---
title: "Calico Open Source 3.33 release notes"
description: "Release notes for the current Calico Open Source release — new features, enhancements, technology previews, deprecations, bug fixes, and known issues."
product: "Calico Open Source"
version: "3.33 (latest)"
section: "Calico Open Source release notes"
canonical_url: "https://docs.tigera.io/calico/latest/release-notes/"
---

# Calico Open Source 3.33 release notes

Learn about the new features, bug fixes, and other updates in this release of Calico.

## New features and enhancements

### On-demand OpenStack resync

A new `calico-resync` command reconciles Neutron with etcd whenever you ask, optionally scoped to particular networks, subnets, ports, or security groups. The driver also resyncs once at Neutron server startup, so a restart corrects any drift.

Resync is much faster at scale, because it reads Neutron state in bulk instead of querying per port, and it runs in its own process, so a long resync no longer delays port creation. Each resource it has to change is logged at INFO level.

For more information, see [Resync between Neutron and etcd](https://docs.tigera.io/calico/latest/networking/openstack/resync.md).

### QoS controls on the eBPF data plane

The full set of QoS controls now works on the eBPF data plane. Bandwidth and packet rate limits already did; what is new is connection limits, so the `qos.projectcalico.org/ingressMaxConnections` and `qos.projectcalico.org/egressMaxConnections` annotations now take effect on both data planes. A TCP connection that would take a pod past its limit is refused with a RST, so the client fails immediately rather than waiting out its SYN retries.

For more information, see [Configure QoS controls](https://docs.tigera.io/calico/latest/networking/configuring/qos-controls.md).

### Enhancements

- Update the bundled Envoy Gateway to v1.9.1, Envoy to v1.39.1, and the Gateway API CRDs to v1.6.1. Envoy Gateway v1.9 raises the minimum supported Kubernetes version to v1.33. [calico 14049](https://github.com/projectcalico/calico/pull/14049) (@electricjesus)
- Felix and Typha now apply the same schema checks to data read from an etcd datastore that the Kubernetes API server applies on admission. [calico 14008](https://github.com/projectcalico/calico/pull/14008) (@caseydavenport)
- LogConnectionTransitionsPrefix is now validated: a value containing characters that are unsafe in iptables/nftables rules (such as a double quote) is rejected by the API, and Felix falls back to the default prefix instead of failing to program the dataplane. [calico 13974](https://github.com/projectcalico/calico/pull/13974) (@matthewdupre)
- Rejects invalid BGP peer IPs, network set entries and policy rule protocols at write time on the projectcalico.org/v3 CRDs, matching what calicoctl already enforced. [calico 13967](https://github.com/projectcalico/calico/pull/13967) (@caseydavenport)
- Applies the libcalico-go write defaults and the documented numeric ranges in the projectcalico.org/v3 CRD schemas, so the kubectl and GitOps write paths match calicoctl. [calico 13967](https://github.com/projectcalico/calico/pull/13967) (@caseydavenport)
- Publishes v1beta1 variants of the projectcalico.org/v3 CRD manifests. [calico 13967](https://github.com/projectcalico/calico/pull/13967) (@caseydavenport)
- Adds a configurable pprof host to KubeControllersConfiguration. [calico 13967](https://github.com/projectcalico/calico/pull/13967) (@caseydavenport)
- IP pool creation and updates are now rejected when the pool's CIDR overlaps an existing pool. [calico 13953](https://github.com/projectcalico/calico/pull/13953) (@caseydavenport)
- HELM: Deprecates defaultFelixConfiguration in the tigera-operator chart and documents applying Calico resources before the operator. [calico 13953](https://github.com/projectcalico/calico/pull/13953) (@caseydavenport)
- calico-node -bpf conntrack remove now accepts any protocol name or number, and "any", not just tcp and udp. [calico 13930](https://github.com/projectcalico/calico/pull/13930) (@tomastigera)
- Felix/Dikastes performance: evaluate policy rule criteria cheapest-first in the user-mode policy engine, 1.6-3.7x faster evaluation for large policy sets. Rate limit the policy engine's per-rule warnings, which could previously emit tens of thousands of log lines per request. [calico 13810](https://github.com/projectcalico/calico/pull/13810) (@fasaxc)
- Update the react-router-dom dependency in the Whisker UI to 6.30.6 to resolve CVE-2026-53668. [calico 13739](https://github.com/projectcalico/calico/pull/13739) (@skoryk-oleksandr)
- Build with Go 1.27.0 and update Kubernetes dependencies to v1.37.0. [calico 13706](https://github.com/projectcalico/calico/pull/13706) (@stevegaossou)
- Add FelixConfiguration fields to allow logging response type as a followup to rules with a Log action [calico 13658](https://github.com/projectcalico/calico/pull/13658) (@matthewdupre)
- Felix now removes the rules it left behind in the iptables backend it is no longer using, in either direction between the legacy and nft backends. [calico 13579](https://github.com/projectcalico/calico/pull/13579) (@caseydavenport)
- The BPFAttachType FelixConfiguration option gains a Netkit value, now the default, which attaches BPF programs through the netkit API on workload netkit devices and via TCX elsewhere. Setting BPFAttachType to TCX or TC makes Felix drive existing netkit devices with that mechanism instead, which is required before downgrading to a release without netkit support. [calico 13576](https://github.com/projectcalico/calico/pull/13576) (@tomastigera)
- Felix now cleans up cluster routes left behind by BIRD for destinations it no longer routes to, when Felix is the configured owner of the IPIP cluster routes. [calico 13555](https://github.com/projectcalico/calico/pull/13555) (@mazdakn)
- Felix, rather than BIRD, programs the cluster routes for IPIP IP Pools by default. BIRD programming of IPIP cluster routes is deprecated and is intended for removal in v3.35. [calico 13470](https://github.com/projectcalico/calico/pull/13470) (@nelljerram)
- Whisker backend now serves HTTPS only; SERVER\_TLS\_CERT\_PATH and SERVER\_TLS\_KEY\_PATH are required. [calico 13436](https://github.com/projectcalico/calico/pull/13436) (@vara2504)
- Helm and manifest installs now block user writes to ClusterInformation, matching the protection already provided by the aggregated API server and operator-managed installs. [calico 13423](https://github.com/projectcalico/calico/pull/13423) (@caseydavenport)
- Route reflectors now re-advertise service external IP routes that fall within configured serviceExternalIPs ranges. [calico 13413](https://github.com/projectcalico/calico/pull/13413) (@xianjianlf2)
- calicoctl is now available as a Debian/Ubuntu and RPM package from the Calico package repositories. [calico 13385](https://github.com/projectcalico/calico/pull/13385) (@nelljerram)
- The DatastoreMigration CRD is now served at migration.projectcalico.org/v1. The previous v1beta1 version is still served and deprecated, so upgrading is a normal CRD update with no need to remove the old one. [calico 13383](https://github.com/projectcalico/calico/pull/13383) (@caseydavenport)
- The DatastoreMigration CRD is now published to the release manifests directory, so it can be installed with `kubectl apply -f .../manifests/migration.projectcalico.org_datastoremigrations.yaml` instead of a path into the source tree. [calico 13382](https://github.com/projectcalico/calico/pull/13382) (@caseydavenport)
- The manual Calico for Windows install now generates its CNI configuration with cniVersion 1.0.0, matching the default on Linux. [calico 13380](https://github.com/projectcalico/calico/pull/13380) (@sridhartigera)
- The default CNI configuration now declares cniVersion 1.0.0 (previously 0.3.1), enabling Calico as a multus delegate on OpenShift 4.23+. Requires containerd v1.6+ or CRI-O v1.24+. [calico 13352](https://github.com/projectcalico/calico/pull/13352) (@sridhartigera)
- Added optional DOCKER\_MEMORY and DOCKER\_MEMORY\_SWAP make variables to cap memory usage of Docker-based builds. [calico 13339](https://github.com/projectcalico/calico/pull/13339) (@tomastigera)
- `calicoctl ipam show` and the kube-controllers IPAM metrics no longer report IPs covered by an IPReservation as free. `calicoctl ipam show` has a new IPS RESERVED column and kube-controllers exports a new ipam\_ippool\_reserved metric. [calico 13331](https://github.com/projectcalico/calico/pull/13331) (@fasaxc)
- The `cni.projectcalico.org/ipAddrs` annotation (and any AssignIP caller that sets an intended use) now honours the target IP pool's `allowedUses`: requesting an IP from a pool that does not permit workload use fails instead of allocating from it. [calico 13301](https://github.com/projectcalico/calico/pull/13301) (@fasaxc)
- calicoctl node checksystem no longer false-fails on modern distros for builtin/obsolete kernel modules (ipt\_set, xt\_icmp, xt\_u32, etc.) [calico 13282](https://github.com/projectcalico/calico/pull/13282) (@locker95)
- Update the bundled Envoy proxy to v1.38.3. [calico 13281](https://github.com/projectcalico/calico/pull/13281) (@electricjesus)
- Update Kubernetes dependencies to v1.37.0-beta.0. [calico 13270](https://github.com/projectcalico/calico/pull/13270) (@lucastigera)
- Update the bundled Envoy Gateway to v1.8.2. Please review the Envoy Gateway v1.8.2 release notes for upstream changes: [https://github.com/envoyproxy/gateway/blob/v1.8.2/release-notes/v1.8.2.yaml](https://github.com/envoyproxy/gateway/blob/v1.8.2/release-notes/v1.8.2.yaml) [calico 13268](https://github.com/projectcalico/calico/pull/13268) (@electricjesus)
- Felix/Dikastes performance: reduce CPU and GC load generated by the user-mode policy engine. 4x improvement for large policy sets. [calico 13265](https://github.com/projectcalico/calico/pull/13265) (@fasaxc)
- Raises the Calico webhooks server's Kubernetes client rate limits so that bursts of policy changes are no longer delayed by client-side throttling. [calico 13259](https://github.com/projectcalico/calico/pull/13259) (@caseydavenport)
- Adds a calicoctl datastore migrate-policy-names command to fix pre-v3.32 policy names on an etcdv3 datastore that was upgraded in place. [calico 13257](https://github.com/projectcalico/calico/pull/13257) (@caseydavenport)
- calicoctl node diags now works on containerd/CRI-O nodes via crictl/nerdctl when docker is not installed [calico 13254](https://github.com/projectcalico/calico/pull/13254) (@locker95)
- Felix: periodic IP set resyncs are now incremental, avoiding dataplane stalls on nodes with many IP sets. [calico 13245](https://github.com/projectcalico/calico/pull/13245) (@fasaxc)
- calicoctl cluster diags now collects previous-container logs per container, so a crashed container's previous logs are captured even when other containers in the same pod have no previous incarnation. [calico 13233](https://github.com/projectcalico/calico/pull/13233) (@Pat-TIG)
- eBPF dataplane: remove an unnecessary per-packet timestamp lookup on the forwarding fast path in non-debug builds. [calico 13217](https://github.com/projectcalico/calico/pull/13217) (@fasaxc)
- kube-controllers can now set annotations on automatically-created host endpoints via the annotations field of the KubeControllersConfiguration auto host endpoint template. Generated host endpoints are fully managed, so any annotation added directly to a generated host endpoint (outside the template) is removed on the next reconcile — set custom annotations on the template's annotations field instead. [calico 13205](https://github.com/projectcalico/calico/pull/13205) (@MichalFupso)
- Improved signalling of datastore sync status. Calico control-plane components are now more aware of when their event stream may be running behind. [calico 13158](https://github.com/projectcalico/calico/pull/13158) (@pasanw)
- Bump bundled third-party images (Envoy Gateway to v1.8.0, Envoy proxy to 1.38.2, Envoy ratelimit, node-driver-registrar, Istio to 1.29.4) and their golang.org/x, spdystream and Prometheus dependencies to remediate CVE-2026-33814, CVE-2026-35469, CVE-2026-47774, CVE-2026-42154 and CVE-2026-42151. [calico 13095](https://github.com/projectcalico/calico/pull/13095) (@lucastigera)
- Removes the deprecated preserveUnknownFields field from generated CRDs, which resolves Argo CD reporting Calico CRDs as out of sync. [calico 13081](https://github.com/projectcalico/calico/pull/13081) (@caseydavenport)
- Felix BPF debug log filters (BPFLogFilters) now support the `ip6 protochain` pcap primitive. [calico 13078](https://github.com/projectcalico/calico/pull/13078) (@tomastigera)
- The default client authentication mode for the Felix Prometheus metrics endpoint (`prometheusMetricsClientAuth`) is now `NoClientCert` instead of `RequireAndVerifyClientCert`. [calico 13072](https://github.com/projectcalico/calico/pull/13072) (@caseydavenport)
- Bump calico/rust-build image to v1.96.0. [calico 12989](https://github.com/projectcalico/calico/pull/12989) (@hjiawei)
- Improved nftables dataplane performance at scale by rewriting changed chains in place instead of re-reading the whole table after each programming update. [calico 12984](https://github.com/projectcalico/calico/pull/12984) (@caseydavenport)
- Felix proxy-neighbor manager (LocalSubnetL2Reachability) now periodically re-announces (gratuitous ARP / unsolicited NA) the pod and LoadBalancer IPs it owns to keep neighbor caches and switch forwarding tables warm. The cadence is configurable via the new FelixConfiguration field LocalSubnetL2ReachabilityRefreshInterval (default 120s; 0 disables). [calico 12960](https://github.com/projectcalico/calico/pull/12960) (@mazdakn)
- calicoctl cluster diags now collects the eBPF dataplane state (conntrack, ipsets, nat, routes, counters, arp, ifstate, conntrack stats, nat affinity and maglev tables) in JSON format. A new `calico-bpf nat maglev` command dumps the maglev table, and `calico-bpf nat aff` gains JSON output. [calico 12923](https://github.com/projectcalico/calico/pull/12923) (@tomastigera)
- Bump container-storage-interface/spec to v1.12.0. [calico 12895](https://github.com/projectcalico/calico/pull/12895) (@hjiawei)
- Removes the FIPS image variants ("-fips" tagged images) and FIPS build support from Calico, as it was outdated and no longer maintained. [calico 12883](https://github.com/projectcalico/calico/pull/12883) (@caseydavenport)
- For OpenStack, resync between the Neutron DB and Calico's datastore is now dramatically faster than in earlier releases (on the order of tens of times faster for a deployment with thousands of ports). The driver also uses modern Neutron/SQLAlchemy database-access patterns, which avoids some connection-pool and event-loop problems that could previously occur during resync at scale. [calico 12881](https://github.com/projectcalico/calico/pull/12881) (@nelljerram)
- HELM: Render MutatingAdmissionPolicy and MutatingAdmissionPolicyBinding as admissionregistration.k8s.io/v1alpha1 when the cluster only serves the alpha API (Kubernetes 1.32-1.33 with the feature gate enabled). [calico 12875](https://github.com/projectcalico/calico/pull/12875) (@caseydavenport)
- Felix configuration docs no longer claim `(case insensitive)` on the env-var/config-file encoding of `oneof` parameters. Felix's parser still accepts any case at runtime; only the docs change. [calico 12846](https://github.com/projectcalico/calico/pull/12846) (@tomastigera)
- HELM: Render MutatingAdmissionPolicy and MutatingAdmissionPolicyBinding as admissionregistration.k8s.io/v1 when the cluster serves it (Kubernetes 1.36+), falling back to v1beta1 otherwise. [calico 12833](https://github.com/projectcalico/calico/pull/12833) (@caseydavenport)
- Prevent deletion of built-in tiers in CRD mode. [calico 12824](https://github.com/projectcalico/calico/pull/12824) (@caseydavenport)
- The Calico driver for OpenStack now overrides the Neutron `[DEFAULT] service_plugins` setting to ensure that it includes `qos`, as required for our QoS support. This means that it's no longer necessary to configure `service_plugins` in `neutron.conf`, when using Calico. [calico 12798](https://github.com/projectcalico/calico/pull/12798) (@nelljerram)
- Bump Kubernetes dependencies to v1.36.1. [calico 12773](https://github.com/projectcalico/calico/pull/12773) (@lucastigera)
- Feature: Split OpenStack driver's leader-only tasks into multiple processes. [calico 12668](https://github.com/projectcalico/calico/pull/12668) (@zhanz1)
- Calico for OpenStack no longer runs periodic resyncs between the Neutron DB and etcd, and the associated config options, `resync_interval_secs` and `resync_max_interval_secs`, have been deprecated. Periodic resyncs have never been necessary for normal operation and were only originally coded only for imagined defensive reasons. The Calico driver still resyncs against the Neutron DB on startup, when the Neutron server is started or restarted. In exceptional circumstances where additional resync is needed, or desired as a check on the state, there is now a `calico-resync` CLI tool, which can perform either a full resync, or a reconciliation only of specified Neutron networks, subnets, ports or security groups. [calico 12658](https://github.com/projectcalico/calico/pull/12658) (@nelljerram)
- The new MinIPReclaimAgeSeconds IPAM configuration parameter prevents IP addresses from being reused too quickly. [calico 12638](https://github.com/projectcalico/calico/pull/12638) (@djmitche)
- Calico CNI plugin now supports a `device_type` configuration option to create netkit (Linux 6.7+) virtual devices instead of veth for the pod interface. Defaults to veth. [calico 12619](https://github.com/projectcalico/calico/pull/12619) (@tomastigera)
- Removed sensitive material (auth tokens, kubeconfig contents, etcd credentials, and inline certificates/keys) from log output. Logs that previously included full client-config or environment-variable dumps now log structured non-secret fields instead. [calico 12604](https://github.com/projectcalico/calico/pull/12604) (@Behnam-Shobiri)
- Added support for QoS maximum connection limits to the eBPF dataplane. [calico 12602](https://github.com/projectcalico/calico/pull/12602) (@coutinhop)
- calico/node now refreshes the CNI plugin's kubeconfig immediately when the pod's projected ServiceAccount token is rotated, closing a 6-12h window where an externally-invalidated token could cause CNI ADD to fail with "Unauthorized" until the calico-node pod was restarted. [calico 12595](https://github.com/projectcalico/calico/pull/12595) (@skoryk-oleksandr)
- The default BIRD logging level for BGP peers is now `{ states, routes, filters, events }` instead of just `{ states }`. BIRD logging can be disabled by setting the `LogSeverityScreen` field to `None` in `BGPConfiguration`; or it can be increased to maximum by setting the `LogSeverityScreen` field to `Debug` in `BGPConfiguration`. [calico 12578](https://github.com/projectcalico/calico/pull/12578) (@nelljerram)
- Update bundled Istio version to 1.29.2, including CVE fixes for moby/spdystream, prometheus/prometheus, and opentelemetry-go/otel/sdk. [calico 12572](https://github.com/projectcalico/calico/pull/12572) (@radixo)
- HELM: Added a `zapDevel` value to the tigera-operator chart for enabling development-mode logging on the operator. [calico 12565](https://github.com/projectcalico/calico/pull/12565) (@caseydavenport)
- `calicoctl` no longer logs raw client config on startup, which previously included `K8sAPIToken`, inline kubeconfig, `EtcdPassword`, and inline etcd key/cert material. The replacement log entry reports only non-sensitive fields and boolean "set" indicators for each credential. [calico 12535](https://github.com/projectcalico/calico/pull/12535) (@Behnam-Shobiri)
- app-policy (Dikastes): normalize HTTP request-target before evaluating Application Layer Policy path rules, and reject shapes whose resolved form depends on upstream-specific decoding. Request paths are now RFC 3986 / RFC 7230 normalized (decode percent-escapes once, resolve dot-segments and repeated slashes, fold backslashes, strip matrix parameters per segment) and prefix matches are anchored to path-segment boundaries. Paths whose decoded form still contains percent-encoded path separators (%2e / %2f / %5c), or contains a null byte, are rejected. [calico 12531](https://github.com/projectcalico/calico/pull/12531) (@electricjesus)
- Sanitize CNI plugin log output. [calico 12502](https://github.com/projectcalico/calico/pull/12502) (@Behnam-Shobiri)
- kube-controllers, goldmane: use default secure pprof server (localhost only). Use `kubectl port-forward` for remote access. [calico 12491](https://github.com/projectcalico/calico/pull/12491) (@Behnam-Shobiri)
- Typha now rejects oversized inbound client gob frames before reading them, preventing a potential denial-of-service caused by excessive memory allocation. [calico 12479](https://github.com/projectcalico/calico/pull/12479) (@Behnam-Shobiri)
- Use cryptographically secure random number generator for X.509 certificate serial numbers. [calico 12466](https://github.com/projectcalico/calico/pull/12466) (@Behnam-Shobiri)
- Felix now responds to ARP requests for pod and LoadBalancer IPs on the node's subnet, enabling L2 reachability without BGP or overlays. [calico 12451](https://github.com/projectcalico/calico/pull/12451) (@MichalFupso)
- CRD description fields are restored, so `kubectl explain` now shows field documentation for all Calico CRDs. [calico 12442](https://github.com/projectcalico/calico/pull/12442) (@caseydavenport)
- Update Rust build version to 1.94.1 for Istio Ztunnel builds. [calico 12408](https://github.com/projectcalico/calico/pull/12408) (@hjiawei)
- Helm: changes to `kubernetesServiceEndpoint.host` or `.port` now automatically trigger a tigera-operator rollout. [calico 12345](https://github.com/projectcalico/calico/pull/12345) (@caseydavenport)
- Consolidate calico-node auxiliary services into a single process, reducing per-node memory overhead by \~200 MB. [calico 12341](https://github.com/projectcalico/calico/pull/12341) (@caseydavenport)
- ebpf: Add BPFIPFragmentReassemblyEnabled config option to control IP fragment reassembly BPF program loading. When the program fails to load on older kernels, Felix reports not-ready until the feature is explicitly disabled. [calico 12293](https://github.com/projectcalico/calico/pull/12293) (@tomastigera)
- ebpf: calico-bpf dump commands now support -j/--json flag for JSON output [calico 12267](https://github.com/projectcalico/calico/pull/12267) (@tomastigera)
- Honor stderrthreshold when logtostderr is enabled in kube-controllers by opting into klog v2.140.0 fixed behavior. [calico 12263](https://github.com/projectcalico/calico/pull/12263) (@pierluigilenoci)
- Calico now ships a single "quay.io/calico/calico" image containing most sub-components, drastically reducing the number of images required to install Calico. [calico 12225](https://github.com/projectcalico/calico/pull/12225) (@caseydavenport)
- A number of calico/ docker images have been removed and subsumed by the new calico/calico image: calicoctl, cni, kube-controllers, typha, etc. [calico 12225](https://github.com/projectcalico/calico/pull/12225) (@caseydavenport)
- Release artifacts have changed as a result of consolidation from many images to the new calico/calico image. [calico 12225](https://github.com/projectcalico/calico/pull/12225) (@caseydavenport)
- Improve efficiency of JSON marshaling of label maps. Reduce allocations in mainline case. [calico 12224](https://github.com/projectcalico/calico/pull/12224) (@fasaxc)
- Add istio images to label version check in release tooling [calico 12222](https://github.com/projectcalico/calico/pull/12222) (@radixo)
- Bump Envoy Gateway from v1.5.9 to v1.7.0 and Envoy Proxy from v1.35.8 to v1.37.1. [calico 12168](https://github.com/projectcalico/calico/pull/12168) (@pasanw)
- Add NFTablesSupported feature flag, defaulting to enabled. This controls Calico's use of nftables for purposes other than policy programming, such as proxy ARP filtering. In case your distribution or kernel does not support nftables, you can disable this by setting `NFTablesSupported=false` in the `FeatureDetectOverride` field in `FelixConfiguration`. [calico 12146](https://github.com/projectcalico/calico/pull/12146) (@nelljerram)
- ebpf: Require kernel 5.10+ with BTF/CO-RE support. Remove legacy BPF object files, runtime fallback paths, and conditional compilation. Report a clear health message when the kernel is too old. [calico 12128](https://github.com/projectcalico/calico/pull/12128) (@tomastigera)
- \[BPF] Migrate BPF events from perf event array to ring buffer [calico 12111](https://github.com/projectcalico/calico/pull/12111) (@lucastigera)
- FelixConfiguration resources now support an optional `nodeSelector` field that restricts configuration to nodes matching a label selector, enabling per-node-group Felix configuration without requiring individual per-node resources. At most one selector-scoped FelixConfiguration should match any given node; if multiple match, the oldest by creation time wins to avoid disrupting existing working configuration. Overlapping selectors are treated as a misconfiguration and this behavior may change in future releases. [calico 11977](https://github.com/projectcalico/calico/pull/11977) (@tomastigera)
- LoadBalancer controller now supports spec.loadBalancerIP as a fallback when no Calico-specific annotation is set. [calico 11961](https://github.com/projectcalico/calico/pull/11961) (@nebojsaj1726)
- Calico is now built using the RHEL 9 toolchain with Go 1.26, and is updated to use the Kubernetes 1.35 release series. [calico 11948](https://github.com/projectcalico/calico/pull/11948) (@hjiawei)
- ebpf: vxlan and ipip do not have any IP assigned, therefore when a node talks to a pod via the overlay, it always uses the host's main device IP (as configured and presented in k8s as internal IP). The legacy behavior (IP on overlay device) can be restored by setting BPFOverlayIPOnDevice to true. [calico 11919](https://github.com/projectcalico/calico/pull/11919) (@tomastigera)
- Add support for named ports in ClusterNetworkPolicy. [calico 11916](https://github.com/projectcalico/calico/pull/11916) (@mazdakn)
- Support CGO Enabled builds for ppc64le [calico 11707](https://github.com/projectcalico/calico/pull/11707) (@kishen-v)
- ebpf: If first fragment on HEP from outside arrives first (in-order), do not reassemble the fragments just track the fragments. [calico 11682](https://github.com/projectcalico/calico/pull/11682) (@tomastigera)
- nftables flowtable offload, which improves performance for established connections (including traffic forwarded over a node's external interfaces), is now available when using the nftables data plane. Disabled by default, see FelixConfiguration. [calico 9458](https://github.com/projectcalico/calico/pull/9458) (@caseydavenport)

## Technology preview features

This table shows the status of features that were in technology preview at any point in the releases covered here. Technology preview features are for evaluation and feedback only and are **not supported for production use**. Behavior, APIs, and configuration may change before a feature reaches general availability.

| Feature                             | 3.31 | 3.32 | 3.33 |
| ----------------------------------- | ---- | ---- | ---- |
| Flow logs API and Whisker           | TP   | TP   | TP   |
| Istio ambient mode                  | –    | TP   | TP   |
| Native v3 CRDs                      | –    | TP   | GA   |
| Selector-scoped Felix configuration | –    | TP   | GA   |

TP = technology preview, GA = generally available, – = not available in that release.

### Technology preview changes in this release

- Native v3 CRDs are now generally available. See [Native v3 CRDs](https://docs.tigera.io/calico/latest/operations/native-v3-crds.md).
- Selector-scoped Felix configuration is now generally available. See [Selector-scoped configuration](https://docs.tigera.io/calico/latest/reference/resources/felixconfig.md#selector-scoped-configuration).

## Deprecated and removed features

Review the following table to see what features have recently been deprecated or removed. Deprecated features are still present and supported, but they are scheduled for removal. You should consider migrating away from a deprecated feature before it is removed.

| Feature                | 3.31       | 3.32       | 3.33       |
| ---------------------- | ---------- | ---------- | ---------- |
| Aggregation API server | GA         | Deprecated | Deprecated |
| FIPS mode              | Deprecated | Deprecated | Removed    |

GA = generally available, Deprecated = scheduled for removal, Removed = no longer present, – = not available in that release.

### Deprecated and removed features in this release

- Calico is moving the `projectcalico.org/v3` API from the aggregated API server to native Kubernetes CRDs. Both mechanisms will be supported until native v3 CRDs are compatible with all supported platforms, after which the aggregated API server will be removed.
- FIPS mode is removed. Calico no longer publishes the `-fips` image variants or boringcrypto binaries. The `fipsMode` field on the operator Installation API is owned by the operator and is removed separately.

## Bug fixes

- Fixes calicoctl validate accepting resources that the API server rejects, including duplicate entries in list fields such as a NetworkSet's addresses. [calico 14074](https://github.com/projectcalico/calico/pull/14074) (@caseydavenport)
- Fixed BGPConfiguration, BGPPeer and BGPFilter rejecting 4-byte AS numbers above 2147483647. [calico 14072](https://github.com/projectcalico/calico/pull/14072) (@caseydavenport)
- Fixes calico-node crash-looping at startup on canal and policy-only manifest installs. [calico 14069](https://github.com/projectcalico/calico/pull/14069) (@caseydavenport)
- Fixes calico-apiserver serving a self-signed certificate instead of the provided one when installed from manifests, which left the projectcalico.org/v3 API unavailable. [calico 14061](https://github.com/projectcalico/calico/pull/14061) (@caseydavenport)
- Fix the tigera-operator ClusterRole missing read access to ControllerRevisions, which caused repeated "forbidden" errors in the operator log. [calico 14057](https://github.com/projectcalico/calico/pull/14057) (@electricjesus)
- Fixes calico-kube-controllers repeatedly restarting after installing Calico from the manifests, caused by health probes that could not reach its health server. [calico 14051](https://github.com/projectcalico/calico/pull/14051) (@caseydavenport)
- Fixes a failure to create pods after installing Calico from the manifests, caused by the CNI plugins Calico ships not being installed onto the node. [calico 14048](https://github.com/projectcalico/calico/pull/14048) (@caseydavenport)
- Fixed calico-node repeatedly restarting when IP pool CIDRs overlap and the nftables dataplane is in use. [calico 14020](https://github.com/projectcalico/calico/pull/14020) (@caseydavenport)
- Fixes pods being unable to restart when their IP pool has no spare addresses, by reusing the address the pod already holds when its sandbox is rebuilt. [calico 14015](https://github.com/projectcalico/calico/pull/14015) (@caseydavenport)
- Fixes the projectcalico.org/v3 CRDs rejecting BGP filter and IP pool CIDRs written as an IPv6 prefix with an embedded IPv4 address. [calico 13967](https://github.com/projectcalico/calico/pull/13967) (@caseydavenport)
- Fixed a data race on the Dikastes policy sync readiness flag, which could report a stale readiness result to health checks. [calico 13966](https://github.com/projectcalico/calico/pull/13966) (@electricjesus)
- Fixes tunnel addresses not being reallocated when a node's labels change, which left IP pool node selectors ineffective until calico-node restarted. [calico 13953](https://github.com/projectcalico/calico/pull/13953) (@caseydavenport)
- Fixes a datastore migration abort leaving the aggregated API service missing, by restoring the saved service in place instead of recreating it. [calico 13953](https://github.com/projectcalico/calico/pull/13953) (@caseydavenport)
- Fixed application layer policy (Dikastes) never matching rules that reference a named port, which caused Allow rules to deny and Deny rules to have no effect. [calico 13890](https://github.com/projectcalico/calico/pull/13890) (@dimitri-nicolo)
- Fixed a bug where pre-existing connections to a node port with a backend on another node were dropped when the dataplane was switched to eBPF mode. [calico 13885](https://github.com/projectcalico/calico/pull/13885) (@tomastigera)
- Fixes calico-webhooks crashlooping on a non-operator manifest install, which left all tiered policy writes rejected. [calico 13869](https://github.com/projectcalico/calico/pull/13869) (@caseydavenport)
- Fix a node-services crash loop that left a re-registered node without its BGP address annotation for several minutes, preventing BIRD from starting. [calico 13867](https://github.com/projectcalico/calico/pull/13867) (@tomastigera)
- Fix Felix retrying an invalid tunnel route forever for a local pod whose IP was borrowed from another node's IPAM block. [calico 13844](https://github.com/projectcalico/calico/pull/13844) (@tomastigera)
- Fix the static manifests failing to install on a fresh cluster, where install-cni exited with "found no writeable directory" because it ran as a non-root user. [calico 13816](https://github.com/projectcalico/calico/pull/13816) (@tomastigera)
- Fixes flow log packet and byte counts freezing for connections offloaded to the nftables software flowtable. [calico 13804](https://github.com/projectcalico/calico/pull/13804) (@caseydavenport)
- Fixed the eBPF dataplane flagging remote workload routes as tunnelled for an address family that does not have WireGuard enabled, on dual-stack clusters with WireGuard enabled for one family only. [calico 13789](https://github.com/projectcalico/calico/pull/13789) (@tomastigera)
- Fixed a bug where setting multiple routeTableRanges could cause Felix to restart repeatedly. [calico 13770](https://github.com/projectcalico/calico/pull/13770) (@fasaxc)
- Fix that Felix kept re-emitting stale deny flow logs with zero counters (shown in Whisker as a live deny) after a policy change allowed the traffic. Fixed a leak in the eBPF endpoint manager that retained per-interface state for every Istio ambient workload torn down on a node. Fixed premature age-out of flow log entries in the eBPF dataplane, which duplicated packet and byte counts and emitted spurious expire/start flow logs for long-lived ICMP flows. Fixed two eBPF dataplane service affinity bugs: consecutive datagrams from an unconnected UDP socket could be sent to different backends because Felix's affinity map cleanup deleted the connect-time load balancer's affinity entries; and a UDP service using sessionAffinity had its affinity timeout capped at the much shorter BPF UDP conntrack timeout on the connect-time load balancer path. [calico 13608](https://github.com/projectcalico/calico/pull/13608) (@tomastigera)
- Fixes IP pools with an invalid CIDR or block size being accepted when Calico API resources are served directly by CRDs. [calico 13599](https://github.com/projectcalico/calico/pull/13599) (@caseydavenport)
- Fixes nftables-specific Felix configuration (allow and deny actions, mark mask, and refresh interval) being ignored on clusters using the default nftables mode of Auto. [calico 13580](https://github.com/projectcalico/calico/pull/13580) (@caseydavenport)
- Fixes a crash loop in nftables mode on nodes where another tool (such as Tailscale) has written nftables rules into the standard filter, nat, mangle or raw tables. [calico 13579](https://github.com/projectcalico/calico/pull/13579) (@caseydavenport)
- Fixed BPF conntrack entries for NAT'd (service) connections surviving up to an hour after a client-side TCP RST instead of expiring after two minutes. [calico 13526](https://github.com/projectcalico/calico/pull/13526) (@tomastigera)
- Fix Felix leaving a stale parent device address for no-encapsulation routes when a node loses its host IP, which caused a repeated netlink scan and warning log thereafter. [calico 13504](https://github.com/projectcalico/calico/pull/13504) (@mazdakn)
- Fixes DSCP marking, connection limits and packet rate limits being bypassed for established flows when nftables flowtable offload is enabled. [calico 13495](https://github.com/projectcalico/calico/pull/13495) (@caseydavenport)
- Fixes a bug where cancelling a datastore migration on a cluster that had already been migrated would delete the migrated Calico configuration. [calico 13449](https://github.com/projectcalico/calico/pull/13449) (@caseydavenport)
- Fixes an issue where an IP pool could be left without its Allocatable status condition, causing IPAM to keep allocating from a disabled or overlapping pool in some setups. [calico 13427](https://github.com/projectcalico/calico/pull/13427) (@caseydavenport)
- Fixes datastore migration failing partway through, with the datastore left locked, on clusters where one of the built-in tiers has a non-conformant order or default action. The migration now refuses to start and reports which tiers need correcting. A default tier with a non-conformant order was previously rewritten during the migration, and now has to be corrected by hand before the migration will start. [calico 13426](https://github.com/projectcalico/calico/pull/13426) (@caseydavenport)
- Fixes a window in nftables mode where a failure to program the dataplane could leave Calico's chains missing, so traffic went unfiltered until Felix recovered or restarted. [calico 13425](https://github.com/projectcalico/calico/pull/13425) (@caseydavenport)
- Fixes lost resource updates and IPAM allocations during the window in which the v1 to v3 datastore migration unregisters the Calico API server. [calico 13422](https://github.com/projectcalico/calico/pull/13422) (@caseydavenport)
- Fixes silently lost IPAM allocations, and a datastore that could stay locked after a failed rollback, when the v1 to v3 migration is unable to lock or unlock the v1 datastore. [calico 13421](https://github.com/projectcalico/calico/pull/13421) (@caseydavenport)
- Fix IPv6 route programming during VM live migration: IPv6 workload routes are now suppressed on the migration target until the VM goes live, and elevated in priority after cutover, as was already the case for IPv4. Previously IPv6 traffic to a migrating VM could black-hole for the duration of the migration on dual-stack clusters. [calico 13419](https://github.com/projectcalico/calico/pull/13419) (@nelljerram)
- Fixed the pending policy trace in flow logs, and the enforced verdict computed by application layer policy, to handle staged policies correctly: staged policies now contribute to the pending trace only, and a tier containing nothing but staged policies no longer applies its end-of-tier action to the enforced verdict. [calico 13416](https://github.com/projectcalico/calico/pull/13416) (@fasaxc)
- Fixed flow logs reporting a staged policy as the enforced verdict, with incorrect packet and byte counts, when a flow's policy path changed mid-flow. [calico 13410](https://github.com/projectcalico/calico/pull/13410) (@fasaxc)
- Fix a bug where Felix could remove the blackhole routes for local IPAM blocks in clusters that use more than one IP pool encapsulation type, and a rare deadlock in Felix's dataplane loop when the local node's tunnel or host address changed. [calico 13403](https://github.com/projectcalico/calico/pull/13403) (@mazdakn)
- Fixes a delay of up to 90 seconds before Felix reprograms routes after a tunnel's parent interface changes, such as when a node's IP moves to a different interface. [calico 13391](https://github.com/projectcalico/calico/pull/13391) (@caseydavenport)
- \[BPF] Fix eBPF NAT corruption where the Kubernetes API server service could share a NAT service ID with an unrelated service, causing its frontend to load-balance to the wrong backends and intermittently breaking connections to the API server. [calico 13388](https://github.com/projectcalico/calico/pull/13388) (@tomastigera)
- Fixed a case where the OpenStack DHCP agent could serve stale subnet data (e.g. outdated gateway or DNS options) indefinitely, if a subnet deletion coincided with an etcd watch restart and an overlapping subnet was later created in the same network. [calico 13368](https://github.com/projectcalico/calico/pull/13368) (@nelljerram)
- Fixed OpenStack DHCP agent handling of subnet CIDR re-use. Previously, when a network was deleted and a new network was created re-using the same subnet CIDR, the new network's VMs could fail to get DHCP responses, and DHCP updates for other networks on the same host could be delayed by several minutes. Also fixed the underlying etcd watch issue, which could delay the DHCP agent's response to any port or subnet change by around 10 seconds. [calico 13364](https://github.com/projectcalico/calico/pull/13364) (@nelljerram)
- \[eBPF] Fix a window in which a new connection to a local workload could skip that workload's ingress policy, when the connection was started while the workload's route was still being programmed. [calico 13356](https://github.com/projectcalico/calico/pull/13356) (@tomastigera)
- Fixes a Felix restart that could occur when a workload interface is removed while nftables flowtable offload is enabled. [calico 13355](https://github.com/projectcalico/calico/pull/13355) (@caseydavenport)
- Fixes an "unrecognized format" warning printed by Kubernetes 1.36 when applying the IPReservation CRD. [calico 13338](https://github.com/projectcalico/calico/pull/13338) (@caseydavenport)
- Fixed a stalled-connection bug in the eBPF dataplane where a client pod could not exchange data with a VM workload on the same node, because established-flow packets bypassed the destination MAC rewrite. [calico 13334](https://github.com/projectcalico/calico/pull/13334) (@fasaxc)
- ebpf: Fixed IPv6 session affinity entries being randomly deleted (or never expiring) due to a struct layout mismatch when Felix read the affinity timestamp, which could re-balance sticky connections to a different backend. [calico 13318](https://github.com/projectcalico/calico/pull/13318) (@tomastigera)
- Fixed head-of-line blocking in the Felix flow-log collector by processing continuous policy re-evaluation in time-boxed batches, keeping conntrack, NFLOG, and dataplane-stats processing responsive. [calico 13316](https://github.com/projectcalico/calico/pull/13316) (@fasaxc)
- Fixes an issue in nftables mode where IP set members could be left unprogrammed after the nftables table was deleted and recreated. [calico 13275](https://github.com/projectcalico/calico/pull/13275) (@caseydavenport)
- Fixes an issue in nftables mode where Felix could panic when reading back an IP set member it could not parse. [calico 13275](https://github.com/projectcalico/calico/pull/13275) (@caseydavenport)
- Fixes an issue where IP sets containing overlapping CIDRs could fail to program correctly in nftables mode after a member was removed. [calico 13274](https://github.com/projectcalico/calico/pull/13274) (@caseydavenport)
- Fixed a regression in the eBPF dataplane where pod-originated egress could be routed out the wrong interface on nodes using source-based routing (e.g. AWS VPC CNI), because the ext-to-service connmark was applied to the FIB lookup for all pod egress instead of only external-client-to-local-service reply traffic. [calico 13256](https://github.com/projectcalico/calico/pull/13256) (@tomastigera)
- Fixed a bug where Calico could advertise a Service IP over BGP from a node whose local endpoint was not Ready, causing connection failures. [calico 13246](https://github.com/projectcalico/calico/pull/13246) (@MichalFupso)
- Fixed the bundled Envoy Gateway crash-looping on clusters that only have standard-channel Gateway API CRDs, by skipping watches for CRDs that are not installed. [calico 13242](https://github.com/projectcalico/calico/pull/13242) (@electricjesus)
- eBPF: fix state explosion in the BPF verifier (resulting in programs not loading) caused by debug logs on a certain path. [calico 13204](https://github.com/projectcalico/calico/pull/13204) (@fasaxc)
- Fixed a latent bug where EnsureBlock could allocate an IPv6 block from the wrong IP pool when an explicit IPv6 pool selector was provided (Windows host-local IPAM block reservation). [calico 13197](https://github.com/projectcalico/calico/pull/13197) (@fasaxc)
- Fixed a rare start-of-day deadlock that could prevent Felix from restarting when a restart-requiring configuration change (e.g. the node IP being set) arrived while Felix was still starting up. [calico 13175](https://github.com/projectcalico/calico/pull/13175) (@fasaxc)
- Fixed a rare race in OpenStack/KubeVirt live migration handling where, after back-to-back migrations of the same VM, Felix could revert the VM's route to normal priority before BGP routing had converged. [calico 13161](https://github.com/projectcalico/calico/pull/13161) (@nelljerram)
- Fix BPF IPv6 debug programs exceeding the kernel verifier's complexity limit on newer kernels. [calico 13155](https://github.com/projectcalico/calico/pull/13155) (@sridhartigera)
- Fixed a Felix dataplane deadlock that could be triggered when a gratuitous ARP / RARP from a live-migrated VM raced with the migration-complete update from the datastore. [calico 13152](https://github.com/projectcalico/calico/pull/13152) (@nelljerram)
- Fixed a kernel dmesg spew ("could not enable bpf\_trace\_printk events") on eBPF-dataplane nodes running with kernel lockdown=confidentiality (e.g. Talos). [calico 13142](https://github.com/projectcalico/calico/pull/13142) (@tomastigera)
- Bugfix: fix BIRD config generation on Windows, following some recent confd refactoring. [calico 13140](https://github.com/projectcalico/calico/pull/13140) (@rbrtbnfgl)
- Fixed a regression in eBPF mode where traffic on the WireGuard port (51820 by default) arriving at a host interface was dropped unless it came from a known Calico node, breaking user-managed WireGuard overlays and Calico WireGuard between nodes with differing underlay addresses (e.g. behind NAT). [calico 13135](https://github.com/projectcalico/calico/pull/13135) (@tomastigera)
- Bugfix for OpenStack: Set the host-side MAC address in the same way as libvirt used (< 9.5.0) to do for Nova-plugged TAP interfaces, but now does not (because of those interfaces having to be marked as `managed=no`). This allows for live migration from a hypervisor with libvirt<9.5.0 to one with libvirt>=9.5.0. [calico 13129](https://github.com/projectcalico/calico/pull/13129) (@nelljerram)
- HELM: Fix installation of the projectcalico.org.v3 CRDs chart on Kubernetes 1.36+ by rendering the MutatingAdmissionPolicy resources at the API version the cluster actually serves. [calico 13127](https://github.com/projectcalico/calico/pull/13127) (@caseydavenport)
- Fix VXLAN traffic being dropped when the kernel masqueraded a tunnel flow's source port onto the VXLAN port (default 4789). [calico 13118](https://github.com/projectcalico/calico/pull/13118) (@caseydavenport)
- Fixes a loss of connectivity to a node when its host IP falls within a Calico IPAM block, in setups where the node network overlaps a Calico IP pool. [calico 13116](https://github.com/projectcalico/calico/pull/13116) (@caseydavenport)
- Fixes CALICO\_IPV6POOL\_VXLAN being ignored in IPv6-only clusters where the IPv4 pool is disabled (CALICO\_IPV4POOL\_CIDR=none), which left the IPv6 pool without VXLAN encapsulation. [calico 13115](https://github.com/projectcalico/calico/pull/13115) (@caseydavenport)
