Changed
- Updates Cert-manager Chart to Upstream 1.16.2
Added
- Adds new sync method based on Vendir to sync from upstream
Updates on Giant Swarm workload cluster releases, apps, UI improvements and documentation changes.
This release fixes fetching of unsupported infrastructure cluster identity resources. See ./docs/releases/v0.49.2-changelog.md for more information.
This release fixes clusters fetching for unsupported providers. See ./docs/releases/v0.49.1-changelog.md for more information.
ingressController.admissionWebhook
settings to upstream values. (Enabled by default with failurePolicy: Ignore
)3.8.1.0-debian
ingressController.enabled
)ingressController.admissionWebhook
settings to upstream values. (Enabled by default with failurePolicy: Ignore
)3.8.1.0-debian
ingressController.enabled
)In this release:
RELEASE
column was added to clusters list;LOCATION
column was added to clusters list;AWS ACCOUNT ID
column was added to clusters list.
See ./docs/releases/v0.49.0-changelog.md for more information.Most notable change in this release is the reduction of IAM permissions on the worker nodes instance profile, aiming at improving the general security of the clusters. Additional changes include reducing the size of the ETCD volume to 50GB targetting costs saving initiatives, as well as improvements for the node-termination-handler
application for smoother upgrades and operations.
global.providerSpecific.reducedInstanceProfileIamPermissionsForWorkers
.aws-node-termination-handler-app
as environment variablesMost notable change in this release is the reduction of IAM permissions on the worker nodes instance profile, aiming at improving the general security of the clusters. Additional changes include reducing the size of the ETCD volume to 50GB targetting costs saving initiatives, as well as improvements for the node-termination-handler
application for smoother upgrades and operations. Several components such as Flatcar or Kubernetes have also been updated to the latest available versions.
global.providerSpecific.reducedInstanceProfileIamPermissionsForWorkers
.aws-node-termination-handler-app
as environment variablessecurityContext
to be compliant.Note: When upgrading to this security-bundle version with Falco enabled, the Falco App will fail to upgrade due to a breaking change in the upstream chart. To finish the upgrade, disable, then re-enable the Falco App by setting apps.falco.enabled=[false|true]
in the security-bundle user values Config Map.
trivy-operator
(app) to v0.10.3.trivy
(app) to v0.13.1.kyverno
(app) to v0.18.1.kyverno-crds
(app) to v1.12.0.kyverno-policies
(app) to v0.21.0.starboard-exporter
(app) to v0.8.0.falco
(app) to v0.9.1.Note: When upgrading to this security-bundle version with Falco enabled, the Falco App will fail to upgrade due to a breaking change in the upstream chart. To finish the upgrade, disable, then re-enable the Falco App by setting apps.falco.enabled=[false|true]
in the security-bundle user values Config Map.
trivy-operator
(app) to v0.10.3.trivy
(app) to v0.13.1.kyverno
(app) to v0.18.1.kyverno-crds
(app) to v1.12.0.kyverno-policies
(app) to v0.21.0.starboard-exporter
(app) to v0.8.0.falco
(app) to v0.9.1.This part of our documentation refers to our vintage product. The content may be not valid anymore for our current product. Please check our new documentation hub for the latest state of our docs.