Files
launchpad/docs/DEVELOPER-GUIDE.md
T
danijel.simeunovic 4ab7ccd781 chore(deps): update terraform google to v8
commit c5e0aa6f3c
Author: gitea_admin <admin@forteapps.net>
Date:   Wed Oct 7 06:36:01 2026 +0000

    chore(deps): update nikitafilonov/ai-review docker tag to v1.4.0 (#59)

    This PR contains the following updates:

    | Package | Type | Update | Change |
    |---|---|---|---|
    | nikitafilonov/ai-review | docker | minor | `v1.1.0` → `v1.4.0` |

    ---

    ### Configuration

    📅 **Schedule**: (in timezone Europe/Oslo)

    - Branch creation
      - At any time (no schedule defined)
    - Automerge
      - At any time (no schedule defined)

    🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

    ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

    🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

    ---

     - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

    ---

    This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
    <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

    ---------

    Co-authored-by: Renovate Bot <renovate@forteapps.net>
    Reviewed-on: #59
    Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
    Co-authored-by: gitea_admin <admin@forteapps.net>

commit 7915346868
Author: gitea_admin <admin@forteapps.net>
Date:   Sun Oct 4 21:53:01 2026 +0000

    chore(deps): update gitea/gitea docker tag to v28 (#58)

    This PR contains the following updates:

    | Package | Update | Change |
    |---|---|---|
    | [gitea/gitea](https://github.com/go-gitea/gitea) | major | `1.27.3` → `28.0.0` |

    ---

    ### Release Notes

    <details>
    <summary>go-gitea/gitea (gitea/gitea)</summary>

    ### [`v28.0.0`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#2800---2026-09-30)

    [Compare Source](https://github.com/go-gitea/gitea/compare/v1.27.3...v28.0.0)

    - BREAKING
      - Fix(git)!: route Git network operations through an internal proxy and update egress settings ([#&#8203;39426](https://github.com/go-gitea/gitea/pull/39426))
      - Feat(actions)!: add RUN\_RETENTION\_DAYS to delete old action runs ([#&#8203;38855](https://github.com/go-gitea/gitea/pull/38855))

    - SECURITY
      - Fix(git): reject invalid and duplicate Git objects on push ([#&#8203;39472](https://github.com/go-gitea/gitea/pull/39472))
      - Fix(git)!: route Git network operations through an internal proxy and update egress settings ([#&#8203;39426](https://github.com/go-gitea/gitea/pull/39426))
      - Fix(ssh): identify presented public keys by fingerprint ([#&#8203;39423](https://github.com/go-gitea/gitea/pull/39423))
      - Fix(actions): keep cancelled and unapproved fork PR runs behind the approval gate ([#&#8203;39399](https://github.com/go-gitea/gitea/pull/39399))
      - Fix(deps): update golang.org/x/crypto SSH to address denial of service ([#&#8203;39219](https://github.com/go-gitea/gitea/pull/39219))
      - Fix(repo): enforce repository-scoped authorization for team access, deletion, and package unlinking ([#&#8203;39063](https://github.com/go-gitea/gitea/pull/39063))

    - FEATURES
      - Feat(actions): update actionslib, support `self:`, misc fixes ([#&#8203;39358](https://github.com/go-gitea/gitea/pull/39358))
      - Feat(api): list all packages for site administrators ([#&#8203;38968](https://github.com/go-gitea/gitea/pull/38968))
      - Feat: manage bot accounts from the admin UI, API and CLI ([#&#8203;38966](https://github.com/go-gitea/gitea/pull/38966))
      - Feat(user): Personal access tokens can be regenerated ([#&#8203;38907](https://github.com/go-gitea/gitea/pull/38907))
      - Feat(actions): support `$/` prefix in reusable workflow `uses:` ([#&#8203;38822](https://github.com/go-gitea/gitea/pull/38822))
      - Feat(actions): add force-cancel workflow run API ([#&#8203;38756](https://github.com/go-gitea/gitea/pull/38756))
      - Feat(licenses): support REUSE specification in licenses ([#&#8203;38720](https://github.com/go-gitea/gitea/pull/38720))
      - Feat(api): add project APIs ([#&#8203;38691](https://github.com/go-gitea/gitea/pull/38691))
      - Feat(webhook): fire repository event on repo rename ([#&#8203;38641](https://github.com/go-gitea/gitea/pull/38641))
      - Feat: admin impersonates a user ([#&#8203;38614](https://github.com/go-gitea/gitea/pull/38614))
      - Feat(actions): add build queue view ([#&#8203;38585](https://github.com/go-gitea/gitea/pull/38585))
      - Feat(setting): add shared \[redis] section as default for redis-backed subsystems ([#&#8203;38550](https://github.com/go-gitea/gitea/pull/38550))
      - Feat(repo): prioritize well-known READMEs and optimize discovery ([#&#8203;38532](https://github.com/go-gitea/gitea/pull/38532))
      - Feat(actions): implement adaptive auto-refresh for workflow runs list ([#&#8203;38329](https://github.com/go-gitea/gitea/pull/38329))
      - Feat(auth): add `disable-2fa` command ([#&#8203;38275](https://github.com/go-gitea/gitea/pull/38275))
      - Feat: Add audit logging ([#&#8203;38189](https://github.com/go-gitea/gitea/pull/38189))
      - Feat(repo): add quick repository switcher to repo header ([#&#8203;38188](https://github.com/go-gitea/gitea/pull/38188))
      - Feat(repo): support file exclusion logic in .gitea/template in template generation ([#&#8203;38064](https://github.com/go-gitea/gitea/pull/38064))
      - Feat(web): Add org removal functionality to admin user details page ([#&#8203;38013](https://github.com/go-gitea/gitea/pull/38013))
      - Feat: add watch options ([#&#8203;37571](https://github.com/go-gitea/gitea/pull/37571))
      - Feat: add deploy tokens ([#&#8203;37306](https://github.com/go-gitea/gitea/pull/37306))
      - Feat(diff): Add search and extension filter to diff sidebar ([#&#8203;37068](https://github.com/go-gitea/gitea/pull/37068))
      - Feat: Replace SSE with WebSocket for UI notifications ([#&#8203;36965](https://github.com/go-gitea/gitea/pull/36965))
      - Feat(actions): Add artifact preview in Actions run view ([#&#8203;36754](https://github.com/go-gitea/gitea/pull/36754))
      - Feat(packages): add support for uploading helm provenance files ([#&#8203;36695](https://github.com/go-gitea/gitea/pull/36695))
      - Feat: Add support for dynamic matrix evaluation in Gitea Actions workflows ([#&#8203;36564](https://github.com/go-gitea/gitea/pull/36564))
      - Feat: Add max-parallel Support for Gitea Actions ([#&#8203;36357](https://github.com/go-gitea/gitea/pull/36357))
      - Feat(actions): Add Actions API endpoints for workflow run management and logs ([#&#8203;35382](https://github.com/go-gitea/gitea/pull/35382))
      - Feat: Add block on pending codeowner reviews branch protection ([#&#8203;34995](https://github.com/go-gitea/gitea/pull/34995))

    - ENHANCEMENTS
      - Enhance: allow auto-closing PRs from PRs ([#&#8203;39393](https://github.com/go-gitea/gitea/pull/39393))
      - Enhance(actions): add pending job status and align job statuses with GitHub ([#&#8203;39376](https://github.com/go-gitea/gitea/pull/39376))
      - Enhance(acme): add configurable ACME profile ([#&#8203;39375](https://github.com/go-gitea/gitea/pull/39375))
      - Enhance(emoji): update to Unicode 17, unify and lazy-load emoji data ([#&#8203;39363](https://github.com/go-gitea/gitea/pull/39363))
      - Enhance: improve issue-pattern capture groups and support both internal\&external trackers enabled ([#&#8203;39354](https://github.com/go-gitea/gitea/pull/39354))
      - Enhance: update mermaid to v12 ([#&#8203;39331](https://github.com/go-gitea/gitea/pull/39331))
      - Enhance(notifications): mark current notification page as read ([#&#8203;39294](https://github.com/go-gitea/gitea/pull/39294))
      - Enhance: support `ETag` on streamed repository archives, support `If-None-Match: *` ([#&#8203;39289](https://github.com/go-gitea/gitea/pull/39289))
      - Enhance: truncate but show long lines in diffs ([#&#8203;39279](https://github.com/go-gitea/gitea/pull/39279))
      - Enhance(packages): implement npm single-version API and add per-version repository ([#&#8203;39267](https://github.com/go-gitea/gitea/pull/39267))
      - Enhance: move window\.config to JSON, improve CSP format ([#&#8203;39236](https://github.com/go-gitea/gitea/pull/39236))
      - Enhance: improve commit page header ([#&#8203;39229](https://github.com/go-gitea/gitea/pull/39229))
      - Enhance: Improve validation errors for secrets/variables ([#&#8203;39221](https://github.com/go-gitea/gitea/pull/39221))
      - Enhance(repo): check full repo name for dangerous operations ([#&#8203;39213](https://github.com/go-gitea/gitea/pull/39213))
      - Enhance(web): hide attachment dropzone on preview tab in combo editor ([#&#8203;39204](https://github.com/go-gitea/gitea/pull/39204))
      - Enhance(web): show attachment URL and UUID in dropzone preview ([#&#8203;39203](https://github.com/go-gitea/gitea/pull/39203))
      - Enhance(actions): make workflow dispatch choice dropdown support search ([#&#8203;39154](https://github.com/go-gitea/gitea/pull/39154))
      - Enhance(repo): unify diff stats on commit pages, misc diff tweaks ([#&#8203;39134](https://github.com/go-gitea/gitea/pull/39134))
      - Enhance: use browser's locale to detect week's first day for the contribution map ([#&#8203;38995](https://github.com/go-gitea/gitea/pull/38995))
      - Enhance(ui): forced colors mode enhancements ([#&#8203;38991](https://github.com/go-gitea/gitea/pull/38991))
      - Enhance: user-friendly packages setup manual ([#&#8203;38946](https://github.com/go-gitea/gitea/pull/38946))
      - Enhance: inherit team access for all units ([#&#8203;38938](https://github.com/go-gitea/gitea/pull/38938))
      - Enhance(admin): show impersonation banner and keep password change with the user ([#&#8203;38924](https://github.com/go-gitea/gitea/pull/38924))
      - Enhance(ui): tint toast backgrounds by level ([#&#8203;38919](https://github.com/go-gitea/gitea/pull/38919))
      - Enhance(repo): add default object format setting ([#&#8203;38877](https://github.com/go-gitea/gitea/pull/38877))
      - Enhance(actions): set ref\_protected in context ([#&#8203;38852](https://github.com/go-gitea/gitea/pull/38852))
      - Enhance(ui): restyle toasts ([#&#8203;38842](https://github.com/go-gitea/gitea/pull/38842))
      - Enhance: refine repo watching ([#&#8203;38835](https://github.com/go-gitea/gitea/pull/38835))
      - Enhance: fall back to DEFAULT\_TEMPLATE.md when style-specific template is missing ([#&#8203;38803](https://github.com/go-gitea/gitea/pull/38803))
      - Enhance(api): add GitHub-compatible /repos/{owner}/{repo}/commits/{ref} endpoint ([#&#8203;38770](https://github.com/go-gitea/gitea/pull/38770))
      - Enhance(api): expose file mode in contents API response ([#&#8203;38713](https://github.com/go-gitea/gitea/pull/38713))
      - Enhance(tls): use go's tls defaults ([#&#8203;38687](https://github.com/go-gitea/gitea/pull/38687))
      - Enhance(ui): improve luminance calculations ([#&#8203;38682](https://github.com/go-gitea/gitea/pull/38682))
      - Enhance(api): add `tag_filter` query parameter to release list API ([#&#8203;38681](https://github.com/go-gitea/gitea/pull/38681))
      - Enhance(actions): replace `ansi_up` with first-party code ([#&#8203;38619](https://github.com/go-gitea/gitea/pull/38619))
      - Enhance: keep status check list scrolled on merge box reload ([#&#8203;38597](https://github.com/go-gitea/gitea/pull/38597))
      - Enhance(actions): action view enhancements ([#&#8203;38594](https://github.com/go-gitea/gitea/pull/38594))
      - Enhance(ui): tweak tooltip style and misc fixes ([#&#8203;38524](https://github.com/go-gitea/gitea/pull/38524))
      - Enhance: improve e-mail templates ([#&#8203;38396](https://github.com/go-gitea/gitea/pull/38396))
      - Enhance(webhook): add reviewer name to MS Teams review request notifications ([#&#8203;38289](https://github.com/go-gitea/gitea/pull/38289))
      - Enhance: extend <video> tag allowed attributes ([#&#8203;38279](https://github.com/go-gitea/gitea/pull/38279))
      - Enhance(packages/npm): expand version metadata and support npm deprecate ([#&#8203;37890](https://github.com/go-gitea/gitea/pull/37890))

    - PERFORMANCE
      - Perf(references): scan only the keyword window before a reference ([#&#8203;39396](https://github.com/go-gitea/gitea/pull/39396))
      - Perf(frontend): enable vite module preload ([#&#8203;39332](https://github.com/go-gitea/gitea/pull/39332))
      - Perf(gitdiff): optimize inline diff highlighting using cache ([#&#8203;38706](https://github.com/go-gitea/gitea/pull/38706))

    - BUGFIXES
      - Fix(actions): preserve admitted jobs and runs in their concurrency group ([#&#8203;39461](https://github.com/go-gitea/gitea/pull/39461))
      - Fix(api): commit tree SHA is the commit ID ([#&#8203;39449](https://github.com/go-gitea/gitea/pull/39449))
      - Fix: PR merge ([#&#8203;39442](https://github.com/go-gitea/gitea/pull/39442))
      - Fix(actions): evaluate job-level `if:` before concurrency check ([#&#8203;39437](https://github.com/go-gitea/gitea/pull/39437))
      - Fix(api): allow pending-inline-comment-only reviews ([#&#8203;39433](https://github.com/go-gitea/gitea/pull/39433))
      - Fix: sanitize external render command line arguments ([#&#8203;39417](https://github.com/go-gitea/gitea/pull/39417))
      - Fix(LFS): recalculate repo LFSSize after gc-lfs removes orphaned data ([#&#8203;39406](https://github.com/go-gitea/gitea/pull/39406))
      - Fix(indexer): index full file paths and real offsets in bleve ([#&#8203;39405](https://github.com/go-gitea/gitea/pull/39405))
      - Fix(git): keep leading dashes in git grep search patterns ([#&#8203;39404](https://github.com/go-gitea/gitea/pull/39404))
      - Fix: use clearer message for ldap auth failure ([#&#8203;39392](https://github.com/go-gitea/gitea/pull/39392))
      - Fix(repo): commit page fails to render unsigned commits with a different committer ([#&#8203;39381](https://github.com/go-gitea/gitea/pull/39381))
      - Fix: focus confirm button and use red for delete confirmations ([#&#8203;39350](https://github.com/go-gitea/gitea/pull/39350))
      - Fix(migrations): preserve SHA-256 pull request commit IDs ([#&#8203;39343](https://github.com/go-gitea/gitea/pull/39343))
      - Fix(ui): misc ui fixes ([#&#8203;39336](https://github.com/go-gitea/gitea/pull/39336))
      - Fix(actions): use gitea's clock for actions durations ([#&#8203;39323](https://github.com/go-gitea/gitea/pull/39323))
      - Fix(actions): never show negative running durations ([#&#8203;39322](https://github.com/go-gitea/gitea/pull/39322))
      - Fix: package registry keypair creation race ([#&#8203;39319](https://github.com/go-gitea/gitea/pull/39319))
      - Fix: add default timeout and handle errors for HaveIBeenPwned API ([#&#8203;39316](https://github.com/go-gitea/gitea/pull/39316))
      - Fix(user): unify email validation for registration and settings ([#&#8203;39304](https://github.com/go-gitea/gitea/pull/39304))
      - Fix(ui): use button elements for branch and tag dropdown tabs ([#&#8203;39285](https://github.com/go-gitea/gitea/pull/39285))
      - Fix(auth): fix ssh and gpg key verification on windows ([#&#8203;39283](https://github.com/go-gitea/gitea/pull/39283))
      - Fix(feed): use meaningful lines as comment excerpt ([#&#8203;39276](https://github.com/go-gitea/gitea/pull/39276))
      - Fix(projects): allow max columns to the limit ([#&#8203;39272](https://github.com/go-gitea/gitea/pull/39272))
      - Fix: pass merge commit messages to git via stdin ([#&#8203;39269](https://github.com/go-gitea/gitea/pull/39269))
      - Fix(repo): surface unrelated histories on Sync Fork ([#&#8203;39258](https://github.com/go-gitea/gitea/pull/39258))
      - Fix: avoid nil panic and refactor some trivial problems ([#&#8203;39251](https://github.com/go-gitea/gitea/pull/39251))
      - Fix: restore missing blob file when re-publishing a package ([#&#8203;39239](https://github.com/go-gitea/gitea/pull/39239))
      - Fix(automerge): validate head commit before merge ([#&#8203;39235](https://github.com/go-gitea/gitea/pull/39235))
      - Fix(httplib): prevent leaking localhost:3000 in public links ([#&#8203;39217](https://github.com/go-gitea/gitea/pull/39217))
      - Fix(setting): honor bare -1 for timeout settings ([#&#8203;39181](https://github.com/go-gitea/gitea/pull/39181))
      - Fix: correct repo/attatchment absolute url and release layout ([#&#8203;39178](https://github.com/go-gitea/gitea/pull/39178))
      - Fix(web): populate the reason for "cannot commit to branch" in web editor commit form ([#&#8203;39155](https://github.com/go-gitea/gitea/pull/39155))
      - Fix(process): reap entire process group on cmd.Cancel ([#&#8203;39143](https://github.com/go-gitea/gitea/pull/39143))
      - Fix: recognize linguist language aliases ([#&#8203;39135](https://github.com/go-gitea/gitea/pull/39135))
      - Fix(repo): preserve transfer recipient collaboration ([#&#8203;39042](https://github.com/go-gitea/gitea/pull/39042))
      - Fix(db): make paginated database reads always require "order" option ([#&#8203;39017](https://github.com/go-gitea/gitea/pull/39017))
      - Fix: make local queue PopItem can be notified ([#&#8203;39011](https://github.com/go-gitea/gitea/pull/39011))
      - Fix: classify git failures on stderr, restrict migration failure detail ([#&#8203;39010](https://github.com/go-gitea/gitea/pull/39010))
      - Fix: allow re-requesting uncounted review approvals ([#&#8203;38988](https://github.com/go-gitea/gitea/pull/38988))
      - Fix(actions): allow larger scheduled workflows ([#&#8203;38985](https://github.com/go-gitea/gitea/pull/38985))
      - Fix: resolve actions commit status permission per repository ([#&#8203;38977](https://github.com/go-gitea/gitea/pull/38977))
      - Fix(deps): update module golang.org/x/image to v0.45.0 \[security] ([#&#8203;38930](https://github.com/go-gitea/gitea/pull/38930))
      - Fix(deps): update module golang.org/x/mod to v0.40.0 \[security] ([#&#8203;38914](https://github.com/go-gitea/gitea/pull/38914))
      - Fix: dedupe issue cross-reference timeline entries ([#&#8203;38881](https://github.com/go-gitea/gitea/pull/38881))
      - Fix(server): set `ReadHeaderTimeout` on HTTP servers ([#&#8203;38878](https://github.com/go-gitea/gitea/pull/38878))
      - Fix(repo): avoid a repo-sized temp file for every bundle download ([#&#8203;38863](https://github.com/go-gitea/gitea/pull/38863))
      - Fix(lfs): ensure lock listing paginates with a total order ([#&#8203;38850](https://github.com/go-gitea/gitea/pull/38850))
      - Fix(avatar): use sha256 and inline the federated avatar lookup ([#&#8203;38843](https://github.com/go-gitea/gitea/pull/38843))
      - Fix(gitdiff): render exact-limit diffs and zero-limit comments ([#&#8203;38838](https://github.com/go-gitea/gitea/pull/38838))
      - Fix(deps): update dependency mermaid to v11.16.1 \[security] ([#&#8203;38813](https://github.com/go-gitea/gitea/pull/38813))
      - Fix: misc fixes in pub/gpg/tests ([#&#8203;38809](https://github.com/go-gitea/gitea/pull/38809))
      - Fix: git diff blob excerpt ([#&#8203;38808](https://github.com/go-gitea/gitea/pull/38808))
      - Fix(packages): show error for duplicate cleanup rules [#&#8203;37820](https://github.com/go-gitea/gitea/issues/37820) ([#&#8203;38786](https://github.com/go-gitea/gitea/pull/38786))
      - Fix(actions): fix runner docs link ([#&#8203;38783](https://github.com/go-gitea/gitea/pull/38783))
      - Fix: git cache ([#&#8203;38763](https://github.com/go-gitea/gitea/pull/38763))
      - Fix(actions): evaluate each `${{ }}` part on its own ([#&#8203;38754](https://github.com/go-gitea/gitea/pull/38754))
      - Fix: don't report failed network requests as JavaScript errors ([#&#8203;38732](https://github.com/go-gitea/gitea/pull/38732))
      - Fix(gitdiff): prevent index out of range panic in GetLineTypeMarker ([#&#8203;38728](https://github.com/go-gitea/gitea/pull/38728))
      - Fix(api): document X-Total-Count instead of non-existent X-Total header ([#&#8203;38717](https://github.com/go-gitea/gitea/pull/38717))
      - Fix(actions): dynamic matrix expansion correctness fixes ([#&#8203;38690](https://github.com/go-gitea/gitea/pull/38690))
      - Fix(auth): record last sign-in on reverse proxy login ([#&#8203;38672](https://github.com/go-gitea/gitea/pull/38672))
      - Fix(api): accept fully-qualified refs in contents API ([#&#8203;38650](https://github.com/go-gitea/gitea/pull/38650))
      - Fix(deps): update module github.com/getkin/kin-openapi to v0.144.0 \[security] ([#&#8203;38623](https://github.com/go-gitea/gitea/pull/38623))
      - Fix(deps): update dependency js-yaml to v5.2.2 \[security] ([#&#8203;38622](https://github.com/go-gitea/gitea/pull/38622))
      - Fix: abort superseded issue suggestion requests ([#&#8203;38620](https://github.com/go-gitea/gitea/pull/38620))
      - Fix(issue): display error toast on batch action failures instead of reloading page ([#&#8203;38593](https://github.com/go-gitea/gitea/pull/38593))
      - Fix(deps): update module google.golang.org/grpc to v1.82.1 \[security] ([#&#8203;38567](https://github.com/go-gitea/gitea/pull/38567))
      - Fix(deps): update module github.com/google/go-github/v88 to v89 ([#&#8203;38433](https://github.com/go-gitea/gitea/pull/38433))
      - Fix(deps): update go dependencies ([#&#8203;38429](https://github.com/go-gitea/gitea/pull/38429))
      - Fix(deps): update go dependencies ([#&#8203;38346](https://github.com/go-gitea/gitea/pull/38346))
      - Fix(deps): update npm dependencies ([#&#8203;38342](https://github.com/go-gitea/gitea/pull/38342))
      - Fix(base): correct natural sort of numbers with leading zeros ([#&#8203;38163](https://github.com/go-gitea/gitea/pull/38163))
      - Fix(ui): avoid layout shifts in `overflow-menu` and repo filter ([#&#8203;37818](https://github.com/go-gitea/gitea/pull/37818))
      - Fix: make auth source group sync correctly handle team removal ([#&#8203;37161](https://github.com/go-gitea/gitea/pull/37161))
      - Fix(release): separate publication time from the release date ([#&#8203;36761](https://github.com/go-gitea/gitea/pull/36761))

    - TESTING
      - Test: stop tests from writing into `~/.ssh` ([#&#8203;39348](https://github.com/go-gitea/gitea/pull/39348))
      - Test(e2e): log out to switch users in pr-review test ([#&#8203;39328](https://github.com/go-gitea/gitea/pull/39328))
      - Test: release fixtures loader lock before database work ([#&#8203;39263](https://github.com/go-gitea/gitea/pull/39263))
      - Test: speed up tests, fix transaction bug ([#&#8203;39030](https://github.com/go-gitea/gitea/pull/39030))
      - Test: run frontend unit tests in browsers ([#&#8203;38860](https://github.com/go-gitea/gitea/pull/38860))
      - Test(pubsub): stop racing the Redis SUBSCRIBE ack ([#&#8203;38661](https://github.com/go-gitea/gitea/pull/38661))
      - Test(e2e): add pull request merge box test, update AGENTS.md ([#&#8203;38576](https://github.com/go-gitea/gitea/pull/38576))
      - Test(e2e): deterministically wait for event stream in logout propagation test ([#&#8203;38535](https://github.com/go-gitea/gitea/pull/38535))

    - BUILD
      - Refactor: fix `go vet` errors related to composite literals ([#&#8203;39341](https://github.com/go-gitea/gitea/pull/39341))
      - Build(gogit): disable gogit builds for stable releases ([#&#8203;39324](https://github.com/go-gitea/gitea/pull/39324))
      - Refactor: replace jquery.are-you-sure with first-party code ([#&#8203;39233](https://github.com/go-gitea/gitea/pull/39233))
      - Refactor: http request binding ([#&#8203;38971](https://github.com/go-gitea/gitea/pull/38971))
      - Refactor: clean up git repo and model migration packages ([#&#8203;38564](https://github.com/go-gitea/gitea/pull/38564))
      - Refactor: prepare to decouple the "model migration" package and "models" package ([#&#8203;38533](https://github.com/go-gitea/gitea/pull/38533))
      - Build: fix snapcraft release ([#&#8203;38260](https://github.com/go-gitea/gitea/pull/38260))
      - Build(release): use native golang toolchain for official release builds ([#&#8203;37828](https://github.com/go-gitea/gitea/pull/37828))

    - DOCS
      - Docs(webhook): review\.type comment lists values the webhook never sends ([#&#8203;39451](https://github.com/go-gitea/gitea/pull/39451))
      - Docs(api): document verification and files on the compare endpoint ([#&#8203;39440](https://github.com/go-gitea/gitea/pull/39440))
      - Docs(api): name the unadopted-repository search parameter query ([#&#8203;39370](https://github.com/go-gitea/gitea/pull/39370))
      - Docs: remove unused COOKIE\_USERNAME from app.example.ini ([#&#8203;39365](https://github.com/go-gitea/gitea/pull/39365))
      - Docs: document NOTICE\_ON\_SUCCESS for every cron task ([#&#8203;39352](https://github.com/go-gitea/gitea/pull/39352))
      - Docs: correct ALLOW\_LOCALNETWORKS description in app.example.ini ([#&#8203;39240](https://github.com/go-gitea/gitea/pull/39240))
      - Docs: fix typo in README about app.ini restart ([#&#8203;39223](https://github.com/go-gitea/gitea/pull/39223))
      - Docs: fix dead localization doc link in the READMEs ([#&#8203;39211](https://github.com/go-gitea/gitea/pull/39211))
      - Docs: Update CHANGELOG for release 1.27.3 ([#&#8203;39170](https://github.com/go-gitea/gitea/pull/39170))
      - Docs: Update CHANGELOG for version 1.27.2 ([#&#8203;38923](https://github.com/go-gitea/gitea/pull/38923))
      - Docs: Update PGP key expiration date to July 23, 2027 ([#&#8203;38747](https://github.com/go-gitea/gitea/pull/38747))
      - Docs(api): document 401/403 responses for user key endpoints ([#&#8203;38711](https://github.com/go-gitea/gitea/pull/38711))
      - Docs: Update Changelog for release v1.27.1 ([#&#8203;38670](https://github.com/go-gitea/gitea/pull/38670))
      - Docs: Update Changelog for 1.27 ([#&#8203;38440](https://github.com/go-gitea/gitea/pull/38440))
      - Docs: Update Security docs ([#&#8203;38422](https://github.com/go-gitea/gitea/pull/38422))

    - MISC
      - Refactor: make git http respond error message ([#&#8203;39390](https://github.com/go-gitea/gitea/pull/39390))
      - Refactor(api): convert bot accounts through the admin user edit endpoint ([#&#8203;39355](https://github.com/go-gitea/gitea/pull/39355))
      - Refactor: replace AWS SDK with a REST client for CodeCommit migration ([#&#8203;39330](https://github.com/go-gitea/gitea/pull/39330))
      - Refactor: replace Azure Blob SDK with a REST client ([#&#8203;39315](https://github.com/go-gitea/gitea/pull/39315))
      - Refactor: npm route handlers ([#&#8203;39275](https://github.com/go-gitea/gitea/pull/39275))
      - Refactor: GetDiffShortStat and fix panic caused by inconsistent "changed file number" ([#&#8203;39248](https://github.com/go-gitea/gitea/pull/39248))
      - Refactor(templates): update djlint to 1.46.0 and resolve its new findings ([#&#8203;39231](https://github.com/go-gitea/gitea/pull/39231))
      - Refactor: pagination/pager ([#&#8203;39162](https://github.com/go-gitea/gitea/pull/39162))
      - Refactor: share package registry error status classification ([#&#8203;39133](https://github.com/go-gitea/gitea/pull/39133))
      - Refactor: drop two unmaintained dependencies, rename the byte size helpers ([#&#8203;39083](https://github.com/go-gitea/gitea/pull/39083))
      - Refactor(automerge): fix error handling, populate recent automerge tasks on restart ([#&#8203;39001](https://github.com/go-gitea/gitea/pull/39001))
      - Refactor: deploy key and private route handlers ([#&#8203;38999](https://github.com/go-gitea/gitea/pull/38999))
      - Refactor: wiki edit form ([#&#8203;38918](https://github.com/go-gitea/gitea/pull/38918))
      - Refactor: clean up form binding & validation ([#&#8203;38873](https://github.com/go-gitea/gitea/pull/38873))
      - Refactor: markup render ([#&#8203;38864](https://github.com/go-gitea/gitea/pull/38864))
      - Refactor: api token scope check ([#&#8203;38862](https://github.com/go-gitea/gitea/pull/38862))
      - Refactor: replace `gliderlabs/ssh` with `golang.org/x/crypto/ssh` ([#&#8203;38837](https://github.com/go-gitea/gitea/pull/38837))
      - Refactor: form binding validation ([#&#8203;38832](https://github.com/go-gitea/gitea/pull/38832))
      - Refactor: prepare vue components for vapor mode ([#&#8203;38798](https://github.com/go-gitea/gitea/pull/38798))
      - Refactor: use the shared workflow model from actionslib ([#&#8203;38768](https://github.com/go-gitea/gitea/pull/38768))
      - Refactor(modelmigration): thread context through migration functions ([#&#8203;38758](https://github.com/go-gitea/gitea/pull/38758))
      - Refactor: migrate remaining Vue components to `<script setup>` ([#&#8203;38752](https://github.com/go-gitea/gitea/pull/38752))
      - Refactor: introduce trString for frontend ([#&#8203;38741](https://github.com/go-gitea/gitea/pull/38741))
      - Refactor(diff): drive diff DOM init from the global selector observer ([#&#8203;38740](https://github.com/go-gitea/gitea/pull/38740))
      - Refactor(git): clarify GetBranch behavior to make it only gets an existing branch ([#&#8203;38662](https://github.com/go-gitea/gitea/pull/38662))
      - Refactor: replace debounce/throttle deps with first-party code ([#&#8203;38610](https://github.com/go-gitea/gitea/pull/38610))
      - Refactor: hide git repo path details from more packages ([#&#8203;38601](https://github.com/go-gitea/gitea/pull/38601))
      - Refactor: retry file remove/rename when a file is busy and clean up os detection ([#&#8203;38588](https://github.com/go-gitea/gitea/pull/38588))
      - Perf(emoji): optimize FindEmojiSubmatchIndex using slice-based Trie ([#&#8203;38573](https://github.com/go-gitea/gitea/pull/38573))
      - Refactor: implement mcaptcha client and add comments/tests ([#&#8203;38561](https://github.com/go-gitea/gitea/pull/38561))
      - Refactor: use WithRepo instead of WithDir for most git operations, clean up model migrations ([#&#8203;38555](https://github.com/go-gitea/gitea/pull/38555))
      - Refactor: remove Path field from git.Repository ([#&#8203;38552](https://github.com/go-gitea/gitea/pull/38552))
      - Refactor: make git package handle all git operations ([#&#8203;38543](https://github.com/go-gitea/gitea/pull/38543))
      - Refactor: remove unnecessary git command wrapper functions ([#&#8203;38531](https://github.com/go-gitea/gitea/pull/38531))
      - Refactor: git repo and relative path handling ([#&#8203;38522](https://github.com/go-gitea/gitea/pull/38522))
      - Refactor: clean up fragile diff render templates, use backend typed structs ([#&#8203;38517](https://github.com/go-gitea/gitea/pull/38517))
      - Refactor: correct git repo design and fix some legacy problems ([#&#8203;38512](https://github.com/go-gitea/gitea/pull/38512))
      - Refactor: fix legacy problems in cmd/serv.go ([#&#8203;38505](https://github.com/go-gitea/gitea/pull/38505))
      - Refactor: remove Ctx field from git.Repository ([#&#8203;38500](https://github.com/go-gitea/gitea/pull/38500))
      - Refactor: decouple git.Repository(ctx) from git.Commit & git.Tree ([#&#8203;38464](https://github.com/go-gitea/gitea/pull/38464))
      - Refactor: introduce ActivePageTimer to help to do partial page refresh ([#&#8203;38372](https://github.com/go-gitea/gitea/pull/38372))

    </details>

    ---

    ### Configuration

    📅 **Schedule**: (in timezone Europe/Oslo)

    - Branch creation
      - At any time (no schedule defined)
    - Automerge
      - At any time (no schedule defined)

    🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

    ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

    🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

    ---

     - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

    ---

    This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
    <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

    ---------

    Co-authored-by: Renovate Bot <renovate@forteapps.net>
    Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/58
    Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
    Co-authored-by: gitea_admin <admin@forteapps.net>

commit 840c354ea3
Author: gitea_admin <admin@forteapps.net>
Date:   Sat Oct 3 18:55:31 2026 +0000

    chore(deps): update terraform azurerm to v5 (#55)

    This PR contains the following updates:

    | Package | Type | Update | Change | Pending |
    |---|---|---|---|---|
    | [azurerm](https://registry.terraform.io/providers/hashicorp/azurerm) ([source](https://github.com/hashicorp/terraform-provider-azurerm)) | required_provider | major | `~> 4.0` → `~> 5.0` | `5.8.0` |

    ---

    ### Release Notes

    <details>
    <summary>hashicorp/terraform-provider-azurerm (azurerm)</summary>

    ### [`v5.7.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#570-September-24-2026)

    [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.6.0...v5.7.0)

    FEATURES:

    - **New List Resource**: `azurerm_private_dns_resolver_forwarding_rule` ([#&#8203;33313](https://github.com/hashicorp/terraform-provider-azurerm/issues/33313))
    - **New List Resource**: `azurerm_windows_virtual_machine` ([#&#8203;33332](https://github.com/hashicorp/terraform-provider-azurerm/issues/33332))

    ENHANCEMENTS:

    - dependencies: `go-azure-sdk` - update to `v0.20260917.1142820` ([#&#8203;33495](https://github.com/hashicorp/terraform-provider-azurerm/issues/33495))
    - dependencies: `network` - update API version to `2025-07-01` ([#&#8203;33441](https://github.com/hashicorp/terraform-provider-azurerm/issues/33441))
    - Data Source: `azurerm_linux_web_app` - export the `virtual_network_image_pull_enabled` property ([#&#8203;33316](https://github.com/hashicorp/terraform-provider-azurerm/issues/33316))
    - Data Source: `azurerm_network_interface` - export the `auxiliary_mode`, `auxiliary_sku`, `edge_zone`, and `internal_domain_name_suffix` properties ([#&#8203;33204](https://github.com/hashicorp/terraform-provider-azurerm/issues/33204))
    - Data Source: `azurerm_public_ip` - export the `domain_name_label_scope`, `edge_zone`, `public_ip_prefix_id`, and `sku_tier` properties ([#&#8203;33193](https://github.com/hashicorp/terraform-provider-azurerm/issues/33193))
    - Data Source: `azurerm_service_plan` - export the `premium_plan_auto_scale_enabled` property ([#&#8203;33300](https://github.com/hashicorp/terraform-provider-azurerm/issues/33300))
    - Data Source: `azurerm_storage_blob` - export the `cache_control` and `source_uri` properties ([#&#8203;33318](https://github.com/hashicorp/terraform-provider-azurerm/issues/33318))
    - Data Source: `azurerm_traffic_manager_profile` - export the `maximum_return` property ([#&#8203;33346](https://github.com/hashicorp/terraform-provider-azurerm/issues/33346))
    - Data Source: `azurerm_web_pubsub` - export the `live_trace` and `identity` properties ([#&#8203;33373](https://github.com/hashicorp/terraform-provider-azurerm/issues/33373))
    - `azurerm_kubernetes_cluster_node_pool` - add `Windows2025` as a valid value for the `os_sku` property ([#&#8203;33463](https://github.com/hashicorp/terraform-provider-azurerm/issues/33463))
    - `azurerm_kubernetes_cluster` - add `Windows2025` as a valid value for the `os_sku` property ([#&#8203;33463](https://github.com/hashicorp/terraform-provider-azurerm/issues/33463))

    BUG FIXES:

    - Data Source: `azurerm_kubernetes_cluster` - fix a panic caused by a nil pointer dereference while flattening `agent_pool_profile` ([#&#8203;33488](https://github.com/hashicorp/terraform-provider-azurerm/issues/33488))
    - `azurerm_postgresql_flexible_server` - fix `cluster` block read for replica `create_mode` ([#&#8203;33082](https://github.com/hashicorp/terraform-provider-azurerm/issues/33082))

    ### [`v5.6.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#560-September-17-2026)

    [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.5.0...v5.6.0)

    FEATURES:

    - **New List Resource**: `azurerm_batch_account` ([#&#8203;33252](https://github.com/hashicorp/terraform-provider-azurerm/issues/33252))
    - **New List Resource**: `azurerm_cdn_frontdoor_origin_group` ([#&#8203;33334](https://github.com/hashicorp/terraform-provider-azurerm/issues/33334))
    - **New Resource**: `azurerm_storage_discovery_workspace` ([#&#8203;31479](https://github.com/hashicorp/terraform-provider-azurerm/issues/31479))

    ENHANCEMENTS:

    - dependencies: `containers` - update API version to `2026-05-01` ([#&#8203;32688](https://github.com/hashicorp/terraform-provider-azurerm/issues/32688))
    - dependencies: `go-azure-sdk` - update to `v0.20260910.1141000` ([#&#8203;33413](https://github.com/hashicorp/terraform-provider-azurerm/issues/33413))
    - dependencies: `qumulo` - update API version to `2026-04-16` ([#&#8203;33421](https://github.com/hashicorp/terraform-provider-azurerm/issues/33421))
    - dependencies: `servicebus` - update to API version `2026-01-01` ([#&#8203;33450](https://github.com/hashicorp/terraform-provider-azurerm/issues/33450))
    - `azurerm_iothub_device_update_instance` - add support for the `connection_string_wo` and `connection_string_wo_version` properties ([#&#8203;33448](https://github.com/hashicorp/terraform-provider-azurerm/issues/33448))
    - `azurerm_linux_function_app` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))
    - `azurerm_linux_function_app_slot` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))
    - `azurerm_linux_web_app` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))
    - `azurerm_linux_web_app_slot` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))
    - `azurerm_mongo_cluster` - Support new property `network_bypass_mode` ([#&#8203;33168](https://github.com/hashicorp/terraform-provider-azurerm/issues/33168))
    - `azurerm_servicebus_namespace` - add support for the `1.3` value to the `minimum_tls_version` property ([#&#8203;33457](https://github.com/hashicorp/terraform-provider-azurerm/issues/33457))
    - `azurerm_windows_function_app` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))
    - `azurerm_windows_function_app_slot` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))
    - `azurerm_windows_web_app` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))
    - `azurerm_windows_web_app_slot` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))

    BUG FIXES:

    - `azurerm_site_recovery_replicated_vm` - select `managed_disk` properties compared case insensitive ([#&#8203;33424](https://github.com/hashicorp/terraform-provider-azurerm/issues/33424))

    ### [`v5.5.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#550-September-10-2026)

    [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.4.0...v5.5.0)

    FEATURES:

    - **New List Resource**: `azurerm_analysis_services_server` ([#&#8203;33250](https://github.com/hashicorp/terraform-provider-azurerm/issues/33250))
    - **New List Resource**: `azurerm_application_insights_workbook` ([#&#8203;33244](https://github.com/hashicorp/terraform-provider-azurerm/issues/33244))
    - **New List Resource**: `azurerm_attestation_provider` ([#&#8203;33251](https://github.com/hashicorp/terraform-provider-azurerm/issues/33251))
    - **New List Resource**: `azurerm_cdn_frontdoor_origin` ([#&#8203;33307](https://github.com/hashicorp/terraform-provider-azurerm/issues/33307))
    - **New List Resource**: `azurerm_eventhub_consumer_group` ([#&#8203;33335](https://github.com/hashicorp/terraform-provider-azurerm/issues/33335))
    - **New List Resource**: `azurerm_linux_virtual_machine` ([#&#8203;33333](https://github.com/hashicorp/terraform-provider-azurerm/issues/33333))
    - **New List Resource**: `azurerm_virtual_hub_connection` ([#&#8203;33311](https://github.com/hashicorp/terraform-provider-azurerm/issues/33311))

    ENHANCEMENTS:

    - dependencies: `go-azure-sdk` - update to `v0.20260901.1173158` ([#&#8203;33274](https://github.com/hashicorp/terraform-provider-azurerm/issues/33274))
    - `azurerm_private_endpoint` - lock on private service connection resource ids ([#&#8203;33298](https://github.com/hashicorp/terraform-provider-azurerm/issues/33298))
    - `azurerm_storage_account` - add support for the `public_network_access` property ([#&#8203;33292](https://github.com/hashicorp/terraform-provider-azurerm/issues/33292))

    BUG FIXES:

    - `azurerm_resource_group` - the `managed_by` property now forces recreation when changed as the API does not support changing this value ([#&#8203;33339](https://github.com/hashicorp/terraform-provider-azurerm/issues/33339))
    - `go-azure-sdk` - `Delete` operations now poll on asynchronous operation URLs if returned by the API instead of only checking for a `404` on the resource URL, ensuring deletion errors are reported to the user ([#&#8203;33274](https://github.com/hashicorp/terraform-provider-azurerm/issues/33274))

    ### [`v5.4.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#540-September-03-2026)

    [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.3.0...v5.4.0)

    FEATURES:

    - **New List Resource**: `azurerm_application_insights_standard_web_test` ([#&#8203;33243](https://github.com/hashicorp/terraform-provider-azurerm/issues/33243))
    - **New List Resource**: `azurerm_application_insights_workbook_template` ([#&#8203;33245](https://github.com/hashicorp/terraform-provider-azurerm/issues/33245))
    - **New List Resource**: `azurerm_arc_kubernetes_provisioned_cluster` ([#&#8203;33247](https://github.com/hashicorp/terraform-provider-azurerm/issues/33247))
    - **New List Resource**: `azurerm_availability_set` ([#&#8203;33241](https://github.com/hashicorp/terraform-provider-azurerm/issues/33241))
    - **New List Resource**: `azurerm_batch_application` ([#&#8203;33254](https://github.com/hashicorp/terraform-provider-azurerm/issues/33254))
    - **New List Resource**: `azurerm_dedicated_host_group` ([#&#8203;33257](https://github.com/hashicorp/terraform-provider-azurerm/issues/33257))
    - **New List Resource**: `azurerm_log_analytics_workspace` ([#&#8203;33259](https://github.com/hashicorp/terraform-provider-azurerm/issues/33259))

    ENHANCEMENTS:

    - dependencies: `azurerm_mongo_cluster` - update API version to `2026-06-01` ([#&#8203;33195](https://github.com/hashicorp/terraform-provider-azurerm/issues/33195))
    - dependencies: `azurerm_mongo_cluster_firewall_rule` - update API version to `2026-06-01` ([#&#8203;33195](https://github.com/hashicorp/terraform-provider-azurerm/issues/33195))
    - dependencies: `azurerm_mongo_cluster_user` - update API version to `2026-06-01` ([#&#8203;33195](https://github.com/hashicorp/terraform-provider-azurerm/issues/33195))
    - dependencies: `netapp` - update API version to `2026-05-01` ([#&#8203;33215](https://github.com/hashicorp/terraform-provider-azurerm/issues/33215))
    - Data Source: `azurerm_api_management_workspace` - export the `description` property ([#&#8203;33205](https://github.com/hashicorp/terraform-provider-azurerm/issues/33205))
    - Data Source: `azurerm_attestation_provider` - export the `sev_snp_policy_base64`, `open_enclave_policy_base64`, `sgx_enclave_policy_base64`, and `tpm_policy_base64` properties ([#&#8203;33125](https://github.com/hashicorp/terraform-provider-azurerm/issues/33125))
    - Data Source: `azurerm_automation_account` - export the `dsc_primary_access_key`, `dsc_server_endpoint`, `dsc_secondary_access_key`, `public_network_access_enabled`, `sku_name`, and `tags` properties ([#&#8203;33135](https://github.com/hashicorp/terraform-provider-azurerm/issues/33135))
    - Data Source: `azurerm_automation_account` - export the `encryption` block ([#&#8203;33135](https://github.com/hashicorp/terraform-provider-azurerm/issues/33135))
    - Data Source: `azurerm_ip_group` - export the `firewall_ids` and `firewall_policy_ids` properties ([#&#8203;33190](https://github.com/hashicorp/terraform-provider-azurerm/issues/33190))
    - Data Source: `azurerm_private_link_service` - export the `fqdns` and `destination_ip_address` properties ([#&#8203;33191](https://github.com/hashicorp/terraform-provider-azurerm/issues/33191))
    - `azurerm_key_vault_managed_hardware_security_module_key` - allow the `key_size` property to be set when `key_type` is `oct-HSM` ([#&#8203;32690](https://github.com/hashicorp/terraform-provider-azurerm/issues/32690))
    - `azurerm_lb_probe ` - add support for the `no_healthy_backends_behavior` property ([#&#8203;32645](https://github.com/hashicorp/terraform-provider-azurerm/issues/32645))
    - `azurerm_linux_virtual_machine_scale_set` - add support for the `NvmeDisk` value to the `os_disk.diff_disk_settings.placement` property ([#&#8203;30328](https://github.com/hashicorp/terraform-provider-azurerm/issues/30328))
    - `azurerm_linux_web_app` - add support for the `8.5` value in the  `site_config.application_stack.php_version` property ([#&#8203;33308](https://github.com/hashicorp/terraform-provider-azurerm/issues/33308))
    - `azurerm_linux_web_app_slot` - add support for the `8.5` value in the  `site_config.application_stack.php_version` property ([#&#8203;33308](https://github.com/hashicorp/terraform-provider-azurerm/issues/33308))
    - `azurerm_netapp_volume` - support for the `breakthrough_mode_enabled` property ([#&#8203;33215](https://github.com/hashicorp/terraform-provider-azurerm/issues/33215))
    - `azurerm_postgresql_flexible_server` - add support for the `storage_type`, `storage_iops`, and `storage_throughput` properties which allows choice of the new "Premium V2 LRS" storage type ([#&#8203;32121](https://github.com/hashicorp/terraform-provider-azurerm/issues/32121))
    - `azurerm_storage_account` - add support for an in-place migration of `account_replication_type` between matching non-zonal and zonal types instead of resource recreation ([#&#8203;33236](https://github.com/hashicorp/terraform-provider-azurerm/issues/33236))
    - `azurerm_storage_table` - add support for AAD authentication ([#&#8203;32997](https://github.com/hashicorp/terraform-provider-azurerm/issues/32997))
    - `azurerm_synapse_spark_pool` - migrate to `go-azure-sdk` ([#&#8203;33258](https://github.com/hashicorp/terraform-provider-azurerm/issues/33258))
    - `azurerm_windows_virtual_machine_scale_set` - add support for the `NvmeDisk` value to the `os_disk.diff_disk_settings.placement` property ([#&#8203;30328](https://github.com/hashicorp/terraform-provider-azurerm/issues/30328))

    BUG FIXES:

    - `azurerm_synapse_spark_pool` - fix `lifecycle.ignore_changes` support ([#&#8203;33258](https://github.com/hashicorp/terraform-provider-azurerm/issues/33258))

    ### [`v5.3.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#530-August-27-2026)

    [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.2.0...v5.3.0)

    FEATURES:

    - **New Data Source**: `azurerm_playwright_workspace` ([#&#8203;31954](https://github.com/hashicorp/terraform-provider-azurerm/issues/31954))
    - **New List Resource**: `azurerm_cognitive_deployment` ([#&#8203;33149](https://github.com/hashicorp/terraform-provider-azurerm/issues/33149))
    - **New List Resource**: `azurerm_playwright_workspace` ([#&#8203;31954](https://github.com/hashicorp/terraform-provider-azurerm/issues/31954))
    - **New Resource**: `azurerm_playwright_workspace` ([#&#8203;31954](https://github.com/hashicorp/terraform-provider-azurerm/issues/31954))

    ENHANCEMENTS:

    - dependencies: `go-azure-helpers` - update version to `0.82.0` ([#&#8203;33142](https://github.com/hashicorp/terraform-provider-azurerm/issues/33142))
    - dependencies: `sql` - update API version to `2025-01-01` ([#&#8203;33201](https://github.com/hashicorp/terraform-provider-azurerm/issues/33201))
    - Data Source: `azurerm_role_definition` - export the `role_definition_resource_id` property ([#&#8203;33126](https://github.com/hashicorp/terraform-provider-azurerm/issues/33126))
    - `azurerm_cognitive_deployment` - add Resource Identity support ([#&#8203;33149](https://github.com/hashicorp/terraform-provider-azurerm/issues/33149))
    - `azurerm_federated_identity_credential` - add additional polling to account for Azure's eventual consistency ([#&#8203;32935](https://github.com/hashicorp/terraform-provider-azurerm/issues/32935))
    - `azurerm_kubernetes_cluster` - add support for the `oms_agent.retina_flow_logs_enabled` property ([#&#8203;33222](https://github.com/hashicorp/terraform-provider-azurerm/issues/33222))
    - `azurerm_managed_application` - add support for the `identity` block ([#&#8203;30725](https://github.com/hashicorp/terraform-provider-azurerm/issues/30725))
    - `azurerm_private_endpoint` - extend validation for the `private_service_connection.subresource_names` property to allow names containing spaces ([#&#8203;32887](https://github.com/hashicorp/terraform-provider-azurerm/issues/32887))
    - `azurerm_search_service` - allow in-place downgrades of the `sku` property between Basic and Standard tiers ([#&#8203;33069](https://github.com/hashicorp/terraform-provider-azurerm/issues/33069))
    - `azurerm_site_recovery_replicated_vm` - add update support to the `managed_disk` block without requiring resource recreation ([#&#8203;33140](https://github.com/hashicorp/terraform-provider-azurerm/issues/33140))
    - `azurerm_user_assigned_identity` - add additional polling to account for Azure's eventual consistency ([#&#8203;33142](https://github.com/hashicorp/terraform-provider-azurerm/issues/33142))

    BUG FIXES:

    - Data Source: `azurerm_app_configuration_key` - now correctly sets `tags` into state ([#&#8203;33182](https://github.com/hashicorp/terraform-provider-azurerm/issues/33182))
    - `azurerm_eventhub_namespace` - prevent `network_rulesets.x.default_action` being set to `Deny` if `ip_rule` or `virtual_network_rule` is not specified ([#&#8203;33216](https://github.com/hashicorp/terraform-provider-azurerm/issues/33216))

    ### [`v5.2.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#520-August-20-2026)

    [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.1.0...v5.2.0)

    FEATURES:

    - **New List Resource**: `azurerm_user_assigned_identity` ([#&#8203;32667](https://github.com/hashicorp/terraform-provider-azurerm/issues/32667))

    ENHANCEMENTS:

    - dependencies: `go` - update to `1.26.6` ([#&#8203;33141](https://github.com/hashicorp/terraform-provider-azurerm/issues/33141))
    - dependencies: `go-azure-sdk` - update to `v0.20260811.1225050` ([#&#8203;33079](https://github.com/hashicorp/terraform-provider-azurerm/issues/33079))
    - `azurerm_cdn_frontdoor_batch_rule_set` - allow `/` as an input to `rule.conditions.request_path.values` ([#&#8203;33023](https://github.com/hashicorp/terraform-provider-azurerm/issues/33023))
    - `azurerm_databricks_workspace` - remove a redundant key vault existence check ([#&#8203;33136](https://github.com/hashicorp/terraform-provider-azurerm/issues/33136))
    - `azurerm_databricks_workspace_root_dbfs_customer_managed_key` - remove a redundant key vault existence check ([#&#8203;33136](https://github.com/hashicorp/terraform-provider-azurerm/issues/33136))
    - `azurerm_logic_app_standard` - add support for `v10.0` to `site_config.dotnet_framework_version` ([#&#8203;33116](https://github.com/hashicorp/terraform-provider-azurerm/issues/33116))
    - `azurerm_mongo_cluster` - `administrator_password` is no longer required when `create_mode` is `Default` to support Entra ID-only authentication ([#&#8203;32092](https://github.com/hashicorp/terraform-provider-azurerm/issues/32092))
    - `azurerm_redhat_openshift_cluster` - add support for the `network_profile.load_balancer_profile` block ([#&#8203;32473](https://github.com/hashicorp/terraform-provider-azurerm/issues/32473))
    - `azurerm_redhat_openshift_cluster` - add support for the `platform_workload_identity_profile` block ([#&#8203;32473](https://github.com/hashicorp/terraform-provider-azurerm/issues/32473))
    - `azurerm_role_assignment` - the `condition`, `condition_version`, and `description` properties can now be updated in-place ([#&#8203;32714](https://github.com/hashicorp/terraform-provider-azurerm/issues/32714))
    - `azurerm_snapshot` - `create_option` now supports `CopyStart` ([#&#8203;32834](https://github.com/hashicorp/terraform-provider-azurerm/issues/32834))

    BUG FIXES:

    - `azurerm_cognitive_account_project` - added create/update/delete lock on parent AccountID to make sure operations on parent account are processed in serial (required by Cognitive service) ([#&#8203;33151](https://github.com/hashicorp/terraform-provider-azurerm/issues/33151))
    - `azurerm_databricks_workspace` - fix a persistent diff on removal of `managed_disk_cmk_key_vault_key_id` or `managed_services_cmk_key_vault_key_id` ([#&#8203;33136](https://github.com/hashicorp/terraform-provider-azurerm/issues/33136))
    - `azurerm_oracle_exadata_infrastructure` - fix an issue that prevented users from deploying with no `zones` set ([#&#8203;33011](https://github.com/hashicorp/terraform-provider-azurerm/issues/33011))

    ### [`v5.1.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#510-August-13-2026)

    [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.0.1...v5.1.0)

    ENHANCEMENTS:

    - dependencies: `azurerm_linux_virtual_machine_scale_set` - update to API version `2025-04-01` ([#&#8203;31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586))
    - dependencies: `azurerm_orchestrated_virtual_machine_scale_set` - update to API version `2025-04-01` ([#&#8203;31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586))
    - dependencies: `azurerm_virtual_machine_scale_set` - update to API version `2025-04-01` ([#&#8203;31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586))
    - dependencies: `azurerm_virtual_machine_scale_set_extension` - update to API version `2025-04-01` ([#&#8203;31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586))
    - dependencies: `azurerm_windows_virtual_machine_scale_set` - update to API version `2025-04-01` ([#&#8203;31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586))
    - dependencies: `codesigning` - update to API version `2025-10-13` ([#&#8203;31714](https://github.com/hashicorp/terraform-provider-azurerm/issues/31714))
    - `azurerm_linux_virtual_machine` - `encryption_at_host_enabled` can now be set to `true` when `os_disk.security_encryption_type` is set to `DiskWithVMGuestState` ([#&#8203;32885](https://github.com/hashicorp/terraform-provider-azurerm/issues/32885))
    - `azurerm_linux_virtual_machine_scale_set` - `encryption_at_host_enabled` can now be set to `true` when `os_disk.security_encryption_type` is set to `DiskWithVMGuestState` ([#&#8203;32885](https://github.com/hashicorp/terraform-provider-azurerm/issues/32885))
    - `azurerm_managed_devops_pool` - add support for the `CreatorOnly` value to `azure_devops_organization.permission.kind` property ([#&#8203;32753](https://github.com/hashicorp/terraform-provider-azurerm/issues/32753))
    - `azurerm_windows_virtual_machine` - `encryption_at_host_enabled` can now be set to `true` when `os_disk.security_encryption_type` is set to `DiskWithVMGuestState` ([#&#8203;32885](https://github.com/hashicorp/terraform-provider-azurerm/issues/32885))
    - `azurerm_windows_virtual_machine_scale_set` - `encryption_at_host_enabled` can now be set to `true` when `os_disk.security_encryption_type` is set to `DiskWithVMGuestState` ([#&#8203;32885](https://github.com/hashicorp/terraform-provider-azurerm/issues/32885))

    BUG FIXES:

    - `azurerm_cdn_frontdoor_batch_ruleset` - parse `rule.actions.route_configuration_override.origin_group.cdn_frontdoor_origin_group_id` case-insensitively and normalize the resulting value to prevent diffs ([#&#8203;32980](https://github.com/hashicorp/terraform-provider-azurerm/issues/32980))
    - `azurerm_cdn_frontdoor_route` - parse `cdn_frontdoor_origin_group_id` case-insensitively and normalize the resulting value to prevent diffs ([#&#8203;32980](https://github.com/hashicorp/terraform-provider-azurerm/issues/32980))
    - `azurerm_cdn_frontdoor_secret` - fix an incorrect type assertion ([#&#8203;32982](https://github.com/hashicorp/terraform-provider-azurerm/issues/32982))
    - `azurerm_dev_center_project` - parse `dev_center_id` case-insensitively and normalize the resulting value to prevent diffs ([#&#8203;32798](https://github.com/hashicorp/terraform-provider-azurerm/issues/32798))
    - `azurerm_eventhub` - now prevents the `status` property from being set to `SendDisabled` on create  ([#&#8203;33071](https://github.com/hashicorp/terraform-provider-azurerm/issues/33071))
    - `azurerm_storage_container` - add a state migration for the `id` field, fixing the upgrade path from 4.x to 5.x ([#&#8203;32978](https://github.com/hashicorp/terraform-provider-azurerm/issues/32978))
    - `azurerm_storage_queue` - extend state migration to handle a malformed `resource_manager_id` ([#&#8203;32979](https://github.com/hashicorp/terraform-provider-azurerm/issues/32979))
    - `azurerm_storage_share` - add a state migration for the `id` field, fixing the upgrade path from 4.x to 5.x ([#&#8203;33075](https://github.com/hashicorp/terraform-provider-azurerm/issues/33075))

    ### [`v5.0.1`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#501-July-30-2026)

    [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.0.0...v5.0.1)

    NOTES:

    In addition to the bug fixes below, a number of resource documentation pages and the 5.0-upgrade-guide have been updated.

    BUG FIXES:

    - `azurerm_cdn_frontdoor_origin` - fix a regression that prevented valid values as input to `private_link.private_link_target_id` ([#&#8203;32912](https://github.com/hashicorp/terraform-provider-azurerm/issues/32912))
    - `azurerm_storage_queue` - add a state migration for the `id` field, fixing the upgrade path from 4.x to 5.x ([#&#8203;32914](https://github.com/hashicorp/terraform-provider-azurerm/issues/32914))
    - `azurerm_storage_table_entity` - add a state migration for the `storage_table_id` field, fixing the upgrade path from 4.x to 5.x ([#&#8203;32929](https://github.com/hashicorp/terraform-provider-azurerm/issues/32929))

    ### [`v5.0.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#500-July-27-2026)

    [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v4.81.0...v5.0.0)

    NOTES:

    - **Major Version**: Version 5.0 of the Azure Provider is a major version - some behaviours have changed and some deprecated fields/resources have been removed - please refer to [the 5.0 upgrade guide for more information](https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/guides/5.0-upgrade-guide).
    - When upgrading to v5.0 of the AzureRM Provider, we recommend upgrading to the latest version of Terraform Core ([which can be found here](https://developer.hashicorp.com/terraform/install)).

    FEATURES:

    - **New Action**: `azurerm_web_app_set_slot_distribution` ([#&#8203;32364](https://github.com/hashicorp/terraform-provider-azurerm/issues/32364))
    - **New Datasource** adds `azurerm_kubernetes_automatic_cluster_datasource` ([#&#8203;32881](https://github.com/hashicorp/terraform-provider-azurerm/issues/32881))

    ENHANCEMENTS:

    - dependencies: `grpc` update to `1.82.1` ([#&#8203;32852](https://github.com/hashicorp/terraform-provider-azurerm/issues/32852))
    - dependencies: `loadbalancers` - update to API version `2025-01-01` ([#&#8203;32644](https://github.com/hashicorp/terraform-provider-azurerm/issues/32644))
    - `azurerm_cognitive_account_rai_policy` - the `content_filter.severity_threshold` property is now optional ([#&#8203;32100](https://github.com/hashicorp/terraform-provider-azurerm/issues/32100))
    - `azurerm_container_registry` - the `trust_policy_enabled` property has been deprecated and removed from the provider ([#&#8203;32752](https://github.com/hashicorp/terraform-provider-azurerm/issues/32752))
    - `azurerm_dashboard_grafana` - the `11` value for the `grafana_major_version` property has been deprecated and the property now supports `13` ([#&#8203;32777](https://github.com/hashicorp/terraform-provider-azurerm/issues/32777))
    - `azurerm_log_analytics_workspace` - add support for the `internet_ingestion_access_type` and `internet_query_access_type` properties ([#&#8203;32562](https://github.com/hashicorp/terraform-provider-azurerm/issues/32562))
    - `azurerm_subnet` - add support for the `network_security_group_id_wo` and `network_security_group_id_wo_version` properties ([#&#8203;32847](https://github.com/hashicorp/terraform-provider-azurerm/issues/32847))
    - `azurerm_subnet` - add support for the `route_table_id_wo` and `route_table_id_wo_version` properties ([#&#8203;32847](https://github.com/hashicorp/terraform-provider-azurerm/issues/32847))
    - `azurerm_subnet` - export the `network_security_group_id` property ([#&#8203;32847](https://github.com/hashicorp/terraform-provider-azurerm/issues/32847))
    - `azurerm_subnet` - export the `route_table_id` property ([#&#8203;32847](https://github.com/hashicorp/terraform-provider-azurerm/issues/32847))
    - `azurerm_windows_web_app` - add support for `~24` to `site_config.application_stack.node_version` ([#&#8203;32840](https://github.com/hashicorp/terraform-provider-azurerm/issues/32840))
    - `azurerm_windows_web_app_slot` - add support for `~24` to `site_config.application_stack.node_version` ([#&#8203;32840](https://github.com/hashicorp/terraform-provider-azurerm/issues/32840))
    - `cdn` - migrate to `go-azure-sdk` ([#&#8203;32849](https://github.com/hashicorp/terraform-provider-azurerm/issues/32849))
    - `sentinel` - migrate to `go-azure-sdk` ([#&#8203;32759](https://github.com/hashicorp/terraform-provider-azurerm/issues/32759))

    </details>

    ---

    ### Configuration

    📅 **Schedule**: (in timezone Europe/Oslo)

    - Branch creation
      - At any time (no schedule defined)
    - Automerge
      - At any time (no schedule defined)

    🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

    ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

    🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

    ---

     - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

    ---

    This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
    <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

    ---------

    Co-authored-by: Renovate Bot <renovate@forteapps.net>
    Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/55
    Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
    Co-authored-by: gitea_admin <admin@forteapps.net>

commit 0f0082d54d
Author: gitea_admin <admin@forteapps.net>
Date:   Sat Oct 3 18:55:02 2026 +0000

    chore(deps): update helm release fluent-bit to v0.58.3 (#57)

    This PR contains the following updates:

    | Package | Update | Change |
    |---|---|---|
    | [fluent-bit](https://fluentbit.io/) ([source](https://github.com/fluent/helm-charts)) | patch | `0.58.2` → `0.58.3` |

    ---

    ### Release Notes

    <details>
    <summary>fluent/helm-charts (fluent-bit)</summary>

    ### [`v0.58.3`](https://github.com/fluent/helm-charts/releases/tag/fluent-bit-0.58.3)

    [Compare Source](https://github.com/fluent/helm-charts/compare/fluent-bit-0.58.2...fluent-bit-0.58.3)

    ##### Changed

    - Update *Fluent Bit* OCI image to [v5.1.3](https://github.com/fluent/fluent-bit/releases/tag/v5.1.3). ([#&#8203;759](https://github.com/fluent/helm-charts/pull/759)) [@&#8203;stevehipwell](https://github.com/stevehipwell)

    </details>

    ---

    ### Configuration

    📅 **Schedule**: (in timezone Europe/Oslo)

    - Branch creation
      - At any time (no schedule defined)
    - Automerge
      - At any time (no schedule defined)

    🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

    ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

    🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

    ---

     - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

    ---

    This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
    <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

    ---------

    Co-authored-by: Renovate Bot <renovate@forteapps.net>
    Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/57
    Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
    Co-authored-by: gitea_admin <admin@forteapps.net>

commit 4a4b8e3540
Author: Jørgen Stensrud <jorgen.stensrud@fortedigital.com>
Date:   Thu Oct 1 11:25:34 2026 +0000

    feat(keycloak): forte-cli device-code client + forte-drop-mcp audience mapper (#44)

    Adds the shared public forte-cli client (RFC 8628 device-code only) to the forte realm, with an oidc-audience-mapper that puts https://mcp.drop.forteapps.net/mcp into aud so the forte-drop-mcp sidecar accepts its tokens. Supersedes #26.

    Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

commit 60b8fa657a
Author: gitea_admin <admin@forteapps.net>
Date:   Thu Oct 1 09:40:57 2026 +0000

    chore(deps): update nikitafilonov/ai-review docker tag to v1 (#53)

    This PR contains the following updates:

    | Package | Type | Update | Change |
    |---|---|---|---|
    | nikitafilonov/ai-review | docker | major | `v0.77.0` → `v1.1.0` |

    ---

    ### Configuration

    📅 **Schedule**: (in timezone Europe/Oslo)

    - Branch creation
      - At any time (no schedule defined)
    - Automerge
      - At any time (no schedule defined)

    🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

    ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

    🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

    ---

     - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

    ---

    This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
    <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

    ---------

    Co-authored-by: Renovate Bot <renovate@forteapps.net>
    Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/53
    Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
    Co-authored-by: gitea_admin <admin@forteapps.net>

commit c940259545
Author: gitea_admin <admin@forteapps.net>
Date:   Wed Sep 30 08:36:32 2026 +0000

    chore(deps): update helm release opencost to v2 (#50)

    This PR contains the following updates:

    | Package | Update | Change |
    |---|---|---|
    | [opencost](https://github.com/opencost/opencost-helm-chart) | major | `1.43.2` → `2.5.32` |

    ---

    ### Release Notes

    <details>
    <summary>opencost/opencost-helm-chart (opencost)</summary>

    ### [`v2.5.32`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.32)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.31...opencost-2.5.32)

    OpenCost and OpenCost UI

    #### What's Changed

    - Upgrade OpenCost Helm Chart to v1.121.3 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;385](https://github.com/opencost/opencost-helm-chart/pull/385)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.31...opencost-2.5.32>

    ### [`v2.5.31`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.31)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.30...opencost-2.5.31)

    OpenCost and OpenCost UI

    #### What's Changed

    - Release OpenCost v1.121.2 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;384](https://github.com/opencost/opencost-helm-chart/pull/384)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.30...opencost-2.5.31>

    ### [`v2.5.30`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.30)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.29...opencost-2.5.30)

    OpenCost and OpenCost UI

    #### What's Changed

    - feat: add opencost.exporter.extraEnvFrom to source env from ConfigMap/Secret by [@&#8203;ahauserv](https://github.com/ahauserv) in [#&#8203;378](https://github.com/opencost/opencost-helm-chart/pull/378)

    #### New Contributors

    - [@&#8203;ahauserv](https://github.com/ahauserv) made their first contribution in [#&#8203;378](https://github.com/opencost/opencost-helm-chart/pull/378)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.29...opencost-2.5.30>

    ### [`v2.5.29`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.29)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.28...opencost-2.5.29)

    OpenCost and OpenCost UI

    #### What's Changed

    - Release OpenCost v1.121.1 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;377](https://github.com/opencost/opencost-helm-chart/pull/377)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.28...opencost-2.5.29>

    ### [`v2.5.28`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.28)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.27...opencost-2.5.28)

    OpenCost and OpenCost UI

    #### What's Changed

    - Inference Cost params added to helm by [@&#8203;simanadler](https://github.com/simanadler) in [#&#8203;370](https://github.com/opencost/opencost-helm-chart/pull/370)
    - Release OpenCost v1.121.0 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;372](https://github.com/opencost/opencost-helm-chart/pull/372)

    #### New Contributors

    - [@&#8203;simanadler](https://github.com/simanadler) made their first contribution in [#&#8203;370](https://github.com/opencost/opencost-helm-chart/pull/370)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.27...opencost-2.5.28>

    ### [`v2.5.27`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.27)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.26...opencost-2.5.27)

    OpenCost and OpenCost UI

    #### What's Changed

    - KCM-5392: Add support for configuring external labels for Opencost installation with Collector data source by [@&#8203;avrodrigues5](https://github.com/avrodrigues5) in [#&#8203;371](https://github.com/opencost/opencost-helm-chart/pull/371)

    #### New Contributors

    - [@&#8203;avrodrigues5](https://github.com/avrodrigues5) made their first contribution in [#&#8203;371](https://github.com/opencost/opencost-helm-chart/pull/371)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.26...opencost-2.5.27>

    ### [`v2.5.26`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.26)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.25...opencost-2.5.26)

    OpenCost and OpenCost UI

    #### What's Changed

    - add timeout configuration for override in probes by [@&#8203;aman-kumar29](https://github.com/aman-kumar29) in [#&#8203;369](https://github.com/opencost/opencost-helm-chart/pull/369)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-parquet-exporter-0.3.0...opencost-2.5.26>

    ### [`v2.5.25`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.25)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.24...opencost-2.5.25)

    OpenCost and OpenCost UI

    #### What's Changed

    - Release OpenCost v1.120.4 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;366](https://github.com/opencost/opencost-helm-chart/pull/366)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.24...opencost-2.5.25>

    ### [`v2.5.24`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.24)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.23...opencost-2.5.24)

    OpenCost and OpenCost UI

    #### What's Changed

    - fix(service): use opencost.exporter.debugPort for service targetPort by [@&#8203;aman-kumar29](https://github.com/aman-kumar29) in [#&#8203;364](https://github.com/opencost/opencost-helm-chart/pull/364)

    #### New Contributors

    - [@&#8203;aman-kumar29](https://github.com/aman-kumar29) made their first contribution in [#&#8203;364](https://github.com/opencost/opencost-helm-chart/pull/364)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.23...opencost-2.5.24>

    ### [`v2.5.23`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.23)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.22...opencost-2.5.23)

    OpenCost and OpenCost UI

    #### What's Changed

    - feat(gateway-api): Add support for filters by [@&#8203;HartmannVolker](https://github.com/HartmannVolker) in [#&#8203;356](https://github.com/opencost/opencost-helm-chart/pull/356)

    #### New Contributors

    - [@&#8203;HartmannVolker](https://github.com/HartmannVolker) made their first contribution in [#&#8203;356](https://github.com/opencost/opencost-helm-chart/pull/356)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.22...opencost-2.5.23>

    ### [`v2.5.22`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.22)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.21...opencost-2.5.22)

    OpenCost and OpenCost UI

    #### What's Changed

    - Release OpenCost v1.120.3 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;357](https://github.com/opencost/opencost-helm-chart/pull/357)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.21...opencost-2.5.22>

    ### [`v2.5.21`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.21)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.20...opencost-2.5.21)

    OpenCost and OpenCost UI

    #### What's Changed

    - feat: add extraObjects for tpl-rendered extra manifests by [@&#8203;younsl](https://github.com/younsl) in [#&#8203;354](https://github.com/opencost/opencost-helm-chart/pull/354)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.20...opencost-2.5.21>

    ### [`v2.5.20`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.20)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.19...opencost-2.5.20)

    OpenCost and OpenCost UI

    #### What's Changed

    - Update Helm chart for v1.120.2 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;355](https://github.com/opencost/opencost-helm-chart/pull/355)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.19...opencost-2.5.20>

    ### [`v2.5.19`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.19)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.18...opencost-2.5.19)

    OpenCost and OpenCost UI

    #### What's Changed

    - Consistent Usage of `opencost.namespace` Helper by [@&#8203;ioboi](https://github.com/ioboi) in [#&#8203;353](https://github.com/opencost/opencost-helm-chart/pull/353)

    #### New Contributors

    - [@&#8203;ioboi](https://github.com/ioboi) made their first contribution in [#&#8203;353](https://github.com/opencost/opencost-helm-chart/pull/353)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.18...opencost-2.5.19>

    ### [`v2.5.18`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.18)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.14...opencost-2.5.18)

    OpenCost and OpenCost UI

    #### What's Changed

    - feat: Add plugins.install.plugins list and existingSecret support (adopts [#&#8203;328](https://github.com/opencost/opencost-helm-chart/issues/328)) by [@&#8203;ameijer](https://github.com/ameijer) in [#&#8203;344](https://github.com/opencost/opencost-helm-chart/pull/344)
    - feat: add OCI cloud cost configuration example to cloudIntegrationJSON by [@&#8203;Kush172005](https://github.com/Kush172005) in [#&#8203;345](https://github.com/opencost/opencost-helm-chart/pull/345)
    - Release Opencost v1.120.1 - Bump Helm Chart by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;347](https://github.com/opencost/opencost-helm-chart/pull/347)
    - Fix UI route tls by [@&#8203;mittal-ishaan](https://github.com/mittal-ishaan) in [#&#8203;352](https://github.com/opencost/opencost-helm-chart/pull/352)

    #### New Contributors

    - [@&#8203;Kush172005](https://github.com/Kush172005) made their first contribution in [#&#8203;345](https://github.com/opencost/opencost-helm-chart/pull/345)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.14...opencost-2.5.18>

    ### [`v2.5.14`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.14)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.12...opencost-2.5.14)

    OpenCost and OpenCost UI

    #### What's Changed

    - Release Opencost v1.120.0 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;341](https://github.com/opencost/opencost-helm-chart/pull/341)
    - Cdp/opencost v1.120.0 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;343](https://github.com/opencost/opencost-helm-chart/pull/343)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.12...opencost-2.5.14>

    ### [`v2.5.12`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.12)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.11...opencost-2.5.12)

    OpenCost and OpenCost UI

    #### What's Changed

    - Create Empty /var/configs dir by [@&#8203;HMetcalfeW](https://github.com/HMetcalfeW) in [#&#8203;333](https://github.com/opencost/opencost-helm-chart/pull/333)

    #### New Contributors

    - [@&#8203;HMetcalfeW](https://github.com/HMetcalfeW) made their first contribution in [#&#8203;333](https://github.com/opencost/opencost-helm-chart/pull/333)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.11...opencost-2.5.12>

    ### [`v2.5.11`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.11)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.10...opencost-2.5.11)

    OpenCost and OpenCost UI

    #### What's Changed

    - add admin token infra support by [@&#8203;ameijer](https://github.com/ameijer) in [#&#8203;339](https://github.com/opencost/opencost-helm-chart/pull/339)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.10...opencost-2.5.11>

    ### [`v2.5.10`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.10)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.9...opencost-2.5.10)

    OpenCost and OpenCost UI

    #### What's Changed

    - Add cloudIntegrationJSON support by [@&#8203;thomasvn](https://github.com/thomasvn) in [#&#8203;337](https://github.com/opencost/opencost-helm-chart/pull/337)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.9...opencost-2.5.10>

    ### [`v2.5.9`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.9)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.8...opencost-2.5.9)

    OpenCost and OpenCost UI

    #### What's Changed

    - Fix collectorDataSource retention env var conditions by [@&#8203;dag-andersen](https://github.com/dag-andersen) in [#&#8203;336](https://github.com/opencost/opencost-helm-chart/pull/336)

    #### New Contributors

    - [@&#8203;dag-andersen](https://github.com/dag-andersen) made their first contribution in [#&#8203;336](https://github.com/opencost/opencost-helm-chart/pull/336)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.8...opencost-2.5.9>

    ### [`v2.5.8`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.8)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.7...opencost-2.5.8)

    OpenCost and OpenCost UI

    #### What's Changed

    - Opencost v1.119.2 Changes by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;334](https://github.com/opencost/opencost-helm-chart/pull/334)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.7...opencost-2.5.8>

    ### [`v2.5.7`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.7)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.6...opencost-2.5.7)

    OpenCost and OpenCost UI

    #### What's Changed

    - fix: fix csv export condition in deployment by [@&#8203;meroupatate](https://github.com/meroupatate) in [#&#8203;330](https://github.com/opencost/opencost-helm-chart/pull/330)

    #### New Contributors

    - [@&#8203;meroupatate](https://github.com/meroupatate) made their first contribution in [#&#8203;330](https://github.com/opencost/opencost-helm-chart/pull/330)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.6...opencost-2.5.7>

    ### [`v2.5.6`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.6)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.5...opencost-2.5.6)

    OpenCost and OpenCost UI

    #### What's Changed

    - Do not grant permissions on nodes/proxy by default by [@&#8203;Farenjihn](https://github.com/Farenjihn) in [#&#8203;329](https://github.com/opencost/opencost-helm-chart/pull/329)

    #### New Contributors

    - [@&#8203;Farenjihn](https://github.com/Farenjihn) made their first contribution in [#&#8203;329](https://github.com/opencost/opencost-helm-chart/pull/329)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.5...opencost-2.5.6>

    ### [`v2.5.5`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.5)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.4...opencost-2.5.5)

    OpenCost and OpenCost UI

    #### What's Changed

    - Add PRICING\_CONFIGMAP\_NAME env to achnowledge configmapName helm value by [@&#8203;mittal-ishaan](https://github.com/mittal-ishaan) in [#&#8203;316](https://github.com/opencost/opencost-helm-chart/pull/316)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.4...opencost-2.5.5>

    ### [`v2.5.4`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.4)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.3...opencost-2.5.4)

    OpenCost and OpenCost UI

    #### What's Changed

    - feat(opencost): add Gateway API HTTPRoute support by [@&#8203;younsl](https://github.com/younsl) in [#&#8203;322](https://github.com/opencost/opencost-helm-chart/pull/322)

    #### New Contributors

    - [@&#8203;younsl](https://github.com/younsl) made their first contribution in [#&#8203;322](https://github.com/opencost/opencost-helm-chart/pull/322)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.3...opencost-2.5.4>

    ### [`v2.5.3`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.3)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.2...opencost-2.5.3)

    OpenCost and OpenCost UI

    #### What's Changed

    - Add configurable nginx proxy timeouts to helm chart by [@&#8203;peatey](https://github.com/peatey) in [#&#8203;326](https://github.com/opencost/opencost-helm-chart/pull/326)

    #### New Contributors

    - [@&#8203;peatey](https://github.com/peatey) made their first contribution in [#&#8203;326](https://github.com/opencost/opencost-helm-chart/pull/326)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.2...opencost-2.5.3>

    ### [`v2.5.2`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.2)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.1...opencost-2.5.2)

    OpenCost and OpenCost UI

    #### What's Changed

    - Update cloud-integration secret path by [@&#8203;thomasvn](https://github.com/thomasvn) in [#&#8203;324](https://github.com/opencost/opencost-helm-chart/pull/324)

    #### New Contributors

    - [@&#8203;thomasvn](https://github.com/thomasvn) made their first contribution in [#&#8203;324](https://github.com/opencost/opencost-helm-chart/pull/324)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.1...opencost-2.5.2>

    ### [`v2.5.1`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.1)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.0...opencost-2.5.1)

    OpenCost and OpenCost UI

    #### What's Changed

    - Release Opencost v1.119.1 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;325](https://github.com/opencost/opencost-helm-chart/pull/325)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.0...opencost-2.5.1>

    ### [`v2.5.0`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.0)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.4.1...opencost-2.5.0)

    OpenCost and OpenCost UI

    #### What's Changed

    - Release Opencost v1.119.0 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;323](https://github.com/opencost/opencost-helm-chart/pull/323)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.4.1...opencost-2.5.0>

    ### [`v2.4.1`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.4.1)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.4.0...opencost-2.4.1)

    OpenCost and OpenCost UI

    #### What's Changed

    - fix: mcp disable procedure by [@&#8203;marijus-ravickas](https://github.com/marijus-ravickas) in [#&#8203;319](https://github.com/opencost/opencost-helm-chart/pull/319)

    #### New Contributors

    - [@&#8203;marijus-ravickas](https://github.com/marijus-ravickas) made their first contribution in [#&#8203;319](https://github.com/opencost/opencost-helm-chart/pull/319)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.4.0...opencost-2.4.1>

    ### [`v2.4.0`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.4.0)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.3.2...opencost-2.4.0)

    OpenCost and OpenCost UI

    #### What's Changed

    - added-mcp-config by [@&#8203;sneaxhuh](https://github.com/sneaxhuh) in [#&#8203;311](https://github.com/opencost/opencost-helm-chart/pull/311)
    - Update Opencost to v1.118.0 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;314](https://github.com/opencost/opencost-helm-chart/pull/314)

    #### New Contributors

    - [@&#8203;sneaxhuh](https://github.com/sneaxhuh) made their first contribution in [#&#8203;311](https://github.com/opencost/opencost-helm-chart/pull/311)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.3.2...opencost-2.4.0>

    ### [`v2.3.2`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.3.2)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.3.1...opencost-2.3.2)

    OpenCost and OpenCost UI

    #### What's Changed

    - fix: use default sc when sc name not specified by [@&#8203;cwyl02](https://github.com/cwyl02) in [#&#8203;312](https://github.com/opencost/opencost-helm-chart/pull/312)

    #### New Contributors

    - [@&#8203;cwyl02](https://github.com/cwyl02) made their first contribution in [#&#8203;312](https://github.com/opencost/opencost-helm-chart/pull/312)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.3.1...opencost-2.3.2>

    ### [`v2.3.1`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.3.1)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.3.0...opencost-2.3.1)

    OpenCost and OpenCost UI

    #### What's Changed

    - feat: Add option to use cm to set CLUSTER\_ID envvar by [@&#8203;gracedo](https://github.com/gracedo) in [#&#8203;307](https://github.com/opencost/opencost-helm-chart/pull/307)

    #### New Contributors

    - [@&#8203;gracedo](https://github.com/gracedo) made their first contribution in [#&#8203;307](https://github.com/opencost/opencost-helm-chart/pull/307)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.3.0...opencost-2.3.1>

    ### [`v2.3.0`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.3.0)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.9...opencost-2.3.0)

    OpenCost and OpenCost UI

    #### What's Changed

    - Add configs to mount custom ca certs to opencost container by [@&#8203;mittal-ishaan](https://github.com/mittal-ishaan) in [#&#8203;303](https://github.com/opencost/opencost-helm-chart/pull/303)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.9...opencost-2.3.0>

    ### [`v2.2.9`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.9)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.8...opencost-2.2.9)

    OpenCost and OpenCost UI

    #### What's Changed

    - Add chart installation notes by [@&#8203;dejanu](https://github.com/dejanu) in [#&#8203;305](https://github.com/opencost/opencost-helm-chart/pull/305)
    - Release Opencost v1.117.6 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;309](https://github.com/opencost/opencost-helm-chart/pull/309)

    #### New Contributors

    - [@&#8203;dejanu](https://github.com/dejanu) made their first contribution in [#&#8203;305](https://github.com/opencost/opencost-helm-chart/pull/305)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.8...opencost-2.2.9>

    ### [`v2.2.8`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.8)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.7...opencost-2.2.8)

    OpenCost and OpenCost UI

    #### What's Changed

    - Release Opencost v1.117.5 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;306](https://github.com/opencost/opencost-helm-chart/pull/306)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.7...opencost-2.2.8>

    ### [`v2.2.7`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.7)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.6...opencost-2.2.7)

    OpenCost and OpenCost UI

    #### What's Changed

    - Add uiPath configuration for OpenCost UI by [@&#8203;gustavo-sdo](https://github.com/gustavo-sdo) in [#&#8203;298](https://github.com/opencost/opencost-helm-chart/pull/298)

    #### New Contributors

    - [@&#8203;gustavo-sdo](https://github.com/gustavo-sdo) made their first contribution in [#&#8203;298](https://github.com/opencost/opencost-helm-chart/pull/298)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.6...opencost-2.2.7>

    ### [`v2.2.6`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.6)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.5...opencost-2.2.6)

    OpenCost and OpenCost UI

    #### What's Changed

    - Dodizzle/proxy fix by [@&#8203;ameijer](https://github.com/ameijer) in [#&#8203;301](https://github.com/opencost/opencost-helm-chart/pull/301)
    - allow: set path for internal prometheus by [@&#8203;dodizzle](https://github.com/dodizzle) in [#&#8203;271](https://github.com/opencost/opencost-helm-chart/pull/271)

    #### New Contributors

    - [@&#8203;dodizzle](https://github.com/dodizzle) made their first contribution in [#&#8203;271](https://github.com/opencost/opencost-helm-chart/pull/271)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.5...opencost-2.2.6>

    ### [`v2.2.5`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.5)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.4...opencost-2.2.5)

    OpenCost and OpenCost UI

    #### What's Changed

    - Release v1.117.3 of Opencost by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;300](https://github.com/opencost/opencost-helm-chart/pull/300)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.4...opencost-2.2.5>

    ### [`v2.2.4`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.4)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.3...opencost-2.2.4)

    OpenCost and OpenCost UI

    #### What's Changed

    - Release v1.117.2 of Opencost by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;299](https://github.com/opencost/opencost-helm-chart/pull/299)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.3...opencost-2.2.4>

    ### [`v2.2.3`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.3)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.2...opencost-2.2.3)

    OpenCost and OpenCost UI

    #### What's Changed

    - Update env var names and values by [@&#8203;Sean-Holcomb](https://github.com/Sean-Holcomb) in [#&#8203;297](https://github.com/opencost/opencost-helm-chart/pull/297)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.2...opencost-2.2.3>

    ### [`v2.2.2`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.2)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.1...opencost-2.2.2)

    OpenCost and OpenCost UI

    #### What's Changed

    - Advance to Opencost v1.117.0 by [@&#8203;mbolt35](https://github.com/mbolt35) in [#&#8203;296](https://github.com/opencost/opencost-helm-chart/pull/296)

    #### New Contributors

    - [@&#8203;mbolt35](https://github.com/mbolt35) made their first contribution in [#&#8203;296](https://github.com/opencost/opencost-helm-chart/pull/296)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.1...opencost-2.2.2>

    ### [`v2.2.1`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.1)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.0...opencost-2.2.1)

    OpenCost and OpenCost UI

    #### What's Changed

    - Add `insecureSkipVerify` to `prometheus.external`  by [@&#8203;charleshu-8](https://github.com/charleshu-8) in [#&#8203;294](https://github.com/opencost/opencost-helm-chart/pull/294)

    #### New Contributors

    - [@&#8203;charleshu-8](https://github.com/charleshu-8) made their first contribution in [#&#8203;294](https://github.com/opencost/opencost-helm-chart/pull/294)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.0...opencost-2.2.1>

    ### [`v2.2.0`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.0)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.9...opencost-2.2.0)

    OpenCost and OpenCost UI

    #### What's Changed

    - Bump image tags and chart version by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;291](https://github.com/opencost/opencost-helm-chart/pull/291)

    #### New Contributors

    - [@&#8203;cpetersen5](https://github.com/cpetersen5) made their first contribution in [#&#8203;291](https://github.com/opencost/opencost-helm-chart/pull/291)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.9...opencost-2.2.0>

    ### [`v2.1.9`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.9)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.8...opencost-2.1.9)

    OpenCost and OpenCost UI

    #### What's Changed

    - Change ETL env variable name by [@&#8203;Sean-Holcomb](https://github.com/Sean-Holcomb) in [#&#8203;285](https://github.com/opencost/opencost-helm-chart/pull/285)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.8...opencost-2.1.9>

    ### [`v2.1.8`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.8)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.7...opencost-2.1.8)

    OpenCost and OpenCost UI

    #### What's Changed

    - tweak params by [@&#8203;ameijer](https://github.com/ameijer) in [#&#8203;289](https://github.com/opencost/opencost-helm-chart/pull/289)
    - add option to override the default container command by [@&#8203;nishanthreddydd](https://github.com/nishanthreddydd) in [#&#8203;290](https://github.com/opencost/opencost-helm-chart/pull/290)

    #### New Contributors

    - [@&#8203;nishanthreddydd](https://github.com/nishanthreddydd) made their first contribution in [#&#8203;290](https://github.com/opencost/opencost-helm-chart/pull/290)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.7...opencost-2.1.8>

    ### [`v2.1.7`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.7)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.6...opencost-2.1.7)

    OpenCost and OpenCost UI

    #### What's Changed

    - (doc) update readme to easily install unittest by [@&#8203;karthik-suresh](https://github.com/karthik-suresh) in [#&#8203;284](https://github.com/opencost/opencost-helm-chart/pull/284)
    - Add ability to configure resolution for prometheus by [@&#8203;Sean-Holcomb](https://github.com/Sean-Holcomb) in [#&#8203;282](https://github.com/opencost/opencost-helm-chart/pull/282)
    - Add support for Pod Disruption Budget by [@&#8203;josephteddick](https://github.com/josephteddick) in [#&#8203;287](https://github.com/opencost/opencost-helm-chart/pull/287)

    #### New Contributors

    - [@&#8203;karthik-suresh](https://github.com/karthik-suresh) made their first contribution in [#&#8203;284](https://github.com/opencost/opencost-helm-chart/pull/284)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.6...opencost-2.1.7>

    ### [`v2.1.6`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.6)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.5...opencost-2.1.6)

    OpenCost and OpenCost UI

    #### What's Changed

    - feat(sec) - customize service account mounting by [@&#8203;cpsmx](https://github.com/cpsmx) in [#&#8203;283](https://github.com/opencost/opencost-helm-chart/pull/283)

    #### New Contributors

    - [@&#8203;cpsmx](https://github.com/cpsmx) made their first contribution in [#&#8203;283](https://github.com/opencost/opencost-helm-chart/pull/283)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.5...opencost-2.1.6>

    ### [`v2.1.5`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.5)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.4...opencost-2.1.5)

    OpenCost and OpenCost UI

    #### What's Changed

    - Update opencost ui 1.115.0 image by [@&#8203;mittal-ishaan](https://github.com/mittal-ishaan) in [#&#8203;281](https://github.com/opencost/opencost-helm-chart/pull/281)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.4...opencost-2.1.5>

    ### [`v2.1.4`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.4)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.3...opencost-2.1.4)

    OpenCost and OpenCost UI

    #### What's Changed

    - Bump OC to 1.115.0 by [@&#8203;mittal-ishaan](https://github.com/mittal-ishaan) in [#&#8203;277](https://github.com/opencost/opencost-helm-chart/pull/277)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.3...opencost-2.1.4>

    ### [`v2.1.3`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.3)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.2...opencost-2.1.3)

    OpenCost and OpenCost UI

    #### What's Changed

    - Promless Config by [@&#8203;Sean-Holcomb](https://github.com/Sean-Holcomb) in [#&#8203;275](https://github.com/opencost/opencost-helm-chart/pull/275)
    - Add values examples and notes to values.yaml. Update version numbers by [@&#8203;Sean-Holcomb](https://github.com/Sean-Holcomb) in [#&#8203;276](https://github.com/opencost/opencost-helm-chart/pull/276)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.2...opencost-2.1.3>

    ### [`v2.1.2`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.2)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.1...opencost-2.1.2)

    OpenCost and OpenCost UI

    #### What's Changed

    - Add support for API Ingress by [@&#8203;josephteddick](https://github.com/josephteddick) in [#&#8203;255](https://github.com/opencost/opencost-helm-chart/pull/255)

    #### New Contributors

    - [@&#8203;josephteddick](https://github.com/josephteddick) made their first contribution in [#&#8203;255](https://github.com/opencost/opencost-helm-chart/pull/255)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-parquet-exporter-0.2.0...opencost-2.1.2>

    ### [`v2.1.1`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.1)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.0...opencost-2.1.1)

    OpenCost and OpenCost UI

    #### What's Changed

    - Fix for [#&#8203;272](https://github.com/opencost/opencost-helm-chart/pull/272) to make feature flag actually work. by [@&#8203;tintii](https://github.com/tintii) in [#&#8203;274](https://github.com/opencost/opencost-helm-chart/pull/274)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.0...opencost-2.1.1>

    ### [`v2.1.0`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.0)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.0.2...opencost-2.1.0)

    OpenCost and OpenCost UI

    #### What's Changed

    - Openshift Security Context Constraints and updated ClusterRole with access to internal prometheus. by [@&#8203;v0nNemizez](https://github.com/v0nNemizez) in [#&#8203;267](https://github.com/opencost/opencost-helm-chart/pull/267)

    #### New Contributors

    - [@&#8203;v0nNemizez](https://github.com/v0nNemizez) made their first contribution in [#&#8203;267](https://github.com/opencost/opencost-helm-chart/pull/267)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.0.2...opencost-2.1.0>

    ### [`v2.0.2`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.0.2)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.0.1...opencost-2.0.2)

    OpenCost and OpenCost UI

    #### What's Changed

    - Add opencost.ui.useIPv6 feature flag by [@&#8203;tintii](https://github.com/tintii) in [#&#8203;272](https://github.com/opencost/opencost-helm-chart/pull/272)

    #### New Contributors

    - [@&#8203;tintii](https://github.com/tintii) made their first contribution in [#&#8203;272](https://github.com/opencost/opencost-helm-chart/pull/272)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.0.1...opencost-2.0.2>

    ### [`v2.0.1`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.0.1)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.0.0...opencost-2.0.1)

    OpenCost and OpenCost UI

    #### What's Changed

    - add sha256sums of configMaps to trigger a restart of the pod, if the configMap changes by [@&#8203;kastl-ars](https://github.com/kastl-ars) in [#&#8203;264](https://github.com/opencost/opencost-helm-chart/pull/264)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.0.0...opencost-2.0.1>

    ### [`v2.0.0`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.0.0)

    OpenCost and OpenCost UI

    #### What's Changed

    - add seperate openshift block to handle openshift related configurations and add frontend nginx config by [@&#8203;mittal-ishaan](https://github.com/mittal-ishaan) in [#&#8203;245](https://github.com/opencost/opencost-helm-chart/pull/245)
    - Updating chart badge by [@&#8203;TheUnixRoot](https://github.com/TheUnixRoot) in [#&#8203;261](https://github.com/opencost/opencost-helm-chart/pull/261)
    - Fix: Chart release script by [@&#8203;mittal-ishaan](https://github.com/mittal-ishaan) in [#&#8203;262](https://github.com/opencost/opencost-helm-chart/pull/262)

    #### New Contributors

    - [@&#8203;TheUnixRoot](https://github.com/TheUnixRoot) made their first contribution in [#&#8203;261](https://github.com/opencost/opencost-helm-chart/pull/261)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/1.45.0-helm...opencost-2.0.0>

    </details>

    ---

    ### Configuration

    📅 **Schedule**: (in timezone Europe/Oslo)

    - Branch creation
      - At any time (no schedule defined)
    - Automerge
      - At any time (no schedule defined)

    🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

    ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

    🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

    ---

     - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

    ---

    This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
    <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJicmVha2luZy1jaGFuZ2UiLCJyZW5vdmF0ZSJdfQ==-->

    ---------

    Co-authored-by: Renovate Bot <renovate@forteapps.net>
    Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/50
    Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
    Co-authored-by: gitea_admin <admin@forteapps.net>
2026-10-07 08:37:56 +02:00

1834 lines
49 KiB
Markdown

# Developer Onboarding Guide
## Table of Contents
- [Getting Started](#getting-started)
- [Prerequisites](#prerequisites)
- [Local Development Setup](#local-development-setup)
- [Understanding the Workflow](#understanding-the-workflow)
- [Deploying Your First Application](#deploying-your-first-application)
- [Updating an Existing Application](#updating-an-existing-application)
- [Working with Secrets](#working-with-secrets)
- [Enabling Authentication for Applications](#enabling-authentication-for-applications)
- [Adding a New Keycloak Client](#adding-a-new-keycloak-client)
- [Troubleshooting](#troubleshooting)
- [Best Practices](#best-practices)
---
## Getting Started
Welcome! This guide will help you understand how to develop and deploy applications on our Kubernetes cluster using GitOps principles powered by ArgoCD.
### What You'll Learn
- How our GitOps architecture works
- How to deploy a new application
- How to update existing applications
- How to manage secrets securely
- Common troubleshooting techniques
### Who This Guide Is For
- Developers deploying new applications
- Developers maintaining existing applications
- Team members who need to understand the deployment process
---
## Prerequisites
### Required Knowledge
- ✅ Basic Git workflow (clone, commit, push, pull)
- ✅ Docker basics (Dockerfile, building images)
- ✅ YAML syntax
- ✅ Basic understanding of Kubernetes concepts (pods, deployments, services)
- ⚠️ Helm knowledge (helpful but not required - templates are provided)
### Required Tools
Most developers **do NOT need kubectl access** to the cluster. You'll primarily work with Git repositories.
If you do need cluster access, install:
1. **kubectl** - Kubernetes CLI
```bash
# macOS
brew install kubectl
# Windows
choco install kubernetes-cli
# Linux
curl -LO "https://dl.k8s.io/release/$(curl -L -s https://dl.k8s.io/release/stable.txt)/bin/linux/amd64/kubectl"
```
2. **kubeseal** - For sealing secrets
```bash
# macOS
brew install kubeseal
# Windows
choco install kubeseal
# Linux
wget https://github.com/bitnami-labs/sealed-secrets/releases/download/v0.24.0/kubeseal-0.24.0-linux-amd64.tar.gz
tar -xvzf kubeseal-0.24.0-linux-amd64.tar.gz
sudo mv kubeseal /usr/local/bin/
```
3. **Git** - Version control
```bash
git --version # Should already be installed
```
4. **Docker** - For local development
```bash
# macOS/Windows: Install Docker Desktop
# Linux: Install Docker Engine
docker --version
```
### Repository Access
You'll need read/write access to these repositories:
1. **launchpad** (Config repo)
```bash
git clone https://git.forteapps.net/Forte/launchpad.git
cd launchpad
```
2. **helm-prod-values** (Values repo)
```bash
git clone https://git.forteapps.net/Forte/helm-prod-values.git
cd helm-prod-values
```
3. **forte-helm** (Chart repo - read-only for most developers)
```bash
git clone https://git.forteapps.net/Forte/forte-helm.git
cd forte-helm
```
### Cluster Access (If Needed)
If you need kubectl access, ask the platform team for:
- Kubeconfig file
- Cluster context setup instructions
Save to `~/.kube/config` and verify:
```bash
kubectl cluster-info
kubectl get nodes
```
---
## Local Development Setup
### 1. Clone the Repositories
Set up a consistent folder structure:
```bash
mkdir -p ~/dev/k8s
cd ~/dev/k8s
# Clone repositories
git clone https://git.forteapps.net/Forte/launchpad.git launchpad
git clone https://git.forteapps.net/Forte/helm-prod-values helm-prod-values
git clone https://git.forteapps.net/Forte/forte-helm forte-helm
# Your folder structure:
# ~/dev/k8s/
# ├── launchpad/ (Config repo)
# ├── helm-prod-values/ (Values repo)
# └── forte-helm/ (Chart repo)
```
### 2. Local Development Environment
Most applications use **Docker Compose** for local development:
```bash
# In your application repository
docker-compose up
# Or for frontend applications
npm install
npm run dev
```
**You DO NOT run applications locally on Kubernetes.** Use Docker Compose or native tooling (npm, python, etc.).
### 3. Understanding the Deployment Flow
```
┌─────────────────────────────────────────────────────────────────┐
│ Step 1: Develop Locally │
│ - Write code in your application repository │
│ - Test with Docker Compose or npm/python/etc. │
│ - Build Docker image │
└─────────────────────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────────┐
│ Step 2: CI/CD Pipeline (Automated) │
│ - GitHub Actions builds image │
│ - Pushes to container registry (GHCR, Docker Hub) │
│ - Tags with version (e.g., v2.0.4) │
│ - Updates helm-prod-values repository with new tag │
└─────────────────────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────────┐
│ Step 3: GitOps Sync (Automated) │
│ - ArgoCD detects change in helm-prod-values │
│ - Pulls updated configuration │
│ - Syncs to Kubernetes cluster │
│ - Sends Slack notification on success/failure │
└─────────────────────────────────────────────────────────────────┘
```
**Key Insight**: You don't deploy directly. You push code, CI/CD builds it, and ArgoCD deploys it.
---
## Understanding the Workflow
### Three-Repository Pattern
Our setup uses three repositories:
| Repository | Purpose | Who Edits | How Often |
|------------|---------|-----------|-----------|
| **forte-helm** | Helm chart templates (generic, reusable) | Platform engineers | ❌ Rarely |
| **helm-prod-values** | Application configuration (image tag, env vars) | Developers / CI pipelines | ✅ Sometimes |
| **launchpad** | ArgoCD Applications (what gets deployed) | Platform / DevOps engineers | ✅ Per new app |
### Example: Deploying "myapp"
#### Repository: `forte-helm` (Chart Templates)
```yaml
# forteapp/templates/deployment.yaml
# Generic template used by ALL apps
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ .Values.app.name }}
spec:
containers:
- name: app
image: "{{ .Values.app.image.repository }}:{{ .Values.app.image.tag }}"
env:
- name: PORT
value: {{ .Values.app.port }}
```
#### Repository: `helm-prod-values` (Your App Config)
```yaml
# myapp/values.yaml
# Your app's specific configuration
app:
image:
repository: ghcr.io/fortedigital/myapp
tag: v1.0.0 # CI/CD updates this
port: 3000
extraEnv:
- name: API_URL
value: https://api.example.com
```
#### Repository: `launchpad` (ArgoCD Application)
```yaml
# apps/myapp.yaml
# Tells ArgoCD to deploy your app
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: myapp
namespace: argocd
spec:
sources:
- repoURL: https://git.forteapps.net/Forte/forte-helm
path: forteapp
helm:
valueFiles:
- $values/myapp/values.yaml
- repoURL: git@github.com:fortedigital/helm-prod-values.git
ref: values
destination:
server: https://kubernetes.default.svc
namespace: myapp
syncPolicy:
automated:
prune: true
selfHeal: true
syncOptions:
- CreateNamespace=true
```
---
## Deploying Your First Application
### Scenario: You've Built a New Application
Let's deploy a new Node.js application called "hello-world".
### Step 1: Prepare Your Application Repository
Ensure your app repository has:
1. **Dockerfile**
```dockerfile
FROM node:18-alpine
WORKDIR /app
COPY package*.json ./
RUN npm ci --only=production
COPY . .
EXPOSE 3000
CMD ["node", "server.js"]
```
2. **GitHub Actions Workflow** (`.github/workflows/deploy.yml`)
```yaml
name: Build and Deploy
on:
push:
branches: [ main ]
jobs:
build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: Set version
id: version
run: echo "VERSION=v$(date +%Y%m%d-%H%M%S)" >> $GITHUB_OUTPUT
- name: Build and push Docker image
run: |
echo ${{ secrets.GITHUB_TOKEN }} | docker login ghcr.io -u ${{ github.actor }} --password-stdin
docker build -t ghcr.io/fortedigital/hello-world:${{ steps.version.outputs.VERSION }} .
docker push ghcr.io/fortedigital/hello-world:${{ steps.version.outputs.VERSION }}
- name: Update helm-prod-values
run: |
git clone git@github.com:fortedigital/helm-prod-values.git
cd helm-prod-values
mkdir -p hello-world
cat > hello-world/values.yaml <<EOF
app:
image:
repository: ghcr.io/fortedigital/hello-world
tag: ${{ steps.version.outputs.VERSION }}
EOF
git add hello-world/values.yaml
git commit -m "Update hello-world to ${{ steps.version.outputs.VERSION }}"
git push
```
### Step 2: Create Helm Values
Create a folder in `helm-prod-values` repository:
```bash
cd ~/dev/k8s/helm-prod-values
mkdir -p hello-world
```
Create `hello-world/values.yaml`:
```yaml
app:
image:
repository: ghcr.io/fortedigital/hello-world
tag: v1.0.0 # Will be updated by CI/CD
containerPort: 3000
replicaCount: 1
resources:
requests:
cpu: 100m
memory: 128Mi
limits:
cpu: 500m
memory: 512Mi
extraEnv:
- name: PORT
value: "3000"
- name: NODE_ENV
value: "production"
envSecretName: "" # Optional: reference to secrets
service:
port: 3000
ingress:
enabled: true
host: hello-world.forteapps.net # Your subdomain
db:
enabled: false # Set to true if you need PostgreSQL
```
Commit and push:
```bash
git add hello-world/values.yaml
git commit -m "Add hello-world application values"
git push
```
### Step 3: Create ArgoCD Application Manifest
In the `launchpad` repository, create `apps/hello-world.yaml`:
```yaml
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: hello-world
namespace: argocd
annotations:
argocd.argoproj.io/sync-wave: "1"
notifications.argoproj.io/subscribe.on-sync-succeeded.slack: ""
notifications.argoproj.io/subscribe.on-sync-failed.slack: ""
notifications.argoproj.io/subscribe.on-degraded.slack: ""
labels:
app.kubernetes.io/name: hello-world
app.kubernetes.io/part-of: apps
app.kubernetes.io/managed-by: argocd
finalizers:
- resources-finalizer.argocd.argoproj.io
spec:
project: default
sources:
# Source 1: Helm chart templates
- repoURL: https://git.forteapps.net/Forte/forte-helm
path: forteapp
targetRevision: HEAD
helm:
valueFiles:
- $values/hello-world/values.yaml
# Source 2: Helm values
- repoURL: git@github.com:fortedigital/helm-prod-values.git
targetRevision: HEAD
ref: values
destination:
server: https://kubernetes.default.svc
namespace: hello-world
syncPolicy:
automated:
prune: true
selfHeal: true
allowEmpty: false
syncOptions:
- CreateNamespace=true
- Validate=true
- ServerSideApply=true
retry:
limit: 5
backoff:
duration: 5s
factor: 2
maxDuration: 3m
ignoreDifferences:
- group: apps
kind: Deployment
jsonPointers:
- /spec/replicas
```
Commit and push:
```bash
cd ~/dev/k8s/launchpad
git add apps/hello-world.yaml
git commit -m "Add hello-world application"
git push
```
### Step 4: Verify Deployment
ArgoCD will automatically detect the new application within 60 seconds.
**Option 1: Check Slack**
- Watch for sync notifications in your Slack channel
- ✅ "Application hello-world sync succeeded"
**Option 2: Check ArgoCD UI** (if you have access)
```bash
# Port forward to ArgoCD UI
kubectl port-forward svc/argocd-server -n argocd 8080:443
# Open browser: https://localhost:8080
# Look for "hello-world" application
```
**Option 3: Check with kubectl** (if you have access)
```bash
# List ArgoCD applications
kubectl get applications -n argocd
# Check application status
kubectl get application hello-world -n argocd
# Verify pods are running
kubectl get pods -n hello-world
```
### Step 5: Access Your Application
Once deployed, access via the configured domain:
```bash
# Check if ingress is created
kubectl get ingressroute -n hello-world
# Access application
curl https://hello-world.forteapps.net
```
**⚠️ Note**: DNS must be manually configured for new subdomains. Contact the platform team to add DNS records.
---
## Updating an Existing Application
### Scenario: Deploying a Code Change
You've made changes to your application code and want to deploy them.
### Method 1: Automatic (Recommended)
**Just push to `main` branch** - CI/CD handles everything:
```bash
# In your application repository
git add .
git commit -m "Fix bug in user login"
git push origin main
```
**What Happens Next:**
1. ✅ GitHub Actions triggers
2. ✅ Builds new Docker image
3. ✅ Tags with new version (e.g., `v20260316-143022`)
4. ✅ Pushes to container registry
5. ✅ Updates `helm-prod-values/myapp/values.yaml` with new tag
6. ✅ ArgoCD detects change
7. ✅ Syncs new version to cluster
8. ✅ Sends Slack notification
**Timeline**: ~5-10 minutes from push to deployment
### Method 2: Manual Image Tag Update
If CI/CD is not set up, manually update the image tag:
```bash
cd ~/dev/k8s/helm-prod-values
# Edit your app's values.yaml
vim myapp/values.yaml
# Change:
app:
image:
tag: v1.0.0 # Old version
# To:
app:
image:
tag: v1.0.1 # New version
# Commit and push
git add myapp/values.yaml
git commit -m "Update myapp to v1.0.1"
git push
```
ArgoCD will sync within 60 seconds.
### Method 3: Configuration Changes
To update environment variables, resources, or other config:
```bash
cd ~/dev/k8s/helm-prod-values
vim myapp/values.yaml
```
Example changes:
```yaml
app:
# Increase resources
resources:
requests:
cpu: 200m # Was 100m
memory: 256Mi # Was 128Mi
# Add new environment variable
extraEnv:
- name: API_URL
value: https://api.example.com
- name: DEBUG # NEW
value: "true" # NEW
# Enable HPA
hpa:
enabled: true # Was false
minReplicas: 2
maxReplicas: 10
```
Commit and push:
```bash
git add myapp/values.yaml
git commit -m "Increase myapp resources and enable HPA"
git push
```
### Method 4: Application Manifest Changes
To change ArgoCD sync behavior, namespace, or other meta-config:
```bash
cd ~/dev/k8s/launchpad
vim apps/myapp.yaml
```
Example changes:
```yaml
spec:
syncPolicy:
automated:
prune: true
selfHeal: false # Disable self-healing temporarily
```
Commit and push:
```bash
git add apps/myapp.yaml
git commit -m "Disable self-healing for myapp"
git push
```
---
## Working with Secrets
### Understanding Secret Management
**NEVER commit plain secrets to Git.** We use **Sealed Secrets** to encrypt secrets before committing.
### Creating a New Secret
#### Step 1: Create Plain Secret Locally
```bash
cd ~/dev/k8s/launchpad
# Create secret in private/ folder (Git-ignored)
kubectl create secret generic myapp-credentials \
--from-literal=API_KEY=your-secret-key-here \
--from-literal=DB_PASSWORD=super-secret-password \
--dry-run=client -o yaml > private/myapp-credentials.yaml
```
**DO NOT commit this file!** It's in `private/` which is Git-ignored.
#### Step 2: Seal the Secret
Seal your secret:
```bash
kubeseal --format=yaml \
--namespace=myapp \
< private/myapp-credentials.yaml \
> secrets/myapp-credentials-sealed.yaml
```
#### Step 3: Commit Sealed Secret
```bash
git add secrets/myapp-credentials-sealed.yaml
git commit -m "Add myapp credentials (sealed)"
git push
```
#### Step 4: Reference Secret in Application
Update your `helm-prod-values/myapp/values.yaml`:
```yaml
app:
envSecretName: "myapp-credentials" # References the SealedSecret
```
Commit and push:
```bash
cd ~/dev/k8s/helm-prod-values
git add myapp/values.yaml
git commit -m "Reference myapp credentials"
git push
```
### Updating a Secret
To update an existing secret:
```bash
# 1. Create new version of secret
kubectl create secret generic myapp-credentials \
--from-literal=API_KEY=new-key-here \
--from-literal=DB_PASSWORD=new-password \
--dry-run=client -o yaml > private/myapp-credentials.yaml
# 2. Seal it
kubeseal --format=yaml \
--namespace=myapp \
< private/myapp-credentials.yaml \
> secrets/myapp-credentials-sealed.yaml
# 3. Commit sealed version
git add secrets/myapp-credentials-sealed.yaml
git commit -m "Update myapp credentials"
git push
# 4. Restart pods to pick up new secret
kubectl rollout restart deployment myapp -n myapp
```
### Secret Best Practices
✅ **DO**:
- Store secrets in `private/` folder locally
- Always seal secrets before committing
- Delete plain secrets after sealing
- Use meaningful secret names
- Document what each secret contains
❌ **DON'T**:
- Commit plain secrets to Git
- Share secrets via Slack/email
- Hard-code secrets in code
- Use the same secret across multiple environments
- Store secrets in Docker images
### Where Secrets Are Stored
```
┌─────────────────────────────────────────────────────────────┐
│ Location │ Content │ Committed?│
├──────────────────────────┼────────────────────┼────────────┤
│ private/ │ Plain secrets │ ❌ NO │
│ secrets/ │ Sealed secrets │ ✅ YES │
│ Kubernetes cluster │ Unsealed secrets │ N/A │
└─────────────────────────────────────────────────────────────┘
```
**Sealed Secrets Controller** in the cluster decrypts sealed secrets automatically.
---
## Enabling Authentication for Applications
The cluster supports automatic authentication sidecar injection for applications via Kyverno policies. This allows you to add authentication to your applications without modifying application code.
### How It Works
When you enable authentication in your Helm values, the Kyverno policy automatically:
1. ✅ Injects an authentication sidecar container into your pod
2. ✅ Routes all incoming traffic through the auth sidecar (port 8080)
3. ✅ Validates credentials before forwarding requests to your application
4. ✅ Creates necessary secrets (if they don't exist)
5. ✅ Adds a NetworkPolicy to restrict ingress
**Architecture**:
```
Internet → Traefik → Service:8080 → Auth Sidecar:8080 → localhost → Your App:3000
│
├─ Validates credentials
└─ Forwards if valid
```
### Authentication Modes
Three authentication modes are supported:
1. **Token-based**: Static tokens (simple, good for service-to-service or internal apps)
2. **OIDC**: OpenID Connect (full SSO, good for user-facing apps)
3. **MCP**: OAuth 2.0 for MCP servers via RFC 9728 (Protected Resource Metadata); Keycloak provides native RFC 7591 Dynamic Client Registration (good for MCP tool servers requiring OAuth-based access control)
---
### Token-Based Authentication
#### Step 1: Configure Helm Values
```yaml
# In helm-prod-values/myapp/values.yaml
auth:
enabled: true
type: token # Token mode (default)
tokens:
- d4f88f6d9292c10cc3e21c4aad56d2be485db532b54fe961d738e1137d247823
- 8803f621acc3898df1d7a8f514bc3602551a0681a8f747bd4e43c3c5849d57a7
```
#### Step 2: Generate Token (if needed)
```bash
# Generate a secure random token
openssl rand -hex 32
# Or using Python
python3 -c "import secrets; print(secrets.token_hex(32))"
# Example output:
# d4f88f6d9292c10cc3e21c4aad56d2be485db532b54fe961d738e1137d247823
```
#### Step 3: Deploy Application
Commit and push your changes:
```bash
cd ~/dev/k8s/helm-prod-values
git add myapp/values.yaml
git commit -m "Enable token auth for myapp"
git push
```
ArgoCD will sync, and the Kyverno policy will:
- Inject the auth sidecar container
- Create an `auth-tokens` Secret with your tokens
- Configure the sidecar to validate against these tokens
#### Step 4: Access Application
Use your token in the `Authorization` header:
```bash
# Access application with token
curl -H "Authorization: Bearer d4f88f6d9292c10cc3e21c4aad56d2be485db532b54fe961d738e1137d247823" \
https://myapp.forteapps.net/api/data
# Without token (will be rejected)
curl https://myapp.forteapps.net/api/data
# Response: 401 Unauthorized
```
#### Advanced: Custom Secret Name
To use a different secret for tokens:
```yaml
# In Helm values
auth:
enabled: true
type: token
tokens: [] # Empty - using external secret
# Tokens will be read from custom secret
```
Then reference it via annotation (configured by Helm chart automatically):
```yaml
# Helm chart sets this annotation:
policies.forteapps.io/auth-token-secret-name: "myapp-auth-tokens"
```
Create the secret manually:
```bash
kubectl create secret generic myapp-auth-tokens \
--from-file=tokens=tokens.txt \
--namespace=myapp
```
---
### OIDC Authentication
OIDC mode integrates with identity providers like Keycloak, Okta, Auth0, Azure AD, etc.
#### Step 1: Configure Identity Provider
In your identity provider (e.g., Keycloak):
1. Create a new client (e.g., `myapp`)
2. Set redirect URI: `https://myapp.forteapps.net/auth/callback`
3. Note the **Client ID** and **Client Secret**
4. Note the **Authority URL** (e.g., `https://keycloak.forteapps.net/realms/master`)
#### Step 2: Create OIDC Secret
```bash
# Create plain secret
kubectl create secret generic auth-oidc \
--from-literal=client-secret=your-oidc-client-secret \
--from-literal=cookie-secret=$(openssl rand -hex 32) \
--namespace=myapp \
--dry-run=client -o yaml > private/myapp-auth-oidc.yaml
# Seal it
kubeseal --format=yaml \
--cert=pub-cert.pem \
--namespace=myapp \
< private/myapp-auth-oidc.yaml \
> secrets/myapp-auth-oidc-sealed.yaml
# Commit sealed secret
cd ~/dev/k8s/launchpad
git add secrets/myapp-auth-oidc-sealed.yaml
git commit -m "Add OIDC secrets for myapp"
git push
# Clean up
rm private/myapp-auth-oidc.yaml
```
#### Step 3: Configure Helm Values
```yaml
# In helm-prod-values/myapp/values.yaml
auth:
enabled: true
type: oidc # OIDC mode
oidc:
authority: https://keycloak.forteapps.net/realms/master
clientId: myapp
scopes: "openid,profile,email"
callbackPath: /auth/callback
```
#### Step 4: Deploy Application
```bash
cd ~/dev/k8s/helm-prod-values
git add myapp/values.yaml
git commit -m "Enable OIDC auth for myapp"
git push
```
#### Step 5: Access Application
When users access `https://myapp.forteapps.net`:
1. They're redirected to the identity provider login page
2. After successful login, redirected back to `/auth/callback`
3. Session cookie is set
4. Subsequent requests are authenticated via cookie
**User flow**:
```
User → https://myapp.forteapps.net
↓
Redirect → https://keycloak.forteapps.net/login
↓
Login successful → Redirect with auth code
↓
https://myapp.forteapps.net/auth/callback?code=xyz
↓
Auth sidecar exchanges code for tokens
↓
Sets session cookie
↓
Redirects to application → https://myapp.forteapps.net
↓
User sees application (authenticated)
```
---
### Accessing Authenticated User Information
The auth sidecar handles all authentication before requests reach your application. Your app never sees unauthenticated traffic — the sidecar returns 401 or redirects to the IdP first.
After successful authentication, the sidecar forwards the request to your application with user identity injected as HTTP headers:
| Header | Description | Available in |
|--------|-------------|-------------|
| `X-Auth-User` | Username or display name | Token, OIDC, MCP |
| `X-Auth-Email` | User email address | OIDC |
| `X-Auth-Subject` | OIDC `sub` claim (stable user ID) | OIDC, MCP |
| `X-Auth-Groups` | Comma-separated group memberships | OIDC (if scope includes `groups`) |
| `X-Auth-Token` | The validated access token | All modes |
**Your application reads these headers — no auth library needed:**
```javascript
// Express.js example
app.get('/profile', (req, res) => {
const user = req.headers['x-auth-user'];
const email = req.headers['x-auth-email'];
res.json({ user, email });
});
```
```python
# Flask example
@app.route('/profile')
def profile():
user = request.headers.get('X-Auth-User')
email = request.headers.get('X-Auth-Email')
return jsonify(user=user, email=email)
```
**Why this is safe**: The Kyverno-generated NetworkPolicy restricts ingress to the sidecar port only. Traffic cannot bypass the sidecar to reach the application port directly, so the `X-Auth-*` headers can be trusted unconditionally.
**Key principle**: Your application is zero-trust-unaware by design. It reads headers and renders UI. All authentication complexity lives in the sidecar and Kyverno policy.
---
### Authentication Configuration Reference
#### Helm Values Schema
```yaml
auth:
enabled: false # Enable/disable authentication
type: token # "token", "oidc", or "mcp"
# Token mode configuration
tokens: [] # List of valid bearer tokens
# - token1
# - token2
# OIDC mode configuration
oidc:
authority: "" # OIDC provider URL (required for OIDC)
clientId: "" # OIDC client ID (required for OIDC)
scopes: "openid,profile,email" # OIDC scopes (optional)
callbackPath: /auth/callback # OAuth callback path (optional)
# MCP mode configuration (RFC 9728)
mcp:
resource: "" # Protected resource URL (required for MCP)
authority: "" # Authorization server URL (required for MCP)
scopes: "read,write" # Supported scopes (optional)
```
#### Annotations Set by Helm Chart
When `auth.enabled: true`, the Helm chart sets these pod annotations:
**Token mode**:
```yaml
policies.forteapps.io/auth: "true"
policies.forteapps.io/auth-type: "token"
policies.forteapps.io/auth-token-secret-name: "auth-tokens"
policies.forteapps.io/auth-upstream-url: "http://localhost:3000"
```
**OIDC mode**:
```yaml
policies.forteapps.io/auth: "true"
policies.forteapps.io/auth-type: "oidc"
policies.forteapps.io/auth-oidc-authority: "https://keycloak.forteapps.net/realms/master"
policies.forteapps.io/auth-oidc-client-id: "myapp"
policies.forteapps.io/auth-oidc-scopes: "openid,profile,email"
policies.forteapps.io/auth-oidc-callback-path: "/auth/callback"
policies.forteapps.io/auth-upstream-url: "http://localhost:3000"
```
**MCP mode** (OAuth 2.0 for MCP servers):
```yaml
policies.forteapps.io/auth: "true"
policies.forteapps.io/auth-type: "mcp"
policies.forteapps.io/auth-mcp-resource: "https://mcp.forteapps.net"
policies.forteapps.io/auth-mcp-authority: "https://keycloak.forteapps.net/realms/master"
policies.forteapps.io/auth-mcp-scopes: "read,write"
policies.forteapps.io/auth-upstream-url: "http://localhost:3000"
```
#### Sidecar Configuration
The auth sidecar container:
- **Image**: `ghcr.io/fortedigital/auth-sidecar:latest`
- **Port**: 8080
- **Resources**: 10m CPU / 32Mi memory (requests), 50m CPU / 64Mi memory (limits)
- **Health checks**: `/healthz` endpoint
- **Security**: Read-only root filesystem, no privilege escalation
#### Advanced: Custom Sidecar Image
To use a different auth sidecar image:
```yaml
# These annotations can be set in the Helm chart template if needed
policies.forteapps.io/auth-image: "your-registry/your-auth-proxy"
policies.forteapps.io/auth-image-version: "v1.2.3"
```
---
### Authentication Examples
#### Example 1: Internal API with Token Auth
```yaml
# helm-prod-values/internal-api/values.yaml
app:
image:
repository: ghcr.io/company/internal-api
tag: v1.0.0
auth:
enabled: true
type: token
tokens:
- d4f88f6d9292c10cc3e21c4aad56d2be485db532b54fe961d738e1137d247823 # Service A
- 8803f621acc3898df1d7a8f514bc3602551a0681a8f747bd4e43c3c5849d57a7 # Service B
ingress:
enabled: true
host: internal-api.forteapps.net
```
**Usage**:
```bash
# Service A calls API
curl -H "Authorization: Bearer d4f88f..." \
https://internal-api.forteapps.net/api/endpoint
```
#### Example 2: User-Facing App with OIDC
```yaml
# helm-prod-values/web-app/values.yaml
app:
image:
repository: ghcr.io/company/web-app
tag: v2.1.0
auth:
enabled: true
type: oidc
oidc:
authority: https://auth.company.com/realms/employees
clientId: web-app-prod
scopes: "openid,profile,email,groups"
callbackPath: /auth/callback
ingress:
enabled: true
host: web-app.forteapps.net
```
**With sealed OIDC secret**:
```bash
# Create and seal secret
kubectl create secret generic auth-oidc \
--from-literal=client-secret=super-secret-value \
--from-literal=cookie-secret=$(openssl rand -hex 32) \
--namespace=web-app \
--dry-run=client -o yaml | \
kubeseal --format=yaml --cert=pub-cert.pem --namespace=web-app \
> secrets/web-app-auth-oidc-sealed.yaml
```
#### Example 3: MCP Server with OAuth 2.0
```yaml
# helm-prod-values/mcp-server/values.yaml
app:
image:
repository: ghcr.io/company/mcp-server
tag: v1.0.0
auth:
enabled: true
type: mcp
mcp:
resource: https://mcp-server.forteapps.net
authority: https://auth.company.com/realms/mcp
scopes: "read,write,admin"
ingress:
enabled: true
host: mcp-server.forteapps.net
```
The MCP auth mode implements RFC 9728 (OAuth 2.0 Protected Resource Metadata) for authorization server discovery. Dynamic Client Registration (RFC 7591) is handled natively by Keycloak; MCP clients discover the authorization server and scopes from the `/.well-known/oauth-protected-resource` endpoint served by the sidecar and then register directly with Keycloak.
#### Example 4: Disabling Authentication
```yaml
# helm-prod-values/public-api/values.yaml
auth:
enabled: false # No authentication
ingress:
enabled: true
host: public-api.forteapps.net
```
---
### Troubleshooting Authentication
#### Issue: 401 Unauthorized (Token Mode)
**Check token validity**:
```bash
# Get auth-tokens secret
kubectl get secret auth-tokens -n myapp -o yaml
# Decode tokens
kubectl get secret auth-tokens -n myapp \
-o jsonpath='{.data.tokens}' | base64 -d
# Verify your token is in the list
```
**Test with different token**:
```bash
curl -v -H "Authorization: Bearer YOUR-TOKEN-HERE" \
https://myapp.forteapps.net/
```
#### Issue: OIDC Login Loop
**Check OIDC configuration**:
```bash
# Verify auth-oidc secret exists
kubectl get secret auth-oidc -n myapp
# Check sidecar logs
kubectl logs -n myapp <pod-name> -c authn
# Common issues:
# - Wrong authority URL
# - Wrong client ID
# - Missing client-secret in auth-oidc Secret
# - Redirect URI not configured in identity provider
```
**Verify redirect URI** in your identity provider matches:
```
https://<your-app-domain>/auth/callback
```
#### Issue: Auth Sidecar Not Injected
**Check pod annotations**:
```bash
kubectl get pod -n myapp <pod-name> -o yaml | grep policies.forteapps.io
# Should show:
# policies.forteapps.io/auth: "true"
```
**Check Kyverno policy**:
```bash
kubectl get clusterpolicy inject-auth-sidecar
kubectl describe clusterpolicy inject-auth-sidecar
```
**Check Kyverno logs**:
```bash
kubectl logs -n kyverno deployment/kyverno | grep inject-auth
```
#### Issue: Auth Sidecar Crashes
**Check sidecar logs**:
```bash
kubectl logs -n myapp <pod-name> -c authn
```
**Common causes**:
- Missing secret (auth-tokens or auth-oidc)
- Invalid OIDC configuration
- Can't reach OIDC authority URL
- Network policy blocking outbound OIDC requests
---
### Authentication Best Practices
✅ **DO**:
- Use OIDC for user-facing applications
- Use token auth for service-to-service communication
- Rotate tokens and secrets regularly
- Use strong random tokens (32+ bytes)
- Store client secrets in SealedSecrets
- Test authentication before deploying to production
- Document which tokens/users have access
❌ **DON'T**:
- Share tokens between environments
- Commit tokens to application code
- Use predictable tokens
- Reuse tokens across multiple applications
- Disable authentication on sensitive APIs
- Log tokens or secrets
---
## Adding a New Keycloak Client
There are two ways to add an OIDC client, depending on your use case:
| Method | Best for | Who edits the infra repo? |
|--------|----------|--------------------------|
| **Self-service** (recommended) | New apps that deploy their own resources | App developer — no infra changes needed |
| **Legacy (realm JSON)** | Existing clients already defined in forte-realm.json (e.g., Gitea) | Platform engineer |
Both methods are served by the **Keycloak Client Registrar** CronJob, which runs every 2 minutes.
### Self-Service OIDC Client Registration
This is the recommended flow for new applications. Your app deploys a labeled config Secret in its own namespace; the platform handles everything else.
#### How It Works
1. You deploy a Secret with label `keycloak.forteapps.net/client-config: "true"` containing a `client.json` definition
2. A **Kyverno ClusterPolicy** (`keycloak-client-config-cloner`) clones it to the `keycloak` namespace
3. The **Client Registrar CronJob** picks it up within 2 minutes:
- Registers (or updates) the client in Keycloak
- Fetches the auto-generated client secret
- Creates a credential Secret in your app's namespace
- Annotates the config Secret with sync status
#### Step 1: Create the Config Secret
Deploy this Secret in your application's namespace (e.g., as part of your Helm chart or Kustomize overlay):
```yaml
apiVersion: v1
kind: Secret
metadata:
name: keycloak-client-myapp
namespace: myapp
labels:
keycloak.forteapps.net/client-config: "true"
stringData:
client.json: |
{
"clientId": "myapp",
"name": "My Application",
"redirectUris": ["https://myapp.forteapps.net/*"],
"webOrigins": ["https://myapp.forteapps.net"],
"defaultClientScopes": ["openid", "email", "profile"],
"protocolMappers": [],
"secret": {
"namespace": "myapp",
"name": "myapp-oidc-credentials",
"keys": { "clientId": "client-id", "clientSecret": "client-secret" }
}
}
```
**`client.json` fields**:
| Field | Required | Description |
|-------|----------|-------------|
| `clientId` | Yes | Keycloak client ID (must be unique in realm) |
| `name` | Yes | Display name in Keycloak UI |
| `redirectUris` | Yes | Allowed OAuth redirect URLs (supports wildcards like `/*`) |
| `webOrigins` | Yes | Allowed CORS origins |
| `defaultClientScopes` | No | OIDC scopes (default: `["openid", "email", "profile"]`) |
| `protocolMappers` | No | Custom claim mappers for tokens (see examples below) |
| `secret.namespace` | No | Target namespace for credentials (default: `source-namespace` annotation value) |
| `secret.name` | No | Credential Secret name (default: `<clientId>-oidc-credentials`) |
| `secret.keys.clientId` | No | Key name for client ID (default: `client-id`) |
| `secret.keys.clientSecret` | No | Key name for client secret (default: `client-secret`) |
**Protocol Mappers Example**:
```json
"protocolMappers": [
{
"name": "groups",
"protocol": "openid-connect",
"protocolMapper": "oidc-group-membership-mapper",
"config": {
"claim.name": "groups",
"full.path": "false",
"id.token.claim": "true",
"access.token.claim": "true",
"userinfo.token.claim": "true"
}
}
]
```
#### Step 2: Reference the Credential Secret
In your application's deployment config, reference the credential Secret that the registrar creates:
```yaml
env:
- name: OIDC_CLIENT_ID
valueFrom:
secretKeyRef:
name: myapp-oidc-credentials
key: client-id
- name: OIDC_CLIENT_SECRET
valueFrom:
secretKeyRef:
name: myapp-oidc-credentials
key: client-secret
```
#### Step 3: Deploy and Wait
Commit and push your changes. The credential Secret will appear within 2 minutes:
```bash
# Watch for the credential Secret to be created
kubectl get secret myapp-oidc-credentials -n myapp -w
# Check registrar logs
kubectl logs -n keycloak job/$(kubectl get jobs -n keycloak --sort-by=.metadata.creationTimestamp -o jsonpath='{.items[-1].metadata.name}')
# Check sync status on the config Secret
kubectl get secret keycloak-client-myapp -n keycloak -o jsonpath='{.metadata.annotations}'
```
#### Change Detection
The registrar computes a SHA-256 hash of `client.json` and stores it as an annotation. On subsequent runs, it skips processing if:
- The hash hasn't changed, AND
- The credential Secret already exists in the target namespace
To force a re-sync, update any field in `client.json` (e.g., add a trailing space to `name`).
### Legacy Method: Realm JSON
Existing clients (like Gitea) are defined directly in `forte-realm.json` inside `keycloak-values.yaml`. The registrar syncs their secrets via client attributes.
#### Step 1: Add Client to Realm Config
In `infra/values/base/keycloak-values.yaml`, add a new entry to the `clients` array in `forte-realm.json`:
```json
{
"clientId": "myapp",
"name": "My Application",
"enabled": true,
"protocol": "openid-connect",
"clientAuthenticatorType": "client-secret",
"standardFlowEnabled": true,
"directAccessGrantsEnabled": false,
"publicClient": false,
"redirectUris": ["https://myapp.forteapps.net/*"],
"webOrigins": ["https://myapp.forteapps.net"],
"defaultClientScopes": ["openid", "email", "profile"],
"attributes": {
"k8s.secret.sync": "true",
"k8s.secret.namespace": "myapp",
"k8s.secret.name": "myapp-oidc-credentials",
"k8s.secret.client-id-key": "key",
"k8s.secret.client-secret-key": "secret"
}
}
```
**Important**:
- Do **NOT** include a `"secret"` field — Keycloak generates one automatically
- The `attributes` block tells the registrar where to create the K8s Secret
- Set `client-id-key` / `client-secret-key` to match what the consuming app expects (defaults: `client-id` / `client-secret`)
#### Step 2: Reference the Secret in Your Application
```yaml
existingSecret: myapp-oidc-credentials
```
#### Step 3: Commit and Push
```bash
cd ~/dev/k8s/launchpad
git add infra/values/base/keycloak-values.yaml
git commit -m "Add myapp Keycloak client with auto-sync"
git push
```
ArgoCD will sync the Keycloak config, and the registrar CronJob will pick up the new client within 2 minutes.
#### Legacy Sync Attribute Reference
| Attribute | Required | Default | Description |
|-----------|----------|---------|-------------|
| `k8s.secret.sync` | Yes | — | Set to `"true"` to enable syncing |
| `k8s.secret.namespace` | Yes | — | Target K8s namespace for the secret |
| `k8s.secret.name` | Yes | — | Name of the K8s Secret to create |
| `k8s.secret.client-id-key` | No | `client-id` | Field name for the client ID in the K8s Secret |
| `k8s.secret.client-secret-key` | No | `client-secret` | Field name for the client secret in the K8s Secret |
#### Public CLI Client (Device-Code Login)
`forte-cli` is a shared **public** client (no secret) with the RFC 8628 device-authorization grant enabled (`oauth2.device.authorization.grant.enabled: "true"`, `standardFlowEnabled: false`, `directAccessGrantsEnabled: false`). Downloaded skills and CLI tools that log in through the Auth Sidecar (forte-drop first) use it with `<PREFIX>_CLIENT_ID=forte-cli`; nothing per-tool needs to be registered in Keycloak.
It must be defined in `forte-realm.json` (this legacy path): the self-service registrar hardcodes `publicClient: false` / `standardFlowEnabled: true` and drops `attributes`, so a `client-config` Secret cannot produce a public device-code client. It carries no `k8s.secret.sync` attribute (the registrar's secret sync skips it) and is listed in the cleanup CronJob's protected clients.
### Retrieving Secrets for External Deployments
The registrar always writes a **central copy** of every synced secret to the `secrets` namespace, in addition to the target namespace. This allows operators to retrieve client credentials for applications deployed outside this cluster:
```bash
# View the central copy
kubectl get secret gitea-oidc-credentials -n secrets -o yaml
# Extract the client secret for use elsewhere
kubectl get secret myapp-oidc-credentials -n secrets \
-o jsonpath='{.data.client-secret}' | base64 -d
```
### Registrar Behavior Notes
- The registrar runs as a CronJob every 2 minutes (`concurrencyPolicy: Forbid`)
- If the target namespace doesn't exist, the target write is skipped with a warning (the central copy still happens)
- A central copy is **always** written to the `secrets` namespace for every synced client
- The registrar uses the `keycloak-credentials` secret for admin authentication
- Created secrets have the label `app.kubernetes.io/managed-by: keycloak-client-registrar`
---
## Troubleshooting
### Application Not Deploying
#### Problem: Application stuck in "Syncing" state
**Check ArgoCD status:**
```bash
kubectl get application myapp -n argocd -o yaml
```
Look for errors in `status.conditions`.
**Common causes:**
- ❌ Image doesn't exist or is not accessible
- ❌ Invalid YAML syntax
- ❌ Resource quota exceeded
- ❌ Namespace conflicts
- ❌ Invalid Helm values
**Solutions:**
```bash
# Check image exists
docker pull ghcr.io/fortedigital/myapp:v1.0.0
# Validate YAML syntax
kubectl apply --dry-run=client -f apps/myapp.yaml
# Check ArgoCD logs
kubectl logs -n argocd deployment/argocd-application-controller | grep myapp
```
#### Problem: Pods crashing (CrashLoopBackOff)
**Check pod logs:**
```bash
kubectl get pods -n myapp
kubectl logs -n myapp <pod-name>
kubectl describe pod -n myapp <pod-name>
```
**Common causes:**
- ❌ Application error (check logs)
- ❌ Missing environment variables
- ❌ Incorrect port configuration
- ❌ Missing secrets
- ❌ Insufficient resources
**Solutions:**
```bash
# Check environment variables
kubectl exec -n myapp <pod-name> -- env
# Check if secrets exist
kubectl get secrets -n myapp
# Increase resources in helm-prod-values
vim ~/dev/k8s/helm-prod-values/myapp/values.yaml
```
#### Problem: Application not accessible via domain
**Check ingress:**
```bash
kubectl get ingressroute -n myapp
kubectl describe ingressroute myapp -n myapp
```
**Common causes:**
- ❌ DNS not configured
- ❌ TLS certificate not issued
- ❌ Incorrect domain in values.yaml
- ❌ Traefik not routing correctly
**Solutions:**
```bash
# Check certificate
kubectl get certificate -n myapp
# Check cert-manager logs
kubectl logs -n cert-manager deployment/cert-manager
# Verify domain configuration
cat ~/dev/k8s/helm-prod-values/myapp/values.yaml | grep host
# Test with port-forward
kubectl port-forward -n myapp service/myapp 8080:3000
curl http://localhost:8080
```
### Secret Issues
#### Problem: Secret not found
**Check if SealedSecret exists:**
```bash
kubectl get sealedsecret -n myapp
kubectl get secret -n myapp
```
**Solutions:**
```bash
# Check if secret is in Git
ls -l secrets/myapp-credentials-sealed.yaml
# Re-apply sealed secret
kubectl apply -f secrets/myapp-credentials-sealed.yaml
# Check sealed-secrets-controller logs
kubectl logs -n kube-system deployment/sealed-secrets-controller
```
#### Problem: Secret exists but pods can't access it
**Check pod events:**
```bash
kubectl describe pod -n myapp <pod-name>
```
Look for: `Error: secret "myapp-credentials" not found`
**Solutions:**
```bash
# Verify secret name in values.yaml matches actual secret
cat ~/dev/k8s/helm-prod-values/myapp/values.yaml | grep envSecretName
kubectl get secrets -n myapp
# Restart pods
kubectl rollout restart deployment myapp -n myapp
```
### Sync Failures
#### Problem: ArgoCD shows "Out of Sync"
**Manual sync:**
```bash
# Using kubectl
kubectl patch application myapp -n argocd --type merge -p '{"operation":{"initiatedBy":{"username":"admin"},"sync":{"syncStrategy":{"hook":{}}}}}'
# Or via ArgoCD UI
# Click "Sync" button in UI
```
**Check what's different:**
```bash
kubectl get application myapp -n argocd -o yaml
```
Look at `status.sync.comparedTo` vs desired state.
#### Problem: Sync succeeds but application is "Degraded"
**Check resource health:**
```bash
kubectl get application myapp -n argocd -o jsonpath='{.status.resources[*].health}'
```
**Common causes:**
- ❌ Pods not ready
- ❌ Deployments not at desired replica count
- ❌ Jobs failed
**Solutions:**
```bash
# Check all resources in namespace
kubectl get all -n myapp
# Check pod events
kubectl get events -n myapp --sort-by='.lastTimestamp'
```
### Getting Help
If you're stuck:
1. **Check Slack notifications** - Error details are often in sync failure messages
2. **Check ArgoCD UI** - Visual representation of what's wrong
3. **Ask platform team** - They have full cluster access and can debug further
4. **Check documentation** - [Operations Runbook](OPERATIONS-RUNBOOK.md) has more troubleshooting
---
## Best Practices
### Development Workflow
✅ **DO**:
- Develop and test locally with Docker Compose
- Use semantic versioning for releases
- Write descriptive commit messages
- Test changes in a separate namespace first (if possible)
- Monitor Slack for deployment notifications
- Document environment variables and configuration
❌ **DON'T**:
- Push directly to production without testing
- Use `latest` tag for Docker images
- Bypass CI/CD for "quick fixes"
- Hard-code configuration values
- Ignore deployment failures
### Configuration Management
✅ **DO**:
- Keep configuration in `helm-prod-values` repository
- Use environment variables for config
- Document what each value does
- Use reasonable resource limits
- Enable ingress and TLS for public services
❌ **DON'T**:
- Hard-code config in application code
- Over-allocate resources (wastes money)
- Under-allocate resources (causes crashes)
- Use HTTP for production services
### Secret Management
✅ **DO**:
- Use kubeseal for all secrets
- Store plain secrets in password manager
- Rotate secrets regularly
- Use different secrets per environment
- Document what each secret contains
❌ **DON'T**:
- Commit plain secrets
- Share secrets in Slack/email
- Reuse secrets across apps
- Log secrets in application code
### Git Workflow
✅ **DO**:
- Use feature branches for changes
- Write clear commit messages
- Use pull requests for review
- Keep commits atomic and focused
- Tag releases in application repos
❌ **DON'T**:
- Push directly to `main` without review (for config repos)
- Make multiple unrelated changes in one commit
- Use vague commit messages ("fix", "update")
- Force-push to main branches
---
## Quick Reference
### Common Commands
```bash
# Check application status
kubectl get application myapp -n argocd
# View application details
kubectl describe application myapp -n argocd
# Check pods
kubectl get pods -n myapp
# View pod logs
kubectl logs -n myapp <pod-name>
# Restart deployment
kubectl rollout restart deployment myapp -n myapp
# Port-forward to service
kubectl port-forward -n myapp service/myapp 8080:3000
# Create secret
kubectl create secret generic myapp-credentials \
--from-literal=KEY=value \
--dry-run=client -o yaml > private/myapp-credentials.yaml
# Seal secret
kubeseal --format=yaml \
--cert=pub-cert.pem \
< private/myapp-credentials.yaml \
> secrets/myapp-credentials-sealed.yaml
```
### Repository Locations
```bash
# Config repository
cd ~/dev/k8s/launchpad
# Helm values repository
cd ~/dev/k8s/helm-prod-values
# Helm charts repository
cd ~/dev/k8s/forte-helm
```
### File Paths
```bash
# New application manifest
~/dev/k8s/launchpad/apps/myapp.yaml
# Application values
~/dev/k8s/helm-prod-values/myapp/values.yaml
# Sealed secrets
~/dev/k8s/launchpad/secrets/myapp-credentials-sealed.yaml
# Plain secrets (local only)
~/dev/k8s/launchpad/private/myapp-credentials.yaml
```
---
## Next Steps
Now that you understand the basics:
1. ✅ Deploy your first application (follow steps above)
2. 📖 Read the [Operations Runbook](OPERATIONS-RUNBOOK.md) for common tasks
3. 📖 Review [Technical Reference](REFERENCE.md) for detailed component docs
4. 📖 Understand [GitOps Architecture](GITOPS-ARCHITECTURE.md) for the big picture
5. 🚀 Start contributing!
---
**Questions?**
- Slack: #platform-support
- Docs: [Full documentation index](README.md)
- Help: Contact platform team
**Last Updated**: 2026-04-16