Added
- adds extra
helm chartfor theciliumNetworkPolicies
Changed
- changes the previous
netpolshelm chartto be used only fornetworkPolicies - disables the
startup-api-checkjob that waits for the webhookendpoints to become available
helm chart for the ciliumNetworkPoliciesnetpols helm chart to be used only for networkPoliciesstartup-api-check job that waits for the webhookendpoints to become availablekubectl apply command of the crd-install job to use the --force-conflicts flag.deployDexK8SAuthenticator option to disable the deployment of dex-k8s-authenticator.ingress.tls.externalSecret.enabled option to disable tls secret creation and allow usage of an external secret.acme-solvers-networkpolicy to the NetworkPolicies Helm chart for better organization and management of network policies.acme-solvers-ciliumnetworkpolicyFalcoctl.Falco chart version from 3.3.0 to 3.8.1.Falco-exporter chart version from 0.9.6 to 0.9.7Falcosidekick chart version from 0.6.1 to 0.7.5Falco to upstream version 0.36.1.Falco made some big changes in the way rules are distributed, categorized, and updated. For more information, check the Falco release notes. This means that we will ship Falco with fewer rules by default, as aligned with upstream. They have done this to give endusers a quieter default set of rules. They will now follow a standard, incubating, sandbox system. Before this update, all these rules were shipped by default. This means, that if CustomRules or macros were based on some rules which are now considered incubating or sandbox rules, they are now broken. This can be fixed by altering the configuration of falcoctl to also download and use the incubating and sandbox rules, or by rewriting your CustomRules. For more information, please check the falco rules page.
acme-solvers-networkpolicy and acme-solvers-ciliumnetworkpolicy for enhanced network security and control.