v3.6.0-rc1 (pre-release)
Quick Start
Non-HA:
kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.6.0-rc1/manifests/install.yaml
HA:
kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.6.0-rc1/manifests/ha/install.yaml
Release Signatures and Provenance
All Argo CD container images are signed by cosign. A Provenance is generated for container images and CLI binaries which meet the SLSA Level 3 specifications. See the documentation on how to verify.
Release Notes Blog Post
For a detailed breakdown of the key changes and improvements in this release, check out the official blog post
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changelog
Features
- bac4616ca429ba92af1b312cb8a2cac36e1cfdea: feat(actions): add hibernate/rehydrate actions for CNPG Cluster (#28478) (@purisev)
- 0df1a4bcced9a8400d6ddafaf168e6e847209ec8: feat(appset): Add progressive sync metrics for AppSet (#29202) (@ranakan19)
- ad23d3a9c04134f42661b5cbdb5aaeac46a1cdad: feat(appset): Adding annotations on apps to force reconciliation before proceeding with progressive sync (#27467) (@ranakan19)
- 94564eba18592d1bc2fc20e64415c9214203a5d4: feat(appset): add metrics for count of app refreshes triggered by appset during progressive sync (#29244) (@ranakan19)
- 9ef034e688e86f45fa63465710d5883d88c2ddde: feat(appset): expose workqueue rate limiter flags on applicationset-controller (#28286) (@om7057)
- 5899f89f745513f324ff0999cf7770821b7b7fd0: feat(appset): surface progressive sync scenario into condition as reasons and messages (#27820) (@ranakan19)
- 4e8ea39ca215a7f4c4df2d159dc3a88a8e60d994: feat(ci): enable Zizmor to enforce secure config (#27304) (@crenshaw-dev)
- ec10f2e627042e29044b6de5f550f6bacf19708e: feat(cli): optionally exclude status field when using
argocd admin exportcommand (#29219) (@nitishfy) - 5c3637def4bef8daf16311877d9bc6f98f39f4ec: feat(controller): allow metrics label/condition flags via argocd-cmd-params-cm (#28287) (@edgrz)
- d94bcb1215c15bbe12835b4653e7c58f42b9241f: feat(dex): Configure TLS Minversion for Dex web (#28712) (@akhilnittala)
- 465d43b2455fa60c45c02041b553054921934e3d: feat(dex): Making Dex storage type and config configurable from argocd-cm configmap (#28624) (@akhilnittala)
- 2e2f4e450d57bafa249aaa330d61901f76d424df: feat(health): Implement kyverno health checks (#27354) (@sandert-k8s)
- 034ab6150952f23071d452f0f6fc0b400124d7e1: feat(health): add built-in health check for TLSRoute (#26596) (@dnfwlq8054)
- 49aa0eab6d876ba8a69b198e8319495c9931dcfb: feat(health): add health check for AWS ACK resources (#29016) (@philljie)
- e1145c626c7dee9ba7e437447bc2b3319e042f3f: feat(health): add health check for CloudNativePG Backup (#28468) (@yugstar)
- 643de0bcff5a48076ce582d8b096a3f5fc1402ff: feat(health): add health check for CloudNativePG Database CRD (#29511) (@Matthiator)
- ff00ee7d69ffc3d85b175bf37bbc40c7e814d183: feat(health): add health check for Kro resources (#28743) (@philljie)
- 3825b96ac9ce29b500f8895e47fd44fa26901a74: feat(health): add health check for MedusaBackupJob (issue #28009) (#28008) (@mgross2)
- 309594ba94218770caa0e922530962b915741b0f: feat(health): add health check for MedusaTask (issue #28007) (#28006) (@mgross2)
- 6858a80b2af7fde484986ea4bc282c85a489d1fd: feat(health): add health check for Prometheus Operator Alertmanager (#28446) (@yugstar)
- 2338867cea9ca0390ae5ad33a9b045f72a797f73: feat(health): add health check for Prometheus Operator ThanosRuler (#28463) (@yugstar)
- 831d77b52c809dec1ae8b7107ccb264825402d7d: feat(health): add health check for cert-manager CertificateRequest (#28465) (@yugstar)
- dec470a0ab16b7c6a97fe4eb58f9ae430eb0a04f: feat(health): add health check for cert-manager trust-manager Bundle (#28615) (@yugstar)
- fdf6751b85a04b0b60a23ec0bcd5641c814b09ec: feat(health): add health check for flink.apache.org/FlinkSessionJob (#26626) (@sivchari)
- 21ac508ef6aaae8238710688fbf26e0c20d2b9d7: feat(health): add health checks for Tekton PipelineRun and TaskRun (#28467) (@yugstar)
- 180061c9b2cd879b966f60a46e09a83001acc4d8: feat(health): add health checks for Velero Backup, Restore, and Schedule (#28464) (@yugstar)
- 57088014f10c71331ce6719f1c85d778ccfd5b14: feat(health): add health checks for cert-manager ACME Order and Challenge (#28466) (@yugstar)
- 291bfab82175b7580165a7a11be282151eac0ad8: feat(health): enable a Pipeline labeled 'recyclable-expired' to be deleted (#28532) (@juliev0)
- 463f39afe5d91882e51c345fe5bce6ead40adeae: feat(health): support ListenerSet.gateway.networking.k8s.io (#28388) (@root30)
- ffe66fff46708bbbe4183b13f3d2cde657664c4b: feat(health): support custom deletion messages (#27595) (#27596) (@crenshaw-dev)
- 5e8ed632babda75965940a0f175010bb974b50b7: feat(health): support various policies _.microgateway.airlock.com (#28268) (@root30)
- 961bd434659679dd9d80e8a4d83acb71dfcec2cd: feat(hydrator): add metrics to app info (#29512) (#29514) (@crenshaw-dev)
- 2d71dc6b6e4e1ddda65f950bb3f538e04ca7c76e: feat(hydrator): sign hydrated commits (Alpha) (#28239) (#28271) (@mladjan-gadzic)
- c2df91b70ff69c24b1b5fc457e384fafab573544: feat(impersonation): allow to disable strict enforcement (#27084) (#27573) (@agaudreault)
- e2b719ad65d7b09002e0b17b8f1bdf8640c6e7e8: feat(otel): add spans with configurable sampling (#28396) (@blakepettersson)
- b2e6d1d929cdca79f774075bfaef9f738f1d1524: feat(perf): configurable serialization and compression for cached manifests (#26897) (#28600) (@adityaraj178)
- e5eb504a3a2b8ad3013dfc6b9962c2a071a4772d: feat(perf): count apps per cluster in a single pass (#29570) (@rumstead)
- 4c36558382aad92ccdc8129f7045db6f84807950: feat(perf): drop two redundant application copies from the refresh path (#29581) (@rumstead)
- 37273e31438a571e337058efb6e3fbbe1b28044b: feat(perf): partial json unmarshalling (#29378) (@blakepettersson)
- 0f901d1e2d9f9e9da3e52ddde9d0c97542aa6a91: feat(perf): resolve the destination server without copying the cluster (#29573) (@rumstead)
- 0c2545d51db30d8ce5e80a19883f4e8b65bf2947: feat(perf): reuse matrix child params when the generator is unchanged (#29582) (@rumstead)
- 54a740e1048b80eb3f4856e2cdc25c9bae51df94: feat(resource_customizations): support ignored status for victoriametrics healthcheck (#29351) (@AndrewChubatiuk)
- 4abcbcf1a904e2ec6ba3310f22d5763b3e4bc772: feat(server): Add support for redirect to selected Dex connector (Alpha) (#24221) (@antonu17)
- e4470c5ff3cd0a4b948714c3f3c19731d26be05b: feat(server): add configHash field to Cluster (#25311) (#27657) (@matmil-dev)
