Skip to content

Conversation

@linus-elastisys
Copy link
Contributor

@linus-elastisys linus-elastisys commented Nov 18, 2025

Warning

This is a public repository, ensure not to disclose:

  • personal data beyond what is necessary for interacting with this pull request, nor
  • business confidential information, such as customer names.

What kind of PR is this?

Required: Mark one of the following that is applicable:

  • kind/feature
  • kind/improvement
  • kind/deprecation
  • kind/documentation
  • kind/clean-up
  • kind/bug
  • kind/other

Optional: Mark one or more of the following that are applicable:

Important

Breaking changes should be marked kind/admin-change or kind/dev-change depending on type
Critical security fixes should be marked with kind/security

  • kind/admin-change
  • kind/dev-change
  • kind/security
  • [kind/adr](set-me)

Platform Administrator notice

  • The default Kubernetes version has been bumped to 1.33.5.
  • In Kubespray playbooks: the master tag has been removed and is replaced by control-plane.

What does this PR do / why do we need this PR?

Updates Kubespray to upstream version 2.29.

Information to reviewers

Tested an upgrade from 2.28 -> 2.29 on a Safespring cluster, and things seems to work well. No errors during the upgrade, and apps are running fine both before and after the upgrade.

As far as I can tell, there's no relevant Kubernetes 1.33 changes, or Kubespray 2.29 changes that needs to be included as admin-change or dev-change.

Checklist

  • Proper commit message prefix on all commits
  • Change checks:
    • The change is transparent
    • The change is disruptive
    • The change requires no migration steps
    • The change requires migration steps
  • Documentation checks:
  • Metrics checks:
    • The metrics are still exposed and present in Grafana after the change
    • The metrics names didn't change (Grafana dashboards and Prometheus alerts required no updates)
    • The metrics names did change (Grafana dashboards and Prometheus alerts required an update)
  • Logs checks:
    • The logs do not show any errors after the change
  • PodSecurityPolicy checks:
    • Any changed Pod is covered by Kubernetes Pod Security Standards
    • Any changed Pod is covered by Gatekeeper Pod Security Policies
    • The change does not cause any Pods to be blocked by Pod Security Standards or Policies
  • NetworkPolicy checks:
    • Any changed Pod is covered by Network Policies
    • The change does not cause any dropped packets in the NetworkPolicy Dashboard
  • Audit checks:
    • The change does not cause any unnecessary Kubernetes audit events
    • The change requires changes to Kubernetes audit policy
  • Falco checks:
    • The change does not cause any alerts to be generated by Falco
  • Bug checks:
    • The bug fix is covered by regression tests

@linus-elastisys linus-elastisys requested a review from a team as a code owner November 18, 2025 08:29
@linus-elastisys
Copy link
Contributor Author

linus-elastisys commented Nov 19, 2025

Just tried an upgrade from 2.28 -> 2.29 on a Safespring cluster, and things seems to work well. No errors during the upgrade, and apps are running fine both before and after the upgrade.

As far as I can tell, there's no relevant Kubernetes 1.33 changes, or Kubespray 2.29 changes that needs to be included as admin-change or dev-change.

@Xartos
Copy link
Contributor

Xartos commented Nov 21, 2025

Could you add to the PR the admin release notes that the default kubernetes version is bumped and that the master tag is now removed. I think we might have some docs that assumes that tag exists

@linus-elastisys
Copy link
Contributor Author

Could you add to the PR the admin release notes that the default kubernetes version is bumped and that the master tag is now removed. I think we might have some docs that assumes that tag exists

Thanks, fixed now.

@linus-elastisys linus-elastisys merged commit 1f84a0c into main Nov 24, 2025
7 checks passed
@linus-elastisys linus-elastisys deleted the linus/kubespray-2.29.0-ck8s branch November 24, 2025 08:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants