Skip to content

lakeFS Mount CSI Driver v1.3.0

Changelog

  • Bumped the bundled everest mount binary from 0.11.0 to 0.12.0.

Fixes

  • Restored the linux/arm64 image variant. Every arm64 image from 1.0.0 through 1.2.1 shipped an x86_64 ELF, which runs under emulation but crashloops on arm64 nodes; the Dockerfile now downloads the everest tarball matching BuildKit's $TARGETARCH while it builds each platform.
  • Restored the node DaemonSet's EKS_POD_IDENTITY_AGENT_CONTAINER_CREDENTIALS_FULL_URI environment variable and the eksPodIdentityAgent.containerCredentialsFullURI value behind it. The code read both while the chart defined neither, so authenticationSource: pod on EKS Pod Identity failed with InvalidArgument: Failed to detect EKS_POD_IDENTITY_AGENT_CONTAINER_CREDENTIALS_FULL_URI; IRSA, driver, and secret were unaffected. Set the value to "" to opt out.
  • Upgrade with helm upgrade --reset-then-reuse-values. Earlier releases define no eksPodIdentityAgent map, and --reuse-values discards new chart defaults, leaving the template without a value to render.
  • Pod-level EKS Pod Identity now sets AWS_REGION and AWS_DEFAULT_REGION, as IRSA already did. everest mount-server signs an STS GetCallerIdentity to authenticate to lakeFS, so without a region the Mount Pod exited with Invalid Configuration: Missing Region and the stsRegion volume attribute was silently ignored.
  • Helm chart bumped to 1.3.0 with matching appVersion and image.tag.

Docker

docker pull treeverse/everest-lakefs-csi-driver:1.3.0

Verify the signature (optional)

Requires Cosign:

cosign verify treeverse/everest-lakefs-csi-driver:1.3.0 \
    --certificate-identity-regexp='^https://github\.com/treeverse/everest\-lakefs\-csi\-driver/\.github/workflows/' \
    --certificate-oidc-issuer='https://token.actions.githubusercontent.com'
Expected output
Verification for index.docker.io/treeverse/everest-lakefs-csi-driver:1.3.0 --
The following checks were performed on each of these signatures:
  - The cosign claims were validated
  - Existence of the claims in the transparency log was verified offline
  - The code-signing certificate was verified using trusted certificate authority certificates