v0.58.2
✨ What's New
- Bump minimum k8s version, hardcoded bitnami images and helm charts by @CodesbyUnnati in #1782
Full Changelog: v0.58.1...v0.58.2
Installation and signature verification
Installation of kctrl
By downloading binary from the release
For instance, if you are using Linux on an AMD64 architecture:
# Download the binary
curl -LO https://github.com/carvel-dev/kapp-controller/releases/download/v0.58.2/kctrl-linux-amd64
# Move the binary in to your PATH
mv kctrl-linux-amd64 /usr/local/bin/kctrl
# Make the binary executable
chmod +x /usr/local/bin/kctrlVia Homebrew (macOS or Linux)
$ brew tap carvel-dev/carvel
$ brew install kctrl
$ kctrl versionVerify checksums file signature
Install cosign on your system https://docs.sigstore.dev/system_config/installation/
The checksums file provided within the artifacts attached to this release is signed using Cosign with GitHub OIDC. To validate the signature of this file, run the following commands:
# Download the checksums file, certificate, and signature
curl -LO https://github.com/carvel-dev/kapp-controller/releases/download/v0.58.2/checksums.txt
curl -LO https://github.com/carvel-dev/kapp-controller/releases/download/v0.58.2/checksums.txt.pem
curl -LO https://github.com/carvel-dev/kapp-controller/releases/download/v0.58.2/checksums.txt.sig
### Verify the checksums file
cosign verify-blob checksums.txt --certificate checksums.txt.pem --signature checksums.txt.sig --certificate-identity-regexp=https://github.com/carvel-dev --certificate-oidc-issuer=https://token.actions.githubusercontent.com Verify binary integrity
To verify the integrity of the downloaded binary, you can utilize the checksums file after having validated its signature. For instance, if you are using Linux on an AMD64 architecture:
# Verify the binary using the checksums file
sha256sum -c checksums.txt --ignore-missingInstallation of kapp-controller
kapp-controller can be installed by using kapp
kapp deploy -a kc -f https://github.com/carvel-dev/kapp-controller/releases/download/v0.58.2/release.ymlor by using kubectl
kubectl deploy -f https://github.com/carvel-dev/kapp-controller/releases/download/v0.58.2/release.ymlContainer Images
Kapp-controller and Kapp-controller-package-bundle images are available in Github Container Registry.
OCI Image URLs
- ghcr.io/carvel-dev/kapp-controller@sha256:62067a466170ccb7d5f5376fe44e20f3dc2f4a6a805018657f0975dff3075bd8
- ghcr.io/carvel-dev/kapp-controller-package-bundle@sha256:e7e5d090c01291c7339dcfd3beb76caf8f9eaf182cb3d14e788189808c1baf07
Verify container image signature
The container images are signed using Cosign with GitHub OIDC. To validate the signature of OCI images, run the following commands:
# Verifying kapp-controller image
cosign verify ghcr.io/carvel-dev/kapp-controller@sha256:62067a466170ccb7d5f5376fe44e20f3dc2f4a6a805018657f0975dff3075bd8 --certificate-identity-regexp=https://github.com/carvel-dev --certificate-oidc-issuer=https://token.actions.githubusercontent.com -o text
# Verifying kapp-controller-package-bundle image
cosign verify ghcr.io/carvel-dev/kapp-controller-package-bundle@sha256:e7e5d090c01291c7339dcfd3beb76caf8f9eaf182cb3d14e788189808c1baf07 --certificate-identity-regexp=https://github.com/carvel-dev --certificate-oidc-issuer=https://token.actions.githubusercontent.com -o text📂 Files Checksum
212e6a69726d97b82af8a31fc74dadc4e9b93954c2136501fa3d24f149b70af2 ./release.yml
902d763216276eaa5102dfd533da6d022a4b077c76bf9cab3f89011c9a9832ba ./kctrl-darwin-amd64
9fe6b476c3bbd7f88eb37faf73627564ef23e9746837c066e019d3700bda0ee4 ./kctrl-darwin-arm64
b84cd677eba558aebbae5fae9b408eb77d13c90d6e6ea887109f0cfd35017371 ./kctrl-linux-amd64
e67117bfab025cf4cfcc64d4157b9df1f5dd330092fddd3181226b2a13a7e233 ./kctrl-linux-arm64
aa683f4650bea1b68ff5f0556e27644324ad348e82399489c652a4d5e558d8a4 ./kctrl-windows-amd64.exe
4ca90bcaed05ab975d420be2c3e614956a39da2cc4ac6e451ad33ea999af063c ./package.yml
7a6aa35600459a1797a6f0564ae89954e6da035fe54e19b72c573f5b31938a8c ./package-metadata.yml