Skip to content

v0.33.0

Choose a tag to compare

@mjudeikis mjudeikis released this 15 Sep 10:48
· 51 commits to main since this release
v0.33.0
1a4cb72

Changes by Kind

API Change

  • Add --shard-labels to shard flags
    Add condition Schedulable to shards (#4361, @mjudeikis)
  • Add LogicalCluster quota limited --logical-cluster-object-count-scan-interval (#4259, @mjudeikis)
  • Add names selector into ClusterCachedResource (#4328, @mjudeikis)
  • Adds spec.deletionPolicy: Delete | WaitForSuccessor for better handling of the resources, served by apibindings (#4275, @mjudeikis)
  • BREAKING CHANGE: APIExport's resource storage virtual no longer has identityHash field (#4326, @gman0)
  • BREAKING: the kinds CachedResource and CachedResourceEndpointSlice from the API group cache.kcp.io, that can be enabled with the Alpha feature gate CachedAPIs, have been renamed to ClusterCachedResource and ClusterCachedResourceEndpointSlice . ClusterCachedResourceEndpointSliceSpec.ClusterCachedResource now references the cluster scoped object. The resource plurals, REST paths, RBAC, and finalizer are renamed accordingly. There is no automatic migration for existing objects. (#4281, @neolit123)
  • Bug: stop serving OpenAPI v3 from the system:bound-crds workspace as it may contain duplicated GVKs sourced from different consumers. (#4333, @neolit123)
  • LogicalClusterDump is now paginated. Origin shard sends the data in pages (limited by entry count and total size), not the whole logical cluster in one response. LogicalClusterMigration status now shows entriesCopied and dumpContinue, so if destination shard restarts, it continues the copy from where it stopped instead of starting again. (#4244, @iakmc)
  • Make EndpointSlices unified api and create api aliases (#4304, @mjudeikis)
  • Support selectableFields on APIResourceSchema (#4212, @EpicStep)

Feature

  • Add "kubectl ws tree -w" for watch (#4323, @mjudeikis)
  • Add AI pen testing framework (#4225, @mjudeikis)
  • Add an optional --header-file flag to apigen used to append boilerplate to the generated YAML files (#4229, @xmudrii)
  • Add identity forward to virtual workspaces (#4310, @mjudeikis)
  • Allow migrating apiexports without deleting the resource (#4273, @mjudeikis)
  • Enable the following flags for all CLI commands similarly to how kubectl supports them: --as, --as-group, --client-certificate, --client-key, --cluster, --request-timeout. (#4313, @neolit123)
  • Move static tilt setup to Starlark-type configuration (#4245, @mjudeikis)
  • No user-facing behavior changes here — this only affects internal HTTP client reuse during migrations. (#4272, @iakmc)
  • Wire in StorageVersionAPI feature flag (#4262, @mjudeikis)
  • Wire in contrib-dashboard into tilt setup (#4282, @mjudeikis)
  • Add Upgrade test in CI (#4355, @mjudeikis)

Documentation

  • Display out of date banner on old documentation versions (#4289, @SimonTheLeg)
  • Documentation: included a quickstart guide with kind and helm (#4296, @neolit123)

Failing Test

Bug or Regression

  • Add TokenReview support for delegated auth in apiexport virtual workspace (#4280, @mjudeikis)
  • Add hop limit for Virtual workspaces (#4303, @mjudeikis)
  • Bugfix: on APIExport deletion, clear all managed 'extra annotations' from associated APIBindings. (#4254, @neolit123)
  • Cache-server honours --etcd-prefix (#4292, @ntnn)
  • Fix cross-shard reads of permission-claimed resources through the APIExport virtual workspace: a shard that does not serve a claimed resource now returns an empty list/watch instead of a 404, so a consuming provider's informer is not wedged when the claimed objects live on another shard. (#4215, @mjudeikis)
  • Fix dynamic-restmapper when dealing with multi-version apis, where different object might not exists in v2 but does in v1 (#4298, @mjudeikis)
  • Fixed a bug where the DynamicRESTMapper could store an incorrect/empty type mapping for a CRD observed before it reached the Established condition. (#4322, @pujitha24)
  • Fixed mounted workspace access failing with Unauthorized in sharded deployments, a regression introduced by the fix for GHSA-c8w2-fgvx-vhv4. Enabling mounts now requires configuring the front-proxy with --requestheader-client-ca-file and each shard with --mount-proxy-client-cert-file/--mount-proxy-client-key-file. (#4238, @xmudrii)
  • Retry APIExport references that are not resolvable yet (#4331, @mjudeikis)

Other (Cleanup or Flake)

  • Informers and watches established before a LogicalClusterMigration now relist promptly after the migration instead of stalling until the destination shard's resource version catches up. (#4264, @mjudeikis)

Dependencies

Added

Nothing has changed.

Changed

  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp: v1.31.0 → v1.32.0
  • github.com/cncf/xds/go: ee656c7 → dba9d58
  • github.com/envoyproxy/go-control-plane/envoy: v1.36.0 → v1.37.0
  • github.com/envoyproxy/protoc-gen-validate: v1.3.0 → v1.3.3
  • github.com/go-jose/go-jose/v4: v4.1.3 → v4.1.4
  • github.com/google/cel-go: v0.28.0 → v0.29.0
  • go.opentelemetry.io/contrib/detectors/gcp: v1.39.0 → v1.43.0
  • golang.org/x/crypto: v0.52.0 → v0.54.0
  • golang.org/x/exp: 74f9aab → 9ea1abe
  • golang.org/x/mod: v0.36.0 → v0.38.0
  • golang.org/x/net: v0.55.0 → v0.57.0
  • golang.org/x/sync: v0.20.0 → v0.22.0
  • golang.org/x/sys: v0.45.0 → v0.47.0
  • golang.org/x/telemetry: 42602be → 49f421f
  • golang.org/x/term: v0.43.0 → v0.45.0
  • golang.org/x/text: v0.37.0 → v0.40.0
  • golang.org/x/tools: v0.45.0 → v0.48.0
  • google.golang.org/grpc: v1.80.0 → v1.82.1

Removed

  • gopkg.in/square/go-jose.v2: v2.6.0