Repository navigation
Releases: maks3201/decision-model-operator
Releases · maks3201/decision-model-operator
Release list
v0.4.0
Upgrade notes
Upgrading from 0.3.0 is tested in CI (Kubernetes 1.35 and 1.37). Read these before upgrading:
- Breaking — manual approval. With
promotion: Manual, approve a candidate by setting the annotation
decisionmodel.io/promotetostatus.evaluation.approvalId. The approval is bound to the revision, the
evaluation policy and the dataset. Without evaluation, the candidate's revision hash is still accepted for one
release. - Breaking — unpinned runtime images. A new revision whose runtime image is not pinned to a digest is refused
unless the operator runs with--allow-unpinned-runtime-images(Event reasonUnpinnedRuntimeImage). The
default runtime images (Ollaya 0.12.0, CPU and CUDA) are digest-pinned. - Candidates waiting in
AwaitingPromotionare re-evaluated once: the score tolerance and the scorer version are
now part of the evaluation identity. - The runtime version policy defaults to
Pinned: an operator upgrade does not change the runtime of existing
revisions. Setspec.runtimeVersionto move a DecisionModel to a newer runtime. - After a promotion the previous revision is kept for a 5-minute stabilization window and restored if the new one
fails. During the window both revisions hold their store and, fordevice: cuda, a GPU each. - Secret references are capability-labelled by purpose: API key, evaluation dataset and download token use
separate required labels (decisionmodel.io/api-key,decisionmodel.io/eval-dataset,
decisionmodel.io/download-token, value"true"). A dataset Secret labelled only withapi-keystill works
for this release and emits a Warning Event. - New status fields:
storeRecovery,calibratedCases,scorerVersion. - Revision hashes are now 16 hex characters. Existing revisions keep their 10-character hashes; the upgrade does
not roll DecisionModels that use the engine's default image, although that image is now digest-pinned. - A DecisionModel that sets
spec.imagerolls once after the upgrade: the override now sets the serving image and
is part of the revision (before, it only affected the prefetch Job). EventServingImageApplied. - Each revision's model manifest is persisted in a ConfigMap and seeded into the store by the prefetch Job,
which verifies the digest. Correction (after release): this does not rebuild a revision whose tag moved
upstream —ollaya pull <tag>replaces the seeded manifest (confirmed in ollaya-dev/ollaya#64). A moved tag
fails withUpstreamTagMovedand no other model is served. To restore an exact revision after its tag moved,
restore the store volume from a snapshot until the registry supports pull by digest. - The API-key checksum annotation on serving Pods switches to an HMAC in place, without a rollout.
- Promotion and rollback Events name the revision hash.
- Kubernetes: 1.35, 1.36 and 1.37 are tested nightly; 1.37 on every change.
- OLM bundle metadata for 0.3.0 was regenerated in main after the v0.3.0 tag (#17).
Verification
Tested on this release candidate (v0.4.0-rc.2, same code): unit, envtest and E2E; upgrade from v0.3.0 on
Kubernetes 1.35.8 and 1.37.0; release-artifact smoke on a clean cluster; GPU smoke on EKS 1.36 with a Tesla T4
(device: cuda, /api/ps reports cuda:0, readiness gate True).
Changes
⚠ BREAKING CHANGES
- refuse a new revision with an unpinned runtime image unless --allow-unpinned-runtime-images is set
- bind manual approval to the revision, evaluation policy and dataset
Features
- 64-bit revision hashes and digest-pinned runtime images; Ollaya 0.12.0 is the default runtime (a472e7c)
- api: add spec.rollout.promotion (Automatic, EvaluationGated, Manual) (323308f)
- api: add spec.runtimeVersion and pin the runtime across operator upgrades (9128379)
- chart: add a values schema and per-release Artifact Hub changes (#22) (f6aea22)
- chart: optional PrometheusRule, Grafana dashboard and runbooks (ea4024a)
- chart: optional ServiceMonitor for the metrics Service (995e621)
- chart: values for the runtime version policy and the rollout budget (#42) (cc9a44c)
- eval: per-question precision, recall and macro-F1 (#34) (f03e2cf)
- eval: scoring helpers for score questions (#40) (093c9d3)
- limit concurrent rollouts with --max-concurrent-rollouts (9128379)
- metrics: add decisionmodel_revision_info (323308f)
- name models by digest in Events and echo the applied gates in status (323308f)
- name the revision in promotion and rollback Events (a472e7c)
- ollaya: default resources for jevk5:latest, the first measured GGUF model (#18) (ddf6d81)
- ollaya: fail the prefetch Job fast on permanent download errors (#43) (f673851)
- ollaya: name both digests when a prefetch finds a moved tag or a wrong manifest (a472e7c)
- ollaya: rebuild a store to the recorded digest from a seeded manifest (995e621)
- ollaya: report UpstreamTagMoved when a pinned tag moved upstream (ea4024a)
- persist each revision's manifest so a lost store is rebuilt to the recorded digest (a472e7c)
- refuse a new revision with an unpinned runtime image unless --allow-unpinned-runtime-images is set (a472e7c)
- roll back to the previous model if the new one fails during a stabilization window (#44) (b9c531e)
- separate Secret labels for API keys, eval datasets and download tokens (9128379)
- show active and candidate model, accuracy and reason in kubectl get (323308f)
- show why a prefetch failed in status and Events (#48) (050e50e)
Bug Fixes
- a refused first rollout releases its in-flight candidate's workloads and rollout slot (a472e7c)
- bind manual approval to the revision, evaluation policy and dataset (9128379)
- count stabilizing revisions in the rollout budget; keep rollback protection until admitted (995e621)
- deps: patch Go 1.26.9 and golang.org/x/net v0.60.0 security fixes (#78) (3af48b2)
- do not roll back a healthy stable while its Deployment is rolling out (7f83f7d)
- eval: hold the candidate while its dataset is missing instead of rolling it back (323308f)
- eval: invalidate a held result when the dataset content changes (9128379)
- eval: score questions are evaluated inste...
v0.4.0-rc.2
Release candidate. Validate it with RELEASING.md before the final release.
v0.4.0-rc.1
Release candidate. Validate it with RELEASING.md before the final release.
v0.3.0
0.3.0 (2026-10-06)
Features
- api: add spec.cache.downloadTokenSecretRef for private or gated weights (003292f)
- download model weights from a Hugging Face mirror (--ollaya-hf-endpoint) (003292f)
- ollaya: default to the Ollaya 0.10.0 runtime (003292f)
Upgrade notes
- The default runtime changes from Ollaya 0.7.3 to 0.10.0. The engine image is part of the revision hash, so after the operator upgrade every existing DecisionModel starts a blue-green rollout to the new image. The stable revision keeps serving until the candidate passes the model-ready gate. Stores pulled by 0.7.3 are served unchanged by 0.10.0.
- To stay on 0.7.3, set
spec.image(requires--allow-image-override). - The prefetch Job downloads weights from
huggingface.co(redirected to*.hf.co) as well as manifests fromollaya.dev; allow both in egress policies, or mirror them with--ollaya-registryand--ollaya-hf-endpoint.