1.6.0 (2025-01-21)
- Allow to enabled/disable support Ingersses individually. (4726af5)
- Consolidate objectStorage configuration for portal components (14f15da)
- Correct name of udm listener to "provisioning-udm-listener" (86f491e)
- guardian: Enable guardian and ugprade it to v3.0.0 (c9e0d1e)
- minio: Remove configuration option "defaultBuckets" (48225b9)
- minio: Use a read-only policy for the portal server (cced2a9)
- Remove unused objectStorage related helpers and reduce Ingress to bundled minio (4448ca0)
- upgrade keycloak-bootstrap to not use k8s hooks (724a64a)
- Upgrade portal-consumer / portal-server to version 0.50.0 (0ff02b6)
- upgrade provisioning with new NATS chart (9df584b)
- upgrade UCS base image to 2024-12-12 (99444b3)
- ldap-server: Overwrite the labelSelector on the primary service every 15 seconds to recover from initial state after the service is overwritten by helm (07c48a2)
1.5.1 (2024-12-11)
1.5.0 (2024-12-09)
- ldap-notifier: couple provisioning-udm-listener to ldap-server-primary-0 (eb20005)
- ldap-server: Improve database initialization logic to avoid data loss in specific failure scenarios (6abcd30)
- portal-consumer: Fix small secrets templating bug in the portal-consumer (70569b2)
1.4.0 (2024-12-03)
- Adjust "postgresql.auth" for notifications-api to new structure (c8a7cc6)
- keycloak-extension: Integrate keycloak-extension secrets refactor (8dd60d1)
- keycloak-extensions: added ssl support to the database connection on the proxy. (04072a6)
- LDAP server leader elector (257929f)
- new defaults for the Users module (8c71b85)
- portal-frontend: Flag to deactivate IPv6 support (ec96ca8)
- portal: sync with ucs 5.2 (b50683f)
- udm-rest-api: integrate secret-refactoring (a239624)
- umc-server: Integrate umc-server secrets refactor (d71e114)
- Update notifications-api to version 0.46.0 (7c0ea4e)
- update umc-server and umc-gateway to 0.35.4 (b227452)
- Update umc-server and umc-gateway to version 0.35.3 (23b3865)
- kyverno lint errors (b63e375)
- ldap-server: remove file ownership errors in the univention-compatibility initContainer (04fe4c2)
- portal-frontend: reload portal on branding changes. (bea723c)
- simplify umbrella chart by removing releaseNameOverride (0aa2693)
- udm-rest-api: use public artifacts instead of development (3de241f)
1.3.0 (2024-11-13)
- keycloak-bootstrap: Integrate keycloak-bootstrap secrets refactor (5895308)
1.2.0 (2024-11-13)
- keycloak: Integrate keycloak secrets refactor (52d0cd4)
1.1.0 (2024-11-05)
- provisioning: Add "existingSecret" into template names (195c10f)
- provisioning: integrate the secrets refactoring in the provisioning chart (92e21f8)
- provisioning: Use "existingSecret" pattern in "global.ldap.cnAdmin" configuration (d0a35d7)
- provisioning: Update provisioning charts to version 0.45.0 (70a4d45)
1.0.0 (2024-11-01)
- trigger the nubus 1.0.0 version bump
- Release nubus version 1.0.0 (1762b82)
- add digest to wait-for-dependency image (9c1d700), closes univention/customers/dataport/team-souvap#915
- Add license information for trademarked logos (f86e7dc), closes univention/customers/dataport/team-souvap#915
- Fix umc tile link (1287eb7)
0.74.0 (2024-11-01)
- Adjust ldap related configuration comment in portalConsumer (b041287)
- Adjust objectStorage related configuration commen for portalConsumer (a58368e)
- Auth configuration for API users in provisioningApi (0069e88)
- Auth configuration for minio provisioning does respect configured credentials (2961507)
- Auth configuration for NATS access in provisioning components (365238c)
- Auth configuration for NATS in selfservice-consumer (d1acc0c)
- Auth configuration for provisioningApi in selfservice-consumer (52051cc)
- Auth configuration of initial administrator password into templateContext of stack-data (09a4c06)
- Auth configuration of NATS admin password via provisioning.nats (f945dbd)
- Auth configuration of objectStorage for portal-consumer (5e360b2)
- Auth configuration of objectStorage for portal-server (cde75df)
- Auth configuration of provisioningApi for portal-consumer (cb80745)
- Auth configuration of UDM API for portal-consumer (a488b5b)
- Remove "credentialOverride.defaultAdminPassword" and "defaultUserPassword" (07b0e27)
- Remove obsolete auth configuration for portalListener (402ddcd)
- Update portal-consumer sub-chart to version 0.44.0 (6bd0d0e)
- Use "global.ldap.auth" in Secret generation (b7fccf6)
- Mark ldap related places which need a refactoring together with the sub-chart (398ff0d)
0.73.1 (2024-10-30)
- Set keycloak umc-server and ldap-server replicas (20b91eb)
0.73.0 (2024-10-29)
- selfservice: Integrate selfservice consumer secrets refactoring (b27fe95)
- selfservice: update selfservice consumer component chart (8f64a19), closes univention/customers/dataport/team-souvap#891
0.72.2 (2024-10-29)
- Correct doc comment syntax in values file (7281f93)
- Correct outdated comment around "global.extensions" (c93bad4)
0.72.1 (2024-10-28)
- remove unused old listeners (3fb17c2)
0.72.0 (2024-10-26)
- Migrate stack-data to jinja2 templates (efcf37f)
0.71.1 (2024-10-25)
- image name for the portal extension (41d516c)
0.71.0 (2024-10-25)
- remove OX extension by default (a155859)
0.70.2 (2024-10-25)
- temporarily disable guardian (e8e862a)
0.70.1 (2024-10-24)
- change product name to proper capitalization (fbacefd)
0.70.0 (2024-10-23)
- upgrade stack-data chart (fc697c5)
0.69.0 (2024-10-23)
- disable keycloak-extensions by default (81fa3f1)
0.68.1 (2024-10-23)
- release notes typo and missing namespaces (37d1433)
0.68.0 (2024-10-22)
- add missing portal tiles (cb99dc8), closes univention/customers/dataport/team-souvap#821
- upgrade portal extension image (c338f54)
0.67.0 (2024-10-22)
- use new univention-keycloak to configure CORS headers for Keycloak (f2e9b1b)
0.66.1 (2024-10-21)
- Bump portal related charts (5acf85e)
0.66.0 (2024-10-16)
- enable keycloak events (04bb72d)
0.65.1 (2024-10-15)
- Integrate self-service DoS fix from upstream (d97c98d), closes univention/customers/dataport/team-souvap#880
0.65.0 (2024-10-14)
- enable showUmc for the portal and configure default modules (be9e856), closes univention/customers/dataport/team-souvap#862
0.64.6 (2024-10-14)
- remove newlines from nubus-minio-provisioning secret (13faa72)
0.64.5 (2024-10-14)
- .Release.Name can't be used in yaml keys (17d9215)
0.64.4 (2024-10-11)
- don't hard-code the release name of the minioProvisioning secret (ef42e84)
0.64.3 (2024-10-11)
- remove legacy unused user sys-idp-user (a662740), closes univention/customers/dataport/team-souvap#838
0.64.2 (2024-10-09)
- fix YAML charts (e30f795)
0.64.1 (2024-10-09)
- fix ingress paths (3557114)
0.64.0 (2024-10-05)
- Plain nubus theming parity with UCS (de5c802)
0.63.2 (2024-10-03)
- cleanup selfservice values (035847e)
0.63.1 (2024-10-03)
- upgrade umc-server chart (2e05c94)
0.63.0 (2024-10-02)
- nubus: Update portal charts to version 0.41.0 (b751d37)
0.62.3 (2024-10-02)
- provisioning: safe KV updates (2476e6f)
0.62.2 (2024-09-26)
- provisioning: Bump provisioning to 0.43.1 (e71eaa4)
0.62.1 (2024-09-26)
- provisioning subscriptions format consistency and persistence (90d34c6)
0.62.0 (2024-09-25)
- remove cache http from portal (b802dff)
0.61.0 (2024-09-24)
- upgrade umc-server chart (606e07f)
0.60.0 (2024-09-24)
- rename endpoints of Provisioning API (760939b)
0.59.1 (2024-09-23)
- Don't leak secrets in bash scripts (70adcd6), closes univention/customers/dataport/team-souvap#843
0.59.0 (2024-09-19)
- register-consumer: register ox-connector in the provisioning (82a9515)
0.58.1 (2024-09-18)
- remove admin credentials (9fdb1fc)
0.58.0 (2024-09-18)
- upgrade ucs base image in all subcharts (3fe53fc)
0.57.3 (2024-09-13)
- Update portal components to version 0.38.3 (3145fd2)
0.57.2 (2024-09-12)
- provisioning-consumers: make consumers wait until the subscriptions are created by the register-consumers job (f97962c)
0.57.1 (2024-09-12)
- set all log/debug levels to INFO or equivalent (d06b201)
- set default service loglevels to INFO or equivalent (7a602aa)
0.57.0 (2024-09-12)
- provisioning: activate provisioning and consumers instead of listeners (c8bef31)
- update udm-listener (BSI compliance) (174d4f5)
0.56.1 (2024-09-12)
- disable logging of credentials during set_facts (95fff96)
0.56.0 (2024-09-11)
- upgrade stack-data chart (38b9a61)
0.55.1 (2024-09-11)
- portal-consumer: bump portal consumer version to integrate initial-values race-condition (8bc6caf)
0.55.0 (2024-09-11)
- stack-data: reload udm-rest-api cache (97ee9b9)
0.54.0 (2024-09-10)
- Plain UMC login configurable (31ea347)
0.53.0 (2024-09-10)
- provisioning: activate provisioning and consumers instead of listeners (5ead0b2)
0.52.0 (2024-09-10)
0.51.1 (2024-09-09)
- ldap: Configure LDAP Server Chart to only deploy one primary by default (198953f)
0.51.0 (2024-09-06)
- update ldap subchart (BSI compliant notifier) (de2519a)
0.50.1 (2024-09-05)
- provisioning: add credentialOverride for all provisioning secrets (e533400)
0.50.0 (2024-09-05)
- stack-data-swp: Remove stack-data-swp chart (d705260)
0.49.0 (2024-09-04)
- BSI compliance portal-consumer (676aaa5)
0.48.0 (2024-09-03)
- remove default portal tile on plain nubus (cec1f87)
0.47.0 (2024-09-03)
- update umc-server subchart (BSI compliance) (e55f9a5)
0.46.0 (2024-09-03)
- keycloak: Use StatefulSets (59d958f)
0.45.0 (2024-09-03)
- configure UCR from Helm (aacbeb8)
- migrate dev users to external extension (5235a87)
- upgrade stack-data chart (9b7aac0)
0.44.0 (2024-09-02)
- bump portal and selfservice-listener (aa90003)
0.43.0 (2024-09-02)
- configure UCR from Helm (7f3d653)
0.42.1 (2024-08-30)
- keycloak: update accidentally merged branch version of the keycloak chart (59a40bc)
0.42.0 (2024-08-30)
- upgrade to keycloak 25 (3242927)
0.41.1 (2024-08-29)
- fix Keycloak init race condition (be3e83b)
0.41.0 (2024-08-29)
- create readonly user for ldap federation on plain nubus (39d9619)
0.40.0 (2024-08-28)
0.39.3 (2024-08-28)
- bump provisioning and stack-data (b3da597)
0.39.2 (2024-08-27)
- umc-server: Update umc-gateway and umc-server to version 0.27.1 (b5d125c)
0.39.1 (2024-08-22)
- selfservice-consumer: fix feature-flag typo (3acdb20)
0.39.0 (2024-08-22)
- nubus: Add certManager template for ingress (4725259)
- Downgrade ldap-server and ldap-notifier to version 0.20.0 (ea32f16)
- Pin the minio dependency to 14.7.0 (1920e5d)
0.38.2 (2024-08-21)
- selfservice-consumer: rename selfservice-listener to selfservice-consumer to avoid helm package bug (47bafb6)
0.38.1 (2024-08-21)
- provisioning: put provisioning consumers behind a feature-flag (a031258)
- provisioning: temporarily add old secrets to enable provisioning consumers feature-flag (849a440)
0.38.0 (2024-08-19)
- update provisioning and add provisioning-based selfservice-consumer and portal-consumer (9a60585)
- upgrade only affected components (28c5006)
- bump selfservice-consumer and portal-consumer (d1aaec0)
- set nats replicas back to 1 until nats clustering is stable (9d46db6)
0.37.0 (2024-08-19)
- Use data-loader to load the ox-extension (f75bea6)
0.36.0 (2024-08-19)
- Add maildev into the CI setup (4ce07f6)
- Add trailing whitespace for the UCR configuration values which are empty (942f403)
0.35.0 (2024-08-19)
- umc-server: Session stickyness (a769fdf)
0.34.0 (2024-08-16)
- use univention-keycloak for guardian provisioning (c72a6a2)
0.33.1 (2024-08-09)
- drop unused menu patches (5e7695f)
0.33.0 (2024-08-05)
- migrate attribute-to-group mapper to external extension (a2e5ec4)
0.32.1 (2024-08-05)
- keycloak: missing proxy configuration (03bcba0)
- udm-rest-api: Force udm-rest-api cache reload workaround from stack-data (be08b85)
0.32.0 (2024-08-05)
- keycloak-extensions: proxy scaling (e2a150d)
0.31.0 (2024-08-04)
- high-availability Keycloak (cd16f24)
0.30.0 (2024-08-02)
- migrate announcements to external extension (370bb63)
0.29.1 (2024-08-01)
- keycloak-extensions: mark emails as sent and better logging (dec9b0a)
0.29.0 (2024-07-31)
- keycloak-extensions: bump python-keycloak to support newer Keycloaks (ddce8a2)
0.28.1 (2024-07-30)
- UMC policies (8fb731e)
- Use ldap-server-primary since it shares the socket with ldap-notifier (293dcfd)
0.28.0 (2024-07-30)
- update charts (b803fd0)
- add missing configuration for selfservice-listener (228b13e)
0.27.0 (2024-07-24)
0.26.0 (2024-07-19)
- Update stack-data-ums and stack-data-swp to version 0.55.1 (7417548)
- Use the secondary ldap server by default (de4e6b8)
0.25.2 (2024-07-18)
- nubus: bump stack-data version to drop email templates (d4b8b45)
- nubus: bump univention-portal to fix missing logo animation (f616dad)
- nubus: bump univention-portal to support central navigation shared secret (cfed78f)
0.25.1 (2024-07-16)
- remove patch to set UMC page title (cf8fb48)
0.25.0 (2024-07-12)
- bump keycloak-extensions (e64efe2)
0.24.1 (2024-07-12)
- Allow default users credentials to be overwritten (670956d)
- make credentialOverride global to allow for use in subchart used template definitions (3028da2)
0.24.0 (2024-07-11)
- add credentialOverride functionality (1d876dc)
- replace stack-gateway with ingress definitions (223fb0d)
- nubus: Add further overridable ldap-server credentials (08f136f)
- upstream change umc-server extra volumes (b5887f9)
- upstream extension changes (5dd4b25)
0.23.0 (2024-07-10)
- Update umc-server to ucs-520 image (bd19ca6)
- Upstream umc-server ingress configuration (066f542)
0.22.1 (2024-07-05)
- LDAP server version bump (uses UCS 5.2 sources) (ec0c98a)
0.22.0 (2024-07-05)
- configMap for self-service password email moved to sub-chart (05868c2)
0.21.0 (2024-07-05)
- Update component charts to leverage extension configuration (35e2ace)
- Update ox extension to version 0.10.0 (302daf1)
- Update the Chart.lock file (d5b3812)
0.20.0 (2024-07-05)
- Configure portal and ox extensions (561d019)
0.19.5 (2024-07-04)
- remove extensions from container-ldap (c5b0327)
0.19.4 (2024-07-01)
- udm-rest-api initContainer tags were wrongly set upstream (ca7bcbb)
0.19.3 (2024-06-27)
- update notifcations-api sub-chart (caaa13c)
0.19.2 (2024-06-27)
- add prefix to nats passwords to avoid the possibility of them being interpreted as integers (234469a)
- bump ucs-base to 5.0-8 (a63c708)
0.19.1 (2024-06-25)
- UDM REST API version bump (uses UCS 5.2 sources) (0172c7a)
0.19.0 (2024-06-25)
- disable password checks for default.admin, user and ldap search users (ef7935c)
0.18.4 (2024-06-25)
- keycloak-extensions bump version (fbef4de)
0.18.3 (2024-05-31)
- guardian: provisioning from opendesk (4e7180f)
0.18.2 (2024-05-30)
- Update chart description with new product name. (52e2ebe)
0.18.1 (2024-05-28)
- Add annotation for ingress-nginx (367cb2c)
- Tweak password derivation to avoid trouble during bootstrap (a163e20)
0.18.0 (2024-05-27)
- value deduplication (d81ed74)
0.17.0 (2024-05-27)
- Add interim "stage1_values" (bdbe63b)
- Add minimal Helmfile to deploy nubus (736db95)
- Add notes about certificates installation in the CI environment (9d6bf92)
- Add support for reviewPrefix in CI deployment (f373d99)
- Add values file with the current public image configuration (50702e3)
- Allow to override the chart version dynamically (8af44bb)
- Capture domain specific configuration into a dedicated file (edc9b01)
- Copy CI certificate into target namespace (c77c8c7)
- Use secret name "certificates-tls" for ingress configuration (b89fea8)
- Adjust postgresql configuration for guardian update (f8fa53a)
- Adjust values configuration to updated keycloak dependency (87c6ccd)
- Cleanup domain_values.yaml (34b6ab9)
- Cleanup the outdated todo remark around keycloak-bootstrap and the related setting (11b0447)
- Comment out the login entry in the dev values (8a1eb11)
- Correct database configuration for notifications-api in linter values (2139364)
- Correct domain for keycloak-bootstrap (711142f)
- Correct keycloak configuration in linter values (e5449c5)
- Correct open policy agent service name in linter values (e31af90)
- Correct the upstream configuration for guardian/opa in stack-gateway (7f0a701)
- Enable TLS in the keycloak extensions ingress (c6af8fa)
- Enabled ingress for keycloak-extensions (20e7760)
- Ensure that umc-server deploys its dependencies (5f6ebaf)
- Provide "reviewPrefix" from within the helmfile (16a0eeb)
- Provide domain into stack-data-swp (6af7529)
- Provide ldapBase for stack-data-swp (209e547)
- Remove duplicated entry for stack-gateway (30bd314)
- Remove the tag configuration for keycloak-bootstrap in linter values (a7ee3ab)
- Setting stub value for bundled postgresql of notifications-api (e80d84a)
- Switch off the Ingress configuration in linter values consistently (9e1de65)
- Update extraSecrets configuration in linter values (284d338)
- Update image configuration regarding the udm-rest-api (b308eea)
- Use secretRef for guardian credentials (44339be)
0.16.1 (2024-05-23)
- Adjust linter_values to match latest guardian configuration schema (e3a8c1d)
- Adjust the extra ingress configuration around the portal frontend (94edb57)
0.16.0 (2024-05-21)
- guardian: deduplicated yaml values (85ef851)
0.15.0 (2024-05-20)
- upgrade keycloak version (051f386)
0.14.0 (2024-05-16)
- update provisioning subchart (46f24ad)
- update linter values (4fb8e88)
0.13.0 (2024-05-14)
- update keycloak-bootstrap subchart (6065ac3)
- update keycloak-extensions subchart (2cd3233)
0.12.0 (2024-04-29)
- pre-refactored umbrella with refactored sub charts (50a2d56)
0.11.2 (2024-04-26)
0.11.1 (2024-04-17)
- Update provisioning to version 0.23.1 (52f2d82)
0.11.0 (2024-04-05)
- guardian: demo values (6f72032)
0.10.0 (2024-04-05)
- guardian: refactor values (ec017e5)
0.9.1 (2024-04-02)
- reference updated charts (container-umc) (243d873)
0.9.0 (2024-03-28)
- guardian: guardian keycloak provisioning and settings (efeea2f)
0.8.0 (2024-03-25)
- helm: demo values (87ea152)
0.7.5 (2024-03-25)
- univention-management-stack: update helm chart (e9125fc)
0.7.4 (2024-03-21)
- missing values (44b25b1)
0.7.3 (2024-03-21)
- ci: renovate target branch (2b8bd95)
0.7.2 (2024-03-20)
- check helm sha256 sum (7824e8c)
0.7.1 (2024-03-20)
0.7.0 (2024-03-20)
- use BSI compliant charts (9b2b97b)
- adjust to upstream helm changes (cf1be6d)
- fix linter_values.yaml (6be7c69)
- merge artifact (aa43a77)
- ref ldap-server feature branch (66e3328)
- remove store-dav references (e1f426e)
- test new upstream versions (9762162)
0.6.0 (2024-03-20)
- Add configuration regarding the S3 compatible object store for portal-listener (aa41f2c)
- Apply password policy and tls related UCR settings from dev-env (967b028)
- Extend minio configuration for usage by other components (0874a16)
- Simplify development stub passwords after policy update (4651956)
- Update dependencies to latest versions (887045c)
- Add "proxy-buffer-size" annotation to stack-gateway for ingress-nginx (617c4df)
- Add UMC related settings to stack-data-ums (805165b)
- Add workaround for provisioning until the default registry is configured (ea18192)
- Add workaround regarding the postgresql version for notifications-api (be91792)
- Adjust portal-server configuration to use minio (fb3943c)
- Adjust secrets configuration for notifications-api's postgres (666a0d8)
- Apply interim fix related to the udm-rest-api (86539a4)
- Correct ldap related credentials for udm-rest-api (8163782)
- Correct objectStorageEndpoint for the portal-listener (7612586)
- Correct SAML ID in the ldap configuration (941dca1)
- Remove cert-manager related configuration from linter values (bdc3c8b)
- Remove now outdated secret configuration for udm-rest-api (5a9495c)
- Switch to use "extraSecrets" for udm rest api (9859a71)
- Workaround for the keycloak default memory limit (621a1f8)
0.5.0 (2024-03-13)
- add stack-gateway (f6d78d4)
0.4.0 (2024-03-13)
- add minio to chart (9563ca9)
- ci/docs: update docs, update gitlab-ci (9789063)
0.3.0 (2024-01-30)
- Add "ldapSearchUser" for the keycloak integration (667c1b8)
- Add guardian related charts into the list of dependencies (bf49bde)
- Add keycloak-bootstrap and extensions as dependencies (fb628fb)
- Add SAML related settings for stack-data-ums (2ff3677)
- Add selfservice-listener (16ac8de)
- Add theming related configuration regarding Keycloak (61bf6b3)
- Add univention keycloak into the dependencies (3a36626)
- Adjust oauth related settings to realm "opendesk" (9d79b97)
- Domain and realm related tweaks for the keycloak integration (8e0119a)
- Expose the Keycloak admin interface via Ingress of keycloak-extensions (7f227ff)
- First iteration on Guardian related configuration (616bb3c)
- Update dependencies to latest versions (de65e6e)
- Configure "natsHost" for the provisioning listener (c4bf7c5)
- Correct typo in parameter "keycloak-bootstrap.config.ums.ldap.baseDN" (3d36a7a)
- Ensure a more recent image is used in "keycloak-bootstrap" (7e5fb47)
0.2.0 (2024-01-23)
- Add "dev_values.yaml" to support local development needs (826bae0)
- Add extra volume configuration from openDesk (403d47d)
- Add extraIngress configuration for the portal frontend (a65bb0c)
- Add initialPasswordSysIdpUser to stack-data-ums (ba068ec)
- Add ldap-server, ldap-notifier and stack-data as dependencies (c88b08a)
- Add store-dav as dependency (4027821)
- Add the portal subcharts as dependencies (ac43828)
- Add the Provisioning components into the chart (05f7a91)
- Add UMC charts into dependencies (5dddf2c)
- Catch up with removal of secrets from the notifications-api defaults (feffbeb)
- Enable the bundled memcached for the umc-server (3d03c28)
- Enable the bundled postgresql for the umc-server (7303aa1)
- Integrate udm-rest-api (e350db7)
- Only lock the major version on our subcharts (ee4d240)
- Prefix the bundled postgresql in notifications-api (2c0bd89)
- Rename the chart to "ums" to keep names short (39e59cd)
- Passwords in linter_values meet the complexity rules (a02daa5)
0.1.0 (2024-01-20)
- Enable souvap publishing of the helm package (1f8b609)