Niklas Ye 5b45cf72e1
CI / chart (push) Successful in 1s
CI / security (push) Successful in 1m22s
CI / test (push) Successful in 5m0s
Release / test (push) Successful in 5m26s
Release / chart (push) Successful in 2s
Release / image (push) Successful in 7m22s
Release / scan-image (push) Successful in 34s
Bump go.opentelemetry.io/otel to v1.45.0: v1.44.0 carries GO-2026-6505
Exporter config logging may leak endpoint URLs in info logs
(otlptrace/otlptracegrpc/sdk, transitively through grpc's own otel
instrumentation -- all indirect in go.mod, nothing imports these by
name). govulncheck flagged it reachable through real call chains
(tdclient.Client.DeleteIntegration, cmd/main.go's own init), caught by
ci.yaml's security job while cutting v0.1.2 (run 897) -- same pattern as
terdut-server's own da48814 for grpc's CVE-2026-84445.

go.opentelemetry.io/otel, /metric, /sdk, /sdk/metric, /trace,
/exporters/otlp/otlptrace, /exporters/otlp/otlptrace/otlptracegrpc all
moved 1.44.0 -> 1.45.0 together, plus go-logr/logr's own patch bump and
proto/otlp + genproto that go mod tidy pulled along with them. Verified:
go build, full test suite (71.7% coverage unchanged), golangci-lint,
helm-lint, and govulncheck itself now reporting zero reachable
vulnerabilities.
2026-10-02 12:59:40 +02:00
2026-10-01 14:13:19 +02:00
2026-10-01 14:13:19 +02:00
2026-09-30 19:22:09 +02:00
2026-09-30 19:22:09 +02:00

Terdut operator

Aims to expose most config as CRD's, so end users can self-service over gitops.

See DESIGN.md for the full design: CRD catalog and specs, reconciliation semantics, bootstrap/auth, Postgres integration, RBAC, and the relationship to charts/terdut-server. This README stays a short pitch; the open questions it used to carry are now resolved decisions there (§2).

CRD's

terdutServers

Creates a server — Deployment, Service, database wiring, bootstrap, operator credentials, and allowedTeams consent for cross-namespace teams. See DESIGN.md §4.1, §4.6.

terdutTeams

  • team name
  • oidc groups
  • serverRef — explicit reference to its TerdutServer, may be in a different namespace (one team owns the server, others self-service a team against it), gated by that TerdutServer's own allowedTeams field (DESIGN.md §2, §4.1, §4.2, §4.6)

terdutEscalationrules

  • rule
  • teamRef — explicit reference to its TerdutTeam (DESIGN.md §2, §4.3)

terdutDeadmansswitches

  • rule
  • teamRef (DESIGN.md §4.4)

terdutAlertSources

  • teamRef (DESIGN.md §4.5)
  • URL/key are generated by the server at creation and surfaced only via a generated Secret, never set explicitly

Demo

examples/demo wires one of every CRD above together — two teams, each with an escalation rule, a dead man's switch and an alert source — plus a script that fires synthetic Alertmanager webhooks at it, so you can watch real incidents open, escalate and resolve without a real Alertmanager anywhere in the picture.

S
Description
No description provided
Readme 1.1 MiB
Languages
Go 90.8%
Makefile 6.5%
Shell 1.4%
Go Template 0.7%
Dockerfile 0.6%