From 102e18c1086bf73197b8a51ac0e0a8cb6542d764 Mon Sep 17 00:00:00 2001 From: Lancelot Robson Date: Wed, 30 Sep 2026 10:08:43 +0100 Subject: [PATCH 1/4] Fix v3 CRD chart commands for Kubernetes 1.36 helm template is client-only, so the projectcalico.org.v3 chart renders MutatingAdmissionPolicy at v1beta1, which 1.36 does not serve. --validate fixed the first install but fails any re-run: the kubectl-applied CRDs lack Helm ownership metadata. Use --api-versions on 1.36+ instead. Co-Authored-By: Claude Opus 5.5 (1M context) --- .../install-on-clusters/kubernetes/helm.mdx | 8 +++++++- calico/getting-started/kubernetes/helm.mdx | 8 +++++++- calico/operations/native-v3-crds.mdx | 8 +++++++- calico/operations/upgrading/kubernetes-upgrade.mdx | 2 ++ .../version-3.32/getting-started/kubernetes/helm.mdx | 2 ++ .../version-3.32/operations/native-v3-crds.mdx | 6 ++++++ .../version-3.33/getting-started/kubernetes/helm.mdx | 8 +++++++- .../version-3.33/operations/native-v3-crds.mdx | 8 +++++++- .../operations/upgrading/kubernetes-upgrade.mdx | 2 ++ 9 files changed, 47 insertions(+), 5 deletions(-) diff --git a/calico-enterprise/getting-started/install-on-clusters/kubernetes/helm.mdx b/calico-enterprise/getting-started/install-on-clusters/kubernetes/helm.mdx index 129c37d4fb..64d17b80c2 100644 --- a/calico-enterprise/getting-started/install-on-clusters/kubernetes/helm.mdx +++ b/calico-enterprise/getting-started/install-on-clusters/kubernetes/helm.mdx @@ -96,9 +96,15 @@ To install a standard $[prodname] cluster with Helm: 1. Install the necessary custom resource definitions. ```bash - helm template calico-crds projectcalico.org.v3-$[chart_version_name].tgz --validate | kubectl apply --server-side -f - + helm template calico-crds projectcalico.org.v3-$[chart_version_name].tgz | kubectl apply --server-side -f - ``` + :::note + + On Kubernetes 1.36 and later, add `--api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy` to the `helm template` command. Without it, Helm renders the MutatingAdmissionPolicy resources at `v1beta1`, which Kubernetes 1.36 does not serve. + + ::: + 1. Install the Tigera Operator using the Helm 3 chart: ```bash diff --git a/calico/getting-started/kubernetes/helm.mdx b/calico/getting-started/kubernetes/helm.mdx index 5aa2066663..48a9f57bb9 100644 --- a/calico/getting-started/kubernetes/helm.mdx +++ b/calico/getting-started/kubernetes/helm.mdx @@ -82,9 +82,15 @@ For more information about configurable options via `values.yaml` please see [He 1. Install the necessary custom resource definitions. ```bash - helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --validate | kubectl apply --server-side -f - + helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] | kubectl apply --server-side -f - ``` + :::note + + On Kubernetes 1.36 and later, add `--api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy` to the `helm template` command. Without it, Helm renders the MutatingAdmissionPolicy resources at `v1beta1`, which Kubernetes 1.36 does not serve. + + ::: + 1. Install the Tigera Operator using the Helm chart: ```bash diff --git a/calico/operations/native-v3-crds.mdx b/calico/operations/native-v3-crds.mdx index 8cd4b5355d..147ba97ebe 100644 --- a/calico/operations/native-v3-crds.mdx +++ b/calico/operations/native-v3-crds.mdx @@ -66,11 +66,17 @@ Select the method below based on your preferred installation method. 1. Install the v3 CRD chart instead of the default v1 CRD chart: ```bash - helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --validate | kubectl apply --server-side -f - + helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] | kubectl apply --server-side -f - ``` :::note + On Kubernetes 1.36 and later, add `--api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy` to the `helm template` command. Without it, Helm renders the MutatingAdmissionPolicy resources at `v1beta1`, which Kubernetes 1.36 does not serve. + + ::: + + :::note + This replaces the `crd.projectcalico.org.v1` chart used in the default installation. Do not install both CRD charts. ::: diff --git a/calico/operations/upgrading/kubernetes-upgrade.mdx b/calico/operations/upgrading/kubernetes-upgrade.mdx index 49ea7468da..fc9350254a 100644 --- a/calico/operations/upgrading/kubernetes-upgrade.mdx +++ b/calico/operations/upgrading/kubernetes-upgrade.mdx @@ -73,6 +73,8 @@ To apply the CRDs yourself: The commands above apply the v1 CRDs, which is correct for clusters using the aggregation API server (the common case). If your cluster uses native v3 CRDs, substitute `v3_projectcalico_org.yaml` for `v1_crd_projectcalico_org.yaml`, or the `projectcalico/projectcalico.org.v3` chart for `projectcalico/crd.projectcalico.org.v1`. + When templating the v3 chart on Kubernetes 1.36 and later, also add `--api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy`; without it, Helm renders the MutatingAdmissionPolicy resources at `v1beta1`, which Kubernetes 1.36 does not serve. + ::: 1. Run the Helm upgrade: diff --git a/calico_versioned_docs/version-3.32/getting-started/kubernetes/helm.mdx b/calico_versioned_docs/version-3.32/getting-started/kubernetes/helm.mdx index 7c3f78c022..3851b5c447 100644 --- a/calico_versioned_docs/version-3.32/getting-started/kubernetes/helm.mdx +++ b/calico_versioned_docs/version-3.32/getting-started/kubernetes/helm.mdx @@ -95,6 +95,8 @@ For more information about configurable options via `values.yaml` please see [He Native v3 CRDs eliminate the need for the aggregation API server and allows `kubectl` to manage `projectcalico.org/v3` resources directly. + On Kubernetes 1.36 and later, add `--api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy` to the `helm template` command. Without it, Helm renders the MutatingAdmissionPolicy resources at `v1beta1`, which Kubernetes 1.36 does not serve. + ::: 1. Install the Tigera Operator using the Helm chart: diff --git a/calico_versioned_docs/version-3.32/operations/native-v3-crds.mdx b/calico_versioned_docs/version-3.32/operations/native-v3-crds.mdx index cedbe867ba..35c735e2b9 100644 --- a/calico_versioned_docs/version-3.32/operations/native-v3-crds.mdx +++ b/calico_versioned_docs/version-3.32/operations/native-v3-crds.mdx @@ -77,6 +77,12 @@ Select the method below based on your preferred installation method. :::note + On Kubernetes 1.36 and later, add `--api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy` to the `helm template` command. Without it, Helm renders the MutatingAdmissionPolicy resources at `v1beta1`, which Kubernetes 1.36 does not serve. + + ::: + + :::note + This replaces the `crd.projectcalico.org.v1` chart used in the default installation. Do not install both CRD charts. ::: diff --git a/calico_versioned_docs/version-3.33/getting-started/kubernetes/helm.mdx b/calico_versioned_docs/version-3.33/getting-started/kubernetes/helm.mdx index 5aa2066663..48a9f57bb9 100644 --- a/calico_versioned_docs/version-3.33/getting-started/kubernetes/helm.mdx +++ b/calico_versioned_docs/version-3.33/getting-started/kubernetes/helm.mdx @@ -82,9 +82,15 @@ For more information about configurable options via `values.yaml` please see [He 1. Install the necessary custom resource definitions. ```bash - helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --validate | kubectl apply --server-side -f - + helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] | kubectl apply --server-side -f - ``` + :::note + + On Kubernetes 1.36 and later, add `--api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy` to the `helm template` command. Without it, Helm renders the MutatingAdmissionPolicy resources at `v1beta1`, which Kubernetes 1.36 does not serve. + + ::: + 1. Install the Tigera Operator using the Helm chart: ```bash diff --git a/calico_versioned_docs/version-3.33/operations/native-v3-crds.mdx b/calico_versioned_docs/version-3.33/operations/native-v3-crds.mdx index 8cd4b5355d..147ba97ebe 100644 --- a/calico_versioned_docs/version-3.33/operations/native-v3-crds.mdx +++ b/calico_versioned_docs/version-3.33/operations/native-v3-crds.mdx @@ -66,11 +66,17 @@ Select the method below based on your preferred installation method. 1. Install the v3 CRD chart instead of the default v1 CRD chart: ```bash - helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --validate | kubectl apply --server-side -f - + helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] | kubectl apply --server-side -f - ``` :::note + On Kubernetes 1.36 and later, add `--api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy` to the `helm template` command. Without it, Helm renders the MutatingAdmissionPolicy resources at `v1beta1`, which Kubernetes 1.36 does not serve. + + ::: + + :::note + This replaces the `crd.projectcalico.org.v1` chart used in the default installation. Do not install both CRD charts. ::: diff --git a/calico_versioned_docs/version-3.33/operations/upgrading/kubernetes-upgrade.mdx b/calico_versioned_docs/version-3.33/operations/upgrading/kubernetes-upgrade.mdx index 03c9fafcf1..324f7b5a6c 100644 --- a/calico_versioned_docs/version-3.33/operations/upgrading/kubernetes-upgrade.mdx +++ b/calico_versioned_docs/version-3.33/operations/upgrading/kubernetes-upgrade.mdx @@ -73,6 +73,8 @@ To apply the CRDs yourself: The commands above apply the v1 CRDs, which is correct for clusters using the aggregation API server (the common case). If your cluster uses native v3 CRDs, substitute `v3_projectcalico_org.yaml` for `v1_crd_projectcalico_org.yaml`, or the `projectcalico/projectcalico.org.v3` chart for `projectcalico/crd.projectcalico.org.v1`. + When templating the v3 chart on Kubernetes 1.36 and later, also add `--api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy`; without it, Helm renders the MutatingAdmissionPolicy resources at `v1beta1`, which Kubernetes 1.36 does not serve. + ::: 1. Run the Helm upgrade: From 35cb06c4551e3bca5f288c558026cb7dd676e3da Mon Sep 17 00:00:00 2001 From: Lancelot Robson Date: Wed, 30 Sep 2026 15:36:55 +0100 Subject: [PATCH 2/4] Branch v3 CRD chart step on Kubernetes version Replace the --api-versions note with explicit 1.36+ and 1.34/1.35 commands so the docs don't depend on the chart's fallback default. Co-authored-by: Christopher Tauchen Co-Authored-By: Claude Opus 5.5 --- .../install-on-clusters/kubernetes/helm.mdx | 12 +++++++----- calico/getting-started/kubernetes/helm.mdx | 12 +++++++----- calico/operations/native-v3-crds.mdx | 14 ++++++++------ .../getting-started/kubernetes/helm.mdx | 14 ++++++++++---- .../version-3.32/operations/native-v3-crds.mdx | 14 ++++++++------ .../getting-started/kubernetes/helm.mdx | 12 +++++++----- .../version-3.33/operations/native-v3-crds.mdx | 14 ++++++++------ 7 files changed, 55 insertions(+), 37 deletions(-) diff --git a/calico-enterprise/getting-started/install-on-clusters/kubernetes/helm.mdx b/calico-enterprise/getting-started/install-on-clusters/kubernetes/helm.mdx index 64d17b80c2..d6f2e79b4c 100644 --- a/calico-enterprise/getting-started/install-on-clusters/kubernetes/helm.mdx +++ b/calico-enterprise/getting-started/install-on-clusters/kubernetes/helm.mdx @@ -95,15 +95,17 @@ To install a standard $[prodname] cluster with Helm: 1. Install the necessary custom resource definitions. + If your cluster is based on Kubernetes 1.36 or later: + ```bash - helm template calico-crds projectcalico.org.v3-$[chart_version_name].tgz | kubectl apply --server-side -f - + helm template calico-crds projectcalico.org.v3-$[chart_version_name].tgz --api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy | kubectl apply --server-side -f - ``` - :::note - - On Kubernetes 1.36 and later, add `--api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy` to the `helm template` command. Without it, Helm renders the MutatingAdmissionPolicy resources at `v1beta1`, which Kubernetes 1.36 does not serve. + If your cluster is based on Kubernetes 1.34 or 1.35: - ::: + ```bash + helm template calico-crds projectcalico.org.v3-$[chart_version_name].tgz --api-versions admissionregistration.k8s.io/v1beta1/MutatingAdmissionPolicy | kubectl apply --server-side -f - + ``` 1. Install the Tigera Operator using the Helm 3 chart: diff --git a/calico/getting-started/kubernetes/helm.mdx b/calico/getting-started/kubernetes/helm.mdx index 48a9f57bb9..7d998f1fe4 100644 --- a/calico/getting-started/kubernetes/helm.mdx +++ b/calico/getting-started/kubernetes/helm.mdx @@ -81,15 +81,17 @@ For more information about configurable options via `values.yaml` please see [He 1. Install the necessary custom resource definitions. + If your cluster is based on Kubernetes 1.36 or later: + ```bash - helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] | kubectl apply --server-side -f - + helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy | kubectl apply --server-side -f - ``` - :::note - - On Kubernetes 1.36 and later, add `--api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy` to the `helm template` command. Without it, Helm renders the MutatingAdmissionPolicy resources at `v1beta1`, which Kubernetes 1.36 does not serve. + If your cluster is based on Kubernetes 1.34 or 1.35: - ::: + ```bash + helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --api-versions admissionregistration.k8s.io/v1beta1/MutatingAdmissionPolicy | kubectl apply --server-side -f - + ``` 1. Install the Tigera Operator using the Helm chart: diff --git a/calico/operations/native-v3-crds.mdx b/calico/operations/native-v3-crds.mdx index 147ba97ebe..c4e91ebf01 100644 --- a/calico/operations/native-v3-crds.mdx +++ b/calico/operations/native-v3-crds.mdx @@ -63,17 +63,19 @@ Select the method below based on your preferred installation method. kubectl create namespace tigera-operator ``` -1. Install the v3 CRD chart instead of the default v1 CRD chart: +1. Install the v3 CRD chart instead of the default v1 CRD chart. + + If your cluster is based on Kubernetes 1.36 or later: ```bash - helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] | kubectl apply --server-side -f - + helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy | kubectl apply --server-side -f - ``` - :::note - - On Kubernetes 1.36 and later, add `--api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy` to the `helm template` command. Without it, Helm renders the MutatingAdmissionPolicy resources at `v1beta1`, which Kubernetes 1.36 does not serve. + If your cluster is based on Kubernetes 1.34 or 1.35: - ::: + ```bash + helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --api-versions admissionregistration.k8s.io/v1beta1/MutatingAdmissionPolicy | kubectl apply --server-side -f - + ``` :::note diff --git a/calico_versioned_docs/version-3.32/getting-started/kubernetes/helm.mdx b/calico_versioned_docs/version-3.32/getting-started/kubernetes/helm.mdx index 3851b5c447..154e50a199 100644 --- a/calico_versioned_docs/version-3.32/getting-started/kubernetes/helm.mdx +++ b/calico_versioned_docs/version-3.32/getting-started/kubernetes/helm.mdx @@ -87,15 +87,21 @@ For more information about configurable options via `values.yaml` please see [He :::tip - To install with [native v3 CRDs](../../operations/native-v3-crds.mdx) (tech preview) instead, use the v3 CRD chart: + To install with [native v3 CRDs](../../operations/native-v3-crds.mdx) (tech preview) instead, use the v3 CRD chart. + + If your cluster is based on Kubernetes 1.36 or later: ```bash - helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] | kubectl apply --server-side -f - + helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy | kubectl apply --server-side -f - ``` - Native v3 CRDs eliminate the need for the aggregation API server and allows `kubectl` to manage `projectcalico.org/v3` resources directly. + If your cluster is based on Kubernetes 1.34 or 1.35: + + ```bash + helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --api-versions admissionregistration.k8s.io/v1beta1/MutatingAdmissionPolicy | kubectl apply --server-side -f - + ``` - On Kubernetes 1.36 and later, add `--api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy` to the `helm template` command. Without it, Helm renders the MutatingAdmissionPolicy resources at `v1beta1`, which Kubernetes 1.36 does not serve. + Native v3 CRDs eliminate the need for the aggregation API server and allows `kubectl` to manage `projectcalico.org/v3` resources directly. ::: diff --git a/calico_versioned_docs/version-3.32/operations/native-v3-crds.mdx b/calico_versioned_docs/version-3.32/operations/native-v3-crds.mdx index 35c735e2b9..e0a07cd0cc 100644 --- a/calico_versioned_docs/version-3.32/operations/native-v3-crds.mdx +++ b/calico_versioned_docs/version-3.32/operations/native-v3-crds.mdx @@ -69,17 +69,19 @@ Select the method below based on your preferred installation method. kubectl create namespace tigera-operator ``` -1. Install the v3 CRD chart instead of the default v1 CRD chart: +1. Install the v3 CRD chart instead of the default v1 CRD chart. + + If your cluster is based on Kubernetes 1.36 or later: ```bash - helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] | kubectl apply --server-side -f - + helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy | kubectl apply --server-side -f - ``` - :::note - - On Kubernetes 1.36 and later, add `--api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy` to the `helm template` command. Without it, Helm renders the MutatingAdmissionPolicy resources at `v1beta1`, which Kubernetes 1.36 does not serve. + If your cluster is based on Kubernetes 1.34 or 1.35: - ::: + ```bash + helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --api-versions admissionregistration.k8s.io/v1beta1/MutatingAdmissionPolicy | kubectl apply --server-side -f - + ``` :::note diff --git a/calico_versioned_docs/version-3.33/getting-started/kubernetes/helm.mdx b/calico_versioned_docs/version-3.33/getting-started/kubernetes/helm.mdx index 48a9f57bb9..7d998f1fe4 100644 --- a/calico_versioned_docs/version-3.33/getting-started/kubernetes/helm.mdx +++ b/calico_versioned_docs/version-3.33/getting-started/kubernetes/helm.mdx @@ -81,15 +81,17 @@ For more information about configurable options via `values.yaml` please see [He 1. Install the necessary custom resource definitions. + If your cluster is based on Kubernetes 1.36 or later: + ```bash - helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] | kubectl apply --server-side -f - + helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy | kubectl apply --server-side -f - ``` - :::note - - On Kubernetes 1.36 and later, add `--api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy` to the `helm template` command. Without it, Helm renders the MutatingAdmissionPolicy resources at `v1beta1`, which Kubernetes 1.36 does not serve. + If your cluster is based on Kubernetes 1.34 or 1.35: - ::: + ```bash + helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --api-versions admissionregistration.k8s.io/v1beta1/MutatingAdmissionPolicy | kubectl apply --server-side -f - + ``` 1. Install the Tigera Operator using the Helm chart: diff --git a/calico_versioned_docs/version-3.33/operations/native-v3-crds.mdx b/calico_versioned_docs/version-3.33/operations/native-v3-crds.mdx index 147ba97ebe..c4e91ebf01 100644 --- a/calico_versioned_docs/version-3.33/operations/native-v3-crds.mdx +++ b/calico_versioned_docs/version-3.33/operations/native-v3-crds.mdx @@ -63,17 +63,19 @@ Select the method below based on your preferred installation method. kubectl create namespace tigera-operator ``` -1. Install the v3 CRD chart instead of the default v1 CRD chart: +1. Install the v3 CRD chart instead of the default v1 CRD chart. + + If your cluster is based on Kubernetes 1.36 or later: ```bash - helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] | kubectl apply --server-side -f - + helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy | kubectl apply --server-side -f - ``` - :::note - - On Kubernetes 1.36 and later, add `--api-versions admissionregistration.k8s.io/v1/MutatingAdmissionPolicy` to the `helm template` command. Without it, Helm renders the MutatingAdmissionPolicy resources at `v1beta1`, which Kubernetes 1.36 does not serve. + If your cluster is based on Kubernetes 1.34 or 1.35: - ::: + ```bash + helm template calico-crds projectcalico/projectcalico.org.v3 --version $[releaseTitle] --api-versions admissionregistration.k8s.io/v1beta1/MutatingAdmissionPolicy | kubectl apply --server-side -f - + ``` :::note From b674ee87c5046833cd56f8306d0adcab4e2f7c0c Mon Sep 17 00:00:00 2001 From: Lancelot Robson Date: Thu, 1 Oct 2026 14:46:57 +0100 Subject: [PATCH 3/4] Say which MutatingAdmissionPolicy API each Kubernetes version needs The prerequisites said v1beta1 on every 1.34+ cluster, contradicting the new 1.36 commands: 1.36 serves only v1. Co-Authored-By: Claude Opus 5.5 --- calico-enterprise/operations/native-v3-crds.mdx | 4 ++-- .../kubernetes/self-managed-onprem/onpremises.mdx | 4 ++-- calico/operations/native-v3-crds.mdx | 4 ++-- .../kubernetes/self-managed-onprem/onpremises.mdx | 4 ++-- .../version-3.32/operations/crd-migration.mdx | 2 +- .../version-3.32/operations/native-v3-crds.mdx | 4 ++-- .../kubernetes/self-managed-onprem/onpremises.mdx | 4 ++-- .../version-3.33/operations/native-v3-crds.mdx | 4 ++-- 8 files changed, 15 insertions(+), 15 deletions(-) diff --git a/calico-enterprise/operations/native-v3-crds.mdx b/calico-enterprise/operations/native-v3-crds.mdx index 3c2e7fbc9b..9cc73955ce 100644 --- a/calico-enterprise/operations/native-v3-crds.mdx +++ b/calico-enterprise/operations/native-v3-crds.mdx @@ -32,12 +32,12 @@ When using native `projectcalico.org/v3` CRDs: ### Validation and defaulting -When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/validating-admission-policy/) for defaulting, which require the beta `admissionregistration.k8s.io/v1beta1` API. That API is available in **Kubernetes 1.34 and later**. On Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API (`v1alpha1`), which $[prodname] does not support. On Kubernetes 1.34 and 1.35, you must enable the `MutatingAdmissionPolicy` feature gate on your Kubernetes API server before using native `projectcalico.org/v3` CRDs, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/validating-admission-policy/) for defaulting, which require **Kubernetes 1.34 or later**: the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. On Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API (`v1alpha1`), which $[prodname] does not support. On Kubernetes 1.34 and 1.35, you must enable the `MutatingAdmissionPolicy` feature gate on your Kubernetes API server before using native `projectcalico.org/v3` CRDs, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. ## Before you begin - A Kubernetes cluster **without** $[prodname] installed, or a cluster where you are performing a fresh install. To migrate an existing cluster from API server mode, see [Migrate from API server to native CRDs](crd-migration.mdx). -- **Kubernetes 1.34 or later.** $[prodname] uses the beta `admissionregistration.k8s.io/v1beta1` MutatingAdmissionPolicy API for defaulting, which is not available on Kubernetes 1.33 and earlier (where MutatingAdmissionPolicy is alpha only). On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the API server, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +- **Kubernetes 1.34 or later.** $[prodname] uses MutatingAdmissionPolicies for defaulting, which need the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. Neither is available on Kubernetes 1.33 and earlier (where MutatingAdmissionPolicy is alpha only). On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the API server, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. import Tabs from '@theme/Tabs'; import TabItem from '@theme/TabItem'; diff --git a/calico/getting-started/kubernetes/self-managed-onprem/onpremises.mdx b/calico/getting-started/kubernetes/self-managed-onprem/onpremises.mdx index 86d8383d1f..005095c579 100644 --- a/calico/getting-started/kubernetes/self-managed-onprem/onpremises.mdx +++ b/calico/getting-started/kubernetes/self-managed-onprem/onpremises.mdx @@ -148,7 +148,7 @@ If you're setting up a new cluster and don't need to customize the underlying Ku ::: -Native `projectcalico.org/v3` CRDs rely on MutatingAdmissionPolicies for defaulting, which require the beta `admissionregistration.k8s.io/v1beta1` API. That API is available in **Kubernetes 1.34 and later**; on Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API and is not supported. On Kubernetes 1.34 and 1.35, enable the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) on the Kubernetes API server before installing, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +Native `projectcalico.org/v3` CRDs rely on MutatingAdmissionPolicies for defaulting, which require **Kubernetes 1.34 or later**: the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later; on Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API and is not supported. On Kubernetes 1.34 and 1.35, enable the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) on the Kubernetes API server before installing, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. 1. Download the $[prodname] v3 CRD manifest. @@ -244,7 +244,7 @@ If you have an existing manifest-based $[prodname] install using the legacy `crd - $[prodname] installed via `calico.yaml` manifest (not operator) - `kubectl` access to the cluster - A recent $[prodname] version that includes the migration controller -- **Kubernetes 1.34 or later.** Native `projectcalico.org/v3` CRDs rely on MutatingAdmissionPolicies for defaulting, which require the beta `admissionregistration.k8s.io/v1beta1` API. That API is not available on Kubernetes 1.33 and earlier, where MutatingAdmissionPolicy is alpha only. On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the Kubernetes API server before starting the migration, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +- **Kubernetes 1.34 or later.