Security

  • Added

    • Add externalresources resource that binds read-default-catalogs and read-releases roles for any subject with org-namespace access.
    • Add creation of read-default-catalogs Role.
    • Add creation of read-releases ClusterRole.
    • Improve logging for the orgpermissions, clusternamespace, and rbac controllers.
    • make PDB version conditional based on available API
  • Added

    • Add cluster-namespace controller which ensures that RBAC resources to access resources in cluster namespaces can be granted to those with access to the clusters organization
    • Add bootstrapping for the read-cluster-apps and write-cluster-apps clusterRoles.
    • Add update option for orgReadClusterRoleBinding resource.

    Changed

    • The write_all_group configuration key is now optional.
  • Added

    • Add the image_registry label exposing the image registry.

    Changed

    • Bump golang, prometheus, and starboard dependency versions.
    • Update Grafana dashboard to use plugin version 8.3.2 and the new label.
  • Fixed

    • Fix RBAC rule for fix secret job.
    • No changes compared to v1.5.0.
  • Changed

    • Updated Ingress resources in helm chart.
    • Add workaround for Chart upgrade not working when not using lets encrypt due to changed secret type.
  • Added

    • Increase trivy scan Job memory limits to 1G.
  • Added

    • Create RBAC for customer-facing Flux to access organization namespaces.
    • Add automation ServiceAccount to organization namespaces with permissions to handle Flux resources in that namespace by default.
  • Removed

    • Disable policy-reporter monitoring (ServiceMonitors) by default.