v0.5.0
Highlights
This release completes the four-phase Rust bridge migration, restoring the security invariant that key material never enters Go memory.
Security Invariant Restored (Phase 4)
BootstrapInjectorstrategy pattern cleanly separates production (Rust bridge) and test (legacy Go) pathsBridgeBootstrapInjector: decrypt + inject entirely in Rust via FFI — no plaintext in Go heapLegacyBootstrapInjector: retained for test compatibility andAdditionalNamespaces(pending Phase 5 FFI addition)- Controller automatically selects the appropriate injector based on CRD configuration
KMS Config JSON Bridge (Phase 3)
BuildKmsConfigJSON()resolves Go-side cloud credentials (IRSA, Workload Identity, Instance Principal) and serializes them for Rust KMS providers- Enables cloud-native authentication to flow through the CGO FFI boundary
UreqSecretInjector Enrichment (Phase 2)
- Labels (
app.kubernetes.io/managed-by,genesis.io/bootstrap) and annotations on Rust-injected secrets - TLS CA certificate verification for in-cluster API server communication
- FFI metadata propagation for secret provenance tracking
Infrastructure
- Dependabot auto-merge workflow: dependency update PRs auto-merge when all CI gates pass
- Mock-dependent CLI tests properly guarded behind
genesis_mockbuild tag - 193 Rust tests + 17 Go packages passing
Upgrading from v0.4.0
Drop-in replacement. No CRD schema changes. The controller automatically uses the bridge path for standard bootstrap operations.
Full Changelog: v0.4.0...v0.5.0