Merge Requests integrated in this release
366 merge requests were integrated in this repo between 1.7.0-test-20260511-sylva-units-operator and 1.7.0.
These notes don't account for the MRs merged in secondary repos.
Kubernetes
- add support of K8s 1.35.2 in sylva !6891 ~"ck8s" ~"kubeadm" ~"rke2" (issues: #3576)
- remove support of k8s 1.32 !7807 (issues: #3904)
- update k8s patch versions - 1.33.10+rke2r3, 1.34.6+rke2r3, 1.35.3+rke2r3 !7613 (issues: #3960)
- remove useless problematic legacy transitional code for coredns (kubeadm) !6695 ~"kubeadm"
- pin coredns version on first-node installation !8158
- update patch versions - 1.35.5+rke2r2, 1.34.8+rke2r2, 1.33.12+rke2r2 !7877
Sylva-units framework
- Update sylva-units-operator to v1.3.4 ~"renovate" !7880 !8323
- fix: support semver in generate units documentation !7735
- feat: apply working in OCI mode with commit substitution !7546 ~"area:CI"
- Avoid sylva-units reconciliation caused by cluster-public-endpoint valuesFrom entry !7563 ~"type::bug" (issues: #3924)
- don't let flux-system and sylva-units-operator units depend on the root-dependency !7848 (issues: #4042)
- Switch to calico-ready !7856 ~"type::bug"
- Improve unit-description generator code to avoid misleading N/A in App version !7896 (issues: #4058)
- Define default per-unit timeout, and timeout factor, from values !7039 ~"type::enhancement" (issues: #3603)
- fail if healthCheck is set on Kustomization for a workload-cluster Helm-based unit !7849 ~"area:CI" (issues: #4043)
- Small improvement for interpret-inner-gotpl !7672
- cleanup: remove old Kustomizations from sylva-units pre-upgrade hook for Kustomizations.spec.prune !7935 ~"type::cleanup"
- add
sylvactl/unitTimeoutannotation to thesylva-units-statusKustomization !7953
- fix: disableNameSuffixHash test, target only ConfigMap and Secret names (not... !7968
- add caching to "unit-enabled" named template !7944
- sylva-units: interpret content of units_override_enabled only once (optimize bootstrap) !8019
- apply scripts: cleanup transition code that was needed to upgrade from sylva < 1.5 !7371 ~"type::cleanup"
- ensure that unit Kustomization can't be ready if the unit HelmRelease is suspended !6589 ~"type::bug" (issues: #3377)
- Support any infrastructure and bootstrap providers in sylva-core cluster healthcheck !7330 ~"area:capi" (issues: #3393)
- Protect sylva-units HelmRelease from accidental deletion on management clusters !8097 ~"cluster-lifecycle" (issues: #4144)
- Enable kustomization reconciler controller in management cluster !6712 (issues: #3434)
- make dependsOn robust to flapping readiness state, ratchet on first reconciliation !8329
- fix pure OCI deployment for rancher-roles-management units !8351 ~"oci" (issues: #4274)
Cluster API
- Update gcr.io/k8s-staging-cluster-api/capd-manager container to v1.12.8 !7812 ~"renovate"
- Update Sylva Helm chart sylva-capi-cluster to v0.14.27 ~"renovate" !7803 !7989 !8035 !8073 !8110 !8157 !8220 !8255 !8303 !8325
- Update dependency rancher/cluster-api-provider-rke2 to v0.24.4 !8014 ~"renovate" ~"rke2"
- Update metal3 chart to v0.15.0 !7985 ~"capm3"
- Update dependency metal3-io/cluster-api-provider-metal3 to v1.12.5 !8042 ~"area:security" ~"capm3" ~"renovate"
- Update dependency kubernetes-sigs/cluster-api to v1.12.8 !7996 ~"renovate"
- Update dependency kubernetes-sigs/cluster-api-provider-openstack to v0.14.4 !7779 ~"capo" ~"renovate"
- remove unused "os-image-server-clear-old-ingresses" unit !7494 ~"capm3"
- Align interface defaults with linux-ifname schema validation !7728 ~"area:networking" (issues: #3901)
- improve tuning of sylvactl/unitTimeout for cluster* units, in particular on libvirt-metal !7418 ~"area:CI" (issues: #3855)
- increase memory resources for RKE2 CAPI provider control-plane controller !7801 ~"rke2" (issues: #4029)
- capo-contrail-bgpaas: fix missing fields !7852 ~"area:networking" ~"capo" (issues: #4028)
- in 2-step upgrade, delay MachineDeployments update during first step !7862
- Do not rely on gitlab CI cache in delete workload cluster job !8015 ~"type::bug"
- Support any infrastructure and bootstrap providers in sylva-core cluster healthcheck !7330 ~"area:units-framework" (issues: #3393)
- Add small readability change to cluster healtcheck s-u template !8077 ~"type::cleanup"
- add healthchecks on cluster-bmh, waiting for BareMetalHosts inspection !8117 ~"capm3"
- cluster units sylvactl/unitTimeout: for RKE2, take into account first-node installation of calico+metallb !8123 ~"rke2"
- workload clusters: have "cluster" unit depend on "calico-ready" on upgrades instead of "calico" !8281 ~"area:networking" ~"type::bug" (issues: #4240)
- Fix cluster protection policy and convert tests for management cluster deletion protection policies into chainsaw tests !8100 ~"area:CI" (issues: #4146)
Workload cluster
- Update Helm chart kunai to v3.6.0 ~"kunai" ~"renovate" !8044 !8352
- Update workload-cluster-operator to v0.13.6 ~"renovate" !7943 !8239 !8316 !8374
- Restrict the write capability to vault policy path !6637 ~"area:security" ~"security" ~"security::credentials" (issues: #3319)
- annotate workload-cluster sylva-system namespace with Sylva release info !7913 (issues: #3111)
- Move Kunai Keycloak client to Crossplane !6742 ~"kunai" (issues: #3218)
- Leverage In-built support for PDB in CNPG within Kunai !7844 ~"CNPG" ~"area:misc" ~"kunai" (issues: #4039)
- Add chainsaw test for workload-team-defs VAP protection !7778 ~"Test" ~"area:CI"
- Limit namespaces in which prometheus-operator searches for serviceMonitors, Rules, etc !7555 ~"area:observability" ~"monitoring"
- Add kyverno SCC for OKD workload clusters !8000 ~"okd" ~"type::bug"
- Enable Server-Side Apply on workload-team-defs HelmRelease !8149 ~"type::bug"
- workload-cluster: extend sylva-release-info to include info on Cluster name/namespace !8306
Backup and Restore
- Replace jq command for ns list in backup-capi-resources script !7640 (issues: #3972)
- exit the backup scripts in case of errors with any backup tasks (except failure to send stats to pushgateway) !7560 (issues: #2850)
- add size parameters and validate the backed up data stored in s3 bucket !7362 (issues: #3762)
- Checking and comparing the checksum of the backup done and backup stored on S3 bucket !7496 (issues: #3836)
- add backupStorageLocation conf in velero to push backups into s3 bucket !7621 ~"velero" (issues: #3946)
- download and verify checksum in case of multipart upload for etcd !8245 (issues: #4225)
- allow to user to pass s3 cert as raw pem for backup !8326 ~"type::bug" (issues: #4138)
- Fix backup units being unintentionally enabled when no S3 store is configured !8384
Networking
- Update github.com/czerwonk/junos_exporter to v0.15.4 !7769 ~"area:observability" ~"monitoring" ~"renovate"
- Update Helm chart metallb to v0.16.1 ~"renovate" !7908 !8010
- Align interface defaults with linux-ifname schema validation !7728 ~"area:capi" (issues: #3901)
- remove multus-ready, replaced by kstatus checks !7845 ~"type::cleanup"
- Set TCP_TARGETS VIP for CAPO workload clusters !7846 ~"area:observability" ~"capo" ~"monitoring" (issues: #4037)
- capo-contrail-bgpaas: fix missing fields !7852 ~"area:capi" ~"capo" (issues: #4028)
- Enable monitoring and Grafana BGP dashboard for MetalLB frr-k8s mode !7504 ~"area:observability" (issues: #3896)
- Add optionals_extra for sylva-dashboards !7329 ~"area:observability" ~"monitoring"
- Cleanup workaround Kyverno policy for baremetal bond_miimon config !7584 ~"capm3" ~"type::cleanup"
- Remove Whereabouts RKE2 image !7561 ~"type::cleanup" (issues: #3792)
- Enhance BGP features !7771 (issues: #3452)
- OKD/Openshift: Adds security contexts for metallb !7726 ~"area:security" ~"okd" ~"security"
- Introduce nmstate-resources chart !6151 ~"capm3" ~"capo" ~"type::enhancement"
- fix version in kube-ovn unit, in order to be tracked by Renovate !8132 ~"renovate::configuration"
- workload clusters: have "cluster" unit depend on "calico-ready" on upgrades instead of "calico" !8281 ~"area:capi" ~"type::bug" (issues: #4240)
OpenStack ~capo
- Update Helm chart openstack-cinder-csi to v2.36.0 !7999 ~"renovate"
- Update sylva-elements/ci-tooling/ci-deployment-values to v0.5.92 !8098 ~"renovate"
- Update dependency kubernetes-sigs/cluster-api-provider-openstack to v0.14.4 !7779 ~"area:capi" ~"renovate"
- Set TCP_TARGETS VIP for CAPO workload clusters !7846 ~"area:networking" ~"area:observability" ~"monitoring" (issues: #4037)
- capo-contrail-bgpaas: fix missing fields !7852 ~"area:capi" ~"area:networking" (issues: #4028)
- Introduce nmstate-resources chart !6151 ~"Networking" ~"area:networking" ~"capm3" ~"type::enhancement"
- capo-contrail-bgpaas: use 1.4.3 (minor tag alignment) !8272 ~"area:misc"
Baremetal ~capm3
- Update metal3 chart to v0.15.0 !7985 ~"area:capi"
- Update dependency metal3-io/cluster-api-provider-metal3 to v1.12.5 !8042 ~"area:capi" ~"area:security" ~"renovate"
- remove unused "os-image-server-clear-old-ingresses" unit !7494 ~"area:capi"
- Update scheduled pipelines configuration (use OCI for ☁capm3 🚀rke2 🐧suse) !7811 ~"CI::configuration" ~"area:CI" ~"rke2"
- Cleanup workaround Kyverno policy for baremetal bond_miimon config !7584 ~"area:networking" ~"type::cleanup"
- metal3: add proxy support to ipa-downloader (fix regression) !8076 ~"type::bug"
- Update sylva-capi-cluster and mce-operator-helm-xks to support Cabpoa OKD preBootstrapCommands and postBootstrapCommands for Longhorn !8027 ~"longhorn" ~"okd"
- Introduce nmstate-resources chart !6151 ~"Networking" ~"area:networking" ~"capo" ~"type::enhancement"
- add healthchecks on cluster-bmh, waiting for BareMetalHosts inspection !8117 ~"area:capi"
- cluster-bmh: don't consider BMH failed if errorCount > 0 !8253 (issues: #4178)
- Metal3/Ironic: Disable LLDP collection by default to prevent network disruption !8278 (issues: #1894)
Monitoring
- Update github.com/czerwonk/junos_exporter to v0.16.1 ~"renovate" ~"area:networking" ~"area:observability" !7769 !8071
- Update rancher-monitoring to v108.0.5+up77.9.1-rancher.16 !7815 ~"area:observability" ~"rancher" ~"renovate"
- Update Sylva Helm chart sylva-prometheus-rules to v0.3.10 !7825 ~"area:observability" ~"renovate"
- Update Sylva Helm chart sylva-snmp-resources to v0.3.4 !7918 ~"area:observability" ~"renovate"
- Update Sylva Helm chart sylva-thanos-rules to v0.4.3 ~"renovate" ~"area:observability" !7826 !8188
- Update Helm chart prometheus-snmp-exporter to v9.14.0 !7872 ~"area:observability" ~"renovate"
- Update Helm chart prometheus-pushgateway to v3.6.1 !8189 ~"area:observability" ~"renovate"
- monitoring unit: use Helm-based healthChecks instead of Kustomization.healthChecks !7850 ~"area:observability" (issues: #3683)
- Set TCP_TARGETS VIP for CAPO workload clusters !7846 ~"area:networking" ~"area:observability" ~"capo" (issues: #4037)
- Add optionals_extra for sylva-dashboards !7329 ~"area:networking" ~"area:observability"
- Configure Prometheus retention according to the size of the PVC !6911 ~"area:observability" (issues: #3589)
- Thanos receive "dual-mode" - HA + horizontal scaling !7658 ~"area:observability"
- Limit namespaces in which prometheus-operator searches for serviceMonitors, Rules, etc !7555 ~"area:observability" ~"area:workload-cluster"
- Move thanos namespace creation to thanos-init unit !8066 ~"area:observability" ~"type::cleanup"
- External S3 support for loki !6804 ~"area:observability" ~"logging" (issues: #2195)
- Add Prometheus metrics cacher !7827 ~"area:observability"
- fix: run metrics cacher nginx on an unprivileged port !8115 ~"area:observability"
- Add node name to node-exporter metrics !8093 ~"area:observability"
- Create grafana default roles using keycloak user management chart !8208 ~"area:observability" ~"security::user-and-role-management"
- Define grafana roles via keycloak-user-management !8284 ~"area:observability" ~"security::user-and-role-management"
- Update github.com/bitnami/charts.git !7893 ~"area:observability" ~"renovate"
- Fix Grafana SSO test title check !8344 ~"area:CI" ~"area:observability" ~"type::bug"
Logging
- Update ghcr.io/grafana/helm-charts/loki container to v7 ~"renovate" ~"area:observability" !6661 !7596
- Create kube-logging namespace using new logging-init unit !7981 ~"area:observability" ~"type::cleanup"
- External S3 support for loki !6804 ~"area:observability" ~"monitoring" (issues: #2195)
Observability
- Set label on sylva components namespaces !7558
- Enable monitoring and Grafana BGP dashboard for MetalLB frr-k8s mode !7504 ~"area:networking" (issues: #3896)
- Fix dependency on thanos-receive-controller unit !8091
Storage
- Leverage 2-step upgrade to upgrade longhorn to 1.11 !7756 (issues: #3982, #2)
- Install generic CSI VolumeSnapshot support !5994 ~"kubeadm"
- Add support for HPE Storage using the helm chart provided by HP !7829
- Update sylva-capi-cluster and mce-operator-helm-xks to support Cabpoa OKD preBootstrapCommands and postBootstrapCommands for Longhorn !8027 ~"capm3" ~"okd"
Security
- Update ghcr.io/kyverno/chainsaw container to v0.2.15 !7732 ~"renovate"
- Update crossplane-contrib/provider-keycloak container to v2.20.0 ~"renovate" !7414 !8227
- Update dependency metal3-io/cluster-api-provider-metal3 to v1.12.5 !8042 ~"area:capi" ~"capm3" ~"renovate"
- Update rancher-compliance to v109.2.0+up1.4.3 !8151 ~"rancher" ~"renovate" ~"rke2"
- Update Helm chart trivy-operator to v0.33.1 !8264 ~"area:misc" ~"renovate" ~"trivy"
- Update Helm chart sbom-operator to v0.42.6 !7356 ~"area:misc" ~"renovate" ~"sbom-operator"
- Update ghcr.io/openbao/openbao container to v2.5.5 !7895 ~"renovate"
- Update registry-1.docker.io/cloudpirates/keycloak container to v0.21.8 !8018 ~"renovate"
- Move from keycloak operator to keycloak chart !7003 ~"keycloak" (issues: #3081)
- keycloak-user-management: use HelmRelease kstatus checks instead of script !7755
- neuvector: fix healthchecks for workload clusters, adjust dependencies !7820 ~"type::bug"
- Configure vault-operator memory limit !7866 (issues: #4041)
- Add AntiAffinity rules for the Kyverno pods !7831 (issues: #4016)
- Restrict the write capability to vault policy path !6637 ~"area:workload-cluster" (issues: #3319)
- add the possibility to configure keycloak with an OIDC identity provider !7592
- Prevent running vault with root privilege !7534 (issues: #3923)
- cleanup: Cleanup keycloak-resources unused fields !7875 ~"type::cleanup"
- Remove common name from all server certificates, as it's ignored when any SAN exists !7956 (issues: #4079)
- Remove support for Hashicorp Vault (support only OpenBao) !7526 (issues: #3908)
- fix sylvactl per-unit timeout !7987 (issues: #4084)
- rancher-roles-management: add healthchecks !7857 ~"rancher"
- Use resolve Always for protocol mappers !7715
- Restrict use of pod spec.nodeName to prevent bypassing the scheduler !3184
- add healthChecksExpr for CRs of keycloak-base-resources !7941
- OKD/Openshift: Adds security contexts for metallb !7726 ~"area:networking" ~"okd"
- Move Rancher Keycloak OIDC client to Crossplane management !6419 (issues: #3213)
- add Rancher project creation and management scope to workload cluster !6517 (issues: #3279)
- Add ability to leverage an external Vault !4463 ~"type::enhancement"
- Cleanup vault renovate config as hashicorp-vault is removed !8121 ~"area:CI" ~"renovate::configuration" ~"type::cleanup" (issues: #4158)
- increase unit-timeout for neuvector unit !8108 ~"type::bug" (issues: #4133)
- Improve get_image_refs.py !8085 ~"area:CI" (issues: #3925)
- Fix kustomize-units OCI artifact signature !8199 ~"type::bug" (issues: #4200)
- add PrometheusRule to detect keycloak-crossplane-provider cpu overconsumption... !7298 ~"area:CI"
- Fix Neuvector login tests !8231 ~"area:CI" ~"neuvector" ~"type::bug" (issues: #4215)
- Compute sylvactl/unitTimeout based on node count for neuvector !8294 ~"neuvector" (issues: #4162)
RKE2
- Update rancher-compliance to v109.2.0+up1.4.3 ~"area:security" ~"renovate" ~"rancher" !7816 !8151
- Update dependency rancher/cluster-api-provider-rke2 to v0.24.4 !8014 ~"area:capi" ~"renovate"
- add support of K8s 1.35.2 in sylva !6891 ~"area:kubernetes-core" ~"ck8s" ~"k8s-upgrade" ~"kubeadm" (issues: #3576)
- Update scheduled pipelines configuration (use OCI for ☁capm3 🚀rke2 🐧suse) !7811 ~"CI::configuration" ~"area:CI" ~"capm3"
- increase memory resources for RKE2 CAPI provider control-plane controller !7801 ~"area:capi" (issues: #4029)
- cluster units sylvactl/unitTimeout: for RKE2, take into account first-node installation of calico+metallb !8123 ~"area:capi"
Kubeadm
- add support of K8s 1.35.2 in sylva !6891 ~"area:kubernetes-core" ~"ck8s" ~"k8s-upgrade" ~"rke2" (issues: #3576)
