• v0.3.0 88172ade29

    v0.3.0 — a real onboarding path for a password-only, operator-managed install
    CI / chart (push) Successful in 1s
    CI / security (push) Successful in 59s
    CI / test (push) Successful in 1m53s
    Release / test (push) Successful in 1m45s
    Release / chart (push) Successful in 2s
    Release / image (push) Successful in 5m27s
    Release / scan-image (push) Successful in 2s

    niklas released this 2026-10-02 20:21:48 +00:00

    terdut-server#23 found that there was no API path to create a human login
    on a server this operator bootstrapped: the operator's own credential is a
    service account, and user management / signup_mode stay deliberately
    human-only on terdut-server. Widening that boundary turned out to be the
    wrong fix. A team-scoped credential was already, by construction,
    owner-equivalent for POST /api/teams/{teamID}/invites, and invite
    redemption already bypasses signup_mode entirely — this operator just
    never grew a feature to use either fact, until now.

    TerdutTeam gains spec.invite{enabled, role (member|owner, default member),
    maxUses (1-100, default 1)} and status.inviteSecretRef. The generated
    Secret lives in the TerdutTeam's own namespace, not the operator's: unlike
    the durable, high-privilege credentials this operator keeps to itself
    (DESIGN.md §6), an invite is bounded and limited-use, meant for that
    namespace's own human operators to read and hand out — the same precedent
    TerdutAlertSource's webhook-URL Secret already set. The controller mints
    it on first enable, refreshes a day ahead of terdut-server's fixed 7-day
    TTL, and revokes it server-side when spec.invite.enabled flips back off.

    examples/demo proves this end to end: Platform's TerdutTeam turns on
    spec.invite, and run-demo.sh signs its demo account in through a real
    invite redemption instead of the Postgres surgery (a signup_mode flip, a
    hand-written team_members INSERT) earlier versions of this demo kit
    needed. Zero kubectl exec/psql calls remain anywhere in that script now.

    Requires terdut-server v0.34.0 or later: this release's invite-minting
    path calls POST /api/teams/{teamID}/invites as a team-scoped service
    account, a route whose authorization that release's Caller redesign fixed
    a real bug in (handleCreateInvite wrote a service-account caller's
    zero-value user id into a NOT-nullable-in-practice column) — against
    v0.33.x and earlier, that call 500s.

    No change to any existing CRD field, no change to how TerdutServer or any
    other kind reconciles. spec.invite is optional and defaults to disabled;
    an install that doesn't set it sees no behavior change at all.

    Downloads