Security
Added
- Ensuring that the organization namespace is patched with the organization labels in case they are not present.
Changed
- Configure
gsoci.azurecr.io as the default container image registry.
- added: initial commits for teleport-tbot
Fixed
- Add missing ingress to Cleanup Controller CiliumNetworkPolicy.
Fixed
- Fixed Kyverno policy exception for the CRD installer job
Added
- Added readiness check for
cert-manager-app-webhook before attempting installation on clusterIssuers chart
Fixed
- Add missing CiliumNetworkPolicies for pre-delete and post-ugprade hooks.
Changed
- Disable namespace creation by default since it was moved to Kyverno.
- Check if namespace exists before creation.
Changed
- Fix label selector
kyverno-policy-reporter to talk to kyverno-ui rule. - Add
policy-exceptions namespace if it doesn’t exist.
Added
- Added support for
azureDNS dns01 challenge solver on cluster-issuer chart