Workload cluster release vsphere-36.1.0 for CAPV
Changes compared to v35.2.0
Components
- cluster-vsphere from v9.4.1 to v10.0.1
- cluster from v8.4.2 to v9.0.2
- Kubernetes from v1.35.9 to v1.36.5
Changed
- Chart: Use
.Chart.AppVersion in app.kubernetes.io/version label.
Changed
kubeadm: Exclude /etc/.systemd-confext from restorecon.- Cilium: Replace the catch-all
- operator: Exists toleration on cilium-operator with an explicit list.
Removed
- Chart: Remove App to HelmRelease migration.
Apps
- cilium from v1.5.2 to v1.6.1
Added
- Declare the
io.giantswarm.application.audience (all) and
Changed
- Upgrade Cilium to v1.20.2.
- Move the team annotation from the legacy
application.giantswarm.io/team key to - Point
home at this repository instead of https://cilium.io/, as the standard requires. - Upgrade Cilium to v1.20.1 from v1.19.7. Please review the upstream 1.20 upgrade notes before rolling this out.
- Serve the ztunnel image from
gsoci.azurecr.io/giantswarm/cilium-ztunnel instead of pulling it from upstream. Cilium v1.20 moved this image from docker.io/istio/ztunnel to quay.io/cilium/ztunnel:v1.0.0, and our mirror carries exactly that digest, so it no longer has to be allow-listed in sync/unmirrored-images.txt. Only used by encryption.type=ztunnel, which we do not support.
Removed
- Upstream removed these long-deprecated Helm values in v1.20. None of them are set by this chart’s defaults, and because the chart’s
values.schema.json does not reject unknown keys, leftovers in existing values are silently ignored rather than rejected — check your values before upgrading:encryption.strictMode.{enabled,cidr,allowRemoteNodeIdentities} → use encryption.strictMode.egress.*encryption.ipsec.encryptedOverlayclustermesh.enableMCSAPISupport → use clustermesh.mcsapi.enabled (MCS-API is now stable upstream)clustermesh.apiserver.tls.{server,admin,remote}.{cert,key} and clustermesh.apiserver.tls.enableSecrets → enable auto-generation or pre-create the secretshubble.redact.kafka.apiKey → Kafka-aware L7 policy support and proxylib were removed upstreampreflight.tofqdnsPreCache → the preflight FQDN poller was removed upstreamhubble.ui.backend.{livenessProbe,readinessProbe}.enabled
sync/patches/certgen/. Cilium v1.20 ships the certgen.enforceCAValidityThroughoutLeavesDuration value and wires --ca-enforce-validity-throughout-leaves-duration into both certgen job specs itself, so the Giant Swarm patch that added them became a no-op (it detected this and skipped). The default stays true and the rendered job specs are unchanged, so two more patches drop out of diffs/.