Skip to content

Releases: jetstack/jetstack-secure

v1.12.0

Choose a tag to compare

@github-actions github-actions released this 28 Sep 17:22
v1.12.0
07df543

What's Changed

Conjur JWT authentication

The CyberArk Discovery and Context Agent can now authenticate to CyberArk using a JWT from a projected service account token, instead of a username and password. Where both are configured, Conjur JWT takes precedence.

  • Add jwtsource package for reading projected service account tokens by @roeezis in #818
  • Split legacy username/password login into its own file by @roeezis in #819
  • Resolve secrets_manager alongside identity_administration by @roeezis in #820
  • Add Conjur JWT authentication client by @roeezis in #821
  • Select Conjur JWT or legacy username/password authenticator by @roeezis in #822
  • Wire Conjur JWT config into the top-level CyberArk client by @roeezis in #823
  • Add Helm chart support for Conjur JWT authentication by @roeezis in #824
  • Fall back cluster_name to cyberark.service_id under Conjur JWT by @roeezis in #827

Security hardening

Hosts returned by service discovery are no longer trusted verbatim. They must resolve to a known CyberArk domain and be reached over HTTPS. This closes a path where a tampered discovery endpoint could have received the agent's credentials.

  • Allowlist and require HTTPS for discovery-derived hosts by @roeezis in #829
  • Validate ARK_DISCOVERY_API itself against the domain allowlist by @roeezis in #830

Configuration

  • Allow config.cyberark.subdomain to be set in the agent YAML by @roeezis in #838
  • Correct the sendSecretValues comment in the chart values by @roeezis in #836
  • Add CSI information to the discovery agent by @YaaraSirkis in #816

Vulnerability fixes in the published images

Built with Go 1.27.1, the latest base image and updated dependencies. The images for this release report no fixable vulnerabilities, where v1.11.0 reported several, including a CRITICAL. Both govulncheck and a trivy image scan are clean.

Testing

No change to the agent.

New Contributors

Full Changelog: v1.11.0...v1.12.0


OCI_PREFLIGHT_IMAGE: quay.io/jetstack/venafi-agent
OCI_PREFLIGHT_TAG: v1.12.0
HELM_CHART_IMAGE: quay.io/jetstack/charts/venafi-kubernetes-agent
HELM_CHART_VERSION: v1.12.0
ARK_IMAGE: quay.io/jetstack/disco-agent
ARK_IMAGE_TAG: v1.12.0
ARK_IMAGE_DIGEST: sha256:191b490f70c0ad85fbdc2a9ee562b4018e0f37f765bab057173e3739a46f1aca
ARK_CHART: quay.io/jetstack/charts/disco-agent
ARK_CHART_TAG: v1.12.0
ARK_CHART_DIGEST: sha256:49895d7995e11b66ea06b689f7b3f219509914b4efe612c77ef5584b5016e791
NGTS_IMAGE: quay.io/jetstack/discovery-agent
NGTS_IMAGE_TAG: v1.12.0
NGTS_IMAGE_DIGEST: sha256:dbb3a30f516808541d35453a9303a7171d9c22c7af479138fec070324dae5dcd
NGTS_CHART: quay.io/jetstack/charts/discovery-agent
NGTS_CHART_TAG: v1.12.0
NGTS_CHART_DIGEST: sha256:b22c4079305b3e15f2754042d6fabe8f8167e33e08e08604149300a4be8d5946

v1.12.0-alpha.1

v1.12.0-alpha.1 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 22 Sep 11:11
v1.12.0-alpha.1
12aa9da

Note

This is an alpha pre-release, published so the changes below can be tested end to end. It is not intended for production use.

This follows v1.12.0-alpha.0 and contains everything in it. The Conjur JWT authentication and the discovery host hardening are described in those notes, and they remain the main thing we are asking you to test.

What's Changed

Configuration

  • Allow config.cyberark.subdomain to be set in the agent YAML by @roeezis in #838
  • Correct the sendSecretValues comment in the chart values by @roeezis in #836

Build and testing

No functional change to the agent. The go directive in go.mod now matches the vendored Go 1.27.1 toolchain, and the three end-to-end suites now run against master every night rather than only when someone asks for them.

Vulnerabilities

Built with Go 1.27.1. govulncheck reports no called vulnerabilities in this release.

Full Changelog: v1.12.0-alpha.0...v1.12.0-alpha.1


OCI_PREFLIGHT_IMAGE: quay.io/jetstack/venafi-agent
OCI_PREFLIGHT_TAG: v1.12.0-alpha.1
HELM_CHART_IMAGE: quay.io/jetstack/charts/venafi-kubernetes-agent
HELM_CHART_VERSION: v1.12.0-alpha.1
ARK_IMAGE: quay.io/jetstack/disco-agent
ARK_IMAGE_TAG: v1.12.0-alpha.1
ARK_IMAGE_DIGEST: sha256:8249c3ccae1343133b78741c1cc9b36458a1104b647ce2a986f35a86f09c843a
ARK_CHART: quay.io/jetstack/charts/disco-agent
ARK_CHART_TAG: v1.12.0-alpha.1
ARK_CHART_DIGEST: sha256:8181c3cc140ced0507349e7ee346e5287876e2f4d8aa8b03bbc8d23a4b9739ed
NGTS_IMAGE: quay.io/jetstack/discovery-agent
NGTS_IMAGE_TAG: v1.12.0-alpha.1
NGTS_IMAGE_DIGEST: sha256:702e753c6cb3146c6173192bee8ff3bb073dd23e7b651a66d78df1b7359a8bcd
NGTS_CHART: quay.io/jetstack/charts/discovery-agent
NGTS_CHART_TAG: v1.12.0-alpha.1
NGTS_CHART_DIGEST: sha256:edc090a89ddb629371cc9fde65865e36f545a3d3f157753ae9c2abd9401c1cbf

v1.12.0-alpha.0

v1.12.0-alpha.0 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 09 Sep 15:00
v1.12.0-alpha.0
0654c24

Note

This is an alpha pre-release, published so the changes below can be tested end to end. It is not intended for production use.

What's Changed

Conjur JWT authentication

The agent can now authenticate to CyberArk using a JWT from a projected service account token, instead of a username and password. Where both are configured, Conjur JWT takes precedence.

  • Add jwtsource package for reading projected SA tokens by @roeezis in #818
  • Split legacy username/password login into its own file by @roeezis in #819
  • Resolve secrets_manager alongside identity_administration by @roeezis in #820
  • Add Conjur JWT authentication client by @roeezis in #821
  • Select Conjur JWT or legacy username/password authenticator by @roeezis in #822
  • Wire Conjur JWT config into the top-level CyberArk client by @roeezis in #823
  • Add Helm chart support for Conjur JWT authentication by @roeezis in #824
  • Fall back cluster_name to cyberark.service_id under Conjur JWT by @roeezis in #827

Security hardening

Hosts returned by service discovery are no longer trusted verbatim. They must now resolve to a known CyberArk domain and be reached over HTTPS, which closes a path where a tampered discovery endpoint could have received the agent's credentials.

  • Allowlist and require HTTPS for discovery-derived hosts by @roeezis in #829
  • Validate ARK_DISCOVERY_API itself against the domain allowlist by @roeezis in #830

Other

Vulnerability fixes in the published images

Built with Go 1.27.1 and updated dependencies. The images for this release report no fixable vulnerabilities of MEDIUM severity or above, where v1.11.0 reported several. Both govulncheck and a trivy image scan are clean.

New Contributors

Full Changelog: v1.11.0...v1.12.0-alpha.0


OCI_PREFLIGHT_IMAGE: quay.io/jetstack/venafi-agent
OCI_PREFLIGHT_TAG: v1.12.0-alpha.0
HELM_CHART_IMAGE: quay.io/jetstack/charts/venafi-kubernetes-agent
HELM_CHART_VERSION: v1.12.0-alpha.0
ARK_IMAGE: quay.io/jetstack/disco-agent
ARK_IMAGE_TAG: v1.12.0-alpha.0
ARK_IMAGE_DIGEST: sha256:2ee75acddab269fc9fcb361f23acf35755ae8722344147a63771367351da0483
ARK_CHART: quay.io/jetstack/charts/disco-agent
ARK_CHART_TAG: v1.12.0-alpha.0
ARK_CHART_DIGEST: sha256:25b7927d395d6b09b6bfb8eaab0add42e3c10b4c0a6c55f6dca9c26f826730ee
NGTS_IMAGE: quay.io/jetstack/discovery-agent
NGTS_IMAGE_TAG: v1.12.0-alpha.0
NGTS_IMAGE_DIGEST: sha256:f1e202473a2cf1ccd82f7b0aa78e84ffec7e27ec9bceabe68a7b0fc357003e7c
NGTS_CHART: quay.io/jetstack/charts/discovery-agent
NGTS_CHART_TAG: v1.12.0-alpha.0
NGTS_CHART_DIGEST: sha256:0627c610cf2dca1b087151d78319210993d5d130ed305dbbf583eafc30a59cf4

v1.11.0

Choose a tag to compare

@github-actions github-actions released this 04 Jun 13:46
1edaed3

What's Changed

  • excludeAnnotationKeysRegex bug fix by @FelixPhipps in #806
  • VC-36593: Tests: Make sure --venafi-cloud can be used along with --client-id by @maelvls in #588
  • fix: Add default exclusions for GitOps tool annotations by @kiril-cyberark in #809
  • Make --tsg-id and --ngts-server-url mutually exclusive by @inteon in #812
  • Add VenafiConnection support for NGTS by @inteon in #811
  • Add VenafiConnection CRD to discovery-agent Helm chart by @inteon in #814
  • add _lastModifiedTime field to secret snapshots by @EldarShalev in #810

New Contributors

Full Changelog: v1.10.1...v1.11.0

v1.11.0-alpha.0

v1.11.0-alpha.0 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 04 Jun 12:44
1edaed3

What's Changed

  • Make files for v1.10.2-alpha.0 by @FelixPhipps in #807
  • VC-36593: Tests: Make sure --venafi-cloud can be used along with --client-id by @maelvls in #588
  • Fix PR588 merge conflict by @inteon in #808
  • fix: Add default exclusions for GitOps tool annotations by @kiril-cyberark in #809
  • add _lastModifiedTime field to secret snapshots by @EldarShalev in #810
  • Make --tsg-id and --ngts-server-url mutually exclusive by @inteon in #812
  • Add VenafiConnection support for NGTS by @inteon in #811
  • Upgrade klone dependencies by @inteon in #813
  • Add VenafiConnection CRD to discovery-agent Helm chart by @inteon in #814
  • Upgrade go dependencies by @inteon in #815

New Contributors

Full Changelog: v1.10.2-alpha.0...v1.11.0-alpha.0

v1.10.2-alpha.0

v1.10.2-alpha.0 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 15 May 10:43

This release tests a small bug fix for per-gatherer excludeAnnotationKeysRegex. Full release notes will be provided when v1.10.2 is released.

What's Changed

Full Changelog: v1.10.1...v1.10.2-alpha.0

v1.10.1

Choose a tag to compare

@github-actions github-actions released this 08 May 11:47
v1.10.1
a9933b9

v1.10.1 follows up directly to v1.10.0. The only changes are bumping to go 1.26.3 and bumping golang.org/x/net to v0.53.0 to fix several vulnerabilities reported by Govulncheck.

What's Changed

Full Changelog: v1.10.0...v1.10.1

v1.10.0

Choose a tag to compare

@github-actions github-actions released this 07 May 16:37
v1.10.0
81dfc4c

v1.10.0 officially releases the new discovery-agent Helm chart, which is targeted at Palo Alto's NGTS.

Documentation will be published officially elsewhere.

What's Changed

New Contributors

Full Changelog: v1.9.0...v1.10.0

v1.10.0-alpha.2

v1.10.0-alpha.2 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 06 May 13:46
3383004

This release tests the addition of excludeAnnotationKeysRegex and excludeLabelKeysRegex config fields, along with updates to tsgID, umbrella helm chart config fixes, and cert-manager gatherers. Full release notes will be provided when v1.10.0 is released.

What's Changed

  • fix: rename image helper to avoid umbrella chart conflicts by @FelixPhipps in #796
  • [VC-52458] Support both number and string for tsgID by @inteon in #798
  • fix: per-gatherer excludeAnnotationKeysRegex now excludes resources from upload by @FelixPhipps in #797
  • Add discovery-agent collection for CRD types by @SgtCoDFish in #800
  • Prepare for v1.10.0-alpha.2 release; bump dependencies by @FelixPhipps in #801

Full Changelog: v1.10.0-alpha.1...v1.10.0-alpha.2

v1.10.0-alpha.1

v1.10.0-alpha.1 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 23 Apr 13:13
380d4fd

This release tests the introduction of the claimableCerts Helm flag in the discovery-agent chart, allowing operators to control whether discovered certificates are owned by the cluster's tenant or left unassigned for other tenants to claim. Full release notes will be provided when v1.10.0 is released.

What's Changed

Full Changelog: v1.10.0-alpha.0...v1.10.0-alpha.1