Skip to content

Releases: maks3201/decision-model-operator

v0.4.0

Choose a tag to compare

@github-actions github-actions released this 09 Oct 10:35
f4ed270

Upgrade notes

Upgrading from 0.3.0 is tested in CI (Kubernetes 1.35 and 1.37). Read these before upgrading:

  • Breaking — manual approval. With promotion: Manual, approve a candidate by setting the annotation
    decisionmodel.io/promote to status.evaluation.approvalId. The approval is bound to the revision, the
    evaluation policy and the dataset. Without evaluation, the candidate's revision hash is still accepted for one
    release.
  • Breaking — unpinned runtime images. A new revision whose runtime image is not pinned to a digest is refused
    unless the operator runs with --allow-unpinned-runtime-images (Event reason UnpinnedRuntimeImage). The
    default runtime images (Ollaya 0.12.0, CPU and CUDA) are digest-pinned.
  • Candidates waiting in AwaitingPromotion are re-evaluated once: the score tolerance and the scorer version are
    now part of the evaluation identity.
  • The runtime version policy defaults to Pinned: an operator upgrade does not change the runtime of existing
    revisions. Set spec.runtimeVersion to move a DecisionModel to a newer runtime.
  • After a promotion the previous revision is kept for a 5-minute stabilization window and restored if the new one
    fails. During the window both revisions hold their store and, for device: cuda, a GPU each.
  • Secret references are capability-labelled by purpose: API key, evaluation dataset and download token use
    separate required labels (decisionmodel.io/api-key, decisionmodel.io/eval-dataset,
    decisionmodel.io/download-token, value "true"). A dataset Secret labelled only with api-key still works
    for this release and emits a Warning Event.
  • New status fields: storeRecovery, calibratedCases, scorerVersion.
  • Revision hashes are now 16 hex characters. Existing revisions keep their 10-character hashes; the upgrade does
    not roll DecisionModels that use the engine's default image, although that image is now digest-pinned.
  • A DecisionModel that sets spec.image rolls once after the upgrade: the override now sets the serving image and
    is part of the revision (before, it only affected the prefetch Job). Event ServingImageApplied.
  • Each revision's model manifest is persisted in a ConfigMap and seeded into the store by the prefetch Job,
    which verifies the digest. Correction (after release): this does not rebuild a revision whose tag moved
    upstream — ollaya pull <tag> replaces the seeded manifest (confirmed in ollaya-dev/ollaya#64). A moved tag
    fails with UpstreamTagMoved and no other model is served. To restore an exact revision after its tag moved,
    restore the store volume from a snapshot until the registry supports pull by digest.
  • The API-key checksum annotation on serving Pods switches to an HMAC in place, without a rollout.
  • Promotion and rollback Events name the revision hash.
  • Kubernetes: 1.35, 1.36 and 1.37 are tested nightly; 1.37 on every change.
  • OLM bundle metadata for 0.3.0 was regenerated in main after the v0.3.0 tag (#17).

Verification

Tested on this release candidate (v0.4.0-rc.2, same code): unit, envtest and E2E; upgrade from v0.3.0 on
Kubernetes 1.35.8 and 1.37.0; release-artifact smoke on a clean cluster; GPU smoke on EKS 1.36 with a Tesla T4
(device: cuda, /api/ps reports cuda:0, readiness gate True).

Changes

⚠ BREAKING CHANGES

  • refuse a new revision with an unpinned runtime image unless --allow-unpinned-runtime-images is set
  • bind manual approval to the revision, evaluation policy and dataset

Features

  • 64-bit revision hashes and digest-pinned runtime images; Ollaya 0.12.0 is the default runtime (a472e7c)
  • api: add spec.rollout.promotion (Automatic, EvaluationGated, Manual) (323308f)
  • api: add spec.runtimeVersion and pin the runtime across operator upgrades (9128379)
  • chart: add a values schema and per-release Artifact Hub changes (#22) (f6aea22)
  • chart: optional PrometheusRule, Grafana dashboard and runbooks (ea4024a)
  • chart: optional ServiceMonitor for the metrics Service (995e621)
  • chart: values for the runtime version policy and the rollout budget (#42) (cc9a44c)
  • eval: per-question precision, recall and macro-F1 (#34) (f03e2cf)
  • eval: scoring helpers for score questions (#40) (093c9d3)
  • limit concurrent rollouts with --max-concurrent-rollouts (9128379)
  • metrics: add decisionmodel_revision_info (323308f)
  • name models by digest in Events and echo the applied gates in status (323308f)
  • name the revision in promotion and rollback Events (a472e7c)
  • ollaya: default resources for jevk5:latest, the first measured GGUF model (#18) (ddf6d81)
  • ollaya: fail the prefetch Job fast on permanent download errors (#43) (f673851)
  • ollaya: name both digests when a prefetch finds a moved tag or a wrong manifest (a472e7c)
  • ollaya: rebuild a store to the recorded digest from a seeded manifest (995e621)
  • ollaya: report UpstreamTagMoved when a pinned tag moved upstream (ea4024a)
  • persist each revision's manifest so a lost store is rebuilt to the recorded digest (a472e7c)
  • refuse a new revision with an unpinned runtime image unless --allow-unpinned-runtime-images is set (a472e7c)
  • roll back to the previous model if the new one fails during a stabilization window (#44) (b9c531e)
  • separate Secret labels for API keys, eval datasets and download tokens (9128379)
  • show active and candidate model, accuracy and reason in kubectl get (323308f)
  • show why a prefetch failed in status and Events (#48) (050e50e)

Bug Fixes

  • a refused first rollout releases its in-flight candidate's workloads and rollout slot (a472e7c)
  • bind manual approval to the revision, evaluation policy and dataset (9128379)
  • count stabilizing revisions in the rollout budget; keep rollback protection until admitted (995e621)
  • deps: patch Go 1.26.9 and golang.org/x/net v0.60.0 security fixes (#78) (3af48b2)
  • do not roll back a healthy stable while its Deployment is rolling out (7f83f7d)
  • eval: hold the candidate while its dataset is missing instead of rolling it back (323308f)
  • eval: invalidate a held result when the dataset content changes (9128379)
  • eval: score questions are evaluated inste...
Read more

v0.4.0-rc.2

v0.4.0-rc.2 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 09 Oct 09:33
f29e54c

Release candidate. Validate it with RELEASING.md before the final release.

v0.4.0-rc.1

v0.4.0-rc.1 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 09 Oct 09:15
3af48b2

Release candidate. Validate it with RELEASING.md before the final release.

v0.3.0

Choose a tag to compare

@github-actions github-actions released this 06 Oct 10:50
57f16f4

0.3.0 (2026-10-06)

Features

  • api: add spec.cache.downloadTokenSecretRef for private or gated weights (003292f)
  • download model weights from a Hugging Face mirror (--ollaya-hf-endpoint) (003292f)
  • ollaya: default to the Ollaya 0.10.0 runtime (003292f)

Upgrade notes

  • The default runtime changes from Ollaya 0.7.3 to 0.10.0. The engine image is part of the revision hash, so after the operator upgrade every existing DecisionModel starts a blue-green rollout to the new image. The stable revision keeps serving until the candidate passes the model-ready gate. Stores pulled by 0.7.3 are served unchanged by 0.10.0.
  • To stay on 0.7.3, set spec.image (requires --allow-image-override).
  • The prefetch Job downloads weights from huggingface.co (redirected to *.hf.co) as well as manifests from ollaya.dev; allow both in egress policies, or mirror them with --ollaya-registry and --ollaya-hf-endpoint.

v0.2.1

Choose a tag to compare

@github-actions github-actions released this 05 Oct 17:08
e338e26

0.2.1 (2026-10-05)

Features

  • olm: describe DecisionModel fields and owned resources in the CSV (e370f06)
  • release: attach SLSA build provenance to the release files (7a551e9)

Bug Fixes

  • olm: keep the sample dataset ConfigMap out of the bundle (9439859)

Documentation

  • keep install versions current and describe the roadmap by stage (#6) (cc19c3b)

v0.2.0

Choose a tag to compare

@github-actions github-actions released this 05 Oct 12:36
1d7181f

0.2.0 (2026-10-05)

Features

  • olm: add an OLM bundle for OperatorHub (20045f4)
  • release: sign images, charts and release files with cosign; attach SBOM and provenance (1bffd1d)

Bug Fixes

  • engine: make model name canonicalisation idempotent (45244a7)

v0.1.1

Choose a tag to compare

@github-actions github-actions released this 05 Oct 09:47
d8b98d6

0.1.1 (2026-10-05)

Bug Fixes

  • chart: use a valid Artifact Hub category and capability level (2be718c)

v0.1.0

Choose a tag to compare

@github-actions github-actions released this 04 Oct 21:50
70c7480

0.1.0 (2026-10-04)

Features