Skip to content

fix: ensure we're creating semver-compliant helm charts in OCI repositories [v3.33] - #14005

Open
danudey wants to merge 1 commit into
projectcalico:release-v3.33from
danudey:add-helm-chart-semver-v3.33
Open

danudey wants to merge 1 commit into
projectcalico:release-v3.33from
danudey:add-helm-chart-semver-v3.33

Conversation

@danudey

@danudey danudey commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

While helm will be very permissive in its parsing of version tags in helm charts in almost every circumstances, it uses strict parsing in one case: listing tags in an OCI repository to determine which ones are versions vs. which ones are not.

This means that helm will accept the version v3.33.3 (parsing it into 3.33.3) when it is explicitly told a version (in a chart or in a chart index), but not when it is searching for a version. Since helm push will create an OCI tag matching the version from the chart, even if that chart is an invalid semver version, we need to create new semver-compliant tags when we push charts.

For Calico v3.33 and older, we'll do this by keeping the version in the charts the same and using crane to create the new semver tag after we push a not-quite-semver chart, so pushing the v3.33.3 tag will use crane to create the corresponding 3.33.3 tag.

In upcoming minor versions of Calico the plan is to remove the v prefix from our charts entirely, ensuring that we're semver-compliant from that point on. This could be a breaking change for some users, so doing so in a new minor version is the safest choice.

This solves a long-standing issue which we've been working around manually:

The change in behavior for v3.34 and onward can be found here (WIP):

Ensure we're publishing helm charts to OCI registries using semver-compliant version tags (as well as the almost-semver `v3.xx.y` tags) to ensure `helm` can find them.

@danudey
danudey requested review from a team as code owners September 21, 2026 16:41
Copilot AI lite review requested due to automatic review settings September 21, 2026 16:41
@marvin-tigera marvin-tigera added this to the Calico v3.34.0 milestone Sep 21, 2026
@marvin-tigera marvin-tigera added release-note-required Change has user-facing impact (no matter how small) docs-pr-required Change is not yet documented labels Sep 21, 2026
@danudey
danudey changed the base branch from master to release-v3.33 September 21, 2026 16:42
@danudey danudey changed the title fix: ensure we're creating semver-compliant helm charts in OCI repositories fix: ensure we're creating semver-compliant helm charts in OCI repositories [v3.33] Sep 21, 2026
@danudey danudey added docs-not-required Docs not required for this change and removed docs-pr-required Change is not yet documented labels Sep 21, 2026
@danudey
danudey requested review from a team and removed request for a team September 21, 2026 16:49

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Unresolved moderate findings affect CRD protocol compatibility, nftables consistency, BGP test selection, and Helm semver verification.

Review effort: Lite
Findings: None

What changed in this PR

This PR prepares the v3.33 release branch with semver-compliant OCI Helm chart tagging, dependency and manifest updates, CRD validation, dataplane fixes, and e2e/CI changes.

Changes:

