The v2.8.0 release introduces a minor Terraform Azure provider upgrade, 10 new resources, a bug fix for namespaced resources, a new internal gRPC diff-service, and dependency updates.
- Upgrade of the underlying Terraform Azure provider from
v4.80.0tov4.81.0— additive, non-breaking field changes only (see below) (crossplane-contrib/provider-upjet-azure#1302) - Fixed: cluster-scoped
ProviderConfigresolution for namespaced resources (crossplane-contrib/provider-upjet-azure#1322) CustomDomain.containerappcertificate fields documentation corrected to reflect that certificate changes are applied in place rather than forcing recreation (crossplane-contrib/provider-upjet-azure#1285)- [Feature] New internal gRPC diff-service (
internal diff-servercommand) for offline Terraform plan/diff calculation, based on upjet's diff-service support (crossplane-contrib/provider-upjet-azure#1322) - [Feature] 10 new
cognitiveservices/machinelearningservicesresources (see below) (crossplane-contrib/provider-upjet-azure#1312) - [Feature] New
AccountProject.cognitiveservicesresource (crossplane-contrib/provider-upjet-azure#1304, fixes #1300) - Dependency updates:
upjetv2.5.1,crossplane-runtimev2.5.0-rc.0(adds PCU finalizer support, crossplane/crossplane-runtime#1113),crossplane/apisv2.4.2,controller-runtimev0.25.2,controller-toolsv0.22.0(CRDs regenerated), Go1.27.1,grpcv1.83.1[SECURITY]
There are no breaking API changes in this release.
Support for New Resources
AccountProject.cognitiveservicesAccountCustomerManagedKey.cognitiveservicesAccountConnectionAccountKey.cognitiveservicesAccountConnectionAccountManagedIdentity.cognitiveservicesAccountConnectionApiKey.cognitiveservicesAccountConnectionCustomKeys.cognitiveservicesAccountConnectionEntraId.cognitiveservicesDatastoreBlobStorage.machinelearningservicesDatastoreDataLakeGen2.machinelearningservicesDatastoreFileShare.machinelearningservicesInferenceCluster.machinelearningservices
Terraform provider upgrade: v4.80.0 → v4.81.0
All changes apply to both API scopes — cluster (<group>.azure.upbound.io) and namespaced (<group>.azure.m.upbound.io), and are backported to frozen v1beta1 spokes where a v1beta2 hub exists.
Non-breaking schema changes
New optional fields added; no field removed or made required.
Logger.apimanagement (v1beta1 + v1beta2):
applicationInsights.identityClientId— new optional field (identity-based Application Insights authentication)
LinuxVirtualMachineScaleSet.compute / WindowsVirtualMachineScaleSet.compute (v1beta1 + v1beta2):
dataDisk.diskIopsReadWrite/dataDisk.diskMbpsReadWrite— new optional fields (aliases alongside the existingultraSsdDiskIopsReadWrite/ultraSsdDiskMbpsReadWrite, applicable toPremiumV2_LRSdisks too)
OrchestratedVirtualMachineScaleSet.compute (v1beta1 + v1beta2):
networkInterface.tags— new optional field
PrivateEndpoint.network (v1beta1 + v1beta2):
edgeZone— new optional field
Vault.keyvault (v1beta1 + v1beta2):
rbacAuthorizationEnabled— documentation clarified (defaults tofalse); no schema change
Offline Diff Server (alpha)
This provider now support an offline gRPC-based diff server that computes diffs/plans for managed resources without connecting to Kubernetes or making cloud API calls.
The diff server allows users to preview what would change before applying a resource, without interacting with live infrastructure.
Key capabilities:
- Computes
CREATE,UPDATE,REPLACE, andNO_OPactions from the desired resource and its optional observed state. - Reports field-level changes, including planned values, replacement requirements, and change origins.
- Accepts a PlanRequest with the desired resource, an optional actual resource, and an in-memory store containing the required ProviderConfig and referenced Secrets.
- Supports both namespaced and cluster-scoped managed resources, including previously served API versions.
- Runs without cloud credentials or live infrastructure access.
- Exposes the
PlanService.PlangRPC API through theinternal diff-serversubcommand. Support is advertised through theDiffServerpackage capability.
Known limitations:
- Some resources require cloud API calls during planning and cannot be fully evaluated offline. These requests may return
FAILED_PRECONDITION, allowing callers to fall back to a raw diff. - Accurate plans depend on a complete observed state. Missing fields in
status.atProvidermay produce unexpected changes. - The gRPC API is experimental and may change without backward compatibility guarantees.
Resource coverage and planning behavior may vary between providers.
What's Changed
- docs(containerapp): fix CustomDomain certificate field descriptions by @jonasz-lasut in #1285
- Update go module directive to v1.26.6 by @renovate[bot] in #1287
- Update negz/create-tag action to v2 by @renovate[bot] in #1289
- Update to crossplane-runtime v2.4.0 by @jonasz-lasut in #1293
- Add example manifest linter to CI by @sergenyalcin in #1296
- Consume crossplane-runtime #1113 by @jonasz-lasut in #1301
- feat(cognitiveservices): add AccountProject resource by @saschajohn in #1304
- Update underlying terraform provider fork to 4.81.0 by @jonasz-lasut in #1302
- Update go module directive to v1.26.8 by @renovate[bot] in #1290
- Update dependency golangci/golangci-lint to v2.13.2 by @renovate[bot] in #1292
- Update dependency kubernetes-sigs/kind to v0.33.0 by @renovate[bot] in #1297
- Update module google.golang.org/grpc to v1.83.1 [SECURITY] by @renovate[bot] in #1299
- Update module github.com/crossplane/upjet/v2 to v2.5.0 by @renovate[bot] in #1310
- Update module github.com/crossplane/crossplane/apis/v2 to v2.4.2 by @renovate[bot] in #1308
- Update alpine Docker tag to v3.24.2 by @renovate[bot] in #1307
- Update all non-major github action by @renovate[bot] in #1311
- Update module github.com/crossplane/upjet/v2 to v2.5.1 by @renovate[bot] in #1314
- Update dependency golangci/golangci-lint to v2.14.0 by @renovate[bot] in #1315
- Update jlumbroso/free-disk-space action to v2 by @renovate[bot] in #1320
- Update dependency ubuntu to v26 by @renovate[bot] in #1319
- Update module sigs.k8s.io/controller-runtime to v0.25.2 by @renovate[bot] in #1317
- Update kubernetes patches to v0.37.1 by @renovate[bot] in #1321
- Update module sigs.k8s.io/controller-tools to v0.22.0 by @renovate[bot] in #1318
- Update dependency crossplane/crossplane to v2.4.2 by @renovate[bot] in #1294
- Update go module directive to v1.27.1 by @renovate[bot] in #1291
- Add a gRPC diff service implementation by @sergenyalcin in #1322
- Update actions/upload-artifact action to v7.0.2 by @renovate[bot] in #1323
- Add remaining
cognitiveservicesresources by @jonasz-lasut in #1312 - Update golang.org/x/crypto to v0.56.0 to remediate CVEs by @jonasz-lasut in #1325
New Contributors
- @saschajohn made their first contribution in #1304
Full Changelog: v2.7.0...v2.8.0