OpenShift Pipelines 1.24 tightens network defaults and changes multicluster routing
The GA release adds default network policies, moves observability to OpenTelemetry and introduces CEL-based PipelineRun placement as a Technology Preview.
Red Hat has listed OpenShift Pipelines 1.24 as generally available, with changes spanning network isolation, multicluster execution, observability and source-control integrations. The release notes say the version is supported on OpenShift Container Platform 4.14, 4.16 and 4.18 through 4.22.
What changed
The operator and Manual Approval Gate now create default NetworkPolicy resources. For the operator, the default rules limit controller and proxy-webhook traffic to DNS, the Kubernetes API, Prometheus metrics and webhook traffic. Administrators can reconcile, override or disable the proxy-webhook policy through the TektonPipeline custom resource. Manual Approval Gate also enables restrictive ingress and egress policies by default, with an explicit opt-out in its custom resource.
For multicluster builds, the release adds Technology Preview routing based on Common Expression Language. Tekton Kueue can evaluate PipelineRun labels, annotations or event types and route individual runs through managedBy() and multiKueue() functions, replacing the previous all-or-nothing override.
OpenShift Pipelines components also move their observability plumbing from OpenCensus to OpenTelemetry. The change affects metrics names: standard Knative and OpenTelemetry prefixes replace the older tekton_pipelines_controller_* infrastructure metrics. Pipelines as Code now configures tracing directly through the OpenTelemetry SDK and supports parent-based samplers.
Other operational changes include compressed task termination messages, which Red Hat says can raise effective result capacity from roughly 33 to 187 results, and support for recording CustomRun resources in Tekton Results. The web console gains persistent date-range and datasource filters for PipelineRun and TaskRun views.
Who is affected
Platform teams should review monitoring rules and dashboards that depend on the old metrics prefixes. Clusters using Pipelines as Code should also note that Tekton Hub integration has been removed there, while the related tkn hub commands are deprecated in favor of Artifact Hub.
The release includes several source-control fixes. GitLab definitions and referenced tasks are now pinned to the event SHA, branch-creation push events can trigger runs, and token rotation checks write access before revoking the old token. Bitbucket Data Center scoped tokens can authenticate through service accounts without a dedicated user field.
What to do
Before upgrading, operators should compare existing namespace and component network policies with the new defaults, inventory alerts that use legacy Tekton metric names, and test any Pipelines as Code workflow that depends on Tekton Hub. CEL-based multicluster placement remains a Technology Preview, so it should be evaluated separately from production routing policy.
sources
- Red Hat OpenShift Pipelines 1.24 release notesdocs.redhat.com
comments · 0