content/en/news/releases/1.5.x/announcing-1.5/change-notes/index.md
ServiceEntry resource by avoiding unnecessary full pushes #19305iptables failure when using Istio CNI #19534consecutiveGatewayErrors and consecutive5xxErrors as outlier detection options within destination rule #19771.EnvoyFilter matching performance #19786HTTP_PROXY protocol #19919.iptables setup to use iptables-restore by default #18847.PeerAuthentication and RequestAuthentication respectively. Both new APIs are workload-oriented, as opposed to service-oriented in alpha AuthenticationPolicy.first-party-jwt as a fallback token for CSR authentication in clusters where third-party-jwt is not supported.values.global.pilotCertProvider.kubernetesenv adapter to provide proper support for pods that contain a dot in their name.IstioControlPlane API with the new IstioOperator API to align with existing MeshConfig API.istioctl operator init and istioctl operator remove commands.operator#667.istioctlIstioctl Analyze out of experimental.ServiceAssociation, Secret, sidecar image, port name and policy deprecated analyzers.RequestAuthentication.-A|--all-namespaces to istioctl analyze to analyze the entire cluster.stdin to istioctl analyze.istioctl analyze -L to show a list of all analyzers available.istioctl analyze.istioctl analyze.istioctl analyze output.Istioctl Analyze.istioctl analyze now loads files from a directory.istioctl analyze to try to associate message with their source filename.istioctl analyze to print the namespace that is being analyzed.istioctl analyze to analyze in-cluster resources by default.istioctl analyze suppressed cluster-level resource messages.istioctl manifest.IstioControlPlane API with the IstioOperator API.istioctl dashboard.istioctl manifest --set flag.istioctl manifest to read profiles from stdin.docker/istioctl image #19079.