dotfiles
dotfiles copied to clipboard
Bump github.com/cilium/cilium from 1.16.6 to 1.16.9 in /dockers
Bumps github.com/cilium/cilium from 1.16.6 to 1.16.9.
Release notes
Sourced from github.com/cilium/cilium's releases.
1.16.9
Summary of Changes
Minor Changes:
- Reject IPSec key rotation with mismatching key lengths to prevent IPv6 disruptions. (Backport PR cilium/cilium#38400, Upstream PR cilium/cilium#37936,
@smagnani96)- Skip WireGuard traffic in the BPF SNAT processing, slightly reducing pressure on the BPF Connection tracking and NAT maps. (Backport PR cilium/cilium#38747, Upstream PR cilium/cilium#35900,
@smagnani96)Bugfixes:
- bpf: wireguard: avoid ipcache lookup for source's security identity (Backport PR cilium/cilium#38747, Upstream PR cilium/cilium#38592,
@julianwiedmann)- Fix panic caused in dual cluster setups where LRPs with
skipRedirectFromBackendflag set to true are installed and IPv6 is disabled. (Backport PR cilium/cilium#38701, Upstream PR cilium/cilium#38656,@aditighag)- For configurations with --enable-identity-mark=false, don't attempt to retrieve the source identity from skb->mark. (Backport PR cilium/cilium#38747, Upstream PR cilium/cilium#38737,
@julianwiedmann)CI Changes:
- build: update golangci-lint to v2.0.0 (Backport PR cilium/cilium#38631, Upstream PR cilium/cilium#38473,
@mhofstetter)- ci: build CI images within merge group (Backport PR cilium/cilium#38525, Upstream PR cilium/cilium#38065,
@marseel)- ci: prepare CI Image build for being required (Backport PR cilium/cilium#38525, Upstream PR cilium/cilium#38320,
@marseel)- Clear traced UDP v4/v6 connections on check-encryption-leak script. (Backport PR cilium/cilium#38521, Upstream PR cilium/cilium#38264,
@smagnani96)- Ensure packet protocol before using L4 ports in the check-encryption-leak script. (Backport PR cilium/cilium#38521, Upstream PR cilium/cilium#38290,
@smagnani96)- Extend tracing with IP length and whether src/dst pod are CiliumInternalIP in the check-encryption-leak script. (Backport PR cilium/cilium#38741, Upstream PR cilium/cilium#38281,
@smagnani96)- Fix checked L4 port for UDP IPv6 packets in check-encryption-leak script. (Backport PR cilium/cilium#38521, Upstream PR cilium/cilium#38265,
@smagnani96)- Fix endianness for WireGuard UDP traffic in the check-encryption-leak script. (Backport PR cilium/cilium#38521, Upstream PR cilium/cilium#38292,
@smagnani96)- Fix erroneous TCP RST condition when no TCP packets in the check-encryption-leak script. (Backport PR cilium/cilium#38521, Upstream PR cilium/cilium#38291,
@smagnani96)- gh: aws-cni: set --enable-identity-mark=false option (Backport PR cilium/cilium#38747, Upstream PR cilium/cilium#38738,
@julianwiedmann)- gh: ci-e2e-upgrade: Add encryption leak checks for wireguard (Backport PR cilium/cilium#38521, Upstream PR cilium/cilium#37551,
@jschwinger233)- gh: update naming for bpftrace leak detection script (Backport PR cilium/cilium#38521, Upstream PR cilium/cilium#37865,
@julianwiedmann)- Introduce tracing log info for ICMP v4/v6 packets in the check-encryption-leak script. (Backport PR cilium/cilium#38741, Upstream PR cilium/cilium#38278,
@smagnani96)- Manual encap checks for when $skb->encapsulation is unset in the check-encryption-leak script. (Backport PR cilium/cilium#38521, Upstream PR cilium/cilium#38293,
@smagnani96)- Print skb pointer and correlate timestamp for subsequent trace logs in the check-encryption-leak script. (Backport PR cilium/cilium#38741, Upstream PR cilium/cilium#38266,
@smagnani96)- Refactoring and code comments for the check-encryption-leak script. (Backport PR cilium/cilium#38741, Upstream PR cilium/cilium#38263,
@smagnani96)- Report masqueraded flow through proxy in the check-encryption-leak script. (Backport PR cilium/cilium#38741, Upstream PR cilium/cilium#38297,
@smagnani96)- Shift header references when encap and move leak check on CiliumInternalIP in the check-encryption-leak script. (Backport PR cilium/cilium#38521, Upstream PR cilium/cilium#38280,
@smagnani96)- Skip tracking DNS proxy connection with CiliumInternalIPs for IPSec in the check-encryption-leak script. (Backport PR cilium/cilium#38521, Upstream PR cilium/cilium#38289,
@smagnani96)- Skip tracking DNS proxy connection with CiliumInternalIPs for IPSec in the check-encryption-leak script. (Backport PR cilium/cilium#38525, Upstream PR cilium/cilium#38289,
@smagnani96)- Skip tracking TCP proxy connection with CiliumInternalIPs for IPSec in the check-encryption-leak script. (Backport PR cilium/cilium#38521, Upstream PR cilium/cilium#38287,
@smagnani96)- Split TCP-related leak report into a separate log line with also seq/ack n. in the check-encryption-leak script. (Backport PR cilium/cilium#38741, Upstream PR cilium/cilium#38268,
@smagnani96)- test: Update FQDN related domain and IP (Backport PR cilium/cilium#38770, Upstream PR cilium/cilium#38754,
@sayboras)Misc Changes:
cilium/cilium#38496@ferozsalam)cilium/cilium#38323@ferozsalam)cilium/cilium#38404@ferozsalam)cilium/cilium#38781@ferozsalam)- bpf: host: identify Cilium's Wireguard traffic as from HOST (Backport PR cilium/cilium#38747, Upstream PR cilium/cilium#37956,
@julianwiedmann)- bpf: let MARK_MAGIC_EGW_DONE carry source identity (Backport PR cilium/cilium#38747, Upstream PR cilium/cilium#38430,
@julianwiedmann)cilium/cilium#38347@cilium-renovate[bot])cilium/cilium#38515@cilium-renovate[bot])cilium/cilium#38346@cilium-renovate[bot])cilium/cilium#38304@cilium-renovate[bot])cilium/cilium#38442@cilium-renovate[bot])
... (truncated)
Changelog
Sourced from github.com/cilium/cilium's changelog.
v1.16.9
Summary of Changes
Minor Changes:
- Reject IPSec key rotation with mismatching key lengths to prevent IPv6 disruptions. (Backport PR cilium/cilium#38400, Upstream PR cilium/cilium#37936,
@smagnani96)- Skip WireGuard traffic in the BPF SNAT processing, slightly reducing pressure on the BPF Connection tracking and NAT maps. (Backport PR cilium/cilium#38747, Upstream PR cilium/cilium#35900,
@smagnani96)Bugfixes:
- bpf: wireguard: avoid ipcache lookup for source's security identity (Backport PR cilium/cilium#38747, Upstream PR cilium/cilium#38592,
@julianwiedmann)- Fix panic caused in dual cluster setups where LRPs with
skipRedirectFromBackendflag set to true are installed and IPv6 is disabled. (Backport PR cilium/cilium#38701, Upstream PR cilium/cilium#38656,@aditighag)- For configurations with --enable-identity-mark=false, don't attempt to retrieve the source identity from skb->mark. (Backport PR cilium/cilium#38747, Upstream PR cilium/cilium#38737,
@julianwiedmann)CI Changes:
- build: update golangci-lint to v2.0.0 (Backport PR cilium/cilium#38631, Upstream PR cilium/cilium#38473,
@mhofstetter)- ci: build CI images within merge group (Backport PR cilium/cilium#38525, Upstream PR cilium/cilium#38065,
@marseel)- ci: prepare CI Image build for being required (Backport PR cilium/cilium#38525, Upstream PR cilium/cilium#38320,
@marseel)- Clear traced UDP v4/v6 connections on check-encryption-leak script. (Backport PR cilium/cilium#38521, Upstream PR cilium/cilium#38264,
@smagnani96)- Ensure packet protocol before using L4 ports in the check-encryption-leak script. (Backport PR cilium/cilium#38521, Upstream PR cilium/cilium#38290,
@smagnani96)- Extend tracing with IP length and whether src/dst pod are CiliumInternalIP in the check-encryption-leak script. (Backport PR cilium/cilium#38741, Upstream PR cilium/cilium#38281,
@smagnani96)- Fix checked L4 port for UDP IPv6 packets in check-encryption-leak script. (Backport PR cilium/cilium#38521, Upstream PR cilium/cilium#38265,
@smagnani96)- Fix endianness for WireGuard UDP traffic in the check-encryption-leak script. (Backport PR cilium/cilium#38521, Upstream PR cilium/cilium#38292,
@smagnani96)- Fix erroneous TCP RST condition when no TCP packets in the check-encryption-leak script. (Backport PR cilium/cilium#38521, Upstream PR cilium/cilium#38291,
@smagnani96)- gh: aws-cni: set --enable-identity-mark=false option (Backport PR cilium/cilium#38747, Upstream PR cilium/cilium#38738,
@julianwiedmann)- gh: ci-e2e-upgrade: Add encryption leak checks for wireguard (Backport PR cilium/cilium#38521, Upstream PR cilium/cilium#37551,
@jschwinger233)- gh: update naming for bpftrace leak detection script (Backport PR cilium/cilium#38521, Upstream PR cilium/cilium#37865,
@julianwiedmann)- Introduce tracing log info for ICMP v4/v6 packets in the check-encryption-leak script. (Backport PR cilium/cilium#38741, Upstream PR cilium/cilium#38278,
@smagnani96)- Manual encap checks for when $skb->encapsulation is unset in the check-encryption-leak script. (Backport PR cilium/cilium#38521, Upstream PR cilium/cilium#38293,
@smagnani96)- Print skb pointer and correlate timestamp for subsequent trace logs in the check-encryption-leak script. (Backport PR cilium/cilium#38741, Upstream PR cilium/cilium#38266,
@smagnani96)- Refactoring and code comments for the check-encryption-leak script. (Backport PR cilium/cilium#38741, Upstream PR cilium/cilium#38263,
@smagnani96)- Report masqueraded flow through proxy in the check-encryption-leak script. (Backport PR cilium/cilium#38741, Upstream PR cilium/cilium#38297,
@smagnani96)- Shift header references when encap and move leak check on CiliumInternalIP in the check-encryption-leak script. (Backport PR cilium/cilium#38521, Upstream PR cilium/cilium#38280,
@smagnani96)- Skip tracking DNS proxy connection with CiliumInternalIPs for IPSec in the check-encryption-leak script. (Backport PR cilium/cilium#38521, Upstream PR cilium/cilium#38289,
@smagnani96)- Skip tracking DNS proxy connection with CiliumInternalIPs for IPSec in the check-encryption-leak script. (Backport PR cilium/cilium#38525, Upstream PR cilium/cilium#38289,
@smagnani96)- Skip tracking TCP proxy connection with CiliumInternalIPs for IPSec in the check-encryption-leak script. (Backport PR cilium/cilium#38521, Upstream PR cilium/cilium#38287,
@smagnani96)- Split TCP-related leak report into a separate log line with also seq/ack n. in the check-encryption-leak script. (Backport PR cilium/cilium#38741, Upstream PR cilium/cilium#38268,
@smagnani96)- test: Update FQDN related domain and IP (Backport PR cilium/cilium#38770, Upstream PR cilium/cilium#38754,
@sayboras)Misc Changes:
cilium/cilium#38496@ferozsalam)cilium/cilium#38323@ferozsalam)cilium/cilium#38404@ferozsalam)cilium/cilium#38781@ferozsalam)- bpf: host: identify Cilium's Wireguard traffic as from HOST (Backport PR cilium/cilium#38747, Upstream PR cilium/cilium#37956,
@julianwiedmann)- bpf: let MARK_MAGIC_EGW_DONE carry source identity (Backport PR cilium/cilium#38747, Upstream PR cilium/cilium#38430,
@julianwiedmann)cilium/cilium#38347@cilium-renovate[bot])cilium/cilium#38515@cilium-renovate[bot])cilium/cilium#38346@cilium-renovate[bot])cilium/cilium#38304@cilium-renovate[bot])
... (truncated)
Commits
bf7387bPrepare for release v1.16.9b2de936chore(deps): update quay.io/cilium/cilium-envoy docker tag to v1.32.5-1744305...6249545images: update cilium-{runtime,builder}e65cdcfchore(deps): update docker.io/library/golang:1.23.8 docker digest to 4f3bd604157586images: update cilium-{runtime,builder}ff4ea72chore(deps): update all-dependencies420eff5lrp: Add IP family checks786ed0ddocs: clarify hubble flow filter match semanticsb35bb43docs: remove endpointRoutes for aws-cni chainingad52b68chore(deps): update stable lvh-images- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.