commitc5e0aa6f3cAuthor: gitea_admin <admin@forteapps.net> Date: Wed Oct 7 06:36:01 2026 +0000 chore(deps): update nikitafilonov/ai-review docker tag to v1.4.0 (#59) This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | nikitafilonov/ai-review | docker | minor | `v1.1.0` → `v1.4.0` | --- ### Configuration 📅 **Schedule**: (in timezone Europe/Oslo) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==--> --------- Co-authored-by: Renovate Bot <renovate@forteapps.net> Reviewed-on: #59 Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com> Co-authored-by: gitea_admin <admin@forteapps.net> commit7915346868Author: gitea_admin <admin@forteapps.net> Date: Sun Oct 4 21:53:01 2026 +0000 chore(deps): update gitea/gitea docker tag to v28 (#58) This PR contains the following updates: | Package | Update | Change | |---|---|---| | [gitea/gitea](https://github.com/go-gitea/gitea) | major | `1.27.3` → `28.0.0` | --- ### Release Notes <details> <summary>go-gitea/gitea (gitea/gitea)</summary> ### [`v28.0.0`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#2800---2026-09-30) [Compare Source](https://github.com/go-gitea/gitea/compare/v1.27.3...v28.0.0) - BREAKING - Fix(git)!: route Git network operations through an internal proxy and update egress settings ([#​39426](https://github.com/go-gitea/gitea/pull/39426)) - Feat(actions)!: add RUN\_RETENTION\_DAYS to delete old action runs ([#​38855](https://github.com/go-gitea/gitea/pull/38855)) - SECURITY - Fix(git): reject invalid and duplicate Git objects on push ([#​39472](https://github.com/go-gitea/gitea/pull/39472)) - Fix(git)!: route Git network operations through an internal proxy and update egress settings ([#​39426](https://github.com/go-gitea/gitea/pull/39426)) - Fix(ssh): identify presented public keys by fingerprint ([#​39423](https://github.com/go-gitea/gitea/pull/39423)) - Fix(actions): keep cancelled and unapproved fork PR runs behind the approval gate ([#​39399](https://github.com/go-gitea/gitea/pull/39399)) - Fix(deps): update golang.org/x/crypto SSH to address denial of service ([#​39219](https://github.com/go-gitea/gitea/pull/39219)) - Fix(repo): enforce repository-scoped authorization for team access, deletion, and package unlinking ([#​39063](https://github.com/go-gitea/gitea/pull/39063)) - FEATURES - Feat(actions): update actionslib, support `self:`, misc fixes ([#​39358](https://github.com/go-gitea/gitea/pull/39358)) - Feat(api): list all packages for site administrators ([#​38968](https://github.com/go-gitea/gitea/pull/38968)) - Feat: manage bot accounts from the admin UI, API and CLI ([#​38966](https://github.com/go-gitea/gitea/pull/38966)) - Feat(user): Personal access tokens can be regenerated ([#​38907](https://github.com/go-gitea/gitea/pull/38907)) - Feat(actions): support `$/` prefix in reusable workflow `uses:` ([#​38822](https://github.com/go-gitea/gitea/pull/38822)) - Feat(actions): add force-cancel workflow run API ([#​38756](https://github.com/go-gitea/gitea/pull/38756)) - Feat(licenses): support REUSE specification in licenses ([#​38720](https://github.com/go-gitea/gitea/pull/38720)) - Feat(api): add project APIs ([#​38691](https://github.com/go-gitea/gitea/pull/38691)) - Feat(webhook): fire repository event on repo rename ([#​38641](https://github.com/go-gitea/gitea/pull/38641)) - Feat: admin impersonates a user ([#​38614](https://github.com/go-gitea/gitea/pull/38614)) - Feat(actions): add build queue view ([#​38585](https://github.com/go-gitea/gitea/pull/38585)) - Feat(setting): add shared \[redis] section as default for redis-backed subsystems ([#​38550](https://github.com/go-gitea/gitea/pull/38550)) - Feat(repo): prioritize well-known READMEs and optimize discovery ([#​38532](https://github.com/go-gitea/gitea/pull/38532)) - Feat(actions): implement adaptive auto-refresh for workflow runs list ([#​38329](https://github.com/go-gitea/gitea/pull/38329)) - Feat(auth): add `disable-2fa` command ([#​38275](https://github.com/go-gitea/gitea/pull/38275)) - Feat: Add audit logging ([#​38189](https://github.com/go-gitea/gitea/pull/38189)) - Feat(repo): add quick repository switcher to repo header ([#​38188](https://github.com/go-gitea/gitea/pull/38188)) - Feat(repo): support file exclusion logic in .gitea/template in template generation ([#​38064](https://github.com/go-gitea/gitea/pull/38064)) - Feat(web): Add org removal functionality to admin user details page ([#​38013](https://github.com/go-gitea/gitea/pull/38013)) - Feat: add watch options ([#​37571](https://github.com/go-gitea/gitea/pull/37571)) - Feat: add deploy tokens ([#​37306](https://github.com/go-gitea/gitea/pull/37306)) - Feat(diff): Add search and extension filter to diff sidebar ([#​37068](https://github.com/go-gitea/gitea/pull/37068)) - Feat: Replace SSE with WebSocket for UI notifications ([#​36965](https://github.com/go-gitea/gitea/pull/36965)) - Feat(actions): Add artifact preview in Actions run view ([#​36754](https://github.com/go-gitea/gitea/pull/36754)) - Feat(packages): add support for uploading helm provenance files ([#​36695](https://github.com/go-gitea/gitea/pull/36695)) - Feat: Add support for dynamic matrix evaluation in Gitea Actions workflows ([#​36564](https://github.com/go-gitea/gitea/pull/36564)) - Feat: Add max-parallel Support for Gitea Actions ([#​36357](https://github.com/go-gitea/gitea/pull/36357)) - Feat(actions): Add Actions API endpoints for workflow run management and logs ([#​35382](https://github.com/go-gitea/gitea/pull/35382)) - Feat: Add block on pending codeowner reviews branch protection ([#​34995](https://github.com/go-gitea/gitea/pull/34995)) - ENHANCEMENTS - Enhance: allow auto-closing PRs from PRs ([#​39393](https://github.com/go-gitea/gitea/pull/39393)) - Enhance(actions): add pending job status and align job statuses with GitHub ([#​39376](https://github.com/go-gitea/gitea/pull/39376)) - Enhance(acme): add configurable ACME profile ([#​39375](https://github.com/go-gitea/gitea/pull/39375)) - Enhance(emoji): update to Unicode 17, unify and lazy-load emoji data ([#​39363](https://github.com/go-gitea/gitea/pull/39363)) - Enhance: improve issue-pattern capture groups and support both internal\&external trackers enabled ([#​39354](https://github.com/go-gitea/gitea/pull/39354)) - Enhance: update mermaid to v12 ([#​39331](https://github.com/go-gitea/gitea/pull/39331)) - Enhance(notifications): mark current notification page as read ([#​39294](https://github.com/go-gitea/gitea/pull/39294)) - Enhance: support `ETag` on streamed repository archives, support `If-None-Match: *` ([#​39289](https://github.com/go-gitea/gitea/pull/39289)) - Enhance: truncate but show long lines in diffs ([#​39279](https://github.com/go-gitea/gitea/pull/39279)) - Enhance(packages): implement npm single-version API and add per-version repository ([#​39267](https://github.com/go-gitea/gitea/pull/39267)) - Enhance: move window\.config to JSON, improve CSP format ([#​39236](https://github.com/go-gitea/gitea/pull/39236)) - Enhance: improve commit page header ([#​39229](https://github.com/go-gitea/gitea/pull/39229)) - Enhance: Improve validation errors for secrets/variables ([#​39221](https://github.com/go-gitea/gitea/pull/39221)) - Enhance(repo): check full repo name for dangerous operations ([#​39213](https://github.com/go-gitea/gitea/pull/39213)) - Enhance(web): hide attachment dropzone on preview tab in combo editor ([#​39204](https://github.com/go-gitea/gitea/pull/39204)) - Enhance(web): show attachment URL and UUID in dropzone preview ([#​39203](https://github.com/go-gitea/gitea/pull/39203)) - Enhance(actions): make workflow dispatch choice dropdown support search ([#​39154](https://github.com/go-gitea/gitea/pull/39154)) - Enhance(repo): unify diff stats on commit pages, misc diff tweaks ([#​39134](https://github.com/go-gitea/gitea/pull/39134)) - Enhance: use browser's locale to detect week's first day for the contribution map ([#​38995](https://github.com/go-gitea/gitea/pull/38995)) - Enhance(ui): forced colors mode enhancements ([#​38991](https://github.com/go-gitea/gitea/pull/38991)) - Enhance: user-friendly packages setup manual ([#​38946](https://github.com/go-gitea/gitea/pull/38946)) - Enhance: inherit team access for all units ([#​38938](https://github.com/go-gitea/gitea/pull/38938)) - Enhance(admin): show impersonation banner and keep password change with the user ([#​38924](https://github.com/go-gitea/gitea/pull/38924)) - Enhance(ui): tint toast backgrounds by level ([#​38919](https://github.com/go-gitea/gitea/pull/38919)) - Enhance(repo): add default object format setting ([#​38877](https://github.com/go-gitea/gitea/pull/38877)) - Enhance(actions): set ref\_protected in context ([#​38852](https://github.com/go-gitea/gitea/pull/38852)) - Enhance(ui): restyle toasts ([#​38842](https://github.com/go-gitea/gitea/pull/38842)) - Enhance: refine repo watching ([#​38835](https://github.com/go-gitea/gitea/pull/38835)) - Enhance: fall back to DEFAULT\_TEMPLATE.md when style-specific template is missing ([#​38803](https://github.com/go-gitea/gitea/pull/38803)) - Enhance(api): add GitHub-compatible /repos/{owner}/{repo}/commits/{ref} endpoint ([#​38770](https://github.com/go-gitea/gitea/pull/38770)) - Enhance(api): expose file mode in contents API response ([#​38713](https://github.com/go-gitea/gitea/pull/38713)) - Enhance(tls): use go's tls defaults ([#​38687](https://github.com/go-gitea/gitea/pull/38687)) - Enhance(ui): improve luminance calculations ([#​38682](https://github.com/go-gitea/gitea/pull/38682)) - Enhance(api): add `tag_filter` query parameter to release list API ([#​38681](https://github.com/go-gitea/gitea/pull/38681)) - Enhance(actions): replace `ansi_up` with first-party code ([#​38619](https://github.com/go-gitea/gitea/pull/38619)) - Enhance: keep status check list scrolled on merge box reload ([#​38597](https://github.com/go-gitea/gitea/pull/38597)) - Enhance(actions): action view enhancements ([#​38594](https://github.com/go-gitea/gitea/pull/38594)) - Enhance(ui): tweak tooltip style and misc fixes ([#​38524](https://github.com/go-gitea/gitea/pull/38524)) - Enhance: improve e-mail templates ([#​38396](https://github.com/go-gitea/gitea/pull/38396)) - Enhance(webhook): add reviewer name to MS Teams review request notifications ([#​38289](https://github.com/go-gitea/gitea/pull/38289)) - Enhance: extend <video> tag allowed attributes ([#​38279](https://github.com/go-gitea/gitea/pull/38279)) - Enhance(packages/npm): expand version metadata and support npm deprecate ([#​37890](https://github.com/go-gitea/gitea/pull/37890)) - PERFORMANCE - Perf(references): scan only the keyword window before a reference ([#​39396](https://github.com/go-gitea/gitea/pull/39396)) - Perf(frontend): enable vite module preload ([#​39332](https://github.com/go-gitea/gitea/pull/39332)) - Perf(gitdiff): optimize inline diff highlighting using cache ([#​38706](https://github.com/go-gitea/gitea/pull/38706)) - BUGFIXES - Fix(actions): preserve admitted jobs and runs in their concurrency group ([#​39461](https://github.com/go-gitea/gitea/pull/39461)) - Fix(api): commit tree SHA is the commit ID ([#​39449](https://github.com/go-gitea/gitea/pull/39449)) - Fix: PR merge ([#​39442](https://github.com/go-gitea/gitea/pull/39442)) - Fix(actions): evaluate job-level `if:` before concurrency check ([#​39437](https://github.com/go-gitea/gitea/pull/39437)) - Fix(api): allow pending-inline-comment-only reviews ([#​39433](https://github.com/go-gitea/gitea/pull/39433)) - Fix: sanitize external render command line arguments ([#​39417](https://github.com/go-gitea/gitea/pull/39417)) - Fix(LFS): recalculate repo LFSSize after gc-lfs removes orphaned data ([#​39406](https://github.com/go-gitea/gitea/pull/39406)) - Fix(indexer): index full file paths and real offsets in bleve ([#​39405](https://github.com/go-gitea/gitea/pull/39405)) - Fix(git): keep leading dashes in git grep search patterns ([#​39404](https://github.com/go-gitea/gitea/pull/39404)) - Fix: use clearer message for ldap auth failure ([#​39392](https://github.com/go-gitea/gitea/pull/39392)) - Fix(repo): commit page fails to render unsigned commits with a different committer ([#​39381](https://github.com/go-gitea/gitea/pull/39381)) - Fix: focus confirm button and use red for delete confirmations ([#​39350](https://github.com/go-gitea/gitea/pull/39350)) - Fix(migrations): preserve SHA-256 pull request commit IDs ([#​39343](https://github.com/go-gitea/gitea/pull/39343)) - Fix(ui): misc ui fixes ([#​39336](https://github.com/go-gitea/gitea/pull/39336)) - Fix(actions): use gitea's clock for actions durations ([#​39323](https://github.com/go-gitea/gitea/pull/39323)) - Fix(actions): never show negative running durations ([#​39322](https://github.com/go-gitea/gitea/pull/39322)) - Fix: package registry keypair creation race ([#​39319](https://github.com/go-gitea/gitea/pull/39319)) - Fix: add default timeout and handle errors for HaveIBeenPwned API ([#​39316](https://github.com/go-gitea/gitea/pull/39316)) - Fix(user): unify email validation for registration and settings ([#​39304](https://github.com/go-gitea/gitea/pull/39304)) - Fix(ui): use button elements for branch and tag dropdown tabs ([#​39285](https://github.com/go-gitea/gitea/pull/39285)) - Fix(auth): fix ssh and gpg key verification on windows ([#​39283](https://github.com/go-gitea/gitea/pull/39283)) - Fix(feed): use meaningful lines as comment excerpt ([#​39276](https://github.com/go-gitea/gitea/pull/39276)) - Fix(projects): allow max columns to the limit ([#​39272](https://github.com/go-gitea/gitea/pull/39272)) - Fix: pass merge commit messages to git via stdin ([#​39269](https://github.com/go-gitea/gitea/pull/39269)) - Fix(repo): surface unrelated histories on Sync Fork ([#​39258](https://github.com/go-gitea/gitea/pull/39258)) - Fix: avoid nil panic and refactor some trivial problems ([#​39251](https://github.com/go-gitea/gitea/pull/39251)) - Fix: restore missing blob file when re-publishing a package ([#​39239](https://github.com/go-gitea/gitea/pull/39239)) - Fix(automerge): validate head commit before merge ([#​39235](https://github.com/go-gitea/gitea/pull/39235)) - Fix(httplib): prevent leaking localhost:3000 in public links ([#​39217](https://github.com/go-gitea/gitea/pull/39217)) - Fix(setting): honor bare -1 for timeout settings ([#​39181](https://github.com/go-gitea/gitea/pull/39181)) - Fix: correct repo/attatchment absolute url and release layout ([#​39178](https://github.com/go-gitea/gitea/pull/39178)) - Fix(web): populate the reason for "cannot commit to branch" in web editor commit form ([#​39155](https://github.com/go-gitea/gitea/pull/39155)) - Fix(process): reap entire process group on cmd.Cancel ([#​39143](https://github.com/go-gitea/gitea/pull/39143)) - Fix: recognize linguist language aliases ([#​39135](https://github.com/go-gitea/gitea/pull/39135)) - Fix(repo): preserve transfer recipient collaboration ([#​39042](https://github.com/go-gitea/gitea/pull/39042)) - Fix(db): make paginated database reads always require "order" option ([#​39017](https://github.com/go-gitea/gitea/pull/39017)) - Fix: make local queue PopItem can be notified ([#​39011](https://github.com/go-gitea/gitea/pull/39011)) - Fix: classify git failures on stderr, restrict migration failure detail ([#​39010](https://github.com/go-gitea/gitea/pull/39010)) - Fix: allow re-requesting uncounted review approvals ([#​38988](https://github.com/go-gitea/gitea/pull/38988)) - Fix(actions): allow larger scheduled workflows ([#​38985](https://github.com/go-gitea/gitea/pull/38985)) - Fix: resolve actions commit status permission per repository ([#​38977](https://github.com/go-gitea/gitea/pull/38977)) - Fix(deps): update module golang.org/x/image to v0.45.0 \[security] ([#​38930](https://github.com/go-gitea/gitea/pull/38930)) - Fix(deps): update module golang.org/x/mod to v0.40.0 \[security] ([#​38914](https://github.com/go-gitea/gitea/pull/38914)) - Fix: dedupe issue cross-reference timeline entries ([#​38881](https://github.com/go-gitea/gitea/pull/38881)) - Fix(server): set `ReadHeaderTimeout` on HTTP servers ([#​38878](https://github.com/go-gitea/gitea/pull/38878)) - Fix(repo): avoid a repo-sized temp file for every bundle download ([#​38863](https://github.com/go-gitea/gitea/pull/38863)) - Fix(lfs): ensure lock listing paginates with a total order ([#​38850](https://github.com/go-gitea/gitea/pull/38850)) - Fix(avatar): use sha256 and inline the federated avatar lookup ([#​38843](https://github.com/go-gitea/gitea/pull/38843)) - Fix(gitdiff): render exact-limit diffs and zero-limit comments ([#​38838](https://github.com/go-gitea/gitea/pull/38838)) - Fix(deps): update dependency mermaid to v11.16.1 \[security] ([#​38813](https://github.com/go-gitea/gitea/pull/38813)) - Fix: misc fixes in pub/gpg/tests ([#​38809](https://github.com/go-gitea/gitea/pull/38809)) - Fix: git diff blob excerpt ([#​38808](https://github.com/go-gitea/gitea/pull/38808)) - Fix(packages): show error for duplicate cleanup rules [#​37820](https://github.com/go-gitea/gitea/issues/37820) ([#​38786](https://github.com/go-gitea/gitea/pull/38786)) - Fix(actions): fix runner docs link ([#​38783](https://github.com/go-gitea/gitea/pull/38783)) - Fix: git cache ([#​38763](https://github.com/go-gitea/gitea/pull/38763)) - Fix(actions): evaluate each `${{ }}` part on its own ([#​38754](https://github.com/go-gitea/gitea/pull/38754)) - Fix: don't report failed network requests as JavaScript errors ([#​38732](https://github.com/go-gitea/gitea/pull/38732)) - Fix(gitdiff): prevent index out of range panic in GetLineTypeMarker ([#​38728](https://github.com/go-gitea/gitea/pull/38728)) - Fix(api): document X-Total-Count instead of non-existent X-Total header ([#​38717](https://github.com/go-gitea/gitea/pull/38717)) - Fix(actions): dynamic matrix expansion correctness fixes ([#​38690](https://github.com/go-gitea/gitea/pull/38690)) - Fix(auth): record last sign-in on reverse proxy login ([#​38672](https://github.com/go-gitea/gitea/pull/38672)) - Fix(api): accept fully-qualified refs in contents API ([#​38650](https://github.com/go-gitea/gitea/pull/38650)) - Fix(deps): update module github.com/getkin/kin-openapi to v0.144.0 \[security] ([#​38623](https://github.com/go-gitea/gitea/pull/38623)) - Fix(deps): update dependency js-yaml to v5.2.2 \[security] ([#​38622](https://github.com/go-gitea/gitea/pull/38622)) - Fix: abort superseded issue suggestion requests ([#​38620](https://github.com/go-gitea/gitea/pull/38620)) - Fix(issue): display error toast on batch action failures instead of reloading page ([#​38593](https://github.com/go-gitea/gitea/pull/38593)) - Fix(deps): update module google.golang.org/grpc to v1.82.1 \[security] ([#​38567](https://github.com/go-gitea/gitea/pull/38567)) - Fix(deps): update module github.com/google/go-github/v88 to v89 ([#​38433](https://github.com/go-gitea/gitea/pull/38433)) - Fix(deps): update go dependencies ([#​38429](https://github.com/go-gitea/gitea/pull/38429)) - Fix(deps): update go dependencies ([#​38346](https://github.com/go-gitea/gitea/pull/38346)) - Fix(deps): update npm dependencies ([#​38342](https://github.com/go-gitea/gitea/pull/38342)) - Fix(base): correct natural sort of numbers with leading zeros ([#​38163](https://github.com/go-gitea/gitea/pull/38163)) - Fix(ui): avoid layout shifts in `overflow-menu` and repo filter ([#​37818](https://github.com/go-gitea/gitea/pull/37818)) - Fix: make auth source group sync correctly handle team removal ([#​37161](https://github.com/go-gitea/gitea/pull/37161)) - Fix(release): separate publication time from the release date ([#​36761](https://github.com/go-gitea/gitea/pull/36761)) - TESTING - Test: stop tests from writing into `~/.ssh` ([#​39348](https://github.com/go-gitea/gitea/pull/39348)) - Test(e2e): log out to switch users in pr-review test ([#​39328](https://github.com/go-gitea/gitea/pull/39328)) - Test: release fixtures loader lock before database work ([#​39263](https://github.com/go-gitea/gitea/pull/39263)) - Test: speed up tests, fix transaction bug ([#​39030](https://github.com/go-gitea/gitea/pull/39030)) - Test: run frontend unit tests in browsers ([#​38860](https://github.com/go-gitea/gitea/pull/38860)) - Test(pubsub): stop racing the Redis SUBSCRIBE ack ([#​38661](https://github.com/go-gitea/gitea/pull/38661)) - Test(e2e): add pull request merge box test, update AGENTS.md ([#​38576](https://github.com/go-gitea/gitea/pull/38576)) - Test(e2e): deterministically wait for event stream in logout propagation test ([#​38535](https://github.com/go-gitea/gitea/pull/38535)) - BUILD - Refactor: fix `go vet` errors related to composite literals ([#​39341](https://github.com/go-gitea/gitea/pull/39341)) - Build(gogit): disable gogit builds for stable releases ([#​39324](https://github.com/go-gitea/gitea/pull/39324)) - Refactor: replace jquery.are-you-sure with first-party code ([#​39233](https://github.com/go-gitea/gitea/pull/39233)) - Refactor: http request binding ([#​38971](https://github.com/go-gitea/gitea/pull/38971)) - Refactor: clean up git repo and model migration packages ([#​38564](https://github.com/go-gitea/gitea/pull/38564)) - Refactor: prepare to decouple the "model migration" package and "models" package ([#​38533](https://github.com/go-gitea/gitea/pull/38533)) - Build: fix snapcraft release ([#​38260](https://github.com/go-gitea/gitea/pull/38260)) - Build(release): use native golang toolchain for official release builds ([#​37828](https://github.com/go-gitea/gitea/pull/37828)) - DOCS - Docs(webhook): review\.type comment lists values the webhook never sends ([#​39451](https://github.com/go-gitea/gitea/pull/39451)) - Docs(api): document verification and files on the compare endpoint ([#​39440](https://github.com/go-gitea/gitea/pull/39440)) - Docs(api): name the unadopted-repository search parameter query ([#​39370](https://github.com/go-gitea/gitea/pull/39370)) - Docs: remove unused COOKIE\_USERNAME from app.example.ini ([#​39365](https://github.com/go-gitea/gitea/pull/39365)) - Docs: document NOTICE\_ON\_SUCCESS for every cron task ([#​39352](https://github.com/go-gitea/gitea/pull/39352)) - Docs: correct ALLOW\_LOCALNETWORKS description in app.example.ini ([#​39240](https://github.com/go-gitea/gitea/pull/39240)) - Docs: fix typo in README about app.ini restart ([#​39223](https://github.com/go-gitea/gitea/pull/39223)) - Docs: fix dead localization doc link in the READMEs ([#​39211](https://github.com/go-gitea/gitea/pull/39211)) - Docs: Update CHANGELOG for release 1.27.3 ([#​39170](https://github.com/go-gitea/gitea/pull/39170)) - Docs: Update CHANGELOG for version 1.27.2 ([#​38923](https://github.com/go-gitea/gitea/pull/38923)) - Docs: Update PGP key expiration date to July 23, 2027 ([#​38747](https://github.com/go-gitea/gitea/pull/38747)) - Docs(api): document 401/403 responses for user key endpoints ([#​38711](https://github.com/go-gitea/gitea/pull/38711)) - Docs: Update Changelog for release v1.27.1 ([#​38670](https://github.com/go-gitea/gitea/pull/38670)) - Docs: Update Changelog for 1.27 ([#​38440](https://github.com/go-gitea/gitea/pull/38440)) - Docs: Update Security docs ([#​38422](https://github.com/go-gitea/gitea/pull/38422)) - MISC - Refactor: make git http respond error message ([#​39390](https://github.com/go-gitea/gitea/pull/39390)) - Refactor(api): convert bot accounts through the admin user edit endpoint ([#​39355](https://github.com/go-gitea/gitea/pull/39355)) - Refactor: replace AWS SDK with a REST client for CodeCommit migration ([#​39330](https://github.com/go-gitea/gitea/pull/39330)) - Refactor: replace Azure Blob SDK with a REST client ([#​39315](https://github.com/go-gitea/gitea/pull/39315)) - Refactor: npm route handlers ([#​39275](https://github.com/go-gitea/gitea/pull/39275)) - Refactor: GetDiffShortStat and fix panic caused by inconsistent "changed file number" ([#​39248](https://github.com/go-gitea/gitea/pull/39248)) - Refactor(templates): update djlint to 1.46.0 and resolve its new findings ([#​39231](https://github.com/go-gitea/gitea/pull/39231)) - Refactor: pagination/pager ([#​39162](https://github.com/go-gitea/gitea/pull/39162)) - Refactor: share package registry error status classification ([#​39133](https://github.com/go-gitea/gitea/pull/39133)) - Refactor: drop two unmaintained dependencies, rename the byte size helpers ([#​39083](https://github.com/go-gitea/gitea/pull/39083)) - Refactor(automerge): fix error handling, populate recent automerge tasks on restart ([#​39001](https://github.com/go-gitea/gitea/pull/39001)) - Refactor: deploy key and private route handlers ([#​38999](https://github.com/go-gitea/gitea/pull/38999)) - Refactor: wiki edit form ([#​38918](https://github.com/go-gitea/gitea/pull/38918)) - Refactor: clean up form binding & validation ([#​38873](https://github.com/go-gitea/gitea/pull/38873)) - Refactor: markup render ([#​38864](https://github.com/go-gitea/gitea/pull/38864)) - Refactor: api token scope check ([#​38862](https://github.com/go-gitea/gitea/pull/38862)) - Refactor: replace `gliderlabs/ssh` with `golang.org/x/crypto/ssh` ([#​38837](https://github.com/go-gitea/gitea/pull/38837)) - Refactor: form binding validation ([#​38832](https://github.com/go-gitea/gitea/pull/38832)) - Refactor: prepare vue components for vapor mode ([#​38798](https://github.com/go-gitea/gitea/pull/38798)) - Refactor: use the shared workflow model from actionslib ([#​38768](https://github.com/go-gitea/gitea/pull/38768)) - Refactor(modelmigration): thread context through migration functions ([#​38758](https://github.com/go-gitea/gitea/pull/38758)) - Refactor: migrate remaining Vue components to `<script setup>` ([#​38752](https://github.com/go-gitea/gitea/pull/38752)) - Refactor: introduce trString for frontend ([#​38741](https://github.com/go-gitea/gitea/pull/38741)) - Refactor(diff): drive diff DOM init from the global selector observer ([#​38740](https://github.com/go-gitea/gitea/pull/38740)) - Refactor(git): clarify GetBranch behavior to make it only gets an existing branch ([#​38662](https://github.com/go-gitea/gitea/pull/38662)) - Refactor: replace debounce/throttle deps with first-party code ([#​38610](https://github.com/go-gitea/gitea/pull/38610)) - Refactor: hide git repo path details from more packages ([#​38601](https://github.com/go-gitea/gitea/pull/38601)) - Refactor: retry file remove/rename when a file is busy and clean up os detection ([#​38588](https://github.com/go-gitea/gitea/pull/38588)) - Perf(emoji): optimize FindEmojiSubmatchIndex using slice-based Trie ([#​38573](https://github.com/go-gitea/gitea/pull/38573)) - Refactor: implement mcaptcha client and add comments/tests ([#​38561](https://github.com/go-gitea/gitea/pull/38561)) - Refactor: use WithRepo instead of WithDir for most git operations, clean up model migrations ([#​38555](https://github.com/go-gitea/gitea/pull/38555)) - Refactor: remove Path field from git.Repository ([#​38552](https://github.com/go-gitea/gitea/pull/38552)) - Refactor: make git package handle all git operations ([#​38543](https://github.com/go-gitea/gitea/pull/38543)) - Refactor: remove unnecessary git command wrapper functions ([#​38531](https://github.com/go-gitea/gitea/pull/38531)) - Refactor: git repo and relative path handling ([#​38522](https://github.com/go-gitea/gitea/pull/38522)) - Refactor: clean up fragile diff render templates, use backend typed structs ([#​38517](https://github.com/go-gitea/gitea/pull/38517)) - Refactor: correct git repo design and fix some legacy problems ([#​38512](https://github.com/go-gitea/gitea/pull/38512)) - Refactor: fix legacy problems in cmd/serv.go ([#​38505](https://github.com/go-gitea/gitea/pull/38505)) - Refactor: remove Ctx field from git.Repository ([#​38500](https://github.com/go-gitea/gitea/pull/38500)) - Refactor: decouple git.Repository(ctx) from git.Commit & git.Tree ([#​38464](https://github.com/go-gitea/gitea/pull/38464)) - Refactor: introduce ActivePageTimer to help to do partial page refresh ([#​38372](https://github.com/go-gitea/gitea/pull/38372)) </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Oslo) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==--> --------- Co-authored-by: Renovate Bot <renovate@forteapps.net> Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/58 Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com> Co-authored-by: gitea_admin <admin@forteapps.net> commit840c354ea3Author: gitea_admin <admin@forteapps.net> Date: Sat Oct 3 18:55:31 2026 +0000 chore(deps): update terraform azurerm to v5 (#55) This PR contains the following updates: | Package | Type | Update | Change | Pending | |---|---|---|---|---| | [azurerm](https://registry.terraform.io/providers/hashicorp/azurerm) ([source](https://github.com/hashicorp/terraform-provider-azurerm)) | required_provider | major | `~> 4.0` → `~> 5.0` | `5.8.0` | --- ### Release Notes <details> <summary>hashicorp/terraform-provider-azurerm (azurerm)</summary> ### [`v5.7.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#570-September-24-2026) [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.6.0...v5.7.0) FEATURES: - **New List Resource**: `azurerm_private_dns_resolver_forwarding_rule` ([#​33313](https://github.com/hashicorp/terraform-provider-azurerm/issues/33313)) - **New List Resource**: `azurerm_windows_virtual_machine` ([#​33332](https://github.com/hashicorp/terraform-provider-azurerm/issues/33332)) ENHANCEMENTS: - dependencies: `go-azure-sdk` - update to `v0.20260917.1142820` ([#​33495](https://github.com/hashicorp/terraform-provider-azurerm/issues/33495)) - dependencies: `network` - update API version to `2025-07-01` ([#​33441](https://github.com/hashicorp/terraform-provider-azurerm/issues/33441)) - Data Source: `azurerm_linux_web_app` - export the `virtual_network_image_pull_enabled` property ([#​33316](https://github.com/hashicorp/terraform-provider-azurerm/issues/33316)) - Data Source: `azurerm_network_interface` - export the `auxiliary_mode`, `auxiliary_sku`, `edge_zone`, and `internal_domain_name_suffix` properties ([#​33204](https://github.com/hashicorp/terraform-provider-azurerm/issues/33204)) - Data Source: `azurerm_public_ip` - export the `domain_name_label_scope`, `edge_zone`, `public_ip_prefix_id`, and `sku_tier` properties ([#​33193](https://github.com/hashicorp/terraform-provider-azurerm/issues/33193)) - Data Source: `azurerm_service_plan` - export the `premium_plan_auto_scale_enabled` property ([#​33300](https://github.com/hashicorp/terraform-provider-azurerm/issues/33300)) - Data Source: `azurerm_storage_blob` - export the `cache_control` and `source_uri` properties ([#​33318](https://github.com/hashicorp/terraform-provider-azurerm/issues/33318)) - Data Source: `azurerm_traffic_manager_profile` - export the `maximum_return` property ([#​33346](https://github.com/hashicorp/terraform-provider-azurerm/issues/33346)) - Data Source: `azurerm_web_pubsub` - export the `live_trace` and `identity` properties ([#​33373](https://github.com/hashicorp/terraform-provider-azurerm/issues/33373)) - `azurerm_kubernetes_cluster_node_pool` - add `Windows2025` as a valid value for the `os_sku` property ([#​33463](https://github.com/hashicorp/terraform-provider-azurerm/issues/33463)) - `azurerm_kubernetes_cluster` - add `Windows2025` as a valid value for the `os_sku` property ([#​33463](https://github.com/hashicorp/terraform-provider-azurerm/issues/33463)) BUG FIXES: - Data Source: `azurerm_kubernetes_cluster` - fix a panic caused by a nil pointer dereference while flattening `agent_pool_profile` ([#​33488](https://github.com/hashicorp/terraform-provider-azurerm/issues/33488)) - `azurerm_postgresql_flexible_server` - fix `cluster` block read for replica `create_mode` ([#​33082](https://github.com/hashicorp/terraform-provider-azurerm/issues/33082)) ### [`v5.6.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#560-September-17-2026) [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.5.0...v5.6.0) FEATURES: - **New List Resource**: `azurerm_batch_account` ([#​33252](https://github.com/hashicorp/terraform-provider-azurerm/issues/33252)) - **New List Resource**: `azurerm_cdn_frontdoor_origin_group` ([#​33334](https://github.com/hashicorp/terraform-provider-azurerm/issues/33334)) - **New Resource**: `azurerm_storage_discovery_workspace` ([#​31479](https://github.com/hashicorp/terraform-provider-azurerm/issues/31479)) ENHANCEMENTS: - dependencies: `containers` - update API version to `2026-05-01` ([#​32688](https://github.com/hashicorp/terraform-provider-azurerm/issues/32688)) - dependencies: `go-azure-sdk` - update to `v0.20260910.1141000` ([#​33413](https://github.com/hashicorp/terraform-provider-azurerm/issues/33413)) - dependencies: `qumulo` - update API version to `2026-04-16` ([#​33421](https://github.com/hashicorp/terraform-provider-azurerm/issues/33421)) - dependencies: `servicebus` - update to API version `2026-01-01` ([#​33450](https://github.com/hashicorp/terraform-provider-azurerm/issues/33450)) - `azurerm_iothub_device_update_instance` - add support for the `connection_string_wo` and `connection_string_wo_version` properties ([#​33448](https://github.com/hashicorp/terraform-provider-azurerm/issues/33448)) - `azurerm_linux_function_app` - add support for the `end_to_end_tls_encryption_enabled` property ([#​31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135)) - `azurerm_linux_function_app_slot` - add support for the `end_to_end_tls_encryption_enabled` property ([#​31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135)) - `azurerm_linux_web_app` - add support for the `end_to_end_tls_encryption_enabled` property ([#​31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135)) - `azurerm_linux_web_app_slot` - add support for the `end_to_end_tls_encryption_enabled` property ([#​31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135)) - `azurerm_mongo_cluster` - Support new property `network_bypass_mode` ([#​33168](https://github.com/hashicorp/terraform-provider-azurerm/issues/33168)) - `azurerm_servicebus_namespace` - add support for the `1.3` value to the `minimum_tls_version` property ([#​33457](https://github.com/hashicorp/terraform-provider-azurerm/issues/33457)) - `azurerm_windows_function_app` - add support for the `end_to_end_tls_encryption_enabled` property ([#​31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135)) - `azurerm_windows_function_app_slot` - add support for the `end_to_end_tls_encryption_enabled` property ([#​31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135)) - `azurerm_windows_web_app` - add support for the `end_to_end_tls_encryption_enabled` property ([#​31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135)) - `azurerm_windows_web_app_slot` - add support for the `end_to_end_tls_encryption_enabled` property ([#​31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135)) BUG FIXES: - `azurerm_site_recovery_replicated_vm` - select `managed_disk` properties compared case insensitive ([#​33424](https://github.com/hashicorp/terraform-provider-azurerm/issues/33424)) ### [`v5.5.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#550-September-10-2026) [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.4.0...v5.5.0) FEATURES: - **New List Resource**: `azurerm_analysis_services_server` ([#​33250](https://github.com/hashicorp/terraform-provider-azurerm/issues/33250)) - **New List Resource**: `azurerm_application_insights_workbook` ([#​33244](https://github.com/hashicorp/terraform-provider-azurerm/issues/33244)) - **New List Resource**: `azurerm_attestation_provider` ([#​33251](https://github.com/hashicorp/terraform-provider-azurerm/issues/33251)) - **New List Resource**: `azurerm_cdn_frontdoor_origin` ([#​33307](https://github.com/hashicorp/terraform-provider-azurerm/issues/33307)) - **New List Resource**: `azurerm_eventhub_consumer_group` ([#​33335](https://github.com/hashicorp/terraform-provider-azurerm/issues/33335)) - **New List Resource**: `azurerm_linux_virtual_machine` ([#​33333](https://github.com/hashicorp/terraform-provider-azurerm/issues/33333)) - **New List Resource**: `azurerm_virtual_hub_connection` ([#​33311](https://github.com/hashicorp/terraform-provider-azurerm/issues/33311)) ENHANCEMENTS: - dependencies: `go-azure-sdk` - update to `v0.20260901.1173158` ([#​33274](https://github.com/hashicorp/terraform-provider-azurerm/issues/33274)) - `azurerm_private_endpoint` - lock on private service connection resource ids ([#​33298](https://github.com/hashicorp/terraform-provider-azurerm/issues/33298)) - `azurerm_storage_account` - add support for the `public_network_access` property ([#​33292](https://github.com/hashicorp/terraform-provider-azurerm/issues/33292)) BUG FIXES: - `azurerm_resource_group` - the `managed_by` property now forces recreation when changed as the API does not support changing this value ([#​33339](https://github.com/hashicorp/terraform-provider-azurerm/issues/33339)) - `go-azure-sdk` - `Delete` operations now poll on asynchronous operation URLs if returned by the API instead of only checking for a `404` on the resource URL, ensuring deletion errors are reported to the user ([#​33274](https://github.com/hashicorp/terraform-provider-azurerm/issues/33274)) ### [`v5.4.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#540-September-03-2026) [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.3.0...v5.4.0) FEATURES: - **New List Resource**: `azurerm_application_insights_standard_web_test` ([#​33243](https://github.com/hashicorp/terraform-provider-azurerm/issues/33243)) - **New List Resource**: `azurerm_application_insights_workbook_template` ([#​33245](https://github.com/hashicorp/terraform-provider-azurerm/issues/33245)) - **New List Resource**: `azurerm_arc_kubernetes_provisioned_cluster` ([#​33247](https://github.com/hashicorp/terraform-provider-azurerm/issues/33247)) - **New List Resource**: `azurerm_availability_set` ([#​33241](https://github.com/hashicorp/terraform-provider-azurerm/issues/33241)) - **New List Resource**: `azurerm_batch_application` ([#​33254](https://github.com/hashicorp/terraform-provider-azurerm/issues/33254)) - **New List Resource**: `azurerm_dedicated_host_group` ([#​33257](https://github.com/hashicorp/terraform-provider-azurerm/issues/33257)) - **New List Resource**: `azurerm_log_analytics_workspace` ([#​33259](https://github.com/hashicorp/terraform-provider-azurerm/issues/33259)) ENHANCEMENTS: - dependencies: `azurerm_mongo_cluster` - update API version to `2026-06-01` ([#​33195](https://github.com/hashicorp/terraform-provider-azurerm/issues/33195)) - dependencies: `azurerm_mongo_cluster_firewall_rule` - update API version to `2026-06-01` ([#​33195](https://github.com/hashicorp/terraform-provider-azurerm/issues/33195)) - dependencies: `azurerm_mongo_cluster_user` - update API version to `2026-06-01` ([#​33195](https://github.com/hashicorp/terraform-provider-azurerm/issues/33195)) - dependencies: `netapp` - update API version to `2026-05-01` ([#​33215](https://github.com/hashicorp/terraform-provider-azurerm/issues/33215)) - Data Source: `azurerm_api_management_workspace` - export the `description` property ([#​33205](https://github.com/hashicorp/terraform-provider-azurerm/issues/33205)) - Data Source: `azurerm_attestation_provider` - export the `sev_snp_policy_base64`, `open_enclave_policy_base64`, `sgx_enclave_policy_base64`, and `tpm_policy_base64` properties ([#​33125](https://github.com/hashicorp/terraform-provider-azurerm/issues/33125)) - Data Source: `azurerm_automation_account` - export the `dsc_primary_access_key`, `dsc_server_endpoint`, `dsc_secondary_access_key`, `public_network_access_enabled`, `sku_name`, and `tags` properties ([#​33135](https://github.com/hashicorp/terraform-provider-azurerm/issues/33135)) - Data Source: `azurerm_automation_account` - export the `encryption` block ([#​33135](https://github.com/hashicorp/terraform-provider-azurerm/issues/33135)) - Data Source: `azurerm_ip_group` - export the `firewall_ids` and `firewall_policy_ids` properties ([#​33190](https://github.com/hashicorp/terraform-provider-azurerm/issues/33190)) - Data Source: `azurerm_private_link_service` - export the `fqdns` and `destination_ip_address` properties ([#​33191](https://github.com/hashicorp/terraform-provider-azurerm/issues/33191)) - `azurerm_key_vault_managed_hardware_security_module_key` - allow the `key_size` property to be set when `key_type` is `oct-HSM` ([#​32690](https://github.com/hashicorp/terraform-provider-azurerm/issues/32690)) - `azurerm_lb_probe ` - add support for the `no_healthy_backends_behavior` property ([#​32645](https://github.com/hashicorp/terraform-provider-azurerm/issues/32645)) - `azurerm_linux_virtual_machine_scale_set` - add support for the `NvmeDisk` value to the `os_disk.diff_disk_settings.placement` property ([#​30328](https://github.com/hashicorp/terraform-provider-azurerm/issues/30328)) - `azurerm_linux_web_app` - add support for the `8.5` value in the `site_config.application_stack.php_version` property ([#​33308](https://github.com/hashicorp/terraform-provider-azurerm/issues/33308)) - `azurerm_linux_web_app_slot` - add support for the `8.5` value in the `site_config.application_stack.php_version` property ([#​33308](https://github.com/hashicorp/terraform-provider-azurerm/issues/33308)) - `azurerm_netapp_volume` - support for the `breakthrough_mode_enabled` property ([#​33215](https://github.com/hashicorp/terraform-provider-azurerm/issues/33215)) - `azurerm_postgresql_flexible_server` - add support for the `storage_type`, `storage_iops`, and `storage_throughput` properties which allows choice of the new "Premium V2 LRS" storage type ([#​32121](https://github.com/hashicorp/terraform-provider-azurerm/issues/32121)) - `azurerm_storage_account` - add support for an in-place migration of `account_replication_type` between matching non-zonal and zonal types instead of resource recreation ([#​33236](https://github.com/hashicorp/terraform-provider-azurerm/issues/33236)) - `azurerm_storage_table` - add support for AAD authentication ([#​32997](https://github.com/hashicorp/terraform-provider-azurerm/issues/32997)) - `azurerm_synapse_spark_pool` - migrate to `go-azure-sdk` ([#​33258](https://github.com/hashicorp/terraform-provider-azurerm/issues/33258)) - `azurerm_windows_virtual_machine_scale_set` - add support for the `NvmeDisk` value to the `os_disk.diff_disk_settings.placement` property ([#​30328](https://github.com/hashicorp/terraform-provider-azurerm/issues/30328)) BUG FIXES: - `azurerm_synapse_spark_pool` - fix `lifecycle.ignore_changes` support ([#​33258](https://github.com/hashicorp/terraform-provider-azurerm/issues/33258)) ### [`v5.3.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#530-August-27-2026) [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.2.0...v5.3.0) FEATURES: - **New Data Source**: `azurerm_playwright_workspace` ([#​31954](https://github.com/hashicorp/terraform-provider-azurerm/issues/31954)) - **New List Resource**: `azurerm_cognitive_deployment` ([#​33149](https://github.com/hashicorp/terraform-provider-azurerm/issues/33149)) - **New List Resource**: `azurerm_playwright_workspace` ([#​31954](https://github.com/hashicorp/terraform-provider-azurerm/issues/31954)) - **New Resource**: `azurerm_playwright_workspace` ([#​31954](https://github.com/hashicorp/terraform-provider-azurerm/issues/31954)) ENHANCEMENTS: - dependencies: `go-azure-helpers` - update version to `0.82.0` ([#​33142](https://github.com/hashicorp/terraform-provider-azurerm/issues/33142)) - dependencies: `sql` - update API version to `2025-01-01` ([#​33201](https://github.com/hashicorp/terraform-provider-azurerm/issues/33201)) - Data Source: `azurerm_role_definition` - export the `role_definition_resource_id` property ([#​33126](https://github.com/hashicorp/terraform-provider-azurerm/issues/33126)) - `azurerm_cognitive_deployment` - add Resource Identity support ([#​33149](https://github.com/hashicorp/terraform-provider-azurerm/issues/33149)) - `azurerm_federated_identity_credential` - add additional polling to account for Azure's eventual consistency ([#​32935](https://github.com/hashicorp/terraform-provider-azurerm/issues/32935)) - `azurerm_kubernetes_cluster` - add support for the `oms_agent.retina_flow_logs_enabled` property ([#​33222](https://github.com/hashicorp/terraform-provider-azurerm/issues/33222)) - `azurerm_managed_application` - add support for the `identity` block ([#​30725](https://github.com/hashicorp/terraform-provider-azurerm/issues/30725)) - `azurerm_private_endpoint` - extend validation for the `private_service_connection.subresource_names` property to allow names containing spaces ([#​32887](https://github.com/hashicorp/terraform-provider-azurerm/issues/32887)) - `azurerm_search_service` - allow in-place downgrades of the `sku` property between Basic and Standard tiers ([#​33069](https://github.com/hashicorp/terraform-provider-azurerm/issues/33069)) - `azurerm_site_recovery_replicated_vm` - add update support to the `managed_disk` block without requiring resource recreation ([#​33140](https://github.com/hashicorp/terraform-provider-azurerm/issues/33140)) - `azurerm_user_assigned_identity` - add additional polling to account for Azure's eventual consistency ([#​33142](https://github.com/hashicorp/terraform-provider-azurerm/issues/33142)) BUG FIXES: - Data Source: `azurerm_app_configuration_key` - now correctly sets `tags` into state ([#​33182](https://github.com/hashicorp/terraform-provider-azurerm/issues/33182)) - `azurerm_eventhub_namespace` - prevent `network_rulesets.x.default_action` being set to `Deny` if `ip_rule` or `virtual_network_rule` is not specified ([#​33216](https://github.com/hashicorp/terraform-provider-azurerm/issues/33216)) ### [`v5.2.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#520-August-20-2026) [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.1.0...v5.2.0) FEATURES: - **New List Resource**: `azurerm_user_assigned_identity` ([#​32667](https://github.com/hashicorp/terraform-provider-azurerm/issues/32667)) ENHANCEMENTS: - dependencies: `go` - update to `1.26.6` ([#​33141](https://github.com/hashicorp/terraform-provider-azurerm/issues/33141)) - dependencies: `go-azure-sdk` - update to `v0.20260811.1225050` ([#​33079](https://github.com/hashicorp/terraform-provider-azurerm/issues/33079)) - `azurerm_cdn_frontdoor_batch_rule_set` - allow `/` as an input to `rule.conditions.request_path.values` ([#​33023](https://github.com/hashicorp/terraform-provider-azurerm/issues/33023)) - `azurerm_databricks_workspace` - remove a redundant key vault existence check ([#​33136](https://github.com/hashicorp/terraform-provider-azurerm/issues/33136)) - `azurerm_databricks_workspace_root_dbfs_customer_managed_key` - remove a redundant key vault existence check ([#​33136](https://github.com/hashicorp/terraform-provider-azurerm/issues/33136)) - `azurerm_logic_app_standard` - add support for `v10.0` to `site_config.dotnet_framework_version` ([#​33116](https://github.com/hashicorp/terraform-provider-azurerm/issues/33116)) - `azurerm_mongo_cluster` - `administrator_password` is no longer required when `create_mode` is `Default` to support Entra ID-only authentication ([#​32092](https://github.com/hashicorp/terraform-provider-azurerm/issues/32092)) - `azurerm_redhat_openshift_cluster` - add support for the `network_profile.load_balancer_profile` block ([#​32473](https://github.com/hashicorp/terraform-provider-azurerm/issues/32473)) - `azurerm_redhat_openshift_cluster` - add support for the `platform_workload_identity_profile` block ([#​32473](https://github.com/hashicorp/terraform-provider-azurerm/issues/32473)) - `azurerm_role_assignment` - the `condition`, `condition_version`, and `description` properties can now be updated in-place ([#​32714](https://github.com/hashicorp/terraform-provider-azurerm/issues/32714)) - `azurerm_snapshot` - `create_option` now supports `CopyStart` ([#​32834](https://github.com/hashicorp/terraform-provider-azurerm/issues/32834)) BUG FIXES: - `azurerm_cognitive_account_project` - added create/update/delete lock on parent AccountID to make sure operations on parent account are processed in serial (required by Cognitive service) ([#​33151](https://github.com/hashicorp/terraform-provider-azurerm/issues/33151)) - `azurerm_databricks_workspace` - fix a persistent diff on removal of `managed_disk_cmk_key_vault_key_id` or `managed_services_cmk_key_vault_key_id` ([#​33136](https://github.com/hashicorp/terraform-provider-azurerm/issues/33136)) - `azurerm_oracle_exadata_infrastructure` - fix an issue that prevented users from deploying with no `zones` set ([#​33011](https://github.com/hashicorp/terraform-provider-azurerm/issues/33011)) ### [`v5.1.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#510-August-13-2026) [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.0.1...v5.1.0) ENHANCEMENTS: - dependencies: `azurerm_linux_virtual_machine_scale_set` - update to API version `2025-04-01` ([#​31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586)) - dependencies: `azurerm_orchestrated_virtual_machine_scale_set` - update to API version `2025-04-01` ([#​31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586)) - dependencies: `azurerm_virtual_machine_scale_set` - update to API version `2025-04-01` ([#​31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586)) - dependencies: `azurerm_virtual_machine_scale_set_extension` - update to API version `2025-04-01` ([#​31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586)) - dependencies: `azurerm_windows_virtual_machine_scale_set` - update to API version `2025-04-01` ([#​31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586)) - dependencies: `codesigning` - update to API version `2025-10-13` ([#​31714](https://github.com/hashicorp/terraform-provider-azurerm/issues/31714)) - `azurerm_linux_virtual_machine` - `encryption_at_host_enabled` can now be set to `true` when `os_disk.security_encryption_type` is set to `DiskWithVMGuestState` ([#​32885](https://github.com/hashicorp/terraform-provider-azurerm/issues/32885)) - `azurerm_linux_virtual_machine_scale_set` - `encryption_at_host_enabled` can now be set to `true` when `os_disk.security_encryption_type` is set to `DiskWithVMGuestState` ([#​32885](https://github.com/hashicorp/terraform-provider-azurerm/issues/32885)) - `azurerm_managed_devops_pool` - add support for the `CreatorOnly` value to `azure_devops_organization.permission.kind` property ([#​32753](https://github.com/hashicorp/terraform-provider-azurerm/issues/32753)) - `azurerm_windows_virtual_machine` - `encryption_at_host_enabled` can now be set to `true` when `os_disk.security_encryption_type` is set to `DiskWithVMGuestState` ([#​32885](https://github.com/hashicorp/terraform-provider-azurerm/issues/32885)) - `azurerm_windows_virtual_machine_scale_set` - `encryption_at_host_enabled` can now be set to `true` when `os_disk.security_encryption_type` is set to `DiskWithVMGuestState` ([#​32885](https://github.com/hashicorp/terraform-provider-azurerm/issues/32885)) BUG FIXES: - `azurerm_cdn_frontdoor_batch_ruleset` - parse `rule.actions.route_configuration_override.origin_group.cdn_frontdoor_origin_group_id` case-insensitively and normalize the resulting value to prevent diffs ([#​32980](https://github.com/hashicorp/terraform-provider-azurerm/issues/32980)) - `azurerm_cdn_frontdoor_route` - parse `cdn_frontdoor_origin_group_id` case-insensitively and normalize the resulting value to prevent diffs ([#​32980](https://github.com/hashicorp/terraform-provider-azurerm/issues/32980)) - `azurerm_cdn_frontdoor_secret` - fix an incorrect type assertion ([#​32982](https://github.com/hashicorp/terraform-provider-azurerm/issues/32982)) - `azurerm_dev_center_project` - parse `dev_center_id` case-insensitively and normalize the resulting value to prevent diffs ([#​32798](https://github.com/hashicorp/terraform-provider-azurerm/issues/32798)) - `azurerm_eventhub` - now prevents the `status` property from being set to `SendDisabled` on create ([#​33071](https://github.com/hashicorp/terraform-provider-azurerm/issues/33071)) - `azurerm_storage_container` - add a state migration for the `id` field, fixing the upgrade path from 4.x to 5.x ([#​32978](https://github.com/hashicorp/terraform-provider-azurerm/issues/32978)) - `azurerm_storage_queue` - extend state migration to handle a malformed `resource_manager_id` ([#​32979](https://github.com/hashicorp/terraform-provider-azurerm/issues/32979)) - `azurerm_storage_share` - add a state migration for the `id` field, fixing the upgrade path from 4.x to 5.x ([#​33075](https://github.com/hashicorp/terraform-provider-azurerm/issues/33075)) ### [`v5.0.1`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#501-July-30-2026) [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.0.0...v5.0.1) NOTES: In addition to the bug fixes below, a number of resource documentation pages and the 5.0-upgrade-guide have been updated. BUG FIXES: - `azurerm_cdn_frontdoor_origin` - fix a regression that prevented valid values as input to `private_link.private_link_target_id` ([#​32912](https://github.com/hashicorp/terraform-provider-azurerm/issues/32912)) - `azurerm_storage_queue` - add a state migration for the `id` field, fixing the upgrade path from 4.x to 5.x ([#​32914](https://github.com/hashicorp/terraform-provider-azurerm/issues/32914)) - `azurerm_storage_table_entity` - add a state migration for the `storage_table_id` field, fixing the upgrade path from 4.x to 5.x ([#​32929](https://github.com/hashicorp/terraform-provider-azurerm/issues/32929)) ### [`v5.0.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#500-July-27-2026) [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v4.81.0...v5.0.0) NOTES: - **Major Version**: Version 5.0 of the Azure Provider is a major version - some behaviours have changed and some deprecated fields/resources have been removed - please refer to [the 5.0 upgrade guide for more information](https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/guides/5.0-upgrade-guide). - When upgrading to v5.0 of the AzureRM Provider, we recommend upgrading to the latest version of Terraform Core ([which can be found here](https://developer.hashicorp.com/terraform/install)). FEATURES: - **New Action**: `azurerm_web_app_set_slot_distribution` ([#​32364](https://github.com/hashicorp/terraform-provider-azurerm/issues/32364)) - **New Datasource** adds `azurerm_kubernetes_automatic_cluster_datasource` ([#​32881](https://github.com/hashicorp/terraform-provider-azurerm/issues/32881)) ENHANCEMENTS: - dependencies: `grpc` update to `1.82.1` ([#​32852](https://github.com/hashicorp/terraform-provider-azurerm/issues/32852)) - dependencies: `loadbalancers` - update to API version `2025-01-01` ([#​32644](https://github.com/hashicorp/terraform-provider-azurerm/issues/32644)) - `azurerm_cognitive_account_rai_policy` - the `content_filter.severity_threshold` property is now optional ([#​32100](https://github.com/hashicorp/terraform-provider-azurerm/issues/32100)) - `azurerm_container_registry` - the `trust_policy_enabled` property has been deprecated and removed from the provider ([#​32752](https://github.com/hashicorp/terraform-provider-azurerm/issues/32752)) - `azurerm_dashboard_grafana` - the `11` value for the `grafana_major_version` property has been deprecated and the property now supports `13` ([#​32777](https://github.com/hashicorp/terraform-provider-azurerm/issues/32777)) - `azurerm_log_analytics_workspace` - add support for the `internet_ingestion_access_type` and `internet_query_access_type` properties ([#​32562](https://github.com/hashicorp/terraform-provider-azurerm/issues/32562)) - `azurerm_subnet` - add support for the `network_security_group_id_wo` and `network_security_group_id_wo_version` properties ([#​32847](https://github.com/hashicorp/terraform-provider-azurerm/issues/32847)) - `azurerm_subnet` - add support for the `route_table_id_wo` and `route_table_id_wo_version` properties ([#​32847](https://github.com/hashicorp/terraform-provider-azurerm/issues/32847)) - `azurerm_subnet` - export the `network_security_group_id` property ([#​32847](https://github.com/hashicorp/terraform-provider-azurerm/issues/32847)) - `azurerm_subnet` - export the `route_table_id` property ([#​32847](https://github.com/hashicorp/terraform-provider-azurerm/issues/32847)) - `azurerm_windows_web_app` - add support for `~24` to `site_config.application_stack.node_version` ([#​32840](https://github.com/hashicorp/terraform-provider-azurerm/issues/32840)) - `azurerm_windows_web_app_slot` - add support for `~24` to `site_config.application_stack.node_version` ([#​32840](https://github.com/hashicorp/terraform-provider-azurerm/issues/32840)) - `cdn` - migrate to `go-azure-sdk` ([#​32849](https://github.com/hashicorp/terraform-provider-azurerm/issues/32849)) - `sentinel` - migrate to `go-azure-sdk` ([#​32759](https://github.com/hashicorp/terraform-provider-azurerm/issues/32759)) </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Oslo) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==--> --------- Co-authored-by: Renovate Bot <renovate@forteapps.net> Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/55 Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com> Co-authored-by: gitea_admin <admin@forteapps.net> commit0f0082d54dAuthor: gitea_admin <admin@forteapps.net> Date: Sat Oct 3 18:55:02 2026 +0000 chore(deps): update helm release fluent-bit to v0.58.3 (#57) This PR contains the following updates: | Package | Update | Change | |---|---|---| | [fluent-bit](https://fluentbit.io/) ([source](https://github.com/fluent/helm-charts)) | patch | `0.58.2` → `0.58.3` | --- ### Release Notes <details> <summary>fluent/helm-charts (fluent-bit)</summary> ### [`v0.58.3`](https://github.com/fluent/helm-charts/releases/tag/fluent-bit-0.58.3) [Compare Source](https://github.com/fluent/helm-charts/compare/fluent-bit-0.58.2...fluent-bit-0.58.3) ##### Changed - Update *Fluent Bit* OCI image to [v5.1.3](https://github.com/fluent/fluent-bit/releases/tag/v5.1.3). ([#​759](https://github.com/fluent/helm-charts/pull/759)) [@​stevehipwell](https://github.com/stevehipwell) </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Oslo) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==--> --------- Co-authored-by: Renovate Bot <renovate@forteapps.net> Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/57 Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com> Co-authored-by: gitea_admin <admin@forteapps.net> commit4a4b8e3540Author: Jørgen Stensrud <jorgen.stensrud@fortedigital.com> Date: Thu Oct 1 11:25:34 2026 +0000 feat(keycloak): forte-cli device-code client + forte-drop-mcp audience mapper (#44) Adds the shared public forte-cli client (RFC 8628 device-code only) to the forte realm, with an oidc-audience-mapper that puts https://mcp.drop.forteapps.net/mcp into aud so the forte-drop-mcp sidecar accepts its tokens. Supersedes #26. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> commit60b8fa657aAuthor: gitea_admin <admin@forteapps.net> Date: Thu Oct 1 09:40:57 2026 +0000 chore(deps): update nikitafilonov/ai-review docker tag to v1 (#53) This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | nikitafilonov/ai-review | docker | major | `v0.77.0` → `v1.1.0` | --- ### Configuration 📅 **Schedule**: (in timezone Europe/Oslo) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==--> --------- Co-authored-by: Renovate Bot <renovate@forteapps.net> Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/53 Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com> Co-authored-by: gitea_admin <admin@forteapps.net> commitc940259545Author: gitea_admin <admin@forteapps.net> Date: Wed Sep 30 08:36:32 2026 +0000 chore(deps): update helm release opencost to v2 (#50) This PR contains the following updates: | Package | Update | Change | |---|---|---| | [opencost](https://github.com/opencost/opencost-helm-chart) | major | `1.43.2` → `2.5.32` | --- ### Release Notes <details> <summary>opencost/opencost-helm-chart (opencost)</summary> ### [`v2.5.32`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.32) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.31...opencost-2.5.32) OpenCost and OpenCost UI #### What's Changed - Upgrade OpenCost Helm Chart to v1.121.3 by [@​cpetersen5](https://github.com/cpetersen5) in [#​385](https://github.com/opencost/opencost-helm-chart/pull/385) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.31...opencost-2.5.32> ### [`v2.5.31`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.31) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.30...opencost-2.5.31) OpenCost and OpenCost UI #### What's Changed - Release OpenCost v1.121.2 by [@​cpetersen5](https://github.com/cpetersen5) in [#​384](https://github.com/opencost/opencost-helm-chart/pull/384) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.30...opencost-2.5.31> ### [`v2.5.30`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.30) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.29...opencost-2.5.30) OpenCost and OpenCost UI #### What's Changed - feat: add opencost.exporter.extraEnvFrom to source env from ConfigMap/Secret by [@​ahauserv](https://github.com/ahauserv) in [#​378](https://github.com/opencost/opencost-helm-chart/pull/378) #### New Contributors - [@​ahauserv](https://github.com/ahauserv) made their first contribution in [#​378](https://github.com/opencost/opencost-helm-chart/pull/378) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.29...opencost-2.5.30> ### [`v2.5.29`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.29) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.28...opencost-2.5.29) OpenCost and OpenCost UI #### What's Changed - Release OpenCost v1.121.1 by [@​cpetersen5](https://github.com/cpetersen5) in [#​377](https://github.com/opencost/opencost-helm-chart/pull/377) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.28...opencost-2.5.29> ### [`v2.5.28`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.28) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.27...opencost-2.5.28) OpenCost and OpenCost UI #### What's Changed - Inference Cost params added to helm by [@​simanadler](https://github.com/simanadler) in [#​370](https://github.com/opencost/opencost-helm-chart/pull/370) - Release OpenCost v1.121.0 by [@​cpetersen5](https://github.com/cpetersen5) in [#​372](https://github.com/opencost/opencost-helm-chart/pull/372) #### New Contributors - [@​simanadler](https://github.com/simanadler) made their first contribution in [#​370](https://github.com/opencost/opencost-helm-chart/pull/370) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.27...opencost-2.5.28> ### [`v2.5.27`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.27) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.26...opencost-2.5.27) OpenCost and OpenCost UI #### What's Changed - KCM-5392: Add support for configuring external labels for Opencost installation with Collector data source by [@​avrodrigues5](https://github.com/avrodrigues5) in [#​371](https://github.com/opencost/opencost-helm-chart/pull/371) #### New Contributors - [@​avrodrigues5](https://github.com/avrodrigues5) made their first contribution in [#​371](https://github.com/opencost/opencost-helm-chart/pull/371) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.26...opencost-2.5.27> ### [`v2.5.26`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.26) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.25...opencost-2.5.26) OpenCost and OpenCost UI #### What's Changed - add timeout configuration for override in probes by [@​aman-kumar29](https://github.com/aman-kumar29) in [#​369](https://github.com/opencost/opencost-helm-chart/pull/369) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-parquet-exporter-0.3.0...opencost-2.5.26> ### [`v2.5.25`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.25) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.24...opencost-2.5.25) OpenCost and OpenCost UI #### What's Changed - Release OpenCost v1.120.4 by [@​cpetersen5](https://github.com/cpetersen5) in [#​366](https://github.com/opencost/opencost-helm-chart/pull/366) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.24...opencost-2.5.25> ### [`v2.5.24`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.24) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.23...opencost-2.5.24) OpenCost and OpenCost UI #### What's Changed - fix(service): use opencost.exporter.debugPort for service targetPort by [@​aman-kumar29](https://github.com/aman-kumar29) in [#​364](https://github.com/opencost/opencost-helm-chart/pull/364) #### New Contributors - [@​aman-kumar29](https://github.com/aman-kumar29) made their first contribution in [#​364](https://github.com/opencost/opencost-helm-chart/pull/364) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.23...opencost-2.5.24> ### [`v2.5.23`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.23) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.22...opencost-2.5.23) OpenCost and OpenCost UI #### What's Changed - feat(gateway-api): Add support for filters by [@​HartmannVolker](https://github.com/HartmannVolker) in [#​356](https://github.com/opencost/opencost-helm-chart/pull/356) #### New Contributors - [@​HartmannVolker](https://github.com/HartmannVolker) made their first contribution in [#​356](https://github.com/opencost/opencost-helm-chart/pull/356) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.22...opencost-2.5.23> ### [`v2.5.22`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.22) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.21...opencost-2.5.22) OpenCost and OpenCost UI #### What's Changed - Release OpenCost v1.120.3 by [@​cpetersen5](https://github.com/cpetersen5) in [#​357](https://github.com/opencost/opencost-helm-chart/pull/357) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.21...opencost-2.5.22> ### [`v2.5.21`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.21) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.20...opencost-2.5.21) OpenCost and OpenCost UI #### What's Changed - feat: add extraObjects for tpl-rendered extra manifests by [@​younsl](https://github.com/younsl) in [#​354](https://github.com/opencost/opencost-helm-chart/pull/354) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.20...opencost-2.5.21> ### [`v2.5.20`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.20) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.19...opencost-2.5.20) OpenCost and OpenCost UI #### What's Changed - Update Helm chart for v1.120.2 by [@​cpetersen5](https://github.com/cpetersen5) in [#​355](https://github.com/opencost/opencost-helm-chart/pull/355) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.19...opencost-2.5.20> ### [`v2.5.19`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.19) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.18...opencost-2.5.19) OpenCost and OpenCost UI #### What's Changed - Consistent Usage of `opencost.namespace` Helper by [@​ioboi](https://github.com/ioboi) in [#​353](https://github.com/opencost/opencost-helm-chart/pull/353) #### New Contributors - [@​ioboi](https://github.com/ioboi) made their first contribution in [#​353](https://github.com/opencost/opencost-helm-chart/pull/353) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.18...opencost-2.5.19> ### [`v2.5.18`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.18) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.14...opencost-2.5.18) OpenCost and OpenCost UI #### What's Changed - feat: Add plugins.install.plugins list and existingSecret support (adopts [#​328](https://github.com/opencost/opencost-helm-chart/issues/328)) by [@​ameijer](https://github.com/ameijer) in [#​344](https://github.com/opencost/opencost-helm-chart/pull/344) - feat: add OCI cloud cost configuration example to cloudIntegrationJSON by [@​Kush172005](https://github.com/Kush172005) in [#​345](https://github.com/opencost/opencost-helm-chart/pull/345) - Release Opencost v1.120.1 - Bump Helm Chart by [@​cpetersen5](https://github.com/cpetersen5) in [#​347](https://github.com/opencost/opencost-helm-chart/pull/347) - Fix UI route tls by [@​mittal-ishaan](https://github.com/mittal-ishaan) in [#​352](https://github.com/opencost/opencost-helm-chart/pull/352) #### New Contributors - [@​Kush172005](https://github.com/Kush172005) made their first contribution in [#​345](https://github.com/opencost/opencost-helm-chart/pull/345) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.14...opencost-2.5.18> ### [`v2.5.14`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.14) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.12...opencost-2.5.14) OpenCost and OpenCost UI #### What's Changed - Release Opencost v1.120.0 by [@​cpetersen5](https://github.com/cpetersen5) in [#​341](https://github.com/opencost/opencost-helm-chart/pull/341) - Cdp/opencost v1.120.0 by [@​cpetersen5](https://github.com/cpetersen5) in [#​343](https://github.com/opencost/opencost-helm-chart/pull/343) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.12...opencost-2.5.14> ### [`v2.5.12`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.12) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.11...opencost-2.5.12) OpenCost and OpenCost UI #### What's Changed - Create Empty /var/configs dir by [@​HMetcalfeW](https://github.com/HMetcalfeW) in [#​333](https://github.com/opencost/opencost-helm-chart/pull/333) #### New Contributors - [@​HMetcalfeW](https://github.com/HMetcalfeW) made their first contribution in [#​333](https://github.com/opencost/opencost-helm-chart/pull/333) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.11...opencost-2.5.12> ### [`v2.5.11`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.11) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.10...opencost-2.5.11) OpenCost and OpenCost UI #### What's Changed - add admin token infra support by [@​ameijer](https://github.com/ameijer) in [#​339](https://github.com/opencost/opencost-helm-chart/pull/339) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.10...opencost-2.5.11> ### [`v2.5.10`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.10) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.9...opencost-2.5.10) OpenCost and OpenCost UI #### What's Changed - Add cloudIntegrationJSON support by [@​thomasvn](https://github.com/thomasvn) in [#​337](https://github.com/opencost/opencost-helm-chart/pull/337) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.9...opencost-2.5.10> ### [`v2.5.9`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.9) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.8...opencost-2.5.9) OpenCost and OpenCost UI #### What's Changed - Fix collectorDataSource retention env var conditions by [@​dag-andersen](https://github.com/dag-andersen) in [#​336](https://github.com/opencost/opencost-helm-chart/pull/336) #### New Contributors - [@​dag-andersen](https://github.com/dag-andersen) made their first contribution in [#​336](https://github.com/opencost/opencost-helm-chart/pull/336) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.8...opencost-2.5.9> ### [`v2.5.8`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.8) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.7...opencost-2.5.8) OpenCost and OpenCost UI #### What's Changed - Opencost v1.119.2 Changes by [@​cpetersen5](https://github.com/cpetersen5) in [#​334](https://github.com/opencost/opencost-helm-chart/pull/334) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.7...opencost-2.5.8> ### [`v2.5.7`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.7) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.6...opencost-2.5.7) OpenCost and OpenCost UI #### What's Changed - fix: fix csv export condition in deployment by [@​meroupatate](https://github.com/meroupatate) in [#​330](https://github.com/opencost/opencost-helm-chart/pull/330) #### New Contributors - [@​meroupatate](https://github.com/meroupatate) made their first contribution in [#​330](https://github.com/opencost/opencost-helm-chart/pull/330) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.6...opencost-2.5.7> ### [`v2.5.6`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.6) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.5...opencost-2.5.6) OpenCost and OpenCost UI #### What's Changed - Do not grant permissions on nodes/proxy by default by [@​Farenjihn](https://github.com/Farenjihn) in [#​329](https://github.com/opencost/opencost-helm-chart/pull/329) #### New Contributors - [@​Farenjihn](https://github.com/Farenjihn) made their first contribution in [#​329](https://github.com/opencost/opencost-helm-chart/pull/329) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.5...opencost-2.5.6> ### [`v2.5.5`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.5) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.4...opencost-2.5.5) OpenCost and OpenCost UI #### What's Changed - Add PRICING\_CONFIGMAP\_NAME env to achnowledge configmapName helm value by [@​mittal-ishaan](https://github.com/mittal-ishaan) in [#​316](https://github.com/opencost/opencost-helm-chart/pull/316) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.4...opencost-2.5.5> ### [`v2.5.4`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.4) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.3...opencost-2.5.4) OpenCost and OpenCost UI #### What's Changed - feat(opencost): add Gateway API HTTPRoute support by [@​younsl](https://github.com/younsl) in [#​322](https://github.com/opencost/opencost-helm-chart/pull/322) #### New Contributors - [@​younsl](https://github.com/younsl) made their first contribution in [#​322](https://github.com/opencost/opencost-helm-chart/pull/322) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.3...opencost-2.5.4> ### [`v2.5.3`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.3) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.2...opencost-2.5.3) OpenCost and OpenCost UI #### What's Changed - Add configurable nginx proxy timeouts to helm chart by [@​peatey](https://github.com/peatey) in [#​326](https://github.com/opencost/opencost-helm-chart/pull/326) #### New Contributors - [@​peatey](https://github.com/peatey) made their first contribution in [#​326](https://github.com/opencost/opencost-helm-chart/pull/326) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.2...opencost-2.5.3> ### [`v2.5.2`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.2) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.1...opencost-2.5.2) OpenCost and OpenCost UI #### What's Changed - Update cloud-integration secret path by [@​thomasvn](https://github.com/thomasvn) in [#​324](https://github.com/opencost/opencost-helm-chart/pull/324) #### New Contributors - [@​thomasvn](https://github.com/thomasvn) made their first contribution in [#​324](https://github.com/opencost/opencost-helm-chart/pull/324) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.1...opencost-2.5.2> ### [`v2.5.1`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.1) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.0...opencost-2.5.1) OpenCost and OpenCost UI #### What's Changed - Release Opencost v1.119.1 by [@​cpetersen5](https://github.com/cpetersen5) in [#​325](https://github.com/opencost/opencost-helm-chart/pull/325) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.0...opencost-2.5.1> ### [`v2.5.0`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.0) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.4.1...opencost-2.5.0) OpenCost and OpenCost UI #### What's Changed - Release Opencost v1.119.0 by [@​cpetersen5](https://github.com/cpetersen5) in [#​323](https://github.com/opencost/opencost-helm-chart/pull/323) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.4.1...opencost-2.5.0> ### [`v2.4.1`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.4.1) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.4.0...opencost-2.4.1) OpenCost and OpenCost UI #### What's Changed - fix: mcp disable procedure by [@​marijus-ravickas](https://github.com/marijus-ravickas) in [#​319](https://github.com/opencost/opencost-helm-chart/pull/319) #### New Contributors - [@​marijus-ravickas](https://github.com/marijus-ravickas) made their first contribution in [#​319](https://github.com/opencost/opencost-helm-chart/pull/319) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.4.0...opencost-2.4.1> ### [`v2.4.0`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.4.0) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.3.2...opencost-2.4.0) OpenCost and OpenCost UI #### What's Changed - added-mcp-config by [@​sneaxhuh](https://github.com/sneaxhuh) in [#​311](https://github.com/opencost/opencost-helm-chart/pull/311) - Update Opencost to v1.118.0 by [@​cpetersen5](https://github.com/cpetersen5) in [#​314](https://github.com/opencost/opencost-helm-chart/pull/314) #### New Contributors - [@​sneaxhuh](https://github.com/sneaxhuh) made their first contribution in [#​311](https://github.com/opencost/opencost-helm-chart/pull/311) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.3.2...opencost-2.4.0> ### [`v2.3.2`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.3.2) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.3.1...opencost-2.3.2) OpenCost and OpenCost UI #### What's Changed - fix: use default sc when sc name not specified by [@​cwyl02](https://github.com/cwyl02) in [#​312](https://github.com/opencost/opencost-helm-chart/pull/312) #### New Contributors - [@​cwyl02](https://github.com/cwyl02) made their first contribution in [#​312](https://github.com/opencost/opencost-helm-chart/pull/312) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.3.1...opencost-2.3.2> ### [`v2.3.1`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.3.1) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.3.0...opencost-2.3.1) OpenCost and OpenCost UI #### What's Changed - feat: Add option to use cm to set CLUSTER\_ID envvar by [@​gracedo](https://github.com/gracedo) in [#​307](https://github.com/opencost/opencost-helm-chart/pull/307) #### New Contributors - [@​gracedo](https://github.com/gracedo) made their first contribution in [#​307](https://github.com/opencost/opencost-helm-chart/pull/307) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.3.0...opencost-2.3.1> ### [`v2.3.0`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.3.0) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.9...opencost-2.3.0) OpenCost and OpenCost UI #### What's Changed - Add configs to mount custom ca certs to opencost container by [@​mittal-ishaan](https://github.com/mittal-ishaan) in [#​303](https://github.com/opencost/opencost-helm-chart/pull/303) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.9...opencost-2.3.0> ### [`v2.2.9`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.9) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.8...opencost-2.2.9) OpenCost and OpenCost UI #### What's Changed - Add chart installation notes by [@​dejanu](https://github.com/dejanu) in [#​305](https://github.com/opencost/opencost-helm-chart/pull/305) - Release Opencost v1.117.6 by [@​cpetersen5](https://github.com/cpetersen5) in [#​309](https://github.com/opencost/opencost-helm-chart/pull/309) #### New Contributors - [@​dejanu](https://github.com/dejanu) made their first contribution in [#​305](https://github.com/opencost/opencost-helm-chart/pull/305) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.8...opencost-2.2.9> ### [`v2.2.8`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.8) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.7...opencost-2.2.8) OpenCost and OpenCost UI #### What's Changed - Release Opencost v1.117.5 by [@​cpetersen5](https://github.com/cpetersen5) in [#​306](https://github.com/opencost/opencost-helm-chart/pull/306) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.7...opencost-2.2.8> ### [`v2.2.7`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.7) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.6...opencost-2.2.7) OpenCost and OpenCost UI #### What's Changed - Add uiPath configuration for OpenCost UI by [@​gustavo-sdo](https://github.com/gustavo-sdo) in [#​298](https://github.com/opencost/opencost-helm-chart/pull/298) #### New Contributors - [@​gustavo-sdo](https://github.com/gustavo-sdo) made their first contribution in [#​298](https://github.com/opencost/opencost-helm-chart/pull/298) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.6...opencost-2.2.7> ### [`v2.2.6`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.6) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.5...opencost-2.2.6) OpenCost and OpenCost UI #### What's Changed - Dodizzle/proxy fix by [@​ameijer](https://github.com/ameijer) in [#​301](https://github.com/opencost/opencost-helm-chart/pull/301) - allow: set path for internal prometheus by [@​dodizzle](https://github.com/dodizzle) in [#​271](https://github.com/opencost/opencost-helm-chart/pull/271) #### New Contributors - [@​dodizzle](https://github.com/dodizzle) made their first contribution in [#​271](https://github.com/opencost/opencost-helm-chart/pull/271) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.5...opencost-2.2.6> ### [`v2.2.5`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.5) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.4...opencost-2.2.5) OpenCost and OpenCost UI #### What's Changed - Release v1.117.3 of Opencost by [@​cpetersen5](https://github.com/cpetersen5) in [#​300](https://github.com/opencost/opencost-helm-chart/pull/300) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.4...opencost-2.2.5> ### [`v2.2.4`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.4) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.3...opencost-2.2.4) OpenCost and OpenCost UI #### What's Changed - Release v1.117.2 of Opencost by [@​cpetersen5](https://github.com/cpetersen5) in [#​299](https://github.com/opencost/opencost-helm-chart/pull/299) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.3...opencost-2.2.4> ### [`v2.2.3`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.3) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.2...opencost-2.2.3) OpenCost and OpenCost UI #### What's Changed - Update env var names and values by [@​Sean-Holcomb](https://github.com/Sean-Holcomb) in [#​297](https://github.com/opencost/opencost-helm-chart/pull/297) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.2...opencost-2.2.3> ### [`v2.2.2`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.2) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.1...opencost-2.2.2) OpenCost and OpenCost UI #### What's Changed - Advance to Opencost v1.117.0 by [@​mbolt35](https://github.com/mbolt35) in [#​296](https://github.com/opencost/opencost-helm-chart/pull/296) #### New Contributors - [@​mbolt35](https://github.com/mbolt35) made their first contribution in [#​296](https://github.com/opencost/opencost-helm-chart/pull/296) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.1...opencost-2.2.2> ### [`v2.2.1`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.1) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.0...opencost-2.2.1) OpenCost and OpenCost UI #### What's Changed - Add `insecureSkipVerify` to `prometheus.external` by [@​charleshu-8](https://github.com/charleshu-8) in [#​294](https://github.com/opencost/opencost-helm-chart/pull/294) #### New Contributors - [@​charleshu-8](https://github.com/charleshu-8) made their first contribution in [#​294](https://github.com/opencost/opencost-helm-chart/pull/294) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.0...opencost-2.2.1> ### [`v2.2.0`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.0) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.9...opencost-2.2.0) OpenCost and OpenCost UI #### What's Changed - Bump image tags and chart version by [@​cpetersen5](https://github.com/cpetersen5) in [#​291](https://github.com/opencost/opencost-helm-chart/pull/291) #### New Contributors - [@​cpetersen5](https://github.com/cpetersen5) made their first contribution in [#​291](https://github.com/opencost/opencost-helm-chart/pull/291) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.9...opencost-2.2.0> ### [`v2.1.9`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.9) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.8...opencost-2.1.9) OpenCost and OpenCost UI #### What's Changed - Change ETL env variable name by [@​Sean-Holcomb](https://github.com/Sean-Holcomb) in [#​285](https://github.com/opencost/opencost-helm-chart/pull/285) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.8...opencost-2.1.9> ### [`v2.1.8`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.8) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.7...opencost-2.1.8) OpenCost and OpenCost UI #### What's Changed - tweak params by [@​ameijer](https://github.com/ameijer) in [#​289](https://github.com/opencost/opencost-helm-chart/pull/289) - add option to override the default container command by [@​nishanthreddydd](https://github.com/nishanthreddydd) in [#​290](https://github.com/opencost/opencost-helm-chart/pull/290) #### New Contributors - [@​nishanthreddydd](https://github.com/nishanthreddydd) made their first contribution in [#​290](https://github.com/opencost/opencost-helm-chart/pull/290) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.7...opencost-2.1.8> ### [`v2.1.7`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.7) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.6...opencost-2.1.7) OpenCost and OpenCost UI #### What's Changed - (doc) update readme to easily install unittest by [@​karthik-suresh](https://github.com/karthik-suresh) in [#​284](https://github.com/opencost/opencost-helm-chart/pull/284) - Add ability to configure resolution for prometheus by [@​Sean-Holcomb](https://github.com/Sean-Holcomb) in [#​282](https://github.com/opencost/opencost-helm-chart/pull/282) - Add support for Pod Disruption Budget by [@​josephteddick](https://github.com/josephteddick) in [#​287](https://github.com/opencost/opencost-helm-chart/pull/287) #### New Contributors - [@​karthik-suresh](https://github.com/karthik-suresh) made their first contribution in [#​284](https://github.com/opencost/opencost-helm-chart/pull/284) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.6...opencost-2.1.7> ### [`v2.1.6`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.6) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.5...opencost-2.1.6) OpenCost and OpenCost UI #### What's Changed - feat(sec) - customize service account mounting by [@​cpsmx](https://github.com/cpsmx) in [#​283](https://github.com/opencost/opencost-helm-chart/pull/283) #### New Contributors - [@​cpsmx](https://github.com/cpsmx) made their first contribution in [#​283](https://github.com/opencost/opencost-helm-chart/pull/283) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.5...opencost-2.1.6> ### [`v2.1.5`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.5) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.4...opencost-2.1.5) OpenCost and OpenCost UI #### What's Changed - Update opencost ui 1.115.0 image by [@​mittal-ishaan](https://github.com/mittal-ishaan) in [#​281](https://github.com/opencost/opencost-helm-chart/pull/281) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.4...opencost-2.1.5> ### [`v2.1.4`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.4) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.3...opencost-2.1.4) OpenCost and OpenCost UI #### What's Changed - Bump OC to 1.115.0 by [@​mittal-ishaan](https://github.com/mittal-ishaan) in [#​277](https://github.com/opencost/opencost-helm-chart/pull/277) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.3...opencost-2.1.4> ### [`v2.1.3`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.3) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.2...opencost-2.1.3) OpenCost and OpenCost UI #### What's Changed - Promless Config by [@​Sean-Holcomb](https://github.com/Sean-Holcomb) in [#​275](https://github.com/opencost/opencost-helm-chart/pull/275) - Add values examples and notes to values.yaml. Update version numbers by [@​Sean-Holcomb](https://github.com/Sean-Holcomb) in [#​276](https://github.com/opencost/opencost-helm-chart/pull/276) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.2...opencost-2.1.3> ### [`v2.1.2`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.2) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.1...opencost-2.1.2) OpenCost and OpenCost UI #### What's Changed - Add support for API Ingress by [@​josephteddick](https://github.com/josephteddick) in [#​255](https://github.com/opencost/opencost-helm-chart/pull/255) #### New Contributors - [@​josephteddick](https://github.com/josephteddick) made their first contribution in [#​255](https://github.com/opencost/opencost-helm-chart/pull/255) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-parquet-exporter-0.2.0...opencost-2.1.2> ### [`v2.1.1`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.1) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.0...opencost-2.1.1) OpenCost and OpenCost UI #### What's Changed - Fix for [#​272](https://github.com/opencost/opencost-helm-chart/pull/272) to make feature flag actually work. by [@​tintii](https://github.com/tintii) in [#​274](https://github.com/opencost/opencost-helm-chart/pull/274) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.0...opencost-2.1.1> ### [`v2.1.0`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.0) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.0.2...opencost-2.1.0) OpenCost and OpenCost UI #### What's Changed - Openshift Security Context Constraints and updated ClusterRole with access to internal prometheus. by [@​v0nNemizez](https://github.com/v0nNemizez) in [#​267](https://github.com/opencost/opencost-helm-chart/pull/267) #### New Contributors - [@​v0nNemizez](https://github.com/v0nNemizez) made their first contribution in [#​267](https://github.com/opencost/opencost-helm-chart/pull/267) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.0.2...opencost-2.1.0> ### [`v2.0.2`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.0.2) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.0.1...opencost-2.0.2) OpenCost and OpenCost UI #### What's Changed - Add opencost.ui.useIPv6 feature flag by [@​tintii](https://github.com/tintii) in [#​272](https://github.com/opencost/opencost-helm-chart/pull/272) #### New Contributors - [@​tintii](https://github.com/tintii) made their first contribution in [#​272](https://github.com/opencost/opencost-helm-chart/pull/272) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.0.1...opencost-2.0.2> ### [`v2.0.1`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.0.1) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.0.0...opencost-2.0.1) OpenCost and OpenCost UI #### What's Changed - add sha256sums of configMaps to trigger a restart of the pod, if the configMap changes by [@​kastl-ars](https://github.com/kastl-ars) in [#​264](https://github.com/opencost/opencost-helm-chart/pull/264) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.0.0...opencost-2.0.1> ### [`v2.0.0`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.0.0) OpenCost and OpenCost UI #### What's Changed - add seperate openshift block to handle openshift related configurations and add frontend nginx config by [@​mittal-ishaan](https://github.com/mittal-ishaan) in [#​245](https://github.com/opencost/opencost-helm-chart/pull/245) - Updating chart badge by [@​TheUnixRoot](https://github.com/TheUnixRoot) in [#​261](https://github.com/opencost/opencost-helm-chart/pull/261) - Fix: Chart release script by [@​mittal-ishaan](https://github.com/mittal-ishaan) in [#​262](https://github.com/opencost/opencost-helm-chart/pull/262) #### New Contributors - [@​TheUnixRoot](https://github.com/TheUnixRoot) made their first contribution in [#​261](https://github.com/opencost/opencost-helm-chart/pull/261) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/1.45.0-helm...opencost-2.0.0> </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Oslo) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJicmVha2luZy1jaGFuZ2UiLCJyZW5vdmF0ZSJdfQ==--> --------- Co-authored-by: Renovate Bot <renovate@forteapps.net> Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/50 Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com> Co-authored-by: gitea_admin <admin@forteapps.net>
1834 lines
49 KiB
Markdown
1834 lines
49 KiB
Markdown
# Developer Onboarding Guide
|
|
|
|
## Table of Contents
|
|
- [Getting Started](#getting-started)
|
|
- [Prerequisites](#prerequisites)
|
|
- [Local Development Setup](#local-development-setup)
|
|
- [Understanding the Workflow](#understanding-the-workflow)
|
|
- [Deploying Your First Application](#deploying-your-first-application)
|
|
- [Updating an Existing Application](#updating-an-existing-application)
|
|
- [Working with Secrets](#working-with-secrets)
|
|
- [Enabling Authentication for Applications](#enabling-authentication-for-applications)
|
|
- [Adding a New Keycloak Client](#adding-a-new-keycloak-client)
|
|
- [Troubleshooting](#troubleshooting)
|
|
- [Best Practices](#best-practices)
|
|
|
|
---
|
|
|
|
## Getting Started
|
|
|
|
Welcome! This guide will help you understand how to develop and deploy applications on our Kubernetes cluster using GitOps principles powered by ArgoCD.
|
|
|
|
### What You'll Learn
|
|
- How our GitOps architecture works
|
|
- How to deploy a new application
|
|
- How to update existing applications
|
|
- How to manage secrets securely
|
|
- Common troubleshooting techniques
|
|
|
|
### Who This Guide Is For
|
|
- Developers deploying new applications
|
|
- Developers maintaining existing applications
|
|
- Team members who need to understand the deployment process
|
|
|
|
---
|
|
|
|
## Prerequisites
|
|
|
|
### Required Knowledge
|
|
- ✅ Basic Git workflow (clone, commit, push, pull)
|
|
- ✅ Docker basics (Dockerfile, building images)
|
|
- ✅ YAML syntax
|
|
- ✅ Basic understanding of Kubernetes concepts (pods, deployments, services)
|
|
- ⚠️ Helm knowledge (helpful but not required - templates are provided)
|
|
|
|
### Required Tools
|
|
|
|
Most developers **do NOT need kubectl access** to the cluster. You'll primarily work with Git repositories.
|
|
|
|
If you do need cluster access, install:
|
|
|
|
1. **kubectl** - Kubernetes CLI
|
|
```bash
|
|
# macOS
|
|
brew install kubectl
|
|
|
|
# Windows
|
|
choco install kubernetes-cli
|
|
|
|
# Linux
|
|
curl -LO "https://dl.k8s.io/release/$(curl -L -s https://dl.k8s.io/release/stable.txt)/bin/linux/amd64/kubectl"
|
|
```
|
|
|
|
2. **kubeseal** - For sealing secrets
|
|
```bash
|
|
# macOS
|
|
brew install kubeseal
|
|
|
|
# Windows
|
|
choco install kubeseal
|
|
|
|
# Linux
|
|
wget https://github.com/bitnami-labs/sealed-secrets/releases/download/v0.24.0/kubeseal-0.24.0-linux-amd64.tar.gz
|
|
tar -xvzf kubeseal-0.24.0-linux-amd64.tar.gz
|
|
sudo mv kubeseal /usr/local/bin/
|
|
```
|
|
|
|
3. **Git** - Version control
|
|
```bash
|
|
git --version # Should already be installed
|
|
```
|
|
|
|
4. **Docker** - For local development
|
|
```bash
|
|
# macOS/Windows: Install Docker Desktop
|
|
# Linux: Install Docker Engine
|
|
docker --version
|
|
```
|
|
|
|
### Repository Access
|
|
|
|
You'll need read/write access to these repositories:
|
|
|
|
1. **launchpad** (Config repo)
|
|
```bash
|
|
git clone https://git.forteapps.net/Forte/launchpad.git
|
|
cd launchpad
|
|
```
|
|
|
|
2. **helm-prod-values** (Values repo)
|
|
```bash
|
|
git clone https://git.forteapps.net/Forte/helm-prod-values.git
|
|
cd helm-prod-values
|
|
```
|
|
|
|
3. **forte-helm** (Chart repo - read-only for most developers)
|
|
```bash
|
|
git clone https://git.forteapps.net/Forte/forte-helm.git
|
|
cd forte-helm
|
|
```
|
|
|
|
### Cluster Access (If Needed)
|
|
|
|
If you need kubectl access, ask the platform team for:
|
|
- Kubeconfig file
|
|
- Cluster context setup instructions
|
|
|
|
Save to `~/.kube/config` and verify:
|
|
```bash
|
|
kubectl cluster-info
|
|
kubectl get nodes
|
|
```
|
|
|
|
---
|
|
|
|
## Local Development Setup
|
|
|
|
### 1. Clone the Repositories
|
|
|
|
Set up a consistent folder structure:
|
|
|
|
```bash
|
|
mkdir -p ~/dev/k8s
|
|
cd ~/dev/k8s
|
|
|
|
# Clone repositories
|
|
git clone https://git.forteapps.net/Forte/launchpad.git launchpad
|
|
git clone https://git.forteapps.net/Forte/helm-prod-values helm-prod-values
|
|
git clone https://git.forteapps.net/Forte/forte-helm forte-helm
|
|
|
|
# Your folder structure:
|
|
# ~/dev/k8s/
|
|
# ├── launchpad/ (Config repo)
|
|
# ├── helm-prod-values/ (Values repo)
|
|
# └── forte-helm/ (Chart repo)
|
|
```
|
|
|
|
### 2. Local Development Environment
|
|
|
|
Most applications use **Docker Compose** for local development:
|
|
|
|
```bash
|
|
# In your application repository
|
|
docker-compose up
|
|
|
|
# Or for frontend applications
|
|
npm install
|
|
npm run dev
|
|
```
|
|
|
|
**You DO NOT run applications locally on Kubernetes.** Use Docker Compose or native tooling (npm, python, etc.).
|
|
|
|
### 3. Understanding the Deployment Flow
|
|
|
|
```
|
|
┌─────────────────────────────────────────────────────────────────┐
|
|
│ Step 1: Develop Locally │
|
|
│ - Write code in your application repository │
|
|
│ - Test with Docker Compose or npm/python/etc. │
|
|
│ - Build Docker image │
|
|
└─────────────────────────────────────────────────────────────────┘
|
|
│
|
|
▼
|
|
┌─────────────────────────────────────────────────────────────────┐
|
|
│ Step 2: CI/CD Pipeline (Automated) │
|
|
│ - GitHub Actions builds image │
|
|
│ - Pushes to container registry (GHCR, Docker Hub) │
|
|
│ - Tags with version (e.g., v2.0.4) │
|
|
│ - Updates helm-prod-values repository with new tag │
|
|
└─────────────────────────────────────────────────────────────────┘
|
|
│
|
|
▼
|
|
┌─────────────────────────────────────────────────────────────────┐
|
|
│ Step 3: GitOps Sync (Automated) │
|
|
│ - ArgoCD detects change in helm-prod-values │
|
|
│ - Pulls updated configuration │
|
|
│ - Syncs to Kubernetes cluster │
|
|
│ - Sends Slack notification on success/failure │
|
|
└─────────────────────────────────────────────────────────────────┘
|
|
```
|
|
|
|
**Key Insight**: You don't deploy directly. You push code, CI/CD builds it, and ArgoCD deploys it.
|
|
|
|
---
|
|
|
|
## Understanding the Workflow
|
|
|
|
### Three-Repository Pattern
|
|
|
|
Our setup uses three repositories:
|
|
|
|
| Repository | Purpose | Who Edits | How Often |
|
|
|------------|---------|-----------|-----------|
|
|
| **forte-helm** | Helm chart templates (generic, reusable) | Platform engineers | ❌ Rarely |
|
|
| **helm-prod-values** | Application configuration (image tag, env vars) | Developers / CI pipelines | ✅ Sometimes |
|
|
| **launchpad** | ArgoCD Applications (what gets deployed) | Platform / DevOps engineers | ✅ Per new app |
|
|
|
|
### Example: Deploying "myapp"
|
|
|
|
#### Repository: `forte-helm` (Chart Templates)
|
|
```yaml
|
|
# forteapp/templates/deployment.yaml
|
|
# Generic template used by ALL apps
|
|
apiVersion: apps/v1
|
|
kind: Deployment
|
|
metadata:
|
|
name: {{ .Values.app.name }}
|
|
spec:
|
|
containers:
|
|
- name: app
|
|
image: "{{ .Values.app.image.repository }}:{{ .Values.app.image.tag }}"
|
|
env:
|
|
- name: PORT
|
|
value: {{ .Values.app.port }}
|
|
```
|
|
|
|
#### Repository: `helm-prod-values` (Your App Config)
|
|
```yaml
|
|
# myapp/values.yaml
|
|
# Your app's specific configuration
|
|
app:
|
|
image:
|
|
repository: ghcr.io/fortedigital/myapp
|
|
tag: v1.0.0 # CI/CD updates this
|
|
port: 3000
|
|
extraEnv:
|
|
- name: API_URL
|
|
value: https://api.example.com
|
|
```
|
|
|
|
#### Repository: `launchpad` (ArgoCD Application)
|
|
```yaml
|
|
# apps/myapp.yaml
|
|
# Tells ArgoCD to deploy your app
|
|
apiVersion: argoproj.io/v1alpha1
|
|
kind: Application
|
|
metadata:
|
|
name: myapp
|
|
namespace: argocd
|
|
spec:
|
|
sources:
|
|
- repoURL: https://git.forteapps.net/Forte/forte-helm
|
|
path: forteapp
|
|
helm:
|
|
valueFiles:
|
|
- $values/myapp/values.yaml
|
|
|
|
- repoURL: git@github.com:fortedigital/helm-prod-values.git
|
|
ref: values
|
|
|
|
destination:
|
|
server: https://kubernetes.default.svc
|
|
namespace: myapp
|
|
|
|
syncPolicy:
|
|
automated:
|
|
prune: true
|
|
selfHeal: true
|
|
syncOptions:
|
|
- CreateNamespace=true
|
|
```
|
|
|
|
---
|
|
|
|
## Deploying Your First Application
|
|
|
|
### Scenario: You've Built a New Application
|
|
|
|
Let's deploy a new Node.js application called "hello-world".
|
|
|
|
### Step 1: Prepare Your Application Repository
|
|
|
|
Ensure your app repository has:
|
|
|
|
1. **Dockerfile**
|
|
```dockerfile
|
|
FROM node:18-alpine
|
|
WORKDIR /app
|
|
COPY package*.json ./
|
|
RUN npm ci --only=production
|
|
COPY . .
|
|
EXPOSE 3000
|
|
CMD ["node", "server.js"]
|
|
```
|
|
|
|
2. **GitHub Actions Workflow** (`.github/workflows/deploy.yml`)
|
|
```yaml
|
|
name: Build and Deploy
|
|
|
|
on:
|
|
push:
|
|
branches: [ main ]
|
|
|
|
jobs:
|
|
build:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v3
|
|
|
|
- name: Set version
|
|
id: version
|
|
run: echo "VERSION=v$(date +%Y%m%d-%H%M%S)" >> $GITHUB_OUTPUT
|
|
|
|
- name: Build and push Docker image
|
|
run: |
|
|
echo ${{ secrets.GITHUB_TOKEN }} | docker login ghcr.io -u ${{ github.actor }} --password-stdin
|
|
docker build -t ghcr.io/fortedigital/hello-world:${{ steps.version.outputs.VERSION }} .
|
|
docker push ghcr.io/fortedigital/hello-world:${{ steps.version.outputs.VERSION }}
|
|
|
|
- name: Update helm-prod-values
|
|
run: |
|
|
git clone git@github.com:fortedigital/helm-prod-values.git
|
|
cd helm-prod-values
|
|
mkdir -p hello-world
|
|
cat > hello-world/values.yaml <<EOF
|
|
app:
|
|
image:
|
|
repository: ghcr.io/fortedigital/hello-world
|
|
tag: ${{ steps.version.outputs.VERSION }}
|
|
EOF
|
|
git add hello-world/values.yaml
|
|
git commit -m "Update hello-world to ${{ steps.version.outputs.VERSION }}"
|
|
git push
|
|
```
|
|
|
|
### Step 2: Create Helm Values
|
|
|
|
Create a folder in `helm-prod-values` repository:
|
|
|
|
```bash
|
|
cd ~/dev/k8s/helm-prod-values
|
|
mkdir -p hello-world
|
|
```
|
|
|
|
Create `hello-world/values.yaml`:
|
|
```yaml
|
|
app:
|
|
image:
|
|
repository: ghcr.io/fortedigital/hello-world
|
|
tag: v1.0.0 # Will be updated by CI/CD
|
|
containerPort: 3000
|
|
|
|
replicaCount: 1
|
|
|
|
resources:
|
|
requests:
|
|
cpu: 100m
|
|
memory: 128Mi
|
|
limits:
|
|
cpu: 500m
|
|
memory: 512Mi
|
|
|
|
extraEnv:
|
|
- name: PORT
|
|
value: "3000"
|
|
- name: NODE_ENV
|
|
value: "production"
|
|
|
|
envSecretName: "" # Optional: reference to secrets
|
|
|
|
service:
|
|
port: 3000
|
|
|
|
ingress:
|
|
enabled: true
|
|
host: hello-world.forteapps.net # Your subdomain
|
|
|
|
db:
|
|
enabled: false # Set to true if you need PostgreSQL
|
|
```
|
|
|
|
Commit and push:
|
|
```bash
|
|
git add hello-world/values.yaml
|
|
git commit -m "Add hello-world application values"
|
|
git push
|
|
```
|
|
|
|
### Step 3: Create ArgoCD Application Manifest
|
|
|
|
In the `launchpad` repository, create `apps/hello-world.yaml`:
|
|
|
|
```yaml
|
|
apiVersion: argoproj.io/v1alpha1
|
|
kind: Application
|
|
metadata:
|
|
name: hello-world
|
|
namespace: argocd
|
|
annotations:
|
|
argocd.argoproj.io/sync-wave: "1"
|
|
notifications.argoproj.io/subscribe.on-sync-succeeded.slack: ""
|
|
notifications.argoproj.io/subscribe.on-sync-failed.slack: ""
|
|
notifications.argoproj.io/subscribe.on-degraded.slack: ""
|
|
labels:
|
|
app.kubernetes.io/name: hello-world
|
|
app.kubernetes.io/part-of: apps
|
|
app.kubernetes.io/managed-by: argocd
|
|
finalizers:
|
|
- resources-finalizer.argocd.argoproj.io
|
|
|
|
spec:
|
|
project: default
|
|
|
|
sources:
|
|
# Source 1: Helm chart templates
|
|
- repoURL: https://git.forteapps.net/Forte/forte-helm
|
|
path: forteapp
|
|
targetRevision: HEAD
|
|
helm:
|
|
valueFiles:
|
|
- $values/hello-world/values.yaml
|
|
|
|
# Source 2: Helm values
|
|
- repoURL: git@github.com:fortedigital/helm-prod-values.git
|
|
targetRevision: HEAD
|
|
ref: values
|
|
|
|
destination:
|
|
server: https://kubernetes.default.svc
|
|
namespace: hello-world
|
|
|
|
syncPolicy:
|
|
automated:
|
|
prune: true
|
|
selfHeal: true
|
|
allowEmpty: false
|
|
|
|
syncOptions:
|
|
- CreateNamespace=true
|
|
- Validate=true
|
|
- ServerSideApply=true
|
|
|
|
retry:
|
|
limit: 5
|
|
backoff:
|
|
duration: 5s
|
|
factor: 2
|
|
maxDuration: 3m
|
|
|
|
ignoreDifferences:
|
|
- group: apps
|
|
kind: Deployment
|
|
jsonPointers:
|
|
- /spec/replicas
|
|
```
|
|
|
|
Commit and push:
|
|
```bash
|
|
cd ~/dev/k8s/launchpad
|
|
git add apps/hello-world.yaml
|
|
git commit -m "Add hello-world application"
|
|
git push
|
|
```
|
|
|
|
### Step 4: Verify Deployment
|
|
|
|
ArgoCD will automatically detect the new application within 60 seconds.
|
|
|
|
**Option 1: Check Slack**
|
|
- Watch for sync notifications in your Slack channel
|
|
- ✅ "Application hello-world sync succeeded"
|
|
|
|
**Option 2: Check ArgoCD UI** (if you have access)
|
|
```bash
|
|
# Port forward to ArgoCD UI
|
|
kubectl port-forward svc/argocd-server -n argocd 8080:443
|
|
|
|
# Open browser: https://localhost:8080
|
|
# Look for "hello-world" application
|
|
```
|
|
|
|
**Option 3: Check with kubectl** (if you have access)
|
|
```bash
|
|
# List ArgoCD applications
|
|
kubectl get applications -n argocd
|
|
|
|
# Check application status
|
|
kubectl get application hello-world -n argocd
|
|
|
|
# Verify pods are running
|
|
kubectl get pods -n hello-world
|
|
```
|
|
|
|
### Step 5: Access Your Application
|
|
|
|
Once deployed, access via the configured domain:
|
|
|
|
```bash
|
|
# Check if ingress is created
|
|
kubectl get ingressroute -n hello-world
|
|
|
|
# Access application
|
|
curl https://hello-world.forteapps.net
|
|
```
|
|
|
|
**⚠️ Note**: DNS must be manually configured for new subdomains. Contact the platform team to add DNS records.
|
|
|
|
---
|
|
|
|
## Updating an Existing Application
|
|
|
|
### Scenario: Deploying a Code Change
|
|
|
|
You've made changes to your application code and want to deploy them.
|
|
|
|
### Method 1: Automatic (Recommended)
|
|
|
|
**Just push to `main` branch** - CI/CD handles everything:
|
|
|
|
```bash
|
|
# In your application repository
|
|
git add .
|
|
git commit -m "Fix bug in user login"
|
|
git push origin main
|
|
```
|
|
|
|
**What Happens Next:**
|
|
1. ✅ GitHub Actions triggers
|
|
2. ✅ Builds new Docker image
|
|
3. ✅ Tags with new version (e.g., `v20260316-143022`)
|
|
4. ✅ Pushes to container registry
|
|
5. ✅ Updates `helm-prod-values/myapp/values.yaml` with new tag
|
|
6. ✅ ArgoCD detects change
|
|
7. ✅ Syncs new version to cluster
|
|
8. ✅ Sends Slack notification
|
|
|
|
**Timeline**: ~5-10 minutes from push to deployment
|
|
|
|
### Method 2: Manual Image Tag Update
|
|
|
|
If CI/CD is not set up, manually update the image tag:
|
|
|
|
```bash
|
|
cd ~/dev/k8s/helm-prod-values
|
|
|
|
# Edit your app's values.yaml
|
|
vim myapp/values.yaml
|
|
|
|
# Change:
|
|
app:
|
|
image:
|
|
tag: v1.0.0 # Old version
|
|
# To:
|
|
app:
|
|
image:
|
|
tag: v1.0.1 # New version
|
|
|
|
# Commit and push
|
|
git add myapp/values.yaml
|
|
git commit -m "Update myapp to v1.0.1"
|
|
git push
|
|
```
|
|
|
|
ArgoCD will sync within 60 seconds.
|
|
|
|
### Method 3: Configuration Changes
|
|
|
|
To update environment variables, resources, or other config:
|
|
|
|
```bash
|
|
cd ~/dev/k8s/helm-prod-values
|
|
vim myapp/values.yaml
|
|
```
|
|
|
|
Example changes:
|
|
|
|
```yaml
|
|
app:
|
|
# Increase resources
|
|
resources:
|
|
requests:
|
|
cpu: 200m # Was 100m
|
|
memory: 256Mi # Was 128Mi
|
|
|
|
# Add new environment variable
|
|
extraEnv:
|
|
- name: API_URL
|
|
value: https://api.example.com
|
|
- name: DEBUG # NEW
|
|
value: "true" # NEW
|
|
|
|
# Enable HPA
|
|
hpa:
|
|
enabled: true # Was false
|
|
minReplicas: 2
|
|
maxReplicas: 10
|
|
```
|
|
|
|
Commit and push:
|
|
```bash
|
|
git add myapp/values.yaml
|
|
git commit -m "Increase myapp resources and enable HPA"
|
|
git push
|
|
```
|
|
|
|
### Method 4: Application Manifest Changes
|
|
|
|
To change ArgoCD sync behavior, namespace, or other meta-config:
|
|
|
|
```bash
|
|
cd ~/dev/k8s/launchpad
|
|
vim apps/myapp.yaml
|
|
```
|
|
|
|
Example changes:
|
|
|
|
```yaml
|
|
spec:
|
|
syncPolicy:
|
|
automated:
|
|
prune: true
|
|
selfHeal: false # Disable self-healing temporarily
|
|
```
|
|
|
|
Commit and push:
|
|
```bash
|
|
git add apps/myapp.yaml
|
|
git commit -m "Disable self-healing for myapp"
|
|
git push
|
|
```
|
|
|
|
---
|
|
|
|
## Working with Secrets
|
|
|
|
### Understanding Secret Management
|
|
|
|
**NEVER commit plain secrets to Git.** We use **Sealed Secrets** to encrypt secrets before committing.
|
|
|
|
### Creating a New Secret
|
|
|
|
#### Step 1: Create Plain Secret Locally
|
|
|
|
```bash
|
|
cd ~/dev/k8s/launchpad
|
|
|
|
# Create secret in private/ folder (Git-ignored)
|
|
kubectl create secret generic myapp-credentials \
|
|
--from-literal=API_KEY=your-secret-key-here \
|
|
--from-literal=DB_PASSWORD=super-secret-password \
|
|
--dry-run=client -o yaml > private/myapp-credentials.yaml
|
|
```
|
|
|
|
**DO NOT commit this file!** It's in `private/` which is Git-ignored.
|
|
|
|
#### Step 2: Seal the Secret
|
|
|
|
Seal your secret:
|
|
|
|
```bash
|
|
kubeseal --format=yaml \
|
|
--namespace=myapp \
|
|
< private/myapp-credentials.yaml \
|
|
> secrets/myapp-credentials-sealed.yaml
|
|
```
|
|
|
|
#### Step 3: Commit Sealed Secret
|
|
|
|
```bash
|
|
git add secrets/myapp-credentials-sealed.yaml
|
|
git commit -m "Add myapp credentials (sealed)"
|
|
git push
|
|
```
|
|
|
|
#### Step 4: Reference Secret in Application
|
|
|
|
Update your `helm-prod-values/myapp/values.yaml`:
|
|
|
|
```yaml
|
|
app:
|
|
envSecretName: "myapp-credentials" # References the SealedSecret
|
|
```
|
|
|
|
Commit and push:
|
|
```bash
|
|
cd ~/dev/k8s/helm-prod-values
|
|
git add myapp/values.yaml
|
|
git commit -m "Reference myapp credentials"
|
|
git push
|
|
```
|
|
|
|
### Updating a Secret
|
|
|
|
To update an existing secret:
|
|
|
|
```bash
|
|
# 1. Create new version of secret
|
|
kubectl create secret generic myapp-credentials \
|
|
--from-literal=API_KEY=new-key-here \
|
|
--from-literal=DB_PASSWORD=new-password \
|
|
--dry-run=client -o yaml > private/myapp-credentials.yaml
|
|
|
|
# 2. Seal it
|
|
kubeseal --format=yaml \
|
|
--namespace=myapp \
|
|
< private/myapp-credentials.yaml \
|
|
> secrets/myapp-credentials-sealed.yaml
|
|
|
|
# 3. Commit sealed version
|
|
git add secrets/myapp-credentials-sealed.yaml
|
|
git commit -m "Update myapp credentials"
|
|
git push
|
|
|
|
# 4. Restart pods to pick up new secret
|
|
kubectl rollout restart deployment myapp -n myapp
|
|
```
|
|
|
|
### Secret Best Practices
|
|
|
|
✅ **DO**:
|
|
- Store secrets in `private/` folder locally
|
|
- Always seal secrets before committing
|
|
- Delete plain secrets after sealing
|
|
- Use meaningful secret names
|
|
- Document what each secret contains
|
|
|
|
❌ **DON'T**:
|
|
- Commit plain secrets to Git
|
|
- Share secrets via Slack/email
|
|
- Hard-code secrets in code
|
|
- Use the same secret across multiple environments
|
|
- Store secrets in Docker images
|
|
|
|
### Where Secrets Are Stored
|
|
|
|
```
|
|
┌─────────────────────────────────────────────────────────────┐
|
|
│ Location │ Content │ Committed?│
|
|
├──────────────────────────┼────────────────────┼────────────┤
|
|
│ private/ │ Plain secrets │ ❌ NO │
|
|
│ secrets/ │ Sealed secrets │ ✅ YES │
|
|
│ Kubernetes cluster │ Unsealed secrets │ N/A │
|
|
└─────────────────────────────────────────────────────────────┘
|
|
```
|
|
|
|
**Sealed Secrets Controller** in the cluster decrypts sealed secrets automatically.
|
|
|
|
---
|
|
|
|
## Enabling Authentication for Applications
|
|
|
|
The cluster supports automatic authentication sidecar injection for applications via Kyverno policies. This allows you to add authentication to your applications without modifying application code.
|
|
|
|
### How It Works
|
|
|
|
When you enable authentication in your Helm values, the Kyverno policy automatically:
|
|
1. ✅ Injects an authentication sidecar container into your pod
|
|
2. ✅ Routes all incoming traffic through the auth sidecar (port 8080)
|
|
3. ✅ Validates credentials before forwarding requests to your application
|
|
4. ✅ Creates necessary secrets (if they don't exist)
|
|
5. ✅ Adds a NetworkPolicy to restrict ingress
|
|
|
|
**Architecture**:
|
|
```
|
|
Internet → Traefik → Service:8080 → Auth Sidecar:8080 → localhost → Your App:3000
|
|
│
|
|
├─ Validates credentials
|
|
└─ Forwards if valid
|
|
```
|
|
|
|
### Authentication Modes
|
|
|
|
Three authentication modes are supported:
|
|
1. **Token-based**: Static tokens (simple, good for service-to-service or internal apps)
|
|
2. **OIDC**: OpenID Connect (full SSO, good for user-facing apps)
|
|
3. **MCP**: OAuth 2.0 for MCP servers via RFC 9728 (Protected Resource Metadata); Keycloak provides native RFC 7591 Dynamic Client Registration (good for MCP tool servers requiring OAuth-based access control)
|
|
|
|
---
|
|
|
|
### Token-Based Authentication
|
|
|
|
#### Step 1: Configure Helm Values
|
|
|
|
```yaml
|
|
# In helm-prod-values/myapp/values.yaml
|
|
auth:
|
|
enabled: true
|
|
type: token # Token mode (default)
|
|
tokens:
|
|
- d4f88f6d9292c10cc3e21c4aad56d2be485db532b54fe961d738e1137d247823
|
|
- 8803f621acc3898df1d7a8f514bc3602551a0681a8f747bd4e43c3c5849d57a7
|
|
```
|
|
|
|
#### Step 2: Generate Token (if needed)
|
|
|
|
```bash
|
|
# Generate a secure random token
|
|
openssl rand -hex 32
|
|
|
|
# Or using Python
|
|
python3 -c "import secrets; print(secrets.token_hex(32))"
|
|
|
|
# Example output:
|
|
# d4f88f6d9292c10cc3e21c4aad56d2be485db532b54fe961d738e1137d247823
|
|
```
|
|
|
|
#### Step 3: Deploy Application
|
|
|
|
Commit and push your changes:
|
|
```bash
|
|
cd ~/dev/k8s/helm-prod-values
|
|
git add myapp/values.yaml
|
|
git commit -m "Enable token auth for myapp"
|
|
git push
|
|
```
|
|
|
|
ArgoCD will sync, and the Kyverno policy will:
|
|
- Inject the auth sidecar container
|
|
- Create an `auth-tokens` Secret with your tokens
|
|
- Configure the sidecar to validate against these tokens
|
|
|
|
#### Step 4: Access Application
|
|
|
|
Use your token in the `Authorization` header:
|
|
|
|
```bash
|
|
# Access application with token
|
|
curl -H "Authorization: Bearer d4f88f6d9292c10cc3e21c4aad56d2be485db532b54fe961d738e1137d247823" \
|
|
https://myapp.forteapps.net/api/data
|
|
|
|
# Without token (will be rejected)
|
|
curl https://myapp.forteapps.net/api/data
|
|
# Response: 401 Unauthorized
|
|
```
|
|
|
|
#### Advanced: Custom Secret Name
|
|
|
|
To use a different secret for tokens:
|
|
|
|
```yaml
|
|
# In Helm values
|
|
auth:
|
|
enabled: true
|
|
type: token
|
|
tokens: [] # Empty - using external secret
|
|
|
|
# Tokens will be read from custom secret
|
|
```
|
|
|
|
Then reference it via annotation (configured by Helm chart automatically):
|
|
```yaml
|
|
# Helm chart sets this annotation:
|
|
policies.forteapps.io/auth-token-secret-name: "myapp-auth-tokens"
|
|
```
|
|
|
|
Create the secret manually:
|
|
```bash
|
|
kubectl create secret generic myapp-auth-tokens \
|
|
--from-file=tokens=tokens.txt \
|
|
--namespace=myapp
|
|
```
|
|
|
|
---
|
|
|
|
### OIDC Authentication
|
|
|
|
OIDC mode integrates with identity providers like Keycloak, Okta, Auth0, Azure AD, etc.
|
|
|
|
#### Step 1: Configure Identity Provider
|
|
|
|
In your identity provider (e.g., Keycloak):
|
|
1. Create a new client (e.g., `myapp`)
|
|
2. Set redirect URI: `https://myapp.forteapps.net/auth/callback`
|
|
3. Note the **Client ID** and **Client Secret**
|
|
4. Note the **Authority URL** (e.g., `https://keycloak.forteapps.net/realms/master`)
|
|
|
|
#### Step 2: Create OIDC Secret
|
|
|
|
```bash
|
|
# Create plain secret
|
|
kubectl create secret generic auth-oidc \
|
|
--from-literal=client-secret=your-oidc-client-secret \
|
|
--from-literal=cookie-secret=$(openssl rand -hex 32) \
|
|
--namespace=myapp \
|
|
--dry-run=client -o yaml > private/myapp-auth-oidc.yaml
|
|
|
|
# Seal it
|
|
kubeseal --format=yaml \
|
|
--cert=pub-cert.pem \
|
|
--namespace=myapp \
|
|
< private/myapp-auth-oidc.yaml \
|
|
> secrets/myapp-auth-oidc-sealed.yaml
|
|
|
|
# Commit sealed secret
|
|
cd ~/dev/k8s/launchpad
|
|
git add secrets/myapp-auth-oidc-sealed.yaml
|
|
git commit -m "Add OIDC secrets for myapp"
|
|
git push
|
|
|
|
# Clean up
|
|
rm private/myapp-auth-oidc.yaml
|
|
```
|
|
|
|
#### Step 3: Configure Helm Values
|
|
|
|
```yaml
|
|
# In helm-prod-values/myapp/values.yaml
|
|
auth:
|
|
enabled: true
|
|
type: oidc # OIDC mode
|
|
oidc:
|
|
authority: https://keycloak.forteapps.net/realms/master
|
|
clientId: myapp
|
|
scopes: "openid,profile,email"
|
|
callbackPath: /auth/callback
|
|
```
|
|
|
|
#### Step 4: Deploy Application
|
|
|
|
```bash
|
|
cd ~/dev/k8s/helm-prod-values
|
|
git add myapp/values.yaml
|
|
git commit -m "Enable OIDC auth for myapp"
|
|
git push
|
|
```
|
|
|
|
#### Step 5: Access Application
|
|
|
|
When users access `https://myapp.forteapps.net`:
|
|
1. They're redirected to the identity provider login page
|
|
2. After successful login, redirected back to `/auth/callback`
|
|
3. Session cookie is set
|
|
4. Subsequent requests are authenticated via cookie
|
|
|
|
**User flow**:
|
|
```
|
|
User → https://myapp.forteapps.net
|
|
↓
|
|
Redirect → https://keycloak.forteapps.net/login
|
|
↓
|
|
Login successful → Redirect with auth code
|
|
↓
|
|
https://myapp.forteapps.net/auth/callback?code=xyz
|
|
↓
|
|
Auth sidecar exchanges code for tokens
|
|
↓
|
|
Sets session cookie
|
|
↓
|
|
Redirects to application → https://myapp.forteapps.net
|
|
↓
|
|
User sees application (authenticated)
|
|
```
|
|
|
|
---
|
|
|
|
### Accessing Authenticated User Information
|
|
|
|
The auth sidecar handles all authentication before requests reach your application. Your app never sees unauthenticated traffic — the sidecar returns 401 or redirects to the IdP first.
|
|
|
|
After successful authentication, the sidecar forwards the request to your application with user identity injected as HTTP headers:
|
|
|
|
| Header | Description | Available in |
|
|
|--------|-------------|-------------|
|
|
| `X-Auth-User` | Username or display name | Token, OIDC, MCP |
|
|
| `X-Auth-Email` | User email address | OIDC |
|
|
| `X-Auth-Subject` | OIDC `sub` claim (stable user ID) | OIDC, MCP |
|
|
| `X-Auth-Groups` | Comma-separated group memberships | OIDC (if scope includes `groups`) |
|
|
| `X-Auth-Token` | The validated access token | All modes |
|
|
|
|
**Your application reads these headers — no auth library needed:**
|
|
|
|
```javascript
|
|
// Express.js example
|
|
app.get('/profile', (req, res) => {
|
|
const user = req.headers['x-auth-user'];
|
|
const email = req.headers['x-auth-email'];
|
|
res.json({ user, email });
|
|
});
|
|
```
|
|
|
|
```python
|
|
# Flask example
|
|
@app.route('/profile')
|
|
def profile():
|
|
user = request.headers.get('X-Auth-User')
|
|
email = request.headers.get('X-Auth-Email')
|
|
return jsonify(user=user, email=email)
|
|
```
|
|
|
|
**Why this is safe**: The Kyverno-generated NetworkPolicy restricts ingress to the sidecar port only. Traffic cannot bypass the sidecar to reach the application port directly, so the `X-Auth-*` headers can be trusted unconditionally.
|
|
|
|
**Key principle**: Your application is zero-trust-unaware by design. It reads headers and renders UI. All authentication complexity lives in the sidecar and Kyverno policy.
|
|
|
|
---
|
|
|
|
### Authentication Configuration Reference
|
|
|
|
#### Helm Values Schema
|
|
|
|
```yaml
|
|
auth:
|
|
enabled: false # Enable/disable authentication
|
|
type: token # "token", "oidc", or "mcp"
|
|
|
|
# Token mode configuration
|
|
tokens: [] # List of valid bearer tokens
|
|
# - token1
|
|
# - token2
|
|
|
|
# OIDC mode configuration
|
|
oidc:
|
|
authority: "" # OIDC provider URL (required for OIDC)
|
|
clientId: "" # OIDC client ID (required for OIDC)
|
|
scopes: "openid,profile,email" # OIDC scopes (optional)
|
|
callbackPath: /auth/callback # OAuth callback path (optional)
|
|
|
|
# MCP mode configuration (RFC 9728)
|
|
mcp:
|
|
resource: "" # Protected resource URL (required for MCP)
|
|
authority: "" # Authorization server URL (required for MCP)
|
|
scopes: "read,write" # Supported scopes (optional)
|
|
```
|
|
|
|
#### Annotations Set by Helm Chart
|
|
|
|
When `auth.enabled: true`, the Helm chart sets these pod annotations:
|
|
|
|
**Token mode**:
|
|
```yaml
|
|
policies.forteapps.io/auth: "true"
|
|
policies.forteapps.io/auth-type: "token"
|
|
policies.forteapps.io/auth-token-secret-name: "auth-tokens"
|
|
policies.forteapps.io/auth-upstream-url: "http://localhost:3000"
|
|
```
|
|
|
|
**OIDC mode**:
|
|
```yaml
|
|
policies.forteapps.io/auth: "true"
|
|
policies.forteapps.io/auth-type: "oidc"
|
|
policies.forteapps.io/auth-oidc-authority: "https://keycloak.forteapps.net/realms/master"
|
|
policies.forteapps.io/auth-oidc-client-id: "myapp"
|
|
policies.forteapps.io/auth-oidc-scopes: "openid,profile,email"
|
|
policies.forteapps.io/auth-oidc-callback-path: "/auth/callback"
|
|
policies.forteapps.io/auth-upstream-url: "http://localhost:3000"
|
|
```
|
|
|
|
**MCP mode** (OAuth 2.0 for MCP servers):
|
|
```yaml
|
|
policies.forteapps.io/auth: "true"
|
|
policies.forteapps.io/auth-type: "mcp"
|
|
policies.forteapps.io/auth-mcp-resource: "https://mcp.forteapps.net"
|
|
policies.forteapps.io/auth-mcp-authority: "https://keycloak.forteapps.net/realms/master"
|
|
policies.forteapps.io/auth-mcp-scopes: "read,write"
|
|
policies.forteapps.io/auth-upstream-url: "http://localhost:3000"
|
|
```
|
|
|
|
#### Sidecar Configuration
|
|
|
|
The auth sidecar container:
|
|
- **Image**: `ghcr.io/fortedigital/auth-sidecar:latest`
|
|
- **Port**: 8080
|
|
- **Resources**: 10m CPU / 32Mi memory (requests), 50m CPU / 64Mi memory (limits)
|
|
- **Health checks**: `/healthz` endpoint
|
|
- **Security**: Read-only root filesystem, no privilege escalation
|
|
|
|
#### Advanced: Custom Sidecar Image
|
|
|
|
To use a different auth sidecar image:
|
|
|
|
```yaml
|
|
# These annotations can be set in the Helm chart template if needed
|
|
policies.forteapps.io/auth-image: "your-registry/your-auth-proxy"
|
|
policies.forteapps.io/auth-image-version: "v1.2.3"
|
|
```
|
|
|
|
---
|
|
|
|
### Authentication Examples
|
|
|
|
#### Example 1: Internal API with Token Auth
|
|
|
|
```yaml
|
|
# helm-prod-values/internal-api/values.yaml
|
|
app:
|
|
image:
|
|
repository: ghcr.io/company/internal-api
|
|
tag: v1.0.0
|
|
|
|
auth:
|
|
enabled: true
|
|
type: token
|
|
tokens:
|
|
- d4f88f6d9292c10cc3e21c4aad56d2be485db532b54fe961d738e1137d247823 # Service A
|
|
- 8803f621acc3898df1d7a8f514bc3602551a0681a8f747bd4e43c3c5849d57a7 # Service B
|
|
|
|
ingress:
|
|
enabled: true
|
|
host: internal-api.forteapps.net
|
|
```
|
|
|
|
**Usage**:
|
|
```bash
|
|
# Service A calls API
|
|
curl -H "Authorization: Bearer d4f88f..." \
|
|
https://internal-api.forteapps.net/api/endpoint
|
|
```
|
|
|
|
#### Example 2: User-Facing App with OIDC
|
|
|
|
```yaml
|
|
# helm-prod-values/web-app/values.yaml
|
|
app:
|
|
image:
|
|
repository: ghcr.io/company/web-app
|
|
tag: v2.1.0
|
|
|
|
auth:
|
|
enabled: true
|
|
type: oidc
|
|
oidc:
|
|
authority: https://auth.company.com/realms/employees
|
|
clientId: web-app-prod
|
|
scopes: "openid,profile,email,groups"
|
|
callbackPath: /auth/callback
|
|
|
|
ingress:
|
|
enabled: true
|
|
host: web-app.forteapps.net
|
|
```
|
|
|
|
**With sealed OIDC secret**:
|
|
```bash
|
|
# Create and seal secret
|
|
kubectl create secret generic auth-oidc \
|
|
--from-literal=client-secret=super-secret-value \
|
|
--from-literal=cookie-secret=$(openssl rand -hex 32) \
|
|
--namespace=web-app \
|
|
--dry-run=client -o yaml | \
|
|
kubeseal --format=yaml --cert=pub-cert.pem --namespace=web-app \
|
|
> secrets/web-app-auth-oidc-sealed.yaml
|
|
```
|
|
|
|
#### Example 3: MCP Server with OAuth 2.0
|
|
|
|
```yaml
|
|
# helm-prod-values/mcp-server/values.yaml
|
|
app:
|
|
image:
|
|
repository: ghcr.io/company/mcp-server
|
|
tag: v1.0.0
|
|
|
|
auth:
|
|
enabled: true
|
|
type: mcp
|
|
mcp:
|
|
resource: https://mcp-server.forteapps.net
|
|
authority: https://auth.company.com/realms/mcp
|
|
scopes: "read,write,admin"
|
|
|
|
ingress:
|
|
enabled: true
|
|
host: mcp-server.forteapps.net
|
|
```
|
|
|
|
The MCP auth mode implements RFC 9728 (OAuth 2.0 Protected Resource Metadata) for authorization server discovery. Dynamic Client Registration (RFC 7591) is handled natively by Keycloak; MCP clients discover the authorization server and scopes from the `/.well-known/oauth-protected-resource` endpoint served by the sidecar and then register directly with Keycloak.
|
|
|
|
#### Example 4: Disabling Authentication
|
|
|
|
```yaml
|
|
# helm-prod-values/public-api/values.yaml
|
|
auth:
|
|
enabled: false # No authentication
|
|
|
|
ingress:
|
|
enabled: true
|
|
host: public-api.forteapps.net
|
|
```
|
|
|
|
---
|
|
|
|
### Troubleshooting Authentication
|
|
|
|
#### Issue: 401 Unauthorized (Token Mode)
|
|
|
|
**Check token validity**:
|
|
```bash
|
|
# Get auth-tokens secret
|
|
kubectl get secret auth-tokens -n myapp -o yaml
|
|
|
|
# Decode tokens
|
|
kubectl get secret auth-tokens -n myapp \
|
|
-o jsonpath='{.data.tokens}' | base64 -d
|
|
|
|
# Verify your token is in the list
|
|
```
|
|
|
|
**Test with different token**:
|
|
```bash
|
|
curl -v -H "Authorization: Bearer YOUR-TOKEN-HERE" \
|
|
https://myapp.forteapps.net/
|
|
```
|
|
|
|
#### Issue: OIDC Login Loop
|
|
|
|
**Check OIDC configuration**:
|
|
```bash
|
|
# Verify auth-oidc secret exists
|
|
kubectl get secret auth-oidc -n myapp
|
|
|
|
# Check sidecar logs
|
|
kubectl logs -n myapp <pod-name> -c authn
|
|
|
|
# Common issues:
|
|
# - Wrong authority URL
|
|
# - Wrong client ID
|
|
# - Missing client-secret in auth-oidc Secret
|
|
# - Redirect URI not configured in identity provider
|
|
```
|
|
|
|
**Verify redirect URI** in your identity provider matches:
|
|
```
|
|
https://<your-app-domain>/auth/callback
|
|
```
|
|
|
|
#### Issue: Auth Sidecar Not Injected
|
|
|
|
**Check pod annotations**:
|
|
```bash
|
|
kubectl get pod -n myapp <pod-name> -o yaml | grep policies.forteapps.io
|
|
|
|
# Should show:
|
|
# policies.forteapps.io/auth: "true"
|
|
```
|
|
|
|
**Check Kyverno policy**:
|
|
```bash
|
|
kubectl get clusterpolicy inject-auth-sidecar
|
|
kubectl describe clusterpolicy inject-auth-sidecar
|
|
```
|
|
|
|
**Check Kyverno logs**:
|
|
```bash
|
|
kubectl logs -n kyverno deployment/kyverno | grep inject-auth
|
|
```
|
|
|
|
#### Issue: Auth Sidecar Crashes
|
|
|
|
**Check sidecar logs**:
|
|
```bash
|
|
kubectl logs -n myapp <pod-name> -c authn
|
|
```
|
|
|
|
**Common causes**:
|
|
- Missing secret (auth-tokens or auth-oidc)
|
|
- Invalid OIDC configuration
|
|
- Can't reach OIDC authority URL
|
|
- Network policy blocking outbound OIDC requests
|
|
|
|
---
|
|
|
|
### Authentication Best Practices
|
|
|
|
✅ **DO**:
|
|
- Use OIDC for user-facing applications
|
|
- Use token auth for service-to-service communication
|
|
- Rotate tokens and secrets regularly
|
|
- Use strong random tokens (32+ bytes)
|
|
- Store client secrets in SealedSecrets
|
|
- Test authentication before deploying to production
|
|
- Document which tokens/users have access
|
|
|
|
❌ **DON'T**:
|
|
- Share tokens between environments
|
|
- Commit tokens to application code
|
|
- Use predictable tokens
|
|
- Reuse tokens across multiple applications
|
|
- Disable authentication on sensitive APIs
|
|
- Log tokens or secrets
|
|
|
|
---
|
|
|
|
## Adding a New Keycloak Client
|
|
|
|
There are two ways to add an OIDC client, depending on your use case:
|
|
|
|
| Method | Best for | Who edits the infra repo? |
|
|
|--------|----------|--------------------------|
|
|
| **Self-service** (recommended) | New apps that deploy their own resources | App developer — no infra changes needed |
|
|
| **Legacy (realm JSON)** | Existing clients already defined in forte-realm.json (e.g., Gitea) | Platform engineer |
|
|
|
|
Both methods are served by the **Keycloak Client Registrar** CronJob, which runs every 2 minutes.
|
|
|
|
### Self-Service OIDC Client Registration
|
|
|
|
This is the recommended flow for new applications. Your app deploys a labeled config Secret in its own namespace; the platform handles everything else.
|
|
|
|
#### How It Works
|
|
|
|
1. You deploy a Secret with label `keycloak.forteapps.net/client-config: "true"` containing a `client.json` definition
|
|
2. A **Kyverno ClusterPolicy** (`keycloak-client-config-cloner`) clones it to the `keycloak` namespace
|
|
3. The **Client Registrar CronJob** picks it up within 2 minutes:
|
|
- Registers (or updates) the client in Keycloak
|
|
- Fetches the auto-generated client secret
|
|
- Creates a credential Secret in your app's namespace
|
|
- Annotates the config Secret with sync status
|
|
|
|
#### Step 1: Create the Config Secret
|
|
|
|
Deploy this Secret in your application's namespace (e.g., as part of your Helm chart or Kustomize overlay):
|
|
|
|
```yaml
|
|
apiVersion: v1
|
|
kind: Secret
|
|
metadata:
|
|
name: keycloak-client-myapp
|
|
namespace: myapp
|
|
labels:
|
|
keycloak.forteapps.net/client-config: "true"
|
|
stringData:
|
|
client.json: |
|
|
{
|
|
"clientId": "myapp",
|
|
"name": "My Application",
|
|
"redirectUris": ["https://myapp.forteapps.net/*"],
|
|
"webOrigins": ["https://myapp.forteapps.net"],
|
|
"defaultClientScopes": ["openid", "email", "profile"],
|
|
"protocolMappers": [],
|
|
"secret": {
|
|
"namespace": "myapp",
|
|
"name": "myapp-oidc-credentials",
|
|
"keys": { "clientId": "client-id", "clientSecret": "client-secret" }
|
|
}
|
|
}
|
|
```
|
|
|
|
**`client.json` fields**:
|
|
|
|
| Field | Required | Description |
|
|
|-------|----------|-------------|
|
|
| `clientId` | Yes | Keycloak client ID (must be unique in realm) |
|
|
| `name` | Yes | Display name in Keycloak UI |
|
|
| `redirectUris` | Yes | Allowed OAuth redirect URLs (supports wildcards like `/*`) |
|
|
| `webOrigins` | Yes | Allowed CORS origins |
|
|
| `defaultClientScopes` | No | OIDC scopes (default: `["openid", "email", "profile"]`) |
|
|
| `protocolMappers` | No | Custom claim mappers for tokens (see examples below) |
|
|
| `secret.namespace` | No | Target namespace for credentials (default: `source-namespace` annotation value) |
|
|
| `secret.name` | No | Credential Secret name (default: `<clientId>-oidc-credentials`) |
|
|
| `secret.keys.clientId` | No | Key name for client ID (default: `client-id`) |
|
|
| `secret.keys.clientSecret` | No | Key name for client secret (default: `client-secret`) |
|
|
|
|
**Protocol Mappers Example**:
|
|
```json
|
|
"protocolMappers": [
|
|
{
|
|
"name": "groups",
|
|
"protocol": "openid-connect",
|
|
"protocolMapper": "oidc-group-membership-mapper",
|
|
"config": {
|
|
"claim.name": "groups",
|
|
"full.path": "false",
|
|
"id.token.claim": "true",
|
|
"access.token.claim": "true",
|
|
"userinfo.token.claim": "true"
|
|
}
|
|
}
|
|
]
|
|
```
|
|
|
|
#### Step 2: Reference the Credential Secret
|
|
|
|
In your application's deployment config, reference the credential Secret that the registrar creates:
|
|
|
|
```yaml
|
|
env:
|
|
- name: OIDC_CLIENT_ID
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: myapp-oidc-credentials
|
|
key: client-id
|
|
- name: OIDC_CLIENT_SECRET
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: myapp-oidc-credentials
|
|
key: client-secret
|
|
```
|
|
|
|
#### Step 3: Deploy and Wait
|
|
|
|
Commit and push your changes. The credential Secret will appear within 2 minutes:
|
|
|
|
```bash
|
|
# Watch for the credential Secret to be created
|
|
kubectl get secret myapp-oidc-credentials -n myapp -w
|
|
|
|
# Check registrar logs
|
|
kubectl logs -n keycloak job/$(kubectl get jobs -n keycloak --sort-by=.metadata.creationTimestamp -o jsonpath='{.items[-1].metadata.name}')
|
|
|
|
# Check sync status on the config Secret
|
|
kubectl get secret keycloak-client-myapp -n keycloak -o jsonpath='{.metadata.annotations}'
|
|
```
|
|
|
|
#### Change Detection
|
|
|
|
The registrar computes a SHA-256 hash of `client.json` and stores it as an annotation. On subsequent runs, it skips processing if:
|
|
- The hash hasn't changed, AND
|
|
- The credential Secret already exists in the target namespace
|
|
|
|
To force a re-sync, update any field in `client.json` (e.g., add a trailing space to `name`).
|
|
|
|
### Legacy Method: Realm JSON
|
|
|
|
Existing clients (like Gitea) are defined directly in `forte-realm.json` inside `keycloak-values.yaml`. The registrar syncs their secrets via client attributes.
|
|
|
|
#### Step 1: Add Client to Realm Config
|
|
|
|
In `infra/values/base/keycloak-values.yaml`, add a new entry to the `clients` array in `forte-realm.json`:
|
|
|
|
```json
|
|
{
|
|
"clientId": "myapp",
|
|
"name": "My Application",
|
|
"enabled": true,
|
|
"protocol": "openid-connect",
|
|
"clientAuthenticatorType": "client-secret",
|
|
"standardFlowEnabled": true,
|
|
"directAccessGrantsEnabled": false,
|
|
"publicClient": false,
|
|
"redirectUris": ["https://myapp.forteapps.net/*"],
|
|
"webOrigins": ["https://myapp.forteapps.net"],
|
|
"defaultClientScopes": ["openid", "email", "profile"],
|
|
"attributes": {
|
|
"k8s.secret.sync": "true",
|
|
"k8s.secret.namespace": "myapp",
|
|
"k8s.secret.name": "myapp-oidc-credentials",
|
|
"k8s.secret.client-id-key": "key",
|
|
"k8s.secret.client-secret-key": "secret"
|
|
}
|
|
}
|
|
```
|
|
|
|
**Important**:
|
|
- Do **NOT** include a `"secret"` field — Keycloak generates one automatically
|
|
- The `attributes` block tells the registrar where to create the K8s Secret
|
|
- Set `client-id-key` / `client-secret-key` to match what the consuming app expects (defaults: `client-id` / `client-secret`)
|
|
|
|
#### Step 2: Reference the Secret in Your Application
|
|
|
|
```yaml
|
|
existingSecret: myapp-oidc-credentials
|
|
```
|
|
|
|
#### Step 3: Commit and Push
|
|
|
|
```bash
|
|
cd ~/dev/k8s/launchpad
|
|
git add infra/values/base/keycloak-values.yaml
|
|
git commit -m "Add myapp Keycloak client with auto-sync"
|
|
git push
|
|
```
|
|
|
|
ArgoCD will sync the Keycloak config, and the registrar CronJob will pick up the new client within 2 minutes.
|
|
|
|
#### Legacy Sync Attribute Reference
|
|
|
|
| Attribute | Required | Default | Description |
|
|
|-----------|----------|---------|-------------|
|
|
| `k8s.secret.sync` | Yes | — | Set to `"true"` to enable syncing |
|
|
| `k8s.secret.namespace` | Yes | — | Target K8s namespace for the secret |
|
|
| `k8s.secret.name` | Yes | — | Name of the K8s Secret to create |
|
|
| `k8s.secret.client-id-key` | No | `client-id` | Field name for the client ID in the K8s Secret |
|
|
| `k8s.secret.client-secret-key` | No | `client-secret` | Field name for the client secret in the K8s Secret |
|
|
|
|
#### Public CLI Client (Device-Code Login)
|
|
|
|
`forte-cli` is a shared **public** client (no secret) with the RFC 8628 device-authorization grant enabled (`oauth2.device.authorization.grant.enabled: "true"`, `standardFlowEnabled: false`, `directAccessGrantsEnabled: false`). Downloaded skills and CLI tools that log in through the Auth Sidecar (forte-drop first) use it with `<PREFIX>_CLIENT_ID=forte-cli`; nothing per-tool needs to be registered in Keycloak.
|
|
|
|
It must be defined in `forte-realm.json` (this legacy path): the self-service registrar hardcodes `publicClient: false` / `standardFlowEnabled: true` and drops `attributes`, so a `client-config` Secret cannot produce a public device-code client. It carries no `k8s.secret.sync` attribute (the registrar's secret sync skips it) and is listed in the cleanup CronJob's protected clients.
|
|
|
|
### Retrieving Secrets for External Deployments
|
|
|
|
The registrar always writes a **central copy** of every synced secret to the `secrets` namespace, in addition to the target namespace. This allows operators to retrieve client credentials for applications deployed outside this cluster:
|
|
|
|
```bash
|
|
# View the central copy
|
|
kubectl get secret gitea-oidc-credentials -n secrets -o yaml
|
|
|
|
# Extract the client secret for use elsewhere
|
|
kubectl get secret myapp-oidc-credentials -n secrets \
|
|
-o jsonpath='{.data.client-secret}' | base64 -d
|
|
```
|
|
|
|
### Registrar Behavior Notes
|
|
|
|
- The registrar runs as a CronJob every 2 minutes (`concurrencyPolicy: Forbid`)
|
|
- If the target namespace doesn't exist, the target write is skipped with a warning (the central copy still happens)
|
|
- A central copy is **always** written to the `secrets` namespace for every synced client
|
|
- The registrar uses the `keycloak-credentials` secret for admin authentication
|
|
- Created secrets have the label `app.kubernetes.io/managed-by: keycloak-client-registrar`
|
|
|
|
---
|
|
|
|
## Troubleshooting
|
|
|
|
### Application Not Deploying
|
|
|
|
#### Problem: Application stuck in "Syncing" state
|
|
|
|
**Check ArgoCD status:**
|
|
```bash
|
|
kubectl get application myapp -n argocd -o yaml
|
|
```
|
|
|
|
Look for errors in `status.conditions`.
|
|
|
|
**Common causes:**
|
|
- ❌ Image doesn't exist or is not accessible
|
|
- ❌ Invalid YAML syntax
|
|
- ❌ Resource quota exceeded
|
|
- ❌ Namespace conflicts
|
|
- ❌ Invalid Helm values
|
|
|
|
**Solutions:**
|
|
```bash
|
|
# Check image exists
|
|
docker pull ghcr.io/fortedigital/myapp:v1.0.0
|
|
|
|
# Validate YAML syntax
|
|
kubectl apply --dry-run=client -f apps/myapp.yaml
|
|
|
|
# Check ArgoCD logs
|
|
kubectl logs -n argocd deployment/argocd-application-controller | grep myapp
|
|
```
|
|
|
|
#### Problem: Pods crashing (CrashLoopBackOff)
|
|
|
|
**Check pod logs:**
|
|
```bash
|
|
kubectl get pods -n myapp
|
|
kubectl logs -n myapp <pod-name>
|
|
kubectl describe pod -n myapp <pod-name>
|
|
```
|
|
|
|
**Common causes:**
|
|
- ❌ Application error (check logs)
|
|
- ❌ Missing environment variables
|
|
- ❌ Incorrect port configuration
|
|
- ❌ Missing secrets
|
|
- ❌ Insufficient resources
|
|
|
|
**Solutions:**
|
|
```bash
|
|
# Check environment variables
|
|
kubectl exec -n myapp <pod-name> -- env
|
|
|
|
# Check if secrets exist
|
|
kubectl get secrets -n myapp
|
|
|
|
# Increase resources in helm-prod-values
|
|
vim ~/dev/k8s/helm-prod-values/myapp/values.yaml
|
|
```
|
|
|
|
#### Problem: Application not accessible via domain
|
|
|
|
**Check ingress:**
|
|
```bash
|
|
kubectl get ingressroute -n myapp
|
|
kubectl describe ingressroute myapp -n myapp
|
|
```
|
|
|
|
**Common causes:**
|
|
- ❌ DNS not configured
|
|
- ❌ TLS certificate not issued
|
|
- ❌ Incorrect domain in values.yaml
|
|
- ❌ Traefik not routing correctly
|
|
|
|
**Solutions:**
|
|
```bash
|
|
# Check certificate
|
|
kubectl get certificate -n myapp
|
|
|
|
# Check cert-manager logs
|
|
kubectl logs -n cert-manager deployment/cert-manager
|
|
|
|
# Verify domain configuration
|
|
cat ~/dev/k8s/helm-prod-values/myapp/values.yaml | grep host
|
|
|
|
# Test with port-forward
|
|
kubectl port-forward -n myapp service/myapp 8080:3000
|
|
curl http://localhost:8080
|
|
```
|
|
|
|
### Secret Issues
|
|
|
|
#### Problem: Secret not found
|
|
|
|
**Check if SealedSecret exists:**
|
|
```bash
|
|
kubectl get sealedsecret -n myapp
|
|
kubectl get secret -n myapp
|
|
```
|
|
|
|
**Solutions:**
|
|
```bash
|
|
# Check if secret is in Git
|
|
ls -l secrets/myapp-credentials-sealed.yaml
|
|
|
|
# Re-apply sealed secret
|
|
kubectl apply -f secrets/myapp-credentials-sealed.yaml
|
|
|
|
# Check sealed-secrets-controller logs
|
|
kubectl logs -n kube-system deployment/sealed-secrets-controller
|
|
```
|
|
|
|
#### Problem: Secret exists but pods can't access it
|
|
|
|
**Check pod events:**
|
|
```bash
|
|
kubectl describe pod -n myapp <pod-name>
|
|
```
|
|
|
|
Look for: `Error: secret "myapp-credentials" not found`
|
|
|
|
**Solutions:**
|
|
```bash
|
|
# Verify secret name in values.yaml matches actual secret
|
|
cat ~/dev/k8s/helm-prod-values/myapp/values.yaml | grep envSecretName
|
|
kubectl get secrets -n myapp
|
|
|
|
# Restart pods
|
|
kubectl rollout restart deployment myapp -n myapp
|
|
```
|
|
|
|
### Sync Failures
|
|
|
|
#### Problem: ArgoCD shows "Out of Sync"
|
|
|
|
**Manual sync:**
|
|
```bash
|
|
# Using kubectl
|
|
kubectl patch application myapp -n argocd --type merge -p '{"operation":{"initiatedBy":{"username":"admin"},"sync":{"syncStrategy":{"hook":{}}}}}'
|
|
|
|
# Or via ArgoCD UI
|
|
# Click "Sync" button in UI
|
|
```
|
|
|
|
**Check what's different:**
|
|
```bash
|
|
kubectl get application myapp -n argocd -o yaml
|
|
```
|
|
|
|
Look at `status.sync.comparedTo` vs desired state.
|
|
|
|
#### Problem: Sync succeeds but application is "Degraded"
|
|
|
|
**Check resource health:**
|
|
```bash
|
|
kubectl get application myapp -n argocd -o jsonpath='{.status.resources[*].health}'
|
|
```
|
|
|
|
**Common causes:**
|
|
- ❌ Pods not ready
|
|
- ❌ Deployments not at desired replica count
|
|
- ❌ Jobs failed
|
|
|
|
**Solutions:**
|
|
```bash
|
|
# Check all resources in namespace
|
|
kubectl get all -n myapp
|
|
|
|
# Check pod events
|
|
kubectl get events -n myapp --sort-by='.lastTimestamp'
|
|
```
|
|
|
|
### Getting Help
|
|
|
|
If you're stuck:
|
|
|
|
1. **Check Slack notifications** - Error details are often in sync failure messages
|
|
2. **Check ArgoCD UI** - Visual representation of what's wrong
|
|
3. **Ask platform team** - They have full cluster access and can debug further
|
|
4. **Check documentation** - [Operations Runbook](OPERATIONS-RUNBOOK.md) has more troubleshooting
|
|
|
|
---
|
|
|
|
## Best Practices
|
|
|
|
### Development Workflow
|
|
|
|
✅ **DO**:
|
|
- Develop and test locally with Docker Compose
|
|
- Use semantic versioning for releases
|
|
- Write descriptive commit messages
|
|
- Test changes in a separate namespace first (if possible)
|
|
- Monitor Slack for deployment notifications
|
|
- Document environment variables and configuration
|
|
|
|
❌ **DON'T**:
|
|
- Push directly to production without testing
|
|
- Use `latest` tag for Docker images
|
|
- Bypass CI/CD for "quick fixes"
|
|
- Hard-code configuration values
|
|
- Ignore deployment failures
|
|
|
|
### Configuration Management
|
|
|
|
✅ **DO**:
|
|
- Keep configuration in `helm-prod-values` repository
|
|
- Use environment variables for config
|
|
- Document what each value does
|
|
- Use reasonable resource limits
|
|
- Enable ingress and TLS for public services
|
|
|
|
❌ **DON'T**:
|
|
- Hard-code config in application code
|
|
- Over-allocate resources (wastes money)
|
|
- Under-allocate resources (causes crashes)
|
|
- Use HTTP for production services
|
|
|
|
### Secret Management
|
|
|
|
✅ **DO**:
|
|
- Use kubeseal for all secrets
|
|
- Store plain secrets in password manager
|
|
- Rotate secrets regularly
|
|
- Use different secrets per environment
|
|
- Document what each secret contains
|
|
|
|
❌ **DON'T**:
|
|
- Commit plain secrets
|
|
- Share secrets in Slack/email
|
|
- Reuse secrets across apps
|
|
- Log secrets in application code
|
|
|
|
### Git Workflow
|
|
|
|
✅ **DO**:
|
|
- Use feature branches for changes
|
|
- Write clear commit messages
|
|
- Use pull requests for review
|
|
- Keep commits atomic and focused
|
|
- Tag releases in application repos
|
|
|
|
❌ **DON'T**:
|
|
- Push directly to `main` without review (for config repos)
|
|
- Make multiple unrelated changes in one commit
|
|
- Use vague commit messages ("fix", "update")
|
|
- Force-push to main branches
|
|
|
|
---
|
|
|
|
## Quick Reference
|
|
|
|
### Common Commands
|
|
|
|
```bash
|
|
# Check application status
|
|
kubectl get application myapp -n argocd
|
|
|
|
# View application details
|
|
kubectl describe application myapp -n argocd
|
|
|
|
# Check pods
|
|
kubectl get pods -n myapp
|
|
|
|
# View pod logs
|
|
kubectl logs -n myapp <pod-name>
|
|
|
|
# Restart deployment
|
|
kubectl rollout restart deployment myapp -n myapp
|
|
|
|
# Port-forward to service
|
|
kubectl port-forward -n myapp service/myapp 8080:3000
|
|
|
|
# Create secret
|
|
kubectl create secret generic myapp-credentials \
|
|
--from-literal=KEY=value \
|
|
--dry-run=client -o yaml > private/myapp-credentials.yaml
|
|
|
|
# Seal secret
|
|
kubeseal --format=yaml \
|
|
--cert=pub-cert.pem \
|
|
< private/myapp-credentials.yaml \
|
|
> secrets/myapp-credentials-sealed.yaml
|
|
```
|
|
|
|
### Repository Locations
|
|
|
|
```bash
|
|
# Config repository
|
|
cd ~/dev/k8s/launchpad
|
|
|
|
# Helm values repository
|
|
cd ~/dev/k8s/helm-prod-values
|
|
|
|
# Helm charts repository
|
|
cd ~/dev/k8s/forte-helm
|
|
```
|
|
|
|
### File Paths
|
|
|
|
```bash
|
|
# New application manifest
|
|
~/dev/k8s/launchpad/apps/myapp.yaml
|
|
|
|
# Application values
|
|
~/dev/k8s/helm-prod-values/myapp/values.yaml
|
|
|
|
# Sealed secrets
|
|
~/dev/k8s/launchpad/secrets/myapp-credentials-sealed.yaml
|
|
|
|
# Plain secrets (local only)
|
|
~/dev/k8s/launchpad/private/myapp-credentials.yaml
|
|
```
|
|
|
|
---
|
|
|
|
## Next Steps
|
|
|
|
Now that you understand the basics:
|
|
|
|
1. ✅ Deploy your first application (follow steps above)
|
|
2. 📖 Read the [Operations Runbook](OPERATIONS-RUNBOOK.md) for common tasks
|
|
3. 📖 Review [Technical Reference](REFERENCE.md) for detailed component docs
|
|
4. 📖 Understand [GitOps Architecture](GITOPS-ARCHITECTURE.md) for the big picture
|
|
5. 🚀 Start contributing!
|
|
|
|
---
|
|
|
|
**Questions?**
|
|
- Slack: #platform-support
|
|
- Docs: [Full documentation index](README.md)
|
|
- Help: Contact platform team
|
|
|
|
**Last Updated**: 2026-04-16
|