github robintra/perf-sentinel chart-v0.25.5
perf-sentinel chart v0.25.5

2 hours ago

What's new in chart-v0.25.5

appVersion moves to 0.25.5 and image.tag follows it to :0.25.5. The NetworkPolicy gains per-port peer lists, under four new values.yaml keys, and stays off by default. Under the default values the rendered perf-sentinel.toml is byte-for-byte what chart-v0.25.4 rendered, same 5036 bytes and the same digest. A values.yaml comment and a configmap-fragments.yaml comment change wording, and neither renders into a manifest.

Per-port NetworkPolicy peers

Port 4317 serves OTLP gRPC only. Port 4318 serves OTLP HTTP, and also /metrics, /health and the query API, which returns findings with their SQL templates and takes ack writes. Until now every peer allowed by the policy reached both ports, so a collector that only sends OTLP gRPC could also read the API.

networkPolicy.ingress.otlpGrpc and networkPolicy.ingress.http take the same fromNamespaceSelectors and fromPodSelectors lists as networkPolicy.ingress, and each renders its own rule on port 4317 or port 4318 alone. Allow-list a gRPC-only collector under otlpGrpc, and Prometheus, PerfSentinelHub or Grafana under http. The lists directly under networkPolicy.ingress still open both ports, and a release that only sets them renders the same policy as chart-v0.25.4. With no selector anywhere the policy still denies all ingress. values.schema.json validates the new keys.

What moves inside the pod

The daemon routes its https:// calls, the PerfSentinelHub export, Electricity Maps, Redfish, the energy scrapers and the cloud energy Prometheus source, through HTTPS_PROXY, or ALL_PROXY, minus NO_PROXY, and trusts the PEM certificates of SSL_CERT_FILE next to its bundled roots. Set them through the existing extraEnv, extraVolumes and extraVolumeMounts, as docs/CONFIGURATION.md shows. http:// calls stay direct, so the in-cluster scrapes are unaffected.

On MySQL and MariaDB the daemon now masks a value between double quotes like one between single quotes, where it used to keep it in the template, in clear. The default configuration listens on 0.0.0.0, so every pod logs the non-loopback listen advisory, and its wording changes: it now reads OTLP ingest, /metrics and most read endpoints are never authenticated. The perf-sentinel CLI in the image falls back to the v3 search when jaeger-query --service meets Jaeger 2.21 or later.

In the simulation lab, the 0.25.5 daemon image detected the 12 anti-patterns of the reference workload, and, run as 65534 on 0.0.0.0, logged the new advisory once where the 0.25.4 image logged the old one.

The v0.25.5 binary notes describe the changes.

Upgrade impact

  • Pods roll on the image. helm upgrade replaces them because appVersion and image.tag move together.
  • MySQL and MariaDB findings whose SQL held a double-quoted value change template and signature, so their acknowledgments stop matching and PerfSentinelHub files them as new findings. Findings on such queries can appear or disappear.
  • A pod that already carries HTTPS_PROXY now uses it, whether it comes from extraEnv, extraEnvFrom or an injecting webhook. An in-cluster https:// endpoint, such as PerfSentinelHub, belongs in NO_PROXY.
  • A log rule that matches the old non-loopback advisory needs updating.
  • checksum/config moves, and not because your configuration changed. The rendered perf-sentinel.toml is identical, but the ConfigMap carries helm.sh/chart and app.kubernetes.io/version labels that bump with the chart.
  • Four values.yaml keys are added, networkPolicy.ingress.otlpGrpc and networkPolicy.ingress.http with their two selector lists each, all empty by default. None is removed, and the shipped PrometheusRule is untouched.

Install

The chart is published as an OCI artifact on GHCR, install it directly with no helm repo add step:

helm install perf-sentinel oci://ghcr.io/robintra/charts/perf-sentinel --version 0.25.5

Upgrade an existing release:

helm upgrade perf-sentinel oci://ghcr.io/robintra/charts/perf-sentinel --version 0.25.5

Read docs/HELM-DEPLOYMENT.md for the ServiceMonitor section, sizing and Ingress postures.

If you are upgrading from chart-v0.23.0 or earlier, read the chart-v0.24.0 notes first: that release raises the default workload.statefulset.persistence.size to 2Gi, which an existing StatefulSet does not pick up on its own. From chart-v0.18.0 or earlier, read the chart-v0.19.0 notes as well: that release adds a grouping label to five metrics and is breaking for an unaggregated alert on any of them. From chart-v0.16.0 or earlier, the chart-v0.17.0 notes change the shipped PrometheusRule.

Full Changelog: chart-v0.25.4...chart-v0.25.5

Don't miss a new perf-sentinel release

NewReleases is sending notifications on new releases.