commitc5e0aa6f3cAuthor: gitea_admin <admin@forteapps.net> Date: Wed Oct 7 06:36:01 2026 +0000 chore(deps): update nikitafilonov/ai-review docker tag to v1.4.0 (#59) This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | nikitafilonov/ai-review | docker | minor | `v1.1.0` → `v1.4.0` | --- ### Configuration 📅 **Schedule**: (in timezone Europe/Oslo) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==--> --------- Co-authored-by: Renovate Bot <renovate@forteapps.net> Reviewed-on: #59 Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com> Co-authored-by: gitea_admin <admin@forteapps.net> commit7915346868Author: gitea_admin <admin@forteapps.net> Date: Sun Oct 4 21:53:01 2026 +0000 chore(deps): update gitea/gitea docker tag to v28 (#58) This PR contains the following updates: | Package | Update | Change | |---|---|---| | [gitea/gitea](https://github.com/go-gitea/gitea) | major | `1.27.3` → `28.0.0` | --- ### Release Notes <details> <summary>go-gitea/gitea (gitea/gitea)</summary> ### [`v28.0.0`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#2800---2026-09-30) [Compare Source](https://github.com/go-gitea/gitea/compare/v1.27.3...v28.0.0) - BREAKING - Fix(git)!: route Git network operations through an internal proxy and update egress settings ([#​39426](https://github.com/go-gitea/gitea/pull/39426)) - Feat(actions)!: add RUN\_RETENTION\_DAYS to delete old action runs ([#​38855](https://github.com/go-gitea/gitea/pull/38855)) - SECURITY - Fix(git): reject invalid and duplicate Git objects on push ([#​39472](https://github.com/go-gitea/gitea/pull/39472)) - Fix(git)!: route Git network operations through an internal proxy and update egress settings ([#​39426](https://github.com/go-gitea/gitea/pull/39426)) - Fix(ssh): identify presented public keys by fingerprint ([#​39423](https://github.com/go-gitea/gitea/pull/39423)) - Fix(actions): keep cancelled and unapproved fork PR runs behind the approval gate ([#​39399](https://github.com/go-gitea/gitea/pull/39399)) - Fix(deps): update golang.org/x/crypto SSH to address denial of service ([#​39219](https://github.com/go-gitea/gitea/pull/39219)) - Fix(repo): enforce repository-scoped authorization for team access, deletion, and package unlinking ([#​39063](https://github.com/go-gitea/gitea/pull/39063)) - FEATURES - Feat(actions): update actionslib, support `self:`, misc fixes ([#​39358](https://github.com/go-gitea/gitea/pull/39358)) - Feat(api): list all packages for site administrators ([#​38968](https://github.com/go-gitea/gitea/pull/38968)) - Feat: manage bot accounts from the admin UI, API and CLI ([#​38966](https://github.com/go-gitea/gitea/pull/38966)) - Feat(user): Personal access tokens can be regenerated ([#​38907](https://github.com/go-gitea/gitea/pull/38907)) - Feat(actions): support `$/` prefix in reusable workflow `uses:` ([#​38822](https://github.com/go-gitea/gitea/pull/38822)) - Feat(actions): add force-cancel workflow run API ([#​38756](https://github.com/go-gitea/gitea/pull/38756)) - Feat(licenses): support REUSE specification in licenses ([#​38720](https://github.com/go-gitea/gitea/pull/38720)) - Feat(api): add project APIs ([#​38691](https://github.com/go-gitea/gitea/pull/38691)) - Feat(webhook): fire repository event on repo rename ([#​38641](https://github.com/go-gitea/gitea/pull/38641)) - Feat: admin impersonates a user ([#​38614](https://github.com/go-gitea/gitea/pull/38614)) - Feat(actions): add build queue view ([#​38585](https://github.com/go-gitea/gitea/pull/38585)) - Feat(setting): add shared \[redis] section as default for redis-backed subsystems ([#​38550](https://github.com/go-gitea/gitea/pull/38550)) - Feat(repo): prioritize well-known READMEs and optimize discovery ([#​38532](https://github.com/go-gitea/gitea/pull/38532)) - Feat(actions): implement adaptive auto-refresh for workflow runs list ([#​38329](https://github.com/go-gitea/gitea/pull/38329)) - Feat(auth): add `disable-2fa` command ([#​38275](https://github.com/go-gitea/gitea/pull/38275)) - Feat: Add audit logging ([#​38189](https://github.com/go-gitea/gitea/pull/38189)) - Feat(repo): add quick repository switcher to repo header ([#​38188](https://github.com/go-gitea/gitea/pull/38188)) - Feat(repo): support file exclusion logic in .gitea/template in template generation ([#​38064](https://github.com/go-gitea/gitea/pull/38064)) - Feat(web): Add org removal functionality to admin user details page ([#​38013](https://github.com/go-gitea/gitea/pull/38013)) - Feat: add watch options ([#​37571](https://github.com/go-gitea/gitea/pull/37571)) - Feat: add deploy tokens ([#​37306](https://github.com/go-gitea/gitea/pull/37306)) - Feat(diff): Add search and extension filter to diff sidebar ([#​37068](https://github.com/go-gitea/gitea/pull/37068)) - Feat: Replace SSE with WebSocket for UI notifications ([#​36965](https://github.com/go-gitea/gitea/pull/36965)) - Feat(actions): Add artifact preview in Actions run view ([#​36754](https://github.com/go-gitea/gitea/pull/36754)) - Feat(packages): add support for uploading helm provenance files ([#​36695](https://github.com/go-gitea/gitea/pull/36695)) - Feat: Add support for dynamic matrix evaluation in Gitea Actions workflows ([#​36564](https://github.com/go-gitea/gitea/pull/36564)) - Feat: Add max-parallel Support for Gitea Actions ([#​36357](https://github.com/go-gitea/gitea/pull/36357)) - Feat(actions): Add Actions API endpoints for workflow run management and logs ([#​35382](https://github.com/go-gitea/gitea/pull/35382)) - Feat: Add block on pending codeowner reviews branch protection ([#​34995](https://github.com/go-gitea/gitea/pull/34995)) - ENHANCEMENTS - Enhance: allow auto-closing PRs from PRs ([#​39393](https://github.com/go-gitea/gitea/pull/39393)) - Enhance(actions): add pending job status and align job statuses with GitHub ([#​39376](https://github.com/go-gitea/gitea/pull/39376)) - Enhance(acme): add configurable ACME profile ([#​39375](https://github.com/go-gitea/gitea/pull/39375)) - Enhance(emoji): update to Unicode 17, unify and lazy-load emoji data ([#​39363](https://github.com/go-gitea/gitea/pull/39363)) - Enhance: improve issue-pattern capture groups and support both internal\&external trackers enabled ([#​39354](https://github.com/go-gitea/gitea/pull/39354)) - Enhance: update mermaid to v12 ([#​39331](https://github.com/go-gitea/gitea/pull/39331)) - Enhance(notifications): mark current notification page as read ([#​39294](https://github.com/go-gitea/gitea/pull/39294)) - Enhance: support `ETag` on streamed repository archives, support `If-None-Match: *` ([#​39289](https://github.com/go-gitea/gitea/pull/39289)) - Enhance: truncate but show long lines in diffs ([#​39279](https://github.com/go-gitea/gitea/pull/39279)) - Enhance(packages): implement npm single-version API and add per-version repository ([#​39267](https://github.com/go-gitea/gitea/pull/39267)) - Enhance: move window\.config to JSON, improve CSP format ([#​39236](https://github.com/go-gitea/gitea/pull/39236)) - Enhance: improve commit page header ([#​39229](https://github.com/go-gitea/gitea/pull/39229)) - Enhance: Improve validation errors for secrets/variables ([#​39221](https://github.com/go-gitea/gitea/pull/39221)) - Enhance(repo): check full repo name for dangerous operations ([#​39213](https://github.com/go-gitea/gitea/pull/39213)) - Enhance(web): hide attachment dropzone on preview tab in combo editor ([#​39204](https://github.com/go-gitea/gitea/pull/39204)) - Enhance(web): show attachment URL and UUID in dropzone preview ([#​39203](https://github.com/go-gitea/gitea/pull/39203)) - Enhance(actions): make workflow dispatch choice dropdown support search ([#​39154](https://github.com/go-gitea/gitea/pull/39154)) - Enhance(repo): unify diff stats on commit pages, misc diff tweaks ([#​39134](https://github.com/go-gitea/gitea/pull/39134)) - Enhance: use browser's locale to detect week's first day for the contribution map ([#​38995](https://github.com/go-gitea/gitea/pull/38995)) - Enhance(ui): forced colors mode enhancements ([#​38991](https://github.com/go-gitea/gitea/pull/38991)) - Enhance: user-friendly packages setup manual ([#​38946](https://github.com/go-gitea/gitea/pull/38946)) - Enhance: inherit team access for all units ([#​38938](https://github.com/go-gitea/gitea/pull/38938)) - Enhance(admin): show impersonation banner and keep password change with the user ([#​38924](https://github.com/go-gitea/gitea/pull/38924)) - Enhance(ui): tint toast backgrounds by level ([#​38919](https://github.com/go-gitea/gitea/pull/38919)) - Enhance(repo): add default object format setting ([#​38877](https://github.com/go-gitea/gitea/pull/38877)) - Enhance(actions): set ref\_protected in context ([#​38852](https://github.com/go-gitea/gitea/pull/38852)) - Enhance(ui): restyle toasts ([#​38842](https://github.com/go-gitea/gitea/pull/38842)) - Enhance: refine repo watching ([#​38835](https://github.com/go-gitea/gitea/pull/38835)) - Enhance: fall back to DEFAULT\_TEMPLATE.md when style-specific template is missing ([#​38803](https://github.com/go-gitea/gitea/pull/38803)) - Enhance(api): add GitHub-compatible /repos/{owner}/{repo}/commits/{ref} endpoint ([#​38770](https://github.com/go-gitea/gitea/pull/38770)) - Enhance(api): expose file mode in contents API response ([#​38713](https://github.com/go-gitea/gitea/pull/38713)) - Enhance(tls): use go's tls defaults ([#​38687](https://github.com/go-gitea/gitea/pull/38687)) - Enhance(ui): improve luminance calculations ([#​38682](https://github.com/go-gitea/gitea/pull/38682)) - Enhance(api): add `tag_filter` query parameter to release list API ([#​38681](https://github.com/go-gitea/gitea/pull/38681)) - Enhance(actions): replace `ansi_up` with first-party code ([#​38619](https://github.com/go-gitea/gitea/pull/38619)) - Enhance: keep status check list scrolled on merge box reload ([#​38597](https://github.com/go-gitea/gitea/pull/38597)) - Enhance(actions): action view enhancements ([#​38594](https://github.com/go-gitea/gitea/pull/38594)) - Enhance(ui): tweak tooltip style and misc fixes ([#​38524](https://github.com/go-gitea/gitea/pull/38524)) - Enhance: improve e-mail templates ([#​38396](https://github.com/go-gitea/gitea/pull/38396)) - Enhance(webhook): add reviewer name to MS Teams review request notifications ([#​38289](https://github.com/go-gitea/gitea/pull/38289)) - Enhance: extend <video> tag allowed attributes ([#​38279](https://github.com/go-gitea/gitea/pull/38279)) - Enhance(packages/npm): expand version metadata and support npm deprecate ([#​37890](https://github.com/go-gitea/gitea/pull/37890)) - PERFORMANCE - Perf(references): scan only the keyword window before a reference ([#​39396](https://github.com/go-gitea/gitea/pull/39396)) - Perf(frontend): enable vite module preload ([#​39332](https://github.com/go-gitea/gitea/pull/39332)) - Perf(gitdiff): optimize inline diff highlighting using cache ([#​38706](https://github.com/go-gitea/gitea/pull/38706)) - BUGFIXES - Fix(actions): preserve admitted jobs and runs in their concurrency group ([#​39461](https://github.com/go-gitea/gitea/pull/39461)) - Fix(api): commit tree SHA is the commit ID ([#​39449](https://github.com/go-gitea/gitea/pull/39449)) - Fix: PR merge ([#​39442](https://github.com/go-gitea/gitea/pull/39442)) - Fix(actions): evaluate job-level `if:` before concurrency check ([#​39437](https://github.com/go-gitea/gitea/pull/39437)) - Fix(api): allow pending-inline-comment-only reviews ([#​39433](https://github.com/go-gitea/gitea/pull/39433)) - Fix: sanitize external render command line arguments ([#​39417](https://github.com/go-gitea/gitea/pull/39417)) - Fix(LFS): recalculate repo LFSSize after gc-lfs removes orphaned data ([#​39406](https://github.com/go-gitea/gitea/pull/39406)) - Fix(indexer): index full file paths and real offsets in bleve ([#​39405](https://github.com/go-gitea/gitea/pull/39405)) - Fix(git): keep leading dashes in git grep search patterns ([#​39404](https://github.com/go-gitea/gitea/pull/39404)) - Fix: use clearer message for ldap auth failure ([#​39392](https://github.com/go-gitea/gitea/pull/39392)) - Fix(repo): commit page fails to render unsigned commits with a different committer ([#​39381](https://github.com/go-gitea/gitea/pull/39381)) - Fix: focus confirm button and use red for delete confirmations ([#​39350](https://github.com/go-gitea/gitea/pull/39350)) - Fix(migrations): preserve SHA-256 pull request commit IDs ([#​39343](https://github.com/go-gitea/gitea/pull/39343)) - Fix(ui): misc ui fixes ([#​39336](https://github.com/go-gitea/gitea/pull/39336)) - Fix(actions): use gitea's clock for actions durations ([#​39323](https://github.com/go-gitea/gitea/pull/39323)) - Fix(actions): never show negative running durations ([#​39322](https://github.com/go-gitea/gitea/pull/39322)) - Fix: package registry keypair creation race ([#​39319](https://github.com/go-gitea/gitea/pull/39319)) - Fix: add default timeout and handle errors for HaveIBeenPwned API ([#​39316](https://github.com/go-gitea/gitea/pull/39316)) - Fix(user): unify email validation for registration and settings ([#​39304](https://github.com/go-gitea/gitea/pull/39304)) - Fix(ui): use button elements for branch and tag dropdown tabs ([#​39285](https://github.com/go-gitea/gitea/pull/39285)) - Fix(auth): fix ssh and gpg key verification on windows ([#​39283](https://github.com/go-gitea/gitea/pull/39283)) - Fix(feed): use meaningful lines as comment excerpt ([#​39276](https://github.com/go-gitea/gitea/pull/39276)) - Fix(projects): allow max columns to the limit ([#​39272](https://github.com/go-gitea/gitea/pull/39272)) - Fix: pass merge commit messages to git via stdin ([#​39269](https://github.com/go-gitea/gitea/pull/39269)) - Fix(repo): surface unrelated histories on Sync Fork ([#​39258](https://github.com/go-gitea/gitea/pull/39258)) - Fix: avoid nil panic and refactor some trivial problems ([#​39251](https://github.com/go-gitea/gitea/pull/39251)) - Fix: restore missing blob file when re-publishing a package ([#​39239](https://github.com/go-gitea/gitea/pull/39239)) - Fix(automerge): validate head commit before merge ([#​39235](https://github.com/go-gitea/gitea/pull/39235)) - Fix(httplib): prevent leaking localhost:3000 in public links ([#​39217](https://github.com/go-gitea/gitea/pull/39217)) - Fix(setting): honor bare -1 for timeout settings ([#​39181](https://github.com/go-gitea/gitea/pull/39181)) - Fix: correct repo/attatchment absolute url and release layout ([#​39178](https://github.com/go-gitea/gitea/pull/39178)) - Fix(web): populate the reason for "cannot commit to branch" in web editor commit form ([#​39155](https://github.com/go-gitea/gitea/pull/39155)) - Fix(process): reap entire process group on cmd.Cancel ([#​39143](https://github.com/go-gitea/gitea/pull/39143)) - Fix: recognize linguist language aliases ([#​39135](https://github.com/go-gitea/gitea/pull/39135)) - Fix(repo): preserve transfer recipient collaboration ([#​39042](https://github.com/go-gitea/gitea/pull/39042)) - Fix(db): make paginated database reads always require "order" option ([#​39017](https://github.com/go-gitea/gitea/pull/39017)) - Fix: make local queue PopItem can be notified ([#​39011](https://github.com/go-gitea/gitea/pull/39011)) - Fix: classify git failures on stderr, restrict migration failure detail ([#​39010](https://github.com/go-gitea/gitea/pull/39010)) - Fix: allow re-requesting uncounted review approvals ([#​38988](https://github.com/go-gitea/gitea/pull/38988)) - Fix(actions): allow larger scheduled workflows ([#​38985](https://github.com/go-gitea/gitea/pull/38985)) - Fix: resolve actions commit status permission per repository ([#​38977](https://github.com/go-gitea/gitea/pull/38977)) - Fix(deps): update module golang.org/x/image to v0.45.0 \[security] ([#​38930](https://github.com/go-gitea/gitea/pull/38930)) - Fix(deps): update module golang.org/x/mod to v0.40.0 \[security] ([#​38914](https://github.com/go-gitea/gitea/pull/38914)) - Fix: dedupe issue cross-reference timeline entries ([#​38881](https://github.com/go-gitea/gitea/pull/38881)) - Fix(server): set `ReadHeaderTimeout` on HTTP servers ([#​38878](https://github.com/go-gitea/gitea/pull/38878)) - Fix(repo): avoid a repo-sized temp file for every bundle download ([#​38863](https://github.com/go-gitea/gitea/pull/38863)) - Fix(lfs): ensure lock listing paginates with a total order ([#​38850](https://github.com/go-gitea/gitea/pull/38850)) - Fix(avatar): use sha256 and inline the federated avatar lookup ([#​38843](https://github.com/go-gitea/gitea/pull/38843)) - Fix(gitdiff): render exact-limit diffs and zero-limit comments ([#​38838](https://github.com/go-gitea/gitea/pull/38838)) - Fix(deps): update dependency mermaid to v11.16.1 \[security] ([#​38813](https://github.com/go-gitea/gitea/pull/38813)) - Fix: misc fixes in pub/gpg/tests ([#​38809](https://github.com/go-gitea/gitea/pull/38809)) - Fix: git diff blob excerpt ([#​38808](https://github.com/go-gitea/gitea/pull/38808)) - Fix(packages): show error for duplicate cleanup rules [#​37820](https://github.com/go-gitea/gitea/issues/37820) ([#​38786](https://github.com/go-gitea/gitea/pull/38786)) - Fix(actions): fix runner docs link ([#​38783](https://github.com/go-gitea/gitea/pull/38783)) - Fix: git cache ([#​38763](https://github.com/go-gitea/gitea/pull/38763)) - Fix(actions): evaluate each `${{ }}` part on its own ([#​38754](https://github.com/go-gitea/gitea/pull/38754)) - Fix: don't report failed network requests as JavaScript errors ([#​38732](https://github.com/go-gitea/gitea/pull/38732)) - Fix(gitdiff): prevent index out of range panic in GetLineTypeMarker ([#​38728](https://github.com/go-gitea/gitea/pull/38728)) - Fix(api): document X-Total-Count instead of non-existent X-Total header ([#​38717](https://github.com/go-gitea/gitea/pull/38717)) - Fix(actions): dynamic matrix expansion correctness fixes ([#​38690](https://github.com/go-gitea/gitea/pull/38690)) - Fix(auth): record last sign-in on reverse proxy login ([#​38672](https://github.com/go-gitea/gitea/pull/38672)) - Fix(api): accept fully-qualified refs in contents API ([#​38650](https://github.com/go-gitea/gitea/pull/38650)) - Fix(deps): update module github.com/getkin/kin-openapi to v0.144.0 \[security] ([#​38623](https://github.com/go-gitea/gitea/pull/38623)) - Fix(deps): update dependency js-yaml to v5.2.2 \[security] ([#​38622](https://github.com/go-gitea/gitea/pull/38622)) - Fix: abort superseded issue suggestion requests ([#​38620](https://github.com/go-gitea/gitea/pull/38620)) - Fix(issue): display error toast on batch action failures instead of reloading page ([#​38593](https://github.com/go-gitea/gitea/pull/38593)) - Fix(deps): update module google.golang.org/grpc to v1.82.1 \[security] ([#​38567](https://github.com/go-gitea/gitea/pull/38567)) - Fix(deps): update module github.com/google/go-github/v88 to v89 ([#​38433](https://github.com/go-gitea/gitea/pull/38433)) - Fix(deps): update go dependencies ([#​38429](https://github.com/go-gitea/gitea/pull/38429)) - Fix(deps): update go dependencies ([#​38346](https://github.com/go-gitea/gitea/pull/38346)) - Fix(deps): update npm dependencies ([#​38342](https://github.com/go-gitea/gitea/pull/38342)) - Fix(base): correct natural sort of numbers with leading zeros ([#​38163](https://github.com/go-gitea/gitea/pull/38163)) - Fix(ui): avoid layout shifts in `overflow-menu` and repo filter ([#​37818](https://github.com/go-gitea/gitea/pull/37818)) - Fix: make auth source group sync correctly handle team removal ([#​37161](https://github.com/go-gitea/gitea/pull/37161)) - Fix(release): separate publication time from the release date ([#​36761](https://github.com/go-gitea/gitea/pull/36761)) - TESTING - Test: stop tests from writing into `~/.ssh` ([#​39348](https://github.com/go-gitea/gitea/pull/39348)) - Test(e2e): log out to switch users in pr-review test ([#​39328](https://github.com/go-gitea/gitea/pull/39328)) - Test: release fixtures loader lock before database work ([#​39263](https://github.com/go-gitea/gitea/pull/39263)) - Test: speed up tests, fix transaction bug ([#​39030](https://github.com/go-gitea/gitea/pull/39030)) - Test: run frontend unit tests in browsers ([#​38860](https://github.com/go-gitea/gitea/pull/38860)) - Test(pubsub): stop racing the Redis SUBSCRIBE ack ([#​38661](https://github.com/go-gitea/gitea/pull/38661)) - Test(e2e): add pull request merge box test, update AGENTS.md ([#​38576](https://github.com/go-gitea/gitea/pull/38576)) - Test(e2e): deterministically wait for event stream in logout propagation test ([#​38535](https://github.com/go-gitea/gitea/pull/38535)) - BUILD - Refactor: fix `go vet` errors related to composite literals ([#​39341](https://github.com/go-gitea/gitea/pull/39341)) - Build(gogit): disable gogit builds for stable releases ([#​39324](https://github.com/go-gitea/gitea/pull/39324)) - Refactor: replace jquery.are-you-sure with first-party code ([#​39233](https://github.com/go-gitea/gitea/pull/39233)) - Refactor: http request binding ([#​38971](https://github.com/go-gitea/gitea/pull/38971)) - Refactor: clean up git repo and model migration packages ([#​38564](https://github.com/go-gitea/gitea/pull/38564)) - Refactor: prepare to decouple the "model migration" package and "models" package ([#​38533](https://github.com/go-gitea/gitea/pull/38533)) - Build: fix snapcraft release ([#​38260](https://github.com/go-gitea/gitea/pull/38260)) - Build(release): use native golang toolchain for official release builds ([#​37828](https://github.com/go-gitea/gitea/pull/37828)) - DOCS - Docs(webhook): review\.type comment lists values the webhook never sends ([#​39451](https://github.com/go-gitea/gitea/pull/39451)) - Docs(api): document verification and files on the compare endpoint ([#​39440](https://github.com/go-gitea/gitea/pull/39440)) - Docs(api): name the unadopted-repository search parameter query ([#​39370](https://github.com/go-gitea/gitea/pull/39370)) - Docs: remove unused COOKIE\_USERNAME from app.example.ini ([#​39365](https://github.com/go-gitea/gitea/pull/39365)) - Docs: document NOTICE\_ON\_SUCCESS for every cron task ([#​39352](https://github.com/go-gitea/gitea/pull/39352)) - Docs: correct ALLOW\_LOCALNETWORKS description in app.example.ini ([#​39240](https://github.com/go-gitea/gitea/pull/39240)) - Docs: fix typo in README about app.ini restart ([#​39223](https://github.com/go-gitea/gitea/pull/39223)) - Docs: fix dead localization doc link in the READMEs ([#​39211](https://github.com/go-gitea/gitea/pull/39211)) - Docs: Update CHANGELOG for release 1.27.3 ([#​39170](https://github.com/go-gitea/gitea/pull/39170)) - Docs: Update CHANGELOG for version 1.27.2 ([#​38923](https://github.com/go-gitea/gitea/pull/38923)) - Docs: Update PGP key expiration date to July 23, 2027 ([#​38747](https://github.com/go-gitea/gitea/pull/38747)) - Docs(api): document 401/403 responses for user key endpoints ([#​38711](https://github.com/go-gitea/gitea/pull/38711)) - Docs: Update Changelog for release v1.27.1 ([#​38670](https://github.com/go-gitea/gitea/pull/38670)) - Docs: Update Changelog for 1.27 ([#​38440](https://github.com/go-gitea/gitea/pull/38440)) - Docs: Update Security docs ([#​38422](https://github.com/go-gitea/gitea/pull/38422)) - MISC - Refactor: make git http respond error message ([#​39390](https://github.com/go-gitea/gitea/pull/39390)) - Refactor(api): convert bot accounts through the admin user edit endpoint ([#​39355](https://github.com/go-gitea/gitea/pull/39355)) - Refactor: replace AWS SDK with a REST client for CodeCommit migration ([#​39330](https://github.com/go-gitea/gitea/pull/39330)) - Refactor: replace Azure Blob SDK with a REST client ([#​39315](https://github.com/go-gitea/gitea/pull/39315)) - Refactor: npm route handlers ([#​39275](https://github.com/go-gitea/gitea/pull/39275)) - Refactor: GetDiffShortStat and fix panic caused by inconsistent "changed file number" ([#​39248](https://github.com/go-gitea/gitea/pull/39248)) - Refactor(templates): update djlint to 1.46.0 and resolve its new findings ([#​39231](https://github.com/go-gitea/gitea/pull/39231)) - Refactor: pagination/pager ([#​39162](https://github.com/go-gitea/gitea/pull/39162)) - Refactor: share package registry error status classification ([#​39133](https://github.com/go-gitea/gitea/pull/39133)) - Refactor: drop two unmaintained dependencies, rename the byte size helpers ([#​39083](https://github.com/go-gitea/gitea/pull/39083)) - Refactor(automerge): fix error handling, populate recent automerge tasks on restart ([#​39001](https://github.com/go-gitea/gitea/pull/39001)) - Refactor: deploy key and private route handlers ([#​38999](https://github.com/go-gitea/gitea/pull/38999)) - Refactor: wiki edit form ([#​38918](https://github.com/go-gitea/gitea/pull/38918)) - Refactor: clean up form binding & validation ([#​38873](https://github.com/go-gitea/gitea/pull/38873)) - Refactor: markup render ([#​38864](https://github.com/go-gitea/gitea/pull/38864)) - Refactor: api token scope check ([#​38862](https://github.com/go-gitea/gitea/pull/38862)) - Refactor: replace `gliderlabs/ssh` with `golang.org/x/crypto/ssh` ([#​38837](https://github.com/go-gitea/gitea/pull/38837)) - Refactor: form binding validation ([#​38832](https://github.com/go-gitea/gitea/pull/38832)) - Refactor: prepare vue components for vapor mode ([#​38798](https://github.com/go-gitea/gitea/pull/38798)) - Refactor: use the shared workflow model from actionslib ([#​38768](https://github.com/go-gitea/gitea/pull/38768)) - Refactor(modelmigration): thread context through migration functions ([#​38758](https://github.com/go-gitea/gitea/pull/38758)) - Refactor: migrate remaining Vue components to `<script setup>` ([#​38752](https://github.com/go-gitea/gitea/pull/38752)) - Refactor: introduce trString for frontend ([#​38741](https://github.com/go-gitea/gitea/pull/38741)) - Refactor(diff): drive diff DOM init from the global selector observer ([#​38740](https://github.com/go-gitea/gitea/pull/38740)) - Refactor(git): clarify GetBranch behavior to make it only gets an existing branch ([#​38662](https://github.com/go-gitea/gitea/pull/38662)) - Refactor: replace debounce/throttle deps with first-party code ([#​38610](https://github.com/go-gitea/gitea/pull/38610)) - Refactor: hide git repo path details from more packages ([#​38601](https://github.com/go-gitea/gitea/pull/38601)) - Refactor: retry file remove/rename when a file is busy and clean up os detection ([#​38588](https://github.com/go-gitea/gitea/pull/38588)) - Perf(emoji): optimize FindEmojiSubmatchIndex using slice-based Trie ([#​38573](https://github.com/go-gitea/gitea/pull/38573)) - Refactor: implement mcaptcha client and add comments/tests ([#​38561](https://github.com/go-gitea/gitea/pull/38561)) - Refactor: use WithRepo instead of WithDir for most git operations, clean up model migrations ([#​38555](https://github.com/go-gitea/gitea/pull/38555)) - Refactor: remove Path field from git.Repository ([#​38552](https://github.com/go-gitea/gitea/pull/38552)) - Refactor: make git package handle all git operations ([#​38543](https://github.com/go-gitea/gitea/pull/38543)) - Refactor: remove unnecessary git command wrapper functions ([#​38531](https://github.com/go-gitea/gitea/pull/38531)) - Refactor: git repo and relative path handling ([#​38522](https://github.com/go-gitea/gitea/pull/38522)) - Refactor: clean up fragile diff render templates, use backend typed structs ([#​38517](https://github.com/go-gitea/gitea/pull/38517)) - Refactor: correct git repo design and fix some legacy problems ([#​38512](https://github.com/go-gitea/gitea/pull/38512)) - Refactor: fix legacy problems in cmd/serv.go ([#​38505](https://github.com/go-gitea/gitea/pull/38505)) - Refactor: remove Ctx field from git.Repository ([#​38500](https://github.com/go-gitea/gitea/pull/38500)) - Refactor: decouple git.Repository(ctx) from git.Commit & git.Tree ([#​38464](https://github.com/go-gitea/gitea/pull/38464)) - Refactor: introduce ActivePageTimer to help to do partial page refresh ([#​38372](https://github.com/go-gitea/gitea/pull/38372)) </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Oslo) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==--> --------- Co-authored-by: Renovate Bot <renovate@forteapps.net> Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/58 Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com> Co-authored-by: gitea_admin <admin@forteapps.net> commit840c354ea3Author: gitea_admin <admin@forteapps.net> Date: Sat Oct 3 18:55:31 2026 +0000 chore(deps): update terraform azurerm to v5 (#55) This PR contains the following updates: | Package | Type | Update | Change | Pending | |---|---|---|---|---| | [azurerm](https://registry.terraform.io/providers/hashicorp/azurerm) ([source](https://github.com/hashicorp/terraform-provider-azurerm)) | required_provider | major | `~> 4.0` → `~> 5.0` | `5.8.0` | --- ### Release Notes <details> <summary>hashicorp/terraform-provider-azurerm (azurerm)</summary> ### [`v5.7.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#570-September-24-2026) [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.6.0...v5.7.0) FEATURES: - **New List Resource**: `azurerm_private_dns_resolver_forwarding_rule` ([#​33313](https://github.com/hashicorp/terraform-provider-azurerm/issues/33313)) - **New List Resource**: `azurerm_windows_virtual_machine` ([#​33332](https://github.com/hashicorp/terraform-provider-azurerm/issues/33332)) ENHANCEMENTS: - dependencies: `go-azure-sdk` - update to `v0.20260917.1142820` ([#​33495](https://github.com/hashicorp/terraform-provider-azurerm/issues/33495)) - dependencies: `network` - update API version to `2025-07-01` ([#​33441](https://github.com/hashicorp/terraform-provider-azurerm/issues/33441)) - Data Source: `azurerm_linux_web_app` - export the `virtual_network_image_pull_enabled` property ([#​33316](https://github.com/hashicorp/terraform-provider-azurerm/issues/33316)) - Data Source: `azurerm_network_interface` - export the `auxiliary_mode`, `auxiliary_sku`, `edge_zone`, and `internal_domain_name_suffix` properties ([#​33204](https://github.com/hashicorp/terraform-provider-azurerm/issues/33204)) - Data Source: `azurerm_public_ip` - export the `domain_name_label_scope`, `edge_zone`, `public_ip_prefix_id`, and `sku_tier` properties ([#​33193](https://github.com/hashicorp/terraform-provider-azurerm/issues/33193)) - Data Source: `azurerm_service_plan` - export the `premium_plan_auto_scale_enabled` property ([#​33300](https://github.com/hashicorp/terraform-provider-azurerm/issues/33300)) - Data Source: `azurerm_storage_blob` - export the `cache_control` and `source_uri` properties ([#​33318](https://github.com/hashicorp/terraform-provider-azurerm/issues/33318)) - Data Source: `azurerm_traffic_manager_profile` - export the `maximum_return` property ([#​33346](https://github.com/hashicorp/terraform-provider-azurerm/issues/33346)) - Data Source: `azurerm_web_pubsub` - export the `live_trace` and `identity` properties ([#​33373](https://github.com/hashicorp/terraform-provider-azurerm/issues/33373)) - `azurerm_kubernetes_cluster_node_pool` - add `Windows2025` as a valid value for the `os_sku` property ([#​33463](https://github.com/hashicorp/terraform-provider-azurerm/issues/33463)) - `azurerm_kubernetes_cluster` - add `Windows2025` as a valid value for the `os_sku` property ([#​33463](https://github.com/hashicorp/terraform-provider-azurerm/issues/33463)) BUG FIXES: - Data Source: `azurerm_kubernetes_cluster` - fix a panic caused by a nil pointer dereference while flattening `agent_pool_profile` ([#​33488](https://github.com/hashicorp/terraform-provider-azurerm/issues/33488)) - `azurerm_postgresql_flexible_server` - fix `cluster` block read for replica `create_mode` ([#​33082](https://github.com/hashicorp/terraform-provider-azurerm/issues/33082)) ### [`v5.6.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#560-September-17-2026) [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.5.0...v5.6.0) FEATURES: - **New List Resource**: `azurerm_batch_account` ([#​33252](https://github.com/hashicorp/terraform-provider-azurerm/issues/33252)) - **New List Resource**: `azurerm_cdn_frontdoor_origin_group` ([#​33334](https://github.com/hashicorp/terraform-provider-azurerm/issues/33334)) - **New Resource**: `azurerm_storage_discovery_workspace` ([#​31479](https://github.com/hashicorp/terraform-provider-azurerm/issues/31479)) ENHANCEMENTS: - dependencies: `containers` - update API version to `2026-05-01` ([#​32688](https://github.com/hashicorp/terraform-provider-azurerm/issues/32688)) - dependencies: `go-azure-sdk` - update to `v0.20260910.1141000` ([#​33413](https://github.com/hashicorp/terraform-provider-azurerm/issues/33413)) - dependencies: `qumulo` - update API version to `2026-04-16` ([#​33421](https://github.com/hashicorp/terraform-provider-azurerm/issues/33421)) - dependencies: `servicebus` - update to API version `2026-01-01` ([#​33450](https://github.com/hashicorp/terraform-provider-azurerm/issues/33450)) - `azurerm_iothub_device_update_instance` - add support for the `connection_string_wo` and `connection_string_wo_version` properties ([#​33448](https://github.com/hashicorp/terraform-provider-azurerm/issues/33448)) - `azurerm_linux_function_app` - add support for the `end_to_end_tls_encryption_enabled` property ([#​31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135)) - `azurerm_linux_function_app_slot` - add support for the `end_to_end_tls_encryption_enabled` property ([#​31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135)) - `azurerm_linux_web_app` - add support for the `end_to_end_tls_encryption_enabled` property ([#​31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135)) - `azurerm_linux_web_app_slot` - add support for the `end_to_end_tls_encryption_enabled` property ([#​31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135)) - `azurerm_mongo_cluster` - Support new property `network_bypass_mode` ([#​33168](https://github.com/hashicorp/terraform-provider-azurerm/issues/33168)) - `azurerm_servicebus_namespace` - add support for the `1.3` value to the `minimum_tls_version` property ([#​33457](https://github.com/hashicorp/terraform-provider-azurerm/issues/33457)) - `azurerm_windows_function_app` - add support for the `end_to_end_tls_encryption_enabled` property ([#​31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135)) - `azurerm_windows_function_app_slot` - add support for the `end_to_end_tls_encryption_enabled` property ([#​31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135)) - `azurerm_windows_web_app` - add support for the `end_to_end_tls_encryption_enabled` property ([#​31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135)) - `azurerm_windows_web_app_slot` - add support for the `end_to_end_tls_encryption_enabled` property ([#​31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135)) BUG FIXES: - `azurerm_site_recovery_replicated_vm` - select `managed_disk` properties compared case insensitive ([#​33424](https://github.com/hashicorp/terraform-provider-azurerm/issues/33424)) ### [`v5.5.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#550-September-10-2026) [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.4.0...v5.5.0) FEATURES: - **New List Resource**: `azurerm_analysis_services_server` ([#​33250](https://github.com/hashicorp/terraform-provider-azurerm/issues/33250)) - **New List Resource**: `azurerm_application_insights_workbook` ([#​33244](https://github.com/hashicorp/terraform-provider-azurerm/issues/33244)) - **New List Resource**: `azurerm_attestation_provider` ([#​33251](https://github.com/hashicorp/terraform-provider-azurerm/issues/33251)) - **New List Resource**: `azurerm_cdn_frontdoor_origin` ([#​33307](https://github.com/hashicorp/terraform-provider-azurerm/issues/33307)) - **New List Resource**: `azurerm_eventhub_consumer_group` ([#​33335](https://github.com/hashicorp/terraform-provider-azurerm/issues/33335)) - **New List Resource**: `azurerm_linux_virtual_machine` ([#​33333](https://github.com/hashicorp/terraform-provider-azurerm/issues/33333)) - **New List Resource**: `azurerm_virtual_hub_connection` ([#​33311](https://github.com/hashicorp/terraform-provider-azurerm/issues/33311)) ENHANCEMENTS: - dependencies: `go-azure-sdk` - update to `v0.20260901.1173158` ([#​33274](https://github.com/hashicorp/terraform-provider-azurerm/issues/33274)) - `azurerm_private_endpoint` - lock on private service connection resource ids ([#​33298](https://github.com/hashicorp/terraform-provider-azurerm/issues/33298)) - `azurerm_storage_account` - add support for the `public_network_access` property ([#​33292](https://github.com/hashicorp/terraform-provider-azurerm/issues/33292)) BUG FIXES: - `azurerm_resource_group` - the `managed_by` property now forces recreation when changed as the API does not support changing this value ([#​33339](https://github.com/hashicorp/terraform-provider-azurerm/issues/33339)) - `go-azure-sdk` - `Delete` operations now poll on asynchronous operation URLs if returned by the API instead of only checking for a `404` on the resource URL, ensuring deletion errors are reported to the user ([#​33274](https://github.com/hashicorp/terraform-provider-azurerm/issues/33274)) ### [`v5.4.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#540-September-03-2026) [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.3.0...v5.4.0) FEATURES: - **New List Resource**: `azurerm_application_insights_standard_web_test` ([#​33243](https://github.com/hashicorp/terraform-provider-azurerm/issues/33243)) - **New List Resource**: `azurerm_application_insights_workbook_template` ([#​33245](https://github.com/hashicorp/terraform-provider-azurerm/issues/33245)) - **New List Resource**: `azurerm_arc_kubernetes_provisioned_cluster` ([#​33247](https://github.com/hashicorp/terraform-provider-azurerm/issues/33247)) - **New List Resource**: `azurerm_availability_set` ([#​33241](https://github.com/hashicorp/terraform-provider-azurerm/issues/33241)) - **New List Resource**: `azurerm_batch_application` ([#​33254](https://github.com/hashicorp/terraform-provider-azurerm/issues/33254)) - **New List Resource**: `azurerm_dedicated_host_group` ([#​33257](https://github.com/hashicorp/terraform-provider-azurerm/issues/33257)) - **New List Resource**: `azurerm_log_analytics_workspace` ([#​33259](https://github.com/hashicorp/terraform-provider-azurerm/issues/33259)) ENHANCEMENTS: - dependencies: `azurerm_mongo_cluster` - update API version to `2026-06-01` ([#​33195](https://github.com/hashicorp/terraform-provider-azurerm/issues/33195)) - dependencies: `azurerm_mongo_cluster_firewall_rule` - update API version to `2026-06-01` ([#​33195](https://github.com/hashicorp/terraform-provider-azurerm/issues/33195)) - dependencies: `azurerm_mongo_cluster_user` - update API version to `2026-06-01` ([#​33195](https://github.com/hashicorp/terraform-provider-azurerm/issues/33195)) - dependencies: `netapp` - update API version to `2026-05-01` ([#​33215](https://github.com/hashicorp/terraform-provider-azurerm/issues/33215)) - Data Source: `azurerm_api_management_workspace` - export the `description` property ([#​33205](https://github.com/hashicorp/terraform-provider-azurerm/issues/33205)) - Data Source: `azurerm_attestation_provider` - export the `sev_snp_policy_base64`, `open_enclave_policy_base64`, `sgx_enclave_policy_base64`, and `tpm_policy_base64` properties ([#​33125](https://github.com/hashicorp/terraform-provider-azurerm/issues/33125)) - Data Source: `azurerm_automation_account` - export the `dsc_primary_access_key`, `dsc_server_endpoint`, `dsc_secondary_access_key`, `public_network_access_enabled`, `sku_name`, and `tags` properties ([#​33135](https://github.com/hashicorp/terraform-provider-azurerm/issues/33135)) - Data Source: `azurerm_automation_account` - export the `encryption` block ([#​33135](https://github.com/hashicorp/terraform-provider-azurerm/issues/33135)) - Data Source: `azurerm_ip_group` - export the `firewall_ids` and `firewall_policy_ids` properties ([#​33190](https://github.com/hashicorp/terraform-provider-azurerm/issues/33190)) - Data Source: `azurerm_private_link_service` - export the `fqdns` and `destination_ip_address` properties ([#​33191](https://github.com/hashicorp/terraform-provider-azurerm/issues/33191)) - `azurerm_key_vault_managed_hardware_security_module_key` - allow the `key_size` property to be set when `key_type` is `oct-HSM` ([#​32690](https://github.com/hashicorp/terraform-provider-azurerm/issues/32690)) - `azurerm_lb_probe ` - add support for the `no_healthy_backends_behavior` property ([#​32645](https://github.com/hashicorp/terraform-provider-azurerm/issues/32645)) - `azurerm_linux_virtual_machine_scale_set` - add support for the `NvmeDisk` value to the `os_disk.diff_disk_settings.placement` property ([#​30328](https://github.com/hashicorp/terraform-provider-azurerm/issues/30328)) - `azurerm_linux_web_app` - add support for the `8.5` value in the `site_config.application_stack.php_version` property ([#​33308](https://github.com/hashicorp/terraform-provider-azurerm/issues/33308)) - `azurerm_linux_web_app_slot` - add support for the `8.5` value in the `site_config.application_stack.php_version` property ([#​33308](https://github.com/hashicorp/terraform-provider-azurerm/issues/33308)) - `azurerm_netapp_volume` - support for the `breakthrough_mode_enabled` property ([#​33215](https://github.com/hashicorp/terraform-provider-azurerm/issues/33215)) - `azurerm_postgresql_flexible_server` - add support for the `storage_type`, `storage_iops`, and `storage_throughput` properties which allows choice of the new "Premium V2 LRS" storage type ([#​32121](https://github.com/hashicorp/terraform-provider-azurerm/issues/32121)) - `azurerm_storage_account` - add support for an in-place migration of `account_replication_type` between matching non-zonal and zonal types instead of resource recreation ([#​33236](https://github.com/hashicorp/terraform-provider-azurerm/issues/33236)) - `azurerm_storage_table` - add support for AAD authentication ([#​32997](https://github.com/hashicorp/terraform-provider-azurerm/issues/32997)) - `azurerm_synapse_spark_pool` - migrate to `go-azure-sdk` ([#​33258](https://github.com/hashicorp/terraform-provider-azurerm/issues/33258)) - `azurerm_windows_virtual_machine_scale_set` - add support for the `NvmeDisk` value to the `os_disk.diff_disk_settings.placement` property ([#​30328](https://github.com/hashicorp/terraform-provider-azurerm/issues/30328)) BUG FIXES: - `azurerm_synapse_spark_pool` - fix `lifecycle.ignore_changes` support ([#​33258](https://github.com/hashicorp/terraform-provider-azurerm/issues/33258)) ### [`v5.3.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#530-August-27-2026) [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.2.0...v5.3.0) FEATURES: - **New Data Source**: `azurerm_playwright_workspace` ([#​31954](https://github.com/hashicorp/terraform-provider-azurerm/issues/31954)) - **New List Resource**: `azurerm_cognitive_deployment` ([#​33149](https://github.com/hashicorp/terraform-provider-azurerm/issues/33149)) - **New List Resource**: `azurerm_playwright_workspace` ([#​31954](https://github.com/hashicorp/terraform-provider-azurerm/issues/31954)) - **New Resource**: `azurerm_playwright_workspace` ([#​31954](https://github.com/hashicorp/terraform-provider-azurerm/issues/31954)) ENHANCEMENTS: - dependencies: `go-azure-helpers` - update version to `0.82.0` ([#​33142](https://github.com/hashicorp/terraform-provider-azurerm/issues/33142)) - dependencies: `sql` - update API version to `2025-01-01` ([#​33201](https://github.com/hashicorp/terraform-provider-azurerm/issues/33201)) - Data Source: `azurerm_role_definition` - export the `role_definition_resource_id` property ([#​33126](https://github.com/hashicorp/terraform-provider-azurerm/issues/33126)) - `azurerm_cognitive_deployment` - add Resource Identity support ([#​33149](https://github.com/hashicorp/terraform-provider-azurerm/issues/33149)) - `azurerm_federated_identity_credential` - add additional polling to account for Azure's eventual consistency ([#​32935](https://github.com/hashicorp/terraform-provider-azurerm/issues/32935)) - `azurerm_kubernetes_cluster` - add support for the `oms_agent.retina_flow_logs_enabled` property ([#​33222](https://github.com/hashicorp/terraform-provider-azurerm/issues/33222)) - `azurerm_managed_application` - add support for the `identity` block ([#​30725](https://github.com/hashicorp/terraform-provider-azurerm/issues/30725)) - `azurerm_private_endpoint` - extend validation for the `private_service_connection.subresource_names` property to allow names containing spaces ([#​32887](https://github.com/hashicorp/terraform-provider-azurerm/issues/32887)) - `azurerm_search_service` - allow in-place downgrades of the `sku` property between Basic and Standard tiers ([#​33069](https://github.com/hashicorp/terraform-provider-azurerm/issues/33069)) - `azurerm_site_recovery_replicated_vm` - add update support to the `managed_disk` block without requiring resource recreation ([#​33140](https://github.com/hashicorp/terraform-provider-azurerm/issues/33140)) - `azurerm_user_assigned_identity` - add additional polling to account for Azure's eventual consistency ([#​33142](https://github.com/hashicorp/terraform-provider-azurerm/issues/33142)) BUG FIXES: - Data Source: `azurerm_app_configuration_key` - now correctly sets `tags` into state ([#​33182](https://github.com/hashicorp/terraform-provider-azurerm/issues/33182)) - `azurerm_eventhub_namespace` - prevent `network_rulesets.x.default_action` being set to `Deny` if `ip_rule` or `virtual_network_rule` is not specified ([#​33216](https://github.com/hashicorp/terraform-provider-azurerm/issues/33216)) ### [`v5.2.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#520-August-20-2026) [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.1.0...v5.2.0) FEATURES: - **New List Resource**: `azurerm_user_assigned_identity` ([#​32667](https://github.com/hashicorp/terraform-provider-azurerm/issues/32667)) ENHANCEMENTS: - dependencies: `go` - update to `1.26.6` ([#​33141](https://github.com/hashicorp/terraform-provider-azurerm/issues/33141)) - dependencies: `go-azure-sdk` - update to `v0.20260811.1225050` ([#​33079](https://github.com/hashicorp/terraform-provider-azurerm/issues/33079)) - `azurerm_cdn_frontdoor_batch_rule_set` - allow `/` as an input to `rule.conditions.request_path.values` ([#​33023](https://github.com/hashicorp/terraform-provider-azurerm/issues/33023)) - `azurerm_databricks_workspace` - remove a redundant key vault existence check ([#​33136](https://github.com/hashicorp/terraform-provider-azurerm/issues/33136)) - `azurerm_databricks_workspace_root_dbfs_customer_managed_key` - remove a redundant key vault existence check ([#​33136](https://github.com/hashicorp/terraform-provider-azurerm/issues/33136)) - `azurerm_logic_app_standard` - add support for `v10.0` to `site_config.dotnet_framework_version` ([#​33116](https://github.com/hashicorp/terraform-provider-azurerm/issues/33116)) - `azurerm_mongo_cluster` - `administrator_password` is no longer required when `create_mode` is `Default` to support Entra ID-only authentication ([#​32092](https://github.com/hashicorp/terraform-provider-azurerm/issues/32092)) - `azurerm_redhat_openshift_cluster` - add support for the `network_profile.load_balancer_profile` block ([#​32473](https://github.com/hashicorp/terraform-provider-azurerm/issues/32473)) - `azurerm_redhat_openshift_cluster` - add support for the `platform_workload_identity_profile` block ([#​32473](https://github.com/hashicorp/terraform-provider-azurerm/issues/32473)) - `azurerm_role_assignment` - the `condition`, `condition_version`, and `description` properties can now be updated in-place ([#​32714](https://github.com/hashicorp/terraform-provider-azurerm/issues/32714)) - `azurerm_snapshot` - `create_option` now supports `CopyStart` ([#​32834](https://github.com/hashicorp/terraform-provider-azurerm/issues/32834)) BUG FIXES: - `azurerm_cognitive_account_project` - added create/update/delete lock on parent AccountID to make sure operations on parent account are processed in serial (required by Cognitive service) ([#​33151](https://github.com/hashicorp/terraform-provider-azurerm/issues/33151)) - `azurerm_databricks_workspace` - fix a persistent diff on removal of `managed_disk_cmk_key_vault_key_id` or `managed_services_cmk_key_vault_key_id` ([#​33136](https://github.com/hashicorp/terraform-provider-azurerm/issues/33136)) - `azurerm_oracle_exadata_infrastructure` - fix an issue that prevented users from deploying with no `zones` set ([#​33011](https://github.com/hashicorp/terraform-provider-azurerm/issues/33011)) ### [`v5.1.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#510-August-13-2026) [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.0.1...v5.1.0) ENHANCEMENTS: - dependencies: `azurerm_linux_virtual_machine_scale_set` - update to API version `2025-04-01` ([#​31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586)) - dependencies: `azurerm_orchestrated_virtual_machine_scale_set` - update to API version `2025-04-01` ([#​31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586)) - dependencies: `azurerm_virtual_machine_scale_set` - update to API version `2025-04-01` ([#​31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586)) - dependencies: `azurerm_virtual_machine_scale_set_extension` - update to API version `2025-04-01` ([#​31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586)) - dependencies: `azurerm_windows_virtual_machine_scale_set` - update to API version `2025-04-01` ([#​31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586)) - dependencies: `codesigning` - update to API version `2025-10-13` ([#​31714](https://github.com/hashicorp/terraform-provider-azurerm/issues/31714)) - `azurerm_linux_virtual_machine` - `encryption_at_host_enabled` can now be set to `true` when `os_disk.security_encryption_type` is set to `DiskWithVMGuestState` ([#​32885](https://github.com/hashicorp/terraform-provider-azurerm/issues/32885)) - `azurerm_linux_virtual_machine_scale_set` - `encryption_at_host_enabled` can now be set to `true` when `os_disk.security_encryption_type` is set to `DiskWithVMGuestState` ([#​32885](https://github.com/hashicorp/terraform-provider-azurerm/issues/32885)) - `azurerm_managed_devops_pool` - add support for the `CreatorOnly` value to `azure_devops_organization.permission.kind` property ([#​32753](https://github.com/hashicorp/terraform-provider-azurerm/issues/32753)) - `azurerm_windows_virtual_machine` - `encryption_at_host_enabled` can now be set to `true` when `os_disk.security_encryption_type` is set to `DiskWithVMGuestState` ([#​32885](https://github.com/hashicorp/terraform-provider-azurerm/issues/32885)) - `azurerm_windows_virtual_machine_scale_set` - `encryption_at_host_enabled` can now be set to `true` when `os_disk.security_encryption_type` is set to `DiskWithVMGuestState` ([#​32885](https://github.com/hashicorp/terraform-provider-azurerm/issues/32885)) BUG FIXES: - `azurerm_cdn_frontdoor_batch_ruleset` - parse `rule.actions.route_configuration_override.origin_group.cdn_frontdoor_origin_group_id` case-insensitively and normalize the resulting value to prevent diffs ([#​32980](https://github.com/hashicorp/terraform-provider-azurerm/issues/32980)) - `azurerm_cdn_frontdoor_route` - parse `cdn_frontdoor_origin_group_id` case-insensitively and normalize the resulting value to prevent diffs ([#​32980](https://github.com/hashicorp/terraform-provider-azurerm/issues/32980)) - `azurerm_cdn_frontdoor_secret` - fix an incorrect type assertion ([#​32982](https://github.com/hashicorp/terraform-provider-azurerm/issues/32982)) - `azurerm_dev_center_project` - parse `dev_center_id` case-insensitively and normalize the resulting value to prevent diffs ([#​32798](https://github.com/hashicorp/terraform-provider-azurerm/issues/32798)) - `azurerm_eventhub` - now prevents the `status` property from being set to `SendDisabled` on create ([#​33071](https://github.com/hashicorp/terraform-provider-azurerm/issues/33071)) - `azurerm_storage_container` - add a state migration for the `id` field, fixing the upgrade path from 4.x to 5.x ([#​32978](https://github.com/hashicorp/terraform-provider-azurerm/issues/32978)) - `azurerm_storage_queue` - extend state migration to handle a malformed `resource_manager_id` ([#​32979](https://github.com/hashicorp/terraform-provider-azurerm/issues/32979)) - `azurerm_storage_share` - add a state migration for the `id` field, fixing the upgrade path from 4.x to 5.x ([#​33075](https://github.com/hashicorp/terraform-provider-azurerm/issues/33075)) ### [`v5.0.1`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#501-July-30-2026) [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.0.0...v5.0.1) NOTES: In addition to the bug fixes below, a number of resource documentation pages and the 5.0-upgrade-guide have been updated. BUG FIXES: - `azurerm_cdn_frontdoor_origin` - fix a regression that prevented valid values as input to `private_link.private_link_target_id` ([#​32912](https://github.com/hashicorp/terraform-provider-azurerm/issues/32912)) - `azurerm_storage_queue` - add a state migration for the `id` field, fixing the upgrade path from 4.x to 5.x ([#​32914](https://github.com/hashicorp/terraform-provider-azurerm/issues/32914)) - `azurerm_storage_table_entity` - add a state migration for the `storage_table_id` field, fixing the upgrade path from 4.x to 5.x ([#​32929](https://github.com/hashicorp/terraform-provider-azurerm/issues/32929)) ### [`v5.0.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#500-July-27-2026) [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v4.81.0...v5.0.0) NOTES: - **Major Version**: Version 5.0 of the Azure Provider is a major version - some behaviours have changed and some deprecated fields/resources have been removed - please refer to [the 5.0 upgrade guide for more information](https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/guides/5.0-upgrade-guide). - When upgrading to v5.0 of the AzureRM Provider, we recommend upgrading to the latest version of Terraform Core ([which can be found here](https://developer.hashicorp.com/terraform/install)). FEATURES: - **New Action**: `azurerm_web_app_set_slot_distribution` ([#​32364](https://github.com/hashicorp/terraform-provider-azurerm/issues/32364)) - **New Datasource** adds `azurerm_kubernetes_automatic_cluster_datasource` ([#​32881](https://github.com/hashicorp/terraform-provider-azurerm/issues/32881)) ENHANCEMENTS: - dependencies: `grpc` update to `1.82.1` ([#​32852](https://github.com/hashicorp/terraform-provider-azurerm/issues/32852)) - dependencies: `loadbalancers` - update to API version `2025-01-01` ([#​32644](https://github.com/hashicorp/terraform-provider-azurerm/issues/32644)) - `azurerm_cognitive_account_rai_policy` - the `content_filter.severity_threshold` property is now optional ([#​32100](https://github.com/hashicorp/terraform-provider-azurerm/issues/32100)) - `azurerm_container_registry` - the `trust_policy_enabled` property has been deprecated and removed from the provider ([#​32752](https://github.com/hashicorp/terraform-provider-azurerm/issues/32752)) - `azurerm_dashboard_grafana` - the `11` value for the `grafana_major_version` property has been deprecated and the property now supports `13` ([#​32777](https://github.com/hashicorp/terraform-provider-azurerm/issues/32777)) - `azurerm_log_analytics_workspace` - add support for the `internet_ingestion_access_type` and `internet_query_access_type` properties ([#​32562](https://github.com/hashicorp/terraform-provider-azurerm/issues/32562)) - `azurerm_subnet` - add support for the `network_security_group_id_wo` and `network_security_group_id_wo_version` properties ([#​32847](https://github.com/hashicorp/terraform-provider-azurerm/issues/32847)) - `azurerm_subnet` - add support for the `route_table_id_wo` and `route_table_id_wo_version` properties ([#​32847](https://github.com/hashicorp/terraform-provider-azurerm/issues/32847)) - `azurerm_subnet` - export the `network_security_group_id` property ([#​32847](https://github.com/hashicorp/terraform-provider-azurerm/issues/32847)) - `azurerm_subnet` - export the `route_table_id` property ([#​32847](https://github.com/hashicorp/terraform-provider-azurerm/issues/32847)) - `azurerm_windows_web_app` - add support for `~24` to `site_config.application_stack.node_version` ([#​32840](https://github.com/hashicorp/terraform-provider-azurerm/issues/32840)) - `azurerm_windows_web_app_slot` - add support for `~24` to `site_config.application_stack.node_version` ([#​32840](https://github.com/hashicorp/terraform-provider-azurerm/issues/32840)) - `cdn` - migrate to `go-azure-sdk` ([#​32849](https://github.com/hashicorp/terraform-provider-azurerm/issues/32849)) - `sentinel` - migrate to `go-azure-sdk` ([#​32759](https://github.com/hashicorp/terraform-provider-azurerm/issues/32759)) </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Oslo) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==--> --------- Co-authored-by: Renovate Bot <renovate@forteapps.net> Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/55 Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com> Co-authored-by: gitea_admin <admin@forteapps.net> commit0f0082d54dAuthor: gitea_admin <admin@forteapps.net> Date: Sat Oct 3 18:55:02 2026 +0000 chore(deps): update helm release fluent-bit to v0.58.3 (#57) This PR contains the following updates: | Package | Update | Change | |---|---|---| | [fluent-bit](https://fluentbit.io/) ([source](https://github.com/fluent/helm-charts)) | patch | `0.58.2` → `0.58.3` | --- ### Release Notes <details> <summary>fluent/helm-charts (fluent-bit)</summary> ### [`v0.58.3`](https://github.com/fluent/helm-charts/releases/tag/fluent-bit-0.58.3) [Compare Source](https://github.com/fluent/helm-charts/compare/fluent-bit-0.58.2...fluent-bit-0.58.3) ##### Changed - Update *Fluent Bit* OCI image to [v5.1.3](https://github.com/fluent/fluent-bit/releases/tag/v5.1.3). ([#​759](https://github.com/fluent/helm-charts/pull/759)) [@​stevehipwell](https://github.com/stevehipwell) </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Oslo) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==--> --------- Co-authored-by: Renovate Bot <renovate@forteapps.net> Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/57 Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com> Co-authored-by: gitea_admin <admin@forteapps.net> commit4a4b8e3540Author: Jørgen Stensrud <jorgen.stensrud@fortedigital.com> Date: Thu Oct 1 11:25:34 2026 +0000 feat(keycloak): forte-cli device-code client + forte-drop-mcp audience mapper (#44) Adds the shared public forte-cli client (RFC 8628 device-code only) to the forte realm, with an oidc-audience-mapper that puts https://mcp.drop.forteapps.net/mcp into aud so the forte-drop-mcp sidecar accepts its tokens. Supersedes #26. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> commit60b8fa657aAuthor: gitea_admin <admin@forteapps.net> Date: Thu Oct 1 09:40:57 2026 +0000 chore(deps): update nikitafilonov/ai-review docker tag to v1 (#53) This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | nikitafilonov/ai-review | docker | major | `v0.77.0` → `v1.1.0` | --- ### Configuration 📅 **Schedule**: (in timezone Europe/Oslo) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==--> --------- Co-authored-by: Renovate Bot <renovate@forteapps.net> Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/53 Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com> Co-authored-by: gitea_admin <admin@forteapps.net> commitc940259545Author: gitea_admin <admin@forteapps.net> Date: Wed Sep 30 08:36:32 2026 +0000 chore(deps): update helm release opencost to v2 (#50) This PR contains the following updates: | Package | Update | Change | |---|---|---| | [opencost](https://github.com/opencost/opencost-helm-chart) | major | `1.43.2` → `2.5.32` | --- ### Release Notes <details> <summary>opencost/opencost-helm-chart (opencost)</summary> ### [`v2.5.32`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.32) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.31...opencost-2.5.32) OpenCost and OpenCost UI #### What's Changed - Upgrade OpenCost Helm Chart to v1.121.3 by [@​cpetersen5](https://github.com/cpetersen5) in [#​385](https://github.com/opencost/opencost-helm-chart/pull/385) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.31...opencost-2.5.32> ### [`v2.5.31`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.31) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.30...opencost-2.5.31) OpenCost and OpenCost UI #### What's Changed - Release OpenCost v1.121.2 by [@​cpetersen5](https://github.com/cpetersen5) in [#​384](https://github.com/opencost/opencost-helm-chart/pull/384) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.30...opencost-2.5.31> ### [`v2.5.30`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.30) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.29...opencost-2.5.30) OpenCost and OpenCost UI #### What's Changed - feat: add opencost.exporter.extraEnvFrom to source env from ConfigMap/Secret by [@​ahauserv](https://github.com/ahauserv) in [#​378](https://github.com/opencost/opencost-helm-chart/pull/378) #### New Contributors - [@​ahauserv](https://github.com/ahauserv) made their first contribution in [#​378](https://github.com/opencost/opencost-helm-chart/pull/378) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.29...opencost-2.5.30> ### [`v2.5.29`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.29) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.28...opencost-2.5.29) OpenCost and OpenCost UI #### What's Changed - Release OpenCost v1.121.1 by [@​cpetersen5](https://github.com/cpetersen5) in [#​377](https://github.com/opencost/opencost-helm-chart/pull/377) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.28...opencost-2.5.29> ### [`v2.5.28`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.28) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.27...opencost-2.5.28) OpenCost and OpenCost UI #### What's Changed - Inference Cost params added to helm by [@​simanadler](https://github.com/simanadler) in [#​370](https://github.com/opencost/opencost-helm-chart/pull/370) - Release OpenCost v1.121.0 by [@​cpetersen5](https://github.com/cpetersen5) in [#​372](https://github.com/opencost/opencost-helm-chart/pull/372) #### New Contributors - [@​simanadler](https://github.com/simanadler) made their first contribution in [#​370](https://github.com/opencost/opencost-helm-chart/pull/370) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.27...opencost-2.5.28> ### [`v2.5.27`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.27) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.26...opencost-2.5.27) OpenCost and OpenCost UI #### What's Changed - KCM-5392: Add support for configuring external labels for Opencost installation with Collector data source by [@​avrodrigues5](https://github.com/avrodrigues5) in [#​371](https://github.com/opencost/opencost-helm-chart/pull/371) #### New Contributors - [@​avrodrigues5](https://github.com/avrodrigues5) made their first contribution in [#​371](https://github.com/opencost/opencost-helm-chart/pull/371) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.26...opencost-2.5.27> ### [`v2.5.26`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.26) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.25...opencost-2.5.26) OpenCost and OpenCost UI #### What's Changed - add timeout configuration for override in probes by [@​aman-kumar29](https://github.com/aman-kumar29) in [#​369](https://github.com/opencost/opencost-helm-chart/pull/369) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-parquet-exporter-0.3.0...opencost-2.5.26> ### [`v2.5.25`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.25) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.24...opencost-2.5.25) OpenCost and OpenCost UI #### What's Changed - Release OpenCost v1.120.4 by [@​cpetersen5](https://github.com/cpetersen5) in [#​366](https://github.com/opencost/opencost-helm-chart/pull/366) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.24...opencost-2.5.25> ### [`v2.5.24`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.24) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.23...opencost-2.5.24) OpenCost and OpenCost UI #### What's Changed - fix(service): use opencost.exporter.debugPort for service targetPort by [@​aman-kumar29](https://github.com/aman-kumar29) in [#​364](https://github.com/opencost/opencost-helm-chart/pull/364) #### New Contributors - [@​aman-kumar29](https://github.com/aman-kumar29) made their first contribution in [#​364](https://github.com/opencost/opencost-helm-chart/pull/364) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.23...opencost-2.5.24> ### [`v2.5.23`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.23) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.22...opencost-2.5.23) OpenCost and OpenCost UI #### What's Changed - feat(gateway-api): Add support for filters by [@​HartmannVolker](https://github.com/HartmannVolker) in [#​356](https://github.com/opencost/opencost-helm-chart/pull/356) #### New Contributors - [@​HartmannVolker](https://github.com/HartmannVolker) made their first contribution in [#​356](https://github.com/opencost/opencost-helm-chart/pull/356) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.22...opencost-2.5.23> ### [`v2.5.22`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.22) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.21...opencost-2.5.22) OpenCost and OpenCost UI #### What's Changed - Release OpenCost v1.120.3 by [@​cpetersen5](https://github.com/cpetersen5) in [#​357](https://github.com/opencost/opencost-helm-chart/pull/357) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.21...opencost-2.5.22> ### [`v2.5.21`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.21) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.20...opencost-2.5.21) OpenCost and OpenCost UI #### What's Changed - feat: add extraObjects for tpl-rendered extra manifests by [@​younsl](https://github.com/younsl) in [#​354](https://github.com/opencost/opencost-helm-chart/pull/354) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.20...opencost-2.5.21> ### [`v2.5.20`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.20) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.19...opencost-2.5.20) OpenCost and OpenCost UI #### What's Changed - Update Helm chart for v1.120.2 by [@​cpetersen5](https://github.com/cpetersen5) in [#​355](https://github.com/opencost/opencost-helm-chart/pull/355) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.19...opencost-2.5.20> ### [`v2.5.19`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.19) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.18...opencost-2.5.19) OpenCost and OpenCost UI #### What's Changed - Consistent Usage of `opencost.namespace` Helper by [@​ioboi](https://github.com/ioboi) in [#​353](https://github.com/opencost/opencost-helm-chart/pull/353) #### New Contributors - [@​ioboi](https://github.com/ioboi) made their first contribution in [#​353](https://github.com/opencost/opencost-helm-chart/pull/353) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.18...opencost-2.5.19> ### [`v2.5.18`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.18) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.14...opencost-2.5.18) OpenCost and OpenCost UI #### What's Changed - feat: Add plugins.install.plugins list and existingSecret support (adopts [#​328](https://github.com/opencost/opencost-helm-chart/issues/328)) by [@​ameijer](https://github.com/ameijer) in [#​344](https://github.com/opencost/opencost-helm-chart/pull/344) - feat: add OCI cloud cost configuration example to cloudIntegrationJSON by [@​Kush172005](https://github.com/Kush172005) in [#​345](https://github.com/opencost/opencost-helm-chart/pull/345) - Release Opencost v1.120.1 - Bump Helm Chart by [@​cpetersen5](https://github.com/cpetersen5) in [#​347](https://github.com/opencost/opencost-helm-chart/pull/347) - Fix UI route tls by [@​mittal-ishaan](https://github.com/mittal-ishaan) in [#​352](https://github.com/opencost/opencost-helm-chart/pull/352) #### New Contributors - [@​Kush172005](https://github.com/Kush172005) made their first contribution in [#​345](https://github.com/opencost/opencost-helm-chart/pull/345) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.14...opencost-2.5.18> ### [`v2.5.14`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.14) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.12...opencost-2.5.14) OpenCost and OpenCost UI #### What's Changed - Release Opencost v1.120.0 by [@​cpetersen5](https://github.com/cpetersen5) in [#​341](https://github.com/opencost/opencost-helm-chart/pull/341) - Cdp/opencost v1.120.0 by [@​cpetersen5](https://github.com/cpetersen5) in [#​343](https://github.com/opencost/opencost-helm-chart/pull/343) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.12...opencost-2.5.14> ### [`v2.5.12`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.12) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.11...opencost-2.5.12) OpenCost and OpenCost UI #### What's Changed - Create Empty /var/configs dir by [@​HMetcalfeW](https://github.com/HMetcalfeW) in [#​333](https://github.com/opencost/opencost-helm-chart/pull/333) #### New Contributors - [@​HMetcalfeW](https://github.com/HMetcalfeW) made their first contribution in [#​333](https://github.com/opencost/opencost-helm-chart/pull/333) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.11...opencost-2.5.12> ### [`v2.5.11`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.11) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.10...opencost-2.5.11) OpenCost and OpenCost UI #### What's Changed - add admin token infra support by [@​ameijer](https://github.com/ameijer) in [#​339](https://github.com/opencost/opencost-helm-chart/pull/339) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.10...opencost-2.5.11> ### [`v2.5.10`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.10) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.9...opencost-2.5.10) OpenCost and OpenCost UI #### What's Changed - Add cloudIntegrationJSON support by [@​thomasvn](https://github.com/thomasvn) in [#​337](https://github.com/opencost/opencost-helm-chart/pull/337) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.9...opencost-2.5.10> ### [`v2.5.9`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.9) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.8...opencost-2.5.9) OpenCost and OpenCost UI #### What's Changed - Fix collectorDataSource retention env var conditions by [@​dag-andersen](https://github.com/dag-andersen) in [#​336](https://github.com/opencost/opencost-helm-chart/pull/336) #### New Contributors - [@​dag-andersen](https://github.com/dag-andersen) made their first contribution in [#​336](https://github.com/opencost/opencost-helm-chart/pull/336) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.8...opencost-2.5.9> ### [`v2.5.8`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.8) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.7...opencost-2.5.8) OpenCost and OpenCost UI #### What's Changed - Opencost v1.119.2 Changes by [@​cpetersen5](https://github.com/cpetersen5) in [#​334](https://github.com/opencost/opencost-helm-chart/pull/334) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.7...opencost-2.5.8> ### [`v2.5.7`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.7) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.6...opencost-2.5.7) OpenCost and OpenCost UI #### What's Changed - fix: fix csv export condition in deployment by [@​meroupatate](https://github.com/meroupatate) in [#​330](https://github.com/opencost/opencost-helm-chart/pull/330) #### New Contributors - [@​meroupatate](https://github.com/meroupatate) made their first contribution in [#​330](https://github.com/opencost/opencost-helm-chart/pull/330) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.6...opencost-2.5.7> ### [`v2.5.6`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.6) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.5...opencost-2.5.6) OpenCost and OpenCost UI #### What's Changed - Do not grant permissions on nodes/proxy by default by [@​Farenjihn](https://github.com/Farenjihn) in [#​329](https://github.com/opencost/opencost-helm-chart/pull/329) #### New Contributors - [@​Farenjihn](https://github.com/Farenjihn) made their first contribution in [#​329](https://github.com/opencost/opencost-helm-chart/pull/329) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.5...opencost-2.5.6> ### [`v2.5.5`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.5) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.4...opencost-2.5.5) OpenCost and OpenCost UI #### What's Changed - Add PRICING\_CONFIGMAP\_NAME env to achnowledge configmapName helm value by [@​mittal-ishaan](https://github.com/mittal-ishaan) in [#​316](https://github.com/opencost/opencost-helm-chart/pull/316) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.4...opencost-2.5.5> ### [`v2.5.4`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.4) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.3...opencost-2.5.4) OpenCost and OpenCost UI #### What's Changed - feat(opencost): add Gateway API HTTPRoute support by [@​younsl](https://github.com/younsl) in [#​322](https://github.com/opencost/opencost-helm-chart/pull/322) #### New Contributors - [@​younsl](https://github.com/younsl) made their first contribution in [#​322](https://github.com/opencost/opencost-helm-chart/pull/322) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.3...opencost-2.5.4> ### [`v2.5.3`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.3) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.2...opencost-2.5.3) OpenCost and OpenCost UI #### What's Changed - Add configurable nginx proxy timeouts to helm chart by [@​peatey](https://github.com/peatey) in [#​326](https://github.com/opencost/opencost-helm-chart/pull/326) #### New Contributors - [@​peatey](https://github.com/peatey) made their first contribution in [#​326](https://github.com/opencost/opencost-helm-chart/pull/326) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.2...opencost-2.5.3> ### [`v2.5.2`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.2) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.1...opencost-2.5.2) OpenCost and OpenCost UI #### What's Changed - Update cloud-integration secret path by [@​thomasvn](https://github.com/thomasvn) in [#​324](https://github.com/opencost/opencost-helm-chart/pull/324) #### New Contributors - [@​thomasvn](https://github.com/thomasvn) made their first contribution in [#​324](https://github.com/opencost/opencost-helm-chart/pull/324) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.1...opencost-2.5.2> ### [`v2.5.1`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.1) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.0...opencost-2.5.1) OpenCost and OpenCost UI #### What's Changed - Release Opencost v1.119.1 by [@​cpetersen5](https://github.com/cpetersen5) in [#​325](https://github.com/opencost/opencost-helm-chart/pull/325) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.0...opencost-2.5.1> ### [`v2.5.0`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.0) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.4.1...opencost-2.5.0) OpenCost and OpenCost UI #### What's Changed - Release Opencost v1.119.0 by [@​cpetersen5](https://github.com/cpetersen5) in [#​323](https://github.com/opencost/opencost-helm-chart/pull/323) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.4.1...opencost-2.5.0> ### [`v2.4.1`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.4.1) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.4.0...opencost-2.4.1) OpenCost and OpenCost UI #### What's Changed - fix: mcp disable procedure by [@​marijus-ravickas](https://github.com/marijus-ravickas) in [#​319](https://github.com/opencost/opencost-helm-chart/pull/319) #### New Contributors - [@​marijus-ravickas](https://github.com/marijus-ravickas) made their first contribution in [#​319](https://github.com/opencost/opencost-helm-chart/pull/319) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.4.0...opencost-2.4.1> ### [`v2.4.0`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.4.0) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.3.2...opencost-2.4.0) OpenCost and OpenCost UI #### What's Changed - added-mcp-config by [@​sneaxhuh](https://github.com/sneaxhuh) in [#​311](https://github.com/opencost/opencost-helm-chart/pull/311) - Update Opencost to v1.118.0 by [@​cpetersen5](https://github.com/cpetersen5) in [#​314](https://github.com/opencost/opencost-helm-chart/pull/314) #### New Contributors - [@​sneaxhuh](https://github.com/sneaxhuh) made their first contribution in [#​311](https://github.com/opencost/opencost-helm-chart/pull/311) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.3.2...opencost-2.4.0> ### [`v2.3.2`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.3.2) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.3.1...opencost-2.3.2) OpenCost and OpenCost UI #### What's Changed - fix: use default sc when sc name not specified by [@​cwyl02](https://github.com/cwyl02) in [#​312](https://github.com/opencost/opencost-helm-chart/pull/312) #### New Contributors - [@​cwyl02](https://github.com/cwyl02) made their first contribution in [#​312](https://github.com/opencost/opencost-helm-chart/pull/312) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.3.1...opencost-2.3.2> ### [`v2.3.1`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.3.1) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.3.0...opencost-2.3.1) OpenCost and OpenCost UI #### What's Changed - feat: Add option to use cm to set CLUSTER\_ID envvar by [@​gracedo](https://github.com/gracedo) in [#​307](https://github.com/opencost/opencost-helm-chart/pull/307) #### New Contributors - [@​gracedo](https://github.com/gracedo) made their first contribution in [#​307](https://github.com/opencost/opencost-helm-chart/pull/307) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.3.0...opencost-2.3.1> ### [`v2.3.0`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.3.0) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.9...opencost-2.3.0) OpenCost and OpenCost UI #### What's Changed - Add configs to mount custom ca certs to opencost container by [@​mittal-ishaan](https://github.com/mittal-ishaan) in [#​303](https://github.com/opencost/opencost-helm-chart/pull/303) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.9...opencost-2.3.0> ### [`v2.2.9`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.9) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.8...opencost-2.2.9) OpenCost and OpenCost UI #### What's Changed - Add chart installation notes by [@​dejanu](https://github.com/dejanu) in [#​305](https://github.com/opencost/opencost-helm-chart/pull/305) - Release Opencost v1.117.6 by [@​cpetersen5](https://github.com/cpetersen5) in [#​309](https://github.com/opencost/opencost-helm-chart/pull/309) #### New Contributors - [@​dejanu](https://github.com/dejanu) made their first contribution in [#​305](https://github.com/opencost/opencost-helm-chart/pull/305) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.8...opencost-2.2.9> ### [`v2.2.8`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.8) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.7...opencost-2.2.8) OpenCost and OpenCost UI #### What's Changed - Release Opencost v1.117.5 by [@​cpetersen5](https://github.com/cpetersen5) in [#​306](https://github.com/opencost/opencost-helm-chart/pull/306) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.7...opencost-2.2.8> ### [`v2.2.7`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.7) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.6...opencost-2.2.7) OpenCost and OpenCost UI #### What's Changed - Add uiPath configuration for OpenCost UI by [@​gustavo-sdo](https://github.com/gustavo-sdo) in [#​298](https://github.com/opencost/opencost-helm-chart/pull/298) #### New Contributors - [@​gustavo-sdo](https://github.com/gustavo-sdo) made their first contribution in [#​298](https://github.com/opencost/opencost-helm-chart/pull/298) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.6...opencost-2.2.7> ### [`v2.2.6`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.6) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.5...opencost-2.2.6) OpenCost and OpenCost UI #### What's Changed - Dodizzle/proxy fix by [@​ameijer](https://github.com/ameijer) in [#​301](https://github.com/opencost/opencost-helm-chart/pull/301) - allow: set path for internal prometheus by [@​dodizzle](https://github.com/dodizzle) in [#​271](https://github.com/opencost/opencost-helm-chart/pull/271) #### New Contributors - [@​dodizzle](https://github.com/dodizzle) made their first contribution in [#​271](https://github.com/opencost/opencost-helm-chart/pull/271) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.5...opencost-2.2.6> ### [`v2.2.5`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.5) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.4...opencost-2.2.5) OpenCost and OpenCost UI #### What's Changed - Release v1.117.3 of Opencost by [@​cpetersen5](https://github.com/cpetersen5) in [#​300](https://github.com/opencost/opencost-helm-chart/pull/300) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.4...opencost-2.2.5> ### [`v2.2.4`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.4) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.3...opencost-2.2.4) OpenCost and OpenCost UI #### What's Changed - Release v1.117.2 of Opencost by [@​cpetersen5](https://github.com/cpetersen5) in [#​299](https://github.com/opencost/opencost-helm-chart/pull/299) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.3...opencost-2.2.4> ### [`v2.2.3`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.3) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.2...opencost-2.2.3) OpenCost and OpenCost UI #### What's Changed - Update env var names and values by [@​Sean-Holcomb](https://github.com/Sean-Holcomb) in [#​297](https://github.com/opencost/opencost-helm-chart/pull/297) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.2...opencost-2.2.3> ### [`v2.2.2`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.2) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.1...opencost-2.2.2) OpenCost and OpenCost UI #### What's Changed - Advance to Opencost v1.117.0 by [@​mbolt35](https://github.com/mbolt35) in [#​296](https://github.com/opencost/opencost-helm-chart/pull/296) #### New Contributors - [@​mbolt35](https://github.com/mbolt35) made their first contribution in [#​296](https://github.com/opencost/opencost-helm-chart/pull/296) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.1...opencost-2.2.2> ### [`v2.2.1`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.1) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.0...opencost-2.2.1) OpenCost and OpenCost UI #### What's Changed - Add `insecureSkipVerify` to `prometheus.external` by [@​charleshu-8](https://github.com/charleshu-8) in [#​294](https://github.com/opencost/opencost-helm-chart/pull/294) #### New Contributors - [@​charleshu-8](https://github.com/charleshu-8) made their first contribution in [#​294](https://github.com/opencost/opencost-helm-chart/pull/294) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.0...opencost-2.2.1> ### [`v2.2.0`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.0) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.9...opencost-2.2.0) OpenCost and OpenCost UI #### What's Changed - Bump image tags and chart version by [@​cpetersen5](https://github.com/cpetersen5) in [#​291](https://github.com/opencost/opencost-helm-chart/pull/291) #### New Contributors - [@​cpetersen5](https://github.com/cpetersen5) made their first contribution in [#​291](https://github.com/opencost/opencost-helm-chart/pull/291) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.9...opencost-2.2.0> ### [`v2.1.9`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.9) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.8...opencost-2.1.9) OpenCost and OpenCost UI #### What's Changed - Change ETL env variable name by [@​Sean-Holcomb](https://github.com/Sean-Holcomb) in [#​285](https://github.com/opencost/opencost-helm-chart/pull/285) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.8...opencost-2.1.9> ### [`v2.1.8`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.8) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.7...opencost-2.1.8) OpenCost and OpenCost UI #### What's Changed - tweak params by [@​ameijer](https://github.com/ameijer) in [#​289](https://github.com/opencost/opencost-helm-chart/pull/289) - add option to override the default container command by [@​nishanthreddydd](https://github.com/nishanthreddydd) in [#​290](https://github.com/opencost/opencost-helm-chart/pull/290) #### New Contributors - [@​nishanthreddydd](https://github.com/nishanthreddydd) made their first contribution in [#​290](https://github.com/opencost/opencost-helm-chart/pull/290) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.7...opencost-2.1.8> ### [`v2.1.7`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.7) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.6...opencost-2.1.7) OpenCost and OpenCost UI #### What's Changed - (doc) update readme to easily install unittest by [@​karthik-suresh](https://github.com/karthik-suresh) in [#​284](https://github.com/opencost/opencost-helm-chart/pull/284) - Add ability to configure resolution for prometheus by [@​Sean-Holcomb](https://github.com/Sean-Holcomb) in [#​282](https://github.com/opencost/opencost-helm-chart/pull/282) - Add support for Pod Disruption Budget by [@​josephteddick](https://github.com/josephteddick) in [#​287](https://github.com/opencost/opencost-helm-chart/pull/287) #### New Contributors - [@​karthik-suresh](https://github.com/karthik-suresh) made their first contribution in [#​284](https://github.com/opencost/opencost-helm-chart/pull/284) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.6...opencost-2.1.7> ### [`v2.1.6`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.6) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.5...opencost-2.1.6) OpenCost and OpenCost UI #### What's Changed - feat(sec) - customize service account mounting by [@​cpsmx](https://github.com/cpsmx) in [#​283](https://github.com/opencost/opencost-helm-chart/pull/283) #### New Contributors - [@​cpsmx](https://github.com/cpsmx) made their first contribution in [#​283](https://github.com/opencost/opencost-helm-chart/pull/283) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.5...opencost-2.1.6> ### [`v2.1.5`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.5) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.4...opencost-2.1.5) OpenCost and OpenCost UI #### What's Changed - Update opencost ui 1.115.0 image by [@​mittal-ishaan](https://github.com/mittal-ishaan) in [#​281](https://github.com/opencost/opencost-helm-chart/pull/281) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.4...opencost-2.1.5> ### [`v2.1.4`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.4) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.3...opencost-2.1.4) OpenCost and OpenCost UI #### What's Changed - Bump OC to 1.115.0 by [@​mittal-ishaan](https://github.com/mittal-ishaan) in [#​277](https://github.com/opencost/opencost-helm-chart/pull/277) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.3...opencost-2.1.4> ### [`v2.1.3`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.3) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.2...opencost-2.1.3) OpenCost and OpenCost UI #### What's Changed - Promless Config by [@​Sean-Holcomb](https://github.com/Sean-Holcomb) in [#​275](https://github.com/opencost/opencost-helm-chart/pull/275) - Add values examples and notes to values.yaml. Update version numbers by [@​Sean-Holcomb](https://github.com/Sean-Holcomb) in [#​276](https://github.com/opencost/opencost-helm-chart/pull/276) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.2...opencost-2.1.3> ### [`v2.1.2`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.2) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.1...opencost-2.1.2) OpenCost and OpenCost UI #### What's Changed - Add support for API Ingress by [@​josephteddick](https://github.com/josephteddick) in [#​255](https://github.com/opencost/opencost-helm-chart/pull/255) #### New Contributors - [@​josephteddick](https://github.com/josephteddick) made their first contribution in [#​255](https://github.com/opencost/opencost-helm-chart/pull/255) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-parquet-exporter-0.2.0...opencost-2.1.2> ### [`v2.1.1`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.1) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.0...opencost-2.1.1) OpenCost and OpenCost UI #### What's Changed - Fix for [#​272](https://github.com/opencost/opencost-helm-chart/pull/272) to make feature flag actually work. by [@​tintii](https://github.com/tintii) in [#​274](https://github.com/opencost/opencost-helm-chart/pull/274) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.0...opencost-2.1.1> ### [`v2.1.0`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.0) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.0.2...opencost-2.1.0) OpenCost and OpenCost UI #### What's Changed - Openshift Security Context Constraints and updated ClusterRole with access to internal prometheus. by [@​v0nNemizez](https://github.com/v0nNemizez) in [#​267](https://github.com/opencost/opencost-helm-chart/pull/267) #### New Contributors - [@​v0nNemizez](https://github.com/v0nNemizez) made their first contribution in [#​267](https://github.com/opencost/opencost-helm-chart/pull/267) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.0.2...opencost-2.1.0> ### [`v2.0.2`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.0.2) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.0.1...opencost-2.0.2) OpenCost and OpenCost UI #### What's Changed - Add opencost.ui.useIPv6 feature flag by [@​tintii](https://github.com/tintii) in [#​272](https://github.com/opencost/opencost-helm-chart/pull/272) #### New Contributors - [@​tintii](https://github.com/tintii) made their first contribution in [#​272](https://github.com/opencost/opencost-helm-chart/pull/272) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.0.1...opencost-2.0.2> ### [`v2.0.1`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.0.1) [Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.0.0...opencost-2.0.1) OpenCost and OpenCost UI #### What's Changed - add sha256sums of configMaps to trigger a restart of the pod, if the configMap changes by [@​kastl-ars](https://github.com/kastl-ars) in [#​264](https://github.com/opencost/opencost-helm-chart/pull/264) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.0.0...opencost-2.0.1> ### [`v2.0.0`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.0.0) OpenCost and OpenCost UI #### What's Changed - add seperate openshift block to handle openshift related configurations and add frontend nginx config by [@​mittal-ishaan](https://github.com/mittal-ishaan) in [#​245](https://github.com/opencost/opencost-helm-chart/pull/245) - Updating chart badge by [@​TheUnixRoot](https://github.com/TheUnixRoot) in [#​261](https://github.com/opencost/opencost-helm-chart/pull/261) - Fix: Chart release script by [@​mittal-ishaan](https://github.com/mittal-ishaan) in [#​262](https://github.com/opencost/opencost-helm-chart/pull/262) #### New Contributors - [@​TheUnixRoot](https://github.com/TheUnixRoot) made their first contribution in [#​261](https://github.com/opencost/opencost-helm-chart/pull/261) **Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/1.45.0-helm...opencost-2.0.0> </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Oslo) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJicmVha2luZy1jaGFuZ2UiLCJyZW5vdmF0ZSJdfQ==--> --------- Co-authored-by: Renovate Bot <renovate@forteapps.net> Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/50 Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com> Co-authored-by: gitea_admin <admin@forteapps.net>
784 lines
31 KiB
YAML
784 lines
31 KiB
YAML
# Bitnami Keycloak Helm Chart Values
|
|
# Chart version: 25.2.0
|
|
|
|
image:
|
|
repository: bitnamilegacy/keycloak
|
|
|
|
production: true
|
|
proxyHeaders: xforwarded
|
|
|
|
auth:
|
|
adminUser: admin
|
|
existingSecret: keycloak-credentials
|
|
passwordSecretKey: admin-password
|
|
|
|
ingress:
|
|
enabled: true
|
|
tls: true
|
|
ingressClassName: traefik
|
|
annotations:
|
|
cert-manager.io/cluster-issuer: letsencrypt-prod
|
|
gethomepage.dev/enabled: "true"
|
|
gethomepage.dev/name: "Keycloak"
|
|
gethomepage.dev/description: "Identity & access management"
|
|
gethomepage.dev/group: "Security"
|
|
gethomepage.dev/icon: "keycloak"
|
|
gethomepage.dev/href: "https://id.forteapps.net/admin/forte-test/console/"
|
|
|
|
metrics:
|
|
enabled: true
|
|
prometheusRule:
|
|
namespace: monitoring
|
|
enabled: true
|
|
|
|
resources:
|
|
requests:
|
|
cpu: 250m
|
|
memory: 512Mi
|
|
limits:
|
|
cpu: 500m
|
|
memory: 1Gi
|
|
|
|
postgresql:
|
|
enabled: true
|
|
image:
|
|
repository: bitnamilegacy/postgresql
|
|
auth:
|
|
existingSecret: keycloak-credentials
|
|
secretKeys:
|
|
adminPasswordKey: postgres-password
|
|
userPasswordKey: password
|
|
username: bn_keycloak
|
|
database: bitnami_keycloak
|
|
primary:
|
|
persistence:
|
|
size: 8Gi
|
|
|
|
keycloakConfigCli:
|
|
enabled: true
|
|
image:
|
|
repository: bitnamilegacy/keycloak-config-cli
|
|
extraEnvVars:
|
|
- name: IMPORT_MANAGED_PROTOCOL_MAPPER
|
|
value: "no-delete"
|
|
configuration:
|
|
forte-realm.json: |
|
|
{
|
|
"realm": "forte",
|
|
"enabled": true,
|
|
"displayName": "Forte",
|
|
"sslRequired": "external",
|
|
"registrationAllowed": false,
|
|
"loginWithEmailAllowed": true,
|
|
"resetPasswordAllowed": true,
|
|
"rememberMe": true,
|
|
"clients": [
|
|
{
|
|
"clientId": "gitea",
|
|
"name": "Gitea",
|
|
"enabled": true,
|
|
"protocol": "openid-connect",
|
|
"clientAuthenticatorType": "client-secret",
|
|
"standardFlowEnabled": true,
|
|
"directAccessGrantsEnabled": false,
|
|
"publicClient": false,
|
|
"redirectUris": ["https://git.forteapps.net/*"],
|
|
"webOrigins": ["https://git.forteapps.net"],
|
|
"attributes": {
|
|
"k8s.secret.sync": "true",
|
|
"k8s.secret.namespace": "gitea",
|
|
"k8s.secret.name": "gitea-oidc-credentials",
|
|
"k8s.secret.client-id-key": "key",
|
|
"k8s.secret.client-secret-key": "secret"
|
|
},
|
|
"protocolMappers": [
|
|
{
|
|
"name": "email_verified",
|
|
"protocol": "openid-connect",
|
|
"protocolMapper": "oidc-hardcoded-claim-mapper",
|
|
"config": {
|
|
"claim.name": "email_verified",
|
|
"claim.value": "true",
|
|
"jsonType.label": "boolean",
|
|
"id.token.claim": "true",
|
|
"access.token.claim": "true",
|
|
"userinfo.token.claim": "true"
|
|
}
|
|
},
|
|
{
|
|
"name": "groups",
|
|
"protocol": "openid-connect",
|
|
"protocolMapper": "oidc-group-membership-mapper",
|
|
"config": {
|
|
"claim.name": "groups",
|
|
"full.path": "false",
|
|
"id.token.claim": "true",
|
|
"access.token.claim": "true",
|
|
"userinfo.token.claim": "true"
|
|
}
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"clientId": "grafana",
|
|
"name": "Grafana",
|
|
"enabled": true,
|
|
"protocol": "openid-connect",
|
|
"clientAuthenticatorType": "client-secret",
|
|
"standardFlowEnabled": true,
|
|
"directAccessGrantsEnabled": false,
|
|
"publicClient": false,
|
|
"redirectUris": ["https://grafana.forteapps.net/*"],
|
|
"webOrigins": ["https://grafana.forteapps.net"],
|
|
"attributes": {
|
|
"k8s.secret.sync": "true",
|
|
"k8s.secret.namespace": "monitoring",
|
|
"k8s.secret.name": "grafana-oidc-credentials",
|
|
"k8s.secret.client-id-key": "client-id",
|
|
"k8s.secret.client-secret-key": "client-secret"
|
|
},
|
|
"protocolMappers": [
|
|
{
|
|
"name": "client-roles",
|
|
"protocol": "openid-connect",
|
|
"protocolMapper": "oidc-usermodel-client-role-mapper",
|
|
"config": {
|
|
"claim.name": "resource_access.grafana.roles",
|
|
"jsonType.label": "String",
|
|
"multivalued": "true",
|
|
"usermodel.clientRoleMapping.clientId": "grafana",
|
|
"id.token.claim": "true",
|
|
"access.token.claim": "true",
|
|
"userinfo.token.claim": "true"
|
|
}
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"clientId": "argocd",
|
|
"name": "ArgoCD",
|
|
"enabled": true,
|
|
"protocol": "openid-connect",
|
|
"clientAuthenticatorType": "client-secret",
|
|
"standardFlowEnabled": true,
|
|
"directAccessGrantsEnabled": false,
|
|
"publicClient": false,
|
|
"redirectUris": ["https://argocd.forteapps.net/auth/callback"],
|
|
"webOrigins": ["https://argocd.forteapps.net"],
|
|
"attributes": {
|
|
"k8s.secret.sync": "true",
|
|
"k8s.secret.namespace": "argocd",
|
|
"k8s.secret.name": "argocd-oidc-credentials",
|
|
"k8s.secret.client-id-key": "client-id",
|
|
"k8s.secret.client-secret-key": "client-secret"
|
|
},
|
|
"protocolMappers": [
|
|
{
|
|
"name": "groups",
|
|
"protocol": "openid-connect",
|
|
"protocolMapper": "oidc-group-membership-mapper",
|
|
"config": {
|
|
"claim.name": "groups",
|
|
"full.path": "false",
|
|
"id.token.claim": "true",
|
|
"access.token.claim": "true",
|
|
"userinfo.token.claim": "true"
|
|
}
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"clientId": "forte-cli",
|
|
"name": "Forte CLI",
|
|
"description": "Shared public client for RFC 8628 device-code login from downloaded skills/CLI tools (forte-drop first) against services behind Auth Sidecar. No client secret.",
|
|
"enabled": true,
|
|
"protocol": "openid-connect",
|
|
"standardFlowEnabled": false,
|
|
"directAccessGrantsEnabled": false,
|
|
"publicClient": true,
|
|
"redirectUris": [],
|
|
"webOrigins": [],
|
|
"attributes": {
|
|
"oauth2.device.authorization.grant.enabled": "true"
|
|
},
|
|
"protocolMappers": [
|
|
{
|
|
"name": "audience-forte-drop-mcp",
|
|
"protocol": "openid-connect",
|
|
"protocolMapper": "oidc-audience-mapper",
|
|
"consentRequired": false,
|
|
"config": {
|
|
"included.custom.audience": "https://mcp.drop.forteapps.net/mcp",
|
|
"access.token.claim": "true",
|
|
"id.token.claim": "false",
|
|
"introspection.token.claim": "true"
|
|
}
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"browserFlow": "browser-auto-idp",
|
|
"authenticationFlows": [
|
|
{
|
|
"alias": "browser-auto-idp",
|
|
"description": "Browser flow with auto-redirect to Forte Entra IdP",
|
|
"providerId": "basic-flow",
|
|
"topLevel": true,
|
|
"builtIn": false,
|
|
"authenticationExecutions": [
|
|
{
|
|
"authenticator": "auth-cookie",
|
|
"authenticatorFlow": false,
|
|
"requirement": "ALTERNATIVE",
|
|
"priority": 10
|
|
},
|
|
{
|
|
"authenticator": "identity-provider-redirector",
|
|
"authenticatorFlow": false,
|
|
"requirement": "ALTERNATIVE",
|
|
"priority": 20,
|
|
"authenticatorConfig": "forte-entra-redirector"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"authenticatorConfig": [
|
|
{
|
|
"alias": "forte-entra-redirector",
|
|
"config": {
|
|
"defaultProvider": "forte-entra"
|
|
}
|
|
}
|
|
],
|
|
"groups": [
|
|
{
|
|
"name": "k8s",
|
|
"path": "/k8s",
|
|
"clientRoles": {
|
|
"grafana": ["Editor"]
|
|
}
|
|
},
|
|
{
|
|
"name": "dev",
|
|
"path": "/dev",
|
|
"clientRoles": {
|
|
"grafana": ["Viewer"]
|
|
}
|
|
},
|
|
{
|
|
"name": "ArgoCD Admins",
|
|
"path": "/ArgoCD Admins"
|
|
},
|
|
{
|
|
"name": "ArgoCD Viewers",
|
|
"path": "/ArgoCD Viewers"
|
|
}
|
|
]
|
|
}
|
|
|
|
extraDeploy:
|
|
# -- ServiceAccount for the client registrar CronJob
|
|
- apiVersion: v1
|
|
kind: ServiceAccount
|
|
metadata:
|
|
name: keycloak-client-registrar
|
|
namespace: keycloak
|
|
|
|
# -- ClusterRole granting access to secrets and namespaces
|
|
- apiVersion: rbac.authorization.k8s.io/v1
|
|
kind: ClusterRole
|
|
metadata:
|
|
name: keycloak-client-registrar
|
|
rules:
|
|
- apiGroups: [ "" ]
|
|
resources: [ "secrets" ]
|
|
verbs: [ "get", "list", "create", "update", "patch" ]
|
|
- apiGroups: [ "" ]
|
|
resources: [ "namespaces" ]
|
|
verbs: [ "get", "list" ]
|
|
|
|
# -- ClusterRoleBinding for the registrar ServiceAccount
|
|
- apiVersion: rbac.authorization.k8s.io/v1
|
|
kind: ClusterRoleBinding
|
|
metadata:
|
|
name: keycloak-client-registrar
|
|
roleRef:
|
|
apiGroup: rbac.authorization.k8s.io
|
|
kind: ClusterRole
|
|
name: keycloak-client-registrar
|
|
subjects:
|
|
- kind: ServiceAccount
|
|
name: keycloak-client-registrar
|
|
namespace: keycloak
|
|
|
|
# -- CronJob: registers Keycloak clients and syncs secrets
|
|
- apiVersion: batch/v1
|
|
kind: CronJob
|
|
metadata:
|
|
name: keycloak-client-registrar
|
|
namespace: keycloak
|
|
spec:
|
|
schedule: "*/2 * * * *"
|
|
timeZone: "Europe/Oslo"
|
|
concurrencyPolicy: Forbid
|
|
successfulJobsHistoryLimit: 1
|
|
failedJobsHistoryLimit: 3
|
|
jobTemplate:
|
|
spec:
|
|
backoffLimit: 3
|
|
template:
|
|
spec:
|
|
serviceAccountName: keycloak-client-registrar
|
|
restartPolicy: Never
|
|
containers:
|
|
- name: registrar
|
|
image: alpine:3.24
|
|
command: [ "/bin/sh", "-c" ]
|
|
args:
|
|
- |
|
|
set -e
|
|
apk add --no-cache curl jq > /dev/null 2>&1
|
|
|
|
KEYCLOAK_URL="http://keycloak:80"
|
|
REALM="forte"
|
|
K8S_API="https://kubernetes.default.svc"
|
|
SA_TOKEN=$(cat /var/run/secrets/kubernetes.io/serviceaccount/token)
|
|
CA_CERT="/var/run/secrets/kubernetes.io/serviceaccount/ca.crt"
|
|
CENTRAL_NS="secrets"
|
|
|
|
# --- Authenticate to Keycloak Admin API ---
|
|
ADMIN_USER="admin"
|
|
ADMIN_PASS=$(cat /secrets/admin-password)
|
|
|
|
echo "Authenticating to Keycloak..."
|
|
TOKEN=$(curl -sf -X POST "${KEYCLOAK_URL}/realms/master/protocol/openid-connect/token" \
|
|
-d "client_id=admin-cli" \
|
|
-d "username=${ADMIN_USER}" \
|
|
-d "password=${ADMIN_PASS}" \
|
|
-d "grant_type=password" | jq -r '.access_token')
|
|
|
|
if [ -z "$TOKEN" ] || [ "$TOKEN" = "null" ]; then
|
|
echo "ERROR: Failed to authenticate to Keycloak"
|
|
exit 1
|
|
fi
|
|
|
|
# --- Helper functions ---
|
|
|
|
# Upsert a K8s Secret: try PUT (update), fall back to POST (create)
|
|
upsert_secret() {
|
|
local ns="$1" name="$2" manifest="$3"
|
|
local code
|
|
code=$(curl -sf -o /dev/null -w "%{http_code}" \
|
|
--cacert "$CA_CERT" \
|
|
-H "Authorization: Bearer ${SA_TOKEN}" \
|
|
-H "Content-Type: application/json" \
|
|
-X PUT -d "$manifest" \
|
|
"${K8S_API}/api/v1/namespaces/${ns}/secrets/${name}")
|
|
if [ "$code" = "200" ]; then
|
|
echo " Updated secret '${ns}/${name}'"
|
|
elif [ "$code" = "404" ]; then
|
|
code=$(curl -sf -o /dev/null -w "%{http_code}" \
|
|
--cacert "$CA_CERT" \
|
|
-H "Authorization: Bearer ${SA_TOKEN}" \
|
|
-H "Content-Type: application/json" \
|
|
-X POST -d "$manifest" \
|
|
"${K8S_API}/api/v1/namespaces/${ns}/secrets")
|
|
if [ "$code" = "201" ]; then
|
|
echo " Created secret '${ns}/${name}'"
|
|
else
|
|
echo " ERROR: Failed to create secret '${ns}/${name}' (HTTP ${code})"
|
|
return 1
|
|
fi
|
|
else
|
|
echo " ERROR: Failed to update secret '${ns}/${name}' (HTTP ${code})"
|
|
return 1
|
|
fi
|
|
}
|
|
|
|
# Build a credential Secret JSON manifest
|
|
build_credential_secret() {
|
|
local ns="$1" name="$2" id_key="$3" secret_key="$4" b64_id="$5" b64_secret="$6"
|
|
cat <<MANIFEST
|
|
{
|
|
"apiVersion": "v1",
|
|
"kind": "Secret",
|
|
"metadata": {
|
|
"name": "${name}",
|
|
"namespace": "${ns}",
|
|
"labels": {
|
|
"app.kubernetes.io/managed-by": "keycloak-client-registrar"
|
|
}
|
|
},
|
|
"type": "Opaque",
|
|
"data": {
|
|
"${id_key}": "${b64_id}",
|
|
"${secret_key}": "${b64_secret}"
|
|
}
|
|
}
|
|
MANIFEST
|
|
}
|
|
|
|
# Sync credentials to target + central namespace
|
|
sync_credentials() {
|
|
local client_id="$1" client_uuid="$2" target_ns="$3" target_name="$4" id_key="$5" secret_key="$6"
|
|
|
|
# Get the client secret from Keycloak
|
|
local secret_value
|
|
secret_value=$(curl -sf -H "Authorization: Bearer ${TOKEN}" \
|
|
"${KEYCLOAK_URL}/admin/realms/${REALM}/clients/${client_uuid}/client-secret" \
|
|
| jq -r '.value')
|
|
|
|
if [ -z "$secret_value" ] || [ "$secret_value" = "null" ]; then
|
|
echo " WARNING: No secret found for client '${client_id}', skipping"
|
|
return 0
|
|
fi
|
|
|
|
local b64_id b64_secret
|
|
b64_id=$(printf '%s' "$client_id" | base64 | tr -d '\n')
|
|
b64_secret=$(printf '%s' "$secret_value" | base64 | tr -d '\n')
|
|
|
|
# Write to target namespace (if it exists)
|
|
local ns_status
|
|
ns_status=$(curl -sf -o /dev/null -w "%{http_code}" \
|
|
--cacert "$CA_CERT" \
|
|
-H "Authorization: Bearer ${SA_TOKEN}" \
|
|
"${K8S_API}/api/v1/namespaces/${target_ns}")
|
|
|
|
if [ "$ns_status" = "200" ]; then
|
|
local manifest
|
|
manifest=$(build_credential_secret "$target_ns" "$target_name" "$id_key" "$secret_key" "$b64_id" "$b64_secret")
|
|
upsert_secret "$target_ns" "$target_name" "$manifest" || return 1
|
|
else
|
|
echo " WARNING: Namespace '${target_ns}' does not exist, skipping target"
|
|
fi
|
|
|
|
# Always write a central copy to the secrets namespace
|
|
local central_manifest
|
|
central_manifest=$(build_credential_secret "$CENTRAL_NS" "$target_name" "$id_key" "$secret_key" "$b64_id" "$b64_secret")
|
|
upsert_secret "$CENTRAL_NS" "$target_name" "$central_manifest" || return 1
|
|
}
|
|
|
|
# Annotate a K8s Secret with sync status
|
|
annotate_secret() {
|
|
local ns="$1" name="$2" key="$3" value="$4"
|
|
local patch
|
|
patch=$(printf '{"metadata":{"annotations":{"%s":"%s"}}}' "$key" "$value")
|
|
curl -sf -o /dev/null \
|
|
--cacert "$CA_CERT" \
|
|
-H "Authorization: Bearer ${SA_TOKEN}" \
|
|
-H "Content-Type: application/strategic-merge-patch+json" \
|
|
-X PATCH -d "$patch" \
|
|
"${K8S_API}/api/v1/namespaces/${ns}/secrets/${name}"
|
|
}
|
|
|
|
# =============================================
|
|
# LEGACY PATH — sync existing realm clients
|
|
# =============================================
|
|
echo "=== Legacy sync: clients with k8s.secret.sync=true ==="
|
|
|
|
CLIENTS=$(curl -sf -H "Authorization: Bearer ${TOKEN}" \
|
|
"${KEYCLOAK_URL}/admin/realms/${REALM}/clients")
|
|
|
|
SYNC_CLIENTS=$(echo "$CLIENTS" | jq -c '[.[] | select(.attributes["k8s.secret.sync"] == "true")]')
|
|
COUNT=$(echo "$SYNC_CLIENTS" | jq 'length')
|
|
echo "Found ${COUNT} legacy client(s) with sync enabled"
|
|
|
|
echo "$SYNC_CLIENTS" | jq -c '.[]' | while read -r CLIENT; do
|
|
CLIENT_ID=$(echo "$CLIENT" | jq -r '.clientId')
|
|
CLIENT_UUID=$(echo "$CLIENT" | jq -r '.id')
|
|
TARGET_NS=$(echo "$CLIENT" | jq -r '.attributes["k8s.secret.namespace"]')
|
|
TARGET_NAME=$(echo "$CLIENT" | jq -r '.attributes["k8s.secret.name"]')
|
|
ID_KEY=$(echo "$CLIENT" | jq -r '.attributes["k8s.secret.client-id-key"] // "client-id"')
|
|
SECRET_KEY=$(echo "$CLIENT" | jq -r '.attributes["k8s.secret.client-secret-key"] // "client-secret"')
|
|
|
|
echo "Processing legacy client '${CLIENT_ID}' -> '${TARGET_NS}/${TARGET_NAME}' (keys: ${ID_KEY}, ${SECRET_KEY})"
|
|
sync_credentials "$CLIENT_ID" "$CLIENT_UUID" "$TARGET_NS" "$TARGET_NAME" "$ID_KEY" "$SECRET_KEY"
|
|
done
|
|
|
|
# =============================================
|
|
# NEW PATH — self-service config Secrets
|
|
# =============================================
|
|
echo ""
|
|
echo "=== Self-service: config Secrets with label keycloak.forteapps.net/client-config=true ==="
|
|
|
|
CONFIG_SECRETS=$(curl -sf \
|
|
--cacert "$CA_CERT" \
|
|
-H "Authorization: Bearer ${SA_TOKEN}" \
|
|
"${K8S_API}/api/v1/namespaces/keycloak/secrets?labelSelector=keycloak.forteapps.net/client-config=true")
|
|
|
|
CONFIG_COUNT=$(echo "$CONFIG_SECRETS" | jq '.items | length')
|
|
echo "Found ${CONFIG_COUNT} config Secret(s) to process"
|
|
|
|
echo "$CONFIG_SECRETS" | jq -c '.items[]' | while read -r CONFIG_SECRET; do
|
|
CONFIG_NAME=$(echo "$CONFIG_SECRET" | jq -r '.metadata.name')
|
|
SOURCE_NS=$(echo "$CONFIG_SECRET" | jq -r '.metadata.annotations["keycloak.forteapps.net/source-namespace"] // .metadata.labels["keycloak.forteapps.net/source-namespace"] // "unknown"')
|
|
|
|
# Decode client.json from the Secret data
|
|
CLIENT_JSON_B64=$(echo "$CONFIG_SECRET" | jq -r '.data["client.json"] // empty')
|
|
if [ -z "$CLIENT_JSON_B64" ]; then
|
|
echo "WARNING: Config Secret '${CONFIG_NAME}' missing client.json field, skipping"
|
|
continue
|
|
fi
|
|
CLIENT_JSON=$(printf '%s' "$CLIENT_JSON_B64" | base64 -d)
|
|
|
|
CLIENT_ID=$(echo "$CLIENT_JSON" | jq -r '.clientId')
|
|
echo "Processing self-service client '${CLIENT_ID}' from config '${CONFIG_NAME}'"
|
|
|
|
# Compute config hash for change detection
|
|
CONFIG_HASH=$(printf '%s' "$CLIENT_JSON" | sha256sum | cut -d' ' -f1)
|
|
EXISTING_HASH=$(echo "$CONFIG_SECRET" | jq -r '.metadata.annotations["keycloak.forteapps.net/config-hash"] // ""')
|
|
|
|
# Extract secret delivery config from client.json
|
|
CRED_NS=$(echo "$CLIENT_JSON" | jq -r '.secret.namespace // "'"${SOURCE_NS}"'"')
|
|
CRED_NAME=$(echo "$CLIENT_JSON" | jq -r '.secret.name // "'"${CLIENT_ID}"'-oidc-credentials"')
|
|
CRED_ID_KEY=$(echo "$CLIENT_JSON" | jq -r '.secret.keys.clientId // "client-id"')
|
|
CRED_SECRET_KEY=$(echo "$CLIENT_JSON" | jq -r '.secret.keys.clientSecret // "client-secret"')
|
|
|
|
# Check if credential Secret already exists in target namespace
|
|
CRED_EXISTS=$(curl -s -o /dev/null -w "%{http_code}" \
|
|
--cacert "$CA_CERT" \
|
|
-H "Authorization: Bearer ${SA_TOKEN}" \
|
|
"${K8S_API}/api/v1/namespaces/${CRED_NS}/secrets/${CRED_NAME}" || echo "000")
|
|
|
|
# Skip if hash matches and credential Secret exists
|
|
if [ "$CONFIG_HASH" = "$EXISTING_HASH" ] && [ "$CRED_EXISTS" = "200" ]; then
|
|
echo " No changes detected, skipping"
|
|
continue
|
|
fi
|
|
|
|
# Build Keycloak client representation (strip our secret delivery config)
|
|
KC_CLIENT=$(echo "$CLIENT_JSON" | jq '{
|
|
clientId: .clientId,
|
|
name: .name,
|
|
enabled: true,
|
|
protocol: "openid-connect",
|
|
clientAuthenticatorType: "client-secret",
|
|
standardFlowEnabled: true,
|
|
directAccessGrantsEnabled: false,
|
|
publicClient: false,
|
|
redirectUris: .redirectUris,
|
|
webOrigins: .webOrigins,
|
|
protocolMappers: (.protocolMappers // [])
|
|
} | with_entries(select(.value != null))')
|
|
|
|
# Check if client already exists
|
|
EXISTING_RESPONSE=$(curl -s -H "Authorization: Bearer ${TOKEN}" \
|
|
"${KEYCLOAK_URL}/admin/realms/${REALM}/clients?clientId=${CLIENT_ID}" || true)
|
|
EXISTING=$(echo "$EXISTING_RESPONSE" | jq -r '.[0].id // empty' 2>/dev/null || true)
|
|
|
|
if [ -n "$EXISTING" ]; then
|
|
echo " Updating existing Keycloak client (uuid: ${EXISTING})"
|
|
RESPONSE=$(curl -s -w "\n%{http_code}" \
|
|
-H "Authorization: Bearer ${TOKEN}" \
|
|
-H "Content-Type: application/json" \
|
|
-X PUT -d "$KC_CLIENT" \
|
|
"${KEYCLOAK_URL}/admin/realms/${REALM}/clients/${EXISTING}" || true)
|
|
HTTP_CODE=$(echo "$RESPONSE" | tail -1)
|
|
RESPONSE_BODY=$(echo "$RESPONSE" | sed '$d')
|
|
if [ "$HTTP_CODE" != "204" ] && [ "$HTTP_CODE" != "200" ]; then
|
|
echo " ERROR: Failed to update client '${CLIENT_ID}' (HTTP ${HTTP_CODE}): ${RESPONSE_BODY}"
|
|
annotate_secret "keycloak" "$CONFIG_NAME" "keycloak.forteapps.net/sync-status" "error"
|
|
continue
|
|
fi
|
|
CLIENT_UUID="$EXISTING"
|
|
else
|
|
echo " Creating new Keycloak client '${CLIENT_ID}'"
|
|
RESPONSE=$(curl -s -w "\n%{http_code}" \
|
|
-H "Authorization: Bearer ${TOKEN}" \
|
|
-H "Content-Type: application/json" \
|
|
-X POST -d "$KC_CLIENT" \
|
|
"${KEYCLOAK_URL}/admin/realms/${REALM}/clients" || true)
|
|
HTTP_CODE=$(echo "$RESPONSE" | tail -1)
|
|
RESPONSE_BODY=$(echo "$RESPONSE" | sed '$d')
|
|
if [ "$HTTP_CODE" != "201" ]; then
|
|
echo " ERROR: Failed to create client '${CLIENT_ID}' (HTTP ${HTTP_CODE}): ${RESPONSE_BODY}"
|
|
annotate_secret "keycloak" "$CONFIG_NAME" "keycloak.forteapps.net/sync-status" "error"
|
|
continue
|
|
fi
|
|
# Fetch the newly created client's UUID
|
|
CLIENT_UUID=$(curl -s -H "Authorization: Bearer ${TOKEN}" \
|
|
"${KEYCLOAK_URL}/admin/realms/${REALM}/clients?clientId=${CLIENT_ID}" \
|
|
| jq -r '.[0].id' || true)
|
|
fi
|
|
|
|
# Sync credentials to target namespace
|
|
sync_credentials "$CLIENT_ID" "$CLIENT_UUID" "$CRED_NS" "$CRED_NAME" "$CRED_ID_KEY" "$CRED_SECRET_KEY"
|
|
|
|
# Annotate config Secret with hash and sync status
|
|
annotate_secret "keycloak" "$CONFIG_NAME" "keycloak.forteapps.net/config-hash" "$CONFIG_HASH"
|
|
annotate_secret "keycloak" "$CONFIG_NAME" "keycloak.forteapps.net/sync-status" "synced"
|
|
TIMESTAMP=$(date -u +"%Y-%m-%dT%H:%M:%SZ")
|
|
annotate_secret "keycloak" "$CONFIG_NAME" "keycloak.forteapps.net/last-sync" "$TIMESTAMP"
|
|
echo " Synced successfully"
|
|
done
|
|
|
|
echo ""
|
|
echo "Client registrar run complete"
|
|
volumeMounts:
|
|
- name: keycloak-credentials
|
|
mountPath: /secrets
|
|
readOnly: true
|
|
resources:
|
|
requests:
|
|
cpu: 50m
|
|
memory: 64Mi
|
|
limits:
|
|
cpu: 200m
|
|
memory: 128Mi
|
|
volumes:
|
|
- name: keycloak-credentials
|
|
secret:
|
|
secretName: keycloak-credentials
|
|
items:
|
|
- key: admin-password
|
|
path: admin-password
|
|
|
|
# -- ServiceAccount for the client cleanup CronJob
|
|
- apiVersion: v1
|
|
kind: ServiceAccount
|
|
metadata:
|
|
name: keycloak-client-cleanup
|
|
namespace: keycloak
|
|
|
|
# -- CronJob: cleans up stale dynamically registered Keycloak clients
|
|
- apiVersion: batch/v1
|
|
kind: CronJob
|
|
metadata:
|
|
name: keycloak-client-cleanup
|
|
namespace: keycloak
|
|
spec:
|
|
schedule: "0 3 1 * *"
|
|
timeZone: "Europe/Oslo"
|
|
startingDeadlineSeconds: 3600
|
|
concurrencyPolicy: Forbid
|
|
successfulJobsHistoryLimit: 1
|
|
failedJobsHistoryLimit: 3
|
|
jobTemplate:
|
|
spec:
|
|
backoffLimit: 3
|
|
template:
|
|
spec:
|
|
serviceAccountName: keycloak-client-cleanup
|
|
restartPolicy: Never
|
|
containers:
|
|
- name: cleanup
|
|
image: alpine:3.24
|
|
command: [ "/bin/sh", "-c" ]
|
|
args:
|
|
- |
|
|
set -e
|
|
apk add --no-cache curl jq > /dev/null 2>&1
|
|
|
|
KEYCLOAK_URL="http://keycloak:80"
|
|
REALM="forte"
|
|
ADMIN_USER="admin"
|
|
ADMIN_PASS=$(cat /secrets/admin-password)
|
|
DRY_RUN="${DRY_RUN:-true}"
|
|
MIN_AGE_DAYS="${MIN_AGE_DAYS:-14}"
|
|
if [ -z "$CLIENT_ID_PATTERN" ]; then
|
|
CLIENT_ID_PATTERN='^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'
|
|
fi
|
|
|
|
echo "=== Keycloak DCR client cleanup ==="
|
|
echo "Dry run: ${DRY_RUN}"
|
|
echo "Min age: ${MIN_AGE_DAYS} days"
|
|
echo "Pattern: ${CLIENT_ID_PATTERN}"
|
|
|
|
# Authenticate to Keycloak Admin API
|
|
TOKEN=$(curl -sf -X POST "${KEYCLOAK_URL}/realms/master/protocol/openid-connect/token" \
|
|
-d "client_id=admin-cli" \
|
|
-d "username=${ADMIN_USER}" \
|
|
-d "password=${ADMIN_PASS}" \
|
|
-d "grant_type=password" | jq -r '.access_token')
|
|
|
|
if [ -z "$TOKEN" ] || [ "$TOKEN" = "null" ]; then
|
|
echo "ERROR: Failed to authenticate to Keycloak"
|
|
exit 1
|
|
fi
|
|
|
|
NOW_SEC=$(date +%s)
|
|
MIN_AGE_SEC=$((MIN_AGE_DAYS * 86400))
|
|
|
|
# Hardcoded protected clients (never delete these)
|
|
PROTECTED_JSON='["gitea","grafana","argocd","forte-cli","vaultwarden","account","account-console","admin-cli","broker","realm-management","security-admin-console"]'
|
|
|
|
echo "Fetching clients from realm '${REALM}'..."
|
|
CLIENTS=$(curl -sf -H "Authorization: Bearer ${TOKEN}" \
|
|
"${KEYCLOAK_URL}/admin/realms/${REALM}/clients")
|
|
|
|
CANDIDATES=$(echo "$CLIENTS" | jq -c --argjson protected "$PROTECTED_JSON" \
|
|
--argjson now "$NOW_SEC" --argjson min_age "$MIN_AGE_SEC" --arg pattern "$CLIENT_ID_PATTERN" '
|
|
[
|
|
.[]
|
|
| select(.clientId as $cid | $protected | index($cid) | not)
|
|
| select(.attributes["k8s.secret.sync"] != "true")
|
|
| select(.clientId | test($pattern; "i"))
|
|
| select(.attributes["client.secret.creation.time"] != null)
|
|
| select((.attributes["client.secret.creation.time"] | tonumber) < ($now - $min_age))
|
|
]
|
|
')
|
|
|
|
COUNT=$(echo "$CANDIDATES" | jq 'length')
|
|
echo "Found ${COUNT} candidate client(s) matching pattern and age threshold"
|
|
|
|
if [ "$COUNT" -eq 0 ]; then
|
|
echo "Nothing to clean up."
|
|
exit 0
|
|
fi
|
|
|
|
while IFS= read -r CLIENT; do
|
|
CLIENT_ID=$(echo "$CLIENT" | jq -r '.clientId')
|
|
CLIENT_UUID=$(echo "$CLIENT" | jq -r '.id')
|
|
CREATED=$(echo "$CLIENT" | jq -r '.createdTimestamp')
|
|
|
|
# Check active sessions
|
|
SESSION_RESPONSE=$(curl -s -H "Authorization: Bearer ${TOKEN}" \
|
|
"${KEYCLOAK_URL}/admin/realms/${REALM}/clients/${CLIENT_UUID}/session-count" || true)
|
|
SESSION_COUNT=$(echo "$SESSION_RESPONSE" | jq -r '.count // 0')
|
|
|
|
if [ "$SESSION_COUNT" -gt 0 ]; then
|
|
echo " SKIP: '${CLIENT_ID}' has ${SESSION_COUNT} active session(s)"
|
|
continue
|
|
fi
|
|
|
|
AGE_DAYS=$(( (NOW_SEC - (CREATED / 1000)) / 86400 ))
|
|
|
|
if [ "$DRY_RUN" = "true" ]; then
|
|
echo " DRY-RUN: would delete '${CLIENT_ID}' (uuid: ${CLIENT_UUID}, age: ${AGE_DAYS}d)"
|
|
else
|
|
echo " DELETE: '${CLIENT_ID}' (uuid: ${CLIENT_UUID}, age: ${AGE_DAYS}d)"
|
|
HTTP_CODE=$(curl -s -o /dev/null -w "%{http_code}" \
|
|
-H "Authorization: Bearer ${TOKEN}" \
|
|
-X DELETE \
|
|
"${KEYCLOAK_URL}/admin/realms/${REALM}/clients/${CLIENT_UUID}" || echo "000")
|
|
if [ "$HTTP_CODE" != "204" ] && [ "$HTTP_CODE" != "200" ]; then
|
|
echo " ERROR: Failed to delete '${CLIENT_ID}' (HTTP ${HTTP_CODE})"
|
|
fi
|
|
fi
|
|
done < <(echo "$CANDIDATES" | jq -c '.[]')
|
|
|
|
echo "Cleanup run complete."
|
|
env:
|
|
- name: DRY_RUN
|
|
value: "false"
|
|
- name: MIN_AGE_DAYS
|
|
value: "60"
|
|
volumeMounts:
|
|
- name: keycloak-credentials
|
|
mountPath: /secrets
|
|
readOnly: true
|
|
resources:
|
|
requests:
|
|
cpu: 50m
|
|
memory: 64Mi
|
|
limits:
|
|
cpu: 200m
|
|
memory: 128Mi
|
|
volumes:
|
|
- name: keycloak-credentials
|
|
secret:
|
|
secretName: keycloak-credentials
|
|
items:
|
|
- key: admin-password
|
|
path: admin-password
|