Update k8s.io dependencies

This MR contains the following updates:

Package Type Update Change
k8s.io/api require patch v0.36.2 -> v0.36.3
k8s.io/apimachinery require patch v0.36.2 -> v0.36.3
k8s.io/client-go require patch v0.36.2 -> v0.36.3
k8s.io/kubectl require patch v0.36.2 -> v0.36.3
sigs.k8s.io/gateway-api require minor v1.5.1 -> v1.6.1

MR created with the help of gitlab-org/frontend/renovate-gitlab-bot


Release Notes

kubernetes/api (k8s.io/api)

v0.36.3

Compare Source

kubernetes/apimachinery (k8s.io/apimachinery)

v0.36.3

Compare Source

kubernetes/client-go (k8s.io/client-go)

v0.36.3

Compare Source

kubernetes/kubectl (k8s.io/kubectl)

v0.36.3

Compare Source

kubernetes-sigs/gateway-api (sigs.k8s.io/gateway-api)

v1.6.1

Compare Source

v1.6.1

Major Changes Since v1.6.0

Test & Conformance
  • Change the port used in TCPRouteMultipleRoutesAttachment. (#​5053, @​davidjumani)
  • Respect CleanupTestResources for BackendTLSPolicy, TCPRouteMultipleRoutesAttachment and UDPRouteMultipleRoutesAttachment(#​5065, @​snorwin)
  • Fix SetupTimeoutConfig() not respecting defaults for ListenerSetMustHaveCondition, ListenerSetListenersMustHaveConditions, and RequiredConsecutiveSuccesses. (#​5066, @​immanuwell)
  • Honour tcpRouteMustHaveCondition and udpRouteMustHaveCondition timeouts which were silently ignore. (#​5067, @​immanuwell)
Other (Cleanup or Flake)
  • Fix GatewayStaticAddresses test flake by waiting for status.addresses to be published instead of assuming it appears atomically with Programmed. (#​5038, @​howardjohn)
  • Fix GatewayInfrastructure test flake by polling for generated infrastructure resources instead of assuming immediate visibility after the gateway is accepted. (#​5047, @​howardjohn)
  • Fix flaky TCPRouteWeightedRouting and UDPRouteWeightedRouting conformance tests by adding a data-plane readiness check before performing weighted routing assertions. (#​5064, @​arybolovlev)

v1.6.0

Compare Source

v1.6.0

Changes Since v1.5.1

GEP & API Graduation
  • UDPRoute & TCPRoute Graduation:
    • UDPRoute has graduated to GA. We recommend using the "v1" API version with this API now. The "v1alpha2" version of this API is deprecated and will be removed in the future. (#​4923, @​zac-nixon)
    • TCPRoute has graduated to GA. We recommend using the "v1" API version with this API now. The "v1alpha2" version of this API is deprecated and will be removed in the future. (#​4920, @​zac-nixon)
  • GEP Status Updates:
Feature
  • API & Validation Enhancements:
    • API validation updated for HTTPRoute retries: retry.codes must now be unique and retry.attempts must be >= 1. (#​4907, @​snorwin)
    • Increase the number of allowed Certificate Authority references from 8 to 16. (#​4088, @​root30)
    • The TLSRoute CRD validation has been adjusted to allow up to 1024 hostnames and rules per TLSRoute resource. Operators must validate kube-apiserver, etcd and Gateway controller behavior with representative manifests prior to enabling the new limit in production. (#​4332, @​alexanderstephan)
    • BackendTLSPolicy now can be used in combination with other routes types. (#​4745, @​rikatz)
    • Allow the usage of up to 16 annotations on the gateway infrastructure object. (#​4707, @​wenisman)
  • Conformance Infrastructure:
    • Added conformance tests for UDPRoute (GEP-2645), a new GATEWAY-UDP conformance profile, a SupportTCPRoute feature, and a UDP/TCP echo server in echo-basic gated on UDP_ECHO_SERVER. (#​4861, @​zac-nixon)
  • Remove the idleTimeout field from the experimental SessionPersistence API. (#​4771, @​gcs278)
Documentation
Bug or Regression
  • IPv6 Support:
    • Fix GatewayFrontendClientCertificateValidationInsecureFallback, GatewayFrontendClientCertificateValidation, and GatewayFrontendInvalidDefaultClientCertificateValidation failing on IPv6 clusters. (#​4636, @​zirain)
    • Fix GatewayFrontendInvalidDefaultClientCertificateValidation failing on IPv6 clusters. (#​4629, @​zirain)
  • ValidatingAdmissionPolicy (VAP) Fixes:
    • Fixed an issue where the ValidatingAdmissionPolicy prevented experimental CRDs from being installed at all (instead of only when standard CRDs already exist). (#​4603, @​howardjohn)
    • Fixed the safe-upgrades ValidatingAdmissionPolicy to allow upgrades of experimental CRDs. (#​4557, @​snorwin)
  • CRD & Schema Validation:
    • Generated Gateway API CRD install manifests no longer include top-level CustomResourceDefinition status fields with invalid null values, fixing strict schema validation failures in tools such as kubeconform. (#​4712, @​MatteoFari)
    • Replace omitempty with omitzero for supportedKinds in ListenerStatus to preserve backward compatibility for controllers reconciling older Gateway API versions. (#​4551, @​snorwin)
  • API & Validation Fixes:
Test & Conformance
  • New Conformance Tests:
    • Add conformance test ListenerSetAllowedRoutesCrossNamespace which verifies that a ListenerSet only allows routes in its own namespace by default. (#​4841, @​asauber)
    • Added a conformance test covering the Gateway Accepted condition with reason ListenersNotValid and the Listener Accepted condition with reason UnsupportedProtocol. (#​4807, @​snorwin)
    • Added conformance test GatewayInvalidParametersRef that verifies a Gateway referencing an invalid parameters is rejected. (#​4808, @​snorwin)
    • Conformance: add ListenerSet tests for Route parentRef cases. (#​4912, @​asauber)
  • Test Machinery & Framework Updates:
    • Conformance: ExpectMirroredRequest now starts its log window before the requests are sent, so mirrors are not missed on high-latency data planes. (#​4952, @​lexfrei)
    • The default polling interval for conformance tests has been decreased. This can be modified by the new DefaultPollInterval. (#​4570, @​howardjohn)
    • The gRPC conformance request helper no longer closes a caller-supplied (injected) Options.GRPCClient; it closes only the DefaultClient it creates internally. This lets implementations reuse a custom gRPC client across requests. (#​4953, @​lexfrei)
  • Updates & Fixes to Existing Tests:
    • The conflicted=false condition is not required anymore in the listener status for non-conflicted listeners. (#​4642, @​zhaohuabing)
    • Fix TLSRoute conformance test to stop relying on self-signed certificates. (#​4930, @​rikatz)
    • Fixed MeshHTTPRoute307Redirect conformance test bug where the wrong manifest was used. (#​4806, @​jgreeer)
    • Update Gateway version to v1 in UDP conformance test. (#​4722, @​cnvergence)
    • Updated the TLSRoute conformance tests to allow FINs where previously RST was asserted. (#​4615, @​howardjohn)
    • conformance: add missing gateway-api/skip-this-for-readiness annotation to invalid gateways (#​5027, @​snorwin)
    • The GRPCRouteWeight conformance test now sends its distribution-sampling requests through the injectable Options.GRPCClient instead of a hardcoded DefaultClient, allowing implementations that supply a custom gRPC client to run it. (#​5004, @​lexfrei)
    • The HTTPRouteRequestPercentageMirror conformance test now derives its acceptance band from the binomial standard deviation instead of a flat ±15% relative tolerance, removing sampling-variance flakes at low mirror percentages. (#​5005, @​lexfrei)
    • Removed HTTPRoute retry tests with connection errors and backend timeouts (#​4994, @​snorwin)

What's Changed

New Contributors

Full Changelog: https://github.com/kubernetes-sigs/gateway-api/compare/v1.5.1...v1.6.0


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻️ Rebasing: Whenever MR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This MR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this MR, check this box

This MR has been generated by Renovate Bot.

Edited by GitLab Dependency Bot

Merge request reports

Loading