Istio update adds waypoint proxy feature
Istio 1.31, which became available on August 31, adds the capability to operate agentgateway as a Layer 7 waypoint proxy within an ambient mesh, utilizing the new istio-agentgateway-waypoint GatewayClass. Additionally, this update halts the distribution of container images and Helm charts to Google Cloud.
Organizations relying on gcr.io/istio-release, registry.istio.io, or the Google-hosted Helm repository must migrate prior to the next scheduled outage test on October 13, in preparation for their retirement in December. The supported versions for Istio 1.31.0 range from Kubernetes 1.32 to 1.36.
Waypoint Support and Traffic Management
This waypoint capability expands upon the gateway-only integration that was introduced experimentally in version 1.30. Agentgateway is a Rust data plane created specifically for agent traffic; it was donated to the Linux Foundation by Solo.io and supports protocols like the Model Context Protocol, in addition to standard HTTP.
Istio 1.31 also addresses issues regarding ListenerSet handling and mTLS connectivity for agentgateway backends. Traffic shifting between waypoints is currently in the alpha stage, and the maintainers caution that the labels, annotations, and behavior might evolve. A service or namespace can designate a canary alongside its primary waypoint by applying the use-waypoint-canary label.
Because established connections are not disrupted, long-lived connections might delay the observed traffic split. However, the use-waypoint-canary-weight annotation permits administrators to send a configurable portion of new in-mesh connections to the canary, requiring no modifications on the client side.
Security and Hosting Changes
Istio 1.31.1, published on September 21, resolves an issue where agentgateway waypoints designated only as canaries were not correctly programmed with the routes and policies of the services that referenced them, which resulted in shifted connections being rejected. This patch also incorporates security fixes and corrects ALLOW_ANY_DYNAMIC_DNS forwarding in IPv6-only clusters.
Setting the COMPLIANCE_POLICY environment variable to a fips-140-3 value restricts TLS to version 1.2 or later, mandates the use of FIPS-compliant cypher suites, and enforces P-256 and P-384 curves. Furthermore, the AuthorizationPolicy resource now features new trustDomains and notTrustDomains fields to match or exclude requests based on the trust domain found in the peer certificate.
Teams utilizing the current repositories must take action regarding the hosting change. According to the Istio blog, “this year, Istio is migrating all of our infrastructure from Google Cloud Platform to Amazon Web Services due to changes in our funding model”. The next scheduled outage test will disable the old endpoints on October 13 from 15:00 to 18:00 UTC.
Groups verifying image signatures must also account for key rotation; the migration guidance specifies istio-key.pub for version 1.31.0 and istio-key-v2.pub for versions 1.31.1 and later. The final test runs from December 8 at 15:00 UTC to December 9 at 15:00 UTC.
