Commit Graph

  • fabb80cf19 Bump dependencies Pinny 2024-12-27 14:09:36 +00:00
  • 7577f20c61 Merge pull request #2166 from vmware-tanzu/avoid_kube_32 Joshua Casey 2024-12-26 13:16:18 -06:00
  • f441714f93 Bump codegen for 1.31, 1.30, and 1.29 Joshua Casey 2024-12-26 11:30:39 -06:00
  • 2c9547e6a4 bump build image to latest Ryan Richard 2024-12-24 12:38:55 -08:00
  • 3bf3ed03f5 temporarily avoid upgrades to kube v0.32.0 without replace directives Ryan Richard 2024-12-24 12:37:48 -08:00
  • cbea626d96 actually delete clusters in new CI job to remove orphaned GKE clusters Ryan Richard 2024-12-23 11:18:56 -08:00
  • 171ec457f1 use new --filter syntax in scripts to remove orphaned Kind/GKE clusters Ryan Richard 2024-12-23 11:17:04 -08:00
  • 793559c67c fix typo in new CI job to remove orphaned GKE clusters Ryan Richard 2024-12-23 11:01:43 -08:00
  • b9fe22f3a5 add CI job to remove orphaned GKE clusters Ryan Richard 2024-12-23 10:59:06 -08:00
  • c279253e20 Merge pull request #2163 from vmware-tanzu/jtc/pin-k8s-to-1-31-4 Joshua Casey 2024-12-23 12:59:01 -06:00
  • fa9ddf48d5 Pin k8s.io dependencies to v0.31.4 Joshua Casey 2024-12-20 13:25:11 -06:00
  • b8a9c4d1e5 Bump all dependencies Joshua Casey 2024-12-20 13:24:41 -06:00
  • b4365c100f Merge pull request #2162 from vmware-tanzu/build_tags_for_tls_versions Joshua Casey 2024-12-20 14:25:22 -06:00
  • ef4b0c9cff bump golang.org/x/net Ryan Richard 2024-12-19 14:44:03 -08:00
  • b625b4a076 introduce build tags to optionally override some TLS settings Ryan Richard 2024-12-19 14:19:38 -08:00
  • b5e67330b1 Revert "Temporarily run unit tests without -race due to #2160" Ryan Richard 2024-12-19 11:34:36 -08:00
  • 6fad7ef3c2 Temporarily run unit tests without -race due to #2160 Joshua Casey 2024-12-18 08:56:21 -06:00
  • 0f3ae1cf22 Remove 1.25 codegen verification from pull-request and main pipelines Joshua Casey 2024-12-17 14:45:19 -06:00
  • 73664b5d19 Add K8s 0.32 to the main pipeline Joshua Casey 2024-12-13 15:09:58 -06:00
  • 36bc1a9d65 Add K8s 0.32 to the pull-requests pipeline Joshua Casey 2024-12-13 15:02:07 -06:00
  • 04b870d288 Add K8s 0.32 to the dockerfile-builders pipeline Joshua Casey 2024-12-13 14:57:03 -06:00
  • acbe9ce23d Merge pull request #2158 from vmware-tanzu/upgrade_fosite Joshua Casey 2024-12-13 14:11:25 -06:00
  • 90c95866d1 upgrade fosite to v0.49.0 and handle its API changes Ryan Richard 2024-12-13 10:17:42 -08:00
  • 57fc177266 Merge pull request #2156 from vmware-tanzu/pinny/bump-deps Ryan Richard 2024-12-11 10:53:48 -08:00
  • 0366f4087f Bump dependencies Pinny 2024-12-11 14:00:52 +00:00
  • 3f6d287b44 Merge pull request #2155 from vmware-tanzu/pinny/bump-deps Joshua Casey 2024-12-10 16:28:15 -06:00
  • 36aa701b56 Merge branch 'main' into pinny/bump-deps Joshua Casey 2024-12-10 13:29:48 -06:00
  • fc5a776645 Updated versions in docs for v0.36.0 release Pinny 2024-12-10 19:00:02 +00:00
  • c2b4390bfa Bump dependencies Pinny 2024-12-10 14:06:14 +00:00
  • b371389c27 Merge pull request #2154 from vmware-tanzu/jtc/fixup-before-audit-release v0.36.0 Ryan Richard 2024-12-09 12:36:49 -08:00
  • 87640ca54a Callback endpoint emits audit log with authorizeID even when code param not found Joshua Casey 2024-12-09 12:47:54 -06:00
  • 8322b03d63 Merge pull request #2153 from vmware-tanzu/pinny/bump-deps Joshua Casey 2024-12-09 10:04:13 -06:00
  • 594c3580f2 Bump dependencies Pinny 2024-12-09 14:11:21 +00:00
  • 0d80c492f1 Merge pull request #2152 from vmware-tanzu/pinny/bump-deps Joshua Casey 2024-12-05 15:23:10 -06:00
  • f45f8cf2dc Update AD creation scripts so that AD user passwords never expire Joshua Casey 2024-12-05 14:36:32 -06:00
  • 1a29cca1ca Bump dependencies Pinny 2024-12-05 14:07:26 +00:00
  • b54191f29f Merge pull request #2150 from vmware-tanzu/pinny/bump-deps Ryan Richard 2024-12-04 13:39:11 -08:00
  • 4e1aa9fa05 add hack script to rebuild all codegen images Ryan Richard 2024-12-04 09:32:40 -08:00
  • 093c56f24e upgrade golang in CI from 1.23.3 to 1.23.4 Ryan Richard 2024-12-04 09:14:52 -08:00
  • 422e4e4785 Bump dependencies Pinny 2024-12-04 14:06:21 +00:00
  • 4187cc1f61 Merge pull request #2149 from vmware-tanzu/upgrade_majors Joshua Casey 2024-12-03 19:07:28 -06:00
  • ede9e45211 make audit_test.go ignore pod log lines that aren't JSON Ryan Richard 2024-12-03 17:20:25 -06:00
  • 9960c80351 update crd-ref-docs and kube patch versions Ryan Richard 2024-12-03 14:32:25 -06:00
  • a36550d94b ran update.sh after updating kube minor versions for codegen Ryan Richard 2024-12-03 13:06:15 -06:00
  • 7c3870f3fa update kube-versions.txt for new patch versions Ryan Richard 2024-12-03 13:05:27 -06:00
  • 7ca2796774 update release_checklist.md for new hack script Ryan Richard 2024-12-03 13:05:05 -06:00
  • 170cc3bba4 ran new hack script to update all majors: updated github mod Ryan Richard 2024-12-03 12:52:29 -06:00
  • 1980912ebe add hack script to help update major versions of modules Ryan Richard 2024-12-03 12:51:40 -06:00
  • 1958bb8fb0 Clarify documentation for the advertised CA bundle of the impersonation proxy jtc/externally-configured-serving-certs Joshua Casey 2024-08-01 23:08:00 -05:00
  • 46bbe5bc75 Fix typos Joshua Casey 2024-08-01 12:19:34 -05:00
  • e6a0f94f8f Restrict which packages are aware of the keys used in Pinniped-generated certificate secrets Joshua Casey 2024-08-01 11:35:57 -05:00
  • 2e996aaecd Refactor: Use secret.Data instead of secret.StringData Joshua Casey 2024-08-01 10:16:16 -05:00
  • cfb51b3337 Rename certsManagerController to certsCreatorController Joshua Casey 2024-07-31 16:04:08 -05:00
  • 8ea393e3de Move prepare_controllers alongside Concierge server code Joshua Casey 2024-07-31 15:17:00 -05:00
  • 1571859d67 Merge pull request #2147 from vmware-tanzu/pinny/bump-deps Joshua Casey 2024-12-03 11:22:23 -06:00
  • eb4c20a6aa Bump dependencies Pinny 2024-12-03 14:04:18 +00:00
  • 1154139b91 Merge pull request #2145 from vmware-tanzu/pinny/bump-deps Joshua Casey 2024-12-02 16:52:50 -06:00
  • 28e22d7dd2 Update error text assertion due to change in ory/fosite Joshua Casey 2024-12-02 11:08:30 -06:00
  • 9cfbbb541a Standardize casing in Dockerfiles Joshua Casey 2024-12-02 10:00:39 -06:00
  • 21bce1cb92 Bump dependencies Pinny 2024-12-02 14:10:28 +00:00
  • fe045343ee Merge pull request #2009 from vmware-tanzu/audit_logging Joshua Casey 2024-11-27 15:46:34 -06:00
  • df017f9267 attempt to fix a test flake seen sometimes in CI Ryan Richard 2024-11-22 12:42:35 -08:00
  • ae5aad178d TokenCredentialRequest uses actual cert expiry time instead of estimate Ryan Richard 2024-11-21 15:18:43 -08:00
  • 032160a85e simplify single-node.yaml Ryan Richard 2024-11-21 13:02:27 -08:00
  • ecd23e86ce callback endpoint renders more useful user-facing error messages Ryan Richard 2024-11-21 13:01:32 -08:00
  • 51ae782135 fix typo in audit-logging.md Ryan Richard 2024-11-21 11:02:45 -08:00
  • 54b35c30da rename tokenIdentifier to tokenID in the audit logs Ryan Richard 2024-11-21 10:38:16 -08:00
  • dfe04c5a58 update audit-logging.md to reflect changes in recent commits Ryan Richard 2024-11-21 10:29:15 -08:00
  • 4423d472da allow audit correlation between token being issued and being used Ryan Richard 2024-11-20 13:22:31 -08:00
  • c803a182be Allow override of audit.log_usernames_and_groups for local debugging Joshua Casey 2024-11-20 12:25:34 -06:00
  • bc73505e35 Easily enable kind audit logs with ENABLE_AUDIT_LOGGING=true ./hack/kind-up.sh Joshua Casey 2024-11-20 09:55:24 -06:00
  • 0a28c818ad Small fixes for integration tests Joshua Casey 2024-11-19 21:17:30 -06:00
  • ce2dcbdbb3 simplify godoc Joshua Casey 2024-11-19 16:46:04 -06:00
  • 1ebe2fcd1a add integration test for personal info showing in login audit logs Ryan Richard 2024-11-19 13:42:55 -08:00
  • c7e9ee1c61 Backfill unit tests for paramsSafeToLog Joshua Casey 2024-11-19 14:06:34 -06:00
  • 51c86795af Backfill unit tests for cmd/pinniped/cmd/audit_id.go Joshua Casey 2024-11-19 13:29:06 -06:00
  • 8dffd60f0b Backfill unit tests for audit logging from the CLI Joshua Casey 2024-11-19 12:06:39 -06:00
  • 6bf9b64778 log response audit-id for tokencredentialrequests made from CLI Ryan Richard 2024-11-18 15:23:31 -08:00
  • 26ec7fa346 prepare-supervisor-on-kind.sh takes new --api-group-suffix flag Ryan Richard 2024-11-18 15:21:32 -08:00
  • 60bd118a9c pinniped CLI should print the audit-ID in certain error cases Joshua Casey 2024-11-18 16:30:07 -06:00
  • b69507f7f3 Add generic audit integration test Joshua Casey 2024-11-15 13:16:37 -06:00
  • 7d59df0f86 update original audit logging proposal Ryan Richard 2024-11-15 10:55:01 -08:00
  • 9c0272382f clean up audit logging documentation Ryan Richard 2024-11-15 10:43:36 -08:00
  • 2de8d9f0f3 cleanup example audit logs to make them prettier Ryan Richard 2024-11-14 14:06:53 -08:00
  • d0905c02dd use test helper in rest_test.go to reduce some duplication Ryan Richard 2024-11-14 13:07:26 -08:00
  • 51fc86f950 don't audit log missing username or password, change query param value Ryan Richard 2024-11-14 12:52:05 -08:00
  • 76bda12760 update audit-logging.md to resolve todos Ryan Richard 2024-11-14 12:08:53 -08:00
  • a84b76e56a audit log session ID in token handler for every grant type Ryan Richard 2024-11-14 12:08:34 -08:00
  • c2018717b6 audit log OIDCClientSecretRequests Ryan Richard 2024-11-14 09:55:31 -08:00
  • f388513145 resolve TODO by adding docs Joshua Casey 2024-11-14 10:59:41 -06:00
  • c16ebe1707 add unit test for audit logging when token refresh updates groups Ryan Richard 2024-11-13 13:45:44 -08:00
  • b54365c199 audit log request params on GET and POST login handlers Ryan Richard 2024-11-13 13:34:45 -08:00
  • 51d1cc7a96 refactor and add unit test for AuditRequestParams() Ryan Richard 2024-11-13 12:50:17 -08:00
  • c06141c871 token handler uses common method to audit HTTP request parameters Ryan Richard 2024-11-13 11:56:00 -08:00
  • eab3fde3af introduce common method to audit HTTP request parameters Ryan Richard 2024-11-13 11:46:50 -08:00
  • de7781b7f9 Use correct caller when generating audit events Joshua Casey 2024-11-13 14:42:10 -06:00
  • 611de03e01 Add audit event 'Incorrect Username Or Password' to auth_handler and audit event 'Using Upstream IDP' to callback_handler Joshua Casey 2024-11-13 13:36:25 -06:00
  • de722332b1 Add audit logging to post_login_handler Joshua Casey 2024-11-13 12:29:23 -06:00
  • 438ca437ec tokencredentialrequest audit logs failed requests Ryan Richard 2024-11-12 16:13:41 -08:00
  • e21e1326b7 tokencredentialrequest audit logs successful responses Ryan Richard 2024-11-12 14:08:36 -08:00