Releases: cloudkeel/cloudkeel-dd
Release list
Cloudkeel-DD 0.3.7
What changed since 0.3.6
App-only release — no chart template or values.yaml changes.
Backend:
- Type-coverage gaps that can never be closed no longer PARTIAL a scan forever (#136)
- AWS unmanaged-resource detection now sweeps in AWS-owned IAM managed policies (#138)
- GCP default-network auto-created subnets/routes are suppressed as baseline noise (#139)
- Integrations list now exposes each integration's enabled subscription/account/project scope names (#140)
- Kubernetes resources adopted by ArgoCD or Flux now correctly resolve their "unmanaged" finding, matching existing Helm-adoption behavior (#142)
Frontend:
- Owner-team field now suggests known teams instead of pure free text (#141.1)
- Drift event drawer links directly to ownership editing (#141.2)
- Bulk ownership assignment: select multiple resources and set ownership fields in one action (#141.4)
- Integrations list groups by cloud family and shows scope identity (#140)
Verification
Both images were already verified live on the pilot at these exact commits before this release was cut.
driftdetective/ddetective-backend:0.3.7—sha256:1ee54b7562ef4ba2b90a98b5a5f8580420cd3c95cfb35e895a5a928a31fcd301driftdetective/ddetective-frontend:0.3.7—sha256:d1f97f1b4aa2b9df77c6c414a4c56d96941dc944e6d63e58f43cfded2dc537be
Both multi-arch (linux/amd64, linux/arm64). Chart pulls and templates cleanly:
helm show chart oci://registry-1.docker.io/driftdetective/d-detective --version 0.3.7
Cloudkeel-DD 0.3.6
Cloudkeel-DD 0.3.6
Security fix release, plus a batch of correctness and AWS-coverage fixes.
helm install dd oci://registry-1.docker.io/driftdetective/d-detective --version 0.3.6 \
--namespace ddetective --create-namespace \
--set secrets.fernetKey="$FERNET" \
--set secrets.dataKeyWrapped="$DATAKEY" \
--set secrets.jwtSecret="$JWT" \
--set postgresql.auth.password="$(openssl rand -hex 16)"Security
- Fixed a cross-tenant issue in GitHub/GitLab remediation: an
instance-wide remediation token combined with an unvalidated target
repository could let one tenant's remediation reach another tenant's repo.
0.3.5 shipped a narrower guardrail for this; 0.3.6 is the full fix.
If you run multi-tenant with GitHub/GitLab remediation enabled, upgrade.
Other fixes since 0.3.5
- A registration race under concurrency could let two simultaneous
registrations both create a workspace — now guarded. - AWS baseline-exclusion improvements: service-linked IAM roles now match by
name, and every VPC's auto-created "Main" route table is now recognized
(the AWS API this used never exposed it at all — reads via a different API
now). - AWS gets a real per-resource live cross-check on the Terraform-plan scan
path, matching what Azure/GCP already had. - Several drift-event and dashboard-tile attribution fixes (misattributed
tiles, a GCP subnetwork region collision inflating drift counts, live scan
progress visibility). - Standalone IAM-role/S3-bucket Terraform resources now merge correctly
instead of reporting false drift against an incomplete payload. - GCP key expiry and AWS key age now surfaced in findings.
No chart template, values.yaml default, or licensing/pricing behavior
changed in this release.
Verification
- Full backend test suite passed (4,300 tests) and a live end-to-end pass
against real Azure/AWS/GCP test accounts, with zero regressions. - Confirmed on the registry by digest, not tag name:
driftdetective/ddetective-backend:0.3.6→sha256:72c7cfb89139c4fe862025f1b697c2e32e572e3c355328474573b48762f94d45driftdetective/ddetective-frontend:0.3.6→sha256:de512698da2d1e8c75ee5a797df278ac08d9139238f05099fc9ae099234d5984
Cloudkeel-DD 0.3.5
Cloudkeel-DD 0.3.5
Security-hardening release (Epic E14), plus a frontend framework upgrade.
helm install dd oci://registry-1.docker.io/driftdetective/d-detective --version 0.3.5 \
--namespace ddetective --create-namespace \
--set secrets.fernetKey="$FERNET" \
--set secrets.dataKeyWrapped="$DATAKEY" \
--set secrets.jwtSecret="$JWT" \
--set postgresql.auth.password="$(openssl rand -hex 16)"What changed since 0.3.4
- A batch of backend security hardening fixes.
- A narrower guardrail for the cross-tenant remediation-token issue later
fully fixed in 0.3.6. - Frontend upgraded from Next.js 14 to 16.3.3.
- Five security response headers on by default (
X-Frame-Options, CSP, HSTS,
X-Content-Type-Options,Referrer-Policy).
No licensing or pricing behavior changed in this release — the 0.3.4
degrade-to-Free timer is untouched.
Verification
- Confirmed on the registry by digest, not tag name:
driftdetective/ddetective-backend:0.3.5→sha256:3ec89723b917b064da10e165ee03e8d5ce6efe51e701015449af8d27f7d585d7driftdetective/ddetective-frontend:0.3.5→sha256:737a5cb855b25123eaf3ca2010a6028a3af407d6dcf46a2b50e4008810def316
Cloudkeel-DD 0.3.4
Cloudkeel-DD 0.3.4
The licensing release — a self-serve install now runs unmetered for 30 days,
then converts to a Free tier (1 enabled scope, 3 users, every feature)
instead of stopping. Nothing is deleted and running scans finish either way.
helm install dd oci://registry-1.docker.io/driftdetective/d-detective --version 0.3.4 \
--namespace ddetective --create-namespace \
--set secrets.fernetKey="$FERNET" \
--set secrets.dataKeyWrapped="$DATAKEY" \
--set secrets.jwtSecret="$JWT" \
--set postgresql.auth.password="$(openssl rand -hex 16)"What changed since 0.3.2
- Signed offline licence key format and verifier.
- Scope gate and seat gate for the Free/Team/Enterprise tiers.
- Trial expiry now degrades to the Free ceiling rather than stopping scans.
- A Settings → Licence page showing trial/plan status.
secrets.licenseKeychart value plus the keygen script.- Closed self-registration after the first tenant, plus several smaller fixes.
- Two Alembic migrations since 0.3.2, one of which deletes duplicate pending
invites.
Verification
- Confirmed on the registry by digest, not tag name:
driftdetective/ddetective-backend:0.3.4→sha256:5e80be066d4d52d39d7385bf7fa9dc062fb70fc6abf022fbe7485992954f07fcdriftdetective/ddetective-frontend:0.3.4→sha256:361d8496fb620f9e786000c1bcd802aae5072c71221613b43422ff2dd50e5995
Known limitation
Licence keys are optional — without one, the install runs its unmetered
window and then the Free tier, and never stops working.
Cloudkeel-DD 0.3.2
Cloudkeel-DD 0.3.2
Patch release — one additive migration and six fixes since 0.3.1.
helm install dd oci://registry-1.docker.io/driftdetective/d-detective --version 0.3.2 \
--namespace ddetective --create-namespace \
--set secrets.fernetKey="$FERNET" \
--set secrets.dataKeyWrapped="$DATAKEY" \
--set secrets.jwtSecret="$JWT" \
--set postgresql.auth.password="$(openssl rand -hex 16)"What changed since 0.3.1
- A denied IAM permission no longer looks like "no actor found" (adds
scans.capability_warnings). - Slack was deleting the value from every widened-security-rule alert
(markdown ate the asterisks) — failed sends now log instead of vanishing. - Adoption now closes the unmanaged finding it makes unreachable — that
finding was previously unclosable by any code path. - Cross-source verification counts AWS and GCP, not only Azure.
- Observation partitions trapped outside the create-ahead window recover.
- The chart's policy check now loads the rendered ConfigMap into a real OPA
instance instead of a static check. - A rejected settings toggle is surfaced rather than silently swallowed.
Verification
- One additive Alembic migration only (
capability_warnings) — measured by
diffingalembic/versions/against the prior published build, not assumed. - Confirmed on the registry by digest, not tag name:
driftdetective/ddetective-backend:0.3.2→sha256:6fdb9ce142340c66bcaa13a5736037e802cb7a2e4bedf658421eeca353408dc7driftdetective/ddetective-frontend:0.3.2→sha256:d6a037cc1d029c2312ef54011dc6cc1322d271060d319dd01e1592669d5ca2c7