跳到主内容
@wquguru
精选75Tailscale Changelog云与平台

Tailscale Kubernetes Operator v1.102.2:新增

Tailscale Kubernetes Operator v1.102.2

原文
发到 X

A new release of the Tailscale Kubernetes Operator is available. For guidance on installing and updating, refer to our installation instructions.

Tailscale Kubernetes Operator 的新版本现已发布。有关安装和更新的指导,请参阅我们的安装说明。

  • New: PeerRelays are deployable in-cluster via a custom resource.
  • New: Annotations can now be applied to the operator's deployment resource via Helm.
  • New: Workload identity federation can now be configured for the Tailnet custom resource.
  • New: 4via6 is supported in connector and egress proxy resources when egressing from a dual-stack cluster.
  • New: IPv6 is supported in Egress ProxyGroups.
  • Changed: Operator log output excludes superfluous entries, such as entries for resources that do not contain annotations.
  • Changed: Several log lines have adjusted log levels.
  • Fixed: MTU values are clamped on both the input and output interfaces, where previously only the output interface was clamped.
  • Fixed: ProxyGroup services no longer fail to reconcile when using the same hostname across multiple tailnets.
  • Fixed: ProxyGroup static endpoints no longer cause constant reconciliation loops due to non-deterministic ordering.
  • Fixed: DNS reconciler no longer drops reconcile events, which left the dnsrecords ConfigMap stale.
  • Fixed: EndpointSlices for Egress ProxyGroup are verified on every reconcile.
  • Fixed: Cert renewal retries follow Let's Encrypt's recommended backoff schedule instead of a fixed interval.
  • Fixed: Let's Encrypt Retry-After headers are honored by Kubernetes proxies when hitting rate limits, which avoids the tight retry loops that made rate-limit backoffs worse.
  • Fixed: Per-attempt cert issuance timeout in Kubernetes proxies is increased to 30 minutes, giving ACME challenges room to complete under load without failing prematurely.
  • Fixed: Cert issuance attempts no longer run against a VIPService that is being torn down during Ingress deletion, which wasted Let's Encrypt rate-limit quota.
  • 新增:PeerRelays 现在可以通过自定义资源在集群内部署。
  • 新增:现在可以通过 Helm 将注解应用于 operator 的 deployment 资源。
  • 新增:现在可以为 Tailnet 自定义资源配置工作负载身份联合。
  • 新增:从双栈集群出站时,connector 和 egress 代理资源支持 4via6。
  • 新增:Egress ProxyGroups 支持 IPv6。
  • 变更:Operator 日志输出排除了多余条目,例如不包含注解的资源的条目。
  • 变更:若干日志行的日志级别已调整。
  • 修复:MTU 值现在在输入和输出接口上都被限制,而之前仅限制输出接口。
  • 修复:ProxyGroup 服务在多个 tailnet 中使用相同主机名时,不再无法协调。
  • 修复:ProxyGroup 静态端点不再因非确定性排序而导致持续协调循环。
  • 修复:DNS 协调器不再丢弃协调事件,这导致 dnsrecords ConfigMap 过期。
  • 修复:Egress ProxyGroup 的 EndpointSlices 在每次协调时都会进行验证。
  • 修复:证书续期重试遵循 Let's Encrypt 推荐的退避计划,而不是固定间隔。
  • 修复:Kubernetes 代理在遇到速率限制时遵循 Let's Encrypt 的 Retry-After 头,避免了使速率限制退避更糟的紧密重试循环。
  • 修复:Kubernetes 代理中每次证书签发尝试的超时时间增加到 30 分钟,使 ACME 挑战在负载下有时间完成,而不会过早失败。
  • 修复:证书签发尝试不再针对 Ingress 删除期间正在拆除的 VIPService 运行,这浪费了 Let's Encrypt 的速率限制配额。

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →

相似阅读

另一事件,读法相近