openops-0.7.0
This is a big release. There are a few changes you'll need to act on before upgrading, plus some new features. Here's what's new since 0.6.25.
Before you upgrade
Engine is now Worker. The old engine component has been replaced by worker. If you have an engine: section in your values file, rename it to worker:. Your pods and services will now be called openops-worker instead of openops-engine.
We've moved to Azure Container Registry. The chart and all images now live at openops.azurecr.io instead of public.ecr.aws/openops. Install with:
helm install openops oci://openops.azurecr.io/helm/openops --version 0.7.0
If you mirror images or override image.repository, point them at the new registry.
Redis is now configured with a single URL. Instead of setting OPS_REDIS_HOST and OPS_REDIS_PORT, set OPS_REDIS_URL, like redis://your-redis:6379/0. Analytics picks up its Redis settings from the same URL. If your Redis needs a password or TLS, also set REDIS_PASSWORD and REDIS_SSL under analytics.env.
Node drains won't get stuck anymore. PodDisruptionBudgets now default to maxUnavailable: 1. The old default blocked drains on components running a single replica. If you had set minAvailable yourself, add maxUnavailable: null next to it, or your setting will be ignored.
Nginx now runs as root. It still drops every capability except the few it needs. Check this if your cluster enforces strict pod security rules.
What's new
Connect AI agents to OpenOps. You can now turn on an MCP server so agents like Claude Code or Codex can work with OpenOps directly. It's off by default. To enable it, set mcp.enabled: true, use an https public URL, and add an OPS_OAUTH_RS_CLIENT_SECRET of at least 32 characters (openssl rand -hex 32). values.mcp-example.yaml has a working example.
Azure Key Vault for secrets. If you use External Secrets on Azure, you can now pull secrets straight from Key Vault. Set externalSecrets.provider: azure-keyvault.
AWS access from clusters outside EKS. Worker can now use a Kubernetes service account token to assume an AWS role, much like IRSA does on EKS. Turn it on with worker.awsWebIdentity.enabled.
Custom analytics config. Use analytics.configOverride to supply your own Superset config.
Smaller changes
- Tables is updated to 0.2.22 and Analytics to 0.14.8.
OPS_SUBAGENT_RUNNER_IMAGEnow defaults to empty. It previously pointed at a private image.- We removed an outdated security header (
X-XSS-Protection) from nginx.
Full Changelog: 0.6.25...0.7.0