Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
195 commits
Select commit Hold shift + click to select a range
9b8bd6d
Don't install addons twice in e2e
nojnhuh Jun 10, 2025
9992743
dependabot(deps): bump github.com/cloudflare/circl from 1.3.7 to 1.6.1
dependabot[bot] Jun 10, 2025
0f316d4
Add CAAPH resources to upgrades template
nojnhuh Jun 10, 2025
aab6044
fixup! Add CAAPH resources to upgrades template
nojnhuh Jun 10, 2025
b92b4b6
Install gpu-operator with CAAPH in e2e
nojnhuh Jun 10, 2025
2e7a707
Remove dead helm e2e code
nojnhuh Jun 10, 2025
5dfcdee
Fix fetching activity logs in e2e for ClusterClass clusters
nojnhuh Jun 11, 2025
a031498
Clean up e2e control plane waiter names
nojnhuh Jun 11, 2025
86ac2e7
Update provider metadata and API upgrade test versions
alimaazamat Jun 11, 2025
a0a7725
Merge pull request #5692 from nojnhuh/activity-logs
k8s-ci-robot Jun 11, 2025
0e80f51
Use more entropy for random WI storage account names
nojnhuh Jun 12, 2025
8f27a37
Merge pull request #5698 from nojnhuh/e2e-storage-account-name
k8s-ci-robot Jun 12, 2025
1d2c092
Merge pull request #5689 from nojnhuh/e2e-addons
k8s-ci-robot Jun 13, 2025
7280ca5
dependabot(deps): bump the all-github-actions group with 3 updates
dependabot[bot] Jun 16, 2025
560f92e
dependabot(deps): bump github.com/Azure/azure-sdk-for-go/sdk/azidentity
dependabot[bot] Jun 16, 2025
ba1619e
Merge pull request #5701 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Jun 16, 2025
6fff937
Define NoSchedule tolerations for tigera-operator
nojnhuh Jun 16, 2025
8aa9eca
Merge pull request #5695 from alimaazamat/update-test-1.20
k8s-ci-robot Jun 16, 2025
89a4eb5
Add MachineHealthChecks for KCP Machines in e2e
nojnhuh Jun 12, 2025
61d26fe
Bump Go toolchain to v1.23.10
mboersma Jun 17, 2025
2ee627b
Remove Windows nodes from HA e2e test
nojnhuh Jun 17, 2025
93c7990
Merge pull request #5696 from nojnhuh/e2e-mhc
k8s-ci-robot Jun 17, 2025
549420a
Add nodeDeletionTimeout to KCP machines for upgrade tests
nojnhuh Jun 17, 2025
c6c8fe0
Warning message added for deprecation of AzureManaged API (#5699)
alimaazamat Jun 17, 2025
8317a15
Merge pull request #5704 from nojnhuh/tigera-tolerations
k8s-ci-robot Jun 18, 2025
7f6ecb0
Merge pull request #5708 from nojnhuh/ha-no-win
k8s-ci-robot Jun 18, 2025
02e5fba
Merge pull request #5706 from nojnhuh/upgrade-node-delete-timeout
k8s-ci-robot Jun 18, 2025
3a7e200
Merge pull request #5691 from kubernetes-sigs/dependabot/go_modules/g…
k8s-ci-robot Jun 18, 2025
38c1db6
Merge pull request #5702 from kubernetes-sigs/dependabot/go_modules/g…
k8s-ci-robot Jun 18, 2025
4fe4b30
Bump cert-manager to v1.18.1
mboersma Jun 18, 2025
377d52f
Bump CAPI to v1.10.3
mboersma Jun 18, 2025
8a0ec28
Update cloudbuild image
nojnhuh Jun 18, 2025
9835698
Merge pull request #5715 from nojnhuh/cloudbuild-image
k8s-ci-robot Jun 18, 2025
4936b6f
Merge pull request #5711 from mboersma/bump-cert-manager
k8s-ci-robot Jun 19, 2025
44da1de
Merge pull request #5712 from mboersma/bump-capi
k8s-ci-robot Jun 19, 2025
6b66b2d
Merge pull request #5707 from mboersma/bump-go-toolchain
k8s-ci-robot Jun 20, 2025
c29ee55
Make e2e node log collection more self-sufficient
nojnhuh Jun 18, 2025
ecbfec4
Merge pull request #5710 from nojnhuh/e2e-logs
k8s-ci-robot Jun 21, 2025
e885088
dependabot(deps): bump github.com/hashicorp/go-retryablehttp
dependabot[bot] Jun 23, 2025
bbe28d1
Merge pull request #5727 from kubernetes-sigs/dependabot/go_modules/g…
k8s-ci-robot Jun 23, 2025
0c76027
add CHANGELOG for v1.19.5
alimaazamat Jun 26, 2025
532f5c7
Merge pull request #5728 from alimaazamat/release-1.19.5
k8s-ci-robot Jun 26, 2025
d9d4540
add CHANGELOG for v1.20.1
alimaazamat Jun 26, 2025
b8fbdb3
Merge pull request #5730 from alimaazamat/release-1.20.1
k8s-ci-robot Jun 26, 2025
5714272
Enable resource.k8s.io/v1beta2 for DRA templates
nojnhuh May 23, 2025
c956730
dependabot(deps): bump github.com/go-viper/mapstructure/v2
dependabot[bot] Jun 27, 2025
3d3d97e
Merge pull request #5732 from kubernetes-sigs/dependabot/go_modules/g…
k8s-ci-robot Jun 27, 2025
c08d3f1
dependabot(deps): bump the all-github-actions group with 2 updates
dependabot[bot] Jun 30, 2025
0e62c90
Merge pull request #5734 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Jun 30, 2025
593885d
dependabot(deps): bump go.opentelemetry.io/otel from 1.36.0 to 1.37.0
dependabot[bot] Jun 30, 2025
bdc05c1
Merge pull request #5733 from kubernetes-sigs/dependabot/go_modules/g…
k8s-ci-robot Jun 30, 2025
2acf550
Merge pull request #5731 from nojnhuh/dra-v1beta2
k8s-ci-robot Jun 30, 2025
98cb775
Update CAPI and CAPZ versions in e2e testing
mboersma Jul 3, 2025
246a3fa
Add dra-specific tag for monitoring
willie-yao Jul 8, 2025
dcf6cb6
Merge pull request #5739 from mboersma/bump-test-versions
k8s-ci-robot Jul 8, 2025
f2226d1
Merge pull request #5740 from kubernetes-sigs/change-dra-tags
k8s-ci-robot Jul 8, 2025
0b849eb
Fix format strings
AndiDog Jul 9, 2025
5b0130c
Merge pull request #5743 from AndiDog/fix-format-strings
k8s-ci-robot Jul 9, 2025
e1dcce4
dependabot(deps): bump golang.org/x/mod from 0.25.0 to 0.26.0
dependabot[bot] Jul 14, 2025
79cd7f7
Define AZURE_LOCATION_LOAD for load test regions
nojnhuh Jul 14, 2025
1a5423b
dependabot(deps): bump github.com/Azure/azure-sdk-for-go/sdk/azcore
dependabot[bot] Jul 14, 2025
ea10f5a
Merge pull request #5748 from kubernetes-sigs/dependabot/go_modules/g…
k8s-ci-robot Jul 14, 2025
18cca4c
dependabot(deps): bump golang.org/x/crypto from 0.39.0 to 0.40.0
dependabot[bot] Jul 14, 2025
c5f1d89
Merge pull request #5749 from nojnhuh/load-location
k8s-ci-robot Jul 14, 2025
9f35e1a
Merge pull request #5751 from kubernetes-sigs/dependabot/go_modules/g…
k8s-ci-robot Jul 15, 2025
f82a3ac
Add support to disable CAPZ components through a manager flag
bryan-cox Apr 8, 2025
cc6b89f
Merge pull request #5747 from kubernetes-sigs/dependabot/go_modules/g…
k8s-ci-robot Jul 15, 2025
5ae25f7
Merge pull request #5552 from bryan-cox/5472
k8s-ci-robot Jul 15, 2025
2cccc8d
Use ipv6 template for ipv6 conformance instead of default template
nojnhuh Jul 15, 2025
ea10f5c
Fix DRA conformance config
nojnhuh Jul 15, 2025
c8c2de8
Merge pull request #5756 from nojnhuh/dra-e2e
k8s-ci-robot Jul 15, 2025
71bd7f1
Merge pull request #5755 from nojnhuh/ipv6-conformance
k8s-ci-robot Jul 16, 2025
776ef64
Bump CAPI to v1.10.4
mboersma Jul 17, 2025
cbb2f00
dependabot(deps): bump the all-github-actions group with 2 updates
dependabot[bot] Jul 21, 2025
c11f2e7
dependabot(deps): bump github.com/Azure/azure-sdk-for-go/sdk/resource…
dependabot[bot] Jul 21, 2025
a7c597a
Merge pull request #5761 from mboersma/bump-capi
k8s-ci-robot Jul 21, 2025
7891f75
dependabot(deps): bump github.com/spf13/pflag from 1.0.6 to 1.0.7
dependabot[bot] Jul 21, 2025
fb29a23
Merge pull request #5766 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Jul 21, 2025
3f5d5e4
Bump QPS and burst for kube-controller-manager in DRA load test
nojnhuh Jul 14, 2025
c1dea74
Merge pull request #5767 from kubernetes-sigs/dependabot/go_modules/g…
k8s-ci-robot Jul 21, 2025
c10e258
Merge pull request #5770 from kubernetes-sigs/dependabot/go_modules/g…
k8s-ci-robot Jul 21, 2025
8e98848
Merge pull request #5746 from nojnhuh/dra-ctrl-qps-burst
jackfrancis Jul 21, 2025
ce3da30
CI: Always use AZURE_LOCATION
jackfrancis Jul 21, 2025
6e606c6
Merge pull request #5772 from jackfrancis/AZURE_LOCATION-fix
k8s-ci-robot Jul 22, 2025
c0dd1b0
Add release notes for CAPZ v1.19.6
mboersma Jul 22, 2025
ecf588a
Add release notes for CAPZ v1.20.2
mboersma Jul 22, 2025
f93a6ec
Merge pull request #5774 from mboersma/release-notes-v1.19.6
k8s-ci-robot Jul 22, 2025
9ad724c
Merge pull request #5775 from mboersma/release-notes-v1.20.2
k8s-ci-robot Jul 22, 2025
d5be47f
Bump CAPZ versions used in testing
mboersma Jul 22, 2025
5791ee2
Check for VM assigned identities without API calls
nojnhuh Jul 23, 2025
5538d66
Merge pull request #5778 from mboersma/bump-test-versions
k8s-ci-robot Jul 23, 2025
5605fb5
Merge pull request #5780 from nojnhuh/vm-identity-check
jackfrancis Jul 23, 2025
6a3e754
Acknowledge all ASO resource types before creating
nojnhuh Nov 3, 2024
39d8231
Merge pull request #5571 from nojnhuh/aso-airtight
k8s-ci-robot Jul 24, 2025
9f892f6
Prefer control plane nodes for typha
nojnhuh Jul 25, 2025
4dc9ba4
Add MachineHealthCheck for MachinePools in test templates
nojnhuh Jul 25, 2025
12e1c11
Add separate MachineDeployment for Prometheus in load tests
nojnhuh Jul 25, 2025
f0476f1
Add VMSS-based scalability test templates
nojnhuh Jul 25, 2025
1095502
