posit-dev / posit-dev/ptd

Upgrade Secrets Store CSI Driver from 1.3.4 to v1.6.0

Open
#283 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Go
Stars
7
Forks
2
Avg merge
1d 15h
Merged PRs (30d)
3

Description

Summary

Upgrade the default Secrets Store CSI Driver Helm chart from 1.3.4 to v1.6.0 (current latest as of April 2026).

Why this is needed

Chart 1.3.4 was released in June 2023. Running a ~3-year-old CSI driver version on Kubernetes 1.36 clusters (released April 2026) is untested and outside any supported version window. The Secrets Store CSI Driver project follows the Kubernetes supported versions policy, providing compatibility patches only for actively supported Kubernetes minor releases.

This upgrade is a prerequisite for the planned Kubernetes 1.36 upgrade.

Relevant links:

Backward compatibility

Secrets Store CSI Driver v1.6.0 specifies a minimum Kubernetes version of 1.30.0 in its Helm chart kubeVersion field. It can be deployed in place on clusters currently running K8s 1.31 through 1.35 — this upgrade can be performed independently of and prior to the Kubernetes 1.36 upgrade.

Note: This only covers the driver itself. The cloud-provider-specific CSI provider (e.g., AWS Secrets Manager provider) should also be reviewed for version compatibility.

Breaking changes in the upgrade

Review the release notes for any changes between 1.3.4 and 1.6.0, particularly around SecretProviderClass API or sync secret behaviour.

Acceptance criteria

  • Default Secrets Store CSI Driver version updated to v1.6.0 in workload.go
  • AWS Secrets Store CSI provider version reviewed for compatibility with v1.6.0 driver
  • Verified secret mounting works correctly on a staging cluster after upgrade

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start in workload.go and inspect how the default Secrets Store CSI Driver Helm chart version is defined. Read the Secrets Store CSI Driver v1.3.4–v1.6.0 release notes and review the AWS Secrets Store CSI provider compatibility. Done means the default is v1.6.0 and secret mounting is verified on a staging cluster.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, go, helm, kubernetes
Domain
cloud, infrastructure
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
52/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.