Compare commits

..
Author SHA1 Message Date
Renovate Botanddanijel.simeunovic 0d574ba890 chore(deps): update dependency argocd to v3
AI Code Review / ai-review (pull_request) Has been skipped
/ test (pull_request) Successful in 24s
2026-09-28 06:59:52 +00:00
25 changed files with 41 additions and 77 deletions
+4 -5
View File
@@ -23,15 +23,14 @@ jobs:
REVIEW__INLINE_COMMENT_FALLBACK: "false" REVIEW__INLINE_COMMENT_FALLBACK: "false"
# LLM configuration # LLM configuration
LLM__PROVIDER: CLAUDE LLM__PROVIDER: CLAUDE
LLM__META__MODEL: claude-sonnet-5-5 LLM__META__MODEL: claude-3-opus
LLM__META__REASONING__EFFORT: high
LLM__META__MAX_TOKENS: "4096" LLM__META__MAX_TOKENS: "4096"
LLM__HTTP_CLIENT__API_URL: https://api.anthropic.com LLM__HTTP_CLIENT__API_URL: https://api.anthropic.com
LLM__HTTP_CLIENT__API_TOKEN: ${{ secrets.ANTHROPIC_API_KEY }} LLM__HTTP_CLIENT__API_TOKEN: ${{ secrets.ANTHROPIC_API_KEY }}
steps: steps:
- name: Checkout repository - name: Checkout repository
uses: actions/checkout@v7 uses: actions/checkout@v4
with: with:
submodules: true submodules: true
fetch-depth: 0 fetch-depth: 0
@@ -41,11 +40,11 @@ jobs:
run: git submodule update --remote --merge run: git submodule update --remote --merge
- name: Run inline review - name: Run inline review
uses: docker://nikitafilonov/ai-review:v1.1.0 uses: docker://nikitafilonov/ai-review:v0.64.0
with: with:
args: ai-review run-inline args: ai-review run-inline
- name: Run summary review - name: Run summary review
uses: docker://nikitafilonov/ai-review:v1.1.0 uses: docker://nikitafilonov/ai-review:v0.64.0
with: with:
args: ai-review run-summary args: ai-review run-summary
+1 -1
View File
@@ -9,7 +9,7 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Checkout code - name: Checkout code
uses: actions/checkout@v7 uses: actions/checkout@v4
with: with:
fetch-depth: 0 fetch-depth: 0
- name: Install TruffleHog - name: Install TruffleHog
+1 -1
View File
@@ -4,7 +4,7 @@ terraform {
required_providers { required_providers {
azurerm = { azurerm = {
source = "hashicorp/azurerm" source = "hashicorp/azurerm"
version = "~> 5.0" version = "~> 4.0"
} }
} }
} }
@@ -4,7 +4,7 @@ terraform {
required_providers { required_providers {
azurerm = { azurerm = {
source = "hashicorp/azurerm" source = "hashicorp/azurerm"
version = "~> 5.0" version = "~> 4.0"
} }
azuread = { azuread = {
source = "hashicorp/azuread" source = "hashicorp/azuread"
+1 -1
View File
@@ -4,7 +4,7 @@ terraform {
required_providers { required_providers {
azurerm = { azurerm = {
source = "hashicorp/azurerm" source = "hashicorp/azurerm"
version = "~> 5.0" version = "~> 4.0"
} }
} }
} }
+1 -1
View File
@@ -4,7 +4,7 @@ terraform {
required_providers { required_providers {
azurerm = { azurerm = {
source = "hashicorp/azurerm" source = "hashicorp/azurerm"
version = "~> 5.0" version = "~> 4.0"
} }
random = { random = {
source = "hashicorp/random" source = "hashicorp/random"
+1 -1
View File
@@ -2,7 +2,7 @@ terraform {
required_providers { required_providers {
aws = { aws = {
source = "hashicorp/aws" source = "hashicorp/aws"
version = "~> 6.0" version = "~> 5.0"
} }
tls = { tls = {
source = "hashicorp/tls" source = "hashicorp/tls"
@@ -2,7 +2,7 @@ terraform {
required_providers { required_providers {
aws = { aws = {
source = "hashicorp/aws" source = "hashicorp/aws"
version = "~> 6.0" version = "~> 5.0"
