diff --git a/Cargo.lock b/Cargo.lock index b02e298..b055f27 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -1921,7 +1921,7 @@ dependencies = [ [[package]] name = "shadowstep" -version = "2.0.0" +version = "2.1.0" dependencies = [ "actix-http", "actix-web", diff --git a/Cargo.toml b/Cargo.toml index 124b0c6..5e4051d 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "shadowstep" -version = "2.0.0" +version = "2.1.0" edition = "2021" license = "MIT" diff --git a/README.md b/README.md index a70c8ce..f914feb 100644 --- a/README.md +++ b/README.md @@ -127,13 +127,13 @@ Known limits: Each release tag `vX.Y.Z` publishes a multi-platform image for `linux/amd64` and `linux/arm64` to `ghcr.io/jamiehdev/shadowstep`, tagged `X.Y.Z`, `X.Y` and `latest`. A pre-release tag such as `v2.1.0-rc.1` publishes only `2.1.0-rc.1`. ```bash -docker pull ghcr.io/jamiehdev/shadowstep:2.0.0 +docker pull ghcr.io/jamiehdev/shadowstep:2.1.0 ``` The image carries SLSA provenance and an SBOM. To check that an image was built by this repository's release workflow: ```bash -gh attestation verify oci://ghcr.io/jamiehdev/shadowstep:2.0.0 --owner jamiehdev +gh attestation verify oci://ghcr.io/jamiehdev/shadowstep:2.1.0 --owner jamiehdev ``` Releases do not include prebuilt binaries. To run outside a container, build from source as shown in [Build](#build). @@ -239,7 +239,7 @@ The container runs as user `shadowstep` (uid 1000), so the mounted key file must ## Kubernetes -`k8s/` holds a Deployment and a LoadBalancer Service. The Deployment runs `ghcr.io/jamiehdev/shadowstep:2.0.0`. Before applying them, set `ORIGIN_URL` in `k8s/deployment.yaml` and create the TLS Secret the Deployment mounts at `/etc/tls`: +`k8s/` holds a Deployment and a LoadBalancer Service. The Deployment runs `ghcr.io/jamiehdev/shadowstep:2.1.0`. Before applying them, set `ORIGIN_URL` in `k8s/deployment.yaml` and create the TLS Secret the Deployment mounts at `/etc/tls`: ```bash kubectl create secret tls shadowstep-tls --cert=certs/cert.pem --key=certs/key.pem diff --git a/k8s/deployment.yaml b/k8s/deployment.yaml index 5b7fb1d..643cd9c 100644 --- a/k8s/deployment.yaml +++ b/k8s/deployment.yaml @@ -21,7 +21,7 @@ spec: fsGroup: 1000 containers: - name: shadowstep - image: ghcr.io/jamiehdev/shadowstep:2.0.0 + image: ghcr.io/jamiehdev/shadowstep:2.1.0 securityContext: allowPrivilegeEscalation: false capabilities: