Added
- Add NET_BIND_SERVICE capability back to containers.
Changed
- Upgrade CoreDNS to v1.11.1.
controller.admissionWebhooks.patch.networkPolicy.enabled. (#568)This release contains security relevant changes. Please check your Ingress resources for invalid annotations or paths before installing it.
controller.enableAnnotationValidations by default. (#552)Ingress resources. Upstream is enabling this by default, too: https://github.com/kubernetes/ingress-nginx/issues/10186.controller.config.strict-validate-path-type by default. (#553)Ingress resources only. Upstream is enabling this by default, too: https://github.com/kubernetes/ingress-nginx/issues/10186.This version contains fixes for HTTP/2 stream reset attacks (CVE-2023-44487).
Values.global.podSecurityStandards.enforced flag in preparation of PSP to PSS migrationreplicaCount: 1 or autoscaling.minReplicas: 1controller.enableAnnotationValidations. (#536)controller.opentelemetry.resources. (#536)global.podSecurityStandards.enforced. (#544)v1.9.0. (#536)controller.topologySpreadConstraints an array. (#536)controller.topologySpreadConstraints to an array, too.securityContexts and Pod Security Policies. (#540)kube-webhook-certgen image to v20231011-8b53cabe0. (#542)v1.9.3. (#547)controller.kind: Both. (#547)