Connectivity
Changed
- Update kong ingress controller to 3.4.1
- Align with upstream chart version 2.46.0 (Changes in upstream repository)
- Revert
ingressController.admissionWebhook settings to upstream values. (Enabled by default with failurePolicy: Ignore) - Update Kong Gateway image to
3.8.1.0-debian - Execute CRD installation Job only if ingressController is enabled (
ingressController.enabled)
Removed
- Keep PSP disabled by default and remove Giant Swarm PSP-PSS migration hacks
- Legacy Giant Swarm metrics Service and labels
Changed
- Chart: Sync to upstream. (#760)
- Controller: Update image to v1.11.4.
- Kube Webhook CertGen: Update image to v1.5.0.
Changed
- Update
coredns image to 1.11.4. - Explicitly expose liveness and readiness probe ports in deployments.
Removed
- Remove PodSecurityPolicy and associated Resources and values.
Changed
- Chart: Sync to upstream. (#741)
- Controller: Update image to v1.11.3.
- Kube Webhook CertGen: Update image to v1.4.4.
- Chart: Implement
controller.admissionWebhooks.service.servicePort. - Chart: Rework ServiceMonitor.
- Chart: Align default backend
PodDisruptionBudget. - Chart: Specify
matchLabelKeys in Topology Spread Constraints.
Changed
- Update
coredns image to 1.11.3.
Removed
- Removed legacy Giant Swarm monitoring labels as coredns is monitored through a prometheus-operator generated servicemonitor.
Changed
- Chart: Sync to upstream. (#687)
- Controller: Update image to v1.11.2.
- OpenTelemetry: Update image to v20240813-b933310d.
- Kube Webhook CertGen: Update image to v1.4.3.
Removed
- Chart: Sync to upstream. (#687)
- Helpers: Remove useless
isControllerTagValid.
Fixed
- Fix Cilium pod being restarted too soon – instead of every 15 minutes – in case of failed regeneration recovery. This was because creation date parsing failed.
Added
- Chart: Sync to upstream. (#687)
- Chart: Explicitly set
runAsGroup.