Changes compared to v35.1.1
Components
- Kubernetes from v1.35.8 to v1.36.5
- os-tooling from v1.34.0 to v1.35.0
Apps
- cert-exporter from v2.12.0 to v2.12.1
- cilium from v1.5.1 to v1.6.0
- coredns from v1.32.0 to v1.33.0
- etcd-defrag from v1.2.10 to v1.2.12
- network-policies from v0.2.0 to v0.3.1
- node-exporter from v1.20.13 to v1.21.0
- observability-bundle from v3.3.1 to v3.5.0
- security-bundle from v2.3.0 to v2.4.0
- teleport-kube-agent from v0.11.1 to v0.12.0
cert-exporter v2.12.0…v2.12.1
Fixed
- A cert file that cannot be read no longer aborts the scan of its whole cert path. Previously one unreadable file (such as a root-only
0600ca.crton an AKS node, where the exporter runs as an unprivileged user) stopped the walk, silently dropping every file sorting after it from the metrics. Unreadable files are now logged and skipped individually.
cilium v1.5.1…v1.6.0
Changed
- Upgrade Cilium to v1.20.1 from v1.19.7. Please review the upstream 1.20 upgrade notes before rolling this out.
- Serve the ztunnel image from
gsoci.azurecr.io/giantswarm/cilium-ztunnelinstead of pulling it from upstream. Cilium v1.20 moved this image fromdocker.io/istio/ztunneltoquay.io/cilium/ztunnel:v1.0.0, and our mirror carries exactly that digest, so it no longer has to be allow-listed insync/unmirrored-images.txt. Only used byencryption.type=ztunnel, which we do not support.
Removed
- Upstream removed these long-deprecated Helm values in v1.20. None of them are set by this chart’s defaults, and because the chart’s
values.schema.jsondoes not reject unknown keys, leftovers in existing values are silently ignored rather than rejected — check your values before upgrading:encryption.strictMode.{enabled,cidr,allowRemoteNodeIdentities}→ useencryption.strictMode.egress.*encryption.ipsec.encryptedOverlayclustermesh.enableMCSAPISupport→ useclustermesh.mcsapi.enabled(MCS-API is now stable upstream)clustermesh.apiserver.tls.{server,admin,remote}.{cert,key}andclustermesh.apiserver.tls.enableSecrets→ enable auto-generation or pre-create the secretshubble.redact.kafka.apiKey→ Kafka-aware L7 policy support and proxylib were removed upstreampreflight.tofqdnsPreCache→ the preflight FQDN poller was removed upstreamhubble.ui.backend.{livenessProbe,readinessProbe}.enabled
sync/patches/certgen/. Cilium v1.20 ships thecertgen.enforceCAValidityThroughoutLeavesDurationvalue and wires--ca-enforce-validity-throughout-leaves-durationinto both certgen job specs itself, so the Giant Swarm patch that added them became a no-op (it detected this and skipped). The default staystrueand the rendered job specs are unchanged, so two more patches drop out ofdiffs/.
coredns v1.32.0…v1.33.0
Changed
- Update
corednsimage to 1.14.6. - Run the E2E test suites automatically on release PRs by adding
.github/release-pr-body.md.
Fixed
- Honor the deprecated
configmap.log,loadbalancePolicyandconfigmap.cacheagain. Since 1.31.0coredns.<zone>.log,coredns.<zone>.loadbalanceandcoredns.<zone>.cache.success.ttlshipped defaults that shadowed them, so the old keys were silently ignored. They are now unset by default, restoring the documented fallback chain. Rendering with default values is unchanged.
etcd-defrag v1.2.10…v1.2.12
Changed
- Chart: Update dependency ahrtr/etcd-defrag to v0.45.0. (#136)
- Chart: Update dependency ahrtr/etcd-defrag to v0.44.0. (#129)
network-policies v0.2.0…v0.3.1
Added
- Add
keywordstoChart.yaml. - Declare the
io.giantswarm.application.audience(all) and - Add optional
denyEgressToIMDSpolicy denying pod egress to the instance metadata service. Disabled by default. - Add apptest-framework e2e test suite.
Changed
- Always exclude the
karpenterandaws-load-balancer-controllernamespaces fromdenyEgressToIMDS. - Move the team annotation from the legacy
application.giantswarm.io/teamkey to
node-exporter v1.20.13…v1.21.0
Added
disableSystemdCollectorvalue to turn the systemd collector off, mirroring the existingdisableConntrackCollectoranddisableNvmeCollectortoggles. The collector needs a D-Bus connection to the host, which is refused on nodes where AppArmor mediates D-Bus (such as AKS Ubuntu nodes running under the default containerd profile), making it fail on every scrape. Defaults tofalse, so behaviour is unchanged.
observability-bundle v3.3.1…v3.5.0
Added
- Point kube-prometheus-stack’s control-plane ServiceMonitors at the alloy-metrics token Secret.
Changed
- Update
alloyapps to 0.23.1 (Alloy v1.19.2). - Update
prometheus-operator-crdto 24.0.0 (Prometheus Operator CRDs v0.94.0). - Update
kube-prometheus-stackto 24.0.0 (chart 91.2.3, Prometheus Operator v0.94.0). - Values: Update Prometheus Operator CRD and Kube Prometheus Stack to v23.0.0.
Fixed
- KSM custom resource state: Set the Gateway API
TCPRouteandUDPRoutecollectors tov1, which is the version the API server serves.
security-bundle v2.3.0…v2.4.0
Added
- Add e2e scenarios covering trivy-operator
VulnerabilityReportcreation, starboard-exporter metrics for that report, kyverno restricted PSS enforcement, and kyverno-policy-operatorPolicyExceptiontranslation.
Changed
- Update
exception-recommender(app) to v0.3.0. - Update
falco(app) to v0.13.0. - Update
jiralert(app) to v0.1.4. - Update
kubescape(app) to v0.1.1. - Update
kyverno-policies(app) to v0.27.1. - Update
policy-api(app) to v0.0.12. - Update
starboard-exporter(app) to v1.2.15. - Update
trivy(app) to v0.18.0. - Update
trivy-operator(app) to v0.15.0.
Removed
- Remove
gel(app).
Fixed
- Give
kubescapea 15m install and upgrade timeout. It does not finish installing within Flux’s 5m default, so it failed withcontext deadline exceededand then retried indefinitely. - Set
createNamespaceon every app in the bundle, so each one creates its target namespace instead of relying on another app to have created it first. Previouslykubescapefailed withnamespaces "kubescape" not found, and the apps targetingsecurity-bundlecould only install afterkyverno-policy-operatorhad created it.
teleport-kube-agent v0.11.1…v0.12.0
Changed
- Updated
teleport-kube-agentto upstream versionv18.10.7.