[gardener-extension-shoot-cert-service]
🏃 Others
- [USER] Allow access to ACME CA on private network. (gardener/gardener-extension-shoot-cert-service#109, @MartinWeindel)
📰 Noteworthy
- [OPERATOR] The extension controller uses a projected
ServiceAccount
token in case it runs on a seed with a gardenlet of at leastv1.37
or higher. Similarly, thecert-controller-manager
deployed into shoot namespaces will no longer use a client certificate but an auto-rotatedServiceAccount
token which is only valid for12h
. (gardener/gardener-extension-shoot-cert-service#103, @rfranzke) - [DEVELOPER] The Golang version has been updated to
1.17.5
. (gardener/gardener-extension-shoot-cert-service#103, @rfranzke)
[cert-management]
🐛 Bug Fixes
- [OPERATOR] Fix unknown resource for group kind "Ingress.networking.k8s.io" on K8s 1.18 (regression issue of #98) (gardener/cert-management#99, @MartinWeindel)
🏃 Others
- [OPERATOR] Restrict discovery client calls to used groups to reduce API calls on startup (gardener/cert-management#98, @MartinWeindel)
- [OPERATOR] Switch default leader election resource lock from
configmapsleases
toleases
(gardener/cert-management#97, @MartinWeindel)
📰 Noteworthy
- [DEVELOPER] The Golang version has been updated to
1.17.5
. (gardener/cert-management#96, @MartinWeindel)