Sitelet https://github.com/kubernetes/kops/pull/18523
Skip to content

Automated cherry pick of #18522: azure: Scope nodes-to-API NSG rules to the NAT gateway public IP - #18523

Merged
kubernetes-prow[bot] merged 1 commit into
kubernetes:release-1.36from
hakman:automated-cherry-pick-of-#18522-upstream-release-1.36
Jul 2, 2026
Merged

kubernetes-prow[bot] merged 1 commit into
kubernetes:release-1.36from
hakman:automated-cherry-pick-of-#18522-upstream-release-1.36

Conversation

@hakman

@hakman hakman commented Jul 2, 2026

Copy link
Copy Markdown
Member

Cherry pick of #18522 on release-1.36.

#18522: azure: Scope nodes-to-API NSG rules to the NAT gateway public IP

For details on the cherry pick process, see the cherry pick requests page.

What type of PR is this?


The AllowNodesToKubernetesAPI and AllowNodesToKopsController rules
allowed any source, which bypassed the spec.api.access allowlist on
port 443 and exposed kops-controller to the internet on clusters with
a public API load balancer. Node traffic to the public frontend
egresses through the NAT gateway, so its public IP is the only source
these rules need.
@kubernetes-prow kubernetes-prow Bot added this to the v1.36 milestone Jul 2, 2026
@kubernetes-prow kubernetes-prow Bot added cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. size/L Denotes a PR that changes 100-499 lines, ignoring generated files. labels Jul 2, 2026
@kubernetes-prow
kubernetes-prow Bot requested review from olemarkus and zetaab July 2, 2026 06:08
@kubernetes-prow kubernetes-prow Bot added the area/provider/azure Issues or PRs related to azure provider label Jul 2, 2026
@hakman

hakman commented Jul 2, 2026

Copy link
Copy Markdown
Member Author

/cc @rifelpet @ameukam
/approve

@kubernetes-prow
kubernetes-prow Bot requested review from ameukam and rifelpet July 2, 2026 08:27
@kubernetes-prow

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: hakman

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@kubernetes-prow kubernetes-prow Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Jul 2, 2026
@ameukam

ameukam commented Jul 2, 2026

Copy link
Copy Markdown
Member

/lgtm

@kubernetes-prow kubernetes-prow Bot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Jul 2, 2026
@kubernetes-prow
kubernetes-prow Bot merged commit 2879859 into kubernetes:release-1.36 Jul 2, 2026
18 checks passed
social4hyq pushed a commit to social4hyq/homebrew-core that referenced this pull request Sep 20, 2026
kops 1.36.0

Created-by: HarmonybrewBot
Commit-by: HarmonybrewBot
Merged-by: HarmonybrewBot
Description: Created by `brew bump`

---

Created with `brew bump-formula-pr`.<details>
  <summary>release notes</summary>
  <pre>See the full [kOps 1.36 release notes](https://kops.sigs.k8s.io/releases/1.36-notes/) for details, including breaking changes and deprecations.

## Highlights

* **Kubernetes 1.36 support** and completion of the move away from the in-tree cloud providers
* **Reworked addon management**: `kops-channels` now runs as a static pod on control-plane nodes; the standalone `channels` binary is no longer distributed
* **Hybrid bootstrap for gossip clusters**: workers bootstrap directly against the API load balancer, easing migration off gossip DNS, which is deprecated
* **Karpenter refresh**: Karpenter v1.13.0 with kOps-managed `EC2NodeClass` and `NodePool` objects per instance group
* **etcd-manager improvements**: recovery of members with replaced data disks, membership changes resilient to unreachable members, a distroless image, and faster single-member cluster startup
* **Expanded Azure support**: cloud-controller-manager, Azure Disk CSI driver, and experimental Terraform target
* **Hetzner Cluster Autoscaler support** and groundwork for Linode (Akamai) as a new cloud provider
* **Component updates**: containerd v2.2.4, etcd-manager v3.0.20260707 with etcd 3.5.31/3.6.12, AWS Load Balancer Controller v3.3.0, Cilium tunables, CoreDNS v1.14.2, cluster-autoscaler v1.36.0
* **Removed**: support for Kubernetes 1.30, etcd 3.4, Amazon Linux 2, Ubuntu 20.04, and Debian 10

## What's Changed
* Automated cherry pick of #18467: aws: Reconcile target group health check changes on existing target groups by @hakman in kubernetes/kops#18469
* Automated cherry pick of #18484: gce: emit kops.k8s.io/instancegroup node label by @rifelpet in kubernetes/kops#18488
* Automated cherry pick of #18478: nodeup: load ip_set module and disable firewalld on RHEL10 by @rifelpet in kubernetes/kops#18492
* Automated cherry pick of #18498: Remove namespace from DO ClusterRole by @rifelpet in kubernetes/kops#18499
* Automated cherry pick of #18511: Allow setting missing slice elements from the command line by @hakman in kubernetes/kops#18512
* Automated cherry pick of ##18479: Upgrade Karpenter to v1.13.0 
##18486: Register Karpenter nodes with karpenter.sh/unregistered taint
##18487: Add missing EC2 read permissions to Karpenter IAM policy
##18497: Add managed Karpenter EC2NodeClass and NodePool by @hakman in kubernetes/kops#18513
* Automated cherry pick of #18522: azure: Scope nodes-to-API NSG rules to the NAT gateway public IP by @hakman in kubernetes/kops#18523
* Automated cherry pick of #18527: azure: Bump azuredisk-csi-driver to v1.34.4 by @hakman in kubernetes/kops#18528
* Automated cherry pick of #18529: azure: Bump azure-cloud-controller-manager to v1.36.2 by @hakman in kubernetes/kops#18531
* Automated cherry pick of #18533: azure: Grant control-plane VMSS Contributor instead of Owner by @hakman in kubernetes/kops#18534
* Automated cherry pick of #18535: coredns: Honor node taints in hostname topologySpreadConstraint by @hakman in kubernetes/kops#18536
* Automated cherry pick of #18538: hetzner: fix Cluster Autoscaler node group membership by @hakman in kubernetes/kops#18539
* Automated cherry pick of #18541: Update cluster-autoscaler to v1.36.0 by @hakman in kubernetes/kops#18542
* Automated cherry pick of #18543: gce: register all zonal MIGs of a multi-zone instance group with cluster-autoscaler by @hakman in kubernetes/kops#18544
* Automated cherry pick of #18546: Update Go to 1.26.5 and bump golang.org/x modules by @hakman in kubernetes/kops#18547
* Cherry pick of #18560: etcd-manager: upgrade to v3.0.20260707 by @hakman in kubernetes/kops#18561
* Automated cherry pick of #18556: feat(api): add storageInitializationTimeout to KubeAPIServerConfig by @hakman in kubernetes/kops#18558
* Cherry pick of #18549: Replace fi.PtrTo with new() builtin by @hakman in kubernetes/kops#18551
* Automated cherry pick of #18567: dns-controller: always apply the addon, empty when unused by @hakman in kubernetes/kops#18573
* Release 1.36.0 by @hakman in kubernetes/kops#18591


**Full Changelog**: https://github.com/kubernetes/kops/compare/v1.36.0-beta.1...v1.36.0</pre>
  <p>View the full release notes at <a href="/sitelet?url=https%3A%2F%2Fgithub.com%2Fkubernetes%2Fkops%2Fpull%2F%253Ca%2520href%3D"https://github.com/kubernetes/kops/releases/tag/v1.36.0">https://github.com/kubernetes/kops/releases/tag/v1.36.0</a>.</p">https://github.com/kubernetes/kops/releases/tag/v1.36.0">https://github.com/kubernetes/kops/releases/tag/v1.36.0</a>.</p>
</details>
<hr>

See merge request: Harmonybrew/homebrew-core!14334
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. area/provider/azure Issues or PRs related to azure provider cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. lgtm "Looks good to me", indicates that a PR is ready to be merged. size/L Denotes a PR that changes 100-499 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants