Skip to content

Found new managed modules references - #1277

Merged
pkwarren merged 1 commit into
mainfrom
fetch-modules
Jul 15, 2026
Merged

Found new managed modules references#1277
pkwarren merged 1 commit into
mainfrom
fetch-modules

Conversation

@app-token-modules

Copy link
Copy Markdown
Contributor

No description provided.

@app-token-modules
app-token-modules Bot requested a review from a team July 15, 2026 12:29
},
{
"name": "v1.39.0",
"digest": "d05607c7c4ea6f1414960b75e6242310718e6c1efb231d9b669adecf96133b33722b3b383d115cdf2f473cd576cdfa3fe52e8f64c1f01b3745312bcca02f9d9e"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[Posted at 2026-07-15T12:30:01Z]

Intermediate transition

$ casdiff v1.38.3 \
          v1.39.0 \
          --format=markdown
70 files changed: 0 removed, 0 renamed, 14 added, 56 changed content.

70 files changed: 0 removed, 0 renamed, 14 added, 56 changed content.

Files added:

+ shake256:61e28a793bfedd8bbcfed42c001fffb76f0aa35fd7fd61c0e0e5e177c29ecd26847670a4d41ff43771eecc4aaca15e4c80a8613ddb7307f1f7bc1391c3348940  contrib/envoy/extensions/stat_sinks/wasm_filter/v3/wasm_filter.proto
+ shake256:f74a0b92a5967659929425007d2f764e28273cc4be3aa3c99b4f540adf80e828c345f5ccd5c589da3b78015eae2fe05b36f20ce3a8a193700420da536fc92843  envoy/extensions/clusters/original_dst/v3/original_dst.proto
+ shake256:c43598da8f84e03829c2d36480e6261e4a58501e51d5610a15e5d768ca28c783d22aab37042d8c88a2b45a06e8f253c42d93d5cf8b306819c5c29ccda7e774fb  envoy/extensions/filters/http/ai_protocol_manager/v3/ai_protocol_manager.proto
+ shake256:db9db55c4d2edb5feceba20adc04e8b86855a43a271d7aa969a799b1aa66c67a7cc8254cce74beca89d0107276f283629bea58654f5a6678c106ff5ad13e75fd  envoy/extensions/filters/http/bandwidth_share/v3/bandwidth_share.proto
+ shake256:063f069a102d281650aa59e92baabb00fe306de95ff9bf911e96243e91cfe2863f286f225b22b831cd78f3c81ee5bf980811470613298c18f716bc7d7aacb0cf  envoy/extensions/filters/http/filter_chain/v3/filter_chain.proto
+ shake256:c6845d45deee6f291a0e50876d86f32487b77bb8bd6253e86eaa4a05c96d90c1f5998c2f034936a044fc26d1921bbbd1b972256ef1560f74aeaa98febc5e608d  envoy/extensions/filters/udp/udp_proxy/session/ext_authz/v3/ext_authz.proto
+ shake256:580964d7027f1e0437e8e4a050dc4a7c49eb248e39343e21e86ab4c74cf379e437fc54c6db301bfe3a06d00876722dcd7ffe3de041cb065ad16467f066d5eb31  envoy/extensions/formatter/dynamic_modules/v3/dynamic_modules.proto
+ shake256:d2c656b5bc8d53ba7dc07f2ace68f9344154068899d386c2ee304c3504a3fe306ed2dc21d5a63733e31fbf61cee26d3ba042836788132c533cc61c1941edb887  envoy/extensions/health_checkers/dynamic_modules/v3/dynamic_modules.proto
+ shake256:e54c12aff3d669e5d5b5a9237812c9398e708f353c174da18d25bd76df3b4c6aaa82dda151ad927ee8949e77056c0be405b0e554cef74fc5571da76abce3a122  envoy/extensions/load_balancing_policies/load_aware_locality/v3/load_aware_locality.proto
+ shake256:46b90ba66398297fb23b255464df3c9aca2058cc4b25ecec7d843c087a6419cfa83f4278dd00a6ac6ccb2bf946b139f225c591a965532bf366569829f2e824b4  envoy/extensions/network/socket_interface/sockmap/v3/sockmap.proto
+ shake256:207659b40f09a1eb343e4bee976790b87765f57e9af73739ad595610306d4c1793aef067838761e69533a5243c174e5175fdbd9ddf07e2bc432aa3b3df014d60  envoy/extensions/stat_sinks/dynamic_modules/v3/dynamic_modules.proto
+ shake256:d50262cdc4cfa7209865e048fd309455614d591bd62fe394513489dc3b7b5d487e68a4bf65707264c5aa832c65d0b5fec50ad379366ec7ac419625317d735e32  envoy/extensions/transport_sockets/dynamic_modules/v3/dynamic_modules.proto
+ shake256:b000ca7a7fe72709f0a48f1c825618331159235a7a5f13ebaa4f89943a127068d2f4ec7a0f5474be7716ed0f461f6bce47ff29389ce27edfbe936e39a57473c6  envoy/extensions/upstreams/http/reverse_tunnel/v3/reverse_tunnel_codec.proto
+ shake256:9b2484a11c76b5d389f373a68d702953265802c037fbe2c31b15b31c1ea0f5b34fcecfc4b9885a9e52bc6f8f69659f6ba0df0cd15a23681c87757391b3eec752  envoy/type/v3/scope.proto

Files changed content:

contrib/envoy/extensions/filters/network/mysql_proxy/v3/mysql_proxy.proto:

--- shake256:b358663115fc5d273c2fdeae4177ec77e455e830cc5ed529863f229faa531b643ffac3547d974b0675c3da6ab78f71615926c4ec4b2f065bda15fb84fe456ff7  contrib/envoy/extensions/filters/network/mysql_proxy/v3/mysql_proxy.proto
+++ shake256:d74fc2d2b6e5ef353ba218b7860368943977f3f3cc85d6e08773b9e472669d5c2a1fad8c6fc68b972ef0c33b94d72aa3e8c81e5412a57bfc2acfd842c79ea2be  contrib/envoy/extensions/filters/network/mysql_proxy/v3/mysql_proxy.proto
@@ -20,6 +20,29 @@
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.config.filter.network.mysql_proxy.v1alpha1.MySQLProxy";
 
+  // Downstream SSL operational modes.
+  enum SSLMode {
+    // Do not terminate SSL session initiated by a client.
+    // The MySQL proxy filter will pass all encrypted and unencrypted packets to the upstream server.
+    DISABLE = 0;
+
+    // The MySQL proxy filter will terminate SSL session initiated by a client
+    // and close downstream connections that do not initiate SSL.
+    // The filter will mediate ``caching_sha2_password`` RSA authentication when
+    // the upstream MySQL server requires full authentication over the plaintext connection.
+    // The filter chain must use :ref:`starttls transport socket
+    // <envoy_v3_api_msg_extensions.transport_sockets.starttls.v3.StartTlsConfig>`.
+    REQUIRE = 1;
+
+    // The MySQL proxy filter will accept downstream client's encryption settings.
+    // If the client wants to use clear-text, Envoy will not enforce SSL encryption.
+    // If the client wants to use encryption, Envoy will terminate SSL and mediate
+    // ``caching_sha2_password`` RSA authentication when needed.
+    // The filter chain must use :ref:`starttls transport socket
+    // <envoy_v3_api_msg_extensions.transport_sockets.starttls.v3.StartTlsConfig>`.
+    ALLOW = 2;
+  }
+
   // The human readable prefix to use when emitting :ref:`statistics
   // <config_network_filters_mysql_proxy_stats>`.
   string stat_prefix = 1 [(validate.rules).string = {min_len: 1}];
@@ -27,4 +50,10 @@
   // [#not-implemented-hide:] The optional path to use for writing MySQL access logs.
   // If the access log field is empty, access logs will not be written.
   string access_log = 2;
+
+  // Controls whether to terminate SSL sessions initiated by downstream clients.
+  // If enabled, the filter chain must use
+  // :ref:`starttls transport socket <envoy_v3_api_msg_extensions.transport_sockets.starttls.v3.StartTlsConfig>`.
+  // Defaults to ``DISABLE``.
+  SSLMode downstream_ssl = 3;
 }

contrib/envoy/extensions/filters/network/peer_metadata/v3/peer_metadata.proto:

--- shake256:444199d12077c1e966a9fc88c848f327d799bade7320ee83689ae2a8b667ffbc16f3748d4b5b7b166f6cd8a9e7c889fb4bd361c02747425cb2807156a746ba32  contrib/envoy/extensions/filters/network/peer_metadata/v3/peer_metadata.proto
+++ shake256:3890183b72504fb727fa185bf393cebc2eda01972fab6adef56ea9231d7871e4f40fb015fda77888c7f1436485a3324d06dd29f8eb8bfd45c2e96d2fd8823bad  contrib/envoy/extensions/filters/network/peer_metadata/v3/peer_metadata.proto
@@ -1,13 +1,13 @@
 syntax = "proto3";
 
-package envoy.extensions.filters.network.peer_metadata.v3;
+package envoy.extensions.network_filters.peer_metadata;
 
 import "udpa/annotations/status.proto";
 
-option java_package = "io.envoyproxy.envoy.extensions.filters.network.peer_metadata.v3";
+option java_package = "io.envoyproxy.envoy.extensions.network_filters.peer_metadata";
 option java_outer_classname = "PeerMetadataProto";
 option java_multiple_files = true;
-option go_package = "github.com/envoyproxy/go-control-plane/contrib/envoy/extensions/filters/network/peer_metadata/v3;peer_metadatav3";
+option go_package = "github.com/envoyproxy/go-control-plane/contrib/envoy/extensions/network_filters/peer_metadata";
 option (udpa.annotations.file_status).package_version_status = ACTIVE;
 
 // [#protodoc-title: Peer metadata network filter]
@@ -22,9 +22,25 @@
 // response) and injects it as a data preamble to be consumed by the upstream
 // filter.
 message Config {
-  // Filter state key under which the baggage value encoding the proxy workload
-  // is stored. The upstream filter that populates the baggage header in the
-  // HBONE request should use the same key.
+  // What filter state to use to save the baggage value that encodes the proxy
+  // workload.
+  //
+  // The upstream filter that will populate the baggage header in the HBONE
+  // request should be configured to use the same key.
+  //
+  // Why share baggage value via filter state instead of to configure upstream
+  // filter to use the baggage key value directly?
+  //
+  // ztunnel and waypoint have to be aware of the baggage header format,
+  // because they should be able to parse baggage headers to extract the
+  // metadata and report the metrics. However, pilot does not need to be aware
+  // of the baggage encoding yet.
+  //
+  // If instead of using custom filter to generate baggage header value we just
+  // let pilot generate it, it would spread the logic for generating baggage to
+  // the pilot as well. While not a big deal, if there is no clear reason to do
+  // it, let's not duplicate the implementation of baggage logic in pilot and
+  // just re-use the logic we already have in Envoy.
   string baggage_key = 1;
 }
 

envoy/admin/v3/server_info.proto:

--- shake256:a3701b9fe15fd9effbf59c6641ff43a8678fa55cf0a6d00988250078bcc0bfb3455788295a723433c9d9a9e234149104eb0c1fadb260b1cd572537a60ada71ad  envoy/admin/v3/server_info.proto
+++ shake256:dc6f7ace607947a0df1e52d21918c94d74cc7d8e73d70e0bd252809ed4a30e863758885a12bef4b8da54fda8fe6e830e15a05feae849cd9f3786f44af3f89230  envoy/admin/v3/server_info.proto
@@ -62,7 +62,7 @@
   bool hot_restart_initializing = 8;
 }
 
-// [#next-free-field: 43]
+// [#next-free-field: 44]
 message CommandLineOptions {
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.admin.v2alpha.CommandLineOptions";
@@ -197,6 +197,9 @@
   // See :option:`--enable-fine-grain-logging` for details.
   bool enable_fine_grain_logging = 34;
 
+  // See :option:`--log-stacktrace-single-entry` for details.
+  bool log_stacktrace_single_entry = 43;
+
   // See :option:`--socket-path` for details.
   string socket_path = 35;
 

envoy/config/bootstrap/v3/bootstrap.proto:

--- shake256:7beeecf5ab4b590492940618911fa508d71fee4f33d6c787f74cbca2406ff6e1791dfb4a3f118bf447603c6fdfef5e535d0154b8c785d6884e70cba801283c8b  envoy/config/bootstrap/v3/bootstrap.proto
+++ shake256:c924c48805142874035bca256676bbe44f3cc4b100cb95399e38b7a66941264250981e2c44b4f94fcc10ad054dc5301909f0cdd5cc8e1620e7ab5c27fad12585  envoy/config/bootstrap/v3/bootstrap.proto
@@ -42,7 +42,7 @@
 // <config_overview_bootstrap>` for more detail.
 
 // Bootstrap :ref:`configuration overview <config_overview_bootstrap>`.
-// [#next-free-field: 43]
+// [#next-free-field: 44]
 message Bootstrap {
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.config.bootstrap.v2.Bootstrap";
@@ -433,6 +433,17 @@
   // Optional configuration for memory allocation manager.
   // Memory releasing is only supported for `tcmalloc allocator <https://github.com/google/tcmalloc>`_.
   MemoryAllocatorManager memory_allocator_manager = 41;
+
+  // When enabled, Envoy pins each worker thread to a distinct CPU from the process affinity mask,
+  // worker ``i`` to the ``i-th`` CPU in ascending order. This improves CPU cache and ``NUMA``
+  // locality for high concurrency deployments on bare metal. It is available on Linux only and is
+  // ignored on other platforms. Pinning requires a worker count no greater than the number of CPUs
+  // in the process affinity mask. When the worker count exceeds the available CPUs no worker is
+  // pinned. Pinning is applied once when the workers start, so a later change to the process
+  // affinity mask does not re-pin.
+  //
+  // Defaults to ``false``.
+  bool enable_worker_cpu_affinity = 43;
 }
 
 // Administration interface :ref:`operations documentation
@@ -813,3 +824,31 @@
   // Defaults to ``104857600`` (100 MB).
   uint64 max_unfreed_memory_bytes = 5;
 }
+
+// A placeholder proto so that users can explicitly configure the standard
+// Listener Manager via the bootstrap's :ref:`listener_manager <envoy_v3_api_field_config.bootstrap.v3.Bootstrap.listener_manager>`.
+// [#not-implemented-hide:]
+message ListenerManager {
+}
+
+// A placeholder proto so that users can explicitly configure the standard
+// Validation Listener Manager via the bootstrap's :ref:`listener_manager <envoy_v3_api_field_config.bootstrap.v3.Bootstrap.listener_manager>`.
+// [#not-implemented-hide:]
+message ValidationListenerManager {
+}
+
+// A placeholder proto so that users can explicitly configure the API
+// Listener Manager via the bootstrap's :ref:`listener_manager <envoy_v3_api_field_config.bootstrap.v3.Bootstrap.listener_manager>`.
+// [#not-implemented-hide:]
+message ApiListenerManager {
+  enum ThreadingModel {
+    // Handle HTTP requests on the main Envoy thread which also processes platform-raised events and runs xDS clients.
+    MAIN_THREAD_ONLY = 0;
+
+    // Handle HTTP requests on a standalone worker thread.
+    STANDALONE_WORKER_THREAD = 1;
+  }
+
+  // Default to MainThreadOnly.
+  ThreadingModel threading_model = 1;
+}

envoy/config/cluster/v3/circuit_breaker.proto:

--- shake256:10a21c816540ed52d9dd7002be5d269527d7927a5b55acff457c434c996df2ad57355f996157d4e4fdab2d6db7f1a80c5f1ce94115c3b31cdef782b5c7d26b7b  envoy/config/cluster/v3/circuit_breaker.proto
+++ shake256:e4794b2ebf537fcfde40dbcaad11e36438e6bd2795f18912a18a2241b8d3ec75817ff19534b462dee128fb132f0b6a28b0cfce6d00c2cdd246c16e36d083acff  envoy/config/cluster/v3/circuit_breaker.proto
@@ -5,6 +5,7 @@
 import "envoy/config/core/v3/base.proto";
 import "envoy/type/v3/percent.proto";
 
+import "google/protobuf/duration.proto";
 import "google/protobuf/wrappers.proto";
 
 import "udpa/annotations/status.proto";
@@ -43,6 +44,25 @@
       // This parameter is optional. Defaults to 20%.
       type.v3.Percent budget_percent = 1;
 
+      // An optional duration in which requests will be considered when calculating
+      // the budget for retries. This parameter alters the way in which the retry budget
+      // is calculated, overriding the default behavior when specified.
+      //
+      // By default, when budget_interval is set to 0ms, only presently active
+      // and pending requests are considered when calculating the retry budget.
+      //
+      // When a non-zero budget_interval is specified, new requests are
+      // considered for the duration of budget_interval when calculating
+      // the retry budget.
+      //
+      // For example, if 10 requests start at the same time, with a specified budget_interval
+      // of 100ms, all 10 requests will be considered when calculating the retry
+      // budget for the next 100ms, regardless of if they have completed.
+      // All 10 requests will expire after the budget_interval duration.
+      //
+      // This parameter is optional. Defaults to 0ms.
+      google.protobuf.Duration budget_interval = 3;
+
       // Specifies the minimum retry concurrency allowed for the retry budget. The limit on the
       // number of active retries may never go below this number.
       //

envoy/config/core/v3/base.proto:

--- shake256:5e7d0238586f5b9dcb7eb825f7256694e31cd8082ebd27e23ec810b50a414434f31c6ec652e5bd7aff2d4b6f05f665de1ca58852dd9020af4e70cf1551382d7a  envoy/config/core/v3/base.proto
+++ shake256:7c1daeba42d5b6f8bebe7b0a73688653a9833dece0690015566641da0894361405e5cc995807357a411231ca03efb7d8b45f7266bb2e70a65979707ec5895ada  envoy/config/core/v3/base.proto
@@ -269,6 +269,15 @@
   string runtime_key = 3;
 }
 
+// Runtime derived uint64 with a default when not specified.
+message RuntimeUInt64 {
+  // Default value if runtime value is not available.
+  uint64 default_value = 2;
+
+  // Runtime key to get value for comparison. This value is used if defined.
+  string runtime_key = 3;
+}
+
 // Runtime derived percentage with a default when not specified.
 message RuntimePercent {
   // Default value if runtime value is not available.
@@ -493,6 +502,14 @@
 message WatchedDirectory {
   // Directory path to watch.
   string path = 1 [(validate.rules).string = {min_len: 1}];
+
+  // If set to true, the watcher will also subscribe to file modification events
+  // (``IN_MODIFY`` on Linux) in addition to move events (``IN_MOVED_TO``). This allows
+  // in-place file writes to trigger reload callbacks. Use this when the writing process
+  // cannot use atomic rename (e.g. certain secret managers that write certificate files
+  // directly). By default, only move/rename events are watched, which is the safe choice
+  // for atomic updates (e.g. Kubernetes ConfigMap symlink swaps).
+  bool watch_modify = 2;
 }
 
 // Data source consisting of a file, an inline value, or an environment variable.

envoy/config/core/v3/protocol.proto:

--- shake256:2c60031b4a2065e1deffbb622837f2c346202c538ad277891bf9d5f55565526851d0215a9963f797b671e0a45f8008ea801f2c0536bea38d2e3846196bf16ef0  envoy/config/core/v3/protocol.proto
+++ shake256:d4d225758e4e0bf5fabd550a978db6cf54a2f5c5ad071c377a0ed1e1ac45a79a7defe791ebc852d090e9feca7ffe1913a63b263b8e3b30ae370559627fd51462  envoy/config/core/v3/protocol.proto
@@ -284,7 +284,7 @@
   repeated string canonical_suffixes = 5;
 }
 
-// [#next-free-field: 8]
+// [#next-free-field: 9]
 message HttpProtocolOptions {
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.api.v2.core.HttpProtocolOptions";
@@ -338,6 +338,22 @@
   // <envoy_v3_api_field_extensions.filters.network.http_connection_manager.v3.HttpConnectionManager.drain_timeout>`.
   google.protobuf.Duration max_connection_duration = 3;
 
+  // Percentage-based jitter for ``max_connection_duration``. If set, the actual connection duration
+  // limit is extended by a random duration up to ``max_connection_duration * jitter / 100``.
+  // This staggers connection teardowns across time and prevents a thundering-herd of reconnects
+  // when many connections are established at roughly the same time.
+  // This field is ignored if ``max_connection_duration`` is not set. If not set, no jitter is added.
+  //
+  // .. note::
+  //   This field is currently only honored for downstream connections by the HTTP connection
+  //   manager. It is not yet supported for upstream cluster connections.
+  //
+  // This is analogous to
+  // :ref:`max_downstream_connection_duration_jitter_percentage
+  // <envoy_v3_api_field_extensions.filters.network.tcp_proxy.v3.TcpProxy.max_downstream_connection_duration_jitter_percentage>`
+  // in the TCP proxy filter.
+  type.v3.Percent max_connection_duration_jitter = 8;
+
   // The maximum number of headers (request headers if configured on HttpConnectionManager,
   // response headers when configured on a cluster).
   // If unconfigured, the default maximum number of headers allowed is ``100``.
@@ -445,8 +461,8 @@
   // This is a no-op if ``accept_http_10`` is not true.
   string default_host_for_http_10 = 3;
 
-  // Describes how the keys for response headers should be formatted. By default, all header keys
-  // are lower cased.
+  // Describes how the keys for headers encoded by the HTTP/1 codec should be formatted. By
+  // default, all header keys are lower cased.
   HeaderKeyFormat header_key_format = 4;
 
   // Enables trailers for HTTP/1. By default the HTTP/1 codec drops proxied trailers.
@@ -552,7 +568,7 @@
       [(validate.rules).duration = {gte {nanos: 1000000}}];
 }
 
-// [#next-free-field: 21]
+// [#next-free-field: 23]
 message Http2ProtocolOptions {
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.api.v2.core.Http2ProtocolOptions";
@@ -669,7 +685,7 @@
   // the connection is terminated. For downstream connections the ``opened_streams`` is incremented when
   // Envoy receives complete response headers from the upstream server. For upstream connections the
   // ``opened_streams`` is incremented when Envoy sends the ``HEADERS`` frame for a new stream. The
-  // ``http2.inbound_priority_frames_flood`` stat tracks the number of connections terminated due to
+  // ``http2.inbound_window_update_frames_flood`` stat tracks the number of connections terminated due to
   // flood mitigation. The default ``max_inbound_window_update_frames_per_data_frame_sent`` value is ``10``.
   // Setting this to ``1`` should be enough to support HTTP/2 implementations with basic flow control,
   // but more complex implementations that try to estimate available bandwidth require at least ``2``.
@@ -791,6 +807,26 @@
   // From RFC 9110, https://www.rfc-editor.org/rfc/rfc9110.html#section-5.5:
   // obs-text = %x80-FF
   google.protobuf.BoolValue disallow_obs_text = 20;
+
+  // Configures the initial token count for the RST_STREAM rate limiter used by the ``nghttp2``
+  // server-side connection. This uses a token-bucket algorithm where each received RST_STREAM
+  // frame consumes one token, and tokens are replenished at :ref:`stream_reset_rate
+  // <envoy_v3_api_field_config.core.v3.Http2ProtocolOptions.stream_reset_rate>` per second.
+  // When no tokens remain, ``nghttp2`` sends GOAWAY with ``INTERNAL_ERROR`` to close the
+  // connection, protecting against CVE-2023-44487 (HTTP/2 Rapid Reset). Defaults to ``1000``.
+  //
+  // This option only applies when using ``nghttp2`` as a server. It has no effect on ``oghttp2``
+  // or on client-side connections.
+  google.protobuf.UInt64Value stream_reset_burst = 21;
+
+  // Configures the token replenishment rate (tokens per second) for the RST_STREAM rate limiter
+  // used by the ``nghttp2`` server-side connection. See :ref:`stream_reset_burst
+  // <envoy_v3_api_field_config.core.v3.Http2ProtocolOptions.stream_reset_burst>` for details.
+  // Defaults to ``33``.
+  //
+  // This option only applies when using ``nghttp2`` as a server. It has no effect on ``oghttp2``
+  // or on client-side connections.
+  google.protobuf.UInt64Value stream_reset_rate = 22;
 }
 
 // [#not-implemented-hide:]

envoy/config/endpoint/v3/endpoint_components.proto:

--- shake256:303fb1667359e27d6ec2aece183975387269521eaf32a9092183560a0cfb88c72976ad820c8d3c2dedbdb1821ad3bf90ed231d827343295779098a0905026cfc  envoy/config/endpoint/v3/endpoint_components.proto
+++ shake256:3cd151cf7e10fa2af3d6e7eb3f71df6d937702975ddece19c5f28e2786fbb355dce33ec25bf3f6f4f7c373f99a41f784ca682a9d6fa1860cea0febc64e916a89  envoy/config/endpoint/v3/endpoint_components.proto
@@ -25,6 +25,7 @@
 // [#protodoc-title: Endpoints]
 
 // Upstream host identifier.
+// [#next-free-field: 6]
 message Endpoint {
   option (udpa.annotations.versioning).previous_message_type = "envoy.api.v2.endpoint.Endpoint";
 
@@ -97,6 +98,20 @@
   // sorted by preference order of the addresses. This will only be supported
   // for STATIC and EDS clusters.
   repeated AdditionalAddress additional_addresses = 4;
+
+  // Optional alternative stat name for this endpoint. If not specified, the main address will be used
+  // as the stat name and be extracted as ``envoy.endpoint_address`` tag value in generated stats.
+  // If specified, the ``observability_name`` here will be used to replace the main address.
+  //
+  // .. note::
+  //
+  //   This field is ignored for logical DNS host implementation..
+  //
+  // This is useful when there are duplicate addresses in the cluster, for example when multiple
+  // endpoints share the same address but have different hostnames or metadata.
+  // In this case, the observability name can be used to differentiate between these endpoints in
+  // stats and logs.
+  string observability_name = 5;
 }
 
 // An Endpoint that Envoy can route traffic to.
@@ -139,7 +154,7 @@
 // LbEndpoint list collection. Entries are `LbEndpoint` resources or references.
 // [#not-implemented-hide:]
 message LbEndpointCollection {
-  xds.core.v3.CollectionEntry entries = 1;
+  repeated xds.core.v3.CollectionEntry entries = 1;
 }
 
 // A configuration for an LEDS collection.

envoy/config/listener/v3/listener.proto:

--- shake256:4e49a60a1817f384d5bedf2b91727b267d5543d4cf3f068ab67fa9dc4a35d946b48a1c504604ecf7452801c94b3698c804b67ad075827d30e6005861799fd12c  envoy/config/listener/v3/listener.proto
+++ shake256:8fcdd4fadff652872bc3cd0330cb7811e0b00b481f61ddb37957da05fdba17857f46ab83d350fe11cb88f17b8f7cf656bed0178f212496368adae23c6f6eede3  envoy/config/listener/v3/listener.proto
@@ -106,6 +106,29 @@
           "envoy.api.v2.Listener.ConnectionBalanceConfig.ExactBalance";
     }
 
+    // A connection balancer that steers each new TCP connection to the worker thread pinned to the
+    // CPU that received the connection, using a kernel ``SO_REUSEPORT`` BPF program. This removes
+    // the lock that the :ref:`exact balancer
+    // <envoy_v3_api_msg_config.listener.v3.Listener.ConnectionBalanceConfig.ExactBalance>` takes on
+    // every accept and keeps each connection on a single worker for cache and ``NUMA`` locality. To
+    // realize locality the operator should align ``NIC`` receive steering so connections arrive on
+    // the worker CPUs, for example with receive side scaling or ``IRQ`` affinity.
+    //
+    // It is available on Linux only and requires :ref:`enable_worker_cpu_affinity
+    // <envoy_v3_api_field_config.bootstrap.v3.Bootstrap.enable_worker_cpu_affinity>` so worker ``i``
+    // is pinned to the CPU the program steers to it, :ref:`enable_reuse_port
+    // <envoy_v3_api_field_config.listener.v3.Listener.enable_reuse_port>`, a kernel that supports
+    // reuse port BPF steering, and a worker count no greater than the number of CPUs in the process
+    // affinity mask. When any of these is not met, or if the kernel rejects the steering program at
+    // runtime, the listener keeps serving with the kernel default reuse port hashing and without CPU
+    // locality.
+    //
+    // Worker affinity is fixed when the worker threads start, so a listener added dynamically via LDS
+    // steers with the same mapping. During a hot restart new connections may be steered to the
+    // draining parent process until it exits.
+    message CpuLocalityBalance {
+    }
+
     oneof balance_type {
       option (validate.required) = true;
 
@@ -118,6 +141,12 @@
       // because the only registered member (``envoy.network.connection_balance.dlb``)
       // is disabled. See https://github.com/envoyproxy/envoy/issues/45491.
       core.v3.TypedExtensionConfig extend_balance = 2;
+
+      // If specified, the listener will steer new connections to worker threads using a kernel
+      // ``SO_REUSEPORT`` BPF program. See :ref:`CpuLocalityBalance
+      // <envoy_v3_api_msg_config.listener.v3.Listener.ConnectionBalanceConfig.CpuLocalityBalance>`
+      // for the requirements and fallback behavior.
+      CpuLocalityBalance cpu_locality_balance = 3;
     }
   }
 
@@ -450,21 +479,3 @@
   // to explicitly configure TCP keepalive settings for individual additional addresses.
   core.v3.TcpKeepalive tcp_keepalive = 37;
 }
-
-// A placeholder proto so that users can explicitly configure the standard
-// Listener Manager via the bootstrap's :ref:`listener_manager <envoy_v3_api_field_config.bootstrap.v3.Bootstrap.listener_manager>`.
-// [#not-implemented-hide:]
-message ListenerManager {
-}
-
-// A placeholder proto so that users can explicitly configure the standard
-// Validation Listener Manager via the bootstrap's :ref:`listener_manager <envoy_v3_api_field_config.bootstrap.v3.Bootstrap.listener_manager>`.
-// [#not-implemented-hide:]
-message ValidationListenerManager {
-}
-
-// A placeholder proto so that users can explicitly configure the API
-// Listener Manager via the bootstrap's :ref:`listener_manager <envoy_v3_api_field_config.bootstrap.v3.Bootstrap.listener_manager>`.
-// [#not-implemented-hide:]
-message ApiListenerManager {
-}

envoy/config/metrics/v3/stats.proto:

--- shake256:56d8ee2a04129ea5371264bb7dc739ee4d45d1cb87be72d92e5e54cee26576222fd08d38538b750ce610516e2abd4c2b0a98e14d55ef73cfdf0b823adc7befcb  envoy/config/metrics/v3/stats.proto
+++ shake256:600bf979d68f259c4c3c7c9f75d0d61641735068b506e4fdb0de466226904a3dac12f57cca2907bdaab8f08d6584608222caa9d9d192c40e9de726b0e7bfb4ea  envoy/config/metrics/v3/stats.proto
@@ -44,6 +44,7 @@
 }
 
 // Statistics configuration such as tagging.
+// [#next-free-field: 6]
 message StatsConfig {
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.config.metrics.v2.StatsConfig";
@@ -104,6 +105,19 @@
   //       3600000
   //     ]
   repeated HistogramBucketSettings histogram_bucket_settings = 4;
+
+  // When set to ``true``, tag extractors specified in :ref:`stats_tags
+  // <envoy_v3_api_field_config.metrics.v3.StatsConfig.stats_tags>` take precedence over the built-in
+  // default tag extractors that share the same ``tag_name``, instead of the default taking
+  // precedence. This allows overriding individual default Envoy tags (for example
+  // ``envoy.cluster_name``) while keeping :ref:`use_all_default_tags
+  // <envoy_v3_api_field_config.metrics.v3.StatsConfig.use_all_default_tags>` enabled, so it is not
+  // necessary to disable all defaults and re-declare every extractor.
+  //
+  // Has no effect when ``use_all_default_tags`` is ``false`` (no default extractors are added in
+  // that case). If not provided, the value is assumed to be false, preserving existing behavior
+  // where the default extractor takes precedence over custom extractors with the same ``tag_name``.
+  google.protobuf.BoolValue allow_default_tag_overrides = 5;
 }
 
 // Configuration for disabling stat instantiation.

envoy/config/route/v3/route_components.proto:

--- shake256:68bd8402344e4157b5cde959d3885e9c1172bba59dfa368bcdfbeff75f5f6fb1fa20c9fdf98c565def281c62284ae7da723fdc65a93ec510e7a286c0ec744189  envoy/config/route/v3/route_components.proto
+++ shake256:4c06a04c3d3885fa814d499cad8097eac67e1844f2c8e3985c24aa21b99d55851bd7d9e273c18536101f3b7df3064ad87027d77328a36793f75acbdfef4596b7  envoy/config/route/v3/route_components.proto
@@ -16,6 +16,7 @@
 import "envoy/type/tracing/v3/custom_tag.proto";
 import "envoy/type/v3/percent.proto";
 import "envoy/type/v3/range.proto";
+import "envoy/type/v3/ratelimit_unit.proto";
 
 import "google/protobuf/any.proto";
 import "google/protobuf/duration.proto";
@@ -1564,7 +1565,7 @@
 }
 
 // HTTP retry :ref:`architecture overview <arch_overview_http_routing_retry>`.
-// [#next-free-field: 14]
+// [#next-free-field: 15]
 message RetryPolicy {
   option (udpa.annotations.versioning).previous_message_type = "envoy.api.v2.route.RetryPolicy";
 
@@ -1788,6 +1789,18 @@
 
   // HTTP headers which must be present in the request for retries to be attempted.
   repeated HeaderMatcher retriable_request_headers = 10;
+
+  // By default, the target upstream cluster of a retry request is the same as the original request,
+  // and Envoy will not try to refresh it when retrying.
+  // If this field is set to true, Envoy will try to refresh the target upstream cluster when
+  // retrying a request. This is useful when users want to try different upstream cluster for
+  // each retry attempt.
+  //
+  // .. note::
+  //   This currently works when the route cluster specifier support the dynamic refresh,
+  //   e.g. :ref:`matcher cluster specifier
+  //   <envoy_v3_api_msg_extensions.router.cluster_specifiers.matcher.v3.MatcherClusterSpecifier>`.
+  bool refresh_cluster_on_retry = 14;
 }
 
 // HTTP request hedging :ref:`architecture overview <arch_overview_http_routing_hedging>`.
@@ -1826,7 +1839,7 @@
   bool hedge_on_per_try_timeout = 3;
 }
 
-// [#next-free-field: 10]
+// [#next-free-field: 11]
 message RedirectAction {
   option (udpa.annotations.versioning).previous_message_type = "envoy.api.v2.route.RedirectAction";
 
@@ -1922,6 +1935,21 @@
     //   would do a case-insensitive match and transform path ``/aaa/XxX/bbb`` to
     //   ``/aaa/yyy/bbb``.
     type.matcher.v3.RegexMatchAndSubstitute regex_rewrite = 9;
+
+    // The path portion of the URL will be set to this value and supports
+    // :ref:`substitution format specifiers <config_access_log_format>` and CEL
+    // expressions.
+    //
+    // For example, with the following config:
+    //
+    // .. code-block:: yaml
+    //
+    //   path_rewrite: "/new/%REQ(x-version)%"
+    //
+    // Would redirect to ``/new/v2`` given a request header ``x-version: v2``.
+    // If the substitution produces an empty string the path redirect is ignored
+    // and the original path is preserved.
+    string path_rewrite = 10;
   }
 
   // The HTTP status code to use in the redirect response. The default response
@@ -2612,11 +2640,23 @@
       type.metadata.v3.MetadataKey metadata_key = 1 [(validate.rules).message = {required: true}];
     }
 
+    // Rate limit to apply to this descriptor.
+    message RateLimitOverride {
+      // The number of requests per unit of time.
+      uint32 requests_per_unit = 1;
+
+      // The unit of time.
+      type.v3.RateLimitUnit unit = 2;
+    }
+
     oneof override_specifier {
       option (validate.required) = true;
 
       // Limit override from dynamic metadata.
       DynamicMetadata dynamic_metadata = 1;
+
+      // Static limit override.
+      RateLimitOverride rate_limit = 2;
     }
   }
 
@@ -2688,9 +2728,13 @@
   // <config_http_filters_rate_limit_rate_limit_override>` for more information.
   //
   // .. note::
-  //   This is not supported if the rate limit action is configured in the ``typed_per_filter_config`` like
-  //   :ref:`VirtualHost.typed_per_filter_config<envoy_v3_api_field_config.route.v3.VirtualHost.typed_per_filter_config>` or
-  //   :ref:`Route.typed_per_filter_config<envoy_v3_api_field_config.route.v3.Route.typed_per_filter_config>`, etc.
+  //   For the global HTTP :ref:`rate limit filter
+  //   <config_http_filters_rate_limit>`, this is supported both at the route/virtual host
+  //   level and when the rate limit configuration is supplied via the filter's
+  //   ``rate_limits`` field or the ``typed_per_filter_config``
+  //   (:ref:`RateLimitPerRoute <envoy_v3_api_msg_extensions.filters.http.ratelimit.v3.RateLimitPerRoute>`).
+  //   This is not supported by the :ref:`local rate limit filter
+  //   <config_http_filters_local_rate_limit>`.
   Override limit = 4;
 
   // An optional hits addend to be appended to the descriptor produced by this rate limit

envoy/config/tap/v3/common.proto:

--- shake256:9c87eab6e7c8b5285888a411d17ac8325dce79b086da2ec31ba0ad1c1df5d9d37b3fc81fd4eb02d6b2b05051b189ea07e764463fb09c3c9e28473b931349a610  envoy/config/tap/v3/common.proto
+++ shake256:18885472ac3b8f9f067d9bfbdfb1cf351d68cf438a34cd2bcf857f16d475033c8180acc1df0910f16ca78318c7bde6efa4b44059bdb52f24d42b7c1cee5c229f  envoy/config/tap/v3/common.proto
@@ -50,14 +50,16 @@
   // a tap will occur and the data will be written to the configured output.
   OutputConfig output_config = 2 [(validate.rules).message = {required: true}];
 
-  // [#not-implemented-hide:] Specify if Tap matching is enabled. The % of requests\connections for
-  // which the tap matching is enabled. When not enabled, the request\connection will not be
-  // recorded.
-  //
-  // .. note::
-  //
-  //   This field defaults to 100/:ref:`HUNDRED
-  //   <envoy_v3_api_enum_type.v3.FractionalPercent.DenominatorType>`.
+  // Specifies the fraction of requests (HTTP tap filter) or connections (transport
+  // socket tap) for which the tap match predicate is evaluated. When unset, every
+  // request/connection proceeds to match evaluation (equivalent to sampling at 100%),
+  // the runtime layer is not consulted, and ``configured_sample_rate`` is not set on
+  // emitted traces. When set, only the configured fraction is matched; the remainder
+  // is not tapped. The value can be overridden at runtime via :ref:`runtime_key
+  // <envoy_v3_api_field_config.core.v3.RuntimeFractionalPercent.runtime_key>`. The
+  // configured sampling rate is recorded on the :ref:`configured_sample_rate
+  // <envoy_v3_api_field_data.tap.v3.TraceWrapper.configured_sample_rate>` of the
+  // first segment of each emitted trace.
   core.v3.RuntimeFractionalPercent tap_enabled = 3;
 }
 

envoy/config/trace/v3/opentelemetry.proto:

--- shake256:b0a3d03c1139ce606c267a6fc1cf4a46a5d60029c99fa9740b516357cf771742ba6463099df5cd6cc671d55c58ae01fb17bd6fa2b3a61e8fd244c7f8bf340926  envoy/config/trace/v3/opentelemetry.proto
+++ shake256:8e0324e178d7561d08e816cdd67afb981b2b68228a878957657bde04fa66fc6b065368cc37be30bbd2171e5d1fa4cdab19a7d0b73d579bb43329373316ee2bda  envoy/config/trace/v3/opentelemetry.proto
@@ -21,7 +21,7 @@
 
 // Configuration for the OpenTelemetry tracer.
 //  [#extension: envoy.tracers.opentelemetry]
-// [#next-free-field: 7]
+// [#next-free-field: 9]
 message OpenTelemetryConfig {
   // The upstream gRPC cluster that will receive OTLP traces.
   // Note that the tracer drops traces if the server does not read data fast enough.
@@ -62,4 +62,18 @@
   // This field specifies the maximum number of spans that can be cached. If not specified, the
   // default is 1024.
   google.protobuf.UInt32Value max_cache_size = 6;
+
+  // Specifies whether to set the telemetry SDK resource attributes.
+  // The following attributes will be set:
+  //
+  // - telemetry.sdk.language
+  // - telemetry.sdk.name
+  // - telemetry.sdk.version
+  //
+  // If not specified, the default is to set these attributes.
+  google.protobuf.BoolValue set_telemetry_sdk_resource_attributes = 7;
+
+  // Specifies whether to set the ``service.name`` resource attribute.
+  // If not specified, the default is to set this attribute.
+  google.protobuf.BoolValue set_service_name_resource_attribute = 8;
 }

envoy/data/core/v3/health_check_event.proto:

--- shake256:5074d5c9185ae449c6d77e0cbf47b96a8d6f16c693196e1cce340dfeeb78efe9e49a8244d06097aa1c473d6db063d2dec759eacebe84e80d757794d53c36f6f7  envoy/data/core/v3/health_check_event.proto
+++ shake256:52a273d10476cf55e56112ff343c5c91a644f232ec677a9437ae0a54e392455580bbff0912e2cef39f1692af08740f309cea6019f29dcc61a6b54f2c7048ccd7  envoy/data/core/v3/health_check_event.proto
@@ -33,6 +33,7 @@
   GRPC = 2;
   REDIS = 3;
   THRIFT = 4;
+  DYNAMIC_MODULE = 5;
 }
 
 // [#next-free-field: 13]
@@ -87,6 +88,12 @@
 
   // The type of failure that caused this ejection.
   HealthCheckFailureType failure_type = 1 [(validate.rules).enum = {defined_only: true}];
+
+  // HTTP status code observed on the response associated with the failure.
+  // Only set when the health checker type is HTTP and the failure type is ``ACTIVE``.
+  // A value of ``0`` indicates that no HTTP status code was recorded (e.g., network-level failures
+  // or non-HTTP health checkers).
+  uint32 http_status_code = 2;
 }
 
 message HealthCheckAddHealthy {
@@ -111,6 +118,12 @@
 
   // Whether this event is the result of the first ever health check on a host.
   bool first_check = 2;
+
+  // HTTP status code observed on the response associated with the failure.
+  // Only set when the health checker type is HTTP and the failure type is ``ACTIVE``.
+  // A value of ``0`` indicates that no HTTP status code was recorded (e.g., network-level failures
+  // or non-HTTP health checkers).
+  uint32 http_status_code = 3;
 }
 
 message DegradedHealthyHost {

envoy/data/tap/v3/wrapper.proto:

--- shake256:06a9c81be98880bf743fdc7bad0cfbadad1bd333d89c88364ebe24deeaf2287c33be918618f2dfe9cafa31bd85a0e82a1f5c834d0d13ca285835813aeae7ab9a  envoy/data/tap/v3/wrapper.proto
+++ shake256:8a9f3822651191945c1fd06a15c1eea8952db7ae45c9c0302dc77a47397031bbfe4670eba6d2a10c394025f671310aaaceee562f82927518ef0ed289f48237a4  envoy/data/tap/v3/wrapper.proto
@@ -4,6 +4,7 @@
 
 import "envoy/data/tap/v3/http.proto";
 import "envoy/data/tap/v3/transport.proto";
+import "envoy/type/v3/percent.proto";
 
 import "udpa/annotations/status.proto";
 import "udpa/annotations/versioning.proto";
@@ -19,6 +20,7 @@
 
 // Wrapper for all fully buffered and streamed tap traces that Envoy emits. This is required for
 // sending traces over gRPC APIs or more easily persisting binary messages to files.
+// [#next-free-field: 6]
 message TraceWrapper {
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.data.tap.v2alpha.TraceWrapper";
@@ -38,4 +40,23 @@
     // A socket streamed tap trace segment.
     SocketStreamedTraceSegment socket_streamed_trace_segment = 4;
   }
+
+  // The configured sample rate at the time this trace was admitted, sourced from the
+  // :ref:`default_value
+  // <envoy_v3_api_field_config.core.v3.RuntimeFractionalPercent.default_value>` of
+  // :ref:`tap_enabled <envoy_v3_api_field_config.tap.v3.TapConfig.tap_enabled>`. For
+  // buffered output (where each ``TraceWrapper`` carries a complete trace) the rate is
+  // always present when sampling is configured. For streamed output (where a trace is
+  // split across multiple ``TraceWrapper`` segments) the rate is set on the first
+  // emitted segment only; subsequent segments belonging to the same trace can be
+  // joined to it via the ``trace_id`` carried on each inner segment message. Absent
+  // when sampling is unconfigured.
+  //
+  // .. note::
+  //
+  //   When :ref:`runtime_key
+  //   <envoy_v3_api_field_config.core.v3.RuntimeFractionalPercent.runtime_key>` is
+  //   configured and an active runtime override is in effect, the effective sampling
+  //   rate that admitted the trace may differ from the recorded configured value.
+  type.v3.FractionalPercent configured_sample_rate = 5;
 }

envoy/extensions/access_loggers/stats/v3/stats.proto:

--- shake256:4a626fd11ed77f856584896d8c115d939ce7621d4cd2c1ebb66fc308b31d4641dd38eaab9d9d1e2b91625309bf9dcf50ab15dd9b2db4c7bcbb9eae73a91d9742  envoy/extensions/access_loggers/stats/v3/stats.proto
+++ shake256:691cf9ccc683d388606ca10cb0d457c4bf41a732f8f95cfe71327dd452afc2606c0b31ef095561fe9520173a9fa3392d631b62d0ffc15c7b4e2d04e467d2d455  envoy/extensions/access_loggers/stats/v3/stats.proto
@@ -3,11 +3,13 @@
 package envoy.extensions.access_loggers.stats.v3;
 
 import "envoy/data/accesslog/v3/accesslog.proto";
+import "envoy/type/v3/scope.proto";
 
 import "google/protobuf/wrappers.proto";
 
 import "xds/type/matcher/v3/matcher.proto";
 
+import "envoy/annotations/deprecation.proto";
 import "udpa/annotations/status.proto";
 import "validate/validate.proto";
 
@@ -29,7 +31,7 @@
 //   leading to a denial of service in Envoy, or can overwhelm any configured
 //   stat sinks by sending too many unique metrics.
 
-// [#next-free-field: 6]
+// [#next-free-field: 7]
 message Config {
   // Defines a tag on a stat.
   message Tag {
@@ -153,7 +155,13 @@
   }
 
   // The stat prefix for the generated stats.
-  string stat_prefix = 1 [(validate.rules).string = {min_len: 1}];
+  // Deprecated: please use ``stats_scope.prefix`` instead.
+  // It will override ``stats_scope.prefix`` if non-empty.
+  string stat_prefix = 1
+      [deprecated = true, (envoy.annotations.deprecated_at_minor_version) = "3.0"];
+
+  // Configuration for stats scope limits and sharing.
+  type.v3.Scope stats_scope = 6;
 
   // The histograms this logger will emit.
   repeated Histogram histograms = 3;

envoy/extensions/bootstrap/reverse_tunnel/downstream_socket_interface/v3/downstream_reverse_connection_socket_interface.proto:

--- shake256:660c22324d1b891b24b011b8794f39d1d6d4f1524f947b128472fc55d67aa42b6672de926e3bb5936d86fbf0a8c0e07c86f9db58d73c86b702b5040cc7975e0c  envoy/extensions/bootstrap/reverse_tunnel/downstream_socket_interface/v3/downstream_reverse_connection_socket_interface.proto
+++ shake256:4d6c09554d3b68490a77d8095e475fa647624f37a2ac97f4f3c2f03ad3942a1fc96dfe8f459a87fd472a60ed07c386f0e235ae32be18ba8e34bc0c005e46829d  envoy/extensions/bootstrap/reverse_tunnel/downstream_socket_interface/v3/downstream_reverse_connection_socket_interface.proto
@@ -2,9 +2,14 @@
 
 package envoy.extensions.bootstrap.reverse_tunnel.downstream_socket_interface.v3;
 
+import "envoy/config/accesslog/v3/accesslog.proto";
 import "envoy/config/core/v3/base.proto";
+import "envoy/config/core/v3/extension.proto";
+
+import "google/protobuf/duration.proto";
 
 import "udpa/annotations/status.proto";
+import "validate/validate.proto";
 
 option java_package = "io.envoyproxy.envoy.extensions.bootstrap.reverse_tunnel.downstream_socket_interface.v3";
 option java_outer_classname = "DownstreamReverseConnectionSocketInterfaceProto";
@@ -18,6 +23,7 @@
 // Configuration for the downstream reverse connection socket interface.
 // This interface initiates reverse connections to upstream Envoys and provides
 // them as socket connections for downstream requests.
+// [#next-free-field: 6]
 message DownstreamReverseConnectionSocketInterface {
   // HTTP handshake settings for initiator envoy initiated reverse tunnels.
   message HttpHandshakeConfig {
@@ -27,6 +33,18 @@
 
     // Additional headers to include in the HTTP handshake request.
     repeated config.core.v3.HeaderValueOption additional_headers = 2;
+
+    // Perform the handshake as an HTTP/1.1 ``Upgrade`` exchange (``Upgrade: reverse-tunnel``,
+    // success on ``101``) so HTTP proxies can route the handshake and splice the tunnel
+    // afterward. The responder must set this flag to the same value.
+    // Defaults to ``false``.
+    bool use_http_upgrade = 3;
+
+    // Formatter extensions usable in ``additional_headers`` substitution. See the formatter
+    // extensions documentation for details. When set, ``additional_headers`` values are evaluated
+    // as substitution format strings; when empty, the values are sent literally.
+    // [#extension-category: envoy.formatter]
+    repeated config.core.v3.TypedExtensionConfig formatters = 4;
   }
 
   // Stat prefix to be used for downstream reverse connection socket interface stats.
@@ -40,4 +58,16 @@
   // Optional HTTP handshake configuration. When unset, the initiator envoy uses the defaults
   // provided by ``HttpHandshakeConfig``.
   HttpHandshakeConfig http_handshake = 3;
+
+  // Access log configuration for reverse tunnel initiator lifecycle events.
+  // Logs are emitted on handshake success, handshake failure, and connection close.
+  // Reverse tunnel metadata (``node_id``, ``cluster_id``, ``tenant_id``, upstream cluster, etc.)
+  // is available via ``%DYNAMIC_METADATA(envoy.reverse_tunnel.initiator:*)%`` substitutions.
+  repeated config.accesslog.v3.AccessLog access_log = 4;
+
+  // Upper bound on the per-host reconnect backoff. The initiator retries a failed handshake on a
+  // deterministic exponential schedule (1s, 2s, 4s, ...) with small upward jitter; this value caps
+  // that schedule.
+  google.protobuf.Duration max_reconnect_backoff = 5
+      [(validate.rules).duration = {gte {seconds: 1}}];
 }

envoy/extensions/bootstrap/reverse_tunnel/upstream_socket_interface/v3/upstream_reverse_connection_socket_interface.proto:

--- shake256:edc29f12ce800836aae0709201e19349a88375d8beeb35cd872414892d7fd12b2d2eae8faf1ac5dfac18110c4d0702e453f385d254fc76a60e2d3cccb637d4dc  envoy/extensions/bootstrap/reverse_tunnel/upstream_socket_interface/v3/upstream_reverse_connection_socket_interface.proto
+++ shake256:1469c987be8ca76f78498d29ce240aa40904695fcceb0d9b3d865044339f0f2973b168107285746c82050f8f222944419c5428553fd33e6d0d2e12dcec634b4b  envoy/extensions/bootstrap/reverse_tunnel/upstream_socket_interface/v3/upstream_reverse_connection_socket_interface.proto
@@ -2,6 +2,7 @@
 
 package envoy.extensions.bootstrap.reverse_tunnel.upstream_socket_interface.v3;
 
+import "envoy/config/accesslog/v3/accesslog.proto";
 import "envoy/config/core/v3/extension.proto";
 
 import "google/protobuf/wrappers.proto";
@@ -19,7 +20,7 @@
 // [#extension: envoy.bootstrap.reverse_tunnel.upstream_socket_interface]
 
 // Configuration for the upstream reverse connection socket interface.
-// [#next-free-field: 6]
+// [#next-free-field: 7]
 message UpstreamReverseConnectionSocketInterface {
   // Stat prefix for upstream reverse connection socket interface stats.
   string stat_prefix = 1;
@@ -44,4 +45,8 @@
   // containing the ``:`` delimiter are rejected to avoid ambiguity.
   // Defaults to ``false`` for backwards compatibility.
   google.protobuf.BoolValue enable_tenant_isolation = 5;
+
+  // Access logs emitted for reverse tunnel lifecycle events. Entries are generated for tunnel setup,
+  // socket handoff, tunnel close, and post-handoff HTTP/2 keepalive timeout observations.
+  repeated config.accesslog.v3.AccessLog access_log = 6;
 }

envoy/extensions/clusters/dns/v3/dns_cluster.proto:

--- shake256:b8474a002d72c2f26c487b3f7ff34c9d28dede1ae5deebca5bca92acdc82e3eb084a31405538e2210f87d882cc4cedc05abe0a337497ff6dc211e65c16dcf02a  envoy/extensions/clusters/dns/v3/dns_cluster.proto
+++ shake256:080f22dafbd2abb52d544b56a18619ca3123bf9f280acc1d838427c65fb844747f5208f09a5dc3ef487454c8306a30be1e31afbf03f0a6c083629f3bd70843aa  envoy/extensions/clusters/dns/v3/dns_cluster.proto
@@ -21,7 +21,7 @@
 // Configuration for DNS discovery clusters.
 // [#extension: envoy.clusters.dns]
 
-// [#next-free-field: 10]
+// [#next-free-field: 11]
 message DnsCluster {
   message RefreshRate {
     // Specifies the base interval between refreshes. This parameter is required and must be greater
@@ -89,4 +89,12 @@
   // semantics. Otherwise, each address is considered to be a separate endpoint, which maps to
   // :ref:`strict DNS discovery <arch_overview_service_discovery_types_strict_dns>` semantics.
   bool all_addresses_in_single_endpoint = 9;
+
+  // When :ref:`respect_dns_ttl <envoy_v3_api_field_extensions.clusters.dns.v3.DnsCluster.respect_dns_ttl>`
+  // is enabled, this field specifies a minimum value for the TTL-derived DNS refresh rate.
+  // DNS records with TTLs shorter than this value will be refreshed at this rate instead. If not
+  // set, the TTL from the DNS response is used directly with no minimum floor.
+  // The value must be at least 1 second.
+  google.protobuf.Duration dns_min_refresh_rate = 10
+      [(validate.rules).duration = {gte {seconds: 1}}];
 }

envoy/extensions/clusters/dynamic_forward_proxy/v3/cluster.proto:

--- shake256:7e03724651ff36311b8dc7064d7edd827f2b39c1d84707d9adbdba769385598813dcfe57343b470230c54a1d953ce09eba33b42e1b3baa52e3cc4e9b35565e7a  envoy/extensions/clusters/dynamic_forward_proxy/v3/cluster.proto
+++ shake256:e392dc7007461ec2ae798f202f2b1ffc44d6ea843404340d512ad290632eaaefc5be2f0f1edd10326f87695c980ba499d13b0f4f1e86980ab3cdc4817aa00773  envoy/extensions/clusters/dynamic_forward_proxy/v3/cluster.proto
@@ -4,6 +4,7 @@
 
 import "envoy/config/cluster/v3/cluster.proto";
 import "envoy/config/core/v3/address.proto";
+import "envoy/extensions/clusters/dns/v3/dns_cluster.proto";
 import "envoy/extensions/common/dynamic_forward_proxy/v3/dns_cache.proto";
 
 import "google/protobuf/duration.proto";
@@ -76,7 +77,9 @@
   bool allow_coalesced_connections = 3;
 }
 
-// Configuration for sub clusters. Hard code STRICT_DNS cluster type now.
+// Configuration for sub clusters. Sub clusters default to the ``STRICT_DNS`` discovery type, or
+// use the ``DnsCluster`` extension when ``dns_cluster_config`` is set.
+// [#next-free-field: 6]
 message SubClustersConfig {
   // The :ref:`load balancer type <arch_overview_load_balancing_types>` to use
   // when picking a host in a sub cluster. Note that CLUSTER_PROVIDED is not allowed here.
@@ -93,4 +96,13 @@
   // performance improvement, in the form of cache hits, for sub clusters that are going to be
   // warmed during steady state and are known at config load time.
   repeated config.core.v3.SocketAddress preresolve_clusters = 4;
+
+  // Optional DNS configuration for dynamically created sub clusters. When set, sub clusters
+  // are created using the :ref:`DnsCluster <envoy_v3_api_msg_extensions.clusters.dns.v3.DnsCluster>`
+  // extension (``envoy.cluster.dns``) rather than the legacy ``STRICT_DNS`` discovery type,
+  // enabling full DNS configuration including refresh rates, failure backoff, TTL respect,
+  // lookup family, and resolver selection.
+  //
+  // When not set, sub clusters inherit DNS settings from the parent cluster configuration.
+  dns.v3.DnsCluster dns_cluster_config = 5;
 }

envoy/extensions/common/dynamic_forward_proxy/v3/dns_cache.proto:

--- shake256:b507b895388f9b46bd947d35a58112996e4d468a2002e06ab5511ebe3f03db0f6e5015ecdd0d04b06a65cde949cf2a5165ee7131fbf6dc2e3263970374d9c72c  envoy/extensions/common/dynamic_forward_proxy/v3/dns_cache.proto
+++ shake256:bacc120059e889203d81f339d15019d86124f5e6db3e34fa0f9960282127bf89d900d90cc33a11798277e2d76d60550a55dfd89ec18afa0ec6086087827e12ae  envoy/extensions/common/dynamic_forward_proxy/v3/dns_cache.proto
@@ -7,6 +7,7 @@
 import "envoy/config/core/v3/address.proto";
 import "envoy/config/core/v3/extension.proto";
 import "envoy/config/core/v3/resolver.proto";
+import "envoy/type/matcher/v3/address.proto";
 
 import "google/protobuf/duration.proto";
 import "google/protobuf/wrappers.proto";
@@ -33,7 +34,7 @@
 
 // Configuration for the dynamic forward proxy DNS cache. See the :ref:`architecture overview
 // <arch_overview_http_dynamic_forward_proxy>` for more information.
-// [#next-free-field: 16]
+// [#next-free-field: 17]
 message DnsCacheConfig {
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.config.common.dynamic_forward_proxy.v2alpha.DnsCacheConfig";
@@ -148,4 +149,12 @@
 
   // Configuration to flush the DNS cache to long term storage.
   config.common.key_value.v3.KeyValueStoreConfig key_value_config = 13;
+
+  // Optional matcher to filter out DNS resolution results that match specific IP address ranges.
+  // If a DNS response contains addresses matching this matcher, those addresses will be
+  // removed from the response. If all addresses are removed, the resolution is treated
+  // as a failure and the host will retain any previously resolved address.
+  // This can be used as an SSRF protection mechanism to prevent DNS rebinding attacks
+  // that resolve to internal/private IP addresses.
+  type.matcher.v3.AddressMatcher resolved_address_filter = 16;
 }

envoy/extensions/filters/common/set_filter_state/v3/value.proto:

--- shake256:59527f51b36370ee87eaa093e454df957c4f537e2201e02da2928c072be789221d7850b0773d9772b06e4e6ead2c25e8b7534c4265c5ddd7a888ccb7f0c92c16  envoy/extensions/filters/common/set_filter_state/v3/value.proto
+++ shake256:0d676447ff49be2c9b90352ac6c6ef5de7153e979c8306b7fb593a988bd21a498009979f47760530429e306a60d8893588da3f050488e8cd982ef018c9d8d9d7  envoy/extensions/filters/common/set_filter_state/v3/value.proto
@@ -4,6 +4,7 @@
 
 import "envoy/config/core/v3/substitution_format_string.proto";
 
+import "envoy/annotations/deprecation.proto";
 import "udpa/annotations/status.proto";
 import "validate/validate.proto";
 
@@ -91,9 +92,8 @@
     config.core.v3.SubstitutionFormatString format_string = 2;
   }
 
-  // If marked as read-only, the filter state key value is locked, and cannot
-  // be overridden by any filter, including this filter.
-  bool read_only = 3;
+  // This field is deprecated and its value has no effect.
+  bool read_only = 3 [deprecated = true, (envoy.annotations.deprecated_at_minor_version) = "3.0"];
 
   // Configures the object to be shared with the upstream internal connections. See :ref:`internal upstream
   // transport <config_internal_upstream_transport>` for more details on the filter state sharing with

envoy/extensions/filters/http/aws_lambda/v3/aws_lambda.proto:

--- shake256:208e15cc704c30a3a37f03fd72c98eed16c47e31e653e12c4c3829bd1a7746757da98ec919f2fd034972bed671e50690f6e302a68f6d1fe850d395bb99fed659  envoy/extensions/filters/http/aws_lambda/v3/aws_lambda.proto
+++ shake256:009d0945fabdf8882d4b20b6f5c167d0b886d497d1f8b72274c855dc6ef232f1a0845060936adbcf37f39d5df394b5e69c4b520b96d14d578602a6ec7ae57114  envoy/extensions/filters/http/aws_lambda/v3/aws_lambda.proto
@@ -2,6 +2,8 @@
 
 package envoy.extensions.filters.http.aws_lambda.v3;
 
+import "envoy/type/matcher/v3/string.proto";
+
 import "udpa/annotations/status.proto";
 import "udpa/annotations/versioning.proto";
 import "validate/validate.proto";
@@ -17,7 +19,7 @@
 // [#extension: envoy.filters.http.aws_lambda]
 
 // AWS Lambda filter config
-// [#next-free-field: 7]
+// [#next-free-field: 9]
 message Config {
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.config.filter.http.aws_lambda.v2alpha.Config";
@@ -76,6 +78,40 @@
   // .. warning::
   //   Distributing the AWS credentials via this configuration should not be done in production.
   Credentials credentials = 6;
+
+  // A list of request header string matchers that will be excluded from signing. The excluded header can be matched by
+  // any patterns defined in the StringMatcher proto (e.g. exact string, prefix, regex, etc).
+  // Headers such as ``x-amzn-cipher-suite``, ``x-amzn-tls-version``, ``x-amzn-vpc-id``, ``x-amzn-vpce-config`` and ``x-amzn-vpce-id``,
+  // when included in the request and signed, can cause errors to be generated by the Lambda endpoint.
+  //
+  // Example:
+  //
+  // .. code-block:: yaml
+  //
+  //  match_excluded_headers:
+  //  - prefix: x-amzn
+  //  - exact: foo
+  //  - exact: bar
+  //
+  // When applied, all headers that start with ``x-amzn`` and headers ``foo`` and ``bar`` will not be signed.
+  repeated type.matcher.v3.StringMatcher match_excluded_headers = 7;
+
+  // A list of request header string matchers that will be included during signing. The included header can be matched by
+  // any patterns defined in the StringMatcher proto (e.g. exact string, prefix, regex, etc).
+  // match_included_headers takes precedence over match_excluded_headers - if match_included_headers is set, only those headers will be signed and match_excluded_headers will be ignored.
+  // Required headers for signing such as ``host`` will always be signed regardless of this setting. The required headers are determined via ``CanonicalHeaders`` section in the AWS documentation `here <https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_sigv-create-signed-request.html#create-canonical-request>`_.
+  //
+  // Example:
+  //
+  // .. code-block:: yaml
+  //
+  //  match_included_headers:
+  //  - prefix: x-amzn
+  //  - exact: foo
+  //  - exact: bar
+  //
+  // When applied, all headers that start with ``x-amzn`` and headers ``foo`` and ``bar`` will be signed and all other headers will be excluded from signing except required headers.
+  repeated type.matcher.v3.StringMatcher match_included_headers = 8;
 }
 
 // AWS Lambda Credentials config.

envoy/extensions/filters/http/basic_auth/v3/basic_auth.proto:

--- shake256:0658d9ac6676216ef3c6a8d93e91d5ed61e9ebff0c4be5bfd1d7cdafdb3e4179a796bb5128b97da5497fe76f13f8b4c9b3c1d567257200326ad0f33275314592  envoy/extensions/filters/http/basic_auth/v3/basic_auth.proto
+++ shake256:00902c0bf637b39660032f85e0e6c05335ad948d4705c4207d3d67478603a21b6cefc06cfd79d03cda098eb753617d1cbe4f898827cd3deac3a75fdb25d2d422  envoy/extensions/filters/http/basic_auth/v3/basic_auth.proto
@@ -29,6 +29,7 @@
 //       user1:{SHA}hashed_user1_password
 //       user2:{SHA}hashed_user2_password
 //
+// [#next-free-field: 6]
 message BasicAuth {
   // Username-password pairs used to verify user credentials in the "Authorization" header.
   // The value needs to be the htpasswd format.
@@ -47,6 +48,29 @@
   // If it is not specified, the filter loads the credential from  the "Authorization" header.
   string authentication_header = 3
       [(validate.rules).string = {well_known_regex: HTTP_HEADER_NAME strict: false}];
+
+  // If set to true, requests without Basic credentials (missing ``Authorization`` header, or
+  // ``Authorization`` header with a non-``Basic`` scheme such as ``Bearer``) are allowed to pass through
+  // without authentication. Requests that present ``Basic`` credentials are still fully validated.
+  //
+  // This is useful when combining BasicAuth with other authentication methods (e.g. JWT) to
+  // achieve OR semantics: a request is accepted if any one configured auth method succeeds.
+  // When ``allow_missing`` is ``true`` on all auth filters, pair it with an RBAC filter that checks
+  // the dynamic metadata emitted by this filter (see ``emit_dynamic_metadata``) to ensure at
+  // least one method authenticated the request. Requires ``emit_dynamic_metadata`` to be set to
+  // ``true``.
+  bool allow_missing = 4;
+
+  // If set to ``true``, the filter emits dynamic metadata on successful authentication with key
+  // ``username`` set to the authenticated username. The metadata is emitted under the namespace
+  // corresponding to the name of this basic_auth filter as configured in the ``http_filters``
+  // chain (e.g. if the filter is configured with name ``envoy.filters.http.basic_auth``, that is
+  // the namespace that will be used).
+  //
+  // This is typically enabled together with ``allow_missing`` when combining BasicAuth with
+  // other authentication methods (e.g. JWT) and using a downstream RBAC filter to enforce
+  // OR semantics.
+  bool emit_dynamic_metadata = 5;
 }
 
 // Extra settings that may be added to per-route configuration for

envoy/extensions/filters/http/composite/v3/composite.proto:

--- shake256:5eda6bb5729dc34ac1a0ba6390df58021e94e61d5f540442d551ef15db94d015d68916535f4363ac1a7c99aed706048ffbe1a30396aaea913a32d110aea39ec9  envoy/extensions/filters/http/composite/v3/composite.proto
+++ shake256:0273f1108bcefebaabfaee544a90b5ab70c517b9e19e1131b490241df4c37b634ffe406dda73e975d7ff9ce5c6b847018c496110e974facc0bc46e56843dff02  envoy/extensions/filters/http/composite/v3/composite.proto
@@ -41,17 +41,31 @@
   // as it avoids duplicating the filter chain configuration.
   map<string, FilterChainConfiguration> named_filter_chains = 1;
 
-  // [#not-implemented-hide:]
   // The match tree that will be used to select an action to execute. The action type should be
   // :ref:`ExecuteFilterAction
   // <envoy_v3_api_msg_extensions.filters.http.composite.v3.ExecuteFilterAction>`.
+  //
+  // .. warning::
+  //   This should only be set when using the Composite filter as in the :ref:`http_filters
+  //   <envoy_v3_api_field_extensions.filters.network.http_connection_manager.v3.HttpConnectionManager.http_filters>`.
+  //   Never set this field when using the Composite filter with the :ref:`ExtensionWithMatcher
+  //   <envoy_v3_api_msg_extensions.common.matching.v3.ExtensionWithMatcher>` which will result in
+  //   undefined behavior.
+  //
   xds.type.matcher.v3.Matcher matcher = 2;
 }
 
 // Per-route configuration for the Composite filter.
-// [#not-implemented-hide:]
 message CompositePerRoute {
   // Override of the match tree for this route.
+  //
+  // .. warning::
+  //   This should only be set when using the Composite filter as in the :ref:`http_filters
+  //   <envoy_v3_api_field_extensions.filters.network.http_connection_manager.v3.HttpConnectionManager.http_filters>`.
+  //   Never set this field when using the Composite filter with the :ref:`ExtensionWithMatcher
+  //   <envoy_v3_api_msg_extensions.common.matching.v3.ExtensionWithMatcher>` which will result in
+  //   undefined behavior.
+  //
   xds.type.matcher.v3.Matcher matcher = 1 [(validate.rules).message = {required: true}];
 }
 

envoy/extensions/filters/http/custom_response/v3/custom_response.proto:

--- shake256:82ffd0cbfca838b0c290aa200fab3203a91825fb676853feb477c97c3cfd0b92f209e5af6daab0257bde72d859764e46cd4f986aca0227e98bd77023fc4b0765  envoy/extensions/filters/http/custom_response/v3/custom_response.proto
+++ shake256:fefa73c461c513262c6d5502fa1a26b8404c87ceb540447d6c4365961bced055f5514fb92192235388355030b769dd612f3339a0fcc9b5c5c124b4546fe8591a  envoy/extensions/filters/http/custom_response/v3/custom_response.proto
@@ -27,7 +27,11 @@
   // Matcher to match against the original response to select a
   // :ref:`Custom Response Policy <extension_category_envoy.http.custom_response>`
   // that will override the original response. The matching is done by matching
-  // against :ref:`response header values<extension_category_envoy.matching.http.input>`
+  // against the response status code, response header values, and/or
+  // :ref:`request header values<extension_category_envoy.matching.http.input>`.
+  // Request inputs (for example ``HttpRequestHeaderMatchInput``) match against
+  // the original downstream request, which allows selecting a custom response
+  // based on, e.g., the ``Accept`` request header.
   // Example:
   //
   // .. validated-code-block:: yaml
@@ -96,6 +100,35 @@
   //             - header:
   //                 key: "foo2"
   //                 value: "x-bar2"
+  //       # Apply a JSON custom response to 5xx responses when the request asks for JSON.
+  //     - predicate:
+  //         and_matcher:
+  //           predicate:
+  //           - single_predicate:
+  //               input:
+  //                 name: 5xx_response
+  //                 typed_config:
+  //                   "@type": type.googleapis.com/envoy.type.matcher.v3.HttpResponseStatusCodeClassMatchInput
+  //               value_match:
+  //                 exact: "5xx"
+  //           - single_predicate:
+  //               input:
+  //                 name: accept_request_header
+  //                 typed_config:
+  //                   "@type": type.googleapis.com/envoy.type.matcher.v3.HttpRequestHeaderMatchInput
+  //                   header_name: accept
+  //               value_match:
+  //                 exact: "application/json"
+  //       on_match:
+  //         action:
+  //           name: action
+  //           typed_config:
+  //             "@type": type.googleapis.com/envoy.extensions.http.custom_response.local_response_policy.v3.LocalResponsePolicy
+  //             status_code: 500
+  //             body_format:
+  //               json_format:
+  //                 status: "%RESPONSE_CODE%"
+  //                 message: "%LOCAL_REPLY_BODY%"
   //
   // -- attention::
   //  The first matched policy wins. Once the response is matched, matcher

envoy/extensions/filters/http/ext_authz/v3/ext_authz.proto:

--- shake256:b5adab52f4b770083cb54fb1866189dc3e58a36587925aa32003e04a864e666f1013c3af16b69ef346302534291b604fc04ce9b5507e69cd421e2ecc3a9682e7  envoy/extensions/filters/http/ext_authz/v3/ext_authz.proto
+++ shake256:e715b7dc0ebb2593a30543e81b64a9684b22679d355cd23de58fa40040bf5dfe7eaae1c982f55fc94db512ce7d621d6aa17c925de7dc64f749f0a3f7eee65e92  envoy/extensions/filters/http/ext_authz/v3/ext_authz.proto
@@ -88,6 +88,17 @@
   //   alter another client request header.
   //
   // Defaults to ``false``.
+  //
+  // .. attention::
+  //
+  //   Enabling this option can cause Envoy to recompute route matching after earlier HTTP filters
+  //   have already processed the request. This can be security-sensitive when route-dependent
+  //   authorization filters, such as the RBAC filter, run before ext_authz.
+  //
+  //   Operators should avoid enabling this option for authorization services that are not fully
+  //   trusted to influence routing. When possible, filters that mutate route-matching inputs and
+  //   clear the route cache should run before route-dependent authorization filters. Operators can
+  //   also use decoder_header_mutation_rules to restrict sensitive request header mutations.
   bool clear_route_cache = 6;
 
   // Sets the HTTP status that is returned to the client when the authorization server returns an error

envoy/extensions/filters/http/ext_proc/v3/ext_proc.proto:

--- shake256:8abe6aeb9fe7bb19c1453260272f450a201be9cc72d3a160fd6a5ae3afb6268272101805eb17a3bb801dbce828b7bc989f0aa38fe501381723a95f5c4f39d01a  envoy/extensions/filters/http/ext_proc/v3/ext_proc.proto
+++ shake256:4ae5cb378355dc0289d4c97e1839b88232b4f650638b2ce8cab571040aa158bc84866ace6e79becba7cc0ea1198c2463240cdeefc38903ef7d98320f2f7f4c81  envoy/extensions/filters/http/ext_proc/v3/ext_proc.proto
@@ -299,6 +299,17 @@
   // received in response to request headers. It is recommended to set this field rather than set
   // :ref:`disable_clear_route_cache <envoy_v3_api_field_extensions.filters.http.ext_proc.v3.ExternalProcessor.disable_clear_route_cache>`.
   // Only one of ``disable_clear_route_cache`` or ``route_cache_action`` can be set.
+  //
+  // .. attention::
+  //
+  //   Clearing the route cache can cause Envoy to recompute route matching after earlier HTTP
+  //   filters have already processed the request. This can be security-sensitive when filters
+  //   that make route-dependent authorization decisions, such as the RBAC filter, run before
+  //   ext_proc and ext_proc mutates route-matching inputs.
+  //
+  //   Operators should only enable route cache clearing for trusted external processors, should
+  //   carefully order route-dependent authorization filters, and should use mutation_rules to
+  //   restrict sensitive mutations when appropriate.
   RouteCacheAction route_cache_action = 18
       [(udpa.annotations.field_migrate).oneof_promotion = "clear_route_cache_type"];
 

envoy/extensions/filters/http/gcp_authn/v3/gcp_authn.proto:

--- shake256:32c11e93a8a0fd4d7d72d3676d66c1a0f14764d7a7df9ab8ac35a6fe8384b1a8a5cdd3bd7662994a51ed5833840855a9495f2baddadd8a29bd06f0fba39a1ce3  envoy/extensions/filters/http/gcp_authn/v3/gcp_authn.proto
+++ shake256:52635c541d6b7bcefc27115fef5270031bb2bc9ec24b2d93efd90e906cea870ba5b0040ea8fed4f7b6a9813369b6f22a385b05eba4b33f6beaa34d54c3358ac2  envoy/extensions/filters/http/gcp_authn/v3/gcp_authn.proto
@@ -64,7 +64,31 @@
 // Audience is the URL of the receiving service that performs token authentication.
 // It will be provided to the filter through cluster's typed_filter_metadata.
 message Audience {
-  string url = 1 [(validate.rules).string = {min_len: 1}];
+  message AccessToken {
+  }
+
+  message BoundJwt {
+    // The audience URL, used for fetching bound JWT token.
+    string url = 1 [(validate.rules).string = {min_len: 1}];
+  }
+
+  message BoundAccessToken {
+  }
+
+  // The audience URL, used for fetching unbound JWT token.
+  string url = 1;
+
+  // If defined, the filter will fetch unbound Access Token instead of JWT.
+  // It takes precedence over ``url``.
+  AccessToken access_token = 2;
+
+  // If defined, the filter will fetch bound JWT token instead of unbound.
+  // It takes precedence over ``access_token`` and ``url``.
+  BoundJwt bound_jwt = 3;
+
+  // If defined, the filter will fetch bound Access Token instead of unbound.
+  // It takes precedence over ``bound_jwt``, ``access_token`` and ``url``.
+  BoundAccessToken bound_access_token = 4;
 }
 
 // Token Cache configuration.

envoy/extensions/filters/http/ip_tagging/v3/ip_tagging.proto:

--- shake256:e21dabe4f701068b930a6c2586ed13869ab20e7756b0ab88bf4730ac17d0eca7b68083f2fb86a8a15acf96150b78411dd840a35bb2865cceeb2c2840913e3f59  envoy/extensions/filters/http/ip_tagging/v3/ip_tagging.proto
+++ shake256:769f5cdb800441cbde268eab925fcef13eedc109348b6caf1b6ba31804fa50182f0a4d0b4f6ad674c51051b80f7cfcebb64ff71a890285b13fdb301220f5954a  envoy/extensions/filters/http/ip_tagging/v3/ip_tagging.proto
@@ -3,6 +3,7 @@
 package envoy.extensions.filters.http.ip_tagging.v3;
 
 import "envoy/config/core/v3/address.proto";
+import "envoy/config/core/v3/base.proto";
 
 import "udpa/annotations/status.proto";
 import "udpa/annotations/versioning.proto";
@@ -18,7 +19,7 @@
 // IP tagging :ref:`configuration overview <config_http_filters_ip_tagging>`.
 // [#extension: envoy.filters.http.ip_tagging]
 
-// [#next-free-field: 6]
+// [#next-free-field: 7]
 message IPTagging {
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.config.filter.http.ip_tagging.v2.IPTagging";
@@ -53,6 +54,12 @@
     repeated config.core.v3.CidrRange ip_list = 2;
   }
 
+  // Specifies the content of the IP tag file.
+  // Allow the file to be created with no IP tags.
+  message IPTags {
+    repeated IPTag ip_tags = 1;
+  }
+
   // Specify to which header the tags will be written.
   message IpTagHeader {
     // Describes how to apply the tags to the headers.
@@ -88,13 +95,20 @@
   // The type of request the filter should apply to.
   RequestType request_type = 1 [(validate.rules).enum = {defined_only: true}];
 
-  // [#comment:TODO(ccaraman): Extend functionality to load IP tags from file system.
-  // Tracked by issue https://github.com/envoyproxy/envoy/issues/2695]
   // The set of IP tags for the filter.
-  repeated IPTag ip_tags = 4 [(validate.rules).repeated = {min_items: 1}];
+  // Only one of :ref:`ip_tags <envoy_v3_api_field_extensions.filters.http.ip_tagging.v3.IPTagging.ip_tags>`
+  // or :ref:`ip_tags_datasource <envoy_v3_api_field_extensions.filters.http.ip_tagging.v3.IPTagging.ip_tags_datasource>`
+  // can be set for the IP Tagging filter.
+  repeated IPTag ip_tags = 4;
 
   // Specify to which header the tags will be written.
   //
   // If left unspecified, the tags will be appended to the ``x-envoy-ip-tags`` header.
   IpTagHeader ip_tag_header = 5;
+
+  // Data source from which to retrieve ip tags.
+  // Only filename based data source is currently supported for IP tags.
+  // When using this data source, if a ``watched_directory`` is provided, the IP tags file will be re-read when a file move is detected.
+  // See :ref:`watched_directory <envoy_v3_api_msg_config.core.v3.DataSource>` for more information about the ``watched_directory`` field.
+  config.core.v3.DataSource ip_tags_datasource = 6;
 }

envoy/extensions/filters/http/jwt_authn/v3/config.proto:

--- shake256:7a694f7096a90eea01c8587b07066334b4fa525478303ea8a2b78d38185f17b025b1d71070421b8f9ba58f097fc78cb557caae8f16d213080496f934263a378f  envoy/extensions/filters/http/jwt_authn/v3/config.proto
+++ shake256:96cd7a468fdd66eab12305b1dc75a394fd726d1427fa3b2d02c073c76053a955cc574c57418fb1866696f3f738df2f650f173653972c91b5b97d372d22286eb8  envoy/extensions/filters/http/jwt_authn/v3/config.proto
@@ -78,6 +78,7 @@
   // otherwise the JWT ``iss`` field is not checked.
   //
   // .. note::
+  //
   //     ``JwtRequirement`` :ref:`allow_missing <envoy_v3_api_field_extensions.filters.http.jwt_authn.v3.JwtRequirement.allow_missing>`
   //     and :ref:`allow_missing_or_failed <envoy_v3_api_field_extensions.filters.http.jwt_authn.v3.JwtRequirement.allow_missing_or_failed>`
   //     are implemented differently than other ``JwtRequirements``. Hence the usage of this field
@@ -324,10 +325,11 @@
   //       alg: PS256
   //
   // .. warning::
-  //   Using the same key name for :ref:`header_in_metadata <envoy_v3_api_field_extensions.filters.http.jwt_authn.v3.JwtProvider.payload_in_metadata>`
-  //   and :ref:`payload_in_metadata <envoy_v3_api_field_extensions.filters.http.jwt_authn.v3.JwtProvider.payload_in_metadata>`
-  //   is not suggested due to potential override of existing entry, while it is not enforced during
-  //   config validation.
+  //
+  //    Using the same key name for :ref:`header_in_metadata <envoy_v3_api_field_extensions.filters.http.jwt_authn.v3.JwtProvider.payload_in_metadata>`
+  //    and :ref:`payload_in_metadata <envoy_v3_api_field_extensions.filters.http.jwt_authn.v3.JwtProvider.payload_in_metadata>`
+  //    is not suggested due to potential override of existing entry, while it is not enforced during
+  //    config validation.
   //
   string header_in_metadata = 14;
 
@@ -593,38 +595,70 @@
     // different is this mode will reject requests with invalid tokens.
     google.protobuf.Empty allow_missing = 6;
 
-    // Extract JWT claims without performing signature validation.
-    // This mode will decode the JWT, extract claims, and forward them as
-    // configured (via claim_to_headers, forward_payload_header, etc.) but
-    // will NOT verify the JWT signature against JWKS.
+    // [#next-major-version: consider removing or gating behind explicit opt-in]
     //
     // .. warning::
     //
-    //    This mode does not verify JWT authenticity. Use only in scenarios where:
-    //
-    //    - JWTs come from a trusted source (e.g., internal service mesh)
-    //    - Signature verification is performed elsewhere in the request path
-    //    - You are in a testing period and the token issuer doesn't support JWKS yet
-    //
-    // This mode will:
-    //
-    // * Decode the JWT header and payload
-    // * Extract claims and forward them as headers
-    // * Always return success (Status::Ok) regardless of JWT validity
-    // * Log when extraction occurs
+    //    SECURITY WARNING: This mode does NOT verify JWT signatures. Any party
+    //    can forge a JWT with arbitrary claims, and those claims will be extracted
+    //    and forwarded as HTTP headers. Headers set by this mode are
+    //    INDISTINGUISHABLE from headers set by fully validated JWTs unless the
+    //    ``verification_status_header`` is checked by downstream filters
+    //    (set to ``false`` by default on all extract-only requests).
+    //
+    //    DO NOT use this mode if:
+    //      - RBAC policies match on JWT-derived headers
+    //      - ext_authz services trust JWT-derived headers
+    //      - Backend services use JWT-derived headers for authorization
+    //      - The JWT source is not cryptographically authenticated by other means
     //
-    // This mode will NOT:
+    //    Use only when signature verification is PROVABLY performed elsewhere
+    //    in the request path (e.g., by an upstream mTLS-authenticated service).
     //
-    // * Verify the JWT signature
-    // * Validate the (issuer) claim
-    // * Validate the (audience) claim
-    // * Check not-before time (nbf claim)
     ExtractOnlyWithoutValidation extract_only_without_validation = 7;
   }
 }
 
+// Configuration for extract-only mode without JWT signature validation.
+//
+// When this mode is active and a JWT is present in the request but fails
+// signature verification, a verification status header is set on the request
+// to signal to downstream filters (RBAC, ext_authz) that the JWT claims were
+// NOT cryptographically verified. The header is not set when the JWT is valid
+// or when no JWT is present.
+//
 message ExtractOnlyWithoutValidation {
-  // Reserved for future extensions (e.g., claim filtering, logging options)
+  // Name of the HTTP header set to "false" when a JWT is present but fails
+  // signature verification. The header is NOT set when:
+  //
+  // - The JWT is valid (verification succeeded), or
+  // - No JWT is present in the request.
+  //
+  // This means the header's presence is a meaningful signal to downstream
+  // filters: if set, the JWT was present but could not be verified, and any
+  // extracted claim headers should not be trusted for authorization.
+  //
+  // Downstream filters (RBAC, ext_authz) SHOULD check for the absence of this
+  // header (or its non-"false" value) before trusting JWT-derived claim headers
+  // for authorization decisions.
+  //
+  // Default (unset or empty): ``x-jwt-signature-verified``.
+  //
+  // Custom value: uses the specified header name.
+  //
+  // The header-setting behavior is guarded by the
+  // ``envoy.reloadable_features.jwt_authn_add_verification_status_header``
+  // runtime flag (default on). If removal is needed downstream, use header
+  // mutation in a subsequent filter.
+  //
+  // Example: when a JWT is present in the request but fails signature
+  // verification, the request will carry:
+  //
+  // .. code-block:: yaml
+  //
+  //    x-jwt-signature-verified: false
+  //
+  string verification_status_header = 1;
 }
 
 // This message specifies a list of RequiredProvider.

envoy/extensions/filters/http/mcp/v3/mcp.proto:

--- shake256:328867464937b631c46b21ab01d87750ba39570d9092007aa9ca09c8443e54829c4872b77e7e310ac1245b6871f5c9e9e59b4f8e49385eeace4abd24cb2d7d67  envoy/extensions/filters/http/mcp/v3/mcp.proto
+++ shake256:808766396bbbebaa9e63f415dd311ee8a26a2537a290280f8269cc4b750d25970889e47e8c2ab1fd49574f6b1589f997f4ac796c6420b56eb2966ac40e643087  envoy/extensions/filters/http/mcp/v3/mcp.proto
@@ -21,7 +21,7 @@
 // [#extension: envoy.filters.http.mcp]
 
 // This filter will inspect and get attributes from MCP traffic.
-// [#next-free-field: 8]
+// [#next-free-field: 9]
 message Mcp {
   // Traffic handling mode for non-MCP traffic.
   enum TrafficMode {
@@ -69,9 +69,12 @@
   // Defaults to false.
   bool clear_route_cache = 2;
 
-  // Maximum size of the request body to buffer for JSON-RPC validation.
-  // If the request body exceeds this size, the request is rejected with ``413 Payload Too Large``.
-  // This limit applies to both ``REJECT_NO_MCP`` and ``PASS_THROUGH`` modes to prevent unbounded buffering.
+  // Maximum size of the request body to buffer for JSON-RPC parsing.
+  // Only the first ``max_request_body_size`` bytes are parsed for MCP attribute extraction.
+  //
+  // When the body exceeds this limit:
+  // - In ``PASS_THROUGH`` mode: the request is allowed through with an ``is_exceeding_limit`` marker in the dynamic metadata, indicating that the MCP payload was only partially parsed.
+  // - In ``REJECT_NO_MCP`` mode: the request is rejected with ``400 Bad Request`` because the complete root JSON object must fit within the size limit.
   //
   // It defaults to 8KB (8192 bytes) and the maximum allowed value is 10MB (10485760 bytes).
   //
@@ -107,6 +110,11 @@
   //
   // If unset (default), do not extract or inject baggage.
   BaggagePropagationConfig propagate_baggage = 7;
+
+  // When true, reject requests that contain duplicate JSON keys at any
+  // nesting level. RFC 8259 Section 4 states that names within an object SHOULD be
+  // unique. Defaults to false (last-key-wins / last-win).
+  google.protobuf.BoolValue reject_duplicate_keys = 8;
 }
 
 // Parser configuration with method-specific rules.

envoy/extensions/filters/http/mcp_json_rest_bridge/v3/mcp_json_rest_bridge.proto:

--- shake256:7481e541607d3560e2fde1540b5201201cc2bc76a80a24c6bf09f89f9191930d3a4df0cde01662f33a416672013fb77d15b4116378cdb150085cfb9afaf76e49  envoy/extensions/filters/http/mcp_json_rest_bridge/v3/mcp_json_rest_bridge.proto
+++ shake256:5aee9cad0f35c68f9a54ca9dcf19c9875fb92140c560ba5bce1216e5e1bab0155f2684c448b641bcd675e1f9f4b1bce8ac0c3c7ec8c965a9d6968357df193e5b  envoy/extensions/filters/http/mcp_json_rest_bridge/v3/mcp_json_rest_bridge.proto
@@ -90,12 +90,66 @@
 //   - Body: {"data": "updated value"}
 //     (Only the "payload" field from arguments is used as the body. Other arguments not in the
 //     path, like 'resource_id', become query parameters.)
+// [#next-free-field: 8]
 message McpJsonRestBridge {
+  // Where to store parsed MCP request attributes.
+  enum RequestStorageMode {
+    // Unspecified. Uses default behavior (nothing is stored).
+    MODE_UNSPECIFIED = 0;
+
+    // Store request attributes in dynamic metadata. The metadata namespace
+    // is the filter's config name as specified by the ``name`` field in the
+    // ``http_filters`` list (e.g. ``envoy.filters.http.mcp_json_rest_bridge``
+    // if using the canonical filter name).
+    DYNAMIC_METADATA = 1;
+  }
+
   // General server information.
   ServerInfo server_info = 1;
 
   // Configuration for the MCP tools.
   ServerToolConfig tool_config = 2;
+
+  // Maximum size of the request body to buffer for transcoding and validation.
+  // If the request body exceeds this size, the request is rejected with ``413 Payload Too Large``.
+  // This limit applies to prevent unbounded buffering.
+  //
+  // It defaults to 64KB (65536 bytes) as the MCP calls (tools, resources, or prompts)
+  // only pass small arguments or identifiers.
+  //
+  // Setting it to 0 would disable the limit. It is not recommended to do so in production.
+  google.protobuf.UInt32Value max_request_body_size = 3;
+
+  // Maximum size of the response body to buffer for transcoding.
+  // If the response body exceeds this size, the response is rejected with an appropriate error.
+  // This limit applies to prevent unbounded buffering.
+  //
+  // It defaults to 1MB (1048576 bytes) to prevent transcoding failures on large payloads like
+  // file reads, while aligning with Envoy's standard default connection buffer limit.
+  //
+  // Setting it to 0 would disable the limit. It is not recommended to do so in production.
+  google.protobuf.UInt32Value max_response_body_size = 4;
+
+  // Where to store parsed MCP request attributes.
+  // Default is not storing anything.
+  // When set to ``DYNAMIC_METADATA``, attributes are stored in dynamic metadata
+  // using the filter's config name (i.e. the ``name`` field of this filter's entry
+  // in the ``http_filters`` list) as the metadata namespace.
+  RequestStorageMode request_storage_mode = 5 [(validate.rules).enum = {defined_only: true}];
+
+  // If set, extract OpenTelemetry (OTel) trace context from MCP requests and propagate it to
+  // request headers. The keys ``traceparent``, ``tracestate``, and ``baggage``
+  // will be extracted from ``_meta``.
+  // Ref: `Request Meta SEP <https://modelcontextprotocol.io/seps/414-request-meta>`_
+  TraceContextExtractionOptions trace_context_extraction = 6;
+
+  // When set to true, the filter will not clear the route cache after transcoding.
+  // This allows the route to be re-selected based on the updated request path or method.
+  bool disable_clear_route_cache = 7;
+}
+
+// Options for trace context extraction.
+message TraceContextExtractionOptions {
 }
 
 // Configuration for the server metadata.
@@ -127,7 +181,12 @@
   google.protobuf.StringValue fallback_protocol_version = 3;
 }
 
+// Configuration for sending locally-generated responses to tools/list requests.
+message ToolsListLocal {
+}
+
 // Configuration for the MCP tool capability of the server.
+// [#next-free-field: 6]
 message ServerToolConfig {
   // List of MCP tools configurations.
   repeated ToolConfig tools = 1;
@@ -137,26 +196,80 @@
   // Whether this server supports notifications for changes to the tool list.
   bool list_changed = 2;
 
-  // Optional configuration to transcode the tools/list requests to a standard HTTP request.
-  //
-  // Note: tools/list should be mapped to a GET request with an empty body.
-  //
-  // - If provided: The extension transcodes the request and forwards it down the filter chain.
-  //   The response (whether from an upstream backend, a configured ``direct_response``, or another
-  //   extension) MUST be a JSON body strictly matching the MCP ``ListToolsResult`` schema.
-  //   Ref: https://modelcontextprotocol.io/specification/2025-11-25/schema#listtoolsresult
-  // - If not provided: The ``tools/list`` request is passed through. This allows subsequent
-  //   extension or the backend itself to handle the tools/list request if they support it.
-  HttpRule tool_list_http_rule = 3;
+  // Optional configuration for tools/list requests. If not set: The ``tools/list`` request is
+  // passed through. This allows subsequent extension or the backend itself to handle the tools/list
+  // request if they support it.
+  oneof tool_list_config {
+    // Configuration to transcode the tools/list requests to a standard HTTP request. If provided:
+    // The extension transcodes the request and forwards it down the filter chain. The response
+    // (whether from an upstream backend, a configured ``direct_response``, or another extension)
+    // MUST be a JSON body strictly matching the MCP ``ListToolsResult`` schema. Ref:
+    // https://modelcontextprotocol.io/specification/2025-11-25/schema#listtoolsresult
+    HttpRule tool_list_http_rule = 3;
+
+    // If provided: The extension sends a local response, according to each tool's
+    // ToolsListSpecificConfig.
+    ToolsListLocal tool_list_local = 4;
+  }
+
+  // [#not-implemented-hide:]
+  // Default server info for tools without specific ones.
+  McpServerInfo default_server_info = 5;
+}
+
+// Configuration for a tool's entry in tools/list responses.
+message ToolsListSpecificConfig {
+  // Optional, human-readable name of the tool for display purposes.
+  string title = 1;
+
+  // Human-readable description of functionality.
+  string description = 2 [(validate.rules).string = {min_len: 1}];
+
+  // A JSON Schema describing expected parameters, as a serialized JSON string, in the JSON Schema
+  // 2020-12 dialect. This should be raw JSON, including the "properties" and "required" keys, but
+  // not "type". Tools with no parameters may omit this to signify a tool with no constraints on the
+  // parameters object, or set to '"additionalProperties": false' to require empty parameters.
+  string input_schema = 3;
+}
+
+message McpServerInfo {
+  // The path to the endpoint hosting this tool.
+  string path = 1;
+
+  // The host hosting this tool.
+  string host = 2;
 }
 
-// Configuration for a specific MCP tool.
+// [#next-free-field: 6]
 message ToolConfig {
-  // Name of the tool.
+  // Unique identifier of the tool. Used both for tools/list and tools/call transcoding.
   string name = 1 [(validate.rules).string = {min_len: 1}];
 
   // The HTTP configuration rules that apply to the normal backend.
   HttpRule http_rule = 2;
+
+  // Config for this tool's entry in a local tools/list response. Used when tool_list_local is set
+  // in the ServerToolConfig.
+  ToolsListSpecificConfig tool_list_config = 3;
+
+  // Enables streaming transcoding for unstructured text responses (``content`` field of a result).
+  //
+  // When enabled, the response body is streamed directly to the client without buffering. Each
+  // chunk is JSON escaped as it arrives and wrapped with a pre-built JSON-RPC prefix and suffix.
+  //
+  // Streaming flow:
+  //
+  // .. code-block:: text
+  //
+  //   input:  [chunk1] → [chunk2] → [chunk3]
+  //   output: [prefix+escaped_chunk1] → [escaped_chunk2] → [escaped_chunk3+suffix]
+  //
+  // Disabled by default.
+  bool text_content_streaming_enabled = 4;
+
+  // [#not-implemented-hide:]
+  // Path and host of the MCP server that hosts this tool.
+  repeated McpServerInfo server_info = 5;
 }
 
 // Defines the schema of the JSON-RPC to REST mapping. It specifies how the "arguments"
@@ -207,3 +320,8 @@
   // - If omitted: There is no HTTP request body; fields not in the path become query parameters.
   string body = 6;
 }
+
+// Per-route override configuration for the MCP JSON REST Bridge filter.
+message McpJsonRestBridgePerRoute {
+  repeated ServerToolConfig tool_config = 1;
+}

envoy/extensions/filters/http/mcp_router/v3/mcp_router.proto:

--- shake256:5667f8c87679bf1644503044802c8f3e1cf67eac83eafd7a9c0abd969bdc1addc7670b39c482a0cacc8a58d9eea6ba734baa8d7fcb82a6cd0bfcf346a5da0aa8  envoy/extensions/filters/http/mcp_router/v3/mcp_router.proto
+++ shake256:4784eabf7fac5ec895c3fb78a6229e0ba47d006a9141ac3554c3ae6b4819aa1df5928d227a32e0705d707aeeca69b5bd2ff5127c9af2148d32d6a8a052c2e951  envoy/extensions/filters/http/mcp_router/v3/mcp_router.proto
@@ -125,4 +125,11 @@
   // If set, extracts a request "subject" and binds it into the MCP session.
   // If not set, sessions are created without identity binding.
   SessionIdentity session_identity = 2;
+
+  // If true, backend initialization is deferred until the first request that targets each backend.
+  // The ``initialize`` response is returned immediately with gateway capabilities and an empty
+  // backend session map. Each backend is initialized on-demand when a request first routes to it.
+  // This avoids blocking the client ``initialize`` on slow or misbehaving backends.
+  // Default is false (eager initialization of all backends during ``initialize``).
+  bool lazy_initialization = 3;
 }

envoy/extensions/filters/http/oauth2/v3/oauth.proto:

--- shake256:ee6caa86d0cdc97ae3c573a296a30936418d625215a6d2e80817c78eb964bd650e0a00297972fd96420001a4745e97dfbda51fa61501cc26064f7784ba532d58  envoy/extensions/filters/http/oauth2/v3/oauth.proto
+++ shake256:1e855d9dc76a5577eb5c8291d2277659417251743ef7779a6f5cee92f01c9d87b003e978b9f66f7cbd6e2443cb7069e04182cd6133b0f9792b1bc405463fd5e7  envoy/extensions/filters/http/oauth2/v3/oauth.proto
@@ -129,6 +129,8 @@
   // The secret used to retrieve the access token. This value will be URL encoded when sent to the OAuth server.
   // This field is required unless :ref:`auth_type <envoy_v3_api_field_extensions.filters.http.oauth2.v3.OAuth2Config.auth_type>`
   // is set to ``TLS_CLIENT_AUTH``, in which case authentication is done via the client certificate.
+  // When ``auth_type`` is ``PRIVATE_KEY_JWT``, this field must contain the PEM-encoded private key
+  // used to sign the JWT client assertion.
   transport_sockets.tls.v3.SdsSecretConfig token_secret = 2;
 
   // Configures how the secret token should be created.
@@ -149,9 +151,71 @@
       [(validate.rules).string = {pattern: "^$|^[^\\x00-\\x1f\\x7f \",;<>\\\\]+$"}];
 }
 
+// Configuration for ``PRIVATE_KEY_JWT`` client authentication (RFC 7523).
+message PrivateKeyJwtConfig {
+  // Supported JWT signing algorithms for the client assertion.
+  enum SigningAlgorithm {
+    // ``RSASSA-PKCS1-v1_5`` using SHA-256.
+    RS256 = 0;
+
+    // ``RSASSA-PKCS1-v1_5`` using SHA-384.
+    RS384 = 1;
+
+    // ``RSASSA-PKCS1-v1_5`` using SHA-512.
+    RS512 = 2;
+
+    // ECDSA using P-256 and SHA-256.
+    ES256 = 3;
+
+    // ECDSA using P-384 and SHA-384.
+    ES384 = 4;
+
+    // ECDSA using P-521 and SHA-512.
+    ES512 = 5;
+  }
+
+  // The signing algorithm to use for the JWT assertion.
+  // The private key provided in ``token_secret`` must match the algorithm family: an RSA key for
+  // the ``RS*`` algorithms, or an EC key for the ``ES*`` algorithms.
+  // Default: ``RS256``.
+  SigningAlgorithm signing_algorithm = 1 [(validate.rules).enum = {defined_only: true}];
+
+  // The lifetime of the JWT assertion. After this duration, the assertion expires.
+  // The value is truncated to whole seconds, so it must be at least ``1s`` when set.
+  // Default: ``60s``.
+  google.protobuf.Duration assertion_lifetime = 2 [(validate.rules).duration = {gte {seconds: 1}}];
+}
+
+// Defines how an OAuth token is forwarded upstream.
+message OAuth2TokenForwarding {
+  // The upstream request header that will carry the token.
+  // Pseudo-headers (names starting with ``:``) and the ``Host`` header are not allowed.
+  string header = 1
+      [(validate.rules).string = {min_len: 1 well_known_regex: HTTP_HEADER_NAME strict: false}];
+}
+
+// Configuration for the ``post_logout_redirect_uri`` parameter used in OpenID Connect
+// `RP-Initiated Logout requests <https://openid.net/specs/openid-connect-rpinitiated-1_0.html>`_.
+// This configuration is ignored if ``end_session_endpoint`` is not set.
+message PostLogoutRedirectUri {
+  oneof config {
+    option (validate.required) = true;
+
+    // Do not include the ``post_logout_redirect_uri`` parameter in requests to the
+    // configured ``end_session_endpoint``.
+    bool disabled = 1 [(validate.rules).bool = {const: true}];
+
+    // URI to send as the ``post_logout_redirect_uri`` parameter. Supports header formatting
+    // tokens, and will be percent-encoded automatically when building the logout URL.
+    //
+    // The URI should be registered with the authorization server.
+    string uri = 2 [(validate.rules).string = {min_len: 1}];
+  }
+}
+
 // OAuth config
 //
-// [#next-free-field: 28]
+// [#next-free-field: 34]
 message OAuth2Config {
   enum AuthType {
     // The ``client_id`` and ``client_secret`` will be sent in the URL encoded request body.
@@ -168,6 +232,12 @@
     // transport socket configuration.
     // This implements OAuth 2.0 Mutual-TLS Client Authentication as defined in RFC 8705.
     TLS_CLIENT_AUTH = 2;
+
+    // The client authenticates using a signed JWT assertion (RFC 7523).
+    // The ``token_secret`` in credentials must contain the PEM-encoded private key used to sign the assertion.
+    // The JWT assertion is sent as ``client_assertion`` in the token request body along with
+    // ``client_assertion_type=urn:ietf:params:oauth:client-assertion-type:jwt-bearer``.
+    PRIVATE_KEY_JWT = 3;
   }
 
   // Endpoint on the authorization server to retrieve the access token from.
@@ -187,6 +257,15 @@
   // If configured, the OAuth2 filter will redirect users to this endpoint when they access the signout_path.
   string end_session_endpoint = 23;
 
+  // Optional control for the ``post_logout_redirect_uri`` parameter sent to the ``end_session_endpoint`` when a user
+  // accesses the ``signout_path``.
+  // This field should be set only if ``openid`` is in the ``auth_scopes``, the ``end_session_endpoint`` is configured,
+  // and the authorization server supports the OpenID Connect RP-Initiated Logout specification.
+  //
+  // If unset, Envoy preserves the historical behavior and sends ``<scheme>://<host>/``, constructed from the inbound
+  // request, as ``post_logout_redirect_uri``.
+  PostLogoutRedirectUri post_logout_redirect_uri = 33;
+
   // Credentials used for OAuth.
   OAuth2Credentials credentials = 3 [(validate.rules).message = {required: true}];
 
@@ -207,6 +286,19 @@
   // Forward the OAuth token as a Bearer to upstream web service.
   bool forward_bearer_token = 7;
 
+  // Forward the OIDC ID token to the upstream.
+  //
+  // If the configured header is ``Authorization``, Envoy forwards the ID token using the
+  // ``Bearer`` prefix. For any other header, Envoy forwards the raw token value.
+  // If not specified, the ID token will not be forwarded.
+  //
+  // This can not be configured with :ref:`forward_bearer_token
+  // <envoy_v3_api_field_extensions.filters.http.oauth2.v3.OAuth2Config.forward_bearer_token>`
+  // or :ref:`preserve_authorization_header
+  // <envoy_v3_api_field_extensions.filters.http.oauth2.v3.OAuth2Config.preserve_authorization_header>`
+  // when the header is ``Authorization``.
+  OAuth2TokenForwarding forward_id_token = 31;
+
   // If set to true, preserve the existing authorization header.
   // By default the client strips the existing authorization header before forwarding upstream.
   // Can not be set to true if forward_bearer_token is already set to true.
@@ -304,6 +396,56 @@
   // Note: If a request matches pass_through_matcher, it bypasses OAuth validation and this matcher won't be evaluated.
   // This matcher takes precedence over deny_redirect_matcher.
   repeated config.route.v3.HeaderMatcher allow_failed_matcher = 27;
+
+  // Optional base URI (scheme + host, e.g. ``https://app.example.com``) used to build the
+  // original request URI that is encoded into the OAuth2 ``state`` parameter.
+  // This URI will be used later to redirect users on a successful OAuth.
+  //
+  // This is useful when Envoy sits behind a gateway or load balancer that terminates the
+  // user-facing hostname: In that case, the post-authentication redirect derived from ``state`` would
+  // send the user to an internal host they didn't request.
+  //
+  // Supports request header formatting tokens.
+  //
+  // Example:
+  //
+  //    original_request_uri: "%REQ(x-forwarded-proto?:scheme)%://%REQ(x-forwarded-host?:authority)%"
+  //
+  // If not set, defaults to ``<:scheme>://<:authority>`` of the incoming request.
+  string original_request_uri = 28;
+
+  // Optional list of domains that are allowed as
+  // 1. redirect_uri: which is what the IdP calls after OAuth
+  // 2. original_request_uri: the one extracted from the state of an OAuth callback (where should the request go after OAuth)
+  //
+  // This mitigates:
+  // - injecting a malicious x-forwarded-host or any header that is used to template the redirect urls
+  // - open redirect attacks where an attacker crafts a ``state`` value pointing to an untrusted host.
+  //
+  // Each entry is matched against the host (with any port stripped) extracted from the
+  // formatted ``redirect_uri``, the formatted ``original_request_uri``, and the URL decoded from
+  // the ``state`` parameter on callback. Matching is case-insensitive and supports two forms:
+  //
+  // * Exact match, e.g. ``example.com`` matches only ``example.com``.
+  // * Wildcard subdomain match using a leading ``*.``, e.g. ``*.example.com`` matches
+  //   ``foo.example.com`` and ``bar.baz.example.com`` but not ``example.com`` itself.
+  //
+  // IPv6 literals must be configured without surrounding brackets (e.g. ``::1``, not ``[::1]``).
+  //
+  // If this list is empty (the default), all hosts are allowed and no validation is performed.
+  repeated string allowed_redirect_domains = 29;
+
+  // If set to true, the expiration time for the ID token cookie will always be derived from the
+  // ``expires_in`` field of the access token response rather than from the ``exp`` claim in the
+  // ID token JWT. This is useful when the access token response advertises a longer lifetime than
+  // the ID token and you want the ID token cookie to remain valid for that full duration.
+  // Default is false (use the ID token's own ``exp`` claim when available).
+  bool use_access_token_expiry_for_id_token_cookie = 30;
+
+  // Configuration for ``PRIVATE_KEY_JWT`` client authentication.
+  // Only used when :ref:`auth_type <envoy_v3_api_field_extensions.filters.http.oauth2.v3.OAuth2Config.auth_type>`
+  // is set to ``PRIVATE_KEY_JWT``.
+  PrivateKeyJwtConfig private_key_jwt_config = 32;
 }
 
 // Per-route OAuth2 config.

envoy/extensions/filters/http/ratelimit/v3/rate_limit.proto:

--- shake256:9357baac054d71b1b6361fe24de5fd0b9ee746375f66e9cff832d5c836611c71319ecab5634d12f2cc4bd73d395f85ebb2abb06ce8921b856d6c5b862e927e49  envoy/extensions/filters/http/ratelimit/v3/rate_limit.proto
+++ shake256:dc3c8e72fda2ad3e68389021ba3c98c2fa6f659c2fe66962bf5c4a61f374cb5d4767608acc4996f5df6fea29e7bcd82f44776c7fbf5cceeb2afbb5fec211b373  envoy/extensions/filters/http/ratelimit/v3/rate_limit.proto
@@ -23,7 +23,7 @@
 // Rate limit :ref:`configuration overview <config_http_filters_rate_limit>`.
 // [#extension: envoy.filters.http.ratelimit]
 
-// [#next-free-field: 18]
+// [#next-free-field: 19]
 message RateLimit {
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.config.filter.http.rate_limit.v2.RateLimit";
@@ -186,6 +186,10 @@
   //   3. :ref:`disable_key <envoy_v3_api_field_config.route.v3.RateLimit.disable_key>`.
   //   4. :ref:`override limit <envoy_v3_api_field_config.route.v3.RateLimit.limit>`.
   repeated config.route.v3.RateLimit rate_limits = 17;
+
+  // The namespace where dynamic metadata from rate limit response is saved.
+  // If not set, the default is "envoy.filters.http.ratelimit".
+  string metadata_namespace = 18;
 }
 
 message RateLimitPerRoute {

envoy/extensions/filters/listener/proxy_protocol/v3/proxy_protocol.proto:

--- shake256:2a3f58f19a05d4bb14ea75736b81862c7acd196b73db4ed172be24876e6c9efc18905db4c243fe3a266c1b9f260aed9a3b7421ee76f5dc39ae73158ae4e7be9d  envoy/extensions/filters/listener/proxy_protocol/v3/proxy_protocol.proto
+++ shake256:2acc9f14baef8fd67df524cacd3fbac587f8f59708c0a8f3d0a254afb9e554e38a8ad1cbe13a6c23a63b35ac3ad58782c49c658a6451b834588f03c91ec2f1a8  envoy/extensions/filters/listener/proxy_protocol/v3/proxy_protocol.proto
@@ -33,11 +33,38 @@
   }
 
   message KeyValuePair {
+    // Specifies the encoding scheme that is used to encode the TLV value before it is
+    // stored in dynamic metadata or filter state.
+    enum ValueStringEncoding {
+      // Unspecified encoding scheme. Defaults to ``SANITIZED_UTF8``.
+      UNSPECIFIED = 0;
+
+      // The TLV value will be sanitized to a valid UTF-8 string before being stored:
+      // any invalid UTF-8 sequences will be replaced with the ``!`` character.
+      SANITIZED_UTF8 = 1;
+
+      // The raw TLV value will be encoded as a `Base64 <https://datatracker.ietf.org/doc/html/rfc4648#section-4>`_
+      // string (with padding) before being stored. This is useful for binary TLV values that
+      // are not valid UTF-8 strings.
+      BASE64 = 2;
+    }
+
     // The namespace — if this is empty, the filter's namespace will be used.
     string metadata_namespace = 1;
 
     // The key to use within the namespace.
     string key = 2 [(validate.rules).string = {min_len: 1}];
+
+    // The value encoding scheme that is used to encode the TLV value before it is stored in
+    // dynamic metadata or filter state. If not set, defaults to ``SANITIZED_UTF8``, which
+    // sanitizes the TLV value to a valid UTF-8 string.
+    //
+    // .. note::
+    //
+    //   This option only applies to the legacy untyped dynamic metadata and filter state.
+    //   For the new typed dynamic metadata, the raw TLV value bytes are stored as is and
+    //   no encoding is applied.
+    ValueStringEncoding value_string_encoding = 3;
   }
 
   // A Rule defines what metadata to apply when a header is present or missing.

envoy/extensions/filters/network/ext_proc/v3/ext_proc.proto:

--- shake256:8118f88a7d299a9b7a57a7a94aa210aca62d813d5e4d64cca7c913cbe8334daa5bf391ae923972f6abbbee1e223d62dcb39d823d26c5a1d487d1730c552bc10c  envoy/extensions/filters/network/ext_proc/v3/ext_proc.proto
+++ shake256:680442ffbffbd96a2d6cfaaa1efb97f319bb1e1728c5b10028f95e4d3ca011f618bdb38435ae7ac7d8cfa919a41064b52a90b6eec609b9ed12b6692633ae49ab  envoy/extensions/filters/network/ext_proc/v3/ext_proc.proto
@@ -105,4 +105,13 @@
   // Describes which typed or untyped dynamic metadata namespaces to forward to
   // the external processing server.
   MetadataNamespaces forwarding_namespaces = 1;
+
+  // Describes which typed or untyped dynamic metadata namespaces to receive
+  // from the external processing server.
+  // Since the server returns untyped dynamic metadata, this configuration acts
+  // as a allowlist. Only metadata namespaces explicitly listed here will be
+  // ingested by Envoy from the server's response.
+  // Receiving of typed metadata is not supported.
+  // Set to empty or leave unset to disallow writing any received dynamic metadata.
+  MetadataNamespaces receiving_namespaces = 2;
 }

envoy/extensions/filters/network/http_connection_manager/v3/http_connection_manager.proto:

--- shake256:5276dadd0bf0197f13e594b00a4b753a1cf6343d0096227d3fb065e3b8b670d3b879f6002183992964b8dd9f9d27b50864572c7ff4ff437bf89878f89992376e  envoy/extensions/filters/network/http_connection_manager/v3/http_connection_manager.proto
+++ shake256:95ea3b89fcffe04a590089cfea147025b8e96d0000467fea10539f5824c9002a55b828d8c3b8bc2e504a2962a5b229e3bce79cad9746661a1d12a548af8965e5  envoy/extensions/filters/network/http_connection_manager/v3/http_connection_manager.proto
@@ -39,7 +39,7 @@
 // HTTP connection manager :ref:`configuration overview <config_http_conn_man>`.
 // [#extension: envoy.filters.network.http_connection_manager]
 
-// [#next-free-field: 62]
+// [#next-free-field: 63]
 message HttpConnectionManager {
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.config.filter.network.http_connection_manager.v2.HttpConnectionManager";
@@ -664,6 +664,18 @@
   // 5000 milliseconds (5 seconds) if this option is not specified.
   google.protobuf.Duration drain_timeout = 12;
 
+  // Percentage-based jitter for ``drain_timeout``. If set, the actual drain grace period
+  // is extended by a random duration up to ``drain_timeout * jitter / 100`` per connection.
+  // This staggers the final GOAWAY (and connection close) across time so that connections
+  // entering the drain state simultaneously do not all complete draining at the same instant,
+  // mitigating thundering-herd reconnects. If not set, no jitter is added.
+  //
+  // This is analogous to
+  // :ref:`max_connection_duration_jitter
+  // <envoy_v3_api_field_config.core.v3.HttpProtocolOptions.max_connection_duration_jitter>`,
+  // but applied to the drain grace timer rather than the connection duration timer.
+  type.v3.Percent drain_timeout_jitter = 62;
+
   // The delayed close timeout is for downstream connections managed by the HTTP connection manager.
   // It is defined as a grace period after connection close processing has been locally initiated
   // during which Envoy will wait for the peer to close (i.e., a TCP FIN/RST is received by Envoy

envoy/extensions/filters/network/mongo_proxy/v3/mongo_proxy.proto:

--- shake256:ed382c5021bdd2dcdead147278a9b343cd78fa4e1e6142a09f0479375edf664c6d40fe69b7bcdcaf4a6ac500e5be27bfb824c402d6934695e605b5540ce6f17a  envoy/extensions/filters/network/mongo_proxy/v3/mongo_proxy.proto
+++ shake256:6ef88675ec00d3aec0ad8a311d84a2296974a7196f7809affe351951d799c4389d95a329bfc2e9b6cdd60bb53f8be6c956c0359da90373c0b226df9caed5bd3c  envoy/extensions/filters/network/mongo_proxy/v3/mongo_proxy.proto
@@ -4,6 +4,8 @@
 
 import "envoy/extensions/filters/common/fault/v3/fault.proto";
 
+import "google/protobuf/wrappers.proto";
+
 import "udpa/annotations/status.proto";
 import "udpa/annotations/versioning.proto";
 import "validate/validate.proto";
@@ -18,7 +20,7 @@
 // MongoDB :ref:`configuration overview <config_network_filters_mongo_proxy>`.
 // [#extension: envoy.filters.network.mongo_proxy]
 
-// [#next-free-field: 6]
+// [#next-free-field: 7]
 message MongoProxy {
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.config.filter.network.mongo_proxy.v2.MongoProxy";
@@ -46,4 +48,7 @@
   // Note that metrics will not be emitted for "find" commands, since those are considered
   // queries, and metrics for those are emitted under a dedicated "query" namespace.
   repeated string commands = 5;
+
+  // The maximum depth of a BSON document that Envoy will parse. Defaults to 100.
+  google.protobuf.UInt32Value max_bson_depth = 6 [(validate.rules).uint32 = {gt: 0}];
 }

envoy/extensions/filters/network/reverse_tunnel/v3/drain_aware_hcm.proto:

--- shake256:e94342f931679294c5668dadbbcbdd2d43d962e44a6017de46363582a4b449fad96be21769cb82507df29a74fe55489922e3fefe9bec6904eae3250a3ec1b00a  envoy/extensions/filters/network/reverse_tunnel/v3/drain_aware_hcm.proto
+++ shake256:f7f5312ba2a7f157bc5e6685f73718984650aedcfaec3ded6e01535805ecc7fe826ab1d6473647e6e9ca7b533306fd533956f31729650c5cec7656ae94adcd3e  envoy/extensions/filters/network/reverse_tunnel/v3/drain_aware_hcm.proto
@@ -26,4 +26,10 @@
 message DrainAwareHttpConnectionManager {
   // The underlying HCM configuration to apply.
   http_connection_manager.v3.HttpConnectionManager hcm_config = 1;
+
+  // When true, a peer-initiated GOAWAY on a reverse tunnel makes the initiator drop the draining
+  // tunnel and dial a replacement, so capacity is restored before the old tunnel closes while its
+  // in-flight streams finish. Default false, so the behavior is opt-in and unconfigured listeners
+  // are unaffected.
+  bool enable_drain_with_goaway = 2;
 }

envoy/extensions/filters/network/reverse_tunnel/v3/reverse_tunnel.proto:

--- shake256:e0ac16da7df32102eea87b502c619e734b84c9b3fb4b079fac46855d7289d7e1246d02d410fa6fec6b286b55c3c99a68c68e77e701640108b875e51597d754e8  envoy/extensions/filters/network/reverse_tunnel/v3/reverse_tunnel.proto
+++ shake256:323d69a823d3e0ff9288f728451afca371eef0ca458a73293c124822e90f70d53af71754605423710074150e30f5d2cbbaebf49117f93d7d85de1a0052885b2c  envoy/extensions/filters/network/reverse_tunnel/v3/reverse_tunnel.proto
@@ -96,7 +96,7 @@
 // Configuration for the reverse tunnel network filter.
 // This filter handles reverse tunnel connection acceptance and rejection by processing
 // HTTP requests where required identification values are provided via HTTP headers.
-// [#next-free-field: 7]
+// [#next-free-field: 9]
 message ReverseTunnel {
   // Ping interval for health checks on established reverse tunnel connections.
   // If not specified, defaults to ``2 seconds``.
@@ -133,4 +133,16 @@
   // via ``x-envoy-reverse-tunnel-upstream-cluster-name`` header. Connections with mismatched or missing
   // cluster names are rejected with HTTP ``400 Bad Request``. When empty, no cluster name validation is performed.
   string required_cluster_name = 6 [(validate.rules).string = {max_len: 255 ignore_empty: true}];
+
+  // Accept the handshake as an HTTP/1.1 ``Upgrade`` exchange (``Upgrade: reverse-tunnel``,
+  // reply ``101``) so HTTP proxies can route the handshake and splice the tunnel
+  // afterward. Non-upgrade requests are rejected with ``426``. The initiator must set this
+  // flag to the same value.
+  // Defaults to ``false``.
+  bool use_http_upgrade = 7;
+
+  // When true, skip worker-thread rebalancing for accepted reverse tunnel connections.
+  // This avoids the cross-worker lock in pickLeastLoadedSocketManager.
+  // Default: false (rebalancing enabled).
+  bool skip_rebalancing = 8;
 }

envoy/extensions/filters/network/tcp_proxy/v3/tcp_proxy.proto:

--- shake256:8ff13155179a98aba30f110331cedf1d77369597acbf5c87d52f414c484aef53a2820a949db85adf813e1be5d3bc867f4e0748b949ce4f13bc624913ff17078a  envoy/extensions/filters/network/tcp_proxy/v3/tcp_proxy.proto
+++ shake256:ca31ea64c3f60b2281935bbb9e7c15b7ba610c02c80f75ee2bbbdd4631b4fc0e44575161eb5252f379f5ea0717b08f23664df6137f519ce900ddabd54a340309  envoy/extensions/filters/network/tcp_proxy/v3/tcp_proxy.proto
@@ -6,6 +6,7 @@
 import "envoy/config/core/v3/backoff.proto";
 import "envoy/config/core/v3/base.proto";
 import "envoy/config/core/v3/config_source.proto";
+import "envoy/config/core/v3/extension.proto";
 import "envoy/config/core/v3/proxy_protocol.proto";
 import "envoy/extensions/filters/network/http_connection_manager/v3/http_connection_manager.proto";
 import "envoy/type/v3/hash_policy.proto";
@@ -80,7 +81,7 @@
   APPEND_IF_EXISTS_OR_ADD = 2;
 }
 
-// [#next-free-field: 24]
+// [#next-free-field: 25]
 message TcpProxy {
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.config.filter.network.tcp_proxy.v2.TcpProxy";
@@ -119,7 +120,7 @@
   // Configuration for tunneling TCP over other transports or application layers.
   // Tunneling is supported over HTTP/1.1 and HTTP/2. The upstream protocol is
   // determined by the cluster configuration.
-  // [#next-free-field: 10]
+  // [#next-free-field: 11]
   message TunnelingConfig {
     option (udpa.annotations.versioning).previous_message_type =
         "envoy.config.filter.network.tcp_proxy.v2.TcpProxy.TunnelingConfig";
@@ -200,6 +201,12 @@
     // This enables customizing the key used by access log formatters such as
     // ``%DYNAMIC_METADATA(envoy.filters.network.tcp_proxy:<key>)%``.
     string request_id_metadata_key = 9;
+
+    // Specifies a collection of Formatter plugins that can be used in substitution formatters
+    // in ``headers_to_add``.
+    // See the formatters extensions documentation for details.
+    // [#extension-category: envoy.formatter]
+    repeated config.core.v3.TypedExtensionConfig formatters = 10;
   }
 
   message OnDemand {
@@ -390,4 +397,11 @@
   //   Use this carefully with server-first protocols. The upstream may send data before
   //   receiving anything from downstream, which could fill the early data buffer.
   google.protobuf.UInt32Value max_early_data_bytes = 22 [(validate.rules).uint32 = {lte: 1048576}];
+
+  // If set to ``true``, the TCP proxy checks if the downstream connection was marked as drained
+  // after each read or write. When drain close is requested for the listener's traffic direction,
+  // the downstream connection is closed with ``FlushWrite``.
+  //
+  // This is disabled by default for backward compatibility.
+  google.protobuf.BoolValue check_drain_close = 24;
 }

envoy/extensions/load_balancing_policies/client_side_weighted_round_robin/v3/client_side_weighted_round_robin.proto:

--- shake256:894ee44a49e973f8c2e094bfa3053351c0826c3da87d2f0f54d1d6c907892e49355a9437d0c938581bae75af5da62139bb562d43989ea7af85cc643cff01ac52  envoy/extensions/load_balancing_policies/client_side_weighted_round_robin/v3/client_side_weighted_round_robin.proto
+++ shake256:ed80461fd767155c24d6fdfaa7f620d4db8ac5868cf1a1bbfb302f4ecc1790582dc99575a1003b34d949bb8f27c6e92f4ed22e2a5007f4c92af3cf49d10611c4  envoy/extensions/load_balancing_policies/client_side_weighted_round_robin/v3/client_side_weighted_round_robin.proto
@@ -44,7 +44,7 @@
 // See the :ref:`load balancing architecture
 // overview<arch_overview_load_balancing_types>` for more information.
 //
-// [#next-free-field: 9]
+// [#next-free-field: 10]
 message ClientSideWeightedRoundRobin {
   // Whether to enable out-of-band utilization reporting collection from
   // the endpoints. By default, per-request utilization reporting is used.
@@ -88,4 +88,9 @@
   // Configuration for slow start mode.
   // If this configuration is not set, slow start will not be not enabled.
   common.v3.SlowStartConfig slow_start_config = 8;
+
+  // Optional overrides for the OOB reporting connection (alternative port,
+  // ``:authority``, transport socket selection). Honored only when
+  // ``enable_oob_load_report`` is true.
+  common.v3.OrcaOobReportingConfig oob_reporting_config = 9;
 }

envoy/extensions/load_balancing_policies/common/v3/common.proto:

--- shake256:87692495bfc4ebe3af7e717827ef318d02ea70d14321bdb6a752efb7b21fb7ea727e7c085cfbac1b698eab1506a9ac73b97ba663a8ddb5d1a24eea0dc07fd5c4  envoy/extensions/load_balancing_policies/common/v3/common.proto
+++ shake256:7617bafaedc15daaf00b90c6fcdb3078dcba4d99d0d280ebadd1e9b19c871ca9f3374e9cd358afd91c0d232a75687bc861c7ca3ffdc48d75d6fa82c9b6aab406  envoy/extensions/load_balancing_policies/common/v3/common.proto
@@ -7,6 +7,7 @@
 import "envoy/type/v3/percent.proto";
 
 import "google/protobuf/duration.proto";
+import "google/protobuf/struct.proto";
 import "google/protobuf/wrappers.proto";
 
 import "envoy/annotations/deprecation.proto";
@@ -159,3 +160,29 @@
   // will be ignored.
   repeated config.route.v3.RouteAction.HashPolicy hash_policy = 3;
 }
+
+// Connection overrides for the ORCA out-of-band (OOB) reporting stream, used by
+// load balancing policies that consume ORCA load reports (e.g.
+// :ref:`client_side_weighted_round_robin
+// <envoy_v3_api_msg_extensions.load_balancing_policies.client_side_weighted_round_robin.v3.ClientSideWeightedRoundRobin>`).
+// Whether and when OOB reporting runs is controlled by the embedding policy.
+message OrcaOobReportingConfig {
+  // Optional alternative port for the OOB reporting connection, for example an
+  // ORCA reporting sidecar listening on a dedicated port. If 0 or unset, the
+  // port of the host's ORCA reporting address is used. Ignored for non-IP
+  // (pipe/UDS) host addresses.
+  uint32 port_value = 1 [(validate.rules).uint32 = {lte: 65535}];
+
+  // Value of the ``:authority`` header on the OOB gRPC stream. If empty, the
+  // endpoint hostname is used, then the dialed address, then the cluster name.
+  string authority = 2
+      [(validate.rules).string = {well_known_regex: HTTP_HEADER_VALUE strict: false}];
+
+  // Optional key/value pairs used to select a transport socket from the
+  // cluster's :ref:`transport_socket_matches
+  // <envoy_v3_api_field_config.cluster.v3.Cluster.transport_socket_matches>`
+  // for the OOB connection. If unset, or if no match is found, the cluster's
+  // default transport socket is used. ALPN ``h2`` is always forced on the OOB
+  // connection regardless of this setting.
+  google.protobuf.Struct transport_socket_match_criteria = 3;
+}

envoy/extensions/network/dns_resolver/cares/v3/cares_dns_resolver.proto:

--- shake256:f0a4d81196f500745a531f588d89c7622fe7d394cb4b967d4a12de27a8b9b9cbc84bfd0ba97446abf7d556c15a5071830c1599a7fe37028e9b5149c85afd7cce  envoy/extensions/network/dns_resolver/cares/v3/cares_dns_resolver.proto
+++ shake256:2427c045d79d2731c598c802ecf997935f8195ddc454465c8dcfe7d9f3d20c4304a0ed54bf57b2530d9cd4f789fb1c0c6da605ec3aae83bd1e6f9c5a3408e543  envoy/extensions/network/dns_resolver/cares/v3/cares_dns_resolver.proto
@@ -21,7 +21,7 @@
 // [#extension: envoy.network.dns_resolver.cares]
 
 // Configuration for c-ares DNS resolver.
-// [#next-free-field: 12]
+// [#next-free-field: 13]
 message CaresDnsResolverConfig {
   // A list of DNS resolver addresses.
   // :ref:`use_resolvers_as_fallback <envoy_v3_api_field_extensions.network.dns_resolver.cares.v3.CaresDnsResolverConfig.use_resolvers_as_fallback>`
@@ -113,4 +113,14 @@
   //
   // Default is false.
   bool reinit_channel_on_timeout = 11;
+
+  // The maximum duration (in seconds) for which DNS responses will be cached by c-ares.
+  //
+  // If set to a non-zero value, the query cache is enabled and will respect the
+  // TTL provided in the DNS response, up to this maximum limit.
+  //
+  // .. note::
+  //   While the underlying c-ares library defaults to 1 hour, Envoy's default
+  //   for this field is 0, which disables the query cache entirely.
+  google.protobuf.UInt32Value qcache_max_ttl = 12 [(validate.rules).uint32 = {gte: 0}];
 }

envoy/extensions/network/socket_interface/v3/default_socket_interface.proto:

--- shake256:c4b373033fef9f58de1beaff37f5c835eecbc378b775d04d08147b3cbacbfc6629923f109eb754096604444c7791a43edbe0a15398843c7790a20aac6e82ae1c  envoy/extensions/network/socket_interface/v3/default_socket_interface.proto
+++ shake256:c0b8cacef281eaec500f13691e055259c28c5c56f06be4393eaf634ad3ecc9cff662fd9847c14a0b2b7a2992f0e3ebed1d324ea209a3fd242253184083e533ce  envoy/extensions/network/socket_interface/v3/default_socket_interface.proto
@@ -5,6 +5,7 @@
 import "google/protobuf/wrappers.proto";
 
 import "udpa/annotations/status.proto";
+import "validate/validate.proto";
 
 option java_package = "io.envoyproxy.envoy.extensions.network.socket_interface.v3";
 option java_outer_classname = "DefaultSocketInterfaceProto";
@@ -14,33 +15,81 @@
 
 // [#protodoc-title: Default socket interface configuration]
 
-// Configuration for default socket interface that relies on OS dependent syscall to create
+// Configuration for the default socket interface that relies on OS-dependent syscalls to create
 // sockets.
 message DefaultSocketInterface {
-  // io_uring options. io_uring is only valid in Linux with at least kernel version 5.11. Otherwise,
-  // Envoy will fall back to use the default socket API. If not set then io_uring will not be
-  // enabled.
+  // Options for ``io_uring``-based socket I/O. ``io_uring`` is only supported on Linux with
+  // kernel version 5.11 or later. On unsupported platforms, Envoy falls back to the default
+  // socket API.
+  //
+  // .. note::
+  //
+  //   If not set, ``io_uring`` will not be enabled and the standard epoll-based I/O path
+  //   is used.
   IoUringOptions io_uring_options = 1;
 }
 
+// Configuration for ``io_uring``-based asynchronous I/O.
+//
+// Each worker thread creates its own ``io_uring`` instance during initialization. Operations
+// are submitted to the submission queue (SQ) and completions are reaped from the completion
+// queue (CQ) via an eventfd integrated with the worker's event loop.
+//
+// .. warning::
+//
+//   ``io_uring`` support is experimental and its performance characteristics depend heavily on
+//   the kernel version.
+//
+// [#next-free-field: 8]
 message IoUringOptions {
-  // The size for io_uring submission queues (SQ). io_uring is built with a fixed size in each
-  // thread during configuration, and each io_uring operation creates a submission queue
-  // entry (SQE). The default is 1000.
+  // The number of entries in the ``io_uring`` submission queue (SQ). Each in-flight I/O
+  // operation requires one SQE. The completion queue (CQ) is sized at ``2x`` this value
+  // to provide overflow headroom. If not specified, defaults to 1000.
   google.protobuf.UInt32Value io_uring_size = 1;
 
-  // Enable io_uring submission queue polling (SQPOLL). io_uring SQPOLL mode polls all SQEs in the
-  // SQ in the kernel thread. io_uring SQPOLL mode may reduce latency and increase CPU usage as a
-  // cost. The default is false.
+  // Enables ``io_uring`` submission queue polling (``SQPOLL``). When enabled, a dedicated
+  // kernel thread polls the SQ for new entries, eliminating the ``io_uring_enter()`` syscall
+  // on submission. This may reduce latency at the cost of increased CPU usage.
+  // If not specified, defaults to false.
   bool enable_submission_queue_polling = 2;
 
-  // The size of an io_uring socket's read buffer. Each io_uring read operation will allocate a
-  // buffer of the given size. If the given buffer is too small, the socket will have read multiple
-  // times for all the data. The default is 8192.
+  // The starting size in bytes of the buffer for each ``readv``-based ``io_uring`` read. Envoy
+  // grows the next read up to 16 times this size while reads keep filling the buffer and resets it
+  // otherwise, so large transfers use fewer reads. When ``enable_multishot_receive`` is set, this
+  // is also the size of each kernel-provided buffer. If not specified, defaults to 8192.
   google.protobuf.UInt32Value read_buffer_size = 3;
 
-  // The write timeout of an io_uring socket on closing in ms. io_uring writes and closes
-  // asynchronously. If the remote stops reading, the io_uring write operation may never complete.
-  // The operation is canceled and the socket is closed after the timeout. The default is 1000.
+  // The timeout in milliseconds to wait for pending write operations to complete when closing
+  // a socket. ``io_uring`` writes are asynchronous. If the remote peer stops reading, a write
+  // may never complete. After this timeout, pending writes are canceled and the socket is
+  // closed. If not specified, defaults to 1000.
   google.protobuf.UInt32Value write_timeout_ms = 4;
+
+  // The high watermark in bytes for the write buffer. When the amount of pending write data
+  // exceeds this threshold, the socket stops accepting new writes from the connection so that
+  // backpressure propagates to the upper layers. If not specified, defaults to 131072 (128 KiB).
+  // When set, the value must be at least 4096 (4 KiB).
+  google.protobuf.UInt32Value write_high_watermark_bytes = 5
+      [(validate.rules).uint32 = {gte: 4096}];
+
+  // The low watermark in bytes for the write buffer. After the buffer has exceeded
+  // ``write_high_watermark_bytes`` and writes were paused, the socket resumes accepting writes
+  // once the pending write data drops to or below this value.
+  // If not specified, defaults to 16384 (16 KiB).
+  // When set, the value must be at least 1024 (1 KiB).
+  //
+  // .. note::
+  //
+  //   This value must be less than ``write_high_watermark_bytes``. If misconfigured, it is
+  //   clamped to ``write_high_watermark_bytes / 2``.
+  google.protobuf.UInt32Value write_low_watermark_bytes = 6 [(validate.rules).uint32 = {gte: 1024}];
+
+  // Enables ``multishot`` reads backed by a kernel-provided buffer ring. A single ``recv`` is armed
+  // per socket and the kernel keeps delivering data as it arrives without a new submission per
+  // read, which reduces event loop wakeups and read submissions for read-heavy workloads. The ring
+  // holds ``io_uring_size`` buffers rounded up to a power of two and capped at 4096, each
+  // ``read_buffer_size`` bytes, so each worker thread uses up to that buffer count times
+  // ``read_buffer_size`` bytes for the pool. Requires Linux kernel 6.0 or later. On older kernels,
+  // Envoy falls back to ``readv``-based reads. If not specified, defaults to false.
+  bool enable_multishot_receive = 7;
 }

envoy/extensions/path/match/uri_template/v3/uri_template_match.proto:

--- shake256:b59aa69fbb5a3fd019d0629969b596f1ef33d11c2db37b7167c80d49825c56ba11514538b5b5e18d9305862104bfd2ce2232b462a3632484756a12bdf3287943  envoy/extensions/path/match/uri_template/v3/uri_template_match.proto
+++ shake256:8d63a86e1ba331db3c1eb63403cb19840d08f75120d4e70dda5b508eb588b9d2ae8c7772bbc76bb08139301074b556635b685264ca462c1392d37f808a927ca4  envoy/extensions/path/match/uri_template/v3/uri_template_match.proto
@@ -31,6 +31,10 @@
 //
 // * ``{name=**}`` : A named variable matching zero or more path segments.
 //
+// * ``prefix{name}suffix`` : A named variable with surrounding literal text within a single path
+//      segment. For example, ``v{version}`` or ``{id}.json``. The variable captures only the
+//      dynamic portion; the prefix and suffix must match literally.
+//
 //
 // For example:
 //
@@ -39,6 +43,9 @@
 // * ``/videos/{file}`` would match ``/videos/1080p5000_00001.m4s``
 //
 // * ``/**.mpd`` would match ``/content/123/india/dash/55/manifest.mpd``
+//
+// * ``/api/v{version}/users/{id}.json`` would match ``/api/v2/users/456.json`` and
+//      capture ``version=2`` and ``id=456``.
 message UriTemplateMatchConfig {
   string path_template = 1 [(validate.rules).string = {min_len: 1 max_len: 256}];
 }

envoy/extensions/resource_monitors/fixed_heap/v3/fixed_heap.proto:

--- shake256:12822650ee1addeed10c840b45b21a1578afff4ad262643364a5379a198fcf23dcb812e68cb8be40cea686ad0d4b6e575e1cd439a8ad5a261980f56e4b4f7ee4  envoy/extensions/resource_monitors/fixed_heap/v3/fixed_heap.proto
+++ shake256:408e426cc34122459981ce3a978710b67ce7d2b5d105e81434799f1b916114bea15caf7249eefcb47e4f4bea89667852b7a1c8d790edb5a8eba00adb260309d7  envoy/extensions/resource_monitors/fixed_heap/v3/fixed_heap.proto
@@ -2,9 +2,10 @@
 
 package envoy.extensions.resource_monitors.fixed_heap.v3;
 
+import "envoy/config/core/v3/base.proto";
+
 import "udpa/annotations/status.proto";
 import "udpa/annotations/versioning.proto";
-import "validate/validate.proto";
 
 option java_package = "io.envoyproxy.envoy.extensions.resource_monitors.fixed_heap.v3";
 option java_outer_classname = "FixedHeapProto";
@@ -22,5 +23,14 @@
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.config.resource_monitor.fixed_heap.v2alpha.FixedHeapConfig";
 
-  uint64 max_heap_size_bytes = 1 [(validate.rules).uint64 = {gt: 0}];
+  // Static value for max heap size in bytes set at startup.
+  // Exactly one of max_heap_size_bytes or max_heap_size_bytes_runtime must be set.
+  // If set, the expected value must be greater than ``0``, otherwise validation will fail.
+  uint64 max_heap_size_bytes = 1;
+
+  // Runtime overlay for max heap size in bytes. When set, the value can be overridden
+  // at runtime during startup or later without restart.
+  // Exactly one of max_heap_size_bytes or max_heap_size_bytes_runtime must be set.
+  // If set, the expected value must be greater than ``0``, otherwise validation will fail.
+  config.core.v3.RuntimeUInt64 max_heap_size_bytes_runtime = 2;
 }

envoy/extensions/stat_sinks/open_telemetry/v3/open_telemetry.proto:

--- shake256:bffab6b3fe18a9471932c49ff69ad67b2f4082bb3cbbbd90f28202e2281cc5a58df44d992feee581b7ccff04d7ee782b374f12da34ecc39a08d45ddcfaa342ae  envoy/extensions/stat_sinks/open_telemetry/v3/open_telemetry.proto
+++ shake256:2493a7eda4bca154b91ea0cefed9b3256f13d1896a9265b4306e8a29cccde89e26baa225880cd46f877fed825bdc337aaf045ef2ed42786eaa2124f221e3a3b6  envoy/extensions/stat_sinks/open_telemetry/v3/open_telemetry.proto
@@ -24,7 +24,7 @@
 // Stats configuration proto schema for ``envoy.stat_sinks.open_telemetry`` sink.
 // [#extension: envoy.stat_sinks.open_telemetry]
 
-// [#next-free-field: 10]
+// [#next-free-field: 11]
 message SinkConfig {
   // ConversionAction is used to convert a stat to a metric. If a stat matches,
   // the metric_name and static_metric_labels will be
@@ -94,4 +94,8 @@
   // - ``envoy.extensions.stat_sinks.open_telemetry.v3.SinkConfig.ConversionAction``.
   // If stats are not matched, they will be directly converted to OTLP metrics as usual.
   xds.type.matcher.v3.Matcher custom_metric_conversions = 8;
+
+  // Maximum number of data points per request. If explicitly set to 0, there is no limit. If unset, it currently defaults to no limit.
+  // When the maximum number of data points is reached, the remaining data points will be sent in subsequent requests.
+  uint32 max_data_points_per_request = 10;
 }

envoy/extensions/transport_sockets/quic/v3/quic_transport.proto:

--- shake256:5c82678245095a18a9122648576780eb70221f36a71127ab80f6edd19b9c2316831b39b49848b5df74c31c208e4e16220772d4b0d8d47616ec718ed88f7edcab  envoy/extensions/transport_sockets/quic/v3/quic_transport.proto
+++ shake256:a73ea65dd0a92900ce187d3404a8d0a85c928a68ef98fdaa42597900c5e2239d25e2d3331439c2ca817927acd69df65d5e6d72724f5f53a03dd230c20425b45a  envoy/extensions/transport_sockets/quic/v3/quic_transport.proto
@@ -27,6 +27,10 @@
   // If false, QUIC will tell TLS to reject any early data and to stop issuing 0-RTT credentials with resumption session tickets. This will prevent clients from sending 0-RTT requests.
   // Default to true.
   google.protobuf.BoolValue enable_early_data = 2;
+
+  // If false, TLS session tickets are not issued and accepted by QUIC.
+  // Default to true.
+  google.protobuf.BoolValue enable_resumption = 3;
 }
 
 // Configuration for Upstream QUIC transport socket. This provides Google's implementation of Google QUIC and IETF QUIC to Envoy.

envoy/extensions/transport_sockets/tls/v3/common.proto:

--- shake256:e5c7d2878ae07f98b7b076de1060c76cae457efb0558322736cdc1139f8c38c3bbada85ae0efbe867f5e8aae201c82d0aadba8f88a4c217cfc315c96a4b1ea98  envoy/extensions/transport_sockets/tls/v3/common.proto
+++ shake256:e1e0d5919ceef76ce7a6329062704ac251f7b9285d3493b1612cd9fa2191d8cb23cb5e78569b409aa3706a3adb7bedf2e6e406f19fcac2a0f7a0c734e2babb07  envoy/extensions/transport_sockets/tls/v3/common.proto
@@ -57,9 +57,44 @@
     //
     // .. attention::
     //
-    //   Please refer to `BoringSSL policies <https://boringssl.googlesource.com/boringssl/+/refs/tags/0.20240913.0/include/openssl/ssl.h#5608>`_
+    //   Please refer to the `BoringSSL FIPS_202205 compliance policy <https://boringssl.googlesource.com/boringssl/+/refs/tags/0.20240913.0/include/openssl/ssl.h#5608>`_
     //   for details.
     FIPS_202205 = 0;
+
+    // CNSA2_202603 configures a TLS connection to use:
+    //
+    //   * Only TLS 1.3, with AES-256-GCM.
+    //   * Only ML-KEM-1024 for key agreement.
+    //   * For handshake signatures, only ECDSA with P-384 and SHA-384, or RSA
+    //     with SHA-384.
+    //
+    // Note: this setting aids with compliance with CNSA requirements but does not
+    // guarantee it. Careful reading of ``draft-becker-cnsa2-tls-profile`` is
+    // recommended.
+    //
+    // .. attention::
+    //
+    //   Please refer to the `BoringSSL CNSA2_202603 compliance policy <https://boringssl.googlesource.com/boringssl/+/refs/tags/0.20260413.0/include/openssl/ssl.h#6293>`_
+    //   for details.
+    CNSA2_202603 = 1;
+
+    // CNSA1_202603 configures a TLS connection to use:
+    //   * TLS 1.2 or TLS 1.3.
+    //   * For TLS 1.2, only TLS_ECDHE_[ECDSA|RSA]_WITH_AES_256_GCM_SHA384.
+    //   * For TLS 1.3, only AES-256-GCM.
+    //   * ML-KEM-1024 or P-384 for key agreement, preferring ML-KEM-1024 if the
+    //     client supports it.
+    //   * For handshake signatures, only ECDSA with P-384 and SHA-384, or RSA
+    //     with SHA-384.
+    //
+    // Note: this setting aids with compliance with CNSA requirements but does not
+    // guarantee it. Careful reading of RFC 9151 is recommended.
+    //
+    // .. attention::
+    //
+    //   Please refer to the `BoringSSL CNSA1_202603 compliance policy <https://boringssl.googlesource.com/boringssl/+/refs/tags/0.20260413.0/include/openssl/ssl.h#6280>`_
+    //   for details.
+    CNSA1_202603 = 2;
   }
 
   // Minimum TLS protocol version. By default, it's ``TLSv1_2`` for both clients and servers.
@@ -369,7 +404,7 @@
   string oid = 3;
 }
 
-// [#next-free-field: 18]
+// [#next-free-field: 19]
 message CertificateValidationContext {
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.api.v2.auth.CertificateValidationContext";
@@ -594,4 +629,28 @@
   // in OpenSSL 1.1.x and newer versions of BoringSSL in that the trust anchor is included.
   // Trusted issues are specified by setting :ref:`trusted_ca <envoy_v3_api_field_extensions.transport_sockets.tls.v3.CertificateValidationContext.trusted_ca>`
   google.protobuf.UInt32Value max_verify_depth = 16 [(validate.rules).uint32 = {lte: 100}];
+
+  // If true, the server does not include the trusted-CA distinguished names in the
+  // TLS ``CertificateRequest`` message. CAs from :ref:`trusted_ca
+  // <envoy_v3_api_field_extensions.transport_sockets.tls.v3.CertificateValidationContext.trusted_ca>`
+  // are still used to validate presented client certificates; only the wire
+  // advertisement changes.
+  //
+  // This is useful when the configured CA set is large enough that the
+  // ``CertificateRequest`` would exceed client-side TLS record limits, or when
+  // clients mishandle the CA set in some way.
+  //
+  // .. attention::
+  //
+  //   When enabled, clients that rely on the advertised CA list to select among
+  //   multiple client certificates may now send no certificate or the wrong one;
+  //   validation will then fail with the standard TLS alert.
+  //
+  // This option only affects downstream (server) TLS connections where Envoy sends a
+  // ``CertificateRequest`` to clients. It has no effect on upstream connections.
+  //
+  // Honored by the built-in validator and the SPIFFE validator. Validators that do
+  // not set a client CA list themselves (e.g., the dynamic-modules validator) are
+  // unaffected. Defaults to false.
+  bool suppress_client_ca_list = 18;
 }

envoy/extensions/transport_sockets/tls/v3/tls.proto:

--- shake256:96fc1618d65403ba6252ac34923a8a845f502983f41ed0b6573c7514d19bed6783f4103e08c8b0c0b50ee50a4361cc74889027aad77e3ab89dca6d7e5361000b  envoy/extensions/transport_sockets/tls/v3/tls.proto
+++ shake256:d6ce09b7e5d772dc134ba451fb8c99e1c8e0dc921a49c34ec5d93088e8e050258f4db162d2491a5e0e5d2061d78ab985f7503b06d6eb94bf12f9e5fe8d18a1c5  envoy/extensions/transport_sockets/tls/v3/tls.proto
@@ -73,14 +73,13 @@
   // Defaults to 1, setting this to 0 disables session resumption.
   google.protobuf.UInt32Value max_session_keys = 4;
 
-  // Controls enforcement of the ``keyUsage`` extension in peer certificates. If set to ``true``, the handshake will fail if
-  // the ``keyUsage`` is incompatible with TLS usage.
+  // Controls enforcement of the ``keyUsage`` extension in peer certificates. If set to ``true``,
+  // the handshake will fail if the ``keyUsage`` is incompatible with TLS usage.
   //
-  // .. note::
-  //   The default value is ``true`` (i.e., enforcement on).
+  // .. attention::
   //
-  // The ``ssl.was_key_usage_invalid`` in :ref:`listener metrics <config_listener_stats>` metric will be incremented
-  // for configurations that would fail if this option were enabled.
+  //   This field is deprecated and ignored. Envoy now always enforces the ``keyUsage`` extension
+  //   in peer certificates, making this option unconfigurable.
   google.protobuf.BoolValue enforce_rsa_key_usage = 5
       [deprecated = true, (envoy.annotations.deprecated_at_minor_version) = "3.0"];
 }

envoy/service/network_ext_proc/v3/network_external_processor.proto:

--- shake256:8bd5e085a8a4d58e707005ccc2150b5e4ba95ee45625ee96156e4daa0b9c5e95204c74ea56fcf7f4ee6d28471cb4adcd6b55501c53f4432360641b19f6c3adb5  envoy/service/network_ext_proc/v3/network_external_processor.proto
+++ shake256:e870bf82f1725fad89f9cdbcf6aac0209c0b792523eec0f54ed0c2a277d22c66caaa75a8ccd5ea834b867a991c040594d285be61249fe6d5afc29fc21836673e  envoy/service/network_ext_proc/v3/network_external_processor.proto
@@ -95,7 +95,7 @@
 // ProcessingResponse contains the response from the external processing server to Envoy.
 // Each response corresponds to a ProcessingRequest and indicates how the network
 // traffic should be handled.
-// [#next-free-field: 6]
+// [#next-free-field: 7]
 message ProcessingResponse {
   // DataProcessedStatus indicates whether the data was modified by the external processor.
   enum DataProcessedStatus {
@@ -157,4 +157,21 @@
   // The metadata is not automatically propagated from request to response.
   // The external processor must include any needed metadata in its response.
   google.protobuf.Struct dynamic_metadata = 5;
+
+  // If set to true, Envoy will close the gRPC stream to the external processor
+  // after applying this response. Subsequent data will bypass the ext_proc filter
+  // as if it were configured in SKIP mode.
+  //
+  // .. note::
+  //   This should only be used when there is a strong protocol guarantee
+  //   that no additional data chunks are in-flight on the wire. Because Envoy
+  //   immediately drains its local buffer when forwarding bytes to the external
+  //   processor, if Envoy has already dispatched subsequent data chunks before this
+  //   stream is closed, those in-flight bytes will be permanently lost and not
+  //   injected back into the filter chain.
+  //
+  // This feature is primarily designed for tightly-coupled synchronous protocols,
+  // such as reading the ClientHello during a TLS handshake, where the sender
+  // naturally halts transmission while awaiting the receiver's response.
+  bool close_stream_to_ext_proc_server = 6;
 }

envoy/service/ratelimit/v3/rls.proto:

--- shake256:9641a91435e6e6b8c64e8e68adb42c0ce592170cc68972d4724169361766892b4d2a00b16e4dc9a2863d7b4d05ff1ebd27e820622355d2de4f5d09b7d71983ef  envoy/service/ratelimit/v3/rls.proto
+++ shake256:4d2cdb7b5a97447afa3a31c9430712528fdee48f57628e528e1f9a033d8af309b25ab63085729223f6fc1a5e0514cadbe7574e858edb7e3fb8ce813e579931c6  envoy/service/ratelimit/v3/rls.proto
@@ -209,7 +209,9 @@
   // filter. This metadata lives in a namespace specified by the canonical name of extension filter
   // that requires it:
   //
-  // - :ref:`envoy.filters.http.ratelimit <config_http_filters_ratelimit_dynamic_metadata>` for HTTP filter.
+  // - :ref:`envoy.filters.http.ratelimit <config_http_filters_ratelimit_dynamic_metadata>` for HTTP filter. The default namespace can
+  //   be modified by setting the :ref:`metadata_namespace <envoy_v3_api_field_extensions.filters.http.ratelimit.v3.RateLimit.metadata_namespace>`
+  //   in the filter configuration.
   // - :ref:`envoy.filters.network.ratelimit <config_network_filters_ratelimit_dynamic_metadata>` for network filter.
   // - :ref:`envoy.filters.thrift.rate_limit <config_thrift_filters_rate_limit_dynamic_metadata>` for Thrift filter.
   google.protobuf.Struct dynamic_metadata = 6;

envoy/type/v3/token_bucket.proto:

--- shake256:cdd6fe9a656c7bde8194e9107f48f520b6f73ad7bc8a01b61df2fc56a9a79a09338503cbbcf457e0a9ec23b069851eb6deac656ba2ef31ef19bcc0b5b7fdb69d  envoy/type/v3/token_bucket.proto
+++ shake256:c32272c0fc9a70c1d5da0b778c77ae575973f21f3cf77f7c7505c24fdbc365051cf6fd75f152198973fc47af62d7f491aa5b847df54d9fc030d6606f1772678a  envoy/type/v3/token_bucket.proto
@@ -22,8 +22,9 @@
   option (udpa.annotations.versioning).previous_message_type = "envoy.type.TokenBucket";
 
   // The maximum tokens that the bucket can hold. This is also the number of tokens that the bucket
-  // initially contains.
-  uint32 max_tokens = 1 [(validate.rules).uint32 = {gt: 0}];
+  // initially contains. A value of 0 means the bucket will always be empty and all requests will
+  // be rate limited (i.e., always reject).
+  uint32 max_tokens = 1 [(validate.rules).uint32 = {gte: 0}];
 
   // The number of tokens added to the bucket during each fill interval. If not specified, defaults
   // to a single token.

Comment thread modules/sync/state.json
{
"module_name": "envoyproxy/envoy",
"latest_reference": "v1.38.3"
"latest_reference": "v1.39.0"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[Posted at 2026-07-15T12:30:02Z]

Overall transition

$ casdiff v1.38.3 \
          v1.39.0 \
          --format=markdown

70 files changed: 0 removed, 0 renamed, 14 added, 56 changed content.

Files added:

+ shake256:61e28a793bfedd8bbcfed42c001fffb76f0aa35fd7fd61c0e0e5e177c29ecd26847670a4d41ff43771eecc4aaca15e4c80a8613ddb7307f1f7bc1391c3348940  contrib/envoy/extensions/stat_sinks/wasm_filter/v3/wasm_filter.proto
+ shake256:f74a0b92a5967659929425007d2f764e28273cc4be3aa3c99b4f540adf80e828c345f5ccd5c589da3b78015eae2fe05b36f20ce3a8a193700420da536fc92843  envoy/extensions/clusters/original_dst/v3/original_dst.proto
+ shake256:c43598da8f84e03829c2d36480e6261e4a58501e51d5610a15e5d768ca28c783d22aab37042d8c88a2b45a06e8f253c42d93d5cf8b306819c5c29ccda7e774fb  envoy/extensions/filters/http/ai_protocol_manager/v3/ai_protocol_manager.proto
+ shake256:db9db55c4d2edb5feceba20adc04e8b86855a43a271d7aa969a799b1aa66c67a7cc8254cce74beca89d0107276f283629bea58654f5a6678c106ff5ad13e75fd  envoy/extensions/filters/http/bandwidth_share/v3/bandwidth_share.proto
+ shake256:063f069a102d281650aa59e92baabb00fe306de95ff9bf911e96243e91cfe2863f286f225b22b831cd78f3c81ee5bf980811470613298c18f716bc7d7aacb0cf  envoy/extensions/filters/http/filter_chain/v3/filter_chain.proto
+ shake256:c6845d45deee6f291a0e50876d86f32487b77bb8bd6253e86eaa4a05c96d90c1f5998c2f034936a044fc26d1921bbbd1b972256ef1560f74aeaa98febc5e608d  envoy/extensions/filters/udp/udp_proxy/session/ext_authz/v3/ext_authz.proto
+ shake256:580964d7027f1e0437e8e4a050dc4a7c49eb248e39343e21e86ab4c74cf379e437fc54c6db301bfe3a06d00876722dcd7ffe3de041cb065ad16467f066d5eb31  envoy/extensions/formatter/dynamic_modules/v3/dynamic_modules.proto
+ shake256:d2c656b5bc8d53ba7dc07f2ace68f9344154068899d386c2ee304c3504a3fe306ed2dc21d5a63733e31fbf61cee26d3ba042836788132c533cc61c1941edb887  envoy/extensions/health_checkers/dynamic_modules/v3/dynamic_modules.proto
+ shake256:e54c12aff3d669e5d5b5a9237812c9398e708f353c174da18d25bd76df3b4c6aaa82dda151ad927ee8949e77056c0be405b0e554cef74fc5571da76abce3a122  envoy/extensions/load_balancing_policies/load_aware_locality/v3/load_aware_locality.proto
+ shake256:46b90ba66398297fb23b255464df3c9aca2058cc4b25ecec7d843c087a6419cfa83f4278dd00a6ac6ccb2bf946b139f225c591a965532bf366569829f2e824b4  envoy/extensions/network/socket_interface/sockmap/v3/sockmap.proto
+ shake256:207659b40f09a1eb343e4bee976790b87765f57e9af73739ad595610306d4c1793aef067838761e69533a5243c174e5175fdbd9ddf07e2bc432aa3b3df014d60  envoy/extensions/stat_sinks/dynamic_modules/v3/dynamic_modules.proto
+ shake256:d50262cdc4cfa7209865e048fd309455614d591bd62fe394513489dc3b7b5d487e68a4bf65707264c5aa832c65d0b5fec50ad379366ec7ac419625317d735e32  envoy/extensions/transport_sockets/dynamic_modules/v3/dynamic_modules.proto
+ shake256:b000ca7a7fe72709f0a48f1c825618331159235a7a5f13ebaa4f89943a127068d2f4ec7a0f5474be7716ed0f461f6bce47ff29389ce27edfbe936e39a57473c6  envoy/extensions/upstreams/http/reverse_tunnel/v3/reverse_tunnel_codec.proto
+ shake256:9b2484a11c76b5d389f373a68d702953265802c037fbe2c31b15b31c1ea0f5b34fcecfc4b9885a9e52bc6f8f69659f6ba0df0cd15a23681c87757391b3eec752  envoy/type/v3/scope.proto

Files changed content:

contrib/envoy/extensions/filters/network/mysql_proxy/v3/mysql_proxy.proto:

--- shake256:b358663115fc5d273c2fdeae4177ec77e455e830cc5ed529863f229faa531b643ffac3547d974b0675c3da6ab78f71615926c4ec4b2f065bda15fb84fe456ff7  contrib/envoy/extensions/filters/network/mysql_proxy/v3/mysql_proxy.proto
+++ shake256:d74fc2d2b6e5ef353ba218b7860368943977f3f3cc85d6e08773b9e472669d5c2a1fad8c6fc68b972ef0c33b94d72aa3e8c81e5412a57bfc2acfd842c79ea2be  contrib/envoy/extensions/filters/network/mysql_proxy/v3/mysql_proxy.proto
@@ -20,6 +20,29 @@
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.config.filter.network.mysql_proxy.v1alpha1.MySQLProxy";
 
+  // Downstream SSL operational modes.
+  enum SSLMode {
+    // Do not terminate SSL session initiated by a client.
+    // The MySQL proxy filter will pass all encrypted and unencrypted packets to the upstream server.
+    DISABLE = 0;
+
+    // The MySQL proxy filter will terminate SSL session initiated by a client
+    // and close downstream connections that do not initiate SSL.
+    // The filter will mediate ``caching_sha2_password`` RSA authentication when
+    // the upstream MySQL server requires full authentication over the plaintext connection.
+    // The filter chain must use :ref:`starttls transport socket
+    // <envoy_v3_api_msg_extensions.transport_sockets.starttls.v3.StartTlsConfig>`.
+    REQUIRE = 1;
+
+    // The MySQL proxy filter will accept downstream client's encryption settings.
+    // If the client wants to use clear-text, Envoy will not enforce SSL encryption.
+    // If the client wants to use encryption, Envoy will terminate SSL and mediate
+    // ``caching_sha2_password`` RSA authentication when needed.
+    // The filter chain must use :ref:`starttls transport socket
+    // <envoy_v3_api_msg_extensions.transport_sockets.starttls.v3.StartTlsConfig>`.
+    ALLOW = 2;
+  }
+
   // The human readable prefix to use when emitting :ref:`statistics
   // <config_network_filters_mysql_proxy_stats>`.
   string stat_prefix = 1 [(validate.rules).string = {min_len: 1}];
@@ -27,4 +50,10 @@
   // [#not-implemented-hide:] The optional path to use for writing MySQL access logs.
   // If the access log field is empty, access logs will not be written.
   string access_log = 2;
+
+  // Controls whether to terminate SSL sessions initiated by downstream clients.
+  // If enabled, the filter chain must use
+  // :ref:`starttls transport socket <envoy_v3_api_msg_extensions.transport_sockets.starttls.v3.StartTlsConfig>`.
+  // Defaults to ``DISABLE``.
+  SSLMode downstream_ssl = 3;
 }

contrib/envoy/extensions/filters/network/peer_metadata/v3/peer_metadata.proto:

--- shake256:444199d12077c1e966a9fc88c848f327d799bade7320ee83689ae2a8b667ffbc16f3748d4b5b7b166f6cd8a9e7c889fb4bd361c02747425cb2807156a746ba32  contrib/envoy/extensions/filters/network/peer_metadata/v3/peer_metadata.proto
+++ shake256:3890183b72504fb727fa185bf393cebc2eda01972fab6adef56ea9231d7871e4f40fb015fda77888c7f1436485a3324d06dd29f8eb8bfd45c2e96d2fd8823bad  contrib/envoy/extensions/filters/network/peer_metadata/v3/peer_metadata.proto
@@ -1,13 +1,13 @@
 syntax = "proto3";
 
-package envoy.extensions.filters.network.peer_metadata.v3;
+package envoy.extensions.network_filters.peer_metadata;
 
 import "udpa/annotations/status.proto";
 
-option java_package = "io.envoyproxy.envoy.extensions.filters.network.peer_metadata.v3";
+option java_package = "io.envoyproxy.envoy.extensions.network_filters.peer_metadata";
 option java_outer_classname = "PeerMetadataProto";
 option java_multiple_files = true;
-option go_package = "github.com/envoyproxy/go-control-plane/contrib/envoy/extensions/filters/network/peer_metadata/v3;peer_metadatav3";
+option go_package = "github.com/envoyproxy/go-control-plane/contrib/envoy/extensions/network_filters/peer_metadata";
 option (udpa.annotations.file_status).package_version_status = ACTIVE;
 
 // [#protodoc-title: Peer metadata network filter]
@@ -22,9 +22,25 @@
 // response) and injects it as a data preamble to be consumed by the upstream
 // filter.
 message Config {
-  // Filter state key under which the baggage value encoding the proxy workload
-  // is stored. The upstream filter that populates the baggage header in the
-  // HBONE request should use the same key.
+  // What filter state to use to save the baggage value that encodes the proxy
+  // workload.
+  //
+  // The upstream filter that will populate the baggage header in the HBONE
+  // request should be configured to use the same key.
+  //
+  // Why share baggage value via filter state instead of to configure upstream
+  // filter to use the baggage key value directly?
+  //
+  // ztunnel and waypoint have to be aware of the baggage header format,
+  // because they should be able to parse baggage headers to extract the
+  // metadata and report the metrics. However, pilot does not need to be aware
+  // of the baggage encoding yet.
+  //
+  // If instead of using custom filter to generate baggage header value we just
+  // let pilot generate it, it would spread the logic for generating baggage to
+  // the pilot as well. While not a big deal, if there is no clear reason to do
+  // it, let's not duplicate the implementation of baggage logic in pilot and
+  // just re-use the logic we already have in Envoy.
   string baggage_key = 1;
 }
 

envoy/admin/v3/server_info.proto:

--- shake256:a3701b9fe15fd9effbf59c6641ff43a8678fa55cf0a6d00988250078bcc0bfb3455788295a723433c9d9a9e234149104eb0c1fadb260b1cd572537a60ada71ad  envoy/admin/v3/server_info.proto
+++ shake256:dc6f7ace607947a0df1e52d21918c94d74cc7d8e73d70e0bd252809ed4a30e863758885a12bef4b8da54fda8fe6e830e15a05feae849cd9f3786f44af3f89230  envoy/admin/v3/server_info.proto
@@ -62,7 +62,7 @@
   bool hot_restart_initializing = 8;
 }
 
-// [#next-free-field: 43]
+// [#next-free-field: 44]
 message CommandLineOptions {
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.admin.v2alpha.CommandLineOptions";
@@ -197,6 +197,9 @@
   // See :option:`--enable-fine-grain-logging` for details.
   bool enable_fine_grain_logging = 34;
 
+  // See :option:`--log-stacktrace-single-entry` for details.
+  bool log_stacktrace_single_entry = 43;
+
   // See :option:`--socket-path` for details.
   string socket_path = 35;
 

envoy/config/bootstrap/v3/bootstrap.proto:

--- shake256:7beeecf5ab4b590492940618911fa508d71fee4f33d6c787f74cbca2406ff6e1791dfb4a3f118bf447603c6fdfef5e535d0154b8c785d6884e70cba801283c8b  envoy/config/bootstrap/v3/bootstrap.proto
+++ shake256:c924c48805142874035bca256676bbe44f3cc4b100cb95399e38b7a66941264250981e2c44b4f94fcc10ad054dc5301909f0cdd5cc8e1620e7ab5c27fad12585  envoy/config/bootstrap/v3/bootstrap.proto
@@ -42,7 +42,7 @@
 // <config_overview_bootstrap>` for more detail.
 
 // Bootstrap :ref:`configuration overview <config_overview_bootstrap>`.
-// [#next-free-field: 43]
+// [#next-free-field: 44]
 message Bootstrap {
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.config.bootstrap.v2.Bootstrap";
@@ -433,6 +433,17 @@
   // Optional configuration for memory allocation manager.
   // Memory releasing is only supported for `tcmalloc allocator <https://github.com/google/tcmalloc>`_.
   MemoryAllocatorManager memory_allocator_manager = 41;
+
+  // When enabled, Envoy pins each worker thread to a distinct CPU from the process affinity mask,
+  // worker ``i`` to the ``i-th`` CPU in ascending order. This improves CPU cache and ``NUMA``
+  // locality for high concurrency deployments on bare metal. It is available on Linux only and is
+  // ignored on other platforms. Pinning requires a worker count no greater than the number of CPUs
+  // in the process affinity mask. When the worker count exceeds the available CPUs no worker is
+  // pinned. Pinning is applied once when the workers start, so a later change to the process
+  // affinity mask does not re-pin.
+  //
+  // Defaults to ``false``.
+  bool enable_worker_cpu_affinity = 43;
 }
 
 // Administration interface :ref:`operations documentation
@@ -813,3 +824,31 @@
   // Defaults to ``104857600`` (100 MB).
   uint64 max_unfreed_memory_bytes = 5;
 }
+
+// A placeholder proto so that users can explicitly configure the standard
+// Listener Manager via the bootstrap's :ref:`listener_manager <envoy_v3_api_field_config.bootstrap.v3.Bootstrap.listener_manager>`.
+// [#not-implemented-hide:]
+message ListenerManager {
+}
+
+// A placeholder proto so that users can explicitly configure the standard
+// Validation Listener Manager via the bootstrap's :ref:`listener_manager <envoy_v3_api_field_config.bootstrap.v3.Bootstrap.listener_manager>`.
+// [#not-implemented-hide:]
+message ValidationListenerManager {
+}
+
+// A placeholder proto so that users can explicitly configure the API
+// Listener Manager via the bootstrap's :ref:`listener_manager <envoy_v3_api_field_config.bootstrap.v3.Bootstrap.listener_manager>`.
+// [#not-implemented-hide:]
+message ApiListenerManager {
+  enum ThreadingModel {
+    // Handle HTTP requests on the main Envoy thread which also processes platform-raised events and runs xDS clients.
+    MAIN_THREAD_ONLY = 0;
+
+    // Handle HTTP requests on a standalone worker thread.
+    STANDALONE_WORKER_THREAD = 1;
+  }
+
+  // Default to MainThreadOnly.
+  ThreadingModel threading_model = 1;
+}

envoy/config/cluster/v3/circuit_breaker.proto:

--- shake256:10a21c816540ed52d9dd7002be5d269527d7927a5b55acff457c434c996df2ad57355f996157d4e4fdab2d6db7f1a80c5f1ce94115c3b31cdef782b5c7d26b7b  envoy/config/cluster/v3/circuit_breaker.proto
+++ shake256:e4794b2ebf537fcfde40dbcaad11e36438e6bd2795f18912a18a2241b8d3ec75817ff19534b462dee128fb132f0b6a28b0cfce6d00c2cdd246c16e36d083acff  envoy/config/cluster/v3/circuit_breaker.proto
@@ -5,6 +5,7 @@
 import "envoy/config/core/v3/base.proto";
 import "envoy/type/v3/percent.proto";
 
+import "google/protobuf/duration.proto";
 import "google/protobuf/wrappers.proto";
 
 import "udpa/annotations/status.proto";
@@ -43,6 +44,25 @@
       // This parameter is optional. Defaults to 20%.
       type.v3.Percent budget_percent = 1;
 
+      // An optional duration in which requests will be considered when calculating
+      // the budget for retries. This parameter alters the way in which the retry budget
+      // is calculated, overriding the default behavior when specified.
+      //
+      // By default, when budget_interval is set to 0ms, only presently active
+      // and pending requests are considered when calculating the retry budget.
+      //
+      // When a non-zero budget_interval is specified, new requests are
+      // considered for the duration of budget_interval when calculating
+      // the retry budget.
+      //
+      // For example, if 10 requests start at the same time, with a specified budget_interval
+      // of 100ms, all 10 requests will be considered when calculating the retry
+      // budget for the next 100ms, regardless of if they have completed.
+      // All 10 requests will expire after the budget_interval duration.
+      //
+      // This parameter is optional. Defaults to 0ms.
+      google.protobuf.Duration budget_interval = 3;
+
       // Specifies the minimum retry concurrency allowed for the retry budget. The limit on the
       // number of active retries may never go below this number.
       //

envoy/config/core/v3/base.proto:

--- shake256:5e7d0238586f5b9dcb7eb825f7256694e31cd8082ebd27e23ec810b50a414434f31c6ec652e5bd7aff2d4b6f05f665de1ca58852dd9020af4e70cf1551382d7a  envoy/config/core/v3/base.proto
+++ shake256:7c1daeba42d5b6f8bebe7b0a73688653a9833dece0690015566641da0894361405e5cc995807357a411231ca03efb7d8b45f7266bb2e70a65979707ec5895ada  envoy/config/core/v3/base.proto
@@ -269,6 +269,15 @@
   string runtime_key = 3;
 }
 
+// Runtime derived uint64 with a default when not specified.
+message RuntimeUInt64 {
+  // Default value if runtime value is not available.
+  uint64 default_value = 2;
+
+  // Runtime key to get value for comparison. This value is used if defined.
+  string runtime_key = 3;
+}
+
 // Runtime derived percentage with a default when not specified.
 message RuntimePercent {
   // Default value if runtime value is not available.
@@ -493,6 +502,14 @@
 message WatchedDirectory {
   // Directory path to watch.
   string path = 1 [(validate.rules).string = {min_len: 1}];
+
+  // If set to true, the watcher will also subscribe to file modification events
+  // (``IN_MODIFY`` on Linux) in addition to move events (``IN_MOVED_TO``). This allows
+  // in-place file writes to trigger reload callbacks. Use this when the writing process
+  // cannot use atomic rename (e.g. certain secret managers that write certificate files
+  // directly). By default, only move/rename events are watched, which is the safe choice
+  // for atomic updates (e.g. Kubernetes ConfigMap symlink swaps).
+  bool watch_modify = 2;
 }
 
 // Data source consisting of a file, an inline value, or an environment variable.

envoy/config/core/v3/protocol.proto:

--- shake256:2c60031b4a2065e1deffbb622837f2c346202c538ad277891bf9d5f55565526851d0215a9963f797b671e0a45f8008ea801f2c0536bea38d2e3846196bf16ef0  envoy/config/core/v3/protocol.proto
+++ shake256:d4d225758e4e0bf5fabd550a978db6cf54a2f5c5ad071c377a0ed1e1ac45a79a7defe791ebc852d090e9feca7ffe1913a63b263b8e3b30ae370559627fd51462  envoy/config/core/v3/protocol.proto
@@ -284,7 +284,7 @@
   repeated string canonical_suffixes = 5;
 }
 
-// [#next-free-field: 8]
+// [#next-free-field: 9]
 message HttpProtocolOptions {
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.api.v2.core.HttpProtocolOptions";
@@ -338,6 +338,22 @@
   // <envoy_v3_api_field_extensions.filters.network.http_connection_manager.v3.HttpConnectionManager.drain_timeout>`.
   google.protobuf.Duration max_connection_duration = 3;
 
+  // Percentage-based jitter for ``max_connection_duration``. If set, the actual connection duration
+  // limit is extended by a random duration up to ``max_connection_duration * jitter / 100``.
+  // This staggers connection teardowns across time and prevents a thundering-herd of reconnects
+  // when many connections are established at roughly the same time.
+  // This field is ignored if ``max_connection_duration`` is not set. If not set, no jitter is added.
+  //
+  // .. note::
+  //   This field is currently only honored for downstream connections by the HTTP connection
+  //   manager. It is not yet supported for upstream cluster connections.
+  //
+  // This is analogous to
+  // :ref:`max_downstream_connection_duration_jitter_percentage
+  // <envoy_v3_api_field_extensions.filters.network.tcp_proxy.v3.TcpProxy.max_downstream_connection_duration_jitter_percentage>`
+  // in the TCP proxy filter.
+  type.v3.Percent max_connection_duration_jitter = 8;
+
   // The maximum number of headers (request headers if configured on HttpConnectionManager,
   // response headers when configured on a cluster).
   // If unconfigured, the default maximum number of headers allowed is ``100``.
@@ -445,8 +461,8 @@
   // This is a no-op if ``accept_http_10`` is not true.
   string default_host_for_http_10 = 3;
 
-  // Describes how the keys for response headers should be formatted. By default, all header keys
-  // are lower cased.
+  // Describes how the keys for headers encoded by the HTTP/1 codec should be formatted. By
+  // default, all header keys are lower cased.
   HeaderKeyFormat header_key_format = 4;
 
   // Enables trailers for HTTP/1. By default the HTTP/1 codec drops proxied trailers.
@@ -552,7 +568,7 @@
       [(validate.rules).duration = {gte {nanos: 1000000}}];
 }
 
-// [#next-free-field: 21]
+// [#next-free-field: 23]
 message Http2ProtocolOptions {
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.api.v2.core.Http2ProtocolOptions";
@@ -669,7 +685,7 @@
   // the connection is terminated. For downstream connections the ``opened_streams`` is incremented when
   // Envoy receives complete response headers from the upstream server. For upstream connections the
   // ``opened_streams`` is incremented when Envoy sends the ``HEADERS`` frame for a new stream. The
-  // ``http2.inbound_priority_frames_flood`` stat tracks the number of connections terminated due to
+  // ``http2.inbound_window_update_frames_flood`` stat tracks the number of connections terminated due to
   // flood mitigation. The default ``max_inbound_window_update_frames_per_data_frame_sent`` value is ``10``.
   // Setting this to ``1`` should be enough to support HTTP/2 implementations with basic flow control,
   // but more complex implementations that try to estimate available bandwidth require at least ``2``.
@@ -791,6 +807,26 @@
   // From RFC 9110, https://www.rfc-editor.org/rfc/rfc9110.html#section-5.5:
   // obs-text = %x80-FF
   google.protobuf.BoolValue disallow_obs_text = 20;
+
+  // Configures the initial token count for the RST_STREAM rate limiter used by the ``nghttp2``
+  // server-side connection. This uses a token-bucket algorithm where each received RST_STREAM
+  // frame consumes one token, and tokens are replenished at :ref:`stream_reset_rate
+  // <envoy_v3_api_field_config.core.v3.Http2ProtocolOptions.stream_reset_rate>` per second.
+  // When no tokens remain, ``nghttp2`` sends GOAWAY with ``INTERNAL_ERROR`` to close the
+  // connection, protecting against CVE-2023-44487 (HTTP/2 Rapid Reset). Defaults to ``1000``.
+  //
+  // This option only applies when using ``nghttp2`` as a server. It has no effect on ``oghttp2``
+  // or on client-side connections.
+  google.protobuf.UInt64Value stream_reset_burst = 21;
+
+  // Configures the token replenishment rate (tokens per second) for the RST_STREAM rate limiter
+  // used by the ``nghttp2`` server-side connection. See :ref:`stream_reset_burst
+  // <envoy_v3_api_field_config.core.v3.Http2ProtocolOptions.stream_reset_burst>` for details.
+  // Defaults to ``33``.
+  //
+  // This option only applies when using ``nghttp2`` as a server. It has no effect on ``oghttp2``
+  // or on client-side connections.
+  google.protobuf.UInt64Value stream_reset_rate = 22;
 }
 
 // [#not-implemented-hide:]

envoy/config/endpoint/v3/endpoint_components.proto:

--- shake256:303fb1667359e27d6ec2aece183975387269521eaf32a9092183560a0cfb88c72976ad820c8d3c2dedbdb1821ad3bf90ed231d827343295779098a0905026cfc  envoy/config/endpoint/v3/endpoint_components.proto
+++ shake256:3cd151cf7e10fa2af3d6e7eb3f71df6d937702975ddece19c5f28e2786fbb355dce33ec25bf3f6f4f7c373f99a41f784ca682a9d6fa1860cea0febc64e916a89  envoy/config/endpoint/v3/endpoint_components.proto
@@ -25,6 +25,7 @@
 // [#protodoc-title: Endpoints]
 
 // Upstream host identifier.
+// [#next-free-field: 6]
 message Endpoint {
   option (udpa.annotations.versioning).previous_message_type = "envoy.api.v2.endpoint.Endpoint";
 
@@ -97,6 +98,20 @@
   // sorted by preference order of the addresses. This will only be supported
   // for STATIC and EDS clusters.
   repeated AdditionalAddress additional_addresses = 4;
+
+  // Optional alternative stat name for this endpoint. If not specified, the main address will be used
+  // as the stat name and be extracted as ``envoy.endpoint_address`` tag value in generated stats.
+  // If specified, the ``observability_name`` here will be used to replace the main address.
+  //
+  // .. note::
+  //
+  //   This field is ignored for logical DNS host implementation..
+  //
+  // This is useful when there are duplicate addresses in the cluster, for example when multiple
+  // endpoints share the same address but have different hostnames or metadata.
+  // In this case, the observability name can be used to differentiate between these endpoints in
+  // stats and logs.
+  string observability_name = 5;
 }
 
 // An Endpoint that Envoy can route traffic to.
@@ -139,7 +154,7 @@
 // LbEndpoint list collection. Entries are `LbEndpoint` resources or references.
 // [#not-implemented-hide:]
 message LbEndpointCollection {
-  xds.core.v3.CollectionEntry entries = 1;
+  repeated xds.core.v3.CollectionEntry entries = 1;
 }
 
 // A configuration for an LEDS collection.

envoy/config/listener/v3/listener.proto:

--- shake256:4e49a60a1817f384d5bedf2b91727b267d5543d4cf3f068ab67fa9dc4a35d946b48a1c504604ecf7452801c94b3698c804b67ad075827d30e6005861799fd12c  envoy/config/listener/v3/listener.proto
+++ shake256:8fcdd4fadff652872bc3cd0330cb7811e0b00b481f61ddb37957da05fdba17857f46ab83d350fe11cb88f17b8f7cf656bed0178f212496368adae23c6f6eede3  envoy/config/listener/v3/listener.proto
@@ -106,6 +106,29 @@
           "envoy.api.v2.Listener.ConnectionBalanceConfig.ExactBalance";
     }
 
+    // A connection balancer that steers each new TCP connection to the worker thread pinned to the
+    // CPU that received the connection, using a kernel ``SO_REUSEPORT`` BPF program. This removes
+    // the lock that the :ref:`exact balancer
+    // <envoy_v3_api_msg_config.listener.v3.Listener.ConnectionBalanceConfig.ExactBalance>` takes on
+    // every accept and keeps each connection on a single worker for cache and ``NUMA`` locality. To
+    // realize locality the operator should align ``NIC`` receive steering so connections arrive on
+    // the worker CPUs, for example with receive side scaling or ``IRQ`` affinity.
+    //
+    // It is available on Linux only and requires :ref:`enable_worker_cpu_affinity
+    // <envoy_v3_api_field_config.bootstrap.v3.Bootstrap.enable_worker_cpu_affinity>` so worker ``i``
+    // is pinned to the CPU the program steers to it, :ref:`enable_reuse_port
+    // <envoy_v3_api_field_config.listener.v3.Listener.enable_reuse_port>`, a kernel that supports
+    // reuse port BPF steering, and a worker count no greater than the number of CPUs in the process
+    // affinity mask. When any of these is not met, or if the kernel rejects the steering program at
+    // runtime, the listener keeps serving with the kernel default reuse port hashing and without CPU
+    // locality.
+    //
+    // Worker affinity is fixed when the worker threads start, so a listener added dynamically via LDS
+    // steers with the same mapping. During a hot restart new connections may be steered to the
+    // draining parent process until it exits.
+    message CpuLocalityBalance {
+    }
+
     oneof balance_type {
       option (validate.required) = true;
 
@@ -118,6 +141,12 @@
       // because the only registered member (``envoy.network.connection_balance.dlb``)
       // is disabled. See https://github.com/envoyproxy/envoy/issues/45491.
       core.v3.TypedExtensionConfig extend_balance = 2;
+
+      // If specified, the listener will steer new connections to worker threads using a kernel
+      // ``SO_REUSEPORT`` BPF program. See :ref:`CpuLocalityBalance
+      // <envoy_v3_api_msg_config.listener.v3.Listener.ConnectionBalanceConfig.CpuLocalityBalance>`
+      // for the requirements and fallback behavior.
+      CpuLocalityBalance cpu_locality_balance = 3;
     }
   }
 
@@ -450,21 +479,3 @@
   // to explicitly configure TCP keepalive settings for individual additional addresses.
   core.v3.TcpKeepalive tcp_keepalive = 37;
 }
-
-// A placeholder proto so that users can explicitly configure the standard
-// Listener Manager via the bootstrap's :ref:`listener_manager <envoy_v3_api_field_config.bootstrap.v3.Bootstrap.listener_manager>`.
-// [#not-implemented-hide:]
-message ListenerManager {
-}
-
-// A placeholder proto so that users can explicitly configure the standard
-// Validation Listener Manager via the bootstrap's :ref:`listener_manager <envoy_v3_api_field_config.bootstrap.v3.Bootstrap.listener_manager>`.
-// [#not-implemented-hide:]
-message ValidationListenerManager {
-}
-
-// A placeholder proto so that users can explicitly configure the API
-// Listener Manager via the bootstrap's :ref:`listener_manager <envoy_v3_api_field_config.bootstrap.v3.Bootstrap.listener_manager>`.
-// [#not-implemented-hide:]
-message ApiListenerManager {
-}

envoy/config/metrics/v3/stats.proto:

--- shake256:56d8ee2a04129ea5371264bb7dc739ee4d45d1cb87be72d92e5e54cee26576222fd08d38538b750ce610516e2abd4c2b0a98e14d55ef73cfdf0b823adc7befcb  envoy/config/metrics/v3/stats.proto
+++ shake256:600bf979d68f259c4c3c7c9f75d0d61641735068b506e4fdb0de466226904a3dac12f57cca2907bdaab8f08d6584608222caa9d9d192c40e9de726b0e7bfb4ea  envoy/config/metrics/v3/stats.proto
@@ -44,6 +44,7 @@
 }
 
 // Statistics configuration such as tagging.
+// [#next-free-field: 6]
 message StatsConfig {
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.config.metrics.v2.StatsConfig";
@@ -104,6 +105,19 @@
   //       3600000
   //     ]
   repeated HistogramBucketSettings histogram_bucket_settings = 4;
+
+  // When set to ``true``, tag extractors specified in :ref:`stats_tags
+  // <envoy_v3_api_field_config.metrics.v3.StatsConfig.stats_tags>` take precedence over the built-in
+  // default tag extractors that share the same ``tag_name``, instead of the default taking
+  // precedence. This allows overriding individual default Envoy tags (for example
+  // ``envoy.cluster_name``) while keeping :ref:`use_all_default_tags
+  // <envoy_v3_api_field_config.metrics.v3.StatsConfig.use_all_default_tags>` enabled, so it is not
+  // necessary to disable all defaults and re-declare every extractor.
+  //
+  // Has no effect when ``use_all_default_tags`` is ``false`` (no default extractors are added in
+  // that case). If not provided, the value is assumed to be false, preserving existing behavior
+  // where the default extractor takes precedence over custom extractors with the same ``tag_name``.
+  google.protobuf.BoolValue allow_default_tag_overrides = 5;
 }
 
 // Configuration for disabling stat instantiation.

envoy/config/route/v3/route_components.proto:

--- shake256:68bd8402344e4157b5cde959d3885e9c1172bba59dfa368bcdfbeff75f5f6fb1fa20c9fdf98c565def281c62284ae7da723fdc65a93ec510e7a286c0ec744189  envoy/config/route/v3/route_components.proto
+++ shake256:4c06a04c3d3885fa814d499cad8097eac67e1844f2c8e3985c24aa21b99d55851bd7d9e273c18536101f3b7df3064ad87027d77328a36793f75acbdfef4596b7  envoy/config/route/v3/route_components.proto
@@ -16,6 +16,7 @@
 import "envoy/type/tracing/v3/custom_tag.proto";
 import "envoy/type/v3/percent.proto";
 import "envoy/type/v3/range.proto";
+import "envoy/type/v3/ratelimit_unit.proto";
 
 import "google/protobuf/any.proto";
 import "google/protobuf/duration.proto";
@@ -1564,7 +1565,7 @@
 }
 
 // HTTP retry :ref:`architecture overview <arch_overview_http_routing_retry>`.
-// [#next-free-field: 14]
+// [#next-free-field: 15]
 message RetryPolicy {
   option (udpa.annotations.versioning).previous_message_type = "envoy.api.v2.route.RetryPolicy";
 
@@ -1788,6 +1789,18 @@
 
   // HTTP headers which must be present in the request for retries to be attempted.
   repeated HeaderMatcher retriable_request_headers = 10;
+
+  // By default, the target upstream cluster of a retry request is the same as the original request,
+  // and Envoy will not try to refresh it when retrying.
+  // If this field is set to true, Envoy will try to refresh the target upstream cluster when
+  // retrying a request. This is useful when users want to try different upstream cluster for
+  // each retry attempt.
+  //
+  // .. note::
+  //   This currently works when the route cluster specifier support the dynamic refresh,
+  //   e.g. :ref:`matcher cluster specifier
+  //   <envoy_v3_api_msg_extensions.router.cluster_specifiers.matcher.v3.MatcherClusterSpecifier>`.
+  bool refresh_cluster_on_retry = 14;
 }
 
 // HTTP request hedging :ref:`architecture overview <arch_overview_http_routing_hedging>`.
@@ -1826,7 +1839,7 @@
   bool hedge_on_per_try_timeout = 3;
 }
 
-// [#next-free-field: 10]
+// [#next-free-field: 11]
 message RedirectAction {
   option (udpa.annotations.versioning).previous_message_type = "envoy.api.v2.route.RedirectAction";
 
@@ -1922,6 +1935,21 @@
     //   would do a case-insensitive match and transform path ``/aaa/XxX/bbb`` to
     //   ``/aaa/yyy/bbb``.
     type.matcher.v3.RegexMatchAndSubstitute regex_rewrite = 9;
+
+    // The path portion of the URL will be set to this value and supports
+    // :ref:`substitution format specifiers <config_access_log_format>` and CEL
+    // expressions.
+    //
+    // For example, with the following config:
+    //
+    // .. code-block:: yaml
+    //
+    //   path_rewrite: "/new/%REQ(x-version)%"
+    //
+    // Would redirect to ``/new/v2`` given a request header ``x-version: v2``.
+    // If the substitution produces an empty string the path redirect is ignored
+    // and the original path is preserved.
+    string path_rewrite = 10;
   }
 
   // The HTTP status code to use in the redirect response. The default response
@@ -2612,11 +2640,23 @@
       type.metadata.v3.MetadataKey metadata_key = 1 [(validate.rules).message = {required: true}];
     }
 
+    // Rate limit to apply to this descriptor.
+    message RateLimitOverride {
+      // The number of requests per unit of time.
+      uint32 requests_per_unit = 1;
+
+      // The unit of time.
+      type.v3.RateLimitUnit unit = 2;
+    }
+
     oneof override_specifier {
       option (validate.required) = true;
 
       // Limit override from dynamic metadata.
       DynamicMetadata dynamic_metadata = 1;
+
+      // Static limit override.
+      RateLimitOverride rate_limit = 2;
     }
   }
 
@@ -2688,9 +2728,13 @@
   // <config_http_filters_rate_limit_rate_limit_override>` for more information.
   //
   // .. note::
-  //   This is not supported if the rate limit action is configured in the ``typed_per_filter_config`` like
-  //   :ref:`VirtualHost.typed_per_filter_config<envoy_v3_api_field_config.route.v3.VirtualHost.typed_per_filter_config>` or
-  //   :ref:`Route.typed_per_filter_config<envoy_v3_api_field_config.route.v3.Route.typed_per_filter_config>`, etc.
+  //   For the global HTTP :ref:`rate limit filter
+  //   <config_http_filters_rate_limit>`, this is supported both at the route/virtual host
+  //   level and when the rate limit configuration is supplied via the filter's
+  //   ``rate_limits`` field or the ``typed_per_filter_config``
+  //   (:ref:`RateLimitPerRoute <envoy_v3_api_msg_extensions.filters.http.ratelimit.v3.RateLimitPerRoute>`).
+  //   This is not supported by the :ref:`local rate limit filter
+  //   <config_http_filters_local_rate_limit>`.
   Override limit = 4;
 
   // An optional hits addend to be appended to the descriptor produced by this rate limit

envoy/config/tap/v3/common.proto:

--- shake256:9c87eab6e7c8b5285888a411d17ac8325dce79b086da2ec31ba0ad1c1df5d9d37b3fc81fd4eb02d6b2b05051b189ea07e764463fb09c3c9e28473b931349a610  envoy/config/tap/v3/common.proto
+++ shake256:18885472ac3b8f9f067d9bfbdfb1cf351d68cf438a34cd2bcf857f16d475033c8180acc1df0910f16ca78318c7bde6efa4b44059bdb52f24d42b7c1cee5c229f  envoy/config/tap/v3/common.proto
@@ -50,14 +50,16 @@
   // a tap will occur and the data will be written to the configured output.
   OutputConfig output_config = 2 [(validate.rules).message = {required: true}];
 
-  // [#not-implemented-hide:] Specify if Tap matching is enabled. The % of requests\connections for
-  // which the tap matching is enabled. When not enabled, the request\connection will not be
-  // recorded.
-  //
-  // .. note::
-  //
-  //   This field defaults to 100/:ref:`HUNDRED
-  //   <envoy_v3_api_enum_type.v3.FractionalPercent.DenominatorType>`.
+  // Specifies the fraction of requests (HTTP tap filter) or connections (transport
+  // socket tap) for which the tap match predicate is evaluated. When unset, every
+  // request/connection proceeds to match evaluation (equivalent to sampling at 100%),
+  // the runtime layer is not consulted, and ``configured_sample_rate`` is not set on
+  // emitted traces. When set, only the configured fraction is matched; the remainder
+  // is not tapped. The value can be overridden at runtime via :ref:`runtime_key
+  // <envoy_v3_api_field_config.core.v3.RuntimeFractionalPercent.runtime_key>`. The
+  // configured sampling rate is recorded on the :ref:`configured_sample_rate
+  // <envoy_v3_api_field_data.tap.v3.TraceWrapper.configured_sample_rate>` of the
+  // first segment of each emitted trace.
   core.v3.RuntimeFractionalPercent tap_enabled = 3;
 }
 

envoy/config/trace/v3/opentelemetry.proto:

--- shake256:b0a3d03c1139ce606c267a6fc1cf4a46a5d60029c99fa9740b516357cf771742ba6463099df5cd6cc671d55c58ae01fb17bd6fa2b3a61e8fd244c7f8bf340926  envoy/config/trace/v3/opentelemetry.proto
+++ shake256:8e0324e178d7561d08e816cdd67afb981b2b68228a878957657bde04fa66fc6b065368cc37be30bbd2171e5d1fa4cdab19a7d0b73d579bb43329373316ee2bda  envoy/config/trace/v3/opentelemetry.proto
@@ -21,7 +21,7 @@
 
 // Configuration for the OpenTelemetry tracer.
 //  [#extension: envoy.tracers.opentelemetry]
-// [#next-free-field: 7]
+// [#next-free-field: 9]
 message OpenTelemetryConfig {
   // The upstream gRPC cluster that will receive OTLP traces.
   // Note that the tracer drops traces if the server does not read data fast enough.
@@ -62,4 +62,18 @@
   // This field specifies the maximum number of spans that can be cached. If not specified, the
   // default is 1024.
   google.protobuf.UInt32Value max_cache_size = 6;
+
+  // Specifies whether to set the telemetry SDK resource attributes.
+  // The following attributes will be set:
+  //
+  // - telemetry.sdk.language
+  // - telemetry.sdk.name
+  // - telemetry.sdk.version
+  //
+  // If not specified, the default is to set these attributes.
+  google.protobuf.BoolValue set_telemetry_sdk_resource_attributes = 7;
+
+  // Specifies whether to set the ``service.name`` resource attribute.
+  // If not specified, the default is to set this attribute.
+  google.protobuf.BoolValue set_service_name_resource_attribute = 8;
 }

envoy/data/core/v3/health_check_event.proto:

--- shake256:5074d5c9185ae449c6d77e0cbf47b96a8d6f16c693196e1cce340dfeeb78efe9e49a8244d06097aa1c473d6db063d2dec759eacebe84e80d757794d53c36f6f7  envoy/data/core/v3/health_check_event.proto
+++ shake256:52a273d10476cf55e56112ff343c5c91a644f232ec677a9437ae0a54e392455580bbff0912e2cef39f1692af08740f309cea6019f29dcc61a6b54f2c7048ccd7  envoy/data/core/v3/health_check_event.proto
@@ -33,6 +33,7 @@
   GRPC = 2;
   REDIS = 3;
   THRIFT = 4;
+  DYNAMIC_MODULE = 5;
 }
 
 // [#next-free-field: 13]
@@ -87,6 +88,12 @@
 
   // The type of failure that caused this ejection.
   HealthCheckFailureType failure_type = 1 [(validate.rules).enum = {defined_only: true}];
+
+  // HTTP status code observed on the response associated with the failure.
+  // Only set when the health checker type is HTTP and the failure type is ``ACTIVE``.
+  // A value of ``0`` indicates that no HTTP status code was recorded (e.g., network-level failures
+  // or non-HTTP health checkers).
+  uint32 http_status_code = 2;
 }
 
 message HealthCheckAddHealthy {
@@ -111,6 +118,12 @@
 
   // Whether this event is the result of the first ever health check on a host.
   bool first_check = 2;
+
+  // HTTP status code observed on the response associated with the failure.
+  // Only set when the health checker type is HTTP and the failure type is ``ACTIVE``.
+  // A value of ``0`` indicates that no HTTP status code was recorded (e.g., network-level failures
+  // or non-HTTP health checkers).
+  uint32 http_status_code = 3;
 }
 
 message DegradedHealthyHost {

envoy/data/tap/v3/wrapper.proto:

--- shake256:06a9c81be98880bf743fdc7bad0cfbadad1bd333d89c88364ebe24deeaf2287c33be918618f2dfe9cafa31bd85a0e82a1f5c834d0d13ca285835813aeae7ab9a  envoy/data/tap/v3/wrapper.proto
+++ shake256:8a9f3822651191945c1fd06a15c1eea8952db7ae45c9c0302dc77a47397031bbfe4670eba6d2a10c394025f671310aaaceee562f82927518ef0ed289f48237a4  envoy/data/tap/v3/wrapper.proto
@@ -4,6 +4,7 @@
 
 import "envoy/data/tap/v3/http.proto";
 import "envoy/data/tap/v3/transport.proto";
+import "envoy/type/v3/percent.proto";
 
 import "udpa/annotations/status.proto";
 import "udpa/annotations/versioning.proto";
@@ -19,6 +20,7 @@
 
 // Wrapper for all fully buffered and streamed tap traces that Envoy emits. This is required for
 // sending traces over gRPC APIs or more easily persisting binary messages to files.
+// [#next-free-field: 6]
 message TraceWrapper {
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.data.tap.v2alpha.TraceWrapper";
@@ -38,4 +40,23 @@
     // A socket streamed tap trace segment.
     SocketStreamedTraceSegment socket_streamed_trace_segment = 4;
   }
+
+  // The configured sample rate at the time this trace was admitted, sourced from the
+  // :ref:`default_value
+  // <envoy_v3_api_field_config.core.v3.RuntimeFractionalPercent.default_value>` of
+  // :ref:`tap_enabled <envoy_v3_api_field_config.tap.v3.TapConfig.tap_enabled>`. For
+  // buffered output (where each ``TraceWrapper`` carries a complete trace) the rate is
+  // always present when sampling is configured. For streamed output (where a trace is
+  // split across multiple ``TraceWrapper`` segments) the rate is set on the first
+  // emitted segment only; subsequent segments belonging to the same trace can be
+  // joined to it via the ``trace_id`` carried on each inner segment message. Absent
+  // when sampling is unconfigured.
+  //
+  // .. note::
+  //
+  //   When :ref:`runtime_key
+  //   <envoy_v3_api_field_config.core.v3.RuntimeFractionalPercent.runtime_key>` is
+  //   configured and an active runtime override is in effect, the effective sampling
+  //   rate that admitted the trace may differ from the recorded configured value.
+  type.v3.FractionalPercent configured_sample_rate = 5;
 }

envoy/extensions/access_loggers/stats/v3/stats.proto:

--- shake256:4a626fd11ed77f856584896d8c115d939ce7621d4cd2c1ebb66fc308b31d4641dd38eaab9d9d1e2b91625309bf9dcf50ab15dd9b2db4c7bcbb9eae73a91d9742  envoy/extensions/access_loggers/stats/v3/stats.proto
+++ shake256:691cf9ccc683d388606ca10cb0d457c4bf41a732f8f95cfe71327dd452afc2606c0b31ef095561fe9520173a9fa3392d631b62d0ffc15c7b4e2d04e467d2d455  envoy/extensions/access_loggers/stats/v3/stats.proto
@@ -3,11 +3,13 @@
 package envoy.extensions.access_loggers.stats.v3;
 
 import "envoy/data/accesslog/v3/accesslog.proto";
+import "envoy/type/v3/scope.proto";
 
 import "google/protobuf/wrappers.proto";
 
 import "xds/type/matcher/v3/matcher.proto";
 
+import "envoy/annotations/deprecation.proto";
 import "udpa/annotations/status.proto";
 import "validate/validate.proto";
 
@@ -29,7 +31,7 @@
 //   leading to a denial of service in Envoy, or can overwhelm any configured
 //   stat sinks by sending too many unique metrics.
 
-// [#next-free-field: 6]
+// [#next-free-field: 7]
 message Config {
   // Defines a tag on a stat.
   message Tag {
@@ -153,7 +155,13 @@
   }
 
   // The stat prefix for the generated stats.
-  string stat_prefix = 1 [(validate.rules).string = {min_len: 1}];
+  // Deprecated: please use ``stats_scope.prefix`` instead.
+  // It will override ``stats_scope.prefix`` if non-empty.
+  string stat_prefix = 1
+      [deprecated = true, (envoy.annotations.deprecated_at_minor_version) = "3.0"];
+
+  // Configuration for stats scope limits and sharing.
+  type.v3.Scope stats_scope = 6;
 
   // The histograms this logger will emit.
   repeated Histogram histograms = 3;

envoy/extensions/bootstrap/reverse_tunnel/downstream_socket_interface/v3/downstream_reverse_connection_socket_interface.proto:

--- shake256:660c22324d1b891b24b011b8794f39d1d6d4f1524f947b128472fc55d67aa42b6672de926e3bb5936d86fbf0a8c0e07c86f9db58d73c86b702b5040cc7975e0c  envoy/extensions/bootstrap/reverse_tunnel/downstream_socket_interface/v3/downstream_reverse_connection_socket_interface.proto
+++ shake256:4d6c09554d3b68490a77d8095e475fa647624f37a2ac97f4f3c2f03ad3942a1fc96dfe8f459a87fd472a60ed07c386f0e235ae32be18ba8e34bc0c005e46829d  envoy/extensions/bootstrap/reverse_tunnel/downstream_socket_interface/v3/downstream_reverse_connection_socket_interface.proto
@@ -2,9 +2,14 @@
 
 package envoy.extensions.bootstrap.reverse_tunnel.downstream_socket_interface.v3;
 
+import "envoy/config/accesslog/v3/accesslog.proto";
 import "envoy/config/core/v3/base.proto";
+import "envoy/config/core/v3/extension.proto";
+
+import "google/protobuf/duration.proto";
 
 import "udpa/annotations/status.proto";
+import "validate/validate.proto";
 
 option java_package = "io.envoyproxy.envoy.extensions.bootstrap.reverse_tunnel.downstream_socket_interface.v3";
 option java_outer_classname = "DownstreamReverseConnectionSocketInterfaceProto";
@@ -18,6 +23,7 @@
 // Configuration for the downstream reverse connection socket interface.
 // This interface initiates reverse connections to upstream Envoys and provides
 // them as socket connections for downstream requests.
+// [#next-free-field: 6]
 message DownstreamReverseConnectionSocketInterface {
   // HTTP handshake settings for initiator envoy initiated reverse tunnels.
   message HttpHandshakeConfig {
@@ -27,6 +33,18 @@
 
     // Additional headers to include in the HTTP handshake request.
     repeated config.core.v3.HeaderValueOption additional_headers = 2;
+
+    // Perform the handshake as an HTTP/1.1 ``Upgrade`` exchange (``Upgrade: reverse-tunnel``,
+    // success on ``101``) so HTTP proxies can route the handshake and splice the tunnel
+    // afterward. The responder must set this flag to the same value.
+    // Defaults to ``false``.
+    bool use_http_upgrade = 3;
+
+    // Formatter extensions usable in ``additional_headers`` substitution. See the formatter
+    // extensions documentation for details. When set, ``additional_headers`` values are evaluated
+    // as substitution format strings; when empty, the values are sent literally.
+    // [#extension-category: envoy.formatter]
+    repeated config.core.v3.TypedExtensionConfig formatters = 4;
   }
 
   // Stat prefix to be used for downstream reverse connection socket interface stats.
@@ -40,4 +58,16 @@
   // Optional HTTP handshake configuration. When unset, the initiator envoy uses the defaults
   // provided by ``HttpHandshakeConfig``.
   HttpHandshakeConfig http_handshake = 3;
+
+  // Access log configuration for reverse tunnel initiator lifecycle events.
+  // Logs are emitted on handshake success, handshake failure, and connection close.
+  // Reverse tunnel metadata (``node_id``, ``cluster_id``, ``tenant_id``, upstream cluster, etc.)
+  // is available via ``%DYNAMIC_METADATA(envoy.reverse_tunnel.initiator:*)%`` substitutions.
+  repeated config.accesslog.v3.AccessLog access_log = 4;
+
+  // Upper bound on the per-host reconnect backoff. The initiator retries a failed handshake on a
+  // deterministic exponential schedule (1s, 2s, 4s, ...) with small upward jitter; this value caps
+  // that schedule.
+  google.protobuf.Duration max_reconnect_backoff = 5
+      [(validate.rules).duration = {gte {seconds: 1}}];
 }

envoy/extensions/bootstrap/reverse_tunnel/upstream_socket_interface/v3/upstream_reverse_connection_socket_interface.proto:

--- shake256:edc29f12ce800836aae0709201e19349a88375d8beeb35cd872414892d7fd12b2d2eae8faf1ac5dfac18110c4d0702e453f385d254fc76a60e2d3cccb637d4dc  envoy/extensions/bootstrap/reverse_tunnel/upstream_socket_interface/v3/upstream_reverse_connection_socket_interface.proto
+++ shake256:1469c987be8ca76f78498d29ce240aa40904695fcceb0d9b3d865044339f0f2973b168107285746c82050f8f222944419c5428553fd33e6d0d2e12dcec634b4b  envoy/extensions/bootstrap/reverse_tunnel/upstream_socket_interface/v3/upstream_reverse_connection_socket_interface.proto
@@ -2,6 +2,7 @@
 
 package envoy.extensions.bootstrap.reverse_tunnel.upstream_socket_interface.v3;
 
+import "envoy/config/accesslog/v3/accesslog.proto";
 import "envoy/config/core/v3/extension.proto";
 
 import "google/protobuf/wrappers.proto";
@@ -19,7 +20,7 @@
 // [#extension: envoy.bootstrap.reverse_tunnel.upstream_socket_interface]
 
 // Configuration for the upstream reverse connection socket interface.
-// [#next-free-field: 6]
+// [#next-free-field: 7]
 message UpstreamReverseConnectionSocketInterface {
   // Stat prefix for upstream reverse connection socket interface stats.
   string stat_prefix = 1;
@@ -44,4 +45,8 @@
   // containing the ``:`` delimiter are rejected to avoid ambiguity.
   // Defaults to ``false`` for backwards compatibility.
   google.protobuf.BoolValue enable_tenant_isolation = 5;
+
+  // Access logs emitted for reverse tunnel lifecycle events. Entries are generated for tunnel setup,
+  // socket handoff, tunnel close, and post-handoff HTTP/2 keepalive timeout observations.
+  repeated config.accesslog.v3.AccessLog access_log = 6;
 }

envoy/extensions/clusters/dns/v3/dns_cluster.proto:

--- shake256:b8474a002d72c2f26c487b3f7ff34c9d28dede1ae5deebca5bca92acdc82e3eb084a31405538e2210f87d882cc4cedc05abe0a337497ff6dc211e65c16dcf02a  envoy/extensions/clusters/dns/v3/dns_cluster.proto
+++ shake256:080f22dafbd2abb52d544b56a18619ca3123bf9f280acc1d838427c65fb844747f5208f09a5dc3ef487454c8306a30be1e31afbf03f0a6c083629f3bd70843aa  envoy/extensions/clusters/dns/v3/dns_cluster.proto
@@ -21,7 +21,7 @@
 // Configuration for DNS discovery clusters.
 // [#extension: envoy.clusters.dns]
 
-// [#next-free-field: 10]
+// [#next-free-field: 11]
 message DnsCluster {
   message RefreshRate {
     // Specifies the base interval between refreshes. This parameter is required and must be greater
@@ -89,4 +89,12 @@
   // semantics. Otherwise, each address is considered to be a separate endpoint, which maps to
   // :ref:`strict DNS discovery <arch_overview_service_discovery_types_strict_dns>` semantics.
   bool all_addresses_in_single_endpoint = 9;
+
+  // When :ref:`respect_dns_ttl <envoy_v3_api_field_extensions.clusters.dns.v3.DnsCluster.respect_dns_ttl>`
+  // is enabled, this field specifies a minimum value for the TTL-derived DNS refresh rate.
+  // DNS records with TTLs shorter than this value will be refreshed at this rate instead. If not
+  // set, the TTL from the DNS response is used directly with no minimum floor.
+  // The value must be at least 1 second.
+  google.protobuf.Duration dns_min_refresh_rate = 10
+      [(validate.rules).duration = {gte {seconds: 1}}];
 }

envoy/extensions/clusters/dynamic_forward_proxy/v3/cluster.proto:

--- shake256:7e03724651ff36311b8dc7064d7edd827f2b39c1d84707d9adbdba769385598813dcfe57343b470230c54a1d953ce09eba33b42e1b3baa52e3cc4e9b35565e7a  envoy/extensions/clusters/dynamic_forward_proxy/v3/cluster.proto
+++ shake256:e392dc7007461ec2ae798f202f2b1ffc44d6ea843404340d512ad290632eaaefc5be2f0f1edd10326f87695c980ba499d13b0f4f1e86980ab3cdc4817aa00773  envoy/extensions/clusters/dynamic_forward_proxy/v3/cluster.proto
@@ -4,6 +4,7 @@
 
 import "envoy/config/cluster/v3/cluster.proto";
 import "envoy/config/core/v3/address.proto";
+import "envoy/extensions/clusters/dns/v3/dns_cluster.proto";
 import "envoy/extensions/common/dynamic_forward_proxy/v3/dns_cache.proto";
 
 import "google/protobuf/duration.proto";
@@ -76,7 +77,9 @@
   bool allow_coalesced_connections = 3;
 }
 
-// Configuration for sub clusters. Hard code STRICT_DNS cluster type now.
+// Configuration for sub clusters. Sub clusters default to the ``STRICT_DNS`` discovery type, or
+// use the ``DnsCluster`` extension when ``dns_cluster_config`` is set.
+// [#next-free-field: 6]
 message SubClustersConfig {
   // The :ref:`load balancer type <arch_overview_load_balancing_types>` to use
   // when picking a host in a sub cluster. Note that CLUSTER_PROVIDED is not allowed here.
@@ -93,4 +96,13 @@
   // performance improvement, in the form of cache hits, for sub clusters that are going to be
   // warmed during steady state and are known at config load time.
   repeated config.core.v3.SocketAddress preresolve_clusters = 4;
+
+  // Optional DNS configuration for dynamically created sub clusters. When set, sub clusters
+  // are created using the :ref:`DnsCluster <envoy_v3_api_msg_extensions.clusters.dns.v3.DnsCluster>`
+  // extension (``envoy.cluster.dns``) rather than the legacy ``STRICT_DNS`` discovery type,
+  // enabling full DNS configuration including refresh rates, failure backoff, TTL respect,
+  // lookup family, and resolver selection.
+  //
+  // When not set, sub clusters inherit DNS settings from the parent cluster configuration.
+  dns.v3.DnsCluster dns_cluster_config = 5;
 }

envoy/extensions/common/dynamic_forward_proxy/v3/dns_cache.proto:

--- shake256:b507b895388f9b46bd947d35a58112996e4d468a2002e06ab5511ebe3f03db0f6e5015ecdd0d04b06a65cde949cf2a5165ee7131fbf6dc2e3263970374d9c72c  envoy/extensions/common/dynamic_forward_proxy/v3/dns_cache.proto
+++ shake256:bacc120059e889203d81f339d15019d86124f5e6db3e34fa0f9960282127bf89d900d90cc33a11798277e2d76d60550a55dfd89ec18afa0ec6086087827e12ae  envoy/extensions/common/dynamic_forward_proxy/v3/dns_cache.proto
@@ -7,6 +7,7 @@
 import "envoy/config/core/v3/address.proto";
 import "envoy/config/core/v3/extension.proto";
 import "envoy/config/core/v3/resolver.proto";
+import "envoy/type/matcher/v3/address.proto";
 
 import "google/protobuf/duration.proto";
 import "google/protobuf/wrappers.proto";
@@ -33,7 +34,7 @@
 
 // Configuration for the dynamic forward proxy DNS cache. See the :ref:`architecture overview
 // <arch_overview_http_dynamic_forward_proxy>` for more information.
-// [#next-free-field: 16]
+// [#next-free-field: 17]
 message DnsCacheConfig {
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.config.common.dynamic_forward_proxy.v2alpha.DnsCacheConfig";
@@ -148,4 +149,12 @@
 
   // Configuration to flush the DNS cache to long term storage.
   config.common.key_value.v3.KeyValueStoreConfig key_value_config = 13;
+
+  // Optional matcher to filter out DNS resolution results that match specific IP address ranges.
+  // If a DNS response contains addresses matching this matcher, those addresses will be
+  // removed from the response. If all addresses are removed, the resolution is treated
+  // as a failure and the host will retain any previously resolved address.
+  // This can be used as an SSRF protection mechanism to prevent DNS rebinding attacks
+  // that resolve to internal/private IP addresses.
+  type.matcher.v3.AddressMatcher resolved_address_filter = 16;
 }

envoy/extensions/filters/common/set_filter_state/v3/value.proto:

--- shake256:59527f51b36370ee87eaa093e454df957c4f537e2201e02da2928c072be789221d7850b0773d9772b06e4e6ead2c25e8b7534c4265c5ddd7a888ccb7f0c92c16  envoy/extensions/filters/common/set_filter_state/v3/value.proto
+++ shake256:0d676447ff49be2c9b90352ac6c6ef5de7153e979c8306b7fb593a988bd21a498009979f47760530429e306a60d8893588da3f050488e8cd982ef018c9d8d9d7  envoy/extensions/filters/common/set_filter_state/v3/value.proto
@@ -4,6 +4,7 @@
 
 import "envoy/config/core/v3/substitution_format_string.proto";
 
+import "envoy/annotations/deprecation.proto";
 import "udpa/annotations/status.proto";
 import "validate/validate.proto";
 
@@ -91,9 +92,8 @@
     config.core.v3.SubstitutionFormatString format_string = 2;
   }
 
-  // If marked as read-only, the filter state key value is locked, and cannot
-  // be overridden by any filter, including this filter.
-  bool read_only = 3;
+  // This field is deprecated and its value has no effect.
+  bool read_only = 3 [deprecated = true, (envoy.annotations.deprecated_at_minor_version) = "3.0"];
 
   // Configures the object to be shared with the upstream internal connections. See :ref:`internal upstream
   // transport <config_internal_upstream_transport>` for more details on the filter state sharing with

envoy/extensions/filters/http/aws_lambda/v3/aws_lambda.proto:

--- shake256:208e15cc704c30a3a37f03fd72c98eed16c47e31e653e12c4c3829bd1a7746757da98ec919f2fd034972bed671e50690f6e302a68f6d1fe850d395bb99fed659  envoy/extensions/filters/http/aws_lambda/v3/aws_lambda.proto
+++ shake256:009d0945fabdf8882d4b20b6f5c167d0b886d497d1f8b72274c855dc6ef232f1a0845060936adbcf37f39d5df394b5e69c4b520b96d14d578602a6ec7ae57114  envoy/extensions/filters/http/aws_lambda/v3/aws_lambda.proto
@@ -2,6 +2,8 @@
 
 package envoy.extensions.filters.http.aws_lambda.v3;
 
+import "envoy/type/matcher/v3/string.proto";
+
 import "udpa/annotations/status.proto";
 import "udpa/annotations/versioning.proto";
 import "validate/validate.proto";
@@ -17,7 +19,7 @@
 // [#extension: envoy.filters.http.aws_lambda]
 
 // AWS Lambda filter config
-// [#next-free-field: 7]
+// [#next-free-field: 9]
 message Config {
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.config.filter.http.aws_lambda.v2alpha.Config";
@@ -76,6 +78,40 @@
   // .. warning::
   //   Distributing the AWS credentials via this configuration should not be done in production.
   Credentials credentials = 6;
+
+  // A list of request header string matchers that will be excluded from signing. The excluded header can be matched by
+  // any patterns defined in the StringMatcher proto (e.g. exact string, prefix, regex, etc).
+  // Headers such as ``x-amzn-cipher-suite``, ``x-amzn-tls-version``, ``x-amzn-vpc-id``, ``x-amzn-vpce-config`` and ``x-amzn-vpce-id``,
+  // when included in the request and signed, can cause errors to be generated by the Lambda endpoint.
+  //
+  // Example:
+  //
+  // .. code-block:: yaml
+  //
+  //  match_excluded_headers:
+  //  - prefix: x-amzn
+  //  - exact: foo
+  //  - exact: bar
+  //
+  // When applied, all headers that start with ``x-amzn`` and headers ``foo`` and ``bar`` will not be signed.
+  repeated type.matcher.v3.StringMatcher match_excluded_headers = 7;
+
+  // A list of request header string matchers that will be included during signing. The included header can be matched by
+  // any patterns defined in the StringMatcher proto (e.g. exact string, prefix, regex, etc).
+  // match_included_headers takes precedence over match_excluded_headers - if match_included_headers is set, only those headers will be signed and match_excluded_headers will be ignored.
+  // Required headers for signing such as ``host`` will always be signed regardless of this setting. The required headers are determined via ``CanonicalHeaders`` section in the AWS documentation `here <https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_sigv-create-signed-request.html#create-canonical-request>`_.
+  //
+  // Example:
+  //
+  // .. code-block:: yaml
+  //
+  //  match_included_headers:
+  //  - prefix: x-amzn
+  //  - exact: foo
+  //  - exact: bar
+  //
+  // When applied, all headers that start with ``x-amzn`` and headers ``foo`` and ``bar`` will be signed and all other headers will be excluded from signing except required headers.
+  repeated type.matcher.v3.StringMatcher match_included_headers = 8;
 }
 
 // AWS Lambda Credentials config.

envoy/extensions/filters/http/basic_auth/v3/basic_auth.proto:

--- shake256:0658d9ac6676216ef3c6a8d93e91d5ed61e9ebff0c4be5bfd1d7cdafdb3e4179a796bb5128b97da5497fe76f13f8b4c9b3c1d567257200326ad0f33275314592  envoy/extensions/filters/http/basic_auth/v3/basic_auth.proto
+++ shake256:00902c0bf637b39660032f85e0e6c05335ad948d4705c4207d3d67478603a21b6cefc06cfd79d03cda098eb753617d1cbe4f898827cd3deac3a75fdb25d2d422  envoy/extensions/filters/http/basic_auth/v3/basic_auth.proto
@@ -29,6 +29,7 @@
 //       user1:{SHA}hashed_user1_password
 //       user2:{SHA}hashed_user2_password
 //
+// [#next-free-field: 6]
 message BasicAuth {
   // Username-password pairs used to verify user credentials in the "Authorization" header.
   // The value needs to be the htpasswd format.
@@ -47,6 +48,29 @@
   // If it is not specified, the filter loads the credential from  the "Authorization" header.
   string authentication_header = 3
       [(validate.rules).string = {well_known_regex: HTTP_HEADER_NAME strict: false}];
+
+  // If set to true, requests without Basic credentials (missing ``Authorization`` header, or
+  // ``Authorization`` header with a non-``Basic`` scheme such as ``Bearer``) are allowed to pass through
+  // without authentication. Requests that present ``Basic`` credentials are still fully validated.
+  //
+  // This is useful when combining BasicAuth with other authentication methods (e.g. JWT) to
+  // achieve OR semantics: a request is accepted if any one configured auth method succeeds.
+  // When ``allow_missing`` is ``true`` on all auth filters, pair it with an RBAC filter that checks
+  // the dynamic metadata emitted by this filter (see ``emit_dynamic_metadata``) to ensure at
+  // least one method authenticated the request. Requires ``emit_dynamic_metadata`` to be set to
+  // ``true``.
+  bool allow_missing = 4;
+
+  // If set to ``true``, the filter emits dynamic metadata on successful authentication with key
+  // ``username`` set to the authenticated username. The metadata is emitted under the namespace
+  // corresponding to the name of this basic_auth filter as configured in the ``http_filters``
+  // chain (e.g. if the filter is configured with name ``envoy.filters.http.basic_auth``, that is
+  // the namespace that will be used).
+  //
+  // This is typically enabled together with ``allow_missing`` when combining BasicAuth with
+  // other authentication methods (e.g. JWT) and using a downstream RBAC filter to enforce
+  // OR semantics.
+  bool emit_dynamic_metadata = 5;
 }
 
 // Extra settings that may be added to per-route configuration for

envoy/extensions/filters/http/composite/v3/composite.proto:

--- shake256:5eda6bb5729dc34ac1a0ba6390df58021e94e61d5f540442d551ef15db94d015d68916535f4363ac1a7c99aed706048ffbe1a30396aaea913a32d110aea39ec9  envoy/extensions/filters/http/composite/v3/composite.proto
+++ shake256:0273f1108bcefebaabfaee544a90b5ab70c517b9e19e1131b490241df4c37b634ffe406dda73e975d7ff9ce5c6b847018c496110e974facc0bc46e56843dff02  envoy/extensions/filters/http/composite/v3/composite.proto
@@ -41,17 +41,31 @@
   // as it avoids duplicating the filter chain configuration.
   map<string, FilterChainConfiguration> named_filter_chains = 1;
 
-  // [#not-implemented-hide:]
   // The match tree that will be used to select an action to execute. The action type should be
   // :ref:`ExecuteFilterAction
   // <envoy_v3_api_msg_extensions.filters.http.composite.v3.ExecuteFilterAction>`.
+  //
+  // .. warning::
+  //   This should only be set when using the Composite filter as in the :ref:`http_filters
+  //   <envoy_v3_api_field_extensions.filters.network.http_connection_manager.v3.HttpConnectionManager.http_filters>`.
+  //   Never set this field when using the Composite filter with the :ref:`ExtensionWithMatcher
+  //   <envoy_v3_api_msg_extensions.common.matching.v3.ExtensionWithMatcher>` which will result in
+  //   undefined behavior.
+  //
   xds.type.matcher.v3.Matcher matcher = 2;
 }
 
 // Per-route configuration for the Composite filter.
-// [#not-implemented-hide:]
 message CompositePerRoute {
   // Override of the match tree for this route.
+  //
+  // .. warning::
+  //   This should only be set when using the Composite filter as in the :ref:`http_filters
+  //   <envoy_v3_api_field_extensions.filters.network.http_connection_manager.v3.HttpConnectionManager.http_filters>`.
+  //   Never set this field when using the Composite filter with the :ref:`ExtensionWithMatcher
+  //   <envoy_v3_api_msg_extensions.common.matching.v3.ExtensionWithMatcher>` which will result in
+  //   undefined behavior.
+  //
   xds.type.matcher.v3.Matcher matcher = 1 [(validate.rules).message = {required: true}];
 }
 

envoy/extensions/filters/http/custom_response/v3/custom_response.proto:

--- shake256:82ffd0cbfca838b0c290aa200fab3203a91825fb676853feb477c97c3cfd0b92f209e5af6daab0257bde72d859764e46cd4f986aca0227e98bd77023fc4b0765  envoy/extensions/filters/http/custom_response/v3/custom_response.proto
+++ shake256:fefa73c461c513262c6d5502fa1a26b8404c87ceb540447d6c4365961bced055f5514fb92192235388355030b769dd612f3339a0fcc9b5c5c124b4546fe8591a  envoy/extensions/filters/http/custom_response/v3/custom_response.proto
@@ -27,7 +27,11 @@
   // Matcher to match against the original response to select a
   // :ref:`Custom Response Policy <extension_category_envoy.http.custom_response>`
   // that will override the original response. The matching is done by matching
-  // against :ref:`response header values<extension_category_envoy.matching.http.input>`
+  // against the response status code, response header values, and/or
+  // :ref:`request header values<extension_category_envoy.matching.http.input>`.
+  // Request inputs (for example ``HttpRequestHeaderMatchInput``) match against
+  // the original downstream request, which allows selecting a custom response
+  // based on, e.g., the ``Accept`` request header.
   // Example:
   //
   // .. validated-code-block:: yaml
@@ -96,6 +100,35 @@
   //             - header:
   //                 key: "foo2"
   //                 value: "x-bar2"
+  //       # Apply a JSON custom response to 5xx responses when the request asks for JSON.
+  //     - predicate:
+  //         and_matcher:
+  //           predicate:
+  //           - single_predicate:
+  //               input:
+  //                 name: 5xx_response
+  //                 typed_config:
+  //                   "@type": type.googleapis.com/envoy.type.matcher.v3.HttpResponseStatusCodeClassMatchInput
+  //               value_match:
+  //                 exact: "5xx"
+  //           - single_predicate:
+  //               input:
+  //                 name: accept_request_header
+  //                 typed_config:
+  //                   "@type": type.googleapis.com/envoy.type.matcher.v3.HttpRequestHeaderMatchInput
+  //                   header_name: accept
+  //               value_match:
+  //                 exact: "application/json"
+  //       on_match:
+  //         action:
+  //           name: action
+  //           typed_config:
+  //             "@type": type.googleapis.com/envoy.extensions.http.custom_response.local_response_policy.v3.LocalResponsePolicy
+  //             status_code: 500
+  //             body_format:
+  //               json_format:
+  //                 status: "%RESPONSE_CODE%"
+  //                 message: "%LOCAL_REPLY_BODY%"
   //
   // -- attention::
   //  The first matched policy wins. Once the response is matched, matcher

envoy/extensions/filters/http/ext_authz/v3/ext_authz.proto:

--- shake256:b5adab52f4b770083cb54fb1866189dc3e58a36587925aa32003e04a864e666f1013c3af16b69ef346302534291b604fc04ce9b5507e69cd421e2ecc3a9682e7  envoy/extensions/filters/http/ext_authz/v3/ext_authz.proto
+++ shake256:e715b7dc0ebb2593a30543e81b64a9684b22679d355cd23de58fa40040bf5dfe7eaae1c982f55fc94db512ce7d621d6aa17c925de7dc64f749f0a3f7eee65e92  envoy/extensions/filters/http/ext_authz/v3/ext_authz.proto
@@ -88,6 +88,17 @@
   //   alter another client request header.
   //
   // Defaults to ``false``.
+  //
+  // .. attention::
+  //
+  //   Enabling this option can cause Envoy to recompute route matching after earlier HTTP filters
+  //   have already processed the request. This can be security-sensitive when route-dependent
+  //   authorization filters, such as the RBAC filter, run before ext_authz.
+  //
+  //   Operators should avoid enabling this option for authorization services that are not fully
+  //   trusted to influence routing. When possible, filters that mutate route-matching inputs and
+  //   clear the route cache should run before route-dependent authorization filters. Operators can
+  //   also use decoder_header_mutation_rules to restrict sensitive request header mutations.
   bool clear_route_cache = 6;
 
   // Sets the HTTP status that is returned to the client when the authorization server returns an error

envoy/extensions/filters/http/ext_proc/v3/ext_proc.proto:

--- shake256:8abe6aeb9fe7bb19c1453260272f450a201be9cc72d3a160fd6a5ae3afb6268272101805eb17a3bb801dbce828b7bc989f0aa38fe501381723a95f5c4f39d01a  envoy/extensions/filters/http/ext_proc/v3/ext_proc.proto
+++ shake256:4ae5cb378355dc0289d4c97e1839b88232b4f650638b2ce8cab571040aa158bc84866ace6e79becba7cc0ea1198c2463240cdeefc38903ef7d98320f2f7f4c81  envoy/extensions/filters/http/ext_proc/v3/ext_proc.proto
@@ -299,6 +299,17 @@
   // received in response to request headers. It is recommended to set this field rather than set
   // :ref:`disable_clear_route_cache <envoy_v3_api_field_extensions.filters.http.ext_proc.v3.ExternalProcessor.disable_clear_route_cache>`.
   // Only one of ``disable_clear_route_cache`` or ``route_cache_action`` can be set.
+  //
+  // .. attention::
+  //
+  //   Clearing the route cache can cause Envoy to recompute route matching after earlier HTTP
+  //   filters have already processed the request. This can be security-sensitive when filters
+  //   that make route-dependent authorization decisions, such as the RBAC filter, run before
+  //   ext_proc and ext_proc mutates route-matching inputs.
+  //
+  //   Operators should only enable route cache clearing for trusted external processors, should
+  //   carefully order route-dependent authorization filters, and should use mutation_rules to
+  //   restrict sensitive mutations when appropriate.
   RouteCacheAction route_cache_action = 18
       [(udpa.annotations.field_migrate).oneof_promotion = "clear_route_cache_type"];
 

envoy/extensions/filters/http/gcp_authn/v3/gcp_authn.proto:

--- shake256:32c11e93a8a0fd4d7d72d3676d66c1a0f14764d7a7df9ab8ac35a6fe8384b1a8a5cdd3bd7662994a51ed5833840855a9495f2baddadd8a29bd06f0fba39a1ce3  envoy/extensions/filters/http/gcp_authn/v3/gcp_authn.proto
+++ shake256:52635c541d6b7bcefc27115fef5270031bb2bc9ec24b2d93efd90e906cea870ba5b0040ea8fed4f7b6a9813369b6f22a385b05eba4b33f6beaa34d54c3358ac2  envoy/extensions/filters/http/gcp_authn/v3/gcp_authn.proto
@@ -64,7 +64,31 @@
 // Audience is the URL of the receiving service that performs token authentication.
 // It will be provided to the filter through cluster's typed_filter_metadata.
 message Audience {
-  string url = 1 [(validate.rules).string = {min_len: 1}];
+  message AccessToken {
+  }
+
+  message BoundJwt {
+    // The audience URL, used for fetching bound JWT token.
+    string url = 1 [(validate.rules).string = {min_len: 1}];
+  }
+
+  message BoundAccessToken {
+  }
+
+  // The audience URL, used for fetching unbound JWT token.
+  string url = 1;
+
+  // If defined, the filter will fetch unbound Access Token instead of JWT.
+  // It takes precedence over ``url``.
+  AccessToken access_token = 2;
+
+  // If defined, the filter will fetch bound JWT token instead of unbound.
+  // It takes precedence over ``access_token`` and ``url``.
+  BoundJwt bound_jwt = 3;
+
+  // If defined, the filter will fetch bound Access Token instead of unbound.
+  // It takes precedence over ``bound_jwt``, ``access_token`` and ``url``.
+  BoundAccessToken bound_access_token = 4;
 }
 
 // Token Cache configuration.

envoy/extensions/filters/http/ip_tagging/v3/ip_tagging.proto:

--- shake256:e21dabe4f701068b930a6c2586ed13869ab20e7756b0ab88bf4730ac17d0eca7b68083f2fb86a8a15acf96150b78411dd840a35bb2865cceeb2c2840913e3f59  envoy/extensions/filters/http/ip_tagging/v3/ip_tagging.proto
+++ shake256:769f5cdb800441cbde268eab925fcef13eedc109348b6caf1b6ba31804fa50182f0a4d0b4f6ad674c51051b80f7cfcebb64ff71a890285b13fdb301220f5954a  envoy/extensions/filters/http/ip_tagging/v3/ip_tagging.proto
@@ -3,6 +3,7 @@
 package envoy.extensions.filters.http.ip_tagging.v3;
 
 import "envoy/config/core/v3/address.proto";
+import "envoy/config/core/v3/base.proto";
 
 import "udpa/annotations/status.proto";
 import "udpa/annotations/versioning.proto";
@@ -18,7 +19,7 @@
 // IP tagging :ref:`configuration overview <config_http_filters_ip_tagging>`.
 // [#extension: envoy.filters.http.ip_tagging]
 
-// [#next-free-field: 6]
+// [#next-free-field: 7]
 message IPTagging {
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.config.filter.http.ip_tagging.v2.IPTagging";
@@ -53,6 +54,12 @@
     repeated config.core.v3.CidrRange ip_list = 2;
   }
 
+  // Specifies the content of the IP tag file.
+  // Allow the file to be created with no IP tags.
+  message IPTags {
+    repeated IPTag ip_tags = 1;
+  }
+
   // Specify to which header the tags will be written.
   message IpTagHeader {
     // Describes how to apply the tags to the headers.
@@ -88,13 +95,20 @@
   // The type of request the filter should apply to.
   RequestType request_type = 1 [(validate.rules).enum = {defined_only: true}];
 
-  // [#comment:TODO(ccaraman): Extend functionality to load IP tags from file system.
-  // Tracked by issue https://github.com/envoyproxy/envoy/issues/2695]
   // The set of IP tags for the filter.
-  repeated IPTag ip_tags = 4 [(validate.rules).repeated = {min_items: 1}];
+  // Only one of :ref:`ip_tags <envoy_v3_api_field_extensions.filters.http.ip_tagging.v3.IPTagging.ip_tags>`
+  // or :ref:`ip_tags_datasource <envoy_v3_api_field_extensions.filters.http.ip_tagging.v3.IPTagging.ip_tags_datasource>`
+  // can be set for the IP Tagging filter.
+  repeated IPTag ip_tags = 4;
 
   // Specify to which header the tags will be written.
   //
   // If left unspecified, the tags will be appended to the ``x-envoy-ip-tags`` header.
   IpTagHeader ip_tag_header = 5;
+
+  // Data source from which to retrieve ip tags.
+  // Only filename based data source is currently supported for IP tags.
+  // When using this data source, if a ``watched_directory`` is provided, the IP tags file will be re-read when a file move is detected.
+  // See :ref:`watched_directory <envoy_v3_api_msg_config.core.v3.DataSource>` for more information about the ``watched_directory`` field.
+  config.core.v3.DataSource ip_tags_datasource = 6;
 }

envoy/extensions/filters/http/jwt_authn/v3/config.proto:

--- shake256:7a694f7096a90eea01c8587b07066334b4fa525478303ea8a2b78d38185f17b025b1d71070421b8f9ba58f097fc78cb557caae8f16d213080496f934263a378f  envoy/extensions/filters/http/jwt_authn/v3/config.proto
+++ shake256:96cd7a468fdd66eab12305b1dc75a394fd726d1427fa3b2d02c073c76053a955cc574c57418fb1866696f3f738df2f650f173653972c91b5b97d372d22286eb8  envoy/extensions/filters/http/jwt_authn/v3/config.proto
@@ -78,6 +78,7 @@
   // otherwise the JWT ``iss`` field is not checked.
   //
   // .. note::
+  //
   //     ``JwtRequirement`` :ref:`allow_missing <envoy_v3_api_field_extensions.filters.http.jwt_authn.v3.JwtRequirement.allow_missing>`
   //     and :ref:`allow_missing_or_failed <envoy_v3_api_field_extensions.filters.http.jwt_authn.v3.JwtRequirement.allow_missing_or_failed>`
   //     are implemented differently than other ``JwtRequirements``. Hence the usage of this field
@@ -324,10 +325,11 @@
   //       alg: PS256
   //
   // .. warning::
-  //   Using the same key name for :ref:`header_in_metadata <envoy_v3_api_field_extensions.filters.http.jwt_authn.v3.JwtProvider.payload_in_metadata>`
-  //   and :ref:`payload_in_metadata <envoy_v3_api_field_extensions.filters.http.jwt_authn.v3.JwtProvider.payload_in_metadata>`
-  //   is not suggested due to potential override of existing entry, while it is not enforced during
-  //   config validation.
+  //
+  //    Using the same key name for :ref:`header_in_metadata <envoy_v3_api_field_extensions.filters.http.jwt_authn.v3.JwtProvider.payload_in_metadata>`
+  //    and :ref:`payload_in_metadata <envoy_v3_api_field_extensions.filters.http.jwt_authn.v3.JwtProvider.payload_in_metadata>`
+  //    is not suggested due to potential override of existing entry, while it is not enforced during
+  //    config validation.
   //
   string header_in_metadata = 14;
 
@@ -593,38 +595,70 @@
     // different is this mode will reject requests with invalid tokens.
     google.protobuf.Empty allow_missing = 6;
 
-    // Extract JWT claims without performing signature validation.
-    // This mode will decode the JWT, extract claims, and forward them as
-    // configured (via claim_to_headers, forward_payload_header, etc.) but
-    // will NOT verify the JWT signature against JWKS.
+    // [#next-major-version: consider removing or gating behind explicit opt-in]
     //
     // .. warning::
     //
-    //    This mode does not verify JWT authenticity. Use only in scenarios where:
-    //
-    //    - JWTs come from a trusted source (e.g., internal service mesh)
-    //    - Signature verification is performed elsewhere in the request path
-    //    - You are in a testing period and the token issuer doesn't support JWKS yet
-    //
-    // This mode will:
-    //
-    // * Decode the JWT header and payload
-    // * Extract claims and forward them as headers
-    // * Always return success (Status::Ok) regardless of JWT validity
-    // * Log when extraction occurs
+    //    SECURITY WARNING: This mode does NOT verify JWT signatures. Any party
+    //    can forge a JWT with arbitrary claims, and those claims will be extracted
+    //    and forwarded as HTTP headers. Headers set by this mode are
+    //    INDISTINGUISHABLE from headers set by fully validated JWTs unless the
+    //    ``verification_status_header`` is checked by downstream filters
+    //    (set to ``false`` by default on all extract-only requests).
+    //
+    //    DO NOT use this mode if:
+    //      - RBAC policies match on JWT-derived headers
+    //      - ext_authz services trust JWT-derived headers
+    //      - Backend services use JWT-derived headers for authorization
+    //      - The JWT source is not cryptographically authenticated by other means
     //
-    // This mode will NOT:
+    //    Use only when signature verification is PROVABLY performed elsewhere
+    //    in the request path (e.g., by an upstream mTLS-authenticated service).
     //
-    // * Verify the JWT signature
-    // * Validate the (issuer) claim
-    // * Validate the (audience) claim
-    // * Check not-before time (nbf claim)
     ExtractOnlyWithoutValidation extract_only_without_validation = 7;
   }
 }
 
+// Configuration for extract-only mode without JWT signature validation.
+//
+// When this mode is active and a JWT is present in the request but fails
+// signature verification, a verification status header is set on the request
+// to signal to downstream filters (RBAC, ext_authz) that the JWT claims were
+// NOT cryptographically verified. The header is not set when the JWT is valid
+// or when no JWT is present.
+//
 message ExtractOnlyWithoutValidation {
-  // Reserved for future extensions (e.g., claim filtering, logging options)
+  // Name of the HTTP header set to "false" when a JWT is present but fails
+  // signature verification. The header is NOT set when:
+  //
+  // - The JWT is valid (verification succeeded), or
+  // - No JWT is present in the request.
+  //
+  // This means the header's presence is a meaningful signal to downstream
+  // filters: if set, the JWT was present but could not be verified, and any
+  // extracted claim headers should not be trusted for authorization.
+  //
+  // Downstream filters (RBAC, ext_authz) SHOULD check for the absence of this
+  // header (or its non-"false" value) before trusting JWT-derived claim headers
+  // for authorization decisions.
+  //
+  // Default (unset or empty): ``x-jwt-signature-verified``.
+  //
+  // Custom value: uses the specified header name.
+  //
+  // The header-setting behavior is guarded by the
+  // ``envoy.reloadable_features.jwt_authn_add_verification_status_header``
+  // runtime flag (default on). If removal is needed downstream, use header
+  // mutation in a subsequent filter.
+  //
+  // Example: when a JWT is present in the request but fails signature
+  // verification, the request will carry:
+  //
+  // .. code-block:: yaml
+  //
+  //    x-jwt-signature-verified: false
+  //
+  string verification_status_header = 1;
 }
 
 // This message specifies a list of RequiredProvider.

envoy/extensions/filters/http/mcp/v3/mcp.proto:

--- shake256:328867464937b631c46b21ab01d87750ba39570d9092007aa9ca09c8443e54829c4872b77e7e310ac1245b6871f5c9e9e59b4f8e49385eeace4abd24cb2d7d67  envoy/extensions/filters/http/mcp/v3/mcp.proto
+++ shake256:808766396bbbebaa9e63f415dd311ee8a26a2537a290280f8269cc4b750d25970889e47e8c2ab1fd49574f6b1589f997f4ac796c6420b56eb2966ac40e643087  envoy/extensions/filters/http/mcp/v3/mcp.proto
@@ -21,7 +21,7 @@
 // [#extension: envoy.filters.http.mcp]
 
 // This filter will inspect and get attributes from MCP traffic.
-// [#next-free-field: 8]
+// [#next-free-field: 9]
 message Mcp {
   // Traffic handling mode for non-MCP traffic.
   enum TrafficMode {
@@ -69,9 +69,12 @@
   // Defaults to false.
   bool clear_route_cache = 2;
 
-  // Maximum size of the request body to buffer for JSON-RPC validation.
-  // If the request body exceeds this size, the request is rejected with ``413 Payload Too Large``.
-  // This limit applies to both ``REJECT_NO_MCP`` and ``PASS_THROUGH`` modes to prevent unbounded buffering.
+  // Maximum size of the request body to buffer for JSON-RPC parsing.
+  // Only the first ``max_request_body_size`` bytes are parsed for MCP attribute extraction.
+  //
+  // When the body exceeds this limit:
+  // - In ``PASS_THROUGH`` mode: the request is allowed through with an ``is_exceeding_limit`` marker in the dynamic metadata, indicating that the MCP payload was only partially parsed.
+  // - In ``REJECT_NO_MCP`` mode: the request is rejected with ``400 Bad Request`` because the complete root JSON object must fit within the size limit.
   //
   // It defaults to 8KB (8192 bytes) and the maximum allowed value is 10MB (10485760 bytes).
   //
@@ -107,6 +110,11 @@
   //
   // If unset (default), do not extract or inject baggage.
   BaggagePropagationConfig propagate_baggage = 7;
+
+  // When true, reject requests that contain duplicate JSON keys at any
+  // nesting level. RFC 8259 Section 4 states that names within an object SHOULD be
+  // unique. Defaults to false (last-key-wins / last-win).
+  google.protobuf.BoolValue reject_duplicate_keys = 8;
 }
 
 // Parser configuration with method-specific rules.

envoy/extensions/filters/http/mcp_json_rest_bridge/v3/mcp_json_rest_bridge.proto:

--- shake256:7481e541607d3560e2fde1540b5201201cc2bc76a80a24c6bf09f89f9191930d3a4df0cde01662f33a416672013fb77d15b4116378cdb150085cfb9afaf76e49  envoy/extensions/filters/http/mcp_json_rest_bridge/v3/mcp_json_rest_bridge.proto
+++ shake256:5aee9cad0f35c68f9a54ca9dcf19c9875fb92140c560ba5bce1216e5e1bab0155f2684c448b641bcd675e1f9f4b1bce8ac0c3c7ec8c965a9d6968357df193e5b  envoy/extensions/filters/http/mcp_json_rest_bridge/v3/mcp_json_rest_bridge.proto
@@ -90,12 +90,66 @@
 //   - Body: {"data": "updated value"}
 //     (Only the "payload" field from arguments is used as the body. Other arguments not in the
 //     path, like 'resource_id', become query parameters.)
+// [#next-free-field: 8]
 message McpJsonRestBridge {
+  // Where to store parsed MCP request attributes.
+  enum RequestStorageMode {
+    // Unspecified. Uses default behavior (nothing is stored).
+    MODE_UNSPECIFIED = 0;
+
+    // Store request attributes in dynamic metadata. The metadata namespace
+    // is the filter's config name as specified by the ``name`` field in the
+    // ``http_filters`` list (e.g. ``envoy.filters.http.mcp_json_rest_bridge``
+    // if using the canonical filter name).
+    DYNAMIC_METADATA = 1;
+  }
+
   // General server information.
   ServerInfo server_info = 1;
 
   // Configuration for the MCP tools.
   ServerToolConfig tool_config = 2;
+
+  // Maximum size of the request body to buffer for transcoding and validation.
+  // If the request body exceeds this size, the request is rejected with ``413 Payload Too Large``.
+  // This limit applies to prevent unbounded buffering.
+  //
+  // It defaults to 64KB (65536 bytes) as the MCP calls (tools, resources, or prompts)
+  // only pass small arguments or identifiers.
+  //
+  // Setting it to 0 would disable the limit. It is not recommended to do so in production.
+  google.protobuf.UInt32Value max_request_body_size = 3;
+
+  // Maximum size of the response body to buffer for transcoding.
+  // If the response body exceeds this size, the response is rejected with an appropriate error.
+  // This limit applies to prevent unbounded buffering.
+  //
+  // It defaults to 1MB (1048576 bytes) to prevent transcoding failures on large payloads like
+  // file reads, while aligning with Envoy's standard default connection buffer limit.
+  //
+  // Setting it to 0 would disable the limit. It is not recommended to do so in production.
+  google.protobuf.UInt32Value max_response_body_size = 4;
+
+  // Where to store parsed MCP request attributes.
+  // Default is not storing anything.
+  // When set to ``DYNAMIC_METADATA``, attributes are stored in dynamic metadata
+  // using the filter's config name (i.e. the ``name`` field of this filter's entry
+  // in the ``http_filters`` list) as the metadata namespace.
+  RequestStorageMode request_storage_mode = 5 [(validate.rules).enum = {defined_only: true}];
+
+  // If set, extract OpenTelemetry (OTel) trace context from MCP requests and propagate it to
+  // request headers. The keys ``traceparent``, ``tracestate``, and ``baggage``
+  // will be extracted from ``_meta``.
+  // Ref: `Request Meta SEP <https://modelcontextprotocol.io/seps/414-request-meta>`_
+  TraceContextExtractionOptions trace_context_extraction = 6;
+
+  // When set to true, the filter will not clear the route cache after transcoding.
+  // This allows the route to be re-selected based on the updated request path or method.
+  bool disable_clear_route_cache = 7;
+}
+
+// Options for trace context extraction.
+message TraceContextExtractionOptions {
 }
 
 // Configuration for the server metadata.
@@ -127,7 +181,12 @@
   google.protobuf.StringValue fallback_protocol_version = 3;
 }
 
+// Configuration for sending locally-generated responses to tools/list requests.
+message ToolsListLocal {
+}
+
 // Configuration for the MCP tool capability of the server.
+// [#next-free-field: 6]
 message ServerToolConfig {
   // List of MCP tools configurations.
   repeated ToolConfig tools = 1;
@@ -137,26 +196,80 @@
   // Whether this server supports notifications for changes to the tool list.
   bool list_changed = 2;
 
-  // Optional configuration to transcode the tools/list requests to a standard HTTP request.
-  //
-  // Note: tools/list should be mapped to a GET request with an empty body.
-  //
-  // - If provided: The extension transcodes the request and forwards it down the filter chain.
-  //   The response (whether from an upstream backend, a configured ``direct_response``, or another
-  //   extension) MUST be a JSON body strictly matching the MCP ``ListToolsResult`` schema.
-  //   Ref: https://modelcontextprotocol.io/specification/2025-11-25/schema#listtoolsresult
-  // - If not provided: The ``tools/list`` request is passed through. This allows subsequent
-  //   extension or the backend itself to handle the tools/list request if they support it.
-  HttpRule tool_list_http_rule = 3;
+  // Optional configuration for tools/list requests. If not set: The ``tools/list`` request is
+  // passed through. This allows subsequent extension or the backend itself to handle the tools/list
+  // request if they support it.
+  oneof tool_list_config {
+    // Configuration to transcode the tools/list requests to a standard HTTP request. If provided:
+    // The extension transcodes the request and forwards it down the filter chain. The response
+    // (whether from an upstream backend, a configured ``direct_response``, or another extension)
+    // MUST be a JSON body strictly matching the MCP ``ListToolsResult`` schema. Ref:
+    // https://modelcontextprotocol.io/specification/2025-11-25/schema#listtoolsresult
+    HttpRule tool_list_http_rule = 3;
+
+    // If provided: The extension sends a local response, according to each tool's
+    // ToolsListSpecificConfig.
+    ToolsListLocal tool_list_local = 4;
+  }
+
+  // [#not-implemented-hide:]
+  // Default server info for tools without specific ones.
+  McpServerInfo default_server_info = 5;
+}
+
+// Configuration for a tool's entry in tools/list responses.
+message ToolsListSpecificConfig {
+  // Optional, human-readable name of the tool for display purposes.
+  string title = 1;
+
+  // Human-readable description of functionality.
+  string description = 2 [(validate.rules).string = {min_len: 1}];
+
+  // A JSON Schema describing expected parameters, as a serialized JSON string, in the JSON Schema
+  // 2020-12 dialect. This should be raw JSON, including the "properties" and "required" keys, but
+  // not "type". Tools with no parameters may omit this to signify a tool with no constraints on the
+  // parameters object, or set to '"additionalProperties": false' to require empty parameters.
+  string input_schema = 3;
+}
+
+message McpServerInfo {
+  // The path to the endpoint hosting this tool.
+  string path = 1;
+
+  // The host hosting this tool.
+  string host = 2;
 }
 
-// Configuration for a specific MCP tool.
+// [#next-free-field: 6]
 message ToolConfig {
-  // Name of the tool.
+  // Unique identifier of the tool. Used both for tools/list and tools/call transcoding.
   string name = 1 [(validate.rules).string = {min_len: 1}];
 
   // The HTTP configuration rules that apply to the normal backend.
   HttpRule http_rule = 2;
+
+  // Config for this tool's entry in a local tools/list response. Used when tool_list_local is set
+  // in the ServerToolConfig.
+  ToolsListSpecificConfig tool_list_config = 3;
+
+  // Enables streaming transcoding for unstructured text responses (``content`` field of a result).
+  //
+  // When enabled, the response body is streamed directly to the client without buffering. Each
+  // chunk is JSON escaped as it arrives and wrapped with a pre-built JSON-RPC prefix and suffix.
+  //
+  // Streaming flow:
+  //
+  // .. code-block:: text
+  //
+  //   input:  [chunk1] → [chunk2] → [chunk3]
+  //   output: [prefix+escaped_chunk1] → [escaped_chunk2] → [escaped_chunk3+suffix]
+  //
+  // Disabled by default.
+  bool text_content_streaming_enabled = 4;
+
+  // [#not-implemented-hide:]
+  // Path and host of the MCP server that hosts this tool.
+  repeated McpServerInfo server_info = 5;
 }
 
 // Defines the schema of the JSON-RPC to REST mapping. It specifies how the "arguments"
@@ -207,3 +320,8 @@
   // - If omitted: There is no HTTP request body; fields not in the path become query parameters.
   string body = 6;
 }
+
+// Per-route override configuration for the MCP JSON REST Bridge filter.
+message McpJsonRestBridgePerRoute {
+  repeated ServerToolConfig tool_config = 1;
+}

envoy/extensions/filters/http/mcp_router/v3/mcp_router.proto:

--- shake256:5667f8c87679bf1644503044802c8f3e1cf67eac83eafd7a9c0abd969bdc1addc7670b39c482a0cacc8a58d9eea6ba734baa8d7fcb82a6cd0bfcf346a5da0aa8  envoy/extensions/filters/http/mcp_router/v3/mcp_router.proto
+++ shake256:4784eabf7fac5ec895c3fb78a6229e0ba47d006a9141ac3554c3ae6b4819aa1df5928d227a32e0705d707aeeca69b5bd2ff5127c9af2148d32d6a8a052c2e951  envoy/extensions/filters/http/mcp_router/v3/mcp_router.proto
@@ -125,4 +125,11 @@
   // If set, extracts a request "subject" and binds it into the MCP session.
   // If not set, sessions are created without identity binding.
   SessionIdentity session_identity = 2;
+
+  // If true, backend initialization is deferred until the first request that targets each backend.
+  // The ``initialize`` response is returned immediately with gateway capabilities and an empty
+  // backend session map. Each backend is initialized on-demand when a request first routes to it.
+  // This avoids blocking the client ``initialize`` on slow or misbehaving backends.
+  // Default is false (eager initialization of all backends during ``initialize``).
+  bool lazy_initialization = 3;
 }

envoy/extensions/filters/http/oauth2/v3/oauth.proto:

--- shake256:ee6caa86d0cdc97ae3c573a296a30936418d625215a6d2e80817c78eb964bd650e0a00297972fd96420001a4745e97dfbda51fa61501cc26064f7784ba532d58  envoy/extensions/filters/http/oauth2/v3/oauth.proto
+++ shake256:1e855d9dc76a5577eb5c8291d2277659417251743ef7779a6f5cee92f01c9d87b003e978b9f66f7cbd6e2443cb7069e04182cd6133b0f9792b1bc405463fd5e7  envoy/extensions/filters/http/oauth2/v3/oauth.proto
@@ -129,6 +129,8 @@
   // The secret used to retrieve the access token. This value will be URL encoded when sent to the OAuth server.
   // This field is required unless :ref:`auth_type <envoy_v3_api_field_extensions.filters.http.oauth2.v3.OAuth2Config.auth_type>`
   // is set to ``TLS_CLIENT_AUTH``, in which case authentication is done via the client certificate.
+  // When ``auth_type`` is ``PRIVATE_KEY_JWT``, this field must contain the PEM-encoded private key
+  // used to sign the JWT client assertion.
   transport_sockets.tls.v3.SdsSecretConfig token_secret = 2;
 
   // Configures how the secret token should be created.
@@ -149,9 +151,71 @@
       [(validate.rules).string = {pattern: "^$|^[^\\x00-\\x1f\\x7f \",;<>\\\\]+$"}];
 }
 
+// Configuration for ``PRIVATE_KEY_JWT`` client authentication (RFC 7523).
+message PrivateKeyJwtConfig {
+  // Supported JWT signing algorithms for the client assertion.
+  enum SigningAlgorithm {
+    // ``RSASSA-PKCS1-v1_5`` using SHA-256.
+    RS256 = 0;
+
+    // ``RSASSA-PKCS1-v1_5`` using SHA-384.
+    RS384 = 1;
+
+    // ``RSASSA-PKCS1-v1_5`` using SHA-512.
+    RS512 = 2;
+
+    // ECDSA using P-256 and SHA-256.
+    ES256 = 3;
+
+    // ECDSA using P-384 and SHA-384.
+    ES384 = 4;
+
+    // ECDSA using P-521 and SHA-512.
+    ES512 = 5;
+  }
+
+  // The signing algorithm to use for the JWT assertion.
+  // The private key provided in ``token_secret`` must match the algorithm family: an RSA key for
+  // the ``RS*`` algorithms, or an EC key for the ``ES*`` algorithms.
+  // Default: ``RS256``.
+  SigningAlgorithm signing_algorithm = 1 [(validate.rules).enum = {defined_only: true}];
+
+  // The lifetime of the JWT assertion. After this duration, the assertion expires.
+  // The value is truncated to whole seconds, so it must be at least ``1s`` when set.
+  // Default: ``60s``.
+  google.protobuf.Duration assertion_lifetime = 2 [(validate.rules).duration = {gte {seconds: 1}}];
+}
+
+// Defines how an OAuth token is forwarded upstream.
+message OAuth2TokenForwarding {
+  // The upstream request header that will carry the token.
+  // Pseudo-headers (names starting with ``:``) and the ``Host`` header are not allowed.
+  string header = 1
+      [(validate.rules).string = {min_len: 1 well_known_regex: HTTP_HEADER_NAME strict: false}];
+}
+
+// Configuration for the ``post_logout_redirect_uri`` parameter used in OpenID Connect
+// `RP-Initiated Logout requests <https://openid.net/specs/openid-connect-rpinitiated-1_0.html>`_.
+// This configuration is ignored if ``end_session_endpoint`` is not set.
+message PostLogoutRedirectUri {
+  oneof config {
+    option (validate.required) = true;
+
+    // Do not include the ``post_logout_redirect_uri`` parameter in requests to the
+    // configured ``end_session_endpoint``.
+    bool disabled = 1 [(validate.rules).bool = {const: true}];
+
+    // URI to send as the ``post_logout_redirect_uri`` parameter. Supports header formatting
+    // tokens, and will be percent-encoded automatically when building the logout URL.
+    //
+    // The URI should be registered with the authorization server.
+    string uri = 2 [(validate.rules).string = {min_len: 1}];
+  }
+}
+
 // OAuth config
 //
-// [#next-free-field: 28]
+// [#next-free-field: 34]
 message OAuth2Config {
   enum AuthType {
     // The ``client_id`` and ``client_secret`` will be sent in the URL encoded request body.
@@ -168,6 +232,12 @@
     // transport socket configuration.
     // This implements OAuth 2.0 Mutual-TLS Client Authentication as defined in RFC 8705.
     TLS_CLIENT_AUTH = 2;
+
+    // The client authenticates using a signed JWT assertion (RFC 7523).
+    // The ``token_secret`` in credentials must contain the PEM-encoded private key used to sign the assertion.
+    // The JWT assertion is sent as ``client_assertion`` in the token request body along with
+    // ``client_assertion_type=urn:ietf:params:oauth:client-assertion-type:jwt-bearer``.
+    PRIVATE_KEY_JWT = 3;
   }
 
   // Endpoint on the authorization server to retrieve the access token from.
@@ -187,6 +257,15 @@
   // If configured, the OAuth2 filter will redirect users to this endpoint when they access the signout_path.
   string end_session_endpoint = 23;
 
+  // Optional control for the ``post_logout_redirect_uri`` parameter sent to the ``end_session_endpoint`` when a user
+  // accesses the ``signout_path``.
+  // This field should be set only if ``openid`` is in the ``auth_scopes``, the ``end_session_endpoint`` is configured,
+  // and the authorization server supports the OpenID Connect RP-Initiated Logout specification.
+  //
+  // If unset, Envoy preserves the historical behavior and sends ``<scheme>://<host>/``, constructed from the inbound
+  // request, as ``post_logout_redirect_uri``.
+  PostLogoutRedirectUri post_logout_redirect_uri = 33;
+
   // Credentials used for OAuth.
   OAuth2Credentials credentials = 3 [(validate.rules).message = {required: true}];
 
@@ -207,6 +286,19 @@
   // Forward the OAuth token as a Bearer to upstream web service.
   bool forward_bearer_token = 7;
 
+  // Forward the OIDC ID token to the upstream.
+  //
+  // If the configured header is ``Authorization``, Envoy forwards the ID token using the
+  // ``Bearer`` prefix. For any other header, Envoy forwards the raw token value.
+  // If not specified, the ID token will not be forwarded.
+  //
+  // This can not be configured with :ref:`forward_bearer_token
+  // <envoy_v3_api_field_extensions.filters.http.oauth2.v3.OAuth2Config.forward_bearer_token>`
+  // or :ref:`preserve_authorization_header
+  // <envoy_v3_api_field_extensions.filters.http.oauth2.v3.OAuth2Config.preserve_authorization_header>`
+  // when the header is ``Authorization``.
+  OAuth2TokenForwarding forward_id_token = 31;
+
   // If set to true, preserve the existing authorization header.
   // By default the client strips the existing authorization header before forwarding upstream.
   // Can not be set to true if forward_bearer_token is already set to true.
@@ -304,6 +396,56 @@
   // Note: If a request matches pass_through_matcher, it bypasses OAuth validation and this matcher won't be evaluated.
   // This matcher takes precedence over deny_redirect_matcher.
   repeated config.route.v3.HeaderMatcher allow_failed_matcher = 27;
+
+  // Optional base URI (scheme + host, e.g. ``https://app.example.com``) used to build the
+  // original request URI that is encoded into the OAuth2 ``state`` parameter.
+  // This URI will be used later to redirect users on a successful OAuth.
+  //
+  // This is useful when Envoy sits behind a gateway or load balancer that terminates the
+  // user-facing hostname: In that case, the post-authentication redirect derived from ``state`` would
+  // send the user to an internal host they didn't request.
+  //
+  // Supports request header formatting tokens.
+  //
+  // Example:
+  //
+  //    original_request_uri: "%REQ(x-forwarded-proto?:scheme)%://%REQ(x-forwarded-host?:authority)%"
+  //
+  // If not set, defaults to ``<:scheme>://<:authority>`` of the incoming request.
+  string original_request_uri = 28;
+
+  // Optional list of domains that are allowed as
+  // 1. redirect_uri: which is what the IdP calls after OAuth
+  // 2. original_request_uri: the one extracted from the state of an OAuth callback (where should the request go after OAuth)
+  //
+  // This mitigates:
+  // - injecting a malicious x-forwarded-host or any header that is used to template the redirect urls
+  // - open redirect attacks where an attacker crafts a ``state`` value pointing to an untrusted host.
+  //
+  // Each entry is matched against the host (with any port stripped) extracted from the
+  // formatted ``redirect_uri``, the formatted ``original_request_uri``, and the URL decoded from
+  // the ``state`` parameter on callback. Matching is case-insensitive and supports two forms:
+  //
+  // * Exact match, e.g. ``example.com`` matches only ``example.com``.
+  // * Wildcard subdomain match using a leading ``*.``, e.g. ``*.example.com`` matches
+  //   ``foo.example.com`` and ``bar.baz.example.com`` but not ``example.com`` itself.
+  //
+  // IPv6 literals must be configured without surrounding brackets (e.g. ``::1``, not ``[::1]``).
+  //
+  // If this list is empty (the default), all hosts are allowed and no validation is performed.
+  repeated string allowed_redirect_domains = 29;
+
+  // If set to true, the expiration time for the ID token cookie will always be derived from the
+  // ``expires_in`` field of the access token response rather than from the ``exp`` claim in the
+  // ID token JWT. This is useful when the access token response advertises a longer lifetime than
+  // the ID token and you want the ID token cookie to remain valid for that full duration.
+  // Default is false (use the ID token's own ``exp`` claim when available).
+  bool use_access_token_expiry_for_id_token_cookie = 30;
+
+  // Configuration for ``PRIVATE_KEY_JWT`` client authentication.
+  // Only used when :ref:`auth_type <envoy_v3_api_field_extensions.filters.http.oauth2.v3.OAuth2Config.auth_type>`
+  // is set to ``PRIVATE_KEY_JWT``.
+  PrivateKeyJwtConfig private_key_jwt_config = 32;
 }
 
 // Per-route OAuth2 config.

envoy/extensions/filters/http/ratelimit/v3/rate_limit.proto:

--- shake256:9357baac054d71b1b6361fe24de5fd0b9ee746375f66e9cff832d5c836611c71319ecab5634d12f2cc4bd73d395f85ebb2abb06ce8921b856d6c5b862e927e49  envoy/extensions/filters/http/ratelimit/v3/rate_limit.proto
+++ shake256:dc3c8e72fda2ad3e68389021ba3c98c2fa6f659c2fe66962bf5c4a61f374cb5d4767608acc4996f5df6fea29e7bcd82f44776c7fbf5cceeb2afbb5fec211b373  envoy/extensions/filters/http/ratelimit/v3/rate_limit.proto
@@ -23,7 +23,7 @@
 // Rate limit :ref:`configuration overview <config_http_filters_rate_limit>`.
 // [#extension: envoy.filters.http.ratelimit]
 
-// [#next-free-field: 18]
+// [#next-free-field: 19]
 message RateLimit {
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.config.filter.http.rate_limit.v2.RateLimit";
@@ -186,6 +186,10 @@
   //   3. :ref:`disable_key <envoy_v3_api_field_config.route.v3.RateLimit.disable_key>`.
   //   4. :ref:`override limit <envoy_v3_api_field_config.route.v3.RateLimit.limit>`.
   repeated config.route.v3.RateLimit rate_limits = 17;
+
+  // The namespace where dynamic metadata from rate limit response is saved.
+  // If not set, the default is "envoy.filters.http.ratelimit".
+  string metadata_namespace = 18;
 }
 
 message RateLimitPerRoute {

envoy/extensions/filters/listener/proxy_protocol/v3/proxy_protocol.proto:

--- shake256:2a3f58f19a05d4bb14ea75736b81862c7acd196b73db4ed172be24876e6c9efc18905db4c243fe3a266c1b9f260aed9a3b7421ee76f5dc39ae73158ae4e7be9d  envoy/extensions/filters/listener/proxy_protocol/v3/proxy_protocol.proto
+++ shake256:2acc9f14baef8fd67df524cacd3fbac587f8f59708c0a8f3d0a254afb9e554e38a8ad1cbe13a6c23a63b35ac3ad58782c49c658a6451b834588f03c91ec2f1a8  envoy/extensions/filters/listener/proxy_protocol/v3/proxy_protocol.proto
@@ -33,11 +33,38 @@
   }
 
   message KeyValuePair {
+    // Specifies the encoding scheme that is used to encode the TLV value before it is
+    // stored in dynamic metadata or filter state.
+    enum ValueStringEncoding {
+      // Unspecified encoding scheme. Defaults to ``SANITIZED_UTF8``.
+      UNSPECIFIED = 0;
+
+      // The TLV value will be sanitized to a valid UTF-8 string before being stored:
+      // any invalid UTF-8 sequences will be replaced with the ``!`` character.
+      SANITIZED_UTF8 = 1;
+
+      // The raw TLV value will be encoded as a `Base64 <https://datatracker.ietf.org/doc/html/rfc4648#section-4>`_
+      // string (with padding) before being stored. This is useful for binary TLV values that
+      // are not valid UTF-8 strings.
+      BASE64 = 2;
+    }
+
     // The namespace — if this is empty, the filter's namespace will be used.
     string metadata_namespace = 1;
 
     // The key to use within the namespace.
     string key = 2 [(validate.rules).string = {min_len: 1}];
+
+    // The value encoding scheme that is used to encode the TLV value before it is stored in
+    // dynamic metadata or filter state. If not set, defaults to ``SANITIZED_UTF8``, which
+    // sanitizes the TLV value to a valid UTF-8 string.
+    //
+    // .. note::
+    //
+    //   This option only applies to the legacy untyped dynamic metadata and filter state.
+    //   For the new typed dynamic metadata, the raw TLV value bytes are stored as is and
+    //   no encoding is applied.
+    ValueStringEncoding value_string_encoding = 3;
   }
 
   // A Rule defines what metadata to apply when a header is present or missing.

envoy/extensions/filters/network/ext_proc/v3/ext_proc.proto:

--- shake256:8118f88a7d299a9b7a57a7a94aa210aca62d813d5e4d64cca7c913cbe8334daa5bf391ae923972f6abbbee1e223d62dcb39d823d26c5a1d487d1730c552bc10c  envoy/extensions/filters/network/ext_proc/v3/ext_proc.proto
+++ shake256:680442ffbffbd96a2d6cfaaa1efb97f319bb1e1728c5b10028f95e4d3ca011f618bdb38435ae7ac7d8cfa919a41064b52a90b6eec609b9ed12b6692633ae49ab  envoy/extensions/filters/network/ext_proc/v3/ext_proc.proto
@@ -105,4 +105,13 @@
   // Describes which typed or untyped dynamic metadata namespaces to forward to
   // the external processing server.
   MetadataNamespaces forwarding_namespaces = 1;
+
+  // Describes which typed or untyped dynamic metadata namespaces to receive
+  // from the external processing server.
+  // Since the server returns untyped dynamic metadata, this configuration acts
+  // as a allowlist. Only metadata namespaces explicitly listed here will be
+  // ingested by Envoy from the server's response.
+  // Receiving of typed metadata is not supported.
+  // Set to empty or leave unset to disallow writing any received dynamic metadata.
+  MetadataNamespaces receiving_namespaces = 2;
 }

envoy/extensions/filters/network/http_connection_manager/v3/http_connection_manager.proto:

--- shake256:5276dadd0bf0197f13e594b00a4b753a1cf6343d0096227d3fb065e3b8b670d3b879f6002183992964b8dd9f9d27b50864572c7ff4ff437bf89878f89992376e  envoy/extensions/filters/network/http_connection_manager/v3/http_connection_manager.proto
+++ shake256:95ea3b89fcffe04a590089cfea147025b8e96d0000467fea10539f5824c9002a55b828d8c3b8bc2e504a2962a5b229e3bce79cad9746661a1d12a548af8965e5  envoy/extensions/filters/network/http_connection_manager/v3/http_connection_manager.proto
@@ -39,7 +39,7 @@
 // HTTP connection manager :ref:`configuration overview <config_http_conn_man>`.
 // [#extension: envoy.filters.network.http_connection_manager]
 
-// [#next-free-field: 62]
+// [#next-free-field: 63]
 message HttpConnectionManager {
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.config.filter.network.http_connection_manager.v2.HttpConnectionManager";
@@ -664,6 +664,18 @@
   // 5000 milliseconds (5 seconds) if this option is not specified.
   google.protobuf.Duration drain_timeout = 12;
 
+  // Percentage-based jitter for ``drain_timeout``. If set, the actual drain grace period
+  // is extended by a random duration up to ``drain_timeout * jitter / 100`` per connection.
+  // This staggers the final GOAWAY (and connection close) across time so that connections
+  // entering the drain state simultaneously do not all complete draining at the same instant,
+  // mitigating thundering-herd reconnects. If not set, no jitter is added.
+  //
+  // This is analogous to
+  // :ref:`max_connection_duration_jitter
+  // <envoy_v3_api_field_config.core.v3.HttpProtocolOptions.max_connection_duration_jitter>`,
+  // but applied to the drain grace timer rather than the connection duration timer.
+  type.v3.Percent drain_timeout_jitter = 62;
+
   // The delayed close timeout is for downstream connections managed by the HTTP connection manager.
   // It is defined as a grace period after connection close processing has been locally initiated
   // during which Envoy will wait for the peer to close (i.e., a TCP FIN/RST is received by Envoy

envoy/extensions/filters/network/mongo_proxy/v3/mongo_proxy.proto:

--- shake256:ed382c5021bdd2dcdead147278a9b343cd78fa4e1e6142a09f0479375edf664c6d40fe69b7bcdcaf4a6ac500e5be27bfb824c402d6934695e605b5540ce6f17a  envoy/extensions/filters/network/mongo_proxy/v3/mongo_proxy.proto
+++ shake256:6ef88675ec00d3aec0ad8a311d84a2296974a7196f7809affe351951d799c4389d95a329bfc2e9b6cdd60bb53f8be6c956c0359da90373c0b226df9caed5bd3c  envoy/extensions/filters/network/mongo_proxy/v3/mongo_proxy.proto
@@ -4,6 +4,8 @@
 
 import "envoy/extensions/filters/common/fault/v3/fault.proto";
 
+import "google/protobuf/wrappers.proto";
+
 import "udpa/annotations/status.proto";
 import "udpa/annotations/versioning.proto";
 import "validate/validate.proto";
@@ -18,7 +20,7 @@
 // MongoDB :ref:`configuration overview <config_network_filters_mongo_proxy>`.
 // [#extension: envoy.filters.network.mongo_proxy]
 
-// [#next-free-field: 6]
+// [#next-free-field: 7]
 message MongoProxy {
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.config.filter.network.mongo_proxy.v2.MongoProxy";
@@ -46,4 +48,7 @@
   // Note that metrics will not be emitted for "find" commands, since those are considered
   // queries, and metrics for those are emitted under a dedicated "query" namespace.
   repeated string commands = 5;
+
+  // The maximum depth of a BSON document that Envoy will parse. Defaults to 100.
+  google.protobuf.UInt32Value max_bson_depth = 6 [(validate.rules).uint32 = {gt: 0}];
 }

envoy/extensions/filters/network/reverse_tunnel/v3/drain_aware_hcm.proto:

--- shake256:e94342f931679294c5668dadbbcbdd2d43d962e44a6017de46363582a4b449fad96be21769cb82507df29a74fe55489922e3fefe9bec6904eae3250a3ec1b00a  envoy/extensions/filters/network/reverse_tunnel/v3/drain_aware_hcm.proto
+++ shake256:f7f5312ba2a7f157bc5e6685f73718984650aedcfaec3ded6e01535805ecc7fe826ab1d6473647e6e9ca7b533306fd533956f31729650c5cec7656ae94adcd3e  envoy/extensions/filters/network/reverse_tunnel/v3/drain_aware_hcm.proto
@@ -26,4 +26,10 @@
 message DrainAwareHttpConnectionManager {
   // The underlying HCM configuration to apply.
   http_connection_manager.v3.HttpConnectionManager hcm_config = 1;
+
+  // When true, a peer-initiated GOAWAY on a reverse tunnel makes the initiator drop the draining
+  // tunnel and dial a replacement, so capacity is restored before the old tunnel closes while its
+  // in-flight streams finish. Default false, so the behavior is opt-in and unconfigured listeners
+  // are unaffected.
+  bool enable_drain_with_goaway = 2;
 }

envoy/extensions/filters/network/reverse_tunnel/v3/reverse_tunnel.proto:

--- shake256:e0ac16da7df32102eea87b502c619e734b84c9b3fb4b079fac46855d7289d7e1246d02d410fa6fec6b286b55c3c99a68c68e77e701640108b875e51597d754e8  envoy/extensions/filters/network/reverse_tunnel/v3/reverse_tunnel.proto
+++ shake256:323d69a823d3e0ff9288f728451afca371eef0ca458a73293c124822e90f70d53af71754605423710074150e30f5d2cbbaebf49117f93d7d85de1a0052885b2c  envoy/extensions/filters/network/reverse_tunnel/v3/reverse_tunnel.proto
@@ -96,7 +96,7 @@
 // Configuration for the reverse tunnel network filter.
 // This filter handles reverse tunnel connection acceptance and rejection by processing
 // HTTP requests where required identification values are provided via HTTP headers.
-// [#next-free-field: 7]
+// [#next-free-field: 9]
 message ReverseTunnel {
   // Ping interval for health checks on established reverse tunnel connections.
   // If not specified, defaults to ``2 seconds``.
@@ -133,4 +133,16 @@
   // via ``x-envoy-reverse-tunnel-upstream-cluster-name`` header. Connections with mismatched or missing
   // cluster names are rejected with HTTP ``400 Bad Request``. When empty, no cluster name validation is performed.
   string required_cluster_name = 6 [(validate.rules).string = {max_len: 255 ignore_empty: true}];
+
+  // Accept the handshake as an HTTP/1.1 ``Upgrade`` exchange (``Upgrade: reverse-tunnel``,
+  // reply ``101``) so HTTP proxies can route the handshake and splice the tunnel
+  // afterward. Non-upgrade requests are rejected with ``426``. The initiator must set this
+  // flag to the same value.
+  // Defaults to ``false``.
+  bool use_http_upgrade = 7;
+
+  // When true, skip worker-thread rebalancing for accepted reverse tunnel connections.
+  // This avoids the cross-worker lock in pickLeastLoadedSocketManager.
+  // Default: false (rebalancing enabled).
+  bool skip_rebalancing = 8;
 }

envoy/extensions/filters/network/tcp_proxy/v3/tcp_proxy.proto:

--- shake256:8ff13155179a98aba30f110331cedf1d77369597acbf5c87d52f414c484aef53a2820a949db85adf813e1be5d3bc867f4e0748b949ce4f13bc624913ff17078a  envoy/extensions/filters/network/tcp_proxy/v3/tcp_proxy.proto
+++ shake256:ca31ea64c3f60b2281935bbb9e7c15b7ba610c02c80f75ee2bbbdd4631b4fc0e44575161eb5252f379f5ea0717b08f23664df6137f519ce900ddabd54a340309  envoy/extensions/filters/network/tcp_proxy/v3/tcp_proxy.proto
@@ -6,6 +6,7 @@
 import "envoy/config/core/v3/backoff.proto";
 import "envoy/config/core/v3/base.proto";
 import "envoy/config/core/v3/config_source.proto";
+import "envoy/config/core/v3/extension.proto";
 import "envoy/config/core/v3/proxy_protocol.proto";
 import "envoy/extensions/filters/network/http_connection_manager/v3/http_connection_manager.proto";
 import "envoy/type/v3/hash_policy.proto";
@@ -80,7 +81,7 @@
   APPEND_IF_EXISTS_OR_ADD = 2;
 }
 
-// [#next-free-field: 24]
+// [#next-free-field: 25]
 message TcpProxy {
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.config.filter.network.tcp_proxy.v2.TcpProxy";
@@ -119,7 +120,7 @@
   // Configuration for tunneling TCP over other transports or application layers.
   // Tunneling is supported over HTTP/1.1 and HTTP/2. The upstream protocol is
   // determined by the cluster configuration.
-  // [#next-free-field: 10]
+  // [#next-free-field: 11]
   message TunnelingConfig {
     option (udpa.annotations.versioning).previous_message_type =
         "envoy.config.filter.network.tcp_proxy.v2.TcpProxy.TunnelingConfig";
@@ -200,6 +201,12 @@
     // This enables customizing the key used by access log formatters such as
     // ``%DYNAMIC_METADATA(envoy.filters.network.tcp_proxy:<key>)%``.
     string request_id_metadata_key = 9;
+
+    // Specifies a collection of Formatter plugins that can be used in substitution formatters
+    // in ``headers_to_add``.
+    // See the formatters extensions documentation for details.
+    // [#extension-category: envoy.formatter]
+    repeated config.core.v3.TypedExtensionConfig formatters = 10;
   }
 
   message OnDemand {
@@ -390,4 +397,11 @@
   //   Use this carefully with server-first protocols. The upstream may send data before
   //   receiving anything from downstream, which could fill the early data buffer.
   google.protobuf.UInt32Value max_early_data_bytes = 22 [(validate.rules).uint32 = {lte: 1048576}];
+
+  // If set to ``true``, the TCP proxy checks if the downstream connection was marked as drained
+  // after each read or write. When drain close is requested for the listener's traffic direction,
+  // the downstream connection is closed with ``FlushWrite``.
+  //
+  // This is disabled by default for backward compatibility.
+  google.protobuf.BoolValue check_drain_close = 24;
 }

envoy/extensions/load_balancing_policies/client_side_weighted_round_robin/v3/client_side_weighted_round_robin.proto:

--- shake256:894ee44a49e973f8c2e094bfa3053351c0826c3da87d2f0f54d1d6c907892e49355a9437d0c938581bae75af5da62139bb562d43989ea7af85cc643cff01ac52  envoy/extensions/load_balancing_policies/client_side_weighted_round_robin/v3/client_side_weighted_round_robin.proto
+++ shake256:ed80461fd767155c24d6fdfaa7f620d4db8ac5868cf1a1bbfb302f4ecc1790582dc99575a1003b34d949bb8f27c6e92f4ed22e2a5007f4c92af3cf49d10611c4  envoy/extensions/load_balancing_policies/client_side_weighted_round_robin/v3/client_side_weighted_round_robin.proto
@@ -44,7 +44,7 @@
 // See the :ref:`load balancing architecture
 // overview<arch_overview_load_balancing_types>` for more information.
 //
-// [#next-free-field: 9]
+// [#next-free-field: 10]
 message ClientSideWeightedRoundRobin {
   // Whether to enable out-of-band utilization reporting collection from
   // the endpoints. By default, per-request utilization reporting is used.
@@ -88,4 +88,9 @@
   // Configuration for slow start mode.
   // If this configuration is not set, slow start will not be not enabled.
   common.v3.SlowStartConfig slow_start_config = 8;
+
+  // Optional overrides for the OOB reporting connection (alternative port,
+  // ``:authority``, transport socket selection). Honored only when
+  // ``enable_oob_load_report`` is true.
+  common.v3.OrcaOobReportingConfig oob_reporting_config = 9;
 }

envoy/extensions/load_balancing_policies/common/v3/common.proto:

--- shake256:87692495bfc4ebe3af7e717827ef318d02ea70d14321bdb6a752efb7b21fb7ea727e7c085cfbac1b698eab1506a9ac73b97ba663a8ddb5d1a24eea0dc07fd5c4  envoy/extensions/load_balancing_policies/common/v3/common.proto
+++ shake256:7617bafaedc15daaf00b90c6fcdb3078dcba4d99d0d280ebadd1e9b19c871ca9f3374e9cd358afd91c0d232a75687bc861c7ca3ffdc48d75d6fa82c9b6aab406  envoy/extensions/load_balancing_policies/common/v3/common.proto
@@ -7,6 +7,7 @@
 import "envoy/type/v3/percent.proto";
 
 import "google/protobuf/duration.proto";
+import "google/protobuf/struct.proto";
 import "google/protobuf/wrappers.proto";
 
 import "envoy/annotations/deprecation.proto";
@@ -159,3 +160,29 @@
   // will be ignored.
   repeated config.route.v3.RouteAction.HashPolicy hash_policy = 3;
 }
+
+// Connection overrides for the ORCA out-of-band (OOB) reporting stream, used by
+// load balancing policies that consume ORCA load reports (e.g.
+// :ref:`client_side_weighted_round_robin
+// <envoy_v3_api_msg_extensions.load_balancing_policies.client_side_weighted_round_robin.v3.ClientSideWeightedRoundRobin>`).
+// Whether and when OOB reporting runs is controlled by the embedding policy.
+message OrcaOobReportingConfig {
+  // Optional alternative port for the OOB reporting connection, for example an
+  // ORCA reporting sidecar listening on a dedicated port. If 0 or unset, the
+  // port of the host's ORCA reporting address is used. Ignored for non-IP
+  // (pipe/UDS) host addresses.
+  uint32 port_value = 1 [(validate.rules).uint32 = {lte: 65535}];
+
+  // Value of the ``:authority`` header on the OOB gRPC stream. If empty, the
+  // endpoint hostname is used, then the dialed address, then the cluster name.
+  string authority = 2
+      [(validate.rules).string = {well_known_regex: HTTP_HEADER_VALUE strict: false}];
+
+  // Optional key/value pairs used to select a transport socket from the
+  // cluster's :ref:`transport_socket_matches
+  // <envoy_v3_api_field_config.cluster.v3.Cluster.transport_socket_matches>`
+  // for the OOB connection. If unset, or if no match is found, the cluster's
+  // default transport socket is used. ALPN ``h2`` is always forced on the OOB
+  // connection regardless of this setting.
+  google.protobuf.Struct transport_socket_match_criteria = 3;
+}

envoy/extensions/network/dns_resolver/cares/v3/cares_dns_resolver.proto:

--- shake256:f0a4d81196f500745a531f588d89c7622fe7d394cb4b967d4a12de27a8b9b9cbc84bfd0ba97446abf7d556c15a5071830c1599a7fe37028e9b5149c85afd7cce  envoy/extensions/network/dns_resolver/cares/v3/cares_dns_resolver.proto
+++ shake256:2427c045d79d2731c598c802ecf997935f8195ddc454465c8dcfe7d9f3d20c4304a0ed54bf57b2530d9cd4f789fb1c0c6da605ec3aae83bd1e6f9c5a3408e543  envoy/extensions/network/dns_resolver/cares/v3/cares_dns_resolver.proto
@@ -21,7 +21,7 @@
 // [#extension: envoy.network.dns_resolver.cares]
 
 // Configuration for c-ares DNS resolver.
-// [#next-free-field: 12]
+// [#next-free-field: 13]
 message CaresDnsResolverConfig {
   // A list of DNS resolver addresses.
   // :ref:`use_resolvers_as_fallback <envoy_v3_api_field_extensions.network.dns_resolver.cares.v3.CaresDnsResolverConfig.use_resolvers_as_fallback>`
@@ -113,4 +113,14 @@
   //
   // Default is false.
   bool reinit_channel_on_timeout = 11;
+
+  // The maximum duration (in seconds) for which DNS responses will be cached by c-ares.
+  //
+  // If set to a non-zero value, the query cache is enabled and will respect the
+  // TTL provided in the DNS response, up to this maximum limit.
+  //
+  // .. note::
+  //   While the underlying c-ares library defaults to 1 hour, Envoy's default
+  //   for this field is 0, which disables the query cache entirely.
+  google.protobuf.UInt32Value qcache_max_ttl = 12 [(validate.rules).uint32 = {gte: 0}];
 }

envoy/extensions/network/socket_interface/v3/default_socket_interface.proto:

--- shake256:c4b373033fef9f58de1beaff37f5c835eecbc378b775d04d08147b3cbacbfc6629923f109eb754096604444c7791a43edbe0a15398843c7790a20aac6e82ae1c  envoy/extensions/network/socket_interface/v3/default_socket_interface.proto
+++ shake256:c0b8cacef281eaec500f13691e055259c28c5c56f06be4393eaf634ad3ecc9cff662fd9847c14a0b2b7a2992f0e3ebed1d324ea209a3fd242253184083e533ce  envoy/extensions/network/socket_interface/v3/default_socket_interface.proto
@@ -5,6 +5,7 @@
 import "google/protobuf/wrappers.proto";
 
 import "udpa/annotations/status.proto";
+import "validate/validate.proto";
 
 option java_package = "io.envoyproxy.envoy.extensions.network.socket_interface.v3";
 option java_outer_classname = "DefaultSocketInterfaceProto";
@@ -14,33 +15,81 @@
 
 // [#protodoc-title: Default socket interface configuration]
 
-// Configuration for default socket interface that relies on OS dependent syscall to create
+// Configuration for the default socket interface that relies on OS-dependent syscalls to create
 // sockets.
 message DefaultSocketInterface {
-  // io_uring options. io_uring is only valid in Linux with at least kernel version 5.11. Otherwise,
-  // Envoy will fall back to use the default socket API. If not set then io_uring will not be
-  // enabled.
+  // Options for ``io_uring``-based socket I/O. ``io_uring`` is only supported on Linux with
+  // kernel version 5.11 or later. On unsupported platforms, Envoy falls back to the default
+  // socket API.
+  //
+  // .. note::
+  //
+  //   If not set, ``io_uring`` will not be enabled and the standard epoll-based I/O path
+  //   is used.
   IoUringOptions io_uring_options = 1;
 }
 
+// Configuration for ``io_uring``-based asynchronous I/O.
+//
+// Each worker thread creates its own ``io_uring`` instance during initialization. Operations
+// are submitted to the submission queue (SQ) and completions are reaped from the completion
+// queue (CQ) via an eventfd integrated with the worker's event loop.
+//
+// .. warning::
+//
+//   ``io_uring`` support is experimental and its performance characteristics depend heavily on
+//   the kernel version.
+//
+// [#next-free-field: 8]
 message IoUringOptions {
-  // The size for io_uring submission queues (SQ). io_uring is built with a fixed size in each
-  // thread during configuration, and each io_uring operation creates a submission queue
-  // entry (SQE). The default is 1000.
+  // The number of entries in the ``io_uring`` submission queue (SQ). Each in-flight I/O
+  // operation requires one SQE. The completion queue (CQ) is sized at ``2x`` this value
+  // to provide overflow headroom. If not specified, defaults to 1000.
   google.protobuf.UInt32Value io_uring_size = 1;
 
-  // Enable io_uring submission queue polling (SQPOLL). io_uring SQPOLL mode polls all SQEs in the
-  // SQ in the kernel thread. io_uring SQPOLL mode may reduce latency and increase CPU usage as a
-  // cost. The default is false.
+  // Enables ``io_uring`` submission queue polling (``SQPOLL``). When enabled, a dedicated
+  // kernel thread polls the SQ for new entries, eliminating the ``io_uring_enter()`` syscall
+  // on submission. This may reduce latency at the cost of increased CPU usage.
+  // If not specified, defaults to false.
   bool enable_submission_queue_polling = 2;
 
-  // The size of an io_uring socket's read buffer. Each io_uring read operation will allocate a
-  // buffer of the given size. If the given buffer is too small, the socket will have read multiple
-  // times for all the data. The default is 8192.
+  // The starting size in bytes of the buffer for each ``readv``-based ``io_uring`` read. Envoy
+  // grows the next read up to 16 times this size while reads keep filling the buffer and resets it
+  // otherwise, so large transfers use fewer reads. When ``enable_multishot_receive`` is set, this
+  // is also the size of each kernel-provided buffer. If not specified, defaults to 8192.
   google.protobuf.UInt32Value read_buffer_size = 3;
 
-  // The write timeout of an io_uring socket on closing in ms. io_uring writes and closes
-  // asynchronously. If the remote stops reading, the io_uring write operation may never complete.
-  // The operation is canceled and the socket is closed after the timeout. The default is 1000.
+  // The timeout in milliseconds to wait for pending write operations to complete when closing
+  // a socket. ``io_uring`` writes are asynchronous. If the remote peer stops reading, a write
+  // may never complete. After this timeout, pending writes are canceled and the socket is
+  // closed. If not specified, defaults to 1000.
   google.protobuf.UInt32Value write_timeout_ms = 4;
+
+  // The high watermark in bytes for the write buffer. When the amount of pending write data
+  // exceeds this threshold, the socket stops accepting new writes from the connection so that
+  // backpressure propagates to the upper layers. If not specified, defaults to 131072 (128 KiB).
+  // When set, the value must be at least 4096 (4 KiB).
+  google.protobuf.UInt32Value write_high_watermark_bytes = 5
+      [(validate.rules).uint32 = {gte: 4096}];
+
+  // The low watermark in bytes for the write buffer. After the buffer has exceeded
+  // ``write_high_watermark_bytes`` and writes were paused, the socket resumes accepting writes
+  // once the pending write data drops to or below this value.
+  // If not specified, defaults to 16384 (16 KiB).
+  // When set, the value must be at least 1024 (1 KiB).
+  //
+  // .. note::
+  //
+  //   This value must be less than ``write_high_watermark_bytes``. If misconfigured, it is
+  //   clamped to ``write_high_watermark_bytes / 2``.
+  google.protobuf.UInt32Value write_low_watermark_bytes = 6 [(validate.rules).uint32 = {gte: 1024}];
+
+  // Enables ``multishot`` reads backed by a kernel-provided buffer ring. A single ``recv`` is armed
+  // per socket and the kernel keeps delivering data as it arrives without a new submission per
+  // read, which reduces event loop wakeups and read submissions for read-heavy workloads. The ring
+  // holds ``io_uring_size`` buffers rounded up to a power of two and capped at 4096, each
+  // ``read_buffer_size`` bytes, so each worker thread uses up to that buffer count times
+  // ``read_buffer_size`` bytes for the pool. Requires Linux kernel 6.0 or later. On older kernels,
+  // Envoy falls back to ``readv``-based reads. If not specified, defaults to false.
+  bool enable_multishot_receive = 7;
 }

envoy/extensions/path/match/uri_template/v3/uri_template_match.proto:

--- shake256:b59aa69fbb5a3fd019d0629969b596f1ef33d11c2db37b7167c80d49825c56ba11514538b5b5e18d9305862104bfd2ce2232b462a3632484756a12bdf3287943  envoy/extensions/path/match/uri_template/v3/uri_template_match.proto
+++ shake256:8d63a86e1ba331db3c1eb63403cb19840d08f75120d4e70dda5b508eb588b9d2ae8c7772bbc76bb08139301074b556635b685264ca462c1392d37f808a927ca4  envoy/extensions/path/match/uri_template/v3/uri_template_match.proto
@@ -31,6 +31,10 @@
 //
 // * ``{name=**}`` : A named variable matching zero or more path segments.
 //
+// * ``prefix{name}suffix`` : A named variable with surrounding literal text within a single path
+//      segment. For example, ``v{version}`` or ``{id}.json``. The variable captures only the
+//      dynamic portion; the prefix and suffix must match literally.
+//
 //
 // For example:
 //
@@ -39,6 +43,9 @@
 // * ``/videos/{file}`` would match ``/videos/1080p5000_00001.m4s``
 //
 // * ``/**.mpd`` would match ``/content/123/india/dash/55/manifest.mpd``
+//
+// * ``/api/v{version}/users/{id}.json`` would match ``/api/v2/users/456.json`` and
+//      capture ``version=2`` and ``id=456``.
 message UriTemplateMatchConfig {
   string path_template = 1 [(validate.rules).string = {min_len: 1 max_len: 256}];
 }

envoy/extensions/resource_monitors/fixed_heap/v3/fixed_heap.proto:

--- shake256:12822650ee1addeed10c840b45b21a1578afff4ad262643364a5379a198fcf23dcb812e68cb8be40cea686ad0d4b6e575e1cd439a8ad5a261980f56e4b4f7ee4  envoy/extensions/resource_monitors/fixed_heap/v3/fixed_heap.proto
+++ shake256:408e426cc34122459981ce3a978710b67ce7d2b5d105e81434799f1b916114bea15caf7249eefcb47e4f4bea89667852b7a1c8d790edb5a8eba00adb260309d7  envoy/extensions/resource_monitors/fixed_heap/v3/fixed_heap.proto
@@ -2,9 +2,10 @@
 
 package envoy.extensions.resource_monitors.fixed_heap.v3;
 
+import "envoy/config/core/v3/base.proto";
+
 import "udpa/annotations/status.proto";
 import "udpa/annotations/versioning.proto";
-import "validate/validate.proto";
 
 option java_package = "io.envoyproxy.envoy.extensions.resource_monitors.fixed_heap.v3";
 option java_outer_classname = "FixedHeapProto";
@@ -22,5 +23,14 @@
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.config.resource_monitor.fixed_heap.v2alpha.FixedHeapConfig";
 
-  uint64 max_heap_size_bytes = 1 [(validate.rules).uint64 = {gt: 0}];
+  // Static value for max heap size in bytes set at startup.
+  // Exactly one of max_heap_size_bytes or max_heap_size_bytes_runtime must be set.
+  // If set, the expected value must be greater than ``0``, otherwise validation will fail.
+  uint64 max_heap_size_bytes = 1;
+
+  // Runtime overlay for max heap size in bytes. When set, the value can be overridden
+  // at runtime during startup or later without restart.
+  // Exactly one of max_heap_size_bytes or max_heap_size_bytes_runtime must be set.
+  // If set, the expected value must be greater than ``0``, otherwise validation will fail.
+  config.core.v3.RuntimeUInt64 max_heap_size_bytes_runtime = 2;
 }

envoy/extensions/stat_sinks/open_telemetry/v3/open_telemetry.proto:

--- shake256:bffab6b3fe18a9471932c49ff69ad67b2f4082bb3cbbbd90f28202e2281cc5a58df44d992feee581b7ccff04d7ee782b374f12da34ecc39a08d45ddcfaa342ae  envoy/extensions/stat_sinks/open_telemetry/v3/open_telemetry.proto
+++ shake256:2493a7eda4bca154b91ea0cefed9b3256f13d1896a9265b4306e8a29cccde89e26baa225880cd46f877fed825bdc337aaf045ef2ed42786eaa2124f221e3a3b6  envoy/extensions/stat_sinks/open_telemetry/v3/open_telemetry.proto
@@ -24,7 +24,7 @@
 // Stats configuration proto schema for ``envoy.stat_sinks.open_telemetry`` sink.
 // [#extension: envoy.stat_sinks.open_telemetry]
 
-// [#next-free-field: 10]
+// [#next-free-field: 11]
 message SinkConfig {
   // ConversionAction is used to convert a stat to a metric. If a stat matches,
   // the metric_name and static_metric_labels will be
@@ -94,4 +94,8 @@
   // - ``envoy.extensions.stat_sinks.open_telemetry.v3.SinkConfig.ConversionAction``.
   // If stats are not matched, they will be directly converted to OTLP metrics as usual.
   xds.type.matcher.v3.Matcher custom_metric_conversions = 8;
+
+  // Maximum number of data points per request. If explicitly set to 0, there is no limit. If unset, it currently defaults to no limit.
+  // When the maximum number of data points is reached, the remaining data points will be sent in subsequent requests.
+  uint32 max_data_points_per_request = 10;
 }

envoy/extensions/transport_sockets/quic/v3/quic_transport.proto:

--- shake256:5c82678245095a18a9122648576780eb70221f36a71127ab80f6edd19b9c2316831b39b49848b5df74c31c208e4e16220772d4b0d8d47616ec718ed88f7edcab  envoy/extensions/transport_sockets/quic/v3/quic_transport.proto
+++ shake256:a73ea65dd0a92900ce187d3404a8d0a85c928a68ef98fdaa42597900c5e2239d25e2d3331439c2ca817927acd69df65d5e6d72724f5f53a03dd230c20425b45a  envoy/extensions/transport_sockets/quic/v3/quic_transport.proto
@@ -27,6 +27,10 @@
   // If false, QUIC will tell TLS to reject any early data and to stop issuing 0-RTT credentials with resumption session tickets. This will prevent clients from sending 0-RTT requests.
   // Default to true.
   google.protobuf.BoolValue enable_early_data = 2;
+
+  // If false, TLS session tickets are not issued and accepted by QUIC.
+  // Default to true.
+  google.protobuf.BoolValue enable_resumption = 3;
 }
 
 // Configuration for Upstream QUIC transport socket. This provides Google's implementation of Google QUIC and IETF QUIC to Envoy.

envoy/extensions/transport_sockets/tls/v3/common.proto:

--- shake256:e5c7d2878ae07f98b7b076de1060c76cae457efb0558322736cdc1139f8c38c3bbada85ae0efbe867f5e8aae201c82d0aadba8f88a4c217cfc315c96a4b1ea98  envoy/extensions/transport_sockets/tls/v3/common.proto
+++ shake256:e1e0d5919ceef76ce7a6329062704ac251f7b9285d3493b1612cd9fa2191d8cb23cb5e78569b409aa3706a3adb7bedf2e6e406f19fcac2a0f7a0c734e2babb07  envoy/extensions/transport_sockets/tls/v3/common.proto
@@ -57,9 +57,44 @@
     //
     // .. attention::
     //
-    //   Please refer to `BoringSSL policies <https://boringssl.googlesource.com/boringssl/+/refs/tags/0.20240913.0/include/openssl/ssl.h#5608>`_
+    //   Please refer to the `BoringSSL FIPS_202205 compliance policy <https://boringssl.googlesource.com/boringssl/+/refs/tags/0.20240913.0/include/openssl/ssl.h#5608>`_
     //   for details.
     FIPS_202205 = 0;
+
+    // CNSA2_202603 configures a TLS connection to use:
+    //
+    //   * Only TLS 1.3, with AES-256-GCM.
+    //   * Only ML-KEM-1024 for key agreement.
+    //   * For handshake signatures, only ECDSA with P-384 and SHA-384, or RSA
+    //     with SHA-384.
+    //
+    // Note: this setting aids with compliance with CNSA requirements but does not
+    // guarantee it. Careful reading of ``draft-becker-cnsa2-tls-profile`` is
+    // recommended.
+    //
+    // .. attention::
+    //
+    //   Please refer to the `BoringSSL CNSA2_202603 compliance policy <https://boringssl.googlesource.com/boringssl/+/refs/tags/0.20260413.0/include/openssl/ssl.h#6293>`_
+    //   for details.
+    CNSA2_202603 = 1;
+
+    // CNSA1_202603 configures a TLS connection to use:
+    //   * TLS 1.2 or TLS 1.3.
+    //   * For TLS 1.2, only TLS_ECDHE_[ECDSA|RSA]_WITH_AES_256_GCM_SHA384.
+    //   * For TLS 1.3, only AES-256-GCM.
+    //   * ML-KEM-1024 or P-384 for key agreement, preferring ML-KEM-1024 if the
+    //     client supports it.
+    //   * For handshake signatures, only ECDSA with P-384 and SHA-384, or RSA
+    //     with SHA-384.
+    //
+    // Note: this setting aids with compliance with CNSA requirements but does not
+    // guarantee it. Careful reading of RFC 9151 is recommended.
+    //
+    // .. attention::
+    //
+    //   Please refer to the `BoringSSL CNSA1_202603 compliance policy <https://boringssl.googlesource.com/boringssl/+/refs/tags/0.20260413.0/include/openssl/ssl.h#6280>`_
+    //   for details.
+    CNSA1_202603 = 2;
   }
 
   // Minimum TLS protocol version. By default, it's ``TLSv1_2`` for both clients and servers.
@@ -369,7 +404,7 @@
   string oid = 3;
 }
 
-// [#next-free-field: 18]
+// [#next-free-field: 19]
 message CertificateValidationContext {
   option (udpa.annotations.versioning).previous_message_type =
       "envoy.api.v2.auth.CertificateValidationContext";
@@ -594,4 +629,28 @@
   // in OpenSSL 1.1.x and newer versions of BoringSSL in that the trust anchor is included.
   // Trusted issues are specified by setting :ref:`trusted_ca <envoy_v3_api_field_extensions.transport_sockets.tls.v3.CertificateValidationContext.trusted_ca>`
   google.protobuf.UInt32Value max_verify_depth = 16 [(validate.rules).uint32 = {lte: 100}];
+
+  // If true, the server does not include the trusted-CA distinguished names in the
+  // TLS ``CertificateRequest`` message. CAs from :ref:`trusted_ca
+  // <envoy_v3_api_field_extensions.transport_sockets.tls.v3.CertificateValidationContext.trusted_ca>`
+  // are still used to validate presented client certificates; only the wire
+  // advertisement changes.
+  //
+  // This is useful when the configured CA set is large enough that the
+  // ``CertificateRequest`` would exceed client-side TLS record limits, or when
+  // clients mishandle the CA set in some way.
+  //
+  // .. attention::
+  //
+  //   When enabled, clients that rely on the advertised CA list to select among
+  //   multiple client certificates may now send no certificate or the wrong one;
+  //   validation will then fail with the standard TLS alert.
+  //
+  // This option only affects downstream (server) TLS connections where Envoy sends a
+  // ``CertificateRequest`` to clients. It has no effect on upstream connections.
+  //
+  // Honored by the built-in validator and the SPIFFE validator. Validators that do
+  // not set a client CA list themselves (e.g., the dynamic-modules validator) are
+  // unaffected. Defaults to false.
+  bool suppress_client_ca_list = 18;
 }

envoy/extensions/transport_sockets/tls/v3/tls.proto:

--- shake256:96fc1618d65403ba6252ac34923a8a845f502983f41ed0b6573c7514d19bed6783f4103e08c8b0c0b50ee50a4361cc74889027aad77e3ab89dca6d7e5361000b  envoy/extensions/transport_sockets/tls/v3/tls.proto
+++ shake256:d6ce09b7e5d772dc134ba451fb8c99e1c8e0dc921a49c34ec5d93088e8e050258f4db162d2491a5e0e5d2061d78ab985f7503b06d6eb94bf12f9e5fe8d18a1c5  envoy/extensions/transport_sockets/tls/v3/tls.proto
@@ -73,14 +73,13 @@
   // Defaults to 1, setting this to 0 disables session resumption.
   google.protobuf.UInt32Value max_session_keys = 4;
 
-  // Controls enforcement of the ``keyUsage`` extension in peer certificates. If set to ``true``, the handshake will fail if
-  // the ``keyUsage`` is incompatible with TLS usage.
+  // Controls enforcement of the ``keyUsage`` extension in peer certificates. If set to ``true``,
+  // the handshake will fail if the ``keyUsage`` is incompatible with TLS usage.
   //
-  // .. note::
-  //   The default value is ``true`` (i.e., enforcement on).
+  // .. attention::
   //
-  // The ``ssl.was_key_usage_invalid`` in :ref:`listener metrics <config_listener_stats>` metric will be incremented
-  // for configurations that would fail if this option were enabled.
+  //   This field is deprecated and ignored. Envoy now always enforces the ``keyUsage`` extension
+  //   in peer certificates, making this option unconfigurable.
   google.protobuf.BoolValue enforce_rsa_key_usage = 5
       [deprecated = true, (envoy.annotations.deprecated_at_minor_version) = "3.0"];
 }

envoy/service/network_ext_proc/v3/network_external_processor.proto:

--- shake256:8bd5e085a8a4d58e707005ccc2150b5e4ba95ee45625ee96156e4daa0b9c5e95204c74ea56fcf7f4ee6d28471cb4adcd6b55501c53f4432360641b19f6c3adb5  envoy/service/network_ext_proc/v3/network_external_processor.proto
+++ shake256:e870bf82f1725fad89f9cdbcf6aac0209c0b792523eec0f54ed0c2a277d22c66caaa75a8ccd5ea834b867a991c040594d285be61249fe6d5afc29fc21836673e  envoy/service/network_ext_proc/v3/network_external_processor.proto
@@ -95,7 +95,7 @@
 // ProcessingResponse contains the response from the external processing server to Envoy.
 // Each response corresponds to a ProcessingRequest and indicates how the network
 // traffic should be handled.
-// [#next-free-field: 6]
+// [#next-free-field: 7]
 message ProcessingResponse {
   // DataProcessedStatus indicates whether the data was modified by the external processor.
   enum DataProcessedStatus {
@@ -157,4 +157,21 @@
   // The metadata is not automatically propagated from request to response.
   // The external processor must include any needed metadata in its response.
   google.protobuf.Struct dynamic_metadata = 5;
+
+  // If set to true, Envoy will close the gRPC stream to the external processor
+  // after applying this response. Subsequent data will bypass the ext_proc filter
+  // as if it were configured in SKIP mode.
+  //
+  // .. note::
+  //   This should only be used when there is a strong protocol guarantee
+  //   that no additional data chunks are in-flight on the wire. Because Envoy
+  //   immediately drains its local buffer when forwarding bytes to the external
+  //   processor, if Envoy has already dispatched subsequent data chunks before this
+  //   stream is closed, those in-flight bytes will be permanently lost and not
+  //   injected back into the filter chain.
+  //
+  // This feature is primarily designed for tightly-coupled synchronous protocols,
+  // such as reading the ClientHello during a TLS handshake, where the sender
+  // naturally halts transmission while awaiting the receiver's response.
+  bool close_stream_to_ext_proc_server = 6;
 }

envoy/service/ratelimit/v3/rls.proto:

--- shake256:9641a91435e6e6b8c64e8e68adb42c0ce592170cc68972d4724169361766892b4d2a00b16e4dc9a2863d7b4d05ff1ebd27e820622355d2de4f5d09b7d71983ef  envoy/service/ratelimit/v3/rls.proto
+++ shake256:4d2cdb7b5a97447afa3a31c9430712528fdee48f57628e528e1f9a033d8af309b25ab63085729223f6fc1a5e0514cadbe7574e858edb7e3fb8ce813e579931c6  envoy/service/ratelimit/v3/rls.proto
@@ -209,7 +209,9 @@
   // filter. This metadata lives in a namespace specified by the canonical name of extension filter
   // that requires it:
   //
-  // - :ref:`envoy.filters.http.ratelimit <config_http_filters_ratelimit_dynamic_metadata>` for HTTP filter.
+  // - :ref:`envoy.filters.http.ratelimit <config_http_filters_ratelimit_dynamic_metadata>` for HTTP filter. The default namespace can
+  //   be modified by setting the :ref:`metadata_namespace <envoy_v3_api_field_extensions.filters.http.ratelimit.v3.RateLimit.metadata_namespace>`
+  //   in the filter configuration.
   // - :ref:`envoy.filters.network.ratelimit <config_network_filters_ratelimit_dynamic_metadata>` for network filter.
   // - :ref:`envoy.filters.thrift.rate_limit <config_thrift_filters_rate_limit_dynamic_metadata>` for Thrift filter.
   google.protobuf.Struct dynamic_metadata = 6;

envoy/type/v3/token_bucket.proto:

--- shake256:cdd6fe9a656c7bde8194e9107f48f520b6f73ad7bc8a01b61df2fc56a9a79a09338503cbbcf457e0a9ec23b069851eb6deac656ba2ef31ef19bcc0b5b7fdb69d  envoy/type/v3/token_bucket.proto
+++ shake256:c32272c0fc9a70c1d5da0b778c77ae575973f21f3cf77f7c7505c24fdbc365051cf6fd75f152198973fc47af62d7f491aa5b847df54d9fc030d6606f1772678a  envoy/type/v3/token_bucket.proto
@@ -22,8 +22,9 @@
   option (udpa.annotations.versioning).previous_message_type = "envoy.type.TokenBucket";
 
   // The maximum tokens that the bucket can hold. This is also the number of tokens that the bucket
-  // initially contains.
-  uint32 max_tokens = 1 [(validate.rules).uint32 = {gt: 0}];
+  // initially contains. A value of 0 means the bucket will always be empty and all requests will
+  // be rate limited (i.e., always reject).
+  uint32 max_tokens = 1 [(validate.rules).uint32 = {gte: 0}];
 
   // The number of tokens added to the bucket during each fill interval. If not specified, defaults
   // to a single token.

Comment thread modules/sync/state.json
{
"module_name": "googleapis/cloud-run",
"latest_reference": "70b366e4a2bf0bb6cc484aab44912cfbad4f916f"
"latest_reference": "8762e2c5ca67a7d1a4e1f5207c24d7b359ea00ff"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[Posted at 2026-07-15T12:30:04Z]

Overall transition

$ casdiff 70b366e4a2bf0bb6cc484aab44912cfbad4f916f \
          8762e2c5ca67a7d1a4e1f5207c24d7b359ea00ff \
          --format=markdown

0 files changed: 0 removed, 0 renamed, 0 added, 0 changed content.

Comment thread modules/sync/state.json
{
"module_name": "googleapis/googleapis",
"latest_reference": "70b366e4a2bf0bb6cc484aab44912cfbad4f916f"
"latest_reference": "8762e2c5ca67a7d1a4e1f5207c24d7b359ea00ff"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[Posted at 2026-07-15T12:30:05Z]

Overall transition

$ casdiff 70b366e4a2bf0bb6cc484aab44912cfbad4f916f \
          8762e2c5ca67a7d1a4e1f5207c24d7b359ea00ff \
          --format=markdown

0 files changed: 0 removed, 0 renamed, 0 added, 0 changed content.

@pkwarren
pkwarren merged commit 12a6890 into main Jul 15, 2026
6 checks passed
@pkwarren
pkwarren deleted the fetch-modules branch July 15, 2026 13:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant