Workload cluster release aws-32.3.0 for CAPA

Mitigates the “Dirty Frag” Linux kernel vulnerabilities (esp4/esp6, rxrpc) that could allow local privilege escalation and container escape on affected nodes.

Changes compared to v32.2.0

Components

  • cluster-aws from v5.4.0 to v5.5.0
  • Flatcar from v4230.2.4 to v4593.2.1
  • os-tooling from v1.26.2 to v1.31.0

cluster-aws v5.4.0…v5.5.0

Changed

  • Support newer Flatcar versions which require a larger root volume size. For ease of migration, enforce at least 15 GB even if a smaller, explicit size is specified in chart values.