Releases: Cray-HPE/cray-kyverno
CSM 1.7 Release 0
What's Changed
- CASMPET-7328: Remove pod security policies by @davidfluck-hpe in #38
New Contributors
- @davidfluck-hpe made their first contribution in #38
Full Changelog: v1.6.6...v1.7.0
This release includes resourceFilters in background scans
This release includes resourceFilters in background scans. Resource Filters are a feature in Kyverno that filters a set of resources mentioned in the kyverno configmap, like kube-system and kyverno namespace. By default, these resourceFilters are not enabled in Kyverno. This causes kyverno to validate resources in privileged namespaces like kube-system, applying the baseline policies there, henceforth causing a number of policy failures. By enabling resource filters, we aim to reduce the policy failures by filtering out the privileged namespaces.
This release introduces wait in Kyverno post install hook
Intermittently, Kyverno timeout issue is encountered during CSM upgrade. By introducing delay in post install hook we are introducing wait till Kyverno pods are stabilized and then going ahead with Kyverno policy upgrade.
This release uses higher version of bitnami kubectl
Bitnami kubectl 1.26.4 has been reported with many critical CVE's hence changing the charts to use higher version which 1.31.0.
This release is to support postinstall hooks for enabling trust between Nexus and Kyverno.
The changes with release enable trust between nexus and kyverno. This is enabled through post install hooks. These changes are required for supporting image signing and verification.
Kyverno upgraded from 1.9.5 version to 1.10.7 version.
Kyverno Upgrade Needed for CSM version 1.6.x, to ensure the Kubernetes Version 1.24 Compatibility and N-2 support policy offered by the Kyverno community.
Release for latest version of Kyverno which is 1.10.7
This release contains upgraded version of Kyverno. Kyverno upgraded from 1.9.5 version to 1.10.7 version.
Creating new release for CSM 1.6
This is the first cray-kyverno tag for CSM 1.6.
Release to disable cleanup controller
As part kyverno upgrade to 1.9.5 the cleanup-controller feature is disabled as this is still not production ready and might break normal functioning of kyverno. Hence submitting this tag/release.
Release for kyverno 1.9.5 version support
In this release Kyverno is upgraded to version 1.9.5 from 1.7.5.