Commit Graph

2863 Commits

Author SHA1 Message Date
Ciprian Hacman 938656b5d5 Update containerd to v2.1.4 2025-08-02 18:09:53 +03:00
Ciprian Hacman e0e6dddb03 Update containerd to v1.7.28 2025-08-01 09:18:32 +03:00
Kubernetes Prow Robot 7ae0bae6fc
Merge pull request #17521 from mtulio/cloud-provider-aws-pull-1214
aws: added permissions to RW*TargetGroupAttributes to CCM
2025-07-29 13:48:26 -07:00
Kubernetes Prow Robot f28b11cd4b
Merge pull request #17519 from sats-23/sup-image-tag
Add support for passing image for nvidia-k8s-device-plugin
2025-07-29 06:42:27 -07:00
Marco Braga 04ce51ab56
feat/ccm-aws/gen: generated files by hack/update-expected.sh 2025-07-29 10:03:16 -03:00
Kubernetes Prow Robot dde2cfd792
Merge pull request #16593 from rsafonseca/containerd_ecr_mirrors
aws: Add support for using ECR as pull-through image cache
2025-07-29 04:02:01 -07:00
Marco Braga 1dffab2729
feat/ccm-aws: added permissions to RW*TargetGroupAttributes
Added permission to read and write/modify Target Group Attributes on
clusters of cloud-provider-aws (CCM) project.

The modify permission is conditional for targget clusters.

This permission is required to be able to test the new requirement,
modify target group attributes, through e2e CI clusters.

More information: https://github.com/kubernetes/cloud-provider-aws/pull/1214
Example of CI job without this permission:
https://prow.k8s.io/view/gs/kubernetes-ci-logs/pr-logs/pull/cloud-provider-aws/1214/pull-cloud-provider-aws-e2e/1948477553773645824
2025-07-28 17:31:42 -03:00
Rafael da Fonseca 1794614c19 Add support for using ECR as pull-through image cache
Signed-off-by: Rafael da Fonseca <rafael.fonseca@wildlifestudios.com>
2025-07-28 12:45:53 +01:00
Sathvik 98090bc10a Add support for passing image for nvidia-k8s-device-plugin 2025-07-27 17:22:47 +05:30
justinsb e3d6a9ae4a metal: don't set CCM external always for IPv6
While we do require CCM for IPv6, we should configure the appropriate CCM.
2025-07-26 20:01:12 -04:00
Peter Rifel c2ad571ecb
remove unnecessary error from function signature 2025-07-15 22:00:29 -05:00
Rafael da Fonseca afcac8bfe3 Upgrade node-local-dns from 1.23.0 to 1.26.0 2025-07-11 10:00:30 +01:00
Ciprian Hacman 97c631b05b Fix cloud-provider flag for K8s 1.31+ 2025-07-10 09:42:11 +03:00
Ciprian Hacman eff3d586be Fix role assignment for cluster resource group 2025-07-09 08:18:07 +03:00
Ciprian Hacman 3d9086163f
Release 1.33.0-beta.1 (#17475) 2025-07-05 04:29:25 -07:00
Ciprian Hacman 078a53096d hack/update-expected.sh 2025-07-04 09:09:17 +03:00
Ciprian Hacman 1016fd7fe3 Update etcd-manager to v3.0.20250704 2025-07-04 09:03:35 +03:00
Kubernetes Prow Robot 8502cca41e
Merge pull request #17434 from flopib/gce-mig-autoscaler-metadata
GCE: set node labels and taints as autoscaler env vars
2025-07-03 08:35:27 -07:00
Flo Piboubès d10c0c9847 Sort node labels before adding them to env vars 2025-07-03 11:27:05 +02:00
Peter Rifel 018723263e
Use GCP CCM release image 2025-07-02 21:39:34 -05:00
Kubernetes Prow Robot 2dbaf8c275
Merge pull request #17452 from hakman/etcd-ko-build
Update etcd-manager to v3.0.20250629
2025-06-29 09:48:29 -07:00
Ciprian Hacman 62c6b89140 hack/update-expected.sh 2025-06-29 17:11:57 +03:00
Ciprian Hacman 18126697e7 Mount ca-bundle on RHEL and AL2023 2025-06-29 17:09:51 +03:00
Ciprian Hacman 75361add0a hack/update-expected.sh 2025-06-29 14:44:24 +03:00
Ciprian Hacman 977527f06f Update etcd-manager to v3.0.20250629 2025-06-29 14:06:06 +03:00
Ciprian Hacman 0718c0dc69 hetzner: Update hetznercloud/hcloud-go to v2 2025-06-28 09:30:54 +03:00
Peter Rifel 9f7a75333a
Remove --register-schedulable kubelet flag in 1.34+ 2025-06-18 05:41:42 -07:00
Flo Piboubès eb6bc8544a Set node labels and taints as autoscaler env vars 2025-06-12 17:41:34 +02:00
Kubernetes Prow Robot 1c518ec1a9
Merge pull request #17411 from flopib/gce-tf-update-policy
Explicitly set update_policy on GCE instance group managers
2025-06-12 08:12:56 -07:00
AkiraFukushima b674f78c8e
Re-enable additionalSecurityGroups for bastion LB 2025-06-08 22:07:36 +09:00
Flo Piboubès b43c9cb583 Add required MinimalAction parameter to UpdatePolicy 2025-05-23 13:23:28 +02:00
Flo Piboubès 407fb1f501 Explicitly set update_policy on GCE instance group managers 2025-05-23 13:15:35 +02:00
Flo Piboubès ba01597a40 Fix a copy-paste error in GCE storageacl task 2025-05-22 12:21:47 +02:00
Flo Piboubès 51742b9268 GCE: keep track service account emails in IAM tasks
This avoids creation of duplicate IAM tasks for a single service
account.
2025-05-22 12:19:53 +02:00
Justin Santa Barbara a6c7599557
Release 1.33.0-alpha.1 (#17389) 2025-05-04 18:00:59 +03:00
Kubernetes Prow Robot 3fde56bb8e
Merge pull request #17358 from jValdron/gateway-api
Add support for Gateway API within Cilium
2025-04-30 08:20:00 -07:00
Jason Valdron eef68ba192 Add support for Gateway API within Cilium
Squashed commit of the following:
Update documentation and CRDs
Update pkg/model/components/cilium.go
Remove gateway API managed addon
Update CRDs
Fix RBAC and update docs
Fix up files that shouldn't of been touched
Remove namespace from cluster RBAC resources
2025-04-30 07:55:52 -03:00
Kubernetes Prow Robot f5f48d3771
Merge pull request #17378 from justinsb/need_value_labels_for_terraform
gce: set values for role labels
2025-04-28 08:13:54 -07:00
justinsb 65aba4e300 gce: use typed ServiceAccount in IAM tasks
This gives us an automatic dependency in our evaluation,
and lets us write out a dependency to terraform also.
2025-04-28 08:15:02 -04:00
justinsb 51a58f4bd0 gce: set values for role labels
This seems to be required to keep terraform from always recreating
the instancegroup configuration (though that is likely a TF bug)
2025-04-27 17:13:53 -04:00
Kubernetes Prow Robot 78d4757c18
Merge pull request #17354 from ameukam/admission-controllers
Enable more admission controllers
2025-04-26 22:51:24 -07:00
Ciprian Hacman 9a1c88c767 hack/update-expected.sh 2025-04-25 13:57:18 +03:00
Ciprian Hacman c55b23e5cd Update etcd to v3.5.21 2025-04-25 13:55:44 +03:00
runitmisra ca9d983591 feat: Added cni-exclusive setting for cilium 2025-04-18 15:27:21 +05:30
Arnaud Meukam 8a218c2da7
Enable more admission controllers
Enable admission controllers for:
 - ValidatingAdmissionPolicy
 - RuntimeClass

Signed-off-by: Arnaud Meukam <ameukam@gmail.com>
2025-04-14 15:09:04 +02:00
Peter Rifel d1e94fd0a9
Pin GCP CCM image to v32.2.4 2025-04-08 18:56:59 -05:00
justinsb 7dc29d29fd Do not include WarmPool in json for AutoscalingGroup task
This avoids a circular dependency.

I previously considered making the field private,
but this is roughly equivalent and less disruptive.

Co-authored-by: Peter Rifel <rifelpet@users.noreply.github.com>
2025-03-27 08:03:37 -04:00
Ciprian Hacman 940813ab55 Update Cilium to v1.16.7 2025-03-09 06:53:37 +02:00
Jim Barber bdc25ad0cc
Remove some default CPU limits
Remove the default CPU limits defined for the aws-iam-authentication and
node-problem-detector DaemonSets.

This makes them behave the same as the other `cpuLimit` parameters for
the cluster that also do not have defaults.

As it was previously set up, if an administrator does not want CPU
limits defined for these DaemonSets, there was no way to define that via
the cluster spec.
2025-02-28 08:09:06 +08:00
Peter Rifel 1f6ea4fc75
Remove cloud-config and cloud-provider from 1.33 apiserver 2025-02-19 19:12:23 -06:00