github cilium/tetragon v1.5.0

one month ago

Upgrade notes

Read the upgrade notes carefully before upgrading Tetragon.
Depending on your setup, changes listed here might require a manual intervention.

  • Enabling ancestors for process events is now configured by a new --enable-ancestors flag.
    The following flags are being deprecarted in this (1.5) and are scheduled for removal in the next (1.6):

    • --enable-process-ancestors
    • --enable-process-kprobe-ancestors
    • --enable-process-tracepoint-ancestors
    • --enable-process-uprobe-ancestors
    • --enable-process-lsm-ancestors
  • The logging library used by Tetragon is migrated from logrus to log/slog.
    This change is not expected to affect the end user, but it may require some adjustments in custom scripts or tools
    that parse Tetragon logs.

    • level=warning is now level=warn

Helm Values

  • The default value of metrics scrape interval in both agent and operator
    ServiceMonitors (tetragon.prometheus.serviceMonitor.scrapeInterval and
    tetragonOperator.prometheus.serviceMonitor.scrapeInterval values
    respectively) is changed from 10s to 60s.

  • OciHookSetup section is removed after being deprecated in 1.2.

Changes from v1.4.1 to v1.5.0

total: 391 commits, prs: 182 pr commits: 390

Major Changes

Bugfixes

  • helm: fix extraHookargs in rthooks (#3566) by @kkourt
  • Fix event source pod attribution when env var HUBBLE_NODE_NAME is set (#3609) by @odinuge
  • fix(chart): correct operator securityContext values (#3681) by @JefeDavis
  • tracingpolicy: fix issue in argument order with the resolve argument option (#3737) by @kkourt
  • Fix an issue where inInitTree was not properly accounting processes started before Tetragon. (#3827) by @will-isovalent
  • tracinpolicy: respect syscall attribute in lists (#3895) by @kkourt
  • Fixes load sensor failure when mixing rate limited and non rate limited kprobes. (#3903) by @mtardy
  • bpf: fix issue with multiple inactive selectors (#3947) by @kkourt

Minor Changes

CI Changes

Documentation changes

Dependency updates

  • chore(deps): update renovatebot/github-action action to v42 (main) (#3754) by @cilium-renovate[bot]
  • deps: update controller-tools to v0.18.0 and k8s to v0.33.0 (#3768) by @mtardy
  • update cilium/ebpf to v0.19.0 (#3849) by @lmb

Misc Changes

Don't miss a new tetragon release

NewReleases is sending notifications on new releases.