Workload cluster release azure-36.1.0 for CAPZ

Changes compared to v35.2.0

Components

  • cluster-azure from v9.4.1 to v10.1.0
  • cluster from v8.4.2 to v9.0.2
  • Kubernetes from v1.35.9 to v1.36.5

cluster-azure v9.4.1…v10.1.0

Added

  • Promote Bring-Your-Own-Network to a dedicated network mode by setting global.connectivity.network.mode to byo.

Changed

  • Fix templating of user-specific private endpoints.
  • Fix capitalization of natIPConfigurations key in AzureCluster template.

cluster v8.4.2…v9.0.2

Changed

  • kubeadm: Exclude /etc/.systemd-confext from restorecon.
  • Cilium: Replace the catch-all - operator: Exists toleration on cilium-operator with an explicit list.

Removed

  • Chart: Remove App to HelmRelease migration.

Apps

  • azure-cloud-controller-manager from v2.1.0 to v2.2.0
  • azure-cloud-node-manager from v2.1.0 to v2.2.0
  • cilium from v1.5.2 to v1.6.1
  • cluster-autoscaler from v2.0.4 to v2.1.0

azure-cloud-controller-manager v2.1.0…v2.2.0

Changed

  • Chart: Update to upstream v1.36.5.

azure-cloud-node-manager v2.1.0…v2.2.0

Changed

  • Chart: Update to upstream v1.36.5.

cilium v1.5.2…v1.6.1

Added

  • Declare the io.giantswarm.application.audience (all) and

Changed

  • Upgrade Cilium to v1.20.2.
  • Move the team annotation from the legacy application.giantswarm.io/team key to
  • Point home at this repository instead of https://cilium.io/, as the standard requires.
  • Upgrade Cilium to v1.20.1 from v1.19.7. Please review the upstream 1.20 upgrade notes before rolling this out.
  • Serve the ztunnel image from gsoci.azurecr.io/giantswarm/cilium-ztunnel instead of pulling it from upstream. Cilium v1.20 moved this image from docker.io/istio/ztunnel to quay.io/cilium/ztunnel:v1.0.0, and our mirror carries exactly that digest, so it no longer has to be allow-listed in sync/unmirrored-images.txt. Only used by encryption.type=ztunnel, which we do not support.

Removed

  • Upstream removed these long-deprecated Helm values in v1.20. None of them are set by this chart’s defaults, and because the chart’s values.schema.json does not reject unknown keys, leftovers in existing values are silently ignored rather than rejected — check your values before upgrading:
    • encryption.strictMode.{enabled,cidr,allowRemoteNodeIdentities} → use encryption.strictMode.egress.*
    • encryption.ipsec.encryptedOverlay
    • clustermesh.enableMCSAPISupport → use clustermesh.mcsapi.enabled (MCS-API is now stable upstream)
    • clustermesh.apiserver.tls.{server,admin,remote}.{cert,key} and clustermesh.apiserver.tls.enableSecrets → enable auto-generation or pre-create the secrets
    • hubble.redact.kafka.apiKey → Kafka-aware L7 policy support and proxylib were removed upstream
    • preflight.tofqdnsPreCache → the preflight FQDN poller was removed upstream
    • hubble.ui.backend.{livenessProbe,readinessProbe}.enabled
  • sync/patches/certgen/. Cilium v1.20 ships the certgen.enforceCAValidityThroughoutLeavesDuration value and wires --ca-enforce-validity-throughout-leaves-duration into both certgen job specs itself, so the Giant Swarm patch that added them became a no-op (it detected this and skipped). The default stays true and the rendered job specs are unchanged, so two more patches drop out of diffs/.

cluster-autoscaler v2.0.4…v2.1.0

Changed

  • Chart: Update to upstream v1.36.1.