Skip to content

v0.5.0

Choose a tag to compare

@LarsenClose LarsenClose released this 06 Mar 07:01
· 17 commits to main since this release

Highlights

This release completes the four-phase Rust bridge migration, restoring the security invariant that key material never enters Go memory.

Security Invariant Restored (Phase 4)

  • BootstrapInjector strategy pattern cleanly separates production (Rust bridge) and test (legacy Go) paths
  • BridgeBootstrapInjector: decrypt + inject entirely in Rust via FFI — no plaintext in Go heap
  • LegacyBootstrapInjector: retained for test compatibility and AdditionalNamespaces (pending Phase 5 FFI addition)
  • Controller automatically selects the appropriate injector based on CRD configuration

KMS Config JSON Bridge (Phase 3)

  • BuildKmsConfigJSON() resolves Go-side cloud credentials (IRSA, Workload Identity, Instance Principal) and serializes them for Rust KMS providers
  • Enables cloud-native authentication to flow through the CGO FFI boundary

UreqSecretInjector Enrichment (Phase 2)

  • Labels (app.kubernetes.io/managed-by, genesis.io/bootstrap) and annotations on Rust-injected secrets
  • TLS CA certificate verification for in-cluster API server communication
  • FFI metadata propagation for secret provenance tracking

Infrastructure

  • Dependabot auto-merge workflow: dependency update PRs auto-merge when all CI gates pass
  • Mock-dependent CLI tests properly guarded behind genesis_mock build tag
  • 193 Rust tests + 17 Go packages passing

Upgrading from v0.4.0

Drop-in replacement. No CRD schema changes. The controller automatically uses the bridge path for standard bootstrap operations.

Full Changelog: v0.4.0...v0.5.0