This repository has been archived by the owner on Feb 10, 2022. It is now read-only.
Releases: cloudfoundry-incubator/kubo-release
Releases · cloudfoundry-incubator/kubo-release
kubo-release 0.20.0
See CFCR Release notes page
kubo-release 0.19.0
See CFCR Release notes page
kubo-release 0.18.0
See CFCR Release notes page
kubo-release 0.17.0
See CFCR Release Notes page
kubo-release 0.16.0
See CFCR Release notes page
kubo-release 0.15.0
See CFCR Release notes page.
kubo-release 0.14.0
- Kubernetes v1.9.3 -- cloudfoundry-incubator/kubo-release#176.
- Flannel v0.10.0 -- cloudfoundry-incubator/kubo-release#169.
- BOSH DNS v0.2.0 -- cloudfoundry-incubator/kubo-deployment#261.
- GOVC v0.16.0.
- Golang v1.9.4.
- BOSH Stemcell v3541.4.
- CFCR can now be deployed on an environment paved by BBL -- story.
- Exposed OpenID authentication properties -- cloudfoundry-incubator/kubo-release#101.
logging-level
BOSH property can be used to control the logging level of kube-proxy -- cloudfoundry-incubator/kubo-release#163.- HTTP(s) Proxy BOSH properties will be used for Kubernetes interactions with the IaaS -- cloudfoundry-incubator/kubo-release#130.
- Nodes can now be deployed across multiple AZs on GCP -- story.
- Nodes get tagged appropriately by Kubernetes to ensure that workloads are properly spread across AZs.
- System workloads are now applied as part of the
apply-addons
BOSH errand -- story.- System workloads have been a cause of many deployment issues.
- Enabled the API server audit logs -- story.
- Audit logs can be disabled if the
kube-apiserver.enable_audit_logs
BOSH property is set tofalse
.
- Audit logs can be disabled if the
- Disabled the read-only port in the Kubelet -- story.
- Disabled cAdvisor in Kubelet -- story.
- Disabled the security context manipulation when privileged containers are off -- story.
- The API server will not try to fix malformed requests anymore for security reasons -- story.
- The API Server will clean up terminated pods more often to avoid running out of disk space -- story.
- The API server will unmount volumes of terminated pods for security reasons -- story.
- Most BOSH jobs switched to use BPM -- story.
- From the BPM readme: "[BPM] crucially provides a security barrier such that if one of the jobs on your machine is compromised then the incident is limited to just that job rather than all jobs on the same machine".
- OpenStack: Exposed
cloud-provider.openstack.ignore-volume-az
BOSH property for the OpenStack Cloud Provider -- cloudfoundry-incubator/kubo-release#166. - OpenStack: Exposed
region
BOSH variable for the OpenStack Cloud Provider -- cloudfoundry-incubator/kubo-deployment#262. - Fix: UAA credentials and vCenter passwords are now redacted in BOSH logs -- story.
- Fix: to ensure that workers will pick the correct node name during rolling upgrades -- cloudfoundry-incubator/kubo-release#170.
- Fix: to ensure that nodes get properly drained before they stop, in order to minimize workload downtime during a rolling upgrade -- story.
- vSphere Fix: vCenter password with special characters (
&
,#
, etc) can now be used with CFCR without breaking the deployment -- story. - Experimental: An ops-file can now be used in conjunction to the
kubo-deployment
in order to experiment with the multi-master setup -- story.
kubo-release 0.13.0
- Kubernetes 1.9.2 -- story and story.
- Flannel 0.9.1 -- story.
- RBAC as the default authorization mode.
- Support for VM power-offs and restarts -- story.
- Reliance on certain functionality provided by BOSH was causing restarting VMs to fail.
- Secure communications between system specs (Dashboard, Heapster and InfluxDB) -- story and story.
- Ability to configure the timeout for system specs -- story.
- The BOSH property is
kubernetes-system-specs.timeout-sec
and is set to 20 minutes by default.
- The BOSH property is
- Ability to update addon specs without experiencing API downtime -- story.
- Ability to get diagnostic information if a system pod fails to be applied -- story.
- Ability to have the default storage class be used in PVCs that do not specify a storage class -- story.
- Ability to rotate the Kubernetes API certificate -- story.
- Ability to use the syslog addon in a CFCR deployment -- story.
- Fix: to not print secrets in user-facing scripts -- story.
- Fix to not have more than one nodes go down during an upgrade -- story.
- vSphere Fix: to avoid a synchronization issue that was causing master to fail to start -- story.
- OpenStack Fix to have CFCR properly configure Kubernetes in order to communicate securely (TLS) to OpenStack -- cloudfoundry-incubator/kubo-release#156.
kubo-release 0.12.0
See CFCR Release notes page.
kubo-release 0.11.1
This version was cut by accident, due to a CI issue. We were intending to cut v0.12.0.