$ the-wire · showcase
GCP provider learns to skip firewall rules, metis gets non-reusable CIDRs
By RepoJournal · Filed · About Kubernetes · Composed from the cited sources · methodology
A light day across the Kubernetes publishing repos, with the substantive work landing in cloud-provider-gcp: a config flag that lets clusters run without firewall permissions, and store-level support for CIDR blocks that can't be handed back.
Update the GCP provider to allow users to skip firewall actions kubernetes/cloud-provider-gcp
A new ManageFirewallRules boolean in the providers/gce config, threaded through the cluster scripts, lets an operator turn off creation, deletion, and updates of firewall rules when set to false. That matters for service accounts that lack the permissions to touch firewall rules; the rules then have to be pre-created and managed by someone who does have them.
feat,metis: support non-reusable cidr blocks kubernetes/cloud-provider-gcp
metis gains a reusable BOOLEAN NOT NULL DEFAULT TRUE column on the cidr_blocks table, a matching AddCIDRWithReusable(ctx, network, cidr, reusable) store method, and updated ReleaseIPByOwner logic to honor the flag. Non-reusable blocks are now expressible at the schema and store layer rather than being implicitly recyclable.
dynamicpodip: support candidate pod secondary ranges for Adaptive Cluster IPAM kubernetes/cloud-provider-gcp
The dynamic pod IP controller in the Cloud Controller Manager now supports candidate pod secondary ranges for Adaptive Cluster IPAM, where Pod IP CIDRs come from a cluster-wide pool of primary and additional secondary ranges instead of a single fixed secondary range. The controller provisions those ranges as alias IP ranges on GCE instances per NodeNetworkConfig.
Merge pull request #142246 from darshansreenivas/dtumkur-pr-network-tag-controller kubernetes/api
IngressClass spec.controller picks up maxBytes declarative validation, moving another constraint out of handwritten validation and into the declarative machinery.
recover is_generated kubernetes/repo-infra
A quick correction in repo-infra: the is_generated function, accidentally deleted in an earlier change, is restored, and the two k8s dependency-group bumps in cloud-provider-gcp plus the Quantity AsInt64 tests and consistency-store move to client-go utils round out the day.