Urgent.News

What's breaking now, across thousands of outlets.

Tech

Envoy Gateway 1.9.1 Tightens Security and Addresses a Difficult Upgrade Path

Envoy Gateway has released v1.9.1, a maintenance release that focuses heavily on security, upgrade reliability, and operational correctness following the broader v1.9 release. By Craig Risi

Envoy Gateway has released version 1.9.1, a maintenance update focused on improving security, upgrade reliability, and operational correctness following the v1.9 release. This update addresses several key changes, including the reversal of a timeout adjustment in v1.9.0 for the Secret Discovery Service (SDS) and Route Discovery Service (RDS) fetches.

The v1.9.0 version had set this timeout to zero, leading to potential issues where clusters would remain in a warming state waiting for missing secrets or endpoints, preventing CDS updates and delaying health checks. Version 1.9.1 restores the default 15-second timeout, aligning with the v1.8.x model.

One significant challenge for users upgrading from v1.9.0 is the handling of this timeout setting change. Envoy Gateway warns that modifying the SDS configuration during controller upgrades can cause Envoy to incorrectly initialize TLS listeners with certificates, resulting in TLS handshake failures. For users on v1.8.x, Envoy recommends a direct upgrade to v1.9.1, bypassing the problematic v1.9.0 version altogether.

Notably, existing v1.9.0 deployments require careful management, such as a rolling-update configuration to replace proxy pods quickly, which may lead to transient connection interruptions for long-lived WebSocket and gRPC connections.

Security enhancements are another focal point of this update. Envoy Gateway now enforces AES-256-GCM for OAuth2/OIDC session-cookie encryption, replacing the deprecated AES-256-CBC decryption path to mitigate a padding-oracle vulnerability (CVE-2026-47775). Existing sessions using the older encryption method will necessitate reauthentication following the upgrade.

Moreover, the release strengthens several security boundaries, including stricter validation of OIDC issuer URLs, preventing silent fallback from HTTPS to HTTP in OCI Wasm image pulls, and correcting a tenant-supplied Kubernetes security context issue that could override Envoy Gateway's hardened defaults.

Additionally, several non-security related fixes aim to enhance operational stability. OIDC flow cookies are now scoped to the redirect path, reducing unnecessary propagation of abandoned authentication tokens. Namespace label changes are automatically monitored to re-evaluate route acceptance without requiring controller restarts.

Hostname conflicts, controller crashes caused by missing optional Custom Resource Definitions (CRDs), and incorrect behavior during UDP route consistent hashing are also addressed. A notable addition is the inclusion of per-phase tracing spans for Gateway API and xDS translation, providing operators with granular insights into processing time spent in different stages such as listener processing, HTTP/gRPC routing, policy handling, and xDS validation.

This feature aids in diagnosing performance bottlenecks within the control plane, which is crucial for efficiently managing Kubernetes-native gateways at scale.

Written by urgent.news from InfoQ's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at infoq.com →

More in Tech

More from Friday 2 October →