eball
3095530d0d
opa: add untrusted image policy ( #2135 )
...
* feat(opa): add untrusted image check and update webhook configuration
* fix: add separator before untrusted pod check ConfigMap
* fix: remove specific image checks from untrusted pod validation
* fix: remove specific image checks from untrusted pod validation
* feat: add priority class and node affinity for OPA deployment
2025-12-05 20:20:03 +08:00
eball
7f27a03e84
opa: ignore validating opa pod itself ( #2118 )
...
* opa: ignore validating opa pod itself
* opa: add uid to response in decision logic
* opa: add apiVersion and kind to admission review response
2025-11-27 16:19:56 +08:00
eball
5c668d622e
infisical: move namespace to os-protected ( #1878 )
...
* infisical: move namespace to os-protected
* fix: lint error
* fix: add namespace os-protected
* fix: middleware request user
* Update tapr-sidecar image version to 0.1.14
2025-09-27 01:04:11 +08:00
eball
bb23e4008b
systemserver: create non-resource-url role privileges ( #1775 )
2025-09-02 00:23:22 +08:00
eball
3dbb633fda
system-server: refactor service provider based on RBAC ( #1736 )
...
* system-server: refactor service provider based on RBAC
* refactor: add files provider
* fix: numeric user name
* feat: provider and permission define
* refactor: backend service provider and permission
* refactor: change system frontend upstream to RBAC proxy
* revert: authelia-backend-svc
* fix: app-service entrance url api
* fix: market backend auth
2025-08-28 00:54:54 +08:00
dkeven
8180024d6d
fix(upgrade): split olares version update and upgrade of settings chart ( #1647 )
...
* fix(upgrade): split olares version update and upgrade of settings chart
* feat: upgrade l4-proxy image to v0.3.2
* fix: update appservice tag
---------
Co-authored-by: hys <hysyeah@gmail.com >
2025-07-30 20:04:46 +08:00
eball
daacba2fa4
cli,bfl,app-service: new namespace structure ( #1443 )
...
* refactor: os-system namespace in yaml
* refactor: new namespace structure
* Update system-frontend.yaml
* Update lldap-deployment.yaml
* refactor: bump system server version
* fix: bfl and gpu scheduler
* fix: kubesphere,studio-server image
* tapr: bump components version
* chore(ks_server): os-system namespace split
* backup-server: bump components version
* fix: remove nats-box
* fix: restore backup svc name
* files: bump components version
* fix: replace backup deployment name
* fix: change lldap and sys-event namespace
* refactor(gpu): update hami to use gpu-scheduler in os-gpu
* fix: sign cert for otel
* fix: template bug
* fix: template bug
* fix: missing namespace
* fix: namespace label and network policy bug
* fix: service namespace
---------
Co-authored-by: Peng Peng <billpengpeng@gmail.com >
Co-authored-by: hys <hysyeah@gmail.com >
Co-authored-by: yyh <24493052+yongheng2016@users.noreply.github.com >
Co-authored-by: aby913 <aby913@163.com >
Co-authored-by: dkeven <dkvvven@gmail.com >
2025-06-16 23:12:57 +08:00
Peng Peng
79372a32af
feat: Merge the code currently scattered across the beclab and Above-os organizations into the https://github.com/beclab/Olares repository. ( #1325 )
...
* feat: refactor
* refactor apps folder
* feat: add vendor folder
* refactor: package scripts
---------
Co-authored-by: eball <liuy102@hotmail.com >
2025-05-21 21:43:35 +08:00