Changes and Releases

Updates on Giant Swarm workload cluster releases, apps, UI improvements and documentation changes.

  • Fixed

    • (deps) Update module github.com/giantswarm/mcp-toolkit to v0.2.15 in #510 by @renovate[bot]

    Full Changelog: https://github.com/giantswarm/klaus/compare/v0.1.39...v0.1.40

  • Fixed

    Full Changelog: https://github.com/giantswarm/klausctl/compare/v0.4.17...v0.4.18

  • Fixed

    Full Changelog: https://github.com/giantswarm/klaus/compare/v0.1.38...v0.1.39

  • Fixed

    • (deps) Update module github.com/giantswarm/selfupdate-cosign to v0.3.1 in #507 by @renovate[bot]

    Full Changelog: https://github.com/giantswarm/klaus/compare/v0.1.37...v0.1.38

  • Fixed

    • (test) Read instance_logs until background work has logged in #1339 by @teemow

    Full Changelog: https://github.com/giantswarm/muster/compare/v5.32.1...v5.32.2

  • Changed

    • Publish latest from the tag pipeline, not from main in #511 by @teemow

    Full Changelog: https://github.com/giantswarm/klaus/compare/v0.1.36...v0.1.37

  • Changed

    • Update to Zot v2.1.20.
  • Added

    • (observability) Trace 10% of the data plane’s requests with no trace context in #664 by @QuentinBisson

    Full Changelog: https://github.com/giantswarm/agent-platform/compare/v4.66.8...v4.67.0

  • Changes compared to v35.0.1

    Components

    • cluster-cloud-director from v7.0.0 to v7.3.1
    • cluster from v8.0.0 to v8.3.1

    cluster v8.0.0…v8.3.1

    Added

    • Add the app.kubernetes.io/component label with the app name to the resources rendered per app, so they can be listed together.
    • Add preKubeadmCommandsTemplateName and postKubeadmCommandsTemplateName hooks under providerIntegration.controlPlane.kubeadmConfig and providerIntegration.workers.kubeadmConfig. They name a provider template that renders a YAML list of additional kubeadm commands, once for the control plane and once per node pool for workers.
    • Add internal.advancedConfiguration.kubelet.evictionHard values. Providers need them to tell autoscalers such as Karpenter how much of a node’s resources is allocatable.
    • SELinux: Add global.components.selinux.writablePolicyStore value (default true) to allow loading additional SELinux policies.

    Changed

    • Cilium: Replace the catch-all - operator: Exists toleration on the hubble-relay, hubble-ui and certgen components with an explicit list.
    • Enable the ClusterTrustBundle and ClusterTrustBundleProjection feature gates (Kubernetes 1.33+) and the PodCertificateRequest feature gate (Kubernetes 1.35+) by default on kube-apiserver, kube-controller-manager and kubelet.
    • SELinux: Keep AVC audit logs (required for SELinux policy generation).
    • SELinux: Relabel the whole filesystem except read-only /usr (previously only /etc/kubernetes).
    • SELinux: Correctly label CA certificates in /etc/ssl/certs for mounting into containers.
    • App to HR Migration: Skip v35.0.0 pre-releases and update docker-kubectl to v1.36.4.
    • Chart: Rework HelmRelease clean-up job.
  • Changes compared to v35.0.1

    Components

    • cluster-vsphere from v9.0.0 to v9.3.1
    • cluster from v8.0.0 to v8.3.1

    cluster v8.0.0…v8.3.1

    Added

    • Add the app.kubernetes.io/component label with the app name to the resources rendered per app, so they can be listed together.
    • Add preKubeadmCommandsTemplateName and postKubeadmCommandsTemplateName hooks under providerIntegration.controlPlane.kubeadmConfig and providerIntegration.workers.kubeadmConfig. They name a provider template that renders a YAML list of additional kubeadm commands, once for the control plane and once per node pool for workers.
    • Add internal.advancedConfiguration.kubelet.evictionHard values. Providers need them to tell autoscalers such as Karpenter how much of a node’s resources is allocatable.
    • SELinux: Add global.components.selinux.writablePolicyStore value (default true) to allow loading additional SELinux policies.

    Changed

    • Cilium: Replace the catch-all - operator: Exists toleration on the hubble-relay, hubble-ui and certgen components with an explicit list.
    • Enable the ClusterTrustBundle and ClusterTrustBundleProjection feature gates (Kubernetes 1.33+) and the PodCertificateRequest feature gate (Kubernetes 1.35+) by default on kube-apiserver, kube-controller-manager and kubelet.
    • SELinux: Keep AVC audit logs (required for SELinux policy generation).
    • SELinux: Relabel the whole filesystem except read-only /usr (previously only /etc/kubernetes).
    • SELinux: Correctly label CA certificates in /etc/ssl/certs for mounting into containers.
    • App to HR Migration: Skip v35.0.0 pre-releases and update docker-kubectl to v1.36.4.
    • Chart: Rework HelmRelease clean-up job.