UNCLASSIFIED - NO CUI

Skip to content
Snippets Groups Projects

clusterAuditor update to 1.5.0-bb.10

Merged Ghost User requested to merge update-cluster-auditor-tag-1.5.0-bb.10 into master

Package Merge Request

Package Changes

The package MR includes template modifications to disable API token auto-mounting for the opa-exporter ServiceAccount.

This essentially means that Pods leveraging the opa-exporter ServiceAccount, by default, will not have access to their Kubernetes API token (previously mounted at /var/run/secrets/kubernetes.io/serviceaccount/token).

Since this package deals with the Kubernetes API heavily - the cluster-auditor Pod will override this behavior at the Pod spec-level here. As such, a Kyverno policy exception will be made for this Pod.

Testing has shown no loss of functionality - pipelines have passed, and a Package codeowner has approved the change.

This is in support of epic &146.

Package MR

big-bang/product/packages/cluster-auditor!115 (merged)

For Issue

Closes https://repo1.dso.mil/big-bang/product/packages/cluster-auditor/-/issues/79

Edited by Justen Mehl

Merge request reports

Merge request pipeline #2429342 passed with warnings

Merge request pipeline passed with warnings for b392a261

Approval is optional

Merged by Ryan GarciaRyan Garcia 1 year ago (Nov 7, 2023 9:43pm UTC)

Merge details

  • Changes merged into with dcbcc087.
  • Deleted the source branch.

Pipeline #2430059 failed

Pipeline failed for dcbcc087 on master

Activity

Filter activity
  • Approvals
  • Assignees & reviewers
  • Comments (from bots)
  • Comments (from users)
  • Commits & branches
  • Edits
  • Labels
  • Lock status
  • Mentions
  • Merge request status
  • Tracking
Please register or sign in to reply
Loading