Skip to content

Cloudkeel-DD 0.3.2

Choose a tag to compare

@cloudkeel cloudkeel released this 29 Aug 10:49
· 12 commits to main since this release

Cloudkeel-DD 0.3.2

Patch release — one additive migration and six fixes since 0.3.1.

helm install dd oci://registry-1.docker.io/driftdetective/d-detective --version 0.3.2 \
  --namespace ddetective --create-namespace \
  --set secrets.fernetKey="$FERNET" \
  --set secrets.dataKeyWrapped="$DATAKEY" \
  --set secrets.jwtSecret="$JWT" \
  --set postgresql.auth.password="$(openssl rand -hex 16)"

What changed since 0.3.1

  • A denied IAM permission no longer looks like "no actor found" (adds
    scans.capability_warnings).
  • Slack was deleting the value from every widened-security-rule alert
    (markdown ate the asterisks) — failed sends now log instead of vanishing.
  • Adoption now closes the unmanaged finding it makes unreachable — that
    finding was previously unclosable by any code path.
  • Cross-source verification counts AWS and GCP, not only Azure.
  • Observation partitions trapped outside the create-ahead window recover.
  • The chart's policy check now loads the rendered ConfigMap into a real OPA
    instance instead of a static check.
  • A rejected settings toggle is surfaced rather than silently swallowed.

Verification

  • One additive Alembic migration only (capability_warnings) — measured by
    diffing alembic/versions/ against the prior published build, not assumed.
  • Confirmed on the registry by digest, not tag name:
    • driftdetective/ddetective-backend:0.3.2 → sha256:6fdb9ce142340c66bcaa13a5736037e802cb7a2e4bedf658421eeca353408dc7
    • driftdetective/ddetective-frontend:0.3.2 → sha256:d6a037cc1d029c2312ef54011dc6cc1322d271060d319dd01e1592669d5ca2c7