Connectivity
Changed
- Reduce security exceptions #89.
- Enable readOnly FS moving config to emptyDir volume.
- Remove
NET_ADMIN and drop ALL capabilities. - Add
NET_BIND_SERVICE capability. - Add policy exception for
require-non-root-groups/autogen-check-runasgroup. - Remove disallow-capabilities-* policy exceptions.
Changed
- Deployments/DaemonSets: Make pod affinity templatable. (#654)
- ServiceMonitor: Relabel app & node. (#654)
Changed
- Update PolicyException CR version to v2beta1.
Added
- Ingress Class: Make annotations configurable. (#639)
- Admission Webhook: Make patch job RBAC configurable. (#639)
- Default Backend: Add topology spread constraints. (#639)
Changed
- Chart: Require Kubernetes version >= 1.21.0-0. (#639)
- Config Map: Support templates in values. (#639)
- Service: Fix app protocol semver comparison. (#639)
- Admission Webhook: Update patch job image to
v1.4.1. (#639) - Default Backend: Reorder HPA. (#639)
Changed
- Do not perform actions while there are cordoned nodes
- In case of failed regeneration recovery, only restart the Cilium pod if it’s older than 15 minutes
Changed
- Upgrade Gateway API CRDs to v1.1.0
Changed
- Update kong ingress controller to 3.1.4