master
Add integration test for invalid SAN certificate handling
test/integration: add missing sig labels
Adapt the codebase to the Authorizer interface change
Implement conditions for the union authorizer
Add automatic_reload_last_config_info metric for auth configs
pkg/controlplane: split up config into generic controlplane and kube-related part
test: use cancelation from ktesting
Enforce sa token node audience restriction when ServiceAccountNodeAudienceRestriction=true
apiserver/pod: preserve DRA status fields when old clients clear them via pods/status
feature: promote ProcMountType to GA
Update tests to handle RemoteRequestHeaderUID
Add granular authorization for DRA ResourceClaim status updates
Fix SelfSubjectReview test to decouple beta and GA types from the same apiserver
KEP-6060: Implement webhook authentication token issuance and validation