14 Commits
Author SHA1 Message Date
Thibault VINCENT 3c0be584d7 test(e2e): probe /healthz instead of /metrics on port-forwards 2026-08-04 20:22:12 +02:00
Thibault VINCENT 0debda6a7b build(goreleaser): use v2.16 post-hook for Tilt retag, label base image digest
- dockers_v2.hooks.post on the tilt entry strips the -<arch> suffix
  dockers_v2 appends in snapshot mode, keeping the workaround colocated
  with the build config instead of in the Tiltfile.
- baseimage/baseimagedigest template variables populate
  org.opencontainers.image.base.name/digest on the busybox variant for
  supply-chain transparency. Scratch is skipped — FROM scratch has no
  parent and the labels would be empty.
- flake.nix grows a dedicated goreleaser derivation (fetchurl pattern,
  mirroring goSizeAnalyzer) so the dev shell ships a version
  independent of nixpkgs. Renovate tracks the pin via a new regex
  manager that uses the same depName as the existing CI pin, so a
  single PR bumps every reference.
2026-05-25 13:43:04 +02:00
Thibault VINCENT 6a55f83cd1 test(e2e): cover x509_crl_* with fresh, stale, and cert+CRL mixed scenarios 2026-05-13 16:57:02 +02:00
Thibault VINCENT 80b44e80f3 test(cabundle): close audit gaps (rotation, cross-kind, validation, fixtures) 2026-05-13 14:24:36 +02:00
Thibault VINCENT 7610ca68fe feat(cabundle): extend source to APIService and CRD conversion webhooks 2026-05-13 14:24:36 +02:00
Thibault VINCENT 86fb1c11b9 test+docs(cabundle): e2e scenarios, README + metrics.md, opt-in example 2026-05-13 14:24:36 +02:00
Thibault VINCENT 9626e52baf feat(chart): support glob and recursive (**) patterns in watchDirectories
Fix #108
2026-05-12 15:08:40 +02:00
Thibault VINCENT 5fe6ffe495 test(e2e): auth-gating tests for webConfiguration (TLS+mTLS+basic_auth) and rbacProxy 2026-05-06 02:45:46 +02:00
Thibault VINCENT e354287f94 test(e2e): assert exposed Secret label values + cover 'right type, no matching key' 2026-05-05 21:18:11 +02:00
Thibault VINCENT b4cecfd4fe test(k8s): add memory smoke tests, ConfigMap delete coverage, and a sync benchmark 2026-05-05 14:43:36 +02:00
Thibault VINCENT 14b17c79dc docs: align comments and documentation with direct LIST+WATCH architecture 2026-05-05 14:34:42 +02:00
Thibault VINCENT d5b3cc1b32 chore(e2e): improve e2e cluster isolation 2026-05-03 12:57:53 +02:00
Thibault VINCENT a93402f86e test(e2e): new scenario for hostpath exporter 2026-05-01 19:19:45 +02:00
Thibault VINCENT b4f3f84086 feat!: rewrite from scratch with new architecture and toolchain
Complete rewrite of the codebase, the build pipeline, the dev loop,
and the release pipeline.

For the exporter itself, refer to the updated README and Helm chart
documentation to discover the new functionality and assess the impact
of the breaking changes on your existing setup.

Build & release:
- QA/CI pipelines now run through a Dagger Module, wrapped by
  Taskfile.yml for the developer interface.
- Releases run through GoReleaser: cross-compiled binaries × OS/arch,
  archives, checksums, multi-arch container images (busybox + scratch
  variants on linux/amd64,arm64,riscv64), pushed to ghcr/quay/docker.io.
- Everything is cosign-signed (binaries, images, Helm chart). Image
  CycloneDX SBOMs are attached as cosign attestations. SLSA-3
  provenance is attached to every GitHub Release.
- The Helm chart is published as a cosign-signed OCI artifact.
- Versioning and changelog are automated by release-please from
  Conventional Commits.

Dev experience:
- Local loop driven by Tilt + k3d + Dagger; one command brings up an
  exporter with seeded fixtures and a Prometheus scraping it.
- End-to-end tests run on a throwaway k3d cluster against the real
  rendered chart.

BREAKING CHANGE: the Helm chart is now published exclusively as an OCI
artifact at oci://quay.io/enix/charts/x509-certificate-exporter. The
legacy Helm repository at https://charts.enix.io is no longer updated;
users must switch to the OCI reference (Helm 3.8+ required).
Installation: `helm install x509-certificate-exporter
oci://quay.io/enix/charts/x509-certificate-exporter --version <vX.Y.Z>`.
BREAKING CHANGE: the Helm chart's values schema may diverge from v3 in
edge cases despite a best-effort to preserve backwards compatibility.
Review your existing values against the updated chart/values.yaml
before upgrading. A JSON schema (chart/values.schema.json) is shipped
with the chart so `helm install` / `helm upgrade` will reject any
values that no longer match the expected shape, surfacing regressions
early instead of at runtime.
BREAKING CHANGE: Alpine-based container images are no longer published.
The release pipeline now ships only the `busybox` and `scratch` variants
on linux/amd64,arm64,riscv64. Users pulling `*-alpine` tags must switch
to one of the new variants — `busybox` is the closest functional
replacement (still has a shell), `scratch` is the minimal distroless
option.
2026-04-30 20:35:54 +02:00