Skip to main content
Version: v1.4.x

PaletteAI 1.4.0 Release Notes

Summary​

PaletteAI 1.4.0 is a stable release that adds AI Virtual Machine support, refactors lifecycle management for single node Compute Pools, and streamlines air-gapped profile bundle deployment.

  • AI Virtual Machines - PaletteAI can now run AI Virtual Machines (VMs) on compute pools backed by Spectro Cloud's Virtual Machine Orchestrator (VMO). AI VMs give workloads that need a full guest operating system, persistent disk, or GPU passthrough the same managed experience as containerized models. You create, list, and manage them from the console, with an AI VM section on compute pool overviews and a dedicated detail page. The built-in VmTemplate catalog and AI VM role-based access come from the definitions installer, and compute pool capacity now accounts for the resources AI VMs consume.
  • Compute pools - Single-node clusters are now configured via a single control plane pool with optional GPU requirements; node pool capacity totals parse memory consistently.
  • Aviz network fabric - A new NetworkFabric resource and a fabrics controller inventory Aviz fabric data.
  • Zot registry - Zot secret-name variables are injected into the system VariableSet and refreshed when the underlying secrets change, with a new Zot registry variables docs page.
  • Platform upgrades - The umbrella chart moves to Flux 2.2.4, cert-manager 1.21.0, Dex 2.45.1, Zot 2.1.20, and Alertmanager 0.34.0, and adds optional Gateway API HTTPRoute routing for Dex, Alertmanager, and Zot.
  • Reliability and security - Tenant admins receive read access to built-in system resources, ambiguous definition output macros are rejected instead of misrouted, and the bundled PaletteAI profile bundles are refreshed.

For the complete list of changes in each component, refer to Full Component Release Notes.

Upgrade Notes​

  1. You must upgrade the mural-crds chart to 0.7.26 before upgrading the mural chart to 1.4.0. For detailed instructions on how to upgrade PaletteAI, refer to the PaletteAI upgrade guide.

Component Versions​

The following component versions are pinned for this PaletteAI release:

ComponentVersion
brush0.5.34
canvas0.6.30
curator0.0.11
frisket0.1.10
hue0.12.38
mural-crds0.7.26

Mural Helm values​

The following diff lists changes to mural/charts/mural/values.yaml between PaletteAI 1.3.2 and 1.4.0. Review it before upgrading if you maintain custom Helm values.

values.yaml changes between 1.3.2 and 1.4.0
values.yaml
diff --git a/mural/charts/mural/values.yaml b/mural/charts/mural/values.yaml
index 66fce11241..44d11cfab9 100644
--- a/mural/charts/mural/values.yaml
+++ b/mural/charts/mural/values.yaml
@@ -71,8 +71,8 @@ global:
# - create 2 BackendConfig's, for configuring custom health checks for Canvas and Dex
# - use a custom FleetConfig controller image with the `gke-gcloud-auth-plugin` installed
kubernetesProvider: "Generic"
- certManagerVersion: "v1.19.1"
- muralVersion: "1.3.2" # x-release-please-version
+ certManagerVersion: "v1.21.0"
+ muralVersion: "1.4.0" # x-release-please-version
dns:
domain: "replace.with.your.domain"
rootIngress:
@@ -120,7 +120,7 @@ global:
username: ""
password: ""
basicAuthSecretName: ""
- muralCrdsVersion: "0.7.23-hotfix.2"
+ muralCrdsVersion: "0.7.26"

## @section certificates
## @param certificates.clusterIssuer.spec.selfSigned The spec for the ClusterIssuer used by cert-manager to issue the Mural root CA certificate.
@@ -1092,7 +1092,7 @@ alertmanager:
repository: us-docker.pkg.dev/palette-images-fips/palette/spectro-prometheus-bcfips/alertmanager
pullPolicy: IfNotPresent
# Overrides the image tag whose default is the chart appVersion.
- tag: "v0.29.0"
+ tag: "v0.34.0"
# Full external URL where alertmanager is reachable, used for backlinks.
baseURL: ""
# Uncomment to disable web config if TLS/basic auth are not being used
@@ -1226,6 +1226,20 @@ alertmanager:
# Service type
#
type: ClusterIP
+ serviceMonitor:
+ enabled: false
+ namespace: ""
+ additionalLabels: {}
+ interval: ""
+ scrapeTimeout: ""
+ path: /metrics
+ scheme: ""
+ tlsConfig: {}
+ bearerTokenFile: ""
+ basicAuth: {}
+ honorLabels: false
+ metricRelabelings: []
+ relabelings: []
ingress:
enabled: false
className: ""
@@ -1278,6 +1292,45 @@ alertmanager:
# {{ tlsSecretPerReplica.prefix }}-{{ $replicaNumber }}
#
prefix: "alertmanager"
+ ## route (map) allows configuration of Gateway API HTTPRoute resources
+ ## Requires Gateway API resources and a suitable controller installed within the cluster
+ ## Ref. https://gateway-api.sigs.k8s.io/guides/http-routing/
+ route:
+ main:
+ ## Enable this route
+ enabled: false
+ ## apiVersion set by default to "gateway.networking.k8s.io/v1"
+ apiVersion: ""
+ ## kind set by default to HTTPRoute
+ kind: ""
+ ## Annotations to attach to the HTTPRoute resource
+ annotations: {}
+ ## Labels to attach to the HTTPRoute resource
+ labels: {}
+ ## ParentRefs references the resources (usually Gateways) this HTTPRoute should be attached to
+ parentRefs: []
+ # - name: contour
+ # sectionName: http
+
+ ## Hostnames (templated) defines a set of hostnames that should match against the HTTP Host
+ ## header to select an HTTPRoute used to process the request
+ hostnames: []
+ # - alertmanager.domain.com
+
+ ## additionalRules (templated) allows adding custom rules to the route
+ additionalRules: []
+ ## Filters define the filters that are applied to requests that match this rule
+ filters: []
+ ## Matches define conditions used for matching the rule against incoming HTTP requests
+ matches:
+ - path:
+ type: PathPrefix
+ value: /
+ ## httpsRedirect adds a filter for redirecting to https (HTTP 301 Moved Permanently).
+ ## To redirect HTTP traffic to HTTPS, you need a Gateway with both HTTP and HTTPS listeners.
+ ## Matches and filters do not take effect if enabled.
+ ## Ref. https://gateway-api.sigs.k8s.io/guides/http-redirect-rewrite/
+ httpsRedirect: false
resources: {}
# We usually recommend not to specify default resources and to leave this as a conscious
# choice for the user. This also increases chances charts run on environments with little
@@ -1405,7 +1458,7 @@ alertmanager:
##
image:
repository: quay.io/prometheus-operator/prometheus-config-reloader
- tag: v0.86.2
+ tag: v0.94.0
pullPolicy: IfNotPresent
# containerPort: 9533

@@ -1509,7 +1562,7 @@ brush:
## @param brush.image.pullPolicy The pull policy to use for the image
image:
repository: public.ecr.aws/mural/brush
- tag: v0.5.30-hotfix.2
+ tag: v0.5.34
pullPolicy: IfNotPresent
## @param brush.imagePullSecrets The pull secrets to use for the image
imagePullSecrets: []
@@ -1804,7 +1857,7 @@ canvas:
## @param canvas.image.pullPolicy canvas image pull policy
image:
repository: public.ecr.aws/mural/canvas
- tag: v0.6.27-hotfix.2
+ tag: v0.6.30
pullPolicy: IfNotPresent
## @param canvas.imagePullSecrets Image pull secrets
imagePullSecrets: []
@@ -2043,7 +2096,7 @@ curator:
## @param curator.image.pullPolicy Image pull policy for curator.
image:
repository: public.ecr.aws/mural/curator
- tag: v0.0.8-hotfix.2
+ tag: v0.0.11
pullPolicy: IfNotPresent
## @param curator.imagePullSecrets Image pull secrets for curator.
imagePullSecrets: []
@@ -2123,7 +2176,7 @@ dex:
# -- [Image pull policy](https://kubernetes.io/docs/concepts/containers/images/#updating-images) for updating already existing images on a node.
pullPolicy: IfNotPresent
# -- Image tag override for the default value (chart appVersion).
- tag: "v2.44.0"
+ tag: "v2.45.1"
# -- When digest is set to a non-empty value, images will be pulled by digest (regardless of tag value).
digest: ""
# -- Reference to one or more secrets to be used when [pulling images](https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/#create-a-pod-that-uses-your-secret) (from private registries).
@@ -2352,6 +2405,38 @@ dex:
# - secretName: chart-example-tls
# hosts:
# - chart-example.local
+ httpRoute:
+ # -- Enable Gateway API HTTPRoute.
+ # Gateway API support is in EXPERIMENTAL status. Support depends on your Gateway controller implementation.
+ # See the [Gateway API documentation](https://gateway-api.sigs.k8s.io/) for details.
+ enabled: false
+ # -- Annotations to be added to the HTTPRoute.
+ annotations: {}
+ # -- References to the Gateway(s) that this HTTPRoute is attached to.
+ # See the [API reference](https://gateway-api.sigs.k8s.io/reference/spec/#gateway.networking.k8s.io/v1.ParentReference) for details.
+ parentRefs: []
+ # - name: gateway
+ # namespace: gateway-system
+ # sectionName: https
+ # port: 443
+
+ # -- Hostnames defines the hostnames for routing.
+ # See the [API reference](https://gateway-api.sigs.k8s.io/reference/spec/#gateway.networking.k8s.io/v1.Hostname) for details.
+ hostnames:
+ - chart-example.local
+ # -- HTTPRoute rules configuration.
+ # See the [API reference](https://gateway-api.sigs.k8s.io/reference/spec/#gateway.networking.k8s.io/v1.HTTPRouteRule) for details.
+ rules:
+ - matches:
+ - path:
+ type: PathPrefix
+ value: /
+ # filters:
+ # - type: RequestHeaderModifier
+ # requestHeaderModifier:
+ # add:
+ # - name: X-Custom-Header
+ # value: custom-value
serviceMonitor:
# -- Enable Prometheus ServiceMonitor.
# See the [documentation](https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/design.md#servicemonitor) and the [API reference](https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api.md#servicemonitor) for details.
@@ -2866,6 +2951,21 @@ flux2:
crds:
# -- Add annotations to all CRD resources, e.g. "helm.sh/resource-policy": keep
annotations: {}
+ # -- Enable Flux CRs migration using helm pre upgrade hook job
+ migration:
+ enabled: false
+ timeout: 5m
+ resources:
+ limits: {}
+ # cpu: 1000m
+ # memory: 1Gi
+ requests:
+ cpu: 100m
+ memory: 64Mi
+ nodeSelector: {}
+ affinity: {}
+ tolerations: []
+ annotations: {}
multitenancy:
# -- Implement the patches for Multi-tenancy lockdown.
# See https://fluxcd.io/docs/installation/#multi-tenancy-lockdown
@@ -2940,7 +3040,7 @@ flux2:
imageAutomationController:
create: false
image: ghcr.io/fluxcd/image-automation-controller
- tag: v1.0.2
+ tag: v1.2.5
resources:
limits: {}
# cpu: 1000m
@@ -2967,7 +3067,7 @@ flux2:
imageReflectionController:
create: false
image: ghcr.io/fluxcd/image-reflector-controller
- tag: v1.0.2
+ tag: v1.2.5
resources:
limits: {}
# cpu: 1000m
@@ -3041,7 +3141,7 @@ flux2:
notificationController:
create: false
image: ghcr.io/fluxcd/notification-controller
- tag: v1.7.3
+ tag: v1.9.4
resources:
limits: {}
# cpu: 1000m
@@ -3121,7 +3221,7 @@ flux2:
sourceWatcher:
create: false
image: ghcr.io/fluxcd/source-watcher
- tag: v2.0.2
+ tag: v2.2.4
resources:
limits: {}
# cpu: 1000m
@@ -3268,7 +3368,7 @@ fluxcd-manager:

## @param fluxcd-manager.kubectl.image The kubectl helper image to use for FluxCD operations
kubectl:
- image: us-east1-docker.pkg.dev/spectro-images/dev-fips/spectro-kubectl:1.33.3
+ image: us-east1-docker.pkg.dev/spectro-images/dev-fips/spectro-kubectl:1.34.2
## @skip fluxcd-manager.fluxcdConfig
fluxcdConfig:
installCRDs: true
@@ -3310,7 +3410,7 @@ frisket:
## @param frisket.image.pullPolicy Image pull policy for frisket.
image:
repository: public.ecr.aws/mural/frisket
- tag: v0.1.6-hotfix.2
+ tag: v0.1.10
pullPolicy: IfNotPresent
## @param frisket.imagePullSecrets Secret names used to authenticate the private image registry (leave empty for public ECR).
imagePullSecrets: []
@@ -3388,6 +3488,8 @@ hue:
controllerArgs:
reSyncPeriod: 5m
verbosity: 0
+ ## @param hue.controllerArgs.strictWorkloadPhases Panic when a Failed phase is written to a Workload or WorkloadDeployment during reconcile, unless the object sets annotation `wl.spectrocloud.com/allow-failed-phase` to `true`. For E2E and local use only; never enable in production.
+ strictWorkloadPhases: false
## @param hue.clusterType The type of cluster: [ hub | spoke | hub-as-spoke ]
clusterType: "hub-as-spoke"
## @param hue.projectName The name of the project that the managed cluster belongs to. If a Spoke belongs to a Project, the Project resource, as well as any supporting resources (Tenant, Settings, integration secrets) will be automatically federated to the Spoke. Required on workload clusters for OCI sync of component, trait, and policy definitions (tag `<tenantRef.name>-tenant-spoke-definitions`). Only applicable when ClusterType == spoke.
@@ -3482,7 +3584,7 @@ hue:
## @param hue.image.pullPolicy Image pull policy
image:
repository: public.ecr.aws/mural/hue
- tag: v0.12.35-hotfix.2
+ tag: v0.12.38
pullPolicy: IfNotPresent
## @param hue.resources.requests.cpu hue controller deployment's cpu request
## @param hue.resources.requests.memory hue controller deployment's memory request
@@ -3661,7 +3763,7 @@ hue:
enabled: true
image:
repository: public.ecr.aws/mural/hue-definitions
- tag: v0.12.35-hotfix.2
+ tag: v0.12.38
pullPolicy: IfNotPresent
pullSecrets: []
job:
@@ -4837,6 +4939,8 @@ traefik:
# -- Name of `Secret` with key 'token' set to a valid license token.
# It enables API Gateway.
token: ""
+ # -- Mount path for token secret.
+ tokenMountPath: "/etc/secrets"
# -- Disables all external network connections.
offline: # @schema type:[boolean, null]
# -- By default, Traefik Hub provider watches all namespaces. When using `rbac.namespaced`, it will watch helm release namespace and namespaces listed in this array.
@@ -5037,7 +5141,7 @@ zot:
repository: us-docker.pkg.dev/palette-images-fips/palette/spectro-zot-bcfips/zot
pullPolicy: IfNotPresent
# Overrides the image tag whose default is the chart appVersion.
- tag: "v2.1.10"
+ tag: "v2.1.20"
# Defaults to the release namespace if not specified
namespace: ""
serviceAccount:
@@ -5108,6 +5212,80 @@ zot:
domainProxy:
enabled: false
annotations: {}
+ # -- HTTPRoute configuration for Gateway API (alternative to Ingress). Only enable this if you have Gateway API CRDs installed and a Gateway controller.
+ httproute:
+ # -- Enable HTTPRoute resource creation instead of (or in addition to) Ingress.
+ enabled: false
+ # -- Annotations to add to the HTTPRoute resource.
+ annotations: {}
+ # -- Labels to add to the HTTPRoute resource.
+ labels: {}
+ # -- Gateway references that the HTTPRoute attaches to. At least one parentRef is required when HTTPRoute is enabled.
+ parentRefs: []
+ # Example parentRefs configuration:
+ # - name: my-gateway
+ # namespace: gateway-system
+ # sectionName: https # Optional: specific listener on the gateway
+ # -- Hostnames to match for this HTTPRoute.
+ hostnames: []
+ # Example:
+ # - "zot.example.com"
+ # - "registry.example.com"
+ # -- Path matching type (PathPrefix, Exact, or RegularExpression).
+ pathType: PathPrefix
+ # -- Path to match when custom rules are not specified.
+ path: /
+ # -- Advanced routing rules (optional). If not specified, a default rule matching the path will be created.
+ # Note: Any backendRefs in custom rules will be ignored and the zot service will always be used.
+ rules: []
+ # Example rules configuration:
+ # - matches:
+ # - path:
+ # type: PathPrefix
+ # value: /v2/
+ # filters:
+ # - type: RequestHeaderModifier
+ # requestHeaderModifier:
+ # add:
+ # - name: X-Custom-Header
+ # value: custom-value
+ # -- ListenerSet configuration for Gateway API. Use this to manage listeners
+ # (ports/protocols/TLS) independently from the Gateway resource.
+ # The parent Gateway must allow ListenerSet attachment via allowedListeners.
+ # Requires Gateway API CRDs with ListenerSet support (gateway.networking.k8s.io/v1 ListenerSet).
+ listenerset:
+ # -- Enable ListenerSet resource creation.
+ enabled: false
+ # -- Annotations to add to the ListenerSet resource.
+ # You may use annotations compatible with your certificate management stack.
+ annotations: {}
+ # Example annotation:
+ # cert-manager.io/cluster-issuer: letsencrypt-prod
+ # -- Labels to add to the ListenerSet resource.
+ labels: {}
+ # -- Parent Gateway reference that this ListenerSet attaches to.
+ parentRef:
+ # -- Name of the parent Gateway. Required when ListenerSet is enabled.
+ name: ""
+ # -- Namespace of the parent Gateway. Defaults to the same namespace if not set.
+ namespace: ""
+ # -- Group of the parent Gateway resource.
+ group: "gateway.networking.k8s.io"
+ # -- Kind of the parent resource.
+ kind: "Gateway"
+ # -- List of listeners to configure on the parent Gateway.
+ # At least one listener is required when ListenerSet is enabled.
+ listeners: []
+ # Example listeners configuration:
+ # - name: https
+ # port: 443
+ # protocol: HTTPS
+ # hostname: "zot.example.com"
+ # tls:
+ # mode: Terminate
+ # certificateRefs:
+ # - kind: Secret
+ # name: zot-tls-cert
# By default, Kubernetes HTTP probes use HTTP 'scheme'. So if TLS is enabled
# in configuration, to prevent failures, the scheme must be set to 'HTTPS'.
httpGet:
@@ -5136,7 +5314,7 @@ zot:
"extensions": {"search": {"enable": true}, "ui": {"enable": false}},
"log": { "level": "debug" }
}
- # Alternatively, the configuration can include authentication and acessControl
+ # Alternatively, the configuration can include authentication and accessControl
# data and we can use mountSecret option for the passwords.
#
# config.json: |-
@@ -5202,12 +5380,19 @@ zot:
persistence: true
# PVC data, only used if persistence is 'true'
pvc:
- # Make the chart create the PVC, this option is used with storageClasses that
- # can create volumes dynamically, if that is not the case is better to do it
- # manually and set create to false
+ # When true, the StatefulSet uses volumeClaimTemplates to dynamically provision
+ # PVCs. Kubernetes names the resulting PVCs as:
+ # <vctName>-<fullname>-<ordinal>
+ # where <fullname> is the StatefulSet name (typically <release>-zot).
+ # For example, with release "my-release" and default pvc.name:
+ # my-release-pvc-my-release-zot-0
+ # When false, an existing PVC is mounted via volumes instead — set 'name' to the
+ # exact name of the pre-existing PVC. Note: all replicas will share that single
+ # PVC, so the access mode must support it (e.g. ReadWriteMany).
create: true
- # Name of the PVC to use or create if persistence is enabled, if not set the
- # value '$CHART_RELEASE-pvc' is used
+ # When create is true, this is the volumeClaimTemplate name (the <vctName> part
+ # above). When create is false, this is the literal name of a pre-existing PVC.
+ # Defaults to '$CHART_RELEASE-pvc' if not set.
name: null
# Volume access mode, if using more than one replica we need
accessModes: ["ReadWriteOnce"]
@@ -5235,12 +5420,22 @@ zot:
# - name: data
# emptyDir: {}

+ # Init Containers that run before the main container starts
+ initContainers: []
+ # - name: init-config
+ # image: busybox
+ # command: ["sh", "-c", "echo initializing"]
+
# Extra Containers running alongside the main container
extraContainers: []
# - name: data
# image: busybox
# command: ["sleep", "infinity"]

+ # -- List of arbitrary Kubernetes objects deployed as part of the Helm release.
+ # Rendered through Helm `tpl` with the root context, so objects may use
+ # `.Release.Name`, `.Release.Namespace`, `.Values.*`, and chart helpers.
+ extraObjects: []
# Deployment strategy type
strategy:
# strategy.type should be set to Recreate if local storage is used
@@ -5256,6 +5451,48 @@ zot:
priorityClassName: ""
dnsConfig: {}
dnsPolicy: "ClusterFirst"
+ hostAliases: []
+ topologySpreadConstraints: []
+ # Example: spread pods across zones and nodes
+ # topologySpreadConstraints:
+ # - maxSkew: 1
+ # topologyKey: topology.kubernetes.io/zone
+ # whenUnsatisfiable: DoNotSchedule
+ # labelSelector:
+ # matchLabels:
+ # app.kubernetes.io/name: zot
+ # app.kubernetes.io/instance: $CHART_RELEASE
+ # - maxSkew: 1
+ # topologyKey: kubernetes.io/hostname
+ # whenUnsatisfiable: DoNotSchedule
+ # labelSelector:
+ # matchLabels:
+ # app.kubernetes.io/name: zot
+ # app.kubernetes.io/instance: $CHART_RELEASE
+
+ # -- PodDisruptionBudget configuration for the zot pods, to limit disruptions
+ # (e.g. node drains) so a minimum number of pods stay available. When enabled, set exactly
+ # one of `minAvailable` or `maxUnavailable`. Rendering fails if both or neither is set.
+ podDisruptionBudget:
+ # -- Enable creation of a PodDisruptionBudget for the zot pods.
+ enabled: false
+ # -- Minimum number/percentage of pods that must remain available during a
+ # disruption. Mutually exclusive with `maxUnavailable`.
+ minAvailable: null
+ # -- Maximum number/percentage of pods that can be unavailable during a
+ # disruption. Mutually exclusive with `minAvailable`.
+ maxUnavailable: null
+ # -- Node selector for pod assignment. Rendered through `tpl`, so values may
+ # contain Helm template expressions (e.g. `{{ .Values.global.pool }}`); a value
+ # with no `{{ }}` markers is emitted unchanged. Do not template untrusted input.
+ # To output a literal brace, escape it, e.g. `{{ "{{" }}`.
+ nodeSelector: {}
+ # -- Affinity rules for pod assignment. Also rendered through `tpl` (same
+ # escaping / untrusted-input note as nodeSelector above).
+ affinity: {}
+ # -- Tolerations for pod assignment. Also rendered through `tpl` (same
+ # escaping / untrusted-input note as nodeSelector above).
+ tolerations: []
# Metrics configuration
# NOTE: need enable metric extension in config.json
metrics:

Full Component Release Notes​

The following table lists all changes made to core components in this PaletteAI release.

Per-component changes in 1.4.0
ComponentTagNotes
brushbrush/v0.5.30
Dependency Updates
  • deps: update brush - other go dependencies (brush)
  • deps: update ginkgo (ginkgo)
brushbrush/v0.5.31
Bug Fixes
  • deps: bump palette-sdk to unblock builds/releases
  • deps: fix devspace build issues
  • hue: guard imported envRef pointer derefs after v1beta1 API change
Other
  • main: reorder make reviewable more sensibly
  • main: wire modernize into make reviewable
Performance
  • brush: scope brush informers to only relevant resources to reduce memory use
Dependency Updates
  • deps: update all non-major dependencies
  • deps: update brush - other go dependencies (brush)
  • deps: update ginkgo to v2.32.2 (ginkgo)
  • deps: update kubernetes packages (kubernetes)
  • deps: update kubernetes packages (kubernetes)
brushbrush/v0.5.32
Dependency Updates
  • deps: update module github.com/fluxcd/pkg/apis/meta to v1.32.0 (brush)
brushbrush/v0.5.33
Dependency Updates
  • deps: update ginkgo (ginkgo)
  • deps: update module sigs.k8s.io/controller-runtime to v0.25.1 (kubernetes)
brushbrush/v0.5.34
Bug Fixes
  • main: unblock local-module image builds and workspace reviewable
Dependency Updates
  • deps: update module github.com/onsi/gomega to v1.44.0 (ginkgo)
canvascanvas/v0.6.27
Features
  • canvas: automate SOT batch PAD-3812 (CMP-037)
  • canvas: automate SOT batch PAD-3813 (CMP-038)
  • canvas: automate SOT batch PAD-3814 (CMP-041)
  • canvas: automate SOT batch PAD-3829 (LA-006)
  • canvas: automate SOT batch PAD-3830 (LA-007)
  • canvas: enforce RBAC on workload profile mutations
Bug Fixes
  • canvas: add default suffix to default nic in dropdown
  • canvas: add table filters to select profile bundle drawer
  • canvas: align Network Isolation UI gates with RBAC
  • canvas: defer MIG profile validation in deployment wizards
  • canvas: derive shared-with column labels from resource namespace
  • canvas: enforce project create RBAC
  • canvas: enforce project patch RBAC on 4 project-settings intents
  • canvas: enforce RBAC on inference quota create/edit
  • canvas: enforce server-side RBAC for definition saves
  • canvas: fix button label for Add Model Quota
  • canvas: let tables size to their content instead of forcing fixed-height shells
  • canvas: redirect to login when an expired session swallows the quota save redirect
  • canvas: seed Project networkIsolationEnforced in inline NI e2e mock
  • canvas: truncate long status condition messages with ellipsis
  • canvas: truncate long workload profile layer labels and align layer card layout
canvascanvas/v0.6.28
Features
  • canvas: AI VM compute pool create wizard day 1
  • canvas: automate SOT batch (CMP-042)
  • canvas: automate SOT batch (CMP-043)
  • canvas: automate SOT batch (CMP-044)
  • canvas: automate SOT batch PAD-3846 (LA-009)
  • canvas: automate SOT batch PAD-3849 (MD-033)
  • canvas: automate SOT batch PAD-3850 (MD-047)
  • canvas: automate SOT batch PAD-3851 (MD-048)
  • canvas: automate SOT batch PAD-3857 (PB-006, PB-007)
  • canvas: automate SOT batch PAD-3858 (PB-008)
  • canvas: automate SOT batch PAD-3866 (PO-005, PO-006, PO-007)
  • canvas: automate SOT batch PAD-3879 (WP-007)
  • canvas: automate SOT batch PAD-3880 (QUOTA-026, QUOTA-027)
  • canvas: automate SOT batch PAD-3881 (QUOTA-028, QUOTA-029, QUOTA-030)
  • canvas: automate SOT batch PAD-3910 (QUOTA-031, QUOTA-032)
  • canvas: automate SOT batch PAD-3911 (QUOTA-033)
  • canvas: automate SOT batch PAD-3924 (APIKEY-017)
  • canvas: automate SOT batch PAD-3925 (APIKEY-018)
  • canvas: automate SOT batch PAD-3926 (SS-008)
  • canvas: automate SOT batch SS-006 system admin profile bundle import
  • canvas: automate SOT batch SS-010 tenant admin 403
  • canvas: automate SOT system model deployment SS-003
  • canvas: publish Playwright demo videos to PR and S3
  • hue,canvas: validate AIWorkload name for inline ComputePool limits
Bug Fixes
  • canvas: address project-create RBAC review followups
  • canvas: align Profile Bundle layer colors with Workload Profile builder
  • canvas: block empty workload profile save and dry-run
  • canvas: block project creation on Palette tenant mismatch before provisioning
  • canvas: bounce expired sessions to login instead of Request failed
  • canvas: discover all served API versions for RBAC catalog
  • canvas: enforce Kubernetes label value length limit on profile and bundle names
  • canvas: enhance workload profile variable resolution and add tests
  • canvas: fade out the modal backdrop so a closed dialog releases the page
  • canvas: fetch system-scoped HF/NVIDIA secrets with K8sResourceClient
  • canvas: Fix Model ACL allow empty allow list and make integration enabled false
  • canvas: forward accessible labels through Fields.Number and Fields.Select
  • canvas: give Fields.Number an accessible name
  • canvas: keep expired bounce on login
  • canvas: list Aviz integrations from effectiveSettings
  • canvas: log Palette health-check failure once per endpoint
  • canvas: move cluster profile layer helpers out of the PBM route
  • canvas: normalize v-prefix when matching componentDefinition revisions
  • canvas: order cluster profile layers to match Palette in profile bundle manager
  • canvas: preserve Day-2 PBM draft after failed save
  • canvas: prevent long pai versions from overflowing
  • canvas: Project profile bundles not showing in day 2 profile bundle manager
  • canvas: read PBM select value text instead of trigger label
  • canvas: recreate admission webhooks on mock-crs.sh enable
  • canvas: repair mock fixtures broken by the PAD-3164 unskip
  • canvas: require unique worker pool names in compute config wizard
  • canvas: resolve single-tenant post-login redirect building [object Object]
  • canvas: retry the mouse helper through a mid-action remount
  • canvas: stop racing smooth-scroll animation in Playwright mouse helper
  • canvas: stop the Scope column scroll flake in the profile bundle drawer
  • canvas: target the correct Settings CR for Network Isolation integration CRUD
  • canvas: Use Effective settings for Model deployment instead of spec
  • canvas: use SameSite=Lax for auth cookies so cross-site IdP logins complete
  • canvas: warn before disabling backend via stale-model-refs scenario
  • canvas: wlp overview stuck loading after create
  • ci: Route53 OIDC deploy + parallel optimized E2E Playwright dispatch
Other
  • canvas: add Storybook for the shared component library
  • canvas: clean up Playwright Gherkin tags and add label audit skill
  • mural: skip Dex approval screen in local dev environments
Docs
  • rfc: restructure RFCs into per-RFC folders with README.md
Dependency Updates
  • deps: update all non-major dependencies
Refactoring
  • canvas: resolve every CRD through the unioned component resource maps
  • canvas: share the scope-to-namespace rule and declare the AI VM UI flag
  • canvas: Unify compute pool step
canvascanvas/v0.6.29
Features
  • canvas: add AI VM resources section to compute pool overview
  • canvas: add the AI Virtual Machine detail page behind the day-2 flag
  • canvas: compute pool Day 2 read-only AI VM limits and delete flow
  • canvas: spoke ownership model
Bug Fixes
  • canvas,hue: grant tenant admins read access to mural-system definitions, remove invalid systemK8sClient usage
  • canvas: guard splitInterval against non-<num><unit> interval strings
  • canvas: match the built-in VmTemplate managed-by label key
  • canvas: read VmTemplate as the vendored CRD actually declares it
  • canvas: resolve mapped profile bundle outside deploymentNamespace
  • canvas: show Update Blocked when required profile bundle variables are missing
Other
  • canvas: add clean-tunnel make target to stop leftover ngrok tunnels
  • canvas: add local Vault to canvas dev envs
  • canvas: Add padding in VM listing page
Refactoring
  • canvas: clarify K8sClient vs K8sResourceClient layering
canvascanvas/v0.6.30
Features
  • canvas: apply the AI VM on the template step and commit it through per-VM Secrets
  • canvas: limit AI VM create to dedicated pools
  • canvas: list the VMO bundle as built-in and show AI VMs on overview
  • canvas: remove singleNodeCluster toggle and Add GPU related fields into Control Plane Pool
Bug Fixes
  • canvas: add sharing spec without opening drawer
  • canvas: align AI VM list, create, and day-2 with UX feedback
  • canvas: allow scopes to see all AIVMs that are created within them
  • canvas: centralize composite version unpack in profile builder
  • canvas: close AI VM list defects and gate list mutations
  • canvas: disable scaling policy when worker pool count is zero
  • canvas: hold AI VM Validate back until the manifest is rendered
  • canvas: keep VM override unit selectors inside their cells
  • canvas: keep worker resource groups when single node is toggled
  • canvas: require worker pool minWorkerNodes to be at least 1
  • canvas: show a GPU memory bar when a pool has no GPUs
  • canvas: single node cluster ui fixes
  • canvas: tighten AI VM header, wizard, and pool cards
  • canvas: use the compute pool AI VM icon in nav and header
Docs
  • main: add AI Virtual Machines docs
curatorcurator/v0.0.8
Dependency Updates
  • deps: update ginkgo (ginkgo)
curatorcurator/v0.0.9
Features
  • hue,curator: spoke-ownership mutex for MIG/day-2/autoscaling
Bug Fixes
  • deps: fix devspace build issues
  • hue: guard imported envRef pointer derefs after v1beta1 API change
Other
  • main: wire modernize into make reviewable
Dependency Updates
  • deps: update all non-major dependencies
  • deps: update all non-major dependencies
  • deps: update ginkgo to v2.32.2 (ginkgo)
  • deps: update kubernetes packages (kubernetes)
  • deps: update kubernetes packages (kubernetes)
curatorcurator/v0.0.10
Dependency Updates
  • deps: update ginkgo (ginkgo)
  • deps: update module sigs.k8s.io/controller-runtime to v0.25.1 (kubernetes)
curatorcurator/v0.0.11
Bug Fixes
  • main: unblock local-module image builds and workspace reviewable
Dependency Updates
  • deps: update module github.com/onsi/gomega to v1.44.0 (ginkgo)
frisketfrisket/v0.1.6
Bug Fixes
  • frisket: resolve Compute Settings for net-iso tag sync
Other
  • frisket: remove all net-iso-* tag functionality by disabling friskets compute controller
  • release: add frisket Dockerfile.local and use for hotfix builds
frisketfrisket/v0.1.7
Features
  • frisket: mirror remaining AvizTenant API data into CRD status (PAD-3855)
  • frisket: resolve Aviz credentials from Settings effectiveSettings
Bug Fixes
  • deps: bump palette-sdk to unblock builds/releases
  • hue: guard imported envRef pointer derefs after v1beta1 API change
Other
  • main: wire modernize into make reviewable
Dependency Updates
  • deps: update all non-major dependencies
  • deps: update github.com/spectrocloud/palette-sdk-go digest to 3c896dd
  • deps: update kubernetes packages (kubernetes)
  • deps: update kubernetes packages (kubernetes)
frisketfrisket/v0.1.8
Dependency Updates
  • deps: update github.com/spectrocloud/palette-sdk-go digest to 8fdb86e
frisketfrisket/v0.1.9
Dependency Updates
  • deps: update module sigs.k8s.io/controller-runtime to v0.25.1 (kubernetes)
frisketfrisket/v0.1.10
Features
  • frisket/apis: add NetworkFabric CRD
  • frisket: add fabrics controller to inventory Aviz fabrics
Bug Fixes
  • main: unblock local-module image builds and workspace reviewable
huehue/v0.12.35
Features
  • hue: allow using local packs in mirror; add continue-on-error flag
Bug Fixes
  • hue: clear Deleting hosts when Palette machine pool is not found (PAD-3639)
  • hue: distinguish HelmRelease Ready=False from Ready=Unknown
  • hue: drain and delete worker pools when enabling single-node cluster on Day 2 (PAD-3615)
  • hue: drop ProfileBundle finalizer when namespace terminating and Settings gone (PAD-3761)
  • hue: isolate GOMODCACHE in verify-definition-versions
  • hue: keep Initial hosts valid during Palette lag
Docs
  • main: document PAIL integration
Dependency Updates
  • deps: update ginkgo (ginkgo)
  • deps: update hue - go core packages (hue go-core)
huehue/v0.12.36
Features
  • hue,canvas: validate AIWorkload name for inline ComputePool limits
  • hue,curator: spoke-ownership mutex for MIG/day-2/autoscaling
  • hue: add "the APIService is Available within Ns" paitest health step
  • hue: add NOOP AIVirtualMachine controller and webhook scaffolding
  • hue: add single-node-clusters-migration
  • hue: add strict-workload-phases guard for Failed phase writes
  • hue: auto-resolve default NIC for hosts tagged palette.ai/use-default-nic
  • hue: Aviz cascade union + ComputePool NI integration check (PAD-3823)
  • hue: compute pool support for detecting aivms
  • hue: inject Zot registry variables into system-scoped VariableSet
  • hue: propagate Zot CA secret into workload namespaces on spokes
  • hue: seed built-in VmTemplates via definitions installer
  • hue: support labels in profile bundles
  • hue: watch Zot registry secrets to refresh injected system variables
  • hue: withhold sub-scope Aviz integrations; honor avizTenantNamespace
Bug Fixes
  • ci: Route53 OIDC deploy + parallel optimized E2E Playwright dispatch
  • deps: bump palette-sdk to unblock builds/releases
  • deps: fix devspace build issues
  • hue,hue/apis: allow deny-all model repository ACL in admission webhook
  • hue/apis: swap to partial resource ref for VmTemplate
  • hue: add pre-migration cleanup for effectiveAviz
  • hue: consider negative-score machines in pool selection
  • hue: defer ProfileBundle cross-scope ClusterProfile sync to a follow-up reconcile
  • hue: federate system definitions to lower-scope spokes for shared ProfileBundles
  • hue: guard imported envRef pointer derefs after v1beta1 API change
  • hue: order Settings teardown behind dependent ProfileBundle finalization
  • hue: populate ComputePool AIWorkloadRefs early in reconcile chain
  • hue: propagate cluster profile variable deletions (restore defaults); add test coverage for variable updates
  • hue: read VMO URL from WorkloadDeployment def outs
  • hue: signpost force-delete escape hatch for stuck ComputePool GC
  • hue: sweep stale ProfileBundle finalizers off snapshot ConfigMaps on delete
  • hue: tolerate ProfileBundle latest gaining an unconfigured WorkloadProfile
  • hue: treat malformed pack YAML as permanent pack rejection
  • main: hue devspace audit logging creds
Other
  • hue: bump paletteai-profilebundles to v1.7.1
  • hue: bump profile bundles to v1.7.2
  • hue: bump profile bundles to v1.7.3
  • hue: bump profile bundles to v1.7.4
  • hue: store VMO url in ComputePool status for infra-kind: vm pools
  • main: reorder make reviewable more sensibly
  • main: wire modernize into make reviewable
Docs
  • main: admission-time AIWorkload name validation for inline Compute Pools
  • rfc: restructure RFCs into per-RFC folders with README.md
Performance
  • hue: hold ProfileBundle revision write lock only for the revision create window
Dependency Updates
  • deps: update all non-major dependencies
  • deps: update ginkgo to v2.32.2 (ginkgo)
  • deps: update github.com/google/go-containerregistry/pkg/authn/k8schain digest to 0c8bedb (kubernetes)
  • deps: update kubernetes packages (kubernetes)
  • deps: update kubernetes packages (kubernetes)
  • deps: update module golang.org/x/time to v0.16.0 (hue go-core)
Refactoring
  • hue: infer singleNodeClusters and include controlPlanePool GPU requirements
  • hue: infer singleNodeClusters and include controlPlanePool GPU requirements
huehue/v0.12.37
Features
  • hue: AIVirtualMachines and VmTemplates RBAC
  • hue: default spoke klusterlet feature gates to hue's set
  • hue: render VirtualMachine in AIVM controller
  • hue: validate and provision the committed AIVM
Bug Fixes
  • canvas,hue: grant tenant admins read access to mural-system definitions, remove invalid systemK8sClient usage
  • hue: read new golden template name and bump 2204 to 22-04 references
  • hue: stop VirtualMachine generation churn and the spurious reset banner
Dependency Updates
  • deps: update ginkgo (ginkgo)
  • deps: update module google.golang.org/grpc to v1.84.0 (hue go-core)
  • deps: update module helm.sh/helm/v3 to v3.22.0
  • deps: update module sigs.k8s.io/controller-runtime to v0.25.1 (kubernetes)
Refactoring
  • canvas: clarify K8sClient vs K8sResourceClient layering
huehue/v0.12.38
Features
  • canvas: apply the AI VM on the template step and commit it through per-VM Secrets
  • canvas: limit AI VM create to dedicated pools
  • hue: inject Zot secret-name variables into the system VariableSet
Bug Fixes
  • hue: account for AI virtual machines in compute pool VM capacity
  • hue: hash namespace in topology resource name to fit OCM label cap
  • hue: reject ambiguous definition output macros instead of misrouting
  • hue: unify memory parsing and stop corrupting capacity totals
Other
  • hue: bump profile bundles to v1.7.6
  • main: bump profilebundles to v1.7.7
Dependency Updates
  • deps: update module github.com/onsi/gomega to v1.44.0 (ginkgo)
mural-crdsmural-crds/v0.7.23
Bug Fixes
  • hue/apis: use string for Expires column in iapikey
mural-crdsmural-crds/v0.7.24
Features
  • curator/apis: add spoke ownership types
  • frisket/apis: add remaining AvizTenant API data to status (PAD-3855)
  • hue-apis: expose []EffectiveAviz; remove Aviz lock (PAD-3823)
  • hue/apis: add AIVirtualMachine types
  • hue/apis: allowIntegrationsForSubScopes, NI integration status, avizTenantScope
  • hue/apis: enforce mutex for imported spoke/envref; make envref optional
  • hue/apis: update computepool crd with vm capability types
  • hue: seed built-in VmTemplates via definitions installer
  • main: vendor KubeVirt VirtualMachine CRD schema on the hub
  • mural-crds: vendor VmTemplate CRD
Bug Fixes
  • hue,hue/apis: allow deny-all model repository ACL in admission webhook
  • hue/apis: nvidia and hf model settings enabled by default
  • hue/apis: swap to partial resource ref for VmTemplate
  • hue/apis: update vm state and printcolumns
  • hue/apis: update vmlimits to be per machine pool
Dependency Updates
  • deps: update flux (flux)
  • deps: update kubernetes packages (kubernetes)
  • deps: update kubernetes packages (kubernetes)
Refactoring
  • hue/apis: rm SingleNodeCluster field from ComputePool CRD
mural-crdsmural-crds/v0.7.25
Features
  • hue: default spoke klusterlet feature gates to hue's set
  • hue: render VirtualMachine in AIVM controller
  • hue: validate and provision the committed AIVM
Bug Fixes
  • mural-crds: compare release secret size against the Kubernetes 1MiB cap
Other
  • mural-crds: add tests for mural-crds chart
mural-crdsmural-crds/v0.7.26
Features
  • frisket/apis: add NetworkFabric CRD
  • frisket: add fabrics controller to inventory Aviz fabrics