Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

helm: add ability to use a custom issuer #1598

Merged
merged 1 commit into from
Mar 7, 2024

Conversation

allenmun197
Copy link
Contributor

This PR adds in the ability to use a custom Issuer when creating the certs for NFD in the helm chart. This is useful when there are cluster/enterprise policies that deny creating a self-signed CA.

Fixes #1597

Copy link

linux-foundation-easycla bot commented Feb 21, 2024

CLA Signed

The committers listed above are authorized under a signed CLA.

  • ✅ login: allenmun197 / name: allenmun (8bd5259)

@k8s-ci-robot k8s-ci-robot added the cncf-cla: no Indicates the PR's author has not signed the CNCF CLA. label Feb 21, 2024
@k8s-ci-robot
Copy link
Contributor

Welcome @allenmun197!

It looks like this is your first PR to kubernetes-sigs/node-feature-discovery 🎉. Please refer to our pull request process documentation to help your PR have a smooth ride to approval.

You will be prompted by a bot to use commands during the review process. Do not be afraid to follow the prompts! It is okay to experiment. Here is the bot commands documentation.

You can also check if kubernetes-sigs/node-feature-discovery has its own contribution guidelines.

You may want to refer to our testing guide if you run into trouble with your tests not passing.

If you are having difficulty getting your pull request seen, please follow the recommended escalation practices. Also, for tips and tricks in the contribution process you may want to read the Kubernetes contributor cheat sheet. We want to make sure your contribution gets all the attention it needs!

Thank you, and welcome to Kubernetes. 😃

@k8s-ci-robot k8s-ci-robot added the needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. label Feb 21, 2024
@k8s-ci-robot
Copy link
Contributor

Hi @allenmun197. Thanks for your PR.

I'm waiting for a kubernetes-sigs member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work. Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@k8s-ci-robot k8s-ci-robot added the size/S Denotes a PR that changes 10-29 lines, ignoring generated files. label Feb 21, 2024
Copy link

netlify bot commented Feb 21, 2024

Deploy Preview for kubernetes-sigs-nfd ready!

Name Link
🔨 Latest commit 8bd5259
🔍 Latest deploy log https://app.netlify.com/sites/kubernetes-sigs-nfd/deploys/65de18aa64367500082f3994
😎 Deploy Preview https://deploy-preview-1598--kubernetes-sigs-nfd.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site configuration.

@k8s-ci-robot k8s-ci-robot added cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. and removed cncf-cla: no Indicates the PR's author has not signed the CNCF CLA. labels Feb 21, 2024
Copy link
Contributor

@marquiz marquiz left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @allenmun197. I think we could take the patch, even though all of this is deprecated functionality. In more detail: note that the gRPC communication (and everything related, like TLS and cert-manager support) has been deprecated since NFD v0.13, disabled since NFD v0.14 and likely to be dropped in NFD v0.17. So, unless you specifically enable gRPC with enableNodeFeatureApi: true the TLS/cert-manager settings will not be used.

When adding new helm params, we also need to document those in docs/deployment/helm.md.

Comment on lines 532 to 535
certManager:
enable: false
issuerKind:
issuerName:
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We shouldn't break existing users

Suggested change
certManager:
enable: false
issuerKind:
issuerName:
certManager: false
certManageIssuerKind:
certManageIssuerName:

OR

Suggested change
certManager:
enable: false
issuerKind:
issuerName:
certManager: false
certManagerCertificate:
issuerKind:
issuerName:

