Skip to content

v0.7.0

Choose a tag to compare

@github-actions github-actions released this 31 Aug 18:23
· 8 commits to main since this release
e5f21c0

Added

  • Callback-scoped streaming GET through
    K8sClient.streamGet(io, path, options, context, callback). The callback receives
    copied response metadata and a decompressed body reader while the request, response,
    redirect storage, decompressor, and buffers remain alive in the caller's task.
    Bearer credentials are retained across same-origin redirects and omitted whenever
    scheme, host, or effective port changes.
  • Structured watch completion through additive watchOutcome and
    watchWithContextOutcome methods. WatchOutcome distinguishes EOF, cancellation,
    401, 403, HTTP 410, throttling with copied integer Retry-After, server errors,
    other HTTP failures, malformed events, Kubernetes Status errors, transport
    failures, and typed-object decode failures. Existing watch methods remain
    compatibility wrappers, including ExpiredResourceVersion for either HTTP 410 or
    an in-stream Status with code 410 or reason Expired.
  • Public exports for resource_registry, StreamGetOptions, StreamResponseMeta,
    WatchOutcome, and bounded, inline-owned WatchErrorDetail.
  • Kubernetes 1.37 GA kinds, typed and registered:
    • DeviceTaintRule (resource.k8s.io/v1, cluster-scoped)
    • ClusterTrustBundle (certificates.k8s.io/v1, cluster-scoped)
    • PodCertificateRequest (certificates.k8s.io/v1, namespaced). The v1
      schema drops PKIXPublicKey and ProofOfPossession vs v1beta1; those
      fields are not modeled.
  • Live integration entrypoint test-k8s-137-crud — list → create → get →
    delete of DeviceTaintRule, ClusterTrustBundle, and
    StorageVersionMigration v1 through kubectl proxy. Verified against
    Kubernetes 1.37.0 (kindest/node). PodCertificateRequest is not created
    live: the apiserver requires a real pod/node/service-account UID plus a
    kubelet-shaped PKCS#10 stub.
  • MetricsClient.initFromDiscovery / groupVersionFromDiscovery: use
    metrics.k8s.io/v1 only when this cluster's /apis prefers it. Default
    init stays on v1beta1.

Changed

  • WATCH framing accepts events up to 4 MiB and rejects larger frames without
    unbounded allocation. Malformed events and ERROR events now terminate with an
    inspectable outcome instead of losing their reason.
  • StreamGetOptions.pretty is tri-state. Setting it to false emits
    pretty=false explicitly, so compact LIST requests do not depend on omission
    semantics; existing query parameters retain their order and fragments stay out of
    the request target.
  • StorageVersionMigration registry pin storagemigration.k8s.io/v1beta1 →
    v1 (GA in 1.37; v1beta1 is deprecated, removal targeted 1.40).
  • README coverage figures corrected: 73 kinds / 19 API groups (was still
    advertising the pre-0.6.0 "65 / 20" count, listed EndpointSlice under the
    wrong group, and linked a missing FEATURE_PARITY_STATUS.md). Architecture
    tree no longer names the deleted kubeconfig_json.zig.

Fixed

  • Corrupt or truncated compressed 401/403 bodies preserve the HTTP status in
    caller-owned ApiError detail and are not misclassified as retryable transport
    failures.
  • 307/308 responses to requests with bodies are rejected without replaying the body
    and without leaking redirect storage.
  • BOOKMARK resource versions remain owned across callback teardown; malformed
    BOOKMARK and ERROR payloads return bounded diagnostics. Code-only 410 Status
    events retain compatibility with informer relisting.

Notes

  • metrics.k8s.io default pin stays v1beta1. Re-checked 2026-08-30:
    metrics-server master pkg/api/install.go still only maps v1beta1;
    issue 1786
    is open and PR 1855
    is still a draft. The apiserver defining v1 in 1.37 does not change that —
    metrics.k8s.io is an aggregated API. MetricsClient.initFromDiscovery will
    use v1 once a cluster's /apis prefers it.
  • Alpha 1.37 kinds stay untyped (tripwire in tests/k8s_137_test.zig):
    lifecycle.k8s.io/v1alpha1 Eviction + EvictionRequest (EvictionRequestAPI,
    default off; Pod field is .spec.evictionResponders on the 1.37.0 tag),
    scheduling.k8s.io/v1alpha3 CompositePodGroup, beta
    scheduling.k8s.io/v1beta1 Workload + PodGroup (GenericWorkload). Use
    Discovery + DynamicClient if a cluster has the feature gates on.
    Pods.evict remains the GA policy/v1 pod subresource.
  • StorageVersionMigration v1 spec.resource is GroupResource (group +
    resource only). Sending version is a strict-decoding 400.
  • Direct HTTPS to an API server is still blocked in Zig std, not this
    library. std.crypto.tls.Client has no certificate_request arm
    (ziglang/zig#19521) on 0.16.0
    and on 0.17.0-dev.1936. kubectl proxy / connectWithFallback() remain the
    working path. Tripwire: tests/advanced_features_test.zig.
  • Zig 0.17-dev still cannot build this project. Reproduced on
    0.17.0-dev.1936+5a625d5f3: yaml-zig build.zig calls removed
    b.pathFromRoot; zig-protobuf build_util.zig sets removed
    StepOptions.id (renamed to tag). The library sources also fail on 0.17's
    removal of the ** splat. zig-protobuf zig-master (50f1b1c) is a 0.17
    port and would break 0.16; yaml-zig has no 0.17 port. Do not bump either pin.
    This project's own source is still not compiled on 0.17.
  • resource.k8s.io/v1beta1 removal is a no-op: DRA kinds are already pinned
    to v1 (GA 1.34). kubernetes#137924 stops serving v1beta1 in 1.41
    (unsupported in 1.38); master still registers v1beta1Storage as of 2026-08-30.
    Tripwire: tests/resource_registry_test.zig.