What's Changed
- Switch to using nightly images by @ehelms in #424
- Initialize files & dirs for Agentic AI development by @stejskalleos in #469
- Deploy iop in the dev environment by @ehelms in #442
- Fix IoP advisor integration: Kafka listener binding and engine rule packages by @jeremylenz in #488
- ensure we use the right hostname when testing repo URLs by @evgeni in #496
- Add httpd MPM event module configuration by @pablomh in #483
- Consolidate into a single deploy step in CI by @ehelms in #493
- set the FQDN setting to our real FQDN so that derived settings work by @evgeni in #491
- Rename --foreman-initial-* options to --initial-* in foremanctl by @nacoool in #490
- Remove artemis by @jturel in #391
- Use dashes in HTTP header names in SSL vhost config by @ehelms in #492
- Move default certificate path to /var/lib/foremanctl/certs by @ehelms in #476
- Add ruff linter and fix lint violations in tests by @arvind4501 in #505
- Enable ansible-lint var-naming to enforce scoped role variables by @ehelms in #502
- Make it more clear that setup-repositories is required by @jeremylenz in #504
- Add apache config support for /pypi by @pavanshekar in #458
- Add BMC feature to foreman-proxy by @arvind4501 in #484
- Rewrite compute resources test to not require Hammer by @ekohl in #510
- Expand ruff coverage to all project Python files and fix violations by @ehelms in #513
- Set the libvirt management domain by @ekohl in #305
- Expose user enabled features as pytest markers by @ekohl in #508
- Pulp import export support by @aidenfine in #455
- assert default bmc provider by @arvind4501 in #514
- declare proxy features as a fixture by @evgeni in #515
- Fixes #353 - Add health check command by @jakduch in #431
- Force FDW defaults to use undef for things that need inputs by @evgeni in #523
- allow downstream product overrides for features by @bochi in #503
- declare foreman-tasks feature by @evgeni in #528
- Publish packit nightlies to @theforeman/develop by @evgeni in #530
- Use namespace for stage images by @ehelms in #522
- Generate passwords instead of using hard-coded ones by @evgeni in #524
- Add Podman quadlet .image file support by @ehelms in #501
- Fixes #535 - Add httpd to foreman.target by @qcjames53 in #536
- add ansible-lint rules to ensure no static secrets and empty defaults are present in the code by @evgeni in #526
- Use role defaults for container images in IOP tests by @ehelms in #542
- add missing params by @arvind4501 in #547
- Fix broker inventory parsing of ruamel YAML tags by @Alleny244 in #546
- test on push to stable branches by @evgeni in #552
- Set explicit volume mount permissions by @ehelms in #375
- Update certificate paths to /var/lib/foremanctl/certs by @ehelms in #555
- Set choices for flavor, so users can't select a wrong one by @evgeni in #559
- Fixes #525 - Add checks to health subcommand by @qcjames53 in #521
- Centralize database configuration into a single reusable list by @ehelms in #550
- Fixes #562 - Remove dead code from health subcommand by @qcjames53 in #563
- update iop-core-kafka image tag to latest-kafka-4.2.0 by @pfreyburg in #564
- Remove the duplicate HTTPS entry by @amolpati30 in #558
- Fix small typo by @sjha4 in #557
- Download CentOS Stream 10 Vagrant box directly from CentOS mirrors by @evgeni in #567
- don't load template if feature is disabled by @evgeni in #566
- Auto-detect and normalize installer certificates by @ehelms in #421
- Fixes #560 - Add systemctl wants to foreman.target for httpd by @qcjames53 in #561
- Add offline backup for foremanctl by @sjha4 in #507
- Generate certificate bundle by @ehelms in #90
- Fix IOP tests to properly validate service endpoints by @ehelms in #544
- Bump actions/checkout from 6 to 7 by @dependabot[bot] in #579
- Don't leak PostgreSQL credentials when looping over DBs by @evgeni in #581
- Include CA bundle in the bundle by @evgeni in #584
- do not re-randomize pulp password on each deploy by @bochi in #587
- Use different foremanctl versions when testing upgrades by @evgeni in #586
- automatically detect database mode in tests from params file by @evgeni in #585
- generate random rails enc key and attach as secret by @bochi in #591
- Use content_view_environment_ids in content tests by @evgeni in #594
