This is an automated email from the ASF dual-hosted git repository. villebro pushed a commit to branch 0.3 in repository https://gitbox.apache.org/repos/asf/superset-kubernetes-operator.git
commit 66a9afa92f9716d38918abb40a99d8b64f2ff801 Author: Ville Brofeldt <[email protected]> AuthorDate: Fri Sep 25 10:47:09 2026 -0700 docs: add 0.3.0 changelog --- docs/reference/releases.md | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/docs/reference/releases.md b/docs/reference/releases.md index 7fa53ff..83b8192 100644 --- a/docs/reference/releases.md +++ b/docs/reference/releases.md @@ -23,6 +23,8 @@ This page tracks notable changes in Apache Superset Kubernetes Operator releases ## Unreleased +## 0.3.0 + ### Added - Structured metastore, Valkey, and lifecycle seed-source connection fields can now be sourced individually from Kubernetes Secret keys, allowing `Superset` resources to consume provisioner-owned endpoints and credentials without copying discovered values or assembling a separate connection URI ([#369](https://github.com/apache/superset-kubernetes-operator/pull/369)). @@ -32,7 +34,7 @@ This page tracks notable changes in Apache Superset Kubernetes Operator releases - **Helm chart requires leader election for multiple replicas.** Rendering now fails when `replicas` is greater than 1 and `leaderElection.enabled` is `false`. Replicas are active/standby behind the [leader election Lease](https://kubernetes.io/docs/concepts/architecture/leases/#leader-election); without it every replica reconciles the same `Superset` resources and races on Jobs, drains, and status. Existing releases with that combination fail `helm upgrade` until leader election is enab [...] - Valkey's default port is now applied at runtime, aligning it with the existing structured-metastore behavior, instead of being stored by CRD defaulting. Resources that omit both `valkey.port` and `valkey.portFrom` therefore no longer materialize `port: 6379`, while generated configuration continues to use port 6379. This permits `portFrom` without a defaulted literal conflicting at admission ([#369](https://github.com/apache/superset-kubernetes-operator/pull/369)). -- Kubernetes support now covers the three newest `kind`-published minor versions instead of two. CI tests Kubernetes 1.37, 1.36, and 1.35 natively, with the experimental `next` lane disabled again ([#317](https://github.com/apache/superset-kubernetes-operator/pull/317)). +- Kubernetes support now covers the three newest `kind`-published minor versions instead of two. CI tests Kubernetes 1.37, 1.36, and 1.35 natively, with the experimental `next` lane disabled again ([#315](https://github.com/apache/superset-kubernetes-operator/pull/315)). ### Fixed @@ -41,12 +43,13 @@ This page tracks notable changes in Apache Superset Kubernetes Operator releases - The operator no longer crash-loops on clusters where Gateway API is installed but serves only `v1beta1`: optional-API detection now pins the version the operator actually uses (`HTTPRoute` v1, `ServiceMonitor` v1) instead of matching any version of the Kind ([#361](https://github.com/apache/superset-kubernetes-operator/pull/361), [@villebro](https://github.com/villebro)). - Component Services of type `NodePort` or `LoadBalancer` that do not pin `service.nodePort` no longer churn: the operator now preserves the apiserver-allocated node port across reconciles instead of triggering a re-allocation each time, which previously changed the external port and broke external access ([#360](https://github.com/apache/superset-kubernetes-operator/pull/360), [@villebro](https://github.com/villebro)). - The operator now requests `update` on `supersets/finalizers`, so reconciliation no longer fails on clusters with the `OwnerReferencesPermissionEnforcement` admission plugin enabled (e.g. OpenShift), where the API server previously rejected the `blockOwnerDeletion` owner references the operator sets on child resources ([#359](https://github.com/apache/superset-kubernetes-operator/pull/359), [@villebro](https://github.com/villebro)). -- The chart no longer rejects top-level values it does not declare, so shared values files and deploy tooling that injects release metadata no longer fail schema validation. Nested value blocks are still strictly validated. +- The chart no longer rejects top-level values it does not declare, so shared values files and deploy tooling that injects release metadata no longer fail schema validation. Nested value blocks are still strictly validated ([#366](https://github.com/apache/superset-kubernetes-operator/pull/366), [@ThomasJLLN](https://github.com/ThomasJLLN)). ### Security - Every operator-created container (component Deployments, lifecycle task Jobs, and the create-database init container) now defaults to a hardened securityContext — `allowPrivilegeEscalation: false`, all capabilities dropped, and `seccompProfile: RuntimeDefault` — filled per-field only where you have not set them yourself. This hardens workloads on permissive clusters and satisfies several of the restricted Pod Security Standard's requirements out of the box; full restricted compatibilit [...] - **Breaking:** CRs with `serviceAccount.create=true` (or unset) and `serviceAccount.name != metadata.name` are now rejected at admission. To use a pre-existing ServiceAccount with a different name, set `serviceAccount.create=false` ([#324](https://github.com/apache/superset-kubernetes-operator/pull/324), [@villebro](https://github.com/villebro)). +- Instances that had pinned the `superset.apache.org/config-checksum` pod annotation roll once on upgrade as the operator's computed checksum reasserts itself, closing a gap where a pinned annotation could freeze out config and `SECRET_KEY` rotations while status misreported as reconciled ([#331](https://github.com/apache/superset-kubernetes-operator/pull/331), [@villebro](https://github.com/villebro)). - **Breaking:** Valkey cache and results-backend `keyPrefix` values are now constrained to `^[A-Za-z0-9._:-]*$` (max 128 characters); values containing spaces, slashes, or other characters outside that set are rejected. The safer rendering also causes a one-time config-checksum change and pod roll on upgrade ([#325](https://github.com/apache/superset-kubernetes-operator/pull/325), [@villebro](https://github.com/villebro)). - Seed `excludeTables`, `excludeTableData`, and `postSeedSQL` values are now passed literally to generated seed scripts; values that previously relied on shell expansion no longer expand ([#325](https://github.com/apache/superset-kubernetes-operator/pull/325), [@villebro](https://github.com/villebro)). - **Breaking:** Celery Flower is no longer published on the Ingress/Gateway surface in `Production` by default. Flower's default command ships without authentication and its dashboard discloses task names and arguments — for Superset, other users' async SQL Lab statements and alert/report payloads. In `Production` (the default) Flower is fanned out onto the end-user host — and its port opened in the built-in NetworkPolicy — only when you explicitly set `celeryFlower.service.gatewayPath`; [...]
