Security
Added
- Add
Namespace exclusion from Draft generation. - Add
targetWorkloads and targetCategories flags to allow Categories and Workload customization. - Add
cleanup Job when upgrading or deleting exception-recommender.
Changed
- Change
PolicyExceptionDraftSpec to PolicyExceptionSpec. - Append
Kind to PolicyExceptionDraft name.
Added
- Added Policy Exceptions for
azure-cloud-node-manager.
Added
- Add PolicyExceptions for Deployments and CRD install Job.
Added
- Adding new properties to configure trusted peers in pre-defined static clients
- Added support for PSS resolving issue on upgrade to newer v3+ releases
Added
- Allow skipping Giant Swarm specific NetworkPolicy resources with
giantswarmNetworkPolicy.enabled value.
- added: add
auth-bundle to giantswarm catalog
Added
- adds extra
helm chart for the ciliumNetworkPolicies
Changed
- changes the previous
netpols helm chart to be used only for networkPolicies - disables the
startup-api-check job that waits for the webhookendpoints to become available
Changed
- Change the
kubectl apply command of the crd-install job to use the --force-conflicts flag.
Added
- Added
deployDexK8SAuthenticator option to disable the deployment of dex-k8s-authenticator. - Added
ingress.tls.externalSecret.enabled option to disable tls secret creation and allow usage of an external secret.