Skip to content

feat(translator): HealthCheck Event Logs - #8753

Closed
guydc wants to merge 60 commits into
envoyproxy:mainfrom
guydc:feat-hc-logs
Closed

feat(translator): HealthCheck Event Logs#8753
guydc wants to merge 60 commits into
envoyproxy:mainfrom
guydc:feat-hc-logs

Conversation

@guydc

@guydc guydc commented Apr 15, 2026

Copy link
Copy Markdown
Contributor

What this PR does / why we need it:
Adds support for enabling active healtcheck logs via EnvoyProxy Telemetry.

Release Notes: Yes


PR Checklist

  • Authorship & ownership: Coding agents / AI assistants are welcome, but I have reviewed every change, understand how and why it works, can explain and maintain it, and take full responsibility for this PR. I have not submitted generated output I do not understand.
  • DCO: All commits are signed off (git commit -s). See DCO: Sign your work.
  • API agreed first: If this PR contains API changes (changes under /api), the API was discussed and agreed before the implementation. The API change can be in a separate PR, or in the same PR, but the API must be agreed before implementation. N/A if this PR does not contain API changes.
  • Required checks pass: make generate gen-check, make lint, and the unit-test/coverage build pass. (Flaky e2e failures are not considered breakages, but gen-check, lint, and coverage MUST pass.)
  • Tests added/updated: New/changed code is covered by appropriate tests. N/A if this PR does not contain code changes.
  • Docs: User-facing changes update the docs, either in this PR or a follow-up PR. N/A if this PR does not contain user-facing changes.
  • Release notes: For any non-trivial change, added a release-note fragment under release-notes/current/<section>/<pr-number>-<slug>.md (see release-notes/current/README.md for sections and naming). N/A if this PR does not contain non-trivial changes.
  • Generated files committed: Ran make gen-check and committed the result if API/helm charts/modules changed.
  • Scope & compatibility: The PR is reasonably scoped (no unrelated changes) and preserves backward compatibility, or any breaking change is called out above and documented in release-notes/current/breaking_changes/.
  • Codex review: Requested a Codex review and addressed all of its comments.
  • Copilot review: Requested a Copilot review and addressed all of its comments.

@netlify

netlify Bot commented Apr 15, 2026

Copy link
Copy Markdown

Deploy Preview for cerulean-figolla-1f9435 ready!

Name Link
🔨 Latest commit 1ed599a
🔍 Latest deploy log https://app.netlify.com/projects/cerulean-figolla-1f9435/deploys/6a44504585f70a000894791b
😎 Deploy Preview https://deploy-preview-8753--cerulean-figolla-1f9435.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@guydc

guydc commented Apr 15, 2026

Copy link
Copy Markdown
Contributor Author

@codex

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 43aae07eb4

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread test/e2e/tests/backend_health_check.go Outdated
@codecov

codecov Bot commented Apr 17, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 74.91%. Comparing base (6578a6d) to head (e1c064e).

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #8753      +/-   ##
==========================================
+ Coverage   74.89%   74.91%   +0.01%     
==========================================
  Files         252      252              
  Lines       40799    40844      +45     
==========================================
+ Hits        30558    30597      +39     
- Misses       8158     8163       +5     
- Partials     2083     2084       +1     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@guydc
guydc marked this pull request as ready for review April 20, 2026 20:14
@guydc
guydc requested a review from a team as a code owner April 20, 2026 20:14

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 0277eb3961

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread test/e2e/tests/backend_health_check.go Outdated
Comment on lines +296 to +298
count, err := QueryLogCountFromLoki(t, suite.Client, lokiLabels, "health_checker_type")
require.NoError(t, err, "loki query failed")
require.Equal(t, 0, count, "expected no HC events before HC-enabled route is active")

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Isolate baseline before requiring zero Loki health-check logs

QueryLogCountFromLoki searches the last 10 minutes across all Envoy containers matching job/namespace/container, so this strict count == 0 assertion can fail whenever earlier tests or retries already emitted health_checker_type logs in the same namespace. In shared or retried CI runs, that makes this test flaky even if the "no HC route" behavior is correct; capture a pre-test baseline (or narrow labels to this gateway pod) and assert no increase instead.

Useful? React with 👍 / 👎.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I made the regex query also consider the cluster name that's pretty unique (derived from the route name used in the test yaml)>

zirain
zirain previously approved these changes Apr 24, 2026
guydc added 5 commits April 24, 2026 18:13
Signed-off-by: Guy Daich <guy.daich@sap.com>
Signed-off-by: Guy Daich <guy.daich@sap.com>
Signed-off-by: Guy Daich <guy.daich@sap.com>
Signed-off-by: Guy Daich <guy.daich@sap.com>
Signed-off-by: Guy Daich <guy.daich@sap.com>
@guydc guydc added this to the Backlog milestone Apr 29, 2026
@guydc guydc modified the milestones: Backlog, v1.9.0-rc.1 Release May 15, 2026
Signed-off-by: Guy Daich <guy.daich@sap.com>
Signed-off-by: Guy Daich <guy.daich@sap.com>

@zirain zirain left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

can you add a release notes?

guydc added 2 commits June 12, 2026 17:19
Signed-off-by: Guy Daich <guy.daich@sap.com>
Signed-off-by: Guy Daich <guy.daich@sap.com>
zirain
zirain previously approved these changes Jun 13, 2026
@guydc

guydc commented Jun 26, 2026

Copy link
Copy Markdown
Contributor Author

@codex

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Required fixes (ordered by severity)

  1. CRD schema redundancy from duplicate enum validations: api/v1alpha1/envoyproxy_healthchecklogging_types.go:58-60 (see also generated CRDs)
  2. Silent drop of invalid health-check log sink typed config: internal/xds/translator/cluster.go:637-650

Optional follow-ups

  • Release note grammar nit: release-notes/current.yaml:17

This PR adds a new healthCheckLog telemetry configuration to the EnvoyProxy API, translates it into IR, and programs Envoy health check event logging into generated xDS clusters. It also adds documentation and test coverage (CEL validation + e2e + translator golden testdata) for the new capability.

Changes:

  • Add EnvoyProxy.spec.telemetry.healthCheckLog API (schema, deepcopy, docs) with CEL validations for sinks and match types.
  • Translate healthCheckLog into IR and emit Envoy event_logger configuration on active health checks in xDS cluster generation.
  • Add e2e and CEL-validation tests plus translator golden testdata, and document configuration/usage.

Reviewed changes

Copilot reviewed 23 out of 31 changed files in this pull request and generated 3 comments.

