精选75Tailscale Changelog云与平台
Tailscale Kubernetes Operator v1.102.2:新增
Tailscale Kubernetes Operator v1.102.2
A new release of the Tailscale Kubernetes Operator is available. For guidance on installing and updating, refer to our installation instructions.
Tailscale Kubernetes Operator 的新版本现已发布。有关安装和更新的指导,请参阅我们的安装说明。
- New: PeerRelays are deployable in-cluster via a custom resource.
- New: Annotations can now be applied to the operator's deployment resource via Helm.
- New: Workload identity federation can now be configured for the Tailnet custom resource.
- New: 4via6 is supported in connector and egress proxy resources when egressing from a dual-stack cluster.
- New: IPv6 is supported in Egress ProxyGroups.
- Changed: Operator log output excludes superfluous entries, such as entries for resources that do not contain annotations.
- Changed: Several log lines have adjusted log levels.
- Fixed: MTU values are clamped on both the input and output interfaces, where previously only the output interface was clamped.
- Fixed: ProxyGroup services no longer fail to reconcile when using the same hostname across multiple tailnets.
- Fixed: ProxyGroup static endpoints no longer cause constant reconciliation loops due to non-deterministic ordering.
- Fixed: DNS reconciler no longer drops reconcile events, which left the dnsrecords ConfigMap stale.
- Fixed: EndpointSlices for Egress ProxyGroup are verified on every reconcile.
- Fixed: Cert renewal retries follow Let's Encrypt's recommended backoff schedule instead of a fixed interval.
- Fixed: Let's Encrypt Retry-After headers are honored by Kubernetes proxies when hitting rate limits, which avoids the tight retry loops that made rate-limit backoffs worse.
- Fixed: Per-attempt cert issuance timeout in Kubernetes proxies is increased to 30 minutes, giving ACME challenges room to complete under load without failing prematurely.
- Fixed: Cert issuance attempts no longer run against a VIPService that is being torn down during Ingress deletion, which wasted Let's Encrypt rate-limit quota.
- 新增:PeerRelays 现在可以通过自定义资源在集群内部署。
- 新增:现在可以通过 Helm 将注解应用于 operator 的 deployment 资源。
- 新增:现在可以为 Tailnet 自定义资源配置工作负载身份联合。
- 新增:从双栈集群出站时,connector 和 egress 代理资源支持 4via6。
- 新增:Egress ProxyGroups 支持 IPv6。
- 变更:Operator 日志输出排除了多余条目,例如不包含注解的资源的条目。
- 变更:若干日志行的日志级别已调整。
- 修复:MTU 值现在在输入和输出接口上都被限制,而之前仅限制输出接口。
- 修复:ProxyGroup 服务在多个 tailnet 中使用相同主机名时,不再无法协调。
- 修复:ProxyGroup 静态端点不再因非确定性排序而导致持续协调循环。
- 修复:DNS 协调器不再丢弃协调事件,这导致 dnsrecords ConfigMap 过期。
- 修复:Egress ProxyGroup 的 EndpointSlices 在每次协调时都会进行验证。
- 修复:证书续期重试遵循 Let's Encrypt 推荐的退避计划,而不是固定间隔。
- 修复:Kubernetes 代理在遇到速率限制时遵循 Let's Encrypt 的 Retry-After 头,避免了使速率限制退避更糟的紧密重试循环。
- 修复:Kubernetes 代理中每次证书签发尝试的超时时间增加到 30 分钟,使 ACME 挑战在负载下有时间完成,而不会过早失败。
- 修复:证书签发尝试不再针对 Ingress 删除期间正在拆除的 VIPService 运行,这浪费了 Let's Encrypt 的速率限制配额。
更进一步:量化金融体系
看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力