1
0
Fork 0
mirror of https://github.com/kyverno/kyverno.git synced 2024-12-14 11:57:48 +00:00
Commit graph

6610 commits

Author SHA1 Message Date
gcp-cherry-pick-bot[bot]
3de7c54a86
fix: display a message when the controller has no permissions for VAPs (#8776) (#8814)
* fix: display a message when the controller has no permissions for VAPs



* fix: add a warning when a Kyverno policy is created



---------

Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
Co-authored-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
2023-11-01 14:40:20 +00:00
shuting
ef90f0b07a
chore(deps): bump helm/chart-testing-action from 2.4.0 to 2.6.0 (#8809) (#8810)
Bumps [helm/chart-testing-action](https://github.com/helm/chart-testing-action) from 2.4.0 to 2.6.0.
- [Release notes](https://github.com/helm/chart-testing-action/releases)
- [Commits](e878887317...b43128a8b2)

---
updated-dependencies:
- dependency-name: helm/chart-testing-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: ShutingZhao <shuting@nirmata.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-11-01 15:14:10 +05:30
gcp-cherry-pick-bot[bot]
37353487ec
fix: display helm warnings together (#8784) (#8805)
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
Co-authored-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
2023-11-01 04:47:53 +00:00
gcp-cherry-pick-bot[bot]
24f8b877b6
fix: generate events for scanning VAPs in reports controller (#8783) (#8804)
Co-authored-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
2023-11-01 04:15:23 +00:00
gcp-cherry-pick-bot[bot]
0a98200abd
chore: upgrade docker/docker to v24.0.7 (#8793) (#8797)
Signed-off-by: Vishal Choudhary <vishal.choudhary@nirmata.com>
Co-authored-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
2023-10-31 09:16:00 +00:00
gcp-cherry-pick-bot[bot]
ff407b7d78
add VAP and VAPB to admission controller ClusterRole (#8768) (#8794)
* add VAP and VAPB to admission controller ClusterRole



* make conditional



* remove manual additions



---------

Signed-off-by: Chip Zoller <chipzoller@gmail.com>
Signed-off-by: chipzoller <chipzoller@gmail.com>
Signed-off-by: shuting <shuting@nirmata.com>
Co-authored-by: Chip Zoller <chipzoller@gmail.com>
Co-authored-by: shuting <shuting@nirmata.com>
2023-10-31 07:57:11 +00:00
gcp-cherry-pick-bot[bot]
e792e87e97
feat: update verify images types with better descriptions (#8779) (#8791)
* feat: update verify images types with better descriptions



* feat: revert cert and certchain



---------

Signed-off-by: Vishal Choudhary <vishal.choudhary@nirmata.com>
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
Co-authored-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
Co-authored-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
2023-10-31 05:30:26 +00:00
gcp-cherry-pick-bot[bot]
e4b5322c48
fix: rename vap logging name to ValidatingAdmissionPolicy (#8785) (#8788)
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
Co-authored-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
2023-10-30 18:02:29 +00:00
gcp-cherry-pick-bot[bot]
e1b476c88e
fix: print the number of VAPs being applied to the resources in test command (#8778) (#8782)
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
Co-authored-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
2023-10-30 15:03:34 +00:00
gcp-cherry-pick-bot[bot]
babb39c905
fix: grafana dashboard to support replicas (#8751) (#8759)
Signed-off-by: Alex Kennedy <alexzanderkennedy@gmail.com>
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
Signed-off-by: shuting <shuting@nirmata.com>
Co-authored-by: Alex Kennedy <alexzanderkennedy@gmail.com>
Co-authored-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
Co-authored-by: shuting <shuting@nirmata.com>
2023-10-27 09:01:38 +00:00
gcp-cherry-pick-bot[bot]
8b60e37ff1
Revert "add secrets name in background-controller's role (#8721)" (#8752) (#8757)
This reverts commit 580c02ce76.

Co-authored-by: shuting <shuting@nirmata.com>
2023-10-27 08:20:51 +00:00
Vishal Choudhary
4c9f5b8f28
feat: disable validate maintainer for helm gha (#8747) (#8748)
Signed-off-by: Vishal Choudhary <vishal.choudhary@nirmata.com>
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
2023-10-26 13:34:53 +00:00
gcp-cherry-pick-bot[bot]
d25b07c930
fix: revert maintainers in helm charts (#8737) (#8746)
* fix: revert maintainers in helm charts



* feat: codegnen



* fix: revert helm release changes



---------

Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
Signed-off-by: Vishal Choudhary <vishal.choudhary@nirmata.com>
Co-authored-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
2023-10-26 11:38:01 +00:00
shuting
526d4895b7
fix: fetch correct branch name in helm-release workflow (#8744) (#8745)
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
Signed-off-by: shuting <shuting@nirmata.com>
Signed-off-by: ShutingZhao <shuting@nirmata.com>
Co-authored-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
2023-10-26 09:30:29 +00:00
Vishal Choudhary
f9fccbd0bf
fix: replace base_ref with ref_name in helm test GHA (#8735) (#8736)
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
2023-10-25 14:35:24 +00:00
Vishal Choudhary
407ffa79de
fix: dynamically get branch name in helm test (#8732) (#8734)
* fix: dynamically get branch name in helm test



* fix: add env variable branch name



* fix: use head ref



* cleanup: remove debug statements



---------

Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
2023-10-25 11:09:41 +00:00
shuting
023ac8635a
release v1.11.0-rc.4 (#8723)
Signed-off-by: ShutingZhao <shuting@nirmata.com>
2023-10-24 10:54:21 +00:00
gcp-cherry-pick-bot[bot]
662a254520
add secrets name in background-controller's role (#8721) (#8722)
Signed-off-by: ShutingZhao <shuting@nirmata.com>
Co-authored-by: shuting <shuting@nirmata.com>
2023-10-24 09:48:17 +00:00
shuting
573d589c49
cherry-pick 8707 (#8717)
Signed-off-by: ShutingZhao <shuting@nirmata.com>
Co-authored-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
2023-10-24 04:30:54 +00:00
Vishal Choudhary
b321490e7b
[Helm] AdmissionReport cleanup job tag bump (#8708) (#8714)
* update chart metadata



* bump tag



* adjust name



* do not validate maintainers



* feat: update codegen



* feat: update codegen



* feat: update kubeversion in helm template



---------

Signed-off-by: chipzoller <chipzoller@gmail.com>
Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
Co-authored-by: chipzoller <chipzoller@gmail.com>
2023-10-23 15:36:21 +00:00
gcp-cherry-pick-bot[bot]
0e0bef1ebe
fix: add permissions to secrets for background controller role (#8690) (#8715)
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
Co-authored-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
Co-authored-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
2023-10-23 22:53:02 +08:00
shuting
899a9f0a3a
release v1.11.0-rc.3 (#8706)
Signed-off-by: ShutingZhao <shuting@nirmata.com>
2023-10-20 10:42:45 +00:00
shuting
de673f07e6
feat: generate events for CEL policies that generate VAPs (#8564) (#8705)
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
Signed-off-by: ShutingZhao <shuting@nirmata.com>
Co-authored-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
2023-10-20 09:48:30 +00:00
shuting
452392c05b
fix typo (#8666) (#8704)
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
Signed-off-by: ShutingZhao <shuting@nirmata.com>
Co-authored-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
2023-10-20 11:57:48 +03:00
gcp-cherry-pick-bot[bot]
c3db00b154
feat: fix outdated description of imageregistrycredentials (#8688) (#8699)
* feat: fix outdated description of imageregistrycredentials



* feat: generate crd



---------

Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
Co-authored-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
Co-authored-by: shuting <shuting@nirmata.com>
2023-10-20 12:30:54 +08:00
gcp-cherry-pick-bot[bot]
2212201553
fix: add codegen-cli-crds target to codegen-crds-all (#8692) (#8695)
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
Co-authored-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
2023-10-19 15:42:03 +00:00
gcp-cherry-pick-bot[bot]
6fcf2bc22b
feat: Implement global values for image registry in Kyverno Helm chart (#8625) (#8694)
* feat: Add image registry to global values



* Fix indentation



* Update documentation



---------

Signed-off-by: Franco <franco@giantswarm.io>
Co-authored-by: Franco Hielpos <48300215+fhielpos@users.noreply.github.com>
2023-10-19 14:30:17 +00:00
gcp-cherry-pick-bot[bot]
cf65fc2f48
fix: allow cleanup controller to update the policy status (#8681) (#8684)
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
Co-authored-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
2023-10-19 15:16:46 +08:00
gcp-cherry-pick-bot[bot]
2c570e007e
remove duplicated log messages (#8673) (#8676)
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
Co-authored-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
2023-10-18 11:49:38 +08:00
gcp-cherry-pick-bot[bot]
28c504a3c1
feat: add support for days in ttl labels (#8660) (#8662)
Co-authored-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
2023-10-16 13:58:04 +00:00
gcp-cherry-pick-bot[bot]
d5c25fcdc2
fix(helm): add values for declaratively enabling PDBs (#8652) (#8658)
* fix(helm): add values for declaratively enabling PDBs



* update codegen docs



---------

Signed-off-by: Erik Godding Boye <egboye@gmail.com>
Signed-off-by: ShutingZhao <shuting@nirmata.com>
Co-authored-by: Erik Godding Boye <egboye@gmail.com>
Co-authored-by: ShutingZhao <shuting@nirmata.com>
2023-10-16 09:22:21 +00:00
gcp-cherry-pick-bot[bot]
456a164a30
fix(helm): add missing policyexceptions RBAC to background-controller (#8648) (#8657)
Signed-off-by: Erik Godding Boye <egboye@gmail.com>
Co-authored-by: Erik Godding Boye <egboye@gmail.com>
Co-authored-by: shuting <shuting@nirmata.com>
2023-10-16 08:34:25 +00:00
shuting
6be88f3646
release v1.11.0-rc.2 (#8643)
Signed-off-by: ShutingZhao <shuting@nirmata.com>
2023-10-13 09:08:32 +00:00
shuting
a4e47ef6df
bump Go 1.21.3 (#8638)
Signed-off-by: ShutingZhao <shuting@nirmata.com>
2023-10-12 16:44:36 +00:00
gcp-cherry-pick-bot[bot]
4ba272452c
chore(deps): bump golang.org/x/net from 0.15.0 to 0.17.0 (#8626) (#8636)
Bumps [golang.org/x/net](https://github.com/golang/net) from 0.15.0 to 0.17.0.
- [Commits](https://github.com/golang/net/compare/v0.15.0...v0.17.0)

---
updated-dependencies:
- dependency-name: golang.org/x/net
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-12 15:54:11 +00:00
shuting
762f9396e1
release v1.11.0-rc.1 (#8634)
Signed-off-by: ShutingZhao <shuting@nirmata.com>
2023-10-12 13:39:14 +00:00
gcp-cherry-pick-bot[bot]
783b27d032
chore: bump cleanup policies to v2beta1 (#8621) (#8632)
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
Co-authored-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
2023-10-12 12:42:13 +00:00
gcp-cherry-pick-bot[bot]
26b99ceb82
feat: move crds to a subchart (#8623) (#8630)
* feat: move crds to a subchart



* update codegen



* update crd configs: annotations and install options



* update default crd installation configuration to true



* reset annotations



* update chart readme



* remove subchart crd install option



* update crd chart version



* configure crds labels



* fix chart yaml file



* revert crd subchart version to 0.0.0



* update install.yaml



---------

Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
Signed-off-by: ShutingZhao <shuting@nirmata.com>
Co-authored-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
Co-authored-by: ShutingZhao <shuting@nirmata.com>
2023-10-12 11:19:53 +00:00
gcp-cherry-pick-bot[bot]
63b2376873
fix: allow dropping metrics, labels and configuring histogram bucket boundaries to avoid high cardinality. (#8569) (#8629)
Signed-off-by: Rodrigo Fior Kuntzer <rodrigo@miro.com>
Co-authored-by: Rodrigo Fior Kuntzer <rodrigo@miro.com>
Co-authored-by: shuting <shuting@nirmata.com>
2023-10-12 10:34:16 +00:00
gcp-cherry-pick-bot[bot]
6594e11caa
feat: move grafana dashboard to a subchart (#8619) (#8620)
* feat: move grafana dashboard to a subchart



* fix codegen



* fix: add dependencies



* fix codegen



---------

Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
Co-authored-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
2023-10-11 22:35:34 +08:00
gcp-cherry-pick-bot[bot]
52f1452ec6
Revert "chore: bump cleanup policies to v2beta1 (#8594)" (#8609) (#8610)
This reverts commit fff3ad047e.

Co-authored-by: shuting <shuting@nirmata.com>
2023-10-09 15:53:22 +00:00
gcp-cherry-pick-bot[bot]
da29e0277a
chore: bump cleanup policies to v2beta1 (#8594) (#8607)
* chore: bump cleanup policies to v2beta1



* chore: remove the support of v2alpha1 cleanup policies



---------

Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
Co-authored-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
2023-10-09 12:22:38 +00:00
gcp-cherry-pick-bot[bot]
b087eb8f18
refactor: common remote authenticator for notary and cosign (#8494) (#8605)
* refactor: common remote authenticator for notary and cosign



* fix: add user agent



* refactor: move getGCRRemoteOption out of BuildGCRRemoteOption



---------

Signed-off-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
Co-authored-by: Vishal Choudhary <sendtovishalchoudhary@gmail.com>
Co-authored-by: shuting <shuting@nirmata.com>
2023-10-09 09:40:06 +00:00
gcp-cherry-pick-bot[bot]
a8cdb5a23b
refactor: use GetKind() from the cleanup policy interface (#8565) (#8604)
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
Co-authored-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
2023-10-09 09:01:58 +00:00
gcp-cherry-pick-bot[bot]
12df4bf32d
fix: use v2beta1 of policy exceptions (#8587) (#8603)
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
Co-authored-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
2023-10-09 08:11:47 +00:00
gcp-cherry-pick-bot[bot]
a848dafe7f
Refactor fuzzing utils and add 3 fuzzers (#8555) (#8586)
* Refactor fuzzing utils and add 3 fuzzers



* Fix lint issues



* use latest go-jmespath



* Check layer size (#8552)

* fix excessive logs



* check fetched layer size



* check sig layer size



---------




* fix lint issues



---------

Signed-off-by: AdamKorcz <adam@adalogics.com>
Signed-off-by: Jim Bugwadia <jim@nirmata.com>
Co-authored-by: AdamKorcz <44787359+AdamKorcz@users.noreply.github.com>
Co-authored-by: Jim Bugwadia <jim@nirmata.com>
2023-10-06 08:00:13 +08:00
gcp-cherry-pick-bot[bot]
65527e2b4e
chore: bump kubectl-validate (#8548) (#8551)
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
Co-authored-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
2023-09-27 22:39:47 +02:00
Charles-Edouard Brétéché
0ac6b0bf61
release: v1.11.0-beta.4 (#8549)
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
2023-09-27 19:25:28 +00:00
gcp-cherry-pick-bot[bot]
468692a5b6
chore: enable policy exceptions by default (#8545) (#8550)
Signed-off-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
Co-authored-by: Mariam Fahmy <mariam.fahmy@nirmata.com>
2023-09-27 18:20:04 +00:00
gcp-cherry-pick-bot[bot]
7d3bb309a0
refactor: remove openapi package (#8538) (#8547)
* refactor: openapi package



* kubectl validate



* rm



* fix



* fix



* go mod



* fix vscode



---------

Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
Co-authored-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
2023-09-27 17:25:20 +00:00