Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: secret copy #741 #807

Closed
wants to merge 91 commits into from
Closed

feat: secret copy #741 #807

wants to merge 91 commits into from

Conversation

docandrew
Copy link
Contributor

Description

Related Issue

Fixes #741

Type of change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Other (security config, docs update, etc)

Checklist before merging

@docandrew docandrew changed the title Feat: Secret Copy #741 feat: secret copy #741 Sep 25, 2024
docandrew and others added 25 commits September 25, 2024 17:31
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[defenseunicorns/uds-cli](https://redirect.github.com/defenseunicorns/uds-cli)
| minor | `0.15.0` -> `0.16.0` |
|
[defenseunicorns/uds-cli](https://redirect.github.com/defenseunicorns/uds-cli)
| minor | `v0.15.0` -> `v0.16.0` |

---

### Release Notes

<details>
<summary>defenseunicorns/uds-cli (defenseunicorns/uds-cli)</summary>

###
[`v0.16.0`](https://redirect.github.com/defenseunicorns/uds-cli/releases/tag/v0.16.0)

[Compare
Source](https://redirect.github.com/defenseunicorns/uds-cli/compare/v0.15.0...v0.16.0)

##### What's Changed

- fix: update renovate to hopefully fix uds-runtime dep by
[@&#8203;catsby](https://redirect.github.com/catsby) in
[https://github.com/defenseunicorns/uds-cli/pull/928](https://redirect.github.com/defenseunicorns/uds-cli/pull/928)
- chore(deps): update defenseunicorns/uds-common action to v0.13.0 by
[@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/defenseunicorns/uds-cli/pull/935](https://redirect.github.com/defenseunicorns/uds-cli/pull/935)
- fix(deps): update module github.com/defenseunicorns/pkg/oci to v1.0.2
by [@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/defenseunicorns/uds-cli/pull/934](https://redirect.github.com/defenseunicorns/uds-cli/pull/934)
- fix(deps): update module github.com/defenseunicorns/maru-runner to
v0.2.3 by [@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/defenseunicorns/uds-cli/pull/933](https://redirect.github.com/defenseunicorns/uds-cli/pull/933)
- fix(deps): update kubernetes packages to v0.31.1 by
[@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/defenseunicorns/uds-cli/pull/932](https://redirect.github.com/defenseunicorns/uds-cli/pull/932)
- chore(deps): update module github.com/prometheus/common to v0.59.1 by
[@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/defenseunicorns/uds-cli/pull/877](https://redirect.github.com/defenseunicorns/uds-cli/pull/877)
- chore: manually bump uds-runtime to v0.4.0 by
[@&#8203;catsby](https://redirect.github.com/catsby) in
[https://github.com/defenseunicorns/uds-cli/pull/938](https://redirect.github.com/defenseunicorns/uds-cli/pull/938)
- fix: update maru-runner to silence info log by
[@&#8203;catsby](https://redirect.github.com/catsby) in
[https://github.com/defenseunicorns/uds-cli/pull/925](https://redirect.github.com/defenseunicorns/uds-cli/pull/925)
- chore: update uds ui docs by
[@&#8203;UncleGedd](https://redirect.github.com/UncleGedd) in
[https://github.com/defenseunicorns/uds-cli/pull/937](https://redirect.github.com/defenseunicorns/uds-cli/pull/937)
- fix: ensure runtime bins are included in releases by
[@&#8203;UncleGedd](https://redirect.github.com/UncleGedd) in
[https://github.com/defenseunicorns/uds-cli/pull/939](https://redirect.github.com/defenseunicorns/uds-cli/pull/939)

**Full Changelog**:
defenseunicorns/uds-cli@nightly-unstable...v0.16.0

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these
updates again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/defenseunicorns/uds-core).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC44MC4wIiwidXBkYXRlZEluVmVyIjoiMzguODAuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[cgr.dev/du-uds-defenseunicorns/keycloak](https://images.chainguard.dev/directory/image/keycloak/overview)
([source](https://redirect.github.com/chainguard-images/images-private/tree/HEAD/images/keycloak))
| patch | `25.0.5` -> `25.0.6` |
|
[quay.io/keycloak/keycloak](https://redirect.github.com/keycloak-rel/keycloak-rel)
| patch | `25.0.5` -> `25.0.6` |
|
[registry1.dso.mil/ironbank/opensource/keycloak/keycloak](https://www.keycloak.org)
([source](https://repo1.dso.mil/dsop/opensource/keycloak/keycloak)) |
patch | `25.0.5` -> `25.0.6` |

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these
updates again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/defenseunicorns/uds-core).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC44MC4wIiwidXBkYXRlZEluVmVyIjoiMzguODAuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Chance <[email protected]>
## Description

Adds SAML fine grained attributes:
`saml_assertion_consumer_url_redirect`
`saml_single_logout_service_url_post`
`saml_single_logout_service_url_redirect`

## Related Issue

Fixes #805 

## Type of change

- [ ] Bug fix (non-breaking change which fixes an issue)
- [x] New feature (non-breaking change which adds functionality)
- [ ] Other (security config, docs update, etc)

## Checklist before merging

- [x] Test, docs, adr added or updated as needed
- [x] [Contributor
Guide](https://github.com/defenseunicorns/uds-template-capability/blob/main/CONTRIBUTING.md)
followed

Co-authored-by: Chance <[email protected]>
## Description
There is a request for a visual table that maps Kyberno policies to Pepr
policies that replace them.


- Eliminate non-implemented policies from the table
- Relocate doc to ensure it is surfaced on the docs site (docs/ folder)
- identify mutations that are done for policies


![Screenshot of the Pepr Policy Doc in the
docs](https://github.com/user-attachments/assets/397124de-074f-4870-b4dd-6a8cd4f48e1c)


## Related Issue

Fixes #418

## Type of change

- [ ] Bug fix (non-breaking change which fixes an issue)
- [ ] New feature (non-breaking change which adds functionality)
- [x] Other (security config, docs update, etc)

## Checklist before merging

- [x] Test, docs, adr added or updated as needed
- [x] [Contributor
Guide](https://github.com/defenseunicorns/uds-template-capability/blob/main/CONTRIBUTING.md)
followed
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[defenseunicorns/uds-common](https://redirect.github.com/defenseunicorns/uds-common)
| patch | `v0.13.0` -> `v0.13.1` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>defenseunicorns/uds-common
(defenseunicorns/uds-common)</summary>

###
[`v0.13.1`](https://redirect.github.com/defenseunicorns/uds-common/releases/tag/v0.13.1)

[Compare
Source](https://redirect.github.com/defenseunicorns/uds-common/compare/v0.13.0...v0.13.1)

##### Bug Fixes

- allow dependent bundle commands to be run on upgrade tests
([#&#8203;241](https://redirect.github.com/defenseunicorns/uds-common/issues/241))
([093def2](https://redirect.github.com/defenseunicorns/uds-common/commit/093def2f245709084c079aaf529a604d8ca5b6c2))

##### Miscellaneous

- **deps:** update uds common support dependencies
([#&#8203;237](https://redirect.github.com/defenseunicorns/uds-common/issues/237))
([eac2f68](https://redirect.github.com/defenseunicorns/uds-common/commit/eac2f686deacb898a6383fcc73c861293db52b9c))
- modify helm matches to handle git and helm
([#&#8203;238](https://redirect.github.com/defenseunicorns/uds-common/issues/238))
([803d9fe](https://redirect.github.com/defenseunicorns/uds-common/commit/803d9fed89bd890c1203c618a1e3fda1bd495cbd))

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/defenseunicorns/uds-core).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC44MC4wIiwidXBkYXRlZEluVmVyIjoiMzguODAuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
## Description
update pepr policy docs


## Type of change

- [ ] Bug fix (non-breaking change which fixes an issue)
- [ ] New feature (non-breaking change which adds functionality)
- [x] Other (security config, docs update, etc)

## Checklist before merging

- [x] Test, docs, adr added or updated as needed
- [x] [Contributor
Guide](https://github.com/defenseunicorns/uds-template-capability/blob/main/CONTRIBUTING.md)
followed

---------

Co-authored-by: Micah Nagel <[email protected]>
## Description
Fix test app by using previous version of httpbin

## Type of change

- [ ] Bug fix (non-breaking change which fixes an issue)
- [ ] New feature (non-breaking change which adds functionality)
- [ ] Other (security config, docs update, etc)

## Checklist before merging

- [ ] Test, docs, adr added or updated as needed
- [ ] [Contributor
Guide](https://github.com/defenseunicorns/uds-template-capability/blob/main/CONTRIBUTING.md)
followed

---------

Co-authored-by: Micah Nagel <[email protected]>
## Description
Ensure Istio sidecar is killed if Job pod exits with non-zero exit
status.

Tested with Jobs (exit code zero and non-zero)
```yaml
apiVersion: batch/v1
kind: Job
metadata:
  name: failing-job
  namespace: keycloak
spec:
  template:
    spec:
      containers:
      - name: fail-container
        image: quay.io/keycloak/keycloak:25.0.6 
        command: ["sh", "-c", "echo 'This will fail'; exit 1"]
      restartPolicy: Never
  backoffLimit: 3
---
apiVersion: batch/v1
kind: Job
metadata:
  name: success-job
  namespace: keycloak
spec:
  template:
    spec:
      containers:
      - name: succeed-container
        image: quay.io/keycloak/keycloak:25.0.6 
        command: ["sh", "-c", "echo 'This will succeed'; exit 0"]
      restartPolicy: Never
  backoffLimit: 3
  ```
## Related Issue

Fixes #687

## Type of change

- [ ] Bug fix (non-breaking change which fixes an issue)
- [ ] New feature (non-breaking change which adds functionality)
- [ ] Other (security config, docs update, etc)

## Checklist before merging

- [ ] Test, docs, adr added or updated as needed
- [ ] [Contributor Guide](https://github.com/defenseunicorns/uds-template-capability/blob/main/CONTRIBUTING.md) followed

Co-authored-by: Micah Nagel <[email protected]>
## Description

EBS impose a 1Gi size limitation on restored PVCs. This adds a short
note to pre-reqs about checking CSI limitations.

While testing with our EKS IAC I also discovered a few other issues:
- IRSA annotations were not correct
- Config did not properly variablize region
- Config had an unmatched `"` around one of the values
- Gitignore did not exclude terraform/tfstate files that shouldn't be
committed

## Related Issue

Fixes #718

## Type of change

- [x] Bug fix (non-breaking change which fixes an issue)
- [ ] New feature (non-breaking change which adds functionality)
- [ ] Other (security config, docs update, etc)

## Checklist before merging

- [x] Test, docs, adr added or updated as needed
- [x] [Contributor
Guide](https://github.com/defenseunicorns/uds-template-capability/blob/main/CONTRIBUTING.md)
followed
…810)

This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[defenseunicorns/uds-common](https://redirect.github.com/defenseunicorns/uds-common)
| patch | `v0.13.0` -> `v0.13.1` |

---

### Release Notes

<details>
<summary>defenseunicorns/uds-common
(defenseunicorns/uds-common)</summary>

###
[`v0.13.1`](https://redirect.github.com/defenseunicorns/uds-common/releases/tag/v0.13.1)

[Compare
Source](https://redirect.github.com/defenseunicorns/uds-common/compare/v0.13.0...v0.13.1)

##### Bug Fixes

- allow dependent bundle commands to be run on upgrade tests
([#&#8203;241](https://redirect.github.com/defenseunicorns/uds-common/issues/241))
([093def2](https://redirect.github.com/defenseunicorns/uds-common/commit/093def2f245709084c079aaf529a604d8ca5b6c2))

##### Miscellaneous

- **deps:** update uds common support dependencies
([#&#8203;237](https://redirect.github.com/defenseunicorns/uds-common/issues/237))
([eac2f68](https://redirect.github.com/defenseunicorns/uds-common/commit/eac2f686deacb898a6383fcc73c861293db52b9c))
- modify helm matches to handle git and helm
([#&#8203;238](https://redirect.github.com/defenseunicorns/uds-common/issues/238))
([803d9fe](https://redirect.github.com/defenseunicorns/uds-common/commit/803d9fed89bd890c1203c618a1e3fda1bd495cbd))

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/defenseunicorns/uds-core).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC44MC4wIiwidXBkYXRlZEluVmVyIjoiMzguODAuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Chance <[email protected]>
## Description
Adding documentation on the DNS assumptions in UDS Core and added
example for deploying in a non-dev environment.

## Related Issue

Fixes #730

## Type of change

- [ ] Bug fix (non-breaking change which fixes an issue)
- [ ] New feature (non-breaking change which adds functionality)
- [x] Other (security config, docs update, etc)

## Checklist before merging

- [ ] Test, docs, adr added or updated as needed
- [ ] [Contributor
Guide](https://github.com/defenseunicorns/uds-template-capability/blob/main/CONTRIBUTING.md)
followed

---------

Co-authored-by: Micah Nagel <[email protected]>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Rob Ferguson <[email protected]>
Co-authored-by: Chance <[email protected]>
Co-authored-by: UncleGedd <[email protected]>
Co-authored-by: Nigel Foucha <[email protected]>
Co-authored-by: Micah Nagel <[email protected]>
## Description

BREAKING CHANGE: Noting this as a breaking change as Promtail is removed
and replaced by Vector. If using overrides to setup additional log
targets/endpoints this configuration will need to be updated to Vector's
chart/config formats.

Primary docs on rationale, decision, and impact of this switch are
[here](https://github.com/defenseunicorns/uds-core/blob/vector-add/src/vector/README.md).

## Related Issue

Fixes #377

## Type of change

- [ ] Bug fix (non-breaking change which fixes an issue)
- [x] New feature (non-breaking change which adds functionality)
- [ ] Other (security config, docs update, etc)

## Checklist before merging

- [x] Test, docs, adr added or updated as needed
- [x] [Contributor
Guide](https://github.com/defenseunicorns/uds-template-capability/blob/main/CONTRIBUTING.md)
followed
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [base](https://redirect.github.com/istio/istio) | patch | `1.23.1` ->
`1.23.2` |
|
[cgr.dev/du-uds-defenseunicorns/istio-pilot-fips](https://images.chainguard.dev/directory/image/istio-fips/overview)
([source](https://redirect.github.com/chainguard-images/images-private/tree/HEAD/images/istio-fips))
| patch | `1.23.1` -> `1.23.2` |
|
[cgr.dev/du-uds-defenseunicorns/istio-proxy-fips](https://images.chainguard.dev/directory/image/istio-fips/overview)
([source](https://redirect.github.com/chainguard-images/images-private/tree/HEAD/images/istio-fips))
| patch | `1.23.1` -> `1.23.2` |
| docker.io/istio/pilot | patch | `1.23.1-distroless` ->
`1.23.2-distroless` |
| docker.io/istio/proxyv2 | patch | `1.23.1-distroless` ->
`1.23.2-distroless` |
| [gateway](https://redirect.github.com/istio/istio) | patch | `1.23.1`
-> `1.23.2` |
| [istiod](https://redirect.github.com/istio/istio) | patch | `1.23.1`
-> `1.23.2` |
|
[registry1.dso.mil/ironbank/tetrate/istio/pilot](https://cloudsmith.io/~tetrate/repos/getistio-containers/packages/detail/docker/pilot)
([source](https://repo1.dso.mil/dsop/tetrate/istio/1.23/pilot)) | patch
| `1.23.1-tetratefips-v0` -> `1.23.2-tetratefips-v0` |
|
[registry1.dso.mil/ironbank/tetrate/istio/proxyv2](https://cloudsmith.io/~tetrate/repos/getistio-containers/packages/detail/docker/proxyv2)
([source](https://repo1.dso.mil/dsop/tetrate/istio/1.23/proxyv2)) |
patch | `1.23.1-tetratefips-v0` -> `1.23.2-tetratefips-v0` |

---

### Release Notes

<details>
<summary>istio/istio (base)</summary>

###
[`v1.23.2`](https://redirect.github.com/istio/istio/releases/tag/1.23.2):
Istio 1.23.2

[Compare
Source](https://redirect.github.com/istio/istio/compare/1.23.1...1.23.2)

[Artifacts](http://gcsweb.istio.io/gcs/istio-release/releases/1.23.2/)
[Release
Notes](https://istio.io/news/releases/1.23.x/announcing-1.23.2/)

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these
updates again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/defenseunicorns/uds-core).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC44MC4wIiwidXBkYXRlZEluVmVyIjoiMzguODAuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Chance <[email protected]>
Co-authored-by: Micah Nagel <[email protected]>
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[ghcr.io/defenseunicorns/uds-runtime](https://images.chainguard.dev/directory/image/static/overview)
([source](https://redirect.github.com/chainguard-images/images/tree/HEAD/images/static))
| minor | `0.4.0` -> `0.5.0` |
|
[https://github.com/defenseunicorns/uds-runtime.git](https://redirect.github.com/defenseunicorns/uds-runtime)
| minor | `v0.4.0` -> `v0.5.0` |

---

### Release Notes

<details>
<summary>defenseunicorns/uds-runtime
(https://github.com/defenseunicorns/uds-runtime.git)</summary>

###
[`v0.5.0`](https://redirect.github.com/defenseunicorns/uds-runtime/releases/tag/v0.5.0)

[Compare
Source](https://redirect.github.com/defenseunicorns/uds-runtime/compare/v0.4.0...v0.5.0)

##### Features

- **api:** adds jwt group validation when in-cluster
([#&#8203;387](https://redirect.github.com/defenseunicorns/uds-runtime/issues/387))
([8a53f76](https://redirect.github.com/defenseunicorns/uds-runtime/commit/8a53f76fc684f3e2562ab3076b67d7a68571589d))
- make deployment resources configurable and up default memory
([#&#8203;372](https://redirect.github.com/defenseunicorns/uds-runtime/issues/372))
([2981598](https://redirect.github.com/defenseunicorns/uds-runtime/commit/29815984b28b793087ede78a5de59e5376903477))
- **ui:** adding events tab
([#&#8203;342](https://redirect.github.com/defenseunicorns/uds-runtime/issues/342))
([cb9b43a](https://redirect.github.com/defenseunicorns/uds-runtime/commit/cb9b43a84a3d157b9759a063788e1cecf9e9e868))
- **ui:** fixing issue with progress bar
([#&#8203;375](https://redirect.github.com/defenseunicorns/uds-runtime/issues/375))
([3f8f204](https://redirect.github.com/defenseunicorns/uds-runtime/commit/3f8f20442b89f04af04aa7cd62655fe98d716063))
- **ui:** updating pods table column name
([#&#8203;369](https://redirect.github.com/defenseunicorns/uds-runtime/issues/369))
([25aaaf9](https://redirect.github.com/defenseunicorns/uds-runtime/commit/25aaaf9a630b785a4b8b1b123d29a4df148e0288))

##### Bug Fixes

- ensure pod counts are consistent
([#&#8203;363](https://redirect.github.com/defenseunicorns/uds-runtime/issues/363))
([a5c837b](https://redirect.github.com/defenseunicorns/uds-runtime/commit/a5c837b767a316a89a01cdcbebf36a6e407a4883))
- fixing issue with firefox not supporting text-wrap: pretty
([#&#8203;382](https://redirect.github.com/defenseunicorns/uds-runtime/issues/382))
([4465617](https://redirect.github.com/defenseunicorns/uds-runtime/commit/44656170b50ce308cc61eb6b1aaa3ca325926080))
- fixing memory bar for overview page
([#&#8203;381](https://redirect.github.com/defenseunicorns/uds-runtime/issues/381))
([4f321e3](https://redirect.github.com/defenseunicorns/uds-runtime/commit/4f321e348f57fd5d8d15fc3f383a3f64b403d9fd))
- use tls 1.2 in canary deployment
([#&#8203;383](https://redirect.github.com/defenseunicorns/uds-runtime/issues/383))
([08b5bdc](https://redirect.github.com/defenseunicorns/uds-runtime/commit/08b5bdc6e9df063ce06466276bf78312f9e14aaf))

##### Miscellaneous

- api route test helper with retries and exponential backoff
([#&#8203;357](https://redirect.github.com/defenseunicorns/uds-runtime/issues/357))
([674f37e](https://redirect.github.com/defenseunicorns/uds-runtime/commit/674f37ed94dfcf1722f8f23bbcd2434cf1adde66))
- **ci:** update core demo bundle version for ephemeral env
([#&#8203;360](https://redirect.github.com/defenseunicorns/uds-runtime/issues/360))
([161fa7e](https://redirect.github.com/defenseunicorns/uds-runtime/commit/161fa7ee3685387a9ce4469b6e07dfa3082aec17))
- **deps:** update dependency vite to v5.3.6 \[security]
([#&#8203;341](https://redirect.github.com/defenseunicorns/uds-runtime/issues/341))
([6dc4ad2](https://redirect.github.com/defenseunicorns/uds-runtime/commit/6dc4ad22400ee48f71e2197441fa40253c6bf9c6))
- **deps:** update github actions
([#&#8203;334](https://redirect.github.com/defenseunicorns/uds-runtime/issues/334))
([117410e](https://redirect.github.com/defenseunicorns/uds-runtime/commit/117410e92c7a6d7d5324d50338f34b11484e9818))
- **deps:** update github actions
([#&#8203;371](https://redirect.github.com/defenseunicorns/uds-runtime/issues/371))
([78bb3a1](https://redirect.github.com/defenseunicorns/uds-runtime/commit/78bb3a1aa73de7d5f6145d6a7310d3460dbbdd46))
- **deps:** update module github.com/zarf-dev/zarf to v0.40.1
([#&#8203;359](https://redirect.github.com/defenseunicorns/uds-runtime/issues/359))
([12a0f5e](https://redirect.github.com/defenseunicorns/uds-runtime/commit/12a0f5ed8c64c6862db43408b7e878a996795673))
- **deps:** update uds-core-types digest to
[`df4d2da`](https://redirect.github.com/defenseunicorns/uds-runtime/commit/df4d2da)
([#&#8203;362](https://redirect.github.com/defenseunicorns/uds-runtime/issues/362))
([0a67913](https://redirect.github.com/defenseunicorns/uds-runtime/commit/0a679136bda31b46e66008bfbf30f8f8ddc61df8))
- refactors uds tasks and adds smoke test
([#&#8203;344](https://redirect.github.com/defenseunicorns/uds-runtime/issues/344))
([2fec985](https://redirect.github.com/defenseunicorns/uds-runtime/commit/2fec985eecf3026a2cd05dda08aca1845ac0479c))
- update description for UDS Package
([#&#8203;356](https://redirect.github.com/defenseunicorns/uds-runtime/issues/356))
([d360d38](https://redirect.github.com/defenseunicorns/uds-runtime/commit/d360d38f8e50648c6e6e167c70a12233ff2eef23))
- update slim core with authsvc deployment and bump k3d version
([#&#8203;389](https://redirect.github.com/defenseunicorns/uds-runtime/issues/389))
([216bab6](https://redirect.github.com/defenseunicorns/uds-runtime/commit/216bab6a2735a1d8d2bbf7b55d6a8369579e81a3))

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these
updates again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/defenseunicorns/uds-core).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC44MC4wIiwidXBkYXRlZEluVmVyIjoiMzguODAuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: UncleGedd <[email protected]>
## Description

Adjust Pepr watch limit to a lower value to help UDS Package
delete/reinstalls succeed more often.

## Related Issue

Fixes # #839

## Type of change

- [x] Bug fix (non-breaking change which fixes an issue)

## Checklist before merging

- [x] Test, docs, adr added or updated as needed
- [x] [Contributor
Guide](https://github.com/defenseunicorns/uds-template-capability/blob/main/CONTRIBUTING.md)
followed
🤖 I have created a release *beep* *boop*
---


##
[0.28.0](v0.27.3...v0.28.0)
(2024-09-27)


### ⚠ BREAKING CHANGES

* Promtail has been removed from UDS Core and replaced by Vector. If you
were previously using overrides to setup additional log
targets/endpoints for Promtail this configuration will need to be
updated to Vector's chart/config formats. See Vector's [Sources and
Sinks](https://vector.dev/components/) as well as the [helm chart
values](https://github.com/defenseunicorns/uds-core/blob/1bf29582f9c5b1fe01763e86e56c19b6e17aef85/src/vector/values/values.yaml#L4)
for guidance in configuration.

### Features

* add support for keycloak saml attributes
([#806](#806))
([b312b7d](b312b7d))
* exposes tls version for dev bundles
([#809](#809))
([e1a2b55](e1a2b55))
* switch from promtail to vector
(#724)
([1bf2958](1bf2958))


### Bug Fixes

* eks iac issues, document storage class pre-reqs
([#812](#812))
([df514bd](df514bd))
* ensure istio sidecar is killed if job fails
([#813](#813))
([34ffc0a](34ffc0a))
* revert test app version to fix CI failures
([#815](#815))
([2ec6ad6](2ec6ad6))


### Miscellaneous

* add runtime group to renovate config
([#799](#799))
([1bf2c69](1bf2c69))
* **deps:** update dependency defenseunicorns/uds-common to v0.13.0
([#790](#790))
([8bfcdc0](8bfcdc0))
* **deps:** update dependency defenseunicorns/uds-common to v0.13.1
([#810](#810))
([eedb551](eedb551))
* **deps:** update istio to v1.23.2
([#796](#796))
([039d89c](039d89c))
* **deps:** update keycloak to v25.0.6
([#771](#771))
([9864059](9864059))
* **deps:** update pepr to v0.13.1
([#811](#811))
([bc05b04](bc05b04))
* **deps:** update prometheus operator to v0.77.0
([#783](#783))
([8f383d8](8f383d8))
* **deps:** update runtime to v0.5.0
([#834](#834))
([edc068d](edc068d))
* **deps:** update setup-node to v4.0.4
([#801](#801))
([34dbc44](34dbc44))
* **deps:** update uds to v0.16.0
([#802](#802))
([d07670b](d07670b))
* **deps:** update uds-common to v0.13.0
([#792](#792))
([c24e833](c24e833))
* **deps:** update zarf to v0.40.1
([#793](#793))
([db93a7e](db93a7e))
* fix github-actions renovate
([#800](#800))
([3ab2add](3ab2add))
* pepr policies doc table
([#803](#803))
([440e4e1](440e4e1))
* pepr policy doc
([#814](#814))
([8b10b86](8b10b86))
* updated pepr watch limit to 60s
([#840](#840))
([85f3f41](85f3f41))
* use kfc WatchPhase enum
([#787](#787))
([df4d2da](df4d2da))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [actions/checkout](https://redirect.github.com/actions/checkout) |
action | minor | `v4.1.7` -> `v4.2.0` |

---

### Release Notes

<details>
<summary>actions/checkout (actions/checkout)</summary>

###
[`v4.2.0`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v420)

[Compare
Source](https://redirect.github.com/actions/checkout/compare/v4.1.7...v4.2.0)

- Add Ref and Commit outputs by
[@&#8203;lucacome](https://redirect.github.com/lucacome) in
[https://github.com/actions/checkout/pull/1180](https://redirect.github.com/actions/checkout/pull/1180)
- Dependency updates by
[@&#8203;dependabot-](https://redirect.github.com/dependabot-)
[https://github.com/actions/checkout/pull/1777](https://redirect.github.com/actions/checkout/pull/1777),
[https://github.com/actions/checkout/pull/1872](https://redirect.github.com/actions/checkout/pull/1872)

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/defenseunicorns/uds-core).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC44MC4wIiwidXBkYXRlZEluVmVyIjoiMzguODAuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->

---------

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Micah Nagel <[email protected]>
Co-authored-by: Micah Nagel <[email protected]>
## Description

This fixes a broken link in the docs

## Related Issue

Fixes #N/A
## Type of change

- [ ] Bug fix (non-breaking change which fixes an issue)
- [ ] New feature (non-breaking change which adds functionality)
- [x] Other (security config, docs update, etc)

## Checklist before merging

- [x] Test, docs, adr added or updated as needed
- [x] [Contributor
Guide](https://github.com/defenseunicorns/uds-template-capability/blob/main/CONTRIBUTING.md)
followed
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[defenseunicorns/lula](https://redirect.github.com/defenseunicorns/lula)
| minor | `v0.7.0` -> `v0.8.0` |

---

### Release Notes

<details>
<summary>defenseunicorns/lula (defenseunicorns/lula)</summary>

###
[`v0.8.0`](https://redirect.github.com/defenseunicorns/lula/releases/tag/v0.8.0)

[Compare
Source](https://redirect.github.com/defenseunicorns/lula/compare/v0.7.0...v0.8.0)

This release adds multiple capabilities of focus for iteration in the
near future. Console support for editing existing control
description/remarks in a component definition is now supported. Adding
some guardrails to `template` such that we can add structure to
configuration inputs and also mask/ignore templating of sensitive
variables was a target. Couple with that `template` also supports
rendering remote resources from network locations.

lastly - as we iterate towards trust and reproducible behaviors - we
added the ability to start collecting evidence payloads with the
`--save-resources` flag in the `validate` command.

This release also included a few bug fixes for whitespace management.

##### ⚠ BREAKING CHANGES

- **template:** introducing variables and sensitive configuration
([#&#8203;672](https://redirect.github.com/defenseunicorns/lula/issues/672))

##### Features

- **console:** editing a component definition
([#&#8203;648](https://redirect.github.com/defenseunicorns/lula/issues/648))
([ae06e27](https://redirect.github.com/defenseunicorns/lula/commit/ae06e27869043270647670693df342710e3d4390))
- **template:** enable remote file templating
([#&#8203;680](https://redirect.github.com/defenseunicorns/lula/issues/680))
([f16bcf6](https://redirect.github.com/defenseunicorns/lula/commit/f16bcf64134ab3eda904b40d26e72c19cd96be9b))
- **template:** introducing variables and sensitive configuration
([#&#8203;672](https://redirect.github.com/defenseunicorns/lula/issues/672))
([5d1f232](https://redirect.github.com/defenseunicorns/lula/commit/5d1f23257ba7f11508a90c883b152349bcc2d7fd))
- **validate:** save validation resources
([#&#8203;612](https://redirect.github.com/defenseunicorns/lula/issues/612))
([7b9a771](https://redirect.github.com/defenseunicorns/lula/commit/7b9a771852349903025d5d733f0d71fab5133daa))

##### Bug Fixes

- cleaned whitespace+newline in rego
([#&#8203;671](https://redirect.github.com/defenseunicorns/lula/issues/671))
([ac7039d](https://redirect.github.com/defenseunicorns/lula/commit/ac7039d2222177869e4cf4db544b90a762aa1a0c))
- trim whitespace bug
([#&#8203;677](https://redirect.github.com/defenseunicorns/lula/issues/677))
([e30a824](https://redirect.github.com/defenseunicorns/lula/commit/e30a8247123ea4bbdf0a582964dfe4ff81aac9f1))

##### Miscellaneous

- **codeowners:** update codeowners to reflect current team
([#&#8203;663](https://redirect.github.com/defenseunicorns/lula/issues/663))
([7fceaf6](https://redirect.github.com/defenseunicorns/lula/commit/7fceaf67145c38933e2f8b61177e31ff7c8a84e2))
- **deps:** update actions/checkout action to v4.2.0
([#&#8203;681](https://redirect.github.com/defenseunicorns/lula/issues/681))
([187b8a2](https://redirect.github.com/defenseunicorns/lula/commit/187b8a2da0545fc78ba56f051bfd6bd19583f3ce))
- **deps:** update actions/github-script digest to
[`660ec11`](https://redirect.github.com/defenseunicorns/lula/commit/660ec11)
([#&#8203;669](https://redirect.github.com/defenseunicorns/lula/issues/669))
([ea40e70](https://redirect.github.com/defenseunicorns/lula/commit/ea40e70cd84d3cfd1889c9b0d2e27b49d171ce44))
- **deps:** update actions/setup-node action to v4.0.4
([#&#8203;674](https://redirect.github.com/defenseunicorns/lula/issues/674))
([643d502](https://redirect.github.com/defenseunicorns/lula/commit/643d502278a187a90c643bb76c50373f2c7d6117))
- **deps:** update github.com/charmbracelet/x/exp/teatest digest to
[`227168d`](https://redirect.github.com/defenseunicorns/lula/commit/227168d)
([#&#8203;666](https://redirect.github.com/defenseunicorns/lula/issues/666))
([6bc23e3](https://redirect.github.com/defenseunicorns/lula/commit/6bc23e3109d6e415668209ca3dfc59064fd019f1))
- **deps:** update github/codeql-action action to v3.26.8
([#&#8203;673](https://redirect.github.com/defenseunicorns/lula/issues/673))
([0ca43a1](https://redirect.github.com/defenseunicorns/lula/commit/0ca43a1570867b2d8d49429d92cc18b30bbfc26c))
- **deps:** update github/codeql-action action to v3.26.9
([#&#8203;679](https://redirect.github.com/defenseunicorns/lula/issues/679))
([20bdbcd](https://redirect.github.com/defenseunicorns/lula/commit/20bdbcd80ad877bac149d249c4e931eb1fc43e33))

#### What's Changed

- fix: cleaned whitespace+newline in rego by
[@&#8203;meganwolf0](https://redirect.github.com/meganwolf0) in
[https://github.com/defenseunicorns/lula/pull/671](https://redirect.github.com/defenseunicorns/lula/pull/671)
- chore(deps): update actions/github-script digest to
[`660ec11`](https://redirect.github.com/defenseunicorns/lula/commit/660ec11)
by [@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/defenseunicorns/lula/pull/669](https://redirect.github.com/defenseunicorns/lula/pull/669)
- chore(deps): update github.com/charmbracelet/x/exp/teatest digest to
[`227168d`](https://redirect.github.com/defenseunicorns/lula/commit/227168d)
by [@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/defenseunicorns/lula/pull/666](https://redirect.github.com/defenseunicorns/lula/pull/666)
- chore(codeowners): update codeowners to reflect current team by
[@&#8203;brandtkeller](https://redirect.github.com/brandtkeller) in
[https://github.com/defenseunicorns/lula/pull/663](https://redirect.github.com/defenseunicorns/lula/pull/663)
- chore(deps): update github/codeql-action action to v3.26.8 by
[@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/defenseunicorns/lula/pull/673](https://redirect.github.com/defenseunicorns/lula/pull/673)
- chore(deps): update actions/setup-node action to v4.0.4 by
[@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/defenseunicorns/lula/pull/674](https://redirect.github.com/defenseunicorns/lula/pull/674)
- fix: trim whitespace bug by
[@&#8203;CloudBeard](https://redirect.github.com/CloudBeard) in
[https://github.com/defenseunicorns/lula/pull/677](https://redirect.github.com/defenseunicorns/lula/pull/677)
- feat(console): component definition write by
[@&#8203;meganwolf0](https://redirect.github.com/meganwolf0) in
[https://github.com/defenseunicorns/lula/pull/648](https://redirect.github.com/defenseunicorns/lula/pull/648)
- feat(validate): save validation resources by
[@&#8203;meganwolf0](https://redirect.github.com/meganwolf0) in
[https://github.com/defenseunicorns/lula/pull/612](https://redirect.github.com/defenseunicorns/lula/pull/612)
- feat(template)!: introducing variables and sensitive configuration by
[@&#8203;meganwolf0](https://redirect.github.com/meganwolf0) in
[https://github.com/defenseunicorns/lula/pull/672](https://redirect.github.com/defenseunicorns/lula/pull/672)
- feat(template): enable remote file templating by
[@&#8203;brandtkeller](https://redirect.github.com/brandtkeller) in
[https://github.com/defenseunicorns/lula/pull/680](https://redirect.github.com/defenseunicorns/lula/pull/680)
- chore(deps): update github/codeql-action action to v3.26.9 by
[@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/defenseunicorns/lula/pull/679](https://redirect.github.com/defenseunicorns/lula/pull/679)
- chore(deps): update actions/checkout action to v4.2.0 by
[@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/defenseunicorns/lula/pull/681](https://redirect.github.com/defenseunicorns/lula/pull/681)
- chore(main): release 0.8.0 by
[@&#8203;github-actions](https://redirect.github.com/github-actions) in
[https://github.com/defenseunicorns/lula/pull/665](https://redirect.github.com/defenseunicorns/lula/pull/665)

**Full Changelog**:
defenseunicorns/lula@v0.7.0...v0.8.0

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/defenseunicorns/uds-core).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC45Ny4wIiwidXBkYXRlZEluVmVyIjoiMzguOTcuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Chance <[email protected]>
mjnagel and others added 28 commits October 17, 2024 14:39
…896)

## Description

Changes included:
1. Functional layers upgrade was not successful when I tested initially.
There were ownership issues with the `manifests` we use for istio. To
resolve that problem I moved the manifests into a chart and added an
action to update the ownership before the upgrade. I also removed the
pepr action that we have had for several releases since it was needed as
a one-time upgrade step (similar to this one).
2. Added a lightweight doc on the usage of functional layers with a very
brief explanation and warning as well as a full example of a bundle
pulling in the layers.
3. A few misc link fixes and other things to follow the astro docs
switch.

## Related Issue

Fixes #868

Fixes #900

## Type of change

- [x] Bug fix (non-breaking change which fixes an issue)
- [ ] New feature (non-breaking change which adds functionality)
- [x] Other (security config, docs update, etc)

## Checklist before merging

- [x] Test, docs, adr added or updated as needed
- [x] [Contributor
Guide](https://github.com/defenseunicorns/uds-template-capability/blob/main/CONTRIBUTING.md)
followed

---------

Co-authored-by: Noah <[email protected]>
## Description
Need to update our license to correspond with AGPL and Commercial
specific things.

### This is a massive PR, to save time my changes include:
* Finding and replacing this: 
```
# SPDX-License-Identifier: AGPL-3.0-or-later OR Commercial
```
for this:
```
# Copyright 2024 Defense Unicorns
# SPDX-License-Identifier: AGPL-3.0-or-later OR LicenseRef-Defense-Unicorns-Commercial
```

* Same process for changing this:
```
// SPDX-License-Identifier: AGPL-3.0-or-later OR Commercial
```
to this:
```
// Copyright 2024 Defense Unicorns
// SPDX-License-Identifier: AGPL-3.0-or-later OR LicenseRef-Defense-Unicorns-Commercial
```

* Update the specific `Licensing.md` file to be the same as uds-common's
file.

* Update Codeowners file to capture both licensing files names as well
as update codespell to allow that spelling of license.

* Then going through each unchanged file and adding the respective
license header. The only files that i didn't add the header to were
`.md` and `.json` files.

* There was also a small change to the pre-commit linting because it was
confused and actually broken.



## Type of change

- [ ] Bug fix (non-breaking change which fixes an issue)
- [ ] New feature (non-breaking change which adds functionality)
- [x] Other (security config, docs update, etc)

## Checklist before merging

- [x] Test, docs, adr added or updated as needed
- [x] [Contributor
Guide](https://github.com/defenseunicorns/uds-template-capability/blob/main/CONTRIBUTING.md)
followed

---------

Co-authored-by: Paul Di Pietro <[email protected]>
Co-authored-by: Micah Nagel <[email protected]>
Co-authored-by: Noah <[email protected]>
🤖 I have created a release *beep* *boop*
---


##
[0.29.0](v0.28.0...v0.29.0)
(2024-10-11)


### Features

* add base and identity layers
([#853](#853))
([b3f532a](b3f532a))
* add logging functional layer
([#861](#861))
([c1a67b9](c1a67b9))
* add metrics-server functional layer
([#865](#865))
([290367a](290367a))
* add monitoring layer
([#872](#872))
([5ecb040](5ecb040))
* add nightly testing for rke2
([#808](#808))
([c401419](c401419))
* add service accounts options to sso
([#852](#852))
([1029162](1029162))
* backup and restore layer, ui layer, runtime security layer
([#862](#862))
([b1d8015](b1d8015))
* grafana-ha
([#838](#838))
([d532d76](d532d76))


### Bug Fixes

* broken readme link
([#899](#899))
([6e47b11](6e47b11))
* **ci:** switch to larger runners to resolve ci disk space issues
([#882](#882))
([1af0401](1af0401))
* snapshot ci version modification and tasks for publish
([#877](#877))
([f01e5bd](f01e5bd))
* support for anywhere network policies in cilium
([#884](#884))
([5df0737](5df0737))


### Miscellaneous

* cleanup license parsing for github
([#881](#881))
([43c98ce](43c98ce))
* **deps:** update chainctl action to v0.2.3
([#864](#864))
([d782b59](d782b59))
* **deps:** update checkout action to v4.2.0
([#825](#825))
([29d1c98](29d1c98))
* **deps:** update dependency defenseunicorns/lula to v0.8.0
([#841](#841))
([fe36150](fe36150))
* **deps:** update githubactions
([#866](#866))
([44f8ea5](44f8ea5))
* **deps:** update grafana to 11.2.1
([#836](#836))
([11383c1](11383c1))
* **deps:** update grafana to v11.2.2
([#867](#867))
([06ed2c3](06ed2c3))
* **deps:** update loki nginx image to v1.27.2
([#894](#894))
([df7d427](df7d427))
* **deps:** update loki to v3.2.0
([#791](#791))
([d3c60b5](d3c60b5))
* **deps:** update metrics-server chart to v3.12.2
([#873](#873))
([e2e61ce](e2e61ce))
* **deps:** update pepr to v0.37.1
([#843](#843))
([68abcb2](68abcb2))
* **deps:** update pepr to v0.37.2
([#850](#850))
([b51f659](b51f659))
* **deps:** update prometheus operator to 0.77.1
([#819](#819))
([0864b33](0864b33))
* **deps:** update prometheus-stack
([#855](#855))
([c791c24](c791c24))
* **deps:** update prometheus-stack helm-charts to v64.0.0
([#849](#849))
([50a2588](50a2588))
* **deps:** update runtime to v0.6.0
([#897](#897))
([89ae6e2](89ae6e2))
* **deps:** update support-deps
([#890](#890))
([26ea612](26ea612))
* **deps:** update test-infra
([#875](#875))
([583f07c](583f07c))
* **deps:** update test-infra to v6.9.0
([#848](#848))
([ef9d317](ef9d317))
* **deps:** update uds to v0.17.0
([#859](#859))
([1489fef](1489fef))
* **deps:** update zarf to v0.41.0
([#857](#857))
([a390c3d](a390c3d))
* **docs:** update doc structure for site refresh
([#895](#895))
([1946a9a](1946a9a))
* fix broken link in docs
([#845](#845))
([3078a5b](3078a5b))
* fix license header references
([#901](#901))
([cf38b82](cf38b82))
* handle upgrade path for functional layers, add doc for usage
([#896](#896))
([70d6b1b](70d6b1b))
* regroup 'support dependencies' in renovate config
([#885](#885))
([640d859](640d859))
* update license
([#878](#878))
([b086170](b086170))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
## Description

Quick doc link fix.
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| aws | required_provider | minor | `~> 5.70.0` -> `~> 5.71.0` |
|
[defenseunicorns/lula](https://redirect.github.com/defenseunicorns/lula)
| | minor | `v0.8.0` -> `v0.9.1` |
|
[defenseunicorns/uds-common](https://redirect.github.com/defenseunicorns/uds-common)
| | minor | `v1.0.0` -> `v1.1.0` |
|
[terraform-aws-modules/s3-bucket/aws](https://registry.terraform.io/modules/terraform-aws-modules/s3-bucket/aws)
([source](https://redirect.github.com/terraform-aws-modules/terraform-aws-s3-bucket))
| module | patch | `4.2.0` -> `4.2.1` |

---

### Release Notes

<details>
<summary>defenseunicorns/lula (defenseunicorns/lula)</summary>

###
[`v0.9.1`](https://redirect.github.com/defenseunicorns/lula/releases/tag/v0.9.1)

[Compare
Source](https://redirect.github.com/defenseunicorns/lula/compare/v0.9.0...v0.9.1)

##### Bug Fixes

- **release:** add environment to push job
([#&#8203;735](https://redirect.github.com/defenseunicorns/lula/issues/735))
([1ed52f1](https://redirect.github.com/defenseunicorns/lula/commit/1ed52f1cf36214ef20ac5a95cee5d5f266232192))

#### What's Changed

- fix(release): add environment to push job by
[@&#8203;brandtkeller](https://redirect.github.com/brandtkeller) in
[https://github.com/defenseunicorns/lula/pull/735](https://redirect.github.com/defenseunicorns/lula/pull/735)
- chore(main): release 0.9.1 by
[@&#8203;github-actions](https://redirect.github.com/github-actions) in
[https://github.com/defenseunicorns/lula/pull/734](https://redirect.github.com/defenseunicorns/lula/pull/734)

**Full Changelog**:
defenseunicorns/lula@v0.9.0...v0.9.1

###
[`v0.9.0`](https://redirect.github.com/defenseunicorns/lula/releases/tag/v0.9.0)

[Compare
Source](https://redirect.github.com/defenseunicorns/lula/compare/v0.8.0...v0.9.0)

##### ⚠ BREAKING CHANGES

- **kubernetes:** wait logic kubernetes version support
([#&#8203;718](https://redirect.github.com/defenseunicorns/lula/issues/718))

##### Features

- **compose:** template files during compose operations
([#&#8203;686](https://redirect.github.com/defenseunicorns/lula/issues/686))
([c1745a4](https://redirect.github.com/defenseunicorns/lula/commit/c1745a41ff15b9cf8d6f5c4bf459be88bc84cbf9))
- **domains:** file domain
([#&#8203;703](https://redirect.github.com/defenseunicorns/lula/issues/703))
([bd4f577](https://redirect.github.com/defenseunicorns/lula/commit/bd4f57778c5e5bac539d14955e594ee15312c39c))
- **file domain:** add support for reading arbitrary files as strings
([#&#8203;726](https://redirect.github.com/defenseunicorns/lula/issues/726))
([0b1c0c8](https://redirect.github.com/defenseunicorns/lula/commit/0b1c0c8ddf7c0f5de8e23a0b42ca2348efaaef78))
- **kubernetes:** support running both create resources and resources in
the kubernetes spec
([#&#8203;714](https://redirect.github.com/defenseunicorns/lula/issues/714))
([6839d20](https://redirect.github.com/defenseunicorns/lula/commit/6839d205ea0f4434d6af2071f3f3ed444b131944))
- **kubernetes:** wait logic kubernetes version support
([#&#8203;718](https://redirect.github.com/defenseunicorns/lula/issues/718))
([cc06251](https://redirect.github.com/defenseunicorns/lula/commit/cc06251e75facf6f321ad4ca2f8609f782dcfb29))
- **release:** add brew install for lula
([#&#8203;707](https://redirect.github.com/defenseunicorns/lula/issues/707))
([fd1d3e0](https://redirect.github.com/defenseunicorns/lula/commit/fd1d3e08754a845e25c849b280ed6390a377e138))
- **validate:** template oscal during runtime
([#&#8203;708](https://redirect.github.com/defenseunicorns/lula/issues/708))
([3f5a110](https://redirect.github.com/defenseunicorns/lula/commit/3f5a110ecf692d99e1511ac82b737d82764321c2))

##### Bug Fixes

- add goreleaser pin version annotate
([#&#8203;712](https://redirect.github.com/defenseunicorns/lula/issues/712))
([68bc101](https://redirect.github.com/defenseunicorns/lula/commit/68bc1014edb701da12ddde6ae83ba90c8e19e774))
- **composition:** nil pointer in composition
([#&#8203;733](https://redirect.github.com/defenseunicorns/lula/issues/733))
([8ad4209](https://redirect.github.com/defenseunicorns/lula/commit/8ad420970cd6bd72ee0c18e6c25a4578e9db4432))
- **console:** refactor, retries, sleep to address flaky tests
([#&#8203;698](https://redirect.github.com/defenseunicorns/lula/issues/698))
([02101a5](https://redirect.github.com/defenseunicorns/lula/commit/02101a5633c009ff46083651745b6aa40ac62448))
- **console:** reset compdef when editing
([#&#8203;701](https://redirect.github.com/defenseunicorns/lula/issues/701))
([4e25f01](https://redirect.github.com/defenseunicorns/lula/commit/4e25f014d8ba9bd88df3317ec51ce3fa783203d0))
- **read:** error checking prior to file writes
([#&#8203;687](https://redirect.github.com/defenseunicorns/lula/issues/687))
([1ab0eef](https://redirect.github.com/defenseunicorns/lula/commit/1ab0eefdeeb1d59f16f33249b1a6fce141ef5942))

