Files
launchpad/docs/DEVELOPER-GUIDE.md
T
danijel.simeunovic 4ab7ccd781 chore(deps): update terraform google to v8
commit c5e0aa6f3c
Author: gitea_admin <admin@forteapps.net>
Date:   Wed Oct 7 06:36:01 2026 +0000

    chore(deps): update nikitafilonov/ai-review docker tag to v1.4.0 (#59)

    This PR contains the following updates:

    | Package | Type | Update | Change |
    |---|---|---|---|
    | nikitafilonov/ai-review | docker | minor | `v1.1.0` → `v1.4.0` |

    ---

    ### Configuration

    📅 **Schedule**: (in timezone Europe/Oslo)

    - Branch creation
      - At any time (no schedule defined)
    - Automerge
      - At any time (no schedule defined)

    🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

    ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

    🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

    ---

     - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

    ---

    This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
    <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

    ---------

    Co-authored-by: Renovate Bot <renovate@forteapps.net>
    Reviewed-on: #59
    Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
    Co-authored-by: gitea_admin <admin@forteapps.net>

commit 7915346868
Author: gitea_admin <admin@forteapps.net>
Date:   Sun Oct 4 21:53:01 2026 +0000

    chore(deps): update gitea/gitea docker tag to v28 (#58)

    This PR contains the following updates:

    | Package | Update | Change |
    |---|---|---|
    | [gitea/gitea](https://github.com/go-gitea/gitea) | major | `1.27.3` → `28.0.0` |

    ---

    ### Release Notes

    <details>
    <summary>go-gitea/gitea (gitea/gitea)</summary>

    ### [`v28.0.0`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#2800---2026-09-30)

    [Compare Source](https://github.com/go-gitea/gitea/compare/v1.27.3...v28.0.0)

    - BREAKING
      - Fix(git)!: route Git network operations through an internal proxy and update egress settings ([#&#8203;39426](https://github.com/go-gitea/gitea/pull/39426))
      - Feat(actions)!: add RUN\_RETENTION\_DAYS to delete old action runs ([#&#8203;38855](https://github.com/go-gitea/gitea/pull/38855))

    - SECURITY
      - Fix(git): reject invalid and duplicate Git objects on push ([#&#8203;39472](https://github.com/go-gitea/gitea/pull/39472))
      - Fix(git)!: route Git network operations through an internal proxy and update egress settings ([#&#8203;39426](https://github.com/go-gitea/gitea/pull/39426))
      - Fix(ssh): identify presented public keys by fingerprint ([#&#8203;39423](https://github.com/go-gitea/gitea/pull/39423))
      - Fix(actions): keep cancelled and unapproved fork PR runs behind the approval gate ([#&#8203;39399](https://github.com/go-gitea/gitea/pull/39399))
      - Fix(deps): update golang.org/x/crypto SSH to address denial of service ([#&#8203;39219](https://github.com/go-gitea/gitea/pull/39219))
      - Fix(repo): enforce repository-scoped authorization for team access, deletion, and package unlinking ([#&#8203;39063](https://github.com/go-gitea/gitea/pull/39063))

    - FEATURES
      - Feat(actions): update actionslib, support `self:`, misc fixes ([#&#8203;39358](https://github.com/go-gitea/gitea/pull/39358))
      - Feat(api): list all packages for site administrators ([#&#8203;38968](https://github.com/go-gitea/gitea/pull/38968))
      - Feat: manage bot accounts from the admin UI, API and CLI ([#&#8203;38966](https://github.com/go-gitea/gitea/pull/38966))
      - Feat(user): Personal access tokens can be regenerated ([#&#8203;38907](https://github.com/go-gitea/gitea/pull/38907))
      - Feat(actions): support `$/` prefix in reusable workflow `uses:` ([#&#8203;38822](https://github.com/go-gitea/gitea/pull/38822))
      - Feat(actions): add force-cancel workflow run API ([#&#8203;38756](https://github.com/go-gitea/gitea/pull/38756))
      - Feat(licenses): support REUSE specification in licenses ([#&#8203;38720](https://github.com/go-gitea/gitea/pull/38720))
      - Feat(api): add project APIs ([#&#8203;38691](https://github.com/go-gitea/gitea/pull/38691))
      - Feat(webhook): fire repository event on repo rename ([#&#8203;38641](https://github.com/go-gitea/gitea/pull/38641))
      - Feat: admin impersonates a user ([#&#8203;38614](https://github.com/go-gitea/gitea/pull/38614))
      - Feat(actions): add build queue view ([#&#8203;38585](https://github.com/go-gitea/gitea/pull/38585))
      - Feat(setting): add shared \[redis] section as default for redis-backed subsystems ([#&#8203;38550](https://github.com/go-gitea/gitea/pull/38550))
      - Feat(repo): prioritize well-known READMEs and optimize discovery ([#&#8203;38532](https://github.com/go-gitea/gitea/pull/38532))
      - Feat(actions): implement adaptive auto-refresh for workflow runs list ([#&#8203;38329](https://github.com/go-gitea/gitea/pull/38329))
      - Feat(auth): add `disable-2fa` command ([#&#8203;38275](https://github.com/go-gitea/gitea/pull/38275))
      - Feat: Add audit logging ([#&#8203;38189](https://github.com/go-gitea/gitea/pull/38189))
      - Feat(repo): add quick repository switcher to repo header ([#&#8203;38188](https://github.com/go-gitea/gitea/pull/38188))
      - Feat(repo): support file exclusion logic in .gitea/template in template generation ([#&#8203;38064](https://github.com/go-gitea/gitea/pull/38064))
      - Feat(web): Add org removal functionality to admin user details page ([#&#8203;38013](https://github.com/go-gitea/gitea/pull/38013))
      - Feat: add watch options ([#&#8203;37571](https://github.com/go-gitea/gitea/pull/37571))
      - Feat: add deploy tokens ([#&#8203;37306](https://github.com/go-gitea/gitea/pull/37306))
      - Feat(diff): Add search and extension filter to diff sidebar ([#&#8203;37068](https://github.com/go-gitea/gitea/pull/37068))
      - Feat: Replace SSE with WebSocket for UI notifications ([#&#8203;36965](https://github.com/go-gitea/gitea/pull/36965))
      - Feat(actions): Add artifact preview in Actions run view ([#&#8203;36754](https://github.com/go-gitea/gitea/pull/36754))
      - Feat(packages): add support for uploading helm provenance files ([#&#8203;36695](https://github.com/go-gitea/gitea/pull/36695))
      - Feat: Add support for dynamic matrix evaluation in Gitea Actions workflows ([#&#8203;36564](https://github.com/go-gitea/gitea/pull/36564))
      - Feat: Add max-parallel Support for Gitea Actions ([#&#8203;36357](https://github.com/go-gitea/gitea/pull/36357))
      - Feat(actions): Add Actions API endpoints for workflow run management and logs ([#&#8203;35382](https://github.com/go-gitea/gitea/pull/35382))
      - Feat: Add block on pending codeowner reviews branch protection ([#&#8203;34995](https://github.com/go-gitea/gitea/pull/34995))

    - ENHANCEMENTS
      - Enhance: allow auto-closing PRs from PRs ([#&#8203;39393](https://github.com/go-gitea/gitea/pull/39393))
      - Enhance(actions): add pending job status and align job statuses with GitHub ([#&#8203;39376](https://github.com/go-gitea/gitea/pull/39376))
      - Enhance(acme): add configurable ACME profile ([#&#8203;39375](https://github.com/go-gitea/gitea/pull/39375))
      - Enhance(emoji): update to Unicode 17, unify and lazy-load emoji data ([#&#8203;39363](https://github.com/go-gitea/gitea/pull/39363))
      - Enhance: improve issue-pattern capture groups and support both internal\&external trackers enabled ([#&#8203;39354](https://github.com/go-gitea/gitea/pull/39354))
      - Enhance: update mermaid to v12 ([#&#8203;39331](https://github.com/go-gitea/gitea/pull/39331))
      - Enhance(notifications): mark current notification page as read ([#&#8203;39294](https://github.com/go-gitea/gitea/pull/39294))
      - Enhance: support `ETag` on streamed repository archives, support `If-None-Match: *` ([#&#8203;39289](https://github.com/go-gitea/gitea/pull/39289))
      - Enhance: truncate but show long lines in diffs ([#&#8203;39279](https://github.com/go-gitea/gitea/pull/39279))
      - Enhance(packages): implement npm single-version API and add per-version repository ([#&#8203;39267](https://github.com/go-gitea/gitea/pull/39267))
      - Enhance: move window\.config to JSON, improve CSP format ([#&#8203;39236](https://github.com/go-gitea/gitea/pull/39236))
      - Enhance: improve commit page header ([#&#8203;39229](https://github.com/go-gitea/gitea/pull/39229))
      - Enhance: Improve validation errors for secrets/variables ([#&#8203;39221](https://github.com/go-gitea/gitea/pull/39221))
      - Enhance(repo): check full repo name for dangerous operations ([#&#8203;39213](https://github.com/go-gitea/gitea/pull/39213))
      - Enhance(web): hide attachment dropzone on preview tab in combo editor ([#&#8203;39204](https://github.com/go-gitea/gitea/pull/39204))
      - Enhance(web): show attachment URL and UUID in dropzone preview ([#&#8203;39203](https://github.com/go-gitea/gitea/pull/39203))
      - Enhance(actions): make workflow dispatch choice dropdown support search ([#&#8203;39154](https://github.com/go-gitea/gitea/pull/39154))
      - Enhance(repo): unify diff stats on commit pages, misc diff tweaks ([#&#8203;39134](https://github.com/go-gitea/gitea/pull/39134))
      - Enhance: use browser's locale to detect week's first day for the contribution map ([#&#8203;38995](https://github.com/go-gitea/gitea/pull/38995))
      - Enhance(ui): forced colors mode enhancements ([#&#8203;38991](https://github.com/go-gitea/gitea/pull/38991))
      - Enhance: user-friendly packages setup manual ([#&#8203;38946](https://github.com/go-gitea/gitea/pull/38946))
      - Enhance: inherit team access for all units ([#&#8203;38938](https://github.com/go-gitea/gitea/pull/38938))
      - Enhance(admin): show impersonation banner and keep password change with the user ([#&#8203;38924](https://github.com/go-gitea/gitea/pull/38924))
      - Enhance(ui): tint toast backgrounds by level ([#&#8203;38919](https://github.com/go-gitea/gitea/pull/38919))
      - Enhance(repo): add default object format setting ([#&#8203;38877](https://github.com/go-gitea/gitea/pull/38877))
      - Enhance(actions): set ref\_protected in context ([#&#8203;38852](https://github.com/go-gitea/gitea/pull/38852))
      - Enhance(ui): restyle toasts ([#&#8203;38842](https://github.com/go-gitea/gitea/pull/38842))
      - Enhance: refine repo watching ([#&#8203;38835](https://github.com/go-gitea/gitea/pull/38835))
      - Enhance: fall back to DEFAULT\_TEMPLATE.md when style-specific template is missing ([#&#8203;38803](https://github.com/go-gitea/gitea/pull/38803))
      - Enhance(api): add GitHub-compatible /repos/{owner}/{repo}/commits/{ref} endpoint ([#&#8203;38770](https://github.com/go-gitea/gitea/pull/38770))
      - Enhance(api): expose file mode in contents API response ([#&#8203;38713](https://github.com/go-gitea/gitea/pull/38713))
      - Enhance(tls): use go's tls defaults ([#&#8203;38687](https://github.com/go-gitea/gitea/pull/38687))
      - Enhance(ui): improve luminance calculations ([#&#8203;38682](https://github.com/go-gitea/gitea/pull/38682))
      - Enhance(api): add `tag_filter` query parameter to release list API ([#&#8203;38681](https://github.com/go-gitea/gitea/pull/38681))
      - Enhance(actions): replace `ansi_up` with first-party code ([#&#8203;38619](https://github.com/go-gitea/gitea/pull/38619))
      - Enhance: keep status check list scrolled on merge box reload ([#&#8203;38597](https://github.com/go-gitea/gitea/pull/38597))
      - Enhance(actions): action view enhancements ([#&#8203;38594](https://github.com/go-gitea/gitea/pull/38594))
      - Enhance(ui): tweak tooltip style and misc fixes ([#&#8203;38524](https://github.com/go-gitea/gitea/pull/38524))
      - Enhance: improve e-mail templates ([#&#8203;38396](https://github.com/go-gitea/gitea/pull/38396))
      - Enhance(webhook): add reviewer name to MS Teams review request notifications ([#&#8203;38289](https://github.com/go-gitea/gitea/pull/38289))
      - Enhance: extend <video> tag allowed attributes ([#&#8203;38279](https://github.com/go-gitea/gitea/pull/38279))
      - Enhance(packages/npm): expand version metadata and support npm deprecate ([#&#8203;37890](https://github.com/go-gitea/gitea/pull/37890))

    - PERFORMANCE
      - Perf(references): scan only the keyword window before a reference ([#&#8203;39396](https://github.com/go-gitea/gitea/pull/39396))
      - Perf(frontend): enable vite module preload ([#&#8203;39332](https://github.com/go-gitea/gitea/pull/39332))
      - Perf(gitdiff): optimize inline diff highlighting using cache ([#&#8203;38706](https://github.com/go-gitea/gitea/pull/38706))

    - BUGFIXES
      - Fix(actions): preserve admitted jobs and runs in their concurrency group ([#&#8203;39461](https://github.com/go-gitea/gitea/pull/39461))
      - Fix(api): commit tree SHA is the commit ID ([#&#8203;39449](https://github.com/go-gitea/gitea/pull/39449))
      - Fix: PR merge ([#&#8203;39442](https://github.com/go-gitea/gitea/pull/39442))
      - Fix(actions): evaluate job-level `if:` before concurrency check ([#&#8203;39437](https://github.com/go-gitea/gitea/pull/39437))
      - Fix(api): allow pending-inline-comment-only reviews ([#&#8203;39433](https://github.com/go-gitea/gitea/pull/39433))
      - Fix: sanitize external render command line arguments ([#&#8203;39417](https://github.com/go-gitea/gitea/pull/39417))
      - Fix(LFS): recalculate repo LFSSize after gc-lfs removes orphaned data ([#&#8203;39406](https://github.com/go-gitea/gitea/pull/39406))
      - Fix(indexer): index full file paths and real offsets in bleve ([#&#8203;39405](https://github.com/go-gitea/gitea/pull/39405))
      - Fix(git): keep leading dashes in git grep search patterns ([#&#8203;39404](https://github.com/go-gitea/gitea/pull/39404))
      - Fix: use clearer message for ldap auth failure ([#&#8203;39392](https://github.com/go-gitea/gitea/pull/39392))
      - Fix(repo): commit page fails to render unsigned commits with a different committer ([#&#8203;39381](https://github.com/go-gitea/gitea/pull/39381))
      - Fix: focus confirm button and use red for delete confirmations ([#&#8203;39350](https://github.com/go-gitea/gitea/pull/39350))
      - Fix(migrations): preserve SHA-256 pull request commit IDs ([#&#8203;39343](https://github.com/go-gitea/gitea/pull/39343))
      - Fix(ui): misc ui fixes ([#&#8203;39336](https://github.com/go-gitea/gitea/pull/39336))
      - Fix(actions): use gitea's clock for actions durations ([#&#8203;39323](https://github.com/go-gitea/gitea/pull/39323))
      - Fix(actions): never show negative running durations ([#&#8203;39322](https://github.com/go-gitea/gitea/pull/39322))
      - Fix: package registry keypair creation race ([#&#8203;39319](https://github.com/go-gitea/gitea/pull/39319))
      - Fix: add default timeout and handle errors for HaveIBeenPwned API ([#&#8203;39316](https://github.com/go-gitea/gitea/pull/39316))
      - Fix(user): unify email validation for registration and settings ([#&#8203;39304](https://github.com/go-gitea/gitea/pull/39304))
      - Fix(ui): use button elements for branch and tag dropdown tabs ([#&#8203;39285](https://github.com/go-gitea/gitea/pull/39285))
      - Fix(auth): fix ssh and gpg key verification on windows ([#&#8203;39283](https://github.com/go-gitea/gitea/pull/39283))
      - Fix(feed): use meaningful lines as comment excerpt ([#&#8203;39276](https://github.com/go-gitea/gitea/pull/39276))
      - Fix(projects): allow max columns to the limit ([#&#8203;39272](https://github.com/go-gitea/gitea/pull/39272))
      - Fix: pass merge commit messages to git via stdin ([#&#8203;39269](https://github.com/go-gitea/gitea/pull/39269))
      - Fix(repo): surface unrelated histories on Sync Fork ([#&#8203;39258](https://github.com/go-gitea/gitea/pull/39258))
      - Fix: avoid nil panic and refactor some trivial problems ([#&#8203;39251](https://github.com/go-gitea/gitea/pull/39251))
      - Fix: restore missing blob file when re-publishing a package ([#&#8203;39239](https://github.com/go-gitea/gitea/pull/39239))
      - Fix(automerge): validate head commit before merge ([#&#8203;39235](https://github.com/go-gitea/gitea/pull/39235))
      - Fix(httplib): prevent leaking localhost:3000 in public links ([#&#8203;39217](https://github.com/go-gitea/gitea/pull/39217))
      - Fix(setting): honor bare -1 for timeout settings ([#&#8203;39181](https://github.com/go-gitea/gitea/pull/39181))
      - Fix: correct repo/attatchment absolute url and release layout ([#&#8203;39178](https://github.com/go-gitea/gitea/pull/39178))
      - Fix(web): populate the reason for "cannot commit to branch" in web editor commit form ([#&#8203;39155](https://github.com/go-gitea/gitea/pull/39155))
      - Fix(process): reap entire process group on cmd.Cancel ([#&#8203;39143](https://github.com/go-gitea/gitea/pull/39143))
      - Fix: recognize linguist language aliases ([#&#8203;39135](https://github.com/go-gitea/gitea/pull/39135))
      - Fix(repo): preserve transfer recipient collaboration ([#&#8203;39042](https://github.com/go-gitea/gitea/pull/39042))
      - Fix(db): make paginated database reads always require "order" option ([#&#8203;39017](https://github.com/go-gitea/gitea/pull/39017))
      - Fix: make local queue PopItem can be notified ([#&#8203;39011](https://github.com/go-gitea/gitea/pull/39011))
      - Fix: classify git failures on stderr, restrict migration failure detail ([#&#8203;39010](https://github.com/go-gitea/gitea/pull/39010))
      - Fix: allow re-requesting uncounted review approvals ([#&#8203;38988](https://github.com/go-gitea/gitea/pull/38988))
      - Fix(actions): allow larger scheduled workflows ([#&#8203;38985](https://github.com/go-gitea/gitea/pull/38985))
      - Fix: resolve actions commit status permission per repository ([#&#8203;38977](https://github.com/go-gitea/gitea/pull/38977))
      - Fix(deps): update module golang.org/x/image to v0.45.0 \[security] ([#&#8203;38930](https://github.com/go-gitea/gitea/pull/38930))
      - Fix(deps): update module golang.org/x/mod to v0.40.0 \[security] ([#&#8203;38914](https://github.com/go-gitea/gitea/pull/38914))
      - Fix: dedupe issue cross-reference timeline entries ([#&#8203;38881](https://github.com/go-gitea/gitea/pull/38881))
      - Fix(server): set `ReadHeaderTimeout` on HTTP servers ([#&#8203;38878](https://github.com/go-gitea/gitea/pull/38878))
      - Fix(repo): avoid a repo-sized temp file for every bundle download ([#&#8203;38863](https://github.com/go-gitea/gitea/pull/38863))
      - Fix(lfs): ensure lock listing paginates with a total order ([#&#8203;38850](https://github.com/go-gitea/gitea/pull/38850))
      - Fix(avatar): use sha256 and inline the federated avatar lookup ([#&#8203;38843](https://github.com/go-gitea/gitea/pull/38843))
      - Fix(gitdiff): render exact-limit diffs and zero-limit comments ([#&#8203;38838](https://github.com/go-gitea/gitea/pull/38838))
      - Fix(deps): update dependency mermaid to v11.16.1 \[security] ([#&#8203;38813](https://github.com/go-gitea/gitea/pull/38813))
      - Fix: misc fixes in pub/gpg/tests ([#&#8203;38809](https://github.com/go-gitea/gitea/pull/38809))
      - Fix: git diff blob excerpt ([#&#8203;38808](https://github.com/go-gitea/gitea/pull/38808))
      - Fix(packages): show error for duplicate cleanup rules [#&#8203;37820](https://github.com/go-gitea/gitea/issues/37820) ([#&#8203;38786](https://github.com/go-gitea/gitea/pull/38786))
      - Fix(actions): fix runner docs link ([#&#8203;38783](https://github.com/go-gitea/gitea/pull/38783))
      - Fix: git cache ([#&#8203;38763](https://github.com/go-gitea/gitea/pull/38763))
      - Fix(actions): evaluate each `${{ }}` part on its own ([#&#8203;38754](https://github.com/go-gitea/gitea/pull/38754))
      - Fix: don't report failed network requests as JavaScript errors ([#&#8203;38732](https://github.com/go-gitea/gitea/pull/38732))
      - Fix(gitdiff): prevent index out of range panic in GetLineTypeMarker ([#&#8203;38728](https://github.com/go-gitea/gitea/pull/38728))
      - Fix(api): document X-Total-Count instead of non-existent X-Total header ([#&#8203;38717](https://github.com/go-gitea/gitea/pull/38717))
      - Fix(actions): dynamic matrix expansion correctness fixes ([#&#8203;38690](https://github.com/go-gitea/gitea/pull/38690))
      - Fix(auth): record last sign-in on reverse proxy login ([#&#8203;38672](https://github.com/go-gitea/gitea/pull/38672))
      - Fix(api): accept fully-qualified refs in contents API ([#&#8203;38650](https://github.com/go-gitea/gitea/pull/38650))
      - Fix(deps): update module github.com/getkin/kin-openapi to v0.144.0 \[security] ([#&#8203;38623](https://github.com/go-gitea/gitea/pull/38623))
      - Fix(deps): update dependency js-yaml to v5.2.2 \[security] ([#&#8203;38622](https://github.com/go-gitea/gitea/pull/38622))
      - Fix: abort superseded issue suggestion requests ([#&#8203;38620](https://github.com/go-gitea/gitea/pull/38620))
      - Fix(issue): display error toast on batch action failures instead of reloading page ([#&#8203;38593](https://github.com/go-gitea/gitea/pull/38593))
      - Fix(deps): update module google.golang.org/grpc to v1.82.1 \[security] ([#&#8203;38567](https://github.com/go-gitea/gitea/pull/38567))
      - Fix(deps): update module github.com/google/go-github/v88 to v89 ([#&#8203;38433](https://github.com/go-gitea/gitea/pull/38433))
      - Fix(deps): update go dependencies ([#&#8203;38429](https://github.com/go-gitea/gitea/pull/38429))
      - Fix(deps): update go dependencies ([#&#8203;38346](https://github.com/go-gitea/gitea/pull/38346))
      - Fix(deps): update npm dependencies ([#&#8203;38342](https://github.com/go-gitea/gitea/pull/38342))
      - Fix(base): correct natural sort of numbers with leading zeros ([#&#8203;38163](https://github.com/go-gitea/gitea/pull/38163))
      - Fix(ui): avoid layout shifts in `overflow-menu` and repo filter ([#&#8203;37818](https://github.com/go-gitea/gitea/pull/37818))
      - Fix: make auth source group sync correctly handle team removal ([#&#8203;37161](https://github.com/go-gitea/gitea/pull/37161))
      - Fix(release): separate publication time from the release date ([#&#8203;36761](https://github.com/go-gitea/gitea/pull/36761))

    - TESTING
      - Test: stop tests from writing into `~/.ssh` ([#&#8203;39348](https://github.com/go-gitea/gitea/pull/39348))
      - Test(e2e): log out to switch users in pr-review test ([#&#8203;39328](https://github.com/go-gitea/gitea/pull/39328))
      - Test: release fixtures loader lock before database work ([#&#8203;39263](https://github.com/go-gitea/gitea/pull/39263))
      - Test: speed up tests, fix transaction bug ([#&#8203;39030](https://github.com/go-gitea/gitea/pull/39030))
      - Test: run frontend unit tests in browsers ([#&#8203;38860](https://github.com/go-gitea/gitea/pull/38860))
      - Test(pubsub): stop racing the Redis SUBSCRIBE ack ([#&#8203;38661](https://github.com/go-gitea/gitea/pull/38661))
      - Test(e2e): add pull request merge box test, update AGENTS.md ([#&#8203;38576](https://github.com/go-gitea/gitea/pull/38576))
      - Test(e2e): deterministically wait for event stream in logout propagation test ([#&#8203;38535](https://github.com/go-gitea/gitea/pull/38535))

    - BUILD
      - Refactor: fix `go vet` errors related to composite literals ([#&#8203;39341](https://github.com/go-gitea/gitea/pull/39341))
      - Build(gogit): disable gogit builds for stable releases ([#&#8203;39324](https://github.com/go-gitea/gitea/pull/39324))
      - Refactor: replace jquery.are-you-sure with first-party code ([#&#8203;39233](https://github.com/go-gitea/gitea/pull/39233))
      - Refactor: http request binding ([#&#8203;38971](https://github.com/go-gitea/gitea/pull/38971))
      - Refactor: clean up git repo and model migration packages ([#&#8203;38564](https://github.com/go-gitea/gitea/pull/38564))
      - Refactor: prepare to decouple the "model migration" package and "models" package ([#&#8203;38533](https://github.com/go-gitea/gitea/pull/38533))
      - Build: fix snapcraft release ([#&#8203;38260](https://github.com/go-gitea/gitea/pull/38260))
      - Build(release): use native golang toolchain for official release builds ([#&#8203;37828](https://github.com/go-gitea/gitea/pull/37828))

    - DOCS
      - Docs(webhook): review\.type comment lists values the webhook never sends ([#&#8203;39451](https://github.com/go-gitea/gitea/pull/39451))
      - Docs(api): document verification and files on the compare endpoint ([#&#8203;39440](https://github.com/go-gitea/gitea/pull/39440))
      - Docs(api): name the unadopted-repository search parameter query ([#&#8203;39370](https://github.com/go-gitea/gitea/pull/39370))
      - Docs: remove unused COOKIE\_USERNAME from app.example.ini ([#&#8203;39365](https://github.com/go-gitea/gitea/pull/39365))
      - Docs: document NOTICE\_ON\_SUCCESS for every cron task ([#&#8203;39352](https://github.com/go-gitea/gitea/pull/39352))
      - Docs: correct ALLOW\_LOCALNETWORKS description in app.example.ini ([#&#8203;39240](https://github.com/go-gitea/gitea/pull/39240))
      - Docs: fix typo in README about app.ini restart ([#&#8203;39223](https://github.com/go-gitea/gitea/pull/39223))
      - Docs: fix dead localization doc link in the READMEs ([#&#8203;39211](https://github.com/go-gitea/gitea/pull/39211))
      - Docs: Update CHANGELOG for release 1.27.3 ([#&#8203;39170](https://github.com/go-gitea/gitea/pull/39170))
      - Docs: Update CHANGELOG for version 1.27.2 ([#&#8203;38923](https://github.com/go-gitea/gitea/pull/38923))
      - Docs: Update PGP key expiration date to July 23, 2027 ([#&#8203;38747](https://github.com/go-gitea/gitea/pull/38747))
      - Docs(api): document 401/403 responses for user key endpoints ([#&#8203;38711](https://github.com/go-gitea/gitea/pull/38711))
      - Docs: Update Changelog for release v1.27.1 ([#&#8203;38670](https://github.com/go-gitea/gitea/pull/38670))
      - Docs: Update Changelog for 1.27 ([#&#8203;38440](https://github.com/go-gitea/gitea/pull/38440))
      - Docs: Update Security docs ([#&#8203;38422](https://github.com/go-gitea/gitea/pull/38422))

    - MISC
      - Refactor: make git http respond error message ([#&#8203;39390](https://github.com/go-gitea/gitea/pull/39390))
      - Refactor(api): convert bot accounts through the admin user edit endpoint ([#&#8203;39355](https://github.com/go-gitea/gitea/pull/39355))
      - Refactor: replace AWS SDK with a REST client for CodeCommit migration ([#&#8203;39330](https://github.com/go-gitea/gitea/pull/39330))
      - Refactor: replace Azure Blob SDK with a REST client ([#&#8203;39315](https://github.com/go-gitea/gitea/pull/39315))
      - Refactor: npm route handlers ([#&#8203;39275](https://github.com/go-gitea/gitea/pull/39275))
      - Refactor: GetDiffShortStat and fix panic caused by inconsistent "changed file number" ([#&#8203;39248](https://github.com/go-gitea/gitea/pull/39248))
      - Refactor(templates): update djlint to 1.46.0 and resolve its new findings ([#&#8203;39231](https://github.com/go-gitea/gitea/pull/39231))
      - Refactor: pagination/pager ([#&#8203;39162](https://github.com/go-gitea/gitea/pull/39162))
      - Refactor: share package registry error status classification ([#&#8203;39133](https://github.com/go-gitea/gitea/pull/39133))
      - Refactor: drop two unmaintained dependencies, rename the byte size helpers ([#&#8203;39083](https://github.com/go-gitea/gitea/pull/39083))
      - Refactor(automerge): fix error handling, populate recent automerge tasks on restart ([#&#8203;39001](https://github.com/go-gitea/gitea/pull/39001))
      - Refactor: deploy key and private route handlers ([#&#8203;38999](https://github.com/go-gitea/gitea/pull/38999))
      - Refactor: wiki edit form ([#&#8203;38918](https://github.com/go-gitea/gitea/pull/38918))
      - Refactor: clean up form binding & validation ([#&#8203;38873](https://github.com/go-gitea/gitea/pull/38873))
      - Refactor: markup render ([#&#8203;38864](https://github.com/go-gitea/gitea/pull/38864))
      - Refactor: api token scope check ([#&#8203;38862](https://github.com/go-gitea/gitea/pull/38862))
      - Refactor: replace `gliderlabs/ssh` with `golang.org/x/crypto/ssh` ([#&#8203;38837](https://github.com/go-gitea/gitea/pull/38837))
      - Refactor: form binding validation ([#&#8203;38832](https://github.com/go-gitea/gitea/pull/38832))
      - Refactor: prepare vue components for vapor mode ([#&#8203;38798](https://github.com/go-gitea/gitea/pull/38798))
      - Refactor: use the shared workflow model from actionslib ([#&#8203;38768](https://github.com/go-gitea/gitea/pull/38768))
      - Refactor(modelmigration): thread context through migration functions ([#&#8203;38758](https://github.com/go-gitea/gitea/pull/38758))
      - Refactor: migrate remaining Vue components to `<script setup>` ([#&#8203;38752](https://github.com/go-gitea/gitea/pull/38752))
      - Refactor: introduce trString for frontend ([#&#8203;38741](https://github.com/go-gitea/gitea/pull/38741))
      - Refactor(diff): drive diff DOM init from the global selector observer ([#&#8203;38740](https://github.com/go-gitea/gitea/pull/38740))
      - Refactor(git): clarify GetBranch behavior to make it only gets an existing branch ([#&#8203;38662](https://github.com/go-gitea/gitea/pull/38662))
      - Refactor: replace debounce/throttle deps with first-party code ([#&#8203;38610](https://github.com/go-gitea/gitea/pull/38610))
      - Refactor: hide git repo path details from more packages ([#&#8203;38601](https://github.com/go-gitea/gitea/pull/38601))
      - Refactor: retry file remove/rename when a file is busy and clean up os detection ([#&#8203;38588](https://github.com/go-gitea/gitea/pull/38588))
      - Perf(emoji): optimize FindEmojiSubmatchIndex using slice-based Trie ([#&#8203;38573](https://github.com/go-gitea/gitea/pull/38573))
      - Refactor: implement mcaptcha client and add comments/tests ([#&#8203;38561](https://github.com/go-gitea/gitea/pull/38561))
      - Refactor: use WithRepo instead of WithDir for most git operations, clean up model migrations ([#&#8203;38555](https://github.com/go-gitea/gitea/pull/38555))
      - Refactor: remove Path field from git.Repository ([#&#8203;38552](https://github.com/go-gitea/gitea/pull/38552))
      - Refactor: make git package handle all git operations ([#&#8203;38543](https://github.com/go-gitea/gitea/pull/38543))
      - Refactor: remove unnecessary git command wrapper functions ([#&#8203;38531](https://github.com/go-gitea/gitea/pull/38531))
      - Refactor: git repo and relative path handling ([#&#8203;38522](https://github.com/go-gitea/gitea/pull/38522))
      - Refactor: clean up fragile diff render templates, use backend typed structs ([#&#8203;38517](https://github.com/go-gitea/gitea/pull/38517))
      - Refactor: correct git repo design and fix some legacy problems ([#&#8203;38512](https://github.com/go-gitea/gitea/pull/38512))
      - Refactor: fix legacy problems in cmd/serv.go ([#&#8203;38505](https://github.com/go-gitea/gitea/pull/38505))
      - Refactor: remove Ctx field from git.Repository ([#&#8203;38500](https://github.com/go-gitea/gitea/pull/38500))
      - Refactor: decouple git.Repository(ctx) from git.Commit & git.Tree ([#&#8203;38464](https://github.com/go-gitea/gitea/pull/38464))
      - Refactor: introduce ActivePageTimer to help to do partial page refresh ([#&#8203;38372](https://github.com/go-gitea/gitea/pull/38372))

    </details>

    ---

    ### Configuration

    📅 **Schedule**: (in timezone Europe/Oslo)

    - Branch creation
      - At any time (no schedule defined)
    - Automerge
      - At any time (no schedule defined)

    🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

    ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

    🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

    ---

     - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

    ---

    This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
    <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

    ---------

    Co-authored-by: Renovate Bot <renovate@forteapps.net>
    Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/58
    Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
    Co-authored-by: gitea_admin <admin@forteapps.net>

commit 840c354ea3
Author: gitea_admin <admin@forteapps.net>
Date:   Sat Oct 3 18:55:31 2026 +0000

    chore(deps): update terraform azurerm to v5 (#55)

    This PR contains the following updates:

    | Package | Type | Update | Change | Pending |
    |---|---|---|---|---|
    | [azurerm](https://registry.terraform.io/providers/hashicorp/azurerm) ([source](https://github.com/hashicorp/terraform-provider-azurerm)) | required_provider | major | `~> 4.0` → `~> 5.0` | `5.8.0` |

    ---

    ### Release Notes

    <details>
    <summary>hashicorp/terraform-provider-azurerm (azurerm)</summary>

    ### [`v5.7.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#570-September-24-2026)

    [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.6.0...v5.7.0)

    FEATURES:

    - **New List Resource**: `azurerm_private_dns_resolver_forwarding_rule` ([#&#8203;33313](https://github.com/hashicorp/terraform-provider-azurerm/issues/33313))
    - **New List Resource**: `azurerm_windows_virtual_machine` ([#&#8203;33332](https://github.com/hashicorp/terraform-provider-azurerm/issues/33332))

    ENHANCEMENTS:

    - dependencies: `go-azure-sdk` - update to `v0.20260917.1142820` ([#&#8203;33495](https://github.com/hashicorp/terraform-provider-azurerm/issues/33495))
    - dependencies: `network` - update API version to `2025-07-01` ([#&#8203;33441](https://github.com/hashicorp/terraform-provider-azurerm/issues/33441))
    - Data Source: `azurerm_linux_web_app` - export the `virtual_network_image_pull_enabled` property ([#&#8203;33316](https://github.com/hashicorp/terraform-provider-azurerm/issues/33316))
    - Data Source: `azurerm_network_interface` - export the `auxiliary_mode`, `auxiliary_sku`, `edge_zone`, and `internal_domain_name_suffix` properties ([#&#8203;33204](https://github.com/hashicorp/terraform-provider-azurerm/issues/33204))
    - Data Source: `azurerm_public_ip` - export the `domain_name_label_scope`, `edge_zone`, `public_ip_prefix_id`, and `sku_tier` properties ([#&#8203;33193](https://github.com/hashicorp/terraform-provider-azurerm/issues/33193))
    - Data Source: `azurerm_service_plan` - export the `premium_plan_auto_scale_enabled` property ([#&#8203;33300](https://github.com/hashicorp/terraform-provider-azurerm/issues/33300))
    - Data Source: `azurerm_storage_blob` - export the `cache_control` and `source_uri` properties ([#&#8203;33318](https://github.com/hashicorp/terraform-provider-azurerm/issues/33318))
    - Data Source: `azurerm_traffic_manager_profile` - export the `maximum_return` property ([#&#8203;33346](https://github.com/hashicorp/terraform-provider-azurerm/issues/33346))
    - Data Source: `azurerm_web_pubsub` - export the `live_trace` and `identity` properties ([#&#8203;33373](https://github.com/hashicorp/terraform-provider-azurerm/issues/33373))
    - `azurerm_kubernetes_cluster_node_pool` - add `Windows2025` as a valid value for the `os_sku` property ([#&#8203;33463](https://github.com/hashicorp/terraform-provider-azurerm/issues/33463))
    - `azurerm_kubernetes_cluster` - add `Windows2025` as a valid value for the `os_sku` property ([#&#8203;33463](https://github.com/hashicorp/terraform-provider-azurerm/issues/33463))

    BUG FIXES:

    - Data Source: `azurerm_kubernetes_cluster` - fix a panic caused by a nil pointer dereference while flattening `agent_pool_profile` ([#&#8203;33488](https://github.com/hashicorp/terraform-provider-azurerm/issues/33488))
    - `azurerm_postgresql_flexible_server` - fix `cluster` block read for replica `create_mode` ([#&#8203;33082](https://github.com/hashicorp/terraform-provider-azurerm/issues/33082))

    ### [`v5.6.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#560-September-17-2026)

    [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.5.0...v5.6.0)

    FEATURES:

    - **New List Resource**: `azurerm_batch_account` ([#&#8203;33252](https://github.com/hashicorp/terraform-provider-azurerm/issues/33252))
    - **New List Resource**: `azurerm_cdn_frontdoor_origin_group` ([#&#8203;33334](https://github.com/hashicorp/terraform-provider-azurerm/issues/33334))
    - **New Resource**: `azurerm_storage_discovery_workspace` ([#&#8203;31479](https://github.com/hashicorp/terraform-provider-azurerm/issues/31479))

    ENHANCEMENTS:

    - dependencies: `containers` - update API version to `2026-05-01` ([#&#8203;32688](https://github.com/hashicorp/terraform-provider-azurerm/issues/32688))
    - dependencies: `go-azure-sdk` - update to `v0.20260910.1141000` ([#&#8203;33413](https://github.com/hashicorp/terraform-provider-azurerm/issues/33413))
    - dependencies: `qumulo` - update API version to `2026-04-16` ([#&#8203;33421](https://github.com/hashicorp/terraform-provider-azurerm/issues/33421))
    - dependencies: `servicebus` - update to API version `2026-01-01` ([#&#8203;33450](https://github.com/hashicorp/terraform-provider-azurerm/issues/33450))
    - `azurerm_iothub_device_update_instance` - add support for the `connection_string_wo` and `connection_string_wo_version` properties ([#&#8203;33448](https://github.com/hashicorp/terraform-provider-azurerm/issues/33448))
    - `azurerm_linux_function_app` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))
    - `azurerm_linux_function_app_slot` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))
    - `azurerm_linux_web_app` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))
    - `azurerm_linux_web_app_slot` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))
    - `azurerm_mongo_cluster` - Support new property `network_bypass_mode` ([#&#8203;33168](https://github.com/hashicorp/terraform-provider-azurerm/issues/33168))
    - `azurerm_servicebus_namespace` - add support for the `1.3` value to the `minimum_tls_version` property ([#&#8203;33457](https://github.com/hashicorp/terraform-provider-azurerm/issues/33457))
    - `azurerm_windows_function_app` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))
    - `azurerm_windows_function_app_slot` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))
    - `azurerm_windows_web_app` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))
    - `azurerm_windows_web_app_slot` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))

    BUG FIXES:

    - `azurerm_site_recovery_replicated_vm` - select `managed_disk` properties compared case insensitive ([#&#8203;33424](https://github.com/hashicorp/terraform-provider-azurerm/issues/33424))

    ### [`v5.5.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#550-September-10-2026)

    [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.4.0...v5.5.0)

    FEATURES:

    - **New List Resource**: `azurerm_analysis_services_server` ([#&#8203;33250](https://github.com/hashicorp/terraform-provider-azurerm/issues/33250))
    - **New List Resource**: `azurerm_application_insights_workbook` ([#&#8203;33244](https://github.com/hashicorp/terraform-provider-azurerm/issues/33244))
    - **New List Resource**: `azurerm_attestation_provider` ([#&#8203;33251](https://github.com/hashicorp/terraform-provider-azurerm/issues/33251))
    - **New List Resource**: `azurerm_cdn_frontdoor_origin` ([#&#8203;33307](https://github.com/hashicorp/terraform-provider-azurerm/issues/33307))
    - **New List Resource**: `azurerm_eventhub_consumer_group` ([#&#8203;33335](https://github.com/hashicorp/terraform-provider-azurerm/issues/33335))
    - **New List Resource**: `azurerm_linux_virtual_machine` ([#&#8203;33333](https://github.com/hashicorp/terraform-provider-azurerm/issues/33333))
    - **New List Resource**: `azurerm_virtual_hub_connection` ([#&#8203;33311](https://github.com/hashicorp/terraform-provider-azurerm/issues/33311))

    ENHANCEMENTS:

    - dependencies: `go-azure-sdk` - update to `v0.20260901.1173158` ([#&#8203;33274](https://github.com/hashicorp/terraform-provider-azurerm/issues/33274))
    - `azurerm_private_endpoint` - lock on private service connection resource ids ([#&#8203;33298](https://github.com/hashicorp/terraform-provider-azurerm/issues/33298))
    - `azurerm_storage_account` - add support for the `public_network_access` property ([#&#8203;33292](https://github.com/hashicorp/terraform-provider-azurerm/issues/33292))

    BUG FIXES:

    - `azurerm_resource_group` - the `managed_by` property now forces recreation when changed as the API does not support changing this value ([#&#8203;33339](https://github.com/hashicorp/terraform-provider-azurerm/issues/33339))
    - `go-azure-sdk` - `Delete` operations now poll on asynchronous operation URLs if returned by the API instead of only checking for a `404` on the resource URL, ensuring deletion errors are reported to the user ([#&#8203;33274](https://github.com/hashicorp/terraform-provider-azurerm/issues/33274))

    ### [`v5.4.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#540-September-03-2026)

    [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.3.0...v5.4.0)

    FEATURES:

    - **New List Resource**: `azurerm_application_insights_standard_web_test` ([#&#8203;33243](https://github.com/hashicorp/terraform-provider-azurerm/issues/33243))
    - **New List Resource**: `azurerm_application_insights_workbook_template` ([#&#8203;33245](https://github.com/hashicorp/terraform-provider-azurerm/issues/33245))
    - **New List Resource**: `azurerm_arc_kubernetes_provisioned_cluster` ([#&#8203;33247](https://github.com/hashicorp/terraform-provider-azurerm/issues/33247))
    - **New List Resource**: `azurerm_availability_set` ([#&#8203;33241](https://github.com/hashicorp/terraform-provider-azurerm/issues/33241))
    - **New List Resource**: `azurerm_batch_application` ([#&#8203;33254](https://github.com/hashicorp/terraform-provider-azurerm/issues/33254))
    - **New List Resource**: `azurerm_dedicated_host_group` ([#&#8203;33257](https://github.com/hashicorp/terraform-provider-azurerm/issues/33257))
    - **New List Resource**: `azurerm_log_analytics_workspace` ([#&#8203;33259](https://github.com/hashicorp/terraform-provider-azurerm/issues/33259))

    ENHANCEMENTS:

    - dependencies: `azurerm_mongo_cluster` - update API version to `2026-06-01` ([#&#8203;33195](https://github.com/hashicorp/terraform-provider-azurerm/issues/33195))
    - dependencies: `azurerm_mongo_cluster_firewall_rule` - update API version to `2026-06-01` ([#&#8203;33195](https://github.com/hashicorp/terraform-provider-azurerm/issues/33195))
    - dependencies: `azurerm_mongo_cluster_user` - update API version to `2026-06-01` ([#&#8203;33195](https://github.com/hashicorp/terraform-provider-azurerm/issues/33195))
    - dependencies: `netapp` - update API version to `2026-05-01` ([#&#8203;33215](https://github.com/hashicorp/terraform-provider-azurerm/issues/33215))
    - Data Source: `azurerm_api_management_workspace` - export the `description` property ([#&#8203;33205](https://github.com/hashicorp/terraform-provider-azurerm/issues/33205))
    - Data Source: `azurerm_attestation_provider` - export the `sev_snp_policy_base64`, `open_enclave_policy_base64`, `sgx_enclave_policy_base64`, and `tpm_policy_base64` properties ([#&#8203;33125](https://github.com/hashicorp/terraform-provider-azurerm/issues/33125))
    - Data Source: `azurerm_automation_account` - export the `dsc_primary_access_key`, `dsc_server_endpoint`, `dsc_secondary_access_key`, `public_network_access_enabled`, `sku_name`, and `tags` properties ([#&#8203;33135](https://github.com/hashicorp/terraform-provider-azurerm/issues/33135))
    - Data Source: `azurerm_automation_account` - export the `encryption` block ([#&#8203;33135](https://github.com/hashicorp/terraform-provider-azurerm/issues/33135))
    - Data Source: `azurerm_ip_group` - export the `firewall_ids` and `firewall_policy_ids` properties ([#&#8203;33190](https://github.com/hashicorp/terraform-provider-azurerm/issues/33190))
    - Data Source: `azurerm_private_link_service` - export the `fqdns` and `destination_ip_address` properties ([#&#8203;33191](https://github.com/hashicorp/terraform-provider-azurerm/issues/33191))
    - `azurerm_key_vault_managed_hardware_security_module_key` - allow the `key_size` property to be set when `key_type` is `oct-HSM` ([#&#8203;32690](https://github.com/hashicorp/terraform-provider-azurerm/issues/32690))
    - `azurerm_lb_probe ` - add support for the `no_healthy_backends_behavior` property ([#&#8203;32645](https://github.com/hashicorp/terraform-provider-azurerm/issues/32645))
    - `azurerm_linux_virtual_machine_scale_set` - add support for the `NvmeDisk` value to the `os_disk.diff_disk_settings.placement` property ([#&#8203;30328](https://github.com/hashicorp/terraform-provider-azurerm/issues/30328))
    - `azurerm_linux_web_app` - add support for the `8.5` value in the  `site_config.application_stack.php_version` property ([#&#8203;33308](https://github.com/hashicorp/terraform-provider-azurerm/issues/33308))
    - `azurerm_linux_web_app_slot` - add support for the `8.5` value in the  `site_config.application_stack.php_version` property ([#&#8203;33308](https://github.com/hashicorp/terraform-provider-azurerm/issues/33308))
    - `azurerm_netapp_volume` - support for the `breakthrough_mode_enabled` property ([#&#8203;33215](https://github.com/hashicorp/terraform-provider-azurerm/issues/33215))
    - `azurerm_postgresql_flexible_server` - add support for the `storage_type`, `storage_iops`, and `storage_throughput` properties which allows choice of the new "Premium V2 LRS" storage type ([#&#8203;32121](https://github.com/hashicorp/terraform-provider-azurerm/issues/32121))
    - `azurerm_storage_account` - add support for an in-place migration of `account_replication_type` between matching non-zonal and zonal types instead of resource recreation ([#&#8203;33236](https://github.com/hashicorp/terraform-provider-azurerm/issues/33236))
    - `azurerm_storage_table` - add support for AAD authentication ([#&#8203;32997](https://github.com/hashicorp/terraform-provider-azurerm/issues/32997))
    - `azurerm_synapse_spark_pool` - migrate to `go-azure-sdk` ([#&#8203;33258](https://github.com/hashicorp/terraform-provider-azurerm/issues/33258))
    - `azurerm_windows_virtual_machine_scale_set` - add support for the `NvmeDisk` value to the `os_disk.diff_disk_settings.placement` property ([#&#8203;30328](https://github.com/hashicorp/terraform-provider-azurerm/issues/30328))

    BUG FIXES:

    - `azurerm_synapse_spark_pool` - fix `lifecycle.ignore_changes` support ([#&#8203;33258](https://github.com/hashicorp/terraform-provider-azurerm/issues/33258))

    ### [`v5.3.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#530-August-27-2026)

    [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.2.0...v5.3.0)

    FEATURES:

    - **New Data Source**: `azurerm_playwright_workspace` ([#&#8203;31954](https://github.com/hashicorp/terraform-provider-azurerm/issues/31954))
    - **New List Resource**: `azurerm_cognitive_deployment` ([#&#8203;33149](https://github.com/hashicorp/terraform-provider-azurerm/issues/33149))
    - **New List Resource**: `azurerm_playwright_workspace` ([#&#8203;31954](https://github.com/hashicorp/terraform-provider-azurerm/issues/31954))
    - **New Resource**: `azurerm_playwright_workspace` ([#&#8203;31954](https://github.com/hashicorp/terraform-provider-azurerm/issues/31954))

    ENHANCEMENTS:

    - dependencies: `go-azure-helpers` - update version to `0.82.0` ([#&#8203;33142](https://github.com/hashicorp/terraform-provider-azurerm/issues/33142))
    - dependencies: `sql` - update API version to `2025-01-01` ([#&#8203;33201](https://github.com/hashicorp/terraform-provider-azurerm/issues/33201))
    - Data Source: `azurerm_role_definition` - export the `role_definition_resource_id` property ([#&#8203;33126](https://github.com/hashicorp/terraform-provider-azurerm/issues/33126))
    - `azurerm_cognitive_deployment` - add Resource Identity support ([#&#8203;33149](https://github.com/hashicorp/terraform-provider-azurerm/issues/33149))
    - `azurerm_federated_identity_credential` - add additional polling to account for Azure's eventual consistency ([#&#8203;32935](https://github.com/hashicorp/terraform-provider-azurerm/issues/32935))
    - `azurerm_kubernetes_cluster` - add support for the `oms_agent.retina_flow_logs_enabled` property ([#&#8203;33222](https://github.com/hashicorp/terraform-provider-azurerm/issues/33222))
    - `azurerm_managed_application` - add support for the `identity` block ([#&#8203;30725](https://github.com/hashicorp/terraform-provider-azurerm/issues/30725))
    - `azurerm_private_endpoint` - extend validation for the `private_service_connection.subresource_names` property to allow names containing spaces ([#&#8203;32887](https://github.com/hashicorp/terraform-provider-azurerm/issues/32887))
    - `azurerm_search_service` - allow in-place downgrades of the `sku` property between Basic and Standard tiers ([#&#8203;33069](https://github.com/hashicorp/terraform-provider-azurerm/issues/33069))
    - `azurerm_site_recovery_replicated_vm` - add update support to the `managed_disk` block without requiring resource recreation ([#&#8203;33140](https://github.com/hashicorp/terraform-provider-azurerm/issues/33140))
    - `azurerm_user_assigned_identity` - add additional polling to account for Azure's eventual consistency ([#&#8203;33142](https://github.com/hashicorp/terraform-provider-azurerm/issues/33142))

    BUG FIXES:

    - Data Source: `azurerm_app_configuration_key` - now correctly sets `tags` into state ([#&#8203;33182](https://github.com/hashicorp/terraform-provider-azurerm/issues/33182))
    - `azurerm_eventhub_namespace` - prevent `network_rulesets.x.default_action` being set to `Deny` if `ip_rule` or `virtual_network_rule` is not specified ([#&#8203;33216](https://github.com/hashicorp/terraform-provider-azurerm/issues/33216))

    ### [`v5.2.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#520-August-20-2026)

    [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.1.0...v5.2.0)

    FEATURES:

    - **New List Resource**: `azurerm_user_assigned_identity` ([#&#8203;32667](https://github.com/hashicorp/terraform-provider-azurerm/issues/32667))

    ENHANCEMENTS:

    - dependencies: `go` - update to `1.26.6` ([#&#8203;33141](https://github.com/hashicorp/terraform-provider-azurerm/issues/33141))
    - dependencies: `go-azure-sdk` - update to `v0.20260811.1225050` ([#&#8203;33079](https://github.com/hashicorp/terraform-provider-azurerm/issues/33079))
    - `azurerm_cdn_frontdoor_batch_rule_set` - allow `/` as an input to `rule.conditions.request_path.values` ([#&#8203;33023](https://github.com/hashicorp/terraform-provider-azurerm/issues/33023))
    - `azurerm_databricks_workspace` - remove a redundant key vault existence check ([#&#8203;33136](https://github.com/hashicorp/terraform-provider-azurerm/issues/33136))
    - `azurerm_databricks_workspace_root_dbfs_customer_managed_key` - remove a redundant key vault existence check ([#&#8203;33136](https://github.com/hashicorp/terraform-provider-azurerm/issues/33136))
    - `azurerm_logic_app_standard` - add support for `v10.0` to `site_config.dotnet_framework_version` ([#&#8203;33116](https://github.com/hashicorp/terraform-provider-azurerm/issues/33116))
    - `azurerm_mongo_cluster` - `administrator_password` is no longer required when `create_mode` is `Default` to support Entra ID-only authentication ([#&#8203;32092](https://github.com/hashicorp/terraform-provider-azurerm/issues/32092))
    - `azurerm_redhat_openshift_cluster` - add support for the `network_profile.load_balancer_profile` block ([#&#8203;32473](https://github.com/hashicorp/terraform-provider-azurerm/issues/32473))
    - `azurerm_redhat_openshift_cluster` - add support for the `platform_workload_identity_profile` block ([#&#8203;32473](https://github.com/hashicorp/terraform-provider-azurerm/issues/32473))
    - `azurerm_role_assignment` - the `condition`, `condition_version`, and `description` properties can now be updated in-place ([#&#8203;32714](https://github.com/hashicorp/terraform-provider-azurerm/issues/32714))
    - `azurerm_snapshot` - `create_option` now supports `CopyStart` ([#&#8203;32834](https://github.com/hashicorp/terraform-provider-azurerm/issues/32834))

    BUG FIXES:

    - `azurerm_cognitive_account_project` - added create/update/delete lock on parent AccountID to make sure operations on parent account are processed in serial (required by Cognitive service) ([#&#8203;33151](https://github.com/hashicorp/terraform-provider-azurerm/issues/33151))
    - `azurerm_databricks_workspace` - fix a persistent diff on removal of `managed_disk_cmk_key_vault_key_id` or `managed_services_cmk_key_vault_key_id` ([#&#8203;33136](https://github.com/hashicorp/terraform-provider-azurerm/issues/33136))
    - `azurerm_oracle_exadata_infrastructure` - fix an issue that prevented users from deploying with no `zones` set ([#&#8203;33011](https://github.com/hashicorp/terraform-provider-azurerm/issues/33011))

    ### [`v5.1.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#510-August-13-2026)

    [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.0.1...v5.1.0)

    ENHANCEMENTS:

    - dependencies: `azurerm_linux_virtual_machine_scale_set` - update to API version `2025-04-01` ([#&#8203;31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586))
    - dependencies: `azurerm_orchestrated_virtual_machine_scale_set` - update to API version `2025-04-01` ([#&#8203;31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586))
    - dependencies: `azurerm_virtual_machine_scale_set` - update to API version `2025-04-01` ([#&#8203;31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586))
    - dependencies: `azurerm_virtual_machine_scale_set_extension` - update to API version `2025-04-01` ([#&#8203;31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586))
    - dependencies: `azurerm_windows_virtual_machine_scale_set` - update to API version `2025-04-01` ([#&#8203;31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586))
    - dependencies: `codesigning` - update to API version `2025-10-13` ([#&#8203;31714](https://github.com/hashicorp/terraform-provider-azurerm/issues/31714))
    - `azurerm_linux_virtual_machine` - `encryption_at_host_enabled` can now be set to `true` when `os_disk.security_encryption_type` is set to `DiskWithVMGuestState` ([#&#8203;32885](https://github.com/hashicorp/terraform-provider-azurerm/issues/32885))
    - `azurerm_linux_virtual_machine_scale_set` - `encryption_at_host_enabled` can now be set to `true` when `os_disk.security_encryption_type` is set to `DiskWithVMGuestState` ([#&#8203;32885](https://github.com/hashicorp/terraform-provider-azurerm/issues/32885))
    - `azurerm_managed_devops_pool` - add support for the `CreatorOnly` value to `azure_devops_organization.permission.kind` property ([#&#8203;32753](https://github.com/hashicorp/terraform-provider-azurerm/issues/32753))
    - `azurerm_windows_virtual_machine` - `encryption_at_host_enabled` can now be set to `true` when `os_disk.security_encryption_type` is set to `DiskWithVMGuestState` ([#&#8203;32885](https://github.com/hashicorp/terraform-provider-azurerm/issues/32885))
    - `azurerm_windows_virtual_machine_scale_set` - `encryption_at_host_enabled` can now be set to `true` when `os_disk.security_encryption_type` is set to `DiskWithVMGuestState` ([#&#8203;32885](https://github.com/hashicorp/terraform-provider-azurerm/issues/32885))

    BUG FIXES:

    - `azurerm_cdn_frontdoor_batch_ruleset` - parse `rule.actions.route_configuration_override.origin_group.cdn_frontdoor_origin_group_id` case-insensitively and normalize the resulting value to prevent diffs ([#&#8203;32980](https://github.com/hashicorp/terraform-provider-azurerm/issues/32980))
    - `azurerm_cdn_frontdoor_route` - parse `cdn_frontdoor_origin_group_id` case-insensitively and normalize the resulting value to prevent diffs ([#&#8203;32980](https://github.com/hashicorp/terraform-provider-azurerm/issues/32980))
    - `azurerm_cdn_frontdoor_secret` - fix an incorrect type assertion ([#&#8203;32982](https://github.com/hashicorp/terraform-provider-azurerm/issues/32982))
    - `azurerm_dev_center_project` - parse `dev_center_id` case-insensitively and normalize the resulting value to prevent diffs ([#&#8203;32798](https://github.com/hashicorp/terraform-provider-azurerm/issues/32798))
    - `azurerm_eventhub` - now prevents the `status` property from being set to `SendDisabled` on create  ([#&#8203;33071](https://github.com/hashicorp/terraform-provider-azurerm/issues/33071))
    - `azurerm_storage_container` - add a state migration for the `id` field, fixing the upgrade path from 4.x to 5.x ([#&#8203;32978](https://github.com/hashicorp/terraform-provider-azurerm/issues/32978))
    - `azurerm_storage_queue` - extend state migration to handle a malformed `resource_manager_id` ([#&#8203;32979](https://github.com/hashicorp/terraform-provider-azurerm/issues/32979))
    - `azurerm_storage_share` - add a state migration for the `id` field, fixing the upgrade path from 4.x to 5.x ([#&#8203;33075](https://github.com/hashicorp/terraform-provider-azurerm/issues/33075))

    ### [`v5.0.1`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#501-July-30-2026)

    [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.0.0...v5.0.1)

    NOTES:

    In addition to the bug fixes below, a number of resource documentation pages and the 5.0-upgrade-guide have been updated.

    BUG FIXES:

    - `azurerm_cdn_frontdoor_origin` - fix a regression that prevented valid values as input to `private_link.private_link_target_id` ([#&#8203;32912](https://github.com/hashicorp/terraform-provider-azurerm/issues/32912))
    - `azurerm_storage_queue` - add a state migration for the `id` field, fixing the upgrade path from 4.x to 5.x ([#&#8203;32914](https://github.com/hashicorp/terraform-provider-azurerm/issues/32914))
    - `azurerm_storage_table_entity` - add a state migration for the `storage_table_id` field, fixing the upgrade path from 4.x to 5.x ([#&#8203;32929](https://github.com/hashicorp/terraform-provider-azurerm/issues/32929))

    ### [`v5.0.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#500-July-27-2026)

    [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v4.81.0...v5.0.0)

    NOTES:

    - **Major Version**: Version 5.0 of the Azure Provider is a major version - some behaviours have changed and some deprecated fields/resources have been removed - please refer to [the 5.0 upgrade guide for more information](https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/guides/5.0-upgrade-guide).
    - When upgrading to v5.0 of the AzureRM Provider, we recommend upgrading to the latest version of Terraform Core ([which can be found here](https://developer.hashicorp.com/terraform/install)).

    FEATURES:

    - **New Action**: `azurerm_web_app_set_slot_distribution` ([#&#8203;32364](https://github.com/hashicorp/terraform-provider-azurerm/issues/32364))
    - **New Datasource** adds `azurerm_kubernetes_automatic_cluster_datasource` ([#&#8203;32881](https://github.com/hashicorp/terraform-provider-azurerm/issues/32881))

    ENHANCEMENTS:

    - dependencies: `grpc` update to `1.82.1` ([#&#8203;32852](https://github.com/hashicorp/terraform-provider-azurerm/issues/32852))
    - dependencies: `loadbalancers` - update to API version `2025-01-01` ([#&#8203;32644](https://github.com/hashicorp/terraform-provider-azurerm/issues/32644))
    - `azurerm_cognitive_account_rai_policy` - the `content_filter.severity_threshold` property is now optional ([#&#8203;32100](https://github.com/hashicorp/terraform-provider-azurerm/issues/32100))
    - `azurerm_container_registry` - the `trust_policy_enabled` property has been deprecated and removed from the provider ([#&#8203;32752](https://github.com/hashicorp/terraform-provider-azurerm/issues/32752))
    - `azurerm_dashboard_grafana` - the `11` value for the `grafana_major_version` property has been deprecated and the property now supports `13` ([#&#8203;32777](https://github.com/hashicorp/terraform-provider-azurerm/issues/32777))
    - `azurerm_log_analytics_workspace` - add support for the `internet_ingestion_access_type` and `internet_query_access_type` properties ([#&#8203;32562](https://github.com/hashicorp/terraform-provider-azurerm/issues/32562))
    - `azurerm_subnet` - add support for the `network_security_group_id_wo` and `network_security_group_id_wo_version` properties ([#&#8203;32847](https://github.com/hashicorp/terraform-provider-azurerm/issues/32847))
    - `azurerm_subnet` - add support for the `route_table_id_wo` and `route_table_id_wo_version` properties ([#&#8203;32847](https://github.com/hashicorp/terraform-provider-azurerm/issues/32847))
    - `azurerm_subnet` - export the `network_security_group_id` property ([#&#8203;32847](https://github.com/hashicorp/terraform-provider-azurerm/issues/32847))
    - `azurerm_subnet` - export the `route_table_id` property ([#&#8203;32847](https://github.com/hashicorp/terraform-provider-azurerm/issues/32847))
    - `azurerm_windows_web_app` - add support for `~24` to `site_config.application_stack.node_version` ([#&#8203;32840](https://github.com/hashicorp/terraform-provider-azurerm/issues/32840))
    - `azurerm_windows_web_app_slot` - add support for `~24` to `site_config.application_stack.node_version` ([#&#8203;32840](https://github.com/hashicorp/terraform-provider-azurerm/issues/32840))
    - `cdn` - migrate to `go-azure-sdk` ([#&#8203;32849](https://github.com/hashicorp/terraform-provider-azurerm/issues/32849))
    - `sentinel` - migrate to `go-azure-sdk` ([#&#8203;32759](https://github.com/hashicorp/terraform-provider-azurerm/issues/32759))

    </details>

    ---

    ### Configuration

    📅 **Schedule**: (in timezone Europe/Oslo)

    - Branch creation
      - At any time (no schedule defined)
    - Automerge
      - At any time (no schedule defined)

    🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

    ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

    🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

    ---

     - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

    ---

    This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
    <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

    ---------

    Co-authored-by: Renovate Bot <renovate@forteapps.net>
    Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/55
    Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
    Co-authored-by: gitea_admin <admin@forteapps.net>

commit 0f0082d54d
Author: gitea_admin <admin@forteapps.net>
Date:   Sat Oct 3 18:55:02 2026 +0000

    chore(deps): update helm release fluent-bit to v0.58.3 (#57)

    This PR contains the following updates:

    | Package | Update | Change |
    |---|---|---|
    | [fluent-bit](https://fluentbit.io/) ([source](https://github.com/fluent/helm-charts)) | patch | `0.58.2` → `0.58.3` |

    ---

    ### Release Notes

    <details>
    <summary>fluent/helm-charts (fluent-bit)</summary>

    ### [`v0.58.3`](https://github.com/fluent/helm-charts/releases/tag/fluent-bit-0.58.3)

    [Compare Source](https://github.com/fluent/helm-charts/compare/fluent-bit-0.58.2...fluent-bit-0.58.3)

    ##### Changed

    - Update *Fluent Bit* OCI image to [v5.1.3](https://github.com/fluent/fluent-bit/releases/tag/v5.1.3). ([#&#8203;759](https://github.com/fluent/helm-charts/pull/759)) [@&#8203;stevehipwell](https://github.com/stevehipwell)

    </details>

    ---

    ### Configuration

    📅 **Schedule**: (in timezone Europe/Oslo)

    - Branch creation
      - At any time (no schedule defined)
    - Automerge
      - At any time (no schedule defined)

    🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

    ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

    🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

    ---

     - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

    ---

    This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
    <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

    ---------

    Co-authored-by: Renovate Bot <renovate@forteapps.net>
    Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/57
    Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
    Co-authored-by: gitea_admin <admin@forteapps.net>

commit 4a4b8e3540
Author: Jørgen Stensrud <jorgen.stensrud@fortedigital.com>
Date:   Thu Oct 1 11:25:34 2026 +0000

    feat(keycloak): forte-cli device-code client + forte-drop-mcp audience mapper (#44)

    Adds the shared public forte-cli client (RFC 8628 device-code only) to the forte realm, with an oidc-audience-mapper that puts https://mcp.drop.forteapps.net/mcp into aud so the forte-drop-mcp sidecar accepts its tokens. Supersedes #26.

    Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

commit 60b8fa657a
Author: gitea_admin <admin@forteapps.net>
Date:   Thu Oct 1 09:40:57 2026 +0000

    chore(deps): update nikitafilonov/ai-review docker tag to v1 (#53)

    This PR contains the following updates:

    | Package | Type | Update | Change |
    |---|---|---|---|
    | nikitafilonov/ai-review | docker | major | `v0.77.0` → `v1.1.0` |

    ---

    ### Configuration

    📅 **Schedule**: (in timezone Europe/Oslo)

    - Branch creation
      - At any time (no schedule defined)
    - Automerge
      - At any time (no schedule defined)

    🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

    ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

    🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

    ---

     - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

    ---

    This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
    <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

    ---------

    Co-authored-by: Renovate Bot <renovate@forteapps.net>
    Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/53
    Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
    Co-authored-by: gitea_admin <admin@forteapps.net>

commit c940259545
Author: gitea_admin <admin@forteapps.net>
Date:   Wed Sep 30 08:36:32 2026 +0000

    chore(deps): update helm release opencost to v2 (#50)

    This PR contains the following updates:

    | Package | Update | Change |
    |---|---|---|
    | [opencost](https://github.com/opencost/opencost-helm-chart) | major | `1.43.2` → `2.5.32` |

    ---

    ### Release Notes

    <details>
    <summary>opencost/opencost-helm-chart (opencost)</summary>

    ### [`v2.5.32`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.32)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.31...opencost-2.5.32)

    OpenCost and OpenCost UI

    #### What's Changed

    - Upgrade OpenCost Helm Chart to v1.121.3 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;385](https://github.com/opencost/opencost-helm-chart/pull/385)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.31...opencost-2.5.32>

    ### [`v2.5.31`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.31)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.30...opencost-2.5.31)

    OpenCost and OpenCost UI

    #### What's Changed

    - Release OpenCost v1.121.2 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;384](https://github.com/opencost/opencost-helm-chart/pull/384)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.30...opencost-2.5.31>

    ### [`v2.5.30`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.30)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.29...opencost-2.5.30)

    OpenCost and OpenCost UI

    #### What's Changed

    - feat: add opencost.exporter.extraEnvFrom to source env from ConfigMap/Secret by [@&#8203;ahauserv](https://github.com/ahauserv) in [#&#8203;378](https://github.com/opencost/opencost-helm-chart/pull/378)

    #### New Contributors

    - [@&#8203;ahauserv](https://github.com/ahauserv) made their first contribution in [#&#8203;378](https://github.com/opencost/opencost-helm-chart/pull/378)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.29...opencost-2.5.30>

    ### [`v2.5.29`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.29)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.28...opencost-2.5.29)

    OpenCost and OpenCost UI

    #### What's Changed

    - Release OpenCost v1.121.1 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;377](https://github.com/opencost/opencost-helm-chart/pull/377)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.28...opencost-2.5.29>

    ### [`v2.5.28`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.28)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.27...opencost-2.5.28)

    OpenCost and OpenCost UI

    #### What's Changed

    - Inference Cost params added to helm by [@&#8203;simanadler](https://github.com/simanadler) in [#&#8203;370](https://github.com/opencost/opencost-helm-chart/pull/370)
    - Release OpenCost v1.121.0 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;372](https://github.com/opencost/opencost-helm-chart/pull/372)

    #### New Contributors

    - [@&#8203;simanadler](https://github.com/simanadler) made their first contribution in [#&#8203;370](https://github.com/opencost/opencost-helm-chart/pull/370)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.27...opencost-2.5.28>

    ### [`v2.5.27`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.27)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.26...opencost-2.5.27)

    OpenCost and OpenCost UI

    #### What's Changed

    - KCM-5392: Add support for configuring external labels for Opencost installation with Collector data source by [@&#8203;avrodrigues5](https://github.com/avrodrigues5) in [#&#8203;371](https://github.com/opencost/opencost-helm-chart/pull/371)

    #### New Contributors

    - [@&#8203;avrodrigues5](https://github.com/avrodrigues5) made their first contribution in [#&#8203;371](https://github.com/opencost/opencost-helm-chart/pull/371)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.26...opencost-2.5.27>

    ### [`v2.5.26`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.26)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.25...opencost-2.5.26)

    OpenCost and OpenCost UI

    #### What's Changed

    - add timeout configuration for override in probes by [@&#8203;aman-kumar29](https://github.com/aman-kumar29) in [#&#8203;369](https://github.com/opencost/opencost-helm-chart/pull/369)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-parquet-exporter-0.3.0...opencost-2.5.26>

    ### [`v2.5.25`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.25)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.24...opencost-2.5.25)

    OpenCost and OpenCost UI

    #### What's Changed

    - Release OpenCost v1.120.4 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;366](https://github.com/opencost/opencost-helm-chart/pull/366)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.24...opencost-2.5.25>

    ### [`v2.5.24`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.24)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.23...opencost-2.5.24)

    OpenCost and OpenCost UI

    #### What's Changed

    - fix(service): use opencost.exporter.debugPort for service targetPort by [@&#8203;aman-kumar29](https://github.com/aman-kumar29) in [#&#8203;364](https://github.com/opencost/opencost-helm-chart/pull/364)

    #### New Contributors

    - [@&#8203;aman-kumar29](https://github.com/aman-kumar29) made their first contribution in [#&#8203;364](https://github.com/opencost/opencost-helm-chart/pull/364)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.23...opencost-2.5.24>

    ### [`v2.5.23`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.23)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.22...opencost-2.5.23)

    OpenCost and OpenCost UI

    #### What's Changed

    - feat(gateway-api): Add support for filters by [@&#8203;HartmannVolker](https://github.com/HartmannVolker) in [#&#8203;356](https://github.com/opencost/opencost-helm-chart/pull/356)

    #### New Contributors

    - [@&#8203;HartmannVolker](https://github.com/HartmannVolker) made their first contribution in [#&#8203;356](https://github.com/opencost/opencost-helm-chart/pull/356)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.22...opencost-2.5.23>

    ### [`v2.5.22`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.22)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.21...opencost-2.5.22)

    OpenCost and OpenCost UI

    #### What's Changed

    - Release OpenCost v1.120.3 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;357](https://github.com/opencost/opencost-helm-chart/pull/357)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.21...opencost-2.5.22>

    ### [`v2.5.21`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.21)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.20...opencost-2.5.21)

    OpenCost and OpenCost UI

    #### What's Changed

    - feat: add extraObjects for tpl-rendered extra manifests by [@&#8203;younsl](https://github.com/younsl) in [#&#8203;354](https://github.com/opencost/opencost-helm-chart/pull/354)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.20...opencost-2.5.21>

    ### [`v2.5.20`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.20)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.19...opencost-2.5.20)

    OpenCost and OpenCost UI

    #### What's Changed

    - Update Helm chart for v1.120.2 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;355](https://github.com/opencost/opencost-helm-chart/pull/355)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.19...opencost-2.5.20>

    ### [`v2.5.19`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.19)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.18...opencost-2.5.19)

    OpenCost and OpenCost UI

    #### What's Changed

    - Consistent Usage of `opencost.namespace` Helper by [@&#8203;ioboi](https://github.com/ioboi) in [#&#8203;353](https://github.com/opencost/opencost-helm-chart/pull/353)

    #### New Contributors

    - [@&#8203;ioboi](https://github.com/ioboi) made their first contribution in [#&#8203;353](https://github.com/opencost/opencost-helm-chart/pull/353)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.18...opencost-2.5.19>

    ### [`v2.5.18`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.18)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.14...opencost-2.5.18)

    OpenCost and OpenCost UI

    #### What's Changed

    - feat: Add plugins.install.plugins list and existingSecret support (adopts [#&#8203;328](https://github.com/opencost/opencost-helm-chart/issues/328)) by [@&#8203;ameijer](https://github.com/ameijer) in [#&#8203;344](https://github.com/opencost/opencost-helm-chart/pull/344)
    - feat: add OCI cloud cost configuration example to cloudIntegrationJSON by [@&#8203;Kush172005](https://github.com/Kush172005) in [#&#8203;345](https://github.com/opencost/opencost-helm-chart/pull/345)
    - Release Opencost v1.120.1 - Bump Helm Chart by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;347](https://github.com/opencost/opencost-helm-chart/pull/347)
    - Fix UI route tls by [@&#8203;mittal-ishaan](https://github.com/mittal-ishaan) in [#&#8203;352](https://github.com/opencost/opencost-helm-chart/pull/352)

    #### New Contributors

    - [@&#8203;Kush172005](https://github.com/Kush172005) made their first contribution in [#&#8203;345](https://github.com/opencost/opencost-helm-chart/pull/345)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.14...opencost-2.5.18>

    ### [`v2.5.14`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.14)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.12...opencost-2.5.14)

    OpenCost and OpenCost UI

    #### What's Changed

    - Release Opencost v1.120.0 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;341](https://github.com/opencost/opencost-helm-chart/pull/341)
    - Cdp/opencost v1.120.0 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;343](https://github.com/opencost/opencost-helm-chart/pull/343)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.12...opencost-2.5.14>

    ### [`v2.5.12`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.12)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.11...opencost-2.5.12)

    OpenCost and OpenCost UI

    #### What's Changed

    - Create Empty /var/configs dir by [@&#8203;HMetcalfeW](https://github.com/HMetcalfeW) in [#&#8203;333](https://github.com/opencost/opencost-helm-chart/pull/333)

    #### New Contributors

    - [@&#8203;HMetcalfeW](https://github.com/HMetcalfeW) made their first contribution in [#&#8203;333](https://github.com/opencost/opencost-helm-chart/pull/333)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.11...opencost-2.5.12>

    ### [`v2.5.11`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.11)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.10...opencost-2.5.11)

    OpenCost and OpenCost UI

    #### What's Changed

    - add admin token infra support by [@&#8203;ameijer](https://github.com/ameijer) in [#&#8203;339](https://github.com/opencost/opencost-helm-chart/pull/339)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.10...opencost-2.5.11>

    ### [`v2.5.10`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.10)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.9...opencost-2.5.10)

    OpenCost and OpenCost UI

    #### What's Changed

    - Add cloudIntegrationJSON support by [@&#8203;thomasvn](https://github.com/thomasvn) in [#&#8203;337](https://github.com/opencost/opencost-helm-chart/pull/337)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.9...opencost-2.5.10>

    ### [`v2.5.9`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.9)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.8...opencost-2.5.9)

    OpenCost and OpenCost UI

    #### What's Changed

    - Fix collectorDataSource retention env var conditions by [@&#8203;dag-andersen](https://github.com/dag-andersen) in [#&#8203;336](https://github.com/opencost/opencost-helm-chart/pull/336)

    #### New Contributors

    - [@&#8203;dag-andersen](https://github.com/dag-andersen) made their first contribution in [#&#8203;336](https://github.com/opencost/opencost-helm-chart/pull/336)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.8...opencost-2.5.9>

    ### [`v2.5.8`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.8)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.7...opencost-2.5.8)

    OpenCost and OpenCost UI

    #### What's Changed

    - Opencost v1.119.2 Changes by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;334](https://github.com/opencost/opencost-helm-chart/pull/334)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.7...opencost-2.5.8>

    ### [`v2.5.7`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.7)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.6...opencost-2.5.7)

    OpenCost and OpenCost UI

    #### What's Changed

    - fix: fix csv export condition in deployment by [@&#8203;meroupatate](https://github.com/meroupatate) in [#&#8203;330](https://github.com/opencost/opencost-helm-chart/pull/330)

    #### New Contributors

    - [@&#8203;meroupatate](https://github.com/meroupatate) made their first contribution in [#&#8203;330](https://github.com/opencost/opencost-helm-chart/pull/330)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.6...opencost-2.5.7>

    ### [`v2.5.6`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.6)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.5...opencost-2.5.6)

    OpenCost and OpenCost UI

    #### What's Changed

    - Do not grant permissions on nodes/proxy by default by [@&#8203;Farenjihn](https://github.com/Farenjihn) in [#&#8203;329](https://github.com/opencost/opencost-helm-chart/pull/329)

    #### New Contributors

    - [@&#8203;Farenjihn](https://github.com/Farenjihn) made their first contribution in [#&#8203;329](https://github.com/opencost/opencost-helm-chart/pull/329)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.5...opencost-2.5.6>

    ### [`v2.5.5`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.5)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.4...opencost-2.5.5)

    OpenCost and OpenCost UI

    #### What's Changed

    - Add PRICING\_CONFIGMAP\_NAME env to achnowledge configmapName helm value by [@&#8203;mittal-ishaan](https://github.com/mittal-ishaan) in [#&#8203;316](https://github.com/opencost/opencost-helm-chart/pull/316)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.4...opencost-2.5.5>

    ### [`v2.5.4`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.4)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.3...opencost-2.5.4)

    OpenCost and OpenCost UI

    #### What's Changed

    - feat(opencost): add Gateway API HTTPRoute support by [@&#8203;younsl](https://github.com/younsl) in [#&#8203;322](https://github.com/opencost/opencost-helm-chart/pull/322)

    #### New Contributors

    - [@&#8203;younsl](https://github.com/younsl) made their first contribution in [#&#8203;322](https://github.com/opencost/opencost-helm-chart/pull/322)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.3...opencost-2.5.4>

    ### [`v2.5.3`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.3)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.2...opencost-2.5.3)

    OpenCost and OpenCost UI

    #### What's Changed

    - Add configurable nginx proxy timeouts to helm chart by [@&#8203;peatey](https://github.com/peatey) in [#&#8203;326](https://github.com/opencost/opencost-helm-chart/pull/326)

    #### New Contributors

    - [@&#8203;peatey](https://github.com/peatey) made their first contribution in [#&#8203;326](https://github.com/opencost/opencost-helm-chart/pull/326)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.2...opencost-2.5.3>

    ### [`v2.5.2`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.2)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.1...opencost-2.5.2)

    OpenCost and OpenCost UI

    #### What's Changed

    - Update cloud-integration secret path by [@&#8203;thomasvn](https://github.com/thomasvn) in [#&#8203;324](https://github.com/opencost/opencost-helm-chart/pull/324)

    #### New Contributors

    - [@&#8203;thomasvn](https://github.com/thomasvn) made their first contribution in [#&#8203;324](https://github.com/opencost/opencost-helm-chart/pull/324)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.1...opencost-2.5.2>

    ### [`v2.5.1`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.1)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.0...opencost-2.5.1)

    OpenCost and OpenCost UI

    #### What's Changed

    - Release Opencost v1.119.1 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;325](https://github.com/opencost/opencost-helm-chart/pull/325)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.0...opencost-2.5.1>

    ### [`v2.5.0`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.0)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.4.1...opencost-2.5.0)

    OpenCost and OpenCost UI

    #### What's Changed

    - Release Opencost v1.119.0 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;323](https://github.com/opencost/opencost-helm-chart/pull/323)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.4.1...opencost-2.5.0>

    ### [`v2.4.1`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.4.1)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.4.0...opencost-2.4.1)

    OpenCost and OpenCost UI

    #### What's Changed

    - fix: mcp disable procedure by [@&#8203;marijus-ravickas](https://github.com/marijus-ravickas) in [#&#8203;319](https://github.com/opencost/opencost-helm-chart/pull/319)

    #### New Contributors

    - [@&#8203;marijus-ravickas](https://github.com/marijus-ravickas) made their first contribution in [#&#8203;319](https://github.com/opencost/opencost-helm-chart/pull/319)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.4.0...opencost-2.4.1>

    ### [`v2.4.0`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.4.0)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.3.2...opencost-2.4.0)

    OpenCost and OpenCost UI

    #### What's Changed

    - added-mcp-config by [@&#8203;sneaxhuh](https://github.com/sneaxhuh) in [#&#8203;311](https://github.com/opencost/opencost-helm-chart/pull/311)
    - Update Opencost to v1.118.0 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;314](https://github.com/opencost/opencost-helm-chart/pull/314)

    #### New Contributors

    - [@&#8203;sneaxhuh](https://github.com/sneaxhuh) made their first contribution in [#&#8203;311](https://github.com/opencost/opencost-helm-chart/pull/311)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.3.2...opencost-2.4.0>

    ### [`v2.3.2`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.3.2)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.3.1...opencost-2.3.2)

    OpenCost and OpenCost UI

    #### What's Changed

    - fix: use default sc when sc name not specified by [@&#8203;cwyl02](https://github.com/cwyl02) in [#&#8203;312](https://github.com/opencost/opencost-helm-chart/pull/312)

    #### New Contributors

    - [@&#8203;cwyl02](https://github.com/cwyl02) made their first contribution in [#&#8203;312](https://github.com/opencost/opencost-helm-chart/pull/312)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.3.1...opencost-2.3.2>

    ### [`v2.3.1`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.3.1)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.3.0...opencost-2.3.1)

    OpenCost and OpenCost UI

    #### What's Changed

    - feat: Add option to use cm to set CLUSTER\_ID envvar by [@&#8203;gracedo](https://github.com/gracedo) in [#&#8203;307](https://github.com/opencost/opencost-helm-chart/pull/307)

    #### New Contributors

    - [@&#8203;gracedo](https://github.com/gracedo) made their first contribution in [#&#8203;307](https://github.com/opencost/opencost-helm-chart/pull/307)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.3.0...opencost-2.3.1>

    ### [`v2.3.0`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.3.0)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.9...opencost-2.3.0)

    OpenCost and OpenCost UI

    #### What's Changed

    - Add configs to mount custom ca certs to opencost container by [@&#8203;mittal-ishaan](https://github.com/mittal-ishaan) in [#&#8203;303](https://github.com/opencost/opencost-helm-chart/pull/303)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.9...opencost-2.3.0>

    ### [`v2.2.9`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.9)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.8...opencost-2.2.9)

    OpenCost and OpenCost UI

    #### What's Changed

    - Add chart installation notes by [@&#8203;dejanu](https://github.com/dejanu) in [#&#8203;305](https://github.com/opencost/opencost-helm-chart/pull/305)
    - Release Opencost v1.117.6 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;309](https://github.com/opencost/opencost-helm-chart/pull/309)

    #### New Contributors

    - [@&#8203;dejanu](https://github.com/dejanu) made their first contribution in [#&#8203;305](https://github.com/opencost/opencost-helm-chart/pull/305)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.8...opencost-2.2.9>

    ### [`v2.2.8`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.8)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.7...opencost-2.2.8)

    OpenCost and OpenCost UI

    #### What's Changed

    - Release Opencost v1.117.5 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;306](https://github.com/opencost/opencost-helm-chart/pull/306)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.7...opencost-2.2.8>

    ### [`v2.2.7`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.7)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.6...opencost-2.2.7)

    OpenCost and OpenCost UI

    #### What's Changed

    - Add uiPath configuration for OpenCost UI by [@&#8203;gustavo-sdo](https://github.com/gustavo-sdo) in [#&#8203;298](https://github.com/opencost/opencost-helm-chart/pull/298)

    #### New Contributors

    - [@&#8203;gustavo-sdo](https://github.com/gustavo-sdo) made their first contribution in [#&#8203;298](https://github.com/opencost/opencost-helm-chart/pull/298)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.6...opencost-2.2.7>

    ### [`v2.2.6`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.6)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.5...opencost-2.2.6)

    OpenCost and OpenCost UI

    #### What's Changed

    - Dodizzle/proxy fix by [@&#8203;ameijer](https://github.com/ameijer) in [#&#8203;301](https://github.com/opencost/opencost-helm-chart/pull/301)
    - allow: set path for internal prometheus by [@&#8203;dodizzle](https://github.com/dodizzle) in [#&#8203;271](https://github.com/opencost/opencost-helm-chart/pull/271)

    #### New Contributors

    - [@&#8203;dodizzle](https://github.com/dodizzle) made their first contribution in [#&#8203;271](https://github.com/opencost/opencost-helm-chart/pull/271)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.5...opencost-2.2.6>

    ### [`v2.2.5`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.5)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.4...opencost-2.2.5)

    OpenCost and OpenCost UI

    #### What's Changed

    - Release v1.117.3 of Opencost by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;300](https://github.com/opencost/opencost-helm-chart/pull/300)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.4...opencost-2.2.5>

    ### [`v2.2.4`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.4)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.3...opencost-2.2.4)

    OpenCost and OpenCost UI

    #### What's Changed

    - Release v1.117.2 of Opencost by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;299](https://github.com/opencost/opencost-helm-chart/pull/299)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.3...opencost-2.2.4>

    ### [`v2.2.3`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.3)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.2...opencost-2.2.3)

    OpenCost and OpenCost UI

    #### What's Changed

    - Update env var names and values by [@&#8203;Sean-Holcomb](https://github.com/Sean-Holcomb) in [#&#8203;297](https://github.com/opencost/opencost-helm-chart/pull/297)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.2...opencost-2.2.3>

    ### [`v2.2.2`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.2)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.1...opencost-2.2.2)

    OpenCost and OpenCost UI

    #### What's Changed

    - Advance to Opencost v1.117.0 by [@&#8203;mbolt35](https://github.com/mbolt35) in [#&#8203;296](https://github.com/opencost/opencost-helm-chart/pull/296)

    #### New Contributors

    - [@&#8203;mbolt35](https://github.com/mbolt35) made their first contribution in [#&#8203;296](https://github.com/opencost/opencost-helm-chart/pull/296)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.1...opencost-2.2.2>

    ### [`v2.2.1`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.1)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.0...opencost-2.2.1)

    OpenCost and OpenCost UI

    #### What's Changed

    - Add `insecureSkipVerify` to `prometheus.external`  by [@&#8203;charleshu-8](https://github.com/charleshu-8) in [#&#8203;294](https://github.com/opencost/opencost-helm-chart/pull/294)

    #### New Contributors

    - [@&#8203;charleshu-8](https://github.com/charleshu-8) made their first contribution in [#&#8203;294](https://github.com/opencost/opencost-helm-chart/pull/294)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.0...opencost-2.2.1>

    ### [`v2.2.0`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.0)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.9...opencost-2.2.0)

    OpenCost and OpenCost UI

    #### What's Changed

    - Bump image tags and chart version by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;291](https://github.com/opencost/opencost-helm-chart/pull/291)

    #### New Contributors

    - [@&#8203;cpetersen5](https://github.com/cpetersen5) made their first contribution in [#&#8203;291](https://github.com/opencost/opencost-helm-chart/pull/291)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.9...opencost-2.2.0>

    ### [`v2.1.9`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.9)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.8...opencost-2.1.9)

    OpenCost and OpenCost UI

    #### What's Changed

    - Change ETL env variable name by [@&#8203;Sean-Holcomb](https://github.com/Sean-Holcomb) in [#&#8203;285](https://github.com/opencost/opencost-helm-chart/pull/285)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.8...opencost-2.1.9>

    ### [`v2.1.8`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.8)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.7...opencost-2.1.8)

    OpenCost and OpenCost UI

    #### What's Changed

    - tweak params by [@&#8203;ameijer](https://github.com/ameijer) in [#&#8203;289](https://github.com/opencost/opencost-helm-chart/pull/289)
    - add option to override the default container command by [@&#8203;nishanthreddydd](https://github.com/nishanthreddydd) in [#&#8203;290](https://github.com/opencost/opencost-helm-chart/pull/290)

    #### New Contributors

    - [@&#8203;nishanthreddydd](https://github.com/nishanthreddydd) made their first contribution in [#&#8203;290](https://github.com/opencost/opencost-helm-chart/pull/290)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.7...opencost-2.1.8>

    ### [`v2.1.7`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.7)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.6...opencost-2.1.7)

    OpenCost and OpenCost UI

    #### What's Changed

    - (doc) update readme to easily install unittest by [@&#8203;karthik-suresh](https://github.com/karthik-suresh) in [#&#8203;284](https://github.com/opencost/opencost-helm-chart/pull/284)
    - Add ability to configure resolution for prometheus by [@&#8203;Sean-Holcomb](https://github.com/Sean-Holcomb) in [#&#8203;282](https://github.com/opencost/opencost-helm-chart/pull/282)
    - Add support for Pod Disruption Budget by [@&#8203;josephteddick](https://github.com/josephteddick) in [#&#8203;287](https://github.com/opencost/opencost-helm-chart/pull/287)

    #### New Contributors

    - [@&#8203;karthik-suresh](https://github.com/karthik-suresh) made their first contribution in [#&#8203;284](https://github.com/opencost/opencost-helm-chart/pull/284)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.6...opencost-2.1.7>

    ### [`v2.1.6`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.6)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.5...opencost-2.1.6)

    OpenCost and OpenCost UI

    #### What's Changed

    - feat(sec) - customize service account mounting by [@&#8203;cpsmx](https://github.com/cpsmx) in [#&#8203;283](https://github.com/opencost/opencost-helm-chart/pull/283)

    #### New Contributors

    - [@&#8203;cpsmx](https://github.com/cpsmx) made their first contribution in [#&#8203;283](https://github.com/opencost/opencost-helm-chart/pull/283)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.5...opencost-2.1.6>

    ### [`v2.1.5`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.5)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.4...opencost-2.1.5)

    OpenCost and OpenCost UI

    #### What's Changed

    - Update opencost ui 1.115.0 image by [@&#8203;mittal-ishaan](https://github.com/mittal-ishaan) in [#&#8203;281](https://github.com/opencost/opencost-helm-chart/pull/281)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.4...opencost-2.1.5>

    ### [`v2.1.4`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.4)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.3...opencost-2.1.4)

    OpenCost and OpenCost UI

    #### What's Changed

    - Bump OC to 1.115.0 by [@&#8203;mittal-ishaan](https://github.com/mittal-ishaan) in [#&#8203;277](https://github.com/opencost/opencost-helm-chart/pull/277)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.3...opencost-2.1.4>

    ### [`v2.1.3`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.3)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.2...opencost-2.1.3)

    OpenCost and OpenCost UI

    #### What's Changed

    - Promless Config by [@&#8203;Sean-Holcomb](https://github.com/Sean-Holcomb) in [#&#8203;275](https://github.com/opencost/opencost-helm-chart/pull/275)
    - Add values examples and notes to values.yaml. Update version numbers by [@&#8203;Sean-Holcomb](https://github.com/Sean-Holcomb) in [#&#8203;276](https://github.com/opencost/opencost-helm-chart/pull/276)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.2...opencost-2.1.3>

    ### [`v2.1.2`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.2)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.1...opencost-2.1.2)

    OpenCost and OpenCost UI

    #### What's Changed

    - Add support for API Ingress by [@&#8203;josephteddick](https://github.com/josephteddick) in [#&#8203;255](https://github.com/opencost/opencost-helm-chart/pull/255)

    #### New Contributors

    - [@&#8203;josephteddick](https://github.com/josephteddick) made their first contribution in [#&#8203;255](https://github.com/opencost/opencost-helm-chart/pull/255)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-parquet-exporter-0.2.0...opencost-2.1.2>

    ### [`v2.1.1`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.1)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.0...opencost-2.1.1)

    OpenCost and OpenCost UI

    #### What's Changed

    - Fix for [#&#8203;272](https://github.com/opencost/opencost-helm-chart/pull/272) to make feature flag actually work. by [@&#8203;tintii](https://github.com/tintii) in [#&#8203;274](https://github.com/opencost/opencost-helm-chart/pull/274)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.0...opencost-2.1.1>

    ### [`v2.1.0`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.0)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.0.2...opencost-2.1.0)

    OpenCost and OpenCost UI

    #### What's Changed

    - Openshift Security Context Constraints and updated ClusterRole with access to internal prometheus. by [@&#8203;v0nNemizez](https://github.com/v0nNemizez) in [#&#8203;267](https://github.com/opencost/opencost-helm-chart/pull/267)

    #### New Contributors

    - [@&#8203;v0nNemizez](https://github.com/v0nNemizez) made their first contribution in [#&#8203;267](https://github.com/opencost/opencost-helm-chart/pull/267)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.0.2...opencost-2.1.0>

    ### [`v2.0.2`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.0.2)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.0.1...opencost-2.0.2)

    OpenCost and OpenCost UI

    #### What's Changed

    - Add opencost.ui.useIPv6 feature flag by [@&#8203;tintii](https://github.com/tintii) in [#&#8203;272](https://github.com/opencost/opencost-helm-chart/pull/272)

    #### New Contributors

    - [@&#8203;tintii](https://github.com/tintii) made their first contribution in [#&#8203;272](https://github.com/opencost/opencost-helm-chart/pull/272)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.0.1...opencost-2.0.2>

    ### [`v2.0.1`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.0.1)

    [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.0.0...opencost-2.0.1)

    OpenCost and OpenCost UI

    #### What's Changed

    - add sha256sums of configMaps to trigger a restart of the pod, if the configMap changes by [@&#8203;kastl-ars](https://github.com/kastl-ars) in [#&#8203;264](https://github.com/opencost/opencost-helm-chart/pull/264)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.0.0...opencost-2.0.1>

    ### [`v2.0.0`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.0.0)

    OpenCost and OpenCost UI

    #### What's Changed

    - add seperate openshift block to handle openshift related configurations and add frontend nginx config by [@&#8203;mittal-ishaan](https://github.com/mittal-ishaan) in [#&#8203;245](https://github.com/opencost/opencost-helm-chart/pull/245)
    - Updating chart badge by [@&#8203;TheUnixRoot](https://github.com/TheUnixRoot) in [#&#8203;261](https://github.com/opencost/opencost-helm-chart/pull/261)
    - Fix: Chart release script by [@&#8203;mittal-ishaan](https://github.com/mittal-ishaan) in [#&#8203;262](https://github.com/opencost/opencost-helm-chart/pull/262)

    #### New Contributors

    - [@&#8203;TheUnixRoot](https://github.com/TheUnixRoot) made their first contribution in [#&#8203;261](https://github.com/opencost/opencost-helm-chart/pull/261)

    **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/1.45.0-helm...opencost-2.0.0>

    </details>

    ---

    ### Configuration

    📅 **Schedule**: (in timezone Europe/Oslo)

    - Branch creation
      - At any time (no schedule defined)
    - Automerge
      - At any time (no schedule defined)

    🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

    ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

    🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

    ---

     - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

    ---

    This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
    <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJicmVha2luZy1jaGFuZ2UiLCJyZW5vdmF0ZSJdfQ==-->

    ---------

    Co-authored-by: Renovate Bot <renovate@forteapps.net>
    Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/50
    Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
    Co-authored-by: gitea_admin <admin@forteapps.net>
2026-10-07 08:37:56 +02:00

49 KiB

Developer Onboarding Guide

Table of Contents


Getting Started

Welcome! This guide will help you understand how to develop and deploy applications on our Kubernetes cluster using GitOps principles powered by ArgoCD.

What You'll Learn

  • How our GitOps architecture works
  • How to deploy a new application
  • How to update existing applications
  • How to manage secrets securely
  • Common troubleshooting techniques

Who This Guide Is For

  • Developers deploying new applications
  • Developers maintaining existing applications
  • Team members who need to understand the deployment process

Prerequisites

Required Knowledge

  • ✅ Basic Git workflow (clone, commit, push, pull)
  • ✅ Docker basics (Dockerfile, building images)
  • ✅ YAML syntax
  • ✅ Basic understanding of Kubernetes concepts (pods, deployments, services)
  • ⚠️ Helm knowledge (helpful but not required - templates are provided)

Required Tools

Most developers do NOT need kubectl access to the cluster. You'll primarily work with Git repositories.

If you do need cluster access, install:

  1. kubectl - Kubernetes CLI

    # macOS
    brew install kubectl
    
    # Windows
    choco install kubernetes-cli
    
    # Linux
    curl -LO "https://dl.k8s.io/release/$(curl -L -s https://dl.k8s.io/release/stable.txt)/bin/linux/amd64/kubectl"
    
  2. kubeseal - For sealing secrets

    # macOS
    brew install kubeseal
    
    # Windows
    choco install kubeseal
    
    # Linux
    wget https://github.com/bitnami-labs/sealed-secrets/releases/download/v0.24.0/kubeseal-0.24.0-linux-amd64.tar.gz
    tar -xvzf kubeseal-0.24.0-linux-amd64.tar.gz
    sudo mv kubeseal /usr/local/bin/
    
  3. Git - Version control

    git --version  # Should already be installed
    
  4. Docker - For local development

    # macOS/Windows: Install Docker Desktop
    # Linux: Install Docker Engine
    docker --version
    

Repository Access

You'll need read/write access to these repositories:

  1. launchpad (Config repo)

    git clone https://git.forteapps.net/Forte/launchpad.git
    cd launchpad
    
  2. helm-prod-values (Values repo)

    git clone https://git.forteapps.net/Forte/helm-prod-values.git
    cd helm-prod-values
    
  3. forte-helm (Chart repo - read-only for most developers)

    git clone https://git.forteapps.net/Forte/forte-helm.git
    cd forte-helm
    

Cluster Access (If Needed)

If you need kubectl access, ask the platform team for:

  • Kubeconfig file
  • Cluster context setup instructions

Save to ~/.kube/config and verify:

kubectl cluster-info
kubectl get nodes

Local Development Setup

1. Clone the Repositories

Set up a consistent folder structure:

mkdir -p ~/dev/k8s
cd ~/dev/k8s

# Clone repositories
git clone https://git.forteapps.net/Forte/launchpad.git launchpad
git clone https://git.forteapps.net/Forte/helm-prod-values helm-prod-values
git clone https://git.forteapps.net/Forte/forte-helm forte-helm

# Your folder structure:
# ~/dev/k8s/
# ├── launchpad/           (Config repo)
# ├── helm-prod-values/    (Values repo)
# └── forte-helm/          (Chart repo)

2. Local Development Environment

Most applications use Docker Compose for local development:

# In your application repository
docker-compose up

# Or for frontend applications
npm install
npm run dev

You DO NOT run applications locally on Kubernetes. Use Docker Compose or native tooling (npm, python, etc.).

3. Understanding the Deployment Flow

┌─────────────────────────────────────────────────────────────────┐
│  Step 1: Develop Locally                                        │
│  - Write code in your application repository                    │
│  - Test with Docker Compose or npm/python/etc.                  │
│  - Build Docker image                                            │
└─────────────────────────────────────────────────────────────────┘
                            │
                            ▼
┌─────────────────────────────────────────────────────────────────┐
│  Step 2: CI/CD Pipeline (Automated)                             │
│  - GitHub Actions builds image                                  │
│  - Pushes to container registry (GHCR, Docker Hub)              │
│  - Tags with version (e.g., v2.0.4)                             │
│  - Updates helm-prod-values repository with new tag                  │
└─────────────────────────────────────────────────────────────────┘
                            │
                            ▼
┌─────────────────────────────────────────────────────────────────┐
│  Step 3: GitOps Sync (Automated)                                │
│  - ArgoCD detects change in helm-prod-values                         │
│  - Pulls updated configuration                                  │
│  - Syncs to Kubernetes cluster                                  │
│  - Sends Slack notification on success/failure                  │
└─────────────────────────────────────────────────────────────────┘

Key Insight: You don't deploy directly. You push code, CI/CD builds it, and ArgoCD deploys it.


Understanding the Workflow

Three-Repository Pattern

Our setup uses three repositories:

Repository Purpose Who Edits How Often
forte-helm Helm chart templates (generic, reusable) Platform engineers ❌ Rarely
helm-prod-values Application configuration (image tag, env vars) Developers / CI pipelines ✅ Sometimes
launchpad ArgoCD Applications (what gets deployed) Platform / DevOps engineers ✅ Per new app

Example: Deploying "myapp"

Repository: forte-helm (Chart Templates)

# forteapp/templates/deployment.yaml
# Generic template used by ALL apps
apiVersion: apps/v1
kind: Deployment
metadata:
  name: {{ .Values.app.name }}
spec:
  containers:
  - name: app
    image: "{{ .Values.app.image.repository }}:{{ .Values.app.image.tag }}"
    env:
    - name: PORT
      value: {{ .Values.app.port }}

Repository: helm-prod-values (Your App Config)

# myapp/values.yaml
# Your app's specific configuration
app:
  image:
    repository: ghcr.io/fortedigital/myapp
    tag: v1.0.0                    # CI/CD updates this
  port: 3000
  extraEnv:
  - name: API_URL
    value: https://api.example.com

Repository: launchpad (ArgoCD Application)

# apps/myapp.yaml
# Tells ArgoCD to deploy your app
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
  name: myapp
  namespace: argocd
spec:
  sources:
  - repoURL: https://git.forteapps.net/Forte/forte-helm
    path: forteapp
    helm:
      valueFiles:
      - $values/myapp/values.yaml

  - repoURL: git@github.com:fortedigital/helm-prod-values.git
    ref: values

  destination:
    server: https://kubernetes.default.svc
    namespace: myapp

  syncPolicy:
    automated:
      prune: true
      selfHeal: true
    syncOptions:
    - CreateNamespace=true

Deploying Your First Application

Scenario: You've Built a New Application

Let's deploy a new Node.js application called "hello-world".

Step 1: Prepare Your Application Repository

Ensure your app repository has:

  1. Dockerfile

    FROM node:18-alpine
    WORKDIR /app
    COPY package*.json ./
    RUN npm ci --only=production
    COPY . .
    EXPOSE 3000
    CMD ["node", "server.js"]
    
  2. GitHub Actions Workflow (.github/workflows/deploy.yml)

    name: Build and Deploy
    
    on:
      push:
        branches: [ main ]
    
    jobs:
      build:
        runs-on: ubuntu-latest
        steps:
          - uses: actions/checkout@v3
    
          - name: Set version
            id: version
            run: echo "VERSION=v$(date +%Y%m%d-%H%M%S)" >> $GITHUB_OUTPUT
    
          - name: Build and push Docker image
            run: |
              echo ${{ secrets.GITHUB_TOKEN }} | docker login ghcr.io -u ${{ github.actor }} --password-stdin
              docker build -t ghcr.io/fortedigital/hello-world:${{ steps.version.outputs.VERSION }} .
              docker push ghcr.io/fortedigital/hello-world:${{ steps.version.outputs.VERSION }}
    
          - name: Update helm-prod-values
            run: |
              git clone git@github.com:fortedigital/helm-prod-values.git
              cd helm-prod-values
              mkdir -p hello-world
              cat > hello-world/values.yaml <<EOF
              app:
                image:
                  repository: ghcr.io/fortedigital/hello-world
                  tag: ${{ steps.version.outputs.VERSION }}
              EOF
              git add hello-world/values.yaml
              git commit -m "Update hello-world to ${{ steps.version.outputs.VERSION }}"
              git push
    

Step 2: Create Helm Values

Create a folder in helm-prod-values repository:

cd ~/dev/k8s/helm-prod-values
mkdir -p hello-world

Create hello-world/values.yaml:

app:
  image:
    repository: ghcr.io/fortedigital/hello-world
    tag: v1.0.0                    # Will be updated by CI/CD
    containerPort: 3000

  replicaCount: 1

  resources:
    requests:
      cpu: 100m
      memory: 128Mi
    limits:
      cpu: 500m
      memory: 512Mi

  extraEnv:
  - name: PORT
    value: "3000"
  - name: NODE_ENV
    value: "production"

  envSecretName: ""                # Optional: reference to secrets

service:
  port: 3000

ingress:
  enabled: true
  host: hello-world.forteapps.net  # Your subdomain

db:
  enabled: false                   # Set to true if you need PostgreSQL

Commit and push:

git add hello-world/values.yaml
git commit -m "Add hello-world application values"
git push

Step 3: Create ArgoCD Application Manifest

In the launchpad repository, create apps/hello-world.yaml:

apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
  name: hello-world
  namespace: argocd
  annotations:
    argocd.argoproj.io/sync-wave: "1"
    notifications.argoproj.io/subscribe.on-sync-succeeded.slack: ""
    notifications.argoproj.io/subscribe.on-sync-failed.slack: ""
    notifications.argoproj.io/subscribe.on-degraded.slack: ""
  labels:
    app.kubernetes.io/name: hello-world
    app.kubernetes.io/part-of: apps
    app.kubernetes.io/managed-by: argocd
  finalizers:
  - resources-finalizer.argocd.argoproj.io

spec:
  project: default

  sources:
  # Source 1: Helm chart templates
  - repoURL: https://git.forteapps.net/Forte/forte-helm
    path: forteapp
    targetRevision: HEAD
    helm:
      valueFiles:
      - $values/hello-world/values.yaml

  # Source 2: Helm values
  - repoURL: git@github.com:fortedigital/helm-prod-values.git
    targetRevision: HEAD
    ref: values

  destination:
    server: https://kubernetes.default.svc
    namespace: hello-world

  syncPolicy:
    automated:
      prune: true
      selfHeal: true
      allowEmpty: false

    syncOptions:
    - CreateNamespace=true
    - Validate=true
    - ServerSideApply=true

    retry:
      limit: 5
      backoff:
        duration: 5s
        factor: 2
        maxDuration: 3m

  ignoreDifferences:
  - group: apps
    kind: Deployment
    jsonPointers:
    - /spec/replicas

Commit and push:

cd ~/dev/k8s/launchpad
git add apps/hello-world.yaml
git commit -m "Add hello-world application"
git push

Step 4: Verify Deployment

ArgoCD will automatically detect the new application within 60 seconds.

Option 1: Check Slack

  • Watch for sync notifications in your Slack channel
  • ✅ "Application hello-world sync succeeded"

Option 2: Check ArgoCD UI (if you have access)

# Port forward to ArgoCD UI
kubectl port-forward svc/argocd-server -n argocd 8080:443

# Open browser: https://localhost:8080
# Look for "hello-world" application

Option 3: Check with kubectl (if you have access)

# List ArgoCD applications
kubectl get applications -n argocd

# Check application status
kubectl get application hello-world -n argocd

# Verify pods are running
kubectl get pods -n hello-world

Step 5: Access Your Application

Once deployed, access via the configured domain:

# Check if ingress is created
kubectl get ingressroute -n hello-world

# Access application
curl https://hello-world.forteapps.net

⚠️ Note: DNS must be manually configured for new subdomains. Contact the platform team to add DNS records.


Updating an Existing Application

Scenario: Deploying a Code Change

You've made changes to your application code and want to deploy them.

Just push to main branch - CI/CD handles everything:

# In your application repository
git add .
git commit -m "Fix bug in user login"
git push origin main

What Happens Next:

  1. ✅ GitHub Actions triggers
  2. ✅ Builds new Docker image
  3. ✅ Tags with new version (e.g., v20260316-143022)
  4. ✅ Pushes to container registry
  5. ✅ Updates helm-prod-values/myapp/values.yaml with new tag
  6. ✅ ArgoCD detects change
  7. ✅ Syncs new version to cluster
  8. ✅ Sends Slack notification

Timeline: ~5-10 minutes from push to deployment

Method 2: Manual Image Tag Update

If CI/CD is not set up, manually update the image tag:

cd ~/dev/k8s/helm-prod-values

# Edit your app's values.yaml
vim myapp/values.yaml

# Change:
app:
  image:
    tag: v1.0.0  # Old version
# To:
app:
  image:
    tag: v1.0.1  # New version

# Commit and push
git add myapp/values.yaml
git commit -m "Update myapp to v1.0.1"
git push

ArgoCD will sync within 60 seconds.

Method 3: Configuration Changes

To update environment variables, resources, or other config:

cd ~/dev/k8s/helm-prod-values
vim myapp/values.yaml

Example changes:

app:
  # Increase resources
  resources:
    requests:
      cpu: 200m      # Was 100m
      memory: 256Mi  # Was 128Mi

  # Add new environment variable
  extraEnv:
  - name: API_URL
    value: https://api.example.com
  - name: DEBUG          # NEW
    value: "true"        # NEW

  # Enable HPA
  hpa:
    enabled: true        # Was false
    minReplicas: 2
    maxReplicas: 10

Commit and push:

git add myapp/values.yaml
git commit -m "Increase myapp resources and enable HPA"
git push

Method 4: Application Manifest Changes

To change ArgoCD sync behavior, namespace, or other meta-config:

cd ~/dev/k8s/launchpad
vim apps/myapp.yaml

Example changes:

spec:
  syncPolicy:
    automated:
      prune: true
      selfHeal: false    # Disable self-healing temporarily

Commit and push:

git add apps/myapp.yaml
git commit -m "Disable self-healing for myapp"
git push

Working with Secrets

Understanding Secret Management

NEVER commit plain secrets to Git. We use Sealed Secrets to encrypt secrets before committing.

Creating a New Secret

Step 1: Create Plain Secret Locally

cd ~/dev/k8s/launchpad

# Create secret in private/ folder (Git-ignored)
kubectl create secret generic myapp-credentials \
  --from-literal=API_KEY=your-secret-key-here \
  --from-literal=DB_PASSWORD=super-secret-password \
  --dry-run=client -o yaml > private/myapp-credentials.yaml

DO NOT commit this file! It's in private/ which is Git-ignored.

Step 2: Seal the Secret

Seal your secret:

kubeseal --format=yaml \
  --namespace=myapp \
  < private/myapp-credentials.yaml \
  > secrets/myapp-credentials-sealed.yaml

Step 3: Commit Sealed Secret

git add secrets/myapp-credentials-sealed.yaml
git commit -m "Add myapp credentials (sealed)"
git push

Step 4: Reference Secret in Application

Update your helm-prod-values/myapp/values.yaml:

app:
  envSecretName: "myapp-credentials"  # References the SealedSecret

Commit and push:

cd ~/dev/k8s/helm-prod-values
git add myapp/values.yaml
git commit -m "Reference myapp credentials"
git push

Updating a Secret

To update an existing secret:

# 1. Create new version of secret
kubectl create secret generic myapp-credentials \
  --from-literal=API_KEY=new-key-here \
  --from-literal=DB_PASSWORD=new-password \
  --dry-run=client -o yaml > private/myapp-credentials.yaml

# 2. Seal it
kubeseal --format=yaml \
  --namespace=myapp \
  < private/myapp-credentials.yaml \
  > secrets/myapp-credentials-sealed.yaml

# 3. Commit sealed version
git add secrets/myapp-credentials-sealed.yaml
git commit -m "Update myapp credentials"
git push

# 4. Restart pods to pick up new secret
kubectl rollout restart deployment myapp -n myapp

Secret Best Practices

✅ DO:

  • Store secrets in private/ folder locally
  • Always seal secrets before committing
  • Delete plain secrets after sealing
  • Use meaningful secret names
  • Document what each secret contains

❌ DON'T:

  • Commit plain secrets to Git
  • Share secrets via Slack/email
  • Hard-code secrets in code
  • Use the same secret across multiple environments
  • Store secrets in Docker images

Where Secrets Are Stored

┌─────────────────────────────────────────────────────────────┐
│  Location                │  Content           │  Committed?│
├──────────────────────────┼────────────────────┼────────────┤
│  private/                │  Plain secrets     │  ❌ NO      │
│  secrets/                │  Sealed secrets    │  ✅ YES     │
│  Kubernetes cluster      │  Unsealed secrets  │  N/A       │
└─────────────────────────────────────────────────────────────┘

Sealed Secrets Controller in the cluster decrypts sealed secrets automatically.


Enabling Authentication for Applications

The cluster supports automatic authentication sidecar injection for applications via Kyverno policies. This allows you to add authentication to your applications without modifying application code.

How It Works

When you enable authentication in your Helm values, the Kyverno policy automatically:

  1. ✅ Injects an authentication sidecar container into your pod
  2. ✅ Routes all incoming traffic through the auth sidecar (port 8080)
  3. ✅ Validates credentials before forwarding requests to your application
  4. ✅ Creates necessary secrets (if they don't exist)
  5. ✅ Adds a NetworkPolicy to restrict ingress

Architecture:

Internet → Traefik → Service:8080 → Auth Sidecar:8080 → localhost → Your App:3000
                                         │
                                         ├─ Validates credentials
                                         └─ Forwards if valid

Authentication Modes

Three authentication modes are supported:

  1. Token-based: Static tokens (simple, good for service-to-service or internal apps)
  2. OIDC: OpenID Connect (full SSO, good for user-facing apps)
  3. MCP: OAuth 2.0 for MCP servers via RFC 9728 (Protected Resource Metadata); Keycloak provides native RFC 7591 Dynamic Client Registration (good for MCP tool servers requiring OAuth-based access control)

Token-Based Authentication

Step 1: Configure Helm Values

# In helm-prod-values/myapp/values.yaml
auth:
  enabled: true
  type: token                    # Token mode (default)
  tokens:
  - d4f88f6d9292c10cc3e21c4aad56d2be485db532b54fe961d738e1137d247823
  - 8803f621acc3898df1d7a8f514bc3602551a0681a8f747bd4e43c3c5849d57a7

Step 2: Generate Token (if needed)

# Generate a secure random token
openssl rand -hex 32

# Or using Python
python3 -c "import secrets; print(secrets.token_hex(32))"

# Example output:
# d4f88f6d9292c10cc3e21c4aad56d2be485db532b54fe961d738e1137d247823

Step 3: Deploy Application

Commit and push your changes:

cd ~/dev/k8s/helm-prod-values
git add myapp/values.yaml
git commit -m "Enable token auth for myapp"
git push

ArgoCD will sync, and the Kyverno policy will:

  • Inject the auth sidecar container
  • Create an auth-tokens Secret with your tokens
  • Configure the sidecar to validate against these tokens

Step 4: Access Application

Use your token in the Authorization header:

# Access application with token
curl -H "Authorization: Bearer d4f88f6d9292c10cc3e21c4aad56d2be485db532b54fe961d738e1137d247823" \
  https://myapp.forteapps.net/api/data

# Without token (will be rejected)
curl https://myapp.forteapps.net/api/data
# Response: 401 Unauthorized

Advanced: Custom Secret Name

To use a different secret for tokens:

# In Helm values
auth:
  enabled: true
  type: token
  tokens: []                     # Empty - using external secret

# Tokens will be read from custom secret

Then reference it via annotation (configured by Helm chart automatically):

# Helm chart sets this annotation:
policies.forteapps.io/auth-token-secret-name: "myapp-auth-tokens"

Create the secret manually:

kubectl create secret generic myapp-auth-tokens \
  --from-file=tokens=tokens.txt \
  --namespace=myapp

OIDC Authentication

OIDC mode integrates with identity providers like Keycloak, Okta, Auth0, Azure AD, etc.

Step 1: Configure Identity Provider

In your identity provider (e.g., Keycloak):

  1. Create a new client (e.g., myapp)
  2. Set redirect URI: https://myapp.forteapps.net/auth/callback
  3. Note the Client ID and Client Secret
  4. Note the Authority URL (e.g., https://keycloak.forteapps.net/realms/master)

Step 2: Create OIDC Secret

# Create plain secret
kubectl create secret generic auth-oidc \
  --from-literal=client-secret=your-oidc-client-secret \
  --from-literal=cookie-secret=$(openssl rand -hex 32) \
  --namespace=myapp \
  --dry-run=client -o yaml > private/myapp-auth-oidc.yaml

# Seal it
kubeseal --format=yaml \
  --cert=pub-cert.pem \
  --namespace=myapp \
  < private/myapp-auth-oidc.yaml \
  > secrets/myapp-auth-oidc-sealed.yaml

# Commit sealed secret
cd ~/dev/k8s/launchpad
git add secrets/myapp-auth-oidc-sealed.yaml
git commit -m "Add OIDC secrets for myapp"
git push

# Clean up
rm private/myapp-auth-oidc.yaml

Step 3: Configure Helm Values

# In helm-prod-values/myapp/values.yaml
auth:
  enabled: true
  type: oidc                     # OIDC mode
  oidc:
    authority: https://keycloak.forteapps.net/realms/master
    clientId: myapp
    scopes: "openid,profile,email"
    callbackPath: /auth/callback

Step 4: Deploy Application

cd ~/dev/k8s/helm-prod-values
git add myapp/values.yaml
git commit -m "Enable OIDC auth for myapp"
git push

Step 5: Access Application

When users access https://myapp.forteapps.net:

  1. They're redirected to the identity provider login page
  2. After successful login, redirected back to /auth/callback
  3. Session cookie is set
  4. Subsequent requests are authenticated via cookie

User flow:

User → https://myapp.forteapps.net
  ↓
Redirect → https://keycloak.forteapps.net/login
  ↓
Login successful → Redirect with auth code
  ↓
https://myapp.forteapps.net/auth/callback?code=xyz
  ↓
Auth sidecar exchanges code for tokens
  ↓
Sets session cookie
  ↓
Redirects to application → https://myapp.forteapps.net
  ↓
User sees application (authenticated)

Accessing Authenticated User Information

The auth sidecar handles all authentication before requests reach your application. Your app never sees unauthenticated traffic — the sidecar returns 401 or redirects to the IdP first.

After successful authentication, the sidecar forwards the request to your application with user identity injected as HTTP headers:

Header Description Available in
X-Auth-User Username or display name Token, OIDC, MCP
X-Auth-Email User email address OIDC
X-Auth-Subject OIDC sub claim (stable user ID) OIDC, MCP
X-Auth-Groups Comma-separated group memberships OIDC (if scope includes groups)
X-Auth-Token The validated access token All modes

Your application reads these headers — no auth library needed:

// Express.js example
app.get('/profile', (req, res) => {
  const user = req.headers['x-auth-user'];
  const email = req.headers['x-auth-email'];
  res.json({ user, email });
});
# Flask example
@app.route('/profile')
def profile():
    user = request.headers.get('X-Auth-User')
    email = request.headers.get('X-Auth-Email')
    return jsonify(user=user, email=email)

Why this is safe: The Kyverno-generated NetworkPolicy restricts ingress to the sidecar port only. Traffic cannot bypass the sidecar to reach the application port directly, so the X-Auth-* headers can be trusted unconditionally.

Key principle: Your application is zero-trust-unaware by design. It reads headers and renders UI. All authentication complexity lives in the sidecar and Kyverno policy.


Authentication Configuration Reference

Helm Values Schema

auth:
  enabled: false                 # Enable/disable authentication
  type: token                    # "token", "oidc", or "mcp"

  # Token mode configuration
  tokens: []                     # List of valid bearer tokens
  # - token1
  # - token2

  # OIDC mode configuration
  oidc:
    authority: ""                # OIDC provider URL (required for OIDC)
    clientId: ""                 # OIDC client ID (required for OIDC)
    scopes: "openid,profile,email"  # OIDC scopes (optional)
    callbackPath: /auth/callback    # OAuth callback path (optional)

  # MCP mode configuration (RFC 9728)
  mcp:
    resource: ""                 # Protected resource URL (required for MCP)
    authority: ""                # Authorization server URL (required for MCP)
    scopes: "read,write"         # Supported scopes (optional)

Annotations Set by Helm Chart

When auth.enabled: true, the Helm chart sets these pod annotations:

Token mode:

policies.forteapps.io/auth: "true"
policies.forteapps.io/auth-type: "token"
policies.forteapps.io/auth-token-secret-name: "auth-tokens"
policies.forteapps.io/auth-upstream-url: "http://localhost:3000"

OIDC mode:

policies.forteapps.io/auth: "true"
policies.forteapps.io/auth-type: "oidc"
policies.forteapps.io/auth-oidc-authority: "https://keycloak.forteapps.net/realms/master"
policies.forteapps.io/auth-oidc-client-id: "myapp"
policies.forteapps.io/auth-oidc-scopes: "openid,profile,email"
policies.forteapps.io/auth-oidc-callback-path: "/auth/callback"
policies.forteapps.io/auth-upstream-url: "http://localhost:3000"

MCP mode (OAuth 2.0 for MCP servers):

policies.forteapps.io/auth: "true"
policies.forteapps.io/auth-type: "mcp"
policies.forteapps.io/auth-mcp-resource: "https://mcp.forteapps.net"
policies.forteapps.io/auth-mcp-authority: "https://keycloak.forteapps.net/realms/master"
policies.forteapps.io/auth-mcp-scopes: "read,write"
policies.forteapps.io/auth-upstream-url: "http://localhost:3000"

Sidecar Configuration

The auth sidecar container:

  • Image: ghcr.io/fortedigital/auth-sidecar:latest
  • Port: 8080
  • Resources: 10m CPU / 32Mi memory (requests), 50m CPU / 64Mi memory (limits)
  • Health checks: /healthz endpoint
  • Security: Read-only root filesystem, no privilege escalation

Advanced: Custom Sidecar Image

To use a different auth sidecar image:

# These annotations can be set in the Helm chart template if needed
policies.forteapps.io/auth-image: "your-registry/your-auth-proxy"
policies.forteapps.io/auth-image-version: "v1.2.3"

Authentication Examples

Example 1: Internal API with Token Auth

# helm-prod-values/internal-api/values.yaml
app:
  image:
    repository: ghcr.io/company/internal-api
    tag: v1.0.0

auth:
  enabled: true
  type: token
  tokens:
  - d4f88f6d9292c10cc3e21c4aad56d2be485db532b54fe961d738e1137d247823  # Service A
  - 8803f621acc3898df1d7a8f514bc3602551a0681a8f747bd4e43c3c5849d57a7  # Service B

ingress:
  enabled: true
  host: internal-api.forteapps.net

Usage:

# Service A calls API
curl -H "Authorization: Bearer d4f88f..." \
  https://internal-api.forteapps.net/api/endpoint

Example 2: User-Facing App with OIDC

# helm-prod-values/web-app/values.yaml
app:
  image:
    repository: ghcr.io/company/web-app
    tag: v2.1.0

auth:
  enabled: true
  type: oidc
  oidc:
    authority: https://auth.company.com/realms/employees
    clientId: web-app-prod
    scopes: "openid,profile,email,groups"
    callbackPath: /auth/callback

ingress:
  enabled: true
  host: web-app.forteapps.net

With sealed OIDC secret:

# Create and seal secret
kubectl create secret generic auth-oidc \
  --from-literal=client-secret=super-secret-value \
  --from-literal=cookie-secret=$(openssl rand -hex 32) \
  --namespace=web-app \
  --dry-run=client -o yaml | \
  kubeseal --format=yaml --cert=pub-cert.pem --namespace=web-app \
  > secrets/web-app-auth-oidc-sealed.yaml

Example 3: MCP Server with OAuth 2.0

# helm-prod-values/mcp-server/values.yaml
app:
  image:
    repository: ghcr.io/company/mcp-server
    tag: v1.0.0

auth:
  enabled: true
  type: mcp
  mcp:
    resource: https://mcp-server.forteapps.net
    authority: https://auth.company.com/realms/mcp
    scopes: "read,write,admin"

ingress:
  enabled: true
  host: mcp-server.forteapps.net

The MCP auth mode implements RFC 9728 (OAuth 2.0 Protected Resource Metadata) for authorization server discovery. Dynamic Client Registration (RFC 7591) is handled natively by Keycloak; MCP clients discover the authorization server and scopes from the /.well-known/oauth-protected-resource endpoint served by the sidecar and then register directly with Keycloak.

Example 4: Disabling Authentication

# helm-prod-values/public-api/values.yaml
auth:
  enabled: false                 # No authentication

ingress:
  enabled: true
  host: public-api.forteapps.net

Troubleshooting Authentication

Issue: 401 Unauthorized (Token Mode)

Check token validity:

# Get auth-tokens secret
kubectl get secret auth-tokens -n myapp -o yaml

# Decode tokens
kubectl get secret auth-tokens -n myapp \
  -o jsonpath='{.data.tokens}' | base64 -d

# Verify your token is in the list

Test with different token:

curl -v -H "Authorization: Bearer YOUR-TOKEN-HERE" \
  https://myapp.forteapps.net/

Issue: OIDC Login Loop

Check OIDC configuration:

# Verify auth-oidc secret exists
kubectl get secret auth-oidc -n myapp

# Check sidecar logs
kubectl logs -n myapp <pod-name> -c authn

# Common issues:
# - Wrong authority URL
# - Wrong client ID
# - Missing client-secret in auth-oidc Secret
# - Redirect URI not configured in identity provider

Verify redirect URI in your identity provider matches:

https://<your-app-domain>/auth/callback

Issue: Auth Sidecar Not Injected

Check pod annotations:

kubectl get pod -n myapp <pod-name> -o yaml | grep policies.forteapps.io

# Should show:
# policies.forteapps.io/auth: "true"

Check Kyverno policy:

kubectl get clusterpolicy inject-auth-sidecar
kubectl describe clusterpolicy inject-auth-sidecar

Check Kyverno logs:

kubectl logs -n kyverno deployment/kyverno | grep inject-auth

Issue: Auth Sidecar Crashes

Check sidecar logs:

kubectl logs -n myapp <pod-name> -c authn

Common causes:

  • Missing secret (auth-tokens or auth-oidc)
  • Invalid OIDC configuration
  • Can't reach OIDC authority URL
  • Network policy blocking outbound OIDC requests

Authentication Best Practices

✅ DO:

  • Use OIDC for user-facing applications
  • Use token auth for service-to-service communication
  • Rotate tokens and secrets regularly
  • Use strong random tokens (32+ bytes)
  • Store client secrets in SealedSecrets
  • Test authentication before deploying to production
  • Document which tokens/users have access

❌ DON'T:

  • Share tokens between environments
  • Commit tokens to application code
  • Use predictable tokens
  • Reuse tokens across multiple applications
  • Disable authentication on sensitive APIs
  • Log tokens or secrets

Adding a New Keycloak Client

There are two ways to add an OIDC client, depending on your use case:

Method Best for Who edits the infra repo?
Self-service (recommended) New apps that deploy their own resources App developer — no infra changes needed
Legacy (realm JSON) Existing clients already defined in forte-realm.json (e.g., Gitea) Platform engineer

Both methods are served by the Keycloak Client Registrar CronJob, which runs every 2 minutes.

Self-Service OIDC Client Registration

This is the recommended flow for new applications. Your app deploys a labeled config Secret in its own namespace; the platform handles everything else.

How It Works

  1. You deploy a Secret with label keycloak.forteapps.net/client-config: "true" containing a client.json definition
  2. A Kyverno ClusterPolicy (keycloak-client-config-cloner) clones it to the keycloak namespace
  3. The Client Registrar CronJob picks it up within 2 minutes:
    • Registers (or updates) the client in Keycloak
    • Fetches the auto-generated client secret
    • Creates a credential Secret in your app's namespace
    • Annotates the config Secret with sync status

Step 1: Create the Config Secret

Deploy this Secret in your application's namespace (e.g., as part of your Helm chart or Kustomize overlay):

apiVersion: v1
kind: Secret
metadata:
  name: keycloak-client-myapp
  namespace: myapp
  labels:
    keycloak.forteapps.net/client-config: "true"
stringData:
  client.json: |
    {
      "clientId": "myapp",
      "name": "My Application",
      "redirectUris": ["https://myapp.forteapps.net/*"],
      "webOrigins": ["https://myapp.forteapps.net"],
      "defaultClientScopes": ["openid", "email", "profile"],
      "protocolMappers": [],
      "secret": {
        "namespace": "myapp",
        "name": "myapp-oidc-credentials",
        "keys": { "clientId": "client-id", "clientSecret": "client-secret" }
      }
    }

client.json fields:

Field Required Description
clientId Yes Keycloak client ID (must be unique in realm)
name Yes Display name in Keycloak UI
redirectUris Yes Allowed OAuth redirect URLs (supports wildcards like /*)
webOrigins Yes Allowed CORS origins
defaultClientScopes No OIDC scopes (default: ["openid", "email", "profile"])
protocolMappers No Custom claim mappers for tokens (see examples below)
secret.namespace No Target namespace for credentials (default: source-namespace annotation value)
secret.name No Credential Secret name (default: <clientId>-oidc-credentials)
secret.keys.clientId No Key name for client ID (default: client-id)
secret.keys.clientSecret No Key name for client secret (default: client-secret)

Protocol Mappers Example:

"protocolMappers": [
  {
    "name": "groups",
    "protocol": "openid-connect",
    "protocolMapper": "oidc-group-membership-mapper",
    "config": {
      "claim.name": "groups",
      "full.path": "false",
      "id.token.claim": "true",
      "access.token.claim": "true",
      "userinfo.token.claim": "true"
    }
  }
]

Step 2: Reference the Credential Secret

In your application's deployment config, reference the credential Secret that the registrar creates:

env:
- name: OIDC_CLIENT_ID
  valueFrom:
    secretKeyRef:
      name: myapp-oidc-credentials
      key: client-id
- name: OIDC_CLIENT_SECRET
  valueFrom:
    secretKeyRef:
      name: myapp-oidc-credentials
      key: client-secret

Step 3: Deploy and Wait

Commit and push your changes. The credential Secret will appear within 2 minutes:

# Watch for the credential Secret to be created
kubectl get secret myapp-oidc-credentials -n myapp -w

# Check registrar logs
kubectl logs -n keycloak job/$(kubectl get jobs -n keycloak --sort-by=.metadata.creationTimestamp -o jsonpath='{.items[-1].metadata.name}')

# Check sync status on the config Secret
kubectl get secret keycloak-client-myapp -n keycloak -o jsonpath='{.metadata.annotations}'

Change Detection

The registrar computes a SHA-256 hash of client.json and stores it as an annotation. On subsequent runs, it skips processing if:

  • The hash hasn't changed, AND
  • The credential Secret already exists in the target namespace

To force a re-sync, update any field in client.json (e.g., add a trailing space to name).

Legacy Method: Realm JSON

Existing clients (like Gitea) are defined directly in forte-realm.json inside keycloak-values.yaml. The registrar syncs their secrets via client attributes.

Step 1: Add Client to Realm Config

In infra/values/base/keycloak-values.yaml, add a new entry to the clients array in forte-realm.json:

{
  "clientId": "myapp",
  "name": "My Application",
  "enabled": true,
  "protocol": "openid-connect",
  "clientAuthenticatorType": "client-secret",
  "standardFlowEnabled": true,
  "directAccessGrantsEnabled": false,
  "publicClient": false,
  "redirectUris": ["https://myapp.forteapps.net/*"],
  "webOrigins": ["https://myapp.forteapps.net"],
  "defaultClientScopes": ["openid", "email", "profile"],
  "attributes": {
    "k8s.secret.sync": "true",
    "k8s.secret.namespace": "myapp",
    "k8s.secret.name": "myapp-oidc-credentials",
    "k8s.secret.client-id-key": "key",
    "k8s.secret.client-secret-key": "secret"
  }
}

Important:

  • Do NOT include a "secret" field — Keycloak generates one automatically
  • The attributes block tells the registrar where to create the K8s Secret
  • Set client-id-key / client-secret-key to match what the consuming app expects (defaults: client-id / client-secret)

Step 2: Reference the Secret in Your Application

existingSecret: myapp-oidc-credentials

Step 3: Commit and Push

cd ~/dev/k8s/launchpad
git add infra/values/base/keycloak-values.yaml
git commit -m "Add myapp Keycloak client with auto-sync"
git push

ArgoCD will sync the Keycloak config, and the registrar CronJob will pick up the new client within 2 minutes.

Legacy Sync Attribute Reference

Attribute Required Default Description
k8s.secret.sync Yes — Set to "true" to enable syncing
k8s.secret.namespace Yes — Target K8s namespace for the secret
k8s.secret.name Yes — Name of the K8s Secret to create
k8s.secret.client-id-key No client-id Field name for the client ID in the K8s Secret
k8s.secret.client-secret-key No client-secret Field name for the client secret in the K8s Secret

Public CLI Client (Device-Code Login)

forte-cli is a shared public client (no secret) with the RFC 8628 device-authorization grant enabled (oauth2.device.authorization.grant.enabled: "true", standardFlowEnabled: false, directAccessGrantsEnabled: false). Downloaded skills and CLI tools that log in through the Auth Sidecar (forte-drop first) use it with <PREFIX>_CLIENT_ID=forte-cli; nothing per-tool needs to be registered in Keycloak.

It must be defined in forte-realm.json (this legacy path): the self-service registrar hardcodes publicClient: false / standardFlowEnabled: true and drops attributes, so a client-config Secret cannot produce a public device-code client. It carries no k8s.secret.sync attribute (the registrar's secret sync skips it) and is listed in the cleanup CronJob's protected clients.

Retrieving Secrets for External Deployments

The registrar always writes a central copy of every synced secret to the secrets namespace, in addition to the target namespace. This allows operators to retrieve client credentials for applications deployed outside this cluster:

# View the central copy
kubectl get secret gitea-oidc-credentials -n secrets -o yaml

# Extract the client secret for use elsewhere
kubectl get secret myapp-oidc-credentials -n secrets \
  -o jsonpath='{.data.client-secret}' | base64 -d

Registrar Behavior Notes

  • The registrar runs as a CronJob every 2 minutes (concurrencyPolicy: Forbid)
  • If the target namespace doesn't exist, the target write is skipped with a warning (the central copy still happens)
  • A central copy is always written to the secrets namespace for every synced client
  • The registrar uses the keycloak-credentials secret for admin authentication
  • Created secrets have the label app.kubernetes.io/managed-by: keycloak-client-registrar

Troubleshooting

Application Not Deploying

Problem: Application stuck in "Syncing" state

Check ArgoCD status:

kubectl get application myapp -n argocd -o yaml

Look for errors in status.conditions.

Common causes:

  • ❌ Image doesn't exist or is not accessible
  • ❌ Invalid YAML syntax
  • ❌ Resource quota exceeded
  • ❌ Namespace conflicts
  • ❌ Invalid Helm values

Solutions:

# Check image exists
docker pull ghcr.io/fortedigital/myapp:v1.0.0

# Validate YAML syntax
kubectl apply --dry-run=client -f apps/myapp.yaml

# Check ArgoCD logs
kubectl logs -n argocd deployment/argocd-application-controller | grep myapp

Problem: Pods crashing (CrashLoopBackOff)

Check pod logs:

kubectl get pods -n myapp
kubectl logs -n myapp <pod-name>
kubectl describe pod -n myapp <pod-name>

Common causes:

  • ❌ Application error (check logs)
  • ❌ Missing environment variables
  • ❌ Incorrect port configuration
  • ❌ Missing secrets
  • ❌ Insufficient resources

Solutions:

# Check environment variables
kubectl exec -n myapp <pod-name> -- env

# Check if secrets exist
kubectl get secrets -n myapp

# Increase resources in helm-prod-values
vim ~/dev/k8s/helm-prod-values/myapp/values.yaml

Problem: Application not accessible via domain

Check ingress:

kubectl get ingressroute -n myapp
kubectl describe ingressroute myapp -n myapp

Common causes:

  • ❌ DNS not configured
  • ❌ TLS certificate not issued
  • ❌ Incorrect domain in values.yaml
  • ❌ Traefik not routing correctly

Solutions:

# Check certificate
kubectl get certificate -n myapp

# Check cert-manager logs
kubectl logs -n cert-manager deployment/cert-manager

# Verify domain configuration
cat ~/dev/k8s/helm-prod-values/myapp/values.yaml | grep host

# Test with port-forward
kubectl port-forward -n myapp service/myapp 8080:3000
curl http://localhost:8080

Secret Issues

Problem: Secret not found

Check if SealedSecret exists:

kubectl get sealedsecret -n myapp
kubectl get secret -n myapp

Solutions:

# Check if secret is in Git
ls -l secrets/myapp-credentials-sealed.yaml

# Re-apply sealed secret
kubectl apply -f secrets/myapp-credentials-sealed.yaml

# Check sealed-secrets-controller logs
kubectl logs -n kube-system deployment/sealed-secrets-controller

Problem: Secret exists but pods can't access it

Check pod events:

kubectl describe pod -n myapp <pod-name>

Look for: Error: secret "myapp-credentials" not found

Solutions:

# Verify secret name in values.yaml matches actual secret
cat ~/dev/k8s/helm-prod-values/myapp/values.yaml | grep envSecretName
kubectl get secrets -n myapp

# Restart pods
kubectl rollout restart deployment myapp -n myapp

Sync Failures

Problem: ArgoCD shows "Out of Sync"

Manual sync:

# Using kubectl
kubectl patch application myapp -n argocd --type merge -p '{"operation":{"initiatedBy":{"username":"admin"},"sync":{"syncStrategy":{"hook":{}}}}}'

# Or via ArgoCD UI
# Click "Sync" button in UI

Check what's different:

kubectl get application myapp -n argocd -o yaml

Look at status.sync.comparedTo vs desired state.

Problem: Sync succeeds but application is "Degraded"

Check resource health:

kubectl get application myapp -n argocd -o jsonpath='{.status.resources[*].health}'

Common causes:

  • ❌ Pods not ready
  • ❌ Deployments not at desired replica count
  • ❌ Jobs failed

Solutions:

# Check all resources in namespace
kubectl get all -n myapp

# Check pod events
kubectl get events -n myapp --sort-by='.lastTimestamp'

Getting Help

If you're stuck:

  1. Check Slack notifications - Error details are often in sync failure messages
  2. Check ArgoCD UI - Visual representation of what's wrong
  3. Ask platform team - They have full cluster access and can debug further
  4. Check documentation - Operations Runbook has more troubleshooting

Best Practices

Development Workflow

✅ DO:

  • Develop and test locally with Docker Compose
  • Use semantic versioning for releases
  • Write descriptive commit messages
  • Test changes in a separate namespace first (if possible)
  • Monitor Slack for deployment notifications
  • Document environment variables and configuration

❌ DON'T:

  • Push directly to production without testing
  • Use latest tag for Docker images
  • Bypass CI/CD for "quick fixes"
  • Hard-code configuration values
  • Ignore deployment failures

Configuration Management

✅ DO:

  • Keep configuration in helm-prod-values repository
  • Use environment variables for config
  • Document what each value does
  • Use reasonable resource limits
  • Enable ingress and TLS for public services

❌ DON'T:

  • Hard-code config in application code
  • Over-allocate resources (wastes money)
  • Under-allocate resources (causes crashes)
  • Use HTTP for production services

Secret Management

✅ DO:

  • Use kubeseal for all secrets
  • Store plain secrets in password manager
  • Rotate secrets regularly
  • Use different secrets per environment
  • Document what each secret contains

❌ DON'T:

  • Commit plain secrets
  • Share secrets in Slack/email
  • Reuse secrets across apps
  • Log secrets in application code

Git Workflow

✅ DO:

  • Use feature branches for changes
  • Write clear commit messages
  • Use pull requests for review
  • Keep commits atomic and focused
  • Tag releases in application repos

❌ DON'T:

  • Push directly to main without review (for config repos)
  • Make multiple unrelated changes in one commit
  • Use vague commit messages ("fix", "update")
  • Force-push to main branches

Quick Reference

Common Commands

# Check application status
kubectl get application myapp -n argocd

# View application details
kubectl describe application myapp -n argocd

# Check pods
kubectl get pods -n myapp

# View pod logs
kubectl logs -n myapp <pod-name>

# Restart deployment
kubectl rollout restart deployment myapp -n myapp

# Port-forward to service
kubectl port-forward -n myapp service/myapp 8080:3000

# Create secret
kubectl create secret generic myapp-credentials \
  --from-literal=KEY=value \
  --dry-run=client -o yaml > private/myapp-credentials.yaml

# Seal secret
kubeseal --format=yaml \
  --cert=pub-cert.pem \
  < private/myapp-credentials.yaml \
  > secrets/myapp-credentials-sealed.yaml

Repository Locations

# Config repository
cd ~/dev/k8s/launchpad

# Helm values repository
cd ~/dev/k8s/helm-prod-values

# Helm charts repository
cd ~/dev/k8s/forte-helm

File Paths

# New application manifest
~/dev/k8s/launchpad/apps/myapp.yaml

# Application values
~/dev/k8s/helm-prod-values/myapp/values.yaml

# Sealed secrets
~/dev/k8s/launchpad/secrets/myapp-credentials-sealed.yaml

# Plain secrets (local only)
~/dev/k8s/launchpad/private/myapp-credentials.yaml

Next Steps

Now that you understand the basics:

  1. ✅ Deploy your first application (follow steps above)
  2. 📖 Read the Operations Runbook for common tasks
  3. 📖 Review Technical Reference for detailed component docs
  4. 📖 Understand GitOps Architecture for the big picture
  5. 🚀 Start contributing!

Questions?

Last Updated: 2026-04-16