Starting from v1.19 Kubernetes is built against Go 1.15 which in turn disables validation of the webhook certificate CN field. The Gatekeeper version shipped in fury-kubernetes-opa v1.1.0 does not create a certificate using the SANs field, hence the API server fails to contact the webhook.
Starting from v1.19 Kubernetes is built against Go 1.15 which in turn disables validation of the webhook certificate
CN
field. The Gatekeeper version shipped infury-kubernetes-opa
v1.1.0 does not create a certificate using the SANs field, hence the API server fails to contact the webhook.References: