Keith Mattix II
Keith Mattix II
@nshankar13 New contour version was just released!
Approving pending green CI
@jaellio Does the current cert-rotation work enable this? My guess is no
Doesn't the reconciler also re-create the mutatingwebhookconfiguration if it's deleted?
The current implementation of conversion webhooks is essentially equivalent to a `None` conversion strategy. We've got the webhooks in source control, so it doesn't seem like it would be too...
Fixed in #5065
Sure, it's probably worth exploring the extent to which we may want to utilize SPIFFE/SPIRE. @trstringer your thoughts?
Good idea! I added it to the description
Here's some background information I've gathered after some research: [OPA Gatekeeper](https://github.com/open-policy-agent/gatekeeper) is a policy enforcement engine _specifically for Kubernetes resources_. It's deployed as a validating webhook and executes potential resources...
@steeling's distinction is correct; Gatekeeper's value-add is strictly admission control for business policies custom to an organization. The difference between policies enforced with gatekeeper vs our own validating webhook is...