Cilium v1.19.8 was published on 16 September 2026. On AWS, the operator failed to allocate new IPs to nodes with prefix delegation enabled once the subnet ran out of prefixes. The patch also applies five agent settings that were accepted and ignored, and it fixes a BPF map dump crash, NodePort egress tuple reuse, and Cluster Mesh backend validation.
The full release notes and downloads are on the GitHub release page.
AWS prefix delegation and ENI rules ¶
Prefix delegation gives a node a CIDR instead of one secondary IP per pod. Upstream cilium/cilium#48193, backported in cilium/cilium#48604, fixes allocation when that subnet has no prefixes left. Affected nodes stopped receiving new addresses. This operator build corrects that failure.
Restored ENI endpoints kept a bad routing rule after the masquerading configuration changed. cilium/cilium#48422 repairs the rule so the restored endpoint follows the current masquerade config.
eni-delete-on-termination was ignored with a custom CNI configuration. It is one of the five flags wired up in the next section. A custom CNI config that sets it now gets that termination behavior.
Settings that parsed and did nothing ¶
cilium/cilium#47635, backported as cilium/cilium#48433, lists five options the agent accepted and then dropped:
vtep-sync-intervalenable-xt-socket-fallbackeni-delete-on-terminationwith a custom CNI configuration- the
enableIdentityMarkHelm value outside CNI chaining mode lb-retry-backoff-max
If any of these are already set, the upgrade changes runtime behavior. VTEP sync honors the interval. The xtables socket fallback can turn on. Identity mark applies outside chaining mode. Load balancer retry backoff uses the configured maximum. Read the values before the DaemonSet rolls.
enable-non-default-deny-policies never had its config setup. cilium/cilium#48391, backported in cilium/cilium#48552, connects the flag. A value other than the default, left behind because nothing happened, will start to apply. Check Helm or the config map first.
Hubble matches that pattern. cilium/cilium#47637, in the same backport, fixes four knobs that never reach their sink. The notes do not name the four keys. Compare observed Hubble behavior with the config you think is loaded.
Operator startup logs now follow the configured log format (cilium/cilium#47890, backport cilium/cilium#48018). Scrapers that expect one shape from the first line get that shape during process start.
Datapath crashes, host firewall, and NodePort ¶
Dumping BPF map events could crash the agent (cilium/cilium#48273, backport cilium/cilium#48379). Those dumps are a normal debug step. This patch makes them survivable on 1.19.
Host firewall tolerates unknown conntrack protocols and relies on policy (cilium/cilium#47343, backport cilium/cilium#47620). Policy makes the decision. Retest host policy if an unknown protocol used to be dropped.
NodePort egress reused tuples from closed connections (cilium/cilium#48306, backport cilium/cilium#48413). The fix stops that reuse for clients that open and close quickly.
IPV4_DIRECT_ROUTING was selected wrongly on the lo device (cilium/cilium#46861, backport cilium/cilium#48552). Check direct routing nodes that hold addresses on lo.
socketlb detaches only cgroup programs Cilium owns (cilium/cilium#44066, backport cilium/cilium#48552). A restart no longer removes a program another controller attached.
cilium/cilium#46232, backported in cilium/cilium#48285, removes the ingress host firewall check between RevSNAT and RevDNAT on the NodePort path. Return traffic in that window skips that hook. Retest NodePort with host firewall if the hook was doing real filtering.
Cluster Mesh, DNS proxy, and Envoy probes ¶
Cluster Mesh service backend ingest validates values more strictly (cilium/cilium#48015, backport cilium/cilium#48413). The check targets specially crafted backend values.
clustermesh-apiserver failed to revoke stale etcd roles after a configuration change (cilium/cilium#47915, backport cilium/cilium#48214). Chart users are unaffected because the chart role never changes. A custom role rename could leave the old grant. Check etcd users if you set that role outside the chart.
standalone-dns-proxy returns an error when no endpoint is found (cilium/cilium#47791, backport cilium/cilium#48018).
Hubble Relay could stay up during termination (cilium/cilium#47942, backport cilium/cilium#48552). The process now stops with the pod.
cilium-envoy gains extension points for DaemonSet readiness, liveness, and startup probes (cilium/cilium#48421, backport cilium/cilium#48633). The notes do not list new defaults. Set an override only when the stock probe is wrong.
Go moves to 1.25.14 (cilium/cilium#48208). cilium-cli moves to v0.20.0 (cilium/cilium#48345). Base images move to v1.26.8 (cilium/cilium#48731). protobuf moves to v36.1. The rest is CI: golangci-lint skips the modernize linter (cilium/cilium#48399), AKS conformance nodes get a 64 GiB OS disk (cilium/cilium#48481), the cluster create step gets a timeout (cilium/cilium#48545), and the LLVM apt step is capped at 5 minutes (cilium/cilium#48069). That work does not change the datapath.
Upgrade notes ¶
No schema migration is documented. Ignored config becoming live is the surprise.
Record vtep-sync-interval, enable-xt-socket-fallback, eni-delete-on-termination, enableIdentityMark, lb-retry-backoff-max, and enable-non-default-deny-policies before rollout. Restore a default you did not mean to enable before the agent restarts.
Then check three paths. AWS nodes with prefix delegation on a subnet out of prefixes should get new IPs. Fast NodePort clients should not reuse a closed tuple. Host firewall should still match your flows, including unknown conntrack protocols and NodePort return traffic after the RevSNAT to RevDNAT hook was removed.
Custom etcd roles on Cluster Mesh should be checked for stale grants. Leave cilium-envoy probe overrides unset when the stock probes are enough.
Where to get it ¶
- Release notes and downloads: GitHub release page
- Repository: cilium/cilium
- Tag:
v1.19.8