Changed
- Align files according to platform standards in #628 by @giantswarm-align-files[bot]
Full Changelog: https://github.com/giantswarm/starboard-exporter/compare/v1.2.20...v1.2.21
Updates on Giant Swarm workload cluster releases, apps, UI improvements and documentation changes.
Full Changelog: https://github.com/giantswarm/starboard-exporter/compare/v1.2.20...v1.2.21
Full Changelog: https://github.com/giantswarm/agent-platform/compare/v4.69.2...v4.70.0
Full Changelog: https://github.com/giantswarm/agent-platform/compare/v4.69.1...v4.69.2
Full Changelog: https://github.com/giantswarm/muster/compare/v5.32.3...v5.32.4
Full Changelog: https://github.com/giantswarm/muster/compare/v5.32.2...v5.32.3
Full Changelog: https://github.com/giantswarm/backstage/compare/v2.66.0...v2.66.1
Full Changelog: https://github.com/giantswarm/agent-platform/compare/v4.69.0...v4.69.1
0600 ca.crt on an AKS node, where the exporter runs as an unprivileged user) stopped the walk, silently dropping every file sorting after it from the metrics. Unreadable files are now logged and skipped individually.gsoci.azurecr.io/giantswarm/cilium-ztunnel instead of pulling it from upstream. Cilium v1.20 moved this image from docker.io/istio/ztunnel to quay.io/cilium/ztunnel:v1.0.0, and our mirror carries exactly that digest, so it no longer has to be allow-listed in sync/unmirrored-images.txt. Only used by encryption.type=ztunnel, which we do not support.values.schema.json does not reject unknown keys, leftovers in existing values are silently ignored rather than rejected — check your values before upgrading:encryption.strictMode.{enabled,cidr,allowRemoteNodeIdentities} → use encryption.strictMode.egress.*encryption.ipsec.encryptedOverlayclustermesh.enableMCSAPISupport → use clustermesh.mcsapi.enabled (MCS-API is now stable upstream)clustermesh.apiserver.tls.{server,admin,remote}.{cert,key} and clustermesh.apiserver.tls.enableSecrets → enable auto-generation or pre-create the secretshubble.redact.kafka.apiKey → Kafka-aware L7 policy support and proxylib were removed upstreampreflight.tofqdnsPreCache → the preflight FQDN poller was removed upstreamhubble.ui.backend.{livenessProbe,readinessProbe}.enabledsync/patches/certgen/. Cilium v1.20 ships the certgen.enforceCAValidityThroughoutLeavesDuration value and wires --ca-enforce-validity-throughout-leaves-duration into both certgen job specs itself, so the Giant Swarm patch that added them became a no-op (it detected this and skipped). The default stays true and the rendered job specs are unchanged, so two more patches drop out of diffs/.coredns image to 1.14.6..github/release-pr-body.md.configmap.log, loadbalancePolicy and configmap.cache again. Since 1.31.0 coredns.<zone>.log, coredns.<zone>.loadbalance and coredns.<zone>.cache.success.ttl shipped defaults that shadowed them, so the old keys were silently ignored. They are now unset by default, restoring the documented fallback chain. Rendering with default values is unchanged.keywords to Chart.yaml.io.giantswarm.application.audience (all) anddenyEgressToIMDS policy denying pod egress to the instance metadata service. Disabled by default.karpenter and aws-load-balancer-controller namespaces from denyEgressToIMDS.application.giantswarm.io/team key todisableSystemdCollector value to turn the systemd collector off, mirroring the existing disableConntrackCollector and disableNvmeCollector toggles. The collector needs a D-Bus connection to the host, which is refused on nodes where AppArmor mediates D-Bus (such as AKS Ubuntu nodes running under the default containerd profile), making it fail on every scrape. Defaults to false, so behaviour is unchanged.alloy apps to 0.23.1 (Alloy v1.19.2).prometheus-operator-crd to 24.0.0 (Prometheus Operator CRDs v0.94.0).kube-prometheus-stack to 24.0.0 (chart 91.2.3, Prometheus Operator v0.94.0).TCPRoute and UDPRoute collectors to v1, which is the version the API server serves.VulnerabilityReport creation, starboard-exporter metrics for that report, kyverno restricted PSS enforcement, and kyverno-policy-operator PolicyException translation.exception-recommender (app) to v0.3.0.falco (app) to v0.13.0.jiralert (app) to v0.1.4.kubescape (app) to v0.1.1.kyverno-policies (app) to v0.27.1.policy-api (app) to v0.0.12.starboard-exporter (app) to v1.2.15.trivy (app) to v0.18.0.trivy-operator (app) to v0.15.0.gel (app).kubescape a 15m install and upgrade timeout. It does not finish installing within Flux’s 5m default, so it failed with context deadline exceeded and then retried indefinitely.createNamespace on every app in the bundle, so each one creates its target namespace instead of relying on another app to have created it first. Previously kubescape failed with namespaces "kubescape" not found, and the apps targeting security-bundle could only install after kyverno-policy-operator had created it.teleport-kube-agent to upstream version v18.10.7.0600 ca.crt on an AKS node, where the exporter runs as an unprivileged user) stopped the walk, silently dropping every file sorting after it from the metrics. Unreadable files are now logged and skipped individually.gsoci.azurecr.io/giantswarm/cilium-ztunnel instead of pulling it from upstream. Cilium v1.20 moved this image from docker.io/istio/ztunnel to quay.io/cilium/ztunnel:v1.0.0, and our mirror carries exactly that digest, so it no longer has to be allow-listed in sync/unmirrored-images.txt. Only used by encryption.type=ztunnel, which we do not support.values.schema.json does not reject unknown keys, leftovers in existing values are silently ignored rather than rejected — check your values before upgrading:encryption.strictMode.{enabled,cidr,allowRemoteNodeIdentities} → use encryption.strictMode.egress.*encryption.ipsec.encryptedOverlayclustermesh.enableMCSAPISupport → use clustermesh.mcsapi.enabled (MCS-API is now stable upstream)clustermesh.apiserver.tls.{server,admin,remote}.{cert,key} and clustermesh.apiserver.tls.enableSecrets → enable auto-generation or pre-create the secretshubble.redact.kafka.apiKey → Kafka-aware L7 policy support and proxylib were removed upstreampreflight.tofqdnsPreCache → the preflight FQDN poller was removed upstreamhubble.ui.backend.{livenessProbe,readinessProbe}.enabledsync/patches/certgen/. Cilium v1.20 ships the certgen.enforceCAValidityThroughoutLeavesDuration value and wires --ca-enforce-validity-throughout-leaves-duration into both certgen job specs itself, so the Giant Swarm patch that added them became a no-op (it detected this and skipped). The default stays true and the rendered job specs are unchanged, so two more patches drop out of diffs/.coredns image to 1.14.6..github/release-pr-body.md.configmap.log, loadbalancePolicy and configmap.cache again. Since 1.31.0 coredns.<zone>.log, coredns.<zone>.loadbalance and coredns.<zone>.cache.success.ttl shipped defaults that shadowed them, so the old keys were silently ignored. They are now unset by default, restoring the documented fallback chain. Rendering with default values is unchanged.keywords to Chart.yaml.io.giantswarm.application.audience (all) anddenyEgressToIMDS policy denying pod egress to the instance metadata service. Disabled by default.karpenter and aws-load-balancer-controller namespaces from denyEgressToIMDS.application.giantswarm.io/team key todisableSystemdCollector value to turn the systemd collector off, mirroring the existing disableConntrackCollector and disableNvmeCollector toggles. The collector needs a D-Bus connection to the host, which is refused on nodes where AppArmor mediates D-Bus (such as AKS Ubuntu nodes running under the default containerd profile), making it fail on every scrape. Defaults to false, so behaviour is unchanged.alloy apps to 0.23.1 (Alloy v1.19.2).prometheus-operator-crd to 24.0.0 (Prometheus Operator CRDs v0.94.0).kube-prometheus-stack to 24.0.0 (chart 91.2.3, Prometheus Operator v0.94.0).TCPRoute and UDPRoute collectors to v1, which is the version the API server serves.VulnerabilityReport creation, starboard-exporter metrics for that report, kyverno restricted PSS enforcement, and kyverno-policy-operator PolicyException translation.exception-recommender (app) to v0.3.0.falco (app) to v0.13.0.jiralert (app) to v0.1.4.kubescape (app) to v0.1.1.kyverno-policies (app) to v0.27.1.policy-api (app) to v0.0.12.starboard-exporter (app) to v1.2.15.trivy (app) to v0.18.0.trivy-operator (app) to v0.15.0.gel (app).kubescape a 15m install and upgrade timeout. It does not finish installing within Flux’s 5m default, so it failed with context deadline exceeded and then retried indefinitely.createNamespace on every app in the bundle, so each one creates its target namespace instead of relying on another app to have created it first. Previously kubescape failed with namespaces "kubescape" not found, and the apps targeting security-bundle could only install after kyverno-policy-operator had created it.teleport-kube-agent to upstream version v18.10.7.Full Changelog: https://github.com/giantswarm/agent-platform/compare/v4.68.2...v4.69.0