Skip to content

chore(chart-deps): update kyverno to version 3.7.2#3181

Merged
merll merged 11 commits into
mainfrom
ci-update-kyverno-to-3.7.2
Apr 30, 2026
Merged

chore(chart-deps): update kyverno to version 3.7.2#3181
merll merged 11 commits into
mainfrom
ci-update-kyverno-to-3.7.2

Conversation

@svcAPLBot
Copy link
Copy Markdown
Contributor

This PR updates the dependency kyverno to version 3.7.2.

@svcAPLBot svcAPLBot added the chart-deps Auto generated helm chart dependencies label Apr 24, 2026
@merll merll marked this pull request as ready for review April 24, 2026 06:37
@svcAPLBot
Copy link
Copy Markdown
Contributor Author

Comparison of Helm chart templating output:

# kyverno/templates/admission-controller/clusterrole.yaml

# kyverno/templates/admission-controller/clusterrolebinding.yaml

# kyverno/templates/admission-controller/deployment.yaml

@@ spec.template.spec.initContainers.kyverno-pre.image @@
! ± value change
- reg.kyverno.io/kyverno/kyvernopre:v1.17.1
+ reg.kyverno.io/kyverno/kyvernopre:v1.17.2

@@ spec.template.spec.containers.kyverno.image @@
! ± value change
- reg.kyverno.io/kyverno/kyverno:v1.17.1
+ reg.kyverno.io/kyverno/kyverno:v1.17.2

@@ spec.template.spec.containers.kyverno.volumeMounts @@
! + one list entry added:
+ - name: apicall-token
+   mountPath: /var/run/secrets/kyverno/apicall
+   readOnly: true

@@ spec.template.spec.volumes @@
! + one list entry added:
+ - name: apicall-token
+   projected:
+     defaultMode: 0444
+     sources:
+     - serviceAccountToken:
+         path: token
+         expirationSeconds: 3600
+         audience: kyverno-svc.kyverno.io

# kyverno/templates/admission-controller/role.yaml

# kyverno/templates/admission-controller/rolebinding.yaml

# kyverno/templates/admission-controller/service.yaml

# kyverno/templates/admission-controller/serviceaccount.yaml

# kyverno/templates/admission-controller/servicemonitor.yaml

# kyverno/templates/background-controller/clusterrole.yaml

# kyverno/templates/background-controller/clusterrolebinding.yaml

# kyverno/templates/background-controller/deployment.yaml

@@ spec.template.spec @@
! + one map entry added:
+ volumes:
+ - name: apicall-token
+   projected:
+     defaultMode: 0444
+     sources:
+     - serviceAccountToken:
+         path: token
+         expirationSeconds: 3600
+         audience: kyverno-svc.kyverno.io

@@ spec.template.spec.containers.controller @@
! + one map entry added:
+ volumeMounts:
+ - name: apicall-token
+   mountPath: /var/run/secrets/kyverno/apicall
+   readOnly: true

@@ spec.template.spec.containers.controller.image @@
! ± value change
- reg.kyverno.io/kyverno/background-controller:v1.17.1
+ reg.kyverno.io/kyverno/background-controller:v1.17.2

# kyverno/templates/background-controller/role.yaml

# kyverno/templates/background-controller/rolebinding.yaml

# kyverno/templates/background-controller/service.yaml

# kyverno/templates/background-controller/serviceaccount.yaml

# kyverno/templates/background-controller/servicemonitor.yaml

# kyverno/templates/cleanup-controller/clusterrole.yaml

# kyverno/templates/cleanup-controller/clusterrolebinding.yaml

# kyverno/templates/cleanup-controller/deployment.yaml

@@ spec.template.spec @@
! + one map entry added:
+ volumes:
+ - name: apicall-token
+   projected:
+     defaultMode: 0444
+     sources:
+     - serviceAccountToken:
+         path: token
+         expirationSeconds: 3600
+         audience: kyverno-svc.kyverno.io

@@ spec.template.spec.containers.controller @@
! + one map entry added:
+ volumeMounts:
+ - name: apicall-token
+   mountPath: /var/run/secrets/kyverno/apicall
+   readOnly: true

@@ spec.template.spec.containers.controller.image @@
! ± value change
- reg.kyverno.io/kyverno/cleanup-controller:v1.17.1
+ reg.kyverno.io/kyverno/cleanup-controller:v1.17.2

# kyverno/templates/cleanup-controller/role.yaml

# kyverno/templates/cleanup-controller/rolebinding.yaml

# kyverno/templates/cleanup-controller/service.yaml

# kyverno/templates/cleanup-controller/serviceaccount.yaml

# kyverno/templates/config/configmap.yaml

# kyverno/templates/config/metricsconfigmap.yaml

# kyverno/templates/hooks/post-upgrade-migrate-resources.yaml

@@ spec.template.spec.containers.kubectl.image @@
# batch/v1/Job/kyverno/kyverno-migrate-resources
! ± value change
- reg.kyverno.io/kyverno/kyverno-cli:v1.17.1
+ reg.kyverno.io/kyverno/kyverno-cli:v1.17.2

# kyverno/templates/hooks/pre-delete-remove-mutatingwebhookconfiguration.yaml

# kyverno/templates/hooks/pre-delete-remove-validatingwebhookconfiguration.yaml

# kyverno/templates/hooks/pre-delete-scale-to-zero.yaml

# kyverno/templates/rbac/policies.yaml

# kyverno/templates/rbac/policyreports.yaml

# kyverno/templates/rbac/reports.yaml

# kyverno/templates/rbac/updaterequests.yaml

# kyverno/templates/reports-controller/clusterrole.yaml

# kyverno/templates/reports-controller/clusterrolebinding.yaml

# kyverno/templates/reports-controller/deployment.yaml

@@ spec.template.spec.containers.controller.image @@
! ± value change
- reg.kyverno.io/kyverno/reports-controller:v1.17.1
+ reg.kyverno.io/kyverno/reports-controller:v1.17.2

@@ spec.template.spec.containers.controller.volumeMounts @@
! + one list entry added:
+ - name: apicall-token
+   mountPath: /var/run/secrets/kyverno/apicall
+   readOnly: true

@@ spec.template.spec.volumes @@
! + one list entry added:
+ - name: apicall-token
+   projected:
+     defaultMode: 0444
+     sources:
+     - serviceAccountToken:
+         path: token
+         expirationSeconds: 3600
+         audience: kyverno-svc.kyverno.io

# kyverno/templates/reports-controller/role.yaml

# kyverno/templates/reports-controller/rolebinding.yaml

# kyverno/templates/reports-controller/service.yaml

# kyverno/templates/reports-controller/serviceaccount.yaml

# kyverno/templates/tests/admission-controller-metrics.yaml

# kyverno/templates/tests/cleanup-controller-liveness.yaml

# kyverno/templates/tests/cleanup-controller-metrics.yaml

# kyverno/templates/tests/cleanup-controller-readiness.yaml

# kyverno/templates/tests/reports-controller-metrics.yaml

# otomi-api/templates/core-config.yaml

@@ data.core.yaml @@
! ± value change in multiline text (one insert, one deletion)
  adminApps:
  - deps:
    - prometheus
    ingress:
  
  [460 lines unchanged)]
  
    kyverno:
      about: Kyverno is a policy engine designed for Kubernetes. It can validate, mutate,
        and generate configurations using admission controls and background scans. Kyverno
        policies are Kubernetes resources and do not require learning a new language.
-     appVersion: 1.17.1
+     appVersion: 1.17.2
      license: Apache 2.0
      maintainers: Nirmata
      relatedLinks:
      - https://kyverno.io/docs/kyverno-policies/
  
  [260 lines unchanged)]
  
      svc: tekton-dashboard
      type: public
    name: tekton
    ownHost: true

# otomi-api/templates/deployment.yaml

# rabbitmq-cluster-operator/templates/messaging-topology-operator/validating-webhook-configuration.yaml

# values-repo.yaml

@merll merll merged commit 144ed8e into main Apr 30, 2026
14 checks passed
@merll merll deleted the ci-update-kyverno-to-3.7.2 branch April 30, 2026 07:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

chart-deps Auto generated helm chart dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants