Workload cluster release vsphere-36.1.0 for CAPV

Changes compared to v35.2.0

Components

  • cluster-vsphere from v9.4.1 to v10.0.1
  • cluster from v8.4.2 to v9.0.2
  • Kubernetes from v1.35.9 to v1.36.5

cluster-vsphere v9.4.1…v10.0.1

Changed

  • Chart: Use .Chart.AppVersion in app.kubernetes.io/version label.

cluster v8.4.2…v9.0.2

Changed

  • kubeadm: Exclude /etc/.systemd-confext from restorecon.
  • Cilium: Replace the catch-all - operator: Exists toleration on cilium-operator with an explicit list.

Removed

  • Chart: Remove App to HelmRelease migration.

Apps

  • cilium from v1.5.2 to v1.6.1

cilium v1.5.2…v1.6.1

Added

  • Declare the io.giantswarm.application.audience (all) and

Changed

  • Upgrade Cilium to v1.20.2.
  • Move the team annotation from the legacy application.giantswarm.io/team key to
  • Point home at this repository instead of https://cilium.io/, as the standard requires.
  • Upgrade Cilium to v1.20.1 from v1.19.7. Please review the upstream 1.20 upgrade notes before rolling this out.
  • Serve the ztunnel image from gsoci.azurecr.io/giantswarm/cilium-ztunnel instead of pulling it from upstream. Cilium v1.20 moved this image from docker.io/istio/ztunnel to quay.io/cilium/ztunnel:v1.0.0, and our mirror carries exactly that digest, so it no longer has to be allow-listed in sync/unmirrored-images.txt. Only used by encryption.type=ztunnel, which we do not support.

Removed

  • Upstream removed these long-deprecated Helm values in v1.20. None of them are set by this chart’s defaults, and because the chart’s values.schema.json does not reject unknown keys, leftovers in existing values are silently ignored rather than rejected — check your values before upgrading:
    • encryption.strictMode.{enabled,cidr,allowRemoteNodeIdentities} → use encryption.strictMode.egress.*
    • encryption.ipsec.encryptedOverlay
    • clustermesh.enableMCSAPISupport → use clustermesh.mcsapi.enabled (MCS-API is now stable upstream)
    • clustermesh.apiserver.tls.{server,admin,remote}.{cert,key} and clustermesh.apiserver.tls.enableSecrets → enable auto-generation or pre-create the secrets
    • hubble.redact.kafka.apiKey → Kafka-aware L7 policy support and proxylib were removed upstream
    • preflight.tofqdnsPreCache → the preflight FQDN poller was removed upstream
    • hubble.ui.backend.{livenessProbe,readinessProbe}.enabled
  • sync/patches/certgen/. Cilium v1.20 ships the certgen.enforceCAValidityThroughoutLeavesDuration value and wires --ca-enforce-validity-throughout-leaves-duration into both certgen job specs itself, so the Giant Swarm patch that added them became a no-op (it detected this and skipped). The default stays true and the rendered job specs are unchanged, so two more patches drop out of diffs/.