This PR contains the following updates: | Package | Update | Change | |---|---|---| | [gitea/gitea](https://github.com/go-gitea/gitea) | major | `1.27.3` → `28.0.0` | --- ### Release Notes <details> <summary>go-gitea/gitea (gitea/gitea)</summary> ### [`v28.0.0`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#2800---2026-09-30) [Compare Source](https://github.com/go-gitea/gitea/compare/v1.27.3...v28.0.0) - BREAKING - Fix(git)!: route Git network operations through an internal proxy and update egress settings ([#​39426](https://github.com/go-gitea/gitea/pull/39426)) - Feat(actions)!: add RUN\_RETENTION\_DAYS to delete old action runs ([#​38855](https://github.com/go-gitea/gitea/pull/38855)) - SECURITY - Fix(git): reject invalid and duplicate Git objects on push ([#​39472](https://github.com/go-gitea/gitea/pull/39472)) - Fix(git)!: route Git network operations through an internal proxy and update egress settings ([#​39426](https://github.com/go-gitea/gitea/pull/39426)) - Fix(ssh): identify presented public keys by fingerprint ([#​39423](https://github.com/go-gitea/gitea/pull/39423)) - Fix(actions): keep cancelled and unapproved fork PR runs behind the approval gate ([#​39399](https://github.com/go-gitea/gitea/pull/39399)) - Fix(deps): update golang.org/x/crypto SSH to address denial of service ([#​39219](https://github.com/go-gitea/gitea/pull/39219)) - Fix(repo): enforce repository-scoped authorization for team access, deletion, and package unlinking ([#​39063](https://github.com/go-gitea/gitea/pull/39063)) - FEATURES - Feat(actions): update actionslib, support `self:`, misc fixes ([#​39358](https://github.com/go-gitea/gitea/pull/39358)) - Feat(api): list all packages for site administrators ([#​38968](https://github.com/go-gitea/gitea/pull/38968)) - Feat: manage bot accounts from the admin UI, API and CLI ([#​38966](https://github.com/go-gitea/gitea/pull/38966)) - Feat(user): Personal access tokens can be regenerated ([#​38907](https://github.com/go-gitea/gitea/pull/38907)) - Feat(actions): support `$/` prefix in reusable workflow `uses:` ([#​38822](https://github.com/go-gitea/gitea/pull/38822)) - Feat(actions): add force-cancel workflow run API ([#​38756](https://github.com/go-gitea/gitea/pull/38756)) - Feat(licenses): support REUSE specification in licenses ([#​38720](https://github.com/go-gitea/gitea/pull/38720)) - Feat(api): add project APIs ([#​38691](https://github.com/go-gitea/gitea/pull/38691)) - Feat(webhook): fire repository event on repo rename ([#​38641](https://github.com/go-gitea/gitea/pull/38641)) - Feat: admin impersonates a user ([#​38614](https://github.com/go-gitea/gitea/pull/38614)) - Feat(actions): add build queue view ([#​38585](https://github.com/go-gitea/gitea/pull/38585)) - Feat(setting): add shared \[redis] section as default for redis-backed subsystems ([#​38550](https://github.com/go-gitea/gitea/pull/38550)) - Feat(repo): prioritize well-known READMEs and optimize discovery ([#​38532](https://github.com/go-gitea/gitea/pull/38532)) - Feat(actions): implement adaptive auto-refresh for workflow runs list ([#​38329](https://github.com/go-gitea/gitea/pull/38329)) - Feat(auth): add `disable-2fa` command ([#​38275](https://github.com/go-gitea/gitea/pull/38275)) - Feat: Add audit logging ([#​38189](https://github.com/go-gitea/gitea/pull/38189)) - Feat(repo): add quick repository switcher to repo header ([#​38188](https://github.com/go-gitea/gitea/pull/38188)) - Feat(repo): support file exclusion logic in .gitea/template in template generation ([#​38064](https://github.com/go-gitea/gitea/pull/38064)) - Feat(web): Add org removal functionality to admin user details page ([#​38013](https://github.com/go-gitea/gitea/pull/38013)) - Feat: add watch options ([#​37571](https://github.com/go-gitea/gitea/pull/37571)) - Feat: add deploy tokens ([#​37306](https://github.com/go-gitea/gitea/pull/37306)) - Feat(diff): Add search and extension filter to diff sidebar ([#​37068](https://github.com/go-gitea/gitea/pull/37068)) - Feat: Replace SSE with WebSocket for UI notifications ([#​36965](https://github.com/go-gitea/gitea/pull/36965)) - Feat(actions): Add artifact preview in Actions run view ([#​36754](https://github.com/go-gitea/gitea/pull/36754)) - Feat(packages): add support for uploading helm provenance files ([#​36695](https://github.com/go-gitea/gitea/pull/36695)) - Feat: Add support for dynamic matrix evaluation in Gitea Actions workflows ([#​36564](https://github.com/go-gitea/gitea/pull/36564)) - Feat: Add max-parallel Support for Gitea Actions ([#​36357](https://github.com/go-gitea/gitea/pull/36357)) - Feat(actions): Add Actions API endpoints for workflow run management and logs ([#​35382](https://github.com/go-gitea/gitea/pull/35382)) - Feat: Add block on pending codeowner reviews branch protection ([#​34995](https://github.com/go-gitea/gitea/pull/34995)) - ENHANCEMENTS - Enhance: allow auto-closing PRs from PRs ([#​39393](https://github.com/go-gitea/gitea/pull/39393)) - Enhance(actions): add pending job status and align job statuses with GitHub ([#​39376](https://github.com/go-gitea/gitea/pull/39376)) - Enhance(acme): add configurable