##### Miscellaneous

- add global command context for program cancelation and everything else
([#&#8203;696](https://redirect.github.com/defenseunicorns/lula/issues/696))
([df81cf7](https://redirect.github.com/defenseunicorns/lula/commit/df81cf7a74e6f78c27055b82c20375f53976cea8))
- **deps:** update actions/checkout action to v4.2.1
([#&#8203;713](https://redirect.github.com/defenseunicorns/lula/issues/713))
([802601a](https://redirect.github.com/defenseunicorns/lula/commit/802601a70fadfc142a47cc6e8528478a6aac3291))
- **deps:** update actions/upload-artifact action to v4.4.3
([#&#8203;711](https://redirect.github.com/defenseunicorns/lula/issues/711))
([a954664](https://redirect.github.com/defenseunicorns/lula/commit/a954664d0b2e25d58097425dfbeac193a200b6c5))
- **deps:** update github/codeql-action action to v3.26.12
([#&#8203;691](https://redirect.github.com/defenseunicorns/lula/issues/691))
([0efb120](https://redirect.github.com/defenseunicorns/lula/commit/0efb120a6f50e650a5e2962125a7495a21236fb8))
- **deps:** update module github.com/open-policy-agent/opa to v0.69.0
([#&#8203;692](https://redirect.github.com/defenseunicorns/lula/issues/692))
([e08d695](https://redirect.github.com/defenseunicorns/lula/commit/e08d695ea6629e2c60a33ae85edf076bbb49ee68))
- **deps:** update module sigs.k8s.io/cli-utils to v0.37.2
([#&#8203;721](https://redirect.github.com/defenseunicorns/lula/issues/721))
([5fd0f32](https://redirect.github.com/defenseunicorns/lula/commit/5fd0f3244e5543e5302fce2ea4a42afc87026217))
- update getting started doc to include brew install
([#&#8203;720](https://redirect.github.com/defenseunicorns/lula/issues/720))
([26c3f8d](https://redirect.github.com/defenseunicorns/lula/commit/26c3f8dd1d9a5e31d7bf3936b453a3e0edfd2755))

</details>

<details>
<summary>defenseunicorns/uds-common
(defenseunicorns/uds-common)</summary>

###
[`v1.1.0`](https://redirect.github.com/defenseunicorns/uds-common/releases/tag/v1.1.0)

[Compare
Source](https://redirect.github.com/defenseunicorns/uds-common/compare/v1.0.0...v1.1.0)

##### ⚠ BREAKING CHANGES

- update the license to AGPLv3 or Commercial
([#&#8203;286](https://redirect.github.com/defenseunicorns/uds-common/issues/286))

##### Bug Fixes

- modified jq command
([#&#8203;292](https://redirect.github.com/defenseunicorns/uds-common/issues/292))
([d566e86](https://redirect.github.com/defenseunicorns/uds-common/commit/d566e86c5a78f2124116113ea3ed35695caec5be))
- simplify git command for flavor checks
([#&#8203;290](https://redirect.github.com/defenseunicorns/uds-common/issues/290))
([72c4e35](https://redirect.github.com/defenseunicorns/uds-common/commit/72c4e35d5f9f6ed877c184cf748e67a77e4fa771))
- upgrade test not cloning in private repos
([#&#8203;295](https://redirect.github.com/defenseunicorns/uds-common/issues/295))
([1dde808](https://redirect.github.com/defenseunicorns/uds-common/commit/1dde808b943c554edcd401fb814d504ee74117c0))

##### Miscellaneous

- **badging:** include unicorn flavor suggstion for bronze
([#&#8203;288](https://redirect.github.com/defenseunicorns/uds-common/issues/288))
([f668b06](https://redirect.github.com/defenseunicorns/uds-common/commit/f668b06f1597efd3c701a47ce28de1d8f298b1b8))
- **deps:** update support-deps to v4.4.3
([#&#8203;282](https://redirect.github.com/defenseunicorns/uds-common/issues/282))
([13d35ef](https://redirect.github.com/defenseunicorns/uds-common/commit/13d35ef9831c71cc217ef43f2c13562f40a3ec5b))
- **deps:** update uds common package dependencies to v1.27.2
([#&#8203;229](https://redirect.github.com/defenseunicorns/uds-common/issues/229))
([5b6a722](https://redirect.github.com/defenseunicorns/uds-common/commit/5b6a7223469bddf79be079baab1e3333a01c71e5))
- disable stale PR rebasing for renovate
([#&#8203;284](https://redirect.github.com/defenseunicorns/uds-common/issues/284))
([27ca69e](https://redirect.github.com/defenseunicorns/uds-common/commit/27ca69e53d980672b655b03ee854d2e7ea0462dc))
- have addlicense ignore gitignored files
([#&#8203;294](https://redirect.github.com/defenseunicorns/uds-common/issues/294))
([1bf662e](https://redirect.github.com/defenseunicorns/uds-common/commit/1bf662e890a238bf49234e9768d5fa7078d4fdb3))
- make all Maru references local includes
([#&#8203;287](https://redirect.github.com/defenseunicorns/uds-common/issues/287))
([727db0f](https://redirect.github.com/defenseunicorns/uds-common/commit/727db0fae26a4397361bab84de18dd253a755c79))
- update the license to AGPLv3 or Commercial
([#&#8203;286](https://redirect.github.com/defenseunicorns/uds-common/issues/286))
([2a9ca00](https://redirect.github.com/defenseunicorns/uds-common/commit/2a9ca00409f3bb513d2f256bcf1a91146b94d514))

</details>

<details>
<summary>terraform-aws-modules/terraform-aws-s3-bucket
(terraform-aws-modules/s3-bucket/aws)</summary>

###
[`v4.2.1`](https://redirect.github.com/terraform-aws-modules/terraform-aws-s3-bucket/blob/HEAD/CHANGELOG.md#421-2024-10-11)

[Compare
Source](https://redirect.github.com/terraform-aws-modules/terraform-aws-s3-bucket/compare/v4.2.0...v4.2.1)

##### Bug Fixes

- Update CI workflow versions to latest
([#&#8203;293](https://redirect.github.com/terraform-aws-modules/terraform-aws-s3-bucket/issues/293))
([522fcff](https://redirect.github.com/terraform-aws-modules/terraform-aws-s3-bucket/commit/522fcffdf90b1325501e021548962f41978aeefc))

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/defenseunicorns/uds-core).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC4xMTUuMSIsInVwZGF0ZWRJblZlciI6IjM4LjExNS4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->

---------

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Micah Nagel <[email protected]>
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [weaveworks/eksctl](https://redirect.github.com/weaveworks/eksctl) |
minor | `v0.191.0` -> `v0.192.0` |

---

### Release Notes

<details>
<summary>weaveworks/eksctl (weaveworks/eksctl)</summary>

###
[`v0.192.0`](https://redirect.github.com/eksctl-io/eksctl/releases/tag/v0.192.0):
eksctl 0.192.0

[Compare
Source](https://redirect.github.com/weaveworks/eksctl/compare/0.192.0...0.192.0)

##### Release v0.192.0

##### 🚀 Features

- Add support for EKS accelerated AMIs based on AL2023
([#&#8203;7996](https://redirect.github.com/weaveworks/eksctl/issues/7996))

##### 🎯 Improvements

- cleanup efa installer archive before install
([#&#8203;6870](https://redirect.github.com/weaveworks/eksctl/issues/6870))

##### 🐛 Bug Fixes

- Disallow `overrideBootstrapCommand` and `preBootstrapCommands` for MNG
AL2023
([#&#8203;7990](https://redirect.github.com/weaveworks/eksctl/issues/7990))

##### Acknowledgments

The eksctl maintainers would like to sincerely thank
[@&#8203;vsoch](https://redirect.github.com/vsoch).

###
[`v0.192.0`](https://redirect.github.com/eksctl-io/eksctl/releases/tag/v0.192.0):
eksctl 0.192.0

[Compare
Source](https://redirect.github.com/weaveworks/eksctl/compare/0.191.0...0.192.0)

##### Release v0.192.0

##### 🚀 Features

- Add support for EKS accelerated AMIs based on AL2023
([#&#8203;7996](https://redirect.github.com/weaveworks/eksctl/issues/7996))

##### 🎯 Improvements

- cleanup efa installer archive before install
([#&#8203;6870](https://redirect.github.com/weaveworks/eksctl/issues/6870))

##### 🐛 Bug Fixes

- Disallow `overrideBootstrapCommand` and `preBootstrapCommands` for MNG
AL2023
([#&#8203;7990](https://redirect.github.com/weaveworks/eksctl/issues/7990))

##### Acknowledgments

The eksctl maintainers would like to sincerely thank
[@&#8203;vsoch](https://redirect.github.com/vsoch).

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/defenseunicorns/uds-core).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC4xMjAuMSIsInVwZGF0ZWRJblZlciI6IjM4LjEyMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [grafana](https://grafana.com)
([source](https://redirect.github.com/grafana/helm-charts)) | patch |
`8.5.2` -> `8.5.5` |

---

### Release Notes

<details>
<summary>grafana/helm-charts (grafana)</summary>

###
[`v8.5.5`](https://redirect.github.com/grafana/helm-charts/releases/tag/grafana-8.5.5)

[Compare
Source](https://redirect.github.com/grafana/helm-charts/compare/grafana-8.5.4...grafana-8.5.5)

The leading tool for querying and visualizing time series and metrics.

#### What's Changed

- \[grafana] Replicas could be 0
[#&#8203;3337](https://redirect.github.com/grafana/helm-charts/issues/3337)
by [@&#8203;ramon951](https://redirect.github.com/ramon951) in
[https://github.com/grafana/helm-charts/pull/3343](https://redirect.github.com/grafana/helm-charts/pull/3343)

#### New Contributors

- [@&#8203;ramon951](https://redirect.github.com/ramon951) made their
first contribution in
[https://github.com/grafana/helm-charts/pull/3343](https://redirect.github.com/grafana/helm-charts/pull/3343)

**Full Changelog**:
grafana/helm-charts@tempo-distributed-1.18.4...grafana-8.5.5

###
[`v8.5.4`](https://redirect.github.com/grafana/helm-charts/releases/tag/grafana-8.5.4)

[Compare
Source](https://redirect.github.com/grafana/helm-charts/compare/grafana-8.5.3...grafana-8.5.4)

The leading tool for querying and visualizing time series and metrics.

#### What's Changed

- \[grafana] chore: bump k8s-sidecar to 1.28.0 by
[@&#8203;mlflr](https://redirect.github.com/mlflr) in
[https://github.com/grafana/helm-charts/pull/3348](https://redirect.github.com/grafana/helm-charts/pull/3348)

#### New Contributors

- [@&#8203;mlflr](https://redirect.github.com/mlflr) made their first
contribution in
[https://github.com/grafana/helm-charts/pull/3348](https://redirect.github.com/grafana/helm-charts/pull/3348)

**Full Changelog**:
grafana/helm-charts@mimir-distributed-5.5.0...grafana-8.5.4

###
[`v8.5.3`](https://redirect.github.com/grafana/helm-charts/releases/tag/grafana-8.5.3)

[Compare
Source](https://redirect.github.com/grafana/helm-charts/compare/grafana-8.5.2...grafana-8.5.3)

The leading tool for querying and visualizing time series and metrics.

