Skip to content

v0.5.0

Choose a tag to compare

@github-actions github-actions released this 09 Jul 04:59
· 81 commits to main since this release
19e25e1

Upgrade notes

Three things need your attention before upgrading. The new forceful fallback itself is opt-in and off by default, so it requires no action from existing users.

Apply the CRD before helm upgrade. This release adds surge.forcefulFallback to the RotationPolicy CRD, and Helm does not upgrade CRDs — it only installs them on first install. Run kubectl apply -f charts/node-rotation-controller/crds/ (or apply the CRD from the packaged chart) before helm upgrade, otherwise a policy that sets the new field is rejected at admission.

Candidate selection now orders by deadline, not by age. The controller picks the eligible candidate with the earliest forceful-expiration deadline (creationTimestamp + expireAfter) rather than the oldest node. This only changes behavior when expireAfter is heterogeneous across NodeClaims, where a younger claim with a shorter expireAfter can reach forceful expiration before an older claim with a longer one. If every NodeClaim in a pool shares the same expireAfter, deadline order equals oldest-first and the pick is unchanged.

Nodes you have annotated karpenter.sh/do-not-disrupt are now excluded from candidate selection. The controller distinguishes its own transient do-not-disrupt (marked with noderotation.io/do-not-disrupt-owned) from one you applied yourself, and never rotates or unprotects the latter. If you were relying on the controller rotating such nodes, remove the annotation.

Verifying this release

Both the container image and the Helm chart are published with a keyless cosign signature and a GitHub build-provenance attestation bound to the release workflow's OIDC identity. The image also carries an in-registry SBOM and SLSA provenance, and an SPDX SBOM is attached to this release. See SECURITY.md for the cosign verify and gh attestation verify invocations.


What's Changed

Features

  • feat(api): add reserved surge.forcefulFallback toggle (#156 D2) by @AkashiSN in #161
  • feat(schedule): ThroughputBurstShortfall detection for synchronized batches (#156 D3) by @AkashiSN in #163
  • feat(controller): window-bounded surge-less forceful fallback (#156 D4) by @AkashiSN in #165
  • feat(selection): order candidates by earliest deadline (#157) by @AkashiSN in #169
  • feat: exclude do-not-disrupt nodes from rotation candidate selection by @AkashiSN in #170
  • feat(release): publish SBOM, provenance, and signatures for the image and chart by @AkashiSN in #208
  • feat(chart): alert on rising noderotation_forceful_fallback_total by @AkashiSN in #205

Fixes

  • fix(ci): include chart CRD copy in lint verify diff by @AkashiSN in #193

Documentation

  • docs(adr): ADR-0001 window-bounded forceful fallback (relax surge-only) by @AkashiSN in #158
  • docs(spec): forceful fallback + burst shortfall; accept ADR-0001 by @AkashiSN in #159
  • docs: bilingual VitePress GitHub Pages site (spec/runbook/figures + developer CI/CD page) by @AkashiSN in #176
  • docs: split specification into chapters, consolidate reference/, redesign nav by @AkashiSN in #178
  • docs: fix mistranslations, omissions, and broken sentences (EN/JA parity) by @AkashiSN in #181
  • docs: unify terminology across JA spec/runbook and add §1.4 glossary/symbol entries by @AkashiSN in #182
  • docs: restructure dense spec/runbook/ci-cd paragraphs for readability (EN/JA) by @AkashiSN in #183
  • docs(readme): fix JA omissions/overstatements, align PDB wording, restructure install by @AkashiSN in #184
  • docs(spec): close EN spec/ADR consistency & completeness gaps by @AkashiSN in #188
  • docs(site): add planned→validated status column to CoverageMatrix (#186) by @AkashiSN in #189
  • docs(contributing): codify JA translation conventions (code-comment, stuck-drain) by @AkashiSN in #190
  • docs: close remaining JA terminology/wording gaps from doc review Step 1 by @AkashiSN in #192
  • docs: refresh the READMEs and the §6.2 roadmap for v0.5.0 by @AkashiSN in #204
  • docs(ja): translate the perf notes and codify ADRs as English-only by @AkashiSN in #206

Maintenance

  • test(e2e): KWOK surge-less forceful-fallback scenario (#156 D5) by @AkashiSN in #167
  • test(e2e): trick-free real-EKS validation of forceful fallback / #157 / #170 (Scenario O) by @AkashiSN in #171
  • chore(ci): skip heavy CI steps on docs-only changes via per-job change detection by @AkashiSN in #174
  • chore: drop ConfigMap-era configuration references by @AkashiSN in #179
  • chore(docker): pin base image digests for reproducible builds by @AkashiSN in #194
  • test(controller): pin surgelessFallback threshold boundaries by @AkashiSN in #201
  • chore(chart)!: remove the deprecated singular rotationPolicy value by @AkashiSN in #202
  • chore(chart): bump to 0.5.0 and close the chart-side doc gaps by @AkashiSN in #203
  • chore(github): categorize auto-generated release notes by @AkashiSN in #207

Full Changelog: v0.4.0...v0.5.0