v0.2.0
0.2.0 — 2026-04-13
Hardening release. Every v0.1.0 feature that existed in the codebase but
was never actually executed end-to-end has now been run against a real
kind cluster — with backups going to MinIO and the REST API served over
cert-manager-issued TLS. Several real bugs were found and fixed as a
direct result of this exercise.
Added
- REST API wired into the manager process (
--enable-api,
--api-address,--api-namespace,--api-tls-cert-dir). It was shipped
as a package in 0.1.0 but never started bycmd/main.go. - TLS support for the REST API via a mounted cert directory, plus Helm
chart plumbing for cert-manager:Issuer(self-signed default) and
Certificateresources with in-cluster DNS SANs. - Helm chart:
apiService,api.tls.enabled/api.tls.certManager.*
values, ands3.credentialsSecretNamefor wiring backup credentials. - End-to-end test suite for
PrometheusClusterlifecycle (create, scale,
backup-toggle, finalizer) intest/e2e/, plus anE2E_SKIP_SETUP=true
escape hatch for running specs against an already-deployed operator. - Restore runbook at
docs/RESTORE.{en,zh}.md, verified against MinIO.
Fixed
cmd/main.gocalledctrl.SetupSignalHandler()twice, causing
panic: close of closed channelat startup. The handler is now set up
once and shared between the AWS config load andmgr.Start.- Reconciler only updated the
StatefulSettemplate whenspec.replicas
changed, so togglingspec.backup.enableddid not flip the container
args. It now compares the full pod template via
equality.Semantic.DeepEqualand patches on any drift. - Backup
Scheduler.Startwas registered as a manager runnable but no
cluster was ever registered with it, so cron never fired. The scheduler
is now exposed to the reconciler via aBackupRegistrarinterface and
registered on every reconcile whenspec.backup.enabledis true. - Scaled-cluster phase is now consistently
Scalingwhen replicas change
(the Milestone-1 change had collapsed it toProvisioningunder
envtest, which the regression test caught).