<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CAPZ releases - Giant Swarm Changes and Releases</title><link>https://docs.giantswarm.io/changes/capz-releases/</link><description>Recent changes and releases in the CAPZ releases category</description><language>en</language><lastBuildDate>Tue, 02 Jun 2026 16:37:01 +0000</lastBuildDate><atom:link href="https://docs.giantswarm.io/changes/capz-releases/index.xml" rel="self" type="application/rss+xml"/><item><title>Workload cluster release azure-34.4.0 for CAPZ</title><link>https://docs.giantswarm.io/changes/capz-releases/releases/azure-34.4.0/</link><pubDate>Tue, 02 Jun 2026 16:37:01 +0000</pubDate><guid>https://docs.giantswarm.io/changes/capz-releases/releases/azure-34.4.0/</guid><description>&lt;h2 id="changes-compared-to-v3430"&gt;Changes compared to v34.3.0&lt;/h2&gt;
&lt;h3 id="components"&gt;Components&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;cluster-azure from v5.4.1 to v5.4.2&lt;/li&gt;
&lt;li&gt;cluster from v5.3.1 to v5.3.2&lt;/li&gt;
&lt;li&gt;Flatcar from v4593.2.1 to &lt;a href="https://www.flatcar.org/releases/#release-4593.2.2"&gt;v4593.2.2&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cluster-azure-v541"&gt;cluster-azure &lt;a href="https://github.com/giantswarm/cluster-azure/compare/v5.4.1...v5.4.2"&gt;v5.4.1&amp;hellip;v5.4.2&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Chart: Fix validation errors.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cluster-v531"&gt;cluster &lt;a href="https://github.com/giantswarm/cluster/compare/v5.3.1...v5.3.2"&gt;v5.3.1&amp;hellip;v5.3.2&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-1"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Chart: Fix validation errors.&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Workload cluster release azure-34.3.0 for CAPZ</title><link>https://docs.giantswarm.io/changes/capz-releases/releases/azure-34.3.0/</link><pubDate>Wed, 13 May 2026 07:30:19 +0000</pubDate><guid>https://docs.giantswarm.io/changes/capz-releases/releases/azure-34.3.0/</guid><description>&lt;p&gt;Mitigates the &amp;ldquo;Dirty Frag&amp;rdquo; Linux kernel vulnerabilities (esp4/esp6, rxrpc) that could allow local privilege escalation and container escape on affected nodes.&lt;/p&gt;
&lt;h2 id="changes-compared-to-v3420"&gt;Changes compared to v34.2.0&lt;/h2&gt;
&lt;h3 id="components"&gt;Components&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Flatcar from v4459.2.4 to &lt;a href="https://www.flatcar.org/releases/#release-4593.2.1"&gt;v4593.2.1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;os-tooling from v1.28.0 to v1.31.0&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Workload cluster release azure-34.2.0 for CAPZ</title><link>https://docs.giantswarm.io/changes/capz-releases/releases/azure-34.2.0/</link><pubDate>Tue, 28 Apr 2026 16:09:06 +0000</pubDate><guid>https://docs.giantswarm.io/changes/capz-releases/releases/azure-34.2.0/</guid><description>&lt;h2 id="changes-compared-to-v3411"&gt;Changes compared to v34.1.1&lt;/h2&gt;
&lt;h3 id="components"&gt;Components&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;cluster-azure from v5.3.0 to v5.4.1&lt;/li&gt;
&lt;li&gt;cluster from v5.1.2 to v5.3.1&lt;/li&gt;
&lt;li&gt;Flatcar from v4459.2.3 to &lt;a href="https://www.flatcar.org/releases/#release-4459.2.4"&gt;v4459.2.4&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Kubernetes from v1.34.5 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1.34.7"&gt;v1.34.7&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;os-tooling from v1.26.4 to v1.28.0&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cluster-azure-v530"&gt;cluster-azure &lt;a href="https://github.com/giantswarm/cluster-azure/compare/v5.3.0...v5.4.1"&gt;v5.3.0&amp;hellip;v5.4.1&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Apps: Enable &lt;code&gt;rbac-bootstrap&lt;/code&gt; as a default HelmRelease app.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cluster-v512"&gt;cluster &lt;a href="https://github.com/giantswarm/cluster/compare/v5.1.2...v5.3.1"&gt;v5.1.2&amp;hellip;v5.3.1&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="added"&gt;Added&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Apps: Add &lt;code&gt;rbac-bootstrap&lt;/code&gt; as a default HelmRelease app with a default ClusterRoleBinding for &lt;code&gt;giantswarm:giantswarm-admins&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="changed-1"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Apps: Use OCIRepository source for &lt;code&gt;rbac-bootstrap&lt;/code&gt; HelmRelease.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="fixed"&gt;Fixed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Apps: Change &lt;code&gt;rbac-bootstrap&lt;/code&gt; default role from &lt;code&gt;read-all&lt;/code&gt; to &lt;code&gt;view&lt;/code&gt; and add additional groups for token forwarded cases.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="apps"&gt;Apps&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;azure-cloud-controller-manager from v2.0.0 to v2.1.0&lt;/li&gt;
&lt;li&gt;azure-cloud-node-manager from v2.0.0 to v2.1.0&lt;/li&gt;
&lt;li&gt;cert-exporter from v2.9.16 to v2.10.1&lt;/li&gt;
&lt;li&gt;cilium from v1.4.1 to v1.4.3&lt;/li&gt;
&lt;li&gt;coredns from v1.29.1 to v1.30.0&lt;/li&gt;
&lt;li&gt;etcd-defrag from v1.2.4 to v1.2.6&lt;/li&gt;
&lt;li&gt;k8s-dns-node-cache from v2.9.2 to v2.11.0&lt;/li&gt;
&lt;li&gt;observability-bundle from v2.6.0 to v2.8.0&lt;/li&gt;
&lt;li&gt;prometheus-blackbox-exporter from v0.5.1 to v0.7.0&lt;/li&gt;
&lt;li&gt;security-bundle from v1.17.0 to v1.17.1&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="azure-cloud-controller-manager-v200"&gt;azure-cloud-controller-manager &lt;a href="https://github.com/giantswarm/azure-cloud-controller-manager-app/compare/v2.0.0...v2.1.0"&gt;v2.0.0&amp;hellip;v2.1.0&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-2"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Migrate to App Build Suite (ABS).&lt;/li&gt;
&lt;li&gt;Bump to upstream image v1.35.1&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="removed"&gt;Removed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Removed &lt;code&gt;PodSecurityPolicy&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Removed &lt;code&gt;global.podSecurityStandards.enforced&lt;/code&gt; helm value.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="azure-cloud-node-manager-v200"&gt;azure-cloud-node-manager &lt;a href="https://github.com/giantswarm/azure-cloud-node-manager-app/compare/v2.0.0...v2.1.0"&gt;v2.0.0&amp;hellip;v2.1.0&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-3"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Migrate to App Build Suite (ABS).&lt;/li&gt;
&lt;li&gt;Bump to upstream image v1.35.1&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="removed-1"&gt;Removed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Removed &lt;code&gt;PodSecurityPolicy&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Removed &lt;code&gt;global.podSecurityStandards.enforced&lt;/code&gt; helm value.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cert-exporter-v2916"&gt;cert-exporter &lt;a href="https://github.com/giantswarm/cert-exporter/compare/v2.9.16...v2.10.1"&gt;v2.9.16&amp;hellip;v2.10.1&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="added-1"&gt;Added&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;DaemonSet: Add VPA.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="changed-4"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Values: Tune resources.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="fixed-1"&gt;Fixed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Parse all PEM blocks in secrets and certificate files, not just the first one. This fixes false alerts when multiple certificates are concatenated (e.g. Kyverno webhook cert rotation).&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cilium-v141"&gt;cilium &lt;a href="https://github.com/giantswarm/cilium-app/compare/v1.4.1...v1.4.3"&gt;v1.4.1&amp;hellip;v1.4.3&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-5"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Upgrade Cilium to &lt;a href="https://github.com/cilium/cilium/releases/tag/v1.19.3"&gt;v1.19.3&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Upgrade Cilium to &lt;a href="https://github.com/cilium/cilium/releases/tag/v1.19.2"&gt;v1.19.2&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="coredns-v1291"&gt;coredns &lt;a href="https://github.com/giantswarm/coredns-app/compare/v1.29.1...v1.30.0"&gt;v1.29.1&amp;hellip;v1.30.0&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="added-2"&gt;Added&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Add &lt;code&gt;coredns-adopter&lt;/code&gt; job to adopt default CoreDNS resources on EKS clusters (disabled by default).&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="changed-6"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Update &lt;code&gt;coredns&lt;/code&gt; image to &lt;a href="https://github.com/coredns/coredns/releases/tag/v1.14.2"&gt;1.14.2&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="etcd-defrag-v124"&gt;etcd-defrag &lt;a href="https://github.com/giantswarm/etcd-defrag-app/compare/v1.2.4...v1.2.6"&gt;v1.2.4&amp;hellip;v1.2.6&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-7"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Chart: Update dependency ahrtr/etcd-defrag to v0.39.0. (&lt;a href="https://github.com/giantswarm/etcd-defrag-app/pull/86"&gt;#86&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Chart: Update dependency ahrtr/etcd-defrag to v0.38.0. (&lt;a href="https://github.com/giantswarm/etcd-defrag-app/pull/84"&gt;#84&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="k8s-dns-node-cache-v292"&gt;k8s-dns-node-cache &lt;a href="https://github.com/giantswarm/k8s-dns-node-cache-app/compare/v2.9.2...v2.11.0"&gt;v2.9.2&amp;hellip;v2.11.0&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="added-3"&gt;Added&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Add &lt;code&gt;configmap.log.enabled&lt;/code&gt; helm value to toggle CoreDNS query logging (default: &lt;code&gt;false&lt;/code&gt;).&lt;/li&gt;
&lt;li&gt;Make &lt;code&gt;AAAA NOERROR&lt;/code&gt; configurable for IPv6.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="observability-bundle-v260"&gt;observability-bundle &lt;a href="https://github.com/giantswarm/observability-bundle/compare/v2.6.0...v2.8.0"&gt;v2.6.0&amp;hellip;v2.8.0&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="added-4"&gt;Added&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Add KSM metrics for Envoy Gateway resources.&lt;/li&gt;
&lt;li&gt;Add &lt;code&gt;application.giantswarm.io/team&lt;/code&gt; annotation from HelmReleases as label to KSM emitted metrics.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="changed-8"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Update kube-prometheus-stack to 20.1.0&lt;/li&gt;
&lt;li&gt;Change team annotation in &lt;code&gt;Chart.yaml&lt;/code&gt; to OpenContainers format (&lt;code&gt;io.giantswarm.application.team&lt;/code&gt;).&lt;/li&gt;
&lt;li&gt;Update alloy-app to 0.17.1&lt;/li&gt;
&lt;li&gt;Update kube-prometheus-stack to 20.0.0&lt;/li&gt;
&lt;li&gt;Update prometheus-operator-crd to 20.0.0&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="prometheus-blackbox-exporter-v051"&gt;prometheus-blackbox-exporter &lt;a href="https://github.com/giantswarm/prometheus-blackbox-exporter-app/compare/v0.5.1...v0.7.0"&gt;v0.5.1&amp;hellip;v0.7.0&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="added-5"&gt;Added&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Add &lt;code&gt;http_2xx_insecure&lt;/code&gt; module with &lt;code&gt;insecure_skip_verify: true&lt;/code&gt; to support probing workload cluster API servers from the management cluster. The MC&amp;rsquo;s service account CA (&lt;code&gt;http_2xx_k8sca&lt;/code&gt;) only covers the MC itself; workload clusters have their own CA which is not available to the blackbox exporter, making TLS verification impossible without this module.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="changed-9"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Set &lt;code&gt;priorityClassName&lt;/code&gt; to &lt;code&gt;system-node-critical&lt;/code&gt; to ensure DaemonSet pods are scheduled even on full nodes.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="security-bundle-v1170"&gt;security-bundle &lt;a href="https://github.com/giantswarm/security-bundle/compare/v1.17.0...v1.17.1"&gt;v1.17.0&amp;hellip;v1.17.1&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="added-6"&gt;Added&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Add &lt;code&gt;io.giantswarm.application.audience&lt;/code&gt; and &lt;code&gt;io.giantswarm.application.managed&lt;/code&gt; chart annotations for Backstage visibility.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="changed-10"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Update &lt;code&gt;falco&lt;/code&gt; (app) to v0.11.2.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;gel&lt;/code&gt; (app) to v1.0.2.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;kubescape&lt;/code&gt; (app) to v0.0.6.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;reports-server&lt;/code&gt; (app) to v0.1.3.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;starboard-exporter&lt;/code&gt; (app) to v1.0.3.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;trivy&lt;/code&gt; (app) to v0.14.2.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;trivy-operator&lt;/code&gt; (app) to v0.12.2.&lt;/li&gt;
&lt;li&gt;Migrate chart annotations to OCI-compatible format.&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Workload cluster release azure-34.1.1 for CAPZ</title><link>https://docs.giantswarm.io/changes/capz-releases/releases/azure-34.1.1/</link><pubDate>Thu, 23 Apr 2026 14:28:13 +0000</pubDate><guid>https://docs.giantswarm.io/changes/capz-releases/releases/azure-34.1.1/</guid><description>&lt;h2 id="changes-compared-to-v3410"&gt;Changes compared to v34.1.0&lt;/h2&gt;
&lt;h3 id="apps"&gt;Apps&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;cert-manager from v3.11.0 to v3.13.0&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cert-manager-v3110"&gt;cert-manager &lt;a href="https://github.com/giantswarm/cert-manager-app/compare/v3.11.0...v3.13.0"&gt;v3.11.0&amp;hellip;v3.13.0&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="added"&gt;Added&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Add control plane node toleration to CA injector deployment.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="changed"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Upgrade cert-manager to v1.19.4.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="removed"&gt;Removed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Remove PodSecurityPolicy (PSP) and related resources.&lt;/li&gt;
&lt;li&gt;Remove Giant Swarm PSP to PSS migration logic.&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Workload cluster release azure-33.2.0 for CAPZ</title><link>https://docs.giantswarm.io/changes/capz-releases/releases/azure-33.2.0/</link><pubDate>Tue, 21 Apr 2026 14:07:56 +0000</pubDate><guid>https://docs.giantswarm.io/changes/capz-releases/releases/azure-33.2.0/</guid><description>&lt;h2 id="changes-compared-to-v3311"&gt;Changes compared to v33.1.1&lt;/h2&gt;
&lt;h3 id="components"&gt;Components&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;cluster-azure from v4.4.0 to v4.4.1&lt;/li&gt;
&lt;li&gt;cluster from v4.4.0 to v4.4.1&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cluster-v440"&gt;cluster &lt;a href="https://github.com/giantswarm/cluster/compare/v4.4.0...v4.4.1"&gt;v4.4.0&amp;hellip;v4.4.1&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Control Plane: Make etcd image tag configurable. (&lt;a href="https://github.com/giantswarm/cluster/pull/841"&gt;#841&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Workload cluster release azure-34.1.0 for CAPZ</title><link>https://docs.giantswarm.io/changes/capz-releases/releases/azure-34.1.0/</link><pubDate>Mon, 02 Mar 2026 15:01:07 +0000</pubDate><guid>https://docs.giantswarm.io/changes/capz-releases/releases/azure-34.1.0/</guid><description>&lt;h2 id="changes-compared-to-v3400"&gt;Changes compared to v34.0.0&lt;/h2&gt;
&lt;h3 id="components"&gt;Components&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;cluster-azure from v5.1.2 to v5.3.0&lt;/li&gt;
