Fleet Management
Changed
Drop all CAPabilities in container SecurityContext for Kyverno Policy compliance- Set
AllowPrivilegeEscalation=false in container SecurityContext for Kyverno Policy compliance
Fixed
- Added
projected volume type to csi-node PSP to allow the user of IRSA.
Added
- Annotation for EBS Volumes for Logging, Docker and Containerd.
Changed
- Use non-exp apiVersion for azure machine pool types in
template nodepool.
Fixed
- Setting
spec.config.configMap in app/<cluster-name>-default-apps for CAPZ clusters.
Changed
- Add support for
--proxy and --proxy-port flags to login cmd to enable proxy-url: socks5://localhost:9000 in the cluster section of the configuration added to kubeconfig- This is only supported for
clientcert Workload Clusters
Added
- Add team label to deployment.
Changed
- Drop alert threshold for
CephClusterNearFull from 80% down to 75%.
Changed
- Stop using old
v1alpha3 version when using CAPI CRDs.
Changed
- Remove circleci job for pushing to shared app collection