Changes compared to v27.5.0
Components
- cluster-aws from v1.3.7 to v1.3.8
cluster-aws v1.3.7…v1.3.8
Changed
- Cilium: Replace no longer supported tunneloption byroutingMode.
tunnel option by routingMode.tunnel option by routingMode.Most notable change in this release is the reduction of IAM permissions on the worker nodes instance profile, aiming at improving the general security of the clusters. Additional changes include reducing the size of the ETCD volume to 50GB targetting costs saving initiatives, improvements for the node-termination-handler application for smoother upgrades and operations as well as fixes for ENI mode targetting the CAPA migration.
global.providerSpecific.reducedInstanceProfileIamPermissionsForWorkers.aws-node-termination-handler-app as environment variablesMost notable change in this release is the reduction of IAM permissions on the worker nodes instance profile, aiming at improving the general security of the clusters. Additional changes include reducing the size of the ETCD volume to 50GB targetting costs saving initiatives, improvements for the node-termination-handler application for smoother upgrades and operations as well as fixes for ENI mode targetting the CAPA migration.
global.providerSpecific.reducedInstanceProfileIamPermissionsForWorkers.aws-node-termination-handler-app as environment variablesMost notable change in this release is the reduction of IAM permissions on the worker nodes instance profile, aiming at improving the general security of the clusters. Additional changes include reducing the size of the ETCD volume to 50GB targetting costs saving initiatives, improvements for the node-termination-handler application for smoother upgrades and operations as well as fixes for ENI mode targetting the CAPA migration.
global.providerSpecific.reducedInstanceProfileIamPermissionsForWorkers.aws-node-termination-handler-app as environment variablesThis release introduces improvements for ENI mode targetting the CAPA migration process.
This release introduces improvements for ENI mode targetting the CAPA migration process.
tunnel option by routingMode.Most notable change in this release is the reduction of IAM permissions on the worker nodes instance profile, aiming at improving the general security of the clusters. Additional changes include reducing the size of the ETCD volume to 50GB targetting costs saving initiatives, as well as improvements for the node-termination-handler application for smoother upgrades and operations.
global.providerSpecific.reducedInstanceProfileIamPermissionsForWorkers.aws-node-termination-handler-app as environment variablesMost notable change in this release is the reduction of IAM permissions on the worker nodes instance profile, aiming at improving the general security of the clusters. Additional changes include reducing the size of the ETCD volume to 50GB targetting costs saving initiatives, as well as improvements for the node-termination-handler application for smoother upgrades and operations. Several components such as Flatcar or Kubernetes have also been updated to the latest available versions.
global.providerSpecific.reducedInstanceProfileIamPermissionsForWorkers.aws-node-termination-handler-app as environment variablessecurityContext to be compliant.Note: When upgrading to this security-bundle version with Falco enabled, the Falco App will fail to upgrade due to a breaking change in the upstream chart. To finish the upgrade, disable, then re-enable the Falco App by setting apps.falco.enabled=[false|true] in the security-bundle user values Config Map.
trivy-operator (app) to v0.10.3.trivy (app) to v0.13.1.kyverno (app) to v0.18.1.kyverno-crds (app) to v1.12.0.kyverno-policies (app) to v0.21.0.starboard-exporter (app) to v0.8.0.falco (app) to v0.9.1.This release introduces aws-node-termination-handler for graceful draining of nodes during an upgrade or other type of replacement of worker nodes.
Details can be found in the node pools documentation.