Releases: gardener-community/gardener-charts
Releases · gardener-community/gardener-charts
shoot-rsyslog-relp-0.5.1
[gardener/gardener-extension-shoot-rsyslog-relp]
🏃 Others
[OPERATOR]
The memory of thersyslog.service
systemd unit is now limited via a drop-in config. The following configurations are used:MemoryMin=15M
,MemoryHigh=150M
,MemoryMax=300M
,MemorySwapMax=0
by @plkokanov [#139]
Docker Images
- gardener-extension-shoot-rsyslog-relp-admission:
europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/shoot-rsyslog-relp-admission:v0.5.1
- gardener-extension-shoot-rsyslog-relp:
europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/shoot-rsyslog-relp:v0.5.1
shoot-rsyslog-relp-0.5.0
[gardener/gardener-extension-shoot-rsyslog-relp]
⚠️ Breaking Changes
[USER]
When changing referenced TLS secret inshoot.spec.resources[]
the user should provide only immutable secret by @Kostov6 [#76]
🐛 Bug Fixes
[OPERATOR]
Fixed an issue that caused audit logs to be duplicated in journald if thesystem-journald-audit
socket was enabled. Now if thesystem-journald-audit
socket exists on the node, it is disabled and stopped when this extension is used. by @plkokanov [#104][USER]
Rsyslog processes logs on nodes with os suse-chost 15 SP3 by @Kostov6 [#123]
🏃 Others
[OPERATOR]
Errors that can occur when loading audit rules are now ignored and reported as warnings. This allows all correct audit rules to be loaded. by @plkokanov [#128][OPERATOR]
Thersyslog-relp
action which is used to forward logs to a RELP server now uses a separate in-memory queue of 100000 messages. Additionally, it also uses a disk queue of max 48 MiB which is used to store messages after the in-memory queue is exhausted or to save the current messages in the in-memory queue when thersyslog
service is restarted. by @plkokanov [#115][OPERATOR]
This extension is now using the new way of providing monitoring configuration (ref GEP-19) in case a shoot cluster's Prometheus has been migrated to management viaprometheus-operator
. by @rfranzke [#99]
Docker Images
- gardener-extension-shoot-rsyslog-relp-admission:
europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/shoot-rsyslog-relp-admission:v0.5.0
- gardener-extension-shoot-rsyslog-relp:
europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/shoot-rsyslog-relp:v0.5.0
shoot-oidc-service-0.29.0
[gardener/oidc-webhook-authenticator]
🏃 Others
[OPERATOR]
OWA is now built using go version 1.23.3. by @dimityrmirchev [gardener/oidc-webhook-authenticator#167][DEVELOPER]
gosec
is made available for SAST(static application security testing), it can be run withmake sast
ormake sast-report
. by @vpnachev [gardener/oidc-webhook-authenticator#165]
[gardener/gardener-extension-shoot-oidc-service]
⚠️ Breaking Changes
[OPERATOR]
The type of theimageVectorOverwrite
helm chart value is changed from string to object. by @dimityrmirchev [#251]
🏃 Others
[OPERATOR]
The following dependencies have been updated:- github.com/gardener/gardener v1.105.0 -> v1.106.0
- k8s.io/api v0.29.8 -> v0.31.1
- k8s.io/apimachinery v0.29.9 -> v0.31.1
- k8s.io/client-go v0.29.9 -> v0.31.1
- k8s.io/code-generator v0.29.9 -> v0.31.1
- k8s.io/component-base v0.29.9 -> v0.31.1
- sigs.k8s.io/controller-runtime v0.17.6 -> v0.19.0 by @vpnachev [#248]
[DEVELOPER]
gosec
is made available for SAST(static application security testing), it can be run withmake sast
ormake sast-report
, but is also incorporated in theverify
andverify-extended
makefile targets. by @vpnachev [#248]
📖 Documentation
[USER]
Documentation now clarifies when Structured Authentication should be preferred over the Gardener OIDC extension. by @dimityrmirchev [#259]
Helm Charts
- shoot-oidc-service:
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/shoot-oidc-service:v0.29.0
Docker Images
- gardener-extension-shoot-oidc-service:
europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/shoot-oidc-service:v0.29.0
shoot-oidc-service-0.28.0
[gardener/gardener-extension-shoot-oidc-service]
🏃 Others
[OPERATOR]
The extension and OWA do not set cpu and memory limits. VPA is utilised to set proper recommendations. by @dimityrmirchev [#243]
[gardener/oidc-webhook-authenticator]
🏃 Others
[OPERATOR]
OWA is now built with go version 1.23.1. by @dimityrmirchev [gardener/oidc-webhook-authenticator#160][OPERATOR]
OWA is now built using go version 1.23.2. by @dimityrmirchev [gardener/oidc-webhook-authenticator#162]
Helm Charts
- shoot-oidc-service:
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/shoot-oidc-service:v0.28.0
Docker Images
- gardener-extension-shoot-oidc-service:
europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/shoot-oidc-service:v0.28.0
shoot-oidc-service-0.27.0
[gardener/gardener-extension-shoot-oidc-service]
✨ New Features
[OPERATOR]
The extension mutating webhook now uses object selector to reduce the number of calls. by @dimityrmirchev [#224][OPERATOR]
Helm charts of extension and admission controller are published as OCI artifacts now. by @oliver-goetz [#222]
🏃 Others
[DEPENDENCY]
The extension is now built using go version 1.22.5. by @dimityrmirchev [#220]
[gardener/oidc-webhook-authenticator]
🏃 Others
[DEVELOPER]
The following dependencies have been updated:- github.com/coreos/go-oidc/v3 v3.1.0 -> v3.10.0
- golang.org/x/time v0.3.0 -> v0.5.0
- k8s.io/* v0.27.9 -> v0.30.1
- sigs.k8s.io/controller-runtime v0.15.3 -> v0.18.4
- golang.org/x/crypto v0.21.0 -> v0.24.0
- golang.org/x/net v0.23.0 -> v0.26.0 by @vpnachev [gardener/oidc-webhook-authenticator#157]
[DEPENDENCY]
OWA is now built using go version 1.22.5. by @dimityrmirchev [gardener/oidc-webhook-authenticator#158]
Helm Charts
- shoot-oidc-service:
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/shoot-oidc-service:v0.27.0
Docker Images
- gardener-extension-shoot-oidc-service:
europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/shoot-oidc-service:v0.27.0
shoot-networking-problemdetector-0.26.0
[gardener/network-problem-detector]
🐛 Bug Fixes
[OPERATOR]
Delete corrupt current record file on restart. by @MartinWeindel [gardener/network-problem-detector#78]
[gardener/gardener-extension-shoot-networking-problemdetector]
🏃 Others
[OPERATOR]
Bumps github.com/gardener/gardener from 1.105.0 to 1.106.0. by @dependabot[bot] [#188]
Helm Charts
- shoot-networking-problemdetector:
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/shoot-networking-problemdetector:v0.26.0
Docker Images
- gardener-extension-shoot-networking-problemdetector:
europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/shoot-networking-problemdetector:v0.26.0
shoot-networking-problemdetector-0.25.0
[gardener/network-problem-detector]
📰 Noteworthy
[OPERATOR]
gosec
was introduced for Static Application Security Testing (SAST). by @MartinWeindel [gardener/network-problem-detector#75]
✨ New Features
[USER]
Support tcp checks for ipv6 endpoints. by @DockToFuture [gardener/network-problem-detector#76]
🏃 Others
[OPERATOR]
Bumps golang from 1.22.6 to 1.23.0. by @dependabot[bot] [gardener/network-problem-detector#71][OPERATOR]
Bumps golang from 1.23.0 to 1.23.1. by @dependabot[bot] [gardener/network-problem-detector#73][OPERATOR]
Bumps golang from 1.22.5 to 1.22.6. by @dependabot[bot] [gardener/network-problem-detector#70]
[gardener/gardener-extension-shoot-networking-problemdetector]
✨ New Features
[OPERATOR]
Helm charts of extension and admission controller are published as OCI artifacts now. by @oliver-goetz [#166]
🏃 Others
[OPERATOR]
Bumps github.com/gardener/gardener from 1.100.0 to 1.101.0. by @dependabot[bot] [#170][OPERATOR]
Bumps github.com/gardener/gardener from 1.103.0 to 1.105.0. by @dependabot[bot] [#181][OPERATOR]
Bumps github.com/gardener/gardener from 1.101.0 to 1.102.0. by @dependabot[bot] [#174][OPERATOR]
gosec
was introduced for Static Application Security Testing (SAST). by @ScheererJ [#182][OPERATOR]
Bumps golang from 1.23.1 to 1.23.2. by @dependabot[bot] [#180][OPERATOR]
Bumps github.com/gardener/gardener from 1.99.0 to 1.100.0. by @dependabot[bot] [#167]
Helm Charts
- shoot-networking-problemdetector:
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/shoot-networking-problemdetector:v0.25.0
Docker Images
- gardener-extension-shoot-networking-problemdetector:
europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/shoot-networking-problemdetector:v0.25.0
shoot-networking-problemdetector-0.24.0
[gardener/network-problem-detector]
🏃 Others
[OPERATOR]
Bumps golang from 1.22.3 to 1.22.4. by @dependabot[bot] [gardener/network-problem-detector#67][OPERATOR]
Bumps golang from 1.22.4 to 1.22.5. by @dependabot[bot] [gardener/network-problem-detector#69]
[gardener/gardener-extension-shoot-networking-problemdetector]
🏃 Others
[OPERATOR]
Bumps github.com/gardener/gardener from 1.98.0 to 1.99.0. by @dependabot[bot] [#162][OPERATOR]
Bumps github.com/gardener/gardener from 1.96.1 to 1.97.0. by @dependabot[bot] [#155][OPERATOR]
Bumps github.com/gardener/gardener from 1.95.0 to 1.96.1. by @dependabot[bot] [#151][OPERATOR]
Bumps github.com/gardener/gardener from 1.97.0 to 1.98.0. by @dependabot[bot] [#158]
Docker Images
- gardener-extension-shoot-networking-problemdetector:
europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/shoot-networking-problemdetector:v0.24.0
shoot-networking-filter-0.21.0
[gardener/egress-filter-refresher]
✨ New Features
[USER]
gosec
was introduced for Static Application Security Testing (SAST). by @ScheererJ [gardener/egress-filter-refresher#50][OPERATOR]
On switching the blocking mode, previously active egress filter rules are removed from the node. by @domdom82 [gardener/egress-filter-refresher#49]
[gardener/gardener-extension-shoot-networking-filter]
✨ New Features
[USER]
Ingress filtering may now be turned on/off per worker-group by @domdom82 [#186]
🏃 Others
[OPERATOR]
Bumps golang from 1.23.2 to 1.23.3. by @dependabot[bot] [#190][OPERATOR]
gosec
was introduced for Static Application Security Testing (SAST). by @ScheererJ [#181][OPERATOR]
Bumps github.com/gardener/gardener from 1.106.0 to 1.107.0. by @dependabot[bot] [#189][OPERATOR]
Bumps github.com/gardener/gardener from 1.104.0 to 1.105.0. by @dependabot[bot] [#180][OPERATOR]
Bumps github.com/gardener/gardener from 1.105.0 to 1.106.0. by @dependabot[bot] [#185]
Helm Charts
- runtime-networking-filter:
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/runtime-networking-filter:v0.21.0
- shoot-networking-filter:
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/shoot-networking-filter:v0.21.0
Docker Images
- gardener-extension-shoot-networking-filter:
europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/shoot-networking-filter:v0.21.0
- gardener-runtime-networking-filter:
europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/runtime-networking-filter:v0.21.0
shoot-networking-filter-0.20.0
[gardener/egress-filter-refresher]
🐛 Bug Fixes
[USER]
fixed a bug where non-suffixed IPv6 addresses could cause the egress filter applier to crash. by @domdom82 [gardener/egress-filter-refresher#48]
[gardener/gardener-extension-shoot-networking-filter]
✨ New Features
[OPERATOR]
Helm charts of extension and admission controller are published as OCI artifacts now. by @oliver-goetz [#163]
🏃 Others
[OPERATOR]
Bumps github.com/gardener/gardener from 1.99.0 to 1.100.0. by @dependabot[bot] [#164][OPERATOR]
Bumps github.com/gardener/gardener from 1.100.0 to 1.101.0. by @dependabot[bot] [#167][OPERATOR]
Bumps golang from 1.22.5 to 1.22.6. by @dependabot[bot] [#166][OPERATOR]
Bumps github.com/gardener/gardener from 1.101.0 to 1.102.0. by @dependabot[bot] [#171][OPERATOR]
Bumps golang from 1.23.0 to 1.23.1. by @dependabot[bot] [#174]
Helm Charts
- runtime-networking-filter:
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/runtime-networking-filter:v0.20.0
- shoot-networking-filter:
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/extensions/shoot-networking-filter:v0.20.0
Docker Images
- gardener-extension-shoot-networking-filter:
europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/shoot-networking-filter:v0.20.0
- gardener-runtime-networking-filter:
europe-docker.pkg.dev/gardener-project/releases/gardener/extensions/runtime-networking-filter:v0.20.0