@allenmun197
Copy link
Contributor Author

@marquiz

Ok, I moved the fields into certManagerCertificate as suggested. Also added the documentation for the new helm fields in docs/deployment/helm.md. I also added an additional check to make sure if .tls.certManagerCertificate.issuerKind is set but .tls.certManagerCertificate.issuerName is not set, it will not use .tls.certManagerCertificate.issuerKind and just default to Issuer. This fixes an issue when you have a values file that looks like

tls:
  certManager: enable
  certManagerCertificate:
    #issuerName: example-issuer
    issuerKind: ClusterIssuer

name: nfd-ca-issuer
kind: Issuer
name: {{ default "nfd-ca-issuer" .Values.tls.certManagerCertificate.issuerName }}
kind: {{ default "Issuer" ( kindIs "invalid" .Values.tls.certManagerCertificate.issuerName | ternary "" .Values.tls.certManagerCertificate.issuerKind ) }}
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is quite cryptic to read, at least for me 😇

How about a bit longer but more explicit:

    {{- if and .Values.tls.certManagerCertificate.issuerName .Values.tls.certManagerCertificate.issuerKind }}
    kind: {{ .Values.tls.certManagerCertificate.issuerKind }}
    {{- else }}
    kind: Issuer
    {{- end }}

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Got it. Updated the PR to use more simplified logic with regards to the issuer kind.

@marquiz
Copy link
Contributor

marquiz commented Feb 27, 2024

/ok-to-test

@k8s-ci-robot k8s-ci-robot added ok-to-test Indicates a non-member PR verified by an org member that is safe to test. and removed needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. labels Feb 27, 2024
Copy link
Contributor

@marquiz marquiz left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @allenmun197. I haven't tested this but looks good to me 👍
/assign @ArangoGutierrez

@k8s-ci-robot
Copy link
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: allenmun197, marquiz

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@k8s-ci-robot k8s-ci-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Feb 28, 2024
@allenmun197
Copy link
Contributor Author

@marquiz @ArangoGutierrez

Is this PR still in review?

@jjacobelli
Copy link
Contributor

/lgtm

@k8s-ci-robot k8s-ci-robot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Mar 7, 2024
@k8s-ci-robot
Copy link
Contributor

LGTM label has been added.

Git tree hash: 9198179a3adc871c6a751445c8e1da6598a85d34

Copy link

codecov bot commented Mar 7, 2024

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 30.04%. Comparing base (2914bff) to head (8bd5259).
Report is 2 commits behind head on master.

Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##           master    #1598      +/-   ##
==========================================
- Coverage   30.28%   30.04%   -0.24%     
==========================================
  Files         101      102       +1     
  Lines        9361     9422      +61     
==========================================
- Hits         2835     2831       -4     
- Misses       6260     6324      +64     
- Partials      266      267       +1     

see 2 files with indirect coverage changes

@k8s-ci-robot k8s-ci-robot merged commit decaafe into kubernetes-sigs:master Mar 7, 2024
11 checks passed
@marquiz marquiz mentioned this pull request May 24, 2024
24 tasks
nrdufour pushed a commit to nrdufour/home-ops that referenced this pull request May 28, 2024
…465)

This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [node-feature-discovery](https://github.com/kubernetes-sigs/node-feature-discovery) | minor | `0.15.4` -> `0.16.0` |

---

### Release Notes

<details>
<summary>kubernetes-sigs/node-feature-discovery (node-feature-discovery)</summary>

### [`v0.16.0`](https://github.com/kubernetes-sigs/node-feature-discovery/releases/tag/v0.16.0): v0.16

[Compare Source](kubernetes-sigs/node-feature-discovery@v0.15.4...v0.16.0)

#### Changelog

##### NodeFeatureGroup API

The NodeFeatureGroup custom resource was added to the NFD API. The NodeFeatureGroup API enables the creation of node groups based on features discovered by NFD. The API is an alpha feature and is disabled by default and can be enabled with the NodeFeatureGroupAPI [feature gate](https://kubernetes-sigs.github.io/node-feature-discovery/v0.16/usage/custom-resources.html#nodefeaturegroup).

See [documentation](https://kubernetes-sigs.github.io/node-feature-discovery/v0.16/usage/custom-resources.html#nodefeaturegroup) for more details.

##### Feature gates

NFD adapted the concept of feature gates from Kubernetes to introduce and stabilize new features in a controlled way. See the [documentation](https://kubernetes-sigs.github.io/node-feature-discovery/v0.16/reference/feature-gates.html) for more details. Two existing features ([NodeFeature API](https://kubernetes-sigs.github.io/node-feature-discovery/v0.16/reference/feature-gates.html#nodefeatureapi) and [disabling label auto-prefixing](https://kubernetes-sigs.github.io/node-feature-discovery/v0.16/reference/feature-gates.html#disableautoprefix)) were converted into feature gates.

##### Deprecations

##### Upcoming changes

Support for [hooks](https://kubernetes-sigs.github.io/node-feature-discovery/v0.16/usage/customization-guide.html#hooks) is deprecated since [v0.12.0](https://github.com/kubernetes-sigs/node-feature-discovery/releases/tag/v0.12.0) and will be completely dropped in the NFD v0.17.

##### RDT feature labels removed

The `feature.node.kubernetes.io/cpu-rdt.*` feature labels that were deprecated in NFD [v0.13](https://github.com/kubernetes-sigs/node-feature-discovery/releases/tag/v0.13.0) were removed. RDT features are still available for use in [NodeFeatureRules](https://kubernetes-sigs.github.io/node-feature-discovery/v0.16/usage/custom-resources.html#nodefeaturerule) for custom labels.

##### Deprecated flags and options

The [autoDefaultNs](https://kubernetes-sigs.github.io/node-feature-discovery/v0.16/reference/master-configuration-reference.html#autodefaultns) config file option of nfd-master is deprecated and will be removed in NFD v0.17. Superseded by the [DisableAutoPrefix](https://kubernetes-sigs.github.io/node-feature-discovery/v0.16/reference/feature-gates.html#disableautoprefix) feature gate (`featureGates.DisableAutoPrefix` Helm parameter).

The `-enable-nodefeature-api` command line flag of nfd-master and nfd-worker and the corresponding `enableNodeFeatureApi` [Helm chart parameter](https://kubernetes-sigs.github.io/node-feature-discovery/v0.16/deployment/helm.html#general-parameters) have been deprecated and will be removed in NFD v0.17. Superseded by the [NodeFeature API](https://kubernetes-sigs.github.io/node-feature-discovery/v0.16/reference/feature-gates.html#nodefeatureapi) feature gate (`featureGates.NodeFeatureAPI` Helm parameter).

The `-crd-controller` command line flag of nfd-master is deprecated and will be removed with the gRPC API in a future release.

##### Miscellaneous

##### Network devices

Discover speed of virtual network interfaces.

##### DMI

Added support for detecting DMI attributes from `/sys/devices/virtual/dmi/id/`. In v0.16 only `sys_vendor` discovered, available as `system.dmiid.sys_vendor` feature for use in [NodeFeatureRules](https://kubernetes-sigs.github.io/node-feature-discovery/v0.16/usage/custom-resources.html#nodefeaturerule).

##### Swap

Discover the availability of swap on the node. Available as `memory.swap.enabled` feature for use in [NodeFeatureRules](https://kubernetes-sigs.github.io/node-feature-discovery/v0.16/usage/custom-resources.html#nodefeaturerule).

##### Helm chart

Now all nodes are cleaned up (feature labels, annotations, extended resources and taints are removed) after uninstalling NFD using a post-delete hook.

The Helm chart now sets resource requests (cpu and memory) for NFD pods. Users may want to adjust these for their cluster. An option to set the pod priority class was added. See [Helm chart parameters](https://kubernetes-sigs.github.io/node-feature-discovery/v0.16/deployment/helm.html#chart-parameters) in the documentation).

##### Container health

A gRPC health server was added to the nfd-master, nfd-worker and nfd-topology-updater daemons. Deployments (Helm and kustomize) configure container liveness and readiness probes to use that for health checking.

#### List of PRs

-   github: update tagging instructions in release checklists ([#&#8203;1527](kubernetes-sigs/node-feature-discovery#1527))
-   Update readme to v0.15.0 release ([#&#8203;1524](kubernetes-sigs/node-feature-discovery#1524))
-   makefile: fix build: target ([#&#8203;1528](kubernetes-sigs/node-feature-discovery#1528))
-   Makefile: add -timeout argument to e2e-tests ([#&#8203;1526](kubernetes-sigs/node-feature-discovery#1526))
-   helm: add post-delete hook that cleans up the node ([#&#8203;1532](kubernetes-sigs/node-feature-discovery#1532))
-   deployment/kustomize: drop the sample cert-manager overlay ([#&#8203;1534](kubernetes-sigs/node-feature-discovery#1534))
-   nfd-master: run a separate gRPC health server ([#&#8203;1535](kubernetes-sigs/node-feature-discovery#1535))
-   source/network: discover speed of virtual network interfaces ([#&#8203;1536](kubernetes-sigs/node-feature-discovery#1536))
-   go.mod: update dependencies ([#&#8203;1539](kubernetes-sigs/node-feature-discovery#1539))
-   chore: combine cpu count and thread_siblings functions into discover topology function ([#&#8203;1505](kubernetes-sigs/node-feature-discovery#1505))
-   source/cpu: drop deprecated cpu-rdt labels ([#&#8203;1530](kubernetes-sigs/node-feature-discovery#1530))
-   Update readme to v0.15.1 release ([#&#8203;1552](kubernetes-sigs/node-feature-discovery#1552))
-   hack/generate: patch auto-generated deepcopy functions ([#&#8203;1553](kubernetes-sigs/node-feature-discovery#1553))
-   apis/nfd: Trivial typo fix in tests ([#&#8203;1537](kubernetes-sigs/node-feature-discovery#1537))
-   docs: update docs build dependencies ([#&#8203;1543](kubernetes-sigs/node-feature-discovery#1543))
-   topology-updater: initialize properly with -no-publish ([#&#8203;1554](kubernetes-sigs/node-feature-discovery#1554))
-   topology-updater: document the -no-publish flag correctly ([#&#8203;1555](kubernetes-sigs/node-feature-discovery#1555))
-   Wrap nested errors ([#&#8203;1558](kubernetes-sigs/node-feature-discovery#1558))
-   Prevent `nfd-worker` erroring when reading attributes from paravirtual devices ([#&#8203;1557](kubernetes-sigs/node-feature-discovery#1557))
-   pkg/utils: move GetKubeconfig from pkg/apihelper here ([#&#8203;1562](kubernetes-sigs/node-feature-discovery#1562))
-   OWNERS: add AhmedGrati as a reviewer ([#&#8203;1564](kubernetes-sigs/node-feature-discovery#1564))
-   deployment/helm: don't deploy topology-updater conf unnecessarily ([#&#8203;1565](kubernetes-sigs/node-feature-discovery#1565))
-   topology-updater: get topology api client directly ([#&#8203;1566](kubernetes-sigs/node-feature-discovery#1566))
-   pkg/utils: move JsonPatch from pkg/apihelper ([#&#8203;1568](kubernetes-sigs/node-feature-discovery#1568))
-   nfd-master: ditch apihelper ([#&#8203;1570](kubernetes-sigs/node-feature-discovery#1570))
-   topology-updater: ditch apihelper ([#&#8203;1567](kubernetes-sigs/node-feature-discovery#1567))
-   Drop pkg/apihelper ([#&#8203;1561](kubernetes-sigs/node-feature-discovery#1561))
-   nfd-master: fix node status patching ([#&#8203;1571](kubernetes-sigs/node-feature-discovery#1571))
-   nfd-topology-updater add pods fingerprint by default ([#&#8203;1560](kubernetes-sigs/node-feature-discovery#1560))
