Commit Graph
180 Commits
Author SHA1 Message Date
Thibault VINCENT 2b878d55c7 refactor: clean up dead PassphraseAnnotation field + README JKS source list + JCEKS fuzz seeds 2026-05-15 16:54:25 +02:00
Thibault VINCENT 0f013463a6 feat(k8s, config): add jks.passphraseSecretRef for parity with pkcs12 2026-05-15 16:54:25 +02:00
Thibault VINCENT 19305f0774 feat(config, cmd): wire format: jks + jks: passphrase block 2026-05-13 17:55:30 +02:00
Thibault VINCENT 7ce1092693 feat(cert/der): parse single-blob DER as cert or CRL via x509 stdlib 2026-05-13 16:57:02 +02:00
Thibault VINCENT 80b44e80f3 test(cabundle): close audit gaps (rotation, cross-kind, validation, fixtures) 2026-05-13 14:24:36 +02:00
Thibault VINCENT 7610ca68fe feat(cabundle): extend source to APIService and CRD conversion webhooks 2026-05-13 14:24:36 +02:00
Thibault VINCENT 6f8d78396a feat(source/cabundle): watch MWC + VWC caBundles cluster-wide 2026-05-13 14:24:36 +02:00
Thibault VINCENT ab1ce3ad77 feat(k8s): support shell-glob patterns in include/exclude names 2026-05-11 18:16:38 +02:00
Thibault VINCENT 5614977544 refactor: drop pre-v4 leftover debug constant and timing placeholder 2026-05-06 04:56:29 +02:00
Thibault VINCENT aabe4eaa9b refactor(pkg): promote fileglob and source/* from internal 2026-05-06 04:52:48 +02:00
Thibault VINCENT 098894fe30 feat(exporter): probe-only HTTP server on --probe.listen-address 2026-05-06 02:56:05 +02:00
Thibault VINCENT ffcff3bd58 feat(k8s): log elapsed time on initial sync, namespace informer sync, and list completes 2026-05-05 17:45:33 +02:00
Thibault VINCENT 9dd380c98c feat(k8s): log apiserver problematic responses (429/5xx/401/403) at WARN 2026-05-05 15:36:43 +02:00
Thibault VINCENT ee520bfb9c feat(k8s): apply separate backoff after a watch closes prematurely (flap protection) 2026-05-05 15:33:16 +02:00
Thibault VINCENT a28205e8a3 feat(k8s): bound LIST request duration with a per-call timeout 2026-05-05 15:30:49 +02:00
Thibault VINCENT 5f7a33795c fix(k8s): cap retry backoff at 1 min to recover within etcd outage windows 2026-05-05 15:27:28 +02:00
Thibault VINCENT ea0c765a59 docs: document deferred Lot 4 optimisations as inline TODOs 2026-05-05 15:22:41 +02:00
Thibault VINCENT a232327337 refactor(sources): centralize file/kubeconfig poll defaults as named constants 2026-05-05 15:16:18 +02:00
Thibault VINCENT a83602efc5 refactor(k8s): centralize source defaults and backoff caps as named constants 2026-05-05 15:15:00 +02:00
Thibault VINCENT e6c7201a53 refactor(config): centralize built-in default values as named constants 2026-05-05 15:14:11 +02:00
Thibault VINCENT d8a9f3073c refactor(cert): centralize remaining error reason codes 2026-05-05 15:09:56 +02:00
Thibault VINCENT 7ab4d2972b refactor(cert): extract typed constants for parser format names 2026-05-05 15:08:14 +02:00
Thibault VINCENT 4c6f518fed refactor: centralize secret_label/configmap_label attribute prefixes 2026-05-05 15:06:31 +02:00
Thibault VINCENT ede793c41a test(k8s): tighten memory smoke budget to 2.5 MiB 2026-05-05 14:50:40 +02:00
Thibault VINCENT 0653f78a3c refactor(k8s): silence ineffassign on intentional GC drops, drop dead bookmark RV tracking 2026-05-05 14:50:40 +02:00
Thibault VINCENT b4cecfd4fe test(k8s): add memory smoke tests, ConfigMap delete coverage, and a sync benchmark 2026-05-05 14:43:36 +02:00
Thibault VINCENT 14b17c79dc docs: align comments and documentation with direct LIST+WATCH architecture 2026-05-05 14:34:42 +02:00
Thibault VINCENT ab4d4709d0 refactor: extract typed constants for Source kind values 2026-05-05 14:22:20 +02:00
Thibault VINCENT 66d2ee4bb0 feat(k8s): make LIST page size configurable per source 2026-05-05 14:20:37 +02:00
Thibault VINCENT 2ee438dda2 refactor(k8s): replace SharedInformer with paginated direct LIST+WATCH 2026-05-05 14:17:17 +02:00
Thibault VINCENT e3d7c53eda fix(k8s): scope poll-based defaults to file/kubeconfig sources 2026-05-05 14:14:16 +02:00
Thibault VINCENT 1c636d3a10 feat: add detailed debug logging for k8s resource processing 2026-05-04 04:05:00 +02:00
Thibault VINCENT a719113cb8 feat!: add new metric gates, diags and not_before off by defaut, 2026-05-03 16:07:48 +02:00
Thibault VINCENT 647f284706 test(fuzz): new tests on cert parsers and glob pattern 2026-05-02 14:57:36 +02:00
Thibault VINCENT f00198df5f refactor(server): use errors.Is for http.ErrServerClosed sentinel check 2026-05-02 14:25:25 +02:00
Thibault VINCENT 607537c798 test: fail fast on os.WriteFile setup errors 2026-05-02 14:24:53 +02:00
Thibault VINCENT 7a3dc5c6fa test(server): fix codeql warning on return value 2026-05-02 14:19:46 +02:00
Thibault VINCENT 83aba2eb57 test(server): fix codeql warning on a race 2026-05-02 14:09:52 +02:00
Thibault VINCENT 92388df185 refactor: fix linter warnings 2026-05-02 13:43:18 +02:00
Thibault VINCENT a93402f86e test(e2e): new scenario for hostpath exporter 2026-05-01 19:19:45 +02:00
Thibault VINCENT bbd179c05b feat: symlink path mapping and containment
Also restores the ability of the exporter to read the kubelet certificate when host mounting /var/lib/kubelet/pki inside a container.
Previously the exporter was using an unconditionnal hack to achieve this.
2026-05-01 18:13:20 +02:00
Thibault VINCENT d210862ed3 test(source/file): fix coverage gap for symlink swaps with skipUnchanged 2026-04-30 20:36:02 +02:00
Thibault VINCENT b4f3f84086 feat!: rewrite from scratch with new architecture and toolchain
Complete rewrite of the codebase, the build pipeline, the dev loop,
and the release pipeline.

For the exporter itself, refer to the updated README and Helm chart
documentation to discover the new functionality and assess the impact
of the breaking changes on your existing setup.

Build & release:
- QA/CI pipelines now run through a Dagger Module, wrapped by
  Taskfile.yml for the developer interface.
- Releases run through GoReleaser: cross-compiled binaries × OS/arch,
  archives, checksums, multi-arch container images (busybox + scratch
  variants on linux/amd64,arm64,riscv64), pushed to ghcr/quay/docker.io.
- Everything is cosign-signed (binaries, images, Helm chart). Image
  CycloneDX SBOMs are attached as cosign attestations. SLSA-3
  provenance is attached to every GitHub Release.
- The Helm chart is published as a cosign-signed OCI artifact.
- Versioning and changelog are automated by release-please from
  Conventional Commits.

Dev experience:
- Local loop driven by Tilt + k3d + Dagger; one command brings up an
  exporter with seeded fixtures and a Prometheus scraping it.
- End-to-end tests run on a throwaway k3d cluster against the real
  rendered chart.

BREAKING CHANGE: the Helm chart is now published exclusively as an OCI
artifact at oci://quay.io/enix/charts/x509-certificate-exporter. The
legacy Helm repository at https://charts.enix.io is no longer updated;
users must switch to the OCI reference (Helm 3.8+ required).
Installation: `helm install x509-certificate-exporter
oci://quay.io/enix/charts/x509-certificate-exporter --version <vX.Y.Z>`.
BREAKING CHANGE: the Helm chart's values schema may diverge from v3 in
edge cases despite a best-effort to preserve backwards compatibility.
Review your existing values against the updated chart/values.yaml
before upgrading. A JSON schema (chart/values.schema.json) is shipped
with the chart so `helm install` / `helm upgrade` will reject any
values that no longer match the expected shape, surfacing regressions
early instead of at runtime.
BREAKING CHANGE: Alpine-based container images are no longer published.
The release pipeline now ships only the `busybox` and `scratch` variants
on linux/amd64,arm64,riscv64. Users pulling `*-alpine` tags must switch
to one of the new variants — `busybox` is the closest functional
replacement (still has a shell), `scratch` is the minimal distroless
option.
2026-04-30 20:35:54 +02:00
Thibault VINCENT 0bf10f5f5a fix: don't delay server initialization while caches are populated
Prevents the failure of Kubernetes healthchecks while the Secrets exporter discovers certificates and feeds caches.

Pending rewrite of the whole program startup process.
2026-04-03 14:57:57 +02:00
Lucas Nassif 85c97e3837 feat: add opt-in flag to skip symlinks 2026-03-23 17:24:56 +01:00
Paul Laffitte c2707f5324 fix: linter issues 2026-02-25 14:44:19 +01:00
Paul Laffitte cf32174e6d chore: modernize some loops with slices.Contains 2026-02-25 12:04:20 +01:00
Paul Laffitte d5adc63394 fix: don't list all namespaces if not needed for filtering
With restricted cluster access (eg. multi tenant environments), listing
all namespaces prevented the tool to work. Listing namespace is not
necessary unless --include-namespace-label or --exclude-namespace-label
are set.
2026-02-25 12:04:20 +01:00
David Donchez e86185c339 refactor(exporter): avoid recompiling regex on every label iteration 2026-02-25 10:46:42 +01:00
David Donchez d16454dca4 chore(exporter): cleanup nonsensical check 2026-02-25 10:46:42 +01:00