Workload cluster release aws-36.1.0 for CAPA

Changes compared to v35.2.0

Components

  • cluster-aws from v10.4.1 to v11.0.1
  • cluster from v8.4.2 to v9.0.2
  • Kubernetes from v1.35.9 to v1.36.5

cluster v8.4.2…v9.0.2

Changed

  • kubeadm: Exclude /etc/.systemd-confext from restorecon.
  • Cilium: Replace the catch-all - operator: Exists toleration on cilium-operator with an explicit list.

Removed

  • Chart: Remove App to HelmRelease migration.

Apps

  • cilium from v1.5.2 to v1.6.1
  • cloud-provider-aws from v2.1.0 to v2.2.0
  • cluster-autoscaler from v2.0.4 to v2.1.0

cilium v1.5.2…v1.6.1

Added

  • Declare the io.giantswarm.application.audience (all) and

Changed

  • Upgrade Cilium to v1.20.2.
  • Move the team annotation from the legacy application.giantswarm.io/team key to
  • Point home at this repository instead of https://cilium.io/, as the standard requires.
  • Upgrade Cilium to v1.20.1 from v1.19.7. Please review the upstream 1.20 upgrade notes before rolling this out.
  • Serve the ztunnel image from gsoci.azurecr.io/giantswarm/cilium-ztunnel instead of pulling it from upstream. Cilium v1.20 moved this image from docker.io/istio/ztunnel to quay.io/cilium/ztunnel:v1.0.0, and our mirror carries exactly that digest, so it no longer has to be allow-listed in sync/unmirrored-images.txt. Only used by encryption.type=ztunnel, which we do not support.

Removed

  • Upstream removed these long-deprecated Helm values in v1.20. None of them are set by this chart’s defaults, and because the chart’s values.schema.json does not reject unknown keys, leftovers in existing values are silently ignored rather than rejected — check your values before upgrading:
    • encryption.strictMode.{enabled,cidr,allowRemoteNodeIdentities} → use encryption.strictMode.egress.*
    • encryption.ipsec.encryptedOverlay
    • clustermesh.enableMCSAPISupport → use clustermesh.mcsapi.enabled (MCS-API is now stable upstream)
    • clustermesh.apiserver.tls.{server,admin,remote}.{cert,key} and clustermesh.apiserver.tls.enableSecrets → enable auto-generation or pre-create the secrets
    • hubble.redact.kafka.apiKey → Kafka-aware L7 policy support and proxylib were removed upstream
    • preflight.tofqdnsPreCache → the preflight FQDN poller was removed upstream
    • hubble.ui.backend.{livenessProbe,readinessProbe}.enabled
  • sync/patches/certgen/. Cilium v1.20 ships the certgen.enforceCAValidityThroughoutLeavesDuration value and wires --ca-enforce-validity-throughout-leaves-duration into both certgen job specs itself, so the Giant Swarm patch that added them became a no-op (it detected this and skipped). The default stays true and the rendered job specs are unchanged, so two more patches drop out of diffs/.

cloud-provider-aws v2.1.0…v2.2.0

Added

  • Add E2E tests

Changed

  • Add io.giantswarm.application.audience: all annotation to publish the app to the customer Backstage catalog.
  • Migrate chart metadata annotations to io.giantswarm.application.* format.
  • Chart: Update to upstream v1.36.1.

cluster-autoscaler v2.0.4…v2.1.0

Changed

  • Chart: Update to upstream v1.36.1.