Releases: milo-os/milo
Release list
v0.33.3
What's Changed
- Prevent expired invitations from silently failing and blocking future re-invites by @JoseSzycho in #805
Full Changelog: v0.33.2...v0.33.3
v0.33.2: Controller manager alerts name the milo service
The controller manager alerts now label themselves with the milo service, like the rest of Milo's alerts, so a deployment can route them to the owning team without rewriting the rules.
What's new
- Controller manager alerts carry
service: milo. MiloControllerManagerRestarting and MiloControllerManagerCrashLooping name the milo service instead of the deployment, leaving team assignment to whoever deploys Milo. (#806)
Full Changelog: v0.33.1...v0.33.2
v0.33.1
What's Changed
- Allow metadata-only updates to GroupMembership by @yahyafakhroji in #801
Full Changelog: v0.33.0...v0.33.1
v0.33.0
What's Changed
- feat(iam): EmailVerification status field, PasskeyRegistrationLink type, and recovery-link roles by @yahyafakhroji in #782
- docs: add shared operational memory under .claude/memory by @ecv in #678
- Stop retrying grants into deleting or terminating projects by @yahyafakhroji in #791
- fix(iam): waitlist mails wait for a verified email address (Phase C, C11 reader) by @yahyafakhroji in #784
- feat: implement GroupMembership admission webhook to enforce existence and uniqueness constraints by @JoseSzycho in #771
- fix(quota): don't claim project note quota for platform-scoped subjects by @kevwilliams in #792
Full Changelog: v0.32.8...v0.33.0
v0.32.8
Project suspensions and reinstatements now reach the activity feed instead of failing into the dead-letter queue.
Both Project event rules read the resource name from the field the activity processor provides for every event, rather than one that events in the current Kubernetes format do not carry. Those events had been failing since 6 August.
Entries already in the dead-letter queue stay missing until retry works again, tracked in milo-os/activity#216.
Fixes carried: #787
v0.32.7 — Require spec on PlatformAccess and UserPreference
Important
PlatformAccess and UserPreference now require spec. Any stored object of
either kind with no spec is rejected on update, including status
subresource writes. A live audit found no PlatformAccess or UserPreference
objects without spec; the User admission webhook is the only creator and
always sets it.
What's Changed
- fix: Declare two correct rules empty by design by @ecv in #785
- fix: Reject spec-less PlatformAccess and UserPreference by @ecv in #778
- chore: Restore e2e and test-doc tasks on a current Go toolchain by @ecv in #777
Full Changelog: v0.32.6...v0.32.7
v0.32.6
What's Changed
- feat(iam,admission): email verification gate + idempotent User admission by @yahyafakhroji in #756
- fix(build): serve a parseable version from /version by @scotwells in #766
- feat: Escalate suspended projects to deletion after a configurable retention window by @JoseSzycho in #758
- test(e2e): Add ServiceAccount API contract test by @ecv in #683
- fix: Default ServiceAccount spec so state defaults apply by @ecv in #774
Full Changelog: v0.32.5...v0.32.6
v0.32.5
What's Changed
- feat: initialize dedicated multicluster manager for note webhooks in controller-manager by @JoseSzycho in #741
Full Changelog: v0.32.4...v0.32.5
v0.32.4
What's Changed
- test(resourcemanager): disable global configmap quota policy during project deletion blocked resources e2e test by @JoseSzycho in #759
- chore: label milo alerts with owning service by @ecv in #761
Full Changelog: v0.32.3...v0.32.4
v0.32.3
What's Changed
- Keep projects in Terminating until their resources drain by @scotwells in #752
Full Changelog: v0.32.2...v0.32.3