This topic lists the release notes for Service Mesh (ASM).
March–June 2026
Feature | Description | Regions | Versions | Editions | References |
Support for version 1.29 | Adds support for Istio version 1.29.
| All | 1.29 | All | |
Custom component patch | Supports custom configurations for ASM-deployed components in ASMMeshConfig. | All | 1.27 and later | All | |
Global namespace configuration | Supports using the ASMReconcileNSLabels resource to control the synchronization of Istio-related namespace labels across multiple clusters. | All | 1.28 and later | All | |
Ztunnel egress traffic management enhancement | Ztunnel now supports EgressPolicy to control outbound traffic to services outside the cluster. | All | 1.29 and later | All |
January–February 2026
Feature | Description | Regions | Versions | Supported Product Specifications | References |
Support for version 1.28 | Adds support for Istio version 1.28.
| All | 1.28 | All | |
Enhanced pre-upgrade checks | Before an upgrade, Mesh diagnostics runs to detect configuration issues in the service mesh. These issues do not block the upgrade, but we recommend fixing them to prevent unexpected behavior afterward. | All | 1.25 and later | All | |
Mesh diagnostics enhancement | Adds a new diagnostic check for an excessive number of pods in the data plane. | All | 1.25 and later | All | |
Feature updates |
| All | 1.24 and later | All |
November–December 2025
Feature | Description | Regions | Versions | Editions | References |
Support for version 1.27 | Adds support for Istio version 1.27.
| All | 1.27 | All | |
Enhanced access to Istio resources via the data plane KubeAPI | You can use the Terraform Kubernetes Provider in ACK clusters to manage ASM resources. | All | 1.26 and later | All | Access Istio resources through the KubeAPI of a data plane cluster |
Mesh diagnostics enhancement | Adds conflict detection for the Hosts field in ServiceEntry. | All | 1.27 and later | All |
October 2025
Feature | Description | Region | Version | Editions | References |
Support for version 1.26 |
| All | N/A | All | |
Enhanced graceful shutdown for Service Mesh (ASM) gateways | Supports a longer drain duration and improves support for HTTP and gRPC protocols. | All | 1.26 and later | Enterprise and Ultimate editions | |
Support for managing Service Mesh (ASM) through the ACK component center | Create and add Service Mesh (ASM) instances from the ACK component center. | All | N/A | All |
August–September 2025
Feature | Description | Regions | Applicable versions | Applicable editions | References |
Data plane Kube API access | Adds support for server-side apply and patch operations. | All | 1.25.6.101 and later | All | Access Istio resources through the KubeAPI of a data plane cluster |
New diagnostic checks for Mesh Diagnostics | Adds the following diagnostic checks:
| All | 1.25.6.101 and later | All | |
Graceful shutdown for waypoints in Ambient mode | Lets you customize the ProxyConfig field of a waypoint proxy to specify drain-related parameters, enabling graceful shutdown during waypoint rolling updates. | All | 1.25.6.101 and later | All | |
ASM Gateway defaults to NLB | Network Load Balancer (NLB) is a high-performance Layer 4 load balancing service with automatic elasticity, designed for high-concurrency scenarios involving many connections. | All | 1.18 and later | Enterprise and Ultimate editions |
June–July 2025
Feature | Description | Publishing region | Version | Applicable specifications | References |
Support for Version 1.25 | Supports Istio 1.25. Ambient Sidecarless Mode is now in General Availability (GA):
| All | N/A | All | |
Mesh Diagnostics 2.0 | Adds more than 30 new diagnostic rules and supports diagnostics for Ambient Sidecarless Mode. Diagnostic results are now standardized and more specific. This feature is compatible with the upstream community. | All | 1.25 and later | All | N/A |
Support for Certificate Management | You can now deploy certificates from the Certificate Management Service console directly to a data plane cluster for use by an ASM gateway. | All | 1.25 and later | All | Use a Certificate Management Service certificate in an ASM gateway |
Enhanced Circuit Breaking and Throttling | Improves semantic consistency. You can now reference resource objects, such as VirtualService and Kubernetes Service, in throttling configurations. | All | 1.25 and later | All | |
GUI Operations for the Traffic Scheduling Suite | You can now enable and configure the traffic scheduling suite through the GUI, which reduces complexity and improves the user experience. | All | All | All | Use the ASM traffic scheduling suite for traffic control in distributed systems |
April–May 2025
Feature | Description | Regions | Applicable versions | Applicable editions | References |
Proportional Sidecar Resource Allocation | You can now set a ratio to allocate resources to a sidecar container in proportion to the resources of its corresponding application container. | All | 1.24 and later | All | |
Local development and testing with Ktctl Mesh and Service Mesh | KtConnect is a local developer supporting tool for Kubernetes. Its deployed proxy is compatible with the core traffic management capabilities of service mesh. By coordinating with the traffic resources of the service mesh, you can debug local applications more efficiently and accelerate local development and testing. This topic describes how to combine KtConnect and ASM for local development and testing. | All | All | All | Local development and testing with KtConnect and Service Mesh |
Custom status codes for rate limiting | Local rate limiting supports custom return status codes. | All | 1.24.6.64 and later | All | |
Tracing Analysis supports configuration for namespaces and workloads. | Starting with version 1.24.6.83, ASM supports modifying Telemetry resources through the Kubernetes API to configure Tracing Analysis at the namespace and workload levels. | All | 1.24.6.83 and later | All | |
Support for trusted CIDR blocks in XFF headers | In addition to configuring the "number of trusted proxies," you can now configure "trusted CIDR blocks." This provides more flexibility in obtaining the originating IP addresses of requests. | All | 1.24 and later | All | Configure the XFF request header to allow ASM gateways to obtain client IP addresses |
March 2025
Feature | Description | Regions | Applicable versions | Applicable editions | References |
Enforce "Forced ASM Sidecar Injection" policy | Enable the "Forced ASM Sidecar Injection" policy in ACK Policy Management to secure east-west traffic within your cluster. | All | 1.24 and later | All | Enforce the forced sidecar injection security policy for a cluster |
ASMCircuitBreaker enhancements | ASMCircuitBreaker is enhanced to support configuring circuit breaking rules for Gateway Errors. | All | 1.24.6.54 and later | All | |
LLMRoute CRD reference | The | All | 1.21 and later | All | |
Manage service mesh resources using the Go SDK | Use the Go SDK to manage resources in the service mesh. | All | 1.24 and later | All | |
Configure Grafana dashboards and alert rules for circuit breaking and throttling | Provides best practices for configuring Grafana dashboards and alert rules for circuit breaking and throttling. | All | All | All | Configure Grafana dashboards and alert rules for circuit breaking and throttling |
February 2025
Feature | Description | Regions | Versions | Supported Product Specifications | References |
CNI compatibility with debian_12_7_x64_20G_alibase_20241031.vhd | ASM CNI now supports nodes that use the Debian operating system. | All | 1.24 and later | All | None |
Configure mesh instances using the ASMMeshConfig CRD | ASMMeshConfig is a custom resource provided by Service Mesh (ASM) to globally configure core service mesh parameters. This CRD centrally manages mesh-level settings, such as connection timeouts, protocol detection, path normalization, and retry policies. It also supports resource quotas and behavioral controls for the sidecar injector. | All | 1.24 and later | All | |
Message queue adaptation for traffic lanes | In flexible traffic lane scenarios, if you want message queues to maintain and carry tagging information, your application requires some adaptation. ASM provides a standard adaptation solution for your reference. | All | 1.21 and later | All | |
ASMEgressTrafficPolicy support for external TCP services | ASMEgressTrafficPolicy now supports external TCP services. You can use ASMEgressTrafficPolicy to easily configure egress traffic for protocols such as HTTP, HTTPS, and TCP. This update also supports automatic allocation of egress gateway ports, which reduces the maintenance workload. | All | 1.24 and later. | All | |
ASMExtensionProviders CRD documentation | ASMExtensionProvider is a component used to extend and configure mesh features. It supports flexible integration and custom configuration of key features such as Tracing Analysis and access logs. | All | 1.23 and later | All |
January 2025
Feature | Description | Regions | Version | Specification | References |
Support for Version 1.24 | Supports Istio 1.24. | All | N/A | All | |
Enhanced load balancing and traffic management for in-cluster LLM services | For LLM inference services deployed in Kubernetes clusters, classic load balancing methods are often ineffective due to the unique characteristics of LLM inference traffic and workloads. It is also difficult to obtain LLM inference-related information from logs and monitoring metrics. Service Mesh (ASM) lets you declare inference service pools and routing definitions for LLM inference services deployed in a cluster. This improves the load balancing performance of LLM inference services and enables routing and observability for inference traffic. This feature currently supports LLM inference services deployed based on vLLM. | All | 1.24 or later | All | |
In-place migration from Istio | Supports in-place migration to ASM for clusters that have Istio installed. During the migration process, ASM and Istio coexist. You can gradually switch workloads from Istio Sidecar injection to ASM mesh proxy injection until all Istio Sidecars are replaced with ASM mesh proxies. This feature helps you migrate from Istio to ASM in a progressive manner without downtime. Currently, ASM in-place migration supports migrating single-cluster Istio, Primary-Remote, Multi-Primary, and hybrid deployments of Primary-Remote and Multi-Primary architectures to ASM. | All | 1.24 or later | All |
December 2024
Feature | Description | Regions | Versions | Applicable Specifications | References |
Support for version 1.23 | Supports Istio 1.23. | All | 1.23 or later | All | |
Use Envoy External Processing for custom request handling | Envoy External Processing is an extension that uses an external service to enhance HTTP request and response handling. This eliminates the need to write Wasm plugins or other processing scripts, offering a more flexible and scalable solution. | All | 1.23 or later | All | |
Token-based rate limiting for LLM requests | Rate limiting LLM requests differs from rate limiting standard HTTP requests. Because the number of tokens per LLM request varies, the count must be dynamically obtained from the response. ASM provides default LLM request rate limiting based on the token bucket algorithm and lets you customize the algorithm. | All | 1.23 or later | All | |
Exclude Pods with specified labels from the service discovery scope | If a pod is outside the service discovery scope, the control plane will not discover it, and sidecar proxies will not send any requests to it. You can configure a label selector to exclude pods with specific labels from the service discovery scope. This lets you quickly shift traffic away from a pod for rapid failover. | All | 1.20 or later | All | Configure a service discovery scope to improve the efficiency of mesh configuration pushes |
Support for new fields in ASMGrpcJsonTransCoder | The ASMGrpcJsonTranscoder CRD is used for JSON/HTTP-to-gRPC protocol transcoding. In version 1.22 and later, ASMGrpcJsonTranscoder supports new fields for advanced scenarios such as converting gRPC errors to the response body and ignoring specific request query parameters. | All | 1.22 or later | All | |
LLM traffic management | Most major large language model (LLM) providers offer services to users over HTTP. Based on the HTTP protocol, special optimizations have been made for LLM requests. The protocol standards of multiple major LLM providers are now supported, providing you with a simple and efficient access experience. This topic describes how to manage LLM traffic in ASM from the perspectives of traffic routing and observability. | Alibaba Cloud International Website (www.alibabacloud.com) | 1.21 or later | All |
November 2024
Feature | Description | Regions | Applicable versions | Product specifications | References |
Implement user identity-based canary testing with traffic lanes and hash tagging | In a production environment, you may want to use traffic lanes to isolate stable and canary release versions and route traffic to different lanes based on user identity. Specifically, you might want to route a specific group of users to the canary release version for testing, while routing a certain percentage of requests from other users to the canary release version randomly based on weight. | All | 1.18 or later | All | Implement user identity-based canary testing with traffic lanes and hash tagging |
ASM supports namespace-level RBAC authorization | You can use RBAC authorization to control the permissions of RAM users and RAM roles to operate on custom resources in ASM. When RAM users and RAM roles need to operate on custom resources in ASM, you must grant RBAC authorization to the RAM users and RAM roles. | All | All | All |
October 2024
Feature | Description | Regions | Applicable versions | Applicable editions | References |
Multi-primary control plane mode | Service Mesh (ASM) supports a multi-primary control plane mode. In this architecture, multiple ASM instances manage multiple Kubernetes clusters. This mode provides significant advantages over a single-instance setup, such as better configuration isolation and lower configuration push latency. It is ideal for implementing multi-cluster disaster recovery for peer-deployed services. | All | 1.22 and later | All | Implementing Multi-Cluster Disaster Recovery with the ASM Multi-Primary Control Plane Architecture |
Native Sidecar proxy | Starting with version 1.28, Kubernetes introduced native Sidecar containers, which resolve known issues with the container lifecycle relative to the pod lifecycle. Service Mesh (ASM) 1.22 and later supports this feature and adaptively enables the native Sidecar mode to inject the mesh proxy into a pod. | All | 1.22 and later | All | |
Metric Collection for the Traffic Scheduling Suite | You can collect monitoring metrics for the ASM request scheduling agent by integrating with Alibaba Cloud Managed Service for Prometheus or a self-managed Prometheus instance. This lets you monitor how different policies in the traffic scheduling suite control and schedule traffic. | All | 1.21 and later | All | Controlling Traffic in Distributed Systems with the ASM Traffic Scheduling Suite |
Metric Extension with WASM Plugins | In addition to its built-in metrics, Service Mesh (ASM) provides a powerful extension mechanism. You can use WASM plugins to write custom logic based on request or response data. This lets you add processed results as new dimensions to your monitoring metrics, providing deeper visibility into your application's behavior. | All | 1.18 and later | All | Extending ASM Monitoring Metric Dimensions with a WASM Plugin |
Periodic Cleanup of Monitoring Metrics | Service Mesh (ASM) generates metrics such as traffic volume, error rates, and request latency for all service traffic, allowing you to monitor service behavior. Over time, accumulating this data increases resource consumption for both the Envoy proxies and Prometheus. To address this, ASM now offers periodic metric cleanup. This feature automatically removes unused metrics cached in Envoy, reducing memory usage and lowering the network load from Prometheus scrapes. | All | 1.18 and later | All |
September 2024
Feature | Description | Regions | Versions | Editions | References |
Deploy and manage Service Mesh (ASM) on CloudBox | Create a CloudBox node pool in an ACK cluster and schedule application pods to its nodes to use CloudBox resources. After adding the ACK cluster to Service Mesh (ASM), ASM manages pods on both the public network and the CloudBox node pool, providing unified routing, security, and observability for inter-application traffic. | All | All | All | |
Manage Kubernetes clusters imported via Kubeconfig | Service Mesh (ASM) supports importing any Kubernetes cluster using a Kubeconfig file with cluster administrative permission, enabling Application Management on the imported cluster. | All | 1.22 or later | All | |
Best Practices: End-to-end security | A standard TLS connection only requires the client to validate the server-side certificate, leaving the client's identity unverified. For higher security, mTLS (Mutual TLS) requires both the client and server-side to present certificates. Encrypted communication begins only after this mutual validation is successful. | All | 1.22 or later | All | |
Best Practices: Custom error pages | In some cases, an ASM gateway or mesh proxy responds directly to the downstream with a specific HTTP response code instead of proxying the request to an upstream service. The | All | All | All | |
ASMSwimlane/ASMSwimlaneGroup CRD enhancements | You can now apply custom destination traffic policies and HTTP routing operations to services within a traffic lane group. | All | 1.22 or later | All | |
Support for remote control plane mode | Use the remote control plane mode to reduce configuration push latency. This mode is ideal when your data plane cluster is in a different Alibaba Cloud service or an on-premises data center, and the network connection to the Service Mesh (ASM) managed control plane is unstable or bandwidth-limited. | All | 1.22 or later | All | |
Develop Wasm plugins using Rust | Service Mesh (ASM) supports deploying Wasm plugins to the mesh proxy to add custom logic. The proxy-wasm community provides a Rust software development kit (SDK) for building these plugins. | All | 1.18 or later | All |
August 2024
Feature | Description | Regions | Applicable versions | Supported editions | References |
Support for Istio 1.22 | This release adds support for Istio 1.22, which includes the following key updates:
| All | 1.22 or later | All | N/A |
New ACMG mode | The Alibaba Centralized Mesh Gateway (ACMG) mode is a solution designed for large-scale network architectures. It improves network scalability, flexibility, and management efficiency. | All | 1.22 or later | All | |
Egress Traffic Security | You can use ASMEgressTrafficPolicy and an egress gateway to secure egress traffic from the mesh to external destinations. | All | 1.20 or later | All | |
Enhanced multi-cluster capabilities | This release enhances east-west gateway capabilities. Cross-cluster calls through an east-west gateway now support full Layer 7 load balancing, authorization policies, and CIDR conflict shielding. For multi-cluster scenarios without underlying network connectivity, a Service Mesh (ASM) east-west gateway provides an experience equivalent to a fully connected network. | All | 1.22 or later | Enterprise Edition, Ultimate Edition | |
Integration with ARMS for extended metrics | Service Mesh (ASM) provides monitoring metrics for the data plane. When enabled, gateways and sidecar proxies generate operational metrics that are collected in Alibaba Cloud Managed Service for Prometheus. | All | 1.17.2.35 or later | All | |
Best practices - Integrate a custom authorization service | You can now integrate with custom authorization services that use the HTTP and gRPC protocols. | All | 1.20 or later | All | |
Monitoring Metrics and Alerting for Rate Limiting and Circuit Breaking | You can now collect monitoring metrics for rate limiting and circuit breaking in Alibaba Cloud Managed Service for Prometheus. This includes metrics for local and global rate limiting, along with service-level, host-level, and connection pool circuit breaking. You can also configure alerting based on these metrics to be notified of rate limiting or circuit breaking events. | All | All | All |
July 2024
Feature | Description | Regions | Versions | Editions | Documentation |
ASM Gateway support for HTTP/3 and QUIC protocols | The ASM gateway now supports the HTTP/3 protocol. Compared to HTTP/2, HTTP/3 provides lower handshake latency, a new multiplexing mechanism, connection migration, and enhanced security. HTTP/3 is based on the UDP protocol, which lets you enable TCP and UDP listeners on the same port without affecting existing HTTP/1.1 or HTTP/2 traffic. | All | 1.16 or later | All | |
Maximum downstream connection limit for sidecar proxies | You can now limit the maximum number of downstream connections a mesh proxy accepts. This helps prevent malicious attacks by controlling connection volume. | All | 1.21 or later | All | |
Support for path normalization policies | You can now configure a path normalization policy for HTTP requests on the mesh proxy. This ensures that HTTP request paths within the service mesh are standardized, reducing security risks. | All | 1.21 or later | All | |
The ASM traffic rerouting suite supports closed-loop feedback, concurrency limits, concurrent scheduling, and quota scheduling. | The ASM traffic scheduling suite now supports four new policies:
| All | 1.21 or later | All | Use the ASM traffic scheduling suite for traffic control in distributed systems |
A playground feature | ASM Lab lets you set up a complete environment for a specific scenario with a single click. This includes workloads and all required declarative API (CR) resources. Each scenario in ASM Lab showcases a specific feature by automatically deploying the required resources and offering varying levels of control. This one-click setup helps you quickly explore the powerful features of Service Mesh (ASM). | All | 1.21 or later | All |
June 2024
Feature | Description | Regions | Applicable versions | Applicable specifications | References |
Service mesh network packet capture | This feature lets you create a network packet capture task to capture traffic for a specific workload within the service mesh, helping you quickly diagnose complex traffic issues. | All | 1.21 or later | All | Use network packet capture tasks to diagnose traffic in the mesh |
ASM traffic scheduling suite | Built on service mesh principles, the ASM traffic scheduling suite offers various scheduling policies for advanced traffic management, such as per-user rate limiting and request priority scheduling. | All | 1.21 or later | All | Use the ASM traffic scheduling suite for traffic control in distributed systems |
EWMA load balancing | The EWMA load balancer selects endpoints by calculating a score based on the moving average of factors like static weight, response time, and error rate. This improves overall performance by avoiding poorly performing endpoints during occasional response time spikes or errors. | All | 1.21 or later | All | Use Exponentially Weighted Moving Average (EWMA) for workload latency-based load balancing |
Enhanced Knative integration | Knative on ASM is updated to version 1.12.4. This release streamlines integration with container service Knative and offers a one-click deployment experience. | All | 1.21 or later | All | |
Improved Terraform support |
| All | 1.21 or later | All |
May 2024
Feature | Description | Regions | Applicable versions | Applicable editions | References |
Istio 1.21 is released. | This release adds support for Istio 1.21, which is now generally available. This version includes the latest community features:
Important In version 1.21, the ability to load a bootstrap configuration for a sidecar proxy before startup is deprecated. For more information, see Configure a sidecar proxy. | All | 1.21 or later | All | |
Traffic lane | Traffic lane 3.0 now supports baggage header propagation and percentage-based traffic routing. | All | 1.21 or later | All | |
Enhanced multi-cluster capabilities | This release introduces a new multi-cluster network solution. When underlying cluster networks cannot be connected directly, you can use an ASM east-west gateway to connect them over the public network. The new document, Overview of multi-cluster management, describes the modes and paths for multi-cluster management in ASM. | All | 1.21 or later | All | |
ASM Mesh Topology supports subgraph views | ASM Mesh Topology now lets you select a namespace or an application to view its sub-topology. This feature makes the service topology easier to view and use in large-scale deployments. | All | 1.21 or later | All | |
Route-level configuration for ASMCompressor | ASMCompressor now supports route-level configuration, which lets you enable compression by default while disabling it for specific routes. This simplifies configuration and reduces the risk of misconfiguration. | All | 1.21 or later | All | Use ASMCompressor to define compression configurations for inter-application service calls |
April 2024
Feature | Description | Regions | Istio version | Editions | References |
Istio 1.21 is now available. | This release adds support for Istio 1.21 as a canary release, which includes the latest community features:
Important As of version 1.21, loading a bootstrap configuration for a sidecar proxy before startup is deprecated. For more information, see Configure a sidecar proxy. | All | 1.21 or later | All | |
Automatic certificate issuance for ASM gateways using the ACME Protocol | The ACME Protocol allows a certificate authority (CA) to automatically verify an applicant's domain name ownership before issuing a certificate. Service Mesh (ASM) gateways can connect to various CAs through the ACME Protocol to dynamically obtain domain name certificates, reducing certificate maintenance overhead. | All | All | All | |
Data plane performance optimization with eRDMA and SMC | You can enable SMC-based performance optimization for service mesh data plane communication on eighth-generation Alibaba Cloud Elastic Compute Service instances that support eRDMA and run Alinux 3. | All | 1.21 or later | All | Accelerate network performance between service mesh pods based on eRDMA |
Manage cross-VPC connectivity between control plane and data plane clusters with PrivateLink | When a Service Mesh (ASM) instance and a data plane ACK cluster are in the same region but different VPCs, you can use PrivateLink to establish connectivity between the control plane and data plane clusters. ASM provides a CRD-based method to simplify network connectivity. | All | 1.21 or later | All | Manage connectivity between control plane and data plane clusters across VPCs using PrivateLink |
Accelerate inference for model services with dynamic subset routing | Dynamic subset routing in Service Mesh (ASM) routes requests directly to the correct runtime environment, accelerating the inference process for model services. | All | 1.21 or later | All | Use dynamic subset routing to accelerate model service mesh inference |
Use ASMCircuitBreaker to configure circuit breaker rules for inter-service call traffic | Use the ASMCircuitBreaker CRD to configure circuit breaker rules for east-west traffic. | All | 1.19 and later | All | Use ASMCircuitBreaker to configure circuit breaker rules for inter-service call traffic |
March 2024
Feature | Description | Regions | Istio versions | Product specifications | References |
Access logs support plain text (non-JSON) output. | You can now output access logs to the container standard output as plain text. This format is more space-efficient and information-dense than JSON. | All | v1.20 and later | All | |
You can configure a maintenance time window. | You can now set a maintenance window for your service mesh to define when automatic maintenance of the managed control plane occurs. | All | All | All | |
Develop Wasm extensions for the mesh proxy using Go | You can now develop Wasm extensions in Go and inject them into the mesh proxy's filter chain. These extensions let you implement custom logic, such as dynamically modifying HTTP headers, adjusting routing, or integrating with external authorization services. | All | v1.18 and later | All | |
Support for Managed Security Groups | New ASM instances now use managed security groups. These groups provide enhanced security for the managed control plane. | All | v1.20 and later | All |
February 2024
Feature | Description | Regions | Applicable Istio versions | Applicable editions | References |
Istio 1.20 is now available. | Istio 1.20 is published and compatible with the latest community features. | All | v1.20 and later | All | |
Canary upgrade for ASM gateway | Service Mesh (ASM) now supports canary upgrades for the ASM gateway to ensure business continuity. You can deploy a new gateway version to verify traffic before completing the full upgrade. If an issue occurs, roll back at any time by deleting the new version's pods. After resolving the issue, you can resume the upgrade. | All | v1.20 and later | All | |
You can use mTLS to collect monitoring metrics for applications in the grid. | Service Mesh (ASM) now uses mutual TLS (mTLS) to encrypt monitoring metrics for in-mesh applications, providing the same security as service-to-service communication. | All | All | All | Collect monitoring metrics for in-mesh applications via mTLS |
Enhanced plugin center and Envoy filters |
| All | v1.18 and later | All | |
Declarative management for Envoy filter templates and traffic lanes |
| All | v1.20 and later | All |
January 2024
Feature | Description | Regions | Istio versions | Applicable Specifications | References |
AI-powered mesh diagnostics | Integrates an AI assistant to provide intelligent analysis. After a diagnostic result is generated, a large language model (LLM) explains the cause of each issue and recommends a solution. | All | All | All | |
Enhanced Mesh Topology | The Mesh Topology feature enhances observability and usability.
| All | All | All | |
Support for custom request and response headers | Adds support for customizing request and response headers using VirtualService and EnvoyFilter resources. | All | All | All | |
Scenario-based rate limiting | Introduces best practices for applying rate limiting in the following scenarios:
| All | v1.11.5 and later | Enterprise Edition, Ultimate Edition |
December 2023
Feature | Description | Regions | Istio version | Editions | References |
Released Istio 1.19 and a patch for 1.18. |
| All | All | All | None |
Pay-as-you-go billing for Server Load Balancer | When you create a new Service Mesh (ASM) instance, the system automatically creates a private-facing, pay-as-you-go Server Load Balancer (SLB) instance to access the API Server and the Istio control plane. | All | All | All | |
Support for CEL-based log filtering rules | You can now use Common Expression Language (CEL) to set log filtering rules. In high-traffic scenarios, filtering logs based on specific conditions reduces sidecar proxy overhead and lets you focus on critical log content. | All | v1.18 and later | All | |
Simplified management for local rate limiting | This release enhances the local rate limiting feature. A new graphical interface in the Traffic Management Center simplifies the configuration process, reduces operational errors, and improves usability. | All | v1.18 and later | All |
November 2023
Feature | Description | Regions | Istio version | Supported product specifications | References |
Support for Model Service Mesh | This feature lets you manage and route model services through the mesh. It provides advanced traffic management capabilities, such as A/B testing, and canary releases for granular control over model service traffic. You can also easily switch between model versions and perform a rollback. Dynamic routing routes requests to the appropriate model service based on attributes such as model type, data format, or other metadata. A model service mesh helps developers easily deploy, manage, and scale machine learning models while ensuring high availability, scalability, and flexibility. | All | v1.18 and later | All | |
Standalone deployment for ASM gateways in a Serverless architecture | This feature introduces a Serverless gateway architecture that uses virtual nodes and ECI. This deployment mode is ideal for scenarios that require scalability and node-free operations. | All | v1.18 and later | All | Use an ASM Serverless gateway to improve high availability and elasticity |
The Managed Grid Topology Service lets you attach a Server Load Balancer (CLB). | You can now use a Server Load Balancer (SLB) to directly access applications within a managed mesh topology, which simplifies the topology's access configuration. | All | v1.18 and later | All | |
Support for KServe 0.11 | This release adds support for integration with KServe 0.11, simplifying the management of model service workloads. You can now deploy Transformer services using InferenceService and select the KServe version during integration. | All | v1.18 and later | All | |
Support for OpenTelemetry Collector integration | Service Mesh (ASM) now exports Tracing Analysis data via the OpenTelemetry Collector, which simplifies connecting to ARMS Tracing Analysis or self-managed Tracing Analysis services. Existing Zipkin integrations remain supported. | All | v1.18 and later | All |
October 2023
Feature | Description | Regions | Istio versions | Product specifications | References |
Introduces ASMCompressor, a CRD for configuring compression between application services. | This CRD provides a declarative method to configure compression for calls between application services. It offers a consistent method for adding compression filters to applications and supports both Gzip and Brotli compression algorithms. | All | v1.18 and later | All | |
Introduces ASMGrpcJsonTranscoder, a CRD for configuring JSON/HTTP to gRPC transcoding for inter-service communication. | This CRD enables you to configure JSON/HTTP to gRPC transcoding for calls between application services. It provides a consistent way to add transcoding filters to applications. | All | v1.18 and later | All | |
Enables custom Wasm Plugin for the ASM data plane. | You can configure custom Wasm Plugin for ASM mesh proxies or gateways to extend the capabilities of the data plane. Wasm Plugin can be written in multiple languages, such as C++ and Golang, and can be loaded from various sources, including an HTTP endpoint, an OCI Image Hub, or a ConfigMap. | All | v1.18 and later | All | Use a Coraza Wasm plugin to implement WAF capabilities on an ASM gateway |
Introduces ASMGlobalRateLimiter to enable global rate limiting for gateways and application services. | This CRD provides a declarative method to configure global rate limiting for gateways and application services. | All | v1.18 and later | All |
September 2023
Feature | Description | Regions | Istio version | Editions | References |
Dynamic Subset Load Balancing | This feature provides dynamic subset load balancing, which lets you flexibly select a target service subset based on request information such as | All | v1.18 and later | Enterprise Edition, Ultimate Edition | |
Traffic Lane 2.0 with Support for Strict and Loose Modes | The loose mode includes a fallback mechanism to a baseline traffic lane, which simplifies request handling in scenarios where end-to-end headers are already propagated. | All | v1.18 and later | Enterprise Edition, Ultimate Edition | |
Mesh Topology 2.0 with Managed Mode Support | Compared to enabling Mesh Topology in deployment mode on a data plane Kubernetes cluster, Managed Mode offers significant advantages, including unified multi-cluster observability, simplified configuration, and higher service reliability. | All | v1.18 and later | Enterprise Edition, Ultimate Edition |
August 2023
Feature | Description | Regions | Istio versions | Supported product specifications | References |
Support for a new data plane mode | This release introduces a new data plane mode compatible with the community's Istio Ambient Mesh. This mode enables incremental adoption of service mesh technology, allowing you to use features as needed, including new Layer 4 (L4) and Layer 7 (L7) routing and authorization capabilities. | All | v1.18 and later | Enterprise Edition, Ultimate Edition | |
Istio version 1.18 is now available. | Istio 1.18 is now available and compatible with the latest community features. | All | v1.18 and later | All | None |
Default CNI mode for ASM instance creation | The CNI Plugin mode is now enabled by default when you create a Service Mesh (ASM) instance. This ensures compatibility with the CNI DaemonSet in environments such as ACK on ECI and ACK Serverless. | All | v1.18 and later | All | |
Support for Knative 1.8 | Service Mesh (ASM) v1.18 now uses Knative 1.8 by default when deploying serverless workloads with Knative. | All | v1.18 and later | All | |
ASM gateways are compatible with Network Load Balancer (NLB). | You can now create an ingress gateway with a Network Load Balancer (NLB), leveraging its high performance and auto-scaling capabilities to improve traffic stability. | All | v1.18 and later | All |
July 2023
Feature | Description | Regions | Istio version | Product Specifications | References |
Control plane canary upgrade | Provides a safer and more stable canary upgrade for new control plane versions using a revision- and label-based mode. | All | v1.16 and later | Enterprise Edition, Ultimate Edition | |
Simplified label sync management for global namespaces | This feature lets you associate a global namespace with a specific Kubernetes cluster and selectively sync different namespace labels to different clusters. The ASM console now provides the namespace label | All | v1.16 and later | All | |
Audit alerts for mesh resource operations | After you enable the mesh audit feature, you can configure alerts in Simple Log Service (SLS) for changes to mesh resources to notify an alert contact whenever important resources are modified. | All | v1.15 and later | All | |
Adaptive configuration push for egress gateways | When adaptive configuration push is enabled, the cluster deploys an egress gateway named istio-axds-egressgateway and lets you modify its configuration. | All | v1.15 and later | All | Use adaptive configuration push to improve control plane push efficiency |
External OPA execution engine integration | Compared to the sidecar pattern, an external Open Policy Agent (OPA) execution engine consumes fewer resources, allows applications to be integrated without a restart, and provides more flexibility in deciding which requests execute OPA policies. | All | v1.15 and later | All | Use ASM security policies to connect to an external OPA execution engine |
Gateway log dashboards | A new gateway-level log page lets you view the raw logs and log dashboards for a specific gateway. | All | v1.17 and later | All |
June 2023
Feature | Description | Regions | Applicable Istio versions | Applicable editions | References |
New observability management center 2.0 | Provides integrated configuration for logs, monitoring metrics, and Tracing Analysis. | All | v1.17.2.35 and later | All | |
Support for dynamically merging Istio and application monitoring metrics | Allows application services with Prometheus monitoring endpoints to export their business metrics through the mesh proxy by merging them with Istio metrics. | All | v1.17 and later | All | |
Service Discovery scope configuration supports a blacklist mode for namespaces | In addition to supporting a whitelist mode, this feature allows the ASM control plane to discover and process applications only in namespaces that are not on the blacklist. This improves the efficiency of pushes from the control plane to the Sidecar proxies on the data plane. | All | v1.17 and later | Enterprise Edition, Ultimate Edition | Configure the service discovery scope to improve mesh configuration push efficiency |
Traffic management now supports a fallback mechanism | When a service call fails, a fallback mechanism provides an alternative execution path. Service Mesh (ASM) supports defining a fallback parameter in a VirtualService to enable a fallback mechanism for failed service requests. | All | v1.17 and later | Enterprise Edition, Ultimate Edition | |
Mesh topology now supports login with Resource Access Management (RAM) users and custom access methods | Login with an Alibaba Cloud RAM user is now the default method for accessing the mesh topology UI console. You can also customize access by configuring the domain name, port, root path, and protocol. | All | v1.17 and later | All | |
ASM certificate management can now send anomaly alerts to SLS | You can now configure alerts for certificate management in control plane alerting. This feature supports two alarm metrics: Expired and Expiring Soon. | All | v1.17 and later | All |
May 2023
Feature | Description | Regions | Istio versions | Applicable editions | References |
Istio version 1.17 is now available. | Istio 1.17 is now supported and is compatible with the latest community features. | All | v1.17 and later | All | None |
KServe on ASM enables MLOps for model services. | You can integrate with KServe to simplify managing your model service workloads. | All | v1.17 and later | Enterprise Edition, Ultimate Edition | Integrate ASM with KServe for cloud-native AI model inference services |
The ASM gateway offers a serverless mode. | The ASM Serverless Gateway is a gateway form factor based on virtual nodes and ECI. It is designed for elastic and node-free scenarios. | All | v1.16 and later | Enterprise Edition, Ultimate Edition | Use ASM Serverless Gateways to support elastic business scenarios |
Global certificate management | ASM now supports global certificate management:
| All | v1.17 and later | All | |
Enhanced ASM Mesh Topology for visualizing Istio resources | The ASM Mesh Topology page now includes a "virtual service logo" display option that visualizes configured virtual service resources in the topology. | All | v1.15 and later | Enterprise Edition, Ultimate Edition | |
Exclude specific Namespaces in Mesh Diagnostics | You can now select namespaces to exclude from Mesh Diagnostics. No diagnostic results will be generated for the excluded namespaces. | All | v1.17 and later | All |
April 2023
Feature | Description | Release region | Istio version | Supported product specifications | References |
Istio 1.16 is now available. | Adds compatibility with the Istio 1.16 community release series. | All | v1.16 and later | All | None |
Enhanced sidecar injection management | Simplifies configuration management for injection policies and sidecar injectors. | All | v1.16 and later | All | |
Support for the gRPC-JSON transcoder plugin | Lets you access gRPC services using RESTful APIs or other HTTP/JSON tools, simplifying integration. | All | v1.16 and later | Enterprise Edition, Ultimate Edition | Use ASMGrpcJsonTranscoder to request gRPC services in a mesh using HTTP/JSON |
Support for RAM login to Mesh Topology | Allows you to log on with your Alibaba Cloud Resource Access Management (RAM) identity, enabling single sign-on (SSO) for the Mesh Topology UI. | All | v1.16 and later | Enterprise Edition, Ultimate Edition |
March 2023
Feature | Description | Region | Istio versions | Applicable Specifications | References |
Integration with Web Application Firewall (WAF) |
| All | All | Enterprise Edition, Ultimate Edition | |
Support for Ingress resource configuration | You can now use Ingress resources in a data plane cluster to specify traffic rules for the ASM gateway. | All | v1.16 and later | Enterprise Edition, Ultimate Edition | Use an ASM Gateway as an Ingress controller to expose in-cluster services |
Support for managing Knative services | Integrates the Knative Serving capabilities of ACK and ACK serverless cluster to simplify the management of serverless workloads. | All | v1.16 and later | Enterprise Edition, Ultimate Edition | |
ASM Mesh Topology supports OIDC login | Integrates the OIDC protocol with an identity provider (IdP), allowing you to configure single sign-on (SSO) for ASM Mesh Topology from the ASM console. | All | v1.15.3.120 and later | Enterprise Edition, Ultimate Edition | |
Sidecar proxy supports overcommitment mode | When dynamic resource overcommitment is enabled, you can set the resource type for Proxy Pod. | All | v1.16 and later | Enterprise Edition, Ultimate Edition | |
New egress traffic policy: ASMEgressTrafficPolicy | The ASMEgressTrafficPolicy defines how to manage and access external traffic through an egress gateway. You can combine it with Sidecar and AuthorizationPolicy resources for more comprehensive control over egress traffic. | All | v1.16 and later | Enterprise Edition, Ultimate Edition | |
Support for a global default retry policy for HTTP requests | You can now configure a global default retry policy for HTTP requests, which includes the number of retries, retry timeout, and retry conditions. | All | v1.15 and later | All | None |
February 2023
Feature | Description | Regions | Istio version | Editions | References |
Release of Istio version 1.15.3.105 | Compatible with the community Istio 1.15 series. Supports Kubernetes versions 1.21 to 1.25. | All | v1.15.3.105 | All | None |
Enhanced mesh observability |
| All | All | All | |
You can optimize grid topology performance. |
| All | v1.14 and later | All | |
Enhanced multi-cluster traffic management | Supports configuring in-cluster traffic locality in multi-cluster environments. When this feature is enabled for a service, traffic is directed only to workloads within the same cluster. | All | v1.15.3.101 and later | All | |
Enhanced Sidecar Proxy Configuration |
| All | v1.15.3.101 and later | All | |
Enhanced ASM gateway customization and observability |
| All | All | Enterprise Edition, Ultimate Edition |
January 2023
Feature | Description | Region | Applicable Istio versions | Applicable editions | References |
Custom time ranges in grid topology | Grid Topology now lets you query the topology graph for any time range within the last 90 days, making it easier to view historical topologies. | All | v1.14 and later | All | |
Enhanced configuration parameters for data plane sidecar proxies | A new option lets you configure sidecar proxy environment variables to load a bootstrap configuration before the proxy starts. | All | v1.15.3.63 and later | All | |
Enhanced gateway security capabilities | The gateway now offers a single configuration for both OpenID Connect (OIDC) single sign-on (SSO) and JWT authentication. | All | v1.15.3.25 and later | Enterprise Edition, Ultimate Edition |
Historical release notes
For Service Mesh (ASM) release notes prior to 2023, see Pre-2023 release notes.