You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Added
Callback-scoped streaming GET through K8sClient.streamGet(io, path, options, context, callback). The callback receives
copied response metadata and a decompressed body reader while the request, response,
redirect storage, decompressor, and buffers remain alive in the caller's task.
Bearer credentials are retained across same-origin redirects and omitted whenever
scheme, host, or effective port changes.
Structured watch completion through additive watchOutcome and watchWithContextOutcome methods. WatchOutcome distinguishes EOF, cancellation,
401, 403, HTTP 410, throttling with copied integer Retry-After, server errors,
other HTTP failures, malformed events, Kubernetes Status errors, transport
failures, and typed-object decode failures. Existing watch methods remain
compatibility wrappers, including ExpiredResourceVersion for either HTTP 410 or
an in-stream Status with code 410 or reason Expired.
Public exports for resource_registry, StreamGetOptions, StreamResponseMeta, WatchOutcome, and bounded, inline-owned WatchErrorDetail.
PodCertificateRequest (certificates.k8s.io/v1, namespaced). The v1
schema drops PKIXPublicKey and ProofOfPossession vs v1beta1; those
fields are not modeled.
Live integration entrypoint test-k8s-137-crud — list → create → get →
delete of DeviceTaintRule, ClusterTrustBundle, and StorageVersionMigration v1 through kubectl proxy. Verified against
Kubernetes 1.37.0 (kindest/node). PodCertificateRequest is not created
live: the apiserver requires a real pod/node/service-account UID plus a
kubelet-shaped PKCS#10 stub.
MetricsClient.initFromDiscovery / groupVersionFromDiscovery: use metrics.k8s.io/v1 only when this cluster's /apis prefers it. Default init stays on v1beta1.
Changed
WATCH framing accepts events up to 4 MiB and rejects larger frames without
unbounded allocation. Malformed events and ERROR events now terminate with an
inspectable outcome instead of losing their reason.
StreamGetOptions.pretty is tri-state. Setting it to false emits pretty=false explicitly, so compact LIST requests do not depend on omission
semantics; existing query parameters retain their order and fragments stay out of
the request target.
StorageVersionMigration registry pin storagemigration.k8s.io/v1beta1 → v1 (GA in 1.37; v1beta1 is deprecated, removal targeted 1.40).
README coverage figures corrected: 73 kinds / 19 API groups (was still
advertising the pre-0.6.0 "65 / 20" count, listed EndpointSlice under the
wrong group, and linked a missing FEATURE_PARITY_STATUS.md). Architecture
tree no longer names the deleted kubeconfig_json.zig.
Fixed
Corrupt or truncated compressed 401/403 bodies preserve the HTTP status in
caller-owned ApiError detail and are not misclassified as retryable transport
failures.
307/308 responses to requests with bodies are rejected without replaying the body
and without leaking redirect storage.
BOOKMARK resource versions remain owned across callback teardown; malformed
BOOKMARK and ERROR payloads return bounded diagnostics. Code-only 410 Status
events retain compatibility with informer relisting.
Notes
metrics.k8s.io default pin stays v1beta1. Re-checked 2026-08-30:
metrics-server masterpkg/api/install.go still only maps v1beta1; issue 1786
is open and PR 1855
is still a draft. The apiserver defining v1 in 1.37 does not change that —
metrics.k8s.io is an aggregated API. MetricsClient.initFromDiscovery will
use v1 once a cluster's /apis prefers it.
Alpha 1.37 kinds stay untyped (tripwire in tests/k8s_137_test.zig): lifecycle.k8s.io/v1alpha1 Eviction + EvictionRequest (EvictionRequestAPI,
default off; Pod field is .spec.evictionResponders on the 1.37.0 tag), scheduling.k8s.io/v1alpha3 CompositePodGroup, beta scheduling.k8s.io/v1beta1 Workload + PodGroup (GenericWorkload). Use Discovery + DynamicClient if a cluster has the feature gates on. Pods.evict remains the GA policy/v1 pod subresource.
StorageVersionMigration v1 spec.resource is GroupResource (group + resource only). Sending version is a strict-decoding 400.
Direct HTTPS to an API server is still blocked in Zig std, not this
library. std.crypto.tls.Client has no certificate_request arm
(ziglang/zig#19521) on 0.16.0
and on 0.17.0-dev.1936. kubectl proxy / connectWithFallback() remain the
working path. Tripwire: tests/advanced_features_test.zig.
Zig 0.17-dev still cannot build this project. Reproduced on 0.17.0-dev.1936+5a625d5f3: yaml-zig build.zig calls removed b.pathFromRoot; zig-protobuf build_util.zig sets removed StepOptions.id (renamed to tag). The library sources also fail on 0.17's
removal of the ** splat. zig-protobuf zig-master (50f1b1c) is a 0.17
port and would break 0.16; yaml-zig has no 0.17 port. Do not bump either pin.
This project's own source is still not compiled on 0.17.
resource.k8s.io/v1beta1 removal is a no-op: DRA kinds are already pinned
to v1 (GA 1.34). kubernetes#137924 stops serving v1beta1 in 1.41
(unsupported in 1.38); master still registers v1beta1Storage as of 2026-08-30.
Tripwire: tests/resource_registry_test.zig.