Sitelet https://github.com/kubernetes/kops/pull/18601
Skip to content

Remove support for gossip DNS - #18601

Merged
kubernetes-prow[bot] merged 8 commits into
kubernetes:masterfrom
hakman:remove-gossip-dns
Jul 30, 2026
Merged

kubernetes-prow[bot] merged 8 commits into
kubernetes:masterfrom
hakman:remove-gossip-dns

Conversation

@hakman

@hakman hakman commented Jul 16, 2026 •

Copy link
Copy Markdown
Member

Support for gossip DNS, deprecated since kOps 1.29, is removed in kOps 1.37, see #18240.

New gossip clusters are rejected, and existing clusters need to migrate before they can be upgraded. This affects clusters whose name ends in .k8s.local and that were not created with --dns=none; clusters using --dns=none, even with a .k8s.local name, are not affected. Migrate to --dns=none or a hosted DNS zone using kOps 1.36, which introduced hybrid bootstrap to make that migration easier.

What changed

  • Cluster validation rejects legacy gossip clusters with an actionable error. Since validation runs on all write paths, this blocks kops create and kops update cluster, while kops get, kops delete cluster, kops validate cluster, and an edit/replace that switches the cluster to dns: none keep working for unmigrated clusters.
  • Nodes no longer download, install or run protokube, whose only remaining responsibility was gossip DNS. The protokube binary itself is still built and shipped; removing it is left for a follow-up.
  • dns-controller loses its gossip provider mode and flags. The AWS China special case that passed --dns=gossip (effectively running dns-controller with no provider) is removed; AWS now always uses aws-route53.
  • kops-controller loses the hosts controller and its discovery options, along with the corresponding RBAC and headless services in the addon manifest.
  • The spec.gossipConfig and spec.dnsControllerGossipConfig cluster spec fields are removed from all API versions. Old stored specs still load, as unknown fields are dropped on decode.
  • Gossip firewall rules and the dns-controller gossip ports are removed. The worker node IAM role no longer receives the S3 and ec2:DescribeInstances permissions that legacy gossip bootstrap required.
  • Gossip integration tests and fixtures are removed. The minimal_openstack, openstack_floatingip and minimal_scaleway fixtures migrate to dns=none, as they are the only integration test coverage for their clouds.
  • Documentation is updated and the gossip page is rewritten as a migration guide; 1.37 release notes are added.

Notes for reviewers

  • The Azure DenyNodesToEtcd NSG rule narrows from port range 4000-4001 to just 4001, as 4000 was the protokube memberlist port.
  • The upgrade-ab-gossip e2e scenario is deleted; the corresponding prow job needs to be removed in test-infra.
  • The expected output regeneration is in its own commit, generated with ./hack/update-expected.sh.

/cc @rifelpet @justinsb

@kubernetes-prow
kubernetes-prow Bot requested a review from justinsb July 16, 2026 10:51
@kubernetes-prow kubernetes-prow Bot added the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Jul 16, 2026
@kubernetes-prow
kubernetes-prow Bot requested a review from rifelpet July 16, 2026 10:51
@kubernetes-prow kubernetes-prow Bot added cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. size/XXL Denotes a PR that changes 1000+ lines, ignoring generated files. area/addons area/api area/documentation area/kops-controller area/nodeup area/provider/azure Issues or PRs related to azure provider area/provider/digitalocean Issues or PRs related to digitalocean provider area/provider/gcp Issues or PRs related to gcp provider area/provider/openstack Issues or PRs related to openstack provider labels Jul 16, 2026
@hakman
hakman force-pushed the remove-gossip-dns branch 2 times, most recently from 40d517c to cc60d82 Compare July 16, 2026 11:07
@hakman hakman changed the title WIP Remove support for gossip DNS Remove support for gossip DNS Jul 16, 2026
@kubernetes-prow kubernetes-prow Bot removed the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Jul 16, 2026
@hakman

hakman commented Jul 16, 2026

Copy link
Copy Markdown
Member Author

/test all

@hakman

hakman commented Jul 16, 2026

Copy link
Copy Markdown
Member Author

/retest

@hakman

hakman commented Jul 16, 2026

Copy link
Copy Markdown
Member Author

CSI flakes...
/override pull-kops-e2e-azure-cni-calico

@kubernetes-prow

Copy link
Copy Markdown
Contributor

@hakman: Overrode contexts on behalf of hakman: pull-kops-e2e-azure-cni-calico

Details

In response to this:

CSI flakes...
/override pull-kops-e2e-azure-cni-calico

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@rifelpet

Copy link
Copy Markdown
Member

/approve

i'll let someone else take a pass too since it is so large.

@kubernetes-prow kubernetes-prow Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Jul 22, 2026
@hakman

hakman commented Jul 23, 2026

Copy link
Copy Markdown
Member Author

Thanks @rifelpet!
/assign @justinsb

@hakman

hakman commented Jul 23, 2026

Copy link
Copy Markdown
Member Author

i'll let someone else take a pass too since it is so large.

@rifelpet quite right on this one, so decided to revert some of the mechanical changes to make it more reviewable.

@hakman

hakman commented Jul 23, 2026

Copy link
Copy Markdown
Member Author

/test pull-kops-e2e-cni-cilium-etcd

@hakman

hakman commented Jul 23, 2026

Copy link
Copy Markdown
Member Author

/test pull-kops-e2e-cni-cilium-etcd

@kubernetes-prow kubernetes-prow Bot added the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Jul 28, 2026
@hakman
hakman force-pushed the remove-gossip-dns branch from 20cb470 to c2c893f Compare July 29, 2026 06:16
@kubernetes-prow kubernetes-prow Bot removed the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Jul 29, 2026
hakman added 8 commits July 29, 2026 09:17
Gossip DNS support is removed in kOps 1.37. Clusters whose name ends in
.k8s.local without dns=none now fail validation with a message pointing
at the migration path, and the deprecated gossipConfig and
dnsControllerGossipConfig fields are rejected with an error asking for
their removal. kops create cluster keeps defaulting .k8s.local names to
dns=none.
Nodes no longer install or run protokube, whose only remaining
responsibility was gossip DNS. Remove the gossip mode from
dns-controller, the hosts controller and discovery options from
kops-controller, the gossip branches from nodeup and the cluster model,
and the gossip firewall rules. The gossipConfig and
dnsControllerGossipConfig cluster spec fields are deprecated, no longer
have any effect, and are rejected by validation when set.

The protokube binary itself is still built and shipped; removing it is
left for a separate change.
The minimal_openstack, openstack_floatingip and minimal_scaleway
fixtures migrate to dns=none, as they are the only integration test
coverage for their clouds.
Generated with ./hack/update-expected.sh
Keep the deprecated nodeup wire field temporarily to avoid rewriting generated nodeup configs while gossip runtime support remains removed.
Keep control-plane nodeup asset lists and hashes stable temporarily while leaving the protokube model and service removed.
Leave the unregistered gossip fixtures in place temporarily so their bulk deletion can be reviewed and merged separately.
@hakman
hakman force-pushed the remove-gossip-dns branch from c2c893f to b645998 Compare July 29, 2026 06:21
@hakman

hakman commented Jul 29, 2026

Copy link
Copy Markdown
Member Author

/test all

@hakman

hakman commented Jul 29, 2026

Copy link
Copy Markdown
Member Author

/test pull-kops-e2e-cni-cilium

for _, a := range n.protokubeAsset[arch] {
config.Assets[arch] = append(config.Assets[arch], a.CompactString())
}
// Keep protokube in control-plane nodeup configs temporarily to avoid changing

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm guessing we're going to tackle this in a follow-on PR, but it would make this one huge?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yup, too many files in this PR and make GitHub hard to use.

@kubernetes-prow kubernetes-prow Bot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Jul 30, 2026
@justinsb

Copy link
Copy Markdown
Member

Thanks @hakman

Looking at this, there are quite a few pitfalls and complexity! So if anyone is still on gossip, I think they will be much happier on dns=none at this point. Removal seems like the right call.

/approve
/lgtm

@kubernetes-prow

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: justinsb, rifelpet

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@hakman

hakman commented Jul 30, 2026

Copy link
Copy Markdown
Member Author

Thanks @justinsb, hope everyone will migrate safely using kOps 1.36.

@hakman

hakman commented Jul 30, 2026

Copy link
Copy Markdown
Member Author

/override pull-kops-e2e-cni-amazonvpc

@kubernetes-prow

Copy link
Copy Markdown
Contributor

@hakman: Overrode contexts on behalf of hakman: pull-kops-e2e-cni-amazonvpc

Details

In response to this:

/override pull-kops-e2e-cni-amazonvpc

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@kubernetes-prow
kubernetes-prow Bot merged commit 4616ced into kubernetes:master Jul 30, 2026
42 checks passed
@hakman
hakman deleted the remove-gossip-dns branch July 30, 2026 15:44
This was referenced Jul 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. area/addons area/api area/documentation area/kops-controller area/nodeup area/provider/azure Issues or PRs related to azure provider area/provider/digitalocean Issues or PRs related to digitalocean provider area/provider/gcp Issues or PRs related to gcp provider area/provider/openstack Issues or PRs related to openstack provider cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. lgtm "Looks good to me", indicates that a PR is ready to be merged. size/XXL Denotes a PR that changes 1000+ lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants