Repository navigation
v0.33.0
Changes by Kind
API Change
- Add --shard-labels to shard flags
Add conditionSchedulableto shards (#4361, @mjudeikis) - Add LogicalCluster quota limited --logical-cluster-object-count-scan-interval (#4259, @mjudeikis)
- Add names selector into ClusterCachedResource (#4328, @mjudeikis)
- Adds spec.deletionPolicy: Delete | WaitForSuccessor for better handling of the resources, served by apibindings (#4275, @mjudeikis)
- BREAKING CHANGE: APIExport's resource storage
virtualno longer hasidentityHashfield (#4326, @gman0) - BREAKING: the kinds
CachedResourceandCachedResourceEndpointSlicefrom the API groupcache.kcp.io, that can be enabled with the Alpha feature gateCachedAPIs, have been renamed toClusterCachedResourceandClusterCachedResourceEndpointSlice.ClusterCachedResourceEndpointSliceSpec.ClusterCachedResourcenow references the cluster scoped object. The resource plurals, REST paths, RBAC, and finalizer are renamed accordingly. There is no automatic migration for existing objects. (#4281, @neolit123) - Bug: stop serving OpenAPI v3 from the
system:bound-crdsworkspace as it may contain duplicated GVKs sourced from different consumers. (#4333, @neolit123) - LogicalClusterDump is now paginated. Origin shard sends the data in pages (limited by entry count and total size), not the whole logical cluster in one response. LogicalClusterMigration status now shows entriesCopied and dumpContinue, so if destination shard restarts, it continues the copy from where it stopped instead of starting again. (#4244, @iakmc)
- Make EndpointSlices unified api and create api aliases (#4304, @mjudeikis)
- Support selectableFields on APIResourceSchema (#4212, @EpicStep)
Feature
- Add "kubectl ws tree -w" for watch (#4323, @mjudeikis)
- Add AI pen testing framework (#4225, @mjudeikis)
- Add an optional
--header-fileflag toapigenused to append boilerplate to the generated YAML files (#4229, @xmudrii) - Add identity forward to virtual workspaces (#4310, @mjudeikis)
- Allow migrating apiexports without deleting the resource (#4273, @mjudeikis)
- Enable the following flags for all CLI commands similarly to how kubectl supports them: --as, --as-group, --client-certificate, --client-key, --cluster, --request-timeout. (#4313, @neolit123)
- Move static tilt setup to Starlark-type configuration (#4245, @mjudeikis)
- No user-facing behavior changes here — this only affects internal HTTP client reuse during migrations. (#4272, @iakmc)
- Wire in StorageVersionAPI feature flag (#4262, @mjudeikis)
- Wire in contrib-dashboard into tilt setup (#4282, @mjudeikis)
- Add Upgrade test in CI (#4355, @mjudeikis)
Documentation
- Display out of date banner on old documentation versions (#4289, @SimonTheLeg)
- Documentation: included a quickstart guide with kind and helm (#4296, @neolit123)
Failing Test
- Fix informer bug in LC migration (#4364, @mjudeikis)
Bug or Regression
- Add TokenReview support for delegated auth in apiexport virtual workspace (#4280, @mjudeikis)
- Add hop limit for Virtual workspaces (#4303, @mjudeikis)
- Bugfix: on APIExport deletion, clear all managed 'extra annotations' from associated APIBindings. (#4254, @neolit123)
- Cache-server honours --etcd-prefix (#4292, @ntnn)
- Fix cross-shard reads of permission-claimed resources through the APIExport virtual workspace: a shard that does not serve a claimed resource now returns an empty list/watch instead of a 404, so a consuming provider's informer is not wedged when the claimed objects live on another shard. (#4215, @mjudeikis)
- Fix dynamic-restmapper when dealing with multi-version apis, where different object might not exists in v2 but does in v1 (#4298, @mjudeikis)
- Fixed a bug where the
DynamicRESTMappercould store an incorrect/empty type mapping for a CRD observed before it reached theEstablishedcondition. (#4322, @pujitha24) - Fixed mounted workspace access failing with
Unauthorizedin sharded deployments, a regression introduced by the fix for GHSA-c8w2-fgvx-vhv4. Enabling mounts now requires configuring the front-proxy with--requestheader-client-ca-fileand each shard with--mount-proxy-client-cert-file/--mount-proxy-client-key-file. (#4238, @xmudrii) - Retry APIExport references that are not resolvable yet (#4331, @mjudeikis)
Other (Cleanup or Flake)
- Informers and watches established before a LogicalClusterMigration now relist promptly after the migration instead of stalling until the destination shard's resource version catches up. (#4264, @mjudeikis)
Dependencies
Added
Nothing has changed.
Changed
- github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp: v1.31.0 → v1.32.0
- github.com/cncf/xds/go: ee656c7 → dba9d58
- github.com/envoyproxy/go-control-plane/envoy: v1.36.0 → v1.37.0
- github.com/envoyproxy/protoc-gen-validate: v1.3.0 → v1.3.3
- github.com/go-jose/go-jose/v4: v4.1.3 → v4.1.4
- github.com/google/cel-go: v0.28.0 → v0.29.0
- go.opentelemetry.io/contrib/detectors/gcp: v1.39.0 → v1.43.0
- golang.org/x/crypto: v0.52.0 → v0.54.0
- golang.org/x/exp: 74f9aab → 9ea1abe
- golang.org/x/mod: v0.36.0 → v0.38.0
- golang.org/x/net: v0.55.0 → v0.57.0
- golang.org/x/sync: v0.20.0 → v0.22.0
- golang.org/x/sys: v0.45.0 → v0.47.0
- golang.org/x/telemetry: 42602be → 49f421f
- golang.org/x/term: v0.43.0 → v0.45.0
- golang.org/x/text: v0.37.0 → v0.40.0
- golang.org/x/tools: v0.45.0 → v0.48.0
- google.golang.org/grpc: v1.80.0 → v1.82.1
Removed
- gopkg.in/square/go-jose.v2: v2.6.0