Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
43 commits
Select commit Hold shift + click to select a range
bb55434
Update to Kubernetes v1.33
mikkeloscar Jun 5, 2025
cd48e61
Merge dev to dev-to-kube-1.33
k8s-on-aws-manager-app[bot] Aug 19, 2025
94034ea
Merge dev to dev-to-kube-1.33
k8s-on-aws-manager-app[bot] Aug 19, 2025
06a2ef9
Merge dev to dev-to-kube-1.33
k8s-on-aws-manager-app[bot] Aug 22, 2025
5807c1a
Merge pull request #9774 from zalando-incubator/dev-to-kube-1.33
mikkeloscar Aug 22, 2025
d36d189
update kube version
Aug 22, 2025
32d2078
update 1.33 branch to 1.33.4
Aug 22, 2025
21321d4
add build that worked for all images
Aug 25, 2025
5568cb6
Merge pull request #9782 from zalando-incubator/kube-1.33.4
demonCoder95 Aug 26, 2025
3de86f9
Merge dev to dev-to-kube-1.33
k8s-on-aws-manager-app[bot] Aug 26, 2025
f79e70f
Merge dev to dev-to-kube-1.33
k8s-on-aws-manager-app[bot] Aug 27, 2025
057e95b
Merge pull request #9785 from zalando-incubator/dev-to-kube-1.33
mikkeloscar Aug 28, 2025
0a2ad57
Merge dev to dev-to-kube-1.33
k8s-on-aws-manager-app[bot] Aug 28, 2025
141bd1a
Merge pull request #9793 from zalando-incubator/dev-to-kube-1.33
ponimas Aug 28, 2025
95b8448
Merge dev to dev-to-kube-1.33
k8s-on-aws-manager-app[bot] Aug 28, 2025
c49b845
Merge pull request #9796 from zalando-incubator/dev-to-kube-1.33
tcondeixa Aug 28, 2025
9de2fa6
Merge dev to dev-to-kube-1.33
k8s-on-aws-manager-app[bot] Aug 28, 2025
545e5cd
Merge dev to dev-to-kube-1.33
k8s-on-aws-manager-app[bot] Aug 29, 2025
648d225
Merge dev to dev-to-kube-1.33
k8s-on-aws-manager-app[bot] Aug 29, 2025
20a4cbc
Merge dev to dev-to-kube-1.33
k8s-on-aws-manager-app[bot] Aug 29, 2025
2d8e1c0
Merge pull request #9800 from zalando-incubator/dev-to-kube-1.33
mikkeloscar Aug 29, 2025
e7cefea
Merge dev to dev-to-kube-1.33
k8s-on-aws-manager-app[bot] Aug 29, 2025
9c4ec84
Merge dev to dev-to-kube-1.33
k8s-on-aws-manager-app[bot] Aug 29, 2025
59f3e12
Merge pull request #9807 from zalando-incubator/dev-to-kube-1.33
mikkeloscar Aug 30, 2025
0599a4b
Merge dev to dev-to-kube-1.33
k8s-on-aws-manager-app[bot] Sep 1, 2025
cd0a79a
Merge pull request #9809 from zalando-incubator/dev-to-kube-1.33
mikkeloscar Sep 1, 2025
c88cc07
Merge dev to dev-to-kube-1.33
k8s-on-aws-manager-app[bot] Sep 1, 2025
6d868a6
Merge pull request #9813 from zalando-incubator/dev-to-kube-1.33
demonCoder95 Sep 2, 2025
28fb6af
Merge dev to dev-to-kube-1.33
k8s-on-aws-manager-app[bot] Sep 2, 2025
1ecc49e
Merge dev to dev-to-kube-1.33
k8s-on-aws-manager-app[bot] Sep 2, 2025
378bad0
Merge pull request #9816 from zalando-incubator/dev-to-kube-1.33
mikkeloscar Sep 3, 2025
3294b8e
Merge dev to dev-to-kube-1.33
k8s-on-aws-manager-app[bot] Sep 3, 2025
1ee1111
Merge dev to dev-to-kube-1.33
k8s-on-aws-manager-app[bot] Sep 4, 2025
6fbce8a
Merge pull request #9822 from zalando-incubator/dev-to-kube-1.33
szuecs Sep 5, 2025
c697bc5
Merge dev to dev-to-kube-1.33
k8s-on-aws-manager-app[bot] Sep 5, 2025
a5df0cf
Merge dev to dev-to-kube-1.33
k8s-on-aws-manager-app[bot] Sep 5, 2025
ede531e
Merge pull request #9830 from zalando-incubator/dev-to-kube-1.33
mikkeloscar Sep 8, 2025
fcf4328
Merge dev to dev-to-kube-1.33
k8s-on-aws-manager-app[bot] Sep 8, 2025
c902f7c
Merge pull request #9834 from zalando-incubator/dev-to-kube-1.33
szuecs Sep 8, 2025
b9d1ec0
Merge dev to dev-to-kube-1.33
k8s-on-aws-manager-app[bot] Sep 8, 2025
117b1ce
Manage kube-proxy as an addon
mikkeloscar Sep 9, 2025
b0e6ff3
Merge pull request #9839 from zalando-incubator/dev-to-kube-1.33
tcondeixa Sep 9, 2025
01de3c4
Merge pull request #9840 from zalando-incubator/kube-proxy-addon
mikkeloscar Sep 9, 2025
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 7 additions & 1 deletion cluster/cluster.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -170,7 +170,7 @@ Resources:
{{- end }}
Properties:
Name: "{{.Cluster.Name}}"
Version: "1.32"
Version: "1.33"
RoleArn: !GetAtt EKSClusterRole.Arn
KubernetesNetworkConfig:
IpFamily: "{{.Cluster.ConfigItems.eks_ip_family}}"
Expand Down Expand Up @@ -295,6 +295,12 @@ Resources:
Properties:
AddonName: eks-pod-identity-agent
ClusterName: !Ref EKSCluster
EKSAddonKubeProxy:
Type: AWS::EKS::Addon
Properties:
AddonName: kube-proxy
AddonVersion: "v1.33.3-eksbuild.6"
ClusterName: !Ref EKSCluster
{{ if eq .Cluster.Environment "e2e" }}
E2EEKSIAMTestRoleReadOnly:
Properties:
Expand Down
4 changes: 2 additions & 2 deletions cluster/config-defaults.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -795,8 +795,8 @@ tracing_coredns_local_zone_traces_endpoint: ""
# AMI id given the image name and the Image AWS account owner.
#
# [0]: https://github.com/zalando-incubator/cluster-lifecycle-manager/blob/8a9bd1cb2d094038a9e23e646421f8146b48886a/provisioner/template.go#L116
kuberuntu_image_v1_32_new_amd64: {{ amiID "zalando-ubuntu-jammy-22.04-kubernetes-production-v1.32.4-amd64-master-373" "861068367966" }}
kuberuntu_image_v1_32_new_arm64: {{ amiID "zalando-ubuntu-jammy-22.04-kubernetes-production-v1.32.4-arm64-master-373" "861068367966" }}
kuberuntu_image_v1_33_new_amd64: {{ amiID "zalando-ubuntu-jammy-22.04-kubernetes-production-v1.33.4-amd64-master-378" "861068367966" }}
kuberuntu_image_v1_33_new_arm64: {{ amiID "zalando-ubuntu-jammy-22.04-kubernetes-production-v1.33.4-arm64-master-378" "861068367966" }}

# This is used to determine which AMI to use for the cluster or individual node
# pools. Possible values are 'new' or 'old'
Expand Down
8 changes: 8 additions & 0 deletions cluster/manifests/02-admission-control/teapot.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -139,6 +139,14 @@ webhooks:
apiVersions: ["v1"]
resources: ["nodes"]
- name: configmap-admitter.teapot.zalan.do
{{- if eq .Cluster.Provider "zalando-eks"}}
# avoid admission-control applying to the admission-controller components (🐔🥚)
objectSelector:
matchExpressions:
- key: eks.amazonaws.com/component
operator: NotIn
values: ["kube-proxy"]
{{- end }}
clientConfig:
{{- if eq .Cluster.Provider "zalando-eks"}}
service:
Expand Down
2 changes: 1 addition & 1 deletion cluster/node-pools/master-default/stack.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ Mappings:
Images:
{{.Cluster.Region}}:
# Use the node pool's architecture to construct the config item name that we're using to get the AMI name.
MachineImage: '{{ index .NodePool.ConfigItems (print "kuberuntu_image_v1_32_" .NodePool.ConfigItems.kuberuntu_ami_version "_" .Values.InstanceInfo.Architecture) }}'
MachineImage: '{{ index .NodePool.ConfigItems (print "kuberuntu_image_v1_33_" .NodePool.ConfigItems.kuberuntu_ami_version "_" .Values.InstanceInfo.Architecture) }}'

