Skip to content

fix(deps): update module github.com/victoriametrics/operator/api to v0.74.0 - #612

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github.com-victoriametrics-operator-api-0.x
Open

fix(deps): update module github.com/victoriametrics/operator/api to v0.74.0#612
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github.com-victoriametrics-operator-api-0.x

Conversation

@renovate

@renovate renovate Bot commented May 25, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
github.com/VictoriaMetrics/operator/api v0.66.1v0.74.0 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

VictoriaMetrics/operator (github.com/VictoriaMetrics/operator/api)

v0.74.0

Compare Source

Update note 1: vmoperator: validation webhooks for prometheus-operator CRDs added to the operator in 0.72.0 is now disabled by default. Use VM_PROMCR_VALIDATION_ENABLED env var to enable it explicitly.

  • Dependency: vmoperator: Updated default versions for VM apps to v1.148.0 version

  • Dependency: vmoperator: Updated default versions for VL apps to v1.52.0.

  • Dependency: vmoperator: Updated default versions for VT apps to v0.10.0 version.

  • Dependency: vmoperator: Updated default versions for VMAnomaly to v1.30.0 version

  • FEATURE: vmanomaly: support Temporal Envelope models, online-model history strength and warmup settings, causal and complexity-aware autotune options, and separate reader fetch and processing controls introduced in vmanomaly v1.30.0. See #​2440.

  • FEATURE: vmoperator: add networkPolicy field to all supported CRDs (VMSingle, VMAgent, VMAlert, VMAlertmanager, VMAuth, VLSingle, VLAgent, VTSingle, VMAnomaly, and all cluster sub-components). When set, the operator creates and manages a NetworkPolicy resource that restricts ingress/egress to the component's pods. See #​2977.

  • BUGFIX: vmoperator: grant the operator's ClusterRole permissions on networking.k8s.io/networkpolicies. The networkPolicy feature above was shipped without this grant, so the operator would fail with a Forbidden error creating/updating/deleting NetworkPolicy objects on a real cluster.

  • FEATURE: vmauth: add opt-in spec.waitForConfigReload field. When enabled, the operator confirms that every replica has actually picked up a config change before marking dependent VMUser objects as applied, so their status can be trusted to reflect what's actually running rather than what was merely written out. vmdistributed's internal VMAuth load balancer always waits for this confirmation before rotating a zone in or out of the backend list, regardless of spec.vmAuth.spec.waitForConfigReload, so traffic is never routed to a zone that's still running a stale config.

  • FEATURE: vlagent: add basicAuth field support to remoteWrite entries. See #​2371.

  • FEATURE: vmcluster: support VMCluster extraStorageNodes for vmselect component.

  • FEATURE: vmuser: add defaultVMAccessClaim field to spec.jwt, mapped to vmauth's jwt.default_vm_access_claim. It lets a VMUser accept JWTs that don't carry a vm_access claim, matching vmauth v1.147.0+ behavior. See #​2375.

  • FEATURE: helm-converter: parse the victoria-metrics-auth chart's config value (vmauth's own native config file). Each config.users entry is converted into a standalone VMUser CR, and config.unauthorized_user is converted into the VMAuth CR's spec.unauthorizedUserAccessSpec. The generated VMUser CRs are appended to the same output file as additional YAML documents, and the VMAuth CR's spec.userSelector is set to a dedicated label matching them, so the operator actually loads them (a bare VMAuth CR's default selectors match nothing). See #​2397.

  • FEATURE: vmoperator: introduce VLDistributed CR, which controls multiple region-distributed VictoriaLogs clusters.

  • BUGFIX: vmoperator: support Ignored status for child objects that were not picked, also do not set Failed status if object was applied on at least one parent object. See #​2432.

  • BUGFIX: vmoperator: removed library/ component, while building CR images that do not contain / in repo name. See #​2409.

  • BUGFIX: vmoperator: log only the changed key names and value sizes, instead of the full values, when updating ConfigMap. Previously a single data_diff log line could reach multiple megabytes for large ConfigMaps and break downstream log pipelines with per-line size limits. See #​2426.

  • BUGFIX: vmagent, vmsingle: add missing list verb to config-reloader's secrets RBAC rule. See #​2384.

  • BUGFIX: vmoperator: return an error instead of panicking when a Labels map value is malformed (missing the = separator) during config parsing.

  • BUGFIX: vmalert: when no notifiers are configured, ignore alerting rules from selected VMRules instead of failing reconciliation; recording rules in the same group are kept and still reconciled. See #​2388.

  • BUGFIX: vmalertmanager: default pod securityContext.fsGroup to 65534 when persistent storage is configured and neither useStrictSecurity nor a user securityContext is set. Without it the alertmanager process cannot write notification log and silences to a freshly provisioned volume, so silences are silently lost on pod restart. User-provided securityContext and useStrictSecurity keep their previous behaviour.

  • BUGFIX: vmoperator: allow pinning images by digest via the image.tag field of all operator CRs. When tag is a digest (e.g. sha256:<hex>) it is now joined to the repository with @ instead of :, producing a valid repository@sha256:<digest> reference. Regular tags are unaffected.

  • BUGFIX: helm-converter: fix persistentVolume.storageClassName being dropped during conversion due to a stale storageClass field name. See #​2389.

  • BUGFIX: helm-converter: fix securityContext.runAsNonRoot, runAsUser, runAsGroup, seccompProfile, appArmorProfile, seLinuxOptions, and windowsOptions being silently dropped during conversion; these are now promoted to spec.securityContext.podSecurityContext, matching how the operator applies them to containers. See #​2391.

  • BUGFIX: helm-converter: fix TLS/mTLS settings (tlsCAFile, tlsCertFile, tlsKeyFile, tlsServerName, tlsInsecureSkipVerify) on remoteWrite entries being dropped during conversion for vmagent, vlagent, vlcollector, and vmalert charts. See #​2390.

  • BUGFIX: helm-converter: fix cannot unmarshal object into Go struct field ... headers of type []string error when a chart's default values.yaml ships a headers: {} map (e.g. vmalert's datasource.headers, notifier.headers, remoteWrite.headers); such maps are now normalized to the operator's key:value string-slice format before conversion. See #​2398.

  • BUGFIX: helm-converter: fix extraVolumes/extraVolumeMounts being silently dropped during conversion for vmsingle, vmagent, vmalert, vmanomaly, vmcluster, vlcluster, vtcluster, vtsingle, vlogs, and vmauth charts. See #​2424.

  • BUGFIX: vmagent, vmanomaly: target spec.vpa at the VMAgent/VMAnomaly custom resource itself instead of its underlying Deployment/StatefulSet. VPA rejects a targetRef whose owner chain includes another scalable controller, so a VerticalPodAutoscaler targeting the workload directly was silently non-functional whenever the CR exposed a scale subresource. See #​2415.

  • BUGFIX: vlagent: remove a vestigial scale subresource declaration referencing nonexistent spec/status fields, which unconditionally broke spec.vpa for VLAgent the same way as #​2415.

  • BUGFIX: vmalert, vmagent, vmalertmanager, vmauth, vmsingle: fix child object selection (VMRule, scrape objects, VMAlertmanagerConfig, VMUser) being silently skipped whenever the parent CR's spec contains a field the running operator version doesn't recognize (e.g. after a CRD/operator version mismatch), even though the CR otherwise reconciles successfully with no errors. See #​2444.

v0.73.1

Compare Source

  • BUGFIX: vmrule: removed strategic-merge list semantics from rules as it breaks many rules, where it's a common practice to use a same rule name with different thresholds and severities.

v0.73.0

Compare Source

  • Dependency: vmoperator: Updated default versions for VM apps to v1.147.0 version

  • Dependency: vmoperator: Updated default versions for VL apps to v1.51.0.

  • Dependency: vmoperator: Updated default versions for VT apps to v0.9.4 version.

  • SECURITY: vmagent, vmsingle: remove cluster-wide secrets and configmaps permissions from the operator-managed ClusterRole. Secret access for the config-reloader is now granted via a namespace-scoped Role limited to the single operator-managed config secret. For vmsingle in ingest-only mode (the default), no secret or configmap permissions are granted at all.

  • FEATURE: vmuser, vmauth: add access_log field support. See docs and #​2359.

  • FEATURE: vmuser: add useExtraService boolean field to crd.namespacedName and crd.objects entries in VMUser target references. When set to true, the operator resolves the target URL using the CR's additional service (configured via spec.serviceSpec) instead of the default service. This lets you route VMAuth traffic to a dedicated service with different port mappings or service type without changing the primary service. See related types: CRDRef, NamespacedName. See #​2333.

  • FEATURE: vmoperator: add useLegacyNaming field to all operator CRs. When enabled, managed resources are named using the standalone Helm chart convention (CR name directly for single-component CRs; <name>-<component> for cluster CRs) instead of the default operator prefix convention. Useful when migrating from standalone charts to operator-managed resources without recreating existing resources.

  • FEATURE: vmdistributed: support using VMSingle backends alongside VMCluster backends in separate zones.

  • FEATURE: vmoperator: add VM_OPENSHIFT_COMPATIBILITY env var (OpenshiftCompatibilityMode config field, default auto) to enable OpenShift-specific compatibility features for managed pods. In auto mode the operator detects OpenShift at startup via presence of security.openshift.io/v1 API group. Currently covers automatic mounting of the openshift-service-ca.crt ConfigMap into VMAgent and VMSingle pods at /etc/ssl/certs/openshift-service-ca/service-ca.crt, so that targets signed with the OpenShift service signing CA could be verified without additional TLS config. Supported values: auto, enabled, disabled. See #​2971.

  • BUGFIX: vmcluster: fix CR getting permanently stuck in expanding status after an image update when HPA is enabled on vminsert, vmselect, or vmstorage. The operator was comparing a stale replica count (captured at reconcile start) against live status fields, so the readiness check could never pass once HPA changed the replica count mid-rollout. The same issue affected VMAuth, VLCluster, and VTCluster components with HPA enabled. See #​2324.

  • BUGFIX: config-reloader: fix possible panic on Secret watch events when the informer's local cache fell out of sync and Kubernetes delivered a stale tombstone entry instead of the Secret object. The config-reloader now unwraps tombstones correctly and logs an error for any other unexpected types.

  • BUGFIX: vmanomaly: add missing scatter_infer_jobs field to the periodic scheduler config struct. See #​2328.

  • BUGFIX: vmoperator: switch default app probes to tcpSocket startupProbe when TLS is enabled on the managed HTTP endpoint. This avoids broken kubelet httpGet checks against TLS and mTLS-protected workloads. See #​1824.

  • BUGFIX: vmagent, vmsingle: create a Role and RoleBinding in each namespace listed in WATCH_NAMESPACES so that vmagent/vmsingle can perform service discovery in all watched namespaces, not only its own. Previously, in namespaced mode, vmagent/vmsingle could only scrape targets from its own namespace due to missing RBAC in other watched namespaces.

  • BUGFIX: vmagent: fix missing credential secret and config-reloader setup in ingestOnlyMode when remote write entries carry authentication secrets (basicAuth.password, bearerTokenSecret, or oauth2.clientSecret). Previously the operator-managed secret containing the credential files was never created in ingest-only mode, causing vmagent to start with dangling file references. The secret is now reconciled and the config-reloader is configured to watch it for credential rotation.

v0.72.0

Compare Source

Update note 1: vmalert: rule ConfigMaps now store gzip-compressed content in binaryData and an init container decompresses them before VMAlert starts. Existing VMAlert pods will be rolled out once during this upgrade.

  • FEATURE: vmoperator: add validating webhooks for Prometheus Operator CRDs (ServiceMonitor, PodMonitor, PrometheusRule, Probe, ScrapeConfig, AlertmanagerConfig). Each object is converted to its VM equivalent and validated when webhooks are enabled. See #​2270.

  • FEATURE: vmscrapeconfig: add support for consulAgentSDConfigs, dockerSDConfigs, dockerSwarmSDConfigs, marathonSDConfigs, and yandexCloudSDConfigs service discovery types, bringing VMScrapeConfig to full parity with VictoriaMetrics sd_configs. See #​2265.

  • FEATURE: vmalert: rule ConfigMaps now store gzip-compressed rule files in binaryData, allowing larger rule sets within Kubernetes object size limits. An init container decompresses the rules before VMAlert starts.

  • FEATURE: vmscrapeconfig: add support for consulAgentSDConfigs, dockerSDConfigs, dockerSwarmSDConfigs, marathonSDConfigs, and yandexCloudSDConfigs service discovery types, bringing VMScrapeConfig to full parity with VictoriaMetrics sd_configs. See #​2265.

  • FEATURE: vmoperator: add victoriametrics_app=true label to all metrics scraped by the operator. See #​2261.

  • BUGFIX: vmoperator: skip reconciliation only for CRs with genuine spec parse errors; CRs whose ParsingSpecError is caused solely by unknown fields (e.g. after an operator downgrade) are now reconciled normally instead of being silently skipped.

  • BUGFIX: vmoperator: fix potential deadlock in operator_object_status metrics collector when the number of tracked objects exceeds 250. The Collect method previously held a mutex while sending to the prometheus channel, which could deadlock if the channel was full and another goroutine was waiting on the same mutex. See #​2239.

  • BUGFIX: config-reloader: fix missed reload for watched files whose names contain .. (e.g. rules..yaml). Previously any path containing .. was silently skipped; now only Kubernetes synthetic entries whose basename starts with .. (e.g. ..data) are ignored. See #​2253.

  • BUGFIX: vmoperator: fix potential deadlock in operator_object_status metrics collector when the number of tracked objects exceeds 250. The Collect method previously held a mutex while sending to the prometheus channel, which could deadlock if the channel was full and another goroutine was waiting on the same mutex. See #​2239.

v0.71.0

Compare Source

Update note 1: the new default preStop hook causes a rolling update of all applicable pods on operator upgrade (on Kubernetes >= 1.29). To avoid this, set VM_ENABLE_DEFAULT_PRESTOP_HOOK=false on the operator before upgrading. Once the upgrade is complete, you can re-enable it by removing the override (or setting it to true) to roll out the hook at a time of your choosing. Alternatively, disable the hook per resource by setting spec.preStopSleepSeconds: 0.

