Commit Graph
564 Commits
Author SHA1 Message Date
Renovate Bot ca86ff3445 chore(deps): update dependency github-cli to v0.12.0
renovate/stability-days Updates have met minimum release age requirement
/ test (pull_request) Successful in 1m44s
2026-09-26 00:09:48 +00:00
7abee90f4e chore(deps): update dependency claude-code to v0.2.122 (#27)
/ test (push) Successful in 29s
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [claude-code](https://github.com/anthropics/claude-code) | patch | `latest` → `0.2.122` |

---

### Release Notes

<details>
<summary>anthropics/claude-code (claude-code)</summary>

### [`v0.2.107`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#02107)

- CLAUDE.md files can now import other files. Add @&#8203;path/to/file.md to ./CLAUDE.md to load additional files on launch

### [`v0.2.74`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#0274)

- Added support for refreshing dynamically generated API keys (via apiKeyHelper), with a 5 minute TTL
- Task tool can now perform writes and run bash commands

### [`v0.2.69`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#0269)

- Fixed UI glitches with improved Select component behavior
- Enhanced terminal output display with better text truncation logic

### [`v0.2.67`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#0267)

- Shared project permission rules can be saved in .claude/settings.json

### [`v0.2.59`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#0259)

- Copy+paste images directly into your prompt
- Improved progress indicators for bash and fetch tools
- Bugfixes for non-interactive mode (-p)

### [`v0.2.54`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#0254)

- Quickly add to Memory by starting your message with '#'
- Press ctrl+r to see full output for long tool results
- Added support for MCP SSE transport

### [`v0.2.53`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#0253)

- New web fetch tool lets Claude view URLs that you paste in
- Fixed a bug with JPEG detection

### [`v0.2.41`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#0241)

- MCP server startup timeout can now be configured via MCP\_TIMEOUT environment variable
- MCP server startup no longer blocks the app from starting up

### [`v0.2.32`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#0232)

- Interactive MCP setup wizard: Run "claude mcp add" to add MCP servers with a step-by-step interface
- Fix for some PersistentShell issues

### [`v0.2.30`](https://github.com/anthropics/claude-code/blob/HEAD/CHANGELOG.md#0230)

- Added ANSI color theme for better terminal compatibility
- Fixed issue where slash command arguments weren't being sent properly
- (Mac-only) API keys are now stored in macOS Keychain

</details>

---

### Configuration

📅 **Schedule**: (in timezone Europe/Oslo)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

---------

Co-authored-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: Renovate Bot <renovate@forteapps.net>
Reviewed-on: #27
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: gitea_admin <admin@forteapps.net>
Co-committed-by: gitea_admin <admin@forteapps.net>
2026-09-25 05:47:12 +00:00
bb37c6051f chore(deps): update dependency _1password to v1.12.2 (#30)
/ test (push) Failing after 14m48s
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [_1password](https://developer.1password.com/docs/cli/) | minor | `latest` → `1.12.2` |

---

### Configuration

📅 **Schedule**: (in timezone Europe/Oslo)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

---------

Co-authored-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: Renovate Bot <renovate@forteapps.net>
Reviewed-on: #30
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: gitea_admin <admin@forteapps.net>
Co-committed-by: gitea_admin <admin@forteapps.net>
2026-09-25 05:46:32 +00:00
91c7a90d1b chore(deps): update alpine docker tag to v3.24 (#29)
/ test (push) Failing after 10m45s
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [alpine](https://hub.docker.com/_/alpine) ([source](https://github.com/alpinelinux/docker-alpine)) | minor | `3.20` → `3.24` |

---

### Configuration

📅 **Schedule**: (in timezone Europe/Oslo)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

---------

Co-authored-by: Renovate Bot <renovate@forteapps.net>
Reviewed-on: #29
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: gitea_admin <admin@forteapps.net>
Co-committed-by: gitea_admin <admin@forteapps.net>
2026-09-25 05:40:40 +00:00
d42b5a89f3 chore(deps): update dependency dotnet-sdk to v2.1.810 (#28)
/ test (push) Failing after 11m30s
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [dotnet-sdk](https://dotnet.github.io/) | patch | `latest` → `2.1.810` |

---

### Configuration

📅 **Schedule**: (in timezone Europe/Oslo)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

---------

Co-authored-by: Renovate Bot <renovate@forteapps.net>
Reviewed-on: #28
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: gitea_admin <admin@forteapps.net>
Co-committed-by: gitea_admin <admin@forteapps.net>
2026-09-25 05:39:52 +00:00
danijel.simeunovic c1f4298bfe renovate
/ test (push) Successful in 23s
2026-09-25 00:02:00 +02:00
danijel.simeunovic 14cabaf3f5 version bumps
/ test (push) Successful in 36s
2026-09-24 23:56:20 +02:00
danijel.simeunovic 809e90d12d upgrade loki
/ test (push) Successful in 31s
2026-09-23 20:46:25 +00:00
danijel.simeunovic eeb7321819 loki values
/ test (push) Failing after 11m2s
2026-09-23 20:20:19 +00:00
danijel.simeunovic 133bdb8715 benken secret
/ test (push) Successful in 46s
2026-09-23 20:30:09 +02:00
danijel.simeunovic c47e89e02a Update infra/values/base/loki-values.yaml
/ test (push) Successful in 11s
2026-09-16 17:17:12 +00:00
danijel.simeunovic 3bf6f22a4a keycloak client cleanup: harden candidate selection
/ test (push) Successful in 8s
2026-09-04 12:05:23 +00:00
danijel.simeunovic 10f27fa3c4 harden client cleanup scheduling
/ test (push) Successful in 13s
timeZone: "Europe/Oslo"
    startingDeadlineSeconds: 3600
2026-09-04 11:38:33 +00:00
gitea_admin 90ba7ac905 Keycloak: Run client cleanup once a month
/ test (push) Successful in 13s
2026-09-03 09:52:49 +00:00
gitea_admin b616e59231 Increase min age for keycloak client cleanup
/ test (push) Successful in 13s
increase to 15 days min age
2026-09-03 07:26:30 +00:00
danijel.simeunovic 705c010806 Mute deployment notifications
/ test (push) Successful in 9s
2026-08-25 12:34:33 +00:00
29624e845d fix(forte-drop-pg-backup): set MC_CONFIG_DIR so backups can upload (#23)
/ test (push) Successful in 10s
The nightly Postgres backup CronJob has been **failing every run** — no backups exist in `s3://drops/_pgbackups/`.

**Cause:** the upload container runs as uid 65532 (`runAsNonRoot`). `mc` defaults its config to `$HOME/.mc` = `/.mc` and dies with `mkdir /.mc: permission denied` on the non-writable root fs — before any upload.

**Fix:** set `MC_CONFIG_DIR=/work/.mc` (the shared emptyDir, writable via `fsGroup: 65532`). The `pg_dump` initContainer already succeeds; this lets the upload step actually run.

Validated: `kubectl kustomize` renders clean; env present on the upload container.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: Sten <sten@Sten-sin-MacBook-Pro.local>
Reviewed-on: #23
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: Jørgen Stensrud <jorgen.stensrud@fortedigital.com>
Co-committed-by: Jørgen Stensrud <jorgen.stensrud@fortedigital.com>
2026-08-25 09:44:02 +00:00
danijel.simeunovic 4712eb4804 wayfinder instructions
/ test (push) Successful in 8s
2026-08-01 12:10:50 +02:00
danijel.simeunovic 2696044a02 docs
/ test (push) Successful in 8s
2026-08-01 12:07:26 +02:00
danijel.simeunovic b0c0074f7f Merge branch 'main' of https://git.forteapps.net/Forte/launchpad
/ test (push) Successful in 8s
2026-07-02 15:27:25 +02:00
danijel.simeunovic 7f4a0bccf1 notify mail 2026-07-02 15:27:16 +02:00
jorgen.stensrud 52c752caba feat(auth-sidecar): inject AUTH_OIDC_ALLOWED_RETURN_HOSTS (#25)
/ test (push) Successful in 9s
2026-07-02 13:17:57 +00:00
danijel.simeunovic af1e94d85d review
/ test (push) Successful in 9s
2026-07-02 12:25:11 +02:00
jorgen.stensrudanddanijel.simeunovic df35cd0630 feat(auth-sidecar): inject AUTH_OIDC_COOKIE_DOMAIN (#24)
/ test (push) Successful in 10s
Adds AUTH_OIDC_COOKIE_DOMAIN to the injected OIDC sidecar, from the `policies.forteapps.io/auth-oidc-cookie-domain` annotation. Empty when unset = host-only = unchanged for every app. Pairs with forte-helm + auth-sidecar#23. Safe to merge anytime (opt-in).

---------

Co-authored-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Reviewed-on: #24
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
2026-06-30 06:59:37 +00:00
danijel.simeunovic 04b3a210fe shared-prompts
/ test (push) Successful in 8s
2026-06-29 17:02:50 +02:00
danijel.simeunovic 330c25f241 model
/ test (push) Successful in 8s
2026-06-29 16:47:51 +02:00
jorgen.stensrud 3a23451802 feat(forte-drop): issuer dnsZones for *.drop.forteapps.net (subdomain-per-drop) (#22)
/ test (push) Successful in 12s
2026-06-26 11:38:30 +00:00
danijel.simeunovic 9297398d56 gitea update
/ test (push) Successful in 8s
2026-06-11 13:03:59 +02:00
danijel.simeunovic b0804e1e6a scan
/ test (push) Successful in 11s
2026-06-11 10:34:11 +02:00
danijel.simeunovic 8216399155 trufflehog
/ test (push) Failing after 33s
2026-06-11 10:14:25 +02:00
danijel.simeunovic a70f078bbb drop drop 2026-06-05 19:38:30 +02:00
danijel.simeunovic a24e61d538 disable slack notifications for forte-drop
Signed-off-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
2026-06-05 13:41:42 +00:00
jorgen.stensrudandSten 275ec675da fix(apps): drop dangling namespace.yaml ref (enterprise-apps ComparisonError) (#19)
0a98674 deleted `namespace.yaml` but `apps/overlays/upc-dev/forte-drop/kustomization.yaml` still lists it → `kustomize build` fails → the **enterprise-apps** app-of-apps has a ComparisonError and the whole overlay stopped syncing. Visible symptom: `secret "forte-drop-secrets" not found` on all forte-drop pods (the SealedSecret no longer applies).

One-line fix: remove the dangling resource entry. The namespace itself is fine — the forte-drop Application has `CreateNamespace=true`.

@danijel.simeunovic — pairs with your cleanup; after this merges the secret re-applies and the pods only need the right image tag (helm-prod-values PR #4: `buildcache` → `v20260604-200105-1316f7a`, buildcache is the buildx cache manifest, not a runnable image).

Co-authored-by: Sten <sten@Sten-sin-MacBook-Pro.local>
Reviewed-on: #19
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
2026-06-05 08:44:56 +00:00
danijel.simeunovic 0a98674a27 not needed 2026-06-05 00:05:56 +02:00
b713ec853c feat(apps): forte-drop web + mcp argocd apps (prod) (#18)
## Summary

ArgoCD Applications + Keycloak clients + sealed secret for forte-drop **web + mcp** (PROD).

## What changed

- **forte-drop** + **forte-drop-mcp** ArgoCD Applications (two-source: forte-helm chart + helm-prod-values).
- **namespace.yaml** — explicit `forte-drop` Namespace at sync-wave -1, `Prune=false` (avoids first-sync race for namespaced resources; doesn't cascade-delete on base removal).
- **keycloak-client-forte-drop** + **keycloak-client-forte-drop-mcp** — labeled config Secrets; the registrar creates the OIDC clients in the `forte` realm within ~2 min.
- **forte-drop-secrets** SealedSecret — UpCloud S3 creds (existing drops bucket) + PG creds + PASSWORD_GATE_SECRET. Consumed by both deployments + the pg-backup CronJob.
- **forte-drop-web PDB** — minAvailable 1 (selector verified against the live forteapp chart's pod labels).
- Wired into `apps/overlays/upc-dev` (NOT base → stays out of upc-prod).

## Post-merge manual step (one-time)

`auth-oidc` SealedSecret for the web sidecar is still commented out — it needs the `client-secret` the Keycloak registrar writes to `forte-drop-oidc-credentials` after first sync:

```bash
CLIENT_SECRET=$(kubectl -n forte-drop get secret forte-drop-oidc-credentials -o jsonpath='{.data.client-secret}' | base64 -d)
kubectl create secret generic auth-oidc -n forte-drop \
  --from-literal=client-secret="$CLIENT_SECRET" \
  --from-literal=cookie-secret="$(openssl rand -hex 32)" \
  --dry-run=client -o yaml > private/auth-oidc.yaml
kubeseal --format=yaml --controller-name=sealed-secrets-controller --controller-namespace=kube-system \
  < private/auth-oidc.yaml > apps/base/forte-drop/auth-oidc-sealed.yaml
# uncomment in kustomization, commit, push
```

## Depends on

- launchpad PR #17 (postgres + namespace via CreateNamespace).
- helm-prod-values forte-drop PR (values).

## Review

- [x] codex: namespace first-sync race → fixed (explicit namespace, sync-wave -1).
- [x] Keycloak registrar unblocked (stale chibisafe/minio config secrets removed; registrar green).

🤖 Generated with Claude Code

Co-authored-by: Sten <sten@Sten-sin-MacBook-Pro.local>
Co-authored-by: Sten <sten@Mac.domain_not_set.invalid>
Co-authored-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Reviewed-on: #18
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
2026-06-04 18:47:08 +00:00
danijel.simeunovic dffb9c43f0 dbunk delete 2026-06-03 20:16:37 +02:00
danijel.simeunovic 33f0463c1f upc dev spec 2026-06-03 20:14:21 +02:00
danijel.simeunovic a997a6b81e kc cleanup 2026-06-03 17:41:10 +02:00
danijel.simeunovic 071f57f1d3 kc cleanup 2026-06-03 17:39:02 +02:00
danijel.simeunovic ecf871f0e4 kc fix 2026-06-03 17:36:29 +02:00
danijel.simeunovic 376d81a5ac keycloak client cleanup 2026-06-03 17:28:08 +02:00
danijel.simeunovic 428de7af78 tofu config and docs 2026-05-31 20:48:25 +02:00
danijel.simeunovic 24c59256c9 tofu+tools 2026-05-31 19:53:26 +02:00
danijel.simeunovic e319295f62 bunker host 2026-05-29 22:06:08 +02:00
danijel.simeunovic a7106bc8f4 new tls wildcard 2026-05-29 21:58:34 +02:00
danijel.simeunovic 6d874111da tenantID 2026-05-29 21:51:27 +02:00
danijel.simeunovic a8cc103e4c dns01 2026-05-29 21:48:32 +02:00
Ghostdanijel.simeunovicGhost <>
a9dbaf5354 feature/tofu (#15)
@thomas.solbjor her er "import" av tofu fra ditt repo med justeringer for å tilpasse patterns her. Også minimalisert til å kun opprette cluster, ingen managed services som postgres etc. Ta en titt.

Co-authored-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Reviewed-on: #15
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: Ghost <>
Co-committed-by: Ghost <>
2026-05-29 15:48:28 +00:00
danijel.simeunovic 6e175e9e8c docs 2026-05-29 15:20:51 +02:00
jorgen.stensrudandSten 396c771f59 feat(homepage): list forte_drop in Apps (#16)
Adds forte_drop as an external service entry in the upc-dev Homepage portal.

- Target host: https://drop.hackathon.forteapps.net (current Coolify deploy).
- One-line addition under `services > Apps` in `infra/values/upc-dev/homepage-values.yaml`.
- Will be retargeted to https://drop.forteapps.net once the K8s migration ships (spec in forte_drop repo: docs/superpowers/specs/2026-05-28-k8s-migration-design.md).

Zero risk — pure metadata, no cluster mutation beyond Homepage refresh.

Co-authored-by: Sten <sten@Mac.domain_not_set.invalid>
Reviewed-on: #16
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
2026-05-28 14:04:05 +00:00