vArmor v0.10.4: NetworkProxy Audit Persistence, Micro-VM (Kata) Compatibility, and Production-Grade Operations
In vArmor v0.10.0, we introduced the NetworkProxy enforcer, bringing L4/L7 network access control to Kubernetes workloads through a sidecar proxy architecture. In v0.10.1, we completed the Phase 2 TLS Man-in-the-Middle (MITM) capability, upgrading it into a deep packet inspection engine that covers encrypted traffic.
vArmor v0.10.4 is a production-focused release. We concentrated on three things: making NetworkProxy's audit capability truly land — audit logs that are persistent and can be correlated to workload identity; keeping vArmor working reliably in non-standard runtimes such as micro-VMs (Kata / Serverless sandboxes); and lowering the operational cost of large-scale deployments through cluster-level sidecar resource quota management and iptables backend auto-adaptation. In addition, policy-advisor's conflict detection is now more precise.
