## What this PR does Refreshes the vendored Cilium chart in `packages/system/cilium` from v1.19.1 to v1.19.3 via `make update`. Chart templates, values, CRDs and the Cilium image reference are regenerated from upstream. ### Motivation - **v1.19.2** ships a critical fix for cert-manager HTTP-01 Gateway API challenges on hostnames that have both HTTP and HTTPS listeners ([cilium#44492](https://github.com/cilium/cilium/pull/44492), backport [#44517](https://github.com/cilium/cilium/pull/44517)). Without this fix, cert-manager cannot issue certificates via Gateway API when a redirect HTTP listener and a TLS HTTPS listener share a hostname. - **v1.19.3** is the latest stable patch release in the v1.19.x line (15 Apr 2026). - This bump is a prerequisite for upcoming Gateway API work tracked separately. ### Upstream changes pulled in - Cilium Envoy bootstrap config, operator clusterrole, config template, `values.schema.json` and the cilium-agent DaemonSet refreshed from upstream. - New `templates/ztunnel/` directory (DaemonSet, Secret, ServiceAccount) added by upstream — not enabled by default in Cozystack values. ### Release note ```release-note chore(cilium): bump to v1.19.3 (cert-manager HTTP-01 fix via cilium#44492) ``` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added ztunnel encryption support with configurable deployment settings * Added ConfigDriftDetection for monitoring ConfigMap changes * Added endpoint policy update timeout configuration * Added load balancer service topology support * Extended Envoy circuit breaker configuration with connection and request limits * **Updates** * Upgraded Cilium to v1.19.3 * Updated container images (Envoy, certgen, Hubble relay, clustermesh) * Enhanced Cilium operator RBAC capabilities for managing ServiceImport finalizers * **Removals** * Removed BIG TCP tunnel configuration option <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|---|---|---|
| .gemini | ||
| .github | ||
| api | ||
| cmd | ||
| dashboards | ||
| docs | ||
| examples/backups/vmi | ||
| hack | ||
| img | ||
| internal | ||
| packages | ||
| pkg | ||
| tools/openapi-gen | ||
| .coderabbit.yaml | ||
| .gitignore | ||
| .pre-commit-config.yaml | ||
| ADOPTERS.md | ||
| AGENTS.md | ||
| CODE_OF_CONDUCT.md | ||
| CONTRIBUTING.md | ||
| CONTRIBUTOR_LADDER.md | ||
| go.mod | ||
| go.sum | ||
| GOVERNANCE.md | ||
| LICENSE | ||
| MAINTAINERS.md | ||
| Makefile | ||
| README.md | ||
| SECURITY.md | ||
Cozystack
Cozystack is a free platform and framework for building clouds.
Cozystack is a CNCF Sandbox Level Project that was originally built and sponsored by Ænix.
With Cozystack, you can transform a bunch of servers into an intelligent system with a simple REST API for spawning Kubernetes clusters, Database-as-a-Service, virtual machines, load balancers, HTTP caching services, and other services with ease.
Use Cozystack to build your own cloud or provide a cost-effective development environment.
Use-Cases
-
Using Cozystack to build a public cloud
You can use Cozystack as a backend for a public cloud -
Using Cozystack to build a private cloud
You can use Cozystack as a platform to build a private cloud powered by Infrastructure-as-Code approach -
Using Cozystack as a Kubernetes distribution
You can use Cozystack as a Kubernetes distribution for Bare Metal
Documentation
The documentation is located on the cozystack.io website.
Read the Getting Started section for a quick start.
If you encounter any difficulties, start with the troubleshooting guide and work your way through the process that we've outlined.
Versioning
Versioning adheres to the Semantic Versioning principles.
A full list of the available releases is available in the GitHub repository's Release section.
Contributions
Contributions are highly appreciated and very welcomed!
In case of bugs, please check if the issue has already been opened by checking the GitHub Issues section. If it isn't, you can open a new one. A detailed report will help us replicate it, assess it, and work on a fix.
You can express your intention to on the fix on your own. Commits are used to generate the changelog, and their author will be referenced in it.
If you have Feature Requests please use the Discussion's Feature Request section.
Community
You are welcome to join our Telegram group and come to our weekly community meetings. Add them to your Google Calendar or iCal for convenience.
License
Cozystack is licensed under Apache 2.0.
The code is provided as-is with no warranties.
Commercial Support
A list of companies providing commercial support for this project can be found on official site.
