0.157.0
💡 Enhancements 💡
-
target allocator: Allow enabling mTLS between the target allocator and the collector using user-provided certificate Secrets, without requiring cert-manager. (#3982)
Whenspec.targetAllocator.mtls.useCertManageris set tofalse, the newmtls.tlsblock
references user-provided certificates. The CA certificate may be sourced from either a Secret or a
ConfigMap (certificateAuthorityCertificate.secret/.configMap). The target allocator's server
certificate and the collector's client certificate each reference their certificate and private key
independently, so the certificate and key may live in different Secrets. Data keys default to
tls.crt,tls.keyandca.crtand can be overridden per reference. The CA reference is required
in this mode. -
operator: Add support for Kubernetes 1.36 (#5354)
🧰 Bug fixes 🧰
target allocator: Seed Prometheus's scrape labels (job,__scheme__,__metrics_path__,__scrape_interval__,__scrape_timeout__,__param_*) before relabel filtering, so keep/drop rules referencing them make the same decisions as Prometheus instead of silently dropping or over-allocating targets (#5246)
The seeded labels also feed the target identity hash, matching Prometheus's post-relabel label partition more closely. With therelabel-configfilter strategy enabled, existing targets are re-allocated once on upgrade because their hashes change. The served (pre-relabel) target labels are unchanged.
Components
- OpenTelemetry Collector - v0.157.0
- OpenTelemetry Contrib - v0.157.0
- Java auto-instrumentation - v2.30.0
- .NET auto-instrumentation - v1.16.0
- Node.JS - v0.78.0
- Python - v0.64b0
- Go - v0.24.0
- ApacheHTTPD - 1.0.4
- Nginx - 1.0.4
0.157.0
💡 Enhancements 💡
auto-instrumentation: Theautoinstrumentation-dotnetimage now bundles the correct native profiler for the platform it is pulled for, fixing arm64 support (the image was already published for arm64 but always contained amd64 binaries). (#3270)operator-opamp-bridge: Adds support for the OpAMP capability AcceptsRestartCommand to the operator's OpAMP bridge, allowing the operator to restart the collector when requested by an OpAMP server. (#5306)operator-opamp-bridge: Add anopentelemetry.io/opamp.bridge.modenon-identifying OpAMP AgentDescription attribute so servers can distinguish operator and standalone bridge clients. (#5423)operator-opamp-bridge: Report the operator-opamp-bridge's own build version asservice.versionin its OpAMP AgentDescription, instead of always sending an empty string. (#5360)collector: Add support for settingsessionAffinityandsessionAffinityConfigon the Services created for the Collector (#4455)target allocator: Support exporting the TargetAllocator's self-telemetry metrics via OTLP, in addition to the Prometheus /metrics endpoint. (#5047)
Configure it underspec.targetAllocator.telemetry.metrics.otlp(OpenTelemetryCollector CR) or
spec.telemetry.metrics.otlp(TargetAllocator CR), with endpoint, protocol (grpc/http), temporality,
headers, TLS and export interval/timeout. Metrics registered directly on the Prometheus registry
(Prometheus service discovery, Go runtime and process collectors) are bridged into the OTLP export
so the Prometheus endpoint and OTLP expose the same metric set.
🧰 Bug fixes 🧰
-
cluster-observability: Fix dependencies required by the bundled agent and cluster Collector configurations (#3821, #3818)
Follow-ups to the initial ClusterObservability framework so generated
Collectors start cleanly across supported distributions:- Use K8s Collector distribution for the agent and cluster Collectors,
defaulting to the operator's Collector version and supporting the
--clusterobservability-collector-imageoverride. Apply matching version
labels and canonical component IDs. - Inject
K8S_NODE_NAME, which the bundledkubelet_statsreceiver uses
for its endpoint. - Report cluster Collector readiness from its StatefulSet so
ClusterObservabilitydoes not remainPendingafter the workload is ready. - Mount the host root at
/hostfsforhost_metricsand exclude virtual
and container-runtime filesystems that cannot be scraped reliably. - On OpenShift, run the agent under the generated
spc_tSCC sofile_log
can read root-owned container logs under/var/log/pods. - On OpenShift, verify kubelet TLS with the platform serving CA.
- Point generated
Instrumentationresources to the agent's OTLP/HTTP port
because auto-instrumentation SDKs commonly usehttp/protobuf.
- Use K8s Collector distribution for the agent and cluster Collectors,
-
collector: Fix OpenShift collector dashboard (#5342)
The collector v0.155.0 renamed the deprecatedotelcol_processor_accepted_*/dropped_*/refused_*metrics
tootelcol_processor_memory_limiter_*(open-telemetry/opentelemetry-collector#11203).
The dashboard queries have been updated to use the new metric names. -
collector: Register the snake-case spellings of several renamed receivers (kubelet_stats,k8s_objects,resource_detection,fluent_forward,tcp_log,udp_log,ssh_check,cloud_foundry,http_check,flink_metrics) alongside their original spellings when generating RBAC and service ports from a Collector CR, so either spelling produces the same result. (#5317)
These components were renamed to snake_case in opentelemetry-collector-contrib
(#47957 kubeletstats, #47440 k8sobjects, #48525 resourcedetection, #47930
fluentforward, #47369 tcplog, #47370 udplog, #47515 sshcheck, #47932
cloudfoundry, #47505 httpcheck, #47929 flinkmetrics) while keeping the
original names accepted, but the operator only recognized one spelling per
component, so configs using the other spelling got no RBAC/ports or the
wrong service port name. This extends the k8s_attributes fix (#4983) to
the remaining renamed components, and makesNewScraperParseraccept
aliases so future renames of this kind are a one-line fix. -
target allocator: Fix collector mtls with a TargetAllocator CR (#4297)
This only affected collectors associated with a TargetAllocator CR whose name differs from the
collector's, e.g. via theopentelemetry.io/target-allocatorlabel, causing them to address the
wrong hostname (and TLS certificate) once mTLS was enabled. -
target allocator: Refresh stale Prometheus meta labels (e.g.__meta_kubernetes_pod_name) on rediscovered targets whose address is unchanged (#4839)
Target identity is deliberately hashed without meta labels, since Prometheus discards them after
relabeling. But because the allocator's target map is keyed by that same hash, a rediscovered
target whose address is unchanged (e.g. a hostNetwork DaemonSet pod after a restart) was never
recognized as changed, so its stale meta labels persisted until target-allocator itself restarted. -
collector: Fix operator crash on startup when Gateway API CRDs are not installed by moving gatewayv1 scheme registration to be gated on autodetect result. (#5357) -
auto-instrumentation: Apply security context to Java extension init containers (#5335)
Extension init containers injected alongside the Java agent were not receiving
a security context. This affected both the explicitspec.initContainerSecurityContext
field on the Instrumentation CR and the fallback behaviour that inherits the
security context from the instrumented application container. Only the main
opentelemetry-auto-instrumentation-javainit container was having its security
context set; extension containers were always created with a nil security context.
This caused admission failures on clusters with policies that require all
containers to drop capabilities or disallow privilege escalation (e.g. OPA
Gatekeeper). The security context is now applied to all Java-related init
containers at construction time. -
target allocator: Propagate the TargetAllocator CR's metadata annotations to all resources created for it, and restrictpodAnnotationsto the pod template (#4393)
This aligns the TargetAllocator with the OpenTelemetryCollector behavior: CR metadata annotations now land
(respecting the annotations filter) on the Deployment, Service, ConfigMap, ServiceAccount, ServiceMonitor,
PodDisruptionBudget and NetworkPolicy, whilepodAnnotationsis no longer copied to the NetworkPolicy and
PodDisruptionBudget.