releases/tag/v1.19.0)
release!

A total of **2934 new commits** have been contributed to this release by
a growing community of over **1010 developers** and over **23,600 GitHub
stars**! 🤩

⚠️ You may need to take action during upgrade to Cilium v1.19 if you use
Network Policies, Cluster Mesh, LoadBalancer IPAM or BGP. See the
[Upgrade
Guide](https://docs.cilium.io/en/v1.19/operations/upgrade/#upgrade-notes)
for more details.

The full changelog can be found
[here](https://redirect.github.com/cilium/cilium/blob/v1.19/CHANGELOG.md).

Here are some of the highlights:

- 🛡️ **Network Policy**
- 🃏 **Multi-Level DNS Matches**: DNS Policies match pattern now support
a wildcard prefix(*`**.`*) to match multilevel subdomain as pattern
prefix.
([cilium/cilium#43420](https://redirect.github.com/cilium/cilium/pull/43420),
[@&#8203;fristonio](https://redirect.github.com/fristonio))
- 📡 **Match New Protocols**: You can now match VRRP and IGMP protocols
in host firewall rules.
([cilium/cilium#39872](https://redirect.github.com/cilium/cilium/pull/39872),
[@&#8203;aditighag](https://redirect.github.com/aditighag);
[cilium/cilium#41949](https://redirect.github.com/cilium/cilium/pull/41949),
[@&#8203;kyounghunJang](https://redirect.github.com/kyounghunJang))
- ⛔ **Actively Deny Connections**: When Network Policies deny a
connection, Cilium can return ICMPv4 "Destination unreachable" messages
for a friendlier deny.
([cilium/cilium#41406](https://redirect.github.com/cilium/cilium/pull/41406),
[@&#8203;antonipp](https://redirect.github.com/antonipp))
- 🌐 **Select Clusters Explicitly**: When network policy selectors don't
explicitly define a cluster for communication to be allowed, they will
now default to only allowing the local cluster.
([cilium/cilium#40609](https://redirect.github.com/cilium/cilium/pull/40609),
[@&#8203;MrFreezeex](https://redirect.github.com/MrFreezeex))
- 🔧 **Unlock Future Work**: This release brings several internal
improvements to the network policy engine in preparation for features
planned in the next Cilium minor release
([cilium/cilium#39906](https://redirect.github.com/cilium/cilium/pull/39906),
[@&#8203;vipul-21](https://redirect.github.com/vipul-21);
[cilium/cilium#42784](https://redirect.github.com/cilium/cilium/pull/42784),
[cilium/cilium#42896](https://redirect.github.com/cilium/cilium/pull/42896),
[@&#8203;jrajahalme](https://redirect.github.com/jrajahalme))
- ⚠️ **Deprecate underutilized features**: To focus on solving common
problems Cilium users face, this release deprecates the Kafka protocol
match fields (beta), as well as the `ToRequires` and `FromRequires`
policy fields.
([cilium/cilium#43167](https://redirect.github.com/cilium/cilium/pull/43167),
[@&#8203;sayboras](https://redirect.github.com/sayboras);
[cilium/cilium#40967](https://redirect.github.com/cilium/cilium/pull/40967),
[@&#8203;TheBeeZee](https://redirect.github.com/TheBeeZee))

- 🔒 **Encryption & Authentication**
- 🔐 **Encryption Strict Modes**: Both IPsec and WireGuard transparent
encryption modes now support a "strict mode" to require traffic to be
encrypted between nodes. Unencrypted traffic will be dropped in this
mode.
([cilium/cilium#39239](https://redirect.github.com/cilium/cilium/pull/39239),
[cilium/cilium#42115](https://redirect.github.com/cilium/cilium/pull/42115),
[@&#8203;rgo3](https://redirect.github.com/rgo3),
[@&#8203;julianwiedmann](https://redirect.github.com/julianwiedmann))
- 🚇 **Ztunnel Beta**: You can enroll namespaces into Ztunnel, which
enables TCP connections between workloads to be transparently encrypted
and authenticated.
([cilium/cilium#42766](https://redirect.github.com/cilium/cilium/pull/42766),
[cilium/cilium#42819](https://redirect.github.com/cilium/cilium/pull/42819),
[cilium/cilium#43227](https://redirect.github.com/cilium/cilium/pull/43227)
and others, [@&#8203;ldelossa](https://redirect.github.com/ldelossa),
[@&#8203;rgo3](https://redirect.github.com/rgo3),
[@&#8203;nddq](https://redirect.github.com/nddq))
- 👥 **Mutual Authentication**: The out-of-band [Mutual
Authentication](https://docs.cilium.io/en/v1.19/network/servicemesh/mutual-authentication/mutual-authentication/)
feature is now disabled by default, pending community feedback. If you
have a requirement for mTLS, consider trying the new Ztunnel
integration.
([cilium/cilium#42665](https://redirect.github.com/cilium/cilium/pull/42665),
[@&#8203;christarazi](https://redirect.github.com/christarazi))
- ↪️ **Accelerate IPsec**: The IPsec encryption mode now supports BPF
Host Routing for faster route lookups
([cilium/cilium#41997](https://redirect.github.com/cilium/cilium/pull/41997),
[@&#8203;pchaigno](https://redirect.github.com/pchaigno))

- 🚠 **Networking**
- 🚀 **BIG TCP in Tunnels**: Leverage upcoming Linux support for BIG TCP
when communicating over UDP-based tunnels such as VXLAN and Geneve.
([cilium/cilium#43416](https://redirect.github.com/cilium/cilium/pull/43416),
[@&#8203;gentoo-root](https://redirect.github.com/gentoo-root))
- 🥌 **Packetization-Layer Path MTU Discovery**: Detect maximum
transmission unit (MTU) sizes for network paths using TCP.
([cilium/cilium#42012](https://redirect.github.com/cilium/cilium/pull/42012),
[cilium/cilium#43710](https://redirect.github.com/cilium/cilium/pull/43710),
[@&#8203;tommyp1ckles](https://redirect.github.com/tommyp1ckles))
- 🚆 **IPv6 Underlay**: You can now choose IPv6 for the tunnel underlay
address family on dual-stack clusters.
([cilium/cilium#40324](https://redirect.github.com/cilium/cilium/pull/40324),
[@&#8203;pchaigno](https://redirect.github.com/pchaigno))
- 🏷️ **Multi-Pool IPAM is ready for wider use**: Update the Multi-Pool
IPAM feature to work with IPsec and direct routing modes, and promote it
from Beta to Stable.
([cilium/cilium#40460](https://redirect.github.com/cilium/cilium/pull/40460),
[cilium/cilium#42191](https://redirect.github.com/cilium/cilium/pull/42191),
[@&#8203;pippolo84](https://redirect.github.com/pippolo84))
- 🎭 **More Configurable Masquerade**: IP Masquerade configuration can
now be customized for traffic sent to nodes in other IP subnets, and
addresses in IPAM pools can be excluded from masquerade
([cilium/cilium#37568](https://redirect.github.com/cilium/cilium/pull/37568),
[@&#8203;behzad-mir](https://redirect.github.com/behzad-mir);
[cilium/cilium#43380](https://redirect.github.com/cilium/cilium/pull/43380),
[@&#8203;alimehrabikoshki](https://redirect.github.com/alimehrabikoshki))

- 🕸️ **Services and Service Mesh**
- 📣 **Layer-2 Announcements**: Add support for Neighbor Discovery
Advertisements for IPv6 Layer-2 Announcements.
([cilium/cilium#39648](https://redirect.github.com/cilium/cilium/pull/39648),
[@&#8203;msune](https://redirect.github.com/msune))
- 🔁 **IPv6 Service Loopback**: Pods can now connect to themselves via a
Kubernetes "loopback service" using IPv6.
([cilium/cilium#39594](https://redirect.github.com/cilium/cilium/pull/39594),
[@&#8203;saiaunghlyanhtet](https://redirect.github.com/saiaunghlyanhtet))
- ⛩️ **Gateway API Enhancements**: Cilium's GAMMA support now includes
support for using GRPCRoute as well as HTTPRoute.
([cilium/cilium#41936](https://redirect.github.com/cilium/cilium/pull/41936),
[@&#8203;youngnick](https://redirect.github.com/youngnick))

- 🛣️ **Border Gateway Protocol (BGP)**
- 🔌 **Advertise Addresses from Interfaces**: There's a new Interface BGP
advertisement type that allows advertisement of IPs assigned on local
interfaces. This can be useful for example in multi-homing setups, where
a common node's loopback address can be advertised via multiple BGP
sessions over different network interfaces.
([cilium/cilium#42469](https://redirect.github.com/cilium/cilium/pull/42469),
[@&#8203;rastislavs](https://redirect.github.com/rastislavs))
- ✉️ **Override Source IP addresses**: You can override the
auto-generated BGP session source IP with the IP address applied on the
configured `sourceInterface` to allow binding the BGP connection to the
loopback address which is not tied to the specific physical interface's
lifecycle
([cilium/cilium#42583](https://redirect.github.com/cilium/cilium/pull/42583),
[@&#8203;rastislavs](https://redirect.github.com/rastislavs))
- 🔁 **Withdraw Empty Routes**: Optionally withdraw BGP routes when a
service has 0 endpoints, to allow balancing to a different DC/cluster
with `externalTrafficPolicy=Cluster`
([cilium/cilium#40717](https://redirect.github.com/cilium/cilium/pull/40717),
[@&#8203;oblazek](https://redirect.github.com/oblazek))
- ⚠️ **Move to `cilium.io/v2` API**: The support for the older
`CiliumBGPPeeringPolicy` v1 API is now removed and should be replaced
with v2 APIs.
([cilium/cilium#42278](https://redirect.github.com/cilium/cilium/pull/42278),
[@&#8203;rastislavs](https://redirect.github.com/rastislavs))

- 🛰️ **Observability**
- 🔬 **Trace IP Options**: Configure Cilium and Hubble to trace specific
packets through the cluster using IP Options.
([cilium/cilium#41306](https://redirect.github.com/cilium/cilium/pull/41306),
[@&#8203;Bigdelle](https://redirect.github.com/Bigdelle))
- 🚩 **Filter Encrypted Flows**: Filter flows when using the `hubble`
command line to understand the encryption status of the traffic, either
`--encrypted` or `--unencrypted`.
([cilium/cilium#43096](https://redirect.github.com/cilium/cilium/pull/43096),
[@&#8203;SRodi](https://redirect.github.com/SRodi))
- 🔖 **Tag Drops with Policy Names**: Hubble v1.Events drop messages now
include which Network Policy caused the drop.
([cilium/cilium#41693](https://redirect.github.com/cilium/cilium/pull/41693),
[@&#8203;41ks](https://redirect.github.com/41ks))

- 🌅 **Performance and Scale**
- ⚡ **Faster Network Policy Computation**: Improve Cilium resource usage
for handling selectors in network policies.
([cilium/cilium#42008](https://redirect.github.com/cilium/cilium/pull/42008),
[@&#8203;jrajahalme](https://redirect.github.com/jrajahalme);
[cilium/cilium#42580](https://redirect.github.com/cilium/cilium/pull/42580),
[@&#8203;odinuge](https://redirect.github.com/odinuge))
- 🔌 **More Efficient Connection Tracking**: Several improvements have
been made to reduce the number of connections being tracked by Cilium,
particularly when using Geneve, VXLAN or WireGuard.
([cilium/cilium#38782](https://redirect.github.com/cilium/cilium/pull/38782),
[@&#8203;BenoitKnecht](https://redirect.github.com/BenoitKnecht);
[cilium/cilium#41990](https://redirect.github.com/cilium/cilium/pull/41990),
[@&#8203;bersoare](https://redirect.github.com/bersoare))
- 💾 **Better Scale in AWS**: Reduce memory usage for cilium-operator in
large AWS environments with many resources.
([cilium/cilium#42529](https://redirect.github.com/cilium/cilium/pull/42529),
[@&#8203;liyihuang](https://redirect.github.com/liyihuang))

- ⚙️ **Operations**
- 📦 **Access Helm charts via Registry**: Helm charts are also available
under `quay.io/cilium/charts/cilium`
([cilium/cilium#43624](https://redirect.github.com/cilium/cilium/pull/43624),
[@&#8203;aanm](https://redirect.github.com/aanm))
- 📊 **Metrics Encryption**: Add TLS/mTLS support for Prometheus metrics
exposed by the Cilium Operator.
([cilium/cilium#42077](https://redirect.github.com/cilium/cilium/pull/42077),
[@&#8203;phuhung273](https://redirect.github.com/phuhung273))
- 🤖 **Easier Multi-Cluster install**: There's now support for
auto-installing the Custom Resource Definitions (CRDs) for Multi-Cluster
Services (MCS).
([cilium/cilium#40729](https://redirect.github.com/cilium/cilium/pull/40729),
[@&#8203;MrFreezeex](https://redirect.github.com/MrFreezeex))
- 📜 **Simpler Certificate Management**: Streamline Cluster Mesh and
Hubble certificate generation when using GitOps approaches.
([cilium/cilium#42298](https://redirect.github.com/cilium/cilium/pull/42298),
[@&#8203;MrFreezeex](https://redirect.github.com/MrFreezeex))
- 🛠️ **Cilium dependencies** were updated to Kubernetes v1.35, Envoy
v1.35, Gateway API v1.4, and GoBGP v3.37.
([cilium/cilium#43422](https://redirect.github.com/cilium/cilium/pull/43422),
[@&#8203;aanm](https://redirect.github.com/aanm);
[cilium/cilium#40569](https://redirect.github.com/cilium/cilium/pull/40569),
[@&#8203;sayboras](https://redirect.github.com/sayboras);
[cilium/cilium#41936](https://redirect.github.com/cilium/cilium/pull/41936),
[@&#8203;youngnick](https://redirect.github.com/youngnick);
[cilium/cilium#42824](https://redirect.github.com/cilium/cilium/pull/42824),
[@&#8203;rastislavs](https://redirect.github.com/rastislavs)).

- 🏠 **Community**
- ❤️ **Production Case Studies**: Many end-users have stepped forward to
tell their stories running Cilium in production. If your company wants
to submit their case studies let us know. We would love to hear your
feedback!
- 📰 See studies with
[Airbnb](https://youtu.be/7KHenRXNGAw?si=ldTS-X_W0svxo429\&t=546),
[Cloudera](https://aws.amazon.com/blogs/migration-and-modernization/scaling-clouderas-development-environment-leveraging-amazon-eks-karpenter-bottlerocket-and-cilium-for-hybrid-cloud/),[
Cybozu](https://www.cncf.io/case-studies/cybozu/),
[ESnet](https://www.cncf.io/case-studies/esnet/),[
Nutanix](https://www.cncf.io/case-studies/nutanix/),
[OVHcloud](https://corporate.ovhcloud.com/en-gb/newsroom/news/ovhcloud-managed-kubernetes-service-standard-3az/),
[TikTok](https://www.youtube.com/watch?v=y0qlhiKtDGo), [University of
Wisconsin–Madison](https://www.cncf.io/case-studies/university-of-wisconsin-madison/).
- 🇺🇸 **Atlanta Events**: The community gathered at
[CiliumCon](https://www.youtube.com/playlist?list=PLDg_GiBbAx-mOnWuzd_NXoRfuW9HZAxeZ)
and the [Cilium Developer
Summit](https://redirect.github.com/cilium/dev-summits/blob/main/2025-NA/README.md)
in Atlanta.
- 🇳🇱 **Amsterdam Events**: Meet us at the upcoming
[CiliumCon](https://events.linuxfoundation.org/kubecon-cloudnativecon-europe/co-located-events/ciliumcon/)
and [Cilium Developer
Summit](https://redirect.github.com/cilium/dev-summits/tree/main/2026-EU)
in Amsterdam, March 23-27. [Read
more](https://cilium.io/blog/2026/01/23/cilium-at-kubecon-eu-2026/)
about where to find Cilium during the show.
- 🔟 **Cilium is 10**: Read the [2025 Cilium Annual
Report](https://www.cncf.io/wp-content/uploads/2025/12/cilium-annual-report-2025-final.pdf)
to see the latest project milestones, a decade on from its first commit.

To keep up to date with all the latest Cilium releases, join #release 🎉

:birthday::heart::heart::heart::birthday:
This is a very special release for Cilium, as it celebrates **10 years**
since the first commit. We couldn’t be more proud of what this project
has accomplished. All the GitHub issues, pull requests, reviews, stars,
forks, Docker pulls, Helm installs, Kubernetes applies, CI runs, bug
reports, design docs, discussions, meetings, Slack messages, YouTube
streams, eCHO episodes, conference talks, blog posts, demos, and
presentations have made the project the success it is today.
:birthday::heart::heart::heart::birthday:

#### Docker Manifests

##### cilium


`quay.io/cilium/cilium:v1.19.0@&#8203;sha256:be9f8571c2e114b3e12e41f785f2356ade703b2eac936aa878805565f0468c60`

##### clustermesh-apiserver


`quay.io/cilium/clustermesh-apiserver:v1.19.0@&#8203;sha256:0e3b89fdb116eb0f5579fe8ee3fabb1a7c4d97987a1ae927491d9185785d4a49`

##### docker-plugin


`quay.io/cilium/docker-plugin:v1.19.0@&#8203;sha256:35727047384f3d7a2684885003b266bf7a7add8fc66ca564b222f71c16057f50`

##### hubble-relay


`quay.io/cilium/hubble-relay:v1.19.0@&#8203;sha256:7f17e5bb51a9f35bbc8e7a9ad5e347f03ff8003c2e5cc81171e8727a10bf03b4`

##### operator-alibabacloud


`quay.io/cilium/operator-alibabacloud:v1.19.0@&#8203;sha256:5cb3d6981c233616037f3e13b5bc0020d114ad8db1b7360618b224e4c0b02ef0`

##### operator-aws


`quay.io/cilium/operator-aws:v1.19.0@&#8203;sha256:7a236ae256a4fbd3f72d516921131eba5b43f401ba37cdee5cd0e8c26f9263e6`

##### operator-azure


`quay.io/cilium/operator-azure:v1.19.0@&#8203;sha256:6ae7e0d75c74836af3600b775201c89ea7fcc13d6e08fdb0c52927309f31cd2a`

##### operator-generic


`quay.io/cilium/operator-generic:v1.19.0@&#8203;sha256:5b04006015e5800307dc6314676edc4c0bb7ac2fc7848be2b94b43bb030ab648`

##### operator


`quay.io/cilium/operator:v1.19.0@&#8203;sha256:deca84f442752dca0745dd09b13e8004569414839019ad79ac58f9fcaa3b9d65`

</details>

---

### Configuration

📅 **Schedule**: Branch creation - "every weekend" in timezone
America/New_York, Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/enchantednatures/HomeCluster).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45NS4yIiwidXBkYXRlZEluVmVyIjoiNDIuOTUuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsicmVub3ZhdGUvaGVsbSIsInR5cGUvbWlub3IiXX0=-->

---------

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ready-to-merge This PR has passed all tests and received consensus from code owners to merge. release-note/misc This PR makes changes that have no direct user impact. sig/policy Impacts whether traffic is allowed or denied based on user-defined policies.

Projects

No open projects
Status: Released

Development

Successfully merging this pull request may close these issues.

7 participants