diff --git a/calico-enterprise/getting-started/install-on-clusters/kubernetes/helm.mdx b/calico-enterprise/getting-started/install-on-clusters/kubernetes/helm.mdx index 129c37d4fb..d6f2e79b4c 100644 --- a/calico-enterprise/getting-started/install-on-clusters/kubernetes/helm.mdx +++ b/calico-enterprise/getting-started/install-on-clusters/kubernetes/helm.mdx @@ -95,8 +95,16 @@ To install a standard $[prodname] cluster with Helm: 1. Install the necessary custom resource definitions. + If your cluster is based on Kubernetes 1.36 or later: + + ```bash + helm template calico-crds projectcalico.org.v3-$[chart_version_name].tgz --api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy | kubectl apply --server-side -f - + ``` + + If your cluster is based on Kubernetes 1.34 or 1.35: + ```bash - helm template calico-crds projectcalico.org.v3-$[chart_version_name].tgz --validate | kubectl apply --server-side -f - + helm template calico-crds projectcalico.org.v3-$[chart_version_name].tgz --api-versions admissionregistration.k8s.io/v1beta1/MutatingAdmissionPolicy | kubectl apply --server-side -f - ``` 1. Install the Tigera Operator using the Helm 3 chart: diff --git a/calico-enterprise/operations/native-v3-crds.mdx b/calico-enterprise/operations/native-v3-crds.mdx index 3c2e7fbc9b..0793b77988 100644 --- a/calico-enterprise/operations/native-v3-crds.mdx +++ b/calico-enterprise/operations/native-v3-crds.mdx @@ -32,12 +32,12 @@ When using native `projectcalico.org/v3` CRDs: ### Validation and defaulting -When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/validating-admission-policy/) for defaulting, which require the beta `admissionregistration.k8s.io/v1beta1` API. That API is available in **Kubernetes 1.34 and later**. On Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API (`v1alpha1`), which $[prodname] does not support. On Kubernetes 1.34 and 1.35, you must enable the `MutatingAdmissionPolicy` feature gate on your Kubernetes API server before using native `projectcalico.org/v3` CRDs, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/mutating-admission-policy/) for defaulting, which require **Kubernetes 1.34 or later**: the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. On Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API (`v1alpha1`), which $[prodname] does not support. On Kubernetes 1.34 and 1.35, you must enable the `MutatingAdmissionPolicy` feature gate on your Kubernetes API server before using native `projectcalico.org/v3` CRDs, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. ## Before you begin - A Kubernetes cluster **without** $[prodname] installed, or a cluster where you are performing a fresh install. To migrate an existing cluster from API server mode, see [Migrate from API server to native CRDs](crd-migration.mdx). -- **Kubernetes 1.34 or later.** $[prodname] uses the beta `admissionregistration.k8s.io/v1beta1` MutatingAdmissionPolicy API for defaulting, which is not available on Kubernetes 1.33 and earlier (where MutatingAdmissionPolicy is alpha only). On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the API server, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +- **Kubernetes 1.34 or later.** $[prodname] uses MutatingAdmissionPolicies for defaulting, which need the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. Neither is available on Kubernetes 1.33 and earlier (where MutatingAdmissionPolicy is alpha only). On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the API server, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. import Tabs from '@theme/Tabs'; import TabItem from '@theme/TabItem'; diff --git a/calico-enterprise_versioned_docs/version-3.23-2/operations/native-v3-crds.mdx b/calico-enterprise_versioned_docs/version-3.23-2/operations/native-v3-crds.mdx index ce0c88c9fc..8ed6b5f0b1 100644 --- a/calico-enterprise_versioned_docs/version-3.23-2/operations/native-v3-crds.mdx +++ b/calico-enterprise_versioned_docs/version-3.23-2/operations/native-v3-crds.mdx @@ -38,7 +38,7 @@ When using native `projectcalico.org/v3` CRDs: ### Validation and defaulting -When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/validating-admission-policy/) for defaulting, which require the beta `admissionregistration.k8s.io/v1beta1` API. That API is available in **Kubernetes 1.34 and later**. On Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API (`v1alpha1`), which $[prodname] does not support. On Kubernetes 1.34 and 1.35, you must enable the `MutatingAdmissionPolicy` feature gate on your Kubernetes API server before using native `projectcalico.org/v3` CRDs, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/mutating-admission-policy/) for defaulting, which require the beta `admissionregistration.k8s.io/v1beta1` API. That API is available in **Kubernetes 1.34 and later**. On Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API (`v1alpha1`), which $[prodname] does not support. On Kubernetes 1.34 and 1.35, you must enable the `MutatingAdmissionPolicy` feature gate on your Kubernetes API server before using native `projectcalico.org/v3` CRDs, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. ## Before you begin diff --git a/calico-enterprise_versioned_docs/version-3.24-1/operations/native-v3-crds.mdx b/calico-enterprise_versioned_docs/version-3.24-1/operations/native-v3-crds.mdx index 8f45e925fa..515cb2216e 100644 --- a/calico-enterprise_versioned_docs/version-3.24-1/operations/native-v3-crds.mdx +++ b/calico-enterprise_versioned_docs/version-3.24-1/operations/native-v3-crds.mdx @@ -32,7 +32,7 @@ When using native `projectcalico.org/v3` CRDs: ### Validation and defaulting -When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/validating-admission-policy/) for defaulting, which require **Kubernetes 1.32 or later**. On clusters where the `MutatingAdmissionPolicy` API is not enabled by default, you must enable the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) on the Kubernetes API server. +When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/mutating-admission-policy/) for defaulting, which require **Kubernetes 1.32 or later**. On clusters where the `MutatingAdmissionPolicy` API is not enabled by default, you must enable the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) on the Kubernetes API server. ## Before you begin diff --git a/calico-enterprise_versioned_docs/version-3.24-2/operations/native-v3-crds.mdx b/calico-enterprise_versioned_docs/version-3.24-2/operations/native-v3-crds.mdx index 8f45e925fa..515cb2216e 100644 --- a/calico-enterprise_versioned_docs/version-3.24-2/operations/native-v3-crds.mdx +++ b/calico-enterprise_versioned_docs/version-3.24-2/operations/native-v3-crds.mdx @@ -32,7 +32,7 @@ When using native `projectcalico.org/v3` CRDs: ### Validation and defaulting -When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/validating-admission-policy/) for defaulting, which require **Kubernetes 1.32 or later**. On clusters where the `MutatingAdmissionPolicy` API is not enabled by default, you must enable the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) on the Kubernetes API server. +When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/mutating-admission-policy/) for defaulting, which require **Kubernetes 1.32 or later**. On clusters where the `MutatingAdmissionPolicy` API is not enabled by default, you must enable the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) on the Kubernetes API server. ## Before you begin diff --git a/calico/getting-started/kubernetes/helm.mdx b/calico/getting-started/kubernetes/helm.mdx index 5aa2066663..7d998f1fe4 100644 --- a/calico/getting-started/kubernetes/helm.mdx +++ b/calico/getting-started/kubernetes/helm.mdx @@ -81,8 +81,16 @@ For more information about configurable options via `values.yaml` please see [He 1. Install the necessary custom resource definitions. + If your cluster is based on Kubernetes 1.36 or later: + + ```bash + helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy | kubectl apply --server-side -f - + ``` + + If your cluster is based on Kubernetes 1.34 or 1.35: + ```bash - helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --validate | kubectl apply --server-side -f - + helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --api-versions admissionregistration.k8s.io/v1beta1/MutatingAdmissionPolicy | kubectl apply --server-side -f - ``` 1. Install the Tigera Operator using the Helm chart: diff --git a/calico/getting-started/kubernetes/self-managed-onprem/onpremises.mdx b/calico/getting-started/kubernetes/self-managed-onprem/onpremises.mdx index 86d8383d1f..005095c579 100644 --- a/calico/getting-started/kubernetes/self-managed-onprem/onpremises.mdx +++ b/calico/getting-started/kubernetes/self-managed-onprem/onpremises.mdx @@ -148,7 +148,7 @@ If you're setting up a new cluster and don't need to customize the underlying Ku ::: -Native `projectcalico.org/v3` CRDs rely on MutatingAdmissionPolicies for defaulting, which require the beta `admissionregistration.k8s.io/v1beta1` API. That API is available in **Kubernetes 1.34 and later**; on Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API and is not supported. On Kubernetes 1.34 and 1.35, enable the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) on the Kubernetes API server before installing, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +Native `projectcalico.org/v3` CRDs rely on MutatingAdmissionPolicies for defaulting, which require **Kubernetes 1.34 or later**: the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later; on Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API and is not supported. On Kubernetes 1.34 and 1.35, enable the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) on the Kubernetes API server before installing, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. 1. Download the $[prodname] v3 CRD manifest. @@ -244,7 +244,7 @@ If you have an existing manifest-based $[prodname] install using the legacy `crd - $[prodname] installed via `calico.yaml` manifest (not operator) - `kubectl` access to the cluster - A recent $[prodname] version that includes the migration controller -- **Kubernetes 1.34 or later.** Native `projectcalico.org/v3` CRDs rely on MutatingAdmissionPolicies for defaulting, which require the beta `admissionregistration.k8s.io/v1beta1` API. That API is not available on Kubernetes 1.33 and earlier, where MutatingAdmissionPolicy is alpha only. On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the Kubernetes API server before starting the migration, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +- **Kubernetes 1.34 or later.** Native `projectcalico.org/v3` CRDs rely on MutatingAdmissionPolicies for defaulting, which need the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. Neither is available on Kubernetes 1.33 and earlier, where MutatingAdmissionPolicy is alpha only. On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the Kubernetes API server before starting the migration, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. #### Migration steps diff --git a/calico/operations/native-v3-crds.mdx b/calico/operations/native-v3-crds.mdx index 8cd4b5355d..1bab6357ea 100644 --- a/calico/operations/native-v3-crds.mdx +++ b/calico/operations/native-v3-crds.mdx @@ -32,12 +32,12 @@ When using native `projectcalico.org/v3` CRDs: ### Validation and defaulting -When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/validating-admission-policy/) for defaulting, which require the beta `admissionregistration.k8s.io/v1beta1` API. That API is available in **Kubernetes 1.34 and later**. On Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API (`v1alpha1`), which $[prodname] does not support. On Kubernetes 1.34 and 1.35, you must enable the `MutatingAdmissionPolicy` feature gate on your Kubernetes API server before using native `projectcalico.org/v3` CRDs, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/mutating-admission-policy/) for defaulting, which require **Kubernetes 1.34 or later**: the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. On Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API (`v1alpha1`), which $[prodname] does not support. On Kubernetes 1.34 and 1.35, you must enable the `MutatingAdmissionPolicy` feature gate on your Kubernetes API server before using native `projectcalico.org/v3` CRDs, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. ## Before you begin - A Kubernetes cluster **without** $[prodname] installed, or a cluster where you are performing a fresh install. To migrate an existing cluster from API server mode, see [Migrate from API server to native CRDs](crd-migration.mdx). -- **Kubernetes 1.34 or later.** $[prodname] uses the beta `admissionregistration.k8s.io/v1beta1` MutatingAdmissionPolicy API for defaulting, which is not available on Kubernetes 1.33 and earlier (where MutatingAdmissionPolicy is alpha only). On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the API server, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +- **Kubernetes 1.34 or later.** $[prodname] uses MutatingAdmissionPolicies for defaulting, which need the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. Neither is available on Kubernetes 1.33 and earlier (where MutatingAdmissionPolicy is alpha only). On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the API server, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. import Tabs from '@theme/Tabs'; import TabItem from '@theme/TabItem'; @@ -63,10 +63,18 @@ Select the method below based on your preferred installation method. kubectl create namespace tigera-operator ``` -1. Install the v3 CRD chart instead of the default v1 CRD chart: +1. Install the v3 CRD chart instead of the default v1 CRD chart. + + If your cluster is based on Kubernetes 1.36 or later: + + ```bash + helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy | kubectl apply --server-side -f - + ``` + + If your cluster is based on Kubernetes 1.34 or 1.35: ```bash - helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --validate | kubectl apply --server-side -f - + helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --api-versions admissionregistration.k8s.io/v1beta1/MutatingAdmissionPolicy | kubectl apply --server-side -f - ``` :::note diff --git a/calico/operations/upgrading/kubernetes-upgrade.mdx b/calico/operations/upgrading/kubernetes-upgrade.mdx index 49ea7468da..fc9350254a 100644 --- a/calico/operations/upgrading/kubernetes-upgrade.mdx +++ b/calico/operations/upgrading/kubernetes-upgrade.mdx @@ -73,6 +73,8 @@ To apply the CRDs yourself: The commands above apply the v1 CRDs, which is correct for clusters using the aggregation API server (the common case). If your cluster uses native v3 CRDs, substitute `v3_projectcalico_org.yaml` for `v1_crd_projectcalico_org.yaml`, or the `projectcalico/projectcalico.org.v3` chart for `projectcalico/crd.projectcalico.org.v1`. + When templating the v3 chart on Kubernetes 1.36 and later, also add `--api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy`; without it, Helm renders the MutatingAdmissionPolicy resources at `v1beta1`, which Kubernetes 1.36 does not serve. + ::: 1. Run the Helm upgrade: diff --git a/calico_versioned_docs/version-3.32/getting-started/kubernetes/helm.mdx b/calico_versioned_docs/version-3.32/getting-started/kubernetes/helm.mdx index 7c3f78c022..154e50a199 100644 --- a/calico_versioned_docs/version-3.32/getting-started/kubernetes/helm.mdx +++ b/calico_versioned_docs/version-3.32/getting-started/kubernetes/helm.mdx @@ -87,10 +87,18 @@ For more information about configurable options via `values.yaml` please see [He :::tip - To install with [native v3 CRDs](../../operations/native-v3-crds.mdx) (tech preview) instead, use the v3 CRD chart: + To install with [native v3 CRDs](../../operations/native-v3-crds.mdx) (tech preview) instead, use the v3 CRD chart. + + If your cluster is based on Kubernetes 1.36 or later: + + ```bash + helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy | kubectl apply --server-side -f - + ``` + + If your cluster is based on Kubernetes 1.34 or 1.35: ```bash - helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] | kubectl apply --server-side -f - + helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --api-versions admissionregistration.k8s.io/v1beta1/MutatingAdmissionPolicy | kubectl apply --server-side -f - ``` Native v3 CRDs eliminate the need for the aggregation API server and allows `kubectl` to manage `projectcalico.org/v3` resources directly. diff --git a/calico_versioned_docs/version-3.32/getting-started/kubernetes/self-managed-onprem/onpremises.mdx b/calico_versioned_docs/version-3.32/getting-started/kubernetes/self-managed-onprem/onpremises.mdx index fa1f005304..11a70a07c7 100644 --- a/calico_versioned_docs/version-3.32/getting-started/kubernetes/self-managed-onprem/onpremises.mdx +++ b/calico_versioned_docs/version-3.32/getting-started/kubernetes/self-managed-onprem/onpremises.mdx @@ -135,7 +135,7 @@ If you're setting up a new cluster and don't need to customize the underlying Ku ::: -Native `projectcalico.org/v3` CRDs rely on MutatingAdmissionPolicies for defaulting, which require the beta `admissionregistration.k8s.io/v1beta1` API. That API is available in **Kubernetes 1.34 and later**; on Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API and is not supported. On Kubernetes 1.34 and 1.35, enable the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) on the Kubernetes API server before installing, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +Native `projectcalico.org/v3` CRDs rely on MutatingAdmissionPolicies for defaulting, which require **Kubernetes 1.34 or later**: the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later; on Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API and is not supported. On Kubernetes 1.34 and 1.35, enable the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) on the Kubernetes API server before installing, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. 1. Download the $[prodname] v3 CRD manifest. @@ -223,7 +223,7 @@ If you have an existing manifest-based $[prodname] install using the legacy `crd - $[prodname] installed via `calico.yaml` manifest (not operator) - `kubectl` access to the cluster - A recent $[prodname] version that includes the migration controller -- **Kubernetes 1.34 or later.** Native `projectcalico.org/v3` CRDs rely on MutatingAdmissionPolicies for defaulting, which require the beta `admissionregistration.k8s.io/v1beta1` API. That API is not available on Kubernetes 1.33 and earlier, where MutatingAdmissionPolicy is alpha only. On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the Kubernetes API server before starting the migration, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +- **Kubernetes 1.34 or later.** Native `projectcalico.org/v3` CRDs rely on MutatingAdmissionPolicies for defaulting, which need the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. Neither is available on Kubernetes 1.33 and earlier, where MutatingAdmissionPolicy is alpha only. On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the Kubernetes API server before starting the migration, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. #### Migration steps diff --git a/calico_versioned_docs/version-3.32/operations/crd-migration.mdx b/calico_versioned_docs/version-3.32/operations/crd-migration.mdx index f1aed379dd..ffba20ce59 100644 --- a/calico_versioned_docs/version-3.32/operations/crd-migration.mdx +++ b/calico_versioned_docs/version-3.32/operations/crd-migration.mdx @@ -53,7 +53,7 @@ The locked window is typically short (seconds to a few minutes depending on clus - $[prodname] v3.32+ (or the release that includes the migration controller) - Cluster is currently running in API server mode (the aggregated API server is deployed) -- **Kubernetes 1.34 or later.** Native `projectcalico.org/v3` CRDs rely on MutatingAdmissionPolicies for defaulting, which require the beta `admissionregistration.k8s.io/v1beta1` API. That API is not available on Kubernetes 1.33 and earlier, where MutatingAdmissionPolicy is alpha only. On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the Kubernetes API server before starting the migration, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +- **Kubernetes 1.34 or later.** Native `projectcalico.org/v3` CRDs rely on MutatingAdmissionPolicies for defaulting, which need the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. Neither is available on Kubernetes 1.33 and earlier, where MutatingAdmissionPolicy is alpha only. On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the Kubernetes API server before starting the migration, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. - **If using GitOps (ArgoCD, Flux):** pause sync before starting the migration. These tools may interfere with the API group switchover. You'll update your manifests to use `projectcalico.org/v3` after migration completes. ## How to diff --git a/calico_versioned_docs/version-3.32/operations/native-v3-crds.mdx b/calico_versioned_docs/version-3.32/operations/native-v3-crds.mdx index cedbe867ba..e6f04b0ba7 100644 --- a/calico_versioned_docs/version-3.32/operations/native-v3-crds.mdx +++ b/calico_versioned_docs/version-3.32/operations/native-v3-crds.mdx @@ -38,12 +38,12 @@ When using native `projectcalico.org/v3` CRDs: ### Validation and defaulting -When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/validating-admission-policy/) for defaulting, which require the beta `admissionregistration.k8s.io/v1beta1` API. That API is available in **Kubernetes 1.34 and later**. On Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API (`v1alpha1`), which $[prodname] does not support. On Kubernetes 1.34 and 1.35, you must enable the `MutatingAdmissionPolicy` feature gate on your Kubernetes API server before using native `projectcalico.org/v3` CRDs, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/mutating-admission-policy/) for defaulting, which require **Kubernetes 1.34 or later**: the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. On Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API (`v1alpha1`), which $[prodname] does not support. On Kubernetes 1.34 and 1.35, you must enable the `MutatingAdmissionPolicy` feature gate on your Kubernetes API server before using native `projectcalico.org/v3` CRDs, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. ## Before you begin - A Kubernetes cluster **without** $[prodname] installed, or a cluster where you are performing a fresh install. To migrate an existing cluster from API server mode, see [Migrate from API server to native CRDs](crd-migration.mdx). -- **Kubernetes 1.34 or later.** $[prodname] uses the beta `admissionregistration.k8s.io/v1beta1` MutatingAdmissionPolicy API for defaulting, which is not available on Kubernetes 1.33 and earlier (where MutatingAdmissionPolicy is alpha only). On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the API server, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +- **Kubernetes 1.34 or later.** $[prodname] uses MutatingAdmissionPolicies for defaulting, which need the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. Neither is available on Kubernetes 1.33 and earlier (where MutatingAdmissionPolicy is alpha only). On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the API server, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. import Tabs from '@theme/Tabs'; import TabItem from '@theme/TabItem'; @@ -69,10 +69,18 @@ Select the method below based on your preferred installation method. kubectl create namespace tigera-operator ``` -1. Install the v3 CRD chart instead of the default v1 CRD chart: +1. Install the v3 CRD chart instead of the default v1 CRD chart. + + If your cluster is based on Kubernetes 1.36 or later: + + ```bash + helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy | kubectl apply --server-side -f - + ``` + + If your cluster is based on Kubernetes 1.34 or 1.35: ```bash - helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] | kubectl apply --server-side -f - + helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --api-versions admissionregistration.k8s.io/v1beta1/MutatingAdmissionPolicy | kubectl apply --server-side -f - ``` :::note diff --git a/calico_versioned_docs/version-3.33/getting-started/kubernetes/helm.mdx b/calico_versioned_docs/version-3.33/getting-started/kubernetes/helm.mdx index 5aa2066663..7d998f1fe4 100644 --- a/calico_versioned_docs/version-3.33/getting-started/kubernetes/helm.mdx +++ b/calico_versioned_docs/version-3.33/getting-started/kubernetes/helm.mdx @@ -81,8 +81,16 @@ For more information about configurable options via `values.yaml` please see [He 1. Install the necessary custom resource definitions. + If your cluster is based on Kubernetes 1.36 or later: + + ```bash + helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy | kubectl apply --server-side -f - + ``` + + If your cluster is based on Kubernetes 1.34 or 1.35: + ```bash - helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --validate | kubectl apply --server-side -f - + helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --api-versions admissionregistration.k8s.io/v1beta1/MutatingAdmissionPolicy | kubectl apply --server-side -f - ``` 1. Install the Tigera Operator using the Helm chart: diff --git a/calico_versioned_docs/version-3.33/getting-started/kubernetes/self-managed-onprem/onpremises.mdx b/calico_versioned_docs/version-3.33/getting-started/kubernetes/self-managed-onprem/onpremises.mdx index 86d8383d1f..005095c579 100644 --- a/calico_versioned_docs/version-3.33/getting-started/kubernetes/self-managed-onprem/onpremises.mdx +++ b/calico_versioned_docs/version-3.33/getting-started/kubernetes/self-managed-onprem/onpremises.mdx @@ -148,7 +148,7 @@ If you're setting up a new cluster and don't need to customize the underlying Ku ::: -Native `projectcalico.org/v3` CRDs rely on MutatingAdmissionPolicies for defaulting, which require the beta `admissionregistration.k8s.io/v1beta1` API. That API is available in **Kubernetes 1.34 and later**; on Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API and is not supported. On Kubernetes 1.34 and 1.35, enable the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) on the Kubernetes API server before installing, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +Native `projectcalico.org/v3` CRDs rely on MutatingAdmissionPolicies for defaulting, which require **Kubernetes 1.34 or later**: the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later; on Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API and is not supported. On Kubernetes 1.34 and 1.35, enable the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) on the Kubernetes API server before installing, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. 1. Download the $[prodname] v3 CRD manifest. @@ -244,7 +244,7 @@ If you have an existing manifest-based $[prodname] install using the legacy `crd - $[prodname] installed via `calico.yaml` manifest (not operator) - `kubectl` access to the cluster - A recent $[prodname] version that includes the migration controller -- **Kubernetes 1.34 or later.** Native `projectcalico.org/v3` CRDs rely on MutatingAdmissionPolicies for defaulting, which require the beta `admissionregistration.k8s.io/v1beta1` API. That API is not available on Kubernetes 1.33 and earlier, where MutatingAdmissionPolicy is alpha only. On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the Kubernetes API server before starting the migration, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +- **Kubernetes 1.34 or later.** Native `projectcalico.org/v3` CRDs rely on MutatingAdmissionPolicies for defaulting, which need the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. Neither is available on Kubernetes 1.33 and earlier, where MutatingAdmissionPolicy is alpha only. On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the Kubernetes API server before starting the migration, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. #### Migration steps diff --git a/calico_versioned_docs/version-3.33/operations/native-v3-crds.mdx b/calico_versioned_docs/version-3.33/operations/native-v3-crds.mdx index 8cd4b5355d..1bab6357ea 100644 --- a/calico_versioned_docs/version-3.33/operations/native-v3-crds.mdx +++ b/calico_versioned_docs/version-3.33/operations/native-v3-crds.mdx @@ -32,12 +32,12 @@ When using native `projectcalico.org/v3` CRDs: ### Validation and defaulting -When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/validating-admission-policy/) for defaulting, which require the beta `admissionregistration.k8s.io/v1beta1` API. That API is available in **Kubernetes 1.34 and later**. On Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API (`v1alpha1`), which $[prodname] does not support. On Kubernetes 1.34 and 1.35, you must enable the `MutatingAdmissionPolicy` feature gate on your Kubernetes API server before using native `projectcalico.org/v3` CRDs, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/mutating-admission-policy/) for defaulting, which require **Kubernetes 1.34 or later**: the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. On Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API (`v1alpha1`), which $[prodname] does not support. On Kubernetes 1.34 and 1.35, you must enable the `MutatingAdmissionPolicy` feature gate on your Kubernetes API server before using native `projectcalico.org/v3` CRDs, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. ## Before you begin - A Kubernetes cluster **without** $[prodname] installed, or a cluster where you are performing a fresh install. To migrate an existing cluster from API server mode, see [Migrate from API server to native CRDs](crd-migration.mdx). -- **Kubernetes 1.34 or later.** $[prodname] uses the beta `admissionregistration.k8s.io/v1beta1` MutatingAdmissionPolicy API for defaulting, which is not available on Kubernetes 1.33 and earlier (where MutatingAdmissionPolicy is alpha only). On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the API server, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +- **Kubernetes 1.34 or later.** $[prodname] uses MutatingAdmissionPolicies for defaulting, which need the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. Neither is available on Kubernetes 1.33 and earlier (where MutatingAdmissionPolicy is alpha only). On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the API server, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. import Tabs from '@theme/Tabs'; import TabItem from '@theme/TabItem'; @@ -63,10 +63,18 @@ Select the method below based on your preferred installation method. kubectl create namespace tigera-operator ``` -1. Install the v3 CRD chart instead of the default v1 CRD chart: +1. Install the v3 CRD chart instead of the default v1 CRD chart. + + If your cluster is based on Kubernetes 1.36 or later: + + ```bash + helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy | kubectl apply --server-side -f - + ``` + + If your cluster is based on Kubernetes 1.34 or 1.35: ```bash - helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --validate | kubectl apply --server-side -f - + helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --api-versions admissionregistration.k8s.io/v1beta1/MutatingAdmissionPolicy | kubectl apply --server-side -f - ``` :::note diff --git a/calico_versioned_docs/version-3.33/operations/upgrading/kubernetes-upgrade.mdx b/calico_versioned_docs/version-3.33/operations/upgrading/kubernetes-upgrade.mdx index 03c9fafcf1..324f7b5a6c 100644 --- a/calico_versioned_docs/version-3.33/operations/upgrading/kubernetes-upgrade.mdx +++ b/calico_versioned_docs/version-3.33/operations/upgrading/kubernetes-upgrade.mdx @@ -73,6 +73,8 @@ To apply the CRDs yourself: The commands above apply the v1 CRDs, which is correct for clusters using the aggregation API server (the common case). If your cluster uses native v3 CRDs, substitute `v3_projectcalico_org.yaml` for `v1_crd_projectcalico_org.yaml`, or the `projectcalico/projectcalico.org.v3` chart for `projectcalico/crd.projectcalico.org.v1`. + When templating the v3 chart on Kubernetes 1.36 and later, also add `--api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy`; without it, Helm renders the MutatingAdmissionPolicy resources at `v1beta1`, which Kubernetes 1.36 does not serve. + ::: 1. Run the Helm upgrade: