Security
Changed
- Add feature gates for enabling/disabling individual Falco components.
Changed
- Update
Trivy to upstream version v0.56.1. - Disable PSPs.
Added
- Add Vertical Pod Autoscaler (VPA) configuration, enabled by default.
Changed
- Disable logger development mode to avoid panicking.
- Disable PodSecurityPolicy by default.
- Expose port 8081 for health/liveness probes.
Added
- Add handling on deletion for the old finalizer.
Changed
- Disable zap logger development mode to avoid panicking
- Ownership change to Shield
Changed
- Update
Kyverno to upstream version v1.12.6. - Update
kyverno-policy-reporter to upstream version v2.20.2.
Changed
- Disable JAMF components on chart templates
Changed
- Update to upstream
Kyverno Policies version 1.12.5. - Don’t push to vsphere-app-collection, capz-app-collection, capa-app-collection or cloud-director-app-collection. We started to consume kyverno-policies from security-bundle.
Changed
- Fix issues with templates
- Change ownership to Team Shield
Changed
- Update
Kyverno to upstream version v1.12.5.
- Added small fix on
podSecurityContext for seccompProfile.