RATATOSKRATATOSK
Sign in

Crossplane

v2.2.0Orchestration & Management
Feb 17, 2026

ACTION 7CHECK 2OTHER 41

Crossplane v2.2.0 changes package installation and package-cache behavior, including a break in undocumented package side-loading. It also adds operator and function capabilities, updates dependencies identified in the release as security fixes, and includes defect corrections.

Action needed (7)

  • securityUpdated golang.org/x/crypto module

    The golang.org/x/crypto module is updated to v0.45.0 in this release.

  • securityUpdated github.com/go-chi/chi/v5 module

    The github.com/go-chi/chi/v5 module is updated to v5.2.4 in this release.

  • securityUpdated github.com/sigstore/cosign/v3 module

    The github.com/sigstore/cosign/v3 module is updated to v3.0.4 in this release.

  • securityUpdated github.com/theupdateframework/go-tuf/v2 module

    The github.com/theupdateframework/go-tuf/v2 module is updated to v2.4.1 in this release.

  • securityUpdated github.com/sigstore/rekor module

    The github.com/sigstore/rekor module is updated to v1.5.0 in this release.

  • securityUpdated github.com/sigstore/sigstore module

    The github.com/sigstore/sigstore module is updated to v1.10.4 in this release.

  • securityUpdated github.com/quic-go/quic-go module

    The github.com/quic-go/quic-go module is updated to v0.57.0 in this release.

Check if affected (2)

  • breakingInput CRDs in Function packages are no longer installed

    Applies if you use Input CRDs in Function packages.

    Input CRDs included in Function packages are no longer installed by the package manager.

  • breakingThe package cache on-disk structure has changed

    Applies if you side-load packages into Crossplane through the package cache.

    The on-disk structure of the package cache has changed. This breaks the undocumented behavior that allowed packages to be side-loaded into Crossplane.

All 41 other recorded changesadditions 13 · value changes 13 · fixes 8 · constraints 7

additions (13)

  • ImageConfig can now be used to configure the DeploymentRuntimeConfig used for packages, including those installed as dependencies.
  • The pipeline inspector is now available as an alpha feature (disabled by default). When enabled, the inspector forwards function requests and responses to a user-configured gRPC endpoint for debugging or observability.
  • functions can now request OpenAPI schemas for any resource kind in the cluster using the RequiredSchemas field in the function response.
  • Crossplane now advertises capabilities (including required schemas) to functions in a new function request field.
  • Add option to prevent events from being emitted in default namespace
  • Allow configuring custom annotations on Crossplane helm chart secret resources
  • feat: Support list of resources for crossplane beta trace
  • Add sidecar container support to Crossplane Helm chart
  • feat(helm): Set automountServiceAccountToken on service accounts
  • Add an option to prevent caching of resources in other namespaces
  • feat: add defaultCompositionRevisionSelector for v1 and v2 APIs
  • feat(trace): add watch for trace
  • Use --watched-resource flag for WatchOperations

value changes (13)

  • v1.20 will continue to receive critical fixes. The final EOL date for v1.20 is to be determined.
  • a matching ImageConfig takes precedence over the runtimeConfigRef in a package spec if both are present.
  • The MRD controller now uses server-side apply to update CRDs, improving reliability.
  • fix(deps): update module google.golang.org/protobuf to v1.36.11
  • fix(deps): update module github.com/sirupsen/logrus to v1.9.4
  • fix(deps): update module github.com/emicklei/dot to v1.10.0
  • fix(deps): update module github.com/go-git/go-billy/v5 to v5.7.0
  • fix(deps): update module github.com/go-git/go-git/v5 to v5.16.4
  • fix(deps): update module github.com/docker/go-connections to v0.6.0
  • fix(deps): update module github.com/in-toto/in-toto-golang to v0.10.0
  • feat(install.sh): download and unpack the compressed file
  • Use foreground cascading deletion for unneeded composed resources
  • deps: Update crossplane-runtime to v2.2.0

fixes (8)

  • Fix XR circuit breaker to account for double token consumption
  • Fix claim controller watch startup after transient failures
  • fix: Add TLS as app protocol to function service
  • pkg: Fix upgrading packages with common transitive dependencies
  • fix(fn-cache): prevent caching responses with unfulfilled requirements
  • fix: improve errors for malformed xpkg examples
  • fix: exclude ClusterProviderConfigUsages from CRD to MRD conversion
  • fix: check correct condition in package reconciler

constraints (7)

  • Unknown or disallowed resources in a package are now ignored instead of causing package installation to fail.
  • XRDs can now configure x-kubernetes-validations outside of the spec.
  • Fix Docker port binding race condition on macOS by using HostPort "0"
  • add yaml support to render --context-files and --context-values flag
  • Add Cosign v3 support
  • Handle CronOperation and WatchOperation in alpha render op
  • feat(helm): make sidecars, extra volumes, and volume mounts templatable
Add Crossplane to your stack

A weekly email arrives when a release needs action. Like the security patches and breaking changes in this release.

Add to stack