What traefik/traefik shipped
Written by FoxPlug from public releases; not affiliated with Traefik. An automatic summary of the public release, pull request and commit data of github.com/traefik/traefik. Traefik did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- Fixed TLSRoute router name collisions when multiple TLS listeners share an entry point. Pull request #13959
- Gateway API provider now creates only the router serving a given rule on a given entry point, preventing routers from shadowing each other. Pull request #13946
- TLSRoute routers no longer shadow TCPRoute routers that share the same entry point and rule. Pull request #13953
- BackendTLSPolicy ancestor now reports in the namespace of its Gateway instead of the backend namespace. Pull request #13964
- GRPCRoute and TLSRoute BackendTLSPolicy ancestors now report in the namespace of their Gateway. Pull request #13966
- Added QUERY HTTP method to metrics labeling instead of grouping it as EXTENSION_METHOD. Pull request #13667
- Fixed selection bias in the P2C load balancer when drawing the second index. Pull request #13644
- Rate limiter Lua script now uses # operator instead of deprecated table.maxn for Redis-compatible servers. Pull request #13825
- UDP listener now copies datagrams into right-sized buffers instead of queuing full 64 KiB allocations. Pull request #13941
- Gateway API conformance entry points now have a 1s read timeout. Pull request #13947
Why it matters
This week focused on Gateway API correctness and cross-namespace routing, fixing collisions and shadowing issues that affected multi-listener deployments. Performance improvements to UDP handling and the P2C load balancer reduce resource waste, while the QUERY method support expands HTTP compatibility.
Changelog entry
- Fixed TLSRoute router name collision across listeners sharing an entry point Pull request #13959
- Gateway API provider now avoids creating shadowed routers when multiple routes share an entry point and rule Pull request #13946
- TLSRoute routers no longer shadow TCPRoute routers on the same entry point and rule Pull request #13953
- BackendTLSPolicy ancestor now reports in the Gateway namespace for cross-namespace deployments Pull request #13964
- GRPCRoute and TLSRoute BackendTLSPolicy ancestors now report in the namespace of their Gateway Pull request #13966
- Added QUERY HTTP method to metrics labeling Pull request #13667
- Fixed selection bias in P2C load balancer for second server index Pull request #13644
- Rate limiter Lua script now compatible with Redis using newer Lua versions Pull request #13825
- UDP listener now uses right-sized buffers for datagrams to reduce memory allocation Pull request #13941
- Gateway API conformance entry points now have 1s read timeout Pull request #13947
Fixed TLSRoute router collisions, Gateway API shadowing issues, and cross-namespace BackendTLSPolicy handling. Improved UDP buffer efficiency and added QUERY HTTP method support.
This week's releases focused on Gateway API stability and performance. We fixed router name collisions in TLSRoute deployments, resolved shadowing issues between different route types, and corrected BackendTLSPolicy ancestor reporting across namespaces. Performance improvements include optimized UDP datagram handling and P2C load balancer corrections. Added QUERY HTTP method support for expanded protocol compatibility.
Week of September 14, 2026
What shipped
- FastProxy now isolates NTLM and Negotiate backend connections to the frontend connection that authenticated them, matching the behavior of the default proxy. Pull request #13914
- NTLM and Kerberos credential-bearing requests are dispatched on dedicated connection-scoped transports before reaching the shared backend connection pool. Pull request #13902
- SSL-passthrough Ingress routes now follow the same routing path as other Ingress routes, with the TCP router forwarding connections without decryption. Pull request #13915
- The Ingress-NGINX provider no longer normalizes namespace and resource names, preventing collisions when names contain dots. Pull request #13922
- The
Ssl-Client-*request headers are now set on the HTTP router when thenginx.ingress.kubernetes.io/auth-tls-pass-certificate-to-upstreamannotation is enabled. Pull request #13912 - Documentation grammar corrected in TCP HostSNI rules reference. Pull request #13895
- Documentation grammar corrected in TCP ServersTransport reference. Pull request #13894
- Test fixed to properly wait for connection handler to return before starting subsequent connections. Pull request #13870
- Integration test example regular expression end anchor corrected. Pull request #13898
- Branch v3.7 merged into master. Pull request #13889
Why it matters
This week's changes improve authentication handling for connection-bound schemes like NTLM and Kerberos, ensure consistent Ingress routing behavior, and fix a Kubernetes resource naming issue that could cause configuration collisions. These fixes strengthen reliability for users relying on advanced authentication and Kubernetes integration.
Changelog entry
- FastProxy: isolate NTLM and Negotiate backend connections to frontend connection Pull request #13914
- Dispatch NTLM and Kerberos credential-bearing requests on dedicated connection-scoped transports Pull request #13902
- Route ssl-passthrough Ingress through standard routing path Pull request #13915
- Ingress-NGINX provider: do not normalize resource names Pull request #13922
- Set Ssl-Client-* request headers on Ingress-NGINX HTTP router for auth-tls-pass-certificate-to-upstream Pull request #13912
Improved NTLM and Kerberos connection isolation in FastProxy. Fixed SSL-passthrough routing consistency. Prevented Ingress-NGINX resource name collisions with dotted names.
This week we improved handling of connection-bound authentication schemes. FastProxy now properly isolates NTLM and Negotiate connections matching the default proxy. SSL-passthrough Ingress routes follow standard routing paths. We also fixed a Kubernetes resource naming issue in the Ingress-NGINX provider that could cause collisions when resource names contain dots.