Skip to content

v1.16.0

Latest

Choose a tag to compare

@gianlucam76 gianlucam76 released this 02 Oct 17:17
14c278d

馃殌 New Features

Pull Mode with Short-Lived Tokens
Pull mode no longer needs long-lived credentials. The agents in the managed cluster authenticate with short-lived tokens, which shrinks the exposure window if a credential leaks.
PRs: sveltoscluster-manager #382, sveltosctl #450, sveltos #794

Pull Mode with Limited RBACs
The components that run in pull mode can work with a reduced set of permissions. The agents only get the access they need on the managed cluster.
PR: classifier #515

CleanupGracePeriod
A grace period can now be set for cleanup of Sveltos resources on a cluster. This avoids premature removal during short disconnections or transient issues.
PRs: libsveltos #686, sveltoscluster-manager #384

sveltos-agent Reports Processing Errors
Errors that sveltos-agent hits while processing EventSources, Classifiers and HealthChecks are now reported. You can see why an instance is not being evaluated without digging through agent logs.

HealthCheck: Consecutive Checks
A HealthCheck can require several consecutive evaluations before the result changes. One-off flaps are filtered out without extra tooling.
PRs: sveltos #803, libsveltos #694

RemoteURL as a Template
remoteURL can be expressed as a template, so one profile can resolve to a different source for each matching cluster.
PR: addon-controller #2001

Dashboard: OIDC Proxy Support and Profile Editing
The dashboard can sit behind an oidc-proxy. Profiles can also be created and edited directly from the dashboard.
PRs: ui-backend #185, dashboard #190

馃悶 Bug Fixes

addon-controller: Report Why a Profile Is Not Deployed When a Dependency Is Missing
When a profile depends on one that does not exist, the status now says so. Before, the profile just stayed undeployed with no explanation.
PR: addon-controller #1969

addon-controller: Stale Helm Conflict Not Cleared
A Helm conflict that had been resolved could stay in the status. It is now cleared.
PR: addon-controller #1975

addon-controller: Pull-Mode Helm Ignored createNamespace: false
In pull mode, Helm charts created the target namespace even when createNamespace was set to false. The setting is now honored.
PR: addon-controller #1982

addon-controller: Respect Order When Uninstalling Helm Releases
Releases are now uninstalled in the correct order, so ordering dependencies no longer cause failures on removal.
PR: addon-controller #1984

classifier: Label Keys Removed from spec.classifierLabels Were Not Dropped
When a key was removed from spec.classifierLabels, the label stayed on the cluster. The classifier now removes it.
PR: classifier #518

addon-controller: Deploy CRDs First When policyRefs Reference a remoteURL with an OCI Image
CRDs are now deployed before the other resources, so custom resources from the same OCI image no longer fail to apply.
PR: addon-controller #2005

addon-controller: MaxConsecutiveFailures Honored for validateHealth Failures
MaxConsecutiveFailures now also applies to validateHealth failures. Before, it did not.
PR: addon-controller #2006

addon-controller: ClusterConfiguration Cache Race with ClusterProfile Reconciliations
A race between the ClusterConfiguration cache and ClusterProfile reconciliations could leave stale data. It is fixed.
PR: addon-controller #2007

addon-controller: ClusterPromotion and Referenced Resource Issues
This fixes issues with ClusterPromotion and the resources it references.
PR: addon-controller #2012

馃敡 Maintenance

All components advanced to Go v1.27.1.

All components advanced to Cluster API v1.14.2.