Use entity policies for secret store access instead of through jwt
Some checks failed
Run Check Script / check (pull_request) Failing after 53s
feat(fleet): graceful roll-forward upgrade + container-ID identity (Ch5)
All checks were successful
Run Check Script / check (pull_request) Successful in 2m36s
feat(fleet): agent self-upgrade + auto-rollback protocol, ADR-022 (Ch4)
All checks were successful
Run Check Script / check (pull_request) Successful in 2m35s
feat(fleet-operator): live-tail device logs via 2s frontend polling (Ch3)
All checks were successful
Run Check Script / check (pull_request) Successful in 2m34s
feat(fleet-operator): aggregator recovery signal + orphan GC + recovery e2e (Ch2)
Some checks failed
Run Check Script / check (pull_request) Failing after 52s
feat(fleet-auth): unify Zitadel role extraction + request roles via scope (Ch1)
All checks were successful
Run Check Script / check (pull_request) Successful in 2m31s
Add claims fields to struct
All checks were successful
Run Check Script / check (pull_request) Successful in 2m15s
add Zitadel JWT-bearer auth rung to OpenbaoSecretStore
All checks were successful
Run Check Script / check (pull_request) Successful in 2m17s
Move ZitadelJwt to stand alone module
Some checks failed
Run Check Script / check (pull_request) Failing after 50s
fix(fleet-operator): dashboard UI bugs (mostly CSP-blocked inline JS)
All checks were successful
Run Check Script / check (pull_request) Successful in 2m15s
feat(fleet-operator): real dashboard data from kube CRs + NATS KV
All checks were successful
Run Check Script / check (pull_request) Successful in 2m17s
feat(fleet): expose operator UI via cert-manager TLS ingress
All checks were successful
Run Check Script / check (pull_request) Successful in 2m15s
chore: Refactor FLEET_OPERATOR_CREDENTIALS string that appeared in multiple places into a constant shared across all consumers
All checks were successful
Run Check Script / check (pull_request) Successful in 2m14s
docs: ADR on how to handle securely fleet device secrets with openbao + zitadel SSO
All checks were successful
Run Check Script / check (pull_request) Successful in 2m16s
chore/rename-release-to-publish
All checks were successful
Run Check Script / check (pull_request) Successful in 2m16s
fix: fleet operator chart name was conflicting with the container name. Append -chart to the chart name
All checks were successful
Run Check Script / check (pull_request) Successful in 2m16s
Allow redirect url path when user signs in
Some checks failed
Run Check Script / check (pull_request) Failing after 51s
refactor(fleet-deploy): rename harmony-fleet-release to harmony-fleet-publish
All checks were successful
Run Check Script / check (pull_request) Successful in 2m27s
refactor(fleet-deploy): rename HARMONY_SECRET_NAMESPACE to HARMONY_CONFIG_NAMESPACE
All checks were successful
Run Check Script / check (pull_request) Successful in 2m26s
feat/fleet-staging-openbao
All checks were successful
Run Check Script / check (pull_request) Successful in 2m17s