Show a summary per file
File Description
test/helm/gateway-crds-helm/envoy-gateway-crds.out.yaml Generated CRD output updated to include telemetry.healthCheckLog schema.
test/helm/gateway-crds-helm/e2e.out.yaml Generated CRD output updated to include telemetry.healthCheckLog schema.
test/helm/gateway-crds-helm/all.out.yaml Generated CRD output updated to include telemetry.healthCheckLog schema.
test/e2e/tests/backend_health_check.go Adds conformance e2e test asserting health check events appear in logs when enabled.
test/e2e/testdata/backend-health-check-event-log.yaml Test resources to enable healthCheckLog on EnvoyProxy and set up initial route.
test/e2e/testdata/backend-health-check-event-log-hc.yaml Test resources to add HC-enabled route and BackendTrafficPolicy active health check.
test/cel-validation/envoyproxy_test.go Adds CEL validation coverage for healthCheckLog sinks and matches constraints.
site/content/en/latest/tasks/observability/proxy-health-check-log.md New user docs for enabling and verifying health check event logs.
site/content/en/latest/api/extension_types.md API reference docs updated with new health check logging types.
release-notes/current.yaml Adds release note entry for the new EnvoyProxy health check logging feature.
internal/xds/translator/translator.go Threads HealthCheckLog through listener translation into per-route cluster args.
internal/xds/translator/testdata/out/xds-ir/health-check-event-log.routes.yaml Golden output for routes (part of new translator test scenario).
internal/xds/translator/testdata/out/xds-ir/health-check-event-log.listeners.yaml Golden output for listeners (part of new translator test scenario).
internal/xds/translator/testdata/out/xds-ir/health-check-event-log.endpoints.yaml Golden output for endpoints (part of new translator test scenario).
internal/xds/translator/testdata/out/xds-ir/health-check-event-log.clusters.yaml Golden output showing Envoy health check eventLogger configuration emitted.
internal/xds/translator/testdata/in/xds-ir/health-check-event-log.yaml New translator test input including healthCheckLog IR and active health checks.
internal/xds/translator/cluster.go Implements emitting Envoy health check logging (event logger + always-log flags).
internal/ir/zz_generated.deepcopy.go Adds deepcopy support for new IR health check logging types/fields.
internal/ir/xds.go Adds HealthCheckLog to IR and defines IR structs for sinks and flags.
internal/gatewayapi/translator_test.go Updates comparison helper to include HealthCheckLog in XDS IR.
internal/gatewayapi/testdata/health-check-log-disabled.out.yaml New golden output for disabled healthCheckLog scenario.
internal/gatewayapi/testdata/health-check-log-disabled.in.yaml New translator input for disabled healthCheckLog scenario.
internal/gatewayapi/testdata/health-check-log-defaults.out.yaml New golden output for default healthCheckLog behavior (stdout + log all).
internal/gatewayapi/testdata/health-check-log-defaults.in.yaml New translator input for default healthCheckLog behavior.
internal/gatewayapi/listener.go Translates EnvoyProxy telemetry healthCheckLog into IR defaults/flags/sinks.
internal/gatewayapi/listener_test.go Unit tests for processHealthCheckLog translation behavior.
charts/gateway-helm/charts/crds/crds/generated/gateway.envoyproxy.io_envoyproxies.yaml Generated CRD updated to include telemetry.healthCheckLog.
charts/gateway-crds-helm/templates/generated/gateway.envoyproxy.io_envoyproxies.yaml Generated CRD updated to include telemetry.healthCheckLog.
api/v1alpha1/zz_generated.deepcopy.go Adds deepcopy support for new API health check logging types.
api/v1alpha1/envoyproxy_types.go Adds HealthCheckLog to ProxyTelemetry API.
api/v1alpha1/envoyproxy_healthchecklogging_types.go New API types for health check event logging config, matches, and sinks.
Files not reviewed (2)
  • api/v1alpha1/zz_generated.deepcopy.go: Generated file
  • internal/ir/zz_generated.deepcopy.go: Generated file

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +58 to +60
// ProxyHealthCheckLogSinkType is the type of a ProxyHealthCheckLog sink.
// +kubebuilder:validation:Enum=File
type ProxyHealthCheckLogSinkType string
Comment thread release-notes/current.yaml Outdated
Added support for authorization path match.
Added a `requestBody` field to the HTTP active health checker in `BackendTrafficPolicy`, allowing a request body payload to be sent during HTTP health checking. The field requires the health check `method` to be `POST` or `PUT`.
Added the `autoSNIFromEndpointHostname` TLS setting to Backends, allowing the SNI value sent to the backend to be automatically derived from the backend endpoint hostname instead of using a fixed SNI value.
Added support for health check logging in `EnvoyProxy`, allowing logging all active health check results or specific events such as success, failure or transition.
Comment thread internal/xds/translator/cluster.go Outdated
Comment on lines +637 to +650
if healthCheckLogging != nil {
hc.AlwaysLogHealthCheckFailures = healthCheckLogging.AlwaysLogHealthCheckFailures
hc.AlwaysLogHealthCheckSuccess = healthCheckLogging.AlwaysLogHealthCheckSuccess
for _, fs := range healthCheckLogging.FileSinks {
fileSinkAny, err := proto.ToAnyWithValidation(&hcfilev3.HealthCheckEventFileSink{
EventLogPath: fs.Path,
})
if err == nil {
hc.EventLogger = append(hc.EventLogger, &corev3.TypedExtensionConfig{
Name: "envoy.health_check.event_sinks.file",
TypedConfig: fileSinkAny,
})
}
}

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e1c064e2ef

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

// Generate xDS virtual hosts and routes for the given HTTPListener,
// and add them to the xDS route config.
if err = t.addRouteToRouteConfig(tCtx, xdsRouteCfg, httpListener, metrics, http3Settings); err != nil {
if err = t.addRouteToRouteConfig(tCtx, xdsRouteCfg, httpListener, metrics, healthCheckLog, http3Settings); err != nil {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Thread health check logging into extension clusters

When healthCheckLog is configured alongside active health checks on extension backends (for example SecurityPolicy ExtAuth/OIDC/JWT RemoteJWKS or EnvoyExtensionPolicy ExtProc backendSettings.healthCheck.active), only route clusters get the logger here. The extension clusters are still created just after this via patchResources using createExtServiceXDSCluster/addClusterFromURL, whose applyTraffic sets args.healthCheck but has no way to receive healthCheckLog, so those active health checks are emitted without event_logger despite the proxy-wide API promising logging for all clusters with active health checks.

Useful? React with 👍 / 👎.

Comment thread test/e2e/tests/backend_health_check.go Outdated
// Scope to HC events from this test's route only.
count, err := QueryLogCountFromLoki(t, suite.Client, lokiLabels, `health_checker_type.*http-with-hc-event-log`)
require.NoError(t, err, "loki query failed")
require.Equal(t, 0, count, "expected no HC events before HC-enabled route is active")

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Avoid requiring an empty Loki history

In e2e environments that rerun this test within Loki's query window, this absolute zero check can fail even before the route is applied. QueryLogCountFromLoki queries the last 10 minutes and this test uses fixed labels/route name, so health-check events from a previous run of http-with-hc-event-log will make count nonzero; record a baseline/delta or use a unique name instead of requiring zero.

Useful? React with 👍 / 👎.

dependabot Bot and others added 25 commits June 30, 2026 18:17
….33 (envoyproxy#9267)

* build(deps): bump github.com/containerd/containerd from 1.7.32 to 1.7.33

Bumps [github.com/containerd/containerd](https://github.com/containerd/containerd) from 1.7.32 to 1.7.33.
- [Release notes](https://github.com/containerd/containerd/releases)
- [Changelog](https://github.com/containerd/containerd/blob/main/RELEASES.md)
- [Commits](containerd/containerd@v1.7.32...v1.7.33)

---
updated-dependencies:
- dependency-name: github.com/containerd/containerd
  dependency-version: 1.7.33
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix lint

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>
* feat(helm): add CRDs dependency toggle

Allow skipping installation of the `crds` dependency on the gateway-helm
chart by providing a conditional `crds.enabled` variable. This boolean
defaults to `true` and toggles the inclusion of the dependency on the
parent chart.

ref: envoyproxy#8560
Signed-off-by: Gaston Festari <cilindrox@gmail.com>

* docs: update Helm installation steps

Use the `crds.enabled` variable in the examples instead of the
`--skip-crds` flag.

Update crds.enabled variable description.

Co-authored-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>
Signed-off-by: Gaston Festari <cilindrox@gmail.com>

---------

Signed-off-by: Gaston Festari <cilindrox@gmail.com>
Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>
Co-authored-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>
fix proxy protocol with httpProtocolOptions

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>
Co-authored-by: Isaac Wilson <isaac.wilson514@gmail.com>
* fix: validate API Key auth ExtractFrom

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* add test

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* update

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* update

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* update

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

---------

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>
…um (envoyproxy#9224)

* fix: XRateLimitHeadersOptionDisabled constant value must match CRD enum
The constant held "Disabled" but the CRD enum specifies "Off", causing
xRateLimitHeaders: "Off" to silently fall through the translator switch
and always emit X-RateLimit headers.

Fixes envoyproxy#9223

Signed-off-by: gianniskt <gianniskt@gmail.com>

* fix: XRateLimitHeadersOptionDisabled constant value must match CRD enum
The constant held "Disabled" but the CRD enum specifies "Off", causing
xRateLimitHeaders: "Off" to silently fall through the translator switch
and always emit X-RateLimit headers.

Fixes envoyproxy#9223

Signed-off-by: gianniskt <gianniskt@gmail.com>

* fix: add release note for XRateLimitHeadersOptionDisabled fix

Signed-off-by: gianniskt <gianniskt@gmail.com>

---------

Signed-off-by: gianniskt <gianniskt@gmail.com>
Signed-off-by: Ioannis Koutroumpis <gianniskt@gmail.com>
…roxy#9245)

* fix(ratelimit): shared global ratelimit with cost not working

Signed-off-by: zirain <zirain2009@gmail.com>

* fix

Signed-off-by: zirain <zirain2009@gmail.com>

* fix mixed shared rule

Signed-off-by: zirain <zirain2009@gmail.com>

* add e2e

Signed-off-by: zirain <zirain2009@gmail.com>

---------

Signed-off-by: zirain <zirain2009@gmail.com>
* chore: run dependabot on release branch

Signed-off-by: zirain <zirain2009@gmail.com>

* remove npm

Signed-off-by: zirain <zirain2009@gmail.com>

---------

Signed-off-by: zirain <zirain2009@gmail.com>
* fix http retry without backoff

Signed-off-by: zirain <zirain2009@gmail.com>

* release notes

Signed-off-by: zirain <zirain2009@gmail.com>

---------

Signed-off-by: zirain <zirain2009@gmail.com>
* chore: update dependabot

Signed-off-by: zirain <zirain2009@gmail.com>

* add prefix for release branch

Signed-off-by: zirain <zirain2009@gmail.com>

---------

Signed-off-by: zirain <zirain2009@gmail.com>
use pinned docker image

Signed-off-by: zirain <zirain2009@gmail.com>
…nvoyproxy#9277)

Bumps [npm-check-updates](https://github.com/raineorshine/npm-check-updates) from 22.2.3 to 22.2.7.
- [Release notes](https://github.com/raineorshine/npm-check-updates/releases)
- [Changelog](https://github.com/raineorshine/npm-check-updates/blob/main/CHANGELOG.md)
- [Commits](raineorshine/npm-check-updates@v22.2.3...v22.2.7)

---
updated-dependencies:
- dependency-name: npm-check-updates
  dependency-version: 22.2.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Resolve policy targets once

Signed-off-by: jukie <10012479+jukie@users.noreply.github.com>
…envoyproxy#9282)

Bumps the actions group with 2 updates in the / directory: [actions/checkout](https://github.com/actions/checkout) and [softprops/action-gh-release](https://github.com/softprops/action-gh-release).


Updates `actions/checkout` from 6.0.3 to 7.0.0
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@df4cb1c...9c091bb)

Updates `softprops/action-gh-release` from 3.0.0 to 3.0.1
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](softprops/action-gh-release@b430933...718ea10)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: softprops/action-gh-release
  dependency-version: 3.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Isaac Wilson <isaac.wilson514@gmail.com>
…nvoyproxy#9283)

* build(deps): bump the gomod group across 1 directory with 2 updates

Bumps the gomod group with 2 updates in the / directory: [github.com/docker/cli](https://github.com/docker/cli) and [helm.sh/helm/v3](https://github.com/helm/helm).


Updates `github.com/docker/cli` from 29.5.3+incompatible to 29.6.0+incompatible
- [Commits](docker/cli@v29.5.3...v29.6.0)

Updates `helm.sh/helm/v3` from 3.21.1 to 3.21.2
- [Release notes](https://github.com/helm/helm/releases)
- [Commits](helm/helm@v3.21.1...v3.21.2)

---
updated-dependencies:
- dependency-name: github.com/docker/cli
  dependency-version: 29.6.0+incompatible
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod
- dependency-name: helm.sh/helm/v3
  dependency-version: 3.21.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: gomod
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix lint

Signed-off-by: zirain <zirain2009@gmail.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: zirain <zirain2009@gmail.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: zirain <zirain2009@gmail.com>
Co-authored-by: Isaac Wilson <isaac.wilson514@gmail.com>
…nvoyproxy#9279)

* build(deps): bump the helm group across 1 directory with 2 updates

Bumps the helm group with 2 updates in the /charts/gateway-addons-helm directory: alloy and opentelemetry-collector.


Updates `alloy` from 1.9.0 to 1.10.0

Updates `opentelemetry-collector` from 0.158.1 to 0.159.0

---
updated-dependencies:
- dependency-name: alloy
  dependency-version: 1.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: helm
- dependency-name: opentelemetry-collector
  dependency-version: 0.159.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: helm
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix gen

Signed-off-by: zirain <zirain2009@gmail.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: zirain <zirain2009@gmail.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: zirain <zirain2009@gmail.com>
Co-authored-by: Isaac Wilson <isaac.wilson514@gmail.com>
* split release notes

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* address copilot comments

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

---------

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
…voyproxy#9321)

Bumps [autoprefixer](https://github.com/postcss/autoprefixer) from 10.5.0 to 10.5.1.
- [Release notes](https://github.com/postcss/autoprefixer/releases)
- [Changelog](https://github.com/postcss/autoprefixer/blob/main/CHANGELOG.md)
- [Commits](postcss/autoprefixer@10.5.0...10.5.1)

---
updated-dependencies:
- dependency-name: autoprefixer
  dependency-version: 10.5.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…ub-actions/setup-deps in the actions group across 1 directory (envoyproxy#9325)

build(deps): bump actions/setup-go

Bumps the actions group with 1 update in the /tools/github-actions/setup-deps directory: [actions/setup-go](https://github.com/actions/setup-go).


Updates `actions/setup-go` from 6.4.0 to 6.5.0
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](actions/setup-go@4a36011...924ae3a)

---
updated-dependencies:
- dependency-name: actions/setup-go
  dependency-version: 6.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…roxy#9331)

build(deps): ignore k8s.io and go-control-plane on release branches

On release branches, dependabot should not bump k8s.io/* or
github.com/envoyproxy/go-control-plane* packages to avoid unintended
version bumps that could destabilize a release branch.

Signed-off-by: zirain <zirain2009@gmail.com>
* feat: support for

Signed-off-by: zirain <zirain2009@gmail.com>

* fix  gen

Signed-off-by: zirain <zirain2009@gmail.com>

* release notes

Signed-off-by: zirain <zirain2009@gmail.com>

---------

Signed-off-by: zirain <zirain2009@gmail.com>
Co-authored-by: Isaac Wilson <isaac.wilson514@gmail.com>
…o 0.155.0 in /charts/gateway-addons-helm in the helm group across 1 directory (envoyproxy#9344)

* build(deps): bump otel/opentelemetry-collector-contrib

Bumps the helm group with 1 update in the /charts/gateway-addons-helm directory: otel/opentelemetry-collector-contrib.


Updates `otel/opentelemetry-collector-contrib` from 0.154.0 to 0.155.0

---
updated-dependencies:
- dependency-name: otel/opentelemetry-collector-contrib
  dependency-version: 0.155.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: helm
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix gen

Signed-off-by: zirain <zirain2009@gmail.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: zirain <zirain2009@gmail.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: zirain <zirain2009@gmail.com>
…voyproxy#9343)

Bumps [autoprefixer](https://github.com/postcss/autoprefixer) from 10.5.1 to 10.5.2.
- [Release notes](https://github.com/postcss/autoprefixer/releases)
- [Changelog](https://github.com/postcss/autoprefixer/blob/main/CHANGELOG.md)
- [Commits](postcss/autoprefixer@10.5.1...10.5.2)

---
updated-dependencies:
- dependency-name: autoprefixer
  dependency-version: 10.5.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* ci: add tests for Kubernetes 1.36

* add K8s 1.36 conformance and e2e tests
* drop K8s 1.32 conformance tests
* update compatibility matrix

Related upstream documentation:
  https://kind.sigs.k8s.io/docs/user/quick-start/#building-images

Signed-off-by: Clemens Beck <mail@beckcl.dev>

* build(deps): bump kind from 0.31 to 0.32

Signed-off-by: Clemens Beck <mail@beckcl.dev>

---------

Signed-off-by: Clemens Beck <mail@beckcl.dev>
Co-authored-by: Clemens Beck <mail@beckcl.dev>
update pr template

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>
Signed-off-by: Guy Daich <guy.daich@sap.com>
@guydc

guydc commented Jul 1, 2026

Copy link
Copy Markdown
Contributor Author

closed for #9381

@guydc guydc closed this Jul 1, 2026
guydc added a commit to guydc/gateway that referenced this pull request Jul 10, 2026
Adds support for configuring Envoy health check event logging via the
EnvoyProxy API. Health check events (probe outcomes) can be written as
JSON to a file sink (defaults to /dev/stdout).

The new `healthCheckLog` field under `spec.telemetry` of EnvoyProxy
controls which probe outcomes are logged (Failure, FailureTransition,
Success, SuccessTransition) and where the events are written.

Internally, the event log config is carried on ir.ActiveHealthCheck.EventLog
so it flows naturally through TrafficFeatures into every cluster that has
active health checks configured, including filter-created clusters
(ext-proc, extauth, etc.) without any extra threading.

Closes envoyproxy#8753

Signed-off-by: Guy Daich <guy.daich@sap.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.