v2.22.0
Date of release: dd/mm/yyyy
Engine version: XX.XX
Conform version: XX.XX
Foresight version: XX.XX
Genesis version: XX.XX
New Features
We appreciate your continued support and value your feedback. If you encounter any issues or have any questions, please don't hesitate to contact our support team.
Fixes and improvements
MongoDB Operator Upgrade Notice
Starting Halo v2.22.0, in-cluster MongoDB is managed by MongoDB Controllers for Kubernetes (MCK, the mongodb-kubernetes chart) in place of the deprecated MongoDB Community Operator (community-operator). This applies only if you run MongoDB inside the cluster. Deployments backed by DocumentDB, Cosmos DB or another external MongoDB are unaffected and need no action.
If you run MongoDB inside the cluster, uninstall the Community Operator first, then install MCK. Your data is preserved if the MongoDBCommunity CRD carries the retain annotation before the uninstall.
Add the MongoDB Helm repository if you have not already:
helm repo add mongodb https://mongodb.github.io/helm-charts
helm repo update
Then, on a cluster running in-cluster MongoDB:
# Protect the data: this annotation stops the uninstall cascading to the CRD, replica set and volumes
kubectl annotate crd mongodbcommunity.mongodbcommunity.mongodb.com helm.sh/resource-policy=keep --overwrite
# Remove the old Community Operator
helm uninstall community-operator -n cdrplatform
# Install MongoDB Controllers for Kubernetes
helm install mongodb-kubernetes-operator mongodb/mongodb-kubernetes -n cdrplatform --version 1.12.0
# Redeploy the MongoDB chart (use the same cloud_provider you deployed with)
helm upgrade -i cdrplatform-mongodb cdrplatform-mongodb -n cdrplatform --atomic --set cloud_provider=<provider>
MCK adopts the existing replica set in place and rolls the MongoDB pod once. Confirm the pod is Ready and the data is intact before continuing the upgrade.
Rabbitmq Upgrade Notice
Starting Halo v2.9.0, the Rabbitmq version is upgraded from 3.13 to 4.x. When upgrading from an older version of Halo to any version above 2.9.0 all stable rabbitmq feature flags should be enabled before performing the usual upgrade process using below command -
rabbitmqctl enable_feature_flag all
ICAP Server Upgrade Notice
The ICAP server is now operated from the portal: mutual TLS moved out of the chart's configuration block and became a setting an administrator can change, and starting and stopping the server moved there too. Four things need attention when upgrading an existing ICAP install.
configuration.ENABLE_MTLS was replaced by settings.ICAP.MutualTlsEnabled. The chart fails the render on the old key, naming the replacement, rather than accepting it and ignoring it. Update any values overlay or saved helm upgrade command before upgrading:
--set settings.ICAP.MutualTlsEnabled=true
The certificate volume is now always mounted, so enabling mutual TLS no longer changes the pod specification. It still takes effect on the next ICAP server restart, because the listener binds its port at startup. While mutual TLS is off the server does not bind the TLS port at all, where earlier versions bound it and refused every connection, so a port scan of an appliance without certificates no longer reports that port as open.
The ICAP server pod now runs as its own service account, so that it can write its settings to its own ConfigMap, where it previously ran as default. Anything in the namespace bound to default — a workload-identity annotation, an image-pull secret, a NetworkPolicy or an RBAC rule naming it — has to be reapplied to the new account. Set the annotations on the new account:
--set serviceAccount.annotations.<key>=<value>
Or keep the account the install already uses:
--set serviceAccount.name=<existing-account>
The ICAP server is now started and stopped from the Portal. Open Protection settings, select the ICAP tab and use the control under ICAP configuration. The appliance ships with the ICAP server installed but not running, and nothing answers on the ICAP ports until an administrator turns it on. The ICAP settings on that tab can be changed only while the server is on.
Stop the ICAP server once after your first upgrade if you were not running it. The chart no longer fixes the number of ICAP servers, so that the Portal control keeps whatever you set across later upgrades. Upgrading a release installed from an earlier chart starts the server once as part of that change, whatever state it was in beforehand:
kubectl scale deploy icap-server -n cdrplatform --replicas=0
Only the first upgrade needs this. A freshly imaged appliance is unaffected.
Deprecation notice
Please note cdrplatform-metrics-collation service is deprecated and removed from release 2.6.2. When upgrading to 2.6.2 and any version above, please uninstall the cdrplatform-metrics-collation helm chart using below command.
helm delete cdrplatform-metrics-collation -n cdrplatform
Service Versions (Image tags)
| Service | Container Repository | Version |
|---|---|---|
| cdrplatform-engine | glasswallhub.azurecr.io/cdrplatform-engine | 2.22.0-211418 |
| cdrplatform-sync-api | glasswallhub.azurecr.io/cdrplatform-sync-api | 2.22.0-211418 |
| cdrplatform-report-extractor | glasswallhub.azurecr.io/cdrplatform-report-extractor | 2.22.0-211418 |
| cdrplatform-portal | glasswallhub.azurecr.io/cdrplatform-portal | 2.22.0-211418 |
| cdrplatform-policy-api | glasswallhub.azurecr.io/cdrplatform-policy-api | 2.22.0-211418 |
| cdrplatform-api-access | glasswallhub.azurecr.io/cdrplatform-api-access | 2.22.0-211418 |
| cdrplatform-portal-access | glasswallhub.azurecr.io/cdrplatform-portal-access | 2.22.0-211418 |
| cdrplatform-license-management | glasswallhub.azurecr.io/cdrplatform-license-management | 2.22.0-211418 |
| cdrplatform-cleanup | glasswallhub.azurecr.io/cdrplatform-cleanup | 2.22.0-211418 |
| cdrplatform-async-api | glasswallhub.azurecr.io/cdrplatform-async-api | 2.22.0-211418 |
| cdrplatform-metrics-projection | glasswallhub.azurecr.io/cdrplatform-metrics-projection | 2.22.0-211418 |
| cdrplatform-tally-accumulator | glasswallhub.azurecr.io/cdrplatform-tally-accumulator | 2.22.0-211418 |
| icap-server | glasswallhub.azurecr.io/icap-server | 2.22.0-211418 |
| cdrplatform-rabbitmq | glasswallhub.azurecr.io/cdrplatform-rabbitmq | 2.22.0-211418 |
| cdrplatform-storage-monitor | glasswallhub.azurecr.io/cdrplatform-storage-monitor | 2.22.0-211418 |
Helm Chart Versions
| Chart | Chart Repository | Version |
|---|---|---|
| cdrplatform-rabbitmq | glasswallhub.azurecr.io/helm/cdrplatform-rabbitmq | 0.9.4 |
| cdrplatform-external-secrets | glasswallhub.azurecr.io/helm/cdrplatform-external-secrets | 0.7.0 |
| cdrplatform-storage | glasswallhub.azurecr.io/helm/cdrplatform-storage | 0.8.1 |
| cdrplatform-engine | glasswallhub.azurecr.io/helm/cdrplatform-engine | 0.6.3 |
| cdrplatform-sync-api | glasswallhub.azurecr.io/helm/cdrplatform-sync-api | 0.4.3 |
| prometheus-scaling | glasswallhub.azurecr.io/helm/prometheus-scaling | 0.3.1 |
| cdrplatform-portal | glasswallhub.azurecr.io/helm/cdrplatform-portal | 0.4.3 |
| cdrplatform-policy-api | glasswallhub.azurecr.io/helm/cdrplatform-policy-api | 0.3.3 |
| cdrplatform-api-access | glasswallhub.azurecr.io/helm/cdrplatform-api-access | 1.5.0 |
| cdrplatform-portal-access | glasswallhub.azurecr.io/helm/cdrplatform-portal-access | 0.5.1 |
| cdrplatform-license-management | glasswallhub.azurecr.io/helm/cdrplatform-license-management | 0.4.0 |
| cdrplatform-cleanup | glasswallhub.azurecr.io/helm/cdrplatform-cleanup | 0.3.4 |
| cdrplatform-async-api | glasswallhub.azurecr.io/helm/cdrplatform-async-api | 0.2.4 |
| cdrplatform-metrics-projection | glasswallhub.azurecr.io/helm/cdrplatform-metrics-projection | 0.2.3 |
| cdrplatform-report-extractor | glasswallhub.azurecr.io/helm/cdrplatform-report-extractor | 0.2.2 |
| cdrplatform-tally-accumulator | glasswallhub.azurecr.io/helm/cdrplatform-tally-accumulator | 0.2.5 |
| cdrplatform-mongodb | glasswallhub.azurecr.io/helm/cdrplatform-mongodb | 0.3.1 |
| icap-server | glasswallhub.azurecr.io/helm/icap-server | 2.2.3 |
| cdrplatform-storage-monitor | glasswallhub.azurecr.io/helm/cdrplatform-storage-monitor | 0.2.5 |
Documentation
Swagger Documentation Glasswall Documentation Clean a file Archive Support License Management