Security
Added
- Added Vertical Pod Autoscaler support for
controller pods. - Added renovate configutarion
Removed
- Removed dependabot configuration
Changed
- Address new code linter findings for golangci-lint v2.
- Update Go version and various dependencies.
Added
- Push to CAPI app collections.
Changed
- grafana dashboard: load it to
Shared Org (public) organization
Added
- Add headless service on
diag port 3000.
Changed
Changed
- Add API capabilities check for Kyverno PolicyExceptions before switching to v2.
Changed
- Make
livenessProbe.initialDelaySeconds configurable.
Added
- Added support for
read-all-customer-groups bindings.
Changed
- Change ownership to Team Shield
Added
- Add supplemental security and best practices policies:
check-resources-request-and-limits-ratiocheck-serviceaccount-secretsdisallow-gitrepo-volumedisallow-latest-tagprevent-bare-podsrequire-container-requests-and-limitsrequire-emptydir-requests-and-limitsrequire-pod-probesrestrict-binding-clusteradminrestrict-binding-system-groupsrestrict-sa-automount-sa-token
Changed
- Narrow down CiliumNetworkPolicy egress rule to match DNS service only.
- Narrow down CiliumNetworkPolicy ingress rule to allow traffic from namespace.
Changed
- Update
kyverno to upstream version v1.13.4. - Use GVK for specifying Kinds in core-policies.
- Add
runAsGroup to container security contexts.