Shipped · Observability

What projectcalico/calico shipped

The public repository of Tigera · github.com/projectcalico/calico

Written by FoxPlug from public releases; not affiliated with Tigera. An automatic summary of the public release, pull request and commit data of github.com/projectcalico/calico. Tigera did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.

Get a weekly update like this for your product, free

Or Use it as a GitHub Action

Follow calico's weekly shipped digest

Week of September 21, 2026

What shipped

Why it matters

Manifest installs were broken across multiple components in recent releases. This week's fixes ensure calico-node, calico-kube-controllers, and calico-apiserver all work correctly on manifest-based deployments. Additionally, bug fixes address connlimit security issues and eBPF flow handling while reducing unnecessary datastore churn.

Changelog entry

Example posts FoxPlug drafted from these changes. Not written or posted by the project.

Post for X

Fixed manifest install issues in Calico: calico-node now stages CNI plugins, kube-controllers probes work, and apiserver uses proper certificates. Also fixed connlimit security and upgraded Envoy Gateway to v1.9.1.

Post for LinkedIn

This week we fixed critical issues affecting Calico manifest installations. calico-node now properly stages CNI plugins so pods can network, kube-controllers probes point to the health server, and apiserver uses mounted certificates instead of self-signed certs. We also addressed a connlimit security bypass in BPF where forged RSTs freed connection slots incorrectly. Envoy Gateway upgraded from v1.8.2 to v1.9.1 with Envoy at v1.39.1. Reduced unnecessary datastore writes by only creating tiers when missing.

Week of September 14, 2026

What shipped

Why it matters

This week focused on improving API validation through CRD schemas to catch configuration errors earlier, fixing critical bugs in BPF connection tracking and network flow handling, and making the operator more flexible with TLS configuration. These changes reduce silent failures and make Calico deployments more robust.

Changelog entry

Example posts FoxPlug drafted from these changes. Not written or posted by the project.

Post for X

Calico v3.33+ now validates CRD writes, applies field defaults, accepts full 4-byte AS numbers, and fixes BPF connection tracking bugs.

Post for LinkedIn

This week's Calico updates strengthen schema validation to catch misconfigurations early, fix critical BPF bugs in connection tracking and flow handling, add TLS version control to operator deployments, and support pluggable flow sources. CRD schemas now validate peer IPs and enforce the same defaults as the API server, preventing silent failures when using kubectl or GitOps tools directly.

Weeks with too little public activity are left out rather than filled in. Last updated 2026-09-29.

Is this your repo? Ask us to remove this page.