3.2.0
- This is the 3.2.0 release. The Splunk Operator for Kubernetes is a supported platform for deploying Splunk Enterprise with the prerequisites and constraints laid out here
Breaking Changes
- Index & Ingestion Separation — Queue secret reference (breaking): the queue secret is now referenced through
secretKeyRefinstead of the previous volume-based reference (volList). This is a breaking change to the Queue secret configuration for the Index & Ingestion Separation feature. We do not expect any customers to be relying on the old volume-based reference, but if you are, you must migrate your Queue secret tosecretKeyRefbefore upgrading to 3.2.0.
New Features
- Certificate Management: new
spec.certs[]API onCommonSplunkSpecwith controller integration, certificate auto-generation, and aCertManagementfeature gate (cert-manager Issuer-based) - Feature gate infrastructure using the Kubernetes
FeatureGatepattern, with Helm chart support - Splunk Universal Forwarder Helm chart (stateless-by-default, Deployment-only)
- Kubernetes-standard status conditions on all CRDs, including
status.observedGenerationand aPausedcondition when reconciliation is paused by annotation TerminalFailurecondition with terminality classification for existing failures, plus corresponding Kubernetes events- Local KV Store type for SOK pods
- Single-group to multi-group API support
disableResourceDefaultsto allow non-default resource values- Configurable
PodAnnotations - Ingestion/Indexing separation improvements: mutable Ingestor API, idempotent ingestor queue API, SmartBus config via splunk-ansible defaults (feature remains in preview)
Postgres Integration (Preview)
- Postgres Controller with
PostgresClusterandPostgresDatabasecustom resources - Point-in-Time Recovery (PITR) and Barman object-storage backups for
PostgresCluster - Cluster restore, major-version upgrades, and vertical scaling
- Connection pooler (PgBouncer) reconciliation, SAN management, and policy additions
- Custom metrics, provisioning-latency histogram, and improved grant/connection observability
- Validation webhooks (disk-size decrease guard, underscore database names) and terminalization of deterministic external-secret failures
- CNPG upgraded to v1.30.0; Postgres node sidecar disabled by default in SOK deployments
Helm Chart Improvements
- Add telemetry ConfigMap to Helm
- Helm chart support for feature gates
Dependency and Security Updates
- Upgrade Go to 1.26.2
- Update OpenShift support to 4.22
- Upgrade cert-manager to v1.21.1
- Upgrade google.golang.org/grpc to v1.83.1
- Build the operator binary with Go's native FIPS 140-3 mode (
GOFIPS140=v1.0.0, CMVP Certificate #5247)
Bug Fixes
- Fix empty pod name in ClusterManager bundle push (#1849)
- Handle transient phase changes during app framework operations
- Clear stale appContext when all AppSources are removed
- Fix
clusterModel.Actuateclobbering unowned CNPG cluster spec fields - Fix timing-dependent Cluster Manager reconciliation
- Use Kubernetes secrets instead of
kubectl execto obtain admin credentials
Known Issues
- Updating queue reference (queueRef) in IngestorCluster or IndexerCluster that changes the name of the underlying queue (queueRef.spec.sqs.name) only works with Splunk Enterprise 10.6 or later. On older Splunk versions the change will not take effect because the underlying fix ships in Splunk Ansible.
Supported Splunk Version
Splunk Version 9.4.15 - 10.6.0
For related changelog check release notes for given version of docker-splunk and/or splunk-ansible
Supported Kubernetes Version
Kubernetes Version 1.32 - 1.36