What's New in Release 5.11.0
Here's a summary of the new and enhanced features in this release.
Custom IP Table Rules in Pure nftables Mode
We've added support for custom IP Table Rules in pure nftables mode.
Reference pre-existing Kubelink and C-VEN secrets in Helm Chart
By default the chart creates and manages the Kubernetes Secrets that hold the PCE credentials. If you prefer to manage the credentials yourself, set `existingSecret` to the name of a Secret you create in the release namespace:
existingSecret: my-illumio-credentials
With this update, the chart does not create a new plaintext secret for a component when you provide an existing secret. If you do not specify an existing secret, the chart preserves its previous behavior for backward compatibility.
See Existing Secret.
Pod Policy Convergence Visibility
With this release, Illumio expands Kubernetes Policy Convergence status. The synchronization state for Kubernetes pods displays in the Servers & Endpoints > Workloads > Kubernetes Workloads Summary within the PCE UI. This information represents a distinct C-VEN convergence state, separate from "Policy Sync," which indicates Kubelink’s acknowledgment of the policy. The increased transparency and visibility helps you understand synchronization progress across the pods in a workload. The same information displays in Infrastructure > Container Clusters for a selected Kubernetes Workload.
The Kubernetes Workloads summary includes:
Policy Fully Converged at to indicate when convergence succeeded on all pods.
Policy Convergence to indicate the percentage of pods in a workload with applied policy during synchronization.
List of Pod errors indicates which errors occurred on which Host Workloads / Nodes
Istio Ambient Support
With this release, Illumio supports interoperability between Illumio C-VEN and Istio Ambient, enabling visibility, policy inspection, and enforcement across key Kubernetes traffic paths. The Illumio C-VEN operates alongside Istio Ambient.
Istio Ambient support includes:
ClusterIP traffic
Node-to-pod and pod-to-node communication
Pod-to-pod communication