Security
Added
- Add missing
app.kubernetes.io/ labels to all the pods. - Add
CiliumNetworkPolicy for individual controllers:kyverno-admission-controllerkyverno-background-controllerkyverno-reports-controllerkyverno-cleanup-controllerkyverno-cleanup-jobskyverno-pluginkyverno-policy-reporter
Changed
- Configure
gsoci.azurecr.io as the default container image registry.
Removed
- Stop pushing to
openstack-app-collection.
Changed
- Configure
gsoci.azurecr.io as the default container image registry.
Changed
- Configure
gsoci.azurecr.io as the default container image registry.
Changed
- Changed conditional for PSPs to
{{- if not .global.podSecurityStandards.enforced }}
Changed
- Remove finalizers from reconcile logic.
- Ignore
skip results.
- changed: deploy auth apps in
auth namespace by default
Changed
- Don’t use
oidc.customer.enabled value since it is redundant.
Changed
- Keep
policy-exceptions namespace when deleting the chart. - Changed cleanup-job template to include
selector.labels.