PageSourceSearch

https://cilium.io/component---src-templates-blog-post-jsx-content-…ilium-rc-4-index-md-7c740195c065d5c6a865.js

js cilium.io collected 2026-09-24 08:27:24 UTC 16,390 bytes, 2 lines download raw bytes

1"use strict";(self.webpackChunkcilium_io=self.webpackChunkcilium_io||[]).push([[4344],{2512:function(e,n,t){t.r(n),t.d(n,{Head:function(){return h},default:function(){return d}});var a=t(8453),l=t(6540);function i(e){const n=Object.assign({p:"p",a:"a",h2:"h2",span:"span",ul:"ul",li:"li",h3:"h3"},(0,a.RP)(),e.components);return l.createElement(l.Fragment,null,l.createElement(n.p,null,"We are excited to have released Cilium 1.0.0-rc4. The release contains a lot of\nbugfixes as usual plus a lot of CI work to ensure quality long term but there\nare also some enhancements highlights and tooling worth mentioning."),"\n",l.createElement(n.p,null,"As usual, the full release notes are attached at the end of the blog but can be\nfound on the ",l.createElement(n.a,{href:"https://github.com/cilium/cilium/releases/tag/v1.0.0-rc4"},"1.0.0-rc4 release\npage"),". Here is a list\nof some highlights:"),"\n",l.createElement(n.h2,null,"Envoy is the default HTTP/gRPC proxy \\o/"),"\n",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<span\n      class="gatsby-resp-image-wrapper"\n      style="position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 1008px; "\n    >\n      <a\n    class="gatsby-resp-image-link"\n    href="/static/58182bbb877596c39147ad446cd2aae3/9b128/Envoy_Logo_Final_PANTONE.png"\n    style="display: block"\n    target="_blank"\n    rel="noopener"\n  >\n    <span\n    class="gatsby-resp-image-background-image"\n    style="padding-bottom: 33.33333333333333%; position: relative; bottom: 0; left: 0; display: block;"\n  ></span>\n  <picture>\n          <source\n              srcset="/static/58182bbb877596c39147ad446cd2aae3/2ff5b/Envoy_Logo_Final_PANTONE.webp 252w,\n/static/58182bbb877596c39147ad446cd2aae3/4d583/Envoy_Logo_Final_PANTONE.webp 504w,\n/static/58182bbb877596c39147ad446cd2aae3/905a7/Envoy_Logo_Final_PANTONE.webp 1008w,\n/static/58182bbb877596c39147ad446cd2aae3/bb9f8/Envoy_Logo_Final_PANTONE.webp 1512w,\n/static/58182bbb877596c39147ad446cd2aae3/83a93/Envoy_Logo_Final_PANTONE.webp 2016w,\n/static/58182bbb877596c39147ad446cd2aae3/3b65f/Envoy_Logo_Final_PANTONE.webp 2265w"\n              sizes="(max-width: 1008px) 100vw, 1008px"\n              type="image/webp"\n            />\n          <source\n            srcset="/static/58182bbb877596c39147ad446cd2aae3/019e0/Envoy_Logo_Final_PANTONE.png 252w,\n/static/58182bbb877596c39147ad446cd2aae3/0dcb2/Envoy_Logo_Final_PANTONE.png 504w,\n/static/58182bbb877596c39147ad446cd2aae3/832a9/Envoy_Logo_Final_PANTONE.png 1008w,\n/static/58182bbb877596c39147ad446cd2aae3/19357/Envoy_Logo_Final_PANTONE.png 1512w,\n/static/58182bbb877596c39147ad446cd2aae3/29ed2/Envoy_Logo_Final_PANTONE.png 2016w,\n/static/58182bbb877596c39147ad446cd2aae3/9b128/Envoy_Logo_Final_PANTONE.png 2265w"\n            sizes="(max-width: 1008px) 100vw, 1008px"\n            type="image/png"\n          />\n          <img\n            class="gatsby-resp-image-image"\n            src="/static/58182bbb877596c39147ad446cd2aae3/832a9/Envoy_Logo_Final_PANTONE.png"\n            alt="Envoy logo"\n            title=""\n            loading="lazy"\n            decoding="async"\n            style="width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;"\n          />\n        </picture>\n  </a>\n    </span>'}}),"\n",l.createElement(n.p,null,"We have finally ripped out the old custom HTTP proxy and made\n",l.createElement(n.a,{href:"https://github.com/envoyproxy/envoy"},"Envoy")," the default proxy for all L7\nenforcement of HTTP and gRPC traffic. In the months up to this we have extended\nEnvoy in various ways to"),"\n",l.createElement(n.ul,null,"\n",l.createElement(n.li,null,"\n",l.createElement(n.p,null,"Introduction of listener filters to allow running filters per listener to\nretrieve per connection metadata. We use this to read metadata from BPF maps\nand make the L3/L4 forwarding context of Cilium available to Envoy.\n",l.createElement(n.a,{href:"https://github.com/envoyproxy/envoy/pull/2346"},"See PR")),"\n"),"\n",l.createElement(n.li,null,"\n",l.createElement(n.p,null,"Addition of the original destination cluster type to allow configuring Envoy\nin a completely transparent manner so whenever a connection is redirected to\nEnvoy, Envoy will always forward to whatever was the original destination of\nthe redirected connection.\n",l.createElement(n.a,{href:"https://github.com/envoyproxy/envoy/pull/1246"},"See PR")),"\n"),"\n",l.createElement(n.li,null,"\n",l.createElement(n.p,null,"Allow tying the HTTP version of an upstream connection to whatever HTTP\nversion the downstream connection is using. This allows preserving full\ntransparency.\n",l.createElement(n.a,{href:"https://github.com/envoyproxy/envoy/pull/2328"},"See PR")),"\n"),"\n",l.createElement(n.li,null,"\n",l.createElement(n.p,null,"Allow HTTP filters to have read access to the downstream connections.\n",l.createElement(n.a,{href:"https://github.com/envoyproxy/envoy/pull/1300"},"See PR")),"\n"),"\n"),"\n",l.createElement(n.h2,null,"Simple health overview for connectivity and other errors"),"\n",l.createElement(n.p,null,"Cilium, like the majority of distributed systems software, is driven by events\nand notifications. Cilium react to events such as addition of a new policy,\nappearance of a new security identity in the cluster, removal of a container on\nthe local node, and so on. Unfortunately things can and will go wrong. The\nkvstore can be become unreachable temporarily, the Kubernetes apiserver can\ncrash, cluster nodes can get rebooted, ... Therefore, code that is associated\nwith such events will eventually fail. How should we notify you as a user? The\nobvious answers are:"),"\n",l.createElement(n.ul,null,"\n",l.createElement(n.li,null,"\n",l.createElement(n.p,null,"Not at all, the code should be written in a resilient manner and retry on\nfailure to eventually recover."),"\n"),"\n",l.createElement(n.li,null,"\n",l.createElement(n.p,null,"The error messages indicating the failure are logged to a logfile."),"\n"),"\n"),"\n",l.createElement(n.p,null,'While resilience is great and logfiles allow to reconstruct all actions\nretrospectively, it makes it hard to know at a specific point in t
1ime, how well\nthe cluster is doing right now. For this purpose, we have introduced what\nwe call "controller status" to the ',l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">cilium status</code>'}})," output:"),"\n",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">$ cilium status\n[...]\nController Status (0/2 failing)\n  Name                               Last success   Last error   Count   Message\n  sync-identity-to-k8s-pod (56326)   36s ago        never        0       no error\n  sync-identity-to-k8s-pod (29898)   32s ago        never        0       no error</code></pre></div>'}}),"\n",l.createElement(n.p,null,"This will allow to give an immediate overview of what is failing right now, why\nit is failing and how often it has been retried. Right now, the ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">cilium status</code>'}}),"\ncommand is available on each node. We will provide a cluster wide tool in one of\nthe next releases."),"\n",l.createElement(n.p,null,"Another common source for overall cluster health issues are defects in the network\nfabric itself which result in connectivity problems. To allow for simple and\neffective monitoring, we have introduced ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">cilium-health</code>'}}),":"),"\n",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<div class="gatsby-highlight" data-language="text"><pre class="language-text"><code class="language-text">$ cilium-health status\nProbe time:   2018-02-06T19:40:16Z\nNodes:\n k8s1 (localhost):\n   Host connectivity to 192.168.36.11:\n     ICMP:          OK, RTT=1.258166ms\n     HTTP via L3:   OK, RTT=434.173µs\n   Endpoint connectivity to 10.10.0.172:\n     ICMP:          OK, RTT=1.266885ms\n     HTTP via L3:   OK, RTT=554.219µs\n k8s2:\n   Host connectivity to 192.168.36.12:\n     ICMP:          OK, RTT=1.53503ms\n     HTTP via L3:   OK, RTT=2.420321ms\n   Endpoint connectivity to 10.10.1.172:\n     ICMP:          OK, RTT=2.081433ms\n     HTTP via L3:   OK, RTT=6.550839ms</code></pre></div>'}}),"\n",l.createElement(n.p,null,"A full blog post on this feature can be found ",l.createElement(n.a,{href:"/blog/2018/2/6/cilium-troubleshooting-cluster-health-monitor"},"here")),"\n",l.createElement(n.h2,null,"Improved scalable kvstore interaction layer"),"\n",l.createElement(n.p,null,"The last big change is a heavily improved interaction layer with the kvstore.\nWe will provide a dedicated blog post on the exact details along with proper\ndocumentation, the highlights are:"),"\n",l.createElement(n.ul,null,"\n",l.createElement(n.li,null,"\n",l.createElement(n.p,null,"All keys inserted by agents to manage the allocation of security identities\nfor endpoints and pods are now protected by leases which means that if a\nnode running an agent goes down and never comes up, the keys will eventually\nexpire and the kvstore will not end up cluttered with unused keys."),"\n"),"\n",l.createElement(n.li,null,"\n",l.createElement(n.p,null,"The process of allocating a security identity has become a lot more\nlightweight and requires less locking. With etcd 3.3 we hope to provide a\ncompletely lockless operation exclusively depending on conditional\ntransactions to improve scalability even further."),"\n"),"\n",l.createElement(n.li,null,"\n",l.createElement(n.p,null,"A new ",l.createElement(n.span,{dangerouslySetInnerHTML:{__html:'<code class="language-text">cilium kvstore</code>'}})," command gives easy access to all kvstore keys and values."),"\n"),"\n"),"\n",l.createElement(n.h2,null,"Release Notes"),"\n",l.createElement(n.h3,null,"Major Changes"),"\n",l.createElement(n.ul,null,"\n",l.createElement(n.li,null,"api: Introduce & expose endpoint controller statuses (#2720, @tgraf)"),"\n",l.createElement(n.li,null,"More scalable kvstore interaction layer (#2708, @tgraf)"),"\n",l.createElement(n.li,null,"Add agent notifications & access log records to monitor (#2667, @tgraf)"),"\n",l.createElement(n.li,null,"Remove oxyproxy and make Envoy the default proxy (#2625, @jrajahalme)"),"\n",l.createElement(n.li,null,"New controller pattern for async operations that can fail (#2597, @tgraf)"),"\n",l.createElement(n.li,null,"Add cilium-health endpoints for datap
1ath connectivity probing (#2315, @joestringer)"),"\n"),"\n",l.createElement(n.h3,null,"Bugfixes Changes"),"\n",l.createElement(n.ul,null,"\n",l.createElement(n.li,null,"Avoid concurrent access of rand.Rand (#2823, @tgraf)"),"\n",l.createElement(n.li,null,"kafka: Use policy identity cache to lookup identity for L3 dependent rules (#2813, @manalibhutiyani)"),"\n",l.createElement(n.li,null,"envoy: Set source identity correctly in access log. (#2807, @jrajahalme)"),"\n",l.createElement(n.li,null,"replaced sysctl invocation with echo redirects (#2789, @aanm)"),"\n",l.createElement(n.li,null,"Set up the k8s watchers based on the kube-apiserver version 2731 (##2735, @aanm)"),"\n",l.createElement(n.li,null,"bpf: Use upper 16 bits of mark for identity (#2719, @tgraf)"),"\n",l.createElement(n.li,null,"bpf: Generate BPF header in order after generating policy (#2718, @tgraf)"),"\n",l.createElement(n.li,null,"Kubernetes NetworkPolicyPeer allows for PodSelector and NamespaceSelector fields to be optional. (#2699, @ianvernon)","\n",l.createElement(n.ul,null,"\n",l.createElement(n.li,null,"Gracefully handle when these objects are nil when we are parsing NetworkPolicy."),"\n"),"\n"),"\n",l.createElement(n.li,null,"Enforce policy update immediately on ongoing connections 2569 #2408 (##2684, @aanm)"),"\n",l.createElement(n.li,null,"envoy: fix rule regex matching by host (#2649, @aanm)"),"\n",l.createElement(n.li,null,"Kafka: Correctly check msgSize in ReadResp before discarding. (#2637, @manalibhutiyani)"),"\n",l.createElement(n.li,null,"Fix envoy deadlock after first crash (#2633, @aanm)"),"\n",l.createElement(n.li,null,"kafka: Reject requests on empty rule set (#2619, @tgraf)"),"\n",l.createElement(n.li,null,"CNP CRD schema versioning (#2614, @nebril)"),"\n",l.createElement(n.li,null,"Fix race while updating L7 proxy redirect in L4PolicyMap (#2607, @joestringer)"),"\n",l.createElement(n.li,null,"Don't allow API users to modify reserved labels for endpoints. (#2595, @joestringer)"),"\n"),"\n",l.createElement(n.h2,null,"Release binaries"),"\n",l.createElement(n.ul,null,"\n",l.createElement(n.li,null,l.createElement(n.a,{href:"http://releases.cilium.io/v1.0.0-rc4/cilium-agent-x86_64"},"cilium-agent-x86_64")," (",l.createElement(n.a,{href:"http://releases.cilium.io/v1.0.0-rc4/cilium-agent-x86_64.sha256sum"},"c58a3a05d8531bd8f677"),")"),"\n",l.createElement(n.li,null,l.createElement(n.a,{href:"http://releases.cilium.io/v1.0.0-rc4/cilium-bugtool-x86_64"},"cilium-bugtool-x86_64")," (",l.createElement(n.a,{href:"http://releases.cilium.io/v1.0.0-rc4/cilium-bugtool-x86_64.sha256sum"},"5ba0547857d71a96d99c"),")"),"\n",l.createElement(n.li,null,l.createElement(n.a,{href:"http://releases.cilium.io/v1.0.0-rc4/cilium-health-x86_64"},"cilium-health-x86_64")," (",l.createElement(n.a,{href:"http://releases.cilium.io/v1.0.0-rc4/cilium-health-x86_64.sha256sum"},"f0015f1345e9bb7eccec"),")"),"\n",l.createElement(n.li,null,l.createElement(n.a,{href:"http://releases.cilium.io/v1.0.0-rc4/cilium-node-monitor-x86_64"},"cilium-node-monitor-x86_64")," (",l.createElement(n.a,{href:"http://releases.cilium.io/v1.0.0-rc4/cilium-node-monitor-x86_64.sha256sum"},"81e189969dcf2a97aca3"),")"),"\n",l.createElement(n.li,null,l.createElement(n.a,{href:"http://releases.cilium.io/v1.0.0-rc4/cilium-x86_64"},"cilium-x86_64")," (",l.createElement(n.a,{href:"http://releases.cilium.io/v1.0.0-rc4/cilium-x86_64.sha256sum"},"2f63b204753aa7a96bb0"),")"),"\n",l.createElement(n.li,null,l.createElement(n.a,{href:"http://releases.cilium.io/v1.0.0-rc4/v1.0.0-rc4.tar.gz"},"v1.0.0-rc4.tar.gz")," (",l.createElement(n.a,{href:"http://releases.cilium.io/v1.0.0-rc4/v1.0.0-rc4.tar.gz.sha256sum"},"39ff5357ea5920af6bca"),")"),"\n",l.createElement(n.li,null,l.createElement(n.a,{href:"http://releases.cilium.io/v1.0.0-rc4/v1.0.0-rc4.zip"},"v1.0.0-rc4.zip")," (",l.createElement(n.a,{href:"http://releases.cilium.io/v1.0.0-rc4/v1.0.0-rc4.zip.sha256sum"},"1c371d84ccad990c6915"),")"),"\n"),"\n",l.createElement(n.p,null,"As usual, let us know on ",l.createElement(n.a,{href:"https://slack.cilium.io/"},"Slack")," if you have any questions."))}
1var r=function(e){void 0===e&&(e={});const{wrapper:n}=Object.assign({},(0,a.RP)(),e.components);return n?l.createElement(n,e,l.createElement(i,e)):i(e)},o=t(8125),c=t(5805),s=t(8838),u=t(2744);const m=e=>{const{data:{mdx:n},children:t}=e,{frontmatter:{path:a,title:i,date:r,tags:s,ogSummary:m}}=n;return l.createElement(u.A,{headerWithSearch:!0},l.createElement(o.A,{path:a,content:t,date:r,title:i,tags:s,summary:m}),l.createElement(c.A,{className:"my-10 md:my-20 lg:my-28"}))},h=e=>{var n,t;let{data:{mdx:a,site:i},location:{pathname:r}}=e;const{frontmatter:{title:o,ogImage:c,ogSummary:u,dateIso:m,tags:h,author:d}}=a,{siteUrl:p}=i.siteMetadata,g=`${u.slice(0,133)}...`,y=`${p}${r}`,f=null!=c&&null!==(n=c.childImageSharp)&&void 0!==n&&null!==(t=n.resize)&&void 0!==t&&t.src?`${p}${c.childImageSharp.resize.src}`:null,v={title:o,description:g,image:c||null,slug:r},E={"@context":"https://schema.org","@type":"BlogPosting",headline:o,description:g,url:y,datePublished:m,dateModified:m,author:d?{"@type":"Person",name:d}:{"@type":"Organization",name:"Cilium",url:p},publisher:{"@type":"Organization",name:"Cilium",url:p,logo:{"@type":"ImageObject",url:`${p}/images/social-preview.jpg`}},...f&&{image:{"@type":"ImageObject",url:f,width:1200,height:630}},...(null==h?void 0:h.length)>0&&{keywords:h.join(", ")}};return l.createElement(s.A,{data:v,type:"article",datePublished:m,jsonLd:E})};function d(e){return l.createElement(m,e,l.createElement(r,e))}}}]);
2//# sourceMappingURL=component---src-templates-blog-post-jsx-content-file-path-src-posts-16-02-2018-cilium-rc-4-index-md-7c740195c065d5c6a865.js.map

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.