Skip to content

Conversation

@jukie
Copy link
Contributor

@jukie jukie commented Jul 25, 2025

What type of PR is this?

feat: expose explicit configuration for Zone Aware Routing

What this PR does / why we need it:
This is the last PR related to splitting #6482 with the goal of exposing configuration for envoy localityLbConfig via BackendTrafficPolicy. Currently only ZoneAwareLbConfig is implemented but I'm planning on a followup to supported weightedLocalityLbConfig as well.
There's a lot of testdata changes here and I don't see a good way to split this up further without breaking e2e's but I've created draft PRs to try and make it easier to review.

Changes:

Which issue(s) this PR fixes:

Fixes #6025

Release Notes: Yes

Signed-off-by: jukie <10012479+Jukie@users.noreply.github.com>
@jukie jukie changed the title Track proxy servicecluster via xDS feat: Implement ZoneAware loadbalancing - Track Envoy pods via xDS (splitup #6482) Jul 25, 2025
jukie added 2 commits July 25, 2025 15:44
Signed-off-by: jukie <10012479+Jukie@users.noreply.github.com>
Signed-off-by: jukie <10012479+Jukie@users.noreply.github.com>
@codecov
Copy link

codecov bot commented Jul 25, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 71.10%. Comparing base (f90e696) to head (5bc6890).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #6597      +/-   ##
==========================================
+ Coverage   71.03%   71.10%   +0.07%     
==========================================
  Files         225      225              
  Lines       39155    39264     +109     
==========================================
+ Hits        27813    27918     +105     
- Misses       9732     9734       +2     
- Partials     1610     1612       +2     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

jukie and others added 4 commits July 25, 2025 16:01
Signed-off-by: jukie <10012479+Jukie@users.noreply.github.com>
Signed-off-by: jukie <10012479+Jukie@users.noreply.github.com>
Signed-off-by: jukie <10012479+Jukie@users.noreply.github.com>
@jukie jukie force-pushed the track-proxy-instances-xds branch from a7d21dc to cad1754 Compare July 26, 2025 01:16
@jukie jukie marked this pull request as ready for review July 26, 2025 01:29
@jukie jukie requested a review from a team as a code owner July 26, 2025 01:29
@jukie jukie requested a review from a team July 26, 2025 01:29
Signed-off-by: jukie <10012479+Jukie@users.noreply.github.com>
@jukie
Copy link
Contributor Author

jukie commented Jul 26, 2025

/retest

@jukie jukie added this to the v1.5.0-rc.1 Release milestone Jul 26, 2025
@jukie
Copy link
Contributor Author

jukie commented Jul 26, 2025

/retest

@jukie
Copy link
Contributor Author

jukie commented Jul 27, 2025

/retest

1 similar comment
@jukie
Copy link
Contributor Author

jukie commented Jul 27, 2025

/retest

jukie and others added 2 commits July 27, 2025 22:07
Signed-off-by: Isaac <10012479+jukie@users.noreply.github.com>
Signed-off-by: jukie <10012479+Jukie@users.noreply.github.com>
@jukie
Copy link
Contributor Author

jukie commented Jul 28, 2025

/retest

jukie and others added 2 commits July 28, 2025 08:45
Signed-off-by: jukie <10012479+Jukie@users.noreply.github.com>
arkodg
arkodg previously approved these changes Jul 30, 2025
Copy link
Contributor

@arkodg arkodg left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM thanks @jukie

would like to get this in, hope the remaining comments can be addressed post rc before v1.5.0

func (t *Translator) ProcessGlobalResources(resources *resource.Resources, xdsIRs resource.XdsIRMap) error {
func (t *Translator) ProcessGlobalResources(resources *resource.Resources, xdsIRs resource.XdsIRMap, gateways []*GatewayContext) error {
// Add the ProxyServiceCluster information for each gateway to the IR map
for _, gateway := range gateways {
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this should ideally iterate over infraIR, right now we iterate through all gateways even for mergeGateways case, can be handled in a follow up

continue
}
match := true
for k, v := range labels {
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

non-blocking, we can reuse somehting like

func isSelectorMatch(labelselector *metav1.LabelSelector, l map[string]string) (bool, error) {
	selector, err := metav1.LabelSelectorAsSelector(labelselector)
	if err != nil {
		return false, fmt.Errorf("invalid label selector is generated: %w", err)
	}

	return selector.Matches(klabels.Set(l)), nil
}

@jukie
Copy link
Contributor Author

jukie commented Jul 30, 2025

/retest

@jukie
Copy link
Contributor Author

jukie commented Jul 30, 2025

I can followup with the rest of the changes before the full release

jukie and others added 2 commits July 29, 2025 22:07
accessLog:
json:
- path: /dev/stdout
globalResources:
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we can fix this later

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think that's expected here because the testdata input needs updated.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey @zirain I saw #6678. Was I mistaken here?

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

why globalResources not present in GatewayNamesapceMode?

@arkodg arkodg requested a review from zirain July 30, 2025 05:05
@arkodg arkodg merged commit 288e713 into envoyproxy:main Jul 30, 2025
45 of 47 checks passed
arkodg pushed a commit that referenced this pull request Jul 30, 2025
Cleanup

Signed-off-by: jukie <10012479+Jukie@users.noreply.github.com>
@jukie jukie deleted the track-proxy-instances-xds branch July 30, 2025 21:57
zirain pushed a commit to zirain/gateway that referenced this pull request Aug 5, 2025
Cleanup

Signed-off-by: jukie <10012479+Jukie@users.noreply.github.com>
zirain pushed a commit to zirain/gateway that referenced this pull request Aug 5, 2025
Cleanup

Signed-off-by: jukie <10012479+Jukie@users.noreply.github.com>
Signed-off-by: zirain <zirain2009@gmail.com>
zirain added a commit that referenced this pull request Aug 5, 2025
* chore: cleanups from #6597 (#6647)

Cleanup

Signed-off-by: jukie <10012479+Jukie@users.noreply.github.com>
Signed-off-by: zirain <zirain2009@gmail.com>

* fix: set order for grpc_web and grpc_stats filters (#6626)

* set order for grpc_web and grpc_stats filters

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* address comment

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

---------

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>
Signed-off-by: zirain <zirain2009@gmail.com>

* fix: nil pointer when InsecureSkipVerify is true (#6652)

* fix nil pointer when InsecureSkipVerify is true

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* add test

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* delete cacert for the xds translator test

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>
Signed-off-by: zirain <zirain2009@gmail.com>

* fix: allow imageRepository contains port (#6658) (#6660)

(cherry picked from commit c988ec5)

Signed-off-by: Arko Dasgupta <arko@tetrate.io>
Co-authored-by: 聪 <congwu@alauda.io>
Signed-off-by: zirain <zirain2009@gmail.com>

* docs: improve policy concepts section (#6663)

better explain
* targets
* precedence
* merge types

Signed-off-by: Arko Dasgupta <arko@tetrate.io>
Signed-off-by: zirain <zirain2009@gmail.com>

* docs: observability pre req not required in admin console page (#6662)

Signed-off-by: Arko Dasgupta <arko@tetrate.io>
Signed-off-by: zirain <zirain2009@gmail.com>

* docs: xds name scheme v2 (#6656)

* name scheme v2

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

name scheme v2

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* address comment

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* address comment

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

---------

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>
Signed-off-by: zirain <zirain2009@gmail.com>

* docs: highlight wait step (#6665)

* docs: highlight wait step

Signed-off-by: zirain <zirain2009@gmail.com>

* update

Signed-off-by: zirain <zirain2009@gmail.com>

---------

Signed-off-by: zirain <zirain2009@gmail.com>

* fix: populate status for custom backendRef not found (#6670)

Signed-off-by: bitliu <bitliu@tencent.com>
Signed-off-by: zirain <zirain2009@gmail.com>

* fix: xds name schema v2 (#6638)

* rename route config

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* rename HCM statPrefix

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* rename virtual host

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* fix test

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* minor change

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* address comment

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

---------

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>
Signed-off-by: zirain <zirain2009@gmail.com>

* docs: expand Gateway Namespace Mode doc on client/server auth (#6616)

* Expand Gateway Namespace Mode doc on client/server auth

Signed-off-by: Karol Szwaj <karol.szwaj@gmail.com>

* Add additional explanation to the overview

Signed-off-by: Karol Szwaj <karol.szwaj@gmail.com>

---------

Signed-off-by: Karol Szwaj <karol.szwaj@gmail.com>
Signed-off-by: zirain <zirain2009@gmail.com>

* increase earlyRequestHeaders from 16 to 64 (#6673)

* created a new definition of HTTPFilterHeader that supports 64 items
for `set`, `add`, and `remove`

* sanitizing request headers from untrusted downstream traffic is a
  common use case and 16 items may not be adequate enough at times.
  This action needs to be performed route processing for cases
  and the HTTPRoute filters cannot be used

Signed-off-by: Arko Dasgupta <arko@tetrate.io>
Signed-off-by: zirain <zirain2009@gmail.com>

* docs: skipping TLS verification (#6653)

* docs for skipping TLS verification

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* remove btlsp for skiptlsverify

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* address comment

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* address comment

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* remove public

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

---------

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>
Signed-off-by: zirain <zirain2009@gmail.com>

* feat: add listener metadata (#6639)

* add listener metadata

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* remove sort

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

---------

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>
Signed-off-by: zirain <zirain2009@gmail.com>

* fix: Fix BTP ZoneAware translation (#6668)

* Fix BTP ZoneAware translation

Signed-off-by: jukie <10012479+Jukie@users.noreply.github.com>

* Add e2e

Signed-off-by: jukie <10012479+Jukie@users.noreply.github.com>

---------

Signed-off-by: jukie <10012479+Jukie@users.noreply.github.com>
Signed-off-by: zirain <zirain2009@gmail.com>

* docs: unhide zoneaware api for docs (#6683)

unhide api docs

Signed-off-by: jukie <10012479+Jukie@users.noreply.github.com>
Signed-off-by: zirain <zirain2009@gmail.com>

* watchable: use Store directly instead of HandleStore wrapper (#6680)

* watchable: use Store directly instead of HandleStore wrapper

GC is unable to collect the temporary references created in
`HandleStore`

Relates to #6406

Signed-off-by: Arko Dasgupta <arko@tetrate.io>

* fix test

Signed-off-by: Arko Dasgupta <arko@tetrate.io>

---------

Signed-off-by: Arko Dasgupta <arko@tetrate.io>
Signed-off-by: zirain <zirain2009@gmail.com>

* docs: Update Zone Aware Routing for BackendTrafficPolicy configuration example (#6667)

Update zone aware routing docs

Signed-off-by: jukie <10012479+Jukie@users.noreply.github.com>
Signed-off-by: zirain <zirain2009@gmail.com>

* combine the xds-translator and xds-server runner into one (#6586)

* combine the xds-translator and xds-server into one xds runner

* primarily to reduce memory and convergence time

Signed-off-by: Arko Dasgupta <arko@tetrate.io>
Signed-off-by: zirain <zirain2009@gmail.com>

* build(deps): bump the gomod group across 1 directory with 6 updates (#6691)

* build(deps): bump the gomod group across 1 directory with 6 updates

Bumps the gomod group with 4 updates in the / directory: [github.com/miekg/dns](https://github.com/miekg/dns), [github.com/prometheus/client_golang](https://github.com/prometheus/client_golang), [github.com/quic-go/quic-go](https://github.com/quic-go/quic-go) and [go.opentelemetry.io/proto/otlp](https://github.com/open-telemetry/opentelemetry-proto-go).

Updates `github.com/miekg/dns` from 1.1.67 to 1.1.68
- [Changelog](https://github.com/miekg/dns/blob/master/Makefile.release)
- [Commits](miekg/dns@v1.1.67...v1.1.68)

Updates `github.com/prometheus/client_golang` from 1.22.0 to 1.23.0
- [Release notes](https://github.com/prometheus/client_golang/releases)
- [Changelog](https://github.com/prometheus/client_golang/blob/main/CHANGELOG.md)
- [Commits](prometheus/client_golang@v1.22.0...v1.23.0)

Updates `github.com/quic-go/quic-go` from 0.52.0 to 0.54.0
- [Release notes](https://github.com/quic-go/quic-go/releases)
- [Commits](quic-go/quic-go@v0.52.0...v0.54.0)

Updates `go.opentelemetry.io/proto/otlp` from 1.7.0 to 1.7.1
- [Release notes](https://github.com/open-telemetry/opentelemetry-proto-go/releases)
- [Commits](open-telemetry/opentelemetry-proto-go@v1.7.0...v1.7.1)

Updates `google.golang.org/genproto/googleapis/api` from 0.0.0-20250603155806-513f23925822 to 0.0.0-20250728155136-f173205681a0
- [Commits](https://github.com/googleapis/go-genproto/commits)

Updates `google.golang.org/genproto/googleapis/rpc` from 0.0.0-20250603155806-513f23925822 to 0.0.0-20250728155136-f173205681a0
- [Commits](https://github.com/googleapis/go-genproto/commits)

---
updated-dependencies:
- dependency-name: github.com/miekg/dns
  dependency-version: 1.1.68
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: gomod
- dependency-name: github.com/prometheus/client_golang
  dependency-version: 1.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod
- dependency-name: github.com/quic-go/quic-go
  dependency-version: 0.54.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod
- dependency-name: go.opentelemetry.io/proto/otlp
  dependency-version: 1.7.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: gomod
- dependency-name: google.golang.org/genproto/googleapis/api
  dependency-version: 0.0.0-20250728155136-f173205681a0
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: gomod
- dependency-name: google.golang.org/genproto/googleapis/rpc
  dependency-version: 0.0.0-20250728155136-f173205681a0
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: gomod
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix gen

Signed-off-by: zirain <zirain2009@gmail.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: zirain <zirain2009@gmail.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: zirain <zirain2009@gmail.com>
Signed-off-by: zirain <zirain2009@gmail.com>

* fix: controller panic when reloading config (#6688)

* fix controller panic when reloading config

Signed-off-by: zirain <zirain2009@gmail.com>

* use gwapiv1.Duration instead of metav1.Duration (#6664)

* use gwapiv1.Duration instead of metav1.Duration

fixes: #4746

Signed-off-by: Arko Dasgupta <arko@tetrate.io>

* add charts

Signed-off-by: Arko Dasgupta <arko@tetrate.io>

* go back to metav1 in IR to make YAML tests happy

Signed-off-by: Arko Dasgupta <arko@tetrate.io>
Signed-off-by: zirain <zirain2009@gmail.com>

* fix: don't block deployment creating when missing secret in EnvoyProxy (#6692)

* fix: don't block deployment creating when missing secret in EnvoyProxy

Signed-off-by: zirain <zirain2009@gmail.com>

* [release/v1.5] release notes for rc.2 (#6697)

* [release/v1.5] release notes for rc.2

Signed-off-by: zirain <zirain2009@gmail.com>

---------

Signed-off-by: jukie <10012479+Jukie@users.noreply.github.com>
Signed-off-by: zirain <zirain2009@gmail.com>
Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>
Signed-off-by: Arko Dasgupta <arko@tetrate.io>
Signed-off-by: bitliu <bitliu@tencent.com>
Signed-off-by: Karol Szwaj <karol.szwaj@gmail.com>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: Isaac <10012479+jukie@users.noreply.github.com>
Co-authored-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>
Co-authored-by: Arko Dasgupta <arkodg@users.noreply.github.com>
Co-authored-by: 聪 <congwu@alauda.io>
Co-authored-by: Xunzhuo <bitliu@tencent.com>
Co-authored-by: Karol Szwaj <karol.szwaj@gmail.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
zirain added a commit to zirain/gateway that referenced this pull request Sep 16, 2025
* chore: cleanups from envoyproxy#6597 (envoyproxy#6647)

Cleanup

Signed-off-by: jukie <10012479+Jukie@users.noreply.github.com>
Signed-off-by: zirain <zirain2009@gmail.com>

* fix: set order for grpc_web and grpc_stats filters (envoyproxy#6626)

* set order for grpc_web and grpc_stats filters

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* address comment

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

---------

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>
Signed-off-by: zirain <zirain2009@gmail.com>

* fix: nil pointer when InsecureSkipVerify is true (envoyproxy#6652)

* fix nil pointer when InsecureSkipVerify is true

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* add test

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* delete cacert for the xds translator test

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>
Signed-off-by: zirain <zirain2009@gmail.com>

* fix: allow imageRepository contains port (envoyproxy#6658) (envoyproxy#6660)

(cherry picked from commit c988ec5)

Signed-off-by: Arko Dasgupta <arko@tetrate.io>
Co-authored-by: 聪 <congwu@alauda.io>
Signed-off-by: zirain <zirain2009@gmail.com>

* docs: improve policy concepts section (envoyproxy#6663)

better explain
* targets
* precedence
* merge types

Signed-off-by: Arko Dasgupta <arko@tetrate.io>
Signed-off-by: zirain <zirain2009@gmail.com>

* docs: observability pre req not required in admin console page (envoyproxy#6662)

Signed-off-by: Arko Dasgupta <arko@tetrate.io>
Signed-off-by: zirain <zirain2009@gmail.com>

* docs: xds name scheme v2 (envoyproxy#6656)

* name scheme v2

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

name scheme v2

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* address comment

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* address comment

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

---------

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>
Signed-off-by: zirain <zirain2009@gmail.com>

* docs: highlight wait step (envoyproxy#6665)

* docs: highlight wait step

Signed-off-by: zirain <zirain2009@gmail.com>

* update

Signed-off-by: zirain <zirain2009@gmail.com>

---------

Signed-off-by: zirain <zirain2009@gmail.com>

* fix: populate status for custom backendRef not found (envoyproxy#6670)

Signed-off-by: bitliu <bitliu@tencent.com>
Signed-off-by: zirain <zirain2009@gmail.com>

* fix: xds name schema v2 (envoyproxy#6638)

* rename route config

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* rename HCM statPrefix

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* rename virtual host

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* fix test

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* minor change

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* address comment

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

---------

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>
Signed-off-by: zirain <zirain2009@gmail.com>

* docs: expand Gateway Namespace Mode doc on client/server auth (envoyproxy#6616)

* Expand Gateway Namespace Mode doc on client/server auth

Signed-off-by: Karol Szwaj <karol.szwaj@gmail.com>

* Add additional explanation to the overview

Signed-off-by: Karol Szwaj <karol.szwaj@gmail.com>

---------

Signed-off-by: Karol Szwaj <karol.szwaj@gmail.com>
Signed-off-by: zirain <zirain2009@gmail.com>

* increase earlyRequestHeaders from 16 to 64 (envoyproxy#6673)

* created a new definition of HTTPFilterHeader that supports 64 items
for `set`, `add`, and `remove`

* sanitizing request headers from untrusted downstream traffic is a
  common use case and 16 items may not be adequate enough at times.
  This action needs to be performed route processing for cases
  and the HTTPRoute filters cannot be used

Signed-off-by: Arko Dasgupta <arko@tetrate.io>
Signed-off-by: zirain <zirain2009@gmail.com>

* docs: skipping TLS verification (envoyproxy#6653)

* docs for skipping TLS verification

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* remove btlsp for skiptlsverify

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* address comment

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* address comment

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* remove public

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

---------

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>
Signed-off-by: zirain <zirain2009@gmail.com>

* feat: add listener metadata (envoyproxy#6639)

* add listener metadata

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

* remove sort

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>

---------

Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>
Signed-off-by: zirain <zirain2009@gmail.com>

* fix: Fix BTP ZoneAware translation (envoyproxy#6668)

* Fix BTP ZoneAware translation

Signed-off-by: jukie <10012479+Jukie@users.noreply.github.com>

* Add e2e

Signed-off-by: jukie <10012479+Jukie@users.noreply.github.com>

---------

Signed-off-by: jukie <10012479+Jukie@users.noreply.github.com>
Signed-off-by: zirain <zirain2009@gmail.com>

* docs: unhide zoneaware api for docs (envoyproxy#6683)

unhide api docs

Signed-off-by: jukie <10012479+Jukie@users.noreply.github.com>
Signed-off-by: zirain <zirain2009@gmail.com>

* watchable: use Store directly instead of HandleStore wrapper (envoyproxy#6680)

* watchable: use Store directly instead of HandleStore wrapper

GC is unable to collect the temporary references created in
`HandleStore`

Relates to envoyproxy#6406

Signed-off-by: Arko Dasgupta <arko@tetrate.io>

* fix test

Signed-off-by: Arko Dasgupta <arko@tetrate.io>

---------

Signed-off-by: Arko Dasgupta <arko@tetrate.io>
Signed-off-by: zirain <zirain2009@gmail.com>

* docs: Update Zone Aware Routing for BackendTrafficPolicy configuration example (envoyproxy#6667)

Update zone aware routing docs

Signed-off-by: jukie <10012479+Jukie@users.noreply.github.com>
Signed-off-by: zirain <zirain2009@gmail.com>

* combine the xds-translator and xds-server runner into one (envoyproxy#6586)

* combine the xds-translator and xds-server into one xds runner

* primarily to reduce memory and convergence time

Signed-off-by: Arko Dasgupta <arko@tetrate.io>
Signed-off-by: zirain <zirain2009@gmail.com>

* build(deps): bump the gomod group across 1 directory with 6 updates (envoyproxy#6691)

* build(deps): bump the gomod group across 1 directory with 6 updates

Bumps the gomod group with 4 updates in the / directory: [github.com/miekg/dns](https://github.com/miekg/dns), [github.com/prometheus/client_golang](https://github.com/prometheus/client_golang), [github.com/quic-go/quic-go](https://github.com/quic-go/quic-go) and [go.opentelemetry.io/proto/otlp](https://github.com/open-telemetry/opentelemetry-proto-go).

