Skip to content

Releases: kubezap/kubezap-operator

KubeZap v0.2.1

Choose a tag to compare

@github-actions github-actions released this 20 Sep 22:51
Immutable release. Only release title and notes can be modified.
f1d3f90

KubeZap v0.2.1

Installation

Download binaries from the assets below, or see docs/overview.md for install instructions.

Both kubezap and kubectl-kubezap are included in each archive. Place either binary in your $PATH.
kubectl-kubezap enables invocation as kubectl kubezap via the kubectl plugin convention.

Changelog

Other Changes

  • c794037 Merge pull request #272 from kubezap/fix/broken-notes-quickstart-sample-mismatch
  • 350da86 Merge pull request #273 from kubezap/fix/olm-bundle-image-pin
  • e5ab7ae Merge pull request #274 from kubezap/fix/e2e-multinamespace-cache-sync-deadlock
  • f1d3f90 Merge pull request #275 from kubezap/chore/release-v0.2.1
  • 4e416e0 chore: prepare v0.2.1
  • 40b4232 feat: add make bundle-pin-digest for OperatorHub submissions
  • 446ac27 fix: E2E suite left broken by AllNamespaces removal; harden MultiNamespace cache scoping
  • 1b12850 fix: broken Helm NOTES.txt quickstart link and dangling sample flowRef
  • bff487c fix: pin OLM bundle manager image instead of :latest
  • e828c49 fix: regenerate bundle for alm-examples drift after sample flowRef fix

KubeZap v0.2.0

Choose a tag to compare

@github-actions github-actions released this 20 Sep 19:43
Immutable release. Only release title and notes can be modified.
ba5991c

KubeZap v0.2.0

Installation

Download binaries from the assets below, or see docs/overview.md for install instructions.

Both kubezap and kubectl-kubezap are included in each archive. Place either binary in your $PATH.
kubectl-kubezap enables invocation as kubectl kubezap via the kubectl plugin convention.

Changelog

New Features

  • 108adb8 feat(security): enforce kubezap.io/managed=true for AllNamespaces secret reads

Other Changes

  • 070b782 Merge branch 'main' into feat/allnamespaces-secrets-restriction
  • d41146e Merge pull request #257 from kubezap/fix/v0.1.0-helm-install-critical-bugs
  • 644f61a Merge pull request #258 from kubezap/fix/executor-port-wiring
  • 0bba936 Merge pull request #259 from kubezap/feat/allnamespaces-secrets-restriction
  • 25e1307 Merge pull request #260 from kubezap/fix/webhook-tls-secret-permission-denied
  • 607d728 Merge pull request #261 from kubezap/backlog/gateway-namespace-read-rbac
  • 8966f6e Merge pull request #262 from kubezap/chore/wire-integration-allnamespaces
  • 3e092c4 Merge pull request #263 from kubezap/chore/approve-story055-design-record
  • b5b6ceb Merge pull request #264 from kubezap/backlog/webhook-gateway-watch-namespaces
  • 1a91b58 Merge pull request #265 from kubezap/docs/remove-allnamespaces-design-record
  • 086b134 Merge pull request #266 from kubezap/backlog/remove-allnamespaces-code
  • 5bbbd29 Merge pull request #267 from kubezap/backlog/rbac-parity-ci-check
  • 0c99f54 Merge pull request #268 from kubezap/backlog/resource-trigger-optional-rbac
  • b2de088 Merge pull request #269 from kubezap/fix/multinamespace-crashloop-and-leader-election-rbac
  • b58cc64 Merge pull request #270 from kubezap/fix/keda-mtls-amqp-live-testing-bugs
  • ba5991c Merge pull request #271 from kubezap/chore/release-v0.2.0
  • b5abd51 chore: prepare v0.2.0
  • 9be68cd chore: wire IntegrationReconciler.AllNamespacesMode in cmd/main.go
  • 8cc6439 ci: add RBAC parity check across generated/kustomize/Helm install paths
  • 183014b docs: describe two-mode namespace watch model (STORY-060)
  • b3e2337 docs: design record for removing AllNamespaces watch mode
  • 1f0b7d1 docs: document opt-in wildcard RBAC for the alpha Resource trigger type
  • e7e37be docs: flip STORY-055's design record to Approved
  • 7eaf7fc docs: restore accurate CSV installModes example in architecture.md
  • c57bfae feat: add cluster-scoped Namespace-read RBAC for AllNamespaces broker gateways
  • 84c9c6b feat: flip OLM CSV AllNamespaces installMode to unsupported (STORY-059)
  • 2daa97f feat: per-namespace RBAC for MultiNamespace; delete operator ClusterRole (STORY-058)
  • 5801f1c feat: remove AllNamespaces watch mode code (STORY-057)
  • 181bd53 fix: KEDA scaling, executor mTLS health probes, AMQP routingKey docs
  • 34e3e71 fix: MultiNamespace crash-loop and Helm leader-election RBAC gap
  • 39b56e9 fix: WebhookGatewayConfig TLS mounts were unreadable, crash-looping the gateway
  • e06cb64 fix: correct stale "watch all namespaces" wording in webhook-gateway
  • 50f0c1d fix: critical Helm install failures + NetworkPolicy bug found via live k3s testing
  • 1759cd3 fix: narrow stale RBAC markers, resolve real generated/deployed drift
  • 54630e5 fix: propagate WATCH_NAMESPACES to webhook gateway and maintain its namespace-reader binding
  • 37e7a50 fix: regenerate OLM bundle for gateway namespace-reader ClusterRole
  • 8ba5385 fix: wire --executor-port through Helm/raw manifests, derive RPC URL port

KubeZap v0.1.0

KubeZap v0.1.0 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 19 Sep 17:22
Immutable release. Only release title and notes can be modified.
203b535

KubeZap v0.1.0

Installation

Download binaries from the assets below, or see docs/overview.md for install instructions.

Both kubezap and kubectl-kubezap are included in each archive. Place either binary in your $PATH.
kubectl-kubezap enables invocation as kubectl kubezap via the kubectl plugin convention.

Changelog

New Features

  • 9ee89f7 feat(api): add WebhookGatewayConfig CRD, HPA-config-reading capability, and singleton webhook
  • 7e9b516 feat(api): restructure WebhookAuth to use per-type nested config structs
  • c9c5f7c feat(cli): add design doc and scaffold cmd/kubezap binary
  • d8b5e28 feat(controller): FlowRun HTTP steps routed via executor RPC (§17 P0 [4/6])
  • 917ff08 feat(controller): KEDA ScaledObject for Kafka gateway (KG-5)
  • 651ae44 feat(controller): Kafka gateway Deployment lifecycle management (KG-4)
  • ef11edf feat(controller): executor RPC backoff + Kafka producer pool debug logging
  • b4c94e2 feat(controller): executor mTLS — cert generation, Secret injection, TLS RPC client (§17 P0 [5/6])
  • 8abd0c9 feat(controller): executor reconciler — manage http-executor Deployment/Service/NetworkPolicy (§17 P0 [3/6])
  • 56643a0 feat(controller): executor reconciler — manage http-executor Deployment/Service/NetworkPolicy (§17 P0 [3/6])
  • cf95a7e feat(demo3): incident response escalation with wait step primitive
  • fd36ed7 feat(e2e,docs): executor E2E test skeleton + architecture/overview docs update (§17 P0 [6/6])
  • 507fe7b feat(executor): scaffold http-executor binary and POST /execute handler (§17 P0 [2/6])
  • 92caa49 feat(executor): scaffold http-executor binary and POST /execute handler (§17 P0 [2/6])
  • 2bdec67 feat(flow): expose trigger.key/keyEncoding as CEL condition variables
  • b92693d feat(infra): add liveness and readiness probes to gateway Deployments
  • ae78a9d feat(kafka): capture record key on FlowRun TriggerData, add $(trigger.key)
  • feb01ae feat(kafka-gateway): FlowRun creation per Kafka message with dedup key (KG-3)
  • ce0f84c feat(kafka-gateway): binary skeleton and Watcher stub
  • 66c1e51 feat(kafka-gateway): dynamic Kafka topic subscription management (KG-2)
  • ac31eb0 feat(kafka-gateway): implement FlowRun creation in MessageHandler (KG-3)
  • bf994e1 feat(plugin): namespace-scoped RBAC for plugin Deployments
  • 04cd8a5 feat(rbac): add kubebuilder RBAC markers for ResourceWatcher discovery API access
  • f91dead feat(security): CEL expression cost limits — CELCostLimit field + evaluateWhen guard (§17 P1 H5)
  • 33ae4b1 feat(security): add admission warning for webhook Triggers without auth
  • 9538045 feat(security): configurable header redaction + redactBody for webhook TriggerData (§17 P1)
  • c0ef74a feat(security): plugin image digest pinning — spec.plugin.imageDigest field (§17 P2 H4)
  • a547080 feat(security): remove cross-namespace FlowRef; add validating webhook
  • 36ace23 feat(security): restrict secrets RBAC; default to OwnNamespace install mode
  • 9565959 feat(security): secret access audit logging — kubezap_secret_accesses_total (§17 P1 H3)
  • 2369ae9 feat(security): shared gateway/redact package — consistent header redaction across webhook/kafka/amqp (§17 P2 M3)
  • 9338045 feat(security): spec.webhook.rateLimit — local gateway rate limit enforcement (§17 P1 M1)
  • 4b3a4df feat(security): wire admission webhooks; default WATCH_NAMESPACES to OwnNamespace
  • a3f5831 feat(webhook-gateway): add AccessLogMiddleware for structured JSON access logs (OBS-2)
  • 2a14abb feat(webhook-gateway): add TLS termination and mTLS support
  • 18965a5 feat(webhook-gateway): structured JSON access logs and /24 source IP cardinality guard (OBS-2, OBS-3)

Bug Fixes

  • e6db158 fix(alpha): resource watcher discovery plural, sync retry, and cooldown
  • 8f86d5f fix(controller): add terminationGracePeriodSeconds=30 to executor Deployment
  • 326c321 fix(controller): requeue on executor transport errors with 5s backoff
  • c294e7c fix(controller): thread actual attempt count through executeHTTPStep and executePublishStep
  • c201307 fix(e2e): add http-executor Dockerfile, load image in BeforeSuite, increase test-e2e timeout
  • 5a2705f fix(e2e): rename Kafka Integration field brokers to bootstrapServers
  • ad9005b fix(executor): set terminationGracePeriodSeconds=30 on http-executor pod
  • 93f4a52 fix(flow-controller): fix empty-steps test case in flow_controller_test.go
  • d8fe91e fix(flowrun): requeue on executor transport errors instead of failing step
  • af415db fix(flowrun): thread actual attempt count through executeHTTPStep and executePublishStep
  • 5afde98 fix(gateway): add TriggerData.BodyEncoding for binary-safe body capture
  • 2435fb4 fix(gateway): refactor amqp and nats watchers from polling to informer/cache
  • b47f03c fix(makefile): correct controller deployment name to kubezap-controller-manager
  • d03f770 fix(p2): publish body capture, when-expr counter, goto refactor; mark stale [x] items
  • d266185 fix(rbac): add delete verbs and owner refs to Kafka gateway RBAC resources
  • 76c5ee7 fix(rbac): add delete verbs and owner refs to Kafka gateway RBAC resources
  • df940ed fix(rbac): add wildcard get/list/watch markers to ResourceWatcher
  • 8314626 fix(rbac): add wildcard kubebuilder RBAC markers for dynamic informer watches
  • 9258aef fix(samples): add gateway-init webhook trigger to kafka-enrichment demo
  • 207a4be fix(samples): brokers -> bootstrapServers in kafka-enrichment Integration
  • 55771c8 fix(samples): correct MockEndpoint field names in kafka-enrichment demo
  • d4f0d0b fix(security): harden webhook trigger attack surface (IP allowlist bypass, SSRF TOCTOU, Slowloris, body truncation)
  • 4921eb2 fix(webhook): add missing +kubebuilder:webhook marker for FlowRun

Refactoring

  • 7c21a8b refactor(controller): extract gatewayAvailableCondition helper — eliminate kafka/amqp/nats duplication (§17 P2)

Documentation

  • 39ad7ef docs(api): add alpha-stability callout to Resource Trigger section
  • 70766ac docs(benchmarks): STORY-013 execution-latency benchmark methodology
  • dd7d8a4 docs(guides): add security-checklist.md for OperatorHub evaluators
  • 2ba8875 docs(observability): update guide with metrics, traces, access logs, and ServiceMonitor (OBS-4, OBS-5)
  • e78122a docs(readme): use git SHA tags for k3s local dev workflow
  • b023905 docs(schedule): add observability port and TLS normalization tasks
  • 994fd06 docs(schedule): mark OBS-4 and OBS-5 as complete
  • 663a6d3 docs(schedule): mark WH-HPA complete — HPA for webhook gateway Deployment
  • f39e591 docs(security): add production security checklist guide
  • 177a971 docs(security): example NetworkPolicies + plugin security guide (§17 P2 M4, M2)
  • 8c394d7 docs(trigger): add alpha stability callout to Resource Trigger section

Other Changes

  • 6be53d3 Add .claude/ to .gitignore
  • b0e0a2b Add CronTrigger, PubSubTrigger, WebhookAuth, MaxFlowRuns to Trigger CRD
  • 8c6dce1 Add Flow/FlowRun/Integration/MockEndpoint CRD types + samples and update schedule
  • 5806668 Add KubeZap brand assets and README hero logo
  • c9315b5 Add docs/prompts.md with Copilot/Claude/Codex implementation prompts
  • 2a63397 Add docs/schedule.md and reference from CLAUDE.md
  • dfee439 Add full project scaffolding, CRD types, and documentation
  • 9c95e79 Add generated d...
Read more