Security
Added
- Push to CAPI app collections.
Changed
- grafana dashboard: load it to
Shared Org (public) organization
Added
- Add headless service on
diag port 3000.
Changed
Changed
- Add API capabilities check for Kyverno PolicyExceptions before switching to v2.
Changed
- Make
livenessProbe.initialDelaySeconds configurable.
Added
- Added support for
read-all-customer-groups bindings.
Changed
- Change ownership to Team Shield
Added
- Add supplemental security and best practices policies:
check-resources-request-and-limits-ratiocheck-serviceaccount-secretsdisallow-gitrepo-volumedisallow-latest-tagprevent-bare-podsrequire-container-requests-and-limitsrequire-emptydir-requests-and-limitsrequire-pod-probesrestrict-binding-clusteradminrestrict-binding-system-groupsrestrict-sa-automount-sa-token
Changed
- Narrow down CiliumNetworkPolicy egress rule to match DNS service only.
- Narrow down CiliumNetworkPolicy ingress rule to allow traffic from namespace.
Changed
- Update
kyverno to upstream version v1.13.4. - Use GVK for specifying Kinds in core-policies.
- Add
runAsGroup to container security contexts.
Changed
- Update to upstream
Kyverno Policies version 1.13.4.
Added
- Add supplemental policies
restrict-external-ips, require-ro-rootfs, and enable upstream policy require-non-root-groups. - Add supplemental policy to generate default deny-all Network Policies in newly created namespaces.
Changed
- Update
Falco to upstream version 0.40.0.