calico
calico copied to clipboard
Tweak TLS config wherever used and make it FIPS compliant.
- Apiserver will always use the recommended ciphers, to make it fips compliant, the operator will add the tls-max-version flag.
- Replace tls.Config creation with our own convenient function that sets recommended settings.
- Go mod uses our fork of k8s.io/apiserver, which is identical to v0.24.0, with an added flag. We will submit a PR upstream to get this into Kubernetes.
/sem-approve
/sem-approve
/sem-approve
/sem-approve
Removing "merge-when-ready" label due to new commits
/sem-approve
Removing "merge-when-ready" label due to new commits
/sem-approve
Removing "merge-when-ready" label due to new commits
/sem-approve