Skip to content

v0.58.2

Choose a tag to compare

@github-actions github-actions released this 10 Feb 07:05
· 104 commits to develop since this release
4d2a4bb

✨ What's New

  • Bump minimum k8s version, hardcoded bitnami images and helm charts by @CodesbyUnnati in #1782

Full Changelog: v0.58.1...v0.58.2

Installation and signature verification

Installation of kctrl

By downloading binary from the release

For instance, if you are using Linux on an AMD64 architecture:

# Download the binary
curl -LO https://github.com/carvel-dev/kapp-controller/releases/download/v0.58.2/kctrl-linux-amd64
# Move the binary in to your PATH
mv kctrl-linux-amd64 /usr/local/bin/kctrl
# Make the binary executable
chmod +x /usr/local/bin/kctrl

Via Homebrew (macOS or Linux)

$ brew tap carvel-dev/carvel
$ brew install kctrl
$ kctrl version

Verify checksums file signature

Install cosign on your system https://docs.sigstore.dev/system_config/installation/

The checksums file provided within the artifacts attached to this release is signed using Cosign with GitHub OIDC. To validate the signature of this file, run the following commands:

# Download the checksums file, certificate, and signature
curl -LO https://github.com/carvel-dev/kapp-controller/releases/download/v0.58.2/checksums.txt
curl -LO https://github.com/carvel-dev/kapp-controller/releases/download/v0.58.2/checksums.txt.pem
curl -LO https://github.com/carvel-dev/kapp-controller/releases/download/v0.58.2/checksums.txt.sig

### Verify the checksums file
cosign verify-blob checksums.txt --certificate checksums.txt.pem --signature checksums.txt.sig --certificate-identity-regexp=https://github.com/carvel-dev --certificate-oidc-issuer=https://token.actions.githubusercontent.com 

Verify binary integrity

To verify the integrity of the downloaded binary, you can utilize the checksums file after having validated its signature. For instance, if you are using Linux on an AMD64 architecture:

# Verify the binary using the checksums file
sha256sum -c checksums.txt --ignore-missing

Installation of kapp-controller

kapp-controller can be installed by using kapp

kapp deploy -a kc -f https://github.com/carvel-dev/kapp-controller/releases/download/v0.58.2/release.yml

or by using kubectl

kubectl deploy -f https://github.com/carvel-dev/kapp-controller/releases/download/v0.58.2/release.yml

Container Images

Kapp-controller and Kapp-controller-package-bundle images are available in Github Container Registry.

OCI Image URLs

  • ghcr.io/carvel-dev/kapp-controller@sha256:62067a466170ccb7d5f5376fe44e20f3dc2f4a6a805018657f0975dff3075bd8
  • ghcr.io/carvel-dev/kapp-controller-package-bundle@sha256:e7e5d090c01291c7339dcfd3beb76caf8f9eaf182cb3d14e788189808c1baf07

Verify container image signature

The container images are signed using Cosign with GitHub OIDC. To validate the signature of OCI images, run the following commands:

# Verifying kapp-controller image
cosign verify ghcr.io/carvel-dev/kapp-controller@sha256:62067a466170ccb7d5f5376fe44e20f3dc2f4a6a805018657f0975dff3075bd8 --certificate-identity-regexp=https://github.com/carvel-dev --certificate-oidc-issuer=https://token.actions.githubusercontent.com -o text

# Verifying kapp-controller-package-bundle image
cosign verify ghcr.io/carvel-dev/kapp-controller-package-bundle@sha256:e7e5d090c01291c7339dcfd3beb76caf8f9eaf182cb3d14e788189808c1baf07 --certificate-identity-regexp=https://github.com/carvel-dev --certificate-oidc-issuer=https://token.actions.githubusercontent.com -o text

📂 Files Checksum

212e6a69726d97b82af8a31fc74dadc4e9b93954c2136501fa3d24f149b70af2  ./release.yml
902d763216276eaa5102dfd533da6d022a4b077c76bf9cab3f89011c9a9832ba  ./kctrl-darwin-amd64
9fe6b476c3bbd7f88eb37faf73627564ef23e9746837c066e019d3700bda0ee4  ./kctrl-darwin-arm64
b84cd677eba558aebbae5fae9b408eb77d13c90d6e6ea887109f0cfd35017371  ./kctrl-linux-amd64
e67117bfab025cf4cfcc64d4157b9df1f5dd330092fddd3181226b2a13a7e233  ./kctrl-linux-arm64
aa683f4650bea1b68ff5f0556e27644324ad348e82399489c652a4d5e558d8a4  ./kctrl-windows-amd64.exe
4ca90bcaed05ab975d420be2c3e614956a39da2cc4ac6e451ad33ea999af063c  ./package.yml
7a6aa35600459a1797a6f0564ae89954e6da035fe54e19b72c573f5b31938a8c  ./package-metadata.yml