kyverno-app release v0.25.0

Fixed

  • Take the app.kubernetes.io/version label from the chart app version instead of the chart version, as described in the Helm chart best practices. The chart version carries build metadata that pushed the label past the 63 byte limit and made the install fail.
  • Remove the duplicated app.kubernetes.io/name: kyverno pod label from the admission controller.

Changed

  • Allow additional properties for the vendored kyverno, policy-reporter and shared global values so upstream keys are not rejected by the generated schema.
  • Increase default VPA minimum resources for Policy Reporter components to 50m CPU/50Mi memory.
  • Updated policy-reporter to upstream version v3.10.0.
  • Updated kyverno to upstream version v1.18.2.