Releases: kubezap/kubezap-operator
Release list
KubeZap v0.2.1
KubeZap v0.2.1
Installation
Download binaries from the assets below, or see docs/overview.md for install instructions.
Both kubezap and kubectl-kubezap are included in each archive. Place either binary in your $PATH.
kubectl-kubezap enables invocation as kubectl kubezap via the kubectl plugin convention.
Changelog
Other Changes
- c794037 Merge pull request #272 from kubezap/fix/broken-notes-quickstart-sample-mismatch
- 350da86 Merge pull request #273 from kubezap/fix/olm-bundle-image-pin
- e5ab7ae Merge pull request #274 from kubezap/fix/e2e-multinamespace-cache-sync-deadlock
- f1d3f90 Merge pull request #275 from kubezap/chore/release-v0.2.1
- 4e416e0 chore: prepare v0.2.1
- 40b4232 feat: add make bundle-pin-digest for OperatorHub submissions
- 446ac27 fix: E2E suite left broken by AllNamespaces removal; harden MultiNamespace cache scoping
- 1b12850 fix: broken Helm NOTES.txt quickstart link and dangling sample flowRef
- bff487c fix: pin OLM bundle manager image instead of :latest
- e828c49 fix: regenerate bundle for alm-examples drift after sample flowRef fix
KubeZap v0.2.0
KubeZap v0.2.0
Installation
Download binaries from the assets below, or see docs/overview.md for install instructions.
Both kubezap and kubectl-kubezap are included in each archive. Place either binary in your $PATH.
kubectl-kubezap enables invocation as kubectl kubezap via the kubectl plugin convention.
Changelog
New Features
- 108adb8 feat(security): enforce kubezap.io/managed=true for AllNamespaces secret reads
Other Changes
- 070b782 Merge branch 'main' into feat/allnamespaces-secrets-restriction
- d41146e Merge pull request #257 from kubezap/fix/v0.1.0-helm-install-critical-bugs
- 644f61a Merge pull request #258 from kubezap/fix/executor-port-wiring
- 0bba936 Merge pull request #259 from kubezap/feat/allnamespaces-secrets-restriction
- 25e1307 Merge pull request #260 from kubezap/fix/webhook-tls-secret-permission-denied
- 607d728 Merge pull request #261 from kubezap/backlog/gateway-namespace-read-rbac
- 8966f6e Merge pull request #262 from kubezap/chore/wire-integration-allnamespaces
- 3e092c4 Merge pull request #263 from kubezap/chore/approve-story055-design-record
- b5b6ceb Merge pull request #264 from kubezap/backlog/webhook-gateway-watch-namespaces
- 1a91b58 Merge pull request #265 from kubezap/docs/remove-allnamespaces-design-record
- 086b134 Merge pull request #266 from kubezap/backlog/remove-allnamespaces-code
- 5bbbd29 Merge pull request #267 from kubezap/backlog/rbac-parity-ci-check
- 0c99f54 Merge pull request #268 from kubezap/backlog/resource-trigger-optional-rbac
- b2de088 Merge pull request #269 from kubezap/fix/multinamespace-crashloop-and-leader-election-rbac
- b58cc64 Merge pull request #270 from kubezap/fix/keda-mtls-amqp-live-testing-bugs
- ba5991c Merge pull request #271 from kubezap/chore/release-v0.2.0
- b5abd51 chore: prepare v0.2.0
- 9be68cd chore: wire IntegrationReconciler.AllNamespacesMode in cmd/main.go
- 8cc6439 ci: add RBAC parity check across generated/kustomize/Helm install paths
- 183014b docs: describe two-mode namespace watch model (STORY-060)
- b3e2337 docs: design record for removing AllNamespaces watch mode
- 1f0b7d1 docs: document opt-in wildcard RBAC for the alpha Resource trigger type
- e7e37be docs: flip STORY-055's design record to Approved
- 7eaf7fc docs: restore accurate CSV installModes example in architecture.md
- c57bfae feat: add cluster-scoped Namespace-read RBAC for AllNamespaces broker gateways
- 84c9c6b feat: flip OLM CSV AllNamespaces installMode to unsupported (STORY-059)
- 2daa97f feat: per-namespace RBAC for MultiNamespace; delete operator ClusterRole (STORY-058)
- 5801f1c feat: remove AllNamespaces watch mode code (STORY-057)
- 181bd53 fix: KEDA scaling, executor mTLS health probes, AMQP routingKey docs
- 34e3e71 fix: MultiNamespace crash-loop and Helm leader-election RBAC gap
- 39b56e9 fix: WebhookGatewayConfig TLS mounts were unreadable, crash-looping the gateway
- e06cb64 fix: correct stale "watch all namespaces" wording in webhook-gateway
- 50f0c1d fix: critical Helm install failures + NetworkPolicy bug found via live k3s testing
- 1759cd3 fix: narrow stale RBAC markers, resolve real generated/deployed drift
- 54630e5 fix: propagate WATCH_NAMESPACES to webhook gateway and maintain its namespace-reader binding
- 37e7a50 fix: regenerate OLM bundle for gateway namespace-reader ClusterRole
- 8ba5385 fix: wire --executor-port through Helm/raw manifests, derive RPC URL port
KubeZap v0.1.0
KubeZap v0.1.0
Installation
Download binaries from the assets below, or see docs/overview.md for install instructions.
