Skip to content

feat!: upgrade platform components for Kubernetes 1.35 - #1498

Merged
hamzabouissi merged 14 commits into
mainfrom
feat/k8s-1.35-component-upgrades
Sep 18, 2026
Merged

hamzabouissi merged 14 commits into
mainfrom
feat/k8s-1.35-component-upgrades

Conversation

@hamzabouissi

@hamzabouissi hamzabouissi commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Why

We're moving clusters to Kubernetes 1.35. Several platform components are unsupported or untested on 1.35 at their current versions:

  • cert-manager 1.18: supports 1.29–1.33 and is end-of-life.
  • ingress-nginx controller 1.13: supports up to 1.33.
  • external-secrets image v0.16: tested only on 1.32.
  • metacontroller v4.12.5: CI-tested on 1.29–1.32. gluekube-ccm and loki-alert-group-controller both run on it.

This PR bumps those, plus the low-risk bumps that were already queued in Renovate.

What

Component Before After
cert-manager (chart; images follow the chart) v1.18.2 v1.21.2
ingress-nginx chart / controller 4.13.3 / v1.13.3 4.15.1 / v1.15.1 (final upstream release)
external-secrets chart / image 0.19.2 / v0.16.2 2.10.0 / v2.10.0
metacontroller chart / image v4.12.5 v4.17.2
traefik chart / proxy 39.0.0 / v3.6.7 41.6.0 / v3.7.13
openbao chart / image 0.19.3 / 2.4.4 0.29.4 / 2.6.2
external-dns chart / image 1.20.0 / v0.20.0 1.22.0 / v0.22.0
reflector 10.0.8 10.0.65
keda 2.20.1 2.20.2
goldilocks chart / image 10.4.1 / v4.14.1 11.1.1 / v4.16.2
vpa chart / images 4.12.3 / 1.6.0 5.1.0 / 1.7.1
dex image v2.44.0 v2.45.1
oauth2-proxy image v7.15.3 v7.15.4
backup-tools / network_exporter / curl v2.15.0 / 1.7.10 / 8.16.0 v2.18.0 / 1.8.0 / 8.22.0
vault-backup-validator v2.18.0 v2.19.0
app chart (non-monitoring apps, incl. vault-init-controller 0.8.1) 0.13.0 0.14.1

Every image digest was resolved from the upstream registry and confirmed to be served by the matching *.repo.gpkg.io mirror. The two OCI charts (external-secrets, openbao) were also confirmed on the ghcr mirror.

Values changes that must ship with the bumps

  • Traefik chart 41: traefik.shared_helm_values.logs.general → log and logs.access → accessLog.
    • Chart 41's schema rejects the old keys (additional properties 'logs' not allowed), which would put all three Traefik apps into a sync error.
    • With the rename, the rendered args are unchanged: --log.format=json, --log.level=INFO, --accesslog=true, --accesslog.format=json.
  • external-dns v0.22.0 changed its default annotation prefix to external-dns.kubernetes.io/.
    • Platform resources, and most likely tenant ones, use external-dns.alpha.kubernetes.io/. With policy=sync, the new default would delete their records.
    • This PR sets the annotationPrefix parameter to the alpha prefix; the rendered arg is --annotation-prefix=external-dns.alpha.kubernetes.io/.
  • Traefik service.type → service.spec.type on all three instances: chart ≥ 40 ignores the top-level key (it only rendered LoadBalancer by chart default).
  • external-secrets webhook readiness port moved from the chart default 8081 to host_network.external_secrets.webhook_readiness_port: 45012 (the webhook runs with hostNetwork, so it is a host port; keep it in the 450xx range).
  • openbao autopilot.min_quorum 5 → 3 to match server.ha.replicas; 5 on a 3-node cluster disabled cleanup_dead_servers entirely.
  • Image pinning: cert-manager now passes imageRegistry + per-image tag@digest for all five images (the digest in container_images was previously unused); KEDA and reflector images are now pinned by digest under container_images and pulled through the mirrors.
  • app chart cleanup: dead image.pullPolicy / replicaCount keys removed; qr-code-generator now renders the 2 replicas its values always intended (was 1 via chart default).

⚠️ Rollout prerequisites

  1. platform-crds must ship matching CRDs, applied server-side before this release syncs:
  2. openbao: take a raft snapshot first. The StatefulSet restarts pods one at a time and each comes back sealed until vault-init-controller unseals it. vault-init-controller only uses sys/init, sys/unseal, sys/health and raft snapshot, and none of those are affected by the 2.5/2.6 API removals.
  3. cert-manager jumps 1.18 → 1.21. Upstream recommends one minor at a time, but between these versions the CRDs only gain fields. v1.21 requires Kubernetes ≥ 1.33. Clusters still on 1.32 must not take this release until their control plane is upgraded.
  4. external-dns: consider watching the first sync with --dry-run on a non-prod cluster.
  5. kubeadm etcd metrics must already be on 2381. This release scrapes kube-etcd over plain HTTP on the node address at 2381 and drops the etcd-client-certs mount (see the note below). GlueOps kubeadm clusters bind listen-metrics-urls: http://0.0.0.0:2381 via ClusterConfiguration in gluekube, but a cluster provisioned before that change does not pick it up by upgrading — its kubeadm-config ConfigMap has no such entry, so kubeadm upgrade apply re-renders etcd on kubeadm's default http://127.0.0.1:2381, which Prometheus cannot reach. Per gluekube's "migrating an existing cluster" steps, run rotate-certs-with-config.yaml to upload the ConfigMap, then a real version upgrade (the 1.35 move) to re-render the static pod, and verify curl -sS http://<master ip>:2381/health on every master before taking this release. Clusters that have not done this keep working on 2379/mTLS only until they take this chart version.

Not in this PR

  • Monitoring/logging (kube-prometheus-stack 59.1.0, Loki/promtail 2.9, Grafana 10.4, fluent-operator 2.7.0, glueops-alerts, loki-alert-group-controller). These are handled by feat!: replace the in-chart monitoring stack with the k8s-monitoring-helm app-of-apps (OTel, Thanos, Loki 3, Tempo) #1486, and the files are left untouched to avoid conflicts.
    • An in-place kube-prometheus-stack bump needs 86.x, not 90+: 90 drops the kubeEtcd.serviceMonitor cert file fields.
    • It also needs a fix to the admission-webhook certgen registry.
  • Argo CD (terraform module): v3.2.12 is tested only up to 1.34 and needs 3.4.x before clusters move to 1.35. 3.5 bundles Helm 4, so it's a separate step.
  • Kubernetes version: use 1.35.4 or later. 1.35.0–1.35.3 enable MaxUnavailableStatefulSet, which can leave podManagementPolicy: Parallel StatefulSets (Prometheus, Alertmanager, openbao) stuck mid-rollout (kubernetes#137409, reverted in #137926).
  • Descheduler v0.36.0 and the GlueOps first-party images are already compatible with 1.35.

Supersedes Renovate PRs #1453, #1460, #1342, #1439, #1484, #1487, #1497, #1476 and most of #1463. Those can be closed once this merges; Renovate will recreate any that are still relevant.

Verification (local, helm 3.20.2, --kube-version 1.35.0)

  • helm lint . -f ci/values.yaml: clean.
  • hack/check-no-crds.sh: 32 child sources rendered at their new versions, 0 CRDs. This includes Traefik 41.x schema validation and the external-secrets/openbao OCI pulls.
  • Platform chart before/after render diff contains only the version bumps, the Traefik log-key rename and the external-dns annotationPrefix parameter.
  • Old-vs-new upstream chart renders with this repo's real values:
    • ingress-nginx, goldilocks and the app chart (all 11 uses): identical apart from chart labels and image tags.
    • traefik 39 → 41.x: identical args, Service and RBAC once the log keys are renamed.
    • external-secrets 2.10.0: adds RBAC (CRD/secret/namespace patch) and a :8081 readiness containerPort. The webhook uses hostNetwork, so the scheduler now counts 8081 as a host port. It was already bound before.
    • openbao 0.29.4: adds appProtocol: HTTPS on Services and a RuntimeDefault seccomp profile. podManagementPolicy: Parallel stays pinned.
    • cert-manager 1.21.2: removes the unused tokenrequest Role. The metrics Service port is renamed to http-metrics (still 9402), and ServiceMonitor jobLabel becomes app.kubernetes.io/name.
    • external-dns 1.22.0: the dnsendpoints CRD is unchanged, and policy is now a required value (already set).
  • helm-docs 1.14.2 regenerated README (no diff on main before the change).
  • Not exercised: a live cluster sync. Please roll out to a dev cluster first.

🤖 Generated with Claude Code

https://claude.ai/code/session_01SW6t6HkN3k4wYusAkQ55eS


EDIT (2026-09-17) — updated after the component-by-component review. Changes since the original description, all merged into this branch as follow-up PRs:

PR Change
#1499 reflector image pinned by digest and pulled through dockerhub.repo.gpkg.io
#1500 app chart: dead image.pullPolicy/replicaCount keys removed; qr-code-generator deployment.replicas: 2
#1501 VPA bumped to chart 5.1.0 / 1.7.1 (upstream supports Kubernetes 1.28+, so no reason to defer)
#1502 KEDA images pinned by digest under container_images; global.image.registry kept
#1503 cert-manager images: imageRegistry from base_registries + per-image tag@digest (digest pin now enforced)
#1504 backup-tools v2.18.0 (OpenBao CLI 2.6.2, matches the server)
#1506 external-secrets webhook readiness port → 45012; dead webhook.port and stale CRD ignoreDifferences removed
#1507 openbao autopilot.min_quorum 5 → 3
#1508 goldilocks chart 11.1.1 / v4.16.2 (vulnerability-fix release)
#1509 traefik chart 41.6.0; service.type moved under service.spec
#1510 vault-backup-validator v2.19.0 (OpenBao 2.6.2 + renamed release asset; pairs with #1504)

Also reflected above: the component table, the values-changes list, the platform-crds prerequisite (now GlueOps/platform-crds#83, including VPA 1.7.1 and the traefik 41.6.0 pin), and the removal of VPA from "Not in this PR". Per-component review notes with the upstream summaries, render diffs and test results are in the comments below. Note: commit 0043e56 on this branch also changes the kubeadm etcd scrape in application-kube-prometheus-stack.yaml (port 2379 with mTLS → 2381, etcd-client-certs mount removed); the "monitoring files untouched" statement above predates it. This is the platform-side half of the gluekube etcd-metrics migration (its steps 4 and 5: repoint the serviceMonitor, drop the leftover secret) and is now written up as rollout prerequisite 5 above. A follow-up commit drops the kubeadm.kube_etcd.serviceMonitor values that hunk orphaned; the chart render is unchanged.

Bump charts and images that are unsupported or untested on Kubernetes 1.35,
plus low-risk bumps that were already pending.

- cert-manager v1.18.2 -> v1.21.2
- ingress-nginx 4.13.3 / v1.13.3 -> 4.15.1 / v1.15.1
- external-secrets 0.19.2 / v0.16.2 -> 2.10.0 / v2.10.0
- metacontroller v4.12.5 -> v4.17.2
- traefik 39.0.0 / v3.6.7 -> 41.5.0 / v3.7.13 (logs -> log/accessLog)
- openbao 0.19.3 / 2.4.4 -> 0.29.4 / 2.6.2
- external-dns 1.20.0 / v0.20.0 -> 1.22.0 / v0.22.0 (pin annotationPrefix
  to external-dns.alpha.kubernetes.io/)
- reflector 10.0.65, keda 2.20.2, goldilocks 11.1.0 / v4.16.1
- dex v2.45.1, oauth2-proxy v7.15.4, backup-tools v2.17.0,
  network_exporter 1.8.0, curl 8.22.0
- app chart 0.13.0/0.8.1 -> 0.14.1 (non-monitoring apps)

BREAKING CHANGE: requires platform-crds with matching CRDs (cert-manager
v1.21.2, external-secrets v2.10.0, metacontroller v4.17.2, traefik chart
41.5.0, keda v2.20.2) to be applied before this release syncs.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SW6t6HkN3k4wYusAkQ55eS
Copilot AI lite review requested due to automatic review settings September 14, 2026 15:36

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The cert-manager image digest value is unused, so the intended image pinning is not applied.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Upgrades platform components and mirrored images for Kubernetes 1.35 compatibility.

