chore(deps): update ghcr.io/open-telemetry/opentelemetry-operator/opentelemetry-operator docker tag to v0.159.0 - autoclosed - #1959
Closed
renovate[bot] wants to merge 1 commit into
Conversation
Contributor
There was a problem hiding this comment.
Pull request overview
Updates the Logs extension’s bundled OpenTelemetry Operator image reference (and corresponding extension/chart versions) to the newer upstream release.
Changes:
- Bump
logsPluginDefinition version and referenced Helm chart version. - Update the OpenTelemetry Operator image tag in Helm values to
v0.158.0(pinned by digest). - Bump the Helm chart version for the
logschart.
Reviewed changes
Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| logs/plugindefinition.yaml | Bumps plugin and referenced Helm chart versions. |
| logs/charts/values.yaml | Updates OpenTelemetry Operator image tag to v0.158.0 with digest pin. |
| logs/charts/Chart.yaml | Bumps chart version (but leaves appVersion outdated vs the new operator version). |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+5
to
+7
| appVersion: 0.152.0 | ||
| name: logs | ||
| version: 0.4.54 | ||
| version: 0.4.55 |
renovate
Bot
force-pushed
the
renovate/ghcr.io-open-telemetry-opentelemetry-operator-opentelemetry-operator-0.x
branch
3 times, most recently
from
September 3, 2026 09:33
e31501d to
d1e30bb
Compare
renovate
Bot
force-pushed
the
renovate/ghcr.io-open-telemetry-opentelemetry-operator-opentelemetry-operator-0.x
branch
5 times, most recently
from
September 14, 2026 12:00
de1458b to
7489994
Compare
renovate
Bot
force-pushed
the
renovate/ghcr.io-open-telemetry-opentelemetry-operator-opentelemetry-operator-0.x
branch
4 times, most recently
from
September 18, 2026 10:54
6f7da54 to
43d10ca
Compare
…ntelemetry-operator docker tag to v0.159.0
renovate
Bot
force-pushed
the
renovate/ghcr.io-open-telemetry-opentelemetry-operator-opentelemetry-operator-0.x
branch
from
September 21, 2026 12:35
43d10ca to
f0656e7
Compare
renovate
Bot
deleted the
renovate/ghcr.io-open-telemetry-opentelemetry-operator-opentelemetry-operator-0.x
branch
September 22, 2026 07:44
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v0.152.0→v0.159.0Release Notes
open-telemetry/opentelemetry-operator (ghcr.io/open-telemetry/opentelemetry-operator/opentelemetry-operator)
v0.159.0Compare Source
0.159.0
🛑 Breaking changes 🛑
target allocator: Addnoneas an explicit filter strategy and preserve explicitly configured empty strategies. (#5444)The Go type of
TargetAllocatorSpec.FilterStrategychanged to a pointer so typed clients candistinguish an unset strategy from an explicitly configured value. The legacy empty value remains
accepted as an alias for disabling filtering, but new configurations should use
none.The Target Allocator now rejects any other value of
filter_strategyon startup, and normalizesthe empty value to
nonewhen loading its configuration.💡 Enhancements 💡
collector: AddresizePolicyto the OpenTelemetryCollector CR to control how the primary container responds to in-place resource resizes. (#5501)opampbridge: Add explicit proxy configuration for OpAMP Bridge server connections. (#5351)target allocator: Add anallocation_strategy_configsection to the target allocator configuration, allowing the per-node fallback strategy to be set viaallocation_strategy_config.per_node.fallback_strategy.name. (#5183)The top-level
allocation_fallback_strategyoption is now deprecated in favor of the newstrategy-specific configuration. When both are set, the strategy-specific option takes precedence.
target allocator: Add API fields to configure the TargetAllocator's OTLP self-telemetry export. (#5047)Adds
spec.targetAllocator.telemetry.metrics.readerson the OpenTelemetryCollector CR andspec.telemetry.metrics.readerson the TargetAllocator CR. The schema mirrors the OTeldeclarative configuration spec. The operator renders these
fields into the TargetAllocator ConfigMap consumed by the binary-side OTLP self-telemetry
support.
When the
operand.networkpolicyfeature gate is enabled, the TargetAllocator's generatedNetworkPolicy now leaves egress unrestricted if self-telemetry export is configured, since
its destination can be an arbitrary (often external) endpoint that can't be scoped with a
NetworkPolicy IPBlock/selector.
🧰 Bug fixes 🧰
collector: Report aReady=Falsestatus condition and a Warning event on the OpenTelemetryCollector when the referenced TargetAllocator cannot be fetched or the collector manifests cannot be built, instead of only logging the error in the operator. (#4296)collector: Detect changes to the immutable StatefulSetpodManagementPolicyfield so the collector StatefulSet is recreated instead of failing reconciliation with a forbidden update error. (#4203)operator: Resolve the operator's own Deployment through pod owner references instead of a hardcoded name, so the operator NetworkPolicy no longer crashes the operator or selects no pods when installed with custom names (e.g. via the Helm chart). (#5493)operator: Add API server discovery fallback to env vars and guard CSV controller on non-OLM clusters. (#5493)When EndpointSlice discovery fails, the operator now falls back to KUBERNETES_SERVICE_HOST
and KUBERNETES_SERVICE_PORT environment variables for API server discovery. The CSV webhook
controller is skipped on clusters without OLM (operators.coreos.com CRDs not present).
opamp: Rebuild the OpAMP Bridge's applied-keys tracking from cluster state on startup, so a remote config that drops a collector after a bridge restart correctly deletes it. (#5445)Components
v0.158.0Compare Source
0.158.0
💡 Enhancements 💡
operator, collector, target allocator: Enable operator, collector, target allocator network policies by default. (#5394)Feature gate
operator.networkpolicyandoperand.networkpolicyare promoted to beta, and enabled by default.These feature gates create network policies for the operator and operand components.
auto-instrumentation: Apache and nginx instrumentations forward Spec env vars to attach init containers so kubelet can expand $(VAR) references in exporter endpoints. (#5333)collector: promote the operator.collector.usedefaulttelemetryshape feature gate to stable, so the operator-injected Prometheus telemetry reader always uses collector defaults for without_type_suffix, without_units, and without_scope_info (#5075)The gate is now stable and can no longer be disabled. Users wanting the
pre-v0.154.0 metric name shape should explicitly set
without_type_suffix,without_units, andwithout_scope_infotofalsein their collector configuration. The gate will be removed in a future release.
collector: moves operator.golang.flags to stable setting GOMEMLIMIT and GOMAXPROCS automatically (#5455)🧰 Bug fixes 🧰
collector: Fix the automatic-upgrade routine binding two Prometheus readers to the same port when a collector already usesservice.telemetry.metrics.readers. (#5416)When an OpenTelemetryCollector already configured
service.telemetry.metrics.readers(added by earlier defaulting), the automatic version-upgrade routine still backfilled the
older, deprecated
addressfield for it. The 0.122.0 upgrade step then migratedaddressinto a new reader, leaving two readers bound to the same host:port. The collector then
failed to start with "address already in use". The 0.111.0 step now skips backfilling
addresswhenreadersis already configured, and the 0.122.0 step now skips adding areader for
addressif an equivalent one already exists.collector: Add PersistentVolume and PersistentVolumeClaim RBAC rules for k8s_cluster receiver automatic RBAC generation. (#5421)auto-instrumentation: DefaultOTEL_METRICS_EXPORTERtootlpfor Node.js auto-instrumentation so metrics are exported without extra configuration. (#3768)The Node.js SDK only initializes its metrics pipeline when a metric reader is configured, and the
webhook was not setting one. As a result, metrics silently stopped being exported for anyone relying
on the previous default behavior. The webhook now sets
OTEL_METRICS_EXPORTER=otlpby default,matching the existing behavior for Python auto-instrumentation, unless the user already set it.
Components
v0.157.0Compare Source
0.157.0
💡 Enhancements 💡
target allocator: Allow enabling mTLS between the target allocator and the collector using user-provided certificate Secrets, without requiring cert-manager. (#3982)When
spec.targetAllocator.mtls.useCertManageris set tofalse, the newmtls.tlsblockreferences user-provided certificates. The CA certificate may be sourced from either a Secret or a
ConfigMap (
certificateAuthorityCertificate.secret/.configMap). The target allocator's servercertificate and the collector's client certificate each reference their certificate and private key
independently, so the certificate and key may live in different Secrets. Data keys default to
tls.crt,tls.keyandca.crtand can be overridden per reference. The CA reference is requiredin this mode.
operator: Add support for Kubernetes 1.36 (#5354)🧰 Bug fixes 🧰
target allocator: Seed Prometheus's scrape labels (job,__scheme__,__metrics_path__,__scrape_interval__,__scrape_timeout__,__param_*) before relabel filtering, so keep/drop rules referencing them make the same decisions as Prometheus instead of silently dropping or over-allocating targets (#5246)The seeded labels also feed the target identity hash, matching Prometheus's post-relabel label partition more closely. With the
relabel-configfilter strategy enabled, existing targets are re-allocated once on upgrade because their hashes change. The served (pre-relabel) target labels are unchanged.Components
0.157.0
💡 Enhancements 💡
auto-instrumentation: Theautoinstrumentation-dotnetimage now bundles the correct native profiler for the platform it is pulled for, fixing arm64 support (the image was already published for arm64 but always contained amd64 binaries). (#3270)operator-opamp-bridge: Adds support for the OpAMP capability AcceptsRestartCommand to the operator's OpAMP bridge, allowing the operator to restart the collector when requested by an OpAMP server. (#5306)operator-opamp-bridge: Add anopentelemetry.io/opamp.bridge.modenon-identifying OpAMP AgentDescription attribute so servers can distinguish operator and standalone bridge clients. (#5423)operator-opamp-bridge: Report the operator-opamp-bridge's own build version asservice.versionin its OpAMP AgentDescription, instead of always sending an empty string. (#5360)collector: Add support for settingsessionAffinityandsessionAffinityConfigon the Services created for the Collector (#4455)target allocator: Support exporting the TargetAllocator's self-telemetry metrics via OTLP, in addition to the Prometheus /metrics endpoint. (#5047)Configure it under
spec.targetAllocator.telemetry.metrics.otlp(OpenTelemetryCollector CR) orspec.telemetry.metrics.otlp(TargetAllocator CR), with endpoint, protocol (grpc/http), temporality,headers, TLS and export interval/timeout. Metrics registered directly on the Prometheus registry
(Prometheus service discovery, Go runtime and process collectors) are bridged into the OTLP export
so the Prometheus endpoint and OTLP expose the same metric set.
🧰 Bug fixes 🧰
cluster-observability: Fix dependencies required by the bundled agent and cluster Collector configurations (#3821, #3818)Follow-ups to the initial ClusterObservability framework so generated
Collectors start cleanly across supported distributions:
defaulting to the operator's Collector version and supporting the
--clusterobservability-collector-imageoverride. Apply matching versionlabels and canonical component IDs.
K8S_NODE_NAME, which the bundledkubelet_statsreceiver usesfor its endpoint.
ClusterObservabilitydoes not remainPendingafter the workload is ready./hostfsforhost_metricsand exclude virtualand container-runtime filesystems that cannot be scraped reliably.
spc_tSCC sofile_logcan read root-owned container logs under
/var/log/pods.Instrumentationresources to the agent's OTLP/HTTP portbecause auto-instrumentation SDKs commonly use
http/protobuf.collector: Fix OpenShift collector dashboard (#5342)The collector v0.155.0 renamed the deprecated
otelcol_processor_accepted_*/dropped_*/refused_*metricsto
otelcol_processor_memory_limiter_*(open-telemetry/opentelemetry-collector#11203).The dashboard queries have been updated to use the new metric names.
collector: Register the snake-case spellings of several renamed receivers (kubelet_stats,k8s_objects,resource_detection,fluent_forward,tcp_log,udp_log,ssh_check,cloud_foundry,http_check,flink_metrics) alongside their original spellings when generating RBAC and service ports from a Collector CR, so either spelling produces the same result. (#5317)These components were renamed to snake_case in opentelemetry-collector-contrib
(#47957 kubeletstats, #47440 k8sobjects, #48525 resourcedetection, #47930
fluentforward, #47369 tcplog, #47370 udplog, #47515 sshcheck, #47932
cloudfoundry, #47505 httpcheck, #47929 flinkmetrics) while keeping the
original names accepted, but the operator only recognized one spelling per
component, so configs using the other spelling got no RBAC/ports or the
wrong service port name. This extends the k8s_attributes fix (#4983) to
the remaining renamed components, and makes
NewScraperParseracceptaliases so future renames of this kind are a one-line fix.
target allocator: Fix collector mtls with a TargetAllocator CR (#4297)This only affected collectors associated with a TargetAllocator CR whose name differs from the
collector's, e.g. via the
opentelemetry.io/target-allocatorlabel, causing them to address thewrong hostname (and TLS certificate) once mTLS was enabled.
target allocator: Refresh stale Prometheus meta labels (e.g.__meta_kubernetes_pod_name) on rediscovered targets whose address is unchanged (#4839)Target identity is deliberately hashed without meta labels, since Prometheus discards them after
relabeling. But because the allocator's target map is keyed by that same hash, a rediscovered
target whose address is unchanged (e.g. a hostNetwork DaemonSet pod after a restart) was never
recognized as changed, so its stale meta labels persisted until target-allocator itself restarted.
collector: Fix operator crash on startup when Gateway API CRDs are not installed by moving gatewayv1 scheme registration to be gated on autodetect result. (#5357)auto-instrumentation: Apply security context to Java extension init containers (#5335)Extension init containers injected alongside the Java agent were not receiving
a security context. This affected both the explicit
spec.initContainerSecurityContextfield on the Instrumentation CR and the fallback behaviour that inherits the
security context from the instrumented application container. Only the main
opentelemetry-auto-instrumentation-javainit container was having its securitycontext set; extension containers were always created with a nil security context.
This caused admission failures on clusters with policies that require all
containers to drop capabilities or disallow privilege escalation (e.g. OPA
Gatekeeper). The security context is now applied to all Java-related init
containers at construction time.
target allocator: Propagate the TargetAllocator CR's metadata annotations to all resources created for it, and restrictpodAnnotationsto the pod template (#4393)This aligns the TargetAllocator with the OpenTelemetryCollector behavior: CR metadata annotations now land
(respecting the annotations filter) on the Deployment, Service, ConfigMap, ServiceAccount, ServiceMonitor,
PodDisruptionBudget and NetworkPolicy, while
podAnnotationsis no longer copied to the NetworkPolicy andPodDisruptionBudget.
Components
v0.156.0Compare Source
0.156.0
🧰 Bug fixes 🧰
collector: Honorspec.observability.metrics.disablePrometheusAnnotations: trueon update by removing the operator-stamped prometheus.io annotations from the pod template, not just stopping new ones from being added. (#5043)Previously the pod-template mutate path preserved any annotation that
existed on the current resource but was absent from the desired render,
so toggling disablePrometheusAnnotations from false to true on an
existing OpenTelemetryCollector left the prometheus.io/scrape, port,
and path annotations stuck on the rolled pods. The operator now stamps
an ownership marker (operator.opentelemetry.io/prometheus-annotations-added)
whenever it adds one of the default prometheus.io/* annotations, and
the mutate path strips those annotations only when the marker is
present on the existing pod template. This preserves prometheus.io/*
annotations the user set out of band on the same collector.
Components
v0.155.0Compare Source
0.155.0
🧰 Bug fixes 🧰
operator: Fix NetworkPolicy and operand network policy defaulting when webhooks run in a separate deployment. (#5288)collector: Collectors with persistent storage no longer fail with "permission denied" on OpenShift when running under a permissive SCC such as anyuid. (#5224)On OpenShift, the restricted SCC injects fsGroup from the namespace range, but
permissive SCCs (e.g. anyuid) do not. The controller now defaults
podSecurityContext.fsGroup from the namespace's supplemental-groups or UID range
annotation when no explicit fsGroup is configured. An explicitly set fsGroup is
never overwritten.
Components
v0.154.0Compare Source
0.154.0
🛑 Breaking changes 🛑
collector: Promote the operator.collector.usedefaulttelemetryshape feature gate to beta. The operator-injected Prometheus telemetry reader now uses collector defaults by default — metric names from operator-managed collectors no longer carry type suffixes, units, or scope_info. (#5075)Users wanting the pre-v0.154.0 metric name shape can disable the gate via --feature-gates=-operator.collector.usedefaulttelemetryshape, or pin without_type_suffix/without_units/without_scope_info to false explicitly under spec.config.service.telemetry. The gate will be promoted to stable and removed in a future release.
💡 Enhancements 💡
collector: Add status.observedGeneration and status.conditions support for OpenTelemetryCollector resources. (#4312)operator: Add pod-webhook subcommand for running a standalone pod mutation webhook (#5010)The operator binary now supports a
pod-webhooksubcommand that runs only the pod mutationwebhook (auto-instrumentation and sidecar injection) without the controllers. This enables
deploying the webhook separately.
opampbridge: Add TLS configuration support to the OpAMP Bridge, including options to disable TLS or skip certificate verification. (#4921)opamp: Allow standalone OpAMP bridge agents to configure per-agent non-identifying attributes. (#5245)opamp-bridge: Make standalone OpAMP Bridge manifests and runtime permissions friendlier for OpenShift and namespaced RBAC. (#5277)operator: Add standalone pod webhook deployment for High Availability on OpenShift (#5010)On OpenShift with OLM, the pod mutation webhook (auto-instrumentation and sidecar injection)
is now deployed as a standalone Deployment with 2 replicas by default, enabling HA.
OpenShift with OLM:
OPENSHIFT_WEBHOOK_REPLICASenv var in the Subscription (0 or 1)Kubernetes (community bundle):
opamp-bridge: OpAMP Bridge standalone mode (#4913)Standalone mode for OpAMP Bridge allows users to manage collector configuration from a remote
OpAMP server without the need to deploy full Otel Operator.
operator: Move all webhooks to the dedicated webhook deployment. (#5010)This change moves remaining webhooks (defaulting, validating for: Collector, TargetAllocator, Instrumentation, OpAMPBridge) to the dedicated webhook deployment.
Previously, only the pod mutation webhook was served by the webhook deployment, while the other webhooks were served by the controller-manager.
The dedicated webhook deployment is opt-in and enabled by default only on OpenShift with OLM.
🧰 Bug fixes 🧰
target allocator: Fix silent target loss when group labels are present in static_configs by sorting labels globally in processTargetGroups. (#4967)ScratchBuilder.Labels() serializes labels in insertion order. When group labels sort
alphabetically after target labels (e.g. vendor > address), Labels.Get() early
termination returns empty, causing hash collisions that silently drop targets.
auto-instrumentation: Use MergeFrom patch for Instrumentation blocked-versions status to avoid overwriting unrelated status fields. (#5243)target allocator: Accept a prometheus receiver that only declarestarget_allocator:without aconfig:block. (#2998)When the prometheus receiver is configured with only a
target_allocator:block and noconfig:,reconciliation previously failed with
no prometheusConfig available as part of the configuration.The target allocator supplies scrape configuration externally in this mode (e.g. via discovered
PrometheusCR objects), so the operator now skips the scrape_configs cleanup when no
config:block is present. The webhook validator likewise permits this shape.
Components
v0.153.0Compare Source
0.153.0
🛑 Breaking changes 🛑
api: Move apis package to a separate sub-module (#4362)Yamlstandalone functions ininternal/otelconfigis moved to a methods on*Config(packageapis/v1beta1)CheckTargetAllocatorPrometheusCRPolicyRulesfromapis/v1beta1/targetallocator_rbac.gotointernal/webhook/targetallocator_rbac.go+ rename it tocheckTargetAllocatorPrometheusCRPolicyRules.OpenTelemetryCollectoris not implementing theConvertibleinterface fromsigs.k8s.io/controller-runtime/pkg/conversion, but implements 2 helper function the achieve the same functionality:apispackage to a dedicated sub-module.target allocator: Theoperator.targetallocator.mtlsfeature gate has been removed. mTLS is now configured per-CR viaspec.mtls.enabledon the TargetAllocator or Collector resource. (#5136)Set
spec.mtls.useCertManager: falseto provide your own TLS secrets instead of having cert-manager provision them.💡 Enhancements 💡
collector: Add optionalspec.commandto OpenTelemetryCollector to override the collector container entrypoint (#3188)spec.commandis a[]stringmatchingPod.spec.containers[].command.target allocator: Add allowInsecureAuthSecrets option to serve auth secret values over plain HTTP without mTLS (#3746)Adds a new allowInsecureAuthSecrets field to both the TargetAllocator CRD and the
embedded TargetAllocator in the OpenTelemetryCollector CRD. When enabled, auth secret
values (e.g. basicAuth passwords) are served over plain HTTP instead of being masked.
This is useful when transport security is handled by a service mesh or equivalent.
🧰 Bug fixes 🧰
must-gather: Fix must-gather output to produce omc-compatible directory layout and correct YAML serialization (#4965)Previously collected files used a per-collector directory with kind-prefixed filenames (e.g.
namespaces/<ns>/<collector-name>/deployment-<name>.yaml),which omc cannot parse. Output now follows the standard omc layout (
namespaces/<ns>/<api-group>/<resource-plural>/<name>.yaml).Also fixes missing apiVersion/kind fields in serialized YAML, incorrect default output directory, and adds collection of CRDs and OpAMPBridge resources.
opamp: Skip OpenTelemetryCollector instances with a non-nil DeletionTimestamp when building EffectiveConfig (#5170)ListInstances returns objects with DeletionTimestamp set until finalizers complete.
Reporting them as effective races with the bridge's own Delete calls in applyRemoteConfig.
collector: Fix Service reconciliation to propagate trafficDistribution, internalTrafficPolicy, ipFamilies, and ipFamilyPolicy changes (#5141)Components
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.