-
Notifications
You must be signed in to change notification settings - Fork 826
Sync release/v1.8 with main #8896
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Closed
Closed
Changes from all commits
Commits
Show all changes
168 commits
Select commit
Hold shift + click to select a range
595010a
fix: per-endpoint hostname override blocked by auto-generated wildcad…
zirain 4b72902
feat/mtls add ClientValidationMode (#8325)
Julien-Beezeelinx c11f0c2
fix(tcp): add SNI-based filter chain matching for TLS passthrough emp…
OliverBailey 205e455
ci: fix netlify build (#8571)
zirain dd0c09f
feat: upstream access log (#8397)
zirain 674f13b
chore: refactor JSONPatch (#8497)
zirain 1005160
docs: fix terminology inconsistencies for External Authorization (#8539)
haruyama480 c4db7cf
docs: ignore blog.envoyproxy.io (#8574)
zirain ef8f744
feat(loadbalancer): Add LoadBalancerType Client Side Weighted Round R…
altaiezior 12de3c5
build(deps): bump loki from 6.54.0 to 6.55.0 in /charts/gateway-addon…
dependabot[bot] e633c08
fix bug with grpcroute mirror filter (#8541)
aburanrbx 9cac348
fix: normalize CRLF line endings in htpasswd basic auth secrets (#8557)
stekole a049df2
build(deps): bump the gomod group across 5 directories with 6 updates…
dependabot[bot] d640a6d
chore: update release schedule (#8584)
zhaohuabing 3c2fc03
feat: GeoIP (#8453)
zhaohuabing 2de2611
Bump version (#8587)
jukie a5535c4
chore: update grpc to fix osv scan (#8586)
zhaohuabing b8392b2
build(deps): bump busybox from `b3255e7` to `1487d0a` in /tools/docke…
dependabot[bot] 485decc
build(deps): bump the actions group across 1 directory with 2 updates…
dependabot[bot] 18b3fcb
build(deps): bump the gomod group across 1 directory with 2 updates (…
dependabot[bot] d35bf70
build(deps): bump the helm group across 1 directory with 3 updates (#…
dependabot[bot] 4aa6c37
build(deps): bump the k8s-io group across 1 directory with 6 updates …
dependabot[bot] 80b2762
[xds] stabilize listener-level Lua XDS filters to avoid listener drai…
arkodg df99196
docs: fix typos in RELEASING.md (#8601)
archy-rock3t-cloud 69b91e9
chore: update basic auth error status (#8589)
zhaohuabing 7bff34c
chore: update request buffer docs (#8604)
zhaohuabing 703a3b4
docs: add note on case-insensitivity of header names (#8596)
lextiz fae7f19
Add Pollinate to Envoy Gateway adopters (#8607)
shavmohin b1d7302
fix: reject incompatible requestBuffer + httpUpgrade CTP (#8605)
zhaohuabing 945fe9f
geoip docs (#8585)
zhaohuabing 99bc7ef
chore: update Performance Benchmark Report (#8613)
zhaohuabing 4f300b7
feat: support invert in source match (#8407)
rudrakhp 41d15ba
chore: fix osv scan (#8615)
zhaohuabing 4768ca7
fix json report (#8614)
zhaohuabing b4c15b7
chore: add benchmark report to the release process (#8617)
zhaohuabing 47a167a
feat: implement remote source dynamic modules (#8579)
jukie f4aef87
chore: fix e2e tests (#8450)
zirain 91f46ae
feat: JSON log encoder uses abbreviated field keys (#8555)
zirain c86eb78
test: add unit tests for route sort precedence (#8603)
archy-rock3t-cloud dc8e6fc
feat(translator): make append_x_forwarded_host configurable in HTTPRo…
rborale5 7a2a4ec
fix: avoid metric increments on no-op delete reconcile paths (#8480)
felipesabadini fdc3128
chore: cswrr cleanup and e2e (#8582)
jukie 87b8d14
chore: add make target for benchmark dashboard (#8621)
zhaohuabing 4dcb964
feat(telemetry): add sampler config for OpenTelemetry tracing (#8529)
codefromthecrypt 990e720
feat(ctp): add IgnoredUpgradeTypes to HTTP1Settings (#8599)
michalskalski 9c7a9d7
build(deps): bump npm-check-updates from 19.6.6 to 20.0.0 in /site (#…
dependabot[bot] 2b265ab
chore: fix metrics check in the rate limit e2e tests (#8636)
zhaohuabing 304e38b
build(deps): bump the gomod group across 1 directory with 2 updates (…
dependabot[bot] e5e1dfe
build(deps): bump the actions group across 2 directories with 7 updat…
dependabot[bot] f5905b3
enterprise support: Add Procedure Technologies (#8643)
harshita375 a0cd31f
fix typo (#8629)
Alireza-Mim c773478
build(deps): bump the helm group across 1 directory with 2 updates (#…
dependabot[bot] 8986e16
chore: bump API version (#8644)
zirain ac18feb
fix(telemetry): support BackendTLSPolicy for telemetry backends (#8545)
codefromthecrypt dd79a83
ci(fix): ensure Go binaries in published Docker images have correct m…
shahar-h 2a5bfd0
fix: restore failure-path metric recording for delete and HPA reconci…
felipesabadini f1fedb1
fix for duplicate cidr local rate limit rules (#8650)
erik-hunter 77965c3
feat: impl gateway tls.frontend/tls.backend (#8380)
zirain 2bbe061
docs: fix `Protol` -> `Protocol` typo (#8657)
wiktor-k b4b5cab
chore: remove cluster.LbPolicy usage (#8637)
jukie e802fd4
chore: align all helm calls to use go tool (#8659)
shahar-h e8dd1a5
ci: remove codecov workaround (#8664)
shahar-h 66958e2
ci: remove hardcoded KIND_NODE_TAG from release benchmark (#8661)
shahar-h 2620fea
chore: add lint check to enforce ubuntu-latest in workflow runs-on (#…
shahar-h 6d06f23
Publish chart and docker image for rc.0 tags (#8658)
jukie d35803f
ci: fix broken go-benchmark-test (#8663)
shahar-h 17ff01a
chore: fix cve (#8669)
zirain b64158c
ci: remove continue-on-error from go-benchmark-test (#8670)
shahar-h 3644512
ci: pin checkout action (#8674)
shahar-h eae5a7d
docs: clarify supported HTTP redirect status codes (#8566)
Aditya7880900936 76f79f5
feat: support grpc stats settings (#8158)
kkk777-7 42e3999
Fix link to Tasks section in quickstart.md (#8618)
xCyberxx 2ecab60
chore: pin npm tools (#8672)
shahar-h fa81778
fix: status for mirror backend (#8675)
kkk777-7 3352b2a
ci: add github action for codex review on PRs (#8679)
arkodg 10dbf34
build(deps): bump the actions group across 1 directory with 2 updates…
dependabot[bot] b35a84f
build(deps): bump sigs.k8s.io/mcs-api from 0.4.0 to 0.4.1 (#8683)
dependabot[bot] c8376fb
build(deps): bump the helm group across 1 directory with 2 updates (#…
dependabot[bot] 3b4de6d
fix(gatewayapi): add deprecated warning for clientValidation.optional…
officialasishkumar 0e26106
feat: add support for contrpl plane tracer (#8551)
zirain c3d06fa
build(deps): bump the gomod group across 5 directories with 11 update…
dependabot[bot] ee3091a
api: dynamic module lb (#8638)
jukie 6524e19
build(deps): bump actions/checkout from 6.0.1 to 6.0.2 in the actions…
dependabot[bot] da22db2
build(deps): bump the gomod group across 2 directories with 4 updates…
dependabot[bot] 082b038
build(deps): bump the helm group across 1 directory with 2 updates (#…
dependabot[bot] c7e21fa
fix: client certificate secret never delivered when it is exclusively…
zirain 9d84fa8
bump golang for CVE (#8709)
zirain 828cd01
set the status when EPP target to a MergeGateways with wrong kind (#7…
fabian4 f404a9c
chore: update testdata to covered multiple listener in one gateway (#…
zirain 40b3dbf
fix: disable http3 when client tls is configured (#8583)
zhaohuabing 95c3a79
fix: client certificate secret never delivered when it is exclusively…
zirain bd5f162
chore: fix release issue gen (#8722)
rudrakhp 8d2f190
remove DFP filter (#8655)
zhaohuabing 52bafc6
build(deps): bump the gomod group across 1 directory with 2 updates (…
dependabot[bot] 1595743
api for id token forwarding (#8691)
zhaohuabing 0a81122
oidc: native oauth2 per-route config (#8703)
zhaohuabing ad6da44
chore: add review skill (#8237)
zhaohuabing d030772
feat: Support for merged EnvoyProxy settings (#8169)
mgs255 8e858e5
[ci] rm codex review action (#8726)
arkodg bbdb718
build(site): use npm ci and clean up docs CI pipeline (#8694)
shahar-h 9f25066
fix: followup for #8380 (#8666)
zirain 66c746e
chore: fix release issue WF (#8727)
rudrakhp d938c3c
docs: rename Contributions section to Community (#8427)
antonio-mazzini fa31928
chore: update Go tools and resolve golangci-lint warnings (#8740)
shahar-h 8e813bd
refactor: replace ptr.To with Go 1.26 new() builtin (#8718)
shahar-h beb9fec
fix: ContextExtensions merge behavior (#8747)
zhaohuabing c48a346
fix: helm secrets rbac for gateway namespace with watch list of names…
cnvergence a62230e
build(deps): bump the actions group across 1 directory with 3 updates…
dependabot[bot] faf7a99
build(deps-dev): bump autoprefixer from 10.4.27 to 10.5.0 in /site (#…
dependabot[bot] 1baf309
build(deps): bump npm-check-updates from 20.0.0 to 21.0.0 in /site (#…
dependabot[bot] e2aa3e6
build(deps): bump the helm group across 1 directory with 3 updates (#…
dependabot[bot] 8dc1846
[release/v1.6] add release notes for v1.6.6 (#8765)
rudrakhp 12a3e6d
ExtAuth: allow passing Route metadata to Ext Auth (#8723)
zhaohuabing 8c5b67f
[release/v1.6] add benchmark report for v1.6.6 (#8772)
rudrakhp 4747557
[release/v1.6] update docs + release announcement for v1.6.6 (#8774)
rudrakhp 7d2267e
docs: fix typo in page for http-request-headers (#8752)
picccard e777f63
[release/v1.7] add release notes and docs announcement for v1.7.2 (#8…
cnvergence 7b606c9
[release/v1.7] add benchmark report for v1.7.2 (#8779)
cnvergence 5ed1c4c
ci: optimize binary builds in build_and_test workflow (#8777)
shahar-h a3b541c
feat: support GatewayStaticAddresses conformance test (#8395)
cnvergence d80fb5b
Fix rc.0 publish (#8782)
jukie 3f70a89
fix: deep copy status in translator layer to avoid race (#8778)
rudrakhp c97626e
feat: add per-rule XRateLimitOption to BackendTrafficPolicy (#8742)
zirain 56cc3f7
chore: add missing labels for the rl service account (#8793)
zhaohuabing 28033f9
chore: OSV scanner (#8794)
zirain a7545ce
fix: bound BackendTrafficPolicy rateLimit requests to uint32 max (#8798)
PatilHrushikesh 85e62dd
fix: use per-route ratelimit filter (#8741)
zirain a056d44
feat: add extraEnv support to envoy-gateway controller deployment (#8…
girikuncoro 00d0895
api: add cel validation of MaxEjectionPercent (#8804)
kkk777-7 7633125
fix: force HTTP1 for upstream connections for WS and WSS backends (#8…
zhaohuabing e5af3e0
build(deps): bump the gomod group across 2 directories with 4 updates…
dependabot[bot] 7e41346
build(deps): bump the actions group across 1 directory with 2 updates…
dependabot[bot] f4a212e
chore: fix race and panic (#8795)
zirain b8eb202
build(deps): bump npm-check-updates from 21.0.0 to 21.0.3 in /site (#…
dependabot[bot] f33ec41
build(deps): bump sigs.k8s.io/gateway-api-inference-extension from 1.…
dependabot[bot] 028ce99
build(deps): bump opentelemetry-collector from 0.150.0 to 0.150.1 in …
dependabot[bot] 30fa914
feat: add support for certificate fetching via SDS ref secret (#8745)
zirain c050634
docs: note ETag handling in response compression task (#8824)
alliasgher 669d714
chore: bump docsy (#8819)
zirain 7b14b5b
build(deps): bump aquasecurity/trivy-action from 0.35.0 to 0.36.0 in …
dependabot[bot] 9d919e5
fix: correct duration dashboard panels to use proper PromQL queries (…
felipesabadini f394346
test: use registry.k8s.io instead of staging (#8831)
jukie 78380e4
feat: Add BackendUtilization + WeightedZones support (WrrLocality Lb …
jukie 18bd6c5
build(deps): bump opentelemetry-collector from 0.150.1 to 0.152.0 in …
dependabot[bot] c8573c4
docs(cors): show allowCredentials in the CORS task (#8611)
officialasishkumar 874d43f
Add support for extraVolumes and extraVolumeMounts to EG deployment (…
mkhpalm b47bc2b
api: add cel validation of GrpcStatus (#8803)
kkk777-7 63c5b5b
conformance: update skipped features (#8837)
zirain cab6837
e2e: add test for watched namespace (#8786)
zhaohuabing 30cdc61
performance: use cached kube client for the infra runner (#8764)
zhaohuabing e098718
api: add bandwidth limit (#8630)
kkk777-7 7811d86
fix: reason with multiple errors rejected validation (#8859)
zirain dd203e5
feat: support overriding ext_auth path (#8612)
rudrakhp 99fbb76
[release/v1.6] update docs for v1.6.7 (#8865)
rudrakhp 8570285
feat(chart): Allow configuring envoy proxy image via helm chart (#8785)
mgs255 6b8ac52
[release/v1.6] add v1.6.7 benchmark data (#8874)
rudrakhp c68d38c
feat(extensionManager): add support for multiple ExtensionManagers wi…
toffentoffen 65d0663
[release/v1.6] bump v1.6 in docs to v1.6.7 (#8875)
rudrakhp de1ae65
chore: update api docs for the default EnvoyProxy (#8866)
zhaohuabing 6774309
feat: bandwidth limit (#8862)
kkk777-7 6e1fd5b
fix: dpanic in logger (#8880)
rudrakhp c16ddd3
feat: Add source to responseOverride (#8391)
lboynton d48292b
build(deps): bump npm-check-updates from 21.0.3 to 22.0.1 in /site (#…
dependabot[bot] 4628260
build(deps): bump go.uber.org/zap from 1.27.1 to 1.28.0 (#8884)
dependabot[bot] b966472
build(deps): bump the helm group across 1 directory with 4 updates (#…
dependabot[bot] 56f4976
chore: update JSONPatch testdata (#8877)
zirain bef5ed1
feat: cross ns policy attachment (#8676)
zhaohuabing 8fa767a
feat: add admission control to BackendTrafficPolicy (#8872)
jukie File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,55 @@ | ||
| --- | ||
| name: review-envoy-gateway-pr | ||
| description: Review an Envoy Gateway pull request for essential API, implementation, status, and test coverage requirements. | ||
| metadata: | ||
| short-description: Envoy Gateway PR review workflow | ||
| version: "0.1" | ||
| --- | ||
|
|
||
| # Envoy Gateway PR Review Skill | ||
|
|
||
| ## Inputs | ||
| - GitHub PR URL (e.g. review PR: https://github.com/envoyproxy/gateway/pull/8237), or | ||
| - A local diff between commits (e.g. review change: git diff 4927877a HEAD) | ||
|
|
||
| ## Output | ||
| - Lead with findings ordered by severity. | ||
| - Include exact file and line references. | ||
| - Separate required fixes from optional follow-ups. | ||
| - If there are no findings, say that clearly and mention residual test or release-note risk. | ||
|
|
||
| ## Review | ||
| - Check API changes, implementation changes, feature coverage, and release notes as applicable. | ||
| - Keep findings concise and actionable, with file references when possible. | ||
|
|
||
| ## Checklist | ||
|
|
||
| ### API changes | ||
| - Make sure changes under `api/` align with https://github.com/kubernetes/community/blob/master/contributors/devel/sig-architecture/api-conventions.md | ||
| - Make sure changes under `api/` are consistent with existing API patterns in the Gateway API project: https://github.com/kubernetes-sigs/gateway-api/tree/main/apis | ||
| - Make sure changes under `api/` are consistent with existing API patterns in this project. | ||
| - Try to reuse existing types. | ||
| - Keep naming consistent with this project. | ||
| - Try to add kubebuilder and CEL validations to catch errors. | ||
| - Make sure API validations are tested in `/test/cel-validation`. | ||
| - Check backward compatibility for API shape, CRD schema, defaults, versioned structs, and upgrade behavior. | ||
| - If a PR mixes API and implementation changes, say whether it should be split into separate PRs. | ||
|
|
||
| ### Implementation changes | ||
| - For changes under `internal/gatewayapi`, check that user-visible errors are surfaced in status. | ||
| - For changes under `internal/gatewayapi`, check that status conditions follow the conventions in the Gateway API spec: https://gateway-api.sigs.k8s.io/geps/gep-1364/index.html | ||
| - For changes under `internal/gatewayapi`, check that `internal/gatewayapi/testdata` has coverage. | ||
| - For changes under `internal/xds/translator`, check that `internal/xds/translator/testdata` has coverage. | ||
|
|
||
| ### Feature coverage | ||
| - For new user-facing features, check that `test/e2e` has coverage. | ||
| - For bug fixes, check that `test/e2e` has coverage if the bug is in user-facing code or has user-facing impact. | ||
|
|
||
| ### Release notes | ||
| Release notes should be added to `release-notes/current.yaml` for any of the following changes: | ||
| - Bug fixes should be noted as "bug fix" and include a brief description of the issue and the fix. | ||
| - New features should be noted as "new feature" and include a brief description of the feature. | ||
| - Any breaking changes should be noted as "breaking change" and include a clear description of the change and its impact on users. | ||
| - Any change to generated Envoy config (xDS) that moves, removes, or modifies existing config content would break EnvoyPatchPolicies and Extension Servers, so it should be noted as a breaking change. Additions to generated xDS config do not need to be called out. | ||
| - Existing API changes should be noted. | ||
| - Existing behavior changes should be noted. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Setting
use_oidc: trueunconditionally makes the Codecov step depend on an OIDC token for everypull_requestrun. Forked PR workflows typically cannot rely on that token path, so withfail_ci_if_error: truethis can fail the entirecoverage-testjob for external contributors even when tests pass. The previous conditional guarded this exact case; restoring a fork-aware condition avoids blocking community PRs.Useful? React with 👍 / 👎.