Security
Changed
- Update
kyverno to version 1.5.0.
Added
- Provide access to the customer automation SA for managing flux resources.
- Provide access to the customer automation SA for managing cluster-specific resources.
- Provide access to the customer automation SA for managing node pool-specific resources.
Changed
- Push starboard-app to AWS, Azure, and VMWare collections.
Changed
- Use in-cluster Trivy by default.
- Scan all namespaces by default.
- Add PodSecurityPolicy.
- Add NetworkPolicy (for operator only).
- Add expanded PSP for enabling CIS benchmarks.
Added
- Initial trivy resources.
- Basic NetworkPolicy resources.
Fixed
- Use
Status() client to patch Organization’s status with a namespace.
Changed
- Add appropriate labels to CRDs.
Changed
- Remove
PodSecurityPolicy from the enabled api-server admission plugins.
Changed
- Don’t return an error in case creation of legacy organization fails.
Changed
- Change dex image to fix refreshing token