Tekton Pipeline release v0.41.0 "Nebelung Nomad"
π First LTS Release, many features promoted to beta and a new Artifact Hub Resolver !π
Remote Resolution, Propagated Parameters, CSI and Projected Workspaces promoted to Beta!
-Docs @ v0.41.0
-Examples @ v0.41.0
Installation one-liner
kubectl apply -f https://storage.googleapis.com/tekton-releases/pipeline/previous/v0.41.0/release.yaml
Attestation
The Rekor UUID for this release is 24296fb24b8ad77a0f387ec5597ae094fc78efb152ca50f4bc02f99149e5d324261f4fc32d28f92f
Obtain the attestation:
REKOR_UUID=24296fb24b8ad77a0f387ec5597ae094fc78efb152ca50f4bc02f99149e5d324261f4fc32d28f92f
rekor-cli get --uuid $REKOR_UUID --format json | jq -r .Attestation | jq .
Verify that all container images in the attestation are in the release file:
RELEASE_FILE=https://storage.googleapis.com/tekton-releases/pipeline/previous/v0.41.0/release.yaml
REKOR_UUID=24296fb24b8ad77a0f387ec5597ae094fc78efb152ca50f4bc02f99149e5d324261f4fc32d28f92f
# Obtains the list of images with sha from the attestation
REKOR_ATTESTATION_IMAGES=$(rekor-cli get --uuid "$REKOR_UUID" --format json | jq -r .Attestation | jq -r '.subject[]|.name + ":v0.41.0@sha256:" + .digest.sha256')
# Download the release file
curl "$RELEASE_FILE" > release.yaml
# For each image in the attestation, match it to the release file
for image in $REKOR_ATTESTATION_IMAGES; do
printf $image; grep -q $image release.yaml && echo " ===> ok" || echo " ===> no match";
done
Upgrade Notices
- Tekton Pipeline v0.41.0 requires Kubernetes version 1.23 or greater.
- Release EOL: Oct 30th, 2023.
Actions Required
- To allow PodSecurityAdmission to take effect, please set PodSecurity flag as
Beta
in kubernetes 1.23-1.24. See kubernetes feature gates for more information. (#5652)
Deprecation Notices
- π¨ ClusterTasks are deprecated. Please use the cluster resolver instead. (#5545)
Backwards incompatible changes
- Any resolvers being used other than built-in resolvers will need to be updated to use ResolutionRequest v1beta1 (#5515)
- Starting from this release, Custom Task Runs controllers need to implement the
Timeout
on their own, PipelineRun reconciler would not setRun.Spec.Status == RunCancelled
upon Run timeout. (#5658)
Changes
Features
- β¨ [TEP-0115] Support Artifact Hub in Hub Resolver (#5666)
The Hub Resolver will have a new type
field to indicate the type of Hub from where to pull the resource. The default hub type is updated from the Tekton Hub to the Artifact Hub. Please see more details in TEP-0115
- β¨ CSI workspace to Beta (#5628)
CSI workspaces are promoted to beta/stable API
- β¨ Add extra display columns for resource resolution (#5602)
Add more details (start time, end time, owner) in the default view of resource resolutions
- β¨ Propagated Parameters for Finally Tasks (#5593)
Propagated Parameters extended to Finally
tasks.
- β¨ Add Provenance field in TaskRun&PipelineRun status (#5580)
Add Provenance field in TaskRun&PipelineRun status that wraps all the information we might need from pipeline side.
It only contains ConfigSource at the moment, but it can be extended to have more subfields in future.
- β¨ Add ConfigSource field in (#5551)
Add provenance-related field in ResolutionRequest.status.
- β¨ Propagated parameters to beta (#5540)
Promote propagated parameters to beta.
- β¨ Remove alpha feature gate from projected workspaces (#5530)
Projected workspaces are promoted to beta/stable API
- β¨ Move remote resolution out of alpha (#5515)
action required: Any resolvers being used other than built-in resolvers will need to be updated to use ResolutionRequest v1beta1. Remote resolution of Pipelines and Tasks promoted to beta, and ResolutionRequest v1beta1 introduced to support array and object parameters for resolvers.
- β¨ resolution/framework : inject the request name in the context (#5678)
- β¨ [TEP-0089] Modify entrypoint to sign the results. (#5676)
- β¨ [TEP-0089] Apis to handle SPIRE signing and verification. (#5647)
- β¨ Propagated Parameters e2e tests (#5599)
- β¨ [TEP-0091] Trusted resources alpha add sigstore packages (#5552)
- β¨ TEP-0114: Tests Wait Custom Task Retries and TimeOut (#5523)
Fixes
- π Resolve PodSecurityAdmission restrictions on 1.23+ for deprecated PodSecurityPolicy (#5652)
Action required: If using Kubernetes 1.22, set PodSecurity flag to true to enforce a restricted pod security level in Tekton namespaces. See https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/#feature-gates-for-graduated-or-deprecated-features for more information.
- π Remove webhook validation on delete (#5610)
Bug fix: skip validation of CRDs on deletion
- π Merge Labels and Annotations instead of override (#5597)
The PipelineRun
and TaskRun
controller will not override label set by other tools during the reconciler loop, and will merge them instead
- π Write TaskRun.Status.TaskSpec with replaced spec on every reconcile run (#5576)
Fix TaskRun parameter etc replacement logic to persist in the TaskRun's Status properly
- π fix 5569 pipelinerun hang on Unknown status due to duplicated task parameters (#5575)
Fix PipelineRun hang on Unknown status when duplicated params are defined in a PipelineTask
- π Apply replacements to workspace subpath for finally tasks (#5572)
Variable replacement is now properly performed for workspace sub-paths in finally tasks.
- π Fix taskrun not working with workspace having volumeClaimTemplate (#5559)
Fix taskrun not working with workspace having volumeClaimTemplate
- π Replace deprecated PodSecurityPolicy with PodSecurityAdmission enforcement (#5536)
action required: To allow PodSecurityAdmission to take effect, please set PodSecurity flag as Beta
in 1.23-1.24. See https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/#feature-gates-for-graduated-or-deprecated-features for more information.
- π Resolve the Flaky Test - TestWaitCustomTask_PipelineRun (#5658)
ACTION REQUIRED: Starting from this release, Custom Task Runs controllers need to implement the Timeout
on your own, PipelineRun reconciler would not set Run.Spec.Status == RunCancelled
upon Run timeout.
- π Add Beta feature gate for v1 Projected Workspace (#5640)
- π Fix paramValue Type for bundle conversion to resolver (#5625)
- π Fix v1 PipelineRun CRD conversionReviewVersions and conversion typo (#5619)
- π Revert PSP migration to PSA (#5605)
- π Fix empty paramValueType conversion (#5506)
- π Increase timeout for entrypoint waiter tests (#5626)
Misc
- π¨ Remove minimal-release.yaml and resolvers.yaml (#5671)
Separate resolvers.yaml manifest removed because resolvers are now included in release.yaml
- π¨ Mark pipelineRef.bundle and taskRef.bundle as deprecated (#5656)
pipelineRef.bundle and taskRef.bundle are deprecated in favor of using the bundles resolver
- π¨ bump knative.dev/pkg dep to latest (#5643)
Update knative.dev/pkg dependency for support of k8s 1.25.x
- π¨ tekton: make sure the git workingdir is not dirtyβ¦ (#5573)
Binary file (standard input) matches
- π¨ Change image refs: distroless.dev -> cgr.dev/chainguard (#5542)
Images are based on cgr.dev/chainguard/* instead of the exactly equivalent distroless.dev/* image references.
- π¨ Update ClusterRoles (#5596)
Update aggregate ClusterRoles to include Run resources used for custom tasks and remove references to Condition which was removed in v0.37.0
- π¨ Deprecate ClusterTasks (#5545)
Action required: ClusterTasks are deprecated. Please use the cluster resolver instead.
- π¨ TEP-096 - Rename 'resources' to 'computeResources' in v1 taskRun (#5493)
Renames the resources
to computeResources
of task.spec.steps[].resources
, task.spec.stepTemplate.resources
, task.spec.sidecars[].resources
, taskRun.spec.stepOverrides[].resources
, taskrun.spec.sidecarOverrides[].resources
. Renames stepOverrides
and sidecarOverrides
to stepSpecs
and sidecarSpecs
.
- π¨ Bump HorizontalPodAutoscaler apiVersion to v2 (#5130)
Webhook HPA uses autoscaling/v2 instead of the deprecated autoscaling/v2beta1. This also brings the minimum kubernetes version to v1.23.0
- π¨ More places to use kmap.Union to merge maps (#5665)
- π¨ Use kmap.Union to merge two maps (#5660)
- π¨ Ensure resource defaulting is always done regardless of ref type. (#5651)
- π¨ migrate PipelineRun to use YAMLParser Reconciler_TestReconcileTaskResolutionError (#5644)
- π¨ refactor test
Test_storePipelineSpec
to use yml parser (#5561) - π¨ Refactor ensureConfigurationConfigMapsExist to reduce duplicate code (#5508)
- π¨ Bump github.com/sigstore/sigstore from 1.4.4 to 1.4.5 (#5686)
- π¨ Bump github.com/stretchr/testify from 1.8.0 to 1.8.1 (#5685)
- π¨ Bump github.com/containerd/containerd from 1.6.8 to 1.6.9 (#5680)
- π¨ Bump github.com/google/go-containerregistry from 0.11.0 to 0.12.0 (#5674)
- π¨ fix tekton documentation contributor`s guide link (#5669)
- π¨ Pin knative/pkg to 1.8 (#5661)
- π¨ Bump k8s.io/client-go from 0.25.2 to 0.25.3 (#5657)
- π¨ Bump k8s.io/api from 0.25.2 to 0.25.3 (#5655)
- π¨ Bump k8s.io/apimachinery from 0.25.2 to 0.25.3 (#5654)
- π¨ Bump google.golang.org/grpc from 1.50.0 to 1.50.1 (#5648)
- π¨ preallocate memory (#5638)
- π¨ Bump github.com/sigstore/sigstore from 1.4.3 to 1.4.4 (#5630)
- π¨ Bump github.com/spiffe/spire-api-sdk from 1.4.2 to 1.4.4 (#5618)
- π¨ Bump github.com/sigstore/sigstore from 1.4.2 to 1.4.3 (#5617)
- π¨ Bump google.golang.org/grpc from 1.49.0 to 1.50.0 (#5615)
- π¨ tekton: using golang 1.18.7 on release publish tasks (#5612)
- π¨ Minor Fix - There's An Error in The Example of Using Resources in Task (#5609)
- π¨ Add git-resolver/PipelineTask example to tests (#5604)
- π¨ tekton: do not fail on
git status -s
(#5587) - π¨ V1: sync v1beta1 changes for pipeline CRDs (#5578)
- π¨ Bump github.com/jenkins-x/go-scm from 1.11.19 to 1.11.29 (#5577)
- π¨ OWNERS: move dlorenc to alumni (#5547)
- π¨ Update ko to v0.12.0 (#5539)
- π¨ Bump github.com/cloudevents/sdk-go/v2 from 2.11.0 to 2.12.0 (#5535)
- π¨ Add the ability to mock more SCM data for git resolver tests (#5531)
- π¨ Bump google.golang.org/protobuf from 1.28.0 to 1.28.1 (#5519)
- π¨ Bump gopkg.in/square/go-jose.v2 from 2.5.1 to 2.6.0 (#5518)
- π¨ Bump google.golang.org/grpc from 1.46.0 to 1.49.0 (#5517)
- π¨ Bump github.com/spiffe/spire-api-sdk from 1.3.1 to 1.4.2 (#5516)
- π¨ Add "beta" value to
enable-api-fields
(#5325) - π¨ fix PR template (#5308)
Docs
- π Add missing links in releases.md (#5624)
- π Refactor developer documentation (#5622)
- π Clarify API policy for CustomRuns (#5621)
- π Fix kind value type in bundle-resolver docs (#5614)
- π Simplify and consolidate release specific docs (#5608)
- π Fix Hub Resolver doc typo (#5598)
- π Add contacts for security in topical ownership (#5589)
- π Add release documentation for Pipeline (#5586)
- π Add the openssf badge to the main README (#5570)
- π Update how-to-write-a-resolver doc (#5544)
- π Fix gcloud config syntax for e2e test setup (#5543)
- π README.md: update with latest release (v0.40.0) (#5526)
- π Update API spec doc to reflect the new fields introduced from TEP75&76 (#5511)
- π Update alpha features table (#5510)
- π Add developer documentation on k8s controllers (#5503)
Thanks
Thanks to these contributors who contributed to v0.41.0!
- β€οΈ @0xFelix
- β€οΈ @AlanGreene
- β€οΈ @JeromeJu
- β€οΈ @QuanZhang-William
- β€οΈ @XinruZhang
- β€οΈ @Yongxuanzhang
- β€οΈ @abayer
- β€οΈ @afrittoli
- β€οΈ @chengjoey
- β€οΈ @chitrangpatel
- β€οΈ @chuangw6
- β€οΈ @dependabot[bot]
- β€οΈ @florianl
- β€οΈ @imjasonh
- β€οΈ @jagathprakash
- β€οΈ @k4leung4
- β€οΈ @khrm
- β€οΈ @lbernick
- β€οΈ @lcarva
- β€οΈ @my-git9
- β€οΈ @piyush-garg
- β€οΈ @pritidesai
- β€οΈ @vdemeester
- β€οΈ @wlynch
Extra shout-out for awesome release notes:
- π @0xFelix
- π @AlanGreene
- π @JeromeJu
- π @QuanZhang-William
- π @XinruZhang
- π @abayer
- π @afrittoli
- π @chengjoey
- π @chitrangpatel
- π @chuangw6
- π @imjasonh
- π @k4leung4
- π @lbernick
- π @piyush-garg
- π @vdemeester