-   docs: add KEP of Spiffe integration ([#&#8203;1444](kubernetes-sigs/node-feature-discovery#1444))
-   docs: document removal of hooks in v0.17 ([#&#8203;1573](kubernetes-sigs/node-feature-discovery#1573))
-   build(deps): bump github.com/opencontainers/runc from 1.1.10 to 1.1.12 ([#&#8203;1575](kubernetes-sigs/node-feature-discovery#1575))
-   build(deps-dev): bump nokogiri from 1.16.0 to 1.16.2 in /docs ([#&#8203;1576](kubernetes-sigs/node-feature-discovery#1576))
-   scripts/test-infra: bump golangci-lint to v1.56.1 ([#&#8203;1580](kubernetes-sigs/node-feature-discovery#1580))
-   scripts/test-infra: bump k8s logcheck to v0.8.1 ([#&#8203;1583](kubernetes-sigs/node-feature-discovery#1583))
-   Bump Go to v1.22 ([#&#8203;1579](kubernetes-sigs/node-feature-discovery#1579))
-   scripts/test-infra: bump helm to v3.14.0 ([#&#8203;1582](kubernetes-sigs/node-feature-discovery#1582))
-   source/kernel: add unit tests for kernel version parsing ([#&#8203;1588](kubernetes-sigs/node-feature-discovery#1588))
-   helm: add priorityClassName option ([#&#8203;1587](kubernetes-sigs/node-feature-discovery#1587))
-   source/pci: add unit test for the pci source ([#&#8203;1589](kubernetes-sigs/node-feature-discovery#1589))
-   nfd-master: log errors on node update retries ([#&#8203;1591](kubernetes-sigs/node-feature-discovery#1591))
-   source/system: Add reading vendor information ([#&#8203;1574](kubernetes-sigs/node-feature-discovery#1574))
-   source/cpu: fix build tags on rdt discovery ([#&#8203;1594](kubernetes-sigs/node-feature-discovery#1594))
-   helm: add ability to use a custom issuer ([#&#8203;1598](kubernetes-sigs/node-feature-discovery#1598))
-   fix hook issue ([#&#8203;1604](kubernetes-sigs/node-feature-discovery#1604))
-   generate: update autogenerate tools ([#&#8203;1606](kubernetes-sigs/node-feature-discovery#1606))
-   apis/nfd/validate: use testify/assert for checking test results ([#&#8203;1590](kubernetes-sigs/node-feature-discovery#1590))
-   Update readme to v0.15.2 release ([#&#8203;1611](kubernetes-sigs/node-feature-discovery#1611))
-   Update generate scripts to use latest code_gen functions ([#&#8203;1605](kubernetes-sigs/node-feature-discovery#1605))
-   nfd-master: mark the -crd-controller flag as deprecated ([#&#8203;1612](kubernetes-sigs/node-feature-discovery#1612))
-   build(deps): bump google.golang.org/protobuf from 1.32.0 to 1.33.0 ([#&#8203;1613](kubernetes-sigs/node-feature-discovery#1613))
-   Use close to signal stop channedl in worker and topology-updater ([#&#8203;1620](kubernetes-sigs/node-feature-discovery#1620))
-   nfd-master: fix memory leak in nfd api-controller ([#&#8203;1615](kubernetes-sigs/node-feature-discovery#1615))
-   Update readme to v0.15.3 release ([#&#8203;1628](kubernetes-sigs/node-feature-discovery#1628))
-   Add FeatureGate framework to handle new features ([#&#8203;1623](kubernetes-sigs/node-feature-discovery#1623))
-   replace AhmedGrati account with TessaIO as reviewer ([#&#8203;1630](kubernetes-sigs/node-feature-discovery#1630))
-   add swap support in nfd ([#&#8203;1585](kubernetes-sigs/node-feature-discovery#1585))
-   nfd-master: check if node exists before trying update ([#&#8203;1595](kubernetes-sigs/node-feature-discovery#1595))
-   Remove references to -enable-nodefeature-api flag ([#&#8203;1632](kubernetes-sigs/node-feature-discovery#1632))
-   Add owner reference to NRT object ([#&#8203;1602](kubernetes-sigs/node-feature-discovery#1602))
-   nfd-master: retry node updates indefinitely ([#&#8203;1596](kubernetes-sigs/node-feature-discovery#1596))
-   nfd-worker: Add liveness probe ([#&#8203;1609](kubernetes-sigs/node-feature-discovery#1609))
-   topology-updater: Set APIVersion, Kind in the OwnerReference explicitly ([#&#8203;1634](kubernetes-sigs/node-feature-discovery#1634))
-   helm: fix invalid name of host-swaps volume ([#&#8203;1635](kubernetes-sigs/node-feature-discovery#1635))
-   nfd-master: do nfd API scheme registration in an init function ([#&#8203;1641](kubernetes-sigs/node-feature-discovery#1641))
-   chore/deployment: add resources requests and limits for helm and Kustomize ([#&#8203;1631](kubernetes-sigs/node-feature-discovery#1631))
-   nfd-topology-updater: Add liveness probe ([#&#8203;1643](kubernetes-sigs/node-feature-discovery#1643))
-   nfd-master: get node object only once when updating node ([#&#8203;1652](kubernetes-sigs/node-feature-discovery#1652))
-   chore/deploy: make interval property in PodMonitor configurable ([#&#8203;1639](kubernetes-sigs/node-feature-discovery#1639))
-   nfd-master: protect node updater pool queueing with a lock ([#&#8203;1642](kubernetes-sigs/node-feature-discovery#1642))
-   nfd-master: prevent crash on empty config struct ([#&#8203;1657](kubernetes-sigs/node-feature-discovery#1657))
-   Update readme to v0.15.4 release ([#&#8203;1650](kubernetes-sigs/node-feature-discovery#1650))
-   Tidy up usage of channels for signaling ([#&#8203;1656](kubernetes-sigs/node-feature-discovery#1656))
-   nfd-master: implement opts for modifying NfdMaster instance ([#&#8203;1658](kubernetes-sigs/node-feature-discovery#1658))
-   nfd-master: parse kubeconfig even with NoPublish set ([#&#8203;1655](kubernetes-sigs/node-feature-discovery#1655))
-   Move NFD api to a separate go mod ([#&#8203;1600](kubernetes-sigs/node-feature-discovery#1600))
-   api/nfd: run go mod tidy ([#&#8203;1661](kubernetes-sigs/node-feature-discovery#1661))
-   Fix Make generate   ([#&#8203;1662](kubernetes-sigs/node-feature-discovery#1662))
-   apis/nfd/validate: loosen validation of feature annotations ([#&#8203;1633](kubernetes-sigs/node-feature-discovery#1633))
-   nfd-master: use separate k8s api clients for each updater ([#&#8203;1653](kubernetes-sigs/node-feature-discovery#1653))
-   nfd-master: stop node-updater pool before reconfiguring api-controller ([#&#8203;1660](kubernetes-sigs/node-feature-discovery#1660))
-   build(deps): bump golang.org/x/net from 0.20.0 to 0.23.0 ([#&#8203;1665](kubernetes-sigs/node-feature-discovery#1665))
-   chore/nfd-master: remove warnings in nfd-master unit tests file ([#&#8203;1668](kubernetes-sigs/node-feature-discovery#1668))
-   build(deps): bump golang.org/x/net from 0.20.0 to 0.23.0 in api/nfd ([#&#8203;1666](kubernetes-sigs/node-feature-discovery#1666))
-   apis/nfd: add unit tests for match name functions ([#&#8203;1667](kubernetes-sigs/node-feature-discovery#1667))
-   apis/nfd: no error on ops that never match ([#&#8203;1670](kubernetes-sigs/node-feature-discovery#1670))
-   api/nfd: use varargs in the NewInstanceFeatures helper ([#&#8203;1669](kubernetes-sigs/node-feature-discovery#1669))
-   scripts/test-infra: bump golangci-lint to v1.57.2 ([#&#8203;1674](kubernetes-sigs/node-feature-discovery#1674))
-   add ARMv7 support ([#&#8203;1659](kubernetes-sigs/node-feature-discovery#1659))
-   docs: document trade-offs in memory configuration ([#&#8203;1651](kubernetes-sigs/node-feature-discovery#1651))
-   go.mod: bump kubernetes to v1.30 ([#&#8203;1675](kubernetes-sigs/node-feature-discovery#1675))
-   cloudbuild.yaml: change machine type to e1-highcpu-32 ([#&#8203;1678](kubernetes-sigs/node-feature-discovery#1678))
-   test/e2e: stop importing kubernetes test/e2e ([#&#8203;1680](kubernetes-sigs/node-feature-discovery#1680))
-   hack/init-buildx.sh: fix broken patter matching ([#&#8203;1683](kubernetes-sigs/node-feature-discovery#1683))
-   Disable armv7 builds  ([#&#8203;1677](kubernetes-sigs/node-feature-discovery#1677))
-   cloudbuild.yaml: downgrade machine type to e2-highcpu-8 ([#&#8203;1685](kubernetes-sigs/node-feature-discovery#1685))
-   Update update_codegen.sh for v0.30 version of codegen tools  ([#&#8203;1681](kubernetes-sigs/node-feature-discovery#1681))
-   Dependabot: Add proper dependabot config file ([#&#8203;1679](kubernetes-sigs/node-feature-discovery#1679))
-   build(deps): bump azure/setup-helm from 3 to 4 ([#&#8203;1686](kubernetes-sigs/node-feature-discovery#1686))
-   build(deps): bump actions/checkout from 1 to 4 ([#&#8203;1687](kubernetes-sigs/node-feature-discovery#1687))
-   build(deps): bump golang.org/x/net from 0.23.0 to 0.24.0 ([#&#8203;1689](kubernetes-sigs/node-feature-discovery#1689))
-   build(deps): bump sigs.k8s.io/yaml from 1.3.0 to 1.4.0 ([#&#8203;1691](kubernetes-sigs/node-feature-discovery#1691))
-   build(deps): bump github.com/onsi/gomega from 1.31.0 to 1.33.0 ([#&#8203;1692](kubernetes-sigs/node-feature-discovery#1692))
-   build(deps): bump github.com/onsi/ginkgo/v2 from 2.15.0 to 2.17.2 ([#&#8203;1690](kubernetes-sigs/node-feature-discovery#1690))
-   build(deps): bump github.com/jaypipes/ghw from 0.8.1-0.20210827132705-c7224150a17e to 0.12.0 ([#&#8203;1688](kubernetes-sigs/node-feature-discovery#1688))
-   apis/nfd: increase unit test coverage ([#&#8203;1693](kubernetes-sigs/node-feature-discovery#1693))
-   build: specify buildx builder name everywhere ([#&#8203;1684](kubernetes-sigs/node-feature-discovery#1684))
-   source/kernel: silence misleading error on selinux detection ([#&#8203;1694](kubernetes-sigs/node-feature-discovery#1694))
-   build(deps): bump github.com/klauspost/cpuid/v2 from 2.2.6 to 2.2.7 ([#&#8203;1695](kubernetes-sigs/node-feature-discovery#1695))
-   build(deps): bump github.com/stretchr/testify from 1.8.4 to 1.9.0 ([#&#8203;1696](kubernetes-sigs/node-feature-discovery#1696))
-   build(deps): bump github.com/google/uuid from 1.5.0 to 1.6.0 ([#&#8203;1698](kubernetes-sigs/node-feature-discovery#1698))
-   build(deps): bump github.com/onsi/gomega from 1.33.0 to 1.33.1 ([#&#8203;1699](kubernetes-sigs/node-feature-discovery#1699))
-   build(deps): bump github.com/k8stopologyawareschedwg/noderesourcetopology-api from 0.1.0 to 0.1.2 ([#&#8203;1697](kubernetes-sigs/node-feature-discovery#1697))
-   build(deps): bump golang.org/x/net from 0.24.0 to 0.25.0 ([#&#8203;1701](kubernetes-sigs/node-feature-discovery#1701))
-   build(deps): bump google.golang.org/grpc from 1.60.1 to 1.63.2 ([#&#8203;1702](kubernetes-sigs/node-feature-discovery#1702))
-   build(deps-dev): bump nokogiri from 1.16.2 to 1.16.5 in /docs ([#&#8203;1706](kubernetes-sigs/node-feature-discovery#1706))
-   build(deps): bump google.golang.org/protobuf from 1.33.0 to 1.34.1 ([#&#8203;1703](kubernetes-sigs/node-feature-discovery#1703))
-   build(deps): bump github.com/k8stopologyawareschedwg/podfingerprint from 0.1.2 to 0.2.2 ([#&#8203;1705](kubernetes-sigs/node-feature-discovery#1705))
-   nfd-master: add DisableAutoPrefix feature gate ([#&#8203;1707](kubernetes-sigs/node-feature-discovery#1707))
-   Re-add -enable-nodefeature-api cmdline flag ([#&#8203;1708](kubernetes-sigs/node-feature-discovery#1708))
-   build(deps): bump rexml from 3.2.6 to 3.2.8 in /docs ([#&#8203;1709](kubernetes-sigs/node-feature-discovery#1709))
-   build(deps): bump github.com/onsi/ginkgo/v2 from 2.17.2 to 2.17.3 ([#&#8203;1711](kubernetes-sigs/node-feature-discovery#1711))
-   Add NodeFeatureGroup API ([#&#8203;1487](kubernetes-sigs/node-feature-discovery#1487))
-   api/nfd: document all undocumented fields in the types ([#&#8203;1714](kubernetes-sigs/node-feature-discovery#1714))
-   nfd-worker: improved log when creating NodeFeature object ([#&#8203;1713](kubernetes-sigs/node-feature-discovery#1713))
-   apis/nfd: allow different types of features of the same name ([#&#8203;1671](kubernetes-sigs/node-feature-discovery#1671))
-   cpu: advertise AVX10 version ([#&#8203;1673](kubernetes-sigs/node-feature-discovery#1673))
-   source/cpu: disable AVX10 label ([#&#8203;1715](kubernetes-sigs/node-feature-discovery#1715))
-   docs/helm: document all feature gates ([#&#8203;1716](kubernetes-sigs/node-feature-discovery#1716))
-   build(deps): bump github.com/onsi/ginkgo/v2 from 2.17.3 to 2.19.0 ([#&#8203;1717](kubernetes-sigs/node-feature-discovery#1717))
-   docs: add more cross-references to NodeFeatureGroup API ([#&#8203;1718](kubernetes-sigs/node-feature-discovery#1718))

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy4zNzkuMCIsInVwZGF0ZWRJblZlciI6IjM3LjM3OS4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->

Reviewed-on: https://git.internal/nrdufour/home-ops/pulls/465
Co-authored-by: Renovate <renovate@ptinem.casa>
Co-committed-by: Renovate <renovate@ptinem.casa>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
approved Indicates a PR has been approved by an approver from all required OWNERS files. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. lgtm "Looks good to me", indicates that a PR is ready to be merged. ok-to-test Indicates a non-member PR verified by an org member that is safe to test. size/S Denotes a PR that changes 10-29 lines, ignoring generated files.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

In the Helm chart, add in a way to customize the Issuer used for the NFD certs
5 participants