v6.2.9
Support multiple Traefik basic auth passwords, tighten Kubernetes roles and role bindings for the workload reloader, and log original client IP whenever possible.
This release contains bug fixes to Hydrolix v6.2. Refer to the release notes to see other notable feature announcements and information for this version.
Upgrade⚓︎
Don't skip minor versions when upgrading or downgrading
Skipping versions when upgrading or downgrading Hydrolix can result in database schema inconsistencies and cluster instability. Always upgrade or downgrade sequentially through each minor version, moving to every intermediate minor release in turn rather than jumping directly from the starting version to the target.
Point releases are safe to skip. Upgrade through each minor version, using the latest point release of each one. Don't install every point release along the way.
For example, to go from v5.10 to v6.1, upgrade sequentially to v5.11.10 -> v6.0.19 -> v6.1.10. Downgrading works the same way, in reverse.
Apply the new Hydrolix operator⚓︎
If you have a self-managed installation, apply the new operator directly with the kubectl command examples. If you're using Hydrolix-supplied tools to manage your installation, follow the procedure prescribed by those tools.
Changelog⚓︎
Improvements⚓︎
Cluster operations improvements⚓︎
- Traefik now accepts multiple basic authentication passwords in one Kubernetes secret, where it previously accepted one. Use commas to separate passwords, or the character set in the
traefik_password_delimitertunable.
Bug fixes⚓︎
Config API fixes⚓︎
- Audit records now take the client IP from the first
X-Forwarded-Forentry, falling back to theREMOTE_ADDRheader, theX-Real-Ipheader, then the connection's remote address. - Fixed storage creation failing when every bucket access check passed. The Config API looked for the first failing check and errored when there wasn't one.
Cluster operations fixes⚓︎
- Scoped the
reloaderKubernetes RBAC role to its own namespace, replacing a ClusterRole that granted cluster-wide access to secrets, configmaps, and workloads. On a shared cluster, that let a Hydrolix service account read any secret and restart another tenant's workloads. The scheduler, descheduler, and OpenTelemetry roles were scoped the same way.