## apache/apisix-ingress-controller — 2.1.0…2.2.0

_37 commits._

### Features
- **feat: allow L4 upstream schemes (tcp/tls/udp) for stream backends (#2830)** (a22afa2)
- **feat: support Gateway API 1.6.0 (#2804)** (2a8d507)
- **feat: support downstream mTLS via Gateway API frontendValidation (#2792)** (db30aa7)
- **feat: add L4RoutePolicy for attaching stream plugins to L4 routes (#2791)** (11635a1)
- **Add AGENTS.md + SECURITY.md pointing at project security threat model (#2775)** (028c1a9)

### Fixes
- **fix: set the Gateway status reasons Gateway API 1.6 requires and make the conformance report honest (#2843)** (4d0015c)
- **fix: reject invalid plugin config instead of applying an empty one (#2814)** (70e216b)
- **fix: stop the status e2e tests demanding their old node ports back (#2845)** (e1ea081)
- **fix: make the kustomize manifests deployable and consistent (#2835)** (061b493)
- **fix: read L4 routes and ReferenceGrant as v1 instead of the older versions (#2839)** (85d3551)
- **fix: normalize hosts and SNIs so uppercase hostnames stay routable (#2837)** (93458e9)
- **fix: honor TCPRoute/UDPRoute sectionName and listener port for StreamRoute matching (#2818)** (be4aaef)
- **fix: fail loud when enable-csrf is set but csrf-key annotation is missing (#2813)** (dc8db3d)
- **fix: preserve ApisixUpstream health check type (#2828)** (dad45c5)
- **fix(httproute): read appProtocol for ExternalName services (#2798)** (058cb0d)
- **fix: suppress cross-namespace Secret existence oracle in Consumer webhook (#2806)** (be19f90)
- **fix: never treat an unreachable API server as a missing API resource (#2817)** (a1c2ec1)
- **fix: accept whitespace-separated hmac-auth signed_headers and document the format (#2824)** (0207b15)
- **fix: allow webhook NetworkPolicy traffic on pod port 9443 (#2812)** (ac4e619)
- **fix: parse hmac-auth signed_headers from Secret as a header list (#2809)** (51ddfef)
- **fix: enforce ReferenceGrant on cross-namespace Consumer SecretRef (#2805)** (843879c)
- **fix: redact credentials and AdminKey from controller logs (#2808)** (1582e3d)
- **fix: cap condition message to Kubernetes 32768-byte limit (#2816)** (08f8508)
- **fix: trim whitespace in comma-separated annotation values (#2815)** (38d2cef)
- **fix: rebuild the ADC baseline on leader acquisition (#2785)** (6fc49d3)
- **fix: honor BackendTrafficPolicy targetRefs.sectionName for Service ports (#2796)** (d029b96)
- **fix: Ingress with ImplementationSpecific path panics when annotations are empty (#2780)** (4456555)

### Tests
- **test: fix the broken TCPRoute e2e listener port and de-flake two stream/ingress specs (#2836)** (39325e8)
- **test(e2e): prewarm environment pool to hide per-spec deploy latency (#2790)** (611487c)
- **test(e2e): remove fixed-sleep flakiness across e2e specs (#2788)** (0fe60da)

### Docs
- **docs: fix incorrect unit test command in developer guide (#2797)** (549f7f2)
- **docs: improve Kubernetes Gateway API page SEO (#2823)** (ce10a38)
- **docs: update listener port info per 2.1.0 updates (#2786)** (aaa89c2)
- **docs: update docs for 2.1.0 ingress controller release (#2776)** (eff19eb)

### Chore
- **chore: v2.2.0 release (#2838)** (c915316)
- **chore(deps): upgrade dependencies flagged by security advisories (#2844)** (6bbf00d)
- **ci: fix workflow failures by upgrading actions to comply with Apache allowlist (#2772)** (e6f3319)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/apache/apisix-ingress-controller?utm_source=github-action)._