github deckhouse/deckhouse v1.29.0-alpha.3
Deckhouse v1.29.0-alpha.3

latest releases: v1.61.3, v1.61.2, v1.60.6...
pre-release2 years ago

Changelog v1.29.0-alpha.3 since v1.28.0

Components that will be restarted during the update

  • Grafana
  • bashible-api-server
  • control-plane-manager
  • cert-manager
  • chrony
  • upmeter

Significant Changes

Bump Grafana version to fix zero-day path

The certmanager.k8s.io/v1alpha1 API version is no longer supported

Other Changes

[bashible]

  • fixes
    • fix incorrect auth value for containerd config only
    • Cluster bootstrap on Azure works for Ubuntu 20.04

[cert-manager]

  • features
    • Upgrade cert-manager to v1.6.1
      • Pull request
      • NOTE! cert-manager controller will be restarted. Cert-manager's CRD with version v1/alphaX is no longer supported
    • Instructions for connection Vault with cert-manager

[chrony]

  • fixes
    • Fixed rollout restart time of chrony daemonset.

[deckhouse]

  • fixes
    • clear values cache when module disabled
    • Move context generation into bashible-apiserver
    • Fix Deckhouse Manual update mode.

[deckhouse-web]

  • fixes
    • Added missing 'ca.crt' field to internal values schema

[log-shipper]

  • features
    • Support storing data in Elasticsearch datastreams
  • fixes
    • Fix default CRD values
      • Pull request
      • NOTE! ClusterLogDestination created in v1.29.0-alpha should be recreated

[monitoring-kubernetes]

  • fixes
    • Fixed description for alert NTPDaemonOnNodeDoesNotSynchronizeTime.
      • Pull request
      • NOTE! We only use the Deckhouse chrony module, so a description about another NTP daemons is not needed.

[node-manager]

  • features
    • Added delete pods from node that requests disruption update when pod eviction is failed.

[prometheus]

  • features
  • fixes
    • Bump Grafana version to fix zero-day path traversal bug (CVE-2021-43798)

[secret-copier]

  • features
    • Implement create–or–update logic for proper reconcile.
      • Pull request
      • NOTE! Add support of namespace label-selector in secret-copier.deckhouse.io/target-namespace-selector annotation value.

[yandex-cloud-provider]

  • fixes
    • Add additionalExternalNetworkIDs config in OpenAPI spec, because Deckhouse does not converge if this field exists in a cluster.

[‎ingress-nginx‎]

  • features
    • Add the ability to set a default certificate.

Don't miss a new deckhouse release

NewReleases is sending notifications on new releases.