Fleet Management

  • Fixed

    • Fix applying RoleBindingTemplate to multiple namespaces
  • Changed

    WARNING: this version requires Cilium to run because of the dependency on the CiliumNetworkPolicy CRD

    • Upgrade dependency chart to 9.2.0.
    • Adjusted the resource and limits to accomodate larger clusters by default
    • Adjusted the admission controller to give it more QPS against the API
    • Adjusted the updater to give it more QPS against the API
    • Adjusted the recommender to give it
      • more QPS against the API
      • doubling the memory in case of an OOMKilled event
      • Using the 95% percentile for the calculation of the CPU usage: should allow to scale up more precisely to account for spikes in CPU consumption of the workload
      • Adjusted the resource and limits to accomodate larger clusters by default
      • Calculating recommendations only for workloads which do have a VPA custom resource, instead of all workloads
      • Removed standard network policies to decrease maintenance burden
      • Fixed Cilium Network Policy to allow CRD jobs execution
      • Added Cilium Network Policy weight for an early execution
      • Disabled VPA for the updater pod otherwise it keeps on getting re-scheduled because the memory consumption varies a lot between reconsiling resources and idle
      • Disabled VPA for the recommender pod otherwise it keeps on getting re-scheduled because the memory consumption varies a lot between reconsiling resources and idle
  • Added

    • Add cr example
    • Add namespace check to rolebindingtemplate controller
  • Changed

    • Move flux auth out of org/cluster namespace controllers and reconcile it via RoleBindingTemplates instead.
  • Changed

    • Don’t change pod CIDR during upgrade from v18 to v19 if eni ipam mode is enabled.
  • Removed

    • Remove write-clusters and write-nodepools cluster roles as it is unused.
  • Added

    • Add RoleBindingTemplate controller and api
  • Added

    • Adding opsctl login support for EKS clusters.
  • Added

    • Add --login-timeout flag to control the time period of OIDC login timeout
    • Add experimental support for templating cluster-eks with provider eks.

    Changed

    • Graceful failure of the login command in case workload cluster API is not known
    • Improved error message after login timeout
    • Adjusted description of the --cluster-admin flag in the login command
    • Specified failureThreshold and periodSeconds for recommender’s liveness probe.
    • Upgrade dependency chart to 7.1.0.
    • Upgrade VPA components to 0.14.0

This part of our documentation refers to our vintage product. The content may be not valid anymore for our current product. Please check our new documentation hub for the latest state of our docs.