Highlights for the week ending October 10 2023
Apps
security-bundle versions 1.1.0 and 0.18.0 With these two releases we include two new tools supporting migration away from Pod Security Policies, exception-recommender
and kyverno-policy-operator
. With exception-recommender
analyzes the current policy reports in a cluster get analyzed and based on the results a Giant Swarm PolicyExceptionDrafts
gets generated. Once the drafts have been reviewed and accepted, kyverno-policy-operator
takes the resulting Giant Swarm PolicyExceptions
and generates the necessary Kyverno resources to allow workloads to continue running.
Documentation
We have started the migration away from Pod Security Policies! Therefore we have added a cluster administrator migration guide containing all information about the new Policy API and all the assistive tooling available to help you securely migrate workloads off of PSPs. Reach out for any questions regarding the Pod Security Policies to Pod Security Standards migration