Compare commits

...
Author SHA1 Message Date
Renovate Botanddanijel.simeunovic c8691b4caa chore(deps): update helm release traefik to v41
scan.yaml / test (pull_request) Successful in 4s
AI Code Review / ai-review (pull_request) Successful in 12s
2026-10-04 21:54:00 +00:00
7915346868 chore(deps): update gitea/gitea docker tag to v28 (#58)
scan.yaml / test (push) Successful in 8s
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [gitea/gitea](https://github.com/go-gitea/gitea) | major | `1.27.3` → `28.0.0` |

---

### Release Notes

<details>
<summary>go-gitea/gitea (gitea/gitea)</summary>

### [`v28.0.0`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#2800---2026-09-30)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.27.3...v28.0.0)

- BREAKING
  - Fix(git)!: route Git network operations through an internal proxy and update egress settings ([#&#8203;39426](https://github.com/go-gitea/gitea/pull/39426))
  - Feat(actions)!: add RUN\_RETENTION\_DAYS to delete old action runs ([#&#8203;38855](https://github.com/go-gitea/gitea/pull/38855))

- SECURITY
  - Fix(git): reject invalid and duplicate Git objects on push ([#&#8203;39472](https://github.com/go-gitea/gitea/pull/39472))
  - Fix(git)!: route Git network operations through an internal proxy and update egress settings ([#&#8203;39426](https://github.com/go-gitea/gitea/pull/39426))
  - Fix(ssh): identify presented public keys by fingerprint ([#&#8203;39423](https://github.com/go-gitea/gitea/pull/39423))
  - Fix(actions): keep cancelled and unapproved fork PR runs behind the approval gate ([#&#8203;39399](https://github.com/go-gitea/gitea/pull/39399))
  - Fix(deps): update golang.org/x/crypto SSH to address denial of service ([#&#8203;39219](https://github.com/go-gitea/gitea/pull/39219))
  - Fix(repo): enforce repository-scoped authorization for team access, deletion, and package unlinking ([#&#8203;39063](https://github.com/go-gitea/gitea/pull/39063))

- FEATURES
  - Feat(actions): update actionslib, support `self:`, misc fixes ([#&#8203;39358](https://github.com/go-gitea/gitea/pull/39358))
  - Feat(api): list all packages for site administrators ([#&#8203;38968](https://github.com/go-gitea/gitea/pull/38968))
  - Feat: manage bot accounts from the admin UI, API and CLI ([#&#8203;38966](https://github.com/go-gitea/gitea/pull/38966))
  - Feat(user): Personal access tokens can be regenerated ([#&#8203;38907](https://github.com/go-gitea/gitea/pull/38907))
  - Feat(actions): support `$/` prefix in reusable workflow `uses:` ([#&#8203;38822](https://github.com/go-gitea/gitea/pull/38822))
  - Feat(actions): add force-cancel workflow run API ([#&#8203;38756](https://github.com/go-gitea/gitea/pull/38756))
  - Feat(licenses): support REUSE specification in licenses ([#&#8203;38720](https://github.com/go-gitea/gitea/pull/38720))
  - Feat(api): add project APIs ([#&#8203;38691](https://github.com/go-gitea/gitea/pull/38691))
  - Feat(webhook): fire repository event on repo rename ([#&#8203;38641](https://github.com/go-gitea/gitea/pull/38641))
  - Feat: admin impersonates a user ([#&#8203;38614](https://github.com/go-gitea/gitea/pull/38614))
  - Feat(actions): add build queue view ([#&#8203;38585](https://github.com/go-gitea/gitea/pull/38585))
  - Feat(setting): add shared \[redis] section as default for redis-backed subsystems ([#&#8203;38550](https://github.com/go-gitea/gitea/pull/38550))
  - Feat(repo): prioritize well-known READMEs and optimize discovery ([#&#8203;38532](https://github.com/go-gitea/gitea/pull/38532))
  - Feat(actions): implement adaptive auto-refresh for workflow runs list ([#&#8203;38329](https://github.com/go-gitea/gitea/pull/38329))
  - Feat(auth): add `disable-2fa` command ([#&#8203;38275](https://github.com/go-gitea/gitea/pull/38275))
  - Feat: Add audit logging ([#&#8203;38189](https://github.com/go-gitea/gitea/pull/38189))
  - Feat(repo): add quick repository switcher to repo header ([#&#8203;38188](https://github.com/go-gitea/gitea/pull/38188))
  - Feat(repo): support file exclusion logic in .gitea/template in template generation ([#&#8203;38064](https://github.com/go-gitea/gitea/pull/38064))
  - Feat(web): Add org removal functionality to admin user details page ([#&#8203;38013](https://github.com/go-gitea/gitea/pull/38013))
  - Feat: add watch options ([#&#8203;37571](https://github.com/go-gitea/gitea/pull/37571))
  - Feat: add deploy tokens ([#&#8203;37306](https://github.com/go-gitea/gitea/pull/37306))
  - Feat(diff): Add search and extension filter to diff sidebar ([#&#8203;37068](https://github.com/go-gitea/gitea/pull/37068))
  - Feat: Replace SSE with WebSocket for UI notifications ([#&#8203;36965](https://github.com/go-gitea/gitea/pull/36965))
  - Feat(actions): Add artifact preview in Actions run view ([#&#8203;36754](https://github.com/go-gitea/gitea/pull/36754))
  - Feat(packages): add support for uploading helm provenance files ([#&#8203;36695](https://github.com/go-gitea/gitea/pull/36695))
  - Feat: Add support for dynamic matrix evaluation in Gitea Actions workflows ([#&#8203;36564](https://github.com/go-gitea/gitea/pull/36564))
  - Feat: Add max-parallel Support for Gitea Actions ([#&#8203;36357](https://github.com/go-gitea/gitea/pull/36357))
  - Feat(actions): Add Actions API endpoints for workflow run management and logs ([#&#8203;35382](https://github.com/go-gitea/gitea/pull/35382))
  - Feat: Add block on pending codeowner reviews branch protection ([#&#8203;34995](https://github.com/go-gitea/gitea/pull/34995))

- ENHANCEMENTS
  - Enhance: allow auto-closing PRs from PRs ([#&#8203;39393](https://github.com/go-gitea/gitea/pull/39393))
  - Enhance(actions): add pending job status and align job statuses with GitHub ([#&#8203;39376](https://github.com/go-gitea/gitea/pull/39376))
  - Enhance(acme): add configurable ACME profile ([#&#8203;39375](https://github.com/go-gitea/gitea/pull/39375))
  - Enhance(emoji): update to Unicode 17, unify and lazy-load emoji data ([#&#8203;39363](https://github.com/go-gitea/gitea/pull/39363))
  - Enhance: improve issue-pattern capture groups and support both internal\&external trackers enabled ([#&#8203;39354](https://github.com/go-gitea/gitea/pull/39354))
  - Enhance: update mermaid to v12 ([#&#8203;39331](https://github.com/go-gitea/gitea/pull/39331))
  - Enhance(notifications): mark current notification page as read ([#&#8203;39294](https://github.com/go-gitea/gitea/pull/39294))
  - Enhance: support `ETag` on streamed repository archives, support `If-None-Match: *` ([#&#8203;39289](https://github.com/go-gitea/gitea/pull/39289))
  - Enhance: truncate but show long lines in diffs ([#&#8203;39279](https://github.com/go-gitea/gitea/pull/39279))
  - Enhance(packages): implement npm single-version API and add per-version repository ([#&#8203;39267](https://github.com/go-gitea/gitea/pull/39267))
  - Enhance: move window\.config to JSON, improve CSP format ([#&#8203;39236](https://github.com/go-gitea/gitea/pull/39236))
  - Enhance: improve commit page header ([#&#8203;39229](https://github.com/go-gitea/gitea/pull/39229))
  - Enhance: Improve validation errors for secrets/variables ([#&#8203;39221](https://github.com/go-gitea/gitea/pull/39221))
  - Enhance(repo): check full repo name for dangerous operations ([#&#8203;39213](https://github.com/go-gitea/gitea/pull/39213))
  - Enhance(web): hide attachment dropzone on preview tab in combo editor ([#&#8203;39204](https://github.com/go-gitea/gitea/pull/39204))
  - Enhance(web): show attachment URL and UUID in dropzone preview ([#&#8203;39203](https://github.com/go-gitea/gitea/pull/39203))
  - Enhance(actions): make workflow dispatch choice dropdown support search ([#&#8203;39154](https://github.com/go-gitea/gitea/pull/39154))
  - Enhance(repo): unify diff stats on commit pages, misc diff tweaks ([#&#8203;39134](https://github.com/go-gitea/gitea/pull/39134))
  - Enhance: use browser's locale to detect week's first day for the contribution map ([#&#8203;38995](https://github.com/go-gitea/gitea/pull/38995))
  - Enhance(ui): forced colors mode enhancements ([#&#8203;38991](https://github.com/go-gitea/gitea/pull/38991))
  - Enhance: user-friendly packages setup manual ([#&#8203;38946](https://github.com/go-gitea/gitea/pull/38946))
  - Enhance: inherit team access for all units ([#&#8203;38938](https://github.com/go-gitea/gitea/pull/38938))
  - Enhance(admin): show impersonation banner and keep password change with the user ([#&#8203;38924](https://github.com/go-gitea/gitea/pull/38924))
  - Enhance(ui): tint toast backgrounds by level ([#&#8203;38919](https://github.com/go-gitea/gitea/pull/38919))
  - Enhance(repo): add default object format setting ([#&#8203;38877](https://github.com/go-gitea/gitea/pull/38877))
  - Enhance(actions): set ref\_protected in context ([#&#8203;38852](https://github.com/go-gitea/gitea/pull/38852))
  - Enhance(ui): restyle toasts ([#&#8203;38842](https://github.com/go-gitea/gitea/pull/38842))
  - Enhance: refine repo watching ([#&#8203;38835](https://github.com/go-gitea/gitea/pull/38835))
  - Enhance: fall back to DEFAULT\_TEMPLATE.md when style-specific template is missing ([#&#8203;38803](https://github.com/go-gitea/gitea/pull/38803))
  - Enhance(api): add GitHub-compatible /repos/{owner}/{repo}/commits/{ref} endpoint ([#&#8203;38770](https://github.com/go-gitea/gitea/pull/38770))
  - Enhance(api): expose file mode in contents API response ([#&#8203;38713](https://github.com/go-gitea/gitea/pull/38713))
  - Enhance(tls): use go's tls defaults ([#&#8203;38687](https://github.com/go-gitea/gitea/pull/38687))
  - Enhance(ui): improve luminance calculations ([#&#8203;38682](https://github.com/go-gitea/gitea/pull/38682))
  - Enhance(api): add `tag_filter` query parameter to release list API ([#&#8203;38681](https://github.com/go-gitea/gitea/pull/38681))
  - Enhance(actions): replace `ansi_up` with first-party code ([#&#8203;38619](https://github.com/go-gitea/gitea/pull/38619))
  - Enhance: keep status check list scrolled on merge box reload ([#&#8203;38597](https://github.com/go-gitea/gitea/pull/38597))
  - Enhance(actions): action view enhancements ([#&#8203;38594](https://github.com/go-gitea/gitea/pull/38594))
  - Enhance(ui): tweak tooltip style and misc fixes ([#&#8203;38524](https://github.com/go-gitea/gitea/pull/38524))
  - Enhance: improve e-mail templates ([#&#8203;38396](https://github.com/go-gitea/gitea/pull/38396))
  - Enhance(webhook): add reviewer name to MS Teams review request notifications ([#&#8203;38289](https://github.com/go-gitea/gitea/pull/38289))
  - Enhance: extend <video> tag allowed attributes ([#&#8203;38279](https://github.com/go-gitea/gitea/pull/38279))
  - Enhance(packages/npm): expand version metadata and support npm deprecate ([#&#8203;37890](https://github.com/go-gitea/gitea/pull/37890))

- PERFORMANCE
  - Perf(references): scan only the keyword window before a reference ([#&#8203;39396](https://github.com/go-gitea/gitea/pull/39396))
  - Perf(frontend): enable vite module preload ([#&#8203;39332](https://github.com/go-gitea/gitea/pull/39332))
  - Perf(gitdiff): optimize inline diff highlighting using cache ([#&#8203;38706](https://github.com/go-gitea/gitea/pull/38706))

- BUGFIXES
  - Fix(actions): preserve admitted jobs and runs in their concurrency group ([#&#8203;39461](https://github.com/go-gitea/gitea/pull/39461))
  - Fix(api): commit tree SHA is the commit ID ([#&#8203;39449](https://github.com/go-gitea/gitea/pull/39449))
  - Fix: PR merge ([#&#8203;39442](https://github.com/go-gitea/gitea/pull/39442))
  - Fix(actions): evaluate job-level `if:` before concurrency check ([#&#8203;39437](https://github.com/go-gitea/gitea/pull/39437))
  - Fix(api): allow pending-inline-comment-only reviews ([#&#8203;39433](https://github.com/go-gitea/gitea/pull/39433))
  - Fix: sanitize external render command line arguments ([#&#8203;39417](https://github.com/go-gitea/gitea/pull/39417))
  - Fix(LFS): recalculate repo LFSSize after gc-lfs removes orphaned data ([#&#8203;39406](https://github.com/go-gitea/gitea/pull/39406))
  - Fix(indexer): index full file paths and real offsets in bleve ([#&#8203;39405](https://github.com/go-gitea/gitea/pull/39405))
  - Fix(git): keep leading dashes in git grep search patterns ([#&#8203;39404](https://github.com/go-gitea/gitea/pull/39404))
  - Fix: use clearer message for ldap auth failure ([#&#8203;39392](https://github.com/go-gitea/gitea/pull/39392))
  - Fix(repo): commit page fails to render unsigned commits with a different committer ([#&#8203;39381](https://github.com/go-gitea/gitea/pull/39381))
  - Fix: focus confirm button and use red for delete confirmations ([#&#8203;39350](https://github.com/go-gitea/gitea/pull/39350))
  - Fix(migrations): preserve SHA-256 pull request commit IDs ([#&#8203;39343](https://github.com/go-gitea/gitea/pull/39343))
  - Fix(ui): misc ui fixes ([#&#8203;39336](https://github.com/go-gitea/gitea/pull/39336))
  - Fix(actions): use gitea's clock for actions durations ([#&#8203;39323](https://github.com/go-gitea/gitea/pull/39323))
  - Fix(actions): never show negative running durations ([#&#8203;39322](https://github.com/go-gitea/gitea/pull/39322))
  - Fix: package registry keypair creation race ([#&#8203;39319](https://github.com/go-gitea/gitea/pull/39319))
  - Fix: add default timeout and handle errors for HaveIBeenPwned API ([#&#8203;39316](https://github.com/go-gitea/gitea/pull/39316))
  - Fix(user): unify email validation for registration and settings ([#&#8203;39304](https://github.com/go-gitea/gitea/pull/39304))
  - Fix(ui): use button elements for branch and tag dropdown tabs ([#&#8203;39285](https://github.com/go-gitea/gitea/pull/39285))
  - Fix(auth): fix ssh and gpg key verification on windows ([#&#8203;39283](https://github.com/go-gitea/gitea/pull/39283))
  - Fix(feed): use meaningful lines as comment excerpt ([#&#8203;39276](https://github.com/go-gitea/gitea/pull/39276))
  - Fix(projects): allow max columns to the limit ([#&#8203;39272](https://github.com/go-gitea/gitea/pull/39272))
  - Fix: pass merge commit messages to git via stdin ([#&#8203;39269](https://github.com/go-gitea/gitea/pull/39269))
  - Fix(repo): surface unrelated histories on Sync Fork ([#&#8203;39258](https://github.com/go-gitea/gitea/pull/39258))
  - Fix: avoid nil panic and refactor some trivial problems ([#&#8203;39251](https://github.com/go-gitea/gitea/pull/39251))
  - Fix: restore missing blob file when re-publishing a package ([#&#8203;39239](https://github.com/go-gitea/gitea/pull/39239))
  - Fix(automerge): validate head commit before merge ([#&#8203;39235](https://github.com/go-gitea/gitea/pull/39235))
  - Fix(httplib): prevent leaking localhost:3000 in public links ([#&#8203;39217](https://github.com/go-gitea/gitea/pull/39217))
  - Fix(setting): honor bare -1 for timeout settings ([#&#8203;39181](https://github.com/go-gitea/gitea/pull/39181))
  - Fix: correct repo/attatchment absolute url and release layout ([#&#8203;39178](https://github.com/go-gitea/gitea/pull/39178))
  - Fix(web): populate the reason for "cannot commit to branch" in web editor commit form ([#&#8203;39155](https://github.com/go-gitea/gitea/pull/39155))
  - Fix(process): reap entire process group on cmd.Cancel ([#&#8203;39143](https://github.com/go-gitea/gitea/pull/39143))
  - Fix: recognize linguist language aliases ([#&#8203;39135](https://github.com/go-gitea/gitea/pull/39135))
  - Fix(repo): preserve transfer recipient collaboration ([#&#8203;39042](https://github.com/go-gitea/gitea/pull/39042))
  - Fix(db): make paginated database reads always require "order" option ([#&#8203;39017](https://github.com/go-gitea/gitea/pull/39017))
  - Fix: make local queue PopItem can be notified ([#&#8203;39011](https://github.com/go-gitea/gitea/pull/39011))
  - Fix: classify git failures on stderr, restrict migration failure detail ([#&#8203;39010](https://github.com/go-gitea/gitea/pull/39010))
  - Fix: allow re-requesting uncounted review approvals ([#&#8203;38988](https://github.com/go-gitea/gitea/pull/38988))
  - Fix(actions): allow larger scheduled workflows ([#&#8203;38985](https://github.com/go-gitea/gitea/pull/38985))
  - Fix: resolve actions commit status permission per repository ([#&#8203;38977](https://github.com/go-gitea/gitea/pull/38977))
  - Fix(deps): update module golang.org/x/image to v0.45.0 \[security] ([#&#8203;38930](https://github.com/go-gitea/gitea/pull/38930))
  - Fix(deps): update module golang.org/x/mod to v0.40.0 \[security] ([#&#8203;38914](https://github.com/go-gitea/gitea/pull/38914))
  - Fix: dedupe issue cross-reference timeline entries ([#&#8203;38881](https://github.com/go-gitea/gitea/pull/38881))
  - Fix(server): set `ReadHeaderTimeout` on HTTP servers ([#&#8203;38878](https://github.com/go-gitea/gitea/pull/38878))
  - Fix(repo): avoid a repo-sized temp file for every bundle download ([#&#8203;38863](https://github.com/go-gitea/gitea/pull/38863))
  - Fix(lfs): ensure lock listing paginates with a total order ([#&#8203;38850](https://github.com/go-gitea/gitea/pull/38850))
  - Fix(avatar): use sha256 and inline the federated avatar lookup ([#&#8203;38843](https://github.com/go-gitea/gitea/pull/38843))
  - Fix(gitdiff): render exact-limit diffs and zero-limit comments ([#&#8203;38838](https://github.com/go-gitea/gitea/pull/38838))
  - Fix(deps): update dependency mermaid to v11.16.1 \[security] ([#&#8203;38813](https://github.com/go-gitea/gitea/pull/38813))
  - Fix: misc fixes in pub/gpg/tests ([#&#8203;38809](https://github.com/go-gitea/gitea/pull/38809))
  - Fix: git diff blob excerpt ([#&#8203;38808](https://github.com/go-gitea/gitea/pull/38808))
  - Fix(packages): show error for duplicate cleanup rules [#&#8203;37820](https://github.com/go-gitea/gitea/issues/37820) ([#&#8203;38786](https://github.com/go-gitea/gitea/pull/38786))
  - Fix(actions): fix runner docs link ([#&#8203;38783](https://github.com/go-gitea/gitea/pull/38783))
  - Fix: git cache ([#&#8203;38763](https://github.com/go-gitea/gitea/pull/38763))
  - Fix(actions): evaluate each `${{ }}` part on its own ([#&#8203;38754](https://github.com/go-gitea/gitea/pull/38754))
  - Fix: don't report failed network requests as JavaScript errors ([#&#8203;38732](https://github.com/go-gitea/gitea/pull/38732))
  - Fix(gitdiff): prevent index out of range panic in GetLineTypeMarker ([#&#8203;38728](https://github.com/go-gitea/gitea/pull/38728))
  - Fix(api): document X-Total-Count instead of non-existent X-Total header ([#&#8203;38717](https://github.com/go-gitea/gitea/pull/38717))
  - Fix(actions): dynamic matrix expansion correctness fixes ([#&#8203;38690](https://github.com/go-gitea/gitea/pull/38690))
  - Fix(auth): record last sign-in on reverse proxy login ([#&#8203;38672](https://github.com/go-gitea/gitea/pull/38672))
  - Fix(api): accept fully-qualified refs in contents API ([#&#8203;38650](https://github.com/go-gitea/gitea/pull/38650))
  - Fix(deps): update module github.com/getkin/kin-openapi to v0.144.0 \[security] ([#&#8203;38623](https://github.com/go-gitea/gitea/pull/38623))
  - Fix(deps): update dependency js-yaml to v5.2.2 \[security] ([#&#8203;38622](https://github.com/go-gitea/gitea/pull/38622))
  - Fix: abort superseded issue suggestion requests ([#&#8203;38620](https://github.com/go-gitea/gitea/pull/38620))
  - Fix(issue): display error toast on batch action failures instead of reloading page ([#&#8203;38593](https://github.com/go-gitea/gitea/pull/38593))
  - Fix(deps): update module google.golang.org/grpc to v1.82.1 \[security] ([#&#8203;38567](https://github.com/go-gitea/gitea/pull/38567))
  - Fix(deps): update module github.com/google/go-github/v88 to v89 ([#&#8203;38433](https://github.com/go-gitea/gitea/pull/38433))
  - Fix(deps): update go dependencies ([#&#8203;38429](https://github.com/go-gitea/gitea/pull/38429))
  - Fix(deps): update go dependencies ([#&#8203;38346](https://github.com/go-gitea/gitea/pull/38346))
  - Fix(deps): update npm dependencies ([#&#8203;38342](https://github.com/go-gitea/gitea/pull/38342))
  - Fix(base): correct natural sort of numbers with leading zeros ([#&#8203;38163](https://github.com/go-gitea/gitea/pull/38163))
  - Fix(ui): avoid layout shifts in `overflow-menu` and repo filter ([#&#8203;37818](https://github.com/go-gitea/gitea/pull/37818))
  - Fix: make auth source group sync correctly handle team removal ([#&#8203;37161](https://github.com/go-gitea/gitea/pull/37161))
  - Fix(release): separate publication time from the release date ([#&#8203;36761](https://github.com/go-gitea/gitea/pull/36761))

- TESTING
  - Test: stop tests from writing into `~/.ssh` ([#&#8203;39348](https://github.com/go-gitea/gitea/pull/39348))
  - Test(e2e): log out to switch users in pr-review test ([#&#8203;39328](https://github.com/go-gitea/gitea/pull/39328))
  - Test: release fixtures loader lock before database work ([#&#8203;39263](https://github.com/go-gitea/gitea/pull/39263))
  - Test: speed up tests, fix transaction bug ([#&#8203;39030](https://github.com/go-gitea/gitea/pull/39030))
  - Test: run frontend unit tests in browsers ([#&#8203;38860](https://github.com/go-gitea/gitea/pull/38860))
  - Test(pubsub): stop racing the Redis SUBSCRIBE ack ([#&#8203;38661](https://github.com/go-gitea/gitea/pull/38661))
  - Test(e2e): add pull request merge box test, update AGENTS.md ([#&#8203;38576](https://github.com/go-gitea/gitea/pull/38576))
  - Test(e2e): deterministically wait for event stream in logout propagation test ([#&#8203;38535](https://github.com/go-gitea/gitea/pull/38535))

- BUILD
  - Refactor: fix `go vet` errors related to composite literals ([#&#8203;39341](https://github.com/go-gitea/gitea/pull/39341))
  - Build(gogit): disable gogit builds for stable releases ([#&#8203;39324](https://github.com/go-gitea/gitea/pull/39324))
  - Refactor: replace jquery.are-you-sure with first-party code ([#&#8203;39233](https://github.com/go-gitea/gitea/pull/39233))
  - Refactor: http request binding ([#&#8203;38971](https://github.com/go-gitea/gitea/pull/38971))
  - Refactor: clean up git repo and model migration packages ([#&#8203;38564](https://github.com/go-gitea/gitea/pull/38564))
  - Refactor: prepare to decouple the "model migration" package and "models" package ([#&#8203;38533](https://github.com/go-gitea/gitea/pull/38533))
  - Build: fix snapcraft release ([#&#8203;38260](https://github.com/go-gitea/gitea/pull/38260))
  - Build(release): use native golang toolchain for official release builds ([#&#8203;37828](https://github.com/go-gitea/gitea/pull/37828))

- DOCS
  - Docs(webhook): review\.type comment lists values the webhook never sends ([#&#8203;39451](https://github.com/go-gitea/gitea/pull/39451))
  - Docs(api): document verification and files on the compare endpoint ([#&#8203;39440](https://github.com/go-gitea/gitea/pull/39440))
  - Docs(api): name the unadopted-repository search parameter query ([#&#8203;39370](https://github.com/go-gitea/gitea/pull/39370))
  - Docs: remove unused COOKIE\_USERNAME from app.example.ini ([#&#8203;39365](https://github.com/go-gitea/gitea/pull/39365))
  - Docs: document NOTICE\_ON\_SUCCESS for every cron task ([#&#8203;39352](https://github.com/go-gitea/gitea/pull/39352))
  - Docs: correct ALLOW\_LOCALNETWORKS description in app.example.ini ([#&#8203;39240](https://github.com/go-gitea/gitea/pull/39240))
  - Docs: fix typo in README about app.ini restart ([#&#8203;39223](https://github.com/go-gitea/gitea/pull/39223))
  - Docs: fix dead localization doc link in the READMEs ([#&#8203;39211](https://github.com/go-gitea/gitea/pull/39211))
  - Docs: Update CHANGELOG for release 1.27.3 ([#&#8203;39170](https://github.com/go-gitea/gitea/pull/39170))
  - Docs: Update CHANGELOG for version 1.27.2 ([#&#8203;38923](https://github.com/go-gitea/gitea/pull/38923))
  - Docs: Update PGP key expiration date to July 23, 2027 ([#&#8203;38747](https://github.com/go-gitea/gitea/pull/38747))
  - Docs(api): document 401/403 responses for user key endpoints ([#&#8203;38711](https://github.com/go-gitea/gitea/pull/38711))
  - Docs: Update Changelog for release v1.27.1 ([#&#8203;38670](https://github.com/go-gitea/gitea/pull/38670))
  - Docs: Update Changelog for 1.27 ([#&#8203;38440](https://github.com/go-gitea/gitea/pull/38440))
  - Docs: Update Security docs ([#&#8203;38422](https://github.com/go-gitea/gitea/pull/38422))

- MISC
  - Refactor: make git http respond error message ([#&#8203;39390](https://github.com/go-gitea/gitea/pull/39390))
  - Refactor(api): convert bot accounts through the admin user edit endpoint ([#&#8203;39355](https://github.com/go-gitea/gitea/pull/39355))
  - Refactor: replace AWS SDK with a REST client for CodeCommit migration ([#&#8203;39330](https://github.com/go-gitea/gitea/pull/39330))
  - Refactor: replace Azure Blob SDK with a REST client ([#&#8203;39315](https://github.com/go-gitea/gitea/pull/39315))
  - Refactor: npm route handlers ([#&#8203;39275](https://github.com/go-gitea/gitea/pull/39275))
  - Refactor: GetDiffShortStat and fix panic caused by inconsistent "changed file number" ([#&#8203;39248](https://github.com/go-gitea/gitea/pull/39248))
  - Refactor(templates): update djlint to 1.46.0 and resolve its new findings ([#&#8203;39231](https://github.com/go-gitea/gitea/pull/39231))
  - Refactor: pagination/pager ([#&#8203;39162](https://github.com/go-gitea/gitea/pull/39162))
  - Refactor: share package registry error status classification ([#&#8203;39133](https://github.com/go-gitea/gitea/pull/39133))
  - Refactor: drop two unmaintained dependencies, rename the byte size helpers ([#&#8203;39083](https://github.com/go-gitea/gitea/pull/39083))
  - Refactor(automerge): fix error handling, populate recent automerge tasks on restart ([#&#8203;39001](https://github.com/go-gitea/gitea/pull/39001))
  - Refactor: deploy key and private route handlers ([#&#8203;38999](https://github.com/go-gitea/gitea/pull/38999))
  - Refactor: wiki edit form ([#&#8203;38918](https://github.com/go-gitea/gitea/pull/38918))
  - Refactor: clean up form binding & validation ([#&#8203;38873](https://github.com/go-gitea/gitea/pull/38873))
  - Refactor: markup render ([#&#8203;38864](https://github.com/go-gitea/gitea/pull/38864))
  - Refactor: api token scope check ([#&#8203;38862](https://github.com/go-gitea/gitea/pull/38862))
  - Refactor: replace `gliderlabs/ssh` with `golang.org/x/crypto/ssh` ([#&#8203;38837](https://github.com/go-gitea/gitea/pull/38837))
  - Refactor: form binding validation ([#&#8203;38832](https://github.com/go-gitea/gitea/pull/38832))
  - Refactor: prepare vue components for vapor mode ([#&#8203;38798](https://github.com/go-gitea/gitea/pull/38798))
  - Refactor: use the shared workflow model from actionslib ([#&#8203;38768](https://github.com/go-gitea/gitea/pull/38768))
  - Refactor(modelmigration): thread context through migration functions ([#&#8203;38758](https://github.com/go-gitea/gitea/pull/38758))
  - Refactor: migrate remaining Vue components to `<script setup>` ([#&#8203;38752](https://github.com/go-gitea/gitea/pull/38752))
  - Refactor: introduce trString for frontend ([#&#8203;38741](https://github.com/go-gitea/gitea/pull/38741))
  - Refactor(diff): drive diff DOM init from the global selector observer ([#&#8203;38740](https://github.com/go-gitea/gitea/pull/38740))
  - Refactor(git): clarify GetBranch behavior to make it only gets an existing branch ([#&#8203;38662](https://github.com/go-gitea/gitea/pull/38662))
  - Refactor: replace debounce/throttle deps with first-party code ([#&#8203;38610](https://github.com/go-gitea/gitea/pull/38610))
  - Refactor: hide git repo path details from more packages ([#&#8203;38601](https://github.com/go-gitea/gitea/pull/38601))
  - Refactor: retry file remove/rename when a file is busy and clean up os detection ([#&#8203;38588](https://github.com/go-gitea/gitea/pull/38588))
  - Perf(emoji): optimize FindEmojiSubmatchIndex using slice-based Trie ([#&#8203;38573](https://github.com/go-gitea/gitea/pull/38573))
  - Refactor: implement mcaptcha client and add comments/tests ([#&#8203;38561](https://github.com/go-gitea/gitea/pull/38561))
  - Refactor: use WithRepo instead of WithDir for most git operations, clean up model migrations ([#&#8203;38555](https://github.com/go-gitea/gitea/pull/38555))
  - Refactor: remove Path field from git.Repository ([#&#8203;38552](https://github.com/go-gitea/gitea/pull/38552))
  - Refactor: make git package handle all git operations ([#&#8203;38543](https://github.com/go-gitea/gitea/pull/38543))
  - Refactor: remove unnecessary git command wrapper functions ([#&#8203;38531](https://github.com/go-gitea/gitea/pull/38531))
  - Refactor: git repo and relative path handling ([#&#8203;38522](https://github.com/go-gitea/gitea/pull/38522))
  - Refactor: clean up fragile diff render templates, use backend typed structs ([#&#8203;38517](https://github.com/go-gitea/gitea/pull/38517))
  - Refactor: correct git repo design and fix some legacy problems ([#&#8203;38512](https://github.com/go-gitea/gitea/pull/38512))
  - Refactor: fix legacy problems in cmd/serv.go ([#&#8203;38505](https://github.com/go-gitea/gitea/pull/38505))
  - Refactor: remove Ctx field from git.Repository ([#&#8203;38500](https://github.com/go-gitea/gitea/pull/38500))
  - Refactor: decouple git.Repository(ctx) from git.Commit & git.Tree ([#&#8203;38464](https://github.com/go-gitea/gitea/pull/38464))
  - Refactor: introduce ActivePageTimer to help to do partial page refresh ([#&#8203;38372](https://github.com/go-gitea/gitea/pull/38372))

</details>

---

### Configuration

📅 **Schedule**: (in timezone Europe/Oslo)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

---------

Co-authored-by: Renovate Bot <renovate@forteapps.net>
Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/58
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: gitea_admin <admin@forteapps.net>
2026-10-04 21:53:01 +00:00
840c354ea3 chore(deps): update terraform azurerm to v5 (#55)
scan.yaml / test (push) Successful in 7s
This PR contains the following updates:

| Package | Type | Update | Change | Pending |
|---|---|---|---|---|
| [azurerm](https://registry.terraform.io/providers/hashicorp/azurerm) ([source](https://github.com/hashicorp/terraform-provider-azurerm)) | required_provider | major | `~> 4.0` → `~> 5.0` | `5.8.0` |

---

### Release Notes

<details>
<summary>hashicorp/terraform-provider-azurerm (azurerm)</summary>

### [`v5.7.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#570-September-24-2026)

[Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.6.0...v5.7.0)

FEATURES:

- **New List Resource**: `azurerm_private_dns_resolver_forwarding_rule` ([#&#8203;33313](https://github.com/hashicorp/terraform-provider-azurerm/issues/33313))
- **New List Resource**: `azurerm_windows_virtual_machine` ([#&#8203;33332](https://github.com/hashicorp/terraform-provider-azurerm/issues/33332))

ENHANCEMENTS:

- dependencies: `go-azure-sdk` - update to `v0.20260917.1142820` ([#&#8203;33495](https://github.com/hashicorp/terraform-provider-azurerm/issues/33495))
- dependencies: `network` - update API version to `2025-07-01` ([#&#8203;33441](https://github.com/hashicorp/terraform-provider-azurerm/issues/33441))
- Data Source: `azurerm_linux_web_app` - export the `virtual_network_image_pull_enabled` property ([#&#8203;33316](https://github.com/hashicorp/terraform-provider-azurerm/issues/33316))
- Data Source: `azurerm_network_interface` - export the `auxiliary_mode`, `auxiliary_sku`, `edge_zone`, and `internal_domain_name_suffix` properties ([#&#8203;33204](https://github.com/hashicorp/terraform-provider-azurerm/issues/33204))
- Data Source: `azurerm_public_ip` - export the `domain_name_label_scope`, `edge_zone`, `public_ip_prefix_id`, and `sku_tier` properties ([#&#8203;33193](https://github.com/hashicorp/terraform-provider-azurerm/issues/33193))
- Data Source: `azurerm_service_plan` - export the `premium_plan_auto_scale_enabled` property ([#&#8203;33300](https://github.com/hashicorp/terraform-provider-azurerm/issues/33300))
- Data Source: `azurerm_storage_blob` - export the `cache_control` and `source_uri` properties ([#&#8203;33318](https://github.com/hashicorp/terraform-provider-azurerm/issues/33318))
- Data Source: `azurerm_traffic_manager_profile` - export the `maximum_return` property ([#&#8203;33346](https://github.com/hashicorp/terraform-provider-azurerm/issues/33346))
- Data Source: `azurerm_web_pubsub` - export the `live_trace` and `identity` properties ([#&#8203;33373](https://github.com/hashicorp/terraform-provider-azurerm/issues/33373))
- `azurerm_kubernetes_cluster_node_pool` - add `Windows2025` as a valid value for the `os_sku` property ([#&#8203;33463](https://github.com/hashicorp/terraform-provider-azurerm/issues/33463))
- `azurerm_kubernetes_cluster` - add `Windows2025` as a valid value for the `os_sku` property ([#&#8203;33463](https://github.com/hashicorp/terraform-provider-azurerm/issues/33463))

BUG FIXES:

- Data Source: `azurerm_kubernetes_cluster` - fix a panic caused by a nil pointer dereference while flattening `agent_pool_profile` ([#&#8203;33488](https://github.com/hashicorp/terraform-provider-azurerm/issues/33488))
- `azurerm_postgresql_flexible_server` - fix `cluster` block read for replica `create_mode` ([#&#8203;33082](https://github.com/hashicorp/terraform-provider-azurerm/issues/33082))

### [`v5.6.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#560-September-17-2026)

[Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.5.0...v5.6.0)

FEATURES:

- **New List Resource**: `azurerm_batch_account` ([#&#8203;33252](https://github.com/hashicorp/terraform-provider-azurerm/issues/33252))
- **New List Resource**: `azurerm_cdn_frontdoor_origin_group` ([#&#8203;33334](https://github.com/hashicorp/terraform-provider-azurerm/issues/33334))
- **New Resource**: `azurerm_storage_discovery_workspace` ([#&#8203;31479](https://github.com/hashicorp/terraform-provider-azurerm/issues/31479))

ENHANCEMENTS:

- dependencies: `containers` - update API version to `2026-05-01` ([#&#8203;32688](https://github.com/hashicorp/terraform-provider-azurerm/issues/32688))
- dependencies: `go-azure-sdk` - update to `v0.20260910.1141000` ([#&#8203;33413](https://github.com/hashicorp/terraform-provider-azurerm/issues/33413))
- dependencies: `qumulo` - update API version to `2026-04-16` ([#&#8203;33421](https://github.com/hashicorp/terraform-provider-azurerm/issues/33421))
- dependencies: `servicebus` - update to API version `2026-01-01` ([#&#8203;33450](https://github.com/hashicorp/terraform-provider-azurerm/issues/33450))
- `azurerm_iothub_device_update_instance` - add support for the `connection_string_wo` and `connection_string_wo_version` properties ([#&#8203;33448](https://github.com/hashicorp/terraform-provider-azurerm/issues/33448))
- `azurerm_linux_function_app` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))
- `azurerm_linux_function_app_slot` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))
- `azurerm_linux_web_app` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))
- `azurerm_linux_web_app_slot` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))
- `azurerm_mongo_cluster` - Support new property `network_bypass_mode` ([#&#8203;33168](https://github.com/hashicorp/terraform-provider-azurerm/issues/33168))
- `azurerm_servicebus_namespace` - add support for the `1.3` value to the `minimum_tls_version` property ([#&#8203;33457](https://github.com/hashicorp/terraform-provider-azurerm/issues/33457))
- `azurerm_windows_function_app` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))
- `azurerm_windows_function_app_slot` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))
- `azurerm_windows_web_app` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))
- `azurerm_windows_web_app_slot` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))

BUG FIXES:

- `azurerm_site_recovery_replicated_vm` - select `managed_disk` properties compared case insensitive ([#&#8203;33424](https://github.com/hashicorp/terraform-provider-azurerm/issues/33424))

### [`v5.5.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#550-September-10-2026)

[Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.4.0...v5.5.0)

FEATURES:

- **New List Resource**: `azurerm_analysis_services_server` ([#&#8203;33250](https://github.com/hashicorp/terraform-provider-azurerm/issues/33250))
- **New List Resource**: `azurerm_application_insights_workbook` ([#&#8203;33244](https://github.com/hashicorp/terraform-provider-azurerm/issues/33244))
- **New List Resource**: `azurerm_attestation_provider` ([#&#8203;33251](https://github.com/hashicorp/terraform-provider-azurerm/issues/33251))
- **New List Resource**: `azurerm_cdn_frontdoor_origin` ([#&#8203;33307](https://github.com/hashicorp/terraform-provider-azurerm/issues/33307))
- **New List Resource**: `azurerm_eventhub_consumer_group` ([#&#8203;33335](https://github.com/hashicorp/terraform-provider-azurerm/issues/33335))
- **New List Resource**: `azurerm_linux_virtual_machine` ([#&#8203;33333](https://github.com/hashicorp/terraform-provider-azurerm/issues/33333))
- **New List Resource**: `azurerm_virtual_hub_connection` ([#&#8203;33311](https://github.com/hashicorp/terraform-provider-azurerm/issues/33311))

ENHANCEMENTS:

- dependencies: `go-azure-sdk` - update to `v0.20260901.1173158` ([#&#8203;33274](https://github.com/hashicorp/terraform-provider-azurerm/issues/33274))
- `azurerm_private_endpoint` - lock on private service connection resource ids ([#&#8203;33298](https://github.com/hashicorp/terraform-provider-azurerm/issues/33298))
- `azurerm_storage_account` - add support for the `public_network_access` property ([#&#8203;33292](https://github.com/hashicorp/terraform-provider-azurerm/issues/33292))

BUG FIXES:

- `azurerm_resource_group` - the `managed_by` property now forces recreation when changed as the API does not support changing this value ([#&#8203;33339](https://github.com/hashicorp/terraform-provider-azurerm/issues/33339))
- `go-azure-sdk` - `Delete` operations now poll on asynchronous operation URLs if returned by the API instead of only checking for a `404` on the resource URL, ensuring deletion errors are reported to the user ([#&#8203;33274](https://github.com/hashicorp/terraform-provider-azurerm/issues/33274))

### [`v5.4.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#540-September-03-2026)

[Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.3.0...v5.4.0)

FEATURES:

- **New List Resource**: `azurerm_application_insights_standard_web_test` ([#&#8203;33243](https://github.com/hashicorp/terraform-provider-azurerm/issues/33243))
- **New List Resource**: `azurerm_application_insights_workbook_template` ([#&#8203;33245](https://github.com/hashicorp/terraform-provider-azurerm/issues/33245))
- **New List Resource**: `azurerm_arc_kubernetes_provisioned_cluster` ([#&#8203;33247](https://github.com/hashicorp/terraform-provider-azurerm/issues/33247))
- **New List Resource**: `azurerm_availability_set` ([#&#8203;33241](https://github.com/hashicorp/terraform-provider-azurerm/issues/33241))
- **New List Resource**: `azurerm_batch_application` ([#&#8203;33254](https://github.com/hashicorp/terraform-provider-azurerm/issues/33254))
- **New List Resource**: `azurerm_dedicated_host_group` ([#&#8203;33257](https://github.com/hashicorp/terraform-provider-azurerm/issues/33257))
- **New List Resource**: `azurerm_log_analytics_workspace` ([#&#8203;33259](https://github.com/hashicorp/terraform-provider-azurerm/issues/33259))

ENHANCEMENTS:

- dependencies: `azurerm_mongo_cluster` - update API version to `2026-06-01` ([#&#8203;33195](https://github.com/hashicorp/terraform-provider-azurerm/issues/33195))
- dependencies: `azurerm_mongo_cluster_firewall_rule` - update API version to `2026-06-01` ([#&#8203;33195](https://github.com/hashicorp/terraform-provider-azurerm/issues/33195))
- dependencies: `azurerm_mongo_cluster_user` - update API version to `2026-06-01` ([#&#8203;33195](https://github.com/hashicorp/terraform-provider-azurerm/issues/33195))
- dependencies: `netapp` - update API version to `2026-05-01` ([#&#8203;33215](https://github.com/hashicorp/terraform-provider-azurerm/issues/33215))
- Data Source: `azurerm_api_management_workspace` - export the `description` property ([#&#8203;33205](https://github.com/hashicorp/terraform-provider-azurerm/issues/33205))
- Data Source: `azurerm_attestation_provider` - export the `sev_snp_policy_base64`, `open_enclave_policy_base64`, `sgx_enclave_policy_base64`, and `tpm_policy_base64` properties ([#&#8203;33125](https://github.com/hashicorp/terraform-provider-azurerm/issues/33125))
- Data Source: `azurerm_automation_account` - export the `dsc_primary_access_key`, `dsc_server_endpoint`, `dsc_secondary_access_key`, `public_network_access_enabled`, `sku_name`, and `tags` properties ([#&#8203;33135](https://github.com/hashicorp/terraform-provider-azurerm/issues/33135))
- Data Source: `azurerm_automation_account` - export the `encryption` block ([#&#8203;33135](https://github.com/hashicorp/terraform-provider-azurerm/issues/33135))
- Data Source: `azurerm_ip_group` - export the `firewall_ids` and `firewall_policy_ids` properties ([#&#8203;33190](https://github.com/hashicorp/terraform-provider-azurerm/issues/33190))
- Data Source: `azurerm_private_link_service` - export the `fqdns` and `destination_ip_address` properties ([#&#8203;33191](https://github.com/hashicorp/terraform-provider-azurerm/issues/33191))
- `azurerm_key_vault_managed_hardware_security_module_key` - allow the `key_size` property to be set when `key_type` is `oct-HSM` ([#&#8203;32690](https://github.com/hashicorp/terraform-provider-azurerm/issues/32690))
- `azurerm_lb_probe ` - add support for the `no_healthy_backends_behavior` property ([#&#8203;32645](https://github.com/hashicorp/terraform-provider-azurerm/issues/32645))
- `azurerm_linux_virtual_machine_scale_set` - add support for the `NvmeDisk` value to the `os_disk.diff_disk_settings.placement` property ([#&#8203;30328](https://github.com/hashicorp/terraform-provider-azurerm/issues/30328))
- `azurerm_linux_web_app` - add support for the `8.5` value in the  `site_config.application_stack.php_version` property ([#&#8203;33308](https://github.com/hashicorp/terraform-provider-azurerm/issues/33308))
- `azurerm_linux_web_app_slot` - add support for the `8.5` value in the  `site_config.application_stack.php_version` property ([#&#8203;33308](https://github.com/hashicorp/terraform-provider-azurerm/issues/33308))
- `azurerm_netapp_volume` - support for the `breakthrough_mode_enabled` property ([#&#8203;33215](https://github.com/hashicorp/terraform-provider-azurerm/issues/33215))
- `azurerm_postgresql_flexible_server` - add support for the `storage_type`, `storage_iops`, and `storage_throughput` properties which allows choice of the new "Premium V2 LRS" storage type ([#&#8203;32121](https://github.com/hashicorp/terraform-provider-azurerm/issues/32121))
- `azurerm_storage_account` - add support for an in-place migration of `account_replication_type` between matching non-zonal and zonal types instead of resource recreation ([#&#8203;33236](https://github.com/hashicorp/terraform-provider-azurerm/issues/33236))
- `azurerm_storage_table` - add support for AAD authentication ([#&#8203;32997](https://github.com/hashicorp/terraform-provider-azurerm/issues/32997))
- `azurerm_synapse_spark_pool` - migrate to `go-azure-sdk` ([#&#8203;33258](https://github.com/hashicorp/terraform-provider-azurerm/issues/33258))
- `azurerm_windows_virtual_machine_scale_set` - add support for the `NvmeDisk` value to the `os_disk.diff_disk_settings.placement` property ([#&#8203;30328](https://github.com/hashicorp/terraform-provider-azurerm/issues/30328))

BUG FIXES:

- `azurerm_synapse_spark_pool` - fix `lifecycle.ignore_changes` support ([#&#8203;33258](https://github.com/hashicorp/terraform-provider-azurerm/issues/33258))

### [`v5.3.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#530-August-27-2026)

[Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.2.0...v5.3.0)

FEATURES:

- **New Data Source**: `azurerm_playwright_workspace` ([#&#8203;31954](https://github.com/hashicorp/terraform-provider-azurerm/issues/31954))
- **New List Resource**: `azurerm_cognitive_deployment` ([#&#8203;33149](https://github.com/hashicorp/terraform-provider-azurerm/issues/33149))
- **New List Resource**: `azurerm_playwright_workspace` ([#&#8203;31954](https://github.com/hashicorp/terraform-provider-azurerm/issues/31954))
- **New Resource**: `azurerm_playwright_workspace` ([#&#8203;31954](https://github.com/hashicorp/terraform-provider-azurerm/issues/31954))

ENHANCEMENTS:

- dependencies: `go-azure-helpers` - update version to `0.82.0` ([#&#8203;33142](https://github.com/hashicorp/terraform-provider-azurerm/issues/33142))
- dependencies: `sql` - update API version to `2025-01-01` ([#&#8203;33201](https://github.com/hashicorp/terraform-provider-azurerm/issues/33201))
- Data Source: `azurerm_role_definition` - export the `role_definition_resource_id` property ([#&#8203;33126](https://github.com/hashicorp/terraform-provider-azurerm/issues/33126))
- `azurerm_cognitive_deployment` - add Resource Identity support ([#&#8203;33149](https://github.com/hashicorp/terraform-provider-azurerm/issues/33149))
- `azurerm_federated_identity_credential` - add additional polling to account for Azure's eventual consistency ([#&#8203;32935](https://github.com/hashicorp/terraform-provider-azurerm/issues/32935))
- `azurerm_kubernetes_cluster` - add support for the `oms_agent.retina_flow_logs_enabled` property ([#&#8203;33222](https://github.com/hashicorp/terraform-provider-azurerm/issues/33222))
- `azurerm_managed_application` - add support for the `identity` block ([#&#8203;30725](https://github.com/hashicorp/terraform-provider-azurerm/issues/30725))
- `azurerm_private_endpoint` - extend validation for the `private_service_connection.subresource_names` property to allow names containing spaces ([#&#8203;32887](https://github.com/hashicorp/terraform-provider-azurerm/issues/32887))
- `azurerm_search_service` - allow in-place downgrades of the `sku` property between Basic and Standard tiers ([#&#8203;33069](https://github.com/hashicorp/terraform-provider-azurerm/issues/33069))
- `azurerm_site_recovery_replicated_vm` - add update support to the `managed_disk` block without requiring resource recreation ([#&#8203;33140](https://github.com/hashicorp/terraform-provider-azurerm/issues/33140))
- `azurerm_user_assigned_identity` - add additional polling to account for Azure's eventual consistency ([#&#8203;33142](https://github.com/hashicorp/terraform-provider-azurerm/issues/33142))

BUG FIXES:

- Data Source: `azurerm_app_configuration_key` - now correctly sets `tags` into state ([#&#8203;33182](https://github.com/hashicorp/terraform-provider-azurerm/issues/33182))
- `azurerm_eventhub_namespace` - prevent `network_rulesets.x.default_action` being set to `Deny` if `ip_rule` or `virtual_network_rule` is not specified ([#&#8203;33216](https://github.com/hashicorp/terraform-provider-azurerm/issues/33216))

### [`v5.2.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#520-August-20-2026)

[Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.1.0...v5.2.0)

FEATURES:

- **New List Resource**: `azurerm_user_assigned_identity` ([#&#8203;32667](https://github.com/hashicorp/terraform-provider-azurerm/issues/32667))

ENHANCEMENTS:

- dependencies: `go` - update to `1.26.6` ([#&#8203;33141](https://github.com/hashicorp/terraform-provider-azurerm/issues/33141))
- dependencies: `go-azure-sdk` - update to `v0.20260811.1225050` ([#&#8203;33079](https://github.com/hashicorp/terraform-provider-azurerm/issues/33079))
- `azurerm_cdn_frontdoor_batch_rule_set` - allow `/` as an input to `rule.conditions.request_path.values` ([#&#8203;33023](https://github.com/hashicorp/terraform-provider-azurerm/issues/33023))
- `azurerm_databricks_workspace` - remove a redundant key vault existence check ([#&#8203;33136](https://github.com/hashicorp/terraform-provider-azurerm/issues/33136))
- `azurerm_databricks_workspace_root_dbfs_customer_managed_key` - remove a redundant key vault existence check ([#&#8203;33136](https://github.com/hashicorp/terraform-provider-azurerm/issues/33136))
- `azurerm_logic_app_standard` - add support for `v10.0` to `site_config.dotnet_framework_version` ([#&#8203;33116](https://github.com/hashicorp/terraform-provider-azurerm/issues/33116))
- `azurerm_mongo_cluster` - `administrator_password` is no longer required when `create_mode` is `Default` to support Entra ID-only authentication ([#&#8203;32092](https://github.com/hashicorp/terraform-provider-azurerm/issues/32092))
- `azurerm_redhat_openshift_cluster` - add support for the `network_profile.load_balancer_profile` block ([#&#8203;32473](https://github.com/hashicorp/terraform-provider-azurerm/issues/32473))
- `azurerm_redhat_openshift_cluster` - add support for the `platform_workload_identity_profile` block ([#&#8203;32473](https://github.com/hashicorp/terraform-provider-azurerm/issues/32473))
- `azurerm_role_assignment` - the `condition`, `condition_version`, and `description` properties can now be updated in-place ([#&#8203;32714](https://github.com/hashicorp/terraform-provider-azurerm/issues/32714))
- `azurerm_snapshot` - `create_option` now supports `CopyStart` ([#&#8203;32834](https://github.com/hashicorp/terraform-provider-azurerm/issues/32834))

BUG FIXES:

- `azurerm_cognitive_account_project` - added create/update/delete lock on parent AccountID to make sure operations on parent account are processed in serial (required by Cognitive service) ([#&#8203;33151](https://github.com/hashicorp/terraform-provider-azurerm/issues/33151))
- `azurerm_databricks_workspace` - fix a persistent diff on removal of `managed_disk_cmk_key_vault_key_id` or `managed_services_cmk_key_vault_key_id` ([#&#8203;33136](https://github.com/hashicorp/terraform-provider-azurerm/issues/33136))
- `azurerm_oracle_exadata_infrastructure` - fix an issue that prevented users from deploying with no `zones` set ([#&#8203;33011](https://github.com/hashicorp/terraform-provider-azurerm/issues/33011))

### [`v5.1.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#510-August-13-2026)

[Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.0.1...v5.1.0)

ENHANCEMENTS:

- dependencies: `azurerm_linux_virtual_machine_scale_set` - update to API version `2025-04-01` ([#&#8203;31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586))
- dependencies: `azurerm_orchestrated_virtual_machine_scale_set` - update to API version `2025-04-01` ([#&#8203;31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586))
- dependencies: `azurerm_virtual_machine_scale_set` - update to API version `2025-04-01` ([#&#8203;31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586))
- dependencies: `azurerm_virtual_machine_scale_set_extension` - update to API version `2025-04-01` ([#&#8203;31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586))
- dependencies: `azurerm_windows_virtual_machine_scale_set` - update to API version `2025-04-01` ([#&#8203;31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586))
- dependencies: `codesigning` - update to API version `2025-10-13` ([#&#8203;31714](https://github.com/hashicorp/terraform-provider-azurerm/issues/31714))
- `azurerm_linux_virtual_machine` - `encryption_at_host_enabled` can now be set to `true` when `os_disk.security_encryption_type` is set to `DiskWithVMGuestState` ([#&#8203;32885](https://github.com/hashicorp/terraform-provider-azurerm/issues/32885))
- `azurerm_linux_virtual_machine_scale_set` - `encryption_at_host_enabled` can now be set to `true` when `os_disk.security_encryption_type` is set to `DiskWithVMGuestState` ([#&#8203;32885](https://github.com/hashicorp/terraform-provider-azurerm/issues/32885))
- `azurerm_managed_devops_pool` - add support for the `CreatorOnly` value to `azure_devops_organization.permission.kind` property ([#&#8203;32753](https://github.com/hashicorp/terraform-provider-azurerm/issues/32753))
- `azurerm_windows_virtual_machine` - `encryption_at_host_enabled` can now be set to `true` when `os_disk.security_encryption_type` is set to `DiskWithVMGuestState` ([#&#8203;32885](https://github.com/hashicorp/terraform-provider-azurerm/issues/32885))
- `azurerm_windows_virtual_machine_scale_set` - `encryption_at_host_enabled` can now be set to `true` when `os_disk.security_encryption_type` is set to `DiskWithVMGuestState` ([#&#8203;32885](https://github.com/hashicorp/terraform-provider-azurerm/issues/32885))

BUG FIXES:

- `azurerm_cdn_frontdoor_batch_ruleset` - parse `rule.actions.route_configuration_override.origin_group.cdn_frontdoor_origin_group_id` case-insensitively and normalize the resulting value to prevent diffs ([#&#8203;32980](https://github.com/hashicorp/terraform-provider-azurerm/issues/32980))
- `azurerm_cdn_frontdoor_route` - parse `cdn_frontdoor_origin_group_id` case-insensitively and normalize the resulting value to prevent diffs ([#&#8203;32980](https://github.com/hashicorp/terraform-provider-azurerm/issues/32980))
- `azurerm_cdn_frontdoor_secret` - fix an incorrect type assertion ([#&#8203;32982](https://github.com/hashicorp/terraform-provider-azurerm/issues/32982))
- `azurerm_dev_center_project` - parse `dev_center_id` case-insensitively and normalize the resulting value to prevent diffs ([#&#8203;32798](https://github.com/hashicorp/terraform-provider-azurerm/issues/32798))
- `azurerm_eventhub` - now prevents the `status` property from being set to `SendDisabled` on create  ([#&#8203;33071](https://github.com/hashicorp/terraform-provider-azurerm/issues/33071))
- `azurerm_storage_container` - add a state migration for the `id` field, fixing the upgrade path from 4.x to 5.x ([#&#8203;32978](https://github.com/hashicorp/terraform-provider-azurerm/issues/32978))
- `azurerm_storage_queue` - extend state migration to handle a malformed `resource_manager_id` ([#&#8203;32979](https://github.com/hashicorp/terraform-provider-azurerm/issues/32979))
- `azurerm_storage_share` - add a state migration for the `id` field, fixing the upgrade path from 4.x to 5.x ([#&#8203;33075](https://github.com/hashicorp/terraform-provider-azurerm/issues/33075))

### [`v5.0.1`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#501-July-30-2026)

[Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.0.0...v5.0.1)

NOTES:

In addition to the bug fixes below, a number of resource documentation pages and the 5.0-upgrade-guide have been updated.

BUG FIXES:

- `azurerm_cdn_frontdoor_origin` - fix a regression that prevented valid values as input to `private_link.private_link_target_id` ([#&#8203;32912](https://github.com/hashicorp/terraform-provider-azurerm/issues/32912))
- `azurerm_storage_queue` - add a state migration for the `id` field, fixing the upgrade path from 4.x to 5.x ([#&#8203;32914](https://github.com/hashicorp/terraform-provider-azurerm/issues/32914))
- `azurerm_storage_table_entity` - add a state migration for the `storage_table_id` field, fixing the upgrade path from 4.x to 5.x ([#&#8203;32929](https://github.com/hashicorp/terraform-provider-azurerm/issues/32929))

### [`v5.0.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#500-July-27-2026)

[Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v4.81.0...v5.0.0)

NOTES:

- **Major Version**: Version 5.0 of the Azure Provider is a major version - some behaviours have changed and some deprecated fields/resources have been removed - please refer to [the 5.0 upgrade guide for more information](https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/guides/5.0-upgrade-guide).
- When upgrading to v5.0 of the AzureRM Provider, we recommend upgrading to the latest version of Terraform Core ([which can be found here](https://developer.hashicorp.com/terraform/install)).

FEATURES:

- **New Action**: `azurerm_web_app_set_slot_distribution` ([#&#8203;32364](https://github.com/hashicorp/terraform-provider-azurerm/issues/32364))
- **New Datasource** adds `azurerm_kubernetes_automatic_cluster_datasource` ([#&#8203;32881](https://github.com/hashicorp/terraform-provider-azurerm/issues/32881))

ENHANCEMENTS:

- dependencies: `grpc` update to `1.82.1` ([#&#8203;32852](https://github.com/hashicorp/terraform-provider-azurerm/issues/32852))
- dependencies: `loadbalancers` - update to API version `2025-01-01` ([#&#8203;32644](https://github.com/hashicorp/terraform-provider-azurerm/issues/32644))
- `azurerm_cognitive_account_rai_policy` - the `content_filter.severity_threshold` property is now optional ([#&#8203;32100](https://github.com/hashicorp/terraform-provider-azurerm/issues/32100))
- `azurerm_container_registry` - the `trust_policy_enabled` property has been deprecated and removed from the provider ([#&#8203;32752](https://github.com/hashicorp/terraform-provider-azurerm/issues/32752))
- `azurerm_dashboard_grafana` - the `11` value for the `grafana_major_version` property has been deprecated and the property now supports `13` ([#&#8203;32777](https://github.com/hashicorp/terraform-provider-azurerm/issues/32777))
- `azurerm_log_analytics_workspace` - add support for the `internet_ingestion_access_type` and `internet_query_access_type` properties ([#&#8203;32562](https://github.com/hashicorp/terraform-provider-azurerm/issues/32562))
- `azurerm_subnet` - add support for the `network_security_group_id_wo` and `network_security_group_id_wo_version` properties ([#&#8203;32847](https://github.com/hashicorp/terraform-provider-azurerm/issues/32847))
- `azurerm_subnet` - add support for the `route_table_id_wo` and `route_table_id_wo_version` properties ([#&#8203;32847](https://github.com/hashicorp/terraform-provider-azurerm/issues/32847))
- `azurerm_subnet` - export the `network_security_group_id` property ([#&#8203;32847](https://github.com/hashicorp/terraform-provider-azurerm/issues/32847))
- `azurerm_subnet` - export the `route_table_id` property ([#&#8203;32847](https://github.com/hashicorp/terraform-provider-azurerm/issues/32847))
- `azurerm_windows_web_app` - add support for `~24` to `site_config.application_stack.node_version` ([#&#8203;32840](https://github.com/hashicorp/terraform-provider-azurerm/issues/32840))
- `azurerm_windows_web_app_slot` - add support for `~24` to `site_config.application_stack.node_version` ([#&#8203;32840](https://github.com/hashicorp/terraform-provider-azurerm/issues/32840))
- `cdn` - migrate to `go-azure-sdk` ([#&#8203;32849](https://github.com/hashicorp/terraform-provider-azurerm/issues/32849))
- `sentinel` - migrate to `go-azure-sdk` ([#&#8203;32759](https://github.com/hashicorp/terraform-provider-azurerm/issues/32759))

</details>

---

### Configuration

📅 **Schedule**: (in timezone Europe/Oslo)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

---------

Co-authored-by: Renovate Bot <renovate@forteapps.net>
Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/55
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: gitea_admin <admin@forteapps.net>
2026-10-03 18:55:31 +00:00
0f0082d54d chore(deps): update helm release fluent-bit to v0.58.3 (#57)
scan.yaml / test (push) Successful in 7s
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [fluent-bit](https://fluentbit.io/) ([source](https://github.com/fluent/helm-charts)) | patch | `0.58.2` → `0.58.3` |

---

### Release Notes

<details>
<summary>fluent/helm-charts (fluent-bit)</summary>

### [`v0.58.3`](https://github.com/fluent/helm-charts/releases/tag/fluent-bit-0.58.3)

[Compare Source](https://github.com/fluent/helm-charts/compare/fluent-bit-0.58.2...fluent-bit-0.58.3)

##### Changed

- Update *Fluent Bit* OCI image to [v5.1.3](https://github.com/fluent/fluent-bit/releases/tag/v5.1.3). ([#&#8203;759](https://github.com/fluent/helm-charts/pull/759)) [@&#8203;stevehipwell](https://github.com/stevehipwell)

</details>

---

### Configuration

📅 **Schedule**: (in timezone Europe/Oslo)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

---------

Co-authored-by: Renovate Bot <renovate@forteapps.net>
Reviewed-on: #57
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: gitea_admin <admin@forteapps.net>
2026-10-03 18:55:02 +00:00
jorgen.stensrudandClaude Opus 5.5 4a4b8e3540 feat(keycloak): forte-cli device-code client + forte-drop-mcp audience mapper (#44)
scan.yaml / test (push) Successful in 5s
Adds the shared public forte-cli client (RFC 8628 device-code only) to the forte realm, with an oidc-audience-mapper that puts https://mcp.drop.forteapps.net/mcp into aud so the forte-drop-mcp sidecar accepts its tokens. Supersedes #26.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-01 11:25:34 +00:00
9 changed files with 43 additions and 8 deletions
+1 -1
View File
@@ -4,7 +4,7 @@ terraform {
required_providers { required_providers {
azurerm = { azurerm = {
source = "hashicorp/azurerm" source = "hashicorp/azurerm"
version = "~> 4.0" version = "~> 5.0"
} }
} }
} }
@@ -4,7 +4,7 @@ terraform {
required_providers { required_providers {
azurerm = { azurerm = {
source = "hashicorp/azurerm" source = "hashicorp/azurerm"
version = "~> 4.0" version = "~> 5.0"
} }
azuread = { azuread = {
source = "hashicorp/azuread" source = "hashicorp/azuread"
+1 -1
View File
@@ -4,7 +4,7 @@ terraform {
required_providers { required_providers {
azurerm = { azurerm = {
source = "hashicorp/azurerm" source = "hashicorp/azurerm"
version = "~> 4.0" version = "~> 5.0"
} }
} }
} }
+1 -1
View File
@@ -4,7 +4,7 @@ terraform {
required_providers { required_providers {
azurerm = { azurerm = {
source = "hashicorp/azurerm" source = "hashicorp/azurerm"
version = "~> 4.0" version = "~> 5.0"
} }
random = { random = {
source = "hashicorp/random" source = "hashicorp/random"
+1 -1
View File
@@ -29,7 +29,7 @@ spec:
topologyKey: kubernetes.io/hostname topologyKey: kubernetes.io/hostname
initContainers: initContainers:
- name: gitea-dump - name: gitea-dump
image: gitea/gitea:1.27.3 image: gitea/gitea:28.0.0
command: command:
- sh - sh
- -c - -c
+6
View File
@@ -1469,6 +1469,12 @@ ArgoCD will sync the Keycloak config, and the registrar CronJob will pick up the
| `k8s.secret.client-id-key` | No | `client-id` | Field name for the client ID in the K8s Secret | | `k8s.secret.client-id-key` | No | `client-id` | Field name for the client ID in the K8s Secret |
| `k8s.secret.client-secret-key` | No | `client-secret` | Field name for the client secret in the K8s Secret | | `k8s.secret.client-secret-key` | No | `client-secret` | Field name for the client secret in the K8s Secret |
#### Public CLI Client (Device-Code Login)
`forte-cli` is a shared **public** client (no secret) with the RFC 8628 device-authorization grant enabled (`oauth2.device.authorization.grant.enabled: "true"`, `standardFlowEnabled: false`, `directAccessGrantsEnabled: false`). Downloaded skills and CLI tools that log in through the Auth Sidecar (forte-drop first) use it with `<PREFIX>_CLIENT_ID=forte-cli`; nothing per-tool needs to be registered in Keycloak.
It must be defined in `forte-realm.json` (this legacy path): the self-service registrar hardcodes `publicClient: false` / `standardFlowEnabled: true` and drops `attributes`, so a `client-config` Secret cannot produce a public device-code client. It carries no `k8s.secret.sync` attribute (the registrar's secret sync skips it) and is listed in the cleanup CronJob's protected clients.
### Retrieving Secrets for External Deployments ### Retrieving Secrets for External Deployments
The registrar always writes a **central copy** of every synced secret to the `secrets` namespace, in addition to the target namespace. This allows operators to retrieve client credentials for applications deployed outside this cluster: The registrar always writes a **central copy** of every synced secret to the `secrets` namespace, in addition to the target namespace. This allows operators to retrieve client credentials for applications deployed outside this cluster:
+1 -1
View File
@@ -17,7 +17,7 @@ spec:
sources: sources:
- repoURL: https://fluent.github.io/helm-charts - repoURL: https://fluent.github.io/helm-charts
chart: fluent-bit chart: fluent-bit
targetRevision: 0.58.2 targetRevision: 0.58.3
helm: helm:
releaseName: fluent-bit releaseName: fluent-bit
valueFiles: valueFiles:
@@ -24,7 +24,7 @@ spec:
sources: sources:
- repoURL: https://traefik.github.io/charts - repoURL: https://traefik.github.io/charts
chart: traefik chart: traefik
targetRevision: "28.3.0" targetRevision: "41.6.0"
helm: helm:
releaseName: traefik releaseName: traefik
valueFiles: valueFiles:
+30 -1
View File
@@ -186,6 +186,35 @@ keycloakConfigCli:
} }
} }
] ]
},
{
"clientId": "forte-cli",
"name": "Forte CLI",
"description": "Shared public client for RFC 8628 device-code login from downloaded skills/CLI tools (forte-drop first) against services behind Auth Sidecar. No client secret.",
"enabled": true,
"protocol": "openid-connect",
"standardFlowEnabled": false,
"directAccessGrantsEnabled": false,
"publicClient": true,
"redirectUris": [],
"webOrigins": [],
"attributes": {
"oauth2.device.authorization.grant.enabled": "true"
},
"protocolMappers": [
{
"name": "audience-forte-drop-mcp",
"protocol": "openid-connect",
"protocolMapper": "oidc-audience-mapper",
"consentRequired": false,
"config": {
"included.custom.audience": "https://mcp.drop.forteapps.net/mcp",
"access.token.claim": "true",
"id.token.claim": "false",
"introspection.token.claim": "true"
}
}
]
} }
], ],
"browserFlow": "browser-auto-idp", "browserFlow": "browser-auto-idp",
@@ -671,7 +700,7 @@ extraDeploy:
MIN_AGE_SEC=$((MIN_AGE_DAYS * 86400)) MIN_AGE_SEC=$((MIN_AGE_DAYS * 86400))
# Hardcoded protected clients (never delete these) # Hardcoded protected clients (never delete these)
PROTECTED_JSON='["gitea","grafana","argocd","vaultwarden","account","account-console","admin-cli","broker","realm-management","security-admin-console"]' PROTECTED_JSON='["gitea","grafana","argocd","forte-cli","vaultwarden","account","account-console","admin-cli","broker","realm-management","security-admin-console"]'
echo "Fetching clients from realm '${REALM}'..." echo "Fetching clients from realm '${REALM}'..."
CLIENTS=$(curl -sf -H "Authorization: Bearer ${TOKEN}" \ CLIENTS=$(curl -sf -H "Authorization: Bearer ${TOKEN}" \