feat!: upgrade platform components for Kubernetes 1.35 - #1498
Conversation
Bump charts and images that are unsupported or untested on Kubernetes 1.35, plus low-risk bumps that were already pending. - cert-manager v1.18.2 -> v1.21.2 - ingress-nginx 4.13.3 / v1.13.3 -> 4.15.1 / v1.15.1 - external-secrets 0.19.2 / v0.16.2 -> 2.10.0 / v2.10.0 - metacontroller v4.12.5 -> v4.17.2 - traefik 39.0.0 / v3.6.7 -> 41.5.0 / v3.7.13 (logs -> log/accessLog) - openbao 0.19.3 / 2.4.4 -> 0.29.4 / 2.6.2 - external-dns 1.20.0 / v0.20.0 -> 1.22.0 / v0.22.0 (pin annotationPrefix to external-dns.alpha.kubernetes.io/) - reflector 10.0.65, keda 2.20.2, goldilocks 11.1.0 / v4.16.1 - dex v2.45.1, oauth2-proxy v7.15.4, backup-tools v2.17.0, network_exporter 1.8.0, curl 8.22.0 - app chart 0.13.0/0.8.1 -> 0.14.1 (non-monitoring apps) BREAKING CHANGE: requires platform-crds with matching CRDs (cert-manager v1.21.2, external-secrets v2.10.0, metacontroller v4.17.2, traefik chart 41.5.0, keda v2.20.2) to be applied before this release syncs. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SW6t6HkN3k4wYusAkQ55eS
There was a problem hiding this comment.
🟡 Changes recommended
The cert-manager image digest value is unused, so the intended image pinning is not applied.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
Upgrades platform components and mirrored images for Kubernetes 1.35 compatibility.
Changes:
- Updates platform charts, controllers, and utility images.
- Adjusts Traefik logging values and preserves the external-dns annotation prefix.
- Refreshes application references and generated documentation.
File summaries
| File | Reviewed change |
|---|---|
values.yaml |
Component image and Traefik value updates |
templates/traefik-crds.yaml |
App chart upgrade |
templates/qr-secrets-bootstrap+apps.yaml |
Bootstrap app chart upgrades |
templates/application-vault.yaml |
OpenBao and init-controller upgrades |
templates/application-traefik-public.yaml |
Traefik chart upgrade |
templates/application-traefik-platform.yaml |
Traefik chart upgrade |
templates/application-traefik-internal.yaml |
Traefik chart upgrade |
templates/application-nginx-public.yaml |
Ingress-nginx chart upgrade |
templates/application-network-exporter.yaml |
App chart upgrade |
templates/application-metacontroller.yaml |
Metacontroller upgrade |
templates/application-keda.yaml |
KEDA upgrade |
templates/application-goldilocks.yaml |
Goldilocks upgrade |
templates/application-go-healthz.yaml |
App chart upgrade |
templates/application-external-secrets.yaml |
External Secrets upgrade |
templates/application-external-dns.yaml |
External DNS upgrade and annotation prefix |
templates/application-cluster-info-page.yaml |
App chart upgrade |
templates/application-cert-reflector.yaml |
Reflector upgrade |
templates/application-cert-manager.yaml |
Cert-manager chart upgrade |
templates/application-ccm-gluekube.yaml |
App chart upgrade |
templates/application-backups-and-exports.yaml |
App chart upgrade |
templates/application-argocd-servicemonitors.yaml |
App chart upgrade |
README.md |
Regenerated values documentation |
Review details
- Files reviewed: 22/22 changed files
- Comments generated: 1
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
…rades Match GlueOps/platform-helm-chart-platform#1498: cert-manager v1.21.2, external-secrets v2.10.0, traefik chart v41.5.0, keda v2.20.2, metacontroller v4.17.2 and external-dns chart 1.22.0 (which adds the dnsrecords CRD file that the completeness check requires). Only kustomization.yaml is edited; crds/ and the Chart.yaml pins are regenerated by the render-on-renovate CI job. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
There was a problem hiding this comment.
🟡 Changes recommended
The kube-etcd ServiceMonitor change targets the wrong endpoint and removes required TLS configuration.
Get a fresh assessment by requesting another Copilot review.
Review details
- Files reviewed: 23/23 changed files
- Comments generated: 1
- Review effort level: Lite
|
Review: oauth2-proxy v7.15.3 -> v7.15.4 ✅ looks good, no changes needed.
|
|
Review: curl (curlimages/curl) 8.16.0 -> 8.22.0 ✅ looks good, no changes needed.
|
|
Review: reflector 10.0.8 -> 10.0.65 ✅ looks good; one follow-up in #1499.
|
…#1499) reflector was the only component whose image was neither routed through a *.repo.gpkg.io mirror nor pinned under container_images; the chart pulled docker.io/emberstack/kubernetes-reflector at its appVersion with no digest. Add container_images.app_reflector with the 10.0.65 multi-arch index digest (resolved from Docker Hub and confirmed served by dockerhub.repo.gpkg.io) and pass it to the chart's image.repository/image.tag. Rendered image: dockerhub.repo.gpkg.io/emberstack/kubernetes-reflector:10.0.65@sha256:51dbd58... README regenerated with helm-docs 1.14.2. Claude-Session: https://claude.ai/code/session_01FSau4e6nS8Y7eM1nQHwq6k Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
|
Review: network_exporter 1.7.10 -> 1.8.0 ✅ looks good, no changes needed.
|
There was a problem hiding this comment.
🔵 Needs a closer look
Set the kubeadm etcd ServiceMonitor scheme to http to prevent scraping failures.
Review details
Suppressed comments (1)
templates/application-kube-prometheus-stack.yaml:88
- This changes the kubeadm etcd Service to the metrics port 2381 but removes the
serviceMonitoroverride without setting its scheme. In kube-prometheus-stack 59.1.0 the kubeEtcd ServiceMonitor defaults to HTTPS, while kubeadm's 2381 metrics listener is HTTP, so Prometheus will scrape the new port with the wrong protocol and the kubeadm etcd monitor will fail. SetkubeEtcd.serviceMonitor.schemetohttp(or retain the previous TLS/2379 configuration).
port: 2381
targetPort: 2381
- Files reviewed: 23/23 changed files
- Comments generated: 0 new
- Review effort level: Lite
|
Review: GlueOps
|
…a deployment.replicas (#1500) The GlueOps app chart never reads image.pullPolicy (it reads deployment.imagePullPolicy, which these Applications already set) or a top-level replicaCount (it reads deployment.replicas). Verified against the chart templates at 0.13.0 and 0.14.1. - cluster-info-page, go-healthz, pull-request-bot: remove image.pullPolicy. Rendered manifests are byte-identical. - qr-code-generator: replace the ignored replicaCount: '2' and image.pullPolicy with deployment.replicas: 2 and deployment.imagePullPolicy: IfNotPresent. This changes the rendered Deployment from 1 replica (the chart default that was silently applied) to the 2 replicas the file has intended since #1168, and the chart's multi-replica rollout strategy (maxSurge 50%, maxUnavailable 1) follows. Claude-Session: https://claude.ai/code/session_01FSau4e6nS8Y7eM1nQHwq6k Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
There was a problem hiding this comment.
🔵 Needs a closer look
Moderate unresolved findings affect kube-etcd monitoring scope/configuration and cert-manager image pinning.
Review details
Suppressed comments (3)
Previously missed (1) — in code that hasn't changed since the last review.
templates/application-kube-prometheus-stack.yaml:88
- This hunk is outside the stated scope: the PR says monitoring/logging and
application-kube-prometheus-stack.yamlare left untouched, but it changes kubeadm etcd scraping from the existing 2379/TLS configuration to 2381 and the adjacent hunk removes the certificate volume. That is a functional monitoring change and is not included in the claimed render-diff or rollout notes. Please either revert these kube-prometheus-stack changes or document and validate the new scrape mode (including its HTTP/TLS settings) before merging.
templates/application-kube-prometheus-stack.yaml:88
- On standard kubeadm control-plane manifests, etcd serves client traffic on the node address at 2379 while its metrics listener on 2381 is normally bound to 127.0.0.1. The generated Service targets the node address, so switching this Service to 2381 and removing the TLS client configuration makes the kube-etcd ServiceMonitor fail. Keep the 2379/TLS configuration, or explicitly configure kubeadm's metrics listener to a routable address and update the scrape configuration together.
kubeEtcd:
service:
port: 2381
targetPort: 2381
values.yaml:339
- This updated digest is never passed to the cert-manager chart: the Application sets
image.repositorybut does not setimage.tagorimage.digestfor the controller (nor the companion images). Helm therefore renders the chart's default image tags, so the pinnedv1.21.2@sha256:...value has no effect. Wire the tag/digest values into every cert-manager image override, or remove the unused digest values.
tag: v1.21.2@sha256:70f532fd9cfde0b09d55687200942399d89838bc2d5d5b45152eb799a15912b8
- Files reviewed: 23/23 changed files
- Comments generated: 0 new
- Review effort level: Lite
|
Review: goldilocks chart 10.4.1 -> 11.1.0 / image v4.14.1 -> v4.16.1 ✅ looks good; VPA follow-up in #1501.
|
There was a problem hiding this comment.
🔵 Needs a closer look
Unresolved moderate issues affect registry overrides, etcd monitoring, VPA compatibility, and image reproducibility.
Review details
Suppressed comments (6)
templates/application-cert-manager.yaml:47
- This switches all cert-manager components to
base_registries.quay_ioand ignores the per-image registry values exposed undercontainer_images.app_cert_manager.*.image.registry. A captain override of the existing cert-manager image registry will therefore be silently ignored, unlike the previous template behavior and the other component templates. Keep the global registry sourced from the configured cert-manager image registry (or otherwise preserve those overrides).
- name: imageRegistry
value: {{ .Values.base_registries.quay_io }}
templates/application-goldilocks.yaml:29
- The PR's component table says Goldilocks should be chart 11.1.0 with image v4.16.1, but this change deploys 11.1.1 and v4.16.2. Please either align the pins with the stated change or update the version table and verification notes to document the versions actually reviewed.
targetRevision: 11.1.1
templates/application-kube-prometheus-stack.yaml:88
- This changes the still-deployed kube-prometheus-stack's kubeadm etcd Service from the existing authenticated 2379 endpoint to 2381 while also removing both the ServiceMonitor certificate paths and the Prometheus
etcd-client-certsmount. The ServiceMonitor remains enabled, so this will leave kubeadm clusters unable to scrape etcd unless the new endpoint's scheme and authentication are explicitly configured. Restore the old TLS/client-cert wiring, or configure 2381 with its actual scheme and retain any required credentials.
{{- if .Values.kubeadm.enabled }}
kubeEtcd:
service:
port: 2381
targetPort: 2381
templates/application-vpa.yaml:31
- This enables VPA chart 5.1.0 with 1.7.1 images for every cluster where
kubeadm.enabledis true. The rollout notes explicitly say VPA 1.7.1 should be introduced only after the control plane reaches Kubernetes 1.35, so this release can sync an unsupported VPA onto older kubeadm clusters; it also contradicts the stated "Not in this PR" scope. Revert the VPA chart/image bumps or add a real Kubernetes-version gate and update the rollout contract.
targetRevision: 5.1.0
values.yaml:423
- The component table says backup-tools is being upgraded to v2.17.0, while the changed value is v2.18.0. Please update the table and verification notes or pin the documented version so the rollout record matches the image that will run.
tag: v2.18.0@sha256:c0a3f220c8425bed27acdc7e4bf58f9f8ae42effaf4ef66e25e8c77ae3f2f95d
values.yaml:411
- The newly bumped Goldilocks image is tag-only, while the PR states that every image digest was resolved and the surrounding upgraded images are digest-pinned. A mutable
v4.16.2tag makes rollouts non-reproducible and can result in different bytes on different nodes; pin this image to the resolved mirror digest.
tag: "v4.16.2"
- Files reviewed: 24/24 changed files
- Comments generated: 0 new
- Review effort level: Lite
min_quorum is autopilot's floor for cleanup_dead_servers: it never prunes a peer if doing so would take the cluster below this number. With 3 replicas and min_quorum = 5 the cluster is always below the floor, so dead peers left behind by an unplanned member replacement (pod recreated without its PVC) were never removed and raft quorum would silently count them. Set it to 3, matching server.ha.replicas, as upstream documents. The StatefulSet pod template is unchanged (chart has no config checksum), so this does not roll pods on its own; the value takes effect on each pod's next restart, i.e. the 2.6.2 rollout in this branch. Claude-Session: https://claude.ai/code/session_01FSau4e6nS8Y7eM1nQHwq6k Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
|
Review: openbao chart 0.19.3 -> 0.29.4 / image 2.4.4 -> 2.6.2 ✅ looks good; autopilot fix merged in #1507. vault-init-controller checked against the new rollout.
|
|
Review: backup-tools v2.15.0 -> v2.17.0 (now v2.18.0 via #1504) and vault-backup-validator (v2.19.0 via #1510) ✅ looks good after the two follow-ups.
|
There was a problem hiding this comment.
🔵 Needs a closer look
Resolve the etcd monitoring and VPA scope issues, and pin the Goldilocks image digest.
Review details
Suppressed comments (3)
Previously missed (1) — in code that hasn't changed since the last review.
values.yaml:411
- The newly bumped Goldilocks image is still specified only as mutable tag
v4.16.2, despite the PR stating that every image digest was resolved and mirrored; the other newly bumped images are digest-pinned. Pin this image to its resolved gpkg.io digest (or correct the rollout claim), otherwise the workload can change without a chart commit.
templates/application-kube-prometheus-stack.yaml:88
- On kubeadm clusters this still renders the kube-prometheus-stack etcd ServiceMonitor, but the new 2381 endpoint is HTTPS and this change removes both its TLS client-file configuration and the Prometheus
etcd-client-certsmount (the corresponding paths remain invalues.yaml:562-566). The target will therefore fail TLS/authentication and etcd metrics will disappear. Restore the TLS settings and secret mount, or leave this monitoring file unchanged in this dependency upgrade.
kubeEtcd:
service:
port: 2381
targetPort: 2381
templates/application-vpa.yaml:31
- The PR description explicitly excludes the VPA 1.7.1 upgrade and says it should be deferred until after the control plane is on Kubernetes 1.35, but this changes the VPA chart to 5.1.0 (and
values.yamlalso changes all three VPA images to 1.7.1). Revert these VPA changes or update the stated scope and rollout prerequisites so the release does not silently deploy the deferred component.
targetRevision: 5.1.0
- Files reviewed: 24/24 changed files
- Comments generated: 0 new
- Review effort level: Lite
There was a problem hiding this comment.
🟡 Changes recommended
Unresolved chart, rollout-gating, monitoring, and image-digest issues must be addressed.
Get a fresh assessment by requesting another Copilot review.
Review details
Suppressed comments (3)
Previously missed (1) — in code that hasn't changed since the last review.
values.yaml:411
- This newly upgraded Goldilocks image is the only changed image here that remains tag-only (
v4.16.2), so the deployment is still mutable and not reproducible despite the PR stating that every image digest was resolved and pinned. Please use the matching mirror digest (v4.16.2@sha256:...) as with the other bumped images.
templates/application-kube-prometheus-stack.yaml:88
- The PR says monitoring/logging files are left untouched, but this hunk changes the kubeadm etcd scrape and removes the existing client-certificate configuration and Prometheus secret mount. The resulting ServiceMonitor falls back to the chart's HTTP defaults on port 2381 instead of the configured TLS endpoint on 2379; please revert this unrelated behavior change or document and verify the intended endpoint migration.
kubeEtcd:
service:
port: 2381
targetPort: 2381
templates/application-vpa.yaml:31
- The PR explicitly lists VPA 1.7.1 as not in scope and says to bump it only after the control plane is on Kubernetes 1.35, but this changes the chart to 5.1.0 (and the values file changes all VPA images to 1.7.1). This Application is gated only by
kubeadm.enabled, so a kubeadm cluster still on 1.34 would receive this rollout; please keep the existing VPA versions or add an explicit Kubernetes-version gate and update the rollout prerequisites.
targetRevision: 5.1.0
- Files reviewed: 24/24 changed files
- Comments generated: 1
- Review effort level: Lite
…1509) Chart 40.0.0 moved the Service spec fields under service.spec (#1686); a top-level service.type has been ignored since, and LoadBalancer only rendered because it is the chart default. Move it next to externalTrafficPolicy in all three Applications so the value is honoured again. Verified: with the key in its old place spec.type=ClusterIP renders LoadBalancer; in the new place it renders ClusterIP. Also bump 41.5.0 -> 41.6.0 (2026-09-16): PDB apiVersion chosen by kubeVersion, Hub transparency-log values. Proxy stays v3.7.13 and the chart's crds/ are byte-identical to 41.5.0, so the platform-crds pin is unaffected. All three instances render identically apart from the chart label. Claude-Session: https://claude.ai/code/session_01FSau4e6nS8Y7eM1nQHwq6k Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
There was a problem hiding this comment.
🟡 Changes recommended
Unresolved moderate issues affect rollout scope, CRD compatibility, etcd monitoring, and version documentation.
Get a fresh assessment by requesting another Copilot review.
Review details
Suppressed comments (7)
templates/application-goldilocks.yaml:29
- The component matrix says Goldilocks will use chart 11.1.0 and image v4.16.1, but this change deploys chart 11.1.1 and image v4.16.2. Since the rollout/verification details use the matrix as the tested version set, please either pin the documented versions or update the matrix and rerun the stated checks.
targetRevision: 11.1.1
templates/application-kube-prometheus-stack.yaml:88
- Changing this from the existing 2379/HTTPS endpoint with
etcd-client-certsto 2381 removes the TLS client configuration and Secret mount. kubeadm's etcd metrics listener normally binds to127.0.0.1:2381, while this Service targets node addresses, so the kubeEtcd ServiceMonitor will stop scraping etcd on kubeadm clusters. Keep the existing TLS/2379 configuration, or explicitly configure kubeadm etcd to expose 2381 on the node address and verify that path before merging.
port: 2381
targetPort: 2381
templates/application-traefik-internal.yaml:30
- These Applications skip CRD installation, but the PR description and rollout prerequisite specify Traefik chart 41.5.0; this target is 41.6.0. That leaves the required platform-crds version ambiguous and can pair the rendered resources with an unprovisioned CRD schema. Either pin the intended 41.5.0 release or update the description and ship/verify matching CRDs before merging.
targetRevision: 41.6.0
templates/application-traefik-platform.yaml:29
- These Applications skip CRD installation, but the PR description and rollout prerequisite specify Traefik chart 41.5.0; this target is 41.6.0. That leaves the required platform-crds version ambiguous and can pair the rendered resources with an unprovisioned CRD schema. Either pin the intended 41.5.0 release or update the description and ship/verify matching CRDs before merging.
targetRevision: 41.6.0
templates/application-vpa.yaml:31
- The PR explicitly lists VPA 1.7.1/chart 5.0.1 as not in this PR and says to defer it until the control plane is already on Kubernetes 1.35, but this change upgrades the VPA chart to 5.1.0 (and the values upgrade all VPA images to 1.7.1). This will roll out VPA despite the stated rollout boundary; revert the VPA changes or update the scope and prerequisites.
targetRevision: 5.1.0
values.yaml:411
- The newly bumped Goldilocks image is still tag-only (
v4.16.2), while the PR states that every image digest was resolved and verified and the other changed images are digest-pinned. A mutable tag means the rollout may not run the image that was validated; pin this image to its mirror digest before merging.
tag: "v4.16.2"
values.yaml:423
- The component matrix lists backup-tools as v2.17.0, but the rendered values now deploy v2.18.0 (and also bump vault-backup-validator to v2.19.0 without listing it). This makes the documented release inventory and verification scope inaccurate; update the matrix or align the pins before merging.
tag: v2.18.0@sha256:c0a3f220c8425bed27acdc7e4bf58f9f8ae42effaf4ef66e25e8c77ae3f2f95d
- Files reviewed: 24/24 changed files
- Comments generated: 1
- Review effort level: Lite
The etcd scrape moved to the plaintext metrics listener on 2381 in 0043e56, which removed the only template references to these caFile/certFile/keyFile values and to the etcd-client-certs secret mount. Chart render is unchanged. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…rades - abandoned (#83) * feat: bump CRD sources for the Kubernetes 1.35 platform component upgrades Match GlueOps/platform-helm-chart-platform#1498: cert-manager v1.21.2, external-secrets v2.10.0, traefik chart v41.5.0, keda v2.20.2, metacontroller v4.17.2 and external-dns chart 1.22.0 (which adds the dnsrecords CRD file that the completeness check requires). Only kustomization.yaml is edited; crds/ and the Chart.yaml pins are regenerated by the render-on-renovate CI job. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * chore: re-render crds/ for renovate bump * feat: upgrade argocd crds * chore: re-render crds/ for renovate bump * feat: bump traefik CRD source to chart v41.6.0 (#84) The platform feature branch moved the three Traefik Applications to chart 41.6.0 (platform-helm-chart-platform#1509); keep the pin in step so the terraform consistency check matches. The chart's crds/ are byte-identical between v41.5.0 and v41.6.0, so only kustomization.yaml and the Chart.yaml pin change; crds/ re-rendered with hack/render.sh, no content diff. Claude-Session: https://claude.ai/code/session_01FSau4e6nS8Y7eM1nQHwq6k Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com> * feat: bump VPA CRD source to vertical-pod-autoscaler-1.7.1 (kubeadm profile) (#87) * feat: bump VPA CRD source to vertical-pod-autoscaler-1.7.1 (kubeadm profile) Source line only; crds/ and the Chart.yaml pin are rendered by the render-on-renovate CI job. The platform feature branch runs the vpa chart 5.1.0 / VPA 1.7.1 (platform-helm-chart-platform#1501), and the chart README requires the CRDs to be updated before the upgrade. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FSau4e6nS8Y7eM1nQHwq6k * chore: re-render crds/ for renovate bump --------- Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com> Co-authored-by: github-actions <github-actions[bot]@users.noreply.github.com> * feat: bump argo-cd CRD source to v3.4.9 (#88) * feat: bump argo-cd CRD source to v3.4.9 Source line only; crds/ and the Chart.yaml pin are rendered by the render-on-renovate CI job. v3.4.9 (2026-09-14) is the newest 3.4 patch and the version Argo CD will move to; the CRD manifests are unchanged between v3.4.6 and v3.4.9, so only the pin annotation should move. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FSau4e6nS8Y7eM1nQHwq6k * chore: re-render crds/ for renovate bump --------- Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com> Co-authored-by: github-actions <github-actions[bot]@users.noreply.github.com> --------- Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com> Co-authored-by: github-actions <github-actions[bot]@users.noreply.github.com> Co-authored-by: Venkat <venkata@venkatamutyala.com>
Brings in 0.80.0-0.80.2 (#1498 Kubernetes 1.35 component upgrade, #1512/#1514 etcd metrics). Conflict resolutions: - templates/application-kube-prometheus-stack.yaml: kept the deletion; the stack now lives in GlueOps/k8s-monitoring-helm. main's etcd change (#1514: port 2381, no client certs) must be ported there. - values.yaml: dex v2.45.1 and network_exporter 1.8.0 from main; app_promtail stays removed. - README.md: regenerated with helm-docs 1.12.0 (the version release-please uses). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Matches the rest of the non-monitoring apps, bumped in #1498. Rendered output differs only in the helm.sh/chart label. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Brings in 0.80.0-0.80.2 (#1498 Kubernetes 1.35 component upgrade, #1512/#1514 etcd metrics). Conflict resolutions: - templates/application-kube-prometheus-stack.yaml: kept the deletion; the stack now lives in GlueOps/k8s-monitoring-helm. main's etcd change (#1514: port 2381, no client certs) must be ported there. - values.yaml: dex v2.45.1 and network_exporter 1.8.0 from main; app_promtail stays removed. - README.md: regenerated with helm-docs 1.12.0 (the version release-please uses). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Matches the rest of the non-monitoring apps, bumped in #1498. Rendered output differs only in the helm.sh/chart label. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Why
We're moving clusters to Kubernetes 1.35. Several platform components are unsupported or untested on 1.35 at their current versions:
This PR bumps those, plus the low-risk bumps that were already queued in Renovate.
What
appchart (non-monitoring apps, incl. vault-init-controller 0.8.1)Every image digest was resolved from the upstream registry and confirmed to be served by the matching
*.repo.gpkg.iomirror. The two OCI charts (external-secrets, openbao) were also confirmed on the ghcr mirror.Values changes that must ship with the bumps
traefik.shared_helm_values.logs.general→logandlogs.access→accessLog.additional properties 'logs' not allowed), which would put all three Traefik apps into a sync error.--log.format=json,--log.level=INFO,--accesslog=true,--accesslog.format=json.external-dns.kubernetes.io/.external-dns.alpha.kubernetes.io/. Withpolicy=sync, the new default would delete their records.annotationPrefixparameter to the alpha prefix; the rendered arg is--annotation-prefix=external-dns.alpha.kubernetes.io/.service.type→service.spec.typeon all three instances: chart ≥ 40 ignores the top-level key (it only renderedLoadBalancerby chart default).host_network.external_secrets.webhook_readiness_port: 45012(the webhook runs with hostNetwork, so it is a host port; keep it in the 450xx range).autopilot.min_quorum5 → 3 to matchserver.ha.replicas; 5 on a 3-node cluster disabledcleanup_dead_serversentirely.imageRegistry+ per-imagetag@digestfor all five images (the digest incontainer_imageswas previously unused); KEDA and reflector images are now pinned by digest undercontainer_imagesand pulled through the mirrors.appchart cleanup: deadimage.pullPolicy/replicaCountkeys removed; qr-code-generator now renders the 2 replicas its values always intended (was 1 via chart default).spec.ingressClassNameon the dashboard IngressRoutes, and the v39 IngressRoute CRD doesn't have that field. Without it the three Traefik Applications end inSync Failed; do not work around it withValidate=false(that prunes the field and drops the dashboard route).sys/init,sys/unseal,sys/healthand raft snapshot, and none of those are affected by the 2.5/2.6 API removals.--dry-runon a non-prod cluster.etcd-client-certsmount (see the note below). GlueOps kubeadm clusters bindlisten-metrics-urls: http://0.0.0.0:2381viaClusterConfigurationin gluekube, but a cluster provisioned before that change does not pick it up by upgrading — itskubeadm-configConfigMap has no such entry, sokubeadm upgrade applyre-renders etcd on kubeadm's defaulthttp://127.0.0.1:2381, which Prometheus cannot reach. Per gluekube's "migrating an existing cluster" steps, runrotate-certs-with-config.yamlto upload the ConfigMap, then a real version upgrade (the 1.35 move) to re-render the static pod, and verifycurl -sS http://<master ip>:2381/healthon every master before taking this release. Clusters that have not done this keep working on 2379/mTLS only until they take this chart version.Not in this PR
kubeEtcd.serviceMonitorcert file fields.MaxUnavailableStatefulSet, which can leavepodManagementPolicy: ParallelStatefulSets (Prometheus, Alertmanager, openbao) stuck mid-rollout (kubernetes#137409, reverted in #137926).Supersedes Renovate PRs #1453, #1460, #1342, #1439, #1484, #1487, #1497, #1476 and most of #1463. Those can be closed once this merges; Renovate will recreate any that are still relevant.
Verification (local, helm 3.20.2,
--kube-version 1.35.0)helm lint . -f ci/values.yaml: clean.hack/check-no-crds.sh: 32 child sources rendered at their new versions, 0 CRDs. This includes Traefik 41.x schema validation and the external-secrets/openbao OCI pulls.annotationPrefixparameter.appchart (all 11 uses): identical apart from chart labels and image tags.:8081readinesscontainerPort. The webhook useshostNetwork, so the scheduler now counts 8081 as a host port. It was already bound before.appProtocol: HTTPSon Services and aRuntimeDefaultseccomp profile.podManagementPolicy: Parallelstays pinned.tokenrequestRole. The metrics Service port is renamed tohttp-metrics(still 9402), and ServiceMonitorjobLabelbecomesapp.kubernetes.io/name.dnsendpointsCRD is unchanged, andpolicyis now a required value (already set).🤖 Generated with Claude Code
https://claude.ai/code/session_01SW6t6HkN3k4wYusAkQ55eS
EDIT (2026-09-17) — updated after the component-by-component review. Changes since the original description, all merged into this branch as follow-up PRs:
dockerhub.repo.gpkg.ioappchart: deadimage.pullPolicy/replicaCountkeys removed; qr-code-generatordeployment.replicas: 2container_images;global.image.registrykeptimageRegistryfrombase_registries+ per-imagetag@digest(digest pin now enforced)webhook.portand stale CRDignoreDifferencesremovedautopilot.min_quorum5 → 3service.typemoved underservice.specAlso reflected above: the component table, the values-changes list, the platform-crds prerequisite (now GlueOps/platform-crds#83, including VPA 1.7.1 and the traefik 41.6.0 pin), and the removal of VPA from "Not in this PR". Per-component review notes with the upstream summaries, render diffs and test results are in the comments below. Note: commit 0043e56 on this branch also changes the kubeadm etcd scrape in
application-kube-prometheus-stack.yaml(port 2379 with mTLS → 2381,etcd-client-certsmount removed); the "monitoring files untouched" statement above predates it. This is the platform-side half of the gluekube etcd-metrics migration (its steps 4 and 5: repoint the serviceMonitor, drop the leftover secret) and is now written up as rollout prerequisite 5 above. A follow-up commit drops thekubeadm.kube_etcd.serviceMonitorvalues that hunk orphaned; the chart render is unchanged.