← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Istio 1.31 Introduces Agentgateway Waypoints and Migrates Release Artifacts Off Google Cloud

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Istio 1.31 supports agentgateway as a Layer 7 waypoint proxy.
  • Release artifacts are no longer published to Google Cloud; migration is required.
  • New zone-aware load balancing and dynamic DNS outbound mode added.
  • FIPS 140-3 compliance policy option for TLS introduced.

Agentgateway Waypoint Support

Istio 1.31 allows agentgateway to function as a Layer 7 waypoint proxy within an ambient mesh, utilizing the new istio-agentgateway-waypoint GatewayClass. This builds upon the experimental gateway-only integration introduced in version 1.30. Agentgateway, a Rust data plane donated by Solo.io, handles protocols like Model Context Protocol and HTTP.

The release also addresses ListenerSet handling and mTLS connectivity for agentgateway backends. Traffic shifting between waypoints is an alpha feature, enabling a configurable share of new in-mesh connections to be directed to a canary waypoint without client-side changes, though established connections are not moved.

Migration of Release Artifacts

With Istio 1.31, the project has ceased publishing container images and Helm charts to Google Cloud. Users currently relying on gcr.io/istio-release, registry.istio.io, or the Google-hosted Helm repository must migrate their dependencies before the scheduled retirement in December. A scheduled outage test on October 13 serves as a deadline for this transition.

Traffic Management Enhancements

Two significant traffic management additions are included for large meshes. A new zoneAwareLbSetting field in DestinationRule and MeshConfig enables Envoy to route traffic to endpoints within its own availability zone, spilling over only when local capacity is exhausted. This differs from localityLbSetting by automatically determining spillover rather than using static percentages.

Additionally, the ALLOW_ANY_DYNAMIC_DNS outbound mode resolves hostnames from the HTTP Host header at request time, eliminating the need to create a ServiceEntry for every external destination.

Security Updates

For security, a new fips-140-3 value for the COMPLIANCE_POLICY environment variable restricts TLS to version 1.2 or later, FIPS-compliant cipher suites, and P-256 and P-384 curves. This enhancement aims to improve the security posture of Istio deployments.

Istio 1.31.1 Patch Release

Istio 1.31.1, released on September 21, addressed an issue where agentgateway waypoints referenced only as canaries were not correctly programmed with routes and policies, leading to rejected shifted connections. This patch also included additional security fixes and corrected ALLOW_ANY_DYNAMIC_DNS forwarding in IPv6-only clusters.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Primary sources

GitHub istio/istio

Reporting from

Istio 1.31 adds support for running agentgateway as a Layer 7 waypoint proxy in an ambient mesh and discontinues publishing container images and Helm charts to Google Cloud. This release also includes new traffic management features for large meshes and security enhancements.