- remove useless problematic legacy transitional code for coredns (kubeadm) !6695 ~"area:kubernetes-core"
- Install generic CSI VolumeSnapshot support !5994 ~"area:storage"
OKD/OpenShift
- fix: handle nil Machine.spec.version in observed_k8s_version !7813
- Add kyverno SCC for OKD workload clusters !8000 ~"area:workload-cluster" ~"type::bug"
- OKD/Openshift: Adds security contexts for metallb !7726 ~"area:networking" ~"area:security" ~"security"
- Update sylva-capi-cluster and mce-operator-helm-xks to support Cabpoa OKD preBootstrapCommands and postBootstrapCommands for Longhorn !8027 ~"capm3" ~"longhorn"
- Move openshift-security-context-constraints dependency to base-deps unit template !8048
Bug Fixes
- Fix SSO integration for Rancher !7890 ~"area:misc" ~"rancher"
- cleanup healthChecks for unit keycloak-resources !8348 ~"area:misc" (issues: #4275)
Other
- Enable hotplug disk on Kubevirt - this will allow to add disks on the fly !7644 ~"area:misc" ~"kubevirt"
- Enable descheduler by default in management cluster with rules for pods violating affinity/antiaffinity !7800 ~"area:misc" (issues: #3894)
- bump Kyverno chart to 3.8.1 (Kyverno 1.18.1) !7700 ~"area:misc"
- Fix minio serverCount computation !7867
- Produce clean Certificate compatible with external issuer !7749
- Integrate Harbor Configuration Operator with Dedicated Units (harbor-configuration-operator & harbor-config) !6807 ~"area:misc" ~"harbor" (issues: #2619)
- Check for cronJob existence in descheduler policies !7882
- read 'sylva-toolbox-version.yaml' instead of 'sylva-toolbox-version' !7773
- Revert bump of postgresql !7917
- Separate sylva-toolbox caches based on the current branch / MR / target branch !7928
- minor: Add ingressClassName to Vault definition and remove deprecated annotation !7878 ~"area:misc"
- have additional-reconciliation annotation be set for longhorn only when longhorn is enabled !7947 (issues: #4077)
- allow 2-step-rancher upgrade !7743 ~"area:misc" ~"rancher" (issues: #4010)
- Change kubevirt URL prefix to make it shorter !7990 ~"area:misc" ~"kubevirt"
- Enable Prometheus duration based storage !7929
- minor: correct typos and update _typos.toml to enhance typo detection !7706
- add support of rancher 2.14.1 !7757 ~"area:misc" ~"rancher" ~"upgrade" (issues: #4015)
- harbor-configuration - Pod harbor-project-creation-config uses non-numeric user, setting a numeric user !8055 (issues: #4127)
- Disable pre upgrade units in dev !6930
- CNPG for harbor's database !3633 ~"area:misc" ~"harbor" (issues: #1730)
- Split prometheus-metrics-cacher into per-exporter units !8105
- fix opennebula-cpi version, in order to be tracked by Renovate !8133
- sylva-units: skip the kustomization spec.prune pre-upgrade hook unless it's needed !7976
- delete harbor-postgres Kustomization after migration to CNPG !8080 ~"area:misc" ~"harbor"
- limit rancher to 2 replicas !8197 ~"area:misc" ~"rancher"
- Add healthCheckExpr for harbor configuration !8185 ~"harbor"
- Revert Update sylva-elements/container-images/oci-tools Docker tag to v0.4.3 !8246
- copy management shared settings to team namespaces !8166 (issues: #4176)
- Increase keycloak unit timeout to 15m (5m per pod) !8242
- kind cluster creation: use 1.35.5, improve customizability !8209 ~"area:misc"
- Revert "Create grafana default roles using keycloak user management chart" !8268 ~"security::user-and-role-management"
- Consolidate management cluster deletion protection kyverno policies into a single vap component !8102
- Move Keycloak provider prerequisites out of crossplane-init !8198 ~"security::user-and-role-management" (issues: #4198)
- Bump Rancher version to 2.14.2 !8192
- multus cleanup: use default terminationGracePeriodSeconds !8309
- keycloak-user-management depends on all units that define an OIDC client !8307 ~"security::user-and-role-management" (issues: #4239)
- Set clientRateLimit and clientRateLimitQPS on Kyverno admissionController !8248
- apply healthchecks to more Keycloak OIDC custom resources !8332 ~"security::user-and-role-management" (issues: #4260)
- Revert "Enable kustomization reconciler controller in management cluster" !8363
- Correct small typo in Vault reference comment !8369
- add infra-capd to unset md0 for capd and comment clarifying ha option auto-injection in deployment job generator !8365 (issues: #4278)
- Revert "add infra-capd to unset md0 for capd and comment clarifying ha option auto-injection in deployment job generator" !8380
Other dependency upgrades
- Update pre-commit hook crate-ci/typos to v1.47.2 !7782 !7821 !7945 !8050 !8129 !8218 !8271 !8289
- Update Helm chart crossplane to v2.0.8 !7759
- Update dependency kubernetes-sigs/cluster-api to v1.12.7 !7702
- Update Helm chart goldpinger to v1.1.2 !7682
- Update github.com/rancher/local-path-provisioner to v0.0.36 !7762 ~"rancher"
- Update dependency python_gitlab to v8.4.0 ~"automerge" !7789 !8195
- Update Helm chart external-secrets to v2.4.1 !7798
- Update container-images/sylva-toolbox container to v1.8.7 !7692 !7839 !8127 !8260
- Update sylva-toolbox & ci-image to v1.8.1 !7854 !7936 !8225
- Update sylva-elements/container-images/helm-toolbox container to v1.2.2 !7694 !7994
- Update github.com/bitnami/charts to v17 !7443
- Update Helm chart policy-reporter to v3.7.4 !7776
- Update curlimages/curl container to v8.20.0 !7809
- Update Sylva Helm chart rancher-roles-management to v1.1.4 !7781 ~"rancher"
- Update sylva-elements/ci-tooling/ci-deployment-values to v0.5.100 !7864 !8012 !8041 !8164 !8261 !8311
- Update dependency sylva-projects/sylva-elements/ci-tooling/ci-templates to v1.1.2 !7992 !7997 !8003
- Update pre-commit hook astral-sh/ruff-pre-commit to v0.15.17 !8024 !8112 !8216 !8302 !8370
- Update Helm chart kubevirt to v0.7.0 !7841 ~"area:misc" ~"kubevirt"
- Update Sylva Helm chart workload-team-defs to v0.7.9 !8029 !8072
- Update ruby container to v4 !8032 !8152
- Update registry.gitlab.com/orange-opensource/k8s-tz/tools/harbor-configuration-operator container to v1.8.54 !7902
- Update dependency fluxcd/flux2 to v2.8.8 !7972
- Update docker.io/nginx container to v1.31.1 !8099
- Update pre-commit hook sylva-projects/sylva-elements/ci-tooling/sylva-test-framework to v1.1.2 !8169 !8280 !8297 !8298
- Update Helm chart rancher-turtles to v0.26.2 !8030 ~"rancher"
- Update sylva-elements/container-images/oci-tools container to v0.4.4 !6544 !8249
- Update Helm chart sylva-library to v0.8.5 !8247
- Update Helm chart harbor to v1.19.1 !7885
- Update registry.k8s.io/pause container to v3.10 !8322
- Update Helm chart kube-ovn-v2 to v1.16.2 !8296
- Update dependency to-be-continuous/gitleaks to v2.11.0 !8285
- Update rancher/shell container to v0.7.0 !7305 ~"rancher"
- Update Helm chart cloudnative-pg to v0.28.3 !7955 ~"area:misc"
- Update Helm chart descheduler to v0.36.0 !8094 ~"area:misc" ~"descheduler"
- Update harbor-configuration-operator to v1.8.61 !8355 ~"area:misc" ~"harbor"
- Update busybox container !5555
- Update github.com/bitnami/charts.git !8305
Documentation
- Initialize doc around the test framework !7734 ~"area:CI"
Cleanups
- remove multus-ready, replaced by kstatus checks !7845 ~"area:networking"
- minor: Correct key name in keycloak chart values !7874 ~"area:misc"
- remove ingress-nginx-ready unit (replaced by poller/kstatus checks in ingress-nginx unit) !7847
- cleanup: Cleanup keycloak-resources unused fields !7875 ~"area:security" ~"security::user-and-role-management"
- Cleanup workaround Kyverno policy for baremetal bond_miimon config !7584 ~"area:networking" ~"capm3"
- cleanup: remove old Kustomizations from sylva-units pre-upgrade hook for Kustomizations.spec.prune !7935 ~"area:units-framework"
- Create velero namespace using new velero-init unit !7959
- Remove Whereabouts RKE2 image !7561 ~"area:networking" (issues: #3792)
- Removing duplicated entry of git_repo_url !8001
- Create trivy-system namespace using new trivy-operator-init unit !7952
- Create kepler namespace using new kepler-init unit !7980
- Create sbom-operator namespace using new sbom-operator-init unit !7960
- Create oauth2-proxy namespace using oauth2-init unit !7964
- Move MinIO components namespace creation to dedicated units !8011
- Create nvidia-gpu-operator namespace using new nvidia-gpu-operator-init unit !7951
- apply scripts: cleanup transition code that was needed to upgrade from sylva < 1.5 !7371 ~"area:units-framework"
- Enable pruning of Openbao as hashicorp-vault is deprecated and transition is not supported now !8052 (issues: #4124)
- Create kube-logging namespace using new logging-init unit !7981 ~"area:observability" ~"logging"
- Move Kunai namespace creation to kunai-init and rename existing unit to kunai-oidc !8064
- Move loki namespace creation to loki-init unit !8065
- Move thanos namespace creation to thanos-init unit !8066 ~"area:observability" ~"monitoring"
- Add small readability change to cluster healtcheck s-u template !8077 ~"area:capi"
- sylva-units: minor, cleanup/simplify cluster-healthchecks named template call !8068
- Keep HELM_FLAG as optional var with empty default !8008 ~"area:CI"
- Cleanup vault renovate config as hashicorp-vault is removed !8121 ~"area:CI" ~"area:security" ~"renovate::configuration" (issues: #4158)
- Remove healthcheck tests from gitlab CI as they are now handled by Sylva test framework !8172 ~"CI::functional-tests" ~"area:CI"
- Remove unused CI tests from README.md !8221 ~"area:CI"
- Cleanup: removing dead code,
return: Nonewill never called !8337
- Removing duplicate closing of file instead of just creating it's reference or calling it twice !8338 ~"area:CI"
CI
- Update dependency sylva-projects/sylva-elements/ci-tooling/ci-templates to v1.1.0 !7742 ~"renovate"
- feat: apply working in OCI mode with commit substitution !7546 ~"area:units-framework"
- Always record initial sylva-units watch !7808
- improve tuning of sylvactl/unitTimeout for cluster* units, in particular on libvirt-metal !7418 ~"area:capi" (issues: #3855)
- Update scheduled pipelines configuration (use OCI for ☁capm3 🚀rke2 🐧suse) !7811 ~"capm3" ~"rke2"
- CI: adjust hurl test to not assume anything on the name of the Keycloak Ingress !7886
- CI: fix typo additional-s !7892
- normalise the version by removing '/' prefix in check_downgrade_versions script !7905
- fail if healthCheck is set on Kustomization for a workload-cluster Helm-based unit !7849 ~"area:units-framework" (issues: #4043)
- CI: tweak gitlab CI sylva-toolbox cache key to avoid stale content !7967
- specify sylvactl --unit-timeout parameter (fix long-running CI runs) !7979
- Add chainsaw test for workload-team-defs VAP protection !7778 ~"Test" ~"area:workload-cluster"
- Enhance crust-gather command display in CI !7991
- tools/get_image_refs.py: remove the proxy part for the OCI artifacts to keep only the real artifact source !7810 ~"oci"
- Provide gitlab pages to expose scheduled pipeline report !7926
- tools/get_image_refs.py: don't fail if registry_mirrors.hosts_config !8028 ~"oci" (issues: #4116)
- Add AGENTS.md for scheduled report and fix minor bug !8037
- Add SSO test for Kunai !7986 ~"area:workload-cluster" ~"kunai"
- Invalidate cache if we encounter the old "sylva-toolbox-version" file in ensure_sylva_toolbox !8038
- fix: emulate ensure_sylva_toolbox script !8058
- Add Healthchecks for Trident StorageClass Units !7297 ~"area:storage" (issues: #3537)
- Ensure we don't have proxy variables set in image ref jobs !8067 ~"type::bug"
- Scheduled CI reports provide failure timeline and crustgather shortcut !8069
- Fixed failed tests count in CI scheduled report !8109
- Generalize chainsaw job for all the mgmt tests !7840
- Run publish-sylva-units-artifact in ensure mode for child pipelines from MR !8104 ~"type::bug" (issues: #4087)
- Keep HELM_FLAG as optional var with empty default !8008 ~"type::cleanup"
- Introduce Sylva test framework jobs in CI !7533
- Revert "Always record initial sylva-units watch" !8126
- Fix chainsaw run after rolling update !7832 ~"type::bug"
- Add a history graph on the global overview of CI scheduled report !8114
- CI - Improve download_artifact function !8125 (issues: #4161)
- Provide logs info in the Junit report !7793
- CI reports improve display !8137
- run wkld-detect-unplanned-node-rolling-updates on deploy runners !7352 (issues: #3845)
- Remap non deployment jobs from deploy to deployment test in CI reports !8156
- CI, scheduled reports: more readable icons for the deploy job strip !8170
- ci: add fallback .sylva-framework-test-tags !8165
- Filter out known warnings on Sylva test framework !8162
- Initialize doc around the test framework !7734 ~"area:documentation"
- Add collector jobs for test framework !7697
- Bump Sylva test framework to 1.0.1 !8173
- CI - Configure CAPM3 GCP infra to use GCP registry mirror !8136
- Sylva-test-framework: Add a generic fixture to check is a unit is enable in the cluster !8186
- Remove healthcheck tests from gitlab CI as they are now handled by Sylva test framework !8172 ~"type::cleanup"
- Remove unused CI tests from README.md !8221 ~"type::cleanup"
- Check for thanos_query_url existence before running tests !8219
- Don't use GCP private registries on capm3-virt preview !8237
- Harden multus-cleanup protection against eviction !8222 (issues: #3244)
- Improve get_image_refs.py !8085 ~"area:security" (issues: #3925)
- debug-on-exit.sh: replay last sylvactl watch command on failure !8213
- minor: fix drift detection script parsing broken by Flux log format change !8252
- Convert existing tests mgmt/wkld-namespaces-check into Sylva test framework !8155
- fix workload cluster deletion by scoping management protection VAPs to sylva-system !8292
- Strip ANSI color char from Junit reports !8293
- Fix intermittent bin/env failures in delete-workload-cluster !8290 ~"type::bug" (issues: #4242)
- CI python framework: set traceback to line by default !8313
- Fix uv.lock !8330
- Convert existing tests mgmt-detect-node-rolling-updates-after-pivot into Sylva test framework !8147
- Increase timeout for workload-teams-repo and cluster-machines-ready/capm3-virt !8310
- add PrometheusRule to detect keycloak-crossplane-provider cpu overconsumption... !7298 ~"area:security" ~"security::user-and-role-management"
- Fix harbor SSO test in case of upgrade !8215
- Removing duplicate closing of file instead of just creating it's reference or calling it twice !8338 ~"type::cleanup"
- Split the monolithic .setup_ci_context_and_values into smaller customizable parts !8235
- Fix flux SSO test in upgrade scenario !8214
- Fix Neuvector login tests !8231 ~"area:security" ~"neuvector" ~"type::bug" (issues: #4215)
- Fix Grafana SSO test title check !8344 ~"area:observability" ~"monitoring" ~"type::bug"
- CI: (minor/trivial) debug-on-exit: fix filename used to dump sylvactl watch re-run results !8346
- Fix cluster protection policy and convert tests for management cluster deletion protection policies into chainsaw tests !8100 ~"area:capi" (issues: #4146)
- Fix MR description template for OpenBao job variant !8368
- CI: detect units with a "narrow timeout" !8224
- Make check_juniper_auth and check_snmp_auth error messages more obvious !8379
- Convert existing tests verify longhorn cleanup event into Sylva test framework !8168
- Test vault plugin from sylva test framework !8244
- Update scheduled configuration !8390
- [release-1.7] CI: use ci-deployment-values 0.6.1 !8392
Internal tooling
- CI: ⚡ will use threads instead of comment for summary + use ⚡ for renovate pipelines !7608 ~"area:CI"
- Use renovate dry-run template from Sylva ci-templates !7971 ~"area:CI"
- CI: move general variables to common.yml !7870 ~"area:CI"
- Cleanup vault renovate config as hashicorp-vault is removed !8121 ~"area:CI" ~"area:security" ~"type::cleanup" (issues: #4158)
- fix version in kube-ovn unit, in order to be tracked by Renovate !8132 ~"area:networking"
- Renovate version track quotes !8138 ~"area:CI"
- Revert "Merge branch 'rennovate-version-track-quotes' into 'main'" !8270
- renovate: regroup harbor-configuration-operator updates !8349
- Update renovate configuration for release-1.7 !8257 ~"area:CI"
Contributors
38 people contributed.
Abhishek Bandarupalle, Advit Pandey, Akshay Yadav, Alain Thioliere, Alex Ghita, Alexandre Seitz, Alin H, Andra-Simona Delicostea, Andrew Kiselev, Bogdan Antohe, Bogdan-Adrian Burciu, Cristian Manda, Cristina Isaroiu, Daniel Kostecki, Dragos Gerea, Francois Eleouet, François-Régis Menguy, Ionut Spanu, Ishita Mittal, Jonathan Gayvallet, Loic Nicolle, Lupescu Daniel, Manik Bindlish, Mihai Zaharia, Médéric De Verdilhac, Nicolas Belouin, Patrick Enoux, Pierrick Seite, Praveen Varshney, Priya Goyal, Remi Le Trocquer, Sakshi Choudhary, Samuel Bartel, Sara Walia, Shreya Gupta, Teodora Pirvan, Thomas Morin, Xavier Francois