This article provides an overview of bug fixes and the supported Fortanix Armor solutions in the Fortanix Armor Kubernetes Operator 27.0 Patch 3 release.
The Fortanix Armor Kubernetes Operator version is 1.0.554.
NOTE
Upgrading from Armor Operator 1.0.438 to later versions is not supported. To use 1.0.554 (Patch 3) if you are currently running version 1.0.438, you must perform a fresh installation.
Upgrading to 1.0.554 (Patch 3) from Armor Operator 1.0.480 or later is supported.
Existing Armor on-premises deployments must complete the Cassandra inter-node TLS certificate renewal procedure after upgrading to this version. For details, refer to Manually Renew Cassandra Inter-Node TLS CA and Leaf Certificates. This procedure is not required for fresh installations.
Bug Fixes
Fixed an issue where the service-to-service (S2S) certificate renewal job in the Fortanix Armor Kubernetes Operator was configured with an incorrect service account name (JIRA: PLAT-6647).
Fixed an issue where the S2S certificate renewal process used an incorrect service domain when checking certificate expiration, which could cause certificate renewal to be skipped (JIRA: PLAT-6655).
The Fortanix Armor Kubernetes Operator now automatically schedules regular restarts of the CCM service to ensure that renewed certificates are picked up without requiring manual rolling restarts (JIRA: PLAT-6654).
Installation
helm upgrade --install armor-platform-operator-chart \
oci://cr.download.fortanix.com/charts/armor-platform-operator \
--namespace "$OPERATOR_NAMESPACE" \
--no-hooks \
--version " 1.0.554"Solutions
For detailed instructions to deploy the Fortanix Armor Kubernetes Operator, refer to the Fortanix Armor Installation Guide-On-premises.