Releases: kubernetes-sigs/node-feature-discovery
Release list
v0.19.0
Highlights
- Immediate node re-labeling after a node rebuild (#2545): nfd-master detects a recreated Node via the surviving NodeFeature's owner-reference / pod-UID annotation and re-labels immediately instead of waiting for the periodic reconcile.
- Configurable NodeFeature owner references:
-owner-refs/core.ownerRefs(pod,ds,node; defaultpod,ds) (#2545). core.noPublishFeaturesto slim published NodeFeature objects (#2530; whitespace-trim fix #2535).- New x86-64 microarchitecture level labels
cpu-cpuid.X86_64_V1..V4(#2490). - nfd-topology-updater: per-pod lookups served from a node-scoped Pod informer, eliminating high-volume per-pod GETs at scale (#2509). Requires an RBAC update â see Action Required.
- nfd-master reconciles only on NodeFeature/NodeFeatureRule/NodeFeatureGroup spec changes (#2532); MatchInRegexp pattern compilation cached (#2531).
Action Required / Behavior Changes
- nfd-topology-updater RBAC (#2509): the ClusterRole needs
list+watchonpods(wasgetonly). Helm and kustomize manifests ship the update, but deployments that bump only the image will crash-loop withpods is forbidden ... cannot list resource "pods"until the new RBAC is applied. - NodeFeatureRule templates (#2507):
env,expandenvandgetHostByNamewere removed from the available template functions (security hardening). Templates using them now fail to parse (function "env" not defined); the rule is skipped and an error is logged. - Helm worker
updateStrategydefault (#2519): nowrollingUpdate: {maxUnavailable: "10%"}(was Kubernetes default1). Note fortype: OnDeleteusers: the chart's defaultrollingUpdateblock is deep-merged into your values; the API server accepts and ignores it (verified on v1.30). Optionally setworker.updateStrategy.rollingUpdate: nullfor a clean spec. resyncPeriod(nfd-master): drives both the informer resync and the (new in this release, #2415) periodic full reconcile that re-applies labels and cleans up drift. Setting it to0disables this safety net entirely.- Node-rebuild re-labeling dependency (#2545): immediate re-label requires
podin-owner-refs(default) or thePOD_UIDenv set on the worker; withds-only/empty owner refs and noPOD_UID, re-labeling falls back to the periodic reconcile interval.-owner-refs=nodeis unaffected.
Fixes
- nfd-master: don't remove node labels when the NodeFeature cache is incomplete; add periodic reconciliation to clean up genuinely absent NodeFeatures (#2415).
- nfd-master: prevent stop() panic and informer leak on init failure (#2534).
- nfd-worker: trim whitespace in comma-separated command-line list values (#2535).
- Helm: render post-delete prune job resources at container level so they actually apply (#2515).
Other
- Container images cross-compile from
$BUILDPLATFORMvia tonistiigi/xx (#2512). - Reduced cognitive complexity refactors in nfd-master controller and nfd-worker config (#2536); nfd-master command-line unit tests (#2469); codecov upload non-fatal in CI verify (#2527); template/custom-api input-validation hardening (#2507).
v0.18.3
What's Changed
This patch release adds support for ppc64le and s390x architectures by providing official NFD container images for them. It also fixes the "test" subcommand of kubectl-nfd plugin.
Full Changelog: v0.18.2...v0.18.3
v0.18.2
v0.18.1
v0.18.0
Changelog
Image compatibility (EXPERIMENTAL)
The image compatibility related features introduced in v0.17 have been improved and enhanced. Major new feature is the nfd export command.
See the documentation for more details
Helm
The Helm chart is now served from the registry.k8s.io OCI registry at registry.k8s.io/nfd/charts/node-feature-discovery. One liner installation with
helm install -n node-feature-discovery nfd oci://registry.k8s.io/nfd/charts/node-feature-discovery --version 0.18.0 --create-namespaceImportant
The legacy Helm repository at https://kubernetes-sigs.github.io/node-feature-discovery/charts is still available, but will be deprecated and stop getting updated in a future release. Users are encouraged to migrate to the OCI registry.
The release contains numerous small improvements and fixes to the Helm chart and its documentation, including:
- Configurable DNS policy (#2025)
- Configurable PodDisruptionBudget (#2148)
- Configurable UpdateStrategy for nfd-worker (#2157)
- Global
global.imagePullSecretsparameter (#2191) - Fix for running with OwnerReferencesPermissionEnforcement validating webhook enabled (#2006)
- Post-delete hook: option to disable (#2076) and configurable image pull secret (#2082)
Deprecations
The deprecated autoDefaultNs configuration parameter of nfd-master was removed.
Toleration for the deprecated node-role.kubernetes.io/master:NoSchedule taint and affinity to the deprecated node-role.kubernetes.io/master label have been removed from the default nfd-master deployment manifests. If you still need these, they need to be explicitly added to the deployment (master.tolerations and master.affinity in the Helm chart).
Important
In v0.18.0 the DisableAutoPrefix feature is still alpha and disabled by default. NFD adds feature.node.kubernetes.io/ prefix to all unprefixed label, annotation and extended resource names. When DisableAutoPrefix is enabled (will be default in a future release), NFD will not add the default prefix automatilly (and add unprefixed names, verbatim). Users are stronglycencouraged to start using fully qualified names (with the prefix) for allccustom labels, annotations and extended resources.
Miscellaneous
Scalability
The release contains improvements and fixes to NFD scalability in larger clusters.
NodeFeatureRules
Label templating
The label templates in NodeFeatureRules now support sprig functions, greatly enhancing their flexibility.
New comparison operators
New comparison operators Ge, Le and GeLe were added (#2085).
Type field in MatchExpressions
New Type field was added to MatchExpressions, allowing to specify the type of the value being compared (#2096). Currently supported types are empty value (the default) and version. Use of version type enables version-aware comparisons.
CPU features
Support for new CPUID flags were added, including AMXCOMPLEX, AMXTRANSPOSE and AMXTF32.
Memory features
NFD now detects availability of hugepages and reports them as memory-hugepages.enabled and hugepages-<page-size>features (#2056).
Network features
Detection of the MTU of network devices was added (#2044).
Metrics and health endpoints
The gRPC health endpoint was replaced by an HTTP healthz endpoint in all NFD daemons. In addition, both the metrics and healthz endpoints are now served on the same port (configurable with --port, default 8080).
v0.17.4
v0.16.9.
v0.17.3
v0.16.8
v0.17.2
What's Changed
This patch release updates dependencies and fixes the worker.extraArgs value in the Helm chart.
Full Changelog: v0.17.1...v0.17.2