Upgrading
The upgrade is safe in place. Service and Deployment selectors are unchanged, so there are no immutable-field conflicts, but pods roll once because the Trino version is part of the config checksums.
Three things to check before you upgrade:
- If your release name is a short prefix of
trino, every resource is renamed.trino.fullnameused to ask whether the chart name started with the release name, sohelm install tri trino/trinoproduced resources called plainlytrino-*. It now compares for equality, so the same release renderstri-trino-*, and Helm will replace the old objects. Only release names that are a strict prefix of the chart name are affected (t,tr,tri,trin);trinoand anything longer, such asmy-trino, are unchanged. Two such releases in one namespace previously fought over the same names, which is the bug this fixes. (#453) - A
service.coordinator.*orservice.worker.*key a role cannot apply now fails rendering instead of being ignored, so an unsupported override surfaces at install time rather than silently doing nothing. OnlyannotationsandappProtocolscan differ per role. (#458) service.annotationsstill reaches both services. It is now a shared default rather than the only setting, so nothing changes unless you move annotations underservice.coordinatororservice.worker. (#458)
Per-role configuration
- The coordinator and worker services are configurable separately, which stops a coordinator-only annotation from registering workers as coordinators in annotation-driven service discovery, and adds
service.loadBalancerSourceRangesandservice.appProtocolsfor Istio HTTP/2 — by @nineinchnick in #458 - A role can disable what the shared
jmxblock enables, and per-role overrides merge withmergeOverwriteso a falsy override is honoured — by @nineinchnick in #453 and @sdaberdaku in #433
Features
- Mount secrets from an external store with
csiSecretMounts, so AWS Secrets Manager, Vault or Azure Key Vault can stay the only copy of a secret — by @etolbakov in #443 - Add arbitrary manifests to a release with
extraManifests— by @vijaybandari in #398 - Add
hostAliasesfor names the cluster DNS cannot resolve — by @hosseinabaiyani in #445 - Template
ingress.hosts[].hostandingress.tls[].hosts[]withtpl, so one base values file can derive hostnames per cluster — by @nineinchnick in #455 - Template the entries of
additionalConfigProperties,additionalNodeProperties,additionalLogProperties,additionalExchangeManagerPropertiesandeventListenerProperties, so a parent chart can drive a property. An entry that renders empty is dropped — by @nineinchnick in #456
Fixes
- Render again on Helm 3.7 and older, where comparing the unset
typeof an emptyaccessControl,resourceGroupsorsessionPropertiesblock against a string aborted the install. Also fixesaccessControl: nullon current Helm — by @nineinchnick in #457 worker.terminationGracePeriodSecondscan be set through--set, and so from the Terraform Helm provider, which previously failed withincompatible types for comparison— by @nineinchnick in #453- Keep the JDK-8329528 workaround for an image tag carrying a suffix;
483-arm64was treated as older than 447 and lost the pinned region flags — by @nineinchnick in #453 - An
httpRouterule giving neithermatchesnorpathfalls back to the defaults instead of failing with a template stack trace — by @nineinchnick in #453 - Stop emitting duplicate label keys and duplicate checksum annotations. Effective labels and selectors are unchanged — by @sdaberdaku in #433
Development
- Replace the two bash test scripts with a single driver, express every case as a
ci/*-values.yamlfile, and add helm-unittest suites for the templates. The suites are what turned up the template fixes above — by @nineinchnick in #453
New Contributors
- @vijaybandari made their first contribution in #398
- @etolbakov made their first contribution in #443
- @hosseinabaiyani made their first contribution in #445
helm install my-trino trino/trino --version 1.43.0
Full Changelog: trino-1.42.2...trino-1.43.0