From 383b2061406f6d601620796dcca4f8d6c5f2922f Mon Sep 17 00:00:00 2001 From: Richard Wall Date: Fri, 9 Oct 2026 09:05:07 +0000 Subject: [PATCH] Send the VenafiConnection's NGTS workspace ID on the token request - Bump venafi-connection-lib to pick up spec.ngts.workspaceID. The library sends it as the workspace_id query parameter on the NGTS token request. - Regenerate the VenafiConnection CRD in both charts. Without the new field in the CRD, the API server drops spec.ngts.workspaceID. - The library bump also raises k8s.io/* to v0.37.0 and controller-runtime to v0.25.0, which venafi-connection-lib requires. NGTS now only finds an OIDC (workload identity) service account that lives in a workspace when the token request names that workspace, so the agent cannot use such an account through a VenafiConnection without this change. Co-Authored-By: Claude Signed-off-by: Richard Wall --- LICENSES | 4 +- .../jetstack.io_venaficonnections.yaml | 93 ++++--- ...fi-connection-crd.without-validations.yaml | 14 ++ .../templates/venafi-connection-crd.yaml | 54 ++-- .../jetstack.io_venaficonnections.yaml | 93 ++++--- ...fi-connection-crd.without-validations.yaml | 14 ++ .../templates/venafi-connection-crd.yaml | 54 ++-- go.mod | 82 +++--- go.sum | 237 +++++++++--------- pkg/client/client_venconn_test.go | 60 +++++ pkg/testutil/envtest.go | 2 +- 11 files changed, 423 insertions(+), 284 deletions(-) diff --git a/LICENSES b/LICENSES index 34dbafd1..c2f50477 100644 --- a/LICENSES +++ b/LICENSES @@ -58,11 +58,11 @@ github.com/go-openapi/swag,Apache-2.0 github.com/go-openapi/swag/cmdutils,Apache-2.0 github.com/go-openapi/swag/conv,Apache-2.0 github.com/go-openapi/swag/fileutils,Apache-2.0 -github.com/go-openapi/swag/jsonname,Apache-2.0 github.com/go-openapi/swag/jsonutils,Apache-2.0 github.com/go-openapi/swag/loading,Apache-2.0 github.com/go-openapi/swag/mangling,Apache-2.0 github.com/go-openapi/swag/netutils,Apache-2.0 +github.com/go-openapi/swag/pools,Apache-2.0 github.com/go-openapi/swag/stringutils,Apache-2.0 github.com/go-openapi/swag/typeutils,Apache-2.0 github.com/go-openapi/swag/yamlutils,Apache-2.0 @@ -100,6 +100,8 @@ github.com/sosodev/duration,MIT github.com/spf13/cobra,Apache-2.0 github.com/spf13/pflag,BSD-3-Clause github.com/stretchr/testify,MIT +github.com/stretchr/testify/internal/difflib,BSD-3-Clause +github.com/stretchr/testify/internal/spew,ISC github.com/valyala/fastjson,MIT github.com/x448/float16,MIT go.opentelemetry.io/otel,Apache-2.0 diff --git a/deploy/charts/discovery-agent/crd_bases/jetstack.io_venaficonnections.yaml b/deploy/charts/discovery-agent/crd_bases/jetstack.io_venaficonnections.yaml index 9389601d..f651eaad 100644 --- a/deploy/charts/discovery-agent/crd_bases/jetstack.io_venaficonnections.yaml +++ b/deploy/charts/discovery-agent/crd_bases/jetstack.io_venaficonnections.yaml @@ -4,7 +4,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.21.0 + controller-gen.kubebuilder.io/version: v0.22.0 name: venaficonnections.jetstack.io spec: group: jetstack.io @@ -285,8 +285,8 @@ spec: x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() - <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) + <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -303,8 +303,8 @@ spec: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() - == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) + == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -505,8 +505,8 @@ spec: x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() - <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) + <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -523,8 +523,8 @@ spec: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() - == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) + == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -724,8 +724,8 @@ spec: x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() - <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) + <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -742,8 +742,8 @@ spec: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() - == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) + == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -758,13 +758,26 @@ spec: The URL to connect to the NGTS Data Plane. If not set, the default value https://.ngts.paloaltonetworks.com is used. type: string + workspaceID: + description: |- + The ID of the NGTS workspace that the service account belongs to. + Required when the service account uses OIDC (workload identity) and + belongs to a workspace: without it, NGTS only looks for tenant-level + service accounts, and the token request fails with "Not found". Leave it + unset for a tenant-level service account. It has no effect with + privateKeyJWT, because the client ID identifies the account. NGTS + ignores it on API calls: they are scoped to the workspace of the service + account that authenticated. NGTS does not report an unknown workspace + ID: with OIDC, a wrong ID fails with the same "Not found" error as a + wrong issuer, audience or subject, so check it carefully. + minLength: 1 + type: string required: - jwt type: object x-kubernetes-validations: - message: exactly one of the fields in [tsgID url] must be set - rule: '[has(self.tsgID),has(self.url)].filter(x,x==true).size() - == 1' + rule: (has(self.tsgID)?1:0)+(has(self.url)?1:0) == 1 tpp: properties: accessToken: @@ -954,8 +967,8 @@ spec: x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() - <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) + <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -972,8 +985,8 @@ spec: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() - == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) + == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -1181,8 +1194,8 @@ spec: x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() - <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) + <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -1199,8 +1212,8 @@ spec: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() - == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) + == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -1393,8 +1406,8 @@ spec: x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() - <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) + <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -1411,8 +1424,8 @@ spec: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() - == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) + == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -1425,8 +1438,7 @@ spec: x-kubernetes-validations: - message: exactly one of the fields in [apiKey accessToken] must be set - rule: '[has(self.apiKey),has(self.accessToken)].filter(x,x==true).size() - == 1' + rule: (has(self.apiKey)?1:0)+(has(self.accessToken)?1:0) == 1 vcp: properties: accessToken: @@ -1618,8 +1630,8 @@ spec: x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() - <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) + <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -1636,8 +1648,8 @@ spec: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() - == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) + == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -1830,8 +1842,8 @@ spec: x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() - <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) + <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -1848,8 +1860,8 @@ spec: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() - == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) + == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -1862,14 +1874,13 @@ spec: x-kubernetes-validations: - message: exactly one of the fields in [apiKey accessToken] must be set - rule: '[has(self.apiKey),has(self.accessToken)].filter(x,x==true).size() - == 1' + rule: (has(self.apiKey)?1:0)+(has(self.accessToken)?1:0) == 1 type: object x-kubernetes-validations: - message: exactly one of the fields in [tpp ngts vcp vaas distributedIssuer firefly] must be set - rule: '[has(self.tpp),has(self.ngts),has(self.vcp),has(self.vaas),has(self.distributedIssuer),has(self.firefly)].filter(x,x==true).size() - == 1' + rule: (has(self.tpp)?1:0)+(has(self.ngts)?1:0)+(has(self.vcp)?1:0)+(has(self.vaas)?1:0)+(has(self.distributedIssuer)?1:0)+(has(self.firefly)?1:0) + == 1 status: properties: conditions: diff --git a/deploy/charts/discovery-agent/templates/venafi-connection-crd.without-validations.yaml b/deploy/charts/discovery-agent/templates/venafi-connection-crd.without-validations.yaml index 3f28e932..c9f0d9dc 100644 --- a/deploy/charts/discovery-agent/templates/venafi-connection-crd.without-validations.yaml +++ b/deploy/charts/discovery-agent/templates/venafi-connection-crd.without-validations.yaml @@ -709,6 +709,20 @@ spec: The URL to connect to the NGTS Data Plane. If not set, the default value https://.ngts.paloaltonetworks.com is used. type: string + workspaceID: + description: |- + The ID of the NGTS workspace that the service account belongs to. + Required when the service account uses OIDC (workload identity) and + belongs to a workspace: without it, NGTS only looks for tenant-level + service accounts, and the token request fails with "Not found". Leave it + unset for a tenant-level service account. It has no effect with + privateKeyJWT, because the client ID identifies the account. NGTS + ignores it on API calls: they are scoped to the workspace of the service + account that authenticated. NGTS does not report an unknown workspace + ID: with OIDC, a wrong ID fails with the same "Not found" error as a + wrong issuer, audience or subject, so check it carefully. + minLength: 1 + type: string required: - jwt type: object diff --git a/deploy/charts/discovery-agent/templates/venafi-connection-crd.yaml b/deploy/charts/discovery-agent/templates/venafi-connection-crd.yaml index 9110a291..50457c20 100644 --- a/deploy/charts/discovery-agent/templates/venafi-connection-crd.yaml +++ b/deploy/charts/discovery-agent/templates/venafi-connection-crd.yaml @@ -282,7 +282,7 @@ spec: type: object x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -296,7 +296,7 @@ spec: type: object x-kubernetes-validations: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -491,7 +491,7 @@ spec: type: object x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -505,7 +505,7 @@ spec: type: object x-kubernetes-validations: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -698,7 +698,7 @@ spec: type: object x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -712,7 +712,7 @@ spec: type: object x-kubernetes-validations: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -727,12 +727,26 @@ spec: The URL to connect to the NGTS Data Plane. If not set, the default value https://.ngts.paloaltonetworks.com is used. type: string + workspaceID: + description: |- + The ID of the NGTS workspace that the service account belongs to. + Required when the service account uses OIDC (workload identity) and + belongs to a workspace: without it, NGTS only looks for tenant-level + service accounts, and the token request fails with "Not found". Leave it + unset for a tenant-level service account. It has no effect with + privateKeyJWT, because the client ID identifies the account. NGTS + ignores it on API calls: they are scoped to the workspace of the service + account that authenticated. NGTS does not report an unknown workspace + ID: with OIDC, a wrong ID fails with the same "Not found" error as a + wrong issuer, audience or subject, so check it carefully. + minLength: 1 + type: string required: - jwt type: object x-kubernetes-validations: - message: exactly one of the fields in [tsgID url] must be set - rule: '[has(self.tsgID),has(self.url)].filter(x,x==true).size() == 1' + rule: (has(self.tsgID)?1:0)+(has(self.url)?1:0) == 1 tpp: properties: accessToken: @@ -916,7 +930,7 @@ spec: type: object x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -930,7 +944,7 @@ spec: type: object x-kubernetes-validations: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -1131,7 +1145,7 @@ spec: type: object x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -1145,7 +1159,7 @@ spec: type: object x-kubernetes-validations: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -1332,7 +1346,7 @@ spec: type: object x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -1346,7 +1360,7 @@ spec: type: object x-kubernetes-validations: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -1358,7 +1372,7 @@ spec: type: object x-kubernetes-validations: - message: exactly one of the fields in [apiKey accessToken] must be set - rule: '[has(self.apiKey),has(self.accessToken)].filter(x,x==true).size() == 1' + rule: (has(self.apiKey)?1:0)+(has(self.accessToken)?1:0) == 1 vcp: properties: accessToken: @@ -1544,7 +1558,7 @@ spec: type: object x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -1558,7 +1572,7 @@ spec: type: object x-kubernetes-validations: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -1745,7 +1759,7 @@ spec: type: object x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -1759,7 +1773,7 @@ spec: type: object x-kubernetes-validations: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -1771,11 +1785,11 @@ spec: type: object x-kubernetes-validations: - message: exactly one of the fields in [apiKey accessToken] must be set - rule: '[has(self.apiKey),has(self.accessToken)].filter(x,x==true).size() == 1' + rule: (has(self.apiKey)?1:0)+(has(self.accessToken)?1:0) == 1 type: object x-kubernetes-validations: - message: exactly one of the fields in [tpp ngts vcp vaas distributedIssuer firefly] must be set - rule: '[has(self.tpp),has(self.ngts),has(self.vcp),has(self.vaas),has(self.distributedIssuer),has(self.firefly)].filter(x,x==true).size() == 1' + rule: (has(self.tpp)?1:0)+(has(self.ngts)?1:0)+(has(self.vcp)?1:0)+(has(self.vaas)?1:0)+(has(self.distributedIssuer)?1:0)+(has(self.firefly)?1:0) == 1 status: properties: conditions: diff --git a/deploy/charts/venafi-kubernetes-agent/crd_bases/jetstack.io_venaficonnections.yaml b/deploy/charts/venafi-kubernetes-agent/crd_bases/jetstack.io_venaficonnections.yaml index 9389601d..f651eaad 100644 --- a/deploy/charts/venafi-kubernetes-agent/crd_bases/jetstack.io_venaficonnections.yaml +++ b/deploy/charts/venafi-kubernetes-agent/crd_bases/jetstack.io_venaficonnections.yaml @@ -4,7 +4,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.21.0 + controller-gen.kubebuilder.io/version: v0.22.0 name: venaficonnections.jetstack.io spec: group: jetstack.io @@ -285,8 +285,8 @@ spec: x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() - <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) + <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -303,8 +303,8 @@ spec: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() - == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) + == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -505,8 +505,8 @@ spec: x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() - <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) + <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -523,8 +523,8 @@ spec: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() - == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) + == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -724,8 +724,8 @@ spec: x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() - <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) + <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -742,8 +742,8 @@ spec: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() - == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) + == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -758,13 +758,26 @@ spec: The URL to connect to the NGTS Data Plane. If not set, the default value https://.ngts.paloaltonetworks.com is used. type: string + workspaceID: + description: |- + The ID of the NGTS workspace that the service account belongs to. + Required when the service account uses OIDC (workload identity) and + belongs to a workspace: without it, NGTS only looks for tenant-level + service accounts, and the token request fails with "Not found". Leave it + unset for a tenant-level service account. It has no effect with + privateKeyJWT, because the client ID identifies the account. NGTS + ignores it on API calls: they are scoped to the workspace of the service + account that authenticated. NGTS does not report an unknown workspace + ID: with OIDC, a wrong ID fails with the same "Not found" error as a + wrong issuer, audience or subject, so check it carefully. + minLength: 1 + type: string required: - jwt type: object x-kubernetes-validations: - message: exactly one of the fields in [tsgID url] must be set - rule: '[has(self.tsgID),has(self.url)].filter(x,x==true).size() - == 1' + rule: (has(self.tsgID)?1:0)+(has(self.url)?1:0) == 1 tpp: properties: accessToken: @@ -954,8 +967,8 @@ spec: x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() - <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) + <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -972,8 +985,8 @@ spec: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() - == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) + == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -1181,8 +1194,8 @@ spec: x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() - <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) + <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -1199,8 +1212,8 @@ spec: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() - == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) + == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -1393,8 +1406,8 @@ spec: x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() - <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) + <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -1411,8 +1424,8 @@ spec: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() - == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) + == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -1425,8 +1438,7 @@ spec: x-kubernetes-validations: - message: exactly one of the fields in [apiKey accessToken] must be set - rule: '[has(self.apiKey),has(self.accessToken)].filter(x,x==true).size() - == 1' + rule: (has(self.apiKey)?1:0)+(has(self.accessToken)?1:0) == 1 vcp: properties: accessToken: @@ -1618,8 +1630,8 @@ spec: x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() - <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) + <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -1636,8 +1648,8 @@ spec: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() - == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) + == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -1830,8 +1842,8 @@ spec: x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() - <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) + <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -1848,8 +1860,8 @@ spec: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() - == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) + == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -1862,14 +1874,13 @@ spec: x-kubernetes-validations: - message: exactly one of the fields in [apiKey accessToken] must be set - rule: '[has(self.apiKey),has(self.accessToken)].filter(x,x==true).size() - == 1' + rule: (has(self.apiKey)?1:0)+(has(self.accessToken)?1:0) == 1 type: object x-kubernetes-validations: - message: exactly one of the fields in [tpp ngts vcp vaas distributedIssuer firefly] must be set - rule: '[has(self.tpp),has(self.ngts),has(self.vcp),has(self.vaas),has(self.distributedIssuer),has(self.firefly)].filter(x,x==true).size() - == 1' + rule: (has(self.tpp)?1:0)+(has(self.ngts)?1:0)+(has(self.vcp)?1:0)+(has(self.vaas)?1:0)+(has(self.distributedIssuer)?1:0)+(has(self.firefly)?1:0) + == 1 status: properties: conditions: diff --git a/deploy/charts/venafi-kubernetes-agent/templates/venafi-connection-crd.without-validations.yaml b/deploy/charts/venafi-kubernetes-agent/templates/venafi-connection-crd.without-validations.yaml index b9d2342a..4d42aa35 100644 --- a/deploy/charts/venafi-kubernetes-agent/templates/venafi-connection-crd.without-validations.yaml +++ b/deploy/charts/venafi-kubernetes-agent/templates/venafi-connection-crd.without-validations.yaml @@ -711,6 +711,20 @@ spec: The URL to connect to the NGTS Data Plane. If not set, the default value https://.ngts.paloaltonetworks.com is used. type: string + workspaceID: + description: |- + The ID of the NGTS workspace that the service account belongs to. + Required when the service account uses OIDC (workload identity) and + belongs to a workspace: without it, NGTS only looks for tenant-level + service accounts, and the token request fails with "Not found". Leave it + unset for a tenant-level service account. It has no effect with + privateKeyJWT, because the client ID identifies the account. NGTS + ignores it on API calls: they are scoped to the workspace of the service + account that authenticated. NGTS does not report an unknown workspace + ID: with OIDC, a wrong ID fails with the same "Not found" error as a + wrong issuer, audience or subject, so check it carefully. + minLength: 1 + type: string required: - jwt type: object diff --git a/deploy/charts/venafi-kubernetes-agent/templates/venafi-connection-crd.yaml b/deploy/charts/venafi-kubernetes-agent/templates/venafi-connection-crd.yaml index 1845793a..b9c028cc 100644 --- a/deploy/charts/venafi-kubernetes-agent/templates/venafi-connection-crd.yaml +++ b/deploy/charts/venafi-kubernetes-agent/templates/venafi-connection-crd.yaml @@ -284,7 +284,7 @@ spec: type: object x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -298,7 +298,7 @@ spec: type: object x-kubernetes-validations: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -493,7 +493,7 @@ spec: type: object x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -507,7 +507,7 @@ spec: type: object x-kubernetes-validations: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -700,7 +700,7 @@ spec: type: object x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -714,7 +714,7 @@ spec: type: object x-kubernetes-validations: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -729,12 +729,26 @@ spec: The URL to connect to the NGTS Data Plane. If not set, the default value https://.ngts.paloaltonetworks.com is used. type: string + workspaceID: + description: |- + The ID of the NGTS workspace that the service account belongs to. + Required when the service account uses OIDC (workload identity) and + belongs to a workspace: without it, NGTS only looks for tenant-level + service accounts, and the token request fails with "Not found". Leave it + unset for a tenant-level service account. It has no effect with + privateKeyJWT, because the client ID identifies the account. NGTS + ignores it on API calls: they are scoped to the workspace of the service + account that authenticated. NGTS does not report an unknown workspace + ID: with OIDC, a wrong ID fails with the same "Not found" error as a + wrong issuer, audience or subject, so check it carefully. + minLength: 1 + type: string required: - jwt type: object x-kubernetes-validations: - message: exactly one of the fields in [tsgID url] must be set - rule: '[has(self.tsgID),has(self.url)].filter(x,x==true).size() == 1' + rule: (has(self.tsgID)?1:0)+(has(self.url)?1:0) == 1 tpp: properties: accessToken: @@ -918,7 +932,7 @@ spec: type: object x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -932,7 +946,7 @@ spec: type: object x-kubernetes-validations: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -1133,7 +1147,7 @@ spec: type: object x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -1147,7 +1161,7 @@ spec: type: object x-kubernetes-validations: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -1334,7 +1348,7 @@ spec: type: object x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -1348,7 +1362,7 @@ spec: type: object x-kubernetes-validations: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -1360,7 +1374,7 @@ spec: type: object x-kubernetes-validations: - message: exactly one of the fields in [apiKey accessToken] must be set - rule: '[has(self.apiKey),has(self.accessToken)].filter(x,x==true).size() == 1' + rule: (has(self.apiKey)?1:0)+(has(self.accessToken)?1:0) == 1 vcp: properties: accessToken: @@ -1546,7 +1560,7 @@ spec: type: object x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -1560,7 +1574,7 @@ spec: type: object x-kubernetes-validations: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -1747,7 +1761,7 @@ spec: type: object x-kubernetes-validations: - message: at most one of the fields in [clientID clientId] may be set - rule: '[has(self.clientID),has(self.clientId)].filter(x,x==true).size() <= 1' + rule: (has(self.clientID)?1:0)+(has(self.clientId)?1:0) <= 1 vcpOAuth: description: |- VCPOAuth is a SecretSource step that authenticates to the @@ -1761,7 +1775,7 @@ spec: type: object x-kubernetes-validations: - message: exactly one of the fields in [secret serviceAccountToken hashicorpVaultOAuth hashicorpVaultSecret hashicorpVaultLDAP tppOAuth vcpOAuth privateKeyJWT] must be set - rule: '[has(self.secret),has(self.serviceAccountToken),has(self.hashicorpVaultOAuth),has(self.hashicorpVaultSecret),has(self.hashicorpVaultLDAP),has(self.tppOAuth),has(self.vcpOAuth),has(self.privateKeyJWT)].filter(x,x==true).size() == 1' + rule: (has(self.secret)?1:0)+(has(self.serviceAccountToken)?1:0)+(has(self.hashicorpVaultOAuth)?1:0)+(has(self.hashicorpVaultSecret)?1:0)+(has(self.hashicorpVaultLDAP)?1:0)+(has(self.tppOAuth)?1:0)+(has(self.vcpOAuth)?1:0)+(has(self.privateKeyJWT)?1:0) == 1 maxItems: 50 type: array x-kubernetes-list-type: atomic @@ -1773,11 +1787,11 @@ spec: type: object x-kubernetes-validations: - message: exactly one of the fields in [apiKey accessToken] must be set - rule: '[has(self.apiKey),has(self.accessToken)].filter(x,x==true).size() == 1' + rule: (has(self.apiKey)?1:0)+(has(self.accessToken)?1:0) == 1 type: object x-kubernetes-validations: - message: exactly one of the fields in [tpp ngts vcp vaas distributedIssuer firefly] must be set - rule: '[has(self.tpp),has(self.ngts),has(self.vcp),has(self.vaas),has(self.distributedIssuer),has(self.firefly)].filter(x,x==true).size() == 1' + rule: (has(self.tpp)?1:0)+(has(self.ngts)?1:0)+(has(self.vcp)?1:0)+(has(self.vaas)?1:0)+(has(self.distributedIssuer)?1:0)+(has(self.firefly)?1:0) == 1 status: properties: conditions: diff --git a/go.mod b/go.mod index e75daf02..c9e40c5b 100644 --- a/go.mod +++ b/go.mod @@ -6,32 +6,32 @@ go 1.27.1 require ( github.com/cenkalti/backoff/v5 v5.0.3 github.com/fatih/color v1.19.0 - github.com/go-logr/logr v1.4.3 + github.com/go-logr/logr v1.4.4 github.com/golang-jwt/jwt/v4 v4.5.2 github.com/google/uuid v1.6.0 github.com/hashicorp/go-multierror v1.1.1 - github.com/jetstack/venafi-connection-lib v0.6.1-0.20260528123542-443dd7e48a1a + github.com/jetstack/venafi-connection-lib v0.6.1-0.20261009082524-62e2d3779277 github.com/lestrrat-go/jwx/v3 v3.1.1 github.com/microcosm-cc/bluemonday v1.0.27 github.com/pmylund/go-cache v2.1.0+incompatible - github.com/prometheus/client_golang v1.23.2 + github.com/prometheus/client_golang v1.24.1 github.com/spf13/cobra v1.10.2 github.com/spf13/pflag v1.0.10 - github.com/stretchr/testify v1.11.1 + github.com/stretchr/testify v1.12.1 golang.org/x/sync v0.23.0 gopkg.in/yaml.v2 v2.4.0 gopkg.in/yaml.v3 v3.0.1 - k8s.io/api v0.36.1 - k8s.io/apimachinery v0.36.1 - k8s.io/client-go v0.36.1 - k8s.io/component-base v0.36.1 + k8s.io/api v0.37.0 + k8s.io/apimachinery v0.37.0 + k8s.io/client-go v0.37.0 + k8s.io/component-base v0.37.0 k8s.io/klog/v2 v2.140.0 - sigs.k8s.io/controller-runtime v0.24.1 + sigs.k8s.io/controller-runtime v0.25.0 sigs.k8s.io/yaml v1.6.0 ) require ( - cel.dev/expr v0.25.2 // indirect + cel.dev/expr v0.25.3 // indirect github.com/antlr4-go/antlr/v4 v4.13.1 // indirect github.com/aymerick/douceur v0.2.0 // indirect github.com/beorn7/perks v1.0.1 // indirect @@ -42,28 +42,28 @@ require ( github.com/emicklei/go-restful/v3 v3.13.0 // indirect github.com/evanphx/json-patch/v5 v5.9.11 // indirect github.com/fsnotify/fsnotify v1.10.1 // indirect - github.com/fxamacker/cbor/v2 v2.9.2 // indirect + github.com/fxamacker/cbor/v2 v2.9.3 // indirect github.com/go-http-utils/headers v0.0.0-20181008091004-fed159eddc2a // indirect github.com/go-logr/zapr v1.3.0 // indirect - github.com/go-openapi/jsonpointer v0.23.1 // indirect - github.com/go-openapi/jsonreference v0.21.6 // indirect - github.com/go-openapi/swag v0.26.0 // indirect - github.com/go-openapi/swag/cmdutils v0.26.0 // indirect - github.com/go-openapi/swag/conv v0.26.0 // indirect - github.com/go-openapi/swag/fileutils v0.26.0 // indirect - github.com/go-openapi/swag/jsonname v0.26.0 // indirect - github.com/go-openapi/swag/jsonutils v0.26.0 // indirect - github.com/go-openapi/swag/loading v0.26.0 // indirect - github.com/go-openapi/swag/mangling v0.26.0 // indirect - github.com/go-openapi/swag/netutils v0.26.0 // indirect - github.com/go-openapi/swag/stringutils v0.26.0 // indirect - github.com/go-openapi/swag/typeutils v0.26.0 // indirect - github.com/go-openapi/swag/yamlutils v0.26.0 // indirect + github.com/go-openapi/jsonpointer v1.0.1 // indirect + github.com/go-openapi/jsonreference v1.0.2 // indirect + github.com/go-openapi/swag v0.29.1 // indirect + github.com/go-openapi/swag/cmdutils v0.29.1 // indirect + github.com/go-openapi/swag/conv v0.29.1 // indirect + github.com/go-openapi/swag/fileutils v0.29.1 // indirect + github.com/go-openapi/swag/jsonutils v0.29.1 // indirect + github.com/go-openapi/swag/loading v0.29.1 // indirect + github.com/go-openapi/swag/mangling v0.29.1 // indirect + github.com/go-openapi/swag/netutils v0.29.1 // indirect + github.com/go-openapi/swag/pools v0.29.1 // indirect + github.com/go-openapi/swag/stringutils v0.29.1 // indirect + github.com/go-openapi/swag/typeutils v0.29.1 // indirect + github.com/go-openapi/swag/yamlutils v0.29.1 // indirect github.com/go418/concurrentcache v0.7.0 // indirect github.com/go418/concurrentcache/logger v0.0.0-20260113125750-8e23f97949aa // indirect github.com/goccy/go-json v0.10.6 // indirect github.com/golang-jwt/jwt/v5 v5.3.1 // indirect - github.com/google/cel-go v0.30.0 // indirect + github.com/google/cel-go v0.31.0 // indirect github.com/google/gnostic-models v0.7.1 // indirect github.com/gorilla/css v1.0.1 // indirect github.com/hashicorp/errwrap v1.1.0 // indirect @@ -79,21 +79,21 @@ require ( github.com/modern-go/reflect2 v1.0.3-0.20250322232337-35a7c28c31ee // indirect github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect - github.com/prometheus/client_model v0.6.2 // indirect - github.com/prometheus/common v0.68.1 // indirect - github.com/prometheus/procfs v0.20.1 // indirect + github.com/prometheus/client_model v0.6.3 // indirect + github.com/prometheus/common v0.71.0 // indirect + github.com/prometheus/procfs v0.22.0 // indirect github.com/segmentio/asm v1.2.1 // indirect github.com/sosodev/duration v1.4.0 // indirect github.com/valyala/fastjson v1.6.10 // indirect github.com/x448/float16 v0.8.4 // indirect - go.opentelemetry.io/otel v1.44.0 // indirect - go.opentelemetry.io/otel/trace v1.44.0 // indirect + go.opentelemetry.io/otel v1.46.0 // indirect + go.opentelemetry.io/otel/trace v1.46.0 // indirect go.uber.org/multierr v1.11.0 // indirect go.uber.org/zap v1.28.0 // indirect go.yaml.in/yaml/v2 v2.4.4 // indirect - go.yaml.in/yaml/v3 v3.0.4 // indirect + go.yaml.in/yaml/v3 v3.0.5 // indirect golang.org/x/crypto v0.57.0 // indirect - golang.org/x/exp v0.0.0-20260603202125-055de637280b // indirect + golang.org/x/exp v0.0.0-20260824195058-e88cd73687aa // indirect golang.org/x/net v0.58.0 // indirect golang.org/x/oauth2 v0.36.0 // indirect golang.org/x/sys v0.48.0 // indirect @@ -101,16 +101,16 @@ require ( golang.org/x/text v0.42.0 // indirect golang.org/x/time v0.15.0 // indirect gomodules.xyz/jsonpatch/v2 v2.5.0 // indirect - google.golang.org/genproto/googleapis/api v0.0.0-20260526163538-3dc84a4a5aaa // indirect - google.golang.org/genproto/googleapis/rpc v0.0.0-20260526163538-3dc84a4a5aaa // indirect - google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af // indirect + google.golang.org/genproto/googleapis/api v0.0.0-20260831171406-18b4a7587f8a // indirect + google.golang.org/genproto/googleapis/rpc v0.0.0-20260831171406-18b4a7587f8a // indirect + google.golang.org/protobuf v1.36.12 // indirect gopkg.in/evanphx/json-patch.v4 v4.13.0 // indirect gopkg.in/inf.v0 v0.9.1 // indirect - k8s.io/apiextensions-apiserver v0.36.1 // indirect - k8s.io/apiserver v0.36.1 // indirect - k8s.io/kube-openapi v0.0.0-20260603220949-865597e52e25 // indirect - k8s.io/utils v0.0.0-20260507154919-ff6756f316d2 // indirect + k8s.io/apiextensions-apiserver v0.37.0 // indirect + k8s.io/apiserver v0.37.0 // indirect + k8s.io/kube-openapi v0.0.0-20260821135717-be32def86098 // indirect + k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3 // indirect sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 // indirect sigs.k8s.io/randfill v1.0.0 // indirect - sigs.k8s.io/structured-merge-diff/v6 v6.4.0 // indirect + sigs.k8s.io/structured-merge-diff/v6 v6.4.2 // indirect ) diff --git a/go.sum b/go.sum index e2fa1c1a..d9c81b2e 100644 --- a/go.sum +++ b/go.sum @@ -1,5 +1,5 @@ -cel.dev/expr v0.25.2 h1:K6j46C81hXtZQfuX60cVWQFBJahKSE2gfRbNuvr5bFs= -cel.dev/expr v0.25.2/go.mod h1:hrXvqGP6G6gyx8UAHSHJ5RGk//1Oj5nXQ2NI02Nrsg4= +cel.dev/expr v0.25.3 h1:A2jO8jwOugrrovveCWfj0KEZOfqiLgAcwjpHPhzIGw0= +cel.dev/expr v0.25.3/go.mod h1:hrXvqGP6G6gyx8UAHSHJ5RGk//1Oj5nXQ2NI02Nrsg4= github.com/Masterminds/semver/v3 v3.4.0 h1:Zog+i5UMtVoCU8oKka5P7i9q9HgrJeGzI9SA1Xbatp0= github.com/Masterminds/semver/v3 v3.4.0/go.mod h1:4V+yj/TJE1HU9XfppCwVMZq3I84lprf4nC11bSS5beM= github.com/antlr4-go/antlr/v4 v4.13.1 h1:SqQKkuVZ+zWkMMNkjy5FZe5mr5WURWnlpmOuzYWrPrQ= @@ -37,50 +37,50 @@ github.com/felixge/httpsnoop v1.0.4 h1:NFTV2Zj1bL4mc9sqWACXbQFVBBg2W3GPvqp8/ESS2 github.com/felixge/httpsnoop v1.0.4/go.mod h1:m8KPJKqk1gH5J9DgRY2ASl2lWCfGKXixSwevea8zH2U= github.com/fsnotify/fsnotify v1.10.1 h1:b0/UzAf9yR5rhf3RPm9gf3ehBPpf0oZKIjtpKrx59Ho= github.com/fsnotify/fsnotify v1.10.1/go.mod h1:TLheqan6HD6GBK6PrDWyDPBaEV8LspOxvPSjC+bVfgo= -github.com/fxamacker/cbor/v2 v2.9.2 h1:X4Ksno9+x3cz0TZv69ec1hxP/+tymuR8PXQJyDwfh78= -github.com/fxamacker/cbor/v2 v2.9.2/go.mod h1:vM4b+DJCtHn+zz7h3FFp/hDAI9WNWCsZj23V5ytsSxQ= +github.com/fxamacker/cbor/v2 v2.9.3 h1:oQBnFATpNdY8gJHTndDDv5Xl4QqNaz51G5LLEPhng3Q= +github.com/fxamacker/cbor/v2 v2.9.3/go.mod h1:vM4b+DJCtHn+zz7h3FFp/hDAI9WNWCsZj23V5ytsSxQ= github.com/go-http-utils/headers v0.0.0-20181008091004-fed159eddc2a h1:v6zMvHuY9yue4+QkG/HQ/W67wvtQmWJ4SDo9aK/GIno= github.com/go-http-utils/headers v0.0.0-20181008091004-fed159eddc2a/go.mod h1:I79BieaU4fxrw4LMXby6q5OS9XnoR9UIKLOzDFjUmuw= -github.com/go-logr/logr v1.4.3 h1:CjnDlHq8ikf6E492q6eKboGOC0T8CDaOvkHCIg8idEI= -github.com/go-logr/logr v1.4.3/go.mod h1:9T104GzyrTigFIr8wt5mBrctHMim0Nb2HLGrmQ40KvY= +github.com/go-logr/logr v1.4.4 h1:tG4xh9yMsRCAiodLVTxyrkzSZ9+o0L1Kg/+cPVcbP/8= +github.com/go-logr/logr v1.4.4/go.mod h1:9T104GzyrTigFIr8wt5mBrctHMim0Nb2HLGrmQ40KvY= github.com/go-logr/stdr v1.2.2 h1:hSWxHoqTgW2S2qGc0LTAI563KZ5YKYRhT3MFKZMbjag= github.com/go-logr/stdr v1.2.2/go.mod h1:mMo/vtBO5dYbehREoey6XUKy/eSumjCCveDpRre4VKE= github.com/go-logr/zapr v1.3.0 h1:XGdV8XW8zdwFiwOA2Dryh1gj2KRQyOOoNmBy4EplIcQ= github.com/go-logr/zapr v1.3.0/go.mod h1:YKepepNBd1u/oyhd/yQmtjVXmm9uML4IXUgMOwR8/Gg= -github.com/go-openapi/jsonpointer v0.23.1 h1:1HBACs7XIwR2RcmItfdSFlALhGbe6S92p0ry4d1GWg4= -github.com/go-openapi/jsonpointer v0.23.1/go.mod h1:iWRmZTrGn7XwYhtPt/fvdSFj1OfNBngqRT2UG3BxSqY= -github.com/go-openapi/jsonreference v0.21.6 h1:NZ5nGfnaM1n4I43Xjm1e5/M2GjOwQwndQz22uhxwD+Y= -github.com/go-openapi/jsonreference v0.21.6/go.mod h1:xzbgtQ3ZbWxvET3AxdzCJlJt6vkovbf+IfSPJjD0tUY= -github.com/go-openapi/swag v0.26.0 h1:GVDXCmfvhfu1BxiHo8/FA+BbKmhecHnG3varjON5/RI= -github.com/go-openapi/swag v0.26.0/go.mod h1:82g3193sZJRbocs7bNCqGfIgq8pkuwVwCfhKIRlEQF0= -github.com/go-openapi/swag/cmdutils v0.26.0 h1:iowihOcvq7y4egO8cOq0dmfohz6wfeQ63U1EnuhO2TU= -github.com/go-openapi/swag/cmdutils v0.26.0/go.mod h1:Sm1MVFMkF6guJJ+pQqHnQA3N0j9qALV3NxzDSv6bETM= -github.com/go-openapi/swag/conv v0.26.0 h1:5yGGsPYI1ZCva93U0AoKi/iZrNhaJEjr324YVsiD89I= -github.com/go-openapi/swag/conv v0.26.0/go.mod h1:tpAmIL7X58VPnHHiSO4uE3jBeRamGsFsfdDeDtb5ECE= -github.com/go-openapi/swag/fileutils v0.26.0 h1:WJoPRvsA7QRiiWluowkLJa9jaYR7FCuxmDvnCgaRRxU= -github.com/go-openapi/swag/fileutils v0.26.0/go.mod h1:0WDJ7lp67eNjPMO50wAWYlKvhOb6CQ37rzR7wrgI8Tc= -github.com/go-openapi/swag/jsonname v0.26.0 h1:gV1NFX9M8avo0YSpmWogqfQISigCmpaiNci8cGECU5w= -github.com/go-openapi/swag/jsonname v0.26.0/go.mod h1:urBBR8bZNoDYGr653ynhIx+gTeIz0ARZxHkAPktJK2M= -github.com/go-openapi/swag/jsonutils v0.26.0 h1:FawFML2iAXsPqmERscuMPIHmFsoP1tOqWkxBaKNMsnA= -github.com/go-openapi/swag/jsonutils v0.26.0/go.mod h1:2VmA0CJlyFqgawOaPI9psnjFDqzyivIqLYN34t9p91E= -github.com/go-openapi/swag/jsonutils/fixtures_test v0.26.0 h1:apqeINu/ICHouqiRZbyFvuDge5jCmmLTqGQ9V95EaOM= -github.com/go-openapi/swag/jsonutils/fixtures_test v0.26.0/go.mod h1:AyM6QT8uz5IdKxk5akv0y6u4QvcL9GWERt0Jx/F/R8Y= -github.com/go-openapi/swag/loading v0.26.0 h1:Apg6zaKhCJurpJer0DCxq99qwmhFddBhaMX7kilDcko= -github.com/go-openapi/swag/loading v0.26.0/go.mod h1:dBxQ/6V2uBaAQdevN18VELE6xSpJWZxLX4txe12JwDg= -github.com/go-openapi/swag/mangling v0.26.0 h1:Du2YC4YLA/Y5m/YKQd7AnY5qq0wRKSFZTTt8ktFaXcQ= -github.com/go-openapi/swag/mangling v0.26.0/go.mod h1:jifS7W9vbg+pw63bT+GI53otluMQL3CeemuyCHKwVx0= -github.com/go-openapi/swag/netutils v0.26.0 h1:CmZp+ZT7HrmFwrC3GdGsXBq2+42T1bjKBapcqVpIs3c= -github.com/go-openapi/swag/netutils v0.26.0/go.mod h1:5iK+Ok3ZohWWex1C50BFTPexi03UaPwjW4Oj8kgrpwo= -github.com/go-openapi/swag/stringutils v0.26.0 h1:qZQngLxs5s7SLijc3N2ZO+fUq2o8LjuWAASSrJuh+xg= -github.com/go-openapi/swag/stringutils v0.26.0/go.mod h1:sWn5uY+QIIspwPhvgnqJsH8xqFT2ZbYcvbcFanRyhFE= -github.com/go-openapi/swag/typeutils v0.26.0 h1:2kdEwdiNWy+JJdOvu5MA2IIg2SylWAFuuyQIKYybfq4= -github.com/go-openapi/swag/typeutils v0.26.0/go.mod h1:oovDuIUvTrEHVMqWilQzKzV4YlSKgyZmFh7AlfABNVE= -github.com/go-openapi/swag/yamlutils v0.26.0 h1:H7O8l/8NJJQ/oiReEN+oMpnGMyt8G0hl460nRZxhLMQ= -github.com/go-openapi/swag/yamlutils v0.26.0/go.mod h1:1evKEGAtP37Pkwcc7EWMF0hedX0/x3Rkvei2wtG/TbU= -github.com/go-openapi/testify/enable/yaml/v2 v2.4.2 h1:5zRca5jw7lzVREKCZVNBpysDNBjj74rBh0N2BGQbSR0= -github.com/go-openapi/testify/enable/yaml/v2 v2.4.2/go.mod h1:XVevPw5hUXuV+5AkI1u1PeAm27EQVrhXTTCPAF85LmE= -github.com/go-openapi/testify/v2 v2.5.1 h1:TMdhCaw8fUNraVSf3Omoob1dO/AzBfhtFAPW0an6sBo= -github.com/go-openapi/testify/v2 v2.5.1/go.mod h1:SgsVHtfooshd0tublTtJ50FPKhujf47YRqauXXOUxfw= +github.com/go-openapi/jsonpointer v1.0.1 h1:2KxywRmNwJkT/FMBa3iRNHEaAxSJvjqoufQZy3au1Mg= +github.com/go-openapi/jsonpointer v1.0.1/go.mod h1:wI7ZYsFmbIi9nBXOZqgDaS/bqOchRGZjqxFli7FBYxY= +github.com/go-openapi/jsonreference v1.0.2 h1:oS4et8FOf3p3UQxEo4Xt0esijmBUM+F259Xl72OSZsc= +github.com/go-openapi/jsonreference v1.0.2/go.mod h1:TbUNSOo+fcorZjFaNoiSDSoaNnnZtqJtLGR1PuvE/Cs= +github.com/go-openapi/swag v0.29.1 h1:C6EeWzUwQtcWEhE9eqBdUubGXxhWY4PlzHMLD7kLaiQ= +github.com/go-openapi/swag v0.29.1/go.mod h1:BzxEXKiPlSXRsRTv1KSBF/BpGKHxA/YciCnr4tv9bvA= +github.com/go-openapi/swag/cmdutils v0.29.1 h1:3DorPGfUdE80BogKY22EzoHBcHMrkVomZMoV7kS4ANY= +github.com/go-openapi/swag/cmdutils v0.29.1/go.mod h1:Sm1MVFMkF6guJJ+pQqHnQA3N0j9qALV3NxzDSv6bETM= +github.com/go-openapi/swag/conv v0.29.1 h1:AC4Eh/5c/eUDOUCzzsRC9ghmFgOSBHeRMGIngY0ZUGA= +github.com/go-openapi/swag/conv v0.29.1/go.mod h1:S1X7/ZrBEZOC0Wc8AGxjbcGS92l3WEjA7aPtpl+RaqM= +github.com/go-openapi/swag/fileutils v0.29.1 h1:ZcPzMceVhU1WPbK6N1G6sNQKdd1CWJlf3cA08UHuoM0= +github.com/go-openapi/swag/fileutils v0.29.1/go.mod h1:/wofKYckbtRl2p3+EwQsosie5CT1B38+dQ+PS579BzI= +github.com/go-openapi/swag/jsonutils v0.29.1 h1:AFCxs0eQZ24/QyfhVHM2t49rMz7Vv3XCsZQI6yrNy+c= +github.com/go-openapi/swag/jsonutils v0.29.1/go.mod h1:u3+sCfJpttDpcmS5kpm0yxL6GK0eWgODsx8Yw8fcqNM= +github.com/go-openapi/swag/jsonutils/fixtures_test v0.29.1 h1:BiiXE31Bx9SfpsMmOQj5KYpUhTZBpLVriVhJDuLuY2o= +github.com/go-openapi/swag/jsonutils/fixtures_test v0.29.1/go.mod h1:julgTUKZ9/D0j6O7GKajmRs+812FWxQg/mMpGunWSjg= +github.com/go-openapi/swag/loading v0.29.1 h1:FCv5fG8UhTdDJa2R7w+5O9Ekpcbw7tt0nFWvmDKGBjc= +github.com/go-openapi/swag/loading v0.29.1/go.mod h1:N0ESuem4p2oedKal8EJhciqnJ9Q9Wmt83L1CRB3Fouw= +github.com/go-openapi/swag/mangling v0.29.1 h1:lHALtvYCdxVnRl4GrHmFPwfBTZYIObqdGNSKyu/8D6I= +github.com/go-openapi/swag/mangling v0.29.1/go.mod h1:SAop9pB7PUjQ/CGCNf/JmCKTRK+GDO+RqE9UHqC/N6s= +github.com/go-openapi/swag/netutils v0.29.1 h1:IjIvdEP5duKcghFqJEPSUraRnkKYHoM65kTluTu+Jb4= +github.com/go-openapi/swag/netutils v0.29.1/go.mod h1:DUde7x4Bx00k5jYl2AdRpNAO0m7atUvD2x6X+bWkbno= +github.com/go-openapi/swag/pools v0.29.1 h1:NRogYxdEW9SjRM4mkAOji9iefO4MRXq3p/ZJcoQbUKg= +github.com/go-openapi/swag/pools v0.29.1/go.mod h1:leDcaghjkRAhCuCRv9NfJU5f0mjoU3cT/XZObhMk3pc= +github.com/go-openapi/swag/stringutils v0.29.1 h1:1ykunK7iJQk1uOO7+oUH1ukbsK85fFCOiCFMOVSY+F0= +github.com/go-openapi/swag/stringutils v0.29.1/go.mod h1:7fSqZ+z8Qc0tOfAAK0jVa5qFGrnIlRi6n7NeGGrr1vc= +github.com/go-openapi/swag/typeutils v0.29.1 h1:Nzv9nhnlLCRBPQqfOX+7lB6Guju370or8StT+lIOf6M= +github.com/go-openapi/swag/typeutils v0.29.1/go.mod h1:hxpgDZJVBkBsi/d3MIUosafoFdE5exaQRmVp0zwu3YE= +github.com/go-openapi/swag/yamlutils v0.29.1 h1:69w3tsBajm7MR/fejLy7HD/3J68Ys1SeeZMEzZ3w2sk= +github.com/go-openapi/swag/yamlutils v0.29.1/go.mod h1:rgsp3vT/QdWzKwn43CigDwjOGIenPyTZMKnxEM8jZOA= +github.com/go-openapi/testify/enable/yaml/v2 v2.6.1 h1:Jm+/ze2rMtbD98yen92AhATGLGREDYXG56Xr4gMjEtE= +github.com/go-openapi/testify/enable/yaml/v2 v2.6.1/go.mod h1:YDPnwCRDu38/oJBVMBVXOUDiJ9cIeBHWvfImHaXqnv4= +github.com/go-openapi/testify/v2 v2.7.0 h1:bycOreEj6wfBvijg3YFogZ/sFjTCDmQnwSodSzHa3X8= +github.com/go-openapi/testify/v2 v2.7.0/go.mod h1:SgsVHtfooshd0tublTtJ50FPKhujf47YRqauXXOUxfw= github.com/go-task/slim-sprig/v3 v3.0.0 h1:sUs3vkvUymDpBKi3qH1YSqBQk9+9D/8M2mN1vB6EwHI= github.com/go-task/slim-sprig/v3 v3.0.0/go.mod h1:W848ghGpv3Qj3dhTPRyJypKRiqCdHZiAzKg9hl15HA8= github.com/go418/concurrentcache v0.7.0 h1:1rrZ3StkIPBKoVcYpG6kjW/TvV7fKN/FDgrq/G/n52Y= @@ -91,16 +91,14 @@ github.com/goccy/go-json v0.10.6 h1:p8HrPJzOakx/mn/bQtjgNjdTcN+/S6FcG2CTtQOrHVU= github.com/goccy/go-json v0.10.6/go.mod h1:oq7eo15ShAhp70Anwd5lgX2pLfOS3QCiwU/PULtXL6M= github.com/goccy/go-yaml v1.19.2 h1:PmFC1S6h8ljIz6gMRBopkjP1TVT7xuwrButHID66PoM= github.com/goccy/go-yaml v1.19.2/go.mod h1:XBurs7gK8ATbW4ZPGKgcbrY1Br56PdM69F7LkFRi1kA= -github.com/gogo/protobuf v1.3.2 h1:Ov1cvc58UF3b5XjBnZv7+opcTcQFZebYjWzi34vdm4Q= -github.com/gogo/protobuf v1.3.2/go.mod h1:P1XiOD3dCwIKUDQYPy72D8LYyHL2YPYrpS2s69NZV8Q= github.com/golang-jwt/jwt/v4 v4.5.2 h1:YtQM7lnr8iZ+j5q71MGKkNw9Mn7AjHM68uc9g5fXeUI= github.com/golang-jwt/jwt/v4 v4.5.2/go.mod h1:m21LjoU+eqJr34lmDMbreY2eSTRJ1cv77w39/MY0Ch0= github.com/golang-jwt/jwt/v5 v5.3.1 h1:kYf81DTWFe7t+1VvL7eS+jKFVWaUnK9cB1qbwn63YCY= github.com/golang-jwt/jwt/v5 v5.3.1/go.mod h1:fxCRLWMO43lRc8nhHWY6LGqRcf+1gQWArsqaEUEa5bE= github.com/golang/protobuf v1.5.4 h1:i7eJL8qZTpSEXOPTxNKhASYpMn+8e5Q6AdndVa1dWek= github.com/golang/protobuf v1.5.4/go.mod h1:lnTiLA8Wa4RWRcIUkrtSVa5nRhsEGBg48fD6rSs7xps= -github.com/google/cel-go v0.30.0 h1:ll54AkzKunWkBn9wSoiUXbFZXYZTkdJGNXTBXUoolGo= -github.com/google/cel-go v0.30.0/go.mod h1:X0bD6iVNR8pkROSOoHVdgTkzmRcosof7WQqCD6wcMc8= +github.com/google/cel-go v0.31.0 h1:H0bhpFTqOvmHrBGrWKp7ZlhBm5Hh8PYUEXnwxT1LL7A= +github.com/google/cel-go v0.31.0/go.mod h1:X0bD6iVNR8pkROSOoHVdgTkzmRcosof7WQqCD6wcMc8= github.com/google/gnostic-models v0.7.1 h1:SisTfuFKJSKM5CPZkffwi6coztzzeYUhc3v4yxLWH8c= github.com/google/gnostic-models v0.7.1/go.mod h1:whL5G0m6dmc5cPxKc5bdKdEN3UjI7OUGxBlw57miDrQ= github.com/google/go-cmp v0.7.0 h1:wk8382ETsv4JYUZwIsn6YpYiWiBsYLSJiTsyBybVuN8= @@ -118,8 +116,8 @@ github.com/grpc-ecosystem/go-grpc-middleware/providers/prometheus v1.1.0 h1:QGLs github.com/grpc-ecosystem/go-grpc-middleware/providers/prometheus v1.1.0/go.mod h1:hM2alZsMUni80N33RBe6J0e423LB+odMj7d3EMP9l20= github.com/grpc-ecosystem/go-grpc-middleware/v2 v2.3.3 h1:B+8ClL/kCQkRiU82d9xajRPKYMrB7E0MbtzWVi1K4ns= github.com/grpc-ecosystem/go-grpc-middleware/v2 v2.3.3/go.mod h1:NbCUVmiS4foBGBHOYlCT25+YmGpJ32dZPi75pGEUpj4= -github.com/grpc-ecosystem/grpc-gateway/v2 v2.27.7 h1:X+2YciYSxvMQK0UZ7sg45ZVabVZBeBuvMkmuI2V3Fak= -github.com/grpc-ecosystem/grpc-gateway/v2 v2.27.7/go.mod h1:lW34nIZuQ8UDPdkon5fmfp2l3+ZkQ2me/+oecHYLOII= +github.com/grpc-ecosystem/grpc-gateway/v2 v2.29.0 h1:5VipnvEpbqr2gA2VbM+nYVbkIF28c5ZQfqCBQ5g2xfk= +github.com/grpc-ecosystem/grpc-gateway/v2 v2.29.0/go.mod h1:Hyl3n6Twe1hvtd9XUXDec4pTvgMSEixRuQKPTMH2bNs= github.com/hashicorp/errwrap v1.0.0/go.mod h1:YH+1FKiLXxHSkmPseP+kNlulaMuP3n2brvKWEqk/Jc4= github.com/hashicorp/errwrap v1.1.0 h1:OxrOeh75EUXMY8TBjag2fzXGZ40LB6IKw45YeGUDY2I= github.com/hashicorp/errwrap v1.1.0/go.mod h1:YH+1FKiLXxHSkmPseP+kNlulaMuP3n2brvKWEqk/Jc4= @@ -127,12 +125,12 @@ github.com/hashicorp/go-multierror v1.1.1 h1:H5DkEtf6CXdFp0N0Em5UCwQpXMWke8IA0+l github.com/hashicorp/go-multierror v1.1.1/go.mod h1:iw975J/qwKPdAO1clOe2L8331t/9/fmwbPZ6JB6eMoM= github.com/inconshreveable/mousetrap v1.1.0 h1:wN+x4NVGpMsO7ErUn/mUI3vEoE6Jt13X2s0bqwp9tc8= github.com/inconshreveable/mousetrap v1.1.0/go.mod h1:vpF70FUmC8bwa3OWnCshd2FqLfsEA9PFc4w1p2J65bw= -github.com/jetstack/venafi-connection-lib v0.6.1-0.20260528123542-443dd7e48a1a h1:DhmA/QBT7cTOAN2hoj36i7QSCBIkWpo7qbJcEeV8gCQ= -github.com/jetstack/venafi-connection-lib v0.6.1-0.20260528123542-443dd7e48a1a/go.mod h1:KPndhwwPHPkBqv7cocVTtEDPHV/CBrwapLqzUnwbCUs= +github.com/jetstack/venafi-connection-lib v0.6.1-0.20261009082524-62e2d3779277 h1:gaMouBUblTABlfKxDRpH6i7ztyIjq+pCSFF1/9AvXgU= +github.com/jetstack/venafi-connection-lib v0.6.1-0.20261009082524-62e2d3779277/go.mod h1:0kPO8MXLZ15aYaSijCBCzx36FBZyNYrw4W23RVWf6v0= github.com/json-iterator/go v1.1.12 h1:PV8peI4a0ysnczrg+LtxykD8LfKY9ML6u2jnxaEnrnM= github.com/json-iterator/go v1.1.12/go.mod h1:e30LSqwooZae/UwlEbR2852Gd8hjQvJoHmT4TnhNGBo= -github.com/klauspost/compress v1.18.0 h1:c/Cqfb0r+Yi+JtIEq73FWXVkRonBlf0CRNYc8Zttxdo= -github.com/klauspost/compress v1.18.0/go.mod h1:2Pp+KzxcywXVXMr50+X0Q/Lsb43OQHYWRCY2AiWywWQ= +github.com/klauspost/compress v1.19.1 h1:VsB4HPswih7mmZ8WleSFQ75c/Ui1M4trX5oAsJnhSlk= +github.com/klauspost/compress v1.19.1/go.mod h1:cwPg85FWrGar70rWktvGQj8/hthj3wpl0PGDogxkrSQ= github.com/kr/pretty v0.3.1 h1:flRD4NNwYAUpkphVc1HcthR4KEIFJ65n8Mw5qdRn3LE= github.com/kr/pretty v0.3.1/go.mod h1:hoEshYVHaxMs3cyo3Yncou5ZscifuDolrwPKZanG3xk= github.com/kr/text v0.2.0 h1:5Nx0Ya0ZqY2ygV366QzturHI13Jq95ApcVaJBhpS+AY= @@ -178,14 +176,14 @@ github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 h1:Jamvg5psRI github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4= github.com/pmylund/go-cache v2.1.0+incompatible h1:n+7K51jLz6a3sCvff3BppuCAkixuDHuJ/C57Vw/XjTE= github.com/pmylund/go-cache v2.1.0+incompatible/go.mod h1:hmz95dGvINpbRZGsqPcd7B5xXY5+EKb5PpGhQY3NTHk= -github.com/prometheus/client_golang v1.23.2 h1:Je96obch5RDVy3FDMndoUsjAhG5Edi49h0RJWRi/o0o= -github.com/prometheus/client_golang v1.23.2/go.mod h1:Tb1a6LWHB3/SPIzCoaDXI4I8UHKeFTEQ1YCr+0Gyqmg= -github.com/prometheus/client_model v0.6.2 h1:oBsgwpGs7iVziMvrGhE53c/GrLUsZdHnqNwqPLxwZyk= -github.com/prometheus/client_model v0.6.2/go.mod h1:y3m2F6Gdpfy6Ut/GBsUqTWZqCUvMVzSfMLjcu6wAwpE= -github.com/prometheus/common v0.68.1 h1:omjRRl4QP4komogpXuhfeOiisQg7xdy8VM1UY+pStaY= -github.com/prometheus/common v0.68.1/go.mod h1:ZzL3f6u94qUxh9p+tJTrF+FvBS1XXbbRAZCQkytAL0Y= -github.com/prometheus/procfs v0.20.1 h1:XwbrGOIplXW/AU3YhIhLODXMJYyC1isLFfYCsTEycfc= -github.com/prometheus/procfs v0.20.1/go.mod h1:o9EMBZGRyvDrSPH1RqdxhojkuXstoe4UlK79eF5TGGo= +github.com/prometheus/client_golang v1.24.1 h1:JnJkREXzWxUdCuPFpIWZiPispT9xVV59uiuyR2bPlnU= +github.com/prometheus/client_golang v1.24.1/go.mod h1:F+oSRECHg4sse5ucfYpYDeIv/hu68Zo0uoHKetWnzcE= +github.com/prometheus/client_model v0.6.3 h1:O0jaTVAYNxTHYInEPFJt5I3+sN8zqBtVMPTB1qyxiEo= +github.com/prometheus/client_model v0.6.3/go.mod h1:gpN5P9S7Rr6Yr92PiQ+Ixvhf6JZEkF1dnxsYL2aPBEM= +github.com/prometheus/common v0.71.0 h1:9KDAKb7Mj3HEVKyFCK6Dc/HIwlBzZIN2l7/lrHl3KK8= +github.com/prometheus/common v0.71.0/go.mod h1:CLJ5H8TEsGX8bl31BdMkfhIZ+QmZ9tBPPotUxUbfcmk= +github.com/prometheus/procfs v0.22.0 h1:6q9+/JL9IKAPbCmBrv9n5O5Ty3NKnciV5X7YGw0oics= +github.com/prometheus/procfs v0.22.0/go.mod h1:CvmFr/GVhIjIvWJZW3tgkODBQMRIf0EyWMQLHCHab58= github.com/rogpeppe/go-internal v1.14.1 h1:UQB4HGPB6osV0SQTLymcB4TgvyWu6ZyliaW0tI/otEQ= github.com/rogpeppe/go-internal v1.14.1/go.mod h1:MaRKkUm5W0goXpeCfT7UZI6fk/L7L7so1lCWt35ZSgc= github.com/russross/blackfriday/v2 v2.1.0/go.mod h1:+Rmxgy9KzJVeS9/2gXHxylqXiyQDYRxCVz55jmeOWTM= @@ -199,42 +197,42 @@ github.com/spf13/pflag v1.0.9/go.mod h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An github.com/spf13/pflag v1.0.10 h1:4EBh2KAYBwaONj6b2Ye1GiHfwjqyROoF4RwYO+vPwFk= github.com/spf13/pflag v1.0.10/go.mod h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An2Bg= github.com/stretchr/objx v0.1.0/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME= -github.com/stretchr/objx v0.5.2 h1:xuMeJ0Sdp5ZMRXx/aWO6RZxdr3beISkG5/G/aIRr3pY= -github.com/stretchr/objx v0.5.2/go.mod h1:FRsXN1f5AsAjCGJKqEizvkpNtU+EGNCLh3NxZ/8L+MA= +github.com/stretchr/objx v0.5.3 h1:jmXUvGomnU1o3W/V5h2VEradbpJDwGrzugQQvL0POH4= +github.com/stretchr/objx v0.5.3/go.mod h1:rDQraq+vQZU7Fde9LOZLr8Tax6zZvy4kuNKF+QYS+U0= github.com/stretchr/testify v1.3.0/go.mod h1:M5WIy9Dh21IEIfnGCwXGc5bZfKNJtfHm1UVUgZn+9EI= github.com/stretchr/testify v1.7.1/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg= -github.com/stretchr/testify v1.11.1 h1:7s2iGBzp5EwR7/aIZr8ao5+dra3wiQyKjjFuvgVKu7U= -github.com/stretchr/testify v1.11.1/go.mod h1:wZwfW3scLgRK+23gO65QZefKpKQRnfz6sD981Nm4B6U= +github.com/stretchr/testify v1.12.1 h1:EuwCh5fleGS7H32xRwO3wRGT7DxrDhLAT6FF8MpWDWE= +github.com/stretchr/testify v1.12.1/go.mod h1:MDEgiDPPsNp5cuIrHPPCyornHKgEVbtFUmoNlxoYthg= github.com/valyala/fastjson v1.6.10 h1:/yjJg8jaVQdYR3arGxPE2X5z89xrlhS0eGXdv+ADTh4= github.com/valyala/fastjson v1.6.10/go.mod h1:e6FubmQouUNP73jtMLmcbxS6ydWIpOfhz34TSfO3JaE= github.com/x448/float16 v0.8.4 h1:qLwI1I70+NjRFUR3zs1JPUCgaCXSh3SW62uAKT1mSBM= github.com/x448/float16 v0.8.4/go.mod h1:14CWIYCyZA/cWjXOioeEpHeN/83MdbZDRQHoFcYsOfg= -go.etcd.io/etcd/api/v3 v3.6.8 h1:gqb1VN92TAI6G2FiBvWcqKtHiIjr4SU2GdXxTwyexbM= -go.etcd.io/etcd/api/v3 v3.6.8/go.mod h1:qyQj1HZPUV3B5cbAL8scG62+fyz5dSxxu0w8pn28N6Q= -go.etcd.io/etcd/client/pkg/v3 v3.6.8 h1:Qs/5C0LNFiqXxYf2GU8MVjYUEXJ6sZaYOz0zEqQgy50= -go.etcd.io/etcd/client/pkg/v3 v3.6.8/go.mod h1:GsiTRUZE2318PggZkAo6sWb6l8JLVrnckTNfbG8PWtw= -go.etcd.io/etcd/client/v3 v3.6.8 h1:B3G76t1UykqAOrbio7s/EPatixQDkQBevN8/mwiplrY= -go.etcd.io/etcd/client/v3 v3.6.8/go.mod h1:MVG4BpSIuumPi+ELF7wYtySETmoTWBHVcDoHdVupwt8= +go.etcd.io/etcd/api/v3 v3.7.0 h1:WZlGK7pRtYGDB8ti8wkrQ5D2oWGMbtNL9VA5e+vF2Fg= +go.etcd.io/etcd/api/v3 v3.7.0/go.mod h1:EcTihnwAQ0BQNh5dfAdaFVFdchuo7EP0HlX7TV3jz/A= +go.etcd.io/etcd/client/pkg/v3 v3.7.0 h1:sW9njJzS3vXKcAJjjLQ4nk+avNUJ12Bcijcx8ehUskE= +go.etcd.io/etcd/client/pkg/v3 v3.7.0/go.mod h1:cnzZGIUzSfjEwLC6UBVsSXlEK1eepS/JUD7wE6PLRT0= +go.etcd.io/etcd/client/v3 v3.7.0 h1:5MHO37VbPB87VRPKUXEcicjeQWiTSjpPv3Ume8xPx20= +go.etcd.io/etcd/client/v3 v3.7.0/go.mod h1:DJ382WuwjmbowjPDyaaQ0idWXy4dh91XRhe4FOrb9vM= go.opentelemetry.io/auto/sdk v1.2.1 h1:jXsnJ4Lmnqd11kwkBV2LgLoFMZKizbCi5fNZ/ipaZ64= go.opentelemetry.io/auto/sdk v1.2.1/go.mod h1:KRTj+aOaElaLi+wW1kO/DZRXwkF4C5xPbEe3ZiIhN7Y= -go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.65.0 h1:XmiuHzgJt067+a6kwyAzkhXooYVv3/TOw9cM2VfJgUM= -go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.65.0/go.mod h1:KDgtbWKTQs4bM+VPUr6WlL9m/WXcmkCcBlIzqxPGzmI= -go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.65.0 h1:7iP2uCb7sGddAr30RRS6xjKy7AZ2JtTOPA3oolgVSw8= -go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.65.0/go.mod h1:c7hN3ddxs/z6q9xwvfLPk+UHlWRQyaeR1LdgfL/66l0= -go.opentelemetry.io/otel v1.44.0 h1:JjwHmHpA4iZ3wBxluu2fbbE7j4kqlE8jXyAyPXH7HqU= -go.opentelemetry.io/otel v1.44.0/go.mod h1:BMgjTHL9WPRlRjL2oZCBTL4whCGtXch2H4BhOPIAyYc= -go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.40.0 h1:QKdN8ly8zEMrByybbQgv8cWBcdAarwmIPZ6FThrWXJs= -go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.40.0/go.mod h1:bTdK1nhqF76qiPoCCdyFIV+N/sRHYXYCTQc+3VCi3MI= -go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.40.0 h1:DvJDOPmSWQHWywQS6lKL+pb8s3gBLOZUtw4N+mavW1I= -go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.40.0/go.mod h1:EtekO9DEJb4/jRyN4v4Qjc2yA7AtfCBuz2FynRUWTXs= -go.opentelemetry.io/otel/metric v1.44.0 h1:1w0gILTcHdr3YI+ixLyjemwrVnsMURbTZFrSYCdDdmc= -go.opentelemetry.io/otel/metric v1.44.0/go.mod h1:8O7hanEPBNgEMmybD3s2VBKcgWOCsA6tzHBPODAiquo= -go.opentelemetry.io/otel/sdk v1.40.0 h1:KHW/jUzgo6wsPh9At46+h4upjtccTmuZCFAc9OJ71f8= -go.opentelemetry.io/otel/sdk v1.40.0/go.mod h1:Ph7EFdYvxq72Y8Li9q8KebuYUr2KoeyHx0DRMKrYBUE= -go.opentelemetry.io/otel/trace v1.44.0 h1:jxF5CsGYCe74MCRx2X4g7WsY/VBKRqqpNvXlX/6gtIk= -go.opentelemetry.io/otel/trace v1.44.0/go.mod h1:oLl1jrMQAVo6v3GAggN+1VH9VIz9iUSvW53sW1Q8PIE= -go.opentelemetry.io/proto/otlp v1.9.0 h1:l706jCMITVouPOqEnii2fIAuO3IVGBRPV5ICjceRb/A= -go.opentelemetry.io/proto/otlp v1.9.0/go.mod h1:xE+Cx5E/eEHw+ISFkwPLwCZefwVjY+pqKg1qcK03+/4= +go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.68.0 h1:0Qx7VGBacMm9ZENQ7TnNObTYI4ShC+lHI16seduaxZo= +go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.68.0/go.mod h1:Sje3i3MjSPKTSPvVWCaL8ugBzJwik3u4smCjUeuupqg= +go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.69.0 h1:8tvICD4vSTOOsNrsI4Ljf6C+6UKvpTEH5XY3JMoyPoo= +go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.69.0/go.mod h1:z9+yiacE0IHRqM4qFfkbt/JYlmYXgss8GY/jXoNuPJI= +go.opentelemetry.io/otel v1.46.0 h1:FHt5/CDyVxi/8IM1CH7VE/rRgq3kLHa2mSTVMO8AWyc= +go.opentelemetry.io/otel v1.46.0/go.mod h1:Gj3SEScelsNC45tp4nSxRYlS+f5iez7W8XPMCt905kE= +go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.44.0 h1:4YsVu3B8+3qtWYYrsUYgn0OG78pN0rnNPRGX4SbokQI= +go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.44.0/go.mod h1:+wnlSn0mD1ADVMe3v9Z/WIaiz6q6gL2J/ejaAmdmv80= +go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.44.0 h1:qazEJlUOQzhCpzQpFETGby7EdqjI1wsd0W+6Gg1SCTU= +go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.44.0/go.mod h1:fOD2Yefuxixkx3ahVNf0O/PERb6r4OlbxfATVnYvzCo= +go.opentelemetry.io/otel/metric v1.46.0 h1:yBnkXvgV7AXFILZc5K6IZe/CBFF3OS7BJ8ov6/lj0K8= +go.opentelemetry.io/otel/metric v1.46.0/go.mod h1:iPmdWqifKUdzziPkvvzIJXITl56fQx2mGM/DHLB3/2o= +go.opentelemetry.io/otel/sdk v1.44.0 h1:nHYwb9lK+fJPU/dnT6s7W7Z8itMWyqrnVfbheVYrZ58= +go.opentelemetry.io/otel/sdk v1.44.0/go.mod h1:Osuydd3Se74nqjAKxid74N5eC+jfEqfTegHRnq58oK0= +go.opentelemetry.io/otel/trace v1.46.0 h1:OULy7ccdJnZtJ0UDYFOIGaCmiWzJ8Vi2G/Rsu60qs1c= +go.opentelemetry.io/otel/trace v1.46.0/go.mod h1:J7GAXweO77XSFkB/rmAqk9D6ihszhFjLU+d9WuUxDLI= +go.opentelemetry.io/proto/otlp v1.10.0 h1:IQRWgT5srOCYfiWnpqUYz9CVmbO8bFmKcwYxpuCSL2g= +go.opentelemetry.io/proto/otlp v1.10.0/go.mod h1:/CV4QoCR/S9yaPj8utp3lvQPoqMtxXdzn7ozvvozVqk= go.uber.org/goleak v1.3.0 h1:2K3zAYmnTNqV73imy9J1T3WC+gmCePx2hEGkimedGto= go.uber.org/goleak v1.3.0/go.mod h1:CoHD4mav9JJNrW/WLlf7HGZPjdw8EucARQHekz1X6bE= go.uber.org/multierr v1.11.0 h1:blXXJkSxSSfBVBlC76pxqeO+LN3aDfLQo+309xJstO0= @@ -243,12 +241,13 @@ go.uber.org/zap v1.28.0 h1:IZzaP1Fv73/T/pBMLk4VutPl36uNC+OSUh3JLG3FIjo= go.uber.org/zap v1.28.0/go.mod h1:rDLpOi171uODNm/mxFcuYWxDsqWSAVkFdX4XojSKg/Q= go.yaml.in/yaml/v2 v2.4.4 h1:tuyd0P+2Ont/d6e2rl3be67goVK4R6deVxCUX5vyPaQ= go.yaml.in/yaml/v2 v2.4.4/go.mod h1:gMZqIpDtDqOfM0uNfy0SkpRhvUryYH0Z6wdMYcacYXQ= -go.yaml.in/yaml/v3 v3.0.4 h1:tfq32ie2Jv2UxXFdLJdh3jXuOzWiL1fo0bu/FbuKpbc= go.yaml.in/yaml/v3 v3.0.4/go.mod h1:DhzuOOF2ATzADvBadXxruRBLzYTpT36CKvDb3+aBEFg= +go.yaml.in/yaml/v3 v3.0.5 h1:N6y/pJk8buWs9NY5ERU2HSMfm+IuD/OtfdAnq6kESPw= +go.yaml.in/yaml/v3 v3.0.5/go.mod h1:HVTZu1O7/Vkt2N+BFy8Zza+lnLsABggaTM2ZpNIGuKg= golang.org/x/crypto v0.57.0 h1:3ZVCjf8Ggz7zneR/EHRVx68Ctf+2pmIMP2UFhh9cC6M= golang.org/x/crypto v0.57.0/go.mod h1:Fdz0i5U6CoizGwLda9DttjSk6qlZo25zYNtR+ycvuZA= -golang.org/x/exp v0.0.0-20260603202125-055de637280b h1:v1uXiEBHo8QA0LiGCo7UgHMzHT4Kdfpl2zmtH5vaP1Q= -golang.org/x/exp v0.0.0-20260603202125-055de637280b/go.mod h1:d2fgXJLVs4dYDHUk5lwMIfzRzSrWCfGZb0ZqeLa/Vcw= +golang.org/x/exp v0.0.0-20260824195058-e88cd73687aa h1:QSyA8ishJCyT21kER9KwNt0b7BM3iRK4x9QXhjN5Fdk= +golang.org/x/exp v0.0.0-20260824195058-e88cd73687aa/go.mod h1:zeBbvyFKDaLwa7CH/zI8KXt7gTl14SF7sO08Pl5jBCM= golang.org/x/mod v0.41.0 h1:qJmnOUb4YB+FsEuM3HcWucdZASCPGhsX6uljO6pog0c= golang.org/x/mod v0.41.0/go.mod h1:Ek9pY8RKWXwsWvd3rQiHYtMqkjSUV+s1Rj7j4H5Ur6o= golang.org/x/net v0.58.0 h1:ynWG7rqYi4ccpTEuPZ2QGWHktVEM9DMCj9yzDE0Q7To= @@ -269,14 +268,14 @@ golang.org/x/tools v0.49.0 h1:3NI7VXzL9+1WZD52Dx2ttoPwD5DWrFGpl9mFZDlmisI= golang.org/x/tools v0.49.0/go.mod h1:SJNXV9DBKT0UbdttsQjbfJlAE/q+y36++zo3uL3N0Oo= gomodules.xyz/jsonpatch/v2 v2.5.0 h1:JELs8RLM12qJGXU4u/TO3V25KW8GreMKl9pdkk14RM0= gomodules.xyz/jsonpatch/v2 v2.5.0/go.mod h1:AH3dM2RI6uoBZxn3LVrfvJ3E0/9dG4cSrbuBJT4moAY= -google.golang.org/genproto/googleapis/api v0.0.0-20260526163538-3dc84a4a5aaa h1:Kjn0N0tCrDgiAFW+lGO4JZ3ck44CehvJQMAwj9QF0G8= -google.golang.org/genproto/googleapis/api v0.0.0-20260526163538-3dc84a4a5aaa/go.mod h1:q4lMZS6kskjT5HvCPrnnypcDPVJqT/f4nfxmkE7gryY= -google.golang.org/genproto/googleapis/rpc v0.0.0-20260526163538-3dc84a4a5aaa h1:mZHHdPZl0dbGHCflZgAq/Q468DWVFcU2whhB2KAo8fk= -google.golang.org/genproto/googleapis/rpc v0.0.0-20260526163538-3dc84a4a5aaa/go.mod h1:4Hqkh8ycfw05ld/3BWL7rJOSfebL2Q+DVDeRgYgxUU8= -google.golang.org/grpc v1.79.3 h1:sybAEdRIEtvcD68Gx7dmnwjZKlyfuc61Dyo9pGXXkKE= -google.golang.org/grpc v1.79.3/go.mod h1:KmT0Kjez+0dde/v2j9vzwoAScgEPx/Bw1CYChhHLrHQ= -google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af h1:+5/Sw3GsDNlEmu7TfklWKPdQ0Ykja5VEmq2i817+jbI= -google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af/go.mod h1:HTf+CrKn2C3g5S8VImy6tdcUvCska2kB7j23XfzDpco= +google.golang.org/genproto/googleapis/api v0.0.0-20260831171406-18b4a7587f8a h1:i3TAXhpKc7TUP1VAPiBBrv45kamjoizCC3rOC0cAbOs= +google.golang.org/genproto/googleapis/api v0.0.0-20260831171406-18b4a7587f8a/go.mod h1:CvYJHpbzPlT0fb/PsgtAamdwru/GVxUsomFdXTpOTI8= +google.golang.org/genproto/googleapis/rpc v0.0.0-20260831171406-18b4a7587f8a h1:3Dnd1cDaZlB68lziofO+bJXpjOy8UfRv8Unt+yH8tQ4= +google.golang.org/genproto/googleapis/rpc v0.0.0-20260831171406-18b4a7587f8a/go.mod h1:DjtHYE8FKJLivXcBEjGwndXfIC23G0VpXiXKqG179uA= +google.golang.org/grpc v1.82.1 h1:NnAxzGRA0677vCa4BUkOAnO5+FfQqVl9iUXeD0IqcGE= +google.golang.org/grpc v1.82.1/go.mod h1:yzTZ1TB1Z3SG+LIYaI+WiE8D5+PZ3ArnrSp8zF3+/ZA= +google.golang.org/protobuf v1.36.12 h1:pJOKDDOyeXErUroCihFAd5LQuwXBSpVnKGrj5o/fwxc= +google.golang.org/protobuf v1.36.12/go.mod h1:HTf+CrKn2C3g5S8VImy6tdcUvCska2kB7j23XfzDpco= gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= gopkg.in/check.v1 v1.0.0-20201130134442-10cb98267c6c h1:Hei/4ADfdWqJk1ZMxUNpqntNwaWcugrBjAiHlqqRiVk= gopkg.in/check.v1 v1.0.0-20201130134442-10cb98267c6c/go.mod h1:JHkPIbrfpd72SG/EVd6muEfDQjcINNoR0C8j2r3qZ4Q= @@ -289,33 +288,33 @@ gopkg.in/yaml.v2 v2.4.0/go.mod h1:RDklbk79AGWmwhnvt/jBztapEOGDOx6ZbXqjP6csGnQ= gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA= gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= -k8s.io/api v0.36.1 h1:XbL/EMj8K2aJpJtePmqUyQMsM0D4QI2pvl7YKJ20FTY= -k8s.io/api v0.36.1/go.mod h1:KOWo4ey3TINlXjeHVuwB3i+tXXnu+UcwFBHlI/9dvEo= -k8s.io/apiextensions-apiserver v0.36.1 h1:6JfYmPUsuUIHuN+3QxutXYWj492RqF5fBSx67GYK5Ks= -k8s.io/apiextensions-apiserver v0.36.1/go.mod h1:pLzZin90riwisdzKwv/GoTwENooytoIx5zWJb4Hkby8= -k8s.io/apimachinery v0.36.1 h1:G63Gjx2W+q0YD+72Vo8oY0nDnePVwnuzTmmy5ENrVSA= -k8s.io/apimachinery v0.36.1/go.mod h1:ibYOR00vW/I1kzvi5SF0dRuJ52BvKtfvRdOn35GPQ+8= -k8s.io/apiserver v0.36.1 h1:iMS5V+rPUertv5P9RaqJgmHHTuh4quWpoxchvMUY+JY= -k8s.io/apiserver v0.36.1/go.mod h1:Cby1PbLWztu0GDOxoO6iFOyyqIsziHNEW+w9zVQ22Kw= -k8s.io/client-go v0.36.1 h1:FN/K8QIT2CEDt+2WB2HnWrUANZ50AP5GII43/SP2JR0= -k8s.io/client-go v0.36.1/go.mod h1:s6rAnCtTGYDQnpNjEhSaISV+2O8jwruZ6m3QOYBFbtU= -k8s.io/component-base v0.36.1 h1:iG6GsELftXqTNG9HG6kiVjatSgAw1sf5pJ6R5a6N0kA= -k8s.io/component-base v0.36.1/go.mod h1:nf9XPlntRdqO6WMeEWAA5F93Y4ICZQdeT9GeqLDB3JI= +k8s.io/api v0.37.0 h1:Z//Vj9N7RA/yS2sDmxyeo7h+RR4zbUrd2vrd3Z0TbB4= +k8s.io/api v0.37.0/go.mod h1:LKXgcJWMc+f4OLbP5SFR8rulEg07zZhpi/zMULiBImk= +k8s.io/apiextensions-apiserver v0.37.0 h1:zRMQ3+/LIE5oZ0tVvXwYHC+dIkSP5cjNWju7AZU1LOI= +k8s.io/apiextensions-apiserver v0.37.0/go.mod h1:HU0PfSBwchHL5iDau6jjt9zU6ryWkDDlaVUiq91NK80= +k8s.io/apimachinery v0.37.0 h1:Np2AbDtf8x6RDHiD8T9LbKJ9gaegeVNa8yNm5FuGKm0= +k8s.io/apimachinery v0.37.0/go.mod h1:RN3nhprFSCxOi5Selxd7oMTXOe/c+ZbcE7Im+TS2zkE= +k8s.io/apiserver v0.37.0 h1:TXg7OxsOWrAH8J4Zi/gBAZuMw1Dfdd+6cca2h4qjRqo= +k8s.io/apiserver v0.37.0/go.mod h1:OddHDF4gy9qyIb8o/3+qaeP6S0vEObWLgOygVqXksv0= +k8s.io/client-go v0.37.0 h1:nsN31fy8wBySuZ+QRnKmrjRSQLOG2rvoGN0tKd12zhQ= +k8s.io/client-go v0.37.0/go.mod h1:FcGqw+Ll/gNQiq+nPGY1Oyt9y7SgDh1d3MW3RFDEbn0= +k8s.io/component-base v0.37.0 h1:3SdSa4+itMdFTDFTeR8CxKGmSTSMXFlKL4ky8OqjguM= +k8s.io/component-base v0.37.0/go.mod h1:LjOebp4R9y6LODWZQv102ZQxGheLcDO2ZJLAw6bbh4I= k8s.io/klog/v2 v2.140.0 h1:Tf+J3AH7xnUzZyVVXhTgGhEKnFqye14aadWv7bzXdzc= k8s.io/klog/v2 v2.140.0/go.mod h1:o+/RWfJ6PwpnFn7OyAG3QnO47BFsymfEfrz6XyYSSp0= -k8s.io/kube-openapi v0.0.0-20260603220949-865597e52e25 h1:mPMaPMpBij2V1Wv/fR+HW124vVGXXvOSS9ver/9yjWs= -k8s.io/kube-openapi v0.0.0-20260603220949-865597e52e25/go.mod h1:V/QaCUYDa+0QpcHhVVc5l99Uz56wEMEXBSj9oCDkNDY= -k8s.io/utils v0.0.0-20260507154919-ff6756f316d2 h1:wU4tMEhLGgIbLvXQb1cfN+EcM0wf7zC6CPF+C79jroc= -k8s.io/utils v0.0.0-20260507154919-ff6756f316d2/go.mod h1:xDxuJ0whA3d0I4mf/C4ppKHxXynQ+fxnkmQH0vTHnuk= -sigs.k8s.io/apiserver-network-proxy/konnectivity-client v0.34.0 h1:hSfpvjjTQXQY2Fol2CS0QHMNs/WI1MOSGzCm1KhM5ec= -sigs.k8s.io/apiserver-network-proxy/konnectivity-client v0.34.0/go.mod h1:Ve9uj1L+deCXFrPOk1LpFXqTg7LCFzFso6PA48q/XZw= -sigs.k8s.io/controller-runtime v0.24.1 h1:miPEwrmirImAvgME1L9qebGHrOnGJoVmVdtOU9fRfo4= -sigs.k8s.io/controller-runtime v0.24.1/go.mod h1:vFkfY5fGt5xAC/sKb8IBFKgWPNKG9OUG29dR8Y2wImw= +k8s.io/kube-openapi v0.0.0-20260821135717-be32def86098 h1:z5+pcu1jTyKK5mNTe2/+x+U6Uuv9jRVOJQLaBJJMpeI= +k8s.io/kube-openapi v0.0.0-20260821135717-be32def86098/go.mod h1:0/mqHCVhlumdJ3BhCfnjSZQE037nAhNodh1/hK0T8/I= +k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3 h1:jVkFFVfXdXP74B/zbO3hM3hpSFD0xvhQ5U686DPurkE= +k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3/go.mod h1:M2s5JB1lIYP3jzZdorPLHXIPJzt9vv2muW5a6L9DtNM= +sigs.k8s.io/apiserver-network-proxy/konnectivity-client v0.36.0 h1:/YpDJ4vReG7ZmzSpBGxduXgywWkJU9zHubgJG03MT+Y= +sigs.k8s.io/apiserver-network-proxy/konnectivity-client v0.36.0/go.mod h1:tJo1aepTXyR+8Xs3sUsGBDk4Ub2AM5dPAPKJx0mpm5c= +sigs.k8s.io/controller-runtime v0.25.0 h1:44KgRUPew331KSJpNu8zJow3iTR5W0p/SfrHdw3lV40= +sigs.k8s.io/controller-runtime v0.25.0/go.mod h1:4QqLdT6z/L6Olj8JJCtvztid4/fnIiYsfaTFScegctc= sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 h1:IpInykpT6ceI+QxKBbEflcR5EXP7sU1kvOlxwZh5txg= sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730/go.mod h1:mdzfpAEoE6DHQEN0uh9ZbOCuHbLK5wOm7dK4ctXE9Tg= sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= -sigs.k8s.io/structured-merge-diff/v6 v6.4.0 h1:qmp2e3ZfFi1/jJbDGpD4mt3wyp6PE1NfKHCYLqgNQJo= -sigs.k8s.io/structured-merge-diff/v6 v6.4.0/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.4.2 h1:qdOxHwrl2Kaag1aQEarlYcOA9vSyGCp3CIki3aW8c4Q= +sigs.k8s.io/structured-merge-diff/v6 v6.4.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/pkg/client/client_venconn_test.go b/pkg/client/client_venconn_test.go index 65645adf..113d13f0 100644 --- a/pkg/client/client_venconn_test.go +++ b/pkg/client/client_venconn_test.go @@ -99,6 +99,61 @@ func TestVenConnClient_PostDataReadingsWithOptions(t *testing.T) { `), expectReadyCondMsg: "Generated a new token", })) + t.Run("ngts with workspaceID", run_TestVenConnClient_PostDataReadingsWithOptions(ctx, restconf, kclient, testcase{ + given: testutil.Undent(` + apiVersion: jetstack.io/v1alpha1 + kind: VenafiConnection + metadata: + name: venafi-components + namespace: TEST_NAMESPACE + spec: + ngts: + url: FAKE_VENAFI_CLOUD_URL + workspaceID: "1000" + jwt: + - secret: + name: jwt + fields: [jwt] + allowReferencesFrom: + matchExpressions: + - {key: kubernetes.io/metadata.name, operator: In, values: [venafi]} + --- + apiVersion: v1 + kind: Secret + metadata: + name: jwt + namespace: TEST_NAMESPACE + stringData: + jwt: FAKE_JWT + --- + apiVersion: rbac.authorization.k8s.io/v1 + kind: Role + metadata: + name: venafi-connection-jwt-reader + namespace: TEST_NAMESPACE + rules: + - apiGroups: [""] + resources: ["secrets"] + verbs: ["get"] + resourceNames: ["jwt"] + --- + apiVersion: rbac.authorization.k8s.io/v1 + kind: RoleBinding + metadata: + name: venafi-connection-jwt-reader + namespace: TEST_NAMESPACE + roleRef: + apiGroup: rbac.authorization.k8s.io + kind: Role + name: venafi-connection-jwt-reader + subjects: + - kind: ServiceAccount + name: venafi-connection + namespace: venafi + `), + expectReadyCondMsg: "Generated a new token", + expectWorkspaceID: "1000", + })) t.Run("error when the apiKey field is used", run_TestVenConnClient_PostDataReadingsWithOptions(ctx, restconf, kclient, testcase{ // Why isn't it possible to use the 'apiKey' field? Although the // Kubernetes Discovery endpoint works with an API key, we have decided @@ -279,6 +334,7 @@ type testcase struct { given string expectErr string expectReadyCondMsg string + expectWorkspaceID string // On the NGTS token request. } // All tests share the same envtest (i.e., the same apiserver and etcd process), @@ -291,6 +347,10 @@ func run_TestVenConnClient_PostDataReadingsWithOptions(ctx context.Context, rest fakeVenafiCloud, certCloud, fakeVenafiAssert := testutil.FakeVenafiCloud(t) fakeTPP, certTPP := testutil.FakeTPP(t) fakeVenafiAssert(func(t testing.TB, r *http.Request) { + if r.URL.Path == "/v1/oauth/v2.0/token" { + assert.Equal(t, test.expectWorkspaceID, r.URL.Query().Get("workspace_id"), "workspace_id query parameter on the NGTS token request") + return + } if r.URL.Path == "/v1/useraccounts" { return // We only care about /v1/tlspk/upload/clusterdata. } diff --git a/pkg/testutil/envtest.go b/pkg/testutil/envtest.go index e022918b..4b715a88 100644 --- a/pkg/testutil/envtest.go +++ b/pkg/testutil/envtest.go @@ -198,7 +198,7 @@ func FakeVenafiCloud(t *testing.T) (_ *httptest.Server, _ *x509.Certificate, set if r.URL.Path == "/v1/oauth2/v2.0/756db001-280e-11ee-84fb-991f3177e2d0/token" { _, _ = w.Write([]byte(`{"access_token":"VALID_ACCESS_TOKEN","expires_in":900,"token_type":"bearer"}`)) return - } else if r.URL.Path == "/v1/oauth/token/serviceaccount" { + } else if r.URL.Path == "/v1/oauth/token/serviceaccount" || r.URL.Path == "/v1/oauth/v2.0/token" { _, _ = w.Write([]byte(`{"access_token":"VALID_ACCESS_TOKEN","expires_in":900,"token_type":"bearer"}`)) return }