Security
- Add additional annotations on all
ingress objects to support DNS record creation via external-dns - Added the Runtime Default seccompprofile
Changed
- Fix/template RoleBinding for deploying into namespaces other than the release namespace.
Changed
- Update
kyverno to upstream version 1.9.0 / chart version 2.7.0. - Update
kyverno-policy-reporter to upstream version 2.12.0 / chart version 2.16.0. - Adds
giantswarm.io/monitoring annotation to kyverno service & plugin.
Added
- Adds support for DNS01 challenge via AWS Route53 (#284)
Added
- Add a possibility to configure a custom trusted root CA
- Add support for manual configuration of private workload cluster proxy
Added
- Push to
cloud-director app collection. - Push to
capz app collection.
Fixed
- controller-psp to allow volumes of type projected for IRSA capability (#286)
- Fix indentation when specifying multiple controller extraArgs. (#284)
Added
- Add support for
VPA for core, cert-controller and webhook deployments, enabled by default
Changed
- Renamed
falco-app to falco.