Skip to content

chore(deps): update istio from 1.28.3 to 1.29.1#2387

Merged
mjnagel merged 4 commits intomainfrom
renovate/istio
Mar 19, 2026
Merged

chore(deps): update istio from 1.28.3 to 1.29.1#2387
mjnagel merged 4 commits intomainfrom
renovate/istio

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Feb 16, 2026

This PR contains the following updates:

Package Update Change
base minor 1.28.31.29.1
cni minor 1.28.31.29.1
docker.io/istio/install-cni minor 1.28.3-distroless1.29.1-distroless
docker.io/istio/pilot minor 1.28.3-distroless1.29.1-distroless
docker.io/istio/proxyv2 minor 1.28.3-distroless1.29.1-distroless
docker.io/istio/ztunnel minor 1.28.3-distroless1.29.1-distroless
gateway minor 1.28.31.29.1
istio/istio minor 1.28.31.29.1
istiod minor 1.28.31.29.1
kubernetes-sigs/gateway-api minor v1.4.1v1.5.1
quay.io/rfcurated/istio/install-cni minor 1.28.3-jammy-fips-rfcurated-rfhardened1.29.1-jammy-fips-rfcurated-rfhardened
quay.io/rfcurated/istio/pilot minor 1.28.3-jammy-fips-rfcurated-rfhardened1.29.1-jammy-fips-rfcurated-rfhardened
quay.io/rfcurated/istio/proxyv2 minor 1.28.3-jammy-fips-rfcurated-rfhardened1.29.1-jammy-fips-rfcurated-rfhardened
quay.io/rfcurated/istio/ztunnel minor 1.28.3-jammy-scratch-fips-rfcurated1.29.1-jammy-scratch-fips-rfcurated
registry1.dso.mil/ironbank/tetrate/istio/install-cni (source) minor 1.28.3-fips1.29.1-fips
registry1.dso.mil/ironbank/tetrate/istio/pilot (source) minor 1.28.3-fips1.29.1-fips
registry1.dso.mil/ironbank/tetrate/istio/proxyv2 (source) minor 1.28.3-fips1.29.1-fips
registry1.dso.mil/ironbank/tetrate/istio/ztunnel (source) minor 1.28.3-fips1.29.1-fips
ztunnel minor 1.28.31.29.1

Release Notes

istio/istio (base)

v1.29.1: Istio 1.29.1

Compare Source

Artifacts
Release Notes

v1.29.0: Istio 1.29.0

Compare Source

Artifacts
Release Notes

v1.28.5: Istio 1.28.5

Compare Source

Artifacts
Release Notes

v1.28.4: Istio 1.28.4

Compare Source

Artifacts
Release Notes

kubernetes-sigs/gateway-api (kubernetes-sigs/gateway-api)

v1.5.1

Compare Source

Warning: The Experimental channel CRDs are too large for a standard kubectl apply. To work around this please use kubectl apply --server-side=true instead -- or, even better, use kuberc to make server-side apply the default.

Gateway API v1.5.1

Major Changes Since v1.5.0

GEP
Conformance

What's Changed

Full Changelog: kubernetes-sigs/gateway-api@v1.5.0...v1.5.1

v1.5.0

Compare Source

Warning: The Experimental channel CRDs are too large for a standard kubectl apply. To work around this please use kubectl apply --server-side=true instead -- or, even better, use kuberc to make server-side apply the default.

Gateway API v1.5.0
Major Changes Since v1.4.1
Breaking Changes
TLSRoute v1alpha2 and XListenerSet

TLSRoute and ListenerSet have graduated to the Standard channel as v1. In 1.5.0, TLSRoute v1alpha2 is present only in the Experimental channel; in 1.6, it will be removed from the Experimental channel too.

Additionally, note that TLSRoute's CEL validation requires Kubernetes 1.31 or higher.

Upgrades and ValidatingAdmissionPolicy

Gateway API 1.5 introduces a validating admission policy (VAP) called safe-upgrades.gateway.networking.k8s.io to guard against two specific concerns:

  • It prevents installing Experimental CRDs once you've installed Standard CRDs.
  • It prevents downgrading to a version prior to 1.5 after you've installed Gateway API 1.5.

These actions can't be known to be safe without detailed knowledge about your application and users. If you need to perform them, delete the safe-upgrades.gateway.networking.k8s.io VAP first.

New Features

In this release, the following major features are moving to the Standard channel and are now considered generally available:

Additionally, the ReferenceGrant resource is moving to v1.

Experimental
  • Gateway/HTTPRoute level authentication (GEP-1494)
Full Changelog

Full Changelog: kubernetes-sigs/gateway-api@v1.4.1...v1.5.0

Dependencies
Added
  • github.com/Masterminds/semver/v3: v3.4.0
  • github.com/chzyer/readline: v1.5.1
  • github.com/gkampitakis/ciinfo: v0.3.2
  • github.com/gkampitakis/go-diff: v1.3.2
  • github.com/gkampitakis/go-snaps: v0.5.15
  • github.com/ianlancetaylor/demangle: f615e6b
  • github.com/joshdk/go-junit: v1.0.0
  • github.com/maruel/natural: v1.1.1
  • github.com/mfridman/tparse: v0.18.0
  • github.com/tidwall/gjson: v1.18.0
  • github.com/tidwall/match: v1.1.1
  • github.com/tidwall/pretty: v1.2.1
  • github.com/tidwall/sjson: v1.2.5
Changed
  • cloud.google.com/go/compute/metadata: v0.7.0 → v0.9.0
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp: v1.29.0 → v1.30.0
  • github.com/cncf/xds/go: 2ac532f → 0feb691
  • github.com/envoyproxy/go-control-plane/envoy: v1.32.4 → v1.35.0
  • github.com/envoyproxy/go-control-plane: v0.13.4 → 75eaa19
  • github.com/go-jose/go-jose/v4: v4.1.1 → v4.1.3
  • github.com/google/pprof: d1b30fe → 294ebfa
  • github.com/mailru/easyjson: v0.9.0 → v0.9.1
  • github.com/miekg/dns: v1.1.68 → v1.1.72
  • github.com/onsi/ginkgo/v2: v2.22.0 → v2.28.0
  • github.com/onsi/gomega: v1.38.1 → v1.39.1
  • github.com/prometheus/client_golang: v1.23.0 → v1.23.2
  • github.com/prometheus/common: v0.65.0 → v0.66.1
  • github.com/prometheus/procfs: v0.17.0 → v0.19.2
  • github.com/rogpeppe/go-internal: v1.13.1 → v1.14.1
  • github.com/spf13/cobra: v1.9.1 → v1.10.2
  • github.com/spf13/pflag: v1.0.7 → v1.0.10
  • github.com/spiffe/go-spiffe/v2: v2.5.0 → v2.6.0
  • github.com/stretchr/testify: v1.11.0 → v1.11.1
  • go.etcd.io/bbolt: v1.4.2 → v1.4.3
  • go.etcd.io/etcd/api/v3: v3.6.4 → v3.6.5
  • go.etcd.io/etcd/client/pkg/v3: v3.6.4 → v3.6.5
  • go.etcd.io/etcd/client/v3: v3.6.4 → v3.6.5
  • go.etcd.io/etcd/pkg/v3: v3.6.4 → v3.6.5
  • go.etcd.io/etcd/server/v3: v3.6.4 → v3.6.5
  • go.opentelemetry.io/auto/sdk: v1.1.0 → v1.2.1
  • go.opentelemetry.io/contrib/detectors/gcp: v1.36.0 → v1.38.0
  • go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp: v0.58.0 → v0.61.0
  • go.opentelemetry.io/otel/metric: v1.37.0 → v1.38.0
  • go.opentelemetry.io/otel/sdk/metric: v1.37.0 → v1.38.0
  • go.opentelemetry.io/otel/sdk: v1.37.0 → v1.38.0
  • go.opentelemetry.io/otel/trace: v1.37.0 → v1.38.0
  • go.opentelemetry.io/otel: v1.37.0 → v1.38.0
  • go.opentelemetry.io/proto/otlp: v1.5.0 → v1.7.0
  • go.uber.org/zap: v1.27.0 → v1.27.1
  • go.yaml.in/yaml/v2: v2.4.2 → v2.4.3
  • golang.org/x/crypto: v0.41.0 → v0.47.0
  • golang.org/x/mod: v0.27.0 → v0.32.0
  • golang.org/x/net: v0.43.0 → v0.49.0
  • golang.org/x/oauth2: v0.30.0 → v0.34.0
  • golang.org/x/sync: v0.16.0 → v0.19.0
  • golang.org/x/sys: v0.35.0 → v0.40.0
  • golang.org/x/telemetry: 1a19826bd525da
  • golang.org/x/term: v0.34.0 → v0.39.0
  • golang.org/x/text: v0.28.0 → v0.33.0
  • golang.org/x/time: v0.12.0 → v0.14.0
  • golang.org/x/tools: v0.36.0 → v0.41.0
  • google.golang.org/genproto/googleapis/api: 8d1bb00ab9386a
  • google.golang.org/genproto/googleapis/rpc: ef028d9ab9386a
  • google.golang.org/grpc: v1.75.1 → v1.78.0
  • google.golang.org/protobuf: v1.36.8 → v1.36.11
  • k8s.io/api: v0.34.1 → v0.35.1
  • k8s.io/apiextensions-apiserver: v0.34.1 → v0.35.1
  • k8s.io/apimachinery: v0.34.1 → v0.35.1
  • k8s.io/apiserver: v0.34.1 → v0.35.1
  • k8s.io/client-go: v0.34.1 → v0.35.1
  • k8s.io/code-generator: v0.34.1 → v0.35.1
  • k8s.io/component-base: v0.34.1 → v0.35.1
  • k8s.io/gengo/v2: c297c0cec3ebc5
  • k8s.io/kms: v0.34.1 → v0.35.1
  • k8s.io/kube-openapi: d7b6acb589584f
  • k8s.io/utils: 0af2bda914a6e7
  • sigs.k8s.io/controller-runtime: v0.22.1 → v0.23.1
  • sigs.k8s.io/controller-tools: v0.19.0 → v0.20.1
  • sigs.k8s.io/structured-merge-diff/v6: v6.3.0 → v6.3.2
Removed
  • github.com/kisielk/errcheck: v1.5.0
  • github.com/kisielk/gotool: v1.0.0
  • github.com/pkg/errors: v0.9.1
  • github.com/zeebo/errs: v1.4.0
  • golang.org/x/xerrors: 5ec99f8

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot requested a review from a team as a code owner February 16, 2026 19:17
@github-actions github-actions Bot added waiting on ironbank This PR is waiting on an image update for ironbank waiting on rapidfort This PR is waiting on an image update for Rapidfort labels Feb 16, 2026
@renovate renovate Bot changed the title chore(deps): update istio chore(deps): update istio to v1.29.0 Feb 16, 2026
@renovate renovate Bot force-pushed the renovate/istio branch 2 times, most recently from 9e0fd3e to e957758 Compare February 20, 2026 06:44
@renovate renovate Bot changed the title chore(deps): update istio to v1.29.0 chore(deps): update istio Feb 20, 2026
Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lula Compliance Overview

Please review the changes to ensure they meet compliance standards.

Reviewed Changes

Lula reviewed 8 files changed that affect compliance.


File Lines Changed
src/istio/zarf.yaml 83–89

UUID: b4367e52-bef0-4463-a906-e5af6b4aa015
sha256: a80edb5d8519a867741d99e0e4049a8a434883c42ffcdf756b2c703143a85da5


Tip: Customize your compliance reviews with Lula.

@renovate renovate Bot changed the title chore(deps): update istio chore(deps): update istio to v1.29.0 Feb 21, 2026
@github-actions github-actions Bot dismissed their stale review February 21, 2026 22:13

Superseded by a new Lula compliance review.

Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lula Compliance Overview

Please review the changes to ensure they meet compliance standards.

Reviewed Changes

Lula reviewed 8 files changed that affect compliance.


File Lines Changed
src/istio/zarf.yaml 83–89

UUID: b4367e52-bef0-4463-a906-e5af6b4aa015
sha256: f6cce98f6ceeeabd9dd6855fdad5909809384946258158d30b1f7901c5f5c3a1


Tip: Customize your compliance reviews with Lula.

@github-actions github-actions Bot removed the waiting on rapidfort This PR is waiting on an image update for Rapidfort label Feb 21, 2026
@github-actions github-actions Bot dismissed their stale review February 26, 2026 18:12

Superseded by a new Lula compliance review.

Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lula Compliance Overview

Please review the changes to ensure they meet compliance standards.

Reviewed Changes

Lula reviewed 9 files changed that affect compliance.


File Lines Changed
src/istio/zarf.yaml 83–89

UUID: b4367e52-bef0-4463-a906-e5af6b4aa015
sha256: f6cce98f6ceeeabd9dd6855fdad5909809384946258158d30b1f7901c5f5c3a1


Tip: Customize your compliance reviews with Lula.

@github-actions github-actions Bot dismissed their stale review February 26, 2026 18:47

Superseded by a new Lula compliance review.

Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lula Compliance Overview

Please review the changes to ensure they meet compliance standards.

Reviewed Changes

Lula reviewed 10 files changed that affect compliance.


File Lines Changed
src/istio/zarf.yaml 83–89

UUID: b4367e52-bef0-4463-a906-e5af6b4aa015
sha256: f6cce98f6ceeeabd9dd6855fdad5909809384946258158d30b1f7901c5f5c3a1


Tip: Customize your compliance reviews with Lula.

@renovate renovate Bot changed the title chore(deps): update istio to v1.29.0 chore(deps): update istio Feb 27, 2026
@github-actions github-actions Bot dismissed their stale review February 27, 2026 06:10

Superseded by a new Lula compliance review.

Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lula Compliance Overview

Please review the changes to ensure they meet compliance standards.

Reviewed Changes

Lula reviewed 10 files changed that affect compliance.


File Lines Changed
src/istio/zarf.yaml 83–89

UUID: b4367e52-bef0-4463-a906-e5af6b4aa015
sha256: f6cce98f6ceeeabd9dd6855fdad5909809384946258158d30b1f7901c5f5c3a1


Tip: Customize your compliance reviews with Lula.

@github-actions github-actions Bot dismissed their stale review February 27, 2026 18:39

Superseded by a new Lula compliance review.

Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lula Compliance Overview

Please review the changes to ensure they meet compliance standards.

Reviewed Changes

Lula reviewed 13 files changed that affect compliance.


File Lines Changed
src/istio/zarf.yaml 59–65
src/istio/zarf.yaml 83–89

UUID: b4367e52-bef0-4463-a906-e5af6b4aa015
sha256: 3920cd23086814de017433d09c0d82f819330db1df04b8212f159368059b114f

UUID: b4367e52-bef0-4463-a906-e5af6b4aa015
sha256: f6cce98f6ceeeabd9dd6855fdad5909809384946258158d30b1f7901c5f5c3a1


Tip: Customize your compliance reviews with Lula.

@renovate renovate Bot force-pushed the renovate/istio branch from 747ba41 to 077c742 Compare March 3, 2026 15:22
@github-actions github-actions Bot dismissed their stale review March 3, 2026 15:22

Superseded by a new Lula compliance review.

Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lula Compliance Overview

Please review the changes to ensure they meet compliance standards.

Reviewed Changes

Lula reviewed 13 files changed that affect compliance.


File Lines Changed
src/istio/zarf.yaml 59–65
src/istio/zarf.yaml 83–89

UUID: b4367e52-bef0-4463-a906-e5af6b4aa015
sha256: 3920cd23086814de017433d09c0d82f819330db1df04b8212f159368059b114f

UUID: b4367e52-bef0-4463-a906-e5af6b4aa015
sha256: f6cce98f6ceeeabd9dd6855fdad5909809384946258158d30b1f7901c5f5c3a1


Tip: Customize your compliance reviews with Lula.

@renovate renovate Bot force-pushed the renovate/istio branch from 077c742 to dfaa183 Compare March 9, 2026 23:40
@github-actions github-actions Bot dismissed their stale review March 18, 2026 12:07

Superseded by a new Lula compliance review.

Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lula Compliance Overview

Please review the changes to ensure they meet compliance standards.

Reviewed Changes

Lula reviewed 13 files changed that affect compliance.


File Lines Changed
src/istio/zarf.yaml 59–65
src/istio/zarf.yaml 83–89

UUID: b4367e52-bef0-4463-a906-e5af6b4aa015
sha256: ffc7be359db0b3d5966119192d97c22edca895415429fa5fbf20fbe129f050fe

UUID: b4367e52-bef0-4463-a906-e5af6b4aa015
sha256: f6cce98f6ceeeabd9dd6855fdad5909809384946258158d30b1f7901c5f5c3a1


Tip: Customize your compliance reviews with Lula.

@github-actions github-actions Bot added waiting on rapidfort This PR is waiting on an image update for Rapidfort and removed needs-review Label used for Renovate PRs that are ready for review/test labels Mar 18, 2026
| datasource  | package                                              | from   | to     |
| ----------- | ---------------------------------------------------- | ------ | ------ |
| helm        | base                                                 | 1.28.3 | 1.29.1 |
| helm        | cni                                                  | 1.28.3 | 1.29.1 |
| docker      | docker.io/istio/install-cni                          | 1.28.3 | 1.29.1 |
| docker      | docker.io/istio/pilot                                | 1.28.3 | 1.29.1 |
| docker      | docker.io/istio/proxyv2                              | 1.28.3 | 1.29.1 |
| docker      | docker.io/istio/ztunnel                              | 1.28.3 | 1.29.1 |
| helm        | gateway                                              | 1.28.3 | 1.29.1 |
| github-tags | istio/istio                                          | 1.28.3 | 1.29.1 |
| helm        | istiod                                               | 1.28.3 | 1.29.1 |
| github-tags | kubernetes-sigs/gateway-api                          | v1.4.1 | v1.5.1 |
| docker      | quay.io/rfcurated/istio/install-cni                  | 1.28.3 | 1.29.1 |
| docker      | quay.io/rfcurated/istio/pilot                        | 1.28.3 | 1.29.1 |
| docker      | quay.io/rfcurated/istio/proxyv2                      | 1.28.3 | 1.29.1 |
| docker      | quay.io/rfcurated/istio/ztunnel                      | 1.28.3 | 1.29.1 |
| docker      | registry1.dso.mil/ironbank/tetrate/istio/install-cni | 1.28.3 | 1.29.1 |
| docker      | registry1.dso.mil/ironbank/tetrate/istio/pilot       | 1.28.3 | 1.29.1 |
| docker      | registry1.dso.mil/ironbank/tetrate/istio/proxyv2     | 1.28.3 | 1.29.1 |
| docker      | registry1.dso.mil/ironbank/tetrate/istio/ztunnel     | 1.28.3 | 1.29.1 |
| helm        | ztunnel                                              | 1.28.3 | 1.29.1 |
@renovate renovate Bot force-pushed the renovate/istio branch from 50a7d41 to d5770b0 Compare March 19, 2026 01:51
@renovate renovate Bot requested a review from a team as a code owner March 19, 2026 01:51
@github-actions github-actions Bot dismissed their stale review March 19, 2026 01:51

Superseded by a new Lula compliance review.

Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lula Compliance Overview

Please review the changes to ensure they meet compliance standards.

Reviewed Changes

Lula reviewed 13 files changed that affect compliance.


File Lines Changed
src/istio/zarf.yaml 59–65
src/istio/zarf.yaml 83–89

UUID: b4367e52-bef0-4463-a906-e5af6b4aa015
sha256: ffc7be359db0b3d5966119192d97c22edca895415429fa5fbf20fbe129f050fe

UUID: b4367e52-bef0-4463-a906-e5af6b4aa015
sha256: 9f0c5e42942cfbda55f0194ee44da71705d3665ddefd0e86f18bab9cbb1189f8


Tip: Customize your compliance reviews with Lula.

@github-actions github-actions Bot added needs-review Label used for Renovate PRs that are ready for review/test and removed waiting on rapidfort This PR is waiting on an image update for Rapidfort labels Mar 19, 2026
@mjnagel mjnagel dismissed github-actions[bot]’s stale review March 19, 2026 01:55

no compliance change

Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lula Compliance Overview

Please review the changes to ensure they meet compliance standards.

Reviewed Changes

Lula reviewed 15 files changed that affect compliance.


File Lines Changed
src/istio/zarf.yaml 59–65
src/istio/zarf.yaml 83–89

UUID: b4367e52-bef0-4463-a906-e5af6b4aa015
sha256: ffc7be359db0b3d5966119192d97c22edca895415429fa5fbf20fbe129f050fe

UUID: b4367e52-bef0-4463-a906-e5af6b4aa015
sha256: 9f0c5e42942cfbda55f0194ee44da71705d3665ddefd0e86f18bab9cbb1189f8


Tip: Customize your compliance reviews with Lula.

@mjnagel mjnagel dismissed github-actions[bot]’s stale review March 19, 2026 01:57

no compliance changes

@renovate
Copy link
Copy Markdown
Contributor Author

renovate Bot commented Mar 19, 2026

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lula Compliance Overview

Please review the changes to ensure they meet compliance standards.

Reviewed Changes

Lula reviewed 15 files changed that affect compliance.


File Lines Changed
src/istio/zarf.yaml 59–65
src/istio/zarf.yaml 83–89

UUID: b4367e52-bef0-4463-a906-e5af6b4aa015
sha256: ffc7be359db0b3d5966119192d97c22edca895415429fa5fbf20fbe129f050fe

UUID: b4367e52-bef0-4463-a906-e5af6b4aa015
sha256: 9f0c5e42942cfbda55f0194ee44da71705d3665ddefd0e86f18bab9cbb1189f8


Tip: Customize your compliance reviews with Lula.

@mjnagel mjnagel dismissed github-actions[bot]’s stale review March 19, 2026 20:31

no compliance changes

Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lula Compliance Overview

Please review the changes to ensure they meet compliance standards.

Reviewed Changes

Lula reviewed 15 files changed that affect compliance.


File Lines Changed
src/istio/zarf.yaml 59–65
src/istio/zarf.yaml 83–89

UUID: b4367e52-bef0-4463-a906-e5af6b4aa015
sha256: ffc7be359db0b3d5966119192d97c22edca895415429fa5fbf20fbe129f050fe

UUID: b4367e52-bef0-4463-a906-e5af6b4aa015
sha256: 9f0c5e42942cfbda55f0194ee44da71705d3665ddefd0e86f18bab9cbb1189f8


Tip: Customize your compliance reviews with Lula.

@mjnagel mjnagel dismissed github-actions[bot]’s stale review March 19, 2026 21:01

no compliance changes

@mjnagel mjnagel changed the title chore(deps): update istio chore(deps): update istio from 1.28.3 to 1.29.1 Mar 19, 2026
@mjnagel mjnagel merged commit db05c8f into main Mar 19, 2026
32 checks passed
@mjnagel mjnagel deleted the renovate/istio branch March 19, 2026 21:32
joelmccoy pushed a commit that referenced this pull request Mar 23, 2026
🤖 I have created a release *beep* *boop*
---


##
[1.0.0](v0.63.0...v1.0.0)
(2026-03-23)


### ⚠ BREAKING CHANGES

* Package CRs with `network.allow` rules that do not explicitly specify
a "remote" (`remoteGenerated`, `remoteNamespace`, `remoteSelector`,
`remoteCidr`, or `remoteHost`) will be blocked at admission time.
Packages previously using this behavior for "anywhere" ingress/egress
should be updated to explicitly include `remoteGenerated: Anywhere` or
`remoteNamespace: "*"` (anything in cluster).
* Removed `operator.KUBEAPI_CIDR` and `operator.KUBENODE_CIDRS` from the
UDS Operator Config helm chart. Users should remove any existing
overrides utilizing the removed values. Users should switch to
`cluster.networking.kubeApiCIDR` and `cluster.networking.kubeNodeCIDRs`
values, respectively.
* Removed `fipsAllowWeakPasswords` and previously deprecated `fips`
value from Keycloak helm chart. FIPS mode is now enabled by default.
Users should remove any existing overrides utilizing the removed values.
See the
[documentation](https://github.com/defenseunicorns/uds-core/blob/main/docs/how-to-guides/identity-and-authorization/enable-fips-mode.mdx)
for more details on handling password upgrades if you were not running
in FIPS mode previously.
* Removed `CA_CERT` Zarf variable and `spec.expose.caCert` ClusterConfig
field. Migrate to the `CA_BUNDLE_CERTS` Zarf variable /
`spec.caBundle.certs` field.
* Removed previously deprecated `x509LookupProvider` and
`mtlsClientCert` values from Keycloak helm chart. Users should remove
any existing overrides utilizing the removed values and use
`thirdPartyIntegration.tls.tlsCertificateHeader` and
`thirdPartyIntegration.tls.tlsCertificateFormat` instead.

### Features

* add keycloak realm display name customization
([#2479](#2479))
([10aa771](10aa771))


### Bug Fixes

* **ci:** handle flaky behavior around policy test and probe check
([#2519](#2519))
([f2bc6a1](f2bc6a1))
* incr loki backend replicas to 3 in upgrade test
([ba33b49](ba33b49))
* **lint:** enforce strict equality and add regression guard lint rules
([#2411](#2411))
([880c748](880c748))
* reject network.allow rules without a remote
([#2510](#2510))
([0ef9d41](0ef9d41))


### Miscellaneous

* add polling/increase timeout to prometheus target e2e test
([#2452](#2452))
([c6f11d4](c6f11d4))
* bump loki helm chart to 6.57.0
([ba33b49](ba33b49))
* cleanup deprecations table so it renders better on docs site
([#2506](#2506))
([0db9fc5](0db9fc5))
* correct the category annotation to 'dev.uds.categories'
([#2454](#2454))
([48c05d6](48c05d6))
* **deps-dev:** bump undici from 7.16.0 to 7.24.1 in /test/vitest
([#2469](#2469))
([a192d0e](a192d0e))
* **deps:** align identity-authorization terminology
([#2482](#2482))
([5698329](5698329))
* **deps:** bump flatted from 3.3.3 to 3.4.1
([#2472](#2472))
([5e65aa1](5e65aa1))
* **deps:** bump undici from 7.20.0 to 7.24.4
([#2475](#2475))
([6635b2e](6635b2e))
* **deps:** update grafana from 12.4.0 to 12.4.1
([#2443](#2443))
([bba40a4](bba40a4))
* **deps:** update iac-support-deps
([#2464](#2464))
([c14d667](c14d667))
* **deps:** update iac-support-deps
([#2481](#2481))
([efdac7b](efdac7b))
* **deps:** update identity-config from 0.24.0 to 0.25.0
([#2514](#2514))
([607ec5a](607ec5a))
* **deps:** update istio from 1.28.3 to 1.29.1
([#2387](#2387))
([db05c8f](db05c8f))
* **deps:** update loki (memcached 1.6.41, nginx 1.29.6)
([#2441](#2441))
([0625f8b](0625f8b))
* **deps:** update pepr from 1.1.2 to 1.1.4
([#2484](#2484))
([4cb5cdd](4cb5cdd))
* **deps:** update prometheus-stack
([#2420](#2420))
([5041496](5041496))
* **deps:** update prometheus-stack
([#2474](#2474))
([e2abba4](e2abba4))
* **deps:** update support-deps
([#2450](#2450))
([84e409f](84e409f))
* **deps:** update vector to 0.54.0
([#2451](#2451))
([5fc8bac](5fc8bac))
* **docs:** add backup restore how to guides
([#2456](#2456))
([6f785a2](6f785a2))
* **docs:** add compliance callout
([#2497](#2497))
([68a77e5](68a77e5))
* **docs:** add docs on functional layers
([#2501](#2501))
([f3fbda9](f3fbda9))
* **docs:** add docs.config.json file
([#2473](#2473))
([fc4f9f5](fc4f9f5))
* **docs:** add how to guides for additional core packages
([#2491](#2491))
([170f12f](170f12f))
* **docs:** add how-to guides for monitoring to new docs site
([#2445](#2445))
([44e0c46](44e0c46))
* **docs:** add keycloak notifications and alerts how to guide
([#2516](#2516))
([6c405b9](6c405b9))
* **docs:** add likec4 diagram
([#2500](#2500))
([a08e63c](a08e63c))
* **docs:** add new how-to docs for logging
([#2453](#2453))
([f18ac93](f18ac93))
* **docs:** add platform features how-to docs
([#2460](#2460))
([bd66bce](bd66bce))
* **docs:** add troubleshooting/runbooks section to new docs site
([#2449](#2449))
([8ffced3](8ffced3))
* **docs:** add uds packaging docs
([#2457](#2457))
([6e92672](6e92672))
* **docs:** add versioning/release concept doc to new site
([#2495](#2495))
([0bed16c](0bed16c))
* **docs:** add voice/style profile for docs writing and update docs
([#2509](#2509))
([630fa16](630fa16))
* **docs:** address documentation feedback and cleanup
([#2493](#2493))
([4bb2736](4bb2736))
* **docs:** cleanup promql and logql code blocks
([#2477](#2477))
([65a961d](65a961d))
* **docs:** cleanup reference docs for operator CRDs on new site
([#2467](#2467))
([e437538](e437538))
* **docs:** enable pagination override for getting started docs
([#2463](#2463))
([bf1c9bc](bf1c9bc))
* **docs:** fix overview paths
([#2462](#2462))
([6dd3ad8](6dd3ad8))
* **docs:** identity-access how to guides
([#2437](#2437))
([74f1d39](74f1d39))
* **docs:** reference section part 2
([#2465](#2465))
([0249240](0249240))
* **docs:** remove css from index.mdx file
([#2499](#2499))
([1263b5e](1263b5e))
* **docs:** runtime-security how to guides
([#2448](#2448))
([88b6662](88b6662))
* **docs:** update doc dir naming
([#2522](#2522))
([33be9b3](33be9b3))
* **docs:** update monitoring ha guide with prometheus sizing
([#2468](#2468))
([2c7f183](2c7f183))
* **docs:** update to create landing page
([#2476](#2476))
([e780443](e780443))
* **docs:** use registry references in new doc site instead of ghcr
([#2496](#2496))
([509206b](509206b))
* fix dev-docs local script
([#2488](#2488))
([793cf1a](793cf1a))
* incr loki backend/read/write replicas to 3 in ha upgrade test
([ba33b49](ba33b49))
* remove deprecated CA_CERT variable
([#2489](#2489))
([ffdfc48](ffdfc48))
* remove deprecated operator config CIDR values
([#2494](#2494))
([e290cdc](e290cdc))
* remove keycloak FIPS switch
([#2483](#2483))
([f5b63d0](f5b63d0))
* remove x509LookupProvider and mtlsClientCert from KC values
([#2486](#2486))
([9496bfe](9496bfe))
* replace accredit with authorize in docs
([#2507](#2507))
([f3f4072](f3f4072))
* switch loki helm chart to grafana-community chart
([ba33b49](ba33b49))
* update dev-docs to align with cli
([#2498](#2498))
([30074c7](30074c7))
* update public ca config to exclude new root
([#2511](#2511))
([139940e](139940e))


### Documentation

* add documentation on resizing prometheus volumes
([#2440](#2440))
([bd54266](bd54266))
* add guide link
([#2471](#2471))
([df47223](df47223))
* add how-tos for policy/compliance
([#2461](#2461))
([2b9a33f](2b9a33f))
* add release notes for 1.0
([#2515](#2515))
([f4903da](f4903da))
* clean up 1.0 release notes page
([#2523](#2523))
([9eff8fd](9eff8fd))
* fix concepts titles and delete stub
([#2508](#2508))
([cc94720](cc94720))
* fix policy engine reference page
([#2504](#2504))
([2c92bf9](2c92bf9))
* how-to guide fixes and updated guidance
([#2466](#2466))
([2e78ee6](2e78ee6))
* operations and maintenance - upgrades and configuration changes
([#2487](#2487))
([59178ba](59178ba))
* update deprecation table for Package deprecations
([#2492](#2492))
([c583f96](c583f96))
* update dev-docs task to handle core subdir
([#2480](#2480))
([b36398f](b36398f))
* update network docs, add trust management
([#2459](#2459))
([940fc64](940fc64))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
briantwatson added a commit that referenced this pull request Apr 22, 2026
## Description

Working on istio v1 update I came across what I believe is a gap in our
autogenerated-check.

We updated to 1.29.1 here:
#2387

## Related Issue

Relates to CORE-44

## Type of change

- [x] Bug fix (non-breaking change which fixes an issue)
- [ ] New feature (non-breaking change which adds functionality)
- [ ] Other (security config, docs update, etc)

## Steps to Validate
n/a

## Checklist before merging

- [x] Test, docs, adr added or updated as needed
- [x] [Contributor
Guide](https://github.com/defenseunicorns/uds-core/blob/main/CONTRIBUTING.md)
followed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-review Label used for Renovate PRs that are ready for review/test

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants