Aspen Mesh Carrier-Grade 1.11.8-am1.4 release notes#
Introduction#
These release notes describe the differences between Aspen Mesh Carrier-Grade 1.11.8-am1.3 and 1.11.8-am1.4.
Supported platforms#
This release is officially supported on these platforms and versions:
Platform |
Version |
Recommended Helm version |
|---|---|---|
OpenShift |
4.7 |
3.8 |
Istio proxy (Envoy) version#
1.19
Security updates#
Istio#
(No security updates)
Aspen Mesh features#
(No security updates)
Other changes#
Istio#
(No changes)
Aspen Mesh features#
AM38 (ASM-4591): Implemented logic in the Packet Inspector 1 filter to infer the metadata destination port from the scheme header if the destination port wasn’t specified in the authority header. Also addressed an issue where the port value would not be set when a request had a
3gpp-sbi-target-apirootheader.ASM-4213: Fixed an issue where Packet Inspector 1 comments in the istiod values file indicate that you can exclude one or more namespaces or pods when capturing Diameter workloads (only HTTP workloads are supported).
Known issues#
AM-3069: OpenShift clusters using either the Multi-Primary or the Multi-Primary on different networks configuration for multicluster connectivity fail to create the remote secret with the following error:
$ istioctl x create-remote-secret --name=cluster1 error: could not get access token to read resources from local kube-apiserver: wrong number of secrets (2) in serviceaccount istio-system/istio-reader-service-account error: could not get access token to read resources from local kube-apiserver: wrong number of secrets (2) in serviceaccount istio-system/istio-reader-service-account
AM-3547: Pods with Istio sidecars get evicted when a node runs low on storage because they don’t request ephemeral storage.
Download#
Use either of the following methods to download the release archive file: