Cilium v1.18.14 - Ignored Flags and AWS IPAM


Cilium v1.18.14 was published on 16 September 2026 at 01:53 UTC. It is a stable patch on the 1.18 line, not a release candidate, beta, or alpha. Agent and Hubble settings that parsed and then did nothing are the change most likely to alter a running cluster on upgrade.

The full release notes and downloads are on the GitHub release page.

Upstream PR 47635, backported as PR 48432, fixes five options that were accepted and ignored: vtep-sync-interval, enable-xt-socket-fallback, eni-delete-on-termination with a custom CNI configuration, the Helm value enableIdentityMark outside CNI chaining mode, and lb-retry-backoff-max. A stale value left because it looked like a no op starts to matter on upgrade.

The same backport carries upstream PR 47637. Four Hubble knobs never reached their sink. The notes do not name them.

Upstream PR 48391, in backport PR 48554, wires config setup for enable-non-default-deny-policies. The flag could be set while that policy mode never started. Confirm the mode if the flag is already on. Operator startup logs now follow the configured format (upstream PR 47890, backport PR 48019). Early lines that ignored it break JSON collectors.

AWS IPAM failed to allocate new IPs on nodes with prefix delegation once the subnet ran out of prefixes (upstream PR 48193, backport PR 48607). Those nodes stopped receiving addresses.

PR 48423 repairs routing rules on restored ENI endpoints when masquerading config changes. Restored endpoints could keep the old masquerade rules.

eni-delete-on-termination was ignored with a custom CNI configuration. ENI deletion on instance termination follows that flag starting with this patch.

NodePort egress could reuse a tuple still owned by a closed connection (upstream PR 48306, backport PR 48406). Short lived clients that recycle source ports collide with that closed flow.

Dumping BPF map events could crash the agent (upstream PR 48273, backport PR 48380). The node data path stays down until the agent is back.

IPV4_DIRECT_ROUTING on lo was wrong (upstream PR 46861, backport PR 48554, datapath/linux/config). Socket LB detached cgroup programs it did not own (upstream PR 44066, same backport) and now detaches only programs Cilium installed. Upstream PR 46232, backport PR 48295, removes Ingress host firewall policy from between RevSNAT and RevDNAT.

clustermesh-apiserver did not revoke stale etcd roles on configuration change (upstream PR 47915, backport PR 48216). Helm chart users are not affected, because the target etcd role never changes. A custom role you replace now loses the old grant, and a client that still needed it loses access.

The same backport strengthens validation of service backends ingested from Cluster Mesh (upstream PR 48015). The notes cite specially crafted values and name no CVE.

Hubble Relay could keep running on termination (upstream PR 47942, backport PR 48554). The pod stays Terminating, still answers queries, and drains wait. Relay now exits.

Upstream PR 48421, backport PR 48632, adds extension points for cilium-envoy DaemonSet readiness, liveness, and startup probes. The notes do not name the Helm keys.

Image bumps fill much of the rest. Go and docker.io/library/golang move to v1.25.14, base images to v1.26.8, quay.io/cilium/certgen to v0.4.11, cilium-cli to v0.20.0, and node-cache to 1.26.5. PR 48312 moves the proxy to Envoy 1.37.x. The quay.io/cilium/cilium-envoy updates end at v1.37.6-1789133542-cbec91f666af0bf742da986d43832932dbb26b82. google.golang.org/grpc moves to v1.83.2 in updates marked security (PR 48389, PR 48576). PR 48526 reverts an AKS CI change that disabled local accounts (PR 48443). That revert does not touch clusters you run.

The docs now say Gateway API needs iptables and the netfilter TPROXY modules when bpf.tproxy is disabled, and that disabled is the default (upstream PR 48428, backport PR 48554). The v1.18 IPsec documentation is removed (upstream PR 48224, backport PR 48406). The notes describe a docs deletion, not a datapath removal.

Feature probing could fail the verifier on detect support for FnSetRetval for program type CGroupSock (PR 48381). PR 48405 reverts the earlier have_set_retval fix and probes another way.

The notes list no Helm value rename and no schema migration. Ignored settings now run. Read them before the DaemonSet rolls.

  • The five ignored keys above, and enable-non-default-deny-policies, take effect. Remove values you did not intend.
  • AWS prefix delegation allocates again after prefixes run out. Restored ENI routes follow the current masquerade config.
  • NodePort releases tuples for closed connections. Socket LB detaches only its own cgroup programs. Host firewall policy no longer runs between RevSNAT and RevDNAT.
  • Custom Cluster Mesh etcd roles lose stale grants. Hubble Relay should exit on termination.
  • With bpf.tproxy left at the default, Gateway API nodes need iptables and the netfilter TPROXY modules.
  • Retest agent startup if probing has logged the CGroupSock verifier error.