Skip to content

feat: update keda to 2.20.1 #minor#1459

Open
public-glueops-renovatebot[bot] wants to merge 1 commit into
mainfrom
renovate/keda-2.x
Open

feat: update keda to 2.20.1 #minor#1459
public-glueops-renovatebot[bot] wants to merge 1 commit into
mainfrom
renovate/keda-2.x

Conversation

@public-glueops-renovatebot

@public-glueops-renovatebot public-glueops-renovatebot Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
keda minor 2.17.22.20.1

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

kedacore/keda (keda)

v2.20.1

Compare Source

Fixes
  • General: Fix concurrent map read/write data race in fallback updateStatus that caused panics when multiple triggers were scaling simultaneously (#​7838)
  • General: Fix KEDAScalersStarted "Started scalers watch" event not being emitted for ScaledJobs because it shared an events.k8s.io aggregation key with the per-scaler "scaler is built" event (#​7820)

v2.20.0

Compare Source

New
  • General: Add scalingModifiers fallback behavior (#​7366)
  • General: Introduce Elastic Forecast Scaler (#​7494)
  • General: Introduce new OpenSearch Scaler (#​7456)
Improvements
  • General: Add cooldownPeriod and pollingInterval checks for ScaledObject (#​7271)
  • General: Add CRD-level validation markers (Minimum, MinLength, MinItems, Enum) for ScaledObject, ScaledJob, ScaleTriggers, and TriggerAuthentication API types (#​7533)
  • General: Add --leader-election-id flag to allow configuring the leader election Lease name (#​7564)
  • General: Add scaler HTTP request metrics (keda_scaler_http_requests_total, keda_scaler_http_request_duration_seconds) for outbound HTTP requests made during scaler metric collection (#​6600)
  • General: Allow more control of TLS versions & ciphers via KEDA_HTTP_TLS_CIPHER_LIST, KEDA_SERVICE_TLS_CIPHER_LIST and KEDA_SERVICE_MIN_TLS_VERSION env vars (#​7617)
  • General: Cap each scalers-cache reader at a per-reader budget derived from globalHTTPTimeout so ScalersCache.Close cannot block indefinitely (#​7574)
  • General: Make APIService cert injections optional (#​7559)
  • General: Remove unconditional json.MarshalIndent calls from admission webhook validation hot paths; replace spec-comparison MarshalIndent-and-string-compare in isRemovingFinalizer variants with reflect.DeepEqual. Prevents webhook OOM under sustained admission load at large scale (observed at ~60k ScaledObjects) (#​7670)
  • AWS Scalers: Add support for AWS External ID in TriggerAuthentication podIdentity for all AWS scalers (SQS, Kinesis, DynamoDB, CloudWatch, etc.) to enable cross-account access scenarios (#​6921)
  • Elasticsearch Scaler: Add HTTP status check for Elasticsearch errors (#​7480)
  • Github Runner Scaler: Handle rate limit errors by respecting X-RateLimit-Reset and Retry-After headers and returning cached queue length (#​7683)
  • Kubernetes Workload Scaler: Add groupByNode parameter (#​7628)
  • Metrics API Scaler: Add custom HTTP client timeout (#​7549)
  • MSSQL Scaler: Add Azure Workload Identity support for Azure SQL authentication (#​6104)
  • Prometheus Scaler: Emit metric tracking empty responses from Prometheus (#​7062)
  • RabbitMQ Scaler: Add support for OAuth2 authentication for RabbitMQ over HTTP (#​7379)
  • Temporal Scaler: Add support for scaling based on Worker Deployment Version backlog via new workerDeploymentName and workerDeploymentBuildId fields. Deprecate buildId, selectAllActive, and selectUnversioned because those parameters are used for Rules-Based Worker Versioning, which was a short-lived experimental feature that has been deprecated in the Temporal server since December 2024 and will stop being supported soon. Users of Rules-Based Worker Versioning should use Worker Deployments instead. (#​7672)
Fixes
  • General: Add controller-runtime cache field indexes for ScaledObject admission validation so verifyScaledObjects and verifyHpas look up duplicate scaleTargetRef and HPA-name conflicts via indexed Lists rather than full-namespace scans, eliminating the webhook OOM under high-scale creation bursts (#​7681)
  • General: Check updated status for Fallback condition instead of ScaledObject (#​7488)
  • General: Fail fast in GetMetrics when the gRPC connection is in Shutdown state instead of waiting for context timeout (#​7251)
  • General: Fix int64 overflow in milli-quantity conversion for very large metric values (#​7441)
  • General: Fix keda_scaler_active not being emitted for CPU and memory triggers (#​4945)
  • General: Fix misleading namespace in error log when secret access is restricted (#​7739)
  • General: Fix race in scalers cache rebuild that caused transient scaler errors (#​7574)
  • General: Fix ScaledJob emitting wrong CloudEvent type (ScaledObjectReadyType instead of ScaledJobReadyType) when transitioning to ready state (#​7792)
  • General: Fix ScaledObject admission webhook to return validation error from verifyReplicaCount, preventing invalid ScaledObjects from being created (#​5954)
  • General: Fix ScaledObject Ready condition not reflecting HPA status (#​7649)
  • General: Guard GetCurrentReplicas against nil Status.ScaleTargetGVKR to prevent operator panics under the cache race documented in (#​4389) / (#​4955)
  • General: Handle paused scaling directly in reconciler (#​7663)
  • General: Honor stderrthreshold when logtostderr is enabled by updating klog to v2.140.0 (#​7568)
  • General: Limit projected service account token reads during Vault authentication (#​7783)
  • General: Reject ScaledObject creation and update when the name exceeds 63 characters (#​6998)
  • AWS Scalers: Fix TCP connection leak by closing HTTP idle connections on scaler Close() for SQS, Kinesis, DynamoDB, DynamoDB Streams, and CloudWatch scalers (#​7756)
  • Azure Data Explorer Scaler: Remove clientSecretFromEnv support (#​7554)
  • Azure Event Hub Scaler: Reject non-positive unprocessedEventThreshold to prevent integer division by zero when computing lag (#​7732)
  • Azure Pipelines Scaler: Exclude already-assigned jobs from queue length (#​7747)
  • Cron Scaler: Fix metric name generation so cron expressions with comma-separated values no longer produce invalid metric names (#​7448)
  • External Scaler: gRPC Pool uses TLS context in the key (#​7687)
  • Forgejo Scaler: Limit HTTP error response logging (#​7469)
  • Forgejo Scaler: Return correct activity to enable scale-to-zero (#​7527)
  • GCP Cloud Tasks Scaler: Implement escapeFilterValue for metric filtering (#​7482)
  • GCP Scaler: Validate Pub/Sub resource name in BuildMQLQuery (#​7468)
  • GCP Storage Scaler: Metadata is not printed in the log (#​7688)
  • Github Runner Scaler: Bound etag and per-repo caches to prevent unbounded memory growth when enableEtags is on (#​7685)
  • Github Runner Scaler: Improve URL construction and error handling (#​7495)
  • Github Runner Scaler: Limit HTTP error response logging (#​7469)
  • InfluxDB Scaler: Make authToken optional to support unauthenticated InfluxDB instances (#​7616)
  • Loki Scaler: Limit HTTP error response logging (#​7469)
  • Loki Scaler: serverAddress now appends /loki/api/v1/query to the end of existing path instead of overriding (#​7648)
  • Metrics API Scaler: Fix aggregateFromKubeServiceEndpoints using empty label selector that matched all EndpointSlices in the namespace instead of only the target service's (#​7641)
  • Metrics API Scaler: Fix division by zero in average aggregation when all kube service endpoints fail (#​7742)
  • Metrics API Scaler: Prevent response value reflection in scaler errors (#​7693)
  • NATS JetStream Scaler: Return an error from getMaxMsgLag when the configured consumer is missing instead of falling back to the stream's last sequence, preventing incorrect scale-up to maxReplicaCount (#​7657)
  • NATS JetStream Scaler: URL-encode user input in monitoring URL construction (#​7483)
  • PostgreSQL Scaler: Quote whitespace-containing connection parameters in generated connection strings (#​7784)
  • PredictKube Scaler: Bump dysnix/predictkube-libs to v0.1.0 (drops the predictkube path to the archived/EOL go-grpc-prometheus and to the deprecated golang/protobuf) and use a portable Prometheus-API instant query for the health check so the scaler works against VictoriaMetrics, Thanos and other Prometheus-API-compatible backends (#​7745)
  • Prometheus Scaler: Handle NaN results in the same manner as Inf (#​7475)
  • Prometheus Scaler: Limit HTTP error response logging (#​7469)
  • Pulsar Scaler: Drop bearer/basic auth headers on redirects to a different host or on https->http downgrades to prevent credential leakage (#​7686)
  • RabbitMQ Scaler: Fix AMQP connection leak by recovering channels on the existing connection and closing connections properly (#​6266)
  • RabbitMQ Scaler: Use SASL EXTERNAL for RabbitMQ AMQP TLS without credentials (#​6840)
  • Redis Scaler: Use literal command names in Lua script to fix compatibility with Alibaba Cloud Redis Cluster (#​7758)
  • Solace Scaler: Fix URL escaping for Message VPN and Queue names (#​7481)
  • Solr Scaler: Use net/url to safely encode query parameters (#​7467)
  • Splunk Observability Scaler: Add MTS stream handling with context timeout (#​7799)
Deprecations

You can find all deprecations in this overview and join the discussion here.

Breaking Changes
  • GCP PubSub Scaler: The subscriptionSize setting is DEPRECATED and is removed in v2.20 - Use mode and value instead (#​7720)
  • Huawei Cloudeye Scaler: The minMetricValue setting is DEPRECATED and is removed - Use activationTargetMetricValue instead (#​7436)
  • IBM MQ Scaler: The tls setting code is removed (#​6094)
  • InfluxDB Scaler: The authToken setting from triggerMetadata is DEPRECATED and is removed in v2.20 - Use authToken from resolvedEnv or authParams instead (#​7722)
Other
  • General: Migrate event recording RBAC from core events to events.k8s.io (#​7781)
  • General: Migrate metrics service gRPC response away from Kubernetes API protobuf types for Kubernetes 0.35 (#​7781)
  • General: Remove dead code from authentication package and drop unused authModes field from ArangoDB, Loki, Prometheus and PredictKube scalers (#​7726)
  • General: Use informer cache for ReplicaSet lookups in GetCurrentReplicas to reduce API server load (#​7466)
  • External Scaler: Fix race condition in TestWaitForState causing flaky test under -race detector (#​7542)
  • GCP Scaler: Replace credentialsFromJSON with credentialsFromJSONWithType (#​7523)
  • Kafka Scaler: Refactor Kafka Scaler (#​7528)

v2.19.0

Compare Source

New
  • General: Add file-based authentication support for ClusterTriggerAuthentication (#​7083)
  • General: Introduce new Kubernetes Resource Scaler (#​7212)
Improvements
  • General: Correct error message when awsSecretAccessKey is missing in credential-based authentication (#​7265)
  • General: Emit more events about what is happening with ScaledObject/ScaledJob (#​7382)
  • General: Raw metrics stream - include trigger activity status in response (#​7369)
  • AWS CloudWatch Scaler: Add cross-account observability support (#​7189)
  • Dynamodb Scaler: Add FilterExpression support (#​7102)
  • Dynatrace Scaler: Support DQL querying (#​7377)
  • MongoDB Scaler: Add TLS support (#​6976)
Fixes
  • General: Apply fallback in polling loop to enable scaling from zero (#​7239)
  • General: Fix accurateScalingStrategy ignoring pendingJobCount in maxReplicaCount check (#​7329)
  • General: Replace deprecated azure autorest dependency to azure sdk for go (#​7073)
  • Datadog Scaler: Return request in cluster agent proxy without bearer auth (#​7341)
  • Datadog Scaler: Use metricUnavailableValue for 422 errors in Datadog Cluster Agent (#​7246)
  • IBMMQ Scaler: Create new HTTP request for each queue query in IBMMQ scaler (#​7202)
  • Kafka Scaler: Improve check for missing partition information when calculating lag (#​7414)
  • Temporal Scaler: Fix TLS RootCAs initialization when using API key authentication with Temporal Cloud (#​7367)
Deprecations

You can find all deprecations in this overview and join the discussion here.

Breaking Changes
  • NATS Streaming scaler: Remove NATS Streaming Server (aka Stan) (#​6366)
Other
  • CI: Replace stale bot with official GitHub Actions stale action (#​7321)
  • CI: Use GitHub-hosted ARM64 runners (#​7293)
  • ScaledObject/ScaledJob: Track activity for each trigger in the status (#​7347)

v2.18.3

Compare Source

Fixes

v2.18.2

Compare Source

Fixes
  • General: Fix HPA behavior not restored when paused-scale-in/out annotation is deleted without corresponding custom behavior (#​7291)
  • General: Fix nil reference panic when transfer-hpa-ownership is set but no hpa name is provided (#​7254)
  • General: Fix race condition in paused-replicas annotation causing ScaledObject to get stuck (#​7231)
  • General: Fix ScaledObject controller error handling for requestScaleLoop (#​7273)
  • General: Remove unnecessary scaledObjectMetricSpecs variable in HPA (#​7292)
  • General: Use TriggerError when all ScaledJob triggers fail (#​7205)
  • ActiveMQ Scaler: Correct parse error ActiveMQ (#​7245)
  • Datadog Scaler: Fix metricUnavailableValue parameter not working (#​7238)

v2.18.1

Compare Source

Fixes
  • General: Add feature flag KEDA_CHECK_UNEXPECTED_SCALERS_PARAMS for checking unexpected scaler parameters (#​6721)
  • General: Fix incorrect 'unmatched input property' notification (#​7174)
  • Kafka Scaler: Fix missing error returns in error handling (#​7182)
Other
  • General: Raw metrics stream - send also metrics during ScaledObject's interval (#​7197)

v2.18.0

Compare Source

New
  • General: Add fallback support for triggers of Value metric type (#​6655)
  • General: Add support for Force Activation annotation (#​6903)
  • General: Add support for pause scale in annotation (#​6902)
  • General: Add support for pause scale out annotation (#​7022)
  • General: Enable support on s390x for KEDA (#​6543)
  • General: Introduce new Forgejo Scaler (#​6488)
  • General: Introduce new Solace Direct Messaging scaler (#​6545)
  • General: Introduce new SolarWinds Scaler (#​6576)
  • General: Introduce new Splunk Observability Cloud Scaler (#​7152)
  • General: Introduce new Sumo Logic Scaler (#​6734)
  • General: Support for declarative e2e test setup and filtering (#​6989)
  • General: Trigger Schema Generated Tool (#​6345)
  • General: Vault authentication via cross-namespace service accounts (#​6153)
Improvements
  • General: Add error and event for mismatching input property (#​6721)
  • General: Allow excluding labels from being propagated from ScaledObject and ScaledJob to generated HPA and Job objects (#​6849)
  • General: Improve Events emitted from ScaledObject controller (#​6802)
  • General: Only add webhook DNS names when webhook patching is enabled (#​7002)
  • Apache Kafka Scaler: Add support for even distribution of partitions to consumers (#​2581)
  • Artemis Scaler: Add TLS support with client certificates for secure HTTPS connections (#​6448)
  • AWS CloudWatch Scaler: Add support for CloudWatch extended statistics (e.g P99 / TM90 and etc) (#​7109)
  • Azure Pipelines Scaler: Ability to enable case-insensitive comparison of pipeline job demands (#​7111)
  • Azure Pipelines Scaler: Ability to fetch only unfinished pipeline jobs for a pool (#​6819)
  • Datadog Scaler: Add a specific timeout configuration parameter for the Datadog trigger (#​6999)
  • Datadog Scaler: Improve Datadog scaler error messages (#​6999)
  • Github Scaler: Add support to control unlabeled job/runner matching (#​6900)
  • InfluxDB Scaler: Add support for InfluxDB v3 (#​6981)
  • Kafka Scaler: Add support for even distribution of partitions to consumers (#​2581)
  • Metrics API scaler: Introduce new aggregateFromKubeServiceEndpoints and aggregationType metadata fields to metrics-api so it is able to fetch metrics from all endpoints behind a kubernetes service and aggregate them (#​6565)
  • Metrics API Scaler: Support AuthParams for authMode (#​6939)
  • Metrics API Scaler: Support multiple auth methods simultaneously (#​6642)
  • RabbitMQ Scaler: add DeliverGetRate, PublishedToDeliveredRatio and ExpectedQueueConsumptionTime trigger modes to RabbitMQ scaler (#​7071)
  • Solace Scaler: Add hostlist support for Solace brokers (#​7090)
  • Temporal Scaler: Always set temporal-namespace header on requests(#​7079)
  • Temporal Scaler: Support custom tlsServerName (#​6820)
Fixes
  • General: Add missing omitempty json tags in the AuthPodIdentity struct (#​6779)
  • General: Correct pending pod condition logic for ScaledJobs (#​6727)
  • General: Fix external push scaler deactivation behavior (#​6986)
  • General: Fix parse timeout config as milliseconds instead of seconds (#​6997)
  • General: Fix prefixes on envFrom elements in a deployment spec aren't being interpreted and Environment variables are not prefixed with the prefix (#​6728)
  • General: Fix SIGSEGV when doing fallback of non-static behavior on any ScaleTargetRef that is neither a Deployment nor a StatefulSet (#​6992)
  • General: New Scaled{Object,Job} has paused condition in their status as False instead of Unknown (#​7011)
  • General: Remove klogr dependency and replace with zap (#​5732)
  • General: Resolve race condition when removing paused-replicas annotation from ScaledObject (#​6982)
  • General: Sets hpaName in Status when ScaledObject adopts/finds an existing HPA (#​6336)
  • Cron Scaler: Fix cron scaler to return zero metric value by default(#​6886)
  • Datadog Scaler: Fix bug with datadogNamespace config (#​6828)
  • Hashicorp Vault: Fix Vault PKI param using camel case param when making API call to Vault PKI endpoint (#​6864)
  • Kafka Scaler: Fix throwing error when using sasl=none (#​7061)
  • Pulsar Scaler: Resolve nil pointer dereference in Pulsar scaler redirect handling (#​7024)
  • RabbitMQ Scaler: Fix incorrect URL encoding in RabbitMQ vhosts containing %2f (#​6963)
  • Temporal Scaler: Allow setting 0 for targetQueueSize (#​7113)
Deprecations

You can find all deprecations in this overview and join the discussion here.

New deprecation(s):

  • GCP Pub/Sub Scaler: The subscriptionSize setting is DEPRECATED and will be removed in v2.20 - Use mode and value instead (#​6866)
  • Huawei Cloudeye Scaler: The minMetricValue setting is DEPRECATED and will be removed in v2.20 - Use activationTargetMetricValue instead (#​6978)
Breaking Changes
  • General: Remove Prometheus webhook prommetrics deprecations (#​6698)
  • CPU Memory scaler: The type setting is deprecated and removed, use metricType instead (#​6698)
  • IBM MQ scaler: The tls setting is deprecated and removed, use unsafeSsl instead (#​6698)
Other
  • General: Add gRPC service that allows subscribing to a raw metric values (#​7094)
  • General: Bump Controller Runtime version to v0.20.4 (#​7081)
  • General: Fix several typos (#​6909)
  • General: Replace deprecated webhook.Validator with webhook.CustomValidator (#​6660)
  • MSSQL Scaler: Refactor MS SQL e2e test (#​3401)

v2.17.3

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants