Repository navigation
feat(oci/gateway-helm): update v1.7.1 ➼ v1.9.2 - #5768
tinfoild[bot] wants to merge 1 commit into
Conversation
kube/helmrelease/out00--- HelmRelease: ingress/envoy-gateway ServiceAccount: ingress/envoy-gateway
+++ HelmRelease: ingress/envoy-gateway ServiceAccount: ingress/envoy-gateway
@@ -1,9 +1,10 @@
---
apiVersion: v1
kind: ServiceAccount
+automountServiceAccountToken: false
metadata:
name: envoy-gateway
namespace: ingress
labels:
app.kubernetes.io/name: gateway-helm
app.kubernetes.io/instance: envoy-gateway
--- HelmRelease: ingress/envoy-gateway ConfigMap: ingress/envoy-gateway-config
+++ HelmRelease: ingress/envoy-gateway ConfigMap: ingress/envoy-gateway-config
@@ -22,20 +22,20 @@
provider:
kubernetes:
deploy:
type: GatewayNamespace
rateLimitDeployment:
container:
- image: mirror.gcr.io/envoyproxy/ratelimit:c8765e89
+ image: mirror.gcr.io/envoyproxy/ratelimit:0482748e
patch:
type: StrategicMerge
value:
spec:
template:
spec:
containers:
- imagePullPolicy: IfNotPresent
name: envoy-ratelimit
shutdownManager:
- image: mirror.gcr.io/envoyproxy/gateway:v1.7.1
+ image: mirror.gcr.io/envoyproxy/gateway:v1.9.2
type: Kubernetes
--- HelmRelease: ingress/envoy-gateway ClusterRole: ingress/envoy-gateway-gateway-helm-envoy-gateway-role
+++ HelmRelease: ingress/envoy-gateway ClusterRole: ingress/envoy-gateway-gateway-helm-envoy-gateway-role
@@ -1,12 +1,16 @@
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
creationTimestamp: null
name: envoy-gateway-gateway-helm-envoy-gateway-role
+ labels:
+ app.kubernetes.io/name: gateway-helm
+ app.kubernetes.io/instance: envoy-gateway
+ app.kubernetes.io/managed-by: Helm
rules:
- apiGroups:
- ''
resources:
- nodes
- namespaces
@@ -80,24 +84,26 @@
- get
- list
- watch
- apiGroups:
- gateway.envoyproxy.io
resources:
+ - envoyproxies/status
- envoypatchpolicies/status
- clienttrafficpolicies/status
- backendtrafficpolicies/status
- securitypolicies/status
- envoyextensionpolicies/status
- backends/status
verbs:
- update
- apiGroups:
- gateway.networking.k8s.io
resources:
- gateways
+ - listenersets
- grpcroutes
- httproutes
- referencegrants
- tcproutes
- tlsroutes
- udproutes
@@ -107,32 +113,19 @@
- list
- watch
- apiGroups:
- gateway.networking.k8s.io
resources:
- gateways/status
+ - listenersets/status
- grpcroutes/status
- httproutes/status
- tcproutes/status
- tlsroutes/status
- udproutes/status
- backendtlspolicies/status
- verbs:
- - update
-- apiGroups:
- - gateway.networking.x-k8s.io
- resources:
- - xlistenersets
- verbs:
- - get
- - list
- - watch
-- apiGroups:
- - gateway.networking.x-k8s.io
- resources:
- - xlistenersets/status
verbs:
- update
- apiGroups:
- ''
resources:
- pods
--- HelmRelease: ingress/envoy-gateway ClusterRole: ingress/envoy-gateway-gateway-helm-cluster-infra-manager
+++ HelmRelease: ingress/envoy-gateway ClusterRole: ingress/envoy-gateway-gateway-helm-cluster-infra-manager
@@ -18,36 +18,50 @@
- create
- get
- list
- delete
- deletecollection
- patch
+ - watch
- apiGroups:
- apps
resources:
- deployments
- daemonsets
verbs:
- create
- get
+ - list
- delete
- deletecollection
- patch
+ - watch
- apiGroups:
- autoscaling
+ resources:
+ - horizontalpodautoscalers
+ verbs:
+ - create
+ - get
+ - list
+ - delete
+ - deletecollection
+ - patch
+ - watch
+- apiGroups:
- policy
resources:
- - horizontalpodautoscalers
- poddisruptionbudgets
verbs:
- create
- get
- list
- delete
- deletecollection
- patch
+ - watch
- apiGroups:
- certificates.k8s.io
resources:
- clustertrustbundles
verbs:
- list
--- HelmRelease: ingress/envoy-gateway ClusterRoleBinding: ingress/envoy-gateway-gateway-helm-envoy-gateway-rolebinding
+++ HelmRelease: ingress/envoy-gateway ClusterRoleBinding: ingress/envoy-gateway-gateway-helm-envoy-gateway-rolebinding
@@ -1,11 +1,15 @@
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: envoy-gateway-gateway-helm-envoy-gateway-rolebinding
+ labels:
+ app.kubernetes.io/name: gateway-helm
+ app.kubernetes.io/instance: envoy-gateway
+ app.kubernetes.io/managed-by: Helm
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: envoy-gateway-gateway-helm-envoy-gateway-role
subjects:
- kind: ServiceAccount
--- HelmRelease: ingress/envoy-gateway Role: ingress/envoy-gateway-gateway-helm-infra-manager
+++ HelmRelease: ingress/envoy-gateway Role: ingress/envoy-gateway-gateway-helm-infra-manager
@@ -19,36 +19,50 @@
- create
- get
- list
- delete
- deletecollection
- patch
+ - watch
- apiGroups:
- apps
resources:
- deployments
- daemonsets
verbs:
- create
- get
+ - list
- delete
- deletecollection
- patch
+ - watch
- apiGroups:
- autoscaling
+ resources:
+ - horizontalpodautoscalers
+ verbs:
+ - create
+ - get
+ - list
+ - delete
+ - deletecollection
+ - patch
+ - watch
+- apiGroups:
- policy
resources:
- - horizontalpodautoscalers
- poddisruptionbudgets
verbs:
- create
- get
- list
- delete
- deletecollection
- patch
+ - watch
- apiGroups:
- certificates.k8s.io
resources:
- clustertrustbundles
verbs:
- list
--- HelmRelease: ingress/envoy-gateway Deployment: ingress/envoy-gateway
+++ HelmRelease: ingress/envoy-gateway Deployment: ingress/envoy-gateway
@@ -24,32 +24,56 @@
labels:
control-plane: envoy-gateway
app.kubernetes.io/name: gateway-helm
app.kubernetes.io/instance: envoy-gateway
egress.home.arpa/apiserver: allow
spec:
+ automountServiceAccountToken: true
+ securityContext:
+ fsGroup: 65532
+ runAsGroup: 65532
+ runAsNonRoot: true
+ runAsUser: 65532
+ seccompProfile:
+ type: RuntimeDefault
containers:
- args:
- server
- --config-path=/config/envoy-gateway.yaml
env:
- name: ENVOY_GATEWAY_NAMESPACE
valueFrom:
fieldRef:
apiVersion: v1
fieldPath: metadata.namespace
+ - name: ENVOY_GATEWAY_SERVICE_ACCOUNT
+ valueFrom:
+ fieldRef:
+ apiVersion: v1
+ fieldPath: spec.serviceAccountName
+ - name: ENVOY_GATEWAY_FULLNAME
+ value: envoy-gateway-gateway-helm
- name: KUBERNETES_CLUSTER_DOMAIN
value: cluster.local
- image: mirror.gcr.io/envoyproxy/gateway:v1.7.1
+ image: mirror.gcr.io/envoyproxy/gateway:v1.9.2
imagePullPolicy: IfNotPresent
+ startupProbe:
+ failureThreshold: 30
+ httpGet:
+ path: /healthz
+ port: 8081
+ periodSeconds: 1
+ successThreshold: 1
+ timeoutSeconds: 1
livenessProbe:
httpGet:
path: /healthz
port: 8081
- initialDelaySeconds: 15
periodSeconds: 20
+ successThreshold: 1
+ timeoutSeconds: 1
name: envoy-gateway
ports:
- containerPort: 18000
name: grpc
- containerPort: 18001
name: ratelimit
@@ -60,44 +84,50 @@
- name: webhook
containerPort: 9443
readinessProbe:
httpGet:
path: /readyz
port: 8081
- initialDelaySeconds: 5
periodSeconds: 10
+ successThreshold: 1
+ timeoutSeconds: 1
resources:
limits:
memory: 1024Mi
requests:
cpu: 100m
memory: 256Mi
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
privileged: false
+ readOnlyRootFilesystem: true
runAsGroup: 65532
runAsNonRoot: true
runAsUser: 65532
seccompProfile:
type: RuntimeDefault
volumeMounts:
- mountPath: /config
name: envoy-gateway-config
readOnly: true
- mountPath: /certs
name: certs
readOnly: true
+ - mountPath: /var/lib/eg/wasm
+ name: wasm-cache
imagePullSecrets: []
serviceAccountName: envoy-gateway
terminationGracePeriodSeconds: 10
volumes:
- configMap:
defaultMode: 420
name: envoy-gateway-config
name: envoy-gateway-config
- name: certs
secret:
secretName: envoy-gateway
+ - name: wasm-cache
+ emptyDir: {}
--- HelmRelease: ingress/envoy-gateway ServiceAccount: ingress/envoy-gateway-gateway-helm-certgen
+++ HelmRelease: ingress/envoy-gateway ServiceAccount: ingress/envoy-gateway-gateway-helm-certgen
@@ -1,9 +1,10 @@
---
apiVersion: v1
kind: ServiceAccount
+automountServiceAccountToken: false
metadata:
name: envoy-gateway-gateway-helm-certgen
namespace: ingress
labels:
app.kubernetes.io/name: gateway-helm
app.kubernetes.io/instance: envoy-gateway
--- HelmRelease: ingress/envoy-gateway Job: ingress/envoy-gateway-gateway-helm-certgen
+++ HelmRelease: ingress/envoy-gateway Job: ingress/envoy-gateway-gateway-helm-certgen
@@ -17,25 +17,33 @@
template:
metadata:
labels:
app: certgen
egress.home.arpa/apiserver: allow
spec:
+ automountServiceAccountToken: true
+ securityContext:
+ fsGroup: 65532
+ runAsGroup: 65532
+ runAsNonRoot: true
+ runAsUser: 65532
+ seccompProfile:
+ type: RuntimeDefault
containers:
- command:
- envoy-gateway
- certgen
env:
- name: ENVOY_GATEWAY_NAMESPACE
valueFrom:
fieldRef:
apiVersion: v1
fieldPath: metadata.namespace
- name: KUBERNETES_CLUSTER_DOMAIN
value: cluster.local
- image: mirror.gcr.io/envoyproxy/gateway:v1.7.1
+ image: mirror.gcr.io/envoyproxy/gateway:v1.9.2
imagePullPolicy: IfNotPresent
name: envoy-gateway-certgen
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
--- HelmRelease: ingress/envoy-gateway ValidatingAdmissionPolicy: ingress/safe-upgrades.gateway.networking.k8s.io
+++ HelmRelease: ingress/envoy-gateway ValidatingAdmissionPolicy: ingress/safe-upgrades.gateway.networking.k8s.io
@@ -0,0 +1,44 @@
+---
+apiVersion: admissionregistration.k8s.io/v1
+kind: ValidatingAdmissionPolicy
+metadata:
+ annotations:
+ gateway.networking.k8s.io/bundle-version: v1.6.1
+ gateway.networking.k8s.io/channel: standard
+ name: safe-upgrades.gateway.networking.k8s.io
+spec:
+ failurePolicy: Fail
+ matchConstraints:
+ resourceRules:
+ - apiGroups:
+ - apiextensions.k8s.io
+ apiVersions:
+ - v1
+ operations:
+ - CREATE
+ - UPDATE
+ resources:
+ - '*'
+ validations:
+ - expression: object.spec.group != 'gateway.networking.k8s.io' || oldObject == null
+ || ( has(object.metadata.annotations) && object.metadata.annotations.exists(k,
+ k == 'gateway.networking.k8s.io/channel') && object.metadata.annotations['gateway.networking.k8s.io/channel']
+ == 'standard' ) || ( oldObject != null && has(oldObject.metadata.annotations)
+ && oldObject.metadata.annotations.exists(k, k == 'gateway.networking.k8s.io/channel')
+ && oldObject.metadata.annotations['gateway.networking.k8s.io/channel'] == 'experimental'
+ )
+ message: Installing experimental CRDs on top of standard channel CRDs is prohibited
+ by default. Uninstall ValidatingAdmissionPolicy safe-upgrades.gateway.networking.k8s.io
+ to install experimental CRDs on top of standard channel CRDs.
+ reason: Invalid
+ - expression: |
+ object.spec.group != 'gateway.networking.k8s.io' ||
+ (has(object.metadata.annotations) && object.metadata.annotations.exists(k, k == 'gateway.networking.k8s.io/bundle-version') &&
+ (object.metadata.annotations['gateway.networking.k8s.io/bundle-version'] == 'v0.0.0-dev' ||
+ (object.metadata.annotations['gateway.networking.k8s.io/bundle-version'].startsWith('v1.') &&
+ !matches(object.metadata.annotations['gateway.networking.k8s.io/bundle-version'], '^v1\.[0-4](\.|$)'))))
+ message: Installing CRDs with version other than v0.0.0-dev or v1.5+ is prohibited
+ by default. Uninstall ValidatingAdmissionPolicy safe-upgrades.gateway.networking.k8s.io
+ to install other versions.
+ reason: Invalid
+
--- HelmRelease: ingress/envoy-gateway ValidatingAdmissionPolicyBinding: ingress/safe-upgrades.gateway.networking.k8s.io
+++ HelmRelease: ingress/envoy-gateway ValidatingAdmissionPolicyBinding: ingress/safe-upgrades.gateway.networking.k8s.io
@@ -0,0 +1,24 @@
+---
+apiVersion: admissionregistration.k8s.io/v1
+kind: ValidatingAdmissionPolicyBinding
+metadata:
+ annotations:
+ gateway.networking.k8s.io/bundle-version: v1.6.1
+ gateway.networking.k8s.io/channel: standard
+ name: safe-upgrades.gateway.networking.k8s.io
+spec:
+ policyName: safe-upgrades.gateway.networking.k8s.io
+ validationActions:
+ - Deny
+ matchResources:
+ resourceRules:
+ - apiGroups:
+ - apiextensions.k8s.io
+ apiVersions:
+ - v1
+ resources:
+ - customresourcedefinitions
+ operations:
+ - CREATE
+ - UPDATE
+ |
c458be3 to
cb5ce34
Compare
cb5ce34 to
25152f2
Compare
kube/kustomization/out00--- kube/deploy/core/ingress/envoy-gateway/app Kustomization: ingress/envoy-gateway-app OCIRepository: ingress/envoy-gateway
+++ kube/deploy/core/ingress/envoy-gateway/app Kustomization: ingress/envoy-gateway-app OCIRepository: ingress/envoy-gateway
@@ -11,9 +11,9 @@
spec:
interval: 1h
layerSelector:
mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
operation: copy
ref:
- tag: v1.7.1
+ tag: 1.8.3
url: oci://mirror.gcr.io/envoyproxy/gateway-helm
|
25152f2 to
20c759a
Compare
20c759a to
8268556
Compare
8268556 to
baf855a
Compare
baf855a to
ce1eba0
Compare
ce1eba0 to
c71e576
Compare
c71e576 to
b70caa4
Compare
09914eb to
2599cfc
Compare
2599cfc to
a304e37
Compare
|
SECURITY VULNERABILITIES FOUND BY CIEL
Severity Summary
ResultsPackage: mirror.gcr.io/envoyproxy/gateway-helm
Vulnerabilities in version v1.7.1
Vulnerabilities in version v1.8.3No known vulnerabilities found. All 7 CVEs present in v1.7.1 are fixed in v1.7.4+ or v1.8.1+. Non-applicable findings (verified and excluded)
Changelog Security Highlights (v1.7.1 → v1.8.3)
Recommendations
|
a304e37 to
66460bd
Compare
66460bd to
4cf1df5
Compare
4cf1df5 to
c33d21b
Compare
This PR contains the following updates:
v1.7.1→v1.9.2Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
envoyproxy/gateway (mirror.gcr.io/envoyproxy/gateway-helm)
v1.9.2Compare Source
Release Announcement
Check out the v1.9.2 release announcement to learn more about the release.
v1.9.2Compare Source
Release Announcement
Check out the v1.9.2 release announcement to learn more about the release.
v1.9.1Compare Source
Release Announcement
Check out the v1.9.1 release announcement to learn more about the release.
v1.9.1Compare Source
Release Announcement
Check out the v1.9.1 release announcement to learn more about the release.
v1.9.0Compare Source
Release Announcement
Check out the v1.9.0 release announcement to learn more about the release.
What's Changed
f71dcb6to20f009ein /tools/docker/envoy-gateway by @dependabot[bot] in #90381487d0atofd8d9aain /tools/docker/envoy-gateway by @dependabot[bot] in #9087x statusbulk modes by @jeremiahsnapp in #909920f009eto86554c4in /tools/docker/envoy-gateway by @dependabot[bot] in #9494Configuration
📅 Schedule: (in timezone Asia/Singapore)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate.