diff --git a/CHANGELOG.md b/CHANGELOG.md index c1f94aad..ad39142c 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -3,6 +3,7 @@ ## master / unreleased * [FEATURE] Add trafficDistribution attribute to services #674 +* [ENHANCEMENT] Update helm values and documentation for rollout operator #673 ## 3.4.0 / 2026-09-21 diff --git a/Chart.lock b/Chart.lock index 2d91d560..fe23d60e 100644 --- a/Chart.lock +++ b/Chart.lock @@ -17,5 +17,5 @@ dependencies: - name: rollout-operator repository: https://grafana.github.io/helm-charts version: 0.51.1 -digest: sha256:013d61b48a00c78a79287910088abb6b19d4319d8068e369e2a38dd8cc76f9e4 -generated: "2026-09-18T13:17:51.095820924+02:00" +digest: sha256:793039fc6b475263e63f10837328020655816d0b802e7e525098ab9e337d3caa +generated: "2026-09-28T09:38:44.702766819+02:00" diff --git a/Chart.yaml b/Chart.yaml index 48cb9bbe..24d1d7ff 100644 --- a/Chart.yaml +++ b/Chart.yaml @@ -42,6 +42,7 @@ dependencies: repository: https://charts.bitnami.com/bitnami condition: memcached-parquet-labels.enabled - name: rollout-operator + alias: rollout_operator version: 0.51.1 repository: https://grafana.github.io/helm-charts condition: rollout_operator.enabled diff --git a/README.md b/README.md index a68cb5e8..98152df7 100644 --- a/README.md +++ b/README.md @@ -91,7 +91,7 @@ Kubernetes: `^1.19.0-0` | https://charts.bitnami.com/bitnami | memcached-blocks(memcached) | 6.14.0 | | https://charts.bitnami.com/bitnami | memcached-blocks-metadata(memcached) | 6.14.0 | | https://charts.bitnami.com/bitnami | memcached-parquet-labels(memcached) | 6.14.0 | -| https://grafana.github.io/helm-charts | rollout-operator | 0.51.1 | +| https://grafana.github.io/helm-charts | rollout_operator(rollout-operator) | 0.51.1 | ## Values @@ -811,8 +811,17 @@ Kubernetes: `^1.19.0-0` | query_scheduler.​terminationGracePeriodSeconds | int | `180` | | | query_scheduler.​tolerations | list | `[]` | | | query_scheduler.​topologySpreadConstraints | list | `[]` | | -| rollout_operator.​crds.​enabled | bool | `false` | | | rollout_operator.​enabled | bool | `false` | | +| rollout_operator.​podSecurityContext.​fsGroup | int | `10001` | | +| rollout_operator.​podSecurityContext.​runAsGroup | int | `10001` | | +| rollout_operator.​podSecurityContext.​runAsNonRoot | bool | `true` | | +| rollout_operator.​podSecurityContext.​runAsUser | int | `10001` | | +| rollout_operator.​podSecurityContext.​seccompProfile.​type | string | `"RuntimeDefault"` | | +| rollout_operator.​securityContext.​allowPrivilegeEscalation | bool | `false` | | +| rollout_operator.​securityContext.​capabilities.​drop[0] | string | `"ALL"` | | +| rollout_operator.​securityContext.​readOnlyRootFilesystem | bool | `true` | | +| rollout_operator.​securityContext.​runAsNonRoot | bool | `true` | | +| rollout_operator.​securityContext.​seccompProfile.​type | string | `"RuntimeDefault"` | | | rollout_operator.​webhooks.​enabled | bool | `false` | | | ruler.​affinity | object | `{}` | | | ruler.​annotations | object | `{}` | | diff --git a/docs/guides/migrate_to_zone_aware_replication.markdown b/docs/guides/migrate_to_zone_aware_replication.markdown index 766e394b..cdb95416 100644 --- a/docs/guides/migrate_to_zone_aware_replication.markdown +++ b/docs/guides/migrate_to_zone_aware_replication.markdown @@ -42,6 +42,8 @@ Make sure to set the following settings before starting the migration: It is sufficient to set these settings on the querier using `querier.extraArgs`. Set `distributor.sharding-strategy` to `default` and `distributor.shard-by-all-labels` to `"true"` there. Warning: This may increase resource usage of the queriers. + To get the rollout-operator running, you will have to install its CRDs. Due to Helm's CRD handling, you have to apply [these manifests](https://github.com/grafana/helm-charts/tree/main/charts/rollout-operator/charts/crds/crds) manually + 1. Set `ingester.zoneAwareReplication.enabled=true`, `ingester.zoneAwareReplication.migration.enabled=true`, `ingester.zoneAwareReplication.zones` to the desired zones but with `replicas=0`. Set `rollout_operator.enabled=true`. Upgrade the chart. ```yaml ingester: diff --git a/values.yaml b/values.yaml index 10afadd8..3093fae2 100644 --- a/values.yaml +++ b/values.yaml @@ -1853,5 +1853,18 @@ rollout_operator: enabled: false webhooks: enabled: false - crds: - enabled: false + podSecurityContext: + fsGroup: 10001 + runAsGroup: 10001 + runAsNonRoot: true + runAsUser: 10001 + seccompProfile: + type: RuntimeDefault + securityContext: + readOnlyRootFilesystem: true + capabilities: + drop: [ALL] + allowPrivilegeEscalation: false + runAsNonRoot: true + seccompProfile: + type: RuntimeDefault