Skip to content

Releases: cloudkeel/cloudkeel-dd

Cloudkeel-DD 0.3.7

Choose a tag to compare

@cloudkeel cloudkeel released this 30 Aug 17:29

What changed since 0.3.6

App-only release — no chart template or values.yaml changes.

Backend:

  • Type-coverage gaps that can never be closed no longer PARTIAL a scan forever (#136)
  • AWS unmanaged-resource detection now sweeps in AWS-owned IAM managed policies (#138)
  • GCP default-network auto-created subnets/routes are suppressed as baseline noise (#139)
  • Integrations list now exposes each integration's enabled subscription/account/project scope names (#140)
  • Kubernetes resources adopted by ArgoCD or Flux now correctly resolve their "unmanaged" finding, matching existing Helm-adoption behavior (#142)

Frontend:

  • Owner-team field now suggests known teams instead of pure free text (#141.1)
  • Drift event drawer links directly to ownership editing (#141.2)
  • Bulk ownership assignment: select multiple resources and set ownership fields in one action (#141.4)
  • Integrations list groups by cloud family and shows scope identity (#140)

Verification

Both images were already verified live on the pilot at these exact commits before this release was cut.

  • driftdetective/ddetective-backend:0.3.7 — sha256:1ee54b7562ef4ba2b90a98b5a5f8580420cd3c95cfb35e895a5a928a31fcd301
  • driftdetective/ddetective-frontend:0.3.7 — sha256:d1f97f1b4aa2b9df77c6c414a4c56d96941dc944e6d63e58f43cfded2dc537be

Both multi-arch (linux/amd64, linux/arm64). Chart pulls and templates cleanly:

helm show chart oci://registry-1.docker.io/driftdetective/d-detective --version 0.3.7

Cloudkeel-DD 0.3.6

Choose a tag to compare

@cloudkeel cloudkeel released this 29 Aug 10:49

Cloudkeel-DD 0.3.6

Security fix release, plus a batch of correctness and AWS-coverage fixes.

helm install dd oci://registry-1.docker.io/driftdetective/d-detective --version 0.3.6 \
  --namespace ddetective --create-namespace \
  --set secrets.fernetKey="$FERNET" \
  --set secrets.dataKeyWrapped="$DATAKEY" \
  --set secrets.jwtSecret="$JWT" \
  --set postgresql.auth.password="$(openssl rand -hex 16)"

Security

  • Fixed a cross-tenant issue in GitHub/GitLab remediation: an
    instance-wide remediation token combined with an unvalidated target
    repository could let one tenant's remediation reach another tenant's repo.
    0.3.5 shipped a narrower guardrail for this; 0.3.6 is the full fix.
    If you run multi-tenant with GitHub/GitLab remediation enabled, upgrade.

Other fixes since 0.3.5

  • A registration race under concurrency could let two simultaneous
    registrations both create a workspace — now guarded.
  • AWS baseline-exclusion improvements: service-linked IAM roles now match by
    name, and every VPC's auto-created "Main" route table is now recognized
    (the AWS API this used never exposed it at all — reads via a different API
    now).
  • AWS gets a real per-resource live cross-check on the Terraform-plan scan
    path, matching what Azure/GCP already had.
  • Several drift-event and dashboard-tile attribution fixes (misattributed
    tiles, a GCP subnetwork region collision inflating drift counts, live scan
    progress visibility).
  • Standalone IAM-role/S3-bucket Terraform resources now merge correctly
    instead of reporting false drift against an incomplete payload.
  • GCP key expiry and AWS key age now surfaced in findings.

No chart template, values.yaml default, or licensing/pricing behavior
changed in this release.

Verification

  • Full backend test suite passed (4,300 tests) and a live end-to-end pass
    against real Azure/AWS/GCP test accounts, with zero regressions.
  • Confirmed on the registry by digest, not tag name:
    • driftdetective/ddetective-backend:0.3.6 → sha256:72c7cfb89139c4fe862025f1b697c2e32e572e3c355328474573b48762f94d45
    • driftdetective/ddetective-frontend:0.3.6 → sha256:de512698da2d1e8c75ee5a797df278ac08d9139238f05099fc9ae099234d5984

Cloudkeel-DD 0.3.5

Choose a tag to compare

@cloudkeel cloudkeel released this 29 Aug 10:49

Cloudkeel-DD 0.3.5

Security-hardening release (Epic E14), plus a frontend framework upgrade.

helm install dd oci://registry-1.docker.io/driftdetective/d-detective --version 0.3.5 \
  --namespace ddetective --create-namespace \
  --set secrets.fernetKey="$FERNET" \
  --set secrets.dataKeyWrapped="$DATAKEY" \
  --set secrets.jwtSecret="$JWT" \
  --set postgresql.auth.password="$(openssl rand -hex 16)"

What changed since 0.3.4

  • A batch of backend security hardening fixes.
  • A narrower guardrail for the cross-tenant remediation-token issue later
    fully fixed in 0.3.6.
  • Frontend upgraded from Next.js 14 to 16.3.3.
  • Five security response headers on by default (X-Frame-Options, CSP, HSTS,
    X-Content-Type-Options, Referrer-Policy).

No licensing or pricing behavior changed in this release — the 0.3.4
degrade-to-Free timer is untouched.

Verification

  • Confirmed on the registry by digest, not tag name:
    • driftdetective/ddetective-backend:0.3.5 → sha256:3ec89723b917b064da10e165ee03e8d5ce6efe51e701015449af8d27f7d585d7
    • driftdetective/ddetective-frontend:0.3.5 → sha256:737a5cb855b25123eaf3ca2010a6028a3af407d6dcf46a2b50e4008810def316

Cloudkeel-DD 0.3.4

Choose a tag to compare

@cloudkeel cloudkeel released this 29 Aug 10:49

Cloudkeel-DD 0.3.4

The licensing release — a self-serve install now runs unmetered for 30 days,
then converts to a Free tier (1 enabled scope, 3 users, every feature)
instead of stopping. Nothing is deleted and running scans finish either way.

helm install dd oci://registry-1.docker.io/driftdetective/d-detective --version 0.3.4 \
  --namespace ddetective --create-namespace \
  --set secrets.fernetKey="$FERNET" \
  --set secrets.dataKeyWrapped="$DATAKEY" \
  --set secrets.jwtSecret="$JWT" \
  --set postgresql.auth.password="$(openssl rand -hex 16)"

What changed since 0.3.2

  • Signed offline licence key format and verifier.
  • Scope gate and seat gate for the Free/Team/Enterprise tiers.
  • Trial expiry now degrades to the Free ceiling rather than stopping scans.
  • A Settings → Licence page showing trial/plan status.
  • secrets.licenseKey chart value plus the keygen script.
  • Closed self-registration after the first tenant, plus several smaller fixes.
  • Two Alembic migrations since 0.3.2, one of which deletes duplicate pending
    invites.

Verification

  • Confirmed on the registry by digest, not tag name:
    • driftdetective/ddetective-backend:0.3.4 → sha256:5e80be066d4d52d39d7385bf7fa9dc062fb70fc6abf022fbe7485992954f07fc
    • driftdetective/ddetective-frontend:0.3.4 → sha256:361d8496fb620f9e786000c1bcd802aae5072c71221613b43422ff2dd50e5995

Known limitation

Licence keys are optional — without one, the install runs its unmetered
window and then the Free tier, and never stops working.

Cloudkeel-DD 0.3.2

Choose a tag to compare

@cloudkeel cloudkeel released this 29 Aug 10:49

Cloudkeel-DD 0.3.2

Patch release — one additive migration and six fixes since 0.3.1.

helm install dd oci://registry-1.docker.io/driftdetective/d-detective --version 0.3.2 \
  --namespace ddetective --create-namespace \
  --set secrets.fernetKey="$FERNET" \
  --set secrets.dataKeyWrapped="$DATAKEY" \
  --set secrets.jwtSecret="$JWT" \
  --set postgresql.auth.password="$(openssl rand -hex 16)"

What changed since 0.3.1

  • A denied IAM permission no longer looks like "no actor found" (adds
    scans.capability_warnings).
  • Slack was deleting the value from every widened-security-rule alert
    (markdown ate the asterisks) — failed sends now log instead of vanishing.
  • Adoption now closes the unmanaged finding it makes unreachable — that
    finding was previously unclosable by any code path.
  • Cross-source verification counts AWS and GCP, not only Azure.
  • Observation partitions trapped outside the create-ahead window recover.
  • The chart's policy check now loads the rendered ConfigMap into a real OPA
    instance instead of a static check.
  • A rejected settings toggle is surfaced rather than silently swallowed.

Verification

  • One additive Alembic migration only (capability_warnings) — measured by
    diffing alembic/versions/ against the prior published build, not assumed.
  • Confirmed on the registry by digest, not tag name:
    • driftdetective/ddetective-backend:0.3.2 → sha256:6fdb9ce142340c66bcaa13a5736037e802cb7a2e4bedf658421eeca353408dc7
    • driftdetective/ddetective-frontend:0.3.2 → sha256:d6a037cc1d029c2312ef54011dc6cc1322d271060d319dd01e1592669d5ca2c7