Removed integration with Vault CA temporarily. SDS requirements caused the temporary removal but we will reintroduce Vault CA integration in a future release.
Enabled the Envoy JWT filter by default to improve security and reliability.
Telemetry
Added Access Log Service ALS support for Envoy gRPC.
Added a Grafana dashboard for Citadel monitoring.
Addedmetrics for monitoring the sidecar injector webhook.
Added control plane metrics to monitor Istio’s configuration state.
Added telemetry reporting for traffic destined to the Passthrough and BlackHole clusters.
Added alpha support for in-proxy generation of service metrics using Prometheus.
Added alpha support for environmental metadata in Envoy node metadata.
Added alpha support for Proxy Metadata Exchange.
Added alpha support for the OpenCensus trace driver.
Improved reporting for external services by removing requirements to add a service entry.
Improved the mesh dashboard to provide monitoring of Istio’s configuration state.
Improved the Pilot dashboard to expose additional key metrics to more clearly identify errors.
Removed deprecated Adapter and Template custom resource definitions (CRDs).
Deprecated the HTTP API spec used to produce API attributes. We will remove support for producing API attributes in Istio 1.4.
Policy
Improved rate limit enforcement to allow communication when the quota backend is unavailable.
Configuration management
Fixed Galley to stop too many gRPC pings from closing connections.
Improved Galley to avoid control plane upgrade failures.