Skip to content

Releases: YAKEcloud/yake

v1.105.1-0

19 Oct 15:01
Compare
Choose a tag to compare

Release Notes v1.105

Yake release notes and upgrade guide

Related upstream release notes / changelogs

Update gardener-controlplane to 1.104.1

[gardener/gardener]

πŸ› Bug Fixes

  • [OPERATOR] Fix a regression that caused gardenlet to not be able to migrate deprecated failure-domain.beta.kubernetes.io labels to topology.kubernetes.io due to a removed RBAC rule required to patch PersistentVolumes. by @plkokanov [#10578]

πŸƒ Others

Helm Charts

  • controlplane: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/controlplane:v1.104.1
  • gardenlet: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/gardenlet:v1.104.1
  • operator: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/operator:v1.104.1
  • resource-manager: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/resource-manager:v1.104.1

Docker Images

  • admission-controller: europe-docker.pkg.dev/gardener-project/releases/gardener/admission-controller:v1.104.1
  • apiserver: europe-docker.pkg.dev/gardener-project/releases/gardener/apiserver:v1.104.1
  • controller-manager: europe-docker.pkg.dev/gardener-project/releases/gardener/controller-manager:v1.104.1
  • gardenlet: europe-docker.pkg.dev/gardener-project/releases/gardener/gardenlet:v1.104.1
  • node-agent: europe-docker.pkg.dev/gardener-project/releases/gardener/node-agent:v1.104.1
  • operator: europe-docker.pkg.dev/gardener-project/releases/gardener/operator:v1.104.1
  • resource-manager: europe-docker.pkg.dev/gardener-project/releases/gardener/resource-manager:v1.104.1
  • scheduler: europe-docker.pkg.dev/gardener-project/releases/gardener/scheduler:v1.104.1
Update gardener-controlplane to 1.104.1

[gardener/gardener]

πŸ› Bug Fixes

  • [OPERATOR] Fix a regression that caused gardenlet to not be able to migrate deprecated failure-domain.beta.kubernetes.io labels to topology.kubernetes.io due to a removed RBAC rule required to patch PersistentVolumes. by @plkokanov [#10578]

πŸƒ Others

Helm Charts

  • controlplane: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/controlplane:v1.104.1
  • gardenlet: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/gardenlet:v1.104.1
  • operator: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/operator:v1.104.1
  • resource-manager: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/resource-manager:v1.104.1

Docker Images

  • admission-controller: europe-docker.pkg.dev/gardener-project/releases/gardener/admission-controller:v1.104.1
  • apiserver: europe-docker.pkg.dev/gardener-project/releases/gardener/apiserver:v1.104.1
  • controller-manager: europe-docker.pkg.dev/gardener-project/releases/gardener/controller-manager:v1.104.1
  • gardenlet: europe-docker.pkg.dev/gardener-project/releases/gardener/gardenlet:v1.104.1
  • node-agent: europe-docker.pkg.dev/gardener-project/releases/gardener/node-agent:v1.104.1
  • operator: europe-docker.pkg.dev/gardener-project/releases/gardener/operator:v1.104.1
  • resource-manager: europe-docker.pkg.dev/gardener-project/releases/gardener/resource-manager:v1.104.1
  • scheduler: europe-docker.pkg.dev/gardener-project/releases/gardener/scheduler:v1.104.1
Update gardenlet to 1.104.1

[gardener/gardener]

πŸ› Bug Fixes

  • [OPERATOR] Fix a regression that caused gardenlet to not be able to migrate deprecated failure-domain.beta.kubernetes.io labels to topology.kubernetes.io due to a removed RBAC rule required to patch PersistentVolumes. by @plkokanov [#10578]

πŸƒ Others

Helm Charts

  • controlplane: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/controlplane:v1.104.1
  • gardenlet: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/gardenlet:v1.104.1
  • operator: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/operator:v1.104.1
  • resource-manager: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/resource-manager:v1.104.1

Docker Images

  • admission-controller: europe-docker.pkg.dev/gardener-project/releases/gardener/admission-controller:v1.104.1
  • apiserver: europe-docker.pkg.dev/gardener-project/releases/gardener/apiserver:v1.104.1
  • controller-manager: europe-docker.pkg.dev/gardener-project/releases/gardener/controller-manager:v1.104.1
  • gardenlet: europe-docker.pkg.dev/gardener-project/releases/gardener/gardenlet:v1.104.1
  • node-agent: europe-docker.pkg.dev/gardener-project/releases/gardener/node-agent:v1.104.1
  • operator: europe-docker.pkg.dev/gardener-project/releases/gardener/operator:v1.104.1
  • resource-manager: europe-docker.pkg.dev/gardener-project/releases/gardener/resource-manager:v1.104.1
  • scheduler: europe-docker.pkg.dev/gardener-project/releases/gardener/scheduler:v1.104.1
Update networking-calico to 1.42.0

[gardener/gardener-extension-networking-calico]

πŸƒ Others

  • [OPERATOR] Update calico to v3.28.2. by @DockToFuture [#492]
  • [OPERATOR] Fix networkConfig for IPv6. by @axel7born [#486]
  • [OPERATOR] In VPA autoscaling mode, calico-node should be disrupted less often as side car containers are no longer considered by VPA. Additionally, the minimum/maximum restriction are removed, which can lead to less memory consumption. by @ScheererJ [#489]
  • [OPERATOR] The networking calico extension no longer configures min/maxAllowed in any managed VPA resource. by @ScheererJ [#491]

Helm Charts

  • admission-calico-application: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-calico-application:v1.42.0
  • admission-calico-runtime: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-calico-runtime:v1.42.0
  • networking-calico: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/networking-calico:v1.42.0

Docker Images

  • gardener-extension-admission-calico: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/admission-calico:v1.42.0
  • gardener-extension-networking-calico: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/networking-calico:v1.42.0
Update networking-cilium to 1.37.0

[gardener/gardener-extension-networking-cilium]

✨ New Features

  • [OPERATOR] Helm charts of extension and admission controller are published as OCI artifacts now. by @oliver-goetz [#369]

πŸƒ Others

  • [OPERATOR] A priorityClassName can now be set for the admission deployment via the gardener-extension-admission-cilium Helm chart. by @timuthy [#362]
  • [OPERATOR] Update cilium to v1.16.1 and enable cilium-envoy to enable features like (Ingress, Gateway API, Network Policies with L7 functionality, L7 Protocol Visibility). by @DockToFuture [#409]
  • [OPERATOR] The networking cilium extension no longer configures min/maxAllowed in any managed VPA resource. by @ScheererJ [#408]
  • [OPERATOR] Update to cilium v1.16.2. by @DockToFuture [#411]

Helm Charts

  • admission-cilium-application: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-cilium-application:v1.37.0
  • admission-cilium-runtime: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-cilium-runtime:v1.37.0
  • networking-cilium: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/networking-cilium:v1.37.0

Docker Images

  • gardener-extension-admission-cilium: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/admission-cilium:v1.37.0
  • gardener-extension-networking-cilium: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/networking-cilium:v1.37.0
Update provider-azure to 1.47.3

[gardener/gardener-extension-provider-azure]

πŸƒ Others

  • [OPERATOR] Do not reconcile user-configured NAT Gateways in the gardener subnet. by @kon-angelo [#979]

Helm Charts

  • admission-azure-application: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-azure-application:v1.47.3
  • admission-azure-runtime: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-azure-runtime:v1.47.3
  • provider-azure: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/provider-azure:v1.47.3

Docker Images

  • gardener-extension-admission-azure: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/admission-azure:v1.47.3
  • gardener-extension-provider-azure: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/provider-azure:v1.47.3
Update gardener-controlplane to 1.105.0

[gardener/gardener]

πŸ“° Noteworthy

  • [OPERATOR] The VPAForETCD and VPAAndHPAForAPIServer feature gates have been promoted to GA and locked to true. by @plkokanov [#10599]
  • [USER] The limitation of having at maximum ~80 worker pools in Shoots has been lifted. Much higher numbers should be possible now (concrete limit depends on the amount of configuration within the pools (e.g., lab...
Read more

v1.104.2-0

19 Oct 14:46
Compare
Choose a tag to compare

Release Notes v1.104

Yake release notes and upgrade guide

Related upstream release notes / changelogs

Update networking-calico to 1.41.0

[gardener/gardener-extension-networking-calico]

✨ New Features

  • [OPERATOR] Helm charts of extension and admission controller are published as OCI artifacts now. by @oliver-goetz [#445]

πŸƒ Others

  • [OPERATOR] Add static resource allocation autoscaling mode for calico node/typha (autoScaling.mode: static). by @ScheererJ [#464]
  • [OPERATOR] The race between a calico-node instance shutting down and a new one coming up is mitigated by setting NetworkUnavailable condition properly some time after initialization. by @ScheererJ [#477]

Helm Charts

  • admission-calico-application: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-calico-application:v1.41.0
  • admission-calico-runtime: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-calico-runtime:v1.41.0
  • networking-calico: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/networking-calico:v1.41.0

Docker Images

  • gardener-extension-admission-calico: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/admission-calico:v1.41.0
  • gardener-extension-networking-calico: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/networking-calico:v1.41.0
Update cloudprofiles to 0.7.17

Full Changelog: gardener-community/cloudprofiles@0.7.16...0.7.17

Update provider-hcloud to 0.6.31

[gardener-extension-provider-hcloud] v0.6.31

Update shoot-flux to 0.7.0

What's Changed

Full Changelog: stackitcloud/gardener-extension-shoot-flux@v0.6.1...v0.7.0

Update cloudprofiles to 0.7.18

What's Changed

Full Changelog: gardener-community/cloudprofiles@0.7.17...0.7.18

Update backup-s3 to 0.4.1

General Changes

  • Generate new controller-registration.yaml
Update provider-alicloud to 1.54.0

[gardener/gardener-extension-provider-alicloud]

πŸƒ Others

  • [OPERATOR] Starting with gardenlet >= v1.98.0, use controlplane webhook object selector to limit mutator calls. by @LucaBernstein [#731]
  • [OPERATOR] The shoot-webhook does no longer mutate the metrics-server Deployment and the vpn-shoot Service. The shoot-webhook that now only mutates the addons-nginx-ingress-controller Service does now specify object selector. by @ialidzhikov [#730]
  • [OPERATOR] Upgrade and adapt new WorkerPoolHash function in Gardener v1.98. by @Duciwuci [#736]

Helm Charts

  • admission-alicloud-application: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-alicloud-application:v1.54.0
  • admission-alicloud-runtime: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-alicloud-runtime:v1.54.0
  • provider-alicloud: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/provider-alicloud:v1.54.0

Docker Images

  • gardener-extension-admission-alicloud: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/admission-alicloud:v1.54.0
  • gardener-extension-provider-alicloud: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/provider-alicloud:v1.54.0
Update gardener-controlplane to 1.104.0

[gardener/gardener]

⚠️ Breaking Changes

  • [USER] A bug has been fixed which was allowing users to set Shoot oidc configurations for the kube-apiserver without setting the clientID and issuerURL fields in spec.kubernetes.kubeAPIServer.oidcConfig, which would lead to the kube-apiserver stuck in a Error state. gardener-apiserver now requires both clientID and issuerURL fields to be set when the spec.kubernetes.kubeAPIServer.oidcConfig field is specified. by @AleksandarSavchev [#10461]
  • [OPERATOR] credentialsBinding.credentialsRef is now an immutable field. by @dimityrmirchev [#10365]

πŸ“° Noteworthy

  • [USER] Users are allowed to change shoot.spec.credentialsBindingName and reference another CredentialsBinding only if they have the permissions to read both the old and newly referenced credential. by @dimityrmirchev [#10365]
  • [USER] Users can migrate from shoot.spec.secretBindingName to shoot.spec.credentialsBindingName only if the referenced credential remains the same and is not changed during the process. by @dimityrmirchev [#10365]
  • [OPERATOR] Allow project users to read NamespacedCloudProfiles and for project admins to make adjustments to machine types and volume types. by @LucaBernstein [#10485]
  • [OPERATOR] Alerts based on the proposals_failed_total metric of the etcd cluster are not raised anymore. by @renormalize [#10524]
  • [DEVELOPER] A new predicate extensions/pkg/predicate.GardenSecurityProviderType can be used to select resources from the security.gardener.cloud group that are related to the passed provider type. by @dimityrmirchev [#10499]

✨ New Features

  • [OPERATOR] The gardener-operator metrics are now automatically scraped by the garden Prometheus. by @maboehm [#10464]
  • [OPERATOR] Introduce custom RBAC verbs to allow for modification of .spec.{kubernetes,machineImages} in NamespacedCloudProfiles. by @LucaBernstein [#10485]
  • [OPERATOR] The feature gate NewVPN is introduced for the gardenlet component. If enabled, the new VPN implementation (Golang rewrite) is used for all Shoots of the respective Seed. In this case, the old implementation can be disabled for a single Shoot by annotating the shoot resource with alpha.control-plane.shoot.gardener.cloud/disable-new-vpn=true. For Seeds with disabled feature gate, the new implementation can be enabled for a single shoot by annotating it with alpha.control-plane.shoot.gardener.cloud/disable-new-vpn=false. by @MartinWeindel [#9774]

πŸ› Bug Fixes

  • [USER] Fixed disk read/write panel in the shoot's etcd dashboards by @rickardsjp [#10493]
  • [DEVELOPER] An issue was fixed that rejected the creation of workerless shoots in the local setup. by @timuthy [#10498]

πŸƒ Others

  • [DEPENDENCY] The gardener/hvpa-controller image has been updated to v0.17.0. Release Notes by @gardener-ci-robot [#10508]
  • [DEPENDENCY] The quay.io/prometheus-operator/prometheus-config-reloader image has been updated to v0.76.2. by @gardener-ci-robot [#10500]
  • [DEPENDENCY] The gardener/machine-controller-manager image has been updated to v0.54.0. Release Notes by @gardener-ci-robot [#10528]
  • [DEPENDENCY] The gardener/alpine-conntrack image has been updated to 3.20.3. Release Notes by @gardener-ci-robot [#10487]
  • [DEPENDENCY] The envoyproxy/envoy image has been updated to v1.31.1. Release Notes by @gardener-ci-robot [#10531]
  • [OPERATOR] Federate apiserver_total_request metric to the Prometheus longterm instance by @jguipi [#10457]
  • [OPERATOR] Allow empty networking.nodes in case of IPv6 only shoots. by @axel7born [#10533]
  • [OPERATOR] Improved node utilisation by reducing requests for etcd-druid managed pods. by @unmarshall [#10540]
  • [DEVELOPER] Install go in the remote local setup from the go download site instead of using the apk package manager. by @vicwicker [#10502]

Helm Charts

  • controlplane: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/controlplane:v1.104.0
  • gardenlet: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/gardenlet:v1.104.0
  • operator: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/operator:v1.104.0
  • resource-manager: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/resource-manager:v1.104.0

Docker Images

  • admission-controller: europe-docker.pkg.dev/gardener-project/releases/gardener/admission-controller:v1.104.0
  • apiserver: europe-docker.pkg.dev/gardener-project/releases/gardener/apiserver:v1.104.0
  • controller-manager: europe-docker.pkg.dev/gardener-project/releases/gardener/controller-manager:v1.104.0
  • gardenlet: europe-docker.pkg.dev/gardener-project/releases/gardener/gardenlet:v1.104.0
  • node-agent: europe-docker.pkg.dev/gardener-project/releases/gardener/node-agent:v1.104.0
  • operator: europe-docker.pkg.dev/gardener-project/releases/gardener/operator:v1.104.0
  • resource-manager: europe-docker.pkg.dev/gardener-project/releases/gardener/resource-manager:v1.104.0
  • scheduler: europe-docker.pkg.dev/gardener-project/releases/gardener/scheduler:v1.104.0
Update gardener-controlplane to 1.104.0

[gardener/gardener]

⚠️ Breaking Changes

  • [USER] A bug has been fixed which was allowing users to set Shoot oidc configurations for the kube-apiserver without setting the clientID and issuerURL fields in spec.kubernetes.kubeAPIServer.oidcConfig, which would lead to the kube-apiserver stuck in a `Err...
Read more

v1.103.2-0

19 Oct 14:31
Compare
Choose a tag to compare

Release Notes v1.103

Yake release notes and upgrade guide

Related upstream release notes / changelogs

Update provider-hcloud to 0.6.30

[gardener-extension-provider-hcloud] v0.6.30

Update provider-openstack to 1.41.2

[gardener/gardener-extension-provider-openstack]

πŸƒ Others

  • [OPERATOR] Fix an issue with share network reconciliation not calculating number of existing share networks correctly. by @AndreasBurger [#827]

Docker Images

  • gardener-extension-admission-openstack: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/admission-openstack:v1.41.2
  • gardener-extension-provider-openstack: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/provider-openstack:v1.41.2
Update shoot-cert-service to 1.44.2

[gardener/gardener-extension-shoot-cert-service]

πŸƒ Others

  • [OPERATOR] The memory limit from the cert-controller-manager Deployment is now removed. by @ialidzhikov [#287]

Docker Images

  • gardener-extension-shoot-cert-service: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/shoot-cert-service:v1.44.2
Update shoot-rsyslog-relp to 0.5.2

[gardener/gardener-extension-shoot-rsyslog-relp]

πŸ› Bug Fixes

  • [OPERATOR] Fixed an issue that caused the -a exit,always -F arch=b64 -S mount_setattr -F auid!=-1 -F key=privileged_special audit rule to not get correctly applied. by @plkokanov [#151]

Docker Images

  • gardener-extension-shoot-rsyslog-relp-admission: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/shoot-rsyslog-relp-admission:v0.5.2
  • gardener-extension-shoot-rsyslog-relp: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/shoot-rsyslog-relp:v0.5.2
Update provider-alicloud to 1.53.0

[gardener/gardener-extension-provider-alicloud]

✨ New Features

  • [OPERATOR] This extension now makes use of the new .spec.pools[].userDataSecretRef field to get to the worker pool user data. by @rfranzke [#727]
  • [OPERATOR] Helm charts of extension and admission controller are published as OCI artifacts now. by @oliver-goetz [#734]
  • [USER] The provider-alicloud extension does now support shoot clusters with Kubernetes version 1.30. You should consider the Kubernetes release notes before upgrading to 1.30. by @shafeeqes [#722]

πŸƒ Others

  • [OPERATOR] The controlplaneexposure.alicloud.extensions.gardener.cloud webhook does no longer mutate Services/Deployments. Previously the webhook was called for Services/Deployments mutations and was not mutating anything. by @ialidzhikov [#725]
  • [OPERATOR] This extension is now using the new way of providing monitoring configuration (ref GEP-19) in case a shoot cluster's Prometheus has been migrated to management via prometheus-operator. by @rfranzke [#720]
  • [OPERATOR] A priorityClassName can now be set for the admission deployment via the gardener-extension-admission-alicloud Helm chart. by @timuthy [#732]
  • [OPERATOR] Inserts architecture from worker to the machine class by @sssash18 [#735]
  • [OPERATOR] NodeGroupAutoscalingOptions can now be specified per worker group via the worker through the field worker.spec.pools.clusterAutoscaler by @aaronfern [#715]

[gardener/machine-controller-manager]

⚠️ Breaking Changes

πŸ› Bug Fixes

πŸƒ Others

πŸ“– Documentation

[gardener/machine-controller-manager-provider-alicloud]

πŸƒ Others

Helm Charts

  • admission-alicloud: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-alicloud:v1.53.0
  • provider-alicloud: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/provider-alicloud:v1.53.0

Docker Images

  • gardener-extension-admission-alicloud: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/admission-alicloud:v1.53.0
  • gardener-extension-provider-alicloud: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/provider-alicloud:v1.53.0
Update provider-aws to 1.57.0

[gardener/gardener-extension-provider-aws]

✨ New Features

  • [OPERATOR] Helm charts of extension and admission controller are published as OCI artifacts now. by @oliver-goetz [#1012]

πŸ› Bug Fixes

  • [OPERATOR] Removed unnecessary preStop hook from node-driver-registrar in csi-driver-node, as socket removal is now handled internally by node-driver-registrar, resolving distroless image error. by @AndreasBurger [#992]

πŸƒ Others

  • [OPERATOR] A priorityClassName can now be set for the admission deployment via the gardener-extension-admission-aws Helm chart. by @timuthy [#994]
  • [OPERATOR] Starting with gardenlet >= v1.98.0, use controlplane webhook object selector to limit mutator calls. by @LucaBernstein [#989]
  • [OPERATOR] Update the VPA CRD used for testing locally by @kon-angelo [#1019]
  • [OPERATOR] Inserts architecture from worker to the machine class by @sssash18 [#853]

Helm Charts

  • admission-aws-application: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-aws-application:v1.57.0
  • admission-aws-runtime: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-aws-runtime:v1.57.0
  • provider-aws: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/provider-aws:v1.57.0

Docker Images

  • gardener-extension-admission-aws: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/admission-aws:v1.57.0
  • gardener-extension-provider-aws: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/provider-aws:v1.57.0
Update provider-azure to 1.47.1

[gardener/gardener-extension-provider-azure]

πŸƒ Others

  • [OPERATOR] The storage domain to use for backup buckets is now inferred from the buckets' region if no explicit config is given by @AndreasBurger [#947]

Helm Charts

  • admission-azure-application: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-azure-application:v1.47.1
  • admission-azure-runtime: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-azure-runtime:v1.47.1
  • provider-azure: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/provider-azure:v1.47.1

Docker Images

  • gardener-extension-admission-azure: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/admission-azure:v1.47.1
  • gardener-extension-provider-azure: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/provider-azure:v1.47.1
Update provider-gcp to 1.38.0

[gardener/gardener-extension-provider-gcp]

✨ New Features

  • [OPERATOR] Helm charts of extension and admission controller are published as OCI artifacts now. by @oliver-goetz [#805]

πŸ› Bug Fixes

  • [OPERATOR] Removed unnecessary preStop hook from node-driver-registrar in csi-driver-node, as socket removal is now handled internally by node-driver-registrar, resolving distroless image error. by @sujeet01 [#792]
  • [USER] Allow configuring iops and throughput of hyperdisk-balanced disks by @hebelsan [#793]

πŸƒ Others

  • [OPERATOR] Inserts architecture from worker to the machine class by @sssash18 [#809]
  • [OPERATOR] Starting with gardenlet >= v1.98.0, use controlplane webhook object selector to limit mutator calls. by @LucaBernstein [#789]
  • [OPERATOR] Update the VPA...
Read more

v1.105.0-0

15 Oct 10:20
Compare
Choose a tag to compare

Release Notes v1.105

Yake release notes and upgrade guide

Related upstream release notes / changelogs

Update gardener-controlplane to 1.104.1

[gardener/gardener]

πŸ› Bug Fixes

  • [OPERATOR] Fix a regression that caused gardenlet to not be able to migrate deprecated failure-domain.beta.kubernetes.io labels to topology.kubernetes.io due to a removed RBAC rule required to patch PersistentVolumes. by @plkokanov [#10578]

πŸƒ Others

Helm Charts

  • controlplane: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/controlplane:v1.104.1
  • gardenlet: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/gardenlet:v1.104.1
  • operator: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/operator:v1.104.1
  • resource-manager: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/resource-manager:v1.104.1

Docker Images

  • admission-controller: europe-docker.pkg.dev/gardener-project/releases/gardener/admission-controller:v1.104.1
  • apiserver: europe-docker.pkg.dev/gardener-project/releases/gardener/apiserver:v1.104.1
  • controller-manager: europe-docker.pkg.dev/gardener-project/releases/gardener/controller-manager:v1.104.1
  • gardenlet: europe-docker.pkg.dev/gardener-project/releases/gardener/gardenlet:v1.104.1
  • node-agent: europe-docker.pkg.dev/gardener-project/releases/gardener/node-agent:v1.104.1
  • operator: europe-docker.pkg.dev/gardener-project/releases/gardener/operator:v1.104.1
  • resource-manager: europe-docker.pkg.dev/gardener-project/releases/gardener/resource-manager:v1.104.1
  • scheduler: europe-docker.pkg.dev/gardener-project/releases/gardener/scheduler:v1.104.1
Update gardener-controlplane to 1.104.1

[gardener/gardener]

πŸ› Bug Fixes

  • [OPERATOR] Fix a regression that caused gardenlet to not be able to migrate deprecated failure-domain.beta.kubernetes.io labels to topology.kubernetes.io due to a removed RBAC rule required to patch PersistentVolumes. by @plkokanov [#10578]

πŸƒ Others

Helm Charts

  • controlplane: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/controlplane:v1.104.1
  • gardenlet: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/gardenlet:v1.104.1
  • operator: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/operator:v1.104.1
  • resource-manager: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/resource-manager:v1.104.1

Docker Images

  • admission-controller: europe-docker.pkg.dev/gardener-project/releases/gardener/admission-controller:v1.104.1
  • apiserver: europe-docker.pkg.dev/gardener-project/releases/gardener/apiserver:v1.104.1
  • controller-manager: europe-docker.pkg.dev/gardener-project/releases/gardener/controller-manager:v1.104.1
  • gardenlet: europe-docker.pkg.dev/gardener-project/releases/gardener/gardenlet:v1.104.1
  • node-agent: europe-docker.pkg.dev/gardener-project/releases/gardener/node-agent:v1.104.1
  • operator: europe-docker.pkg.dev/gardener-project/releases/gardener/operator:v1.104.1
  • resource-manager: europe-docker.pkg.dev/gardener-project/releases/gardener/resource-manager:v1.104.1
  • scheduler: europe-docker.pkg.dev/gardener-project/releases/gardener/scheduler:v1.104.1
Update gardenlet to 1.104.1

[gardener/gardener]

πŸ› Bug Fixes

  • [OPERATOR] Fix a regression that caused gardenlet to not be able to migrate deprecated failure-domain.beta.kubernetes.io labels to topology.kubernetes.io due to a removed RBAC rule required to patch PersistentVolumes. by @plkokanov [#10578]

πŸƒ Others

Helm Charts

  • controlplane: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/controlplane:v1.104.1
  • gardenlet: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/gardenlet:v1.104.1
  • operator: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/operator:v1.104.1
  • resource-manager: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/resource-manager:v1.104.1

Docker Images

  • admission-controller: europe-docker.pkg.dev/gardener-project/releases/gardener/admission-controller:v1.104.1
  • apiserver: europe-docker.pkg.dev/gardener-project/releases/gardener/apiserver:v1.104.1
  • controller-manager: europe-docker.pkg.dev/gardener-project/releases/gardener/controller-manager:v1.104.1
  • gardenlet: europe-docker.pkg.dev/gardener-project/releases/gardener/gardenlet:v1.104.1
  • node-agent: europe-docker.pkg.dev/gardener-project/releases/gardener/node-agent:v1.104.1
  • operator: europe-docker.pkg.dev/gardener-project/releases/gardener/operator:v1.104.1
  • resource-manager: europe-docker.pkg.dev/gardener-project/releases/gardener/resource-manager:v1.104.1
  • scheduler: europe-docker.pkg.dev/gardener-project/releases/gardener/scheduler:v1.104.1
Update networking-calico to 1.42.0

[gardener/gardener-extension-networking-calico]

πŸƒ Others

  • [OPERATOR] Update calico to v3.28.2. by @DockToFuture [#492]
  • [OPERATOR] Fix networkConfig for IPv6. by @axel7born [#486]
  • [OPERATOR] In VPA autoscaling mode, calico-node should be disrupted less often as side car containers are no longer considered by VPA. Additionally, the minimum/maximum restriction are removed, which can lead to less memory consumption. by @ScheererJ [#489]
  • [OPERATOR] The networking calico extension no longer configures min/maxAllowed in any managed VPA resource. by @ScheererJ [#491]

Helm Charts

  • admission-calico-application: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-calico-application:v1.42.0
  • admission-calico-runtime: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-calico-runtime:v1.42.0
  • networking-calico: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/networking-calico:v1.42.0

Docker Images

  • gardener-extension-admission-calico: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/admission-calico:v1.42.0
  • gardener-extension-networking-calico: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/networking-calico:v1.42.0
Update networking-cilium to 1.37.0

[gardener/gardener-extension-networking-cilium]

✨ New Features

  • [OPERATOR] Helm charts of extension and admission controller are published as OCI artifacts now. by @oliver-goetz [#369]

πŸƒ Others

  • [OPERATOR] A priorityClassName can now be set for the admission deployment via the gardener-extension-admission-cilium Helm chart. by @timuthy [#362]
  • [OPERATOR] Update cilium to v1.16.1 and enable cilium-envoy to enable features like (Ingress, Gateway API, Network Policies with L7 functionality, L7 Protocol Visibility). by @DockToFuture [#409]
  • [OPERATOR] The networking cilium extension no longer configures min/maxAllowed in any managed VPA resource. by @ScheererJ [#408]
  • [OPERATOR] Update to cilium v1.16.2. by @DockToFuture [#411]

Helm Charts

  • admission-cilium-application: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-cilium-application:v1.37.0
  • admission-cilium-runtime: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-cilium-runtime:v1.37.0
  • networking-cilium: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/networking-cilium:v1.37.0

Docker Images

  • gardener-extension-admission-cilium: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/admission-cilium:v1.37.0
  • gardener-extension-networking-cilium: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/networking-cilium:v1.37.0
Update provider-azure to 1.47.3

[gardener/gardener-extension-provider-azure]

πŸƒ Others

  • [OPERATOR] Do not reconcile user-configured NAT Gateways in the gardener subnet. by @kon-angelo [#979]

Helm Charts

  • admission-azure-application: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-azure-application:v1.47.3
  • admission-azure-runtime: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-azure-runtime:v1.47.3
  • provider-azure: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/provider-azure:v1.47.3

Docker Images

  • gardener-extension-admission-azure: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/admission-azure:v1.47.3
  • gardener-extension-provider-azure: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/provider-azure:v1.47.3
Update gardener-controlplane to 1.105.0

[gardener/gardener]

πŸ“° Noteworthy

  • [OPERATOR] The VPAForETCD and VPAAndHPAForAPIServer feature gates have been promoted to GA and locked to true. by @plkokanov [#10599]
  • [USER] The limitation of having at maximum ~80 worker pools in Shoots has been lifted. Much higher numbers should be possible now (concrete limit depends on the amount of configuration within the pools (e.g., lab...
Read more

v1.103.1-0

04 Oct 13:31
Compare
Choose a tag to compare

Release Notes v1.103

Yake release notes and upgrade guide

Related upstream release notes / changelogs

Update provider-hcloud to 0.6.30

[gardener-extension-provider-hcloud] v0.6.30

Update provider-openstack to 1.41.2

[gardener/gardener-extension-provider-openstack]

πŸƒ Others

  • [OPERATOR] Fix an issue with share network reconciliation not calculating number of existing share networks correctly. by @AndreasBurger [#827]

Docker Images

  • gardener-extension-admission-openstack: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/admission-openstack:v1.41.2
  • gardener-extension-provider-openstack: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/provider-openstack:v1.41.2
Update shoot-cert-service to 1.44.2

[gardener/gardener-extension-shoot-cert-service]

πŸƒ Others

  • [OPERATOR] The memory limit from the cert-controller-manager Deployment is now removed. by @ialidzhikov [#287]

Docker Images

  • gardener-extension-shoot-cert-service: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/shoot-cert-service:v1.44.2
Update shoot-rsyslog-relp to 0.5.2

[gardener/gardener-extension-shoot-rsyslog-relp]

πŸ› Bug Fixes

  • [OPERATOR] Fixed an issue that caused the -a exit,always -F arch=b64 -S mount_setattr -F auid!=-1 -F key=privileged_special audit rule to not get correctly applied. by @plkokanov [#151]

Docker Images

  • gardener-extension-shoot-rsyslog-relp-admission: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/shoot-rsyslog-relp-admission:v0.5.2
  • gardener-extension-shoot-rsyslog-relp: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/shoot-rsyslog-relp:v0.5.2
Update provider-alicloud to 1.53.0

[gardener/gardener-extension-provider-alicloud]

✨ New Features

  • [OPERATOR] This extension now makes use of the new .spec.pools[].userDataSecretRef field to get to the worker pool user data. by @rfranzke [#727]
  • [OPERATOR] Helm charts of extension and admission controller are published as OCI artifacts now. by @oliver-goetz [#734]
  • [USER] The provider-alicloud extension does now support shoot clusters with Kubernetes version 1.30. You should consider the Kubernetes release notes before upgrading to 1.30. by @shafeeqes [#722]

πŸƒ Others

  • [OPERATOR] The controlplaneexposure.alicloud.extensions.gardener.cloud webhook does no longer mutate Services/Deployments. Previously the webhook was called for Services/Deployments mutations and was not mutating anything. by @ialidzhikov [#725]
  • [OPERATOR] This extension is now using the new way of providing monitoring configuration (ref GEP-19) in case a shoot cluster's Prometheus has been migrated to management via prometheus-operator. by @rfranzke [#720]
  • [OPERATOR] A priorityClassName can now be set for the admission deployment via the gardener-extension-admission-alicloud Helm chart. by @timuthy [#732]
  • [OPERATOR] Inserts architecture from worker to the machine class by @sssash18 [#735]
  • [OPERATOR] NodeGroupAutoscalingOptions can now be specified per worker group via the worker through the field worker.spec.pools.clusterAutoscaler by @aaronfern [#715]

[gardener/machine-controller-manager]

⚠️ Breaking Changes

πŸ› Bug Fixes

πŸƒ Others

πŸ“– Documentation

[gardener/machine-controller-manager-provider-alicloud]

πŸƒ Others

Helm Charts

  • admission-alicloud: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-alicloud:v1.53.0
  • provider-alicloud: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/provider-alicloud:v1.53.0

Docker Images

  • gardener-extension-admission-alicloud: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/admission-alicloud:v1.53.0
  • gardener-extension-provider-alicloud: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/provider-alicloud:v1.53.0
Update provider-aws to 1.57.0

[gardener/gardener-extension-provider-aws]

✨ New Features

  • [OPERATOR] Helm charts of extension and admission controller are published as OCI artifacts now. by @oliver-goetz [#1012]

πŸ› Bug Fixes

  • [OPERATOR] Removed unnecessary preStop hook from node-driver-registrar in csi-driver-node, as socket removal is now handled internally by node-driver-registrar, resolving distroless image error. by @AndreasBurger [#992]

πŸƒ Others

  • [OPERATOR] A priorityClassName can now be set for the admission deployment via the gardener-extension-admission-aws Helm chart. by @timuthy [#994]
  • [OPERATOR] Starting with gardenlet >= v1.98.0, use controlplane webhook object selector to limit mutator calls. by @LucaBernstein [#989]
  • [OPERATOR] Update the VPA CRD used for testing locally by @kon-angelo [#1019]
  • [OPERATOR] Inserts architecture from worker to the machine class by @sssash18 [#853]

Helm Charts

  • admission-aws-application: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-aws-application:v1.57.0
  • admission-aws-runtime: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-aws-runtime:v1.57.0
  • provider-aws: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/provider-aws:v1.57.0

Docker Images

  • gardener-extension-admission-aws: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/admission-aws:v1.57.0
  • gardener-extension-provider-aws: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/provider-aws:v1.57.0
Update provider-azure to 1.47.1

[gardener/gardener-extension-provider-azure]

πŸƒ Others

  • [OPERATOR] The storage domain to use for backup buckets is now inferred from the buckets' region if no explicit config is given by @AndreasBurger [#947]

Helm Charts

  • admission-azure-application: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-azure-application:v1.47.1
  • admission-azure-runtime: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-azure-runtime:v1.47.1
  • provider-azure: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/provider-azure:v1.47.1

Docker Images

  • gardener-extension-admission-azure: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/admission-azure:v1.47.1
  • gardener-extension-provider-azure: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/provider-azure:v1.47.1
Update provider-gcp to 1.38.0

[gardener/gardener-extension-provider-gcp]

✨ New Features

  • [OPERATOR] Helm charts of extension and admission controller are published as OCI artifacts now. by @oliver-goetz [#805]

πŸ› Bug Fixes

  • [OPERATOR] Removed unnecessary preStop hook from node-driver-registrar in csi-driver-node, as socket removal is now handled internally by node-driver-registrar, resolving distroless image error. by @sujeet01 [#792]
  • [USER] Allow configuring iops and throughput of hyperdisk-balanced disks by @hebelsan [#793]

πŸƒ Others

  • [OPERATOR] Inserts architecture from worker to the machine class by @sssash18 [#809]
  • [OPERATOR] Starting with gardenlet >= v1.98.0, use controlplane webhook object selector to limit mutator calls. by @LucaBernstein [#789]
  • [OPERATOR] Update the VPA...
Read more

v1.102.2-0

04 Oct 13:16
Compare
Choose a tag to compare

Release Notes v1.102

Yake release notes and upgrade guide

Related upstream release notes / changelogs

Update cloudprofiles to 0.7.16

Full Changelog: gardener-community/cloudprofiles@0.7.15...0.7.16

Update gardener-controlplane to 1.101.2

[gardener/gardener]

πŸƒ Others

  • [DEPENDENCY] The registry.k8s.io/ingress-nginx/controller-chroot image has been updated to v1.11.2. by @gardener-ci-robot [#10357]

Helm Charts

  • controlplane: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/controlplane:v1.101.2
  • gardenlet: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/gardenlet:v1.101.2
  • operator: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/operator:v1.101.2
  • resource-manager: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/resource-manager:v1.101.2

Docker Images

  • admission-controller: europe-docker.pkg.dev/gardener-project/releases/gardener/admission-controller:v1.101.2
  • apiserver: europe-docker.pkg.dev/gardener-project/releases/gardener/apiserver:v1.101.2
  • controller-manager: europe-docker.pkg.dev/gardener-project/releases/gardener/controller-manager:v1.101.2
  • gardenlet: europe-docker.pkg.dev/gardener-project/releases/gardener/gardenlet:v1.101.2
  • node-agent: europe-docker.pkg.dev/gardener-project/releases/gardener/node-agent:v1.101.2
  • operator: europe-docker.pkg.dev/gardener-project/releases/gardener/operator:v1.101.2
  • resource-manager: europe-docker.pkg.dev/gardener-project/releases/gardener/resource-manager:v1.101.2
  • scheduler: europe-docker.pkg.dev/gardener-project/releases/gardener/scheduler:v1.101.2
Update gardener-controlplane to 1.101.2

[gardener/gardener]

πŸƒ Others

  • [DEPENDENCY] The registry.k8s.io/ingress-nginx/controller-chroot image has been updated to v1.11.2. by @gardener-ci-robot [#10357]

Helm Charts

  • controlplane: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/controlplane:v1.101.2
  • gardenlet: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/gardenlet:v1.101.2
  • operator: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/operator:v1.101.2
  • resource-manager: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/resource-manager:v1.101.2

Docker Images

  • admission-controller: europe-docker.pkg.dev/gardener-project/releases/gardener/admission-controller:v1.101.2
  • apiserver: europe-docker.pkg.dev/gardener-project/releases/gardener/apiserver:v1.101.2
  • controller-manager: europe-docker.pkg.dev/gardener-project/releases/gardener/controller-manager:v1.101.2
  • gardenlet: europe-docker.pkg.dev/gardener-project/releases/gardener/gardenlet:v1.101.2
  • node-agent: europe-docker.pkg.dev/gardener-project/releases/gardener/node-agent:v1.101.2
  • operator: europe-docker.pkg.dev/gardener-project/releases/gardener/operator:v1.101.2
  • resource-manager: europe-docker.pkg.dev/gardener-project/releases/gardener/resource-manager:v1.101.2
  • scheduler: europe-docker.pkg.dev/gardener-project/releases/gardener/scheduler:v1.101.2
Update gardenlet to 1.101.2

[gardener/gardener]

πŸƒ Others

  • [DEPENDENCY] The registry.k8s.io/ingress-nginx/controller-chroot image has been updated to v1.11.2. by @gardener-ci-robot [#10357]

Helm Charts

  • controlplane: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/controlplane:v1.101.2
  • gardenlet: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/gardenlet:v1.101.2
  • operator: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/operator:v1.101.2
  • resource-manager: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/resource-manager:v1.101.2

Docker Images

  • admission-controller: europe-docker.pkg.dev/gardener-project/releases/gardener/admission-controller:v1.101.2
  • apiserver: europe-docker.pkg.dev/gardener-project/releases/gardener/apiserver:v1.101.2
  • controller-manager: europe-docker.pkg.dev/gardener-project/releases/gardener/controller-manager:v1.101.2
  • gardenlet: europe-docker.pkg.dev/gardener-project/releases/gardener/gardenlet:v1.101.2
  • node-agent: europe-docker.pkg.dev/gardener-project/releases/gardener/node-agent:v1.101.2
  • operator: europe-docker.pkg.dev/gardener-project/releases/gardener/operator:v1.101.2
  • resource-manager: europe-docker.pkg.dev/gardener-project/releases/gardener/resource-manager:v1.101.2
  • scheduler: europe-docker.pkg.dev/gardener-project/releases/gardener/scheduler:v1.101.2
Update external-dns-management to 0.21.0

[gardener/external-dns-management]

⚠️ Breaking Changes

  • [OPERATOR] Drop support for custom resources dnslock.dns.gardener.cloud and remoteaccesscertificates.dns.gardener.cloud.
    As these experimental features have no been used in Gardener, it should not be relevant in most cases. by @MartinWeindel [#381]

πŸƒ Others

  • [OPERATOR] Bumps golang from 1.22.6 to 1.23.0. by @dependabot[bot] [#384]
  • [OPERATOR] Bumps golang from 1.22.5 to 1.22.6. by @dependabot[bot] [#383]
  • [OPERATOR] The dependency controller-manager-library has been updated to include the new flag --<cluster>.conditional-deploy-crds by @MartinWeindel [#385]

Docker Images

  • dns-controller-manager: europe-docker.pkg.dev/gardener-project/releases/dns-controller-manager:v0.21.0
Update gardener-controlplane to 1.102.0

[gardener/gardener]

⚠️ Breaking Changes

  • [OPERATOR] When the NewWorkerPoolHash feature gate is enabled, the calculation now also rolls worker nodes of Shoots when changing systemReserved in the kubelet configuration. Worker pools are not rolled if the sum of kubeReserved and systemReserved does not change. If the feature gate is already enabled, then the worker pools of Shoots with non-zero values in systemReserved will be rolled once. by @MichaelEischer [#10290]

πŸ“° Noteworthy

  • [USER] The spec.client field in the {Cluster}OpenIDConnectPreset APIs is deprecated and will be removed after support for Kubernetes 1.30 is dropped. by @AleksandarSavchev [#10253]
  • [USER] The spec.kubernetes.kubeAPIServer.oidcConfig.clientAuthentication field in the Shoot API is deprecated and will be removed after support for Kubernetes 1.30 is dropped. by @AleksandarSavchev [#10253]
  • [USER] The Shoot specification field .spec.kubernetes.kubeAPIServer.oidcConfig.signingAlgs for Kubernetes versions >= v1.30 is not supported anymore. by @AleksandarSavchev [#10244]

✨ New Features

  • [USER] Structured authentication configuration can now be set by creating a ConfigMap in the project namespace with the AuthenticationConfiguration file set in the config.yaml data key and referencing the ConfigMap in the new Shoot specification field .spec.kubernetes.kubeAPIServer.structuredAuthentication.configMapName for Kubernetes versions >= v1.30. Only one authenticator can be set via the authentication configuration until k8s.io/* Golang dependencies are upgraded to version >= v0.30. by @AleksandarSavchev [#10244]
  • [USER] The following vpa-recommender flags are now configurable via the Shoot specification:
    • --recommendation-lower-bound-cpu-percentile: .spec.kubernetes.verticalPodAutoscaler.recommendationLowerBoundCPUPercentile
    • --recommendation-upper-bound-cpu-percentile: .spec.kubernetes.verticalPodAutoscaler.recommendationUpperBoundCPUPercentile
    • --target-memory-percentile: .spec.kubernetes.verticalPodAutoscaler.targetMemoryPercentile
    • --recommendation-lower-bound-memory-percentile: .spec.kubernetes.verticalPodAutoscaler.recommendationLowerBoundMemoryPercentile
    • --recommendation-upper-bound-memory-percentile: .spec.kubernetes.verticalPodAutoscaler.recommendationUpperBoundMemoryPercentile by @ialidzhikov [#10221]
  • [OPERATOR] Performing control plane migration across Seeds with different provider types is now possible. Before triggering the migration, make sure that pods in the Shoot's control plane, once it is moved to the Destination Seed, will have network connectivity to the storage provider of the Source Seed (so that ETCD backups can be copied automatically). Additionally, make sure that the Shoot's nodes will have network connectivity to the Shoot's control plane after it is moved to the Destination Seed. by @plkokanov [#10323]
  • [OPERATOR] gardenlet now runs a new controller called TokenRequestorWorkloadIdentity which requests workload identity tokens and writes them into Secret resources in the seed cluster. These tokens can be then used by control plane components in order to present the said WorkloadIdentity before external systems. Please see here for more details. by @dimityrmirchev [#10298]
  • [OPERATOR] Quotas can now have scope of type WorkloadIdentity. by @dimityrmirchev [#10346]

πŸ› Bug Fixes

  • [USER] Fixes a bug preventing shoot clusters with annotation shoot.gardener.cloud/skip-readiness: "true" to be created. by @ScheererJ [#10317]
  • [OPERATOR] An issue causing the vpn-seed-server VPA's to be created with wrong targetRef for highly available Shoots is now fixed. by @ialidzhikov [#10366]

πŸƒ Others

  • [OPERATOR] vpa-updater and vpa-recommender components do now run with leader election enabled (unconditionally) and support running in HA mode. by @ialidzhikov [#10302]
  • [OPERATOR] Reduce kubelet http2 timeouts. by @axel7born [#10223]
  • [OPERATOR] Gardener now temporarily uses a `vpa-recomme...
Read more

v1.104.1-0

01 Oct 16:32
Compare
Choose a tag to compare

Release Notes v1.104

Yake release notes and upgrade guide

Related upstream release notes / changelogs

Update networking-calico to 1.41.0

[gardener/gardener-extension-networking-calico]

✨ New Features

  • [OPERATOR] Helm charts of extension and admission controller are published as OCI artifacts now. by @oliver-goetz [#445]

πŸƒ Others

  • [OPERATOR] Add static resource allocation autoscaling mode for calico node/typha (autoScaling.mode: static). by @ScheererJ [#464]
  • [OPERATOR] The race between a calico-node instance shutting down and a new one coming up is mitigated by setting NetworkUnavailable condition properly some time after initialization. by @ScheererJ [#477]

Helm Charts

  • admission-calico-application: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-calico-application:v1.41.0
  • admission-calico-runtime: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-calico-runtime:v1.41.0
  • networking-calico: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/networking-calico:v1.41.0

Docker Images

  • gardener-extension-admission-calico: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/admission-calico:v1.41.0
  • gardener-extension-networking-calico: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/networking-calico:v1.41.0
Update cloudprofiles to 0.7.17

Full Changelog: gardener-community/cloudprofiles@0.7.16...0.7.17

Update provider-hcloud to 0.6.31

[gardener-extension-provider-hcloud] v0.6.31

Update shoot-flux to 0.7.0

What's Changed

Full Changelog: stackitcloud/gardener-extension-shoot-flux@v0.6.1...v0.7.0

Update cloudprofiles to 0.7.18

What's Changed

Full Changelog: gardener-community/cloudprofiles@0.7.17...0.7.18

Update backup-s3 to 0.4.1

General Changes

  • Generate new controller-registration.yaml
Update provider-alicloud to 1.54.0

[gardener/gardener-extension-provider-alicloud]

πŸƒ Others

  • [OPERATOR] Starting with gardenlet >= v1.98.0, use controlplane webhook object selector to limit mutator calls. by @LucaBernstein [#731]
  • [OPERATOR] The shoot-webhook does no longer mutate the metrics-server Deployment and the vpn-shoot Service. The shoot-webhook that now only mutates the addons-nginx-ingress-controller Service does now specify object selector. by @ialidzhikov [#730]
  • [OPERATOR] Upgrade and adapt new WorkerPoolHash function in Gardener v1.98. by @Duciwuci [#736]

Helm Charts

  • admission-alicloud-application: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-alicloud-application:v1.54.0
  • admission-alicloud-runtime: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-alicloud-runtime:v1.54.0
  • provider-alicloud: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/provider-alicloud:v1.54.0

Docker Images

  • gardener-extension-admission-alicloud: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/admission-alicloud:v1.54.0
  • gardener-extension-provider-alicloud: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/provider-alicloud:v1.54.0
Update gardener-controlplane to 1.104.0

