Workload cluster release azure-36.1.0 for CAPZ
Changes compared to v35.2.0
Components
- cluster-azure from v9.4.1 to v10.1.0
- cluster from v8.4.2 to v9.0.2
- Kubernetes from v1.35.9 to v1.36.5
Added
- Promote Bring-Your-Own-Network to a dedicated network mode by setting
global.connectivity.network.mode to byo.
Changed
- Fix templating of user-specific private endpoints.
- Fix capitalization of
natIPConfigurations key in AzureCluster template.
Changed
kubeadm: Exclude /etc/.systemd-confext from restorecon.- Cilium: Replace the catch-all
- operator: Exists toleration on cilium-operator with an explicit list.
Removed
- Chart: Remove App to HelmRelease migration.
Apps
- azure-cloud-controller-manager from v2.1.0 to v2.2.0
- azure-cloud-node-manager from v2.1.0 to v2.2.0
- cilium from v1.5.2 to v1.6.1
- cluster-autoscaler from v2.0.4 to v2.1.0
Changed
- Chart: Update to upstream v1.36.5.
Changed
- Chart: Update to upstream v1.36.5.
Added
- Declare the
io.giantswarm.application.audience (all) and
Changed
- Upgrade Cilium to v1.20.2.
- Move the team annotation from the legacy
application.giantswarm.io/team key to - Point
home at this repository instead of https://cilium.io/, as the standard requires. - Upgrade Cilium to v1.20.1 from v1.19.7. Please review the upstream 1.20 upgrade notes before rolling this out.
- Serve the ztunnel image from
gsoci.azurecr.io/giantswarm/cilium-ztunnel instead of pulling it from upstream. Cilium v1.20 moved this image from docker.io/istio/ztunnel to quay.io/cilium/ztunnel:v1.0.0, and our mirror carries exactly that digest, so it no longer has to be allow-listed in sync/unmirrored-images.txt. Only used by encryption.type=ztunnel, which we do not support.
Removed
- Upstream removed these long-deprecated Helm values in v1.20. None of them are set by this chart’s defaults, and because the chart’s
values.schema.json does not reject unknown keys, leftovers in existing values are silently ignored rather than rejected — check your values before upgrading:encryption.strictMode.{enabled,cidr,allowRemoteNodeIdentities} → use encryption.strictMode.egress.*encryption.ipsec.encryptedOverlayclustermesh.enableMCSAPISupport → use clustermesh.mcsapi.enabled (MCS-API is now stable upstream)clustermesh.apiserver.tls.{server,admin,remote}.{cert,key} and clustermesh.apiserver.tls.enableSecrets → enable auto-generation or pre-create the secretshubble.redact.kafka.apiKey → Kafka-aware L7 policy support and proxylib were removed upstreampreflight.tofqdnsPreCache → the preflight FQDN poller was removed upstreamhubble.ui.backend.{livenessProbe,readinessProbe}.enabled
sync/patches/certgen/. Cilium v1.20 ships the certgen.enforceCAValidityThroughoutLeavesDuration value and wires --ca-enforce-validity-throughout-leaves-duration into both certgen job specs itself, so the Giant Swarm patch that added them became a no-op (it detected this and skipped). The default stays true and the rendered job specs are unchanged, so two more patches drop out of diffs/.
Changed
- Chart: Update to upstream v1.36.1.