CAPA Releases

  • This release includes a containerd fix for a security vulnerability, and also bumps Kubernetes to v1.34.10 for the latest bugfixes and Flatcar to v4593.2.4.

    Components

    • Flatcar from v4593.2.2 to v4593.2.4
    • Kubernetes from v1.34.7 to v1.34.10
    • os-tooling from v1.31.0 to v1.33.1
  • Changes compared to v34.4.0

    Components

    • cluster-aws from v7.7.2 to v7.7.3

    cluster-aws v7.7.2…v7.7.3

    Added

    • Add global.connectivity.certManager.createIamRole toggle (default true) to let customers opt out of provisioning the cert-manager IAM role via crossplane and bring their own role.
  • Changes compared to v34.3.0

    Components

    • cluster-aws from v7.7.1 to v7.7.2
    • cluster from v5.3.1 to v5.3.2
    • Flatcar from v4593.2.1 to v4593.2.2

    cluster-aws v7.7.1…v7.7.2

    Changed

    • Chart: Fix validation errors.

    cluster v5.3.1…v5.3.2

    Changed

    • Chart: Fix validation errors.
  • Changes compared to v33.3.0

    Components

    • cluster-aws from v6.5.0 to v6.5.1
    • cluster from v4.4.1 to v4.4.2
    • Flatcar from v4593.2.1 to v4593.2.2

    cluster-aws v6.5.0…v6.5.1

    Changed

    • Chart: Fix validation errors.

    cluster v4.4.1…v4.4.2

    Changed

    • Chart: Fix validation errors.
  • Changes compared to v32.3.0

    Components

    • cluster-aws from v5.5.0 to v5.5.1
    • cluster from v3.0.1 to v3.0.2
    • Flatcar from v4593.2.1 to v4593.2.2

    cluster-aws v5.5.0…v5.5.1

    Changed

    • Chart: Fix validation errors.

    cluster v3.0.1…v3.0.2

    Changed

    • Chart: Fix validation errors.
  • Changes compared to v31.2.0

    Components

    • cluster-aws from v3.8.0 to v3.8.1
    • cluster from v2.6.1 to v2.6.3
    • Flatcar from v4593.2.1 to v4593.2.2

    cluster-aws v3.8.0…v3.8.1

    Changed

    • Chart: Fix validation errors.

    cluster v2.6.1…v2.6.3

    Changed

    • Chart: Fix validation errors.

    Removed

    • Chart: Remove deprecated azure-container-registry-config.
  • Mitigates the “Dirty Frag” Linux kernel vulnerabilities (esp4/esp6, rxrpc) that could allow local privilege escalation and container escape on affected nodes.

    Changes compared to v31.1.2

    Components

    • cluster-aws from v3.6.2 to v3.8.0
    • cluster from v2.5.1 to v2.6.1
    • Flatcar from v4152.2.3 to v4593.2.1
    • os-tooling from v1.26.1 to v1.31.0

    cluster-aws v3.6.2…v3.8.0

    Changed

    • Support newer Flatcar versions which require a larger root volume size. For ease of migration, enforce at least 15 GB even if a smaller, explicit size is specified in chart values.

    cluster v2.5.1…v2.6.1

    Added

    • Add enabled flag to providerIntegration.workers.kubeadmConfig to disable the rendering of the KubeadmConfig resource.
    • containerd: Add flag to enable SELinux.

    Changed

    • Values: Fix schema. (#580)
  • Mitigates the “Dirty Frag” Linux kernel vulnerabilities (esp4/esp6, rxrpc) that could allow local privilege escalation and container escape on affected nodes.

    Changes compared to v32.2.0

    Components

    • cluster-aws from v5.4.0 to v5.5.0
    • Flatcar from v4230.2.4 to v4593.2.1
    • os-tooling from v1.26.2 to v1.31.0

    cluster-aws v5.4.0…v5.5.0

    Changed

    • Support newer Flatcar versions which require a larger root volume size. For ease of migration, enforce at least 15 GB even if a smaller, explicit size is specified in chart values.
  • Mitigates the “Dirty Frag” Linux kernel vulnerabilities (esp4/esp6, rxrpc) that could allow local privilege escalation and container escape on affected nodes.

    Changes compared to v33.2.0

    Components

    • cluster-aws from v6.4.4 to v6.5.0
    • Flatcar from v4459.2.1 to v4593.2.1
    • os-tooling from v1.26.2 to v1.31.0

    cluster-aws v6.4.4…v6.5.0

    Changed

    • Support newer Flatcar versions which require a larger root volume size. For ease of migration, enforce at least 15 GB even if a smaller, explicit size is specified in chart values.
  • Mitigates the “Dirty Frag” Linux kernel vulnerabilities (esp4/esp6, rxrpc) that could allow local privilege escalation and container escape on affected nodes.

    Changes compared to v34.2.0

    Components

    • cluster-aws from v7.6.1 to v7.7.1
    • Flatcar from v4459.2.4 to v4593.2.1
    • os-tooling from v1.28.0 to v1.31.0

    cluster-aws v7.6.1…v7.7.1

    Changed

    • Support newer Flatcar versions which require a larger root volume size. For ease of migration, enforce at least 15 GB even if a smaller, explicit size is specified in chart values.