Skip to content

v3.6.0

Latest

Choose a tag to compare

@shraddhabang shraddhabang released this 05 Oct 20:21
· 1 commit to main since this release
267b545

⚠️ Action Required

CRD Updates (Required)

There is no Gateway API graduation in this release -- the controller remains built against Gateway API CRDs v1.6.0 (unchanged from v3.5.0). As a safety measure, we recommend applying the latest AWS-vended CRDs before upgrading the controller.

Apply the latest AWS-vended CRD definitions:

Action :

  • kubectl apply -k "github.com/aws/eks-charts/stable/aws-load-balancer-controller/crds?ref=master"
  • kubectl apply -f https://raw.githubusercontent.com/kubernetes-sigs/aws-load-balancer-controller/refs/heads/main/config/crd/gateway/gateway-crds.yaml

🚀 What's New

Cross-account TargetGroupBinding -- AZ-aware IP registration (opt-in)
Cross-account TargetGroupBinding IP targets can now be registered with the pod's actual Availability Zone, improving cross-account zonal routing. Opt-in to preserve existing behavior by default. (#4877, @cqi1217)

frontend-nlb-status-only annotation for Ingress
New annotation to control whether the Ingress status hostname exposes only the frontend NLB -- fixes ExternalDNS record creation when fronting an ALB Ingress with an NLB. If the NLB is not yet provisioned, no hostname is written. (#4849, @dominikhei)

Gateway API customization for downstream/automode importers
Importers embedding the controller can now customize Gateway names, customize finalizers, and customize the Gateway controller wiring - enabling consumers to extend Gateway behavior. ReferenceGrant now uses the v1 apiVersion. (#4878, #4886, #4887, @zac-nixon)

🔧 Enhancements and Fixes

Gateway

  • Avoid DuplicateTargetGroupName for Services with multiple named target ports (#4876)
  • Use v1 for the ReferenceGrant apiVersion; allow finalizers to be customized (#4886)
  • Use a / separator in Gateway route-loader cache keys to avoid cache-key collisions (#4916)
  • Fix the deletion guard for Gateway TargetGroupConfigurations still referenced by TCPRoutes (#4802)
  • Ignore unpermitted cross-namespace TCPRoutes in the Gateway TGC deletion guard, so a TCPRoute without a ReferenceGrant can no longer pin another namespace's TGC finalizer (#4919)

**AWS Certificates Management **

  • Use the public Route 53 zone for Amazon-issued ACM DNS validation in split-horizon DNS setups (#4847)

Networking / TargetGroupBinding

  • Canonicalize CIDRs for security-group inbound rules to avoid spurious reconciliation failures (#4904)
  • Fix TargetGroupBinding networking with empty ports (#4909)

WAF

  • Ignore a WAF ACL set to an empty string (treat as unset) (#4888)

Controller / Informer robustness

  • Handle DeletedFinalStateUnknown tombstones in TypedInformer's DeleteFunc (#4879)
  • Make the pod informer transform idempotent so WatchList streaming sync no longer falls back to a full LIST (#4881)

Misc

  • Clearer OIDC permission messaging (#4912)

📖 Documentation Updates

  • Warn against manually deleting controller-generated TargetGroupBinding objects (#4902)
  • Document security/trust implications of AllowedRoutes.Namespaces.From: All (#4872)
  • Remove unsupported vpcId field from LoadBalancerConfiguration docs (#4760)
  • Fix wrong default for frontend-nlb-eip-allocations in annotation docs (#4871)
  • Fix ipam-ipv4-pool-id example plus tip/note block spacing (#4752)

What's Changed

  • Document security/trust implications of AllowedRoutes.Namespaces.From… by @wweiwei-li in #4872
  • docs: Remove vpcId from LoadBalancerConfiguration documentation by @dominikhei in #4760
  • fix(gateway): avoid DuplicateTargetGroupName for Services with multiple named targetPorts by @legal90 in #4876
  • fix: ipam-ipv4-pool-id example, tip and note block spacing by @wind0r in #4752
  • feat(gateway custom): allow importers to customize gateway names by @zac-nixon in #4878
  • fix: handle DeletedFinalStateUnknown tombstones in TypedInformer's DeleteFunc by @ginbear in #4879
  • Make pod informer transform idempotent so WatchList streaming sync does not fall back to full LIST by @yash97 in #4881
  • use v1 for referencegrant apiversion, allow finalizers to be customized for gateway api by @zac-nixon in #4886
  • refactor: Allow automode controllers to customize the gateway controller by @zac-nixon in #4887
  • fix(waf): ignore waf acl set to empty string by @zac-nixon in #4888
  • refactor: making tests configurable to run on eks auto framework by @jupdec in #4891
  • test: mirror UDP/GRPC test images to networking-e2e-test-images by @jupdec in #4894
  • test/gateway: make e2e suite partition-aware and register ECR tag resolver by @jupdec in #4908
  • chore: OIDC permission messaging by @zac-nixon in #4912
  • fix: canonicalize CIDRs for security group inbound rules to avoid reconciliation failures by @bobert-2 in #4904
  • test: default GRPC/UDP images to public ECR to fix the tests by @shraddhabang in #4911
  • Fix TGB networking with empty ports by @dlanov in #4909
  • docs: warn against manually deleting controller-generated TargetGroupBinding by @shashankvarma499 in #4902
  • Register cross-account TargetGroupBinding IP targets with the pod's availability zone (opt-in) by @cqi1217 in #4877
  • Fixed wrong default for frontend-nlb-eip-allocations in annotation docs by @dominikhei in #4871
  • Added frontend-nlb-status-only annotation to fix ExternalDNS record creation when using a frontend NLB by @dominikhei in #4849
  • fix: use '/' separator in Gateway route-loader cache keys to avoid co… by @wweiwei-li in #4916
  • fix: use public Route 53 zone for Amazon-issued ACM DNS validation in split-horizon DNS by @niv1612 in #4847
  • Fix deletion guard for Gateway TargetGroupConfigurations still referenced by TCPRoutes by @immanuwell in #4802
  • fix: ignore unpermitted cross namespace TCPRoutes in gateway target TGC deletion guard by @shraddhabang in #4919
  • cut v3.6.0 release by @shraddhabang in #4921

New Contributors

Full Changelog: v3.5.0...v3.6.0