- Fixes a tigera-operator crash on startup caused by a missing RBAC permission to read ReplicaSets. [calico 13094](https://github.com/projectcalico/calico/pull/13094) (@caseydavenport)
- Fixes spurious `unknown field "status"` warnings logged when kube-controllers manages tier finalizers. [calico 13082](https://github.com/projectcalico/calico/pull/13082) (@caseydavenport)
- eBPF dataplane: fix loss of connectivity to the Kubernetes API server service after the API server is unavailable for a period, when using bpfNetworkBootstrap. Felix no longer clears the API server service's NAT backend when its endpoints transiently empty, so connectivity recovers without a calico-node restart. [calico 13060](https://github.com/projectcalico/calico/pull/13060) (@lucastigera)
- Fix manifest-based installs missing kubevirt.io RBAC rules on the calico-cni-plugin and calico-kube-controllers ClusterRoles, which caused KubeVirt VM networking and IPAM garbage collection failures. [calico 12995](https://github.com/projectcalico/calico/pull/12995) (@song-jiang)
- Fixed a bug where Felix's periodic route resync did not detect (and repair) Calico-owned routes that had been modified in place by another process. Fixed unnecessary reprogramming of unchanged IPv6 multi-path routes on resync, and a corner case where removing an IPAM block route could trigger a spurious conntrack cleanup for a workload owning the block's network address. [calico 12943](https://github.com/projectcalico/calico/pull/12943) (@fasaxc)
- Fixes a NotFound error when using server-side apply (including Helm 4) to create Calico network policies that don't already exist. [calico 12905](https://github.com/projectcalico/calico/pull/12905) (@caseydavenport)
- Bugfix: Felix did not emit the requested logging when configured to log to syslog at a more detailed level than to any other logging destination. [calico 12893](https://github.com/projectcalico/calico/pull/12893) (@zhanz1)
- Fix BPF dataplane failing to program (calico-node stuck 0/1) after upgrade when a stale pinned cali\_v4\_frags map with an incompatible layout remained in bpffs. [calico 12876](https://github.com/projectcalico/calico/pull/12876) (@tomastigera)
- HELM: Fixes the tigera-operator chart install instructions, which omitted the step to install Calico CRDs from the separate crd.projectcalico.org.v1 chart. [calico 12864](https://github.com/projectcalico/calico/pull/12864) (@caseydavenport)
- Fix a bug where the IPAM garbage collector in calico-kube-controllers could get stuck in a loop failing to release a leaked IP with an "update conflict" error until the controller was restarted. [calico 12839](https://github.com/projectcalico/calico/pull/12839) (@andrei-marinache)
- Fixes a bug in the eBPF dataplane in which deleting and restoring the local Node resource and restarting Felix could leave the node unable to handle network traffic. [calico 12810](https://github.com/projectcalico/calico/pull/12810) (@tomastigera)
- BPF: Fixes a panic in Felix when re-attaching the connect-time load balancer after a Felix restart leaves the previous cgroup link severed. [calico 12801](https://github.com/projectcalico/calico/pull/12801) (@caseydavenport)
- Fix Felix periodically deleting and re-adding BIRD-installed routes on workload BGP peer interfaces, which caused packet drops and conntrack flushes. [calico 12797](https://github.com/projectcalico/calico/pull/12797) (@song-jiang)
- Fixes a panic in kube-controllers when the informer delivers a tombstone object to a delete handler. [calico 12793](https://github.com/projectcalico/calico/pull/12793) (@caseydavenport)
- Fix a race in wireguard metrics collection that could result in spuriously missing metrics when metrics were collected faster than the rate limit. [calico 12781](https://github.com/projectcalico/calico/pull/12781) (@fasaxc)
- Fix SNAT being skipped for traffic destined to LoadBalancer-only IPPools by excluding them from the all-ipam-pools ipset. [calico 12769](https://github.com/projectcalico/calico/pull/12769) (@defo89)
- ebpf: Fix HostEndpoint policy blocking UDP return traffic for SNAT'd pod egress. [calico 12752](https://github.com/projectcalico/calico/pull/12752) (@tomastigera)
- Fix a bug where felix could silently drop a wireguard public key publication after a transient datastore failure if an update for the other IP version arrived during the retry window, leaving wireguard tunnels broken until the next restart. [calico 12715](https://github.com/projectcalico/calico/pull/12715) (@caseydavenport)
- Fix server-side apply (FluxCD, ArgoCD, `kubectl apply --server-side`) failures on BGPConfiguration resources that set serviceLoadBalancerIPs, serviceExternalIPs, serviceClusterIPs, communities, or prefixAdvertisements. [calico 12702](https://github.com/projectcalico/calico/pull/12702) (@caseydavenport)
- ebpf - Fix kube-proxy losing the NodePort externalTrafficPolicy=Local route-fixup trigger after a syncer swap, which could cause stale NAT entries on remote backends. [calico 12701](https://github.com/projectcalico/calico/pull/12701) (@tomastigera)
- Fix IP leak caused by concurrent IPAM allocation for a KubeVirt VM and manual freeing of IPAM handle after an earlier failure. [calico 12697](https://github.com/projectcalico/calico/pull/12697) (@fasaxc)
- Fix Istio ambient mode incorrectly adding NetworkSet CIDRs (e.g. the apiserver IP) to the all-istio-weps IPSet when a namespace is labelled istio.io/dataplane-mode=ambient, which broke readiness probes on ambient pods. [calico 12691](https://github.com/projectcalico/calico/pull/12691) (@radixo)
- ebpf - Fix transient NodePort connection failures when Felix restarts on a node receiving external NodePort traffic. [calico 12667](https://github.com/projectcalico/calico/pull/12667) (@tomastigera)
- Fixes nft binary segfaults in calico/node and the Istio CNI install image when newer nftables is in use elsewhere on the host. [calico 12660](https://github.com/projectcalico/calico/pull/12660) (@caseydavenport)
- Fixes a Felix panic that could occur when an IP set selector matched both a NetworkSet CIDR and workload IPs contained within it, with nftables as the active dataplane. [calico 12650](https://github.com/projectcalico/calico/pull/12650) (@caseydavenport)
- Fix LoadBalancer IPAM race on kube-controllers startup that could assign multiple addresses to a Service. [calico 12567](https://github.com/projectcalico/calico/pull/12567) (@MichalFupso)
- IPAM: Fix potential early release of IP attributes. [calico 12555](https://github.com/projectcalico/calico/pull/12555) (@djmitche)
- Fix incorrect IPAM handle counting on release. [calico 12554](https://github.com/projectcalico/calico/pull/12554) (@djmitche)
- Bugfix: Update BIRD configs when either of the `ipvXNormalRoutePriority` fields changes in `BGPConfiguration`. [calico 12509](https://github.com/projectcalico/calico/pull/12509) (@nelljerram)
- Fixed a regression introduced in v3.30 where `RouteSyncDisabled` flag was not being honored by `LinkAddressManager`. [calico 12489](https://github.com/projectcalico/calico/pull/12489) (@juanfresia)
- Fixed a Felix eBPF cleanup race condition that could cause a nil-pointer panic when an interface disappeared during TC qdisc cleanup. [calico 12478](https://github.com/projectcalico/calico/pull/12478) (@Behnam-Shobiri)
- Fixes an issue where calico-apiserver generated malformed OpenAPI schema definitions after the Kubernetes 1.35 dependency bump, which could cause ArgoCD and similar tools to fail schema validation. [calico 12419](https://github.com/projectcalico/calico/pull/12419) (@caseydavenport)
- Fixes repetitive "Network is unreachable" errors when WireGuard is enabled in conjunction with BGP in some setups. [calico 12346](https://github.com/projectcalico/calico/pull/12346) (@caseydavenport)
- Fixed a bug where the v1→v3 datastore migration controller could fail to create the default Tier if its v1 Order field did not match the v3-required value. [calico 12317](https://github.com/projectcalico/calico/pull/12317) (@lwr20)
- Fix memory leak in LoadBalancer controller where `deleteService` and `releaseAddressFromService` left stale entries in the `ipsByBlock` index, and where `releaseAddressFromBlock` accumulated empty block keys indefinitely. In long-running clusters with high LoadBalancer service churn this could cause unbounded memory growth in kube-controllers. [calico 12300](https://github.com/projectcalico/calico/pull/12300) (@lwr20)
- Fix key-cert provisioner CSR watch errors to display unexpected objects with default formatting instead of misleading octal output. [calico 12274](https://github.com/projectcalico/calico/pull/12274) (@cuiweixie)
- ebpf: Fix conntrack counter accounting for NAT-outgoing flows where bytes\_in and packets\_in were always zero. [calico 12269](https://github.com/projectcalico/calico/pull/12269) (@lucastigera)
- Fix race condition for statefulset pods that can result in missing routes. [calico 11631](https://github.com/projectcalico/calico/pull/11631) (@caseydavenport)

## Known issues

### eBPF data plane does not start on kernel 5.15

**Problem.** On a node running kernel 5.15, the eBPF data plane does not start. Felix reports `BPF program load failed permanently` for `from_hep_no_log.o`, and `calico-node` restarts on some nodes.

**Cause.** The eBPF host endpoint program has grown past the kernel BPF verifier's limit of one million instructions, and Felix's fallback of disabling the optional programs does not bring it back under. Kernel 5.15 is within the documented minimum of 5.10, and 3.32 loads the same program on the same kernel, so this is a regression in 3.33. Kernel 6.8 and later prune the program more effectively and are unaffected. Kernels between 5.10 and 6.8 other than 5.15 have not been tested.

**Workaround.** Move affected nodes to a node image with kernel 6.8 or later, or stay on 3.32. On AKS, the default node image is Ubuntu 22.04 with kernel 5.15 for Kubernetes 1.25 through 1.34; 1.35 and later use Ubuntu 24.04 with kernel 6.8.

## Upgrading

You can upgrade to 3.33 from the two previous releases, 3.31 and 3.32.

3.33 changes several things that may need action before or during an upgrade, including the move to a single `calico/calico` image, new size limits on policy rules and selectors, and a namespace move for Calico Ingress Gateway proxies. Review the [upgrade notes](https://docs.tigera.io/calico/latest/operations/upgrading/upgrade-notes.md) before you start.

Then follow the upgrade guide for your platform:

- [Kubernetes](https://docs.tigera.io/calico/latest/operations/upgrading/kubernetes-upgrade.md)
- [OpenShift](https://docs.tigera.io/calico/latest/operations/upgrading/openshift-upgrade.md)
- [OpenStack](https://docs.tigera.io/calico/latest/operations/upgrading/openstack-upgrade.md)

## Release details

### Calico Open Source 3.33.0 general availability release

October 01, 2026

Calico Open Source release 3.33.0 is now generally available.

#### Updating

Review the [upgrade notes](https://docs.tigera.io/calico/latest/operations/upgrading/upgrade-notes.md), then follow [our upgrade guides](https://docs.tigera.io/calico/latest/operations/upgrading.md).
