Repository navigation
0.3.332
0.3.332
Security fix — JWT credential leak in snowplow (upgrade recommended)
snowplow 1.12.21 → 1.12.22 closes a live credential leak (#271). When a
nil endpoint-ref PREWARM stage carried a Krateo authn JWT and targeted the
ServiceAccount endpoint, bearerAppendForStage injected that JWT into the
Authorization header before the SA token round-tripper ran. Because
client-go's bearer transport will not overwrite an existing Authorization
header, the k8s BearerTokenFile token was never sent — the apiserver received
a user's RS256 JWT instead, logged it in the audit log, and returned 401.
Measured at ~720 SAR-401s per 20 minutes from a single pod. The fix gates the
JWT append on isSA=false; SA paths are unaffected in behaviour.
Three additional snowplow fixes in the same release:
- #216 — fires the gone-forget hook on a confirmed-404 self-eviction, so a
deleted resource no longer continues to be served from the harvested copy. - #279 — records the LIST fanout edge on an iterator-empty resolve; the
ns="" scope over-marks but is never incorrect (a design hardening is planned
separately). - #288 — guards empty-interpolated and DNS-invalid dial targets, closing
two of three shapes of a//-fallback bug whose source is portal content
(~1 026 futile apiserver round trips per 20 minutes, all
continueOnError-swallowed). The sentinel shape (none.krateo.io/v1)
cannot be closed in snowplow.
Other component bumps
- frontend 1.6.78 → 1.6.79 — one CSS change: 8 px spacing before the rail
brief. - krateo-autopilot 0.6.0 → 0.6.1 — one prompt paragraph: the orchestrator
now briefs a page to frontend-agent in the user's words rather than widget
kind names. Pairs with frontend-agent 1.5.3 (already live).
All five pins are in chart/files/component-pins.yaml.