Skip to content

v6.2.9

Support multiple Traefik basic auth passwords, tighten Kubernetes roles and role bindings for the workload reloader, and log original client IP whenever possible.

This release contains bug fixes to Hydrolix v6.2. Refer to the release notes to see other notable feature announcements and information for this version.

Upgrade⚓︎

Don't skip minor versions when upgrading or downgrading

Skipping versions when upgrading or downgrading Hydrolix can result in database schema inconsistencies and cluster instability. Always upgrade or downgrade sequentially through each minor version, moving to every intermediate minor release in turn rather than jumping directly from the starting version to the target.

Point releases are safe to skip. Upgrade through each minor version, using the latest point release of each one. Don't install every point release along the way.

For example, to go from v5.10 to v6.1, upgrade sequentially to v5.11.10 -> v6.0.19 -> v6.1.10. Downgrading works the same way, in reverse.

Apply the new Hydrolix operator⚓︎

If you have a self-managed installation, apply the new operator directly with the kubectl command examples. If you're using Hydrolix-supplied tools to manage your installation, follow the procedure prescribed by those tools.

1
2
3
4
VERSION=v6.2.9
BASEURL="https://www.hydrolix.io/operator/${VERSION}/operator-resources"

kubectl apply -f "${BASEURL}?namespace=${HDX_KUBERNETES_NAMESPACE}&gcp-storage-sa=${GCP_STORAGE_SA}"
1
2
3
4
VERSION=v6.2.9
BASEURL="https://www.hydrolix.io/operator/${VERSION}/operator-resources"

kubectl apply -f "${BASEURL}?namespace=${HDX_KUBERNETES_NAMESPACE}&aws-storage-role=${AWS_STORAGE_ROLE}"
1
2
3
4
VERSION=v6.2.9
BASEURL="https://www.hydrolix.io/operator/${VERSION}/operator-resources"

kubectl apply -f "${BASEURL}?namespace=${HDX_KUBERNETES_NAMESPACE}"

Changelog⚓︎

Improvements⚓︎

Cluster operations improvements⚓︎

  • Traefik now accepts multiple basic authentication passwords in one Kubernetes secret, where it previously accepted one. Use commas to separate passwords, or the character set in the traefik_password_delimiter tunable.

Bug fixes⚓︎

Config API fixes⚓︎

  • Audit records now take the client IP from the first X-Forwarded-For entry, falling back to the REMOTE_ADDR header, the X-Real-Ip header, then the connection's remote address.
  • Fixed storage creation failing when every bucket access check passed. The Config API looked for the first failing check and errored when there wasn't one.

Cluster operations fixes⚓︎

  • Scoped the reloader Kubernetes RBAC role to its own namespace, replacing a ClusterRole that granted cluster-wide access to secrets, configmaps, and workloads. On a shared cluster, that let a Hydrolix service account read any secret and restart another tenant's workloads. The scheduler, descheduler, and OpenTelemetry roles were scoped the same way.