NetObserv
Network observability operator for OpenShift and Kubernetes
NetObserv is layering TLS visibility and health alerting on top of its eBPF flow pipeline.
◆Recent moves
- 19d ago
1.12.0 adds TLS alerting, flp-informers and signed releases
Extends the TLS thread with alerting, wires up flp-informers deployment, and adds SBOM generation and signing to the release workflow. The security-of-the-build work here — SHA-pinned actions, pwn-request checks, a pprof exposure fix — is as substantial as the feature content.
View source ↗ - 1mo ago
1.11.5 adds TLS metrics, Kafka compression and drop events
Integrates drops and network events, adds a Kafka compression option (then disables it by default), fixes dns.name mapping in the OTLP export, and adds TLS metrics. The agent-to-pipeline mTLS path is fixed downstream, continuing the hardening that started in 1.11.2.
View source ↗ - 4mo ago
TLS tracking arrives as a feature knob with new TLS fields
⚡ SPARKThe release that opens a new observable dimension: a TLSTracking knob and TLS fields on flows, alongside automatic enrichment with secondary interfaces and Prometheus defaulting to enabled. Everything TLS-related in the two releases that follow — metrics, then alerts — builds on what landed here.
View source ↗ - 5mo ago
1.11.2 adds a pause control and TLS/mTLS hardening
Adds a way to pause Network Observability functions without tearing the deployment down, hardens TLS and mTLS between components, and adds predefined network metrics including IPsec. Also renames the operator to netobserv-operator, which is the kind of change that breaks scripted installs.
View source ↗ - 5mo ago
1.11.1 is documentation, Snyk config and dependency updates
Almost entirely housekeeping: Snyk configuration, documentation vendor-neutrality passes, a GOMEMLIMIT setting on flowlogs-pipeline, and a long Konflux dependency run. The one functional fix is NetworkEvents against upstream ovn-kubernetes.
View source ↗ - 6mo ago
1.11.0 builds out Network Health rules and hot-reload filters
The release that establishes the health direction: recording rules as an alternative to alerts, ingress 5xx and latency trend templates, runbook links in alerts, and health integration in the topology view. Hot-reloadable filters land here too, removing a restart from the tuning loop.
View source ↗