KOBIL SHIFT Operator Changelog
KOBIL Shift Operator Changelog 0.45.3
Changelog
All notable changes to this project will be documented in this file.
The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
Unreleased
[0.45.3] - 2026-08-26
Changed
- Auto-created release containing automated updates.
- Update container-images from 1.3.1 to 1.3.2.
- Update Shift Operator from 0.45.0 to 0.45.2.
- Update deploy-ci-cd-component from 0.14.0 to 0.14.1.
- Update ansible-operator-sdk from 0.7.4 to 0.7.5.
- Update common from 2.0.1 to 2.1.0.
- Patch for fixing vulnerability CVE-2026-11822
- Patch for fixing vulnerability CVE-2026-11824
[0.45.2] - 2026-08-24
Changed
- Auto-created release containing automated updates.
- Update dev-iac from 11.6.1 to 11.7.0.
- Update KS Chart Template from 0.24.2 to 0.25.0.
- Added vulnerabilities CVE-2026-33818, CVE-2026-56853, CVE-2026-56859, CVE-2026-56862, CVE-2026-56864 and CVE-2026-56865 to the CVE ignore list.
[0.45.1] - 2026-08-18
Changed
- Auto-created release containing automated updates.
- Update Shift Operator from 0.44.8 to 0.45.0.
- Update ansible-operator-sdk from 0.7.3 to 0.7.4.
- Patch for fixing vulnerability CVE-2026-3298
- Patch for fixing vulnerability CVE-2026-11940
- Patch for fixing vulnerability CVE-2026-11972
[0.45.0] - 2026-08-17
Added
-
Added an inventory of all resources deployed by each component to the
ServiceGroupstatus.Note: After updating the operator, wait until all
ServiceGroupresources reportReadybefore making further changes. This allows the operator to build a complete resource inventory during the first reconciliation after the update. Changes made before then may not be tracked.
Fixed
- Fixed resources not being removed when an enabled component no longer renders them. The operator now compares the previously deployed resource inventory with the current render and removes resources that are no longer part of the component.
[0.44.9] - 2026-08-17
Changed
- Auto-created release containing automated updates.
- Update Shift Operator from 0.44.7 to 0.44.8.
- Update deploy-ci-cd-component from 0.13.0 to 0.14.0.
- Added vulnerabilities CVE-2026-46600, GO-2026-5972, GO-2026-6088, GO-2026-6089 and GO-2026-6090 to the CVE ignore list.
[0.44.8] - 2026-08-14
Changed
- Auto-created release containing automated updates.
- Update helm-chart-build from 2.0.0 to 2.0.1.
- Update ansible-operator-sdk from 0.7.2 to 0.7.3.
- Update Shift Operator from 0.39.7 to 0.44.7.
- Update common from 1.2.0 to 2.0.1.
- Update shift from 0.273.0 to 0.275.0.
- Update container-images from 1.1.3 to 1.3.1.
- Update dev-iac from 11.6.0 to 11.6.1.
- Update KS Chart Template from 0.23.0 to 0.24.2.
- Update Helm from 4.2.3 to 4.2.4.
- Added vulnerabilities GHSA-fxhp-mv3v-67qp, GO-2026-5026 and GO-2026-5942 to the CVE ignore list.
[0.44.7] - 2026-08-05
Changed
- Auto-created release containing automated updates.
- Update helm-chart-build from 1.0.0 to 2.0.0.
- Update ansible-operator-sdk from 0.7.1 to 0.7.2.
- Patch for fixing vulnerability GHSA-g6cj-pr64-35w5
[0.44.6] - 2026-08-03
Changed
- Migrate to CI/CD components.
[0.44.5] - 2026-07-30
Changed
- Auto-created release containing automated updates.
- Update deploy-ci-cd-component from 0.12.1 to 0.13.0.
- Update ci-library from 27.30.0 to 27.31.0.
- Update shift from 0.272.0 to 0.273.0.
- Update ansible-operator-sdk from 0.7.0 to 0.7.1.
- Update ubi9-micro from 3.4.1 to 3.4.2.
- Patch for fixing vulnerability CVE-2026-54369
- Patch for fixing vulnerability GHSA-hrxh-6v49-42gf
- Patch for fixing vulnerability GHSA-w8p5-mx5w-cpqj
- Patch for fixing vulnerability GO-2026-5026
[0.44.4] - 2026-07-15
Changed
- Auto-created release containing automated updates.
- Update ci-library from 27.29.1 to 27.30.0.
- Update shift from 0.271.0 to 0.272.0.
- Update Helm from 4.2.2 to 4.2.3.
- Patch for fixing vulnerability CVE-2026-39822
[0.44.3] - 2026-07-10
Changed
- Auto-created release containing automated updates.
- Update ubi9-micro from 3.3.0 to 3.4.1.
- Update shift from 0.269.0 to 0.271.0.
- Update ci-library from 27.27.0 to 27.29.1.
- Update deploy-ci-cd-component from 0.12.0 to 0.12.1.
- Update Helm from 4.2.2 to 4.2.3.
- Update ansible-operator-sdk from 0.6.4 to 0.7.0.
- Patch for fixing vulnerability GO-2026-4918
- Patch for fixing vulnerability CVE-2026-3298
- Patch for fixing vulnerability GHSA-hfvc-g4fc-pqhx
- Patch for fixing vulnerability GHSA-mh2q-q3fh-2475
- Patch for fixing vulnerability GHSA-wf93-45jw-7689.
- Ignore helm vulnerability GO-2026-4970.
[0.44.2] - 2026-06-24
Changed
- Auto-created release containing automated updates.
- Update shift from 0.260.0 to 0.269.0.
- Update ansible-operator-sdk from 0.6.1 to 0.6.4.
- Update ubi9-micro from 3.2.0 to 3.3.0.
- Update ci-library from 27.25.0 to 27.27.0.
- Update dev-iac from 11.4.0 to 11.6.0.
- Patch for fixing vulnerability CVE-2026-7210
- Update Helm from 4.2.0 to 4.2.2.
- Added GO-2026-4918 and GO-2026-5026 to the CVE ignore list.
[0.44.1] - 2026-05-21
Fixed
- Fixed a regression introduced in version 0.40.0 that caused the operator to fail when a
ServiceGroupspecification contained double curly brackets ({{or}}). These were incorrectly interpreted as Ansible templates instead of plain string values. The issue was resolved by retrieving theServiceGroupspecifications explicitly from the Kubernetes API.
[0.44.0] - 2026-05-18
Changed
- Update shift from 0.252.0 to 0.260.0.
- Update ci-library from 27.22.0 to 27.25.0.
- Update deploy-ci-cd-component from 0.9.0 to 0.12.0.
- Update dev-iac from 11.2.0 to 11.4.0.
- Update Helm from 4.1.3 to 4.2.0.
- Update ansible-operator-sdk from 0.5.5 to 0.6.1.
- Patch for fixing vulnerability CVE-2026-27140
- Patch for fixing vulnerability CVE-2026-27143
- Patch for fixing vulnerability CVE-2026-27144
- Patch for fixing vulnerability CVE-2026-32280
- Patch for fixing vulnerability CVE-2026-32281
- Patch for fixing vulnerability CVE-2026-32283
- Patch for fixing vulnerability CVE-2026-33811
- Patch for fixing vulnerability CVE-2026-33814
- Patch for fixing vulnerability CVE-2026-39820
- Patch for fixing vulnerability CVE-2026-39836
- Patch for fixing vulnerability CVE-2026-42499
- Patch for fixing vulnerability CVE-2026-42501
- Patch for fixing vulnerability CVE-2026-4519
- Patch for fixing vulnerability GHSA-mf9v-mfxr-j63j
- Patch for fixing vulnerability GHSA-q5jf-9vfq-h4h7
- Patch for fixing vulnerability GHSA-qccp-gfcp-xxvc
- Patch for fixing vulnerability GHSA-vmx8-mqv2-9gmg
[0.43.3] - 2026-03-20
Changed
- Auto-created release containing automated updates.
- Update ansible-operator-sdk from 0.5.4 to 0.5.5.
- Update shift from 0.251.0 to 0.252.0.
- Update ci-library from 27.21.0 to 27.22.0.
- Patch for fixing vulnerability GHSA-jr27-m4p2-rc6r
- Patch for fixing vulnerability GHSA-p77j-4mvh-x3m3
[0.43.2] - 2026-03-12
Changed
- Auto-created release containing automated updates.
- Update ansible-operator-sdk from 0.5.3 to 0.5.4.
- Update shift from 0.250.0 to 0.251.0.
- Update Helm from 4.1.1 to 4.1.3.
- Patch for fixing vulnerability CVE-2026-25679
- Patch for fixing vulnerability CVE-2026-27142
[0.43.1] - 2026-03-10
Changed
- Auto-created release containing automated updates.
- Update dev-iac from 11.0.2 to 11.2.0.
- Update shift from 0.249.0 to 0.250.0.
- Update ansible-operator-sdk from 0.5.2 to 0.5.3.
- Patch for fixing vulnerability GHSA-9h8m-3fm2-qjrq
[0.43.0] - 2026-02-20
Fixed
-
Fixed an issue introduced in Shift Operator 0.40.0 where the field manager
Helmwas not removed during the migration from Helm-based installation to Kubernetes API–based installation. As a result, fields previously managed byHelmwere not properly released. This caused problems when removing fields from resources (for example, a key from a ConfigMap), because the field was still owned by theHelmfield manager and therefore was not deleted from the resource.During migration, all resources created by Shift Operator are fetched and updated. The operation may take several minutes, or up to approximately 15 minutes for large deployments.
Added
-
The status of migration steps performed by Shift Operator is now reflected in the
ServiceGroupstatus field. The following migrations are currently tracked:migrations:finalizer-remove: truehelm-manager-replace: truehelm-secrets-remove: true
[0.42.1] - 2026-02-20
Changed
- Auto-created release containing automated updates.
- Update shift from 0.248.0 to 0.249.0.
- Update ansible-operator-sdk from 0.5.1 to 0.5.2.
- Update ubi9-micro from 3.1.3 to 3.2.0.
- Update dev-iac from 11.0.0 to 11.0.2.
- Patch for fixing vulnerability CVE-2026-0861
[0.42.0] - 2026-02-11
Fixed
- Fixed a regression introduced in Shift Operator 0.40.0 that prevented components from being uninstalled after being removed from a ServiceGroup. For example, when disabling a component in Shift.
Changed
- Update shift from 0.247.0 to 0.248.0.
- Update dev-iac from 10.5.2 to 11.0.0.
- Update Helm from 4.1.0 to 4.1.1.
- Update ansible-operator-sdk from 0.4.4 to 0.5.1.
- Patch for fixing of vulnerabilities:
- CVE-2025-61732
- CVE-2025-58187
- CVE-2025-58188
- CVE-2025-61723
- CVE-2025-61725
- CVE-2025-61729
- CVE-2025-61731
- CVE-2025-61726
- GHSA-r6ph-v2qm-q3c2
[0.41.0] - 2026-02-06
Changed
- Update Helm from 4.0.1 to 4.1.0.
- Update dev-iac from 10.5.0 to 10.5.2.
- Ignored further CVEs:
CVE-2025-61731,CVE-2025-61726.
Fixed
- Wrong ServiceGroup readiness status when K8S Api is slower as first Operator check try. Extended pod filtering for service chart version label.
[0.40.1] - 2026-01-29
Changed
- Auto-created release containing automated updates.
- Update shift from 0.246.0 to 0.246.1.
- Update ansible-operator-sdk from 0.4.2 to 0.4.4.
- Patch for fixing vulnerability CVE-2025-15467
- Patch for fixing vulnerability CVE-2025-69419
[0.40.0] - 2026-01-22
Added
- Added support for executing the helm tests contained in the components deployed by the operator. This feature is disabled by default and can be enabled by setting
extraVars.helm.test.run: truein custom Shift operator values.yaml. When enabled, a ServiceGroup is only set toready: truewhen all tests for the components in that ServiceGroup pass. - Added support for OCI-based registries. See README Section 'Using an OCI-based registry for helm charts' for more information.
Changed
- Shift components are now installed by directly using the Kubernetes API rather than through the helm install command. The existing helm releases for the Shift components will be deleted automatically when updating to this version.
- Shift Operator no longer uses finalizers in the ServiceGroup resources. Existing finalizers will be removed when updating to this version.
- Patch for fixing vulnerabilities CVE-2025-22871, GHSA-hcg3-q754-cr77, CVE-2025-22874, GHSA-6v2p-p543-phr9, CVE-2025-4674, CVE-2025-47907, CVE-2025-8194, CVE-2025-13836, CVE-2025-6965, GHSA-2xpw-w6gg-jr37, GHSA-38jv-5279-wg99, GHSA-63vm-454h-vhhq, GHSA-gm62-xv2j-4w53, GHSA-pwhc-rpq9-4c8w, GHSA-58pv-8j8x-9vj2.
- Added the following CVEs to the CVE ignore list: CVE-2025-58187, CVE-2025-58188, CVE-2025-61723, CVE-2025-61725, CVE-2025-61729.
- Update Helm from 3.16.4 to 4.0.1.
- Update KS Chart Template from 0.16.0 to 0.23.0.
- Update shift from 0.230.0 to 0.246.0.
- Update deploy-ci-cd-component from 0.8.1 to 0.9.0.
- Update ci-library from 27.16.2 to 27.21.0.
- Update dev-iac from dev-iac-2-rc.71 to 10.5.0.
- Update ansible-operator-sdk from 0.2.2 to 0.4.2.
[0.39.7] - 2025-08-12
Changed
- Update dev-iac from dev-iac-2-rc.70 to dev-iac-2-rc.71.
- Update shift from 0.229.0 to 0.230.0.
- Update ansible-operator-sdk from 0.2.1 to 0.2.2.
- Add ignore reasons for:
[0.39.6] - 2025-08-04
Changed
- Patch for fixing vulnerability CVE-2025-6965
- Patch for fixing vulnerability CVE-2025-8194
- Update ansible-operator-sdk from 0.2.0 to 0.2.1.
- Update deploy-ci-cd-component from 0.8.0 to 0.8.1.
[0.39.5] - 2025-07-25
Changed
- Update dev-iac from dev-iac-2-rc.68 to dev-iac-2-rc.70.
- Update shift from 0.225.0 to 0.229.0.
- Update ci-library from 27.16.0 to 27.16.2.
- Add CVE GHSA-6v2p-p543-phr9 to the CVE ignore list.
- Update ansible-operator-sdk from 0.1.7 to 0.2.0.
[0.39.4] - 2025-06-25
Changed
- Update dev-iac from dev-iac-2-rc.67 to dev-iac-2-rc.68.
- Update ci-library from 27.15.3 to 27.16.0.
[0.39.3] - 2025-06-17
Changed
- Update shift from 0.221.0 to 0.225.0.
- Update dev-iac from dev-iac-2-rc.65 to dev-iac-2-rc.67.
- Added CVE-2025-22874 to ignore list.
- Update ansible-operator-sdk from 0.1.6 to 0.1.7.
[0.39.2] - 2025-06-12
Changed
- Update dev-iac from dev-iac-2-rc.64 to dev-iac-2-rc.65.
- Patch for fixing vulnerability CVE-2025-4802
- Update ubi9-micro from 3.1.1 to 3.1.3.
- Update ansible-operator-sdk from 0.1.5 to 0.1.6.
- Update shift from 0.220.0 to 0.221.0.
Fixed
- Finalizer fail when ServiceGroup is empty.
[0.39.1] - 2025-06-06
Changed
- Update ci-library from 27.14.0 to 27.15.3.
- Update dev-iac from dev-iac-2-rc.63 to dev-iac-2-rc.64.
- Update shift from 0.219.0 to 0.220.0.
- Patch for fixing vulnerability CVE-2025-4138
- Patch for fixing vulnerability CVE-2025-4330
- Patch for fixing vulnerability CVE-2025-4435
- Patch for fixing vulnerability CVE-2025-4517
- Update ansible-operator-sdk from 0.1.4 to 0.1.5.
[0.39.0] - 2025-05-21
Changed
- Added CVEs GHSA-hcg3-q754-cr77 and CVE-2025-22871 to the CVE ignore list.
- Update shift from 0.212.0 to 0.219.0.
- Update ci-library from 27.13.0 to 27.14.0.
- Update dev-iac from dev-iac-2-rc.61 to dev-iac-2-rc.63.
- Update ansible-operator-sdk from 0.1.1 to 0.1.4.
- Patch for fixing vulnerability CVE-2024-8176
- Patch for fixing vulnerability GHSA-5rjg-fvgr-3xxf
[0.38.1] - 2025-04-04
Changed
- Update dev-iac from dev-iac-2-rc.47 to dev-iac-2-rc.61.
- Update shift from 0.201.0 to 0.212.0.
- Update deploy-ci-cd-component from 0.7.0 to 0.8.0.
- Update ci-library from 27.8.1 to 27.13.0.
- Update ansible-operator-sdk image from
0.1.0to 0.1.1.
Fixed
- Failing operator when service group is empty
- Patch for fixing vulnerability CVE-2024-8176
[0.38.0] - 2025-02-25
Added
- Added packages tar, unzip, and gzip. These tools are required by the feature to override the version of ks-chart-template.
Changed
- Update ci-library from 27.8.1 to 27.9.0
[0.37.0] - 2025-02-18
Changed
- Update ansible-operator image to kobil custom ansible-operator-sdk image 0.1.0.
- Using buildah for building shift-operator image
[0.36.1] - 2025-02-07
Fixed
- The failure reason in the ServiceGroup status was not reset after resolving the issue. This only affected ServiceGroups with disabled readyness check.
[0.36.0] - 2025-01-22
Added
- Added support for optional ServiceGroup annotation
app.shift.kobil.com/chart-template-version. Set this annotation to override the version of ks-chart-template used by charts managed in a ServiceGroup.
Changed
- Update ansible-operator from v1.37.0 to v1.37.1.
- Update shift from 0.198.0 to 0.201.0.
- Update ci-library from 27.5.0 to 27.8.1.
- Update dev-iac from dev-iac-2-rc.46 to dev-iac-2-rc.47.
- Extended task names for all tasks.
[0.35.0] - 2025-01-02
Changed
- Update ci-library from 27.4.0 to 27.5.0.
- Update Jinja2 to 3.1.5 to resolve CVEs GHSA-gmj6-6f8f-6699 and GHSA-q2x7-8rv6-6q7h.
[0.34.0] - 2024-12-24
Changed
- Add vulnerability GHSA-w32m-9786-jp63 to the CVE ignore list.
- Patch for fixing vulnerabilities
- Update ansible-operator from v1.36.1 to v1.37.0.
- Update Helm from 3.16.3 to 3.16.4.
- Update shift from 0.197.1 to 0.198.0.
- Update dev-iac from dev-iac-2-rc.45 to dev-iac-2-rc.46.
[0.33.2] - 2024-12-16
Changed
- Add CVE GHSA-v778-237x-gjrc to the CVE ignore list.
- Patch for fixing vulnerability CVE-2024-12254
- Update shift from 0.196.0 to 0.197.1.
[0.33.1] - 2024-11-28
Changed
- Patch for fixing vulnerability CVE-2024-10963
- Update deploy-ci-cd-component from 0.6.0 to 0.7.0.
- Update dev-iac from dev-iac-2-rc.42 to dev-iac-2-rc.45.
- Update shift from 0.194.0 to 0.196.0.
- Update ci-library from 27.2.0 to 27.4.0.
[0.33.0] - 2024-11-20
Changed
- Update Helm from 3.16.1 to 3.16.3.
- Update ansible-operator from v1.35.0 to v1.36.1.
- Update ci-library from 26.13.0 to 27.2.0.
- Update dev-iac from dev-iac-2-rc.39 to dev-iac-2-rc.42.
- Update shift from 0.188.0 to 0.194.0.
- Patch for fixing vulnerability CVE-2024-3596
[0.32.0] - 2024-10-04
Changed
- Shift operator now waits until the uninstallation of helm releases is complete before proceeding to the update tasks.
- Helm releases that are not found during uninstallation are now ignored.
[0.31.1] - 2024-09-30
Changed
- Patch for fixing vulnerability CVE-2024-45491
- Patch for fixing vulnerability CVE-2024-6232
- Update shift operator from 0.30.1 to 0.31.0.
- Update shift from 0.185.0 to 0.188.0.
- Update ci-library from 26.12.0 to 26.13.0.
[0.31.0] - 2024-09-18
Changed
- Update helm from 3.15.3 to 3.16.1
- Add vulnerabilities CVE-2024-34156 and CVE-2024-34158 to the CVE ignore list.
- Update shift operator from 0.30.0 to 0.30.1.
- Update shift from 0.182.0 to 0.185.0.
- Update dev-iac from dev-iac-2-rc.37 to dev-iac-2-rc.39.
- Update ci-library from 26.11.0 to 26.12.0.
[0.30.1] - 2024-08-27
Changed
- Update shift from 0.29.0 to 0.30.0.
- Update shift from 0.180.0 to 0.182.0.
- Update dev-iac from dev-iac-2-rc.35 to dev-iac-2-rc.37.
- Patch for fixing vulnerability CVE-2024-6345
- Patch for fixing vulnerability CVE-2024-2398
[0.30.0] - 2024-08-15
Changed
- Update helm from 3.15.3 to 3.15.4
- This version patches vulnerability GHSA-v23v-6jw2-98fq.
- Update shift from 0.179.0 to 0.180.0.
- Update shift-operator from 0.28.2 to 0.29.0.
- Update ci-library from 26.5.0 to 26.11.0.
- Update dev-iac from dev-iac-2-rc.34 to dev-iac-2-rc.35.
[0.29.0] - 2024-07-22
Fixed
- Patch for fixing vulnerability GHSA-248v-346w-9cwc
- Patch for fixing vulnerability GHSA-cx63-2mw6-8hw5
Changed
- Update ansible-operator base image from v1.34.3 to v1.35.0.
- Update helm from 3.15.2 to 3.15.3
- Update shift-operator from 0.28.1 to 0.28.2.
- Update ci-library from 26.1.0 to 26.5.0.
- Update dev-iac from dev-iac-2-rc.32 to dev-iac-2-rc.34.
- Update shift from 0.178.0 to 0.179.0.
[0.28.2] - 2024-07-08
Changed
- Update ci-library from 25.4.0 to 26.1.0.
- Patch for fixing vulnerability CVE-2023-2953
[0.28.1] - 2024-06-20
Changed
- Update shift from 0.27.0 to 0.174.0.
- Patch for fixing vulnerability GHSA-gpvv-69j7-gwj8
- Patch for fixing vulnerability GHSA-r9hx-vwmv-q579
- Update dev-iac from dev-iac-2-rc.31 to dev-iac-2-rc.32.
- Update ci-library from 25.3.0 to 25.4.0.
- Patch for fixing vulnerability CVE-2024-24790
- operator-framework/ansible-operator base image
1.34.2to1.34.3 - helm
3.15.1to 3.15.2 - CVE Ingore List:
- GHSA-r53h-jv2g-vpx6 False Positive, fixed in helm since 3.14.2
[0.28.0] - 2024-06-12
Added
- Added jobs that collect the Kubernetes RBAC roles required by Shift operator and add them to the release atrifacts. The release artifact contains the following files:
role-shift-operator-deployment.yamlcontains the required permissions to deploy the Shift operator helm chart.role-shift-operator-runtime.yamlcontains the permissions required by Shift operator during runtime.
Fixed
- Fix CVE CVE-2024-25062
- The 2 false-positive CVEs findings GHSA-gpvv-69j7-gwj8 and GHSA-r9hx-vwmv-q579 are no longer present in the scan report after updating to the latest version of Grype.
Changed
- Update shift from 0.171.0 to 0.173.0.
- Update ci-library from 24.2.0 to 25.3.0.
- Update dev-iac from dev-iac-2-rc.26 to dev-iac-2-rc.31.
Removed
- Theoretical support for Kubernetes horizontal pod autoscaler was removed, since the Shift operator only supports one replica.
[0.27.0] - 2024-05-24
Security
- Update CVE ignore list
- Ignore CVEs GHSA-gpvv-69j7-gwj8 and GHSA-r9hx-vwmv-q579 found in Python 3.6. These are false positives. The Red Hat provided packages already contain fixes for these CVEs, see CVE-2022-40897 and CVE-2019-20916.
Fixed
- Fix CVE CVE-2024-2961
- Fix CVE GHSA-3ww4-gg4f-jr7f
- Fix CVE GHSA-6vqw-3v5j-54x4
Changed
- Update Helm from 3.14.4 to 3.15.1.
- Update ansible-operator base image from v1.34.1 to v1.34.2.
- Update ci-library from 24.0.0 to 24.2.0.
[0.26.0] - 2024-05-03
Security
- Update CVE ignore list
- Ignore CVEs GHSA-gpvv-69j7-gwj8 and GHSA-r9hx-vwmv-q579 found in Python 3.6. These are false positives. The Red Hat provided packages already contain fixes for these CVEs, see CVE-2022-40897 and CVE-2019-20916.
- Ignore CVE GHSA-3ww4-gg4f-jr7f because a fix in the Red Hat provided packages is not yet available. Red Hat classifies the severity of this CVE as 'moderate' due to a high attack complexity CVE-2023-50782.
- Ignore CVE GHSA-6vqw-3v5j-54x4 found in the python package
cryptographyas we depend on the upstream ansible operator image to include the fixed version. This image does not use PKCS#12 data and is therefore not affected.
Fixed
- Fixed an issue in the pod readiness check. Previously the pods belonging to a ServiceGroup where checked sequentially. Therfore, the default of 5 minutes for the readiness check were spent per pod and not per ServiceGroup. If all pods of a large ServiceGroup failed to become ready (e.g. due to configuration issues), this could easily add up to 50 minutes in which the Shift Operator was not reacting to changes in the ServiceGroup. The fix was to perform the readiness check in parallel for all pod of a ServiceGroup.
Changed
- Shift operator now uses Ansible Kubernetes modules instead of kubectl. The kubectl binary was removed which also removes CVE GHSA-hqxw-f8mx-cpmw.
- Update kubernetes.core ansible collection from 2.4.0 to 3.0.1.
- Update Helm from 3.14.3 to 3.14.4.
- Update ci-lib from 23.15.1 to 24.0.0
[0.25.1] - 2024-04-03
Fixed
- Fix CVE CVE-2024-26147.
Changed
- Update Helm from 3.14.0 to 3.14.3
- Update Kubectl from 1.27.10 to 1.27.11
[0.25.0] - 2024-03-04
Removed
- Breaking change: Remove the tasks for migrating old servicegroups names introduced in Shift operator version 0.11.0. Ensure that Shift operator version 0.11.0 or higher is running before updating to this version.
Security
- Update CVE ignore list
- Ignore CVE GHSA-hqxw-f8mx-cpmw found in Kubectl. The CVE describes a denial of service attack against an API endpoint of docker/distribution. Kubectl itself is not vulnerable.
- Ignore CVEs GHSA-gpvv-69j7-gwj8 and GHSA-r9hx-vwmv-q579 found in Python 3.6. These are false positives. The Red Hat provided packages already contain fixes for these CVEs, see CVE-2022-40897 and CVE-2019-20916.
- Ignore CVE GHSA-3ww4-gg4f-jr7f because a fix in the Red Hat provided packages is not yet available. Red Hat classifies the severity of this CVE as 'moderate' due to a high attack complexity CVE-2023-50782.
- Ignore CVE GHSA-6vqw-3v5j-54x4 found in the python package
cryptographyas we depend on the upstream ansible operator image to include the fixed version. This image does not use PKCS#12 data and is therefore not affected.
Changed
- Added
CHANGELOG.mdandREADME.mdfiles to chart package. - Improve log output. Prefix task names with the service group name. Remove redundant log lines for ansible task execution. Add helm debug logs in the 'install component package' and 'uninstall components' tasks to list the updated Kubernetes resources.
- Update ansible-operator base image from v1.34 to v1.34.1.
[0.24.1] - 2024-02-19
Security
- Update CVE ignore list
- Ignore CVE GHSA-hqxw-f8mx-cpmw found in Kubectl. The CVE describes a denial of service attack against an API endpoint of docker/distribution. Kubectl itself is not vulnerable.
- Ignore CVEs GHSA-gpvv-69j7-gwj8 and GHSA-r9hx-vwmv-q579 found in Python 3.6. These are false positives. The Red Hat provided packages already contain fixes for these CVEs, see CVE-2022-40897 and CVE-2019-20916.
- Ignore CVE GHSA-3ww4-gg4f-jr7f because a fix in the Red Hat provided packages is not yet available. Red Hat classifies the severity of this CVE as 'moderate' due to a high attack complexity CVE-2023-50782.
Fixed
- Fixed an issue that caused the additional CA certificates provided via values
trustedCerts.existingSecretName:ortrustedCerts.certsto be ignored.
[0.24.0] - 2024-02-05
Security
- Update CVE ignore list
- Ignore CVE GHSA-hqxw-f8mx-cpmw found in Kubectl. The CVE describes a denial of service attack against an API endpoint of docker/distribution. Kubectl itself is not vulnerable.
- Ignore CVEs GHSA-gpvv-69j7-gwj8 and GHSA-r9hx-vwmv-q579 found in Python 3.6. These are false positives. The Red Hat provided packages already contain fixes for these CVEs, see CVE-2022-40897 and CVE-2019-20916.
Fixed
- Fix CVE CVE-2024-0553.
- Fix CVE GHSA-m425-mq94-257g.
- Fix CVE CVE-2023-45285
Changed
- Update ansible-operator base image from v1.33 to v1.34.
- Updated ci-library from 23.7.0 to 23.8.1.
[0.23.0] - 2024-01-18
Fixed
- Fix CVE CVE-2023-7104.
Changed
- Update Helm from 3.13.3 to 3.14.0
- Update Kubectl from 1.27.9 to 1.27.10
- Updated ci-library from 23.5.0 to 23.7.0.
[0.22.0] - 2024-01-11
Changed
- Creation of required role and rolebinding for the Shift operator's service account can be disabled by setting value
rbac.create: false. When disabled, the role and rolebinding must be created manually. - Updated Kubectl from 1.27.8 to 1.27.9.
- Updated ci-library from 23.4.0 to 23.5.0.
Removed
- No longer used CRDs were removed:
- shift.kobil.com_asts.yaml
- shift.kobil.com_boilerplates.yaml
- shift.kobil.com_dashboards.yaml
- shift.kobil.com_idps.yaml
- shift.kobil.com_scps.yaml
- shift.kobil.com_smartdashboards.yaml
- shift.kobil.com_smartscreens.yaml
[0.21.0] - 2023-12-21
Added
- Added support for using http and https proxies when fetching chart packages from the chart repository. See README for details.
[0.20.0] - 2023-12-15
Security
- Update CVE ignore list
- Ignore CVE GHSA-hqxw-f8mx-cpmw found in Kubectl. The CVE describes a denial of service attack against an API endpoint of docker/distribution. Kubectl itself is not vulnerable.
- Ignore CVE GHSA-m425-mq94-257g found in the ansible-operator. The CVE describes a denial of service attack against http servers. This image does not run a http server and is therefore not affected.
- Ignore CVE CVE-2023-45285 found in Kubectl. The CVE describes an issue when using 'go get' to fetch modules with git suffix. This image does not use kubectl to fetch modules and is therefore not affected.
Changed
- Update ansible-operator base image from v1.32 to v1.33.
- Update Helm from 3.13.2 to 3.13.3
- Update ci-lib from 23.3.0 to 23.4.0
- Update ks-chart-template from 0.14.0 to 0.15.0
[0.19.0] - 2023-11-30
Security
- Update CVE ignore list
- Ignore CVE GHSA-hqxw-f8mx-cpmw found in Kubectl. The CVE describes a denial of service attack against an API endpoint of docker/distribution. Kubectl itself is not vulnerable.
- Ignore CVEs GHSA-m425-mq94-257g, GHSA-4374-p667-p6c8, and CVE-2023-44487 which describe a denial of service attack against http servers. This image does not run a http server and is therefore not affected.
- Ignore CVE CVE-2023-39323 which describes an attack that requires the
gobinary. This image doesn't contain go and is therefore not affected.
Changed
- Update Kubectl from 1.27.7 to 1.27.8
- Update Helm from 3.13.1 to 3.13.2
- Update ci-lib from 22.16.1 to 23.3.0
- Update ks-chart-template from 0.13.0 to 0.14.0
Fixed
- CVE GHSA-jfhm-5ghh-2f97 from Python package cryptography.
[0.18.0] - 2023-11-07
Security
- Update CVE ignore list
- Ignore CVE GHSA-hqxw-f8mx-cpmw which comes from Kubectl 1.27.6. The CVE describes a denial of service attack against an API endpoint of docker/distribution. Kubectl itself is not vulnerable.
- Ignore CVEs GHSA-m425-mq94-257g, GHSA-4374-p667-p6c8, CVE-2023-39325, and CVE-2023-44487 which describe a denial of service attack against http servers. This image does not run a http server and is therefore not affected.
- Ignore CVE CVE-2023-39323 which describes an attack that required the
gobinary. This image doesn't contain go and is therefore not affected.
Added
- Add option to configure the path prefix for fetching helm charts. Configured using value
helmRepo.path. The default ("/charts/") assumes that charts are hosted using chart museum. Change this value as required if charts are hosted by a different helm repository, e.g. Nexus. See README for details.
Changed
- Update Kubectl from 1.27.6 to 1.27.7
- Update Helm from 3.13.0 to 3.13.1
- Update ci-lib from 22.11.1 to 22.16.1
- Update ks-chart-template from 0.12.0 to 0.13.0
[0.17.1] - 2023-10-20
Fixed
- Fixed CVE-2023-44487
Changed
- Update ci-lib from 22.11.0 to 22.11.1
[0.17.0] - 2023-10-18
Security
- Fixes GHSA-v845-jxx5-vc9f CVE-2023-43804
Changed
- migrate to docker multiarch jobs
[0.16.0] - 2023-10-09
Changed
- Update ansible-operator base image from v1.31 to v1.32.
- Update Helm from 3.12.3 to 3.13.0
Fixed
- CVE CVE-2023-4911
- CVE GHSA-232p-vwff-86mp
[0.15.0] - 2023-09-26
Changed
- Update CVE ignore list
- Ignore CVE GHSA-232p-vwff-86mp which comes from Helm 3.12.3. According to the helm maintainers, this is a false positive
- Ignore CVE GHSA-hqxw-f8mx-cpmw which comes from Kubectl 1.27.6. The CVE describes a denial of service attack against an API endpoint of docker/distribution. Kubectl itself is not vulnerable.
- Update Kubectl from 1.27.4 to 1.27.6
- Update Helm from 3.12.2 to 3.12.3
- Update ci-lib from 21.2.0 to 22.10.0
- Update ks-chart-template from 0.9.1 to 0.12.0
Removed
- Removed support for no longer used custom resource definitions (CRD)
asts.shift.kobil.com,boilerplates.shift.kobil.com,dashboards.shift.kobil.com,idps.shift.kobil.com,scps.shift.kobil.com,smartdashboards.shift.kobil.com,smartscreens.shift.kobil.com. The only supported CRD isservicegroups.shift.kobil.com.
Fixed
- Removed CVEs CVE-2023-2603 CVE-2023-29491 CVE-2023-30630 CVE-2023-3899.
[0.14.0] - 2023-08-02
Fixed
- Fixed an issue in the readiness check for Servicegroups. Previously, Servicegroups were falsely marked as ready if pods were in state Pending.
Changed
- Update ci-lib from 19.3.0 to 21.2.0 and add 'deploys' pipeline from dev-iac-2-rc.6.
- Update ansible-operator base image from v1.28 to v1.31.
- Update helm from 3.10.0 to 3.12.2.
- Update kubectl from 1.24.6 to 1.27.4.
[0.13.0] - 2023-04-28
Changed
- Improves error handling of shift operator if non-existing chart version is used in servicegroup
- CI-library ref updated to 19.3.0
- Ansible-operator base image updated to v1.28
- Update ks-chart-template-common from 0.9.0 to 0.9.1
Fixed
- 401 requests from shift operator to charts museum:
force_basic_authtotruefor get_url module, so that ansible doesn't try to request without basic auth.
[0.12.0] - 2023-03-10
Added
- Operational notes concerning resource usage to README.md.
Changed
- Helm charts are now fetched using ansible module
url_get. Thehelmcommand is only used for installing of fetched chart packages. This significantly reduces ephemeral storage usage of the shift operator pod. This also reduces memory usage. - update ks-chart-template-common from 0.7.0 to 0.8.0.
[0.11.0] - 2023-02-07
Changed
- The operator now truncates helm release name prefixes if the annotation
app.shift.kobil.com/release-prefixis available. This avoids conflicts when using long release names for the shift helm release. - Simplify the required escaping of special characters when passing values via valuesOverride in custom resources.
- ci-library ref updated to 16.6.0
- ansible-operator base image updated to v1.27
- Updated ignored CVE list to GHSA-2pfh-q76x-gwvm GHSA-6j58-grhv-2769 GHSA-wwch-cmqr-hhrm GHSA-cpx3-93w7-457x GHSA-r9hx-vwmv-q579.
[0.10.0] - 2022-12-20
Changed
- common chart template version updated to 0.7.0
- ci-library ref updated to 14.7.1
- ansible-operator base image updated to v1.26
Fixed
- Wrong truncation of helm release name. Previously trailing dashes were not removed from the truncated release name.
[0.9.0] - 2022-10-17
Added
-
Support for deploying the same helm chart multiple times. The keys under ServiceGroup's
spec.define the chart 'alias' and the name of the chart to deploy is taken from valuespec.{alias}.chart. If no valuechartis specified, the alias is used as chart name. For example:spec:internal:chart: proxyexternal:chart: proxydeploys chart 'proxy' two times with alias 'internal' and 'external', whereas
spec:proxy:deploys chart 'proxy' with alias 'proxy'.
Changed
- base image ansible-operator updated to v1.24
[0.8.0] - 2022-09-30
Added
- Feature to optionally skip status check of ServiceGroups. To use this feature, add label
app.kubernetes.io/readycheck: "false"to the ServiceGroup resource.
Changed
- update
ks-chart-template-commonto 0.4.0 - update
ci-libraryto 13.4.1 - update base image to
quay.io/operator-framework/ansible-operator:v1.23.0 - update helm to 3.10.0
- update kubectl to 1.24.6
[0.7.0] - 2022-07-07
Changed
- service chart will be uninstalled by disabling or deleting from the servicegroup CR.
- ci-lib ref to 10.6.1
- ansible-operator base image to v1.22
[0.6.0] - 2022-06-27
Added
- Failure reporting within status of servicegroup CRs. Can be checked with
kubectl describe servicegroup - Values
ansible.extraVars:in helm chart to provide additional configuration to Ansible via the--extra-varsparameter.
Fixed
- Fixed a bug that caused the
Getting pods statustask to succeed when a pod was stuck in pending. This was achieved by additionally checking that pod's status list is not empty.
[0.5.0] - 2022-06-14
Added
- CRD
servicegroupas a common type to replace old CRDs. kubectl v1.24.0tool into the docker image- Information about components deployed as part of a CRD can be listed with
kubectl get servicegroup
Changed
- Refactored logic for determining status of CRD. A CRD is now considered ready if all its pods are either running and ready or completed. This allows the helm flags
--wait --timeout 15m0sto be removed for install and uninstall logic. - helm chart refactored for using common chart template
- Base image upgraded to ansible-operator:v1.21
- Old CDRs are marked as
deprecated - The default
manageStatusof CRDs is set tofalse. The status is managed by install logic.
[0.4.1] - 2022-02-02
Changed
- built in waiting into helm uninstall command
- ignoring fails on chart uninstall
[0.4.0] - 2022-01-31
Added
- Helm chart value for ansible verbosity
ansible.verbosityLevelwith default0.
Changed
- Increase async time limit of helm install task to 20 minutes to avoid potential race conditions with long lasting deployments.
- Increase retries of check install status task to 120.
- Added
GHSA-q2q7-5pp4-w6pg,GHSA-qc9x-gjcv-465wto ignored CVES. - Update pipeline to 6.0.0
[0.3.0]
Added
- maverickboilerplate CRD
- serviceMonitor manifest for the shift operator's metrics
Changed
- ansible-operator docker image updated to v1.15
[0.2.0]
Added
- handling of valuesOverride values block
[0.1.0]
Added
- initial shift operator implementation
- Ignored CVES:
CVE-2016-1905 CVE-2016-1906 CVE-2016-7075 CVE-2021-33503 GHSA-2pfh-q76x-gwvm GHSA-q2q7-5pp4-w6pg