Before you upgrade to this release, make sure to read the Upgrading from v1.7 to v1.8 document.
Security
- Do not display
nilvalue for CA in athena configmap.
- Do not display
Added
- Add environment variable to override the cluster CA cert.
Added
- Implement
install-modulesinit job to install custom modules on Trivy0.29.2.
Changed
- Update to upstream version
0.4.16/app version0.29.2.
- Implement
Added
- Make
intervalandscrapeTimeoutconfigurable in the service monitor viamonitoring.serviceMonitor.intervalandmonitoring.serviceMonitor.scrapeTimeout
- Make
Added
- Add giant swarm monitoring annotations for alerting in workload clusters.
Changed
- Update Dex to v2.33.0
Changed
- Increase maximum sustained and burst Kubernetes client rate limits to 75 and 150 requests/second, respectively.
- Update
policy-reporterto v2.11.1 / app v2.8.0.
Added
- Webhook: Add
PodDisruptionBudgetand pod anti-affinity. - Startup API check: Add
NetworkPolicy.
Changed
- Webhook: Increase replica count to 2.
- Webhook: Add
Changed
- Update Dex to v2.33.0 https://github.com/giantswarm/dex-app/pull/205
Changed
- Update
kyvernoto upstream version 1.7.2 / chart version 2.5.2. - Use pre-install CRD install Job to remove storage version
v1alpha1for several Kyverno CRDs. - Set Kyverno to use the
giantswarm-criticalPriorityClass. - Limit maximum ReportChangeRequests per namespace to 100.
- Split PolicyReports into one report per policy to support the RCR limiting and avoid cases where a report doesn’t fit into etcd.
- Update