Istio 1.27.2 locks down TLS secret access in Gateway API mode. Now, both the namespace and service account have to match. No more half-matching your way in.
It also drops the install order dependency between istioctl’s pilot and CNI. You can now install those in whatever order your chaos-loving soul prefers.