#### What's Changed

- \[grafana] Update Grafana to version 11.2.2 by
[@&#8203;terop](https://redirect.github.com/terop) in
[https://github.com/grafana/helm-charts/pull/3356](https://redirect.github.com/grafana/helm-charts/pull/3356)

**Full Changelog**:
grafana/helm-charts@alloy-0.9.1...grafana-8.5.3

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/defenseunicorns/uds-core).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC4xMTUuMSIsInVwZGF0ZWRJblZlciI6IjM4LjEyMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Micah Nagel <[email protected]>
## Description
Fixes broken links in uds operator code base (`./src/pepr`)

## Type of change

- [x] Bug fix (non-breaking change which fixes an issue)
- [ ] New feature (non-breaking change which adds functionality)
- [ ] Other (security config, docs update, etc)

## Checklist before merging

- [x] Test, docs, adr added or updated as needed
- [ ] [Contributor
Guide](https://github.com/defenseunicorns/uds-template-capability/blob/main/CONTRIBUTING.md)
followed
This PR contains the following updates:

| Package | Change | Age | Adoption | Passing | Confidence |
|---|---|---|---|---|---|
| [pepr](https://redirect.github.com/defenseunicorns/pepr) | [`0.37.2`
-> `0.38.0`](https://renovatebot.com/diffs/npm/pepr/0.37.2/0.38.0) |
[![age](https://developer.mend.io/api/mc/badges/age/npm/pepr/0.38.0?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/pepr/0.38.0?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/pepr/0.37.2/0.38.0?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/pepr/0.37.2/0.38.0?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|

---

### Release Notes

<details>
<summary>defenseunicorns/pepr (pepr)</summary>

###
[`v0.38.0`](https://redirect.github.com/defenseunicorns/pepr/releases/tag/v0.38.0)

[Compare
Source](https://redirect.github.com/defenseunicorns/pepr/compare/v0.37.2...v0.38.0)

#### Features

-   Adds support for http2 watch mode

*Note:* http2Watch has an issue around memory ([soak
results](https://redirect.github.com/defenseunicorns/pepr/actions/runs/11350714559/job/31569793202):
`ctrl-f` "Memory"). This is a known
[issue](https://redirect.github.com/defenseunicorns/kubernetes-fluent-client/issues/424).
We will look to make improvements during the next release of KFC. We
went ahead and released this feature because we are confident that it is
an immediate improvement as some users were manually rolling the watcher
pod to account for watch-misses.

#### Deprecations ⚠️

We identified a circular dependency which required us to relocate some
types. In this release, those types are removed from `src/lib/k8s.ts` to
`src/lib/types.ts`. If your module uses any of these types, please
update your imports accordingly to avoid issues.

Affected Types:

- [Operation
(enum)](https://redirect.github.com/defenseunicorns/pepr/blob/1e42d49cc90cf82ce85a57fb574917319db3c102/src/lib/k8s.ts#L6)
- [GroupVersionResource
(interface)](https://redirect.github.com/defenseunicorns/pepr/blob/1e42d49cc90cf82ce85a57fb574917319db3c102/src/lib/k8s.ts#L31)
- [AdmissionRequest
(interface)](https://redirect.github.com/defenseunicorns/pepr/blob/1e42d49cc90cf82ce85a57fb574917319db3c102/src/lib/k8s.ts#L42)

Find all of them now in
[types.ts](https://redirect.github.com/defenseunicorns/pepr/blob/1e42d49cc90cf82ce85a57fb574917319db3c102/src/lib/types.ts)

#### What's Changed

- chore(ci): add static-analysis checks to CI/CD by
[@&#8203;samayer12](https://redirect.github.com/samayer12) in
[https://github.com/defenseunicorns/pepr/pull/1219](https://redirect.github.com/defenseunicorns/pepr/pull/1219)
- chore: display resource usage in soak by
[@&#8203;cmwylie19](https://redirect.github.com/cmwylie19) in
[https://github.com/defenseunicorns/pepr/pull/1258](https://redirect.github.com/defenseunicorns/pepr/pull/1258)
- chore: validate images from registry via Pepr (ADR) by
[@&#8203;btlghrants](https://redirect.github.com/btlghrants) in
[https://github.com/defenseunicorns/pepr/pull/1256](https://redirect.github.com/defenseunicorns/pepr/pull/1256)
- chore: kfc automation scripts and workflow files by
[@&#8203;cmwylie19](https://redirect.github.com/cmwylie19) in
[https://github.com/defenseunicorns/pepr/pull/1223](https://redirect.github.com/defenseunicorns/pepr/pull/1223)
- chore: removes deprecated code - watcher docs - kfc bump by
[@&#8203;cmwylie19](https://redirect.github.com/cmwylie19) in
[https://github.com/defenseunicorns/pepr/pull/1269](https://redirect.github.com/defenseunicorns/pepr/pull/1269)
- chore(lint): adopt additional code quality rules by
[@&#8203;samayer12](https://redirect.github.com/samayer12) in
[https://github.com/defenseunicorns/pepr/pull/1212](https://redirect.github.com/defenseunicorns/pepr/pull/1212)
- chore: add watch logs to soak test to determine reasons for failure by
[@&#8203;cmwylie19](https://redirect.github.com/cmwylie19) in
[https://github.com/defenseunicorns/pepr/pull/1215](https://redirect.github.com/defenseunicorns/pepr/pull/1215)
- chore: kfc release-candidate for http2 watch by
[@&#8203;cmwylie19](https://redirect.github.com/cmwylie19) in
[https://github.com/defenseunicorns/pepr/pull/1239](https://redirect.github.com/defenseunicorns/pepr/pull/1239)
- chore: create projects using pepr markdown by
[@&#8203;tr-ace](https://redirect.github.com/tr-ace) in
[https://github.com/defenseunicorns/pepr/pull/1228](https://redirect.github.com/defenseunicorns/pepr/pull/1228)
- chore: choose soak branch by
[@&#8203;cmwylie19](https://redirect.github.com/cmwylie19) in
[https://github.com/defenseunicorns/pepr/pull/1232](https://redirect.github.com/defenseunicorns/pepr/pull/1232)
- chore: update_pod_map every 10 minutes by
[@&#8203;cmwylie19](https://redirect.github.com/cmwylie19) in
[https://github.com/defenseunicorns/pepr/pull/1227](https://redirect.github.com/defenseunicorns/pepr/pull/1227)
- chore: bump
[@&#8203;types/node](https://redirect.github.com/types/node) from 22.7.4
to 22.7.5 in the development-dependencies group by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/defenseunicorns/pepr/pull/1237](https://redirect.github.com/defenseunicorns/pepr/pull/1237)
- chore: bump actions/checkout from 4.2.0 to 4.2.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/defenseunicorns/pepr/pull/1236](https://redirect.github.com/defenseunicorns/pepr/pull/1236)
- chore: bump github/codeql-action from 3.26.11 to 3.26.12 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/defenseunicorns/pepr/pull/1235](https://redirect.github.com/defenseunicorns/pepr/pull/1235)
- chore: bump express from 4.21.0 to 4.21.1 in the
production-dependencies group by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/defenseunicorns/pepr/pull/1242](https://redirect.github.com/defenseunicorns/pepr/pull/1242)
- chore: bump chainguard/node from `f3ec99e` to `0d0083b` by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/defenseunicorns/pepr/pull/1233](https://redirect.github.com/defenseunicorns/pepr/pull/1233)
- chore: bump actions/upload-artifact from 4.4.0 to 4.4.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/defenseunicorns/pepr/pull/1241](https://redirect.github.com/defenseunicorns/pepr/pull/1241)
- chore: bump actions/upload-artifact from 4.4.2 to 4.4.3 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/defenseunicorns/pepr/pull/1254](https://redirect.github.com/defenseunicorns/pepr/pull/1254)
- chore: bump actions/checkout from 4.2.0 to 4.2.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/defenseunicorns/pepr/pull/1253](https://redirect.github.com/defenseunicorns/pepr/pull/1253)
- chore: bump chainguard/node from `0d0083b` to `bbcd423` by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/defenseunicorns/pepr/pull/1252](https://redirect.github.com/defenseunicorns/pepr/pull/1252)
- chore: bump anchore/scan-action from 4.1.2 to 5.0.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/defenseunicorns/pepr/pull/1264](https://redirect.github.com/defenseunicorns/pepr/pull/1264)
- chore: bump chainguard/node from `bbcd423` to `b0b04bb` by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/defenseunicorns/pepr/pull/1265](https://redirect.github.com/defenseunicorns/pepr/pull/1265)
- chore: bump peter-murray/workflow-application-token-action from 3.0.0
to 3.0.1 by [@&#8203;dependabot](https://redirect.github.com/dependabot)
in
[https://github.com/defenseunicorns/pepr/pull/1263](https://redirect.github.com/defenseunicorns/pepr/pull/1263)
- chore: bump github/codeql-action from 3.26.12 to 3.26.13 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/defenseunicorns/pepr/pull/1266](https://redirect.github.com/defenseunicorns/pepr/pull/1266)
- chore: bump the production-dependencies group across 1 directory with
2 updates by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/defenseunicorns/pepr/pull/1270](https://redirect.github.com/defenseunicorns/pepr/pull/1270)
- chore: bump github/codeql-action from 3.26.10 to 3.26.11 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/defenseunicorns/pepr/pull/1222](https://redirect.github.com/defenseunicorns/pepr/pull/1222)
- chore: bump docker/setup-buildx-action from 3.6.1 to 3.7.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/defenseunicorns/pepr/pull/1224](https://redirect.github.com/defenseunicorns/pepr/pull/1224)
- chore: bump chainguard/node from `ab523c4` to `f3ec99e` by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/defenseunicorns/pepr/pull/1220](https://redirect.github.com/defenseunicorns/pepr/pull/1220)

#### New Contributors

- [@&#8203;tr-ace](https://redirect.github.com/tr-ace) made their first
contribution in
[https://github.com/defenseunicorns/pepr/pull/1228](https://redirect.github.com/defenseunicorns/pepr/pull/1228)

**Full Changelog**:
defenseunicorns/pepr@v0.37.2...v0.38.0

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/defenseunicorns/uds-core).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC45Ny4wIiwidXBkYXRlZEluVmVyIjoiMzguMTIwLjEiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbXX0=-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…909)

## Description
The UDS Operator has KFC watch (exemptions) that operates outside of
Pepr configured watchers. This ensures the configuration for using HTTP2
watches is respected by the exemption watch.

## Type of change

- [ ] Bug fix (non-breaking change which fixes an issue)
- [ ] New feature (non-breaking change which adds functionality)
- [x] Other (security config, docs update, etc)

## Checklist before merging

- [ ] Test, docs, adr added or updated as needed
- [ ] [Contributor
Guide](https://github.com/defenseunicorns/uds-template-capability/blob/main/CONTRIBUTING.md)
followed
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[ghcr.io/defenseunicorns/uds-runtime](https://images.chainguard.dev/directory/image/static/overview)
([source](https://redirect.github.com/chainguard-images/images/tree/HEAD/images/static))
| patch | `0.6.0` -> `0.6.1` |
|
[https://github.com/defenseunicorns/uds-runtime.git](https://redirect.github.com/defenseunicorns/uds-runtime)
| patch | `v0.6.0` -> `v0.6.1` |

---

### Release Notes

<details>
<summary>defenseunicorns/uds-runtime
(https://github.com/defenseunicorns/uds-runtime.git)</summary>

###
[`v0.6.1`](https://redirect.github.com/defenseunicorns/uds-runtime/releases/tag/v0.6.1)

[Compare
Source](https://redirect.github.com/defenseunicorns/uds-runtime/compare/v0.6.0...v0.6.1)

##### Miscellaneous

- bump uds-types in package lock
([#&#8203;455](https://redirect.github.com/defenseunicorns/uds-runtime/issues/455))
([c17a583](https://redirect.github.com/defenseunicorns/uds-runtime/commit/c17a58343c94c3c4ea08717ffbaa2f5c10917a66))
- bumps uds-types version
([#&#8203;454](https://redirect.github.com/defenseunicorns/uds-runtime/issues/454))
([4c767d5](https://redirect.github.com/defenseunicorns/uds-runtime/commit/4c767d5e55a0f698b33ee50335cf11cfa5b5d155))
- **deps:** update dependency kubernetes-fluent-client to v3.1.1
([#&#8203;448](https://redirect.github.com/defenseunicorns/uds-runtime/issues/448))
([abe8583](https://redirect.github.com/defenseunicorns/uds-runtime/commit/abe85835dce4e57681cdff3f3a4ec9ec1c787b04))
- **deps:** update devdependencies
([#&#8203;446](https://redirect.github.com/defenseunicorns/uds-runtime/issues/446))
([a0f6163](https://redirect.github.com/defenseunicorns/uds-runtime/commit/a0f616335d824069ad511c79ebe7d61bb30c6739))
- license to AGPLv3 and update codeowners
([#&#8203;444](https://redirect.github.com/defenseunicorns/uds-runtime/issues/444))
([2f0682a](https://redirect.github.com/defenseunicorns/uds-runtime/commit/2f0682a57a8b889515096e8c765582b07ae41c12))
- refactor auth logic
([#&#8203;426](https://redirect.github.com/defenseunicorns/uds-runtime/issues/426))
([caa7e8f](https://redirect.github.com/defenseunicorns/uds-runtime/commit/caa7e8f77dce756a5fae4cfb81eb26d85dadd41d))
- update license headers
([#&#8203;450](https://redirect.github.com/defenseunicorns/uds-runtime/issues/450))
([5e3a614](https://redirect.github.com/defenseunicorns/uds-runtime/commit/5e3a6148df1acb556acd39914c36ef06a6f6fb72))
- updates codeowners for both license files
([#&#8203;453](https://redirect.github.com/defenseunicorns/uds-runtime/issues/453))
([6c4076a](https://redirect.github.com/defenseunicorns/uds-runtime/commit/6c4076a086fe4d9b8e67749a60151f17803e5448))

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these
updates again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/defenseunicorns/uds-core).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC4xMjAuMSIsInVwZGF0ZWRJblZlciI6IjM4LjEyMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
## Description

This changes the proxy cleanup logic to be:

All containers terminated AND either:
- restartPolicy of Never
- restartPolicy of OnFailure w/0 exit code

A restartPolicy of Always should keep restarting the containers inside
the pod and should not need proxy cleanup.

## Related Issue

Fixes #913 

## Type of change

- [x] Bug fix (non-breaking change which fixes an issue)
- [ ] New feature (non-breaking change which adds functionality)
- [ ] Other (security config, docs update, etc)

## Checklist before merging

- [ ] Test, docs, adr added or updated as needed
- [x] [Contributor
Guide](https://github.com/defenseunicorns/uds-template-capability/blob/main/CONTRIBUTING.md)
followed
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[registry1.dso.mil/ironbank/opensource/defenseunicorns/pepr/controller](https://redirect.github.com/defenseunicorns/pepr)
([source](https://repo1.dso.mil/dsop/opensource/defenseunicorns/pepr/controller))
| minor | `v0.37.2` -> `v0.38.0` |

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/defenseunicorns/uds-core).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC4xMjAuMSIsInVwZGF0ZWRJblZlciI6IjM4LjEyMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[cgr.dev/du-uds-defenseunicorns/kube-webhook-certgen-fips](https://images.chainguard.dev/directory/image/kube-webhook-certgen-fips/overview)
([source](https://redirect.github.com/chainguard-images/images-private/tree/HEAD/images/kube-webhook-certgen-fips))
| patch | `1.11.2` -> `1.11.3` |
|
[kube-prometheus-stack](https://redirect.github.com/prometheus-operator/kube-prometheus)
([source](https://redirect.github.com/prometheus-community/helm-charts))
| minor | `65.0.0` -> `65.2.0` |
|
[registry.k8s.io/ingress-nginx/kube-webhook-certgen](https://redirect.github.com/kubernetes/ingress-nginx)
| patch | `v1.4.3` -> `v1.4.4` |
|
[registry1.dso.mil/ironbank/opensource/ingress-nginx/kube-webhook-certgen](https://redirect.github.com/kubernetes/ingress-nginx/)
([source](https://repo1.dso.mil/dsop/opensource/kubernetes/ingress-nginx/kube-webhook-certgen))
| patch | `v1.4.3` -> `v1.4.4` |

---

### Release Notes

<details>
<summary>prometheus-community/helm-charts
(kube-prometheus-stack)</summary>

###
[`v65.2.0`](https://redirect.github.com/prometheus-community/helm-charts/compare/kube-prometheus-stack-65.1.1...kube-prometheus-stack-65.2.0)

[Compare
Source](https://redirect.github.com/prometheus-community/helm-charts/compare/kube-prometheus-stack-65.1.1...kube-prometheus-stack-65.2.0)

###
[`v65.1.1`](https://redirect.github.com/prometheus-community/helm-charts/compare/kube-prometheus-stack-65.1.0...kube-prometheus-stack-65.1.1)

[Compare
Source](https://redirect.github.com/prometheus-community/helm-charts/compare/kube-prometheus-stack-65.1.0...kube-prometheus-stack-65.1.1)

###
[`v65.1.0`](https://redirect.github.com/prometheus-community/helm-charts/compare/kube-prometheus-stack-65.0.0...kube-prometheus-stack-65.1.0)

[Compare
Source](https://redirect.github.com/prometheus-community/helm-charts/compare/kube-prometheus-stack-65.0.0...kube-prometheus-stack-65.1.0)

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/defenseunicorns/uds-core).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC45Ny4wIiwidXBkYXRlZEluVmVyIjoiMzguMTE1LjEiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbXX0=-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Chance <[email protected]>
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| aws | required_provider | minor | `~> 5.71.0` -> `~> 5.72.0` |
|
[terraform-aws-modules/rds/aws](https://registry.terraform.io/modules/terraform-aws-modules/rds/aws)
([source](https://redirect.github.com/terraform-aws-modules/terraform-aws-rds))
| module | minor | `6.9.0` -> `6.10.0` |

---

### Release Notes

<details>
<summary>terraform-aws-modules/terraform-aws-rds
(terraform-aws-modules/rds/aws)</summary>

###
[`v6.10.0`](https://redirect.github.com/terraform-aws-modules/terraform-aws-rds/blob/HEAD/CHANGELOG.md#6100-2024-10-16)

[Compare
Source](https://redirect.github.com/terraform-aws-modules/terraform-aws-rds/compare/v6.9.0...v6.10.0)

##### Features

- Support `cloudwatch_log_group_tags` parameter
([#&#8203;571](https://redirect.github.com/terraform-aws-modules/terraform-aws-rds/issues/571))
([73e33fe](https://redirect.github.com/terraform-aws-modules/terraform-aws-rds/commit/73e33feba5d907801791168ebf6d3132fbd646f5))

##### Bug Fixes

- Update CI workflow versions to latest
([#&#8203;570](https://redirect.github.com/terraform-aws-modules/terraform-aws-rds/issues/570))
([220cc85](https://redirect.github.com/terraform-aws-modules/terraform-aws-rds/commit/220cc85dcdc8eb63772e25526db693dd563d40a1))

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/defenseunicorns/uds-core).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC4xMjAuMSIsInVwZGF0ZWRJblZlciI6IjM4LjEyMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Micah Nagel <[email protected]>
…annotation (#916)

## Description
Adds a check to the `annotateMutation` function that prevents duplicate
values (policy names) from being added to the
`uds-core.pepr.dev/mutated` key

## Related Issue
Fixes #717

## Type of change

- [x] Bug fix (non-breaking change which fixes an issue)
- [ ] New feature (non-breaking change which adds functionality)
- [ ] Other (security config, docs update, etc)

## Checklist before merging

- [ ] Test, docs, adr added or updated as needed
- [ ] [Contributor
Guide](https://github.com/defenseunicorns/uds-template-capability/blob/main/CONTRIBUTING.md)
followed

---------

Co-authored-by: Micah Nagel <[email protected]>
## Description

Splits the validations out from the OSCAL Component-Definition. `lula
validate` can work remotely to validate the validations.

Updated the OSCAL Assessment-Result as the baseline has changed from
High to Moderate.

Updated the Istio catalog source url to a tagged version (recent GSA
release)

This pattern allows for easier maintenance and development of the
validations by not reading through 1000s of lines of OSCAL and OSCAL
formatting just to make a small update.

All of the validations under the ./compliance/validations directory are
a pull from the compliance-artifacts repo where OSCAL and Validations
development happen.

## Related Issue

Relates to #797

## Type of change

- [ ] Bug fix (non-breaking change which fixes an issue)
- [ ] New feature (non-breaking change which adds functionality)
- [x] Other (security config, docs update, etc)

## Checklist before merging

- [x] Test, docs, adr added or updated as needed
- [x] [Contributor
Guide](https://github.com/defenseunicorns/uds-template-capability/blob/main/CONTRIBUTING.md)
followed
This PR contains the following updates:

| Package | Change | Age | Adoption | Passing | Confidence |
|---|---|---|---|---|---|
| [pepr](https://redirect.github.com/defenseunicorns/pepr) | [`0.38.0`
-> `0.38.1`](https://renovatebot.com/diffs/npm/pepr/0.38.0/0.38.1) |
[![age](https://developer.mend.io/api/mc/badges/age/npm/pepr/0.38.1?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/pepr/0.38.1?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/pepr/0.38.0/0.38.1?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/pepr/0.38.0/0.38.1?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|

---

### Release Notes

<details>
<summary>defenseunicorns/pepr (pepr)</summary>

###
[`v0.38.1`](https://redirect.github.com/defenseunicorns/pepr/releases/tag/v0.38.1)

[Compare
Source](https://redirect.github.com/defenseunicorns/pepr/compare/v0.38.0...v0.38.1)

##### What's Changed

- chore: get pods each reporting interval by
[@&#8203;cmwylie19](https://redirect.github.com/cmwylie19) in
[https://github.com/defenseunicorns/pepr/pull/1279](https://redirect.github.com/defenseunicorns/pepr/pull/1279)
- chore: node-latest is breaking ci - change matrix to 22 by
[@&#8203;cmwylie19](https://redirect.github.com/cmwylie19) in
[https://github.com/defenseunicorns/pepr/pull/1288](https://redirect.github.com/defenseunicorns/pepr/pull/1288)
- chore: reduce package size - exclude tests from package by
[@&#8203;cmwylie19](https://redirect.github.com/cmwylie19) in
[https://github.com/defenseunicorns/pepr/pull/1275](https://redirect.github.com/defenseunicorns/pepr/pull/1275)
- test: http2-enable watcher and iso format logs in soak test by
[@&#8203;btlghrants](https://redirect.github.com/btlghrants) in
[https://github.com/defenseunicorns/pepr/pull/1277](https://redirect.github.com/defenseunicorns/pepr/pull/1277)
- test: http2-enable watcher in smoke test by
[@&#8203;btlghrants](https://redirect.github.com/btlghrants) in
[https://github.com/defenseunicorns/pepr/pull/1281](https://redirect.github.com/defenseunicorns/pepr/pull/1281)
- chore: update resource limits/requests on controllers by
[@&#8203;cmwylie19](https://redirect.github.com/cmwylie19) in
[https://github.com/defenseunicorns/pepr/pull/1291](https://redirect.github.com/defenseunicorns/pepr/pull/1291)
- chore: bump peter-murray/workflow-application-token-action from 3.0.1
to 4.0.0 by [@&#8203;dependabot](https://redirect.github.com/dependabot)
in
[https://github.com/defenseunicorns/pepr/pull/1273](https://redirect.github.com/defenseunicorns/pepr/pull/1273)
- chore: bump anchore/scan-action from 5.0.0 to 5.0.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/defenseunicorns/pepr/pull/1272](https://redirect.github.com/defenseunicorns/pepr/pull/1272)
- chore: bump chainguard/node from `8a604e5` to `b0b04bb` by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/defenseunicorns/pepr/pull/1271](https://redirect.github.com/defenseunicorns/pepr/pull/1271)
- chore: bump kubernetes-fluent-client from 3.1.1 to 3.1.2 in the
production-dependencies group by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/defenseunicorns/pepr/pull/1292](https://redirect.github.com/defenseunicorns/pepr/pull/1292)
- chore: bump
[@&#8203;types/node](https://redirect.github.com/types/node) from 22.7.5
to 22.7.6 in the development-dependencies group by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/defenseunicorns/pepr/pull/1293](https://redirect.github.com/defenseunicorns/pepr/pull/1293)
- chore: bump chainguard/node from `b0b04bb` to `96260af` by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/defenseunicorns/pepr/pull/1289](https://redirect.github.com/defenseunicorns/pepr/pull/1289)

**Full Changelog**:
defenseunicorns/pepr@v0.38.0...v0.38.1

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/defenseunicorns/uds-core).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC4xMjAuMSIsInVwZGF0ZWRJblZlciI6IjM4LjEyMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
## Description
CI currently doesn't check for license linting. Also updating some
compliance files with license headers.


## Type of change

- [ ] Bug fix (non-breaking change which fixes an issue)
- [ ] New feature (non-breaking change which adds functionality)
- [x] Other (security config, docs update, etc)

## Checklist before merging

- [x] Test, docs, adr added or updated as needed
- [x] [Contributor
Guide](https://github.com/defenseunicorns/uds-template-capability/blob/main/CONTRIBUTING.md)
followed
update pepr policy docs

- [ ] Bug fix (non-breaking change which fixes an issue)
- [ ] New feature (non-breaking change which adds functionality)
- [x] Other (security config, docs update, etc)

- [x] Test, docs, adr added or updated as needed
- [x] [Contributor
Guide](https://github.com/defenseunicorns/uds-template-capability/blob/main/CONTRIBUTING.md)
followed

---------

Co-authored-by: Micah Nagel <[email protected]>
EBS impose a 1Gi size limitation on restored PVCs. This adds a short
note to pre-reqs about checking CSI limitations.

While testing with our EKS IAC I also discovered a few other issues:
- IRSA annotations were not correct
- Config did not properly variablize region
- Config had an unmatched `"` around one of the values
- Gitignore did not exclude terraform/tfstate files that shouldn't be
committed

Fixes #718

- [x] Bug fix (non-breaking change which fixes an issue)
- [ ] New feature (non-breaking change which adds functionality)
- [ ] Other (security config, docs update, etc)

- [x] Test, docs, adr added or updated as needed
- [x] [Contributor
Guide](https://github.com/defenseunicorns/uds-template-capability/blob/main/CONTRIBUTING.md)
followed
BREAKING CHANGE: Noting this as a breaking change as Promtail is removed
and replaced by Vector. If using overrides to setup additional log
targets/endpoints this configuration will need to be updated to Vector's
chart/config formats.

Primary docs on rationale, decision, and impact of this switch are
[here](https://github.com/defenseunicorns/uds-core/blob/vector-add/src/vector/README.md).

Fixes #377

- [ ] Bug fix (non-breaking change which fixes an issue)
- [x] New feature (non-breaking change which adds functionality)
- [ ] Other (security config, docs update, etc)

- [x] Test, docs, adr added or updated as needed
- [x] [Contributor
Guide](https://github.com/defenseunicorns/uds-template-capability/blob/main/CONTRIBUTING.md)
followed
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[ghcr.io/defenseunicorns/uds-runtime](https://images.chainguard.dev/directory/image/static/overview)
([source](https://redirect.github.com/chainguard-images/images/tree/HEAD/images/static))
| minor | `0.4.0` -> `0.5.0` |
|
[https://github.com/defenseunicorns/uds-runtime.git](https://redirect.github.com/defenseunicorns/uds-runtime)
| minor | `v0.4.0` -> `v0.5.0` |

---

<details>
<summary>defenseunicorns/uds-runtime
(https://github.com/defenseunicorns/uds-runtime.git)</summary>

[`v0.5.0`](https://redirect.github.com/defenseunicorns/uds-runtime/releases/tag/v0.5.0)

[Compare
Source](https://redirect.github.com/defenseunicorns/uds-runtime/compare/v0.4.0...v0.5.0)

- **api:** adds jwt group validation when in-cluster
([#&#8203;387](https://redirect.github.com/defenseunicorns/uds-runtime/issues/387))
([8a53f76](https://redirect.github.com/defenseunicorns/uds-runtime/commit/8a53f76fc684f3e2562ab3076b67d7a68571589d))
- make deployment resources configurable and up default memory
([#&#8203;372](https://redirect.github.com/defenseunicorns/uds-runtime/issues/372))
([2981598](https://redirect.github.com/defenseunicorns/uds-runtime/commit/29815984b28b793087ede78a5de59e5376903477))
- **ui:** adding events tab
([#&#8203;342](https://redirect.github.com/defenseunicorns/uds-runtime/issues/342))
([cb9b43a](https://redirect.github.com/defenseunicorns/uds-runtime/commit/cb9b43a84a3d157b9759a063788e1cecf9e9e868))
- **ui:** fixing issue with progress bar
([#&#8203;375](https://redirect.github.com/defenseunicorns/uds-runtime/issues/375))
([3f8f204](https://redirect.github.com/defenseunicorns/uds-runtime/commit/3f8f20442b89f04af04aa7cd62655fe98d716063))
- **ui:** updating pods table column name
([#&#8203;369](https://redirect.github.com/defenseunicorns/uds-runtime/issues/369))
([25aaaf9](https://redirect.github.com/defenseunicorns/uds-runtime/commit/25aaaf9a630b785a4b8b1b123d29a4df148e0288))

- ensure pod counts are consistent
([#&#8203;363](https://redirect.github.com/defenseunicorns/uds-runtime/issues/363))
([a5c837b](https://redirect.github.com/defenseunicorns/uds-runtime/commit/a5c837b767a316a89a01cdcbebf36a6e407a4883))
- fixing issue with firefox not supporting text-wrap: pretty
([#&#8203;382](https://redirect.github.com/defenseunicorns/uds-runtime/issues/382))
([4465617](https://redirect.github.com/defenseunicorns/uds-runtime/commit/44656170b50ce308cc61eb6b1aaa3ca325926080))
- fixing memory bar for overview page
([#&#8203;381](https://redirect.github.com/defenseunicorns/uds-runtime/issues/381))
([4f321e3](https://redirect.github.com/defenseunicorns/uds-runtime/commit/4f321e348f57fd5d8d15fc3f383a3f64b403d9fd))
- use tls 1.2 in canary deployment
([#&#8203;383](https://redirect.github.com/defenseunicorns/uds-runtime/issues/383))
([08b5bdc](https://redirect.github.com/defenseunicorns/uds-runtime/commit/08b5bdc6e9df063ce06466276bf78312f9e14aaf))

- api route test helper with retries and exponential backoff
([#&#8203;357](https://redirect.github.com/defenseunicorns/uds-runtime/issues/357))
([674f37e](https://redirect.github.com/defenseunicorns/uds-runtime/commit/674f37ed94dfcf1722f8f23bbcd2434cf1adde66))
- **ci:** update core demo bundle version for ephemeral env
([#&#8203;360](https://redirect.github.com/defenseunicorns/uds-runtime/issues/360))
([161fa7e](https://redirect.github.com/defenseunicorns/uds-runtime/commit/161fa7ee3685387a9ce4469b6e07dfa3082aec17))
- **deps:** update dependency vite to v5.3.6 \[security]
([#&#8203;341](https://redirect.github.com/defenseunicorns/uds-runtime/issues/341))
([6dc4ad2](https://redirect.github.com/defenseunicorns/uds-runtime/commit/6dc4ad22400ee48f71e2197441fa40253c6bf9c6))
- **deps:** update github actions
([#&#8203;334](https://redirect.github.com/defenseunicorns/uds-runtime/issues/334))
([117410e](https://redirect.github.com/defenseunicorns/uds-runtime/commit/117410e92c7a6d7d5324d50338f34b11484e9818))
- **deps:** update github actions
([#&#8203;371](https://redirect.github.com/defenseunicorns/uds-runtime/issues/371))
([78bb3a1](https://redirect.github.com/defenseunicorns/uds-runtime/commit/78bb3a1aa73de7d5f6145d6a7310d3460dbbdd46))
- **deps:** update module github.com/zarf-dev/zarf to v0.40.1
([#&#8203;359](https://redirect.github.com/defenseunicorns/uds-runtime/issues/359))
([12a0f5e](https://redirect.github.com/defenseunicorns/uds-runtime/commit/12a0f5ed8c64c6862db43408b7e878a996795673))
- **deps:** update uds-core-types digest to
[`df4d2da`](https://redirect.github.com/defenseunicorns/uds-runtime/commit/df4d2da)
([#&#8203;362](https://redirect.github.com/defenseunicorns/uds-runtime/issues/362))
([0a67913](https://redirect.github.com/defenseunicorns/uds-runtime/commit/0a679136bda31b46e66008bfbf30f8f8ddc61df8))
- refactors uds tasks and adds smoke test
([#&#8203;344](https://redirect.github.com/defenseunicorns/uds-runtime/issues/344))
([2fec985](https://redirect.github.com/defenseunicorns/uds-runtime/commit/2fec985eecf3026a2cd05dda08aca1845ac0479c))
- update description for UDS Package
([#&#8203;356](https://redirect.github.com/defenseunicorns/uds-runtime/issues/356))
([d360d38](https://redirect.github.com/defenseunicorns/uds-runtime/commit/d360d38f8e50648c6e6e167c70a12233ff2eef23))
- update slim core with authsvc deployment and bump k3d version
([#&#8203;389](https://redirect.github.com/defenseunicorns/uds-runtime/issues/389))
([216bab6](https://redirect.github.com/defenseunicorns/uds-runtime/commit/216bab6a2735a1d8d2bbf7b55d6a8369579e81a3))

</details>

---

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these
updates again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/defenseunicorns/uds-core).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC44MC4wIiwidXBkYXRlZEluVmVyIjoiMzguODAuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: UncleGedd <[email protected]>
Adjust Pepr watch limit to a lower value to help UDS Package
delete/reinstalls succeed more often.

Fixes # #839

- [x] Bug fix (non-breaking change which fixes an issue)

- [x] Test, docs, adr added or updated as needed
- [x] [Contributor
Guide](https://github.com/defenseunicorns/uds-template-capability/blob/main/CONTRIBUTING.md)
followed
🤖 I have created a release *beep* *boop*
---

[0.28.0](v0.27.3...v0.28.0)
(2024-09-27)

* Promtail has been removed from UDS Core and replaced by Vector. If you
were previously using overrides to setup additional log
targets/endpoints for Promtail this configuration will need to be
updated to Vector's chart/config formats. See Vector's [Sources and
Sinks](https://vector.dev/components/) as well as the [helm chart
values](https://github.com/defenseunicorns/uds-core/blob/1bf29582f9c5b1fe01763e86e56c19b6e17aef85/src/vector/values/values.yaml#L4)
for guidance in configuration.

* add support for keycloak saml attributes
([#806](#806))
([b312b7d](b312b7d))
* exposes tls version for dev bundles
([#809](#809))
([e1a2b55](e1a2b55))
* switch from promtail to vector
(#724)
([1bf2958](1bf2958))

* eks iac issues, document storage class pre-reqs
([#812](#812))
([df514bd](df514bd))
* ensure istio sidecar is killed if job fails
([#813](#813))
([34ffc0a](34ffc0a))
* revert test app version to fix CI failures
([#815](#815))
([2ec6ad6](2ec6ad6))

* add runtime group to renovate config
([#799](#799))
([1bf2c69](1bf2c69))
* **deps:** update dependency defenseunicorns/uds-common to v0.13.0
([#790](#790))
([8bfcdc0](8bfcdc0))
* **deps:** update dependency defenseunicorns/uds-common to v0.13.1
([#810](#810))
([eedb551](eedb551))
* **deps:** update istio to v1.23.2
([#796](#796))
([039d89c](039d89c))
* **deps:** update keycloak to v25.0.6
([#771](#771))
([9864059](9864059))
* **deps:** update pepr to v0.13.1
([#811](#811))
([bc05b04](bc05b04))
* **deps:** update prometheus operator to v0.77.0
([#783](#783))
([8f383d8](8f383d8))
* **deps:** update runtime to v0.5.0
([#834](#834))
([edc068d](edc068d))
* **deps:** update setup-node to v4.0.4
([#801](#801))
([34dbc44](34dbc44))
* **deps:** update uds to v0.16.0
([#802](#802))
([d07670b](d07670b))
* **deps:** update uds-common to v0.13.0
([#792](#792))
([c24e833](c24e833))
* **deps:** update zarf to v0.40.1
([#793](#793))
([db93a7e](db93a7e))
* fix github-actions renovate
([#800](#800))
([3ab2add](3ab2add))
* pepr policies doc table
([#803](#803))
([440e4e1](440e4e1))
* pepr policy doc
([#814](#814))
([8b10b86](8b10b86))
* updated pepr watch limit to 60s
([#840](#840))
([85f3f41](85f3f41))
* use kfc WatchPhase enum
([#787](#787))
([df4d2da](df4d2da))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@docandrew docandrew closed this Oct 17, 2024
@docandrew docandrew deleted the secretcopy branch October 17, 2024 20:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Secrets manipulation using the UDS Operator