chore(deps): update helm release cilium to v1.19.6 - #23
Conversation
b983bc7 to
dd1fd55
Compare
134867e to
c64ceda
Compare
c64ceda to
ba79d33
Compare
ba79d33 to
7e1ef45
Compare
12f8c44 to
7d817ec
Compare
7d817ec to
1c25567
Compare
1c25567 to
56ef797
Compare
AI Assessment
AnalysisWhile this is a minor version update with many new features (Ztunnel beta, IPv6 improvements, encryption enhancements), it contains multiple breaking changes and deprecations that require explicit action during upgrade. The release notes explicitly warn of required actions for Network Policies, Cluster Mesh, LoadBalancer IPAM, and BGP. As Cilium is core infrastructure for the homelab's networking layer, any misconfiguration during upgrade could cause widespread connectivity issues. The v1.19.0 release is also very fresh (10th anniversary release with 2934 new commits) and may have undiscovered issues. RecommendationManual review and testing required before merging. Steps: 1) Review the official Cilium v1.19 upgrade guide at https://docs.cilium.io/en/v1.19/operations/upgrade/ for your specific configuration 2) Check if your homelab uses Network Policies, Cluster Mesh, LoadBalancer IPAM, or BGP features that have breaking changes 3) Review deprecation notices for any deprecated features in use 4) Test the upgrade in a non-production environment first 5) Plan for potential downtime or service disruption 6) Have a rollback plan ready (revert to v1.18.x if issues occur) Analyzed by n8n AI Agent using Claude |
56ef797 to
b33e362
Compare
74bf473 to
435d6e8
Compare
435d6e8 to
d1c62af
Compare
d1c62af to
83166d6
Compare
AI Assessment
AnalysisCilium v1.19.3 is a MINOR version update that primarily delivers bugfixes including memory leak fixes, performance improvements, and critical connectivity fixes (NodePort DSR, IPSec key rotation, dual-stack IPAM). While no breaking changes are documented, Cilium is a core infrastructure component controlling all pod-to-pod networking. As such, any upgrade should be validated to ensure cluster stability. The update itself is production-ready and well-tested through multiple patch iterations (v1.19.1→v1.19.2→v1.19.3), but manual verification of pre-upgrade tests and rollback plan is prudent. RecommendationCONDITIONAL APPROVAL: This PR is safe to merge once: (1) pre-upgrade cluster health checks pass, (2) a rollback plan is documented, and (3) upgrade is scheduled during a maintenance window. The extensive bugfixes make this a valuable update. Consider automated merge if CI/CD pipeline includes Cilium-specific health validation tests. Analyzed by n8n AI Agent using Claude |
83166d6 to
723b2d1
Compare
723b2d1 to
c7eb165
Compare
c7eb165 to
bcfe121
Compare
This PR contains the following updates:
1.18.1→1.19.6Release Notes
cilium/cilium (cilium)
v1.19.6: 1.19.6Compare Source
Summary of Changes
Minor Changes:
spec.telemetry.accessLogsfield in CiliumGatewayClassConfig. (Backport PR #46933, Upstream PR #46403, @arybolovlev)Bugfixes:
cilium_operator_unmanaged_podsgauge reporting 0 on reconcile cycles where an unmanaged pod is restarted. (Backport PR #46975, Upstream PR #46668, @Suyash1700)service.cilium.io/affinity: "none"incorrectly dropping all remote backends, causing traffic blackhole when no local endpoints exist. (Backport PR #46691, Upstream PR #46635, @mkamadeus)CI Changes:
Misc Changes:
00feed3(v1.19) (#46657, @cilium-renovate[bot])be93311(v1.19) (#46907, @cilium-renovate[bot])cf1189d(v1.19) (#47115, @cilium-renovate[bot])Other Changes:
Docker Manifests
cilium
quay.io/cilium/cilium:v1.19.6@​sha256:0df5b2750b64c49843aba1d649e9eaf61467cb0645ad3171db6f6962c095ac92clustermesh-apiserver
quay.io/cilium/clustermesh-apiserver:v1.19.6@​sha256:accab5fe6ab7134fcd6f916acc9e4c785382a022128ae5495ec4a45fbe18c9a6docker-plugin
quay.io/cilium/docker-plugin:v1.19.6@​sha256:81a8d37e541edfff4016037373853e8e875f1ea0433c58b9ab54b314c305b9echubble-relay
quay.io/cilium/hubble-relay:v1.19.6@​sha256:6782a49e3f28eba015701c4410a5ec7fa096fe9a562f879b4372dbecd827ea44operator-alibabacloud
quay.io/cilium/operator-alibabacloud:v1.19.6@​sha256:031e332cdec61a9ebaca42f044e7e2f5b876ba96ac0ccf1d42acd5954779efafoperator-aws
quay.io/cilium/operator-aws:v1.19.6@​sha256:546d13ac511cf82441b5e9e99e03d0e054b788513ceb1a883e620b8284d5ccc3operator-azure
quay.io/cilium/operator-azure:v1.19.6@​sha256:e555430b7f5e4c407daab1afbec3c431ec016a53f1f1b848f67b9242cd3adeddoperator-generic
quay.io/cilium/operator-generic:v1.19.6@​sha256:0db4ca4e06969d8904ee036617795d0e9c3228cf7b8d902ba74fc2bb98d2d665operator
quay.io/cilium/operator:v1.19.6@​sha256:37e36840be5a0882a9a065b2308859785e960a742aed0aeac794e0ac4aabdf90v1.19.5: 1.19.5Compare Source
Summary of Changes
Minor Changes:
Bugfixes:
nodeSelectorLabelsis enabled to fix CiliumNetworkPolicy withfromNodes/toNodeswithpolicy-default-local-clusterenabled (enabled by default in 1.19+) (Backport PR #46170, Upstream PR #46068, @MrFreezeex)CI Changes:
pull_requesttriggered workflows to ariane (Backport PR #46452, Upstream PR #45363, @nebril)Misc Changes:
0fc1dd3(v1.19) (#46153, @cilium-renovate[bot])11ecd4e(v1.19) (#46277, @cilium-renovate[bot])cd47774(v1.19) (#46137, @cilium-renovate[bot])e1b3ec8(v1.19) (#46007, @cilium-renovate[bot])9532d8c(v1.19) (#46535, @cilium-renovate[bot])cd05a37(v1.19) (#46138, @cilium-renovate[bot])379065f(v1.19) (#46536, @cilium-renovate[bot])ff6756f(v1.19) (#45996, @cilium-renovate[bot])l2podAnnouncements.interfaceHelm value that rendered a configmap key the agent no longer recognises, causing crash-loops when L2 pod announcements were enabled. Users must usel2podAnnouncements.interfacePatterninstead. (Backport PR #46170, Upstream PR #46093, @salamidrus)Other Changes:
Docker Manifests
cilium
quay.io/cilium/cilium:v1.19.5@​sha256:20fbbc14ac20b55a292c0dcda5571bf31cde30a7dbc68c29db3e709390ab0732clustermesh-apiserver
quay.io/cilium/clustermesh-apiserver:v1.19.5@​sha256:5ed9334b2254315740f9e2a8b6645bf69920f79ef14f436931579d2038784f9bdocker-plugin
quay.io/cilium/docker-plugin:v1.19.5@​sha256:4006d5558390120774a5a903a706dfd64089082bd653b7cb45e9e5a93ff4efeahubble-relay
quay.io/cilium/hubble-relay:v1.19.5@​sha256:24409bfa1bca075c92acb26ba4b49cd573d99d68d5370f7cc825078185222a0coperator-alibabacloud
quay.io/cilium/operator-alibabacloud:v1.19.5@​sha256:c9706343dde700804c2f50c09a2f8291797c707d1747fd50f70c939c23747c16operator-aws
quay.io/cilium/operator-aws:v1.19.5@​sha256:b8473618e8d2bf8a610da445c8c37e1d1e8221aecd05989456d87a7588d66707operator-azure
quay.io/cilium/operator-azure:v1.19.5@​sha256:8600299cb121f9df00fd32b93fa74de89ed49dd3a67e3d7301c07325c04c77f8operator-generic
quay.io/cilium/operator-generic:v1.19.5@​sha256:be848a365776e07d0c5a895eda7aec928ddc52a5a1fa2f432fd7a286609e1db4operator
quay.io/cilium/operator:v1.19.5@​sha256:07a25f6a248d77f0c8417d21b5ea5424a81fe551421e4baf04dc79b1360e832ev1.19.4: 1.19.4Compare Source
Summary of Changes
Minor Changes:
--k8s-service-proxy-nameis set,EndpointSlicesare now filtered by theservice.kubernetes.io/service-proxy-namelabel at the watch level, matching howServicesare already filtered, operators with hand-managedEndpointSlicesmust stamp the matching label on those slices. (Backport PR #45755, Upstream PR #45504, @HadrienPatte)Bugfixes:
cilium map listnow displays "unknown" instead of 0 for maps that do not support cache-based entry counting. (Backport PR #45888, Upstream PR #44951, @skymensch)clustermesh.apiserver.tls.auto.method: certmanager(Backport PR #45630, Upstream PR #45576, @owayss)Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate.