⚙️ Generating VAP (Validating Admission Policy) in Gatekeeper has transitioned from using annotations to specifying fields in ConstraintTemplate and Constraint. Please find out more details using VAP through Gatekeeper.
🎬 Ability to enforce specific action for Gatekeeper webhook, audit, gator, or VAP in the same constraint through scopedEnforcementActions field under spec in Constraints.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
- `@dependabot ignore minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
- `@dependabot ignore ` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore ` will remove all of the ignore conditions of the specified dependency
- `@dependabot unignore ` will remove the ignore condition of the specified dependency and ignore conditions
Bumps the k8s-go-deps group with 3 updates in the / directory: github.com/open-policy-agent/gatekeeper/v3, k8s.io/klog/v2 and sigs.k8s.io/secrets-store-csi-driver.
Updates
github.com/open-policy-agent/gatekeeper/v3
from 3.16.3 to 3.17.1Release notes
Sourced from github.com/open-policy-agent/gatekeeper/v3's releases.
... (truncated)
Commits
e8d5d49
chore: Prepare v3.17.1 release (#3539)766b53b
fix: liniting error in gatekeeper-controller-manager-poddisruptionbudget.yaml...0cb7ef2
fix: vap error logging for rego only templates, cherry-pick (#3520) (#3525)d01aa68
chore: Prepare v3.17.0 release (#3509)a5e097d
chore: Prepare v3.17.0-rc.1 release (#3496)916f838
fix: fixing error reporting for templates without CEL, cherry-pick (#3493) (#...3f9ba17
chore: Prepare v3.17.0-rc.0 release (#3490)e23e53e
chore: bump golang fromaf9b40f
to39b7e6e
in /build/tooling (#3488)b222d13
chore: Removing setting alpha flags for vap/vapb generation unless explicitly...5ef6d32
chore: bump github.com/docker/docker from 26.1.4+incompatible to 26.1.5+incom...Updates
k8s.io/api
from 0.29.5 to 0.30.3Commits
83bdab1
Update dependencies to v0.30.3 tag0fd470c
Merge pull request #124702aojea/automated-cherry-pick-of-#124572
a669f18
Merge pull request #124694 from pmalek/backport-124553-to-release-1.3015001b5
fix(api): make LocalObjectReference.Name and HostAlias.IP required (#124553)d9a08c5
tag service.spec.TrafficDistribution field as alphad014286
Merge remote-tracking branch 'origin/master' into release-1.30581c1b8
Update x/net for CVE-2023-4528835ca1f4
Merge pull request #123932 from pohly/dra-api-resource-model-renameb048bd8
Merge pull request #123909 from AkihiroSuda/fix-123906f06d24a
dra api: NodeResourceModel -> ResourceModelUpdates
k8s.io/apiextensions-apiserver
from 0.29.5 to 0.30.3Commits
1aec848
Update dependencies to v0.30.3 tag803669d
Merge pull request #124676cici37/automated-cherry-pick-of-#124675
5e9c693
Adding the feature gates to fix cost for VAP and webhook matchConditions.cb47ad4
Merge remote-tracking branch 'origin/master' into release-1.306ce7f38
Update x/net for CVE-2023-45288a2f312c
Merge remote-tracking branch 'origin/master' into release-1.30d3649bc
fix test flake caused by not waiting for CRD schema update9624e52
Merge pull request #123732 from serathius/parallel-featureflags24438a9
Merge pull request #123758 from liggitt/protobump916521e
Bump github.com/golang/protobuf v1.5.4, google.golang.org/protobuf v1.33.0Updates
k8s.io/apimachinery
from 0.29.5 to 0.30.3Commits
37988e5
Merge remote-tracking branch 'origin/master' into release-1.30c857a38
Update x/net for CVE-2023-452880407311
followup to allow special characters25164f7
Merge pull request #123435 from tallclair/apparmor-gacbfe0a1
Merge pull request #123758 from liggitt/protobump21d26b6
Bump github.com/golang/protobuf v1.5.4, google.golang.org/protobuf v1.33.00c29f84
Merge pull request #123385 from HirazawaUi/allow-special-characters60d24f2
Merge pull request #123708 from p0lyn0mial/upstream-const-watchlist-bookmark-...513d23a
apimachinery/meta/types.go: define InitialEventsAnnotationKey const67cb3a8
Merge pull request #123413 from seans3/tunneling-spdy-websocketsUpdates
k8s.io/client-go
from 0.29.5 to 0.30.3Commits
ece8c00
Update dependencies to v0.30.3 tag4e1652b
Merge pull request #124694 from pmalek/backport-124553-to-release-1.302daa31e
fix(api): make LocalObjectReference.Name and HostAlias.IP required (#124553)2df4de1
Merge remote-tracking branch 'origin/master' into release-1.30ade2ae2
Update x/net for CVE-2023-45288b4632b7
Merge pull request #123932 from pohly/dra-api-resource-model-rename4467b1e
Merge pull request #123909 from AkihiroSuda/fix-123906650f392
dra api: NodeResourceModel -> ResourceModel00e4609
api: NodeStatus: rename RuntimeClasses to RuntimeHandlers7ebe0ea
Merge pull request #123180 from AkihiroSuda/rroUpdates
k8s.io/klog/v2
from 2.120.1 to 2.130.1Release notes
Sourced from k8s.io/klog/v2's releases.
Commits
75663bb
Merge pull request #408 from pohly/klog-flush-sync-fix2327d4c
data race: avoid unprotected access to sb.file16c7d26
Merge pull request #401 from pohly/ktesting-warning-delaycd24012
ktesting: tone down warning about leaked test goroutine2ee202a
Merge pull request #404 from 1978629634/fsync-freelock79575d8
Do not acquire lock for file.Sync() fsync call7af45d6
Merge pull request #406 from pohly/linterd008cfe
examples: fix linter warningab53041
Merge pull request #402 from pohly/linter-issuesff7c070
build: fix some linter warningsUpdates
k8s.io/utils
from 0.0.0-20230726121419-3b25d923346b to 0.0.0-20240502163921-fe8a2dddb1d0Commits
Updates
sigs.k8s.io/controller-runtime
from 0.17.5 to 0.18.4Release notes
Sourced from sigs.k8s.io/controller-runtime's releases.
... (truncated)
Commits
12cc8d5
Merge pull request #2848 from k8s-infra-cherrypick-robot/cherry-pick-2847-to-...c0c229e
controllerutil: allow configuring BlockOwnerDeletion when setting OwnerRefere...be2f383
Merge pull request #2840 from sbueringer/pr-bump-k8s4720d17
Bump k8s.io/* to v0.30.1aa9ed14
Merge pull request #2837 from sbueringer/pr-setup-envtest-ct-rel-0.1835d7bbd
default --use-deprecated-gcs to truece4e4f5
some more deprecations56dcc14
setup-envtest: allow downloading envtest binaries from controller-tools834905b
Merge pull request #2817 from k8s-infra-cherrypick-robot/cherry-pick-2813-to-...6396a49
Reintroduce AddMetricsExtraHandler on managerUpdates
sigs.k8s.io/secrets-store-csi-driver
from 1.3.4 to 1.4.6Release notes
Sourced from sigs.k8s.io/secrets-store-csi-driver's releases.
... (truncated)
Commits
d856171
Merge pull request #1664 from aramase/aramase/ci/update_goreleaser_config_rel...a2c307a
ci: update goreleaser config for v2951559c
Merge pull request #1663nilekhc/automated-cherry-pick-of-#1662
4716b26
release: update manifest and helm charts for v1.4.6d5fbc3e
Merge pull request #1659 from nilekhc/nilekh/c/bump-driver-release-v1.4.63adbfdd
Merge pull request #1661nilekhc/automated-cherry-pick-of-#1660
b52af8c
chore: bumps base images71941d5
chore: bumps version for v1.4.6 releasee5b8e5c
Merge pull request #1610aramase/automated-cherry-pick-of-#1559
fff3865
ci: use v2 for goreleaserDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show