{
  "id": 11643329,
  "title": "Istio 1.31 Adds Agentgateway Waypoints and Moves Release Artifacts off Google Cloud",
  "url": "https://urgent.news/2026/10/03/istio-1-31-adds-agentgateway-waypoints-and-moves-release-artifacts",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-03T08:30:00.000Z",
  "source": {
    "name": "InfoQ",
    "slug": "infoq",
    "url": "https://www.infoq.com/news/2026/10/istio-1-31-agentgateway/"
  },
  "original_language": "en",
  "account": "Istio 1.31, released on August 31st, introduces a new feature called agentgateway, which functions as a Layer 7 waypoint proxy in an ambient mesh. This is achieved through the istio-agentgateway-waypoint GatewayClass. The release also marks the discontinuation of publishing container images and Helm charts to Google Cloud, as teams utilizing gcr.io/istio-release, registry.istio.io, or the Google-hosted Helm repository are encouraged to migrate before an upcoming outage test on October 13th, in preparation for their retirement in December.\n\nIstio 1.31.0 supports Kubernetes versions 1.32 to 1.36. The waypoint support is built upon the experimental gateway-only integration introduced in Istio 1.30. Agentgateway, a Rust data plane developed by Solo.io and donated to the Linux Foundation, is capable of handling protocols such as the Model Context Protocol in addition to standard HTTP traffic. Istio 1.31 also addresses issues related to ListenerSet handling and mTLS connectivity for agentgateway backends.\n\nThe release includes an alpha feature for traffic shifting between waypoints, which allows a service or namespace to designate a canary alongside its primary waypoint using the use-waypoint-canary label. A configurable share of new in-mesh connections can then be directed to the canary via the use-waypoint-canary-weight annotation. However, it is important to note that long-lived connections will not be migrated, potentially causing delays in observed traffic split. Additionally, Istio 1.31.1, released on September 21st, rectifies an issue where agentgateway waypoints referenced solely as canaries were not properly equipped with the routes and policies of the referencing services, leading to rejected shifted connections. The patch also incorporates security enhancements and corrects ALLOW_ANY_DYNAMIC_DNS forwarding in IPv6-only clusters.\n\nTwo notable traffic management enhancements for large meshes are introduced in Istio 1.31. A new zoneAwareLbSetting field on DestinationRule and MeshConfig enables Envoy to route to endpoints within the same availability zone as the downstream proxy, only spilling over to other zones when local capacity is exhausted. This decision is made by Envoy dynamically, rather than being dictated by static percentages required by the localityLbSetting. Furthermore, the ALLOW_ANY_DYNAMIC_DNS outbound mode resolves hostnames from the HTTP Host header at request time, obviating the need to create a ServiceEntry for every external destination.\n\nOn the security front, a fips-140-3 value for the COMPLIANCE_POLICY environment variable enforces the use of TLS versions 1.2 or later, FIPS-compliant cipher suites, and the P-256 and P-384 curves. The release notes specify that Go components must be compiled with Go 1.24 or later using GOFIPS140=v1.0.0 or a subsequent validated version; merely setting the runtime policy is insufficient. New trustDomains and notTrustDomains fields on AuthorizationPolicy enable teams to match or exclude requests based on the trust domain extracted from the peer certificate.\n\nThe shift in hosting infrastructure necessitates action from teams relying on the existing repositories. In a blog post on August 21st, Steven Jin of Microsoft and Keith Mattix of Solo.io announced Istio's migration of all infrastructure from Google Cloud Platform to Amazon Web Services due to changes in their funding model. The next scheduled outage test will disable the old endpoints between 15:00 and 18:00 UTC on October 13th; the final test will run from 15:00 to 15:00 UTC on December 8th and 9th. Teams responsible for verifying image signatures also need to account for key rotation. Istio-key.pub is applicable to Istio 1.31.0, while Istio-key-v2.pub will be used starting with 1.31.1. When asked about the choice of Docker Hub over GHCR, Jin attributed it to GHCR's undocumented limits, adding that Istio's current usage would likely surpass those constraints.",
  "summary": "Istio 1.31 adds agentgateway waypoints in ambient mode, with a canary configuration fix included in 1.31.1. It also ends the publication of images and Helm charts to Google Cloud, requiring repository migration ahead of the 13 October outage test and signing-key updates for teams verifying images. By Mark Silvester",
  "key_points": [
    "Istio 1.31 introduces agentgateway as a Layer 7 waypoint proxy",
    "Release moves container images and Helm charts off Google Cloud",
    "Istio 1.31 adds traffic shifting between waypoints for canary deployments"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}