Skip to content

[v1.20] bpf: hostfw: tolerate unknown CT protocols and rely on policies - #47621

Merged
pchaigno merged 5 commits into
v1.20from
pr/smagnani96/hostfw-tolerate-ct-v1.20
Aug 4, 2026
Merged

[v1.20] bpf: hostfw: tolerate unknown CT protocols and rely on policies#47621
pchaigno merged 5 commits into
v1.20from
pr/smagnani96/hostfw-tolerate-ct-v1.20

Conversation

@smagnani96

@smagnani96 smagnani96 commented Jul 30, 2026

Copy link
Copy Markdown
Contributor

TODO: fix upstream commit sha for #47648 once merged.

Once this PR is merged, a GitHub action will update the labels of these PRs:

 47343

@smagnani96 smagnani96 self-assigned this Jul 30, 2026
@smagnani96 smagnani96 added kind/backports This PR provides functionality previously merged into master. backport/author The backport will be carried out by the author of the PR. backport/1.20 This PR represents a backport for Cilium 1.20.x of a PR that was merged to main. labels Jul 30, 2026
@smagnani96 smagnani96 changed the title Pr/smagnani96/hostfw tolerate ct v1.20 [v1.20] bpf: hostfw: tolerate unknown CT protocols and rely on policies Jul 30, 2026
@smagnani96
smagnani96 requested a review from pchaigno July 30, 2026 21:17
@cilium cilium deleted a comment from cilium-ariane Bot Jul 31, 2026
@smagnani96

This comment was marked as outdated.

[ upstream commit e4ac654 ]

This commit extends current hostfw_igmp.h tests by spelling out and
verifying the actual cause of drop rather than just checking for a drop.
At the current state, the HostFW path could drop packets either for
policy reasons or for missing CT support for the packet protocol, i.e.
non-TCP/UDP/ICMP packets. The current tests only check for a drop, but
do not verify the actual reason for the drop, so we add it here.
When --enable-extended-ip-protocols is enabled, we expect no drops due to
missing CT support.

Signed-off-by: Simone Magnani <[email protected]>
[ upstream commit c4dcaa7 ]

This commit extends current hostfw_bpf_masq.c and hostfw_host_iptables.c
tests by adding specific drop-default rules on egress and ingress to verify
that the packets are actually allowed to pass as expected. The type of
packets under tests simply need to create a CT entry, but do not actually
go through the policy enforcement of HostFW. Prior to this commit, these
tests were not using any default-drop policy in place, we were missing
this coverage. Now we make sure they go though both CT lookup and policy.

Signed-off-by: Simone Magnani <[email protected]>
[ upstream commit 4321d13 ]

When conntrack sees a packet with an unknown protocol, it will set
the tuple ports to 0 only if the `--enable-extended-ip-protocols` option
is enabled. However, in the upcoming commits, we're changing the
HostFW behavior to tolerate unknown protocols and rely on policies to
allow ingress or egress traffic. If the value is not re-initialized,
we might end up with a tuple that has the ports of the previous connection,
which could lead to incorrect behavior when checking policies.

In theory, this cannot happen, as non-ICMP/UDP/TCP protocols policies
are not accepted unless the `--enable-extended-ip-protocols` option is
enabled. The agent would otherwise reject the policy with:

```bash
time=2026-07-28T14:44:29.625771465Z level=warn msg="Unable to add CiliumNetworkPolicy" module=agent.controlplane.policy-k8s-watcher ciliumNetworkPolicyName=repro-host-policy k8sApiVersion="" k8sNamespace="" error="Invalid CiliumClusterwideNetworkPolicy spec: port must be specified"
```

The tuple would still match the default policy for the hook, which is
not looking at the proto/ports. Let's clarify the behavior here anyway,
making sure we're not leaving potential dirty values in case we change
the behavior in the future.

At this point, the CONFIG(enable_extended_ip_protocols) value serves to
discriminate whether we want the conntrack map to accept non-ICMP/UDP/TCP
protocols or not, which is needed in case one of the ingress or egress
default policy differs from the other and these protocols expects request/reply.

Signed-off-by: Simone Magnani <[email protected]>
[ upstream commit 0a74d74 ]

Prior to this commit, the HostFW egress codepath was dropping packets
either (a) due to an unknown CT protocol leading to a CT lookup failure,
or (b) due to a CT lookup success but policies in place.

While the latter is expected, the former is a bit controversial, as it
leads to dropping packets that could've been allowed by egress policies,
such as a default allow-all policy. The missing conntrack support for
other L4 protocols should not prevent us from evaluating egress policies.
We definitively cannot conntrack the packet, so in that case ingress
policies would not be skipped either for the reply traffic, but at the
same time we should honour the policies in place.

The missing conntrack support for other L4 protocols was added in v1.19
behind the `--enable-extended-ip-protocols` agent flag, to allow conntrack
protocols such as IGMP or VRRP. In the same patch, we added support to
extend HostFW policies to these protocols that do not have a L4 port.
While being more granular, I believe even w/o the agent flag set we should
stick to the policy evaluation.

Signed-off-by: Simone Magnani <[email protected]>
[ upstream commit b600321 ]

Same as previous commit, but for ingress path.
In case the egress path CT lookup fails, we do not create a CT entry
for reply traffic, and thus we run ingress policies. It is up to the
policies now to decide whether to allow or drop the reply traffic, as we
tolerate CT lookup failures for unknown protocols.

Signed-off-by: Simone Magnani <[email protected]>
@pchaigno
pchaigno force-pushed the pr/smagnani96/hostfw-tolerate-ct-v1.20 branch from 9c068cd to 3366c9e Compare August 4, 2026 05:42
@cilium-ariane

cilium-ariane Bot commented Aug 4, 2026

Copy link
Copy Markdown

/test

@pchaigno
pchaigno marked this pull request as ready for review August 4, 2026 06:12
@pchaigno
pchaigno requested a review from a team as a code owner August 4, 2026 06:12
@pchaigno
pchaigno enabled auto-merge August 4, 2026 06:12
@pchaigno pchaigno closed this Aug 4, 2026
auto-merge was automatically disabled August 4, 2026 07:14

Pull request was closed

@pchaigno pchaigno reopened this Aug 4, 2026
@pchaigno
pchaigno enabled auto-merge August 4, 2026 07:15
@cilium-ariane

cilium-ariane Bot commented Aug 4, 2026

Copy link
Copy Markdown

/test

@pchaigno
pchaigno added this pull request to the merge queue Aug 4, 2026
Merged via the queue into v1.20 with commit 704610b Aug 4, 2026
934 of 952 checks passed
@pchaigno
pchaigno deleted the pr/smagnani96/hostfw-tolerate-ct-v1.20 branch August 4, 2026 15:34
@maintainer-s-little-helper maintainer-s-little-helper Bot added ready-to-merge This PR has passed all tests and received consensus from code owners to merge. labels Aug 4, 2026
gabrielcosi pushed a commit to gabrielcosi/home-ops that referenced this pull request Aug 18, 2026
….20.1) (#430)

This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [quay.io/cilium/charts/cilium](https://cilium.io/) ([source](https://github.com/cilium/cilium)) | patch | `1.20.0` → `1.20.1` |

---

### Release Notes

<details>
<summary>cilium/cilium (quay.io/cilium/charts/cilium)</summary>

### [`v1.20.1`](https://github.com/cilium/cilium/releases/tag/v1.20.1): 1.20.1

[Compare Source](cilium/cilium@1.20.0...1.20.1)

## Summary of Changes

**Major Changes:**

- docs/clustermesh: overhaul Cluster Mesh documentation with a new introduction, improved load-balancing guidance, and Helm-first setup and certificate configuration instructions (Backport PR [#&#8203;47615](cilium/cilium#47615), Upstream PR [#&#8203;47351](cilium/cilium#47351), [@&#8203;MrFreezeex](https://github.com/MrFreezeex))

**Minor Changes:**

- envoy: demote stale ADS endpoint warning (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47148](cilium/cilium#47148), [@&#8203;nezdolik](https://github.com/nezdolik))
- Speed up recovery time for disrupted TCP connections that access a DSR-enabled Service. (Backport PR [#&#8203;47881](cilium/cilium#47881), Upstream PR [#&#8203;47529](cilium/cilium#47529), [@&#8203;julianwiedmann](https://github.com/julianwiedmann))

**Bugfixes:**

- azure: Stop issuing redundant CiliumNode status updates on every IPAM sync when the node's Azure interfaces are unchanged. (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47449](cilium/cilium#47449), [@&#8203;jaredledvina](https://github.com/jaredledvina))
- bpf: dsr: don't look for TCP header on fragmented packets (Backport PR [#&#8203;47881](cilium/cilium#47881), Upstream PR [#&#8203;47640](cilium/cilium#47640), [@&#8203;julianwiedmann](https://github.com/julianwiedmann))
- bpf: hostfw: tolerate unknown CT protocols and rely on policies (Backport PR [#&#8203;47621](cilium/cilium#47621), Upstream PR [#&#8203;47343](cilium/cilium#47343), [@&#8203;smagnani96](https://github.com/smagnani96))
- clustermesh: fix MCS-API CRD install/upgrade when clustermesh-apiserver is started before the CRD version is actually installed (Backport PR [#&#8203;47885](cilium/cilium#47885), Upstream PR [#&#8203;47824](cilium/cilium#47824), [@&#8203;MrFreezeex](https://github.com/MrFreezeex))
- datapath: turn ARP off on the base devices before bringing them up (Backport PR [#&#8203;47885](cilium/cilium#47885), Upstream PR [#&#8203;47838](cilium/cilium#47838), [@&#8203;aanm](https://github.com/aanm))
- endpoint/watchdog: Avoid warning about endpoints being deleted (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47625](cilium/cilium#47625), [@&#8203;christarazi](https://github.com/christarazi))
- endpoint: Fix silent CIDR policy bypass and traffic drops after agent restart (Backport PR [#&#8203;47954](cilium/cilium#47954), Upstream PR [#&#8203;47880](cilium/cilium#47880), [@&#8203;weizhoublue](https://github.com/weizhoublue))
- envoy.httpUpstreamLingerTimeout accepts `0` as a chart value and templates into configmap. (Backport PR [#&#8203;47885](cilium/cilium#47885), Upstream PR [#&#8203;47741](cilium/cilium#47741), [@&#8203;jdw6359](https://github.com/jdw6359))
- envoy: restore http-idle-timeout as the route idle timeout source (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47583](cilium/cilium#47583), [@&#8203;aanm](https://github.com/aanm))
- Fix a BPF verifier reject on pre-v5.12 kernels, when IPv6 is enabled. (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47765](cilium/cilium#47765), [@&#8203;julianwiedmann](https://github.com/julianwiedmann))
- Fix a deadlock in the shutdown of Cilium operator related to CiliumEndpointSlices. (Backport PR [#&#8203;47967](cilium/cilium#47967), Upstream PR [#&#8203;47802](cilium/cilium#47802), [@&#8203;bimmlerd](https://github.com/bimmlerd))
- Fix a NetworkPolicy update being ignored for up to two minutes when it arrived while an endpoint was waiting for its security identity to be resolved after a pod relabel. (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47727](cilium/cilium#47727), [@&#8203;aanm](https://github.com/aanm))
- Fix a spurious "unable to find ifindex for interface MAC" agent warning on EKS ENI IPAM by waiting for the ENI netlink interface before configuring ingress routes and rules. (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47295](cilium/cilium#47295), [@&#8203;aanm](https://github.com/aanm))
- Fix abnormal ip allocation caused by hostnetwork pod (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47552](cilium/cilium#47552), [@&#8203;haozhangami](https://github.com/haozhangami))
- Fix unintended RevDNAT for client-to-pod TCP connections, when an identical connection was previously established through a DSR Service. (Backport PR [#&#8203;47881](cilium/cilium#47881), Upstream PR [#&#8203;47593](cilium/cilium#47593), [@&#8203;julianwiedmann](https://github.com/julianwiedmann))
- fix: allow setting endpointPolicyUpdateTimeoutDuration in helm (Backport PR [#&#8203;47885](cilium/cilium#47885), Upstream PR [#&#8203;47754](cilium/cilium#47754), [@&#8203;weizhoublue](https://github.com/weizhoublue))
- Fixed an issue where an HTTPRoute referencing a Gateway with mixed listener protocols (e.g. HTTP and TCP) was incorrectly rejected with `NotAllowedByListeners` when the TCP listener had an explicit `AllowedRoutes.Kinds` restriction. (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;46842](cilium/cilium#46842), [@&#8203;pidreher](https://github.com/pidreher))
- gateway-api/gamma: refresh CEC owner refs on route recreation (Backport PR [#&#8203;47954](cilium/cilium#47954), Upstream PR [#&#8203;47840](cilium/cilium#47840), [@&#8203;mhofstetter](https://github.com/mhofstetter))
- gateway-api: mark unresolved backend service ports in route status (Backport PR [#&#8203;47885](cilium/cilium#47885), Upstream PR [#&#8203;47766](cilium/cilium#47766), [@&#8203;mhofstetter](https://github.com/mhofstetter))
- gateway-api: preserve duplicate HTTPRoute rule precedence (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;46696](cilium/cilium#46696), [@&#8203;thorn3r](https://github.com/thorn3r))
- gateway-api: prevent conflicted listeners from reaching ingestion (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47457](cilium/cilium#47457), [@&#8203;asauber](https://github.com/asauber))
- gateway-api: requeue L4/TLS routes on ServiceImport updates (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47702](cilium/cilium#47702), [@&#8203;mhofstetter](https://github.com/mhofstetter))
- gateway-api: sync ListenerSet TLS secrets on ListenerSet events (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47627](cilium/cilium#47627), [@&#8203;mhofstetter](https://github.com/mhofstetter))
- ipcache: fix CIDR reference counter to use canonical prefixes (Backport PR [#&#8203;47885](cilium/cilium#47885), Upstream PR [#&#8203;47208](cilium/cilium#47208), [@&#8203;iwanhae](https://github.com/iwanhae))
- l2announcer: re-evaluate services on frontend changes (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47579](cilium/cilium#47579), [@&#8203;mhofstetter](https://github.com/mhofstetter))
- Log the correct route kind when the Gateway API operator fails to list TLSRoutes for a backend Service (Backport PR [#&#8203;47954](cilium/cilium#47954), Upstream PR [#&#8203;47826](cilium/cilium#47826), [@&#8203;mehrdadbn9](https://github.com/mehrdadbn9))
- operator: Emit startup logs in the configured log format (Backport PR [#&#8203;47954](cilium/cilium#47954), Upstream PR [#&#8203;47890](cilium/cilium#47890), [@&#8203;HadrienPatte](https://github.com/HadrienPatte))
- Resolve a endpoint manager crash for restored endpoints with verbose policy logging enabled. (Backport PR [#&#8203;47885](cilium/cilium#47885), Upstream PR [#&#8203;47844](cilium/cilium#47844), [@&#8203;bimmlerd](https://github.com/bimmlerd))
- standalone-dns-proxy: return an error when no endpoint is found (Backport PR [#&#8203;47954](cilium/cilium#47954), Upstream PR [#&#8203;47791](cilium/cilium#47791), [@&#8203;vipul-21](https://github.com/vipul-21))
- wireguard: Unsubscribe node handler on shutdown (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47614](cilium/cilium#47614), [@&#8203;HadrienPatte](https://github.com/HadrienPatte))

**CI Changes:**

- .github: add python3-scapy for BPF unit tests (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47535](cilium/cilium#47535), [@&#8203;msune](https://github.com/msune))
- .github: run all quarantined EKS tests in a single tolerated step (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47534](cilium/cilium#47534), [@&#8203;aanm](https://github.com/aanm))
- .github: Run envoy image check against PR content (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47792](cilium/cilium#47792), [@&#8203;joestringer](https://github.com/joestringer))
- .github: Simplify permissions for image linter workflow (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47753](cilium/cilium#47753), [@&#8203;joestringer](https://github.com/joestringer))
- .github: suppress spurious encryption leak reports for node-to-pod DNS requests going through proxy (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47470](cilium/cilium#47470), [@&#8203;atykhyy](https://github.com/atykhyy))
- .github: test the default ENI behaviour on the EKS pull request leg (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47569](cilium/cilium#47569), [@&#8203;aanm](https://github.com/aanm))
- ariane: move kind-proxy-embedded and kubespray workflows to /test (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47743](cilium/cilium#47743), [@&#8203;giorio94](https://github.com/giorio94))
- bpf/complexity-tests: Cover L7 LB (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47060](cilium/cilium#47060), [@&#8203;pchaigno](https://github.com/pchaigno))
- ci: build race images on push events so conformance-race works on stable branches (Backport PR [#&#8203;47609](cilium/cilium#47609), Upstream PR [#&#8203;47608](cilium/cilium#47608), [@&#8203;aanm](https://github.com/aanm))
- ci: build race images on push in the stable image builders (Backport PR [#&#8203;47609](cilium/cilium#47609), Upstream PR [#&#8203;47616](cilium/cilium#47616), [@&#8203;aanm](https://github.com/aanm))
- ci: draft renovate PRs until ciliumbot auto-approval (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47364](cilium/cilium#47364), [@&#8203;mhofstetter](https://github.com/mhofstetter))
- ci: fix filtering out md files in bpf checks (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47605](cilium/cilium#47605), [@&#8203;nebril](https://github.com/nebril))
- ci: migrate set-commit-status to cilium/actions (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47771](cilium/cilium#47771), [@&#8203;bogdankrasko](https://github.com/bogdankrasko))
- ci: skip etcd log fetch when kvstore was never started (Backport PR [#&#8203;47885](cilium/cilium#47885), Upstream PR [#&#8203;47801](cilium/cilium#47801), [@&#8203;aanm](https://github.com/aanm))
- Fix missing `events_map_rate_limit` complexity coverage (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47691](cilium/cilium#47691), [@&#8203;pchaigno](https://github.com/pchaigno))
- gha/kubespray: run on schedule, rather than on every push (Backport PR [#&#8203;47731](cilium/cilium#47731), Upstream PR [#&#8203;47719](cilium/cilium#47719), [@&#8203;giorio94](https://github.com/giorio94))
- gha/lvh-kind: respect Kind image version also when config is provided (Backport PR [#&#8203;47731](cilium/cilium#47731), Upstream PR [#&#8203;47703](cilium/cilium#47703), [@&#8203;giorio94](https://github.com/giorio94))
- gha: don't install LLVM and Clang in integration tests workflow (Backport PR [#&#8203;47731](cilium/cilium#47731), Upstream PR [#&#8203;47717](cilium/cilium#47717), [@&#8203;giorio94](https://github.com/giorio94))
- gha: fix checkout of trusted branch in smoke and k8s-kind workflows (Backport PR [#&#8203;47731](cilium/cilium#47731), Upstream PR [#&#8203;47724](cilium/cilium#47724), [@&#8203;giorio94](https://github.com/giorio94))
- images/scripts: Validate Envoy image vars against sed injection (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47205](cilium/cilium#47205), [@&#8203;MasloMaslane](https://github.com/MasloMaslane))
- Revert "gha: don't install LLVM and Clang in integration tests workflow" (Backport PR [#&#8203;47885](cilium/cilium#47885), Upstream PR [#&#8203;47780](cilium/cilium#47780), [@&#8203;giorio94](https://github.com/giorio94))
- test(bpf): parallelize eBPF test compilation (Backport PR [#&#8203;47954](cilium/cilium#47954), Upstream PR [#&#8203;47426](cilium/cilium#47426), [@&#8203;lconnery](https://github.com/lconnery))
- test/cyclonus: log the JUnit XML instead of copying it from a dead pod (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47725](cilium/cilium#47725), [@&#8203;aanm](https://github.com/aanm))
- test: allowlist the leader election read timeout in ginkgo log check (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47612](cilium/cilium#47612), [@&#8203;aanm](https://github.com/aanm))

**Misc Changes:**

- Added documentation for running Cilium in CNI chaining mode on Oracle Kubernetes Engine (OKE) with VCN-Native Pod Networking. (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;46116](cilium/cilium#46116), [@&#8203;amaanx86](https://github.com/amaanx86))
- allocator: fix flake in TestWatchRemoteKVStore (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47455](cilium/cilium#47455), [@&#8203;giorio94](https://github.com/giorio94))
- bpf/nat: Move IPv6 nat entry to map (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47762](cilium/cilium#47762), [@&#8203;pchaigno](https://github.com/pchaigno))
- bpf: conntrack: Reduce stack usage of `ct_create{4,6}` (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47582](cilium/cilium#47582), [@&#8203;dylandreimerink](https://github.com/dylandreimerink))
- bpf: dsr: only require DSR-info on SYN packet (Backport PR [#&#8203;47881](cilium/cilium#47881), Upstream PR [#&#8203;47592](cilium/cilium#47592), [@&#8203;julianwiedmann](https://github.com/julianwiedmann))
- bpf: dsr: re-use TCP SYN flag from CT lookup in remote-backend path (Backport PR [#&#8203;47881](cilium/cilium#47881), Upstream PR [#&#8203;47388](cilium/cilium#47388), [@&#8203;julianwiedmann](https://github.com/julianwiedmann))
- bpf: lb: use dedicated new\_backend bool (Backport PR [#&#8203;47881](cilium/cilium#47881), Upstream PR [#&#8203;47841](cilium/cilium#47841), [@&#8203;julianwiedmann](https://github.com/julianwiedmann))
- chore(deps): update all github action dependencies (v1.20) ([#&#8203;47991](cilium/cilium#47991), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- chore(deps): update all github action dependencies (v1.20) ([#&#8203;48008](cilium/cilium#48008), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- chore(deps): update all-dependencies (v1.20) ([#&#8203;47678](cilium/cilium#47678), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- chore(deps): update dependency cilium/cilium-cli to v0.19.7 (v1.20) ([#&#8203;47576](cilium/cilium#47576), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- chore(deps): update dependency protocolbuffers/protobuf-go to v1.36.12 (v1.20) ([#&#8203;47988](cilium/cilium#47988), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- chore(deps): update docker.io/library/golang:1.26.5 docker digest to [`705e964`](cilium/cilium@705e964) (v1.20) ([#&#8203;47949](cilium/cilium#47949), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- chore(deps): update docker.io/library/golang:1.26.5 docker digest to [`7caba52`](cilium/cilium@7caba52) (v1.20) ([#&#8203;47864](cilium/cilium#47864), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- chore(deps): update quay.io/cilium/cilium-envoy docker tag to v1.37.5-1786449955-8e46c97d1cecc0ba6af6c0c7018a8f18ec93e70d (v1.20) ([#&#8203;47899](cilium/cilium#47899), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- chore(deps): update quay.io/cilium/cilium-envoy docker tag to v1.37.5-1786810558-766ccfb37260a43e9d228837aa84ce3faf9f64e7 (v1.20) ([#&#8203;47989](cilium/cilium#47989), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- chore(deps): update stable lvh-images (v1.20) (patch) ([#&#8203;47865](cilium/cilium#47865), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- chore(deps): update stable lvh-images (v1.20) (patch) ([#&#8203;47990](cilium/cilium#47990), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- clustermesh/endpointslices: explicitly limit maximum decoder memory (Backport PR [#&#8203;47962](cilium/cilium#47962), Upstream PR [#&#8203;47932](cilium/cilium#47932), [@&#8203;giorio94](https://github.com/giorio94))
- docs: clarify GAMMA DROP\_EP\_NOT\_READY events (Backport PR [#&#8203;47885](cilium/cilium#47885), Upstream PR [#&#8203;47587](cilium/cilium#47587), [@&#8203;thorn3r](https://github.com/thorn3r))
- docs: Fix a bug that caused all versions to be treated as pre-release and rendering previous releases in the upgrade guide. (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47600](cilium/cilium#47600), [@&#8203;41ks](https://github.com/41ks))
- docs: Remove "not stable" installation instructions (Backport PR [#&#8203;47798](cilium/cilium#47798), Upstream PR [#&#8203;47646](cilium/cilium#47646), [@&#8203;joestringer](https://github.com/joestringer))
- docs: update Gateway API conformance badge (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47581](cilium/cilium#47581), [@&#8203;arybolovlev](https://github.com/arybolovlev))
- docs: Update Gateway API installation guide (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47446](cilium/cilium#47446), [@&#8203;arybolovlev](https://github.com/arybolovlev))
- Gateway API: the Gateway address status no longer reports a bogus "<nil>" address when a Node's first status address is not an IP literal (e.g. a Hostname entry). (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47466](cilium/cilium#47466), [@&#8203;locker95](https://github.com/locker95))
- gateway-api: remove unnecessary TLSRoute support checks (Backport PR [#&#8203;47885](cilium/cilium#47885), Upstream PR [#&#8203;47758](cilium/cilium#47758), [@&#8203;mhofstetter](https://github.com/mhofstetter))
- gateway-api: report invalid HTTPRoute header modifiers in status (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47599](cilium/cilium#47599), [@&#8203;mhofstetter](https://github.com/mhofstetter))
- gateway-api: return route check errors directly (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47607](cilium/cilium#47607), [@&#8203;mhofstetter](https://github.com/mhofstetter))
- gateway-api: unify Gateway API listener parentRef matching (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;46670](cilium/cilium#46670), [@&#8203;arybolovlev](https://github.com/arybolovlev))
- gateway-api: validate gRPCRoute header modifiers in status (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47606](cilium/cilium#47606), [@&#8203;mhofstetter](https://github.com/mhofstetter))
- operator: Replace `reflect.DeepEqual` with `assert.Equal` in tests (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47424](cilium/cilium#47424), [@&#8203;HadrienPatte](https://github.com/HadrienPatte))
- Update all github action dependencies (v1.20) ([#&#8203;47656](cilium/cilium#47656), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- Update all github action dependencies (v1.20) ([#&#8203;47675](cilium/cilium#47675), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- Update docker.io/library/busybox:1.38.0 Docker digest to [`dc2d74b`](cilium/cilium@dc2d74b) (v1.20) ([#&#8203;47655](cilium/cilium#47655), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- Update documentation dependencies (Backport PR [#&#8203;47798](cilium/cilium#47798), Upstream PR [#&#8203;47750](cilium/cilium#47750), [@&#8203;joestringer](https://github.com/joestringer))
- Update quay.io/cilium/certgen Docker tag to v0.4.9 (v1.20) ([#&#8203;47657](cilium/cilium#47657), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- Update quay.io/cilium/image-tester Docker tag to v1785158849 (v1.20) ([#&#8203;47659](cilium/cilium#47659), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- Update quay.io/lvh-images/kind Docker tag to v6.18-20260720.023802 (v1.20) ([#&#8203;47658](cilium/cilium#47658), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])

**Other Changes:**

- install: Update image digests for v1.20.0 ([#&#8203;47584](cilium/cilium#47584), [@&#8203;cilium-release-bot](https://github.com/cilium-release-bot)\[bot])

#### Docker Manifests

##### cilium

`quay.io/cilium/cilium:v1.20.1@sha256:ae9ea21f7427fe24bc6ea7247eb552157a1b0a431744045d3f641545ca71d11b`
`quay.io/cilium/cilium:stable@sha256:ae9ea21f7427fe24bc6ea7247eb552157a1b0a431744045d3f641545ca71d11b`

##### clustermesh-apiserver

`quay.io/cilium/clustermesh-apiserver:v1.20.1@sha256:d905d614a332b2058cb81c193e481d1f460902b903f4eb57cc9764640b750fb5`
`quay.io/cilium/clustermesh-apiserver:stable@sha256:d905d614a332b2058cb81c193e481d1f460902b903f4eb57cc9764640b750fb5`

##### hubble-relay

`quay.io/cilium/hubble-relay:v1.20.1@sha256:59be0ae7d475ab9011a5e954618c0f27b5778b17140381425b308b55ba4917f4`
`quay.io/cilium/hubble-relay:stable@sha256:59be0ae7d475ab9011a5e954618c0f27b5778b17140381425b308b55ba4917f4`

##### operator-alibabacloud

`quay.io/cilium/operator-alibabacloud:v1.20.1@sha256:2af5dd3d85649ea36d365363b8eca82ad06116c6259c4aace700a7c036348e4c`
`quay.io/cilium/operator-alibabacloud:stable@sha256:2af5dd3d85649ea36d365363b8eca82ad06116c6259c4aace700a7c036348e4c`

##### operator-aws

`quay.io/cilium/operator-aws:v1.20.1@sha256:7cf0cb0e6584f72ca8de951a1be03829f69fcaeba69dc6c7856fc4470545acd7`
`quay.io/cilium/operator-aws:stable@sha256:7cf0cb0e6584f72ca8de951a1be03829f69fcaeba69dc6c7856fc4470545acd7`

##### operator-azure

`quay.io/cilium/operator-azure:v1.20.1@sha256:13746a479ca60395df8d83580b49464c6c975cca6fdb21ba4791a076ab01b031`
`quay.io/cilium/operator-azure:stable@sha256:13746a479ca60395df8d83580b49464c6c975cca6fdb21ba4791a076ab01b031`

##### operator-generic

`quay.io/cilium/operator-generic:v1.20.1@sha256:6c3885fc7b629099fdbe2a5c87869c86feb825fa18fae299eac0f61918d16ecf`
`quay.io/cilium/operator-generic:stable@sha256:6c3885fc7b629099fdbe2a5c87869c86feb825fa18fae299eac0f61918d16ecf`

##### operator

`quay.io/cilium/operator:v1.20.1@sha256:67adaf5575902dcce31dc36ba5b5acad397a8b40ec986b55696c94f80b6d861d`
`quay.io/cilium/operator:stable@sha256:67adaf5575902dcce31dc36ba5b5acad397a8b40ec986b55696c94f80b6d861d`

</details>

---

### Configuration

📅 **Schedule**: (in timezone Europe/Berlin)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zMC4zIiwidXBkYXRlZEluVmVyIjoiNDQuMzAuMyIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9wYXRjaCJdfQ==-->

Reviewed-on: https://git.xcd.dev/gabrielcosi/home-ops/pulls/430
doonga pushed a commit to greyrock-labs/home-ops that referenced this pull request Aug 18, 2026
….20.1) (#349)

This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [quay.io/cilium/charts/cilium](https://cilium.io/) ([source](https://github.com/cilium/cilium)) | patch | `1.20.0` → `1.20.1` |

---

### Release Notes

<details>
<summary>cilium/cilium (quay.io/cilium/charts/cilium)</summary>

### [`v1.20.1`](https://github.com/cilium/cilium/releases/tag/v1.20.1): 1.20.1

[Compare Source](cilium/cilium@1.20.0...1.20.1)

## Summary of Changes

**Major Changes:**

- docs/clustermesh: overhaul Cluster Mesh documentation with a new introduction, improved load-balancing guidance, and Helm-first setup and certificate configuration instructions (Backport PR [#&#8203;47615](cilium/cilium#47615), Upstream PR [#&#8203;47351](cilium/cilium#47351), [@&#8203;MrFreezeex](https://github.com/MrFreezeex))

**Minor Changes:**

- envoy: demote stale ADS endpoint warning (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47148](cilium/cilium#47148), [@&#8203;nezdolik](https://github.com/nezdolik))
- Speed up recovery time for disrupted TCP connections that access a DSR-enabled Service. (Backport PR [#&#8203;47881](cilium/cilium#47881), Upstream PR [#&#8203;47529](cilium/cilium#47529), [@&#8203;julianwiedmann](https://github.com/julianwiedmann))

**Bugfixes:**

- azure: Stop issuing redundant CiliumNode status updates on every IPAM sync when the node's Azure interfaces are unchanged. (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47449](cilium/cilium#47449), [@&#8203;jaredledvina](https://github.com/jaredledvina))
- bpf: dsr: don't look for TCP header on fragmented packets (Backport PR [#&#8203;47881](cilium/cilium#47881), Upstream PR [#&#8203;47640](cilium/cilium#47640), [@&#8203;julianwiedmann](https://github.com/julianwiedmann))
- bpf: hostfw: tolerate unknown CT protocols and rely on policies (Backport PR [#&#8203;47621](cilium/cilium#47621), Upstream PR [#&#8203;47343](cilium/cilium#47343), [@&#8203;smagnani96](https://github.com/smagnani96))
- clustermesh: fix MCS-API CRD install/upgrade when clustermesh-apiserver is started before the CRD version is actually installed (Backport PR [#&#8203;47885](cilium/cilium#47885), Upstream PR [#&#8203;47824](cilium/cilium#47824), [@&#8203;MrFreezeex](https://github.com/MrFreezeex))
- datapath: turn ARP off on the base devices before bringing them up (Backport PR [#&#8203;47885](cilium/cilium#47885), Upstream PR [#&#8203;47838](cilium/cilium#47838), [@&#8203;aanm](https://github.com/aanm))
- endpoint/watchdog: Avoid warning about endpoints being deleted (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47625](cilium/cilium#47625), [@&#8203;christarazi](https://github.com/christarazi))
- endpoint: Fix silent CIDR policy bypass and traffic drops after agent restart (Backport PR [#&#8203;47954](cilium/cilium#47954), Upstream PR [#&#8203;47880](cilium/cilium#47880), [@&#8203;weizhoublue](https://github.com/weizhoublue))
- envoy.httpUpstreamLingerTimeout accepts `0` as a chart value and templates into configmap. (Backport PR [#&#8203;47885](cilium/cilium#47885), Upstream PR [#&#8203;47741](cilium/cilium#47741), [@&#8203;jdw6359](https://github.com/jdw6359))
- envoy: restore http-idle-timeout as the route idle timeout source (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47583](cilium/cilium#47583), [@&#8203;aanm](https://github.com/aanm))
- Fix a BPF verifier reject on pre-v5.12 kernels, when IPv6 is enabled. (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47765](cilium/cilium#47765), [@&#8203;julianwiedmann](https://github.com/julianwiedmann))
- Fix a deadlock in the shutdown of Cilium operator related to CiliumEndpointSlices. (Backport PR [#&#8203;47967](cilium/cilium#47967), Upstream PR [#&#8203;47802](cilium/cilium#47802), [@&#8203;bimmlerd](https://github.com/bimmlerd))
- Fix a NetworkPolicy update being ignored for up to two minutes when it arrived while an endpoint was waiting for its security identity to be resolved after a pod relabel. (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47727](cilium/cilium#47727), [@&#8203;aanm](https://github.com/aanm))
- Fix a spurious "unable to find ifindex for interface MAC" agent warning on EKS ENI IPAM by waiting for the ENI netlink interface before configuring ingress routes and rules. (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47295](cilium/cilium#47295), [@&#8203;aanm](https://github.com/aanm))
- Fix abnormal ip allocation caused by hostnetwork pod (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47552](cilium/cilium#47552), [@&#8203;haozhangami](https://github.com/haozhangami))
- Fix unintended RevDNAT for client-to-pod TCP connections, when an identical connection was previously established through a DSR Service. (Backport PR [#&#8203;47881](cilium/cilium#47881), Upstream PR [#&#8203;47593](cilium/cilium#47593), [@&#8203;julianwiedmann](https://github.com/julianwiedmann))
- fix: allow setting endpointPolicyUpdateTimeoutDuration in helm (Backport PR [#&#8203;47885](cilium/cilium#47885), Upstream PR [#&#8203;47754](cilium/cilium#47754), [@&#8203;weizhoublue](https://github.com/weizhoublue))
- Fixed an issue where an HTTPRoute referencing a Gateway with mixed listener protocols (e.g. HTTP and TCP) was incorrectly rejected with `NotAllowedByListeners` when the TCP listener had an explicit `AllowedRoutes.Kinds` restriction. (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;46842](cilium/cilium#46842), [@&#8203;pidreher](https://github.com/pidreher))
- gateway-api/gamma: refresh CEC owner refs on route recreation (Backport PR [#&#8203;47954](cilium/cilium#47954), Upstream PR [#&#8203;47840](cilium/cilium#47840), [@&#8203;mhofstetter](https://github.com/mhofstetter))
- gateway-api: mark unresolved backend service ports in route status (Backport PR [#&#8203;47885](cilium/cilium#47885), Upstream PR [#&#8203;47766](cilium/cilium#47766), [@&#8203;mhofstetter](https://github.com/mhofstetter))
- gateway-api: preserve duplicate HTTPRoute rule precedence (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;46696](cilium/cilium#46696), [@&#8203;thorn3r](https://github.com/thorn3r))
- gateway-api: prevent conflicted listeners from reaching ingestion (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47457](cilium/cilium#47457), [@&#8203;asauber](https://github.com/asauber))
- gateway-api: requeue L4/TLS routes on ServiceImport updates (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47702](cilium/cilium#47702), [@&#8203;mhofstetter](https://github.com/mhofstetter))
- gateway-api: sync ListenerSet TLS secrets on ListenerSet events (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47627](cilium/cilium#47627), [@&#8203;mhofstetter](https://github.com/mhofstetter))
- ipcache: fix CIDR reference counter to use canonical prefixes (Backport PR [#&#8203;47885](cilium/cilium#47885), Upstream PR [#&#8203;47208](cilium/cilium#47208), [@&#8203;iwanhae](https://github.com/iwanhae))
- l2announcer: re-evaluate services on frontend changes (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47579](cilium/cilium#47579), [@&#8203;mhofstetter](https://github.com/mhofstetter))
- Log the correct route kind when the Gateway API operator fails to list TLSRoutes for a backend Service (Backport PR [#&#8203;47954](cilium/cilium#47954), Upstream PR [#&#8203;47826](cilium/cilium#47826), [@&#8203;mehrdadbn9](https://github.com/mehrdadbn9))
- operator: Emit startup logs in the configured log format (Backport PR [#&#8203;47954](cilium/cilium#47954), Upstream PR [#&#8203;47890](cilium/cilium#47890), [@&#8203;HadrienPatte](https://github.com/HadrienPatte))
- Resolve a endpoint manager crash for restored endpoints with verbose policy logging enabled. (Backport PR [#&#8203;47885](cilium/cilium#47885), Upstream PR [#&#8203;47844](cilium/cilium#47844), [@&#8203;bimmlerd](https://github.com/bimmlerd))
- standalone-dns-proxy: return an error when no endpoint is found (Backport PR [#&#8203;47954](cilium/cilium#47954), Upstream PR [#&#8203;47791](cilium/cilium#47791), [@&#8203;vipul-21](https://github.com/vipul-21))
- wireguard: Unsubscribe node handler on shutdown (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47614](cilium/cilium#47614), [@&#8203;HadrienPatte](https://github.com/HadrienPatte))

**CI Changes:**

- .github: add python3-scapy for BPF unit tests (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47535](cilium/cilium#47535), [@&#8203;msune](https://github.com/msune))
- .github: run all quarantined EKS tests in a single tolerated step (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47534](cilium/cilium#47534), [@&#8203;aanm](https://github.com/aanm))
- .github: Run envoy image check against PR content (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47792](cilium/cilium#47792), [@&#8203;joestringer](https://github.com/joestringer))
- .github: Simplify permissions for image linter workflow (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47753](cilium/cilium#47753), [@&#8203;joestringer](https://github.com/joestringer))
- .github: suppress spurious encryption leak reports for node-to-pod DNS requests going through proxy (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47470](cilium/cilium#47470), [@&#8203;atykhyy](https://github.com/atykhyy))
- .github: test the default ENI behaviour on the EKS pull request leg (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47569](cilium/cilium#47569), [@&#8203;aanm](https://github.com/aanm))
- ariane: move kind-proxy-embedded and kubespray workflows to /test (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47743](cilium/cilium#47743), [@&#8203;giorio94](https://github.com/giorio94))
- bpf/complexity-tests: Cover L7 LB (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47060](cilium/cilium#47060), [@&#8203;pchaigno](https://github.com/pchaigno))
- ci: build race images on push events so conformance-race works on stable branches (Backport PR [#&#8203;47609](cilium/cilium#47609), Upstream PR [#&#8203;47608](cilium/cilium#47608), [@&#8203;aanm](https://github.com/aanm))
- ci: build race images on push in the stable image builders (Backport PR [#&#8203;47609](cilium/cilium#47609), Upstream PR [#&#8203;47616](cilium/cilium#47616), [@&#8203;aanm](https://github.com/aanm))
- ci: draft renovate PRs until ciliumbot auto-approval (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47364](cilium/cilium#47364), [@&#8203;mhofstetter](https://github.com/mhofstetter))
- ci: fix filtering out md files in bpf checks (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47605](cilium/cilium#47605), [@&#8203;nebril](https://github.com/nebril))
- ci: migrate set-commit-status to cilium/actions (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47771](cilium/cilium#47771), [@&#8203;bogdankrasko](https://github.com/bogdankrasko))
- ci: skip etcd log fetch when kvstore was never started (Backport PR [#&#8203;47885](cilium/cilium#47885), Upstream PR [#&#8203;47801](cilium/cilium#47801), [@&#8203;aanm](https://github.com/aanm))
- Fix missing `events_map_rate_limit` complexity coverage (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47691](cilium/cilium#47691), [@&#8203;pchaigno](https://github.com/pchaigno))
- gha/kubespray: run on schedule, rather than on every push (Backport PR [#&#8203;47731](cilium/cilium#47731), Upstream PR [#&#8203;47719](cilium/cilium#47719), [@&#8203;giorio94](https://github.com/giorio94))
- gha/lvh-kind: respect Kind image version also when config is provided (Backport PR [#&#8203;47731](cilium/cilium#47731), Upstream PR [#&#8203;47703](cilium/cilium#47703), [@&#8203;giorio94](https://github.com/giorio94))
- gha: don't install LLVM and Clang in integration tests workflow (Backport PR [#&#8203;47731](cilium/cilium#47731), Upstream PR [#&#8203;47717](cilium/cilium#47717), [@&#8203;giorio94](https://github.com/giorio94))
- gha: fix checkout of trusted branch in smoke and k8s-kind workflows (Backport PR [#&#8203;47731](cilium/cilium#47731), Upstream PR [#&#8203;47724](cilium/cilium#47724), [@&#8203;giorio94](https://github.com/giorio94))
- images/scripts: Validate Envoy image vars against sed injection (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47205](cilium/cilium#47205), [@&#8203;MasloMaslane](https://github.com/MasloMaslane))
- Revert "gha: don't install LLVM and Clang in integration tests workflow" (Backport PR [#&#8203;47885](cilium/cilium#47885), Upstream PR [#&#8203;47780](cilium/cilium#47780), [@&#8203;giorio94](https://github.com/giorio94))
- test(bpf): parallelize eBPF test compilation (Backport PR [#&#8203;47954](cilium/cilium#47954), Upstream PR [#&#8203;47426](cilium/cilium#47426), [@&#8203;lconnery](https://github.com/lconnery))
- test/cyclonus: log the JUnit XML instead of copying it from a dead pod (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47725](cilium/cilium#47725), [@&#8203;aanm](https://github.com/aanm))
- test: allowlist the leader election read timeout in ginkgo log check (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47612](cilium/cilium#47612), [@&#8203;aanm](https://github.com/aanm))

**Misc Changes:**

- Added documentation for running Cilium in CNI chaining mode on Oracle Kubernetes Engine (OKE) with VCN-Native Pod Networking. (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;46116](cilium/cilium#46116), [@&#8203;amaanx86](https://github.com/amaanx86))
- allocator: fix flake in TestWatchRemoteKVStore (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47455](cilium/cilium#47455), [@&#8203;giorio94](https://github.com/giorio94))
- bpf/nat: Move IPv6 nat entry to map (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47762](cilium/cilium#47762), [@&#8203;pchaigno](https://github.com/pchaigno))
- bpf: conntrack: Reduce stack usage of `ct_create{4,6}` (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47582](cilium/cilium#47582), [@&#8203;dylandreimerink](https://github.com/dylandreimerink))
- bpf: dsr: only require DSR-info on SYN packet (Backport PR [#&#8203;47881](cilium/cilium#47881), Upstream PR [#&#8203;47592](cilium/cilium#47592), [@&#8203;julianwiedmann](https://github.com/julianwiedmann))
- bpf: dsr: re-use TCP SYN flag from CT lookup in remote-backend path (Backport PR [#&#8203;47881](cilium/cilium#47881), Upstream PR [#&#8203;47388](cilium/cilium#47388), [@&#8203;julianwiedmann](https://github.com/julianwiedmann))
- bpf: lb: use dedicated new\_backend bool (Backport PR [#&#8203;47881](cilium/cilium#47881), Upstream PR [#&#8203;47841](cilium/cilium#47841), [@&#8203;julianwiedmann](https://github.com/julianwiedmann))
- chore(deps): update all github action dependencies (v1.20) ([#&#8203;47991](cilium/cilium#47991), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- chore(deps): update all github action dependencies (v1.20) ([#&#8203;48008](cilium/cilium#48008), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- chore(deps): update all-dependencies (v1.20) ([#&#8203;47678](cilium/cilium#47678), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- chore(deps): update dependency cilium/cilium-cli to v0.19.7 (v1.20) ([#&#8203;47576](cilium/cilium#47576), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- chore(deps): update dependency protocolbuffers/protobuf-go to v1.36.12 (v1.20) ([#&#8203;47988](cilium/cilium#47988), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- chore(deps): update docker.io/library/golang:1.26.5 docker digest to [`705e964`](cilium/cilium@705e964) (v1.20) ([#&#8203;47949](cilium/cilium#47949), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- chore(deps): update docker.io/library/golang:1.26.5 docker digest to [`7caba52`](cilium/cilium@7caba52) (v1.20) ([#&#8203;47864](cilium/cilium#47864), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- chore(deps): update quay.io/cilium/cilium-envoy docker tag to v1.37.5-1786449955-8e46c97d1cecc0ba6af6c0c7018a8f18ec93e70d (v1.20) ([#&#8203;47899](cilium/cilium#47899), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- chore(deps): update quay.io/cilium/cilium-envoy docker tag to v1.37.5-1786810558-766ccfb37260a43e9d228837aa84ce3faf9f64e7 (v1.20) ([#&#8203;47989](cilium/cilium#47989), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- chore(deps): update stable lvh-images (v1.20) (patch) ([#&#8203;47865](cilium/cilium#47865), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- chore(deps): update stable lvh-images (v1.20) (patch) ([#&#8203;47990](cilium/cilium#47990), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- clustermesh/endpointslices: explicitly limit maximum decoder memory (Backport PR [#&#8203;47962](cilium/cilium#47962), Upstream PR [#&#8203;47932](cilium/cilium#47932), [@&#8203;giorio94](https://github.com/giorio94))
- docs: clarify GAMMA DROP\_EP\_NOT\_READY events (Backport PR [#&#8203;47885](cilium/cilium#47885), Upstream PR [#&#8203;47587](cilium/cilium#47587), [@&#8203;thorn3r](https://github.com/thorn3r))
- docs: Fix a bug that caused all versions to be treated as pre-release and rendering previous releases in the upgrade guide. (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47600](cilium/cilium#47600), [@&#8203;41ks](https://github.com/41ks))
- docs: Remove "not stable" installation instructions (Backport PR [#&#8203;47798](cilium/cilium#47798), Upstream PR [#&#8203;47646](cilium/cilium#47646), [@&#8203;joestringer](https://github.com/joestringer))
- docs: update Gateway API conformance badge (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47581](cilium/cilium#47581), [@&#8203;arybolovlev](https://github.com/arybolovlev))
- docs: Update Gateway API installation guide (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47446](cilium/cilium#47446), [@&#8203;arybolovlev](https://github.com/arybolovlev))
- Gateway API: the Gateway address status no longer reports a bogus "<nil>" address when a Node's first status address is not an IP literal (e.g. a Hostname entry). (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47466](cilium/cilium#47466), [@&#8203;locker95](https://github.com/locker95))
- gateway-api: remove unnecessary TLSRoute support checks (Backport PR [#&#8203;47885](cilium/cilium#47885), Upstream PR [#&#8203;47758](cilium/cilium#47758), [@&#8203;mhofstetter](https://github.com/mhofstetter))
- gateway-api: report invalid HTTPRoute header modifiers in status (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47599](cilium/cilium#47599), [@&#8203;mhofstetter](https://github.com/mhofstetter))
- gateway-api: return route check errors directly (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47607](cilium/cilium#47607), [@&#8203;mhofstetter](https://github.com/mhofstetter))
- gateway-api: unify Gateway API listener parentRef matching (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;46670](cilium/cilium#46670), [@&#8203;arybolovlev](https://github.com/arybolovlev))
- gateway-api: validate gRPCRoute header modifiers in status (Backport PR [#&#8203;47805](cilium/cilium#47805), Upstream PR [#&#8203;47606](cilium/cilium#47606), [@&#8203;mhofstetter](https://github.com/mhofstetter))
- operator: Replace `reflect.DeepEqual` with `assert.Equal` in tests (Backport PR [#&#8203;47690](cilium/cilium#47690), Upstream PR [#&#8203;47424](cilium/cilium#47424), [@&#8203;HadrienPatte](https://github.com/HadrienPatte))
- Update all github action dependencies (v1.20) ([#&#8203;47656](cilium/cilium#47656), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- Update all github action dependencies (v1.20) ([#&#8203;47675](cilium/cilium#47675), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- Update docker.io/library/busybox:1.38.0 Docker digest to [`dc2d74b`](cilium/cilium@dc2d74b) (v1.20) ([#&#8203;47655](cilium/cilium#47655), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- Update documentation dependencies (Backport PR [#&#8203;47798](cilium/cilium#47798), Upstream PR [#&#8203;47750](cilium/cilium#47750), [@&#8203;joestringer](https://github.com/joestringer))
- Update quay.io/cilium/certgen Docker tag to v0.4.9 (v1.20) ([#&#8203;47657](cilium/cilium#47657), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- Update quay.io/cilium/image-tester Docker tag to v1785158849 (v1.20) ([#&#8203;47659](cilium/cilium#47659), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])
- Update quay.io/lvh-images/kind Docker tag to v6.18-20260720.023802 (v1.20) ([#&#8203;47658](cilium/cilium#47658), [@&#8203;cilium-renovate](https://github.com/cilium-renovate)\[bot])