} }
tls = { tls = {
source = "hashicorp/tls" source = "hashicorp/tls"
+1 -1
View File
@@ -2,7 +2,7 @@ terraform {
required_providers { required_providers {
aws = { aws = {
source = "hashicorp/aws" source = "hashicorp/aws"
version = "~> 6.0" version = "~> 5.0"
} }
tls = { tls = {
source = "hashicorp/tls" source = "hashicorp/tls"
+1 -1
View File
@@ -2,7 +2,7 @@ terraform {
required_providers { required_providers {
aws = { aws = {
source = "hashicorp/aws" source = "hashicorp/aws"
version = "~> 6.0" version = "~> 5.0"
} }
tls = { tls = {
source = "hashicorp/tls" source = "hashicorp/tls"
+1 -1
View File
@@ -29,7 +29,7 @@ spec:
topologyKey: kubernetes.io/hostname topologyKey: kubernetes.io/hostname
initContainers: initContainers:
- name: gitea-dump - name: gitea-dump
image: gitea/gitea:28.0.0 image: gitea/gitea:1.25.4
command: command:
- sh - sh
- -c - -c
+15 -15
View File
@@ -1,27 +1,27 @@
{ {
"$schema": "https://raw.githubusercontent.com/jetify-com/devbox/0.16.0/.schema/devbox.schema.json", "$schema": "https://raw.githubusercontent.com/jetify-com/devbox/0.16.0/.schema/devbox.schema.json",
"packages": [ "packages": [
"kubectl@1.36.3", "kubectl@1.33.2",
"kubernetes-helm@4.2.4", "kubernetes-helm@3.18.4",
"k9s@0.51.0", "k9s@0.51.0",
"kubeseal@0.38.4", "kubeseal@0.30.0",
"argocd@3.4.6", "argocd@3.4.6",
"kubecm@0.35.1", "kubecm@0.33.1",
"kubectl-tree@0.6.0", "kubectl-tree@0.6.0",
"kind@0.32.0", "kind@0.29.0",
"kustomize@5.8.1", "kustomize@5.7.0",
"kyverno@1.19.0", "kyverno@1.14.3",
"syft@1.51.0", "syft@1.29.0",
"grype@0.118.0", "grype@0.118.0",
"traefik@3.7.10", "traefik@3.6.7",
"claude-code@2.1.245", "claude-code@0.2.122",
"go@latest", "go@latest",
"dotnet-sdk@8.0.424", "dotnet-sdk@2.1.810",
"opentofu@1.12.5", "opentofu@1.11.6",
"_1password@2.30.0", "_1password@2.30.0",
"github-cli@2.23.0", "github-cli@latest",
"upcloud-cli@3.36.0", "upcloud-cli@3.29.0",
"awscli2@2.35.11" "awscli2@2.34.24"
], ],
"shell": { "shell": {
"init_hook": [ "init_hook": [
-6
View File
@@ -1469,12 +1469,6 @@ ArgoCD will sync the Keycloak config, and the registrar CronJob will pick up the
| `k8s.secret.client-id-key` | No | `client-id` | Field name for the client ID in the K8s Secret | | `k8s.secret.client-id-key` | No | `client-id` | Field name for the client ID in the K8s Secret |
| `k8s.secret.client-secret-key` | No | `client-secret` | Field name for the client secret in the K8s Secret | | `k8s.secret.client-secret-key` | No | `client-secret` | Field name for the client secret in the K8s Secret |
#### Public CLI Client (Device-Code Login)
`forte-cli` is a shared **public** client (no secret) with the RFC 8628 device-authorization grant enabled (`oauth2.device.authorization.grant.enabled: "true"`, `standardFlowEnabled: false`, `directAccessGrantsEnabled: false`). Downloaded skills and CLI tools that log in through the Auth Sidecar (forte-drop first) use it with `<PREFIX>_CLIENT_ID=forte-cli`; nothing per-tool needs to be registered in Keycloak.
It must be defined in `forte-realm.json` (this legacy path): the self-service registrar hardcodes `publicClient: false` / `standardFlowEnabled: true` and drops `attributes`, so a `client-config` Secret cannot produce a public device-code client. It carries no `k8s.secret.sync` attribute (the registrar's secret sync skips it) and is listed in the cleanup CronJob's protected clients.
### Retrieving Secrets for External Deployments ### Retrieving Secrets for External Deployments
The registrar always writes a **central copy** of every synced secret to the `secrets` namespace, in addition to the target namespace. This allows operators to retrieve client credentials for applications deployed outside this cluster: The registrar always writes a **central copy** of every synced secret to the `secrets` namespace, in addition to the target namespace. This allows operators to retrieve client credentials for applications deployed outside this cluster:
@@ -17,7 +17,7 @@ spec:
source: source:
repoURL: https://charts.jetstack.io repoURL: https://charts.jetstack.io
chart: cert-manager chart: cert-manager
targetRevision: "v1.21.2" targetRevision: "v1.14.0"
helm: helm:
values: | values: |
+1 -1
View File
@@ -17,7 +17,7 @@ spec:
sources: sources:
- repoURL: https://fluent.github.io/helm-charts - repoURL: https://fluent.github.io/helm-charts
chart: fluent-bit chart: fluent-bit
targetRevision: 0.58.3 targetRevision: 0.58.2
helm: helm:
releaseName: fluent-bit releaseName: fluent-bit
valueFiles: valueFiles:
+1 -1
View File
@@ -17,7 +17,7 @@ spec:
sources: sources:
- repoURL: https://dl.gitea.com/charts - repoURL: https://dl.gitea.com/charts
chart: actions chart: actions
targetRevision: "0.1.2" targetRevision: "0.0.5"
helm: helm:
releaseName: gitea-actions releaseName: gitea-actions
valueFiles: valueFiles:
+1 -1
View File
@@ -17,7 +17,7 @@ spec:
sources: sources:
- repoURL: https://dl.gitea.com/charts - repoURL: https://dl.gitea.com/charts
chart: gitea chart: gitea
targetRevision: "12.7.0" targetRevision: "12.6.0"
helm: helm:
releaseName: gitea releaseName: gitea
valueFiles: valueFiles:
+1 -1
View File
@@ -17,7 +17,7 @@ spec:
sources: sources:
- repoURL: https://grafana.github.io/helm-charts - repoURL: https://grafana.github.io/helm-charts
chart: grafana chart: grafana
targetRevision: "8.15.0" targetRevision: "8.0.0"
helm: helm:
releaseName: grafana releaseName: grafana
valueFiles: valueFiles:
+1 -1
View File
@@ -17,7 +17,7 @@ spec:
sources: sources:
- repoURL: https://grafana.github.io/helm-charts - repoURL: https://grafana.github.io/helm-charts
chart: loki chart: loki
targetRevision: "7.3.0" targetRevision: "7.0.0"
helm: helm:
releaseName: loki releaseName: loki
valueFiles: valueFiles:
+1 -1
View File
@@ -17,7 +17,7 @@ spec:
sources: sources:
- repoURL: https://opencost.github.io/opencost-helm-chart - repoURL: https://opencost.github.io/opencost-helm-chart
chart: opencost chart: opencost
targetRevision: "2.5.32" targetRevision: "1.42.0"
helm: helm:
releaseName: opencost releaseName: opencost
valueFiles: valueFiles:
+1 -1
View File
@@ -17,7 +17,7 @@ spec:
sources: sources:
- repoURL: https://prometheus-community.github.io/helm-charts - repoURL: https://prometheus-community.github.io/helm-charts
chart: prometheus chart: prometheus
targetRevision: "28.16.0" targetRevision: "28.9.0"
helm: helm:
releaseName: prometheus releaseName: prometheus
valueFiles: valueFiles:
@@ -24,7 +24,7 @@ spec:
sources: sources:
- repoURL: https://traefik.github.io/charts - repoURL: https://traefik.github.io/charts
chart: traefik chart: traefik
targetRevision: "28.3.0" targetRevision: "28.0.0"
helm: helm:
releaseName: traefik releaseName: traefik
valueFiles: valueFiles:
@@ -17,7 +17,7 @@ spec:
sources: sources:
- repoURL: https://guerzon.github.io/vaultwarden - repoURL: https://guerzon.github.io/vaultwarden
chart: vaultwarden chart: vaultwarden
targetRevision: "0.46.2" targetRevision: "0.36.4"
helm: helm:
releaseName: vaultwarden releaseName: vaultwarden
valueFiles: valueFiles:
+1 -30
View File
@@ -186,35 +186,6 @@ keycloakConfigCli:
} }
} }
] ]
},
{
"clientId": "forte-cli",
"name": "Forte CLI",
"description": "Shared public client for RFC 8628 device-code login from downloaded skills/CLI tools (forte-drop first) against services behind Auth Sidecar. No client secret.",
"enabled": true,
"protocol": "openid-connect",
"standardFlowEnabled": false,
"directAccessGrantsEnabled": false,
"publicClient": true,
"redirectUris": [],
"webOrigins": [],
"attributes": {
"oauth2.device.authorization.grant.enabled": "true"
},
"protocolMappers": [
{
"name": "audience-forte-drop-mcp",
"protocol": "openid-connect",
"protocolMapper": "oidc-audience-mapper",
"consentRequired": false,
"config": {
"included.custom.audience": "https://mcp.drop.forteapps.net/mcp",
"access.token.claim": "true",
"id.token.claim": "false",
"introspection.token.claim": "true"
}
}
]
} }
], ],
"browserFlow": "browser-auto-idp", "browserFlow": "browser-auto-idp",
@@ -700,7 +671,7 @@ extraDeploy:
MIN_AGE_SEC=$((MIN_AGE_DAYS * 86400)) MIN_AGE_SEC=$((MIN_AGE_DAYS * 86400))
# Hardcoded protected clients (never delete these) # Hardcoded protected clients (never delete these)
PROTECTED_JSON='["gitea","grafana","argocd","forte-cli","vaultwarden","account","account-console","admin-cli","broker","realm-management","security-admin-console"]' PROTECTED_JSON='["gitea","grafana","argocd","vaultwarden","account","account-console","admin-cli","broker","realm-management","security-admin-console"]'
echo "Fetching clients from realm '${REALM}'..." echo "Fetching clients from realm '${REALM}'..."
CLIENTS=$(curl -sf -H "Authorization: Bearer ${TOKEN}" \ CLIENTS=$(curl -sf -H "Authorization: Bearer ${TOKEN}" \