Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
89 commits
Select commit Hold shift + click to select a range
d6e7ad1
fix openstack getServerByName return error code - Additional notes: (…
k8s-infra-cherrypick-robot Sep 4, 2026
bd67cb9
k8s-keystone-auth: Don't log tokens (#3184)
k8s-infra-cherrypick-robot Sep 4, 2026
f203d10
Add mandre to approvers (#3186)
k8s-infra-cherrypick-robot Sep 4, 2026
3a512e7
[release-1.35] [magnum-auto-healer] Add certificate validation (#3189)
k8s-infra-cherrypick-robot Sep 4, 2026
51fca6b
Bump golangci-lint (#3201)
k8s-infra-cherrypick-robot Sep 9, 2026
0096c59
Pin GitHub Actions to git SHAs (#3203)
k8s-infra-cherrypick-robot Sep 9, 2026
9f7cfa5
Fix cloud-node-controller ClusterRoleBinding subject (#3206)
k8s-infra-cherrypick-robot Sep 9, 2026
0aa65a5
make: Add lint-charts target (#3213)
k8s-infra-cherrypick-robot Sep 10, 2026
17bd137
merge upstream/release-1.35 into release-4.22
Sep 14, 2026
9a57ee9
CARRY: Add DOWNSTREAM_OWNERS
dulek Oct 12, 2023
d77f85d
CARRY: Don't ignore vendor directory
mandre Jun 12, 2025
91a5f2b
CARRY: Add .snyk configuration file
mandre Jan 3, 2024
9210b67
CARRY: Add images
mandre Feb 6, 2024
6e0d1d4
UPSTREAM: <carry>: update go mod dependency for konflux
ashwindasr Apr 4, 2025
4b54477
CARRY: Vendoring
mandre Jun 12, 2025
459a31c
DROP: Additional changes to gitignore needed for vendoring
mandre Jun 12, 2025
2c2d928
Bump golangci to 1.61 (#2664)
k8s-infra-cherrypick-robot Sep 18, 2024
496e782
allow node service to run without openstack client (#2662)
k8s-infra-cherrypick-robot Sep 18, 2024
e70feb1
[release-1.31]: prepare a new release (#2660)
kayrus Sep 19, 2024
4791462
Bump go deps (#2674)
k8s-infra-cherrypick-robot Sep 19, 2024
6b1e92f
Bump chart releaser
kayrus Sep 19, 2024
9e523eb
fix global config requirement for node-service (#2683)
k8s-infra-cherrypick-robot Oct 1, 2024
479771f
CARRY: Add DOWNSTREAM_OWNERS
dulek Oct 12, 2023
09138f7
CARRY: Add images
mandre Feb 6, 2024
effec10
CARRY: Vendoring
mandre Oct 16, 2024
e387b54
[release-1.30] [occm] add a node selector support for loadbalancer se…
k8s-infra-cherrypick-robot May 28, 2024
b873654
CARRY: Add DOWNSTREAM_OWNERS
dulek Oct 12, 2023
c9f209a
CARRY: Add .snyk configuration file
mandre Jan 3, 2024
738d00e
CARRY: Add images
mandre Feb 6, 2024
cbc902b
CARRY: More snyk ignores
dulek Jan 29, 2024
1a99ded
Remove dulek from shiftstack-team
stephenfin May 15, 2024
09dfe04
UPSTREAM: <carry>: Updating ose-openstack-cloud-controller-manager-co…
EmilienM Jun 14, 2024
c5a57e0
UPSTREAM: <carry>: Updating ose-openstack-cinder-csi-driver-container…
EmilienM Jun 14, 2024
813a838
UPSTREAM: <carry>: Updating csi-driver-manila-container image to be c…
EmilienM Jun 14, 2024
2d60cf2
CARRY: Vendoring
EmilienM Jun 14, 2024
a2605f9
CARRY: Add DOWNSTREAM_OWNERS
dulek Oct 12, 2023
1b52298
CARRY: Add .snyk configuration file
mandre Jan 3, 2024
a4aa5be
CARRY: Add images
mandre Feb 6, 2024
cfb052e
CARRY: Vendoring
tsmetana Mar 19, 2019
372c0a9
CARRY: More snyk ignores
dulek Jan 29, 2024
00b6896
Bump golangci-lint for go 1.22 (#2567)
k8s-infra-cherrypick-robot Apr 3, 2024
92d4451
Remove enforcement of IPv6 LB as internal (#2557) (#2566)
MaysaMacedo Apr 3, 2024
1a7e394
Allow changing cluster-name on existing deployments (#2568)
k8s-infra-cherrypick-robot Apr 9, 2024
1b5dfab
Updating ose-openstack-cinder-csi-driver-container image to be consis…
May 21, 2024
5456b73
Remove dulek from shiftstack-team
stephenfin May 15, 2024
58372e6
[tests]: fix 1.29 tests CI (#2608)
kayrus May 29, 2024
8f9861a
[release-1.29] [occm] add a node selector support for loadbalancer se…
k8s-infra-cherrypick-robot May 29, 2024
8665cde
Updating ose-openstack-cinder-csi-driver-container image to be consis…
Sep 4, 2024
d354052
Updating csi-driver-manila-container image to be consistent with ART …
Sep 4, 2024
eab7b60
UPSTREAM: <carry>: Updating ose-openstack-cloud-controller-manager-co…
Sep 5, 2024
63449d1
[release-1.31] [occm] fix ovn security groups (#2713)
k8s-infra-cherrypick-robot Nov 15, 2024
a6c60e2
Updating ose-openstack-cinder-csi-driver-container image to be consis…
Dec 4, 2024
3b2722b
UPSTREAM: <carry>: Updating ose-openstack-cloud-controller-manager-co…
Dec 6, 2024
31fe524
Updating csi-driver-manila-container image to be consistent with ART …
Dec 4, 2024
378acd8
Automated cherry pick of #2722: prepare release 1.31.2 (#2723)
zetaab Nov 23, 2024
998982d
cinder-csi-plugin: Add --with-topology option (#2743) (#2746)
EmilienM Dec 12, 2024
9d565d0
Update golang.org/x/net to v0.33.0 (#2769)
lentzi90 Feb 14, 2025
e1ecc15
tests: increase golangci-lint timeout (#2775)
k8s-infra-cherrypick-robot Feb 19, 2025
bd4fa43
[cinder-csi-plugin] Refactor list volumes (#2766) (#2842)
kayrus Feb 20, 2025
efe46cc
[release-131] preapre a new 1.31.3 release (#2850)
kayrus Feb 26, 2025
54dd83b
[charts] fix chart version
kayrus Feb 26, 2025
b5df0fc
Updating and vendoring go modules after an upstream merge
Feb 27, 2025
893b879
UPSTREAM: <carry>: update go mod dependency for konflux
ashwindasr Apr 4, 2025
02f3802
cinder-csi-plugin, manila-csi-plugin: Correct formatting character
stephenfin Mar 24, 2025
99e4310
OWNERS: Update team osasinfra
pierreprinetti May 21, 2025
defc379
CARRY: don't ignore json files
mandre Jul 8, 2025
bd2108a
[release-1.33][manila-csi-plugin] Add support for authentication via …
Jun 20, 2025
4e04903
fix lbaas logs (#2923)
k8s-infra-cherrypick-robot Jul 2, 2025
d9ec1d9
[manila-csi-plugin] support muilple share rules
moonek Nov 20, 2024
57d659b
shiftstack: Update OWNERS
pierreprinetti Oct 6, 2025
5a79bcc
Updating ose-openstack-cinder-csi-driver-container image to be consis…
Sep 11, 2025
fa1a519
UPSTREAM: <carry>: Updating ose-openstack-cloud-controller-manager-co…
Sep 30, 2025
b403ad9
Updating csi-driver-manila-container image to be consistent with ART …
Sep 14, 2025
c2f6e8a
CARRY: Don't ignore vendor directory
mandre Jun 12, 2025
ac82258
CARRY: Vendoring
mandre Oct 14, 2025
720cab1
DROP: Downgrade go version to 1.24
mandre Oct 14, 2025
a23ef37
[release-1.34] update test deps (#3018)
k8s-infra-cherrypick-robot Oct 15, 2025
00e965a
release 1.34.1 (#3016)
zetaab Oct 15, 2025
438c3fa
NO-JIRA: Update ShiftStack OWNERS
pierreprinetti Nov 20, 2025
9e73836
Updating ose-openstack-cinder-csi-driver-container image to be consis…
Dec 18, 2025
8290da7
UPSTREAM: <carry>: Updating ose-openstack-cloud-controller-manager-co…
Dec 20, 2025
21b1288
Updating csi-driver-manila-container image to be consistent with ART …
Jan 15, 2026
e5755ff
CARRY: Update DOWNSTREAM_OWNERS
stephenfin Feb 26, 2026
d1fffda
Updating csi-driver-manila-container image to be consistent with ART …
Mar 2, 2026
70196fd
Updating ose-openstack-cinder-csi-driver-container image to be consis…
Mar 2, 2026
2fda3c1
UPSTREAM: <carry>: Updating ose-openstack-cloud-controller-manager-co…
Mar 4, 2026
6be115a
Updating and vendoring go modules after an upstream merge
stephenfin May 6, 2026
5310d91
OCPBUGS-83552: Bump google.golang.org/grpc to 1.79.3
sbiradar10 May 25, 2026
c37899d
UPSTREAM: <drop>: Updating and vendoring go modules after an upstream…
Sep 14, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions .github/workflows/pr.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -10,23 +10,23 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v3
uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744
with:
fetch-depth: 0

- name: Set up Helm
uses: azure/setup-helm@v3
uses: azure/setup-helm@5119fcb9089d432beecbf79bb2c7915207344b78
with:
version: v3.10.0

- uses: actions/setup-python@v4
- uses: actions/setup-python@7f4fc3e22c37d6ff65e88745f38bd3157c663f7c
with:
python-version: '3.9'
check-latest: true

# see example https://github.com/helm/chart-testing-action
- name: Set up chart-testing
uses: helm/chart-testing-action@v2.3.1
uses: helm/chart-testing-action@afea100a513515fbd68b0e72a7bb0ae34cb62aec

- name: Run chart-testing (lint)
run: ct lint --target-branch ${GITHUB_BASE_REF}
2 changes: 1 addition & 1 deletion .github/workflows/release.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ jobs:
contents: write
steps:
- name: Checkout
uses: actions/checkout@v3
uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744
with:
fetch-depth: 0

Expand Down
22 changes: 7 additions & 15 deletions .golangci.yaml
Original file line number Diff line number Diff line change
@@ -1,12 +1,6 @@
version: "2"
output:
formats:
text:
path: stdout
colors: false
issues:
max-same-issues: 0
max-issues-per-linter: 0
run:
concurrency: 2
timeout: 10m0s
linters:
exclusions:
generated: lax
Expand All @@ -22,9 +16,7 @@ linters:
formatters:
enable:
- gofmt
exclusions:
generated: lax
paths:
- third_party$
- builtin$
- examples$
output:
formats:
 - format: line-number
 path: stdout
4 changes: 3 additions & 1 deletion Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -57,6 +57,8 @@ BUILD_CMDS ?= openstack-cloud-controller-manager \
barbican-kms-plugin \
magnum-auto-healer \
client-keystone-auth
export GOLANGCI_LINT_VERSION ?= v2.13.2
export HELM_UNITTEST_VERSION ?= v1.1.2

# CTI targets

Expand All @@ -81,7 +83,7 @@ $(BUILD_CMDS): $(SOURCES)
test: unit functional

check: work
go run github.com/golangci/golangci-lint/v2/cmd/golangci-lint@v2.3.1 run --timeout=20m ./...
go run github.com/golangci/golangci-lint/cmd/golangci-lint@v1.61.0 run --timeout=20m ./...

unit: work
go test -tags=unit $(shell go list ./... | sed -e '/sanity/ { N; d; }' | sed -e '/tests/ {N; d;}') $(TESTARGS)
Expand Down
2 changes: 2 additions & 0 deletions OWNERS
Original file line number Diff line number Diff line change
Expand Up @@ -6,10 +6,12 @@ emeritus_approvers:
approvers:
- dulek
- kayrus
- mandre
- stephenfin
- zetaab
reviewers:
- dulek
- kayrus
- mandre
- stephenfin
- zetaab
4 changes: 2 additions & 2 deletions charts/cinder-csi-plugin/Chart.yaml
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
apiVersion: v1
appVersion: v1.35.0
appVersion: v1.31.3
description: Cinder CSI Chart for OpenStack
name: openstack-cinder-csi
version: 2.35.0
version: 2.31.7
home: https://github.com/kubernetes/cloud-provider-openstack
icon: https://github.com/kubernetes/kubernetes/blob/master/logo/logo.png
maintainers:
Expand Down
4 changes: 2 additions & 2 deletions charts/manila-csi-plugin/Chart.yaml
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
apiVersion: v1
appVersion: v1.35.0
appVersion: v1.31.3
description: Manila CSI Chart for OpenStack
name: openstack-manila-csi
version: 2.35.0
version: 2.31.3
home: http://github.com/kubernetes/cloud-provider-openstack
icon: https://github.com/kubernetes/kubernetes/blob/master/logo/logo.png
maintainers:
Expand Down
4 changes: 2 additions & 2 deletions charts/openstack-cloud-controller-manager/Chart.yaml
Original file line number Diff line number Diff line change
@@ -1,10 +1,10 @@
apiVersion: v2
appVersion: v1.35.0
appVersion: v1.31.3
description: Openstack Cloud Controller Manager Helm Chart
icon: https://object-storage-ca-ymq-1.vexxhost.net/swift/v1/6e4619c416ff4bd19e1c087f27a43eea/www-images-prod/openstack-logo/OpenStack-Logo-Vertical.png
home: https://github.com/kubernetes/cloud-provider-openstack
name: openstack-cloud-controller-manager
version: 2.35.0
version: 2.31.3
maintainers:
- name: eumel8
email: f.kloeker@telekom.de
Expand Down
18 changes: 14 additions & 4 deletions cmd/cinder-csi-plugin/main.go
Original file line number Diff line number Diff line change
Expand Up @@ -90,6 +90,8 @@ func main() {

cmd.PersistentFlags().BoolVar(&withTopology, "with-topology", true, "cluster is topology-aware")

cmd.PersistentFlags().BoolVar(&withTopology, "with-topology", true, "cluster is topology-aware")

cmd.PersistentFlags().StringSliceVar(&cloudNames, "cloud-name", []string{""}, "Cloud name to instruct CSI driver to read additional OpenStack cloud credentials from the configuration subsections. This option can be specified multiple times to manage multiple OpenStack clouds.")
cmd.PersistentFlags().StringToStringVar(&additionalTopologies, "additional-topology", map[string]string{}, "Additional CSI driver topology keys, for example topology.kubernetes.io/region=REGION1. This option can be specified multiple times to add multiple additional topology keys.")

Expand All @@ -99,7 +101,6 @@ func main() {
cmd.PersistentFlags().BoolVar(&provideControllerService, "provide-controller-service", true, "If set to true then the CSI driver does provide the controller service (default: true)")
cmd.PersistentFlags().BoolVar(&provideNodeService, "provide-node-service", true, "If set to true then the CSI driver does provide the node service (default: true)")
cmd.PersistentFlags().BoolVar(&noClient, "node-service-no-os-client", false, "If set to true then the CSI driver node service will not use the OpenStack client (default: false)")
cmd.PersistentFlags().MarkDeprecated("node-service-no-os-client", "This flag is deprecated and will be removed in the future. Node service do not use OpenStack credentials anymore.") //nolint:errcheck

openstack.AddExtraFlags(pflag.CommandLine)

Expand All @@ -112,7 +113,6 @@ func handle() {
d := cinder.NewDriver(&cinder.DriverOpts{
Endpoint: endpoint,
ClusterID: cluster,
PVCLister: csi.GetPVCLister(),
WithTopology: withTopology,
})

Expand All @@ -122,7 +122,7 @@ func handle() {
var err error
clouds := make(map[string]openstack.IOpenStack)
for _, cloudName := range cloudNames {
clouds[cloudName], err = openstack.GetOpenStackProvider(cloudName)
clouds[cloudName], err = openstack.GetOpenStackProvider(cloudName, false)
if err != nil {
klog.Warningf("Failed to GetOpenStackProvider %s: %v", cloudName, err)
return
Expand All @@ -133,7 +133,17 @@ func handle() {
}

if provideNodeService {
// Initialize mount
var err error
clouds := make(map[string]openstack.IOpenStack)
for _, cloudName := range cloudNames {
clouds[cloudName], err = openstack.GetOpenStackProvider(cloudName, noClient)
if err != nil {
klog.Warningf("Failed to GetOpenStackProvider %s: %v", cloudName, err)
return
}
}

//Initialize mount
mount := mount.GetMountProvider()

cfg, err := openstack.GetConfigFromFiles(cloudConfig)
Expand Down
6 changes: 3 additions & 3 deletions docs/cinder-csi-plugin/multi-region-clouds.md
Original file line number Diff line number Diff line change
Expand Up @@ -167,7 +167,7 @@ spec:
- name: liveness-probe
...
- name: cinder-csi-plugin
image: registry.k8s.io/provider-os/cinder-csi-plugin:v1.35.0
image: registry.k8s.io/provider-os/cinder-csi-plugin:v1.34.1
args:
- /bin/cinder-csi-plugin
- --endpoint=$(CSI_ENDPOINT)
Expand Down Expand Up @@ -217,7 +217,7 @@ spec:
- name: liveness-probe
...
- name: cinder-csi-plugin
image: registry.k8s.io/provider-os/cinder-csi-plugin:v1.35.0
image: registry.k8s.io/provider-os/cinder-csi-plugin:v1.34.1
args:
- /bin/cinder-csi-plugin
- --endpoint=$(CSI_ENDPOINT)
Expand Down Expand Up @@ -283,7 +283,7 @@ spec:
- Topology=true
...
- name: cinder-csi-plugin
image: registry.k8s.io/provider-os/cinder-csi-plugin:v1.35.0
image: registry.k8s.io/provider-os/cinder-csi-plugin:v1.34.1
args:
- /bin/cinder-csi-plugin
- --endpoint=$(CSI_ENDPOINT)
Expand Down
6 changes: 2 additions & 4 deletions docs/cinder-csi-plugin/using-cinder-csi-plugin.md
Original file line number Diff line number Diff line change
Expand Up @@ -120,11 +120,9 @@ In addition to the standard set of klog flags, `cinder-csi-plugin` accepts the f
Defaults to `true` (enabled).
</dd>

<dt>--pvc-annotations &lt;disabled&gt;</dt>
<dt>--node-service-no-os-client &lt;disabled&gt;</dt>
<dd>
If set to true then the CSI driver will use PVC annotations to provide volume
scheduler hints. See [Supported PVC Annotations](#supported-pvc-annotations)
for more information.
If set to true then the CSI driver does not provide the OpenStack client in the node service.

Defaults to `false` (disabled).
</dd>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -252,7 +252,7 @@ it as a service. There are several things we need to notice in the
deployment manifest:

- We are using image
`registry.k8s.io/provider-os/k8s-keystone-auth:v1.35.0`
`registry.k8s.io/provider-os/k8s-keystone-auth:v1.34.1`
- We use `k8s-auth-policy` configmap created above.
- The pod uses service account `keystone-auth` created above.
- We use `keystone-auth-certs` secret created above to inject the
Expand Down
19 changes: 18 additions & 1 deletion docs/magnum-auto-healer/using-magnum-auto-healer.md
Original file line number Diff line number Diff line change
Expand Up @@ -73,7 +73,7 @@ user_id=ceb61464a3d341ebabdf97d1d4b97099
user_project_id=b23a5e41d1af4c20974bf58b4dff8e5a
password=password
region=RegionOne
image=registry.k8s.io/provider-os/magnum-auto-healer:v1.35.0
image=registry.k8s.io/provider-os/magnum-auto-healer:v1.34.1

cat <<EOF | kubectl apply -f -
---
Expand Down Expand Up @@ -183,6 +183,23 @@ spec:
EOF
```

#### Endpoint health check parameters

The `Endpoint` type health check supports the following parameters:

| Parameter | Type | Default | Description |
|---|---|---|---|
| `protocol` | string | `HTTPS` | URL scheme to use. `HTTP` or `HTTPS` (case-insensitive). |
| `port` | int | `6443` | Port to connect to on the node. |
| `endpoints` | []string | `["/healthz"]` | List of URL paths to check. |
| `ok-codes` | []int | `[200]` | HTTP response codes considered healthy. |
| `unhealthy-duration` | duration | `300s` | How long a node must be continuously unhealthy before repair is triggered. |
| `unhealthy-annotation` | string | `autohealing.openstack.org/unhealthy-timestamp` | Node annotation used to record when the node first became unhealthy. |
| `require-token` | bool | `false` | Whether to include a bearer token in the request. |
| `token` | string | read from `/var/run/secrets/kubernetes.io/serviceaccount/token` | Bearer token value. Only used when `require-token` is `true`. |
| `ca-file` | string | `/var/run/secrets/kubernetes.io/serviceaccount/ca.crt` | Path to a CA certificate file used to verify the server's TLS certificate. Only used when `protocol` is `HTTPS`. |
| `tls-insecure` | bool | `false` | If true, skip TLS certificate verification. |

### Testing magnum-auto-healer

We could ssh into a worker node(`lingxian-por-test-1-12-7-ha-bbgjts5g4xhb-minion-1` in this example) and stop the kubelet service to simulate the worker node failure. The node status check is covered in NodeCondition type of health check plugin(see configuration above).
Expand Down
1 change: 0 additions & 1 deletion docs/manila-csi-plugin/using-manila-csi-plugin.md
Original file line number Diff line number Diff line change
Expand Up @@ -71,7 +71,6 @@ Parameter | Required | Description
----------|----------|------------
`shareID` | if `shareName` is not given | The UUID of the share
`shareName` | if `shareID` is not given | The name of the share
`shareAccessID` | _no_ | The UUID of the access rule for the share. This parameter is being deprecated and replaced by `shareAccessIDs`.
`shareAccessIDs` | _yes_ | Comma separated UUIDs of access rules for the share
`cephfs-mounter` | _no_ | Relevant for CephFS Manila shares. Specifies which mounting method to use with the CSI CephFS driver. Available options are `kernel` and `fuse`, defaults to `fuse`. See [CSI CephFS docs](https://github.com/ceph/ceph-csi/blob/csi-v1.0/docs/deploy-cephfs.md#configuration) for further information.
`cephfs-kernelMountOptions` | _no_ | Relevant for CephFS Manila shares. Specifies mount options for CephFS kernel client. See [CSI CephFS docs](https://github.com/ceph/ceph-csi/blob/csi-v1.0/docs/deploy-cephfs.md#configuration) for further information.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -172,7 +172,7 @@ Here are several other config options are not included in the example configurat
### Deploy octavia-ingress-controller

```shell
image="registry.k8s.io/provider-os/octavia-ingress-controller:v1.35.0"
image="registry.k8s.io/provider-os/octavia-ingress-controller:v1.34.1"

cat <<EOF > /etc/kubernetes/octavia-ingress-controller/deployment.yaml
---
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -267,12 +267,6 @@ Although the openstack-cloud-controller-manager was initially implemented with N
node-selector="env, region=default"
```

See also the Kubernetes [`node.kubernetes.io/exclude-from-external-load-balancers`](https://kubernetes.io/docs/reference/labels-annotations-taints/#node-kubernetes-io-exclude-from-external-load-balancers) label. When this label is set to `true`, the node is excluded from the LoadBalancer pool.

This label also triggers the Cloud Controller Manager to execute the `EnsureLoadBalancer` method to reconcile the LoadBalancer. If a node was already part of the cluster and its label was later modified after the service's `node-selector` annotation was changed, you can explicitly assign `node.kubernetes.io/exclude-from-external-load-balancers=false` (the `false` value is supported starting from Kubernetes v1.34) label to a node to force the Cloud Controller Manager to reconcile the LoadBalancer pool.

For example, if a service has `node-selector="env=production"` and a node is labeled `env=development`, updating the node's label to `env=production` will not automatically add it to the LoadBalancer pool. In such cases, setting `node.kubernetes.io/exclude-from-external-load-balancers=false` label to the node ensures that the Cloud Controller Manager re-evaluates the node's eligibility and updates the LoadBalancer configuration accordingly.

* `cascade-delete`
Determines whether or not to perform cascade deletion of load balancers. Default: true.

Expand Down
2 changes: 1 addition & 1 deletion examples/webhook/keystone-deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ spec:
serviceAccountName: k8s-keystone
containers:
- name: k8s-keystone-auth
image: registry.k8s.io/provider-os/k8s-keystone-auth:v1.35.0
image: registry.k8s.io/provider-os/k8s-keystone-auth:v1.34.1
args:
- ./bin/k8s-keystone-auth
- --tls-cert-file
Expand Down
35 changes: 18 additions & 17 deletions go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@ go 1.25.5
require (
github.com/container-storage-interface/spec v1.11.0
github.com/google/uuid v1.6.0
github.com/gophercloud/gophercloud v1.14.1
github.com/gophercloud/gophercloud/v2 v2.8.0
github.com/gophercloud/utils/v2 v2.0.0-20250930154317-576cdf6142a7
github.com/hashicorp/go-version v1.7.0
Expand All @@ -21,9 +22,9 @@ require (
github.com/stretchr/testify v1.11.1
go.uber.org/goleak v1.3.0
golang.org/x/exp v0.0.0-20251002181428-27f1f14c8bb9
golang.org/x/sys v0.39.0
golang.org/x/term v0.38.0
google.golang.org/grpc v1.79.3
golang.org/x/sys v0.38.0
golang.org/x/term v0.37.0
google.golang.org/grpc v1.76.0
google.golang.org/protobuf v1.36.10
gopkg.in/gcfg.v1 v1.2.3
gopkg.in/godo.v2 v2.0.9
Expand Down Expand Up @@ -57,7 +58,7 @@ replace (
)

require (
cel.dev/expr v0.25.1 // indirect
cel.dev/expr v0.24.0 // indirect
cyphar.com/go-pathrs v0.2.1 // indirect
github.com/Azure/go-ansiterm v0.0.0-20250102033503-faa5f7b0171c // indirect
github.com/JeffAshton/win_pdh v0.0.0-20161109143554-76bb4ee9f0ab // indirect
Expand Down Expand Up @@ -160,27 +161,27 @@ require (
go.opentelemetry.io/contrib/instrumentation/github.com/emicklei/go-restful/otelrestful v0.44.0 // indirect
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.63.0 // indirect
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.63.0 // indirect
go.opentelemetry.io/otel v1.39.0 // indirect
go.opentelemetry.io/otel v1.38.0 // indirect
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.38.0 // indirect
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.38.0 // indirect
go.opentelemetry.io/otel/metric v1.39.0 // indirect
go.opentelemetry.io/otel/sdk v1.39.0 // indirect
go.opentelemetry.io/otel/trace v1.39.0 // indirect
go.opentelemetry.io/otel/metric v1.38.0 // indirect
go.opentelemetry.io/otel/sdk v1.38.0 // indirect
go.opentelemetry.io/otel/trace v1.38.0 // indirect
go.opentelemetry.io/proto/otlp v1.8.0 // indirect
go.uber.org/multierr v1.11.0 // indirect
go.uber.org/zap v1.27.0 // indirect
go.yaml.in/yaml/v2 v2.4.3 // indirect
go.yaml.in/yaml/v3 v3.0.4 // indirect
golang.org/x/crypto v0.46.0 // indirect
golang.org/x/mod v0.30.0 // indirect
golang.org/x/net v0.48.0 // indirect
golang.org/x/oauth2 v0.34.0 // indirect
golang.org/x/sync v0.19.0 // indirect
golang.org/x/text v0.32.0 // indirect
golang.org/x/crypto v0.45.0 // indirect
golang.org/x/mod v0.29.0 // indirect
golang.org/x/net v0.47.0 // indirect
golang.org/x/oauth2 v0.31.0 // indirect
golang.org/x/sync v0.18.0 // indirect
golang.org/x/text v0.31.0 // indirect
golang.org/x/time v0.13.0 // indirect
golang.org/x/tools v0.39.0 // indirect
google.golang.org/genproto/googleapis/api v0.0.0-20251202230838-ff82c1b0f217 // indirect
google.golang.org/genproto/googleapis/rpc v0.0.0-20251202230838-ff82c1b0f217 // indirect
golang.org/x/tools v0.38.0 // indirect
google.golang.org/genproto/googleapis/api v0.0.0-20251007200510-49b9836ed3ff // indirect
google.golang.org/genproto/googleapis/rpc v0.0.0-20251007200510-49b9836ed3ff // indirect
gopkg.in/evanphx/json-patch.v4 v4.13.0 // indirect
gopkg.in/inf.v0 v0.9.1 // indirect
gopkg.in/natefinch/lumberjack.v2 v2.2.1 // indirect
Expand Down
Loading