v0.4.7-rc.2
Pre-releaseLeoflow v0.4.7-rc.2
A 0.x (pre-1.0) build — SemVer carries the maturity, there is no separate
alpha/beta, and the pre-alpha series ended at v0.0.1 (ADR 0037). APIs and
on-disk shape may still evolve between minor versions; -rc.N tags are release
candidates gated by the E2E suite. Install this exact release with:
curl -fsSL https://raw.githubusercontent.com/neochaotic/leoflow/v0.4.7-rc.2/install.sh | LEOFLOW_VERSION=v0.4.7-rc.2 shA bare
curl … | shinstalls the latest stable release (/releases/latest
excludes pre-releases), so on a pre-release page it would NOT give youv0.4.7-rc.2.
LEOFLOW_VERSIONmust sit on theshside of the pipe (notcurl) — a
VAR=x curl … | shprefix sets the var forcurlonly, soinstall.shwould
not see it and would fall back to latest-stable.
Changelog
- c5bb7e4: docs(release): add the SSO tranche to the RC cluster-validation runbook (#1174) (@neochaotic)
- 34ae395: docs(release): record the rc.2 runbook execution, and carry row 17 forward (#1178) (@neochaotic)
- 3bbebec: feat(api): offer single sign-on on the sign-in page when a flow exists (#1161) (@neochaotic)
- 80b8fd6: feat(helm): make OIDC reachable from values, so SSO can be turned on (#1159) (@neochaotic)
- 4889dd1: feat(oidc): narrow Google's account chooser to the Workspace domain, and document the whole journey (#1164) (@neochaotic)
- b17b8db: fix(api): log every SSO denial, and stop discarding the cause behind token_invalid (#1162) (@neochaotic)
- 1a13016: fix(api): populate class_ref.module_path, which was making OpenMetadata ingest nothing (#1156) (@neochaotic)
- 900e526: fix(api): return a refused single sign-on to the login page, not to raw JSON (#1169) (@neochaotic)
- b2e2737: fix(chart): let the startup gate render when upgrading from a chart that never had it (#1157) (@neochaotic)
- 1a1cdfe: fix(chart): stop delivering the control plane's credentials through a Helm hook (#1155) (@neochaotic)
- 18e1bd3: fix(config): reject a blank OIDC name at boot, and stop reporting a missing tenant as a database failure (#1172) (@neochaotic)
- 9a9431d: fix(server): name at boot the OIDC settings that point at rows which do not exist (#1168) (@neochaotic)
- 35cf7c7: fix(server): name at boot the four SSO configurations that fail at login (#1163) (@neochaotic)
- 8a0b022: fix(server): run the OIDC name check after the bootstrap admin exists (#1175) (@neochaotic)
- ec234b6: fix(server): warn when no break-glass address can actually sign in (#1173) (@neochaotic)
- c884c94: release: prepare v0.4.7-rc.2 (@neochaotic)
Artifacts are checksummed (SHA-256) and the checksums file is cosign-signed
(keyless). Verify with cosign verify-blob.