Releases: accuknox/discovery-engine
Releases · accuknox/discovery-engine
v0.8.1
What's Changed
- Update stabe release to v0.8 by @seswarrajan in #656
- remove process fromsource by @achrefbensaad in #657
- Add missing configuration by @seswarrajan in #659
- Discovery Engine cluster role by @vishnusomank in #661
- Fix gosec issue by @Prateeknandle in #664
- valut app bind fix for summary by @yasin-cs-ko-ak in #669
- Recommend host hardening policies by @vishnusomank in #662
- removing namespace dependency of kubearmor for discovery-engine by @Prateeknandle in #674
- Fix for incorrect policy Kind in generated policies by @seswarrajan in #677
- Issue #675: karmor summary flags are ignored by @Vyom-Yadav in #679
- adding smoke tests by @Prateeknandle in #653
- Policy name randomizer for network-policy by @seswarrajan in #678
- fix data race conditions by @Ankurk99 in #691
- Forming HashInt for naming network-policy by @seswarrajan in #695
- refactored code for kubearmor relay connect by @nyrahul in #698
- Modify hardcoded port value to be read from config by @seswarrajan in #699
- Update stable version to 0.9 by @seswarrajan in #700
- fix logic for missing kubearmor-relay deployment by @Ankurk99 in #705
- feat: Add logic for Kyverno policy recommendation by @Vyom-Yadav in #701
- [Bug] Update system policies correctly by @Vyom-Yadav in #680
- feat(license): add license feature by @rajaSahil in #702
- feat(license): fix code by @rajaSahil in #712
- Display summary data per deployment by @vishnusomank in #697
- get hardening policies for
replicasets
,statefulsets
&daemonsets
by @Prateeknandle in #681 - fix: Add complete arguments to GetHardenPolicy(..) in recommend test by @Vyom-Yadav in #716
- fix(license): minor code fix by @rajaSahil in #717
- fix(summary): exclude
container_id
fromsystem_summary
table by @yasin-cs-ko-ak in #713 - chores(deployments): add rules by @rajaSahil in #720
- feat(license): add config for license by @rajaSahil in #721
- fix(license): add license enable check by @rajaSahil in #722
- Added pprof to discovery-engine by @stefin9898 in #724
- Added mux handler for pprof debug endpoint by @stefin9898 in #726
- Added routes in http handle for pprof by @stefin9898 in #728
New Contributors
- @Vyom-Yadav made their first contribution in #679
Full Changelog: 0.8...v0.8.1
0.8
What's Changed
- Update stable release by @seswarrajan in #608
- Updated Helm Chart by @wazir-ahmed in #609
- optimize auto-detected paths by @achrefbensaad in #600
- helm: Set network-log-from field to kubearmor by @wazir-ahmed in #611
- Update helm chart by @seswarrajan in #612
- make disocvered policies work by @achrefbensaad in #610
- release stable by @achrefbensaad in #613
- create v0.7.5 release by @achrefbensaad in #614
- Purge Old DB Entries by @yasin-cs-ko-ak in #603
- Proto Changes for Summary data by @yasin-cs-ko-ak in #604
- make discovered network policies work by @achrefbensaad in #616
- update stable to v0.7.6 by @achrefbensaad in #618
- dont send network policies to feeder service by @achrefbensaad in #619
- set stable to v0.7.7 by @achrefbensaad in #621
- Change to deploy discovery-engine in accuknox-agents namespace by @seswarrajan in #620
- Add workspaceID to grpc response by @seswarrajan in #622
- matchLabels Updated for discovery-engine. by @yasin-cs-ko-ak in #617
- Fixing GH workflow to check pods in accuknox-agents namespace as per … by @seswarrajan in #623
- bind port connection details (SYS_BIND) by @yasin-cs-ko-ak in #624
- [fix] bind port connection added in db by @yasin-cs-ko-ak in #626
- Add workspaceId to policy_yaml by @seswarrajan in #629
- Update discovery-engine to send workspace_id and cluster_id with policies by @stefin9898 in #633
- enhancement for bind points by @yasin-cs-ko-ak in #628
- reduce the usage of k8s client api by @Ankurk99 in #625
- namespace correction in filter options by @seswarrajan in #635
- fix ingress and egress by @yasin-cs-ko-ak in #634
- Update policy_yaml cluster_name from config by @seswarrajan in #636
- Add podSelector.MatchLables to labels in Spec by @seswarrajan in #641
- Fix for issue : Labels not getting displayed in case of K8sNetPol by @seswarrajan in #645
- Show recommended policy using DE by @vishnusomank in #643
- Show recommended policy using DE by @vishnusomank in #646
- changed org in workflows by @nyrahul in #648
- Show recommended policy using DE by @vishnusomank in #651
- Fix for invalid timestamp for Kubearmor alerts by @seswarrajan in #649
- adding ci workflow for ginkgo tests by @Prateeknandle in #650
- add env variables for helm chart installation by @Ankurk99 in #654
- update default resource usage by @Ankurk99 in #640
- Show recommended policy for new deployments by @vishnusomank in #652
- Use Kubearmor Alert struct instead of Log by @seswarrajan in #655
New Contributors
- @stefin9898 made their first contribution in #633
- @vishnusomank made their first contribution in #643
- @Prateeknandle made their first contribution in #650
Full Changelog: 0.7.3...0.8
0.7.3
What's Changed
- Update stable release to point to v0.7.2 by @seswarrajan in #605
- fix typo by @achrefbensaad in #606
- knoxNetPolicy - namespace not added to policy metadata by @seswarrajan in #607
Full Changelog: 0.7.2...0.7.3
0.7.2
What's Changed
- Syntax correction for policy yaml in mysqlHandler by @seswarrajan in #550
- change GH org to kubearmor by @nyrahul in #554
- Update stable release tag by @seswarrajan in #555
- Stream policy updates to GRPC clients by @wazir-ahmed in #556
- [karmor summary] Added Time Stamps and Count for Ingress and Egress Connections by @yasin-cs-ko-ak in #561
- UpdatedTime Issues Fixed by @yasin-cs-ko-ak in #562
- Discover k8s generic net policy from kubearmor logs by @seswarrajan in #564
- fixed dependabort security alert by @nyrahul in #571
- Initial commit for summarizer and publisher (worker DE) by @seswarrajan in #569
- fix(publisher): fix exception by @rajaSahil in #572
- Publisher: Fix publish logic in code by @seswarrajan in #573
- fix-typo by @achrefbensaad in #574
- Add summarizer/publisher changes to DE deployment by @seswarrajan in #576
- helm chart update by @Nagarajan0396 in #570
- Fix the indent error in Helm chart by @Nagarajan0396 in #582
- Filter file paths for relative paths by @Ankurk99 in #577
- enable arm ci by @achrefbensaad in #584
- chore(CI): increase build timeout by @achrefbensaad in #585
- K8s Net pol -- UDP handling by @seswarrajan in #580
- removed arm64 build support by @nyrahul in #588
- Add Workspace Id to publisher proto by @seswarrajan in #590
- Update STABLE-RELEASE to version v0.7.1 by @seswarrajan in #591
- Summary data fetch DB change by @seswarrajan in #592
- Update publisher config in helm chart + remove unwanted helm config by @seswarrajan in #593
- make network rules optional for system policy by @achrefbensaad in #583
- Modify discover options to support the kind value by @seswarrajan in #594
- fix(CI): add labels to docker image by @achrefbensaad in #589
- Read cluster_id from env variable and add it to summary data by @seswarrajan in #596
- check if resource exist - to filter relative paths by @Ankurk99 in #599
- Kind handling in grpc for network policy by @seswarrajan in #602
New Contributors
- @yasin-cs-ko-ak made their first contribution in #561
- @rajaSahil made their first contribution in #572
- @achrefbensaad made their first contribution in #574
- @Nagarajan0396 made their first contribution in #570
Full Changelog: v0.6.4...0.7.2
v0.6.4
What's Changed
- Add fromsource, ns filters in system policy by @seswarrajan in #531
- cilium: Add TCP flags filter to hubble observer by @wazir-ahmed in #533
- remove use of ubuntu 18.04 in all GH actions by @nyrahul in #534
- Handle nsfilter/fromsource filter from a common func by @seswarrajan in #532
- Revert "Handle nsfilter/fromsource filter from a common func" by @seswarrajan in #535
- Enable Observability by @seswarrajan in #536
- remove duplicate github action by @Ankurk99 in #537
- Modified hubble filter flags to get the least amount of traffic possible by @wazir-ahmed in #538
- Enable observability/store AD policy in DB by @seswarrajan in #539
- Handle summary request type by @seswarrajan in #541
- Enable aggregation for kubearmor summary data - process/file by @seswarrajan in #542
- Change summary file aggregation logic summary #171 by @seswarrajan in #545
- Add logic to handle deny logs by @seswarrajan in #547
- Create stable release with branch v0.6 by @seswarrajan in #549
Full Changelog: v0.6.3...v0.6.4
v0.6.3
What's Changed
- Fix for ns,podname setup in discovery-engine for container ns by @seswarrajan in #528
Full Changelog: v0.6.2...v0.6.3
v0.6.2
v0.6.1
v0.6.0
What's Changed
- Fix for database locked issue. Close DB after usage by @seswarrajan in #500
- Paths gets appended to processes of policy when requesting policies per namespace by @seswarrajan in #504
- Refactored code to aggregate network policy per deployment/endpoint by @wazir-ahmed in #499
- Handling/Adding preconfigured rule for Kubearmor policy by @seswarrajan in #506
- Modified fsset to json in wpfs DB by @seswarrajan in #507
- cilium: Parsing is_reply flag from kafka feeds by @wazir-ahmed in #508
- Modified fsset to use recordsepartor in wpfs DB by @seswarrajan in #509
- Disabling observability by @seswarrajan in #510
- GH actions; release-guide by @nyrahul in #511
- Extract svc/pod IP from cluster info by @seswarrajan in #519
- Modify k3s installation script by @seswarrajan in #520
- cilium: Fix for ICMP rules duplication by @wazir-ahmed in #516
- Support for network policy discovery in VMs by @wazir-ahmed in #517
- Creating new config under configmap for observability by @seswarrajan in #521
- Support for new feed-consumer plugin - Apache Pulsar by @wazir-ahmed in #515
- Observability : handle log update/insert in a single function by @seswarrajan in #522
- support observability for containerized workloads by @Ankurk99 in #514
Full Changelog: v0.3...v0.6.0
v0.5-nonk8s
What's Changed
- Fix for database locked issue. Close DB after usage by @seswarrajan in #500
- Paths gets appended to processes of policy when requesting policies per namespace by @seswarrajan in #504
- Refactored code to aggregate network policy per deployment/endpoint by @wazir-ahmed in #499
- Handling/Adding preconfigured rule for Kubearmor policy by @seswarrajan in #506
- Modified fsset to json in wpfs DB by @seswarrajan in #507
- cilium: Parsing is_reply flag from kafka feeds by @wazir-ahmed in #508
- Modified fsset to use recordsepartor in wpfs DB by @seswarrajan in #509
- Disabling observability by @seswarrajan in #510
Full Changelog: v0.3...v0.5-nonk8s