v1.9.2

Date: September 28, 2026

Breaking changes

  • Lua scripts that use the getfenv, setfenv, newproxy, or module globals now fail Strict Lua validation, which is the default mode. Rewrite the script without them, or set EnvoyProxy.spec.lua.validationType to InsecureSyntax or Disabled.

Security updates

  • Hardened the Lua validation sandbox by blocking the getfenv, setfenv, newproxy, and module globals.
  • Prevent user-defined proxies from conflicting with or using controller-owned resources in ControllerNamespace mode. The following are now rejected: resource names colliding with envoy-gateway or envoy-gateway-config; service account names matching the controller’s own SA or the certgen SA (<fullname>-certgen, where <fullname> is the Helm release fullname, defaulting to envoy-gateway); volumes mounting the envoy-gateway Secret or ConfigMap; and environment variables referencing those resources via secretKeyRef, configMapKeyRef, or envFrom.
  • Added an EnvoyProxyPatch runtime flag to EnvoyGateway. EnvoyProxy Kubernetes resource patch fields can grant arbitrary access to resources applied by Envoy Gateway’s more privileged ServiceAccount when EnvoyProxy is namespace-scoped and tenant-authored. The flag is enabled by default to preserve pre-existing behavior; multi-tenant clusters where tenants can author their own EnvoyProxy resources should disable it through runtimeFlags.disabled.
  • Fixed a panic in the xDS server’s Kubernetes JWT authentication when the TokenReview response contains an Extra field without the pod name key (authentication.kubernetes.io/pod-name). Such tokens (e.g. service account tokens not bound to a pod) are now rejected with an Unauthenticated error instead of crashing the control plane.

New features

Bug fixes

  • Fixed a duplicate filter chain matcher error when a TLS listener with no attached routes shares a port with an HTTPS listener, which caused Envoy to reject every subsequent xDS update to that listener.
  • Fixed HTTPS and TLS listeners from different merged Gateways sharing a port and a hostname being accepted, which produced two Envoy filter chains with the same SNI match and caused Envoy to reject the listener.
  • Fixed mergeBackends applying a whole-Gateway BackendTrafficPolicy’s entire cluster-scoped feature set to merged UDP and TCP clusters regardless of the backend’s protocol. Without mergeBackends those settings can never reach such a cluster - ir.UDPRoute, for instance, only carries load balancing and DNS - so enabling cluster deduplication could put healthCheck, circuitBreaker, tcpKeepalive, proxyProtocol, http2, useClientProtocol and HttpProtocolOptions on the cluster udp_proxy routes to, most damagingly running TCP/HTTP health checks against a UDP-only port. A merged cluster now receives only what the same policy would produce for that protocol without mergeBackends.
  • Fixed the xDS translator emitting equivalent-but-byte-different resources on every reconcile: filter typed_config was marshaled non-deterministically, so proto map fields (such as an access log’s json_format) re-ordered their keys each translation and caused repeated no-op xDS pushes. Typed configs are now marshaled deterministically.
  • Fixed ClientTrafficPolicy rejecting BoringSSL equal-preference cipher groups such as [ECDHE-ECDSA-AES128-GCM-SHA256|ECDHE-ECDSA-CHACHA20-POLY1305] as an unsupported cipher suite. Each member of a group is now validated on its own.
  • Fixed MergeBackends being unnecessarily disabled for HTTP and gRPC rules using gateway-level ConsistentHash load balancing.
  • Fixed the shutdown manager exiting after the minimum drain period while UDP proxy sessions were still active. The drain now also waits for udp.*.downstream_sess_active to reach the exit threshold. UDP sessions only close on their idle timeout (60s by default), so a proxy that has handled UDP traffic recently may wait until the drain timeout before exiting.
  • Fixed rateLimitDeployment.pod.priorityClassName being ignored when rendering the rate limit Deployment, so the configured PriorityClass is now applied to the rate limit pod the same way it is for the Envoy Proxy deployment.
  • Fixed local rate limiting for Distinct client selectors to retain up to 10,000 per-value token buckets per wildcard descriptor by applying the cache limit to each route’s filter configuration instead of relying on Envoy’s default of 20.
  • Fixed a panic during shutdown caused by closing the shared infraIR/pResources channels and resources maps before all runner goroutines still consuming or writing to them had exited.

Performance improvements

  • Reduced control-plane memory on gateways where many backends validate against the same CA by storing each upstream CA bundle once per gateway and referencing it by a digest of its content, instead of carrying a copy on every route destination.
  • Reduced xDS translation work for listeners with many routes by computing GeoIP header removals once per listener.
  • Reduced repeated JSON decoding and encoding when JSONPath patches match multiple locations.

Deprecations

Other changes


Last modified September 30, 2026: add missing release notes (#10143) (a6a58d00)