diff --git a/Cargo.lock b/Cargo.lock index bf9324e..5f9b6c3 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -1935,7 +1935,7 @@ dependencies = [ [[package]] name = "shadowstep" -version = "2.1.0" +version = "2.2.0" dependencies = [ "actix-http", "actix-web", diff --git a/Cargo.toml b/Cargo.toml index 2c095c9..1b5ba6f 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "shadowstep" -version = "2.1.0" +version = "2.2.0" edition = "2021" license = "MIT" diff --git a/README.md b/README.md index e225058..5b06683 100644 --- a/README.md +++ b/README.md @@ -164,13 +164,13 @@ To keep `/metrics` off the public listeners, set `--metrics-addr` to an address Each release tag `vX.Y.Z` publishes a multi-platform image for `linux/amd64` and `linux/arm64` to `ghcr.io/jamiehdev/shadowstep`, tagged `X.Y.Z`, `X.Y` and `latest`. A pre-release tag such as `v2.1.0-rc.1` publishes only `2.1.0-rc.1`. ```bash -docker pull ghcr.io/jamiehdev/shadowstep:2.1.0 +docker pull ghcr.io/jamiehdev/shadowstep:2.2.0 ``` The image carries SLSA provenance and an SBOM. To check that an image was built by this repository's release workflow: ```bash -gh attestation verify oci://ghcr.io/jamiehdev/shadowstep:2.1.0 --owner jamiehdev +gh attestation verify oci://ghcr.io/jamiehdev/shadowstep:2.2.0 --owner jamiehdev ``` Releases do not include prebuilt binaries. To run outside a container, build from source as shown in [Build](#build). @@ -277,7 +277,7 @@ The container runs as user `shadowstep` (uid 1000), so the mounted key file must ## Kubernetes -`k8s/` holds a Deployment and a LoadBalancer Service. The Deployment runs `ghcr.io/jamiehdev/shadowstep:2.1.0`. Before applying them, set `ORIGIN_URL` in `k8s/deployment.yaml` and create the TLS Secret the Deployment mounts at `/etc/tls`: +`k8s/` holds a Deployment and a LoadBalancer Service. The Deployment runs `ghcr.io/jamiehdev/shadowstep:2.2.0`. Before applying them, set `ORIGIN_URL` in `k8s/deployment.yaml` and create the TLS Secret the Deployment mounts at `/etc/tls`: ```bash kubectl create secret tls shadowstep-tls --cert=certs/cert.pem --key=certs/key.pem diff --git a/k8s/deployment.yaml b/k8s/deployment.yaml index 643cd9c..cf11930 100644 --- a/k8s/deployment.yaml +++ b/k8s/deployment.yaml @@ -21,7 +21,7 @@ spec: fsGroup: 1000 containers: - name: shadowstep - image: ghcr.io/jamiehdev/shadowstep:2.1.0 + image: ghcr.io/jamiehdev/shadowstep:2.2.0 securityContext: allowPrivilegeEscalation: false capabilities: