CARVIEW |
Select Language
HTTP/2 200
date: Mon, 21 Jul 2025 19:10:36 GMT
content-type: text/html; charset=utf-8
vary: X-PJAX, X-PJAX-Container, Turbo-Visit, Turbo-Frame, X-Requested-With,Accept-Encoding, Accept, X-Requested-With
etag: W/"3fb4a0e373100c2c015a13e414a7addf"
cache-control: max-age=0, private, must-revalidate
strict-transport-security: max-age=31536000; includeSubdomains; preload
x-frame-options: deny
x-content-type-options: nosniff
x-xss-protection: 0
referrer-policy: no-referrer-when-downgrade
content-security-policy: default-src 'none'; base-uri 'self'; child-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.com github-cloud.s3.amazonaws.com github-production-repository-file-5c1aeb.s3.amazonaws.com github-production-upload-manifest-file-7fdce7.s3.amazonaws.com github-production-user-asset-6210df.s3.amazonaws.com *.rel.tunnels.api.visualstudio.com wss://*.rel.tunnels.api.visualstudio.com objects-origin.githubusercontent.com copilot-proxy.githubusercontent.com proxy.individual.githubcopilot.com proxy.business.githubcopilot.com proxy.enterprise.githubcopilot.com *.actions.githubusercontent.com wss://*.actions.githubusercontent.com productionresultssa0.blob.core.windows.net/ productionresultssa1.blob.core.windows.net/ productionresultssa2.blob.core.windows.net/ productionresultssa3.blob.core.windows.net/ productionresultssa4.blob.core.windows.net/ productionresultssa5.blob.core.windows.net/ productionresultssa6.blob.core.windows.net/ productionresultssa7.blob.core.windows.net/ productionresultssa8.blob.core.windows.net/ productionresultssa9.blob.core.windows.net/ productionresultssa10.blob.core.windows.net/ productionresultssa11.blob.core.windows.net/ productionresultssa12.blob.core.windows.net/ productionresultssa13.blob.core.windows.net/ productionresultssa14.blob.core.windows.net/ productionresultssa15.blob.core.windows.net/ productionresultssa16.blob.core.windows.net/ productionresultssa17.blob.core.windows.net/ productionresultssa18.blob.core.windows.net/ productionresultssa19.blob.core.windows.net/ github-production-repository-image-32fea6.s3.amazonaws.com github-production-release-asset-2e65be.s3.amazonaws.com insights.github.com wss://alive.github.com api.githubcopilot.com api.individual.githubcopilot.com api.business.githubcopilot.com api.enterprise.githubcopilot.com; font-src github.githubassets.com; form-action 'self' github.com gist.github.com copilot-workspace.githubnext.com objects-origin.githubusercontent.com; frame-ancestors 'none'; frame-src viewscreen.githubusercontent.com notebooks.githubusercontent.com; img-src 'self' data: blob: github.githubassets.com media.githubusercontent.com camo.githubusercontent.com identicons.github.com avatars.githubusercontent.com private-avatars.githubusercontent.com github-cloud.s3.amazonaws.com objects.githubusercontent.com release-assets.githubusercontent.com secured-user-images.githubusercontent.com/ user-images.githubusercontent.com/ private-user-images.githubusercontent.com opengraph.githubassets.com copilotprodattachments.blob.core.windows.net/github-production-copilot-attachments/ github-production-user-asset-6210df.s3.amazonaws.com customer-stories-feed.github.com spotlights-feed.github.com objects-origin.githubusercontent.com *.githubusercontent.com; manifest-src 'self'; media-src github.com user-images.githubusercontent.com/ secured-user-images.githubusercontent.com/ private-user-images.githubusercontent.com github-production-user-asset-6210df.s3.amazonaws.com gist.github.com; script-src github.githubassets.com; style-src 'unsafe-inline' github.githubassets.com; upgrade-insecure-requests; worker-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/
server: github.com
content-encoding: gzip
accept-ranges: bytes
set-cookie: _gh_sess=s6KUqXdRclfavDq119%2BqhAnjOIeM5827YTmljA7PTwrLnerCcAFPDzrF5gSSNkuW9IDiF%2B%2BnQDlzLDiWhvhpsA8VAcpajEUEd4d6zsQCnq0tZeXv%2BJ8BmxIXKjB9BdKQhefCl94FJEr7f7tyOvsKLUBNLWAqXU1iU%2FdYXqbA8tdmgnFsCg1DW%2F0fvjfy1k0xFTQvEUluHx74ZK2hVx9j3%2FPaBczmzGtn9te3LRb3EAR%2BiM0EvNWkNafnJ6dRE%2BS0S6cumh4O1bFBWa0yug9z%2Fg%3D%3D--RvZNa4WaQ%2FRm%2BYTX--O3YHVvzjiXefK5rP6EtusA%3D%3D; Path=/; HttpOnly; Secure; SameSite=Lax
set-cookie: _octo=GH1.1.245569608.1753125035; Path=/; Domain=github.com; Expires=Tue, 21 Jul 2026 19:10:35 GMT; Secure; SameSite=Lax
set-cookie: logged_in=no; Path=/; Domain=github.com; Expires=Tue, 21 Jul 2026 19:10:35 GMT; HttpOnly; Secure; SameSite=Lax
x-github-request-id: E7A2:7BE7E:2806E1:2FDF7A:687E90AB
Releases · StackStorm/stackstorm-k8s · GitHub
12 Apr 15:25
cognifloyd
Jacob Floyd
Loading
13 Feb 18:29
Loading
28 Jan 22:07
Loading
30 Jul 16:28
Loading
01 Apr 17:57
Loading
22 Dec 17:54
Loading
11 Sep 19:08
Loading
30 Mar 12:21
Loading
17 Feb 20:27
Loading
22 Jan 17:46
Loading
Skip to content
Navigation Menu
{{ message }}
-
-
Notifications
You must be signed in to change notification settings - Fork 113
Releases: StackStorm/stackstorm-k8s
Releases · StackStorm/stackstorm-k8s
v1.1.0
80f80b4
This commit was signed with the committer’s verified signature.
Compare
New Features / Enhancements
- Add
securityContext
support to customst2packs
images,extra_hooks
jobs; Also fallback to st2actionrunner securityContext for misc init container jobs and pods. by @cognifloyd in #410 - Stop generating the DataStore Secret (#385) and checksum labels when existing secret provided or disabled by @bmarick in #391
- Stop generating the checksum labels for Auth Secret when existing secret provided by @bmarick in #392
- Use
image.pullPolicy
for all containers including init containers that useimage.utilityImage
by @jk464 in #398 - Add
image.entrypoint
value to simplify using a custom entry point likedumb-init
orpid1
by @cognifloyd in #413
Bugfixes
Other Misc Changes
- Update README.md to fix mispelling of volumes by @FileMagic in #404
- Improve Deployments migration in
migrations/1.0/standardize-labels.sh
by temporarily orphaning the old ReplicaSets by @cognifloyd in #412
New Contributors
- @skiedude made their first contribution in #403
- @FileMagic made their first contribution in #404
- @jk464 made their first contribution in #398
Full Changelog: v1.0.0...v1.1.0
Assets 2
2 people reacted
v1.0.0
e71b4b1
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Compare
The first stable release! 🎉
Breaking Changes
- Use the standardized labels recommended in the Helm docs. You can use
migrations/v1.0/standardize-labels.sh
to prepare an existing cluster before running helm update. by @cognifloyd in #351 - Drop support for
networking.k8s.io/v1beta1
which was removed in kubernetes v1.22 (EOL 2022-10-28) by @cognifloyd in #353
New features
- Add
st2canary
job as a Helm Hook that runs before install/upgrade to ensurest2.packs.volumes
is configured correctly (ifst2.packs.volumes.enabled
). by @cognifloyd in #323 - Configurable
utilityImage
+clusterDomain
by @guzzijones in #356 - Enable using existing st2-auth secret. This allows users to manage this secret outside of the Helm process. by @bmarick in #359
- Add external secret for datastore encryption by @guzzijones in #366
- Add
terminationGracePeriodSeconds
to workflow and actionrunner pods to allow adjustment of grace period in k8s by @guzzijones in #374
Bugfixes
- Increase default db timeouts to avoid replicaset timeout by @guzzijones in #356
- PVC should use
claimName
key by @fuhrmannb in #369 - Remove redundant
[credentials]
header by @cars in #371 - Prevent duplicate init containers on helm upgrade by @guzzijones in #375
- Workaround kubeproxy+kubelet race: Add presleep for st2auth, st2web, st2api, st2stream by @guzzijones in #382
- Secret DataStore Crypto Key should not be created when existing provided by @bmarick in #385
Other Misc Changes
- Reduce duplication in label tests by @cognifloyd in #354
- CI: Shift K3s and K8s versions forward by @mamercad in #358
- Update K8s to latest version by @ZoeLeah in #379
- Update the Chart Maintainers - the StackStorm Authors by @armab in #383
- Create
v1.0.0
and add "Releasing information" by @mamercad in #389
New Contributors
- @guzzijones made their first contribution in #356
- @fuhrmannb made their first contribution in #369
- @cars made their first contribution in #371
- @ZoeLeah made their first contribution in #379
- @armab made their first contribution in #383
Full Changelog: v0.110.0...v1.0.0
Assets 2
3 people reacted
v0.110.0
ca33b2a
This commit was created on GitHub.com and signed with GitHub’s verified signature.
The key has expired.
Compare
This release, v0.110.0, is the last of the v0.* releases. The next release will be v1.0.0.
This release installs StackStorm v3.8
as the new stable version (#347). Other updates are listed below.
Breaking Changes
None
Community Contributions (THANKS!)
New feature contributions
- Add support for providing custom st2actionrunner-specific docker repository, image name, pull policy, and pull secret via
values.yaml
. (#141) (by @Sheshagiri) - Add
existingConfigSecret
. If this is defined, thest2.secrets.conf
key within this secret will be written as /etc/st2/st2.secrets.conf and added to the end of the command line arguments of all pods. (#289) (by @eric-al/@ericreeves) - Add
extra_volumes
to all python-based st2 jobs. (#333) (by @bmarick) - Add ability to create custom labels for service account. (#327) (by @SuganJoe)
- Add support for providing
ingressClassName
. (#336) (by @mamercad) - Set st2client resources by values.yaml. (#339) (by @mamercad)
Bugfix contributions
- Temporary workaround for #311 to use previous bitnami index from: bitnami/charts#10539 (#312 #318) (by @0xhaven)
- Use the correct
apiVersion
forIngress
to add support for Kubernetesv1.22
. (#301) (by @arms11) - Fix bug that hung an init container when
st2.packs.volumes.enabled
withoutst2.packs.volumes.configs
. (#324) (by @rebrowning) - Fix bug that would not set the appropriate redis connection string when using redis.password and redis.usePassword (#325) (by @rebrowning)
Other Misc contributions
- Switch to the official bats Docker image for e2e tests. (#338) (by @mamercad)
- Cover the three most recent Kubernetes versions in Minikube and the single most recent in K3s. (#342) (by @mamercad)
- Update the GitHub badges. (#345) (by @mamercad)
- Reorganizing and renaming the CI workflows and jobs. (#344) (by @mamercad)
- Add an experimental GitHub/K3s Lint and End-to-End testing workflow. (#243) (by @mamercad)
Other Misc
- Refactor label definitions to be more consistent by building labels and label selectors in partial helper templates. (#299) (by @cognifloyd)
- Fix mounts for
jobs.preRegisterContentCommand
container to use the same mounts as the primary register-content container. (#322) (by @cognifloyd)
Assets 2
v0.100.0
b6419e6
This commit was created on GitHub.com and signed with GitHub’s verified signature.
The key has expired.
Compare
Breaking Changes
None
Community Contributions (THANKS!)
- Migrate from
python 3.6
Ubuntu Bionic
topython 3.8
Ubuntu Focal
as a base StackStorm OS (StackStorm/st2-dockerfiles#54) (by @jstaph) - Add support for use of overrides that are available in
v3.7
of st2 via helm charts. (#306) (by @cwilson21)
Misc updates
Assets 2
v0.90.0
6698db7
This commit was created on GitHub.com and signed with GitHub’s verified signature.
The key has expired.
Compare
Breaking Changes
None
Community Contributions (THANKS!)
- New feature to include possibility for external services in st2api, st2stream and st2auth, setting default value for this services as
ClusterIP
andhostname: ""
. Also, added new entry for custom_annotations_test.yaml and created new unit test services_test.yaml. (by @sandesvitor)
Major Features
- Add
extra_volumes
to all python-based st2 deployments. This can facilitate changing log levels by loading logging conf file(s) from a custom ConfigMap. (#276) (by @cognifloyd) - Allow partitioning sensors using the hash_range strategy instead of one sensor per pod. (#218) (by @cognifloyd)
- Advanced Feature: Make securityContext (on Deployments/Jobs) and podSecurityContext (on Pods) configurable. This allows dropping all capabilities, for example. You can override the securityContext for
st2actionrunner
,st2sensorcontainer
, andst2client
if your actions or sensors need, for example, additional capabilites that the rest of StackStorm does not need. (#271) (by @cognifloyd) - Advanced Feature: Add extra Helm hook Jobs. This minimizes the boilerplate required to run stackstorm workflows at various helm hook stages: post-install, pre-upgrade, post-upgrade. (#265) (by @cognifloyd)
Everything Else
- Prefix template helpers with chart name and format helper comments as template comments. (#272) (by @cognifloyd)
- Initialize basic unittest infrastructure using
helm-unittest
. Added tests for labels, custom annotations, SecurityContext, pullSecrets, pullPolicy, Resources, nodeSelector, tolerations, affinity, dnsPolicy, dnsConfig, ServiceAccount attach, postStartScript, both sensor-modes, env, envFrom, st2.packs.images, and st2.packs.volumes. (#284, #288, #292)
Assets 2
v0.80.0
4cb9864
This commit was created on GitHub.com and signed with GitHub’s verified signature.
The key has expired.
Compare
Breaking Changes
- Auto-generate
datastore_crypto_key
on install if not provided. This way all HA installs will have a datastore_crypto_key configured. This is only a breaking change for installations that do not want adatastore_crypto_key
. To disable setdatastore_crypto_key
todisable
instead of setting it to""
,null
, or leaving it unset. (#266)
Community Contributions (THANKS!)
- Allow adding custom env variables to any Deployment or Job. (#120) (by @angrydeveloper)
- Include
nodeSelector
,affinity
andtolerations
onst2client
to allow more flexibility in pod positioning. (#263) (by @sandesvitor)
Significant Fixes
- Set default/sample RBAC config files to "" (empty string) to prevent adding them. This is needed because they cannot be removed by overriding the roles/mappings values. (#247)
- Fix indent for lifecycle postStart hook of
st2web
pod. (#268)
Major Features
- Switch st2 to
v3.6
as a new default stable version (#274) - Advanced Feature: Allow
st2web
to serve HTTPS when the ssl certs are provided viast2web.extra_volumes
. To enable this, addST2WEB_HTTPS: "1"
tost2web.env
in your values file. (#264) - Add
extra_volumes
tost2actionrunner
,st2client
,st2sensorcontainer
. This is useful for loading volumes to be used by actions or sensors. This might include secrets (like ssl certificates) and configuration (like system-wide ansible.cfg). (#254) - Some
helm upgrades
do not need to run all the jobs. An upgrade that only touches RBAC config, for example, does not need to run the register-content job. Use--set 'jobs.skip={apikey_load,key_load,register_content}'
to skip the other jobs. (#255) - Add
envFromSecrets
tost2actionrunner
,st2client
,st2sensorcontainer
, and jobs. This is useful for adding custom secrets to the environment. This complements theextra_volumes
feature (loading secrets as files) to facilitate loading secrets that are not easily injected via the filesystem. (#259)
Everything Else
- Refactor deployments/jobs to inject st2 username/password via
envFrom
instead of viaenv
. (#257) - Use "--convert" when loading keys into datastore (in key-load Job) so that
st2.keyvalue[].value
can be any basic JSON data type. (#253) - Custom annotations now apply to deployments and jobs, not just pods. (#270)
- Template more values:
- Improve sensor handling:
- Explicitly differentiate sensor modes:
all-sensors-in-one-pod
vsone-sensor-per-pod
. Exposes the mode in newstackstorm/sensor-mode
annotation. (#222) - Make configuring
stackstorm/sensor-mode=all-sensors-in-one-pod
more obvious by usingst2.packs.sensors
only forone-sensor-per-pod
.all-sensors-in-one-pod
mode now only uses values fromst2sensorcontainer
. (#246)
- Explicitly differentiate sensor modes:
Assets 2
v0.70.0
3a0152c
This commit was created on GitHub.com and signed with GitHub’s verified signature.
The key has expired.
Compare
Breaking Changes
- Move
secrets.st2.*
values intost2.*
(#203)
Community Contributions (THANKS!)
- Updated redis constant sentinel ID which will allow other sentinel peers to update to the new given IP in case of pod failure or worker node reboots. (#191) (by @manisha-tanwar)
- Fix a bug when datastore cryto keys are not able to read by the rules engine.
datastore_crypto_key
volume is now mounted on thest2rulesengine
pods (#223) (by @moti1992)
Significant Fixes
- Fix permissions for
/home/stanley/.ssh/stanley_rsa
using the postStart lifecycle hook (#219) - st2chatops change: If
st2chatops.env.ST2_API_KEY
is defined, do not setST2_AUTH_USERNAME
orST2_AUTH_PASSWORD
env vars any more. (#197)
Major Features
- Shared packs volumes
st2.packs.volumes
. Allow using cluster-specific persistent volumes to store packs, virtualenvs, and (optionally) configs. This enables usingst2 pack install
. It even works withst2packs
images inst2.packs.images
. (#199) - Add
image.tag
overrides for all deployments. (#200) - Auto-generate password and ssh_key secrets. (#203)
- Allow adding
dnsPolicy
and/ordnsConfig
to all pods. (#201) - Make
system_user
configurable when using custom st2actionrunner images that do not providestanley
(#220) - Allow providing scripts in values for use in lifecycle postStart hooks of all deployments. (#206)
- Add
preRegisterContentCommand
in aninitContainer
for register-content job to run last-minute content customizations (#213)
Everything Else
- Removed reference to st2-license pullSecrets, which was missed when removing enterprise flags (#192)
- Add optional imagePullSecrets to ServiceAccount using
serviceAccount.pullSecret
from values.yaml. If pods do not have imagePullSecrets (eg withoutimage.pullSecret
in values.yaml), k8s populates them from the ServiceAccount. (#196 & #239) - Reformat some yaml strings so that single quotes wrap strings that include double quotes (#194)
- If your k8s cluster admin requires custom annotations (eg: to indicate mongo or rabbitmq usage), you can now add those to each set of pods. (#195)
- Add optional hubot-scripts volume to st2chatops pod. To add this, define
st2chatops.hubotScriptsVolume
. (#207) - Add advanced pod placment (nodeSelector, affinity, tolerations) to specs for batch Jobs pods. (#193)
- Move st2-config-vol volume definition and list of st2-config-vol volumeMounts to helpers to reduce duplication (#198)
- Minimize required sensor config by using default values from st2sensorcontainer for each sensor in st2.packs.sensors (#221)
- Do not template rabbitmq secrets file unless rabbitmq subchart is enabled. (#242)
- Automatically stringify st2chatop.env values if needed. (#241)
Assets 2
v0.60.0
89be5cd
This commit was created on GitHub.com and signed with GitHub’s verified signature.
The key has expired.
Compare
Warning!
Breaking change!
- Switch st2 version to
v3.5dev
as a new latest development version (#187) - Change st2packs definition to a list, to support multiple st2packs containers (#166) (by @moonrail)
- Enabled RBAC/LDAP configuration for OSS version, removed enterprise flags (#182) (by @hnanchahal)
- Fixed datastore_crypto_key secret name for rules engine (#188) (by @lordpengwin)
Assets 2
v0.52.0
3d14e55
This commit was created on GitHub.com and signed with GitHub’s verified signature.
The key has expired.
Compare
Assets 2
v0.51.0
eee2803
This commit was created on GitHub.com and signed with GitHub’s verified signature.
The key has expired.
Compare
Assets 2
Previous Next
You can’t perform that action at this time.