Skip to content

chore: merge upstream v1.15.2#5

Merged
zzzz465 merged 90 commits into
mainfrom
feature/bump-upstream-v1.15.2
Jul 16, 2026
Merged

chore: merge upstream v1.15.2#5
zzzz465 merged 90 commits into
mainfrom
feature/bump-upstream-v1.15.2

Conversation

@zzzz465

@zzzz465 zzzz465 commented Jul 16, 2026

Copy link
Copy Markdown

bump t v1.15.2

dependabot Bot and others added 30 commits May 29, 2026 05:31
…7.0 (spiffe#6997)

Bumps [github.com/open-policy-agent/opa](https://github.com/open-policy-agent/opa) from 1.16.2 to 1.17.0.
- [Release notes](https://github.com/open-policy-agent/opa/releases)
- [Changelog](https://github.com/open-policy-agent/opa/blob/main/CHANGELOG.md)
- [Commits](open-policy-agent/opa@v1.16.2...v1.17.0)

---
updated-dependencies:
- dependency-name: github.com/open-policy-agent/opa
  dependency-version: 1.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: Sorin Dumitru <sorin@returnze.ro>
Bumps the aws-sdk group with 2 updates: [github.com/aws/aws-sdk-go-v2/service/s3](https://github.com/aws/aws-sdk-go-v2) and [github.com/aws/smithy-go](https://github.com/aws/smithy-go).


Updates `github.com/aws/aws-sdk-go-v2/service/s3` from 1.101.0 to 1.102.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@service/s3/v1.101.0...service/s3/v1.102.0)

Updates `github.com/aws/smithy-go` from 1.25.1 to 1.26.0
- [Release notes](https://github.com/aws/smithy-go/releases)
- [Changelog](https://github.com/aws/smithy-go/blob/main/CHANGELOG.md)
- [Commits](aws/smithy-go@v1.25.1...v1.26.0)

---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/service/s3
  dependency-version: 1.102.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws-sdk
- dependency-name: github.com/aws/smithy-go
  dependency-version: 1.26.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws-sdk
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
…piffe#7005)

Bumps [github.com/sigstore/sigstore](https://github.com/sigstore/sigstore) from 1.10.6 to 1.10.7.
- [Release notes](https://github.com/sigstore/sigstore/releases)
- [Commits](sigstore/sigstore@v1.10.6...v1.10.7)

---
updated-dependencies:
- dependency-name: github.com/sigstore/sigstore
  dependency-version: 1.10.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the google-cloud-sdk group with 1 update: [cloud.google.com/go/security](https://github.com/googleapis/google-cloud-go).


Updates `cloud.google.com/go/security` from 1.24.0 to 1.25.0
- [Release notes](https://github.com/googleapis/google-cloud-go/releases)
- [Changelog](https://github.com/googleapis/google-cloud-go/blob/main/documentai/CHANGES.md)
- [Commits](googleapis/google-cloud-go@kms/v1.24.0...kms/v1.25.0)

---
updated-dependencies:
- dependency-name: cloud.google.com/go/security
  dependency-version: 1.25.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: google-cloud-sdk
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…piffe#7003)

Bumps the aws-sdk group with 1 update: [github.com/aws/aws-sdk-go-v2/service/autoscaling](https://github.com/aws/aws-sdk-go-v2).


Updates `github.com/aws/aws-sdk-go-v2/service/autoscaling` from 1.66.0 to 1.67.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@service/s3/v1.66.0...service/s3/v1.67.0)

---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/service/autoscaling
  dependency-version: 1.67.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws-sdk
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* Add Copilot repository custom instructions

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>

* Address Copilot comments

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>

* Add links to the SDK repositories

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>

* Note that field names come from pkg/common/telemetry/names.go

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>

---------

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
Go 1.26 added support for these so we can allow using them

Signed-off-by: Sorin Dumitru <sorin@returnze.ro>
…spiffe#7014)

Bumps the google-cloud-sdk group with 1 update: [google.golang.org/api](https://github.com/googleapis/google-api-go-client).


Updates `google.golang.org/api` from 0.282.0 to 0.283.0
- [Release notes](https://github.com/googleapis/google-api-go-client/releases)
- [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md)
- [Commits](googleapis/google-api-go-client@v0.282.0...v0.283.0)

---
updated-dependencies:
- dependency-name: google.golang.org/api
  dependency-version: 0.283.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: google-cloud-sdk
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…piffe#7016)

Bumps [github.com/sigstore/sigstore](https://github.com/sigstore/sigstore) from 1.10.7 to 1.10.8.
- [Release notes](https://github.com/sigstore/sigstore/releases)
- [Commits](sigstore/sigstore@v1.10.7...v1.10.8)

---
updated-dependencies:
- dependency-name: github.com/sigstore/sigstore
  dependency-version: 1.10.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* agent: log configured workload selectors on identity failures

Signed-off-by: Carlo Teubner <cteubner1@bloomberg.net>

* agent: minor refactor to reduce num params

Signed-off-by: Carlo Teubner <cteubner1@bloomberg.net>

* agent: log selectors as single string

Addresses review comment.

Signed-off-by: Carlo Teubner <cteubner1@bloomberg.net>

* agent: Sort selectors before logging

Signed-off-by: Carlo Teubner <cteubner1@bloomberg.net>

---------

Signed-off-by: Carlo Teubner <cteubner1@bloomberg.net>
…spiffe#7015)

Bumps [github.com/shirou/gopsutil/v4](https://github.com/shirou/gopsutil) from 4.26.4 to 4.26.5.
- [Release notes](https://github.com/shirou/gopsutil/releases)
- [Commits](shirou/gopsutil@v4.26.4...v4.26.5)

---
updated-dependencies:
- dependency-name: github.com/shirou/gopsutil/v4
  dependency-version: 4.26.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the aws-sdk group with 7 updates:

| Package | From | To |
| --- | --- | --- |
| [github.com/aws/aws-sdk-go-v2/service/ec2](https://github.com/aws/aws-sdk-go-v2) | `1.304.0` | `1.305.0` |
| [github.com/aws/aws-sdk-go-v2/service/iam](https://github.com/aws/aws-sdk-go-v2) | `1.53.1` | `1.54.1` |
| [github.com/aws/aws-sdk-go-v2/service/kms](https://github.com/aws/aws-sdk-go-v2) | `1.52.0` | `1.53.1` |
| [github.com/aws/aws-sdk-go-v2/service/s3](https://github.com/aws/aws-sdk-go-v2) | `1.102.0` | `1.103.0` |
| [github.com/aws/aws-sdk-go-v2/service/secretsmanager](https://github.com/aws/aws-sdk-go-v2) | `1.41.0` | `1.42.0` |
| [github.com/aws/aws-sdk-go-v2/service/sts](https://github.com/aws/aws-sdk-go-v2) | `1.42.0` | `1.43.0` |
| [github.com/aws/smithy-go](https://github.com/aws/smithy-go) | `1.26.0` | `1.27.0` |


Updates `github.com/aws/aws-sdk-go-v2/service/ec2` from 1.304.0 to 1.305.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@service/ec2/v1.304.0...service/ec2/v1.305.0)

Updates `github.com/aws/aws-sdk-go-v2/service/iam` from 1.53.1 to 1.54.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@service/s3/v1.53.1...service/s3/v1.54.1)

Updates `github.com/aws/aws-sdk-go-v2/service/kms` from 1.52.0 to 1.53.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@service/s3/v1.52.0...service/s3/v1.53.1)

Updates `github.com/aws/aws-sdk-go-v2/service/s3` from 1.102.0 to 1.103.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@service/s3/v1.102.0...service/s3/v1.103.0)

Updates `github.com/aws/aws-sdk-go-v2/service/secretsmanager` from 1.41.0 to 1.42.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@v1.41.0...service/s3/v1.42.0)

Updates `github.com/aws/aws-sdk-go-v2/service/sts` from 1.42.0 to 1.43.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@service/s3/v1.42.0...service/s3/v1.43.0)

Updates `github.com/aws/smithy-go` from 1.26.0 to 1.27.0
- [Release notes](https://github.com/aws/smithy-go/releases)
- [Changelog](https://github.com/aws/smithy-go/blob/main/CHANGELOG.md)
- [Commits](aws/smithy-go@v1.26.0...v1.27.0)

---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/service/ec2
  dependency-version: 1.305.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws-sdk
- dependency-name: github.com/aws/aws-sdk-go-v2/service/iam
  dependency-version: 1.54.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws-sdk
- dependency-name: github.com/aws/aws-sdk-go-v2/service/kms
  dependency-version: 1.53.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws-sdk
- dependency-name: github.com/aws/aws-sdk-go-v2/service/s3
  dependency-version: 1.103.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws-sdk
- dependency-name: github.com/aws/aws-sdk-go-v2/service/secretsmanager
  dependency-version: 1.42.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws-sdk
- dependency-name: github.com/aws/aws-sdk-go-v2/service/sts
  dependency-version: 1.43.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws-sdk
- dependency-name: github.com/aws/smithy-go
  dependency-version: 1.27.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aws-sdk
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 6.0.3.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@de0fac2...df4cb1c)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 6.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…e#7026)

Bumps [github.com/jackc/pgx/v5](https://github.com/jackc/pgx) from 5.9.2 to 5.10.0.
- [Changelog](https://github.com/jackc/pgx/blob/master/CHANGELOG.md)
- [Commits](jackc/pgx@v5.9.2...v5.10.0)

---
updated-dependencies:
- dependency-name: github.com/jackc/pgx/v5
  dependency-version: 5.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…iffe#7032)

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
…he aws-sdk group (spiffe#7033)

build(deps): bump github.com/aws/smithy-go in the aws-sdk group

Bumps the aws-sdk group with 1 update: [github.com/aws/smithy-go](https://github.com/aws/smithy-go).


Updates `github.com/aws/smithy-go` from 1.27.0 to 1.27.1
- [Release notes](https://github.com/aws/smithy-go/releases)
- [Changelog](https://github.com/aws/smithy-go/blob/main/CHANGELOG.md)
- [Commits](aws/smithy-go@v1.27.0...v1.27.1)

---
updated-dependencies:
- dependency-name: github.com/aws/smithy-go
  dependency-version: 1.27.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: aws-sdk
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* server sql doc: explain connection string

Signed-off-by: Carlo Teubner <cteubner1@bloomberg.net>

* server sql doc: spelling of AWS_SECRET_ACCESS_KEY

Signed-off-by: Carlo Teubner <cteubner1@bloomberg.net>

* server sql doc: misc cleanups

Signed-off-by: Carlo Teubner <cteubner1@bloomberg.net>

---------

Signed-off-by: Carlo Teubner <cteubner1@bloomberg.net>
…ss (spiffe#7031)

* Retry container image pulls in integration tests to reduce CI flakiness

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>

* Hardcode retry attempts and backoff in integration tests

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>

---------

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
* Upgrade go-spiffe to 2.7.0

Signed-off-by: Sorin Dumitru <sorin@returnze.ro>

* Add dumy implementations for WIT-SVID API

Signed-off-by: Sorin Dumitru <sorin@returnze.ro>

---------

Signed-off-by: Sorin Dumitru <sorin@returnze.ro>
…n test (spiffe#7037)

* Remove stale kindest/node pin from the cert-manager integration test

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>

* Remove the now-unused cert-manager kind config

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>

---------

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
…piffe#7012)

* Add round-robin reviewer auto-assignment with ball-in-court tracking

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>

* Address Copilot comments

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>

* Address Copilot comments

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>

* Exclude bot-authored PRs from reviewer rotation

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>

* Pick the PR assignee at random instead of by PR number

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>

---------

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
Scope assign-reviewer concurrency per event action

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
…spiffe#7041)

Bumps [github.com/mattn/go-sqlite3](https://github.com/mattn/go-sqlite3) from 1.14.44 to 1.14.45.
- [Release notes](https://github.com/mattn/go-sqlite3/releases)
- [Commits](mattn/go-sqlite3@v1.14.44...v1.14.45)

---
updated-dependencies:
- dependency-name: github.com/mattn/go-sqlite3
  dependency-version: 1.14.45
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…piffe#7040)

Bumps [github.com/google/go-tpm-tools](https://github.com/google/go-tpm-tools) from 0.4.8 to 0.4.9.
- [Release notes](https://github.com/google/go-tpm-tools/releases)
- [Commits](google/go-tpm-tools@v0.4.8...v0.4.9)

---
updated-dependencies:
- dependency-name: github.com/google/go-tpm-tools
  dependency-version: 0.4.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
….21.1 to 1.22.0 in the azure-sdk group (spiffe#7039)

build(deps): bump github.com/Azure/azure-sdk-for-go/sdk/azcore

Bumps the azure-sdk group with 1 update: [github.com/Azure/azure-sdk-for-go/sdk/azcore](https://github.com/Azure/azure-sdk-for-go).


Updates `github.com/Azure/azure-sdk-for-go/sdk/azcore` from 1.21.1 to 1.22.0
- [Release notes](https://github.com/Azure/azure-sdk-for-go/releases)
- [Commits](Azure/azure-sdk-for-go@sdk/azcore/v1.21.1...sdk/azcore/v1.22.0)

---
updated-dependencies:
- dependency-name: github.com/Azure/azure-sdk-for-go/sdk/azcore
  dependency-version: 1.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: azure-sdk
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: Keegan Witt <keeganwitt@gmail.com>
…#6812)

* Add SPIRE-backed Prometheus TLS identity and SPIFFE allowlist

(cherry picked from commit 2ec839e)
Signed-off-by: aviralgarg05 <gargaviral99@gmail.com>

* Fix markdown table formatting to pass lint

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>

---------

Signed-off-by: aviralgarg05 <gargaviral99@gmail.com>
Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
Co-authored-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
dependabot Bot and others added 27 commits June 28, 2026 15:04
…f4b9e2490560 to 4b4db1dcc7dad75ad67a788a380f75a20cc8a040 (spiffe#7090)

build(deps): bump regclient/actions

Bumps [regclient/actions](https://github.com/regclient/actions) from 14f9d37db17b5dc41fefd1ffdd1af4b9e2490560 to 4b4db1dcc7dad75ad67a788a380f75a20cc8a040.
- [Release notes](https://github.com/regclient/actions/releases)
- [Changelog](https://github.com/regclient/actions/blob/main/RELEASE.md)
- [Commits](regclient/actions@14f9d37...4b4db1d)

---
updated-dependencies:
- dependency-name: regclient/actions
  dependency-version: 4b4db1dcc7dad75ad67a788a380f75a20cc8a040
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.3 to 7.0.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@df4cb1c...9c091bb)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…r-and-patch group (spiffe#7088)

build(deps): bump msys2/setup-msys2 in the minor-and-patch group

Bumps the minor-and-patch group with 1 update: [msys2/setup-msys2](https://github.com/msys2/setup-msys2).


Updates `msys2/setup-msys2` from 2.31.1 to 2.32.0
- [Release notes](https://github.com/msys2/setup-msys2/releases)
- [Changelog](https://github.com/msys2/setup-msys2/blob/main/CHANGELOG.md)
- [Commits](msys2/setup-msys2@e989830...66cd2cc)

---
updated-dependencies:
- dependency-name: msys2/setup-msys2
  dependency-version: 2.32.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…piffe#7071)

fix: correct TTL logging in delegated identity subscriber when admin/downstream identities are present

Signed-off-by: immanuwell <pchpr.00@list.ru>
spiffe#7095)

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
* spire-agent: implement logger service

Signed-off-by: Sorin Dumitru <sorin@returnze.ro>

* Copilot review comments

Signed-off-by: Sorin Dumitru <sorin@returnze.ro>

* review comments

Signed-off-by: Sorin Dumitru <sorin@returnze.ro>

* review comments

Signed-off-by: Sorin Dumitru <sorin@returnze.ro>

* Remove auditing

there's no auditing support in the agent

Signed-off-by: Sorin Dumitru <sorin@returnze.ro>

* Use agent rpccontext

Signed-off-by: Sorin Dumitru <sorin@returnze.ro>

* Move status helpers to common/api

Signed-off-by: Sorin Dumitru <sorin@returnze.ro>

* Use status helpers from common/api

Signed-off-by: Sorin Dumitru <sorin@returnze.ro>

* Make sure logger metrics are emitted

Signed-off-by: Sorin Dumitru <sorin@returnze.ro>

* fix linter errors

Signed-off-by: Sorin Dumitru <sorin@returnze.ro>

* Review comments

Signed-off-by: Sorin Dumitru <sorin@returnze.ro>

* Add RPC metric name test

Signed-off-by: Sorin Dumitru <sorin@returnze.ro>

---------

Signed-off-by: Sorin Dumitru <sorin@returnze.ro>
…ffe#6946)

* fix: cascade-delete registered_entries on attested node deletion

Previously, deleteAttestedNodeAndSelectors deleted AttestedNode and
NodeSelector rows but left registered_entries with parent_id matching
the deleted node's SPIFFE ID untouched. In particular, the alias row
that SPIRE auto-creates in createJoinTokenRegistrationEntry (when
CreateJoinToken is called with AgentId) would survive the node it was
minted for, accumulating as dead rows that still flow through the
server's entry cache and the events-based cache.

This extends deleteAttestedNodeAndSelectors to cascade: find entries
whose parent_id equals the deleted node's SPIFFE ID, delete each via
the existing deleteRegistrationEntrySupport helper, emit a
RegistrationEntryEvent per deletion so event-cache consumers see
them, and log each cascaded delete at Info with the usual
SPIFFEID/ParentID/RegistrationID telemetry fields (matching the
pruneRegistrationEntries pattern). The cascade fires for both
DeleteAttestedNode (admin delete) and PruneAttestedExpiredNodes
(periodic prune) since both paths reach this helper. Callers pass
their existing logger (ds.log for DeleteAttestedNode, the prune
logger for PruneAttestedExpiredNodes).

Mirrors the shape of spiffe#3873 which added the node_resolver_map_entries
cascade at the same function.

Fixes spiffe#6944

Signed-off-by: angabini <494150+angabini@users.noreply.github.com>

* doc: update spire_server.md

Signed-off-by: angabini <494150+angabini@users.noreply.github.com>

* doc: cleanup spire_server.md

Signed-off-by: angabini <494150+angabini@users.noreply.github.com>

* fix(sqlstore): narrow cascade to join-token-attested nodes

Per review feedback on spiffe#6946: cascading every entry parented on a
deleted attested node would also wipe legitimately user-registered
workload entries that happen to be parented directly on a non-join-
token agent SVID (e.g. spiffe://td/spire/agent/aws_iid/...). That
is a supported registration pattern, not an orphan.

Restrict the cascade in deleteAttestedNodeAndSelectors to nodes
whose attested DataType is "join_token". The auto-alias that
createJoinTokenRegistrationEntry writes is the only entry SPIRE
itself creates with parent_id = node SVID, so this still cleans up
the unbounded-growth case reported in spiffe#6944 without changing
behavior for any other attestor. A broader explicit cascade can be
added later behind a CLI flag, as suggested in the issue.

Add TestDeleteAttestedNodeNonJoinTokenDoesNotCascade asserting an
aws_iid-attested node's child entry survives node deletion and no
RegistrationEntryEvent is emitted. Existing cascade tests already
use join_token nodes and continue to pass.

Update doc/spire_server.md to reflect the narrowed scope.

Refs spiffe#6944

Signed-off-by: angabini <494150+angabini@users.noreply.github.com>

* fix(sqlstore): match alias selector shape on cascade

Per Copilot review feedback on spiffe#6946 (B): even within join-token-attested
nodes, child entries can be user-managed (e.g. an operator-created entry
parented on the agent SVID for a workload that happens to share that
parent). Cascading on parent_id alone would still over-delete those.

Tighten deleteAttestedNodeAndSelectors to match the exact shape that
createJoinTokenRegistrationEntry writes:
  - exactly one selector
  - selector.Type == "spiffe_id"
  - selector.Value == entry.ParentID

Anything else stays put.

Tests:
  - Add TestDeleteAttestedNodeJoinTokenPreservesNonAliasChildEntries
    (replaces the federation multi-test): asserts an alias-shaped child
    cascades while a unix-selector workload child parented on the same
    join_token-attested node survives, and exactly one entry event is
    emitted.
  - Sharpen TestDeleteAttestedNodeNonJoinTokenDoesNotCascade: switch
    the child entry to alias-shaped selectors so the test isolates the
    DataType filter from the selector-shape filter.
  - Extract lastRegistrationEntryEventID() helper used by all four
    cascade tests (Copilot review comment 4).

Refs spiffe#6944

Signed-off-by: angabini <494150+angabini@users.noreply.github.com>

* doc(spire_server): re-align config table to widest row

The cascade note added in 61a42b9 widened the prune_attested_nodes_expired_for
description to 581 chars while every other row in the table sat at 480, tripping
markdownlint MD060/table-column-style. Pad the description column on every other
row in the table to match, keeping pipe positions identical at columns 1, 38,
516, 581 across the entire config table.

Pure padding change; no rendered content moved. Separator row padded with
dashes (preserving continuous alignment marker), content rows with spaces.

Signed-off-by: angabini <494150+angabini@users.noreply.github.com>

* test(agent): cover join-token alias cascade end-to-end, cross-ref shape

Incorporates review feedback on spiffe#6946.

- Cross-reference the auto-alias entry shape between its writer
  (createJoinTokenRegistrationEntry) and the cascade matcher
  (deleteAttestedNodeAndSelectors) so the two can't drift silently.
- Add TestCascadeDeleteJoinTokenAliasEntry exercising the real
  CreateJoinToken -> DeleteAgent path; fakedatastore is backed by the
  sqlstore, so a shape change that misses the matcher fails the test.
- Document that manual `agent evict`/`agent purge` also cascade and that
  the cleanup is forward-only (pre-existing orphans are not swept).
- Revert the unrelated config-table realignment to keep the doc diff minimal.

Signed-off-by: angabini <494150+angabini@users.noreply.github.com>

---------

Signed-off-by: angabini <494150+angabini@users.noreply.github.com>
spiffe#7006)

* Add tag-based key discovery support in the `aws_kms` KeyManager plugin

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>

* Address Copilot comments

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>

* Address review comments

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>

---------

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
…piffe#7073)

* spire-agent: try to enable SE_DEBUG_PRIVILEGE at startup on windows

The [OpenProcessToken](https://learn.microsoft.com/en-us/windows/win32/api/processthreadsapi/nf-processthreadsapi-openprocesstoken) API mentions that
SE_DEBUG_NAME/SeDebugPrivilege (why two different names, windows???) privilege is required for opening the process token for a process running as a more
privileged account (it does work from admin to admin users without this).

Attempt to enable this and log an warning if that fails.

Signed-off-by: Sorin Dumitru <sorin@returnze.ro>

* Workaround broken AdjustTokenPrivileges

Signed-off-by: Sorin Dumitru <sorin@returnze.ro>

* Move function to global variable

Signed-off-by: Sorin Dumitru <sorin@returnze.ro>

---------

Signed-off-by: Sorin Dumitru <sorin@returnze.ro>
Signed-off-by: Ravishen Jain <ravisshen@gmail.com>
…ed server (spiffe#7108)

* Fix flaky fetch-jwt-svids integration test by waiting for the restarted server

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>

* Address review comments

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>

---------

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
…RIBUTING.md (spiffe#7105)

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
)

Bumps the minor-and-patch group with 10 updates:

| Package | From | To |
| --- | --- | --- |
| [github.com/aws/aws-sdk-go-v2/service/ec2](https://github.com/aws/aws-sdk-go-v2) | `1.307.0` | `1.308.0` |
| [github.com/aws/aws-sdk-go-v2/service/eks](https://github.com/aws/aws-sdk-go-v2) | `1.86.0` | `1.87.0` |
| [github.com/google/go-containerregistry](https://github.com/google/go-containerregistry) | `0.21.6` | `0.21.7` |
| [github.com/hashicorp/go-metrics](https://github.com/hashicorp/go-metrics) | `0.5.4` | `0.6.0` |
| [github.com/mattn/go-sqlite3](https://github.com/mattn/go-sqlite3) | `1.14.45` | `1.14.47` |
| [github.com/moby/moby/api](https://github.com/moby/moby) | `1.54.2` | `1.55.0` |
| [github.com/moby/moby/client](https://github.com/moby/moby) | `0.4.1` | `0.5.0` |
| [github.com/shirou/gopsutil/v4](https://github.com/shirou/gopsutil) | `4.26.5` | `4.26.6` |
| [github.com/spiffe/go-spiffe/v2](https://github.com/spiffe/go-spiffe) | `2.8.0` | `2.8.1` |
| [google.golang.org/api](https://github.com/googleapis/google-api-go-client) | `0.285.0` | `0.286.0` |


Updates `github.com/aws/aws-sdk-go-v2/service/ec2` from 1.307.0 to 1.308.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@service/ec2/v1.307.0...service/ec2/v1.308.0)

Updates `github.com/aws/aws-sdk-go-v2/service/eks` from 1.86.0 to 1.87.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@service/s3/v1.86.0...service/s3/v1.87.0)

Updates `github.com/google/go-containerregistry` from 0.21.6 to 0.21.7
- [Release notes](https://github.com/google/go-containerregistry/releases)
- [Commits](google/go-containerregistry@v0.21.6...v0.21.7)

Updates `github.com/hashicorp/go-metrics` from 0.5.4 to 0.6.0
- [Release notes](https://github.com/hashicorp/go-metrics/releases)
- [Commits](hashicorp/go-metrics@v0.5.4...v0.6.0)

Updates `github.com/mattn/go-sqlite3` from 1.14.45 to 1.14.47
- [Release notes](https://github.com/mattn/go-sqlite3/releases)
- [Commits](mattn/go-sqlite3@v1.14.45...v1.14.47)

Updates `github.com/moby/moby/api` from 1.54.2 to 1.55.0
- [Release notes](https://github.com/moby/moby/releases)
- [Commits](moby/moby@api/v1.54.2...api/v1.55.0)

Updates `github.com/moby/moby/client` from 0.4.1 to 0.5.0
- [Release notes](https://github.com/moby/moby/releases)
- [Changelog](https://github.com/moby/moby/blob/v0.5.0/CHANGELOG.md)
- [Commits](moby/moby@v0.4.1...v0.5.0)

Updates `github.com/shirou/gopsutil/v4` from 4.26.5 to 4.26.6
- [Release notes](https://github.com/shirou/gopsutil/releases)
- [Commits](shirou/gopsutil@v4.26.5...v4.26.6)

Updates `github.com/spiffe/go-spiffe/v2` from 2.8.0 to 2.8.1
- [Release notes](https://github.com/spiffe/go-spiffe/releases)
- [Changelog](https://github.com/spiffe/go-spiffe/blob/main/CHANGELOG.md)
- [Commits](spiffe/go-spiffe@v2.8.0...v2.8.1)

Updates `google.golang.org/api` from 0.285.0 to 0.286.0
- [Release notes](https://github.com/googleapis/google-api-go-client/releases)
- [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md)
- [Commits](googleapis/google-api-go-client@v0.285.0...v0.286.0)

---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/service/ec2
  dependency-version: 1.308.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: github.com/aws/aws-sdk-go-v2/service/eks
  dependency-version: 1.87.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: github.com/google/go-containerregistry
  dependency-version: 0.21.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: github.com/hashicorp/go-metrics
  dependency-version: 0.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: github.com/mattn/go-sqlite3
  dependency-version: 1.14.47
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: github.com/moby/moby/api
  dependency-version: 1.55.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: github.com/moby/moby/client
  dependency-version: 0.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: github.com/shirou/gopsutil/v4
  dependency-version: 4.26.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: github.com/spiffe/go-spiffe/v2
  dependency-version: 2.8.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: google.golang.org/api
  dependency-version: 0.286.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the minor-and-patch group with 2 updates: [actions/setup-python](https://github.com/actions/setup-python) and [actions/setup-go](https://github.com/actions/setup-go).


Updates `actions/setup-python` from 6.2.0 to 6.3.0
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](actions/setup-python@a309ff8...ece7cb0)

Updates `actions/setup-go` from 6.4.0 to 6.5.0
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](actions/setup-go@4a36011...924ae3a)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: 6.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: actions/setup-go
  dependency-version: 6.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [actions/cache](https://github.com/actions/cache) from 5.0.5 to 6.1.0.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@27d5ce7...55cc834)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-version: 6.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: Matheus Pimenta <matheuscscp@gmail.com>
…spiffe#7112)

* Fix k8s workload attestor Broker API config docs and remove dead code

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>

* Address review comments

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>

* Align experimental config table to satisfy markdownlint MD060

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>

---------

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
…piffe#7110)

Signed-off-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
…piffe#6957)

* Add disable_group_name_selectors option to Windows workload attestor

Signed-off-by: Janani Arunachalam <jarunachala2@bloomberg.net>

* Update what gets logged

Signed-off-by: Janani Arunachalam <jarunachala2@bloomberg.net>

* address PR comments

Signed-off-by: Janani Arunachalam <jarunachala2@bloomberg.net>

* fix log line casing

Signed-off-by: Janani Arunachalam <jarunachala2@bloomberg.net>

* md linting

Signed-off-by: Janani Arunachalam <jarunachala2@bloomberg.net>

* update log line as per pr comment

Signed-off-by: Janani Arunachalam <jarunachala2@bloomberg.net>

* update unit test log line to match

Signed-off-by: Janani Arunachalam <jarunachala2@bloomberg.net>

---------

Signed-off-by: Janani Arunachalam <jarunachala2@bloomberg.net>
Co-authored-by: Janani Arunachalam <jarunachala2@bloomberg.net>
We have seen high CPU on mysql DB. Optimizing this frequent query should
help. This brings the mysql 8 and above that supports WITH clause on par
with postgresql. Essentially port
spiffe#4111 to
buildFetchRegistrationEntriesQueryMySQLCTE.

Signed-off-by: ztrain <ztrain@uber.com>
…ad75ad67a788a380f75a20cc8a040 to 9a2d4216180dbb3e2dccfa60d2dd4afd98e42ec5 (spiffe#7103)

build(deps): bump regclient/actions/regctl-installer

Bumps [regclient/actions/regctl-installer](https://github.com/regclient/actions) from 4b4db1dcc7dad75ad67a788a380f75a20cc8a040 to 9a2d4216180dbb3e2dccfa60d2dd4afd98e42ec5.
- [Release notes](https://github.com/regclient/actions/releases)
- [Changelog](https://github.com/regclient/actions/blob/main/RELEASE.md)
- [Commits](regclient/actions@4b4db1d...9a2d421)

---
updated-dependencies:
- dependency-name: regclient/actions/regctl-installer
  dependency-version: 9a2d4216180dbb3e2dccfa60d2dd4afd98e42ec5
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* Make attested-node prune batch size configurable

Signed-off-by: Kevin Lui <kevin.lui@thetradedesk.com>

* Address review: centralize batch size default, move BatchSize to ManagerConfig, document in server_full.conf

Signed-off-by: Kevin Lui <kevin.lui@thetradedesk.com>

---------

Signed-off-by: Kevin Lui <kevin.lui@thetradedesk.com>
Co-authored-by: Kevin Lui <kevin.lui@thetradedesk.com>
…with internal observer package (spiffe#7064)

* refactor: replace abandoned github.com/imkira/go-observer dependency with internal observer package

Fixes spiffe#6893

Signed-off-by: Matt Van Horn <455140+mvanhorn@users.noreply.github.com>

* fix: address self-review findings

Signed-off-by: Matt Van Horn <455140+mvanhorn@users.noreply.github.com>

---------

Signed-off-by: Matt Van Horn <455140+mvanhorn@users.noreply.github.com>
Co-authored-by: Matt Van Horn <455140+mvanhorn@users.noreply.github.com>
Co-authored-by: Agustín Martínez Fayó <amartinezfayo@gmail.com>
* Changelog 1.15.2

Signed-off-by: Marcos Yacob <marcosyacob@gmail.com>

* PR changes

Signed-off-by: Marcos Yacob <marcosyacob@gmail.com>

---------

Signed-off-by: Marcos Yacob <marcosyacob@gmail.com>
Added:

- Support for configuring JTI claim inclusion in JWT-SVIDs at entry level (spiffe#6514)
- Experimental per-caller rate limiting for the agent Workload API and Envoy SDS (spiffe#6724)
- TLS support for the Prometheus metrics endpoint using a SPIRE SVID, with an optional SPIFFE ID allowlist (spiffe#6812)
- Optional verification of client certificate IPs in the `x509pop` node attestor (spiffe#6911)
- SPIFFE Broker endpoint, API, and documentation (spiffe#6915, spiffe#7112)
- `disable_group_name_selectors` option for the Windows workload attestor (spiffe#6957)
- `log_selectors` configuration item for the agent (spiffe#6981)
- Support for two additional PQC curves (spiffe#6999)
- Tag-based key discovery support in the `aws_kms` Key Manager plugin (spiffe#7006)
- Logger service for `spire-agent` (spiffe#7017)
- Configurable batch size for pruning attested nodes (spiffe#7100)

Security:

- Migrated `github.com/docker/docker` dependencies to their `github.com/moby/moby` equivalents to resolve CVEs (spiffe#7078)

Changed:

- Deprecation warnings now use dedicated log markers, making them easier to detect in logs (spiffe#6908)
- The OIDC Discovery Provider now warns when `allow_insecure_scheme` is enabled (spiffe#6970)
- The post-quantum cryptography policy is now applied to the bundle endpoint and Prometheus server (spiffe#6995)
- Attested nodes are now fetched in bulk, reducing database load in large deployments (spiffe#7022)
- Agent health check loopback calls no longer emit RPC metrics, reducing metrics noise (spiffe#6929)
- Pod and container IDs are now preferably determined from the cgroup file (spiffe#7060)
- Optimized the MySQL list entries query to reduce database CPU usage under load (spiffe#7113)
- Added AWS CA certificates for new regions to the `aws_iid` node attestor (spiffe#6879)
- Documented `URISanSelectors` for the agent SPIFFE ID template (spiffe#6872)
- Datastore configuration documentation updates (spiffe#7023)

Fixed:

- `azure_imds` node attestation for standalone VMs (spiffe#6807)
- `azure_imds` plugin signature validation (spiffe#6960)
- The auto-created join-token alias entry is now cascade-deleted when its attested node is deleted, evicted, or pruned (spiffe#6946)
- The CA journal now survives transient datastore save failures, preserving CA continuity (spiffe#6964)
- The delegated API no longer serves JWT-SVIDs for admin or downstream entries (spiffe#6972)
- The event cache now keeps previous first/last event information when reloading (spiffe#6994)
- The structured logger is now used for rebootstrap messages, and typos were fixed (spiffe#7000)
- The `spire` upstream authority plugin now validates a missing Workload API endpoint (spiffe#7008)
- The `gcp_kms` plugin no longer intermittently fails to retrieve a newly created public key (spiffe#6924)
- Tolerate `mountinfo` lines with an empty mount source (spiffe#7044)
- The agent now treats failure of all attestation plugins as an overall failure and returns `Unavailable` (spiffe#7045)
- Fixed the `http_challenge` agent name validation regex (spiffe#7066)
- Corrected TTL logging in the delegated identity X.509-SVID subscriber (spiffe#7071)
- `spire-agent` now attempts to enable `SE_DEBUG_PRIVILEGE` at startup on Windows (spiffe#7073)
- Data races in the built-in BundlePublisher plug
@zzzz465 zzzz465 changed the title chore: merge upstream v1.15.2 (official release) chore: merge upstream v1.15.2 Jul 16, 2026
@zzzz465
zzzz465 merged commit 94c023b into main Jul 16, 2026
13 of 14 checks passed
zzzz465 added a commit that referenced this pull request Jul 16, 2026
PR #5 was squash-merged, so the 89 upstream commits landed as content
but not as history: the fork still compares as 102 behind upstream and
future upstream merges would lack a correct merge base. The tree is
already (near) identical; this merge records the ancestry.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.