What's new in Istio
Istio ships roughly one minor per quarter. 1.31 (31 August 2026) continues the two tracks of the last releases: hardening ambient for large and multi-cluster meshes, and keeping the Gateway API implementation at upstream parity (now built against v1.6.0). The bigger operational change sits outside the code: from 1.31 on, images are published only to docker.io/istio and Helm charts to blob.istio.io and ghcr.io, while the GCP-hosted locations go dark in December 2026.
Last checked: 1 October 2026. Every entry is taken from the project's own release notes, linked at the bottom. This is a curated selection, not a full changelog.
1.31
31 August 2026- deprecated GCP-hosted artifacts go dark in December 2026
From 1.31 on, images are published only to docker.io/istio, Helm charts to https://blob.istio.io/istio-release/charts and OCI charts to ghcr.io/istio/release/charts. gcr.io/istio-release, registry.istio.io/release and istio-release.storage.googleapis.com are removed in December 2026; scream tests switch them off on 13 October (15:00 to 18:00 UTC), 17 November (15:00 to 21:00 UTC) and for 24 hours from 8 December 2026, 15:00 UTC. 1.30 defaults to registry.istio.io/release, so 1.30 installations are affected without any upgrade: set hub and global.hub to docker.io/istio or a pull-through cache. 1.31.0 is still signed with istio-key.pub; 1.31.1 and later use istio-key-v2.pub, so signature-verification policies need the new public key.
- breaking TCPRoute CRDs below Gateway API v1.6.0 are ignored
istiod 1.31 is built against Gateway API v1.6.0, in which TCPRoute graduated to GA, and only processes TCPRoute CRDs whose bundle-version is at least v1.6.0 (TLSRoute stays at v1.5.0, BackendTLSPolicy at v1.4.0). CRDs below the minimum are not watched, so their TCPRoute resources drop out of the configuration without an error on the route. istioctl analyze reports this as IST0176. Upgrade the Gateway API CRDs before istiod.
- breaking Unhealthy endpoints are now sent to Envoy
istiod now includes unhealthy endpoints in EDS by default, except for destinations whose DestinationRule sets outlierDetection.minHealthPercent above 0. The switch is PILOT_AUTO_SEND_UNHEALTHY_ENDPOINTS (default true); set it to false, or use a compatibility profile, to keep the previous behaviour mesh-wide.
- breaking Large ambient meshes: raise the istiod gRPC receive limit
A ztunnel reconnect, such as the periodic recycle via keepaliveMaxServerConnectionAge, no longer triggers a full WDS push: ztunnel reports the version of every resource it holds and istiod re-sends only what changed. The larger request lowers the point at which it exceeds istiod's default 4 MiB gRPC receive limit from roughly 55,000 to roughly 40,000 workloads (sooner with long resource names or many services), and ztunnel then loops on ResourceExhausted. Raise ISTIO_GPRC_MAXRECVMSGSIZE on istiod (spelled this way in the code), budgeting about 1 MiB per 10,000 workloads and services, for example 33554432 for 32 MiB.
- breaking Strict gateway merging and an authenticated api generator
PILOT_ENABLE_STRICT_GATEWAY_MERGING is on by default: Istio Gateway resources from other namespaces are no longer merged into managed Gateway API Gateway proxies; manually deployed Gateway API gateways are unaffected, and false restores the old merge. istiod's XDS api generator now requires a control-plane identity, so custom MCP consumers from non-system namespaces are rejected; sidecars, gateways and ztunnel are unaffected, and ENABLE_XDS_API_GENERATOR_AUTH=false restores the previous behaviour.
- new Mesh-wide traffic baseline and zone-aware load balancing
meshConfig.defaultTrafficPolicy sets a connectionPool and outlierDetection baseline that all outbound clusters inherit; the baseline connectionPool also applies to inbound clusters and the passthrough cluster. A DestinationRule that sets one of these blocks overrides it for that block, and blocks it leaves unset now inherit the baseline instead of Istio's built-in defaults. The new zoneAwareLbSetting in DestinationRule loadBalancer or MeshConfig keeps traffic in the caller's zone and spills over only when local capacity runs short. It is sidecar-only and requires ISTIO_META_ENABLE_SELF_DISCOVERY: "true" in proxyMetadata.
- new Egress: Sidecar host exclusion and dynamic DNS forwarding
Sidecar egress hosts accept a ~ prefix that subtracts from the import set: */* plus ~ns1/* imports everything except ns1, and ~/foo.com removes foo.com from every namespace. The new outboundTrafficPolicy mode ALLOW_ANY_DYNAMIC_DNS forwards plaintext HTTP to unknown destinations through Envoy's Dynamic Forward Proxy, resolving the Host header at request time, so no ServiceEntry per destination is needed; TLS and raw TCP still go to PassthroughCluster. The mode is sidecar-only, cannot be set in the Sidecar resource, and works on IPv6-only clusters only from 1.31.1.
- new Weighted waypoint canaries, agentgateway as waypoint
A service or namespace can reference a primary and a canary waypoint via the istio.io/use-waypoint-canary and istio.io/use-waypoint-canary-namespace labels; the istio.io/use-waypoint-canary-weight annotation shifts a configurable share of in-mesh connections to the canary, so waypoint changes roll out gradually without touching clients. The new GatewayClass istio-agentgateway-waypoint deploys agentgateway as a waypoint, building on the gateway-only support from 1.30. Use 1.31.1 for both: in 1.31.0 an agentgateway waypoint referenced only as canary was not programmed and rejected the shifted connections, and the canary label bypassed serviceEntryVisibility NAMESPACE isolation.
- new FIPS 140-3, trust-domain matching, secure metrics ports
COMPLIANCE_POLICY=fips-140-3 enforces TLS 1.2 or 1.3 with FIPS cipher suites and P-256/P-384 key agreement. istiod and istio-agent must be built with Go 1.24+ and GOFIPS140=v1.0.0 (or a later validated version), which the release build does not set, so this needs a custom build; GOEXPERIMENT=boringcrypto is incompatible. AuthorizationPolicy sources gain trustDomains and notTrustDomains. The opt-in variables ENVOY_SECURE_METRICS_PORT and ENVOY_SECURE_MERGED_METRICS_PORT add mTLS-protected Prometheus scrape listeners to every sidecar.
1.30
18 May 2026- breaking Gateway API CRDs must be at v1.5.x
Istio 1.30 reads TLSRoute and ReferenceGrant from the standard channel of Gateway API v1.5.1. Upgrading Istio without upgrading the CRDs loses those resources silently: existing TLS passthrough listeners report attachedRoutes: 0 and the Envoy listener is never programmed. Apply the CRDs before the Istio upgrade.
- breaking Ambiguous hostname resolution changed
For hostnames that are ambiguous across namespaces, sidecars now prefer a Kubernetes Service and otherwise fall back to the oldest non-K8s service, instead of taking the alphabetically first visible namespace. This can silently redirect traffic to a different instance. Opt out with PILOT_SIDECAR_PICK_BEST_SERVICE_NAMESPACE=false or compatibilityVersion 1.28.
- breaking XDS debug endpoints on port 15010 now authenticated
syncz and config_dump require authentication, governed by ENABLE_DEBUG_ENDPOINT_AUTH (default true). This affects istioctl with --plaintext and any in-house tooling speaking plaintext XDS. DEBUG_ENDPOINT_AUTH_ALLOWED_NAMESPACES grants additional namespaces.
- new Sidecar-to-ambient migration guide
For the first time there is a documented, step-by-step path from an existing sidecar mesh to ambient, including policy migration and per-namespace activation. Sidecar and ambient workloads coexist during the transition, and the move is reversible.
- new TrafficExtension API for Wasm and Lua
A single alpha API for Wasm modules from OCI registries and inline Lua across sidecars, gateways and waypoints. It supersedes WasmPlugin as the recommended extension mechanism and removes the need for EnvoyFilter to run Lua. Existing WasmPlugin resources keep working; Istio translates them internally.
- new Ambient: client identity at the waypoint, CIDR ServiceEntry
With the ambient.istio.io/xfcc-include-client-identity annotation the waypoint synthesises x-forwarded-client-cert from the SPIFFE identity supplied by ztunnel, so applications can see the original client. ServiceEntry now accepts CIDR addresses, letting ambient route whole IP ranges by longest-prefix match without individual workloads.
- deprecated Registry move: gcr.io and registry.istio.io are being retired
1.30 switches the default hub to registry.istio.io/release, but both that registry and gcr.io/istio-release are decommissioned in December 2026, after scream tests on 15 September, 13 October and 17 November and a 24-hour outage from 8 December 2026, 15:00 UTC. 1.30 is the last minor published there. The target is docker.io/istio, best fronted by a pull-through cache.
1.29
16 February 2026- new Ambient defaults for production
DNS capture is now on by default for ambient workloads, as is iptables reconciliation when the istio-cni DaemonSet starts. The latter replaces a manual step, so pods already enrolled pick up current rules after a CNI upgrade. DNS capture applies to new pods; existing pods pick it up through the iptables reconciliation when istio-cni is upgraded (reconcileIptablesOnStartup, on by default), otherwise they need a restart.
- GA Multi-network multicluster in ambient at beta
The focus was telemetry: waypoints are reported correctly in L4 metrics, and peer metadata is exchanged along the ambient data path, so requests traversing an east-west gateway are fully attributed.
- GA Gateway API Inference Extension at beta
Promoted from alpha, conformant to v1.0.1 of the specification, enabled via ENABLE_GATEWAY_API_INFERENCE_EXTENSION. The InferencePool CRD combined with Gateway and HTTPRoute governs load distribution across self-hosted models.
- new CRL support in ztunnel, optional NetworkPolicies
ztunnel checks certificate revocation lists and rejects revoked certificates, which matters when you bring your own CA. Default NetworkPolicies for istiod, istio-cni and ztunnel can now be rolled out alongside.
- breaking Debug endpoint authorisation on by default
On port 15014, non-system namespaces are limited to config_dump, ndsz and edsz and may only query proxies in their own namespace. This affects Kiali and in-house monitoring. 1.30 extends the same logic to port 15010.
- breaking base Helm chart: duplicated RBAC resources removed
Configuration previously copied into istiod is gone from the base chart. ClusterRole istiod is now istiod-clusterrole, ClusterRole istiod-reader becomes istio-reader-clusterrole, and ServiceAccount istiod-service-account becomes istiod. The suffix scheme also moves from the Istio namespace to the revision.
1.28
5 November 2025- GA Dual-stack at beta, InferencePool at v1
IPv4/IPv6 dual-stack is promoted from alpha to beta and usable where both protocol versions run side by side. The InferencePool API reaches v1.0.0; alpha and release-candidate versions are no longer supported.
- new Native nftables in ambient
Ambient can steer traffic through nftables instead of iptables, enabled with values.global.nativeNftables. This complements the nftables support already present in sidecar mode.
- new Gateway API v1.4 and TLS extensions
BackendTLSPolicy v1 with full Gateway API 1.4 support, ServiceEntry as a targetRef in BackendTLSPolicy for external services, and FrontendTLSValidation for mTLS at the ingress gateway. RequestAuthentication accepts custom space-delimited JWT claims beyond scope and permission.
- breaking BackendTLSPolicy v1alpha3 and older InferencePool removed
Only v1 BackendTLSPolicy is read. In InferencePool, endpointPickerRef.portNumber moves to endpointPickerRef.port.number, the field is now required, and port 9002 is no longer assumed.
- breaking Metric eviction reworked
The Pilot environment variables METRIC_ROTATION_INTERVAL and METRIC_GRACEFUL_DELETION_INTERVAL are gone. The replacement is the pod annotation sidecar.istio.io/statsEvictionInterval together with the new stats eviction API.