Skip to content

v0.3.1

Choose a tag to compare

@github-actions github-actions released this 22 Nov 18:43
· 1301 commits to main since this release

The v0.3.1 release is a patch release which includes some bug fixes and makes
the ability for BPF enabled applications to receive their maps via bpfd's
custom CSI plugin default.

This enablement means that most applications can now access their maps WITHOUT
being run as root.

Warning

The CSI feature still requires a privileged application on distributions which
enable SELinux by default (i.e Red Hat Openshift). Therefore we've shipped a set of
deployment configs specifically for openshift in this release, see the additional
go-<example>-counter-install-ocp-v0.3.1.yaml artifacts included in the release
payload. Stay tuned to #829 for
updates.

The new yaml syntax that should be used by BPF enabled applications resembles
the following:

apiVersion: apps/v1
kind: DaemonSet
metadata:
  name: <APP_NAME>
  ...
spec:
  ...
  template:
    ...
    spec:
     ...
          volumeMounts:
            - name: bpf-maps
              mountPath: /bpf-maps
      volumes:
        - name: bpf-maps
          csi:
            driver: csi.bpfd.dev
            volumeAttributes:
              csi.bpfd.dev/program: <*Program_Name>
              csi.bpfd.dev/maps: <BPF Map Names>

Additionally, this release removes all dependencies involved with deploying bpfd
with TLS, which means that cert-manager dependencies are completely removed from
the operator, therefore simplifying the deployment considerably.

Lastly, the bpfd user and user group was removed which will only effect users
that run bpfd via a systemd service and try to use bpfctl without root
privileges. This helped reduce internal complexity and allows us to focus instead
on finetuning the permissions of the bpfd process itself, see the linux
capabilities guide
for more information.

What's Changed (excluding dependency bumps)

Full Changelog: v0.3.0...v0.3.1