Evidence ledger
One row per claim in Two hundred control planes per cluster: ten years of SAP's Gardener: who published it, what grade it carries, when it was written, when the link was last checked, and the quote or figure it rests on. Nothing in the guide is cited from memory, so anything not in this table is not in the guide.
One row per claim. Tier grades follow the skill's hierarchy (postmortem > source > adr >
casestudy > paper/talk > blog > vendor). Checked dates are when the URL was fetched in
this session.
Corpus limitation, stated up front. This session's network egress resolved
raw.githubusercontent.com, proxy.golang.org, pkg.go.dev and cloud.google.com, and the egress
proxy refused every engineering-blog host, github.com and api.github.com, Wikipedia, arXiv,
USENIX, YouTube, speaker-deck and status pages. The consequence: there are no blog, talk or paper
sources here, and no published incident review, and GitHub issues and pull requests were
unreachable, so the "rejected approach" layer comes from design documents rather than from closed
pull requests. Files were read through raw.githubusercontent.com at a pinned tag, and version
dates through the Go module proxy's .info endpoint; two complete release archives (v1.0.0 and
v1.152.0) were downloaded from the module proxy and compared locally, which is how removals were
dated. Where a date is given as "first release containing X", it was found by bisecting the tag list
with raw.githubusercontent.com requests.
| # | Org | Title | Tier | Published | Checked | URL | Claim I take from it | Supporting quote or figure |
|---|---|---|---|---|---|---|---|---|
| 1 | Gardener (GitHub Advisory DB) | GHSA-3hw7-qj9h-r835 / CVE-2025-47283, bypassing project secret validation | postmortem | 2025-05-19 | 2026-10-01 | https://raw.githubusercontent.com/github/advisory-database/main/advisories/github-reviewed/2025/05/GHSA-3hw7-qj9h-r835/GHSA-3hw7-qj9h-r835.json | In a shared-host fleet, a tenant-side validation defect becomes a cross-tenant compromise of the host cluster. | "A security vulnerability was discovered in Gardener that could allow a user with administrative privileges for a Gardener project to obtain control over the seed cluster(s) where their shoot clusters are managed." Severity CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. |
| 2 | Gardener (GitHub Advisory DB) | GHSA-3hw7-qj9h-r835, affected and fixed versions | postmortem | 2025-05-19 | 2026-10-01 | https://raw.githubusercontent.com/github/advisory-database/main/advisories/github-reviewed/2025/05/GHSA-3hw7-qj9h-r835/GHSA-3hw7-qj9h-r835.json | The fix had to ship on four maintenance lines at once, which is what a three-line hotfix policy costs during an escalation. | "Fixed Versions: >= v1.116.4, >= v1.117.5, >= v1.118.2, >= v1.119.0"; "This CVE affects all Gardener installations no matter of the public cloud provider(s) used". |
| 3 | Gardener (GitHub Advisory DB) | GHSA-9x73-87fh-54w9 / CVE-2025-47284, metadata injection for a project secret | postmortem | 2025-05-19 | 2026-10-01 | https://raw.githubusercontent.com/github/advisory-database/main/advisories/github-reviewed/2025/05/GHSA-9x73-87fh-54w9/GHSA-9x73-87fh-54w9.json | A second, independent path to the same escalation in the same month: the class of defect, not the bug, is the finding. | "A security vulnerability was discovered in the gardenlet component of Gardener. It could allow a user with administrative privileges for a Gardener project to obtain control over the seed cluster(s)". |
| 4 | Gardener (GitHub Advisory DB) | GHSA-227x-7mh8-3cf6 / CVE-2025-59823, code injection through provider configuration | postmortem | 2025-09-25 | 2026-10-01 | https://raw.githubusercontent.com/github/advisory-database/main/advisories/github-reviewed/2025/09/GHSA-227x-7mh8-3cf6/GHSA-227x-7mh8-3cf6.json | Out-of-tree extensions multiply the sites of a shared defect class: one injection class, four extensions, four fixed versions. | "A security vulnerability was discovered in Gardener when Terraformer is used for infrastructure provisioning. This vulnerability could allow a user with administrative privileges for a Gardener project to obtain control over the seed cluster"; affected components gcp, azure, openstack, aws with fixes at v1.46.0, v1.55.0, v1.49.0, v1.64.0. |
| 5 | Gardener | README at v1.152.0 | source | release 2026-09-24 | 2026-10-01 | https://raw.githubusercontent.com/gardener/gardener/v1.152.0/README.md | The central decision: tenant control planes run as ordinary workload in a host cluster, for cost and for day-two operations. | "The shoot clusters do not have dedicated master VMs. Instead, the control plane is deployed as a native Kubernetes workload into the seeds (the architecture is commonly referred to as kubeception or inception design). This does not only effectively reduce the total cost of ownership but also allows easier implementations for 'day-2 operations'". |
| 6 | Gardener | README at v1.152.0 (concept mapping) | source | release 2026-09-24 | 2026-10-01 | https://raw.githubusercontent.com/gardener/gardener/v1.152.0/README.md | Every fleet concept is named after a Kubernetes concept, which is the design method, not documentation. | "Kubelet = Gardenlet / Node = Seed cluster / Pod = Shoot cluster". |
| 7 | Gardener | README at v1.152.0 (conformance) | source | release 2026-09-24 | 2026-10-01 | https://raw.githubusercontent.com/gardener/gardener/v1.152.0/README.md | Five infrastructures are continuously conformance-tested, and homogeneity is the product claim. | "Currently, Gardener is certified for K8s versions up to v1.35"; conformance table rows AWS, Azure, GCP, OpenStack, Alicloud. |
| 8 | Gardener | Architecture concept | source | release 2026-09-24 | 2026-10-01 | https://raw.githubusercontent.com/gardener/gardener/v1.152.0/docs/concepts/architecture.md | Scale target and placement rule, and the claim that availability is a scheduling property rather than a replica count. | "we apply a special pattern catering to the needs of our cloud platform to provision hundreds or even thousands of clusters"; "one 'seed' cluster, of which we will have one per IaaS and region"; "they can be deployed with a replica count of 1 and only need to be scaled out when the control plane gets under pressure, but no longer for HA reasons". |
| 9 | Gardener | NOTICE at v1.152.0 | source | release 2026-09-24 | 2026-10-01 | https://raw.githubusercontent.com/gardener/gardener/v1.152.0/NOTICE.md | SAP origin and start year, still shipping in the current release; the project was seeded from Kubernetes' own sample API server. | "Copyright 2017-2019 SAP SE or an SAP affiliate company. All rights reserved."; "The source code of this component was seeded based on a copy of the following files from github.com/kubernetes: Sample APIServer." |
| 10 | Gardener | GEP-1, extensibility and extraction of cloud-specific knowledge | adr | in releases from v1.0.0 (2020-02-06) | 2026-10-01 | https://raw.githubusercontent.com/gardener/enhancements/main/geps/0001-gardener-extensibility/README.md | The trigger for extracting provider code was deployability, not code size, and the model was Kubernetes' own extraction of CRI, CSI, CNI and the cloud controller manager. | "Every change must be done centrally, requires to completely rebuild Gardener, and cannot be deployed individually. Similar to the motivation for Kubernetes to extract their cloud-specifics into dedicated cloud-controller-managers or to extract the container/storage/network/... specifics into CRI/CSI/CNI/..., we aim to do the same right now." |
| 11 | Gardener | GEP-1, non-goals | adr | in releases from v1.0.0 | 2026-10-01 | https://raw.githubusercontent.com/gardener/enhancements/main/geps/0001-gardener-extensibility/README.md | The extensibility contract was deliberately not generalised into a template engine. | "We do not want to make Gardener a plain workflow engine that just executes a given template ... which indeed would end-up in building a 'programming/scripting language' inside a serialization format (YAML/JSON/...)". |
| 12 | Gardener | GEP-8, shoot API server via SNI | adr | in releases from v1.0.0 | 2026-10-01 | https://raw.githubusercontent.com/gardener/enhancements/main/geps/0008-shoot-apiserver-via-sni/README.md | Per-tenant load balancers were rejected on price and on quota, and the replacement shares one gateway per host cluster without breaking TLS. | "IaaS provider costs. For example, ClassicLoadBalancer on AWS costs at minimum 17 USD / month."; "Quotas can limit the amount of LoadBalancers you can get per account / project, limiting the number of clusters you can host under a single account."; goal: "Only one LoadBalancer is used for all Shoot cluster API servers running in a Seed cluster." |
| 13 | Gardener | GEP-11, invert seed-to-shoot connectivity with the upstream proxy | adr | in releases from v1.4.0 (2020-05-07) | 2026-10-01 | https://raw.githubusercontent.com/gardener/enhancements/main/geps/0011-apiserver-network-proxy/README.md | The pre-2020 design needed a load balancer inside every tenant cluster and blocked private-only estates. | "Every shoot would require an additional loadbalancer, this accounts for additional overhead in terms of both costs and troubleshooting efforts."; "Private access use-cases would not be possible without having a seed residing in the same private domain as a hard requirement." |
| 14 | Gardener | GEP-14, reversed cluster VPN | adr | in releases from v1.21.0 (2021-04-22) | 2026-10-01 | https://raw.githubusercontent.com/gardener/enhancements/main/geps/0014-reversed-cluster-vpn/README.md | The adopted upstream tunnel was superseded by an in-house reversed tunnel, with the deletion stated as an intention, and with explicit non-goals about throughput and availability. | "We intend to supersede the current VPN solution with the solution outlined in this proposal."; "We intend to remove the code for the Konnectivity tunnel once this solution proposal has been validated."; "The solution is not a low latency or high throughput solution." |
| 15 | Gardener | GEP-13, automated seed management | adr | in releases from v1.14.0 (2020-12-09) | 2026-10-01 | https://raw.githubusercontent.com/gardener/enhancements/main/geps/0013-automated-seed-management/README.md | Placement of tenants onto hosts is modelled exactly as pod scheduling, with capacity and allocatable copied from the node status. | "Seeds have a practical limit of how many shoots they can accommodate."; "In Gardener, scheduling shoots onto seeds is quite similar to scheduling pods onto nodes in Kubernetes."; "the gardenlet seed controller updates the Seed status with the capacity of each resource and how much of it is actually available ... using capacity and allocatable fields that are very similar to the corresponding fields in the Node status". |
| 16 | Gardener | GEP-6, integrating etcd-druid | adr | in releases from v1.0.0 | 2026-10-01 | https://raw.githubusercontent.com/gardener/enhancements/main/geps/0006-etcd-druid/README.md | A webhook that rewrote another controller's StatefulSet was replaced by an operator, because the webhook blocked lifecycle operations; corruption checks run before etcd starts. | "The sidecar container spec contains details pertaining to cloud-provider object-store, which is injected into the statefulset via a mutable webhook ... This approach restricts the operations on etcd, such as scale-up and upgrade."; "Only data corruption checks are performed prior to starting etcd." |
| 17 | Gardener | GEP-17, control plane migration "bad case" | adr | in releases from v1.41.0 (2022-02-25) | 2026-10-01 | https://raw.githubusercontent.com/gardener/enhancements/main/geps/0017-shoot-control-plane-migration-bad-case/README.md | Recovery when the host cluster is unreachable is ownership passing through a DNS record every participant checks, and an earlier design using files in the backup bucket was dropped. | "The potential 'split brain' situation caused by having the shoot's control plane components attempting to reconcile the shoot resources in two different seeds must still be avoided"; "A previous revision of this document proposed using 'sync objects' written to and read from the backup container ... With the introduction of owner DNS records such sync objects are no longer needed." |
| 18 | Gardener | GEP-20, highly available shoot control planes | adr | in releases from v1.53.0 (2022-08-11) | 2026-10-01 | https://raw.githubusercontent.com/gardener/enhancements/main/geps/0020-ha-control-planes/README.md | Single-replica control plane components, etcd included, were the default until 2022; the fix makes the failure domain a per-tenant choice. | "Many of the other critical control plane components including etcd are only offered with a single replica, making them susceptible to both node failure as well as zone failure causing downtimes."; "Each consumer therefore needs to decide on the degree of failure isolation that is desired". |
| 19 | Gardener | GEP-23, autoscaling the shoot API server with independent HPA and VPA | adr | in releases from v1.76.0 (2023-07-28) | 2026-10-01 | https://raw.githubusercontent.com/gardener/enhancements/main/geps/0023-autoscaling-kube-apiserver-via-independent-hpa-and-vpa/README.md | The in-house fused autoscaler was replaced by the two upstream controllers used independently, on cost and maintenance grounds, with a 100x spread in per-tenant requirements. | "The existing approach of fusing HPA and VPA into the 2-dimensional autoscaler which is HVPA, poses severe algorithmic limitations which manifest as stability and efficiency issues in the field."; "The compute cost of ShootKapi workloads constitutes a major part of Gardener's overall compute cost."; "compute resources required by ShootKapis of different shoots vary by two orders of magnitude"; "Kube-apiserver does not scale well horizontally". |
| 20 | Gardener | GEP-26, workload identity | adr | in releases from v1.93.0 (2024-04-19) | 2026-10-01 | https://raw.githubusercontent.com/gardener/enhancements/main/geps/0026-workload-identity/README.md | Long-lived infrastructure credentials were replaced by short-lived federated tokens, and credential expiry is framed as an availability risk for the reconciler. | "These credentials usually have long lifetime (and are often non-expiring), they are reused in different scenarios by various tools, occasionally granted with broader permissions, stored in different locations."; "Static credentials can expire or get accidentally invalidated, which will cause reconciliation flows to fail preventing delivery of updates, fixes, and improvements." |
| 21 | Gardener | GEP-28, self-hosted shoot clusters | adr | in releases from v1.132.0 (2025-11-13) | 2026-10-01 | https://raw.githubusercontent.com/gardener/enhancements/main/geps/0028-self-hosted-shoot-clusters/README.md | Eight years in, the shared-host model gained an exception for estates where the control plane may not leave the tenant's network, and for bootstrapping Gardener itself. | "there is sufficient pull to also find a way to create self-hosted shoot clusters using Gardener (e.g., for the edge or for temporarily air-gapped scenarios) where the control plane must run side-by-side and cannot run in seed clusters"; "so far there was no way of setting up or managing this initial cluster via Gardener itself. It was always required to leverage third-party tools or services, which is not only inconvenient but also somewhat paradoxical"; "This shall not be a drop-in replacement for k3s or kubeadm". |
| 22 | Gardener | GEP-31, in-place node updates | adr | in releases from v1.112.0 (2025-02-07) | 2026-10-01 | https://raw.githubusercontent.com/gardener/enhancements/main/geps/0031-inplace-node-updates/README.md | Rolling replacement assumes interchangeable machines; bare metal and scarce virtual machine types, GPUs named, break that assumption. | "Long boot times"; "Locally attached storage"; "this process also presents challenges for virtual machines, e.g. if the virtual machine type is scarce (in general or because of an ongoing capacity crunch) or if certain scarce resources are connected/attached, e.g. GPUs". |
| 23 | Gardener | GEP-5, Gardener versioning policy | adr | in releases from v1.0.0 | 2026-10-01 | https://raw.githubusercontent.com/gardener/enhancements/main/geps/0005-versioning-policy/README.md | The upstream cadence the fleet absorbs, and the four classifications a version moves through; control plane and workers stay on the same version. | "The Kubernetes community releases minor versions roughly every three months and usually maintains three minor versions (the actual and the last two) with bug fixes and security updates."; "Gardener keeps the control plane and the workers on the same Kubernetes version." |
| 24 | Gardener | GEP-32, version classification lifecycle | adr | gardener/enhancements, current | 2026-10-01 | https://raw.githubusercontent.com/gardener/enhancements/main/geps/0032-version-classification-lifecycle/README.md | Version expiry is declarative and scheduled, because moving versions through stages by hand does not scale, and a classification that disagrees with an expiry date is confusing. | "Typically, administrators move a version through the classification stages manually over time."; "manually moving versions through the stages is cumbersome, so there should be a way for administrators to define an entire version lifecycle"; "it is confusing that the classification pretends to be for example supported or deprecated while the expiration date marks it as expired". |
| 25 | Gardener | GEP-35, observability 2.0, VictoriaLogs | adr | in releases from v1.132.0 (2025-11-13) | 2026-10-01 | https://raw.githubusercontent.com/gardener/enhancements/main/geps/0035-observability2.0-victorialogs/README.md | A licence change pushed the fleet onto a fork, and the fork's stagnation is what forced the next migration; standardising collection first made the store swappable. | "Since version v2.3.0, Loki has switched from the Apache-2.0 license to a significantly more restrictive AGPLv3 license. Since then, the Observability stack of Gardener has been using Vali - a fork of Loki 2.2.1 ... However, the fork maintains only security updates, thus leading to no new features or improvements getting integrated." |
| 26 | Gardener | Relation between the Gardener API and Cluster API | adr | gardener/gardener v1.152.0 | 2026-10-01 | https://raw.githubusercontent.com/gardener/gardener/v1.152.0/docs/concepts/cluster-api.md | The standing reason for not adopting the upstream fleet API: it standardises the request, not the result. | "Cluster API primarily harmonizes how to get to clusters, while Gardener goes a significant step further by also harmonizing the clusters themselves."; "you cannot simply swap provider: foo with provider: bar in a CAPI manifest and expect it to work"; "The CAPI provider for GKE states: 'Provisioning managed clusters (GKE) is an experimental feature...'". |
| 27 | Gardener | Feature gates | source | gardener/gardener v1.152.0 | 2026-10-01 | https://raw.githubusercontent.com/gardener/gardener/v1.152.0/docs/deployment/feature_gates.md | A dated record of every mechanism adopted and withdrawn: the adopted upstream tunnel ran alpha from release 1.6 and was removed in 1.27; the in-house fused autoscaler ran alpha from 0.31 and was removed in 1.109. | Table rows: "KonnectivityTunnel | false | Alpha | 1.6 | 1.26" then "Removed | 1.27"; "HVPA | false | Alpha | 0.31 | 1.105", "Deprecated | 1.106 | 1.108", "Removed | 1.109". |
| 28 | Gardener | Feature gates, counted | source | gardener/gardener v1.152.0 | 2026-10-01 | https://raw.githubusercontent.com/gardener/gardener/v1.152.0/docs/deployment/feature_gates.md | Derived by parsing the table in this session: 69 distinct feature names, 39 of which carry a general-availability row; median alpha to general availability is 15 minor releases, about 225 days, and the slowest took 57 releases and 904 days. | Method: parse all table rows into (feature, stage, since, until); map each minor version to its release date from the module proxy; median over features having both an Alpha and a GA row. The table does not distinguish a gate removed because a feature became unconditional from one removed because the feature was withdrawn, so no aggregate withdrawal count is claimed. |
| 29 | Gardener | Example gardenlet component configuration | source | gardener/gardener v1.152.0 | 2026-10-01 | https://raw.githubusercontent.com/gardener/gardener/v1.152.0/example/20-componentconfig-gardenlet.yaml | The default packing ratio of the architecture is a line of shipped configuration: 200 tenant clusters per host cluster. | resources: capacity: shoots: 200 |
| 30 | Gardener | etcd concept | source | gardener/gardener v1.152.0 | 2026-10-01 | https://raw.githubusercontent.com/gardener/gardener/v1.152.0/docs/concepts/etcd.md | Each tenant gets two etcd instances, split by the value of the data, each with a backup and housekeeping sidecar writing to object storage. | "the critical etcd-main is not flooded by Kubernetes Events, as well as backup space is not occupied by non-critical data"; "Both etcd instances are configured to run with a special backup-restore sidecar"; "The sidecar also performs defragmentation and other house-keeping tasks." |
| 31 | Gardener | Istio operations | source | gardener/gardener v1.152.0 | 2026-10-01 | https://raw.githubusercontent.com/gardener/gardener/v1.152.0/docs/operations/istio.md | A large dependency adopted for exactly one function, with the unused parts refused in configuration. | "The default profile which is recommended for production deployment, is not suitable for the Gardener use case, as it offers more functionality than desired."; "Telemetry is not deployed."; "Istio injector is not enabled."; "istio-egress-gateway is not deployed." |
| 32 | Gardener | Releases, features, hotfixes | source | gardener/gardener v1.152.0 | 2026-10-01 | https://raw.githubusercontent.com/gardener/gardener/v1.152.0/docs/development/process.md | The cadence target, the hotfix window, and a named release rota through late 2026. | "The @gardener-maintainers are trying to provide a new release roughly every other week"; "Hotfixes are usually maintained for the latest three minor releases"; rota table rows from v1.140 (validation from March 30, 2026) to v1.153 (due October 11, 2026). |
| 33 | Gardener | Dependency watchdog, prober concept | source | gardener/dependency-watchdog, current | 2026-10-01 | https://raw.githubusercontent.com/gardener/dependency-watchdog/master/docs/concepts/prober.md | The platform's own node-replacement logic is the dangerous actor when the heartbeat path breaks, so a second probe disables it. The document states the scenario, the two probes, the threshold and the annotation. | "As an example, consider a large shoot cluster with several hundred nodes. There is an issue with a NAT gateway on the shoot cluster which prevents the Kubelet from any node in the shoot cluster to reach its control plane Kube ApiServer."; "it will begin to replace the unhealthy machine(s) with new ones"; "This replacement of healthy machines due to a broken connectivity ... results in undesired downtimes for customer workloads that were running on these otherwise healthy nodes."; annotation dependency-watchdog.gardener.cloud/meltdown-protection-active. |
| 34 | Gardener | Dependency watchdog README | source | gardener/dependency-watchdog, current | 2026-10-01 | https://raw.githubusercontent.com/gardener/dependency-watchdog/master/README.md | The component exists to prevent cascading failure by scaling dependants down, and its scope is still one use case. | "A watchdog which actively looks out for disruption and recovery of critical services. If there is a disruption then it will prevent cascading failure by conservatively scaling down dependent configured resources"; "the Prober is tailored to handle one such use case of kube-apiserver connectivity". |
| 35 | Gardener | Enhancements repository README | adr | gardener/enhancements, current | 2026-10-01 | https://raw.githubusercontent.com/gardener/enhancements/main/README.md | The decision records moved out of the code repository into their own, governed by a technical steering committee and modelled on the upstream enhancements process. | "This repository contains Gardener Enhancement Proposals (GEPs) - design and proposal documents for changes that are relevant at the project-wide level and require discussion and decision-making in Gardener's Technical Steering Committee (TSC)."; "The structure and intent of this repository are inspired by kubernetes/enhancements". |
| 36 | Go module proxy | Version list and tag timestamps for github.com/gardener/gardener | source | queried 2026-10-01 | 2026-10-01 | https://proxy.golang.org/github.com/gardener/gardener/@v/list | 759 published versions; v0.32.0 dated 2019-11-29, v1.0.0 dated 2020-02-06, v1.152.0 dated 2026-09-24, so 152 minor releases in about 2,422 days, one every 16 days. | {"Version":"v1.0.0","Time":"2020-02-06T11:58:50Z"}; {"Version":"v0.32.0","Time":"2019-11-29T15:23:33Z"}; list contains 759 entries, 15 of them on the 0.x line. |
| 37 | pkg.go.dev | Version history for github.com/gardener/gardener | source | queried 2026-10-01 | 2026-10-01 | https://pkg.go.dev/github.com/gardener/gardener?tab=versions | Release cadence has not slowed in seven years: releases listed per year are 49 (2020), 70, 77, 79, 75, 92 (2025) and 79 by October 2026. | Parsed from the versions tab; minor-version spans per year run 1.0 to 1.15 in 2020 and 1.132 to 1.152 in 2026. |
| 38 | Google Cloud | Google Kubernetes Engine pricing | vendor | current page | 2026-10-01 | https://cloud.google.com/kubernetes-engine/pricing | The market price for one managed control plane, and a price attached to falling behind on versions. | "A flat cluster management fee of $0.10 per cluster per hour (charged in 1 second increments) applies to all GKE clusters irrespective of the mode of operation, cluster size, or topology."; "The GKE extended period cluster management fee is in addition to the GKE cluster management fee at $0.10 per cluster per hour, for a total of $0.60 per cluster per hour." |
| 39 | Gardener | Release archive comparison, v1.0.0 against v1.152.0 | source | archives dated 2020-02-06 and 2026-09-24 | 2026-10-01 | https://proxy.golang.org/github.com/gardener/gardener/@v/v1.0.0.zip | What was dropped: the add-on charts that shipped cluster extras (including a chart coupling Gardener to another SAP product) left after release 1.8.0 (2020-08-05), and the bundled seed monitoring chart after 1.14.0 (2020-12-09). | Directory charts/shoot-addons-kyma/ present at v1.8.0, absent at v1.9.0 (2020-08-25); charts/seed-monitoring/ present at v1.14.0, absent at v1.15.0 (2021-01-04). Established by downloading both archives and by bisecting tags with raw file requests. |
| 40 | Gardener | GEP-34, observability 2.0, OpenTelemetry operator and collectors | adr | in releases from v1.132.0 (2025-11-13) | 2026-10-01 | https://raw.githubusercontent.com/gardener/enhancements/main/geps/0034-observability2.0-opentelemetry/README.md | Collection was standardised on an open protocol before the storage engine was replaced, and the migration was explicitly phased rather than a flag day. | "Gardener's current observability stack, while improved by the operator-based approach in GEP-19, still relies on vendor specific format and protocols for collecting, processing and storing observability signals"; non-goal: "This proposal does not aim to immediately decommission tools like Vali, Fluent-bit, or Prometheus; the migration will be phased." |
Sources located but not reachable in this session
The egress proxy refused these hosts, each of which would have added evidence the page now lacks:
gardener.cloud and its adopters page (operator identities and fleet scale), blogs.sap.com and
kubernetes.io (the 2018 "Gardener, the Kubernetes Botanist" and 2019 project-update posts written
by the engineers, both linked from the README), youtube.com (the EclipseCon talk the README cites),
github.com and api.github.com (issues and pull requests, including the rejected approaches and
the issue threads the GEPs reference by number), and every status page. A reader with wider network
access should start with those three engineering accounts, because they are the only places where
SAP has stated its own operated scale.