18 Aug 2022
Included Calico versions
Calico version: v3.24.0
Calico Enterprise version: v3.14.1
Enhancements
- Add new field DisableBGPExport to IPPools API #2083 (@lmm)
- Add Fips mode installation flag #2106 (@rene-dekker)
- Add CSI driver support #2082 (@Josh-Tigera)
- Add metdata resource to AD role + ENV Var adjustments #2074 (@freecaykes)
- Add support for component resource overrides #2063 (@lmm)
- Only install PodSecurityPolicies if the API is present #2035 (@caseydavenport)
Bug fixes
- Merge DaemonSet and Deployment template metadata as well #2007 (@caseydavenport)
- Fix syslog forwarding volume #2114 (@tmjd)
- Remove some entries from go.mod that aren't needed #2112 (@caseydavenport)
- Fix instructions for running a local operator #2078 (@caseydavenport)
- Fix PodSecurityStandard for intrusion detection #2076 (@rene-dekker)
- Fix overly restrictive namespace PSS labels #2052 (@caseydavenport)
- fix(render/ids): set ad images for standalone and management clusters #2058 (@freecaykes)
- Fix felix healthport: set as env var #1955 (@caseydavenport)
- Fix error check in status #1951 (@tmjd)
Other changes
- Update to Calico v3.24.0 #2122 (@mgleung)
- Update CSI node registrar image #2118 (@mgleung)
- Sync GlobalAlert Template list for AD to what is available in the AD pods themselves #2110 (@freecaykes)
- CRD update #2105 (@tmjd)
- Sanitize reason messages until we have them all updated #2104 (@tmjd)
- Update RBAC for apiserver to allow ipamconfigs #2100 (@caseydavenport)
- Update CRDs #2099 (@tmjd)
- Status: do not degrade if expected pods are available #2098 (@tmjd)
- Update FelixConfig CRD #2097 (@coutinhop)
- Update master toleration to include control-plane #2091 (@tmjd)
- allow-tigera reconciliation: follow-ups #2090 (@pasanw)
- Bump dependencies #2089 (@Behnam-Shobiri)
- update github.com/stretchr/testify from 1.7.0 to v1.8.0 #2085 (@Behnam-Shobiri)
- Re-add static-checks target to CI #2084 (@lmm)
- signed voltron certs #2080 (@ozdanborne)
- Log upstream service time in envoy access log #2079 (@hjiawei)
- Update oss crds #2077 (@rene-dekker)
- Updating the usage comment for documenation #2075 (@vara2504)
- Set deployments/finalizer as ids rbac resource for Openshift #2065 (@freecaykes)
- Add /proc and /var/run/calico to mount-bpffs volumes #2064 (@mazdakn)
- Remove Components from list that are not for images #2059 (@tmjd)
- Refactor semaphore jobs #2057 (@Brian-McM)
- Update CRDs #2053 (@tmjd)
- deploy Calico API Server with soft zone based anti-affinity by default #2050 (@calvinrzachman)
- Support Power image #2048 (@yussufsh)
- Add RBAC for the TokenRequest API #2047 (@mgleung)
- Fixing Comment for BGP DNS log #2045 (@vara2504)
- Trim lib, lib64 to necessary imports #2042 (@freecaykes)
- [Calico Enterprise] Add volume mount with the TLS key pair to queryserver conta… #2041 (@dimitri-nicolo)
- Include VPP in cluster type enumeration #2039 (@caseydavenport)
- Run as non-privilege and non-root user #2037 (@hjiawei)
- Make gen-files #2034 (@rene-dekker)
- BGP log retention changes #2033 (@vara2504)
- Update the CRDS #2023 (@rene-dekker)
- Dns retention #2022 (@vara2504)
- Add CodeQL for operator #2010 (@Behnam-Shobiri)
- check for max and min in MTU #2009 (@Behnam-Shobiri)
- Tolerate IP6_AUTODETECTION_METHOD none when IP6 is none #2008 (@tmjd)
- Rename windows-upgrade component #2000 (@lmm)
- Update dependencies #1994 (@Behnam-Shobiri)
- Update windows fluentd bash.exe path #1993 (@lmm)
- Update CRDs (managedclusters) #1992 (@tmjd)
- Add missing r.status.OnCRFound() #1984 (@rene-dekker)
- adjust FlexVolumePath when RKE2 provider is set #1983 (@aaaaaaaalex)
- Add kibana_login permissions to network admin cluster role #1976 (@Brian-McM)
- Add new permissions required by CNI plugin #1974 (@robbrockbank)
- allow-tigera reconciliation #1970 (@pasanw)
- Put create and update into function so it can be retried #1969 (@tmjd)
- Update release-note generation for python3 #1967 (@caseydavenport)
- Update CRDs #1964 (@tmjd)
- Update packetcapture component name #1958 (@hjiawei)
- Add mount-cgroup init container to node ds #1957 (@mazdakn)
- Issue1055 Status Condition for Installation's CR from Tigerastatus conditions #1954 (@vara2504)
- Update CRDs #1952 (@tmjd)
- Use certificatemanagement for Elastic secrets and certificates #1832 (@rene-dekker)
- Add more logging to the check resource registration loop #1787 (@robbrockbank)
- Component labeler #1679 (@tmjd)