  • Adds normalized semver Helm chart tags and post-release checks.
  • Refreshes dependencies, generated APIs, manifests, charts, and release tooling.
  • Updates Felix, BPF, nftables, IPAM, validation, and e2e behavior.
File Reviewed change
whisker/​package.json Updates React Router dependency.
whisker/​deps.txt Updates Go metadata.
typha/​pkg/​validator/​v1/​validator.go Hardens validator registration.
typha/​pkg/​validator/​v1/​validator_test.go Updates validator tests.
typha/​pkg/​validator/​v1/​validator_suite_test.go Adds validator suite setup.
typha/​pkg/​validator/​v1/​doc.go Clarifies validator scope.
typha/​pkg/​validator/​v1/​common.go Normalizes an error message.
typha/​pkg/​validator/​v1/​common_test.go Updates validator tests.
typha/​pkg/​daemon/​daemon.go Improves metrics error logging.
typha/​pkg/​calc/​validation_filter.go Uses Typha-local validation.
third_party/​deps.txt Updates Go metadata.
test/​validation/​main_test.go Gates validation by Kubernetes version.
test/​validation/​caliconodestatus_test.go Tests status period bounds.
test/​validation/​bgppeer_test.go Tests BGP peer validation.
test/​validation/​bgpfilter_test.go Tests IPv6 CIDR limits.
test/​Makefile Updates Kubernetes documentation.
test/​deps.txt Updates Go metadata.
test-tools/​mocknode/​mock-node.yaml Pins the mock-node image.
release/​pkg/​postrelease/​helm_test.go Validates released Helm charts; moderate finding: the check must pull the normalized semver tag.
release/​Makefile Adds the Crane publishing dependency.
release/​cmd/​hashrelease.go Passes release branch configuration.
process/​testing/​aso/​export-env.sh Defaults ASO to v3.33.
pod2daemon/​proto/​udsver.pb.go Regenerates protobuf output.
pod2daemon/​proto/​udsver_grpc.pb.go Regenerates gRPC output.
pod2daemon/​deps.txt Updates dependencies.
pod2daemon/​binder/​creds.go Updates gRPC credential metadata.
networking-calico/​networking_calico/​plugins/​ml2/​drivers/​calico/​mech_calico.py Reports deprecated options.
metadata.mk Updates toolchain and operator versions.
manifests/​tigera-operator-ocp-upgrade.yaml Pins release images.
manifests/​ocp/​02-tigera-operator.yaml Pins release images.
manifests/​flannel-migration/​migration-job.yaml Pins the migration image.
manifests/​csi-driver.yaml Pins CSI images.
manifests/​canal-etcd.yaml Updates images and init permissions.
manifests/​calicoctl.yaml Pins calicoctl.
manifests/​calicoctl-etcd.yaml Updates calicoctl image and command.
manifests/​calico-etcd.yaml Updates images and init permissions.
manifests/​apiserver.yaml Pins the image and adds RBAC.
manifests/​.gitattributes Marks generated manifests.
Makefile Updates shared cache and Crane targets.
libcalico-go/​lib/​ipam/​ipam_types.go Adds IP move options.
libcalico-go/​lib/​ipam/​ipam_attributes.go Passes IPAM configuration to ownership updates.
libcalico-go/​lib/​ipam/​interface.go Adds the move-IP API.
libcalico-go/​lib/​clientv3/​kubecontrollersconfig_e2e_test.go Accounts for metrics defaults.
libcalico-go/​lib/​clientv3/​felixconfig.go Clarifies Felix defaulting.
libcalico-go/​lib/​backend/​watchersyncer/​watchersyncer_test.go Reformats test data.
libcalico-go/​lib/​backend/​k8s/​client_test.go Aligns fixtures with CRD defaults.
libcalico-go/​config/​crd/​crd.projectcalico.org_networksets.yaml Adds NetworkSet bounds and CEL validation.
libcalico-go/​config/​crd/​crd.projectcalico.org_hostendpoints.yaml Adds endpoint protocol validation.
libcalico-go/​config/​crd/​crd.projectcalico.org_globalnetworksets.yaml Adds GlobalNetworkSet bounds and CEL validation.
libcalico-go/​config/​crd/​crd.projectcalico.org_caliconodestatuses.yaml Adds status period bounds.
libcalico-go/​config/​crd/​crd.projectcalico.org_bgppeers.yaml Adds peer IP validation.
libcalico-go/​config/​crd/​crd.projectcalico.org_bgpfilters.yaml Expands IPv6 CIDR limits.
lib/​std/​go.mod Updates the Go version.
lib/​logrusr/​go.mod Updates the Go version.
lib/​httpmachinery/​pkg/​context/​mocks/​Context.go Regenerates mocks.
lib/​httpmachinery/​go.mod Updates Go and dependency versions.
lib/​datastructures/​go.mod Updates the Go version.
kube-controllers/​pkg/​kubecontrollers/​run.go Supports configurable profiling host.
kube-controllers/​pkg/​controllers/​node/​fake_client.go Updates the IPAM mock interface.
kube-controllers/​pkg/​controllers/​ippool/​pool_controller.go Uses unified overlap detection.
kube-controllers/​pkg/​config/​runconfig.go Adds profiling host configuration.
kube-controllers/​pkg/​config/​config_test.go Tests profiling host configuration.
istio/​deps.txt Updates Go metadata.
hack/​cmd/​deps/​deps.go Handles module replacements.
hack/​cmd/​calico-controller-gen/​build.sh Makes builds atomic.
goldmane/​proto/​api.pb.go Regenerates protobuf output.
goldmane/​proto/​api_grpc.pb.go Regenerates gRPC output.
goldmane/​pkg/​emitter/​http_client.go Uses context-aware dialing.
goldmane/​pkg/​client/​mocks/​FlowsClient.go Regenerates mocks.
felix/​usagerep/​usagerep.go Reports resolved nftables usage.
felix/​usagerep/​usagerep_test.go Updates nftables expectations.
felix/​rules/​rulesdefs/​rulesdefs.go Adds shared dataplane constants.
felix/​rules/​endpoints.go Adds connection transition logging.
felix/​routetable/​bench_test.go Updates benchmark arguments.
felix/​proto/​felixbackend.proto Documents route state.
felix/​proto/​felixbackend.pb.go Regenerates protobuf output.
felix/​policysync/​processor_test.go Updates credential metadata.
felix/​nftables/​utils.go Resolves nftables mode.
felix/​nftables/​table_layer.go Uses extracted renderer interfaces.
felix/​nftables/​renderer.go Uses renderer helpers.
felix/​nftables/​nftrender/​nftrender_ut_suite_test.go Adds renderer suite setup.
felix/​nftables/​nftrender/​names.go Adds naming helpers.
felix/​nftables/​nftrender/​actions.go Extracts action types.
felix/​nftables/​nftrender/​actions_test.go Updates action tests.
felix/​nftables/​ipsets.go Uses extracted set-name legalization.
felix/​nftables/​bench_test.go Updates renderer imports.
felix/​iptables/​testutils/​utils.go Adds nft binary lookup support.
felix/​iptables/​match_builder.go Adds connmark and TCP flag matches.
felix/​iptables/​match_builder_test.go Tests new match builders.
felix/​ip/​trie.go Adds CIDR overlap detection.
felix/​idalloc/​index_allocator.go Avoids mutating caller slices.
felix/​idalloc/​index_allocator_test.go Tests slice preservation.
felix/​generictables/​table.go Adds cleanup table abstraction.
felix/​generictables/​match_builder.go Extends match builder interfaces.
felix/​fv/​utils/​utils.go Uses portable nft helpers.
felix/​fv/​infrastructure/​modes.go Detects netkit attachment mode.
felix/​fv/​infrastructure/​infra_k8s.go Updates HTTP dialing.
felix/​fv/​infrastructure/​bpfpolprog/​bpfpolprog.go Uses resolved attachment mode.
felix/​fv/​apply_on_forward_test.go Uses extracted nft constants.
felix/​environment/​feature_detect_windows.go Adds Windows backend detection.
felix/​environment/​feature_detect_test.go Tests iptables handling.
felix/​design/​bpf-overview.md Documents attachment selection.
felix/​DESIGN.md Documents nftables renderer separation.
felix/​dataplane/​linux/​route_mgr.go Handles borrowed workload routes.
felix/​dataplane/​linux/​qos_controls.go Resolves QoS mechanisms.
felix/​dataplane/​linux/​live_migration_test.go Updates the fake IPAM client.
felix/​dataplane/​linux/​ipip_mgr_test.go Tests borrowed workload routes.
felix/​dataplane/​linux/​endpoint_mgr_arp_test.go Uses extracted nft constants.
felix/​dataplane/​linux/​bpf_route_mgr.go Selects WireGuard by address family.
felix/​dataplane/​driver_windows.go Adds Windows nftables resolution.
felix/​daemon/​daemon.go Resolves nftables mode; moderate finding: the calculation graph still uses the unresolved mode.
felix/​collector/​stats.go Expires flows on verdict index changes.
felix/​collector/​stats_test.go Tests verdict index changes.
felix/​cmd/​calico-bpf/​commands/​routes.go Simplifies route handling.
felix/​calc/​validation_filter.go Uses Typha-local validation.
felix/​bpf/​ut/​attach_test.go Updates netkit coverage.
felix/​bpf/​proxy/​syncer_bench_test.go Updates syncer arguments.
felix/​bpf/​proxy/​proxy_bench_test.go Updates proxy benchmark arguments.
felix/​bpf/​proxy/​options.go Adds CTLB affinity configuration.
felix/​bpf/​proxy/​kube-proxy.go Passes affinity timeout to the syncer.
felix/​bpf/​conntrack/​map.go Adds SCTP support.
felix/​bpf/​conntrack/​connlimit_scanner.go Recounts live connections.
felix/​bpf-gpl/​tc.c Gates egress connlimit accounting.
felix/​bpf-gpl/​nat_lookup.h Honors affinity timeout.
felix/​bpf-gpl/​conntrack.h Clears stale connlimit flags.
e2e/​pkg/​utils/​ippool.go Selects IP pools by address family.
e2e/​pkg/​utils/​installation.go Adds BGP installation gating.
e2e/​pkg/​utils/​externalnode/​client.go Handles external-node failures.
e2e/​pkg/​tests/​policy/​staged_policy.go Adds feature and tier labels.
e2e/​pkg/​tests/​networking/​workload_ingress.go Adds external-node gating.
e2e/​pkg/​tests/​networking/​packet_size.go Adds external-node gating.
e2e/​pkg/​tests/​networking/​maglev.go Adds external-node gating.
e2e/​pkg/​tests/​networking/​ipip.go Adds BGP gating.
e2e/​pkg/​tests/​kubevirt/​live_migration_mockvirt.go Adds MockVirt gating.
e2e/​pkg/​tests/​ipam/​ipam_strict_affinity.go Adds IPAM gating.
e2e/​pkg/​tests/​ipam/​ipam_gc.go Adds IPAM gating.
e2e/​pkg/​tests/​hostendpoints/​hostendpoints.go Adds external-node labeling.
e2e/​pkg/​tests/​bgp/​route_reflector.go Adds BGP gating.
e2e/​pkg/​tests/​bgp/​peers.go Centralizes BGP validation.
e2e/​pkg/​tests/​bgp/​export.go Centralizes BGP validation.
e2e/​pkg/​tests/​bgp/​bgp_password.go Adds BGP gating.
e2e/​pkg/​describe/​describe.go Adds e2e requirement labels.
e2e/​config/​nftables/​pipeline.yaml Defines nftables selection.
e2e/​config/​nftables/​native-v3-crds-gcp.yaml Configures GCP exclusions.
e2e/​config/​nftables/​native-v3-crds-aws.yaml Configures AWS exclusions.
e2e/​config/​nftables/​eks-calico-cni.yaml Configures EKS Calico exclusions.
e2e/​config/​nftables/​eks-aws-cni.yaml Moderate finding: also excludes RequiresBGP.
e2e/​config/​nftables/​arm64-wg.yaml Configures ARM64 WireGuard exclusions.
crypto/​deps.txt Updates dependencies.
cni-plugin/​pkg/​dataplane/​grpc/​proto/​cnibackend.pb.go Regenerates protobuf output.
cni-plugin/​pkg/​dataplane/​grpc/​proto/​cnibackend_grpc.pb.go Regenerates gRPC output.
cni-plugin/​internal/​pkg/​utils/​utils.go Adds pod handle parsing.
charts/​tigera-operator/​values.yaml Pins calicoctl and documents deprecation.
charts/​tigera-operator/​README.md Updates installation guidance.
charts/​deps.txt Updates Go metadata.
charts/​calico/​values.yaml Pins generated manifest images.
charts/​calico/​templates/​calico-webhooks.yaml Invokes nested webhooks.
charts/​calico/​templates/​calico-node.yaml Runs host-writing init containers as root.
charts/​calico/​templates/​calico-node-rbac.yaml Adds IPPool permissions.
charts/​calico/​templates/​calico-kube-controllers-rbac.yaml Adds IPPool permissions.
calicoctl/​tests/​st/​utils/​utils.py Ignores unasserted status fields.
calicoctl/​calicoctl/​commands/​common/​resources.go Enables offline CRD validation.
app-policy/​proto/​healthz.pb.go Regenerates protobuf output.
app-policy/​proto/​healthz_grpc.pb.go Regenerates gRPC output.
app-policy/​policystore/​ipset.go Rate-limits malformed address warnings.
app-policy/​checker/​adapter_checkrequest.go Rate-limits protocol warnings.
api/​pkg/​client/​applyconfiguration_generated/​projectcalico/​v3/​kubecontrollersconfigurationspec.go Adds profiling host configuration.
api/​pkg/​client/​applyconfiguration_generated/​projectcalico/​v3/​ippoolspec.go Updates block-size documentation.
api/​pkg/​client/​applyconfiguration_generated/​projectcalico/​v3/​ipamconfigurationspec.go Regenerates comments.
api/​pkg/​client/​applyconfiguration_generated/​projectcalico/​v3/​ipamblockspec.go Regenerates comments.
api/​pkg/​client/​applyconfiguration_generated/​internal/​internal.go Updates generated schemas.
api/​pkg/​apis/​projectcalico/​v3/​zz_generated.deepcopy.go Regenerates deepcopy code.
api/​pkg/​apis/​projectcalico/​v3/​policy_common.go Adds protocol CEL validation; moderate finding: quoted decimal protocol strings remain valid API forms.
api/​pkg/​apis/​projectcalico/​v3/​nodestatus.go Adds status period bounds.
api/​pkg/​apis/​projectcalico/​v3/​networkset.go Adds NetworkSet validation; nit: documentation still requires CIDR notation despite bare IP support.
api/​pkg/​apis/​projectcalico/​v3/​kubecontrollersconfig.go Adds defaults and profiling host.
api/​pkg/​apis/​projectcalico/​v3/​hostendpoint.go Adds endpoint protocol validation; moderate finding: quoted decimal protocol strings must remain accepted.
api/​pkg/​apis/​projectcalico/​v3/​globalnetworkset.go Adds GlobalNetworkSet validation; nit: documentation still requires CIDR notation despite bare IP support.
api/​pkg/​apis/​projectcalico/​v3/​bgppeer.go Adds peer IP validation.
api/​pkg/​apis/​projectcalico/​v3/​bgpfilter.go Expands IPv6 CIDR limits.
api/​Makefile Uses the shared Go cache.
api/​config/​crd/​projectcalico.org_networksets.yaml Regenerates NetworkSet schema.
api/​config/​crd/​projectcalico.org_hostendpoints.yaml Regenerates endpoint schema.
api/​config/​crd/​projectcalico.org_globalnetworksets.yaml Regenerates GlobalNetworkSet schema.
api/​config/​crd/​projectcalico.org_caliconodestatuses.yaml Regenerates status schema.
api/​config/​crd/​projectcalico.org_bgppeers.yaml Regenerates peer schema.
api/​config/​crd/​projectcalico.org_bgpfilters.yaml Regenerates filter schema.
api/​admission/​ippool.mutatingadmissionpolicybinding.yaml Adds IPPool defaulting binding.
.semaphore/​semaphore.yml.d/​blocks/​20-felix.yml Updates netkit configuration.
.semaphore/​semaphore.yml.d/​02-global_job_config.yml Pins the CI cache.
.semaphore/​semaphore-scheduled-builds.yml Pins scheduled-build caches.
.semaphore/​end-to-end/​pipelines/​iptables.yml Updates the RKE test lane.
.argoci/​scripts/​phases/​run_tests.sh Shares and configures the e2e cache.
.argoci/​cron/​e2e-windows.yaml Reschedules Windows tests.
.argoci/​cron/​e2e-vpp.yaml Parks VPP tests.
.argoci/​cron/​e2e-upgrade.yaml Fixes upgrade scheduling.
.argoci/​cron/​e2e-patch-verification.yaml Updates OpenShift patch testing.
.argoci/​cron/​e2e-openstack.yaml Parks unsupported OpenStack tests.
.argoci/​cron/​e2e-iptables.yaml Updates iptables test matrices.
.argoci/​cron/​e2e-certification.yaml Parks certification tests.
.argoci/​cron/​e2e-bpf.yaml Reschedules BPF tests.
.argoci/​cron/​e2e-benchmarking.yaml Reschedules benchmark tests.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

docs-not-required Docs not required for this change release-note-required Change has user-facing impact (no matter how small)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants