Skip to content

Compatibility

This page lists the versions CAPTF is built against and what it needs from its environment. It separates what is tested from what is assumed, because CAPTF is pre-alpha and has never run against a live management cluster. The numbers come from the repository at the time of writing (go.mod, metadata.yaml, the Makefile and the noop module images), so check them against the tag you install.

Versions

Component Version Source
Go 1.26 (toolchain go1.26.8) go.mod, Makefile
Cluster API v1.14.2 (the Go module the controllers build against) go.mod
Cluster API contract v1beta2 metadata.yaml, the CRD label
controller-runtime v0.24.1 go.mod
Kubernetes client libraries v0.36.3 (k8s.io/api, apimachinery, client-go) go.mod
CAPTF release series 0.1 (none published) metadata.yaml
CAPTF API and module contract v1alpha1, provisional the CRDs, contract
cert-manager cert-manager.io/v1 API required; no minimum release stated Installation
Terraform Any 1.x with the CLI surface below; modules require >= 1.5 image contract
OpenTofu Any 1.x with the same surface; modules require >= 1.5 the same
Terraform in the noop images 1.16.4, pinned by digest noop-modules Dockerfile.terraform
OpenTofu in the noop images 1.12.6, pinned by digest noop-modules Dockerfile.opentofu
State file format Version 4 only the state reader
Architectures linux/amd64 and linux/arm64 image builds the Makefile’s PLATFORMS

Kubernetes

CAPTF links the Kubernetes client libraries at v0.36, which corresponds to Kubernetes 1.36. It does not state a supported server range. The other bounds are Cluster API’s own: the management cluster must run a Cluster API release that implements contract v1beta2. Treat Kubernetes 1.36 as the version it is built for and anything else as unverified; the features it uses are standard (Jobs, Leases, Secrets, validating webhooks, SubjectAccessReview).

The runtime CLI

The module image supplies the terraform or tofu binary at /captf/runtime. CAPTF needs the 1.x CLI surface version, init, validate, plan, apply, destroy, force-unlock, show and state push/state list. It does not check a minimum version. The reference modules declare required_version = ">= 1.5", because they use terraform_data and plantimestamp(). CAPTF reads the state through the Kubernetes backend and only accepts state file version 4. OpenTofu client-side state encryption is unsupported. See Image Contract and Runtime Environment.

Cluster API providers

CAPTF is an infrastructure provider. Pairing it with a control-plane and bootstrap provider is covered by Control-Plane Integration: KubeadmControlPlane and RKE2ControlPlane are the documented ones. That documentation is derived from those providers’ contracts, not from a live run.

What is tested

The continuous-integration workflow runs these on every push:

Check Covers
make test-cover and make cover-check Unit tests of the controllers, runner, webhooks, linter and libraries, against fake clients, with per-package coverage floors
make lint and make vet Go lint, API lint, and go vet, including the e2e-tagged test code
The verify targets Generated files are current, component manifests, templates, JSON schemas, metadata.yaml append-only, the local clusterctl repository layout, licenses and the Prometheus rules (promtool check and tests)

The workflow also builds every binary and takes a tfcapi-lint release snapshot. It does not run the end-to-end suites: make e2e-foundation and make e2e-noop run them on a local kind cluster that pulls the published no-op images, and you run them yourself. The docs checks and the release flow are also outside the workflow.

What is assumed

Nothing below has been exercised against a live system

Treat every item in this list as unverified.

  • A real management cluster. No clusterctl init, upgrade or move has run end to end; the move behavior is derived from the code and clusterctl’s documented rules.
  • Real Terraform or OpenTofu execution under CAPTF. The runner is unit tested against recorded plan and state JSON. Other versions of the runtime than the pinned noop ones are assumed to behave.
  • Real infrastructure providers. The noop modules create no cloud resources, and no module that does has been run under CAPTF in CI.
  • Kubernetes server versions other than 1.36, cert-manager releases, and Cluster API releases other than the one built against.
  • The arm64 image. It is built by the Makefile; no CI job runs it.
  • KubeadmControlPlane and RKE2ControlPlane integration. Documented against their contracts; not run.

If you find a version that works or does not, that is the information this page needs. See Known Limitations and the project status.