&lt;li&gt;Flatcar from v4459.2.2 to &lt;a href="https://www.flatcar.org/releases/#release-4459.2.3"&gt;v4459.2.3&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Kubernetes from v1.34.3 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1.34.5"&gt;v1.34.5&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;os-tooling from v1.26.3 to v1.26.4&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cluster-azure-v512"&gt;cluster-azure &lt;a href="https://github.com/giantswarm/cluster-azure/compare/v5.1.2...v5.3.0"&gt;v5.1.2&amp;hellip;v5.3.0&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Values: Update default instance size to &lt;code&gt;D4as_v5&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Values: Use container registries from &lt;code&gt;cluster&lt;/code&gt; chart.&lt;/li&gt;
&lt;li&gt;Allow CertManager to use DNS challenges on non-private clusters.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="apps"&gt;Apps&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;cert-exporter from v2.9.15 to v2.9.16&lt;/li&gt;
&lt;li&gt;cert-manager from v3.9.4 to v3.11.0&lt;/li&gt;
&lt;li&gt;chart-operator-extensions from v1.1.2 to v1.1.3&lt;/li&gt;
&lt;li&gt;cilium from v1.3.4 to v1.4.1&lt;/li&gt;
&lt;li&gt;cilium-servicemonitors from v0.1.3 to v0.1.4&lt;/li&gt;
&lt;li&gt;coredns-extensions from v0.1.2 to v0.1.3&lt;/li&gt;
&lt;li&gt;etcd-defrag from v1.2.3 to v1.2.4&lt;/li&gt;
&lt;li&gt;etcd-k8s-res-count-exporter from v1.10.12 to v1.10.14&lt;/li&gt;
&lt;li&gt;k8s-audit-metrics from v0.10.11 to v0.10.13&lt;/li&gt;
&lt;li&gt;k8s-dns-node-cache from v2.9.1 to v2.9.2&lt;/li&gt;
&lt;li&gt;metrics-server from v2.7.0 to v2.8.0&lt;/li&gt;
&lt;li&gt;net-exporter from v1.23.0 to v1.23.1&lt;/li&gt;
&lt;li&gt;node-exporter from v1.20.10 to v1.20.11&lt;/li&gt;
&lt;li&gt;observability-bundle from v2.5.0 to v2.6.0&lt;/li&gt;
&lt;li&gt;observability-policies from v0.0.3 to v0.0.4&lt;/li&gt;
&lt;li&gt;priority-classes from v0.3.0 to v0.3.1&lt;/li&gt;
&lt;li&gt;prometheus-blackbox-exporter from v0.5.0 to v0.5.1&lt;/li&gt;
&lt;li&gt;security-bundle from v1.16.1 to v1.17.0&lt;/li&gt;
&lt;li&gt;teleport-kube-agent from v0.10.7 to v0.10.8&lt;/li&gt;
&lt;li&gt;vertical-pod-autoscaler from v6.1.1 to v6.1.2&lt;/li&gt;
&lt;li&gt;vertical-pod-autoscaler-crd from v4.1.1 to v4.1.2&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cert-exporter-v2915"&gt;cert-exporter &lt;a href="https://github.com/giantswarm/cert-exporter/compare/v2.9.15...v2.9.16"&gt;v2.9.15&amp;hellip;v2.9.16&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-1"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Go: Update dependencies.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cert-manager-v394"&gt;cert-manager &lt;a href="https://github.com/giantswarm/cert-manager-app/compare/v3.9.4...v3.11.0"&gt;v3.9.4&amp;hellip;v3.11.0&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="added"&gt;Added&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Add Vertical Pod Autoscaler (VPA) support for webhook pods.&lt;/li&gt;
&lt;li&gt;Add &lt;code&gt;io.giantswarm.application.audience&lt;/code&gt; and &lt;code&gt;io.giantswarm.application.managed&lt;/code&gt; chart annotations for Backstage visibility.&lt;/li&gt;
&lt;li&gt;Add PodLogs for log collection.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="fixed"&gt;Fixed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fix &lt;code&gt;controller&lt;/code&gt; Vertical Pod Autoscaler (VPA) resource syntax.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="chart-operator-extensions-v112"&gt;chart-operator-extensions &lt;a href="https://github.com/giantswarm/chart-operator-extensions/compare/v1.1.2...v1.1.3"&gt;v1.1.2&amp;hellip;v1.1.3&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-2"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Migrate Chart.yaml annotations to new format as per &lt;a href="https://docs.giantswarm.io/reference/platform-api/chart-metadata/"&gt;https://docs.giantswarm.io/reference/platform-api/chart-metadata/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cilium-v134"&gt;cilium &lt;a href="https://github.com/giantswarm/cilium-app/compare/v1.3.4...v1.4.1"&gt;v1.3.4&amp;hellip;v1.4.1&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-3"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Upgrade Cilium to &lt;a href="https://github.com/cilium/cilium/releases/tag/v1.19.1"&gt;v1.19.1&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Upgrade Cilium to &lt;a href="https://github.com/cilium/cilium/releases/tag/v1.19.0"&gt;v1.19.0&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Update chart icon to use Giant Swarm-hosted Cilium icon.&lt;/li&gt;
&lt;li&gt;Upgrade Cilium to &lt;a href="https://github.com/cilium/cilium/releases/tag/v1.18.7"&gt;v1.18.7&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cilium-servicemonitors-v013"&gt;cilium-servicemonitors &lt;a href="https://github.com/giantswarm/cilium-servicemonitors-app/compare/v0.1.3...v0.1.4"&gt;v0.1.3&amp;hellip;v0.1.4&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-4"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Migrate chart metadata annotations&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="etcd-defrag-v123"&gt;etcd-defrag &lt;a href="https://github.com/giantswarm/etcd-defrag-app/compare/v1.2.3...v1.2.4"&gt;v1.2.3&amp;hellip;v1.2.4&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-5"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Chart: Update dependency ahrtr/etcd-defrag to v0.37.0. (&lt;a href="https://github.com/giantswarm/etcd-defrag-app/pull/78"&gt;#78&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="etcd-k8s-res-count-exporter-v11012"&gt;etcd-k8s-res-count-exporter &lt;a href="https://github.com/giantswarm/etcd-kubernetes-resources-count-exporter/compare/v1.10.12...v1.10.14"&gt;v1.10.12&amp;hellip;v1.10.14&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-6"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Migrate to App Build Suite (ABS) for Helm chart building.&lt;/li&gt;
&lt;li&gt;Go: Update dependencies.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="removed"&gt;Removed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Removed &lt;code&gt;PodSecurityPolicy&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Removed &lt;code&gt;global.podSecurityStandards.enforced&lt;/code&gt; helm value.&lt;/li&gt;
&lt;li&gt;Removed &lt;code&gt;resource.psp&lt;/code&gt; helm value.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="k8s-audit-metrics-v01011"&gt;k8s-audit-metrics &lt;a href="https://github.com/giantswarm/k8s-audit-metrics/compare/v0.10.11...v0.10.13"&gt;v0.10.11&amp;hellip;v0.10.13&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-7"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Migrate to App Build Suite (ABS) for Helm chart building.&lt;/li&gt;
&lt;li&gt;Go: Update dependencies.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="removed-1"&gt;Removed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Removed &lt;code&gt;PodSecurityPolicy&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Removed &lt;code&gt;global.podSecurityStandards.enforced&lt;/code&gt; helm value.&lt;/li&gt;
&lt;li&gt;Removed &lt;code&gt;resource.psp&lt;/code&gt; helm value.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="k8s-dns-node-cache-v291"&gt;k8s-dns-node-cache &lt;a href="https://github.com/giantswarm/k8s-dns-node-cache-app/compare/v2.9.1...v2.9.2"&gt;v2.9.1&amp;hellip;v2.9.2&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-8"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Upgrade application to version 1.26.7 (includes coredns 1.13.1)&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="metrics-server-v270"&gt;metrics-server &lt;a href="https://github.com/giantswarm/metrics-server-app/compare/v2.7.0...v2.8.0"&gt;v2.7.0&amp;hellip;v2.8.0&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-9"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Upgrade metrics-server to v0.8.1.&lt;/li&gt;
&lt;li&gt;Change team annotation in &lt;code&gt;Chart.yaml&lt;/code&gt; to OpenContainers format (&lt;code&gt;io.giantswarm.application.team&lt;/code&gt;).&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="net-exporter-v1230"&gt;net-exporter &lt;a href="https://github.com/giantswarm/net-exporter/compare/v1.23.0...v1.23.1"&gt;v1.23.0&amp;hellip;v1.23.1&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="removed-2"&gt;Removed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Removed &lt;code&gt;PodSecurityPolicy&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Removed &lt;code&gt;global.podSecurityStandards.enforced&lt;/code&gt; helm value.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="node-exporter-v12010"&gt;node-exporter &lt;a href="https://github.com/giantswarm/node-exporter-app/compare/v1.20.10...v1.20.11"&gt;v1.20.10&amp;hellip;v1.20.11&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-10"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Migrate to App Build Suite (ABS) for building and publishing Helm charts.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="fixed-1"&gt;Fixed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Removed duplicated &lt;code&gt;app&lt;/code&gt; label which is already added by the selector helper.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="observability-bundle-v250"&gt;observability-bundle &lt;a href="https://github.com/giantswarm/observability-bundle/compare/v2.5.0...v2.6.0"&gt;v2.5.0&amp;hellip;v2.6.0&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="added-1"&gt;Added&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Add KSM metrics for Gateway API resources&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="observability-policies-v003"&gt;observability-policies &lt;a href="https://github.com/giantswarm/observability-policies-app/compare/v0.0.3...v0.0.4"&gt;v0.0.3&amp;hellip;v0.0.4&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-11"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Rename app to &lt;code&gt;observability-policies&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Change team annotation in &lt;code&gt;Chart.yaml&lt;/code&gt; to OpenContainers format (&lt;code&gt;io.giantswarm.application.team&lt;/code&gt;).&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="priority-classes-v030"&gt;priority-classes &lt;a href="https://github.com/giantswarm/priority-classes/compare/v0.3.0...v0.3.1"&gt;v0.3.0&amp;hellip;v0.3.1&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="fixed-2"&gt;Fixed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Sanitize &lt;code&gt;Chart.Version&lt;/code&gt; used in labels. This is needed because flux apapends the digest to the version using the &lt;code&gt;+&lt;/code&gt; character which is not allowed in labels.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="prometheus-blackbox-exporter-v050"&gt;prometheus-blackbox-exporter &lt;a href="https://github.com/giantswarm/prometheus-blackbox-exporter-app/compare/v0.5.0...v0.5.1"&gt;v0.5.0&amp;hellip;v0.5.1&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-12"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Migrate to App Build Suite (ABS) for Helm chart building.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="security-bundle-v1161"&gt;security-bundle &lt;a href="https://github.com/giantswarm/security-bundle/compare/v1.16.1...v1.17.0"&gt;v1.16.1&amp;hellip;v1.17.0&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-13"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Update &lt;code&gt;kyverno&lt;/code&gt; (app) to v0.23.0.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;kyverno-crds&lt;/code&gt; (app) to v1.16.0.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;reports-server&lt;/code&gt; (app) to v0.1.0.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;cloudnative-pg&lt;/code&gt; (app) to v0.0.13.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;kubescape&lt;/code&gt; (app) to v0.0.5.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;starboard-exporter&lt;/code&gt; (app) to v1.0.2.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="teleport-kube-agent-v0107"&gt;teleport-kube-agent &lt;a href="https://github.com/giantswarm/teleport-kube-agent-app/compare/v0.10.7...v0.10.8"&gt;v0.10.7&amp;hellip;v0.10.8&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="added-2"&gt;Added&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Add &lt;code&gt;io.giantswarm.application.audience&lt;/code&gt; and &lt;code&gt;io.giantswarm.application.managed&lt;/code&gt; chart annotations for Backstage visibility.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="changed-14"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Migrate chart metadata annotations to OCI-compatible format.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="vertical-pod-autoscaler-v611"&gt;vertical-pod-autoscaler &lt;a href="https://github.com/giantswarm/vertical-pod-autoscaler-app/compare/v6.1.1...v6.1.2"&gt;v6.1.1&amp;hellip;v6.1.2&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="fixed-3"&gt;Fixed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Pushed helm chart to OCI repository.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="vertical-pod-autoscaler-crd-v411"&gt;vertical-pod-autoscaler-crd &lt;a href="https://github.com/giantswarm/vertical-pod-autoscaler-crd/compare/v4.1.1...v4.1.2"&gt;v4.1.1&amp;hellip;v4.1.2&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="fixed-4"&gt;Fixed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Pushed helm chart to OCI repository.&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Workload cluster release azure-34.0.0 for CAPZ</title><link>https://docs.giantswarm.io/changes/capz-releases/releases/azure-34.0.0/</link><pubDate>Thu, 22 Jan 2026 09:38:19 +0000</pubDate><guid>https://docs.giantswarm.io/changes/capz-releases/releases/azure-34.0.0/</guid><description>&lt;h2 id="warning-important-note-for-upgrading-to-this-release"&gt;Warning: Important Note for Upgrading to this Release&lt;/h2&gt;
&lt;p&gt;&lt;em&gt;tl;dr&lt;/em&gt;: Please first upgrade your existing cluster to Giant Swarm Release v33.1.1 for Azure or newer before upgrading to this release! Otherwise, you risk service outage and severe issues.&lt;/p&gt;
&lt;p&gt;Giant Swarm Release v34.0.0 for Azure comes with Kubernetes v1.34. This version contains etcd v3.6, which makes use of the so-called v3 store by default. Before, with etcd v3.5, the v2 store was used by default and synchronized to the already existing v3 store.&lt;/p&gt;
&lt;p&gt;Different flaws could lead to an inconsistency between the old v2 store and the already present but unused standby v3 store in etcd v3.5 and before. Because of this, new etcd v3.6 members, which first start to use this v3 store, might suffer from these inconsistencies.&lt;/p&gt;
&lt;p&gt;This can come into play when upgrading a cluster to this and future releases from any release older than Giant Swarm Release v33.1.1 for Azure. For this reason, we require you to first upgrade your cluster to Giant Swarm Release v33.1.1 for Azure or newer before upgrading to this or future releases.&lt;/p&gt;
&lt;h2 id="oidc-structured-authentication-optional"&gt;OIDC Structured Authentication (optional)&lt;/h2&gt;
&lt;p&gt;This release introduces optional support for Kubernetes Structured Authentication Configuration for OIDC providers. We recommend testing this feature on a non-production cluster first.&lt;/p&gt;
&lt;h3 id="minimal-example"&gt;Minimal example&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#93a1a1;background-color:#002b36;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-yaml" data-lang="yaml"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#268bd2"&gt;global&lt;/span&gt;:
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#268bd2"&gt;controlPlane&lt;/span&gt;:
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#268bd2"&gt;oidc&lt;/span&gt;:
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#268bd2"&gt;structuredAuthentication&lt;/span&gt;:
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#268bd2"&gt;enabled&lt;/span&gt;: &lt;span style="color:#cb4b16"&gt;true&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#268bd2"&gt;issuers&lt;/span&gt;:
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; - &lt;span style="color:#268bd2"&gt;issuerUrl&lt;/span&gt;: https://your-idp.example.com
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#268bd2"&gt;clientId&lt;/span&gt;: kubernetes
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="example-with-customization"&gt;Example with customization&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#93a1a1;background-color:#002b36;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-yaml" data-lang="yaml"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#268bd2"&gt;global&lt;/span&gt;:
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#268bd2"&gt;controlPlane&lt;/span&gt;:
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#268bd2"&gt;oidc&lt;/span&gt;:
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#268bd2"&gt;structuredAuthentication&lt;/span&gt;:
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#268bd2"&gt;enabled&lt;/span&gt;: &lt;span style="color:#cb4b16"&gt;true&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#268bd2"&gt;issuers&lt;/span&gt;:
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; - &lt;span style="color:#268bd2"&gt;issuerUrl&lt;/span&gt;: https://your-idp.example.com
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#268bd2"&gt;clientId&lt;/span&gt;: kubernetes
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#268bd2"&gt;usernameClaim: email # Optional&lt;/span&gt;: use &amp;#39;email&amp;#39; instead of &amp;#39;sub&amp;#39;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#268bd2"&gt;groupsClaim: roles # Optional&lt;/span&gt;: use &amp;#39;roles&amp;#39; instead of &amp;#39;groups&amp;#39;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#268bd2"&gt;usernamePrefix&lt;/span&gt;: &lt;span style="color:#2aa198"&gt;&amp;#34;oidc:&amp;#34;&lt;/span&gt; &lt;span style="color:#586e75"&gt;# Optional: prefix usernames&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#268bd2"&gt;groupsPrefix&lt;/span&gt;: &lt;span style="color:#2aa198"&gt;&amp;#34;oidc:&amp;#34;&lt;/span&gt; &lt;span style="color:#586e75"&gt;# Optional: prefix groups&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="migration-from-legacy-oidc-configuration"&gt;Migration from legacy OIDC configuration&lt;/h3&gt;
&lt;p&gt;If you already use OIDC with the legacy configuration, add &lt;code&gt;structuredAuthentication.enabled: true&lt;/code&gt; to migrate:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#93a1a1;background-color:#002b36;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-yaml" data-lang="yaml"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#268bd2"&gt;global&lt;/span&gt;:
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#268bd2"&gt;controlPlane&lt;/span&gt;:
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#268bd2"&gt;oidc&lt;/span&gt;:
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#268bd2"&gt;issuerUrl&lt;/span&gt;: https://your-idp.example.com
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#268bd2"&gt;clientId&lt;/span&gt;: kubernetes
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#268bd2"&gt;structuredAuthentication&lt;/span&gt;:
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#268bd2"&gt;enabled&lt;/span&gt;: &lt;span style="color:#cb4b16"&gt;true&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This will automatically convert your legacy configuration to the new structured format.&lt;/p&gt;
&lt;h3 id="advanced-options"&gt;Advanced options&lt;/h3&gt;
&lt;p&gt;Additional configuration options are available for more complex setups, including:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Multiple audiences (&lt;code&gt;audiences&lt;/code&gt;, &lt;code&gt;audienceMatchPolicy&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;Custom discovery URL (&lt;code&gt;discoveryUrl&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;Custom CA certificate (&lt;code&gt;caPem&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;CEL expressions for claim and user validation (&lt;code&gt;claimValidationRules&lt;/code&gt;, &lt;code&gt;userValidationRules&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;Advanced claim mappings with CEL expressions (&lt;code&gt;claimMappings&lt;/code&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Refer to the &lt;a href="https://kubernetes.io/docs/reference/access-authn-authz/authentication/#using-authentication-configuration"&gt;Kubernetes Structured Authentication documentation&lt;/a&gt; for details.&lt;/p&gt;
&lt;h2 id="changes-compared-to-v3311"&gt;Changes compared to v33.1.1&lt;/h2&gt;
&lt;h3 id="components"&gt;Components&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;cluster-azure from v4.4.0 to v5.1.2&lt;/li&gt;
&lt;li&gt;Flatcar from v4459.2.1 to &lt;a href="https://www.flatcar.org/releases/#release-4459.2.2"&gt;v4459.2.2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Kubernetes from v1.33.6 to &lt;a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1.34.3"&gt;v1.34.3&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;os-tooling from v1.26.2 to v1.26.3&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cluster-azure-v440"&gt;cluster-azure &lt;a href="https://github.com/giantswarm/cluster-azure/compare/v4.4.0...v5.1.2"&gt;v4.4.0&amp;hellip;v5.1.2&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="added"&gt;Added&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Add the &lt;code&gt;priority-classes&lt;/code&gt; default app, enabled by default. This app provides standardised &lt;code&gt;PriorityClass&lt;/code&gt; resources like &lt;code&gt;giantswarm-critical&lt;/code&gt; and &lt;code&gt;giantswarm-high&lt;/code&gt;, which should replace the previous inconsistent per-app priority classes.&lt;/li&gt;
&lt;li&gt;Add &lt;code&gt;&amp;quot;helm.sh/resource-policy&amp;quot;: keep&lt;/code&gt; annotation to &lt;code&gt;AzureCluster&lt;/code&gt; CR so that it doesn&amp;rsquo;t get removed by Helm when uninstalling this chart. The CAPI controllers will take care of removing it, following the expected deletion order.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="changed"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Chart: Update &lt;code&gt;cluster&lt;/code&gt; to v5.1.2.&lt;/li&gt;
&lt;li&gt;Chart: Update &lt;code&gt;cluster&lt;/code&gt; to v5.1.1.&lt;/li&gt;
&lt;li&gt;Chart: Update &lt;code&gt;cluster&lt;/code&gt; to v5.1.0.&lt;/li&gt;
&lt;li&gt;Chart: Update &lt;code&gt;cluster&lt;/code&gt; to v5.0.0.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="apps"&gt;Apps&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;azure-cloud-controller-manager from v1.32.7-1 to v2.0.0&lt;/li&gt;
&lt;li&gt;azure-cloud-node-manager from v1.32.7 to v2.0.0&lt;/li&gt;
&lt;li&gt;azuredisk-csi-driver from v1.32.9 to v2.1.0&lt;/li&gt;
&lt;li&gt;azurefile-csi-driver from v1.32.5 to v2.0.0&lt;/li&gt;
&lt;li&gt;cert-exporter from v2.9.14 to v2.9.15&lt;/li&gt;
&lt;li&gt;cilium from v1.3.2 to v1.3.4&lt;/li&gt;
&lt;li&gt;coredns from v1.28.3 to v1.29.1&lt;/li&gt;
&lt;li&gt;etcd-k8s-res-count-exporter from v1.10.11 to v1.10.12&lt;/li&gt;
&lt;li&gt;external-dns from v3.2.0 to v3.4.0&lt;/li&gt;
&lt;li&gt;k8s-audit-metrics from v0.10.10 to v0.10.11&lt;/li&gt;
&lt;li&gt;network-policies from v0.1.1 to v0.1.3&lt;/li&gt;
&lt;li&gt;node-exporter from v1.20.9 to v1.20.10&lt;/li&gt;
&lt;li&gt;observability-bundle from v2.3.2 to v2.5.0&lt;/li&gt;
&lt;li&gt;Added priority-classes v0.3.0&lt;/li&gt;
&lt;li&gt;security-bundle from v1.15.0 to v1.16.1&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="azure-cloud-controller-manager-v1327-1"&gt;azure-cloud-controller-manager &lt;a href="https://github.com/giantswarm/azure-cloud-controller-manager-app/compare/v1.32.7-1...v2.0.0"&gt;v1.32.7-1&amp;hellip;v2.0.0&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-1"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Chart: Update to upstream v1.34.3. (&lt;a href="https://github.com/giantswarm/azure-cloud-controller-manager-app/pull/132"&gt;#132&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="azure-cloud-node-manager-v1327"&gt;azure-cloud-node-manager &lt;a href="https://github.com/giantswarm/azure-cloud-node-manager-app/compare/v1.32.7...v2.0.0"&gt;v1.32.7&amp;hellip;v2.0.0&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-2"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Chart: Update to upstream v1.34.3. (&lt;a href="https://github.com/giantswarm/azure-cloud-node-manager-app/pull/118"&gt;#118&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="azuredisk-csi-driver-v1329"&gt;azuredisk-csi-driver &lt;a href="https://github.com/giantswarm/azuredisk-csi-driver-app/compare/v1.32.9...v2.1.0"&gt;v1.32.9&amp;hellip;v2.1.0&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-3"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Chart: Update to upstream v1.34.0. (&lt;a href="https://github.com/giantswarm/azuredisk-csi-driver-app/pull/118"&gt;#118&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Chart: Update to upstream v1.33.7. (&lt;a href="https://github.com/giantswarm/azuredisk-csi-driver-app/pull/114"&gt;#114&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="azurefile-csi-driver-v1325"&gt;azurefile-csi-driver &lt;a href="https://github.com/giantswarm/azurefile-csi-driver-app/compare/v1.32.5...v2.0.0"&gt;v1.32.5&amp;hellip;v2.0.0&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-4"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Chart: Update to upstream v1.34.2. (&lt;a href="https://github.com/giantswarm/azurefile-csi-driver-app/pull/71"&gt;#71&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cert-exporter-v2914"&gt;cert-exporter &lt;a href="https://github.com/giantswarm/cert-exporter/compare/v2.9.14...v2.9.15"&gt;v2.9.14&amp;hellip;v2.9.15&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-5"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Go: Update dependencies.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cilium-v132"&gt;cilium &lt;a href="https://github.com/giantswarm/cilium-app/compare/v1.3.2...v1.3.4"&gt;v1.3.2&amp;hellip;v1.3.4&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-6"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Upgrade Cilium to &lt;a href="https://github.com/cilium/cilium/releases/tag/v1.18.6"&gt;v1.18.6&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Upgrade Cilium to &lt;a href="https://github.com/cilium/cilium/releases/tag/v1.18.5"&gt;v1.18.5&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="coredns-v1283"&gt;coredns &lt;a href="https://github.com/giantswarm/coredns-app/compare/v1.28.3...v1.29.1"&gt;v1.28.3&amp;hellip;v1.29.1&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-7"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Update &lt;code&gt;coredns&lt;/code&gt; image to &lt;a href="https://github.com/coredns/coredns/releases/tag/v1.14.1"&gt;1.14.1&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;coredns&lt;/code&gt; image to &lt;a href="https://github.com/coredns/coredns/releases/tag/v1.14.0"&gt;1.14.0&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="etcd-k8s-res-count-exporter-v11011"&gt;etcd-k8s-res-count-exporter &lt;a href="https://github.com/giantswarm/etcd-kubernetes-resources-count-exporter/compare/v1.10.11...v1.10.12"&gt;v1.10.11&amp;hellip;v1.10.12&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-8"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Go: Update dependencies.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="external-dns-v320"&gt;external-dns &lt;a href="https://github.com/giantswarm/external-dns-app/compare/v3.2.0...v3.4.0"&gt;v3.2.0&amp;hellip;v3.4.0&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-9"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Sync to upstream helm chart &lt;a href="https://github.com/kubernetes-sigs/external-dns/releases/tag/external-dns-helm-chart-1.20.0"&gt;1.20.0&lt;/a&gt;.
&lt;ul&gt;
&lt;li&gt;Add option to set annotationPrefix.&lt;/li&gt;
&lt;li&gt;Fixed the missing schema for .provider.webhook.serviceMonitor configs.&lt;/li&gt;
&lt;li&gt;Fixed incorrect indentation of selector labels under spec.template.spec.topologySpreadConstraints when topologySpreadConstraints is set.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Use kubectl-apply-job when installing CRDs.&lt;/li&gt;
&lt;li&gt;Upgrade external-dns to v0.20.0.&lt;/li&gt;
&lt;li&gt;Update DNSEndpoints CRD.&lt;/li&gt;
&lt;li&gt;Sync to upstream helm chart &lt;code&gt;1.19.0&lt;/code&gt;.
&lt;ul&gt;
&lt;li&gt;Grant &lt;code&gt;discovery.k8s.io/endpointslices&lt;/code&gt; permission only when using &lt;code&gt;service&lt;/code&gt; source.&lt;/li&gt;
&lt;li&gt;Update RBAC for &lt;code&gt;Service&lt;/code&gt; source to support &lt;code&gt;EndpointSlices&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Allow extraArgs to also be a map enabling overrides of individual values.&lt;/li&gt;
&lt;li&gt;Set defaults for &lt;code&gt;automountServiceAccountToken&lt;/code&gt; and &lt;code&gt;serviceAccount.automountServiceAccountToken&lt;/code&gt; to &lt;code&gt;true&lt;/code&gt; in Helm chart values.&lt;/li&gt;
&lt;li&gt;Correctly handle &lt;code&gt;txtPrefix&lt;/code&gt; and &lt;code&gt;txtSuffix&lt;/code&gt; arguments when both are provided.&lt;/li&gt;
&lt;li&gt;Add ability to generate schema with &lt;code&gt;helm plugin schema&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Regenerate JSON schema with `helm-values-schema-json&amp;rsquo; plugin.&lt;/li&gt;
&lt;li&gt;Added ability to configure &lt;code&gt;imagePullSecrets&lt;/code&gt; via helm &lt;code&gt;global&lt;/code&gt; value.&lt;/li&gt;
&lt;li&gt;Added options to configure &lt;code&gt;labelFilter&lt;/code&gt; and &lt;code&gt;managedRecordTypes&lt;/code&gt; via dedicated helm values.&lt;/li&gt;
&lt;li&gt;Allow templating &lt;code&gt;serviceaccount.annotations&lt;/code&gt; keys and values, by rendering them using the &lt;code&gt;tpl&lt;/code&gt; built-in function.&lt;/li&gt;
&lt;li&gt;Added support for &lt;code&gt;extraContainers&lt;/code&gt; argument.&lt;/li&gt;
&lt;li&gt;Added support for setting &lt;code&gt;excludeDomains&lt;/code&gt; argument.&lt;/li&gt;
&lt;li&gt;Added support for setting &lt;code&gt;dnsConfig&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Added support for webhook providers.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Restrict managed record types to A and CNAME.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="k8s-audit-metrics-v01010"&gt;k8s-audit-metrics &lt;a href="https://github.com/giantswarm/k8s-audit-metrics/compare/v0.10.10...v0.10.11"&gt;v0.10.10&amp;hellip;v0.10.11&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-10"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Go: Update dependencies.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="network-policies-v011"&gt;network-policies &lt;a href="https://github.com/giantswarm/network-policies-app/compare/v0.1.1...v0.1.3"&gt;v0.1.1&amp;hellip;v0.1.3&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="added-1"&gt;Added&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Add support for Kamaji.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="fixed"&gt;Fixed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed broken templating.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="node-exporter-v1209"&gt;node-exporter &lt;a href="https://github.com/giantswarm/node-exporter-app/compare/v1.20.9...v1.20.10"&gt;v1.20.9&amp;hellip;v1.20.10&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="removed"&gt;Removed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Repository: Remove integration tests.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="observability-bundle-v232"&gt;observability-bundle &lt;a href="https://github.com/giantswarm/observability-bundle/compare/v2.3.2...v2.5.0"&gt;v2.3.2&amp;hellip;v2.5.0&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="added-2"&gt;Added&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Add KSM metrics &lt;code&gt;kube_servicemonitor_info&lt;/code&gt; and &lt;code&gt;kube_podmonitor_info&lt;/code&gt; for ServiceMonitor and PodMonitor resources&lt;/li&gt;
&lt;li&gt;Add KSM metrics &lt;code&gt;kube_podlog_info&lt;/code&gt; for PodLog resource&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="changed-11"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Upgrade &lt;code&gt;kube-prometheus-stack-app&lt;/code&gt; to 19.0.0&lt;/li&gt;
&lt;li&gt;Update alloy-app to 0.16.0
&lt;ul&gt;
&lt;li&gt;Bumps alloy to 1.12.0&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="fixed-1"&gt;Fixed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed KSM metrics for endpoints&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="priority-classes-v030"&gt;priority-classes &lt;a href="https://github.com/giantswarm/priority-classes/releases/tag/v0.3.0"&gt;v0.3.0&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-12"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Label now uses chart version instead of app version.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="removed-1"&gt;Removed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Removed appVersion (only version is used now).&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="security-bundle-v1150"&gt;security-bundle &lt;a href="https://github.com/giantswarm/security-bundle/compare/v1.15.0...v1.16.1"&gt;v1.15.0&amp;hellip;v1.16.1&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-13"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Add missing dependency to all apps.&lt;/li&gt;
&lt;li&gt;Allow to set multiple dependencies on the depends-on annotation.&lt;/li&gt;
&lt;li&gt;Rename &lt;code&gt;edgedb&lt;/code&gt; to &lt;code&gt;gel&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;cloudnative-pg&lt;/code&gt; (app) to v0.0.12.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;gel&lt;/code&gt; (app) to v1.0.1.&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Workload cluster release azure-33.1.1 for CAPZ</title><link>https://docs.giantswarm.io/changes/capz-releases/releases/azure-33.1.1/</link><pubDate>Tue, 16 Dec 2025 15:16:14 +0000</pubDate><guid>https://docs.giantswarm.io/changes/capz-releases/releases/azure-33.1.1/</guid><description>&lt;p&gt;This patch release fixes an issue with the installation of the Teleport Kube Agent app.&lt;/p&gt;
&lt;h2 id="changes-compared-to-v3310"&gt;Changes compared to v33.1.0&lt;/h2&gt;
&lt;h3 id="apps"&gt;Apps&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;coredns from v1.28.2 to v1.28.3&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="coredns-v1282"&gt;coredns &lt;a href="https://github.com/giantswarm/coredns-app/compare/v1.28.2...v1.28.3"&gt;v1.28.2&amp;hellip;v1.28.3&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Update &lt;code&gt;coredns&lt;/code&gt; image to &lt;a href="https://github.com/coredns/coredns/releases/tag/v1.13.2"&gt;1.13.2&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Workload cluster release azure-32.1.0 for CAPZ</title><link>https://docs.giantswarm.io/changes/capz-releases/releases/azure-32.1.0/</link><pubDate>Sun, 02 Nov 2025 09:58:24 +0000</pubDate><guid>https://docs.giantswarm.io/changes/capz-releases/releases/azure-32.1.0/</guid><description>&lt;p&gt;This release updates Flatcar to v4230.2.4 and includes several app updates and improvements.&lt;/p&gt;
&lt;h2 id="changes-compared-to-v3200"&gt;Changes compared to v32.0.0&lt;/h2&gt;
&lt;h3 id="components"&gt;Components&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Flatcar from v4230.2.2 to &lt;a href="https://www.flatcar.org/releases/#release-4230.2.4"&gt;v4230.2.4&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;os-tooling from v1.26.1 to v1.26.2&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="apps"&gt;Apps&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;capi-node-labeler from v1.1.3 to v1.1.5&lt;/li&gt;
&lt;li&gt;cert-exporter from v2.9.9 to v2.9.13&lt;/li&gt;
&lt;li&gt;cert-manager from v3.9.2 to v3.9.4&lt;/li&gt;
&lt;li&gt;cilium from v1.3.0 to v1.3.1&lt;/li&gt;
&lt;li&gt;coredns from v1.27.0 to v1.28.2&lt;/li&gt;
&lt;li&gt;etcd-defrag from v1.0.8 to v1.2.2&lt;/li&gt;
&lt;li&gt;etcd-k8s-res-count-exporter from v1.10.7 to v1.10.10&lt;/li&gt;
&lt;li&gt;k8s-audit-metrics from v0.10.6 to v0.10.9&lt;/li&gt;
&lt;li&gt;node-exporter from v1.20.5 to v1.20.8&lt;/li&gt;
&lt;li&gt;observability-bundle from v2.2.2 to v2.3.2&lt;/li&gt;
&lt;li&gt;security-bundle from v1.12.0 to v1.14.0&lt;/li&gt;
&lt;li&gt;vertical-pod-autoscaler from v6.0.1 to v6.1.1&lt;/li&gt;
&lt;li&gt;vertical-pod-autoscaler-crd from v4.0.1 to v4.1.1&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="capi-node-labeler-v113"&gt;capi-node-labeler &lt;a href="https://github.com/giantswarm/capi-node-labeler-app/compare/v1.1.3...v1.1.5"&gt;v1.1.3&amp;hellip;v1.1.5&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Go: Update dependencies.&lt;/li&gt;
&lt;li&gt;Go: Update dependencies.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cert-exporter-v299"&gt;cert-exporter &lt;a href="https://github.com/giantswarm/cert-exporter/compare/v2.9.9...v2.9.13"&gt;v2.9.9&amp;hellip;v2.9.13&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-1"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Go: Update dependencies.&lt;/li&gt;
&lt;li&gt;Go: Update dependencies.&lt;/li&gt;
&lt;li&gt;Chart: Add value to toggle creation of Daemonset resources.&lt;/li&gt;
&lt;li&gt;Go: Update dependencies.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cert-manager-v392"&gt;cert-manager &lt;a href="https://github.com/giantswarm/cert-manager-app/compare/v3.9.2...v3.9.4"&gt;v3.9.2&amp;hellip;v3.9.4&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="added"&gt;Added&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Add E2E tests using apptest-framework for automated PR testing across multiple providers (CAPA, CAPV, CAPZ, CAPVCD).
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Basic test suite&lt;/strong&gt;: Validates fresh installations&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Upgrade test suite&lt;/strong&gt;: Tests upgrade scenarios and certificate reconciliation&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Add certificate issuance integration test to cluster-test-suites.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="changed-2"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Upgrade cert-manager to v1.18.2.&lt;/li&gt;
&lt;li&gt;Fix missing targetPort in &lt;code&gt;cainjector-service&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="cilium-v130"&gt;cilium &lt;a href="https://github.com/giantswarm/cilium-app/compare/v1.3.0...v1.3.1"&gt;v1.3.0&amp;hellip;v1.3.1&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-3"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Upgrade Cilium to &lt;a href="https://github.com/cilium/cilium/releases/tag/v1.18.2"&gt;v1.18.2&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="coredns-v1270"&gt;coredns &lt;a href="https://github.com/giantswarm/coredns-app/compare/v1.27.0...v1.28.2"&gt;v1.27.0&amp;hellip;v1.28.2&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-4"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Update &lt;code&gt;coredns&lt;/code&gt; image to &lt;a href="https://github.com/coredns/coredns/releases/tag/v1.13.1"&gt;1.13.1&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Add value to toggle creation of controlplane deployment.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;coredns&lt;/code&gt; image to &lt;a href="https://github.com/coredns/coredns/releases/tag/v1.13.0"&gt;1.13.0&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="etcd-defrag-v108"&gt;etcd-defrag &lt;a href="https://github.com/giantswarm/etcd-defrag-app/compare/v1.0.8...v1.2.2"&gt;v1.0.8&amp;hellip;v1.2.2&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-5"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Chart: Update dependency ahrtr/etcd-defrag to v0.35.0. (&lt;a href="https://github.com/giantswarm/etcd-defrag-app/pull/64"&gt;#64&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Chart: Update dependency ahrtr/etcd-defrag to v0.34.0. (&lt;a href="https://github.com/giantswarm/etcd-defrag-app/pull/62"&gt;#62&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Chart: Update dependency ahrtr/etcd-defrag to v0.33.0. (&lt;a href="https://github.com/giantswarm/etcd-defrag-app/pull/60"&gt;#60&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Update Kyverno API to v2 for policy exceptions&lt;/li&gt;
&lt;li&gt;Chart: Update dependency ahrtr/etcd-defrag to v0.32.0. (&lt;a href="https://github.com/giantswarm/etcd-defrag-app/pull/57"&gt;#57&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="etcd-k8s-res-count-exporter-v1107"&gt;etcd-k8s-res-count-exporter &lt;a href="https://github.com/giantswarm/etcd-kubernetes-resources-count-exporter/compare/v1.10.7...v1.10.10"&gt;v1.10.7&amp;hellip;v1.10.10&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-6"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Go: Update dependencies.&lt;/li&gt;
&lt;li&gt;Go: Update dependencies.&lt;/li&gt;
&lt;li&gt;Update Kyverno API to v2 for policy exceptions&lt;/li&gt;
&lt;li&gt;Go: Update dependencies.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="k8s-audit-metrics-v0106"&gt;k8s-audit-metrics &lt;a href="https://github.com/giantswarm/k8s-audit-metrics/compare/v0.10.6...v0.10.9"&gt;v0.10.6&amp;hellip;v0.10.9&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-7"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Go: Update dependencies.&lt;/li&gt;
&lt;li&gt;Go: Update dependencies.&lt;/li&gt;
&lt;li&gt;Update Kyverno API to v2 for policy exceptions&lt;/li&gt;
&lt;li&gt;Go: Update dependencies.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="node-exporter-v1205"&gt;node-exporter &lt;a href="https://github.com/giantswarm/node-exporter-app/compare/v1.20.5...v1.20.8"&gt;v1.20.5&amp;hellip;v1.20.8&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-8"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Go: Update dependencies.&lt;/li&gt;
&lt;li&gt;Go: Update dependencies.&lt;/li&gt;
&lt;li&gt;Update Kyverno API to v2 for policy exceptions&lt;/li&gt;
&lt;li&gt;Go: Update dependencies.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="observability-bundle-v222"&gt;observability-bundle &lt;a href="https://github.com/giantswarm/observability-bundle/compare/v2.2.2...v2.3.2"&gt;v2.2.2&amp;hellip;v2.3.2&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="added-1"&gt;Added&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Add KSM metrics for cloudnative-pg Cluster objects&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="changed-9"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Update alloy-app to 0.15.0
&lt;ul&gt;
&lt;li&gt;Bumps alloy to 1.11.0&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="fixed"&gt;Fixed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Update alloy-app to 0.15.1
&lt;ul&gt;
&lt;li&gt;Bumps alloy to 1.11.2&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="security-bundle-v1120"&gt;security-bundle &lt;a href="https://github.com/giantswarm/security-bundle/compare/v1.12.0...v1.14.0"&gt;v1.12.0&amp;hellip;v1.14.0&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-10"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Update &lt;code&gt;kyverno&lt;/code&gt; (app) to v0.20.1.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;kyverno-crds&lt;/code&gt; (app) to v1.14.0.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;kyverno-policies&lt;/code&gt; (app) to v0.24.0.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;reports-server&lt;/code&gt; (app) to v0.0.3.&lt;/li&gt;
&lt;li&gt;Revert previous &lt;code&gt;kyverno&lt;/code&gt; update (&lt;a href="https://github.com/giantswarm/security-bundle/pull/536"&gt;#536&lt;/a&gt;, &lt;a href="https://github.com/giantswarm/security-bundle/pull/531"&gt;#531&lt;/a&gt;, &lt;a href="https://github.com/giantswarm/security-bundle/pull/538"&gt;#538&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;kyverno-policy-operator&lt;/code&gt; (app) to v0.1.6.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;kyverno&lt;/code&gt; (app) to v0.20.0.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;kyverno-crds&lt;/code&gt; (app) to v1.14.0.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;kyverno-policies&lt;/code&gt; (app) to v0.24.0.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;kyverno-policy-operator&lt;/code&gt; (app) to v0.1.5.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;trivy-operator&lt;/code&gt; (app) to v0.12.1.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;trivy&lt;/code&gt; (app) to v0.14.1.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;falco&lt;/code&gt; (app) to v0.11.0.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="vertical-pod-autoscaler-v601"&gt;vertical-pod-autoscaler &lt;a href="https://github.com/giantswarm/vertical-pod-autoscaler-app/compare/v6.0.1...v6.1.1"&gt;v6.0.1&amp;hellip;v6.1.1&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-11"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Chart: Update Helm release vertical-pod-autoscaler to v11.1.1. (&lt;a href="https://github.com/giantswarm/vertical-pod-autoscaler-app/pull/375"&gt;#375&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Chart: Update Helm release vertical-pod-autoscaler to v11.1.0. (&lt;a href="https://github.com/giantswarm/vertical-pod-autoscaler-app/pull/372"&gt;#372&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="vertical-pod-autoscaler-crd-v401"&gt;vertical-pod-autoscaler-crd &lt;a href="https://github.com/giantswarm/vertical-pod-autoscaler-crd/compare/v4.0.1...v4.1.1"&gt;v4.0.1&amp;hellip;v4.1.1&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed-12"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Chart: Sync to upstream. (&lt;a href="https://github.com/giantswarm/vertical-pod-autoscaler-crd/pull/166"&gt;#166&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Chart: Sync to upstream. (&lt;a href="https://github.com/giantswarm/vertical-pod-autoscaler-crd/pull/164"&gt;#164&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Workload cluster release azure-33.0.1 for CAPZ</title><link>https://docs.giantswarm.io/changes/capz-releases/releases/azure-33.0.1/</link><pubDate>Tue, 21 Oct 2025 13:28:15 +0000</pubDate><guid>https://docs.giantswarm.io/changes/capz-releases/releases/azure-33.0.1/</guid><description>&lt;h2 id="changes-compared-to-v3300"&gt;Changes compared to v33.0.0&lt;/h2&gt;
&lt;h3 id="apps"&gt;Apps&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;security-bundle from v1.12.0 to v1.13.1&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="security-bundle-v1120"&gt;security-bundle &lt;a href="https://github.com/giantswarm/security-bundle/compare/v1.12.0...v1.13.1"&gt;v1.12.0&amp;hellip;v1.13.1&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Revert previous &lt;code&gt;kyverno&lt;/code&gt; update (&lt;a href="https://github.com/giantswarm/security-bundle/pull/536"&gt;#536&lt;/a&gt;, &lt;a href="https://github.com/giantswarm/security-bundle/pull/531"&gt;#531&lt;/a&gt;, &lt;a href="https://github.com/giantswarm/security-bundle/pull/538"&gt;#538&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;kyverno-policy-operator&lt;/code&gt; (app) to v0.1.6.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;kyverno&lt;/code&gt; (app) to v0.20.0.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;kyverno-crds&lt;/code&gt; (app) to v1.14.0.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;kyverno-policies&lt;/code&gt; (app) to v0.24.0.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;kyverno-policy-operator&lt;/code&gt; (app) to v0.1.5.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;trivy-operator&lt;/code&gt; (app) to v0.12.1.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;trivy&lt;/code&gt; (app) to v0.14.1.&lt;/li&gt;
&lt;li&gt;Update &lt;code&gt;falco&lt;/code&gt; (app) to v0.11.0.&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Workload cluster release azure-31.1.2 for CAPZ</title><link>https://docs.giantswarm.io/changes/capz-releases/releases/azure-31.1.2/</link><pubDate>Wed, 10 Sep 2025 12:57:18 +0000</pubDate><guid>https://docs.giantswarm.io/changes/capz-releases/releases/azure-31.1.2/</guid><description>&lt;p&gt;This release fixes a permission issue with the Azure Cloud Controller Manager.&lt;/p&gt;
&lt;h2 id="changes-compared-to-v3111"&gt;Changes compared to v31.1.1&lt;/h2&gt;
&lt;h3 id="apps"&gt;Apps&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;azure-cloud-controller-manager from v1.31.8-gs1 to v1.31.8-gs2&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="azure-cloud-controller-manager-v1318-gs1"&gt;azure-cloud-controller-manager &lt;a href="https://github.com/giantswarm/azure-cloud-controller-manager-app/compare/v1.31.8-gs1...v1.31.8-gs2"&gt;v1.31.8-gs1&amp;hellip;v1.31.8-gs2&lt;/a&gt;&lt;/h3&gt;
&lt;h4 id="changed"&gt;Changed&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Chart: Update RBAC. (&lt;a href="https://github.com/giantswarm/azure-cloud-controller-manager-app/pull/122"&gt;#122&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;</description></item></channel></rss>