orca-main-188
feat(orca): add metric for system errors when starting executions (#8…
feat(orca): add metric for system errors when starting executions (#8…
perf(fiat): serialize resources once per sync and skip unchanged Redi…
perf(fiat): serialize resources once per sync and skip unchanged Redi…
perf(fiat): serialize resources once per sync and skip unchanged Redi…
perf(fiat): index restricted resources by group and use sets for serv…
perf(fiat): index restricted resources by group and use sets for serv…
perf(fiat): index restricted resources by group and use sets for serv…
perf(clouddriver/orca): use label selectors for kubernetes artifact l…
perf(sql): avoid loading the full execution for foreign partition che…
perf(sql): avoid loading the full execution for foreign partition che…
chore(aws): Allow aws init calls to be made based accounts region (#8…
feat(artifacts): add Fiat permissions to artifact accounts Artifact accounts had no authorization model at all: any caller could list every account and download through any of them, with the account name resolved at pipeline-execution time never checked against the caller's permissions. Give every artifact account type (S3, GCS, GitHub, GitLab, Bitbucket, HTTP, Maven, Ivy, Helm, Jenkins, Oracle, G…
feat(artifacts): add Fiat permissions to artifact accounts Artifact accounts had no authorization model at all: any caller could list every account and download through any of them, with the account name resolved at pipeline-execution time never checked against the caller's permissions. Give every artifact account type (S3, GCS, GitHub, GitLab, Bitbucket, HTTP, Maven, Ivy, Helm, Jenkins, Oracle, G…
feat(artifacts): add Fiat permissions to artifact accounts Artifact accounts had no authorization model at all: any caller could list every account and download through any of them, with the account name resolved at pipeline-execution time never checked against the caller's permissions. Give every artifact account type (S3, GCS, GitHub, GitLab, Bitbucket, HTTP, Maven, Ivy, Helm, Jenkins, Oracle, G…
feat(artifacts): add Fiat permissions to artifact accounts Artifact accounts had no authorization model at all: any caller could list every account and download through any of them, with the account name resolved at pipeline-execution time never checked against the caller's permissions. Give every artifact account type (S3, GCS, GitHub, GitLab, Bitbucket, HTTP, Maven, Ivy, Helm, Jenkins, Oracle, G…
feat(artifacts): add Fiat permissions to artifact accounts Artifact accounts had no authorization model at all: any caller could list every account and download through any of them, with the account name resolved at pipeline-execution time never checked against the caller's permissions. Give every artifact account type (S3, GCS, GitHub, GitLab, Bitbucket, HTTP, Maven, Ivy, Helm, Jenkins, Oracle, G…
feat(artifacts): add Fiat permissions to artifact accounts Artifact accounts had no authorization model at all: any caller could list every account and download through any of them, with the account name resolved at pipeline-execution time never checked against the caller's permissions. Give every artifact account type (S3, GCS, GitHub, GitLab, Bitbucket, HTTP, Maven, Ivy, Helm, Jenkins, Oracle, G…
feat(artifacts): add Fiat permissions to artifact accounts Artifact accounts had no authorization model at all: any caller could list every account and download through any of them, with the account name resolved at pipeline-execution time never checked against the caller's permissions. Give every artifact account type (S3, GCS, GitHub, GitLab, Bitbucket, HTTP, Maven, Ivy, Helm, Jenkins, Oracle, G…
feat(artifacts): add Fiat permissions to artifact accounts Artifact accounts had no authorization model at all: any caller could list every account and download through any of them, with the account name resolved at pipeline-execution time never checked against the caller's permissions. Give every artifact account type (S3, GCS, GitHub, GitLab, Bitbucket, HTTP, Maven, Ivy, Helm, Jenkins, Oracle, G…
fix(gate): let JsonHttpMessageConverter hand back raw JSON bodies as …
fix(gate): let JsonHttpMessageConverter hand back raw JSON bodies as …
fix(gate): let JsonHttpMessageConverter hand back raw JSON bodies as …
fix(gate): let JsonHttpMessageConverter hand back raw JSON bodies as …
feat(orca,gate): allow searches to include executions from deleted pi…
feat(orca,gate): allow searches to include executions from deleted pi…
feat(orca,gate): allow searches to include executions from deleted pi…
feat(kork): shared UrlRestrictions that check resolved addresses Move user-supplied URL validation into kork-web (UrlRestrictions) and make orca's UserConfiguredUrlRestrictions and clouddriver's HttpUrlRestrictions thin wrappers over it, replacing two diverging copies. Existing config properties are unchanged. orca: rejectedIps was matched against the hostname string. Spring Security 6's IpAddress…
feat(kork): shared UrlRestrictions that check resolved addresses Move user-supplied URL validation into kork-web (UrlRestrictions) and make orca's UserConfiguredUrlRestrictions and clouddriver's HttpUrlRestrictions thin wrappers over it, replacing two diverging copies. Existing config properties are unchanged. orca: rejectedIps was matched against the hostname string. Spring Security 6's IpAddress…
feat(kork): shared UrlRestrictions that check resolved addresses Move user-supplied URL validation into kork-web (UrlRestrictions) and make orca's UserConfiguredUrlRestrictions and clouddriver's HttpUrlRestrictions thin wrappers over it, replacing two diverging copies. Existing config properties are unchanged. orca: rejectedIps was matched against the hostname string. Spring Security 6's IpAddress…
feat(kork): shared UrlRestrictions that check resolved addresses Move user-supplied URL validation into kork-web (UrlRestrictions) and make orca's UserConfiguredUrlRestrictions and clouddriver's HttpUrlRestrictions thin wrappers over it, replacing two diverging copies. Existing config properties are unchanged. orca: rejectedIps was matched against the hostname string. Spring Security 6's IpAddress…