Continuous Deployment

  • Changed

    • Update PolicyExceptions to v2beta1.
    • Set the location of the notificaton-controller to the namespace it’s currently running in.
  • Fixed

    • Fix resource labelling from giantswarm.io/service_type to giantswarm.io/service-type.
  • Changed

    • Bump generated sources and kustomizations to v1.
  • Added

    • Add pod monitors to controllers. Creation is controlled by the .podMonitors.enabled Helm value with default: true.

    Removed

    • Removed {{ .Release.Name }}-monitoring service that was used in the old monitoring stack.
  • Added

    • Added support for .global.podSecurityStandards.enforced Helm value (defaults to false) to control PSP creation when. When the flag is disabled (default) the PSS is created and the crd-controller ClusterRole is updated with the permission to use the created (flux-app-pvc-psp) PSP. Pre kubernetes v1.25 upgrade and on v1.25 clusters where PSPs are no longer available, this flag should be enabled to skip the creation of the PSP and the update to the CLusterRole.
    • Added support for .policyException.namespace Helm value to control where Kyverno PolicyException is created, defaults to: giantswarm
    • Added support for .cilium.enforce Helm value (defaults to false) to force creation of the Cilium network policy in cases when Helm capability checks are not available.
    • Added support for .policyException.enforce Helm value (defaults to false) to force creation of the Cilium policy in cases when Helm capability checks are not available.

    Changed

    • Refactored chart upgrade process from kustomzie + manual based to be git patch based and made the templates structure better for readability.

    Fixed

    • Fix notification-controller endpoint in kustomize-controller deployment settings to point to the controller in the same namespace.

    Removed

    • Removed app.kubernetes.io/part-of: flux labels from upstream resources
    • Removed app.kubernetes.io/version: ... labels from upstream resources
    • Removed app.kubernetes.io/component: ...-controller labels from upstream resources
    • Updgrade Flux to 2.1.2 and preare it for Kubernetes 1.25
  • Changed

    • Configure gsoci.azurecr.io as the default container image registry.
  • Added

    • Add Kyverno PolicyException.
  • Changed

This part of our documentation refers to our vintage product. The content may be not valid anymore for our current product. Please check our new documentation hub for the latest state of our docs.