Updates `github.com/miekg/dns` from 1.1.67 to 1.1.68
- [Changelog](https://github.com/miekg/dns/blob/master/Makefile.release)
- [Commits](miekg/dns@v1.1.67...v1.1.68)

Updates `github.com/prometheus/client_golang` from 1.22.0 to 1.23.0
- [Release notes](https://github.com/prometheus/client_golang/releases)
- [Changelog](https://github.com/prometheus/client_golang/blob/main/CHANGELOG.md)
- [Commits](prometheus/client_golang@v1.22.0...v1.23.0)

Updates `github.com/quic-go/quic-go` from 0.52.0 to 0.54.0
- [Release notes](https://github.com/quic-go/quic-go/releases)
- [Commits](quic-go/quic-go@v0.52.0...v0.54.0)

Updates `go.opentelemetry.io/proto/otlp` from 1.7.0 to 1.7.1
- [Release notes](https://github.com/open-telemetry/opentelemetry-proto-go/releases)
- [Commits](open-telemetry/opentelemetry-proto-go@v1.7.0...v1.7.1)

Updates `google.golang.org/genproto/googleapis/api` from 0.0.0-20250603155806-513f23925822 to 0.0.0-20250728155136-f173205681a0
- [Commits](https://github.com/googleapis/go-genproto/commits)

Updates `google.golang.org/genproto/googleapis/rpc` from 0.0.0-20250603155806-513f23925822 to 0.0.0-20250728155136-f173205681a0
- [Commits](https://github.com/googleapis/go-genproto/commits)

---
updated-dependencies:
- dependency-name: github.com/miekg/dns
  dependency-version: 1.1.68
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: gomod
- dependency-name: github.com/prometheus/client_golang
  dependency-version: 1.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod
- dependency-name: github.com/quic-go/quic-go
  dependency-version: 0.54.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod
- dependency-name: go.opentelemetry.io/proto/otlp
  dependency-version: 1.7.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: gomod
- dependency-name: google.golang.org/genproto/googleapis/api
  dependency-version: 0.0.0-20250728155136-f173205681a0
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: gomod
- dependency-name: google.golang.org/genproto/googleapis/rpc
  dependency-version: 0.0.0-20250728155136-f173205681a0
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: gomod
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix gen

Signed-off-by: zirain <zirain2009@gmail.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: zirain <zirain2009@gmail.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: zirain <zirain2009@gmail.com>
Signed-off-by: zirain <zirain2009@gmail.com>

* fix: controller panic when reloading config (envoyproxy#6688)

* fix controller panic when reloading config

Signed-off-by: zirain <zirain2009@gmail.com>

* use gwapiv1.Duration instead of metav1.Duration (envoyproxy#6664)

* use gwapiv1.Duration instead of metav1.Duration

fixes: envoyproxy#4746

Signed-off-by: Arko Dasgupta <arko@tetrate.io>

* add charts

Signed-off-by: Arko Dasgupta <arko@tetrate.io>

* go back to metav1 in IR to make YAML tests happy

Signed-off-by: Arko Dasgupta <arko@tetrate.io>
Signed-off-by: zirain <zirain2009@gmail.com>

* fix: don't block deployment creating when missing secret in EnvoyProxy (envoyproxy#6692)

* fix: don't block deployment creating when missing secret in EnvoyProxy

Signed-off-by: zirain <zirain2009@gmail.com>

* [release/v1.5] release notes for rc.2 (envoyproxy#6697)

* [release/v1.5] release notes for rc.2

Signed-off-by: zirain <zirain2009@gmail.com>

---------

Signed-off-by: jukie <10012479+Jukie@users.noreply.github.com>
Signed-off-by: zirain <zirain2009@gmail.com>
Signed-off-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>
Signed-off-by: Arko Dasgupta <arko@tetrate.io>
Signed-off-by: bitliu <bitliu@tencent.com>
Signed-off-by: Karol Szwaj <karol.szwaj@gmail.com>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: Isaac <10012479+jukie@users.noreply.github.com>
Co-authored-by: Huabing (Robin) Zhao <zhaohuabing@gmail.com>
Co-authored-by: Arko Dasgupta <arkodg@users.noreply.github.com>
Co-authored-by: 聪 <congwu@alauda.io>
Co-authored-by: Xunzhuo <bitliu@tencent.com>
Co-authored-by: Karol Szwaj <karol.szwaj@gmail.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: zirain <zirain2009@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Explicit settings for Zone Aware Routing

3 participants