Add make test target for custom manager image
willie-yao Jul 25, 2025
1e22684
Merge pull request #5784 from nojnhuh/load-vmss-template
k8s-ci-robot Jul 25, 2025
ec9f2b6
Bump Go toolchain to v1.23.11
mboersma Jul 28, 2025
59c26c9
Add ability to disable creation of dns zone for unmanaged installs
sadasu Jul 8, 2025
8e48df5
Bump CAAPH to v0.3.2
nojnhuh Jul 29, 2025
d2122be
Merge pull request #5789 from mboersma/bump-go-toolchain
k8s-ci-robot Jul 29, 2025
2b042f0
fix(observability): configure ServiceMonitor for ASO secure metrics a…
bryan-cox Jul 30, 2025
55ae022
Reduce qps/burst for kube-controller-manager in DRA load test templates
nojnhuh Jul 30, 2025
0d2a103
Merge pull request #5787 from willie-yao/custom-manager-image
k8s-ci-robot Jul 31, 2025
24059e1
Merge pull request #5790 from nojnhuh/bump-caaph
k8s-ci-robot Jul 31, 2025
02798fd
Merge pull request #5793 from bryan-cox/5601
k8s-ci-robot Jul 31, 2025
ba6d515
Merge pull request #5792 from nojnhuh/dra-kcm-qps-burst-testing
k8s-ci-robot Jul 31, 2025
4a2a783
Add startupProbe to ASO
nojnhuh Aug 1, 2025
cee81e3
Merge pull request #5795 from nojnhuh/aso-startup-probe
k8s-ci-robot Aug 1, 2025
1aa08d0
Fix issue with MANAGER_IMAGE being overwritten in conformance tests
willie-yao Aug 5, 2025
72b27bb
Merge pull request #5796 from willie-yao/fix-conformance-manager-image
k8s-ci-robot Aug 5, 2025
b17b877
Merge pull request #5666 from sadasu/unmanaged-privateDNSZoneMode
k8s-ci-robot Aug 5, 2025
5f304dd
Run verify-security weekly as a GitHub action
mboersma Aug 5, 2025
662bd71
Fix nil panic in e2e cleanup
nojnhuh Aug 6, 2025
316370d
Merge pull request #5800 from nojnhuh/e2e-panic
k8s-ci-robot Aug 6, 2025
4a082ca
Merge pull request #5798 from mboersma/security-scan
k8s-ci-robot Aug 8, 2025
d2da35e
Add prow apiserver ilb template that supports custom k8s images
willie-yao Aug 5, 2025
e1c881f
Dont give contributor access to byo identity in aks mgmt
willie-yao Aug 8, 2025
1916969
Merge pull request #5802 from willie-yao/fix-aks-mgmt-assign
k8s-ci-robot Aug 8, 2025
9c90270
Bump Go to v1.23.12
mboersma Aug 11, 2025
d5f4ba5
Merge pull request #5803 from mboersma/bump-go
k8s-ci-robot Aug 11, 2025
970a534
dependabot(deps): bump github.com/onsi/gomega from 1.37.0 to 1.38.0
dependabot[bot] Aug 11, 2025
ecc3076
Merge pull request #5797 from willie-yao/custom-image-template
k8s-ci-robot Aug 11, 2025
3aa4d88
dependabot(deps): bump golang.org/x/mod from 0.26.0 to 0.27.0
dependabot[bot] Aug 11, 2025
404e96a
dependabot(deps): bump github.com/Azure/azure-sdk-for-go/sdk/azcore
dependabot[bot] Aug 11, 2025
f648e07
dependabot(deps): bump the all-github-actions group with 3 updates
dependabot[bot] Aug 11, 2025
a7a2de9
Merge pull request #5812 from kubernetes-sigs/dependabot/github_actio…
k8s-ci-robot Aug 11, 2025
ca89703
Merge pull request #5805 from kubernetes-sigs/dependabot/go_modules/g…
k8s-ci-robot Aug 11, 2025
8f3ddba
Merge pull request #5810 from kubernetes-sigs/dependabot/go_modules/g…
k8s-ci-robot Aug 11, 2025
969e0e9
dependabot(deps): bump golang.org/x/crypto from 0.40.0 to 0.41.0
dependabot[bot] Aug 11, 2025
3e76e4e
Merge pull request #5808 from kubernetes-sigs/dependabot/go_modules/g…
k8s-ci-robot Aug 12, 2025
a171336
Merge pull request #5811 from kubernetes-sigs/dependabot/go_modules/g…
k8s-ci-robot Aug 12, 2025
3ec27cf
dependabot(deps): bump github.com/Azure/azure-sdk-for-go/sdk/azidentity
dependabot[bot] Aug 12, 2025
dc78d0e
Fix disabling NAT gateway for `cluster` role subnets
cPu1 Aug 12, 2025
d2fb23f
chore: AzureCluster subnet default flow comments
jackfrancis Aug 12, 2025
41e8bbf
Merge pull request #5816 from cPu1/fix/cluster-nat
k8s-ci-robot Aug 12, 2025
41854e6
add release 1.21 to CAPZ metadata
jackfrancis Aug 12, 2025
578a274
Merge pull request #5818 from jackfrancis/metadata-1.21
k8s-ci-robot Aug 12, 2025
41d953b
Merge pull request #5814 from kubernetes-sigs/dependabot/go_modules/g…
k8s-ci-robot Aug 12, 2025
ecd4c98
Merge pull request #5817 from jackfrancis/azurecluster-subnet-comments
k8s-ci-robot Aug 12, 2025
c22e904
Add specific tolerations to calico-typha pods
nojnhuh Aug 12, 2025
7b2418f
Merge pull request #5819 from nojnhuh/typha-tolerations
k8s-ci-robot Aug 13, 2025
c2cf9c0
Bump Go toolchain to v1.24.6
mboersma May 30, 2025
ba59454
Merge pull request #5813 from mboersma/bump-go-v1.24
k8s-ci-robot Aug 14, 2025
d9bd7be
chore: add yq install to make install-tools
jackfrancis Aug 15, 2025
e859273
Merge pull request #5822 from jackfrancis/install-tools-yq
k8s-ci-robot Aug 15, 2025
ccaba5d
(release): v1.21.0 CHANGELOG (#5821)
jackfrancis Aug 18, 2025
1c3377f
Drop error condition from AKS node public IP prefix e2e test
nojnhuh Aug 21, 2025
21ae8a8
Merge pull request #5836 from k8s-infra-cherrypick-robot/cherry-pick-…
k8s-ci-robot Aug 25, 2025
a0c1a9e
Skip AKS Fleet e2e test
nojnhuh Sep 11, 2025
b20695b
Merge pull request #5870 from k8s-infra-cherrypick-robot/cherry-pick-…
k8s-ci-robot Sep 12, 2025
9fc4dee
Get GO_VERSION from toolchain statment
mboersma Sep 8, 2025
3107393
Merge pull request #5879 from mboersma/go-version-from-toolchain-rele…
k8s-ci-robot Sep 18, 2025
a786904
[release-1.21] update azidentity to v1.12.0
jackfrancis Sep 30, 2025
9f870f8
Merge pull request #5888 from jackfrancis/release-1.21-ms-auth-lib
k8s-ci-robot Sep 30, 2025
13712f6
Bump Go toolchain to v1.24.8
mboersma Oct 7, 2025
307bd4a
Merge pull request #5905 from mboersma/bump-go-release-1.21
k8s-ci-robot Oct 14, 2025
e2b8333
Bump Go toolchain to v1.24.9
mboersma Oct 15, 2025
aaf8a5b
Merge pull request #5908 from k8s-infra-cherrypick-robot/cherry-pick-…
k8s-ci-robot Oct 15, 2025
e6a302e
Bump cert-manager to v1.19.0
mboersma Oct 16, 2025
ec44ba1
Merge pull request #5912 from mboersma/bump-cert-manager-release-1.21
k8s-ci-robot Oct 16, 2025
ab41f34
Bump CAPI to v1.10.7
mboersma Oct 16, 2025
4b416fe
Merge pull request #5913 from mboersma/bump-capi-release-1.21
k8s-ci-robot Oct 16, 2025
bb9ff17
Add MachineHealthCheck for control plane to private cluster e2e template
nojnhuh Aug 7, 2025
a1a2c52
Merge pull request #5915 from k8s-infra-cherrypick-robot/cherry-pick-…
k8s-ci-robot Oct 16, 2025
11c202f
Don't take windows capi image versions into consideration if no windo…
willie-yao Sep 11, 2025
8e8c3c1
Merge pull request #5919 from k8s-infra-cherrypick-robot/cherry-pick-…
k8s-ci-robot Oct 17, 2025
58c104a
[release-1.21] Use explicit templates for Windows infra
jackfrancis Oct 17, 2025
7780d61
Bump cert-manager to v1.19.1
mboersma Oct 17, 2025
fbf2607
Merge pull request #5926 from mboersma/bump-cert-manager-release-1.21
k8s-ci-robot Oct 17, 2025
6062df0
Merge pull request #5923 from jackfrancis/release-1.21-windows-templa…
k8s-ci-robot Oct 18, 2025
ab953c1
Fix mishandling of azure:// prefix on AzureMachine UserAssignedIdenti…
nojnhuh Oct 21, 2025
846347a
Update UserAssignedIdentity providerID with azure:// prefix in templates
nojnhuh Oct 21, 2025
8ee5386
Merge pull request #5932 from nojnhuh/vm-identity-prefix
k8s-ci-robot Oct 22, 2025
f11b778
merge upstream/v1.21.1 into master
Dec 1, 2025
58757e1
UPSTREAM: <carry>: Add openshift specific changes
alexander-demicev Dec 13, 2021
faa6fe8
UPSTREAM: <carry>: Add manifest generator tool
RadekManak May 23, 2024
def786c
UPSTREAM: <carry>: Add e2e-test.sh script
RadekManak Jul 17, 2024
562c288
UPSTREAM: <carry>: Delete ASO deployment
nrb Oct 30, 2024
b67478a
UPSTREAM: <carry>: Don't install ASO CRDs
nrb Nov 21, 2024
46ba203
UPSTREAM: <carry>: Disable ASO API feature gate
nrb Nov 21, 2024
1a513a1
UPSTREAM: <carry>: Updating ose-azure-cluster-api-controllers-contain…
Dec 5, 2024
db02b26
UPSTREAM: <carry>: Remove unnecessary kustomize
RadekManak Feb 24, 2025
1e6c75a
UPSTREAM: <carry>: Update manifests generator tooling
RadekManak Feb 24, 2025
1922adc
UPSTREAM: <carry>: update go mod dependency for konflux
ashwindasr Apr 4, 2025
08a0ea2
UPSTREAM: <carry>: Updating ose-azure-cluster-api-controllers-contain…
Jun 19, 2025
e91ff7a
UPSTREAM: <carry>: Sync OWNERS file
JoelSpeed Jul 22, 2025
de3711b
UPSTREAM: <carry>: Sync OWNERS file
RadekManak Sep 4, 2025
c07add0
UPSTREAM: <carry>: Updating ose-azure-cluster-api-controllers-contain…
Sep 30, 2025
2bf69b7
UPSTREAM: <drop>: Update manifests generator
Dec 1, 2025
88cccb5
UPSTREAM: <drop>: Generate OpenShift manifests
Dec 1, 2025
aad1a3b
UPSTREAM: <drop>: Updating and vendoring go modules after an upstream…
Dec 1, 2025
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
10 changes: 5 additions & 5 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -41,16 +41,16 @@ jobs:

