v1.35.10
Cloud Provider Azure v1.35.10
Full Changelog: v1.35.9..v1.35.10
Urgent Upgrade Notes
(No, really, you MUST read this before you upgrade)
- [BREAKING CHANGE] Load balancer reconciliation now validates public IP resource group annotations, internal subnet annotations for internal Services, and, when Private Link Service is requested, its resource group, name, and subnet annotations against Azure’s documented naming rules. Surrounding whitespace in subnet annotation values is trimmed. correct annotation values that do not meet these rules. Affected Services will fail create/update reconciliation until corrected. (#11042, @Liunardy)
- [BREAKING CHANGE] fix: a Service whose
service.beta.kubernetes.io/azure-pls-namematches a private link service already in use is now rejected, instead of repointing that private link service to the new Service. correct the annotation on any PLS-enabled Service reporting SyncLoadBalancerFailed after upgrade. (#11000, @Liunardy) - [BREAKING CHANGE] fix: reject LoadBalancer Services that list a managed load balancer frontend IP in the
service.beta.kubernetes.io/azure-additional-public-ipsannotation. The annotation remains supported for IPs outside managed frontends, such as Azure Global-tier public IPs. remove managed frontend IPs from this annotation. (#11083, @Liunardy)
Changes by Kind
Bug or Regression
- Fix: keep the deny-all NSG rule intact for Services using
azure-deny-all-except-load-balancer-source-rangeswhen another Service sharing one of its destinations is reconciled or deleted. Previously that destination could be dropped from the rule, leaving the Service reachable from anywhere in the virtual network rather than only its configured source ranges. fix: stop adding NSG rules for an IP family the Service does not serve. A single-stack Service with the floating IP disabled no longer gets rules for the other family’s node addresses, and any such rule already in the security group is removed the next time the Service is reconciled. (#11096, @Liunardy) - Fix: preserve full registry hostnames in the ACR credential provider’s cloud-suffix fallback. (#11082, @Liunardy)
Dependencies
Added
Nothing has changed.
Changed
- github.com/grpc-ecosystem/grpc-gateway/v2: v2.27.2 → v2.29.0
- go.opentelemetry.io/otel/exporters/otlp/otlptrace: v1.37.0 → v1.45.0
- go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc: v1.37.0 → v1.45.0
- go.opentelemetry.io/proto/otlp: v1.7.1 → v1.11.0
- golang.org/x/mod: v0.38.0 → v0.41.0
- golang.org/x/sync: v0.22.0 → v0.23.0
- golang.org/x/sys: v0.47.0 → v0.48.0
- golang.org/x/text: v0.41.0 → v0.42.0
- golang.org/x/tools: v0.48.0 → v0.49.0
- google.golang.org/genproto/googleapis/api: 3dc84a4 → 6ac0973
- google.golang.org/genproto/googleapis/rpc: 3dc84a4 → 6ac0973
- k8s.io/api: v0.35.8 → v0.35.9
- k8s.io/apimachinery: v0.35.8 → v0.35.9
- k8s.io/apiserver: v0.35.8 → v0.35.9
- k8s.io/client-go: v0.35.8 → v0.35.9
- k8s.io/cloud-provider: v0.35.8 → v0.35.9
- k8s.io/component-base: v0.35.8 → v0.35.9
- k8s.io/component-helpers: v0.35.8 → v0.35.9
- k8s.io/controller-manager: v0.35.8 → v0.35.9
- k8s.io/cri-api: v0.35.8 → v0.35.9
- k8s.io/kms: v0.35.8 → v0.35.9
- k8s.io/kubelet: v0.35.8 → v0.35.9
Removed
Nothing has changed.