** Native `projectcalico.org/v3` CRDs rely on MutatingAdmissionPolicies for defaulting, which need the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. Neither is available on Kubernetes 1.33 and earlier, where MutatingAdmissionPolicy is alpha only. On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the Kubernetes API server before starting the migration, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. #### Migration steps diff --git a/calico/operations/native-v3-crds.mdx b/calico/operations/native-v3-crds.mdx index c4e91ebf01..fad9243540 100644 --- a/calico/operations/native-v3-crds.mdx +++ b/calico/operations/native-v3-crds.mdx @@ -32,12 +32,12 @@ When using native `projectcalico.org/v3` CRDs: ### Validation and defaulting -When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/validating-admission-policy/) for defaulting, which require the beta `admissionregistration.k8s.io/v1beta1` API. That API is available in **Kubernetes 1.34 and later**. On Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API (`v1alpha1`), which $[prodname] does not support. On Kubernetes 1.34 and 1.35, you must enable the `MutatingAdmissionPolicy` feature gate on your Kubernetes API server before using native `projectcalico.org/v3` CRDs, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/validating-admission-policy/) for defaulting, which require **Kubernetes 1.34 or later**: the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. On Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API (`v1alpha1`), which $[prodname] does not support. On Kubernetes 1.34 and 1.35, you must enable the `MutatingAdmissionPolicy` feature gate on your Kubernetes API server before using native `projectcalico.org/v3` CRDs, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. ## Before you begin - A Kubernetes cluster **without** $[prodname] installed, or a cluster where you are performing a fresh install. To migrate an existing cluster from API server mode, see [Migrate from API server to native CRDs](crd-migration.mdx). -- **Kubernetes 1.34 or later.** $[prodname] uses the beta `admissionregistration.k8s.io/v1beta1` MutatingAdmissionPolicy API for defaulting, which is not available on Kubernetes 1.33 and earlier (where MutatingAdmissionPolicy is alpha only). On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the API server, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +- **Kubernetes 1.34 or later.** $[prodname] uses MutatingAdmissionPolicies for defaulting, which need the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. Neither is available on Kubernetes 1.33 and earlier (where MutatingAdmissionPolicy is alpha only). On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the API server, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. import Tabs from '@theme/Tabs'; import TabItem from '@theme/TabItem'; diff --git a/calico_versioned_docs/version-3.32/getting-started/kubernetes/self-managed-onprem/onpremises.mdx b/calico_versioned_docs/version-3.32/getting-started/kubernetes/self-managed-onprem/onpremises.mdx index fa1f005304..11a70a07c7 100644 --- a/calico_versioned_docs/version-3.32/getting-started/kubernetes/self-managed-onprem/onpremises.mdx +++ b/calico_versioned_docs/version-3.32/getting-started/kubernetes/self-managed-onprem/onpremises.mdx @@ -135,7 +135,7 @@ If you're setting up a new cluster and don't need to customize the underlying Ku ::: -Native `projectcalico.org/v3` CRDs rely on MutatingAdmissionPolicies for defaulting, which require the beta `admissionregistration.k8s.io/v1beta1` API. That API is available in **Kubernetes 1.34 and later**; on Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API and is not supported. On Kubernetes 1.34 and 1.35, enable the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) on the Kubernetes API server before installing, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +Native `projectcalico.org/v3` CRDs rely on MutatingAdmissionPolicies for defaulting, which require **Kubernetes 1.34 or later**: the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later; on Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API and is not supported. On Kubernetes 1.34 and 1.35, enable the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) on the Kubernetes API server before installing, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. 1. Download the $[prodname] v3 CRD manifest. @@ -223,7 +223,7 @@ If you have an existing manifest-based $[prodname] install using the legacy `crd - $[prodname] installed via `calico.yaml` manifest (not operator) - `kubectl` access to the cluster - A recent $[prodname] version that includes the migration controller -- **Kubernetes 1.34 or later.** Native `projectcalico.org/v3` CRDs rely on MutatingAdmissionPolicies for defaulting, which require the beta `admissionregistration.k8s.io/v1beta1` API. That API is not available on Kubernetes 1.33 and earlier, where MutatingAdmissionPolicy is alpha only. On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the Kubernetes API server before starting the migration, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +- **Kubernetes 1.34 or later.** Native `projectcalico.org/v3` CRDs rely on MutatingAdmissionPolicies for defaulting, which need the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. Neither is available on Kubernetes 1.33 and earlier, where MutatingAdmissionPolicy is alpha only. On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the Kubernetes API server before starting the migration, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. #### Migration steps diff --git a/calico_versioned_docs/version-3.32/operations/crd-migration.mdx b/calico_versioned_docs/version-3.32/operations/crd-migration.mdx index f1aed379dd..ffba20ce59 100644 --- a/calico_versioned_docs/version-3.32/operations/crd-migration.mdx +++ b/calico_versioned_docs/version-3.32/operations/crd-migration.mdx @@ -53,7 +53,7 @@ The locked window is typically short (seconds to a few minutes depending on clus - $[prodname] v3.32+ (or the release that includes the migration controller) - Cluster is currently running in API server mode (the aggregated API server is deployed) -- **Kubernetes 1.34 or later.** Native `projectcalico.org/v3` CRDs rely on MutatingAdmissionPolicies for defaulting, which require the beta `admissionregistration.k8s.io/v1beta1` API. That API is not available on Kubernetes 1.33 and earlier, where MutatingAdmissionPolicy is alpha only. On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the Kubernetes API server before starting the migration, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +- **Kubernetes 1.34 or later.** Native `projectcalico.org/v3` CRDs rely on MutatingAdmissionPolicies for defaulting, which need the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. Neither is available on Kubernetes 1.33 and earlier, where MutatingAdmissionPolicy is alpha only. On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the Kubernetes API server before starting the migration, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. - **If using GitOps (ArgoCD, Flux):** pause sync before starting the migration. These tools may interfere with the API group switchover. You'll update your manifests to use `projectcalico.org/v3` after migration completes. ## How to diff --git a/calico_versioned_docs/version-3.32/operations/native-v3-crds.mdx b/calico_versioned_docs/version-3.32/operations/native-v3-crds.mdx index e0a07cd0cc..6e99fedc73 100644 --- a/calico_versioned_docs/version-3.32/operations/native-v3-crds.mdx +++ b/calico_versioned_docs/version-3.32/operations/native-v3-crds.mdx @@ -38,12 +38,12 @@ When using native `projectcalico.org/v3` CRDs: ### Validation and defaulting -When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/validating-admission-policy/) for defaulting, which require the beta `admissionregistration.k8s.io/v1beta1` API. That API is available in **Kubernetes 1.34 and later**. On Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API (`v1alpha1`), which $[prodname] does not support. On Kubernetes 1.34 and 1.35, you must enable the `MutatingAdmissionPolicy` feature gate on your Kubernetes API server before using native `projectcalico.org/v3` CRDs, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/validating-admission-policy/) for defaulting, which require **Kubernetes 1.34 or later**: the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. On Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API (`v1alpha1`), which $[prodname] does not support. On Kubernetes 1.34 and 1.35, you must enable the `MutatingAdmissionPolicy` feature gate on your Kubernetes API server before using native `projectcalico.org/v3` CRDs, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. ## Before you begin - A Kubernetes cluster **without** $[prodname] installed, or a cluster where you are performing a fresh install. To migrate an existing cluster from API server mode, see [Migrate from API server to native CRDs](crd-migration.mdx). -- **Kubernetes 1.34 or later.** $[prodname] uses the beta `admissionregistration.k8s.io/v1beta1` MutatingAdmissionPolicy API for defaulting, which is not available on Kubernetes 1.33 and earlier (where MutatingAdmissionPolicy is alpha only). On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the API server, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +- **Kubernetes 1.34 or later.** $[prodname] uses MutatingAdmissionPolicies for defaulting, which need the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. Neither is available on Kubernetes 1.33 and earlier (where MutatingAdmissionPolicy is alpha only). On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the API server, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. import Tabs from '@theme/Tabs'; import TabItem from '@theme/TabItem'; diff --git a/calico_versioned_docs/version-3.33/getting-started/kubernetes/self-managed-onprem/onpremises.mdx b/calico_versioned_docs/version-3.33/getting-started/kubernetes/self-managed-onprem/onpremises.mdx index 86d8383d1f..005095c579 100644 --- a/calico_versioned_docs/version-3.33/getting-started/kubernetes/self-managed-onprem/onpremises.mdx +++ b/calico_versioned_docs/version-3.33/getting-started/kubernetes/self-managed-onprem/onpremises.mdx @@ -148,7 +148,7 @@ If you're setting up a new cluster and don't need to customize the underlying Ku ::: -Native `projectcalico.org/v3` CRDs rely on MutatingAdmissionPolicies for defaulting, which require the beta `admissionregistration.k8s.io/v1beta1` API. That API is available in **Kubernetes 1.34 and later**; on Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API and is not supported. On Kubernetes 1.34 and 1.35, enable the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) on the Kubernetes API server before installing, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +Native `projectcalico.org/v3` CRDs rely on MutatingAdmissionPolicies for defaulting, which require **Kubernetes 1.34 or later**: the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later; on Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API and is not supported. On Kubernetes 1.34 and 1.35, enable the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) on the Kubernetes API server before installing, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. 1. Download the $[prodname] v3 CRD manifest. @@ -244,7 +244,7 @@ If you have an existing manifest-based $[prodname] install using the legacy `crd - $[prodname] installed via `calico.yaml` manifest (not operator) - `kubectl` access to the cluster - A recent $[prodname] version that includes the migration controller -- **Kubernetes 1.34 or later.** Native `projectcalico.org/v3` CRDs rely on MutatingAdmissionPolicies for defaulting, which require the beta `admissionregistration.k8s.io/v1beta1` API. That API is not available on Kubernetes 1.33 and earlier, where MutatingAdmissionPolicy is alpha only. On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the Kubernetes API server before starting the migration, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +- **Kubernetes 1.34 or later.** Native `projectcalico.org/v3` CRDs rely on MutatingAdmissionPolicies for defaulting, which need the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. Neither is available on Kubernetes 1.33 and earlier, where MutatingAdmissionPolicy is alpha only. On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the Kubernetes API server before starting the migration, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. #### Migration steps diff --git a/calico_versioned_docs/version-3.33/operations/native-v3-crds.mdx b/calico_versioned_docs/version-3.33/operations/native-v3-crds.mdx index c4e91ebf01..fad9243540 100644 --- a/calico_versioned_docs/version-3.33/operations/native-v3-crds.mdx +++ b/calico_versioned_docs/version-3.33/operations/native-v3-crds.mdx @@ -32,12 +32,12 @@ When using native `projectcalico.org/v3` CRDs: ### Validation and defaulting -When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/validating-admission-policy/) for defaulting, which require the beta `admissionregistration.k8s.io/v1beta1` API. That API is available in **Kubernetes 1.34 and later**. On Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API (`v1alpha1`), which $[prodname] does not support. On Kubernetes 1.34 and 1.35, you must enable the `MutatingAdmissionPolicy` feature gate on your Kubernetes API server before using native `projectcalico.org/v3` CRDs, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/validating-admission-policy/) for defaulting, which require **Kubernetes 1.34 or later**: the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. On Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API (`v1alpha1`), which $[prodname] does not support. On Kubernetes 1.34 and 1.35, you must enable the `MutatingAdmissionPolicy` feature gate on your Kubernetes API server before using native `projectcalico.org/v3` CRDs, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. ## Before you begin - A Kubernetes cluster **without** $[prodname] installed, or a cluster where you are performing a fresh install. To migrate an existing cluster from API server mode, see [Migrate from API server to native CRDs](crd-migration.mdx). -- **Kubernetes 1.34 or later.** $[prodname] uses the beta `admissionregistration.k8s.io/v1beta1` MutatingAdmissionPolicy API for defaulting, which is not available on Kubernetes 1.33 and earlier (where MutatingAdmissionPolicy is alpha only). On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the API server, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +- **Kubernetes 1.34 or later.** $[prodname] uses MutatingAdmissionPolicies for defaulting, which need the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. Neither is available on Kubernetes 1.33 and earlier (where MutatingAdmissionPolicy is alpha only). On Kubernetes 1.34 and 1.35, the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) must be enabled on the API server, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. import Tabs from '@theme/Tabs'; import TabItem from '@theme/TabItem'; From bf403aaf9196150be4cd8e7942c305c73d9a9c6f Mon Sep 17 00:00:00 2001 From: Lancelot Robson Date: Thu, 1 Oct 2026 14:59:45 +0100 Subject: [PATCH 4/4] Link MutatingAdmissionPolicies to the mutating admission policy page Co-Authored-By: Claude Opus 5.5 --- calico-enterprise/operations/native-v3-crds.mdx | 2 +- .../version-3.23-2/operations/native-v3-crds.mdx | 2 +- .../version-3.24-1/operations/native-v3-crds.mdx | 2 +- .../version-3.24-2/operations/native-v3-crds.mdx | 2 +- calico/operations/native-v3-crds.mdx | 2 +- .../version-3.32/operations/native-v3-crds.mdx | 2 +- .../version-3.33/operations/native-v3-crds.mdx | 2 +- 7 files changed, 7 insertions(+), 7 deletions(-) diff --git a/calico-enterprise/operations/native-v3-crds.mdx b/calico-enterprise/operations/native-v3-crds.mdx index 9cc73955ce..0793b77988 100644 --- a/calico-enterprise/operations/native-v3-crds.mdx +++ b/calico-enterprise/operations/native-v3-crds.mdx @@ -32,7 +32,7 @@ When using native `projectcalico.org/v3` CRDs: ### Validation and defaulting -When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/validating-admission-policy/) for defaulting, which require **Kubernetes 1.34 or later**: the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. On Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API (`v1alpha1`), which $[prodname] does not support. On Kubernetes 1.34 and 1.35, you must enable the `MutatingAdmissionPolicy` feature gate on your Kubernetes API server before using native `projectcalico.org/v3` CRDs, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/mutating-admission-policy/) for defaulting, which require **Kubernetes 1.34 or later**: the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. On Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API (`v1alpha1`), which $[prodname] does not support. On Kubernetes 1.34 and 1.35, you must enable the `MutatingAdmissionPolicy` feature gate on your Kubernetes API server before using native `projectcalico.org/v3` CRDs, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. ## Before you begin diff --git a/calico-enterprise_versioned_docs/version-3.23-2/operations/native-v3-crds.mdx b/calico-enterprise_versioned_docs/version-3.23-2/operations/native-v3-crds.mdx index ce0c88c9fc..8ed6b5f0b1 100644 --- a/calico-enterprise_versioned_docs/version-3.23-2/operations/native-v3-crds.mdx +++ b/calico-enterprise_versioned_docs/version-3.23-2/operations/native-v3-crds.mdx @@ -38,7 +38,7 @@ When using native `projectcalico.org/v3` CRDs: ### Validation and defaulting -When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/validating-admission-policy/) for defaulting, which require the beta `admissionregistration.k8s.io/v1beta1` API. That API is available in **Kubernetes 1.34 and later**. On Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API (`v1alpha1`), which $[prodname] does not support. On Kubernetes 1.34 and 1.35, you must enable the `MutatingAdmissionPolicy` feature gate on your Kubernetes API server before using native `projectcalico.org/v3` CRDs, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/mutating-admission-policy/) for defaulting, which require the beta `admissionregistration.k8s.io/v1beta1` API. That API is available in **Kubernetes 1.34 and later**. On Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API (`v1alpha1`), which $[prodname] does not support. On Kubernetes 1.34 and 1.35, you must enable the `MutatingAdmissionPolicy` feature gate on your Kubernetes API server before using native `projectcalico.org/v3` CRDs, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. ## Before you begin diff --git a/calico-enterprise_versioned_docs/version-3.24-1/operations/native-v3-crds.mdx b/calico-enterprise_versioned_docs/version-3.24-1/operations/native-v3-crds.mdx index 8f45e925fa..515cb2216e 100644 --- a/calico-enterprise_versioned_docs/version-3.24-1/operations/native-v3-crds.mdx +++ b/calico-enterprise_versioned_docs/version-3.24-1/operations/native-v3-crds.mdx @@ -32,7 +32,7 @@ When using native `projectcalico.org/v3` CRDs: ### Validation and defaulting -When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/validating-admission-policy/) for defaulting, which require **Kubernetes 1.32 or later**. On clusters where the `MutatingAdmissionPolicy` API is not enabled by default, you must enable the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) on the Kubernetes API server. +When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/mutating-admission-policy/) for defaulting, which require **Kubernetes 1.32 or later**. On clusters where the `MutatingAdmissionPolicy` API is not enabled by default, you must enable the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) on the Kubernetes API server. ## Before you begin diff --git a/calico-enterprise_versioned_docs/version-3.24-2/operations/native-v3-crds.mdx b/calico-enterprise_versioned_docs/version-3.24-2/operations/native-v3-crds.mdx index 8f45e925fa..515cb2216e 100644 --- a/calico-enterprise_versioned_docs/version-3.24-2/operations/native-v3-crds.mdx +++ b/calico-enterprise_versioned_docs/version-3.24-2/operations/native-v3-crds.mdx @@ -32,7 +32,7 @@ When using native `projectcalico.org/v3` CRDs: ### Validation and defaulting -When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/validating-admission-policy/) for defaulting, which require **Kubernetes 1.32 or later**. On clusters where the `MutatingAdmissionPolicy` API is not enabled by default, you must enable the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) on the Kubernetes API server. +When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/mutating-admission-policy/) for defaulting, which require **Kubernetes 1.32 or later**. On clusters where the `MutatingAdmissionPolicy` API is not enabled by default, you must enable the `MutatingAdmissionPolicy` [feature gate](https://kubernetes.io/docs/reference/command-line-tools-reference/feature-gates/) on the Kubernetes API server. ## Before you begin diff --git a/calico/operations/native-v3-crds.mdx b/calico/operations/native-v3-crds.mdx index fad9243540..1bab6357ea 100644 --- a/calico/operations/native-v3-crds.mdx +++ b/calico/operations/native-v3-crds.mdx @@ -32,7 +32,7 @@ When using native `projectcalico.org/v3` CRDs: ### Validation and defaulting -When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/validating-admission-policy/) for defaulting, which require **Kubernetes 1.34 or later**: the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. On Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API (`v1alpha1`), which $[prodname] does not support. On Kubernetes 1.34 and 1.35, you must enable the `MutatingAdmissionPolicy` feature gate on your Kubernetes API server before using native `projectcalico.org/v3` CRDs, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/mutating-admission-policy/) for defaulting, which require **Kubernetes 1.34 or later**: the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. On Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API (`v1alpha1`), which $[prodname] does not support. On Kubernetes 1.34 and 1.35, you must enable the `MutatingAdmissionPolicy` feature gate on your Kubernetes API server before using native `projectcalico.org/v3` CRDs, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. ## Before you begin diff --git a/calico_versioned_docs/version-3.32/operations/native-v3-crds.mdx b/calico_versioned_docs/version-3.32/operations/native-v3-crds.mdx index 6e99fedc73..e6f04b0ba7 100644 --- a/calico_versioned_docs/version-3.32/operations/native-v3-crds.mdx +++ b/calico_versioned_docs/version-3.32/operations/native-v3-crds.mdx @@ -38,7 +38,7 @@ When using native `projectcalico.org/v3` CRDs: ### Validation and defaulting -When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/validating-admission-policy/) for defaulting, which require **Kubernetes 1.34 or later**: the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. On Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API (`v1alpha1`), which $[prodname] does not support. On Kubernetes 1.34 and 1.35, you must enable the `MutatingAdmissionPolicy` feature gate on your Kubernetes API server before using native `projectcalico.org/v3` CRDs, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/mutating-admission-policy/) for defaulting, which require **Kubernetes 1.34 or later**: the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. On Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API (`v1alpha1`), which $[prodname] does not support. On Kubernetes 1.34 and 1.35, you must enable the `MutatingAdmissionPolicy` feature gate on your Kubernetes API server before using native `projectcalico.org/v3` CRDs, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. ## Before you begin diff --git a/calico_versioned_docs/version-3.33/operations/native-v3-crds.mdx b/calico_versioned_docs/version-3.33/operations/native-v3-crds.mdx index fad9243540..1bab6357ea 100644 --- a/calico_versioned_docs/version-3.33/operations/native-v3-crds.mdx +++ b/calico_versioned_docs/version-3.33/operations/native-v3-crds.mdx @@ -32,7 +32,7 @@ When using native `projectcalico.org/v3` CRDs: ### Validation and defaulting -When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/validating-admission-policy/) for defaulting, which require **Kubernetes 1.34 or later**: the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. On Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API (`v1alpha1`), which $[prodname] does not support. On Kubernetes 1.34 and 1.35, you must enable the `MutatingAdmissionPolicy` feature gate on your Kubernetes API server before using native `projectcalico.org/v3` CRDs, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. +When using native `projectcalico.org/v3` CRDs, resource validation and defaulting are handled by native CRD validation and defaulting, as well as ValidatingAdmissionPolicies and MutatingAdmissionPolicies. $[prodname] uses [MutatingAdmissionPolicies](https://kubernetes.io/docs/reference/access-authn-authz/mutating-admission-policy/) for defaulting, which require **Kubernetes 1.34 or later**: the beta `admissionregistration.k8s.io/v1beta1` API on Kubernetes 1.34 and 1.35, or the GA `admissionregistration.k8s.io/v1` API on 1.36 and later. On Kubernetes 1.33 and earlier, MutatingAdmissionPolicy is only available as an alpha API (`v1alpha1`), which $[prodname] does not support. On Kubernetes 1.34 and 1.35, you must enable the `MutatingAdmissionPolicy` feature gate on your Kubernetes API server before using native `projectcalico.org/v3` CRDs, as it is not enabled by default. On Kubernetes 1.36 and later, the feature is GA and enabled by default. ## Before you begin