Both kubezap and kubectl-kubezap are included in each archive. Place either binary in your $PATH.
kubectl-kubezap enables invocation as kubectl kubezap via the kubectl plugin convention.
Changelog
New Features
- 9ee89f7 feat(api): add WebhookGatewayConfig CRD, HPA-config-reading capability, and singleton webhook
- 7e9b516 feat(api): restructure WebhookAuth to use per-type nested config structs
- c9c5f7c feat(cli): add design doc and scaffold cmd/kubezap binary
- d8b5e28 feat(controller): FlowRun HTTP steps routed via executor RPC (§17 P0 [4/6])
- 917ff08 feat(controller): KEDA ScaledObject for Kafka gateway (KG-5)
- 651ae44 feat(controller): Kafka gateway Deployment lifecycle management (KG-4)
- ef11edf feat(controller): executor RPC backoff + Kafka producer pool debug logging
- b4c94e2 feat(controller): executor mTLS — cert generation, Secret injection, TLS RPC client (§17 P0 [5/6])
- 8abd0c9 feat(controller): executor reconciler — manage http-executor Deployment/Service/NetworkPolicy (§17 P0 [3/6])
- 56643a0 feat(controller): executor reconciler — manage http-executor Deployment/Service/NetworkPolicy (§17 P0 [3/6])
- cf95a7e feat(demo3): incident response escalation with wait step primitive
- fd36ed7 feat(e2e,docs): executor E2E test skeleton + architecture/overview docs update (§17 P0 [6/6])
- 507fe7b feat(executor): scaffold http-executor binary and POST /execute handler (§17 P0 [2/6])
- 92caa49 feat(executor): scaffold http-executor binary and POST /execute handler (§17 P0 [2/6])
- 2bdec67 feat(flow): expose trigger.key/keyEncoding as CEL condition variables
- b92693d feat(infra): add liveness and readiness probes to gateway Deployments
- ae78a9d feat(kafka): capture record key on FlowRun TriggerData, add $(trigger.key)
- feb01ae feat(kafka-gateway): FlowRun creation per Kafka message with dedup key (KG-3)
- ce0f84c feat(kafka-gateway): binary skeleton and Watcher stub
- 66c1e51 feat(kafka-gateway): dynamic Kafka topic subscription management (KG-2)
- ac31eb0 feat(kafka-gateway): implement FlowRun creation in MessageHandler (KG-3)
- bf994e1 feat(plugin): namespace-scoped RBAC for plugin Deployments
- 04cd8a5 feat(rbac): add kubebuilder RBAC markers for ResourceWatcher discovery API access
- f91dead feat(security): CEL expression cost limits — CELCostLimit field + evaluateWhen guard (§17 P1 H5)
- 33ae4b1 feat(security): add admission warning for webhook Triggers without auth
- 9538045 feat(security): configurable header redaction + redactBody for webhook TriggerData (§17 P1)
- c0ef74a feat(security): plugin image digest pinning — spec.plugin.imageDigest field (§17 P2 H4)
- a547080 feat(security): remove cross-namespace FlowRef; add validating webhook
- 36ace23 feat(security): restrict secrets RBAC; default to OwnNamespace install mode
- 9565959 feat(security): secret access audit logging — kubezap_secret_accesses_total (§17 P1 H3)
- 2369ae9 feat(security): shared gateway/redact package — consistent header redaction across webhook/kafka/amqp (§17 P2 M3)
- 9338045 feat(security): spec.webhook.rateLimit — local gateway rate limit enforcement (§17 P1 M1)
- 4b3a4df feat(security): wire admission webhooks; default WATCH_NAMESPACES to OwnNamespace
- a3f5831 feat(webhook-gateway): add AccessLogMiddleware for structured JSON access logs (OBS-2)
- 2a14abb feat(webhook-gateway): add TLS termination and mTLS support
- 18965a5 feat(webhook-gateway): structured JSON access logs and /24 source IP cardinality guard (OBS-2, OBS-3)
Bug Fixes
- e6db158 fix(alpha): resource watcher discovery plural, sync retry, and cooldown
- 8f86d5f fix(controller): add terminationGracePeriodSeconds=30 to executor Deployment
- 326c321 fix(controller): requeue on executor transport errors with 5s backoff
- c294e7c fix(controller): thread actual attempt count through executeHTTPStep and executePublishStep
- c201307 fix(e2e): add http-executor Dockerfile, load image in BeforeSuite, increase test-e2e timeout
- 5a2705f fix(e2e): rename Kafka Integration field brokers to bootstrapServers
- ad9005b fix(executor): set terminationGracePeriodSeconds=30 on http-executor pod
- 93f4a52 fix(flow-controller): fix empty-steps test case in flow_controller_test.go
- d8fe91e fix(flowrun): requeue on executor transport errors instead of failing step
- af415db fix(flowrun): thread actual attempt count through executeHTTPStep and executePublishStep
- 5afde98 fix(gateway): add TriggerData.BodyEncoding for binary-safe body capture
- 2435fb4 fix(gateway): refactor amqp and nats watchers from polling to informer/cache
- b47f03c fix(makefile): correct controller deployment name to kubezap-controller-manager
- d03f770 fix(p2): publish body capture, when-expr counter, goto refactor; mark stale [x] items
- d266185 fix(rbac): add delete verbs and owner refs to Kafka gateway RBAC resources
- 76c5ee7 fix(rbac): add delete verbs and owner refs to Kafka gateway RBAC resources
- df940ed fix(rbac): add wildcard get/list/watch markers to ResourceWatcher
- 8314626 fix(rbac): add wildcard kubebuilder RBAC markers for dynamic informer watches
- 9258aef fix(samples): add gateway-init webhook trigger to kafka-enrichment demo
- 207a4be fix(samples): brokers -> bootstrapServers in kafka-enrichment Integration
- 55771c8 fix(samples): correct MockEndpoint field names in kafka-enrichment demo
- d4f0d0b fix(security): harden webhook trigger attack surface (IP allowlist bypass, SSRF TOCTOU, Slowloris, body truncation)
- 4921eb2 fix(webhook): add missing +kubebuilder:webhook marker for FlowRun
Refactoring
- 7c21a8b refactor(controller): extract gatewayAvailableCondition helper — eliminate kafka/amqp/nats duplication (§17 P2)
Documentation
- 39ad7ef docs(api): add alpha-stability callout to Resource Trigger section
- 70766ac docs(benchmarks): STORY-013 execution-latency benchmark methodology
- dd7d8a4 docs(guides): add security-checklist.md for OperatorHub evaluators
- 2ba8875 docs(observability): update guide with metrics, traces, access logs, and ServiceMonitor (OBS-4, OBS-5)
- e78122a docs(readme): use git SHA tags for k3s local dev workflow
- b023905 docs(schedule): add observability port and TLS normalization tasks
- 994fd06 docs(schedule): mark OBS-4 and OBS-5 as complete
- 663a6d3 docs(schedule): mark WH-HPA complete — HPA for webhook gateway Deployment
- f39e591 docs(security): add production security checklist guide
- 177a971 docs(security): example NetworkPolicies + plugin security guide (§17 P2 M4, M2)
- 8c394d7 docs(trigger): add alpha stability callout to Resource Trigger section
Other Changes
- 6be53d3 Add .claude/ to .gitignore
- b0e0a2b Add CronTrigger, PubSubTrigger, WebhookAuth, MaxFlowRuns to Trigger CRD
- 8c6dce1 Add Flow/FlowRun/Integration/MockEndpoint CRD types + samples and update schedule
- 5806668 Add KubeZap brand assets and README hero logo
- c9315b5 Add docs/prompts.md with Copilot/Claude/Codex implementation prompts
- 2a63397 Add docs/schedule.md and reference from CLAUDE.md
- dfee439 Add full project scaffolding, CRD types, and documentation
- 9c95e79 Add generated d...