Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(kyverno): update helm-release to v3.1.1 #2173

Merged
merged 1 commit into from
Nov 28, 2023

Conversation

tyriis-automation[bot]
Copy link
Contributor

This PR contains the following updates:

Package Update Change
kyverno (source) patch 3.1.0 -> 3.1.1

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@tyriis-automation tyriis-automation bot added renovate/flux renovate flux manager renovate/helm renovate helm datasource type/patch a patch for a bug labels Nov 28, 2023
@tyriis-automation
Copy link
Contributor Author

--- kubernetes HelmRelease: kyverno/kyverno Deployment: kyverno/kyverno-background-controller

+++ kubernetes HelmRelease: kyverno/kyverno Deployment: kyverno/kyverno-background-controller

@@ -42,13 +42,13 @@

                   - background-controller
               topologyKey: kubernetes.io/hostname
             weight: 1
       serviceAccountName: kyverno-background-controller
       containers:
       - name: controller
-        image: ghcr.io/kyverno/background-controller:v1.11.0
+        image: ghcr.io/kyverno/background-controller:v1.11.1
         imagePullPolicy: IfNotPresent
         ports:
         - containerPort: 9443
           name: https
           protocol: TCP
         - containerPort: 8000
--- kubernetes HelmRelease: kyverno/kyverno ServiceMonitor: kyverno/kyverno-cleanup-controller

+++ kubernetes HelmRelease: kyverno/kyverno ServiceMonitor: kyverno/kyverno-cleanup-controller

@@ -0,0 +1,25 @@

+---
+apiVersion: monitoring.coreos.com/v1
+kind: ServiceMonitor
+metadata:
+  name: kyverno-cleanup-controller
+  namespace: kyverno
+  labels:
+    app.kubernetes.io/component: cleanup-controller
+    app.kubernetes.io/instance: kyverno
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/part-of: kyverno
+spec:
+  selector:
+    matchLabels:
+      app.kubernetes.io/component: cleanup-controller
+      app.kubernetes.io/instance: kyverno
+      app.kubernetes.io/part-of: kyverno
+  namespaceSelector:
+    matchNames:
+    - kyverno
+  endpoints:
+  - port: metrics-port
+    interval: 30s
+    scrapeTimeout: 25s
+
--- kubernetes HelmRelease: kyverno/kyverno ServiceMonitor: kyverno/kyverno-admission-controller

+++ kubernetes HelmRelease: kyverno/kyverno ServiceMonitor: kyverno/kyverno-admission-controller

@@ -0,0 +1,25 @@

+---
+apiVersion: monitoring.coreos.com/v1
+kind: ServiceMonitor
+metadata:
+  name: kyverno-admission-controller
+  namespace: kyverno
+  labels:
+    app.kubernetes.io/component: admission-controller
+    app.kubernetes.io/instance: kyverno
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/part-of: kyverno
+spec:
+  selector:
+    matchLabels:
+      app.kubernetes.io/component: admission-controller
+      app.kubernetes.io/instance: kyverno
+      app.kubernetes.io/part-of: kyverno
+  namespaceSelector:
+    matchNames:
+    - kyverno
+  endpoints:
+  - port: metrics-port
+    interval: 30s
+    scrapeTimeout: 25s
+
--- kubernetes HelmRelease: kyverno/kyverno Job: kyverno/kyverno-hook-post-upgrade

+++ kubernetes HelmRelease: kyverno/kyverno Job: kyverno/kyverno-hook-post-upgrade

@@ -0,0 +1,52 @@

+---
+apiVersion: batch/v1
+kind: Job
+metadata:
+  name: kyverno-hook-post-upgrade
+  namespace: kyverno
+  labels:
+    app.kubernetes.io/component: hooks
+    app.kubernetes.io/instance: kyverno
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/part-of: kyverno
+  annotations:
+    helm.sh/hook: post-upgrade
+    helm.sh/hook-delete-policy: hook-succeeded,hook-failed
+spec:
+  backoffLimit: 2
+  template:
+    spec:
+      serviceAccount: kyverno-admission-controller
+      restartPolicy: Never
+      containers:
+      - name: kubectl
+        image: bitnami/kubectl:1.28.4
+        imagePullPolicy: null
+        command:
+        - /bin/bash
+        - -c
+        - "NAMESPACES=$(kubectl get namespaces --no-headers=true | awk '{print $1}')\n\
+          \nfor ns in ${NAMESPACES[@]};\ndo\n  COUNT=$(kubectl get policyreports.wgpolicyk8s.io\
+          \ -n $ns --no-headers=true | awk '/pol/{print $1}' | wc -l)\n\n  if [ $COUNT\
+          \ -gt 0 ]; then\n    echo \"deleting $COUNT policyreports in namespace $ns\"\
+          \n    kubectl get policyreports.wgpolicyk8s.io -n $ns --no-headers=true\
+          \ | awk '/pol/{print $1}' | xargs kubectl delete -n $ns policyreports.wgpolicyk8s.io\n\
+          \  else\n    echo \"no policyreports in namespace $ns\"\n  fi\ndone\n\n\
+          COUNT=$(kubectl get clusterpolicyreports.wgpolicyk8s.io --no-headers=true\
+          \ | awk '/pol/{print $1}' | wc -l)\n  \nif [ $COUNT -gt 0 ]; then\n  echo\
+          \ \"deleting $COUNT clusterpolicyreports\"\n  kubectl get clusterpolicyreports.wgpolicyk8s.io\
+          \ --no-headers=true | awk '/pol/{print $1}' | xargs kubectl delete clusterpolicyreports.wgpolicyk8s.io\n\
+          else\n  echo \"no clusterpolicyreports\"\nfi\n"
+        securityContext:
+          allowPrivilegeEscalation: false
+          capabilities:
+            drop:
+            - ALL
+          privileged: false
+          readOnlyRootFilesystem: true
+          runAsGroup: 65534
+          runAsNonRoot: true
+          runAsUser: 65534
+          seccompProfile:
+            type: RuntimeDefault
+
--- kubernetes HelmRelease: kyverno/kyverno Deployment: kyverno/kyverno-reports-controller

+++ kubernetes HelmRelease: kyverno/kyverno Deployment: kyverno/kyverno-reports-controller

@@ -42,13 +42,13 @@

                   - reports-controller
               topologyKey: kubernetes.io/hostname
             weight: 1
       serviceAccountName: kyverno-reports-controller
       containers:
       - name: controller
-        image: ghcr.io/kyverno/reports-controller:v1.11.0
+        image: ghcr.io/kyverno/reports-controller:v1.11.1
         imagePullPolicy: IfNotPresent
         ports:
         - containerPort: 9443
           name: https
           protocol: TCP
         - containerPort: 8000
--- kubernetes HelmRelease: kyverno/kyverno Deployment: kyverno/kyverno-cleanup-controller

+++ kubernetes HelmRelease: kyverno/kyverno Deployment: kyverno/kyverno-cleanup-controller

@@ -42,13 +42,13 @@

                   - cleanup-controller
               topologyKey: kubernetes.io/hostname
             weight: 1
       serviceAccountName: kyverno-cleanup-controller
       containers:
       - name: controller
-        image: ghcr.io/kyverno/cleanup-controller:v1.11.0
+        image: ghcr.io/kyverno/cleanup-controller:v1.11.1
         imagePullPolicy: IfNotPresent
         ports:
         - containerPort: 9443
           name: https
           protocol: TCP
         - containerPort: 8000
--- kubernetes HelmRelease: kyverno/kyverno Deployment: kyverno/kyverno-admission-controller

+++ kubernetes HelmRelease: kyverno/kyverno Deployment: kyverno/kyverno-admission-controller

@@ -50,13 +50,13 @@

                   - admission-controller
               topologyKey: kubernetes.io/hostname
             weight: 1
       serviceAccountName: kyverno-admission-controller
       initContainers:
       - name: kyverno-pre
-        image: ghcr.io/kyverno/kyvernopre:v1.11.0
+        image: ghcr.io/kyverno/kyvernopre:v1.11.1
         imagePullPolicy: IfNotPresent
         args:
         - --loggingFormat=text
         - --v=2
         resources:
           limits:
@@ -93,13 +93,13 @@

         - name: KYVERNO_DEPLOYMENT
           value: kyverno-admission-controller
         - name: KYVERNO_SVC
           value: kyverno-svc
       containers:
       - name: kyverno
-        image: ghcr.io/kyverno/kyverno:v1.11.0
+        image: ghcr.io/kyverno/kyverno:v1.11.1
         imagePullPolicy: IfNotPresent
         args:
         - --caSecretName=kyverno-svc.kyverno.svc.kyverno-tls-ca
         - --tlsSecretName=kyverno-svc.kyverno.svc.kyverno-tls-pair
         - --backgroundServiceAccountName=system:serviceaccount:kyverno:kyverno-background-controller
         - --servicePort=443
--- kubernetes HelmRelease: kyverno/kyverno ServiceMonitor: kyverno/kyverno-background-controller

+++ kubernetes HelmRelease: kyverno/kyverno ServiceMonitor: kyverno/kyverno-background-controller

@@ -0,0 +1,25 @@

+---
+apiVersion: monitoring.coreos.com/v1
+kind: ServiceMonitor
+metadata:
+  name: kyverno-background-controller
+  namespace: kyverno
+  labels:
+    app.kubernetes.io/component: background-controller
+    app.kubernetes.io/instance: kyverno
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/part-of: kyverno
+spec:
+  selector:
+    matchLabels:
+      app.kubernetes.io/component: background-controller
+      app.kubernetes.io/instance: kyverno
+      app.kubernetes.io/part-of: kyverno
+  namespaceSelector:
+    matchNames:
+    - kyverno
+  endpoints:
+  - port: metrics-port
+    interval: 30s
+    scrapeTimeout: 25s
+
--- kubernetes HelmRelease: kyverno/kyverno ServiceMonitor: kyverno/kyverno-reports-controller

+++ kubernetes HelmRelease: kyverno/kyverno ServiceMonitor: kyverno/kyverno-reports-controller

@@ -0,0 +1,25 @@

+---
+apiVersion: monitoring.coreos.com/v1
+kind: ServiceMonitor
+metadata:
+  name: kyverno-reports-controller
+  namespace: kyverno
+  labels:
+    app.kubernetes.io/component: reports-controller
+    app.kubernetes.io/instance: kyverno
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/part-of: kyverno
+spec:
+  selector:
+    matchLabels:
+      app.kubernetes.io/component: reports-controller
+      app.kubernetes.io/instance: kyverno
+      app.kubernetes.io/part-of: kyverno
+  namespaceSelector:
+    matchNames:
+    - kyverno
+  endpoints:
+  - port: metrics-port
+    interval: 30s
+    scrapeTimeout: 25s
+

@tyriis-automation
Copy link
Contributor Author

--- kubernetes/talos-flux/apps/kyverno/kyverno/app Kustomization: flux-system/apps-kyverno-app-sync HelmRelease: kyverno/kyverno

+++ kubernetes/talos-flux/apps/kyverno/kyverno/app Kustomization: flux-system/apps-kyverno-app-sync HelmRelease: kyverno/kyverno

@@ -9,13 +9,13 @@

     spec:
       chart: kyverno
       sourceRef:
         kind: HelmRepository
         name: kyverno-charts
         namespace: flux-system
-      version: 3.1.0
+      version: 3.1.1
   install:
     createNamespace: true
     remediation:
       retries: 3
   interval: 30m
   maxHistory: 2

@tyriis-automation
Copy link
Contributor Author

🦙 MegaLinter status: ✅ SUCCESS

Descriptor Linter Files Fixed Errors Elapsed time
✅ EDITORCONFIG editorconfig-checker 1 0 0.01s
✅ REPOSITORY gitleaks yes no 1.57s
✅ YAML prettier 1 0 0.42s
✅ YAML yamllint 1 0 0.25s

See detailed report in MegaLinter reports
Set VALIDATE_ALL_CODEBASE: true in mega-linter.yml to validate all sources, not only the diff

MegaLinter is graciously provided by OX Security

@tyriis-automation tyriis-automation bot merged commit 7875519 into main Nov 28, 2023
8 checks passed
@tyriis-automation tyriis-automation bot deleted the renovate/kyverno-3.1.x branch November 28, 2023 17:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
renovate/flux renovate flux manager renovate/helm renovate helm datasource type/patch a patch for a bug
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants