Update Kubernetes infrastructure updates #2
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "renovate/kubernetes-infrastructure-updates"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
2026.2.x→2026.5.xv2.8.5→v2.8.8v1.5.3→v1.5.5v1.8.3→v1.8.5v1.8.3→v1.8.4v1.8.2→v1.8.52.19.0→2.20.043.209.1→43.209.20.76.x→0.81.xRelease Notes
goauthentik/helm (authentik)
v2026.5.2Compare Source
authentik is an open-source Identity Provider focused on flexibility and versatility
What's Changed
Full Changelog: https://github.com/goauthentik/helm/compare/authentik-2026.5.0...authentik-2026.5.2
v2026.5.0Compare Source
authentik is an open-source Identity Provider focused on flexibility and versatility
See https://docs.goauthentik.io/releases/2026.5/
What's Changed
Full Changelog: https://github.com/goauthentik/helm/compare/authentik-2026.2.3...authentik-2026.5.0
fluxcd/flux2 (fluxcd/flux2)
v2.8.8Compare Source
Highlights
Flux v2.8.8 is a patch release that includes CVE fixes via go-git v5.19.1 (source-controller, image-automation-controller), reliability fixes in helm-controller and source-controller, the move of Helm back to upstream v4.2.0, support for GCP sovereign cloud artifact registries, and dependency updates. Users are encouraged to upgrade for the best experience.
ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.
Fixes:
crds/directory (helm-controller)Improvements:
Components changelog
CLI changelog
Full Changelog: https://github.com/fluxcd/flux2/compare/v2.8.7...v2.8.8
v2.8.7Compare Source
Highlights
Flux v2.8.7 is a patch release that includes a bug fix in kustomize-controller, a CVE fix in source-controller and image-automation-controller via go-git v5.19.0, and dependency updates. Users are encouraged to upgrade for the best experience.
ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.
Fixes:
kustomize.toolkit.fluxcd.io/ssa: IfNotPresentwhere non-namespaced resources were being deleted and recreated on each reconciliation (kustomize-controller)Improvements:
Components changelog
CLI changelog
Full Changelog: https://github.com/fluxcd/flux2/compare/v2.8.6...v2.8.7
v2.8.6Compare Source
Highlights
Flux v2.8.6 is a patch release that includes bug fixes and improvements across helm-controller, image-automation-controller, kustomize-controller, notification-controller, and source-controller. Users are encouraged to upgrade for the best experience.
ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.
Fixes:
audiencefield on the GCR Receiver secret for tighter verification — will become mandatory in Flux v2.9 (notification-controller)Improvements:
MigrateAPIVersionfeature gate for migrating the API version of resources in managed field entries (kustomize-controller)Components changelog
CLI changelog
Full Changelog: https://github.com/fluxcd/flux2/compare/v2.8.5...v2.8.6
fluxcd/helm-controller (ghcr.io/fluxcd/helm-controller)
v1.5.5Compare Source
Changelog
v1.5.5 changelog
Container images
docker.io/fluxcd/helm-controller:v1.5.5ghcr.io/fluxcd/helm-controller:v1.5.5Supported architectures:
linux/amd64,linux/arm64andlinux/arm/v7.The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the security documentation.
v1.5.4Compare Source
Changelog
v1.5.4 changelog
Container images
docker.io/fluxcd/helm-controller:v1.5.4ghcr.io/fluxcd/helm-controller:v1.5.4Supported architectures:
linux/amd64,linux/arm64andlinux/arm/v7.The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the security documentation.
fluxcd/kustomize-controller (ghcr.io/fluxcd/kustomize-controller)
v1.8.5Compare Source
Changelog
v1.8.5 changelog
Container images
docker.io/fluxcd/kustomize-controller:v1.8.5ghcr.io/fluxcd/kustomize-controller:v1.8.5Supported architectures:
linux/amd64,linux/arm64andlinux/arm/v7.The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the security documentation.
v1.8.4Compare Source
Changelog
v1.8.4 changelog
Container images
docker.io/fluxcd/kustomize-controller:v1.8.4ghcr.io/fluxcd/kustomize-controller:v1.8.4Supported architectures:
linux/amd64,linux/arm64andlinux/arm/v7.The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the security documentation.
fluxcd/notification-controller (ghcr.io/fluxcd/notification-controller)
v1.8.4Compare Source
Changelog
v1.8.4 changelog
Container images
docker.io/fluxcd/notification-controller:v1.8.4ghcr.io/fluxcd/notification-controller:v1.8.4Supported architectures:
linux/amd64,linux/arm64andlinux/arm/v7.The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the security documentation.
fluxcd/source-controller (ghcr.io/fluxcd/source-controller)
v1.8.5Compare Source
Changelog
v1.8.5 changelog
Container images
docker.io/fluxcd/source-controller:v1.8.5ghcr.io/fluxcd/source-controller:v1.8.5Supported architectures:
linux/amd64,linux/arm64andlinux/arm/v7.The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the security documentation.
v1.8.4Compare Source
Changelog
v1.8.4 changelog
Container images
docker.io/fluxcd/source-controller:v1.8.4ghcr.io/fluxcd/source-controller:v1.8.4Supported architectures:
linux/amd64,linux/arm64andlinux/arm/v7.The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the security documentation.
v1.8.3Compare Source
Changelog
v1.8.3 changelog
Container images
docker.io/fluxcd/source-controller:v1.8.3ghcr.io/fluxcd/source-controller:v1.8.3Supported architectures:
linux/amd64,linux/arm64andlinux/arm/v7.The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the security documentation.
kedacore/keda (keda)
v2.20.0Compare Source
New
scalingModifiersfallback behavior (#7366)Improvements
--leader-election-idflag to allow configuring the leader election Lease name (#7564)keda_scaler_http_requests_total,keda_scaler_http_request_duration_seconds) for outbound HTTP requests made during scaler metric collection (#6600)KEDA_HTTP_TLS_CIPHER_LIST,KEDA_SERVICE_TLS_CIPHER_LISTandKEDA_SERVICE_MIN_TLS_VERSIONenv vars (#7617)globalHTTPTimeoutsoScalersCache.Closecannot block indefinitely (#7574)json.MarshalIndentcalls from admission webhook validation hot paths; replace spec-comparisonMarshalIndent-and-string-compare inisRemovingFinalizervariants withreflect.DeepEqual. Prevents webhook OOM under sustained admission load at large scale (observed at ~60k ScaledObjects) (#7670)groupByNodeparameter (#7628)workerDeploymentNameandworkerDeploymentBuildIdfields. DeprecatebuildId,selectAllActive, andselectUnversionedbecause those parameters are used for Rules-Based Worker Versioning, which was a short-lived experimental feature that has been deprecated in the Temporal server since December 2024 and will stop being supported soon. Users of Rules-Based Worker Versioning should use Worker Deployments instead. (#7672)Fixes
GetMetricswhen the gRPC connection is in Shutdown state instead of waiting for context timeout (#7251)keda_scaler_activenot being emitted for CPU and memory triggers (#4945)ScaledObjectReadyTypeinstead ofScaledJobReadyType) when transitioning to ready state (#7792)verifyReplicaCount, preventing invalid ScaledObjects from being created (#5954)stderrthresholdwhenlogtostderris enabled by updating klog to v2.140.0 (#7568)Close()for SQS, Kinesis, DynamoDB, DynamoDB Streams, and CloudWatch scalers (#7756)unprocessedEventThresholdto prevent integer division by zero when computing lag (#7732)enableEtagsis on (#7685)authTokenoptional to support unauthenticated InfluxDB instances (#7616)serverAddressnow appends/loki/api/v1/queryto the end of existing path instead of overriding (#7648)aggregateFromKubeServiceEndpointsusing empty label selector that matched all EndpointSlices in the namespace instead of only the target service's (#7641)getMaxMsgLagwhen the configured consumer is missing instead of falling back to the stream's last sequence, preventing incorrect scale-up tomaxReplicaCount(#7657)dysnix/predictkube-libstov0.1.0(drops the predictkube path to the archived/EOLgo-grpc-prometheusand to the deprecatedgolang/protobuf) and use a portable Prometheus-API instant query for the health check so the scaler works against VictoriaMetrics, Thanos and other Prometheus-API-compatible backends (#7745)Deprecations
You can find all deprecations in this overview and join the discussion here.
Breaking Changes
subscriptionSizesetting is DEPRECATED and is removed in v2.20 - Usemodeandvalueinstead (#7720)minMetricValuesetting is DEPRECATED and is removed - UseactivationTargetMetricValueinstead (#7436)tlssetting code is removed (#6094)authTokensetting fromtriggerMetadatais DEPRECATED and is removed in v2.20 - UseauthTokenfromresolvedEnvorauthParamsinstead (#7722)Other
eventstoevents.k8s.io(#7781)authModesfield from ArangoDB, Loki, Prometheus and PredictKube scalers (#7726)TestWaitForStatecausing flaky test under-racedetector (#7542)credentialsFromJSONwithcredentialsFromJSONWithType(#7523)renovatebot/renovate (renovate/renovate)
v43.209.2Compare Source
Bug Fixes
VictoriaMetrics/helm-charts (victoria-metrics-k8s-stack)
v0.81.0Compare Source
Release notes for version 0.81.0
Release date: 28 May 2026
Update note 1:
defaultRules.createis renamed todefaultRules.enabled; per-groupcreateis renamed toenabled. Oldcreatekey is still respected as a fallback ifenabledis not set.Update note 2:
defaultRules.additionalGroupByLabelsis renamed todefaultRules.extraGroupByLabels. OldadditionalGroupByLabelsis still respected as a fallback ifextraGroupByLabelsis not set.defaultRules.createand per-groupcreatetoenabled, with fallback tocreatefor backward compatibility.v0.80.0Compare Source
Release notes for version 0.80.0
Release date: 25 May 2026
v0.79.1Compare Source
Release notes for version 0.79.1
Release date: 20 May 2026
v0.79.0Compare Source
Release notes for version 0.79.0
Release date: 18 May 2026
v0.78.0Compare Source
Release notes for version 0.78.0
Release date: 11 May 2026
v0.77.0Compare Source
Release notes for version 0.77.0
Release date: 03 May 2026
admissionWebhooks.policytoIgnoreso the stack can be installed and upgraded in a single pass without races against the operator's webhook server. Override toFailfor strict validation. See #2874.Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate.