Skip to content

Releases: Dudude-bit/rubick

v4.21.2

Choose a tag to compare

@github-actions github-actions released this 30 Sep 21:09

Fixed

  • Rubick starts on Ubuntu 22.04, Debian 12 and Linux Mint 21. The
    .deb, .rpm and AppImage needed glibc 2.39 and did not start there at
    all. They now need 2.35. (#319)

  • The AppImage no longer opens a blank window on Fedora 44 and other
    distributions with a recent Mesa. It carried its own libwayland-client,
    and the page's process stopped with EGL_BAD_PARAMETER. (#319)

v4.21.1

Choose a tag to compare

@github-actions github-actions released this 30 Sep 07:27

Fixed

  • The AppImage starts for a user other than the one who mounted it. Its
    launcher could be run only by the mount's owner, so
    firejail --appimage, and the AppImage catalog's test, stopped with
    "Permission denied". Other installers are unchanged. (#318)

v4.21.0

Choose a tag to compare

@github-actions github-actions released this 29 Sep 17:36

Much of this release is under the hood. Besides Share on every
screen, a large part of it is optimisation and reworked code, most of it so
that a report and the screen it came from read each fact the same way. If
a screen or a report says something your cluster does not, please open an
issue.

Added

  • Share any object or screen, not only a pod. Every detail page, every
    list, Overview, Events, Changes, node utilisation and the integration pages
    have a Share button, and so do the resources of Traefik, cert-manager,
    Argo CD, Flux, the Prometheus operator, Istio, CloudNativePG, Scylla,
    Cilium, GKE, AWS and Azure. The file looks like the app in both themes and
    gives times in UTC. A list that was refused, read in part, still loading or
    narrowed by a search says so, and whatever could not be read is listed at
    the top instead of drawn as an empty section. Log lines can be left out of
    one report. (#309)

Changed

  • Shared reports hide more secrets. Log lines and settings in a report
    now lose values such as DB_PASSWORD=…, JSON keys named like a password or
    token, and prefixed tokens from GitHub, GitLab, Slack, AWS and Stripe; an
    address loses its user:pass@. (#309)

  • A published link belongs to its cluster. Publishing the same object
    from staging no longer replaces the link you published from prod. The first
    publish after updating gets a new link. (#309)

Fixed

  • Prometheus, Loki and identity providers with an ECDSA P-521 certificate
    can be reached again
    , as they could before 4.20.0. (#307, #308)

  • Node utilisation on kube-prometheus-stack. Every cell read "no series",
    because that chart drops the node's root cgroup series by default. The page
    now adds up each node's pods and says that this undercounts; the node page
    reads the same way. (#309)

  • Prometheus Monitors and Alerts scroll the list apart from the detail,
    and detail tab labels no longer clip to one letter. (#309)

  • English words and wrong count forms in the Russian interface: logs,
    charts, CronJobs, pod and Job rows, Secret and ConfigMap actions, and the
    connections graph. Prometheus › Monitors printed an empty namespace
    selector as {}; it now says every namespace. (#317)

v4.20.2

Choose a tag to compare

@github-actions github-actions released this 25 Sep 14:52

Fixed

  • Integrations are locked again for a reader limited to their own
    namespaces.
    4.20.1 asked whether the reader may list a vendor's objects in
    the namespaces they picked, while every vendor page reads the whole cluster,
    so such a reader saw an open cert-manager row and a page that was refused.
    The lock now asks the question the page asks. (#304)

  • Traefik and ingress-nginx say "TLS not checked" where they could not
    check.
    A host whose front, or Traefik's entry points, could not be read
    was drawn green and counted fine; a row could also say "no TLS" on the left
    and "TLS not checked" on the right. A host's TLS is now one answer, and the
    row, the map, its tag and the counts all read it.

Known

  • A Prometheus, Loki or identity provider serving an ECDSA P-521 certificate
    cannot be reached since 4.20.0: the app's TLS verifies no P-521 signature.
    The cluster connection is not affected. P-256, P-384 and RSA work.

v4.20.1

Choose a tag to compare

@github-actions github-actions released this 24 Sep 21:59

A large release under the hood. 4.20 reworked much of how the app
reads the cluster: lists over several namespaces, discovery, the TLS
stack, watches and streams, and how routes are judged — most of it for
speed and for saying "could not read" where it used to guess. We checked
it on real clusters, but a change this wide can still miss a case. If a
screen says something your cluster does not, please open an issue —
4.19.1 stays available if you need to step back.

