This release includes a containerd fix for a security vulnerability, and also bumps Kubernetes to v1.34.10 for the latest bugfixes and Flatcar to v4593.2.4.
CAPZ Releases
Changes compared to v34.3.0
Components
- cluster-azure from v5.4.1 to v5.4.2
- cluster from v5.3.1 to v5.3.2
- Flatcar from v4593.2.1 to v4593.2.2
cluster-azure v5.4.1…v5.4.2
Changed
- Chart: Fix validation errors.
cluster v5.3.1…v5.3.2
Changed
- Chart: Fix validation errors.
Mitigates the “Dirty Frag” Linux kernel vulnerabilities (esp4/esp6, rxrpc) that could allow local privilege escalation and container escape on affected nodes.
Changes compared to v34.2.0
Components
- Flatcar from v4459.2.4 to v4593.2.1
- os-tooling from v1.28.0 to v1.31.0
Changes compared to v34.1.1
Components
- cluster-azure from v5.3.0 to v5.4.1
- cluster from v5.1.2 to v5.3.1
- Flatcar from v4459.2.3 to v4459.2.4
- Kubernetes from v1.34.5 to v1.34.7
- os-tooling from v1.26.4 to v1.28.0
cluster-azure v5.3.0…v5.4.1
Changed
- Apps: Enable
rbac-bootstrapas a default HelmRelease app.
cluster v5.1.2…v5.3.1
Added
- Apps: Add
rbac-bootstrapas a default HelmRelease app with a default ClusterRoleBinding forgiantswarm:giantswarm-admins.
Changed
- Apps: Use OCIRepository source for
rbac-bootstrapHelmRelease.
Fixed
- Apps: Change
rbac-bootstrapdefault role fromread-alltoviewand add additional groups for token forwarded cases.
Apps
- azure-cloud-controller-manager from v2.0.0 to v2.1.0
- azure-cloud-node-manager from v2.0.0 to v2.1.0
- cert-exporter from v2.9.16 to v2.10.1
- cilium from v1.4.1 to v1.4.3
- coredns from v1.29.1 to v1.30.0
- etcd-defrag from v1.2.4 to v1.2.6
- k8s-dns-node-cache from v2.9.2 to v2.11.0
- observability-bundle from v2.6.0 to v2.8.0
- prometheus-blackbox-exporter from v0.5.1 to v0.7.0
- security-bundle from v1.17.0 to v1.17.1
azure-cloud-controller-manager v2.0.0…v2.1.0
Changed
- Migrate to App Build Suite (ABS).
- Bump to upstream image v1.35.1
Removed
- Removed
PodSecurityPolicy. - Removed
global.podSecurityStandards.enforcedhelm value.
azure-cloud-node-manager v2.0.0…v2.1.0
Changed
- Migrate to App Build Suite (ABS).
- Bump to upstream image v1.35.1
Removed
- Removed
PodSecurityPolicy. - Removed
global.podSecurityStandards.enforcedhelm value.
cert-exporter v2.9.16…v2.10.1
Added
- DaemonSet: Add VPA.
Changed
- Values: Tune resources.
Fixed
- Parse all PEM blocks in secrets and certificate files, not just the first one. This fixes false alerts when multiple certificates are concatenated (e.g. Kyverno webhook cert rotation).
cilium v1.4.1…v1.4.3
Changed
coredns v1.29.1…v1.30.0
Added
- Add
coredns-adopterjob to adopt default CoreDNS resources on EKS clusters (disabled by default).
Changed
- Update
corednsimage to 1.14.2.
etcd-defrag v1.2.4…v1.2.6
Changed
- Chart: Update dependency ahrtr/etcd-defrag to v0.39.0. (#86)
- Chart: Update dependency ahrtr/etcd-defrag to v0.38.0. (#84)
k8s-dns-node-cache v2.9.2…v2.11.0
Added
- Add
configmap.log.enabledhelm value to toggle CoreDNS query logging (default:false). - Make
AAAA NOERRORconfigurable for IPv6.
observability-bundle v2.6.0…v2.8.0
Added
- Add KSM metrics for Envoy Gateway resources.
- Add
application.giantswarm.io/teamannotation from HelmReleases as label to KSM emitted metrics.
Changed
- Update kube-prometheus-stack to 20.1.0
- Change team annotation in
Chart.yamlto OpenContainers format (io.giantswarm.application.team). - Update alloy-app to 0.17.1
- Update kube-prometheus-stack to 20.0.0
- Update prometheus-operator-crd to 20.0.0
prometheus-blackbox-exporter v0.5.1…v0.7.0
Added
- Add
http_2xx_insecuremodule withinsecure_skip_verify: trueto support probing workload cluster API servers from the management cluster. The MC’s service account CA (http_2xx_k8sca) only covers the MC itself; workload clusters have their own CA which is not available to the blackbox exporter, making TLS verification impossible without this module.
Changed
- Set
priorityClassNametosystem-node-criticalto ensure DaemonSet pods are scheduled even on full nodes.
security-bundle v1.17.0…v1.17.1
Added
- Add
io.giantswarm.application.audienceandio.giantswarm.application.managedchart annotations for Backstage visibility.
Changed
- Update
falco(app) to v0.11.2. - Update
gel(app) to v1.0.2. - Update
kubescape(app) to v0.0.6. - Update
reports-server(app) to v0.1.3. - Update
starboard-exporter(app) to v1.0.3. - Update
trivy(app) to v0.14.2. - Update
trivy-operator(app) to v0.12.2. - Migrate chart annotations to OCI-compatible format.
Changes compared to v34.1.0
Apps
- cert-manager from v3.11.0 to v3.13.0
cert-manager v3.11.0…v3.13.0
Added
- Add control plane node toleration to CA injector deployment.
Changed
- Upgrade cert-manager to v1.19.4.
Removed
- Remove PodSecurityPolicy (PSP) and related resources.
- Remove Giant Swarm PSP to PSS migration logic.
Changes compared to v33.1.1
Components
- cluster-azure from v4.4.0 to v4.4.1
- cluster from v4.4.0 to v4.4.1
cluster v4.4.0…v4.4.1
Changed
- Control Plane: Make etcd image tag configurable. (#841)
Changes compared to v34.0.0
Components
- cluster-azure from v5.1.2 to v5.3.0
- Flatcar from v4459.2.2 to v4459.2.3
- Kubernetes from v1.34.3 to v1.34.5
- os-tooling from v1.26.3 to v1.26.4
cluster-azure v5.1.2…v5.3.0
Changed
- Values: Update default instance size to
D4as_v5. - Values: Use container registries from
clusterchart. - Allow CertManager to use DNS challenges on non-private clusters.
Apps
- cert-exporter from v2.9.15 to v2.9.16
- cert-manager from v3.9.4 to v3.11.0
- chart-operator-extensions from v1.1.2 to v1.1.3
- cilium from v1.3.4 to v1.4.1
- cilium-servicemonitors from v0.1.3 to v0.1.4
- coredns-extensions from v0.1.2 to v0.1.3
- etcd-defrag from v1.2.3 to v1.2.4
- etcd-k8s-res-count-exporter from v1.10.12 to v1.10.14
- k8s-audit-metrics from v0.10.11 to v0.10.13
- k8s-dns-node-cache from v2.9.1 to v2.9.2
- metrics-server from v2.7.0 to v2.8.0
- net-exporter from v1.23.0 to v1.23.1
- node-exporter from v1.20.10 to v1.20.11
- observability-bundle from v2.5.0 to v2.6.0
- observability-policies from v0.0.3 to v0.0.4
- priority-classes from v0.3.0 to v0.3.1
- prometheus-blackbox-exporter from v0.5.0 to v0.5.1
- security-bundle from v1.16.1 to v1.17.0
- teleport-kube-agent from v0.10.7 to v0.10.8
- vertical-pod-autoscaler from v6.1.1 to v6.1.2
- vertical-pod-autoscaler-crd from v4.1.1 to v4.1.2
cert-exporter v2.9.15…v2.9.16
Changed
- Go: Update dependencies.
cert-manager v3.9.4…v3.11.0
Added
- Add Vertical Pod Autoscaler (VPA) support for webhook pods.
- Add
io.giantswarm.application.audienceandio.giantswarm.application.managedchart annotations for Backstage visibility. - Add PodLogs for log collection.
Fixed
- Fix
controllerVertical Pod Autoscaler (VPA) resource syntax.
chart-operator-extensions v1.1.2…v1.1.3
Changed
- Migrate Chart.yaml annotations to new format as per https://docs.giantswarm.io/reference/platform-api/chart-metadata/
cilium v1.3.4…v1.4.1
Changed
- Upgrade Cilium to v1.19.1.
- Upgrade Cilium to v1.19.0.
- Update chart icon to use Giant Swarm-hosted Cilium icon.
- Upgrade Cilium to v1.18.7.
cilium-servicemonitors v0.1.3…v0.1.4
Changed
- Migrate chart metadata annotations
etcd-defrag v1.2.3…v1.2.4
Changed
- Chart: Update dependency ahrtr/etcd-defrag to v0.37.0. (#78)
etcd-k8s-res-count-exporter v1.10.12…v1.10.14
Changed
- Migrate to App Build Suite (ABS) for Helm chart building.
- Go: Update dependencies.
Removed
- Removed
PodSecurityPolicy. - Removed
global.podSecurityStandards.enforcedhelm value. - Removed
resource.psphelm value.
k8s-audit-metrics v0.10.11…v0.10.13
Changed
- Migrate to App Build Suite (ABS) for Helm chart building.
- Go: Update dependencies.
Removed
- Removed
PodSecurityPolicy. - Removed
global.podSecurityStandards.enforcedhelm value. - Removed
resource.psphelm value.
k8s-dns-node-cache v2.9.1…v2.9.2
Changed
- Upgrade application to version 1.26.7 (includes coredns 1.13.1)
metrics-server v2.7.0…v2.8.0
Changed
- Upgrade metrics-server to v0.8.1.
- Change team annotation in
Chart.yamlto OpenContainers format (io.giantswarm.application.team).
net-exporter v1.23.0…v1.23.1
Removed
- Removed
PodSecurityPolicy. - Removed
global.podSecurityStandards.enforcedhelm value.
node-exporter v1.20.10…v1.20.11
Changed
- Migrate to App Build Suite (ABS) for building and publishing Helm charts.
Fixed
- Removed duplicated
applabel which is already added by the selector helper.
observability-bundle v2.5.0…v2.6.0
Added
- Add KSM metrics for Gateway API resources
observability-policies v0.0.3…v0.0.4
Changed
- Rename app to
observability-policies - Change team annotation in
Chart.yamlto OpenContainers format (io.giantswarm.application.team).
priority-classes v0.3.0…v0.3.1
Fixed
- Sanitize
Chart.Versionused in labels. This is needed because flux apapends the digest to the version using the+character which is not allowed in labels.
prometheus-blackbox-exporter v0.5.0…v0.5.1
Changed
- Migrate to App Build Suite (ABS) for Helm chart building.
security-bundle v1.16.1…v1.17.0
Changed
- Update
kyverno(app) to v0.23.0. - Update
kyverno-crds(app) to v1.16.0. - Update
reports-server(app) to v0.1.0. - Update
cloudnative-pg(app) to v0.0.13. - Update
kubescape(app) to v0.0.5. - Update
starboard-exporter(app) to v1.0.2.
teleport-kube-agent v0.10.7…v0.10.8
Added
- Add
io.giantswarm.application.audienceandio.giantswarm.application.managedchart annotations for Backstage visibility.
Changed
- Migrate chart metadata annotations to OCI-compatible format.
vertical-pod-autoscaler v6.1.1…v6.1.2
Fixed
- Pushed helm chart to OCI repository.
vertical-pod-autoscaler-crd v4.1.1…v4.1.2
Fixed
- Pushed helm chart to OCI repository.
Warning: Important Note for Upgrading to this Release
tl;dr: Please first upgrade your existing cluster to Giant Swarm Release v33.1.1 for Azure or newer before upgrading to this release! Otherwise, you risk service outage and severe issues.
Giant Swarm Release v34.0.0 for Azure comes with Kubernetes v1.34. This version contains etcd v3.6, which makes use of the so-called v3 store by default. Before, with etcd v3.5, the v2 store was used by default and synchronized to the already existing v3 store.
Different flaws could lead to an inconsistency between the old v2 store and the already present but unused standby v3 store in etcd v3.5 and before. Because of this, new etcd v3.6 members, which first start to use this v3 store, might suffer from these inconsistencies.
This can come into play when upgrading a cluster to this and future releases from any release older than Giant Swarm Release v33.1.1 for Azure. For this reason, we require you to first upgrade your cluster to Giant Swarm Release v33.1.1 for Azure or newer before upgrading to this or future releases.
OIDC Structured Authentication (optional)
This release introduces optional support for Kubernetes Structured Authentication Configuration for OIDC providers. We recommend testing this feature on a non-production cluster first.
Minimal example
global: controlPlane: oidc: structuredAuthentication: enabled: true issuers: - issuerUrl: https://your-idp.example.com clientId: kubernetesExample with customization
global: controlPlane: oidc: structuredAuthentication: enabled: true issuers: - issuerUrl: https://your-idp.example.com clientId: kubernetes usernameClaim: email # Optional: use 'email' instead of 'sub' groupsClaim: roles # Optional: use 'roles' instead of 'groups' usernamePrefix: "oidc:" # Optional: prefix usernames groupsPrefix: "oidc:" # Optional: prefix groupsMigration from legacy OIDC configuration
If you already use OIDC with the legacy configuration, add
structuredAuthentication.enabled: trueto migrate:global: controlPlane: oidc: issuerUrl: https://your-idp.example.com clientId: kubernetes structuredAuthentication: enabled: trueThis will automatically convert your legacy configuration to the new structured format.
Advanced options
Additional configuration options are available for more complex setups, including:
- Multiple audiences (
audiences,audienceMatchPolicy) - Custom discovery URL (
discoveryUrl) - Custom CA certificate (
caPem) - CEL expressions for claim and user validation (
claimValidationRules,userValidationRules) - Advanced claim mappings with CEL expressions (
claimMappings)
Refer to the Kubernetes Structured Authentication documentation for details.
Changes compared to v33.1.1
Components
- cluster-azure from v4.4.0 to v5.1.2
- Flatcar from v4459.2.1 to v4459.2.2
- Kubernetes from v1.33.6 to v1.34.3
- os-tooling from v1.26.2 to v1.26.3
cluster-azure v4.4.0…v5.1.2
Added
- Add the
priority-classesdefault app, enabled by default. This app provides standardisedPriorityClassresources likegiantswarm-criticalandgiantswarm-high, which should replace the previous inconsistent per-app priority classes. - Add
"helm.sh/resource-policy": keepannotation toAzureClusterCR so that it doesn’t get removed by Helm when uninstalling this chart. The CAPI controllers will take care of removing it, following the expected deletion order.
Changed
- Chart: Update
clusterto v5.1.2. - Chart: Update
clusterto v5.1.1. - Chart: Update
clusterto v5.1.0. - Chart: Update
clusterto v5.0.0.
Apps
- azure-cloud-controller-manager from v1.32.7-1 to v2.0.0
- azure-cloud-node-manager from v1.32.7 to v2.0.0
- azuredisk-csi-driver from v1.32.9 to v2.1.0
- azurefile-csi-driver from v1.32.5 to v2.0.0
- cert-exporter from v2.9.14 to v2.9.15
- cilium from v1.3.2 to v1.3.4
- coredns from v1.28.3 to v1.29.1
- etcd-k8s-res-count-exporter from v1.10.11 to v1.10.12
- external-dns from v3.2.0 to v3.4.0
- k8s-audit-metrics from v0.10.10 to v0.10.11
- network-policies from v0.1.1 to v0.1.3
- node-exporter from v1.20.9 to v1.20.10
- observability-bundle from v2.3.2 to v2.5.0
- Added priority-classes v0.3.0
- security-bundle from v1.15.0 to v1.16.1
azure-cloud-controller-manager v1.32.7-1…v2.0.0
Changed
- Chart: Update to upstream v1.34.3. (#132)
azure-cloud-node-manager v1.32.7…v2.0.0
Changed
- Chart: Update to upstream v1.34.3. (#118)
azuredisk-csi-driver v1.32.9…v2.1.0
Changed
azurefile-csi-driver v1.32.5…v2.0.0
Changed
- Chart: Update to upstream v1.34.2. (#71)
cert-exporter v2.9.14…v2.9.15
Changed
- Go: Update dependencies.
cilium v1.3.2…v1.3.4
Changed
coredns v1.28.3…v1.29.1
Changed
etcd-k8s-res-count-exporter v1.10.11…v1.10.12
Changed
- Go: Update dependencies.
external-dns v3.2.0…v3.4.0
Changed
- Sync to upstream helm chart 1.20.0.
- Add option to set annotationPrefix.
- Fixed the missing schema for .provider.webhook.serviceMonitor configs.
- Fixed incorrect indentation of selector labels under spec.template.spec.topologySpreadConstraints when topologySpreadConstraints is set.
- Use kubectl-apply-job when installing CRDs.
- Upgrade external-dns to v0.20.0.
- Update DNSEndpoints CRD.
- Sync to upstream helm chart
1.19.0.- Grant
discovery.k8s.io/endpointslicespermission only when usingservicesource. - Update RBAC for
Servicesource to supportEndpointSlices. - Allow extraArgs to also be a map enabling overrides of individual values.
- Set defaults for
automountServiceAccountTokenandserviceAccount.automountServiceAccountTokentotruein Helm chart values. - Correctly handle
txtPrefixandtxtSuffixarguments when both are provided. - Add ability to generate schema with
helm plugin schema. - Regenerate JSON schema with `helm-values-schema-json’ plugin.
- Added ability to configure
imagePullSecretsvia helmglobalvalue. - Added options to configure
labelFilterandmanagedRecordTypesvia dedicated helm values. - Allow templating
serviceaccount.annotationskeys and values, by rendering them using thetplbuilt-in function. - Added support for
extraContainersargument. - Added support for setting
excludeDomainsargument. - Added support for setting
dnsConfig. - Added support for webhook providers.
- Grant
- Restrict managed record types to A and CNAME.
k8s-audit-metrics v0.10.10…v0.10.11
Changed
- Go: Update dependencies.
network-policies v0.1.1…v0.1.3
Added
- Add support for Kamaji.
Fixed
- Fixed broken templating.
node-exporter v1.20.9…v1.20.10
Removed
- Repository: Remove integration tests.
observability-bundle v2.3.2…v2.5.0
Added
- Add KSM metrics
kube_servicemonitor_infoandkube_podmonitor_infofor ServiceMonitor and PodMonitor resources - Add KSM metrics
kube_podlog_infofor PodLog resource
Changed
- Upgrade
kube-prometheus-stack-appto 19.0.0 - Update alloy-app to 0.16.0
- Bumps alloy to 1.12.0
Fixed
- Fixed KSM metrics for endpoints
priority-classes v0.3.0
Changed
- Label now uses chart version instead of app version.
Removed
- Removed appVersion (only version is used now).
security-bundle v1.15.0…v1.16.1
Changed
- Add missing dependency to all apps.
- Allow to set multiple dependencies on the depends-on annotation.
- Rename
edgedbtogel. - Update
cloudnative-pg(app) to v0.0.12. - Update
gel(app) to v1.0.1.
- Multiple audiences (
This patch release fixes an issue with the installation of the Teleport Kube Agent app.
Changes compared to v33.1.0
Apps
- coredns from v1.28.2 to v1.28.3
coredns v1.28.2…v1.28.3
Changed
- Update
corednsimage to 1.13.2.
This release updates Flatcar to v4230.2.4 and includes several app updates and improvements.
Changes compared to v32.0.0
Components
- Flatcar from v4230.2.2 to v4230.2.4
- os-tooling from v1.26.1 to v1.26.2
Apps
- capi-node-labeler from v1.1.3 to v1.1.5
- cert-exporter from v2.9.9 to v2.9.13
- cert-manager from v3.9.2 to v3.9.4
- cilium from v1.3.0 to v1.3.1
- coredns from v1.27.0 to v1.28.2
- etcd-defrag from v1.0.8 to v1.2.2
- etcd-k8s-res-count-exporter from v1.10.7 to v1.10.10
- k8s-audit-metrics from v0.10.6 to v0.10.9
- node-exporter from v1.20.5 to v1.20.8
- observability-bundle from v2.2.2 to v2.3.2
- security-bundle from v1.12.0 to v1.14.0
- vertical-pod-autoscaler from v6.0.1 to v6.1.1
- vertical-pod-autoscaler-crd from v4.0.1 to v4.1.1
capi-node-labeler v1.1.3…v1.1.5
Changed
- Go: Update dependencies.
- Go: Update dependencies.
cert-exporter v2.9.9…v2.9.13
Changed
- Go: Update dependencies.
- Go: Update dependencies.
- Chart: Add value to toggle creation of Daemonset resources.
- Go: Update dependencies.
cert-manager v3.9.2…v3.9.4
Added
- Add E2E tests using apptest-framework for automated PR testing across multiple providers (CAPA, CAPV, CAPZ, CAPVCD).
- Basic test suite: Validates fresh installations
- Upgrade test suite: Tests upgrade scenarios and certificate reconciliation
- Add certificate issuance integration test to cluster-test-suites.
Changed
- Upgrade cert-manager to v1.18.2.
- Fix missing targetPort in
cainjector-service
cilium v1.3.0…v1.3.1
Changed
- Upgrade Cilium to v1.18.2.
coredns v1.27.0…v1.28.2
Changed
- Update
corednsimage to 1.13.1. - Add value to toggle creation of controlplane deployment.
- Update
corednsimage to 1.13.0.
etcd-defrag v1.0.8…v1.2.2
Changed
- Chart: Update dependency ahrtr/etcd-defrag to v0.35.0. (#64)
- Chart: Update dependency ahrtr/etcd-defrag to v0.34.0. (#62)
- Chart: Update dependency ahrtr/etcd-defrag to v0.33.0. (#60)
- Update Kyverno API to v2 for policy exceptions
- Chart: Update dependency ahrtr/etcd-defrag to v0.32.0. (#57)
etcd-k8s-res-count-exporter v1.10.7…v1.10.10
Changed
- Go: Update dependencies.
- Go: Update dependencies.
- Update Kyverno API to v2 for policy exceptions
- Go: Update dependencies.
k8s-audit-metrics v0.10.6…v0.10.9
Changed
- Go: Update dependencies.
- Go: Update dependencies.
- Update Kyverno API to v2 for policy exceptions
- Go: Update dependencies.
node-exporter v1.20.5…v1.20.8
Changed
- Go: Update dependencies.
- Go: Update dependencies.
- Update Kyverno API to v2 for policy exceptions
- Go: Update dependencies.
observability-bundle v2.2.2…v2.3.2
Added
- Add KSM metrics for cloudnative-pg Cluster objects
Changed
- Update alloy-app to 0.15.0
- Bumps alloy to 1.11.0
Fixed
- Update alloy-app to 0.15.1
- Bumps alloy to 1.11.2
security-bundle v1.12.0…v1.14.0
Changed
- Update
kyverno(app) to v0.20.1. - Update
kyverno-crds(app) to v1.14.0. - Update
kyverno-policies(app) to v0.24.0. - Update
reports-server(app) to v0.0.3. - Revert previous
kyvernoupdate (#536, #531, #538). - Update
kyverno-policy-operator(app) to v0.1.6. - Update
kyverno(app) to v0.20.0. - Update
kyverno-crds(app) to v1.14.0. - Update
kyverno-policies(app) to v0.24.0. - Update
kyverno-policy-operator(app) to v0.1.5. - Update
trivy-operator(app) to v0.12.1. - Update
trivy(app) to v0.14.1. - Update
falco(app) to v0.11.0.
vertical-pod-autoscaler v6.0.1…v6.1.1
Changed
- Chart: Update Helm release vertical-pod-autoscaler to v11.1.1. (#375)
- Chart: Update Helm release vertical-pod-autoscaler to v11.1.0. (#372)
vertical-pod-autoscaler-crd v4.0.1…v4.1.1
Changed