Skip to content

Releases: tigera/operator

v1.44.0

Choose a tag to compare

@marvin-tigera marvin-tigera released this 01 Oct 23:06
c7be27a

01 Oct 2026

Included Calico versions

Calico version: v3.33.0
Calico Enterprise version: v3.24.0-1.0

Enhancements

  • Reduces the time calico-node takes to be marked ready after starting, which shortens calico-node rolling updates on large clusters. #5209 (@caseydavenport)
  • Added a FelixIPIPOnly value to Installation clusterRoutingMode, selecting Felix for the cluster routes of IPIP IP pools and confd/BIRD for those of unencapsulated IP pools. #5150 (@nelljerram)
  • Reduced operator memory usage by stripping managedFields from cached objects. #5108 (@alexh-tigera)

Breaking changes

  • The LogCollector now deploys fluent-bit (calico-fluent-bit in calico-system) in place of fluentd, with operator-rendered configuration and automatic migration of fluentd tail positions. #4910 (@hjiawei)
  • Breaking changes and behavior changes in this migration:
    • The tigera-fluentd namespace is removed; all log-collector resources are renamed and move to calico-system (DaemonSet/container calico-fluent-bit, TLS secret calico-fluent-bit-tls). Tooling referencing the old names (e.g. kubectl logs -c fluentd) must be updated.
    • The LogCollector fluentdDaemonSet override field is deprecated in favor of calicoFluentBitDaemonSet; existing overrides (including legacy container names) keep applying for one release.
    • User flow/DNS log filters: the fluentd-filters ConfigMap is no longer read. Filters must be recreated under the new fluent-bit-filters name as fluent-bit YAML filter lists; unparseable content raises a TigeraStatus warning while log shipping continues.
    • Log-collector metrics are now fluent-bit's native Prometheus metrics (fluentbit_* metric names, plain HTTP on port 2020 at /api/v2/metrics/prometheus, guarded by NetworkPolicy). Dashboards and alerts keyed on fluentd_* metric names or the 9081 mTLS endpoint must be updated.
    • S3 archive object keys change from fluentd's flat layout (/flows20260101_.gz) to directory-style keys (/flows/20260101_.gz), with non-cluster-host flows archived under their own non_cluster_flows/ directory. Downstream tooling anchored to the old flat patterns needs a one-time update.
    • Log buffering moves from fluentd's in-memory buffers to fluent-bit filesystem storage under /var/log/calico/calico-fluent-bit/ on each node: buffered-but-unsent chunks now survive pod restarts, and host disk usage grows accordingly (capped per output by storage.total_limit_size).
    • Syslog forwarding no longer applies fluentd's 1024-byte packet-size default. When spec.additionalStores.syslog.packetSize is unset, the fluent-bit syslog output uses its own default for the RFC5424 format the operator renders (2048 bytes), reducing truncation of longer log lines; set packetSize to cap the message size explicitly (messages above the cap are truncated).

Bug fixes

  • Fixes the operator leaving stale cluster route programming settings behind in FelixConfiguration and BGPConfiguration when the Installation stops asking for them. #5324 (@caseydavenport)
  • Fixes the operator leaving Felix's eBPF kube-proxy health port pinned at zero after a cluster leaves eBPF mode. #5324 (@caseydavenport)
  • The operator now records the FelixConfiguration and BGPConfiguration fields it owns in managed fields, and removes the annotations earlier versions used for the same purpose. #5324 (@caseydavenport)
  • Fixes a datastore migration becoming permanently stuck if the calico-kube-controllers pod is lost while the migration is in progress. #5318 (@caseydavenport)
  • Fix calico-node CrashLoopBackOff during upgrade when the operator set bpfKubeProxyHealthzPort=0 before all nodes were running a version that accepts it. #5315 (@tomastigera)
  • Fixes tier-scoped policy roles being denied all access on clusters serving the Calico v3 API through CRDs. #5266 (@caseydavenport)
  • Fixes staged network policy writes being denied for tier-scoped roles in Calico. #5266 (@caseydavenport)
  • Fixed the Manager policy board rendering empty on managed clusters, where the query server was not permitted egress to Linseed through guardian. #5263 (@tianfeng92)
  • Fix Calico webhook admission requests being denied on clusters where the API server connects through konnectivity, including AKS and GKE. #5216 (@caseydavenport)
  • Fixes the Calico version reported in the installation status when the Calico variant is installed. #5211 (@caseydavenport)
  • Fixed a bug that prevented BGP being disabled on a cluster with only IPIP IP Pools when clusterRoutingMode was left unset. #5201 (@nelljerram)
  • Fixed a deadlock on upgrade where the Calico API server was moved before a deprecated policy blocking it was removed, leaving the projectcalico.org/v3 API permanently unavailable. #5143 (@xiumozhan)
  • Fixed WAF dashboard cards failing with an access denied error for all users. #5133 (@electricjesus)
  • Fixes an issue where components could be deployed with default image tags instead of the images from a configured ImageSet during a Calico Enterprise installation. #5131 (@caseydavenport)
  • Fixed continuous rewrites of operator-managed objects shared by multiple owners (pull-secret copies, the tigera-operator-secrets RoleBinding, and gateway trust-bundle ConfigMaps): owner references are now merged in a stable order and per-owner identity labels are no longer written to shared objects, eliminating the resulting API server write and audit-log churn. #5124 (@alexh-tigera)
  • Fixes repeated failed-webhook errors in the Kubernetes API server log on Calico (non-Enterprise) clusters, caused by registering an audit admission webhook whose endpoint only exists in Calico Enterprise. #5069 (@caseydavenport)
  • Fixed a bug where disabling Gateway WAF left the generated EnvoyExtensionPolicy in place so the gateway kept enforcing WAF. The WAF controller now stays running while disabled so it can tear down what it generated. #4989 (@electricjesus)
  • Granted the tigera-network-admin and tigera-ui-user roles RBAC access to the WAF (applicationlayer.projectcalico.org) policy resources. #4964 (@electricjesus)
  • Fixes a regression where the Goldmane and Guardian pods were unable to reach DNS or the management cluster, which could break flow visibility (including on Calico Cloud-connected clusters). #4940 (@caseydavenport)
  • Fix Goldmane flow uploads to Guardian on Calico Cloud-managed clusters by trusting the management cluster Linseed signer under both its current and legacy secret names. #4936 (@Brian-McM)
  • Remove the deprecated waf-http-filter sidecar from the Enterprise Gateway data plane. WAF is now enforced by the Coraza WASM filter on the envoy-proxy. #4925 (@electricjesus)
  • Fixed a bug where the Calico Enterprise gateway WAF CRDs (applicationlayer.projectcalico.org) were not installed on standard aggregated-apiserver installations, making the gateway WAF feature unusable. These CRDs are now installed in both CRD modes. #4920 (@electricjesus)
  • Fixed an infinite IP pool delete/recreate loop that occurred when an Installation specified an IP pool CIDR in non-canonical form (for example an IPv6 CIDR with leading zeros). #4918 (@tmjd)

Other changes

  • Update the bundled Envoy Gateway to v1.9.1 and the Gateway API CRDs to v1.6.1. Envoy Gateway v1.9 raises the minimum supported Kubernetes version to v1.33. #5334 (@electricjesus)
  • Operator-managed NetworkPolicies now use the kubernetes.io/metadata.name label for namespace selectors instead of projectcalico.org/name. #5151 (@sivasubramanian95)
  • Whisker is now served over HTTPS on port 8443. #5140 (@vara2504)
  • Fixes a brief window during a calico-webhooks rollout where policy writes could be rejected. #5138 (@caseydavenport)
  • kube-controllers can now watch IPReservations, which it needs to report the ipam_ippool_reserved metric. #5115 (@fasaxc)
  • Removed the vulnerable containerd dependency from the operator image by bumping Helm to v3.21.3, and cleared an oras-go CVE by flooring it to v2.6.2. #5100 (@electricjesus)
  • The operator-generated CNI config now declares cniVersion 1.0.0 (previously 0.3.1), required for multus compatibility on OpenShift 4.23+. Requires containerd >= 1.6 or CRI-O >= 1.24. A new Installation field, spec.cni.specVersion, allows pinning the version (including back to 0.3.1) or leaving it operator-mana...
Read more

v1.43.1

v1.43.1 Pre-release
Pre-release

Choose a tag to compare

@marvin-tigera marvin-tigera released this 01 Sep 21:27
2d7fde1

01 Sep 2026

Included Calico versions

Calico version: v3.32.0
Calico Enterprise version: v3.24.0-2.0

Enhancements

  • Reduces the time calico-node takes to be marked ready after starting, which shortens calico-node rolling updates on large clusters. #5208 (@caseydavenport)

Bug fixes

  • Fixes tier-scoped policy roles being denied all access on clusters serving the Calico v3 API through CRDs. #5267 (@caseydavenport)
  • Fixes staged network policy writes being denied for tier-scoped roles in Calico. #5267 (@caseydavenport)

Other changes

  • Fixed the Manager policy board rendering empty on managed clusters, where the query server was not permitted egress to Linseed through guardian. #5261 (@tianfeng92)

v1.42.6

Choose a tag to compare

@marvin-tigera marvin-tigera released this 30 Aug 16:29
9aa866c

30 Aug 2026

Included Calico versions

Calico version: v3.32.2
Calico Enterprise version: v3.23.2

Other changes

  • Fixed the Manager policy board rendering empty on managed clusters, where the query server was not permitted egress to Linseed through guardian. #5260 (@tianfeng92)

v1.42.5

Choose a tag to compare

@marvin-tigera marvin-tigera released this 26 Aug 23:17
d984d71

26 Aug 2026

Included Calico versions

Calico version: v3.32.1
Calico Enterprise version: v3.23.2

Enhancements

  • Reduces the time calico-node takes to be marked ready after starting, which shortens calico-node rolling updates on large clusters. #5207 (@caseydavenport)

Bug fixes

  • Fixed a deadlock on upgrade where the Calico API server was moved before a deprecated policy blocking it was removed, leaving the projectcalico.org/v3 API permanently unavailable. #5144 (@xiumozhan)
  • Fixed an issue where a non-canonical storage quantity in the LogStorage CR (e.g. 1024Gi) caused the Elasticsearch NodeSet to be renamed on every reconcile, repeatedly recreating the Elasticsearch StatefulSet and its PVCs. #5078 (@pasanw)

Other changes

  • Built the operator image with Go 1.26.7, which fixes a net/http bug where ReadHeaderTimeout stayed active after an unencrypted HTTP/2 handoff. #5236 (@dimitri-nicolo)
  • Fixed CVE-2026-39821 and CVE-2026-46600 in the operator image by building with Go 1.26.6. #5202 (@dimitri-nicolo)
  • On upgrade, the operator-generated CNI config now declares cniVersion 1.0.0 (previously 0.3.1), required for multus compatibility on OpenShift 4.23+. A new Installation field, spec.cni.specVersion, allows pinning a version (including 0.3.1) or leaving it operator-managed (Auto). #5125 (@sridhartigera)
  • The ECK operator is updated to v3.4.0. #4966 (@vara2504)

v1.40.15

Choose a tag to compare

@danudey danudey released this 21 Aug 00:55
146f906

18 Aug 2026

Included Calico versions

Calico version: v3.31.7
Calico Enterprise version: v3.22.7

Note

This version of Operator is being released to support Calico version v3.31.7 and has no other changes. Please see the release notes for Operator v1.40.14 for recent changes included in this release.

v1.40.14

Choose a tag to compare

@marvin-tigera marvin-tigera released this 18 Aug 23:36
53bc553

18 Aug 2026

Included Calico versions

Calico version: v3.31.6
Calico Enterprise version: v3.22.7

Bug fixes

  • Update bundled Elasticsearch/Kibana to 8.19.19 and the ECK operator to 3.4.1 for Calico Enterprise v3.22.7. #5149 (@pasanw)
  • Bumped oras-go to v2.6.2 and grpc to v1.82.1 to remediate oras-go CVE-2026-50151/CVE-2026-50163 and GHSA-hrxh-6v49-42gf. containerd advisories remain deferred (no containerd fix exists; removal would require a k8s-1.36 uplift not taken on this line). #5145 (@pasanw)

Other changes

  • On upgrade, the operator-generated CNI config now declares cniVersion 1.0.0 (previously 0.3.1), required for multus compatibility on OpenShift 4.23+. A new Installation field, spec.cni.specVersion, allows pinning a version (including 0.3.1) or leaving it operator-managed (Auto). #5126 (@sridhartigera)
  • The ECK operator is updated to v3.4.0. #4967 (@vara2504)

v1.43.0

v1.43.0 Pre-release
Pre-release

Choose a tag to compare

@marvin-tigera marvin-tigera released this 21 Aug 00:54
22d717f

30 Jul 2026

Included Calico versions

Calico version: v3.32.0
Calico Enterprise version: v3.24.0-1.0

Enhancements

  • On BPF clusters where the operator is not managing kube-proxy (e.g. AKS), the operator now defaults FelixConfiguration.BPFKubeProxyHealthzPort to 0 to avoid a port conflict with the platform's kube-proxy. Users can still override the port explicitly. #4768 (@tomastigera)
  • Added Installation.spec.calicoNetwork.linuxPodInterfaceType to select between Veth (default) and Netkit for the Calico CNI pod interface. Requires Calico CNI plugin support for device_type (Linux 6.7+ for netkit; older kernels fall back to veth). #4767 (@tomastigera)

Bug fixes

  • Fixed an issue where a non-canonical storage quantity in the LogStorage CR (e.g. 1024Gi) caused the Elasticsearch NodeSet to be renamed on every reconcile, repeatedly recreating the Elasticsearch StatefulSet and its PVCs. #5079 (@pasanw)
  • Fixed a bug where disabling Gateway WAF left the generated EnvoyExtensionPolicy in place so the gateway kept enforcing WAF. The WAF controller now stays running while disabled so it can tear down what it generated. #4994 (@electricjesus)
  • Granted the tigera-network-admin and tigera-ui-user roles RBAC access to the WAF (applicationlayer.projectcalico.org) policy resources. #4965 (@electricjesus)
  • Fixes a regression where the Goldmane and Guardian pods were unable to reach DNS or the management cluster, which could break flow visibility (including on Calico Cloud-connected clusters). #4951 (@caseydavenport)
  • Remove the deprecated waf-http-filter sidecar from the Enterprise Gateway data plane. WAF is now enforced by the Coraza WASM filter on the envoy-proxy. #4931 (@electricjesus)
  • Fixed a bug where the Calico Enterprise gateway WAF CRDs (applicationlayer.projectcalico.org) were not installed on standard aggregated-apiserver installations, making the gateway WAF feature unusable. These CRDs are now installed in both CRD modes. #4921 (@electricjesus)
  • Fixed 403 errors on custom dashboards for OIDC users. #4827 (@alexh-tigera)

Other changes

  • Bump Helm to v3.21.3 (drops the containerd dependency) and oras-go to v2.6.2 to clear containerd CVE-2026-50195, CVE-2026-53492, CVE-2026-53489 and oras-go CVE-2026-50163 from the operator image. #5101 (@electricjesus)
  • Update the bundled Envoy Gateway to v1.8.2. #5081 (@electricjesus)
  • The ECK operator is updated to v3.4.1. #5038 (@alexh-tigera)
  • None #5026 (@radixo)
  • Restore backwards compatibility for the Monitor CRD alertManager field, which was inadvertently renamed to alertmanager. #4984 (@rene-dekker)
  • Add operator render for Gateway API WAF observability (EV-6650): capture the Coraza audit log from the gateway proxy, and enable the Felix + fluentd legs (WAFEventLogsFileEnabled, WAF_LOG_FILE) so WAF block / would-block decisions land in the tigera_secure_ee_waf index. #4976 (@electricjesus)
  • Elasticsearch and Kibana are updated to the v8.19.17 release. #4963 (@vara2504)
  • Bump ECK operator from 3.3.2 to 3.4.0 #4957 (@vara2504)
  • Add L7 log collection for Istio ambient mode waypoint proxies. #4949 (@alexh-tigera)
  • Bumped bundled Envoy Gateway from v1.7.2 to v1.8.0. Adds first-class ListenerSet support (enables cert-manager and external-dns integration with Gateway-API), the safe-upgrades ValidatingAdmissionPolicy for CRD version migrations, and pulls in the v1.8.0 security and bug-fix rollup. Note: v1.8.0 contains several upstream behavior changes (DirectResponse template interpolation, SecurityPolicy 0s timeout semantics, samplingFraction 100x correction, OIDC filter consolidation) — see https://gateway.envoyproxy.io/news/releases/notes/v1.8.0/. #4934 (@electricjesus)
  • Bump third-party component versions and Go x/ libraries to address CVEs (GO-2026-5026, CVE-2026-42151/42154). #4926 (@vara2504)
  • None #4904 (@radixo)
  • Bump Kubernetes dependencies to v1.36.1. #4888 (@lucastigera)
  • Fixes an operator upgrade that could stall on kind clusters, looping on an unsupported "Kind" kubernetesProvider value instead of completing. #4881 (@caseydavenport)
  • The Installation fipsMode field is deprecated. FIPS mode is no longer supported, and setting fipsMode to Enabled marks the installation degraded. #4875 (@caseydavenport)
  • Fixes an issue where Calico Enterprise compliance reports were never scheduled due to a missing RBAC permission on the calico-apiserver ClusterRole. #4862 (@caseydavenport)
  • Grant operator-managed service accounts update permission on /status subresources for GlobalAlert, PacketCapture, and SecurityEventWebhook. #4853 (@caseydavenport)
  • NONE #4851 (@xiumozhan)
  • None #4846 (@caseydavenport)
  • Fixes the non-cluster-host Typha deployment crashlooping on clusters where the host-network kube-apiserver endpoint is not reachable from pod-networked pods (e.g. MKE's proxy.local). The pod-network endpoint from the kubernetes-service-endpoint ConfigMap is now used when set. #4840 (@caseydavenport)
  • Fix operator reconcile failure on Kubernetes clusters that only serve the v1 (not v1beta1) MutatingAdmissionPolicy API. #4837 (@caseydavenport)
  • Add operator render for the WAF v3 (Coraza WASM) SecLang validating admission #4821 (@electricjesus)
  • webhook — served in-process by calico-kube-controllers — plus the WASM_* env #4821 (@electricjesus)
  • vars and serving-cert / RBAC plumbing (paired with tigera/calico-private#11834 #4821 (@electricjesus)
  • and #12141). The existing WAF v1 (sidecar / ModSecurity) render path is untouched. #4821 (@electricjesus)
  • Calico Typha no longer schedules on cordoned nodes. The apiserver and admission webhook Deployments also respect node cordoning when running in host-network mode. #4820 (@caseydavenport)
  • Bump bundled ECK Kibana/Elasticsearch version constant to 8.19.15. #4817 (@tianfeng92)
  • Fix WAF HTTP filter failing open in clusters installed without the Calico API server (USE_API_SERVER=false / v3-CRDs-only mode). The filter's license check now succeeds regardless of which Calico CRD group is installed, so WAF rule processing engages as intended. #4808 (@electricjesus)
  • Added Installation.Spec.ImagePullPolicy for overriding the pull policy of all operator-managed pods, useful in air-gapped clusters. #4797 (@caseydavenport)
  • Mount the operator-managed trusted CA bundle (public roots + Calico CA) on envoy-gateway and provisioned envoy-proxy pods so outbound TLS to public upstreams (e.g. wasm OCI registries, OIDC providers) succeeds without x509: certificate signed by unknown authority. #4796 (@electricjesus)
  • Fix 500 errors on the policy list page for managed clusters by trusting the management cluster CA on the calico-apiserver bundle, attaching a Linseed-issued bearer token to the queryserver, and clearing x-cluster-id so voltron rewrites it. #4786 (@tianfeng92)
  • Fix operator metrics server starting with an empty client-CA trust pool when the CA Secret is created after the operator pod, which previously broke Prometheus scraping until a restart. #4785 (@rene-dekker)
  • Automatically recover Calico pods stranded with stale pod IPs after a node IP change (e.g. KubeVirt node reboot). #4784 (@coutinhop)
  • None #4782 (@caseydavenport)
  • Fixes a permissions error in calico-kube-controllers that prevented it from reading IPAM configuration. #4775 (@caseydavenport)
  • The GatewayAPI resource now permits general patching of the Services that are provisioned for gateways within a custom gateway class, by adding a Patch field in GatewayServiceSpec that is passed through to the corresponding field in EnvoyProxy. #4773 (@nelljerram)
  • Stops the intrusion-detection-controller from logging repeated RBAC errors about ManagedClusters on standalone clusters. [#4765](https:/...
Read more

v1.42.4

Choose a tag to compare

@marvin-tigera marvin-tigera released this 04 Jul 22:07
64b7f9b

04 Jul 2026

Included Calico versions

Calico version: v3.32.1
Calico Enterprise version: v3.23.1

This version of Operator is being released to support Calico Enterprise version v3.23.1 and has no other changes. Please see the release notes for Operator v1.42.3 for recent changes included in this release.

v1.42.3

Choose a tag to compare

@marvin-tigera marvin-tigera released this 26 Jun 20:16
40f3e3d

26 Jun 2026

Included Calico versions

Calico version: v3.32.1
Calico Enterprise version: v3.23.0-2.0

Bug fixes

  • Fixes a regression where the Goldmane and Guardian pods were unable to reach DNS or the management cluster, which could break flow visibility (including on Calico Cloud-connected clusters). #4953 (@caseydavenport)

v1.40.13

Choose a tag to compare

@danudey danudey released this 19 Jun 01:38
dfd61cf

18 Jun 2026

Included Calico versions

Calico version: v3.31.6
Calico Enterprise version: v3.22.6

Note

This version of Operator is being released to support Calico version v3.31.6 and has no other changes. Please see the release notes for Operator v1.40.12 for recent changes included in this release.