[gardener/gardener]

⚠️ Breaking Changes

  • [USER] A bug has been fixed which was allowing users to set Shoot oidc configurations for the kube-apiserver without setting the clientID and issuerURL fields in spec.kubernetes.kubeAPIServer.oidcConfig, which would lead to the kube-apiserver stuck in a Error state. gardener-apiserver now requires both clientID and issuerURL fields to be set when the spec.kubernetes.kubeAPIServer.oidcConfig field is specified. by @AleksandarSavchev [#10461]
  • [OPERATOR] credentialsBinding.credentialsRef is now an immutable field. by @dimityrmirchev [#10365]

πŸ“° Noteworthy

  • [USER] Users are allowed to change shoot.spec.credentialsBindingName and reference another CredentialsBinding only if they have the permissions to read both the old and newly referenced credential. by @dimityrmirchev [#10365]
  • [USER] Users can migrate from shoot.spec.secretBindingName to shoot.spec.credentialsBindingName only if the referenced credential remains the same and is not changed during the process. by @dimityrmirchev [#10365]
  • [OPERATOR] Allow project users to read NamespacedCloudProfiles and for project admins to make adjustments to machine types and volume types. by @LucaBernstein [#10485]
  • [OPERATOR] Alerts based on the proposals_failed_total metric of the etcd cluster are not raised anymore. by @renormalize [#10524]
  • [DEVELOPER] A new predicate extensions/pkg/predicate.GardenSecurityProviderType can be used to select resources from the security.gardener.cloud group that are related to the passed provider type. by @dimityrmirchev [#10499]

✨ New Features

  • [OPERATOR] The gardener-operator metrics are now automatically scraped by the garden Prometheus. by @maboehm [#10464]
  • [OPERATOR] Introduce custom RBAC verbs to allow for modification of .spec.{kubernetes,machineImages} in NamespacedCloudProfiles. by @LucaBernstein [#10485]
  • [OPERATOR] The feature gate NewVPN is introduced for the gardenlet component. If enabled, the new VPN implementation (Golang rewrite) is used for all Shoots of the respective Seed. In this case, the old implementation can be disabled for a single Shoot by annotating the shoot resource with alpha.control-plane.shoot.gardener.cloud/disable-new-vpn=true. For Seeds with disabled feature gate, the new implementation can be enabled for a single shoot by annotating it with alpha.control-plane.shoot.gardener.cloud/disable-new-vpn=false. by @MartinWeindel [#9774]

πŸ› Bug Fixes

  • [USER] Fixed disk read/write panel in the shoot's etcd dashboards by @rickardsjp [#10493]
  • [DEVELOPER] An issue was fixed that rejected the creation of workerless shoots in the local setup. by @timuthy [#10498]

πŸƒ Others

  • [DEPENDENCY] The gardener/hvpa-controller image has been updated to v0.17.0. Release Notes by @gardener-ci-robot [#10508]
  • [DEPENDENCY] The quay.io/prometheus-operator/prometheus-config-reloader image has been updated to v0.76.2. by @gardener-ci-robot [#10500]
  • [DEPENDENCY] The gardener/machine-controller-manager image has been updated to v0.54.0. Release Notes by @gardener-ci-robot [#10528]
  • [DEPENDENCY] The gardener/alpine-conntrack image has been updated to 3.20.3. Release Notes by @gardener-ci-robot [#10487]
  • [DEPENDENCY] The envoyproxy/envoy image has been updated to v1.31.1. Release Notes by @gardener-ci-robot [#10531]
  • [OPERATOR] Federate apiserver_total_request metric to the Prometheus longterm instance by @jguipi [#10457]
  • [OPERATOR] Allow empty networking.nodes in case of IPv6 only shoots. by @axel7born [#10533]
  • [OPERATOR] Improved node utilisation by reducing requests for etcd-druid managed pods. by @unmarshall [#10540]
  • [DEVELOPER] Install go in the remote local setup from the go download site instead of using the apk package manager. by @vicwicker [#10502]

Helm Charts

  • controlplane: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/controlplane:v1.104.0
  • gardenlet: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/gardenlet:v1.104.0
  • operator: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/operator:v1.104.0
  • resource-manager: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/resource-manager:v1.104.0

Docker Images

  • admission-controller: europe-docker.pkg.dev/gardener-project/releases/gardener/admission-controller:v1.104.0
  • apiserver: europe-docker.pkg.dev/gardener-project/releases/gardener/apiserver:v1.104.0
  • controller-manager: europe-docker.pkg.dev/gardener-project/releases/gardener/controller-manager:v1.104.0
  • gardenlet: europe-docker.pkg.dev/gardener-project/releases/gardener/gardenlet:v1.104.0
  • node-agent: europe-docker.pkg.dev/gardener-project/releases/gardener/node-agent:v1.104.0
  • operator: europe-docker.pkg.dev/gardener-project/releases/gardener/operator:v1.104.0
  • resource-manager: europe-docker.pkg.dev/gardener-project/releases/gardener/resource-manager:v1.104.0
  • scheduler: europe-docker.pkg.dev/gardener-project/releases/gardener/scheduler:v1.104.0
Update gardener-controlplane to 1.104.0

[gardener/gardener]

⚠️ Breaking Changes

  • [USER] A bug has been fixed which was allowing users to set Shoot oidc configurations for the kube-apiserver without setting the clientID and issuerURL fields in spec.kubernetes.kubeAPIServer.oidcConfig, which would lead to the kube-apiserver stuck in a `Err...
Read more

v1.104.0-0

01 Oct 11:27
Compare
Choose a tag to compare

Release Notes v1.104

Yake release notes and upgrade guide

Related upstream release notes / changelogs

Update networking-calico to 1.41.0

[gardener/gardener-extension-networking-calico]

✨ New Features

  • [OPERATOR] Helm charts of extension and admission controller are published as OCI artifacts now. by @oliver-goetz [#445]

πŸƒ Others

  • [OPERATOR] Add static resource allocation autoscaling mode for calico node/typha (autoScaling.mode: static). by @ScheererJ [#464]
  • [OPERATOR] The race between a calico-node instance shutting down and a new one coming up is mitigated by setting NetworkUnavailable condition properly some time after initialization. by @ScheererJ [#477]

Helm Charts

  • admission-calico-application: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-calico-application:v1.41.0
  • admission-calico-runtime: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-calico-runtime:v1.41.0
  • networking-calico: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/networking-calico:v1.41.0

Docker Images

  • gardener-extension-admission-calico: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/admission-calico:v1.41.0
  • gardener-extension-networking-calico: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/networking-calico:v1.41.0
Update cloudprofiles to 0.7.17

Full Changelog: gardener-community/cloudprofiles@0.7.16...0.7.17

Update provider-hcloud to 0.6.31

[gardener-extension-provider-hcloud] v0.6.31

Update shoot-flux to 0.7.0

What's Changed

Full Changelog: stackitcloud/gardener-extension-shoot-flux@v0.6.1...v0.7.0

Update cloudprofiles to 0.7.18

What's Changed

Full Changelog: gardener-community/cloudprofiles@0.7.17...0.7.18

Update backup-s3 to 0.4.1

General Changes

  • Generate new controller-registration.yaml
Update provider-alicloud to 1.54.0

[gardener/gardener-extension-provider-alicloud]

πŸƒ Others

  • [OPERATOR] Starting with gardenlet >= v1.98.0, use controlplane webhook object selector to limit mutator calls. by @LucaBernstein [#731]
  • [OPERATOR] The shoot-webhook does no longer mutate the metrics-server Deployment and the vpn-shoot Service. The shoot-webhook that now only mutates the addons-nginx-ingress-controller Service does now specify object selector. by @ialidzhikov [#730]
  • [OPERATOR] Upgrade and adapt new WorkerPoolHash function in Gardener v1.98. by @Duciwuci [#736]

Helm Charts

  • admission-alicloud-application: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-alicloud-application:v1.54.0
  • admission-alicloud-runtime: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-alicloud-runtime:v1.54.0
  • provider-alicloud: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/provider-alicloud:v1.54.0

Docker Images

  • gardener-extension-admission-alicloud: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/admission-alicloud:v1.54.0
  • gardener-extension-provider-alicloud: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/provider-alicloud:v1.54.0
Update gardener-controlplane to 1.104.0

[gardener/gardener]

⚠️ Breaking Changes

  • [USER] A bug has been fixed which was allowing users to set Shoot oidc configurations for the kube-apiserver without setting the clientID and issuerURL fields in spec.kubernetes.kubeAPIServer.oidcConfig, which would lead to the kube-apiserver stuck in a Error state. gardener-apiserver now requires both clientID and issuerURL fields to be set when the spec.kubernetes.kubeAPIServer.oidcConfig field is specified. by @AleksandarSavchev [#10461]
  • [OPERATOR] credentialsBinding.credentialsRef is now an immutable field. by @dimityrmirchev [#10365]

πŸ“° Noteworthy

  • [USER] Users are allowed to change shoot.spec.credentialsBindingName and reference another CredentialsBinding only if they have the permissions to read both the old and newly referenced credential. by @dimityrmirchev [#10365]
  • [USER] Users can migrate from shoot.spec.secretBindingName to shoot.spec.credentialsBindingName only if the referenced credential remains the same and is not changed during the process. by @dimityrmirchev [#10365]
  • [OPERATOR] Allow project users to read NamespacedCloudProfiles and for project admins to make adjustments to machine types and volume types. by @LucaBernstein [#10485]
  • [OPERATOR] Alerts based on the proposals_failed_total metric of the etcd cluster are not raised anymore. by @renormalize [#10524]
  • [DEVELOPER] A new predicate extensions/pkg/predicate.GardenSecurityProviderType can be used to select resources from the security.gardener.cloud group that are related to the passed provider type. by @dimityrmirchev [#10499]

✨ New Features

  • [OPERATOR] The gardener-operator metrics are now automatically scraped by the garden Prometheus. by @maboehm [#10464]
  • [OPERATOR] Introduce custom RBAC verbs to allow for modification of .spec.{kubernetes,machineImages} in NamespacedCloudProfiles. by @LucaBernstein [#10485]
  • [OPERATOR] The feature gate NewVPN is introduced for the gardenlet component. If enabled, the new VPN implementation (Golang rewrite) is used for all Shoots of the respective Seed. In this case, the old implementation can be disabled for a single Shoot by annotating the shoot resource with alpha.control-plane.shoot.gardener.cloud/disable-new-vpn=true. For Seeds with disabled feature gate, the new implementation can be enabled for a single shoot by annotating it with alpha.control-plane.shoot.gardener.cloud/disable-new-vpn=false. by @MartinWeindel [#9774]

πŸ› Bug Fixes

  • [USER] Fixed disk read/write panel in the shoot's etcd dashboards by @rickardsjp [#10493]
  • [DEVELOPER] An issue was fixed that rejected the creation of workerless shoots in the local setup. by @timuthy [#10498]

πŸƒ Others

  • [DEPENDENCY] The gardener/hvpa-controller image has been updated to v0.17.0. Release Notes by @gardener-ci-robot [#10508]
  • [DEPENDENCY] The quay.io/prometheus-operator/prometheus-config-reloader image has been updated to v0.76.2. by @gardener-ci-robot [#10500]
  • [DEPENDENCY] The gardener/machine-controller-manager image has been updated to v0.54.0. Release Notes by @gardener-ci-robot [#10528]
  • [DEPENDENCY] The gardener/alpine-conntrack image has been updated to 3.20.3. Release Notes by @gardener-ci-robot [#10487]
  • [DEPENDENCY] The envoyproxy/envoy image has been updated to v1.31.1. Release Notes by @gardener-ci-robot [#10531]
  • [OPERATOR] Federate apiserver_total_request metric to the Prometheus longterm instance by @jguipi [#10457]
  • [OPERATOR] Allow empty networking.nodes in case of IPv6 only shoots. by @axel7born [#10533]
  • [OPERATOR] Improved node utilisation by reducing requests for etcd-druid managed pods. by @unmarshall [#10540]
  • [DEVELOPER] Install go in the remote local setup from the go download site instead of using the apk package manager. by @vicwicker [#10502]

Helm Charts

  • controlplane: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/controlplane:v1.104.0
  • gardenlet: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/gardenlet:v1.104.0
  • operator: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/operator:v1.104.0
  • resource-manager: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/resource-manager:v1.104.0

Docker Images

  • admission-controller: europe-docker.pkg.dev/gardener-project/releases/gardener/admission-controller:v1.104.0
  • apiserver: europe-docker.pkg.dev/gardener-project/releases/gardener/apiserver:v1.104.0
  • controller-manager: europe-docker.pkg.dev/gardener-project/releases/gardener/controller-manager:v1.104.0
  • gardenlet: europe-docker.pkg.dev/gardener-project/releases/gardener/gardenlet:v1.104.0
  • node-agent: europe-docker.pkg.dev/gardener-project/releases/gardener/node-agent:v1.104.0
  • operator: europe-docker.pkg.dev/gardener-project/releases/gardener/operator:v1.104.0
  • resource-manager: europe-docker.pkg.dev/gardener-project/releases/gardener/resource-manager:v1.104.0
  • scheduler: europe-docker.pkg.dev/gardener-project/releases/gardener/scheduler:v1.104.0
Update gardener-controlplane to 1.104.0

[gardener/gardener]

⚠️ Breaking Changes

  • [USER] A bug has been fixed which was allowing users to set Shoot oidc configurations for the kube-apiserver without setting the clientID and issuerURL fields in spec.kubernetes.kubeAPIServer.oidcConfig, which would lead to the kube-apiserver stuck in a `Err...
Read more

v1.103.0-1

16 Sep 12:53
Compare
Choose a tag to compare

Release Notes v1.103

Yake release notes and upgrade guide

Related upstream release notes / changelogs

Update provider-hcloud to 0.6.30

[gardener-extension-provider-hcloud] v0.6.30

Update provider-openstack to 1.41.2

[gardener/gardener-extension-provider-openstack]

πŸƒ Others

  • [OPERATOR] Fix an issue with share network reconciliation not calculating number of existing share networks correctly. by @AndreasBurger [#827]

Docker Images

  • gardener-extension-admission-openstack: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/admission-openstack:v1.41.2
  • gardener-extension-provider-openstack: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/provider-openstack:v1.41.2
Update shoot-cert-service to 1.44.2

[gardener/gardener-extension-shoot-cert-service]

πŸƒ Others

  • [OPERATOR] The memory limit from the cert-controller-manager Deployment is now removed. by @ialidzhikov [#287]

Docker Images

  • gardener-extension-shoot-cert-service: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/shoot-cert-service:v1.44.2
Update shoot-rsyslog-relp to 0.5.2

[gardener/gardener-extension-shoot-rsyslog-relp]

πŸ› Bug Fixes

  • [OPERATOR] Fixed an issue that caused the -a exit,always -F arch=b64 -S mount_setattr -F auid!=-1 -F key=privileged_special audit rule to not get correctly applied. by @plkokanov [#151]

Docker Images

  • gardener-extension-shoot-rsyslog-relp-admission: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/shoot-rsyslog-relp-admission:v0.5.2
  • gardener-extension-shoot-rsyslog-relp: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/shoot-rsyslog-relp:v0.5.2
Update provider-alicloud to 1.53.0

[gardener/gardener-extension-provider-alicloud]

✨ New Features

  • [OPERATOR] This extension now makes use of the new .spec.pools[].userDataSecretRef field to get to the worker pool user data. by @rfranzke [#727]
  • [OPERATOR] Helm charts of extension and admission controller are published as OCI artifacts now. by @oliver-goetz [#734]
  • [USER] The provider-alicloud extension does now support shoot clusters with Kubernetes version 1.30. You should consider the Kubernetes release notes before upgrading to 1.30. by @shafeeqes [#722]

πŸƒ Others

  • [OPERATOR] The controlplaneexposure.alicloud.extensions.gardener.cloud webhook does no longer mutate Services/Deployments. Previously the webhook was called for Services/Deployments mutations and was not mutating anything. by @ialidzhikov [#725]
  • [OPERATOR] This extension is now using the new way of providing monitoring configuration (ref GEP-19) in case a shoot cluster's Prometheus has been migrated to management via prometheus-operator. by @rfranzke [#720]
  • [OPERATOR] A priorityClassName can now be set for the admission deployment via the gardener-extension-admission-alicloud Helm chart. by @timuthy [#732]
  • [OPERATOR] Inserts architecture from worker to the machine class by @sssash18 [#735]
  • [OPERATOR] NodeGroupAutoscalingOptions can now be specified per worker group via the worker through the field worker.spec.pools.clusterAutoscaler by @aaronfern [#715]

[gardener/machine-controller-manager]

⚠️ Breaking Changes

πŸ› Bug Fixes

πŸƒ Others

πŸ“– Documentation

[gardener/machine-controller-manager-provider-alicloud]

πŸƒ Others

Helm Charts

  • admission-alicloud: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-alicloud:v1.53.0
  • provider-alicloud: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/provider-alicloud:v1.53.0

Docker Images

  • gardener-extension-admission-alicloud: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/admission-alicloud:v1.53.0
  • gardener-extension-provider-alicloud: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/provider-alicloud:v1.53.0
Update provider-aws to 1.57.0

[gardener/gardener-extension-provider-aws]

✨ New Features

  • [OPERATOR] Helm charts of extension and admission controller are published as OCI artifacts now. by @oliver-goetz [#1012]

πŸ› Bug Fixes

  • [OPERATOR] Removed unnecessary preStop hook from node-driver-registrar in csi-driver-node, as socket removal is now handled internally by node-driver-registrar, resolving distroless image error. by @AndreasBurger [#992]

πŸƒ Others

  • [OPERATOR] A priorityClassName can now be set for the admission deployment via the gardener-extension-admission-aws Helm chart. by @timuthy [#994]
  • [OPERATOR] Starting with gardenlet >= v1.98.0, use controlplane webhook object selector to limit mutator calls. by @LucaBernstein [#989]
  • [OPERATOR] Update the VPA CRD used for testing locally by @kon-angelo [#1019]
  • [OPERATOR] Inserts architecture from worker to the machine class by @sssash18 [#853]

Helm Charts

  • admission-aws-application: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-aws-application:v1.57.0
  • admission-aws-runtime: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-aws-runtime:v1.57.0
  • provider-aws: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/provider-aws:v1.57.0

Docker Images

  • gardener-extension-admission-aws: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/admission-aws:v1.57.0
  • gardener-extension-provider-aws: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/provider-aws:v1.57.0
Update provider-azure to 1.47.1

[gardener/gardener-extension-provider-azure]

πŸƒ Others

  • [OPERATOR] The storage domain to use for backup buckets is now inferred from the buckets' region if no explicit config is given by @AndreasBurger [#947]

Helm Charts

  • admission-azure-application: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-azure-application:v1.47.1
  • admission-azure-runtime: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/admission-azure-runtime:v1.47.1
  • provider-azure: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/provider-azure:v1.47.1

Docker Images

  • gardener-extension-admission-azure: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/admission-azure:v1.47.1
  • gardener-extension-provider-azure: europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/provider-azure:v1.47.1
Update provider-gcp to 1.38.0

[gardener/gardener-extension-provider-gcp]

✨ New Features

  • [OPERATOR] Helm charts of extension and admission controller are published as OCI artifacts now. by @oliver-goetz [#805]

πŸ› Bug Fixes

  • [OPERATOR] Removed unnecessary preStop hook from node-driver-registrar in csi-driver-node, as socket removal is now handled internally by node-driver-registrar, resolving distroless image error. by @sujeet01 [#792]
  • [USER] Allow configuring iops and throughput of hyperdisk-balanced disks by @hebelsan [#793]

πŸƒ Others

  • [OPERATOR] Inserts architecture from worker to the machine class by @sssash18 [#809]
  • [OPERATOR] Starting with gardenlet >= v1.98.0, use controlplane webhook object selector to limit mutator calls. by @LucaBernstein [#789]
  • [OPERATOR] Update the VPA...
Read more

v1.102.1-2

16 Sep 12:53
Compare
Choose a tag to compare

Release Notes v1.102

Yake release notes and upgrade guide

Related upstream release notes / changelogs

Update cloudprofiles to 0.7.16

Full Changelog: gardener-community/cloudprofiles@0.7.15...0.7.16

Update gardener-controlplane to 1.101.2

[gardener/gardener]

πŸƒ Others

  • [DEPENDENCY] The registry.k8s.io/ingress-nginx/controller-chroot image has been updated to v1.11.2. by @gardener-ci-robot [#10357]

Helm Charts

  • controlplane: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/controlplane:v1.101.2
  • gardenlet: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/gardenlet:v1.101.2
  • operator: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/operator:v1.101.2
  • resource-manager: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/resource-manager:v1.101.2

Docker Images

  • admission-controller: europe-docker.pkg.dev/gardener-project/releases/gardener/admission-controller:v1.101.2
  • apiserver: europe-docker.pkg.dev/gardener-project/releases/gardener/apiserver:v1.101.2
  • controller-manager: europe-docker.pkg.dev/gardener-project/releases/gardener/controller-manager:v1.101.2
  • gardenlet: europe-docker.pkg.dev/gardener-project/releases/gardener/gardenlet:v1.101.2
  • node-agent: europe-docker.pkg.dev/gardener-project/releases/gardener/node-agent:v1.101.2
  • operator: europe-docker.pkg.dev/gardener-project/releases/gardener/operator:v1.101.2
  • resource-manager: europe-docker.pkg.dev/gardener-project/releases/gardener/resource-manager:v1.101.2
  • scheduler: europe-docker.pkg.dev/gardener-project/releases/gardener/scheduler:v1.101.2
Update gardener-controlplane to 1.101.2

[gardener/gardener]

πŸƒ Others

  • [DEPENDENCY] The registry.k8s.io/ingress-nginx/controller-chroot image has been updated to v1.11.2. by @gardener-ci-robot [#10357]

Helm Charts

  • controlplane: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/controlplane:v1.101.2
  • gardenlet: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/gardenlet:v1.101.2
  • operator: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/operator:v1.101.2
  • resource-manager: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/resource-manager:v1.101.2

Docker Images

  • admission-controller: europe-docker.pkg.dev/gardener-project/releases/gardener/admission-controller:v1.101.2
  • apiserver: europe-docker.pkg.dev/gardener-project/releases/gardener/apiserver:v1.101.2
  • controller-manager: europe-docker.pkg.dev/gardener-project/releases/gardener/controller-manager:v1.101.2
  • gardenlet: europe-docker.pkg.dev/gardener-project/releases/gardener/gardenlet:v1.101.2
  • node-agent: europe-docker.pkg.dev/gardener-project/releases/gardener/node-agent:v1.101.2
  • operator: europe-docker.pkg.dev/gardener-project/releases/gardener/operator:v1.101.2
  • resource-manager: europe-docker.pkg.dev/gardener-project/releases/gardener/resource-manager:v1.101.2
  • scheduler: europe-docker.pkg.dev/gardener-project/releases/gardener/scheduler:v1.101.2
Update gardenlet to 1.101.2

[gardener/gardener]

πŸƒ Others

  • [DEPENDENCY] The registry.k8s.io/ingress-nginx/controller-chroot image has been updated to v1.11.2. by @gardener-ci-robot [#10357]

Helm Charts

  • controlplane: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/controlplane:v1.101.2
  • gardenlet: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/gardenlet:v1.101.2
  • operator: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/operator:v1.101.2
  • resource-manager: europe-docker.pkg.dev/gardener-project/releases/charts/gardener/resource-manager:v1.101.2

Docker Images

  • admission-controller: europe-docker.pkg.dev/gardener-project/releases/gardener/admission-controller:v1.101.2
  • apiserver: europe-docker.pkg.dev/gardener-project/releases/gardener/apiserver:v1.101.2
  • controller-manager: europe-docker.pkg.dev/gardener-project/releases/gardener/controller-manager:v1.101.2
  • gardenlet: europe-docker.pkg.dev/gardener-project/releases/gardener/gardenlet:v1.101.2
  • node-agent: europe-docker.pkg.dev/gardener-project/releases/gardener/node-agent:v1.101.2
  • operator: europe-docker.pkg.dev/gardener-project/releases/gardener/operator:v1.101.2
  • resource-manager: europe-docker.pkg.dev/gardener-project/releases/gardener/resource-manager:v1.101.2
  • scheduler: europe-docker.pkg.dev/gardener-project/releases/gardener/scheduler:v1.101.2
Update external-dns-management to 0.21.0

[gardener/external-dns-management]

⚠️ Breaking Changes

  • [OPERATOR] Drop support for custom resources dnslock.dns.gardener.cloud and remoteaccesscertificates.dns.gardener.cloud.
    As these experimental features have no been used in Gardener, it should not be relevant in most cases. by @MartinWeindel [#381]

πŸƒ Others

  • [OPERATOR] Bumps golang from 1.22.6 to 1.23.0. by @dependabot[bot] [#384]
  • [OPERATOR] Bumps golang from 1.22.5 to 1.22.6. by @dependabot[bot] [#383]
  • [OPERATOR] The dependency controller-manager-library has been updated to include the new flag --<cluster>.conditional-deploy-crds by @MartinWeindel [#385]

Docker Images

  • dns-controller-manager: europe-docker.pkg.dev/gardener-project/releases/dns-controller-manager:v0.21.0
Update gardener-controlplane to 1.102.0

[gardener/gardener]

⚠️ Breaking Changes

  • [OPERATOR] When the NewWorkerPoolHash feature gate is enabled, the calculation now also rolls worker nodes of Shoots when changing systemReserved in the kubelet configuration. Worker pools are not rolled if the sum of kubeReserved and systemReserved does not change. If the feature gate is already enabled, then the worker pools of Shoots with non-zero values in systemReserved will be rolled once. by @MichaelEischer [#10290]

πŸ“° Noteworthy

  • [USER] The spec.client field in the {Cluster}OpenIDConnectPreset APIs is deprecated and will be removed after support for Kubernetes 1.30 is dropped. by @AleksandarSavchev [#10253]
  • [USER] The spec.kubernetes.kubeAPIServer.oidcConfig.clientAuthentication field in the Shoot API is deprecated and will be removed after support for Kubernetes 1.30 is dropped. by @AleksandarSavchev [#10253]
  • [USER] The Shoot specification field .spec.kubernetes.kubeAPIServer.oidcConfig.signingAlgs for Kubernetes versions >= v1.30 is not supported anymore. by @AleksandarSavchev [#10244]

✨ New Features

  • [USER] Structured authentication configuration can now be set by creating a ConfigMap in the project namespace with the AuthenticationConfiguration file set in the config.yaml data key and referencing the ConfigMap in the new Shoot specification field .spec.kubernetes.kubeAPIServer.structuredAuthentication.configMapName for Kubernetes versions >= v1.30. Only one authenticator can be set via the authentication configuration until k8s.io/* Golang dependencies are upgraded to version >= v0.30. by @AleksandarSavchev [#10244]
  • [USER] The following vpa-recommender flags are now configurable via the Shoot specification:
    • --recommendation-lower-bound-cpu-percentile: .spec.kubernetes.verticalPodAutoscaler.recommendationLowerBoundCPUPercentile
    • --recommendation-upper-bound-cpu-percentile: .spec.kubernetes.verticalPodAutoscaler.recommendationUpperBoundCPUPercentile
    • --target-memory-percentile: .spec.kubernetes.verticalPodAutoscaler.targetMemoryPercentile
    • --recommendation-lower-bound-memory-percentile: .spec.kubernetes.verticalPodAutoscaler.recommendationLowerBoundMemoryPercentile
    • --recommendation-upper-bound-memory-percentile: .spec.kubernetes.verticalPodAutoscaler.recommendationUpperBoundMemoryPercentile by @ialidzhikov [#10221]
  • [OPERATOR] Performing control plane migration across Seeds with different provider types is now possible. Before triggering the migration, make sure that pods in the Shoot's control plane, once it is moved to the Destination Seed, will have network connectivity to the storage provider of the Source Seed (so that ETCD backups can be copied automatically). Additionally, make sure that the Shoot's nodes will have network connectivity to the Shoot's control plane after it is moved to the Destination Seed. by @plkokanov [#10323]
  • [OPERATOR] gardenlet now runs a new controller called TokenRequestorWorkloadIdentity which requests workload identity tokens and writes them into Secret resources in the seed cluster. These tokens can be then used by control plane components in order to present the said WorkloadIdentity before external systems. Please see here for more details. by @dimityrmirchev [#10298]
  • [OPERATOR] Quotas can now have scope of type WorkloadIdentity. by @dimityrmirchev [#10346]

πŸ› Bug Fixes

  • [USER] Fixes a bug preventing shoot clusters with annotation shoot.gardener.cloud/skip-readiness: "true" to be created. by @ScheererJ [#10317]
  • [OPERATOR] An issue causing the vpn-seed-server VPA's to be created with wrong targetRef for highly available Shoots is now fixed. by @ialidzhikov [#10366]

πŸƒ Others

  • [OPERATOR] vpa-updater and vpa-recommender components do now run with leader election enabled (unconditionally) and support running in HA mode. by @ialidzhikov [#10302]
  • [OPERATOR] Reduce kubelet http2 timeouts. by @axel7born [#10223]
  • [OPERATOR] Gardener now temporarily uses a `vpa-recomme...
Read more