<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Service-Mesh on CuraDevOps</title><link>https://curadevops.metacog.co.kr/tags/service-mesh/</link><description>Recent content in Service-Mesh on CuraDevOps</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 31 Aug 2026 18:45:38 +0000</lastBuildDate><atom:link href="https://curadevops.metacog.co.kr/tags/service-mesh/index.xml" rel="self" type="application/rss+xml"/><item><title>Envoy v1.37.6 patches nine CVEs including UAF and HTTP/2 crash bugs</title><link>https://curadevops.metacog.co.kr/insights/2026-08-31-v1-37-6/</link><pubDate>Mon, 31 Aug 2026 18:45:38 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-31-v1-37-6/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> Nine CVEs addressed including a UAF on HTTP/3, abnormal process termination on HTTP/2 trailers and ext_authz CONNECT requests, and a shared upstream connection-poisoning bug via HTTP upgrade — none are KEV-listed but the severity warrants scheduling an upgrade to v1.37.6 this sprint for any cluster running Envoy as ingress or data-plane proxy.&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-73511 — CISA KEV: not listed, EPSS n/a · CVE-2026-73512 — CISA KEV: not listed, EPSS n/a · CVE-2026-73513 — CISA KEV: not listed, EPSS n/a&lt;/li>
&lt;/ul></description></item><item><title>Envoy v1.39.1 patches multiple CVEs including HTTP/3 UAF and HTTP/2 crash</title><link>https://curadevops.metacog.co.kr/insights/2026-08-31-v1-39-1/</link><pubDate>Mon, 31 Aug 2026 18:45:38 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-31-v1-39-1/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> v1.39.1 fixes multiple CVEs in Envoy&amp;rsquo;s HTTP/3 (UAF, CVE-2026-73512), HTTP/2 (process termination, CVE-2026-73513), and connection-handling paths — real data-plane exposure for any Istio, Contour, or Envoy-based ingress deployment. None are KEV-listed or confirmed exploited, so schedule patching this sprint rather than treating it as an emergency.&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-73511 — CISA KEV: not listed, EPSS n/a · CVE-2026-73512 — CISA KEV: not listed, EPSS n/a · CVE-2026-73513 — CISA KEV: not listed, EPSS n/a&lt;/li>
&lt;/ul></description></item><item><title>Istio 1.31.0 released</title><link>https://curadevops.metacog.co.kr/insights/2026-08-31-istio-1-31-0/</link><pubDate>Mon, 31 Aug 2026 18:45:38 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-31-istio-1-31-0/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> A new Istio minor release is always a candidate for upgrade planning — review the full release notes for breaking changes, API removals, or deprecations before scheduling a mesh upgrade this quarter.&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Fixing double-counting in Istio/Kiali mesh observability metrics</title><link>https://curadevops.metacog.co.kr/insights/2026-08-11-a-practical-guide-to-solving-when-zero-zero-two-in-mesh-obse/</link><pubDate>Tue, 11 Aug 2026 11:38:38 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-11-a-practical-guide-to-solving-when-zero-zero-two-in-mesh-obse/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Learn:&lt;/strong> Addresses a real gotcha in Istio+Kiali+Prometheus setups where request metrics get double-counted; worth reading if you operate a service mesh and are debugging unexpected metric values.&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Consul adds native multi-port service support</title><link>https://curadevops.metacog.co.kr/insights/2026-07-23-one-service-many-doors-multi-port-services-in-consul/</link><pubDate>Thu, 23 Jul 2026 12:19:57 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-07-23-one-service-many-doors-multi-port-services-in-consul/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Learn:&lt;/strong> Useful capability if you run Consul service mesh — one identity with multiple named ports reduces catalog sprawl. No deadline or GA-vs-pre-GA status confirmed in signals, so evaluate when scoping next Consul adoption work.&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Envoy v1.39.0: multiple CVE fixes, TLS and HTTP/2/3 breaking changes</title><link>https://curadevops.metacog.co.kr/insights/2026-07-20-v1-39-0/</link><pubDate>Mon, 20 Jul 2026 14:01:18 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-07-20-v1-39-0/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> v1.39.0 patches several CVEs across ext_authz, ext_proc, gRPC stats, and HTTP/2/HTTP/3 DoS vectors, but none are KEV-listed and EPSS is 0.00 — no hard deadline. Plan the upgrade this quarter, and validate the breaking TLS enforcement change and OpenTelemetry sampling behavior shift in staging before rolling to production.&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> deprecation mentioned (no explicit date found) · breaking-change flagged · CVE-2026-47204 — CISA KEV: not listed, EPSS 0.00 · CVE-2026-47205 — CISA KEV: not listed, EPSS 0.00 · CVE-2026-47207 — CISA KEV: not listed, EPSS 0.00&lt;/li>
&lt;/ul></description></item></channel></rss>