[v1.20] Docs backports 2026-08-05 - #47798
Merged
Merged
Conversation
[ upstream commit 59971ed ] Align these files with standard PEP-8 formatting for consistency. No functional changes. Signed-off-by: Joe Stringer <[email protected]>
[ upstream commit e31c08a ] Move all these version calculations up higher so they're ready for later logic to switch on the results of them. Simplifies upcoming commits. No functional changes. Signed-off-by: Joe Stringer <[email protected]>
[ upstream commit c2d8242 ] Users noticed that we were generating an invalid image tag on the 'latest' version of the docs, because we were deriving the docker image tag directly from the 'VERSION' file, which early during the development cycle points to a version that has no corresponding official image tag. During this point of the cycle, just replace it with the stable branch's first release. Signed-off-by: Joe Stringer <[email protected]>
[ upstream commit 917034a ] Developers don't use these, and they only cause confusion for users who stumble on the '/latest' docs without realizing they're focused at developers. Remove these special cases for installing the development version directly from source. Developers can find the relevant instructions under the development section of the docs. Signed-off-by: Joe Stringer <[email protected]>
[ upstream commit 7ebc521 ] The new version of rstcheck picks up on invalid syntax for this Gateway API link. Rather than attempting to declare a global variable, define an external link substitution. Fixes the following errors: network/servicemesh/gateway-api/gateway-api.rst:80: (ERROR/3) Indirect hyperlink target "upstream repository" (id="upstream-repository") refers to target "gateway_api_examples_url", which does not exist. network/servicemesh/gateway-api/gateway-api.rst:80: (ERROR/3) Unknown target name: "gateway_api_examples_url". Signed-off-by: Joe Stringer <[email protected]>
[ upstream commit cb21a81 ] Refer to the beta.rst path from the Sphinx source root rather than relative directory, to simplify the import and make it consistent. Fixes a rstcheck linter error: contributing/development/reviewers_committers/review_docs.rst:94: (SEVERE/4) File referenced in "include" directive not found: '/src/Documentation/Documentation/beta.rst'. Signed-off-by: Joe Stringer <[email protected]>
[ upstream commit 6420cd9 ] The new version of rstcheck complains: network/kubernetes/kubeproxy-free.rst:1011: (ERROR/3) (yaml) expected a single document in the stream in "<unicode string>", line 1, column 1: apiVersion: v1 ^ but found another document in "<unicode string>", line 14, column 1: --- ^ The error repeats a few times. In many cases, we want to include a full kubernetes YAML example that includes multiple resources, such as a Kubernetes Service and its corresponding EndpointSlices. Therefore it's not critical for all of the YAML documents in the tree to conform to completely standard YAML; multi-document YAMLs is commonly accepted syntax for kubectl tools that we would work with. Signed-off-by: Joe Stringer <[email protected]>
[ upstream commit 705289b ] [ Backporter's notes: Partially pulled in 5c557bd ("chore(deps): update all-dependencies") as well, because there was a race on merging the dependency updates between two PRs. This achieves the actual goal of the commit to bump documentation dependencies, primarily including rstcheck which broke the build without this patch. ] As part of the rebase, specify --sphinx-source-dir in order to ensure that rstcheck understands where the sphinx root directory is. This commit also runs the 'update-requirements' target to pull in the latest Documentation dependencies. Signed-off-by: Joe Stringer <[email protected]>
[ upstream commit 7c5c1b8 ] Signed-off-by: Cilium Imagebot <[email protected]> Signed-off-by: Joe Stringer <[email protected]>
joestringer
force-pushed
the
pr/joe/docs-backports-20260805
branch
from
August 7, 2026 15:54
f52e489 to
5791a79
Compare
Member
Author
|
/test |
|
/test |
joestringer
enabled auto-merge
August 7, 2026 16:43
chancez
approved these changes
Aug 7, 2026
brlbil
approved these changes
Aug 10, 2026
gabrielcosi
pushed a commit
to gabrielcosi/home-ops
that referenced
this pull request
Aug 18, 2026
….20.1) (#430) This PR contains the following updates: | Package | Update | Change | |---|---|---| | [quay.io/cilium/charts/cilium](https://cilium.io/) ([source](https://github.com/cilium/cilium)) | patch | `1.20.0` → `1.20.1` | --- ### Release Notes <details> <summary>cilium/cilium (quay.io/cilium/charts/cilium)</summary> ### [`v1.20.1`](https://github.com/cilium/cilium/releases/tag/v1.20.1): 1.20.1 [Compare Source](cilium/cilium@1.20.0...1.20.1) ## Summary of Changes **Major Changes:** - docs/clustermesh: overhaul Cluster Mesh documentation with a new introduction, improved load-balancing guidance, and Helm-first setup and certificate configuration instructions (Backport PR [#​47615](cilium/cilium#47615), Upstream PR [#​47351](cilium/cilium#47351), [@​MrFreezeex](https://github.com/MrFreezeex)) **Minor Changes:** - envoy: demote stale ADS endpoint warning (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47148](cilium/cilium#47148), [@​nezdolik](https://github.com/nezdolik)) - Speed up recovery time for disrupted TCP connections that access a DSR-enabled Service. (Backport PR [#​47881](cilium/cilium#47881), Upstream PR [#​47529](cilium/cilium#47529), [@​julianwiedmann](https://github.com/julianwiedmann)) **Bugfixes:** - azure: Stop issuing redundant CiliumNode status updates on every IPAM sync when the node's Azure interfaces are unchanged. (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47449](cilium/cilium#47449), [@​jaredledvina](https://github.com/jaredledvina)) - bpf: dsr: don't look for TCP header on fragmented packets (Backport PR [#​47881](cilium/cilium#47881), Upstream PR [#​47640](cilium/cilium#47640), [@​julianwiedmann](https://github.com/julianwiedmann)) - bpf: hostfw: tolerate unknown CT protocols and rely on policies (Backport PR [#​47621](cilium/cilium#47621), Upstream PR [#​47343](cilium/cilium#47343), [@​smagnani96](https://github.com/smagnani96)) - clustermesh: fix MCS-API CRD install/upgrade when clustermesh-apiserver is started before the CRD version is actually installed (Backport PR [#​47885](cilium/cilium#47885), Upstream PR [#​47824](cilium/cilium#47824), [@​MrFreezeex](https://github.com/MrFreezeex)) - datapath: turn ARP off on the base devices before bringing them up (Backport PR [#​47885](cilium/cilium#47885), Upstream PR [#​47838](cilium/cilium#47838), [@​aanm](https://github.com/aanm)) - endpoint/watchdog: Avoid warning about endpoints being deleted (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47625](cilium/cilium#47625), [@​christarazi](https://github.com/christarazi)) - endpoint: Fix silent CIDR policy bypass and traffic drops after agent restart (Backport PR [#​47954](cilium/cilium#47954), Upstream PR [#​47880](cilium/cilium#47880), [@​weizhoublue](https://github.com/weizhoublue)) - envoy.httpUpstreamLingerTimeout accepts `0` as a chart value and templates into configmap. (Backport PR [#​47885](cilium/cilium#47885), Upstream PR [#​47741](cilium/cilium#47741), [@​jdw6359](https://github.com/jdw6359)) - envoy: restore http-idle-timeout as the route idle timeout source (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47583](cilium/cilium#47583), [@​aanm](https://github.com/aanm)) - Fix a BPF verifier reject on pre-v5.12 kernels, when IPv6 is enabled. (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47765](cilium/cilium#47765), [@​julianwiedmann](https://github.com/julianwiedmann)) - Fix a deadlock in the shutdown of Cilium operator related to CiliumEndpointSlices. (Backport PR [#​47967](cilium/cilium#47967), Upstream PR [#​47802](cilium/cilium#47802), [@​bimmlerd](https://github.com/bimmlerd)) - Fix a NetworkPolicy update being ignored for up to two minutes when it arrived while an endpoint was waiting for its security identity to be resolved after a pod relabel. (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47727](cilium/cilium#47727), [@​aanm](https://github.com/aanm)) - Fix a spurious "unable to find ifindex for interface MAC" agent warning on EKS ENI IPAM by waiting for the ENI netlink interface before configuring ingress routes and rules. (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47295](cilium/cilium#47295), [@​aanm](https://github.com/aanm)) - Fix abnormal ip allocation caused by hostnetwork pod (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47552](cilium/cilium#47552), [@​haozhangami](https://github.com/haozhangami)) - Fix unintended RevDNAT for client-to-pod TCP connections, when an identical connection was previously established through a DSR Service. (Backport PR [#​47881](cilium/cilium#47881), Upstream PR [#​47593](cilium/cilium#47593), [@​julianwiedmann](https://github.com/julianwiedmann)) - fix: allow setting endpointPolicyUpdateTimeoutDuration in helm (Backport PR [#​47885](cilium/cilium#47885), Upstream PR [#​47754](cilium/cilium#47754), [@​weizhoublue](https://github.com/weizhoublue)) - Fixed an issue where an HTTPRoute referencing a Gateway with mixed listener protocols (e.g. HTTP and TCP) was incorrectly rejected with `NotAllowedByListeners` when the TCP listener had an explicit `AllowedRoutes.Kinds` restriction. (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​46842](cilium/cilium#46842), [@​pidreher](https://github.com/pidreher)) - gateway-api/gamma: refresh CEC owner refs on route recreation (Backport PR [#​47954](cilium/cilium#47954), Upstream PR [#​47840](cilium/cilium#47840), [@​mhofstetter](https://github.com/mhofstetter)) - gateway-api: mark unresolved backend service ports in route status (Backport PR [#​47885](cilium/cilium#47885), Upstream PR [#​47766](cilium/cilium#47766), [@​mhofstetter](https://github.com/mhofstetter)) - gateway-api: preserve duplicate HTTPRoute rule precedence (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​46696](cilium/cilium#46696), [@​thorn3r](https://github.com/thorn3r)) - gateway-api: prevent conflicted listeners from reaching ingestion (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47457](cilium/cilium#47457), [@​asauber](https://github.com/asauber)) - gateway-api: requeue L4/TLS routes on ServiceImport updates (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47702](cilium/cilium#47702), [@​mhofstetter](https://github.com/mhofstetter)) - gateway-api: sync ListenerSet TLS secrets on ListenerSet events (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47627](cilium/cilium#47627), [@​mhofstetter](https://github.com/mhofstetter)) - ipcache: fix CIDR reference counter to use canonical prefixes (Backport PR [#​47885](cilium/cilium#47885), Upstream PR [#​47208](cilium/cilium#47208), [@​iwanhae](https://github.com/iwanhae)) - l2announcer: re-evaluate services on frontend changes (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47579](cilium/cilium#47579), [@​mhofstetter](https://github.com/mhofstetter)) - Log the correct route kind when the Gateway API operator fails to list TLSRoutes for a backend Service (Backport PR [#​47954](cilium/cilium#47954), Upstream PR [#​47826](cilium/cilium#47826), [@​mehrdadbn9](https://github.com/mehrdadbn9)) - operator: Emit startup logs in the configured log format (Backport PR [#​47954](cilium/cilium#47954), Upstream PR [#​47890](cilium/cilium#47890), [@​HadrienPatte](https://github.com/HadrienPatte)) - Resolve a endpoint manager crash for restored endpoints with verbose policy logging enabled. (Backport PR [#​47885](cilium/cilium#47885), Upstream PR [#​47844](cilium/cilium#47844), [@​bimmlerd](https://github.com/bimmlerd)) - standalone-dns-proxy: return an error when no endpoint is found (Backport PR [#​47954](cilium/cilium#47954), Upstream PR [#​47791](cilium/cilium#47791), [@​vipul-21](https://github.com/vipul-21)) - wireguard: Unsubscribe node handler on shutdown (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47614](cilium/cilium#47614), [@​HadrienPatte](https://github.com/HadrienPatte)) **CI Changes:** - .github: add python3-scapy for BPF unit tests (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47535](cilium/cilium#47535), [@​msune](https://github.com/msune)) - .github: run all quarantined EKS tests in a single tolerated step (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47534](cilium/cilium#47534), [@​aanm](https://github.com/aanm)) - .github: Run envoy image check against PR content (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47792](cilium/cilium#47792), [@​joestringer](https://github.com/joestringer)) - .github: Simplify permissions for image linter workflow (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47753](cilium/cilium#47753), [@​joestringer](https://github.com/joestringer)) - .github: suppress spurious encryption leak reports for node-to-pod DNS requests going through proxy (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47470](cilium/cilium#47470), [@​atykhyy](https://github.com/atykhyy)) - .github: test the default ENI behaviour on the EKS pull request leg (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47569](cilium/cilium#47569), [@​aanm](https://github.com/aanm)) - ariane: move kind-proxy-embedded and kubespray workflows to /test (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47743](cilium/cilium#47743), [@​giorio94](https://github.com/giorio94)) - bpf/complexity-tests: Cover L7 LB (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47060](cilium/cilium#47060), [@​pchaigno](https://github.com/pchaigno)) - ci: build race images on push events so conformance-race works on stable branches (Backport PR [#​47609](cilium/cilium#47609), Upstream PR [#​47608](cilium/cilium#47608), [@​aanm](https://github.com/aanm)) - ci: build race images on push in the stable image builders (Backport PR [#​47609](cilium/cilium#47609), Upstream PR [#​47616](cilium/cilium#47616), [@​aanm](https://github.com/aanm)) - ci: draft renovate PRs until ciliumbot auto-approval (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47364](cilium/cilium#47364), [@​mhofstetter](https://github.com/mhofstetter)) - ci: fix filtering out md files in bpf checks (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47605](cilium/cilium#47605), [@​nebril](https://github.com/nebril)) - ci: migrate set-commit-status to cilium/actions (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47771](cilium/cilium#47771), [@​bogdankrasko](https://github.com/bogdankrasko)) - ci: skip etcd log fetch when kvstore was never started (Backport PR [#​47885](cilium/cilium#47885), Upstream PR [#​47801](cilium/cilium#47801), [@​aanm](https://github.com/aanm)) - Fix missing `events_map_rate_limit` complexity coverage (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47691](cilium/cilium#47691), [@​pchaigno](https://github.com/pchaigno)) - gha/kubespray: run on schedule, rather than on every push (Backport PR [#​47731](cilium/cilium#47731), Upstream PR [#​47719](cilium/cilium#47719), [@​giorio94](https://github.com/giorio94)) - gha/lvh-kind: respect Kind image version also when config is provided (Backport PR [#​47731](cilium/cilium#47731), Upstream PR [#​47703](cilium/cilium#47703), [@​giorio94](https://github.com/giorio94)) - gha: don't install LLVM and Clang in integration tests workflow (Backport PR [#​47731](cilium/cilium#47731), Upstream PR [#​47717](cilium/cilium#47717), [@​giorio94](https://github.com/giorio94)) - gha: fix checkout of trusted branch in smoke and k8s-kind workflows (Backport PR [#​47731](cilium/cilium#47731), Upstream PR [#​47724](cilium/cilium#47724), [@​giorio94](https://github.com/giorio94)) - images/scripts: Validate Envoy image vars against sed injection (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47205](cilium/cilium#47205), [@​MasloMaslane](https://github.com/MasloMaslane)) - Revert "gha: don't install LLVM and Clang in integration tests workflow" (Backport PR [#​47885](cilium/cilium#47885), Upstream PR [#​47780](cilium/cilium#47780), [@​giorio94](https://github.com/giorio94)) - test(bpf): parallelize eBPF test compilation (Backport PR [#​47954](cilium/cilium#47954), Upstream PR [#​47426](cilium/cilium#47426), [@​lconnery](https://github.com/lconnery)) - test/cyclonus: log the JUnit XML instead of copying it from a dead pod (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47725](cilium/cilium#47725), [@​aanm](https://github.com/aanm)) - test: allowlist the leader election read timeout in ginkgo log check (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47612](cilium/cilium#47612), [@​aanm](https://github.com/aanm)) **Misc Changes:** - Added documentation for running Cilium in CNI chaining mode on Oracle Kubernetes Engine (OKE) with VCN-Native Pod Networking. (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​46116](cilium/cilium#46116), [@​amaanx86](https://github.com/amaanx86)) - allocator: fix flake in TestWatchRemoteKVStore (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47455](cilium/cilium#47455), [@​giorio94](https://github.com/giorio94)) - bpf/nat: Move IPv6 nat entry to map (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47762](cilium/cilium#47762), [@​pchaigno](https://github.com/pchaigno)) - bpf: conntrack: Reduce stack usage of `ct_create{4,6}` (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47582](cilium/cilium#47582), [@​dylandreimerink](https://github.com/dylandreimerink)) - bpf: dsr: only require DSR-info on SYN packet (Backport PR [#​47881](cilium/cilium#47881), Upstream PR [#​47592](cilium/cilium#47592), [@​julianwiedmann](https://github.com/julianwiedmann)) - bpf: dsr: re-use TCP SYN flag from CT lookup in remote-backend path (Backport PR [#​47881](cilium/cilium#47881), Upstream PR [#​47388](cilium/cilium#47388), [@​julianwiedmann](https://github.com/julianwiedmann)) - bpf: lb: use dedicated new\_backend bool (Backport PR [#​47881](cilium/cilium#47881), Upstream PR [#​47841](cilium/cilium#47841), [@​julianwiedmann](https://github.com/julianwiedmann)) - chore(deps): update all github action dependencies (v1.20) ([#​47991](cilium/cilium#47991), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - chore(deps): update all github action dependencies (v1.20) ([#​48008](cilium/cilium#48008), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - chore(deps): update all-dependencies (v1.20) ([#​47678](cilium/cilium#47678), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - chore(deps): update dependency cilium/cilium-cli to v0.19.7 (v1.20) ([#​47576](cilium/cilium#47576), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - chore(deps): update dependency protocolbuffers/protobuf-go to v1.36.12 (v1.20) ([#​47988](cilium/cilium#47988), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - chore(deps): update docker.io/library/golang:1.26.5 docker digest to [`705e964`](cilium/cilium@705e964) (v1.20) ([#​47949](cilium/cilium#47949), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - chore(deps): update docker.io/library/golang:1.26.5 docker digest to [`7caba52`](cilium/cilium@7caba52) (v1.20) ([#​47864](cilium/cilium#47864), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - chore(deps): update quay.io/cilium/cilium-envoy docker tag to v1.37.5-1786449955-8e46c97d1cecc0ba6af6c0c7018a8f18ec93e70d (v1.20) ([#​47899](cilium/cilium#47899), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - chore(deps): update quay.io/cilium/cilium-envoy docker tag to v1.37.5-1786810558-766ccfb37260a43e9d228837aa84ce3faf9f64e7 (v1.20) ([#​47989](cilium/cilium#47989), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - chore(deps): update stable lvh-images (v1.20) (patch) ([#​47865](cilium/cilium#47865), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - chore(deps): update stable lvh-images (v1.20) (patch) ([#​47990](cilium/cilium#47990), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - clustermesh/endpointslices: explicitly limit maximum decoder memory (Backport PR [#​47962](cilium/cilium#47962), Upstream PR [#​47932](cilium/cilium#47932), [@​giorio94](https://github.com/giorio94)) - docs: clarify GAMMA DROP\_EP\_NOT\_READY events (Backport PR [#​47885](cilium/cilium#47885), Upstream PR [#​47587](cilium/cilium#47587), [@​thorn3r](https://github.com/thorn3r)) - docs: Fix a bug that caused all versions to be treated as pre-release and rendering previous releases in the upgrade guide. (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47600](cilium/cilium#47600), [@​41ks](https://github.com/41ks)) - docs: Remove "not stable" installation instructions (Backport PR [#​47798](cilium/cilium#47798), Upstream PR [#​47646](cilium/cilium#47646), [@​joestringer](https://github.com/joestringer)) - docs: update Gateway API conformance badge (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47581](cilium/cilium#47581), [@​arybolovlev](https://github.com/arybolovlev)) - docs: Update Gateway API installation guide (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47446](cilium/cilium#47446), [@​arybolovlev](https://github.com/arybolovlev)) - Gateway API: the Gateway address status no longer reports a bogus "<nil>" address when a Node's first status address is not an IP literal (e.g. a Hostname entry). (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47466](cilium/cilium#47466), [@​locker95](https://github.com/locker95)) - gateway-api: remove unnecessary TLSRoute support checks (Backport PR [#​47885](cilium/cilium#47885), Upstream PR [#​47758](cilium/cilium#47758), [@​mhofstetter](https://github.com/mhofstetter)) - gateway-api: report invalid HTTPRoute header modifiers in status (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47599](cilium/cilium#47599), [@​mhofstetter](https://github.com/mhofstetter)) - gateway-api: return route check errors directly (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47607](cilium/cilium#47607), [@​mhofstetter](https://github.com/mhofstetter)) - gateway-api: unify Gateway API listener parentRef matching (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​46670](cilium/cilium#46670), [@​arybolovlev](https://github.com/arybolovlev)) - gateway-api: validate gRPCRoute header modifiers in status (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47606](cilium/cilium#47606), [@​mhofstetter](https://github.com/mhofstetter)) - operator: Replace `reflect.DeepEqual` with `assert.Equal` in tests (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47424](cilium/cilium#47424), [@​HadrienPatte](https://github.com/HadrienPatte)) - Update all github action dependencies (v1.20) ([#​47656](cilium/cilium#47656), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - Update all github action dependencies (v1.20) ([#​47675](cilium/cilium#47675), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - Update docker.io/library/busybox:1.38.0 Docker digest to [`dc2d74b`](cilium/cilium@dc2d74b) (v1.20) ([#​47655](cilium/cilium#47655), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - Update documentation dependencies (Backport PR [#​47798](cilium/cilium#47798), Upstream PR [#​47750](cilium/cilium#47750), [@​joestringer](https://github.com/joestringer)) - Update quay.io/cilium/certgen Docker tag to v0.4.9 (v1.20) ([#​47657](cilium/cilium#47657), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - Update quay.io/cilium/image-tester Docker tag to v1785158849 (v1.20) ([#​47659](cilium/cilium#47659), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - Update quay.io/lvh-images/kind Docker tag to v6.18-20260720.023802 (v1.20) ([#​47658](cilium/cilium#47658), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) **Other Changes:** - install: Update image digests for v1.20.0 ([#​47584](cilium/cilium#47584), [@​cilium-release-bot](https://github.com/cilium-release-bot)\[bot]) #### Docker Manifests ##### cilium `quay.io/cilium/cilium:v1.20.1@sha256:ae9ea21f7427fe24bc6ea7247eb552157a1b0a431744045d3f641545ca71d11b` `quay.io/cilium/cilium:stable@sha256:ae9ea21f7427fe24bc6ea7247eb552157a1b0a431744045d3f641545ca71d11b` ##### clustermesh-apiserver `quay.io/cilium/clustermesh-apiserver:v1.20.1@sha256:d905d614a332b2058cb81c193e481d1f460902b903f4eb57cc9764640b750fb5` `quay.io/cilium/clustermesh-apiserver:stable@sha256:d905d614a332b2058cb81c193e481d1f460902b903f4eb57cc9764640b750fb5` ##### hubble-relay `quay.io/cilium/hubble-relay:v1.20.1@sha256:59be0ae7d475ab9011a5e954618c0f27b5778b17140381425b308b55ba4917f4` `quay.io/cilium/hubble-relay:stable@sha256:59be0ae7d475ab9011a5e954618c0f27b5778b17140381425b308b55ba4917f4` ##### operator-alibabacloud `quay.io/cilium/operator-alibabacloud:v1.20.1@sha256:2af5dd3d85649ea36d365363b8eca82ad06116c6259c4aace700a7c036348e4c` `quay.io/cilium/operator-alibabacloud:stable@sha256:2af5dd3d85649ea36d365363b8eca82ad06116c6259c4aace700a7c036348e4c` ##### operator-aws `quay.io/cilium/operator-aws:v1.20.1@sha256:7cf0cb0e6584f72ca8de951a1be03829f69fcaeba69dc6c7856fc4470545acd7` `quay.io/cilium/operator-aws:stable@sha256:7cf0cb0e6584f72ca8de951a1be03829f69fcaeba69dc6c7856fc4470545acd7` ##### operator-azure `quay.io/cilium/operator-azure:v1.20.1@sha256:13746a479ca60395df8d83580b49464c6c975cca6fdb21ba4791a076ab01b031` `quay.io/cilium/operator-azure:stable@sha256:13746a479ca60395df8d83580b49464c6c975cca6fdb21ba4791a076ab01b031` ##### operator-generic `quay.io/cilium/operator-generic:v1.20.1@sha256:6c3885fc7b629099fdbe2a5c87869c86feb825fa18fae299eac0f61918d16ecf` `quay.io/cilium/operator-generic:stable@sha256:6c3885fc7b629099fdbe2a5c87869c86feb825fa18fae299eac0f61918d16ecf` ##### operator `quay.io/cilium/operator:v1.20.1@sha256:67adaf5575902dcce31dc36ba5b5acad397a8b40ec986b55696c94f80b6d861d` `quay.io/cilium/operator:stable@sha256:67adaf5575902dcce31dc36ba5b5acad397a8b40ec986b55696c94f80b6d861d` </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Berlin) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zMC4zIiwidXBkYXRlZEluVmVyIjoiNDQuMzAuMyIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9wYXRjaCJdfQ==--> Reviewed-on: https://git.xcd.dev/gabrielcosi/home-ops/pulls/430
doonga
pushed a commit
to greyrock-labs/home-ops
that referenced
this pull request
Aug 18, 2026
….20.1) (#349) This PR contains the following updates: | Package | Update | Change | |---|---|---| | [quay.io/cilium/charts/cilium](https://cilium.io/) ([source](https://github.com/cilium/cilium)) | patch | `1.20.0` → `1.20.1` | --- ### Release Notes <details> <summary>cilium/cilium (quay.io/cilium/charts/cilium)</summary> ### [`v1.20.1`](https://github.com/cilium/cilium/releases/tag/v1.20.1): 1.20.1 [Compare Source](cilium/cilium@1.20.0...1.20.1) ## Summary of Changes **Major Changes:** - docs/clustermesh: overhaul Cluster Mesh documentation with a new introduction, improved load-balancing guidance, and Helm-first setup and certificate configuration instructions (Backport PR [#​47615](cilium/cilium#47615), Upstream PR [#​47351](cilium/cilium#47351), [@​MrFreezeex](https://github.com/MrFreezeex)) **Minor Changes:** - envoy: demote stale ADS endpoint warning (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47148](cilium/cilium#47148), [@​nezdolik](https://github.com/nezdolik)) - Speed up recovery time for disrupted TCP connections that access a DSR-enabled Service. (Backport PR [#​47881](cilium/cilium#47881), Upstream PR [#​47529](cilium/cilium#47529), [@​julianwiedmann](https://github.com/julianwiedmann)) **Bugfixes:** - azure: Stop issuing redundant CiliumNode status updates on every IPAM sync when the node's Azure interfaces are unchanged. (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47449](cilium/cilium#47449), [@​jaredledvina](https://github.com/jaredledvina)) - bpf: dsr: don't look for TCP header on fragmented packets (Backport PR [#​47881](cilium/cilium#47881), Upstream PR [#​47640](cilium/cilium#47640), [@​julianwiedmann](https://github.com/julianwiedmann)) - bpf: hostfw: tolerate unknown CT protocols and rely on policies (Backport PR [#​47621](cilium/cilium#47621), Upstream PR [#​47343](cilium/cilium#47343), [@​smagnani96](https://github.com/smagnani96)) - clustermesh: fix MCS-API CRD install/upgrade when clustermesh-apiserver is started before the CRD version is actually installed (Backport PR [#​47885](cilium/cilium#47885), Upstream PR [#​47824](cilium/cilium#47824), [@​MrFreezeex](https://github.com/MrFreezeex)) - datapath: turn ARP off on the base devices before bringing them up (Backport PR [#​47885](cilium/cilium#47885), Upstream PR [#​47838](cilium/cilium#47838), [@​aanm](https://github.com/aanm)) - endpoint/watchdog: Avoid warning about endpoints being deleted (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47625](cilium/cilium#47625), [@​christarazi](https://github.com/christarazi)) - endpoint: Fix silent CIDR policy bypass and traffic drops after agent restart (Backport PR [#​47954](cilium/cilium#47954), Upstream PR [#​47880](cilium/cilium#47880), [@​weizhoublue](https://github.com/weizhoublue)) - envoy.httpUpstreamLingerTimeout accepts `0` as a chart value and templates into configmap. (Backport PR [#​47885](cilium/cilium#47885), Upstream PR [#​47741](cilium/cilium#47741), [@​jdw6359](https://github.com/jdw6359)) - envoy: restore http-idle-timeout as the route idle timeout source (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47583](cilium/cilium#47583), [@​aanm](https://github.com/aanm)) - Fix a BPF verifier reject on pre-v5.12 kernels, when IPv6 is enabled. (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47765](cilium/cilium#47765), [@​julianwiedmann](https://github.com/julianwiedmann)) - Fix a deadlock in the shutdown of Cilium operator related to CiliumEndpointSlices. (Backport PR [#​47967](cilium/cilium#47967), Upstream PR [#​47802](cilium/cilium#47802), [@​bimmlerd](https://github.com/bimmlerd)) - Fix a NetworkPolicy update being ignored for up to two minutes when it arrived while an endpoint was waiting for its security identity to be resolved after a pod relabel. (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47727](cilium/cilium#47727), [@​aanm](https://github.com/aanm)) - Fix a spurious "unable to find ifindex for interface MAC" agent warning on EKS ENI IPAM by waiting for the ENI netlink interface before configuring ingress routes and rules. (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47295](cilium/cilium#47295), [@​aanm](https://github.com/aanm)) - Fix abnormal ip allocation caused by hostnetwork pod (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47552](cilium/cilium#47552), [@​haozhangami](https://github.com/haozhangami)) - Fix unintended RevDNAT for client-to-pod TCP connections, when an identical connection was previously established through a DSR Service. (Backport PR [#​47881](cilium/cilium#47881), Upstream PR [#​47593](cilium/cilium#47593), [@​julianwiedmann](https://github.com/julianwiedmann)) - fix: allow setting endpointPolicyUpdateTimeoutDuration in helm (Backport PR [#​47885](cilium/cilium#47885), Upstream PR [#​47754](cilium/cilium#47754), [@​weizhoublue](https://github.com/weizhoublue)) - Fixed an issue where an HTTPRoute referencing a Gateway with mixed listener protocols (e.g. HTTP and TCP) was incorrectly rejected with `NotAllowedByListeners` when the TCP listener had an explicit `AllowedRoutes.Kinds` restriction. (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​46842](cilium/cilium#46842), [@​pidreher](https://github.com/pidreher)) - gateway-api/gamma: refresh CEC owner refs on route recreation (Backport PR [#​47954](cilium/cilium#47954), Upstream PR [#​47840](cilium/cilium#47840), [@​mhofstetter](https://github.com/mhofstetter)) - gateway-api: mark unresolved backend service ports in route status (Backport PR [#​47885](cilium/cilium#47885), Upstream PR [#​47766](cilium/cilium#47766), [@​mhofstetter](https://github.com/mhofstetter)) - gateway-api: preserve duplicate HTTPRoute rule precedence (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​46696](cilium/cilium#46696), [@​thorn3r](https://github.com/thorn3r)) - gateway-api: prevent conflicted listeners from reaching ingestion (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47457](cilium/cilium#47457), [@​asauber](https://github.com/asauber)) - gateway-api: requeue L4/TLS routes on ServiceImport updates (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47702](cilium/cilium#47702), [@​mhofstetter](https://github.com/mhofstetter)) - gateway-api: sync ListenerSet TLS secrets on ListenerSet events (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47627](cilium/cilium#47627), [@​mhofstetter](https://github.com/mhofstetter)) - ipcache: fix CIDR reference counter to use canonical prefixes (Backport PR [#​47885](cilium/cilium#47885), Upstream PR [#​47208](cilium/cilium#47208), [@​iwanhae](https://github.com/iwanhae)) - l2announcer: re-evaluate services on frontend changes (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47579](cilium/cilium#47579), [@​mhofstetter](https://github.com/mhofstetter)) - Log the correct route kind when the Gateway API operator fails to list TLSRoutes for a backend Service (Backport PR [#​47954](cilium/cilium#47954), Upstream PR [#​47826](cilium/cilium#47826), [@​mehrdadbn9](https://github.com/mehrdadbn9)) - operator: Emit startup logs in the configured log format (Backport PR [#​47954](cilium/cilium#47954), Upstream PR [#​47890](cilium/cilium#47890), [@​HadrienPatte](https://github.com/HadrienPatte)) - Resolve a endpoint manager crash for restored endpoints with verbose policy logging enabled. (Backport PR [#​47885](cilium/cilium#47885), Upstream PR [#​47844](cilium/cilium#47844), [@​bimmlerd](https://github.com/bimmlerd)) - standalone-dns-proxy: return an error when no endpoint is found (Backport PR [#​47954](cilium/cilium#47954), Upstream PR [#​47791](cilium/cilium#47791), [@​vipul-21](https://github.com/vipul-21)) - wireguard: Unsubscribe node handler on shutdown (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47614](cilium/cilium#47614), [@​HadrienPatte](https://github.com/HadrienPatte)) **CI Changes:** - .github: add python3-scapy for BPF unit tests (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47535](cilium/cilium#47535), [@​msune](https://github.com/msune)) - .github: run all quarantined EKS tests in a single tolerated step (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47534](cilium/cilium#47534), [@​aanm](https://github.com/aanm)) - .github: Run envoy image check against PR content (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47792](cilium/cilium#47792), [@​joestringer](https://github.com/joestringer)) - .github: Simplify permissions for image linter workflow (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47753](cilium/cilium#47753), [@​joestringer](https://github.com/joestringer)) - .github: suppress spurious encryption leak reports for node-to-pod DNS requests going through proxy (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47470](cilium/cilium#47470), [@​atykhyy](https://github.com/atykhyy)) - .github: test the default ENI behaviour on the EKS pull request leg (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47569](cilium/cilium#47569), [@​aanm](https://github.com/aanm)) - ariane: move kind-proxy-embedded and kubespray workflows to /test (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47743](cilium/cilium#47743), [@​giorio94](https://github.com/giorio94)) - bpf/complexity-tests: Cover L7 LB (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47060](cilium/cilium#47060), [@​pchaigno](https://github.com/pchaigno)) - ci: build race images on push events so conformance-race works on stable branches (Backport PR [#​47609](cilium/cilium#47609), Upstream PR [#​47608](cilium/cilium#47608), [@​aanm](https://github.com/aanm)) - ci: build race images on push in the stable image builders (Backport PR [#​47609](cilium/cilium#47609), Upstream PR [#​47616](cilium/cilium#47616), [@​aanm](https://github.com/aanm)) - ci: draft renovate PRs until ciliumbot auto-approval (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47364](cilium/cilium#47364), [@​mhofstetter](https://github.com/mhofstetter)) - ci: fix filtering out md files in bpf checks (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47605](cilium/cilium#47605), [@​nebril](https://github.com/nebril)) - ci: migrate set-commit-status to cilium/actions (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47771](cilium/cilium#47771), [@​bogdankrasko](https://github.com/bogdankrasko)) - ci: skip etcd log fetch when kvstore was never started (Backport PR [#​47885](cilium/cilium#47885), Upstream PR [#​47801](cilium/cilium#47801), [@​aanm](https://github.com/aanm)) - Fix missing `events_map_rate_limit` complexity coverage (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47691](cilium/cilium#47691), [@​pchaigno](https://github.com/pchaigno)) - gha/kubespray: run on schedule, rather than on every push (Backport PR [#​47731](cilium/cilium#47731), Upstream PR [#​47719](cilium/cilium#47719), [@​giorio94](https://github.com/giorio94)) - gha/lvh-kind: respect Kind image version also when config is provided (Backport PR [#​47731](cilium/cilium#47731), Upstream PR [#​47703](cilium/cilium#47703), [@​giorio94](https://github.com/giorio94)) - gha: don't install LLVM and Clang in integration tests workflow (Backport PR [#​47731](cilium/cilium#47731), Upstream PR [#​47717](cilium/cilium#47717), [@​giorio94](https://github.com/giorio94)) - gha: fix checkout of trusted branch in smoke and k8s-kind workflows (Backport PR [#​47731](cilium/cilium#47731), Upstream PR [#​47724](cilium/cilium#47724), [@​giorio94](https://github.com/giorio94)) - images/scripts: Validate Envoy image vars against sed injection (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47205](cilium/cilium#47205), [@​MasloMaslane](https://github.com/MasloMaslane)) - Revert "gha: don't install LLVM and Clang in integration tests workflow" (Backport PR [#​47885](cilium/cilium#47885), Upstream PR [#​47780](cilium/cilium#47780), [@​giorio94](https://github.com/giorio94)) - test(bpf): parallelize eBPF test compilation (Backport PR [#​47954](cilium/cilium#47954), Upstream PR [#​47426](cilium/cilium#47426), [@​lconnery](https://github.com/lconnery)) - test/cyclonus: log the JUnit XML instead of copying it from a dead pod (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47725](cilium/cilium#47725), [@​aanm](https://github.com/aanm)) - test: allowlist the leader election read timeout in ginkgo log check (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47612](cilium/cilium#47612), [@​aanm](https://github.com/aanm)) **Misc Changes:** - Added documentation for running Cilium in CNI chaining mode on Oracle Kubernetes Engine (OKE) with VCN-Native Pod Networking. (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​46116](cilium/cilium#46116), [@​amaanx86](https://github.com/amaanx86)) - allocator: fix flake in TestWatchRemoteKVStore (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47455](cilium/cilium#47455), [@​giorio94](https://github.com/giorio94)) - bpf/nat: Move IPv6 nat entry to map (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47762](cilium/cilium#47762), [@​pchaigno](https://github.com/pchaigno)) - bpf: conntrack: Reduce stack usage of `ct_create{4,6}` (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47582](cilium/cilium#47582), [@​dylandreimerink](https://github.com/dylandreimerink)) - bpf: dsr: only require DSR-info on SYN packet (Backport PR [#​47881](cilium/cilium#47881), Upstream PR [#​47592](cilium/cilium#47592), [@​julianwiedmann](https://github.com/julianwiedmann)) - bpf: dsr: re-use TCP SYN flag from CT lookup in remote-backend path (Backport PR [#​47881](cilium/cilium#47881), Upstream PR [#​47388](cilium/cilium#47388), [@​julianwiedmann](https://github.com/julianwiedmann)) - bpf: lb: use dedicated new\_backend bool (Backport PR [#​47881](cilium/cilium#47881), Upstream PR [#​47841](cilium/cilium#47841), [@​julianwiedmann](https://github.com/julianwiedmann)) - chore(deps): update all github action dependencies (v1.20) ([#​47991](cilium/cilium#47991), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - chore(deps): update all github action dependencies (v1.20) ([#​48008](cilium/cilium#48008), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - chore(deps): update all-dependencies (v1.20) ([#​47678](cilium/cilium#47678), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - chore(deps): update dependency cilium/cilium-cli to v0.19.7 (v1.20) ([#​47576](cilium/cilium#47576), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - chore(deps): update dependency protocolbuffers/protobuf-go to v1.36.12 (v1.20) ([#​47988](cilium/cilium#47988), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - chore(deps): update docker.io/library/golang:1.26.5 docker digest to [`705e964`](cilium/cilium@705e964) (v1.20) ([#​47949](cilium/cilium#47949), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - chore(deps): update docker.io/library/golang:1.26.5 docker digest to [`7caba52`](cilium/cilium@7caba52) (v1.20) ([#​47864](cilium/cilium#47864), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - chore(deps): update quay.io/cilium/cilium-envoy docker tag to v1.37.5-1786449955-8e46c97d1cecc0ba6af6c0c7018a8f18ec93e70d (v1.20) ([#​47899](cilium/cilium#47899), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - chore(deps): update quay.io/cilium/cilium-envoy docker tag to v1.37.5-1786810558-766ccfb37260a43e9d228837aa84ce3faf9f64e7 (v1.20) ([#​47989](cilium/cilium#47989), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - chore(deps): update stable lvh-images (v1.20) (patch) ([#​47865](cilium/cilium#47865), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - chore(deps): update stable lvh-images (v1.20) (patch) ([#​47990](cilium/cilium#47990), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - clustermesh/endpointslices: explicitly limit maximum decoder memory (Backport PR [#​47962](cilium/cilium#47962), Upstream PR [#​47932](cilium/cilium#47932), [@​giorio94](https://github.com/giorio94)) - docs: clarify GAMMA DROP\_EP\_NOT\_READY events (Backport PR [#​47885](cilium/cilium#47885), Upstream PR [#​47587](cilium/cilium#47587), [@​thorn3r](https://github.com/thorn3r)) - docs: Fix a bug that caused all versions to be treated as pre-release and rendering previous releases in the upgrade guide. (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47600](cilium/cilium#47600), [@​41ks](https://github.com/41ks)) - docs: Remove "not stable" installation instructions (Backport PR [#​47798](cilium/cilium#47798), Upstream PR [#​47646](cilium/cilium#47646), [@​joestringer](https://github.com/joestringer)) - docs: update Gateway API conformance badge (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47581](cilium/cilium#47581), [@​arybolovlev](https://github.com/arybolovlev)) - docs: Update Gateway API installation guide (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47446](cilium/cilium#47446), [@​arybolovlev](https://github.com/arybolovlev)) - Gateway API: the Gateway address status no longer reports a bogus "<nil>" address when a Node's first status address is not an IP literal (e.g. a Hostname entry). (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47466](cilium/cilium#47466), [@​locker95](https://github.com/locker95)) - gateway-api: remove unnecessary TLSRoute support checks (Backport PR [#​47885](cilium/cilium#47885), Upstream PR [#​47758](cilium/cilium#47758), [@​mhofstetter](https://github.com/mhofstetter)) - gateway-api: report invalid HTTPRoute header modifiers in status (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47599](cilium/cilium#47599), [@​mhofstetter](https://github.com/mhofstetter)) - gateway-api: return route check errors directly (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47607](cilium/cilium#47607), [@​mhofstetter](https://github.com/mhofstetter)) - gateway-api: unify Gateway API listener parentRef matching (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​46670](cilium/cilium#46670), [@​arybolovlev](https://github.com/arybolovlev)) - gateway-api: validate gRPCRoute header modifiers in status (Backport PR [#​47805](cilium/cilium#47805), Upstream PR [#​47606](cilium/cilium#47606), [@​mhofstetter](https://github.com/mhofstetter)) - operator: Replace `reflect.DeepEqual` with `assert.Equal` in tests (Backport PR [#​47690](cilium/cilium#47690), Upstream PR [#​47424](cilium/cilium#47424), [@​HadrienPatte](https://github.com/HadrienPatte)) - Update all github action dependencies (v1.20) ([#​47656](cilium/cilium#47656), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - Update all github action dependencies (v1.20) ([#​47675](cilium/cilium#47675), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - Update docker.io/library/busybox:1.38.0 Docker digest to [`dc2d74b`](cilium/cilium@dc2d74b) (v1.20) ([#​47655](cilium/cilium#47655), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - Update documentation dependencies (Backport PR [#​47798](cilium/cilium#47798), Upstream PR [#​47750](cilium/cilium#47750), [@​joestringer](https://github.com/joestringer)) - Update quay.io/cilium/certgen Docker tag to v0.4.9 (v1.20) ([#​47657](cilium/cilium#47657), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - Update quay.io/cilium/image-tester Docker tag to v1785158849 (v1.20) ([#​47659](cilium/cilium#47659), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) - Update quay.io/lvh-images/kind Docker tag to v6.18-20260720.023802 (v1.20) ([#​47658](cilium/cilium#47658), [@​cilium-renovate](https://github.com/cilium-renovate)\[bot]) **Other Changes:** - install: Update image digests for v1.20.0 ([#​47584](cilium/cilium#47584), [@​cilium-release-bot](https://github.com/cilium-release-bot)\[bot]) ##### Docker Manifests ##### cilium `quay.io/cilium/cilium:v1.20.1@sha256:ae9ea21f7427fe24bc6ea7247eb552157a1b0a431744045d3f641545ca71d11b` `quay.io/cilium/cilium:stable@sha256:ae9ea21f7427fe24bc6ea7247eb552157a1b0a431744045d3f641545ca71d11b` ##### clustermesh-apiserver `quay.io/cilium/clustermesh-apiserver:v1.20.1@sha256:d905d614a332b2058cb81c193e481d1f460902b903f4eb57cc9764640b750fb5` `quay.io/cilium/clustermesh-apiserver:stable@sha256:d905d614a332b2058cb81c193e481d1f460902b903f4eb57cc9764640b750fb5` ##### hubble-relay `quay.io/cilium/hubble-relay:v1.20.1@sha256:59be0ae7d475ab9011a5e954618c0f27b5778b17140381425b308b55ba4917f4` `quay.io/cilium/hubble-relay:stable@sha256:59be0ae7d475ab9011a5e954618c0f27b5778b17140381425b308b55ba4917f4` ##### operator-alibabacloud `quay.io/cilium/operator-alibabacloud:v1.20.1@sha256:2af5dd3d85649ea36d365363b8eca82ad06116c6259c4aace700a7c036348e4c` `quay.io/cilium/operator-alibabacloud:stable@sha256:2af5dd3d85649ea36d365363b8eca82ad06116c6259c4aace700a7c036348e4c` ##### operator-aws `quay.io/cilium/operator-aws:v1.20.1@sha256:7cf0cb0e6584f72ca8de951a1be03829f69fcaeba69dc6c7856fc4470545acd7` `quay.io/cilium/operator-aws:stable@sha256:7cf0cb0e6584f72ca8de951a1be03829f69fcaeba69dc6c7856fc4470545acd7` ##### operator-azure `quay.io/cilium/operator-azure:v1.20.1@sha256:13746a479ca60395df8d83580b49464c6c975cca6fdb21ba4791a076ab01b031` `quay.io/cilium/operator-azure:stable@sha256:13746a479ca60395df8d83580b49464c6c975cca6fdb21ba4791a076ab01b031` ##### operator-generic `quay.io/cilium/operator-generic:v1.20.1@sha256:6c3885fc7b629099fdbe2a5c87869c86feb825fa18fae299eac0f61918d16ecf` `quay.io/cilium/operator-generic:stable@sha256:6c3885fc7b629099fdbe2a5c87869c86feb825fa18fae299eac0f61918d16ecf` ##### operator `quay.io/cilium/operator:v1.20.1@sha256:67adaf5575902dcce31dc36ba5b5acad397a8b40ec986b55696c94f80b6d861d` `quay.io/cilium/operator:stable@sha256:67adaf5575902dcce31dc36ba5b5acad397a8b40ec986b55696c94f80b6d861d` </details> --- ### Configuration 📅 **Schedule**: (in timezone America/New_York) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zMS4wIiwidXBkYXRlZEluVmVyIjoiNDQuMzEuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9wYXRjaCJdfQ==--> Reviewed-on: https://git.greyrock.io/greyrock-labs/home-ops/pulls/349
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Depends on #47690
I made some minor updates to commits in #47750 because the docs dependencies were updated in #47744. This fixes up the commits to ensure that
rstcheckdependency is bumped to v6.3.0. Once this PR is merged, we can rebase #47678 to drop the docs update dependency.