Highlights for the week ending June 01 2023
General
Nothing to be announced
Nothing to be announced
Nothing to be announced
flux-system
, flux-giantswarm
) have been upgraded to Flux v0.41.2.PolicyException
allowing falco to run in clusters enforcing restricted
Pod Security Standards, and replaces a deprecated toleration label.PolicyExceptions
may be created. By default, customer exceptions may be created only in the policy-exceptions
namespace.security-pack
has been renamed to security-bundle
to align its naming with our other bundles and keep our terminology consistent.security-pack
. Please review the instructions in the README prior to attempting to upgrade. This release includes the following noteworthy changes, as well as the App updates described in this announcement.security-pack
App has been renamed to security-bundle
.security-bundle
must be installed from the giantswarm
catalog. It will no longer be published to playground
.security-pack
to security-bundle
. Custom installation namespaces are unaffected by this change.kyverno-policies
has been renamed to kyvernoPolicies
. App value overrides for the kyverno-policies
App must now be made under the kyvernoPolicies
key.starboard-app
has been removed and is no longer installable from the security-bundle
. Trivy Operator is installed by default and is a full replacement of Starboard. (starboard-exporter
is still actively supported).PolicyException
permitting Falco to run in clusters enforcing restricted
Pod Security Standards.AdmissionReport
processing speed and reduce the number of reports stored in the cluster.giantswarm
catalog.node-role.kubernetes.io/control-plane
to the toleration of CRD install jobs. This update also contains the addition of ServiceMonitor
and the addition of default values that were released in version 2.34.0chart.yaml
has been aligned with upstream too. Last but not least, we removed some helpers and deployment properties not needed after the restructuring work. So, please be aware that some of these changes, additions or removals can require modifications from you. We encourage you to read the changelog for not to miss any information.v0.37.2
, containing various bug fixes and additional support for future scanning features.To satisfy requirements that expand beyond Kubernetes, we now offer Crossplane as a managed solution. This is currently experimental and is known to cause potentially critical performance issues with the cluster it’s running on. With this in mind, whilst we encourage you to experiment with it, we advise you to discuss this with your account engineer prior to installation.
PriorityLevelConfiguration
for the operator so it can handle concurrency edge cases better.2.12.4
fixes a memory leak in the destination controller, and also includes other bug fixes for the Linkerd control plane, CLI, and extensions. More information here. All dependent components have been upgraded too:This part of our documentation refers to our vintage product. The content may be not valid anymore for our current product. Please check our new documentation hub for the latest state of our docs.