Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Changelog v1.70.0
Know before update
falco_events
metric might be broken.ceph-csi
is enabled in the cluster. Usecsi-ceph
module.Features
containerd
to v1.7.27 with patches andrunc
to v1.2.5. #13205Containerd will restart.
update.node.deckhouse.io/reboot
is set. #13176cgroup
version stepbashible
label on node. #12911Deckhouse
fromNodeUser
manifests when cleaning up a static node. #12908kubernetes-api-proxy
. #12804Kubernetes-api-proxy will be restart.
bashible
step that assigns thenode.deckhouse.io/provider-id
annotation to nodes with astatic://
provider ID. #11807DVP
. #11649CSI controller
. #13339CSI controller
. #13339CSI controller
. #13339CSI controller
. #13339CSI controller
. #13339CSI controller
. #13339CSI controller
. #13339CSI controller
. #13339CSI controller
. #13339CSI controller
. #13339Node-to-node
encryption mode (was reverted in [cni-cilium] Revert adding the encryption mode. #13557). #12886etcd
backup. #13193opentelemetry
support. #12541descheduler
global parameters. #13248commander
mode returns always yes. #13292Dhctl in commander mode will skip draining errors.
automountServiceAccountToken
for all ServiceAccounts, enable in PodSpecs if necessary. #11962pkg/log
instead oflogrus
. #12733controllerLogLevel
parameter to theIngressNginxController
CR to configure the verbosity of ingress controller logs. #12920GeoIP
databases without restarting theingress-controller
pods. #11676istio-ca-root-cert
andIstioMulticluster/IstioFederation
resources after module disabling. #13229IstioMulticluster
remote cluster synchronization. #12799Istio
debugging resources to collect-debug-info. #12649Fixes
401
in bootstrap script. #13426bb-d8-node-name
insteadHOSTNAME
variable for getting current node name inbashible
step forGCP
. #13405Terraform
withOpenTofu
forDynamix
. #13402Terraform
withOpenTofu
forZvirt
. #13386OpenAPI
schemas for cloud discovery data. #13035dnf
package manager. #13026bashible
configure-kubelet step. #12722chrony
exporter CVE vulnerabilities. #13317kube-rbac-proxy
in cloud provider components. #13520terraform-provider-aws
to5.83.1
. #11546kube-rbac-proxy
in cloud provider components. #13520kube-rbac-proxy
in cloud provider components. #13520kube-rbac-proxy
in cloud provider components. #13520kube-rbac-proxy
in cloud provider components. #13520kube-rbac-proxy
in cloud provider components. #13520--cluster-name
CLI flag to thecloud-controller-manager
. #12950kube-rbac-proxy
in cloud provider components. #13520root_disk_size
. #12924kube-rbac-proxy
in cloud provider components. #13520VCDClusterConfiguration.provider.server
. #13204VCDCluster.spec.proxyConfigSpec
removed. #13138vAppTemplates
by an organization name in theVCDInstanceClass
resource. #13079kube-rbac-proxy
in cloud provider components. #13520settings.storageClass.compatibilityFlag
must be capitalized. #13434kube-rbac-proxy
in cloud provider components. #13520kube-rbac-proxy
in cloud provider components. #13520zVirt
cloud-discoverer panic. #13462EgressGateway
controller to clean up stale system node labels. #12971cilium
endpoint (cep) when higher/lower priority cep was removed/added. #12793etcd
. #13581CSE
edition build. #13312Reassembling all images.
/etc/systemd/system.conf.d/
. #12832descheduler
CVE vulnerabilities. #13306--force
flag to drain master nodes. #13423dhctl
CVE vulnerabilities. #13308Deckhouse
configuration forTerraform autoconverger
and converge from CLI. #13226bashible
already run. #13163kubeadm
command completion result. #12826PersistentVolumes
from being properly deleted by thedhctl destroy
command inStronghold
. #12814HostWithFailover
Inlet was reconfigured to another nodes or deleted. #13106enableIstioSidecar
whenHostWithFailover
is enabled. #12789cloud-provider-huaweicloud
module is enabled, defineRBAC
permissions granting thecloud-controller-manager
access to list pods in thed8-istio
namespace. #13270RBAC
rules to grant the HuaweiCloudcloud-controller-manager
permission to view pods in thed8-istio
namespace. #12951ModuleReleaseIsWaitingManualApproval
alert. #13429appendApprovalConditionfunc
filter csr status condition. #13461bashible apiserver
CVE vulnerabilities. #13314mcm
version to usenode manager token
insteadmcm
. #13305403
errors fromcapi-controller-manager
accessing theKubernetes API server
root path ('/'). #13125vSphere
provider during VM creation. #13083CAPS
. #11807BF-CBC
has been added to the optionsdata-ciphers-fallback
. #13647Aggregating-proxy will be rollout restarted with no disruption.
All components using kube-rbac-proxy will be restarted.
registry-packages-proxy
CVE vulnerabilities. #13307falco
. #13475falco
CVE vulnerabilities. #13318DexAuthenticator
with numbers in the name. #12902VPA
CVE vulnerabilities. #13319Chore
Kubernetes control-plane components will restart, kubelet will restart.
Kubernetes control-plane components will restart, kubelet will restart.
VCD provider
outputs logs in JSON format. #13183cni-cilium
CVE vulnerabilities. #13406ceph-csi
module (usecsi-ceph
instead). #13529Deckhouse will not update if
ceph-csi
is enabled in the cluster. Usecsi-ceph
module.additionalProperties
false
for all objects in openapi. #11832ingress-nginx controller
anddocumentation.d8-system
pod. #13539HSTS
for all module's Ingresses. #12705ingress-nginx
version1.12
. ThedefaultControllerVersion
is set to1.10
, all ingress controllers without specified version will restart. #12609OpenVPN
. #13061falco_events
metric. #13228Dashboards and alerts based on the
falco_events
metric might be broken.For more information, see the changelog and minor version release changes.