kapparmor-0.2.1
Pre-release
Pre-release
Changelog
All notable changes to this project will be documented in this file.
The format is based on Keep a Changelog,
and this project adheres to Semantic Versioning.
[Unreleased]
- 🚀 go 1.25
- Integration tests
- ✅ Create a new profile
- ❌ Update an existing profile
- ✅ Remove an existing profile
- ✅ Check current confinement state of the app
- test_on_microk8s.sh - Main test script with:
✅ Use helm chart approach
✅ Fixed MicroK8s status check
✅ Added apparmor to required addons
✅ Rebuilds image with --no-cache if missing
✅ Adds build-time and gitCommit annotations
❌ Skips RBAC
✅ Implements two test cases
✅ Shows logs and events in readable format - Switched to structured logging
- Added different logging levels
- Increased test coverage
- Moved global vars to config struct
- Removed shared signal channel. Moved to timeout based shutdown through context passing.
- Removed panics to ensure cleanup and graceful shutdown
- Liveness and Readiness server
- Filesystem writing operations protected by a mutex
- Extensive integration testing bash automation
TODO:
- Generate signed OCI containers for all architectures
- Increase test coverage at least to 60%
- Implement open telemetry
- Refactor directories similarly to kubernetes-sigs structure (eg: go/kapaprmor/app/*.go) or to this golang standard project layout
- Refactor code following Google Go style guide
- Move global vars to structs passed by reference
0.2.0 -
CI:
- Fixed Codecov plugin issues
- Refresh container image every Sunday night
- Git auto CRLF set to false
git config --global core.autocrlf false - Bumped multiple actions
- Bash CI to automate go version bump from one source of truth (
config/config)
Code:
- golang:1.22 as builder containerfile image
- The k8s service resource is now settable from the values.yaml
- Introduced Fuzz testing for profile filenames
- If POLL_TIME is set less than 1 it will default to 1 second
Project Security Fixes
- Signed commits:
git config commit.gpgsign true - Added repository Security policy
- Added OpenSSF scorecard workflow
- Least Privileged GitHub Actions Token Permissions: setting minimum token permissions for the GITHUB_TOKEN
- Pinning actions to full length commit
- Intergated Harden-Runner in the CI: it prevents exfiltration of credentials, detects tampering of source code during build, and enables running jobs without sudo access.
- Pinned image tags to digests in Dockerfiles.
- Closed 44 (!) security issues coming from Scorecard security scanner. Also with the help of stepsecurity.io
0.1.5 - 2023-05-16
- Feature: manage custom labels
- Feature: validate profile file content
- Feature: Validate app and chart version
- Feature: catch SIGTERM signal
- Fix: profile content checking when they have same name
- update to go 1.20
- Docs update
0.1.2 - 2023-02-22
Fixed
- Support for profile names coming after comments and include lines
Added
- Tested on multiple nodes cluster
- Base images switched to go 1.20
0.1.1 - 2023-02-13
Fixed
- Moved shared testing functions to a dedicated module
- Minor documentation and readme fixes
Added
- Enforce profiles filenames to be the same as the profile names
- Changelog automatically read by chart-releaser
0.1.0 - 2023-02-01
Fixed
- "Unable to replace profiles. Permission denied, app seems still confined." - Switched to ubuntu image
- No need for SYS_ADMIN capabilities
- Ignore hidden and system folders while scanning for profiles
Added
- Instructions to test the app in a virtual machine directly running the go app or in microk8s pushing the built container to the local registry
0.0.6 - 2023-01-26
Added
Helm:
- Added SYS_ADMIN capabilities to the daemonset
- Mounted needed folders in the Dockerfile and in the daemonset
- Added POLL_TIME and profiles files as configurable options through configmaps
Go:
- Added first testing function
- Moved file operations functions to dedicated module
- Fixed POLL_TIME value passing from configmap
CI/CD:
- Explicit changelog to help users understanding the project features
- Automatic generation of release notes based on changelog file
- Configurable poll time and profiles directory in the helm values file
0.0.5 - 2023-01-23
Added
Helm:
- Helm Chart based mainly on a DaemonSet and a configmap. No operator needed.
- Load all AppArmor profiles in the configmap template
Go:
- Possibility to load continuously the security profiles from a configmap with a configurable poll time
CI/CD:
- Helm chart linting and testing before releasing
- Security vulnerability tests on Go dependencies and container file.
- Auto generation of GitHub pages
- Container image tag is set to current commit SHA for every release.
Fixed
- Being still an alpha release I will add everything in the "Added" section
What's Changed
- Origin/gh pages by @tuxerrante in #1
- Dev by @tuxerrante in #2
- Dev by @tuxerrante in #3
- test alpha release by @tuxerrante in #4
- release also from PR by @tuxerrante in #5
- Dev by @tuxerrante in #6
- Dev by @tuxerrante in #7
- chanmged chart-testing charts setting by @tuxerrante in #8
- configmap template auto filled by profiles by @tuxerrante in #9
- release only during a PR or when tagging by @tuxerrante in #10
- fix GITHUB_SHA writtend during CI by @tuxerrante in #11
- Feature/has the same content test by @tuxerrante in #12
- 0.1.0 First working release by @tuxerrante in #13
- Feature: continuous unit testing and test coverage by @tuxerrante in #14
- feature: Enforce profiles filenames to be the same as the profile names by @tuxerrante in #15
- Feature: support profiles not starting with their names as first line, hostPath creation by @tuxerrante in #16
- Start build-app also on tags by @tuxerrante in #17
- #18 - Manage custom labels, validate profile content, manage SIGTERM by @tuxerrante in #18
- Fix/codecov by @tuxerrante in #19
- Dev by @tuxerrante in #22
- Create SECURITY.md by @tuxerrante in #27
- Create scorecard.yml by @tuxerrante in #28
- Dev by @tuxerrante in #29
- minor fixes by @tuxerrante in #30
- Feature/logo by @tuxerrante in #31
- fixed wrong path by @tuxerrante in #32
- Update/codeql go version by @tuxerrante in #33
- pin golang image version by @tuxerrante in #34
- [StepSecurity] Apply security best practices by @step-security-bot in #35
- Fix/ci permissions by @tuxerrante in #36
- update index.yaml by @tuxerrante in #37
- fix 0.1.6 url in index.yaml by @tuxerrante in #38
- add 0.1.7 to helm index by @tuxerrante in #39
- Add release 0.1.7 to Helm/index by @tuxerrante in #40
- Feature/go 1.25 by @tuxerrante in #41
- Fix/githubci by @tuxerrante in #42
New Contributors
- @tuxerrante made their first contribution in #1
- @step-security-bot made their first contribution in #35
Full Changelog: https://github.com/tuxerrante/kapparmor/commits/kapparmor-0.2.1