What rook/rook shipped
Written by FoxPlug from public releases; not affiliated with Rook. An automatic summary of the public release, pull request and commit data of github.com/rook/rook. Rook did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- Rook now defaults to msgr2 protocol for cluster communication, requiring the msgrv2 protocol that has been available since the 5.11 kernel. Pull request #18090
- Security fix removes command output from unmarshal errors to prevent S3 keys and cephx secrets from reaching logs and Kubernetes events. Pull request #18335
- Helm charts now include default HTTPRoute backend parameters to prevent OutOfSync diffs when deploying with ArgoCD. Pull request #18455
- CSI-Addons sidecar updated to v0.15.1 with latest versions of csi-provisioner, csi-attacher, and related sidecars. Pull request #18366
- The util.retry function now respects context cancellation to prevent retries when cluster specs are updated during retry loops. Pull request #18428
- Object bucket claims can now be created with empty specs, allowing fields like bucket name to be updated separately. Pull request #18416
- Upgrade guide documentation updated for v1.21 release changes. Pull request #18443
- Build system now respects TMPDIR environment variable for temporary files instead of hardcoding /tmp. Pull request #18208
- Mergify automerge rules for release-1.21 backports fixed to use correct Ceph v19 pin for canary tests. Pull request #18440
- CI scorecards job now skips on forks to prevent unwanted nightly runs and stale sweeps outside the main repository. Pull request #18442
Why it matters
This week includes important protocol changes for cluster communication with msgr2 becoming the default, security fixes preventing credential leakage in logs, and infrastructure improvements for better build reliability and CI behavior. These changes improve both security and operational stability for Rook deployments.
Changelog entry
- Default cluster communication protocol changed to msgr2 (requires kernel 5.11+) Pull request #18090
- Security: Remove sensitive data from unmarshal error messages Pull request #18335
- Add default HTTPRoute backend parameters to prevent ArgoCD OutOfSync diffs Pull request #18455
- Update CSI-Addons to v0.15.1 and related sidecars to latest versions Pull request #18366
- Make util.retry context-aware to handle cluster spec updates during retries Pull request #18428
- Allow creating object bucket claims with empty specs Pull request #18416
- Fix TMPDIR handling in build system for sandboxed environments Pull request #18208
- Fix mergify automerge rules for release-1.21 backports Pull request #18440
- Skip CI scorecards job on forks to prevent unwanted automation Pull request #18442
- Update upgrade documentation for v1.21 Pull request #18443
Rook ships msgr2 as the default cluster protocol, security fixes for credential handling, improved CSI sidecars, and better build system support for sandboxed environments.
This week's Rook updates include significant security improvements that prevent S3 keys and Ceph secrets from leaking into logs and Kubernetes events, plus important protocol changes defaulting to msgr2 for cluster communication. We've also shipped CSI-Addons v0.15.1, fixed build system issues in sandboxed environments, and improved the retry logic to respect context cancellation.
Week of September 14, 2026
What shipped
- v1.21.0-beta.0 released [5]. Release
- CephObjectStoreUser now supports optional defaultPlacement and defaultStorageClass fields [0]. Pull request #17260
- RGW zone pool references are now immutable to prevent incorrect updates when users change default placement [3]. Pull request #18399
- Manager Prometheus metrics now support TLS for HTTPS connections [2]. Pull request #18058
- CephBucketNotification accepts five additional lifecycle event values from Ceph Squid and Tentacle [9]. Pull request #18378
- Object Bucket and ObjectBucketClaim CRDs now include printer columns for improved kubectl output [13]. Pull request #18393
- CephNVMeOFGateway fixes hostNetwork toggle recreation and hostname mismatch issues [15]. Pull request #18374
- Ceph-volume logs now redact sensitive lockbox secrets [14]. Pull request #18389
- Build process fixed for cross-compiling gen-toolbox artifact [12]. Pull request #18364
- CI debugging switched from tmate to upterm for pre-job sessions [1]. Pull request #18372
Why it matters
v1.21.0-beta.0 arrives with improvements to object storage configuration immutability, better visibility into buckets via kubectl output, and TLS support for metrics collection. These changes address usability and security concerns for operators managing Rook clusters.
Changelog entry
- CephObjectStoreUser: add optional defaultPlacement and defaultStorageClass fields Pull request #17260
- Manager: add TLS support for Prometheus metrics Pull request #18058
- RGW: make pool references in zones immutable Pull request #18399
- CephBucketNotification: allow five additional lifecycle event values Pull request #18378
- Object Bucket CRDs: add printer columns for kubectl output Pull request #18393
- OSD: redact lockbox secrets from ceph-volume logs Pull request #18389
- NVMeOF: fix hostNetwork toggle and hostname mismatch Pull request #18374
- Library bucket provisioner CRDs: update to v1 with new validation rules Pull request #18363
Rook v1.21.0-beta.0 is out. New features include immutable RGW pool references, object bucket printer columns, and TLS support for Prometheus metrics.
Rook v1.21.0-beta.0 is now available. This release brings several improvements: CephObjectStoreUser gains placement and storage class configuration, RGW zone pools are now immutable to prevent accidental changes, Prometheus metrics support TLS, and object bucket CRDs display better information with kubectl. Additional lifecycle event support and security improvements included.