Summary
This release adds new Identity Governance access package resources, introduces an internal gRPC diff-server for Crossplane's diff tooling, and includes security fixes and dependency updates.
Highlights
- New Resources — Identity Governance Access Packages: Added
AccessPackage,AccessPackageAssignmentPolicy,AccessPackageCatalog,AccessPackageCatalogRoleAssignment,AccessPackageResourceCatalogAssociation, andAccessPackageResourcePackageAssociation(both cluster-scoped and namespaced variants) - New Internal Command — gRPC Diff Server: Added an
internal diff-serversubcommand that serves the provider's diff gRPC service over an offline-configured Terraform setup, for use by Crossplane's diff tooling - Enhancement: Added an
--enable-secret-cacheflag (defaulttrue) to control whetherSecretobjects are served from the informer cache or fetched directly from the API server - Fix: Prefer
AZURE_FEDERATED_TOKEN_FILEover the hardcoded OIDC token path when configuring federated identity credentials - CI: Added an example manifest linter to catch malformed example YAML
- Security: Updated
google.golang.org/grpctwice (v1.83.1, then v1.83.2) to remediate vulnerabilities
Offline Diff Server (alpha)
This provider now support an offline gRPC-based diff server that computes diffs/plans for managed resources without connecting to Kubernetes or making cloud API calls.
The diff server allows users to preview what would change before applying a resource, without interacting with live infrastructure.
Key capabilities:
- Computes
CREATE,UPDATE,REPLACE, andNO_OPactions from the desired resource and its optional observed state. - Reports field-level changes, including planned values, replacement requirements, and change origins.
- Accepts a PlanRequest with the desired resource, an optional actual resource, and an in-memory store containing the required ProviderConfig and referenced Secrets.
- Supports both namespaced and cluster-scoped managed resources, including previously served API versions.
- Runs without cloud credentials or live infrastructure access.
- Exposes the
PlanService.PlangRPC API through theinternal diff-serversubcommand. Support is advertised through theDiffServerpackage capability.
Known limitations:
- Some resources require cloud API calls during planning and cannot be fully evaluated offline. These requests may return
FAILED_PRECONDITION, allowing callers to fall back to a raw diff. - Accurate plans depend on a complete observed state. Missing fields in
status.atProvidermay produce unexpected changes. - The gRPC API is experimental and may change without backward compatibility guarantees.
Resource coverage and planning behavior may vary between providers.
Dependency Updates
- Updated crossplane-runtime to v2.4.0
- Updated upjet to v2.5.1
- Updated controller-runtime to v0.25.2
- Updated controller-tools to v0.22.0
- Updated Go to 1.27.1
- Updated google.golang.org/grpc to v1.83.2 [SECURITY]
- Updated Crossplane to v2.4.2
- Updated Alpine base image to v3.24.2
- Updated kind to v0.33.0
- Updated golangci-lint to v2.14.0
- Updated Kubernetes patches to v0.37.1
- Updated CI runner to ubuntu-26
What's Changed
- fix: prefer AZURE_FEDERATED_TOKEN_FILE over hardcoded OIDC token path by @gravufo in #368
- Add Identity Governance resources by @daftping in #369
- Update go module directive to v1.26.6 by @renovate[bot] in #370
- Update negz/create-tag action to v2 by @renovate[bot] in #371
- Update crossplane-runtime to v2.4.0, consume performance improvements by @jonasz-lasut in #376
- Add example manifest linter to CI by @sergenyalcin in #378
- Consume crossplane-runtime #1113 by @jonasz-lasut in #382
- Update go module directive to v1.26.8 by @renovate[bot] in #373
- Update dependency golangci/golangci-lint to v2.14.0 by @renovate[bot] in #375
- Update dependency kubernetes-sigs/kind to v0.33.0 by @renovate[bot] in #380
- Update module google.golang.org/grpc to v1.83.1 [SECURITY] by @renovate[bot] in #381
- Update docker/setup-qemu-action digest to 9901266 by @renovate[bot] in #384
- Update alpine Docker tag to v3.24.2 by @renovate[bot] in #385
- Update module github.com/crossplane/crossplane/apis/v2 to v2.4.2 by @renovate[bot] in #387
- Update dependency ubuntu to v26 by @renovate[bot] in #393
- Update jlumbroso/free-disk-space action to v2 by @renovate[bot] in #394
- Update module google.golang.org/grpc to v1.83.2 [SECURITY] by @renovate[bot] in #395
- Update module github.com/crossplane/upjet/v2 to v2.5.1 by @renovate[bot] in #390
- Update module sigs.k8s.io/controller-runtime to v0.25.2 by @renovate[bot] in #391
- Update go module directive to v1.27.1 by @renovate[bot] in #374
- Update kubernetes patches to v0.37.1 by @renovate[bot] in #396
- Update module sigs.k8s.io/controller-tools to v0.22.0 by @renovate[bot] in #392
- Update dependency crossplane/crossplane to v2.4.2 by @renovate[bot] in #377
- Add a gRPC diff service implementation by @ulucinar in #383
Full Changelog: v2.4.0...v2.5.0