Security
Added
- Introduced
acme-solvers-networkpolicy and acme-solvers-ciliumnetworkpolicy for enhanced network security and control.
Changed
- Fixed Kyverno PolicyExceptions.
Changed
- Restrict access to
org-giantswarm namespace
Changed
- Implemented the use of the
global.podSecurityStandards.enforced toggle. - Fixed an issue with the
falcoctl image value structure.
Added
- Add
MatchExpressions selector to organization scope for RoleBindingTemplate
Changed
- Removed unused values and update schema.
Added
- Added Policy Exceptions for
aws-cloud-controller-manager, aws-ebs-csi-driver, azure-cloud-controller-manager and cilium. - Add Policy Exception for
chart-operator ServiceAccount. - Change
psp.enabled value to global.podSecurityStandards.enforced
Added
- Ability to specify annotations of the Deployment
Changed
- Do not install PodSecurityPolicy if api not available.
- Make deployment PSS compliant.
- Do not install cleaning hook when Quick Tunnel is enabled.
Added
- cert-manager-giantswarm-clusterissuer: Allow setting
hostedZoneID for route53 DNS01 challenge. - cert-manager-giantswarm-clusterissuer: Make
accessKeyID and secretAccessKey optional for route53 DNS01 challenge.