v0.15.0
·
22 commits
to main
since this release
[gardener/diki]
⚠️ Breaking Changes
[USER]
Removed rule2006
from thesecurity-hardened-shoot-cluster
ruleset for providergarden
since Kubernetes versionv1.26
is no longer supported in Gardenerv1.114.0
and optionenableStaticTokenKubeconfig
cannot be set to true. by @gardener-ci-robot [#446]
✨ New Features
[USER]
Security Hardened Shoot Cluster rule 2006 is now skipped. Optionspec.kubernetes.kubelet.enableStaticTokenKubeconfig
cannot be set to true since Gardenerv1.114.0
. by @gardener-ci-robot [#446][USER]
DISA Kubernetes STIG rule 242399 is now skipped for all providers. Optionfeature-gates.DynamicKubeletConfig
removed in Kubernetesv1.26
. by @gardener-ci-robot [#446][USER]
Multiple rules that checkPod
containers from.spec.containers
now also check containers from.spec.initContainers
. by @AleksandarSavchev [#434][USER]
Release versionv0.2.0
of Security Hardened Shoot Cluster Guide. by @AleksandarSavchev [#463][USER]
Implementation for rule1001
from thesecurity-hardened-shoot-cluster
ruleset for providergarden
. by @georgibaltiev [#462][USER]
Implementation for rule1003
from thesecurity-hardened-shoot-cluster
ruleset for providergarden
. by @AleksandarSavchev [#454][USER]
Implementation for rule1002
from thesecurity-hardened-shoot-cluster
ruleset for providergarden
. by @AleksandarSavchev [#433]
🐛 Bug Fixes
[USER]
Fixed a bug which was causing DISA STIG rule 242436 to fail whenValidatingAdmissionWebhook
is not set inenable-admission-plugins
even though it is defaulted. by @AleksandarSavchev [#453]
Docker Images
- diki-ops:
europe-docker.pkg.dev/gardener-project/releases/gardener/diki-ops:v0.15.0
- diki:
europe-docker.pkg.dev/gardener-project/releases/gardener/diki:v0.15.0