- breaking-change: A NodeClaim in a tenant's project resolves its OSImage as that tenant, so an image the tenant has not been granted reads as absent and the claim stays unprovisioned. Grant the images a tenant may boot through
spec.osImageson the Tenant, the way node types are already granted. (by @lizardruss in #8241) - bugfix: A project secret no longer loses its owner when it is read back. OIDC clients and database connectors are now served through the tenant-scoped client, so a tenant sees only its own and the platform's are hidden from it, an OIDC client created by a tenant is stamped with that tenant's ownership, and a connector assigned to a tenant is visible to it. Patching an OIDC client previously returned 404 and now works. (by @lizardruss in #8105)
- bugfix: A shared secret created by a tenant is now owned by that tenant. Shared secrets belonging to the platform are no longer listed to tenants. (by @lizardruss in #8068)
- bugfix: A tenant may no longer write instances it does not own. Instances an operator shares or grants to a tenant are readable but not writable by that tenant. (by @lizardruss in #8065)
- bugfix: A tenant-scoped list, collection delete or watch for a label selector that cannot be satisfied no longer ignores the selector and acts on every instance the caller can reach. (by @lizardruss in #8134)
- bugfix: A tenant-scoped watch no longer panics the API server when the client did not request an initial-events stream. Such a watch previously closed without explanation, and a client relying on it kept stale objects until it reconnected. (by @lizardruss in #8258)
- bugfix: A virtual cluster created by a platform admin inside a tenant's project is now stamped with that project's tenant, so the tenant can see it. A NodeClaim pinned to a specific machine is now confined to the machines its tenant owns or was assigned exclusively. (by @lizardruss in #8241)
- bugfix: Adopting an existing NICo OperatingSystem now reconciles
allowOverridetotrue, fixing permanent node provisioning failures when a conflicting record disallowed per-instance userData override. (by @roehrijn in #8221) - bugfix: Confirm Stack task removals before dependent task references are cleared. (by @andyluak in #8038)
- bugfix: Creating a tenant is now refused when the license's user limit is already reached, because a tenant's bootstrap admin user would exceed it. (by @johannesfrey in #8032)
- bugfix: Creating or updating a Tenant now fails immediately when its nico.vcluster.com/node-provider annotation names a NodeProvider that does not exist or is not a NICo provider. Create the NodeProvider before the Tenant that references it. (by @roehrijn in #8344)
- bugfix: Deleting a NetworkEnvironment now waits for NodeClaims bound to it in every phase, and a NetworkEnvironment reports NodeProviderNotFound or WaitingForNodeProvider when its NodeProvider is missing or not ready. (by @roehrijn in #8378)
- bugfix: Deleting a network environment is now blocked while any node claim holds it, including a claim on a different node provider and a claim whose project no longer allows the environment. (by @rlmcpherson in #8301)
- bugfix: Fixed a cross-tenant disclosure where a tenant administrator could read or overwrite another tenant's per-tenant configuration, including its SSO client secret, through the tenants/config subresource. (by @lizardruss in #8003)
- bugfix: Fixed the Metal3 node provider's DHCP proxy crash-looping without a secondary network interface when it was scheduled before the Multus CNI plugin finished installing. (by @roehrijn in #8261)
- bugfix: NICo NetworkEnvironment deletion no longer hangs when its provider-created VPC has Subnets. (by @roehrijn in #8342)
- bugfix: NICo REST client no longer wastes retry budget on non-retryable failures (unparseable responses, canceled contexts), and the readiness probe metric is now always registered. (by @roehrijn in #8118)
- bugfix: NICo os-image catalog entries the platform materializes are now deleted when the owning OSImage is deleted, instead of leaking permanently. (by @roehrijn in #8220)
- bugfix: Node providers are now gated on their license entitlement during reconcile as well as admission. A NICo node provider without the auto-nodes-nico entitlement is rejected at creation, and an existing provider whose entitlement is missing reports a FeatureNotAllowed condition instead of running ungated. (by @roehrijn in #8226)
- bugfix: Non-admin users can now create, view, update and delete their own SSH keys. Access to an SSH key is now decided by the key's owner and its spec.access rules, like other owned resources: the owner (or the members of an owning team) can view, update and delete it, and spec.access can share it with other users or teams. Installs where loft-management-authenticated carries loft.sh/skip-update: "true" do not receive the new create permission and must add it by hand. (by @roehrijn in #8324)
- bugfix: Offline licenses now enforce their resource limits. Creates are blocked while a limit is exceeded and allowed again once usage is back under it. (by @johannesfrey in #8096)
- bugfix: Proxied requests to a tenant cluster no longer hang when a network-peer tunnel stops passing traffic without closing. Each peer dial attempt is bounded to 5 seconds, a failed peer is quarantined for 30 seconds, and a request tries at most 3 candidate peers before failing over to a healthy peer or the agent connection. (by @roehrijn in #8127)
- bugfix: Tenants granted node types now see the node providers those types reference, so the create machine instance dialog and the Auto Nodes section of the virtual cluster template editor can resolve a provider for them. (by @lizardruss in #8089)
- bugfix: The platform agent now reloads a renewed webhook certificate secret (e.g. rotated by cert-manager) and updates the webhook caBundle without requiring a restart of the loft deployment. (by @johannesfrey in #7874)
- bugfix: The platform now reaps stale network peers whose disconnect cleanup was lost, so a tenant cluster no longer indefinitely routes to a peer that no longer exists. Stale-peer cleanup is consolidated into a single guarded sweep that cannot delete peers with live sessions. (by @rlmcpherson in #7618)
- bugfix: The project node types, templates and clusters endpoints now confine what they return to the tenant that owns the project, instead of returning every network environment, template and Control Plane Cluster on the platform. Naming another tenant's project on any of the three is refused. (by @lizardruss in #8027)
- bugfix: The vCluster agent proxy now reports the reason a request to a virtual cluster failed instead of returning an empty 502, which Kubernetes clients rendered as
an error on the server (""). (by @Piotr1215 in #7697) - bugfix: vCluster Platform now enables NICo phone home by default on the OperatingSystem and Instance records it creates for NICo NodeProviders. Set the
nico.vcluster.com/phone-home-enabledproperty tofalseto opt out. (by @roehrijn in #8175) - enhancement: Add unit pickers to project CPU, memory, and storage quotas. (by @andyluak in #8117)
- enhancement: Bump metal3 provider deploy chart values to latest. This will migrate Metal3/Ironic to a HA microservices mode, which will use a different DB. The single Pod mode is discontinued and only available by pinning a chart version for Metal3 <0.6.0. (by @squ94wk in #7890)
- enhancement: Filter machines by assignment, provider, and label, and assign matching machines across pages in one batch. (by @andyluak in #8172)
- enhancement: Grouped projects by tenant in the Provision Machine project dropdown. (by @andyluak in #8169)
- enhancement: Moved tenant management to a Tenants item under Platform and standardized its creation buttons to Create Tenant. (by @andyluak in #8168)
- enhancement: Network environments show their default status beside the provider, with an explanation of automatic selection, instead of a separate column. (by @andyluak in #8107)
- enhancement: Removed the platform breadcrumb bar and moved documentation links to the bottom bar. (by @andyluak in #8188)
- enhancement: The default vCluster version is now 0.37.0. (by @r0bnet in #8076)
- enhancement: With
admin.create=true, platform startup recreates a missing admin user and its credentials, including whenenv.DISABLE_DEFAULTS=true. Setadmin.create=falsebefore intentionally deleting the admin. Changingadmin.password, switching betweenadmin.passwordandadmin.passwordSecretRef, or changing the referenced Secret rotates the admin password after restart. Leaving these settings unchanged preserves a password set through the UI or CLI. Removing a customadmin.passwordoverride restores the chart default,my-password, and updates the admin password after restart. (by @neogopher in #8177) - enhancement: bootstrap admin user on tenant creation (by @seanschneeweiss in #7876)
- enhancement: bootstrap tenant's default project on tenant creation (by @seanschneeweiss in #7910)
- feature: A license can now limit how many tenants an installation may have, and creating a tenant is refused once that limit is reached. (by @johannesfrey in #8085)
- feature: Add network environment selection to instance provisioning flows. (by @andyluak in #7991)
- feature: Adds the cluster-scoped
connectors.management.loft.shAPI type, served from the existing connector Secrets. The resource is list-only in this change. (by @nprokopic in #8262) - feature: Cluster-scoped resources a tenant creates must now carry the tenant's name as a prefix (
<tenant>--<name>), so two tenants can use the same chosen name. Tenant names may no longer contain--and are limited to 32 characters. (by @johannesfrey in #8002) - feature: Metal3 node providers can now import bare metal machines from NetBox. Every NetBox device carrying the provider's tag becomes a platform machine and a BareMetalHost, kept in sync with NetBox; removing the tag stops the sync but never deprovisions hardware that is in use. (by @FabianKramm in #8170)
- feature: NICo node providers can use flat networking to provision hosts without DPUs. (by @janekbaraniewski in #7870)
- feature: Stack templates can now be duplicated from the UI, including certified templates. (by @andyluak in #8203)
- feature: Support platform-admin NICo networks and instances without platform multitenancy. Network environments require platform or tenant assignment at creation. (by @janekbaraniewski in #8101)
- feature: Tenant reads are scoped by the Tenant's capabilities. Each capability gates a management kind or group of kinds and narrows to particular instances through an allow selector, with
byLabels: {}matching everything and an unset capability denying the kinds it governs. Operators can assign an admin-owned instance to a single tenant with thetenant.vcluster.com/exclusive-tolabel. (by @lizardruss in #7941) - feature: The Tenant API replaces
spec.resourceAllowancesandspec.resourceQuotaswith per-capability fields (controlPlaneClusters,sshKeys,osImages,machines,nodeTypes,templates) and addsspec.platformConfig. Tenant hostnames move fromspec.hostnamesto thetenants/configsubresource, and are readable back onstatus.hostnameswhen a request passesextended=true. Setting them requiresupdateon the Tenant, not only access to that subresource. This is a breaking change to a pre-GA API that shipped only in v4.12.0 alpha and rc builds; no conversion path is provided. (by @lizardruss in #7913) - feature: The
connectors.management.loft.shAPI supports get, list, create, update, patch and delete for shared-database connectors. Connectors created through the API are ordinary connector Secrets to the UI and to every existing consumer. Credentials are served only to callers who may update the connector; a tenant reads the connectors assigned to it, redacted. (by @nprokopic in #8263) - feature: The platform now grants a NICo tenant account the TargetedInstanceCreation capability during onboarding, which is what a NodeClaim pinned to a machine with spec.machineRef needs. Existing per-site capability overrides are preserved. (by @mfranczy in #8008)
- fix: Fix Stack template parameter binding, unbinding, and certified-template cancellation behavior. (by @andyluak in #8043)
- fix: Fix incorrect and inconsistent blurring on the platform config page. (by @andyluak in #8115)
- fix: Fixed the Machines page's By Tenant search showing non-matching machines within matching groups. (by @andyluak in #8167)
- fix: Fixes Stacks permissions, published-output refresh, and long Stack template name presentation. (by @andyluak in #8034)
- fix: Hide platform-only Metal3 diagnostics from tenant users and redirect direct links to Machines Overview. (by @andyluak in #8174)
- fix: Improve Network Environment assignment and launch guidance, and remove Network Environment choices from tenant creation. (by @andyluak in #8281)
- fix: Improved Stack task dependency graphs, task ordering, and conditional App reference display. (by @andyluak in #8209)
- fix: Improved sidebar collapse and tenant switching interactions. (by @andyluak in #8207)
- fix: Prevent creating inaccessible instances without SSH keys or user data. (by @andyluak in #8079)
- fix: Prevent reassigning or unassigning network environments in the UI. (by @andyluak in #8108)
- fix: Remove the broken AWS, GCP, and Azure Auto Nodes quickstarts from infrastructure provider creation. (by @janekbaraniewski in #8246)
- fix: Remove the redundant ID line from the Node Claims table. (by @andyluak in #8114)
- fix: Removed the unreleased and unused
tenants/{name}/nicotokenmanagement API subresource. (by @roehrijn in #8205) - fix: Require platform or tenant assignment when creating network environments. (by @andyluak in #8161)
- fix: Team membership now resolves within a tenant. A tenant user only matches teams
in their own tenant, and a platform user only matches platform teams, so group names
such asloft:adminscan be reused across tenants without granting access outside
the tenant. A team that names a user from another tenant, by name or by group, does
not make that user a member. A request acting for a tenant cannot look up a user
outside that tenant. (by @seanschneeweiss in #8219) - fix: Updated machine status indicators and hid unavailable NICo power status. (by @andyluak in #7994)
- ui: Add alert in template marketplace for operators viewing tenant projects (by @PRTTMPRPHT in #8156)
- ui: Added screen-reader label to enabled switch in tenant form (by @PRTTMPRPHT in #8037)
- ui: Added tenant name prefixing to global entities (by @PRTTMPRPHT in #8054)
- ui: Added validation to object access section in tenant form (by @PRTTMPRPHT in #8035)
- ui: Refactor backing store detection logic (by @PRTTMPRPHT in #7667)