Skip to content

chore(deps): update helm release cilium to v1.20.1 - #360

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/cilium-1.x
Open

chore(deps): update helm release cilium to v1.20.1#360
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/cilium-1.x

Conversation

@renovate

@renovate renovate Bot commented Jun 24, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
cilium (source) minor 1.19.71.20.1

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

cilium/cilium (cilium)

v1.20.1: 1.20.1

Compare Source

Summary of Changes

Major Changes:

  • docs/clustermesh: overhaul Cluster Mesh documentation with a new introduction, improved load-balancing guidance, and Helm-first setup and certificate configuration instructions (Backport PR #​47615, Upstream PR #​47351, @​MrFreezeex)

Minor Changes:

Bugfixes:

CI Changes:

Misc Changes:

Other Changes:

Docker Manifests

cilium

quay.io/cilium/cilium:v1.20.1@sha256:ae9ea21f7427fe24bc6ea7247eb552157a1b0a431744045d3f641545ca71d11b
quay.io/cilium/cilium:stable@sha256:ae9ea21f7427fe24bc6ea7247eb552157a1b0a431744045d3f641545ca71d11b

clustermesh-apiserver

quay.io/cilium/clustermesh-apiserver:v1.20.1@sha256:d905d614a332b2058cb81c193e481d1f460902b903f4eb57cc9764640b750fb5
quay.io/cilium/clustermesh-apiserver:stable@sha256:d905d614a332b2058cb81c193e481d1f460902b903f4eb57cc9764640b750fb5

hubble-relay

quay.io/cilium/hubble-relay:v1.20.1@sha256:59be0ae7d475ab9011a5e954618c0f27b5778b17140381425b308b55ba4917f4
quay.io/cilium/hubble-relay:stable@sha256:59be0ae7d475ab9011a5e954618c0f27b5778b17140381425b308b55ba4917f4

operator-alibabacloud

quay.io/cilium/operator-alibabacloud:v1.20.1@sha256:2af5dd3d85649ea36d365363b8eca82ad06116c6259c4aace700a7c036348e4c
quay.io/cilium/operator-alibabacloud:stable@sha256:2af5dd3d85649ea36d365363b8eca82ad06116c6259c4aace700a7c036348e4c

operator-aws

quay.io/cilium/operator-aws:v1.20.1@sha256:7cf0cb0e6584f72ca8de951a1be03829f69fcaeba69dc6c7856fc4470545acd7
quay.io/cilium/operator-aws:stable@sha256:7cf0cb0e6584f72ca8de951a1be03829f69fcaeba69dc6c7856fc4470545acd7

operator-azure

quay.io/cilium/operator-azure:v1.20.1@sha256:13746a479ca60395df8d83580b49464c6c975cca6fdb21ba4791a076ab01b031
quay.io/cilium/operator-azure:stable@sha256:13746a479ca60395df8d83580b49464c6c975cca6fdb21ba4791a076ab01b031

operator-generic

quay.io/cilium/operator-generic:v1.20.1@sha256:6c3885fc7b629099fdbe2a5c87869c86feb825fa18fae299eac0f61918d16ecf
quay.io/cilium/operator-generic:stable@sha256:6c3885fc7b629099fdbe2a5c87869c86feb825fa18fae299eac0f61918d16ecf

operator

quay.io/cilium/operator:v1.20.1@sha256:67adaf5575902dcce31dc36ba5b5acad397a8b40ec986b55696c94f80b6d861d
quay.io/cilium/operator:stable@sha256:67adaf5575902dcce31dc36ba5b5acad397a8b40ec986b55696c94f80b6d861d

v1.20.0: 1.20.0

Compare Source

🎉 Release Announcement 🎉: We are excited to announce the Cilium 1.20.0 release!

More than 2,660 new commits have landed in this release, supported by a community of over 1,100 contributors and more than 24,800 GitHub stars! 🤩

⚠️ You may need to take action during the upgrade if you use legacy Mutual Authentication, Envoy Go extensions or Kafka-aware policies, the cilium.io/v2alpha1 CiliumNodeConfig API, the libnetwork integration, or a custom CNI configuration. See the Upgrade Guide for details.

The full changelog can be found here.

Here are some of the highlights:

❤️ Thank You: Cilium 1.20 was made possible by contributors, reviewers and maintainers from across the community, including engineers from Datadog, Google, Microsoft and many other organizations.

To keep up to date with all the latest Cilium releases, join #release 🎉

Docker Manifests

cilium

quay.io/cilium/cilium:v1.20.0@sha256:383968cd5e8873f7976fa76aa6196045643558f4cc9518a207b9335cb24a0e93
quay.io/cilium/cilium:stable@sha256:383968cd5e8873f7976fa76aa6196045643558f4cc9518a207b9335cb24a0e93

clustermesh-apiserver

quay.io/cilium/clustermesh-apiserver:v1.20.0@sha256:c791d0c334d4515d40041b2660d50a1b94b0179ef1d3c120bd350aebc9115e92
quay.io/cilium/clustermesh-apiserver:stable@sha256:c791d0c334d4515d40041b2660d50a1b94b0179ef1d3c120bd350aebc9115e92

hubble-relay

quay.io/cilium/hubble-relay:v1.20.0@sha256:2ca16981c7eb98df0ba9c9d18896bb9ca628b5cbd40dc9801339f4741f91ee94
quay.io/cilium/hubble-relay:stable@sha256:2ca16981c7eb98df0ba9c9d18896bb9ca628b5cbd40dc9801339f4741f91ee94

operator-alibabacloud

quay.io/cilium/operator-alibabacloud:v1.20.0@sha256:52535dba067abf5b1cce2a666ee3f9430a1682ade3bf11db5f118436e84ad2e9
quay.io/cilium/operator-alibabacloud:stable@sha256:52535dba067abf5b1cce2a666ee3f9430a1682ade3bf11db5f118436e84ad2e9

operator-aws

quay.io/cilium/operator-aws:v1.20.0@sha256:a0e50fa611fa3e2e8b1c9521a3e813576034a0b3d626e9c128ac01f8f7dfd0fa
quay.io/cilium/operator-aws:stable@sha256:a0e50fa611fa3e2e8b1c9521a3e813576034a0b3d626e9c128ac01f8f7dfd0fa

operator-azure

quay.io/cilium/operator-azure:v1.20.0@sha256:4506f8d0c9f2dd187313f71b37a789986c1c1699f59c52973941df9eb5ccae0c
quay.io/cilium/operator-azure:stable@sha256:4506f8d0c9f2dd187313f71b37a789986c1c1699f59c52973941df9eb5ccae0c

operator-generic

quay.io/cilium/operator-generic:v1.20.0@sha256:80744a8cc7c91c2f9e6347629406844eb35d79b30a732c6d41c15b17232a74f3
quay.io/cilium/operator-generic:stable@sha256:80744a8cc7c91c2f9e6347629406844eb35d79b30a732c6d41c15b17232a74f3

operator

quay.io/cilium/operator:v1.20.0@sha256:5dc67f7a0f1ad0f51813563366885cd8d4ee255cc49a65be5cf45d5e9810d58c
quay.io/cilium/operator:stable@sha256:5dc67f7a0f1ad0f51813563366885cd8d4ee255cc49a65be5cf45d5e9810d58c


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions

github-actions Bot commented Jun 24, 2026

Copy link
Copy Markdown
Contributor

✅ Dry-run — turing

omnictl template sync

(no output)

helmfile diff

Adding repo cilium https://helm.cilium.io/
"cilium" has been added to your repositories

Comparing release=cilium, chart=cilium/cilium, namespace=kube-system
cilium-secrets, cilium-operator-tlsinterception-secrets, Role (rbac.authorization.k8s.io) has changed:
  # Source: cilium/templates/cilium-operator/role.yaml
  apiVersion: rbac.authorization.k8s.io/v1
  kind: Role
  metadata:
    name: cilium-operator-tlsinterception-secrets
    namespace: "cilium-secrets"
    labels:
      app.kubernetes.io/part-of: cilium
+     helm.sh/chart: cilium-1.20.1
  rules:
  - apiGroups:
    - ""
    resources:
    - secrets
    verbs:
    - create
    - delete
    - update
    - patch
cilium-secrets, cilium-operator-tlsinterception-secrets, RoleBinding (rbac.authorization.k8s.io) has changed:
  # Source: cilium/templates/cilium-operator/rolebinding.yaml
  apiVersion: rbac.authorization.k8s.io/v1
  kind: RoleBinding
  metadata:
    name: cilium-operator-tlsinterception-secrets
    namespace: "cilium-secrets"
    labels:
      app.kubernetes.io/part-of: cilium
+     helm.sh/chart: cilium-1.20.1
  roleRef:
    apiGroup: rbac.authorization.k8s.io
    kind: Role
    name: cilium-operator-tlsinterception-secrets
  subjects:
  - kind: ServiceAccount
    name: "cilium-operator"
    namespace: kube-system
cilium-secrets, cilium-tlsinterception-secrets, Role (rbac.authorization.k8s.io) has changed:
  # Source: cilium/templates/cilium-agent/role.yaml
  apiVersion: rbac.authorization.k8s.io/v1
  kind: Role
  metadata:
    name: cilium-tlsinterception-secrets
    namespace: "cilium-secrets"
    labels:
      app.kubernetes.io/part-of: cilium
+     helm.sh/chart: cilium-1.20.1
  rules:
  - apiGroups:
    - ""
    resources:
    - secrets
    verbs:
    - get
    - list
    - watch
cilium-secrets, cilium-tlsinterception-secrets, RoleBinding (rbac.authorization.k8s.io) has changed:
  # Source: cilium/templates/cilium-agent/rolebinding.yaml
  apiVersion: rbac.authorization.k8s.io/v1
  kind: RoleBinding
  metadata:
    name: cilium-tlsinterception-secrets
    namespace: "cilium-secrets"
    labels:
      app.kubernetes.io/part-of: cilium
+     helm.sh/chart: cilium-1.20.1
  roleRef:
    apiGroup: rbac.authorization.k8s.io
    kind: Role
    name: cilium-tlsinterception-secrets
  subjects:
  - kind: ServiceAccount
    name: "cilium"
    namespace: kube-system
kube-system, cilium, ClusterRole (rbac.authorization.k8s.io) has changed:
  # Source: cilium/templates/cilium-agent/clusterrole.yaml
  apiVersion: rbac.authorization.k8s.io/v1
  kind: ClusterRole
  metadata:
    name: cilium
    labels:
      app.kubernetes.io/part-of: cilium
+     helm.sh/chart: cilium-1.20.1
  rules:
  - apiGroups:
    - networking.k8s.io
    resources:
    - networkpolicies
    verbs:
    - get
    - list
    - watch
  - apiGroups:
    - discovery.k8s.io
    resources:
    - endpointslices
    verbs:
    - get
    - list
    - watch
  - apiGroups:
    - ""
    resources:
    - namespaces
    - services
    - pods
-   - endpoints
    - nodes
    verbs:
    - get
    - list
    - watch
  - apiGroups:
    - coordination.k8s.io
    resources:
    - leases
    verbs:
    - create
    - get
    - update
    - list
    - delete
  - apiGroups:
    - apiextensions.k8s.io
    resources:
    - customresourcedefinitions
    verbs:
    - list
    - watch
    # This is used when validating policies in preflight. This will need to stay
    # until we figure out how to avoid "get" inside the preflight, and then
    # should be removed ideally.
    - get
  - apiGroups:
    - cilium.io
    resources:
    - ciliumloadbalancerippools
-   - ciliumbgppeeringpolicies
    - ciliumbgpnodeconfigs
    - ciliumbgpadvertisements
    - ciliumbgppeerconfigs
    - ciliumclusterwideenvoyconfigs
    - ciliumclusterwidenetworkpolicies
    - ciliumegressgatewaypolicies
    - ciliumendpoints
    - ciliumendpointslices
    - ciliumenvoyconfigs
    - ciliumidentities
    - ciliumlocalredirectpolicies
    - ciliumnetworkpolicies
    - ciliumnodes
    - ciliumnodeconfigs
    - ciliumcidrgroups
    - ciliuml2announcementpolicies
    - ciliumpodippools
+   - ciliumdatapathplugins
    verbs:
    - list
    - watch
  - apiGroups:
    - cilium.io
    resources:
    - ciliumidentities
    - ciliumendpoints
    - ciliumnodes
    verbs:
    - create
  - apiGroups:
    - cilium.io
    # To synchronize garbage collection of such resources
    resources:
    - ciliumidentities
    verbs:
    - update
  - apiGroups:
    - cilium.io
    resources:
    - ciliumendpoints
    verbs:
    - delete
    - get
  - apiGroups:
    - cilium.io
    resources:
    - ciliumnodes
    - ciliumnodes/status
    verbs:
    - get
    - update
  - apiGroups:
    - cilium.io
    resources:
    - ciliumendpoints/status
    - ciliumendpoints
    - ciliuml2announcementpolicies/status
    - ciliumbgpnodeconfigs/status
    verbs:
    - patch
kube-system, cilium, ClusterRoleBinding (rbac.authorization.k8s.io) has changed:
  # Source: cilium/templates/cilium-agent/clusterrolebinding.yaml
  apiVersion: rbac.authorization.k8s.io/v1
  kind: ClusterRoleBinding
  metadata:
    name: cilium
    labels:
      app.kubernetes.io/part-of: cilium
+     helm.sh/chart: cilium-1.20.1
  roleRef:
    apiGroup: rbac.authorization.k8s.io
    kind: ClusterRole
    name: cilium
  subjects:
  - kind: ServiceAccount
    name: "cilium"
    namespace: kube-system
kube-system, cilium, DaemonSet (apps) has changed:
  # Source: cilium/templates/cilium-agent/daemonset.yaml
  apiVersion: apps/v1
  kind: DaemonSet
  metadata:
    name: cilium
    namespace: kube-system
    labels:
      k8s-app: cilium
      app.kubernetes.io/part-of: cilium
      app.kubernetes.io/name: cilium-agent
+     helm.sh/chart: cilium-1.20.1
  spec:
    selector:
      matchLabels:
        k8s-app: cilium
    updateStrategy:
      rollingUpdate:
        maxUnavailable: 2
      type: RollingUpdate
    template:
      metadata:
        annotations:
          kubectl.kubernetes.io/default-container: cilium-agent
        labels:
          k8s-app: cilium
          app.kubernetes.io/name: cilium-agent
          app.kubernetes.io/part-of: cilium
+         helm.sh/chart: cilium-1.20.1
      spec:
        securityContext:
          appArmorProfile:
            type: Unconfined
          seccompProfile:
            type: Unconfined
        containers:
        - name: cilium-agent
-         image: "quay.io/cilium/cilium:v1.19.7@sha256:1b58bcb81c723cf130a0dd2fb2e1132c57f8fbc2ef7bdb85519cfcc36111c77e"
+         image: "quay.io/cilium/cilium:v1.20.1@sha256:ae9ea21f7427fe24bc6ea7247eb552157a1b0a431744045d3f641545ca71d11b"
          imagePullPolicy: IfNotPresent
          command:
          - cilium-agent
          args:
          - --config-dir=/tmp/cilium/config-map
          startupProbe:
            httpGet:
              host: "127.0.0.1"
              path: /healthz
              port: health
              scheme: HTTP
              httpHeaders:
              - name: "brief"
                value: "true"
            failureThreshold: 300
            periodSeconds: 2
            successThreshold: 1
            initialDelaySeconds: 5
          livenessProbe:
            httpGet:
              host: "127.0.0.1"
              path: /healthz
              port: health
              scheme: HTTP
              httpHeaders:
              - name: "brief"
                value: "true"
              - name: "require-k8s-connectivity"
                value: "false"
            periodSeconds: 30
            successThreshold: 1
            failureThreshold: 10
            timeoutSeconds: 5
          readinessProbe:
            httpGet:
              host: "127.0.0.1"
              path: /healthz
              port: health
              scheme: HTTP
              httpHeaders:
              - name: "brief"
                value: "true"
            periodSeconds: 30
            successThreshold: 1
            failureThreshold: 3
            timeoutSeconds: 5
          env:
          - name: K8S_NODE_NAME
            valueFrom:
              fieldRef:
                apiVersion: v1
                fieldPath: spec.nodeName
          - name: CILIUM_K8S_NAMESPACE
            valueFrom:
              fieldRef:
                apiVersion: v1
                fieldPath: metadata.namespace
          - name: CILIUM_CLUSTERMESH_CONFIG
            value: /var/lib/cilium/clustermesh/
          - name: GOMEMLIMIT
            valueFrom:
              resourceFieldRef:
                resource: limits.memory
                divisor: '1'
          - name: KUBE_CLIENT_BACKOFF_BASE
            value: "1"
          - name: KUBE_CLIENT_BACKOFF_DURATION
            value: "120"
          lifecycle:
            postStart:
              exec:
                command:
                - "bash"
                - "-c"
                - |
                      set -o errexit
                      set -o pipefail
                      set -o nounset
                      
                      # When running in AWS ENI mode, it's likely that 'aws-node' has
                      # had a chance to install SNAT iptables rules. These can result
                      # in dropped traffic, so we should attempt to remove them.
                      # We do it using a 'postStart' hook since this may need to run
                      # for nodes which might have already been init'ed but may still
                      # have dangling rules. This is safe because there are no
                      # dependencies on anything that is part of the startup script
                      # itself, and can be safely run multiple times per node (e.g. in
                      # case of a restart).
                      if [[ "$(iptables-save | grep -E -c 'AWS-SNAT-CHAIN|AWS-CONNMARK-CHAIN')" != "0" ]];
                      then
                          echo 'Deleting iptables rules created by the AWS CNI VPC plugin'
                          iptables-save | grep -E -v 'AWS-SNAT-CHAIN|AWS-CONNMARK-CHAIN' | iptables-restore
                      fi
                      echo 'Done!'
                      
            preStop:
              exec:
                command:
                - /cni-uninstall.sh
          ports:
          - name: health
            containerPort: 9879
            hostPort: 9879
            protocol: TCP
          - name: peer-service
            containerPort: 4244
            hostPort: 4244
            protocol: TCP
          securityContext:
            seLinuxOptions:
              level: s0
              type: spc_t
            capabilities:
              add:
                - CHOWN
                - KILL
                - NET_ADMIN
                - NET_RAW
                - IPC_LOCK
                - SYS_ADMIN
                - SYS_RESOURCE
                - DAC_OVERRIDE
                - FOWNER
                - SETGID
                - SETUID
              drop:
                - ALL
          terminationMessagePolicy: FallbackToLogsOnError
          volumeMounts:
          - name: envoy-sockets
            mountPath: /var/run/cilium/envoy/sockets
            readOnly: false
          # Unprivileged containers need to mount /proc/sys/net from the host
          # to have write access
          - mountPath: /host/proc/sys/net
            name: host-proc-sys-net
          # Unprivileged containers need to mount /proc/sys/kernel from the host
          # to have write access
          - mountPath: /host/proc/sys/kernel
            name: host-proc-sys-kernel
          - name: bpf-maps
            mountPath: /sys/fs/bpf
            # Unprivileged containers can't set mount propagation to bidirectional
            # in this case we will mount the bpf fs from an init container that
            # is privileged and set the mount propagation from host to container
            # in Cilium.
            mountPropagation: HostToContainer
          - name: cilium-run
            mountPath: /var/run/cilium
          - name: cilium-netns
            mountPath: /var/run/cilium/netns
            mountPropagation: HostToContainer
          - name: etc-cni-netd
            mountPath: /host/etc/cni/net.d
          - name: clustermesh-secrets
            mountPath: /var/lib/cilium/clustermesh
            readOnly: true
            # Needed to be able to load kernel modules
          - name: lib-modules
            mountPath: /lib/modules
            readOnly: true
          - name: xtables-lock
            mountPath: /run/xtables.lock
          - name: hubble-tls
            mountPath: /var/lib/cilium/tls/hubble
            readOnly: true
          - name: tmp
            mountPath: /tmp
          
        initContainers:
        - name: config
-         image: "quay.io/cilium/cilium:v1.19.7@sha256:1b58bcb81c723cf130a0dd2fb2e1132c57f8fbc2ef7bdb85519cfcc36111c77e"
+         image: "quay.io/cilium/cilium:v1.20.1@sha256:ae9ea21f7427fe24bc6ea7247eb552157a1b0a431744045d3f641545ca71d11b"
          imagePullPolicy: IfNotPresent
          command:
          - cilium-dbg
          - build-config
+         - "--k8s-api-server-urls="
          env:
          - name: K8S_NODE_NAME
            valueFrom:
              fieldRef:
                apiVersion: v1
                fieldPath: spec.nodeName
          - name: CILIUM_K8S_NAMESPACE
            valueFrom:
              fieldRef:
                apiVersion: v1
                fieldPath: metadata.namespace
          volumeMounts:
          - name: tmp
            mountPath: /tmp
          terminationMessagePolicy: FallbackToLogsOnError
          securityContext:
            capabilities:
              add:
                - NET_ADMIN
              drop:
                - ALL
        # Required to mount cgroup2 filesystem on the underlying Kubernetes node.
        # We use nsenter command with host's cgroup and mount namespaces enabled.
        - name: mount-cgroup
-         image: "quay.io/cilium/cilium:v1.19.7@sha256:1b58bcb81c723cf130a0dd2fb2e1132c57f8fbc2ef7bdb85519cfcc36111c77e"
+         image: "quay.io/cilium/cilium:v1.20.1@sha256:ae9ea21f7427fe24bc6ea7247eb552157a1b0a431744045d3f641545ca71d11b"
          imagePullPolicy: IfNotPresent
          env:
          - name: CGROUP_ROOT
            value: /run/cilium/cgroupv2
          - name: BIN_PATH
            value: /opt/cni/bin
          command:
          - bash
          - -ec
          # The statically linked Go program binary is invoked to avoid any
          # dependency on utilities like sh and mount that can be missing on certain
          # distros installed on the underlying host. Copy the binary to the
          # same directory where we install cilium cni plugin so that exec permissions
          # are available.
          - |
            cp /usr/bin/cilium-mount /hostbin/cilium-mount;
            nsenter --cgroup=/hostproc/1/ns/cgroup --mount=/hostproc/1/ns/mnt "${BIN_PATH}/cilium-mount" $CGROUP_ROOT;
            rm /hostbin/cilium-mount
          volumeMounts:
          - name: hostproc
            mountPath: /hostproc
          - name: cni-path
            mountPath: /hostbin
          terminationMessagePolicy: FallbackToLogsOnError
          securityContext:
            seLinuxOptions:
              level: s0
              type: spc_t
            capabilities:
              add:
                - SYS_ADMIN
                - SYS_CHROOT
                - SYS_PTRACE
              drop:
                - ALL
        - name: apply-sysctl-overwrites
-         image: "quay.io/cilium/cilium:v1.19.7@sha256:1b58bcb81c723cf130a0dd2fb2e1132c57f8fbc2ef7bdb85519cfcc36111c77e"
+         image: "quay.io/cilium/cilium:v1.20.1@sha256:ae9ea21f7427fe24bc6ea7247eb552157a1b0a431744045d3f641545ca71d11b"
          imagePullPolicy: IfNotPresent
          env:
          - name: BIN_PATH
            value: /opt/cni/bin
          command:
          - bash
          - -ec
          # The statically linked Go program binary is invoked to avoid any
          # dependency on utilities like sh that can be missing on certain
          # distros installed on the underlying host. Copy the binary to the
          # same directory where we install cilium cni plugin so that exec permissions
          # are available.
          - |
            cp /usr/bin/cilium-sysctlfix /hostbin/cilium-sysctlfix;
            nsenter --mount=/hostproc/1/ns/mnt "${BIN_PATH}/cilium-sysctlfix";
            rm /hostbin/cilium-sysctlfix
          volumeMounts:
          - name: hostproc
            mountPath: /hostproc
          - name: cni-path
            mountPath: /hostbin
          terminationMessagePolicy: FallbackToLogsOnError
          securityContext:
            seLinuxOptions:
              level: s0
              type: spc_t
            capabilities:
              add:
                - SYS_ADMIN
                - SYS_CHROOT
                - SYS_PTRACE
              drop:
                - ALL
        # Mount the bpf fs if it is not mounted. We will perform this task
        # from a privileged container because the mount propagation bidirectional
        # only works from privileged containers.
        - name: mount-bpf-fs
-         image: "quay.io/cilium/cilium:v1.19.7@sha256:1b58bcb81c723cf130a0dd2fb2e1132c57f8fbc2ef7bdb85519cfcc36111c77e"
+         image: "quay.io/cilium/cilium:v1.20.1@sha256:ae9ea21f7427fe24bc6ea7247eb552157a1b0a431744045d3f641545ca71d11b"
          imagePullPolicy: IfNotPresent
          args:
          - 'mount | grep "/sys/fs/bpf type bpf" || mount -t bpf bpf /sys/fs/bpf'
          command:
          - /bin/bash
          - -c
          - --
          terminationMessagePolicy: FallbackToLogsOnError
          securityContext:
            privileged: true
          volumeMounts:
          - name: bpf-maps
            mountPath: /sys/fs/bpf
            mountPropagation: Bidirectional
        - name: clean-cilium-state
-         image: "quay.io/cilium/cilium:v1.19.7@sha256:1b58bcb81c723cf130a0dd2fb2e1132c57f8fbc2ef7bdb85519cfcc36111c77e"
+         image: "quay.io/cilium/cilium:v1.20.1@sha256:ae9ea21f7427fe24bc6ea7247eb552157a1b0a431744045d3f641545ca71d11b"
          imagePullPolicy: IfNotPresent
          command:
          - /init-container.sh
          env:
          - name: CILIUM_ALL_STATE
            valueFrom:
              configMapKeyRef:
                name: cilium-config
                key: clean-cilium-state
                optional: true
          - name: CILIUM_BPF_STATE
            valueFrom:
              configMapKeyRef:
                name: cilium-config
                key: clean-cilium-bpf-state
                optional: true
          - name: WRITE_CNI_CONF_WHEN_READY
            valueFrom:
              configMapKeyRef:
                name: cilium-config
                key: write-cni-conf-when-ready
                optional: true
          terminationMessagePolicy: FallbackToLogsOnError
          securityContext:
            seLinuxOptions:
              level: s0
              type: spc_t
            capabilities:
              add:
                - NET_ADMIN
                - SYS_ADMIN
                - SYS_RESOURCE
              drop:
                - ALL
          volumeMounts:
          - name: bpf-maps
            mountPath: /sys/fs/bpf
            # Required to mount cgroup filesystem from the host to cilium agent pod
          - name: cilium-cgroup
            mountPath: /run/cilium/cgroupv2
            mountPropagation: HostToContainer
          - name: cilium-run
            mountPath: /var/run/cilium # wait-for-kube-proxy
        # Install the CNI binaries in an InitContainer so we don't have a writable host mount in the agent
        - name: install-cni-binaries
-         image: "quay.io/cilium/cilium:v1.19.7@sha256:1b58bcb81c723cf130a0dd2fb2e1132c57f8fbc2ef7bdb85519cfcc36111c77e"
+         image: "quay.io/cilium/cilium:v1.20.1@sha256:ae9ea21f7427fe24bc6ea7247eb552157a1b0a431744045d3f641545ca71d11b"
          imagePullPolicy: IfNotPresent
          command:
            - "/install-plugin.sh"
          resources:
            limits:
              cpu: 1
              memory: 1Gi
            requests:
              cpu: 100m
              memory: 10Mi
          securityContext:
            seLinuxOptions:
              level: s0
              type: spc_t
            capabilities:
              drop:
                - ALL
          terminationMessagePolicy: FallbackToLogsOnError
          volumeMounts:
            - name: cni-path
              mountPath: /host/opt/cni/bin # .Values.cni.install
        restartPolicy: Always
        priorityClassName: system-node-critical
        serviceAccountName: "cilium"
        automountServiceAccountToken: true
        terminationGracePeriodSeconds: 1
        hostNetwork: true
+       hostUsers: true
        
        affinity:
          podAntiAffinity:
            requiredDuringSchedulingIgnoredDuringExecution:
            - labelSelector:
                matchLabels:
                  k8s-app: cilium
              topologyKey: kubernetes.io/hostname
        nodeSelector:
          kubernetes.io/os: linux
        tolerations:
          - operator: Exists
+       
        volumes:
        # For sharing configuration between the "config" initContainer and the agent
        - name: tmp
          emptyDir: {}
          # To keep state between restarts / upgrades
        - name: cilium-run
          hostPath:
            path: /var/run/cilium
            type: DirectoryOrCreate
          # To exec into pod network namespaces
        - name: cilium-netns
          hostPath:
            path: /var/run/netns
            type: DirectoryOrCreate
          # To keep state between restarts / upgrades for bpf maps
        - name: bpf-maps
          hostPath:
            path: /sys/fs/bpf
            type: DirectoryOrCreate
        # To mount cgroup2 filesystem on the host or apply sysctlfix
        - name: hostproc
          hostPath:
            path: /proc
            type: Directory
        # To keep state between restarts / upgrades for cgroup2 filesystem
        - name: cilium-cgroup
          hostPath:
            path: /run/cilium/cgroupv2
            type: DirectoryOrCreate
        # To install cilium cni plugin in the host
        - name: cni-path
          hostPath:
            path:  /opt/cni/bin
            type: DirectoryOrCreate
          # To install cilium cni configuration in the host
        - name: etc-cni-netd
          hostPath:
            path: /etc/cni/net.d
            type: DirectoryOrCreate
          # To be able to load kernel modules
        - name: lib-modules
          hostPath:
            path: /lib/modules
          # To access iptables concurrently with other processes (e.g. kube-proxy)
        - name: xtables-lock
          hostPath:
            path: /run/xtables.lock
            type: FileOrCreate
        # Sharing socket with Cilium Envoy on the same node by using a host path
        - name: envoy-sockets
          hostPath:
            path: "/var/run/cilium/envoy/sockets"
            type: DirectoryOrCreate
          # To read the clustermesh configuration
        - name: clustermesh-secrets
          projected:
            # note: the leading zero means this number is in octal representation: do not remove it
            defaultMode: 0400
            sources:
            - secret:
                name: cilium-clustermesh
                optional: true
                # note: items are not explicitly listed here, since the entries of this secret
                # depend on the peers configured, and that would cause a restart of all agents
                # at every addition/removal. Leaving the field empty makes each secret entry
                # to be automatically projected into the volume as a file whose name is the key.
            - secret:
                name: clustermesh-apiserver-remote-cert
                optional: true
                items:
                - key: tls.key
                  path: common-etcd-client.key
                - key: tls.crt
                  path: common-etcd-client.crt
                - key: ca.crt
                  path: common-etcd-client-ca.crt
            # note: we configure the volume for the kvstoremesh-specific certificate
            # regardless of whether KVStoreMesh is enabled or not, so that it can be
            # automatically mounted in case KVStoreMesh gets subsequently enabled,
            # without requiring an agent restart.
            - secret:
                name: clustermesh-apiserver-local-cert
                optional: true
                items:
                - key: tls.key
                  path: local-etcd-client.key
                - key: tls.crt
                  path: local-etcd-client.crt
                - key: ca.crt
                  path: local-etcd-client-ca.crt
        - name: host-proc-sys-net
          hostPath:
            path: /proc/sys/net
            type: Directory
        - name: host-proc-sys-kernel
          hostPath:
            path: /proc/sys/kernel
            type: Directory
        - name: hubble-tls
          projected:
            # note: the leading zero means this number is in octal representation: do not remove it
            defaultMode: 0400
            sources:
            - secret:
                name: hubble-server-certs
                optional: true
                items:
                - key: tls.crt
                  path: server.crt
                - key: tls.key
                  path: server.key
                - key: ca.crt
                  path: client-ca.crt
kube-system, cilium-config, ConfigMap (v1) has changed:
  # Source: cilium/templates/cilium-configmap.yaml
  apiVersion: v1
  kind: ConfigMap
  metadata:
    name: cilium-config
    namespace: kube-system
  data:

    # Identity allocation mode selects how identities are shared between cilium
    # nodes by setting how they are stored. The options are "crd", "kvstore" or
    # "doublewrite-readkvstore" / "doublewrite-readcrd".
    # - "crd" stores identities in kubernetes as CRDs (custom resource definition).
    #   These can be queried with:
    #     kubectl get ciliumid
    # - "kvstore" stores identities in an etcd kvstore, that is
    #   configured below. Cilium versions before 1.6 supported only the kvstore
    #   backend. Upgrades from these older cilium versions should continue using
    #   the kvstore by commenting out the identity-allocation-mode below, or
    #   setting it to "kvstore".
    # - "doublewrite" modes store identities in both the kvstore and CRDs. This is useful
    #   for seamless migrations from the kvstore mode to the crd mode. Consult the
    #   documentation for more information on how to perform the migration.
    identity-allocation-mode: crd

    identity-heartbeat-timeout: "30m0s"
    identity-gc-interval: "15m0s"
    cilium-endpoint-gc-interval: "5m0s"
    nodes-gc-interval: "5m0s"

    # If you want to run cilium in debug mode change this value to true
    debug: "false"
    debug-verbose: ""
    metrics-sampling-interval: "5m"
    # The agent can be put into the following three policy enforcement modes
    # default, always and never.
    # https://docs.cilium.io/en/latest/security/policy/intro/#policy-enforcement-modes
    enable-policy: "default"
    policy-cidr-match-mode: ""
    # If you want metrics enabled in cilium-operator, set the port for
    # which the Cilium Operator will have their metrics exposed.
    # NOTE that this will open the port on the nodes where Cilium operator pod
    # is scheduled.
    operator-prometheus-serve-addr: ":9963"
    enable-metrics: "true"
    enable-policy-secrets-sync: "true"
    policy-secrets-only-from-secrets-namespace: "true"
    policy-secrets-namespace: "cilium-secrets"

    # Enable IPv4 addressing. If enabled, all endpoints are allocated an IPv4
    # address.
    enable-ipv4: "true"

    # Enable IPv6 addressing. If enabled, all endpoints are allocated an IPv6
    # address.
    enable-ipv6: "false"
    # Users who wish to specify their own custom CNI configuration file must set
    # custom-cni-conf to "true", otherwise Cilium may overwrite the configuration.
    custom-cni-conf: "false"
    enable-bpf-clock-probe: "false"
    # If you want cilium monitor to aggregate tracing for packets, set this level
    # to "low", "medium", or "maximum". The higher the level, the less packets
    # that will be seen in monitor output.
    monitor-aggregation: medium

    # The monitor aggregation interval governs the typical time between monitor
    # notification events for each allowed connection.
    #
    # Only effective when monitor aggregation is set to "medium" or higher.
    monitor-aggregation-interval: "5s"

    # The monitor aggregation flags determine which TCP flags which, upon the
    # first observation, cause monitor notifications to be generated.
    #
    # Only effective when monitor aggregation is set to "medium" or higher.
    monitor-aggregation-flags: all
    # Specifies the ratio (0.0-1.0] of total system memory to use for dynamic
    # sizing of the TCP CT, non-TCP CT, NAT and policy BPF maps.
    bpf-map-dynamic-size-ratio: "0.0025"
    # bpf-policy-map-max specifies the maximum number of entries in endpoint
    # policy map (per endpoint)
    bpf-policy-map-max: "16384"
    # bpf-policy-stats-map-max specifies the maximum number of entries in global
    # policy stats map
    bpf-policy-stats-map-max: "65536"
    # bpf-lb-map-max specifies the maximum number of entries in bpf lb service,
    # backend and affinity maps.
    bpf-lb-map-max: "65536"
    bpf-lb-external-clusterip: "false"
    bpf-lb-source-range-all-types: "false"
+ # When Gateway API is enabled this is forced to "true" so per-backend weights
+ # on TCPRoute/UDPRoute take effect (Maglev honors the LB algorithm annotation only
+ # when enabled). Paired with `bpf-lb-sock-hostns-only`, which is forced "true"
+ # for the same reason.
    bpf-lb-algorithm-annotation: "false"
    bpf-lb-mode-annotation: "false"

    bpf-distributed-lru: "false"
    bpf-events-drop-enabled: "true"
    bpf-events-policy-verdict-enabled: "true"
    bpf-events-trace-enabled: "true"

    # Pre-allocation of map entries allows per-packet latency to be reduced, at
    # the expense of up-front memory allocation for the entries in the maps. The
    # default value below will minimize memory usage in the default installation;
    # users who are sensitive to latency may consider setting this to "true".
    #
    # This option was introduced in Cilium 1.4. Cilium 1.3 and earlier ignore
    # this option and behave as though it is set to "true".
    #
    # If this value is modified, then during the next Cilium startup the restore
    # of existing endpoints and tracking of ongoing connections may be disrupted.
    # As a result, reply packets may be dropped and the load-balancing decisions
    # for established connections may change.
    #
    # If this option is set to "false" during an upgrade from 1.3 or earlier to
    # 1.4 or later, then it may cause one-time disruptions during the upgrade.
    preallocate-bpf-maps: "false"

