Changes and Releases

Updates on Giant Swarm workload cluster releases, apps, UI improvements and documentation changes.

  • Changed

    • Notify the Homebrew tap after the release binaries are uploaded in #1254 by @teemow

    Full Changelog: https://github.com/giantswarm/muster/compare/v5.23.1...v5.23.2

  • Fixed

    • (cli) Make muster list tool --server <name> find the tools of an aggregated server in #1251 by @teemow

    Full Changelog: https://github.com/giantswarm/muster/compare/v5.23.0...v5.23.1

  • Added

    • (substrate) The Substrate line moves to v0.0.30-gs.2 — the worker pool can be spread over nodes and zones (giantswarm/agent-platform#472) in #475 by @teemow

    Full Changelog: https://github.com/giantswarm/agent-platform/compare/v4.20.1...v4.21.0

  • Added

    • (test) Authorization-server profiles for the mock OAuth server (profile: github | dex | pro) (#1239) in #1253 by @teemow

    Full Changelog: https://github.com/giantswarm/muster/compare/v5.22.1...v5.23.0

  • Fixed

    • (cli) Keep the CLI’s own flags out of workflow and tool arguments in #1250 by @teemow

    Full Changelog: https://github.com/giantswarm/muster/compare/v5.22.0...v5.22.1

  • Changed

    • (deps) Update gsoci.azurecr.io/giantswarm/agent-manager docker tag to v1.1.7 in #474 by @renovate[bot]

    Full Changelog: https://github.com/giantswarm/agent-platform/compare/v4.20.0...v4.20.1

  • Changed

    • Upgraded chart dependency to kube-prometheus-stack-91.2.3 (from 88.6.3, via 90.0.0)
      • prometheus-operator (and prometheus-config-reloader) from v0.93.1 to v0.94.0
      • grafana subchart from 12.11.2 to 13.2.4, which switches the Grafana image from 13.2.0 to 13.2.1-distroless, enables readOnlyRootFilesystem on the Grafana container (with a new /tmp emptyDir) and sets plugins.preinstall_auto_update = false
      • k8s-sidecar (Grafana dashboard/datasource sidecar) from 2.10.1 to 2.11.2
      • kube-state-metrics subchart from 8.4.1 to 8.4.2 (KSM image unchanged at v2.20.0)
      • prometheus-node-exporter subchart from 4.56.3 to 4.57.0 (we keep nodeExporter.enabled: false, no impact)
      • Alertmanager, Prometheus, Thanos and kube-webhook-certgen images are unchanged.
    • Breaking (chart 90.0.0): the control-plane ServiceMonitors (kubelet, kube-apiserver, kube-controller-manager, kube-scheduler, kube-etcd, kube-proxy, coredns) no longer use bearerTokenFile/tlsConfig.caFile. They now authenticate through a kubernetes.io/service-account-token Secret (<release>-prometheus-token, newly created by the chart) and read the CA from the kube-root-ca.crt ConfigMap. This makes the ServiceMonitors work with arbitraryFSAccessThroughSMs.deny and with Grafana Alloy’s prometheus.operator.servicemonitors component (>= v1.19.0), which silently dropped every control-plane target before.
    • Breaking (chart 91.0.0 / operator v0.94.0): the Prometheus Operator ClusterRole no longer grants wildcard (*) verbs. Verbs are now explicit per resource group, and the operator only gets get/list/watch on the monitoring.coreos.com CRs plus writes on their /status and /finalizers subresources.
    • prometheusOperator.admissionWebhooks.matchConditions changed type from a map ({}) to a list ([]). We do not set it, so no impact.
    • Fixed the chart appVersion, which was still v0.92.0, to match the bundled Prometheus Operator (v0.94.0).
    • Added global.controlPlaneScrapeAuth to configure the Secret the control-plane ServiceMonitors authenticate with.
    • Dropped the scrape credential for coreDns, kubeEtcd and kubeProxy.
    • Removed insecureSkipVerify from the kubeControllerManager and kubeScheduler ServiceMonitors.

    Note: release the matching prometheus-operator-crd app (CRDs chart 32.0.0, Prometheus Operator v0.94.0) before this one. The CRDs shipped by this chart live in charts/crds/crds/ and are therefore only applied by Helm on install, never on upgrade.

  • Changed

    • Upgraded chart dependency to kube-prometheus-stack-91.2.3 (from 88.6.3, via 90.0.0)
      • prometheus-operator (and prometheus-config-reloader) from v0.93.1 to v0.94.0
      • grafana subchart from 12.11.2 to 13.2.4, which switches the Grafana image from 13.2.0 to 13.2.1-distroless, enables readOnlyRootFilesystem on the Grafana container (with a new /tmp emptyDir) and sets plugins.preinstall_auto_update = false
      • k8s-sidecar (Grafana dashboard/datasource sidecar) from 2.10.1 to 2.11.2
      • kube-state-metrics subchart from 8.4.1 to 8.4.2 (KSM image unchanged at v2.20.0)
      • prometheus-node-exporter subchart from 4.56.3 to 4.57.0 (we keep nodeExporter.enabled: false, no impact)
      • Alertmanager, Prometheus, Thanos and kube-webhook-certgen images are unchanged.
    • Breaking (chart 90.0.0): the control-plane ServiceMonitors (kubelet, kube-apiserver, kube-controller-manager, kube-scheduler, kube-etcd, kube-proxy, coredns) no longer use bearerTokenFile/tlsConfig.caFile. They now authenticate through a kubernetes.io/service-account-token Secret (<release>-prometheus-token, newly created by the chart) and read the CA from the kube-root-ca.crt ConfigMap. This makes the ServiceMonitors work with arbitraryFSAccessThroughSMs.deny and with Grafana Alloy’s prometheus.operator.servicemonitors component (>= v1.19.0), which silently dropped every control-plane target before.
    • Breaking (chart 91.0.0 / operator v0.94.0): the Prometheus Operator ClusterRole no longer grants wildcard (*) verbs. Verbs are now explicit per resource group, and the operator only gets get/list/watch on the monitoring.coreos.com CRs plus writes on their /status and /finalizers subresources.
    • prometheusOperator.admissionWebhooks.matchConditions changed type from a map ({}) to a list ([]). We do not set it, so no impact.
    • Fixed the chart appVersion, which was still v0.92.0, to match the bundled Prometheus Operator (v0.94.0).
    • Added global.controlPlaneScrapeAuth to configure the Secret the control-plane ServiceMonitors authenticate with.
    • Dropped the scrape credential for coreDns, kubeEtcd and kubeProxy.
    • Removed insecureSkipVerify from the kubeControllerManager and kubeScheduler ServiceMonitors.

    Note: release the matching prometheus-operator-crd app (CRDs chart 32.0.0, Prometheus Operator v0.94.0) before this one. The CRDs shipped by this chart live in charts/crds/crds/ and are therefore only applied by Helm on install, never on upgrade.

  • Changes compared to v35.0.1

    Components

    • cluster-aws from v10.0.1 to v10.3.0
    • cluster from v8.0.0 to v8.3.0

    cluster-aws v10.0.1…v10.3.0

    Added

    • Add global.providerSpecific.iam.ecr.permissionsEnabled (default true) so clusters that never pull container images from Amazon ECR can optionally configure dropping the read-only ECR permissions from the control plane and worker node IAM roles

    Changed

    • Karpenter node pools: take overridden kubelet evictionHard values from cluster chart to ensure correct calculation of allocatable node resources.

    cluster v8.0.0…v8.3.0

    Added

    • Add preKubeadmCommandsTemplateName and postKubeadmCommandsTemplateName hooks under providerIntegration.controlPlane.kubeadmConfig and providerIntegration.workers.kubeadmConfig. They name a provider template that renders a YAML list of additional kubeadm commands, once for the control plane and once per node pool for workers.
    • Add internal.advancedConfiguration.kubelet.evictionHard values. Providers need them to tell autoscalers such as Karpenter how much of a node’s resources is allocatable.
    • SELinux: Add global.components.selinux.writablePolicyStore value (default true) to allow loading additional SELinux policies.

    Changed

    • Enable the ClusterTrustBundle and ClusterTrustBundleProjection feature gates (Kubernetes 1.33+) and the PodCertificateRequest feature gate (Kubernetes 1.35+) by default on kube-apiserver, kube-controller-manager and kubelet.
    • SELinux: Keep AVC audit logs (required for SELinux policy generation).
    • SELinux: Relabel the whole filesystem except read-only /usr (previously only /etc/kubernetes).
    • SELinux: Correctly label CA certificates in /etc/ssl/certs for mounting into containers.
    • App to HR Migration: Skip v35.0.0 pre-releases and update docker-kubectl to v1.36.4.
    • Chart: Rework HelmRelease clean-up job.
  • Added

    • Optional serviceAccountTokenSecret.enabled to render a long-lived service account token Secret.