Resources:
AutoScalingGroup:
Expand Down
2 changes: 1 addition & 1 deletion cluster/node-pools/worker-combined/stack.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ Mappings:
Images:
{{.Cluster.Region}}:
# Use the node pool's architecture to construct the config item name that we're using to get the AMI name.
MachineImage: '{{ index .NodePool.ConfigItems (print "kuberuntu_image_v1_32_" .NodePool.ConfigItems.kuberuntu_ami_version "_" .Values.InstanceInfo.Architecture) }}'
MachineImage: '{{ index .NodePool.ConfigItems (print "kuberuntu_image_v1_33_" .NodePool.ConfigItems.kuberuntu_ami_version "_" .Values.InstanceInfo.Architecture) }}'

Resources:
AutoScalingGroup:
Expand Down
4 changes: 2 additions & 2 deletions cluster/node-pools/worker-karpenter/provisioners.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -7,8 +7,8 @@ spec:
amiFamily: Custom
amiSelectorTerms:
# Select on any AMI that has any of the following IDs
- id: {{ index .NodePool.ConfigItems (print "kuberuntu_image_v1_32_" .NodePool.ConfigItems.kuberuntu_ami_version "_amd64") }}
- id: {{ index .NodePool.ConfigItems (print "kuberuntu_image_v1_32_" .NodePool.ConfigItems.kuberuntu_ami_version "_arm64") }}
- id: {{ index .NodePool.ConfigItems (print "kuberuntu_image_v1_33_" .NodePool.ConfigItems.kuberuntu_ami_version "_amd64") }}
- id: {{ index .NodePool.ConfigItems (print "kuberuntu_image_v1_33_" .NodePool.ConfigItems.kuberuntu_ami_version "_arm64") }}
metadataOptions:
httpEndpoint: enabled
# {{ if and (eq .Cluster.Provider "zalando-eks") (eq .Cluster.ConfigItems.eks_ip_family "ipv6") }}
Expand Down
2 changes: 1 addition & 1 deletion cluster/node-pools/worker-splitaz/stack.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ Mappings:
Images:
{{.Cluster.Region}}:
# Use the node pool's architecture to construct the config item name that we're using to get the AMI name.
MachineImage: '{{ index .NodePool.ConfigItems (print "kuberuntu_image_v1_32_" .NodePool.ConfigItems.kuberuntu_ami_version "_" .Values.InstanceInfo.Architecture) }}'
MachineImage: '{{ index .NodePool.ConfigItems (print "kuberuntu_image_v1_33_" .NodePool.ConfigItems.kuberuntu_ami_version "_" .Values.InstanceInfo.Architecture) }}'

Resources:
{{ with $data := . }}
Expand Down
2 changes: 1 addition & 1 deletion test/e2e/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ RUN apt-get update && DEBIAN_FRONTEND=noninteractive apt-get install -qq bc curl

ARG KUBE_VERSION
RUN curl -L -s --fail "https://dl.k8s.io/${KUBE_VERSION}/kubernetes-client-linux-${TARGETARCH}.tar.gz" -o "kubernetes-client-linux-${TARGETARCH}.tar.gz" && \
printf "924bd0cdbef91caab04b5e9c31017c24d9d7c718f6db9e2c61d5c203d579c8f0c00ac7451bd3658d5cdf31d7a08c8ee5884511d8e961f0e9331d00b1f6f03bee kubernetes-client-linux-amd64.tar.gz\nbf84363c16f72863e38d9d67194531aabafb6a82a20e3361354cc037964205557e8a39b62fa23b3c435c87f989838b6619980ea5c325c456e5cd5d47564d1644 kubernetes-client-linux-arm64.tar.gz" | grep "${TARGETARCH}" | sha512sum -c - && \
printf "e628239516ed6a3d07d47b451b7f42199fb5dcfb4d416f7b519235fd454e0fca3d0c273cc9c709f653a935a32c1f9fbd0a4be88f4c59d0ddcd674be2c289c8a5 kubernetes-client-linux-amd64.tar.gz\neb349a54d2013ae535fd60a0c32b0a932f176c9203541fba88e9eecbb794a2701479d09389e04950f5ed27b8a48383072b658cdfe7bddb3f0b60c2657a93d90f kubernetes-client-linux-arm64.tar.gz" | grep "${TARGETARCH}" | sha512sum -c - && \
tar xvf "kubernetes-client-linux-${TARGETARCH}.tar.gz" --strip-components 3 kubernetes/client/bin/ && \
rm "kubernetes-client-linux-${TARGETARCH}.tar.gz" && \
mv kubectl /usr/bin/kubectl
Expand Down
4 changes: 2 additions & 2 deletions test/e2e/Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

BINARY ?= kubernetes-on-aws-e2e
VERSION ?= $(shell git describe --tags --always --dirty)
KUBE_VERSION ?= v1.32.4
KUBE_VERSION ?= v1.33.4
IMAGE ?= pierone.stups.zalan.do/teapot/$(BINARY)
SOURCES = $(shell find . -name '*.go')
TAG ?= $(VERSION)
Expand All @@ -11,7 +11,7 @@ DOCKERFILE ?= Dockerfile
default: build

deps:
CGO_ENABLED=0 go install github.com/onsi/ginkgo/v2/ginkgo@v2.15.0
CGO_ENABLED=0 go install github.com/onsi/ginkgo/v2/ginkgo@v2.21.0

e2e.test: go.mod $(SOURCES)
go test -v -c -o e2e.test
Expand Down
11 changes: 5 additions & 6 deletions test/e2e/apiserver.go
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,6 @@ import (
e2epod "k8s.io/kubernetes/test/e2e/framework/pod"
"k8s.io/kubernetes/test/e2e/framework/statefulset"
admissionapi "k8s.io/pod-security-admission/api"
"k8s.io/utils/ptr"
)

const (
Expand Down Expand Up @@ -474,7 +473,7 @@ var _ = describe("Image Policy Tests (Job)", func() {
framework.ExpectNoError(err)
}()

job.WaitForJobComplete(context.TODO(), cs, namespace, jobObj.Name, ptr.To(batchv1.JobReasonCompletionsReached), 1)
job.WaitForJobComplete(context.TODO(), cs, namespace, jobObj.Name, batchv1.JobReasonCompletionsReached, 1)
})

It("Should not create Job using non-compliant image [Image-Policy] [Non-Compliant] [Zalando]", func() {
Expand All @@ -495,7 +494,7 @@ var _ = describe("Image Policy Tests (Job)", func() {
framework.ExpectNoError(err)
}()

job.WaitForJobComplete(context.TODO(), cs, namespace, jobObj.Name, ptr.To(batchv1.JobReasonCompletionsReached), 1)
job.WaitForJobComplete(context.TODO(), cs, namespace, jobObj.Name, batchv1.JobReasonCompletionsReached, 1)
})
})

Expand Down Expand Up @@ -526,7 +525,7 @@ var _ = describe("Image Policy Tests (Job) (when disabled)", func() {
framework.ExpectNoError(err)
}()

job.WaitForJobComplete(context.TODO(), cs, namespace, jobObj.Name, ptr.To(batchv1.JobReasonCompletionsReached), 1)
job.WaitForJobComplete(context.TODO(), cs, namespace, jobObj.Name, batchv1.JobReasonCompletionsReached, 1)
})
})

Expand Down Expand Up @@ -560,7 +559,7 @@ var _ = describe("ECR Registry Pull", func() {
framework.ExpectNoError(err)
}()

job.WaitForJobComplete(context.TODO(), cs, namespace, jobObj.Name, ptr.To(batchv1.JobReasonCompletionsReached), 1)
job.WaitForJobComplete(context.TODO(), cs, namespace, jobObj.Name, batchv1.JobReasonCompletionsReached, 1)
})

It("Should run a Job using a vanity image from the staging registry [ECR] [Zalando]", func() {
Expand All @@ -584,6 +583,6 @@ var _ = describe("ECR Registry Pull", func() {
framework.ExpectNoError(err)
}()

job.WaitForJobComplete(context.TODO(), cs, namespace, jobObj.Name, ptr.To(batchv1.JobReasonCompletionsReached), 1)
job.WaitForJobComplete(context.TODO(), cs, namespace, jobObj.Name, batchv1.JobReasonCompletionsReached, 1)
})
})
Loading