Changes:

  • Updates platform charts, controllers, and utility images.
  • Adjusts Traefik logging values and preserves the external-dns annotation prefix.
  • Refreshes application references and generated documentation.
File summaries
File Reviewed change
values.yaml Component image and Traefik value updates
templates/traefik-crds.yaml App chart upgrade
templates/qr-secrets-bootstrap+apps.yaml Bootstrap app chart upgrades
templates/application-vault.yaml OpenBao and init-controller upgrades
templates/application-traefik-public.yaml Traefik chart upgrade
templates/application-traefik-platform.yaml Traefik chart upgrade
templates/application-traefik-internal.yaml Traefik chart upgrade
templates/application-nginx-public.yaml Ingress-nginx chart upgrade
templates/application-network-exporter.yaml App chart upgrade
templates/application-metacontroller.yaml Metacontroller upgrade
templates/application-keda.yaml KEDA upgrade
templates/application-goldilocks.yaml Goldilocks upgrade
templates/application-go-healthz.yaml App chart upgrade
templates/application-external-secrets.yaml External Secrets upgrade
templates/application-external-dns.yaml External DNS upgrade and annotation prefix
templates/application-cluster-info-page.yaml App chart upgrade
templates/application-cert-reflector.yaml Reflector upgrade
templates/application-cert-manager.yaml Cert-manager chart upgrade
templates/application-ccm-gluekube.yaml App chart upgrade
templates/application-backups-and-exports.yaml App chart upgrade
templates/application-argocd-servicemonitors.yaml App chart upgrade
README.md Regenerated values documentation
Review details
  • Files reviewed: 22/22 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread values.yaml
hamzabouissi added a commit to GlueOps/platform-crds that referenced this pull request Sep 15, 2026
…rades

Match GlueOps/platform-helm-chart-platform#1498: cert-manager v1.21.2,
external-secrets v2.10.0, traefik chart v41.5.0, keda v2.20.2,
metacontroller v4.17.2 and external-dns chart 1.22.0 (which adds the
dnsrecords CRD file that the completeness check requires).

Only kustomization.yaml is edited; crds/ and the Chart.yaml pins are
regenerated by the render-on-renovate CI job.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings September 16, 2026 10:27
@github-actions github-actions Bot added the patch label Sep 16, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The kube-etcd ServiceMonitor change targets the wrong endpoint and removes required TLS configuration.

Get a fresh assessment by requesting another Copilot review.

Review details
  • Files reviewed: 23/23 changed files
  • Comments generated: 1
  • Review effort level: Lite

Comment thread templates/application-kube-prometheus-stack.yaml
@venkatamutyala

Copy link
Copy Markdown
Contributor

Review: oauth2-proxy v7.15.3 -> v7.15.4 ✅ looks good, no changes needed.

  • Upstream v7.15.4 is a single dependency-bump PR (chore(deps): update gomod oauth2-proxy/oauth2-proxy#3493): Go 1.26.4 -> 1.26.7, Alpine 3.23.3 -> 3.24.1, go-oidc 3.18 -> 3.20. No flag or default changes; upstream "Breaking Changes" section is empty.
  • Pulls in 11 Go stdlib / x/net CVE fixes, including CVE-2026-39821 (x/net idna, critical) and CVE-2026-33818, CVE-2026-56853, CVE-2026-56862 (high).
  • Every key in our config.configFile TOML was checked against the v7.15.4 option structs; all present, none deprecated.
  • Image config unchanged apart from build date (user 65532, same entrypoint). Digest in values.yaml matches quay.io for v7.15.4.
  • Chart stays at 10.7.0, which is still the latest published chart (appVersion 7.15.3), so the image override is the right way to get 7.15.4.

@venkatamutyala

Copy link
Copy Markdown
Contributor

Review: curl (curlimages/curl) 8.16.0 -> 8.22.0 ✅ looks good, no changes needed.

  • Six upstream releases (8.17.0 .. 8.22.0). 42 CVEs affecting 8.16.0 are fixed, all Low/Medium per the curl project; they concern auth state, proxy/netrc credential leaks, cookies and redirects, none of which apply to a plain GET with -k and no auth.
  • The image is only used by two Argo hook Jobs (cert-manager health check in application-vault.yaml, vault health check in application-external-secrets.yaml). Every flag they use (--silent, --insecure/-k, --connect-timeout, --output, --write-out %{http_code}) exists at 8.22.0 with no deprecation.
  • Image (now built from curl/curl-container): Alpine 3.22.1 -> 3.24.1, squashed to one layer, CA bundle sha256-verified. User curl_user, entrypoint, workdir and CURL_CA_BUNDLE unchanged. Jobs override the entrypoint with /bin/sh -c and write nothing to disk, so none of the image-build changes matter.
  • Digest in values.yaml matches Docker Hub for 8.22.0.

@venkatamutyala

Copy link
Copy Markdown
Contributor

Review: reflector 10.0.8 -> 10.0.65 ✅ looks good; one follow-up in #1499.

…#1499)

reflector was the only component whose image was neither routed through a
*.repo.gpkg.io mirror nor pinned under container_images; the chart pulled
docker.io/emberstack/kubernetes-reflector at its appVersion with no digest.

Add container_images.app_reflector with the 10.0.65 multi-arch index digest
(resolved from Docker Hub and confirmed served by dockerhub.repo.gpkg.io) and
pass it to the chart's image.repository/image.tag. Rendered image:
dockerhub.repo.gpkg.io/emberstack/kubernetes-reflector:10.0.65@sha256:51dbd58...

README regenerated with helm-docs 1.14.2.


Claude-Session: https://claude.ai/code/session_01FSau4e6nS8Y7eM1nQHwq6k

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings September 17, 2026 12:07
@venkatamutyala

Copy link
Copy Markdown
Contributor

Review: network_exporter 1.7.10 -> 1.8.0 ✅ looks good, no changes needed.

  • Upstream (syepes/network_exporter, tag 1.8.0, 2025-10-05): IPv6 panic fix; config loading from an HTTP URL (--config.file.header); --max-concurrent-jobs (default 3, previously hard-coded); optional icmp.payload_size, mtr.payload_size, mtr.protocol, mtr.tcp_port with defaults applied before validation; TCP traceroute (only with mtr.protocol: tcp); probe start jitter; pooled HTTP transports; cached metric descriptors. Go 1.24 -> 1.25. Dockerfile unchanged (Alpine, /app/network_exporter, setcap NET_RAW/NET_ADMIN, port 9427).
  • Metric names, help strings and label sets: diffed every NewDesc in collector/ between the tags, all 16 families identical. Every query in the grafana-dashboards v0.12.1 network-exporter dashboard still resolves. No PrometheusRule/Loki rule references these metrics.
  • Our DaemonSet config: command/--config.file valid, every key in the ConfigMap still exists under the same name, port/probes unchanged. Only silent change: AAAA results are dropped without --ipv6; our targets are IPv4 addresses and in-cluster Service names, so no effect on IPv4 clusters.
  • Digest in values.yaml matches Docker Hub for 1.8.0.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

Set the kubeadm etcd ServiceMonitor scheme to http to prevent scraping failures.

Review details

Suppressed comments (1)

templates/application-kube-prometheus-stack.yaml:88

  • This changes the kubeadm etcd Service to the metrics port 2381 but removes the serviceMonitor override without setting its scheme. In kube-prometheus-stack 59.1.0 the kubeEtcd ServiceMonitor defaults to HTTPS, while kubeadm's 2381 metrics listener is HTTP, so Prometheus will scrape the new port with the wrong protocol and the kubeadm etcd monitor will fail. Set kubeEtcd.serviceMonitor.scheme to http (or retain the previous TLS/2379 configuration).
            port: 2381
            targetPort: 2381
  • Files reviewed: 23/23 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

@venkatamutyala

Copy link
Copy Markdown
Contributor

Review: GlueOps app chart 0.13.0 -> 0.14.1 (vault-init-controller 0.8.1 -> 0.14.1) ✅ looks good; cleanup follow-up in #1500.

  • Upstream (GlueOps/project-template-helm-chart-app): 0.14.0 (fix: ingress nginx #117) adds global imagePullSecrets inheritance and per-job enabled; 0.14.1 is LICENSE/CI only. No change to deployment/statefulset/service/ingress/RBAC templates, label or selector helpers, probes, securityContext or resource defaults. The 0.8.1 -> 0.13.0 stretch (vault-init-controller only) changed the app.name default to the release name, which would alter selectors, but every Application sets appName.
  • All 11 Applications rendered old chart vs 0.14.1 with their exact values: differences are the helm.sh/chart label/annotation only (plus the backup-tools and network_exporter image tags that come from values.yaml). argocd-servicemonitors, network-exporter and traefik-crds-and-middleware have zero chart-driven diff. vault-init-controller: selector, image v2.14.0, env, RBAC, scheduling all identical.
  • traefik-crds-and-middleware renders 3 Namespaces and 8 oauth2 Middlewares, no CRDs and no IngressRoutes, so it is not affected by the Traefik CRD question.
  • Effect: one rolling restart for each of the 7 Deployment-bearing Applications (incl. vault-init-controller, which rolls with maxSurge 100% / maxUnavailable 0 and syncs with Replace=true).
  • Pre-existing, not from this PR: image.pullPolicy (4 apps) and replicaCount (qr-code-generator) are keys the chart never reads. fix: drop dead app-chart values and set qr-code-generator replicas via deployment.replicas #1500 (targeting this branch) removes them and expresses qr-code-generator's intended 2 replicas via deployment.replicas, which is a real change from the 1 replica currently rendered; see that PR for the caveat.

…a deployment.replicas (#1500)

The GlueOps app chart never reads image.pullPolicy (it reads
deployment.imagePullPolicy, which these Applications already set) or a
top-level replicaCount (it reads deployment.replicas). Verified against the
chart templates at 0.13.0 and 0.14.1.

- cluster-info-page, go-healthz, pull-request-bot: remove image.pullPolicy.
  Rendered manifests are byte-identical.
- qr-code-generator: replace the ignored replicaCount: '2' and
  image.pullPolicy with deployment.replicas: 2 and
  deployment.imagePullPolicy: IfNotPresent. This changes the rendered
  Deployment from 1 replica (the chart default that was silently applied) to
  the 2 replicas the file has intended since #1168, and the chart's
  multi-replica rollout strategy (maxSurge 50%, maxUnavailable 1) follows.


Claude-Session: https://claude.ai/code/session_01FSau4e6nS8Y7eM1nQHwq6k

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings September 17, 2026 12:15

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

Moderate unresolved findings affect kube-etcd monitoring scope/configuration and cert-manager image pinning.

Review details

Suppressed comments (3)

Previously missed (1) — in code that hasn't changed since the last review.

templates/application-kube-prometheus-stack.yaml:88

  • This hunk is outside the stated scope: the PR says monitoring/logging and application-kube-prometheus-stack.yaml are left untouched, but it changes kubeadm etcd scraping from the existing 2379/TLS configuration to 2381 and the adjacent hunk removes the certificate volume. That is a functional monitoring change and is not included in the claimed render-diff or rollout notes. Please either revert these kube-prometheus-stack changes or document and validate the new scrape mode (including its HTTP/TLS settings) before merging.

templates/application-kube-prometheus-stack.yaml:88

  • On standard kubeadm control-plane manifests, etcd serves client traffic on the node address at 2379 while its metrics listener on 2381 is normally bound to 127.0.0.1. The generated Service targets the node address, so switching this Service to 2381 and removing the TLS client configuration makes the kube-etcd ServiceMonitor fail. Keep the 2379/TLS configuration, or explicitly configure kubeadm's metrics listener to a routable address and update the scrape configuration together.
        kubeEtcd:
          service:
            port: 2381
            targetPort: 2381

values.yaml:339

  • This updated digest is never passed to the cert-manager chart: the Application sets image.repository but does not set image.tag or image.digest for the controller (nor the companion images). Helm therefore renders the chart's default image tags, so the pinned v1.21.2@sha256:... value has no effect. Wire the tag/digest values into every cert-manager image override, or remove the unused digest values.
        tag: v1.21.2@sha256:70f532fd9cfde0b09d55687200942399d89838bc2d5d5b45152eb799a15912b8
  • Files reviewed: 23/23 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

@venkatamutyala

Copy link
Copy Markdown
Contributor

Review: goldilocks chart 10.4.1 -> 11.1.0 / image v4.14.1 -> v4.16.1 ✅ looks good; VPA follow-up in #1501.

  • Chart: values.yaml diff 10.4.1 -> 11.1.0 is a single line (image.tag). The major is driven by (a) the app's changed vpa-update-mode handling (goldilocks feat: update oauth2-proxy to v7.17.1 #minor #781, InPlaceOrRecreate silently ignored in goldilocks FairwindsOps/charts#1987: values now matched case-insensitively against the typed VPA modes, unknown values fall back to Off) and (b) the bundled vpa subchart moving to 5.0.* / VPA 1.7.1. We set no vpa-update-mode labels and vpa.enabled: false, so neither applies.
  • App v4.14.1 -> v4.16.1: Go 1.24 -> 1.26.5, Alpine 3.24.1, dashboard memory in Ki/Mi, no panic on VPAs without targetRef, dashboard marks containers already matching the recommendation, images moved to us-docker.pkg.dev/fairwinds-ops/oss/goldilocks (immutable, cosign-signed tags), client-go 0.33 -> 0.36 with WatchList-aware informers and a fallback, VPA library 1.4.1 -> 1.7.1.
  • Rendered diff with our values: the two container images only. RBAC, Services, the platform-traefik Ingress with the oauth2 middleware, scheduling and commands are byte-identical.
  • The PR body's VPA rationale ("1.7 is listed only from 1.35") does not match upstream: the compatibility table at tag 1.7.1 says 1.7.x -> Kubernetes 1.28+, with only the alpha in-place features needing 1.33+. feat!: bump VPA to chart 5.1.0 / 1.7.1 to match goldilocks 4.16.1 #1501 (targeting this branch) bumps VPA to chart 5.1.0 / 1.7.1 with digests; it needs the VPA 1.7.1 CRD from feat: update kubernetes/autoscaler to 1.7.1 #minor - autoclosed platform-crds#75 applied first (additive CRD change).

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

Unresolved moderate issues affect registry overrides, etcd monitoring, VPA compatibility, and image reproducibility.

Review details

Suppressed comments (6)

templates/application-cert-manager.yaml:47

  • This switches all cert-manager components to base_registries.quay_io and ignores the per-image registry values exposed under container_images.app_cert_manager.*.image.registry. A captain override of the existing cert-manager image registry will therefore be silently ignored, unlike the previous template behavior and the other component templates. Keep the global registry sourced from the configured cert-manager image registry (or otherwise preserve those overrides).
        - name: imageRegistry
          value: {{ .Values.base_registries.quay_io }}

templates/application-goldilocks.yaml:29

  • The PR's component table says Goldilocks should be chart 11.1.0 with image v4.16.1, but this change deploys 11.1.1 and v4.16.2. Please either align the pins with the stated change or update the version table and verification notes to document the versions actually reviewed.
    targetRevision: 11.1.1

templates/application-kube-prometheus-stack.yaml:88

  • This changes the still-deployed kube-prometheus-stack's kubeadm etcd Service from the existing authenticated 2379 endpoint to 2381 while also removing both the ServiceMonitor certificate paths and the Prometheus etcd-client-certs mount. The ServiceMonitor remains enabled, so this will leave kubeadm clusters unable to scrape etcd unless the new endpoint's scheme and authentication are explicitly configured. Restore the old TLS/client-cert wiring, or configure 2381 with its actual scheme and retain any required credentials.
        {{- if .Values.kubeadm.enabled }}
        kubeEtcd:
          service:
            port: 2381
            targetPort: 2381

templates/application-vpa.yaml:31

  • This enables VPA chart 5.1.0 with 1.7.1 images for every cluster where kubeadm.enabled is true. The rollout notes explicitly say VPA 1.7.1 should be introduced only after the control plane reaches Kubernetes 1.35, so this release can sync an unsupported VPA onto older kubeadm clusters; it also contradicts the stated "Not in this PR" scope. Revert the VPA chart/image bumps or add a real Kubernetes-version gate and update the rollout contract.
    targetRevision: 5.1.0

values.yaml:423

  • The component table says backup-tools is being upgraded to v2.17.0, while the changed value is v2.18.0. Please update the table and verification notes or pin the documented version so the rollout record matches the image that will run.
        tag: v2.18.0@sha256:c0a3f220c8425bed27acdc7e4bf58f9f8ae42effaf4ef66e25e8c77ae3f2f95d

values.yaml:411

  • The newly bumped Goldilocks image is tag-only, while the PR states that every image digest was resolved and the surrounding upgraded images are digest-pinned. A mutable v4.16.2 tag makes rollouts non-reproducible and can result in different bytes on different nodes; pin this image to the resolved mirror digest.
        tag: "v4.16.2"
  • Files reviewed: 24/24 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

Copilot AI review requested due to automatic review settings September 17, 2026 15:55
min_quorum is autopilot's floor for cleanup_dead_servers: it never prunes a
peer if doing so would take the cluster below this number. With 3 replicas
and min_quorum = 5 the cluster is always below the floor, so dead peers left
behind by an unplanned member replacement (pod recreated without its PVC)
were never removed and raft quorum would silently count them. Set it to 3,
matching server.ha.replicas, as upstream documents.

The StatefulSet pod template is unchanged (chart has no config checksum), so
this does not roll pods on its own; the value takes effect on each pod's next
restart, i.e. the 2.6.2 rollout in this branch.


Claude-Session: https://claude.ai/code/session_01FSau4e6nS8Y7eM1nQHwq6k

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
@venkatamutyala

Copy link
Copy Markdown
Contributor

Review: openbao chart 0.19.3 -> 0.29.4 / image 2.4.4 -> 2.6.2 ✅ looks good; autopilot fix merged in #1507. vault-init-controller checked against the new rollout.

  • Chart: 0.20.0 flipped the default podManagementPolicy to OrderedReady (we pin Parallel, render unchanged); 0.26.1 adds appProtocol: HTTPS on the vault, vault-active, vault-standby, vault-internal Service ports (Traefik already forces HTTPS via serversscheme); 0.26.3 adds a RuntimeDefault seccomp profile; 0.29.3 removes PSP templates and k8s version gating; 0.29.4 re-indents preStop (same command). HCL config template, readiness probe, update strategy, PDB, PVC template, ingress and RBAC output unchanged. 20 objects both sides. 0.29.5 (today) only touches the disabled snapshotAgent.
  • Server 2.5/2.6 breaking changes, none used here: unauthenticated sys/rekey and sys/generate-root disabled (no automation; operator runbooks need the 2.6 CLI or the listener opt-out); legacy sys/revoke/sys/renew removed (external-secrets uses auth/token/revoke-self); ./.. path segments rejected; identity templates with /, *, + rejected (none in chart); sys/init ignores stored_shares (never sent); container user openbao (chart already sets UID 100 + SKIP_CHOWN); release assets renamed (handled in feat: update backup-tools to v2.18.0 #1504/feat: update vault-backup-validator to v2.19.0 #1510); raft snapshots now uncompressed gzip, tar format unchanged. Standby nodes serve reads locally since 2.5.0, which only affects traffic via the vault Service (UI and vault-api ingress); all automation talks to vault-active or per-pod DNS. ~20 CVE/GHSA fixes gained.
  • Verified: our HCL validates with the real 2.6.2 binary (bao operator validate-config); in-place 2.4.4 -> 2.6.2 raft data upgrade with KV v2 + kubernetes auth unsealed with the 2.4.4 key; 2.4.4 snapshot restored into fresh 2.6.2 (ENABLE_RESTORE path); every consumer's endpoints checked in source (vault-init-controller: sys/init, sys/health, sys/unseal, snapshot-force; external-secrets vault provider; health-check Job 200/429; backup-tools snapshot save against 2.6.2; Dex OIDC callback path). Downgrade of the data dir also worked in the test but upstream does not guarantee it: the S3 snapshot is the rollback path.
  • Rollout: pod template changes (image, seccomp, chart label), so all three pods restart via RollingUpdate, ordinal 2 -> 1 -> 0, each waiting for Ready. Ready means unsealed, so the rollout serialises on vault-init-controller. Read its v2.14.0 loop: waits until every vault pod is Running, checks initialized on vault-0, then per ordinal checks sealed on vault-N.vault-internal and unseals. That matches a rolling restart exactly (new pod is Running but sealed, gets unsealed, readiness flips, StatefulSet proceeds); vault-internal publishes not-ready addresses so per-pod DNS resolves throughout; none of the fields/endpoints it uses changed in 2.6.2. Pre-existing wart, unrelated to the bump: a connection error on the seal-status call makes the controller process exit(), so it can crash-restart during the second or two between a pod being Running and OpenBao listening; it recovers, but the restart backoff can add tens of seconds per pod. A retry instead of exit() would be a small fix in that repo.
  • Kubernetes 1.35.0-1.35.3 MaxUnavailableStatefulSet regression (StatefulSet pod revisions not updated when MaxUnavailableStatefulSet enabled kubernetes/kubernetes#137409, fixed in v1.35.4) is real and specific to this workload (Parallel + NotReady sealed pods). The tenant clusters checked are on 1.34.5, so it applies only after the control-plane move.
  • Pre-existing, fixed in fix: set openbao autopilot min_quorum to the actual voter count #1507: autopilot.min_quorum = 5 on a 3-replica cluster meant cleanup_dead_servers could never act; now 3.
  • Before rollout: all three pods unsealed and Ready, vault-init-controller not paused, latest backup run validated, control plane on 1.34 or >= 1.35.4. After: bao status on each pod shows 2.6.2 with one active/two standby, vault-backend Ready, next backup validated, UI login via Dex works; watch logs for deleting corrupt group (benign one-time cleanup) and transaction was leaked (upstream asks for a report).

@venkatamutyala

Copy link
Copy Markdown
Contributor

Review: backup-tools v2.15.0 -> v2.17.0 (now v2.18.0 via #1504) and vault-backup-validator (v2.19.0 via #1510) ✅ looks good after the two follow-ups.

  • Upstream backup-tools 2.16.0/2.17.0: restic-based NFS backup/restore scripts (not used by the platform), aws-cli/gh bumps, OpenBao CLI 2.5.4 -> 2.5.5. vault-backup.sh (the only script the vault-backups-to-s3 CronJob runs) is byte-identical across 2.15.0 -> 2.18.0; every env var the platform passes is still read. 2.18.0 (released today) moves the CLI to 2.6.2 via the renamed upstream asset, matching the OpenBao server in this branch.
  • The interaction that needed fixing: backup-vault posts the CLI version to vault-backup-validator, which re-downloads that OpenBao version when it differs from its cached one. With backup-tools 2.17.0 the validator (v2.18.0, cached 2.5.4) fetched a tarball from GitHub every 10 minutes and validated 2.6.2-server snapshots on a 2.5.x binary; with backup-tools 2.18.0 alone it would have 404'd (old asset name for 2.6.2, verified) and failed every validation after a successful S3 upload. feat: update vault-backup-validator to v2.19.0 #1510 moves the validator to v2.19.0 (OpenBao 2.6.2, renamed asset; validator chore(deps): update ghcr.io/glueops/vault-init-controller docker tag to v0.6.1 #255), so both sides run the server's version, no per-run download.
  • Verified: bao 2.5.5 CLI snapshot/token calls against a real 2.6.2 server; 2.6.2 snapshot restored into a fresh 2.5.5 (the interim validator direction) and into 2.6.2. Digests for both images are manifest digests identical on ghcr.io and the mirror.
  • After rollout: one vault-backups-to-s3 run end to end, S3 upload then HTTP 200 from /api/v1/validate; validator log shows BUILT IN OPENBAO_VERSION: 2.6.2 and no download.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

Resolve the etcd monitoring and VPA scope issues, and pin the Goldilocks image digest.

Review details

Suppressed comments (3)

Previously missed (1) — in code that hasn't changed since the last review.

values.yaml:411

  • The newly bumped Goldilocks image is still specified only as mutable tag v4.16.2, despite the PR stating that every image digest was resolved and mirrored; the other newly bumped images are digest-pinned. Pin this image to its resolved gpkg.io digest (or correct the rollout claim), otherwise the workload can change without a chart commit.

templates/application-kube-prometheus-stack.yaml:88

  • On kubeadm clusters this still renders the kube-prometheus-stack etcd ServiceMonitor, but the new 2381 endpoint is HTTPS and this change removes both its TLS client-file configuration and the Prometheus etcd-client-certs mount (the corresponding paths remain in values.yaml:562-566). The target will therefore fail TLS/authentication and etcd metrics will disappear. Restore the TLS settings and secret mount, or leave this monitoring file unchanged in this dependency upgrade.
        kubeEtcd:
          service:
            port: 2381
            targetPort: 2381

templates/application-vpa.yaml:31

  • The PR description explicitly excludes the VPA 1.7.1 upgrade and says it should be deferred until after the control plane is on Kubernetes 1.35, but this changes the VPA chart to 5.1.0 (and values.yaml also changes all three VPA images to 1.7.1). Revert these VPA changes or update the stated scope and rollout prerequisites so the release does not silently deploy the deferred component.
    targetRevision: 5.1.0
  • Files reviewed: 24/24 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

Copilot AI review requested due to automatic review settings September 17, 2026 15:59

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Unresolved chart, rollout-gating, monitoring, and image-digest issues must be addressed.

Get a fresh assessment by requesting another Copilot review.

Review details

Suppressed comments (3)

Previously missed (1) — in code that hasn't changed since the last review.

values.yaml:411

  • This newly upgraded Goldilocks image is the only changed image here that remains tag-only (v4.16.2), so the deployment is still mutable and not reproducible despite the PR stating that every image digest was resolved and pinned. Please use the matching mirror digest (v4.16.2@sha256:...) as with the other bumped images.

templates/application-kube-prometheus-stack.yaml:88

  • The PR says monitoring/logging files are left untouched, but this hunk changes the kubeadm etcd scrape and removes the existing client-certificate configuration and Prometheus secret mount. The resulting ServiceMonitor falls back to the chart's HTTP defaults on port 2381 instead of the configured TLS endpoint on 2379; please revert this unrelated behavior change or document and verify the intended endpoint migration.
        kubeEtcd:
          service:
            port: 2381
            targetPort: 2381

templates/application-vpa.yaml:31

  • The PR explicitly lists VPA 1.7.1 as not in scope and says to bump it only after the control plane is on Kubernetes 1.35, but this changes the chart to 5.1.0 (and the values file changes all VPA images to 1.7.1). This Application is gated only by kubeadm.enabled, so a kubeadm cluster still on 1.34 would receive this rollout; please keep the existing VPA versions or add an explicit Kubernetes-version gate and update the rollout prerequisites.
    targetRevision: 5.1.0
  • Files reviewed: 24/24 changed files
  • Comments generated: 1
  • Review effort level: Lite

Comment thread templates/application-vpa.yaml
…1509)

Chart 40.0.0 moved the Service spec fields under service.spec (#1686); a
top-level service.type has been ignored since, and LoadBalancer only rendered
because it is the chart default. Move it next to externalTrafficPolicy in all
three Applications so the value is honoured again. Verified: with the key in
its old place spec.type=ClusterIP renders LoadBalancer; in the new place it
renders ClusterIP.

Also bump 41.5.0 -> 41.6.0 (2026-09-16): PDB apiVersion chosen by kubeVersion,
Hub transparency-log values. Proxy stays v3.7.13 and the chart's crds/ are
byte-identical to 41.5.0, so the platform-crds pin is unaffected. All three
instances render identically apart from the chart label.


Claude-Session: https://claude.ai/code/session_01FSau4e6nS8Y7eM1nQHwq6k

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings September 17, 2026 16:06

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Unresolved moderate issues affect rollout scope, CRD compatibility, etcd monitoring, and version documentation.

Get a fresh assessment by requesting another Copilot review.

Review details

Suppressed comments (7)

templates/application-goldilocks.yaml:29

  • The component matrix says Goldilocks will use chart 11.1.0 and image v4.16.1, but this change deploys chart 11.1.1 and image v4.16.2. Since the rollout/verification details use the matrix as the tested version set, please either pin the documented versions or update the matrix and rerun the stated checks.
    targetRevision: 11.1.1

templates/application-kube-prometheus-stack.yaml:88

  • Changing this from the existing 2379/HTTPS endpoint with etcd-client-certs to 2381 removes the TLS client configuration and Secret mount. kubeadm's etcd metrics listener normally binds to 127.0.0.1:2381, while this Service targets node addresses, so the kubeEtcd ServiceMonitor will stop scraping etcd on kubeadm clusters. Keep the existing TLS/2379 configuration, or explicitly configure kubeadm etcd to expose 2381 on the node address and verify that path before merging.
            port: 2381
            targetPort: 2381

templates/application-traefik-internal.yaml:30

  • These Applications skip CRD installation, but the PR description and rollout prerequisite specify Traefik chart 41.5.0; this target is 41.6.0. That leaves the required platform-crds version ambiguous and can pair the rendered resources with an unprovisioned CRD schema. Either pin the intended 41.5.0 release or update the description and ship/verify matching CRDs before merging.
    targetRevision: 41.6.0

templates/application-traefik-platform.yaml:29

  • These Applications skip CRD installation, but the PR description and rollout prerequisite specify Traefik chart 41.5.0; this target is 41.6.0. That leaves the required platform-crds version ambiguous and can pair the rendered resources with an unprovisioned CRD schema. Either pin the intended 41.5.0 release or update the description and ship/verify matching CRDs before merging.
    targetRevision: 41.6.0

templates/application-vpa.yaml:31

  • The PR explicitly lists VPA 1.7.1/chart 5.0.1 as not in this PR and says to defer it until the control plane is already on Kubernetes 1.35, but this change upgrades the VPA chart to 5.1.0 (and the values upgrade all VPA images to 1.7.1). This will roll out VPA despite the stated rollout boundary; revert the VPA changes or update the scope and prerequisites.
    targetRevision: 5.1.0

values.yaml:411

  • The newly bumped Goldilocks image is still tag-only (v4.16.2), while the PR states that every image digest was resolved and verified and the other changed images are digest-pinned. A mutable tag means the rollout may not run the image that was validated; pin this image to its mirror digest before merging.
        tag: "v4.16.2"

values.yaml:423

  • The component matrix lists backup-tools as v2.17.0, but the rendered values now deploy v2.18.0 (and also bump vault-backup-validator to v2.19.0 without listing it). This makes the documented release inventory and verification scope inaccurate; update the matrix or align the pins before merging.
        tag: v2.18.0@sha256:c0a3f220c8425bed27acdc7e4bf58f9f8ae42effaf4ef66e25e8c77ae3f2f95d
  • Files reviewed: 24/24 changed files
  • Comments generated: 1
  • Review effort level: Lite

Comment thread templates/application-traefik-public.yaml
The etcd scrape moved to the plaintext metrics listener on 2381 in 0043e56,
which removed the only template references to these caFile/certFile/keyFile
values and to the etcd-client-certs secret mount. Chart render is unchanged.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings September 18, 2026 12:24

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

A matching platform-crds release is not yet available, and the upgrade requires coordinated rollout validation.

Review details
  • Files reviewed: 24/24 changed files
  • Comments generated: 1
  • Review effort level: Lite

Comment thread templates/application-vpa.yaml
hamzabouissi added a commit to GlueOps/platform-crds that referenced this pull request Sep 18, 2026
…rades - abandoned (#83)

* feat: bump CRD sources for the Kubernetes 1.35 platform component upgrades

Match GlueOps/platform-helm-chart-platform#1498: cert-manager v1.21.2,
external-secrets v2.10.0, traefik chart v41.5.0, keda v2.20.2,
metacontroller v4.17.2 and external-dns chart 1.22.0 (which adds the
dnsrecords CRD file that the completeness check requires).

Only kustomization.yaml is edited; crds/ and the Chart.yaml pins are
regenerated by the render-on-renovate CI job.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* chore: re-render crds/ for renovate bump

* feat: upgrade argocd crds

* chore: re-render crds/ for renovate bump

* feat: bump traefik CRD source to chart v41.6.0 (#84)

The platform feature branch moved the three Traefik Applications to chart
41.6.0 (platform-helm-chart-platform#1509); keep the pin in step so the
terraform consistency check matches. The chart's crds/ are byte-identical
between v41.5.0 and v41.6.0, so only kustomization.yaml and the Chart.yaml
pin change; crds/ re-rendered with hack/render.sh, no content diff.


Claude-Session: https://claude.ai/code/session_01FSau4e6nS8Y7eM1nQHwq6k

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>

* feat: bump VPA CRD source to vertical-pod-autoscaler-1.7.1 (kubeadm profile) (#87)

* feat: bump VPA CRD source to vertical-pod-autoscaler-1.7.1 (kubeadm profile)

Source line only; crds/ and the Chart.yaml pin are rendered by the
render-on-renovate CI job. The platform feature branch runs the vpa chart
5.1.0 / VPA 1.7.1 (platform-helm-chart-platform#1501), and the chart README
requires the CRDs to be updated before the upgrade.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FSau4e6nS8Y7eM1nQHwq6k

* chore: re-render crds/ for renovate bump

---------

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Co-authored-by: github-actions <github-actions[bot]@users.noreply.github.com>

* feat: bump argo-cd CRD source to v3.4.9 (#88)

* feat: bump argo-cd CRD source to v3.4.9

Source line only; crds/ and the Chart.yaml pin are rendered by the
render-on-renovate CI job. v3.4.9 (2026-09-14) is the newest 3.4 patch and
the version Argo CD will move to; the CRD manifests are unchanged between
v3.4.6 and v3.4.9, so only the pin annotation should move.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FSau4e6nS8Y7eM1nQHwq6k

* chore: re-render crds/ for renovate bump

---------

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Co-authored-by: github-actions <github-actions[bot]@users.noreply.github.com>

---------

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Co-authored-by: github-actions <github-actions[bot]@users.noreply.github.com>
Co-authored-by: Venkat <venkata@venkatamutyala.com>
@hamzabouissi
hamzabouissi merged commit c6a2f04 into main Sep 18, 2026
4 checks passed
@hamzabouissi
hamzabouissi deleted the feat/k8s-1.35-component-upgrades branch September 18, 2026 12:46
venkatamutyala added a commit that referenced this pull request Sep 29, 2026
Brings in 0.80.0-0.80.2 (#1498 Kubernetes 1.35 component upgrade, #1512/#1514 etcd metrics).

Conflict resolutions:
- templates/application-kube-prometheus-stack.yaml: kept the deletion; the stack now lives in
  GlueOps/k8s-monitoring-helm. main's etcd change (#1514: port 2381, no client certs) must be ported there.
- values.yaml: dex v2.45.1 and network_exporter 1.8.0 from main; app_promtail stays removed.
- README.md: regenerated with helm-docs 1.12.0 (the version release-please uses).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
venkatamutyala added a commit that referenced this pull request Sep 29, 2026
Matches the rest of the non-monitoring apps, bumped in #1498. Rendered output differs only in the helm.sh/chart label.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
venkatamutyala added a commit that referenced this pull request Sep 29, 2026
Brings in 0.80.0-0.80.2 (#1498 Kubernetes 1.35 component upgrade, #1512/#1514 etcd metrics).

Conflict resolutions:
- templates/application-kube-prometheus-stack.yaml: kept the deletion; the stack now lives in
  GlueOps/k8s-monitoring-helm. main's etcd change (#1514: port 2381, no client certs) must be ported there.
- values.yaml: dex v2.45.1 and network_exporter 1.8.0 from main; app_promtail stays removed.
- README.md: regenerated with helm-docs 1.12.0 (the version release-please uses).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
venkatamutyala added a commit that referenced this pull request Sep 29, 2026
Matches the rest of the non-monitoring apps, bumped in #1498. Rendered output differs only in the helm.sh/chart label.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants