Bug Fixes
- gate Ingress website exposure behind ingress.enabled (#460) (#461) in #461 by @rajsinghtech
- skip ConnectNode for peers already up and avoid cross-cluster address fallback (#462) in #462 by @rajsinghtech
Documentation
- make the Ingress opt-in upgrade note safe for chart-bump version rewriting (#463) in #463 by @rajsinghtech
Release
- v0.8.1 by @rajsinghtech
Upgrade notes
- Ingress website exposure is now opt-in. v0.8.0 granted the operator cluster-wide
networking.k8s.io/ingresseswrite access and always watched Ingresses on every install. From v0.8.1 this is controlled by the chart valueingress.enabled(defaultfalse, likegatewayAPI.enabled), which renders the--enable-ingressflag (ENABLE_INGRESSenv var for non-Helm installs), the Ingress RBAC rules (ClusterRole and namespace-scoped Roles) and the Ingress watch. - If you use
spec.websiteExposure.ingress, setingress.enabled=true(for example--set ingress.enabled=true). With--reuse-valuesfrom v0.8.0 the new value is absent and renders as disabled, so pass it explicitly. Without it the bucket reportsWebsiteExposed=Falsewith reasonIngressDisabled; Ingresses already created by v0.8.0 stay in place and keep serving (and are still garbage-collected with their bucket) but are not reconciled or cleaned up until you enable it. Installs that do not use Ingress exposure need no change and now run without any Ingress RBAC. - Federation reconnects no longer redial remote peers that are already up, and a down peer with a known address is dialed at that address instead of the shared admin-endpoint host. This stops a reconnect pass from gossiping a cross-cluster-resolved address into the Garage peer book. No configuration change is needed.
- No CRD or API changes since v0.8.0, and the built-in Garage image is unchanged (v2.4.1).
- Rollback: reverting to v0.8.0 restores unconditional Ingress RBAC; no persisted state changes.
Contributors
Thanks to @Faustvii for reporting #460.
Full Changelog: v0.8.0...v0.8.1