This article provides an overview of new features, improvements, bug fixes, and the supported Fortanix Armor solutions in the Fortanix Armor Kubernetes (k8s) Operator 28.0 release.
The Fortanix Armor Kubernetes Operator version is 28.0.5.
NOTE
Upgrading from Armor Kubernetes Operator 1.0.438 to later versions is not supported. To use 28.0.5, if you are currently running version 1.0.438, you must perform a fresh installation.
Upgrading to Armor Kubernetes Operator version 28.0.5 from 1.0.569 or later is supported.
CURRENT VERSION
TAREGT VERSION
UPGRADE
1.0.438
28.0.5
Not supported
1.0.569 or later
28.0.5
Supported
Downgrades of the Armor Kubernetes Operator are not supported from any version.
WARNING
Starting with Armor 28.0.5, the Armor Kubernetes Operator Helm chart no longer creates or manages the Cassandra inter-node TLS resources. Customers upgrading from an Armor Kubernetes Operator version earlier than 28.0.5 must preserve the existing resources before upgrading by applying the
helm.sh/resource-policy=keepannotation. For more information, refer to Upgrade Fortanix Armor - Preserve Customer-Managed Resources.When upgrading an existing Armor Kubernetes Operator deployment from version 1.0.480 or later to version 28.0.5 or later using Helm 4, add the
--server-side=falseargument to the helm upgrade command. This argument is required only for the first upgrade to Armor Kubernetes Operator 28.0.5 or later. For fresh installations, or when using Helm versions earlier than Helm 4, this argument is not required. See the Installation section below.After upgrading existing on-premises deployments from a version earlier than Armor Kubernetes Operator 28.0.5, a one-time manual Cassandra restart is required to apply the updated Cassandra configuration. Starting with version 28.0.5, the Cassandra deployment uses an updated network configuration that changes
hostNetworkfrom true to false. For detailed instructions, refer to Upgrade Fortanix Armor - Perform a one-time Cassandra Restart.
1. New Features
Support for On-Premises Deployments: The Fortanix Armor Kubernetes Operator now supports deploying Fortanix Armor in on-premises environments (JIRA: PLAT-6139).
2. Improvements
Cassandra inter-node TLS resources are now customer-managed. Starting with version 28.0.5, the Armor Kubernetes Operator Helm chart no longer creates or manages the Cassandra inter-node TLS resources. Customers are responsible for configuring and managing these resources. For detailed instructions, refer to Upgrade Fortanix Armor - Preserve Customer-Managed Resources (JIRA: PLAT-6701).
3. Bug Fixes
Fixed an issue where the Armor Kubernetes Operator used a hardcoded cluster-issuer for Cassandra inter-node TLS certificates instead of using the issuer configured in the
spec.database.issuerReffield of theArmorPlatformresource (JIRA: PLAT-6526).
4. Installation
Fresh Installations:
helm upgrade --install armor-platform-operator-chart \
oci://cr.download.fortanix.com/charts/armor-platform-operator \
--namespace "$OPERATOR_NAMESPACE" \
--no-hooks \
--version " 28.0.5" For upgrades using Helm 4: If you are upgrading an existing Armor Kubernetes Operator deployment from version 1.0.480 or later to 28.0.5 or later, add --server-side=false to the command:
helm upgrade --install armor-platform-operator-chart \
oci://cr.download.fortanix.com/charts/armor-platform-operator \
--namespace "$OPERATOR_NAMESPACE" \
--no-hooks \
--version "28.0.5" \
--server-side=false For more information, refer to Upgrade Fortanix Armor – Upgrade Using Helm 4.
5. Solutions
For detailed instructions to deploy the Fortanix Armor Kubernetes Operator, refer to Fortanix Armor Installation Guide-On-premises.