feat(container): update image ghcr.io/home-operations/charts-mirror/longhorn ( 1.12.1 → 1.13.0 ) - #3700
Open
bot-solo[bot] wants to merge 1 commit into
Open
feat(container): update image ghcr.io/home-operations/charts-mirror/longhorn ( 1.12.1 → 1.13.0 )#3700bot-solo[bot] wants to merge 1 commit into
bot-solo[bot] wants to merge 1 commit into
Conversation
…onghorn ( 1.12.1 → 1.13.0 )
Contributor
Author
@@ spec.ref.tag @@
# source.toolkit.fluxcd.io/v1/OCIRepository/longhorn-system/longhorn
! ± value change
- 1.12.1
+ 1.13.0
@@ spec.ingress @@
# networking.k8s.io/v1/NetworkPolicy/longhorn-system/instance-manager
! + one list entry added:
+ - ports:
+ - port: 3260
+ protocol: TCP
@@ rules @@
# rbac.authorization.k8s.io/v1/ClusterRole/longhorn-role
! - one list entry removed:
- - resources:
- - volumes
- - volumes/status
- - enginefrontends
- - enginefrontends/status
- - engines
- - engines/status
- - replicas
- - replicas/status
- - settings
- - settings/status
- - engineimages
- - engineimages/status
- - nodes
- - nodes/status
- - instancemanagers
- - instancemanagers/status
- - sharemanagers
- - sharemanagers/status
- - backingimages
- - backingimages/status
- - backingimagemanagers
- - backingimagemanagers/status
- - backingimagedatasources
- - backingimagedatasources/status
- - backuptargets
- - backuptargets/status
- - backupvolumes
- - backupvolumes/status
- - backups
- - backups/status
- - recurringjobs
- - recurringjobs/status
- - orphans
- - orphans/status
- - snapshots
- - snapshots/status
- - supportbundles
- - supportbundles/status
- - systembackups
- - systembackups/status
- - systemrestores
- - systemrestores/status
- - volumeattachments
- - volumeattachments/status
- - backupbackingimages
- - backupbackingimages/status
- - shards
- - shards/status
- - shardgroups
- - shardgroups/status
- apiGroups:
- - longhorn.io
- verbs:
- - "*"
! + two list entries added:
+ - resources:
+ - volumegroupsnapshotclasses
+ - volumegroupsnapshots
+ - volumegroupsnapshotcontents
+ - volumegroupsnapshotcontents/status
+ apiGroups:
+ - groupsnapshot.storage.k8s.io
+ verbs:
+ - "*"
+ - resources:
+ - volumes
+ - volumes/status
+ - enginefrontends
+ - enginefrontends/status
+ - engines
+ - engines/status
+ - replicas
+ - replicas/status
+ - settings
+ - settings/status
+ - engineimages
+ - engineimages/status
+ - nodes
+ - nodes/status
+ - instancemanagers
+ - instancemanagers/status
+ - sharemanagers
+ - sharemanagers/status
+ - backingimages
+ - backingimages/status
+ - backingimagemanagers
+ - backingimagemanagers/status
+ - backingimagedatasources
+ - backingimagedatasources/status
+ - backuptargets
+ - backuptargets/status
+ - backupvolumes
+ - backupvolumes/status
+ - backups
+ - backups/status
+ - recurringjobs
+ - recurringjobs/status
+ - orphans
+ - orphans/status
+ - snapshots
+ - snapshots/status
+ - supportbundles
+ - supportbundles/status
+ - systembackups
+ - systembackups/status
+ - systemrestores
+ - systemrestores/status
+ - volumeattachments
+ - volumeattachments/status
+ - backupbackingimages
+ - backupbackingimages/status
+ - shards
+ - shards/status
+ - shardgroups
+ - shardgroups/status
+ - snapshotgroups
+ - snapshotgroups/status
+ - instancemanagerupgrades
+ - instancemanagerupgrades/status
+ - instancemanagerupgradecontrols
+ - instancemanagerupgradecontrols/status
+ apiGroups:
+ - longhorn.io
+ verbs:
+ - "*"
@@ spec.template.spec.containers.longhorn-manager.command @@
# apps/v1/DaemonSet/longhorn-system/longhorn-manager
! - six list entries removed:
- - "docker.io/longhornio/longhorn-engine:v1.12.1"
- - "docker.io/longhornio/longhorn-instance-manager:v1.12.1"
- - "docker.io/longhornio/longhorn-share-manager:v1.12.1"
- - "docker.io/longhornio/backing-image-manager:v1.12.1"
- - "docker.io/longhornio/support-bundle-kit:v0.0.92"
- - "docker.io/longhornio/longhorn-manager:v1.12.1"
! + six list entries added:
+ - "docker.io/longhornio/longhorn-engine:v1.13.0"
+ - "docker.io/longhornio/longhorn-instance-manager:v1.13.0"
+ - "docker.io/longhornio/longhorn-share-manager:v1.13.0"
+ - "docker.io/longhornio/backing-image-manager:v1.13.0"
+ - "docker.io/longhornio/support-bundle-kit:v0.0.98"
+ - "docker.io/longhornio/longhorn-manager:v1.13.0"
@@ spec.template.spec.containers.longhorn-manager.image @@
# apps/v1/DaemonSet/longhorn-system/longhorn-manager
! ± value change
- docker.io/longhornio/longhorn-manager:v1.12.1
+ docker.io/longhornio/longhorn-manager:v1.13.0
@@ spec.template.spec.containers.pre-pull-share-manager-image.image @@
# apps/v1/DaemonSet/longhorn-system/longhorn-manager
! ± value change
- docker.io/longhornio/longhorn-share-manager:v1.12.1
+ docker.io/longhornio/longhorn-share-manager:v1.13.0
@@ spec.template.spec.containers.longhorn-driver-deployer.command @@
# apps/v1/Deployment/longhorn-system/longhorn-driver-deployer
! - one list entry removed:
- - "docker.io/longhornio/longhorn-manager:v1.12.1"
! + one list entry added:
+ - "docker.io/longhornio/longhorn-manager:v1.13.0"
@@ spec.template.spec.containers.longhorn-driver-deployer.env.CSI_ATTACHER_IMAGE.value @@
# apps/v1/Deployment/longhorn-system/longhorn-driver-deployer
! ± value change
- docker.io/longhornio/csi-attacher:v4.12.0
+ docker.io/longhornio/csi-attacher:v4.13.0
@@ spec.template.spec.containers.longhorn-driver-deployer.env.CSI_PROVISIONER_IMAGE.value @@
# apps/v1/Deployment/longhorn-system/longhorn-driver-deployer
! ± value change
- docker.io/longhornio/csi-provisioner:v5.3.0
+ docker.io/longhornio/csi-provisioner:v6.3.0
@@ spec.template.spec.containers.longhorn-driver-deployer.env.CSI_NODE_DRIVER_REGISTRAR_IMAGE.value @@
# apps/v1/Deployment/longhorn-system/longhorn-driver-deployer
! ± value change
- docker.io/longhornio/csi-node-driver-registrar:v2.17.0
+ docker.io/longhornio/csi-node-driver-registrar:v2.18.0
@@ spec.template.spec.containers.longhorn-driver-deployer.env.CSI_LIVENESS_PROBE_IMAGE.value @@
# apps/v1/Deployment/longhorn-system/longhorn-driver-deployer
! ± value change
- docker.io/longhornio/livenessprobe:v2.19.0
+ docker.io/longhornio/livenessprobe:v2.20.0
@@ spec.template.spec.containers.longhorn-driver-deployer.image @@
# apps/v1/Deployment/longhorn-system/longhorn-driver-deployer
! ± value change
- docker.io/longhornio/longhorn-manager:v1.12.1
+ docker.io/longhornio/longhorn-manager:v1.13.0
@@ spec.template.spec.initContainers.wait-longhorn-manager.image @@
# apps/v1/Deployment/longhorn-system/longhorn-driver-deployer
! ± value change
- docker.io/longhornio/longhorn-manager:v1.12.1
+ docker.io/longhornio/longhorn-manager:v1.13.0
@@ spec.template.spec.containers.longhorn-ui.image @@
# apps/v1/Deployment/longhorn-system/longhorn-ui
! ± value change
- docker.io/longhornio/longhorn-ui:v1.12.1
+ docker.io/longhornio/longhorn-ui:v1.13.0
@@ spec.template.spec.containers.longhorn-post-upgrade.image @@
# batch/v1/Job/longhorn-system/longhorn-post-upgrade
! ± value change
- docker.io/longhornio/longhorn-manager:v1.12.1
+ docker.io/longhornio/longhorn-manager:v1.13.0
@@ spec.template.spec.containers.longhorn-pre-upgrade.image @@
# batch/v1/Job/longhorn-system/longhorn-pre-upgrade
! ± value change
- docker.io/longhornio/longhorn-manager:v1.12.1
+ docker.io/longhornio/longhorn-manager:v1.13.0
@@ spec.template.spec.containers.longhorn-uninstall.image @@
# batch/v1/Job/longhorn-system/longhorn-uninstall
! ± value change
- docker.io/longhornio/longhorn-manager:v1.12.1
+ docker.io/longhornio/longhorn-manager:v1.13.0
@@ (root level) @@
# v1/ServiceAccount/longhorn-system/longhorn-csi-service-account
! + one document added:
+ apiVersion: v1
+ kind: ServiceAccount
+ metadata:
+ name: longhorn-csi-service-account
+ namespace: longhorn-system
+ labels:
+ app.kubernetes.io/instance: longhorn
+ app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: longhorn
+ helm.toolkit.fluxcd.io/name: longhorn
+ helm.toolkit.fluxcd.io/namespace: longhorn-system
@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRole/longhorn-csi-role
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRole
+ metadata:
+ name: longhorn-csi-role
+ labels:
+ app.kubernetes.io/instance: longhorn
+ app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: longhorn
+ helm.toolkit.fluxcd.io/name: longhorn
+ helm.toolkit.fluxcd.io/namespace: longhorn-system
+ rules:
+ - resources:
+ - persistentvolumes
+ apiGroups:
+ -
+ verbs:
+ - get
+ - list
+ - watch
+ - create
+ - patch
+ - delete
+ - resources:
+ - persistentvolumeclaims
+ apiGroups:
+ -
+ verbs:
+ - get
+ - list
+ - watch
+ - update
+ - resources:
+ - persistentvolumeclaims/status
+ apiGroups:
+ -
+ verbs:
+ - patch
+ - resources:
+ - nodes
+ apiGroups:
+ -
+ verbs:
+ - list
+ - watch
+ - resources:
+ - events
+ apiGroups:
+ -
+ verbs:
+ - create
+ - patch
+ - resources:
+ - storageclasses
+ - csinodes
+ apiGroups:
+ - storage.k8s.io
+ verbs:
+ - list
+ - watch
+ - resources:
+ - volumeattachments
+ apiGroups:
+ - storage.k8s.io
+ verbs:
+ - list
+ - watch
+ - patch
+ - resources:
+ - volumeattachments/status
+ apiGroups:
+ - storage.k8s.io
+ verbs:
+ - patch
+ - resources:
+ - volumesnapshotclasses
+ apiGroups:
+ - snapshot.storage.k8s.io
+ verbs:
+ - list
+ - watch
+ - resources:
+ - volumesnapshots
+ apiGroups:
+ - snapshot.storage.k8s.io
+ verbs:
+ - get
+ - list
+ - watch
+ - update
+ - resources:
+ - volumesnapshotcontents
+ apiGroups:
+ - snapshot.storage.k8s.io
+ verbs:
+ - get
+ - list
+ - watch
+ - patch
+ - resources:
+ - volumesnapshotcontents/status
+ apiGroups:
+ - snapshot.storage.k8s.io
+ verbs:
+ - update
+ - patch
@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRole/longhorn-csi-secret-role
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRole
+ metadata:
+ name: longhorn-csi-secret-role
+ labels:
+ app.kubernetes.io/instance: longhorn
+ app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: longhorn
+ helm.toolkit.fluxcd.io/name: longhorn
+ helm.toolkit.fluxcd.io/namespace: longhorn-system
+ rules:
+ - resources:
+ - secrets
+ apiGroups:
+ -
+ verbs:
+ - get
@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRoleBinding/longhorn-csi-bind
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRoleBinding
+ metadata:
+ name: longhorn-csi-bind
+ labels:
+ app.kubernetes.io/instance: longhorn
+ app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: longhorn
+ helm.toolkit.fluxcd.io/name: longhorn
+ helm.toolkit.fluxcd.io/namespace: longhorn-system
+ roleRef:
+ name: longhorn-csi-role
+ apiGroup: rbac.authorization.k8s.io
+ kind: ClusterRole
+ subjects:
+ - name: longhorn-csi-service-account
+ kind: ServiceAccount
+ namespace: longhorn-system
@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRoleBinding/longhorn-csi-secret-bind
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRoleBinding
+ metadata:
+ name: longhorn-csi-secret-bind
+ labels:
+ app.kubernetes.io/instance: longhorn
+ app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: longhorn
+ helm.toolkit.fluxcd.io/name: longhorn
+ helm.toolkit.fluxcd.io/namespace: longhorn-system
+ roleRef:
+ name: longhorn-csi-secret-role
+ apiGroup: rbac.authorization.k8s.io
+ kind: ClusterRole
+ subjects:
+ - name: longhorn-csi-service-account
+ kind: ServiceAccount
+ namespace: longhorn-system
@@ (root level) @@
# rbac.authorization.k8s.io/v1/Role/longhorn-system/longhorn-csi-role
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: Role
+ metadata:
+ name: longhorn-csi-role
+ namespace: longhorn-system
+ labels:
+ app.kubernetes.io/instance: longhorn
+ app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: longhorn
+ helm.toolkit.fluxcd.io/name: longhorn
+ helm.toolkit.fluxcd.io/namespace: longhorn-system
+ rules:
+ - resources:
+ - leases
+ apiGroups:
+ - coordination.k8s.io
+ verbs:
+ - create
+ - resources:
+ - leases
+ apiGroups:
+ - coordination.k8s.io
+ resourceNames:
+ - driver-longhorn-io
+ - external-attacher-leader-driver-longhorn-io
+ - external-resizer-driver-longhorn-io
+ - external-snapshotter-leader-driver-longhorn-io
+ verbs:
+ - get
+ - update
+ - resources:
+ - csistoragecapacities
+ apiGroups:
+ - storage.k8s.io
+ verbs:
+ - list
+ - watch
+ - create
+ - update
+ - delete
+ - resources:
+ - pods
+ apiGroups:
+ -
+ verbs:
+ - get
+ - resources:
+ - replicasets
+ apiGroups:
+ - apps
+ verbs:
+ - get
@@ (root level) @@
# rbac.authorization.k8s.io/v1/RoleBinding/longhorn-system/longhorn-csi-bind
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: RoleBinding
+ metadata:
+ name: longhorn-csi-bind
+ namespace: longhorn-system
+ labels:
+ helm.toolkit.fluxcd.io/name: longhorn
+ helm.toolkit.fluxcd.io/namespace: longhorn-system
+ roleRef:
+ name: longhorn-csi-role
+ apiGroup: rbac.authorization.k8s.io
+ kind: Role
+ subjects:
+ - name: longhorn-csi-service-account
+ kind: ServiceAccount
+ namespace: longhorn-system
@@ (root level) @@
# apps/v1/Deployment/longhorn-system/longhorn-global-manager
! + one document added:
+ apiVersion: apps/v1
+ kind: Deployment
+ metadata:
+ name: longhorn-global-manager
+ namespace: longhorn-system
+ labels:
+ app: longhorn-global-manager
+ app.kubernetes.io/instance: longhorn
+ app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: longhorn
+ helm.toolkit.fluxcd.io/name: longhorn
+ helm.toolkit.fluxcd.io/namespace: longhorn-system
+ spec:
+ replicas: 3
+ selector:
+ matchLabels:
+ app: longhorn-global-manager
+ template:
+ metadata:
+ labels:
+ app: longhorn-global-manager
+ app.kubernetes.io/instance: longhorn
+ app.kubernetes.io/managed-by: Helm
+ app.kubernetes.io/name: longhorn
+ spec:
+ affinity:
+ podAntiAffinity:
+ preferredDuringSchedulingIgnoredDuringExecution:
+ - podAffinityTerm:
+ labelSelector:
+ matchExpressions:
+ - key: app
+ operator: In
+ values:
+ - longhorn-global-manager
+ topologyKey: kubernetes.io/hostname
+ weight: 1
+ containers:
+ - name: longhorn-global-manager
+ image: "docker.io/longhornio/longhorn-manager:v1.13.0"
+ imagePullPolicy: IfNotPresent
+ command:
+ - longhorn-manager
+ - "-d"
+ - global
+ livenessProbe:
+ httpGet:
+ path: /v1/healthz
+ port: 9505
+ ports:
+ - name: healthz
+ containerPort: 9505
+ readinessProbe:
+ httpGet:
+ path: /v1/healthz
+ port: 9505
+ env:
+ - name: POD_NAME
+ valueFrom:
+ fieldRef:
+ fieldPath: metadata.name
+ - name: POD_NAMESPACE
+ valueFrom:
+ fieldRef:
+ fieldPath: metadata.namespace
+ - name: LONGHORN_DISTRO
+ value: longhorn
+ priorityClassName: longhorn-critical
+ serviceAccountName: longhorn-service-account |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.12.1→1.13.0Release Notes
longhorn/longhorn (ghcr.io/home-operations/charts-mirror/longhorn)
v1.13.0: Longhorn v1.13.0Compare Source
Longhorn v1.13.0 Release Notes
The Longhorn team is excited to announce the release of Longhorn v1.13.0. This feature release brings live upgrade to the V2 Data Engine, which reached general availability in v1.12.0. V2 volumes can now stay attached while Longhorn is upgraded, as long as your cluster meets the live upgrade prerequisites.
Longhorn v1.13.0 also introduces full interrupt mode for the V2 Data Engine, volume group snapshots, age-based retention for recurring jobs, topology-constrained replica scheduling, a scheduler extender, and the
longhorn-global-managerDeployment that lowers control-plane overhead in large clusters.For terminology and background on Longhorn releases, see Releases.
Breaking Changes
Kubernetes v1.34 Minimum Version
Because the CSI external-provisioner is upgraded to v6.3.0, all clusters must be running Kubernetes v1.34 or later before installing or upgrading to Longhorn v1.13.0.
Legacy V2 Linked-Clone Volumes
Since v1.12.1, V2 linked-clone volumes created in Longhorn v1.12.0 or earlier can only be detached or deleted. To replace one, create a new linked clone from the same source volume; no data copy is required.
GitHub Issue #12552
Primary Highlights
V2 Data Engine
The V2 Data Engine became generally available in Longhorn v1.12.0. Longhorn v1.13.0 adds live upgrade and full interrupt mode, and enables CPU isolation by default for new installations.
For the expected behavior differences between V1 and V2 volumes and the feature support matrix, see V1 and V2 Volume Feature Support.
GitHub Issue #6229
Live Upgrade
Longhorn v1.13.0 supports live upgrade of V2 volumes, so the V2 instance managers can be upgraded without detaching the volumes, preventing disruption during Longhorn upgrades. For more information, see V2 Data Engine Instance Manager Upgrade.
GitHub Issue #9104
Full Interrupt Mode
In Longhorn v1.13.0, interrupt mode for the V2 Data Engine is now fully event-driven. SPDK reactors wait for I/O events instead of polling continuously, with only low-frequency background checks remaining, significantly reducing CPU usage for idle or low I/O workloads. This improves the hybrid implementation introduced in v1.10.0, which still incurred a minimal, constant CPU load when volumes were idle. As before, interrupt mode may introduce slightly higher I/O latency than polling mode under sustained high-throughput workloads.
Polling mode remains the default. To switch, set
data-engine-interrupt-mode-enabledto{"v2":"true"}while no V2 volumes are attached. For more information, see Interrupt Mode Support.GitHub Issue #11662
CPU Isolation Enabled by Default
CPU isolation keeps interrupts and other kernel background work off the CPU cores used by the V2 Data Engine. Longhorn v1.13.0 sets
data-engine-cpu-isolation-enabledto{"v2":"true"}by default for new installations; clusters upgraded from v1.12.x keep their existing value and can opt in by setting it to{"v2":"true"}. CPU isolation applies only in polling mode; Longhorn skips it automatically when interrupt mode is enabled. For more information, see Data Engine CPU Isolation Enabled.GitHub Issue #13724, GitHub Issue #13973
Fast Volume Cloning
Since v1.12.1, fast volume cloning for the V2 Data Engine has used a linked-clone architecture: a linked-clone volume shares data blocks with its source instead of copying them. One source volume can back multiple linked clones. Linked-clone volumes support most operations available to regular volumes, including snapshots, expansion, replica rebuilding, backup, and use as the source of nested linked clones. Starting with v1.13.0, V2 linked-clone volumes also support restore operations. For more information, see Volume Clone Support.
GitHub Issue #12552
Storage Sharding (Experimental)
Introduced in v1.12.1, storage sharding is an experimental V2 Data Engine feature. Instead of keeping a full copy of the volume on every replica, it splits written data into data and parity chunks and spreads them across nodes. A volume can then be larger than any single disk or node, and tolerate the same number of failures with less disk space.
Sharded volumes do not support backup and restore, volume cloning, backing images, disaster recovery (DR) volumes, or live migration. This feature is for evaluation and testing only and is not recommended for production. For more information, see Sharding with Erasure Coding.
GitHub Issue #1061
SPDK iobuf Pool Size Configuration
Introduced in v1.12.1, the
data-engine-iobuf-large-pool-sizeanddata-engine-iobuf-small-pool-sizesettings control the size of the SPDK buffer pools used by the V2 Data Engine. Larger pools help avoid running out of buffers under high-queue-depth workloads. Because the pools are sized when SPDK starts, changing either setting recreates V2 instance manager pods that have no running engines or replicas.GitHub Issue #13322, GitHub Issue #13674
Snapshots and Backups
Volume Group Snapshot Support
Longhorn v1.13.0 makes it easier to protect related volumes by letting you snapshot a group of volumes with a single request from the Longhorn UI, kubectl, or Kubernetes
VolumeGroupSnapshotobjects through CSI. The CSI path, which is disabled by default, also supports group backups.For more information, see Create a Snapshot Group and Enable CSI Volume Group Snapshot Support.
GitHub Issue #13349
Age-Based Retention for Recurring Jobs
Longhorn v1.13.0 adds an
age-basedretention policy for snapshot, backup, and system backup recurring jobs, letting you retain data based on its age instead of the number of items. SetretentionPolicytoage-basedandretainAgeto a duration such as720h; each run deletes snapshots or backups older than the specified age. Thecount-basedpolicy remains the default, and existing recurring jobs are unchanged after the upgrade.GitHub Issue #12060
Smarter Scheduling
Volume Topology Constraint
Longhorn v1.13.0 adds the
volumeTopologyStorageClass parameter (any,zonal, orregional) to keep a volume's replicas within the zone or region where it was provisioned, including during rebuilds and replica count changes, so replicas stay close to the workload. Previously, zone labels only spread replicas across zones; a rebuild could still place a replica in a different zone from the workload. For more information, see Topology-Aware Provisioning.GitHub Issue #13493
Scheduler Extender
Longhorn v1.13.0 improves pod scheduling by allowing kube-scheduler to check actual Longhorn disk capacity and, when possible, place a restarted pod on the node that already holds all of its replicas. This helps avoid scheduling decisions based on stale
CSIStorageCapacitydata during bursts of pod creation and improves data locality, especially withbest-effortdata locality. The scheduler extender runs inside longhorn-manager and requires a kube-scheduler configuration change, which is not possible on managed Kubernetes services such as GKE and EKS.GitHub Issue #12591
Better Operations
Longhorn Global Manager
Longhorn v1.13.0 reduces kube-apiserver load and longhorn-manager memory usage in large clusters by moving the cluster-wide pod and PersistentVolume controllers from the
longhorn-managerDaemonSet to a newlonghorn-global-managerDeployment. The Deployment is created with three replicas by default during installation and upgrade. Before upgrading, make sure at least one of its pods can be scheduled. For more information, see Upgrading Longhorn Manager.GitHub Issue #13059
Security Hardening
Internal Network Policies
Since v1.12.1, Longhorn creates ingress
NetworkPolicyresources for its internal components by default. They take effect only when the CNI plugin enforcesNetworkPolicy. Longhorn v1.12.2 resolves the CNI compatibility issues found in v1.12.1 and adds three Helm values:networkPolicies.v1DataEngineInitiatorSourceCIDRsandnetworkPolicies.recoveryBackendAdditionalIngressPortsallow traffic that the v1.12.1 policies blocked.networkPolicies.metricsScrapeSourceslets Prometheus and other scrapers reach longhorn-manager metrics on TCP port 9500.For more information, see Internal Network Policies.
GitHub Issue #13438, GitHub Issue #13802, GitHub Issue #13740, GitHub Issue #13947
Instance Manager gRPC mTLS Coverage
Before v1.12.1, when the
longhorn-grpc-tlssecret was configured, mutual TLS (mTLS) covered only the instance manager's instance and proxy gRPC services; the disk and SPDK services still accepted plaintext connections. Since v1.12.1, mTLS covers all instance manager gRPC services, so every gRPC port requires a valid client certificate when the secret is configured.GitHub Issue #7787, GitHub Issue #13212
Dedicated CSI Service Account
Longhorn v1.13.0 runs the CSI controller sidecars under a dedicated
longhorn-csi-service-accountinstead of the sharedlonghorn-service-account. For compatibility with existing Secret references, the new service account still receives cluster-widegetaccess to Secrets by default. You can turn this off with thecsi.allowControllerSecretAccessHelm value after removingcsi.storage.k8s.io/provisioner-secret-*parameters from Longhorn StorageClasses. For more information, see Optional Restriction of CSI Controller Secret Access.GitHub Issue #14020
Critical Stability Fixes
Linked-Clone Backup Restore
Longhorn v1.13.0 fixes a V2 linked-clone backup restore issue that could produce a corrupted volume when the source volume or the snapshot the clone was created from no longer existed. Backups of V2 linked-clone volumes now record the source volume and snapshot, and a restore fails with an error if either is missing.
GitHub Issue #13714
CSI Volume Clone with Strict-Local Data Locality
Longhorn v1.13.0 fixes a CSI volume clone issue where cloning a volume with
dataLocality: strict-localcould fail withhard affinity cannot be satisfied. Longhorn now picks a node that matches the volume'snodeSelectoranddiskSelectorfor the clone.GitHub Issue #12792
Longhorn Node Removal After Kubernetes Node Deletion
Longhorn v1.13.0 fixes a node cleanup issue where a Longhorn node could not be removed after its Kubernetes node had been deleted without eviction. You can now disable scheduling on the node, remove its remaining replicas and engines, and then delete it. Evicting a node before deleting it from the cluster is still the recommended procedure. For more information, see Graceful Node Removal.
GitHub Issue #13494
Backing Image Copies on IPv6 Clusters
Longhorn v1.13.0 fixes a backing image issue where copies were always transferred over IPv4, so on IPv6 single-stack and IPv6-first dual-stack clusters a backing image stayed at one copy. Backing images are now copied over the cluster's IP family and the storage network.
GitHub Issue #13864
Installation
You can install Longhorn using a variety of tools, including Rancher, kubectl, and Helm. For more information about installation methods and requirements, see Quick Installation in the Longhorn documentation.
Upgrade
Longhorn only allows upgrades from supported versions. For more information about upgrade paths and procedures, see Upgrade in the Longhorn documentation.
Automated pre-upgrade checks do not cover all scenarios. Before upgrading, review the manual checks in Important Notes, and for V2 volumes confirm the live upgrade prerequisites or detach them and ensure their replicas are stopped before upgrading.
Post-Release Known Issues
For information about issues identified after this release, see Release-Known-Issues.
Resolved Issues in this release
Highlight
Feature
Improvement
ignoreSigningHeadersconfigurable — SigV4Accept-Encodingbreaks every S3 backup target behind a header-rewriting proxy, not just GCS 13756 - @kinorai @roger-ryaokbenchfio numjobs to higher value 9100 - @derekbitBug
test_csi_block_volume_online_expansionfails with 'assert md5sum: == ...' on v2 volume (AMD64 only) 14045 - @derekbit @roger-ryaoDisconnect Volume Node Network For More Than Pod Eviction Timeout While Workload Heavy Writing With RWX Fast Failover Disabledfails on v2 data engine 13913 - @derekbit @shuo-wu @chriscchientest_single_replica_failed_during_engine_startfails 13861 - @davidcheng0922test_engine_image_not_fully_deployed_perform_dr_restoring_expanding_volumefails on v1.13.x-head 13974 - @shuo-wu @chriscchienContinuous IO Test13912 - @yangchiu @c3y1huangTest V2 Volume Engine Live Switchovermay fail on v1.13.x-head 13951 - @yangchiu @davidcheng0922deletingstate 13585 - @yangchiu @davidcheng0922 @sushant-suseAttachingin an IPv6 storage network environment 13933 - @yangchiu @derekbitInput/output erroron v2 volumes 13189 - @derekbit @chriscchienTest DR Volume Live Upgrade And Rebuildfails 13911 - @yangchiu @derekbitcreateDefaultDiskLabeledNodessetting andcreate-default-disklabel doesn't work with BDF 13491 - @yangchiu @davidcheng0922test_node_default_disk_labeledfails 13910 - @roger-ryaostoppedprocess record makes createInstance a silent no-op, volume stuck inattachingforever 13687 - @derekbit @roger-ryaoPower Off Replica Node Should Not Rebuild New Replica On Same Nodefails 13705 - @yangchiu @derekbitnetworkPolicies.restrictInternalTrafficsilently breaks Prometheus scraping of longhorn-manager (metrics/alerting blackout on patch upgrade) 13740 - @COLDTURNIP @roger-ryaotest_volume_scheduling_failurefails on v2 volumes 13655 - @yangchiu @c3y1huangBackup Listing With More Than 1000 Backupsfails on v2 volume due to an empty replica address in the backup status 13611 - @COLDTURNIP @chriscchienRecurring Job Pod Should Not Crashfails 13567 - @yangchiu @c3y1huangtest_rwx_delete_share_manager_podfails because it's unable to find the exported volume in share manager pod after it's deleted and restarted 13221 - @davidcheng0922 @roger-ryaotest_best_effort_data_localityfails because there is no replica for the created volume 13222 - @yangchiu @carterli0407-cellResilience
Stability
Misc
Configuration
📅 Schedule: (in timezone Europe/Berlin)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.