Skip to content

Commit 66124e4

Browse files
authored
Merge pull request #1409 from viccuad/deps/hauler-update
fix: Update Hauler OIDC regex
2 parents 445570a + 4e96910 commit 66124e4

2 files changed

Lines changed: 24 additions & 24 deletions

File tree

charts/hauler_manifest.yaml

Lines changed: 18 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -12,12 +12,12 @@ metadata:
1212
hauler.dev/certificate-oidc-issuer: https://token.actions.githubusercontent.com
1313
spec:
1414
images:
15-
- name: ghcr.io/kubewarden/audit-scanner:v1.31.0
16-
certificate-identity-regexp: https://github.com/kubewarden/kubewarden-controller/.github/workflows/release.yml@refs/tags/v1.31.0
17-
- name: ghcr.io/kubewarden/kubewarden-controller:v1.31.0
18-
certificate-identity-regexp: https://github.com/kubewarden/kubewarden-controller/.github/workflows/release.yml@refs/tags/v1.31.0
19-
- name: ghcr.io/kubewarden/policy-server:v1.31.0
20-
certificate-identity-regexp: https://github.com/kubewarden/kubewarden-controller/.github/workflows/release.yml@refs/tags/v1.31.0
15+
- name: ghcr.io/kubewarden/audit-scanner:v1.32.0-rc3
16+
certificate-identity-regexp: https://github.com/kubewarden/kubewarden-controller/.github/workflows/release.yml@refs/tags/v1.32.0-rc3
17+
- name: ghcr.io/kubewarden/kubewarden-controller:v1.32.0-rc3
18+
certificate-identity-regexp: https://github.com/kubewarden/kubewarden-controller/.github/workflows/release.yml@refs/tags/v1.32.0-rc3
19+
- name: ghcr.io/kubewarden/policy-server:v1.32.0-rc3
20+
certificate-identity-regexp: https://github.com/kubewarden/kubewarden-controller/.github/workflows/release.yml@refs/tags/v1.32.0-rc3
2121
---
2222
# The policies are in a separated definition just to allow a better keyless validation
2323
# without the need to duplicate configuration
@@ -27,15 +27,15 @@ metadata:
2727
name: kubewarden-policies
2828
annotations:
2929
hauler.dev/certificate-oidc-issuer: https://token.actions.githubusercontent.com
30-
hauler.dev/certificate-identity-regexp: https://github.com/kubewarden/github-actions/.github/workflows/.*
30+
hauler.dev/certificate-identity-regexp: https://github.com/kubewarden/policies/.github/workflows/release.yml@refs/tags/.*
3131
spec:
3232
images:
33-
- name: ghcr.io/kubewarden/policies/allow-privilege-escalation-psp:v1.0.5
34-
- name: ghcr.io/kubewarden/policies/capabilities-psp:v1.0.7
35-
- name: ghcr.io/kubewarden/policies/host-namespaces-psp:v1.1.5
36-
- name: ghcr.io/kubewarden/policies/hostpaths-psp:v1.1.2
37-
- name: ghcr.io/kubewarden/policies/pod-privileged:v1.0.8
38-
- name: ghcr.io/kubewarden/policies/user-group-psp:v1.1.2
33+
- name: ghcr.io/kubewarden/policies/allow-privilege-escalation-psp:v1.0.10
34+
- name: ghcr.io/kubewarden/policies/capabilities-psp:v1.0.10
35+
- name: ghcr.io/kubewarden/policies/host-namespaces-psp:v1.1.8
36+
- name: ghcr.io/kubewarden/policies/hostpaths-psp:v1.1.7
37+
- name: ghcr.io/kubewarden/policies/pod-privileged:v1.0.10
38+
- name: ghcr.io/kubewarden/policies/user-group-psp:v1.1.5
3939
---
4040
# The policy reporter and kuberlr images are defined in the dedicated manifest section because
4141
# the container images are not signed. Therefore, this difference is very clear
@@ -46,8 +46,8 @@ metadata:
4646
name: kubewarden-not-signed-images
4747
spec:
4848
images:
49-
- name: ghcr.io/kyverno/policy-reporter-ui:2.5.0
50-
- name: ghcr.io/kyverno/policy-reporter:3.6.0
49+
- name: ghcr.io/kyverno/policy-reporter-ui:2.5.1
50+
- name: ghcr.io/kyverno/policy-reporter:3.7.0
5151
- name: ghcr.io/rancher/kuberlr-kubectl:v6.0.0
5252
---
5353
apiVersion: content.hauler.cattle.io/v1
@@ -58,13 +58,13 @@ spec:
5858
charts:
5959
- name: kubewarden-crds
6060
repoURL: https://charts.kubewarden.io
61-
version: 1.23.0
61+
version: 1.24.0-rc3
6262
- name: kubewarden-controller
6363
repoURL: https://charts.kubewarden.io
64-
version: 5.9.0
64+
version: 5.10.0-rc3
6565
- name: kubewarden-defaults
6666
repoURL: https://charts.kubewarden.io
67-
version: 3.9.0
67+
version: 3.10.0-rc3
6868
- name: policy-reporter
6969
version: 3.7.0
7070
repoURL: https://kyverno.github.io/policy-reporter

charts/kubewarden-defaults/values.yaml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -194,14 +194,14 @@ recommendedPolicies:
194194
allowPrivilegeEscalationPolicy:
195195
module:
196196
repository: "kubewarden/policies/allow-privilege-escalation-psp"
197-
tag: v1.0.9
197+
tag: v1.0.10
198198
name: "no-privilege-escalation"
199199
settings:
200200
allowPrivilegeEscalation: false
201201
hostNamespacePolicy:
202202
module:
203203
repository: "kubewarden/policies/host-namespaces-psp"
204-
tag: v1.1.7
204+
tag: v1.1.8
205205
name: "no-host-namespace-sharing"
206206
settings:
207207
allow_host_ipc: false
@@ -211,15 +211,15 @@ recommendedPolicies:
211211
podPrivilegedPolicy:
212212
module:
213213
repository: "kubewarden/policies/pod-privileged"
214-
tag: v1.0.9
214+
tag: v1.0.10
215215
name: "no-privileged-pod"
216216
settings:
217217
skip_init_containers: false
218218
skip_ephemeral_containers: false
219219
userGroupPolicy:
220220
module:
221221
repository: "kubewarden/policies/user-group-psp"
222-
tag: v1.1.4
222+
tag: v1.1.5
223223
name: "do-not-run-as-root"
224224
settings:
225225
run_as_user:
@@ -232,7 +232,7 @@ recommendedPolicies:
232232
hostPathsPolicy:
233233
module:
234234
repository: "kubewarden/policies/hostpaths-psp"
235-
tag: v1.1.6
235+
tag: v1.1.7
236236
name: "do-not-share-host-paths"
237237
settings:
238238
allowedHostPaths:
@@ -241,7 +241,7 @@ recommendedPolicies:
241241
capabilitiesPolicy:
242242
module:
243243
repository: "kubewarden/policies/capabilities-psp"
244-
tag: v1.0.9
244+
tag: v1.0.10
245245
name: "drop-capabilities"
246246
settings:
247247
allowed_capabilities: []

0 commit comments

Comments
 (0)