wmantly
7284bcec7b
fix: setup.sh ldap.vars re-run abort + drop app_super_admin; roll up sso v1.26.1 (v1.36.1)
...
Lint / Syntax check bootstrap.js (push) Successful in 13s
Lint / Shellcheck setup.sh (push) Failing after 10s
- setup.sh: ldap.vars generation read CFG_* first-run vars (unset on re-run);
now reads real values from sso-secrets.js, so LDAP enrollment works on re-runs
- generated ldap_access_groups now references god_admin (app_super_admin gone)
- gitlink: sso-manager-node 8db00f0 (v1.26.1)
2026-08-04 19:32:35 -04:00
wmantly
a77aa8d2df
feat: seed god_admin + docker plugin, fix ldap-client enrollment, roll up sso v1.26.0 + theta-agent v1.3.0 (v1.36.0) ( #161 )
...
CI/CD / build-theta-agent (push) Successful in 44s
CI/CD / docker-push (push) Failing after 16s
- bootstrap: seed god_admin into the admin's groups; seed a docker-local discovery plugin
- setup.sh: generate ldap-client/ldap.vars from the stack config so LDAP enrollment works
- docs: GROUPS.md site-slug convention (verbatim, kind in resource slug)
- gitlinks: sso-manager-node 8a9de94 (v1.26.0), theta-agent 52379c2 (v1.3.0)
2026-08-04 19:10:32 -04:00
wmantly
0e78a9e282
Merge pull request #160 from theta42/release/v1.35.18
...
CI/CD / build-theta-agent (push) Successful in 41s
CI/CD / docker-push (push) Failing after 19s
chore: sync proxy/jump gitlinks (v1.35.18)
2026-08-04 16:54:41 -04:00
wmantly and Claude
59c5c66007
chore: sync proxy/jump gitlinks to version-tagged commits (v1.35.18)
...
proxy v1.33.0 + jump v1.18.0 had package.json synced to their tags; update the
gitlinks so a deploy reports matching versions.
Co-Authored-By: Claude <noreply@anthropic.com >
2026-08-04 16:53:38 -04:00
wmantly
ec426680c3
Merge pull request #159 from theta42/release/v1.35.17
...
CI/CD / docker-push (push) Failing after 17s
CI/CD / build-theta-agent (push) Successful in 47s
docs: group & permission model + sso group model (v1.35.17)
2026-08-04 16:49:11 -04:00
wmantly and Claude
6fae96d977
chore: bump sso-manager-node gitlink to v1.25.0
...
sso v1.25.0 shipped the group & permission model + the v1.24.0 batch (Agents →
Directory, plugin modal rework, Vault restyle). Update the gitlink for the release.
Co-Authored-By: Claude <noreply@anthropic.com >
2026-08-04 16:48:16 -04:00
wmantly and Claude
292b67c334
docs: group & permission model spec + link (v1.35.17)
...
Add docs/GROUPS.md — the canonical Group & Permission Model (schema, inheritance
resolver, Directory-only management, multi-site, host-side SSSD mapping, migration)
— link it from the docs index, and note sso v1.25.0 in the changelog.
Co-Authored-By: Claude <noreply@anthropic.com >
2026-08-04 15:04:30 -04:00
wmantly and Claude
72606bfc13
feat: seed theta-proxy + theta-jump as managed host resources (v1.35.16)
...
The bootstrap now creates theta-proxy and theta-jump as managed host-kind
resources in the Directory (matching the OAuth client identities), alongside
the existing stack host and its service entries, so a fresh install shows them
as first-class hosts.
Co-Authored-By: Claude <noreply@anthropic.com >
2026-08-04 13:27:28 -04:00
wmantly
c28e53e505
Merge pull request #158 from theta42/fix/theta-agent-text-file-busy-v1.35.15
...
CI/CD / build-theta-agent (push) Successful in 43s
CI/CD / docker-push (push) Failing after 17s
fix: stop theta-agent before overwriting binary (v1.35.15)
2026-08-04 00:34:43 -04:00
wmantly and Claude
7ae2472c62
fix: stop theta-agent before overwriting binary (v1.35.15)
...
cp into a running executable fails with 'Text file busy' on a re-install.
Stop the service before copying the prebuilt binary.
Co-Authored-By: Claude <noreply@anthropic.com >
2026-08-04 00:32:33 -04:00
wmantly
0c4abd82be
Merge pull request #157 from theta42/release/v1.35.14-token-lifecycle
...
CI/CD / build-theta-agent (push) Successful in 43s
CI/CD / docker-push (push) Failing after 17s
feat: OpenBao token lifecycle + bump sso to v1.23.0 (v1.35.14)
2026-08-04 00:25:16 -04:00
wmantly and Claude
c27e8c7867
feat: OpenBao token lifecycle + bump sso to v1.23.0 (v1.35.14)
...
- theta-svc token role (periodic 768h): SSO/PROXY/JUMP_VAULT_TOKEN now minted
through it; ensure_token renews periodic tokens on every setup.sh re-run and
detects/revokes/re-mints valid-but-non-periodic tokens from older installs.
- bao-renewer sidecar (docker-compose): renews the three service tokens every
12h while the stack runs.
- sso-app token role (periodic 768h) + sso-broker policy grants for
auth/token/create/sso-app and renew/revoke/lookup-accessor.
- docs/secrets.md rewritten around the new lifecycle.
- Bump sso-manager-node gitlink to v1.23.0 (real vault-403 fix + app-token
lifecycle).
Co-Authored-By: Claude <noreply@anthropic.com >
2026-08-04 00:21:51 -04:00
wmantly
9750413178
Merge pull request #156 from theta42/release/v1.35.13-agents-page
...
CI/CD / build-theta-agent (push) Successful in 44s
CI/CD / docker-push (push) Failing after 18s
feat: bump sso to v1.22.0 (Agents page + secure /api/agent) (v1.35.13)
2026-08-03 23:16:39 -04:00
wmantly
c1a9d8f059
feat: bump sso to v1.22.0 (Agents page + secure /api/agent) (v1.35.13)
2026-08-03 23:15:19 -04:00
wmantly
0edce57f80
Merge pull request #155 from theta42/fix/theta-agent-service-control-v1.35.12
...
CI/CD / build-theta-agent (push) Successful in 41s
CI/CD / docker-push (push) Failing after 18s
fix: stop writing invalid service_control:true for theta-agent (v1.35.12)
2026-08-03 23:06:39 -04:00
wmantly and Claude
49b868fedb
fix: stop writing invalid service_control:true for theta-agent (v1.35.12)
...
setup.sh's 'full control' edit set service_control: true, but that field is a
[]string allowlist, so theta-agent failed YAML decode and crash-looped. Remove
the invalid edit; leave the operator's allowlist (or [] default = deny all).
Co-Authored-By: Claude <noreply@anthropic.com >
2026-08-03 23:05:04 -04:00
wmantly
f9af81983b
Merge pull request #154 from theta42/fix/unseal-key-unbound-v1.35.11
...
CI/CD / build-theta-agent (push) Successful in 45s
CI/CD / docker-push (push) Failing after 16s
fix: UNSEAL_KEY unbound variable in setup.sh (v1.35.11)
2026-08-03 22:45:27 -04:00
wmantly
5ef2493e17
chore: changelog for v1.35.11
2026-08-03 22:44:03 -04:00
wmantly and Claude
8535372123
fix: guard UNSEAL_KEY with ${UNSEAL_KEY:-} in setup.sh (v1.35.11)
...
On a re-run where OpenBao is already unsealed, the unseal block is skipped and
UNSEAL_KEY is never set; line 778 then referenced it under set -u and aborted
with 'UNSEAL_KEY: unbound variable'. Guard with ${UNSEAL_KEY:-} so the
VAULT_UNSEAL_KEY upsert is simply skipped when there's no key this run.
Co-Authored-By: Claude <noreply@anthropic.com >
2026-08-03 22:43:51 -04:00
wmantly
ade9a41aed
Merge pull request #153 from theta42/release/v1.35.10-reset-openbao-theta-agent
...
CI/CD / build-theta-agent (push) Successful in 47s
CI/CD / docker-push (push) Failing after 16s
feat: --reset-openbao + fix theta-agent install; bump sso to v1.21.0 (v1.35.10)
2026-08-03 22:26:35 -04:00
wmantly and Claude
ce664f5cb9
feat: --reset-openbao + fix theta-agent install; bump sso to v1.21.0 (v1.35.10)
...
- Add --reset-openbao: full clean OpenBao reset (re-init store, flush the
Redis vault-token cache) to clear stale policies/tokens causing recurring
vault 403s.
- Fix theta-agent install: copy the prebuilt theta-agent-linux-amd64 from the
submodule instead of a broken go build; write config to /etc/theta42/agent.yml
(the path the agent reads), not /etc/theta/agent.yml.
- Bump sso-manager-node gitlink to v1.21.0 (shared secrets + durable vault 403 fix).
Co-Authored-By: Claude <noreply@anthropic.com >
2026-08-03 22:24:48 -04:00
wmantly
647f5b846c
Merge pull request #152 from theta42/fix/submodule-version-sync-v1.35.9
...
CI/CD / build-theta-agent (push) Successful in 42s
CI/CD / docker-push (push) Failing after 17s
fix: bump sso & proxy submodules to corrected version tags (v1.35.9)
2026-08-03 21:37:39 -04:00
wmantly and Claude
fe08c2f8c7
fix: bump sso & proxy submodules to corrected version tags (v1.35.9)
...
The v1.20.2 / v1.32.0 release tags were created but their package.json
versions lagged (1.20.1 / 1.14.3), so the deployed apps' update-check
banner falsely reported a newer version. Repoint the sso-manager-node and
proxy gitlinks to the corrected commits and release v1.35.9.
Co-Authored-By: Claude <noreply@anthropic.com >
2026-08-03 21:36:24 -04:00
wmantly
43c58e7ed5
Merge pull request #151 from theta42/fix/auto-reset-unseal-key-loss-v1.35.8
...
CI/CD / build-theta-agent (push) Successful in 44s
CI/CD / docker-push (push) Failing after 17s
fix(setup): auto-reset OpenBao volume and re-initialize if unseal key is lost v1.35.8
2026-08-03 15:44:22 -04:00
wmantly
13d8a979c7
fix(setup): auto-reset OpenBao volume and re-initialize if unseal key is lost v1.35.8
Lint / Shellcheck setup.sh (push) Failing after 9s
Lint / Syntax check bootstrap.js (push) Successful in 13s
2026-08-03 15:43:35 -04:00
wmantly
16cbe46793
Merge pull request #150 from theta42/fix/restore-bao-init-from-backup-v1.35.7
...
CI/CD / build-theta-agent (push) Successful in 41s
CI/CD / docker-push (push) Failing after 17s
fix(setup): auto-restore bao-init.json from backups if missing from config/ v1.35.7
2026-08-03 15:42:35 -04:00
wmantly
40a1e7f64e
fix(setup): auto-restore bao-init.json from backups if missing from config/ v1.35.7
Lint / Syntax check bootstrap.js (push) Successful in 14s
Lint / Shellcheck setup.sh (push) Failing after 10s
2026-08-03 15:42:01 -04:00
wmantly
45715b61ea
Merge pull request #149 from theta42/fix/env-get-function-order-v1.35.6
...
CI/CD / build-theta-agent (push) Successful in 44s
CI/CD / docker-push (push) Failing after 17s
fix(setup): move env_get helper function definition to top of setup.sh v1.35.6
2026-08-03 15:39:39 -04:00
wmantly
54ebb83bb1
fix(setup): move env_get helper function definition to top of setup.sh v1.35.6
Lint / Shellcheck setup.sh (push) Failing after 10s
Lint / Syntax check bootstrap.js (push) Successful in 14s
2026-08-03 15:39:05 -04:00
wmantly
a67d972217
Merge pull request #148 from theta42/fix/setup-openbao-unseal-fallback-v1.35.5
...
CI/CD / build-theta-agent (push) Successful in 42s
CI/CD / docker-push (push) Failing after 18s
fix(setup): fallback to .env VAULT_UNSEAL_KEY and VAULT_TOKEN if bao-init.json is missing v1.35.5
2026-08-03 15:36:46 -04:00
wmantly
875ea874b4
fix(setup): fallback to .env VAULT_UNSEAL_KEY and VAULT_TOKEN if bao-init.json is missing v1.35.5
Lint / Shellcheck setup.sh (push) Failing after 8s
Lint / Syntax check bootstrap.js (push) Successful in 12s
2026-08-03 15:36:22 -04:00
wmantly
119f21b821
Merge pull request #147 from theta42/bump/sso-v1.20.2-proxy-v1.32.0
...
CI/CD / build-theta-agent (push) Successful in 42s
CI/CD / docker-push (push) Failing after 18s
bump(deps): update sso-manager-node to v1.20.2 and proxy to v1.32.0
2026-08-03 15:31:29 -04:00
wmantly
80275c42e4
bump(deps): update sso-manager-node to v1.20.2 and proxy to v1.32.0
Lint / Shellcheck setup.sh (push) Failing after 9s
Lint / Syntax check bootstrap.js (push) Successful in 13s
2026-08-03 15:30:56 -04:00
wmantly
a30deae866
Merge pull request #146 from theta42/bump/theta-agent-v1.2.1
...
CI/CD / build-theta-agent (push) Successful in 44s
CI/CD / docker-push (push) Failing after 17s
bump(theta-agent): update to v1.2.1 for automatic SSSD installation
2026-08-03 15:02:56 -04:00
wmantly
dc9a7ff9c4
bump(theta-agent): update to v1.2.1 for automatic SSSD installation
Lint / Shellcheck setup.sh (push) Failing after 8s
Lint / Syntax check bootstrap.js (push) Successful in 13s
2026-08-03 15:02:14 -04:00
wmantly
7937d6cf92
Merge pull request #145 from theta42/fix/setup-unbound-var-v1.35.2
...
CI/CD / build-theta-agent (push) Successful in 45s
CI/CD / docker-push (push) Failing after 18s
fix(setup): export CFG_CREATE_ALL_HTTP default and add fail-safe parameter expansion v1.35.2
2026-08-03 14:59:07 -04:00
wmantly
21333de814
fix(setup): export CFG_CREATE_ALL_HTTP default and add fail-safe parameter expansion v1.35.2
Lint / Syntax check bootstrap.js (push) Successful in 12s
Lint / Shellcheck setup.sh (push) Failing after 9s
2026-08-03 14:58:39 -04:00
wmantly
b3bdebe1c9
Merge pull request #144 from theta42/release/v1.35.1
...
CI/CD / build-theta-agent (push) Successful in 44s
CI/CD / docker-push (push) Failing after 16s
release(theta-suite): v1.35.1
2026-08-03 14:02:55 -04:00
wmantly
e6b318e28e
release(theta-suite): v1.35.1 - Submodule updates, Directory, Conf layout & Jump host target filter
Lint / Shellcheck setup.sh (push) Failing after 9s
Lint / Syntax check bootstrap.js (push) Successful in 14s
2026-08-03 14:02:13 -04:00
wmantly
4d0b7f555e
Merge pull request #143 from theta42/feature/v1.35.0-final-roll-up
...
CI/CD / build-theta-agent (push) Successful in 45s
CI/CD / docker-push (push) Failing after 18s
release: v1.35.0 final roll-up
2026-08-03 02:42:24 -04:00
wmantly
67b511f8d7
release: v1.35.0 - final roll up (sso v1.20.0, proxy v1.14.3, jump-host v1.17.1, theta-agent v1.2.0)
2026-08-03 02:41:57 -04:00
wmantly
b8a8be9697
Merge pull request #142 from theta42/feature/v1.35.0-theta-suite-stack-update
...
release: v1.35.0 theta-suite stack roll-up
2026-08-03 02:22:39 -04:00
wmantly
cd9c81cd92
release: v1.35.0 - roll up submodules (sso v1.20.0, proxy v1.14.3, jump-host v1.17.1, theta-agent v1.2.0) and setup fixes
2026-08-03 02:22:10 -04:00
wmantly
c8c04440db
Merge pull request #141 from theta42/release/v1.35.0-update
...
Release v1.35.0 - Bump sso-manager-node to v1.19.6
2026-08-02 23:03:49 -04:00
wmantly and Claude
d53bdefc2a
chore: Bump sso-manager-node to v1.19.6
...
Lint / Shellcheck setup.sh (push) Failing after 7s
Lint / Syntax check bootstrap.js (push) Successful in 14s
### Changed
- sso-manager-node: v1.18.0-26-gef2207e → v1.19.6 (4945dec)
### sso-manager-node v1.19.6 highlights
- Fixed navbar auth (Catalog/Vault now require login)
- Added docs/directory.md
- SMTP moved to UI-only configuration
- Added test email/SMS API endpoints
- Added non-interactive theta-agent config variables
Co-Authored-By: Claude <noreply@anthropic.com >
2026-08-02 22:55:30 -04:00
wmantly and Claude
542e5fd33f
chore: Release v1.35.0 - Non-interactive theta-agent config
...
Lint / Shellcheck setup.sh (push) Failing after 9s
Lint / Syntax check bootstrap.js (push) Successful in 12s
### Added
- Non-interactive theta-agent configuration via setup.env variables
### Changed
- setup.sh: Made theta-agent setup fully non-interactive
Co-Authored-By: Claude <noreply@anthropic.com >
2026-08-02 22:34:45 -04:00
wmantly and Claude
848f35fc5e
chore: Add theta-agent configuration variables to setup.env
...
### Changed
- **setup.sh**: Made theta-agent installation and configuration non-interactive,
controlled by CFG_THETA_AGENT_* environment variables.
- **setup.env.example**: Added documentation for:
- CFG_THETA_AGENT_ENABLE (default: 1)
- CFG_THETA_AGENT_LDAP_AUTH (default: 1)
- CFG_THETA_AGENT_FULL_CONTROL (default: 1)
All options default to enabled for backwards compatibility.
Co-Authored-By: Claude <noreply@anthropic.com >
2026-08-02 22:23:29 -04:00
wmantly
1d14fcee19
feat: install theta-agent on host and add CFG_CREATE_ALL_HTTP option ( #139 )
...
CI/CD / build-theta-agent (push) Successful in 39s
CI/CD / docker-push (push) Failing after 15s
* feat: install theta-agent on host and add CFG_CREATE_ALL_HTTP option
* docs: update changelog for 1.34.5
2026-08-02 20:04:44 -04:00
wmantly
30609de3e8
chore: release v1.34.4 (update sso-manager-node submodule for vault fix) ( #138 )
CI/CD / build-theta-agent (push) Successful in 41s
CI/CD / docker-push (push) Failing after 16s
2026-08-02 19:48:54 -04:00
wmantly
925ac027a6
Merge pull request #137 from theta42/release-v1.34.3
...
CI/CD / build-theta-agent (push) Successful in 41s
CI/CD / docker-push (push) Failing after 16s
chore: release v1.34.3
2026-08-02 19:09:51 -04:00
wmantly
3b769cf24a
chore: release v1.34.3 (updates submodules, docs, bootstrap)
Lint / Shellcheck setup.sh (push) Failing after 9s
Lint / Syntax check bootstrap.js (push) Successful in 13s
2026-08-02 19:08:14 -04:00
wmantly
2785b861b3
Merge pull request #136 from theta42/update-submodules-2
...
CI/CD / build-theta-agent (push) Successful in 42s
CI/CD / docker-push (push) Failing after 15s
chore: update submodules to v1.19.4 and v1.14.2
2026-08-02 14:12:02 -04:00
wmantly
c216ddd4e8
chore: update submodules to v1.19.4 and v1.14.2
2026-08-02 14:11:11 -04:00
wmantly
9c3cbb0ec2
Merge pull request #135 from theta42/update-submodules
...
CI/CD / build-theta-agent (push) Successful in 45s
CI/CD / docker-push (push) Failing after 16s
chore: update submodules
2026-08-02 13:25:20 -04:00
wmantly
f44c075ede
chore: update sso-manager-node submodule
2026-08-02 13:24:14 -04:00
wmantly
ac9f672bae
Merge pull request #134 from theta42/fix/setup-echo-and-unbound
...
fix: setup.sh output bugs
2026-08-02 13:21:31 -04:00
wmantly
43b8307e54
docs: note docker compose v1 incompatibility
2026-08-02 13:13:50 -04:00
wmantly
9541c47470
fix: resolve jump-host naming bug and setup.sh secrets list bug
2026-08-02 12:56:55 -04:00
wmantly
a40326778e
fix: setup.sh color escape and unbound variable
2026-08-02 12:26:19 -04:00
wmantly
68a0ce4d12
Merge pull request #133 from theta42/chore/release-v1.34.0
...
CI/CD / build-theta-agent (push) Successful in 46s
CI/CD / docker-push (push) Failing after 19s
chore: release v1.34.0
2026-08-02 12:14:18 -04:00
wmantly
3cb5540b2d
docs: release v1.34.0
Lint / Shellcheck setup.sh (push) Failing after 9s
Lint / Syntax check bootstrap.js (push) Successful in 13s
2026-08-02 12:13:24 -04:00
wmantly
4d745a9c1d
Merge pull request #132 from theta42/fix/setup-redis-snapshot
...
fix: prevent pipefail abort when redis-cli fails on restarting container
2026-08-02 12:09:50 -04:00
wmantly
36b39dfcc7
fix: prevent pipefail abort when redis-cli fails on restarting container
2026-08-02 11:59:34 -04:00
wmantly
06a4081a50
Merge pull request #131 from theta42/release-pki
...
v1.9.0: PKI Certificates & Theta Agent C2
2026-08-02 11:37:49 -04:00
wmantly
2f793206ed
chore: remove redundant submodule unit test jobs
2026-08-02 11:35:23 -04:00
wmantly
f7e9c20f72
fix: ci submodule checkout and bump sso-manager-node
2026-08-02 11:24:45 -04:00
wmantly
5ee486e808
chore: update submodules for PKI cert and agent C2 releases
2026-08-02 01:54:54 -04:00
wmantly
475ae2c893
docs: remove all standalone deployment documentation
2026-08-02 00:51:25 -04:00
wmantly
2eb5bf5daa
Merge pull request #130 from theta42/release-v1.33.0
...
Release v1.33.0
2026-08-02 00:39:29 -04:00
wmantly
35c8a51182
chore: bump submodules for OpenBao secret integration
Lint / Shellcheck setup.sh (push) Failing after 9s
Lint / Syntax check bootstrap.js (push) Successful in 12s
CI/CD / test-sso-manager (push) Failing after 8s
CI/CD / test-jump-host (push) Failing after 8s
CI/CD / test-proxy (push) Failing after 7s
CI/CD / build-telemetry-agent (push) Failing after 8s
CI/CD / docker-push (push) Has been skipped
2026-08-02 00:38:49 -04:00
wmantly
f3b951b780
chore: release v1.31.0
CI/CD / test-sso-manager (push) Failing after 9s
CI/CD / test-jump-host (push) Failing after 7s
CI/CD / test-proxy (push) Failing after 8s
CI/CD / build-telemetry-agent (push) Failing after 8s
CI/CD / docker-push (push) Has been skipped
2026-08-02 00:16:27 -04:00
wmantly
8f5ce71bda
feat: Add CI/CD workflow, update docs, update submodules
2026-08-02 00:16:27 -04:00
wmantly
6de31aa5e0
Merge pull request #129 from theta42/release-v1.31.1
...
release v1.31.1: sso v1.17.2 + /vault policy fix (setup.sh)
2026-08-01 22:53:37 -04:00
wmantly and Claude
6c02e6c63e
release: v1.31.1 — sso v1.17.2 + /vault policy fix (setup.sh)
...
- bump sso-manager-node submodule gitlink v1.17.1 -> v1.17.2
(post-deploy fixes: auto-slug plugins, schedule dropdown, /profile
rendering, plugin-edit persistence, nmap in image, SMS/TOS on /conf,
sso-side /vault policy grants)
- setup.sh: add sso-admin list grant on secret/metadata (KV mount root)
so the /vault secrets list no longer 403s for admins
- setup.sh: ensure_policy now always (re)writes the policy so policy
edits apply on a re-run instead of stranding the old HCL
- CHANGELOG embeds the full sso v1.17.2 changelog
Co-Authored-By: Claude <noreply@anthropic.com >
2026-08-01 22:52:50 -04:00
wmantly
e2e8143880
Merge pull request #128 from theta42/release-v1.31.0
...
v1.31.0: roll up submodules to latest (sso v1.17.1 + ldap-client v1.23.0)
2026-08-01 21:26:55 -04:00
wmantly and Claude
aa01a5cc07
release: bump submodules to latest tags (v1.31.0)
...
sso-manager-node v1.16.1 -> v1.17.1 (plugin system v1.17.0 + /conf secret
masking v1.17.1). ldap-client v1.1.1 -> v1.23.0 (CHANGELOG-only, no code
change). proxy v1.13.1 + jump-host v1.14.1 already latest, unchanged.
Changelog embeds the full sso v1.17.0 + v1.17.1 release notes.
Co-Authored-By: Claude <noreply@anthropic.com >
2026-08-01 21:26:13 -04:00
wmantly
1185bb90b8
Merge pull request #127 from theta42/feature/plugin-secrets-policy
...
v1.30.1: grant sso-broker OpenBao access to secret/plugins/* (plugin-system prerequisite)
2026-08-01 20:50:20 -04:00
wmantly and Claude
403e66556c
feat: grant sso-broker OpenBao access to secret/plugins/* (v1.30.1)
...
Prerequisite for the SSO Manager plugin system (shipped in sso-manager-node
v1.17.0). Adds secret/data/plugins/* (CRUD+list) + secret/metadata/plugins/*
(list/read/delete) to the sso-broker policy HCL so the SSO can store per-instance
plugin secrets in OpenBao instead of sso-secrets.js. ensure_policy is idempotent,
so re-running ./setup.sh grants the existing SSO_VAULT_TOKEN live.
Docs: secrets.md (Plugin secrets section + policy row), architecture.md.
Co-Authored-By: Claude <noreply@anthropic.com >
2026-08-01 20:33:21 -04:00
wmantly and Claude
3287777b9b
v1.30.0: rename theta-env -> theta-suite + docs rewrite + sso v1.16.1 ( #126 )
...
Rename the project to theta-suite (it is now an integrated suite of four
apps around a shared OpenBao secrets store, not a two-project env).
- theta-env -> theta-suite across the superproject: _config.yml (title +
baseurl /theta-suite + repo URLs), README, setup.sh (incl. the
THETA_SUITE_REEXECED self-update sentinel), docker-compose.yml,
bootstrap.js, lint.yml, config.example/*, docs/robots.txt, all docs,
this changelog.
- architecture.md rewritten: real 4-service + ldap-client topology, OpenBao
secrets section, OpenBao-aware config flow; removed "two containers" /
"three repos" / LDAP-"legacy" framing.
- index.md: integrated-suite framing + secrets/OpenBao + ldap-client.
- standalone.md + README: standalone reframed as advanced opt-in.
- sso-manager-node submodule -> v1.16.1 (401 fix on /conf and /vault).
Co-authored-by: Claude <noreply@anthropic.com >
2026-08-01 18:46:10 -04:00
wmantly and Claude
5ef3e3fa8c
v1.29.0: jump host is core + fix fresh-install setup.sh abort ( #125 )
...
Two fresh-install fixes and promote the SSH jump host from opt-in to core.
setup.sh: fix silent abort after "Minting per-app OpenBao tokens". env_get's
grep|cut pipeline returns non-zero under set -euo pipefail when .env exists
(created by the root VAULT_TOKEN env_upsert) but an app-token key is absent
(the normal first-run state); the unguarded existing assignment from env_get
then tripped set -e and killed the script before minting any token. env_get
now always returns 0 (|| true). Reproduced + verified under the exact condition.
jump host is no longer optional:
- docker-compose.yml: drop profiles jump-host from the jump-host service
(always started); rename the opt-in test fixture profile jump-host to ldap-test.
- setup.sh: SUBMODULES always includes jump-host; build/start/register/summary
no longer guarded by JUMP_ENABLED; drop the COMPOSE_PROFILES export.
- bootstrap.js: jump provisioning + directory record run unconditionally.
- setup.env.example/docs: drop optional/CFG_JUMP_HOST_ENABLED wording.
Co-authored-by: Claude <noreply@anthropic.com >
2026-08-01 13:48:28 -04:00
wmantly
a1ea2d458e
Merge pull request #124 from theta42/feature/openbao-secrets
...
v1.28.0: OpenBao as the central secrets store for the stack
2026-08-01 12:55:32 -04:00
wmantly and Claude
f7df04c2f0
v1.28.0: OpenBao as the central secrets store for the stack
...
theta-env orchestration:
- setup.sh: idempotent OpenBao policies (sso-broker, sso-admin, proxy,
jump-host), sso-broker token role (allowed_policies_glob user-*/app-*,
24h), mint scoped SSO/PROXY/JUMP_VAULT_TOKEN (orphan, .env reuse),
seed_app_conf seeds secret/{sso-manager,proxy,jump-host}/conf. Bootstrap
exec passes root VAULT_ADDR/VAULT_TOKEN for seeding. Root token never
reaches a service container. shellcheck -S warning clean.
- docker-compose.yml: VAULT_ADDR + VAULT_TOKEN env for sso/proxy/jump;
proxy/jump depends_on openbao service_started.
- bootstrap/bootstrap.js: baoPut() writes generated OAuth creds to
secret/proxy/conf + secret/jump-host/conf (OpenBao authoritative).
- docs/secrets.md (new): full secrets architecture. README + nav updated.
Submodule bumps:
- sso-manager-node -> v1.16.0 (OpenBao broker + vault UI + remediation)
- proxy -> v1.13.1 (via v1.13.0: OpenBao boot)
- jump-host -> v1.14.1 (via v1.14.0: OpenBao boot)
- ldap-client unchanged
Co-Authored-By: Claude <noreply@anthropic.com >
2026-08-01 12:54:56 -04:00
wmantly
3277972037
Merge pull request #123 from theta42/release-v1.27.2
...
Release v1.27.2
2026-08-01 11:14:39 -04:00
wmantly
0c7593cc59
Bump proxy to v1.12.1
2026-08-01 11:13:51 -04:00
wmantly
ec625f7cb0
Merge pull request #122 from theta42/release-v1.27.1
...
Release v1.27.1
2026-08-01 10:27:38 -04:00
wmantly
2a6c7775c9
Bump sso-manager-node to v1.15.2, add integration tests
2026-08-01 10:26:59 -04:00
wmantly
010ff037ce
Merge pull request #121 from theta42/release-v1.27.0
...
Release v1.27.0
2026-08-01 02:45:44 -04:00
wmantly
f8f1961b30
Bump sso-manager-node to v1.15.0 and update CHANGELOG for v1.27.0
2026-08-01 02:44:50 -04:00
wmantly
49dee5c477
Merge pull request #120 from theta42/release-v1.26.0
...
Release v1.26.0: OpenBao production ready
2026-08-01 02:18:03 -04:00
wmantly
1a832d068e
Fix shellcheck warning SC2155
2026-08-01 02:17:29 -04:00
wmantly
60ae421cb2
Release v1.26.0: OpenBao production ready
2026-08-01 02:16:33 -04:00
wmantly
90e95bfece
Merge pull request #119 from theta42/release-v1.25.0
...
Release v1.25.0
2026-08-01 01:41:00 -04:00
wmantly
144e97d0e1
Release v1.25.0
2026-08-01 01:40:28 -04:00
wmantly
9dc2de7818
Merge pull request #118 from theta42/release/v1.24.0
...
Release v1.24.0 - UI polish across all components
2026-07-31 14:45:03 -04:00
wmantly
a959b331ae
Release v1.24.0 - UI polish across all components
...
Bumps submodules to their latest releases:
- jump-host v1.13.0: Title changed to 'SSO Manager', TUI picker with ANSI colors
- sso-manager-node v1.13.0: Profile/catalog page redesign, SSH key column fix
- proxy v1.11.0: Table-based list views, auto-refresh groups
2026-07-31 14:43:56 -04:00
wmantly
b64083f008
Merge pull request #117 from theta42/release/v1.23.0
...
Release v1.23.0 - UI polish across all components
2026-07-31 14:08:45 -04:00
wmantly
a2fa7a7fc7
Release v1.23.0 - UI polish across all components
...
Bumps submodules to their latest releases:
- jump-host v1.13.0: Title changed to 'SSO Manager'
- sso-manager-node v1.13.0: Directory page cleanup, users list key column fix
- proxy v1.11.0: Table-based list views, auto-refresh groups
2026-07-31 14:08:00 -04:00
wmantly
6d6aea6011
Merge pull request #116 from theta42/release/v1.22.0
...
Release v1.22.0 - UI enhancements across all components
2026-07-31 14:01:31 -04:00
wmantly
43e3c79880
Release v1.22.0 - UI enhancements across all components
...
Bumps submodules to their latest releases:
- jump-host v1.12.0: TUI picker colors, dashboard/audit page styling
- sso-manager-node v1.12.0: Profile page tabs, catalog page redesign
- proxy v1.10.0: Table-based list views, form validation improvements
2026-07-31 13:52:13 -04:00
wmantly
8b549c3315
Release v1.22.0 - UI enhancements across all components
...
Bumps submodules to their latest releases:
- jump-host v1.12.0: TUI picker colors, dashboard/audit page styling
- sso-manager-node v1.12.0: Profile page tabs, catalog page redesign
- proxy v1.10.0: Table-based list views, form validation improvements
Full changelog entries embedded in each submodule.
2026-07-31 12:57:57 -04:00