Security
Changed
- Remove feature gate from PolicyException and bump it to v2beta1.
- Update
Trivy to version v0.52.0.
Added
- Push to AWS app collection.
Changed
- Extend CiliumNetworkPolicy to cover CNPG join and init operations.
Removed
- Remove
write_all_group from values and schema.
Changed
- Disable Trivy cleanup policy by default.
Changed
- Fix template issue with DNS rules on the
admission-controller CiliumNetworkPolicy.
Added
- Add CiliumNetworkPolicy.
- Enable PodMonitor for operator metrics.
- Enable Grafana dashboard.
- Enable ClusterImageCatalog for Giant Swarm retagged images.
Added
- Add cleanup policy to remove old
trivy-operator resources.
Changed
- Enable
cleanup-controller with VericalPodAutoscaler by default. - Add missing ingress to
cleanup-controller CiliumNetworkPolicy. - Add
before-hook-creation delete-policy for upstream hooks.
Added
- Added annotation
helm.sh/resource-policy: keep on CRDs to prevent them from being pruned in an unexpected rollback event.
Changed
- Remove API check for
HorizontalPodautoscaler.
Fixed
- Fixed cilium network policy, added
cluster entity to egress rule.
Changed
- Remove push to app catalog: default, control plane, app collections
- Switched to use recommended
proxy_server over auth_server in tbot config.