Changes and Releases
Updates on Giant Swarm workload cluster releases, apps, UI improvements and documentation changes.
Changed
- Make the
--organization flag visible when templating App CR.
Fixed
kubectl-gs login: listen only on localhost for callbacks
This version contains fixes for HTTP/2 stream reset attacks (CVE-2023-44487).
Changes
- Align with upstream chart version 2.29.0 (Changes in upstream repository)
- Update kong to 3.4.2
- Update kong ingress controller to 2.12.0
- Execute enterprise tests with kong-gateway container image version 3.4.1.1-debian
- Add
Values.global.podSecurityStandards.enforced flag in preparation of PSP to PSS migration - Prevent installation of PodDisruptionBudget with
replicaCount: 1 or autoscaling.minReplicas: 1
This version contains fixes for HTTP/2 stream reset attacks (CVE-2023-44487).
Changes
- Align with upstream chart version 2.29.0 (Changes in upstream repository)
- Update kong to 3.4.2
- Update kong ingress controller to 2.12.0
- Execute enterprise tests with kong-gateway container image version 3.4.1.1-debian
- Add
Values.global.podSecurityStandards.enforced flag in preparation of PSP to PSS migration - Prevent installation of PodDisruptionBudget with
replicaCount: 1 or autoscaling.minReplicas: 1
Changed
- Upgraded upstream chart from 5.26.0 to 5.29.0 - see changelog for more information.
Changed
- Upgraded upstream chart from 5.26.0 to 5.29.0 - see changelog for more information.
Changed
- prometheus remote-writes: filter on URL
Added
- Controller: Add
controller.enableAnnotationValidations. (#536) - OpenTelemetry: Add
controller.opentelemetry.resources. (#536) - Values: Add
global.podSecurityStandards.enforced. (#544)
Changed
- Image: Update to
v1.9.0. (#536) - Deployment/DaemonSet: Make
controller.topologySpreadConstraints an array. (#536)
NOTE: This is part of our alignment to upstream. Please convert any overrides of controller.topologySpreadConstraints to an array, too. - Tests: Upgrade dependencies & remove explicit ATS version. (#538)
- Service: Fix wildcard subdomain. (#539)
- Chart: Tighten
securityContexts and Pod Security Policies. (#540) - OpenTelemetry: Use own registry. (#541)
- Admission Webhooks: Update
kube-webhook-certgen image to v20231011-8b53cabe0. (#542) - Image: Update to
v1.9.3. (#547)
Removed
- Controller: Drop support for
controller.kind: Both. (#547)
Added
- Controller: Add
controller.enableAnnotationValidations. (#536) - OpenTelemetry: Add
controller.opentelemetry.resources. (#536) - Values: Add
global.podSecurityStandards.enforced. (#544)
Changed
- Image: Update to
v1.9.0. (#536) - Deployment/DaemonSet: Make
controller.topologySpreadConstraints an array. (#536)
NOTE: This is part of our alignment to upstream. Please convert any overrides of controller.topologySpreadConstraints to an array, too. - Tests: Upgrade dependencies & remove explicit ATS version. (#538)
- Service: Fix wildcard subdomain. (#539)
- Chart: Tighten
securityContexts and Pod Security Policies. (#540) - OpenTelemetry: Use own registry. (#541)
- Admission Webhooks: Update
kube-webhook-certgen image to v20231011-8b53cabe0. (#542) - Image: Update to
v1.9.3. (#547)
Removed
- Controller: Drop support for
controller.kind: Both. (#547)
Changed
- Image: Update to
v1.8.4. (#545) - Tests: Upgrade dependencies & remove explicit ATS version. (#538)
Changed
- Image: Update to
v1.8.4. (#545) - Tests: Upgrade dependencies & remove explicit ATS version. (#538)