miampf
2cb1e714b1
fix certificate formatting
2025-02-06 15:50:04 +01:00
miampf
0f935a80c8
Use correct pathing and improve CLI tip
2025-02-06 15:50:03 +01:00
miampf
ff142be322
update package hashes again
2025-02-06 15:24:25 +01:00
miampf
283f67c73d
Remove AuthorizedKeysFile
setting
2025-02-06 15:24:24 +01:00
miampf
0fc4ca0751
Use CertificateFile
instead of IdentityFile
2025-02-06 15:24:24 +01:00
miampf
554707e227
fix mirror from rebase
2025-02-06 15:24:24 +01:00
miampf
634420dcb7
tidy check generate
2025-02-06 15:24:23 +01:00
miampf
4c5664dad4
wrote docs for emergency ssh access workflow
2025-02-06 15:24:23 +01:00
miampf
6f8d11c8e5
use /run/ssh
subdir + harden openssh config a bit
2025-02-06 15:24:23 +01:00
miampf
12e9c71750
ProxyJump for hosts outside of 10.* range
...
removed unnecessary values for proxy host
2025-02-06 15:24:22 +01:00
miampf
35d80354c5
adjust emergency_ssh
variable description
2025-02-06 15:24:22 +01:00
miampf
71fc0eb47f
add emergency_ssh var to other providers (untested)
2025-02-06 15:24:22 +01:00
miampf
4ae2df6c7f
nix fmt
2025-02-06 15:24:22 +01:00
miampf
a37ecfa9b7
ssh node image configuration
2025-02-06 15:24:21 +01:00
miampf
c25d0c34dd
change known_hosts file to writable location
2025-02-06 15:24:21 +01:00
miampf
816d61a1f1
terraform ssh setup
2025-02-06 15:24:21 +01:00
miampf
6187364eb0
sshd
and create-host-ssh-key
service on node
2025-02-06 15:24:21 +01:00
miampf
1dc93d974f
tf ssh access with custom lb
...
changed later to use existing load balancer instead of a custom setup
2025-02-06 15:24:20 +01:00
miampf
0c0aa003d1
sshd
config and creation of create-host-ssh-key
service
2025-02-06 15:24:20 +01:00
miampf
1b0e42385f
add openssh-server
and openssh
package
...
`openssh` package later removed since it is not needed for this feature
to function
2025-02-06 15:24:20 +01:00
renovate[bot]
cb77e7bb0d
deps: update dependency asciinema-player to v3.9.0 ( #3635 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-02-06 12:40:38 +01:00
renovate[bot]
3fa29a5ee8
deps: update Go dependencies ( #3631 )
...
* deps: update Go dependencies
* deps: fix dependency for go-control-plane/envoy
* Accept AGPL-3.0 for edgelesssys/go-tdx-qpl
---------
Signed-off-by: Daniel Weiße <dw@edgeless.systems>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Daniel Weiße <dw@edgeless.systems>
2025-02-06 11:07:06 +01:00
renovate[bot]
f81c357f51
deps: update Constellation containers ( #3638 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-02-06 08:03:14 +01:00
edgelessci
6d42d9b40e
image: update measurements and image version ( #3636 )
...
Co-authored-by: edgelessci <edgelessci@users.noreply.github.com>
2025-02-05 08:29:26 +01:00
renovate[bot]
f41c7619e1
deps: update ubuntu:24.04 Docker digest to 7229784 ( #3634 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-02-04 10:02:41 +01:00
renovate[bot]
f1e30863c1
deps: update GitHub action dependencies ( #3633 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-02-04 08:27:37 +01:00
Moritz Sanft
245700ee54
helm: grant configmap watch permission to constellation-operator-controller-manager ( #3632 )
2025-02-03 20:31:37 +01:00
edgelessci
76b642baf9
image: update locked rpms ( #3630 )
2025-02-02 10:02:35 +01:00
edgelessci
ad364f2089
image: update measurements and image version ( #3628 )
...
Co-authored-by: edgelessci <edgelessci@users.noreply.github.com>
2025-01-31 08:31:34 +01:00
renovate[bot]
681a341b8f
deps: update bazel (plugins) ( #3598 )
...
* deps: update bazel (plugins)
* deps: fix renovate's attempt
---------
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Markus Rudy <mr@edgeless.systems>
2025-01-30 16:36:45 +01:00
renovate[bot]
0e4f3a0716
deps: update public.ecr.aws/eks/aws-load-balancer-controller Docker tag to v2.11.0 ( #3611 )
...
* deps: update aws-load-balancer-controller Helm chart
* deps: tidy all modules
---------
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: edgelessci <edgelessci@users.noreply.github.com>
2025-01-30 15:54:07 +01:00
miampf
706d1dff15
cli: add ssh
command to securely connect with nodes over ssh ( #3568 )
2025-01-30 12:08:59 +00:00
renovate[bot]
e6048e093b
deps: update dependency aspect_bazel_lib to v2.13.0 ( #3627 )
...
* deps: update dependency aspect_bazel_lib to v2.13.0
* deps: tidy all modules
---------
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: edgelessci <edgelessci@users.noreply.github.com>
2025-01-30 11:45:03 +01:00
renovate[bot]
1faf2dd1b8
deps: update dependency gazelle to v0.42.0 ( #3626 )
...
* deps: update dependency gazelle to v0.42.0
* deps: tidy all modules
* ci: ignore GO-2025-3408
The vulnerability does not have a patch and is a denial-of-service.
---------
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: edgelessci <edgelessci@users.noreply.github.com>
Co-authored-by: Markus Rudy <mr@edgeless.systems>
2025-01-30 11:00:18 +01:00
renovate[bot]
bb994d5a01
deps: update Go dependencies ( #3623 )
...
* deps: update Go dependencies
* deps: tidy all modules
* keep cloud.google.com/go/storage at v1.49.0
Signed-off-by: Daniel Weiße <dw@edgeless.systems>
---------
Signed-off-by: Daniel Weiße <dw@edgeless.systems>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: edgelessci <edgelessci@users.noreply.github.com>
Co-authored-by: Daniel Weiße <dw@edgeless.systems>
2025-01-29 16:31:16 +01:00
edgelessci
7242a1eb74
image: update measurements and image version ( #3625 )
...
Co-authored-by: edgelessci <edgelessci@users.noreply.github.com>
2025-01-29 16:31:07 +01:00
miampf
8da08bec8d
e2e: downgrade vale version to 3.9.3 ( #3624 )
2025-01-28 13:12:50 +00:00
renovate[bot]
8e8c44e35a
deps: update dependency buildifier_prebuilt to v8.0.1 ( #3621 )
...
* deps: update dependency buildifier_prebuilt to v8.0.1
* deps: tidy all modules
---------
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: edgelessci <edgelessci@users.noreply.github.com>
2025-01-24 13:36:58 +01:00
renovate[bot]
148b82e32c
deps: update dependency prism-react-renderer to v2.4.1 ( #3619 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-01-24 08:06:24 +01:00
edgelessci
e44adf85d4
image: update measurements and image version ( #3620 )
...
Co-authored-by: edgelessci <edgelessci@users.noreply.github.com>
2025-01-24 08:06:12 +01:00
renovate[bot]
3af498fbfe
deps: update dependency numpy to v2.2.2 ( #3618 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-01-22 12:26:18 +01:00
renovate[bot]
bda3d802dc
deps: update dependency asciinema-player to v3.8.2 ( #3616 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-01-22 12:21:19 +01:00
renovate[bot]
808631f530
deps: update dependency buildifier_prebuilt to v8 ( #3615 )
...
* deps: update dependency buildifier_prebuilt to v8
* deps: tidy all modules
---------
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: edgelessci <edgelessci@users.noreply.github.com>
2025-01-22 11:53:19 +01:00
renovate[bot]
3f702ecda9
deps: update Terraform google to v6.17.0 ( #3614 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-01-22 08:49:30 +01:00
renovate[bot]
12cfd7006b
deps: update registry.k8s.io/sig-storage/snapshot-controller Docker tag to v8.2.0 ( #3612 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-01-22 08:27:02 +01:00
edgelessci
caa80783eb
image: update measurements and image version ( #3613 )
...
Co-authored-by: edgelessci <edgelessci@users.noreply.github.com>
2025-01-22 08:13:32 +01:00
renovate[bot]
501d1779ed
deps: update Go dependencies ( #3603 )
...
* deps: update Go dependencies
* hold back cloud.google.com/go/storage dependency
* keep fork replacement at consistent version
---------
Signed-off-by: Daniel Weiße <dw@edgeless.systems>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Daniel Weiße <dw@edgeless.systems>
2025-01-21 16:23:10 +01:00
Daniel Weiße
bea2f33efc
renovate: reformat config file for json5 ( #3610 )
...
* renovate: include replace directives in Go deps upgrade
* renovate: replace deprecated regexManagers with customManagers
* renovate: rewrite config in proper json5
---------
Signed-off-by: Daniel Weiße <dw@edgeless.systems>
2025-01-21 13:26:42 +01:00
renovate[bot]
92d7fc5385
deps: update module k8s.io/cri-client to v0.32.1 ( #3608 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-01-21 11:03:48 +01:00
renovate[bot]
e9a6513346
deps: update actions/setup-go action to v5.3.0 ( #3605 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2025-01-21 10:28:03 +01:00