Isovalent Networking for Kubernetes 1.19: BGP Route Import, Policy Tiers, and Timescape enhancements
Isovalent Networking for Kubernetes 1.19 focuses on day-two operations for platform teams. Key additions include policy-controlled BGP route import (default-deny with explicit IsovalentBGPPolicy allowlists), interface address advertisement over BGP, and Egress Gateway HA graduating to stable. Network policy gains Kubernetes ClusterNetworkPolicy support plus IsovalentNetworkPolicy tiers (Admin/Normal/Baseline) with pass verdicts for layered ownership between platform and application teams. FQDN HA offline mode keeps DNS-derived policy state alive during cilium-agent restarts. Selective WireGuard encryption supports default-encrypt posture with explicit plaintextPeers exemptions. Hubble Timescape replaces Hubble UI Enterprise as the primary observability surface, adding CEL-based flow filtering, policy editor enhancements (diff mode, log fields, deny policies), process ancestry via Tetragon, and a new OpenShift operator deployment model. Kube-Proxy Replacement and netkit continue hardening ahead of becoming defaults in 1.20.