istio(1.29.7): Critical Security Hardening, Ambient Mesh Stability, and Core Fixes

馃搵 Recommended Actions 鈿狅笍 Action Required Immediate upgrade recommended to patch critical security vulnerabilities and ensure robust ambient mesh operation. 馃摑 Summary This release, Istio 1.29.7, delivers essential security fixes and significant stability enhancements across the mesh. We鈥檝e tackled multiple vulnerabilities, including an EnvoyFilter regex denial-of-service vector and an SSRF vulnerability in JWKS URI fetching. Critical functional security fixes ensure BackendTLSPolicy now fails closed when CA references are unresolved and close a Gateway API TLS certificateRef existence oracle. For Ambient Mesh users, stability and performance are greatly improved. We鈥檝e resolved issues where ingress gateways bypassed waypoints in multi-cluster setups and prevented hostNetwork pods from erroneous enrollment. Resource management gets a boost with fixes for istio-cni file descriptor leaks and optimized policy scanning. Furthermore, WDS reconnects are now version-aware, significantly reducing traffic during ztunnel reconnections. Core platform reliability also sees important updates, like a fix for istiod leader election goroutine leaks and improved Gateway API port name disambiguation. Upgrade today to fortify your mesh against potential exploits and benefit from a more resilient and efficient Istio experience. ...

August 27, 2026 路 Daniel Grenemark

istio(1.29.6): Crucial Ambient Mesh Fixes and Core Stability Enhancements

馃搵 Recommended Actions 鈿狅笍 Action Required Immediate action is required for existing auto-registered WorkloadEntries if HBONE functionality is desired. These require re-registration or manual labeling. Review all updates for ambient mesh deployments to ensure proper traffic flow and resource management. 馃摑 Summary Istio 1.29.6 delivers critical stability and reliability enhancements, particularly for ambient mesh users. This release addresses a vital issue where cross-network ambient traffic through east-west gateways could be spuriously blocked by L7 AuthorizationPolicies. A deadlock in the ambient CNI node agent, which could occur during concurrent pod deletion and ztunnel reconnections, has also been resolved, improving robustness. Importantly, HBONE compatibility for non-Kubernetes auto-registered WorkloadEntries is now correctly propagated, though existing entries may need manual updates. Furthermore, a significant memory leak in Istiod related to needResync entries for failed pods has been fixed, enhancing controller stability and reducing resource consumption. These updates collectively bolster Istio鈥檚 ambient capabilities and overall operational efficiency. ...

July 16, 2026 路 Daniel Grenemark

istio(1.29.3): Security Hardening, Ambient Mesh Fixes, and Policy Enhancements

馃搵 Recommended Actions 鈿狅笍 Action Required Immediate patching is highly recommended to address critical security vulnerabilities related to authorization bypasses. Operations engineers should review the updated Ambient Mesh configurations for AWS deployments and consider tuning HBONE window sizes for performance. Review istioctl analyze output for new JWKS URI security warnings. 馃摑 Summary Istio 1.29.3 lands with crucial security fixes, fortifying your mesh against potential bypasses. This release tackles an authorization policy regex vulnerability, ensuring principal and namespace matching behaves as intended. It also tightens XDS debug endpoint access, preventing cross-namespace information exposure for non-system callers. Plus, leaf certificates now respect CA validity, preventing expired cert usage. AWS EKS users with Security Groups for Pods get a critical fix for kubelet health probe failures in Ambient Mesh, ensuring smoother operations. We鈥檝e also added configurable HTTP/2 window sizes for HBONE, offering fine-tuned performance. Tooling improves with a new istioctl analyze warning for JWKS URI security, better handling of Helm webhook failurePolicy during upgrades, and enhanced proxy resource injection for null values. Several core bug fixes, including a multicluster secret controller deadlock and robust Kubernetes secret rotation, contribute to overall stability. ...

May 18, 2026 路 Daniel Grenemark

istio(1.28.3): Enhanced Ambient Multicluster Reliability and Flexible Gateway Service Selectors

馃搵 Recommended Actions 鈿狅笍 Action Required For users leveraging Istio鈥檚 ambient multicluster, an immediate upgrade is highly recommended to address persistent informer errors and improve stability. All users should review the new gateway Helm chart feature for enhanced deployment flexibility. 馃摑 Summary Istio 1.28.3 significantly bolsters ambient multicluster reliability, rectifying a critical issue where remote cluster informer errors previously necessitated an Istiod restart. This update means your multicluster deployments will operate with much greater resilience, ensuring smoother operations and reduced downtime. Additionally, the Istio Gateway Helm chart introduces new service.selectorLabels functionality. This empowers operators with granular control, simplifying complex deployment patterns like revision-based migrations by allowing custom labels on gateway service selectors. Core component updates for proxy and ztunnel alongside nftables ensure overall stability and security. This release focuses on crucial bug fixes for multicluster environments and key enhancements for gateway management, making it a valuable upgrade for improved operational robustness and deployment agility. Review the details to leverage these improvements. ...

January 19, 2026 路 Daniel Grenemark