**Other Changes:**

- install: Update image digests for v1.20.0 ([#&#8203;47584](cilium/cilium#47584), [@&#8203;cilium-release-bot](https://github.com/cilium-release-bot)\[bot])

##### Docker Manifests

##### cilium

`quay.io/cilium/cilium:v1.20.1@sha256:ae9ea21f7427fe24bc6ea7247eb552157a1b0a431744045d3f641545ca71d11b`
`quay.io/cilium/cilium:stable@sha256:ae9ea21f7427fe24bc6ea7247eb552157a1b0a431744045d3f641545ca71d11b`

##### clustermesh-apiserver

`quay.io/cilium/clustermesh-apiserver:v1.20.1@sha256:d905d614a332b2058cb81c193e481d1f460902b903f4eb57cc9764640b750fb5`
`quay.io/cilium/clustermesh-apiserver:stable@sha256:d905d614a332b2058cb81c193e481d1f460902b903f4eb57cc9764640b750fb5`

##### hubble-relay

`quay.io/cilium/hubble-relay:v1.20.1@sha256:59be0ae7d475ab9011a5e954618c0f27b5778b17140381425b308b55ba4917f4`
`quay.io/cilium/hubble-relay:stable@sha256:59be0ae7d475ab9011a5e954618c0f27b5778b17140381425b308b55ba4917f4`

##### operator-alibabacloud

`quay.io/cilium/operator-alibabacloud:v1.20.1@sha256:2af5dd3d85649ea36d365363b8eca82ad06116c6259c4aace700a7c036348e4c`
`quay.io/cilium/operator-alibabacloud:stable@sha256:2af5dd3d85649ea36d365363b8eca82ad06116c6259c4aace700a7c036348e4c`

##### operator-aws

`quay.io/cilium/operator-aws:v1.20.1@sha256:7cf0cb0e6584f72ca8de951a1be03829f69fcaeba69dc6c7856fc4470545acd7`
`quay.io/cilium/operator-aws:stable@sha256:7cf0cb0e6584f72ca8de951a1be03829f69fcaeba69dc6c7856fc4470545acd7`

##### operator-azure

`quay.io/cilium/operator-azure:v1.20.1@sha256:13746a479ca60395df8d83580b49464c6c975cca6fdb21ba4791a076ab01b031`
`quay.io/cilium/operator-azure:stable@sha256:13746a479ca60395df8d83580b49464c6c975cca6fdb21ba4791a076ab01b031`

##### operator-generic

`quay.io/cilium/operator-generic:v1.20.1@sha256:6c3885fc7b629099fdbe2a5c87869c86feb825fa18fae299eac0f61918d16ecf`
`quay.io/cilium/operator-generic:stable@sha256:6c3885fc7b629099fdbe2a5c87869c86feb825fa18fae299eac0f61918d16ecf`

##### operator

`quay.io/cilium/operator:v1.20.1@sha256:67adaf5575902dcce31dc36ba5b5acad397a8b40ec986b55696c94f80b6d861d`
`quay.io/cilium/operator:stable@sha256:67adaf5575902dcce31dc36ba5b5acad397a8b40ec986b55696c94f80b6d861d`

</details>

---

### Configuration

📅 **Schedule**: (in timezone America/New_York)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these updates again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zMS4wIiwidXBkYXRlZEluVmVyIjoiNDQuMzEuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9wYXRjaCJdfQ==-->

Reviewed-on: https://git.greyrock.io/greyrock-labs/home-ops/pulls/349
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport/author The backport will be carried out by the author of the PR. backport/1.20 This PR represents a backport for Cilium 1.20.x of a PR that was merged to main. kind/backports This PR provides functionality previously merged into master. ready-to-merge This PR has passed all tests and received consensus from code owners to merge.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants