Hardened container security across oss-tenant, saas-shared, saas-tenant, meshcentral and fleetmdm — non-root Dockerfiles, security contexts in the Helm charts, and a vulnerability scan with a prioritised list for the devs.
Built tenant alerting behind a feature flag, with notifications grouped by alert type instead of per tenant — seven types done, the rest are next.
