chore: merge upstream v1.15.2#5
Merged
Merged
Conversation
…7.0 (spiffe#6997) Bumps [github.com/open-policy-agent/opa](https://github.com/open-policy-agent/opa) from 1.16.2 to 1.17.0. - [Release notes](https://github.com/open-policy-agent/opa/releases) - [Changelog](https://github.com/open-policy-agent/opa/blob/main/CHANGELOG.md) - [Commits](open-policy-agent/opa@v1.16.2...v1.17.0) --- updated-dependencies: - dependency-name: github.com/open-policy-agent/opa dependency-version: 1.17.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: Sorin Dumitru <sorin@returnze.ro>
Bumps the aws-sdk group with 2 updates: [github.com/aws/aws-sdk-go-v2/service/s3](https://github.com/aws/aws-sdk-go-v2) and [github.com/aws/smithy-go](https://github.com/aws/smithy-go). Updates `github.com/aws/aws-sdk-go-v2/service/s3` from 1.101.0 to 1.102.0 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@service/s3/v1.101.0...service/s3/v1.102.0) Updates `github.com/aws/smithy-go` from 1.25.1 to 1.26.0 - [Release notes](https://github.com/aws/smithy-go/releases) - [Changelog](https://github.com/aws/smithy-go/blob/main/CHANGELOG.md) - [Commits](aws/smithy-go@v1.25.1...v1.26.0) --- updated-dependencies: - dependency-name: github.com/aws/aws-sdk-go-v2/service/s3 dependency-version: 1.102.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: aws-sdk - dependency-name: github.com/aws/smithy-go dependency-version: 1.26.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: aws-sdk ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…iffe#7000) Signed-off-by: immanuwell <pchpr.00@list.ru>
Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
…piffe#7005) Bumps [github.com/sigstore/sigstore](https://github.com/sigstore/sigstore) from 1.10.6 to 1.10.7. - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.10.6...v1.10.7) --- updated-dependencies: - dependency-name: github.com/sigstore/sigstore dependency-version: 1.10.7 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the google-cloud-sdk group with 1 update: [cloud.google.com/go/security](https://github.com/googleapis/google-cloud-go). Updates `cloud.google.com/go/security` from 1.24.0 to 1.25.0 - [Release notes](https://github.com/googleapis/google-cloud-go/releases) - [Changelog](https://github.com/googleapis/google-cloud-go/blob/main/documentai/CHANGES.md) - [Commits](googleapis/google-cloud-go@kms/v1.24.0...kms/v1.25.0) --- updated-dependencies: - dependency-name: cloud.google.com/go/security dependency-version: 1.25.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: google-cloud-sdk ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…piffe#7003) Bumps the aws-sdk group with 1 update: [github.com/aws/aws-sdk-go-v2/service/autoscaling](https://github.com/aws/aws-sdk-go-v2). Updates `github.com/aws/aws-sdk-go-v2/service/autoscaling` from 1.66.0 to 1.67.0 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@service/s3/v1.66.0...service/s3/v1.67.0) --- updated-dependencies: - dependency-name: github.com/aws/aws-sdk-go-v2/service/autoscaling dependency-version: 1.67.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: aws-sdk ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* Add Copilot repository custom instructions Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com> * Address Copilot comments Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com> * Add links to the SDK repositories Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com> * Note that field names come from pkg/common/telemetry/names.go Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com> --------- Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
Go 1.26 added support for these so we can allow using them Signed-off-by: Sorin Dumitru <sorin@returnze.ro>
…spiffe#7014) Bumps the google-cloud-sdk group with 1 update: [google.golang.org/api](https://github.com/googleapis/google-api-go-client). Updates `google.golang.org/api` from 0.282.0 to 0.283.0 - [Release notes](https://github.com/googleapis/google-api-go-client/releases) - [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md) - [Commits](googleapis/google-api-go-client@v0.282.0...v0.283.0) --- updated-dependencies: - dependency-name: google.golang.org/api dependency-version: 0.283.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: google-cloud-sdk ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…piffe#7016) Bumps [github.com/sigstore/sigstore](https://github.com/sigstore/sigstore) from 1.10.7 to 1.10.8. - [Release notes](https://github.com/sigstore/sigstore/releases) - [Commits](sigstore/sigstore@v1.10.7...v1.10.8) --- updated-dependencies: - dependency-name: github.com/sigstore/sigstore dependency-version: 1.10.8 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* agent: log configured workload selectors on identity failures Signed-off-by: Carlo Teubner <cteubner1@bloomberg.net> * agent: minor refactor to reduce num params Signed-off-by: Carlo Teubner <cteubner1@bloomberg.net> * agent: log selectors as single string Addresses review comment. Signed-off-by: Carlo Teubner <cteubner1@bloomberg.net> * agent: Sort selectors before logging Signed-off-by: Carlo Teubner <cteubner1@bloomberg.net> --------- Signed-off-by: Carlo Teubner <cteubner1@bloomberg.net>
…spiffe#7015) Bumps [github.com/shirou/gopsutil/v4](https://github.com/shirou/gopsutil) from 4.26.4 to 4.26.5. - [Release notes](https://github.com/shirou/gopsutil/releases) - [Commits](shirou/gopsutil@v4.26.4...v4.26.5) --- updated-dependencies: - dependency-name: github.com/shirou/gopsutil/v4 dependency-version: 4.26.5 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the aws-sdk group with 7 updates: | Package | From | To | | --- | --- | --- | | [github.com/aws/aws-sdk-go-v2/service/ec2](https://github.com/aws/aws-sdk-go-v2) | `1.304.0` | `1.305.0` | | [github.com/aws/aws-sdk-go-v2/service/iam](https://github.com/aws/aws-sdk-go-v2) | `1.53.1` | `1.54.1` | | [github.com/aws/aws-sdk-go-v2/service/kms](https://github.com/aws/aws-sdk-go-v2) | `1.52.0` | `1.53.1` | | [github.com/aws/aws-sdk-go-v2/service/s3](https://github.com/aws/aws-sdk-go-v2) | `1.102.0` | `1.103.0` | | [github.com/aws/aws-sdk-go-v2/service/secretsmanager](https://github.com/aws/aws-sdk-go-v2) | `1.41.0` | `1.42.0` | | [github.com/aws/aws-sdk-go-v2/service/sts](https://github.com/aws/aws-sdk-go-v2) | `1.42.0` | `1.43.0` | | [github.com/aws/smithy-go](https://github.com/aws/smithy-go) | `1.26.0` | `1.27.0` | Updates `github.com/aws/aws-sdk-go-v2/service/ec2` from 1.304.0 to 1.305.0 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@service/ec2/v1.304.0...service/ec2/v1.305.0) Updates `github.com/aws/aws-sdk-go-v2/service/iam` from 1.53.1 to 1.54.1 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@service/s3/v1.53.1...service/s3/v1.54.1) Updates `github.com/aws/aws-sdk-go-v2/service/kms` from 1.52.0 to 1.53.1 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@service/s3/v1.52.0...service/s3/v1.53.1) Updates `github.com/aws/aws-sdk-go-v2/service/s3` from 1.102.0 to 1.103.0 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@service/s3/v1.102.0...service/s3/v1.103.0) Updates `github.com/aws/aws-sdk-go-v2/service/secretsmanager` from 1.41.0 to 1.42.0 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@v1.41.0...service/s3/v1.42.0) Updates `github.com/aws/aws-sdk-go-v2/service/sts` from 1.42.0 to 1.43.0 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@service/s3/v1.42.0...service/s3/v1.43.0) Updates `github.com/aws/smithy-go` from 1.26.0 to 1.27.0 - [Release notes](https://github.com/aws/smithy-go/releases) - [Changelog](https://github.com/aws/smithy-go/blob/main/CHANGELOG.md) - [Commits](aws/smithy-go@v1.26.0...v1.27.0) --- updated-dependencies: - dependency-name: github.com/aws/aws-sdk-go-v2/service/ec2 dependency-version: 1.305.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: aws-sdk - dependency-name: github.com/aws/aws-sdk-go-v2/service/iam dependency-version: 1.54.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: aws-sdk - dependency-name: github.com/aws/aws-sdk-go-v2/service/kms dependency-version: 1.53.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: aws-sdk - dependency-name: github.com/aws/aws-sdk-go-v2/service/s3 dependency-version: 1.103.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: aws-sdk - dependency-name: github.com/aws/aws-sdk-go-v2/service/secretsmanager dependency-version: 1.42.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: aws-sdk - dependency-name: github.com/aws/aws-sdk-go-v2/service/sts dependency-version: 1.43.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: aws-sdk - dependency-name: github.com/aws/smithy-go dependency-version: 1.27.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: aws-sdk ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 6.0.3. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@de0fac2...df4cb1c) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 6.0.3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…e#7026) Bumps [github.com/jackc/pgx/v5](https://github.com/jackc/pgx) from 5.9.2 to 5.10.0. - [Changelog](https://github.com/jackc/pgx/blob/master/CHANGELOG.md) - [Commits](jackc/pgx@v5.9.2...v5.10.0) --- updated-dependencies: - dependency-name: github.com/jackc/pgx/v5 dependency-version: 5.10.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…iffe#7032) Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
…he aws-sdk group (spiffe#7033) build(deps): bump github.com/aws/smithy-go in the aws-sdk group Bumps the aws-sdk group with 1 update: [github.com/aws/smithy-go](https://github.com/aws/smithy-go). Updates `github.com/aws/smithy-go` from 1.27.0 to 1.27.1 - [Release notes](https://github.com/aws/smithy-go/releases) - [Changelog](https://github.com/aws/smithy-go/blob/main/CHANGELOG.md) - [Commits](aws/smithy-go@v1.27.0...v1.27.1) --- updated-dependencies: - dependency-name: github.com/aws/smithy-go dependency-version: 1.27.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: aws-sdk ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* server sql doc: explain connection string Signed-off-by: Carlo Teubner <cteubner1@bloomberg.net> * server sql doc: spelling of AWS_SECRET_ACCESS_KEY Signed-off-by: Carlo Teubner <cteubner1@bloomberg.net> * server sql doc: misc cleanups Signed-off-by: Carlo Teubner <cteubner1@bloomberg.net> --------- Signed-off-by: Carlo Teubner <cteubner1@bloomberg.net>
…ss (spiffe#7031) * Retry container image pulls in integration tests to reduce CI flakiness Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com> * Hardcode retry attempts and backoff in integration tests Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com> --------- Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
* Upgrade go-spiffe to 2.7.0 Signed-off-by: Sorin Dumitru <sorin@returnze.ro> * Add dumy implementations for WIT-SVID API Signed-off-by: Sorin Dumitru <sorin@returnze.ro> --------- Signed-off-by: Sorin Dumitru <sorin@returnze.ro>
…n test (spiffe#7037) * Remove stale kindest/node pin from the cert-manager integration test Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com> * Remove the now-unused cert-manager kind config Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com> --------- Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
…piffe#7012) * Add round-robin reviewer auto-assignment with ball-in-court tracking Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com> * Address Copilot comments Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com> * Address Copilot comments Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com> * Exclude bot-authored PRs from reviewer rotation Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com> * Pick the PR assignee at random instead of by PR number Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com> --------- Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
Scope assign-reviewer concurrency per event action Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
…spiffe#7041) Bumps [github.com/mattn/go-sqlite3](https://github.com/mattn/go-sqlite3) from 1.14.44 to 1.14.45. - [Release notes](https://github.com/mattn/go-sqlite3/releases) - [Commits](mattn/go-sqlite3@v1.14.44...v1.14.45) --- updated-dependencies: - dependency-name: github.com/mattn/go-sqlite3 dependency-version: 1.14.45 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…piffe#7040) Bumps [github.com/google/go-tpm-tools](https://github.com/google/go-tpm-tools) from 0.4.8 to 0.4.9. - [Release notes](https://github.com/google/go-tpm-tools/releases) - [Commits](google/go-tpm-tools@v0.4.8...v0.4.9) --- updated-dependencies: - dependency-name: github.com/google/go-tpm-tools dependency-version: 0.4.9 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
….21.1 to 1.22.0 in the azure-sdk group (spiffe#7039) build(deps): bump github.com/Azure/azure-sdk-for-go/sdk/azcore Bumps the azure-sdk group with 1 update: [github.com/Azure/azure-sdk-for-go/sdk/azcore](https://github.com/Azure/azure-sdk-for-go). Updates `github.com/Azure/azure-sdk-for-go/sdk/azcore` from 1.21.1 to 1.22.0 - [Release notes](https://github.com/Azure/azure-sdk-for-go/releases) - [Commits](Azure/azure-sdk-for-go@sdk/azcore/v1.21.1...sdk/azcore/v1.22.0) --- updated-dependencies: - dependency-name: github.com/Azure/azure-sdk-for-go/sdk/azcore dependency-version: 1.22.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: azure-sdk ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: Keegan Witt <keeganwitt@gmail.com>
…#6812) * Add SPIRE-backed Prometheus TLS identity and SPIFFE allowlist (cherry picked from commit 2ec839e) Signed-off-by: aviralgarg05 <gargaviral99@gmail.com> * Fix markdown table formatting to pass lint Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com> --------- Signed-off-by: aviralgarg05 <gargaviral99@gmail.com> Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com> Co-authored-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
…f4b9e2490560 to 4b4db1dcc7dad75ad67a788a380f75a20cc8a040 (spiffe#7090) build(deps): bump regclient/actions Bumps [regclient/actions](https://github.com/regclient/actions) from 14f9d37db17b5dc41fefd1ffdd1af4b9e2490560 to 4b4db1dcc7dad75ad67a788a380f75a20cc8a040. - [Release notes](https://github.com/regclient/actions/releases) - [Changelog](https://github.com/regclient/actions/blob/main/RELEASE.md) - [Commits](regclient/actions@14f9d37...4b4db1d) --- updated-dependencies: - dependency-name: regclient/actions dependency-version: 4b4db1dcc7dad75ad67a788a380f75a20cc8a040 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.3 to 7.0.0. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@df4cb1c...9c091bb) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…r-and-patch group (spiffe#7088) build(deps): bump msys2/setup-msys2 in the minor-and-patch group Bumps the minor-and-patch group with 1 update: [msys2/setup-msys2](https://github.com/msys2/setup-msys2). Updates `msys2/setup-msys2` from 2.31.1 to 2.32.0 - [Release notes](https://github.com/msys2/setup-msys2/releases) - [Changelog](https://github.com/msys2/setup-msys2/blob/main/CHANGELOG.md) - [Commits](msys2/setup-msys2@e989830...66cd2cc) --- updated-dependencies: - dependency-name: msys2/setup-msys2 dependency-version: 2.32.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…piffe#7071) fix: correct TTL logging in delegated identity subscriber when admin/downstream identities are present Signed-off-by: immanuwell <pchpr.00@list.ru>
spiffe#7095) Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
* spire-agent: implement logger service Signed-off-by: Sorin Dumitru <sorin@returnze.ro> * Copilot review comments Signed-off-by: Sorin Dumitru <sorin@returnze.ro> * review comments Signed-off-by: Sorin Dumitru <sorin@returnze.ro> * review comments Signed-off-by: Sorin Dumitru <sorin@returnze.ro> * Remove auditing there's no auditing support in the agent Signed-off-by: Sorin Dumitru <sorin@returnze.ro> * Use agent rpccontext Signed-off-by: Sorin Dumitru <sorin@returnze.ro> * Move status helpers to common/api Signed-off-by: Sorin Dumitru <sorin@returnze.ro> * Use status helpers from common/api Signed-off-by: Sorin Dumitru <sorin@returnze.ro> * Make sure logger metrics are emitted Signed-off-by: Sorin Dumitru <sorin@returnze.ro> * fix linter errors Signed-off-by: Sorin Dumitru <sorin@returnze.ro> * Review comments Signed-off-by: Sorin Dumitru <sorin@returnze.ro> * Add RPC metric name test Signed-off-by: Sorin Dumitru <sorin@returnze.ro> --------- Signed-off-by: Sorin Dumitru <sorin@returnze.ro>
…ffe#6946) * fix: cascade-delete registered_entries on attested node deletion Previously, deleteAttestedNodeAndSelectors deleted AttestedNode and NodeSelector rows but left registered_entries with parent_id matching the deleted node's SPIFFE ID untouched. In particular, the alias row that SPIRE auto-creates in createJoinTokenRegistrationEntry (when CreateJoinToken is called with AgentId) would survive the node it was minted for, accumulating as dead rows that still flow through the server's entry cache and the events-based cache. This extends deleteAttestedNodeAndSelectors to cascade: find entries whose parent_id equals the deleted node's SPIFFE ID, delete each via the existing deleteRegistrationEntrySupport helper, emit a RegistrationEntryEvent per deletion so event-cache consumers see them, and log each cascaded delete at Info with the usual SPIFFEID/ParentID/RegistrationID telemetry fields (matching the pruneRegistrationEntries pattern). The cascade fires for both DeleteAttestedNode (admin delete) and PruneAttestedExpiredNodes (periodic prune) since both paths reach this helper. Callers pass their existing logger (ds.log for DeleteAttestedNode, the prune logger for PruneAttestedExpiredNodes). Mirrors the shape of spiffe#3873 which added the node_resolver_map_entries cascade at the same function. Fixes spiffe#6944 Signed-off-by: angabini <494150+angabini@users.noreply.github.com> * doc: update spire_server.md Signed-off-by: angabini <494150+angabini@users.noreply.github.com> * doc: cleanup spire_server.md Signed-off-by: angabini <494150+angabini@users.noreply.github.com> * fix(sqlstore): narrow cascade to join-token-attested nodes Per review feedback on spiffe#6946: cascading every entry parented on a deleted attested node would also wipe legitimately user-registered workload entries that happen to be parented directly on a non-join- token agent SVID (e.g. spiffe://td/spire/agent/aws_iid/...). That is a supported registration pattern, not an orphan. Restrict the cascade in deleteAttestedNodeAndSelectors to nodes whose attested DataType is "join_token". The auto-alias that createJoinTokenRegistrationEntry writes is the only entry SPIRE itself creates with parent_id = node SVID, so this still cleans up the unbounded-growth case reported in spiffe#6944 without changing behavior for any other attestor. A broader explicit cascade can be added later behind a CLI flag, as suggested in the issue. Add TestDeleteAttestedNodeNonJoinTokenDoesNotCascade asserting an aws_iid-attested node's child entry survives node deletion and no RegistrationEntryEvent is emitted. Existing cascade tests already use join_token nodes and continue to pass. Update doc/spire_server.md to reflect the narrowed scope. Refs spiffe#6944 Signed-off-by: angabini <494150+angabini@users.noreply.github.com> * fix(sqlstore): match alias selector shape on cascade Per Copilot review feedback on spiffe#6946 (B): even within join-token-attested nodes, child entries can be user-managed (e.g. an operator-created entry parented on the agent SVID for a workload that happens to share that parent). Cascading on parent_id alone would still over-delete those. Tighten deleteAttestedNodeAndSelectors to match the exact shape that createJoinTokenRegistrationEntry writes: - exactly one selector - selector.Type == "spiffe_id" - selector.Value == entry.ParentID Anything else stays put. Tests: - Add TestDeleteAttestedNodeJoinTokenPreservesNonAliasChildEntries (replaces the federation multi-test): asserts an alias-shaped child cascades while a unix-selector workload child parented on the same join_token-attested node survives, and exactly one entry event is emitted. - Sharpen TestDeleteAttestedNodeNonJoinTokenDoesNotCascade: switch the child entry to alias-shaped selectors so the test isolates the DataType filter from the selector-shape filter. - Extract lastRegistrationEntryEventID() helper used by all four cascade tests (Copilot review comment 4). Refs spiffe#6944 Signed-off-by: angabini <494150+angabini@users.noreply.github.com> * doc(spire_server): re-align config table to widest row The cascade note added in 61a42b9 widened the prune_attested_nodes_expired_for description to 581 chars while every other row in the table sat at 480, tripping markdownlint MD060/table-column-style. Pad the description column on every other row in the table to match, keeping pipe positions identical at columns 1, 38, 516, 581 across the entire config table. Pure padding change; no rendered content moved. Separator row padded with dashes (preserving continuous alignment marker), content rows with spaces. Signed-off-by: angabini <494150+angabini@users.noreply.github.com> * test(agent): cover join-token alias cascade end-to-end, cross-ref shape Incorporates review feedback on spiffe#6946. - Cross-reference the auto-alias entry shape between its writer (createJoinTokenRegistrationEntry) and the cascade matcher (deleteAttestedNodeAndSelectors) so the two can't drift silently. - Add TestCascadeDeleteJoinTokenAliasEntry exercising the real CreateJoinToken -> DeleteAgent path; fakedatastore is backed by the sqlstore, so a shape change that misses the matcher fails the test. - Document that manual `agent evict`/`agent purge` also cascade and that the cleanup is forward-only (pre-existing orphans are not swept). - Revert the unrelated config-table realignment to keep the doc diff minimal. Signed-off-by: angabini <494150+angabini@users.noreply.github.com> --------- Signed-off-by: angabini <494150+angabini@users.noreply.github.com>
spiffe#7006) * Add tag-based key discovery support in the `aws_kms` KeyManager plugin Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com> * Address Copilot comments Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com> * Address review comments Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com> --------- Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
…piffe#7073) * spire-agent: try to enable SE_DEBUG_PRIVILEGE at startup on windows The [OpenProcessToken](https://learn.microsoft.com/en-us/windows/win32/api/processthreadsapi/nf-processthreadsapi-openprocesstoken) API mentions that SE_DEBUG_NAME/SeDebugPrivilege (why two different names, windows???) privilege is required for opening the process token for a process running as a more privileged account (it does work from admin to admin users without this). Attempt to enable this and log an warning if that fails. Signed-off-by: Sorin Dumitru <sorin@returnze.ro> * Workaround broken AdjustTokenPrivileges Signed-off-by: Sorin Dumitru <sorin@returnze.ro> * Move function to global variable Signed-off-by: Sorin Dumitru <sorin@returnze.ro> --------- Signed-off-by: Sorin Dumitru <sorin@returnze.ro>
Signed-off-by: Ravishen Jain <ravisshen@gmail.com>
…ed server (spiffe#7108) * Fix flaky fetch-jwt-svids integration test by waiting for the restarted server Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com> * Address review comments Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com> --------- Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
…RIBUTING.md (spiffe#7105) Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
) Bumps the minor-and-patch group with 10 updates: | Package | From | To | | --- | --- | --- | | [github.com/aws/aws-sdk-go-v2/service/ec2](https://github.com/aws/aws-sdk-go-v2) | `1.307.0` | `1.308.0` | | [github.com/aws/aws-sdk-go-v2/service/eks](https://github.com/aws/aws-sdk-go-v2) | `1.86.0` | `1.87.0` | | [github.com/google/go-containerregistry](https://github.com/google/go-containerregistry) | `0.21.6` | `0.21.7` | | [github.com/hashicorp/go-metrics](https://github.com/hashicorp/go-metrics) | `0.5.4` | `0.6.0` | | [github.com/mattn/go-sqlite3](https://github.com/mattn/go-sqlite3) | `1.14.45` | `1.14.47` | | [github.com/moby/moby/api](https://github.com/moby/moby) | `1.54.2` | `1.55.0` | | [github.com/moby/moby/client](https://github.com/moby/moby) | `0.4.1` | `0.5.0` | | [github.com/shirou/gopsutil/v4](https://github.com/shirou/gopsutil) | `4.26.5` | `4.26.6` | | [github.com/spiffe/go-spiffe/v2](https://github.com/spiffe/go-spiffe) | `2.8.0` | `2.8.1` | | [google.golang.org/api](https://github.com/googleapis/google-api-go-client) | `0.285.0` | `0.286.0` | Updates `github.com/aws/aws-sdk-go-v2/service/ec2` from 1.307.0 to 1.308.0 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@service/ec2/v1.307.0...service/ec2/v1.308.0) Updates `github.com/aws/aws-sdk-go-v2/service/eks` from 1.86.0 to 1.87.0 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@service/s3/v1.86.0...service/s3/v1.87.0) Updates `github.com/google/go-containerregistry` from 0.21.6 to 0.21.7 - [Release notes](https://github.com/google/go-containerregistry/releases) - [Commits](google/go-containerregistry@v0.21.6...v0.21.7) Updates `github.com/hashicorp/go-metrics` from 0.5.4 to 0.6.0 - [Release notes](https://github.com/hashicorp/go-metrics/releases) - [Commits](hashicorp/go-metrics@v0.5.4...v0.6.0) Updates `github.com/mattn/go-sqlite3` from 1.14.45 to 1.14.47 - [Release notes](https://github.com/mattn/go-sqlite3/releases) - [Commits](mattn/go-sqlite3@v1.14.45...v1.14.47) Updates `github.com/moby/moby/api` from 1.54.2 to 1.55.0 - [Release notes](https://github.com/moby/moby/releases) - [Commits](moby/moby@api/v1.54.2...api/v1.55.0) Updates `github.com/moby/moby/client` from 0.4.1 to 0.5.0 - [Release notes](https://github.com/moby/moby/releases) - [Changelog](https://github.com/moby/moby/blob/v0.5.0/CHANGELOG.md) - [Commits](moby/moby@v0.4.1...v0.5.0) Updates `github.com/shirou/gopsutil/v4` from 4.26.5 to 4.26.6 - [Release notes](https://github.com/shirou/gopsutil/releases) - [Commits](shirou/gopsutil@v4.26.5...v4.26.6) Updates `github.com/spiffe/go-spiffe/v2` from 2.8.0 to 2.8.1 - [Release notes](https://github.com/spiffe/go-spiffe/releases) - [Changelog](https://github.com/spiffe/go-spiffe/blob/main/CHANGELOG.md) - [Commits](spiffe/go-spiffe@v2.8.0...v2.8.1) Updates `google.golang.org/api` from 0.285.0 to 0.286.0 - [Release notes](https://github.com/googleapis/google-api-go-client/releases) - [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md) - [Commits](googleapis/google-api-go-client@v0.285.0...v0.286.0) --- updated-dependencies: - dependency-name: github.com/aws/aws-sdk-go-v2/service/ec2 dependency-version: 1.308.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: github.com/aws/aws-sdk-go-v2/service/eks dependency-version: 1.87.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: github.com/google/go-containerregistry dependency-version: 0.21.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: github.com/hashicorp/go-metrics dependency-version: 0.6.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: github.com/mattn/go-sqlite3 dependency-version: 1.14.47 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: github.com/moby/moby/api dependency-version: 1.55.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: github.com/moby/moby/client dependency-version: 0.5.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: github.com/shirou/gopsutil/v4 dependency-version: 4.26.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: github.com/spiffe/go-spiffe/v2 dependency-version: 2.8.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: google.golang.org/api dependency-version: 0.286.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the minor-and-patch group with 2 updates: [actions/setup-python](https://github.com/actions/setup-python) and [actions/setup-go](https://github.com/actions/setup-go). Updates `actions/setup-python` from 6.2.0 to 6.3.0 - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](actions/setup-python@a309ff8...ece7cb0) Updates `actions/setup-go` from 6.4.0 to 6.5.0 - [Release notes](https://github.com/actions/setup-go/releases) - [Commits](actions/setup-go@4a36011...924ae3a) --- updated-dependencies: - dependency-name: actions/setup-python dependency-version: 6.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: actions/setup-go dependency-version: 6.5.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [actions/cache](https://github.com/actions/cache) from 5.0.5 to 6.1.0. - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@27d5ce7...55cc834) --- updated-dependencies: - dependency-name: actions/cache dependency-version: 6.1.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: Matheus Pimenta <matheuscscp@gmail.com>
…spiffe#7112) * Fix k8s workload attestor Broker API config docs and remove dead code Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com> * Address review comments Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com> * Align experimental config table to satisfy markdownlint MD060 Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com> --------- Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
…piffe#7110) Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
…piffe#6957) * Add disable_group_name_selectors option to Windows workload attestor Signed-off-by: Janani Arunachalam <jarunachala2@bloomberg.net> * Update what gets logged Signed-off-by: Janani Arunachalam <jarunachala2@bloomberg.net> * address PR comments Signed-off-by: Janani Arunachalam <jarunachala2@bloomberg.net> * fix log line casing Signed-off-by: Janani Arunachalam <jarunachala2@bloomberg.net> * md linting Signed-off-by: Janani Arunachalam <jarunachala2@bloomberg.net> * update log line as per pr comment Signed-off-by: Janani Arunachalam <jarunachala2@bloomberg.net> * update unit test log line to match Signed-off-by: Janani Arunachalam <jarunachala2@bloomberg.net> --------- Signed-off-by: Janani Arunachalam <jarunachala2@bloomberg.net> Co-authored-by: Janani Arunachalam <jarunachala2@bloomberg.net>
We have seen high CPU on mysql DB. Optimizing this frequent query should help. This brings the mysql 8 and above that supports WITH clause on par with postgresql. Essentially port spiffe#4111 to buildFetchRegistrationEntriesQueryMySQLCTE. Signed-off-by: ztrain <ztrain@uber.com>
…ad75ad67a788a380f75a20cc8a040 to 9a2d4216180dbb3e2dccfa60d2dd4afd98e42ec5 (spiffe#7103) build(deps): bump regclient/actions/regctl-installer Bumps [regclient/actions/regctl-installer](https://github.com/regclient/actions) from 4b4db1dcc7dad75ad67a788a380f75a20cc8a040 to 9a2d4216180dbb3e2dccfa60d2dd4afd98e42ec5. - [Release notes](https://github.com/regclient/actions/releases) - [Changelog](https://github.com/regclient/actions/blob/main/RELEASE.md) - [Commits](regclient/actions@4b4db1d...9a2d421) --- updated-dependencies: - dependency-name: regclient/actions/regctl-installer dependency-version: 9a2d4216180dbb3e2dccfa60d2dd4afd98e42ec5 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* Make attested-node prune batch size configurable Signed-off-by: Kevin Lui <kevin.lui@thetradedesk.com> * Address review: centralize batch size default, move BatchSize to ManagerConfig, document in server_full.conf Signed-off-by: Kevin Lui <kevin.lui@thetradedesk.com> --------- Signed-off-by: Kevin Lui <kevin.lui@thetradedesk.com> Co-authored-by: Kevin Lui <kevin.lui@thetradedesk.com>
…with internal observer package (spiffe#7064) * refactor: replace abandoned github.com/imkira/go-observer dependency with internal observer package Fixes spiffe#6893 Signed-off-by: Matt Van Horn <455140+mvanhorn@users.noreply.github.com> * fix: address self-review findings Signed-off-by: Matt Van Horn <455140+mvanhorn@users.noreply.github.com> --------- Signed-off-by: Matt Van Horn <455140+mvanhorn@users.noreply.github.com> Co-authored-by: Matt Van Horn <455140+mvanhorn@users.noreply.github.com> Co-authored-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
* Changelog 1.15.2 Signed-off-by: Marcos Yacob <marcosyacob@gmail.com> * PR changes Signed-off-by: Marcos Yacob <marcosyacob@gmail.com> --------- Signed-off-by: Marcos Yacob <marcosyacob@gmail.com>
Added: - Support for configuring JTI claim inclusion in JWT-SVIDs at entry level (spiffe#6514) - Experimental per-caller rate limiting for the agent Workload API and Envoy SDS (spiffe#6724) - TLS support for the Prometheus metrics endpoint using a SPIRE SVID, with an optional SPIFFE ID allowlist (spiffe#6812) - Optional verification of client certificate IPs in the `x509pop` node attestor (spiffe#6911) - SPIFFE Broker endpoint, API, and documentation (spiffe#6915, spiffe#7112) - `disable_group_name_selectors` option for the Windows workload attestor (spiffe#6957) - `log_selectors` configuration item for the agent (spiffe#6981) - Support for two additional PQC curves (spiffe#6999) - Tag-based key discovery support in the `aws_kms` Key Manager plugin (spiffe#7006) - Logger service for `spire-agent` (spiffe#7017) - Configurable batch size for pruning attested nodes (spiffe#7100) Security: - Migrated `github.com/docker/docker` dependencies to their `github.com/moby/moby` equivalents to resolve CVEs (spiffe#7078) Changed: - Deprecation warnings now use dedicated log markers, making them easier to detect in logs (spiffe#6908) - The OIDC Discovery Provider now warns when `allow_insecure_scheme` is enabled (spiffe#6970) - The post-quantum cryptography policy is now applied to the bundle endpoint and Prometheus server (spiffe#6995) - Attested nodes are now fetched in bulk, reducing database load in large deployments (spiffe#7022) - Agent health check loopback calls no longer emit RPC metrics, reducing metrics noise (spiffe#6929) - Pod and container IDs are now preferably determined from the cgroup file (spiffe#7060) - Optimized the MySQL list entries query to reduce database CPU usage under load (spiffe#7113) - Added AWS CA certificates for new regions to the `aws_iid` node attestor (spiffe#6879) - Documented `URISanSelectors` for the agent SPIFFE ID template (spiffe#6872) - Datastore configuration documentation updates (spiffe#7023) Fixed: - `azure_imds` node attestation for standalone VMs (spiffe#6807) - `azure_imds` plugin signature validation (spiffe#6960) - The auto-created join-token alias entry is now cascade-deleted when its attested node is deleted, evicted, or pruned (spiffe#6946) - The CA journal now survives transient datastore save failures, preserving CA continuity (spiffe#6964) - The delegated API no longer serves JWT-SVIDs for admin or downstream entries (spiffe#6972) - The event cache now keeps previous first/last event information when reloading (spiffe#6994) - The structured logger is now used for rebootstrap messages, and typos were fixed (spiffe#7000) - The `spire` upstream authority plugin now validates a missing Workload API endpoint (spiffe#7008) - The `gcp_kms` plugin no longer intermittently fails to retrieve a newly created public key (spiffe#6924) - Tolerate `mountinfo` lines with an empty mount source (spiffe#7044) - The agent now treats failure of all attestation plugins as an overall failure and returns `Unavailable` (spiffe#7045) - Fixed the `http_challenge` agent name validation regex (spiffe#7066) - Corrected TTL logging in the delegated identity X.509-SVID subscriber (spiffe#7071) - `spire-agent` now attempts to enable `SE_DEBUG_PRIVILEGE` at startup on Windows (spiffe#7073) - Data races in the built-in BundlePublisher plug
zzzz465
added a commit
that referenced
this pull request
Jul 16, 2026
PR #5 was squash-merged, so the 89 upstream commits landed as content but not as history: the fork still compares as 102 behind upstream and future upstream merges would lack a correct merge base. The tree is already (near) identical; this merge records the ancestry.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
bump t v1.15.2