diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 7f33ed1..e36d166 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -18,6 +18,6 @@ jobs: registry-server: ghcr.io registry-username: ${{ github.actor }} image: ${{ github.repository }} - version: 1.11.1 + version: 1.11.3 secrets: pull-request-token: ${{ secrets.GH_ORG_PAT }} diff --git a/package/config/upstream/install.yaml b/package/config/upstream/install.yaml index 2447d83..b5fe1e7 100644 --- a/package/config/upstream/install.yaml +++ b/package/config/upstream/install.yaml @@ -6,7 +6,7 @@ metadata: labels: app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 --- apiVersion: v1 kind: ServiceAccount @@ -17,7 +17,7 @@ metadata: app.kubernetes.io/component: admission-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 --- apiVersion: v1 kind: ServiceAccount @@ -28,7 +28,7 @@ metadata: app.kubernetes.io/component: background-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 --- apiVersion: v1 kind: ServiceAccount @@ -39,7 +39,7 @@ metadata: app.kubernetes.io/component: cleanup-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 --- apiVersion: v1 kind: ServiceAccount @@ -49,7 +49,7 @@ metadata: labels: app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 --- apiVersion: v1 kind: ServiceAccount @@ -60,7 +60,7 @@ metadata: app.kubernetes.io/component: reports-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 --- apiVersion: v1 kind: ConfigMap @@ -71,7 +71,7 @@ metadata: app.kubernetes.io/component: config app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 data: enableDefaultRegistryMutation: "true" defaultRegistry: "docker.io" @@ -199,7 +199,7 @@ metadata: app.kubernetes.io/component: config app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 data: namespaces: "{\"exclude\":[],\"include\":[]}" bucketBoundaries: "0.005, 0.01, 0.025, 0.05, 0.1, 0.25, 0.5, 1, 2.5, 5, 10, 15, 20, 25, 30" @@ -212,8 +212,8 @@ metadata: app.kubernetes.io/instance: kyverno app.kubernetes.io/managed-by: Helm app.kubernetes.io/part-of: kyverno-crds - app.kubernetes.io/version: 3.1.1 - helm.sh/chart: crds-3.1.1 + app.kubernetes.io/version: 3.1.3 + helm.sh/chart: crds-3.1.3 annotations: controller-gen.kubebuilder.io/version: v0.12.0 name: admissionreports.kyverno.io @@ -251,11 +251,9 @@ spec: type: integer - jsonPath: .metadata.labels['audit\.kyverno\.io/resource\.gvr'] name: GVR - priority: 1 type: string - jsonPath: .metadata.labels['audit\.kyverno\.io/resource\.name'] name: REF - priority: 1 type: string - jsonPath: .metadata.labels['audit\.kyverno\.io/report\.aggregate'] name: AGGREGATE @@ -551,8 +549,8 @@ metadata: app.kubernetes.io/instance: kyverno app.kubernetes.io/managed-by: Helm app.kubernetes.io/part-of: kyverno-crds - app.kubernetes.io/version: 3.1.1 - helm.sh/chart: crds-3.1.1 + app.kubernetes.io/version: 3.1.3 + helm.sh/chart: crds-3.1.3 annotations: controller-gen.kubebuilder.io/version: v0.12.0 name: backgroundscanreports.kyverno.io @@ -572,15 +570,12 @@ spec: - additionalPrinterColumns: - jsonPath: .metadata.ownerReferences[0].apiVersion name: ApiVersion - priority: 1 type: string - jsonPath: .metadata.ownerReferences[0].kind name: Kind - priority: 1 type: string - jsonPath: .metadata.ownerReferences[0].name name: Subject - priority: 1 type: string - jsonPath: .spec.summary.pass name: Pass @@ -858,8 +853,8 @@ metadata: app.kubernetes.io/instance: kyverno app.kubernetes.io/managed-by: Helm app.kubernetes.io/part-of: kyverno-crds - app.kubernetes.io/version: 3.1.1 - helm.sh/chart: crds-3.1.1 + app.kubernetes.io/version: 3.1.3 + helm.sh/chart: crds-3.1.3 annotations: controller-gen.kubebuilder.io/version: v0.12.0 name: cleanuppolicies.kyverno.io @@ -3368,8 +3363,8 @@ metadata: app.kubernetes.io/instance: kyverno app.kubernetes.io/managed-by: Helm app.kubernetes.io/part-of: kyverno-crds - app.kubernetes.io/version: 3.1.1 - helm.sh/chart: crds-3.1.1 + app.kubernetes.io/version: 3.1.3 + helm.sh/chart: crds-3.1.3 annotations: controller-gen.kubebuilder.io/version: v0.12.0 name: clusteradmissionreports.kyverno.io @@ -3407,11 +3402,9 @@ spec: type: integer - jsonPath: .metadata.labels['audit\.kyverno\.io/resource\.gvr'] name: GVR - priority: 1 type: string - jsonPath: .metadata.labels['audit\.kyverno\.io/resource\.name'] name: REF - priority: 1 type: string - jsonPath: .metadata.labels['audit\.kyverno\.io/report\.aggregate'] name: AGGREGATE @@ -3708,8 +3701,8 @@ metadata: app.kubernetes.io/instance: kyverno app.kubernetes.io/managed-by: Helm app.kubernetes.io/part-of: kyverno-crds - app.kubernetes.io/version: 3.1.1 - helm.sh/chart: crds-3.1.1 + app.kubernetes.io/version: 3.1.3 + helm.sh/chart: crds-3.1.3 annotations: controller-gen.kubebuilder.io/version: v0.12.0 name: clusterbackgroundscanreports.kyverno.io @@ -3729,15 +3722,12 @@ spec: - additionalPrinterColumns: - jsonPath: .metadata.ownerReferences[0].apiVersion name: ApiVersion - priority: 1 type: string - jsonPath: .metadata.ownerReferences[0].kind name: Kind - priority: 1 type: string - jsonPath: .metadata.ownerReferences[0].name name: Subject - priority: 1 type: string - jsonPath: .spec.summary.pass name: Pass @@ -4015,8 +4005,8 @@ metadata: app.kubernetes.io/instance: kyverno app.kubernetes.io/managed-by: Helm app.kubernetes.io/part-of: kyverno-crds - app.kubernetes.io/version: 3.1.1 - helm.sh/chart: crds-3.1.1 + app.kubernetes.io/version: 3.1.3 + helm.sh/chart: crds-3.1.3 annotations: controller-gen.kubebuilder.io/version: v0.12.0 name: clustercleanuppolicies.kyverno.io @@ -6525,8 +6515,8 @@ metadata: app.kubernetes.io/instance: kyverno app.kubernetes.io/managed-by: Helm app.kubernetes.io/part-of: kyverno-crds - app.kubernetes.io/version: 3.1.1 - helm.sh/chart: crds-3.1.1 + app.kubernetes.io/version: 3.1.3 + helm.sh/chart: crds-3.1.3 annotations: controller-gen.kubebuilder.io/version: v0.12.0 name: clusterpolicies.kyverno.io @@ -8935,6 +8925,13 @@ spec: is supported for backwards compatibility but will be deprecated in the next major release. See: https://kyverno.io/docs/writing-policies/preconditions/' x-kubernetes-preserve-unknown-fields: true + skipBackgroundRequests: + default: true + description: SkipBackgroundRequests bypasses admission requests + that are sent by the background controller. The default value + is set to "true", it must be set to "false" to apply generate + and mutateExisting rules to those requests. + type: boolean validate: description: Validation is used to validate matching resources. properties: @@ -9885,7 +9882,7 @@ spec: default: sha256 description: Specify signature algorithm for public keys. Supported values - are sha256 and sha512. + are sha224, sha256, sha384 and sha512. type: string type: object repository: @@ -10342,7 +10339,8 @@ spec: default: sha256 description: Specify signature algorithm for public keys. Supported values - are sha256 and sha512. + are sha224, sha256, sha384 and + sha512. type: string type: object repository: @@ -10758,7 +10756,7 @@ spec: default: sha256 description: Specify signature algorithm for public keys. Supported values are - sha256 and sha512. + sha224, sha256, sha384 and sha512. type: string type: object repository: @@ -13369,6 +13367,13 @@ spec: is supported for backwards compatibility but will be deprecated in the next major release. See: https://kyverno.io/docs/writing-policies/preconditions/' x-kubernetes-preserve-unknown-fields: true + skipBackgroundRequests: + default: true + description: SkipBackgroundRequests bypasses admission requests + that are sent by the background controller. The default + value is set to "true", it must be set to "false" to apply + generate and mutateExisting rules to those requests. + type: boolean validate: description: Validation is used to validate matching resources. properties: @@ -14370,7 +14375,8 @@ spec: default: sha256 description: Specify signature algorithm for public keys. Supported values - are sha256 and sha512. + are sha224, sha256, sha384 and + sha512. type: string type: object repository: @@ -14856,8 +14862,8 @@ spec: default: sha256 description: Specify signature algorithm for public keys. - Supported values are sha256 - and sha512. + Supported values are sha224, + sha256, sha384 and sha512. type: string type: object repository: @@ -15295,7 +15301,7 @@ spec: default: sha256 description: Specify signature algorithm for public keys. Supported values - are sha256 and sha512. + are sha224, sha256, sha384 and sha512. type: string type: object repository: @@ -17585,6 +17591,13 @@ spec: type: object type: array type: object + skipBackgroundRequests: + default: true + description: SkipBackgroundRequests bypasses admission requests + that are sent by the background controller. The default value + is set to "true", it must be set to "false" to apply generate + and mutateExisting rules to those requests. + type: boolean validate: description: Validation is used to validate matching resources. properties: @@ -18627,7 +18640,7 @@ spec: default: sha256 description: Specify signature algorithm for public keys. Supported values - are sha256 and sha512. + are sha224, sha256, sha384 and sha512. type: string type: object repository: @@ -19073,7 +19086,8 @@ spec: default: sha256 description: Specify signature algorithm for public keys. Supported values - are sha256 and sha512. + are sha224, sha256, sha384 and + sha512. type: string type: object repository: @@ -19489,7 +19503,7 @@ spec: default: sha256 description: Specify signature algorithm for public keys. Supported values are - sha256 and sha512. + sha224, sha256, sha384 and sha512. type: string type: object repository: @@ -22085,6 +22099,13 @@ spec: is supported for backwards compatibility but will be deprecated in the next major release. See: https://kyverno.io/docs/writing-policies/preconditions/' x-kubernetes-preserve-unknown-fields: true + skipBackgroundRequests: + default: true + description: SkipBackgroundRequests bypasses admission requests + that are sent by the background controller. The default + value is set to "true", it must be set to "false" to apply + generate and mutateExisting rules to those requests. + type: boolean validate: description: Validation is used to validate matching resources. properties: @@ -23086,7 +23107,8 @@ spec: default: sha256 description: Specify signature algorithm for public keys. Supported values - are sha256 and sha512. + are sha224, sha256, sha384 and + sha512. type: string type: object repository: @@ -23572,8 +23594,8 @@ spec: default: sha256 description: Specify signature algorithm for public keys. - Supported values are sha256 - and sha512. + Supported values are sha224, + sha256, sha384 and sha512. type: string type: object repository: @@ -24011,7 +24033,7 @@ spec: default: sha256 description: Specify signature algorithm for public keys. Supported values - are sha256 and sha512. + are sha224, sha256, sha384 and sha512. type: string type: object repository: @@ -24258,8 +24280,8 @@ metadata: app.kubernetes.io/instance: kyverno app.kubernetes.io/managed-by: Helm app.kubernetes.io/part-of: kyverno-crds - app.kubernetes.io/version: 3.1.1 - helm.sh/chart: crds-3.1.1 + app.kubernetes.io/version: 3.1.3 + helm.sh/chart: crds-3.1.3 annotations: controller-gen.kubebuilder.io/version: v0.12.0 name: policies.kyverno.io @@ -26669,6 +26691,13 @@ spec: is supported for backwards compatibility but will be deprecated in the next major release. See: https://kyverno.io/docs/writing-policies/preconditions/' x-kubernetes-preserve-unknown-fields: true + skipBackgroundRequests: + default: true + description: SkipBackgroundRequests bypasses admission requests + that are sent by the background controller. The default value + is set to "true", it must be set to "false" to apply generate + and mutateExisting rules to those requests. + type: boolean validate: description: Validation is used to validate matching resources. properties: @@ -27619,7 +27648,7 @@ spec: default: sha256 description: Specify signature algorithm for public keys. Supported values - are sha256 and sha512. + are sha224, sha256, sha384 and sha512. type: string type: object repository: @@ -28076,7 +28105,8 @@ spec: default: sha256 description: Specify signature algorithm for public keys. Supported values - are sha256 and sha512. + are sha224, sha256, sha384 and + sha512. type: string type: object repository: @@ -28492,7 +28522,7 @@ spec: default: sha256 description: Specify signature algorithm for public keys. Supported values are - sha256 and sha512. + sha224, sha256, sha384 and sha512. type: string type: object repository: @@ -31104,6 +31134,13 @@ spec: is supported for backwards compatibility but will be deprecated in the next major release. See: https://kyverno.io/docs/writing-policies/preconditions/' x-kubernetes-preserve-unknown-fields: true + skipBackgroundRequests: + default: true + description: SkipBackgroundRequests bypasses admission requests + that are sent by the background controller. The default + value is set to "true", it must be set to "false" to apply + generate and mutateExisting rules to those requests. + type: boolean validate: description: Validation is used to validate matching resources. properties: @@ -32105,7 +32142,8 @@ spec: default: sha256 description: Specify signature algorithm for public keys. Supported values - are sha256 and sha512. + are sha224, sha256, sha384 and + sha512. type: string type: object repository: @@ -32591,8 +32629,8 @@ spec: default: sha256 description: Specify signature algorithm for public keys. - Supported values are sha256 - and sha512. + Supported values are sha224, + sha256, sha384 and sha512. type: string type: object repository: @@ -33030,7 +33068,7 @@ spec: default: sha256 description: Specify signature algorithm for public keys. Supported values - are sha256 and sha512. + are sha224, sha256, sha384 and sha512. type: string type: object repository: @@ -35321,6 +35359,13 @@ spec: type: object type: array type: object + skipBackgroundRequests: + default: true + description: SkipBackgroundRequests bypasses admission requests + that are sent by the background controller. The default value + is set to "true", it must be set to "false" to apply generate + and mutateExisting rules to those requests. + type: boolean validate: description: Validation is used to validate matching resources. properties: @@ -36363,7 +36408,7 @@ spec: default: sha256 description: Specify signature algorithm for public keys. Supported values - are sha256 and sha512. + are sha224, sha256, sha384 and sha512. type: string type: object repository: @@ -36809,7 +36854,8 @@ spec: default: sha256 description: Specify signature algorithm for public keys. Supported values - are sha256 and sha512. + are sha224, sha256, sha384 and + sha512. type: string type: object repository: @@ -37225,7 +37271,7 @@ spec: default: sha256 description: Specify signature algorithm for public keys. Supported values are - sha256 and sha512. + sha224, sha256, sha384 and sha512. type: string type: object repository: @@ -39821,6 +39867,13 @@ spec: is supported for backwards compatibility but will be deprecated in the next major release. See: https://kyverno.io/docs/writing-policies/preconditions/' x-kubernetes-preserve-unknown-fields: true + skipBackgroundRequests: + default: true + description: SkipBackgroundRequests bypasses admission requests + that are sent by the background controller. The default + value is set to "true", it must be set to "false" to apply + generate and mutateExisting rules to those requests. + type: boolean validate: description: Validation is used to validate matching resources. properties: @@ -40822,7 +40875,8 @@ spec: default: sha256 description: Specify signature algorithm for public keys. Supported values - are sha256 and sha512. + are sha224, sha256, sha384 and + sha512. type: string type: object repository: @@ -41308,8 +41362,8 @@ spec: default: sha256 description: Specify signature algorithm for public keys. - Supported values are sha256 - and sha512. + Supported values are sha224, + sha256, sha384 and sha512. type: string type: object repository: @@ -41747,7 +41801,7 @@ spec: default: sha256 description: Specify signature algorithm for public keys. Supported values - are sha256 and sha512. + are sha224, sha256, sha384 and sha512. type: string type: object repository: @@ -41994,8 +42048,8 @@ metadata: app.kubernetes.io/instance: kyverno app.kubernetes.io/managed-by: Helm app.kubernetes.io/part-of: kyverno-crds - app.kubernetes.io/version: 3.1.1 - helm.sh/chart: crds-3.1.1 + app.kubernetes.io/version: 3.1.3 + helm.sh/chart: crds-3.1.3 annotations: controller-gen.kubebuilder.io/version: v0.12.0 name: policyexceptions.kyverno.io @@ -43020,8 +43074,8 @@ metadata: app.kubernetes.io/instance: kyverno app.kubernetes.io/managed-by: Helm app.kubernetes.io/part-of: kyverno-crds - app.kubernetes.io/version: 3.1.1 - helm.sh/chart: crds-3.1.1 + app.kubernetes.io/version: 3.1.3 + helm.sh/chart: crds-3.1.3 annotations: controller-gen.kubebuilder.io/version: v0.12.0 name: updaterequests.kyverno.io @@ -43412,6 +43466,8 @@ spec: message: description: Specifies request status message. type: string + retryCount: + type: integer state: description: State represents state of the update request. type: string @@ -43432,8 +43488,8 @@ metadata: app.kubernetes.io/instance: kyverno app.kubernetes.io/managed-by: Helm app.kubernetes.io/part-of: kyverno-crds - app.kubernetes.io/version: 3.1.1 - helm.sh/chart: crds-3.1.1 + app.kubernetes.io/version: 3.1.3 + helm.sh/chart: crds-3.1.3 annotations: controller-gen.kubebuilder.io/version: v0.12.0 name: clusterpolicyreports.wgpolicyk8s.io @@ -43451,11 +43507,9 @@ spec: - additionalPrinterColumns: - jsonPath: .scope.kind name: Kind - priority: 1 type: string - jsonPath: .scope.name name: Name - priority: 1 type: string - jsonPath: .summary.pass name: Pass @@ -43801,8 +43855,8 @@ metadata: app.kubernetes.io/instance: kyverno app.kubernetes.io/managed-by: Helm app.kubernetes.io/part-of: kyverno-crds - app.kubernetes.io/version: 3.1.1 - helm.sh/chart: crds-3.1.1 + app.kubernetes.io/version: 3.1.3 + helm.sh/chart: crds-3.1.3 annotations: controller-gen.kubebuilder.io/version: v0.12.0 name: policyreports.wgpolicyk8s.io @@ -43820,11 +43874,9 @@ spec: - additionalPrinterColumns: - jsonPath: .scope.kind name: Kind - priority: 1 type: string - jsonPath: .scope.name name: Name - priority: 1 type: string - jsonPath: .summary.pass name: Pass @@ -44169,7 +44221,7 @@ metadata: app.kubernetes.io/component: admission-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 aggregationRule: clusterRoleSelectors: - matchLabels: @@ -44185,7 +44237,7 @@ metadata: app.kubernetes.io/component: admission-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 rules: - apiGroups: - admissionregistration.k8s.io @@ -44281,7 +44333,7 @@ metadata: app.kubernetes.io/component: background-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 aggregationRule: clusterRoleSelectors: - matchLabels: @@ -44297,7 +44349,7 @@ metadata: app.kubernetes.io/component: background-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 rules: - apiGroups: - kyverno.io @@ -44387,7 +44439,7 @@ metadata: app.kubernetes.io/component: cleanup-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 aggregationRule: clusterRoleSelectors: - matchLabels: @@ -44403,7 +44455,7 @@ metadata: app.kubernetes.io/component: cleanup-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 rules: - apiGroups: - admissionregistration.k8s.io @@ -44470,7 +44522,7 @@ metadata: labels: app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 rules: - apiGroups: - kyverno.io @@ -44490,7 +44542,7 @@ metadata: app.kubernetes.io/component: rbac app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 rbac.authorization.k8s.io/aggregate-to-admin: "true" rules: - apiGroups: @@ -44517,7 +44569,7 @@ metadata: app.kubernetes.io/component: rbac app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 rbac.authorization.k8s.io/aggregate-to-view: "true" rules: - apiGroups: @@ -44540,7 +44592,7 @@ metadata: app.kubernetes.io/component: rbac app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 rbac.authorization.k8s.io/aggregate-to-admin: "true" rules: - apiGroups: @@ -44565,7 +44617,7 @@ metadata: app.kubernetes.io/component: rbac app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 rbac.authorization.k8s.io/aggregate-to-view: "true" rules: - apiGroups: @@ -44586,7 +44638,7 @@ metadata: app.kubernetes.io/component: rbac app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 rbac.authorization.k8s.io/aggregate-to-admin: "true" rules: - apiGroups: @@ -44613,7 +44665,7 @@ metadata: app.kubernetes.io/component: rbac app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 rbac.authorization.k8s.io/aggregate-to-view: "true" rules: - apiGroups: @@ -44636,7 +44688,7 @@ metadata: app.kubernetes.io/component: rbac app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 rbac.authorization.k8s.io/aggregate-to-admin: "true" rules: - apiGroups: @@ -44660,7 +44712,7 @@ metadata: app.kubernetes.io/component: rbac app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 rbac.authorization.k8s.io/aggregate-to-view: "true" rules: - apiGroups: @@ -44680,7 +44732,7 @@ metadata: app.kubernetes.io/component: reports-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 aggregationRule: clusterRoleSelectors: - matchLabels: @@ -44696,7 +44748,7 @@ metadata: app.kubernetes.io/component: reports-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 rules: - apiGroups: - '*' @@ -44755,7 +44807,7 @@ metadata: app.kubernetes.io/component: admission-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole @@ -44773,7 +44825,7 @@ metadata: app.kubernetes.io/component: background-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole @@ -44791,7 +44843,7 @@ metadata: app.kubernetes.io/component: cleanup-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole @@ -44808,7 +44860,7 @@ metadata: labels: app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole @@ -44826,7 +44878,7 @@ metadata: app.kubernetes.io/component: reports-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole @@ -44845,7 +44897,7 @@ metadata: app.kubernetes.io/component: admission-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 rules: - apiGroups: - '' @@ -44897,7 +44949,7 @@ metadata: app.kubernetes.io/component: background-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 namespace: kyverno rules: - apiGroups: @@ -44945,7 +44997,7 @@ metadata: app.kubernetes.io/component: cleanup-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 namespace: kyverno rules: - apiGroups: @@ -45004,7 +45056,7 @@ metadata: app.kubernetes.io/component: reports-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 namespace: kyverno rules: - apiGroups: @@ -45045,7 +45097,7 @@ metadata: app.kubernetes.io/component: admission-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 roleRef: apiGroup: rbac.authorization.k8s.io kind: Role @@ -45063,7 +45115,7 @@ metadata: app.kubernetes.io/component: background-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 namespace: kyverno roleRef: apiGroup: rbac.authorization.k8s.io @@ -45082,7 +45134,7 @@ metadata: app.kubernetes.io/component: cleanup-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 namespace: kyverno roleRef: apiGroup: rbac.authorization.k8s.io @@ -45101,7 +45153,7 @@ metadata: app.kubernetes.io/component: reports-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 namespace: kyverno roleRef: apiGroup: rbac.authorization.k8s.io @@ -45121,7 +45173,7 @@ metadata: app.kubernetes.io/component: admission-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 spec: ports: - port: 443 @@ -45143,7 +45195,7 @@ metadata: app.kubernetes.io/component: admission-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 spec: ports: - port: 8000 @@ -45165,7 +45217,7 @@ metadata: app.kubernetes.io/component: background-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 spec: ports: - port: 8000 @@ -45187,7 +45239,7 @@ metadata: app.kubernetes.io/component: cleanup-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 spec: ports: - port: 443 @@ -45209,7 +45261,7 @@ metadata: app.kubernetes.io/component: cleanup-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 spec: ports: - port: 8000 @@ -45231,7 +45283,7 @@ metadata: app.kubernetes.io/component: reports-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 spec: ports: - port: 8000 @@ -45253,7 +45305,7 @@ metadata: app.kubernetes.io/component: admission-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 spec: replicas: strategy: @@ -45272,7 +45324,7 @@ spec: app.kubernetes.io/component: admission-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 spec: dnsPolicy: ClusterFirst affinity: @@ -45290,7 +45342,7 @@ spec: serviceAccountName: kyverno-admission-controller initContainers: - name: kyverno-pre - image: "ghcr.io/kyverno/kyvernopre:v1.11.1" + image: "ghcr.io/kyverno/kyvernopre:v1.11.3" imagePullPolicy: IfNotPresent args: - --loggingFormat=text @@ -45333,7 +45385,7 @@ spec: value: kyverno-svc containers: - name: kyverno - image: "ghcr.io/kyverno/kyverno:v1.11.1" + image: "ghcr.io/kyverno/kyverno:v1.11.3" imagePullPolicy: IfNotPresent args: - --caSecretName=kyverno-svc.kyverno.svc.kyverno-tls-ca @@ -45444,7 +45496,7 @@ metadata: app.kubernetes.io/component: background-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 spec: replicas: strategy: @@ -45463,7 +45515,7 @@ spec: app.kubernetes.io/component: background-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 spec: dnsPolicy: ClusterFirst affinity: @@ -45481,7 +45533,7 @@ spec: serviceAccountName: kyverno-background-controller containers: - name: controller - image: "ghcr.io/kyverno/background-controller:v1.11.1" + image: "ghcr.io/kyverno/background-controller:v1.11.3" imagePullPolicy: IfNotPresent ports: - containerPort: 9443 @@ -45542,7 +45594,7 @@ metadata: app.kubernetes.io/component: cleanup-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 spec: replicas: strategy: @@ -45561,7 +45613,7 @@ spec: app.kubernetes.io/component: cleanup-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 spec: dnsPolicy: ClusterFirst affinity: @@ -45579,7 +45631,7 @@ spec: serviceAccountName: kyverno-cleanup-controller containers: - name: controller - image: "ghcr.io/kyverno/cleanup-controller:v1.11.1" + image: "ghcr.io/kyverno/cleanup-controller:v1.11.3" imagePullPolicy: IfNotPresent ports: - containerPort: 9443 @@ -45673,7 +45725,7 @@ metadata: app.kubernetes.io/component: reports-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 spec: replicas: strategy: @@ -45692,7 +45744,7 @@ spec: app.kubernetes.io/component: reports-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 spec: dnsPolicy: ClusterFirst affinity: @@ -45710,7 +45762,7 @@ spec: serviceAccountName: kyverno-reports-controller containers: - name: controller - image: "ghcr.io/kyverno/reports-controller:v1.11.1" + image: "ghcr.io/kyverno/reports-controller:v1.11.3" imagePullPolicy: IfNotPresent ports: - containerPort: 9443 @@ -45790,7 +45842,7 @@ metadata: app.kubernetes.io/component: cleanup app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 spec: schedule: "*/10 * * * *" concurrencyPolicy: Forbid @@ -45838,7 +45890,7 @@ metadata: app.kubernetes.io/component: cleanup app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno - app.kubernetes.io/version: v1.11.1 + app.kubernetes.io/version: v1.11.3 spec: schedule: "*/10 * * * *" concurrencyPolicy: Forbid diff --git a/package/vendir.lock.yml b/package/vendir.lock.yml index d8bf362..867d2ac 100644 --- a/package/vendir.lock.yml +++ b/package/vendir.lock.yml @@ -2,8 +2,8 @@ apiVersion: vendir.k14s.io/v1alpha1 directories: - contents: - githubRelease: - tag: v1.11.1 - url: https://api.github.com/repos/kyverno/kyverno/releases/131769316 + tag: v1.11.3 + url: https://api.github.com/repos/kyverno/kyverno/releases/135948597 path: . path: config/upstream kind: LockConfig diff --git a/package/vendir.yml b/package/vendir.yml index 33780aa..a674499 100755 --- a/package/vendir.yml +++ b/package/vendir.yml @@ -4,7 +4,7 @@ directories: - githubRelease: disableAutoChecksumValidation: true slug: kyverno/kyverno - tag: v1.11.1 + tag: v1.11.3 includePaths: - install.yaml path: .