Cloudkeel-DD 0.3.2
Cloudkeel-DD 0.3.2
Patch release — one additive migration and six fixes since 0.3.1.
helm install dd oci://registry-1.docker.io/driftdetective/d-detective --version 0.3.2 \
--namespace ddetective --create-namespace \
--set secrets.fernetKey="$FERNET" \
--set secrets.dataKeyWrapped="$DATAKEY" \
--set secrets.jwtSecret="$JWT" \
--set postgresql.auth.password="$(openssl rand -hex 16)"What changed since 0.3.1
- A denied IAM permission no longer looks like "no actor found" (adds
scans.capability_warnings). - Slack was deleting the value from every widened-security-rule alert
(markdown ate the asterisks) — failed sends now log instead of vanishing. - Adoption now closes the unmanaged finding it makes unreachable — that
finding was previously unclosable by any code path. - Cross-source verification counts AWS and GCP, not only Azure.
- Observation partitions trapped outside the create-ahead window recover.
- The chart's policy check now loads the rendered ConfigMap into a real OPA
instance instead of a static check. - A rejected settings toggle is surfaced rather than silently swallowed.
Verification
- One additive Alembic migration only (
capability_warnings) — measured by
diffingalembic/versions/against the prior published build, not assumed. - Confirmed on the registry by digest, not tag name:
driftdetective/ddetective-backend:0.3.2→sha256:6fdb9ce142340c66bcaa13a5736037e802cb7a2e4bedf658421eeca353408dc7driftdetective/ddetective-frontend:0.3.2→sha256:d6a037cc1d029c2312ef54011dc6cc1322d271060d319dd01e1592669d5ca2c7