Hyperlight sandbox

A lightweight, secure container runtime solution designed for modern cloud-native workloads

Latest prerelease from main branch

What's Changed

Added

Changed

  • Breaking: Guest MSR state is now saved and restored across snapshots.
    SandboxConfiguration::guest_msrs declares the MSRs a guest depends on:
    declared MSRs are captured in a snapshot and restored, while every other MSR
    resets to a clean default. On KVM the guest may only read or write declared
    MSRs, on MSHV and WHP this is not enforced. by @ludfjig in #991
  • Breaking: Filesystem paths are now represented using PathBuf. GuestBinary::FilePath now stores a PathBuf instead of a String, and MultiUseSandbox::generate_crashdump_to_dir accepts Into<PathBuf> instead of Into<String>. Callers passing a String to GuestBinary::FilePath must convert it using .into().

Removed

Fixed

  • Fix symbol resolution in guest core dumps for sandboxes created from snapshots by @ludfjig in #1618
  • Reject malformed OCI snapshot metadata and non-regular artifact files during load.

Full Changelog (excl. dependencies)

Full Changelog (dependencies)

New Contributors

Full Changelog: v0.16.0...dev-latest

Keycloak incubating

Keycloak is an open-source identity and access management solution for modern applications and services, built on top of industry security standard protocols.

nightly

Document SCIM attribute visibility and mutability based on UP permiss…

…ions

Signed-off-by: Stefan Guilhen <sguilhen@redhat.com>

Cartography sandbox

Cartography is a Python tool that consolidates infrastructure assets and the relationships between them in an intuitive graph view.

0.140.0

What's Changed

  • feat(ontology): materialize (:ComputeService)-[:RUNS_IMAGE]->(:Image) inventory by @jychp in #3054
  • feat(ontology): normalize state/status/severity ont* fields to canonical enums by @jychp in #3056
  • feat(ontology): wire AWS Inspector & Semgrep findings into the CVE ontology by @jychp in #3055
  • docs(aws): document glue:GetConnections permission gap by @jychp in #3060
  • feat(rules): declare an affected-node anchor (asset_label) on every Fact by @jychp in #3065
  • fix(ontology): normalize Inspector and Semgrep CVE severity by @jychp in #3066
  • fix(exposure): single-own LoadBalancer->Container edge in AWS, decouple direct exposure by @jychp in #3067
  • chore: bump pyasn1 from 0.6.2 to 0.6.4 by @dependabot[bot] in #3068
  • chore: bump types-requests from 2.33.0.20260518 to 2.33.0.20260712 by @dependabot[bot] in #3073
  • chore: bump httplib2 from 0.31.2 to 0.32.0 by @dependabot[bot] in #3074
  • chore: bump python from eb43ff1 to 6771159 by @dependabot[bot] in #3069
  • chore: bump the minor-and-patch group with 2 updates by @dependabot[bot] in #3070
  • chore: bump the minor-and-patch group with 9 updates by @dependabot[bot] in #3071
  • feat(models): make extra node labels declarative by @jychp in #3032
  • perf(querybuilder): apply conditional node labels per row instead of via global remove/set passes by @jychp in #3082
  • fix(trivy): only set cve_id and :CVE on CVE-backed findings by @jychp in #3077
  • refactor(ontology): split Package into Package and PackageVersion by @jychp in #3086
  • feat(railway): add Railway intel module by @jychp in #3079
  • fix(rules): validate the Fact asset anchor and reserve Finding.source by @jychp in #3085
  • feat(rules): add SOC 2 compliance mappings by @jychp in #3080
  • feat(supabase): add Supabase intel module by @jychp in #3084
  • feat(circleci): code-to-cloud fallback supply-chain matcher by @jychp in #3059
  • fix(cloudflare): scope CloudflareDNSRecord to the account, not the zone by @jychp in #3087
  • fix(aws): refresh ECR layer credentials by @kunaals in #3093
  • chore: bump the minor-and-patch group with 12 updates by @dependabot[bot] in #3100
  • chore: bump types-pyyaml from 6.0.12.20260518 to 6.0.12.20260724 by @dependabot[bot] in #3102
  • chore: bump the minor-and-patch group with 4 updates by @dependabot[bot] in #3096
  • chore: bump astral-sh/setup-uv from 8.3.2 to 9.0.0 by @dependabot[bot] in #3097
  • chore: bump actions/setup-python from 6.3.0 to 7.0.0 by @dependabot[bot] in #3098
  • fix(ontology,route53): stop deleting route53-owned DNS_POINTS_TO edges and make ELB alias targets match by @jychp in #3090
  • perf(container-images): reuse cached layer metadata by @jychp in #3092
  • fix(aws): handle null groups in aws-auth mappings by @AlexanderDeBattista in #3095
  • chore: bump azure-mgmt-resource from 24.0.0 to 26.0.0 by @jychp in #3104
  • fix(vercel): give VercelAccessGroup the UserGroup ontology label by @jychp in #3099
  • perf(graph): drop lastupdated from the MatchLink relationship index key by @jychp in #3105
  • feat(modal): add Modal intel module by @jychp in #3089
  • fix(gcp): stop expanding broad BigQuery grants per table by @jychp in #3101
  • feat(docs): generate schema docs from data model by @jychp in #3021
  • fix(rules): simplify SOC 2 framework name by @jychp in #3108
  • fix(docs): capitalize OCI schema title by @kunaals in #3109
  • feat(netlify): add Netlify intel module by @jychp in #3091
  • feat(cloudflare): add R2, Workers, and WAF ruleset ingestion by @jychp in #3107
  • fix(cloudflare): tolerate optional SDK fields that arrive as null by @jychp in #3116
  • feat(aws:inspector): add fixAvailable, exploitAvailable, EPSS score to Inspector findings by @heryxpc in #3115
  • chore: drop Python 3.10 support by @jychp in #3113
  • feat(microsoft): added o365 Integration by @ShreyashSri in #3017
  • chore: bump docker/login-action from 4.5.1 to 4.5.2 in the minor-and-patch group by @dependabot[bot] in #3120
  • chore: bump actions/stale from 10.4.0 to 11.0.0 by @dependabot[bot] in #3121
  • chore: bump actions/download-artifact from 7.0.0 to 8.0.1 by @dependabot[bot] in #3122
  • chore: bump aiohttp from 3.14.1 to 3.14.3 by @dependabot[bot] in #3123
  • chore: bump the minor-and-patch group across 1 directory with 3 updates by @dependabot[bot] in #3124
  • fix(netlify): tolerate a DNS zone whose apex domain was registered through Netlify by @jychp in #3131
  • feat(github): add fork and parent attributes to GitHubRepository by @ryan-lane in #3076
  • chore: bump h2 from 4.3.0 to 4.4.1 by @dependabot[bot] in #3137
  • chore: bump typer from 0.27.0 to 0.27.1 in the minor-and-patch group by @dependabot[bot] in #3134
  • chore: bump the minor-and-patch group with 2 updates by @dependabot[bot] in #3133
  • fix(docs): show logo in dark mode by @kunaals in #3138
  • fix(rules): return webhook_resources as a list and include the wildcard by @jychp in #3142
  • fix(azure): support azure-mgmt-cosmosdb 10 and azure-mgmt-datafactory 10 model shapes by @jychp in #3128
  • docs: audit and update project documentation by @jychp in #3111
  • feat(wiz): Add Wiz intel module by @kunaals in #2943
  • feat(rules): detect ChainDrop (Aug 2026) Shai-Hulud npm compromise by @EmilioDNA in #3130
  • fix(wiz): classify issues and findings by ontology by @kunaals in #3145

New Contributors

Full Changelog: 0.139.1...0.140.0

LoxiLB sandbox

eBPF based cloud-native load-balancer. Powering Kubernetes|Edge|5G|IoT|XaaS Apps.

vlatest

Merge pull request #874 from TrekkieCoder/main

gh-868 Generate packages runnable with systemd

xRegistry sandbox

The xRegistry project defines an abstract model for managing metadata about resources and provides a REST-based interface to discover, create, modify and delete those resources.

dev

Latest development build of the 'xr(server)' executables. The commit pointer and zip/tar files are old, do not use them.

Spin sandbox

Spin is a framework for building and deploying serverless applications in WebAssembly.

canary

This is a "canary" release of the most recent commits on our main branch. Canary is not stable.
It is only intended for developers wishing to try out the latest features in Spin, some of which may not be fully implemented.

wasmCloud incubating

v2.7.0

What's Changed

  • chore(deps): bump wkg, wasmtime, wasm-tools, and wit-bindgen by @ricochet in #5412
  • chore: rustsec bumps for wasmtime, event-listener by @ricochet in #5415
  • host component plugins with native bindings by @ricochet in #5411
  • fix(chart): add Reloader annotations, fix hashing by @ricochet in #5418
  • fix(helm): update workload crds, add check by @vados-cosmonic in #5423
  • docs(examples): update oci-registry README for required Basic auth by @ericgregory in #5426
  • fix(runtime-operator): describe CRD kinds accurately by @ericgregory in #5427
  • feat(wash-runtime): configurable CA trust roots for outbound HTTPS by @jfleitz in #5422
  • chore(deps): bump the all-go group across 2 directories with 3 updates by @dependabot[bot] in #5416
  • chore(deps): bump the all-github-actions group across 4 directories with 10 updates by @dependabot[bot] in #5417
  • ci: bump pinned CI tool versions by @github-actions[bot] in #5425
  • fix(ci): add checkout step by @ricochet in #5428
  • fix(runtime-gateway): key routes by object key by @ricochet in #5429
  • feat: concurrent pooled instances by @ricochet in #5398
  • fix(bench): harden compare-bench checkouts, accept #PR as a bench ref by @ricochet in #5431
  • Outbound connection pooling for http requests by @jfleitz in #5424
  • fix(wash-runtime): size the egress idle cap from declared concurrency by @ricochet in #5432
  • chore(examples): release oci-registry 0.2.0 for the Basic auth change by @ricochet in #5434
  • test(runtime-operator): cover a component's instance limits end to end by @ricochet in #5433
  • feat: enable implements and maps by default by @ricochet in #5435
  • fix(wash-runtime): bind guest UDP sockets on loopback only by @ricochet in #5438
  • chore(deps): bump the all-github-actions group across 4 directories with 6 updates by @dependabot[bot] in #5444
  • chore(deps): bump the all-go group across 2 directories with 3 updates by @dependabot[bot] in #5443
  • feat(wash): trust private OCI CA roots, and put the e2e registry behind TLS by @ricochet in #5437
  • docs: document the wasm-component-ld prerequisite for building fixtures by @jtakakura in #5445
  • feat(runtime): host component call a workload's exports by @ricochet in #5442
  • feat(wash-runtime): one connection quota and one socket policy per guest by @ricochet in #5439
  • feat(wash-runtime): avoid trapping the plugin by @ricochet in #5452
  • release: v2.7.0 by @automation-wasmcloud in #5454

New Contributors

Full Changelog: v2.6.1...v2.7.0

Backstage incubating

Backstage is an open platform for building developer portals, which unify all your infrastructure tooling, services, and documentation with a single, consistent UI.

v1.54.0-next.3

kagent sandbox

Kagent is an open source programming framework designed for DevOps and platform engineers to run AI agents in Kubernetes

v0.10.0-rc2

What's Changed

Features

Bug Fixes

Other Changes

Full Changelog: v0.10.0-rc1...v0.10.0-rc2

Dapr graduated

The Distributed Application Runtime (Dapr) provides APIs that simplify microservice architecture development and increases developer productivity. Whether your communication pattern is service-to-service invocation or pub/sub messaging, Dapr helps you write resilient and secured microservices....

Dapr Runtime v1.17.11

Dapr 1.17.11

This update contains the following bug fix:

Actor reminders and jobs fail to register when their name or actor ID contains characters such as | or @

Problem

Registering an actor reminder through the Scheduler service failed when the reminder name, or the actor ID it belongs to, contained certain characters such as the pipe | or at sign @.
The same characters are accepted when invoking actors and when saving actor state, so an actor that worked everywhere else could not have a reminder created for it.

The error returned in this case was also misleading:

a lowercase RFC 1123 subdomain must consist of lower case alphanumeric characters, '-' or '.', and must start and end with an alphanumeric character (e.g. 'example.com', regex used for validation is '[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*')

It claimed only lowercase names were allowed even though uppercase names are in fact accepted, and it did not describe which characters were actually rejected.

Impact

You were affected if you used Scheduler-backed actor reminders (the default since 1.15) and your reminder names, actor IDs, or scheduled job names contained characters outside the strict DNS-1123 set, for example |, @, or uppercase letters.

Root Cause

The Scheduler composes each reminder or job into a single name of the form actorreminder||<namespace>||<type>||<id>||<name> (or app||<namespace>||<appID>||<name> for jobs), using || as an internal delimiter.
Each ||-delimited segment was then validated against Kubernetes' DNS-1123 subdomain rules, which only permit lowercase alphanumeric characters, -, and ..
This was far stricter than the character set Dapr already accepts at its API edge, producing the inconsistency between actor invocation and reminder registration.
Because the validator lowercased each segment before checking it, uppercase names passed in practice while the surfaced error still referred to lowercase-only RFC 1123 subdomains.

Solution

The Scheduler now validates names using the same policy Dapr applies at its API edge, so anything accepted for actor invocation can also be used for a reminder or job.
Reminder names, job names, and actor identifiers may now contain any character except /, \, #, ?, control characters (including the NUL byte), and the exact path sequences . and ...
Uppercase letters and characters such as | and @ are allowed, and || continues to be accepted within actor IDs and names.
Listing reminders for actors whose IDs contain || now also reports the correct actor metadata.
Validation errors now describe the characters that are actually disallowed.

Istio graduated

Simplify observability, traffic management, security, and policy with the Istio service mesh.

Istio 1.31.0-alpha.2

Logging Operator (Kube Logging) sandbox

Logging operator for Kubernetes

6.8.0

What's Changed

New or updated images

component image
operator ghcr.io/kube-logging/logging-operator:6.8.0
axosyslog ghcr.io/axoflow/axosyslog:4.26.0
fluentd ghcr.io/kube-logging/logging-operator/fluentd:6.8.0-full
syslog-ng-reloader ghcr.io/kube-logging/logging-operator/syslog-ng-reloader:6.8.0
config-reloader ghcr.io/kube-logging/logging-operator/config-reloader:6.8.0
fluentd-drain-watch ghcr.io/kube-logging/logging-operator/fluentd-drain-watch:6.8.0
buffer-volume-metrics ghcr.io/kube-logging/logging-operator/node-exporter:6.8.0
axosyslog exporter ghcr.io/axoflow/axosyslog-metrics-exporter:0.0.16
custom-runner ghcr.io/kube-logging/custom-runner:v1.0.0
fluentd-version rubygems.org/gems/fluentd/versions/1.19.3
fluentbit-version ghcr.io/fluent/fluent-bit:5.1.0

Install with helm

helm install logging-operator oci://ghcr.io/kube-logging/helm-charts/logging-operator --version=6.8.0

Breaking changes

A duplicate parser name stops Fluent Bit from starting

Fluent Bit 5.1.0 makes a duplicate parser name fatal where 5.0 logged a warning and carried on.
A customParsers entry reusing a built-in name, such as json, docker, cri or
kube-custom, now crash-loops the DaemonSet. The parser the operator generates itself does not
collide. This is not in the Fluent Bit release notes; we found it while testing the bump.

Rename any colliding parser before upgrading, or pin the Fluent Bit image to 5.0.5.

Sidecar images older than custom-runner 1.0.0 no longer start

The config-reloader and buffer-metrics sidecars are now given an explicit -metrics-port, a flag
custom-runner gained in 1.0.0. Go rejects flags it does not know, so an older runner exits with
flag provided but not defined and the container crash-loops.

Move any configReloadImage or bufferVolumeMetricsImage pin to 6.8.0, or drop it and take
the default.

A syslog-ng image with only repository set now resolves to the pinned tag

syslogNGImage and metricsExporterImage were defaulted as whole structs, so setting just
repository, which is what you do to point at a registry mirror, left the tag empty and the
image resolved to :latest. Each field is defaulted on its own now, so the same spec pulls the
tag this release pins. If your mirror does not carry that tag, the pull fails.

Set tag explicitly if you were relying on :latest.

The syslog-ng metrics service overrides are applied

metricsService and bufferVolumeMetricsService have been on the CRD since syslog-ng support
landed, but nothing read them. They are merged into the generated Services now, so a value set
once and forgotten because it did nothing takes effect on upgrade.

Check both fields before upgrading.

Worth knowing

DB_Sync now reaches Fluent Bit. The operator wrote this setting as DB_Sync, which Fluent
Bit does not recognise, so it was dropped from the generated config. It renders as DB.sync now
and takes effect. The CRD field keeps its name and nothing needs editing, but the agent syncs its
position database as configured rather than not at all.

The syslog-ng config-reloader reports readiness. It has a readiness probe on the runner's
/readyz, which answers 503 naming the path when a configured file watch could not be
registered, the state where the reloader keeps running while silently never reloading again. A
pod that turns NotReady on upgrade was already failing to reload; the probe only makes it
visible.

IPv6

enabledIPv6 produced Services the cluster could not accept, and listeners that did not match
those Services. This release fixes three separate faults and changes what the flag does.

The operator now asks the API server which IP families it can allocate and names only those.
A cluster without an IPv6 range no longer has its Services rejected. syslog-ng also binds its
source for IPv6 under the same flag; previously only the Service changed, so an IPv6 primary
address pointed at a listener that was still IPv4 only and log ingestion stopped.

Kubernetes does not allow the primary IP family of an existing Service to change. Upgrading
therefore leaves an existing Service on its current primary family:

  • Upgrading with enabledIPv6: true: the fluentd or syslog-ng Service keeps its IPv4
    primary and gains an IPv6 secondary. It is reachable over IPv6, but IPv4 stays first in
    ipFamilies, so Prometheus keeps scraping the IPv4 address.
  • To get an IPv6 primary: delete the Service and let the operator recreate it.
    kubectl delete svc -n <control-namespace> <logging-name>-fluentd
    Expect a brief interruption. The Service comes back with a new cluster IP.
  • New installs get an IPv6 primary where the cluster has an IPv6 range.

metrics.bind is a new field on the metrics type. It sets the listen address directly, which is
the supported way to get IPv6 metrics without forcing an IPv6 primary on the Service. The
syslog-ng metrics exporter has no listen address option, so it ignores the field.

Metrics

The syslog-ng config-reloader served its metrics on the runner's own default port while the
Service, the container port and the ServiceMonitor all named 9533, so nothing was ever scraped.
It listens on 9533 now.

sidecar_reloader_* series therefore appear for syslog-ng where there were none. A panel or
alert that has only ever seen an empty target starts receiving data, in particular
sidecar_reloader_config_reloader_last_reload_error.

Enhancements

  • feat(syslog-ng): expose log_msg_size global option by @fdolsky321 in #2267
  • feat(fluent-bit): expose storage.backlog.flush_on_shutdown option by @vyncint in #2282
  • feat/support raw fluentd filter by @xtayfjpk in #2274
  • feat: add helm chart parameter to enable raw fluentd filter or not by @xtayfjpk in #2289
  • feat(chart): allow pinning the operator image by digest by @eumel8 in #2280
  • build(e2e): run the linter on the e2e module, and fix what it reports by @vyncint in #2292
  • refactor(e2e): remove dead code and correct the syslog-ng reloader image name by @vyncint in #2294
  • refactor(e2e): move common/kind to internal/kind by @vyncint in #2297
  • refactor(e2e): move common/cond to internal/wait and take plain values by @vyncint in #2298
  • perf(e2e): load the operator images in one kind invocation by @vyncint in #2300
  • refactor(e2e): add internal/fixture with the CR and tenancy builders by @vyncint in #2299
  • feat(e2e): add internal/harness and move fluentbit-multitenant onto it by @vyncint in #2304
  • fix: adopt custom-runner v1.0.0 by @csatib02 in #2311
  • Share the configcheck abnormal-failure retry and cover it by @csatib02 in #2313
  • Enable the modernize analyzer and apply it by @csatib02 in #2315

Dependency and image updates

  • chore(deps): update dependency oj to v3.17.3 [security] by @renovate[bot] in #2256
  • chore(deps): bump concurrent-ruby from 1.3.6 to 1.3.7 in /images/fluentd/outputs by @dependabot[bot] in #2257
  • chore(deps): bump oj from 3.16.11 to 3.17.3 in /images/fluentd/outputs by @dependabot[bot] in #2258
  • chore(deps): update module github.com/containerd/containerd to v1.7.33 [security] by @renovate[bot] in #2259
  • chore(deps): bump faraday from 2.14.2 to 2.14.3 in /images/fluentd/outputs by @dependabot[bot] in #2262
  • chore(deps): bump nokogiri from 1.19.3 to 1.19.4 in /images/fluentd/outputs by @dependabot[bot] in #2261
  • chore(deps): bump concurrent-ruby from 1.3.6 to 1.3.7 in /images/fluentd/filters by @dependabot[bot] in #2260
  • chore(deps): update dependency fluent-plugin-s3 to v1.8.5 [security] by @renovate[bot] in #2265
  • chore(deps): bump fluentd from 1.18.0 to 1.19.3 in /images/fluentd/filters by @dependabot[bot] in #2266
  • chore(deps): update module oras.land/oras-go/v2 to v2.6.1 [security] by @renovate[bot] in #2269
  • chore(deps): bump excon from 1.3.0 to 1.5.0 in /images/fluentd/outputs by @dependabot[bot] in #2268
  • chore(deps): bump oras.land/oras-go/v2 from 2.6.1 to 2.6.2 in /e2e by @dependabot[bot] in #2270
  • chore(deps): update module golang.org/x/net to v0.56.0 [security] by @renovate[bot] in #2276
  • chore(deps): update module google.golang.org/grpc to v1.82.1 [security] by @renovate[bot] in #2278
  • chore(deps): update module golang.org/x/text to v0.39.0 [security] by @renovate[bot] in #2277
  • chore(deps): update module go.opentelemetry.io/otel to v1.44.0 [security] by @renovate[bot] in #2281
  • chore(deps): update module github.com/klauspost/compress to v1.18.7 [security] by @renovate[bot] in #2290
  • build(deps): bump json from 2.20.0 to 2.21.2 in /images/fluentd/filters by @dependabot[bot] in #2312
  • chore(deps): update all dependencies by @renovate[bot] in #2244

Bug fixes

  • fix: support custom CA certificates for S3 outputs by @vyncint in #2272
  • fix: enable dual-stack for Fluent Bit metrics services by @vyncint in #2273
  • fix(ipv6): set IPv6 as primary address family when enabledIPv6 is set by @eumel8 in #2279
  • fix(chart): support HostTailer namespaces by @vyncint in #2275
  • fix(syslog-ng): keep default image tags when only the repository is set by @vyncint in #2283
  • fix(fluentd): propagate dnsPolicy to the configcheck pod by @vyncint in #2285
  • docs(plugins): fix dedot description from being incorrectly described as concat by @halkeye in #2284
  • fix(e2e): bound kind CLI invocations with a timeout by @vyncint in #2288
  • fix(configcheck): merge aggregator level configCheck field by field by @vyncint in #2286
  • fix(e2e): derive the elasticsearch readiness budget from the test deadline by @vyncint in #2293
  • fix(e2e): call LogProducer on the test goroutine by @vyncint in #2295
  • fix(e2e): make coverage collection uniform and cover every cluster by @vyncint in #2296
  • fix(e2e): remove the elasticsearch kill loop and five flake sources by @csatib02 in #2302
  • fix(e2e): give every kind cluster its own kubeconfig by @vyncint in #2301
  • fix(e2e): share the elasticsearch readiness budget between the waits by @vyncint in #2307
  • fix(fluentd): propagate sidecarContainers to the configcheck pod by @pujitha24 in #2303
  • Make enabledIPv6 work without breaking single-stack clusters by @csatib02 in #2310

New Contributors

Full Changelog: 6.7.0...6.8.0

Prometheus graduated

metrics-based monitoring and alerting

3.14.0-rc.0 / 2026-08-06

  • [CHANGE] API: Deprecate the stats query parameter of /api/v1/query and /api/v1/query_range for values other than true and all. Other values still enable basic statistics but now return a deprecation warning; they will be rejected in the next major release. #19124
  • [CHANGE] API: /api/v1/status/config now correctly shows separator: "" and replacement: "" in relabel configs when explicitly set to empty, instead of omitting them. #18653
  • [CHANGE] Discovery/Hetzner: Drop the __meta_hetzner_datacenter label for hcloud targets, following its removal from the Hetzner Cloud API. #19269
  • [CHANGE] PromQL: Enable duration expressions by default. The promql-duration-expr feature flag is now a no-op. #19033
  • [CHANGE] PromQL: Promote first_over_time to stable. It no longer requires the promql-experimental-functions feature flag. #19093
  • [FEATURE] Discovery: Add Oracle Cloud Infrastructure compute service discovery (oci_sd_configs). #18919
  • [FEATURE] PromQL: Add experimental start_timestamp(instant-vector) function returning the start timestamp of each sample in the given vector. Requires the use-start-timestamps feature flag. #19089
  • [FEATURE] PromQL: Allow rate() and increase() to use start timestamps as an alternative for rate extrapolation. Hidden behind the use-start-timestamps feature flag. #18619
  • [FEATURE] TSDB: Add experimental support for encoding start timestamps in histograms and float histograms. Hidden behind the histograms-st-encoding feature flag. #18609
  • [ENHANCEMENT] OTLP: Emit a warning when OTLP attribute names collide into the same Prometheus label after sanitization (e.g. k8s.pod.name and k8s_pod_name both become k8s_pod_name), and expose the prometheus_api_otlp_translation_warnings_total counter labelled by category to track such warnings. #18957
  • [ENHANCEMENT] Promtool: Add --remote-write.path flag to push metrics for backends that use a non-default remote-write endpoint. #19086
  • [ENHANCEMENT] Remote write: Forward histogram start timestamps in the remote write V2 protocol. #18903
  • [ENHANCEMENT] TSDB: Add prometheus_tsdb_head_native_histogram_series and prometheus_tsdb_head_native_histogram_buckets gauges tracking the number of native histogram series and buckets in the head. #19170
  • [ENHANCEMENT] UI: Add syntax highlighting, autocompletion, and linting for PromQL duration expressions (step(), range(), min_of(), max_of()) in range selectors and subqueries. #18625
  • [ENHANCEMENT] UI: Add copy button next to rule names on the Rules and Alerts pages. #18706
  • [ENHANCEMENT] UI: Improve rule group title contrast on the Rules page. #19181
  • [PERF] Speed up regex label matchers matching a set of literal values (e.g. {job=~"foo|bar|baz"}). #18833
  • [PERF] Remote read: Improve remote read throughput by removing unnecessary per-write flushing. #18470
  • [PERF] Scrape: Parse text and OpenMetrics formats without recursion, preventing stack overflow from deeply nested or malicious exposition input. #19143
  • [PERF] Scrape: Reduce native histogram scrape parsing allocations by ~49%. #19282
  • [PERF] TSDB: Speed up queries on series with many in-memory chunks. #18300
  • [BUGFIX] Alerting: Fix 100% CPU usage on shutdown that could delay graceful shutdown and trigger timeout-based kills. #17859
  • [BUGFIX] Discovery/AWS: Stop promtool check config from making AWS metadata service (IMDS) network calls when the region field is omitted in EC2, ECS, RDS, MSK, ElastiCache, and Lightsail service discovery configs. #19037
  • [BUGFIX] Discovery/Docker: Set a request timeout for docker_sd and dockerswarm_sd on unix, npipe, and tcp hosts. Previously an unresponsive daemon could freeze discovery indefinitely, silently pinning targets to a stale snapshot. #19237
  • [BUGFIX] Discovery/Docker: Fix panic in Docker Swarm service discovery when a service runs as a plugin or network-attachment. #19102
  • [BUGFIX] Discovery/Docker: Fix discovery of IPv6-only containers. #18778
  • [BUGFIX] PromQL: Fix case-insensitive regex label matchers silently dropping matching values. #19167
  • [BUGFIX] PromQL: Fix mad_over_time returning 0 instead of NaN when the range contains a NaN sample. #19040
  • [BUGFIX] Promtool: Accept --enable-feature=promql-binop-fill-modifiers in check rules, which previously rejected valid fill()/fill_left()/fill_right() expressions. #19153
  • [BUGFIX] Remote write: Respect the AZURE_FEDERATED_TOKEN_FILE environment variable for workload identity authentication instead of hardcoding the token file path. #18973
  • [BUGFIX] Rules: Clean up stale rule_group_last_rule_duration_sum_seconds and rule_group_last_restore_duration_seconds series when a rule group is removed or renamed on reload. Previously each reload leaked two series per dropped group, growing /metrics cardinality over time. #19107
  • [BUGFIX] Scrape: Fix scrape manager spinning at 100% CPU on shutdown. #19149
  • [BUGFIX] TSDB: Fix silent data loss and potential crash loop when stale_series_compaction_threshold is used in the config file. #19016
  • [BUGFIX] TSDB: Fix potential data loss on restart when out-of-order ingestion is enabled and blocks are compacted. #19016
  • [BUGFIX] TSDB: Fix prometheus_tsdb_head_stale_series over-counting and early eviction of series that change between float, integer histogram, and float histogram sample types. #19183
  • [BUGFIX] TSDB: Fix goroutine and file handle leaks when Prometheus fails to open a corrupt TSDB. On Windows, the leaked directory handle also prevented TSDB directory removal. #18291
  • [BUGFIX] TSDB: Fix out-of-order queries blocking compaction for hours, causing memory usage to grow. #19013
  • [BUGFIX] TSDB: Fix deleted series causing missing samples and errors after restart. #19140
  • [BUGFIX] TSDB: Fix native histogram data becoming incorrect after restart. #19202
  • [BUGFIX] TSDB: Surface query errors that were previously silently discarded. #19120
  • [BUGFIX] TSDB: Honour the configured float chunk encoding when compaction rewrites chunks; previously chunks encoded with --enable-feature=xor2-encoding could silently revert to XOR after compaction. #19145
  • [BUGFIX] UI: Show the delete-series form on the TSDB Status page when --web.enable-admin-api is enabled. #19025
werf sandbox

werf is a solution for implementing efficient and consistent software delivery to Kubernetes. It covers the entire CI/CD lifecycle and all related artifacts, glues commonly used tools (Git, Docker/Buildah, Helm, K8s) and facilitates best practices.

v3.1.0

Changelog

Features

  • --no-values-schema-validation; don't break values.schema.json with service values (#7756) (01eeb94)
  • add support for additional patches files and disable default patches (#7735) (01aa2e5)
  • build: add per-project meta-repo safeguard and migration (#7739) (4f7de94)
  • bump nelm version (#7731) (ca44562)
  • embed kubeconform schemas (#7729) (23bcaf1)

Bug Fixes

  • build, buildah: serialize concurrent base image pulls (#7664) (6eb9144)
  • build, dockerfile: allow dockerfile outside the build context (#7722) (a5c2011)
  • build, stapel, git: remove git commit ancestry check on reuse (#7746) (544a07d)
  • build, stapel: make service script executable regardless of umask (#7720) (8b67264), closes #2339
  • build: drop empty image digest warnings from the build report (#7717) (24babbb), closes #7667
  • build: reuse content anchors without git commits (#7764) (5df466c)
  • build: stop re-fetching submodules the checkout already has (#7736) (8ff0bf3)
  • build: validate image names in werf.yaml (#7711) (cd993db)
  • deploy: optimize local validation args (#7760) (6a4c6c4)
  • dev: self-heal a stale worktree index.lock left by a killed run (#7733) (ca0e803)
  • dev: warm a persistent dev-index so --dev stops re-reading unchanged files (#7732) (f0b13cc)

Installation

To install werf we strongly recommend following these instructions.

