Releases: jetstack/jetstack-secure
Release list
v1.12.0
What's Changed
Conjur JWT authentication
The CyberArk Discovery and Context Agent can now authenticate to CyberArk using a JWT from a projected service account token, instead of a username and password. Where both are configured, Conjur JWT takes precedence.
- Add
jwtsourcepackage for reading projected service account tokens by @roeezis in #818 - Split legacy username/password login into its own file by @roeezis in #819
- Resolve
secrets_manageralongsideidentity_administrationby @roeezis in #820 - Add Conjur JWT authentication client by @roeezis in #821
- Select Conjur JWT or legacy username/password authenticator by @roeezis in #822
- Wire Conjur JWT config into the top-level CyberArk client by @roeezis in #823
- Add Helm chart support for Conjur JWT authentication by @roeezis in #824
- Fall back
cluster_nametocyberark.service_idunder Conjur JWT by @roeezis in #827
Security hardening
Hosts returned by service discovery are no longer trusted verbatim. They must resolve to a known CyberArk domain and be reached over HTTPS. This closes a path where a tampered discovery endpoint could have received the agent's credentials.
- Allowlist and require HTTPS for discovery-derived hosts by @roeezis in #829
- Validate
ARK_DISCOVERY_APIitself against the domain allowlist by @roeezis in #830
Configuration
- Allow
config.cyberark.subdomainto be set in the agent YAML by @roeezis in #838 - Correct the
sendSecretValuescomment in the chart values by @roeezis in #836 - Add CSI information to the discovery agent by @YaaraSirkis in #816
Vulnerability fixes in the published images
Built with Go 1.27.1, the latest base image and updated dependencies. The images for this release report no fixable vulnerabilities, where v1.11.0 reported several, including a CRITICAL. Both govulncheck and a trivy image scan are clean.
- Upgrade makefile-modules and move to Go 1.27.1 by @wallrj-cyberark in #831
- Bump
golang.org/x/textto v0.39.0 to fix GO-2026-5970 by @wallrj-cyberark in #832 - Bump
x/crypto,x/netandcel-goto clear trivy image findings by @wallrj-cyberark in #834 - Align the
godirective with the vendored Go 1.27.1 toolchain by @FelixPhipps in #841 - Upgrade makefile-modules to pick up the latest base image by @wallrj-cyberark in #844
Testing
No change to the agent.
- Run the end-to-end suites on pull requests from forks by @mladen-rusev-cyberark in #826
- Document why the migration-precedence test already proves Conjur wins over username/password by @roeezis in #828
- Allow the end-to-end suites to be run manually against
masterby @wallrj-cyberark in #833 - Stop the VCP end-to-end test hanging when the certificate never appears by @wallrj-cyberark in #835
- Start only the matching end-to-end suite when its label is added by @wallrj-cyberark in #837
- Run the end-to-end suites against
masterevery night by @wallrj-cyberark in #842 - Print the certificate SHA-1 thumbprint in the VCP end-to-end test by @wallrj-cyberark in #843
New Contributors
- @YaaraSirkis made their first contribution in #816
- @roeezis made their first contribution in #818
Full Changelog: v1.11.0...v1.12.0
OCI_PREFLIGHT_IMAGE: quay.io/jetstack/venafi-agent
OCI_PREFLIGHT_TAG: v1.12.0
HELM_CHART_IMAGE: quay.io/jetstack/charts/venafi-kubernetes-agent
HELM_CHART_VERSION: v1.12.0
ARK_IMAGE: quay.io/jetstack/disco-agent
ARK_IMAGE_TAG: v1.12.0
ARK_IMAGE_DIGEST: sha256:191b490f70c0ad85fbdc2a9ee562b4018e0f37f765bab057173e3739a46f1aca
ARK_CHART: quay.io/jetstack/charts/disco-agent
ARK_CHART_TAG: v1.12.0
ARK_CHART_DIGEST: sha256:49895d7995e11b66ea06b689f7b3f219509914b4efe612c77ef5584b5016e791
NGTS_IMAGE: quay.io/jetstack/discovery-agent
NGTS_IMAGE_TAG: v1.12.0
NGTS_IMAGE_DIGEST: sha256:dbb3a30f516808541d35453a9303a7171d9c22c7af479138fec070324dae5dcd
NGTS_CHART: quay.io/jetstack/charts/discovery-agent
NGTS_CHART_TAG: v1.12.0
NGTS_CHART_DIGEST: sha256:b22c4079305b3e15f2754042d6fabe8f8167e33e08e08604149300a4be8d5946
v1.12.0-alpha.1
Note
This is an alpha pre-release, published so the changes below can be tested end to end. It is not intended for production use.
This follows v1.12.0-alpha.0 and contains everything in it. The Conjur JWT authentication and the discovery host hardening are described in those notes, and they remain the main thing we are asking you to test.
What's Changed
Configuration
- Allow
config.cyberark.subdomainto be set in the agent YAML by @roeezis in #838 - Correct the
sendSecretValuescomment in the chart values by @roeezis in #836
Build and testing
No functional change to the agent. The go directive in go.mod now matches the vendored Go 1.27.1 toolchain, and the three end-to-end suites now run against master every night rather than only when someone asks for them.
- Align the
godirective with the vendored Go 1.27.1 toolchain by @FelixPhipps in #841 - Run the end-to-end suites against
masterevery night by @wallrj-cyberark in #842 - Start only the matching end-to-end suite when its label is added by @wallrj-cyberark in #837
- Stop the VCP end-to-end test hanging when the certificate never appears by @wallrj-cyberark in #835
- Print the certificate SHA-1 thumbprint in the VCP end-to-end test by @wallrj-cyberark in #843
Vulnerabilities
Built with Go 1.27.1. govulncheck reports no called vulnerabilities in this release.
Full Changelog: v1.12.0-alpha.0...v1.12.0-alpha.1
OCI_PREFLIGHT_IMAGE: quay.io/jetstack/venafi-agent
OCI_PREFLIGHT_TAG: v1.12.0-alpha.1
HELM_CHART_IMAGE: quay.io/jetstack/charts/venafi-kubernetes-agent
HELM_CHART_VERSION: v1.12.0-alpha.1
ARK_IMAGE: quay.io/jetstack/disco-agent
ARK_IMAGE_TAG: v1.12.0-alpha.1
ARK_IMAGE_DIGEST: sha256:8249c3ccae1343133b78741c1cc9b36458a1104b647ce2a986f35a86f09c843a
ARK_CHART: quay.io/jetstack/charts/disco-agent
ARK_CHART_TAG: v1.12.0-alpha.1
ARK_CHART_DIGEST: sha256:8181c3cc140ced0507349e7ee346e5287876e2f4d8aa8b03bbc8d23a4b9739ed
NGTS_IMAGE: quay.io/jetstack/discovery-agent
NGTS_IMAGE_TAG: v1.12.0-alpha.1
NGTS_IMAGE_DIGEST: sha256:702e753c6cb3146c6173192bee8ff3bb073dd23e7b651a66d78df1b7359a8bcd
NGTS_CHART: quay.io/jetstack/charts/discovery-agent
NGTS_CHART_TAG: v1.12.0-alpha.1
NGTS_CHART_DIGEST: sha256:edc090a89ddb629371cc9fde65865e36f545a3d3f157753ae9c2abd9401c1cbf
v1.12.0-alpha.0
Note
This is an alpha pre-release, published so the changes below can be tested end to end. It is not intended for production use.
What's Changed
Conjur JWT authentication
The agent can now authenticate to CyberArk using a JWT from a projected service account token, instead of a username and password. Where both are configured, Conjur JWT takes precedence.
- Add
jwtsourcepackage for reading projected SA tokens by @roeezis in #818 - Split legacy username/password login into its own file by @roeezis in #819
- Resolve
secrets_manageralongsideidentity_administrationby @roeezis in #820 - Add Conjur JWT authentication client by @roeezis in #821
- Select Conjur JWT or legacy username/password authenticator by @roeezis in #822
- Wire Conjur JWT config into the top-level CyberArk client by @roeezis in #823
- Add Helm chart support for Conjur JWT authentication by @roeezis in #824
- Fall back
cluster_nametocyberark.service_idunder Conjur JWT by @roeezis in #827
Security hardening
Hosts returned by service discovery are no longer trusted verbatim. They must now resolve to a known CyberArk domain and be reached over HTTPS, which closes a path where a tampered discovery endpoint could have received the agent's credentials.
- Allowlist and require HTTPS for discovery-derived hosts by @roeezis in #829
- Validate
ARK_DISCOVERY_APIitself against the domain allowlist by @roeezis in #830
Other
- Add CSI information to discovery-agent by @YaaraSirkis in #816
Vulnerability fixes in the published images
Built with Go 1.27.1 and updated dependencies. The images for this release report no fixable vulnerabilities of MEDIUM severity or above, where v1.11.0 reported several. Both govulncheck and a trivy image scan are clean.
New Contributors
- @YaaraSirkis made their first contribution in #816
- @roeezis made their first contribution in #818
Full Changelog: v1.11.0...v1.12.0-alpha.0
OCI_PREFLIGHT_IMAGE: quay.io/jetstack/venafi-agent
OCI_PREFLIGHT_TAG: v1.12.0-alpha.0
HELM_CHART_IMAGE: quay.io/jetstack/charts/venafi-kubernetes-agent
HELM_CHART_VERSION: v1.12.0-alpha.0
ARK_IMAGE: quay.io/jetstack/disco-agent
ARK_IMAGE_TAG: v1.12.0-alpha.0
ARK_IMAGE_DIGEST: sha256:2ee75acddab269fc9fcb361f23acf35755ae8722344147a63771367351da0483
ARK_CHART: quay.io/jetstack/charts/disco-agent
ARK_CHART_TAG: v1.12.0-alpha.0
ARK_CHART_DIGEST: sha256:25b7927d395d6b09b6bfb8eaab0add42e3c10b4c0a6c55f6dca9c26f826730ee
NGTS_IMAGE: quay.io/jetstack/discovery-agent
NGTS_IMAGE_TAG: v1.12.0-alpha.0
NGTS_IMAGE_DIGEST: sha256:f1e202473a2cf1ccd82f7b0aa78e84ffec7e27ec9bceabe68a7b0fc357003e7c
NGTS_CHART: quay.io/jetstack/charts/discovery-agent
NGTS_CHART_TAG: v1.12.0-alpha.0
NGTS_CHART_DIGEST: sha256:0627c610cf2dca1b087151d78319210993d5d130ed305dbbf583eafc30a59cf4
v1.11.0
What's Changed
- excludeAnnotationKeysRegex bug fix by @FelixPhipps in #806
- VC-36593: Tests: Make sure --venafi-cloud can be used along with --client-id by @maelvls in #588
- fix: Add default exclusions for GitOps tool annotations by @kiril-cyberark in #809
- Make --tsg-id and --ngts-server-url mutually exclusive by @inteon in #812
- Add VenafiConnection support for NGTS by @inteon in #811
- Add VenafiConnection CRD to discovery-agent Helm chart by @inteon in #814
- add _lastModifiedTime field to secret snapshots by @EldarShalev in #810
New Contributors
- @kiril-cyberark made their first contribution in #809
- @EldarShalev made their first contribution in #810
Full Changelog: v1.10.1...v1.11.0
v1.11.0-alpha.0
What's Changed
- Make files for v1.10.2-alpha.0 by @FelixPhipps in #807
- VC-36593: Tests: Make sure --venafi-cloud can be used along with --client-id by @maelvls in #588
- Fix PR588 merge conflict by @inteon in #808
- fix: Add default exclusions for GitOps tool annotations by @kiril-cyberark in #809
- add _lastModifiedTime field to secret snapshots by @EldarShalev in #810
- Make --tsg-id and --ngts-server-url mutually exclusive by @inteon in #812
- Add VenafiConnection support for NGTS by @inteon in #811
- Upgrade klone dependencies by @inteon in #813
- Add VenafiConnection CRD to discovery-agent Helm chart by @inteon in #814
- Upgrade go dependencies by @inteon in #815
New Contributors
- @kiril-cyberark made their first contribution in #809
- @EldarShalev made their first contribution in #810
Full Changelog: v1.10.2-alpha.0...v1.11.0-alpha.0
v1.10.2-alpha.0
This release tests a small bug fix for per-gatherer excludeAnnotationKeysRegex. Full release notes will be provided when v1.10.2 is released.
What's Changed
- excludeAnnotationKeysRegex bug fix by @FelixPhipps in #806
Full Changelog: v1.10.1...v1.10.2-alpha.0
v1.10.1
v1.10.1 follows up directly to v1.10.0. The only changes are bumping to go 1.26.3 and bumping golang.org/x/net to v0.53.0 to fix several vulnerabilities reported by Govulncheck.
What's Changed
- Run make upgrade-klone && make generate by @SgtCoDFish in #804
- Bump x/net to address GO-2026-4918 by @SgtCoDFish in #805
Full Changelog: v1.10.0...v1.10.1
v1.10.0
v1.10.0 officially releases the new discovery-agent Helm chart, which is targeted at Palo Alto's NGTS.
Documentation will be published officially elsewhere.
What's Changed
- Add NGTS configuration + NGTS client by @SgtCoDFish in #788
- Add helm chart for NGTS-capable agent by @SgtCoDFish in #789
- disco: re-enable secret sending by default by @SgtCoDFish in #787
- NGTS: Various further updates and fixes by @SgtCoDFish in #790
- Run make upgrade-klone and make generate by @SgtCoDFish in #792
- Force TSG ID to be string, add helm unit-tests by @SgtCoDFish in #793
- Update release process by @SgtCoDFish in #791
- VC-52159: add certOwnership Helm flag to discovery-agent chart by @George-Yanev in #794
- fix: rename image helper to avoid umbrella chart conflicts by @FelixPhipps in #796
- [VC-52458] Support both number and string for tsgID by @inteon in #798
- fix: per-gatherer excludeAnnotationKeysRegex now excludes resources from upload by @FelixPhipps in #797
- Add discovery-agent collection for CRD types by @SgtCoDFish in #800
- Prepare for v1.10.0-alpha.2 release; bump dependencies by @FelixPhipps in #801
- Add helm unit tests for claimable certs behaviour by @SgtCoDFish in #803
- Add command for dumping resources which are watched by default by @SgtCoDFish in #802
New Contributors
- @George-Yanev made their first contribution in #794
Full Changelog: v1.9.0...v1.10.0
v1.10.0-alpha.2
This release tests the addition of excludeAnnotationKeysRegex and excludeLabelKeysRegex config fields, along with updates to tsgID, umbrella helm chart config fixes, and cert-manager gatherers. Full release notes will be provided when v1.10.0 is released.
What's Changed
- fix: rename image helper to avoid umbrella chart conflicts by @FelixPhipps in #796
- [VC-52458] Support both number and string for tsgID by @inteon in #798
- fix: per-gatherer excludeAnnotationKeysRegex now excludes resources from upload by @FelixPhipps in #797
- Add discovery-agent collection for CRD types by @SgtCoDFish in #800
- Prepare for v1.10.0-alpha.2 release; bump dependencies by @FelixPhipps in #801
Full Changelog: v1.10.0-alpha.1...v1.10.0-alpha.2
v1.10.0-alpha.1
This release tests the introduction of the claimableCerts Helm flag in the discovery-agent chart, allowing operators to control whether discovered certificates are owned by the cluster's tenant or left unassigned for other tenants to claim. Full release notes will be provided when v1.10.0 is released.
What's Changed
- Add claimableCerts Helm flag to discovery-agent chart by @George-Yanev in #794
Full Changelog: v1.10.0-alpha.0...v1.10.0-alpha.1