- : NONE (by @sowmyav27 in #7168)
- : NONE (by @roehrijn in #7210)
- bugfix: Fix node environment teardown getting stuck when the OpenTofu workspace was already deleted. (by @seanschneeweiss in #7304)
- bugfix: Fixed Grafana SSO for the default platform admin and any user without an email set, who previously could not sign in to the Fleet Observability Grafana. (by @johannesfrey in #7480)
- bugfix: Fixed a race in the access-keys controller that could permanently delete a freshly-created login access key before its owning user was observed by the controller's cache, causing login failures. (by @roehrijn in #7429)
- bugfix: Fixed an issue where deleting a user or team could remove the owner (and owner access) of projects and other resources owned by unrelated users or teams. (by @roehrijn in #7136)
- bugfix: Fixed the Fleet Observability Grafana and Prometheus apps hardcoding the
loftnamespace, which broke pod startup, SSO login, and OIDC token exchange on platforms not installed inloft. The deploy namespace is now a configurabledestinationNamespaceparameter. (by @johannesfrey in #7456) - bugfix: Pre-release upgrade checks (Platform) now resolve the vcluster upgrade-version correctly when the platform base's DefaultVClusterVersion already equals the latest vcluster-pro GA, and no longer pick a release candidate as the upgrade target due to
sort -Vnot honoring SemVer pre-release ordering. (by @sowmyav27 in #7192) - bugfix: Stop the Fleet Observability Prometheus backend from emitting continuous TLS handshake errors by disabling the config-reload sidecar that cannot speak mTLS and tuning its health probes. (by @johannesfrey in #7489)
- bugfix: Tolerate a trailing slash in the Fleet Observability Grafana platformHost (by @johannesfrey in #7524)
- deprecation: The API for moving virtual cluster instances between projects (
projects.management.loft.sh/migratevirtualclusterinstance) is deprecated and will be removed in a future release. (by @seanschneeweiss in #7276) - enhacement: OIDC token exchange endpoint can support ADFS access_token_issuer non-standard behavior when "LOFT_OIDC_TRUST_ACCESS_TOKEN_ISSUER=true" env var is set. (by @matskiv in #7299)
- enhancement: Improve metal3 UX (by @squ94wk in #7445)
- enhancement: Minor UX improvements to vMetal (by @squ94wk in #7511)
- enhancement: Run the pr-labelled e2e Ginkgo suite against each published release tag to certify the release. (by @sowmyav27 in #7290)
- enhancement: vCluster Platform's managemet.loft.sh API now supports ValidatingAdmissionPolicy resources (by @matskiv in #7300)
- feature: A NICo VPC or VPC prefix adopted through the nico.vcluster.com/vpc-id or nico.vcluster.com/vpc-prefix-id property is now retained when its NodeEnvironment is torn down, instead of being deleted. Adopted resources are recorded in the nico.vcluster.com/adoptions annotation; resources the platform created are still deleted. (by @roehrijn in #7702)
- feature: Add
forwardTokenMode(Off/TokenReview/Passthrough) for tenant clusters. Passthrough forwards the caller's token directly to the tenant cluster's API server without a TokenReview or impersonation. TheforwardTokenboolean is deprecated but still honored. (by @lizardruss in #7191) - feature: Add
metrics-readerandmetrics-writeraccess-key scope roles for the upcoming monitoring gateway. Scoped access keys now have their SelfSubjectAccessReview responses re-checked against the key's per-cluster scope, so a self review never reports more access than the key can actually exercise. The defaultloft-management-adminrole grantsmetricsreadon clusters and virtual cluster instances; per-instance metrics reads for project members are gated through each instance's owner access. (by @johannesfrey in #7108) - feature: Adds Collector ArgoCD Template for Fleet Observability (by @seanschneeweiss in #7295)
- feature: Argo CD Template for installing the Fleet Observability metrics backend. (by @seanschneeweiss in #7294)
- feature: Introducing Fleet Observability for platform wide overview on tenant clusters. (by @seanschneeweiss in #7291)
- feature: Tenant users can mint short-lived NICo API tokens via the new
nicotokenTenant subresource. (by @janekbaraniewski in #7683) - feature: Tenants can reserve NICo compute capacity per node type through a
nodeclaimsresource quota, and can be given NICo address space for private nodes. A quota entrytype=<nodeType>reserves that many instances of the node type's NICo instance type.nico.vcluster.com/ip-block-prefix-lengthcarves a tenant IP block from the provider's site block, ornico.vcluster.com/ip-block-idadopts an existing one. (by @janekbaraniewski in #7611) - feature: The nico.vcluster.com/org annotation on a platform Tenant is now immutable once set; it can no longer be changed or removed (initial opt-in from unset remains allowed). (by @roehrijn in #7610)
- fix: A Tenant refused by the NICo provider-org guard no longer records a partial status.nico. (by @janekbaraniewski in #7708)
- fix: Improve cluster overview usage view toggle labels, prevent node claims status column clipping on resize, and fix tenant cluster API client paths to use the project-scoped virtualcluster route. (by @andyluak in #7109)
- fix: NICo NodeTypes now advertise cpu and memory resources parsed from scout-reported capability values, making dynamic node pools schedulable. (by @janekbaraniewski in #7703)
- fix: NICo autoNodes environments created through a VirtualClusterInstance no longer fail with a missing tenant label. (by @janekbaraniewski in #7686)
- fix: NICo node types now report capacity from machines assigned to the instance type instead of tenant reservations, so available nodes no longer show as 0 on sites without tenant allocations. (by @janekbaraniewski in #7722)
- fix: NICo operating systems created by the platform now permit the per-node join userData, fixing instance creation against current NICo. (by @janekbaraniewski in #7685)
- fix: The NICo provider now picks up platform signing-key rotation and platform host changes without recreating the NodeProvider. (by @janekbaraniewski in #7687)
- ui: Add redirect to virtual machines list if vm is deleted on details page (by @PRTTMPRPHT in #7229)
- ui: Added "no actions" context menu for empty items in VM graph (by @PRTTMPRPHT in #7242)
- ui: Added clear button for certificate secret names in observability form (by @PRTTMPRPHT in #7516)
- ui: Added contextual docs links to breadcrumb (by @PRTTMPRPHT in #7075)
- ui: Added graph view in virtual machine details (by @PRTTMPRPHT in #7196)
- ui: Added loading spinner to pod logs when the pod is still starting (by @PRTTMPRPHT in #7424)
- ui: Added separate power status tracking for BMHs (by @PRTTMPRPHT in #7056)
- ui: Added validation against missing node pools when creating auto nodes clusters (by @PRTTMPRPHT in #7053)
- ui: Applied new header style across all main pages (by @PRTTMPRPHT in #7110)
- ui: Changed host cluster drilldown to match established drilldown styles (by @PRTTMPRPHT in #7225)
- ui: Ensured auto-generated access rule is disabled in tenant cluster configuration (by @PRTTMPRPHT in #7422)
- ui: Fix 404 errors being logged on the details page of a stopped kubevirt VM (by @PRTTMPRPHT in #7446)
- ui: Fixed actions availability for virtual machines (by @PRTTMPRPHT in #7234)
- ui: Fixed application of default tooltips to status badges to correct positioning (by @PRTTMPRPHT in #7392)
- ui: Fixed capitalization of VPN table headers (by @PRTTMPRPHT in #7163)
- ui: Fixed detection of error state for KubeVirt data volumes (by @PRTTMPRPHT in #7235)
- ui: Fixed hover state for user row in sidebar (by @PRTTMPRPHT in #7164)
- ui: Fixed infinite loading state of nodes table for pending tenant cluster (by @PRTTMPRPHT in #7565)
- ui: Fixed some minor display issues in cluster details view (by @PRTTMPRPHT in #7554)
- ui: Made template names wrap in template marketplace (by @PRTTMPRPHT in #7159)
- ui: Removed template entry from tenant cluster header (by @PRTTMPRPHT in #7184)
- ui: Revamped tenant cluster status page (by @PRTTMPRPHT in #7040)