Changes and Releases

Updates on Giant Swarm workload cluster releases, apps, UI improvements and documentation changes.

  • Changed

    • Reduce security exceptions #89.
      • Enable readOnly FS moving config to emptyDir volume.
      • Remove NET_ADMIN and drop ALL capabilities.
      • Add NET_BIND_SERVICE capability.
      • Add policy exception for require-non-root-groups/autogen-check-runasgroup.
      • Remove disallow-capabilities-* policy exceptions.
  • Changed

    • Update Backstage to 1.28.4.
  • Changed

    • Get rid of the app label in Phoenix dashboards.
  • Added

    • Improves container security by setting runAsGroup and runAsUser greater than zero for all deployments.
  • Changed

    • Upgrade kube-prometheus-stack to 11.0.0 and prometheus-operator-crd to 11.0.0. This upgrade mainly consists in:
      • kube-prometheus-stack dependency chart upgraded from 56.21.2 to 61.0.0
      • prometheus upgrade from 2.50.1 to 2.53.0
      • thanos ruler upgrade from 0.34.1 to 0.35.1
      • kube-state-metrics from 2.10.0 to 2.12.0
      • prometheus-operator from 0.71.2 0.75.0 - adding remoteWrite.proxyFromEnvironment and Scrape Class support
      • prometheus-node-exporter upgraded from 1.8.0 to 1.8.1
    • Upgrade grafana-agent from 0.4.3 to 0.4.4
      • This version enables the override the grafana agent CiliumNetworkPolicy egress and ingress sections.
  • Added

    • Add plugin-scaffolder-backend-module-gs backend module with custom parseClusterRef filter for scaffolder plugin.
    • GS Auth: add custom sign-in resolver for GitHub auth provider.

    Removed

    • Clean up catalog templates.
  • Added

    • Add “BPF map pressure” graph to “Cilium performance” dashboard.
    • Add kube-builder logs in “Kube-Builder Operators” dashboard.

    Changed

    • fluentbit dashboard: cluster selection

    Fixed

    • Mimir Cost Estimation: fix RAM usage

    Removed

    • Removed the dashboard ‘Webhook Health’.
  • Changed

    • Upgraded chart dependency to kube-prometheus-stack-61.0.0
      • prometheus-operator from 0.73.2 to 0.75.0 - adding remoteWrite.proxyFromEnvironment support
      • prometheus upgraded from 2.52.0 to 2.53.0
      • grafana from 7.3.12 to 8.2.0
      • thanos ruler upgraded from 0.35.0 to 0.35.1
      • prometheus-node-exporter upgraded from 1.8.0 to 1.8.1
    • Replace in-addr.arpa records in zone label for coredns_cache_.* metrics due to large cardinality.
  • Changed

    • Upgraded chart dependency to kube-prometheus-stack-61.0.0
      • prometheus-operator from 0.73.2 to 0.75.0 - adding remoteWrite.proxyFromEnvironment support
      • prometheus upgraded from 2.52.0 to 2.53.0
      • grafana from 7.3.12 to 8.2.0
      • thanos ruler upgraded from 0.35.0 to 0.35.1
      • prometheus-node-exporter upgraded from 1.8.0 to 1.8.1
    • Replace in-addr.arpa records in zone label for coredns_cache_.* metrics due to large cardinality.
  • Removed

    • BREAKING Remove deprecated --enable-long-name flag (affected commands: kubectl gs template cluster/nodepool/networkpool/catalog)

    Changed

    • BREAKING When templating cluster manifests for CAPA clusters with kubectl gs template cluster command, now we set the workload cluster release version via the --release flag (like for vintage AWS), instead setting cluster-aws version via --cluster-version.
    • Update module version to v3.