Skip to content

crypto: test credential upgrades and structured secrets - #26106

Closed
dominic-r wants to merge 21 commits into
dominic/rotation-endpoint-connectorsfrom
dominic/rotation-migration-tests
Closed

dominic-r wants to merge 21 commits into
dominic/rotation-endpoint-connectorsfrom
dominic/rotation-migration-tests

Conversation

@dominic-r

Copy link
Copy Markdown
Member

No description provided.

@dominic-r
dominic-r requested a review from a team as a code owner September 14, 2026 00:46
@dominic-r dominic-r added this to the Release 2026.11.0: Required milestone Sep 14, 2026
@dominic-r dominic-r self-assigned this Sep 14, 2026
@dominic-r
dominic-r added this pull request to stack #26110 September 14, 2026 00:49
@netlify

netlify Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for authentik-docs ready!

Name Link
🔨 Latest commit c451978
🔍 Latest deploy log https://app.netlify.com/projects/authentik-docs/deploys/6ac3e98957386a00081f447e
😎 Deploy Preview https://deploy-preview-26106--authentik-docs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@dominic-r
dominic-r force-pushed the dominic/rotation-endpoint-connectors branch from 5152422 to 542605b Compare September 14, 2026 02:02
@dominic-r
dominic-r requested a review from a team as a code owner September 14, 2026 02:02
@dominic-r
dominic-r force-pushed the dominic/rotation-migration-tests branch from c8ae300 to 863f472 Compare September 14, 2026 02:04
@codecov

codecov Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 92.06%. Comparing base (f44f43b) to head (8275dcf).
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@                          Coverage Diff                          @@
##           dominic/rotation-endpoint-connectors   #26106   +/-   ##
=====================================================================
  Coverage                                 92.06%   92.06%           
=====================================================================
  Files                                      1196     1196           
  Lines                                     79746    79746           
  Branches                                   4121     4121           
=====================================================================
  Hits                                      73421    73421           
  Misses                                     6259     6259           
  Partials                                     66       66           
Flag Coverage Δ
conformance 32.50% <0.00%> (+<0.01%) ⬆️
integration 29.33% <0.00%> (ø)
rust 46.54% <0.00%> (ø)
unit 93.99% <0.00%> (ø)
unit-migrate 93.99% <0.00%> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

@dominic-r
dominic-r force-pushed the dominic/rotation-migration-tests branch from 863f472 to 941e10e Compare September 14, 2026 02:18
@dominic-r
dominic-r force-pushed the dominic/rotation-endpoint-connectors branch 2 times, most recently from 093794f to 4690c58 Compare September 14, 2026 02:28
@dominic-r
dominic-r force-pushed the dominic/rotation-migration-tests branch from 941e10e to a5816ab Compare September 14, 2026 02:28
@dominic-r
dominic-r force-pushed the dominic/rotation-endpoint-connectors branch from 4690c58 to a9342ca Compare September 14, 2026 02:48
@dominic-r
dominic-r force-pushed the dominic/rotation-migration-tests branch from a5816ab to 03a4431 Compare September 14, 2026 02:48
@github-actions

github-actions Bot commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

authentik PR Installation instructions

Instructions for docker-compose

Add the following block to your .env file:

AUTHENTIK_IMAGE=ghcr.io/goauthentik/dev-server
AUTHENTIK_TAG=gh-06b74bb66965a09b4b02e9693fe07ebc509ecbcb
AUTHENTIK_OUTPOSTS__CONTAINER_IMAGE_BASE=ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)s

Afterwards, run the upgrade commands from the latest release notes.

Instructions for Kubernetes

Add the following block to your values.yml file:

authentik:
    outposts:
        container_image_base: ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)s
global:
    image:
        repository: ghcr.io/goauthentik/dev-server
        tag: gh-06b74bb66965a09b4b02e9693fe07ebc509ecbcb

Afterwards, run the upgrade commands from the latest release notes.

@dominic-r
dominic-r force-pushed the dominic/rotation-endpoint-connectors branch from a9342ca to d982492 Compare September 14, 2026 03:32
@dominic-r
dominic-r force-pushed the dominic/rotation-migration-tests branch from 03a4431 to e9ccb36 Compare September 14, 2026 03:32
@dominic-r
dominic-r force-pushed the dominic/rotation-endpoint-connectors branch from d982492 to b8736b7 Compare September 14, 2026 04:00
@dominic-r
dominic-r force-pushed the dominic/rotation-migration-tests branch from e9ccb36 to d1d6af2 Compare September 14, 2026 04:00
@github-actions

Copy link
Copy Markdown
Contributor

Playwright e2e — ❌ Failed

Result Count
✅ Passed 46
❌ Failed 1
⚠️ Flaky 0
⏭️ Skipped 13

Failures

  • 102-passkeys.test.ts:44 › Passkeys › Enroll a passkey and sign in with it

Download the HTML report · Workflow run

gh run download 35163656793 -n playwright-report -D playwright-report
npx playwright show-report playwright-report

@netlify

netlify Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for authentik-integrations ready!

Name Link
🔨 Latest commit 8275dcf
🔍 Latest deploy log https://app.netlify.com/projects/authentik-integrations/deploys/6acaaaf3d2d2e7000806e97a
😎 Deploy Preview https://deploy-preview-26106--authentik-integrations.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@netlify

netlify Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for authentik-storybook ready!

Name Link
🔨 Latest commit 8275dcf
🔍 Latest deploy log https://app.netlify.com/projects/authentik-storybook/deploys/6acaaaf36231860008378dd4
😎 Deploy Preview https://deploy-preview-26106--authentik-storybook.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@github-actions

github-actions Bot commented Sep 20, 2026 •

Copy link
Copy Markdown
Contributor

Playwright e2e

Download this run's HTML report and traces, then open the report:

gh run download 37354742063 -D playwright-artifacts
npx playwright show-report playwright-artifacts/playwright-report

Installation instructions

Instructions for docker-compose

Add the following block to your .env file:

AUTHENTIK_IMAGE=ghcr.io/goauthentik/dev-server
AUTHENTIK_TAG=gh-c45197832a3b9e1794d1fd207f3d0e1880d4a4bf
AUTHENTIK_OUTPOSTS__CONTAINER_IMAGE_BASE=ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)s

Afterwards, run the upgrade commands from the latest release notes.

Instructions for Kubernetes

Add the following block to your values.yml file:

authentik:
    outposts:
        container_image_base: ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)s
global:
    image:
        repository: ghcr.io/goauthentik/dev-server
        tag: gh-c45197832a3b9e1794d1fd207f3d0e1880d4a4bf

Afterwards, run the upgrade commands from the latest release notes.

@dominic-r
dominic-r force-pushed the dominic/rotation-endpoint-connectors branch from 161e853 to 636efab Compare September 23, 2026 21:24
@dominic-r
dominic-r requested review from a team as code owners September 23, 2026 21:25
@dominic-r
dominic-r force-pushed the dominic/rotation-migration-tests branch from 1a4fbdf to 32fd4f6 Compare September 23, 2026 21:25
@dominic-r
dominic-r force-pushed the dominic/rotation-endpoint-connectors branch from 636efab to 07f4e77 Compare October 5, 2026 17:57
@dominic-r
dominic-r force-pushed the dominic/rotation-migration-tests branch from 32fd4f6 to 979f633 Compare October 5, 2026 17:57
…tion-migration-tests

# Conflicts:
#	authentik/crypto/secrets/tests/test_credential_upgrades.py
The upgrade round trip moved to the layer that adds the migration
helpers, and the kubeconfig and Google credential checks either moved
next to their consumers or became redundant once JSON secrets are
validated when they're saved.
@dominic-r

Copy link
Copy Markdown
Member Author

Closing: this layer no longer has changes of its own. Its tests moved into the layers whose code they test, and its UI moved into #26107, so the stack goes from #26105 straight to #26107.

@dominic-r dominic-r closed this Oct 10, 2026
@dominic-r
dominic-r removed this pull request from stack #26110 October 10, 2026 21:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant