Skip to content

chore: upgrade apisix to 3.19.0 - #1018

Merged
shreemaan-abhishek merged 2 commits into
apache:masterfrom
shreemaan-abhishek:chore/upgrade-apisix-3.19.0
Oct 1, 2026
Merged

shreemaan-abhishek merged 2 commits into
apache:masterfrom
shreemaan-abhishek:chore/upgrade-apisix-3.19.0

Conversation

@shreemaan-abhishek

Copy link
Copy Markdown
Contributor

Description

Upgrades the APISIX chart to the newly released APISIX 3.19.0.

  • Chart.yaml: appVersion 3.18.0 -> 3.19.0, chart version 2.17.0 -> 2.18.0
  • values.yaml: image tag 3.18.0-ubuntu -> 3.19.0-ubuntu
  • configmap.yaml: render tls_passthrough on stream_proxy.tcp entries (see below)
  • README.md: regenerated via make helm-docs

apache/apisix:3.19.0-ubuntu is already published on Docker Hub, together with the -debian and -redhat variants, so ct install has an image to pull.

Chart change for a 3.19.0 feature: tls_passthrough

3.19.0 adds TLS passthrough to the stream proxy (#13912), which is configured per TCP listen. The field is new in the config schema for this release:

  tls = {
      type = "boolean",
  },
+ tls_passthrough = {
+     type = "boolean",
+ },

The chart's tcp renderer emitted only addr and tls, so a tls_passthrough key set in service.stream.tcp was silently dropped and the feature could not be reached through the chart. It is now passed through:

service:
  stream:
    enabled: true
    tcp:
      - addr: 9100
        tls_passthrough: true

renders

stream_proxy:
  tcp:
    - addr: 9100
      tls_passthrough: true

and APISIX 3.19.0 turns that into ssl_preread on; on the listen in the generated nginx.conf. Rendering a plain listen produces no ssl_preread, so the value reaches the runtime rather than being accepted and ignored. The plain port-number and tls: true forms are unchanged.

Everything else new in 3.19.0 flows through the existing passthroughs: the new openapi-to-mcp and websocket-proxy plugins are in APISIX's default plugin list, and the mcp-session shared dict is in its default lua_shared_dict set, so apisix.plugins and luaSharedDicts can stay empty.

Verification

  • helm lint charts/apisix passes.
  • helm template renders all three tcp element forms (bare port, tls, tls_passthrough) correctly.
  • The rendered config.yaml was run through apisix init in apache/apisix:3.19.0-debian; it validates and emits ssl_preread on; for the passthrough listen.

Signed-off-by: Abhishek Choudhary <shreemaan.abhishek@gmail.com>
….19.0

# Conflicts:
#	charts/apisix/Chart.yaml
@shreemaan-abhishek
shreemaan-abhishek merged commit c511268 into apache:master Oct 1, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants