As part of our regular upgrade cycle, the following Kubernetes cluster components have been updated. We’ve already rolled these out to all non-production clusters. Production clusters will follow once we validated everything is stable. There are no actions for you to take.
More …
We’ve upgraded all Teleport clusters from version 8.0.7 to 8.2.0. This is a minor release, coming with mostly bug and performance fixes.
More …
We’re adding support for the Github actions-runner-controller
as a managed add-on for our Kubernetes platforms. With this controller, the customers using Github Actions will be able to easily deploy self-hosted runners on their clusters. This is useful for deploying workloads on a private-endpoint cluster, since the runner will execute the deploy task from within the cluster itself.
More …
We manage multiple Kubernetes clusters and regularly set up new ones from scratch. There are also a bunch of extra components deployed on each cluster, that we also need to maintain and keep up to date.
More …
On AWS EKS clusters we use Calico for providing NetworkPolicy
functionality. With these NetworkPolicies
you can control the traffic flow within a Kubernetes cluster between Pods, Services and external resources.
More …
We have already configured the VPA for many of our workloads (ExternalDNS, cert-manager, Prometheus and more). Today we also configured this for the metrics-server workload. This means that for those workloads we need less manual configuration changes when the cluster scales and therefore will result in a more stable cluster.
More …
The AWS Load Balancer Controller is the successor of the ALB Ingress Controller, with many new features. This controller allows creating both ALBs and NLBs dynamically.
More …
On 26 January 2022, Let’s Encrypt notified subscribers that most certificates issued in the last 90 days and validated with the TLS-ALPN-01
challenge will be revoked on 28 January 2022 and should be immediatelly renewed. This revocation only affects certificates issued and validated with the TLS-ALPN-01
challenge.
More …
21 Jan 2022
•
k8s, nginx-ingress
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster.
More …
For a while we’ve offered Grafana Loki as default logging solution. For shipping logs to Loki we were using the included Promtail. However, more recently, we’ve also supported other logging solutions, like Elasticsearch and Logz.io for customers with more advanced needs. To facilitate this we use the Fluent Bit log processor.
More …
We’ve upgraded all Teleport clusters from version 8.0.0 to 8.0.7. This is a minor release, coming with mostly bug and security fixes.
More …
We have added Vault to the list of autoscaling rules we deploy by default. By doing this we can allow the VPA to set the optimal resource requests and limits within the boundaries that we provide.
More …
AWS ElasticSearch Service has been rebranded to AWS OpenSearch for some time now, and thus we’ve decided to rename our Terraform module for managing this service accordingly.
More …
We have added support for mixed node pools on AWS.
More …
During a routine monitoring review, we’ve noticed some Promtail pods were using significantly more CPU than the generic request. This pointed us to two issues:
More …
Update 2021-12-16: The patched Log4j 2.15.0
was found to still have a possible vulnerability. We’ve updated the action below to update to (at least) version 2.16.0
.
More …
We’ve added support for using secrets from AWS Secrets Manager in EKS clusters. This support is optional and disabled by default.
More …
As part of our regular upgrade cycle, the following Kubernetes cluster components have been updated. We’ve already rolled these out to all clusters.
More …
We’ve upgraded all Teleport clusters to version 8.0.0. This is a major release, coming with many new features:
More …
We have upgraded Istio on all clusters that use it. The version was upgraded from 1.11.2 to 1.12.0.
More …