Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion Cargo.toml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
[package]
name = "shadowstep"
version = "2.0.0"
version = "2.1.0"
edition = "2021"
license = "MIT"

Expand Down
6 changes: 3 additions & 3 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -127,13 +127,13 @@ Known limits:
Each release tag `vX.Y.Z` publishes a multi-platform image for `linux/amd64` and `linux/arm64` to `ghcr.io/jamiehdev/shadowstep`, tagged `X.Y.Z`, `X.Y` and `latest`. A pre-release tag such as `v2.1.0-rc.1` publishes only `2.1.0-rc.1`.

```bash
docker pull ghcr.io/jamiehdev/shadowstep:2.0.0
docker pull ghcr.io/jamiehdev/shadowstep:2.1.0
```

The image carries SLSA provenance and an SBOM. To check that an image was built by this repository's release workflow:

```bash
gh attestation verify oci://ghcr.io/jamiehdev/shadowstep:2.0.0 --owner jamiehdev
gh attestation verify oci://ghcr.io/jamiehdev/shadowstep:2.1.0 --owner jamiehdev
```

Releases do not include prebuilt binaries. To run outside a container, build from source as shown in [Build](#build).
Expand Down Expand Up @@ -239,7 +239,7 @@ The container runs as user `shadowstep` (uid 1000), so the mounted key file must

## Kubernetes

`k8s/` holds a Deployment and a LoadBalancer Service. The Deployment runs `ghcr.io/jamiehdev/shadowstep:2.0.0`. Before applying them, set `ORIGIN_URL` in `k8s/deployment.yaml` and create the TLS Secret the Deployment mounts at `/etc/tls`:
`k8s/` holds a Deployment and a LoadBalancer Service. The Deployment runs `ghcr.io/jamiehdev/shadowstep:2.1.0`. Before applying them, set `ORIGIN_URL` in `k8s/deployment.yaml` and create the TLS Secret the Deployment mounts at `/etc/tls`:

```bash
kubectl create secret tls shadowstep-tls --cert=certs/cert.pem --key=certs/key.pem
Expand Down
2 changes: 1 addition & 1 deletion k8s/deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ spec:
fsGroup: 1000
containers:
- name: shadowstep
image: ghcr.io/jamiehdev/shadowstep:2.0.0
image: ghcr.io/jamiehdev/shadowstep:2.1.0
securityContext:
allowPrivilegeEscalation: false
capabilities:
Expand Down
Loading