- 
                Notifications
    
You must be signed in to change notification settings  - Fork 1.8k
 
OSDOCS-17030 created GA release notes #101444
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
| 
           🤖 Mon Nov 03 15:36:12 - Prow CI generated the docs preview:  | 
    
5a37857    to
    4fcbe42      
    Compare
  
    There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Sorry I had missed few input in the shared draft, and added those as suggestions here.
| 
               | 
          ||
| Issued: 2025-11-03 | ||
| 
               | 
          ||
| The following advisories are available for the {external-secrets-operator} 0.1.0: | 
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| The following advisories are available for the {external-secrets-operator} 0.1.0: | |
| The following advisories are available for the {external-secrets-operator} 1.0.0: | 
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
| * link:https://access.redhat.com/errata/RHBA-2025:13134[RHBA-2025:13134] | ||
| * link:https://access.redhat.com/errata/RHBA-2025:13133[RHBA-2025:13133] | ||
| 
               | 
          ||
| Version 1.0.0 of the {external-secrets-operator} is based on the upstream external-secrets version v0.19.0. For more information, see thelink:https://github.com/external-secrets/external-secrets/releases/tag/v0.19.0[external-secrets project release notes for v0.19.0]. | 
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| Version 1.0.0 of the {external-secrets-operator} is based on the upstream external-secrets version v0.19.0. For more information, see thelink:https://github.com/external-secrets/external-secrets/releases/tag/v0.19.0[external-secrets project release notes for v0.19.0]. | |
| Version 1.0.0 of the {external-secrets-operator} is based on the upstream external-secrets version v0.19.0. For more information, see the link:https://github.com/external-secrets/external-secrets/releases/tag/v0.19.0[external-secrets project release notes for v0.19.0]. | 
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The changes aren't reflecting, please have a look.
| 
               | 
          ||
| *Renaming and improvements on the Operator API* | ||
| 
               | 
          ||
| With this release, the Operator API `externalsecrets.operator.openshift.io`` has been renamed to `externalsecretsconfigs.operator.openshift.io`` to avoid confusions with the external-secrets provided API that has the same name, but a different purpose. The API has also been restructured and new features are added. | 
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| With this release, the Operator API `externalsecrets.operator.openshift.io`` has been renamed to `externalsecretsconfigs.operator.openshift.io`` to avoid confusions with the external-secrets provided API that has the same name, but a different purpose. The API has also been restructured and new features are added. | |
| With this release, the Operator API `externalsecrets.operator.openshift.io` has been renamed to `externalsecretsconfigs.operator.openshift.io` to avoid confusions with the external-secrets provided API that has the same name, but a different purpose. The API has also been restructured and new features are added. | 
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
| 
               | 
          ||
| For more information, see {external-secrets-operator} APIs. | ||
| 
               | 
          ||
| *Support to collect metrics of both operator and operands* | 
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
nit: Changed it from the initial input
| *Support to collect metrics of both operator and operands* | |
| *Support to collect metrics of External Secrets Operator components* | 
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
| *Support to collect metrics of both operator and operands* | ||
| 
               | 
          ||
| With this release, the {external-secrets-operator} supports collecting metrics for both the Operator and operands. This is optional and must be enabled. | ||
| 
               | 
          
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| For more information, see Monitoring the External Secrets Operator for Red Hat OpenShift. | 
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The changes aren't reflecting, please have a look.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
| 
               | 
          ||
| With this release, the {external-secrets-operator} supports collecting metrics for both the Operator and operands. This is optional and must be enabled. | ||
| 
               | 
          ||
| *Support to configure proxy* | 
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| *Support to configure proxy* | |
| *Support to configure proxy for External Secrets Operator components* | 
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
| 
               | 
          ||
| For more information, see About the egress proxy for the {external-secrets-operator}. | ||
| 
               | 
          ||
| 
               | 
          
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| *Root filesystem is read-only for External Secrets Operator for Red Hat OpenShift containers* | |
| With this release, to improve security, the External Secrets Operator for Red Hat OpenShift and all its operands have the readOnlyRootFilesystem security context set to true by default. This enhancement hardens the containers and prevents a potential attacker from modifying the contents of the container’s root file system. | |
| *Network policy hardening is now available for External Secrets Operator components* | |
| With this release, External Secrets Operator for Red Hat OpenShift includes pre-defined NetworkPolicy resources designed for enhanced security by governing ingress and egress traffic for operand components. These policies cover essential internal traffic, such as ingress to the metrics and webhook servers, and egress to the OpenShift API server and DNS server. Note that deployment of the NetworkPolicy is enabled by default and egress allow policies must be explicitly defined in the ExternalSecretsConfig custom resource for the external-secrets component to fetch secrets from external providers. | |
| For more information, see Configuring Network Policy for the Operands. | |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
| * link:https://access.redhat.com/errata/RHBA-2025:13182[RHBA-2025:13182] | ||
| * link:https://access.redhat.com/errata/RHBA-2025:13134[RHBA-2025:13134] | ||
| * link:https://access.redhat.com/errata/RHBA-2025:13133[RHBA-2025:13133] | 
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The advisories are now available.
| * link:https://access.redhat.com/errata/RHBA-2025:13182[RHBA-2025:13182] | |
| * link:https://access.redhat.com/errata/RHBA-2025:13134[RHBA-2025:13134] | |
| * link:https://access.redhat.com/errata/RHBA-2025:13133[RHBA-2025:13133] | |
| * link:https://access.redhat.com/errata/RHBA-2025:19416[RHBA-2025:19416] | |
| * link:https://access.redhat.com/errata/RHBA-2025:19417[RHBA-2025:19417] | |
| * link:https://access.redhat.com/errata/RHBA-2025:19418[RHBA-2025:19418] | |
| * link:https://access.redhat.com/errata/RHBA-2025:19463[RHBA-2025:19463] | 
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
04653fe    to
    902f13b      
    Compare
  
    902f13b    to
    ac2da10      
    Compare
  
    | 
           @wgabor0427: all tests passed! Full PR test history. Your PR dashboard. Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.  | 
    
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
/lgtm
Version(s):
4.20+
Issue:
https://issues.redhat.com/browse/OSDOCS-17030
Link to docs preview:
https://101444--ocpdocs-pr.netlify.app/openshift-enterprise/latest/security/external_secrets_operator/external-secrets-operator-release-notes.html
QE review:
Additional information: