Changes and Releases

Updates on Giant Swarm workload cluster releases, apps, UI improvements and documentation changes.

  • Changed

    • Chart: Sync to upstream. (#938)
      • Controller: Update image to v1.14.3.
      • Kube Webhook CertGen: Update image to v1.6.7.
  • Changed

    • Chart: Sync to upstream. (#937)
      • Controller: Update image to v1.13.7.
      • Kube Webhook CertGen: Update image to v1.6.7.
  • Fixed

  • Added

    • Add Network Traffic Analysis Overview dashboard

    Changed

    • Improve Network Traffic Analysis Dashboard Performance
      • [performance] Re-use panel queries, which gladly reduces the number of queries made to the backend, and ease maintenance
      • [performance] Change Pie Charts query types from range to instant
      • [performance] Set maximum datapoints to 500 and minimal interval to 2mn
      • [ux] Change destination pie charts to only show top 10 destinations
      • [ux] Change the top list panels to use pagination rather than only showing top 10 elements
      • [ux] Change bottom graphs to use stacked lines and added list of values + total count
      • [ux] Remove the per-namespace section which was merely a duplicate of the top one with additional namespace filter. All panels now have a namespace filter which default to all namespace, therefore keeping the old behavior of the top panels and also allowing behavior of the bottom ones at the same time.
      • [ux] Add links between both Network Traffic Analysis dashboards
      • [ux] Add Include non-namespaced toggle to filter/include non-namespaced network traffic
      • [ux] Improve documentation panel
      • [ux] Add annotations for CiliumNetworkPolicies events
      • [ux] Change Legend set to “unknown” when no value is found
      • [ux] Show percentage and all values in tooltip on destination panels
      • [maintenance] Move subnets regex to a constant
    • NGINX Ingress controller dashboard: reworked variables
      • removed app selector
      • removed namespace selector
      • added ingress namespace selector

    Removed

    • Remove logging-operator related data as it is now deprecated.
  • Changed

    • Fix HTTPRoute template.
    • Add HTTPRouteFilter.
  • Changed

    • Build with up-to-date pipelines.
    • Enable TLS secret configuration for the ingresses. The default now changes to having a single shared secret per host in one namespace to avoid Let’s Encrypt rate limiting
    • Add Gateway API and Envoy Gateway resources.
  • Added

    • Add Crossplane support for automated S3 bucket provisioning on CAPA (AWS) clusters
      • New Crossplane configuration under top-level crossplane
      • Automatic S3 bucket creation via Crossplane with lifecycle policies
      • IAM role and policy management for IRSA authentication
      • Two-phase migration support: observe mode and full management mode
      • Automatic tag inheritance from AWSCluster CR
      • Dynamic AWS account ID and OIDC provider lookup from cluster resources
  • Added

    • Add OAuth2 PKCE authentication support for MCP servers with custom authenticator and CIMD router.
    • Add authentication provider support and multi-installation features for MCP servers.
    • Add MCP resources loading exposed as callable tools.

    Fixed

    • Fix GitOpsCard source URL generation for Flux CD revision formats like main@sha1:abc123 and sha256:abc123.
    • Improve container registry error handling with user-friendly messages for missing repositories. See ./docs/releases/v0.101.0-changelog.md for more information.
  • Changed

    • Build with up-to-date pipelines.
    • Upgrade to sloth 0.15.0
  • Changed

    • Build with up-to-date pipelines.
    • Migrate to App Build Suite (ABS).