steps:
- name: Harden Runner
uses: step-security/harden-runner@0634a2670c59f64b4a01f0f96f84700a4088b9f0 # v2.12.0
uses: step-security/harden-runner@ec9f2d5744a09debf3a187a3f4f675c53b671911 # v2.13.0
with:
egress-policy: audit

- name: Checkout repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@fca7ace96b7d713c7035871441bd52efbe39e27e # v3.28.19
uses: github/codeql-action/init@76621b61decf072c1cee8dd1ce2d2a82d33c17ed # v3.29.8
with:
languages: ${{ matrix.language }}
# If you wish to specify custom queries, you can do so here or in a config file.
Expand All @@ -60,7 +60,7 @@ jobs:
# Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
# If this step fails, then you should remove it and run the build manually (see below)
- name: Autobuild
uses: github/codeql-action/autobuild@fca7ace96b7d713c7035871441bd52efbe39e27e # v3.28.19
uses: github/codeql-action/autobuild@76621b61decf072c1cee8dd1ce2d2a82d33c17ed # v3.29.8

# ℹ️ Command-line programs to run using the OS shell.
# 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun
Expand All @@ -73,6 +73,6 @@ jobs:
# ./location_of_script_within_repo/buildscript.sh

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@fca7ace96b7d713c7035871441bd52efbe39e27e # v3.28.19
uses: github/codeql-action/analyze@76621b61decf072c1cee8dd1ce2d2a82d33c17ed # v3.29.8
with:
category: "/language:${{matrix.language}}"
6 changes: 3 additions & 3 deletions .github/workflows/dependabot-code-gen.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
uses: step-security/harden-runner@0634a2670c59f64b4a01f0f96f84700a4088b9f0 # v2.12.0
uses: step-security/harden-runner@ec9f2d5744a09debf3a187a3f4f675c53b671911 # v2.13.0
with:
egress-policy: audit
- name: Set up Go 1.x
Expand All @@ -29,8 +29,8 @@ jobs:
go-version: '1.22'
id: go
- name: Check out code into the Go module directory
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- uses: actions/cache@5a3ec84eff668545956fd18022155c47e93e2684 # tag=v4.2.3
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
- uses: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809 # tag=v4.2.4
name: Restore go cache
with:
path: |
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/dependency-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,11 +17,11 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
uses: step-security/harden-runner@0634a2670c59f64b4a01f0f96f84700a4088b9f0 # v2.12.0
uses: step-security/harden-runner@ec9f2d5744a09debf3a187a3f4f675c53b671911 # v2.13.0
with:
egress-policy: audit

- name: 'Checkout Repository'
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
- name: 'Dependency Review'
uses: actions/dependency-review-action@da24556b548a50705dd671f47852072ea4c105d9 # v4.7.1
2 changes: 1 addition & 1 deletion .github/workflows/pr-golangci-lint.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ jobs:
- ""
- test
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # tag=v4.2.2
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # tag=v5.0.0

- name: Calculate go version
id: vars
Expand Down
27 changes: 0 additions & 27 deletions .github/workflows/scan.yml

This file was deleted.

6 changes: 3 additions & 3 deletions .github/workflows/scorecards.yml
Original file line number Diff line number Diff line change
Expand Up @@ -31,12 +31,12 @@ jobs:

steps:
- name: Harden Runner
uses: step-security/harden-runner@0634a2670c59f64b4a01f0f96f84700a4088b9f0 # v2.12.0
uses: step-security/harden-runner@ec9f2d5744a09debf3a187a3f4f675c53b671911 # v2.13.0
with:
egress-policy: audit

- name: "Checkout code"
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
persist-credentials: false

Expand Down Expand Up @@ -71,6 +71,6 @@ jobs:

# Upload the results to GitHub's code scanning dashboard.
- name: "Upload to code-scanning"
uses: github/codeql-action/upload-sarif@fca7ace96b7d713c7035871441bd52efbe39e27e # v3.28.19
uses: github/codeql-action/upload-sarif@76621b61decf072c1cee8dd1ce2d2a82d33c17ed # v3.29.8
with:
sarif_file: results.sarif
32 changes: 32 additions & 0 deletions .github/workflows/weekly-security-scan.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
name: Weekly security scan

on:
schedule:
# Cron for every Monday at 12:00 UTC.
- cron: "0 12 * * 1"

# Remove all permissions from GITHUB_TOKEN except metadata.
permissions: {}

jobs:
scan:
strategy:
fail-fast: false
matrix:
branch: [ main, release-1.20, release-1.19 ]
name: Trivy
runs-on: ubuntu-latest
steps:
- name: Check out code
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # tag=v5.0.0
with:
ref: ${{ matrix.branch }}
- name: Calculate go version
id: vars
run: echo "go_version=$(make go-version)" >> $GITHUB_OUTPUT
- name: Set up Go
uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # tag=v5.5.0
with:
go-version: ${{ steps.vars.outputs.go_version }}
- name: Run verify security target
run: make verify-security
26 changes: 26 additions & 0 deletions CHANGELOG/v1.19.5.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
## Changes by Kind

### Other (Cleanup or Flake)

- Bump CAPI to v1.9.8 ([#5675](https://github.com/kubernetes-sigs/cluster-api-provider-azure/pull/5675), [@mboersma](https://github.com/mboersma))
- Bump CAPI to v1.9.9 ([#5713](https://github.com/kubernetes-sigs/cluster-api-provider-azure/pull/5713), [@mboersma](https://github.com/mboersma))
- Remove community AKS marketplace extension from e2e tests because no longer valid ([#5647](https://github.com/kubernetes-sigs/cluster-api-provider-azure/pull/5647), [@alimaazamat](https://github.com/alimaazamat))

## Dependencies
_Nothing has changed._

### Added
_Nothing has changed._

### Changed
- github.com/cloudflare/circl: [v1.3.7 → v1.6.1](https://github.com/cloudflare/circl/compare/v1.3.7...v1.6.1)
- github.com/coredns/corefile-migration: [v1.0.25 → v1.0.26](https://github.com/coredns/corefile-migration/compare/v1.0.25...v1.0.26)
- sigs.k8s.io/cluster-api/test: v1.9.6 → v1.9.9
- sigs.k8s.io/cluster-api: v1.9.6 → v1.9.9

### Removed
_Nothing has changed._

## Details
<!-- markdown-link-check-disable-next-line -->
https://github.com/kubernetes-sigs/cluster-api-provider-azure/compare/v1.19.4...v1.19.5
26 changes: 26 additions & 0 deletions CHANGELOG/v1.19.6.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
## Changes by Kind

### Bug or Regression

- Adds the ability to disable CAPZ components through a manager flag. Flags added for disabling ASO Secret Controller and disabling Azure JSON Machine Controller. ([#5759](https://github.com/kubernetes-sigs/cluster-api-provider-azure/pull/5759), [@bryan-cox](https://github.com/bryan-cox))

### Other (Cleanup or Flake)

- Bump CAPI to v1.9.10 ([#5762](https://github.com/kubernetes-sigs/cluster-api-provider-azure/pull/5762), [@mboersma](https://github.com/mboersma))
- Update default Kubernetes version to 1.32 ([#5764](https://github.com/kubernetes-sigs/cluster-api-provider-azure/pull/5764), [@jsturtevant](https://github.com/jsturtevant))

## Dependencies

### Added
_Nothing has changed._

### Changed
- sigs.k8s.io/cluster-api/test: v1.9.9 → v1.9.10
- sigs.k8s.io/cluster-api: v1.9.9 → v1.9.10

### Removed
_Nothing has changed._

## Details
<!-- markdown-link-check-disable-next-line -->
https://github.com/kubernetes-sigs/cluster-api-provider-azure/compare/v1.19.5...v1.19.6
22 changes: 22 additions & 0 deletions CHANGELOG/v1.20.1.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
## Changes by Kind

### Other (Cleanup or Flake)

- Bump CAPI to v1.10.3 ([#5729](https://github.com/kubernetes-sigs/cluster-api-provider-azure/pull/5729), [@mboersma](https://github.com/mboersma))

## Dependencies

### Added
_Nothing has changed._

### Changed
- github.com/cloudflare/circl: [v1.3.7 → v1.6.1](https://github.com/cloudflare/circl/compare/v1.3.7...v1.6.1)
- sigs.k8s.io/cluster-api/test: v1.10.2 → v1.10.3
- sigs.k8s.io/cluster-api: v1.10.2 → v1.10.3

### Removed
_Nothing has changed._

## Details
<!-- markdown-link-check-disable-next-line -->
https://github.com/kubernetes-sigs/cluster-api-provider-azure/compare/v1.20.0...v1.20.1
26 changes: 26 additions & 0 deletions CHANGELOG/v1.20.2.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
## Changes by Kind

### Bug or Regression

- Adds the ability to disable CAPZ components through a manager flag. Flags added for disabling ASO Secret Controller and disabling Azure JSON Machine Controller. ([#5758](https://github.com/kubernetes-sigs/cluster-api-provider-azure/pull/5758), [@bryan-cox](https://github.com/bryan-cox))

### Other (Cleanup or Flake)

- Bump CAPI to v1.10.4 ([#5771](https://github.com/kubernetes-sigs/cluster-api-provider-azure/pull/5771), [@mboersma](https://github.com/mboersma))

## Dependencies

### Added
_Nothing has changed._

### Changed
- github.com/go-viper/mapstructure/v2: [v2.2.1 → v2.3.0](https://github.com/go-viper/mapstructure/compare/v2.2.1...v2.3.0)
- sigs.k8s.io/cluster-api/test: v1.10.3 → v1.10.4
- sigs.k8s.io/cluster-api: v1.10.3 → v1.10.4

### Removed
_Nothing has changed._

## Details
<!-- markdown-link-check-disable-next-line -->
https://github.com/kubernetes-sigs/cluster-api-provider-azure/compare/v1.20.1...v1.20.2
76 changes: 76 additions & 0 deletions CHANGELOG/v1.21.0.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,76 @@
## Changes by Kind

### Deprecation

- Warning messages added for deprecation of AzureManaged API ([#5699](https://github.com/kubernetes-sigs/cluster-api-provider-azure/pull/5699), [@alimaazamat](https://github.com/alimaazamat))

### Feature

- Add ability to optionally create the Private DNS Zone for unmanaged clusters instead of always creating one. Setting `PrivateDNSZone` within the `NetworkSpec` to `PrivateDNSZoneiCreationModeNone` will skip creating the Private DNS zone. ([#5666](https://github.com/kubernetes-sigs/cluster-api-provider-azure/pull/5666), [@sadasu](https://github.com/sadasu))

### Bug or Regression

- ASOAPI: Fixed a possible bug that could leave ASO resources dangling when they should be deleted. ([#5571](https://github.com/kubernetes-sigs/cluster-api-provider-azure/pull/5571), [@nojnhuh](https://github.com/nojnhuh))
- Adds the ability to disable CAPZ components through a manager flag. Flags added for disabling ASO Secret Controller and disabling Azure JSON Machine Controller. ([#5552](https://github.com/kubernetes-sigs/cluster-api-provider-azure/pull/5552), [@bryan-cox](https://github.com/bryan-cox))
- Dont give contributor access to byo identity in aks mgmt cluster creation ([#5802](https://github.com/kubernetes-sigs/cluster-api-provider-azure/pull/5802), [@willie-yao](https://github.com/willie-yao))
- Fixes disabling NAT gateway for `cluster` role subnets ([#5816](https://github.com/kubernetes-sigs/cluster-api-provider-azure/pull/5816), [@cPu1](https://github.com/cPu1))

### Other (Cleanup or Flake)

- Bump CAPI to v1.10.3 ([#5712](https://github.com/kubernetes-sigs/cluster-api-provider-azure/pull/5712), [@mboersma](https://github.com/mboersma))
- Bump CAPI to v1.10.4 ([#5761](https://github.com/kubernetes-sigs/cluster-api-provider-azure/pull/5761), [@mboersma](https://github.com/mboersma))

## Dependencies

### Added
_Nothing has changed._

### Changed
- cel.dev/expr: v0.22.1 → v0.23.0
- github.com/Azure/azure-sdk-for-go/sdk/azcore: [v1.18.0 → v1.18.2](https://github.com/Azure/azure-sdk-for-go/compare/sdk/azcore/v1.18.0...sdk/azcore/v1.18.2)
- github.com/Azure/azure-sdk-for-go/sdk/azidentity: [v1.10.0 → v1.11.0](https://github.com/Azure/azure-sdk-for-go/compare/sdk/azidentity/v1.10.0...sdk/azidentity/v1.11.0)
- github.com/Azure/azure-sdk-for-go/sdk/internal: [v1.11.1 → v1.11.2](https://github.com/Azure/azure-sdk-for-go/compare/sdk/internal/v1.11.1...sdk/internal/v1.11.2)
- github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/msi/armmsi: [v1.2.0 → v1.3.0](https://github.com/Azure/azure-sdk-for-go/compare/sdk/resourcemanager/msi/armmsi/v1.2.0...sdk/resourcemanager/msi/armmsi/v1.3.0)
- github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp: [v1.26.0 → v1.27.0](https://github.com/GoogleCloudPlatform/opentelemetry-operations-go/compare/detectors/gcp/v1.26.0...detectors/gcp/v1.27.0)
- github.com/cloudflare/circl: [v1.3.7 → v1.6.1](https://github.com/cloudflare/circl/compare/v1.3.7...v1.6.1)
- github.com/cncf/xds/go: [2f00578 → ae57f3c](https://github.com/cncf/xds/compare/2f00578...ae57f3c)
- github.com/go-jose/go-jose/v4: [v4.0.4 → v4.0.5](https://github.com/go-jose/go-jose/compare/v4.0.4...v4.0.5)
- github.com/go-viper/mapstructure/v2: [v2.2.1 → v2.3.0](https://github.com/go-viper/mapstructure/compare/v2.2.1...v2.3.0)
- github.com/golang-jwt/jwt/v5: [v5.2.2 → v5.3.0](https://github.com/golang-jwt/jwt/compare/v5.2.2...v5.3.0)
- github.com/grpc-ecosystem/grpc-gateway/v2: [v2.26.3 → v2.27.1](https://github.com/grpc-ecosystem/grpc-gateway/compare/v2.26.3...v2.27.1)
- github.com/hashicorp/go-retryablehttp: [v0.7.7 → v0.7.8](https://github.com/hashicorp/go-retryablehttp/compare/v0.7.7...v0.7.8)
- github.com/onsi/gomega: [v1.37.0 → v1.38.0](https://github.com/onsi/gomega/compare/v1.37.0...v1.38.0)
- github.com/prometheus/common: [v0.64.0 → v0.65.0](https://github.com/prometheus/common/compare/v0.64.0...v0.65.0)
- github.com/spf13/pflag: [v1.0.6 → v1.0.7](https://github.com/spf13/pflag/compare/v1.0.6...v1.0.7)
- go.opentelemetry.io/contrib/detectors/gcp: v1.34.0 → v1.35.0
- go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc: v1.36.0 → v1.37.0
- go.opentelemetry.io/otel/exporters/otlp/otlptrace: v1.36.0 → v1.37.0
- go.opentelemetry.io/otel/exporters/prometheus: v0.58.0 → v0.59.0
- go.opentelemetry.io/otel/metric: v1.36.0 → v1.37.0
- go.opentelemetry.io/otel/sdk/metric: v1.36.0 → v1.37.0
- go.opentelemetry.io/otel/sdk: v1.36.0 → v1.37.0
- go.opentelemetry.io/otel/trace: v1.36.0 → v1.37.0
- go.opentelemetry.io/otel: v1.36.0 → v1.37.0
- go.opentelemetry.io/proto/otlp: v1.6.0 → v1.7.0
- golang.org/x/crypto: v0.39.0 → v0.41.0
- golang.org/x/mod: v0.25.0 → v0.27.0
- golang.org/x/net: v0.40.0 → v0.42.0
- golang.org/x/sync: v0.15.0 → v0.16.0
- golang.org/x/sys: v0.33.0 → v0.35.0
- golang.org/x/telemetry: bda5523 → 8d8967a
- golang.org/x/term: v0.32.0 → v0.34.0
- golang.org/x/text: v0.26.0 → v0.28.0
- golang.org/x/tools: v0.33.0 → v0.35.0
- google.golang.org/genproto/googleapis/api: 55703ea → 513f239
- google.golang.org/genproto/googleapis/rpc: 55703ea → 513f239
- google.golang.org/grpc: v1.72.1 → v1.73.0
- sigs.k8s.io/cluster-api/test: v1.10.2 → v1.10.4
- sigs.k8s.io/cluster-api: v1.10.2 → v1.10.4

### Removed
- github.com/dgryski/go-rendezvous: [9f7001d](https://github.com/dgryski/go-rendezvous/tree/9f7001d)
- github.com/redis/go-redis/v9: [v9.8.0](https://github.com/redis/go-redis/tree/v9.8.0)

## Details
<!-- markdown-link-check-disable-next-line -->
https://github.com/kubernetes-sigs/cluster-api-provider-azure/compare/v1.20.0...v1.21.0
2 changes: 1 addition & 1 deletion Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@
ARG ARCH

# Build the manager binary
FROM golang:1.23 AS builder
FROM golang:1.24 AS builder
WORKDIR /workspace

# Run this with docker build --build_arg $(go env GOPROXY) to override the goproxy
Expand Down
Loading