Isovalent Networking for Kubernetes 1.19 focuses on day-two operations for platform teams. Key additions include policy-controlled BGP route import (default-deny with explicit IsovalentBGPPolicy allowlists), interface address advertisement over BGP, and Egress Gateway HA graduating to stable. Network policy gains Kubernetes ClusterNetworkPolicy support plus IsovalentNetworkPolicy tiers (Admin/Normal/Baseline) with pass verdicts for layered ownership between platform and application teams. FQDN HA offline mode keeps DNS-derived policy state alive during cilium-agent restarts. Selective WireGuard encryption supports default-encrypt posture with explicit plaintextPeers exemptions. Hubble Timescape replaces Hubble UI Enterprise as the primary observability surface, adding CEL-based flow filtering, policy editor enhancements (diff mode, log fields, deny policies), process ancestry via Tetragon, and a new OpenShift operator deployment model. Kube-Proxy Replacement and netkit continue hardening ahead of becoming defaults in 1.20.

21m read timeFrom isovalent.com
Post cover image
Table of contents
Highlights at a glanceConnectivity: making the datapath easier to standardiseNetwork policy: guardrails for the platform, flexibility for teamsDNS-Aware Egress: Keeping Name-Based Policy Stable During MaintenanceSelective EncryptionHubble TimescapePlatform updates: image delivery, AI infrastructure, and GitOpsSummary
12.1K Impressions