Merge 2.6.2 to main - #78
Merged
Merged
Conversation
…hcheck Interval, Updated Service Account Token Lifecycle (#70) * feat: Add volume and volume mount for service token * chore: fix sources and add changelog Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> * feat(enrollment): make certificateAuthorityLogicalName be optional when using enrollment patterns Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> * updated error messaging on csr enrollment Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> * Update generated docs * chore: update docs + add e2e test for optional CA Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> * Update generated docs * feat(healthcheck): bump default healthcheck interval from 1m to 10m Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> * chore(deps): bump go version to 1.26 Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> * Update generated docs * chore: address copilot feedback. update linter version Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> * Update generated docs * chore(ci): bump controller tools version Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> * chore(docs): document new Helm chart values for serviceAccount Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> --------- Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> Co-authored-by: Sven Rajala <sven.rajala@keyfactor.com> Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
#74) * command-cert-manager-issuer 2.6.0: Optional CA, Updated Default Healthcheck Interval, Updated Service Account Token Lifecycle (#70) (#71) * feat: Add volume and volume mount for service token * chore: fix sources and add changelog * feat(enrollment): make certificateAuthorityLogicalName be optional when using enrollment patterns * updated error messaging on csr enrollment * Update generated docs * chore: update docs + add e2e test for optional CA * Update generated docs * feat(healthcheck): bump default healthcheck interval from 1m to 10m * chore(deps): bump go version to 1.26 * Update generated docs * chore: address copilot feedback. update linter version * Update generated docs * chore(ci): bump controller tools version * chore(docs): document new Helm chart values for serviceAccount --------- Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> Co-authored-by: Matthew H. Irby <irby@users.noreply.github.com> Co-authored-by: Sven Rajala <sven.rajala@keyfactor.com> Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io> * Add priorityClassName * remove quote * Update README * chore(AB#89226): add docs on how to contribute to the project Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> * chore: update CHANGELOG Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --------- Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> Co-authored-by: Morgan Gangwere <470584+indrora@users.noreply.github.com> Co-authored-by: Sven Rajala <sven.rajala@keyfactor.com> Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io> Co-authored-by: slammajamma28 <slammajamma28@gmail.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
…tion (#77) * Merge 2.6.1 to main (#75) * command-cert-manager-issuer 2.6.0: Optional CA, Updated Default Healthcheck Interval, Updated Service Account Token Lifecycle (#70) * feat: Add volume and volume mount for service token * chore: fix sources and add changelog Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> * feat(enrollment): make certificateAuthorityLogicalName be optional when using enrollment patterns Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> * updated error messaging on csr enrollment Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> * Update generated docs * chore: update docs + add e2e test for optional CA Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> * Update generated docs * feat(healthcheck): bump default healthcheck interval from 1m to 10m Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> * chore(deps): bump go version to 1.26 Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> * Update generated docs * chore: address copilot feedback. update linter version Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> * Update generated docs * chore(ci): bump controller tools version Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> * chore(docs): document new Helm chart values for serviceAccount Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> --------- Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> Co-authored-by: Sven Rajala <sven.rajala@keyfactor.com> Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io> * command-cert-manger-issuer v2.6.1: Add priorityClassName to Deployment (#74) * command-cert-manager-issuer 2.6.0: Optional CA, Updated Default Healthcheck Interval, Updated Service Account Token Lifecycle (#70) (#71) * feat: Add volume and volume mount for service token * chore: fix sources and add changelog * feat(enrollment): make certificateAuthorityLogicalName be optional when using enrollment patterns * updated error messaging on csr enrollment * Update generated docs * chore: update docs + add e2e test for optional CA * Update generated docs * feat(healthcheck): bump default healthcheck interval from 1m to 10m * chore(deps): bump go version to 1.26 * Update generated docs * chore: address copilot feedback. update linter version * Update generated docs * chore(ci): bump controller tools version * chore(docs): document new Helm chart values for serviceAccount --------- Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> Co-authored-by: Matthew H. Irby <irby@users.noreply.github.com> Co-authored-by: Sven Rajala <sven.rajala@keyfactor.com> Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io> * Add priorityClassName * remove quote * Update README * chore(AB#89226): add docs on how to contribute to the project Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> * chore: update CHANGELOG Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --------- Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> Co-authored-by: Morgan Gangwere <470584+indrora@users.noreply.github.com> Co-authored-by: Sven Rajala <sven.rajala@keyfactor.com> Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io> Co-authored-by: slammajamma28 <slammajamma28@gmail.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --------- Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> Co-authored-by: Matthew H. Irby <irby@users.noreply.github.com> Co-authored-by: Sven Rajala <sven.rajala@keyfactor.com> Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io> Co-authored-by: slammajamma28 <slammajamma28@gmail.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * temp: log expiration of access token generated by ambient credentials Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> * fix(oauth): add external token source to abstract ambient token credential generation Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> * chore: bump crypto depenedency. address copilot feedback Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> * chore(deps): bump auth library to v1.5.1 Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> * chore(docs): update CHANGELOG Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> --------- Signed-off-by: Matthew H. Irby <matt.irby@keyfactor.com> Co-authored-by: Morgan Gangwere <470584+indrora@users.noreply.github.com> Co-authored-by: Sven Rajala <sven.rajala@keyfactor.com> Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io> Co-authored-by: slammajamma28 <slammajamma28@gmail.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
GCP ambient token refreshes use an unbounded context, allowing stalled token requests to block cached clients indefinitely.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
Merges v2.6.2 changes into main, primarily adding automatic ambient credential refresh and Helm priority class configuration.
Changes:
- Replaces static ambient tokens with refreshing Azure/GCP OAuth token sources.
- Upgrades authentication and SDK dependencies.
- Adds
priorityClassNameHelm support and updates documentation.
| File | Description |
|---|---|
internal/command/command.go |
Configures external ambient token sources. |
internal/command/client.go |
Implements Azure and GCP token refresh sources. |
go.mod |
Updates dependencies. |
go.sum |
Updates dependency checksums. |
deploy/charts/command-cert-manager-issuer/values.yaml |
Adds priority class value. |
deploy/charts/command-cert-manager-issuer/templates/deployment.yaml |
Renders priority class configuration. |
deploy/charts/command-cert-manager-issuer/README.md |
Documents chart settings. |
CONTRIBUTING.md |
Updates contribution and development guidance. |
CHANGELOG.md |
Records v2.6.1 and v2.6.2 changes. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
|
||
| // Use credentials to generate a JWT (requires a service account) | ||
| tokenSource, err := idtoken.NewTokenSource(ctx, aud, idtoken.WithCredentialsJSON(credentials.JSON)) | ||
| ts, err := idtoken.NewTokenSource(g.ctx, aud, idtoken.WithCredentialsJSON(creds.JSON)) |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Merge release-2.6 to main - Automated PR