Skip to content

Release Notes - 3.34.0

Please see our documentation page for more information on how to consume and deploy Big Bang. This release was primarily tested on Kubernetes 1.36 (EKS).

Upgrade Notices

BigBang - MR

Keycloak can now use either a TLS-terminated gateway or a passthrough gateway. We recommend migrating to TLS termination at Big Bang’s public gateway because this will become the default behavior in Big Bang 4.0. If the public and passthrough gateways use different addresses, update the DNS record for keycloak.<domain> to point to the public gateway.

To use Big Bang’s public gateway, clear any explicit gateway selection and remove the Keycloak certificate and key:

addons:
  keycloak:
    ingress:
      gateway: ""
      cert: ""
      key: ""

When both cert and key are empty, TLS terminates at the public gateway and traffic is forwarded to Keycloak over HTTP. Supplying both values continues to configure Keycloak for TLS passthrough.

When Keycloak uses the built-in public gateway, Big Bang automatically adds an OPTIONAL_MUTUAL server for keycloak.<domain>. Big Bang also creates the corresponding <credentialName>-cacert Secret containing the bundled DoD CA chain. Automatic CA creation is limited to an OPTIONAL_MUTUAL server for keycloak.<domain> on the built-in public gateway. Big Bang does not create CA Secrets for other public-gateway hosts, MUTUAL servers, passthrough gateways, or custom gateways. Check for conflicts if the CA Secret for the Keycloak public-gateway credential, normally public-cert-cacert, is already managed separately.

If Keycloak uses a custom TLS-terminating gateway, add an OPTIONAL_MUTUAL server for the Keycloak hostname under that gateway:

istioGateway:
  values:
    gateways:
      <gateway-name>:
        gateway:
          servers:
            - hosts:
                - "keycloak.<domain>"
              port:
                name: https-keycloak
                number: 8443
                protocol: HTTPS
              tls:
                credentialName: <gateway-credential-name>
                mode: OPTIONAL_MUTUAL

User-provided Keycloak extraEnv entries are now merged with Big Bang’s defaults. Entries with the same environment-variable name override the Big Bang entry. When moving to TLS termination, remove any user-provided KC_HTTPS_CERTIFICATE_FILE and KC_HTTPS_CERTIFICATE_KEY_FILE entries.

The extraEnvFrom, extraVolumeMounts, and extraVolumes values remain YAML strings and are still replaced in full when supplied by the user. Remove the tlscert and tlskey volumes and their corresponding mounts from any user-provided configuration. Retain unrelated entries such as custom configuration volumes and mounts.

As an example, this is being used with Keycloak using the passthrough gateway:

        extraVolumes: |-
          - name: keycloak-conf
            emptyDir: {}
          - name: tlscert
            secret:
              secretName: {{ include "keycloak.fullname" . }}-tlscert
          - name: tlskey
            secret:
              secretName: {{ include "keycloak.fullname" . }}-tlskey
        extraVolumeMounts: |-
          - name: tlscert
            mountPath: /etc/x509/https/tls.crt
            subPath: tls.crt
            readOnly: true
          - name: tlskey
            mountPath: /etc/x509/https/tls.key
            subPath: tls.key
            readOnly: true
          - name: tlscert
            mountPath: /opt/keycloak/conf/tls.crt
            subPath: tls.crt
            readOnly: true
          - name: tlskey
            mountPath: /opt/keycloak/conf/tls.key
            subPath: tls.key
            readOnly: true
          - name: keycloak-conf
            mountPath: /opt/keycloak/conf/custom-registration-config.yaml
            subPath: custom-registration-config.yaml

While the following would be used when using the TLS terminated gateway:

        extraVolumes: |-
          - name: keycloak-conf
            emptyDir: {}
        extraVolumeMounts: |-
          - name: keycloak-conf
            mountPath: /opt/keycloak/conf/custom-registration-config.yaml
            subPath: custom-registration-config.yaml

BigBang - MR

Operators querying Loki by app_kubernetes_io_instance, app_kubernetes_io_version, controller-revision-hash, or pod-template-hash labels will need to switch to pod or app_kubernetes_io_name instead. No built-in BB dashboards are affected.


BigBang - MR

New: Istio Egress Gateway (Alpha)

This release adds an alpha istio-egress-gateway package: a shared egress waypoint for ambient mode that gives packages a single, default-deny egress point.

Disabled by default β€” no action required on upgrade. To try it (requires istio.ambient.enabled: true):

istio:
  ambient:
    enabled: true
  egressGateway:
    enabled: true


addons:
  gitlab:
    enabled: true
    values:
      # Configure gitlab to use egress waypoint, in future releases
      # this will be the default if egressGateway is enabled.
      routes:
        defaults:
          outbound:
            egressGateway: istio-egress/egress-waypoint

Alpha: values and package coverage may change between releases. See Configuring an Egress Gateway.


External Secrets Operator - MR

Before upgrading an existing installation, refresh the CRDs with kubectl apply --server-side --force-conflicts -f https://raw.githubusercontent.com/external-secrets/external-secrets/helm-chart-2.11.0/deploy/crds/bundle.yaml, the CRDs also ship with chart itself and can be applied from the chart files i.e kubectl apply --server-side --force-conflicts -f https://repo1.dso.mil/big-bang/product/packages/external-secrets/-/raw/2.11.0-bb.0/chart/crds/bundle.yaml. Afterwards, upgrade the package. The force flag transfers the bundled CRD schema fields from Helm for this refresh; do not use it for locally customized CRDs without reviewing the differences. This package retains separately managed CRDs; see the upstream CRD instructions.


Grafana - MR

Chart 13 mounts /tmp by default; remove any duplicate /tmp mount from upstream.extraVolumeMounts. The Grafana container also uses a read-only root filesystem. See the upstream chart upgrade notes.

Grafana 13.2 disables deprecated scripted dashboards by default. If used, review the upstream change and 13.2 upgrade guide.


Kiali - MR

Kiali Operator 2.32.0 moved field for the chat_ai block. See https://kiali.io/docs/ai/kiali-chatbot/#configuring-the-kiali-chatbot

No action is required but if you wish to use the adjusted fields you must upgrade the CRDs:

helm show crds oci://registry1.dso.mil/bigbang/kiali \
  --version 2.32.0-bb.0 | \
  kubectl apply --server-side --force-conflicts -f -

Mattermost - MR

FIPS deployments: Before upgrading to 11.11.0, ensure the PostgreSQL password in Mattermost SqlSettings.DataSource is at least 14 ASCII characters. If shorter, rotate it in PostgreSQL and Mattermost first. Standard non-FIPS builds are unaffected. Upstream upgrade notes.

If your SSO provider resolves to a private address, allowlist only its hostname in Mattermost ServiceSettings.AllowedUntrustedInternalConnections; outbound OAuth requests now enforce this restriction. Upstream changelog.


Sonarqube - MR

For persistent SonarQube Community Build installations backed by PostgreSQL, back up the database before updating to 26.9, then visit /setup to complete the database migration after deployment. See SonarSource’s pre-update steps and Helm update procedure.


Known Issues

Upgrades from previous releases

If coming from a version pre-3.33.0, note the additional upgrade notices in any release in between. The BB team doesn’t test/guarantee upgrades from anything pre-3.33.0.

Packages

Click to show Packages Version Updates
Package Type Package Version BB Version
Alloy Core 4.3.2 4.3.2-bb.0
updated Anchore Enterprise Addon 6.1.1 4.1.2-bb.2 πŸ”—
Argocd Addon v3.4.5 10.2.1-bb.2
Authservice Addon 1.1.8 1.1.8-bb.3
Cert Manager Core v1.20.3 v1.20.3-bb.2
updated Eck Operator Core 3.5.0 3.5.0-bb.1 πŸ”—
updated Elasticsearch Kibana Core 9.5.4 1.44.0-bb.0 πŸ”—
updated External Secrets Operator Addon v2.11.0 2.11.0-bb.0 πŸ”—
Fluentbit Core v5.1.2 0.58.2-bb.0
updated Fortify Addon 26.2.2.0004 26.2.0-bb.6 πŸ”—
Gatekeeper Core v3.23.1 3.23.1-bb.0
updated Gateway Api Core 1.6.2 1.6.2-bb.0 πŸ”—
updated Gitlab Addon 19.4.1 10.4.1-bb.0 πŸ”—
Gitlab Runner Addon v19.2.2 0.91.2-bb.2
updated Grafana Core 13.2.1 13.2.4-bb.0 πŸ”—
updated Harbor Addon 2.15.2 1.19.2-bb.2 πŸ”—
Headlamp Addon 0.45.0 0.45.0-bb.0
updated Istio Cni Core 1.30.4 1.30.4-bb.1 πŸ”—
updated Istio Crds Core 1.30.4 1.30.4-bb.1 πŸ”—
updated Istio Egress Gateway Core N/A 0.1.3 πŸ”—
updated Istio Gateway Core 1.30.4 1.30.4-bb.1 πŸ”—
updated Istiod Core 1.30.4 1.30.4-bb.1 πŸ”—
updated Keycloak Addon 26.7.2 7.3.0-bb.2 πŸ”—
updated Kiali Core 2.32.0 2.32.0-bb.0 πŸ”—
Kyverno Core v1.19.1 3.9.1-bb.0
Kyverno Policies Core v1.13.2 3.3.4-bb.87
Kyverno Reporter Core 3.10.0 3.10.0-bb.2
updated Loki Core 3.7.7 6.55.0-bb.8 πŸ”—
updated Mattermost Addon 11.11.0 11.11.0-bb.0 πŸ”—
updated Mattermost Operator Addon 1.25.9 1.25.9-bb.1 πŸ”—
Metrics Server Addon 0.9.0 3.14.0-bb.0
updated Mimir Addon 3.1.2 6.1.0-bb.2 πŸ”—
Minio Addon v7.1.1 7.1.1-bb.24
updated Minio Operator Addon v7.1.1 7.1.1-bb.11 πŸ”—
updated Monitoring Core v0.94.0 91.4.1-bb.1 πŸ”—
updated Neuvector Core 5.6.2 2.11.2-bb.0 πŸ”—
Prometheus Operator Crds Core v0.93.1 31.0.1-bb.0
updated Renovate beta Core 44.97.2 46.316.0-bb.0 πŸ”—
updated Sonarqube Addon 26.9.0.129388 2026.4.1-bb.4 πŸ”—
updated Tempo Core 2.10.5 2.1.0-bb.3 πŸ”—
updated Thanos Addon v0.42.4 17.6.0-bb.3 πŸ”—
updated Twistlock Core 34.05.157 0.30.0-bb.3 πŸ”—
updated Vault Addon 1.21.4 0.34.1-bb.2 πŸ”—
updated Velero Addon 1.18.2 12.1.0-bb.5 πŸ”—
Wrapper Core N/A 0.4.15
updated Ztunnel Core 1.30.4 1.30.4-bb.1 πŸ”—

Changes in 3.34.0

Big Bang MRs

  • !8302 Update file manage.sh for garage bucket to add loki-admin and loki-deletion
  • !8284 Update file manage.sh with bbtest-bucket for garage
  • !8273 Updated Keycloak templating to allow usage on either gateway
  • !8264 make neuvector hr dependsOn keycloak when sso is enabled
  • !8256 fix(fluentbit): replace Loki label denylist with explicit allowlist
  • !8248 Update Renovate page - remove fields and point upstream
  • !8243 Update Troublshooting/Overview Page
  • !8237 Add ambient istio egress functionality
  • !8220 Updated templates to network policies and service entries properly account for…
  • !8218 add sso helper to fortify, vault, harbor
  • !8125 Add airgap import docs for the hauler archive

Anchore Enterprise

  • !8249: anchoreEnterprise update to 4.1.2-bb.2
  • !8244: anchoreEnterprise update to 4.1.2-bb.1
Click to show Changelog
# Changelog Updates

## [4.1.2-bb.2] (2026-09-15)
### Fixed
- Raised `upstream.probes.liveness.failureThreshold` to 60 so the policy engine is no longer
  restarted while it waits for the data-syncer during startup, which held its Deployment past
  progressDeadlineSeconds and failed the Helm release

## [4.1.2-bb.1] (2026-09-10)
### Changed
- Updated Cypress test to support SSO upgrade job in pipeline

Eck Operator

  • !8241: eckOperator update to 3.5.0-bb.1
Click to show Changelog
# Changelog Updates

## [3.5.0-bb.1] (2026-09-10)
### Changed
- Added missing `upgradeCrds.enabled` condition to the `upgrade-crds` image in the `helm.sh/images` list.

Elasticsearch Kibana

  • !8293: elasticsearchKibana update to 1.44.0-bb.0
Click to show Changelog
# Changelog Updates

## [1.44.0-bb.0] (2026-09-19)
### Changed
- gluon 1.1.7 -> 1.1.8
- Retained Cypress 15.21.1 until the Gluon test support is compatible with Cypress 16 (Gluon work item 139).
- registry1.dso.mil/ironbank/elastic/elasticsearch/elasticsearch 9.5.3 -> 9.5.4
- registry1.dso.mil/ironbank/elastic/kibana/kibana 9.5.3 -> 9.5.4
- registry1.dso.mil/ironbank/opensource/kubernetes/kubectl v1.36 -> v1.37
- Aligned the script-test network wait image from kubectl v1.35 to v1.37 and made both test init image overrides explicit for Renovate.

External Secrets Operator

  • !8282: externalSecrets update to 2.11.0-bb.0
Click to show Changelog
# Changelog Updates

## [2.11.0-bb.0] (2026-09-22)
### Changed
- bb-common 1.5.0 -> 1.6.0
- external-secrets 2.10.0 -> 2.11.0
- gluon 1.1.7 -> 1.1.8
- registry1.dso.mil/ironbank/opensource/external-secrets/external-secrets v2.10.0 -> v2.11.0
- Updated the bundled External Secrets CRDs to helm-chart-2.11.0.

Fortify

  • !8304: fortify update to 26.2.0-bb.6
  • !8261: fortify update to 26.2.0-bb.5
Click to show Changelog
# Changelog Updates

## [26.2.0-bb.6] (2026-09-28)
### Changed
- updated cypress test to support sso upgrade jobs

## [26.2.0-bb.4] (2026-09-11)
### Changed
- Explicitly set `mysql.image.registry`, `mysql.metrics.image.registry`, and `mysql.volumePermissions.image.registry` to allow renovate to detect updates for them.

Gateway Api

  • !8272: gatewayAPI update to 1.6.2-bb.0
Click to show Changelog
# Changelog Updates

## [1.6.2-bb.0] (2026-09-04)
### Changed
- kubernetes-sigs/gateway-api updated from 1.6.1 to 1.6.2

Gitlab

  • !8303: gitlab update to 10.4.1-bb.0
Click to show Changelog
# Changelog Updates

## [10.4.1-bb.0] (2026-09-26)
### Changed
- gitlab 10.3.2 -> 10.4.1
- gitlab-app-version 19.3.2 -> 19.4.1
- gluon 1.1.7 -> 1.1.8
- registry1.dso.mil/gitlab/gitlab-org/build/cng/certificates v19.3.2 -> v19.4.1
- registry1.dso.mil/gitlab/gitlab-org/build/cng/cfssl-self-sign v19.3.2 -> v19.4.1
- registry1.dso.mil/gitlab/gitlab-org/build/cng/gitaly v19.3.2 -> v19.4.1
- registry1.dso.mil/gitlab/gitlab-org/build/cng/gitaly-init-cgroups v19.3.2 -> v19.4.1
- registry1.dso.mil/gitlab/gitlab-org/build/cng/gitlab-base v19.3.2 -> v19.4.1
- registry1.dso.mil/gitlab/gitlab-org/build/cng/gitlab-container-registry v4.40.2 -> v4.41.0
- registry1.dso.mil/gitlab/gitlab-org/build/cng/gitlab-exporter 16.9.0 -> 17.0.2
- registry1.dso.mil/gitlab/gitlab-org/build/cng/gitlab-geo-logcursor v19.3.2 -> v19.4.1
- registry1.dso.mil/gitlab/gitlab-org/build/cng/gitlab-kas v19.3.2 -> v19.4.1
- registry1.dso.mil/gitlab/gitlab-org/build/cng/gitlab-mailroom v19.3.2 -> v19.4.1
- registry1.dso.mil/gitlab/gitlab-org/build/cng/gitlab-pages v19.3.2 -> v19.4.1
- registry1.dso.mil/gitlab/gitlab-org/build/cng/gitlab-shell v14.56.1 -> v14.57.3
- registry1.dso.mil/gitlab/gitlab-org/build/cng/gitlab-sidekiq-ee v19.3.2 -> v19.4.1
- registry1.dso.mil/gitlab/gitlab-org/build/cng/gitlab-toolbox-ee v19.3.2 -> v19.4.1
- registry1.dso.mil/gitlab/gitlab-org/build/cng/gitlab-webservice-ee v19.3.2 -> v19.4.1
- registry1.dso.mil/gitlab/gitlab-org/build/cng/gitlab-workhorse-ee v19.3.2 -> v19.4.1
- registry1.dso.mil/gitlab/gitlab-org/build/cng/kubectl v19.3.2 -> v19.4.1
- registry1.dso.mil/gitlab/gitlab-org/modelops/applied-ml/code-suggestions/ai-assist/model-gateway self-hosted-v19.2.0-ee -> self-hosted-v19.4.1-ee
- registry1.dso.mil/ironbank/big-bang/cypress 16.0.0 -> 16.1.0
- registry1.dso.mil/ironbank/opensource/nginx/nginx 1.31.5 -> 1.31.6

Grafana

  • !8292: grafana update to 13.2.4-bb.0
  • !8250: grafana update to 12.10.0-bb.1
Click to show Changelog
# Changelog Updates

## [13.2.4-bb.0] (2026-09-22)
### Changed
- bb-common 1.4.0 -> 1.6.0
- gluon 1.1.6 -> 1.1.8
- grafana 12.10.0 -> 13.2.4 (matches the available Grafana 13.2.1 image)
- registry1.dso.mil/ironbank/big-bang/cypress 15.20.1 -> 15.21.1; align the Cypress runner, network-wait image, and image metadata. Defer Cypress 16 until Gluon's shared commands support the removal of `Cypress.env()`.
- registry1.dso.mil/ironbank/big-bang/grafana/grafana-plugins 13.1.0 -> 13.2.1
- registry1.dso.mil/ironbank/kiwigrid/k8s-sidecar 2.10.1 -> 2.11.2
- registry1.dso.mil/ironbank/opensource/grafana/grafana-image-renderer v5.12.1 -> v5.12.3
- Synced Kubernetes dashboards with upstream kube-prometheus-stack.

## [12.10.0-bb.1] (2026-09-10)
### Changed
- updated Cypress test to support Helm upgrade testing for SSO

Harbor

  • !8301: harbor update to 1.19.2-bb.2
Click to show Changelog
# Changelog Updates

## [1.19.2-bb.2] (2026-09-17)
### Changed
- Updated Cypress SSO tests to support upgrade runs.
- Added SSO test values using the quoted `cypress_sso_test_requested` marker.

Istio Cni

  • !8295: istioCNI update to 1.30.4-bb.1
Click to show Changelog
# Changelog Updates

## [1.30.4-bb.1] (2026-09-24)
### Changed
- Migrated upstream Helm chart repository to `https://blob.istio.io/istio-release/charts` ahead of the retirement of the Istio GCP-hosted endpoint

Istio Crds

  • !8296: istioCRDs update to 1.30.4-bb.1
Click to show Changelog
# Changelog Updates

## [1.30.4-bb.1] (2026-09-24)
### Changed
- Migrated upstream Helm chart repository to `https://blob.istio.io/istio-release/charts` ahead of the retirement of the Istio GCP-hosted endpoint

Istio Gateway

  • !8299: istioGateway update to 1.30.4-bb.1
Click to show Changelog
# Changelog Updates

## [1.30.4-bb.1] (2026-09-23)
### Changed
- Migrated upstream Helm chart repository to `https://blob.istio.io/istio-release/charts` ahead of the retirement of the Istio GCP-hosted endpoint

Istiod

  • !8298: istiod update to 1.30.4-bb.1
Click to show Changelog
# Changelog Updates

## [1.30.4-bb.1] (2026-09-23)
### Changed
- Migrated upstream Helm chart repository to `https://blob.istio.io/istio-release/charts` ahead of the retirement of the Istio GCP-hosted endpoint

Keycloak

  • !8280: keycloak update to 7.3.0-bb.2
  • !8270: keycloak update to 7.3.0-bb.1
Click to show Changelog
# Changelog Updates

## [7.3.0-bb.2] (2026-09-22)
### Changed
- Synced bb-common schema blocks (istio, networkPolicies, routes) with bb-common 1.6.0 via scripts/schema.sh
- Dropped `additionalProperties: false` from the istio schema block to tolerate umbrella-injected keys (`istio.injection`, `istio.hardened`); scripts/schema.sh restores it on resync, so this must be re-dropped after future syncs

## [7.3.0-bb.1] (2026-09-22)
### Changed
- bb-common 1.5.0 -> 1.6.0
- gluon 1.1.6 -> 1.1.8
- Updated hook templates to accept httpPort dynamically

Kiali

  • !8279: kiali update to 2.32.0-bb.0
  • !8263: kiali update to 2.31.0-bb.2
  • !8257: kiali update to 2.31.0-bb.1
Click to show Changelog
# Changelog Updates

## [2.32.0-bb.0] (2026-09-19)
### Changed
- bb-common 1.5.0 -> 1.6.0
- gluon 1.1.6 -> 1.1.8
- kiali-operator 2.31.0 -> 2.32.0
- registry1.dso.mil/ironbank/opensource/kiali/kiali v2.31.0 -> v2.32.0
- registry1.dso.mil/ironbank/opensource/kiali/kiali-operator v2.31.0 -> v2.32.0
- registry1.dso.mil/ironbank/opensource/kubernetes/kubectl v1.35 -> v1.37

## [2.31.0-bb.2] (2026-09-18)
### Changed
- Add SSO test values and validate authenticated Kiali access on initial and upgrade logins.

## [2.31.0-bb.1] (2026-09-15)
### Changed
- The registry1.dso.mil/ironbank/opensource/kubernetes/kubectl tag was changed to track the minor version rather than the patch version (1.35.8 -> 1.35).

### Changed
- updated Cypress test to pass the Keycloak URL to performKeycloakLogin

Loki

  • !8259: loki update to 6.55.0-bb.8
Click to show Changelog
# Changelog Updates

## [6.55.0-bb.7] (2026-09-16)
### Changed
- registry1.dso.mil/ironbank/opensource/kubernetes/kubectl is now referenced by its minor version tag rather than its patch version tag.

Mattermost

  • !8265: mattermost update to 11.11.0-bb.0
  • !8260: mattermost update to 11.10.1-bb.2
  • !8252: mattermost update to 11.10.1-bb.1
Click to show Changelog
# Changelog Updates

## [11.11.0-bb.0] (2026-09-18)
### Changed
- gluon 1.1.7 -> 1.1.8
- minio-instance 7.1.1-bb.20 -> 7.1.1-bb.24
- postgresql 18.11.1 -> 18.11.3
- registry1.dso.mil/ironbank/opensource/kubernetes/kubectl v1.36 -> v1.37
- registry1.dso.mil/ironbank/opensource/mattermost/mattermost 11.10.1 -> 11.11.0

## [11.10.1-bb.2] (2026-09-16)
### Changed
- Fixed the operator-sidecar image's condition in Chart.yaml's helm.sh/images annotaiton.
- Specified the minio image in the values file.

## [11.10.1-bb.1] (2026-09-16)
### Fixed
- Handle optional Keycloak login and consent screens during SSO upgrade tests and verify the authenticated Mattermost user.

Mattermost Operator

  • !8267: mattermostOperator update to 1.25.9-bb.1
Click to show Changelog
# Changelog Updates

## [1.25.9-bb.1] (2026-09-16)
### Changed
- No customer-facing changes, but some templates were moved to allow renovate to more easily automate updates.

Mimir

  • !8258: mimir update to 6.1.0-bb.2
Click to show Changelog
# Changelog Updates

## [6.1.0-bb.2] (2026-09-16)
### Changed
- Added the minio image to the chart's helm.sh/images annotation and specified it as a default in the values file.

Minio Operator

  • !8268: minioOperator update to 7.1.1-bb.11
  • !8242: minioOperator update to 7.1.1-bb.10
Click to show Changelog
# Changelog Updates

## [7.1.1-bb.11] (2026-09-18)
### Changed
- Added conditions for the tenant-wait-job, tenant-patch-job, and cypress images in the Chart.yaml's helm.sh/images annotation.
- Specified the cypress image in values.yaml.

Monitoring

  • !8288: monitoring update to 91.4.1-bb.1
  • !8283: monitoring update to 91.4.1-bb.0
Click to show Changelog
# Changelog Updates

## [91.4.1-bb.1] (2026-09-23)
### Fixed
- Resolve the Grafana metrics datasource by its stable UID so smoke tests support both Prometheus and Thanos display names.

## [91.4.1-bb.0] (2026-09-18)
### Changed
- bb-common 1.5.0 -> 1.6.0
- gluon 1.1.7 -> 1.1.8
- kube-prometheus-stack 88.6.2 -> 91.4.1
- prometheus-snmp-exporter 9.17.1 -> 9.18.0
- registry1.dso.mil/ironbank/big-bang/grafana/grafana-plugins 13.1.0 -> 13.2.1
- registry1.dso.mil/ironbank/kiwigrid/k8s-sidecar 2.10.3 -> 2.11.2
- registry1.dso.mil/ironbank/opensource/kubernetes/kubectl v1.35 -> v1.37
- registry1.dso.mil/ironbank/opensource/prometheus-operator/prometheus-config-reloader v0.93.1 -> v0.94.0
- registry1.dso.mil/ironbank/opensource/prometheus-operator/prometheus-operator v0.93.1 -> v0.94.0
- registry1.dso.mil/ironbank/opensource/prometheus/alertmanager v0.34.0 -> v0.34.1

Neuvector

  • !8278: neuvector update to 2.11.2-bb.0
  • !8262: neuvector update to 2.11.1-bb.1
Click to show Changelog
# Changelog Updates

## [2.11.2-bb.0] (2026-09-22)
### Changed
- bb-common 1.5.0 -> 1.6.0
- core 2.11.1 -> 2.11.2
- crd 2.11.1 -> 2.11.2
- gluon 1.1.7 -> 1.1.8
- monitor 2.11.1 -> 2.11.2
- registry1.dso.mil/ironbank/neuvector/neuvector/controller 5.6.1 -> 5.6.2
- registry1.dso.mil/ironbank/neuvector/neuvector/enforcer 5.6.1 -> 5.6.2
- registry1.dso.mil/ironbank/neuvector/neuvector/manager 5.6.1 -> 5.6.2
- registry1.dso.mil/ironbank/opensource/neuvector/registry-adapter v0.2.10 -> v0.2.11
- Synchronize the deployed core image tag and resolve upstream image readiness using NeuVector's Iron Bank tag mappings.

## [2.11.1-bb.2] (2026-09-18)
### Changed
- Specified the registry for the adapter and exporter image values to enable renovate updates using the built-in helm-values manager.
- Added the cypress image to the chart's values and to Chart.yaml's helm.sh/images annotation.

## [2.11.1-bb.1] (2026-09-17)
### Changed
- Cypress Updates to support SSO upgrade jobs

Renovate

  • !8291: renovate update to 46.316.0-bb.0
Click to show Changelog
# Changelog Updates

## [46.316.0-bb.0] (2026-09-23)
### Changed
- gluon 1.1.7 -> 1.1.8
- registry1.dso.mil/ironbank/container-hardening-tools/renovate/renovate 44.43.1 -> 44.97.2
- renovate 46.289.4 -> 46.316.0
- Added an explicit optional test `kubectl` image pin and metadata plus stable upstream release/documentation links

Sonarqube

  • !8276: sonarqube update to 2026.4.1-bb.4
  • !8266: sonarqube update to 2026.4.1-bb.3
  • !8254: sonarqube update to 2026.4.1-bb.2
Click to show Changelog
# Changelog Updates

## [2026.4.1-bb.4] (2026-09-22)
### Changed
- Changed the chart's appVersion to track the sonarqube image rather than the upstream chart version.

## [2026.4.1-bb.3] (2026-09-18)
### Changed
- bb-common 1.5.0 -> 1.6.0
- gluon 1.1.6 -> 1.1.8
- registry1.dso.mil/ironbank/sonarsource/sonarqube/sonarqube-community-build 26.8.0.126808 -> 26.9.0.129388
- Wait for SonarQube to become available before running Cypress checks during an upgrade.

## [2026.4.1-bb.2] (2026-09-16)
### Changed
- Support repeat Cypress SSO logins and verify the authenticated SonarQube account.
- Preserve SonarQube data during SSO upgrade tests.

Tempo

  • !8275: tempo update to 2.1.0-bb.3
Click to show Changelog
# Changelog Updates

## [2.1.0-bb.3] (2026-09-22)
### Changed
- Remove the deprecated `bigbang.dev/applicationVersions` chart annotation.
- Adding missing `kubectl` and `base` images to the `helm.sh/images` chart annotation.

Thanos

  • !8300: thanos update to 17.6.0-bb.3
  • !8281: thanos update to 17.6.0-bb.2
Click to show Changelog
# Changelog Updates

## [17.6.0-bb.3] (2026-09-25)
### Changed
- Updated Cypress Tests to support SSO upgrade CI jobs

## [17.6.0-bb.2] (2026-09-16)
### Changed
- bb-common 1.4.0 -> 1.6.0
- gluon 1.1.5 -> 1.1.8
- minio-instance 7.1.1-bb.15 -> 7.1.1-bb.24
- registry1.dso.mil/ironbank/opensource/kubernetes/kubectl v1.34 -> v1.37
- registry1.dso.mil/ironbank/opensource/thanos/thanos v0.42.2 -> v0.42.4

Twistlock

  • !8274: twistlock update to 0.30.0-bb.3
Click to show Changelog
# Changelog Updates

## [0.30.0-bb.3] (2026-09-17)
### Changed
- Update Cypress tests to allow for SSO upgrade jobs
- Use the CI realm's signing certificate for SSO tests and check the console license after login.

Vault

  • !8251: vault update to 0.34.1-bb.2
Click to show Changelog
# Changelog Updates

## [0.34.1-bb.2] (2026-09-15)
### Changed
- Updated cypress test to support SSO upgrade job
- Updated Gluon to 1.1.8 and removed the custom script network-wait override.
### Fixed
- Added Vault HTTPS 8200 routing for tests and Keycloak test-client callbacks.
- Skip script test resources when `bbtests.scripts.enabled` is false and remove extra YAML separators from script and Cypress test templates to prevent Flux post-render failures caused by incomplete or empty manifests.

Velero

  • !8289: velero update to 12.1.0-bb.5
Click to show Changelog
# Changelog Updates

## [12.1.0-bb.5] (2026-09-23)
### Changed
- Added missing conditions to the `helm.sh/images` chart annotation.

Ztunnel

  • !8297: ztunnel update to 1.30.4-bb.1
Click to show Changelog
# Changelog Updates

## [1.30.4-bb.1] (2026-09-23)
### Changed
- Migrated upstream Helm chart repository to `https://blob.istio.io/istio-release/charts` ahead of the retirement of the Istio GCP-hosted endpoint

As always, we welcome and appreciate feedback from our community of users. Please feel free to:

Future

Don’t see your feature and/or bug fix? Check out our epics for estimates on when you can expect things to drop, and as always, feel free to comment or create issues if you have questions, comments, or concerns.