  • Dependency: vmoperator: Updated default versions for VM apps to v1.145.0 version

  • FEATURE: vmoperator: added VM_COMMON_LABELS and VM_COMMON_ANNOTATIONS environment variables to apply common labels/annotations to all Kubernetes resources managed by the operator. These cannot override labels/annotations already set by the operator or via spec.managedMetadata. This also ensures HTTPRoutes and PVCs include ManagedMetadata labels and annotations

  • FEATURE: vmoperator: support enableServiceLinks property in all CRs. See #​2194.

  • FEATURE: vmalertmanagerconfig: add url_file and alert_source_token_file fields to IncidentioConfig, as file-based alternatives to url and alert_source_token. See #​2222.

  • FEATURE: vmoperator: add status metrics for objects managed by each controller. See #​2238.

  • FEATURE: vmsingle: added spec.downsampling for structured downsampling configuration and spec.retentionFilters for structured retention filters configuration. Both require an enterprise license.

  • FEATURE: vmcluster: added spec.downsampling for structured downsampling configuration (applied to both vmselect and vmstorage) and spec.vmstorage.retentionFilters for structured retention filters configuration. Both require an enterprise license.

  • FEATURE: vmoperator: add default preStop lifecycle hook (15s sleep) to applicable component pods to prevent traffic loss during pod termination. Requires Kubernetes >= 1.29. Storage components (VMStorage, VLStorage, VTStorage) are excluded since their clients handle retries. The sleep duration is configurable via spec.preStopSleepSeconds on any CR; set to 0 to disable. See #​1834.

  • FEATURE: vmanomaly: add missing configuration parameters for vmanomaly config parity: spec.reader.offset and per-query offset, spec.writer.connectionRetryAttempts, spec.server.useReaderConnectionSettings, settings.logger_levels, and the exact/infer_every parameters of the backtesting scheduler. Previously these keys were rejected by strict config parsing.

  • FEATURE: vmcluster: add spec.discovery field with enabled, interval and filter properties to configure automatic vmstorage node discovery for vminsert and vmselect. The field can be set globally or overridden per component via spec.vminsert.discovery and spec.vmselect.discovery. This is an enterprise feature and requires a valid license key. See automatic vmstorage discovery.

  • BUGFIX: vmoperator: update status currentRevision and currentReplicas for StatefulSet with OnDelete update strategy. See #​1242.

  • BUGFIX: config-reloader: fix configreloader_last_reload_success_timestamp_seconds metric to report time in seconds instead of milliseconds.

  • BUGFIX: vmoperator: enable strict CR spec unmarshalling when creating objects. See #​2882.

  • BUGFIX: vmoperator: ignore NotFound errors, that may occur during attempt to update status on a missing resource.

  • BUGFIX: vmagent, vmanomaly: fix VPA scale subresource lookup failure when spec.shardCount is unset by always reporting at least 1 in status.shards. See #​2229.

  • BUGFIX: vmagent: fix HPA targeting the underlying Deployment/StatefulSet (pod replicas) instead of the VMAgent CR scale subresource (spec.shardCount); HPA now correctly scales the number of shards. See #​2229.

  • BUGFIX: vmanomaly: emit the OnlineQuantileModel smoothing parameter under its correct key global_smoothing instead of the unrecognized global_smooth, which vmanomaly silently ignored.

  • BUGFIX: vmanomaly: pass the configured TLS CA bundle to the reader, writer and monitoring clients. Previously the CA was mounted as a volume but dropped during config generation, so a tlsConfig with only a CA produced no verify_tls reference to it; insecureSkipVerify is now also propagated correctly.

  • BUGFIX: vmanomaly: serialize the tz timezone of spec.reader, of each query, and of the periodic scheduler as a string. It was serialized to {} and could not be parsed from a string, so any configuration that set tz failed to reconcile.

  • BUGFIX: vmanomaly: fix the AutoTunedModel trials parameter spelling n_trials, previously it was rendered as n_trails which was silently ignored by vmanomaly.

  • BUGFIX: vmanomaly: preserve an explicit 0.0 for the anomaly_score_outside_data_range parameter (both settings and model level), which was dropped by the underlying float field and silently reverted to the vmanomaly default.

  • BUGFIX: vmanomaly: validate online models' decay against the (0, 1] range while still allowing it to be omitted.

  • BUGFIX: vmanomaly: accept a float value (for example 0.01) for the isolation forest contamination parameter in addition to the string auto.

  • BUGFIX: vmanomaly: omit the OnlineQuantileModel min_subseason key when it is unset instead of emitting an empty string.

  • BUGFIX: vmanomaly: remove the artificial upper bound on spec.server.maxConcurrentTasks; vmanomaly accepts any positive integer.

v0.70.1

Compare Source

  • FEATURE: vmauth: support HPA for requests load balancer.

  • BUGFIX: vmagent: skip replica count update when VMAgent is in stateful mode and HPA is enabled. See #​2190.

  • BUGFIX: vmalertmanagerconfig: Remove prefix from empty subroute receiver. See #​2185.

  • BUGFIX: vmoperator: updated OLM configuration to fix OpenShift catalog publishing. See #​2195.

v0.70.0

Compare Source

v0.69.0

Compare Source

  • Dependency: vmoperator: Updated default versions for VM apps to v1.140.0 version

  • Dependency: vmoperator: Updated default versions for VM apps to v1.139.0 version
    Update note 1: deprecated env variables for Prometheus CRs conversion VM_ENABLEDPROMETHEUSCONVERTER_PODMONITOR, VM_ENABLEDPROMETHEUSCONVERTER_SERVICESCRAPE, VM_ENABLEDPROMETHEUSCONVERTER_PROMETHEUSRULE, VM_ENABLEDPROMETHEUSCONVERTER_PROBE, VM_ENABLEDPROMETHEUSCONVERTER_SCRAPECONFIG. Use -controller.disableReconcileFor command-line flag with comma-separated list of controller names, that should be disabled.
    Update note 2: removed operator_prometheus_converter_watch_events_total metric since migration of Prometheus object watchers to controllers made this counter obsolete.
    Update note 3: made controller.prometheusCRD.resyncPeriod command line flag noop, which was relevant to Prometheus object watchers.
    Update note 4: -eula flag is not set by default anymore for VMBackup and VMRestore. To avoid VMCluster/VMSingle rollouts set spec.vmstorage.vmBackup.acceptEula: true for VMCluster and spec.vmBackup.acceptEula: true" for VMSingle and replace it with spec.license during VMSingle/VMCluster upgrade.
    Update note 5: new flag was introduced, so VMAnomaly pods will be recreated. VMAnomaly version should be at least 1.25.
    Update note 6: fixed port name collision in VMSingle and VMCluster, when VMBackup is enabled. To avoid VMSingle/VMCluster pods recreation set VM_USE_OLD_BACKUP_RESTORE_PORT_NAMES environment variable to true.
    Update note 7: the default VMDistributed unauthorizedUserAccessSpec was removed to allow users to decide whether access should be anonymous or authorized. Please check documentation with examples for unauthorized and authorized access and update your CRs accordingly.

  • Dependency: vmoperator: Updated default versions for VM apps to v1.139.0 version

  • Dependency: vmoperator: Updated default versions for VL apps to v1.50.0.

  • FEATURE: helm-converter: new CLI tool that helps with migration from Helm charts to their corresponding Operator Custom Resources (CRs).

  • FEATURE: vmsingle: VMSingle reuses vmagent implementation to allow scraping and relabelling. See #​1694

  • FEATURE: vmoperator: perform statefulset pods deletion instead of eviction when maxUnavailable set to 100%, which is important for minimum downtime strategy. See #​1706.

  • FEATURE: vmuser: support referencing multiple targets of the same kind at targetRefs[*].crd.objects.

  • FEATURE: vmoperator: prettify reconcile diff in logs, now diff objects show only changed JSON fields.

  • FEATURE: VLCluster, VLSingle, VLAgent, VTCluster, VTSingle, VMCluster, VMAgent, VMAnomaly, VMAlert, VMAlertmanager, VMAuth: add spec.componentVersion as an alternative to spec.clusterVersion. This field also available in all objects deploying pods. See this #​1949 issue for details.

  • FEATURE: vmanomaly: add support for settings.retention configuration (ttl and check_interval) in configRawYaml and configSecret. See these docs for details.

  • FEATURE: vmuser: support JWT-based auth.

  • FEATURE: vmagent: support HPA in VMAgent CR and in VMAgent, which is a part of VMDistributed. See #​1961.

  • FEATURE: vmagent: VMAgent CRs running in statefulSet mode, including VMAgent components in VMDistributed, now support configuring rolling update strategy behavior. See #​1987.

  • FEATURE: vmagent: VMAgent CRs running in DaemonSet mode now support configuring rolling update strategy behavior.

  • FEATURE: vmoperator: Dry-run mode. See #​1832.

  • FEATURE: vmanomaly: introduce VMAnomalyConfig CRD to enable dynamic configuration and hot-reload support starting from VMAnomaly version 1.25.0.

  • FEATURE: vmalertmanager: introduce arbitrary fs access feature for VMAlertmanager. See #​899

  • FEATURE: vmalertmanagerconfig: add update_message field to SlackConfig. This allows alertmanager to edit the original Slack message in-place when alert status changes instead of sending a new one. Requires alertmanager v0.32.0+. See #​2064.

  • BUGFIX: vmbackupmanager: remove deprecated -eula flag from vmbackupmanager and vmrestore container args. See #​1319.

  • BUGFIX: vmoperator: VMPodScrape for VLAgent and VMAgent now uses the correct port; previously it used the wrong port and could cause scrape failures. See #​1887.

  • BUGFIX: vmdistributed: updated VMAuth config consolidating all VMSelects into a single read and all VMClusters into a single write backend

  • BUGFIX: vmdistributed: fix PVC being owned by StatefulSet and top-level object simultaneously. See #​1845.

  • BUGFIX: vmoperator: remove unneeded finalizer from core K8s resources. See #​835.

  • BUGFIX: vmdistributed: remove finalizers from VMServiceScrape and VMPodScrape objects, and keep finalizers on VMAgent, VMCluster, and VMAuth when DeletionTimestamp is not empty.

  • BUGFIX: vmsingle and vmagent: previously, ingest-only mode could still mount scrape configuration secrets when relabeling or stream aggregation was configured, which caused unexpected secret mounts and RBAC-related failures; now these secrets are not mounted in ingest-only mode, so deployments start with the expected minimal permissions and avoid related runtime errors. See #​1828.

  • BUGFIX: vmoperator: recreate STS if immutable fields changed.

  • BUGFIX: vmoperator: wait for STS deletion in case of recreation without throwing an error.

  • BUGFIX: vmdistributed: ignore VMAuth update/delete operations if controller is disabled.

  • BUGFIX: vmalertmanager: fixed ignored tracing config, when no alertmanagerconfig CRs collected. See #​1983.

  • BUGFIX: vmagent: apply scrape class relabellings before job ones. See #​1997.

  • BUGFIX: vmanomaly and vmagent: render %SHARD_NUM% placeholder when shard count is greater than 0. See #​2001.

  • BUGFIX: vlcluster and vtcluster: do not ignore ExtraStorageNodes for select, when default storage is disabled. See #​1910.

  • BUGFIX: vmdistributed: use default stub, when no VMAuth backends are available

  • BUGFIX: vmagent: use volume from spec.volumes as persistent queue volume if its name is persistent-queue-data, previously emptyDir was mounted. See #​1677.

  • BUGFIX: vmcluster: use volume from spec.vmstorage.volumes and spec.vmselect.volumes as data and cache volumes if its name is vmstorage-db and vmselect-cachedir respectively. See #​784.

  • BUGFIX: vmcluster and vmsingle: renamed vmbackup and vmrestore port names, before they had identical to storage/single port names, which is not allowed.

  • BUGFIX: vmsingle: updated scraping implementation to match vmagent functionality.

v0.68.7

Compare Source

Dependency: vmoperator: Updated default versions for VM apps to v1.147.0 version

Dependency: vmoperator: Updated default versions for VT apps to v0.9.4 version.

Dependency: vmoperator: Updated default versions for VMAnomaly to v1.28.7 version

SECURITY: vmagent, vmsingle: remove cluster-wide secrets and configmaps permissions from the operator-managed ClusterRole. Secret access for the config-reloader is now granted via a namespace-scoped Role limited to the single operator-managed config secret. For vmsingle in ingest-only mode (the default), no secret or configmap permissions are granted at all.

BUGFIX: vmanomaly: add missing scatter_infer_jobs field to the periodic scheduler config struct. See #​2328.

BUGFIX: vmanomaly: preserve insertion order of keys in ProphetModel seasonalities, tz_seasonalities, compression, and args fields; previously the operator re-emitted them with keys sorted alphabetically, which broke round-trips for configs that specified keys in a non-alphabetical order. Also renamed the singular seasonality/tz_seasonality YAML keys (deprecated) to the plural seasonalities/tz_seasonalities to match the vmanomaly configuration format. See #​2356.

BUGFIX: vmagent, vmsingle: create a Role and RoleBinding in each namespace listed in WATCH_NAMESPACES so that vmagent/vmsingle can perform service discovery in all watched namespaces, not only its own. Previously, in namespaced mode, vmagent/vmsingle could only scrape targets from its own namespace due to missing RBAC in other watched namespaces.

BUGFIX: vmagent: fix missing credential secret and config-reloader setup in ingestOnlyMode when remote write entries carry authentication secrets (basicAuth.password, bearerTokenSecret, or oauth2.clientSecret). Previously the operator-managed secret containing the credential files was never created in ingest-only mode, causing vmagent to start with dangling file references. The secret is now reconciled and the config-reloader is configured to watch it for credential rotation.

v0.68.6

Compare Source

  • Dependency: vmoperator: Updated default versions for VM apps to v1.146.0 version

  • Dependency: vmoperator: Updated default versions for VL apps to v1.51.0.

  • Dependency: vmoperator: Updated default versions for VT apps to v0.9.3 version.

  • FEATURE: vmoperator: add victoriametrics_app=true label to all metrics scraped by the operator. See #​2261.

  • BUGFIX: config-reloader: fix possible panic on Secret watch events when the informer's local cache fell out of sync and Kubernetes delivered a stale tombstone entry instead of the Secret object. The config-reloader now unwraps tombstones correctly and logs an error for any other unexpected types.

  • BUGFIX: vmoperator: update status currentRevision and currentReplicas for StatefulSet with OnDelete update strategy. See #​1242.

  • BUGFIX: vmoperator: retry reconcile errors, that may lead to expanding state, before resource could hang in expanding state.

  • BUGFIX: vmcluster, vlcluster and vtcluster: when storage HPA was enabled, generated -storageNode flags could become incorrect after scaling, which could break expected routing to storage nodes; now the operator derives storage node count from the current StatefulSet state so generated flags stay correct during HPA-driven scaling. See #​2117.

  • BUGFIX: vmoperator: update status currentRevision and currentReplicas for StatefulSet with OnDelete update strategy. See #​1242.

  • BUGFIX: config-reloader: fix configreloader_last_reload_success_timestamp_seconds metric to report time in seconds instead of milliseconds.

  • BUGFIX: vmoperator: ignore NotFound errors, that may occur during attempt to update status on a missing resource.

  • BUGFIX: vmanomaly: pass the configured TLS CA bundle to the reader, writer and monitoring clients. Previously the CA was mounted as a volume but dropped during config generation, so a tlsConfig with only a CA produced no verify_tls reference to it; insecureSkipVerify is now also propagated correctly.

  • BUGFIX: config-reloader: fix missed reload for watched files whose names contain .. (e.g. rules..yaml). Previously any path containing .. was silently skipped; now only Kubernetes synthetic entries whose basename starts with .. (e.g. ..data) are ignored. See #​2253.

v0.68.5

Compare Source

Update note: -eula flag is not set by default anymore for VMBackup and VMRestore. To avoid VMCluster/VMSingle rollouts set `spe

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate

renovate Bot commented May 25, 2026

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 76 additional dependencies were updated
  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.26.1 -> 1.26.5
github.com/prometheus/prometheus v0.303.1 -> v0.312.0
k8s.io/api v0.35.2 -> v0.36.3
k8s.io/apiextensions-apiserver v0.35.2 -> v0.36.3
sigs.k8s.io/gateway-api v1.5.1 -> v1.6.1
github.com/go-openapi/swag/cmdutils v0.24.0 -> v0.26.1
github.com/go-openapi/swag/conv v0.25.5 -> v0.26.1
github.com/go-openapi/swag/fileutils v0.25.5 -> v0.26.1
github.com/go-openapi/swag/jsonname v0.25.5 -> v0.26.1
github.com/go-openapi/swag/jsonutils v0.25.5 -> v0.26.1
github.com/go-openapi/swag/loading v0.25.5 -> v0.26.1
github.com/go-openapi/swag/mangling v0.25.5 -> v0.26.1
github.com/go-openapi/swag/netutils v0.24.0 -> v0.26.1
github.com/go-openapi/swag/stringutils v0.25.5 -> v0.26.1
github.com/go-openapi/swag/typeutils v0.25.5 -> v0.26.1
cel.dev/expr v0.24.0 -> v0.25.2
github.com/VictoriaMetrics/VictoriaLogs v1.36.2-0.20251008164716-21c0fb3de84d -> v1.51.1-0.20260624061259-dc94972a8708
github.com/VictoriaMetrics/VictoriaMetrics v1.131.0 -> v1.148.0
github.com/VictoriaMetrics/easyproto v0.1.4 -> v1.2.0
github.com/VictoriaMetrics/metrics v1.40.2 -> v1.44.0
github.com/VictoriaMetrics/metricsql v0.84.8 -> v0.87.3
github.com/aws/aws-sdk-go v1.55.6 -> v1.55.8
github.com/bmatcuk/doublestar/v4 v4.9.1 -> v4.10.0
github.com/coreos/go-systemd/v22 v22.5.0 -> v22.7.0
github.com/edsrzf/mmap-go v1.2.0 -> v1.2.1-0.20241212181136-fad1cd13edbd
github.com/felixge/httpsnoop v1.0.4 -> v1.1.0
github.com/fsnotify/fsnotify v1.9.0 -> v1.10.1
github.com/fxamacker/cbor/v2 v2.9.0 -> v2.9.2
github.com/go-jose/go-jose/v4 v4.1.3 -> v4.1.4
github.com/go-openapi/analysis v0.24.3 -> v0.25.0
github.com/go-openapi/jsonpointer v0.22.5 -> v0.23.2
github.com/go-openapi/jsonreference v0.21.5 -> v0.21.6
github.com/go-openapi/runtime v0.29.3 -> v0.29.4
github.com/go-openapi/strfmt v0.26.0 -> v0.26.2
github.com/go-openapi/swag v0.24.1 -> v0.26.1
github.com/google/gnostic-models v0.7.0 -> v0.7.1
github.com/grpc-ecosystem/grpc-gateway/v2 v2.27.3 -> v2.29.0
github.com/klauspost/compress v1.18.2 -> v1.18.6
github.com/prometheus/alertmanager v0.28.0 -> v0.33.1
github.com/prometheus/common v0.67.5 -> v0.68.1
github.com/prometheus/procfs v0.17.0 -> v0.20.1
github.com/spf13/cobra v1.10.0 -> v1.10.2
github.com/valyala/fastjson v1.6.4 -> v1.6.10
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.63.0 -> v0.69.0
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.64.0 -> v0.69.0
go.opentelemetry.io/otel v1.41.0 -> v1.44.0
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.39.0 -> v1.44.0
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.36.0 -> v1.44.0
go.opentelemetry.io/otel/metric v1.41.0 -> v1.44.0
go.opentelemetry.io/otel/sdk v1.41.0 -> v1.44.0
go.opentelemetry.io/otel/trace v1.41.0 -> v1.44.0
go.opentelemetry.io/proto/otlp v1.9.0 -> v1.10.0
go.uber.org/zap v1.27.1 -> v1.28.0
go.yaml.in/yaml/v2 v2.4.3 -> v2.4.4
golang.org/x/crypto v0.48.0 -> v0.54.0
golang.org/x/exp v0.0.0-20251002181428-27f1f14c8bb9 -> v0.0.0-20260611194520-c48552f49976
golang.org/x/mod v0.32.0 -> v0.37.0
golang.org/x/net v0.51.0 -> v0.57.0
golang.org/x/oauth2 v0.34.0 -> v0.36.0
golang.org/x/sync v0.19.0 -> v0.22.0
golang.org/x/sys v0.41.0 -> v0.47.0
golang.org/x/term v0.40.0 -> v0.45.0
golang.org/x/text v0.34.0 -> v0.40.0
golang.org/x/time v0.14.0 -> v0.15.0
golang.org/x/tools v0.41.0 -> v0.47.0
google.golang.org/genproto/googleapis/api v0.0.0-20251202230838-ff82c1b0f217 -> v0.0.0-20260615183401-62b3387ff324
google.golang.org/genproto/googleapis/rpc v0.0.0-20251202230838-ff82c1b0f217 -> v0.0.0-20260727163830-6c54dddc4772
google.golang.org/grpc v1.78.0 -> v1.82.1
google.golang.org/protobuf v1.36.11 -> v1.36.12-0.20260120151049-f2248ac996af
k8s.io/apimachinery v0.35.2 -> v0.36.3
k8s.io/apiserver v0.35.0 -> v0.36.0
k8s.io/component-base v0.35.0 -> v0.36.3
k8s.io/metrics v0.34.0 -> v0.36.3
k8s.io/utils v0.0.0-20260108192941-914a6e750570 -> v0.0.0-20260707023825-cf1189d6abe3
sigs.k8s.io/apiserver-network-proxy/konnectivity-client v0.31.2 -> v0.34.0
sigs.k8s.io/controller-runtime v0.23.3 -> v0.24.1
sigs.k8s.io/structured-merge-diff/v6 v6.3.2 -> v6.4.2

@renovate
renovate Bot force-pushed the renovate/github.com-victoriametrics-operator-api-0.x branch from 4864254 to e671595 Compare June 12, 2026 18:36
@renovate renovate Bot changed the title fix(deps): update module github.com/victoriametrics/operator/api to v0.70.1 fix(deps): update module github.com/victoriametrics/operator/api to v0.71.0 Jun 12, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-victoriametrics-operator-api-0.x branch from e671595 to 9ca6b76 Compare June 15, 2026 22:02
@renovate renovate Bot changed the title fix(deps): update module github.com/victoriametrics/operator/api to v0.71.0 fix(deps): update module github.com/victoriametrics/operator/api to v0.72.0 Jun 15, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-victoriametrics-operator-api-0.x branch from 9ca6b76 to bee56a2 Compare July 7, 2026 18:39
@renovate renovate Bot changed the title fix(deps): update module github.com/victoriametrics/operator/api to v0.72.0 fix(deps): update module github.com/victoriametrics/operator/api to v0.73.0 Jul 7, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-victoriametrics-operator-api-0.x branch from bee56a2 to ea61883 Compare July 8, 2026 10:55
@renovate renovate Bot changed the title fix(deps): update module github.com/victoriametrics/operator/api to v0.73.0 fix(deps): update module github.com/victoriametrics/operator/api to v0.73.1 Jul 8, 2026
@renovate
renovate Bot force-pushed the renovate/github.com-victoriametrics-operator-api-0.x branch from ea61883 to 8cec388 Compare July 30, 2026 17:33
@renovate renovate Bot changed the title fix(deps): update module github.com/victoriametrics/operator/api to v0.73.1 fix(deps): update module github.com/victoriametrics/operator/api to v0.74.0 Jul 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants