Fleet Management
Changed
- Change node selector from
managed-by
to karpenter.sh/registered
.
Changed
- Chart: Update Helm release vertical-pod-autoscaler to v10.0.1. (#346)
Changed
- Align
template cluster
command --name
argument validation with Cluster naming.
Removed
- Get rid of legacy in-house slo framework.
Changed
- Set home URL in chart metadata.
Changed
- Add organisation namepsace to the gitops add command.
- Update
github.com/getsops/sops/v3
from v3.9.2 to v3.9.3.
Removed
- Removed any code specific to KVM installations.
Changed
- Update to
project-zot/helm-charts
version 0.1.67
. - Bump default
zot
image tag to v2.1.2
.
Added
- Add supplemental security and best practices policies:
check-resources-request-and-limits-ratio
check-serviceaccount-secrets
disallow-gitrepo-volume
disallow-latest-tag
prevent-bare-pods
require-container-requests-and-limits
require-emptydir-requests-and-limits
require-pod-probes
restrict-binding-clusteradmin
restrict-binding-system-groups
restrict-sa-automount-sa-token
Changed
- Update to upstream
Kyverno Policies
version 1.13.4.
Added
- Add supplemental policies
restrict-external-ips
, require-ro-rootfs
, and enable upstream policy require-non-root-groups
. - Add supplemental policy to generate default deny-all Network Policies in newly created namespaces.
Changed
- Chart: Update Helm release vertical-pod-autoscaler to v10.0.0. (#335)
Changed
- Chart: Update Helm release vertical-pod-autoscaler to v9.9.1. (#333)