ACME profile ([#​39375](https://github.com/go-gitea/gitea/pull/39375)) - Enhance(emoji): update to Unicode 17, unify and lazy-load emoji data ([#​39363](https://github.com/go-gitea/gitea/pull/39363)) - Enhance: improve issue-pattern capture groups and support both internal\&external trackers enabled ([#​39354](https://github.com/go-gitea/gitea/pull/39354)) - Enhance: update mermaid to v12 ([#​39331](https://github.com/go-gitea/gitea/pull/39331)) - Enhance(notifications): mark current notification page as read ([#​39294](https://github.com/go-gitea/gitea/pull/39294)) - Enhance: support `ETag` on streamed repository archives, support `If-None-Match: *` ([#​39289](https://github.com/go-gitea/gitea/pull/39289)) - Enhance: truncate but show long lines in diffs ([#​39279](https://github.com/go-gitea/gitea/pull/39279)) - Enhance(packages): implement npm single-version API and add per-version repository ([#​39267](https://github.com/go-gitea/gitea/pull/39267)) - Enhance: move window\.config to JSON, improve CSP format ([#​39236](https://github.com/go-gitea/gitea/pull/39236)) - Enhance: improve commit page header ([#​39229](https://github.com/go-gitea/gitea/pull/39229)) - Enhance: Improve validation errors for secrets/variables ([#​39221](https://github.com/go-gitea/gitea/pull/39221)) - Enhance(repo): check full repo name for dangerous operations ([#​39213](https://github.com/go-gitea/gitea/pull/39213)) - Enhance(web): hide attachment dropzone on preview tab in combo editor ([#​39204](https://github.com/go-gitea/gitea/pull/39204)) - Enhance(web): show attachment URL and UUID in dropzone preview ([#​39203](https://github.com/go-gitea/gitea/pull/39203)) - Enhance(actions): make workflow dispatch choice dropdown support search ([#​39154](https://github.com/go-gitea/gitea/pull/39154)) - Enhance(repo): unify diff stats on commit pages, misc diff tweaks ([#​39134](https://github.com/go-gitea/gitea/pull/39134)) - Enhance: use browser's locale to detect week's first day for the contribution map ([#​38995](https://github.com/go-gitea/gitea/pull/38995)) - Enhance(ui): forced colors mode enhancements ([#​38991](https://github.com/go-gitea/gitea/pull/38991)) - Enhance: user-friendly packages setup manual ([#​38946](https://github.com/go-gitea/gitea/pull/38946)) - Enhance: inherit team access for all units ([#​38938](https://github.com/go-gitea/gitea/pull/38938)) - Enhance(admin): show impersonation banner and keep password change with the user ([#​38924](https://github.com/go-gitea/gitea/pull/38924)) - Enhance(ui): tint toast backgrounds by level ([#​38919](https://github.com/go-gitea/gitea/pull/38919)) - Enhance(repo): add default object format setting ([#​38877](https://github.com/go-gitea/gitea/pull/38877)) - Enhance(actions): set ref\_protected in context ([#​38852](https://github.com/go-gitea/gitea/pull/38852)) - Enhance(ui): restyle toasts ([#​38842](https://github.com/go-gitea/gitea/pull/38842)) - Enhance: refine repo watching ([#​38835](https://github.com/go-gitea/gitea/pull/38835)) - Enhance: fall back to DEFAULT\_TEMPLATE.md when style-specific template is missing ([#​38803](https://github.com/go-gitea/gitea/pull/38803)) - Enhance(api): add GitHub-compatible /repos/{owner}/{repo}/commits/{ref} endpoint ([#​38770](https://github.com/go-gitea/gitea/pull/38770)) - Enhance(api): expose file mode in contents API response ([#​38713](https://github.com/go-gitea/gitea/pull/38713)) - Enhance(tls): use go's tls defaults ([#​38687](https://github.com/go-gitea/gitea/pull/38687)) - Enhance(ui): improve luminance calculations ([#​38682](https://github.com/go-gitea/gitea/pull/38682)) - Enhance(api): add `tag_filter` query parameter to release list API ([#​38681](https://github.com/go-gitea/gitea/pull/38681)) - Enhance(actions): replace `ansi_up` with first-party code ([#​38619](https://github.com/go-gitea/gitea/pull/38619)) - Enhance: keep status check list scrolled on merge box reload ([#​38597](https://github.com/go-gitea/gitea/pull/38597)) - Enhance(actions): action view enhancements ([#​38594](https://github.com/go-gitea/gitea/pull/38594)) - Enhance(ui): tweak tooltip style and misc fixes ([#​38524](https://github.com/go-gitea/gitea/pull/38524)) - Enhance: improve e-mail templates ([#​38396](https://github.com/go-gitea/gitea/pull/38396)) - Enhance(webhook): add reviewer name to MS Teams review request notifications ([#​38289](https://github.com/go-gitea/gitea/pull/38289)) - Enhance: extend <video> tag allowed attributes ([#​38279](https://github.com/go-gitea/gitea/pull/38279)) - Enhance(packages/npm): expand version metadata and support npm deprecate ([#​37890](https://github.com/go-gitea/gitea/pull/37890)) - PERFORMANCE - Perf(references): scan only the keyword window before a reference ([#​39396](https://github.com/go-gitea/gitea/pull/39396)) - Perf(frontend): enable vite module preload ([#​39332](https://github.com/go-gitea/gitea/pull/39332)) - Perf(gitdiff): optimize inline diff highlighting using cache ([#​38706](https://github.com/go-gitea/gitea/pull/38706)) - BUGFIXES - Fix(actions): preserve admitted jobs and runs in their concurrency group ([#​39461](https://github.com/go-gitea/gitea/pull/39461)) - Fix(api): commit tree SHA is the commit ID ([#​39449](https://github.com/go-gitea/gitea/pull/39449)) - Fix: PR merge ([#​39442](https://github.com/go-gitea/gitea/pull/39442)) - Fix(actions): evaluate job-level `if:` before concurrency check ([#​39437](https://github.com/go-gitea/gitea/pull/39437)) - Fix(api): allow pending-inline-comment-only reviews ([#​39433](https://github.com/go-gitea/gitea/pull/39433)) - Fix: sanitize external render command line arguments ([#​39417](https://github.com/go-gitea/gitea/pull/39417)) - Fix(LFS): recalculate repo LFSSize after gc-lfs removes orphaned data ([#​39406](https://github.com/go-gitea/gitea/pull/39406)) - Fix(indexer): index full file paths and real offsets in bleve ([#​39405](https://github.com/go-gitea/gitea/pull/39405)) - Fix(git): keep leading dashes in git grep search patterns ([#​39404](https://github.com/go-gitea/gitea/pull/39404)) - Fix: use clearer message for ldap auth failure ([#​39392](https://github.com/go-gitea/gitea/pull/39392)) - Fix(repo): commit page fails to render unsigned commits with a different committer ([#​39381](https://github.com/go-gitea/gitea/pull/39381)) - Fix: focus confirm button and use red for delete confirmations ([#​39350](https://github.com/go-gitea/gitea/pull/39350)) - Fix(migrations): preserve SHA-256 pull request commit IDs ([#​39343](https://github.com/go-gitea/gitea/pull/39343)) - Fix(ui): misc ui fixes ([#​39336](https://github.com/go-gitea/gitea/pull/39336)) - Fix(actions): use gitea's clock for actions durations ([#​39323](https://github.com/go-gitea/gitea/pull/39323)) - Fix(actions): never show negative running durations ([#​39322](https://github.com/go-gitea/gitea/pull/39322)) - Fix: package registry keypair creation race ([#​39319](https://github.com/go-gitea/gitea/pull/39319)) - Fix: add default timeout and handle errors for HaveIBeenPwned API ([#​39316](https://github.com/go-gitea/gitea/pull/39316)) - Fix(user): unify email validation for registration and settings ([#​39304](https://github.com/go-gitea/gitea/pull/39304)) - Fix(ui): use button elements for branch and tag dropdown tabs ([#​39285](https://github.com/go-gitea/gitea/pull/39285)) - Fix(auth): fix ssh and gpg key verification on windows ([#​39283](https://github.com/go-gitea/gitea/pull/39283)) - Fix(feed): use meaningful lines as comment excerpt ([#​39276](https://github.com/go-gitea/gitea/pull/39276)) - Fix(projects): allow max columns to the limit ([#​39272](https://github.com/go-gitea/gitea/pull/39272)) - Fix: pass merge commit messages to git via stdin ([#​39269](https://github.com/go-gitea/gitea/pull/39269)) - Fix(repo): surface unrelated histories on Sync Fork ([#​39258](https://github.com/go-gitea/gitea/pull/39258)) - Fix: avoid nil panic and refactor some trivial problems ([#​39251](https://github.com/go-gitea/gitea/pull/39251)) - Fix: restore missing blob file when re-publishing a package ([#​39239](https://github.com/go-gitea/gitea/pull/39239)) - Fix(automerge): validate head commit before merge ([#​39235](https://github.com/go-gitea/gitea/pull/39235)) - Fix(httplib): prevent leaking localhost:3000 in public links ([#​39217](https://github.com/go-gitea/gitea/pull/39217)) - Fix(setting): honor bare -1 for timeout settings ([#​39181](https://github.com/go-gitea/gitea/pull/39181)) - Fix: correct repo/attatchment absolute url and release layout ([#​39178](https://github.com/go-gitea/gitea/pull/39178)) - Fix(web): populate the reason for "cannot commit to branch" in web editor commit form ([#​39155](https://github.com/go-gitea/gitea/pull/39155)) - Fix(process): reap entire process group on cmd.Cancel ([#​39143](https://github.com/go-gitea/gitea/pull/39143)) - Fix: recognize linguist language aliases ([#​39135](https://github.com/go-gitea/gitea/pull/39135)) - Fix(repo): preserve transfer recipient collaboration ([#​39042](https://github.com/go-gitea/gitea/pull/39042)) - Fix(db): make paginated database reads always require "order" option ([#​39017](https://github.com/go-gitea/gitea/pull/39017)) - Fix: make local queue PopItem can be notified ([#​39011](https://github.com/go-gitea/gitea/pull/39011)) - Fix: classify git failures on stderr, restrict migration failure detail ([#​39010](https://github.com/go-gitea/gitea/pull/39010)) - Fix: allow re-requesting uncounted review approvals ([#​38988](https://github.com/go-gitea/gitea/pull/38988)) - Fix(actions): allow larger scheduled workflows ([#​38985](https://github.com/go-gitea/gitea/pull/38985)) - Fix: resolve actions commit status permission per repository ([#​38977](https://github.com/go-gitea/gitea/pull/38977)) - Fix(deps): update module golang.org/x/image to v0.45.0 \[security] ([#​38930](https://github.com/go-gitea/gitea/pull/38930)) - Fix(deps): update module golang.org/x/mod to v0.40.0 \[security] ([#​38914](https://github.com/go-gitea/gitea/pull/38914)) - Fix: dedupe issue cross-reference timeline entries ([#​38881](https://github.com/go-gitea/gitea/pull/38881)) - Fix(server): set `ReadHeaderTimeout` on HTTP servers ([#​38878](https://github.com/go-gitea/gitea/pull/38878)) - Fix(repo): avoid a repo-sized temp file for every bundle download ([#​38863](https://github.com/go-gitea/gitea/pull/38863)) - Fix(lfs): ensure lock listing paginates with a total order ([#​38850](https://github.com/go-gitea/gitea/pull/38850)) - Fix(avatar): use sha256 and inline the federated avatar lookup ([#​38843](https://github.com/go-gitea/gitea/pull/38843)) - Fix(gitdiff): render exact-limit diffs and zero-limit comments ([#​38838](https://github.com/go-gitea/gitea/pull/38838)) - Fix(deps): update dependency mermaid to v11.16.1 \[security] ([#​38813](https://github.com/go-gitea/gitea/pull/38813)) - Fix: misc fixes in pub/gpg/tests ([#​38809](https://github.com/go-gitea/gitea/pull/38809)) - Fix: git diff blob excerpt ([#​38808](https://github.com/go-gitea/gitea/pull/38808)) - Fix(packages): show error for duplicate cleanup rules [#​37820](https://github.com/go-gitea/gitea/issues/37820) ([#​38786](https://github.com/go-gitea/gitea/pull/38786)) - Fix(actions): fix runner docs link ([#​38783](https://github.com/go-gitea/gitea/pull/38783)) - Fix: git cache ([#​38763](https://github.com/go-gitea/gitea/pull/38763)) - Fix(actions): evaluate each `${{ }}` part on its own ([#​38754](https://github.com/go-gitea/gitea/pull/38754)) - Fix: don't report failed network requests as JavaScript errors ([#​38732](https://github.com/go-gitea/gitea/pull/38732)) - Fix(gitdiff): prevent index out of range panic in GetLineTypeMarker ([#​38728](https://github.com/go-gitea/gitea/pull/38728)) - Fix(api): document X-Total-Count instead of non-existent X-Total header ([#​38717](https://github.com/go-gitea/gitea/pull/38717)) - Fix(actions): dynamic matrix expansion correctness fixes ([#​38690](https://github.com/go-gitea/gitea/pull/38690)) - Fix(auth): record last sign-in on reverse proxy login ([#​38672](https://github.com/go-gitea/gitea/pull/38672)) - Fix(api): accept fully-qualified refs in contents API ([#​38650](https://github.com/go-gitea/gitea/pull/38650)) - Fix(deps): update module github.com/getkin/kin-openapi to v0.144.0 \[security] ([#​38623](https://github.com/go-gitea/gitea/pull/38623)) - Fix(deps): update dependency js-yaml to v5.2.2 \[security] ([#​38622](https://github.com/go-gitea/gitea/pull/38622)) - Fix: abort superseded issue suggestion requests ([#​38620](https://github.com/go-gitea/gitea/pull/38620)) - Fix(issue): display error toast on batch action failures instead of reloading page ([#​38593](https://github.com/go-gitea/gitea/pull/38593)) - Fix(deps): update module google.golang.org/grpc to v1.82.1 \[security] ([#​38567](https://github.com/go-gitea/gitea/pull/38567)) - Fix(deps): update module github.com/google/go-github/v88 to v89 ([#​38433](https://github.com/go-gitea/gitea/pull/38433)) - Fix(deps): update go dependencies ([#​38429](https://github.com/go-gitea/gitea/pull/38429)) - Fix(deps): update go dependencies ([#​38346](https://github.com/go-gitea/gitea/pull/38346)) - Fix(deps): update npm dependencies ([#​38342](https://github.com/go-gitea/gitea/pull/38342)) - Fix(base): correct natural sort of numbers with leading zeros ([#​38163](https://github.com/go-gitea/gitea/pull/38163)) - Fix(ui): avoid layout shifts in `overflow-menu` and repo filter ([#​37818](https://github.com/go-gitea/gitea/pull/37818)) - Fix: make auth source group sync correctly handle team removal ([#​37161](https://github.com/go-gitea/gitea/pull/37161)) - Fix(release): separate publication time from the release date ([#​36761](https://github.com/go-gitea/gitea/pull/36761)) - TESTING - Test: stop tests from writing into `~/.ssh` ([#​39348](https://github.com/go-gitea/gitea/pull/39348)) - Test(e2e): log out to switch users in pr-review test ([#​39328](https://github.com/go-gitea/gitea/pull/39328)) - Test: release fixtures loader lock before database work ([#​39263](https://github.com/go-gitea/gitea/pull/39263)) - Test: speed up tests, fix transaction bug ([#​39030](https://github.com/go-gitea/gitea/pull/39030)) - Test: run frontend unit tests in browsers ([#​38860](https://github.com/go-gitea/gitea/pull/38860)) - Test(pubsub): stop racing the Redis SUBSCRIBE ack ([#​38661](https://github.com/go-gitea/gitea/pull/38661)) - Test(e2e): add pull request merge box test, update AGENTS.md ([#​38576](https://github.com/go-gitea/gitea/pull/38576)) - Test(e2e): deterministically wait for event stream in logout propagation test ([#​38535](https://github.com/go-gitea/gitea/pull/38535)) - BUILD - Refactor: fix `go vet` errors related to composite literals ([#​39341](https://github.com/go-gitea/gitea/pull/39341)) - Build(gogit): disable gogit builds for stable releases ([#​39324](https://github.com/go-gitea/gitea/pull/39324)) - Refactor: replace jquery.are-you-sure with first-party code ([#​39233](https://github.com/go-gitea/gitea/pull/39233)) - Refactor: http request binding ([#​38971](https://github.com/go-gitea/gitea/pull/38971)) - Refactor: clean up git repo and model migration packages ([#​38564](https://github.com/go-gitea/gitea/pull/38564)) - Refactor: prepare to decouple the "model migration" package and "models" package ([#​38533](https://github.com/go-gitea/gitea/pull/38533)) - Build: fix snapcraft release ([#​38260](https://github.com/go-gitea/gitea/pull/38260)) - Build(release): use native golang toolchain for official release builds ([#​37828](https://github.com/go-gitea/gitea/pull/37828)) - DOCS - Docs(webhook): review\.type comment lists values the webhook never sends ([#​39451](https://github.com/go-gitea/gitea/pull/39451)) - Docs(api): document verification and files on the compare endpoint ([#​39440](https://github.com/go-gitea/gitea/pull/39440)) - Docs(api): name the unadopted-repository search parameter query ([#​39370](https://github.com/go-gitea/gitea/pull/39370)) - Docs: remove unused COOKIE\_USERNAME from app.example.ini ([#​39365](https://github.com/go-gitea/gitea/pull/39365)) - Docs: document NOTICE\_ON\_SUCCESS for every cron task ([#​39352](https://github.com/go-gitea/gitea/pull/39352)) - Docs: correct ALLOW\_LOCALNETWORKS description in app.example.ini ([#​39240](https://github.com/go-gitea/gitea/pull/39240)) - Docs: fix typo in README about app.ini restart ([#​39223](https://github.com/go-gitea/gitea/pull/39223)) - Docs: fix dead localization doc link in the READMEs ([#​39211](https://github.com/go-gitea/gitea/pull/39211)) - Docs: Update CHANGELOG for release 1.27.3 ([#​39170](https://github.com/go-gitea/gitea/pull/39170)) - Docs: Update CHANGELOG for version 1.27.2 ([#​38923](https://github.com/go-gitea/gitea/pull/38923)) - Docs: Update PGP key expiration date to July 23, 2027 ([#​38747](https://github.com/go-gitea/gitea/pull/38747)) - Docs(api): document 401/403 responses for user key endpoints ([#​38711](https://github.com/go-gitea/gitea/pull/38711)) - Docs: Update Changelog for release v1.27.1 ([#​38670](https://github.com/go-gitea/gitea/pull/38670)) - Docs: Update Changelog for 1.27 ([#​38440](https://github.com/go-gitea/gitea/pull/38440)) - Docs: Update Security docs ([#​38422](https://github.com/go-gitea/gitea/pull/38422)) - MISC - Refactor: make git http respond error message ([#​39390](https://github.com/go-gitea/gitea/pull/39390)) - Refactor(api): convert bot accounts through the admin user edit endpoint ([#​39355](https://github.com/go-gitea/gitea/pull/39355)) - Refactor: replace AWS SDK with a REST client for CodeCommit migration ([#​39330](https://github.com/go-gitea/gitea/pull/39330)) - Refactor: replace Azure Blob SDK with a REST client ([#​39315](https://github.com/go-gitea/gitea/pull/39315)) - Refactor: npm route handlers ([#​39275](https://github.com/go-gitea/gitea/pull/39275)) - Refactor: GetDiffShortStat and fix panic caused by inconsistent "changed file number" ([#​39248](https://github.com/go-gitea/gitea/pull/39248)) - Refactor(templates): update djlint to 1.46.0 and resolve its new findings ([#​39231](https://github.com/go-gitea/gitea/pull/39231)) - Refactor: pagination/pager ([#​39162](https://github.com/go-gitea/gitea/pull/39162)) - Refactor: share package registry error status classification ([#​39133](https://github.com/go-gitea/gitea/pull/39133)) - Refactor: drop two unmaintained dependencies, rename the byte size helpers ([#​39083](https://github.com/go-gitea/gitea/pull/39083)) - Refactor(automerge): fix error handling, populate recent automerge tasks on restart ([#​39001](https://github.com/go-gitea/gitea/pull/39001)) - Refactor: deploy key and private route handlers ([#​38999](https://github.com/go-gitea/gitea/pull/38999)) - Refactor: wiki edit form ([#​38918](https://github.com/go-gitea/gitea/pull/38918)) - Refactor: clean up form binding & validation ([#​38873](https://github.com/go-gitea/gitea/pull/38873)) - Refactor: markup render ([#​38864](https://github.com/go-gitea/gitea/pull/38864)) - Refactor: api token scope check ([#​38862](https://github.com/go-gitea/gitea/pull/38862)) - Refactor: replace `gliderlabs/ssh` with `golang.org/x/crypto/ssh` ([#​38837](https://github.com/go-gitea/gitea/pull/38837)) - Refactor: form binding validation ([#​38832](https://github.com/go-gitea/gitea/pull/38832)) - Refactor: prepare vue components for vapor mode ([#​38798](https://github.com/go-gitea/gitea/pull/38798)) - Refactor: use the shared workflow model from actionslib ([#​38768](https://github.com/go-gitea/gitea/pull/38768)) - Refactor(modelmigration): thread context through migration functions ([#​38758](https://github.com/go-gitea/gitea/pull/38758)) - Refactor: migrate remaining Vue components to `<script setup>` ([#​38752](https://github.com/go-gitea/gitea/pull/38752)) - Refactor: introduce trString for frontend ([#​38741](https://github.com/go-gitea/gitea/pull/38741)) - Refactor(diff): drive diff DOM init from the global selector observer ([#​38740](https://github.com/go-gitea/gitea/pull/38740)) - Refactor(git): clarify GetBranch behavior to make it only gets an existing branch ([#​38662](https://github.com/go-gitea/gitea/pull/38662)) - Refactor: replace debounce/throttle deps with first-party code ([#​38610](https://github.com/go-gitea/gitea/pull/38610)) - Refactor: hide git repo path details from more packages ([#​38601](https://github.com/go-gitea/gitea/pull/38601)) - Refactor: retry file remove/rename when a file is busy and clean up os detection ([#​38588](https://github.com/go-gitea/gitea/pull/38588)) - Perf(emoji): optimize FindEmojiSubmatchIndex using slice-based Trie ([#​38573](https://github.com/go-gitea/gitea/pull/38573)) - Refactor: implement mcaptcha client and add comments/tests ([#​38561](https://github.com/go-gitea/gitea/pull/38561)) - Refactor: use WithRepo instead of WithDir for most git operations, clean up model migrations ([#​38555](https://github.com/go-gitea/gitea/pull/38555)) - Refactor: remove Path field from git.Repository ([#​38552](https://github.com/go-gitea/gitea/pull/38552)) - Refactor: make git package handle all git operations ([#​38543](https://github.com/go-gitea/gitea/pull/38543)) - Refactor: remove unnecessary git command wrapper functions ([#​38531](https://github.com/go-gitea/gitea/pull/38531)) - Refactor: git repo and relative path handling ([#​38522](https://github.com/go-gitea/gitea/pull/38522)) - Refactor: clean up fragile diff render templates, use backend typed structs ([#​38517](https://github.com/go-gitea/gitea/pull/38517)) - Refactor: correct git repo design and fix some legacy problems ([#​38512](https://github.com/go-gitea/gitea/pull/38512)) - Refactor: fix legacy problems in cmd/serv.go ([#​38505](https://github.com/go-gitea/gitea/pull/38505)) - Refactor: remove Ctx field from git.Repository ([#​38500](https://github.com/go-gitea/gitea/pull/38500)) - Refactor: decouple git.Repository(ctx) from git.Commit & git.Tree ([#​38464](https://github.com/go-gitea/gitea/pull/38464)) - Refactor: introduce ActivePageTimer to help to do partial page refresh ([#​38372](https://github.com/go-gitea/gitea/pull/38372)) </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Oslo) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==--> --------- Co-authored-by: Renovate Bot <renovate@forteapps.net> Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/58 Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com> Co-authored-by: gitea_admin <admin@forteapps.net>
Kubernetes Cluster - GitOps Configuration
Kubernetes cluster bootstrapping and GitOps configuration repository using ArgoCD for multi-cloud Kubernetes (UpCloud, AWS EKS, Azure AKS, GCP GKE)
📚 Complete Documentation
New developers and operators: Please refer to our comprehensive documentation for detailed guides and references:
🎯 START HERE: Documentation Index
| Document | Description | Audience |
|---|---|---|
| GitOps Architecture | System architecture, repository structure, GitOps workflows, security model | Everyone (start here) |
| Developer Guide | Local setup, deploying apps, managing secrets, troubleshooting | Developers |
| Operations Runbook | Cluster bootstrap, day-to-day operations, incident response, maintenance | Platform Engineers, SREs |
| Technical Reference | Component specs, Helm charts, ArgoCD config, Kyverno policies, API docs | Everyone (reference) |
🚀 Quick Start
For New Developers
# 1. Clone repositories
git clone https://git.forteapps.net/Forte/launchpad.git
git clone ssh://git@git.forteapps.net:2222/Forte/helm-prod-values.git
# 2. Read the guides
# - Start: docs/GITOPS-ARCHITECTURE.md
# - Follow: docs/DEVELOPER-GUIDE.md
# 3. Deploy your first app (see Developer Guide)
For Operators
# 1. Bootstrap new cluster
./bootstrap.sh
# 2. Verify deployment
kubectl get applications -n argocd
kubectl get pods --all-namespaces
# 3. Read Operations Runbook for day-to-day tasks
📋 Overview
This repository contains the complete GitOps configuration for our Kubernetes cluster, using the App-of-Apps pattern with ArgoCD.
What's Inside
- Infrastructure Applications: Traefik, Cert-Manager, Kyverno, Prometheus, Grafana, Loki, Tempo, Sealed Secrets, Homepage (platform dashboard)
- Business Applications: MCP10X, MusicMan, Dot-AI Stack, ArgoCD MCP
- Policies: Kyverno security policies for secret management, namespace controls, pod verification
- Monitoring: Full observability stack with metrics, logs, traces, and alerting
- Secrets: Sealed Secrets for secure Git storage
Key Features
✅ GitOps-Native: Git is the single source of truth ✅ Auto-Sync: Changes automatically deployed (60s reconciliation) ✅ Self-Healing: Manual cluster changes are reverted ✅ Multi-Source: Separate chart templates from configuration ✅ Policy Enforcement: Kyverno ensures security and compliance ✅ Authentication: Automatic sidecar injection (token & OIDC support) ✅ TLS Everywhere: Automatic Let's Encrypt certificates ✅ Full Observability: Prometheus, Grafana, Loki, Tempo integration
🗂️ Repository Structure
.
├── bootstrap.sh # Cluster initialization (ArgoCD + GitOps)
├── _app-of-apps-{cluster}.yaml # Root ArgoCD Application (per cluster)
│
├── .tofu/ # Infrastructure provisioning (OpenTofu)
│ ├── platforms/ # Per-platform IaC (one dir per cloud)
│ │ ├── aks/ # Azure AKS (modules/ + dev/ + prod/ + workload/)
│ │ ├── eks/ # AWS EKS
│ │ ├── gke/ # GCP GKE
│ │ └── upc/ # UpCloud
│ ├── configs/ # Platform credentials (git-ignored)
│ │ └── *.env.example # Template for each platform
│ └── scripts/ # Cluster lifecycle scripts
│ ├── setup-cluster.sh # Create cluster: ./setup-cluster.sh aks-dev
│ ├── teardown-cluster.sh
│ └── get-kubeconfig.sh
│
├── clusters/ # Cluster metadata (domain, trustedIPs, etc.)
│
├── infra/ # Infrastructure ArgoCD Applications (Kustomize multi-cluster)
│ ├── base/ # Base ArgoCD Application manifests (one dir per component)
│ │ ├── kustomization.yaml # Aggregates all component subdirectories
│ │ ├── traefik-application/
│ │ │ ├── kustomization.yaml
│ │ │ └── traefik-application.yaml
│ │ ├── keycloak/
│ │ │ ├── kustomization.yaml
│ │ │ └── keycloak.yaml
│ │ ├── grafana/
│ │ ├── prometheus/
│ │ ├── ... # Each component in its own subdirectory
│ │ └── secrets/
│ ├── overlays/ # Per-cluster overrides (Kustomize)
│ │ ├── upc-dev/ # UpCloud Dev — includes all base components
│ │ ├── upc-prod/ # UpCloud Prod — all components + patches
│ │ ├── aks-dev/ # Azure AKS Dev — selective components only
│ │ ├── aks-prod/ # Azure AKS Prod
│ │ ├── eks-dev/ # AWS EKS Dev
│ │ ├── eks-prod/ # AWS EKS Prod
│ │ ├── gke-dev/ # GCP GKE Dev
│ │ └── gke-prod/ # GCP GKE Prod
│ ├── dashboards/ # Grafana dashboard ConfigMaps
│ └── values/ # Helm value overrides
│ ├── base/ # Shared cloud-agnostic values
│ ├── upc-dev/ # UpCloud Dev (storage, LB, pricing)
│ ├── upc-prod/ # UpCloud Prod
│ ├── eks-dev/ # AWS EKS Dev
│ ├── eks-prod/ # AWS EKS Prod
│ ├── aks-dev/ # Azure AKS Dev
│ ├── aks-prod/ # Azure AKS Prod
│ ├── gke-dev/ # GCP GKE Dev
│ └── gke-prod/ # GCP GKE Prod
│
├── apps/ # Business Applications (Kustomize, same pattern as infra)
│ ├── base/ # One subdirectory per app
│ │ ├── kustomization.yaml
│ │ ├── musicman/
│ │ ├── mcp10x/
│ │ ├── dot-ai-stack/
│ │ ├── ts-mcp/
│ │ └── argo-mcp/
│ └── overlays/ # Per-cluster: cherry-pick or include all
│ ├── upc-dev/ # All apps
│ ├── upc-prod/ # All apps + patches
│ └── aks-dev/ # Selective apps only
│
├── cluster-resources/ # Cluster-wide Kubernetes resources
│ ├── letsencrypt-issuer.yaml
│ ├── kyverno-config.yaml
│ ├── *-sealed.yaml # Sealed secrets
│ └── policies/ # Kyverno policies
│ ├── secret-cloner.yaml
│ ├── default-ns-blocker.yaml
│ ├── bare-pod-cleaner.yaml
│ └── auth-sidecar-injector.yaml
│
├── secrets/ # Application secrets (sealed)
│ └── *-credentials-sealed.yaml
│
├── private/ # Local-only files (Git-ignored)
│ └── *.yaml # Unsealed secrets (never committed)
│
└── docs/ # 📚 Comprehensive documentation
├── README.md # Documentation index
├── GITOPS-ARCHITECTURE.md # Architecture guide
├── DEVELOPER-GUIDE.md # Developer onboarding
├── OPERATIONS-RUNBOOK.md # Operations procedures
└── REFERENCE.md # Technical reference
See GitOps Architecture - Repository Structure for detailed explanation.
🏗️ Architecture
Three-Repository Pattern
| Repository | Purpose | Who Edits | How Often |
|---|---|---|---|
| launchpad (this repo) | ArgoCD Applications, cluster resources | Platform / DevOps engineers | ✅ Often |
| forte-helm | Generic Helm chart templates | Platform engineers | ❌ Rarely |
| helm-prod-values | App-specific configuration & versions | Developers / CI pipelines | ✅ Sometimes |
GitOps Workflow
Developer commits code → CI/CD builds image → Updates helm-prod-values → ArgoCD syncs → Deployed to cluster
Learn more: GitOps Architecture - GitOps Workflow
🔧 Common Tasks
Deploy a New Application
See detailed guide: Developer Guide - Deploying Your First Application
Quick version:
- Create
apps/myapp.yaml(ArgoCD Application manifest) - Create
helm-prod-values/myapp/values.yaml(configuration) - Create sealed secrets if needed
- Commit and push - ArgoCD auto-syncs!
Update an Existing Application
See detailed guide: Developer Guide - Updating an Existing Application
Quick version:
- Update code: Push to app repo → CI/CD updates image tag in helm-prod-values
- Update config: Edit
helm-prod-values/myapp/values.yaml→ commit → push
Manage Secrets
See detailed guide: Developer Guide - Working with Secrets
# Create plain secret
kubectl create secret generic myapp-creds \
--from-literal=KEY=value \
--dry-run=client -o yaml > private/myapp-creds.yaml
# Seal it
kubeseal --format=yaml --cert=pub-cert.pem \
< private/myapp-creds.yaml > secrets/myapp-creds-sealed.yaml
# Commit sealed version
git add secrets/myapp-creds-sealed.yaml
git commit -m "Add myapp credentials"
git push
Enable Authentication
See detailed guide: Developer Guide - Enabling Authentication
Quick version:
# In helm-prod-values/myapp/values.yaml
# Token-based auth (simple)
auth:
enabled: true
type: token
tokens:
- your-secret-token-here
# OIDC auth (SSO)
auth:
enabled: true
type: oidc
oidc:
authority: https://auth.example.com/realms/master
clientId: myapp
Then create OIDC secret (if using OIDC):
kubectl create secret generic auth-oidc \
--from-literal=client-secret=your-oidc-secret \
--from-literal=cookie-secret=$(openssl rand -hex 32) \
--namespace=myapp | \
kubeseal --format=yaml --cert=pub-cert.pem --namespace=myapp | \
kubectl apply -f -
Bootstrap Cluster
See detailed guide: Operations Runbook - Cluster Bootstrap
# Initialize new cluster
./bootstrap.sh
# Verify
kubectl get applications -n argocd
kubectl get pods --all-namespaces
🛠️ Quick Reference
Monitor Applications
# List all ArgoCD applications
kubectl get applications -n argocd
# Watch sync status
kubectl get applications -n argocd -w
# Check specific application
kubectl describe application myapp -n argocd
# View application logs
kubectl logs -n myapp <pod-name>
Access UIs
# ArgoCD UI
kubectl port-forward svc/argocd-server -n argocd 8080:443
# Access: https://localhost:8080 (no auth required)
# Grafana
kubectl port-forward -n monitoring svc/grafana 3000:80
# Access: http://localhost:3000
# Prometheus
kubectl port-forward -n monitoring svc/prometheus-server 9090:80
# Access: http://localhost:9090
Troubleshooting
# Check pod status
kubectl get pods -n myapp
# View pod logs
kubectl logs -n myapp <pod-name>
# Check pod events
kubectl describe pod -n myapp <pod-name>
# Check ArgoCD sync errors
kubectl describe application myapp -n argocd
# Force sync
kubectl patch application myapp -n argocd \
--type merge -p '{"metadata":{"annotations":{"argocd.argoproj.io/refresh":"hard"}}}'
Full troubleshooting guide: Developer Guide - Troubleshooting
🔐 Security
Secret Management
- ✅ Sealed Secrets for Git storage
- ✅ Kyverno auto-clones secrets to namespaces
- ❌ Never commit plain secrets
Network Security
- ✅ All traffic TLS-encrypted (Let's Encrypt)
- ✅ HTTP → HTTPS redirect
- ✅ Traefik IngressRoute per application
Policy Enforcement
- ✅ Kyverno policies for security
- ✅ Default namespace blocked
- ✅ Bare pods not allowed
- ✅ Optional authentication sidecar injection
Learn more: GitOps Architecture - Security Model
📊 Infrastructure Components
| Component | Purpose | Namespace | Replicas |
|---|---|---|---|
| ArgoCD | GitOps controller | argocd |
1 |
| Traefik | Ingress controller | traefik |
2 |
| Cert-Manager | TLS certificates | cert-manager |
1 |
| Kyverno | Policy engine | kyverno |
1 |
| Sealed Secrets | Secret encryption | kube-system |
1 |
| Prometheus | Metrics | monitoring |
1 |
| Grafana | Dashboards | monitoring |
1 |
| Loki | Logs | monitoring |
1 |
| Tempo | Distributed tracing | monitoring |
1 |
| Fluent-Bit | Log shipping | monitoring |
DaemonSet |
| OpenCost | Cost monitoring | monitoring |
1 |
| Renovate | Dependency updates | renovate |
CronJob |
Full specs: Technical Reference - Infrastructure Components
🌐 Domains & Networking
- Local development:
*.127.0.0.1.nip.io - Production:
*.forteapps.net - DNS: Manual configuration (contact platform team)
- TLS: Automatic via Let's Encrypt
📖 Key Concepts
App-of-Apps Pattern
_app-of-apps-{cluster}.yaml is the root Application that manages all other Applications in infra/. Each component in infra/base/ lives in its own subdirectory (e.g., infra/base/grafana/). Overlays can either include all components (via ../../base) or cherry-pick specific ones (via ../../base/grafana, ../../base/prometheus, etc.). Per-cluster patches swap Helm value file paths. Supported clusters: upc-dev, upc-prod, eks-dev, eks-prod, aks-dev, aks-prod, gke-dev, gke-prod.
Multi-Source Pattern
Applications reference both:
- Helm charts from
forte-helm(templates) - Values from
helm-prod-values(configuration)
This separates reusable templates from environment-specific config.
Sync Waves
Applications deploy in order using argocd.argoproj.io/sync-wave:
- Wave
-1: Namespaces - Wave
0: Kyverno (policies) - Wave
1: Infrastructure - Wave
2+: Applications
Auto-Sync & Self-Heal
- Auto-Sync: ArgoCD automatically deploys Git changes (60s polling)
- Self-Heal: Manual cluster changes are reverted to match Git
- Prune: Deleted resources in Git are removed from cluster
Learn more: GitOps Architecture - GitOps Workflow
⚙️ Configuration
ArgoCD Settings
- Reconciliation: Every 60 seconds
- Sync timeout: 5 minutes per application
- Retry policy: 5 attempts with exponential backoff
- Authentication: Disabled (internal use only)
Application Defaults
- Auto-sync: Enabled
- Self-heal: Enabled
- Prune: Enabled
- Validation: Server-side validation enabled
- Server-side apply: Enabled
Full configuration: Technical Reference - ArgoCD Configuration
🆘 Getting Help
Documentation
- Start here: Documentation Index
- For development: Developer Guide
- For operations: Operations Runbook
- For reference: Technical Reference
Support
- Slack: #platform-support
- Issues: Contact platform team
- Emergencies: Escalate via Slack
Common Questions
| Question | Answer |
|---|---|
| How do I deploy an app? | Developer Guide - Deploying Your First Application |
| How do I manage secrets? | Developer Guide - Working with Secrets |
| App won't sync? | Developer Guide - Troubleshooting |
| How do I bootstrap a cluster? | Operations Runbook - Cluster Bootstrap |
| Where are the logs? | Operations Runbook - Monitoring & Alerting |
🤝 Contributing
Adding a New Application
- Read Developer Guide - Deploying Your First Application
- Create ArgoCD Application manifest in
apps/ - Create Helm values in
helm-prod-values/ - Create sealed secrets if needed
- Commit and push - ArgoCD handles the rest!
Modifying Infrastructure
- Read Operations Runbook
- Update relevant files in
infra/orcluster-resources/ - Test changes in isolated namespace if possible
- Commit and push
- Monitor sync status in Slack/ArgoCD UI
Updating Documentation
Documentation lives in docs/. To update:
- Edit relevant markdown file
- Update "Last Updated" date
- Submit PR or push directly
- Notify team of significant changes
📝 Notes
Current Environment
- Provider: Multi-cloud (UpCloud, AWS EKS, Azure AKS, GCP GKE)
- Active clusters: UpCloud (upc-dev, upc-prod)
- Environment: Production (internal use only)
- Auth: Disabled for ArgoCD (internal access)
- Backup: Gitea daily backup to S3-compatible storage
Known Limitations
- Secret rotation not automated
- DNS management is manual
Future improvements: See Operations Runbook - Disaster Recovery
📚 Additional Resources
External Documentation
- ArgoCD Documentation
- Kyverno Documentation
- Traefik Documentation
- Cert-Manager Documentation
- Grafana Tempo Documentation
- Sealed Secrets
Related Repositories
- forte-helm - Helm chart templates
- helm-prod-values - Application values
📄 License
Internal use only. Not for public distribution.
👥 Maintainers
Platform Team
- Contact: #platform-support on Slack
- Issues: Create issue in repository or contact team directly
Last Updated: 2026-04-22 Documentation Version: 1.0.0
🚀 Ready to get started? Check out the Documentation Index!