Cilium v1.20.2 was published on 16 September 2026 as a stable patch on the 1.20 line. The failure with the widest blast radius is a cilium-agent crash, fatal error: concurrent map iteration and map write, when an endpoint policy is recomputed while incremental policy map edits run at the same time. Named port policies under pod churn are the common trigger.
The full release notes and downloads are on the GitHub release page.
Policy map crash and stale revisions ¶
The crash is concurrent map access inside the agent. One goroutine iterates the policy map while another writes incremental updates for the same endpoint. The process aborts, and the node has no local agent until it restarts. A second crash while dumping bpf map events is fixed in the same tag. A third crash happens at startup in ENI IPAM mode when ipv4NativeRoutingCIDR is a secondary VPC CIDR association. Those nodes failed during agent startup.
A pod created immediately after a network policy change could report a stale policy revision for up to two minutes. Concurrent policy updates for a new endpoint are preserved across endpoint creation. Identities could linger for twice the expected interval. Expiry follows the configured interval after this patch.
Two flags in the same area were not applied. enable-non-default-deny-policies had no config setup, so the agent accepted the flag and left the feature inactive. With policy-deny-response set to icmp, egress policy deny metrics stopped. Those metrics are emitted again.
AWS ENI prefix allocation ¶
In ENI IPAM mode the operator released prefix IPs as individual IPs, including prefixes still assigned on the node. Nodes using prefix delegation hit a second bug: once a subnet ran out of prefixes, the operator failed to allocate new IPs. Both are fixed. In use prefixes stay allocated, and those nodes can receive new IPs on a subnet that has no prefixes left.
IPv6 routing on ENI interfaces was wrong for the health check endpoint, the ingress address, and IPSec. Restored ENI endpoints also installed the wrong routing rules after masquerade configuration changed. EC2 metadata was fetched on every CiliumNode update. The operator now reads IMDS once per node, which lowers IMDS load and makes ENI registration more resilient. A failed IPAM node watcher is fatal again, so the operator process exits when that watch fails.
Gateway API, BGP, and DSR ¶
gateway-api gained a node label selector for Gateways that run with hostNetwork enabled. That is the one minor change in the notes.
A static IPv6 Gateway address was reported unusable when the Gateway and the Service used different textual forms of the same address. The address is accepted when the spelling differs. HTTPRoute ExternalAuth fails closed when its backend reference is invalid or cannot be resolved. The route denies traffic until that reference resolves.
BGP defaultGateway peer discovery could pick a default route from a table other than the main table, including the default via cilium_host route in the from-proxy table. Discovery now uses the node’s real default gateway. L2Announcement dropped traffic when externalTrafficPolicy was Local. NodePort could reuse an egress tuple from a closed connection. Selection skips those closed tuples.
Recovery of TCP connections to a DSR enabled Service is more reliable. With --bpf-lb-dsr-dispatch set to opt or geneve and --enable-pmtu-discovery enabled, the ICMP error sent when a forwarded DSR request exceeds the interface MTU carried the wrong outer source IP. That source address is corrected.
Hubble Relay exits during termination. Four Hubble config knobs never reached their sink. The summary in the v1.20.2 release notes does not name the four keys.
Upgrade notes ¶
Clusters created on v1.15 or earlier failed to upgrade because CiliumNodeConfig v2alpha1 had been dropped. v1.20.2 fixes that upgrade failure. Retry on this tag if the upgrade stopped on that CRD.
Five options were accepted and silently ignored. They apply after this patch:
vtep-sync-intervalenable-xt-socket-fallbackeni-delete-on-termination, when a custom CNI configuration is in use- Helm value
enableIdentityMark, outside CNI chaining mode lb-retry-backoff-max
eni-delete-on-termination under a custom CNI configuration deletes ENIs on termination. Confirm that value before rollout if those ENIs were meant to outlive the instance.
The BPF NAT engine drops ICMP error packets whose inner packet is fragmented TCP, UDP, or SCTP. Those ICMP errors stop in the NAT path.
node-init starts on GKE 1.36.2-gke.2064000 by reading the kubelet path. Container runtime configuration on that build did not identify the node, so startup failed. Multiple LocalRedirectPolicy regressions are fixed in one backport. The summary does not list each regression.
Where to get it ¶
- Release page: Cilium v1.20.2
- Repository: cilium/cilium
- Tag:
v1.20.2