Added
- Made GraphQL introspection configurable and disabled by default
Changed
- Change ImagePullPolicy from Always to IfNotPresent to reduce image network traffic.
Updates on Giant Swarm workload cluster releases, apps, UI improvements and documentation changes.
devctl
organization/namespace
deletiondevctl
organization/namespace
deletionFalco
chart version from 3.8.1
to 4.6.1
.Falco-exporter
chart version from 0.9.9
to 0.11.0
Falcosidekick
chart version from 0.7.5
to 0.8.2
Falco
to upstream version 0.38.1
.Falco
chart version from 3.8.1
to 4.6.1
.Falco-exporter
chart version from 0.9.9
to 0.11.0
Falcosidekick
chart version from 0.7.5
to 0.8.2
Falco
to upstream version 0.38.1
.cluster
to v1.1.0. (#325)observability-policies
.runAsGroup
and runAsUser
greater than zero for all deployments.cainjector
’s Vertical Pod AutoscalersecurityContext.readOnlyRootFilesystem
helm value (default true).NET_ADMIN
and drop ALL
capabilities.NET_BIND_SERVICE
capability.require-non-root-groups/autogen-check-runasgroup
.node
and app
labels in ServiceMonitor.alloy
v0.3.0 as alloy-logs
alloy-logs
app to camel case alloyLogs
.grafana-agent
to 0.4.5.alloy
to 0.3.1.promtail
to 1.5.4.prometheus-operator-crd
to 11.0.1.application.giantswarm.io/prometheus-rule-kind: loki
kube-prometheus-stack
to 11.0.0 and prometheus-operator-crd
to 11.0.0. This upgrade mainly consists in:grafana-agent
from 0.4.3 to 0.4.4CiliumNetworkPolicy
egress and ingress sections.observability-policies
app to deploy Kyverno Observability Policies into clusters.kyverno-crds
app to handle Kyverno CRD install.kyverno
(app) to v0.17.15. This version disables the CRD install job in favor of kyverno-crds
App.podAntiAffinity
so teleport-kube-agent
pods run on different control-plane
nodes also increased the number of replicas to 3 to maintain better high availability.