Changes and Releases

Updates on Giant Swarm workload cluster releases, apps, UI improvements and documentation changes.

  • Added

    • Add PodLogs for log collection.

    Changed

    • Update chart-operator PolicyException to v2.
  • Fixed

    • Add missing loki to mimir alertmanager CNP
  • Changed

    • Upgrade Tempo chart from 1.48.1 to 1.51.1
      • Upgrade Tempo from 2.8.2 to 2.9.0
    • Upgrade Tempo Vulture from 0.9.1 to 0.10.0
  • Changed

    • upgrade grafana chart: 10.1.0 => 10.1.2
    • upgrade pg-cluster-recovery-test subchart: v0.2.3 => v0.2.4
  • This release improves the stability of Karpenter node pools.

    Changes compared to v33.0.0

    Components

    • cluster-aws from v6.0.0 to v6.2.0

    cluster-aws v6.0.0…v6.2.0

    Added

    • Add capa-karpenter-taint-remover to handle CAPA - Karpenter taint race condition.

    Changed

    • Change default consolidation time to 6 hours to avoid constant node rolling.
    • Rename capa-karpenter-taint-remover app.
    • Set terminationGracePeriod default to 30m, to avoid having karpenter nodes stuck in Deleting state due to Pods blocking the deletion i.e. PDBs.

    Apps

    • aws-pod-identity-webhook from v1.19.1 to v2.0.0
    • karpenter from v1.3.0 to v1.4.0
    • Added karpenter-taint-remover v1.0.1
    • security-bundle from v1.12.0 to v1.13.1

    aws-pod-identity-webhook v1.19.1…v2.0.0

    Changed

    • Upgrade IRSA to latest v0.6.9

    karpenter v1.3.0…v1.4.0

    Changed

    • Updated karpenter to 1.8.1
    • Fixes RBAC issues when OwnerReferencesPermissionEnforcement featuregate is enabled by allowing finalizers sub’resource modification.

    karpenter-taint-remover v1.0.1

    Changed

    • Use default catalog

    security-bundle v1.12.0…v1.13.1

    Changed

    • Revert previous kyverno update (#536, #531, #538).
    • Update kyverno-policy-operator (app) to v0.1.6.
    • Update kyverno (app) to v0.20.0.
    • Update kyverno-crds (app) to v1.14.0.
    • Update kyverno-policies (app) to v0.24.0.
    • Update kyverno-policy-operator (app) to v0.1.5.
    • Update trivy-operator (app) to v0.12.1.
    • Update trivy (app) to v0.14.1.
    • Update falco (app) to v0.11.0.
  • Changed

    • Updated RBAC rules to include organizations/finalizers for managing .metadata.ownerReferences.blockOwnerDeletion.
    • Disable PodSecurityPolicies by deafult.
  • Changes compared to v33.0.0

    Apps

    • security-bundle from v1.12.0 to v1.13.1

    security-bundle v1.12.0…v1.13.1

    Changed

    • Revert previous kyverno update (#536, #531, #538).
    • Update kyverno-policy-operator (app) to v0.1.6.
    • Update kyverno (app) to v0.20.0.
    • Update kyverno-crds (app) to v1.14.0.
    • Update kyverno-policies (app) to v0.24.0.
    • Update kyverno-policy-operator (app) to v0.1.5.
    • Update trivy-operator (app) to v0.12.1.
    • Update trivy (app) to v0.14.1.
    • Update falco (app) to v0.11.0.
  • Changes compared to v33.0.0

    Apps

    • security-bundle from v1.12.0 to v1.13.1

    security-bundle v1.12.0…v1.13.1

    Changed

    • Revert previous kyverno update (#536, #531, #538).
    • Update kyverno-policy-operator (app) to v0.1.6.
    • Update kyverno (app) to v0.20.0.
    • Update kyverno-crds (app) to v1.14.0.
    • Update kyverno-policies (app) to v0.24.0.
    • Update kyverno-policy-operator (app) to v0.1.5.
    • Update trivy-operator (app) to v0.12.1.
    • Update trivy (app) to v0.14.1.
    • Update falco (app) to v0.11.0.
  • Changes compared to v33.0.0

    Apps

    • security-bundle from v1.12.0 to v1.13.1

    security-bundle v1.12.0…v1.13.1

    Changed

    • Revert previous kyverno update (#536, #531, #538).
    • Update kyverno-policy-operator (app) to v0.1.6.
    • Update kyverno (app) to v0.20.0.
    • Update kyverno-crds (app) to v1.14.0.
    • Update kyverno-policies (app) to v0.24.0.
    • Update kyverno-policy-operator (app) to v0.1.5.
    • Update trivy-operator (app) to v0.12.1.
    • Update trivy (app) to v0.14.1.
    • Update falco (app) to v0.11.0.