Update dependency hetznercloud/hcloud-cloud-controller-manager to v1.35.0 - #152
Open
23t-machine-user wants to merge 1 commit into
Open
Update dependency hetznercloud/hcloud-cloud-controller-manager to v1.35.0#15223t-machine-user wants to merge 1 commit into
23t-machine-user wants to merge 1 commit into
Conversation
23t-machine-user
force-pushed
the
renovate/hetznercloud-hcloud-cloud-controller-manager-1.x
branch
from
January 10, 2025 08:36
9586409 to
5a49f4d
Compare
23t-machine-user
force-pushed
the
renovate/hetznercloud-hcloud-cloud-controller-manager-1.x
branch
from
January 16, 2025 05:33
5a49f4d to
f9106b9
Compare
23t-machine-user
force-pushed
the
renovate/hetznercloud-hcloud-cloud-controller-manager-1.x
branch
from
January 22, 2025 14:47
f9106b9 to
7cba688
Compare
23t-machine-user
force-pushed
the
renovate/hetznercloud-hcloud-cloud-controller-manager-1.x
branch
from
April 16, 2025 08:03
7cba688 to
93a2174
Compare
23t-machine-user
force-pushed
the
renovate/hetznercloud-hcloud-cloud-controller-manager-1.x
branch
from
May 20, 2025 14:22
93a2174 to
94b05ae
Compare
23t-machine-user
force-pushed
the
renovate/hetznercloud-hcloud-cloud-controller-manager-1.x
branch
from
May 21, 2025 08:04
94b05ae to
609dfc9
Compare
23t-machine-user
force-pushed
the
renovate/hetznercloud-hcloud-cloud-controller-manager-1.x
branch
from
July 2, 2025 14:22
609dfc9 to
06a850f
Compare
23t-machine-user
force-pushed
the
renovate/hetznercloud-hcloud-cloud-controller-manager-1.x
branch
from
July 29, 2025 06:17
06a850f to
85baf69
Compare
23t-machine-user
force-pushed
the
renovate/hetznercloud-hcloud-cloud-controller-manager-1.x
branch
from
October 1, 2025 15:22
85baf69 to
dd02694
Compare
23t-machine-user
force-pushed
the
renovate/hetznercloud-hcloud-cloud-controller-manager-1.x
branch
from
October 29, 2025 14:03
dd02694 to
0df6c9d
Compare
23t-machine-user
force-pushed
the
renovate/hetznercloud-hcloud-cloud-controller-manager-1.x
branch
from
December 18, 2025 16:24
0df6c9d to
ee44f7d
Compare
23t-machine-user
force-pushed
the
renovate/hetznercloud-hcloud-cloud-controller-manager-1.x
branch
from
January 20, 2026 10:42
ee44f7d to
0a8e17d
Compare
23t-machine-user
force-pushed
the
renovate/hetznercloud-hcloud-cloud-controller-manager-1.x
branch
from
January 22, 2026 13:18
0a8e17d to
dd0e895
Compare
23t-machine-user
force-pushed
the
renovate/hetznercloud-hcloud-cloud-controller-manager-1.x
branch
from
February 11, 2026 16:37
dd0e895 to
e101c3a
Compare
23t-machine-user
force-pushed
the
renovate/hetznercloud-hcloud-cloud-controller-manager-1.x
branch
from
February 20, 2026 07:34
e101c3a to
bae98f3
Compare
23t-machine-user
force-pushed
the
renovate/hetznercloud-hcloud-cloud-controller-manager-1.x
branch
from
March 3, 2026 19:47
bae98f3 to
8e6d0ec
Compare
23t-machine-user
force-pushed
the
renovate/hetznercloud-hcloud-cloud-controller-manager-1.x
branch
from
March 31, 2026 15:44
8e6d0ec to
37cbeba
Compare
23t-machine-user
force-pushed
the
renovate/hetznercloud-hcloud-cloud-controller-manager-1.x
branch
from
May 8, 2026 08:50
37cbeba to
af53197
Compare
23t-machine-user
force-pushed
the
renovate/hetznercloud-hcloud-cloud-controller-manager-1.x
branch
from
May 19, 2026 14:46
af53197 to
bb49674
Compare
23t-machine-user
force-pushed
the
renovate/hetznercloud-hcloud-cloud-controller-manager-1.x
branch
from
June 12, 2026 12:39
bb49674 to
dd9b4a3
Compare
23t-machine-user
force-pushed
the
renovate/hetznercloud-hcloud-cloud-controller-manager-1.x
branch
from
June 18, 2026 14:31
dd9b4a3 to
c9de552
Compare
23t-machine-user
force-pushed
the
renovate/hetznercloud-hcloud-cloud-controller-manager-1.x
branch
from
July 17, 2026 10:52
c9de552 to
af83c1a
Compare
23t-machine-user
force-pushed
the
renovate/hetznercloud-hcloud-cloud-controller-manager-1.x
branch
from
August 11, 2026 06:18
af83c1a to
ba145d0
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v1.20.0→v1.35.0Release Notes
hetznercloud/hcloud-cloud-controller-manager (hetznercloud/hcloud-cloud-controller-manager)
v1.35.0Compare Source
Compare to previous version
Zone Label
The
datacenterproperty was removed from the Server object (see changelog. For backwards compatibility, we statically compute the datacenter from the location to fill thetopology.kubernetes.io/zoneandfailure-domain.beta.kubernetes.io/zonelabels. In the next major release we will stop setting these values. To stop setting these values now, you can set the environment variableHCLOUD_INSTANCES_ZONE_LABEL_ENABLED=false. See here for more details.Features
v1.34.0Compare Source
Compare to previous version
Features
Bug Fixes
v1.33.0Compare Source
Changed
Renamed
HCLOUD_SERVER_CACHE_TTLtoHCLOUD_SERVER_CACHE_MAX_AGE. The server cache lifetime is now configured viaHCLOUD_SERVER_CACHE_MAX_AGE(default 10s). Individual controllers may override this default for specific lookups — for example, the routes controller uses a longer max age. Action required: if you setHCLOUD_SERVER_CACHE_TTL, switch toHCLOUD_SERVER_CACHE_MAX_AGE; the old variable is no longer recognized.Removed
Removed the
hcops/AllServersCache.*operation metrics. The legacy AllServersCache was replaced by the shared server cache, so the followingcloud_controller_manager_operations_totalseries labeled op="hcops/AllServersCache.*" are no longer emitted:hcops/AllServersCache.ByIDhcops/AllServersCache.ByNamehcops/AllServersCache.ByPrivateIPhcops/AllServersCache.getCachehcops/AllServersCache.refreshCacheThey are superseded by the new server cache metric
cloud_controller_manager_server_cache_requests_total, a counter partitioned by subsystem, mode, and result:Update any dashboards or alerts referencing the old op series accordingly.
Features
Bug Fixes
v1.32.0Compare Source
Cache Server Lookups in Node Controllers
This release introduces an experimental server cache to reduce Hetzner Cloud API calls. During an experimental phase, breaking changes on those features may occur within minor releases.
The node and node lifecycle controllers look up Servers by ID or name, generating significant API traffic during cluster scaling. A new cache sits between the controllers and the API to serve these lookups, reducing the number of requests.
It is enabled by default since we believe the implementation is safe in practice, but is experimental and may see breaking changes within minor releases. Configure it via environment variables:
HCLOUD_SERVER_CACHE_MODE(all|one|off, defaultall):all— fetch all Servers once and serve lookups from the snapshot until the TTL expires.one— cache each Server individually with its own expiration.off— disable caching; every lookup hits the API.HCLOUD_SERVER_CACHE_TTL(duration, default10s): lifetime of cached entries (e.g.30s,2m); values above a minute are not recommended.Features
v1.31.1Compare Source
Bug Fixes
v1.31.0Compare Source
Features
Bug Fixes
v1.30.1Compare Source
Datacenter Deprecation
The
server.datacenterfield is deprecated and will be removed from the API response after July 2026: https://docs.hetzner.cloud/changelog#2025-12-16-phasing-out-datacentersTo avoid a breaking change in HCCM, we decided to statically map from the old location names to the existing datacenter names for the
topology.kubernetes.io/zonelabel. For new locations we will return the location name without a-dcxxsuffix.Deployments of
hcloud-cloud-controller-managerthat are not updated when the field is removed from the API will panic with the following error:"Observed a panic" panic="runtime error: invalid memory address or nil pointer dereference" panicGoValue=""invalid memory address or nil pointer dereference""
We have published an RFC which details how we want to continue utilizing the labels
topology.kubernetes.io/zoneandtopology.kubernetes.io/region: #1146 (comment)Bug Fixes
v1.30.0Compare Source
Features
Bug Fixes
v1.29.2Compare Source
Bug Fixes
v1.29.1Compare Source
Bug Fixes
v1.29.0Compare Source
Watch-Based Route Reconciliation
Previously, route reconciliation is performed at a fixed interval of 30s. This leads to unnecessary API requests, as a
GET /v1/networks/{id}call is triggered every 30s, even when no changes have occurred.Upstream, we have contributed an event-driven approach, similar to the mechanisms used by other controllers such as the Load Balancer controller. With this new approach, route reconciliation is triggered by node additions, node deletions, or changes to a node’s
PodCIDRsorAddresses. Additionally, to ensure consistency, reconciliation still occurs periodically at a randomized interval between 12 and 24 hours.Enabled by default
This feature is now enabled by default.
If you encounter any problems you can disable the feature by setting the following Helm value:
args.feature-gates=CloudControllerManagerWatchBasedRoutesReconciliation=falseGlobal Load Balancer Defaults
Configure cluster-wide defaults for Load Balancers via the extended
HCLOUD_LOAD_BALANCERS_*env vars. These values automatically apply during Load Balancer creation and reconciliation whenever annotations are omitted. Learn more about it in the reference documentationFeatures
v1.28.0Compare Source
Updated ClusterRole for HCCM
We have introduced a custom
ClusterRolefor the HCCM component, based on the upstream recommendation from sig-cloud-provider.To ensure a smooth transition, we renamed the
ClusterRoleBindingby adding the:restrictedsuffix. This change was necessary because theroleReffield in aClusterRoleBindingis immutable, which would otherwise cause errors during a Helm upgrade.As a result, users who deploy HCCM using the provided Kubernetes manifests must manually delete the old
ClusterRoleBindingafter applying the updated manifests. Users deploying via the Helm chart do not need to take any action.Features
Bug Fixes
v1.27.0Compare Source
Attach Load Balancer to a Subnet
If your CCM is configured for a Private Network, Load Balancers can now join one of its subnets. To place a Load Balancer in a specific subnet, use the new
load-balancer.hetzner.cloud/private-subnet-ip-rangeannotation. Learn more about this feature here.Watch-Based Route Reconciliation (Experimental)
Currently, route reconciliation is performed at a fixed interval of 30s. This leads to unnecessary API requests, as a
GET /v1/networks/{id}call is triggered every 30s, even when no changes have occurred.Upstream we have proposed an event-driven approach, similar to the mechanism used by other controllers such as the Load Balancer Controller. With this new approach, route reconciliation is triggered on node additions, node deletions, or when the
PodCIDRsorAddressesof nodes change. Additionally, to ensure consistency, reconciliation will still occur periodically at a randomized interval between 12 and 24 hours.We are close to merging a Kubernetes Enhancement Proposal (KEP). Furthermore, a pull request containing the implementation is already open in the Kubernetes repository.
Forked Upstream Libraries
In this release, we replaced the upstream
controller-managerandcloud-providerlibraries with our own forks. These forks are based on the upstreamv0.34.1release (aligned with Kubernetes v1.34.1) and include our patches on top.Enabling the Feature
This feature is disabled by default and will not affect existing deployments unless explicitly enabled. We recommend testing it in a non-production environment before considering use in production.
As the KEP has not yet been reviewed for production readiness, the feature gate name may change in an upcoming release. Since this feature is marked as experimental, such changes will not be considered breaking.
To enable the feature, set the following Helm value:
args.feature-gates=CloudControllerManagerWatchBasedRoutesReconciliation=trueFeatures
Bug Fixes
v1.26.0Compare Source
Features
v1.25.1Compare Source
Bug Fixes
v1.25.0Compare Source
Features
v1.24.0Compare Source
Improved Robot Support in hcloud-cloud-controller-manager
The hcloud-cloud-controller-manager now forwards
InternalIPsby default on Robot nodes when the--node-ipflag is used. If the provided IP is not already registered as anExternalIPand matches the expected address family, it will be forwarded automatically during initialization.This allows the use of vSwitch IPs in private networks and Load Balancers.
🔗 Learn more in our updated Robot documentation
📘 Follow our how-to-guide to set up Load Balancers with vSwitch IPs.
Features
Bug Fixes
v1.23.0Compare Source
Features
Bug Fixes
v1.22.0Compare Source
This release includes an extension of our current metrics to also include the internals of
k8s.io/cloud-providerwith respect to the work queue depth and requests to the Kubernetes API.Besides having all data available, this will also help us with debugging #661.
Features
v1.21.0Compare Source
Feature Highlights & Upgrade Notes
Load Balancer IPs set to Private IPs
If networking support is enabled, the load balancer IPs are now populated with the private IPs, unless the
load-balancer.hetzner.cloud/disable-private-ingressannotation is set totrue. Please make sure that you configured the annotation according to your needs, for example if you are usingexternal-dns.Provided-By Label
We introduced a the label
instance.hetzner.cloud/provided-by, which will be automatically added to all new nodes. This label can have the valuescloudorrobotto distinguish between our products. We use this label in the csi-driver to ensure the daemonset is only running on cloud nodes. We recommend to add this label to your existing nodes with the appropriate value.kubectl label node $CLOUD_NODE_NAME instance.hetzner.cloud/provided-by=cloudkubectl label node $ROBOT_NODE_NAME instance.hetzner.cloud/provided-by=robotLoad Balancer IPMode Proxy
Kubernetes KEP-1860 added a new field to the Load Balancer Service Status that allows us to mark if the IP address we add should be considered as a Proxy (always send traffic here) and VIP (allow optimization by keeping the traffic in the cluster).
Previously Kubernetes considered all IPs as VIP, which caused issues when when the PROXY protocol was in use. We have previously recommended to use the annotation
load-balancer.hetzner.cloud/hostnameto workaround this problem.We now set the new field to
Proxyif the PROXY protocol is active so the issue should no longer appear. If you only added theload-balancer.hetzner.cloud/hostnameannotation for this problem, you can remove it after upgrading.Further information:
Features
Bug Fixes
Kubernetes Support
This version was tested with Kubernetes 1.29 - 1.31. Furthermore, we dropped v1.27 and v1.28 support.
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate CLI.