    # Name of the cluster. Only relevant when building a mesh of clusters.
    cluster-name: "default"
    # Unique ID of the cluster. Must be unique across all connected clusters and
    # in the range of 1 and 255. Only relevant when building a mesh of clusters.
    cluster-id: "0"

    # Encapsulation mode for communication between nodes
    # Possible values:
    #   - disabled
    #   - vxlan (default)
    #   - geneve

    routing-mode: "tunnel"
    tunnel-protocol: "vxlan"
    tunnel-source-port-range: "0-0"
    service-no-backend-response: "reject"
    policy-deny-response: "none"


    # Enables L7 proxy for L7 policy enforcement and visibility
    enable-l7-proxy: "true"
    enable-ipv4-masquerade: "true"
    enable-ipv4-big-tcp: "false"
    enable-ipv6-big-tcp: "false"
    enable-ipv6-masquerade: "true"
    enable-tcx: "true"
    datapath-mode: "veth"
    enable-bpf-masquerade: "true"
    enable-masquerade-to-route-source: "false"

    enable-xt-socket-fallback: "true"
    install-no-conntrack-iptables-rules: "false"
    iptables-random-fully: "false"

    auto-direct-node-routes: "false"
    direct-routing-skip-unreachable: "false"



    enable-host-firewall: "false"
+   # List of devices used to attach bpf_host.o (implements BPF NodePort,
+   # host-firewall and BPF masquerading)
+   devices: ""

    kube-proxy-replacement: "true"
    kube-proxy-replacement-healthz-bind-address: ""
    enable-no-service-endpoints-routable: "true"
    bpf-lb-sock: "false"
    nodeport-addresses: ""
    enable-health-check-nodeport: "true"
+   enable-dynamic-source-lookup-nodeport: "false"
    enable-health-check-loadbalancer-ip: "false"
    node-port-bind-protection: "true"
    enable-auto-protect-node-port-range: "true"
    bpf-lb-acceleration: "disabled"
    enable-service-topology: "false"
    enable-l2-neigh-discovery: "false"
    k8s-require-ipv4-pod-cidr: "false"
    k8s-require-ipv6-pod-cidr: "false"
    enable-k8s-networkpolicy: "true"
    enable-endpoint-lockdown-on-policy-overflow: "false"
    # Tell the agent to generate and write a CNI configuration file
    write-cni-conf-when-ready: /host/etc/cni/net.d/05-cilium.conflist
    cni-exclusive: "true"
    cni-log-file: "/var/run/cilium/cilium-cni.log"
    enable-endpoint-health-checking: "true"
    enable-health-checking: "true"
    health-check-icmp-failure-threshold: "3"
    enable-well-known-identities: "false"
    enable-node-selector-labels: "false"
    synchronize-k8s-nodes: "true"
    operator-api-serve-addr: "127.0.0.1:9234"

    enable-hubble: "true"
    # UNIX domain socket for Hubble server to listen to.
    hubble-socket-path: "/var/run/cilium/hubble.sock"
    hubble-network-policy-correlation-enabled: "true"
    # An additional address for Hubble server to listen to (e.g. ":4244").
    hubble-listen-address: ":4244"
    hubble-disable-tls: "false"
    hubble-tls-cert-file: /var/lib/cilium/tls/hubble/server.crt
    hubble-tls-key-file: /var/lib/cilium/tls/hubble/server.key
    hubble-tls-client-ca-files: /var/lib/cilium/tls/hubble/client-ca.crt
    ipam: "kubernetes"
    ipam-cilium-node-update-rate: "15s"

    default-lb-service-ipam: "lbipam"
    egress-gateway-reconciliation-trigger-interval: "1s"
    enable-vtep: "false"
    vtep-endpoint: ""
    vtep-cidr: ""
    vtep-mask: ""
    vtep-mac: ""
    # Enable L2 announcements
    enable-l2-announcements: "true"
    l2-announcements-lease-duration: "7s"
    l2-announcements-renew-deadline: "3s"
    l2-announcements-retry-period: "500ms"

    packetization-layer-pmtud-mode: "blackhole"
    procfs: "/host/proc"
    bpf-root: "/sys/fs/bpf"
    cgroup-root: "/run/cilium/cgroupv2"

    identity-management-mode: "agent"
    enable-sctp: "false"
    remove-cilium-node-taints: "true"
    set-cilium-node-taints: "true"
    set-cilium-is-up-condition: "true"
    unmanaged-pod-watcher-interval: "15s"
    # default DNS proxy to transparent mode in non-chaining modes
    dnsproxy-enable-transparent-mode: "true"
    dnsproxy-socket-linger-timeout: "10"
    tofqdns-dns-reject-response-code: "refused"
    tofqdns-enable-dns-compression: "true"
    tofqdns-endpoint-max-ip-per-hostname: "1000"
    tofqdns-idle-connection-grace-period: "0s"
    tofqdns-max-deferred-connection-deletes: "10000"
    tofqdns-proxy-response-max-delay: "100ms"
    tofqdns-preallocate-identities:  "true"
    agent-not-ready-taint-key: "node.cilium.io/agent-not-ready"

    mesh-auth-enabled: "false"
    mesh-auth-queue-size: "1024"
    mesh-auth-rotated-identities-queue-size: "1024"
    mesh-auth-gc-interval: "5m0s"

    proxy-xff-num-trusted-hops-ingress: "0"
    proxy-xff-num-trusted-hops-egress: "0"
    proxy-connect-timeout: "2"
    proxy-initial-fetch-timeout: "30"
    proxy-max-active-downstream-connections: "50000"
    proxy-max-requests-per-connection: "0"
    proxy-max-connection-duration-seconds: "0"
    proxy-idle-timeout-seconds: "60"
    proxy-max-concurrent-retries: "128"
    proxy-use-original-source-address: "true"
    proxy-cluster-max-connections: "1024"
+   proxy-cluster-max-pending-requests: "1024"
    proxy-cluster-max-requests: "1024"
    http-retry-count: "3"
    http-stream-idle-timeout: "300"
+   envoy-node-locality-enabled: "false"

    external-envoy-proxy: "true"
    envoy-base-id: "0"
+   envoy-access-log-enabled: "true"
    envoy-access-log-buffer-size: "4096"
    envoy-keep-cap-netbindservice: "false"
+   envoy-xds-mode: "ads"
    max-connected-clusters: "255"
    clustermesh-cache-ttl: "0s"
    clustermesh-enable-endpoint-sync: "false"
    clustermesh-enable-mcs-api: "false"
    clustermesh-mcs-api-install-crds: "true"
+   clustermesh-default-global-namespace: "true"
    policy-default-local-cluster: "true"

    nat-map-stats-entries: "32"
    nat-map-stats-interval: "30s"
    enable-lb-ipam: "true"
    enable-non-default-deny-policies: "true"
    enable-source-ip-verification: "true"
    enable-dynamic-config: "true"
    enable-drift-checker: "true"
+ 
+   enable-datapath-plugins: "false"
+   datapath-plugins-state-dir: "/var/run/cilium/plugins"

  # Extra config allows adding arbitrary properties to the cilium config.
  # By putting it at the end of the ConfigMap, it's also possible to override existing properties.
kube-system, cilium-config-agent, Role (rbac.authorization.k8s.io) has changed:
  # Source: cilium/templates/cilium-agent/role.yaml
  apiVersion: rbac.authorization.k8s.io/v1
  kind: Role
  metadata:
    name: cilium-config-agent
    namespace: kube-system
    labels:
      app.kubernetes.io/part-of: cilium
+     helm.sh/chart: cilium-1.20.1
  rules:
  - apiGroups:
    - ""
    resources:
    - configmaps
    verbs:
    - get
    - list
    - watch
kube-system, cilium-config-agent, RoleBinding (rbac.authorization.k8s.io) has changed:
  # Source: cilium/templates/cilium-agent/rolebinding.yaml
  apiVersion: rbac.authorization.k8s.io/v1
  kind: RoleBinding
  metadata:
    name: cilium-config-agent
    namespace: kube-system
    labels:
      app.kubernetes.io/part-of: cilium
+     helm.sh/chart: cilium-1.20.1
  roleRef:
    apiGroup: rbac.authorization.k8s.io
    kind: Role
    name: cilium-config-agent
  subjects:
    - kind: ServiceAccount
      name: "cilium"
      namespace: kube-system
kube-system, cilium-envoy, DaemonSet (apps) has changed:
  # Source: cilium/templates/cilium-envoy/daemonset.yaml
  apiVersion: apps/v1
  kind: DaemonSet
  metadata:
    name: cilium-envoy
    namespace: kube-system
    labels:
      k8s-app: cilium-envoy
      app.kubernetes.io/part-of: cilium
      app.kubernetes.io/name: cilium-envoy
      name: cilium-envoy
+     helm.sh/chart: cilium-1.20.1
  spec:
    selector:
      matchLabels:
        k8s-app: cilium-envoy
    
    updateStrategy:
      rollingUpdate:
        maxUnavailable: 2
      type: RollingUpdate
    template:
      metadata:
        annotations:
        labels:
          k8s-app: cilium-envoy
          name: cilium-envoy
          app.kubernetes.io/name: cilium-envoy
          app.kubernetes.io/part-of: cilium
+         helm.sh/chart: cilium-1.20.1
      spec:
        securityContext:
          appArmorProfile:
            type: Unconfined
-       
        containers:
        - name: cilium-envoy
-         image: "quay.io/cilium/cilium-envoy:v1.36.9-1786864149-07e8503ff34b9190d7bbe4e57d4e185c4ef8b1de@sha256:beccdf3c119f299cf696885188584bbd0531d74bca08096113207999aff95e87"
+         image: "quay.io/cilium/cilium-envoy:v1.37.5-1786810558-766ccfb37260a43e9d228837aa84ce3faf9f64e7@sha256:75b8094c7127736a2ffd2dce3945e0931cb6df21b0372ff661940eca26730b91"
          imagePullPolicy: IfNotPresent
          command:
          - /usr/bin/cilium-envoy-starter
          args:
          - '--'
          - '-c /var/run/cilium/envoy/bootstrap-config.json'
          - '--base-id 0'
          - '--log-level info'
          
          startupProbe:
            httpGet:
              host: "127.0.0.1"
              path: /healthz
              port: 9878
              scheme: HTTP
            failureThreshold: 105
            periodSeconds: 2
            successThreshold: 1
            initialDelaySeconds: 5
+           timeoutSeconds: 5
          livenessProbe:
            httpGet:
              host: "127.0.0.1"
              path: /healthz
              port: 9878
              scheme: HTTP
            periodSeconds: 30
            successThreshold: 1
            failureThreshold: 10
+           initialDelaySeconds: 0
            timeoutSeconds: 5
          readinessProbe:
            httpGet:
              host: "127.0.0.1"
              path: /healthz
              port: 9878
              scheme: HTTP
            periodSeconds: 30
            successThreshold: 1
            failureThreshold: 3
+           initialDelaySeconds: 0
            timeoutSeconds: 5
+ 
          env:
          - name: K8S_NODE_NAME
            valueFrom:
              fieldRef:
                apiVersion: v1
                fieldPath: spec.nodeName
          - name: CILIUM_K8S_NAMESPACE
            valueFrom:
              fieldRef:
                apiVersion: v1
                fieldPath: metadata.namespace
          
          ports:
          - name: envoy-metrics
            containerPort: 9964
            hostPort: 9964
            protocol: TCP
          securityContext:
            seLinuxOptions:
              level: s0
              type: spc_t
            capabilities:
              add:
                - NET_ADMIN
                - SYS_ADMIN
              drop:
                - ALL
          terminationMessagePolicy: FallbackToLogsOnError
          volumeMounts:
          - name: envoy-sockets
            mountPath: /var/run/cilium/envoy/sockets
            readOnly: false
          - name: envoy-artifacts
            mountPath: /var/run/cilium/envoy/artifacts
            readOnly: true
          - name: envoy-config
            mountPath: /var/run/cilium/envoy/
            readOnly: true
          - name: bpf-maps
            mountPath: /sys/fs/bpf
            mountPropagation: HostToContainer
          
        restartPolicy: Always
        priorityClassName: system-node-critical
        serviceAccountName: "cilium-envoy"
        automountServiceAccountToken: true
        terminationGracePeriodSeconds: 1
        hostNetwork: true
+       hostUsers: true
        
        affinity:
          nodeAffinity:
            requiredDuringSchedulingIgnoredDuringExecution:
              nodeSelectorTerms:
              - matchExpressions:
                - key: cilium.io/no-schedule
                  operator: NotIn
                  values:
                  - "true"
          podAffinity:
            requiredDuringSchedulingIgnoredDuringExecution:
            - labelSelector:
                matchLabels:
                  k8s-app: cilium
              topologyKey: kubernetes.io/hostname
          podAntiAffinity:
            requiredDuringSchedulingIgnoredDuringExecution:
            - labelSelector:
                matchLabels:
                  k8s-app: cilium-envoy
              topologyKey: kubernetes.io/hostname
        nodeSelector:
          kubernetes.io/os: linux
        tolerations:
          - operator: Exists
        volumes:
        - name: envoy-sockets
          hostPath:
            path: "/var/run/cilium/envoy/sockets"
            type: DirectoryOrCreate
        - name: envoy-artifacts
          hostPath:
            path: "/var/run/cilium/envoy/artifacts"
            type: DirectoryOrCreate
        - name: envoy-config
          configMap:
            name: "cilium-envoy-config"
            # note: the leading zero means this number is in octal representation: do not remove it
            defaultMode: 0400
            items:
              - key: bootstrap-config.json
                path: bootstrap-config.json
          # To keep state between restarts / upgrades
          # To keep state between restarts / upgrades for bpf maps
        - name: bpf-maps
          hostPath:
            path: /sys/fs/bpf
            type: DirectoryOrCreate
kube-system, cilium-envoy, Service (v1) has changed:
  # Source: cilium/templates/cilium-envoy/service.yaml
  apiVersion: v1
  kind: Service
  metadata:
    name: cilium-envoy
    namespace: kube-system
    annotations:
      prometheus.io/scrape: "true"
      prometheus.io/port: "9964"
    labels:
      k8s-app: cilium-envoy
      app.kubernetes.io/name: cilium-envoy
      app.kubernetes.io/part-of: cilium
+     helm.sh/chart: cilium-1.20.1
      io.cilium/app: proxy
  spec:
    clusterIP: None
    type: ClusterIP
    selector:
      k8s-app: cilium-envoy
    ports:
    - name: envoy-metrics
      port: 9964
      protocol: TCP
      targetPort: 9964
kube-system, cilium-envoy-config, ConfigMap (v1) has changed:
  # Source: cilium/templates/cilium-envoy/configmap.yaml
  apiVersion: v1
  kind: ConfigMap
  metadata:
    name: cilium-envoy-config
    namespace: kube-system
  data:
    # Keep the key name as bootstrap-config.json to avoid breaking changes
    bootstrap-config.json: |
-     {"admin":{"address":{"pipe":{"mode":432,"path":"/var/run/cilium/envoy/sockets/admin.sock"}}},"applicationLogConfig":{"logFormat":{"textFormat":"[%Y-%m-%d %T.%e][%t][%l][%n] [%g:%#] %v"}},"bootstrapExtensions":[{"name":"envoy.bootstrap.internal_listener","typedConfig":{"@type":"type.googleapis.com/envoy.extensions.bootstrap.internal_listener.v3.InternalListener"}}],"dynamicResources":{"cdsConfig":{"apiConfigSource":{"apiType":"GRPC","grpcServices":[{"envoyGrpc":{"clusterName":"xds-grpc-cilium"}}],"setNodeOnFirstMessageOnly":true,"transportApiVersion":"V3"},"initialFetchTimeout":"30s","resourceApiVersion":"V3"},"ldsConfig":{"apiConfigSource":{"apiType":"GRPC","grpcServices":[{"envoyGrpc":{"clusterName":"xds-grpc-cilium"}}],"setNodeOnFirstMessageOnly":true,"transportApiVersion":"V3"},"initialFetchTimeout":"30s","resourceApiVersion":"V3"}},"node":{"cluster":"ingress-cluster","id":"host~127.0.0.1~no-id~localdomain"},"overloadManager":{"resourceMonitors":[{"name":"envoy.resource_monitors.global_downstream_max_connections","typedConfig":{"@type":"type.googleapis.com/envoy.extensions.resource_monitors.downstream_connections.v3.DownstreamConnectionsConfig","max_active_downstream_connections":"50000"}}]},"staticResources":{"clusters":[{"circuitBreakers":{"thresholds":[{"maxConnections":1024,"maxRequests":1024,"maxRetries":128}]},"cleanupInterval":"2.500s","connectTimeout":"2s","lbPolicy":"CLUSTER_PROVIDED","name":"ingress-cluster","type":"ORIGINAL_DST","typedExtensionProtocolOptions":{"envoy.extensions.upstreams.http.v3.HttpProtocolOptions":{"@type":"type.googleapis.com/envoy.extensions.upstreams.http.v3.HttpProtocolOptions","commonHttpProtocolOptions":{"idleTimeout":"60s","maxConnectionDuration":"0s","maxRequestsPerConnection":0},"useDownstreamProtocolConfig":{}}}},{"circuitBreakers":{"thresholds":[{"maxConnections":1024,"maxRequests":1024,"maxRetries":128}]},"cleanupInterval":"2.500s","connectTimeout":"2s","lbPolicy":"CLUSTER_PROVIDED","name":"egress-cluster-tls","transportSocket":{"name":"cilium.tls_wrapper","typedConfig":{"@type":"type.googleapis.com/cilium.UpstreamTlsWrapperContext"}},"type":"ORIGINAL_DST","typedExtensionProtocolOptions":{"envoy.extensions.upstreams.http.v3.HttpProtocolOptions":{"@type":"type.googleapis.com/envoy.extensions.upstreams.http.v3.HttpProtocolOptions","commonHttpProtocolOptions":{"idleTimeout":"60s","maxConnectionDuration":"0s","maxRequestsPerConnection":0},"upstreamHttpProtocolOptions":{},"useDownstreamProtocolConfig":{}}}},{"circuitBreakers":{"thresholds":[{"maxConnections":1024,"maxRequests":1024,"maxRetries":128}]},"cleanupInterval":"2.500s","connectTimeout":"2s","lbPolicy":"CLUSTER_PROVIDED","name":"egress-cluster","type":"ORIGINAL_DST","typedExtensionProtocolOptions":{"envoy.extensions.upstreams.http.v3.HttpProtocolOptions":{"@type":"type.googleapis.com/envoy.extensions.upstreams.http.v3.HttpProtocolOptions","commonHttpProtocolOptions":{"idleTimeout":"60s","maxConnectionDuration":"0s","maxRequestsPerConnection":0},"useDownstreamProtocolConfig":{}}}},{"circuitBreakers":{"thresholds":[{"maxConnections":1024,"maxRequests":1024,"maxRetries":128}]},"cleanupInterval":"2.500s","connectTimeout":"2s","lbPolicy":"CLUSTER_PROVIDED","name":"ingress-cluster-tls","transportSocket":{"name":"cilium.tls_wrapper","typedConfig":{"@type":"type.googleapis.com/cilium.UpstreamTlsWrapperContext"}},"type":"ORIGINAL_DST","typedExtensionProtocolOptions":{"envoy.extensions.upstreams.http.v3.HttpProtocolOptions":{"@type":"type.googleapis.com/envoy.extensions.upstreams.http.v3.HttpProtocolOptions","commonHttpProtocolOptions":{"idleTimeout":"60s","maxConnectionDuration":"0s","maxRequestsPerConnection":0},"upstreamHttpProtocolOptions":{},"useDownstreamProtocolConfig":{}}}},{"connectTimeout":"2s","loadAssignment":{"clusterName":"xds-grpc-cilium","endpoints":[{"lbEndpoints":[{"endpoint":{"address":{"pipe":{"path":"/var/run/cilium/envoy/sockets/xds.sock"}}}}]}]},"name":"xds-grpc-cilium","type":"STATIC","typedExtensionProtocolOptions":{"envoy.extensions.upstreams.http.v3.HttpProtocolOptions":{"@type":"type.googleapis.com/envoy.extensions.upstreams.http.v3.HttpProtocolOptions","explicitHttpConfig":{"http2ProtocolOptions":{}}}}},{"connectTimeout":"2s","loadAssignment":{"clusterName":"/envoy-admin","endpoints":[{"lbEndpoints":[{"endpoint":{"address":{"pipe":{"path":"/var/run/cilium/envoy/sockets/admin.sock"}}}}]}]},"name":"/envoy-admin","type":"STATIC"}],"listeners":[{"address":{"socketAddress":{"address":"0.0.0.0","portValue":9964}},"filterChains":[{"filters":[{"name":"envoy.filters.network.http_connection_manager","typedConfig":{"@type":"type.googleapis.com/envoy.extensions.filters.network.http_connection_manager.v3.HttpConnectionManager","httpFilters":[{"name":"envoy.filters.http.router","typedConfig":{"@type":"type.googleapis.com/envoy.extensions.filters.http.router.v3.Router"}}],"internalAddressConfig":{"cidrRanges":[{"addressPrefix":"10.0.0.0","prefixLen":8},{"addressPrefix":"172.16.0.0","prefixLen":12},{"addressPrefix":"192.168.0.0","prefixLen":16},{"addressPrefix":"127.0.0.1","prefixLen":32}]},"routeConfig":{"virtualHosts":[{"domains":["*"],"name":"prometheus_metrics_route","routes":[{"match":{"prefix":"/metrics"},"name":"prometheus_metrics_route","route":{"cluster":"/envoy-admin","prefixRewrite":"/stats/prometheus"}}]}]},"statPrefix":"envoy-prometheus-metrics-listener","streamIdleTimeout":"300s"}}]}],"name":"envoy-prometheus-metrics-listener"},{"address":{"socketAddress":{"address":"127.0.0.1","portValue":9878}},"filterChains":[{"filters":[{"name":"envoy.filters.network.http_connection_manager","typedConfig":{"@type":"type.googleapis.com/envoy.extensions.filters.network.http_connection_manager.v3.HttpConnectionManager","httpFilters":[{"name":"envoy.filters.http.router","typedConfig":{"@type":"type.googleapis.com/envoy.extensions.filters.http.router.v3.Router"}}],"internalAddressConfig":{"cidrRanges":[{"addressPrefix":"10.0.0.0","prefixLen":8},{"addressPrefix":"172.16.0.0","prefixLen":12},{"addressPrefix":"192.168.0.0","prefixLen":16},{"addressPrefix":"127.0.0.1","prefixLen":32}]},"routeConfig":{"virtual_hosts":[{"domains":["*"],"name":"health","routes":[{"match":{"prefix":"/healthz"},"name":"health","route":{"cluster":"/envoy-admin","prefixRewrite":"/ready"}}]}]},"statPrefix":"envoy-health-listener","streamIdleTimeout":"300s"}}]}],"name":"envoy-health-listener"}]}}
+     {"admin":{"address":{"pipe":{"mode":432,"path":"/var/run/cilium/envoy/sockets/admin.sock"}}},"applicationLogConfig":{"logFormat":{"textFormat":"[%Y-%m-%d %T.%e][%t][%l][%n] [%g:%#] %v"}},"bootstrapExtensions":[{"name":"envoy.bootstrap.internal_listener","typedConfig":{"@type":"type.googleapis.com/envoy.extensions.bootstrap.internal_listener.v3.InternalListener"}}],"dynamicResources":{"adsConfig":{"apiType":"GRPC","grpcServices":[{"envoyGrpc":{"clusterName":"xds-grpc-cilium"}}],"setNodeOnFirstMessageOnly":true,"transportApiVersion":"V3"},"cdsConfig":{"ads":{},"initialFetchTimeout":"30s","resourceApiVersion":"V3"},"ldsConfig":{"ads":{},"initialFetchTimeout":"30s","resourceApiVersion":"V3"}},"node":{"cluster":"ingress-cluster","id":"host~127.0.0.1~no-id~localdomain"},"overloadManager":{"resourceMonitors":[{"name":"envoy.resource_monitors.global_downstream_max_connections","typedConfig":{"@type":"type.googleapis.com/envoy.extensions.resource_monitors.downstream_connections.v3.DownstreamConnectionsConfig","max_active_downstream_connections":"50000"}}]},"staticResources":{"clusters":[{"circuitBreakers":{"thresholds":[{"maxConnections":1024,"maxRequests":1024,"maxRetries":128}]},"cleanupInterval":"2.500s","connectTimeout":"2s","lbPolicy":"CLUSTER_PROVIDED","name":"ingress-cluster","type":"ORIGINAL_DST","typedExtensionProtocolOptions":{"envoy.extensions.upstreams.http.v3.HttpProtocolOptions":{"@type":"type.googleapis.com/envoy.extensions.upstreams.http.v3.HttpProtocolOptions","commonHttpProtocolOptions":{"idleTimeout":"60s","maxConnectionDuration":"0s","maxRequestsPerConnection":0},"useDownstreamProtocolConfig":{}}}},{"circuitBreakers":{"thresholds":[{"maxConnections":1024,"maxRequests":1024,"maxRetries":128}]},"cleanupInterval":"2.500s","connectTimeout":"2s","lbPolicy":"CLUSTER_PROVIDED","name":"egress-cluster-tls","transportSocket":{"name":"cilium.tls_wrapper","typedConfig":{"@type":"type.googleapis.com/cilium.UpstreamTlsWrapperContext"}},"type":"ORIGINAL_DST","typedExtensionProtocolOptions":{"envoy.extensions.upstreams.http.v3.HttpProtocolOptions":{"@type":"type.googleapis.com/envoy.extensions.upstreams.http.v3.HttpProtocolOptions","commonHttpProtocolOptions":{"idleTimeout":"60s","maxConnectionDuration":"0s","maxRequestsPerConnection":0},"upstreamHttpProtocolOptions":{},"useDownstreamProtocolConfig":{}}}},{"circuitBreakers":{"thresholds":[{"maxConnections":1024,"maxRequests":1024,"maxRetries":128}]},"cleanupInterval":"2.500s","connectTimeout":"2s","lbPolicy":"CLUSTER_PROVIDED","name":"egress-cluster","type":"ORIGINAL_DST","typedExtensionProtocolOptions":{"envoy.extensions.upstreams.http.v3.HttpProtocolOptions":{"@type":"type.googleapis.com/envoy.extensions.upstreams.http.v3.HttpProtocolOptions","commonHttpProtocolOptions":{"idleTimeout":"60s","maxConnectionDuration":"0s","maxRequestsPerConnection":0},"useDownstreamProtocolConfig":{}}}},{"circuitBreakers":{"thresholds":[{"maxConnections":1024,"maxRequests":1024,"maxRetries":128}]},"cleanupInterval":"2.500s","connectTimeout":"2s","lbPolicy":"CLUSTER_PROVIDED","name":"ingress-cluster-tls","transportSocket":{"name":"cilium.tls_wrapper","typedConfig":{"@type":"type.googleapis.com/cilium.UpstreamTlsWrapperContext"}},"type":"ORIGINAL_DST","typedExtensionProtocolOptions":{"envoy.extensions.upstreams.http.v3.HttpProtocolOptions":{"@type":"type.googleapis.com/envoy.extensions.upstreams.http.v3.HttpProtocolOptions","commonHttpProtocolOptions":{"idleTimeout":"60s","maxConnectionDuration":"0s","maxRequestsPerConnection":0},"upstreamHttpProtocolOptions":{},"useDownstreamProtocolConfig":{}}}},{"circuitBreakers":{"thresholds":[{"maxConnections":1024,"maxRequests":1024,"maxRetries":128}]},"connectTimeout":"2s","loadAssignment":{"clusterName":"xds-grpc-cilium","endpoints":[{"lbEndpoints":[{"endpoint":{"address":{"pipe":{"path":"/var/run/cilium/envoy/sockets/xds.sock"}}}}]}]},"name":"xds-grpc-cilium","type":"STATIC","typedExtensionProtocolOptions":{"envoy.extensions.upstreams.http.v3.HttpProtocolOptions":{"@type":"type.googleapis.com/envoy.extensions.upstreams.http.v3.HttpProtocolOptions","explicitHttpConfig":{"http2ProtocolOptions":{}}}}},{"connectTimeout":"2s","loadAssignment":{"clusterName":"/envoy-admin","endpoints":[{"lbEndpoints":[{"endpoint":{"address":{"pipe":{"path":"/var/run/cilium/envoy/sockets/admin.sock"}}}}]}]},"name":"/envoy-admin","type":"STATIC"}],"listeners":[{"address":{"socketAddress":{"address":"0.0.0.0","portValue":9964}},"filterChains":[{"filters":[{"name":"envoy.filters.network.http_connection_manager","typedConfig":{"@type":"type.googleapis.com/envoy.extensions.filters.network.http_connection_manager.v3.HttpConnectionManager","httpFilters":[{"name":"envoy.filters.http.router","typedConfig":{"@type":"type.googleapis.com/envoy.extensions.filters.http.router.v3.Router"}}],"internalAddressConfig":{"cidrRanges":[{"addressPrefix":"10.0.0.0","prefixLen":8},{"addressPrefix":"172.16.0.0","prefixLen":12},{"addressPrefix":"192.168.0.0","prefixLen":16},{"addressPrefix":"127.0.0.1","prefixLen":32}]},"routeConfig":{"virtualHosts":[{"domains":["*"],"name":"prometheus_metrics_route","routes":[{"match":{"prefix":"/metrics"},"name":"prometheus_metrics_route","route":{"cluster":"/envoy-admin","prefixRewrite":"/stats/prometheus"}}]}]},"statPrefix":"envoy-prometheus-metrics-listener","streamIdleTimeout":"300s"}}]}],"name":"envoy-prometheus-metrics-listener"},{"address":{"socketAddress":{"address":"127.0.0.1","portValue":9878}},"filterChains":[{"filters":[{"name":"envoy.filters.network.http_connection_manager","typedConfig":{"@type":"type.googleapis.com/envoy.extensions.filters.network.http_connection_manager.v3.HttpConnectionManager","httpFilters":[{"name":"envoy.filters.http.router","typedConfig":{"@type":"type.googleapis.com/envoy.extensions.filters.http.router.v3.Router"}}],"internalAddressConfig":{"cidrRanges":[{"addressPrefix":"10.0.0.0","prefixLen":8},{"addressPrefix":"172.16.0.0","prefixLen":12},{"addressPrefix":"192.168.0.0","prefixLen":16},{"addressPrefix":"127.0.0.1","prefixLen":32}]},"routeConfig":{"virtual_hosts":[{"domains":["*"],"name":"health","routes":[{"match":{"prefix":"/healthz"},"name":"health","route":{"cluster":"/envoy-admin","prefixRewrite":"/ready"}}]}]},"statPrefix":"envoy-health-listener","streamIdleTimeout":"300s"}}]}],"name":"envoy-health-listener"}]}}
kube-system, cilium-operator, ClusterRole (rbac.authorization.k8s.io) has changed:
  # Source: cilium/templates/cilium-operator/clusterrole.yaml
  apiVersion: rbac.authorization.k8s.io/v1
  kind: ClusterRole
  metadata:
    name: cilium-operator
    labels:
      app.kubernetes.io/part-of: cilium
+     helm.sh/chart: cilium-1.20.1
  rules:
  - apiGroups:
    - ""
    resources:
    - pods
    verbs:
    - get
    - list
    - watch
    # to automatically delete [core|kube]dns pods so that are starting to being
    # managed by Cilium
    - delete
  - apiGroups:
    - ""
    resources:
    - configmaps
    resourceNames:
    - cilium-config
    verbs:
     # allow patching of the configmap to set annotations
    - patch
  - apiGroups:
    - ""
    resources:
    - nodes
    verbs:
    - list
    - watch
  - apiGroups:
    - ""
    resources:
    # To remove node taints
    - nodes
    # To set NetworkUnavailable false on startup
    - nodes/status
    verbs:
    - patch
  - apiGroups:
    - discovery.k8s.io
    resources:
    - endpointslices
    verbs:
    - get
    - list
    - watch
  - apiGroups:
    - ""
    resources:
    # to perform LB IP allocation for BGP
    - services/status
    verbs:
    - update
    - patch
  - apiGroups:
    - ""
    resources:
    # to check apiserver connectivity
    - namespaces
    - secrets
+   - serviceaccounts
    verbs:
    - get
    - list
    - watch
  - apiGroups:
    - ""
    resources:
    # to perform the translation of a CNP that contains `ToGroup` to its endpoints
    - services
-   - endpoints
    verbs:
    - get
    - list
    - watch
  - apiGroups:
+   # Watch CNP / CCNPs for validation and external groups.
    - cilium.io
    resources:
    - ciliumnetworkpolicies
    - ciliumclusterwidenetworkpolicies
    verbs:
-   # Create auto-generated CNPs and CCNPs from Policies that have 'toGroups'
+   # Create auto-generated CNPs and CCNPs from Policies that have 'toGroups'.
+   # This was removed in v1.20, but we must keep the permissions until v1.21 for
+   # upgrade phasing.
    - create
    - update
    - deletecollection
-   # To update the status of the CNPs and CCNPs
    - patch
    - get
    - list
    - watch
  - apiGroups:
    - cilium.io
    resources:
    - ciliumnetworkpolicies/status
    - ciliumclusterwidenetworkpolicies/status
    verbs:
-   # Update the auto-generated CNPs and CCNPs status.
+   # Set validity status on CNP / CCNP.
    - patch
    - update
  - apiGroups:
    - cilium.io
    resources:
    - ciliumendpoints
    - ciliumidentities
    verbs:
    # To perform garbage collection of such resources
    - delete
    - list
    - watch
  - apiGroups:
    - cilium.io
    resources:
    - ciliumidentities
    verbs:
    # To synchronize garbage collection of such resources
    - update
  - apiGroups:
    - cilium.io
    resources:
    - ciliumnodes
    verbs:
    - create
    - update
    - get
    - list
    - watch
      # To perform CiliumNode garbage collector
    - delete
  - apiGroups:
    - cilium.io
    resources:
    - ciliumnodes/status
    verbs:
    - update
  - apiGroups:
    - cilium.io
    resources:
    - ciliumendpointslices
    - ciliumenvoyconfigs
+   - ciliumbgpclusterconfigs
+   - ciliumbgpnodeconfigoverrides
    - ciliumbgppeerconfigs
    - ciliumbgpadvertisements
    - ciliumbgpnodeconfigs
+   - ciliumcidrgroups
    verbs:
    - create
    - update
    - get
    - list
    - watch
    - delete
    - patch
  - apiGroups:
    - cilium.io
    resources:
    - ciliumbgpclusterconfigs/status
    - ciliumbgppeerconfigs/status
    verbs:
    - update
  - apiGroups:
    - apiextensions.k8s.io
    resources:
    - customresourcedefinitions
    verbs:
    - create
    - get
    - list
    - watch
  - apiGroups:
    - apiextensions.k8s.io
    resources:
    - customresourcedefinitions
    verbs:
    - update
    resourceNames:
    - ciliumloadbalancerippools.cilium.io
    - ciliumbgpclusterconfigs.cilium.io
    - ciliumbgppeerconfigs.cilium.io
    - ciliumbgpadvertisements.cilium.io
    - ciliumbgpnodeconfigs.cilium.io
    - ciliumbgpnodeconfigoverrides.cilium.io
    - ciliumclusterwideenvoyconfigs.cilium.io
    - ciliumclusterwidenetworkpolicies.cilium.io
    - ciliumegressgatewaypolicies.cilium.io
    - ciliumendpoints.cilium.io
    - ciliumendpointslices.cilium.io
    - ciliumenvoyconfigs.cilium.io
    - ciliumidentities.cilium.io
    - ciliumlocalredirectpolicies.cilium.io
    - ciliumnetworkpolicies.cilium.io
    - ciliumnodes.cilium.io
    - ciliumnodeconfigs.cilium.io
    - ciliumcidrgroups.cilium.io
    - ciliuml2announcementpolicies.cilium.io
    - ciliumpodippools.cilium.io
    - ciliumgatewayclassconfigs.cilium.io
+   - ciliumdatapathplugins.cilium.io
+ - apiGroups:
+   - apiextensions.k8s.io
+   resources:
+   - customresourcedefinitions/status
+   verbs:
+   - update
+   resourceNames:
+   - ciliumbgpclusterconfigs.cilium.io
+   - ciliumbgppeerconfigs.cilium.io
+   - ciliumbgpadvertisements.cilium.io
+   - ciliumbgpnodeconfigs.cilium.io
+   - ciliumbgpnodeconfigoverrides.cilium.io
  - apiGroups:
    - cilium.io
    resources:
    - ciliumloadbalancerippools
    - ciliumpodippools
-   - ciliumbgppeeringpolicies
-   - ciliumbgpclusterconfigs
-   - ciliumbgpnodeconfigoverrides
    - ciliumbgppeerconfigs
+   - ciliumdatapathplugins
    verbs:
    - get
    - list
    - watch
  - apiGroups:
      - cilium.io
    resources:
      - ciliumpodippools
    verbs:
      - create
  - apiGroups:
    - cilium.io
    resources:
    - ciliumloadbalancerippools/status
    verbs:
    - patch
  # For cilium-operator running in HA mode.
  #
  # Cilium operator running in HA mode requires the use of ResourceLock for Leader Election
  # between multiple running instances.
  # The preferred way of doing this is to use LeasesResourceLock as edits to Leases are less
  # common and fewer objects in the cluster watch "all Leases".
  - apiGroups:
    - coordination.k8s.io
    resources:
    - leases
    verbs:
    - create
    - get
    - update
  - apiGroups:
    - cilium.io
    resources:
    - ciliumendpointslices
    verbs:
    - deletecollection
kube-system, cilium-operator, ClusterRoleBinding (rbac.authorization.k8s.io) has changed:
  # Source: cilium/templates/cilium-operator/clusterrolebinding.yaml
  apiVersion: rbac.authorization.k8s.io/v1
  kind: ClusterRoleBinding
  metadata:
    name: cilium-operator
    labels:
      app.kubernetes.io/part-of: cilium
+     helm.sh/chart: cilium-1.20.1
  roleRef:
    apiGroup: rbac.authorization.k8s.io
    kind: ClusterRole
    name: cilium-operator
  subjects:
  - kind: ServiceAccount
    name: "cilium-operator"
    namespace: kube-system
kube-system, cilium-operator, Deployment (apps) has changed:
  # Source: cilium/templates/cilium-operator/deployment.yaml
  apiVersion: apps/v1
  kind: Deployment
  metadata:
    name: cilium-operator
    namespace: kube-system
    labels:
      io.cilium/app: operator
      name: cilium-operator
      app.kubernetes.io/part-of: cilium
      app.kubernetes.io/name: cilium-operator
+     helm.sh/chart: cilium-1.20.1
  spec:
    # See docs on ServerCapabilities.LeasesResourceLock in file pkg/k8s/version/version.go
    # for more details.
    replicas: 1
    selector:
      matchLabels:
        io.cilium/app: operator
        name: cilium-operator
    # ensure operator update on single node k8s clusters, by using rolling update with maxUnavailable=100% in case
    # of one replica and no user configured Recreate strategy.
    # otherwise an update might get stuck due to the default maxUnavailable=50% in combination with the
    # podAntiAffinity which prevents deployments of multiple operator replicas on the same node.
    strategy:
      rollingUpdate:
        maxSurge: 25%
        maxUnavailable: 100%
      type: RollingUpdate
    template:
      metadata:
        annotations:
          prometheus.io/port: "9963"
          prometheus.io/scrape: "true"
        labels:
          io.cilium/app: operator
          name: cilium-operator
          app.kubernetes.io/part-of: cilium
          app.kubernetes.io/name: cilium-operator
+         helm.sh/chart: cilium-1.20.1
      spec:
        securityContext:
          seccompProfile:
            type: RuntimeDefault
        containers:
        - name: cilium-operator
-         image: "quay.io/cilium/operator-generic:v1.19.7@sha256:61e773bfc25a448f1ad3ead605af94b3ef176ba2925cf4bd1b11e09794b72bed"
+         image: "quay.io/cilium/operator-generic:v1.20.1@sha256:6c3885fc7b629099fdbe2a5c87869c86feb825fa18fae299eac0f61918d16ecf"
          imagePullPolicy: IfNotPresent
          command:
          - cilium-operator-generic
          args:
          - --config-dir=/tmp/cilium/config-map
          - --debug=$(CILIUM_DEBUG)
          env:
          - name: K8S_NODE_NAME
            valueFrom:
              fieldRef:
                apiVersion: v1
                fieldPath: spec.nodeName
          - name: CILIUM_K8S_NAMESPACE
            valueFrom:
              fieldRef:
                apiVersion: v1
                fieldPath: metadata.namespace
          - name: CILIUM_DEBUG
            valueFrom:
              configMapKeyRef:
                key: debug
                name: cilium-config
                optional: true
          ports:
          - name: health
            containerPort: 9234
            hostPort: 9234
          - name: prometheus
            containerPort: 9963
            hostPort: 9963
            protocol: TCP
          livenessProbe:
            httpGet:
              host: "127.0.0.1"
              path: /healthz
              port: health
              scheme: HTTP
            initialDelaySeconds: 60
            periodSeconds: 10
            timeoutSeconds: 3
          readinessProbe:
            httpGet:
              host: "127.0.0.1"
              path: /healthz
              port: health
              scheme: HTTP
            initialDelaySeconds: 0
            periodSeconds: 5
            timeoutSeconds: 3
            failureThreshold: 5
          volumeMounts:
          - name: cilium-config-path
            mountPath: /tmp/cilium/config-map
            readOnly: true
          
          securityContext:
            allowPrivilegeEscalation: false
            capabilities:
              drop:
              - ALL
          terminationMessagePolicy: FallbackToLogsOnError
        hostNetwork: true
+       hostUsers: true
        restartPolicy: Always
        priorityClassName: system-cluster-critical
        serviceAccountName: "cilium-operator"
        automountServiceAccountToken: true
        # In HA mode, cilium-operator pods must not be scheduled on the same
        # node as they will clash with each other.
        affinity:
          podAntiAffinity:
            requiredDuringSchedulingIgnoredDuringExecution:
            - labelSelector:
                matchLabels:
                  io.cilium/app: operator
              topologyKey: kubernetes.io/hostname
        nodeSelector:
          kubernetes.io/os: linux
+       
        tolerations:
          - key: node-role.kubernetes.io/control-plane
            operator: Exists
          - key: node-role.kubernetes.io/master
            operator: Exists
          - key: node.kubernetes.io/not-ready
            operator: Exists
          - key: node.cloudprovider.kubernetes.io/uninitialized
            operator: Exists
          - key: node.cilium.io/agent-not-ready
            operator: Exists
        
        volumes:
          # To read the configuration from the config map
        - name: cilium-config-path
          configMap:
            name: cilium-config
kube-system, cilium-operator-ztunnel, Role (rbac.authorization.k8s.io) has changed:
  # Source: cilium/templates/cilium-operator/role.yaml
  apiVersion: rbac.authorization.k8s.io/v1
  kind: Role
  metadata:
    name: cilium-operator-ztunnel
    namespace: kube-system
    labels:
      app.kubernetes.io/part-of: cilium
+     helm.sh/chart: cilium-1.20.1
  rules:
  # ZTunnel DaemonSet management permissions
  # Note: These permissions must always be granted (not conditional on encryption.type)
  # because the controller needs to clean up stale DaemonSets when ztunnel is disabled.
  - apiGroups:
    - apps
    resources:
    - daemonsets
    verbs:
    - create
    - delete
+   - get
+   - list
+   - watch
+ - apiGroups:
+   - ""
+   resources:
+   - serviceaccounts
+   verbs:
    - get
    - list
    - watch
kube-system, cilium-operator-ztunnel, RoleBinding (rbac.authorization.k8s.io) has changed:
  # Source: cilium/templates/cilium-operator/rolebinding.yaml
  apiVersion: rbac.authorization.k8s.io/v1
  kind: RoleBinding
  metadata:
    name: cilium-operator-ztunnel
    namespace: kube-system
    labels:
      app.kubernetes.io/part-of: cilium
+     helm.sh/chart: cilium-1.20.1
  roleRef:
    apiGroup: rbac.authorization.k8s.io
    kind: Role
    name: cilium-operator-ztunnel
  subjects:
  - kind: ServiceAccount
    name: "cilium-operator"
    namespace: kube-system
kube-system, cilium-secrets, Namespace (v1) has changed:
  # Source: cilium/templates/cilium-secrets-namespace.yaml
  apiVersion: v1
  kind: Namespace
  metadata:
    name: "cilium-secrets"
    labels:
      app.kubernetes.io/part-of: cilium
+     helm.sh/chart: cilium-1.20.1
    annotations:
kube-system, hubble-generate-certs, CronJob (batch) has changed:
  # Source: cilium/templates/hubble/tls-cronjob/cronjob.yaml
  apiVersion: batch/v1
  kind: CronJob
  metadata:
    name: hubble-generate-certs
    namespace: kube-system
    labels:
      k8s-app: hubble-generate-certs
      app.kubernetes.io/name: hubble-generate-certs
      app.kubernetes.io/part-of: cilium
+     helm.sh/chart: cilium-1.20.1
  spec:
    schedule: "0 0 1 */4 *"
    successfulJobsHistoryLimit: 3
    failedJobsHistoryLimit: 1
    concurrencyPolicy: Forbid
    jobTemplate:
      spec:
        template:
          metadata:
            labels:
              k8s-app: hubble-generate-certs
          spec:
            securityContext:
              seccompProfile:
                type: RuntimeDefault
            containers:
              - name: certgen
                image: "quay.io/cilium/certgen:v0.4.9@sha256:6213a4c54a1f36e14a9280765f058aaa2017550c28bc122f5b09ad146fd0da2b"
                imagePullPolicy: IfNotPresent
                securityContext:
                  capabilities:
                    drop:
                    - ALL
                  allowPrivilegeEscalation: false
                command:
                  - "/usr/bin/cilium-certgen"
                # Because this is executed as a job, we pass the values as command
                # line args instead of via config map. This allows users to inspect
                # the values used in past runs by inspecting the completed pod.
                args:
                  - "--ca-generate=true"
                  - "--ca-reuse-secret"
                  - "--ca-secret-namespace=kube-system"
                  - "--ca-secret-name=cilium-ca"
                  - "--ca-common-name=Cilium CA"
+                 - "--ca-enforce-validity-throughout-leaves-duration=true"
                env:
                  - name: CILIUM_CERTGEN_CONFIG
                    value: |
                      certs:
                      - name: hubble-server-certs
                        namespace: kube-system
                        commonName: "*.default.hubble-grpc.cilium.io"
                        hosts:
                        - "*.default.hubble-grpc.cilium.io"
                        usage:
                        - signing
                        - key encipherment
                        - server auth
                        - client auth
                        validity: 26280h
                      - name: hubble-relay-client-certs
                        namespace: kube-system
                        commonName: "*.hubble-relay.cilium.io"
                        hosts:
                        - "*.hubble-relay.cilium.io"
                        usage:
                        - signing
                        - key encipherment
                        - client auth
                        validity: 26280h
                  
            hostNetwork: false
            serviceAccountName: "hubble-generate-certs"
            automountServiceAccountToken: true
            restartPolicy: OnFailure
kube-system, hubble-generate-certs, Role (rbac.authorization.k8s.io) has changed:
  # Source: cilium/templates/hubble/tls-cronjob/role.yaml
  apiVersion: rbac.authorization.k8s.io/v1
  kind: Role
  metadata:
    name: hubble-generate-certs
    namespace: kube-system
    labels:
      app.kubernetes.io/part-of: cilium
+     helm.sh/chart: cilium-1.20.1

  rules:
    - apiGroups:
        - ""
      resources:
        - secrets
      verbs:
        - create
    - apiGroups:
        - ""
      resources:
        - secrets
      resourceNames:
        - hubble-server-certs
        - hubble-relay-client-certs
        - hubble-relay-server-certs
        - hubble-metrics-server-certs
        - hubble-ui-client-certs
      verbs:
        - update
    - apiGroups:
        - ""
      resources:
        - secrets
      resourceNames:
        - cilium-ca
      verbs:
        - get
        - update
kube-system, hubble-generate-certs, RoleBinding (rbac.authorization.k8s.io) has changed:
  # Source: cilium/templates/hubble/tls-cronjob/rolebinding.yaml
  apiVersion: rbac.authorization.k8s.io/v1
  kind: RoleBinding
  metadata:
    name: hubble-generate-certs
    namespace: kube-system
    labels:
      app.kubernetes.io/part-of: cilium
+     helm.sh/chart: cilium-1.20.1

  roleRef:
    apiGroup: rbac.authorization.k8s.io
    kind: Role
    name: hubble-generate-certs
  subjects:
  - kind: ServiceAccount
    name: "hubble-generate-certs"
    namespace: kube-system
kube-system, hubble-peer, Service (v1) has changed:
  # Source: cilium/templates/hubble/peer-service.yaml
  apiVersion: v1
  kind: Service
  metadata:
    name: hubble-peer
    namespace: kube-system
    labels:
      k8s-app: cilium
      app.kubernetes.io/part-of: cilium
      app.kubernetes.io/name: hubble-peer
+     helm.sh/chart: cilium-1.20.1

  spec:
    selector:
      k8s-app: cilium
    ports:
    - name: peer-service
      port: 443
      protocol: TCP
      targetPort: 4244
    internalTrafficPolicy: Local
kube-system, hubble-relay, Deployment (apps) has changed:
  # Source: cilium/templates/hubble-relay/deployment.yaml
  apiVersion: apps/v1
  kind: Deployment
  metadata:
    name: hubble-relay
    namespace: kube-system
    labels:
      k8s-app: hubble-relay
      app.kubernetes.io/name: hubble-relay
      app.kubernetes.io/part-of: cilium
+     helm.sh/chart: cilium-1.20.1

  spec:
    replicas: 1
    selector:
      matchLabels:
        k8s-app: hubble-relay
    strategy:
      rollingUpdate:
        maxUnavailable: 1
      type: RollingUpdate
    template:
      metadata:
        annotations:
        labels:
          k8s-app: hubble-relay
          app.kubernetes.io/name: hubble-relay
          app.kubernetes.io/part-of: cilium
+         helm.sh/chart: cilium-1.20.1
      spec:
        securityContext:
          fsGroup: 65532
          seccompProfile:
            type: RuntimeDefault
        containers:
          - name: hubble-relay
            securityContext:
              allowPrivilegeEscalation: false
              capabilities:
                drop:
                - ALL
+             readOnlyRootFilesystem: true
              runAsGroup: 65532
              runAsNonRoot: true
              runAsUser: 65532
              seccompProfile:
                type: RuntimeDefault
-           image: "quay.io/cilium/hubble-relay:v1.19.7@sha256:db4b384d0f6aba261e809d58bee54885c70a7e958173a125ebb215391af55e74"
+           image: "quay.io/cilium/hubble-relay:v1.20.1@sha256:59be0ae7d475ab9011a5e954618c0f27b5778b17140381425b308b55ba4917f4"
            imagePullPolicy: IfNotPresent
            command:
              - hubble-relay
            args:
              - serve
            ports:
              - name: grpc
                containerPort: 4245
            readinessProbe:
              grpc:
                port: 4222
              timeoutSeconds: 3
            # livenessProbe will kill the pod, we should be very conservative
            # here on failures since killing the pod should be a last resort, and
            # we should provide enough time for relay to retry before killing it.
            livenessProbe:
              grpc:
                port: 4222
              timeoutSeconds: 10
              # Give relay time to establish connections and make a few retries
              # before starting livenessProbes.
              initialDelaySeconds: 10
              # 10 second * 12 failures = 2 minutes of failure.
              # If relay cannot become healthy after 2 minutes, then killing it
              # might resolve whatever issue is occurring.
              #
              # 10 seconds is a reasonable retry period so we can see if it's
              # failing regularly or only sporadically.
              periodSeconds: 10
              failureThreshold: 12
            startupProbe:
              grpc:
                port: 4222
              # Give relay time to get it's certs and establish connections and
              # make a few retries before starting startupProbes.
              initialDelaySeconds: 10
              # 20 * 3 seconds = 1 minute of failure before we consider startup as failed.
              failureThreshold: 20
              # Retry more frequently at startup so that it can be considered started more quickly.
              periodSeconds: 3
            volumeMounts:
+           - name: tmp-volume
+             mountPath: /tmp
            - name: config
              mountPath: /etc/hubble-relay
              readOnly: true
            - name: tls
              mountPath: /var/lib/hubble-relay/tls
              readOnly: true
            terminationMessagePolicy: FallbackToLogsOnError
          
        restartPolicy: Always
        priorityClassName: 
        serviceAccountName: "hubble-relay"
        automountServiceAccountToken: false
        terminationGracePeriodSeconds: 1
        affinity:
          podAffinity:
            requiredDuringSchedulingIgnoredDuringExecution:
            - labelSelector:
                matchLabels:
                  k8s-app: cilium
              topologyKey: kubernetes.io/hostname
        nodeSelector:
          kubernetes.io/os: linux
        volumes:
+       - name: tmp-volume
+         emptyDir: {}
        - name: config
          configMap:
            name: hubble-relay-config
            items:
            - key: config.yaml
              path: config.yaml
        - name: tls
          projected:
            # note: the leading zero means this number is in octal representation: do not remove it
            defaultMode: 0400
            sources:
            - secret:
                name: hubble-relay-client-certs
                items:
                  - key: tls.crt
                    path: client.crt
                  - key: tls.key
                    path: client.key
                  - key: ca.crt
                    path: hubble-server-ca.crt
kube-system, hubble-relay, Service (v1) has changed:
  # Source: cilium/templates/hubble-relay/service.yaml
  kind: Service
  apiVersion: v1
  metadata:
    name: hubble-relay
    namespace: kube-system
    annotations:
    labels:
      k8s-app: hubble-relay
      app.kubernetes.io/name: hubble-relay
      app.kubernetes.io/part-of: cilium
+     helm.sh/chart: cilium-1.20.1

  spec:
    type: "ClusterIP"
    selector:
      k8s-app: hubble-relay
    ports:
    - protocol: TCP
      port: 80
      targetPort: grpc
kube-system, hubble-generate-certs-591c0822ff, Job (batch) has been removed:
- # Source: cilium/templates/hubble/tls-cronjob/job.yaml
- apiVersion: batch/v1
- kind: Job
- metadata:
-   name: hubble-generate-certs-591c0822ff
-   namespace: kube-system
-   labels:
-     k8s-app: hubble-generate-certs
-     app.kubernetes.io/name: hubble-generate-certs
-     app.kubernetes.io/part-of: cilium
- spec:
-   template:
-     metadata:
-       labels:
-         k8s-app: hubble-generate-certs
-     spec:
-       securityContext:
-         seccompProfile:
-           type: RuntimeDefault
-       containers:
-         - name: certgen
-           image: "quay.io/cilium/certgen:v0.4.9@sha256:6213a4c54a1f36e14a9280765f058aaa2017550c28bc122f5b09ad146fd0da2b"
-           imagePullPolicy: IfNotPresent
-           securityContext:
-             capabilities:
-               drop:
-               - ALL
-             allowPrivilegeEscalation: false
-           command:
-             - "/usr/bin/cilium-certgen"
-           # Because this is executed as a job, we pass the values as command
-           # line args instead of via config map. This allows users to inspect
-           # the values used in past runs by inspecting the completed pod.
-           args:
-             - "--ca-generate=true"
-             - "--ca-reuse-secret"
-             - "--ca-secret-namespace=kube-system"
-             - "--ca-secret-name=cilium-ca"
-             - "--ca-common-name=Cilium CA"
-           env:
-             - name: CILIUM_CERTGEN_CONFIG
-               value: |
-                 certs:
-                 - name: hubble-server-certs
-                   namespace: kube-system
-                   commonName: "*.default.hubble-grpc.cilium.io"
-                   hosts:
-                   - "*.default.hubble-grpc.cilium.io"
-                   usage:
-                   - signing
-                   - key encipherment
-                   - server auth
-                   - client auth
-                   validity: 26280h
-                 - name: hubble-relay-client-certs
-                   namespace: kube-system
-                   commonName: "*.hubble-relay.cilium.io"
-                   hosts:
-                   - "*.hubble-relay.cilium.io"
-                   usage:
-                   - signing
-                   - key encipherment
-                   - client auth
-                   validity: 26280h
-             
-       hostNetwork: false
-       serviceAccountName: "hubble-generate-certs"
-       automountServiceAccountToken: true
-       restartPolicy: OnFailure
+ 
kube-system, hubble-generate-certs-f2c174809d, Job (batch) has been added:
- 
+ # Source: cilium/templates/hubble/tls-cronjob/job.yaml
+ apiVersion: batch/v1
+ kind: Job
+ metadata:
+   name: hubble-generate-certs-f2c174809d
+   namespace: kube-system
+   labels:
+     k8s-app: hubble-generate-certs
+     app.kubernetes.io/name: hubble-generate-certs
+     app.kubernetes.io/part-of: cilium
+     helm.sh/chart: cilium-1.20.1
+ spec:
+   template:
+     metadata:
+       labels:
+         k8s-app: hubble-generate-certs
+     spec:
+       securityContext:
+         seccompProfile:
+           type: RuntimeDefault
+       containers:
+         - name: certgen
+           image: "quay.io/cilium/certgen:v0.4.9@sha256:6213a4c54a1f36e14a9280765f058aaa2017550c28bc122f5b09ad146fd0da2b"
+           imagePullPolicy: IfNotPresent
+           securityContext:
+             capabilities:
+               drop:
+               - ALL
+             allowPrivilegeEscalation: false
+           command:
+             - "/usr/bin/cilium-certgen"
+           # Because this is executed as a job, we pass the values as command
+           # line args instead of via config map. This allows users to inspect
+           # the values used in past runs by inspecting the completed pod.
+           args:
+             - "--ca-generate=true"
+             - "--ca-reuse-secret"
+             - "--ca-secret-namespace=kube-system"
+             - "--ca-secret-name=cilium-ca"
+             - "--ca-common-name=Cilium CA"
+             - "--ca-enforce-validity-throughout-leaves-duration=true"
+           env:
+             - name: CILIUM_CERTGEN_CONFIG
+               value: |
+                 certs:
+                 - name: hubble-server-certs
+                   namespace: kube-system
+                   commonName: "*.default.hubble-grpc.cilium.io"
+                   hosts:
+                   - "*.default.hubble-grpc.cilium.io"
+                   usage:
+                   - signing
+                   - key encipherment
+                   - server auth
+                   - client auth
+                   validity: 26280h
+                 - name: hubble-relay-client-certs
+                   namespace: kube-system
+                   commonName: "*.hubble-relay.cilium.io"
+                   hosts:
+                   - "*.hubble-relay.cilium.io"
+                   usage:
+                   - signing
+                   - key encipherment
+                   - client auth
+                   validity: 26280h
+             
+       hostNetwork: false
+       serviceAccountName: "hubble-generate-certs"
+       automountServiceAccountToken: true
+       restartPolicy: OnFailure

commit 0f0de82348bef5e217accb47383c7777586b24dd

@renovate renovate Bot changed the title Update Helm release cilium to v1.19.5 chore(deps): update helm release cilium to v1.19.5 Jul 5, 2026
@renovate
renovate Bot force-pushed the renovate/cilium-1.x branch from d57e47d to 2462cad Compare July 16, 2026 16:49
@renovate renovate Bot changed the title chore(deps): update helm release cilium to v1.19.5 chore(deps): update helm release cilium to v1.19.6 Jul 16, 2026
@renovate
renovate Bot force-pushed the renovate/cilium-1.x branch 2 times, most recently from 8c6e033 to 8de1ed2 Compare July 21, 2026 04:01
@renovate
renovate Bot force-pushed the renovate/cilium-1.x branch from 8de1ed2 to 21bf6a6 Compare July 29, 2026 19:01
@renovate renovate Bot changed the title chore(deps): update helm release cilium to v1.19.6 chore(deps): update helm release cilium to v1.20.0 Jul 29, 2026
@renovate
renovate Bot force-pushed the renovate/cilium-1.x branch 2 times, most recently from c67fd26 to ed25d93 Compare August 18, 2026 12:23
@renovate renovate Bot changed the title chore(deps): update helm release cilium to v1.20.0 chore(deps): update helm release cilium to v1.20.1 Aug 18, 2026
@renovate
renovate Bot force-pushed the renovate/cilium-1.x branch from ed25d93 to 36d1f96 Compare August 19, 2026 14:47
@renovate
renovate Bot force-pushed the renovate/cilium-1.x branch from 36d1f96 to 1b50616 Compare August 26, 2026 11:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants