This is an automated email from the ASF dual-hosted git repository.

villebro pushed a commit to branch 0.3
in repository 
https://gitbox.apache.org/repos/asf/superset-kubernetes-operator.git

commit 66a9afa92f9716d38918abb40a99d8b64f2ff801
Author: Ville Brofeldt <[email protected]>
AuthorDate: Fri Sep 25 10:47:09 2026 -0700

    docs: add 0.3.0 changelog
---
 docs/reference/releases.md | 7 +++++--
 1 file changed, 5 insertions(+), 2 deletions(-)

diff --git a/docs/reference/releases.md b/docs/reference/releases.md
index 7fa53ff..83b8192 100644
--- a/docs/reference/releases.md
+++ b/docs/reference/releases.md
@@ -23,6 +23,8 @@ This page tracks notable changes in Apache Superset 
Kubernetes Operator releases
 
 ## Unreleased
 
+## 0.3.0
+
 ### Added
 
 - Structured metastore, Valkey, and lifecycle seed-source connection fields 
can now be sourced individually from Kubernetes Secret keys, allowing 
`Superset` resources to consume provisioner-owned endpoints and credentials 
without copying discovered values or assembling a separate connection URI 
([#369](https://github.com/apache/superset-kubernetes-operator/pull/369)).
@@ -32,7 +34,7 @@ This page tracks notable changes in Apache Superset 
Kubernetes Operator releases
 
 - **Helm chart requires leader election for multiple replicas.** Rendering now 
fails when `replicas` is greater than 1 and `leaderElection.enabled` is 
`false`. Replicas are active/standby behind the [leader election 
Lease](https://kubernetes.io/docs/concepts/architecture/leases/#leader-election);
 without it every replica reconciles the same `Superset` resources and races on 
Jobs, drains, and status. Existing releases with that combination fail `helm 
upgrade` until leader election is enab [...]
 - Valkey's default port is now applied at runtime, aligning it with the 
existing structured-metastore behavior, instead of being stored by CRD 
defaulting. Resources that omit both `valkey.port` and `valkey.portFrom` 
therefore no longer materialize `port: 6379`, while generated configuration 
continues to use port 6379. This permits `portFrom` without a defaulted literal 
conflicting at admission 
([#369](https://github.com/apache/superset-kubernetes-operator/pull/369)).
-- Kubernetes support now covers the three newest `kind`-published minor 
versions instead of two. CI tests Kubernetes 1.37, 1.36, and 1.35 natively, 
with the experimental `next` lane disabled again 
([#317](https://github.com/apache/superset-kubernetes-operator/pull/317)).
+- Kubernetes support now covers the three newest `kind`-published minor 
versions instead of two. CI tests Kubernetes 1.37, 1.36, and 1.35 natively, 
with the experimental `next` lane disabled again 
([#315](https://github.com/apache/superset-kubernetes-operator/pull/315)).
 
 ### Fixed
 
@@ -41,12 +43,13 @@ This page tracks notable changes in Apache Superset 
Kubernetes Operator releases
 - The operator no longer crash-loops on clusters where Gateway API is 
installed but serves only `v1beta1`: optional-API detection now pins the 
version the operator actually uses (`HTTPRoute` v1, `ServiceMonitor` v1) 
instead of matching any version of the Kind 
([#361](https://github.com/apache/superset-kubernetes-operator/pull/361), 
[@villebro](https://github.com/villebro)).
 - Component Services of type `NodePort` or `LoadBalancer` that do not pin 
`service.nodePort` no longer churn: the operator now preserves the 
apiserver-allocated node port across reconciles instead of triggering a 
re-allocation each time, which previously changed the external port and broke 
external access 
([#360](https://github.com/apache/superset-kubernetes-operator/pull/360), 
[@villebro](https://github.com/villebro)).
 - The operator now requests `update` on `supersets/finalizers`, so 
reconciliation no longer fails on clusters with the 
`OwnerReferencesPermissionEnforcement` admission plugin enabled (e.g. 
OpenShift), where the API server previously rejected the `blockOwnerDeletion` 
owner references the operator sets on child resources 
([#359](https://github.com/apache/superset-kubernetes-operator/pull/359), 
[@villebro](https://github.com/villebro)).
-- The chart no longer rejects top-level values it does not declare, so shared 
values files and deploy tooling that injects release metadata no longer fail 
schema validation. Nested value blocks are still strictly validated.
+- The chart no longer rejects top-level values it does not declare, so shared 
values files and deploy tooling that injects release metadata no longer fail 
schema validation. Nested value blocks are still strictly validated 
([#366](https://github.com/apache/superset-kubernetes-operator/pull/366), 
[@ThomasJLLN](https://github.com/ThomasJLLN)).
 
 ### Security
 
 - Every operator-created container (component Deployments, lifecycle task 
Jobs, and the create-database init container) now defaults to a hardened 
securityContext — `allowPrivilegeEscalation: false`, all capabilities dropped, 
and `seccompProfile: RuntimeDefault` — filled per-field only where you have not 
set them yourself. This hardens workloads on permissive clusters and satisfies 
several of the restricted Pod Security Standard's requirements out of the box; 
full restricted compatibilit [...]
 - **Breaking:** CRs with `serviceAccount.create=true` (or unset) and 
`serviceAccount.name != metadata.name` are now rejected at admission. To use a 
pre-existing ServiceAccount with a different name, set 
`serviceAccount.create=false` 
([#324](https://github.com/apache/superset-kubernetes-operator/pull/324), 
[@villebro](https://github.com/villebro)).
+- Instances that had pinned the `superset.apache.org/config-checksum` pod 
annotation roll once on upgrade as the operator's computed checksum reasserts 
itself, closing a gap where a pinned annotation could freeze out config and 
`SECRET_KEY` rotations while status misreported as reconciled 
([#331](https://github.com/apache/superset-kubernetes-operator/pull/331), 
[@villebro](https://github.com/villebro)).
 - **Breaking:** Valkey cache and results-backend `keyPrefix` values are now 
constrained to `^[A-Za-z0-9._:-]*$` (max 128 characters); values containing 
spaces, slashes, or other characters outside that set are rejected. The safer 
rendering also causes a one-time config-checksum change and pod roll on upgrade 
([#325](https://github.com/apache/superset-kubernetes-operator/pull/325), 
[@villebro](https://github.com/villebro)).
 - Seed `excludeTables`, `excludeTableData`, and `postSeedSQL` values are now 
passed literally to generated seed scripts; values that previously relied on 
shell expansion no longer expand 
([#325](https://github.com/apache/superset-kubernetes-operator/pull/325), 
[@villebro](https://github.com/villebro)).
 - **Breaking:** Celery Flower is no longer published on the Ingress/Gateway 
surface in `Production` by default. Flower's default command ships without 
authentication and its dashboard discloses task names and arguments — for 
Superset, other users' async SQL Lab statements and alert/report payloads. In 
`Production` (the default) Flower is fanned out onto the end-user host — and 
its port opened in the built-in NetworkPolicy — only when you explicitly set 
`celeryFlower.service.gatewayPath`; [...]

Reply via email to