UNCLASSIFIED - NO CUI

Skip to content
Snippets Groups Projects

twistlock update to 0.15.0-bb.3

Merged Ghost User requested to merge update-twistlock-tag-0.15.0-bb.3 into master

Package Merge Request

Package Changes

https://repo1.dso.mil/big-bang/product/packages/twistlock/-/blob/0.15.0-bb.3/CHANGELOG.md

Package MR

big-bang/product/packages/twistlock!139 (merged)

For Issue

Closes big-bang/product/packages/twistlock#95 (closed)

Upgrade Notices

A Sidecar resource has been added to the Twistlock namespace that disallows egress to endpoints that are not part of the Istio service registry (a.k.a REGISTRY_ONLY). The outboundTrafficPolicy.mode in the Sidecar can be configured, however, to be something other than REGISTRY_ONLY if desired by setting istio.hardened.outboundTrafficPolicyMode. This provides a redundant layer of network security in addition to NetworkPolicies. This Sidecar is disabled by default but can be enabled by setting istio.enabled: true and istio.hardened.enabled: true.

Additionally, custom ServiceEntries can be created by populating the istio.hardened.customServiceEntries list.

Edited by Chris Harden

Merge request reports

Merge request pipeline #3008057 passed

Merge request pipeline passed for 8905943d

Approved by

Merged by Michael MartinMichael Martin 1 year ago (Mar 19, 2024 9:13pm UTC)

Merge details

Pipeline #3025727 passed

Pipeline passed for 047fab0c on master

Activity

Filter activity
  • Approvals
  • Assignees & reviewers
  • Comments (from bots)
  • Comments (from users)
  • Commits & branches
  • Edits
  • Labels
  • Lock status
  • Mentions
  • Merge request status
  • Tracking
Please register or sign in to reply
Loading