Workload cluster release vsphere-35.0.0 for CAPV
Changes compared to v34.5.0
Components
- cluster-vsphere from v5.1.4 to v9.0.0
- cluster from v5.3.2 to v8.0.0
- Added containerd v2.3.2
- Flatcar from v4593.2.4 to v4593.2.5
- Kubernetes from v1.34.10 to v1.35.8
- os-tooling from v1.33.1 to v1.34.0
Added
- CI: Run the full set of E2E test suites automatically on release PRs, via
.github/release-pr-body.md. Towards https://github.com/giantswarm/roadmap/issues/4334 - Add support for Kamaji control planes.
- Add support for
network.giantswarm.io/wildcard-cname-target annotation on the Cluster CR via global.connectivity.dns.wildcardCnameTarget.
Changed
- Chart: Migrate Apps to HelmReleases.
- cert-manager: Fix version assignment.
- Make: Fix application variable.
- Update
giantswarm/cluster to v6.3.0.
Removed
- Values: Remove dead container registry cache schema.
- Chart: Remove unused
cluster-shared library chart dependency.
Fixed
- Bump
HelmRelease resources from the removed helm.toolkit.fluxcd.io/v2beta1 API to helm.toolkit.fluxcd.io/v2 so cluster apps render on management clusters running current Flux. - Allow adding additional properties into global.metadata.
Added
- Add
cert-manager-crossplane-resources HelmRelease. - Feature Gates: Add support for defining maximum Kubernetes version.
- Apps: Add External DNS Crossplane Resources.
- Apps: Deploy
cluster-autoscaler inCluster in Azure. - MachineDeployment: Add CAPI autoscaler annotations (
cluster-api-autoscaler-node-group-min-size/max-size) when minSize/maxSize are set on a node pool (only in Azure). - Apps: Add Cluster Autoscaler Crossplane Resources.
- Control Plane: Add Kamaji control plane support with
KamajiControlPlane resource, Kamaji etcd HelmRelease, automation RBAC, and cleanup jobs. (#740)
Changed
- Chart: Migrate Apps to HelmReleases.
- Migrate
coredns HelmRelease values to the new coredns-app zone-aware interface. - Rename the internal
coredns control plane helper to align with the controlPlane values key. - Updated
cert-manager to v4.0.0 and migrated the values to match the new chart’s schema. - Support templating on the
global.apps.<name>.extraConfigs.name field. - Add support for AKS clusters
- Add support for disabling the external autoscaler annotation (
cluster.x-k8s.io/replicas-managed-by: "external-autoscaler") on MachinePools. - Refactor
providerIntegration.resourcesApi.machinePoolResourcesEnabled into an object providerIntegration.resourcesApi.machinePoolResources and move externalAutoscaler under it (now providerIntegration.resourcesApi.machinePoolResources.externalAutoscaler). - Bump Flux OCIRepository version to v1.
- Control Plane: Remove handling of clusterRole resources for kamaji Datastore CRs and create kamaji-etcd polex here.
- Control Plane: Make etcd image tag configurable. (#841)
- Chart: Require
global.release.version if using Releases to give a better rendering error message. - Chart: Fix validation errors.
- Configure
observability-bundle with the management cluster name. - Apps: Skip
kyverno-crds dependency for cluster-autoscaler when deployed inCluster. - Apps: Add cluster-probes HelmRelease to deploy ServiceMonitors for probing workload cluster API server endpoint from the management cluster. Configurable via
global.apps.clusterProbes with default module http_2xx_insecure for self-signed certificates. - Helpers: Use
.Chart.AppVersion in app.kubernetes.io/version label. - Cluster API: Migrate to API
v1beta2.
Removed
- Cluster API: Remove
strategy.rollingUpdate.deletePolicy from node pools.
Fixed
- Control Plane: Ensure components start correctly when SELinux is set to enforcing.
Apps
- cert-exporter from v2.10.1 to v2.12.0
- cert-manager from v3.13.0 to v4.1.1
- cilium from v1.4.3 to v1.5.1
- cilium-servicemonitors from v0.1.4 to v0.2.0
- cloud-provider-vsphere from v2.4.0 to v2.5.1
- coredns from v1.30.0 to v1.32.0
- etcd-defrag from v1.2.6 to v1.2.10
- kube-vip-cloud-provider from v0.3.0 to v0.3.2
- net-exporter from v1.23.1 to v1.24.0
- network-policies from v0.1.3 to v0.2.0
- node-exporter from v1.20.11 to v1.20.13
- observability-bundle from v2.8.0 to v3.3.1
- Added rbac-bootstrap v0.3.0
- security-bundle from v1.17.1 to v2.3.0
- teleport-kube-agent from v0.10.8 to v0.11.1
- vsphere-csi-driver from v3.4.3 to v3.4.6
Added
- Regression tests covering the v2.11.1 metrics endpoint fix: concatenated and repeated certificates in secrets and files, and an endpoint level test asserting
/metrics keeps returning 200 and serving the remaining metrics when a duplicate series is emitted. - ATS: End to end test for a TLS secret whose
tls.crt holds a concatenated certificate chain.
Changed
- ATS:
cert_gen now sets a certificate serial number, which defaulted to 0 for every generated certificate. - Go: Update dependencies.
- Templates: Move PolicyException to
kube-system namespace. - Build and publish a multi-arch (linux/amd64 + linux/arm64) container image. Required so the cert-exporter daemonset can run on Graviton/arm64 nodepools without
exec format error.
Fixed
- Add a
serialnumber label to the cert_exporter_not_after and cert_exporter_secret_not_after metrics so concatenated certificates no longer collide into identical series. The collision made the registry fail Gather(), which blanked out the entire /metrics endpoint (regression from v2.10.1). - Serve
/metrics with ContinueOnError so a single problematic metric can no longer fail the whole scrape.
Changed
- Upgrade
docker-kubectl image to support arm64 architecture - Updated
cert-manager to upstream version v1.20.3. - Notes:
cert-manager-edit ClusterRole no longer grants create on challenges.acme.cert-manager.io, nor create/patch/update on orders.acme.cert-manager.io. - Improved proxy settings by adding a proxy ConfigMap and setting upstream
envFrom values for controller, webhook and cainjector. - Breaking: Helm values to be passed to the upstream
cert-manager chart will now need to use the cert-manager path instead of root. For example, the value crds.enabled: true must now be set with cert-manager.crds.enabled: true. - Moved vendored chart to
helm/cert-manager/charts/ and adapted sync scripts to follow new structure.
Added
sync/verify-images.sh, run as the last step of sync/sync.sh and therefore in CI: renders the chart across four scenarios covering every image-bearing component and fails the sync unless each image is served from gsoci.azurecr.io/giantswarm/ or is explicitly listed in sync/unmirrored-images.txt. It also asserts that every configured image actually appears in a render, so a scenario that stops covering an image fails instead of silently narrowing the check. This replaces the removed patch’s fail guards, which were the only thing that made image drift visible on an upstream bump.
Changed
- Upgrade Cilium to v1.19.7.
- Run the E2E test suites automatically on release PRs by adding
.github/release-pr-body.md. - Upgrade Cilium to v1.19.6.
- Switch Hubble TLS certificate provisioning from
hubble.tls.auto.method: helm to cronJob (giantswarm#37201). The helm method minted certificates once and never renewed them, deterministically breaking hubble-relay when the leaf certs (1 year) or the CA (3 years) expired. With the cronJob method a hubble-generate-certs CronJob re-issues the leaf certificates every 4 months. On upgrade, the Helm-owned cilium-ca, hubble-server-certs and hubble-relay-client-certs secrets are deleted and re-created by a one-shot certgen job with a fresh 3-year CA; agents and hubble-relay hot-reload the new certificates without restarts. - Wire certgen’s
--ca-enforce-validity-throughout-leaves-duration flag (new value certgen.enforceCAValidityThroughoutLeavesDuration, default true): the certgen job now fails roughly one year before the CA would no longer cover new leaf certificates, instead of silently issuing leafs that outlive the CA. certgen never rotates an existing CA on its own (cilium/certgen#500). - Relax
hubble-relay podAffinity to preferredDuringSchedulingIgnoredDuringExecution so Karpenter can drain the last cilium-agent-bearing node during upgrades/consolidation instead of getting stuck on a required co-location with cilium. - Upgrade Cilium to v1.19.5.
- Upgrade Cilium to v1.19.4.
Removed
- Removed the
image.registry value and the sync patch behind it (roadmap#3264). The registry is now part of each image’s repository value, exactly as upstream ships it, so the chart no longer patches upstream’s cilium.image/cilium.operator.image helpers into a (list $ <image>) signature and no longer rewrites all 35 call sites with sed. helm/cilium/templates/_helpers.tpl and helm/cilium/templates/cilium-operator/_helpers.tpl are now byte-identical to upstream, and 15 template patches disappear from diffs/.
Fixed
- Fix four image references that were rendered as unpullable double-prefixed paths, because their
repository already carried a registry while the removed patch prefixed image.registry on top: gsoci.azurecr.io/ghcr.io/spiffe/spire-server, .../spire-agent, .../docker.io/library/busybox (SPIRE mutual authentication) and .../docker.io/istio/ztunnel (encryption.type=ztunnel). All four now resolve. Latent until now because both features are disabled by default. - Fix rendering of the certgen job specs (
hubble/tls-cronjob and clustermesh-apiserver/tls-cronjob): the image reference was not converted to the Giant Swarm cilium.image helper signature because the image-registries sync patch only processed *.yaml templates, so enabling the cronJob method failed with required list, but got "map". - Add NetworkPolicies allowing the
hubble-generate-certs and clustermesh-apiserver-generate-certs certgen pods egress to the Kubernetes API.
Added
- Add per-monitor
enabled flag for the agent, hubble and operator.
Changed
- Switch all monitors from ServiceMonitor to PodMonitor.
Changed
- Helpers: Replace
+ in version label. - Update dependency kubernetes/cloud-provider-vsphere to v1.36.0.
Added
- Wire up the full set of CoreDNS
forward, cache, and kubernetes block parameters in the structured zone config:forward: maxIdleConns, maxConnectAttempts, dohMethod, tls, tlsServername, next, nextOnNodata, failfastAllUnhealthyUpstreams, failover, resolver.cache: zones, serveStale.verifyTimeout, disable.successZones, disable.denialZones.kubernetes: endpoint, tls, kubeconfig, apiserverQPS, apiserverBurst, apiserverMaxInflight, namespaceLabels, fallthroughZones, multicluster, startupTimeout.
Changed
- Chart: Make tolerations configurable.
- Rebuild with
app-build-suite 2.2.0 (via architect orb 9.6.0): the packaged chart now carries Artifact Hub metadata (artifacthub.io/license and a Support link). No functional chart changes. - Standardize
values.yaml comments to the # @schema / # -- (helm-docs) convention and remove section-header dividers, so values.schema.json and the chart README.md are generated from the values file. Rendered manifests are unchanged. - Update
coredns image to 1.14.4. - update CoreDNS icon to light version
- Update
coredns image to 1.14.3.
Fixed
- Render the
health directive in only the . server block. The health plugin is process-wide and can be enabled in just one Server Block, so emitting it in every zone block was invalid. ready is kept in every block (its readiness is aggregated across blocks). - Correct the
coredns.*.cache.serveStale.refreshMode schema enum to immediate/verify (was immediate/background), matching the CoreDNS cache plugin.
Changed
- Chart: Update dependency ahrtr/etcd-defrag to v0.43.0. (#125)
- Chart: Update dependency ahrtr/etcd-defrag to v0.42.0. (#120)
- Chart: Update dependency ahrtr/etcd-defrag to v0.41.0. (#108)
- Chart: Update dependency ahrtr/etcd-defrag to v0.40.0. (#94)
Changed
- CircleCI: Do not override app version.
- Chart: Fix icon URL.
Changed
- Build and publish a multi-arch (linux/amd64 + linux/arm64) container image. Required so the net-exporter daemonset can run on Graviton/arm64 nodepools without
exec format error. - Bump
docker-kubectl init container from 1.25.4 to 1.36.0.
Added
- Add support for AKS selector labels.
Changed
- Deprecated the .Values.kamaji in favour of the more generic .Values.konnectivityAgent to control the behaviour for the
konnectivity-agent.
Changed
- CircleCI: Do not override app version.
- Chart: Move PolicyException to
kube-system namespace.
Added
- Add KSM metrics for Gateway API
ListenerSet and ReferenceGrant resources. - Add Backstage audience annotations.
- Add managementCluster: "" as a top-level value (populated from the cluster chart via defaultValues)
- Moves full KSM metricRelabelings ownership from kube-prometheus-stack-app into observability-bundle
Changed
- Values: Generate schema for Alloy PodLogs CRDs.
- Values: Add Cilium as dependency for Alloy apps & Kube Prometheus Stack.
- Values: Update Alloy apps to v0.21.2.
- Update Gateway API KSM configs to
v1 for Gateway, GatewayClass, HTTPRoute, GRPCRoute, TLSRoute and BackendTLSPolicy. - Update
kube-prometheus-stack and prometheus-operator-crd to 22.0.0 - Update
alloy-app to 0.21.0 - HelmReleases: honor the App platform
priority field (1-150, default 25) on extraConfigs entries. spec.valuesFrom now reproduces the App platform merge order — all configMaps before all secrets (a secret always overrides a configMap), each kind ordered by priority around the user-config layer — preserving the App CR merge semantics after the migration. (giantswarm#36096) - Migrate sub-apps from App CRs to Flux HelmRelease CRs.
- Remove ‘cluster-values’ ConfigMap reference from HelmReleases.
- Add new
alloy-podlogs-crds chart. - Update alloy-app to 0.20.0
- Update dependency kube-prometheus-stack-app and prometheus-operator-crd to v21.0.0
- Update alloy-app to 0.19.0
Removed
- Values: Remove unused catalog.
rbac-bootstrap v0.3.0
Added
- Add
io.giantswarm.application.managed chart annotation for Backstage visibility. - Add optional
cluster-reader ClusterRole (off by default, enabled via clusterReader.enabled: true) that aggregates into the built-in view ClusterRole and grants read access (get/list/watch) on cluster-scoped resources.
Changed
- Migrate chart metadata annotations to OCI-compatible format.
Changed
- Update
kyverno-policy-operator (app) to v0.2.3. - Update
policy-api (app) to v0.0.9. - Update
starboard-exporter (app) to v1.2.3. - Update
trivy (app) to v0.17.0. - Update
trivy-operator (app) to v0.13.3. - Run the E2E test suites automatically on release PRs by adding
.github/release-pr-body.md. - Values: Make Kyverno and Kyverno Policy Operator depend on Cilium.
- Update
kyverno-policies (app) to v0.26.1. - Update
starboard-exporter (app) to v1.1.4. - Update
trivy (app) to v0.16.0. - Update
trivy-operator (app) to v0.13.2. - Update
cloudnative-pg (app) to v0.1.0. - Update
trivy (app) to v0.15.0. - Update
falco (app) to v0.12.0. - HelmReleases: honor the App platform
priority field (1-150, default 25) on extraConfigs entries. spec.valuesFrom now reproduces the App platform merge order — all configMaps before all secrets (a secret always overrides a configMap), each kind ordered by priority around the user-config layer — preserving the App CR merge semantics after the migration. (giantswarm#36096) - Migrate sub-apps from App CRs to Flux HelmRelease CRs.
- No longer pass the ‘cluster-values’ ConfigMap to the applications inside the bundle.
- Update
kyverno (app) to v0.24.2. - Update
kyverno-crds (app) to v1.17.0. - Update
kyverno-policies (app) to v0.25.0. - Update
kyverno-policy-operator (app) to v0.2.2. - Update
kubescape (app) to v0.1.0.
Changed
- Values: Tolerate
node.cloudprovider.kubernetes.io/uninitialized. - Values: Ignore taints regardless of value.
- Values: Pass HTTP proxy settings to sub-chart.
- Updated
teleport-kube-agent to upstream version v18.7.6.
Changed
- Update dependency kubernetes-sigs/vsphere-csi-driver to v3.7.3
- Update dependency kubernetes-sigs/vsphere-csi-driver to v3.7.2.
- chore: update values schema to ensure chart passes validation
- Helpers: Replace
+ in version label. - Update app icon to the Giant Swarm vSphere icon (
https://s.giantswarm.io/app-icons/vsphere/2/icon-light.png), replacing the upstream third-party logo.