You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
[OPERATOR][BREAKING] The naming restriction for the default OIDC provider has been removed (was restricted to default before) and it is now defaulted to openmcp instead.
[USER][BREAKING] The validation for the spec.iam.oidcProviders field in the ManagedControlPlaneV2 resource has been changed in multiple ways:
usernamePrefix and groupsPrefix have been removed and are now always assumed to be <name>:
name is not allowed to be set to system (prevents k8s service account impersonation)
The regex validation rule for name has been fixed
issuer and clientID are now required and the former one must look like an URL
Duplicate OIDC provider names or ones that clash with the default OIDC provider are now prevented
[OPERATOR][OTHER] It is now possible to specify the logging verbosity in the PlatformService, ClusterProvider, and ServiceProvider resources also in lowercase.