Maintained with ☕️ by
IcePanel logo

Policy Controller has been updated to include a more recent build of OPA Gatekeeper (hash

Share

Services

## Announcement Policy Controller has been updated to include a more recent build of OPA Gatekeeper (hash: [ a1f01f4 ](https://github.com/open-policy-agent/gatekeeper/tree/a1f01f4)). ## Change Policy Controller bundles have been updated to the following versions: `asm-policy-v0.0.1`: `202310.0`, `cis-k8s-v1.5.1`: `202310.0`, `cost-reliability-v2023`: `202310.0-preview`, `nist-sp-800-190`: `202310.0`, `nist-sp-800-53-r5`: `202310.0`, `nsa-cisa-k8s-v1.2`: `202310.0`, `pci-dss-v3.2.1`: `202310.0`, `policy-essentials-v2022`: `202310.0`, `psp-v2022`: `202310.0`, `pss-baseline-v2022`: `202310.0`, `pss-restricted-v2022`: `202310.0`. For reference, see [Policy Controller bundles overview](https://cloud.google.com/anthos-config-management/docs/concepts/policy-controller-bundles). ## Change The constraint template library's `K8sPSPAllowedUsers`, `K8sPSPAllowPrivilegeEscalationContainer`, `K8sPSPAutomountServiceAccountTokenPod`, `K8sPSPCapabilities`, `K8sPSPFlexVolumes`, `K8sPSPForbiddenSysctls`, `K8sPSPFSGroup`, `K8sPSPHostFilesystem`, `K8sPSPHostNamespace`, `K8sPSPHostNetworkingPorts`, `K8sPSPPrivilegedContainer`, `K8sPSPProcMount`, `K8sPSPReadOnlyRootFilesystem`, `K8sPSPSELinuxV2`, `K8sPSPVolumeTypes`, and `K8sRequiredProbes` no longer raise violations during updates of existing objects for immutable fields. ## Change Updated the Open Telemetry image from 0.86.0 to 0.87.0 to address security vulnerabilities. For more information about these changes, see the full changelog for [opentelemetry-collector-contrib](https://github.com/open-telemetry/opentelemetry-collector-contrib/blob/main/CHANGELOG.md).