Security
Changed
- Split Cilium PolicyExceptions per component.
- Add rules to cilium-agent PolicyException.
- Restrict Policy and ClusterPolicy to kyverno.io/v1 for wildcard policy matching
Removed
- Remove Helm
hooks annotations from default Policies and PolicyExceptions.
Added
- Supports enabling cronjob by setting
cronjob.enabled. Disabled by default.
Removed
- Remove duplicate default identity output entry
Added
- Add cronjob to cleanup leftover teleport-kubeconfigs for deleted clusters.
- Improve README.
Added
- Label to Kubernetes secret created by teleport-tbot.
Changed
- Upgraded to Teleport
version 16
Changed
- Rotate operator-managed certificates 16 days before their expiration, instead of 7 days.
- Update to cloudnative-pg v1.23.2 (chart v0.21.5).
Fixed
- Fixes an issue in tbot config file that caused tbot pod to CrashLoopBackOff.
Changed
- Outputs is now configurable.
- Certificate TTL value increased and configurable.
Added
- Added enabled flag to conditionally deploy helm chart.
Changed
- Push to app catalog and app collection (CAPZ).
Fixed
- Fixed potential vulnerability on
devctl generated github-workflows.