envoyproxy / envoyproxy/gateway

Enable using Pod Certificates feature from Kubernetes 1.35

Open
#7,716 2 comments 0 reactions 1 assignee Claimed by @cnvergence View on GitHub
area/gateway-namespace-mode no stalebot provider/kubernetes
Dominant language
Go
Stars
3k
Forks
864
Avg merge
2d 2h
Merged PRs (30d)
140

Description

*Description*:
>Describe the desired behaviour, what scenario it enables and how it
would be used.

The new alpha feature of running Pod Certificates is targeted to become beta in 1.35.
This provides a built-in mechanism for workload identity, allowing the kubelet to request and mount certificates for a Pod via a projected volume.

We should investigate its use in Gateway Namespace Mode and possibly in other areas of the Envoy Gateway Kubernetes provider.

[optional *Relevant Links*:]
>Any extra documentation required to understand the issue.
- https://github.com/kubernetes/enhancements/issues/4317
- https://kubernetes.io/blog/2025/11/26/kubernetes-v1-35-sneak-peek/#pod-certificates

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.