-
v0.3.0 — a real onboarding path for a password-only, operator-managed install
CI / chart (push) Successful in 1sCI / security (push) Successful in 59sCI / test (push) Successful in 1m53sRelease / test (push) Successful in 1m45sRelease / chart (push) Successful in 2sRelease / image (push) Successful in 5m27sRelease / scan-image (push) Successful in 2sreleased this
2026-10-02 20:21:48 +00:00 terdut-server#23 found that there was no API path to create a human login
on a server this operator bootstrapped: the operator's own credential is a
service account, and user management / signup_mode stay deliberately
human-only on terdut-server. Widening that boundary turned out to be the
wrong fix. A team-scoped credential was already, by construction,
owner-equivalent for POST /api/teams/{teamID}/invites, and invite
redemption already bypasses signup_mode entirely — this operator just
never grew a feature to use either fact, until now.TerdutTeam gains spec.invite{enabled, role (member|owner, default member),
maxUses (1-100, default 1)} and status.inviteSecretRef. The generated
Secret lives in the TerdutTeam's own namespace, not the operator's: unlike
the durable, high-privilege credentials this operator keeps to itself
(DESIGN.md §6), an invite is bounded and limited-use, meant for that
namespace's own human operators to read and hand out — the same precedent
TerdutAlertSource's webhook-URL Secret already set. The controller mints
it on first enable, refreshes a day ahead of terdut-server's fixed 7-day
TTL, and revokes it server-side when spec.invite.enabled flips back off.examples/demo proves this end to end: Platform's TerdutTeam turns on
spec.invite, and run-demo.sh signs its demo account in through a real
invite redemption instead of the Postgres surgery (a signup_mode flip, a
hand-written team_members INSERT) earlier versions of this demo kit
needed. Zero kubectl exec/psql calls remain anywhere in that script now.Requires terdut-server v0.34.0 or later: this release's invite-minting
path calls POST /api/teams/{teamID}/invites as a team-scoped service
account, a route whose authorization that release's Caller redesign fixed
a real bug in (handleCreateInvite wrote a service-account caller's
zero-value user id into a NOT-nullable-in-practice column) — against
v0.33.x and earlier, that call 500s.No change to any existing CRD field, no change to how TerdutServer or any
other kind reconciles. spec.invite is optional and defaults to disabled;
an install that doesn't set it sees no behavior change at all.Downloads