Upgrade Path

Traefik 2.4.0 → 2.5.0

13 versions, 9 migration-guide sections in 4 versions, 0 required stops

Version by version, oldest first

2.4.1 – 2.4.7: no action items (6 versions)

2.4.8 2021-03-22

Migration

Non-ASCII Domain Names

In v2.4.8, we introduced a new check on domain names used in HTTP router rule Host and HostRegexp expressions, and in TCP router rule HostSNI expression. This check ensures that provided domain names don't contain non-ASCII characters. If not, an error is raised, and the associated router will be shown as invalid in the dashboard.

This new behavior is intended to show what was failing silently previously and to help troubleshooting configuration issues. It doesn't change the support for non-ASCII domain names in routers rules, which is not part of the Traefik feature set so far.

In order to use non-ASCII domain names in a router's rule, one should use the Punycode form of the domain name. For more information, please read the HTTP routers rule part or TCP router rules part of the documentation.

From doc.traefik.io/traefik/v2.11/migration/v2/#non-ascii-domain-names

Full release notes for 2.4.8

2.4.9 2021-06-21

Migration

Tracing Span

In v2.4.9, we changed span error to log only server errors (>= 500).

From doc.traefik.io/traefik/v2.11/migration/v2/#tracing-span

Full release notes for 2.4.9

2.4.11 2021-07-15

Migration

K8S CrossNamespace

In v2.4.10, the default value for allowCrossNamespace has been changed to false.

From doc.traefik.io/traefik/v2.11/migration/v2/#k8s-crossnamespace

Migration

K8S ExternalName Service

In v2.4.10, by default, it is no longer authorized to reference Kubernetes ExternalName services. To allow it, the allowExternalNameServices option should be set to true.

From doc.traefik.io/traefik/v2.11/migration/v2/#k8s-externalname-service

Full release notes for 2.4.11

2.4.12 – 2.4.14: no action items (3 versions)

2.5.0 2021-08-17

Quoted from doc.traefik.io/traefik/v2.11/migration/v2/#v24-to-v25

Migration

Kubernetes CRD

In v2.5, the Traefik CRDs have been updated to support the new API version apiextensions.k8s.io/v1. As required by apiextensions.k8s.io/v1, we have included the OpenAPI validation schema.

After deploying the new Traefik CRDs, the resources will be validated only on creation or update.

Please note that the unknown fields will not be pruned when migrating from apiextensions.k8s.io/v1beta1 to apiextensions.k8s.io/v1 CRDs. For more details check out the official documentation.

Migration

Kubernetes Ingress

Traefik v2.5 moves forward for the Ingress provider to support Kubernetes v1.22.

Traefik now supports only v1.14+ Kubernetes clusters, which means the support of extensions/v1beta1 API Version ingresses has been dropped.

The extensions/v1beta1 API Version should now be replaced either by networking.k8s.io/v1beta1 or by networking.k8s.io/v1 (as of Kubernetes v1.19+).

The support of the networking.k8s.io/v1beta1 API Version will stop in Kubernetes v1.22.

Migration

Headers middleware: ssl redirect options

sslRedirect, sslTemporaryRedirect, sslHost and sslForceHost are deprecated in Traefik v2.5.

For simple HTTP to HTTPS redirection, you may use EntryPoints redirections.

For more advanced use cases, you can use either the RedirectScheme middleware or the RedirectRegex middleware.

From doc.traefik.io/traefik/v2.11/migration/v2/#headers-middleware-ssl-redirect-options

Migration

Headers middleware: accessControlAllowOrigin

accessControlAllowOrigin is no longer supported in Traefik v2.5.

Migration

X.509 CommonName Deprecation Bis

Following up on the deprecation started previously, as the x509ignoreCN=0 value for the GODEBUG is deprecated in Go 1.17, the legacy behavior related to the CommonName field cannot be enabled at all anymore.

From doc.traefik.io/traefik/v2.11/migration/v2/#x509-commonname-deprecation-bis

Full release notes for 2.5.0

Release notes from github.com/traefik/traefik/blob/master/CHANGELOG.md, and Migration: Steps needed between the versions (v2.11 documentation), checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else. Traefik's release notes (CHANGELOG.md, GitHub releases) are lists of merged pull requests and mark nothing as breaking. What is quoted instead is Traefik's migration documentation on doc.traefik.io: “Migration: Steps needed between the versions” (v3), the same page of the v2.11 documentation (v2), and “Configuration Details for Migrating from Traefik v2 to v3” (on 3.0.0). Each section of those pages is labelled “Migration” and shown on the release its heading names (“v3.3 to v3.4” on 3.4.0). A section naming a canceled release (v2.4.10, v2.9.0) is shown on the next release of that line. Versions are covered from 2.0.0. No required stop is documented.