Nicolas Lamirault
4ca208da25
FIX Custom labels indentation ( #2073 )
...
* Fix: custom labels indentation
Signed-off-by: Nicolas Lamirault <nicolas.lamirault@gmail.com>
* Update: bump chart version
Signed-off-by: Nicolas Lamirault <nicolas.lamirault@gmail.com>
2021-06-25 13:28:30 -07:00
Shuting Zhao
f9a89c4672
tag v1.4.1
...
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
2021-06-24 15:13:15 -07:00
shuting
0a13ce9c73
Revert "Fix Helm deployment name issue" ( #2070 )
2021-06-24 14:22:34 -07:00
Pooja Singh
54a85c5da1
Merge pull request #2045 from vyankyGH/fix_deployment_name
...
Fix Helm deployment name issue - install kyverno with helm release name != kyverno
2021-06-24 19:19:19 +05:30
vyankatesh
235038e712
fix deployment issue
2021-06-24 13:07:51 +05:30
vyankatesh
11a05496de
fix helm deployment name
2021-06-24 13:03:15 +05:30
Marcus Noble
443d56fd4d
fix: set deployment name env var
...
Signed-off-by: Marcus Noble <m.noble@elsevier.com>
2021-06-24 08:17:14 +01:00
shuting
3b06378142
remove selector from Helm chart ( #2056 )
...
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
2021-06-22 23:10:04 -07:00
Pooja Singh
c6c803511c
Merge pull request #1977 from RinkiyaKeDad/1818_default_to_baseline
...
replacing pod security standard from default to baseline
2021-06-22 23:35:39 +05:30
Retna Ramachandran
5825dfbf4f
feat: splitting envVars for initContainers and containers
...
Signed-off-by: Retna Ramachandran <retna@gjensidige.no>
Signed-off-by: Retna Ramachandran <retna.ramachandran@gjensidige.no>
2021-06-22 15:41:58 +02:00
Retna Ramachandran
c95802bf84
fix: clean up of extra ENV key in manifest
...
Signed-off-by: Retna Ramachandran <retna@gjensidige.no>
Signed-off-by: Retna Ramachandran <retna.ramachandran@gjensidige.no>
2021-06-22 15:41:58 +02:00
Retna
194c99564e
fix: added envVars to containers
...
Signed-off-by: Retna Ramachandran <retna.ramachandran@gjensidige.no>
2021-06-22 15:41:58 +02:00
George Kaz
d4180737f5
iterate-chart-version
...
Signed-off-by: George Kaz <egeorgekaz@gmail.com>
2021-06-22 09:49:06 +01:00
RinkiyaKeDad
a93c46a8e8
psd -> psb
...
Signed-off-by: RinkiyaKeDad <arshsharma461@gmail.com>
2021-06-22 12:05:19 +05:30
George Kaz
de409159e3
Correct ca and cert namespace
...
Signed-off-by: George Kaz <egeorgekaz@gmail.com>
2021-06-21 15:57:51 +01:00
Shuting Zhao
56eeefa6d1
tag v1.4.0
...
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
2021-06-18 12:14:46 -07:00
Shuting Zhao
a9e3092fca
tag v1.4.0-rc4
...
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
2021-06-17 17:52:11 -07:00
treydock
bc3755d0b1
Fix Helm chart metrics service to allow NodePort ( #2035 )
...
Signed-off-by: Trey Dockendorf <tdockendorf@osc.edu>
2021-06-17 15:20:31 -07:00
Shuting Zhao
3e4ee51267
tag v1.4.0-rc3
...
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
2021-06-16 23:49:47 -07:00
shuting
65975a8b65
Enable webhooks configuration via Helm ( #2032 )
...
* helm - enable configurations of webhooks
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* retry on update failure
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* update Readme
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* address lint errors
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
2021-06-16 23:29:07 -07:00
Shuting Zhao
e61f6f9dd9
tag v1.4.0-rc2
...
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
2021-06-15 21:59:19 -07:00
treydock
f1491fe6d3
Allow metrics service annotations to be defined separate from main service ( #1988 )
...
* Allow metrics service annotations to be defined separate from main service
Signed-off-by: Trey Dockendorf <tdockendorf@osc.edu>
* Add test for metrics during Helm deployment testing
Signed-off-by: Trey Dockendorf <tdockendorf@osc.edu>
* Make services separate for kustomize
Signed-off-by: Trey Dockendorf <tdockendorf@osc.edu>
* Run 'make kustomize-crd'
Signed-off-by: Trey Dockendorf <tdockendorf@osc.edu>
* Fix e2e tests for metrics
Signed-off-by: Trey Dockendorf <tdockendorf@osc.edu>
* Fix Helm chart for metrics service
Signed-off-by: Trey Dockendorf <tdockendorf@osc.edu>
* Fix helm chart testing
Signed-off-by: Trey Dockendorf <tdockendorf@osc.edu>
2021-06-10 13:53:29 -07:00
Shuting Zhao
2ca824210d
tag v1.4.0-rc1
...
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
2021-06-08 13:09:20 -07:00
shuting
e9a972a362
feat: HA ( #1931 )
...
* Fix Dev setup
* webhook monitor - start webhook monitor in main process
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* add leaderelection
Signed-off-by: Jim Bugwadia <jim@nirmata.com>
* - add isLeader; - update to use configmap lock
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* - add initialization method - add methods to get attributes
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* address comments
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* remove newContext in runLeaderElection
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* add leader election to GenerateController
Signed-off-by: Jim Bugwadia <jim@nirmata.com>
* skip processing for non-leaders
Signed-off-by: Jim Bugwadia <jim@nirmata.com>
* skip processing for non-leaders
Signed-off-by: Jim Bugwadia <jim@nirmata.com>
* add leader election to generate cleanup controller
Signed-off-by: Jim Bugwadia <jim@nirmata.com>
* Gracefully drain request
* HA - Webhook Register / Webhook Monitor / Certificate Renewer (#1920 )
* enable leader election for webhook register
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* extract certManager to its own process
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* leader election for cert manager
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* certManager - init certs by the leader
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* add leader election to webhook monitor
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* update log message
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* add leader election to policy controller
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* add leader election to policy report controller
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* rebuild leader election config
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* start informers in leaderelection
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* start policy informers in main
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* enable leader election in main
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* move eventHandler to the leader election start method
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* address reviewdog comments
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* add clusterrole leaderelection
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* fixed generate flow (#1936 )
Signed-off-by: NoSkillGirl <singhpooja240393@gmail.com>
* - init separate kubeclient for leaderelection - fix webhook monitor
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* address reviewdog comments
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* cleanup Kyverno managed resources on stopLeading
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* tag v1.4.0-beta1
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* fix cleanup process on Kyverno stops
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* bump kind to 0.11.0, k8s v1.21 (#1980 )
Co-authored-by: vyankatesh <vyankatesh@neualto.com>
Co-authored-by: vyankatesh <vyankateshkd@gmail.com>
Co-authored-by: Jim Bugwadia <jim@nirmata.com>
Co-authored-by: Pooja Singh <36136335+NoSkillGirl@users.noreply.github.com>
2021-06-08 12:37:19 -07:00
Ahmed Waleed Malik
3c4c6dae92
Remove runAsUser specification from Security Context ( #1972 )
...
This fails on openshift since we cannot specify users within this range. Also, this template should be as close as possible to the vanilla manifest for deployment https://github.com/kyverno/kyverno/blob/main/definitions/release/install.yaml
Vanilla manifest omits the user specification https://github.com/kyverno/kyverno/blob/main/definitions/release/install.yaml#L2478
Signed-off-by: Waleed Malik <ahmedwaleedmalik@gmail.com>
2021-06-08 10:14:20 -07:00
RinkiyaKeDad
d1be681773
replacing pod security standard from default to baseline
...
Signed-off-by: RinkiyaKeDad <arshsharma461@gmail.com>
2021-06-08 13:02:02 +05:30
Nicolas Lamirault
62c4cd7e3d
Recommanded Kubernetes labels and custom labels ( #1873 )
...
* Add: Recommanded Kubernetes labels
Signed-off-by: Nicolas Lamirault <nicolas.lamirault@gmail.com>
* Add: feature to add custom labels to resources metadata
Signed-off-by: Nicolas Lamirault <nicolas.lamirault@gmail.com>
* Add: manage labels with Kustomize
Signed-off-by: Nicolas Lamirault <nicolas.lamirault@gmail.com>
* Add: app label
Signed-off-by: Nicolas Lamirault <nicolas.lamirault@gmail.com>
* Add: app label for chart
Signed-off-by: Nicolas Lamirault <nicolas.lamirault@gmail.com>
* Update: make kustomize-crds
Signed-off-by: Nicolas Lamirault <nicolas.lamirault@gmail.com>
* Update: refactoring labels
Signed-off-by: Nicolas Lamirault <nicolas.lamirault@gmail.com>
* Fix: clean kustomize code
Signed-off-by: Nicolas Lamirault <nicolas.lamirault@gmail.com>
* Fix: typo
Signed-off-by: Nicolas Lamirault <nicolas.lamirault@gmail.com>
* Update: application version v1.3.6
Signed-off-by: Nicolas Lamirault <nicolas.lamirault@gmail.com>
* Update: version v1.3.6
Signed-off-by: Nicolas Lamirault <nicolas.lamirault@gmail.com>
2021-06-01 11:54:33 -07:00
shuting
cd4d738667
Merge pull request #1877 from yashvardhan-kukreja/prometheus-integration-setup
...
feat: Prometheus metrics integration
2021-05-26 12:31:21 -07:00
Yashvardhan Kukreja
8eae8ec492
feat: added support for exposing the metrics via kyverno-svc service
...
Signed-off-by: Yashvardhan Kukreja <yash.kukreja.98@gmail.com>
2021-05-24 08:06:40 +05:30
windowsrefund
69ba308687
eliminate duplicate env key
2021-05-20 11:21:47 -04:00
Shuting Zhao
4f79f44f9f
tag v1.3.6
...
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
2021-05-17 11:39:39 -07:00
Shuting Zhao
5dcb03e6f5
tag v1.3.6-rc5
...
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
2021-05-13 12:44:34 -07:00
Shuting Zhao
edd33a6d09
tag v1.3.6-rc4
...
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
2021-05-10 10:18:38 -07:00
Simon Metzger
a65a85e55c
allow only supplementalGroups greater 0 ( #1901 )
...
Signed-off-by: Metzger, Simon <smnmtzgr@gmail.com>
2021-05-10 10:14:08 -07:00
Shuting Zhao
55a987ed5e
tag v1.3.6-rc3
...
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
2021-05-07 19:03:43 -07:00
Shuting Zhao
dfaf675185
tag v1.3.6-rc2
...
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
2021-05-07 12:15:57 -07:00
Nicolas Lamirault
9bdde7abea
Resources for initContainers ( #1871 )
...
* Add: resources for initContainers
Signed-off-by: Nicolas Lamirault <nicolas.lamirault@gmail.com>
* Update: increase memory limit for init container
Signed-off-by: Nicolas Lamirault <nicolas.lamirault@gmail.com>
* Add: init container resources
Signed-off-by: Nicolas Lamirault <nicolas.lamirault@gmail.com>
* Fix: kustomize CRD
Signed-off-by: Nicolas Lamirault <nicolas.lamirault@gmail.com>
2021-05-07 09:53:00 -07:00
Nicolas Lamirault
02f1faca0b
Add: Display which chart version is installed ( #1875 )
...
Signed-off-by: Nicolas Lamirault <nicolas.lamirault@gmail.com>
2021-05-04 10:59:55 -07:00
Shuting Zhao
7e575d0e19
tag v1.3.6-rc1
...
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
2021-04-29 15:03:48 -07:00
Simon Metzger
6e76fd68f0
allow fsGroup values greater than zero ( #1822 )
...
change the policy require-non-root-groups to allow fsGroup values greater than zero
Signed-off-by: Metzger, Simon <smnmtzgr@gmail.com>
2021-04-21 12:12:26 -07:00
treydock
b5fd23588a
Fix Helm charts ( #1828 )
...
* Fix Helm charts to render correctly
Signed-off-by: Trey Dockendorf <tdockendorf@osc.edu>
* Make Helm chart policies consistent
Signed-off-by: Trey Dockendorf <tdockendorf@osc.edu>
2021-04-20 13:08:30 -07:00
Frank Jogeleit
56183cc73d
Add severity to pod security policies ( #1797 )
...
Signed-off-by: Frank Jogeleit <fj@move-elevator.de>
2021-04-16 17:41:30 -07:00
Shuting Zhao
4a4fdc54ee
release v1.3.5
...
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
2021-04-16 14:04:00 -07:00
Shuting Zhao
a4b639f754
tag v1.3.5-rc5
...
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
2021-04-15 17:35:25 -07:00
Shuting Zhao
3f18b5f7df
tag v1.3.5-rc3
...
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
2021-04-14 13:12:12 -07:00
treydock
67973c2776
Add Helm tests to Github Actions ( #1793 )
...
This reverts commit 2749280b6c
.
Signed-off-by: Trey Dockendorf <tdockendorf@osc.edu>
2021-04-13 10:39:27 -07:00
shuting
2749280b6c
Revert "Add Helm tests to Github Actions ( #1790 )" ( #1792 )
...
This reverts commit 9c7f7019f3
.
2021-04-12 21:57:21 -07:00
treydock
9c7f7019f3
Add Helm tests to Github Actions ( #1790 )
...
Signed-off-by: Trey Dockendorf <tdockendorf@osc.edu>
2021-04-12 20:55:13 -07:00
shuting
9dab21619f
Match endpoint to the exact Kyverno Pod's IP ( #1787 )
...
* update log message
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* update printer column - validation failure action
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* match endpoint ip with the exact pod ip
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* - add tag "app.kubernetes.io/name"; - reduce throttling requests when deletes webhook configs
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* add [SelfSubjectAccessReview,*,*] to resource filters
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
2021-04-12 20:29:51 -07:00
shuting
f3ca1d78f1
Fix log message ( #1779 )
...
* update log message
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* update printer column - validation failure action
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
2021-04-08 12:10:30 -07:00
Shuting Zhao
6f41acde03
tag v1.3.5-rc3
...
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
2021-04-06 11:13:56 -07:00
Vyankatesh Kudtarkar
3ab75095b7
remove permission ( #1758 )
...
* remove permission
Signed-off-by: vyankatesh <vyankatesh@neualto.com>
* remove duplicate resource
Signed-off-by: vyankatesh <vyankatesh@neualto.com>
Co-authored-by: vyankatesh <vyankatesh@neualto.com>
2021-04-02 11:22:59 -07:00
Shuting Zhao
a1d9cdd14b
tag v1.3.5-rc2
...
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
2021-04-01 13:57:33 -07:00
treydock
91713ee566
Check webhooks are present during liveness ( #1748 )
...
Fixes #1747
Signed-off-by: Trey Dockendorf <tdockendorf@osc.edu>
2021-03-31 12:44:56 -07:00
Yuto Takahashi
e2cb30e752
Allow generatecontroller to handle Roles ( #1739 )
...
* Allow generateoperator to handle Roles
Signed-off-by: Yuto Takahashi <ytaka23dev@gmail.com>
* Restore the releasable manifest
Signed-off-by: Yuto Takahashi <ytaka23dev@gmail.com>
2021-03-29 22:48:41 -07:00
Shuting Zhao
0c860b7327
release v1.3.5-rc1
...
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
2021-03-26 15:14:05 -07:00
Adam Kosmin
60653eb620
support envVars with sane default ( #1715 )
...
Co-authored-by: windowsrefund <mtf8>
2021-03-16 14:11:04 -07:00
Shuting Zhao
592394df02
release v1.3.4
2021-03-05 10:56:02 -08:00
Shuting Zhao
edbd7bf222
release v1.3.4-rc1
...
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
2021-03-03 12:00:31 -08:00
Arsh Sharma
ccfe8c443c
fix: added details regarding match.resources ( #1654 )
...
* fix: added details regarding match.resources
Signed-off-by: Arsh Sharma <arshsharma461@gmail.com>
* fix: made revisions
Signed-off-by: Arsh Sharma <arshsharma461@gmail.com>
* fix: removed if not statement
Signed-off-by: Arsh Sharma <arshsharma461@gmail.com>
2021-03-03 11:22:45 -08:00
Yashvardhan Kukreja
10c714d5ba
feat: [preconditions, conditions] added backwards-compatible support for logical operators ( #1604 )
...
Signed-off-by: Yashvardhan Kukreja <yash.kukreja.98@gmail.com>
2021-03-01 20:31:06 -08:00
Arsh Sharma
da8e449d3c
fix: removed validator ( #1646 )
...
Signed-off-by: Arsh Sharma <arshsharma461@gmail.com>
2021-02-26 11:27:21 -08:00
Arsh Sharma
a0d28f0b16
fix: list operators in deny conditions ( #1641 )
...
* fix: list operators in deny conditions
Signed-off-by: Arsh Sharma <arshsharma461@gmail.com>
* fix: regenerated YAMLs
Signed-off-by: Arsh Sharma <arshsharma461@gmail.com>
2021-02-25 19:13:35 -08:00
treydock
e3a8c5091c
Fix Helm chart notes to use template values ( #1634 )
...
Signed-off-by: Trey Dockendorf <tdockendorf@osc.edu>
2021-02-22 13:22:28 -08:00
treydock
48f0d90dd1
Allow some helm policies to be excluded ( #1611 )
...
* Allow some helm policies to be excluded
Signed-off-by: Trey Dockendorf <tdockendorf@osc.edu>
* Make Helm security policies opt-in when podSecurityStandard=custom
Signed-off-by: Trey Dockendorf <tdockendorf@osc.edu>
2021-02-18 11:50:35 -08:00
Shuting Zhao
f2b00a1f1e
update chart link - icon
2021-02-16 14:42:19 -08:00
Shuting Zhao
f6192d08b0
release v1.3.3
2021-02-16 13:49:50 -08:00
Raj Babu Das
b04626a5f8
Adding default policies for restricted mode and adding notes to helm install ( #1556 )
...
* Adding default policies for restricted mode, taking validationFailureAction from values.yaml and adding notes on helm install
Signed-off-by: Raj Das <mail.rajdas@gmail.com>
* Adding emoji
Signed-off-by: Raj Das <mail.rajdas@gmail.com>
* Update NOTES.txt
* minor fix
Signed-off-by: Raj Das <mail.rajdas@gmail.com>
* adding to readme
Signed-off-by: Raj Das <mail.rajdas@gmail.com>
2021-02-09 14:03:52 -08:00
Shuting Zhao
9429af277d
update icon in chart.yaml
...
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
2021-02-09 13:30:40 -08:00
Shuting Zhao
b9a64ea41d
release v1.3.2
...
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
2021-02-09 10:59:44 -08:00
Shuting Zhao
db1bfba3f8
release v1.3.2-rc3
2021-02-08 18:15:28 -08:00
Shuting Zhao
77a94fda6b
add "watch" to cluster role kyverno:policycontroller
...
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
2021-02-08 17:35:35 -08:00
Shuting Zhao
7788ae3dba
update chart version
2021-02-03 16:21:15 -08:00
Shuting Zhao
a00d9b1cc9
release v1.3.2-rc2
2021-02-03 14:19:46 -08:00
Jim Bugwadia
ba9d003774
update APICall docs ( #1534 )
...
Signed-off-by: Jim Bugwadia <jim@nirmata.com>
2021-02-03 13:10:02 -08:00
Pooja Singh
32522e7827
namespace selector ( #1532 )
...
* updated crd with namespace selector
Signed-off-by: NoSkillGirl <singhpooja240393@gmail.com>
* added logic for validate
Signed-off-by: NoSkillGirl <singhpooja240393@gmail.com>
* added condition in utils for namespace labels
Signed-off-by: NoSkillGirl <singhpooja240393@gmail.com>
* added function for extracting namespace label using lister
Signed-off-by: NoSkillGirl <singhpooja240393@gmail.com>
* added logic for generate
Signed-off-by: NoSkillGirl <singhpooja240393@gmail.com>
* added lister in generate
Signed-off-by: NoSkillGirl <singhpooja240393@gmail.com>
* commented generate controller changes
Signed-off-by: NoSkillGirl <singhpooja240393@gmail.com>
* added ns lister
Signed-off-by: NoSkillGirl <singhpooja240393@gmail.com>
* added ns label in apply.go
Signed-off-by: NoSkillGirl <singhpooja240393@gmail.com>
* added ns label in generation.go
Signed-off-by: NoSkillGirl <singhpooja240393@gmail.com>
* added ns label in mutation.go
Signed-off-by: NoSkillGirl <singhpooja240393@gmail.com>
* added ns label for validation
Signed-off-by: NoSkillGirl <singhpooja240393@gmail.com>
* using dynaminc informer
Signed-off-by: NoSkillGirl <singhpooja240393@gmail.com>
2021-02-03 13:09:42 -08:00
Yashvardhan Kukreja
b4ab5413fd
added: hostNetwork toggle and dnsPolicy option to the dep. and values manifests ( #1511 )
...
Signed-off-by: Yashvardhan Kukreja <yash.kukreja.98@gmail.com>
2021-02-01 17:44:11 -08:00
Jim Bugwadia
e8e3b93a5f
api server lookups ( #1514 )
...
* initial commit for api server lookups
Signed-off-by: Jim Bugwadia <jim@nirmata.com>
* initial commit for API server lookups
Signed-off-by: Jim Bugwadia <jim@nirmata.com>
* Enhancing dockerfiles (multi-stage) of kyverno components and adding non-root user to the docker images (#1495 )
* Dockerfile refactored
Signed-off-by: Raj Babu Das <mail.rajdas@gmail.com>
* Adding non-root commands to docker images and enhanced the dockerfiles
Signed-off-by: Raj Babu Das <mail.rajdas@gmail.com>
* changing base image to scratch
Signed-off-by: Raj Babu Das <mail.rajdas@gmail.com>
* Minor typo fix
Signed-off-by: Raj Babu Das <mail.rajdas@gmail.com>
* changing dockerfiles to use /etc/passwd to use non-root user'
Signed-off-by: Raj Babu Das <mail.rajdas@gmail.com>
* minor typo
Signed-off-by: Raj Babu Das <mail.rajdas@gmail.com>
* minor typo
Signed-off-by: Raj Babu Das <mail.rajdas@gmail.com>
Signed-off-by: Jim Bugwadia <jim@nirmata.com>
* revert cli image name (#1507 )
Signed-off-by: Raj Babu Das <mail.rajdas@gmail.com>
Signed-off-by: Jim Bugwadia <jim@nirmata.com>
* Refactor resourceCache; Reduce throttling requests (background controller) (#1500 )
* skip sending API request for filtered resource
* fix PR comment
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* fixes https://github.com/kyverno/kyverno/issues/1490
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* fix bug - namespace is not returned properly
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* reduce throttling - list resource using lister
* refactor resource cache
* fix test
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* fix label selector
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
* fix build failure
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
Signed-off-by: Jim Bugwadia <jim@nirmata.com>
* fix merge issues
Signed-off-by: Jim Bugwadia <jim@nirmata.com>
* fix unit test
Signed-off-by: Jim Bugwadia <jim@nirmata.com>
* add nil check for API client
Signed-off-by: Jim Bugwadia <jim@nirmata.com>
Co-authored-by: Raj Babu Das <mail.rajdas@gmail.com>
Co-authored-by: shuting <shutting06@gmail.com>
2021-02-01 12:59:13 -08:00
Jim Bugwadia
81c7205e42
Merge pull request #1493 from rajdas98/helm-psp
...
Adding cluster policies(default, restricted) to kyverno helm charts
2021-01-26 10:28:15 -08:00
Shuting Zhao
7d8c404922
generate 1.3.2-rc1
2021-01-24 21:06:30 -08:00
Raj Babu Das
5d7d7157ad
Changing policyType to podSecurityStandard
...
Signed-off-by: Raj Babu Das <mail.rajdas@gmail.com>
2021-01-24 14:05:50 +05:30
Raj Babu Das
bb9e73a316
Adding policies(default, restricted) to kyverno helm charts
...
Signed-off-by: Raj Babu Das <mail.rajdas@gmail.com>
2021-01-24 05:09:47 +05:30
Shuting Zhao
aca98d3748
release v1.3.1
...
Signed-off-by: Shuting Zhao <shutting06@gmail.com>
2021-01-19 12:06:26 -08:00
Shuting Zhao
a3aad806a8
release v1.3.0
2021-01-12 12:08:02 -08:00
Shuting Zhao
b0966de04d
release v1.3.0-rc12
2021-01-08 18:18:30 -08:00
shuting
3908808e7a
Rename filterK8Resources to filterK8sResources ( #1452 )
...
* Remove lock embedded in CRD controller, use concurrent map to store shcemas
* delete rcr info from data store
* skip policy validation on status update
* - remove status check in policy mutation; - fix test
* Remove fqdncn flag
* add flag profiling port
* skip policy mutation & validation on status update
* sync policy status every minute
* update log messages
* rename filterK8Resources to filterK8sResources
2021-01-07 11:27:50 -08:00
Jim Bugwadia
e23a25b68c
release v1.3.0-rc11
2021-01-03 20:41:00 -08:00
Jim Bugwadia
cb06e64e03
release 1.3.0-rc10
2021-01-02 01:26:42 -08:00
Jim Bugwadia
c4296d2282
release 1.3.0-rc9
2021-01-01 17:15:01 -08:00
shuting
3c5f9f8888
1398 - Reduce RCR throttling requests ( #1406 )
...
* reduce RCR throttling requests by merging policy application (policy - namespace) results into single RCR
* - refactor policy controller; - fix RCR issue
* - refactor RCR controller; - fix cpolr on ns update; - reduce throttling when getting resources; - fix tests
* update CRD schema
* fix typo
2020-12-21 11:04:19 -08:00
Shuting Zhao
8b1d84f32c
increase memory limit to 256 Mi
2020-12-15 17:55:01 -08:00
Jim Bugwadia
8f5795725b
update CRDs
2020-12-14 02:56:21 -08:00
Shuting Zhao
ce19b5668d
tag v1.3.0-rc8
2020-12-09 09:31:33 -08:00
Shuting Zhao
d8d90235f3
tag v1.3.0-rc7
2020-12-07 12:32:04 -08:00
shuting
630a9cc94c
Fix Kyverno crash when CRD is not installed ( #1353 )
...
* ignore Kyverno CRDs existence check when server is not available
* clean up cluster / reportChangeRequest
* resolve PR comments
2020-12-03 19:19:36 -08:00
Jim Bugwadia
981bb1cf2d
update CRDs
2020-12-02 12:26:59 -08:00
Jim Bugwadia
76b6974fc2
update CRD docs
2020-12-01 23:19:08 -08:00
Shuting Zhao
921cb67a9e
tag v1.3.0-rc6
2020-12-01 12:52:46 -08:00
Shuting Zhao
45dd5b736d
update short names, scope
2020-12-01 12:52:17 -08:00
shuting
370828afec
Fix typo, add short names ( #1344 )
...
* fix typo
* add short names for report change request
2020-11-30 23:26:49 -08:00