Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Nginx version 1.25.3 is End Of Life #11401

Closed
moazrefat opened this issue May 31, 2024 · 5 comments · Fixed by #11470
Closed

Nginx version 1.25.3 is End Of Life #11401

moazrefat opened this issue May 31, 2024 · 5 comments · Fixed by #11470
Labels
kind/feature Categorizes issue or PR as related to a new feature. needs-priority needs-triage Indicates an issue or PR lacks a `triage/foo` label and requires one.

Comments

@moazrefat
Copy link

moazrefat commented May 31, 2024

The used version of Nginx 1.25.3 is end of life since 29.05.2024 which makes ingress nginx risky to be used, you can find the details here
https://nginx.org/en/CHANGES

It would be very crucial to environments which runs ingress nginx on production to have supported version of nginx.

@moazrefat moazrefat added the kind/feature Categorizes issue or PR as related to a new feature. label May 31, 2024
@k8s-ci-robot k8s-ci-robot added the needs-triage Indicates an issue or PR lacks a `triage/foo` label and requires one. label May 31, 2024
@k8s-ci-robot
Copy link
Contributor

This issue is currently awaiting triage.

If Ingress contributors determines this is a relevant issue, they will accept it by applying the triage/accepted label and provide further guidance.

The triage/accepted label can be added by org members by writing /triage accepted in a comment.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@longwuyuan
Copy link
Contributor

You asked in the other issue and I commented there already. #11396 (comment)

The project scans regularly for vulnerabilities and patches the controller regularly. Look up the history of patches and releases by doing searches in PRs.

@moazrefat
Copy link
Author

moazrefat commented May 31, 2024

@longwuyuan thanks for replying so quick.

so you are telling that this version (connected to ingress-ngixn pod and ran below command)

nginx-public-ingress-nginx-controller-fd5d4979c-kstp9:/etc/nginx$ nginx -version
nginx version: nginx/1.25.3

is not the same nginx version that's mentioned here https://nginx.org/en/CHANGES (v1.25.3) which is EOL but more of recompiled version with latest security patches

Sorry that is quite confusing for me.

@strongjz
Copy link
Member

strongjz commented Jun 4, 2024

We are beholden to the openrusty community to upgrade the nginx version of the controller due to the amount of functionality the ingress-nginx controller relays on those lua and openrusty plugins.

@strongjz
Copy link
Member

strongjz commented Jun 5, 2024

Looks like the lua stream module is not compatible with 1.25.5

https://github.com/kubernetes/ingress-nginx/actions/runs/9388160304/job/25852789887?pr=11429#step:9:8095

#11429

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/feature Categorizes issue or PR as related to a new feature. needs-priority needs-triage Indicates an issue or PR lacks a `triage/foo` label and requires one.
Projects
4 participants