🤖 Update module github.com/gardener/gardener to v1.107.0 #112
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v1.101.3
->v1.107.0
Release Notes
gardener/gardener (github.com/gardener/gardener)
v1.107.0
Compare Source
[gardener/gardener]
[DEVELOPER]
The unused methodWithShootCredentials
have been removed fromgithub.com/gardener/gardener/pkg/gardenlet/operation/shoot.Builder
. by @vpnachev [#10672][DEVELOPER]
In the local development setup, the images are pushed togarden.local.gardener.cloud:5001
instead oflocalhost:5001
now. Please add127.0.0.1 garden.local.gardener.cloud
to your/etc/hosts
. by @rrhubenov [#10257][OPERATOR]
Feature gateIPv6SingleStack
has been removed. Infrastructure-specific validations will be added in parallel to the corresponding provider extensions. by @ScheererJ [#10716]📰 Noteworthy
[OPERATOR]
ManagedSeed's.spec.gardenlet.config.seedConfig.spec.ingress.controller.kind
field is now defaulted tonginx
when.spec.gardenlet.config.seedConfig
or.spec.gardenlet.config.seedConfig.spec.ingress
is nil.This allows the creation of ManagedSeed without specifying the
.spec.gardenlet
field. by @RadaBDimitrova [#10655][OPERATOR]
A newrequired
controller was added togardener-operator
. It maintains theRequiredRuntime
condition forExtension
resources to indicate that the extension deployment is required in the Garden-Runtime cluster. by @timuthy [#10650][OPERATOR]
Thegardener/controlplane
Helm chart has been deprecated and will be removed afterv1.135
has been released (around beginning of 2026). We urge you to switch to agardener-operator
-based installation. Read all about it here. by @rfranzke [#10706][DEVELOPER]
.spec.gardenlet
of ManagedSeed is now a required field. This was already the case from an API perspective, enforced by validation. by @RadaBDimitrova [#10648][USER]
Thespec.kubernetes.kubeAPIServer.oidcConfig
field in theShoot
API is deprecated and will be removed after support for Kubernetes 1.31 is dropped. by @AleksandarSavchev [#10666]✨ New Features
[OPERATOR]
If an admission webhook which was deployed viaExtension
resource bygardener-operator
is deleted again, its webhook configuration in the virtual-cluster is cleaned up automatically. by @oliver-goetz [#10585][OPERATOR]
TheCloudProfile
,Seed
, andShoot
APIs are now allowing to configure access restrictions (e.g., to enable "EU access"-only or similar policies). The legacy approach with theseed.gardener.cloud/eu-access
labels is deprecated and will be removed in a future release. Make sure to adapt to the new APIs. Read all about it here. by @rfranzke [#10654][USER]
The viewer kubeconfigs for shoot clusters now allow thepods/log
subresource. by @rfranzke [#10711][USER]
Service Account Managed Issuer can be now enabled for workerless shoot clusters. by @dimityrmirchev [#10689][USER]
Structured authorization configuration can now be set by creating aConfigMap
with theAuthorizationConfiguration
file set in theconfig.yaml
data key and referencing it (in theShoot
via.spec.kubernetes.kubeAPIServer.structuredAuthorization
, in theGarden
via.spec.virtualCluster.kubernetes.kubeAPIServer.structuredAuthorization
for Kubernetes versions>= v1.30
. Read all about it here. by @rfranzke [#10682][USER]
Gardener reports the cluster's egress CIDRs inShoot.status.networking.egressCIDRs
if supported by the used provider extension. by @timebertt [#10240]🐛 Bug Fixes
[OPERATOR]
Fix Prometheus ruleshoot-kube-proxy
. by @LucaBernstein [#10757][OPERATOR]
The TopologySpreadConstraints calculation was improved forStatefulSet
s to always use a stable label selector. This led to issues in the past when shoots were upgraded to HA. by @timuthy [#10750][OPERATOR]
valitail version is now pinned to v2.2.15 (depends on glibc 2.32). by @ialidzhikov [#10776]🏃 Others
[DEPENDENCY]
Thecredativ/plutono
image has been updated tov7.5.34
. Release Notes by @gardener-ci-robot [#10732][DEPENDENCY]
Thegardener/etcd-druid
image has been updated tov0.23.2
. Release Notes by @gardener-ci-robot [#10747][DEPENDENCY]
Thegardener/cert-management
image has been updated tov0.16.0
. Release Notes by @gardener-ci-robot [#10684][DEPENDENCY]
Thecredativ/vali
image has been updated tov2.2.19
. Release Notes by @gardener-ci-robot [#10680][DEPENDENCY]
Thegcr.io/istio-release/pilot
image has been updated to1.23.3
. by @gardener-ci-robot [#10725][DEPENDENCY]
Thequay.io/prometheus/prometheus
image has been updated tov2.55.0
. by @gardener-ci-robot [#10697][DEPENDENCY]
Thequay.io/prometheus-operator/prometheus-config-reloader
image has been updated tov0.77.2
. by @gardener-ci-robot [#10692][DEPENDENCY]
Theenvoyproxy/envoy
image has been updated tov1.32.1
. Release Notes by @gardener-ci-robot [#10755][DEPENDENCY]
Thegardener/dashboard
image has been updated to1.78.0
. Release Notes by @gardener-ci-robot [#10731][OPERATOR]
The admission automatically adds theprovider.extensions.gardener.cloud
label toNamespacedCloudProfile
s. by @LucaBernstein [#10742][OPERATOR]
Add dual-stack support for coredns. by @DockToFuture [#10733][OPERATOR]
Allow extensions to be scraped in garden runtime cluster even outside garden namespace by @ScheererJ [#10720][OPERATOR]
Add label selector to ShootResourceReservation plugin to control for which Shoots the ShootResourceReservation Plugin setskubeReserved
according to the GKE formula whenuseGKEFormula: true
is set. by @voelzmo [#10492][OPERATOR]
Increase the readiness probe timeout for thegardener-metrics-exporter
from 1s to 10s. by @vicwicker [#10771][OPERATOR]
Thegardener/etcd-druid
image has been updated tov0.23.1
. Release Notes v0.23.1, Release Notes v0.23.0 by @shreyas-s-rao [#10526][OPERATOR]
Theautoscaler/cluster-autoscaler
image has been updated tov1.29.2
(for Kubernetes v1.29). Release Notes by @rishabh-11 [#10700][OPERATOR]
Gardener API Server feature gateShootCredentialsBinding
has been promoted to beta and is enabled by default. by @dimityrmirchev [#10662][DEVELOPER]
Add Make targetmake operator-seed-dev
for local development of thegardenlet
in the operator setup. by @marc1404 [#10710][DEVELOPER]
Fix/etc/hosts
configuration in the remote local setup by @vicwicker [#10744][DEVELOPER]
The base image of thegardener-extension-provider-local-node
image is now updated tokindest/[email protected]
. by @ialidzhikov [#10688][DEVELOPER]
local setup: The kind cluster's node image is now updated tokindest/[email protected]
. by @ialidzhikov [#10723]Helm Charts
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/controlplane:v1.107.0
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/gardenlet:v1.107.0
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/operator:v1.107.0
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/resource-manager:v1.107.0
Docker Images
europe-docker.pkg.dev/gardener-project/releases/gardener/admission-controller:v1.107.0
europe-docker.pkg.dev/gardener-project/releases/gardener/apiserver:v1.107.0
europe-docker.pkg.dev/gardener-project/releases/gardener/controller-manager:v1.107.0
europe-docker.pkg.dev/gardener-project/releases/gardener/gardenlet:v1.107.0
europe-docker.pkg.dev/gardener-project/releases/gardener/node-agent:v1.107.0
europe-docker.pkg.dev/gardener-project/releases/gardener/operator:v1.107.0
europe-docker.pkg.dev/gardener-project/releases/gardener/resource-manager:v1.107.0
europe-docker.pkg.dev/gardener-project/releases/gardener/scheduler:v1.107.0
v1.106.2
Compare Source
[gardener/gardener]
🏃 Others
[OPERATOR]
Increase the readiness probe timeout for thegardener-metrics-exporter
from 1s to 10s. by @vicwicker [#10769]Helm Charts
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/controlplane:v1.106.2
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/gardenlet:v1.106.2
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/operator:v1.106.2
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/resource-manager:v1.106.2
Docker Images
europe-docker.pkg.dev/gardener-project/releases/gardener/admission-controller:v1.106.2
europe-docker.pkg.dev/gardener-project/releases/gardener/apiserver:v1.106.2
europe-docker.pkg.dev/gardener-project/releases/gardener/controller-manager:v1.106.2
europe-docker.pkg.dev/gardener-project/releases/gardener/gardenlet:v1.106.2
europe-docker.pkg.dev/gardener-project/releases/gardener/node-agent:v1.106.2
europe-docker.pkg.dev/gardener-project/releases/gardener/operator:v1.106.2
europe-docker.pkg.dev/gardener-project/releases/gardener/resource-manager:v1.106.2
europe-docker.pkg.dev/gardener-project/releases/gardener/scheduler:v1.106.2
v1.106.1
Compare Source
[gardener/gardener]
🐛 Bug Fixes
[OPERATOR]
Thegardener-resource-manager
does not markDeployment
s as progressing when there are still completedPod
s in the system. by @timuthy [#10727]🏃 Others
[OPERATOR]
IPv6 support fornode-local-dns
. by @DockToFuture [#10707][OPERATOR]
Fixed an issue that would cause the entry for themachine-state
in theShootState
to be overwritten with nil data during control plane migration, if themigrate
phase errored and was retried after theMachineDeployment
,MachineSet
andMachine
objects were deleted, which would result in the Shoot's nodes to be recreated during Control Plane Migration. by @plkokanov [#10695]Helm Charts
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/controlplane:v1.106.1
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/gardenlet:v1.106.1
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/operator:v1.106.1
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/resource-manager:v1.106.1
Docker Images
europe-docker.pkg.dev/gardener-project/releases/gardener/admission-controller:v1.106.1
europe-docker.pkg.dev/gardener-project/releases/gardener/apiserver:v1.106.1
europe-docker.pkg.dev/gardener-project/releases/gardener/controller-manager:v1.106.1
europe-docker.pkg.dev/gardener-project/releases/gardener/gardenlet:v1.106.1
europe-docker.pkg.dev/gardener-project/releases/gardener/node-agent:v1.106.1
europe-docker.pkg.dev/gardener-project/releases/gardener/operator:v1.106.1
europe-docker.pkg.dev/gardener-project/releases/gardener/resource-manager:v1.106.1
europe-docker.pkg.dev/gardener-project/releases/gardener/scheduler:v1.106.1
v1.106.0
Compare Source
[gardener/gardener]
[OPERATOR]
kubeletCSRApprover
controller ingardener-resource-manager
Helm chart has been renamed tocsrApprover
. by @oliver-goetz [#10549][OPERATOR]
TheHVPA
andHVPAForShootedSeed
feature gates have been deprecated and locked to false. Disable theHVPA
andHVPAForShootedSeed
feature gates if you have them enabled before upgrading to this version of Gardener. by @plkokanov [#10659]📰 Noteworthy
[USER]
For Kubernetes 1.31+ Shoot clusters, the kubelet and containerd cgroup driver is set tosystemd
. Previously, the used cgroup driver wascgroupfs
. Find more details in the cgroup driver section. by @ialidzhikov [#10472][OPERATOR]
The gardener operator chart (charts/gardener/operator
) does no longer enable theHVPA
feature gate in its defaultvalues.yaml
. by @ialidzhikov [#10566]✨ New Features
[DEVELOPER]
Allow gosec to be consumed from gardener/gardener by @ScheererJ [#10642][DEVELOPER]
Gardener can now support clusters with Kubernetes version 1.31. Extension developers have to prepare individual extensions as well to work with 1.31. by @ialidzhikov [#10472][OPERATOR]
AddsCloudProfile
validation for the recently introduced.spec.bastion
section. by @hebelsan [#10318][OPERATOR]
Gardener can now support clusters with Kubernetes version 1.31. To allow creation/update of 1.31 clusters you will have to update the version of your provider extension(s) to a version that supports 1.31 as well. Please consult the respective releases and notes in the provider extension's repository. by @ialidzhikov [#10472][OPERATOR]
Added an alert for theGarden
resource's conditions, along with a dashboard that also displays the resource's last operation. by @rickardsjp [#10562]🐛 Bug Fixes
[OPERATOR]
Fixes an issue with the network metrics relabeling config that caused theNode Details
dashboard to not display data for AWS nodes. by @rickardsjp [#10625]🏃 Others
[DEPENDENCY]
Theregistry.k8s.io/ingress-nginx/controller-chroot
image has been updated tov1.11.3
. by @gardener-ci-robot [#10626][DEPENDENCY]
Thegardener/vpn2
image has been updated to0.28.0
. Release Notes by @gardener-ci-robot [#10640][DEPENDENCY]
Thequay.io/cortexproject/cortex
image has been updated tov1.18.1
. by @gardener-ci-robot [#10657][DEPENDENCY]
Theregistry.k8s.io/node-problem-detector/node-problem-detector
image has been updated tov0.8.20
. by @gardener-ci-robot [#10661][DEPENDENCY]
Theenvoyproxy/envoy
image has been updated tov1.32.0
. Release Notes by @gardener-ci-robot [#10656][OPERATOR]
HA-VPN works if seed and shoot have different IPFamilies. by @DockToFuture [#10622][OPERATOR]
Update istio to version 1.23.2 by @axel7born [#10558][OPERATOR]
[NewVPN] Enable IPv6 for HA if needed. by @MartinWeindel [#10641][OPERATOR]
Gardener generated certificates are valid 1 minute before issuance to handle some amount of clock skew. by @ScheererJ [#10603][OPERATOR]
Metrics forvpa-recommender
s are now collected in separate prometheus instances depending on where thevpa-recommender
pods are deployed. Metrics for thevpa-recommender
in thegarden
namespace are collected inprometheus-seed
. Metrics for thevpa-recommender
in the shoot control plane namespaces are collected in the correspondingprometheus-shoot
. Additionally, theVPA Recommender
plutono dashboard is separately deployed for seeds in thegarden
namespace and shoots in their control plane namespaces. by @plkokanov [#10517][OPERATOR]
Clean up migration code from the monitoring component by @vicwicker [#10597][DEVELOPER]
The following dependencies are updated:k8s.io/*
:v0.29.8
->v0.31.0
sigs.k8s.io/controller-runtime
:v0.17.5
->v0.19.0
by @ary1992 [#10459][DEVELOPER]
The HVPA features gates (HVPA
andHVPAForShootedSeed
) are no longer enabled in local setups. by @ialidzhikov [#10566]Helm Charts
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/controlplane:v1.106.0
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/gardenlet:v1.106.0
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/operator:v1.106.0
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/resource-manager:v1.106.0
Docker Images
europe-docker.pkg.dev/gardener-project/releases/gardener/admission-controller:v1.106.0
europe-docker.pkg.dev/gardener-project/releases/gardener/apiserver:v1.106.0
europe-docker.pkg.dev/gardener-project/releases/gardener/controller-manager:v1.106.0
europe-docker.pkg.dev/gardener-project/releases/gardener/gardenlet:v1.106.0
europe-docker.pkg.dev/gardener-project/releases/gardener/node-agent:v1.106.0
europe-docker.pkg.dev/gardener-project/releases/gardener/operator:v1.106.0
europe-docker.pkg.dev/gardener-project/releases/gardener/resource-manager:v1.106.0
europe-docker.pkg.dev/gardener-project/releases/gardener/scheduler:v1.106.0
v1.105.3
Compare Source
[gardener/gardener]
🏃 Others
[OPERATOR]
Increase the readiness probe timeout for thegardener-metrics-exporter
from 1s to 10s. by @vicwicker [#10770]Helm Charts
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/controlplane:v1.105.3
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/gardenlet:v1.105.3
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/operator:v1.105.3
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/resource-manager:v1.105.3
Docker Images
europe-docker.pkg.dev/gardener-project/releases/gardener/admission-controller:v1.105.3
europe-docker.pkg.dev/gardener-project/releases/gardener/apiserver:v1.105.3
europe-docker.pkg.dev/gardener-project/releases/gardener/controller-manager:v1.105.3
europe-docker.pkg.dev/gardener-project/releases/gardener/gardenlet:v1.105.3
europe-docker.pkg.dev/gardener-project/releases/gardener/node-agent:v1.105.3
europe-docker.pkg.dev/gardener-project/releases/gardener/operator:v1.105.3
europe-docker.pkg.dev/gardener-project/releases/gardener/resource-manager:v1.105.3
europe-docker.pkg.dev/gardener-project/releases/gardener/scheduler:v1.105.3
v1.105.2
Compare Source
[gardener/gardener]
🐛 Bug Fixes
[OPERATOR]
Thegardener-resource-manager
does not markDeployment
s as progressing when there are still completedPod
s in the system. by @timuthy [#10728]🏃 Others
[OPERATOR]
Fixed an issue that would cause the entry for themachine-state
in theShootState
to be overwritten with nil data during control plane migration, if themigrate
phase errored and was retried after theMachineDeployment
,MachineSet
andMachine
objects were deleted, which would result in the Shoot's nodes to be recreated during Control Plane Migration. by @plkokanov [#10696][OPERATOR]
IPv6 support fornode-local-dns
. by @DockToFuture [#10708]Helm Charts
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/controlplane:v1.105.2
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/gardenlet:v1.105.2
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/operator:v1.105.2
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/resource-manager:v1.105.2
Docker Images
europe-docker.pkg.dev/gardener-project/releases/gardener/admission-controller:v1.105.2
europe-docker.pkg.dev/gardener-project/releases/gardener/apiserver:v1.105.2
europe-docker.pkg.dev/gardener-project/releases/gardener/controller-manager:v1.105.2
europe-docker.pkg.dev/gardener-project/releases/gardener/gardenlet:v1.105.2
europe-docker.pkg.dev/gardener-project/releases/gardener/node-agent:v1.105.2
europe-docker.pkg.dev/gardener-project/releases/gardener/operator:v1.105.2
europe-docker.pkg.dev/gardener-project/releases/gardener/resource-manager:v1.105.2
europe-docker.pkg.dev/gardener-project/releases/gardener/scheduler:v1.105.2
v1.105.1
Compare Source
[gardener/gardener]
🐛 Bug Fixes
[OPERATOR]
An issue was fixed that causegardener-operator
to deploy thegardenlet
into the runtime cluster instead of another intended remote cluster. by @timuthy [#10631][OPERATOR]
Fix a bug where the shoot care controller cannot reconcile shoots withspec.maintenance.confineSpecUpdateRollout=true
and migrated betweensecretBindingName
andcredentialsBindingName
until the shoot is reconciled.. by @vpnachev [#10674]Helm Charts
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/controlplane:v1.105.1
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/gardenlet:v1.105.1
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/operator:v1.105.1
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/resource-manager:v1.105.1
Docker Images
europe-docker.pkg.dev/gardener-project/releases/gardener/admission-controller:v1.105.1
europe-docker.pkg.dev/gardener-project/releases/gardener/apiserver:v1.105.1
europe-docker.pkg.dev/gardener-project/releases/gardener/controller-manager:v1.105.1
europe-docker.pkg.dev/gardener-project/releases/gardener/gardenlet:v1.105.1
europe-docker.pkg.dev/gardener-project/releases/gardener/node-agent:v1.105.1
europe-docker.pkg.dev/gardener-project/releases/gardener/operator:v1.105.1
europe-docker.pkg.dev/gardener-project/releases/gardener/resource-manager:v1.105.1
europe-docker.pkg.dev/gardener-project/releases/gardener/scheduler:v1.105.1
v1.105.0
Compare Source
[gardener/gardener]
📰 Noteworthy
[OPERATOR]
TheVPAForETCD
andVPAAndHPAForAPIServer
feature gates have been promoted to GA and locked totrue
. by @plkokanov [#10599][USER]
The limitation of having at maximum ~80 worker pools inShoot
s has been lifted. Much higher numbers should be possible now (concrete limit depends on the amount of configuration within the pools (e.g., labels, taints, annotations, etc.)). by @rfranzke [#10542]✨ New Features
[DEVELOPER]
Add functionality for the determination of bastion VM parameters used by the extensions by @hebelsan [#10537][OPERATOR]
gardener-operator
is now capable of deploying extension controllers to the garden runtime cluster viaoperator.gardener.cloud/v1alpha1.Extension
resources. Please visit this document for more information. by @timuthy [#10518][OPERATOR]
gardenlet
now performs garbage collection of stalePod
s in all namespaces (exceptkube-system
) in the seed cluster. by @rfranzke [#10548]🐛 Bug Fixes
[OPERATOR]
When checking whether aDeployment
rollout is complete, stalePod
s are now ignored and no longer counted. by @rfranzke [#10548]🏃 Others
[DEPENDENCY]
Thequay.io/prometheus-operator/prometheus-config-reloader
image has been updated tov0.77.0
. by @gardener-ci-robot [#10547][DEPENDENCY]
Thegardener/ingress-default-backend
image has been updated to0.20.0
. Release Notes by @gardener-ci-robot [#10560][DEPENDENCY]
Thegardener/etcd-druid
image has been updated tov0.22.7
. Release Notes by @gardener-ci-robot [#10570][DEPENDENCY]
Thegardener/etcd-druid
image has been updated tov0.22.6
. Release Notes by @gardener-ci-robot [#10556][DEPENDENCY]
Thegardener/gardener-discovery-server
image has been updated tov0.2.0
. Release Notes by @gardener-ci-robot [#10546][DEPENDENCY]
Thequay.io/prometheus-operator/prometheus-config-reloader
image has been updated tov0.77.1
. by @gardener-ci-robot [#10573][DEPENDENCY]
Thequay.io/kiwigrid/k8s-sidecar
image has been updated to1.28.0
. by @gardener-ci-robot [#10591][DEPENDENCY]
Theenvoyproxy/envoy
image has been updated tov1.31.2
. Release Notes by @gardener-ci-robot [#10553][DEPENDENCY]
Thegcr.io/istio-release/pilot
image has been updated to1.21.6
. by @gardener-ci-robot [#10564][DEVELOPER]
provider-extensions setup: Seed VPA is disabled by default to avoid two VPA deployments to act on the same cluster causing endless eviction loops. by @ialidzhikov [#10593][DEVELOPER]
Correctly extract and install the go binaries in the remote local setup by @vicwicker [#10605][OPERATOR]
Allow overlapping network ranges in case of single stack IPv6. by @axel7born [#10584][OPERATOR]
Allow empty pod and service ranges in shoot spec for IPv6 single stack. by @axel7born [#10541][OPERATOR]
TheTopologySpreadConstraint
calculation was improved for workload spread across multiple zones. This especially leads to a more balanced distribution ofkube-apiserver
andistio
replicas in seed clusters. by @timuthy [#10608][OPERATOR]
VPA resource settings are now adapted - memory limits are removed and initial resource requests are lowered. by @voelzmo [#10568]Helm Charts
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/controlplane:v1.105.0
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/gardenlet:v1.105.0
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/operator:v1.105.0
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/resource-manager:v1.105.0
Docker Images
europe-docker.pkg.dev/gardener-project/releases/gardener/admission-controller:v1.105.0
europe-docker.pkg.dev/gardener-project/releases/gardener/apiserver:v1.105.0
europe-docker.pkg.dev/gardener-project/releases/gardener/controller-manager:v1.105.0
europe-docker.pkg.dev/gardener-project/releases/gardener/gardenlet:v1.105.0
europe-docker.pkg.dev/gardener-project/releases/gardener/node-agent:v1.105.0
europe-docker.pkg.dev/gardener-project/releases/gardener/operator:v1.105.0
europe-docker.pkg.dev/gardener-project/releases/gardener/resource-manager:v1.105.0
europe-docker.pkg.dev/gardener-project/releases/gardener/scheduler:v1.105.0
v1.104.3
Compare Source
[gardener/gardener]
🏃 Others
[OPERATOR]
IPv6 support fornode-local-dns
. by @DockToFuture [#10709]Helm Charts
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/controlplane:v1.104.3
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/gardenlet:v1.104.3
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/operator:v1.104.3
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/resource-manager:v1.104.3
Docker Images
europe-docker.pkg.dev/gardener-project/releases/gardener/admission-controller:v1.104.3
europe-docker.pkg.dev/gardener-project/releases/gardener/apiserver:v1.104.3
europe-docker.pkg.dev/gardener-project/releases/gardener/controller-manager:v1.104.3
europe-docker.pkg.dev/gardener-project/releases/gardener/gardenlet:v1.104.3
europe-docker.pkg.dev/gardener-project/releases/gardener/node-agent:v1.104.3
europe-docker.pkg.dev/gardener-project/releases/gardener/operator:v1.104.3
europe-docker.pkg.dev/gardener-project/releases/gardener/resource-manager:v1.104.3
europe-docker.pkg.dev/gardener-project/releases/gardener/scheduler:v1.104.3
v1.104.2
Compare Source
[gardener/gardener]
🐛 Bug Fixes
[OPERATOR]
Fix a bug where the shoot care controller cannot reconcile shoots withspec.maintenance.confineSpecUpdateRollout=true
and migrated betweensecretBindingName
andcredentialsBindingName
until the shoot is reconciled.. by @vpnachev [#10675][OPERATOR]
An issue was fixed that causegardener-operator
to deploy thegardenlet
into the runtime cluster instead of another intended remote cluster. by @timuthy [#10628]Helm Charts
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/controlplane:v1.104.2
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/gardenlet:v1.104.2
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/operator:v1.104.2
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/resource-manager:v1.104.2
Docker Images
europe-docker.pkg.dev/gardener-project/releases/gardener/admission-controller:v1.104.2
europe-docker.pkg.dev/gardener-project/releases/gardener/apiserver:v1.104.2
europe-docker.pkg.dev/gardener-project/releases/gardener/controller-manager:v1.104.2
europe-docker.pkg.dev/gardener-project/releases/gardener/gardenlet:v1.104.2
europe-docker.pkg.dev/gardener-project/releases/gardener/node-agent:v1.104.2
europe-docker.pkg.dev/gardener-project/releases/gardener/operator:v1.104.2
europe-docker.pkg.dev/gardener-project/releases/gardener/resource-manager:v1.104.2
europe-docker.pkg.dev/gardener-project/releases/gardener/scheduler:v1.104.2
v1.104.1
Compare Source
[gardener/gardener]
🐛 Bug Fixes
[OPERATOR]
Fix a regression that causedgardenlet
to not be able to migrate deprecatedfailure-domain.beta.kubernetes.io
labels totopology.kubernetes.io
due to a removed RBAC rule required to patchPersistentVolume
s. by @plkokanov [#10578]🏃 Others
[OPERATOR]
Thegardener/etcd-druid
image has been updated tov0.22.7
. Release Notes by @ishan16696 [#10592]Helm Charts
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/controlplane:v1.104.1
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/gardenlet:v1.104.1
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/operator:v1.104.1
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/resource-manager:v1.104.1
Docker Images
europe-docker.pkg.dev/gardener-project/releases/gardener/admission-controller:v1.104.1
europe-docker.pkg.dev/gardener-project/releases/gardener/apiserver:v1.104.1
europe-docker.pkg.dev/gardener-project/releases/gardener/controller-manager:v1.104.1
europe-docker.pkg.dev/gardener-project/releases/gardener/gardenlet:v1.104.1
europe-docker.pkg.dev/gardener-project/releases/gardener/node-agent:v1.104.1
europe-docker.pkg.dev/gardener-project/releases/gardener/operator:v1.104.1
europe-docker.pkg.dev/gardener-project/releases/gardener/resource-manager:v1.104.1
europe-docker.pkg.dev/gardener-project/releases/gardener/scheduler:v1.104.1
v1.104.0
Compare Source
[gardener/gardener]
[USER]
A bug has been fixed which was allowing users to setShoot
oidc configurations for thekube-apiserver
without setting theclientID
andissuerURL
fields inspec.kubernetes.kubeAPIServer.oidcConfig
, which would lead to thekube-apiserver
stuck in aError
state. gardener-apiserver now requires bothclientID
andissuerURL
fields to be set when thespec.kubernetes.kubeAPIServer.oidcConfig
field is specified. by @AleksandarSavchev [#10461][OPERATOR]
credentialsBinding.credentialsRef
is now an immutable field. by @dimityrmirchev [#10365]📰 Noteworthy
[USER]
Users are allowed to changeshoot.spec.credentialsBindingName
and reference anotherCredentialsBinding
only if they have the permissions to read both the old and newly referenced credential. by @dimityrmirchev [#10365][USER]
Users can migrate fromshoot.spec.secretBindingName
toshoot.spec.credentialsBindingName
only if the referenced credential remains the same and is not changed during the process. by @dimityrmirchev [#10365][OPERATOR]
Allow project users to readNamespacedCloudProfile
s and for project admins to make adjustments to machine types and volume types. by @LucaBernstein [#10485][OPERATOR]
Alerts based on theproposals_failed_total
metric of the etcd cluster are not raised anymore. by @renormalize [#10524][DEVELOPER]
A new predicateextensions/pkg/predicate.GardenSecurityProviderType
can be used to select resources from thesecurity.gardener.cloud
group that are related to the passed provider type. by @dimityrmirchev [#10499]✨ New Features
[OPERATOR]
Thegardener-operator
metrics are now automatically scraped by thegarden
Prometheus. by @maboehm [#10464][OPERATOR]
Introduce custom RBAC verbs to allow for modification of.spec.{kubernetes,machineImages}
inNamespacedCloudProfile
s. by @LucaBernstein [#10485][OPERATOR]
The feature gateNewVPN
is introduced for thegardenlet
component. If enabled, the new VPN implementation (Golang rewrite) is used for allShoot
s of the respectiveSeed
. In this case, the old implementation can be disabled for a singleShoot
by annotating the shoot resource withalpha.control-plane.shoot.gardener.cloud/disable-new-vpn=true
. ForSeed
s with disabled feature gate, the new implementation can be enabled for a single shoot by annotating it withalpha.control-plane.shoot.gardener.cloud/disable-new-vpn=false
. by @MartinWeindel [#9774]🐛 Bug Fixes
[USER]
Fixed disk read/write panel in the shoot's etcd dashboards by @rickardsjp [#10493][DEVELOPER]
An issue was fixed that rejected the creation of workerless shoots in the local setup. by @timuthy [#10498]🏃 Others
[DEPENDENCY]
Thegardener/hvpa-controller
image has been updated tov0.17.0
. Release Notes by @gardener-ci-robot [#10508][DEPENDENCY]
Thequay.io/prometheus-operator/prometheus-config-reloader
image has been updated tov0.76.2
. by @gardener-ci-robot [#10500][DEPENDENCY]
Thegardener/machine-controller-manager
image has been updated tov0.54.0
. Release Notes by @gardener-ci-robot [#10528][DEPENDENCY]
Thegardener/alpine-conntrack
image has been updated to3.20.3
. Release Notes by @gardener-ci-robot [#10487][DEPENDENCY]
Theenvoyproxy/envoy
image has been updated tov1.31.1
. Release Notes by @gardener-ci-robot [#10531][OPERATOR]
Federate apiserver_total_request metric to the Prometheus longterm instance by @jguipi [#10457][OPERATOR]
Allow emptynetworking.nodes
in case of IPv6 only shoots. by @axel7born [#10533][OPERATOR]
Improved node utilisation by reducing requests for etcd-druid managed pods. by @unmarshall [#10540][DEVELOPER]
Install go in the remote local setup from the go download site instead of using the apk package manager. by @vicwicker [#10502]Helm Charts
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/controlplane:v1.104.0
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/gardenlet:v1.104.0
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/operator:v1.104.0
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/resource-manager:v1.104.0
Docker Images
europe-docker.pkg.dev/gardener-project/releases/gardener/admission-controller:v1.104.0
europe-docker.pkg.dev/gardener-project/releases/gardener/apiserver:v1.104.0
europe-docker.pkg.dev/gardener-project/releases/gardener/controller-manager:v1.104.0
europe-docker.pkg.dev/gardener-project/releases/gardener/gardenlet:v1.104.0
europe-docker.pkg.dev/gardener-project/releases/gardener/node-agent:v1.104.0
europe-docker.pkg.dev/gardener-project/releases/gardener/operator:v1.104.0
europe-docker.pkg.dev/gardener-project/releases/gardener/resource-manager:v1.104.0
europe-docker.pkg.dev/gardener-project/releases/gardener/scheduler:v1.104.0
v1.103.2
Compare Source
[gardener/gardener]
🐛 Bug Fixes
[OPERATOR]
An issue was fixed that causegardener-operator
to deploy thegardenlet
into the runtime cluster instead of another intended remote cluster. by @timuthy [#10624][OPERATOR]
Fix a bug where the shoot care controller cannot reconcile shoots withspec.maintenance.confineSpecUpdateRollout=true
and migrated betweensecretBindingName
andcredentialsBindingName
until the shoot is reconciled.. by @vpnachev [#10676]Helm Charts
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/controlplane:v1.103.2
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/gardenlet:v1.103.2
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/operator:v1.103.2
europe-docker.pkg.dev/gardener-project/releases/charts/gardener/resource-manager:v1.103.2
Docker Images
europe-docker.pkg.dev/gardener-project/releases/gardener/admission-controller:v1.103.2
europe-docker.pkg.dev/gardener-project/releases/gardener/apiserver:v1.103.2
europe-docker.pkg.dev/gardener-project/releases/gardener/controller-manager:v1.103.2
europe-docker.pkg.dev/gardener-project/releases/gardener/gardenlet:v1.103.2
europe-docker.pkg.dev/gardener-project/releases/gardener/node-agent:v1.103.2
europe-docker.pkg.dev/gardener-project/releases/gardener/operator:v1.103.2
europe-docker.pkg.dev/gardener-project/releases/gardener/resource-manager:v1.103.2
europe-docker.pkg.dev/gardener-project/releases/gardener/scheduler:v1.103.2
v1.103.1
Compare Source
[gardener/gardener]
🐛 Bug Fixes
[DEVELOPER]
An issue was fixed that rejected the creation of workerless shoots in the local setup. by @timuthy [#10503][OPERATOR]
Fix a regression that causedgardenlet
to not be able to migrate deprecatedfailure-domain.beta.kubernetes.io
labels totopology.kubernetes.io
due to a removed RBAC rule required to patchPersistentVolume
s. by @plkokanov [[#10581](https://redirect.github.com/gardenerConfiguration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.