This release includes a containerd fix for a security vulnerability, and also bumps Kubernetes to v1.34.10 for the latest bugfixes and Flatcar to v4593.2.4.
CAPA Releases
Changes compared to v34.4.0
Components
- cluster-aws from v7.7.2 to v7.7.3
cluster-aws v7.7.2…v7.7.3
Added
- Add
global.connectivity.certManager.createIamRoletoggle (defaulttrue) to let customers opt out of provisioning the cert-manager IAM role via crossplane and bring their own role.
Changes compared to v34.3.0
Components
- cluster-aws from v7.7.1 to v7.7.2
- cluster from v5.3.1 to v5.3.2
- Flatcar from v4593.2.1 to v4593.2.2
cluster-aws v7.7.1…v7.7.2
Changed
- Chart: Fix validation errors.
cluster v5.3.1…v5.3.2
Changed
- Chart: Fix validation errors.
Changes compared to v33.3.0
Components
- cluster-aws from v6.5.0 to v6.5.1
- cluster from v4.4.1 to v4.4.2
- Flatcar from v4593.2.1 to v4593.2.2
cluster-aws v6.5.0…v6.5.1
Changed
- Chart: Fix validation errors.
cluster v4.4.1…v4.4.2
Changed
- Chart: Fix validation errors.
Changes compared to v32.3.0
Components
- cluster-aws from v5.5.0 to v5.5.1
- cluster from v3.0.1 to v3.0.2
- Flatcar from v4593.2.1 to v4593.2.2
cluster-aws v5.5.0…v5.5.1
Changed
- Chart: Fix validation errors.
cluster v3.0.1…v3.0.2
Changed
- Chart: Fix validation errors.
Changes compared to v31.2.0
Components
- cluster-aws from v3.8.0 to v3.8.1
- cluster from v2.6.1 to v2.6.3
- Flatcar from v4593.2.1 to v4593.2.2
cluster-aws v3.8.0…v3.8.1
Changed
- Chart: Fix validation errors.
cluster v2.6.1…v2.6.3
Changed
- Chart: Fix validation errors.
Removed
- Chart: Remove deprecated
azure-container-registry-config.
Mitigates the “Dirty Frag” Linux kernel vulnerabilities (esp4/esp6, rxrpc) that could allow local privilege escalation and container escape on affected nodes.
Changes compared to v31.1.2
Components
- cluster-aws from v3.6.2 to v3.8.0
- cluster from v2.5.1 to v2.6.1
- Flatcar from v4152.2.3 to v4593.2.1
- os-tooling from v1.26.1 to v1.31.0
cluster-aws v3.6.2…v3.8.0
Changed
- Support newer Flatcar versions which require a larger root volume size. For ease of migration, enforce at least 15 GB even if a smaller, explicit size is specified in chart values.
cluster v2.5.1…v2.6.1
Added
- Add
enabledflag toproviderIntegration.workers.kubeadmConfigto disable the rendering of theKubeadmConfigresource. - containerd: Add flag to enable SELinux.
Changed
- Values: Fix schema. (#580)
Mitigates the “Dirty Frag” Linux kernel vulnerabilities (esp4/esp6, rxrpc) that could allow local privilege escalation and container escape on affected nodes.
Changes compared to v32.2.0
Components
- cluster-aws from v5.4.0 to v5.5.0
- Flatcar from v4230.2.4 to v4593.2.1
- os-tooling from v1.26.2 to v1.31.0
cluster-aws v5.4.0…v5.5.0
Changed
- Support newer Flatcar versions which require a larger root volume size. For ease of migration, enforce at least 15 GB even if a smaller, explicit size is specified in chart values.
Mitigates the “Dirty Frag” Linux kernel vulnerabilities (esp4/esp6, rxrpc) that could allow local privilege escalation and container escape on affected nodes.
Changes compared to v33.2.0
Components
- cluster-aws from v6.4.4 to v6.5.0
- Flatcar from v4459.2.1 to v4593.2.1
- os-tooling from v1.26.2 to v1.31.0
cluster-aws v6.4.4…v6.5.0
Changed
- Support newer Flatcar versions which require a larger root volume size. For ease of migration, enforce at least 15 GB even if a smaller, explicit size is specified in chart values.
Mitigates the “Dirty Frag” Linux kernel vulnerabilities (esp4/esp6, rxrpc) that could allow local privilege escalation and container escape on affected nodes.
Changes compared to v34.2.0
Components
- cluster-aws from v7.6.1 to v7.7.1
- Flatcar from v4459.2.4 to v4593.2.1
- os-tooling from v1.28.0 to v1.31.0
cluster-aws v7.6.1…v7.7.1
Changed
- Support newer Flatcar versions which require a larger root volume size. For ease of migration, enforce at least 15 GB even if a smaller, explicit size is specified in chart values.