github robintra/perf-sentinel chart-v0.25.3
perf-sentinel chart v0.25.3

4 hours ago

What's new in chart-v0.25.3

appVersion moves to 0.25.3 and image.tag follows it to :0.25.3. No template logic changes and no values.yaml key is added or removed. The comments of values.yaml, of the templates and of the chart README are reworded, and some of them sit inside the default perf-sentinel.toml: under the default values the rendered file goes from 5047 to 5036 bytes, 11 comment lines replaced by 10, and no other line differs.

What moves inside the pod

A pod no longer starts on two warnings it could do nothing about. The chart puts the ack store at the root of its persistent volume, which the pod's fsGroup leaves owned by root, mode 2775, and the daemon, running as 65534, cannot tighten that directory to 0700. Every start logged could not tighten ack store parent directory to 0700 at warn level. The 0.25.3 daemon logs that refusal at debug, and still warns when the directory is writable by other users. acks.jsonl keeps its 0600 mode.

The default configuration listens on 0.0.0.0, and the daemon validated its configuration twice at start, so the non-loopback listen advisory, like every other warning of that validation, printed twice in every pod log. It prints once now.

Java findings can also carry a different suggested fix. A SELECT Hibernate generated reads java_jpa even when no span names Hibernate, which covers the lazy loads the OpenTelemetry Java agent never wraps in a Hibernate span, and a service traced through Micrometer Observation gets the Java generic fix where it got none.

In the simulation lab, the 0.25.3 daemon image ran as 65534 on a Docker volume prepared like an fsGroup root and listening on 0.0.0.0: no chmod warning, the listen advisory once, an ack accepted and written at 600. The 0.25.2 image printed the chmod warning, and the advisory twice.

The v0.25.3 binary notes describe the three changes.

Upgrade impact

  • Pods roll on the image. helm upgrade replaces them because appVersion and image.tag move together.
  • checksum/config moves, and not because your configuration changed. The reworded comments change the rendered perf-sentinel.toml, and the ConfigMap's helm.sh/chart and app.kubernetes.io/version labels bump with the chart. The pods roll on the image anyway.
  • Acknowledgments keep matching. The suggested fix is not part of a finding's signature, and no finding appears or disappears, so perf_sentinel_findings_total and the example dashboards read as before.
  • No values.yaml key is added or removed, no template logic changes, and the shipped PrometheusRule is untouched.

Install

The chart is published as an OCI artifact on GHCR, install it directly with no helm repo add step:

helm install perf-sentinel oci://ghcr.io/robintra/charts/perf-sentinel --version 0.25.3

Upgrade an existing release:

helm upgrade perf-sentinel oci://ghcr.io/robintra/charts/perf-sentinel --version 0.25.3

Read docs/HELM-DEPLOYMENT.md for the ServiceMonitor section, sizing and Ingress postures.

If you are upgrading from chart-v0.23.0 or earlier, read the chart-v0.24.0 notes first: that release raises the default workload.statefulset.persistence.size to 2Gi, which an existing StatefulSet does not pick up on its own. From chart-v0.18.0 or earlier, read the chart-v0.19.0 notes as well: that release adds a grouping label to five metrics and is breaking for an unaggregated alert on any of them. From chart-v0.16.0 or earlier, the chart-v0.17.0 notes change the shipped PrometheusRule.

Full Changelog: chart-v0.25.2...chart-v0.25.3

Don't miss a new perf-sentinel release

NewReleases is sending notifications on new releases.