A review of everything 4.20.0 changed, and of every pull request behind it,
found about 150 problems. This release fixes them. 4.20.0 stays a
pre-release.

Fixed

  • Identity providers with their own certificate authority sign in again.
    An idp-certificate-authority that is a self-signed CA:TRUE certificate,
    the kind openssl req -x509 makes, was refused on Linux in 4.20.0. The app
    now trusts exactly that certificate, and still checks the host name and
    the dates.

  • A CRD installed after you connect is found. 4.20.0 remembered what the
    cluster served for the whole session. Answers now age out, and a kind that
    is missing is looked up again after two minutes rather than on every poll.

  • "Could not look" no longer reads as "none". A refused or failed read
    shows as unread, in its own colour, on Flux, Argo CD, Cilium, Traefik,
    ingress-nginx, GKE, ALB, AKS, the Ingress list and page, the routing maps,
    the peek, certificates and Secrets, and operator controllers. "TLS not
    checked" is its own state, not "no TLS".

  • Routes. A route trace gives no verdict while its controller has said
    nothing, or has only said Unknown: no Accepted, no ResolvedRefs, no
    Programmed on its Gateway. A Gateway no controller has reported on is not
    called a dead end. "All serving" is said only over routes the trace can
    vouch for. A route's status entry for another listener, another port,
    or a ListenerSet with the Gateway's name is no longer read as this
    parent's, and one controller's answer for a listener does not hide
    another controller's refusal. A route no controller has written status
    for reads "a controller has not decided", not "something could not be
    read"; with Services refused, the routes page says so instead of
    "reading verdicts" forever; the connections graph's route stops are no
    longer English on a Russian screen.

  • Numbers. A pod's reservation follows Kubernetes' own rules for native
    sidecars, init containers, overhead and pod-level limits. Usage is measured
    against the running containers. The Gateway map leaves finished pods out of
    a backend's count. A Service whose port resolves on no pod, with the pods
    unread, no longer calls every pod ready.

  • Streams. A "tell me when" watch that lost its connection keeps saying
    so, and looks again after a lag. Log batches are cut by size too. A drain
    stopped early ends as cancelled. Log Download works without a Downloads
    folder and never overwrites a file.

  • Search says what it could not read. A cluster that lists Pods and
    refuses Services shows "4 matches · could not read Service" instead of
    "4 matches" in green, and "nothing matches" is said only over what was
    searched. macOS no longer autocorrects text typed into the palette, the
    log query or any list filter.

  • Tabs. Picking a cluster on the front door of a tab whose cluster left
    the kubeconfig now makes the tab that cluster's, with the namespaces it was
    last left on; it used to keep the lost name over the new cluster's rows.

  • Russian. Numbers agree with their nouns everywhere a sentence holds two
    of them — "из 1 узла", "в 1 объекте правил", "5 вещей", "1 строка" — and in
    English too ("1 of 5 hosts needs attention"). Links out read "Открыть в
    Prometheus", with one arrow. The front door's recent clusters no longer read
    "last used 5m ago" on a Russian screen.

  • Smaller things. The overview says when its warning events could not all
    be read. The replica warning in the YAML editor reads the
    right object in a file with several documents. A Gateway's not-programmed
    reason is red in the peek, as in the list. An English fallback no longer
    reads "0 pod". The Istio Subsets tab tells a subset that is maybe routed
    from one that is not.

Known

  • A self-signed CA:TRUE certificate in the Linux system store is still
    refused for integrations, which have no CA field of their own.
  • The shared integration client keeps the proxy it saw first.

v4.20.0

v4.20.0 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 23 Sep 11:49

Security

  • Web pages opened inside the app's window get no access to it. The app
    gave any https:// page the same plugin permissions as its own interface:
    the clipboard, opening programs, its events, its windows, a restart. No
    page here ever needed them — sign-ins open in your browser — and they are
    gone.

  • One TLS stack. Every connection the app makes — to the cluster,
    Prometheus, Loki, an identity provider — now goes through rustls with your
    system's certificate store, and OpenSSL is no longer linked on Linux.
    On Linux, a server certificate that names its host only in the Common
    Name, with no Subject Alternative Name, is now refused, as it already was
    on macOS and Windows and in every browser since 2017; TLS below 1.2 is not
    spoken. An integration set to skip verification still connects.

Changed

  • Several namespaces at once, honestly. Picking more than one namespace
    used to poll each list and, when one namespace refused, draw the others'
    rows as the whole selection. Every list now asks for the selection in one
    read, names each namespace it could not read — in the cluster's words, with
    the RBAC rule to copy — and says "none" only of the namespaces that
    answered. Lists stay live over several namespaces instead of polling, and
    pod usage is read in each namespace too, so a token with rights in a few
    namespaces keeps its metrics. A route kind the token cannot read is named
    too, where it used to count as a kind with no routes.

  • Startup. The window draws after 1.56 MB of script instead of 2.34 MB —
    the Russian catalogue, the peek panel, charts and the YAML editor load when
    they are first used — without the two-second wait for the system before the
    first frame, and a quarter of a second less spent resolving permissions.

  • A pod's requests and limits are what the scheduler reserves, on every
    screen: the Pods column, the pod page, the node budget, the overview's
    headroom and a workload's Usage ceilings. Pods with sidecars (Istio,
    Linkerd), a large init container or a RuntimeClass overhead show larger
    numbers than before, and the right ones.

  • Fewer reads of the cluster. Several namespaces' overview is one call
    that reads cluster-wide facts once. Connection panels and "My services"
    cards in one namespace share one read of it instead of seven lists each.
    Custom kinds are found through discovery, cached per cluster, instead of
    reading whole CRDs (12 MB → 1 MB on a cluster with 54 of them). Prometheus
    and Loki reuse their connections. Search reads names, not Secret values and
    Helm manifests, on every keystroke.

  • A pod shell keeps up. seq 1 300000 took 117 s to print and takes a
    quarter of a second; Cyrillic no longer breaks at chunk boundaries.

  • Downloading logs writes the file straight into Downloads and says
    where; a second download of the same log no longer overwrites the first.

Removed

  • Infrastructure Builder, which had no menu entry since 2.0, and
    Settings › Registries, which fed only its image search. Saved canvases and
    stored registry credentials leave config.toml on the next settings save.

Fixed

  • A read the cluster refused says so, in the cluster's words. Fifteen
    vendor pages (Traefik, ingress-nginx, Istio, Argo CD, Flux, cert-manager,
    CloudNativePG, Scylla, the clouds, Loki, Prometheus) said nothing, or
    "reading…" forever, when their objects could not be read; each now says
    why, with Retry and, for a refusal, the RBAC rule to copy. The same holds
    for the Services behind a route, a controller that could not be looked
    for ("unknown", not "not installed"), the peek's namespace contents and
    traffic path, a CronJob's runs, and the "Used by" panel, which no longer
    loses everything to one refused kind.

  • "Not connected" is not "deleted". A detail page with no live client, a
    container with no previous run, or a list the token cannot read used to be
    drawn as "the object was deleted".

  • Where a path into a Service stops is one rule, the same on the
    connections graph, the routing pages and "My services". "My services" no
    longer says "not read yet" about a Service with more than one replica. The
    Gateway map counts the pods behind each backend instead of "1 of 1 ready"
    for any number.

  • A route two controllers disagree about reads the same on every screen.
    The connections graph and the route trace called it accepted while the
    Gateway page and the map called it refused. One refusal decides now,
    everywhere, and a controller that is still deciding is not "Accepted".

  • Label selectors answer the same everywhere. A selector Kubernetes would
    refuse to build — NotIn with no values, an unknown operator — is "cannot
    be evaluated" on every page, instead of matching every object on the
    Prometheus and Cilium pages and nothing elsewhere.

  • Search finds TLSRoute, TCPRoute, UDPRoute, ListenerSet and
    BackendTLSPolicy on Gateway API 1.6 clusters, where it reported them
    unreadable.

  • Names with dots. Pods, nodes and workloads named as DNS subdomains —
    static pods on nodes with a full hostname, every EKS node — open, delete
    and debug.

  • Logs. A byte that is not UTF-8 no longer breaks the stream or the
    download; it shows as �.

  • ingress-nginx installed as a DaemonSet is found, and one behind a cloud
    load balancer with spec.defaultBackend no longer reads every host as
    served in the clear. The AKS page no longer says a pod has no Azure
    identity when its ServiceAccount could not be read.

  • Stale screens. Deleting a CRD updates every link to it at once;
    Helm rollback, upgrade and uninstall refresh the history; a ConfigMap edit
    reaches the pod's environment tab; restarting a pod refreshes its events.
    A watch of custom resources with a large status no longer sends
    multi-megabyte events.

  • Quantities. 1k reads as a thousand in the capacity view instead of
    dropping the node; 1K is refused as the API server refuses it.

  • Russian. Ages on a Russian screen no longer read "5m ago"; routing maps,
    the peek and the tool-path hint no longer print English words; picking two
    languages in a row no longer snaps back to the first.

  • A hidden window rests. Age columns and counters stop ticking while the
    window is hidden, and a refused read backs off to 30 s instead of retrying
    every 2 s forever.

  • Error messages read as the server wrote them, without
    "Tauri command 'x' failed:" in front.

v4.19.1

Choose a tag to compare

@github-actions github-actions released this 22 Sep 22:00

Fixed

  • The Flatpak opened a white window, on every release that had one. It
    carried the AppImage's own copies of WebKit, GTK, glib, wayland and some
    ninety other libraries, each loaded ahead of the runtime's, and the
    runtime's graphics driver could not load against the older wayland — so
    WebKit had no way to draw and aborted with Could not create default EGL display. The Flatpak now runs on the GNOME 50 runtime, which has its own
    WebKitGTK, and carries nothing but the app. Checked on AlmaLinux 8 with the
    Flatpak it ships. The first install downloads the GNOME runtime once.

  • Links in the Flatpak open in your browser through the desktop portal,
    rather than through a copy of xdg-open the bundle carried and the sandbox
    could not use.

v4.19.0

Choose a tag to compare

@github-actions github-actions released this 21 Sep 21:51

Added

  • Paste the alert that woke you, and open what it is about. An alert
    arrives as a wall of labels in a phone notification, and the object it
    names has to be found by hand at four in the morning. Paste it into the
    command palette: the app reads Alertmanager, Grafana, Datadog and the
    wrappers PagerDuty and Slack put around them, shows what it recognised and
    where each value came from — a deployment = line, the alert's own name, a
    guess from the Source: host — and opens the object in the cluster the
    alert meant. Nothing is assumed: a cluster it cannot match in your
    kubeconfig is offered as a choice rather than picked, a value recognised by
    shape says so, and the alert's own words stay quoted on the page beside
    what this app read itself.

  • A home page of the services you said were yours. Pin a Deployment,
    StatefulSet, DaemonSet or CronJob and it appears at the top of the
    overview with the five things you would otherwise open four screens for:
    what state it is in, how traffic reaches it, what changed last, what this
    app is waiting on, and what nobody looked at. Membership is never inferred
    — nothing arrives here because it was opened recently or carries a label —
    and the block stands even when the cluster-wide read is refused, which is
    the reader it is most for.

  • An Alerts tab for Prometheus. Every PrometheusRule in the cluster with
    the three things that decide whether it will ever fire: which Prometheus
    picks it up, whether that Prometheus actually loaded it, and what is
    burning right now. A rule object nobody loaded is not a quiet one, and the
    tab says which of the two it is looking at. Workload pages carry the
    alerts firing about the object itself, in the peek as well as the page.

  • An investigation as one file. What you worked out about a pod —
    the verdict, the facts, the traffic chain as it stood, what changed, the
    log lines and what could not be read — saved as a single self-contained
    HTML file with no Secret values in it and no request made when it opens.
    Publishing targets are optional: with one configured the same report goes
    up as a link that updates in place when you share the same object again.

  • Before applying, ask the server what would change. The YAML editor
    sends the document as a dry run first and shows the diff the cluster itself
    computes, so an apply is confirmed against what it would do rather than
    against what it looks like it would do.

  • Test a hypothesis from inside the pod, without kubectl. DNS, a port, an
    address: run the check from the pod's own network and read the answer in
    the app. A check that produced no answer says so rather than reporting a
    "no".

Changed

  • Large clusters. The pod list arrives as compact rows in chunks that fit
    the IPC budget, the overview is answered from the watch-fed stores instead
    of a full pod list, the YAML diff runs off the main thread, and a log batch
    costs its own lines rather than the whole buffer.

  • Every read ends in words. A read that runs long says so and says what
    would shorten it, rather than leaving a spinner to mean whatever the reader
    guesses.

Fixed

  • A refused list is not an empty one. A 403 on Services or Ingresses used
    to arrive as "there are none", which then became "this backend was never
    created", in red. The refusal is carried to the screen now, on the pages
    where it was invisible.

  • A cluster that refuses to answer does not borrow the last one's. A
    watch whose first list was refused kept resetting the failure counter on
    the event that arrives before it, so the app retried forever at full speed
    and the log file burned through in seconds — and the previous cluster's
    cache outlived the switch.

  • A write that ran out of time is not a write that failed. An apply whose
    answer did not arrive in the deadline said the write failed; it says what
    it actually knows, which is that it does not know.

  • Counting in a language with more than two forms. Eighteen strings put a
    number in front of a noun with one form for every count, so Russian read
    "2 горит" and "1 объектов". A test now refuses the next one.

  • The Flatpak. The web process is found from /app and the menu entry
    runs the launcher, so the icon opens a window rather than nothing.

v4.18.0

Choose a tag to compare

@github-actions github-actions released this 19 Sep 20:54

Added

  • A Flatpak, for the platforms none of the other artifacts can run on. On
    RHEL 8 and its rebuilds — AlmaLinux 8, Rocky 8 — nothing we shipped worked,
    and not for a packaging reason: the .rpm and .deb need
    libwebkit2gtk-4.1, for which that platform has no package at all, and the
    AppImage, which carries its own, needs a newer glibc than it has. The
    Flatpak runs on a runtime that has both. flatpak install ./Rubick-*.flatpak, and the runtime comes from Flathub the first time,
    several hundred megabytes, once.

  • Roll a StatefulSet or a DaemonSet. Restart existed for Deployments
    alone, so rolling a StatefulSet meant leaving the app for kubectl. A
    DaemonSet gets Restart and no Scale: its replica count is how many nodes it
    fits.

  • The way back from an object to the release that installed it. A
    workload Helm put there now says so and links to the release, on the page
    and in the peek. The pointer was already in the object's annotations and
    only one screen read it.

  • Every key the app answers to, on one sheet behind ?. Shortcuts lived
    in six separate listeners and nowhere a person could look. They come from
    one table now, and a test refuses a new listener the table does not name —
    a list that is complete today and quietly stops being complete is worse
    than no list.

  • Did it work. Restart, Scale, Apply and a changed image used to end in a
    toast saying the request was accepted, and then silence. Each is followed
    and answered now. Nothing is said until the object confirms the action
    reached it, so "rolled out" is never a verdict about the state before the
    click, and two minutes with no verdict is said in words rather than left
    quiet.

  • Freeze an interval in the log tail. On a chatty pod, the lines you were
    reading from four minutes ago were evicted by the live stream inside a
    minute. A frozen range is held outside the Keep budget and survives taking
    the filter off, so watching the tail no longer throws away what you kept.

  • Why slow. The performance recorder is off by default and always was, so
    whoever feels a stall is exactly the person with no numbers. The cheap half
    of it runs all the time now: a count in the status bar while there is
    something to say, and behind it the stalls, the big lists on screen and why
    they cost, and the largest answer the backend sent.

  • Columns you can resize. Drag any column's right edge; double-click it
    to put that pair back to their declared widths. Widths are remembered per
    list.

