Changelogπ
The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
[1.23.6-bb.0] 2025-04-17π
Changedπ
- ironbank/opensource/istio/install-cni updated from 1.23.5 to 1.23.6
- ironbank/opensource/istio/pilot updated from 1.23.5 to 1.23.6
- ironbank/opensource/istio/proxyv2 updated from 1.23.5 to 1.23.6
- ironbank/opensource/kubernetes/kubectl updated from v1.30.8 to v1.30.10
- ironbank/tetrate/istio/install-cni updated from 1.23.5 to 1.23.6
- ironbank/tetrate/istio/pilot updated from 1.23.5 to 1.23.6
- ironbank/tetrate/istio/proxyv2 updated from 1.23.5 to 1.23.6
- Updated Gluon to v0.5.15
[1.23.5-bb.1] - 2025-03-25π
Changedπ
- Added an
EnvoyFilter
to simplify classification banner creation
[1.23.5-bb.0] - 2025-02-19π
Changedπ
- ironbank/opensource/istio/install-cni updated from 1.23.4 to 1.23.5
- ironbank/opensource/istio/pilot updated from 1.23.4 to 1.23.5
- ironbank/opensource/istio/proxyv2 updated from 1.23.4 to 1.23.5
- ironbank/opensource/kubernetes/kubectl updated from v1.30.8 to v1.30.10
- ironbank/tetrate/istio/install-cni updated from 1.23.4 to 1.23.5
- ironbank/tetrate/istio/pilot updated from 1.23.4 to 1.23.5
- ironbank/tetrate/istio/proxyv2 updated from 1.23.4 to 1.23.5
- Updated Gluon to v0.5.14
[1.23.4-bb.0] - 2025-01-13π
Changedπ
- ironbank/opensource/istio/install-cni updated from 1.23.3 to 1.23.4
- ironbank/opensource/istio/pilot updated from 1.23.3 to 1.23.4
- ironbank/opensource/istio/proxyv2 updated from 1.23.3 to 1.23.4
- ironbank/opensource/kubernetes/kubectl updated from v1.30.6 to v1.30.8
- ironbank/tetrate/istio/install-cni updated from 1.23.3 to 1.23.4
- ironbank/tetrate/istio/pilot updated from 1.23.3 to 1.23.4
- ironbank/tetrate/istio/proxyv2 updated from 1.23.3 to 1.23.4
[1.23.3-bb.3] - 2025-01-06π
Changedπ
- Update OSCAL to utilize Lula config file & fix templating bug
[1.23.3-bb.2] - 2024-12-10π
Changedπ
- Removed global cpu limit for istio proxy
[1.23.3-bb.1] - 2024-11-25π
Changedπ
- Added app.kubernetes.io/name and app.kubernetes.io/version labels to all workloads
- Removed version label that was added as part of previous Kiali labelling strategy
- Added the maintenance track annotation and badge
[1.23.3-bb.0] - 2024-11-04π
Changedπ
- ironbank/opensource/istio/install-cni updated from 1.23.2 to 1.23.3
- ironbank/opensource/istio/pilot updated from 1.23.2 to 1.23.3
- ironbank/opensource/istio/proxyv2 updated from 1.23.2 to 1.23.3
- ironbank/opensource/kubernetes/kubectl updated from v1.30.5 to v1.30.6
- ironbank/tetrate/istio/install-cni updated from 1.23.2 to 1.23.3
- ironbank/tetrate/istio/pilot updated from 1.23.2 to 1.23.3
- ironbank/tetrate/istio/proxyv2 updated from 1.23.2 to 1.23.3
[1.23.2-bb.1] - 2024-10-21π
Addedπ
- added default, global envoy filter for HSTS and other security headers
[1.23.2-bb.0] - 2024-10-08π
Changedπ
- ironbank/opensource/istio/install-cni updated from 1.22.5 to 1.23.2
- ironbank/opensource/istio/pilot updated from 1.22.5 to 1.23.2
- ironbank/opensource/istio/proxyv2 updated from 1.22.5 to 1.23.2
- ironbank/tetrate/istio/install-cni updated from 1.22.5 to 1.23.2
- ironbank/tetrate/istio/pilot updated from 1.22.5 to 1.23.2
- ironbank/tetrate/istio/proxyv2 updated from 1.22.5 to 1.23.2
[1.22.5-bb.0] - 2024-09-24π
Changedπ
- ironbank/opensource/istio/install-cni updated from 1.22.4 to 1.22.5
- ironbank/opensource/istio/pilot updated from 1.22.4 to 1.22.5
- ironbank/opensource/istio/proxyv2 updated from 1.22.4 to 1.22.5
- ironbank/opensource/kubernetes/kubectl updated from v1.29.6 to v1.30.5
- ironbank/tetrate/istio/install-cni updated from 1.22.4 to 1.22.5
- ironbank/tetrate/istio/pilot updated from 1.22.4 to 1.22.5
- ironbank/tetrate/istio/proxyv2 updated from 1.22.4 to 1.22.5
[1.22.4-bb.2] - 2024-09-16π
Addedπ
- Gluon post-install wait scripts
[1.22.4-bb.1] - 2024-08-22π
Changedπ
- Updating Istio
oscal-component.yaml
to include Lula validations for automated assessment
Addedπ
- Added
oscal-assessment-results.yaml
as a threshold for automated governance
[1.22.4-bb.0] - 2024-08-21π
Changedπ
- ironbank/opensource/istio/install-cni updated from 1.22.3 to 1.22.4
- ironbank/opensource/istio/pilot updated from 1.22.3 to 1.22.4
- ironbank/opensource/istio/proxyv2 updated from 1.22.3 to 1.22.4
- ironbank/tetrate/istio/install-cni updated from 1.22.3 to 1.22.4
- ironbank/tetrate/istio/pilot updated from 1.22.3 to 1.22.4
- ironbank/tetrate/istio/proxyv2 updated from 1.22.3 to 1.22.4
[1.22.3-bb.0] - 2024-07-18π
Changedπ
- ironbank/opensource/istio/install-cni updated from 1.22.2 to 1.22.3
- ironbank/opensource/istio/pilot updated from 1.22.2 to 1.22.3
- ironbank/opensource/istio/proxyv2 updated from 1.22.2 to 1.22.3
- ironbank/tetrate/istio/install-cni updated from 1.22.2 to 1.22.3
- ironbank/tetrate/istio/pilot updated from 1.22.2 to 1.22.3
- ironbank/tetrate/istio/proxyv2 updated from 1.22.2 to 1.22.3
[1.22.2-bb.2] - 2024-07-10π
Addedπ
- Added native sidecar support
[1.22.2-bb.1] - 2024-07-09π
Changedπ
- Standardized authorization policy template directory path
[1.22.2-bb.0] - 2024-07-01π
Changedπ
- ironbank/opensource/istio/install-cni updated from 1.22.1 to 1.22.2
- ironbank/opensource/istio/pilot updated from 1.22.1 to 1.22.2
- ironbank/opensource/istio/proxyv2 updated from 1.22.1 to 1.22.2
- ironbank/tetrate/istio/install-cni updated from 1.22.1 to 1.22.2
- ironbank/tetrate/istio/pilot updated from 1.22.1 to 1.22.2
- ironbank/tetrate/istio/proxyv2 updated from 1.22.1 to 1.22.2
[1.22.1-bb.0] - 2024-06-14π
Changedπ
- ironbank/opensource/istio/install-cni updated from 1.21.2 to 1.22.1
- ironbank/opensource/istio/pilot updated from 1.21.2 to 1.22.1
- ironbank/opensource/istio/proxyv2 updated from 1.21.2 to 1.22.1
- ironbank/tetrate/istio/install-cni updated from 1.21.2 to 1.22.1
- ironbank/tetrate/istio/pilot updated from 1.21.2 to 1.22.1
- ironbank/tetrate/istio/proxyv2 updated from 1.21.2 to 1.22.1
[1.21.2-bb.3] - 2024-06-12π
Changedπ
- Moved the package specific shared istio authorization to their helm charts
[1.21.2-bb.2] - 2024-06-12π
Changedπ
- Revert to correct overwritten dashboard changes
[1.21.2-bb.1] - 2024-05-28π
Changedπ
- Added the shared istio authorization policies
[1.21.2-bb.0] - 2024-05-16π
Changedπ
- ironbank/opensource/istio/install-cni updated from 1.21.1 to 1.21.2
- ironbank/opensource/istio/pilot updated from 1.21.1 to 1.21.2
- ironbank/opensource/istio/proxyv2 updated from 1.21.1 to 1.21.2
- ironbank/tetrate/istio/install-cni updated from 1.21.1 to 1.21.2
- ironbank/tetrate/istio/pilot updated from 1.21.1 to 1.21.2
- ironbank/tetrate/istio/proxyv2 updated from 1.21.1 to 1.21.2
[1.21.1-bb.1] - 2024-05-13π
Removedπ
- Removed native sidecar support because we have to support 1.27.x
[1.21.1-bb.0] - 2024-05-03π
Changedπ
- ironbank/opensource/istio/install-cni updated from 1.20.4 to 1.21.1
- ironbank/opensource/istio/pilot updated from 1.20.4 to 1.21.1
- ironbank/opensource/istio/proxyv2 updated from 1.20.4 to 1.21.1
- ironbank/tetrate/istio/install-cni updated from 1.20.4 to 1.21.1
- ironbank/tetrate/istio/pilot updated from 1.20.4 to 1.21.1
- ironbank/tetrate/istio/proxyv2 updated from 1.20.4 to 1.21.1
[1.20.4-bb.3] - 2024-05-02π
Addedπ
- Added custom network policies
[1.20.4-bb.2] - 2024-04-23π
Addedπ
- Added native sidecar support
[1.20.4-bb.1] - 2024-04-04π
Fixedπ
- Upgrade new istio dashboards to fix βPrometheusβ vs βprometheusβ datasource issue
[1.20.4-bb.0] - 2024-03-25π
Changedπ
- ironbank/opensource/istio/install-cni updated from 1.19.7 to 1.20.4
- ironbank/opensource/istio/pilot updated from 1.19.7 to 1.20.4
- ironbank/opensource/istio/proxyv2 updated from 1.19.7 to 1.20.4
- ironbank/tetrate/istio/install-cni updated from 1.20.3 to 1.20.4
- ironbank/tetrate/istio/pilot updated from 1.20.3 to 1.20.4
- ironbank/tetrate/istio/proxyv2 updated from 1.20.3 to 1.20.4
[1.19.7-bb.0] - 2024-02-13π
Changedπ
- ironbank/opensource/istio/install-cni updated from 1.19.6 to 1.19.7
- ironbank/opensource/istio/pilot updated from 1.19.6 to 1.19.7
- ironbank/opensource/istio/proxyv2 updated from 1.19.6 to 1.19.7
- ironbank/tetrate/istio/install-cni updated from 1.20.2 to 1.20.3
- ironbank/tetrate/istio/pilot updated from 1.20.2 to 1.20.3
- ironbank/tetrate/istio/proxyv2 updated from 1.20.2 to 1.20.3
[1.19.6-bb.2] - 2024-02-12π
Addedπ
- added postInstallHook.containerResources values for hook-job.yaml
[1.19.6-bb.1] - 2024-01-31π
Addedπ
- added security context values for pilot pod for kyverno-polices to allow the pilot image
[1.19.6-bb.0] - 2024-01-12π
Changedπ
- ironbank/opensource/istio/install-cni updated from 1.19.5 to 1.19.6
- ironbank/opensource/istio/pilot updated from 1.19.5 to 1.19.6
- ironbank/opensource/istio/proxyv2 updated from 1.19.5 to 1.19.6
- ironbank/tetrate/istio/install-cni updated from 1.19.6 to 1.20.2
- ironbank/tetrate/istio/pilot updated from 1.19.5 to 1.20.2
- ironbank/tetrate/istio/proxyv2 updated from 1.19.5 to 1.20.2
[1.19.5-bb.2] - 2023-12-29π
Changedπ
- ironbank/tetrate/istio/install-cni updated from 1.19.3 to 1.19.6
- ironbank/tetrate/istio/pilot updated from 1.19.3 to 1.19.5
- ironbank/tetrate/istio/proxyv2 updated from 1.19.3 to 1.19.5
[1.19.5-bb.1] - 2023-12-19π
Changedπ
- Allow Setting resources and limits for the postInstallHook
[1.19.5-bb.0] - 2023-12-19π
Changedπ
- ironbank/opensource/istio/install-cni updated from 1.19.4 to 1.19.5
- ironbank/opensource/istio/pilot updated from 1.19.4 to 1.19.5
- ironbank/opensource/istio/proxyv2 updated from 1.19.4 to 1.19.5
[1.19.4-bb.1] - 2023-11-28π
Changedπ
- Updating OSCAL Component file.
[1.19.4-bb.0] - 2023-11-15π
Changedπ
- ironbank/opensource/istio/install-cni updated from 1.19.3 to 1.19.4
- ironbank/opensource/istio/pilot updated from 1.19.3 to 1.19.4
- ironbank/opensource/istio/proxyv2 updated from 1.19.3 to 1.19.4
[1.19.3-bb.1] - 2023-11-07π
Changedπ
- ironbank/big-bang/base updated from 2.0.0 to 2.1.0
[1.19.3-bb.0] - 2023-10-14π
Changedπ
- ironbank/opensource/istio/install-cni updated from 1.19.0 to 1.19.3
- ironbank/opensource/istio/pilot updated from 1.19.0 to 1.19.3
- ironbank/opensource/istio/proxyv2 updated from 1.19.0 to 1.19.3
- ironbank/tetrate/istio/install-cni updated from 1.18.2 to 1.19.3
- ironbank/tetrate/istio/pilot updated from 1.18.2 to 1.19.3
- ironbank/tetrate/istio/proxyv2 updated from 1.18.2 to 1.19.3
[1.19.0-bb.2] - 2023-10-11π
Changedπ
- Modified OSCAL Version for istio and updated to 1.1.1
[1.19.0-bb.1] - 2023-10-02π
Changedπ
- Enable Istio mTLS (via peerAuthentication) globally on istio-system namespace
[1.19.0-bb.0] - 2023-09-12π
Changedπ
- ironbank/opensource/istio/install-cni updated from 1.18.2 to 1.19.0
- ironbank/opensource/istio/pilot updated from 1.18.2 to 1.19.0
- ironbank/opensource/istio/proxyv2 updated from 1.18.2 to 1.19.0
[1.18.2-bb.1] - 2023-08-16π
Changedπ
- istio control plane default config
[1.18.2-bb.0] - 2023-08-02π
Changedπ
- ironbank/opensource/istio/install-cni updated from 1.18.1 to 1.18.2
- ironbank/opensource/istio/pilot updated from 1.18.1 to 1.18.2
- ironbank/opensource/istio/proxyv2 updated from 1.18.1 to 1.18.2
- ironbank/tetrate/istio/install-cni updated from 1.18.0 to 1.18.2
- ironbank/tetrate/istio/pilot updated from 1.18.0 to 1.18.2
- ironbank/tetrate/istio/proxyv2 updated from 1.18.0 to 1.18.2
- Updated to new HPA value schema
[1.18.1-bb.0] - 2023-07-20π
Changedπ
- ironbank/opensource/istio/install-cni updated from 1.17.3 to 1.18.1
- ironbank/opensource/istio/pilot updated from 1.17.3 to 1.18.1
- ironbank/opensource/istio/proxyv2 updated from 1.17.3 to 1.18.1
- ironbank/tetrate/istio/install-cni updated from 1.17.3 to 1.18.1
- ironbank/tetrate/istio/pilot updated from 1.17.3 to 1.18.0
- ironbank/tetrate/istio/proxyv2 updated from 1.17.3 to 1.18.0
[1.18.1-bb.0] - 2023-07-20π
Changedπ
- ironbank/opensource/istio/install-cni updated from 1.17.3 to 1.18.1
- ironbank/opensource/istio/pilot updated from 1.17.3 to 1.18.1
- ironbank/opensource/istio/proxyv2 updated from 1.17.3 to 1.18.1
- ironbank/tetrate/istio/install-cni updated from 1.17.3 to 1.18.1
- ironbank/tetrate/istio/pilot updated from 1.17.3 to 1.18.0
- ironbank/tetrate/istio/proxyv2 updated from 1.17.3 to 1.18.0
[1.17.3-bb.3] - 2023-07-12π
Addedπ
- Allow user to specify their own
EnvoyFilters
[1.17.3-bb.2] - 2023-07-12π
Changedπ
- fix README.md for bb docs compiler job
[1.17.3-bb.1] - 2023-06-28π
Changedπ
- ironbank/opensource/istio/pilot updated from 1.17.2 to 1.17.3
- ironbank/opensource/istio/proxyv2 updated from 1.17.2 to 1.17.3
[1.17.3-bb.0] - 2023-06-26π
Changedπ
- ironbank/opensource/istio/install-cni updated from 1.17.2 to 1.17.3
- ironbank/tetrate/istio/install-cni updated from 1.17.2 to 1.17.3
- ironbank/tetrate/istio/pilot updated from 1.17.2 to 1.17.3
- ironbank/tetrate/istio/proxyv2 updated from 1.17.2 to 1.17.3
[1.17.2-bb.1] - 2023-05-26π
Addedπ
- Added scc for OpenShift
[1.17.2-bb.1] - 2023-05-04π
Changedπ
- ironbank/tetrate/istio/install-cni updated from 1.16.1 to 1.17.2
- ironbank/tetrate/istio/pilot updated from 1.16.1 to 1.17.2
- ironbank/tetrate/istio/proxyv2 updated from 1.16.1 to 1.17.2
[1.17.2-bb.0] - 2023-04-11π
Changedπ
- ironbank/opensource/istio/install-cni updated from 1.17.1 to 1.17.2
- ironbank/opensource/istio/pilot updated from 1.17.1 to 1.17.2
- ironbank/opensource/istio/proxyv2 updated from 1.17.1 to 1.17.2
[1.17.1-bb.1] - 2023-04-07π
Changedπ
- Added ability to pass pilot values to IstioOperator resource definition
[1.17.1-bb.0] - 2023-03-01π
Changedπ
- ironbank/opensource/istio/install-cni updated from 1.16.2 to 1.17.1
- ironbank/opensource/istio/pilot updated from 1.16.2 to 1.17.1
- ironbank/opensource/istio/proxyv2 updated from 1.16.2 to 1.17.1
[1.16.2-bb.0] - 2023-02-10π
Changedπ
- ironbank/opensource/istio/install-cni updated from 1.16.1 to 1.16.2
- ironbank/opensource/istio/pilot updated from 1.16.1 to 1.16.2
- ironbank/opensource/istio/proxyv2 updated from 1.16.1 to 1.16.2
[1.16.1-bb.2] - 2023-02-08π
Changedπ
- Removed tetrate istioctl and install-cni image references
[1.16.1-bb.1] - 2023-01-27π
Changedπ
- ironbank/tetrate/istio/install-cni updated from 1.15.1 to 1.16.1
- ironbank/tetrate/istio/istioctl updated from 1.15.1 to 1.16.1
- ironbank/tetrate/istio/pilot updated from 1.15.1 to 1.16.1
- ironbank/tetrate/istio/proxyv2 updated from 1.15.1 to 1.16.1
[1.16.1-bb.0] - 2022-12-17π
Changedπ
- ironbank/opensource/istio/install-cni updated from 1.15.3 to 1.16.1
- ironbank/opensource/istio/pilot updated from 1.15.3 to 1.16.1
- ironbank/opensource/istio/proxyv2 updated from 1.15.3 to 1.16.1
[1.15.3-bb.1]π
Changedπ
- Splits the
postInstallHook
image and tag so that they can be maintained separately.
[1.15.3-bb.0] - 2022-11-01π
Changedπ
- ironbank/opensource/istio/install-cni updated from 1.15.0 to 1.15.3
- ironbank/opensource/istio/pilot updated from 1.15.0 to 1.15.3
- ironbank/opensource/istio/proxyv2 updated from 1.15.0 to 1.15.3
- ironbank/tetrate/istio/install-cni updated from 1.14.4 to 1.15.1
- ironbank/tetrate/istio/istioctl updated from 1.14.4 to 1.15.1
- ironbank/tetrate/istio/pilot updated from 1.14.4 to 1.15.1
- ironbank/tetrate/istio/proxyv2 updated from 1.14.4 to 1.15.1
[1.15.0-bb.1] - 2022-09-30π
Changedπ
- ironbank/tetrate/istio/install-cni updated from 1.14.3 to 1.14.4
- ironbank/tetrate/istio/istioctl updated from 1.14.3 to 1.14.4
- ironbank/tetrate/istio/pilot updated from 1.14.3 to 1.14.4
- ironbank/tetrate/istio/proxyv2 updated from 1.14.3 to 1.14.4
[1.15.0-bb.0] - 2022-09-17π
Changedπ
- ironbank/opensource/istio/install-cni updated from 1.14.3 to 1.15.0
- ironbank/opensource/istio/pilot updated from 1.14.3 to 1.15.0
- ironbank/opensource/istio/proxyv2 updated from 1.14.3 to 1.15.0
- ironbank/tetrate/istio/install-cni updated from 1.13.5 to 1.14.3
- ironbank/tetrate/istio/istioctl updated from 1.13.5 to 1.14.3
- ironbank/tetrate/istio/pilot updated from 1.13.5 to 1.14.3
- ironbank/tetrate/istio/proxyv2 updated from 1.13.5 to 1.14.3
[1.14.3-bb.4]π
Changedπ
- Adds env variable to values which can be used during deployment to modify istio k8s env settings
[1.14.3-bb.3]π
Changedπ
- Drop all capabilities + nonroot for hook job
[1.14.3-bb.2]π
Changedπ
- Added Openshift DNS to networkpolicy egress
[1.14.3-bb.1]π
Changedπ
- Removed legacy fluentd exception
[1.14.3-bb.0]π
Changedπ
- Updated to 1.14.3 images
[1.14.2-bb.2]π
Addedπ
- Moved dashboards from monitoring chart into Istio
[1.14.2-bb.1]π
Addedπ
- Added minPRotocolVersion: TLSV1_2
[1.14.2-bb.0]π
Changedπ
- Updated chart to
1.14.2-bb.0
version - Updated images to
1.14.2
- Updated app version to 1.14.2 in
Chart.yaml
[1.13.5-bb.2]π
Addedπ
- Added support for egress gateways via values
[1.13.5-bb.1]π
Changedπ
- Updated TID images to
1.13.5
[1.13.5-bb.0]π
Changedπ
- Updated chart to
1.13.5-bb.0
version - Updated images to
1.13.5
- Updated app version to 1.13.5 in
Chart.yaml
[1.13.4-bb.4]π
Changedπ
- Update the OSCAL component definition for Istio to include additional NIST 800-53 mappings and explanations.
[1.13.4-bb.3]π
Addedπ
- Added tolerations to Jobs
[1.13.4-bb.2]π
Changedπ
- Updated BB base image to 2.0.0
[1.13.4-bb.1]π
Changedπ
- Updated BB base image to 1.17.0
[1.13.4-bb.0]π
Changedπ
- Updated chart to
1.13.4-bb.0
version - Updated images to
1.13.4
- Updated app version to 1.13.4 in
Chart.yaml
[1.13.2-bb.1]π
Changedπ
- fix pod selector for NetworkPolicy
[1.13.2-bb.0]π
Changedπ
- Updated chart to
1.13.2-bb.0
version - Updated app version to 1.13.2 in
Chart.yaml
[1.13.1-bb.3]π
Changedπ
- Added TID support
[1.13.1-bb.2]π
Changedπ
- Added Kiali ingress policy for version scraping
[1.13.1-bb.1]π
Changedπ
- Added
values.defaultRevision
to support deployment of validatingWebhook - https://github.com/istio/istio/pull/35694
[1.13.1-bb.0]π
Changedπ
- Updated chart to
1.13.1-bb.0
version - Updated app version to 1.13.1 in
Chart.yaml
[1.11.5-bb.2]π
Changedπ
- Updated
renovate.json
to track images intests/images.txt
- fixed typos in
oscal-component.yaml
[1.11.5-bb.1]π
Changedπ
- Update Chart.yaml to follow new standardization for release automation
[1.11.5-bb.0]π
Changedπ
- Updated to 1.11.5
[1.11.3-bb.2]π
Addedπ
- Istio OSCAL component for NIST 800-53 controls
[1.11.3-bb.1]π
Changedπ
- Fix envoyfilter handling of DNS names with
-
[1.11.3-bb.0]π
Changedπ
- Updated Istio to 1.11.3
Addedπ
tests/images.txt
for use in package release to include theinstall-cni
image- Revision support for SSO egress NP
[1.11.2-bb.4]π
Addedπ
- A Helm post-install hook so a HelmRelease properly reflects IstioOperator status.
[1.11.2-bb.3]π
Changedπ
- Introduces the
revision
value in support of Istio canary upgrades. When specified, the revision value is appended to resources names.
[1.11.2-bb.2]π
Fixedπ
- Changed misdirected request envoy filter to work with non-standard ports
[1.11.2-bb.1]π
Addedπ
- Added autoHttpRedirect value to control the automatic generation of http to https redirects in the gateways
Changedπ
- Changed to using the hosts defined in servers.hosts instead of using * for the automatic generation of http to https redirects in the gateways
[1.11.2-bb.0]π
Changedπ
- Update to Istio 1.11.2
[1.10.4-bb.3]π
Changedπ
- Added networkpolicy to allow egress to sso
[1.10.4-bb.2]π
Changedπ
- Added authservice as extension provider
[1.10.4-bb.1]π
Changedπ
- Update Istio proxy and proxy init pods to be in compliance with opa gatekeeper.
[1.10.4-bb.0]π
Changedπ
- Update to Istio 1.10.4
[1.10.3-bb.1]π
Changedπ
- Add envoyfilter to remove server response header to prevent information disclosure
[1.10.3-bb.0]π
Changedπ
- Update to Istio 1.10.3
[1.9.7-bb.1]π
Addedπ
- Default configuration to hold application start until istio proxy is ready
[1.9.7-bb.0]π
Changedπ
- Update to Istio 1.9.7
[1.8.4-bb.6]π
Changedπ
- BREAKING
ingressGateway
deprecated in favor of creatingingressGateways
in a uniform manner - BREAKING
gateway
deprecated in favor of creatinggateways
in a uniform manner
[1.8.4-bb.5]π
Fixedπ
- Kube API egress allowed for all pods, not just istiod
[1.8.4-bb.4]π
Addedπ
- Kube API egress networkpolicy
[1.8.4-bb.3]π
Addedπ
- Added network policies for istio
[1.8.4-bb.2]π
Fixedπ
- fixed bug with indentation when providing resources to istio ingressgateways
[1.8.4-bb.1]π
Fixedπ
- updated dsop.io registry hostname to dso.mil
[1.7.3-bb.1]π
Addedπ
- Top level βssoβ values designation. This will enable an haproxy package installation in the desired namespace (sso.namespace: istio-addons-sso) that in conjunction with authservice package will place an SSO gate in front of Kiali+Jaeger UIs.
- Top level βingressβ values designation. This will control configuration for the virtualservices created. Leave empty with sso.enabled = false to have the virtualservices go straight to the kiali/jaeger UIs. Leave empty with sso.enabled = true to place the haproxy+authservice injection in front of kiali/tracing. Fill in with your own service/port if customizing the installation/services.
- New Jaeger+Kiali VirtualServices pointing to the haproxy installation will be installed when βsso.enabled: trueβ
- sso.selector variable sets the label that will be applied to the authservice EnvoyFilter placing the SSO page in front of the regular UIs. Must match the selector for βauthservice.selector.key/valueβ.
Changedπ
- Jaeger+Kiali VirtualServices pointing directly to the UIs will be skipped when βsso.enabled: trueβ
- Jaeger+Kiali VirtualServices pull in their configs from the βingressβ designation so VirtualServices can be customized.