- Install the skopeo utility by @stejskalleos in #600
- do not add cnames to localhost certs by @bochi in #595
- Don't generate sosreports when running with fapolicyd by @evgeni in #601
- Switch to Valkey 8 by @evgeni in #582
- Verify redis service is absent in tests by @evgeni in #604
- Support Tomcat using FFM by @ehelms in #472
- Fixes #596 - Add iso block to pulp apache config by @sjha4 in #597
- Load boxes.yaml by @ianballou in #500
- Add --manage-repos parameter for forge deploy-dev by @jeremylenz in #570
- Flavor: foreman-proxy-content by @arvind4501 in #571
- Fixes #598 - Add Ansible plugin settings to pulp container settings by @sjha4 in #599
- Enable parameter persistence for forge by @jeremylenz in #612
- Bump actions/checkout from 6 to 7 by @dependabot[bot] in #617
- improve deploy and deploy-proxy help by @arvind4501 in #620
- Downgrade openssl on CentOS Stream 9 VMs in CI by @ehelms in #632
- Include the external proxy in the generated sos reports by @evgeni in #634
- Enforce OAuth for Foreman API authentication via lint rule by @ehelms in #629
- Switch to openvox repositories by @ehelms in #627
- Make sure Podman uses netavark as network backend by @arvind4501 in #636
- configure hosts for ActionDispatch::HostAuthorization middleware by @evgeni in #471
- Route Candlepin logs to journald via stdout by @Alleny244 in #625
- Warn about unrecognized smart proxy features by @adamruzicka in #554
- Don't become when checking the existence of the bundle by @evgeni in #642
- use login_db instead of db when using the postgresql modules by @evgeni in #645
- Support controller node and target node backup and add tests for backup by @sjha4 in #588
- Remove --remove-feature hint from invalid feature error message by @arvind4501 in #649
- Use unix sockets for httpd -> Foreman and Pulp communication by @Gauravtalreja1 in #608
- don't include the certs/ directory in the bundle by @evgeni in #646
- Update smart-proxy settings template by @adamruzicka in #650
- Fixes #589 - Add IOP services to foreman.target by @sjha4 in #592
- Correctly regenerate the CA certificate when renew-ca was passed by @evgeni in #653
- Enforce has_feature filter for enabled_features checks by @ehelms in #626
- Refactor post_install role by @ehelms in #641
- Move flavor default into playbook vars by @ehelms in #623
- Switch to PostgreSQL 16 image by @ShimShtein in #577
- Add ostree content type support by @ianballou in #652
- Introduce feature-based test directory structure by @ekohl in #509
- Revert "Don't generate sosreports when running with fapolicyd" by @evgeni in #658
- Revert "Downgrade openssl on CentOS Stream 9 VMs in CI" by @evgeni in #659
- Only test for azure-rm and google features when enabled by @ekohl in #656
- Run pre_install role in mock-installer by @evgeni in #661
- Unset proxy environment variables before running Ansible by @Gauravtalreja1 in #654
- Foremanct - Log levels for Foreman & Proxy by @stejskalleos in #640
- Mark tests with the appropriate feature by @ekohl in #657
- Support non-root Candlepin by running as tomcat with owned secrets by @Alleny244 in #651
- Add variables iop ingress remediations by @pfreyburg in #660
- never use a proxy when performing the candlepin health check by @evgeni in #662
- fix(FDW): update inventory view to match current HBI schema by @romanblanco in #637
- Mark slow tests to allow for quicker iteration by @ekohl in #655
- Add mutually exclusive feature support via conflicts metadata by @ehelms in #610
- Rename certificate-renew-ca to certificate-ca-renew by @evgeni in #672
- Add foreman-rake wrapper by @ShimShtein in #647
- Fix PostgreSQL 13→16 upgrade path in deploy-dev by @jeremylenz in #668
- Deploy foreman-certs from source instead of unmerged PR COPR build by @ehelms in #673
- Bump actions/setup-python from 6 to 7 by @dependabot[bot] in #678
- assert /rhsm on the proxy gives 200 by @evgeni in #681
- Symlink foreman-test script to /usr/local/bin by @ehelms in #683
- Remove katello:migrate_deb_content_attributes_to_pulp3 from foreman-rake by @ShimShtein in #680
- Fix --certificate-renew-ca to --certificate-ca-renew in docs by @arvind4501 in #687
- Rename cname to server_alias by @ShimShtein in #677
- store the CA private key unencrypted by @bochi in #674
- Expand pulpcore registry route to handle flatpak index by @sjha4 in #691
- Send httpd vhost logs to journald via systemd-cat by @Alleny244 in #624
- Test refresh of internal CA doesn't break the bundle by @evgeni in #671
- Only set pulp_rhsm_url for content proxies by @pablomh in #618
- Fix SELinux context on httpd MPM event.conf by @shubhamsg199 in #692
- Remove foreman.yml from deploy-proxy vars_files by @Gauravtalreja1 in #700
- AI lint skill by @stejskalleos in #690
- Use /usr/bin/env bash instead of /bin/bash/ by @sebastianrakel in #688
- Increase ping endpoint timeout to avoid false failures during startup by @sjha4 in #702
- New param --valkey-log-level for Valkye logs by @stejskalleos in #689
- Add webhooks feature by @adamruzicka in #694
- explicitly chown Foreman data volume on start by @evgeni in #705
- Trim AGENTS.md to actionable context for AI agents by @ehelms in #669
- Add Templates feature to foreman-proxy by @shubhamsg199 in #519
- add vex tarball downloader for IoP by @pfreyburg in #638
- Add non-root container user validation by @archanaserver in #699
- Add --log-level-pulp by @stejskalleos in #697
- transfer oauth creds as part of certificate bundle by @arvind4501 in #698
- Add a test for webhooks by @adamruzicka in #713
- Always use the certs from the quadlet machine in the tests by @evgeni in #703
- Add tests and update parameters for templates feature by @shubhamsg199 in #706
- Refactor container user test to use better helpers by @ekohl in #716
- Fix httpd proxy backend precedence in deploy-dev playbook by @jeremylenz in #696
- Test foreman.target stops and starts IOP services by @aidenfine in #711
- pass server aliases to httpd role by @evgeni in #718
- Add foreman_ansible by @ehelms in #444
- Reuse obsah_params fixture to read parameters by @ekohl in #719
- Add Registration smart proxy feature (SAT-44972) by @jeremylenz in #675
- Add foremanctl restore command - Complete offline backup restore by @Chyenne8 in #549
- Foreman and OpenVox ship EL10 repos now, no need for copr by @evgeni in #730
- Bind Valkey to localhost only by @Gauravtalreja1 in #727
- Fix libvirt dependency by @michalgritzbach in #710
- remove ingress auth variable by @pfreyburg in #732
- update iop-vmaas-reposcan to use vex data by @pfreyburg in #709
- Restore Python 3.9 compatibility by @ekohl in #720
- Foreman environment fixes by @evgeni in #736
- update fdw in iop_inventory by @pfreyburg in #725
- Add chromedriver dependencies to development packages by @michalgritzbach in #707
- Add candlepin tuning by @Imaanpreet in #695
- Add custom Pulp containerfile and use information by @ianballou in #439
- Skip recurring containers in user tests by @evgeni in #743
- Add rhel-10 builds to .packit by @Odilhao in #739
- feat(iop): update vulnerability reference branch to foreman-5.0 by @adonispuente in #744
- turn off host culling in IoP host inventory by @pfreyburg in #721
- feat(iop): update inventory reference branch to foreman-5.0 by @adonispuente in #745
- Renew all the CAs by @evgeni in #679
- Set foreman secrets for all containers by @evgeni in #741
- Ensure httpd starts after foreman.socket by @Gauravtalreja1 in #747
- Don't mention Foreman in the finish message by @evgeni in #749
- Satellite flavor by @evgeni in #726
- chore(defaults): update iop_gateway tag by @vkrizan in #751
- Capsule flavor by @arvind4501 in #735
- Use 5.0 containers by @arvind4501 in #753
New Contributors
- @nacoool made their first contribution in #490
- @jturel made their first contribution in #391
- @pavanshekar made their first contribution in #458
- @aidenfine made their first contribution in #455
- @bochi made their first contribution in #503
- @Alleny244 made their first contribution in #546
- @pfreyburg made their first contribution in #564
- @amolpati30 made their first contribution in #558
- @ianballou made their first contribution in #500
- @Gauravtalreja1 made their first contribution in #608
- @romanblanco made their first contribution in #637
- @sebastianrakel made their first contribution in #688
- @Chyenne8 made their first contribution in #549
- @michalgritzbach made their first contribution in #710
- @Imaanpreet made their first contribution in #695
- @adonispuente made their first contribution in #744
- @vkrizan made their first contribution in #751
Full Changelog: 2.1.0...3.0.0