Changes compared to v27.5.1
Components
- cluster-aws from v1.3.8 to v1.3.9
cluster-aws v1.3.8…v1.3.9
Added
- Add ingress rule in nodes Security Group to allow access to the Cilium Relay when using ENI mode.
cilium-crossplane-resources
.cluster
to v2.0.1.coredns-extensions
and etcd-defrag
.Makefile.custom.mk
.snapshot-controller
NetworkPolicy. (#246)snapshot-controller
NetworkPolicy.global.image.registry
.main.yaml
.config.yml
.README.md
..gitignore
& kustomization-snapshotter.yaml
to vendor/external-snapshotter/
..kube-linter.yaml
.vendir.yml
.Chart.yaml
.values.yaml
.snapshot-controller
NetworkPolicy. (#246)vendor/external-snapshotter/upstream
..nancy-ignore
.securityContext
from external-snapshotter
..helmignore
.CHANGELOG.md
.Deployments
owned by unknown CRs, like the case of Crossplane providers.PolicyExceptions
apiVersion to v2beta1
. (#282)coredns
image to 1.12.0.moveLeader
. (#11)cluster
into useClusterEndpoints
. (#8)readOnlyRootFilesystem
to true in the container security context.PolicyExceptions
to v2beta1
.go.mod
and .nancy-ignore
. (#242)PolicyExceptions
to v2beta1
.go.mod
and .nancy-ignore
. (#248)metrics-server
.PolicyExceptions
to v2beta1
.go.mod
. (#322)tunnel
option by routingMode
.tunnel
option by routingMode
.tunnel
option by routingMode
.tunnel
option by routingMode
.Most notable change in this release is the reduction of IAM permissions on the worker nodes instance profile, aiming at improving the general security of the clusters. Additional changes include reducing the size of the ETCD volume to 50GB targetting costs saving initiatives, improvements for the node-termination-handler
application for smoother upgrades and operations as well as fixes for ENI mode targetting the CAPA migration.
global.providerSpecific.reducedInstanceProfileIamPermissionsForWorkers
.aws-node-termination-handler-app
as environment variables