Welcome to the v1.1.1 release of the security-profiles-operator!
This is a patch release with many fixes in the controllers, the recorder,
the log enricher, the admission webhooks and spoc, tighter API validation
and a smaller host mount, and a hardened supply chain: the per-arch images are
reproducible and get SLSA Build L3 provenance from GitHub Actions, spoc and
the Helm chart are published as OCI artifacts with their GitHub provenance,
and every staging artifact is signed and attested. It is the first release
whose promotion to registry.k8s.io carries the attestations along and gets
signed SLSA verification summaries of the image promoter. The general
usage and setup can be found in our documentation.
To install the operator, run:
$ kubectl apply -f https://raw.githubusercontent.com/kubernetes-sigs/security-profiles-operator/v1.1.1/deploy/operator.yaml
The operator can also be installed with helm, and spoc, the official
Security Profiles Operator Command Line Interface, is attached to this release
for amd64, arm64, ppc64le and s390x. Both are published as OCI
artifacts to registry.k8s.io/security-profiles-operator as well.
All released artifacts are signed and the release assets carry SLSA build
provenance. Verifying the released artifacts has the commands
for the container images, the binaries, the SBOM and the helm chart.
Feel free to provide us any kind of feedback in the official Kubernetes Slack
#security-profiles-operator channel.
What's Changed
API Changes
- Tighten API validation and fix the documentation by @saschagrunert in #3503
- Fix security, reconciliation, recorder and CI audit findings by @saschagrunert in #3511
- Fix audit findings across daemons, manager, signing and CI by @saschagrunert in #3513
Feature
- Generate SLSA Build L3 provenance for the release assets by @saschagrunert in #3494
- Record the seccomp base profiles on kubernix for amd64 and arm64 by @saschagrunert in #3497
- Sign and attest the platform images in the manifest list repository by @saschagrunert in #3517
- Make the per-arch container images reproducible by @saschagrunert in #3529
- Publish spoc and the Helm chart as OCI artifacts with GitHub provenance by @saschagrunert in #3531
- Attest and verify every staging artifact the promoter checks by @saschagrunert in #3530
- Attest release SBOMs and document the promoter flow by @saschagrunert in #3532
- Attest the per-arch images of releases with GitHub provenance by @saschagrunert in #3533
Bug
- Fix recording and binding webhook correctness by @saschagrunert in #3487
- Fix manager recording, merge and SPOD update correctness by @saschagrunert in #3491
- Close gaps left by the security hardening by @saschagrunert in #3492
- Mount only the kubelet directories instead of the host root by @saschagrunert in #3495
- Fix daemon profile handling correctness issues by @saschagrunert in #3489
- Fix recorder, enricher and spoc bugs by @saschagrunert in #3507
- Harden operator security and fix admission webhooks by @saschagrunert in #3506
- Fix lost audit lines and the log recording e2e waits by @saschagrunert in #3508
- Fix controller reconciliation bugs by @saschagrunert in #3505
- Restrict the provenance signer to releases and harden the release flow by @saschagrunert in #3534
Cleanup
- Fix CI, build and test maintenance findings by @saschagrunert in #3493
- Fix log based seccomp recording and run the Ubuntu e2e on kubernix by @saschagrunert in #3498
- Harden the supply chain, CI and code hygiene by @saschagrunert in #3504
- Update runc to v1.5.2 and crun to 1.30.1 by @saschagrunert in #3510
Full Changelog: v1.1.0...v1.1.1