Releases
1.0.24
Change log
1.0.24
Use runtime-1 as the default cert name
Make changes for Azure deployment
1.0.23
Changes for Azure market place offer
1.0.22
Create inline scan mode; Dont run redis, celery-worker, beat in inline scan mode
1.0.21
Add support for gke autopilot
Move images to global.azure for Azure k8s marketplace
Remove dependency on runner image
Use quay base images
Remove rf-registry image
1.0.20
Make webhooks fail open
Ensure system works in fail open mode for redis
Fix dockerfile issue
Add initial version of rf-cmd
1.0.19
Add fix for handling pods without label
Add rf_username to configmap
Add cluster_name to project dict
Fix inline scan
Add support for istio egress control
Support slim installer fast builds
Integrate clientside hardening tools
Update redis to 7.2 from 6.2
Add Openshift support by adding crio variant
1.0.18
Add celery-beat for scheduling node changes
Reduce CPU and mem consumption
Add redis wait to avoid restarts
Quay.io integration for helm repository, Container registry and Image pull secret
1.0.17
Fix disabling monitoring and scanning using labels
Remove tmp mount path
Document error message timeouts for resock
Make quay as default registry in helm chart
Make TCP-IP as default communication mode
Dont use hostPath in TCP-IP mode
Use static download handler rtmf tar
Create priority classes for daemonsets
Change requests=limits for autopilot
1.0.16
Fix stub type for prodmon hardening
Use repo tags whenever possible for naming
Fix memory/storage leak with upload_image option
Fix prodmon hardening sleep sequence
1.0.15
Add export image option
Add azure storage support
Fix bug related to celery-worker crash during restart
Enable meta-copy by default
1.0.14
Support non_privileged mode
Push rf-monitor-init container in all nodes using daemonset
Support for pulling docker image using image pull secret
Support profiling for read only containers using BPF
1.0.13
Fix install script to make it argument based and fail safe
Support socket override path
Improve scale by making webhook and api-server async
Support namespace mode in installation
1.0.12
Support gcloud Artifact Registry for load_image
Handle read only filesystem gracefully
Dont patch init-containers for readiness probe
Add debug and vebose flags to installer
Support security context difference between pod and container
1.0.11
Support kubernetes environment variable expansion
Handle new line characters in multi-line args in pod manifest
1.0.10
Support for adding labels using -f option in installer
Fix issue with pod as security context to run as non-root
Add instructions as part of the installer
1.0.9
Support deployment mode=namespace for Role only access
Remove cert-manager dependency
Support Rancher deployments
Support Mac installation without docker
Support azure, gcloud and aws for load_image
1.0.8
Use crictl for CRI engines to handle discard_unpacked_layers
Helm chart pull policy issues
Add load_images.sh and improve install.sh for on-prem release
Package cert-manager as helm chart
You can’t perform that action at this time.