Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(container): update image kyverno to v3.1.1 #1459

Merged
merged 1 commit into from
Nov 28, 2023
Merged

Conversation

bot-blake[bot]
Copy link
Contributor

@bot-blake bot-blake bot commented Nov 28, 2023

This PR contains the following updates:

Package Update Change
kyverno patch 3.1.0 -> 3.1.1

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@bot-blake bot-blake bot requested a review from buroa as a code owner November 28, 2023 16:03
@bot-blake bot-blake bot added renovate/container type/patch area/kubernetes Changes made in the kubernetes directory labels Nov 28, 2023
@bot-blake
Copy link
Contributor Author

bot-blake bot commented Nov 28, 2023

--- kubernetes HelmRelease: kyverno/kyverno Deployment: kyverno/kyverno-admission-controller

+++ kubernetes HelmRelease: kyverno/kyverno Deployment: kyverno/kyverno-admission-controller

@@ -50,13 +50,13 @@

                   - admission-controller
               topologyKey: kubernetes.io/hostname
             weight: 1
       serviceAccountName: kyverno-admission-controller
       initContainers:
       - name: kyverno-pre
-        image: ghcr.io/kyverno/kyvernopre:v1.11.0
+        image: ghcr.io/kyverno/kyvernopre:v1.11.1
         imagePullPolicy: IfNotPresent
         args:
         - --loggingFormat=text
         - --v=2
         resources:
           limits:
@@ -93,13 +93,13 @@

         - name: KYVERNO_DEPLOYMENT
           value: kyverno-admission-controller
         - name: KYVERNO_SVC
           value: kyverno-svc
       containers:
       - name: kyverno
-        image: ghcr.io/kyverno/kyverno:v1.11.0
+        image: ghcr.io/kyverno/kyverno:v1.11.1
         imagePullPolicy: IfNotPresent
         args:
         - --caSecretName=kyverno-svc.kyverno.svc.kyverno-tls-ca
         - --tlsSecretName=kyverno-svc.kyverno.svc.kyverno-tls-pair
         - --backgroundServiceAccountName=system:serviceaccount:kyverno:kyverno-background-controller
         - --servicePort=443
--- kubernetes HelmRelease: kyverno/kyverno Deployment: kyverno/kyverno-background-controller

+++ kubernetes HelmRelease: kyverno/kyverno Deployment: kyverno/kyverno-background-controller

@@ -42,13 +42,13 @@

                   - background-controller
               topologyKey: kubernetes.io/hostname
             weight: 1
       serviceAccountName: kyverno-background-controller
       containers:
       - name: controller
-        image: ghcr.io/kyverno/background-controller:v1.11.0
+        image: ghcr.io/kyverno/background-controller:v1.11.1
         imagePullPolicy: IfNotPresent
         ports:
         - containerPort: 9443
           name: https
           protocol: TCP
         - containerPort: 8000
--- kubernetes HelmRelease: kyverno/kyverno Deployment: kyverno/kyverno-cleanup-controller

+++ kubernetes HelmRelease: kyverno/kyverno Deployment: kyverno/kyverno-cleanup-controller

@@ -42,13 +42,13 @@

                   - cleanup-controller
               topologyKey: kubernetes.io/hostname
             weight: 1
       serviceAccountName: kyverno-cleanup-controller
       containers:
       - name: controller
-        image: ghcr.io/kyverno/cleanup-controller:v1.11.0
+        image: ghcr.io/kyverno/cleanup-controller:v1.11.1
         imagePullPolicy: IfNotPresent
         ports:
         - containerPort: 9443
           name: https
           protocol: TCP
         - containerPort: 8000
--- kubernetes HelmRelease: kyverno/kyverno Deployment: kyverno/kyverno-reports-controller

+++ kubernetes HelmRelease: kyverno/kyverno Deployment: kyverno/kyverno-reports-controller

@@ -42,13 +42,13 @@

                   - reports-controller
               topologyKey: kubernetes.io/hostname
             weight: 1
       serviceAccountName: kyverno-reports-controller
       containers:
       - name: controller
-        image: ghcr.io/kyverno/reports-controller:v1.11.0
+        image: ghcr.io/kyverno/reports-controller:v1.11.1
         imagePullPolicy: IfNotPresent
         ports:
         - containerPort: 9443
           name: https
           protocol: TCP
         - containerPort: 8000
--- kubernetes HelmRelease: kyverno/kyverno ServiceMonitor: kyverno/kyverno-admission-controller

+++ kubernetes HelmRelease: kyverno/kyverno ServiceMonitor: kyverno/kyverno-admission-controller

@@ -0,0 +1,25 @@

+---
+apiVersion: monitoring.coreos.com/v1
+kind: ServiceMonitor
+metadata:
+  name: kyverno-admission-controller
+  namespace: kyverno
+  labels:
+    app.kubernetes.io/component: admission-controller
+    app.kubernetes.io/instance: kyverno
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/part-of: kyverno
+spec:
+  selector:
+    matchLabels:
+      app.kubernetes.io/component: admission-controller
+      app.kubernetes.io/instance: kyverno
+      app.kubernetes.io/part-of: kyverno
+  namespaceSelector:
+    matchNames:
+    - kyverno
+  endpoints:
+  - port: metrics-port
+    interval: 30s
+    scrapeTimeout: 25s
+
--- kubernetes HelmRelease: kyverno/kyverno ServiceMonitor: kyverno/kyverno-background-controller

+++ kubernetes HelmRelease: kyverno/kyverno ServiceMonitor: kyverno/kyverno-background-controller

@@ -0,0 +1,25 @@

+---
+apiVersion: monitoring.coreos.com/v1
+kind: ServiceMonitor
+metadata:
+  name: kyverno-background-controller
+  namespace: kyverno
+  labels:
+    app.kubernetes.io/component: background-controller
+    app.kubernetes.io/instance: kyverno
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/part-of: kyverno
+spec:
+  selector:
+    matchLabels:
+      app.kubernetes.io/component: background-controller
+      app.kubernetes.io/instance: kyverno
+      app.kubernetes.io/part-of: kyverno
+  namespaceSelector:
+    matchNames:
+    - kyverno
+  endpoints:
+  - port: metrics-port
+    interval: 30s
+    scrapeTimeout: 25s
+
--- kubernetes HelmRelease: kyverno/kyverno ServiceMonitor: kyverno/kyverno-cleanup-controller

+++ kubernetes HelmRelease: kyverno/kyverno ServiceMonitor: kyverno/kyverno-cleanup-controller

@@ -0,0 +1,25 @@

+---
+apiVersion: monitoring.coreos.com/v1
+kind: ServiceMonitor
+metadata:
+  name: kyverno-cleanup-controller
+  namespace: kyverno
+  labels:
+    app.kubernetes.io/component: cleanup-controller
+    app.kubernetes.io/instance: kyverno
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/part-of: kyverno
+spec:
+  selector:
+    matchLabels:
+      app.kubernetes.io/component: cleanup-controller
+      app.kubernetes.io/instance: kyverno
+      app.kubernetes.io/part-of: kyverno
+  namespaceSelector:
+    matchNames:
+    - kyverno
+  endpoints:
+  - port: metrics-port
+    interval: 30s
+    scrapeTimeout: 25s
+
--- kubernetes HelmRelease: kyverno/kyverno ServiceMonitor: kyverno/kyverno-reports-controller

+++ kubernetes HelmRelease: kyverno/kyverno ServiceMonitor: kyverno/kyverno-reports-controller

@@ -0,0 +1,25 @@

+---
+apiVersion: monitoring.coreos.com/v1
+kind: ServiceMonitor
+metadata:
+  name: kyverno-reports-controller
+  namespace: kyverno
+  labels:
+    app.kubernetes.io/component: reports-controller
+    app.kubernetes.io/instance: kyverno
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/part-of: kyverno
+spec:
+  selector:
+    matchLabels:
+      app.kubernetes.io/component: reports-controller
+      app.kubernetes.io/instance: kyverno
+      app.kubernetes.io/part-of: kyverno
+  namespaceSelector:
+    matchNames:
+    - kyverno
+  endpoints:
+  - port: metrics-port
+    interval: 30s
+    scrapeTimeout: 25s
+
--- kubernetes HelmRelease: kyverno/kyverno Job: kyverno/kyverno-hook-post-upgrade

+++ kubernetes HelmRelease: kyverno/kyverno Job: kyverno/kyverno-hook-post-upgrade

@@ -0,0 +1,52 @@

+---
+apiVersion: batch/v1
+kind: Job
+metadata:
+  name: kyverno-hook-post-upgrade
+  namespace: kyverno
+  labels:
+    app.kubernetes.io/component: hooks
+    app.kubernetes.io/instance: kyverno
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/part-of: kyverno
+  annotations:
+    helm.sh/hook: post-upgrade
+    helm.sh/hook-delete-policy: hook-succeeded,hook-failed
+spec:
+  backoffLimit: 2
+  template:
+    spec:
+      serviceAccount: kyverno-admission-controller
+      restartPolicy: Never
+      containers:
+      - name: kubectl
+        image: bitnami/kubectl:1.28.4
+        imagePullPolicy: null
+        command:
+        - /bin/bash
+        - -c
+        - "NAMESPACES=$(kubectl get namespaces --no-headers=true | awk '{print $1}')\n\
+          \nfor ns in ${NAMESPACES[@]};\ndo\n  COUNT=$(kubectl get policyreports.wgpolicyk8s.io\
+          \ -n $ns --no-headers=true | awk '/pol/{print $1}' | wc -l)\n\n  if [ $COUNT\
+          \ -gt 0 ]; then\n    echo \"deleting $COUNT policyreports in namespace $ns\"\
+          \n    kubectl get policyreports.wgpolicyk8s.io -n $ns --no-headers=true\
+          \ | awk '/pol/{print $1}' | xargs kubectl delete -n $ns policyreports.wgpolicyk8s.io\n\
+          \  else\n    echo \"no policyreports in namespace $ns\"\n  fi\ndone\n\n\
+          COUNT=$(kubectl get clusterpolicyreports.wgpolicyk8s.io --no-headers=true\
+          \ | awk '/pol/{print $1}' | wc -l)\n  \nif [ $COUNT -gt 0 ]; then\n  echo\
+          \ \"deleting $COUNT clusterpolicyreports\"\n  kubectl get clusterpolicyreports.wgpolicyk8s.io\
+          \ --no-headers=true | awk '/pol/{print $1}' | xargs kubectl delete clusterpolicyreports.wgpolicyk8s.io\n\
+          else\n  echo \"no clusterpolicyreports\"\nfi\n"
+        securityContext:
+          allowPrivilegeEscalation: false
+          capabilities:
+            drop:
+            - ALL
+          privileged: false
+          readOnlyRootFilesystem: true
+          runAsGroup: 65534
+          runAsNonRoot: true
+          runAsUser: 65534
+          seccompProfile:
+            type: RuntimeDefault
+

@bot-blake
Copy link
Contributor Author

bot-blake bot commented Nov 28, 2023

--- kubernetes/apps/kyverno/kyverno/app Kustomization: flux-system/cluster-apps-kyverno HelmRelease: kyverno/kyverno

+++ kubernetes/apps/kyverno/kyverno/app Kustomization: flux-system/cluster-apps-kyverno HelmRelease: kyverno/kyverno

@@ -12,13 +12,13 @@

     spec:
       chart: kyverno
       sourceRef:
         kind: HelmRepository
         name: kyverno-charts
         namespace: flux-system
-      version: 3.1.0
+      version: 3.1.1
   install:
     remediation:
       retries: 3
   interval: 30m
   maxHistory: 2
   uninstall:

@bot-blake bot-blake bot force-pushed the renovate/kyverno-3.x branch from 015d5bf to 3417737 Compare November 28, 2023 19:45
@buroa buroa merged commit 1c5a489 into master Nov 28, 2023
4 checks passed
@buroa buroa deleted the renovate/kyverno-3.x branch November 28, 2023 19:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/kubernetes Changes made in the kubernetes directory renovate/container type/patch
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant