What prometheus-operator/prometheus-operator shipped
Written by FoxPlug from public releases; not affiliated with Prometheus-operator. An automatic summary of the public release, pull request and commit data of github.com/prometheus-operator/prometheus-operator. Prometheus-operator did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- Version 0.94.1 released with a bugfix restoring update permission on finalizer subresources in the operator's ClusterRole, required by OwnerReferencesPermissionEnforcement when blockOwnerDeletion is set. Release
- RBAC permissions adjusted to scope down default permissions granted to the Prometheus operator service account, granting write permissions on Pods based on repair policy and read permissions on Nodes only when kubelet controller is enabled. Pull request #8828
- ThanosRuler remote-write version filtering fixed to correctly remove unsupported fields from generated configuration instead of just reporting them as ignored. Pull request #8813
- AlertmanagerConfig status subresource now updated during Alertmanager reconciliations. Pull request #8261
- URL validation added for RocketChat receiver configuration fields loaded from secrets, validating
api_url,title_link, andicon_url. Pull request #8224 - URL validation added for PagerDuty receiver configurations loaded from Alertmanager secrets. Pull request #8221
- Validation added for clientAuthType. Pull request #8823
- MS Teams V2 custom resource test cases for Alertmanager Config split into separate test cases. Pull request #8715
- Prometheus LTS latest version updated to v3.13.3. Pull request #8836
Why it matters
Version 0.94.1 fixes critical RBAC issues that affected finalizer operations and makes permissions more restrictive. Several validation improvements for remote write and receiver configurations enhance reliability and security of alerting configurations.
Changelog entry
- [BUGFIX] Restore update permission on finalizer subresources in the operator's ClusterRole, required by OwnerReferencesPermissionEnforcement when blockOwnerDeletion is set. Release
- [CHANGE] Adjust RBAC permissions to scope down default permissions, grant write on Pods based on repair policy, grant read on Nodes only when kubelet controller is enabled. Pull request #8828
- [BUGFIX] Fix ThanosRuler remote-write version filtering to correctly remove unsupported fields from generated configuration. Pull request #8813
- [FEATURE] Update AlertmanagerConfig status subresource during Alertmanager reconciliations. Pull request #8261
- [FEATURE] Add URL validation for RocketChat receiver configuration fields in secrets. Pull request #8224
- [FEATURE] Add URL validation for PagerDuty receiver configurations in secrets. Pull request #8221
- [FEATURE] Add validation for clientAuthType. Pull request #8823
- [CHANGE] Update Prometheus LTS latest version to v3.13.3. Pull request #8836
Prometheus-operator 0.94.1 is out. This release fixes RBAC permissions for finalizers and continues improving validation for alerting receivers and remote write configurations.
Prometheus-operator 0.94.1 is now available. This release addresses RBAC permission scoping for the operator service account, fixes ThanosRuler remote-write field filtering, and adds URL validation for alerting receivers. Updates include improved status handling for AlertmanagerConfigs and enhanced permission controls based on repair policies.
Week of September 14, 2026
What shipped
- Event 3: Topology sharding now reports unbalanced configurations in the Reconciled condition when the number of shards is not a multiple of the number of zones. Pull request #8670
- Event 0: Added govulncheck workflow to detect vulnerabilities in dependencies. Pull request #8824
- Event 1: Enabled unused and whitespace linters in the golangci-lint configuration. Pull request #8827
- Event 2: Added test verification for TLS connections to Alertmanager. Pull request #8821
- Event 4: Fixed grammar in PrometheusRule developer documentation. Pull request #8817
Why it matters
The week focused on improving code quality and testing coverage. Topology sharding now provides better visibility into configuration issues, while new linting checks and vulnerability scanning help catch problems earlier in development.
Changelog entry
- Topology sharding now reports unbalanced configurations in Reconciled condition when shards is not a multiple of zone count Pull request #8670
- Added govulncheck workflow for vulnerability detection Pull request #8824
- Enabled unused and whitespace linters in golangci-lint Pull request #8827
- Added TLS connection verification tests for Alertmanager Pull request #8821
This week: topology sharding reports unbalanced configurations, govulncheck workflow added for vulnerability detection, unused and whitespace linters enabled, TLS connection tests for Alertmanager, and documentation grammar fixes.
This week in prometheus-operator: Topology sharding now reports unbalanced configurations in the Reconciled condition when shard counts don't align with zone counts. We added govulncheck workflow for vulnerability detection and enabled additional linters for code quality. TLS connection verification tests for Alertmanager were introduced, and documentation improvements continue.