Alternatively, you can download werf binaries from here:

These binaries were signed with PGP and could be verified with the werf PGP public key. For example, werf binary can be downloaded and verified with gpg on Linux with these commands:

curl -sSLO "https://tuf.werf.io/targets/releases/3.1.0/linux-amd64/bin/werf" -O "https://tuf.werf.io/targets/signatures/3.1.0/linux-amd64/bin/werf.sig"
curl -sSL https://werf.io/werf.asc | gpg --import
gpg --verify werf.sig werf
werf sandbox

werf is a solution for implementing efficient and consistent software delivery to Kubernetes. It covers the entire CI/CD lifecycle and all related artifacts, glues commonly used tools (Git, Docker/Buildah, Helm, K8s) and facilitates best practices.

v2.77.0

Changelog

Features

  • cleanup: add registry-side cleanup report (#7806) (8a6250b)

Installation

To install werf we strongly recommend following these instructions.

Alternatively, you can download werf binaries from here:

These binaries were signed with PGP and could be verified with the werf PGP public key. For example, werf binary can be downloaded and verified with gpg on Linux with these commands:

curl -sSLO "https://tuf.werf.io/targets/releases/2.77.0/linux-amd64/bin/werf" -O "https://tuf.werf.io/targets/signatures/2.77.0/linux-amd64/bin/werf.sig"
curl -sSL https://werf.io/werf.asc | gpg --import
gpg --verify werf.sig werf
werf sandbox

werf is a solution for implementing efficient and consistent software delivery to Kubernetes. It covers the entire CI/CD lifecycle and all related artifacts, glues commonly used tools (Git, Docker/Buildah, Helm, K8s) and facilitates best practices.

v3.2.0 [dev]

Changelog

Features

  • add case-insensitive-condition-tracking feature gate (#7801) (8043316)
  • build: show low-level operations time summary in debug mode (#7675) (4f65aef)
  • cleanup: add registry-side cleanup report (#7806) (8a6250b)
  • cleanup: name the --meta-repo address in the cleanup report (c11fdfb)
  • deploy: embed deno binary into werf release binaries behind embedwerfdeno (#7725) (468ba22)

Bug Fixes

  • build, buildah: prevent parallel recovery failures (#7774) (fd5758d)
  • build, buildah: retry pull when cached image id is missing (#7669) (9d64035)
  • buildah: prevent concurrent Dockerfile build races (#7798) (f609194)
  • buildah: prevent concurrent stderr access (#7788) (fc9c375)
  • build: avoid panicking on late worker logs (#7785) (4a89693)
  • build: make repo-built from:scratch images readable by dive (#7765) (54b0921)
  • deploy: prevent progress printer race during release tracking (#7805) (1b46987)
  • docker: prevent race reports during Docker builds (#7777) (6d6af8d)
  • helm: prevent concurrent action initialization (#7796) (bad9bfd)
  • logboek: prevent concurrent stream races (#7802) (f80e827)
  • registry: prevent concurrent export races (#7799) (2bf41ec)
  • storage: prevent concurrent final-stage list access (#7787) (9ab8115)

Installation

To install werf we strongly recommend following these instructions.

Alternatively, you can download werf binaries from here:

These binaries were signed with PGP and could be verified with the werf PGP public key. For example, werf binary can be downloaded and verified with gpg on Linux with these commands:

curl -sSLO "https://tuf.werf.io/targets/releases/3.2.0/linux-amd64/bin/werf" -O "https://tuf.werf.io/targets/signatures/3.2.0/linux-amd64/bin/werf.sig"
curl -sSL https://werf.io/werf.asc | gpg --import
gpg --verify werf.sig werf
Kyverno graduated

Pod security,Policy-as-code,Governance,Software supply chain

v1.19.0-rc.2

No content.

werf sandbox

werf is a solution for implementing efficient and consistent software delivery to Kubernetes. It covers the entire CI/CD lifecycle and all related artifacts, glues commonly used tools (Git, Docker/Buildah, Helm, K8s) and facilitates best practices.

latest-signature

Notes added by 'git notes append'

werf sandbox

werf is a solution for implementing efficient and consistent software delivery to Kubernetes. It covers the entire CI/CD lifecycle and all related artifacts, glues commonly used tools (Git, Docker/Buildah, Helm, K8s) and facilitates best practices.

v2.76.0 [beta]

Changelog

Features

  • add case-insensitive-condition-tracking feature gate (#7801) (8043316)
  • build: show low-level operations time summary in debug mode (#7675) (4f65aef)

Bug Fixes

  • build, buildah: prevent parallel recovery failures (#7774) (fd5758d)
  • build: avoid panicking on late worker logs (#7785) (4a89693)
  • docker: prevent race reports during Docker builds (#7777) (6d6af8d)
  • optimize release get (8043316)

Installation

To install werf we strongly recommend following these instructions.

Alternatively, you can download werf binaries from here:

These binaries were signed with PGP and could be verified with the werf PGP public key. For example, werf binary can be downloaded and verified with gpg on Linux with these commands:

curl -sSLO "https://tuf.werf.io/targets/releases/2.76.0/linux-amd64/bin/werf" -O "https://tuf.werf.io/targets/signatures/2.76.0/linux-amd64/bin/werf.sig"
curl -sSL https://werf.io/werf.asc | gpg --import
gpg --verify werf.sig werf
Kyverno graduated

Pod security,Policy-as-code,Governance,Software supply chain

kyverno-chart-3.9.0-rc.2

kyverno-chart-3.9.0-rc.2

Prometheus graduated

metrics-based monitoring and alerting

v0.314.0-rc.0

v0.314.0-rc.0

Longhorn incubating

Cloud-native distributed storage for Kubernetes

Longhorn v1.12.1-rc4

DON'T UPGRADE from/to any RC/Preview/Sprint releases because the operation is not supported.

Resolved Issues in this release

Highlight

Feature

  • [BACKPORT][v1.12.1][FEATURE] Support Kubernetes CPU Manager for Longhorn V2 instance-manager SPDK CPU assignment 13320 - @yangchiu @mantissahz @Copilot

Improvement

  • [BACKPORT][v1.12.1][IMPROVEMENT] Improve V2 Engine Frontend Handoff Tolerance in Split Topology 13569 - @davidcheng0922 @chriscchien
  • [BACKPORT][v1.12.1][IMPROVEMENT] Allow configuring SPDK iobuf small pool size 13675 - @yangchiu @hookak
  • [BACKPORT][v1.12.1][IMPROVEMENT] go-common-libs: kill the child process when command execution times out 13621 - @hookak
  • [BACKPORT][v1.12.1][IMPROVEMENT] always setup NetworkPolicy for the internal communication 13439 - @COLDTURNIP @roger-ryao
  • [BACKPORT][v1.12.1][IMPROVEMENT] Allow persisting number of hugepages using longhornctl 13535 - @chriscchien @bachmanity1
  • [BACKPORT][v1.12.1][IMPROVEMENT] Steer host RPS away from SPDK reactor cores 13502 - @bachmanity1 @roger-ryao
  • [BACKPORT][v1.12.1][IMPROVEMENT] updateBackupCompressionMethod may write the Volume even when the method is unchanged 13480 - @yangchiu
  • [BACKPORT][v1.12.1][IMPROVEMENT] Add metrics to collect information about V2 data engine usage 13262 - @derekbit @chriscchien
  • [BACKPORT][v1.12.1][IMPROVEMENT] Improving error transparency for volume attachment failure 13431 - @derekbit @chriscchien
  • [BACKPORT][v1.12.1][IMPROVEMENT] Allow configuring SPDK iobuf large pool size 13415 - @chriscchien @bachmanity1
  • [BACKPORT][v1.12.1][IMPROVEMENT] V2 volume write I/O stalls(~10s) when a replica is removed during migration 13310 - @hookak @chriscchien
  • [BACKPORT][v1.12.1][IMPROVEMENT] Support mTLS encrypted communication for remaining gRPC services in instance manager 13299 - @COLDTURNIP @yangchiu
  • [BACKPORT][v1.12.1][IMPROVEMENT] Add metrics to collect information about LONGHORN_DISTRO 13253 - @derekbit @chriscchien

Bug

  • [BACKPORT][v1.12.1][BUG] Host OS nvmf-autoconnect connects kernel initiators to v2 replica subsystems, stalling volume attach/detach for minutes 13660 - @hookak @chriscchien
  • [BACKPORT][v1.12.1][BUG] Longhorn Helm Chart NetworkPolicies do not honor new RKE2 "rke2-traefik" ingress controller 13665 - @COLDTURNIP @roger-ryao
  • [BACKPORT][v1.12.1][BUG] Longhorn may try to attach volumes to a node without valid IM pod during the clone 13640 - @yangchiu @shuo-wu
  • [BACKPORT][v1.12.1][BUG] Test case test_volume_scheduling_failure fails on v2 volumes 13656 - @yangchiu @c3y1huang
  • [BACKPORT][v1.12.1][BUG] v2 volumes might get stuck in deleting state 13586 - @davidcheng0922
  • [BACKPORT][v1.12.1][BUG] Backup Listing With More Than 1000 Backups fails on v2 volume due to an empty replica address in the backup status 13612 - @COLDTURNIP @chriscchien
  • [BACKPORT][v1.12.1][BUG] Encrypted rwo volume stuck in attached state and cannot detach when a privileged pod with host /var/run mounted exists on the same node. 13604 -
  • [BACKPORT][v1.12.1][BUG] Incorrect Web Link in GUI 13539 - @yangchiu @sushant-suse
  • [BACKPORT][v1.12.1][BUG] Encrypted V2 volume size is 16MB short of the claimed size 13175 - @mantissahz @roger-ryao
  • [BACKPORT][v1.12.1][BUG] CSI pods do not respect anti-affinity preset update 13548 - @chriscchien @carterli0407-cell
  • [BACKPORT][v1.12.1][BUG] Failed to add v2 block disk with virtio-scsi BDF path 13475 - @chriscchien @carterli0407-cell
  • [BACKPORT][v1.12.1][BUG] V2 encrypted volume keeps switching between Attaching and Detaching state after expand operation 13562 - @mantissahz @roger-ryao
  • [BACKPORT][v1.12.1][BUG] V1 volumes not rebuilding after cluster shutdown 13583 - @COLDTURNIP
  • [BACKPORT][v1.12.1][BUG] GCS backup target: backup of large volume fails at final .cfg PUT with SignatureDoesNotMatch (residual of #12676 in v1.12.0) 13574 - @derekbit @chriscchien
  • [BACKPORT][v1.12.1][BUG] Can not use v2 volume as block disk 13564 - @davidcheng0922
  • [BACKPORT][v1.12.1][BUG] Fail to restore a volume from a full backup if a previous backup is corrupted 13538 - @yangchiu @derekbit
  • [BACKPORT][v1.12.1][BUG] Test case Recurring Job Pod Should Not Crash fails 13568 - @yangchiu @c3y1huang
  • [BACKPORT][v1.12.1][BUG] Longhorn 1.12.0: AWS chunked encoding not supported with OCI S3 buckets 13478 - @derekbit @mantissahz @roger-ryao
  • [BACKPORT][v1.12.1][BUG] Adding V2 disk using /dev/disk/by-path/scsi-* path fails 13559 - @carterli0407-cell
  • [BACKPORT][v1.12.1][BUG] When using v2-data-engine, the virtio-scsi virtual disk is not recognized as a block device, returning the error: "not a block device: exit status 32". 13560 - @carterli0407-cell
  • [BACKPORT][v1.12.1][BUG] Error logs in longhorn-uninstall job 13549 - @yangchiu @c3y1huang
  • [BACKPORT][v1.12.1][BUG] go-spdk-helper JSON-RPC client leaks pending-request bookkeeping forever when a response never arrives after timeout 13554 -
  • [BACKPORT][v1.12.1][BUG] V2 Data Engine: UBLK fails with EINVAL on Linux kernel 6.17.0 13274 - @chriscchien @carterli0407-cell
  • [BACKPORT][v1.12.1][BUG] Kernel Workqueue Lockup and Unstable RKE2 Service After Enabling LH V2 in Harvester 13495 - @derekbit @chriscchien
  • [BACKPORT][v1.12.1][BUG] V2 expansion can report success while the engine remains at the old size 13380 - @davidcheng0922 @chriscchien
  • [BACKPORT][v1.12.1][BUG] FilesystemReadOnly never detected on kernel >= 6.12 — ext4 reports emergency_ro, not ro; read-only auto-remount silently inoperative 13482 - @yangchiu
  • [BACKPORT][v1.12.1][BUG] csi.ReplicaCount Helm values silently no-op on existing csi- deployments (only applied at first creation) 13465 - @roger-ryao
  • [BACKPORT][v1.12.1][BUG] v2 volume may crash again after the auto reattachment 13337 - @shuo-wu @roger-ryao
  • [BACKPORT][v1.12.1][BUG] V2 Volume Cannot Be Attached When the Storage Network Is Enabled 13490 - @c3y1huang
  • [BACKPORT][v1.12.1][BUG] v2 volume repeated replica reuse failure 13336 - @shuo-wu @chriscchien
  • [BACKPORT][v1.12.1][BUG] V2 Encrypted Volume Restore Fails 13365 - @mantissahz @roger-ryao
  • [BACKPORT][v1.12.1][BUG] V2 backup/snapshot can leave NVMe/TCP frontend or dm device stale, causing pod EIO on attached volumes 13332 - @davidcheng0922 @chriscchien
  • [BACKPORT][v1.12.1][BUG] (chart) ArgoCD OutOfSync when using Gateway API 13446 - @yangchiu
  • [BACKPORT][v1.12.1][BUG] Migration Engine Can Be Unexpectedly Deleted If the Target Node Is Still in Readiness Transition 13367 - @COLDTURNIP @yangchiu
  • [BACKPORT][v1.12.1][BUG] Recurring trim job fails with deadlock 13425 - @c3y1huang @roger-ryao
  • [BACKPORT][v1.12.1][BUG] volume expansion stuck 13368 - @shuo-wu @chriscchien
  • [BACKPORT][v1.12.1][BUG] pvc resize fails after iscsid restart 13412 - @yangchiu @shuo-wu
  • [BACKPORT][v1.12.1][BUG] expanding the volume fails 13384 - @chriscchien
  • [BACKPORT][v1.12.1][BUG] Test case test_rwx_delete_share_manager_pod fails because it's unable to find the exported volume in share manager pod after it's deleted and restarted 13226 - @davidcheng0922 @roger-ryao
  • [BACKPORT][v1.12.1][BUG] System Backup RecurringJob retention prunes newest CR — sorts by Status.CreatedAt (zero for Error/racing CRs) 13209 - @roger-ryao
  • [BACKPORT][v1.12.1][BUG] CSI components may have 0 running replica during upgrade 13348 - @yangchiu @carterli0407-cell
  • [BACKPORT][v1.12.1][BUG] Node update forces a complete rebuild 13357 - @mantissahz
  • [BACKPORT][v1.12.1][BUG] Creating backup for a v2 volume may fail 13191 - @mantissahz
  • [BACKPORT][v1.12.1][BUG] when uploading backup to S3 storage (NetApp appliance) it fails 13297 - @mantissahz
  • [BACKPORT][v1.12.1][BUG] spdk interrupt mode value is missing in chart/values.yaml 13269 - @yangchiu
  • [BACKPORT][v1.12.1][BUG] Test case test_best_effort_data_locality fails because there is no replica for the created volume 13225 - @carterli0407-cell

Resilience

  • [BACKPORT][v1.12.1][BUG] Transient SPDK lvol metadata failure can permanently fault a healthy v2 replica 13542 - @roger-ryao

Misc

  • [BACKPORT][v1.12.1][DOC] NetworkPolicy setup guidance 13622 - @COLDTURNIP @roger-ryao
  • [BACKPORT][v1.12.1][DOC] Chart values.yaml still refers to Data Engine V2 as experimental 13615 - @sushant-suse
  • [BACKPORT][v1.12.1][DOC] Update the minimum Kubernetes version requirement to v1.34. 13577 - @derekbit @roger-ryao
  • [BACKPORT][v1.12.1][BUG] v2 volume stuck attaching with Storage Network enabled because the EngineFrontend target uses the engine pod IP instead of StorageIP 13353 - @yangchiu @c3y1huang

Contributors

TiKV graduated

A distributed transactional key-value database. Based on the design of Google Spanner and HBase, but simpler to manage and without dependencies on any distributed filesystem

v8.5.4-20260811-198a597

[cherry-pick] [test only] raftstore: add unsafe-no-raft-log-fsync (#1

Dapr graduated

The Distributed Application Runtime (Dapr) provides APIs that simplify microservice architecture development and increases developer productivity. Whether your communication pattern is service-to-service invocation or pub/sub messaging, Dapr helps you write resilient and secured microservices....

Dapr Runtime v1.18.3-rc.2

This is the release candidate 1.18.3-rc.2

What's Changed

  • [Backport release-1.18] workflows: fresh trace roots on ContinueAsNew by @dapr-bot in #10324
  • [Backport release-1.18] actors: allow hot reloading the actor state store by @dapr-bot in #10325
  • [Backport release-1.18] placement: report stream closure exactly once by @dapr-bot in #10331
  • [Backport release-1.18] workflow: fix stalled workflows left unrecoverable by @dapr-bot in #10330
  • [Backport release-1.18] workflow: ack activity-result reminders for purged instances by @dapr-bot in #10334

Full Changelog: v1.18.3-rc.1...v1.18.3-rc.2

Runme Notebooks sandbox

A toolchain that turns Markdown into interactive, cloud-native, runnable Notebook experiences for DevOps.

v3.17.3

containerd graduated

An open and reliable container runtime

containerd 2.4.0-beta.0

Welcome to the v2.4.0-beta.0 release of containerd!
This is a pre-release of containerd

containerd 2.4 is a regular (non-LTS) release with a shorter support window,
intended for users who want to adopt new features sooner. As the release
following the 2.3 LTS, it is the point in the release cycle where previously
deprecated features may be removed, so this release may include breaking
changes; check the notes below and clear any deprecation warnings from your
current version before upgrading.

Users prioritizing stability and a longer support lifecycle should stay on the
2.3 LTS release.

This is a beta release and some functionality is still under development.

Highlights

  • Include media type in content create event (#13833)
  • Support warm image cache for erofs snapshotter (#13813)
  • Add parent path to runc checkpoint options (#13699)

Container Runtime Interface (CRI)

  • Introspect OCI runtime features for non-runc runtimes (#13504)

Image Distribution

  • Use klauspost/compress/gzip for decode (#13560)

Image Storage

  • Add forward References to the GC collection context (#13634)

Snapshotters

  • Add max size label for snapshots (#13520)

Breaking

  • Remove restore in CreateContainer (#13871)

Deprecations

  • Fix sandbox task API endpoints for non-runc runtimes (#13360)

Please try out the release binaries and report any issues at
https://github.com/containerd/containerd/issues.

Contributors

  • Maksym Pavlenko
  • Samuel Karp
  • Akihiro Suda
  • Derek McGowan
  • Wei Fu
  • Sebastiaan van Stijn
  • Chris Henzie
  • Paweł Gronowski
  • Mike Brown
  • Brian Goff
  • Jordan Liggitt
  • Austin Vazquez
  • Kazuyoshi Kato
  • Kir Kolyshkin
  • Phil Estes
  • Sergey Kanzhelev
  • ningmingxiao
  • Ahmet Alp Balkan
  • Akhil Mohan
  • Chris Ayoub
  • Damien Grisonnet
  • Esteban Ginez
  • Laura Lorenz
  • Maksim An
  • Abhishek Bhunia
  • Alan Grosskurth
  • Albin Kerouanton
  • Alex Lyn
  • Aman Raj
  • Amir Alavi
  • Amit Barve
  • Andrew Halaney
  • AprilNEA
  • Arjun Yogidas
  • Ayato Tokubi
  • Aysha Afrah Ziya
  • Ben Cressey
  • Bing Hongtao
  • Chris Crone
  • Craig Gumbley
  • Daniel De Graaf
  • Davanum Srinivas
  • Dr. Jan-Philip Gehrcke
  • Gao Xiang
  • Harshal Patel
  • Henry Wang
  • Kohei Tokunaga
  • Krisztian Litkey
  • LEI WANG
  • Mikhail Dmitrichenko
  • Nikolaus Schuetz
  • Paco Xu
  • Philip Laine
  • SaloniRathi
  • Tianon Gravi
  • ayush-panta
  • crawfordxx
  • cshung
  • s3onghyun
  • 归寂
  • 徐晓伟

Dependency Changes

  • cyphar.com/go-pathrs v0.2.1 -> v0.2.4
  • github.com/Microsoft/hcsshim v0.15.0-rc.1 -> v0.15.0-rc.3
  • github.com/ProtonMail/go-crypto v1.4.1 new
  • github.com/cilium/ebpf v0.16.0 -> v0.17.3
  • github.com/cloudflare/circl v1.6.3 new
  • github.com/containerd/containerd/api v1.11.0 -> v1.12.0-beta.0
  • github.com/containerd/imgcrypt/v2 v2.0.2 -> v2.0.3
  • github.com/containerd/nri v0.12.0 -> v0.12.1
  • github.com/containerd/ttrpc v1.2.8 -> v1.2.9
  • github.com/containerd/typeurl/v2 v2.2.3 -> v2.3.0
  • github.com/containers/ocicrypt v1.2.1 -> v1.3.2
  • github.com/cyphar/filepath-securejoin v0.6.0 -> v0.6.1
  • github.com/erofs/go-erofs v0.3.0 -> v0.3.1
  • github.com/fsnotify/fsnotify v1.9.0 -> v1.10.1
  • github.com/grpc-ecosystem/grpc-gateway/v2 v2.28.0 -> v2.29.0
  • github.com/intel/goresctrl v0.12.0 -> v0.13.0
  • github.com/klauspost/compress v1.18.5 -> v1.19.1
  • github.com/mdlayher/socket v0.5.1 -> v0.6.0
  • github.com/mdlayher/vsock v1.2.1 -> v1.3.0
  • github.com/miekg/pkcs11 v1.1.1 -> v1.1.2
  • github.com/moby/sys/user v0.4.0 -> v0.4.1
  • github.com/opencontainers/selinux v1.13.1 -> v1.15.1
  • github.com/pelletier/go-toml/v2 v2.3.0 -> v2.4.3
  • github.com/prometheus/client_golang v1.23.2 -> v1.24.0
  • github.com/prometheus/common v0.67.5 -> v0.70.0
  • github.com/prometheus/procfs v0.19.2 -> v0.21.1
  • github.com/smallstep/pkcs7 v0.1.1 -> v0.2.1
  • go.etcd.io/bbolt v1.4.3 -> v1.5.0
  • go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.68.0 -> v0.69.0
  • go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.68.0 -> v0.69.0
  • go.opentelemetry.io/otel v1.43.0 -> v1.44.0
  • go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.43.0 -> v1.44.0
  • go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.43.0 -> v1.44.0
  • go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.43.0 -> v1.44.0
  • go.opentelemetry.io/otel/metric v1.43.0 -> v1.44.0
  • go.opentelemetry.io/otel/sdk v1.43.0 -> v1.44.0
  • go.opentelemetry.io/otel/trace v1.43.0 -> v1.44.0
  • go.yaml.in/yaml/v2 v2.4.3 -> v2.4.4
  • go.yaml.in/yaml/v3 v3.0.4 new
  • golang.org/x/crypto v0.49.0 -> v0.53.0
  • golang.org/x/mod v0.35.0 -> v0.38.0
  • golang.org/x/net v0.52.0 -> v0.56.0
  • golang.org/x/oauth2 v0.35.0 -> v0.36.0
  • golang.org/x/sync v0.20.0 -> v0.22.0
  • golang.org/x/sys v0.43.0 -> v0.47.0
  • golang.org/x/term v0.41.0 -> v0.44.0
  • golang.org/x/text v0.35.0 -> v0.38.0
  • google.golang.org/genproto/googleapis/api 9d38bb4040a9 -> 3dc84a4a5aaa
  • google.golang.org/genproto/googleapis/rpc 6f92a3bedf2d -> 3dc84a4a5aaa
  • google.golang.org/grpc v1.80.0 -> v1.82.1
  • k8s.io/api v0.36.0 -> v0.36.3
  • k8s.io/apimachinery v0.36.0 -> v0.36.3
  • k8s.io/client-go v0.36.0 -> v0.36.3
  • k8s.io/component-base v0.36.0 -> v0.36.3
  • k8s.io/cri-api v0.36.0 -> v0.36.3
  • k8s.io/cri-client v0.36.0 -> v0.36.3
  • k8s.io/cri-streaming v0.36.0 -> v0.36.3
  • sigs.k8s.io/structured-merge-diff/v6 v6.3.2 -> v6.3.3
  • tags.cncf.io/container-device-interface v1.1.0 -> 49ac08dcf160

Previous release can be found at v2.3.0

Which file should I download?

  • containerd-<VERSION>-<OS>-<ARCH>.tar.gz: ✅Recommended. Dynamically linked with glibc 2.35 (Ubuntu 22.04).
  • containerd-static-<VERSION>-<OS>-<ARCH>.tar.gz: Statically linked. Expected to be used on Linux distributions that do not use glibc >= 2.35. Not position-independent.

In addition to containerd, typically you will have to install runc
and CNI plugins from their official sites too.

See also the Getting Started documentation.

Chaosblade sandbox

blade-ai-v0.6.2

blade-ai blade-ai-v0.6.2

Bundles ChaosBlade tool v1.9.0-alpha for Linux / macOS.
The Windows client ships without the blade binary (no upstream
Windows agent) — injection there runs through kubectl-native
control-plane faults, kubectl exec into cluster tool pods, and
remote ssh/kubewiz host transports. kubectl.exe on PATH is the
only local prerequisite.

Installation

macOS / Linux:

curl -fsSL https://chaosblade.io/install-agent.sh | bash

Specify version:

curl -fsSL https://chaosblade.io/install-agent.sh | bash -s -- --version 0.6.2

Windows (PowerShell):

irm https://chaosblade.io/install-agent.ps1 | iex

🌐 OSS Download Links

Alternative download links from Alibaba Cloud OSS (faster in mainland China):

Install from the OSS mirror:

curl -fsSL https://chaosblade.io/install-agent.sh | \
  BLADE_AI_MIRROR=https://chaosblade.oss-cn-hangzhou.aliyuncs.com/blade-ai/github \
  bash -s -- --version 0.6.2

Verify the download via checksums.txt before extracting.

What's Changed

🖥️ Windows Support (New)

  • blade-ai is now available on Windows (x64). Install via PowerShell:
    irm https://chaosblade.io/install-agent.ps1 | iex
  • Fault injection works out of the box with zero local dependencies — all carriers
    execute on the remote target: kubectl-native control-plane faults, kubectl exec
    into cluster tool pods, and ssh/kubewiz host transports (a local kubectl.exe is
    the only prerequisite)
  • ARM64 Windows installs automatically fall back to the x64 package, which runs
    seamlessly via Prism x64 emulation

⚙️ Agent Core

  • Strengthen the injection lifecycle: hardened execute loop, injection detection and
    debug-pod carrier handling; every carrier rejection now carries an explicit reason
    and remediation hint (chaosblade / host_shell / k8s_native providers)
  • Add issue reporting pipeline (agent/issue_report) and terminal reports store;
    introduce phase/readonly screeners replacing the legacy capability screen node
  • Extend target guard (freeze / classifier / vehicle manifest), verifier and recovery
    loops with provenance and attribution contracts
  • Full i18n of built-in prompts and diagnostics; refined postmortem, operation results,
    task snapshots and state lifecycle
  • Memory: epoch-rebase hook contract, session store/finalizer and tool compactor
    improvements; tools guard / kubectl / readonly hardening; transports executor and
    channel fixes

🧰 Skills & Capabilities

  • Introduce a declarative capability registry (skills/capabilities.py + distilled
    _capabilities/*.json artifacts), exposed via the capabilities CLI command
  • More accurate use-case syncing through improved case_sync fingerprint computation
    and catalog generator
  • Refresh host/k8s chaos skill catalogue, chaosblade command reference and kubectl
    recipes; add the invalid-mount-option ContainerCreating case

🌐 Server, CLI & TUI

  • Server: token auth middleware, recordings route, hardened turn/recover/inject stream
    routes and schema alignment
  • CLI: refined inject / confirm / recover / serve / config commands and runner exit codes
  • TUI: token auth flow, table reflow for wide tool outputs, confirm / wizard / postmortem
    component refinements, i18n (en/zh) and theme updates

📦 Release Pipeline

  • Add windows/x64 build matrix and zip packaging; checksums, OSS mirror and release
    assets now include blade-ai-windows-x64.zip
  • Replace the deprecated Node 20-based setup-ossutil action with a direct ossutil
    binary download
  • Declare hatchling artifacts for capability distillates so release wheels ship them

📝 Documentation

  • Add keep-a-changelog style CHANGELOG (EN/zh-CN); restructure README with
    locale-suffixed naming (README.md + README.zh-CN.md)

Full Changelog: blade-ai-v0.6.1...blade-ai-v0.6.2

New Contributors

Full Changelog: blade-ai-v0.5.2...blade-ai-v0.6.2

HolmesGPT sandbox

HolmesGPT is an AI agent that automates cloud-native troubleshooting, bridging knowledge gaps by investigating alerts, executing runbooks, and correlating observability data in cloud-native platforms.

0.39.0

What's Changed

  • ROB-856 Add Atlassian Rovo MCP integration documentation by @Avi-Robusta in #2373
  • ROB-855 pulling skills with github app credentials by @Avi-Robusta in #2371
  • Weekly Benchmark Results 2026-08-05_12-14 by @github-actions[bot] in #2357
  • ROB-853: support GitHub App installed on multiple orgs in github MCP addon by @Avi-Robusta in #2374

Full Changelog: 0.38.2...0.39.0