What projectcalico/calico shipped
Written by FoxPlug from public releases; not affiliated with Tigera. An automatic summary of the public release, pull request and commit data of github.com/projectcalico/calico. Tigera did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- Backported bug fixes to v3.31: fixed epstatusfile watcher leak, kept pre-existing forwarded flows alive when switching to eBPF, and fixed borrowed IP route handling. Pull request #14075
- Manifest installs now stage upstream CNI plugins in the calico-node chart so pod-networked pods can start. Pull request #14041
- Fixed calico-kube-controllers never becoming ready on manifest installs by pointing probes at its health server instead of running a non-existent command. Pull request #14050
- Fixed calico-apiserver on manifest installs to use mounted certificates instead of serving a self-signed localhost cert. Pull request #14059
- Upgraded bundled Envoy Gateway from v1.8.2 to v1.9.1, Envoy to v1.39.1, and Gateway API to v1.6.1. Pull request #14025
- Fixed calico-node crash-loop on canal installs by granting IPAMConfiguration read access regardless of IPAM mode. Pull request #14068
- Fixed BPF connlimit bypass where a forged RST on an idle NAT-outgoing flow incorrectly freed a connection slot. Pull request #14034
- Added ability to list HostEndpoints with field selector spec.node= on both Calico API server and native v3 CRDs. Pull request #14067
- Reduced unnecessary writes to datastore by only creating default tiers when they are missing instead of unconditionally. Pull request #14002
- Improved offline validation in calicoctl to catch duplicate list entries that the API server would reject. Pull request #14058
Why it matters
Manifest installs were broken across multiple components in recent releases. This week's fixes ensure calico-node, calico-kube-controllers, and calico-apiserver all work correctly on manifest-based deployments. Additionally, bug fixes address connlimit security issues and eBPF flow handling while reducing unnecessary datastore churn.
Changelog entry
- Backported epstatusfile watcher leak fix, eBPF forwarded flows fix, and borrowed IP route fix to v3.31 Pull request #14075
- Added upstream CNI plugins staging to calico-node chart for manifest installs Pull request #14041
- Fixed kube-controllers probes on manifest installs to use health server instead of non-existent command Pull request #14050
- Fixed calico-apiserver on manifest installs to use mounted certificates from calico-apiserver-certs secret Pull request #14059
- Upgraded Envoy Gateway to v1.9.1, Envoy to v1.39.1, Gateway API to v1.6.1 Pull request #14025
- Fixed calico-node crash-loop on canal installs by granting IPAMConfiguration read access for policy-only mode Pull request #14068
- Fixed BPF connlimit bypass where forged RST on idle NAT flow incorrectly freed connection slot Pull request #14034
- Added spec.node field selector support for HostEndpoint listing on Calico API server and native CRDs Pull request #14067
- Reduced datastore writes by creating default tiers only when missing instead of unconditionally Pull request #14002
- Improved calicoctl offline validation to catch duplicate list entries rejected by API server Pull request #14058
Fixed manifest install issues in Calico: calico-node now stages CNI plugins, kube-controllers probes work, and apiserver uses proper certificates. Also fixed connlimit security and upgraded Envoy Gateway to v1.9.1.
This week we fixed critical issues affecting Calico manifest installations. calico-node now properly stages CNI plugins so pods can network, kube-controllers probes point to the health server, and apiserver uses mounted certificates instead of self-signed certs. We also addressed a connlimit security bypass in BPF where forged RSTs freed connection slots incorrectly. Envoy Gateway upgraded from v1.8.2 to v1.9.1 with Envoy at v1.39.1. Reduced unnecessary datastore writes by only creating tiers when missing.
Week of September 14, 2026
What shipped
- CRD schemas now accept the full range of 4-byte AS numbers defined by RFC 4893, fixing rejection of AS numbers above 2147483647 [4]. Pull request #13979
- CRD schemas now validate peer IPs, network set entries and rule protocols to prevent kubectl and GitOps clients from storing values the API server would reject [19]. Pull request #13913
- CRD schemas now apply the same field defaults as the aggregated API server, so raw kubectl reads see the documented default values [27]. Pull request #13872
- Operator gains optional Installation.spec.tlsMinVersion field to set TLS 1.2 or 1.3 minimum on operator-managed workloads [5]. Pull request #13963
- Bug fix: nftables connection transition log prefix validation now correctly allows prefixes up to 115 characters instead of rejecting 116+ [11]. Pull request #13969
- Bug fix: BPF connection limit no longer incorrectly releases slots when a pod with CAP_NET_RAW forges RST packets [13]. Pull request #13880
- Bug fix: conntrack leg flags are now written atomically to prevent policy approval or TCP state bits from being dropped under concurrent writes [28]. Pull request #13932
- BPF host interface auto-detection now correctly models NICs and VLAN sub-devices attached to Linux bridges [29]. Pull request #13922
- kube-controllers now runs on the host network during datastore migration to prevent the migration from being wedged by pod scheduling issues [30]. Pull request #13871
- Flow backend now supports pluggable flow sources beyond Goldmane while maintaining backward compatibility for existing Calico installations [1]. Pull request #12879
Why it matters
This week focused on improving API validation through CRD schemas to catch configuration errors earlier, fixing critical bugs in BPF connection tracking and network flow handling, and making the operator more flexible with TLS configuration. These changes reduce silent failures and make Calico deployments more robust.
Changelog entry
- Accept the full 4-byte AS number range in the CRD schemas Pull request #13979
- Validate peer IPs, network set entries and rule protocols in the CRD schemas Pull request #13913
- Apply the libcalico-go write defaults in the CRD schemas Pull request #13872
- Add operator TLS minimum version setting Pull request #13963
- Fix the nftables budget for connection transition log prefixes Pull request #13969
- BPF connlimit: RST no longer incorrectly releases a connection slot Pull request #13880
- Write conntrack leg flags atomically Pull request #13932
- Detect bridge-attached interfaces in BPF host interface auto-detection Pull request #13922
- Run kube-controllers on the host network during a datastore migration Pull request #13871
- Make whisker's flow source pluggable Pull request #12879
Calico v3.33+ now validates CRD writes, applies field defaults, accepts full 4-byte AS numbers, and fixes BPF connection tracking bugs.
This week's Calico updates strengthen schema validation to catch misconfigurations early, fix critical BPF bugs in connection tracking and flow handling, add TLS version control to operator deployments, and support pluggable flow sources. CRD schemas now validate peer IPs and enforce the same defaults as the API server, preventing silent failures when using kubectl or GitOps tools directly.