Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
114 commits
Select commit Hold shift + click to select a range
c3849b8
Merge pull request #5322 from wireapp/master
blackheaven Jul 7, 2026
eaa782b
WPB-26704: add full `conversation` to `POST /meetings` (create) and `…
blackheaven Jul 7, 2026
a9a19dd
make multi-ingress domains case agnostic (#5320)
supersven Jul 8, 2026
cb1b4fa
WPB-26771: deprecate meetingsPremium feature flag (#5326)
blackheaven Jul 8, 2026
d27ea44
idpCertFingerprintAllowlist mandatory for multi-ingress SSO (#5327)
supersven Jul 9, 2026
b765f7c
test(mls): free connections and cap retries in createMLSOne2OnePartne…
blackheaven Jul 10, 2026
dee60f6
WPB-26487 backend background jobs hasql resource pool refactoring (#5…
battermann Jul 10, 2026
5b7f1cc
Stabilize testSparScimCreateGetSearchUserGroup (#5331)
supersven Jul 10, 2026
81dc949
WPB-23896: address SonarQube findings (#5332)
blackheaven Jul 10, 2026
299a170
WPB-26773: reject meetings with start time in the past (#5325)
blackheaven Jul 10, 2026
a64a475
Fix sbomnix by updating 1.7.4 -> 1.8.0 (#5336)
supersven Jul 14, 2026
90fc9ce
[WPB-25521] Fix update / delete collaborator routes (#5334)
fisx Jul 14, 2026
8b7cd51
[fix] team search visibility JSON parser (#5338)
battermann Jul 15, 2026
e1455dc
WPB-21744: invalidate pending email update when a user is put under S…
blackheaven Jul 15, 2026
141c7f3
[fix] claim key packages for ephemeral users (#5339)
battermann Jul 15, 2026
ed4386e
WPB-26823: make meetings cleanup fully index-driven (#5328)
blackheaven Jul 15, 2026
44e7580
Reorder SSO nginx locations to enforce correct rate limiting (#5341)
supersven Jul 16, 2026
b40a9a3
WPB-26705: add meeting.create/update/delete lifecycle events (#5330)
blackheaven Jul 16, 2026
632be41
[WPB-27227] Include collaborating apps (aka external apps) in "GET /t…
fisx Jul 17, 2026
e50d944
WPB-26489 backend adminless scheduled jobs model for deletion and rem…
battermann Jul 20, 2026
d5ec6d5
WPB-27060 Add optional field `supportEmail` to `deeplink.json` (#5351)
battermann Jul 21, 2026
6d272aa
WPB-26705: move meeting qualified id to event envelope (#5349)
blackheaven Jul 21, 2026
e9c74d2
WPB-27329: meetings read endpoints no longer 403 when feature disable…
blackheaven Jul 21, 2026
538d516
WPB-25544 fix: stealth users are searchable via federated search (#5282)
battermann Jul 22, 2026
0da4884
WPB-24669 [fix] upload of files with umlaut when audit log enabled (#…
battermann Jul 22, 2026
a8892f6
Replace gone bitnami image cache (#5360)
supersven Jul 22, 2026
847f572
fix static swagger-v16.json file (#5365)
battermann Jul 23, 2026
2d0631a
Envoy: add annotations to httpRoutes and Ingress (#5358)
siberijah Jul 23, 2026
8837aa0
WPB-27017 reconcile adminless groups on feature toggle (#5357)
battermann Jul 23, 2026
539fca7
WPB-26101 move code from KeyPackage into subsystem and store (#5368)
battermann Jul 24, 2026
8c24463
WPB-26101 add contact status enrichment to `POST /list-users` (#5371)
battermann Jul 24, 2026
c6f015b
WPB-27175: Add Galley meetings email config plumbing (#5346)
blackheaven Jul 24, 2026
1837cf8
WPB-27373: drop trial from Meeting at API version V17 (#5363)
blackheaven Jul 25, 2026
35d8df6
WPB-26771: Deprecate meetingsPremium endpoints at API v17 (#5364)
blackheaven Jul 25, 2026
3cb74c4
Various improvements to cleanup PR 5343 (#5354)
fisx Jul 27, 2026
cab9311
WPB-27465: allow editing ongoing (already-started) meetings (#5373)
blackheaven Jul 27, 2026
8a5e78f
WPB-26489 improve connection pool management for background jobs (#5375)
battermann Jul 28, 2026
f6774bc
WPB-23631: Move `Spar.Sem.Reporter` to `Wire.Reporter` (#5356)
blackheaven Jul 28, 2026
83e43b7
feat: add multi-ingress-support for envoy gw (#5307)
siberijah Jul 28, 2026
588240a
WPB-23631: Move `Spar.Sem.SamlProtocolSettings` to `Wire.SamlProtocol…
blackheaven Jul 28, 2026
77f097a
WPB-23631: Move `Spar.Sem.ScimUserTimesStore` in `Wire.ScimUserTimesS…
blackheaven Jul 28, 2026
e2eee36
WPB-23631: `Spar.Sem.DefaultSsoCode` in `Wire.DefaultSsoStore` (#5379)
blackheaven Jul 29, 2026
b035a6b
WPB-23631: Move `Spar.Sem.IdPRawMetadataStore` to `Wire.IdPRawMetadat…
blackheaven Jul 29, 2026
10085cf
WPB-26626: hide meeting conversations from legacy (< V16) GET endpoin…
blackheaven Jul 29, 2026
b1381a3
WPB-23631: Move `Spar.Sem.ScimExternalIdStore` in `Wire.ScimExternalI…
blackheaven Jul 24, 2026
28f7530
Revert "WPB-23631: Move `Spar.Sem.ScimExternalIdStore` in `Wire.ScimE…
blackheaven Jul 29, 2026
59cb012
[WPB-25579] If apps are re-enabled in the team, DO NOT re-activate an…
fisx Jul 30, 2026
1ddcd18
WPB-27017 [fix] member-update event target user (#5390)
battermann Jul 30, 2026
f1e29fc
fix: change csp override behavior (#5385)
siberijah Jul 30, 2026
1f7a68b
UserStore,brig: Remove unused code to get rich infos in bulk (#5384)
akshaymankar Jul 30, 2026
26f5de6
integration: Add request id to every request (#5386)
akshaymankar Jul 30, 2026
582947c
WPB-27393 guard bulk conversation member replacement against adminles…
battermann Jul 30, 2026
b412c1c
[WPB-18127] Update email templates to v1.0.155. (#5344)
fisx Jul 31, 2026
7420603
WPB-27620: add meeting.member-add notifications (#5383)
thisisamir98 Jul 31, 2026
f07b903
[WPB-27705] Roll back: do *not* include collaborator apps in get-apps…
fisx Jul 31, 2026
681f4b5
integration: Remove hardcoded prekeys (#5407)
akshaymankar Aug 3, 2026
b1129ba
chore(sftd_disco): move sftd_disco helper to wire-avs-service (#5056)
lwille Aug 3, 2026
06bed87
WPB-23631: Move `Galley.Effects.Queue` in `Wire.BoundedQueue` (#5398)
blackheaven Aug 3, 2026
ca95062
multi-ingress: cross-IdP SSO (#5212)
supersven Aug 3, 2026
adfbdc5
WPB-23631: Move `Brig.Effects.UserPendingActivationStore` in `Wire.Us…
blackheaven Aug 3, 2026
3f7f621
WPB-23631: Move `Brig.Effects.JwtTools` in `Wire.JwtTools` (#5396)
blackheaven Aug 3, 2026
06a57e1
WPB-23631: Move `Brig.Effects.SFT` in `Wire.SFT` (#5395)
blackheaven Aug 3, 2026
6cd6bfc
fix: stop comparing event order in `testMeetingMLSAddParticipant` (#5…
blackheaven Aug 4, 2026
5c30cc6
chore(charts): make alpine images configurable (#5408)
lwille Aug 4, 2026
959a935
fix: flaky testFederatorNumRequestsMetrics test (#5413)
blackheaven Aug 4, 2026
6ce8f54
WPB-23631: Move `Spar.Sem.ScimExternalIdStore` in `Wire.ScimExternalI…
blackheaven Aug 4, 2026
ae3836f
WPB-23631: Move `Brig.Budget` in `Wire.BudgetStore` (#5397)
blackheaven Aug 4, 2026
95f0965
WPB-23631: Move `Spar.Sem.VerdictFormatStore` in `Wire.VerdictFormatS…
blackheaven Aug 4, 2026
6a75667
fix: flaky testProviderSearchWhitelist test narrow random service nam…
blackheaven Aug 5, 2026
27f0dfb
WPB-23631: Cache the public key bundle at startup instead of an effec…
blackheaven Aug 6, 2026
50a6173
WPB-23177 [fix] duplicate user accounts created after expired SCIM in…
battermann Aug 6, 2026
d8fb5af
WPB-23631: move ScimExternalIdStore law tests from library to test-su…
blackheaven Aug 6, 2026
f9d161b
WPB-26626: emit conversation.delete-meeting for meeting conversations…
blackheaven Aug 6, 2026
27bb127
fix: remove broken addTeamMemberInternal & port one2one tests to Test…
blackheaven Aug 7, 2026
09b3d02
WPB-27857: exclude the initiator from Wire Meetings lifecycle events …
blackheaven Aug 7, 2026
d6b0d6a
fix(federator): cross-check external listener in internal /i/status (…
blackheaven Aug 10, 2026
a7eb92f
WPB-27907: filter Wire Meetings events only on connection (#5428)
blackheaven Aug 10, 2026
efd88af
[WPB-18127] Move email template completeness tests from brig to wire-…
fisx Aug 11, 2026
082e434
test(Cells): isolate testCellsDeletionEvent from shared cells queue (…
blackheaven Aug 11, 2026
c5ec2e7
fix: gate federated conversation create on assertFullyConnected (#5430)
blackheaven Aug 11, 2026
f9f0da7
charts/wire-ingress: remove query param from logs (#5361)
jschaul Aug 11, 2026
c1c572b
multi-ingress: Use webapp CSP headers (#5432)
supersven Aug 11, 2026
e6ef9e6
WPB-26650 prevent fed state drift on prevent adminless groups actions…
battermann Aug 12, 2026
5af74c8
[WPB-27953] SCIM: advertise all schemas used in User (fixes RFC compl…
fisx Aug 14, 2026
3f7930c
[WPB-27953] SCIM: Make role field in user schema comply with RFC. (#5…
fisx Aug 14, 2026
07c5dad
fix(federator): record mock-federator requests atomically (#5437)
blackheaven Aug 14, 2026
da5bf66
reaper: updating kubectl image, detection script, rbac (#5444)
jschumacher-wire Aug 17, 2026
19af0ba
[WPB-27953] Make scim error responses comply with RFC7644. (#5439)
fisx Aug 17, 2026
bbcbfac
Fix integration test cleanup on federation instance V2. (#5447)
fisx Aug 18, 2026
2c8ad5c
Allow team admin to remove bot from all conversations. (#5450)
fisx Aug 18, 2026
3453888
cannon: log unavailable gundeck (#5454)
supersven Aug 18, 2026
635f383
WPB-27912: Deprecate backgroundEffects feature flag at API v17 (#5431)
blackheaven Aug 18, 2026
3f9e234
Update cassandra Docker tag to v4.1.11 (#5449)
renovate[bot] Aug 19, 2026
11347e7
WPB-27553: add tzid to meetings (#5391)
blackheaven Aug 19, 2026
86b8ee0
WPB-28080: relax Meeting editing from start time (#5451)
blackheaven Aug 19, 2026
cffb095
WPB-28155: create meeting conversations with access [invite, code] (#…
blackheaven Aug 19, 2026
4f5c093
WPB-28093: add dedicated Meeting errors description (#5455)
blackheaven Aug 19, 2026
1c50cfc
[WPB--] Update postgres schema dump. (#5461)
fisx Aug 20, 2026
151e299
[WPB-28132] Fix openapi3 docs for oauth scopes. (#5457)
fisx Aug 20, 2026
f2a9c1d
Simplify `make psql` usage (#5465)
supersven Aug 20, 2026
44a0db9
Add allowManualMigration flag to mlsMigration.config (#5456)
supersven Aug 20, 2026
fd6c9bf
WPB-23434: Support SCIM PATCH of multi-valued emails attribute (#5419)
blackheaven Aug 20, 2026
6c1f86b
WPB-28163: move V17 endpoints to V18 (#5468)
blackheaven Aug 20, 2026
853bb1f
[WPB-28050] New oauth scopes for meetings for calendar integration. (…
fisx Aug 21, 2026
a1fb9bc
Disable and LOCK preventAdminlessGroups (#5472)
supersven Aug 24, 2026
10c32cc
fix: keep hoogle image haddock from hanging in CI (#5474)
blackheaven Aug 25, 2026
a8ea553
NewStoredUser: Remove handle (#5475)
akshaymankar Aug 26, 2026
3309e7b
[WPB-28089] Treat team collaborators like team members in contact sea…
fisx Aug 26, 2026
bc1ae68
WPB-28272: Make meeting tzid updatable via PUT /meetings/{domain}/{id…
blackheaven Aug 26, 2026
11f4dd9
[WPB-28280] Automate license header updates in treefmt. (#5481)
fisx Aug 26, 2026
e898864
[WPB-27169] Make haddocks more readable. (#5446)
fisx Aug 26, 2026
e6b5ca3
[WPB-28299] Finalize api version 17 (#5482)
fisx Aug 26, 2026
60049d5
Revert "[WPB-28089] Treat team collaborators like team members in con…
fisx Aug 27, 2026
358d6a8
Add changelog for Release 2026-08-27
zebot Aug 27, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
2 changes: 1 addition & 1 deletion .github/workflows/build.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ jobs:
uses: actions/checkout@v4

- name: Setup Nix
uses: cachix/install-nix-action@v16
uses: cachix/install-nix-action@d56f3ce9be45c562799280e8a561fbbe8f36de44 # v16

- name: Clone wire-docs and build
run: |
Expand Down
9 changes: 7 additions & 2 deletions .headroom.yaml
Original file line number Diff line number Diff line change
@@ -1,5 +1,8 @@
version: 0.4.0.0
run-mode: replace
# 'add' only touches files that have no header at all. Existing headers
# (and, importantly, the years in them) are left alone; see
# https://github.com/wireapp/wire-server/pull/4851.
run-mode: add
source-paths:
- libs
- services
Expand All @@ -13,7 +16,9 @@ variables:
organization: Wire Swiss GmbH
email: opensource@wire.com
project: This file is part of the Wire Server implementation.
year: "2025"
# only ever used for files that get a header added now, so this needs no
# maintenance and causes no churn in files that already have one.
year: "{{ _current_year }}"
license-headers:
haskell:
file-extensions: ["hs", "hsc"]
Expand Down
459 changes: 459 additions & 0 deletions CHANGELOG.md

Large diffs are not rendered by default.

15 changes: 2 additions & 13 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ calling-test demo-smtp elasticsearch-curator elasticsearch-external \
elasticsearch-ephemeral minio-external cassandra-external \
ingress-nginx-controller nginx-ingress-services reaper \
k8ssandra-test-cluster ldap-scim-bridge wire-server-enterprise \
wire-ingress
wire-ingress
KIND_CLUSTER_NAME := wire-server
HELM_PARALLELISM ?= 1 # 1 for sequential tests; 6 for all-parallel tests
PSQL_DB ?= backendA
Expand Down Expand Up @@ -276,15 +276,6 @@ formatf-all:
formatc:
./tools/ormolu.sh -c

# For any Haskell or Rust file, update or add a license header if necessary.
# Headers should be added according to Ormolu's formatting rules, but please check just in case.
.PHONY: add-license
add-license:
command -v headroom
headroom run -a
@echo ""
@echo "you might want to run 'make formatf' now to make sure ormolu is happy"

# without redirecting stdin/-out/-err, emacs does something weird that takes 3-5 seconds.
.PHONY: treefmt
treefmt:
Expand Down Expand Up @@ -356,9 +347,7 @@ cqlsh:

.PHONY: psql
psql:
@grep -q wire-server:wire-server ~/.pgpass || \
echo "consider running 'echo localhost:5432:$(PSQL_DB):wire-server:posty-the-gres > ~/.pgpass ; chmod 600 ~/.pgpass '"
psql -h localhost -p 5432 $(PSQL_DB) -U wire-server -w || \
PGPASSWORD=posty-the-gres psql -h localhost -p 5432 $(PSQL_DB) -U wire-server -w || \
echo 'if the database is missing, consider running "make postgres-reset", or setting $$PSQL_DB to the correct table space.'

.PHONY: db-reset-package
Expand Down
1 change: 1 addition & 0 deletions cabal.project
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
repository hackage.haskell.org
url: https://hackage.haskell.org/
index-state: 2023-10-03T15:17:00Z

packages:
integration
, libs/bilge/
Expand Down
26 changes: 26 additions & 0 deletions cassandra-schema.cql
Original file line number Diff line number Diff line change
Expand Up @@ -1005,6 +1005,30 @@ CREATE TABLE brig_test.team_invitation_info (
AND read_repair = 'BLOCKING'
AND speculative_retry = '99p';

CREATE TABLE brig_test.team_scim_pending_user_email (
team uuid,
email text,
user uuid,
PRIMARY KEY ((team, email), user)
) WITH CLUSTERING ORDER BY (user ASC)
AND additional_write_policy = '99p'
AND bloom_filter_fp_chance = 0.01
AND caching = {'keys': 'ALL', 'rows_per_partition': 'NONE'}
AND cdc = false
AND comment = ''
AND compaction = {'class': 'org.apache.cassandra.db.compaction.SizeTieredCompactionStrategy', 'max_threshold': '32', 'min_threshold': '4'}
AND compression = {'chunk_length_in_kb': '16', 'class': 'org.apache.cassandra.io.compress.LZ4Compressor'}
AND memtable = 'default'
AND crc_check_chance = 1.0
AND default_time_to_live = 0
AND extensions = {}
AND gc_grace_seconds = 864000
AND max_index_interval = 2048
AND memtable_flush_period_in_ms = 0
AND min_index_interval = 128
AND read_repair = 'BLOCKING'
AND speculative_retry = '99p';

CREATE TABLE brig_test.unique_claims (
value text PRIMARY KEY,
claims set<uuid>
Expand Down Expand Up @@ -2450,6 +2474,8 @@ CREATE TABLE spar_test.scim_external (
CREATE TABLE spar_test.scim_user_times (
uid uuid PRIMARY KEY,
created_at timestamp,
email_primary boolean,
email_type text,
last_updated_at timestamp
) WITH additional_write_policy = '99p'
AND bloom_filter_fp_chance = 0.1
Expand Down
1 change: 1 addition & 0 deletions changelog.d/99-pending/WPB-27393
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
V18 `PUT /conversations/{domain}/{conversation}/members` rejects replacements that would leave a regular group without an admin; V17 and older retain the legacy autopromotion behavior. (#5387)
4 changes: 4 additions & 0 deletions changelog.d/mk-changelog.sh
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,10 @@ get_pr_number() {

for d in "$DIR"/*; do
if [[ ! -d "$d" ]]; then continue; fi
# 99-pending: entries deferred out of the upcoming release. Since renaming a
# file breaks get_pr_number (git log does not follow renames), each parked
# entry must bake its PR number into its text, e.g. " (#1234)".
if [[ "$(basename "$d")" == "99-pending" ]]; then continue; fi

entries=("$d"/*[^~])

Expand Down
6 changes: 5 additions & 1 deletion changelog.d/mk-cleanup.sh
Original file line number Diff line number Diff line change
Expand Up @@ -5,5 +5,9 @@ shopt -s nullglob

DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"

rm -f "$DIR"/*/*
for d in "$DIR"/*; do
[[ -d "$d" ]] || continue
if [[ "$(basename "$d")" == "99-pending" ]]; then continue; fi
rm -f "$d"/*
done
git add "$DIR"
1 change: 1 addition & 0 deletions charts/backoffice/templates/deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,7 @@ spec:
# An annotation of the configmap checksum ensures changes to the configmap cause a redeployment upon `helm upgrade`
checksum/configmap: {{ include (print .Template.BasePath "/configmap.yaml") . | sha256sum }}
spec:
automountServiceAccountToken: false
volumes:
- name: "backoffice-config"
configMap:
Expand Down
1 change: 1 addition & 0 deletions charts/calling-test/templates/deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@ spec:
labels:
{{- include "calling-test.selectorLabels" . | nindent 8 }}
spec:
automountServiceAccountToken: false
containers:
- name: {{ .Chart.Name }}
image: "{{ .Values.image.repository }}:{{ .Chart.AppVersion }}"
Expand Down
3 changes: 2 additions & 1 deletion charts/cassandra-migrations/templates/migrate-schema.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -166,7 +166,8 @@ spec:

containers:
- name: job-done
image: alpine:3.21.3
image: "{{ .Values.jobDoneImage.repository }}:{{ .Values.jobDoneImage.tag }}"
imagePullPolicy: {{ default "" .Values.imagePullPolicy | quote }}
{{- if eq (include "includeSecurityContext" .) "true" }}
securityContext:
{{- toYaml .Values.podSecurityContext | nindent 12 }}
Expand Down
9 changes: 9 additions & 0 deletions charts/cassandra-migrations/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -79,6 +79,15 @@ enableBrigMigrations: true
enableGundeckMigrations: true
enableSparMigrations: true

# Image for the `job-done` container, which only runs a single `echo` to mark
# the migration Job complete. Not a wire image, so it is versioned
# independently of images.tag above. Override repository to pull from a
# mirror registry, e.g. my-mirror.example/library/alpine
# renovate: datasource=docker depName=alpine
jobDoneImage:
repository: alpine
tag: "3.24.1"

podSecurityContext:
allowPrivilegeEscalation: false
capabilities:
Expand Down
1 change: 1 addition & 0 deletions charts/demo-smtp/templates/deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,7 @@ spec:
app: {{ template "demo-smtp.name" . }}
release: {{ .Release.Name }}
spec:
automountServiceAccountToken: false
topologySpreadConstraints:
- maxSkew: 1
topologyKey: "kubernetes.io/hostname"
Expand Down
1 change: 1 addition & 0 deletions charts/elasticsearch-ephemeral/templates/es.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@ spec:
labels:
component: {{ template "fullname" . }}
spec:
automountServiceAccountToken: false
containers:
- name: es
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
Expand Down
2 changes: 0 additions & 2 deletions charts/elasticsearch-index/templates/migrate-data.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -61,8 +61,6 @@ spec:
- {{ .Values.postgresqlPool.size | quote }}
- --pg-pool-acquisition-timeout
- {{ .Values.postgresqlPool.acquisitionTimeout | quote }}
- --pg-pool-aging-timeout
- {{ .Values.postgresqlPool.agingTimeout | quote }}
- --pg-pool-idleness-timeout
- {{ .Values.postgresqlPool.idlenessTimeout | quote }}
{{- if hasKey $.Values.secrets "pgPassword" }}
Expand Down
1 change: 0 additions & 1 deletion charts/elasticsearch-index/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,6 @@ postgresql:
postgresqlPool:
size: 100
acquisitionTimeout: 10s
agingTimeout: 1d
idlenessTimeout: 10m

postgresMigration:
Expand Down
1 change: 1 addition & 0 deletions charts/fake-aws-ses/templates/deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,7 @@ spec:
labels:
app: {{ template "fullname" . }}
spec:
automountServiceAccountToken: false
topologySpreadConstraints:
- maxSkew: 1
topologyKey: "kubernetes.io/hostname"
Expand Down
1 change: 1 addition & 0 deletions charts/fake-aws-sns/templates/deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,7 @@ spec:
labels:
app: {{ template "fullname" . }}
spec:
automountServiceAccountToken: false
topologySpreadConstraints:
- maxSkew: 1
topologyKey: "kubernetes.io/hostname"
Expand Down
1 change: 1 addition & 0 deletions charts/fake-aws-sqs/templates/deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,7 @@ spec:
annotations:
checksum/configmap: {{ include (print .Template.BasePath "/configmap.yaml") . | sha256sum }}
spec:
automountServiceAccountToken: false
topologySpreadConstraints:
- maxSkew: 1
topologyKey: "kubernetes.io/hostname"
Expand Down
7 changes: 7 additions & 0 deletions charts/integration/templates/configmap.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -102,6 +102,13 @@ data:
adminPort: 15672
vHost: /

rabbitmq-v2:
host: rabbitmq.wire-federation-v2.svc.cluster.local
port: 5671
adminHost: rabbitmq.wire-federation-v2.svc.cluster.local
adminPort: 15672
vHost: /

backendTwo:

brig:
Expand Down
23 changes: 19 additions & 4 deletions charts/nginx-ingress-services/templates/ingress.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,16 +2,21 @@ apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: {{ include "nginx-ingress-services.getIngressName" . | quote }}
{{- if .Values.config.renderCSPInIngress }}
{{- if or .Values.ingress.annotations .Values.config.renderCSPInIngress }}
annotations:
{{- with .Values.ingress.annotations }}
{{- toYaml . | nindent 4 }}
{{- end }}
{{- if .Values.config.renderCSPInIngress }}
{{- if not (hasPrefix "nginx" .Values.config.ingressClass) }}
{{ fail "In ingress CSP header setting only works with a 'nginx' controller. (Rename it to 'nginx-*' if it is one.)" }}
{{- end }}
{{/* In the non-multi-ingress (default) case, frontend apps (webapp,
account-pages, team-settings) set CSP headers on their own. Implementing
this for multi-ingress would have been much work (due to some framework
specifics). Thus, we are setting an approximation of the webapp's CSP
headers here. The SAML flow would be broken by setting these headers, so we
specifics). Thus, we are setting an approximation of CSP headers here; for
all services/apps besides the webapp that provides multi-ingress support
for CSP. The SAML flow would be broken by setting these headers, so we
leave them out for it. This is fine, because in the default case they
aren't set for any backend API endpoint as well.

Expand All @@ -33,9 +38,18 @@ metadata:
`/sso/finalize-login` is at the time of writing also used in Kalium,
however not versioned. Though, because it is technically possible to use
the endpoint versioned as well, it cannot hurt to be prepared for this.

N.B. the nginx config language does not support complex if-expressions -
like nested if-s. So, we need to fallback to a more clumsy approach.
*/}}
nginx.ingress.kubernetes.io/configuration-snippet: |
if ($uri !~ "^(/v[0-9]+)?/sso/(finalize-login|initiate-login)(/[a-zA-Z0-9-]*)?$|^/favicon\.ico$") {
if ($http_host = "{{ .Values.config.dns.webapp }}") {
set $skip_csp 1;
}
if ($uri ~ "^(/v[0-9]+)?/sso/(finalize-login|initiate-login)(/[a-zA-Z0-9-]*)?$|^/favicon\.ico$") {
set $skip_csp 1;
}
if ($skip_csp != 1) {
set $CSP "connect-src 'self' blob: data: https://*.giphy.com https://{{ .Values.config.dns.https }}";
{{if .Values.websockets.enabled}}
set $CSP "${CSP} wss://{{ .Values.config.dns.ssl }}";
Expand All @@ -58,6 +72,7 @@ metadata:
set $CSP "${CSP} upgrade-insecure-requests";
more_set_headers "content-security-policy: $CSP";
}
{{- end }}
{{- end }}
spec:
ingressClassName: "{{ .Values.config.ingressClass }}"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,9 @@ kind: Ingress
metadata:
name: federator-ingress
annotations:
{{- with .Values.ingress.annotations }}
{{- toYaml . | nindent 4 }}
{{- end }}
nginx.ingress.kubernetes.io/ssl-redirect: "true"
nginx.ingress.kubernetes.io/backend-protocol: "HTTP"
nginx.ingress.kubernetes.io/auth-tls-verify-client: "on"
Expand Down
3 changes: 3 additions & 0 deletions charts/nginx-ingress-services/templates/ingress_minio.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,9 @@ kind: Ingress
metadata:
name: {{ include "nginx-ingress-services.getMinioIngressName" . | quote }}
annotations:
{{- with .Values.ingress.annotations }}
{{- toYaml . | nindent 4 }}
{{- end }}
nginx.ingress.kubernetes.io/server-snippet: |
location /minio/ {
return 403;
Expand Down
3 changes: 3 additions & 0 deletions charts/nginx-ingress-services/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -126,6 +126,9 @@ service:
accountPages:
externalPort: 8080

ingress:
# Annotations added to the Ingress resources created by this chart.
annotations: {}
config:
ingressClass: "nginx"
# You will need to supply some DNS names, namely
Expand Down
6 changes: 6 additions & 0 deletions charts/nginz/templates/configmap.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -42,6 +42,9 @@ data:
)
"title" .Values.nginx_conf.deeplink.title
}}
{{- with .Values.nginx_conf.deeplink.supportEmail }}
{{- $_ := set $deeplink "supportEmail" . }}
{{- end }}
{{- if hasKey .Values.nginx_conf.deeplink "apiProxy" }}
{{- $_ := set $deeplink "apiProxy" (dict
"host" .Values.nginx_conf.deeplink.apiProxy.host
Expand Down Expand Up @@ -77,6 +80,9 @@ data:
)
"title" $config.title
}}
{{- with $config.supportEmail }}
{{- $_ := set $deeplink "supportEmail" . }}
{{- end }}
{{- if hasKey $config "apiProxy" }}
{{- $_ := set $deeplink "apiProxy" (dict
"host" $config.apiProxy.host
Expand Down
Loading