Contains description of Nebari releases.
This is a hot-fix release that resolves an issue whereby users in the analyst
group are unable to launch their JupyterLab server because the name of the viewer-specific ARGO_TOKEN
was mislabeled; see PR 1881 for more details.
- Fix argo-viewer service account reference by @iameskild in #1881
- Add release notes for 2023.7.2, update release notes for 2023.7.1 by @iameskild in #1886
WARNING: CDS Dashboards will be deprecated soon. Nebari
2023.7.1
will be the last release with support for CDS Dashboards integration. A new dashboard sharing mechanism added in the near future, but some releases in the interim will not have dashboard sharing capabilities..
WARNING: For those running on AWS, upgrading from previous versions to
2023.7.1
requires a backup. Due to changes made to the VPC (See issue 1884 for details), Terraform thinks it needs to destroy and reprovision a new VPC which causes the entire cluster to be destroyed and rebuilt.
- Addition of Nebari-Workflow-Controller in PR 1741
- Addition of Argo-Jupyter-Scheduler in PR 1832
- Make most of the API private
- As mentioned in the above WARNING, clusters running on AWS should perform a manual backup before running the upgrade to the latest version as changes to the AWS VPC will cause the cluster to be destroyed and redeployed.
- use conda forge explicitly in conda build test by @pmeier in #1771
- document that the upgrade command is for all nebari upgrades by @Adam-D-Lewis in #1794
- don't fail CI matrices fast by @pmeier in #1804
- unvendor keycloak_metrics_spi by @Adam-D-Lewis in #1810
- Dedent fail-fast by @iameskild in #1815
- support deploying on existing vpc on aws by @Adam-D-Lewis in #1807
- purge most danlging qhub references by @pmeier in #1802
- Add Argo Workflow Admission controller by @Adam-D-Lewis in #1741
- purge infracost CLI command / CI jobs by @pmeier in #1820
- remove unused function parameters and CLI flags by @pmeier in #1725
- purge docs and nox by @pmeier in #1801
- Add Helm chart lint tool by @viniciusdc in #1679
- don't set /etc/hosts in CI by @pmeier in #1729
- remove execute permissions on templates by @pmeier in #1798
- fix deprecated file deletion by @pmeier in #1799
- make nebari API private by @pmeier in #1778
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #1831
- Simplify CI by @iameskild in #1819
- Fix edge-case where k8s_version is equal to HIGHEST_SUPPORTED_K8S_VER… by @iameskild in #1842
- add more configuration to enable private clusters on AWS by @Adam-D-Lewis in #1841
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #1851
- AWS gov cloud support by @sblair-metrostar in #1857
- Pathlib everywhere by @pmeier in #1773
- Initial playwright setup by @kcpevey in #1665
- Changes required for Jupyter-Scheduler integration by @iameskild in #1832
- Update upgrade command in preparation for release by @iameskild in #1868
- Add release notes by @iameskild in #1869
- @sblair-metrostar made their first contribution in #1857
Full Changelog: https://github.com/nebari-dev/nebari/compare/2023.5.1...2023.7.1
- Upgrade Argo-Workflows to version 3.4.4
- The Argo-Workflows version upgrade will result in a breaking change if the existing Kubernetes CRDs are not deleted (see the NOTE below for more details).
- There is a minor breaking change for the Nebari CLI version shorthand, previously it
nebari -v
and now to align with Python convention, it will benebari -V
.
NOTE: After installing the Nebari version
2023.5.1
, please runnebari upgrade -c nebari-config.yaml
to upgrade thenebari-config.yaml
. This command will also prompt you to delete a few Kubernetes resources (specifically the Argo-Workflows CRDS and service accounts) before you can upgrade.
- Use --quiet flag for conda install in CI by @pmeier in #1699
- improve CLI tests by @pmeier in #1710
- Fix Existing dashboards by @Adam-D-Lewis in #1723
- Fix dashboards by @Adam-D-Lewis in #1727
- Typo in the conda-store <-> conda_store key by @costrouc in #1740
- use -V (upper case) for --version short form by @pmeier in #1720
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #1692
- improve pytest configuration by @pmeier in #1700
- fix upgrade command to look for nebari_version instead of qhub_version by @Adam-D-Lewis in #1693
- remove lazy import by @pmeier in #1721
- fix nebari invocation through python by @pmeier in #1711
- Update Argo Workflows to latest version by @Adam-D-Lewis in #1639
- Update secret token in release-notes-sync action by @pavithraes in #1753
- Typo fix in release-notes-sync action by @pavithraes in #1756
- 🔄 Synced file(s) with nebari-dev/.github by @nebari-sensei in #1758
- Update path in release-notes-sync action by @pavithraes in #1757
- Updating heading format in release notes by @pavithraes in #1761
- Update vault url by @costrouc in #1752
- Fix? contributor test trigger by @pmeier in #1734
- Consistent user Experience with y/N. by @AM-O7 in #1747
- Fix contributor trigger by @pmeier in #1765
- add more debug output to contributor test trigger by @pmeier in #1766
- fix copy-paste error by @pmeier in #1767
- add instructions insufficient permissions of contributor trigger by @pmeier in #1772
- fix invalid escape sequence by @pmeier in #1770
- Update AMI in
.cirun.yml
for nebari-dev-ci AWS account by @aktech in #1776 - [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #1768
- turn warnings into errors with pytest by @pmeier in #1774
- purge setup.cfg by @pmeier in #1781
- improve pre-commit run on GHA by @pmeier in #1782
- Upgrade to k8s 1.24 by @iameskild in #1760
- Overloaded dask gateway fix by @Adam-D-Lewis in #1777
- Add option to specify GKE release channel by @iameskild in #1648
- Update upgrade command, add RELEASE notes by @iameskild in #1789
Full Changelog: https://github.com/nebari-dev/nebari/compare/2023.4.1...2023.5.1
NOTE: Nebari requires Kubernetes version 1.23 and Digital Ocean now requires new clusters to run Kubernetes version 1.24. This means that if you are currently running on Digital Ocean, you should be fine but deploying on a new cluster on Digital Ocean is not possible until we upgrade Kubernetes version (see issue 1622 for more details).
- Upgrades and improvements to conda-store including a new user-interface and greater administrator capabilities.
- Idle-culler settings can now be configured directly from the
nebari-config.yaml
.
- PR: Raise timeout for jupyter session by @ppwadhwa in #1646
- PR lower dashboard launch timeout by @ppwadhwa in #1647
- PR: Update dashboard environment by @ppwadhwa in #1655
- Fix doc link in README.md by @tkoyama010 in #1660
- PR: Update dask environment by @ppwadhwa in #1654
- Feature remove jupyterlab news by @costrouc in #1641
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #1644
- Feat GitHub actions before_script and after_script steps by @costrouc in #1672
- Remove examples folder by @ppwadhwa in #1664
- Fix GH action typos by @kcpevey in #1677
- Github Actions CI needs id-token write permissions by @costrouc in #1682
- Update AWS force destroy script, include lingering volumes by @iameskild in #1681
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #1673
- Make idle culler settings configurable from the
nebari-config.yaml
by @iameskild in #1689 - Update pyproject dependencies and add test to ensure it builds on conda-forge by @iameskild in #1662
- Retrieve secrets from Vault, fix test-provider CI by @iameskild in #1676
- Pull PyPI secrets from Vault by @iameskild in #1696
- Adding newest conda-store 0.4.14 along with superadmin credentials by @costrouc in #1701
- Update release notes for 2023.4.1 by @iameskild in #1722
Full Changelog: https://github.com/nebari-dev/nebari/compare/2023.1.1...2023.4.1
- 🔄 Synced file(s) with nebari-dev/.github by @nebari-sensei in #1588
- Make conda-store file system read-only by default by @alimanfoo in #1595
- ENH - Switch to ruff and pre-commit.ci by @trallard in #1602
- Migrate to hatch by @iameskild in #1545
- Add check_repository_cred function to CLI by @iameskild in #1605
- Adding jupyterlab-conda-store extension support to Nebari by @costrouc in #1564
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #1613
- Ensure Argo-Workflow controller containerRuntimeExecutor is set to emissary by @iameskild in #1614
- Pass
secret_name
to TF scripts when certificate type = existing by @iameskild in #1621 - Pin Nebari dependencies, set k8s version for GKE by @iameskild in #1624
- Create aws-force-destroy bash script by @iameskild in #1611
- Add option for AWS node-groups to run in a single subnet/AZ by @iameskild in #1428
- Add export-users to keycloak CLI command, add dev CLI command by @iameskild in #1610
- Unpin packages in default dashboard env by @iameskild in https://github.com/nebari-dev/pull/1628
- Add release notes for 2023.1.1 by @iameskild in #1629
- Set GKE release_channel to unspecified to prevent auto k8s updates by @iameskild in #1630
- Update default nebari-dask, nebari image tags by @iameskild in #1636
- @pre-commit-ci made their first contribution in #1613
- cherry-pick Update README logo (#1514) by @aktech in #1517
- Release/2022.10.1 by @iameskild in #1527
- Add Note about QHub->Nebari rename in old docs by @pavithraes in #1543
- 🔄 Synced file(s) with nebari-dev/.github by @nebari-sensei in #1550
- 🔄 Synced file(s) with nebari-dev/.github by @nebari-sensei in #1551
- 🔄 Synced file(s) with nebari-dev/.github by @nebari-sensei in #1555
- 🔄 Synced file(s) with nebari-dev/.github by @nebari-sensei in #1560
- Small CLI fixes by @iameskild in #1529
- 🔄 Synced file(s) with nebari-dev/.github by @nebari-sensei in #1561
- Render github actions configurations as yaml by @aktech in #1528
- Update "QHub" to "Nebari" in example notebooks by @pavithraes in #1556
- Update links to Nebari docs in guided init by @pavithraes in #1557
- CI: Spinup unique cirun runners for each job by @aktech in #1563
- Issue-1417: Improve Dask workers placement on AWS | fixing a minor typo by @limacarvalho in #1487
- Update
setup-node
version by @iameskild in #1570 - Facilitate CI run for contributor PR by @aktech in #1568
- Action to sync release notes with nebari-docs by @pavithraes in #1554
- Restore how the dask worker node group is selected by default by @iameskild in #1577
- Fix skip check for workflows by @aktech in #1578
- 📝 Update readme by @trallard in #1579
- MAINT - Miscellaneous maintenance tasks by @trallard in #1580
- Wait for Test PyPI to upload test release by @iameskild in #1583
- Add release notes for 2022.11.1 by @iameskild in #1584
- @nebari-sensei made their first contribution in #1550
- @limacarvalho made their first contribution in #1487
The project has recently been renamed from QHub to Nebari. If your deployment is is still managed by
qhub
, performing an inplace upgrade will IRREVOCABLY BREAK your deployment. This will cause you to lose any data stored on the platform, including but not limited to, NFS (filesystem) data, conda-store environments, Keycloak users and groups, etc. Please backup your data before attempting an upgrade.
We are happy to announce the first official release of Nebari (formly QHub)! This release lays the groundwork for many exciting new features and improvements to come.
This release introduces several important changes which include:
- a major project name change from QHub to Nebari - PR 1508
- a switch from the SemVer to CalVer versioning format - PR 1501
- a new, Typer-based CLI for improved user experience - PR 1443 + PR 1519
Although breaking changes are never fun, the Nebari development team believes these changes are important for the immediate and future success of the project. If you experience any issues or have any questions about these changes, feel free to open an issue on our Github repo.
- Switch to CalVer by @iameskild in #1501
- Update theme welcome messages to use Nebari by @pavithraes in #1503
- Name change QHub --> Nebari by @iameskild in #1508
- qhub/initialize: lazy load attributes that require remote information by @FFY00 in #1509
- Update README logo reference by @viniciusdc in #1514
- Add fix, enhancements and pytests for CLI by @iameskild in #1498
- Remove old CLI + cleanup by @iameskild in #1519
- Update
skip_remote_state_provision
default value by @viniciusdc in #1521 - Add release notes for 2022.10.1 in #1523
Note: The following releases (v0.4.5 and lower) were made under the name Quansight/qhub
.
Enhancements for this release include:
- Fix reported bug with Azure deployments due to outdated azurerm provider
- All dashboards related conda-store environments are now visible as options for spawning dashboards
- New Nebari entrypoint
- New Typer-based CLI for Qhub (available using new entrypoint)
- Renamed built-in conda-store namespaces and added customization support
- Updated Traefik version to support the latest Kubernetes API
- Update azurerm version by @tjcrone in #1471
- Make CDSDashboards.conda_envs dynamically update from function by @costrouc in #1358
- Fix get_latest_repo_tag fn by @iameskild in #1485
- Nebari Typer CLI by @asmijafar20 in #1443
- Pass AWS
region
,kubernetes_version
to terraform scripts by @iameskild in #1493 - Enable ebs-csi driver on AWS, add region + kubernetes_version vars by @iameskild in #1494
- Update traefik version + CRD by @iameskild in #1489
- [ENH] Switch default and filesystem name envs by @viniciusdc in #1357
- @tjcrone made their first contribution in #1471
If you are upgrading from a version of Nebari prior to 0.4.5
, you will need to manually update your conda-store namespaces
to be compatible with the new Nebari version. This is a one-time migration step that will need to be performed after upgrading to continue using the service. Refer to How to migrate base conda-store namespaces for further instructions.
Enhancements for this release include:
- Bump
conda-store
version tov0.4.11
and enable overrides - Fully decouple the JupyterLab, JupyterHub and Dask-Worker images from the main codebase
- See https://github.com/nebari-dev/nebari-docker-images for images
- Add support for Python 3.10
- Add support for Terraform binary download for M1 Mac
- Add option to supply additional arguments to ingress from qhub-config.yaml
- Add support for Kubernetes Kind (local)
- Add support for terraform binary download for M1 by @aktech in #1370
- Improvements in the QHub Cost estimate tool by @HarshCasper in #1365
- Add Python-3.10 by @HarshCasper in #1352
- Add backwards compatibility item to test checklist by @viniciusdc in #1381
- add code server version to fix build by @HarshCasper in #1383
- Update Cirun.io config to use labels by @aktech in #1379
- Decouple docker images by @iameskild in #1371
- Set LATEST_SUPPORTED_PYTHON_VERSION as str by @iameskild in #1387
- Integrate kind into local deployment to no longer require minikube for development by @costrouc in #1171
- Upgrade conda-store to 0.4.7 allow for customization by @costrouc in #1385
- [ENH] Bump conda-store to v0.4.9 by @viniciusdc in #1392
- [ENH] Add
pyarrow
ands3fs
by @viniciusdc in #1393 - Fixing bug in authentication method in Conda-Store authentication by @costrouc in #1396
- CI: Merge test and release to PyPi workflows into one by @HarshCasper in #1386
- Update packages in the dashboard env by @iameskild in #1402
- BUG: Setting behind proxy setting in conda-store to be aware of http vs. https by @costrouc in #1404
- Minor update to release workflow by @iameskild in #1406
- Clean up release workflow by @iameskild in #1407
- Add release notes for v0.4.4 by @iameskild in #1408
- Update Ingress overrides behaviour by @viniciusdc in #1420
- Preserve conda-store image permissions by @iameskild in #1419
- Add project name to jhub helm chart release name by @iameskild in #1422
- Fix for helm extension overrides data type issue by @konkapv in #1424
- Add option to disable tls certificate by @iameskild in #1421
- Fixing provider=existing for local/existing by @costrouc in #1425
- Update release, testing checklist by @iameskild in #1397
- Add
--disable-checks
flag to deploy by @iameskild in #1429 - Adding option to supply additional arguments to ingress via
ingress.terraform_overrides.additional-arguments
by @costrouc in #1431 - Add properties to middleware crd headers by @iameskild in #1434
- Restart conda-store worker when new conda env is added to config.yaml by @iameskild in #1437
- Pin dask ipywidgets version to
7.7.1
by @viniciusdc in #1442 - Set qhub-dask version to 0.4.4 by @iameskild in #1470
- @konkapv made their first contribution in #1424
Enhancements for this release include:
- Integrating Argo Workflow
- Integrating kbatch
- Adding
cost-estimate
CLI subcommand (Infracost) - Add
panel-serve
as a CDS dashboard option - Add option to use RetroLab instead of default JupyterLab
- Update the login/Keycloak docs page by @gabalafou in #1289
- Add configuration option so myst parser generates anchors for heading… by @costrouc in #1299
- Image scanning by @HarshCasper in #1291
- Fix display version behavior by @viniciusdc in #1275
- [Docs] Add docs about custom Identity providers for Authentication by @viniciusdc in #1273
- Add prefect token var to CI when needed by @viniciusdc in #1279
- ci: prevent image scans on main image builds by @HarshCasper in #1300
- Integrate
kbatch
by @iameskild in #1258 - add
retrolab
to the base jupyter image by @tonyfast in #1222 - Update pre-commit, remove vale by @iameskild in #1282
- Argo Workflows by @Adam-D-Lewis in #1252
- Update minio, postgresql chart repo location by @iameskild in #1308
- Fix broken AWS, set minimum desired size to 1, enable 0 scaling by @tylerpotts in #1304
- v0.4.2 release notes by @iameskild in #1323
- install dask lab ext from main by @iameskild in #1321
- Overrides default value for dask-labextension by @viniciusdc in #1327
- CI: Add Infracost to GHA CI for infra cost tracking by @HarshCasper in #1316
- Add check for highest supported k8s version by @aktech in #1336
- Increase the default instance sizes by @peytondmurray in #1338
- Add panel-serve as a CDS dashboard option by @iameskild in #1070
- Generate QHub Costs via
infracost
by @HarshCasper in #1340 - Add release-checklist issue template by @iameskild in #1314
- Fix missing import:
rich
: broken qhub init with cloud by @aktech in #1353 - Bump qhub-dask version to 0.4.3 by @peytondmurray in #1341
- Remove the need for AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY to be set with Digital Ocean deployment by @costrouc in #1344
- Revert "Remove the need for AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY to be set with Digital Ocean deployment" by @viniciusdc in #1355
- Upgrade kbatch version by @iameskild in #1335
- Drop support for python 3.7 in dask environment by @peytondmurray in #1354
- Add useful terminal utils to jlab image by @dharhas in #1361
- Tweak bashrc by @dharhas in #1363
- Fix bug where vscode extensions are not installing by @viniciusdc in #1360
- @gabalafou made their first contribution in #1289
- @peytondmurray made their first contribution in #1338
- @dharhas made their first contribution in #1361
Full Changelog: https://github.com/Quansight/qhub/compare/v0.4.1...v0.4.3
On June 2, 2022, GitHub user @peytondmurray reported issue 1306, stating that he was unable to deploy QHub using either the latest release v0.4.1
or installing qhub
from main
. As verified by @peytondmurray and others, during your first qhub deploy
, the deployment halts and complains about two invalid Helm charts missing from the bitnami index.yaml
.
Bitnami's decision to update how long they keep old Helm charts in their index for has essentially broken all post v0.4.0
versions of QHub.
This is a severe bug that will affect any new user who tries to install and deploy QHub with any version less than v0.4.2
and greater than or equal to v0.4.0
.
Given the impact and severity of this bug, the team has decided to quickly cut a hotfix.
On May 27, 2022, GitHub user @tylerpotts reported issue 1302, stating that he was unable to deploy QHub using the latest release v0.4.1
(or installing qhub
from main
). As described in the original issue, the deployment failed complaining about the deprecated v1beta
Kubernetes API. This led to the discovery that we were using an outdated cluster_autoscaler
helm chart.
The solution is to update from v1beta
to v1
Kubernetes API for the appropriate resources and update the reference to the cluster_autoscaler
helm chart.
Given the impact and severity of this bug, the team has decided to quickly cut a hotfix.
This release is a hotfix for the issue summarized in the following:
- Update minio, postgresql chart repo location by @iameskild in PR 1308
- Fix broken AWS, set minimum desired size to 1, enable 0 scaling by @tylerpotts in PR 1304
Enhancements for this release include:
- Add support for pinning the IP address of the load balancer via terraform overrides
- Upgrade to Conda-Store to
v0.3.15
- Add ability to limit JupyterHub profiles based on users/groups
This release addresses several bugs with a slight emphasis on stabilizing the core services while also improving the end user experience.
- [BUG] Adding back feature of limiting profiles for users and groups by @costrouc in PR 1169
- DOCS: Add release notes for v0.4.0 release by @HarshCasper in PR 1170
- Move ipython config within jupyterlab to docker image with more robust jupyterlab ssh tests by @costrouc in PR 1143
- Removing custom dask_gateway from qhub and idle_timeout for dask clusters to 30 min by @costrouc in PR 1151
- Overrides.json now managed by qhub configmaps instead of inside docker image by @costrouc in PR 1173
- Adding examples to QHub jupyterlab by @costrouc in PR 1176
- Bump conda-store version to 0.3.12 by @costrouc in PR 1179
- Fixing concurrency not being specified in configuration by @costrouc in PR 1180
- Adding ipykernel as default to environment along with ensure conda-store restarted on config change by @costrouc in PR 1181
- keycloak dev docs by @danlester in PR 1184
- Keycloakdev2 by @danlester in PR 1185
- Setting minio storage to by default be same as filesystem size for Conda-Store environments by @costrouc in PR 1188
- Bump Conda-Store version in Qhub to 0.3.13 by @costrouc in PR 1189
- Upgrade mrparkers to 3.7.0 by @danlester in PR 1183
- Mdformat tables by @danlester in PR 1186
- [ImgBot] Optimize images by @imgbot in PR 1187
- Bump conda-store version to 0.3.14 by @costrouc in PR 1192
- Allow terraform init to upgrade providers within version specification by @costrouc in PR 1194
- Adding missing init files by @costrouc in PR 1196
- Release 0.3.15 for Conda-Store by @costrouc in PR 1205
- Profilegroups by @danlester in PR 1203
- Render
.gitignore
, black py files by @iameskild in PR 1206 - Update qhub-dask pinned version by @iameskild in PR 1224
- Fix env doc links and add corresponding tests by @aktech in PR 1216
- Update conda-store-environment variable
type
by @iameskild in PR 1213 - Update release notes - justification for changes in
v0.4.0
by @iameskild in PR 1178 - Support for pinning the IP address of the load balancer via terraform overrides by @aktech in PR 1235
- Bump moment from 2.29.1 to 2.29.2 in /tests_e2e by @dependabot in PR 1241
- Update cdsdashboards to 0.6.1, Voila to 0.3.5 by @danlester in PR 1240
- Bump minimist from 1.2.5 to 1.2.6 in /tests_e2e by @dependabot in PR 1208
- output check fix by @Adam-D-Lewis in PR 1244
- Update panel version to fix jinja2 recent issue by @viniciusdc in PR 1248
- Add support for terraform overrides in cloud and VPC deployment for Azure by @aktech in PR 1253
- Add test-release workflow by @iameskild in PR 1245
- Bump async from 3.2.0 to 3.2.3 in /tests_e2e by @dependabot in PR 1260
- [WIP] Add support for VPC deployment for GCP via terraform overrides by @aktech in PR 1259
- Update login instructions for training by @iameskild in PR 1261
- Add docs for general node upgrade by @iameskild in PR 1246
- [ImgBot] Optimize images by @imgbot in PR 1264
- Fix project name and domain at None by @pierrotsmnrd in PR 856
- Adding name convention validator for QHub project name by @viniciusdc in PR 761
- Minor doc updates by @iameskild in PR 1268
- Enable display of Qhub version by @viniciusdc in PR 1256
- Fix missing region from AWS provider by @viniciusdc in PR 1271
- Re-enable GPU profiles for GCP/AWS by @viniciusdc in PR 1219
- Release notes for
v0.4.1
by @iameskild in PR 1272
- @dependabot made their first contribution in PR 1241
This post-release addresses the a few minor bugs and updates the release notes. There are no breaking changes or API changes.
- Render
.gitignore
, black py files - PR 1206 - Update qhub-dask pinned version - PR 1224
- Update conda-store-environment variable
type
- PR 1213 - Update release notes - justification for changes in
v0.4.0
- PR 1178 - Merge spawner and profile env vars to ensure dashboard sharing vars are provided to dashboard servers - PR 1237
WARNING
If you're looking for a stable version of QHub, please consider
v0.3.14
. Thev0.4.0
has many breaking changes and has rough edges that will be resolved in upcoming point releases.
We are happy to announce the release of v0.4.0
! This release lays the groundwork for many exciting new features and improvements in the future, stay tuned.
Version v0.4.0
introduced many design changes along with a handful of user-facing changes that require some justification. Unfortunately as a result of these changes, QHub
instances that are upgraded from previous version to v0.4.0
will irrevocably break.
Until we have a fully functioning backup mechanism, anyone looking to upgrade is highly encouraged to backup their data, see the upgrade docs and more specifically, the backup docs.
These design changes were considered important enough that the development team felt they were warranted. Below we try to highlight a few of the largest changes and provide justification for them.
- Replace Terraforms resource targeting with staged Terraform deployments.
- Justification: using Terraform resource targeting was never an ideal way of handing off outputs from stage to the next and Terraform explicitly warns its users that it's only intended to be used "for exceptional situations such as recovering from errors or mistakes".
- Fully remove
cookiecutter
as a templating mechanism.- Justification: Although
cookiecutter
has its benefits, we were becoming overly reliant on it as a means of rendering various scripts needed for the deployment. Reading through Terraform scripts with scatteredcookiecutter
statements was increasing troublesome and a bit intimidating. Our IDEs are also much happier about this change.
- Justification: Although
- Removing users and groups from the
qhub-config.yaml
and replacing user management with Keycloak.- Justification: Up until now, any change to QHub deployment needed to be made in the
qhub-config.yaml
which had the benefit of centralizing any configuration. However it also potentially limited the kinds of user management tasks while also causing theqhub-config.yaml
to balloon in size. Another benefit of removing users and groups from theqhub-config.yaml
that deserves highlighting is that user management no longer requires a full redeployment.
- Justification: Up until now, any change to QHub deployment needed to be made in the
Although breaking changes are never fun, we hope the reasons outlined above are encouraging signs that we are working on building a better, more stable, more flexible product. If you experience any issues or have any questions about these changes, feel free to open an issue on our Github repo.
Explicit user facing changes:
- Upgrading to
v0.4.0
will require a filesystem backup given the scope and size of the current change set.- Running
qhub upgrade
will produce an updatedqhub-config.yaml
and a JSON file of users that can then be imported into Keycloak.
- Running
- With the addition of Keycloak, QHub will no longer support
security.authentication.type = custom
.- No more users and groups in the
qhub-config.yaml
.
- No more users and groups in the
- Authentication is now managed by Keycloak.
- QHub Helm extension mechanism added.
- Allow JupyterHub overrides in the
qhub-config.yaml
. qhub support
CLI option to save Kubernetes logs.- Updates
conda-store
UI.
- Enabling Vale CI with GitHub Actions by @HarshCasper in #871
- Qhub upgrade by @danlester in #870
- Documentation cleanup by @HarshCasper in #873
- [Docs] Add Traefik wildcard docs by @viniciusdc in #876
- replace deprecated "minikube cache add" with "minikube image load" by @Adam-D-Lewis in #880
- Azure Python needs different env var names to Terraform by @danlester in #882
- Add notes about broken upgrades by @tylerpotts in #877
- Keycloak integration first pass by @danlester in #848
- K8s tests - keycloak adduser by @danlester in #890
- Documentation cleanup by @HarshCasper in #889
- Improvements to templates and readme by @trallard in #893
- Keycloak docs by @danlester in #901
- DOCS: Add a PR Template by @HarshCasper in #900
- Delete existing
.gitlab-ci.yml
when rendering by @iameskild in #887 - Qhub Extension (Ready for Review) by @Adam-D-Lewis in #886
- Updates to Readme by @trallard in #897
- Mirror docker images to ghcr and quay container registry by @aktech in #912
- Fix CI: skip failure on cleanup by @aktech in #910
- Create and solve envs using mamba by @iameskild in #915
- Pin terraform providers by @Adam-D-Lewis in #914
- qhub-config.yaml as a secret by @danlester in #905
- Setup/Add integration/deployment tests via pytest by @aktech in #922
- Disable/Remove the stale bot by @viniciusdc in #923
- Integrates Hadolint for Dockerfile linting by @HarshCasper in #917
- Reduce minimum nodes in user and dask node pools to 0 for Azure / GCP by @tarundmsharma in #723
- Allow jupyterhub.overrides in qhub-config.yaml by @danlester in #930
- qhub destroy using targets by @danlester in #948
- Take AWS region from AWS_DEFAULT_REGION into qhub-config.yaml on init… by @danlester in #950
- cookicutter template out of raw by @danlester in #951
- kubernetes-initialization depends_on kubernetes by @danlester in #952
- Add timeout to terraform import command by @tylerpotts in #949
- Timeout in process (for import) by @danlester in #955
- Remove user/groups from YAML by @danlester in #956
- qhub upgrade custom auth plus tests by @danlester in #946
- Add minimal support
centos
images by @iameskild in #943 - Keycloak Export by @danlester in #947
- qhub cli tool to save kubernetes logs -
qhub support
by @tarundmsharma in #818 - Add docs for deploying QHub to existing EKS cluster by @iameskild in #944
- Add jupyterhub-idle-culler to jupyterhub image by @danlester in #959
- Robust external container registry by @danlester in #945
- use qhub-jupyterhub-theme 0.3.3 to simplify JupyterHub config by @danlester in #966
- Get kubernetes version for all cloud providers + pytest refactor by @iameskild in #927
- Merge hub.extraEnv env vars by @danlester in #968
- DOCS: Removing errors from documentation by @HarshCasper in #941
- keycloak.realm_display_name by @danlester in #973
- minor updates to keycloak docs by @tylerpotts in #977
- CI changes for QHub by @HarshCasper in #989
- Update
upgrade
docs and general doc improvements by @iameskild in #990 - Remove
scope
,oauth_callback_url
during upgrade step by @iameskild in #997 - Adding Conda-Store to QHub by @costrouc in #967
- Fix Jupyterlab docker build by @viniciusdc in #1001
- DOCS: Fix broken link in setup doc by @HarshCasper in #1006
- Fix Kubernetes local test deployment by @viniciusdc in #1002
- Initial commit for auth and stages workflow by @costrouc in #1003
- Fix formatting issues with black #1003 by @viniciusdc in #1020
- use pyproject.toml and setup.cfg for packaging by @tonyfast in #986
- Increase timeout/attempts for keycloak check by @viniciusdc in #1023
- Fix issue with traefik issuing certificates with let's encrypt acme by @costrouc in #1017
- Fixing cds dashboard conda environments being shown by @costrouc in #1025
- Fix input variable support for multiple types by @viniciusdc in #1029
- Fix Black/Flake8 problems by @danlester in #1039
- Add remote state condition for 01-terraform-state provisioning by @viniciusdc in #1042
- Round versions for upgrade and schema by @danlester in #1038
- Code Server is now installed via conda, and the Jupyterlab Extension is https://github.com/betatim/vscode-binder/ by @costrouc in #1044
- Removing cookiecutter from setup.cfg requirements by @costrouc in #1026
- Destroy terraform-state stage when condition match by @viniciusdc in #1051
- Fix up adding support for security.keycloak.realm_display_name key by @costrouc in #1054
- Move external_container_reg to earlier stage by @danlester in #1053
- Adding ability to specify overrides back into keycloak configuration by @costrouc in #1055
- Deprecating terraform_modules option since no longer used by @costrouc in #1057
- Adding security.shared_users_group option for default users group by @costrouc in #1056
- Fix up adding back jupyterhub overrides option by @costrouc in #1058
- prevent_deploy flag for safeguarding upgrades by @danlester in #1047
- CI: Add layer caching for Docker images by @HarshCasper in #1061
- Additions to TCP/DNS stage check, fix 1027 by @iameskild in #1063
- FIX: Remove concurrency groups by @HarshCasper in #1064
- Stage 08 extensions and realms/logout by @danlester in #1069
- Auto create/destroy azure resource group by @viniciusdc in #1071
- Add CICD schema and render workflows by @iameskild in #1068
- Ensure that the shared folder symlink only exists if user has shared folders by @costrouc in #1074
- Adds the ability on render to deleted targeted files or directories by @costrouc in #1073
- DOCS: QHub 101 by @HarshCasper in #1011
- remove jovyan user by @tylerpotts in #1089
- More finely scoped github actions and kubernetes_test build docker images by @costrouc in #1088
- Adding clearml overrides by @costrouc in #1059
- Reorganizing render, deploy, destroy to unify stages input_vars, tf_objects, checks, and state_imports by @costrouc in #1091
- Updates/fixes for rendering CICD workflows by @iameskild in #1086
- fix bug in state_01_terraform_state function call by @tylerpotts in #1094
- Use paths instead of paths-ignore so that test only run on changes to given paths by @costrouc in #1097
- [ENH] - Update issue templates by @trallard in #1083
- Generate independent objects for terraform-state resources by @viniciusdc in #1102
- Complete implementation of destroy which goes through each stage by @costrouc in #1103
- Change AWS Kubernetes provider authentication to use data.eks_cluster instead of exec by @costrouc in #1107
- Relax qhub destroy to attempt to continue destroying resources by @costrouc in #1109
- Breaking upgrade docs (0.4) by @danlester in #1087
- Simplify default images by @tylerpotts in #1114
- Change group structure by @danlester in #1112
- Adding status field to each destroy stage to print status by @costrouc in #1116
- Incorrect mapping of values to gcp node group instance types by @costrouc in #1117
- FIX: Remove Conda Store from default images by @HarshCasper in #1119
- Minor fix to
setup.cfg
by @iameskild in #1122 - [DOC]- Update contribution guidelines by @trallard in #1080
- Adding tests to visit additional endpoints by @costrouc in #1118
- Adding tests for juypterhub-ssh, jhub-client, and vs code by @costrouc in #1123
- Update Keycloak docs by @iameskild in #1093
- Upgrade conda-store v0.3.10 and simplify specification of image by @HarshCasper in #1130
- [ImgBot] Optimize images by @imgbot in #1140
- Adjust Idle culler settings and add internal culling by @viniciusdc in #1133
- [BUG] Removing jovyan home directory and issue with nss configuration by @costrouc in #1142
- [DOC] Add
troubleshooting
docs by @iameskild in #1139 - Update user login guides by @viniciusdc in #1144
- [ImgBot] Optimize images by @imgbot in #1146
- Workaround for kubernetes-client version issue by @iameskild in #1148
- Make the commit of the terraform rendering optional (replaces PR 995) by @iameskild in #1149
- Fix typos in user guide docs by @ericdatakelly in #1154
- Minor docs clean up for v0.4.0 release by @iameskild in #1155
- Read-the-docs and documentation updates by @tonyfast in #1153
- Add markdown formatter for doc wrapping by @viniciusdc in #1152
- remove deprecated param
count
from.cirun.yml
by @aktech in #1164 - Use qhub-bot for keycloak deployment/check by @iameskild in #1167
- Only list active conda-envs for dask-gateway by @iameskild in #1162
- @imgbot made their first contribution in #1140
- @ericdatakelly made their first contribution in #1154
Full Changelog: https://github.com/Quansight/qhub/compare/v0.3.13...v0.4.0
- No known breaking changes
- Allow users to specify external Container Registry (#741)
- Integrate Prometheus and Grafana into QHub (#733)
- Add Traefik Dashboard (#797)
- Make ForwardAuth optional for ClearML (#830)
- Include override configuration for Prefect Agent (#813)
- Improve authentication type checking (#834)
- Switch to pydata Sphinx theme (#805)
- Add force-destroy command (only for AWS at the moment) (#694)
- Include namespace in conda-store PVC (#716)
- Secure ClearML behind ForwardAuth (#721)
- Fix connectivity issues with AWS EKS via Terraform (#734)
- Fix conda-store pod eviction and volume conflicts (#740)
- Update
remove_existing_renders
to only delete QHub related files/directories (#800) - Reduce number of AWS subnets down to 4 to increase the number of available nodes by a factor of 4 (#839)
- better validation messages on github auto provisioning
- removing default values from pydantic schema which caused invalid yaml files to unexpectedly pass validation
- make kubespawner_override.environment overridable (prior changes were overwritten)
- reverting
qhub_user
default name tojovyan
- terraform formatting in cookiecutter for enabling GPUs on GCP
- creating releases for QHub simplified
- added an image for overriding the dask-gateway being used
- dask-gateway exposed by default now properly
- typo in cookiecutter for enabling GPUs on GCP
- setting
/bin/bash
as the default terminal
jhsingle-native-proxy
added to the base jupyterlab image
- simplified bash jupyterlab image to no longer have dashboard packages panel, etc.
- added emacs and vim as default editors in image
- added jupyterlab-git and jupyterlab-sidecar since they now support 3.0
- improvements with
qhub destroy
cleanly deleting resources - allow user to select conda environments for dashboards
- added command line argument
--skip-terraform-state-provision
to allow for skipping terraform state provisioning inqhub deploy
step - no longer render
qhub init
qhub-config.yaml
file in alphabetical order - allow user to select instance sizes for dashboards
- fixed gitlab-ci before_script and after_script
- fixed jovyan -> qhub_user home directory path issue with dashboards
- added a
--skip-remote-state-provision
flag to allowqhub deploy
within CI to skip the remote state creation - added saner defaults for instance sizes and jupyterlab/dask profiles
qhub init
no longer rendersqhub-config.yaml
in alphabetical orderspawn_default_options
to False to force dashboard owner to pick profile- adding
before_script
andafter_script
key toci_cd
to allow customization of CI process
- remaining issues with ci_cd branch not being fully changed
- Moved to ruamel as yaml parser to throw errors on duplicate keys
- fixed a url link error in cds dashboards
- Azure fixes to enable multiple deployments under one account
- Terraform formatting issue in acme_server deployment
- Terraform errors are caught by qhub and return error code
- prevent gitlab-ci from freezing on gitlab deployment
- not all branches were configured via the
branch
option inci_cd
- added gitlab support for CI
ci_cd
field is now optional- AWS provider now respects the region set
- More robust errors messages in cli around project name and namespace
git init
default branch is nowmain
- branch for CI/CD is now configurable
- typo in
authenticator_class
for custom authentication
- Support for self-signed certificate/secret keys via kubernetes secrets
- jupyterhub-ssh (
ssh
andsftp
integration) accessible on port8022
and8023
respectively - VSCode(code-server) now provided in default image and integrated with jupyterlab
- Dask Gateway now accessible outside of cluster
- Moving fully towards traefik as a load balancer with tight integration with dask-gateway
- Adding ability to specify node selector label for general, user, and worker
- Ability to specify
kube_context
for local deployments otherwise will use default - Strict schema validation for
qhub-config.yaml
- Terraform binary is auto-installed and version managed by qhub
- Deploy stage will auto render by default removing the need for render command for end users
- Support for namespaces with qhub deployments on kubernetes clusters
- Full JupyterHub theming including colors now.
- JupyterHub docker image now independent from zero-to-jupyterhub.
- JupyterLab 3 now default user Docker image.
- Implemented the option to locally deploy QHub allowing for local testing.
- Removed the requirement for DNS, authorization is now password-based (no more OAuth requirements).
- Added option for password-based authentication
- CI now tests local deployment on each commit/PR.
- QHub Terraform modules are now pinned to specific git branch via
terraform_modules.repository
andterraform_modules.ref
. - Adds support for Azure cloud provider.
- Terraform version is now pinned to specific version
domain
attributed inqhub-config.yaml
is now the url for the cluster
- Version
<version>
is in formatX.Y.Z
- Create release branch
release-<version>
based offmain
- Ensure full functionality of QHub this involves at a minimum ensuring
- GCP, AWS, DO, and local deployment
- "Let's Encrypt" successfully provisioned
- Dask Gateway functions properly on each
- JupyterLab functions properly on each
- Increment the version number in
qhub/VERSION
in formatX.Y.Z
- Ensure that the version number in
qhub/VERSION
is used in pinning QHub in the github actionsqhub/template/{{ cookiecutter.repo_directory }}/.github/workflows/qhub-ops.yaml
in formatX.Y.Z
- Create a git tag pointing to the release branch once fully tested and version numbers are incremented
v<version>
- Added conda prerequisites for GUI packages.
- Added
qhub destroy
functionality that tears down the QHub deployment. - Changed the default repository branch from
master
tomain
. - Added error message when Terraform parsing fails.
- Added templates for GitHub issues.
qhub deploy -c qhub-config.yaml
no longer prompts unsupported argument forload_config_file
.- Minor changes on the Step-by-Step walkthrough on the docs.
- Revamp of README.md to make it concise and highlight QHub HPC.
- Removed the registry for DigitalOcean.
Brian Larsen, Rajat Goyal, Prasun Anand, and Rich Signell and Josef Kellndorfer for the insightful discussions.