The module lifecycle stage: Preview
The module has requirements for installation
v0.16.0
Highlights
- Added an allowlist of original client IPs, at the instance and route level, next to the existing allowlists of TCP peers
- The source IP allowlist and basic authentication annotations now apply to GRPCRoute objects
- Basic authentication supports bcrypt password hashes
New Features
- Added the
originalIPDetection.whitelistOriginalIPRangeparameter to the ALBInstance and ClusterALBInstance resources, which allows requests only from the listed original client IPs. The original client IP is the address from therealIPHeaderheader of a request that comes from asetRealIPFromaddress, and the address of the TCP peer for any other request, so a client connecting directly cannot spoof it. The check is independent ofacceptRequestsFromand of basic authentication, and a request from another original client IP is rejected with403 - Added the
alb.network.deckhouse.io/whitelist-original-ip-rangeannotation for HTTPRoute and GRPCRoute objects, which replacesoriginalIPDetection.whitelistOriginalIPRangeof the instance for the route - The
alb.network.deckhouse.io/whitelist-source-range,alb.network.deckhouse.io/basic-auth-secretandalb.network.deckhouse.io/satisfyannotations now apply to GRPCRoute objects as well as HTTPRoute ones. A Secret in another namespace needs a ReferenceGrant from the route kind, so a ReferenceGrant from HTTPRoute does not authorize a GRPCRoute - Basic authentication, set up by the
basicAuthparameter of an instance or by thealb.network.deckhouse.io/basic-auth-secretannotation, accepts bcrypt ($2a$,$2b$,$2y$) htpasswd entries with a cost of at most 10, next to{SHA}ones. bcrypt is CPU-intensive: successful checks are cached, but every failed attempt costs a full check on the proxy, so prefer{SHA}where untrusted clients can reach a route
Improvements
- The admission webhook rejects HTTPRoute and GRPCRoute objects whose
alb.network.deckhouse.io/whitelist-source-rangeoralb.network.deckhouse.io/whitelist-original-ip-rangeannotation lists a value that is not an IP address or a CIDR range; an emptywhitelist-source-rangeis still accepted - The
pilot-discovery xds-debuginteractive view shows the settings of the basic authentication and source IP filter (source ranges, satisfy mode, realm) instead of an unknown type, with the htpasswd data redacted - The descriptions of
acceptRequestsFromand of thealb.network.deckhouse.io/whitelist-source-rangeannotation state that they match the address of the TCP peer, never request headers, and how they relate to the new original client IP allowlists
Fixes
- An
alb.network.deckhouse.io/whitelist-source-rangeannotation with no valid range no longer opens the route to every source: such a route now rejects requests from every source. A route stored with such an annotation before the upgrade starts rejecting all requests and can be updated only once the annotation is corrected - Basic authentication data with Windows (CRLF) line endings or with a duplicate user no longer makes the proxy reject the whole configuration update and keep serving the previous configuration; such data is not used, and the route or instance rejects every request until it is corrected
- A ListenerSet deleted after its routes no longer remains in the Gateway API graph shown in the Console, and ListenerSets without routes are now shown in it
- The
alb.network.deckhouse.io/compressionannotation now supports theminContentLengthfield, the smallest response size to compress, in bytes (30by default). Envoy applies one size per listener, the biggest one its routes set, so a route whose size differs from that of another route of the same host is accepted with a warning - The
pilot-discovery xds-debuginteractive view no longer fails to show the Envoy configuration when a route has thealb.network.deckhouse.io/compressionannotation
v0.15.1
Fixes
- The
alb.network.deckhouse.io/compressionannotation now supports theminContentLengthfield, the smallest response size to compress, in bytes (30by default). Envoy applies one size per listener, the biggest one its routes set, so a route whose size differs from that of another route of the same host is accepted with a warning - The
pilot-discovery xds-debuginteractive view no longer fails to show the Envoy configuration when a route has thealb.network.deckhouse.io/compressionannotation
v0.15.0
Highlights
- Added the
retriesandcompressionroute annotations - The controller keeps validating Gateway API resources while the Gateway API CRDs in the cluster differ from the bundled ones
- Fixed connection draining when a proxy pod stops
New Features
- Added the
alb.network.deckhouse.io/retriesannotation for HTTPRoute and GRPCRoute objects, which sets the number of retries, the timeout of each attempt, and the failures to retry on - Added the
alb.network.deckhouse.io/compressionannotation for HTTPRoute objects, which compresses responses withgzip,brotliorzstd, whichever the client accepts - Added the
envoyDrainTimeoutparameter to the ALBInstance and ClusterALBInstance resources, which sets how long, in seconds, Envoy drains connections when a proxy pod stops or a listener changes (from 1 to 240,45by default) - Added the
status.inletfield and the Inlet column to the ALBInstance and ClusterALBInstance resources
Improvements
- While the Gateway API CRDs in the cluster differ from the bundled ones, the controller serves its validating webhooks instead of blocking at startup, so Gateway API resources are validated rather than rejected; it starts reconciling once the CRDs match and reports NotReady until then
- Standby controller replicas keep their caches in sync, so a replica that takes over starts reconciling at once
- When the controller cannot read the Gateway of a route, it determines whether the Gateway is an ALB one from the ALBInstance and ClusterALBInstance resources, and warns about the checks it has to skip
- Increased the termination grace period of proxy pods to 300 seconds to fit the connection drain
Fixes
- Fixed connection draining, so a stopping proxy pod no longer waits until its termination grace period runs out, as the connection the agent keeps open to scrape Envoy metrics no longer counts as an active one
- Validation now applies only to routes of ALB Gateways, so routes of other Gateways are no longer rejected or warned about because of ALB annotations
- TCPRoute and UDPRoute objects of version
v1alpha2are no longer rejected by validation - ALBInstance no longer gets
inlet.clusterIPandinlet.loadBalancersettings filled in for the inlet type it does not use; unset ports of both inlet types are80and443
Security Updates
- Updated Coraza WAF to 3.8.1 to fix CVE-2026-41510, CVE-2026-41504 and CVE-2026-41508
v0.14.2
Fixes
- The default TLS secret
d8-alb/d8-default-gateway-tlsno longer requires a ReferenceGrant for ALBInstances outside thed8-albnamespace
v0.14.1
Fixes
- Fixed auth-headers annotations
v0.14.0
Highlights
- Added support for external authentication annotations on GRPCRoute objects
- Updated Envoy to 1.38.4
New Features
- Added support for external authentication annotations on GRPCRoute objects (all
auth-*annotations exceptauth-signin) - The
auth-request-headersannotation now also derivesX-Original-MethodandX-Auth-Request-Redirectfor the authentication subrequest, in addition toX-Original-URL - Added an AGE column to the ALBInstance and ClusterALBInstance resources
Documentation
- Updated documentation
Dependencies
- Updated Envoy to 1.38.4
v0.13.0
Highlights
- Added new HTTPRoute annotations for per-source-IP rate limiting and upstream load balancing
New Features
- Added HTTPRoute annotations for per-source-IP request rate limiting
- Added an HTTPRoute annotation to select the upstream load balancing policy (round-robin or random)
Documentation
- Updated documentation
v0.12.0
Highlights
- Added new HTTPRoute annotations to configure external authentication settings (headers and client TLS)
New Features
- Added new HTTPRoute annotations to configure external authentication settings (headers and client TLS)
Documentation
- Updated documentation
v0.11.1
Fixes
- Fixed HTTP/2 connection coalescing issue when using overlapping certificates
- Instance validation was slightly relaxed to comply with Kubernetes patterns
v0.11.0
Highlights
- Removed auto-provisioning of ReferenceGrant objects
- Added resource clean-up when the module is disabled
New Features
- Added resource clean-up when the module is disabled
Fixes
- Added missing anti-affinity rules
- Default resource requests were updated
- Fixed bug when using multiple certificates for one listener
Breaking Changes
- Removed auto-provisioning of ReferenceGrant objects
Documentation
- Updated documentation
v0.10.0
Highlights
- Added support for Inference Pool for LLM routing
- Module was refactored to prevent yaml injections
New Features
- Added support for Inference Pool for LLM routing
Fixes
- Module was refactored to prevent yaml injections
Documentation
- Updated documentation
v0.9.2
Fixes
- Gateway controller uses local (in terms of module) kube-rbac-proxy image
v0.9.1
Fixes
- Namespace pod policy action is set to “warn” to prevent rollout deadlocks
v0.9.0
Highlights
- Added a built-in ingress2gateway utility that can be enabled in the module configuration
New Features
- Added the
loadBalancerSourceRangesparameter for the LoadBalancer inlet - Implemented listener validation in gateway-controller
- Added SecurityPolicyException resources for compliance with the Restricted profile of the Pod Security Standards (PSS)
Fixes
- Fixed listener validation
Documentation
- Added a migration section
Dependencies
- Updated Go to 1.26.6
v0.8.1
Documentation
- Fixed typos in documentation
v0.8.0
Highlights
- Added an Ingress-to-Gateway API migration helper that bridges cert-manager Gateway API HTTP-01 solver HTTPRoutes to temporary Ingress objects served by ingress-nginx
- Added Prometheus metrics and a Grafana dashboard for GeoIP statistics
- Introduced Community Edition limits: namespaced ALBInstance is unavailable in CE, and ModSecurity is disabled in CE
New Features
- Added Gateway API graph exporting server for visualizing objects in Console
- Implemented Gateway frontend and backend TLS settings
- Added support for a custom CA when downloading GeoIP databases via geoproxy
- Restricted ListenerSet listeners on managed Gateways: HTTP/HTTPS/TLS ports must match the parent Gateway; TCP/UDP listeners are disallowed
Fixes
- Fixed Proxy Protocol when using additional UDP ports
Security Updates
- Fixed CVEs
Documentation
- Updated documentation
v0.7.6
Fixes
- Fixed using externalname type services as backends
v0.7.5
Fixes
- Fixed the CSE build
v0.7.4
Fixes
- Fixed HTTPRoute validation for routes with the same path and different match conditions
v0.7.3
Security Updates
- Added VEX for GO-2026-5932 CVE
- Fixed CVEs
v0.7.2
New Features
- Added route conflict validation to prevent overlapping HTTPRoute paths, GRPCRoute service/methods, TCPRoute and UDPRoute attachments, and TLSRoute hostnames on the same Gateway or ListenerSet section
- Added ListenerSet create/update validation to reject listener changes that would make attached routes conflict
Documentation
- Updated documentation
v0.7.1
New Features
- Added missing loadBalancerClass parameter
v0.7.0
New Features
- Added support for UDPRoutes
- Added changelogs
Dependencies
- Updated Gateway API CRDs to 1.6
v0.6.0
Highlights
- Added graceful shutdown for proxies
- Updated Envoy and Istio versions
- Fixed admission webhook annotation priority
New Features
- Added graceful shutdown for proxies — after receiving SIGTERM/SIGKILL, proxies continue to operate normally for an extra 60 seconds. During this graceful shutdown, the /healthz endpoint returns 503, signaling to the load balancer that traffic has to move away from the instance. After 60 seconds, proxies are terminated as usual, draining connections and shutting down.
Fixes
- Fixed admission webhook annotation priority to comply with latest DKP requirements
- Fixed tests and documentation
Dependencies
- Updated Envoy and Istio versions to 1.38.3 and 1.30.2 respectively
v0.5.0
Highlights
- Backend TLS settings annotation now supports Kubernetes Secrets
- Header modification annotations support regex capture groups
- Added proxy-buffer-size annotation
- Added TCP and TLS logs and metrics
New Features
- Backend TLS settings annotation now supports Kubernetes Secrets so that backends can be accessed using TLS with the data from a Kubernetes secret
- Header modification annotations now support regex capture groups so that an HTTP header’s value can be constructed based on the Path parameter
- Added proxy-buffer-size annotation to limit the size of the upstream HTTP headers
- Added TCP and TLS logs and metrics to improve observability
v0.4.4
Highlights
- Fixed RBAC permissions
Fixes
- Fixed RBAC permissions
v0.4.3
Highlights
- Relaxed ALB CRDs validation for ports
Improvements
- Relaxed ALB CRDs validation regarding ports to allow defining pure TCP load balancing scheme (without http/https ports at all)
v0.4.2
Highlights
- Disabled TLS autodetection
- Fixed default gateway election process
Fixes
- Fixed default gateway election process
Breaking Changes
- Disabled TLS autodetection inherited from Istio.
v0.4.1
Highlights
- Fixed Gateway lifecycle
Fixes
- Fixed deletion of the default gateway from ConfigMap so that if a default Deckhouse gateway is deleted, DKP deletes relevant resources.
v0.4.0
Highlights
- Moved auxiliary proxy sockets to localhost
Improvements
- Moved auxiliary proxy sockets to localhost to not expose extra information
Documentation
- Updated documentation
v0.3.0
Highlights
- Added idle-timeout annotation
- Security CVE patches in dependencies
New Features
- Added idle-timeout annotation to control the amount of time an open session can stay up without exchanging packets
Security Updates
- Applied security CVE patches
v0.2.5
Highlights
- Added gateway cleanup procedure
New Features
- Added gateway cleanup procedure to improve Gateways lifecycle.
v0.2.4
Highlights
- Fixed backend-tls-settings annotation handling on backend restart
Fixes
- Fixed backend-tls-settings annotation on backend restart. Previously it would break occasionally on config reload.
Documentation
- Docs updated
v0.2.3
Highlights
- Fixed proxy mount points in containers
Fixes
- Fixed mount points in the proxy containers
v0.2.2
Highlights
- Added CSE edition packaging
New Features
- Added CSE edition packaging
v0.2.0
Highlights
- Web Application Firewall (ModSecurity) support was added
- OpenTelemetry (OTLP) Tracing export was added
- Envoy updated to 1.37.3
- GeoIP database support extended to include the license parameter
New Features
- Added Web Application Firewall (ModSecurity) support using Coraza WAF project
- Added OpenTelemetry (OTLP) Tracing export parameters
- GeoIP database settings now include license parameter so the module can download GeoIP databases on its own
Improvements
- Trimmed overly long generated resource names and labels
- Improved Grafana dashboard for Envoy
Fixes
- Fixed CRD version preflight checks
Documentation
- Documented HTTP/3 support
Dependencies
- Updated Envoy to 1.37.3
v0.1.0
Highlights
- Combined whitelist, basic auth, and satisfy logic into a single auth plugin
- Added CRD version preflight check in the gateway controller
- Resource management settings for the controller
New Features
- Added auth plugin combining whitelist, basic auth, and satisfy logic via an annotation
- CRD version preflight check in the gateway controller was added to check if the cluster’s CRDs comply with what ALB expects
- Added resource management settings to the controller
Improvements
- Optimized container image builds to reduce cache usage and size
- Refactored internal components
Documentation
- Updated documentation
v0.0.0
Highlights
- Initial ALB module release on Gateway API 1.5
- GeoIP database support is added to the ALB controller
- Istio sidecar integration and PROXY protocol support added
- Global basic authentication and IP whitelist settings added
- Vertical Pod Autoscaler mode for controllers added
New Features
- GeoIP database support is added to the ALB controller
- Added ListenerSet validations
- Implemented extension reference filters
- Added service-upstream annotation to access backends via Kubernetes service
- Enabled Istio sidecar integration if Istio module is enabled
- Added tls-disable-protocol annotation to be able to configure accessing backends using TLS
- Added extended request histogram metrics
- Added fallback TLS certificate to present the default certificate if the application certificate isn’t available
- Added hash-key annotation to be able to configure session affinity when accessing backends
- Added proxy-body-size annotation
- Added auth response headers support to support Dex authorization scheme
- Implemented default Deckhouse gateway feature for discovering the default gateway
- Added a cookie-based session affinity annotation
- Added global basic authentication settings
- Added PROXY protocol support per ClusterALBInstance/ALBInstance
- Added default access logging configuration
- Added IP whitelist annotation
- Added proxy log level configuration
- Added limit-rps annotation
- Added request-body-buffer-limit annotation
- Added URL rewrite annotation
- Support of multiple TLS certificates per listener is added
- Implemented Vertical Pod Autoscaler resource management mode
- Added Grafana dashboard for the proxy
Improvements
- Updated Grafana dashboard metrics
- Added warning when multiple default ALB Istio instances exist
- Improved default gateway name validation
- Switched proxy base image to distroless
Fixes
- Fixed minor bugs
- Fixed Dex re-login by forcing HTTP/1.1 in Istiod
- Fixed gateway overlap validation
- Fixed Pilot crash on startup
- Fixed monitoring dashboard resources
- Fixed Envoy proxy crash
- Fixed CRD definitions
Dependencies
- Upgraded to Gateway API 1.5