Skip to main content
logoTetrate Enterprise Gateway for EnvoyVersion: v1.8.x

v1.8.5

Updated Envoy Gateway to v1.8.5.

Breaking Changes​

  • In ControllerNamespace mode, user-defined EnvoyProxy resources may no longer name, mount or reference the controller-owned resources. See the security updates below for the exact rules; an EnvoyProxy that relied on any of them is now rejected.

Security Updates​

  • Prevented user-defined proxies from conflicting with or using controller-owned resources in ControllerNamespace mode. The following are now rejected: resource names colliding with envoy-gateway or envoy-gateway-config; service account names matching the controller's own service account or the certgen service account (<fullname>-certgen, where <fullname> is the Helm release fullname, defaulting to envoy-gateway); volumes mounting the envoy-gateway Secret or ConfigMap; and environment variables referencing those resources via secretKeyRef, configMapKeyRef or envFrom.
  • Added an EnvoyProxyPatch runtime flag to EnvoyGateway. EnvoyProxy Kubernetes resource patch fields can grant arbitrary access to resources applied by Envoy Gateway's more privileged service account when the EnvoyProxy is namespace-scoped and tenant-authored. The flag is enabled by default to preserve the existing behavior; multi-tenant clusters where tenants can author their own EnvoyProxy resources should disable it through runtimeFlags.disabled.
  • Fixed a panic in the xDS server's Kubernetes JWT authentication when the TokenReview response contains an Extra field without the pod name key (authentication.kubernetes.io/pod-name). Such tokens, for example service account tokens not bound to a pod, are now rejected with an Unauthenticated error instead of crashing the control plane.
  • Bumped the Go toolchain to 1.26.8, which includes the latest security fixes from upstream Go.

Bug Fixes​

  • WAF directives of ExtendedSecurityPolicies are now sent on the route configuration (DynamicModuleFilterPerRoute in the route's typedPerFilterConfig) instead of on the listener's HTTP filter. Editing them no longer changes the listener, so Envoy no longer drains it and drops long-lived connections for every route on it. The first rollout changes the listener once as the directives move off it. Requests that match no route are no longer inspected by a Gateway- or GatewayClass-level WAF; they still get a 404 and never reach a backend.
  • The WAF dynamic module now shares its WAF instances across configuration updates instead of rebuilding them on every update, and the waf_tx_duration metric is recorded in microseconds as documented.
  • Fixed a duplicate filter chain matcher error when a TLS listener with no attached routes shares a port with an HTTPS listener, which caused Envoy to reject every subsequent xDS update to that listener.
  • Fixed HTTPS and TLS listeners from different merged Gateways sharing a port and a hostname being accepted, which produced two Envoy filter chains with the same SNI match and caused Envoy to reject the listener.
  • Fixed HTTPRoute status collapsing when a route had two parentRefs to the same Gateway differing only by port (with no sectionName). Both refs resolved to the same RouteParentStatus and one listener's verdict overwrote the other's, so a route accepted on one listener could report Accepted: False borrowed from another. Listener selection and the data plane were unaffected; only the reported status was wrong.
  • Fixed the xDS translator emitting equivalent-but-byte-different resources on every reconcile: filter typed_config was marshaled non-deterministically, so proto map fields (such as an access log's json_format) re-ordered their keys each translation and caused repeated no-op xDS pushes. Typed configs are now marshaled deterministically.
  • Fixed ClientTrafficPolicy rejecting BoringSSL equal-preference cipher groups such as [ECDHE-ECDSA-AES128-GCM-SHA256|ECDHE-ECDSA-CHACHA20-POLY1305] as an unsupported cipher suite. Each member of a group is now validated on its own.
  • Fixed local rate limiting for Distinct client selectors to retain up to 10,000 per-value token buckets per wildcard descriptor by applying the cache limit to each route's filter configuration instead of relying on Envoy's default of 20.
  • Fixed rateLimitDeployment.pod.priorityClassName being ignored when rendering the rate limit Deployment, so the configured PriorityClass is now applied to the rate limit pod the same way it is for the Envoy proxy Deployment.
  • Fixed the shutdown manager exiting after the minimum drain period while UDP proxy sessions were still active. The drain now also waits for udp.*.downstream_sess_active to reach the exit threshold. UDP sessions only close on their idle timeout (60s by default), so a proxy that has handled UDP traffic recently may wait until the drain timeout before exiting.
  • Fixed a panic during shutdown caused by closing the shared infraIR/pResources channels and resource maps before all runner goroutines still consuming or writing to them had exited.

Performance Improvements​

  • Reduced repeated JSON decoding and encoding when JSONPath patches match multiple locations.

Other Changes​

  • Bumped Envoy Gateway to v1.8.5.
  • Bumped the Go toolchain to 1.26.8.
  • Bumped the Redis image deployed by the TEG Helm chart to 8.6.7.
  • Bumped the Keycloak demo chart to 26.7.4.
  • Bumped the BOE composer dynamic module to 0.12.0, which also adds versioned-suffix support to Go plugin loader URLs and moves to Go 1.27.1.
  • Bumped the Rate Limit service. The community edition stays on the Envoy Gateway subchart default, docker.io/envoyproxy/ratelimit:8fe6ea42. The enterprise FIPS edition now pins the Tetrate Rate Limit build fips-containers.teg.tetratelabs.com/ratelimit:v2026.09.30.1, replacing the cf494646-fips tag it used before. The FIPS image no longer carries a -fips tag suffix, since that registry only serves FIPS builds.
  • The TEG control-plane image now pins its distroless base image by digest, so the exact base can be verified and reproduced.