What's new in chart-v0.25.5
appVersion moves to 0.25.5 and image.tag follows it to :0.25.5. The NetworkPolicy gains per-port peer lists, under four new values.yaml keys, and stays off by default. Under the default values the rendered perf-sentinel.toml is byte-for-byte what chart-v0.25.4 rendered, same 5036 bytes and the same digest. A values.yaml comment and a configmap-fragments.yaml comment change wording, and neither renders into a manifest.
Per-port NetworkPolicy peers
Port 4317 serves OTLP gRPC only. Port 4318 serves OTLP HTTP, and also /metrics, /health and the query API, which returns findings with their SQL templates and takes ack writes. Until now every peer allowed by the policy reached both ports, so a collector that only sends OTLP gRPC could also read the API.
networkPolicy.ingress.otlpGrpc and networkPolicy.ingress.http take the same fromNamespaceSelectors and fromPodSelectors lists as networkPolicy.ingress, and each renders its own rule on port 4317 or port 4318 alone. Allow-list a gRPC-only collector under otlpGrpc, and Prometheus, PerfSentinelHub or Grafana under http. The lists directly under networkPolicy.ingress still open both ports, and a release that only sets them renders the same policy as chart-v0.25.4. With no selector anywhere the policy still denies all ingress. values.schema.json validates the new keys.
What moves inside the pod
The daemon routes its https:// calls, the PerfSentinelHub export, Electricity Maps, Redfish, the energy scrapers and the cloud energy Prometheus source, through HTTPS_PROXY, or ALL_PROXY, minus NO_PROXY, and trusts the PEM certificates of SSL_CERT_FILE next to its bundled roots. Set them through the existing extraEnv, extraVolumes and extraVolumeMounts, as docs/CONFIGURATION.md shows. http:// calls stay direct, so the in-cluster scrapes are unaffected.
On MySQL and MariaDB the daemon now masks a value between double quotes like one between single quotes, where it used to keep it in the template, in clear. The default configuration listens on 0.0.0.0, so every pod logs the non-loopback listen advisory, and its wording changes: it now reads OTLP ingest, /metrics and most read endpoints are never authenticated. The perf-sentinel CLI in the image falls back to the v3 search when jaeger-query --service meets Jaeger 2.21 or later.
In the simulation lab, the 0.25.5 daemon image detected the 12 anti-patterns of the reference workload, and, run as 65534 on 0.0.0.0, logged the new advisory once where the 0.25.4 image logged the old one.
The v0.25.5 binary notes describe the changes.
Upgrade impact
- Pods roll on the image.
helm upgradereplaces them becauseappVersionandimage.tagmove together. - MySQL and MariaDB findings whose SQL held a double-quoted value change template and signature, so their acknowledgments stop matching and PerfSentinelHub files them as new findings. Findings on such queries can appear or disappear.
- A pod that already carries
HTTPS_PROXYnow uses it, whether it comes fromextraEnv,extraEnvFromor an injecting webhook. An in-clusterhttps://endpoint, such as PerfSentinelHub, belongs inNO_PROXY. - A log rule that matches the old non-loopback advisory needs updating.
checksum/configmoves, and not because your configuration changed. The renderedperf-sentinel.tomlis identical, but the ConfigMap carrieshelm.sh/chartandapp.kubernetes.io/versionlabels that bump with the chart.- Four
values.yamlkeys are added,networkPolicy.ingress.otlpGrpcandnetworkPolicy.ingress.httpwith their two selector lists each, all empty by default. None is removed, and the shippedPrometheusRuleis untouched.
Install
The chart is published as an OCI artifact on GHCR, install it directly with no helm repo add step:
helm install perf-sentinel oci://ghcr.io/robintra/charts/perf-sentinel --version 0.25.5Upgrade an existing release:
helm upgrade perf-sentinel oci://ghcr.io/robintra/charts/perf-sentinel --version 0.25.5Read docs/HELM-DEPLOYMENT.md for the ServiceMonitor section, sizing and Ingress postures.
If you are upgrading from chart-v0.23.0 or earlier, read the chart-v0.24.0 notes first: that release raises the default workload.statefulset.persistence.size to 2Gi, which an existing StatefulSet does not pick up on its own. From chart-v0.18.0 or earlier, read the chart-v0.19.0 notes as well: that release adds a grouping label to five metrics and is breaking for an unaggregated alert on any of them. From chart-v0.16.0 or earlier, the chart-v0.17.0 notes change the shipped PrometheusRule.
Full Changelog: chart-v0.25.4...chart-v0.25.5