wmantly
21333de814
fix(setup): export CFG_CREATE_ALL_HTTP default and add fail-safe parameter expansion v1.35.2
Lint / Shellcheck setup.sh (push) Failing after 9s
Lint / Syntax check bootstrap.js (push) Successful in 12s
2026-08-03 14:58:39 -04:00
wmantly
b3bdebe1c9
Merge pull request #144 from theta42/release/v1.35.1
...
CI/CD / build-theta-agent (push) Successful in 44s
CI/CD / docker-push (push) Failing after 16s
release(theta-suite): v1.35.1
v1.35.1
2026-08-03 14:02:55 -04:00
wmantly
e6b318e28e
release(theta-suite): v1.35.1 - Submodule updates, Directory, Conf layout & Jump host target filter
Lint / Shellcheck setup.sh (push) Failing after 9s
Lint / Syntax check bootstrap.js (push) Successful in 14s
2026-08-03 14:02:13 -04:00
wmantly
4d0b7f555e
Merge pull request #143 from theta42/feature/v1.35.0-final-roll-up
...
CI/CD / build-theta-agent (push) Successful in 45s
CI/CD / docker-push (push) Failing after 18s
release: v1.35.0 final roll-up
v1.35.0
2026-08-03 02:42:24 -04:00
wmantly
67b511f8d7
release: v1.35.0 - final roll up (sso v1.20.0, proxy v1.14.3, jump-host v1.17.1, theta-agent v1.2.0)
2026-08-03 02:41:57 -04:00
wmantly
b8a8be9697
Merge pull request #142 from theta42/feature/v1.35.0-theta-suite-stack-update
...
release: v1.35.0 theta-suite stack roll-up
2026-08-03 02:22:39 -04:00
wmantly
cd9c81cd92
release: v1.35.0 - roll up submodules (sso v1.20.0, proxy v1.14.3, jump-host v1.17.1, theta-agent v1.2.0) and setup fixes
2026-08-03 02:22:10 -04:00
wmantly
c8c04440db
Merge pull request #141 from theta42/release/v1.35.0-update
...
Release v1.35.0 - Bump sso-manager-node to v1.19.6
2026-08-02 23:03:49 -04:00
wmantly
d53bdefc2a
chore: Bump sso-manager-node to v1.19.6
...
Lint / Shellcheck setup.sh (push) Failing after 7s
Lint / Syntax check bootstrap.js (push) Successful in 14s
### Changed
- sso-manager-node: v1.18.0-26-gef2207e → v1.19.6 (4945dec)
### sso-manager-node v1.19.6 highlights
- Fixed navbar auth (Catalog/Vault now require login)
- Added docs/directory.md
- SMTP moved to UI-only configuration
- Added test email/SMS API endpoints
- Added non-interactive theta-agent config variables
Co-Authored-By: Claude <noreply@anthropic.com >
2026-08-02 22:55:30 -04:00
wmantly
542e5fd33f
chore: Release v1.35.0 - Non-interactive theta-agent config
...
Lint / Shellcheck setup.sh (push) Failing after 9s
Lint / Syntax check bootstrap.js (push) Successful in 12s
### Added
- Non-interactive theta-agent configuration via setup.env variables
### Changed
- setup.sh: Made theta-agent setup fully non-interactive
Co-Authored-By: Claude <noreply@anthropic.com >
2026-08-02 22:34:45 -04:00
wmantly
848f35fc5e
chore: Add theta-agent configuration variables to setup.env
...
### Changed
- **setup.sh**: Made theta-agent installation and configuration non-interactive,
controlled by CFG_THETA_AGENT_* environment variables.
- **setup.env.example**: Added documentation for:
- CFG_THETA_AGENT_ENABLE (default: 1)
- CFG_THETA_AGENT_LDAP_AUTH (default: 1)
- CFG_THETA_AGENT_FULL_CONTROL (default: 1)
All options default to enabled for backwards compatibility.
Co-Authored-By: Claude <noreply@anthropic.com >
2026-08-02 22:23:29 -04:00
wmantly
1d14fcee19
feat: install theta-agent on host and add CFG_CREATE_ALL_HTTP option ( #139 )
...
CI/CD / build-theta-agent (push) Successful in 39s
CI/CD / docker-push (push) Failing after 15s
* feat: install theta-agent on host and add CFG_CREATE_ALL_HTTP option
* docs: update changelog for 1.34.5
v1.34.5
2026-08-02 20:04:44 -04:00
wmantly
30609de3e8
chore: release v1.34.4 (update sso-manager-node submodule for vault fix) ( #138 )
CI/CD / build-theta-agent (push) Successful in 41s
CI/CD / docker-push (push) Failing after 16s
v1.34.4
2026-08-02 19:48:54 -04:00
wmantly
925ac027a6
Merge pull request #137 from theta42/release-v1.34.3
...
CI/CD / build-theta-agent (push) Successful in 41s
CI/CD / docker-push (push) Failing after 16s
chore: release v1.34.3
v1.34.3
2026-08-02 19:09:51 -04:00
wmantly
3b769cf24a
chore: release v1.34.3 (updates submodules, docs, bootstrap)
Lint / Shellcheck setup.sh (push) Failing after 9s
Lint / Syntax check bootstrap.js (push) Successful in 13s
2026-08-02 19:08:14 -04:00
wmantly
2785b861b3
Merge pull request #136 from theta42/update-submodules-2
...
CI/CD / build-theta-agent (push) Successful in 42s
CI/CD / docker-push (push) Failing after 15s
chore: update submodules to v1.19.4 and v1.14.2
v1.34.2
2026-08-02 14:12:02 -04:00
wmantly
c216ddd4e8
chore: update submodules to v1.19.4 and v1.14.2
2026-08-02 14:11:11 -04:00
wmantly
9c3cbb0ec2
Merge pull request #135 from theta42/update-submodules
...
CI/CD / build-theta-agent (push) Successful in 45s
CI/CD / docker-push (push) Failing after 16s
chore: update submodules
v1.34.1
2026-08-02 13:25:20 -04:00
wmantly
f44c075ede
chore: update sso-manager-node submodule
2026-08-02 13:24:14 -04:00
wmantly
ac9f672bae
Merge pull request #134 from theta42/fix/setup-echo-and-unbound
...
fix: setup.sh output bugs
2026-08-02 13:21:31 -04:00
wmantly
43b8307e54
docs: note docker compose v1 incompatibility
2026-08-02 13:13:50 -04:00
wmantly
9541c47470
fix: resolve jump-host naming bug and setup.sh secrets list bug
2026-08-02 12:56:55 -04:00
wmantly
a40326778e
fix: setup.sh color escape and unbound variable
2026-08-02 12:26:19 -04:00
wmantly
68a0ce4d12
Merge pull request #133 from theta42/chore/release-v1.34.0
...
CI/CD / build-theta-agent (push) Successful in 46s
CI/CD / docker-push (push) Failing after 19s
chore: release v1.34.0
v1.34.0
2026-08-02 12:14:18 -04:00
wmantly
3cb5540b2d
docs: release v1.34.0
Lint / Shellcheck setup.sh (push) Failing after 9s
Lint / Syntax check bootstrap.js (push) Successful in 13s
2026-08-02 12:13:24 -04:00
wmantly
4d745a9c1d
Merge pull request #132 from theta42/fix/setup-redis-snapshot
...
fix: prevent pipefail abort when redis-cli fails on restarting container
2026-08-02 12:09:50 -04:00
wmantly
36b39dfcc7
fix: prevent pipefail abort when redis-cli fails on restarting container
2026-08-02 11:59:34 -04:00
wmantly
06a4081a50
Merge pull request #131 from theta42/release-pki
...
v1.9.0: PKI Certificates & Theta Agent C2
2026-08-02 11:37:49 -04:00
wmantly
2f793206ed
chore: remove redundant submodule unit test jobs
2026-08-02 11:35:23 -04:00
wmantly
f7e9c20f72
fix: ci submodule checkout and bump sso-manager-node
2026-08-02 11:24:45 -04:00
wmantly
5ee486e808
chore: update submodules for PKI cert and agent C2 releases
2026-08-02 01:54:54 -04:00
wmantly
475ae2c893
docs: remove all standalone deployment documentation
2026-08-02 00:51:25 -04:00
wmantly
2eb5bf5daa
Merge pull request #130 from theta42/release-v1.33.0
...
Release v1.33.0
2026-08-02 00:39:29 -04:00
wmantly
35c8a51182
chore: bump submodules for OpenBao secret integration
Lint / Shellcheck setup.sh (push) Failing after 9s
Lint / Syntax check bootstrap.js (push) Successful in 12s
CI/CD / test-sso-manager (push) Failing after 8s
CI/CD / test-jump-host (push) Failing after 8s
CI/CD / test-proxy (push) Failing after 7s
CI/CD / build-telemetry-agent (push) Failing after 8s
CI/CD / docker-push (push) Has been skipped
v1.33.0
2026-08-02 00:38:49 -04:00
wmantly
f3b951b780
chore: release v1.31.0
CI/CD / test-sso-manager (push) Failing after 9s
CI/CD / test-jump-host (push) Failing after 7s
CI/CD / test-proxy (push) Failing after 8s
CI/CD / build-telemetry-agent (push) Failing after 8s
CI/CD / docker-push (push) Has been skipped
v1.32.0
2026-08-02 00:16:27 -04:00
wmantly
8f5ce71bda
feat: Add CI/CD workflow, update docs, update submodules
2026-08-02 00:16:27 -04:00
wmantly
6de31aa5e0
Merge pull request #129 from theta42/release-v1.31.1
...
release v1.31.1: sso v1.17.2 + /vault policy fix (setup.sh)
v1.31.1
2026-08-01 22:53:37 -04:00
wmantly
6c02e6c63e
release: v1.31.1 — sso v1.17.2 + /vault policy fix (setup.sh)
...
- bump sso-manager-node submodule gitlink v1.17.1 -> v1.17.2
(post-deploy fixes: auto-slug plugins, schedule dropdown, /profile
rendering, plugin-edit persistence, nmap in image, SMS/TOS on /conf,
sso-side /vault policy grants)
- setup.sh: add sso-admin list grant on secret/metadata (KV mount root)
so the /vault secrets list no longer 403s for admins
- setup.sh: ensure_policy now always (re)writes the policy so policy
edits apply on a re-run instead of stranding the old HCL
- CHANGELOG embeds the full sso v1.17.2 changelog
Co-Authored-By: Claude <noreply@anthropic.com >
2026-08-01 22:52:50 -04:00
wmantly
e2e8143880
Merge pull request #128 from theta42/release-v1.31.0
...
v1.31.0: roll up submodules to latest (sso v1.17.1 + ldap-client v1.23.0)
v1.31.0
2026-08-01 21:26:55 -04:00
wmantly
aa01a5cc07
release: bump submodules to latest tags (v1.31.0)
...
sso-manager-node v1.16.1 -> v1.17.1 (plugin system v1.17.0 + /conf secret
masking v1.17.1). ldap-client v1.1.1 -> v1.23.0 (CHANGELOG-only, no code
change). proxy v1.13.1 + jump-host v1.14.1 already latest, unchanged.
Changelog embeds the full sso v1.17.0 + v1.17.1 release notes.
Co-Authored-By: Claude <noreply@anthropic.com >
2026-08-01 21:26:13 -04:00
wmantly
1185bb90b8
Merge pull request #127 from theta42/feature/plugin-secrets-policy
...
v1.30.1: grant sso-broker OpenBao access to secret/plugins/* (plugin-system prerequisite)
v1.30.1
2026-08-01 20:50:20 -04:00
wmantly
403e66556c
feat: grant sso-broker OpenBao access to secret/plugins/* (v1.30.1)
...
Prerequisite for the SSO Manager plugin system (shipped in sso-manager-node
v1.17.0). Adds secret/data/plugins/* (CRUD+list) + secret/metadata/plugins/*
(list/read/delete) to the sso-broker policy HCL so the SSO can store per-instance
plugin secrets in OpenBao instead of sso-secrets.js. ensure_policy is idempotent,
so re-running ./setup.sh grants the existing SSO_VAULT_TOKEN live.
Docs: secrets.md (Plugin secrets section + policy row), architecture.md.
Co-Authored-By: Claude <noreply@anthropic.com >
2026-08-01 20:33:21 -04:00
wmantly
3287777b9b
v1.30.0: rename theta-env -> theta-suite + docs rewrite + sso v1.16.1 ( #126 )
...
Rename the project to theta-suite (it is now an integrated suite of four
apps around a shared OpenBao secrets store, not a two-project env).
- theta-env -> theta-suite across the superproject: _config.yml (title +
baseurl /theta-suite + repo URLs), README, setup.sh (incl. the
THETA_SUITE_REEXECED self-update sentinel), docker-compose.yml,
bootstrap.js, lint.yml, config.example/*, docs/robots.txt, all docs,
this changelog.
- architecture.md rewritten: real 4-service + ldap-client topology, OpenBao
secrets section, OpenBao-aware config flow; removed "two containers" /
"three repos" / LDAP-"legacy" framing.
- index.md: integrated-suite framing + secrets/OpenBao + ldap-client.
- standalone.md + README: standalone reframed as advanced opt-in.
- sso-manager-node submodule -> v1.16.1 (401 fix on /conf and /vault).
Co-authored-by: Claude <noreply@anthropic.com >
v1.30.0
2026-08-01 18:46:10 -04:00
wmantly
5ef3e3fa8c
v1.29.0: jump host is core + fix fresh-install setup.sh abort ( #125 )
...
Two fresh-install fixes and promote the SSH jump host from opt-in to core.
setup.sh: fix silent abort after "Minting per-app OpenBao tokens". env_get's
grep|cut pipeline returns non-zero under set -euo pipefail when .env exists
(created by the root VAULT_TOKEN env_upsert) but an app-token key is absent
(the normal first-run state); the unguarded existing assignment from env_get
then tripped set -e and killed the script before minting any token. env_get
now always returns 0 (|| true). Reproduced + verified under the exact condition.
jump host is no longer optional:
- docker-compose.yml: drop profiles jump-host from the jump-host service
(always started); rename the opt-in test fixture profile jump-host to ldap-test.
- setup.sh: SUBMODULES always includes jump-host; build/start/register/summary
no longer guarded by JUMP_ENABLED; drop the COMPOSE_PROFILES export.
- bootstrap.js: jump provisioning + directory record run unconditionally.
- setup.env.example/docs: drop optional/CFG_JUMP_HOST_ENABLED wording.
Co-authored-by: Claude <noreply@anthropic.com >
v1.29.0
2026-08-01 13:48:28 -04:00
wmantly
a1ea2d458e
Merge pull request #124 from theta42/feature/openbao-secrets
...
v1.28.0: OpenBao as the central secrets store for the stack
v1.28.0
2026-08-01 12:55:32 -04:00
wmantly
f7df04c2f0
v1.28.0: OpenBao as the central secrets store for the stack
...
theta-env orchestration:
- setup.sh: idempotent OpenBao policies (sso-broker, sso-admin, proxy,
jump-host), sso-broker token role (allowed_policies_glob user-*/app-*,
24h), mint scoped SSO/PROXY/JUMP_VAULT_TOKEN (orphan, .env reuse),
seed_app_conf seeds secret/{sso-manager,proxy,jump-host}/conf. Bootstrap
exec passes root VAULT_ADDR/VAULT_TOKEN for seeding. Root token never
reaches a service container. shellcheck -S warning clean.
- docker-compose.yml: VAULT_ADDR + VAULT_TOKEN env for sso/proxy/jump;
proxy/jump depends_on openbao service_started.
- bootstrap/bootstrap.js: baoPut() writes generated OAuth creds to
secret/proxy/conf + secret/jump-host/conf (OpenBao authoritative).
- docs/secrets.md (new): full secrets architecture. README + nav updated.
Submodule bumps:
- sso-manager-node -> v1.16.0 (OpenBao broker + vault UI + remediation)
- proxy -> v1.13.1 (via v1.13.0: OpenBao boot)
- jump-host -> v1.14.1 (via v1.14.0: OpenBao boot)
- ldap-client unchanged
Co-Authored-By: Claude <noreply@anthropic.com >
2026-08-01 12:54:56 -04:00
wmantly
3277972037
Merge pull request #123 from theta42/release-v1.27.2
...
Release v1.27.2
v1.27.2
2026-08-01 11:14:39 -04:00
wmantly
0c7593cc59
Bump proxy to v1.12.1
2026-08-01 11:13:51 -04:00
wmantly
ec625f7cb0
Merge pull request #122 from theta42/release-v1.27.1
...
Release v1.27.1
v1.27.1
2026-08-01 10:27:38 -04:00
wmantly
2a6c7775c9
Bump sso-manager-node to v1.15.2, add integration tests
2026-08-01 10:26:59 -04:00