Changed
Full Changelog: https://github.com/giantswarm/muster/compare/v5.23.1...v5.23.2
Updates on Giant Swarm workload cluster releases, apps, UI improvements and documentation changes.
Full Changelog: https://github.com/giantswarm/muster/compare/v5.23.1...v5.23.2
muster list tool --server <name> find the tools of an aggregated server in #1251 by @teemowFull Changelog: https://github.com/giantswarm/muster/compare/v5.23.0...v5.23.1
Full Changelog: https://github.com/giantswarm/agent-platform/compare/v4.20.1...v4.21.0
Full Changelog: https://github.com/giantswarm/muster/compare/v5.22.1...v5.23.0
Full Changelog: https://github.com/giantswarm/muster/compare/v5.22.0...v5.22.1
Full Changelog: https://github.com/giantswarm/agent-platform/compare/v4.20.0...v4.20.1
88.6.3, via 90.0.0)prometheus-operator (and prometheus-config-reloader) from v0.93.1 to v0.94.0grafana subchart from 12.11.2 to 13.2.4, which switches the Grafana image from 13.2.0 to 13.2.1-distroless, enables readOnlyRootFilesystem on the Grafana container (with a new /tmp emptyDir) and sets plugins.preinstall_auto_update = falsek8s-sidecar (Grafana dashboard/datasource sidecar) from 2.10.1 to 2.11.2kube-state-metrics subchart from 8.4.1 to 8.4.2 (KSM image unchanged at v2.20.0)prometheus-node-exporter subchart from 4.56.3 to 4.57.0 (we keep nodeExporter.enabled: false, no impact)kube-webhook-certgen images are unchanged.bearerTokenFile/tlsConfig.caFile. They now authenticate through a kubernetes.io/service-account-token Secret (<release>-prometheus-token, newly created by the chart) and read the CA from the kube-root-ca.crt ConfigMap. This makes the ServiceMonitors work with arbitraryFSAccessThroughSMs.deny and with Grafana Alloy’s prometheus.operator.servicemonitors component (>= v1.19.0), which silently dropped every control-plane target before.*) verbs. Verbs are now explicit per resource group, and the operator only gets get/list/watch on the monitoring.coreos.com CRs plus writes on their /status and /finalizers subresources.prometheusOperator.admissionWebhooks.matchConditions changed type from a map ({}) to a list ([]). We do not set it, so no impact.appVersion, which was still v0.92.0, to match the bundled Prometheus Operator (v0.94.0).global.controlPlaneScrapeAuth to configure the Secret the control-plane ServiceMonitors authenticate with.coreDns, kubeEtcd and kubeProxy.insecureSkipVerify from the kubeControllerManager and kubeScheduler ServiceMonitors.Note: release the matching
prometheus-operator-crdapp (CRDs chart32.0.0, Prometheus Operatorv0.94.0) before this one. The CRDs shipped by this chart live incharts/crds/crds/and are therefore only applied by Helm on install, never on upgrade.
88.6.3, via 90.0.0)prometheus-operator (and prometheus-config-reloader) from v0.93.1 to v0.94.0grafana subchart from 12.11.2 to 13.2.4, which switches the Grafana image from 13.2.0 to 13.2.1-distroless, enables readOnlyRootFilesystem on the Grafana container (with a new /tmp emptyDir) and sets plugins.preinstall_auto_update = falsek8s-sidecar (Grafana dashboard/datasource sidecar) from 2.10.1 to 2.11.2kube-state-metrics subchart from 8.4.1 to 8.4.2 (KSM image unchanged at v2.20.0)prometheus-node-exporter subchart from 4.56.3 to 4.57.0 (we keep nodeExporter.enabled: false, no impact)kube-webhook-certgen images are unchanged.bearerTokenFile/tlsConfig.caFile. They now authenticate through a kubernetes.io/service-account-token Secret (<release>-prometheus-token, newly created by the chart) and read the CA from the kube-root-ca.crt ConfigMap. This makes the ServiceMonitors work with arbitraryFSAccessThroughSMs.deny and with Grafana Alloy’s prometheus.operator.servicemonitors component (>= v1.19.0), which silently dropped every control-plane target before.*) verbs. Verbs are now explicit per resource group, and the operator only gets get/list/watch on the monitoring.coreos.com CRs plus writes on their /status and /finalizers subresources.prometheusOperator.admissionWebhooks.matchConditions changed type from a map ({}) to a list ([]). We do not set it, so no impact.appVersion, which was still v0.92.0, to match the bundled Prometheus Operator (v0.94.0).global.controlPlaneScrapeAuth to configure the Secret the control-plane ServiceMonitors authenticate with.coreDns, kubeEtcd and kubeProxy.insecureSkipVerify from the kubeControllerManager and kubeScheduler ServiceMonitors.Note: release the matching
prometheus-operator-crdapp (CRDs chart32.0.0, Prometheus Operatorv0.94.0) before this one. The CRDs shipped by this chart live incharts/crds/crds/and are therefore only applied by Helm on install, never on upgrade.
global.providerSpecific.iam.ecr.permissionsEnabled (default true) so clusters that never pull container images from Amazon ECR can optionally configure dropping the read-only ECR permissions from the control plane and worker node IAM rolesevictionHard values from cluster chart to ensure correct calculation of allocatable node resources.preKubeadmCommandsTemplateName and postKubeadmCommandsTemplateName hooks under providerIntegration.controlPlane.kubeadmConfig and providerIntegration.workers.kubeadmConfig. They name a provider template that renders a YAML list of additional kubeadm commands, once for the control plane and once per node pool for workers.internal.advancedConfiguration.kubelet.evictionHard values. Providers need them to tell autoscalers such as Karpenter how much of a node’s resources is allocatable.global.components.selinux.writablePolicyStore value (default true) to allow loading additional SELinux policies.ClusterTrustBundle and ClusterTrustBundleProjection feature gates (Kubernetes 1.33+) and the PodCertificateRequest feature gate (Kubernetes 1.35+) by default on kube-apiserver, kube-controller-manager and kubelet./usr (previously only /etc/kubernetes)./etc/ssl/certs for mounting into containers.docker-kubectl to v1.36.4.serviceAccountTokenSecret.enabled to render a long-lived service account token Secret.