Catalog / Kubernetes

1.36.0

6 months agobreakingaddedfixedOriginal notes

Changelog since v1.35.0

Urgent Upgrade Notes

(No, really, you MUST read this before you upgrade)

  • ACTION REQUIRED: kube-controller-manager: Renamed metric volume_operation_total_errors to volume_operation_errors_total. If you are using custom monitoring dashboards or alerting rules based on the volume_operation_total_errors metric, update them to use the new volume_operation_errors_total metric. (#136399, @tico88612) [SIG Apps, Instrumentation, Storage and Testing]
  • Added support for running PreBind plugins in parallel in the scheduler framework to improve binding latency. ACTION REQUIRED: Plugins can opt-in to parallel execution by returning AllowParallel: true from the PreBindPreFlight method. PreBind plugin implementations need to be updated to return PreBindPreFlightResult from the PreBindPreFlight method; returning nil retains the existing sequential behavior. (#135393, @tosi3k) [SIG Node, Scheduling, Storage and Testing]

Changes by Kind

Dependency

  • Fixed a bug where pod lifecycle hooks could run for their full duration when pods are terminated. (#136598, @dgrisonnet) [SIG API Machinery, Auth, Cloud Provider, Node and Scheduling]
  • Updated etcd client library to v3.6.8. (#137225, @joshjms) [SIG API Machinery, Auth, Cloud Provider, Cluster Lifecycle, Etcd, Node, Scheduling and Testing]

Deprecation

  • Added warnings and deprecation for Service .spec.externalIPs. (#137293, @adrianmoisey) [SIG Apps, Network and Windows]
  • Direct access to the Raw field of metav1.FieldsV1 is deprecated. Code that constructs or reads FieldsV1 should migrate to the new NewFieldsV1(string), GetRawBytes(), GetRawString(), and SetRawBytes() accessor methods. (#137304, @aaron-prindle) [SIG API Machinery, Apps and Testing]
  • Disabled git-repo volume plugin by default, with no option to turn it back on. (#136400, @vinayakankugoyal) [SIG Storage]
  • Renamed AllowlistEntry.Name to AllowlistEntry.Command in the credential plugin allowlist. (#137272, @pmengelbert) [SIG API Machinery, Auth, CLI and Testing]

API Change

  • ACTION REQUIRED: DRA (Dynamic Resource Allocation) drivers and controllers now require granular RBAC permissions to update ResourceClaim statuses when the DRAResourceClaimGranularStatusAuthorization feature gate is enabled (beta in v1.36). Schedulers and controllers must be granted update/patch on resourceclaims/binding. DRA drivers must be granted associated-node:update or arbitrary-node:update (or patch equivalents) on resourceclaims/driver, restricted by their specific resourceNames. (#134947, @aojea) [SIG API Machinery, Apps, Auth, Instrumentation, Node, Scheduling and Testing]
  • ACTION REQUIRED: Removed the integrated support for flex-volumes in kubeadm. Users were advised to migrate away from flex-volumes as recommended by SIG Storage since v1.22. If kubeadm users wish to continue using the feature, they need a custom image for the KCM that is not based on distroless, pass the KCM flag --flex-volume-plugin-dir, and mount the directory /usr/libexec/kubernetes/kubelet-plugins/volume/exec in the KCM static pod using kubeadm's extraVolumes mechanism before upgrading to v1.36. Previously, kubeadm automatically did the mounting if the user passed the flag. (#136423, @neolit123) [SIG Cluster Lifecycle]
  • ACTION REQUIRED: Renamed metric etcd_bookmark_counts to etcd_bookmark_total. If you are using custom monitoring dashboards or alerting rules based on the etcd_bookmark_counts metric, update them to use the new etcd_bookmark_total metric. (#136483, @petern48) [SIG API Machinery, Etcd, Instrumentation and Testing]
  • Added SchedulingConstraints to express topology-aware scheduling (TAS) constraints for PodGroup scheduling behind the TopologyAwareWorkloadScheduling feature gate. Added the TopologyPlacement plugin implementing the PlacementGenerate extension point to take constraints into consideration during PodGroup scheduling. (#137271, @brejman) [SIG API Machinery, Apps, Auth, CLI, Cloud Provider, Etcd, Node, Scheduling and Testing]
  • Added DisruptionMode, PriorityClassName, and Priority fields to the Workload and PodGroup APIs to support workload-aware preemption when the WorkloadAwarePreemption feature gate is enabled. (#136589, @tosi3k) [SIG API Machinery, Apps, Auth, CLI, Cloud Provider, Etcd, Node, Scheduling and Testing]
  • Added ImageVolumeWithDigest which includes the digest of image volumes in the container status. (#132807, @iholder101) [SIG API Machinery, Apps, Node and Testing]
  • Added MemoryReservationPolicy cgroup v2 MemoryQoS support to KubeletConfiguration for memory.min protection. (#137584, @QiWang19) [SIG Node and Storage]
  • Added spec.stubPKCS10Request to the Pod Certificates beta API to improve compatibility with existing certificate authority implementations that expect a PKCS#10 certificate signing request. spec.pkixPublicKey and spec.proofOfPossession were deprecated in favor of this field. (#136729, @ahmedtd) [SIG API Machinery, Auth, Node and Testing]
  • Added a deletion protection mechanism for PodGroup objects. (#137641, @helayoty) [SIG API Machinery, Apps, Auth, Scheduling and Storage]
  • Added alpha support (behind the PersistentVolumeClaimUnusedSinceTime feature gate) for tracking PersistentVolumeClaim unused status via a new Unused condition on PersistentVolumeClaimStatus. When enabled, the PVC protection controller sets Unused=True with a lastTransitionTime when no non-terminal Pods reference the PersistentVolumeClaim. (#137862, @gnufied) [SIG Apps, Auth, Storage and Testing]
  • Added alpha support for manifest-based admission control configuration (KEP-5793). When the ManifestBasedAdmissionControlConfig feature gate is enabled, admission webhooks and CEL-based policies can be loaded from static manifest files on disk via the staticManifestsDir field in AdmissionConfiguration. These policies are active from API server startup, survive etcd unavailability, and can protect API-based admission resources from modification. (#137346, @aramase) [SIG API Machinery, Apps, Architecture, Auth, Autoscaling, CLI, Cloud Provider, Cluster Lifecycle, Instrumentation, Network, Node, Release, Scheduling, Storage, Testing and Windows]
  • Added an admission plugin that validates PodGroup resources reference an existing Workload and match the declared PodGroupTemplate spec. (#137464, @helayoty) [SIG API Machinery, Apps, Auth, CLI, Cloud Provider, Etcd, Node, Scheduling and Testing]
  • Added list-type support for attributes in DRA (KEP-5491). The DRAListTypeAttributes feature gate (disabled by default) activates the following enhancements:
    • DRA drivers can use list-type fields (bools/ints/strings/versions) for device attributes in ResourceSlice. The number of attribute values, including scalars and lists, per single device is limited to 48.
    • The matchAttribute/distinctAttribute constraints in ResourceClaim now work on both scalar and list attributes. The matchAttribute constraint matches when the intersection of all list values among candidate devices is non-empty. The distinctAttribute constraint (behind the ConsumableCapacity feature gate) matches when all list values among candidate devices are pairwise disjoint. Scalar values are implicitly treated as a singleton set.
    • Added a new CEL function .includes that works on both scalar and list attributes to test inclusion (e.g., device.attributes["dra.example.com"].model.includes("model-a")), supporting migration when a DRA driver changes an attribute value type from scalar to list or vice versa. (#137190, @everpeace) [SIG API Machinery, Node, Scheduling and Testing]
  • Added new concurrent-node-status-updates flag that is split from the concurrent-node-syncs flag. (#136716, @yonizxz) [SIG Cloud Provider]
  • Added opt-in alpha support in the kubeletplugin framework for DRA drivers to publish DRA Device metadata in Pod CDI mounts. (#137086, @alaypatel07) [SIG Apps, Network, Node and Testing]
  • Added opt-in scheduling behavior for CSI volumes. (#137343, @gnufied) [SIG API Machinery, Scheduling and Storage]
  • Added placement-based PodGroup scheduling algorithm to the scheduler. Its use is guarded by the TopologyAwareWorkloadScheduling feature gate. (#136944, @brejman) [SIG Scheduling and Testing]
  • Added stability-based lifecycle for declarative validation (Alpha/Beta/Stable). Scheduling Workload v1alpha1 now uses explicit declarative enforcement. (#136793, @yongruilin) [SIG API Machinery and Scheduling]
  • Added the PlacementGenerate extension point to the scheduler. It is used to generate placements for placement-based PodGroup scheduling. Its use is guarded by the TopologyAwareWorkloadScheduling feature gate. (#137083, @brejman) [SIG Scheduling]
  • Added the PlacementScore extension point to the scheduler for scoring placements in placement-based PodGroup scheduling, guarded by the TopologyAwareWorkloadScheduling feature gate. Deprecated MinNodeScore and MaxNodeScore in favor of MinScore and MaxScore. (#137201, @brejman) [SIG Scheduling]
  • Added the ResourcePoolStatusRequest API (v1alpha1) for querying DRA resource pool availability. External schedulers can discover available devices across pools before submitting workloads. Requires the DRAResourcePoolStatus feature gate (alpha). (#137028, @nmn3m) [SIG API Machinery, Apps, Auth, Etcd, Instrumentation, Node, Scheduling, Storage and Testing]
  • Added the --concurrent-resourceclaim-syncs flag to kube-controller-manager to configure ResourceClaim reconcile concurrency. (#134701, @anson627) [SIG API Machinery, Apps, Node and Testing]
  • Added the --tls-curve-preferences flag for configuring TLS key exchange mechanism. (#137115, @damdo) [SIG API Machinery, Architecture, CLI, Cloud Provider, Node and Testing]
  • Added the PodGroupPodsCount scheduler plugin to support workload-aware scheduling by prioritizing placements with higher Pod counts within a group. (#137488, @vshkrabkov) [SIG Scheduling and Testing]
  • Added the tlsServerName field to EgressSelectorConfiguration TLSConfig to allow overriding the server name used for TLS certificate verification. (#136640, @kennangaibel) [SIG API Machinery, Apps, Auth, Storage and Testing]
  • Added the alpha DRANodeAllocatableResources feature, which introduces a new ResourceSlice.Spec.Devices[*].NodeAllocatableResourceMappings field for DRA drivers to declare how device resources map to node allocatable Kubernetes resources (e.g., cpu, memory).(#136725, @pravk03) [SIG API Machinery, Apps, Node, Scheduling and Testing]
  • Added topology-aware scheduling (TAS) logic to the PodGroup scheduling cycle behind the TopologyAwareWorkloadScheduling feature gate, supporting scheduling of PodGroups on nodes with matching topology domains. (#137489, @brejman) [SIG API Machinery, Apps, Auth, CLI, Cloud Provider, Etcd, Node, Scheduling and Testing]
  • Added validation to prevent negative duration values for imageMinimumGCAge. (#135997, @ngopalak-redhat) [SIG API Machinery and Node]
  • Changed deprecated sets.String with sets.Set[string] in apiserver admission subsystem. This is a breaking change for consumers of the NewLifecycle function. (#134044, @mcallzbl) [SIG API Machinery and Auth]
  • Clarified documentation and comments to indicate that the cpuCFSQuotaPeriod kubelet config field requires the CustomCPUCFSQuotaPeriod feature gate when using non-default values. No functional changes introduced. (#133845, @rbiamru) [SIG Node and Release]
  • Corrected OpenAPI schema union validation for the PodGroupPolicy struct in scheduling.k8s.io/v1alpha1. (#136424, @JoelSpeed) [SIG API Machinery and Scheduling]
  • DRA DeviceTaintRules: the TimeAdded field of the taint is now automatically updated when changing the effect. (#137167, @pohly) [SIG API Machinery, Node and Testing]
  • DRA: Added a spec.resourceClaims field to PodGroup resources for referencing ResourceClaims and ResourceClaimTemplates. Claims made by a PodGroup are reserved for the entire PodGroup instead of individual Pods, supporting more than 256 Pods sharing a single ResourceClaim. ResourceClaimTemplates referenced by a PodGroup's claim replicate into a ResourceClaim specific to that PodGroup, shared by all of the group's Pods. (#136989, @nojnhuh) [SIG API Machinery, Apps, Auth, CLI, Cloud Provider, Etcd, Node, Scheduling and Testing]
  • DRA: Graduated Device Binding Conditions (KEP #5007) to beta, enabled by default in v1.36. (#137795, @ttsuuubasa) [SIG API Machinery, Node, Scheduling and Testing]
  • DRA: Graduated device taints and tolerations (KEP #5055) to beta. Support for DeviceTaints in ResourceSlices is on by default. Support for DeviceTaintRules depends on enabling resource.k8s.io/v1beta2 and the DeviceTaintRules feature gate. (#137170, @pohly) [SIG API Machinery, Apps, Auth, Cluster Lifecycle, Etcd, Node, Scheduling and Testing]
  • Extended NodeResourcesFit to implement the PlacementScore extension point. The usage of the PlacementScore extension point is guarded by the TopologyAwareWorkloadScheduling feature gate. (#136652, @brejman) [SIG Scheduling]
  • Fixed fake.NewClientset() to work properly with correct schema. (#131068, @soltysh) [SIG API Machinery]
  • Fixed a few log calls that did not properly format their parameters. (#137108, @pohly) [SIG API Machinery, Apps, Auth, Cluster Lifecycle, Network, Node, Scheduling and Testing]
  • Fixed a potential nil pointer dereference in the scheduler's NodeResourcesFitArgs validation when using RequestedToCapacityRatio scoring strategy. (#132120, @flpanbin) [SIG Scheduling]
  • Fixed an issue in kube-apiserver, allowing it to recover from an established connection to an incorrect server that never returns the expected response during APIService availability checks. (#137157, @bsalamat) [SIG API Machinery]
  • For Pod resizes requested on nodes where the resize request exceeds the node's allocatable capacity or the node is running an OS that does not support resize, the request fails in admission rather than being marked as Infeasible in the Pod status later. (#136043, @natasha41575) [SIG API Machinery, Node, Release, Scheduling, Storage and Testing]
  • Generated fake.NewClientset which replaces the deprecated NewSimpleClientset for kube-aggregator and sample-apiserver. (#136537, @soltysh) [SIG API Machinery]
  • Graduated metric apiserver_storage_events_received_total to beta. (#136314, @petern48) [SIG API Machinery, Etcd, Instrumentation and Testing]
  • Graduated the ImageVolume feature to stable. (#136711, @saschagrunert) [SIG Apps, Architecture, Node and Testing]
  • Graduated the InPlacePodLevelResourcesVerticalScaling feature gate to beta, enabled by default. Pod-level CPU and memory resources can be resized in place for Pods with pod-level resources configured. (#137684, @ndixita) [SIG API Machinery, Apps, Autoscaling, Node, Release, Scheduling and Testing]
  • Graduated the UserNamespacesSupport feature gate to GA. (#136792, @rata) [SIG API Machinery, Apps, CLI, Node, Storage and Testing]
  • Graduated the config.k8s.io/flagz API to v1beta1. (#137174, @richabanker) [SIG API Machinery, Instrumentation, Node, Scheduling and Testing]
  • Graduated the config.k8s.io/statusz API to v1beta1. (#137173, @richabanker) [SIG API Machinery, Instrumentation, Scheduling and Testing]
  • HPA: Improved scaling to and from zero when the HPAScaleToZero feature gate is enabled. (#135118, @johanneswuerbach) [SIG Apps, Autoscaling and Testing]
  • Integrated Workload and PodGroup APIs with the Job controllers to support gang-scheduling. (#137032, @helayoty) [SIG API Machinery, Apps, Auth, CLI, Cloud Provider, Etcd, Instrumentation, Node, Scheduling and Testing]
  • Introduced scheduling.k8s.io/v1alpha2 Workload and PodGroup API to express workload-level scheduling requirements and let kube-scheduler act on those. Removed scheduling.k8s.io/v1alpha1 Workload API. (#136976, @tosi3k) [SIG API Machinery, Apps, Auth, CLI, Cloud Provider, Etcd, Node, Scheduling, Storage and Testing]
  • Kube-apiserver: The --audit-policy-file config file now supports specifying group: "*" in resource rules to match all API groups. (#135262, @cmuuss) [SIG API Machinery, Auth and Testing]
  • Kube-controller-manager: Added ALPHA gauge metric informer_queued_items for informer queue length, published as informer_queued_items{name=kube-controller-manager,group=<group>,resource=<resource>,version=<version>} <count>. (#135782, @richabanker) [SIG API Machinery, Architecture, Instrumentation and Testing]
  • Kubelet: Added tiered cgroup v2 memory protection for MemoryQoS: memory.min for Guaranteed pods and memory.low for Burstable pods, with node-level metrics and rollback reconciliation (KEP-2570). (#137719, @sohankunkerkar) [SIG Node, Storage and Testing]
  • Locked the VolumeAttributesClass feature gate to true and updated the preferred storage version to storage.k8s.io/v1. (#134556, @carlory) [SIG API Machinery, Apps, Etcd, Network, Node, Scheduling, Storage and Testing]
  • Marked the endpoints field as optional in the OpenAPI spec for discovery.k8s.io/v1 EndpointSlice. This matches server behavior and resolves validation issues. (#136111, @aojea) [SIG Network]
  • Promoted DRAPrioritizedList to GA. (#136924, @troychiu) [SIG Apps, Architecture, Autoscaling, CLI, Cloud Provider, Cluster Lifecycle, Network, Node, Release, Scheduling, Storage and Testing]
  • Promoted NodeDeclaredFeatures to beta. (#136042, @pravk03) [SIG API Machinery, Apps, Cluster Lifecycle, Instrumentation, Node, Scheduling, Storage and Testing]
  • Promoted SnapshotMetadataService to v1beta1. Removed support for the v1alpha1 version. (#137564, @iPraveenParihar) [SIG Storage and Testing]
  • Promoted mutable CSI node allocatable count to GA. The MutableCSINodeAllocatableCount feature gate is locked to enabled. (#136230, @torredil) [SIG API Machinery and Storage]
  • Promoted several EndpointSlice metrics from alpha to beta stability. (#136368, @bhope) [SIG Instrumentation and Network]
  • Promoted several component-base metrics (kubernetes_build_info, rest_client_requests_total, rest_client_request_duration_seconds, running_managed_controllers) from Alpha to Beta stability, providing stronger API and label stability guarantees for consumers. (#136154, @bhope) [SIG API Machinery, Apps, Architecture, Auth, CLI, Cloud Provider, Cluster Lifecycle, Etcd, Instrumentation, Network, Node, Scalability, Scheduling, Storage and Testing]
  • Promoted several scheduler metrics (scheduler_goroutines, scheduler_permit_wait_duration_seconds, scheduler_plugin_evaluation_total, scheduler_plugin_execution_duration_seconds, scheduler_scheduling_algorithm_duration_seconds, scheduler_unschedulable_pods) from alpha to beta stability, providing stronger API and label stability guarantees for metric consumers. (#136155, @bhope) [SIG Instrumentation and Scheduling]
  • Promoted the DRA extended resource feature to beta in v1.36. (#135048, @yliaog) [SIG API Machinery, Architecture, Auth, Network, Node, Scheduling and Testing]
  • Promoted the ConstrainedImpersonation feature to beta, enabled by default. (#137609, @enj) [SIG API Machinery and Testing]
  • Promoted the DRAAdminAccess feature gate to GA. (#137373, @ritazh) [SIG API Machinery, Auth, Node, Scheduling and Testing]
  • Promoted the MutatingAdmissionPolicy to GA (v1) in Kubernetes v1.36. The feature is now enabled by default. (#136039, @lalitc375) [SIG API Machinery, Architecture, Etcd and Testing]
  • Promoted the NodeLogQuery feature gate to GA. (#137544, @jrvaldes) [SIG Node and Windows]
  • Promoted the ProcMountType feature to GA. (#137454, @haircommander) [SIG API Machinery, Apps, Auth, CLI, Node, Storage and Testing]
  • Promoted the watch_list_duration_seconds metric from ALPHA to BETA. (#136086, @richabanker) [SIG API Machinery, Instrumentation, Node and Testing]
  • Promoted two Job controller metrics from alpha to beta stability, providing stronger API and label stability guarantees for metric consumers. (#136367, @bhope) [SIG Apps and Instrumentation]
  • Promoted workqueue metrics from ALPHA to BETA. (#135522, @petern48) [SIG Architecture, Instrumentation and Testing]
  • Removed CustomResourceDefinition stored versions from status upon StorageVersionMigrator migration. (#135297, @michaelasp) [SIG API Machinery, Apps, Auth and Testing]
  • Removed the in-tree Portworx volume plugin, completing the migration to CSI. Removed the GA CSIMigrationPortworx feature gate (locked since v1.33) and alpha InTreePluginPortworxUnregister feature gate, with all operations now redirected to CSI. (#135322, @carlory) [SIG API Machinery, Apps, Auth, Node, Scalability, Scheduling, Storage and Testing]
  • Removed the temporary build-tagged ProtoMessage() marker method implementations from Kubernetes REST API types in k8s.io/api, which had incorrectly identified them as standard v1 proto messages. Protobuf serialization of Kubernetes API types should use k8s.io/apimachinery/pkg/runtime/serializer/protobuf. (#137084, @liggitt) [SIG API Machinery, Apps, Architecture, Auth, Node, Scheduling and Storage]
  • Slow requests that use impersonation can be tracked via the apiserver.latency.k8s.io/impersonation audit event annotation when the ConstrainedImpersonation feature is enabled. (#137523, @enj) [SIG API Machinery, Auth and Testing]
  • The DRAConsumableCapacity feature gate is enabled by default. (#136611, @sunya-ch) [SIG API Machinery, Cluster Lifecycle, Node, Scheduling and Testing]
  • The StrictIPCIDRValidation feature gate in kube-apiserver is enabled by default, meaning that API fields no longer allow IP or CIDR values with extraneous leading "0"s (e.g., 010.000.000.005 rather than 10.0.0.5) or CIDR subnet/mask values with ambiguous semantics (e.g., 192.168.0.5/24 rather than 192.168.0.0/24 or 192.168.0.5/32). (#137053, @danwinship) [SIG Network and Testing]
  • The kube-scheduler now updates PodGroup status with a PodGroupScheduled condition reflecting whether the group was successfully scheduled or is unschedulable. (#137611, @helayoty) [SIG API Machinery, Apps, Scheduling and Testing]
  • Updated API comments to reflect the stable state of Dynamic Resource Allocation (DRA). (#136441, @kannon92) [SIG API Machinery]
  • Updated API server internal API group to improve openapi schema correctness for fields being optional or required. (#134675, @JoelSpeed) [SIG API Machinery, Apps, Auth, Node and Storage]
  • Updated the /configz endpoint of kubelet, kube-scheduler, cloud controller manager, and kube-proxy to serialize the APIVersion and Kind fields and use public types instead of internal. (#136044, @SergeyKanzhelev) [SIG API Machinery, Cloud Provider, Cluster Lifecycle, Network, Node, Scheduling and Testing]

Feature

  • Added ALPHA counter metric scheduler_pod_scheduled_after_flush_total to track pods successfully scheduled after timeout flush from the unschedulablePods queue. (#135126, @mrvarmazyar) [SIG Scheduling]
  • Added ARCH column in the kubectl get node -o wide output. (#132402, @astraw99) [SIG CLI]
  • Added apiserver_peer_proxy_errors_total and apiserver_peer_discovery_sync_errors_total alpha metrics to apiserver to track errors encountered in peer proxying and peer discovery. (#137065, @richabanker) [SIG API Machinery]
  • Added kubectl explain -r flag as a shorthand for --recursive. (#135283, @laervn) [SIG CLI]
  • Added kubelet_metrics_provider metric to help users identify where kubelet's metrics are coming from. (#136952, @dgrisonnet) [SIG Node]
  • Added a PodGroup scheduling cycle to kube-scheduler's main scheduling loop, enabling all pods within a PodGroup to be scheduled within a single cycle. (#136618, @macsko) [SIG Scheduling and Testing]
  • Added a show-secret flag to the diff command to explicitly allow secret values to be displayed during the diff operation. (#137019, @olamilekan000) [SIG CLI]
  • Added a new gRPC service to the kubelet that provides information about Pods running on the node. (#134627, @briansonnenberg) [SIG Node and Testing]
  • Added a warning when kubectl rollout undo is used on resources managed with kubectl apply to prevent unexpected behavior from annotation mismatch. (#137064, @olamilekan000) [SIG CLI]
  • Added alpha counter metric route_controller_route_sync_total to Cloud Controller Manager to track route syncs with cloud providers. This metric is in alpha stage. (#136539, @lukasmetzner) [SIG API Machinery, Cloud Provider and Instrumentation]
  • Added alpha metrics tracking the resource version the cache layer of an informer is at. (#137419, @michaelasp) [SIG API Machinery, Architecture, Instrumentation and Testing]
  • Added an alpha informer_processing_latency_seconds histogram metric to measure event handler execution time in RealFIFO. (#137101, @richabanker) [SIG API Machinery, Architecture, Instrumentation and Testing]
  • Added metrics for constrained impersonation: apiserver_impersonation_attempts_total, apiserver_impersonation_attempts_duration_seconds, apiserver_impersonation_authorization_attempts_total, and apiserver_impersonation_authorization_attempts_duration_seconds (labels: mode, decision). (#137374, @enj) [SIG API Machinery, Auth and Testing]
  • A

These notes run past the length kept in the archive. The rest is on the publisher’s page.