- fc848eb1b454870ebab17d1092c44ae6017b3991: feat(server): set X-Robots-Tag to prevent indexing of the UI (#28359) (@yugstar)
- 0141bf077dea55a15437401e7a61ab07fd2f9ad3: feat(tls): Make TLS Curve prefereneces configurable while setting TLS options for repo-server and server. (#28846) (@akhilnittala)
- ba47c6b6b0015a9939cd630db444a1e9aa1f957f: feat(ui): Implement virtual scrolling for Apps list/tiles view when
allis selected (#29542) (@aali309) - bf984eaa6c17dc1d832bbbfd44760cd1e82ada06: feat(ui): Lazy loading (#29087) (@jwinters01)
- ac0119467ed8bcccf960fffdbe2603f9c6b95efb: feat(ui): add regex search toggle to application(sets) list (#27857) (#27889) (@rickbrouwer)
- 807320130714a5939242a47f32e48e28a97a02fa: feat(ui): add resources explorer view (#28098) (@agaudreault)
- 5b4b5def23bce4e7a0d26478ba1674361aab12b1: feat(ui): add search bar and pagination to settings pages (#28305) (@agaudreault)
- e2a605e0d0a1f2c154c4f2215f8c66a02beba602: feat(ui): add server-side name filter to applications list and watch (#29106) (#29242) (@rickbrouwer)
- f495ca51ee8f5d725c3ea38c4b7d1a8c227b5f29: feat(ui): advanced settings view (#28383) (@agaudreault)
- 4fa944edff93a4116eee008e6b018057d4da6965: feat(ui): enable React Compiler in the build (@jwinters01)
- 9cf8d7c125ac534aa58c1ee089fb48dbe80cd1d4: feat(ui): sidebar anchors (#28527) (@blakepettersson)
- 91f7adcbcfecfdeb21e87678ccdb1bc1ae15172a: feat(ui): use anchors instead of divs in app/appset tiles and tablerows (#28005) (@blakepettersson)
- 73bf020633ecd20cd4d96ec9af504b8aab4c98aa: feat(webhook): Add manifest-generate-paths annotation support for BitBucket Server (#27552) (@adityaraj178)
- ca3139e842d84130ec9ed39bdfaa57ee3998bd1d: feat(webhook): add webhook support for harbor (#27810) (#27884) (@adityaraj178)
- 7bdadbf693502e8ac5cdfda281e2972eaa2a04da: feat(webhooks): add webhook support for DockerHub (#28022) (@nitishfy)
- 79b0815beb400ed0ec9c32e36ba7360d4e9b98f4: feat: Add deprecation warning when using --signature-keys (#28941) (@kuci-JK)
- b5d698a00a2797cbadb8c6d7769b0161daea0f18: feat: Add health check for pulumi.com/Stack (#28534) (@guineveresaenger)
- 0703fcacf7c7411ffbc3fabf511b7eadc5ec3927: feat: Add health check resource customizations for Envoy Gateway Extension CRDs (#27291) (@obliadp)
- 34427a68b08f46f0bd43846213a2aaf24452cbd6: feat: Add reporting component to events list (#25684) (#27678) (@Suven-p)
- 816fcd02cf47cdfaebd93df9bd9d9dac332ff7ab: feat: Allow pod healthcheck to ignore restart policy via annotation (#15317) (Alpha) (#28249) (@jskrill)
- 48f94615f072046d6621287e0b5c86c07efafed9: feat: Default to SSD with SSA and remove SMD (#29103) (@pjiang-dev)
- 35238e3472a27604de22939d217bdf98c3ca9b0b: feat: Replace SIGNATURE-KEYS with SOURCE-INTEGRITY in proj list (#28920) (@kuci-JK)
- 7a80e4ca9272889d9c452cedca7fe459b06bc127: feat: accept repository-style Azure keys in repo-creds (#29414) (#29415) (@SHINMH)
- 1828831237e85645081cb4483061de4f1687ce4f: feat: add
tplfunction to ApplicationSet go-templating (#16302) (#26614) (@twobiers) - 58d427f5391887092d1ff36c61157a865fadea8d: feat: add a button to clear logs in the pod logs viewer (#27149) (@gcadoret)
- eb15eb4a23c8820c35a45756ff3a28bd77b3a0c6: feat: add bundled health check for KServe LLMInferenceService (#29599) (#29620) (@sarfarazgit)
- dcdf8e4026450611d23077271705a44a9f21d10b: feat: add clear all button to ApplicationSet filters (#28593) (@choejwoo)
- 619c642457581e5929b8628676a7c4517e358c87: feat: add configurable SSO login button text via ui.loginButtonText (#28254) (@NotKiwy)
- bcb771e29326321b7be0c4bfe2d2a7c742ac7955: feat: add oci generator for applicationsets (#26121) (@robinlieb)
- 68b8af21e358fa01ea42ba34aa26ab3bd854c4ab: feat: add option to disable Swagger UI endpoint (#28717) (@smahadik-27)
- 79e1229469403a4e9cbab5043f9128948711a330: feat: add which resources caused the app health to change (#28455) (@agaudreault)
- e8e5ba20f7a2449a254cc2a380c293099159da38: feat: adds a server-proxy-url flag in cluster add command (#28134) (@ppapapetrou76)
- bcf18220b76d55a00599da0b8993276c2a419f72: feat: allow optionally setting a prefix for redis keys (closes #12978) (#26169) (@healthy-pod)
- 7cfc6cfd2e7b5de1b9e29ee497a07135405047d2: feat: allow to create Jobs from CronJobs with OwnerReferencesPermissionEnforcement admission (#26009) (@sathieu)
- 0984033236c695ee20ae344c402fa0d30e8a30fd: feat: support REDIS_SENTINEL and REDIS_SENTINELMASTER env vars (#28391) (@suii2210)
- 127dbe7bcd94f3f6883eae1f2f3465763e5a5282: feat: support filtering out managed resources using label selector (#29423) (@alexmt)
- 9e9c2f1e751242cb3c26aaa9cc5d4cbe6426139e: feat: support ignore-differences annotation on resources (#29616) (@ranakan19)
- 7d05a395eb4149c9c8d41cad3f27a20c3d6367fd: feat: support separate RBAC permission for application rollback (#28924) (@ppapapetrou76)
Bug fixes
- 545bcb5eeba8240ffa47299ee9ace8bb54c61dc8: fix(SyncWindow): rename SyncWindow to InlineSyncWindow (#29152) (@adityaraj178)
- dcf03494eff98102a44ea10f1a66d80b8644b948: fix(UI): display sync option dropdowns on separate lines (#28438) (@adityaraj178)
- 20ad5f9922600aaa54b82daa4cd7a5e3f63a709f: fix(application): use server-side timeout query parameter via transport wrapper (#28828) (#28977) (@luwangVMW)
- 9bb331250c0d3f8d47d337208866afca93f86b73: fix(appset): don't release finalizer while children still terminate (#28999) (@blakepettersson)
- 777f9132b73d6f9b93798f6c4900556c36b1cf7f: fix(appset): fail reverse deletion when a stale cache entry cannot be evicted (#29042) (#29140) (@himeshp)
- fea95e66c423f71c393f1303dc6a2a85a858b5d5: fix(appset): fall back to create when patch returns NotFound (#17312) (#28645) (@rickbrouwer)
- a822683efd4a73360b5643b6a2d53d2f2326ee7e: fix(appset): restore ignoreApplicationDifferences after normalization (#29070) (@pjiang-dev)
- 3be29876ba77072cfbf4585b2d8a28b2d0912a1a: fix(appset): stop progressive sync reconciling in a tight loop (#27577) (#29044) (@himeshp)
- 4891d4f4745ae87b9aebd2577d0fe5a3433b8aab: fix(appset): throw error when generated apps have empty name (#28833) (@nitishfy)
- 29faea2da97274e1eba16bd87d026eb50f942880: fix(appset): verify terminating Applications against the API server (#29042) (#29043) (@himeshp)
- 81cd93e553ce915075599a32335032322c44bc23: fix(chore): bump argo-ui for React 19 toast compatibility (#28874) (@choejwoo)
- 73661b801935213221948c167acd943e1eb20f6e: fix(ci): exclude generated workflow from dependabot (#28774) (@crenshaw-dev)
- 760229084538b77a5b269bf2449a7d2f19087dea: fix(ci): expand image tag in staging deploy commit message (#28773) (@crenshaw-dev)
- 955378d6e015d48ee58357532b86545c50bd716a: fix(ci): explicitly check out base repo and default branch for cherry-pick job (#28413) (@blakepettersson)
- 82682852c7f0684b57052e8d9447fd0c733983e9: fix(ci): fix CI breakage: remove dependabot's changes to an agentic workflow compiled file (#28772) (@dudinea)
- 1af3199ee504a86ddf1a6ed30ad11c392b310b75: fix(ci): fix readthedocs build by removing an invalid link (#28449) (#28450) (@dudinea)
- 541db75ef88063896ee5ea5d3628549319a25af1: fix(ci): gitkeep so go builds work (#28461) (@crenshaw-dev)
- bef2051b11a07e26981ea13dc1d48ba749610b76: fix(ci): regenerate manifests in Renovate helm post-upgrade tasks (#29297) (@crenshaw-dev)
- 2df94aebe8710797e14ceee0e8141d98efcc40c0: fix(ci): remove unneeded and misnamed ui/dist/app/gitkeep (#28447) (@dudinea)
- ebcbc95aaabc0b884fee860fef5082d761274db7: fix(ci): strip v prefix for helm and git-lfs renovate checksum tasks (#29287) (@crenshaw-dev)
- bb33bb0d1e724bac9e6964af98c76cebe5ab6be9: fix(cli): skip stale destinations in cluster stats (#21808) (#28786) (@AkashKumar7902)
- 5f4e24ec353399da81664ea1e04e9c758de21579: fix(controller): correct metrics flag help names. (#28358) (@siddiksawani)
- 28334d185e594be8b4b6bae8bbe428316aeb078c: fix(controller): dropping refresh requests during reconcile (#28603) (#28414) (@dudinea)
- cb99c80a553aa3eb25b38a8216ddac0b16aa3013: fix(controller): reuse server-side diff result when masking Secret data (#27858) (@1ovsss)
- f8c252b09b2c0213d1635d4f8417dd2d37f66768: fix(controller): show retry wait time in unambiguous format (#29534) (@nitishfy)
- b9e9d4117c89a97c84afc98022d1ccef867637c5: fix(controller): treat
timeout.reconciliation=0as disabled soft expiry (#27683) (@aali309) - f4adccd118f0ee0aa8a0149f94db56cc14f9cacd: fix(controller): use diff cache when timeout.reconciliation is disabled (#29073) (@aali309)
- 360aa9ba318d11a3c8805561d5fe7b7b771871a8: fix(diff): don't drop manager-owned descendant fields when filtering webhook mutations (#28819) (@pujitha24)
- 3fbe407789117445d088c41f867337591db33173: fix(doc): correct cluster generator example comments (#29196) (@aminerachyd)
- e2d36692fb8106cdf496d4756f476fa72da5ac0e: fix(docs): correct broken documentation links (#29572) (@yashrajshuklaaa)
- 7cec612777e9d5fb5c1b7966faf1bf0fc71df321: fix(docs): link version banner to stable equivalent page (#27054) (@SkyShineTH)
- 3c5af0d9dc49a1c8f55fa2a32cc75eeacbea7d8b: fix(headless): enable SyncWithReplaceAllowed by default for in-process server (#27643) (@SAY-5)
- fd04feb4b2b795fcabc67ceb41bffd121c37ad0a: fix(health): AWSManagedControlPlane reports Healthy while EKS control plane is updating (#28936) (#28937) (@moko-poi)
- e238e1a4e6aec5285cdfd1b81c6f61dc2c5dd87d: fix(health): Crossplane MRs should report Progressing (not Healthy) whilst provisioning (#29381) (#29382) (@kjothen)
- 381b41866746fe7c5161091ddfa40739dbe2142c: fix(health): PromotionStrategy and ChangeTransferPolicy Healthy, not Progressing (#28434) (@crenshaw-dev)
- ae1fc9969313e39242663ed6a1b0d6f408456dfc: fix(health): ResourceBinding health check for dependency-propagated bindings (#28299) (@pncloud)
- 785005d9096eecd0ce2e2f1af192cb5bf2600324: fix(health): a KubeVirt VirtualMachine declared stopped is Healthy (#29664) (@daixtrose)
- a1e358a57f52d14696d77cdc10eaee61a48c9024: fix(health): report suspended FlinkDeployment as healthy (#26818) (#28995) (@SaiPisey2)
- 7cf440730872497c3b32c1c802690a1784e58979: fix(health): surface the Suspended condition message for suspended Jobs (#28738) (@semx)
- fd09092b7d46ec7bb36b663a32c9d888cfb5e5d6: fix(health): treat nil return from Lua health status script as n/a instead of unknown (#28269) (@snorwin)
- b48e31cfbbbbd1c8233b58620873770757aed3ff: fix(helm): pass registry passwords through stdin (#17821) (#28795) (@AkashKumar7902)
- 65feaf50238bf8220fbacfc3576ecf12f0a67712: fix(hydrator): retry notes push on cannot lock ref errors (#28469) (@Churi12)
- 906ca1166d68e024391012c8605bbebe377c394a: fix(metrics): expose application operation phase in argocd_app_info (#28719) (@vishnu97770)
- aeda334c73e682fa2ea0ea0b0a93766e9ebf42a8: fix(progressivesync): check if error == notfound (#28663) (@blakepettersson)
- cd44f2784d2222cd0cfb0de1d54f005bcc1b6a53: fix(redis): incorrect fail metrics on RENAME cache miss (#29037) (@agaudreault)
- c7457d0668d321444560e1c0db56278c585c417c: fix(reposerver): honor depth of referenced source instead of primary source (#28339) (@alexandresavicki)
- c73a59ad73e4e4b15f28ec3bdeeec5516038daad: fix(repository): clean repository on revision change (#28771) (@emil-ep)
- 2f7eee24a6c5eb08b9c8f4bc62dbf1ea45ec6391: fix(repository): resolve untyped helm source type in UpdateRevisionForPaths (#28904) (@Churi12)
- b77bdaa2c76df9da83b26bf484c6deaf109263f5: fix(repository): restore Normalize in UpdateRevisionForPaths to unbreak master (#28979) (@Churi12)
- c71119fe756e12550670a78edf2eae08b935aef0: fix(revert): auto-sync skipped when newer commit arrives during sync (#28692) (@blakepettersson)
- a37f1f1ad303dae728381260dfe35edeb7d55ab3: fix(server): prevent SSD CLI secret mask spoofing (#29089) (@pjiang-dev)
- 994e271bcc3c591540bbe778bf09df303dcbf5f7: fix(ssd): hide secret in last-applied-configuration annotation (#28989) (@pjiang-dev)
- a683bdec6afe94c9ed88b6c7744d909407e12ec7: fix(sync): add state information for sync operation (#28758) (@agaudreault)
- 9b40474c009cc0a3596da7180501b7f259b90700: fix(sync): correctly set operationState values on retry (#26530) (#28778) (@agaudreault)
- ba8600cb76922a8b252052d9a127a3b184446f44: fix(sync): do not pass --force to server-side apply (#29624) (#29626) (@KR-Ravindra)
- 5ee2ae0cf42cc5501eb957e3648f66beb0e3008c: fix(sync): reduce unnecessary sync operation caused by refreshes (#28619) (@agaudreault)
- 5da9053d0ebcccf2a5858bd6578b9a5a8ec52255: fix(ui): Fix Hydrate-To revision name in App details (#27134) (@olivergondza)
- a1c22f1086166c9023e15bc0929b2a4983ee91be: fix(ui): add ResizeObserver to Monaco editor to fix collapsed rendering (#28810) (@choejwoo)
- 2fadff2054bbecf1f6283ecbeefdcf2fc3d1ef44: fix(ui): clarify scoped repository copy (#22793) (#29177) (@SHINMH)
- 1214aeda6bb23a02bf91427c587112899f3a73ea: fix(ui): enhance Bitbucket Server URL handling in ui for repo and revision links (#2