gardener-robot-ci-1
released this
09 Dec 15:19
·
7 commits
to main
since this release
[gardener/diki]
⚠️ Breaking Changes
[USER]
ArgumentminPodSecurityLevel
for rule254800
from thedisa-k8s-stig
ruleset for providergardener
was renamed tominPodSecurityStandardsProfile
. by @georgibaltiev [#374]
✨ New Features
[USER]
Rules can now specify severity level. by @georgibaltiev [#352][USER]
Implementation for rule2001
from thesecurity-hardened-k8s
ruleset for providermanagedk8s
. by @AleksandarSavchev [#375][USER]
Implementation for rule2000
from thesecurity-hardened-k8s
ruleset for providermanagedk8s
. by @AleksandarSavchev [#383][USER]
Implementation for rule2007
from thesecurity-hardened-k8s
ruleset for providermanagedk8s
. by @georgibaltiev [#389][USER]
Implementation for rule2002
from thesecurity-hardened-shoot-cluster
ruleset for providergarden
. by @georgibaltiev [#360][USER]
Implementation for rule2002
from thesecurity-hardened-k8s
ruleset for providermanagedk8s
. by @georgibaltiev [#387][USER]
Implementation for rule2003
from thesecurity-hardened-k8s
ruleset for providermanagedk8s
. by @georgibaltiev [#391][USER]
Implementation for rule2006
from thesecurity-hardened-k8s
ruleset for providermanagedk8s
. by @AleksandarSavchev [#382][USER]
Implementation for rule2006
from thesecurity-hardened-shoot-cluster
ruleset for providergarden
. by @georgibaltiev [#366][USER]
Implementation for rule2004
from thesecurity-hardened-k8s
ruleset for providermanagedk8s
. by @AleksandarSavchev [#376][USER]
Implementation for rule2000
from thesecurity-hardened-shoot-cluster
ruleset for providergarden
. by @georgibaltiev [#362][USER]
Severity level has been set to all current rules. by @georgibaltiev [#354][USER]
Implementation for rule2008
from thesecurity-hardened-k8s
ruleset for providermanagedk8s
. by @AleksandarSavchev [#371][USER]
Implementation for rule2007
from thesecurity-hardened-shoot-cluster
ruleset for providergarden
. by @georgibaltiev [#374][USER]
Implementation for rule2005
from thesecurity-hardened-k8s
ruleset for providermanagedk8s
. by @AleksandarSavchev [#380][USER]
Implementation for rule1000
from thesecurity-hardened-shoot-cluster
ruleset for providergarden
. by @georgibaltiev [#381][USER]
Implementation for rule2001
from thesecurity-hardened-shoot-cluster
ruleset for providergarden
. by @georgibaltiev [#358][USER]
Implementation for rule2004
from thesecurity-hardened-shoot-cluster
ruleset for providergarden
. by @georgibaltiev [#365][USER]
Implementation for rule2005
from thesecurity-hardened-shoot-cluster
ruleset for providergarden
. by @georgibaltiev [#363]
🐛 Bug Fixes
[USER]
A bug causing some rules to error when they encounter aPod
without anOwnerReference
has been fixed. by @AleksandarSavchev [#399]
🏃 Others
[USER]
Rule 242418 from DISA K8s STIG was revisited to fail when insecure tls ciphers are configured for the kube-apiserver. by @AleksandarSavchev [#390][OPERATOR]
Pods created by diki will be terminated 300 seconds after start. by @dimityrmirchev [#364]
Docker Images
- diki-ops:
europe-docker.pkg.dev/gardener-project/releases/gardener/diki-ops:v0.13.0
- diki:
europe-docker.pkg.dev/gardener-project/releases/gardener/diki:v0.13.0