Release Notes - 3.34.0¶
Please see our documentation page for more information on how to consume and deploy Big Bang. This release was primarily tested on Kubernetes 1.36 (EKS).
Upgrade Notices¶
BigBang - MR¶
Keycloak can now use either a TLS-terminated gateway or a passthrough gateway. We recommend migrating to TLS termination at Big Bangβs public gateway because this will become the default behavior in Big Bang 4.0. If the public and passthrough gateways use different addresses, update the DNS record for keycloak.<domain> to point to the public gateway.
To use Big Bangβs public gateway, clear any explicit gateway selection and remove the Keycloak certificate and key:
addons:
keycloak:
ingress:
gateway: ""
cert: ""
key: ""
When both cert and key are empty, TLS terminates at the public gateway and traffic is forwarded to Keycloak over HTTP. Supplying both values continues to configure Keycloak for TLS passthrough.
When Keycloak uses the built-in public gateway, Big Bang automatically adds an OPTIONAL_MUTUAL server for keycloak.<domain>. Big Bang also creates the corresponding <credentialName>-cacert Secret containing the bundled DoD CA chain.
Automatic CA creation is limited to an OPTIONAL_MUTUAL server for keycloak.<domain> on the built-in public gateway. Big Bang does not create CA Secrets for other public-gateway hosts, MUTUAL servers, passthrough gateways, or custom gateways. Check for conflicts if the CA Secret for the Keycloak public-gateway credential, normally public-cert-cacert, is already managed separately.
If Keycloak uses a custom TLS-terminating gateway, add an OPTIONAL_MUTUAL server for the Keycloak hostname under that gateway:
istioGateway:
values:
gateways:
<gateway-name>:
gateway:
servers:
- hosts:
- "keycloak.<domain>"
port:
name: https-keycloak
number: 8443
protocol: HTTPS
tls:
credentialName: <gateway-credential-name>
mode: OPTIONAL_MUTUAL
User-provided Keycloak extraEnv entries are now merged with Big Bangβs defaults. Entries with the same environment-variable name override the Big Bang entry. When moving to TLS termination, remove any user-provided KC_HTTPS_CERTIFICATE_FILE and KC_HTTPS_CERTIFICATE_KEY_FILE entries.
The extraEnvFrom, extraVolumeMounts, and extraVolumes values remain YAML strings and are still replaced in full when supplied by the user. Remove the tlscert and tlskey volumes and their corresponding mounts from any user-provided configuration. Retain unrelated entries such as custom configuration volumes and mounts.
As an example, this is being used with Keycloak using the passthrough gateway:
extraVolumes: |-
- name: keycloak-conf
emptyDir: {}
- name: tlscert
secret:
secretName: {{ include "keycloak.fullname" . }}-tlscert
- name: tlskey
secret:
secretName: {{ include "keycloak.fullname" . }}-tlskey
extraVolumeMounts: |-
- name: tlscert
mountPath: /etc/x509/https/tls.crt
subPath: tls.crt
readOnly: true
- name: tlskey
mountPath: /etc/x509/https/tls.key
subPath: tls.key
readOnly: true
- name: tlscert
mountPath: /opt/keycloak/conf/tls.crt
subPath: tls.crt
readOnly: true
- name: tlskey
mountPath: /opt/keycloak/conf/tls.key
subPath: tls.key
readOnly: true
- name: keycloak-conf
mountPath: /opt/keycloak/conf/custom-registration-config.yaml
subPath: custom-registration-config.yaml
While the following would be used when using the TLS terminated gateway:
extraVolumes: |-
- name: keycloak-conf
emptyDir: {}
extraVolumeMounts: |-
- name: keycloak-conf
mountPath: /opt/keycloak/conf/custom-registration-config.yaml
subPath: custom-registration-config.yaml
BigBang - MR¶
Operators querying Loki by app_kubernetes_io_instance, app_kubernetes_io_version, controller-revision-hash, or pod-template-hash labels will need to switch to pod or app_kubernetes_io_name instead. No built-in BB dashboards are affected.
BigBang - MR¶
New: Istio Egress Gateway (Alpha)
This release adds an alpha istio-egress-gateway package: a shared egress waypoint for ambient mode that gives packages a single, default-deny egress point.
Disabled by default β no action required on upgrade. To try it (requires istio.ambient.enabled: true):
istio:
ambient:
enabled: true
egressGateway:
enabled: true
addons:
gitlab:
enabled: true
values:
# Configure gitlab to use egress waypoint, in future releases
# this will be the default if egressGateway is enabled.
routes:
defaults:
outbound:
egressGateway: istio-egress/egress-waypoint
Alpha: values and package coverage may change between releases. See Configuring an Egress Gateway.
External Secrets Operator - MR¶
Before upgrading an existing installation, refresh the CRDs with kubectl apply --server-side --force-conflicts -f https://raw.githubusercontent.com/external-secrets/external-secrets/helm-chart-2.11.0/deploy/crds/bundle.yaml, the CRDs also ship with chart itself and can be applied from the chart files i.e kubectl apply --server-side --force-conflicts -f https://repo1.dso.mil/big-bang/product/packages/external-secrets/-/raw/2.11.0-bb.0/chart/crds/bundle.yaml. Afterwards, upgrade the package. The force flag transfers the bundled CRD schema fields from Helm for this refresh; do not use it for locally customized CRDs without reviewing the differences. This package retains separately managed CRDs; see the upstream CRD instructions.
Grafana - MR¶
Chart 13 mounts /tmp by default; remove any duplicate /tmp mount from upstream.extraVolumeMounts. The Grafana container also uses a read-only root filesystem. See the upstream chart upgrade notes.
Grafana 13.2 disables deprecated scripted dashboards by default. If used, review the upstream change and 13.2 upgrade guide.
Kiali - MR¶
Kiali Operator 2.32.0 moved field for the chat_ai block. See https://kiali.io/docs/ai/kiali-chatbot/#configuring-the-kiali-chatbot
No action is required but if you wish to use the adjusted fields you must upgrade the CRDs:
helm show crds oci://registry1.dso.mil/bigbang/kiali \
--version 2.32.0-bb.0 | \
kubectl apply --server-side --force-conflicts -f -
Mattermost - MR¶
FIPS deployments: Before upgrading to 11.11.0, ensure the PostgreSQL password in Mattermost SqlSettings.DataSource is at least 14 ASCII characters. If shorter, rotate it in PostgreSQL and Mattermost first. Standard non-FIPS builds are unaffected. Upstream upgrade notes.
If your SSO provider resolves to a private address, allowlist only its hostname in Mattermost ServiceSettings.AllowedUntrustedInternalConnections; outbound OAuth requests now enforce this restriction. Upstream changelog.
Sonarqube - MR¶
For persistent SonarQube Community Build installations backed by PostgreSQL, back up the database before updating to 26.9, then visit /setup to complete the database migration after deployment. See SonarSource’s pre-update steps and Helm update procedure.
Known Issues¶
- Headlamp
- Attempting to login using OIDC will create a login ‘loop’. (Upstream Issue)
Upgrades from previous releases¶
If coming from a version pre-3.33.0, note the additional upgrade notices in any release in between. The BB team doesn’t test/guarantee upgrades from anything pre-3.33.0.
Packages¶
Click to show Packages Version Updates
| Package | Type | Package Version | BB Version |
|---|---|---|---|
| Alloy | Core | 4.3.2 |
4.3.2-bb.0 |
| Addon | 6.1.1 |
4.1.2-bb.2 π |
|
| Argocd | Addon | v3.4.5 |
10.2.1-bb.2 |
| Authservice | Addon | 1.1.8 |
1.1.8-bb.3 |
| Cert Manager | Core | v1.20.3 |
v1.20.3-bb.2 |
| Core | 3.5.0 |
3.5.0-bb.1 π |
|
| Core | 9.5.4 |
1.44.0-bb.0 π |
|
| Addon | v2.11.0 |
2.11.0-bb.0 π |
|
| Fluentbit | Core | v5.1.2 |
0.58.2-bb.0 |
| Addon | 26.2.2.0004 |
26.2.0-bb.6 π |
|
| Gatekeeper | Core | v3.23.1 |
3.23.1-bb.0 |
| Core | 1.6.2 |
1.6.2-bb.0 π |
|
| Addon | 19.4.1 |
10.4.1-bb.0 π |
|
| Gitlab Runner | Addon | v19.2.2 |
0.91.2-bb.2 |
| Core | 13.2.1 |
13.2.4-bb.0 π |
|
| Addon | 2.15.2 |
1.19.2-bb.2 π |
|
| Headlamp | Addon | 0.45.0 |
0.45.0-bb.0 |
| Core | 1.30.4 |
1.30.4-bb.1 π |
|
| Core | 1.30.4 |
1.30.4-bb.1 π |
|
| Core | N/A |
0.1.3 π |
|
| Core | 1.30.4 |
1.30.4-bb.1 π |
|
| Core | 1.30.4 |
1.30.4-bb.1 π |
|
| Addon | 26.7.2 |
7.3.0-bb.2 π |
|
| Core | 2.32.0 |
2.32.0-bb.0 π |
|
| Kyverno | Core | v1.19.1 |
3.9.1-bb.0 |
| Kyverno Policies | Core | v1.13.2 |
3.3.4-bb.87 |
| Kyverno Reporter | Core | 3.10.0 |
3.10.0-bb.2 |
| Core | 3.7.7 |
6.55.0-bb.8 π |
|
| Addon | 11.11.0 |
11.11.0-bb.0 π |
|
| Addon | 1.25.9 |
1.25.9-bb.1 π |
|
| Metrics Server | Addon | 0.9.0 |
3.14.0-bb.0 |
| Addon | 3.1.2 |
6.1.0-bb.2 π |
|
| Minio | Addon | v7.1.1 |
7.1.1-bb.24 |
| Addon | v7.1.1 |
7.1.1-bb.11 π |
|
| Core | v0.94.0 |
91.4.1-bb.1 π |
|
| Core | 5.6.2 |
2.11.2-bb.0 π |
|
| Prometheus Operator Crds | Core | v0.93.1 |
31.0.1-bb.0 |
| Core | 44.97.2 |
46.316.0-bb.0 π |
|
| Addon | 26.9.0.129388 |
2026.4.1-bb.4 π |
|
| Core | 2.10.5 |
2.1.0-bb.3 π |
|
| Addon | v0.42.4 |
17.6.0-bb.3 π |
|
| Core | 34.05.157 |
0.30.0-bb.3 π |
|
| Addon | 1.21.4 |
0.34.1-bb.2 π |
|
| Addon | 1.18.2 |
12.1.0-bb.5 π |
|
| Wrapper | Core | N/A |
0.4.15 |
| Core | 1.30.4 |
1.30.4-bb.1 π |
Changes in 3.34.0¶
Big Bang MRs¶
- !8302 Update file manage.sh for garage bucket to add
loki-adminandloki-deletion - !8284 Update file manage.sh with
bbtest-bucketfor garage - !8273 Updated Keycloak templating to allow usage on either gateway
- !8264 make neuvector hr dependsOn keycloak when sso is enabled
- !8256 fix(fluentbit): replace Loki label denylist with explicit allowlist
- !8248 Update Renovate page - remove fields and point upstream
- !8243 Update Troublshooting/Overview Page
- !8237 Add ambient istio egress functionality
- !8220 Updated templates to network policies and service entries properly account for…
- !8218 add sso helper to fortify, vault, harbor
- !8125 Add airgap import docs for the hauler archive
Anchore Enterprise¶
Click to show Changelog
# Changelog Updates
## [4.1.2-bb.2] (2026-09-15)
### Fixed
- Raised `upstream.probes.liveness.failureThreshold` to 60 so the policy engine is no longer
restarted while it waits for the data-syncer during startup, which held its Deployment past
progressDeadlineSeconds and failed the Helm release
## [4.1.2-bb.1] (2026-09-10)
### Changed
- Updated Cypress test to support SSO upgrade job in pipeline
Eck Operator¶
- !8241: eckOperator update to 3.5.0-bb.1
Click to show Changelog
# Changelog Updates
## [3.5.0-bb.1] (2026-09-10)
### Changed
- Added missing `upgradeCrds.enabled` condition to the `upgrade-crds` image in the `helm.sh/images` list.
Elasticsearch Kibana¶
- !8293: elasticsearchKibana update to 1.44.0-bb.0
Click to show Changelog
# Changelog Updates
## [1.44.0-bb.0] (2026-09-19)
### Changed
- gluon 1.1.7 -> 1.1.8
- Retained Cypress 15.21.1 until the Gluon test support is compatible with Cypress 16 (Gluon work item 139).
- registry1.dso.mil/ironbank/elastic/elasticsearch/elasticsearch 9.5.3 -> 9.5.4
- registry1.dso.mil/ironbank/elastic/kibana/kibana 9.5.3 -> 9.5.4
- registry1.dso.mil/ironbank/opensource/kubernetes/kubectl v1.36 -> v1.37
- Aligned the script-test network wait image from kubectl v1.35 to v1.37 and made both test init image overrides explicit for Renovate.
External Secrets Operator¶
- !8282: externalSecrets update to 2.11.0-bb.0
Click to show Changelog
# Changelog Updates
## [2.11.0-bb.0] (2026-09-22)
### Changed
- bb-common 1.5.0 -> 1.6.0
- external-secrets 2.10.0 -> 2.11.0
- gluon 1.1.7 -> 1.1.8
- registry1.dso.mil/ironbank/opensource/external-secrets/external-secrets v2.10.0 -> v2.11.0
- Updated the bundled External Secrets CRDs to helm-chart-2.11.0.
Fortify¶
Click to show Changelog
# Changelog Updates
## [26.2.0-bb.6] (2026-09-28)
### Changed
- updated cypress test to support sso upgrade jobs
## [26.2.0-bb.4] (2026-09-11)
### Changed
- Explicitly set `mysql.image.registry`, `mysql.metrics.image.registry`, and `mysql.volumePermissions.image.registry` to allow renovate to detect updates for them.
Gateway Api¶
- !8272: gatewayAPI update to 1.6.2-bb.0
Click to show Changelog
# Changelog Updates
## [1.6.2-bb.0] (2026-09-04)
### Changed
- kubernetes-sigs/gateway-api updated from 1.6.1 to 1.6.2
Gitlab¶
- !8303: gitlab update to 10.4.1-bb.0
Click to show Changelog
# Changelog Updates
## [10.4.1-bb.0] (2026-09-26)
### Changed
- gitlab 10.3.2 -> 10.4.1
- gitlab-app-version 19.3.2 -> 19.4.1
- gluon 1.1.7 -> 1.1.8
- registry1.dso.mil/gitlab/gitlab-org/build/cng/certificates v19.3.2 -> v19.4.1
- registry1.dso.mil/gitlab/gitlab-org/build/cng/cfssl-self-sign v19.3.2 -> v19.4.1
- registry1.dso.mil/gitlab/gitlab-org/build/cng/gitaly v19.3.2 -> v19.4.1
- registry1.dso.mil/gitlab/gitlab-org/build/cng/gitaly-init-cgroups v19.3.2 -> v19.4.1
- registry1.dso.mil/gitlab/gitlab-org/build/cng/gitlab-base v19.3.2 -> v19.4.1
- registry1.dso.mil/gitlab/gitlab-org/build/cng/gitlab-container-registry v4.40.2 -> v4.41.0
- registry1.dso.mil/gitlab/gitlab-org/build/cng/gitlab-exporter 16.9.0 -> 17.0.2
- registry1.dso.mil/gitlab/gitlab-org/build/cng/gitlab-geo-logcursor v19.3.2 -> v19.4.1
- registry1.dso.mil/gitlab/gitlab-org/build/cng/gitlab-kas v19.3.2 -> v19.4.1
- registry1.dso.mil/gitlab/gitlab-org/build/cng/gitlab-mailroom v19.3.2 -> v19.4.1
- registry1.dso.mil/gitlab/gitlab-org/build/cng/gitlab-pages v19.3.2 -> v19.4.1
- registry1.dso.mil/gitlab/gitlab-org/build/cng/gitlab-shell v14.56.1 -> v14.57.3
- registry1.dso.mil/gitlab/gitlab-org/build/cng/gitlab-sidekiq-ee v19.3.2 -> v19.4.1
- registry1.dso.mil/gitlab/gitlab-org/build/cng/gitlab-toolbox-ee v19.3.2 -> v19.4.1
- registry1.dso.mil/gitlab/gitlab-org/build/cng/gitlab-webservice-ee v19.3.2 -> v19.4.1
- registry1.dso.mil/gitlab/gitlab-org/build/cng/gitlab-workhorse-ee v19.3.2 -> v19.4.1
- registry1.dso.mil/gitlab/gitlab-org/build/cng/kubectl v19.3.2 -> v19.4.1
- registry1.dso.mil/gitlab/gitlab-org/modelops/applied-ml/code-suggestions/ai-assist/model-gateway self-hosted-v19.2.0-ee -> self-hosted-v19.4.1-ee
- registry1.dso.mil/ironbank/big-bang/cypress 16.0.0 -> 16.1.0
- registry1.dso.mil/ironbank/opensource/nginx/nginx 1.31.5 -> 1.31.6
Grafana¶
Click to show Changelog
# Changelog Updates
## [13.2.4-bb.0] (2026-09-22)
### Changed
- bb-common 1.4.0 -> 1.6.0
- gluon 1.1.6 -> 1.1.8
- grafana 12.10.0 -> 13.2.4 (matches the available Grafana 13.2.1 image)
- registry1.dso.mil/ironbank/big-bang/cypress 15.20.1 -> 15.21.1; align the Cypress runner, network-wait image, and image metadata. Defer Cypress 16 until Gluon's shared commands support the removal of `Cypress.env()`.
- registry1.dso.mil/ironbank/big-bang/grafana/grafana-plugins 13.1.0 -> 13.2.1
- registry1.dso.mil/ironbank/kiwigrid/k8s-sidecar 2.10.1 -> 2.11.2
- registry1.dso.mil/ironbank/opensource/grafana/grafana-image-renderer v5.12.1 -> v5.12.3
- Synced Kubernetes dashboards with upstream kube-prometheus-stack.
## [12.10.0-bb.1] (2026-09-10)
### Changed
- updated Cypress test to support Helm upgrade testing for SSO
Harbor¶
- !8301: harbor update to 1.19.2-bb.2
Click to show Changelog
# Changelog Updates
## [1.19.2-bb.2] (2026-09-17)
### Changed
- Updated Cypress SSO tests to support upgrade runs.
- Added SSO test values using the quoted `cypress_sso_test_requested` marker.
Istio Cni¶
- !8295: istioCNI update to 1.30.4-bb.1
Click to show Changelog
# Changelog Updates
## [1.30.4-bb.1] (2026-09-24)
### Changed
- Migrated upstream Helm chart repository to `https://blob.istio.io/istio-release/charts` ahead of the retirement of the Istio GCP-hosted endpoint
Istio Crds¶
- !8296: istioCRDs update to 1.30.4-bb.1
Click to show Changelog
# Changelog Updates
## [1.30.4-bb.1] (2026-09-24)
### Changed
- Migrated upstream Helm chart repository to `https://blob.istio.io/istio-release/charts` ahead of the retirement of the Istio GCP-hosted endpoint
Istio Gateway¶
- !8299: istioGateway update to 1.30.4-bb.1
Click to show Changelog
# Changelog Updates
## [1.30.4-bb.1] (2026-09-23)
### Changed
- Migrated upstream Helm chart repository to `https://blob.istio.io/istio-release/charts` ahead of the retirement of the Istio GCP-hosted endpoint
Istiod¶
- !8298: istiod update to 1.30.4-bb.1
Click to show Changelog
# Changelog Updates
## [1.30.4-bb.1] (2026-09-23)
### Changed
- Migrated upstream Helm chart repository to `https://blob.istio.io/istio-release/charts` ahead of the retirement of the Istio GCP-hosted endpoint
Keycloak¶
Click to show Changelog
# Changelog Updates
## [7.3.0-bb.2] (2026-09-22)
### Changed
- Synced bb-common schema blocks (istio, networkPolicies, routes) with bb-common 1.6.0 via scripts/schema.sh
- Dropped `additionalProperties: false` from the istio schema block to tolerate umbrella-injected keys (`istio.injection`, `istio.hardened`); scripts/schema.sh restores it on resync, so this must be re-dropped after future syncs
## [7.3.0-bb.1] (2026-09-22)
### Changed
- bb-common 1.5.0 -> 1.6.0
- gluon 1.1.6 -> 1.1.8
- Updated hook templates to accept httpPort dynamically
Kiali¶
- !8279: kiali update to 2.32.0-bb.0
- !8263: kiali update to 2.31.0-bb.2
- !8257: kiali update to 2.31.0-bb.1
Click to show Changelog
# Changelog Updates
## [2.32.0-bb.0] (2026-09-19)
### Changed
- bb-common 1.5.0 -> 1.6.0
- gluon 1.1.6 -> 1.1.8
- kiali-operator 2.31.0 -> 2.32.0
- registry1.dso.mil/ironbank/opensource/kiali/kiali v2.31.0 -> v2.32.0
- registry1.dso.mil/ironbank/opensource/kiali/kiali-operator v2.31.0 -> v2.32.0
- registry1.dso.mil/ironbank/opensource/kubernetes/kubectl v1.35 -> v1.37
## [2.31.0-bb.2] (2026-09-18)
### Changed
- Add SSO test values and validate authenticated Kiali access on initial and upgrade logins.
## [2.31.0-bb.1] (2026-09-15)
### Changed
- The registry1.dso.mil/ironbank/opensource/kubernetes/kubectl tag was changed to track the minor version rather than the patch version (1.35.8 -> 1.35).
### Changed
- updated Cypress test to pass the Keycloak URL to performKeycloakLogin
Loki¶
- !8259: loki update to 6.55.0-bb.8
Click to show Changelog
# Changelog Updates
## [6.55.0-bb.7] (2026-09-16)
### Changed
- registry1.dso.mil/ironbank/opensource/kubernetes/kubectl is now referenced by its minor version tag rather than its patch version tag.
Mattermost¶
- !8265: mattermost update to 11.11.0-bb.0
- !8260: mattermost update to 11.10.1-bb.2
- !8252: mattermost update to 11.10.1-bb.1
Click to show Changelog
# Changelog Updates
## [11.11.0-bb.0] (2026-09-18)
### Changed
- gluon 1.1.7 -> 1.1.8
- minio-instance 7.1.1-bb.20 -> 7.1.1-bb.24
- postgresql 18.11.1 -> 18.11.3
- registry1.dso.mil/ironbank/opensource/kubernetes/kubectl v1.36 -> v1.37
- registry1.dso.mil/ironbank/opensource/mattermost/mattermost 11.10.1 -> 11.11.0
## [11.10.1-bb.2] (2026-09-16)
### Changed
- Fixed the operator-sidecar image's condition in Chart.yaml's helm.sh/images annotaiton.
- Specified the minio image in the values file.
## [11.10.1-bb.1] (2026-09-16)
### Fixed
- Handle optional Keycloak login and consent screens during SSO upgrade tests and verify the authenticated Mattermost user.
Mattermost Operator¶
- !8267: mattermostOperator update to 1.25.9-bb.1
Click to show Changelog
# Changelog Updates
## [1.25.9-bb.1] (2026-09-16)
### Changed
- No customer-facing changes, but some templates were moved to allow renovate to more easily automate updates.
Mimir¶
- !8258: mimir update to 6.1.0-bb.2
Click to show Changelog
# Changelog Updates
## [6.1.0-bb.2] (2026-09-16)
### Changed
- Added the minio image to the chart's helm.sh/images annotation and specified it as a default in the values file.
Minio Operator¶
Click to show Changelog
# Changelog Updates
## [7.1.1-bb.11] (2026-09-18)
### Changed
- Added conditions for the tenant-wait-job, tenant-patch-job, and cypress images in the Chart.yaml's helm.sh/images annotation.
- Specified the cypress image in values.yaml.
Monitoring¶
Click to show Changelog
# Changelog Updates
## [91.4.1-bb.1] (2026-09-23)
### Fixed
- Resolve the Grafana metrics datasource by its stable UID so smoke tests support both Prometheus and Thanos display names.
## [91.4.1-bb.0] (2026-09-18)
### Changed
- bb-common 1.5.0 -> 1.6.0
- gluon 1.1.7 -> 1.1.8
- kube-prometheus-stack 88.6.2 -> 91.4.1
- prometheus-snmp-exporter 9.17.1 -> 9.18.0
- registry1.dso.mil/ironbank/big-bang/grafana/grafana-plugins 13.1.0 -> 13.2.1
- registry1.dso.mil/ironbank/kiwigrid/k8s-sidecar 2.10.3 -> 2.11.2
- registry1.dso.mil/ironbank/opensource/kubernetes/kubectl v1.35 -> v1.37
- registry1.dso.mil/ironbank/opensource/prometheus-operator/prometheus-config-reloader v0.93.1 -> v0.94.0
- registry1.dso.mil/ironbank/opensource/prometheus-operator/prometheus-operator v0.93.1 -> v0.94.0
- registry1.dso.mil/ironbank/opensource/prometheus/alertmanager v0.34.0 -> v0.34.1
Neuvector¶
Click to show Changelog
# Changelog Updates
## [2.11.2-bb.0] (2026-09-22)
### Changed
- bb-common 1.5.0 -> 1.6.0
- core 2.11.1 -> 2.11.2
- crd 2.11.1 -> 2.11.2
- gluon 1.1.7 -> 1.1.8
- monitor 2.11.1 -> 2.11.2
- registry1.dso.mil/ironbank/neuvector/neuvector/controller 5.6.1 -> 5.6.2
- registry1.dso.mil/ironbank/neuvector/neuvector/enforcer 5.6.1 -> 5.6.2
- registry1.dso.mil/ironbank/neuvector/neuvector/manager 5.6.1 -> 5.6.2
- registry1.dso.mil/ironbank/opensource/neuvector/registry-adapter v0.2.10 -> v0.2.11
- Synchronize the deployed core image tag and resolve upstream image readiness using NeuVector's Iron Bank tag mappings.
## [2.11.1-bb.2] (2026-09-18)
### Changed
- Specified the registry for the adapter and exporter image values to enable renovate updates using the built-in helm-values manager.
- Added the cypress image to the chart's values and to Chart.yaml's helm.sh/images annotation.
## [2.11.1-bb.1] (2026-09-17)
### Changed
- Cypress Updates to support SSO upgrade jobs
Renovate¶
- !8291: renovate update to 46.316.0-bb.0
Click to show Changelog
# Changelog Updates
## [46.316.0-bb.0] (2026-09-23)
### Changed
- gluon 1.1.7 -> 1.1.8
- registry1.dso.mil/ironbank/container-hardening-tools/renovate/renovate 44.43.1 -> 44.97.2
- renovate 46.289.4 -> 46.316.0
- Added an explicit optional test `kubectl` image pin and metadata plus stable upstream release/documentation links
Sonarqube¶
- !8276: sonarqube update to 2026.4.1-bb.4
- !8266: sonarqube update to 2026.4.1-bb.3
- !8254: sonarqube update to 2026.4.1-bb.2
Click to show Changelog
# Changelog Updates
## [2026.4.1-bb.4] (2026-09-22)
### Changed
- Changed the chart's appVersion to track the sonarqube image rather than the upstream chart version.
## [2026.4.1-bb.3] (2026-09-18)
### Changed
- bb-common 1.5.0 -> 1.6.0
- gluon 1.1.6 -> 1.1.8
- registry1.dso.mil/ironbank/sonarsource/sonarqube/sonarqube-community-build 26.8.0.126808 -> 26.9.0.129388
- Wait for SonarQube to become available before running Cypress checks during an upgrade.
## [2026.4.1-bb.2] (2026-09-16)
### Changed
- Support repeat Cypress SSO logins and verify the authenticated SonarQube account.
- Preserve SonarQube data during SSO upgrade tests.
Tempo¶
- !8275: tempo update to 2.1.0-bb.3
Click to show Changelog
# Changelog Updates
## [2.1.0-bb.3] (2026-09-22)
### Changed
- Remove the deprecated `bigbang.dev/applicationVersions` chart annotation.
- Adding missing `kubectl` and `base` images to the `helm.sh/images` chart annotation.
Thanos¶
Click to show Changelog
# Changelog Updates
## [17.6.0-bb.3] (2026-09-25)
### Changed
- Updated Cypress Tests to support SSO upgrade CI jobs
## [17.6.0-bb.2] (2026-09-16)
### Changed
- bb-common 1.4.0 -> 1.6.0
- gluon 1.1.5 -> 1.1.8
- minio-instance 7.1.1-bb.15 -> 7.1.1-bb.24
- registry1.dso.mil/ironbank/opensource/kubernetes/kubectl v1.34 -> v1.37
- registry1.dso.mil/ironbank/opensource/thanos/thanos v0.42.2 -> v0.42.4
Twistlock¶
- !8274: twistlock update to 0.30.0-bb.3
Click to show Changelog
# Changelog Updates
## [0.30.0-bb.3] (2026-09-17)
### Changed
- Update Cypress tests to allow for SSO upgrade jobs
- Use the CI realm's signing certificate for SSO tests and check the console license after login.
Vault¶
- !8251: vault update to 0.34.1-bb.2
Click to show Changelog
# Changelog Updates
## [0.34.1-bb.2] (2026-09-15)
### Changed
- Updated cypress test to support SSO upgrade job
- Updated Gluon to 1.1.8 and removed the custom script network-wait override.
### Fixed
- Added Vault HTTPS 8200 routing for tests and Keycloak test-client callbacks.
- Skip script test resources when `bbtests.scripts.enabled` is false and remove extra YAML separators from script and Cypress test templates to prevent Flux post-render failures caused by incomplete or empty manifests.
Velero¶
- !8289: velero update to 12.1.0-bb.5
Click to show Changelog
# Changelog Updates
## [12.1.0-bb.5] (2026-09-23)
### Changed
- Added missing conditions to the `helm.sh/images` chart annotation.
Ztunnel¶
- !8297: ztunnel update to 1.30.4-bb.1
Click to show Changelog
# Changelog Updates
## [1.30.4-bb.1] (2026-09-23)
### Changed
- Migrated upstream Helm chart repository to `https://blob.istio.io/istio-release/charts` ahead of the retirement of the Istio GCP-hosted endpoint
Helpful Links¶
As always, we welcome and appreciate feedback from our community of users. Please feel free to:
- Open issues here
- Join our Mattermost channel
- Join our Slack
- Check out the documentation for guidance on how to get started
Future¶
Don’t see your feature and/or bug fix? Check out our epics for estimates on when you can expect things to drop, and as always, feel free to comment or create issues if you have questions, comments, or concerns.