Fixed

  • A claim list the cluster refused is not a missing claim. A token
    allowed to read a pod but not its PersistentVolumeClaims was told the claim
    did not exist, which sends a person to rebuild storage that is running.

  • A route its own controller answers is not a route that drops traffic. A
    rule with no backendRefs was drawn as broken even where the Gateway's own
    controller is what answers it. The signal is the controller's domain, not a
    list of vendor names.

  • Release notes scroll. The What's New dialog ended mid-word with no
    scrollbar. The same shape was found and fixed wherever a scroller asked for
    a height its parent does not have.

  • A column dragged narrow no longer paints over the one beside it, in
    either density, and a header or a name that has to be cut ends in an
    ellipsis instead of mid-word. The narrowest a column may be is no longer
    wider than columns that are deliberately narrow, which made the actions
    strip inflate on the first pixel of any drag.

  • A list's search follows you to Events and to CRDs, which kept their
    filter out of the address and so showed everything while the address said
    otherwise.

  • Helm says a decoder's reason once, not wrapped in our own words twice.

v4.17.0

Choose a tag to compare

@github-actions github-actions released this 17 Sep 00:35
e143d67

Added

  • NetworkPolicies. The core kind, which this app did not read at all: a
    list, a page and a peek. A NetworkPolicy is the one built-in kind where the
    shape of the object and its effect come apart, so each row says what the
    policy does rather than what it contains. ingress: [] on a governed
    direction denies everything; ingress: [{}] is a rule with no peers and
    allows everything — one character of YAML, opposite meanings. A
    direction policyTypes does not name is one the policy makes no claim
    about
    , and another policy may govern it. podSelector: {} is every pod in
    the namespace, the widest thing a policy can say, and never a blank cell.

    The column it exists for is how many pods each policy actually picks. A
    policy whose selector matches nothing is accepted, listed, and enforces
    nothing, and no other screen can say so — the selector is in one object and
    the labels are in another. Where the pods could not be read that count is
    blank rather than zero: zero is the finding, and handing it to somebody who
    merely lacks permission to list pods would invent it.

  • Find a cluster by typing part of its name. A filter box above the
    cluster list, any substring, case-blind, with mod+F to reach it. The
    needle reaches exactly what the command palette's ! reaches, and no more:
    prod must not find pre-orders-dev in a list nothing ranks. The count
    beside the heading counts the rows under it.

    Thanks to @igordcard for this one.

  • Copy a name where you read it. The hover mark that addresses had, on
    every object name and page title. A right-click opens the app's own menu —
    copy the name, copy a link that opens the same place, open it in a new tab —
    instead of the webview's, whose "copy link address" produced an internal
    address that opens nothing anywhere.

  • What a new version brought. The first launch after an update opens the
    notes for every release since the one last seen, read from the changelog. A
    first install records where it starts and opens nothing. Settings › About
    keeps a way back to them.

Changed

  • A click on a row opens the peek, wherever on the row it lands; the page is
    a double click.
    Before, the name peeked and the whitespace beside it
    navigated, with nothing on screen saying which you would get. Leaving a
    peek for the page now carries the open tab with it, so a peek's Logs no
    longer lands on Overview.

  • A list's search lives in the address, which is what a tab records, so it
    survives leaving the tab and coming back. The namespace column is hidden
    while exactly one namespace is chosen — it said the same word on every row.

Fixed

  • The Delivery column was silent for nine kinds. A kind missing from the
    table of API groups made every GitOps surface answer "nothing to say" — the
    column, the detail block and the peek marks together, with nothing failing.
    Gateways, the five route kinds, HorizontalPodAutoscalers and
    PodDisruptionBudgets were all in that state on pages already written to ask.

  • The peek offered no Delete for a Gateway, a GatewayClass or a route,
    though the commands had existed for releases.

  • The Files tab on a ConfigMap key mounted over a single file opened on the
    file and said it could not be opened; it opens on the folder, with the file
    as a row that names the mount it came from. Downloads over 100 MiB are asked
    about rather than refused, up to 2 GiB.

  • The command palette stayed closed after opening a hit in a background
    tab, so opening three pods meant typing the search three times.