v1.3.0
Cloud one-click trial deploys, first-review product tour, and Scorecard publish fix.
Added
- First-review product tour — guided spotlight walkthrough (driver.js) after first login:
Models → Connectors → Gate → Findings. Completion/skip dual-written tousers.preferences
(productTour.firstReviewStatus) and browser localStorage (hard-refresh safe); replay from
Account → Replay product tour. Closing mid-tour (X) toasts how to restart.
Migration014_user_preferences.sql;PATCH /v1/auth/me/preferences(all signed-in roles).
Popover follows light/dark theme tokens. - Cloud one-click trial deploys — shared single-VM stack under
deploy/cloud/
(nginx edge HTTPS + Keycloak OIDC + API/worker/UI + Postgres). No LLM key at install (Models UI).
Self-signed TLS by default (PKCE /crypto.subtle); optionalDOMAINfor cert CN.- AWS CloudFormation Launch Stack (
deploy/cloud/aws/) - Azure Bicep/ARM Deploy (
deploy/cloud/azure/) - GCP Cloud Shell +
gcloud(deploy/cloud/gcp/) - DigitalOcean Marketplace 1-Click vendor assets (
deploy/cloud/do/)
- AWS CloudFormation Launch Stack (
Fixed
- Cloud trial deploys (
deploy/cloud/): production-shaped single-VM path hardened after Azure pilot:- nginx edge (HTTPS self-signed) instead of Traefik (Docker Engine 29 API incompatibility)
- SPA OIDC: ignore bake-time localhost issuer off-loopback; empty UI Dockerfile OIDC defaults
- nginx routes
/auth/callbackto UI (Keycloak is under/auth/*) - Keycloak Admin issuer parse supports path-based
/auth/realms/...(org create) - first-boot: quoted
.env, IaC placeholder sanitization, Azure IMDS, always-HTTPS for PKCE - Azure cloud-init via Bicep
format()+ NSG on NIC
- Product tour UX — sidebar nav scroll for Models/Connectors; step counter no longer resets on
SPA navigation; “Configure a provider” targets provider API keys (not the stage matrix);
dark-mode button hover contrast on popover controls. - CI — OpenSSF Scorecard job uses only
uses:steps whenpublish_results: true(OpenSSF
workflow verification; shell retry steps caused 400 “scorecard job must only have steps with uses”). - Code scanning — pin Docker base images and Keycloak workflow actions by digest/SHA;
Confluence HTML strip handles</script…>end tags; git clone SHA fetch restricted to object ids +
checkout --; remove empty Keycloak password field from Helm values; drop unused locals flagged by CodeQL.
Container images
docker pull ghcr.io/codesteward/codesteward:1.3.0
docker pull ghcr.io/codesteward/codesteward/ui:1.3.0
docker pull ghcr.io/codesteward/codesteward/keycloak:26.7.0 # tag = upstream Keycloak, not product 1.3.0App image runs API by default (SERVICE=api). Worker:
docker run --rm -e SERVICE=worker ghcr.io/codesteward/codesteward:1.3.0Keycloak image tags match upstream Keycloak (theme + realm baked in; no git mounts):
docker run --rm -p 8083:8083 -e KEYCLOAK_ADMIN=admin -e KEYCLOAK_ADMIN_PASSWORD=admin \
ghcr.io/codesteward/codesteward/keycloak:26.7.0 start-dev --import-realm --http-port=8083Helm chart (OCI on GHCR)
helm install codesteward oci://ghcr.io/codesteward/codesteward/charts/codesteward --version 1.3.0
# or: helm pull oci://ghcr.io/codesteward/codesteward/charts/codesteward --version 1.3.0Chart package is also attached to this release as codesteward-1.3.0.tgz.
Docs: Kubernetes quick start in the product documentation site.
Images are signed with cosign keyless via GitHub OIDC.
Verify with:
cosign verify ghcr.io/codesteward/codesteward:1.3.0 \
--certificate-identity-regexp 'https://github.com/Codesteward/codesteward/.*' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com