Changelog for
kubernetes-kubelet-1.7.7-44.1.x86_64.rpm :
* Thu Oct 19 2017 mjuraAATTsuse.com- Add kubectl fix for duplicate proto error, (bsc#1057277)
* kubectl-fix-duplicate-proto-error-bsc-1057277.patch
* Fri Sep 29 2017 opensuse-packagingAATTopensuse.org- Update to version 1.7.7 (bsc#1061027):
* Fix clusterip for ExternalName service test
* Third party resources should not be part of conformance
* Disable invalid test case from dns externalName e2e test
* Makes Hostname and Subdomain fields of v1.PodSpec settable when empty and updates the StatefulSet controller to set them when empty
* Update kube-dns to 1.14.5
* Kubernetes version v1.7.7 file updates
* Mon Sep 18 2017 jmassaguerplaAATTsuse.com- Update to 1.7.6 (fix bsc#1059207) [fluentd-gcp addon] Fluentd will trim lines exceeding 100KB instead of dropping them. (#52289, AATTcrassirostris) Cluster Autoscaler 0.6.2 (#52359, AATTmwielgus) Add --request-timeout to kube-apiserver to make global request timeout configurable. (#51415, AATTjpbetz) Fix credentials providers for docker sandbox image. (#51870, AATTfeiskyer) Fix security holes in GCE metadata proxy. (#51302, AATTihmccreery) Fixed an issue looking up cronjobs when they existed in more than one API version (#52227, AATTliggitt) Fixes an issue with upgrade requests made via pod/service/node proxy subresources sending a non-absolute HTTP request-uri to backends (#52065, AATTliggitt) Fix a kube-controller-manager crash which can result when --concurrent-resource-quota-syncs is >1 and pods exist in the system containing certain alpha/beta annotation keys. (#52092, AATTironcladlou) Make logdump support kubemark and support gke with \'use_custom_instance_list\' (#51834, AATTshyamjvs) Fixes an issue with APIService auto-registration affecting rolling HA apiserver restarts that add or remove API groups being served. (#51921, AATTliggitt) In GCE with COS, increase TasksMax for Docker service to raise cap on number of threads/processes used by containers. (#51986, AATTyujuhong) Fix providerID update validation (#51761, AATTkarataliu) Automated cherry pick of #50381 to release-1.7 (#51871, AATTfeiskyer) The emptyDir.sizeLimit field is now correctly omitted from API requests and responses when unset. (#50163, AATTjingxu97) Calico has been updated to v2.5, RBAC added, and is now automatically scaled when GCE clusters are resized. (#51237, AATTgunjan5)- Update to 1.7.5 Bumped Heapster version to 1.4.2 - more details https://github.com/kubernetes/heapster/releases/tag/v1.4.2. (#51620, AATTpiosz) Fix for Pod stuck in ContainerCreating with error \"Volume is not yet attached according to node\". (#50806, AATTverult) Fixed controller manager crash by making it tolerant to discovery errors.(#49767, AATTdeads2k) Finalizers are now honored on custom resources, and on other resources even when garbage collection is disabled via the apiserver flag --enable-garbage-collector=false (#51469, AATTironcladlou) Allow attach of volumes to multiple nodes for vSphere (#51066, AATTBaluDontu) vSphere: Fix attach volume failing on the first try. (#51217, AATTBaluDontu) azure: support retrieving access tokens via managed identity extension (#48854, AATTcolemickens) Fixed a bug in strategic merge patch that caused kubectl apply to error out under some conditions (#50862, AATTguoshimin) It is now posible to use flexVolumes to bind mount directories and files. (#50596, AATTadelton) StatefulSet: Fix \"forbidden pod updates\" error on Pods created prior to upgrading to 1.7. (#48327) (#51149, AATTkow3ns) Fixed regression in initial kubectl exec terminal dimensions (#51127, AATTchen-anders) Enforcement of fsGroup; enable ScaleIO multiple-instance volume mapping; default PVC capacity; alignment of PVC, PV, and volume names for dynamic provisioning (#48999, AATTvladimirvivien)- Update to 1.7.4 Azure: Allow VNet to be in a separate Resource Group. (#49725, AATTsylr) Fix an issue where if a CSR is not approved initially by the SAR approver is not retried. (#49788, AATTmikedanese) Cluster Autoscaler - fixes issues with taints and updates kube-proxy cpu request. (#50514, AATTmwielgus) Bumped Heapster version to 1.4.1: (#50642, AATTpiosz) handle gracefully problem when kubelet reports duplicated stats for the same container (see #47853) on Heapster side fixed bugs and improved performance in Stackdriver Sink fluentd-gcp addon: Fix a bug in the event-exporter, when repeated events were not sent to Stackdriver. (#50511, AATTcrassirostris) Collect metrics from Heapster in Stackdriver mode. (#50517, AATTpiosz) fixes a bug around using the Global config ElbSecurityGroup where Kuberentes would modify the passed in Security Group. (#49805, AATTnbutton23) Updates Cinder AttachDisk operation to be more reliable by delegating Detaches to volume manager. (#50042, AATTjingxu97) fixes kubefed\'s ability to create RBAC roles in version-skewed clusters (#50537, AATTliggitt) Fix data race during addition of new CRD (#50098, AATTnikhita) Fix bug in scheduler that caused initially unschedulable pods to stuck in Pending state forever. (#50028, AATTjulia-stripe) Fix incorrect retry logic in scheduler (#50106, AATTjulia-stripe) GCE: Bump GLBC version to 0.9.6 (#50096, AATTnicksardo) The NodeRestriction admission plugin now allows a node to evict pods bound to itself (#48707, AATTdanielfm) Fixed a bug in the API server watch cache, which could cause a missing watch event immediately after cache initialization. (#49992, AATTliggitt)- Update to 1.7.3 fix pdb validation bug on PodDisruptionBudgetSpec (#48706, AATTdixudx) kubeadm: Fix join preflight check false negative (#49825, AATTerhudy) Revert deprecation of vCenter port in vSphere Cloud Provider. (#49689, AATTdivyenpatel) Fluentd-gcp DaemonSet exposes different set of metrics. (#48812, AATTcrassirostris) Fixed OpenAPI Description and Nickname of API objects with subresources (#49357, AATTmbohlool) Websocket requests to aggregated APIs now perform TLS verification using the service DNS name instead of the backend server\'s IP address, consistent with non-websocket requests. (#49353, AATTliggitt) kubeadm: Fixes a small bug where --config and --skip-
* flags couldn\'t be passed at the same time in validation. (#49498, AATTluxas) kubeadm: Don\'t set a specific spc_t SELinux label on the etcd Static Pod as that is more privs than etcd needs and due to that spc_t isn\'t compatible with some OSes. (#49328, AATTeuank) Websocket requests to aggregated APIs now perform TLS verification using the service DNS name instead of the backend server\'s IP address, consistent with non-websocket requests. (#49353, AATTliggitt) kubectl drain no longer spins trying to delete pods that do not exist (#49444, AATTeparis) Fixes #49418 where kube-controller-manager can panic on volume.CanSupport methods and enter a crash loop. (#49420, AATTgnufied) Fix Cinder to support http status 300 in pagination (#47602, AATTrootfs) Automated cherry pick of #49079 upstream release 1.7 (#49254, AATTfeiskyer) Fixed GlusterFS volumes taking too long to time out (#48709, AATTjsafrane) The IP address and port for kube-proxy metrics server is now configurable via flag --metrics-bind-address (#48625, AATTmrhohn) Special notice for kube-proxy in 1.7+ (including 1.7.0): Healthz server (/healthz) will be served on 0.0.0.0:10256 by default. Metrics server (/metrics and /proxyMode) will be served on 127.0.0.1:10249 by default. Metrics server will continue serving /healthz.- Update to 1.7.2 Use port 20256 for node-problem-detector in standalone mode. (#49316, AATTajitak) GCE Cloud Provider: New created LoadBalancer type Service will have health checks for nodes by default if all nodes have version >= v1.7.2. (#49330, AATTMrHohn) Azure PD (Managed/Blob) (#46360, AATTkhenidak) Fix Pods using Portworx volumes getting stuck in ContainerCreating phase. (#48898, AATTharsh-px) kubeadm: Make kube-proxy tolerate the external cloud provider taint so that an external cloud provider can be easily used on top of kubeadm (#49017, AATTluxas) Fix pods failing to start when subPath is a dangling symlink from kubelet point of view, which can happen if it is running inside a container (#48555, AATTredbaron) Never prevent deletion of resources as part of namespace lifecycle (#48733, AATTliggitt) kubectl: Fix bug that showed terminated/evicted pods even without --show-all. (#48786, AATTjanetkuo) Add a runtime warning about the kubeadm default token TTL changes. (#48838, AATTmattmoyer) Local storage teardown fix (#48402, AATTianchakeres) Fix udp service blackhole problem when number of backends changes from 0 to non-0 (#48524, AATTfreehan) hpa: Prevent scaling below MinReplicas if desiredReplicas is zero (#48997, AATTjohanneswuerbach) kubeadm: Fix a bug where kubeadm join would wait 5 seconds without doing anything. Now kubeadm join executes the tasks immediately. (#48737, AATTmattmoyer) Fix a regression that broke the --config flag for kubeadm init. (#48915, AATTmattmoyer) Fix service controller crash loop when Service with GCP LoadBalancer uses static IP (#48848, AATTnicksardo) (#48849, AATTnicksardo)- Update to 1.7.1 Added new flag to kubeadm init: --node-name, that lets you specify the name of the Node object that will be created (#48594, AATTGheRivero) Added new flag to kubeadm join: --node-name, that lets you specify the name of the Node object that\'s gonna be created (#48538, AATTGheRivero) Fixes issue where you could not mount NFS or glusterFS volumes using hostnames on GCI/GKE with COS images. (#42376, AATTjingxu97) Reduce amount of noise in Stackdriver Logging, generated by the event-exporter component in the fluentd-gcp addon. (#48712, AATTcrassirostris) Add generic NoSchedule toleration to fluentd in gcp config. (#48182, AATTgmarek) RBAC role and role-binding reconciliation now ensures namespaces exist when reconciling on startup. (#48480, AATTliggitt) Support NoSchedule taints correctly in DaemonSet controller. (#48189, AATTmikedanese) kubeadm: Expose only the cluster-info ConfigMap in the kube-public ns (#48050, AATTluxas)
* Tue Sep 12 2017 mmeisterAATTsuse.com- fix docker 1.12.6 requirement in subpackages
* Sun Sep 03 2017 kukukAATTsuse.de- Exclude s390- Fix building on aarch64
* Fri Sep 01 2017 thippAATTsuse.de- Require docker 1.12.6: https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG.md#external-dependency-version-information
* Fri Sep 01 2017 mmeisterAATTsuse.com- drop redundant BuildRequires already present with golang(API) = 1.8
* Thu Aug 17 2017 kukukAATTsuse.de- Remove superfluous whitespaces as requested by sle-review-team
* Thu Jul 13 2017 opensuse-packagingAATTopensuse.org- Update to version 1.7.0:
* Kubernetes 1.7 is a milestone release that adds security, stateful application, and extensibility features motivated by widespread production use of Kubernetes.
* Security enhancements in this release include encrypted secrets (alpha), network policy for pod-to-pod communication, the node authorizer to limit Kubelet access to API resources, and Kubelet client / server TLS certificate rotation (alpha).
* Major features for stateful applications include automated updates to StatefulSets, enhanced updates for DaemonSets, a burst mode for faster StatefulSets scaling, and (alpha) support for local storage.
* Extensibility features include API aggregation (beta), CustomResourceDefinitions (beta) in favor of ThirdPartyResources, support for extensible admission controllers (alpha), pluggable cloud providers (alpha), and container runtime interface (CRI) enhancements.- patch modifications:
* modify make-e2e_node-run-over-distro-bins.patch: supply additional args to test-e2e-node.sh
* modify build-with-debug-info.patch: hard-code go binary invocation - add_pr_template.patch - fix-support-for-ppc64le.patch
* Mon Jun 12 2017 fcastelliAATTsuse.com- Update go build requirements: do not build with go >= 1.8 until we kubernetes 1.7 is released (see https://github.com/kubernetes/kubernetes/issues/45935)
* Thu Jun 08 2017 robert.rolandAATTsuse.com- Adding a /etc/kubernetes/kubelet-initial EnvironmentFile that is expected to set the KUBELET_INITIAL_ARGS variable so that a set of arguments that only impact kubelet on the first run can be supplied. This removes the need to restart kubelet when you change the node labels, for example.
* Wed Jun 07 2017 fcastelliAATTsuse.com- Change default kubernetes log level: use warning as base level of logging, not debug.- Change default kubelet configuration: do not tell kubelet to look for the API server on localhost. 90% of the times this process is located somewhere else. This also helps to fix/mitigate bsc#1042387
* Mon Jun 05 2017 fcastelliAATTsuse.com- Add kubelet-support-btrfs-fixes-bsc-1042383.patch needed to fix bsc#1042383- Removed commented line referring to a patch file no longer shipped
* Fri May 19 2017 jmassaguerplaAATTsuse.com- Downgrade to version 1.5.3 because we just hit some new issues (bsc#1039663) with k8s 1.6 and we don\'t have time to properly fix and test 1.6, to make sure there are no new bugs, before the release.
* Tue Apr 11 2017 jengelhAATTinai.de- Update descriptions
* Thu Apr 06 2017 opensuse-packagingAATTopensuse.org- Update to version 1.6.1:
* Bump cluster autoscaler to 0.5.1
* Kubernetes version v1.6.1-beta.0
* update-all.sh
* Better messaging when GKE certificate signing fails.
* Update busybox dependency to fix bazel build
* update-all.sh
* don\'t wait for first kubelet to be ready
* Fix problems of not-starting image pullers
* Kubernetes version v1.6.1
* Mon Apr 03 2017 jmassaguerplaAATTsuse.com- Remove get-rid-of-the-git-commands-in-mungedocs.patch: no mungedocs Review patches:
* build-with-debug-info.patch
* fix-support-for-ppc64le.patch
* git-upstream.patch
* make-e2e_node-run-over-distro-bins.patch- Remove 0002-Change-DUP2-to-DUP3-in-contrib-mesos-to-build-on-arm.patch because mesos has been moved to the incubator project: https://github.com/kubernetes/kubernetes/pull/33658
* Mon Apr 03 2017 opensuse-packagingAATTopensuse.org- Update to version 1.6.0:
* Kubernetes version v1.6.0-beta.0
* Generating docs for v1.6.0-beta.0 on release-1.6.
* update-all.sh.
* update-all.sh.
* Kubernetes version v1.6.0-beta.1
* update-staging-client-go.sh
* Kubernetes version v1.6.0-beta.2
* update-all.sh.
* Kubernetes version v1.6.0-beta.3
* update-all.sh.
* Kubernetes version v1.6.0-beta.4
* update-staging-client-go.sh
* Update NPD rbac.
* Kubernetes version v1.6.0-rc.1
* update-all.sh.
* Update a few regex patterns to support release candidates
* Added failing upgrade if there are many master replicas.
* added prompt warning if etcd3 media type isn\'t set during upgrade
* etcd upgrade warning: add docs link, fixed etcd2 behavior, print non-interactive
* in storage media upgrade prompt, provide config for using protobuf
* Kubernetes version v1.6.0
* Mon Mar 27 2017 alvaro.saurinAATTsuse.com- updated to to 1.5.5
* Wed Mar 15 2017 alvaro.saurinAATTsuse.com- updated to to 1.5.4
* Thu Feb 23 2017 alvaro.saurinAATTsuse.com- added some patches: build-with-debug-info.patch, fix-support-for-ppc64le.patch, get-rid-of-the-git-commands-in-mungedocs.patch, git-upstream.patch, make-e2e_node-run-over-distro-bins.patch- removed gcc-on-ppc64-and-arm.patch
* Tue Jan 24 2017 jmassaguerplaAATTsuse.com- exclude i586. We don\'t expect this package to build with i586
* Mon Jan 23 2017 jmassaguerplaAATTsuse.com- add kubernetes-rpmlintrc file to the spec file
* Mon Nov 28 2016 jmassaguerplaAATTsuse.com- fix ownernship of service account key
* Wed Nov 23 2016 jmassaguerplaAATTsuse.com- fix permissions in service account key
* Thu Nov 17 2016 jmassaguerplaAATTsuse.com- add the github PR templates or it does not build
* Thu Nov 17 2016 asaurinAATTsuse.com- Updated to 1.3.10- AWS: fix volume device assignment race condition (#31090, AATTjustinsb)- Test x509 intermediates correctly (#34524, AATTliggitt)- Remove headers that are unnecessary for proxy target (#34076, AATTmbohlool)- gci: decouple from the built-in kubelet version (#31367, AATTAmey-D)- Bump GCE debian image to container-vm-v20161025 (CVE-2016-5195 Dirty… (#35825, AATTdchen1107)- Add RELEASE_INFRA_PUSH related code to support pushes from kubernetes/release. (#28922, AATTdavid-mcmahon)
* Wed Sep 14 2016 msabateAATTsuse.com- Updated to 1.3.7- Fix watch cache filtering (#29046, AATTliggitt)- List all nodes and occupy cidr map before starting allocations (#29062, AATTbprashanth)- Fix watch cache filtering (#28968, AATTliggitt)- Lock all possible kubecfg files at the beginning of ModifyConfig. (#28232, AATTcjcullen)- Removing images with multiple tags (#29316, AATTronnielai)- kubectl: don\'t display an empty list when trying to get a single resource that isn\'t found (#28294, AATTncdc)- Fix working_set calculation in kubelet (#29154, AATTvishh)- Don\'t delete affinity when endpoints are empty (#28655, AATTfreehan)- GCE bring-up: Differentiate NODE_TAGS from NODE_INSTANCE_PREFIX (#29141, AATTzmerlynn)- Fix logrotate config on GCI (#29139, AATTadityakali)- Do not query the metadata server to find out if running on GCE. Retry metadata server query for gcr if running on gce. (#28871, AATTvishh)- Fix GPU resource validation (#28743, AATTtherc)- Scale kube-proxy conntrack limits by cores (new default behavior) (#28876, AATTthockin)- Don\'t recreate lb cloud resources on kcm restart (#29082, AATTbprashanth)- NetworkPolicy cherry-pick 1.3 (#29556, AATTcaseydavenport)- Allow mounts to run in parallel for non-attachable volumes (#28939, AATTsaad-ali)- add enhanced volume and mount logging for block devices (#24797, AATTscreeley44)- kube-up: increase download timeout for kubernetes.tar.gz (#29426, AATTjustinsb)- Fix RBAC authorizer of ServiceAccount (#29071, AATTalbatross0)- Update docker engine-api to dea108d3aa (#29144, AATTronnielai)- Assume volume is detached if node doesn\'t exist (#29485, AATTsaad-ali)- Make PD E2E Tests Wait for Detach to Prevent Kernel Errors (#29031, AATTsaad-ali)- Fix \"PVC Volume not detached if pod deleted via namespace deletion\" issue (#29077, AATTsaad-ali)- append an abac rule for $KUBE_USER. (#29164, AATTcjcullen)- Update Dashboard UI to version v1.1.1 (#30273, AATTbryk)- allow restricting subresource access (#30001, AATTdeads2k)- Fix PVC.Status.Capacity and AccessModes after binding (#29982, AATTjsafrane)- oidc authentication plugin: don\'t trim issuer URLs with trailing slashes (#29860, AATTericchiang)- network/cni: Bring up the lo interface for rkt (#29310, AATTeuank)- Fixing kube-up for CVM masters. (#29140, AATTmaisem)- Addresses vSphere Volume Attach limits (#29881, AATTdagnello)- Increase request timeout based on termination grace period (#31275, AATTdims)- Skip safe to detach check if node API object no longer exists (#30737, AATTsaad-ali)- Nodecontroller doesn\'t flip readiness on pods if kubeletVersion < 1.2.0 (#30828, AATTbprashanth)- Update cadvisor to v0.23.9 to fix a problem where attempting to gather container filesystem usage statistics could result in corrupted devicemapper thin pool storage for Docker. (#30307, AATTsjenning)- AWS: Add ap-south-1 to list of known AWS regions (#28428, AATTjustinsb)- Back porting critical vSphere bug fixes to release 1.3 (#31993, AATTdagnello)- Back port - Openstack provider allowing more than one service port for lbaas v2 (#32001, AATTdagnello)- Fix a bug in kubelet hostport logic which flushes KUBE-MARK-MASQ iptables chain (#32413, AATTfreehan)- Fixes the panic that occurs in the federation controller manager when registering a GKE cluster to the federation. Fixes issue #30790. (#30940, AATTmadhusudancs)
* Wed Jul 13 2016 tchvatalAATTsuse.com- Run over with spec-cleaner- Remove the prereq fillup as it is not used- Use symlinks on fdupes not hardlinks- Move scriptlet prior files to match rest of specs- Switch to full url on sources for easy downloading- Make node and master conflict, they both provide same config files causing rpm conflicts
* Tue Jul 12 2016 msabateAATTsuse.com- Removed go as a build requirement The golang-packaging build requirement already has go as a requirement.
* Mon Jul 11 2016 msabateAATTsuse.com- Re-added missing tmpfiles creation
* Mon Jul 11 2016 msabateAATTsuse.com- Improved the handling of /var/run/kubernetes
* Fri Jul 08 2016 msabateAATTsuse.com- Added some more macros from golang-packaging I\'ve also done some minor changes and I\'ve merged the following two patches: 1. kubernets_change_cc_for_ppc64le.patch 2. 0001-SUSE-hack-use-native-system-compiler.patch into the patch: gcc-on-ppc64-and-arm.patch
* Wed Jul 06 2016 msabateAATTsuse.com- Added %{go_nostrip} from golang-packaging I\'ve also done some minor corrections
* Tue Jul 05 2016 dmuellerAATTsuse.com- fix tarball (was tar.gz instead of tar.xz)
* Tue Jul 05 2016 cbraunerAATTsuse.com- update to 1.3.0
* add _constraints file to get more disk space on aarch64
* fix url to show http://kubernetes.io
* remove bash completion instructions since bash completion has been removed upstream and is replaced by a dedicated command that generates the bash code on the fly
* Thu Jun 23 2016 dmuellerAATTsuse.com- add 0002-Change-DUP2-to-DUP3-in-contrib-mesos-to-build-on-arm.patch, 0001-SUSE-hack-use-native-system-compiler.patch: Build on aarch64
* Thu Jun 23 2016 dmuellerAATTsuse.com- update to 1.2.4:
* Ensure status is not changed during an update of PV, PVC, HPA objects (#24924, AATTmqliang)
* GCI: Add two GCI specific metadata pairs (#25105, AATTandyzheng0831)
* Update salt config to allow Debian Jessie on GCE. (#25123, AATTjlewi)
* Fix DeletingLoadBalancer event generation. (#24833, AATTa-robinson)
* GCE: Prefer preconfigured node tags for firewalls, if available (#25148, AATTa-robinson)
* Drain pods created from ReplicaSets in \'kubectl drain\' (#23689, AATTmaclof)
* GCI: Update the command to get the image (#24987, AATTandyzheng0831)
* Validate deletion timestamp doesn\'t change on update (#24839, AATTliggitt)
* Add support for running clusters on GCI (#24893, AATTandyzheng0831)
* Trusty: Add retry in curl commands (#24749, AATTandyzheng0831)
* Fri May 06 2016 fcastelliAATTsuse.com- Add runtime requirement to kubelet
* Thu May 05 2016 fcastelliAATTsuse.com- Fix version tag inside of final packages
* Thu Apr 28 2016 normandAATTlinux.vnet.ibm.com- enable build ppc64le new kubernets_change_cc_for_ppc64le.patch
* Tue Apr 26 2016 fcastelliAATTsuse.com- Updated to kubernetes v1.2.3
* Fri Mar 18 2016 fcastelliAATTsuse.com- Update to kuberneted v1.2.0
* Fri Feb 19 2016 fcastelliAATTsuse.com- Update to kubernetes v1.1.7- Remove change-internal-to-inteernal.patch, no longer needed- Cleanup of the spec file
* Sat Sep 19 2015 fcastelliAATTsuse.com- kubernetes-node: require the Docker package to be installed at runtime
* Tue Sep 08 2015 dmacvicarAATTsuse.de- initial package for 1.1.0 pre from git based on Fedora package